xref: /openbmc/linux/drivers/net/wireless/ath/ath11k/wmi.c (revision 50dc9a85)
1 // SPDX-License-Identifier: BSD-3-Clause-Clear
2 /*
3  * Copyright (c) 2018-2019 The Linux Foundation. All rights reserved.
4  */
5 #include <linux/skbuff.h>
6 #include <linux/ctype.h>
7 #include <net/mac80211.h>
8 #include <net/cfg80211.h>
9 #include <linux/completion.h>
10 #include <linux/if_ether.h>
11 #include <linux/types.h>
12 #include <linux/pci.h>
13 #include <linux/uuid.h>
14 #include <linux/time.h>
15 #include <linux/of.h>
16 #include "core.h"
17 #include "debug.h"
18 #include "mac.h"
19 #include "hw.h"
20 #include "peer.h"
21 
22 struct wmi_tlv_policy {
23 	size_t min_len;
24 };
25 
26 struct wmi_tlv_svc_ready_parse {
27 	bool wmi_svc_bitmap_done;
28 };
29 
30 struct wmi_tlv_dma_ring_caps_parse {
31 	struct wmi_dma_ring_capabilities *dma_ring_caps;
32 	u32 n_dma_ring_caps;
33 };
34 
35 struct wmi_tlv_svc_rdy_ext_parse {
36 	struct ath11k_service_ext_param param;
37 	struct wmi_soc_mac_phy_hw_mode_caps *hw_caps;
38 	struct wmi_hw_mode_capabilities *hw_mode_caps;
39 	u32 n_hw_mode_caps;
40 	u32 tot_phy_id;
41 	struct wmi_hw_mode_capabilities pref_hw_mode_caps;
42 	struct wmi_mac_phy_capabilities *mac_phy_caps;
43 	u32 n_mac_phy_caps;
44 	struct wmi_soc_hal_reg_capabilities *soc_hal_reg_caps;
45 	struct wmi_hal_reg_capabilities_ext *ext_hal_reg_caps;
46 	u32 n_ext_hal_reg_caps;
47 	struct wmi_tlv_dma_ring_caps_parse dma_caps_parse;
48 	bool hw_mode_done;
49 	bool mac_phy_done;
50 	bool ext_hal_reg_done;
51 	bool mac_phy_chainmask_combo_done;
52 	bool mac_phy_chainmask_cap_done;
53 	bool oem_dma_ring_cap_done;
54 	bool dma_ring_cap_done;
55 };
56 
57 struct wmi_tlv_svc_rdy_ext2_parse {
58 	struct wmi_tlv_dma_ring_caps_parse dma_caps_parse;
59 	bool dma_ring_cap_done;
60 };
61 
62 struct wmi_tlv_rdy_parse {
63 	u32 num_extra_mac_addr;
64 };
65 
66 struct wmi_tlv_dma_buf_release_parse {
67 	struct ath11k_wmi_dma_buf_release_fixed_param fixed;
68 	struct wmi_dma_buf_release_entry *buf_entry;
69 	struct wmi_dma_buf_release_meta_data *meta_data;
70 	u32 num_buf_entry;
71 	u32 num_meta;
72 	bool buf_entry_done;
73 	bool meta_data_done;
74 };
75 
76 static const struct wmi_tlv_policy wmi_tlv_policies[] = {
77 	[WMI_TAG_ARRAY_BYTE]
78 		= { .min_len = 0 },
79 	[WMI_TAG_ARRAY_UINT32]
80 		= { .min_len = 0 },
81 	[WMI_TAG_SERVICE_READY_EVENT]
82 		= { .min_len = sizeof(struct wmi_service_ready_event) },
83 	[WMI_TAG_SERVICE_READY_EXT_EVENT]
84 		= { .min_len =  sizeof(struct wmi_service_ready_ext_event) },
85 	[WMI_TAG_SOC_MAC_PHY_HW_MODE_CAPS]
86 		= { .min_len = sizeof(struct wmi_soc_mac_phy_hw_mode_caps) },
87 	[WMI_TAG_SOC_HAL_REG_CAPABILITIES]
88 		= { .min_len = sizeof(struct wmi_soc_hal_reg_capabilities) },
89 	[WMI_TAG_VDEV_START_RESPONSE_EVENT]
90 		= { .min_len = sizeof(struct wmi_vdev_start_resp_event) },
91 	[WMI_TAG_PEER_DELETE_RESP_EVENT]
92 		= { .min_len = sizeof(struct wmi_peer_delete_resp_event) },
93 	[WMI_TAG_OFFLOAD_BCN_TX_STATUS_EVENT]
94 		= { .min_len = sizeof(struct wmi_bcn_tx_status_event) },
95 	[WMI_TAG_VDEV_STOPPED_EVENT]
96 		= { .min_len = sizeof(struct wmi_vdev_stopped_event) },
97 	[WMI_TAG_REG_CHAN_LIST_CC_EVENT]
98 		= { .min_len = sizeof(struct wmi_reg_chan_list_cc_event) },
99 	[WMI_TAG_MGMT_RX_HDR]
100 		= { .min_len = sizeof(struct wmi_mgmt_rx_hdr) },
101 	[WMI_TAG_MGMT_TX_COMPL_EVENT]
102 		= { .min_len = sizeof(struct wmi_mgmt_tx_compl_event) },
103 	[WMI_TAG_SCAN_EVENT]
104 		= { .min_len = sizeof(struct wmi_scan_event) },
105 	[WMI_TAG_PEER_STA_KICKOUT_EVENT]
106 		= { .min_len = sizeof(struct wmi_peer_sta_kickout_event) },
107 	[WMI_TAG_ROAM_EVENT]
108 		= { .min_len = sizeof(struct wmi_roam_event) },
109 	[WMI_TAG_CHAN_INFO_EVENT]
110 		= { .min_len = sizeof(struct wmi_chan_info_event) },
111 	[WMI_TAG_PDEV_BSS_CHAN_INFO_EVENT]
112 		= { .min_len = sizeof(struct wmi_pdev_bss_chan_info_event) },
113 	[WMI_TAG_VDEV_INSTALL_KEY_COMPLETE_EVENT]
114 		= { .min_len = sizeof(struct wmi_vdev_install_key_compl_event) },
115 	[WMI_TAG_READY_EVENT] = {
116 		.min_len = sizeof(struct wmi_ready_event_min) },
117 	[WMI_TAG_SERVICE_AVAILABLE_EVENT]
118 		= {.min_len = sizeof(struct wmi_service_available_event) },
119 	[WMI_TAG_PEER_ASSOC_CONF_EVENT]
120 		= { .min_len = sizeof(struct wmi_peer_assoc_conf_event) },
121 	[WMI_TAG_STATS_EVENT]
122 		= { .min_len = sizeof(struct wmi_stats_event) },
123 	[WMI_TAG_PDEV_CTL_FAILSAFE_CHECK_EVENT]
124 		= { .min_len = sizeof(struct wmi_pdev_ctl_failsafe_chk_event) },
125 	[WMI_TAG_HOST_SWFDA_EVENT] = {
126 		.min_len = sizeof(struct wmi_fils_discovery_event) },
127 	[WMI_TAG_OFFLOAD_PRB_RSP_TX_STATUS_EVENT] = {
128 		.min_len = sizeof(struct wmi_probe_resp_tx_status_event) },
129 	[WMI_TAG_VDEV_DELETE_RESP_EVENT] = {
130 		.min_len = sizeof(struct wmi_vdev_delete_resp_event) },
131 };
132 
133 #define PRIMAP(_hw_mode_) \
134 	[_hw_mode_] = _hw_mode_##_PRI
135 
136 static const int ath11k_hw_mode_pri_map[] = {
137 	PRIMAP(WMI_HOST_HW_MODE_SINGLE),
138 	PRIMAP(WMI_HOST_HW_MODE_DBS),
139 	PRIMAP(WMI_HOST_HW_MODE_SBS_PASSIVE),
140 	PRIMAP(WMI_HOST_HW_MODE_SBS),
141 	PRIMAP(WMI_HOST_HW_MODE_DBS_SBS),
142 	PRIMAP(WMI_HOST_HW_MODE_DBS_OR_SBS),
143 	/* keep last */
144 	PRIMAP(WMI_HOST_HW_MODE_MAX),
145 };
146 
147 static int
148 ath11k_wmi_tlv_iter(struct ath11k_base *ab, const void *ptr, size_t len,
149 		    int (*iter)(struct ath11k_base *ab, u16 tag, u16 len,
150 				const void *ptr, void *data),
151 		    void *data)
152 {
153 	const void *begin = ptr;
154 	const struct wmi_tlv *tlv;
155 	u16 tlv_tag, tlv_len;
156 	int ret;
157 
158 	while (len > 0) {
159 		if (len < sizeof(*tlv)) {
160 			ath11k_err(ab, "wmi tlv parse failure at byte %zd (%zu bytes left, %zu expected)\n",
161 				   ptr - begin, len, sizeof(*tlv));
162 			return -EINVAL;
163 		}
164 
165 		tlv = ptr;
166 		tlv_tag = FIELD_GET(WMI_TLV_TAG, tlv->header);
167 		tlv_len = FIELD_GET(WMI_TLV_LEN, tlv->header);
168 		ptr += sizeof(*tlv);
169 		len -= sizeof(*tlv);
170 
171 		if (tlv_len > len) {
172 			ath11k_err(ab, "wmi tlv parse failure of tag %u at byte %zd (%zu bytes left, %u expected)\n",
173 				   tlv_tag, ptr - begin, len, tlv_len);
174 			return -EINVAL;
175 		}
176 
177 		if (tlv_tag < ARRAY_SIZE(wmi_tlv_policies) &&
178 		    wmi_tlv_policies[tlv_tag].min_len &&
179 		    wmi_tlv_policies[tlv_tag].min_len > tlv_len) {
180 			ath11k_err(ab, "wmi tlv parse failure of tag %u at byte %zd (%u bytes is less than min length %zu)\n",
181 				   tlv_tag, ptr - begin, tlv_len,
182 				   wmi_tlv_policies[tlv_tag].min_len);
183 			return -EINVAL;
184 		}
185 
186 		ret = iter(ab, tlv_tag, tlv_len, ptr, data);
187 		if (ret)
188 			return ret;
189 
190 		ptr += tlv_len;
191 		len -= tlv_len;
192 	}
193 
194 	return 0;
195 }
196 
197 static int ath11k_wmi_tlv_iter_parse(struct ath11k_base *ab, u16 tag, u16 len,
198 				     const void *ptr, void *data)
199 {
200 	const void **tb = data;
201 
202 	if (tag < WMI_TAG_MAX)
203 		tb[tag] = ptr;
204 
205 	return 0;
206 }
207 
208 static int ath11k_wmi_tlv_parse(struct ath11k_base *ar, const void **tb,
209 				const void *ptr, size_t len)
210 {
211 	return ath11k_wmi_tlv_iter(ar, ptr, len, ath11k_wmi_tlv_iter_parse,
212 				   (void *)tb);
213 }
214 
215 static const void **
216 ath11k_wmi_tlv_parse_alloc(struct ath11k_base *ab, const void *ptr,
217 			   size_t len, gfp_t gfp)
218 {
219 	const void **tb;
220 	int ret;
221 
222 	tb = kcalloc(WMI_TAG_MAX, sizeof(*tb), gfp);
223 	if (!tb)
224 		return ERR_PTR(-ENOMEM);
225 
226 	ret = ath11k_wmi_tlv_parse(ab, tb, ptr, len);
227 	if (ret) {
228 		kfree(tb);
229 		return ERR_PTR(ret);
230 	}
231 
232 	return tb;
233 }
234 
235 static int ath11k_wmi_cmd_send_nowait(struct ath11k_pdev_wmi *wmi, struct sk_buff *skb,
236 				      u32 cmd_id)
237 {
238 	struct ath11k_skb_cb *skb_cb = ATH11K_SKB_CB(skb);
239 	struct ath11k_base *ab = wmi->wmi_ab->ab;
240 	struct wmi_cmd_hdr *cmd_hdr;
241 	int ret;
242 	u32 cmd = 0;
243 
244 	if (skb_push(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
245 		return -ENOMEM;
246 
247 	cmd |= FIELD_PREP(WMI_CMD_HDR_CMD_ID, cmd_id);
248 
249 	cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
250 	cmd_hdr->cmd_id = cmd;
251 
252 	memset(skb_cb, 0, sizeof(*skb_cb));
253 	ret = ath11k_htc_send(&ab->htc, wmi->eid, skb);
254 
255 	if (ret)
256 		goto err_pull;
257 
258 	return 0;
259 
260 err_pull:
261 	skb_pull(skb, sizeof(struct wmi_cmd_hdr));
262 	return ret;
263 }
264 
265 int ath11k_wmi_cmd_send(struct ath11k_pdev_wmi *wmi, struct sk_buff *skb,
266 			u32 cmd_id)
267 {
268 	struct ath11k_wmi_base *wmi_sc = wmi->wmi_ab;
269 	int ret = -EOPNOTSUPP;
270 
271 	might_sleep();
272 
273 	wait_event_timeout(wmi_sc->tx_credits_wq, ({
274 		ret = ath11k_wmi_cmd_send_nowait(wmi, skb, cmd_id);
275 
276 		if (ret && test_bit(ATH11K_FLAG_CRASH_FLUSH, &wmi_sc->ab->dev_flags))
277 			ret = -ESHUTDOWN;
278 
279 		(ret != -EAGAIN);
280 	}), WMI_SEND_TIMEOUT_HZ);
281 
282 	if (ret == -EAGAIN)
283 		ath11k_warn(wmi_sc->ab, "wmi command %d timeout\n", cmd_id);
284 
285 	return ret;
286 }
287 
288 static int ath11k_pull_svc_ready_ext(struct ath11k_pdev_wmi *wmi_handle,
289 				     const void *ptr,
290 				     struct ath11k_service_ext_param *param)
291 {
292 	const struct wmi_service_ready_ext_event *ev = ptr;
293 
294 	if (!ev)
295 		return -EINVAL;
296 
297 	/* Move this to host based bitmap */
298 	param->default_conc_scan_config_bits = ev->default_conc_scan_config_bits;
299 	param->default_fw_config_bits =	ev->default_fw_config_bits;
300 	param->he_cap_info = ev->he_cap_info;
301 	param->mpdu_density = ev->mpdu_density;
302 	param->max_bssid_rx_filters = ev->max_bssid_rx_filters;
303 	memcpy(&param->ppet, &ev->ppet, sizeof(param->ppet));
304 
305 	return 0;
306 }
307 
308 static int
309 ath11k_pull_mac_phy_cap_svc_ready_ext(struct ath11k_pdev_wmi *wmi_handle,
310 				      struct wmi_soc_mac_phy_hw_mode_caps *hw_caps,
311 				      struct wmi_hw_mode_capabilities *wmi_hw_mode_caps,
312 				      struct wmi_soc_hal_reg_capabilities *hal_reg_caps,
313 				      struct wmi_mac_phy_capabilities *wmi_mac_phy_caps,
314 				      u8 hw_mode_id, u8 phy_id,
315 				      struct ath11k_pdev *pdev)
316 {
317 	struct wmi_mac_phy_capabilities *mac_phy_caps;
318 	struct ath11k_band_cap *cap_band;
319 	struct ath11k_pdev_cap *pdev_cap = &pdev->cap;
320 	u32 phy_map;
321 	u32 hw_idx, phy_idx = 0;
322 
323 	if (!hw_caps || !wmi_hw_mode_caps || !hal_reg_caps)
324 		return -EINVAL;
325 
326 	for (hw_idx = 0; hw_idx < hw_caps->num_hw_modes; hw_idx++) {
327 		if (hw_mode_id == wmi_hw_mode_caps[hw_idx].hw_mode_id)
328 			break;
329 
330 		phy_map = wmi_hw_mode_caps[hw_idx].phy_id_map;
331 		while (phy_map) {
332 			phy_map >>= 1;
333 			phy_idx++;
334 		}
335 	}
336 
337 	if (hw_idx == hw_caps->num_hw_modes)
338 		return -EINVAL;
339 
340 	phy_idx += phy_id;
341 	if (phy_id >= hal_reg_caps->num_phy)
342 		return -EINVAL;
343 
344 	mac_phy_caps = wmi_mac_phy_caps + phy_idx;
345 
346 	pdev->pdev_id = mac_phy_caps->pdev_id;
347 	pdev_cap->supported_bands |= mac_phy_caps->supported_bands;
348 	pdev_cap->ampdu_density = mac_phy_caps->ampdu_density;
349 
350 	/* Take non-zero tx/rx chainmask. If tx/rx chainmask differs from
351 	 * band to band for a single radio, need to see how this should be
352 	 * handled.
353 	 */
354 	if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_2G_CAP) {
355 		pdev_cap->tx_chain_mask = mac_phy_caps->tx_chain_mask_2g;
356 		pdev_cap->rx_chain_mask = mac_phy_caps->rx_chain_mask_2g;
357 	} else if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_5G_CAP) {
358 		pdev_cap->vht_cap = mac_phy_caps->vht_cap_info_5g;
359 		pdev_cap->vht_mcs = mac_phy_caps->vht_supp_mcs_5g;
360 		pdev_cap->he_mcs = mac_phy_caps->he_supp_mcs_5g;
361 		pdev_cap->tx_chain_mask = mac_phy_caps->tx_chain_mask_5g;
362 		pdev_cap->rx_chain_mask = mac_phy_caps->rx_chain_mask_5g;
363 		pdev_cap->nss_ratio_enabled =
364 			WMI_NSS_RATIO_ENABLE_DISABLE_GET(mac_phy_caps->nss_ratio);
365 		pdev_cap->nss_ratio_info =
366 			WMI_NSS_RATIO_INFO_GET(mac_phy_caps->nss_ratio);
367 	} else {
368 		return -EINVAL;
369 	}
370 
371 	/* tx/rx chainmask reported from fw depends on the actual hw chains used,
372 	 * For example, for 4x4 capable macphys, first 4 chains can be used for first
373 	 * mac and the remaing 4 chains can be used for the second mac or vice-versa.
374 	 * In this case, tx/rx chainmask 0xf will be advertised for first mac and 0xf0
375 	 * will be advertised for second mac or vice-versa. Compute the shift value
376 	 * for tx/rx chainmask which will be used to advertise supported ht/vht rates to
377 	 * mac80211.
378 	 */
379 	pdev_cap->tx_chain_mask_shift =
380 			find_first_bit((unsigned long *)&pdev_cap->tx_chain_mask, 32);
381 	pdev_cap->rx_chain_mask_shift =
382 			find_first_bit((unsigned long *)&pdev_cap->rx_chain_mask, 32);
383 
384 	if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_2G_CAP) {
385 		cap_band = &pdev_cap->band[NL80211_BAND_2GHZ];
386 		cap_band->phy_id = mac_phy_caps->phy_id;
387 		cap_band->max_bw_supported = mac_phy_caps->max_bw_supported_2g;
388 		cap_band->ht_cap_info = mac_phy_caps->ht_cap_info_2g;
389 		cap_band->he_cap_info[0] = mac_phy_caps->he_cap_info_2g;
390 		cap_band->he_cap_info[1] = mac_phy_caps->he_cap_info_2g_ext;
391 		cap_band->he_mcs = mac_phy_caps->he_supp_mcs_2g;
392 		memcpy(cap_band->he_cap_phy_info, &mac_phy_caps->he_cap_phy_info_2g,
393 		       sizeof(u32) * PSOC_HOST_MAX_PHY_SIZE);
394 		memcpy(&cap_band->he_ppet, &mac_phy_caps->he_ppet2g,
395 		       sizeof(struct ath11k_ppe_threshold));
396 	}
397 
398 	if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_5G_CAP) {
399 		cap_band = &pdev_cap->band[NL80211_BAND_5GHZ];
400 		cap_band->phy_id = mac_phy_caps->phy_id;
401 		cap_band->max_bw_supported = mac_phy_caps->max_bw_supported_5g;
402 		cap_band->ht_cap_info = mac_phy_caps->ht_cap_info_5g;
403 		cap_band->he_cap_info[0] = mac_phy_caps->he_cap_info_5g;
404 		cap_band->he_cap_info[1] = mac_phy_caps->he_cap_info_5g_ext;
405 		cap_band->he_mcs = mac_phy_caps->he_supp_mcs_5g;
406 		memcpy(cap_band->he_cap_phy_info, &mac_phy_caps->he_cap_phy_info_5g,
407 		       sizeof(u32) * PSOC_HOST_MAX_PHY_SIZE);
408 		memcpy(&cap_band->he_ppet, &mac_phy_caps->he_ppet5g,
409 		       sizeof(struct ath11k_ppe_threshold));
410 
411 		cap_band = &pdev_cap->band[NL80211_BAND_6GHZ];
412 		cap_band->max_bw_supported = mac_phy_caps->max_bw_supported_5g;
413 		cap_band->ht_cap_info = mac_phy_caps->ht_cap_info_5g;
414 		cap_band->he_cap_info[0] = mac_phy_caps->he_cap_info_5g;
415 		cap_band->he_cap_info[1] = mac_phy_caps->he_cap_info_5g_ext;
416 		cap_band->he_mcs = mac_phy_caps->he_supp_mcs_5g;
417 		memcpy(cap_band->he_cap_phy_info, &mac_phy_caps->he_cap_phy_info_5g,
418 		       sizeof(u32) * PSOC_HOST_MAX_PHY_SIZE);
419 		memcpy(&cap_band->he_ppet, &mac_phy_caps->he_ppet5g,
420 		       sizeof(struct ath11k_ppe_threshold));
421 	}
422 
423 	return 0;
424 }
425 
426 static int
427 ath11k_pull_reg_cap_svc_rdy_ext(struct ath11k_pdev_wmi *wmi_handle,
428 				struct wmi_soc_hal_reg_capabilities *reg_caps,
429 				struct wmi_hal_reg_capabilities_ext *wmi_ext_reg_cap,
430 				u8 phy_idx,
431 				struct ath11k_hal_reg_capabilities_ext *param)
432 {
433 	struct wmi_hal_reg_capabilities_ext *ext_reg_cap;
434 
435 	if (!reg_caps || !wmi_ext_reg_cap)
436 		return -EINVAL;
437 
438 	if (phy_idx >= reg_caps->num_phy)
439 		return -EINVAL;
440 
441 	ext_reg_cap = &wmi_ext_reg_cap[phy_idx];
442 
443 	param->phy_id = ext_reg_cap->phy_id;
444 	param->eeprom_reg_domain = ext_reg_cap->eeprom_reg_domain;
445 	param->eeprom_reg_domain_ext =
446 			      ext_reg_cap->eeprom_reg_domain_ext;
447 	param->regcap1 = ext_reg_cap->regcap1;
448 	param->regcap2 = ext_reg_cap->regcap2;
449 	/* check if param->wireless_mode is needed */
450 	param->low_2ghz_chan = ext_reg_cap->low_2ghz_chan;
451 	param->high_2ghz_chan = ext_reg_cap->high_2ghz_chan;
452 	param->low_5ghz_chan = ext_reg_cap->low_5ghz_chan;
453 	param->high_5ghz_chan = ext_reg_cap->high_5ghz_chan;
454 
455 	return 0;
456 }
457 
458 static int ath11k_pull_service_ready_tlv(struct ath11k_base *ab,
459 					 const void *evt_buf,
460 					 struct ath11k_targ_cap *cap)
461 {
462 	const struct wmi_service_ready_event *ev = evt_buf;
463 
464 	if (!ev) {
465 		ath11k_err(ab, "%s: failed by NULL param\n",
466 			   __func__);
467 		return -EINVAL;
468 	}
469 
470 	cap->phy_capability = ev->phy_capability;
471 	cap->max_frag_entry = ev->max_frag_entry;
472 	cap->num_rf_chains = ev->num_rf_chains;
473 	cap->ht_cap_info = ev->ht_cap_info;
474 	cap->vht_cap_info = ev->vht_cap_info;
475 	cap->vht_supp_mcs = ev->vht_supp_mcs;
476 	cap->hw_min_tx_power = ev->hw_min_tx_power;
477 	cap->hw_max_tx_power = ev->hw_max_tx_power;
478 	cap->sys_cap_info = ev->sys_cap_info;
479 	cap->min_pkt_size_enable = ev->min_pkt_size_enable;
480 	cap->max_bcn_ie_size = ev->max_bcn_ie_size;
481 	cap->max_num_scan_channels = ev->max_num_scan_channels;
482 	cap->max_supported_macs = ev->max_supported_macs;
483 	cap->wmi_fw_sub_feat_caps = ev->wmi_fw_sub_feat_caps;
484 	cap->txrx_chainmask = ev->txrx_chainmask;
485 	cap->default_dbs_hw_mode_index = ev->default_dbs_hw_mode_index;
486 	cap->num_msdu_desc = ev->num_msdu_desc;
487 
488 	return 0;
489 }
490 
491 /* Save the wmi_service_bitmap into a linear bitmap. The wmi_services in
492  * wmi_service ready event are advertised in b0-b3 (LSB 4-bits) of each
493  * 4-byte word.
494  */
495 static void ath11k_wmi_service_bitmap_copy(struct ath11k_pdev_wmi *wmi,
496 					   const u32 *wmi_svc_bm)
497 {
498 	int i, j;
499 
500 	for (i = 0, j = 0; i < WMI_SERVICE_BM_SIZE && j < WMI_MAX_SERVICE; i++) {
501 		do {
502 			if (wmi_svc_bm[i] & BIT(j % WMI_SERVICE_BITS_IN_SIZE32))
503 				set_bit(j, wmi->wmi_ab->svc_map);
504 		} while (++j % WMI_SERVICE_BITS_IN_SIZE32);
505 	}
506 }
507 
508 static int ath11k_wmi_tlv_svc_rdy_parse(struct ath11k_base *ab, u16 tag, u16 len,
509 					const void *ptr, void *data)
510 {
511 	struct wmi_tlv_svc_ready_parse *svc_ready = data;
512 	struct ath11k_pdev_wmi *wmi_handle = &ab->wmi_ab.wmi[0];
513 	u16 expect_len;
514 
515 	switch (tag) {
516 	case WMI_TAG_SERVICE_READY_EVENT:
517 		if (ath11k_pull_service_ready_tlv(ab, ptr, &ab->target_caps))
518 			return -EINVAL;
519 		break;
520 
521 	case WMI_TAG_ARRAY_UINT32:
522 		if (!svc_ready->wmi_svc_bitmap_done) {
523 			expect_len = WMI_SERVICE_BM_SIZE * sizeof(u32);
524 			if (len < expect_len) {
525 				ath11k_warn(ab, "invalid len %d for the tag 0x%x\n",
526 					    len, tag);
527 				return -EINVAL;
528 			}
529 
530 			ath11k_wmi_service_bitmap_copy(wmi_handle, ptr);
531 
532 			svc_ready->wmi_svc_bitmap_done = true;
533 		}
534 		break;
535 	default:
536 		break;
537 	}
538 
539 	return 0;
540 }
541 
542 static int ath11k_service_ready_event(struct ath11k_base *ab, struct sk_buff *skb)
543 {
544 	struct wmi_tlv_svc_ready_parse svc_ready = { };
545 	int ret;
546 
547 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
548 				  ath11k_wmi_tlv_svc_rdy_parse,
549 				  &svc_ready);
550 	if (ret) {
551 		ath11k_warn(ab, "failed to parse tlv %d\n", ret);
552 		return ret;
553 	}
554 
555 	return 0;
556 }
557 
558 struct sk_buff *ath11k_wmi_alloc_skb(struct ath11k_wmi_base *wmi_sc, u32 len)
559 {
560 	struct sk_buff *skb;
561 	struct ath11k_base *ab = wmi_sc->ab;
562 	u32 round_len = roundup(len, 4);
563 
564 	skb = ath11k_htc_alloc_skb(ab, WMI_SKB_HEADROOM + round_len);
565 	if (!skb)
566 		return NULL;
567 
568 	skb_reserve(skb, WMI_SKB_HEADROOM);
569 	if (!IS_ALIGNED((unsigned long)skb->data, 4))
570 		ath11k_warn(ab, "unaligned WMI skb data\n");
571 
572 	skb_put(skb, round_len);
573 	memset(skb->data, 0, round_len);
574 
575 	return skb;
576 }
577 
578 int ath11k_wmi_mgmt_send(struct ath11k *ar, u32 vdev_id, u32 buf_id,
579 			 struct sk_buff *frame)
580 {
581 	struct ath11k_pdev_wmi *wmi = ar->wmi;
582 	struct wmi_mgmt_send_cmd *cmd;
583 	struct wmi_tlv *frame_tlv;
584 	struct sk_buff *skb;
585 	u32 buf_len;
586 	int ret, len;
587 
588 	buf_len = frame->len < WMI_MGMT_SEND_DOWNLD_LEN ?
589 		  frame->len : WMI_MGMT_SEND_DOWNLD_LEN;
590 
591 	len = sizeof(*cmd) + sizeof(*frame_tlv) + roundup(buf_len, 4);
592 
593 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
594 	if (!skb)
595 		return -ENOMEM;
596 
597 	cmd = (struct wmi_mgmt_send_cmd *)skb->data;
598 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_MGMT_TX_SEND_CMD) |
599 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
600 	cmd->vdev_id = vdev_id;
601 	cmd->desc_id = buf_id;
602 	cmd->chanfreq = 0;
603 	cmd->paddr_lo = lower_32_bits(ATH11K_SKB_CB(frame)->paddr);
604 	cmd->paddr_hi = upper_32_bits(ATH11K_SKB_CB(frame)->paddr);
605 	cmd->frame_len = frame->len;
606 	cmd->buf_len = buf_len;
607 	cmd->tx_params_valid = 0;
608 
609 	frame_tlv = (struct wmi_tlv *)(skb->data + sizeof(*cmd));
610 	frame_tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
611 			    FIELD_PREP(WMI_TLV_LEN, buf_len);
612 
613 	memcpy(frame_tlv->value, frame->data, buf_len);
614 
615 	ath11k_ce_byte_swap(frame_tlv->value, buf_len);
616 
617 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_MGMT_TX_SEND_CMDID);
618 	if (ret) {
619 		ath11k_warn(ar->ab,
620 			    "failed to submit WMI_MGMT_TX_SEND_CMDID cmd\n");
621 		dev_kfree_skb(skb);
622 	}
623 
624 	return ret;
625 }
626 
627 int ath11k_wmi_vdev_create(struct ath11k *ar, u8 *macaddr,
628 			   struct vdev_create_params *param)
629 {
630 	struct ath11k_pdev_wmi *wmi = ar->wmi;
631 	struct wmi_vdev_create_cmd *cmd;
632 	struct sk_buff *skb;
633 	struct wmi_vdev_txrx_streams *txrx_streams;
634 	struct wmi_tlv *tlv;
635 	int ret, len;
636 	void *ptr;
637 
638 	/* It can be optimized my sending tx/rx chain configuration
639 	 * only for supported bands instead of always sending it for
640 	 * both the bands.
641 	 */
642 	len = sizeof(*cmd) + TLV_HDR_SIZE +
643 		(WMI_NUM_SUPPORTED_BAND_MAX * sizeof(*txrx_streams));
644 
645 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
646 	if (!skb)
647 		return -ENOMEM;
648 
649 	cmd = (struct wmi_vdev_create_cmd *)skb->data;
650 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_CREATE_CMD) |
651 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
652 
653 	cmd->vdev_id = param->if_id;
654 	cmd->vdev_type = param->type;
655 	cmd->vdev_subtype = param->subtype;
656 	cmd->num_cfg_txrx_streams = WMI_NUM_SUPPORTED_BAND_MAX;
657 	cmd->pdev_id = param->pdev_id;
658 	ether_addr_copy(cmd->vdev_macaddr.addr, macaddr);
659 
660 	ptr = skb->data + sizeof(*cmd);
661 	len = WMI_NUM_SUPPORTED_BAND_MAX * sizeof(*txrx_streams);
662 
663 	tlv = ptr;
664 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
665 		      FIELD_PREP(WMI_TLV_LEN, len);
666 
667 	ptr += TLV_HDR_SIZE;
668 	txrx_streams = ptr;
669 	len = sizeof(*txrx_streams);
670 	txrx_streams->tlv_header =
671 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_TXRX_STREAMS) |
672 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
673 	txrx_streams->band = WMI_TPC_CHAINMASK_CONFIG_BAND_2G;
674 	txrx_streams->supported_tx_streams =
675 				 param->chains[NL80211_BAND_2GHZ].tx;
676 	txrx_streams->supported_rx_streams =
677 				 param->chains[NL80211_BAND_2GHZ].rx;
678 
679 	txrx_streams++;
680 	txrx_streams->tlv_header =
681 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_TXRX_STREAMS) |
682 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
683 	txrx_streams->band = WMI_TPC_CHAINMASK_CONFIG_BAND_5G;
684 	txrx_streams->supported_tx_streams =
685 				 param->chains[NL80211_BAND_5GHZ].tx;
686 	txrx_streams->supported_rx_streams =
687 				 param->chains[NL80211_BAND_5GHZ].rx;
688 
689 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_CREATE_CMDID);
690 	if (ret) {
691 		ath11k_warn(ar->ab,
692 			    "failed to submit WMI_VDEV_CREATE_CMDID\n");
693 		dev_kfree_skb(skb);
694 	}
695 
696 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
697 		   "WMI vdev create: id %d type %d subtype %d macaddr %pM pdevid %d\n",
698 		   param->if_id, param->type, param->subtype,
699 		   macaddr, param->pdev_id);
700 
701 	return ret;
702 }
703 
704 int ath11k_wmi_vdev_delete(struct ath11k *ar, u8 vdev_id)
705 {
706 	struct ath11k_pdev_wmi *wmi = ar->wmi;
707 	struct wmi_vdev_delete_cmd *cmd;
708 	struct sk_buff *skb;
709 	int ret;
710 
711 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
712 	if (!skb)
713 		return -ENOMEM;
714 
715 	cmd = (struct wmi_vdev_delete_cmd *)skb->data;
716 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_DELETE_CMD) |
717 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
718 	cmd->vdev_id = vdev_id;
719 
720 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_DELETE_CMDID);
721 	if (ret) {
722 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_DELETE_CMDID\n");
723 		dev_kfree_skb(skb);
724 	}
725 
726 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "WMI vdev delete id %d\n", vdev_id);
727 
728 	return ret;
729 }
730 
731 int ath11k_wmi_vdev_stop(struct ath11k *ar, u8 vdev_id)
732 {
733 	struct ath11k_pdev_wmi *wmi = ar->wmi;
734 	struct wmi_vdev_stop_cmd *cmd;
735 	struct sk_buff *skb;
736 	int ret;
737 
738 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
739 	if (!skb)
740 		return -ENOMEM;
741 
742 	cmd = (struct wmi_vdev_stop_cmd *)skb->data;
743 
744 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_STOP_CMD) |
745 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
746 	cmd->vdev_id = vdev_id;
747 
748 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_STOP_CMDID);
749 	if (ret) {
750 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_STOP cmd\n");
751 		dev_kfree_skb(skb);
752 	}
753 
754 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "WMI vdev stop id 0x%x\n", vdev_id);
755 
756 	return ret;
757 }
758 
759 int ath11k_wmi_vdev_down(struct ath11k *ar, u8 vdev_id)
760 {
761 	struct ath11k_pdev_wmi *wmi = ar->wmi;
762 	struct wmi_vdev_down_cmd *cmd;
763 	struct sk_buff *skb;
764 	int ret;
765 
766 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
767 	if (!skb)
768 		return -ENOMEM;
769 
770 	cmd = (struct wmi_vdev_down_cmd *)skb->data;
771 
772 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_DOWN_CMD) |
773 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
774 	cmd->vdev_id = vdev_id;
775 
776 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_DOWN_CMDID);
777 	if (ret) {
778 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_DOWN cmd\n");
779 		dev_kfree_skb(skb);
780 	}
781 
782 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "WMI vdev down id 0x%x\n", vdev_id);
783 
784 	return ret;
785 }
786 
787 static void ath11k_wmi_put_wmi_channel(struct wmi_channel *chan,
788 				       struct wmi_vdev_start_req_arg *arg)
789 {
790 	u32 center_freq1 = arg->channel.band_center_freq1;
791 
792 	memset(chan, 0, sizeof(*chan));
793 
794 	chan->mhz = arg->channel.freq;
795 	chan->band_center_freq1 = arg->channel.band_center_freq1;
796 
797 	if (arg->channel.mode == MODE_11AX_HE160) {
798 		if (arg->channel.freq > arg->channel.band_center_freq1)
799 			chan->band_center_freq1 = center_freq1 + 40;
800 		else
801 			chan->band_center_freq1 = center_freq1 - 40;
802 
803 		chan->band_center_freq2 = arg->channel.band_center_freq1;
804 
805 	} else if (arg->channel.mode == MODE_11AC_VHT80_80) {
806 		chan->band_center_freq2 = arg->channel.band_center_freq2;
807 	} else {
808 		chan->band_center_freq2 = 0;
809 	}
810 
811 	chan->info |= FIELD_PREP(WMI_CHAN_INFO_MODE, arg->channel.mode);
812 	if (arg->channel.passive)
813 		chan->info |= WMI_CHAN_INFO_PASSIVE;
814 	if (arg->channel.allow_ibss)
815 		chan->info |= WMI_CHAN_INFO_ADHOC_ALLOWED;
816 	if (arg->channel.allow_ht)
817 		chan->info |= WMI_CHAN_INFO_ALLOW_HT;
818 	if (arg->channel.allow_vht)
819 		chan->info |= WMI_CHAN_INFO_ALLOW_VHT;
820 	if (arg->channel.allow_he)
821 		chan->info |= WMI_CHAN_INFO_ALLOW_HE;
822 	if (arg->channel.ht40plus)
823 		chan->info |= WMI_CHAN_INFO_HT40_PLUS;
824 	if (arg->channel.chan_radar)
825 		chan->info |= WMI_CHAN_INFO_DFS;
826 	if (arg->channel.freq2_radar)
827 		chan->info |= WMI_CHAN_INFO_DFS_FREQ2;
828 
829 	chan->reg_info_1 = FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_PWR,
830 				      arg->channel.max_power) |
831 		FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_REG_PWR,
832 			   arg->channel.max_reg_power);
833 
834 	chan->reg_info_2 = FIELD_PREP(WMI_CHAN_REG_INFO2_ANT_MAX,
835 				      arg->channel.max_antenna_gain) |
836 		FIELD_PREP(WMI_CHAN_REG_INFO2_MAX_TX_PWR,
837 			   arg->channel.max_power);
838 }
839 
840 int ath11k_wmi_vdev_start(struct ath11k *ar, struct wmi_vdev_start_req_arg *arg,
841 			  bool restart)
842 {
843 	struct ath11k_pdev_wmi *wmi = ar->wmi;
844 	struct wmi_vdev_start_request_cmd *cmd;
845 	struct sk_buff *skb;
846 	struct wmi_channel *chan;
847 	struct wmi_tlv *tlv;
848 	void *ptr;
849 	int ret, len;
850 
851 	if (WARN_ON(arg->ssid_len > sizeof(cmd->ssid.ssid)))
852 		return -EINVAL;
853 
854 	len = sizeof(*cmd) + sizeof(*chan) + TLV_HDR_SIZE;
855 
856 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
857 	if (!skb)
858 		return -ENOMEM;
859 
860 	cmd = (struct wmi_vdev_start_request_cmd *)skb->data;
861 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
862 				     WMI_TAG_VDEV_START_REQUEST_CMD) |
863 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
864 	cmd->vdev_id = arg->vdev_id;
865 	cmd->beacon_interval = arg->bcn_intval;
866 	cmd->bcn_tx_rate = arg->bcn_tx_rate;
867 	cmd->dtim_period = arg->dtim_period;
868 	cmd->num_noa_descriptors = arg->num_noa_descriptors;
869 	cmd->preferred_rx_streams = arg->pref_rx_streams;
870 	cmd->preferred_tx_streams = arg->pref_tx_streams;
871 	cmd->cac_duration_ms = arg->cac_duration_ms;
872 	cmd->regdomain = arg->regdomain;
873 	cmd->he_ops = arg->he_ops;
874 
875 	if (!restart) {
876 		if (arg->ssid) {
877 			cmd->ssid.ssid_len = arg->ssid_len;
878 			memcpy(cmd->ssid.ssid, arg->ssid, arg->ssid_len);
879 		}
880 		if (arg->hidden_ssid)
881 			cmd->flags |= WMI_VDEV_START_HIDDEN_SSID;
882 		if (arg->pmf_enabled)
883 			cmd->flags |= WMI_VDEV_START_PMF_ENABLED;
884 	}
885 
886 	cmd->flags |= WMI_VDEV_START_LDPC_RX_ENABLED;
887 	if (test_bit(ATH11K_FLAG_HW_CRYPTO_DISABLED, &ar->ab->dev_flags))
888 		cmd->flags |= WMI_VDEV_START_HW_ENCRYPTION_DISABLED;
889 
890 	ptr = skb->data + sizeof(*cmd);
891 	chan = ptr;
892 
893 	ath11k_wmi_put_wmi_channel(chan, arg);
894 
895 	chan->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_CHANNEL) |
896 			   FIELD_PREP(WMI_TLV_LEN,
897 				      sizeof(*chan) - TLV_HDR_SIZE);
898 	ptr += sizeof(*chan);
899 
900 	tlv = ptr;
901 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
902 		      FIELD_PREP(WMI_TLV_LEN, 0);
903 
904 	/* Note: This is a nested TLV containing:
905 	 * [wmi_tlv][wmi_p2p_noa_descriptor][wmi_tlv]..
906 	 */
907 
908 	ptr += sizeof(*tlv);
909 
910 	if (restart)
911 		ret = ath11k_wmi_cmd_send(wmi, skb,
912 					  WMI_VDEV_RESTART_REQUEST_CMDID);
913 	else
914 		ret = ath11k_wmi_cmd_send(wmi, skb,
915 					  WMI_VDEV_START_REQUEST_CMDID);
916 	if (ret) {
917 		ath11k_warn(ar->ab, "failed to submit vdev_%s cmd\n",
918 			    restart ? "restart" : "start");
919 		dev_kfree_skb(skb);
920 	}
921 
922 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "vdev %s id 0x%x freq 0x%x mode 0x%x\n",
923 		   restart ? "restart" : "start", arg->vdev_id,
924 		   arg->channel.freq, arg->channel.mode);
925 
926 	return ret;
927 }
928 
929 int ath11k_wmi_vdev_up(struct ath11k *ar, u32 vdev_id, u32 aid, const u8 *bssid)
930 {
931 	struct ath11k_pdev_wmi *wmi = ar->wmi;
932 	struct wmi_vdev_up_cmd *cmd;
933 	struct sk_buff *skb;
934 	int ret;
935 
936 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
937 	if (!skb)
938 		return -ENOMEM;
939 
940 	cmd = (struct wmi_vdev_up_cmd *)skb->data;
941 
942 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_UP_CMD) |
943 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
944 	cmd->vdev_id = vdev_id;
945 	cmd->vdev_assoc_id = aid;
946 
947 	ether_addr_copy(cmd->vdev_bssid.addr, bssid);
948 
949 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_UP_CMDID);
950 	if (ret) {
951 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_UP cmd\n");
952 		dev_kfree_skb(skb);
953 	}
954 
955 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
956 		   "WMI mgmt vdev up id 0x%x assoc id %d bssid %pM\n",
957 		   vdev_id, aid, bssid);
958 
959 	return ret;
960 }
961 
962 int ath11k_wmi_send_peer_create_cmd(struct ath11k *ar,
963 				    struct peer_create_params *param)
964 {
965 	struct ath11k_pdev_wmi *wmi = ar->wmi;
966 	struct wmi_peer_create_cmd *cmd;
967 	struct sk_buff *skb;
968 	int ret;
969 
970 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
971 	if (!skb)
972 		return -ENOMEM;
973 
974 	cmd = (struct wmi_peer_create_cmd *)skb->data;
975 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_CREATE_CMD) |
976 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
977 
978 	ether_addr_copy(cmd->peer_macaddr.addr, param->peer_addr);
979 	cmd->peer_type = param->peer_type;
980 	cmd->vdev_id = param->vdev_id;
981 
982 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_CREATE_CMDID);
983 	if (ret) {
984 		ath11k_warn(ar->ab, "failed to submit WMI_PEER_CREATE cmd\n");
985 		dev_kfree_skb(skb);
986 	}
987 
988 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
989 		   "WMI peer create vdev_id %d peer_addr %pM\n",
990 		   param->vdev_id, param->peer_addr);
991 
992 	return ret;
993 }
994 
995 int ath11k_wmi_send_peer_delete_cmd(struct ath11k *ar,
996 				    const u8 *peer_addr, u8 vdev_id)
997 {
998 	struct ath11k_pdev_wmi *wmi = ar->wmi;
999 	struct wmi_peer_delete_cmd *cmd;
1000 	struct sk_buff *skb;
1001 	int ret;
1002 
1003 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1004 	if (!skb)
1005 		return -ENOMEM;
1006 
1007 	cmd = (struct wmi_peer_delete_cmd *)skb->data;
1008 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_DELETE_CMD) |
1009 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1010 
1011 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1012 	cmd->vdev_id = vdev_id;
1013 
1014 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1015 		   "WMI peer delete vdev_id %d peer_addr %pM\n",
1016 		   vdev_id,  peer_addr);
1017 
1018 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_DELETE_CMDID);
1019 	if (ret) {
1020 		ath11k_warn(ar->ab, "failed to send WMI_PEER_DELETE cmd\n");
1021 		dev_kfree_skb(skb);
1022 	}
1023 
1024 	return ret;
1025 }
1026 
1027 int ath11k_wmi_send_pdev_set_regdomain(struct ath11k *ar,
1028 				       struct pdev_set_regdomain_params *param)
1029 {
1030 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1031 	struct wmi_pdev_set_regdomain_cmd *cmd;
1032 	struct sk_buff *skb;
1033 	int ret;
1034 
1035 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1036 	if (!skb)
1037 		return -ENOMEM;
1038 
1039 	cmd = (struct wmi_pdev_set_regdomain_cmd *)skb->data;
1040 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1041 				     WMI_TAG_PDEV_SET_REGDOMAIN_CMD) |
1042 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1043 
1044 	cmd->reg_domain = param->current_rd_in_use;
1045 	cmd->reg_domain_2g = param->current_rd_2g;
1046 	cmd->reg_domain_5g = param->current_rd_5g;
1047 	cmd->conformance_test_limit_2g = param->ctl_2g;
1048 	cmd->conformance_test_limit_5g = param->ctl_5g;
1049 	cmd->dfs_domain = param->dfs_domain;
1050 	cmd->pdev_id = param->pdev_id;
1051 
1052 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1053 		   "WMI pdev regd rd %d rd2g %d rd5g %d domain %d pdev id %d\n",
1054 		   param->current_rd_in_use, param->current_rd_2g,
1055 		   param->current_rd_5g, param->dfs_domain, param->pdev_id);
1056 
1057 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_SET_REGDOMAIN_CMDID);
1058 	if (ret) {
1059 		ath11k_warn(ar->ab,
1060 			    "failed to send WMI_PDEV_SET_REGDOMAIN cmd\n");
1061 		dev_kfree_skb(skb);
1062 	}
1063 
1064 	return ret;
1065 }
1066 
1067 int ath11k_wmi_set_peer_param(struct ath11k *ar, const u8 *peer_addr,
1068 			      u32 vdev_id, u32 param_id, u32 param_val)
1069 {
1070 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1071 	struct wmi_peer_set_param_cmd *cmd;
1072 	struct sk_buff *skb;
1073 	int ret;
1074 
1075 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1076 	if (!skb)
1077 		return -ENOMEM;
1078 
1079 	cmd = (struct wmi_peer_set_param_cmd *)skb->data;
1080 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_SET_PARAM_CMD) |
1081 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1082 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1083 	cmd->vdev_id = vdev_id;
1084 	cmd->param_id = param_id;
1085 	cmd->param_value = param_val;
1086 
1087 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_SET_PARAM_CMDID);
1088 	if (ret) {
1089 		ath11k_warn(ar->ab, "failed to send WMI_PEER_SET_PARAM cmd\n");
1090 		dev_kfree_skb(skb);
1091 	}
1092 
1093 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1094 		   "WMI vdev %d peer 0x%pM set param %d value %d\n",
1095 		   vdev_id, peer_addr, param_id, param_val);
1096 
1097 	return ret;
1098 }
1099 
1100 int ath11k_wmi_send_peer_flush_tids_cmd(struct ath11k *ar,
1101 					u8 peer_addr[ETH_ALEN],
1102 					struct peer_flush_params *param)
1103 {
1104 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1105 	struct wmi_peer_flush_tids_cmd *cmd;
1106 	struct sk_buff *skb;
1107 	int ret;
1108 
1109 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1110 	if (!skb)
1111 		return -ENOMEM;
1112 
1113 	cmd = (struct wmi_peer_flush_tids_cmd *)skb->data;
1114 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_FLUSH_TIDS_CMD) |
1115 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1116 
1117 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1118 	cmd->peer_tid_bitmap = param->peer_tid_bitmap;
1119 	cmd->vdev_id = param->vdev_id;
1120 
1121 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_FLUSH_TIDS_CMDID);
1122 	if (ret) {
1123 		ath11k_warn(ar->ab,
1124 			    "failed to send WMI_PEER_FLUSH_TIDS cmd\n");
1125 		dev_kfree_skb(skb);
1126 	}
1127 
1128 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1129 		   "WMI peer flush vdev_id %d peer_addr %pM tids %08x\n",
1130 		   param->vdev_id, peer_addr, param->peer_tid_bitmap);
1131 
1132 	return ret;
1133 }
1134 
1135 int ath11k_wmi_peer_rx_reorder_queue_setup(struct ath11k *ar,
1136 					   int vdev_id, const u8 *addr,
1137 					   dma_addr_t paddr, u8 tid,
1138 					   u8 ba_window_size_valid,
1139 					   u32 ba_window_size)
1140 {
1141 	struct wmi_peer_reorder_queue_setup_cmd *cmd;
1142 	struct sk_buff *skb;
1143 	int ret;
1144 
1145 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
1146 	if (!skb)
1147 		return -ENOMEM;
1148 
1149 	cmd = (struct wmi_peer_reorder_queue_setup_cmd *)skb->data;
1150 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1151 				     WMI_TAG_REORDER_QUEUE_SETUP_CMD) |
1152 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1153 
1154 	ether_addr_copy(cmd->peer_macaddr.addr, addr);
1155 	cmd->vdev_id = vdev_id;
1156 	cmd->tid = tid;
1157 	cmd->queue_ptr_lo = lower_32_bits(paddr);
1158 	cmd->queue_ptr_hi = upper_32_bits(paddr);
1159 	cmd->queue_no = tid;
1160 	cmd->ba_window_size_valid = ba_window_size_valid;
1161 	cmd->ba_window_size = ba_window_size;
1162 
1163 	ret = ath11k_wmi_cmd_send(ar->wmi, skb,
1164 				  WMI_PEER_REORDER_QUEUE_SETUP_CMDID);
1165 	if (ret) {
1166 		ath11k_warn(ar->ab,
1167 			    "failed to send WMI_PEER_REORDER_QUEUE_SETUP\n");
1168 		dev_kfree_skb(skb);
1169 	}
1170 
1171 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1172 		   "wmi rx reorder queue setup addr %pM vdev_id %d tid %d\n",
1173 		   addr, vdev_id, tid);
1174 
1175 	return ret;
1176 }
1177 
1178 int
1179 ath11k_wmi_rx_reord_queue_remove(struct ath11k *ar,
1180 				 struct rx_reorder_queue_remove_params *param)
1181 {
1182 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1183 	struct wmi_peer_reorder_queue_remove_cmd *cmd;
1184 	struct sk_buff *skb;
1185 	int ret;
1186 
1187 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1188 	if (!skb)
1189 		return -ENOMEM;
1190 
1191 	cmd = (struct wmi_peer_reorder_queue_remove_cmd *)skb->data;
1192 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1193 				     WMI_TAG_REORDER_QUEUE_REMOVE_CMD) |
1194 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1195 
1196 	ether_addr_copy(cmd->peer_macaddr.addr, param->peer_macaddr);
1197 	cmd->vdev_id = param->vdev_id;
1198 	cmd->tid_mask = param->peer_tid_bitmap;
1199 
1200 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1201 		   "%s: peer_macaddr %pM vdev_id %d, tid_map %d", __func__,
1202 		   param->peer_macaddr, param->vdev_id, param->peer_tid_bitmap);
1203 
1204 	ret = ath11k_wmi_cmd_send(wmi, skb,
1205 				  WMI_PEER_REORDER_QUEUE_REMOVE_CMDID);
1206 	if (ret) {
1207 		ath11k_warn(ar->ab,
1208 			    "failed to send WMI_PEER_REORDER_QUEUE_REMOVE_CMDID");
1209 		dev_kfree_skb(skb);
1210 	}
1211 
1212 	return ret;
1213 }
1214 
1215 int ath11k_wmi_pdev_set_param(struct ath11k *ar, u32 param_id,
1216 			      u32 param_value, u8 pdev_id)
1217 {
1218 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1219 	struct wmi_pdev_set_param_cmd *cmd;
1220 	struct sk_buff *skb;
1221 	int ret;
1222 
1223 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1224 	if (!skb)
1225 		return -ENOMEM;
1226 
1227 	cmd = (struct wmi_pdev_set_param_cmd *)skb->data;
1228 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_SET_PARAM_CMD) |
1229 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1230 	cmd->pdev_id = pdev_id;
1231 	cmd->param_id = param_id;
1232 	cmd->param_value = param_value;
1233 
1234 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_SET_PARAM_CMDID);
1235 	if (ret) {
1236 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_SET_PARAM cmd\n");
1237 		dev_kfree_skb(skb);
1238 	}
1239 
1240 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1241 		   "WMI pdev set param %d pdev id %d value %d\n",
1242 		   param_id, pdev_id, param_value);
1243 
1244 	return ret;
1245 }
1246 
1247 int ath11k_wmi_pdev_set_ps_mode(struct ath11k *ar, int vdev_id, u32 enable)
1248 {
1249 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1250 	struct wmi_pdev_set_ps_mode_cmd *cmd;
1251 	struct sk_buff *skb;
1252 	int ret;
1253 
1254 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1255 	if (!skb)
1256 		return -ENOMEM;
1257 
1258 	cmd = (struct wmi_pdev_set_ps_mode_cmd *)skb->data;
1259 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_STA_POWERSAVE_MODE_CMD) |
1260 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1261 	cmd->vdev_id = vdev_id;
1262 	cmd->sta_ps_mode = enable;
1263 
1264 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_STA_POWERSAVE_MODE_CMDID);
1265 	if (ret) {
1266 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_SET_PARAM cmd\n");
1267 		dev_kfree_skb(skb);
1268 	}
1269 
1270 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1271 		   "WMI vdev set psmode %d vdev id %d\n",
1272 		   enable, vdev_id);
1273 
1274 	return ret;
1275 }
1276 
1277 int ath11k_wmi_pdev_suspend(struct ath11k *ar, u32 suspend_opt,
1278 			    u32 pdev_id)
1279 {
1280 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1281 	struct wmi_pdev_suspend_cmd *cmd;
1282 	struct sk_buff *skb;
1283 	int ret;
1284 
1285 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1286 	if (!skb)
1287 		return -ENOMEM;
1288 
1289 	cmd = (struct wmi_pdev_suspend_cmd *)skb->data;
1290 
1291 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_SUSPEND_CMD) |
1292 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1293 
1294 	cmd->suspend_opt = suspend_opt;
1295 	cmd->pdev_id = pdev_id;
1296 
1297 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_SUSPEND_CMDID);
1298 	if (ret) {
1299 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_SUSPEND cmd\n");
1300 		dev_kfree_skb(skb);
1301 	}
1302 
1303 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1304 		   "WMI pdev suspend pdev_id %d\n", pdev_id);
1305 
1306 	return ret;
1307 }
1308 
1309 int ath11k_wmi_pdev_resume(struct ath11k *ar, u32 pdev_id)
1310 {
1311 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1312 	struct wmi_pdev_resume_cmd *cmd;
1313 	struct sk_buff *skb;
1314 	int ret;
1315 
1316 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1317 	if (!skb)
1318 		return -ENOMEM;
1319 
1320 	cmd = (struct wmi_pdev_resume_cmd *)skb->data;
1321 
1322 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_RESUME_CMD) |
1323 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1324 	cmd->pdev_id = pdev_id;
1325 
1326 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1327 		   "WMI pdev resume pdev id %d\n", pdev_id);
1328 
1329 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_RESUME_CMDID);
1330 	if (ret) {
1331 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_RESUME cmd\n");
1332 		dev_kfree_skb(skb);
1333 	}
1334 
1335 	return ret;
1336 }
1337 
1338 /* TODO FW Support for the cmd is not available yet.
1339  * Can be tested once the command and corresponding
1340  * event is implemented in FW
1341  */
1342 int ath11k_wmi_pdev_bss_chan_info_request(struct ath11k *ar,
1343 					  enum wmi_bss_chan_info_req_type type)
1344 {
1345 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1346 	struct wmi_pdev_bss_chan_info_req_cmd *cmd;
1347 	struct sk_buff *skb;
1348 	int ret;
1349 
1350 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1351 	if (!skb)
1352 		return -ENOMEM;
1353 
1354 	cmd = (struct wmi_pdev_bss_chan_info_req_cmd *)skb->data;
1355 
1356 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1357 				     WMI_TAG_PDEV_BSS_CHAN_INFO_REQUEST) |
1358 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1359 	cmd->req_type = type;
1360 	cmd->pdev_id = ar->pdev->pdev_id;
1361 
1362 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1363 		   "WMI bss chan info req type %d\n", type);
1364 
1365 	ret = ath11k_wmi_cmd_send(wmi, skb,
1366 				  WMI_PDEV_BSS_CHAN_INFO_REQUEST_CMDID);
1367 	if (ret) {
1368 		ath11k_warn(ar->ab,
1369 			    "failed to send WMI_PDEV_BSS_CHAN_INFO_REQUEST cmd\n");
1370 		dev_kfree_skb(skb);
1371 	}
1372 
1373 	return ret;
1374 }
1375 
1376 int ath11k_wmi_send_set_ap_ps_param_cmd(struct ath11k *ar, u8 *peer_addr,
1377 					struct ap_ps_params *param)
1378 {
1379 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1380 	struct wmi_ap_ps_peer_cmd *cmd;
1381 	struct sk_buff *skb;
1382 	int ret;
1383 
1384 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1385 	if (!skb)
1386 		return -ENOMEM;
1387 
1388 	cmd = (struct wmi_ap_ps_peer_cmd *)skb->data;
1389 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_AP_PS_PEER_CMD) |
1390 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1391 
1392 	cmd->vdev_id = param->vdev_id;
1393 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1394 	cmd->param = param->param;
1395 	cmd->value = param->value;
1396 
1397 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_AP_PS_PEER_PARAM_CMDID);
1398 	if (ret) {
1399 		ath11k_warn(ar->ab,
1400 			    "failed to send WMI_AP_PS_PEER_PARAM_CMDID\n");
1401 		dev_kfree_skb(skb);
1402 	}
1403 
1404 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1405 		   "WMI set ap ps vdev id %d peer %pM param %d value %d\n",
1406 		   param->vdev_id, peer_addr, param->param, param->value);
1407 
1408 	return ret;
1409 }
1410 
1411 int ath11k_wmi_set_sta_ps_param(struct ath11k *ar, u32 vdev_id,
1412 				u32 param, u32 param_value)
1413 {
1414 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1415 	struct wmi_sta_powersave_param_cmd *cmd;
1416 	struct sk_buff *skb;
1417 	int ret;
1418 
1419 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1420 	if (!skb)
1421 		return -ENOMEM;
1422 
1423 	cmd = (struct wmi_sta_powersave_param_cmd *)skb->data;
1424 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1425 				     WMI_TAG_STA_POWERSAVE_PARAM_CMD) |
1426 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1427 
1428 	cmd->vdev_id = vdev_id;
1429 	cmd->param = param;
1430 	cmd->value = param_value;
1431 
1432 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1433 		   "WMI set sta ps vdev_id %d param %d value %d\n",
1434 		   vdev_id, param, param_value);
1435 
1436 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_STA_POWERSAVE_PARAM_CMDID);
1437 	if (ret) {
1438 		ath11k_warn(ar->ab, "failed to send WMI_STA_POWERSAVE_PARAM_CMDID");
1439 		dev_kfree_skb(skb);
1440 	}
1441 
1442 	return ret;
1443 }
1444 
1445 int ath11k_wmi_force_fw_hang_cmd(struct ath11k *ar, u32 type, u32 delay_time_ms)
1446 {
1447 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1448 	struct wmi_force_fw_hang_cmd *cmd;
1449 	struct sk_buff *skb;
1450 	int ret, len;
1451 
1452 	len = sizeof(*cmd);
1453 
1454 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
1455 	if (!skb)
1456 		return -ENOMEM;
1457 
1458 	cmd = (struct wmi_force_fw_hang_cmd *)skb->data;
1459 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_FORCE_FW_HANG_CMD) |
1460 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
1461 
1462 	cmd->type = type;
1463 	cmd->delay_time_ms = delay_time_ms;
1464 
1465 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_FORCE_FW_HANG_CMDID);
1466 
1467 	if (ret) {
1468 		ath11k_warn(ar->ab, "Failed to send WMI_FORCE_FW_HANG_CMDID");
1469 		dev_kfree_skb(skb);
1470 	}
1471 	return ret;
1472 }
1473 
1474 int ath11k_wmi_vdev_set_param_cmd(struct ath11k *ar, u32 vdev_id,
1475 				  u32 param_id, u32 param_value)
1476 {
1477 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1478 	struct wmi_vdev_set_param_cmd *cmd;
1479 	struct sk_buff *skb;
1480 	int ret;
1481 
1482 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1483 	if (!skb)
1484 		return -ENOMEM;
1485 
1486 	cmd = (struct wmi_vdev_set_param_cmd *)skb->data;
1487 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_SET_PARAM_CMD) |
1488 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1489 
1490 	cmd->vdev_id = vdev_id;
1491 	cmd->param_id = param_id;
1492 	cmd->param_value = param_value;
1493 
1494 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_SET_PARAM_CMDID);
1495 	if (ret) {
1496 		ath11k_warn(ar->ab,
1497 			    "failed to send WMI_VDEV_SET_PARAM_CMDID\n");
1498 		dev_kfree_skb(skb);
1499 	}
1500 
1501 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1502 		   "WMI vdev id 0x%x set param %d value %d\n",
1503 		   vdev_id, param_id, param_value);
1504 
1505 	return ret;
1506 }
1507 
1508 int ath11k_wmi_send_stats_request_cmd(struct ath11k *ar,
1509 				      struct stats_request_params *param)
1510 {
1511 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1512 	struct wmi_request_stats_cmd *cmd;
1513 	struct sk_buff *skb;
1514 	int ret;
1515 
1516 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1517 	if (!skb)
1518 		return -ENOMEM;
1519 
1520 	cmd = (struct wmi_request_stats_cmd *)skb->data;
1521 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_REQUEST_STATS_CMD) |
1522 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1523 
1524 	cmd->stats_id = param->stats_id;
1525 	cmd->vdev_id = param->vdev_id;
1526 	cmd->pdev_id = param->pdev_id;
1527 
1528 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_REQUEST_STATS_CMDID);
1529 	if (ret) {
1530 		ath11k_warn(ar->ab, "failed to send WMI_REQUEST_STATS cmd\n");
1531 		dev_kfree_skb(skb);
1532 	}
1533 
1534 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1535 		   "WMI request stats 0x%x vdev id %d pdev id %d\n",
1536 		   param->stats_id, param->vdev_id, param->pdev_id);
1537 
1538 	return ret;
1539 }
1540 
1541 int ath11k_wmi_send_pdev_temperature_cmd(struct ath11k *ar)
1542 {
1543 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1544 	struct wmi_get_pdev_temperature_cmd *cmd;
1545 	struct sk_buff *skb;
1546 	int ret;
1547 
1548 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1549 	if (!skb)
1550 		return -ENOMEM;
1551 
1552 	cmd = (struct wmi_get_pdev_temperature_cmd *)skb->data;
1553 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_GET_TEMPERATURE_CMD) |
1554 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1555 	cmd->pdev_id = ar->pdev->pdev_id;
1556 
1557 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_GET_TEMPERATURE_CMDID);
1558 	if (ret) {
1559 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_GET_TEMPERATURE cmd\n");
1560 		dev_kfree_skb(skb);
1561 	}
1562 
1563 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1564 		   "WMI pdev get temperature for pdev_id %d\n", ar->pdev->pdev_id);
1565 
1566 	return ret;
1567 }
1568 
1569 int ath11k_wmi_send_bcn_offload_control_cmd(struct ath11k *ar,
1570 					    u32 vdev_id, u32 bcn_ctrl_op)
1571 {
1572 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1573 	struct wmi_bcn_offload_ctrl_cmd *cmd;
1574 	struct sk_buff *skb;
1575 	int ret;
1576 
1577 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1578 	if (!skb)
1579 		return -ENOMEM;
1580 
1581 	cmd = (struct wmi_bcn_offload_ctrl_cmd *)skb->data;
1582 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1583 				     WMI_TAG_BCN_OFFLOAD_CTRL_CMD) |
1584 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1585 
1586 	cmd->vdev_id = vdev_id;
1587 	cmd->bcn_ctrl_op = bcn_ctrl_op;
1588 
1589 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1590 		   "WMI bcn ctrl offload vdev id %d ctrl_op %d\n",
1591 		   vdev_id, bcn_ctrl_op);
1592 
1593 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_BCN_OFFLOAD_CTRL_CMDID);
1594 	if (ret) {
1595 		ath11k_warn(ar->ab,
1596 			    "failed to send WMI_BCN_OFFLOAD_CTRL_CMDID\n");
1597 		dev_kfree_skb(skb);
1598 	}
1599 
1600 	return ret;
1601 }
1602 
1603 int ath11k_wmi_bcn_tmpl(struct ath11k *ar, u32 vdev_id,
1604 			struct ieee80211_mutable_offsets *offs,
1605 			struct sk_buff *bcn)
1606 {
1607 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1608 	struct wmi_bcn_tmpl_cmd *cmd;
1609 	struct wmi_bcn_prb_info *bcn_prb_info;
1610 	struct wmi_tlv *tlv;
1611 	struct sk_buff *skb;
1612 	void *ptr;
1613 	int ret, len;
1614 	size_t aligned_len = roundup(bcn->len, 4);
1615 
1616 	len = sizeof(*cmd) + sizeof(*bcn_prb_info) + TLV_HDR_SIZE + aligned_len;
1617 
1618 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
1619 	if (!skb)
1620 		return -ENOMEM;
1621 
1622 	cmd = (struct wmi_bcn_tmpl_cmd *)skb->data;
1623 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_BCN_TMPL_CMD) |
1624 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1625 	cmd->vdev_id = vdev_id;
1626 	cmd->tim_ie_offset = offs->tim_offset;
1627 	cmd->csa_switch_count_offset = offs->cntdwn_counter_offs[0];
1628 	cmd->ext_csa_switch_count_offset = offs->cntdwn_counter_offs[1];
1629 	cmd->buf_len = bcn->len;
1630 
1631 	ptr = skb->data + sizeof(*cmd);
1632 
1633 	bcn_prb_info = ptr;
1634 	len = sizeof(*bcn_prb_info);
1635 	bcn_prb_info->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1636 					      WMI_TAG_BCN_PRB_INFO) |
1637 				   FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
1638 	bcn_prb_info->caps = 0;
1639 	bcn_prb_info->erp = 0;
1640 
1641 	ptr += sizeof(*bcn_prb_info);
1642 
1643 	tlv = ptr;
1644 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1645 		      FIELD_PREP(WMI_TLV_LEN, aligned_len);
1646 	memcpy(tlv->value, bcn->data, bcn->len);
1647 
1648 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_BCN_TMPL_CMDID);
1649 	if (ret) {
1650 		ath11k_warn(ar->ab, "failed to send WMI_BCN_TMPL_CMDID\n");
1651 		dev_kfree_skb(skb);
1652 	}
1653 
1654 	return ret;
1655 }
1656 
1657 int ath11k_wmi_vdev_install_key(struct ath11k *ar,
1658 				struct wmi_vdev_install_key_arg *arg)
1659 {
1660 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1661 	struct wmi_vdev_install_key_cmd *cmd;
1662 	struct wmi_tlv *tlv;
1663 	struct sk_buff *skb;
1664 	int ret, len;
1665 	int key_len_aligned = roundup(arg->key_len, sizeof(uint32_t));
1666 
1667 	len = sizeof(*cmd) + TLV_HDR_SIZE + key_len_aligned;
1668 
1669 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
1670 	if (!skb)
1671 		return -ENOMEM;
1672 
1673 	cmd = (struct wmi_vdev_install_key_cmd *)skb->data;
1674 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_INSTALL_KEY_CMD) |
1675 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1676 	cmd->vdev_id = arg->vdev_id;
1677 	ether_addr_copy(cmd->peer_macaddr.addr, arg->macaddr);
1678 	cmd->key_idx = arg->key_idx;
1679 	cmd->key_flags = arg->key_flags;
1680 	cmd->key_cipher = arg->key_cipher;
1681 	cmd->key_len = arg->key_len;
1682 	cmd->key_txmic_len = arg->key_txmic_len;
1683 	cmd->key_rxmic_len = arg->key_rxmic_len;
1684 
1685 	if (arg->key_rsc_counter)
1686 		memcpy(&cmd->key_rsc_counter, &arg->key_rsc_counter,
1687 		       sizeof(struct wmi_key_seq_counter));
1688 
1689 	tlv = (struct wmi_tlv *)(skb->data + sizeof(*cmd));
1690 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1691 		      FIELD_PREP(WMI_TLV_LEN, key_len_aligned);
1692 	memcpy(tlv->value, (u8 *)arg->key_data, key_len_aligned);
1693 
1694 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_INSTALL_KEY_CMDID);
1695 	if (ret) {
1696 		ath11k_warn(ar->ab,
1697 			    "failed to send WMI_VDEV_INSTALL_KEY cmd\n");
1698 		dev_kfree_skb(skb);
1699 	}
1700 
1701 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1702 		   "WMI vdev install key idx %d cipher %d len %d\n",
1703 		   arg->key_idx, arg->key_cipher, arg->key_len);
1704 
1705 	return ret;
1706 }
1707 
1708 static inline void
1709 ath11k_wmi_copy_peer_flags(struct wmi_peer_assoc_complete_cmd *cmd,
1710 			   struct peer_assoc_params *param,
1711 			   bool hw_crypto_disabled)
1712 {
1713 	cmd->peer_flags = 0;
1714 
1715 	if (param->is_wme_set) {
1716 		if (param->qos_flag)
1717 			cmd->peer_flags |= WMI_PEER_QOS;
1718 		if (param->apsd_flag)
1719 			cmd->peer_flags |= WMI_PEER_APSD;
1720 		if (param->ht_flag)
1721 			cmd->peer_flags |= WMI_PEER_HT;
1722 		if (param->bw_40)
1723 			cmd->peer_flags |= WMI_PEER_40MHZ;
1724 		if (param->bw_80)
1725 			cmd->peer_flags |= WMI_PEER_80MHZ;
1726 		if (param->bw_160)
1727 			cmd->peer_flags |= WMI_PEER_160MHZ;
1728 
1729 		/* Typically if STBC is enabled for VHT it should be enabled
1730 		 * for HT as well
1731 		 **/
1732 		if (param->stbc_flag)
1733 			cmd->peer_flags |= WMI_PEER_STBC;
1734 
1735 		/* Typically if LDPC is enabled for VHT it should be enabled
1736 		 * for HT as well
1737 		 **/
1738 		if (param->ldpc_flag)
1739 			cmd->peer_flags |= WMI_PEER_LDPC;
1740 
1741 		if (param->static_mimops_flag)
1742 			cmd->peer_flags |= WMI_PEER_STATIC_MIMOPS;
1743 		if (param->dynamic_mimops_flag)
1744 			cmd->peer_flags |= WMI_PEER_DYN_MIMOPS;
1745 		if (param->spatial_mux_flag)
1746 			cmd->peer_flags |= WMI_PEER_SPATIAL_MUX;
1747 		if (param->vht_flag)
1748 			cmd->peer_flags |= WMI_PEER_VHT;
1749 		if (param->he_flag)
1750 			cmd->peer_flags |= WMI_PEER_HE;
1751 		if (param->twt_requester)
1752 			cmd->peer_flags |= WMI_PEER_TWT_REQ;
1753 		if (param->twt_responder)
1754 			cmd->peer_flags |= WMI_PEER_TWT_RESP;
1755 	}
1756 
1757 	/* Suppress authorization for all AUTH modes that need 4-way handshake
1758 	 * (during re-association).
1759 	 * Authorization will be done for these modes on key installation.
1760 	 */
1761 	if (param->auth_flag)
1762 		cmd->peer_flags |= WMI_PEER_AUTH;
1763 	if (param->need_ptk_4_way) {
1764 		cmd->peer_flags |= WMI_PEER_NEED_PTK_4_WAY;
1765 		if (!hw_crypto_disabled)
1766 			cmd->peer_flags &= ~WMI_PEER_AUTH;
1767 	}
1768 	if (param->need_gtk_2_way)
1769 		cmd->peer_flags |= WMI_PEER_NEED_GTK_2_WAY;
1770 	/* safe mode bypass the 4-way handshake */
1771 	if (param->safe_mode_enabled)
1772 		cmd->peer_flags &= ~(WMI_PEER_NEED_PTK_4_WAY |
1773 				     WMI_PEER_NEED_GTK_2_WAY);
1774 
1775 	if (param->is_pmf_enabled)
1776 		cmd->peer_flags |= WMI_PEER_PMF;
1777 
1778 	/* Disable AMSDU for station transmit, if user configures it */
1779 	/* Disable AMSDU for AP transmit to 11n Stations, if user configures
1780 	 * it
1781 	 * if (param->amsdu_disable) Add after FW support
1782 	 **/
1783 
1784 	/* Target asserts if node is marked HT and all MCS is set to 0.
1785 	 * Mark the node as non-HT if all the mcs rates are disabled through
1786 	 * iwpriv
1787 	 **/
1788 	if (param->peer_ht_rates.num_rates == 0)
1789 		cmd->peer_flags &= ~WMI_PEER_HT;
1790 }
1791 
1792 int ath11k_wmi_send_peer_assoc_cmd(struct ath11k *ar,
1793 				   struct peer_assoc_params *param)
1794 {
1795 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1796 	struct wmi_peer_assoc_complete_cmd *cmd;
1797 	struct wmi_vht_rate_set *mcs;
1798 	struct wmi_he_rate_set *he_mcs;
1799 	struct sk_buff *skb;
1800 	struct wmi_tlv *tlv;
1801 	void *ptr;
1802 	u32 peer_legacy_rates_align;
1803 	u32 peer_ht_rates_align;
1804 	int i, ret, len;
1805 
1806 	peer_legacy_rates_align = roundup(param->peer_legacy_rates.num_rates,
1807 					  sizeof(u32));
1808 	peer_ht_rates_align = roundup(param->peer_ht_rates.num_rates,
1809 				      sizeof(u32));
1810 
1811 	len = sizeof(*cmd) +
1812 	      TLV_HDR_SIZE + (peer_legacy_rates_align * sizeof(u8)) +
1813 	      TLV_HDR_SIZE + (peer_ht_rates_align * sizeof(u8)) +
1814 	      sizeof(*mcs) + TLV_HDR_SIZE +
1815 	      (sizeof(*he_mcs) * param->peer_he_mcs_count);
1816 
1817 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
1818 	if (!skb)
1819 		return -ENOMEM;
1820 
1821 	ptr = skb->data;
1822 
1823 	cmd = ptr;
1824 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1825 				     WMI_TAG_PEER_ASSOC_COMPLETE_CMD) |
1826 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1827 
1828 	cmd->vdev_id = param->vdev_id;
1829 
1830 	cmd->peer_new_assoc = param->peer_new_assoc;
1831 	cmd->peer_associd = param->peer_associd;
1832 
1833 	ath11k_wmi_copy_peer_flags(cmd, param,
1834 				   test_bit(ATH11K_FLAG_HW_CRYPTO_DISABLED,
1835 					    &ar->ab->dev_flags));
1836 
1837 	ether_addr_copy(cmd->peer_macaddr.addr, param->peer_mac);
1838 
1839 	cmd->peer_rate_caps = param->peer_rate_caps;
1840 	cmd->peer_caps = param->peer_caps;
1841 	cmd->peer_listen_intval = param->peer_listen_intval;
1842 	cmd->peer_ht_caps = param->peer_ht_caps;
1843 	cmd->peer_max_mpdu = param->peer_max_mpdu;
1844 	cmd->peer_mpdu_density = param->peer_mpdu_density;
1845 	cmd->peer_vht_caps = param->peer_vht_caps;
1846 	cmd->peer_phymode = param->peer_phymode;
1847 
1848 	/* Update 11ax capabilities */
1849 	cmd->peer_he_cap_info = param->peer_he_cap_macinfo[0];
1850 	cmd->peer_he_cap_info_ext = param->peer_he_cap_macinfo[1];
1851 	cmd->peer_he_cap_info_internal = param->peer_he_cap_macinfo_internal;
1852 	cmd->peer_he_caps_6ghz = param->peer_he_caps_6ghz;
1853 	cmd->peer_he_ops = param->peer_he_ops;
1854 	memcpy(&cmd->peer_he_cap_phy, &param->peer_he_cap_phyinfo,
1855 	       sizeof(param->peer_he_cap_phyinfo));
1856 	memcpy(&cmd->peer_ppet, &param->peer_ppet,
1857 	       sizeof(param->peer_ppet));
1858 
1859 	/* Update peer legacy rate information */
1860 	ptr += sizeof(*cmd);
1861 
1862 	tlv = ptr;
1863 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1864 		      FIELD_PREP(WMI_TLV_LEN, peer_legacy_rates_align);
1865 
1866 	ptr += TLV_HDR_SIZE;
1867 
1868 	cmd->num_peer_legacy_rates = param->peer_legacy_rates.num_rates;
1869 	memcpy(ptr, param->peer_legacy_rates.rates,
1870 	       param->peer_legacy_rates.num_rates);
1871 
1872 	/* Update peer HT rate information */
1873 	ptr += peer_legacy_rates_align;
1874 
1875 	tlv = ptr;
1876 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1877 		      FIELD_PREP(WMI_TLV_LEN, peer_ht_rates_align);
1878 	ptr += TLV_HDR_SIZE;
1879 	cmd->num_peer_ht_rates = param->peer_ht_rates.num_rates;
1880 	memcpy(ptr, param->peer_ht_rates.rates,
1881 	       param->peer_ht_rates.num_rates);
1882 
1883 	/* VHT Rates */
1884 	ptr += peer_ht_rates_align;
1885 
1886 	mcs = ptr;
1887 
1888 	mcs->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VHT_RATE_SET) |
1889 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*mcs) - TLV_HDR_SIZE);
1890 
1891 	cmd->peer_nss = param->peer_nss;
1892 
1893 	/* Update bandwidth-NSS mapping */
1894 	cmd->peer_bw_rxnss_override = 0;
1895 	cmd->peer_bw_rxnss_override |= param->peer_bw_rxnss_override;
1896 
1897 	if (param->vht_capable) {
1898 		mcs->rx_max_rate = param->rx_max_rate;
1899 		mcs->rx_mcs_set = param->rx_mcs_set;
1900 		mcs->tx_max_rate = param->tx_max_rate;
1901 		mcs->tx_mcs_set = param->tx_mcs_set;
1902 	}
1903 
1904 	/* HE Rates */
1905 	cmd->peer_he_mcs = param->peer_he_mcs_count;
1906 	cmd->min_data_rate = param->min_data_rate;
1907 
1908 	ptr += sizeof(*mcs);
1909 
1910 	len = param->peer_he_mcs_count * sizeof(*he_mcs);
1911 
1912 	tlv = ptr;
1913 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
1914 		      FIELD_PREP(WMI_TLV_LEN, len);
1915 	ptr += TLV_HDR_SIZE;
1916 
1917 	/* Loop through the HE rate set */
1918 	for (i = 0; i < param->peer_he_mcs_count; i++) {
1919 		he_mcs = ptr;
1920 		he_mcs->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1921 						WMI_TAG_HE_RATE_SET) |
1922 				     FIELD_PREP(WMI_TLV_LEN,
1923 						sizeof(*he_mcs) - TLV_HDR_SIZE);
1924 
1925 		he_mcs->rx_mcs_set = param->peer_he_tx_mcs_set[i];
1926 		he_mcs->tx_mcs_set = param->peer_he_rx_mcs_set[i];
1927 		ptr += sizeof(*he_mcs);
1928 	}
1929 
1930 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_ASSOC_CMDID);
1931 	if (ret) {
1932 		ath11k_warn(ar->ab,
1933 			    "failed to send WMI_PEER_ASSOC_CMDID\n");
1934 		dev_kfree_skb(skb);
1935 	}
1936 
1937 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1938 		   "wmi peer assoc vdev id %d assoc id %d peer mac %pM peer_flags %x rate_caps %x peer_caps %x listen_intval %d ht_caps %x max_mpdu %d nss %d phymode %d peer_mpdu_density %d vht_caps %x he cap_info %x he ops %x he cap_info_ext %x he phy %x %x %x peer_bw_rxnss_override %x\n",
1939 		   cmd->vdev_id, cmd->peer_associd, param->peer_mac,
1940 		   cmd->peer_flags, cmd->peer_rate_caps, cmd->peer_caps,
1941 		   cmd->peer_listen_intval, cmd->peer_ht_caps,
1942 		   cmd->peer_max_mpdu, cmd->peer_nss, cmd->peer_phymode,
1943 		   cmd->peer_mpdu_density,
1944 		   cmd->peer_vht_caps, cmd->peer_he_cap_info,
1945 		   cmd->peer_he_ops, cmd->peer_he_cap_info_ext,
1946 		   cmd->peer_he_cap_phy[0], cmd->peer_he_cap_phy[1],
1947 		   cmd->peer_he_cap_phy[2],
1948 		   cmd->peer_bw_rxnss_override);
1949 
1950 	return ret;
1951 }
1952 
1953 void ath11k_wmi_start_scan_init(struct ath11k *ar,
1954 				struct scan_req_params *arg)
1955 {
1956 	/* setup commonly used values */
1957 	arg->scan_req_id = 1;
1958 	arg->scan_priority = WMI_SCAN_PRIORITY_LOW;
1959 	arg->dwell_time_active = 50;
1960 	arg->dwell_time_active_2g = 0;
1961 	arg->dwell_time_passive = 150;
1962 	arg->dwell_time_active_6g = 40;
1963 	arg->dwell_time_passive_6g = 30;
1964 	arg->min_rest_time = 50;
1965 	arg->max_rest_time = 500;
1966 	arg->repeat_probe_time = 0;
1967 	arg->probe_spacing_time = 0;
1968 	arg->idle_time = 0;
1969 	arg->max_scan_time = 20000;
1970 	arg->probe_delay = 5;
1971 	arg->notify_scan_events = WMI_SCAN_EVENT_STARTED |
1972 				  WMI_SCAN_EVENT_COMPLETED |
1973 				  WMI_SCAN_EVENT_BSS_CHANNEL |
1974 				  WMI_SCAN_EVENT_FOREIGN_CHAN |
1975 				  WMI_SCAN_EVENT_DEQUEUED;
1976 	arg->scan_flags |= WMI_SCAN_CHAN_STAT_EVENT;
1977 	arg->num_bssid = 1;
1978 
1979 	/* fill bssid_list[0] with 0xff, otherwise bssid and RA will be
1980 	 * ZEROs in probe request
1981 	 */
1982 	eth_broadcast_addr(arg->bssid_list[0].addr);
1983 }
1984 
1985 static inline void
1986 ath11k_wmi_copy_scan_event_cntrl_flags(struct wmi_start_scan_cmd *cmd,
1987 				       struct scan_req_params *param)
1988 {
1989 	/* Scan events subscription */
1990 	if (param->scan_ev_started)
1991 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_STARTED;
1992 	if (param->scan_ev_completed)
1993 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_COMPLETED;
1994 	if (param->scan_ev_bss_chan)
1995 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_BSS_CHANNEL;
1996 	if (param->scan_ev_foreign_chan)
1997 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_FOREIGN_CHAN;
1998 	if (param->scan_ev_dequeued)
1999 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_DEQUEUED;
2000 	if (param->scan_ev_preempted)
2001 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_PREEMPTED;
2002 	if (param->scan_ev_start_failed)
2003 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_START_FAILED;
2004 	if (param->scan_ev_restarted)
2005 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_RESTARTED;
2006 	if (param->scan_ev_foreign_chn_exit)
2007 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_FOREIGN_CHAN_EXIT;
2008 	if (param->scan_ev_suspended)
2009 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_SUSPENDED;
2010 	if (param->scan_ev_resumed)
2011 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_RESUMED;
2012 
2013 	/** Set scan control flags */
2014 	cmd->scan_ctrl_flags = 0;
2015 	if (param->scan_f_passive)
2016 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_PASSIVE;
2017 	if (param->scan_f_strict_passive_pch)
2018 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_STRICT_PASSIVE_ON_PCHN;
2019 	if (param->scan_f_promisc_mode)
2020 		cmd->scan_ctrl_flags |=  WMI_SCAN_FILTER_PROMISCUOS;
2021 	if (param->scan_f_capture_phy_err)
2022 		cmd->scan_ctrl_flags |=  WMI_SCAN_CAPTURE_PHY_ERROR;
2023 	if (param->scan_f_half_rate)
2024 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_HALF_RATE_SUPPORT;
2025 	if (param->scan_f_quarter_rate)
2026 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_QUARTER_RATE_SUPPORT;
2027 	if (param->scan_f_cck_rates)
2028 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_CCK_RATES;
2029 	if (param->scan_f_ofdm_rates)
2030 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_OFDM_RATES;
2031 	if (param->scan_f_chan_stat_evnt)
2032 		cmd->scan_ctrl_flags |=  WMI_SCAN_CHAN_STAT_EVENT;
2033 	if (param->scan_f_filter_prb_req)
2034 		cmd->scan_ctrl_flags |=  WMI_SCAN_FILTER_PROBE_REQ;
2035 	if (param->scan_f_bcast_probe)
2036 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_BCAST_PROBE_REQ;
2037 	if (param->scan_f_offchan_mgmt_tx)
2038 		cmd->scan_ctrl_flags |=  WMI_SCAN_OFFCHAN_MGMT_TX;
2039 	if (param->scan_f_offchan_data_tx)
2040 		cmd->scan_ctrl_flags |=  WMI_SCAN_OFFCHAN_DATA_TX;
2041 	if (param->scan_f_force_active_dfs_chn)
2042 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_FORCE_ACTIVE_ON_DFS;
2043 	if (param->scan_f_add_tpc_ie_in_probe)
2044 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_TPC_IE_IN_PROBE_REQ;
2045 	if (param->scan_f_add_ds_ie_in_probe)
2046 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_DS_IE_IN_PROBE_REQ;
2047 	if (param->scan_f_add_spoofed_mac_in_probe)
2048 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_SPOOF_MAC_IN_PROBE_REQ;
2049 	if (param->scan_f_add_rand_seq_in_probe)
2050 		cmd->scan_ctrl_flags |=  WMI_SCAN_RANDOM_SEQ_NO_IN_PROBE_REQ;
2051 	if (param->scan_f_en_ie_whitelist_in_probe)
2052 		cmd->scan_ctrl_flags |=
2053 			 WMI_SCAN_ENABLE_IE_WHTELIST_IN_PROBE_REQ;
2054 
2055 	/* for adaptive scan mode using 3 bits (21 - 23 bits) */
2056 	WMI_SCAN_SET_DWELL_MODE(cmd->scan_ctrl_flags,
2057 				param->adaptive_dwell_time_mode);
2058 }
2059 
2060 int ath11k_wmi_send_scan_start_cmd(struct ath11k *ar,
2061 				   struct scan_req_params *params)
2062 {
2063 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2064 	struct wmi_start_scan_cmd *cmd;
2065 	struct wmi_ssid *ssid = NULL;
2066 	struct wmi_mac_addr *bssid;
2067 	struct sk_buff *skb;
2068 	struct wmi_tlv *tlv;
2069 	void *ptr;
2070 	int i, ret, len;
2071 	u32 *tmp_ptr;
2072 	u8 extraie_len_with_pad = 0;
2073 	struct hint_short_ssid *s_ssid = NULL;
2074 	struct hint_bssid *hint_bssid = NULL;
2075 
2076 	len = sizeof(*cmd);
2077 
2078 	len += TLV_HDR_SIZE;
2079 	if (params->num_chan)
2080 		len += params->num_chan * sizeof(u32);
2081 
2082 	len += TLV_HDR_SIZE;
2083 	if (params->num_ssids)
2084 		len += params->num_ssids * sizeof(*ssid);
2085 
2086 	len += TLV_HDR_SIZE;
2087 	if (params->num_bssid)
2088 		len += sizeof(*bssid) * params->num_bssid;
2089 
2090 	len += TLV_HDR_SIZE;
2091 	if (params->extraie.len)
2092 		extraie_len_with_pad =
2093 			roundup(params->extraie.len, sizeof(u32));
2094 	len += extraie_len_with_pad;
2095 
2096 	if (params->num_hint_bssid)
2097 		len += TLV_HDR_SIZE +
2098 		       params->num_hint_bssid * sizeof(struct hint_bssid);
2099 
2100 	if (params->num_hint_s_ssid)
2101 		len += TLV_HDR_SIZE +
2102 		       params->num_hint_s_ssid * sizeof(struct hint_short_ssid);
2103 
2104 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2105 	if (!skb)
2106 		return -ENOMEM;
2107 
2108 	ptr = skb->data;
2109 
2110 	cmd = ptr;
2111 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_START_SCAN_CMD) |
2112 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2113 
2114 	cmd->scan_id = params->scan_id;
2115 	cmd->scan_req_id = params->scan_req_id;
2116 	cmd->vdev_id = params->vdev_id;
2117 	cmd->scan_priority = params->scan_priority;
2118 	cmd->notify_scan_events = params->notify_scan_events;
2119 
2120 	ath11k_wmi_copy_scan_event_cntrl_flags(cmd, params);
2121 
2122 	cmd->dwell_time_active = params->dwell_time_active;
2123 	cmd->dwell_time_active_2g = params->dwell_time_active_2g;
2124 	cmd->dwell_time_passive = params->dwell_time_passive;
2125 	cmd->dwell_time_active_6g = params->dwell_time_active_6g;
2126 	cmd->dwell_time_passive_6g = params->dwell_time_passive_6g;
2127 	cmd->min_rest_time = params->min_rest_time;
2128 	cmd->max_rest_time = params->max_rest_time;
2129 	cmd->repeat_probe_time = params->repeat_probe_time;
2130 	cmd->probe_spacing_time = params->probe_spacing_time;
2131 	cmd->idle_time = params->idle_time;
2132 	cmd->max_scan_time = params->max_scan_time;
2133 	cmd->probe_delay = params->probe_delay;
2134 	cmd->burst_duration = params->burst_duration;
2135 	cmd->num_chan = params->num_chan;
2136 	cmd->num_bssid = params->num_bssid;
2137 	cmd->num_ssids = params->num_ssids;
2138 	cmd->ie_len = params->extraie.len;
2139 	cmd->n_probes = params->n_probes;
2140 
2141 	ptr += sizeof(*cmd);
2142 
2143 	len = params->num_chan * sizeof(u32);
2144 
2145 	tlv = ptr;
2146 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_UINT32) |
2147 		      FIELD_PREP(WMI_TLV_LEN, len);
2148 	ptr += TLV_HDR_SIZE;
2149 	tmp_ptr = (u32 *)ptr;
2150 
2151 	for (i = 0; i < params->num_chan; ++i)
2152 		tmp_ptr[i] = params->chan_list[i];
2153 
2154 	ptr += len;
2155 
2156 	len = params->num_ssids * sizeof(*ssid);
2157 	tlv = ptr;
2158 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2159 		      FIELD_PREP(WMI_TLV_LEN, len);
2160 
2161 	ptr += TLV_HDR_SIZE;
2162 
2163 	if (params->num_ssids) {
2164 		ssid = ptr;
2165 		for (i = 0; i < params->num_ssids; ++i) {
2166 			ssid->ssid_len = params->ssid[i].length;
2167 			memcpy(ssid->ssid, params->ssid[i].ssid,
2168 			       params->ssid[i].length);
2169 			ssid++;
2170 		}
2171 	}
2172 
2173 	ptr += (params->num_ssids * sizeof(*ssid));
2174 	len = params->num_bssid * sizeof(*bssid);
2175 	tlv = ptr;
2176 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2177 		      FIELD_PREP(WMI_TLV_LEN, len);
2178 
2179 	ptr += TLV_HDR_SIZE;
2180 	bssid = ptr;
2181 
2182 	if (params->num_bssid) {
2183 		for (i = 0; i < params->num_bssid; ++i) {
2184 			ether_addr_copy(bssid->addr,
2185 					params->bssid_list[i].addr);
2186 			bssid++;
2187 		}
2188 	}
2189 
2190 	ptr += params->num_bssid * sizeof(*bssid);
2191 
2192 	len = extraie_len_with_pad;
2193 	tlv = ptr;
2194 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
2195 		      FIELD_PREP(WMI_TLV_LEN, len);
2196 	ptr += TLV_HDR_SIZE;
2197 
2198 	if (params->extraie.len)
2199 		memcpy(ptr, params->extraie.ptr,
2200 		       params->extraie.len);
2201 
2202 	ptr += extraie_len_with_pad;
2203 
2204 	if (params->num_hint_s_ssid) {
2205 		len = params->num_hint_s_ssid * sizeof(struct hint_short_ssid);
2206 		tlv = ptr;
2207 		tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2208 			      FIELD_PREP(WMI_TLV_LEN, len);
2209 		ptr += TLV_HDR_SIZE;
2210 		s_ssid = ptr;
2211 		for (i = 0; i < params->num_hint_s_ssid; ++i) {
2212 			s_ssid->freq_flags = params->hint_s_ssid[i].freq_flags;
2213 			s_ssid->short_ssid = params->hint_s_ssid[i].short_ssid;
2214 			s_ssid++;
2215 		}
2216 		ptr += len;
2217 	}
2218 
2219 	if (params->num_hint_bssid) {
2220 		len = params->num_hint_bssid * sizeof(struct hint_bssid);
2221 		tlv = ptr;
2222 		tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2223 			      FIELD_PREP(WMI_TLV_LEN, len);
2224 		ptr += TLV_HDR_SIZE;
2225 		hint_bssid = ptr;
2226 		for (i = 0; i < params->num_hint_bssid; ++i) {
2227 			hint_bssid->freq_flags =
2228 				params->hint_bssid[i].freq_flags;
2229 			ether_addr_copy(&params->hint_bssid[i].bssid.addr[0],
2230 					&hint_bssid->bssid.addr[0]);
2231 			hint_bssid++;
2232 		}
2233 	}
2234 
2235 	ret = ath11k_wmi_cmd_send(wmi, skb,
2236 				  WMI_START_SCAN_CMDID);
2237 	if (ret) {
2238 		ath11k_warn(ar->ab, "failed to send WMI_START_SCAN_CMDID\n");
2239 		dev_kfree_skb(skb);
2240 	}
2241 
2242 	return ret;
2243 }
2244 
2245 int ath11k_wmi_send_scan_stop_cmd(struct ath11k *ar,
2246 				  struct scan_cancel_param *param)
2247 {
2248 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2249 	struct wmi_stop_scan_cmd *cmd;
2250 	struct sk_buff *skb;
2251 	int ret;
2252 
2253 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2254 	if (!skb)
2255 		return -ENOMEM;
2256 
2257 	cmd = (struct wmi_stop_scan_cmd *)skb->data;
2258 
2259 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_STOP_SCAN_CMD) |
2260 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2261 
2262 	cmd->vdev_id = param->vdev_id;
2263 	cmd->requestor = param->requester;
2264 	cmd->scan_id = param->scan_id;
2265 	cmd->pdev_id = param->pdev_id;
2266 	/* stop the scan with the corresponding scan_id */
2267 	if (param->req_type == WLAN_SCAN_CANCEL_PDEV_ALL) {
2268 		/* Cancelling all scans */
2269 		cmd->req_type =  WMI_SCAN_STOP_ALL;
2270 	} else if (param->req_type == WLAN_SCAN_CANCEL_VDEV_ALL) {
2271 		/* Cancelling VAP scans */
2272 		cmd->req_type =  WMI_SCN_STOP_VAP_ALL;
2273 	} else if (param->req_type == WLAN_SCAN_CANCEL_SINGLE) {
2274 		/* Cancelling specific scan */
2275 		cmd->req_type =  WMI_SCAN_STOP_ONE;
2276 	} else {
2277 		ath11k_warn(ar->ab, "invalid scan cancel param %d",
2278 			    param->req_type);
2279 		dev_kfree_skb(skb);
2280 		return -EINVAL;
2281 	}
2282 
2283 	ret = ath11k_wmi_cmd_send(wmi, skb,
2284 				  WMI_STOP_SCAN_CMDID);
2285 	if (ret) {
2286 		ath11k_warn(ar->ab, "failed to send WMI_STOP_SCAN_CMDID\n");
2287 		dev_kfree_skb(skb);
2288 	}
2289 
2290 	return ret;
2291 }
2292 
2293 int ath11k_wmi_send_scan_chan_list_cmd(struct ath11k *ar,
2294 				       struct scan_chan_list_params *chan_list)
2295 {
2296 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2297 	struct wmi_scan_chan_list_cmd *cmd;
2298 	struct sk_buff *skb;
2299 	struct wmi_channel *chan_info;
2300 	struct channel_param *tchan_info;
2301 	struct wmi_tlv *tlv;
2302 	void *ptr;
2303 	int i, ret, len;
2304 	u16 num_send_chans, num_sends = 0, max_chan_limit = 0;
2305 	u32 *reg1, *reg2;
2306 
2307 	tchan_info = chan_list->ch_param;
2308 	while (chan_list->nallchans) {
2309 		len = sizeof(*cmd) + TLV_HDR_SIZE;
2310 		max_chan_limit = (wmi->wmi_ab->max_msg_len[ar->pdev_idx] - len) /
2311 			sizeof(*chan_info);
2312 
2313 		if (chan_list->nallchans > max_chan_limit)
2314 			num_send_chans = max_chan_limit;
2315 		else
2316 			num_send_chans = chan_list->nallchans;
2317 
2318 		chan_list->nallchans -= num_send_chans;
2319 		len += sizeof(*chan_info) * num_send_chans;
2320 
2321 		skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2322 		if (!skb)
2323 			return -ENOMEM;
2324 
2325 		cmd = (struct wmi_scan_chan_list_cmd *)skb->data;
2326 		cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_SCAN_CHAN_LIST_CMD) |
2327 			FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2328 		cmd->pdev_id = chan_list->pdev_id;
2329 		cmd->num_scan_chans = num_send_chans;
2330 		if (num_sends)
2331 			cmd->flags |= WMI_APPEND_TO_EXISTING_CHAN_LIST_FLAG;
2332 
2333 		ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2334 			   "WMI no.of chan = %d len = %d pdev_id = %d num_sends = %d\n",
2335 			   num_send_chans, len, cmd->pdev_id, num_sends);
2336 
2337 		ptr = skb->data + sizeof(*cmd);
2338 
2339 		len = sizeof(*chan_info) * num_send_chans;
2340 		tlv = ptr;
2341 		tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2342 			      FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2343 		ptr += TLV_HDR_SIZE;
2344 
2345 		for (i = 0; i < num_send_chans; ++i) {
2346 			chan_info = ptr;
2347 			memset(chan_info, 0, sizeof(*chan_info));
2348 			len = sizeof(*chan_info);
2349 			chan_info->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2350 							   WMI_TAG_CHANNEL) |
2351 						FIELD_PREP(WMI_TLV_LEN,
2352 							   len - TLV_HDR_SIZE);
2353 
2354 			reg1 = &chan_info->reg_info_1;
2355 			reg2 = &chan_info->reg_info_2;
2356 			chan_info->mhz = tchan_info->mhz;
2357 			chan_info->band_center_freq1 = tchan_info->cfreq1;
2358 			chan_info->band_center_freq2 = tchan_info->cfreq2;
2359 
2360 			if (tchan_info->is_chan_passive)
2361 				chan_info->info |= WMI_CHAN_INFO_PASSIVE;
2362 			if (tchan_info->allow_he)
2363 				chan_info->info |= WMI_CHAN_INFO_ALLOW_HE;
2364 			else if (tchan_info->allow_vht)
2365 				chan_info->info |= WMI_CHAN_INFO_ALLOW_VHT;
2366 			else if (tchan_info->allow_ht)
2367 				chan_info->info |= WMI_CHAN_INFO_ALLOW_HT;
2368 			if (tchan_info->half_rate)
2369 				chan_info->info |= WMI_CHAN_INFO_HALF_RATE;
2370 			if (tchan_info->quarter_rate)
2371 				chan_info->info |= WMI_CHAN_INFO_QUARTER_RATE;
2372 			if (tchan_info->psc_channel)
2373 				chan_info->info |= WMI_CHAN_INFO_PSC;
2374 
2375 			chan_info->info |= FIELD_PREP(WMI_CHAN_INFO_MODE,
2376 						      tchan_info->phy_mode);
2377 			*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_MIN_PWR,
2378 					    tchan_info->minpower);
2379 			*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_PWR,
2380 					    tchan_info->maxpower);
2381 			*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_REG_PWR,
2382 					    tchan_info->maxregpower);
2383 			*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_REG_CLS,
2384 					    tchan_info->reg_class_id);
2385 			*reg2 |= FIELD_PREP(WMI_CHAN_REG_INFO2_ANT_MAX,
2386 					    tchan_info->antennamax);
2387 
2388 			ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2389 				   "WMI chan scan list chan[%d] = %u, chan_info->info %8x\n",
2390 				   i, chan_info->mhz, chan_info->info);
2391 
2392 			ptr += sizeof(*chan_info);
2393 
2394 			tchan_info++;
2395 		}
2396 
2397 		ret = ath11k_wmi_cmd_send(wmi, skb, WMI_SCAN_CHAN_LIST_CMDID);
2398 		if (ret) {
2399 			ath11k_warn(ar->ab, "failed to send WMI_SCAN_CHAN_LIST cmd\n");
2400 			dev_kfree_skb(skb);
2401 			return ret;
2402 		}
2403 
2404 		num_sends++;
2405 	}
2406 
2407 	return 0;
2408 }
2409 
2410 int ath11k_wmi_send_wmm_update_cmd_tlv(struct ath11k *ar, u32 vdev_id,
2411 				       struct wmi_wmm_params_all_arg *param)
2412 {
2413 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2414 	struct wmi_vdev_set_wmm_params_cmd *cmd;
2415 	struct wmi_wmm_params *wmm_param;
2416 	struct wmi_wmm_params_arg *wmi_wmm_arg;
2417 	struct sk_buff *skb;
2418 	int ret, ac;
2419 
2420 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2421 	if (!skb)
2422 		return -ENOMEM;
2423 
2424 	cmd = (struct wmi_vdev_set_wmm_params_cmd *)skb->data;
2425 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2426 				     WMI_TAG_VDEV_SET_WMM_PARAMS_CMD) |
2427 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2428 
2429 	cmd->vdev_id = vdev_id;
2430 	cmd->wmm_param_type = 0;
2431 
2432 	for (ac = 0; ac < WME_NUM_AC; ac++) {
2433 		switch (ac) {
2434 		case WME_AC_BE:
2435 			wmi_wmm_arg = &param->ac_be;
2436 			break;
2437 		case WME_AC_BK:
2438 			wmi_wmm_arg = &param->ac_bk;
2439 			break;
2440 		case WME_AC_VI:
2441 			wmi_wmm_arg = &param->ac_vi;
2442 			break;
2443 		case WME_AC_VO:
2444 			wmi_wmm_arg = &param->ac_vo;
2445 			break;
2446 		}
2447 
2448 		wmm_param = (struct wmi_wmm_params *)&cmd->wmm_params[ac];
2449 		wmm_param->tlv_header =
2450 				FIELD_PREP(WMI_TLV_TAG,
2451 					   WMI_TAG_VDEV_SET_WMM_PARAMS_CMD) |
2452 				FIELD_PREP(WMI_TLV_LEN,
2453 					   sizeof(*wmm_param) - TLV_HDR_SIZE);
2454 
2455 		wmm_param->aifs = wmi_wmm_arg->aifs;
2456 		wmm_param->cwmin = wmi_wmm_arg->cwmin;
2457 		wmm_param->cwmax = wmi_wmm_arg->cwmax;
2458 		wmm_param->txoplimit = wmi_wmm_arg->txop;
2459 		wmm_param->acm = wmi_wmm_arg->acm;
2460 		wmm_param->no_ack = wmi_wmm_arg->no_ack;
2461 
2462 		ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2463 			   "wmi wmm set ac %d aifs %d cwmin %d cwmax %d txop %d acm %d no_ack %d\n",
2464 			   ac, wmm_param->aifs, wmm_param->cwmin,
2465 			   wmm_param->cwmax, wmm_param->txoplimit,
2466 			   wmm_param->acm, wmm_param->no_ack);
2467 	}
2468 	ret = ath11k_wmi_cmd_send(wmi, skb,
2469 				  WMI_VDEV_SET_WMM_PARAMS_CMDID);
2470 	if (ret) {
2471 		ath11k_warn(ar->ab,
2472 			    "failed to send WMI_VDEV_SET_WMM_PARAMS_CMDID");
2473 		dev_kfree_skb(skb);
2474 	}
2475 
2476 	return ret;
2477 }
2478 
2479 int ath11k_wmi_send_dfs_phyerr_offload_enable_cmd(struct ath11k *ar,
2480 						  u32 pdev_id)
2481 {
2482 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2483 	struct wmi_dfs_phyerr_offload_cmd *cmd;
2484 	struct sk_buff *skb;
2485 	int ret;
2486 
2487 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2488 	if (!skb)
2489 		return -ENOMEM;
2490 
2491 	cmd = (struct wmi_dfs_phyerr_offload_cmd *)skb->data;
2492 	cmd->tlv_header =
2493 		FIELD_PREP(WMI_TLV_TAG,
2494 			   WMI_TAG_PDEV_DFS_PHYERR_OFFLOAD_ENABLE_CMD) |
2495 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2496 
2497 	cmd->pdev_id = pdev_id;
2498 
2499 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2500 		   "WMI dfs phy err offload enable pdev id %d\n", pdev_id);
2501 
2502 	ret = ath11k_wmi_cmd_send(wmi, skb,
2503 				  WMI_PDEV_DFS_PHYERR_OFFLOAD_ENABLE_CMDID);
2504 	if (ret) {
2505 		ath11k_warn(ar->ab,
2506 			    "failed to send WMI_PDEV_DFS_PHYERR_OFFLOAD_ENABLE cmd\n");
2507 		dev_kfree_skb(skb);
2508 	}
2509 
2510 	return ret;
2511 }
2512 
2513 int ath11k_wmi_delba_send(struct ath11k *ar, u32 vdev_id, const u8 *mac,
2514 			  u32 tid, u32 initiator, u32 reason)
2515 {
2516 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2517 	struct wmi_delba_send_cmd *cmd;
2518 	struct sk_buff *skb;
2519 	int ret;
2520 
2521 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2522 	if (!skb)
2523 		return -ENOMEM;
2524 
2525 	cmd = (struct wmi_delba_send_cmd *)skb->data;
2526 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_DELBA_SEND_CMD) |
2527 			FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2528 	cmd->vdev_id = vdev_id;
2529 	ether_addr_copy(cmd->peer_macaddr.addr, mac);
2530 	cmd->tid = tid;
2531 	cmd->initiator = initiator;
2532 	cmd->reasoncode = reason;
2533 
2534 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2535 		   "wmi delba send vdev_id 0x%X mac_addr %pM tid %u initiator %u reason %u\n",
2536 		   vdev_id, mac, tid, initiator, reason);
2537 
2538 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_DELBA_SEND_CMDID);
2539 
2540 	if (ret) {
2541 		ath11k_warn(ar->ab,
2542 			    "failed to send WMI_DELBA_SEND_CMDID cmd\n");
2543 		dev_kfree_skb(skb);
2544 	}
2545 
2546 	return ret;
2547 }
2548 
2549 int ath11k_wmi_addba_set_resp(struct ath11k *ar, u32 vdev_id, const u8 *mac,
2550 			      u32 tid, u32 status)
2551 {
2552 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2553 	struct wmi_addba_setresponse_cmd *cmd;
2554 	struct sk_buff *skb;
2555 	int ret;
2556 
2557 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2558 	if (!skb)
2559 		return -ENOMEM;
2560 
2561 	cmd = (struct wmi_addba_setresponse_cmd *)skb->data;
2562 	cmd->tlv_header =
2563 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ADDBA_SETRESPONSE_CMD) |
2564 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2565 	cmd->vdev_id = vdev_id;
2566 	ether_addr_copy(cmd->peer_macaddr.addr, mac);
2567 	cmd->tid = tid;
2568 	cmd->statuscode = status;
2569 
2570 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2571 		   "wmi addba set resp vdev_id 0x%X mac_addr %pM tid %u status %u\n",
2572 		   vdev_id, mac, tid, status);
2573 
2574 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_ADDBA_SET_RESP_CMDID);
2575 
2576 	if (ret) {
2577 		ath11k_warn(ar->ab,
2578 			    "failed to send WMI_ADDBA_SET_RESP_CMDID cmd\n");
2579 		dev_kfree_skb(skb);
2580 	}
2581 
2582 	return ret;
2583 }
2584 
2585 int ath11k_wmi_addba_send(struct ath11k *ar, u32 vdev_id, const u8 *mac,
2586 			  u32 tid, u32 buf_size)
2587 {
2588 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2589 	struct wmi_addba_send_cmd *cmd;
2590 	struct sk_buff *skb;
2591 	int ret;
2592 
2593 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2594 	if (!skb)
2595 		return -ENOMEM;
2596 
2597 	cmd = (struct wmi_addba_send_cmd *)skb->data;
2598 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ADDBA_SEND_CMD) |
2599 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2600 	cmd->vdev_id = vdev_id;
2601 	ether_addr_copy(cmd->peer_macaddr.addr, mac);
2602 	cmd->tid = tid;
2603 	cmd->buffersize = buf_size;
2604 
2605 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2606 		   "wmi addba send vdev_id 0x%X mac_addr %pM tid %u bufsize %u\n",
2607 		   vdev_id, mac, tid, buf_size);
2608 
2609 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_ADDBA_SEND_CMDID);
2610 
2611 	if (ret) {
2612 		ath11k_warn(ar->ab,
2613 			    "failed to send WMI_ADDBA_SEND_CMDID cmd\n");
2614 		dev_kfree_skb(skb);
2615 	}
2616 
2617 	return ret;
2618 }
2619 
2620 int ath11k_wmi_addba_clear_resp(struct ath11k *ar, u32 vdev_id, const u8 *mac)
2621 {
2622 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2623 	struct wmi_addba_clear_resp_cmd *cmd;
2624 	struct sk_buff *skb;
2625 	int ret;
2626 
2627 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2628 	if (!skb)
2629 		return -ENOMEM;
2630 
2631 	cmd = (struct wmi_addba_clear_resp_cmd *)skb->data;
2632 	cmd->tlv_header =
2633 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ADDBA_CLEAR_RESP_CMD) |
2634 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2635 	cmd->vdev_id = vdev_id;
2636 	ether_addr_copy(cmd->peer_macaddr.addr, mac);
2637 
2638 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2639 		   "wmi addba clear resp vdev_id 0x%X mac_addr %pM\n",
2640 		   vdev_id, mac);
2641 
2642 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_ADDBA_CLEAR_RESP_CMDID);
2643 
2644 	if (ret) {
2645 		ath11k_warn(ar->ab,
2646 			    "failed to send WMI_ADDBA_CLEAR_RESP_CMDID cmd\n");
2647 		dev_kfree_skb(skb);
2648 	}
2649 
2650 	return ret;
2651 }
2652 
2653 int ath11k_wmi_pdev_peer_pktlog_filter(struct ath11k *ar, u8 *addr, u8 enable)
2654 {
2655 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2656 	struct wmi_pdev_pktlog_filter_cmd *cmd;
2657 	struct wmi_pdev_pktlog_filter_info *info;
2658 	struct sk_buff *skb;
2659 	struct wmi_tlv *tlv;
2660 	void *ptr;
2661 	int ret, len;
2662 
2663 	len = sizeof(*cmd) + sizeof(*info) + TLV_HDR_SIZE;
2664 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2665 	if (!skb)
2666 		return -ENOMEM;
2667 
2668 	cmd = (struct wmi_pdev_pktlog_filter_cmd *)skb->data;
2669 
2670 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PEER_PKTLOG_FILTER_CMD) |
2671 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2672 
2673 	cmd->pdev_id = DP_HW2SW_MACID(ar->pdev->pdev_id);
2674 	cmd->num_mac = 1;
2675 	cmd->enable = enable;
2676 
2677 	ptr = skb->data + sizeof(*cmd);
2678 
2679 	tlv = ptr;
2680 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2681 		      FIELD_PREP(WMI_TLV_LEN, sizeof(*info));
2682 
2683 	ptr += TLV_HDR_SIZE;
2684 	info = ptr;
2685 
2686 	ether_addr_copy(info->peer_macaddr.addr, addr);
2687 	info->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PEER_PKTLOG_FILTER_INFO) |
2688 			   FIELD_PREP(WMI_TLV_LEN,
2689 				      sizeof(*info) - TLV_HDR_SIZE);
2690 
2691 	ret = ath11k_wmi_cmd_send(wmi, skb,
2692 				  WMI_PDEV_PKTLOG_FILTER_CMDID);
2693 	if (ret) {
2694 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_PKTLOG_ENABLE_CMDID\n");
2695 		dev_kfree_skb(skb);
2696 	}
2697 
2698 	return ret;
2699 }
2700 
2701 int
2702 ath11k_wmi_send_init_country_cmd(struct ath11k *ar,
2703 				 struct wmi_init_country_params init_cc_params)
2704 {
2705 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2706 	struct wmi_init_country_cmd *cmd;
2707 	struct sk_buff *skb;
2708 	int ret;
2709 
2710 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2711 	if (!skb)
2712 		return -ENOMEM;
2713 
2714 	cmd = (struct wmi_init_country_cmd *)skb->data;
2715 	cmd->tlv_header =
2716 		FIELD_PREP(WMI_TLV_TAG,
2717 			   WMI_TAG_SET_INIT_COUNTRY_CMD) |
2718 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2719 
2720 	cmd->pdev_id = ar->pdev->pdev_id;
2721 
2722 	switch (init_cc_params.flags) {
2723 	case ALPHA_IS_SET:
2724 		cmd->init_cc_type = WMI_COUNTRY_INFO_TYPE_ALPHA;
2725 		memcpy((u8 *)&cmd->cc_info.alpha2,
2726 		       init_cc_params.cc_info.alpha2, 3);
2727 		break;
2728 	case CC_IS_SET:
2729 		cmd->init_cc_type = WMI_COUNTRY_INFO_TYPE_COUNTRY_CODE;
2730 		cmd->cc_info.country_code = init_cc_params.cc_info.country_code;
2731 		break;
2732 	case REGDMN_IS_SET:
2733 		cmd->init_cc_type = WMI_COUNTRY_INFO_TYPE_REGDOMAIN;
2734 		cmd->cc_info.regdom_id = init_cc_params.cc_info.regdom_id;
2735 		break;
2736 	default:
2737 		ret = -EINVAL;
2738 		goto out;
2739 	}
2740 
2741 	ret = ath11k_wmi_cmd_send(wmi, skb,
2742 				  WMI_SET_INIT_COUNTRY_CMDID);
2743 
2744 out:
2745 	if (ret) {
2746 		ath11k_warn(ar->ab,
2747 			    "failed to send WMI_SET_INIT_COUNTRY CMD :%d\n",
2748 			    ret);
2749 		dev_kfree_skb(skb);
2750 	}
2751 
2752 	return ret;
2753 }
2754 
2755 int
2756 ath11k_wmi_send_thermal_mitigation_param_cmd(struct ath11k *ar,
2757 					     struct thermal_mitigation_params *param)
2758 {
2759 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2760 	struct wmi_therm_throt_config_request_cmd *cmd;
2761 	struct wmi_therm_throt_level_config_info *lvl_conf;
2762 	struct wmi_tlv *tlv;
2763 	struct sk_buff *skb;
2764 	int i, ret, len;
2765 
2766 	len = sizeof(*cmd) + TLV_HDR_SIZE +
2767 	      THERMAL_LEVELS * sizeof(struct wmi_therm_throt_level_config_info);
2768 
2769 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2770 	if (!skb)
2771 		return -ENOMEM;
2772 
2773 	cmd = (struct wmi_therm_throt_config_request_cmd *)skb->data;
2774 
2775 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_THERM_THROT_CONFIG_REQUEST) |
2776 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2777 
2778 	cmd->pdev_id = ar->pdev->pdev_id;
2779 	cmd->enable = param->enable;
2780 	cmd->dc = param->dc;
2781 	cmd->dc_per_event = param->dc_per_event;
2782 	cmd->therm_throt_levels = THERMAL_LEVELS;
2783 
2784 	tlv = (struct wmi_tlv *)(skb->data + sizeof(*cmd));
2785 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2786 		      FIELD_PREP(WMI_TLV_LEN,
2787 				 (THERMAL_LEVELS *
2788 				  sizeof(struct wmi_therm_throt_level_config_info)));
2789 
2790 	lvl_conf = (struct wmi_therm_throt_level_config_info *)(skb->data +
2791 								sizeof(*cmd) +
2792 								TLV_HDR_SIZE);
2793 	for (i = 0; i < THERMAL_LEVELS; i++) {
2794 		lvl_conf->tlv_header =
2795 			FIELD_PREP(WMI_TLV_TAG, WMI_TAG_THERM_THROT_LEVEL_CONFIG_INFO) |
2796 			FIELD_PREP(WMI_TLV_LEN, sizeof(*lvl_conf) - TLV_HDR_SIZE);
2797 
2798 		lvl_conf->temp_lwm = param->levelconf[i].tmplwm;
2799 		lvl_conf->temp_hwm = param->levelconf[i].tmphwm;
2800 		lvl_conf->dc_off_percent = param->levelconf[i].dcoffpercent;
2801 		lvl_conf->prio = param->levelconf[i].priority;
2802 		lvl_conf++;
2803 	}
2804 
2805 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_THERM_THROT_SET_CONF_CMDID);
2806 	if (ret) {
2807 		ath11k_warn(ar->ab, "failed to send THERM_THROT_SET_CONF cmd\n");
2808 		dev_kfree_skb(skb);
2809 	}
2810 
2811 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2812 		   "WMI vdev set thermal throt pdev_id %d enable %d dc %d dc_per_event %x levels %d\n",
2813 		   ar->pdev->pdev_id, param->enable, param->dc,
2814 		   param->dc_per_event, THERMAL_LEVELS);
2815 
2816 	return ret;
2817 }
2818 
2819 int ath11k_wmi_pdev_pktlog_enable(struct ath11k *ar, u32 pktlog_filter)
2820 {
2821 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2822 	struct wmi_pktlog_enable_cmd *cmd;
2823 	struct sk_buff *skb;
2824 	int ret;
2825 
2826 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2827 	if (!skb)
2828 		return -ENOMEM;
2829 
2830 	cmd = (struct wmi_pktlog_enable_cmd *)skb->data;
2831 
2832 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PKTLOG_ENABLE_CMD) |
2833 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2834 
2835 	cmd->pdev_id = DP_HW2SW_MACID(ar->pdev->pdev_id);
2836 	cmd->evlist = pktlog_filter;
2837 	cmd->enable = ATH11K_WMI_PKTLOG_ENABLE_FORCE;
2838 
2839 	ret = ath11k_wmi_cmd_send(wmi, skb,
2840 				  WMI_PDEV_PKTLOG_ENABLE_CMDID);
2841 	if (ret) {
2842 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_PKTLOG_ENABLE_CMDID\n");
2843 		dev_kfree_skb(skb);
2844 	}
2845 
2846 	return ret;
2847 }
2848 
2849 int ath11k_wmi_pdev_pktlog_disable(struct ath11k *ar)
2850 {
2851 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2852 	struct wmi_pktlog_disable_cmd *cmd;
2853 	struct sk_buff *skb;
2854 	int ret;
2855 
2856 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2857 	if (!skb)
2858 		return -ENOMEM;
2859 
2860 	cmd = (struct wmi_pktlog_disable_cmd *)skb->data;
2861 
2862 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PKTLOG_DISABLE_CMD) |
2863 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2864 
2865 	cmd->pdev_id = DP_HW2SW_MACID(ar->pdev->pdev_id);
2866 
2867 	ret = ath11k_wmi_cmd_send(wmi, skb,
2868 				  WMI_PDEV_PKTLOG_DISABLE_CMDID);
2869 	if (ret) {
2870 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_PKTLOG_ENABLE_CMDID\n");
2871 		dev_kfree_skb(skb);
2872 	}
2873 
2874 	return ret;
2875 }
2876 
2877 int
2878 ath11k_wmi_send_twt_enable_cmd(struct ath11k *ar, u32 pdev_id)
2879 {
2880 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2881 	struct ath11k_base *ab = wmi->wmi_ab->ab;
2882 	struct wmi_twt_enable_params_cmd *cmd;
2883 	struct sk_buff *skb;
2884 	int ret, len;
2885 
2886 	len = sizeof(*cmd);
2887 
2888 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2889 	if (!skb)
2890 		return -ENOMEM;
2891 
2892 	cmd = (struct wmi_twt_enable_params_cmd *)skb->data;
2893 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_TWT_ENABLE_CMD) |
2894 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2895 	cmd->pdev_id = pdev_id;
2896 	cmd->sta_cong_timer_ms = ATH11K_TWT_DEF_STA_CONG_TIMER_MS;
2897 	cmd->default_slot_size = ATH11K_TWT_DEF_DEFAULT_SLOT_SIZE;
2898 	cmd->congestion_thresh_setup = ATH11K_TWT_DEF_CONGESTION_THRESH_SETUP;
2899 	cmd->congestion_thresh_teardown =
2900 		ATH11K_TWT_DEF_CONGESTION_THRESH_TEARDOWN;
2901 	cmd->congestion_thresh_critical =
2902 		ATH11K_TWT_DEF_CONGESTION_THRESH_CRITICAL;
2903 	cmd->interference_thresh_teardown =
2904 		ATH11K_TWT_DEF_INTERFERENCE_THRESH_TEARDOWN;
2905 	cmd->interference_thresh_setup =
2906 		ATH11K_TWT_DEF_INTERFERENCE_THRESH_SETUP;
2907 	cmd->min_no_sta_setup = ATH11K_TWT_DEF_MIN_NO_STA_SETUP;
2908 	cmd->min_no_sta_teardown = ATH11K_TWT_DEF_MIN_NO_STA_TEARDOWN;
2909 	cmd->no_of_bcast_mcast_slots = ATH11K_TWT_DEF_NO_OF_BCAST_MCAST_SLOTS;
2910 	cmd->min_no_twt_slots = ATH11K_TWT_DEF_MIN_NO_TWT_SLOTS;
2911 	cmd->max_no_sta_twt = ATH11K_TWT_DEF_MAX_NO_STA_TWT;
2912 	cmd->mode_check_interval = ATH11K_TWT_DEF_MODE_CHECK_INTERVAL;
2913 	cmd->add_sta_slot_interval = ATH11K_TWT_DEF_ADD_STA_SLOT_INTERVAL;
2914 	cmd->remove_sta_slot_interval =
2915 		ATH11K_TWT_DEF_REMOVE_STA_SLOT_INTERVAL;
2916 	/* TODO add MBSSID support */
2917 	cmd->mbss_support = 0;
2918 
2919 	ret = ath11k_wmi_cmd_send(wmi, skb,
2920 				  WMI_TWT_ENABLE_CMDID);
2921 	if (ret) {
2922 		ath11k_warn(ab, "Failed to send WMI_TWT_ENABLE_CMDID");
2923 		dev_kfree_skb(skb);
2924 	}
2925 	return ret;
2926 }
2927 
2928 int
2929 ath11k_wmi_send_twt_disable_cmd(struct ath11k *ar, u32 pdev_id)
2930 {
2931 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2932 	struct ath11k_base *ab = wmi->wmi_ab->ab;
2933 	struct wmi_twt_disable_params_cmd *cmd;
2934 	struct sk_buff *skb;
2935 	int ret, len;
2936 
2937 	len = sizeof(*cmd);
2938 
2939 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2940 	if (!skb)
2941 		return -ENOMEM;
2942 
2943 	cmd = (struct wmi_twt_disable_params_cmd *)skb->data;
2944 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_TWT_DISABLE_CMD) |
2945 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2946 	cmd->pdev_id = pdev_id;
2947 
2948 	ret = ath11k_wmi_cmd_send(wmi, skb,
2949 				  WMI_TWT_DISABLE_CMDID);
2950 	if (ret) {
2951 		ath11k_warn(ab, "Failed to send WMI_TWT_DISABLE_CMDID");
2952 		dev_kfree_skb(skb);
2953 	}
2954 	return ret;
2955 }
2956 
2957 int
2958 ath11k_wmi_send_obss_spr_cmd(struct ath11k *ar, u32 vdev_id,
2959 			     struct ieee80211_he_obss_pd *he_obss_pd)
2960 {
2961 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2962 	struct ath11k_base *ab = wmi->wmi_ab->ab;
2963 	struct wmi_obss_spatial_reuse_params_cmd *cmd;
2964 	struct sk_buff *skb;
2965 	int ret, len;
2966 
2967 	len = sizeof(*cmd);
2968 
2969 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2970 	if (!skb)
2971 		return -ENOMEM;
2972 
2973 	cmd = (struct wmi_obss_spatial_reuse_params_cmd *)skb->data;
2974 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2975 				     WMI_TAG_OBSS_SPATIAL_REUSE_SET_CMD) |
2976 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2977 	cmd->vdev_id = vdev_id;
2978 	cmd->enable = he_obss_pd->enable;
2979 	cmd->obss_min = he_obss_pd->min_offset;
2980 	cmd->obss_max = he_obss_pd->max_offset;
2981 
2982 	ret = ath11k_wmi_cmd_send(wmi, skb,
2983 				  WMI_PDEV_OBSS_PD_SPATIAL_REUSE_CMDID);
2984 	if (ret) {
2985 		ath11k_warn(ab,
2986 			    "Failed to send WMI_PDEV_OBSS_PD_SPATIAL_REUSE_CMDID");
2987 		dev_kfree_skb(skb);
2988 	}
2989 	return ret;
2990 }
2991 
2992 int
2993 ath11k_wmi_pdev_set_srg_bss_color_bitmap(struct ath11k *ar, u32 *bitmap)
2994 {
2995 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2996 	struct ath11k_base *ab = wmi->wmi_ab->ab;
2997 	struct wmi_pdev_obss_pd_bitmap_cmd *cmd;
2998 	struct sk_buff *skb;
2999 	int ret, len;
3000 
3001 	len = sizeof(*cmd);
3002 
3003 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3004 	if (!skb)
3005 		return -ENOMEM;
3006 
3007 	cmd = (struct wmi_pdev_obss_pd_bitmap_cmd *)skb->data;
3008 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3009 				     WMI_TAG_PDEV_SRG_BSS_COLOR_BITMAP_CMD) |
3010 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3011 	cmd->pdev_id = ar->pdev->pdev_id;
3012 	memcpy(cmd->bitmap, bitmap, sizeof(cmd->bitmap));
3013 
3014 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3015 		   "obss pd pdev_id %d bss color bitmap %08x %08x\n",
3016 		   cmd->pdev_id, cmd->bitmap[0], cmd->bitmap[1]);
3017 
3018 	ret = ath11k_wmi_cmd_send(wmi, skb,
3019 				  WMI_PDEV_SET_SRG_BSS_COLOR_BITMAP_CMDID);
3020 	if (ret) {
3021 		ath11k_warn(ab,
3022 			    "failed to send WMI_PDEV_SET_SRG_BSS_COLOR_BITMAP_CMDID");
3023 		dev_kfree_skb(skb);
3024 	}
3025 
3026 	return ret;
3027 }
3028 
3029 int
3030 ath11k_wmi_pdev_set_srg_patial_bssid_bitmap(struct ath11k *ar, u32 *bitmap)
3031 {
3032 	struct ath11k_pdev_wmi *wmi = ar->wmi;
3033 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3034 	struct wmi_pdev_obss_pd_bitmap_cmd *cmd;
3035 	struct sk_buff *skb;
3036 	int ret, len;
3037 
3038 	len = sizeof(*cmd);
3039 
3040 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3041 	if (!skb)
3042 		return -ENOMEM;
3043 
3044 	cmd = (struct wmi_pdev_obss_pd_bitmap_cmd *)skb->data;
3045 	cmd->tlv_header =
3046 		FIELD_PREP(WMI_TLV_TAG,
3047 			   WMI_TAG_PDEV_SRG_PARTIAL_BSSID_BITMAP_CMD) |
3048 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3049 	cmd->pdev_id = ar->pdev->pdev_id;
3050 	memcpy(cmd->bitmap, bitmap, sizeof(cmd->bitmap));
3051 
3052 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3053 		   "obss pd pdev_id %d partial bssid bitmap %08x %08x\n",
3054 		   cmd->pdev_id, cmd->bitmap[0], cmd->bitmap[1]);
3055 
3056 	ret = ath11k_wmi_cmd_send(wmi, skb,
3057 				  WMI_PDEV_SET_SRG_PARTIAL_BSSID_BITMAP_CMDID);
3058 	if (ret) {
3059 		ath11k_warn(ab,
3060 			    "failed to send WMI_PDEV_SET_SRG_PARTIAL_BSSID_BITMAP_CMDID");
3061 		dev_kfree_skb(skb);
3062 	}
3063 
3064 	return ret;
3065 }
3066 
3067 int
3068 ath11k_wmi_pdev_srg_obss_color_enable_bitmap(struct ath11k *ar, u32 *bitmap)
3069 {
3070 	struct ath11k_pdev_wmi *wmi = ar->wmi;
3071 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3072 	struct wmi_pdev_obss_pd_bitmap_cmd *cmd;
3073 	struct sk_buff *skb;
3074 	int ret, len;
3075 
3076 	len = sizeof(*cmd);
3077 
3078 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3079 	if (!skb)
3080 		return -ENOMEM;
3081 
3082 	cmd = (struct wmi_pdev_obss_pd_bitmap_cmd *)skb->data;
3083 	cmd->tlv_header =
3084 		FIELD_PREP(WMI_TLV_TAG,
3085 			   WMI_TAG_PDEV_SRG_OBSS_COLOR_ENABLE_BITMAP_CMD) |
3086 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3087 	cmd->pdev_id = ar->pdev->pdev_id;
3088 	memcpy(cmd->bitmap, bitmap, sizeof(cmd->bitmap));
3089 
3090 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3091 		   "obss pd srg pdev_id %d bss color enable bitmap %08x %08x\n",
3092 		   cmd->pdev_id, cmd->bitmap[0], cmd->bitmap[1]);
3093 
3094 	ret = ath11k_wmi_cmd_send(wmi, skb,
3095 				  WMI_PDEV_SET_SRG_OBSS_COLOR_ENABLE_BITMAP_CMDID);
3096 	if (ret) {
3097 		ath11k_warn(ab,
3098 			    "failed to send WMI_PDEV_SET_SRG_OBSS_COLOR_ENABLE_BITMAP_CMDID");
3099 		dev_kfree_skb(skb);
3100 	}
3101 
3102 	return ret;
3103 }
3104 
3105 int
3106 ath11k_wmi_pdev_srg_obss_bssid_enable_bitmap(struct ath11k *ar, u32 *bitmap)
3107 {
3108 	struct ath11k_pdev_wmi *wmi = ar->wmi;
3109 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3110 	struct wmi_pdev_obss_pd_bitmap_cmd *cmd;
3111 	struct sk_buff *skb;
3112 	int ret, len;
3113 
3114 	len = sizeof(*cmd);
3115 
3116 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3117 	if (!skb)
3118 		return -ENOMEM;
3119 
3120 	cmd = (struct wmi_pdev_obss_pd_bitmap_cmd *)skb->data;
3121 	cmd->tlv_header =
3122 		FIELD_PREP(WMI_TLV_TAG,
3123 			   WMI_TAG_PDEV_SRG_OBSS_BSSID_ENABLE_BITMAP_CMD) |
3124 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3125 	cmd->pdev_id = ar->pdev->pdev_id;
3126 	memcpy(cmd->bitmap, bitmap, sizeof(cmd->bitmap));
3127 
3128 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3129 		   "obss pd srg pdev_id %d bssid enable bitmap %08x %08x\n",
3130 		   cmd->pdev_id, cmd->bitmap[0], cmd->bitmap[1]);
3131 
3132 	ret = ath11k_wmi_cmd_send(wmi, skb,
3133 				  WMI_PDEV_SET_SRG_OBSS_BSSID_ENABLE_BITMAP_CMDID);
3134 	if (ret) {
3135 		ath11k_warn(ab,
3136 			    "failed to send WMI_PDEV_SET_SRG_OBSS_BSSID_ENABLE_BITMAP_CMDID");
3137 		dev_kfree_skb(skb);
3138 	}
3139 
3140 	return ret;
3141 }
3142 
3143 int
3144 ath11k_wmi_pdev_non_srg_obss_color_enable_bitmap(struct ath11k *ar, u32 *bitmap)
3145 {
3146 	struct ath11k_pdev_wmi *wmi = ar->wmi;
3147 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3148 	struct wmi_pdev_obss_pd_bitmap_cmd *cmd;
3149 	struct sk_buff *skb;
3150 	int ret, len;
3151 
3152 	len = sizeof(*cmd);
3153 
3154 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3155 	if (!skb)
3156 		return -ENOMEM;
3157 
3158 	cmd = (struct wmi_pdev_obss_pd_bitmap_cmd *)skb->data;
3159 	cmd->tlv_header =
3160 		FIELD_PREP(WMI_TLV_TAG,
3161 			   WMI_TAG_PDEV_NON_SRG_OBSS_COLOR_ENABLE_BITMAP_CMD) |
3162 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3163 	cmd->pdev_id = ar->pdev->pdev_id;
3164 	memcpy(cmd->bitmap, bitmap, sizeof(cmd->bitmap));
3165 
3166 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3167 		   "obss pd non_srg pdev_id %d bss color enable bitmap %08x %08x\n",
3168 		   cmd->pdev_id, cmd->bitmap[0], cmd->bitmap[1]);
3169 
3170 	ret = ath11k_wmi_cmd_send(wmi, skb,
3171 				  WMI_PDEV_SET_NON_SRG_OBSS_COLOR_ENABLE_BITMAP_CMDID);
3172 	if (ret) {
3173 		ath11k_warn(ab,
3174 			    "failed to send WMI_PDEV_SET_NON_SRG_OBSS_COLOR_ENABLE_BITMAP_CMDID");
3175 		dev_kfree_skb(skb);
3176 	}
3177 
3178 	return ret;
3179 }
3180 
3181 int
3182 ath11k_wmi_pdev_non_srg_obss_bssid_enable_bitmap(struct ath11k *ar, u32 *bitmap)
3183 {
3184 	struct ath11k_pdev_wmi *wmi = ar->wmi;
3185 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3186 	struct wmi_pdev_obss_pd_bitmap_cmd *cmd;
3187 	struct sk_buff *skb;
3188 	int ret, len;
3189 
3190 	len = sizeof(*cmd);
3191 
3192 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3193 	if (!skb)
3194 		return -ENOMEM;
3195 
3196 	cmd = (struct wmi_pdev_obss_pd_bitmap_cmd *)skb->data;
3197 	cmd->tlv_header =
3198 		FIELD_PREP(WMI_TLV_TAG,
3199 			   WMI_TAG_PDEV_NON_SRG_OBSS_BSSID_ENABLE_BITMAP_CMD) |
3200 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3201 	cmd->pdev_id = ar->pdev->pdev_id;
3202 	memcpy(cmd->bitmap, bitmap, sizeof(cmd->bitmap));
3203 
3204 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3205 		   "obss pd non_srg pdev_id %d bssid enable bitmap %08x %08x\n",
3206 		   cmd->pdev_id, cmd->bitmap[0], cmd->bitmap[1]);
3207 
3208 	ret = ath11k_wmi_cmd_send(wmi, skb,
3209 				  WMI_PDEV_SET_NON_SRG_OBSS_BSSID_ENABLE_BITMAP_CMDID);
3210 	if (ret) {
3211 		ath11k_warn(ab,
3212 			    "failed to send WMI_PDEV_SET_NON_SRG_OBSS_BSSID_ENABLE_BITMAP_CMDID");
3213 		dev_kfree_skb(skb);
3214 	}
3215 
3216 	return ret;
3217 }
3218 
3219 int
3220 ath11k_wmi_send_obss_color_collision_cfg_cmd(struct ath11k *ar, u32 vdev_id,
3221 					     u8 bss_color, u32 period,
3222 					     bool enable)
3223 {
3224 	struct ath11k_pdev_wmi *wmi = ar->wmi;
3225 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3226 	struct wmi_obss_color_collision_cfg_params_cmd *cmd;
3227 	struct sk_buff *skb;
3228 	int ret, len;
3229 
3230 	len = sizeof(*cmd);
3231 
3232 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3233 	if (!skb)
3234 		return -ENOMEM;
3235 
3236 	cmd = (struct wmi_obss_color_collision_cfg_params_cmd *)skb->data;
3237 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3238 				     WMI_TAG_OBSS_COLOR_COLLISION_DET_CONFIG) |
3239 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3240 	cmd->vdev_id = vdev_id;
3241 	cmd->evt_type = enable ? ATH11K_OBSS_COLOR_COLLISION_DETECTION :
3242 				 ATH11K_OBSS_COLOR_COLLISION_DETECTION_DISABLE;
3243 	cmd->current_bss_color = bss_color;
3244 	cmd->detection_period_ms = period;
3245 	cmd->scan_period_ms = ATH11K_BSS_COLOR_COLLISION_SCAN_PERIOD_MS;
3246 	cmd->free_slot_expiry_time_ms = 0;
3247 	cmd->flags = 0;
3248 
3249 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3250 		   "wmi_send_obss_color_collision_cfg id %d type %d bss_color %d detect_period %d scan_period %d\n",
3251 		   cmd->vdev_id, cmd->evt_type, cmd->current_bss_color,
3252 		   cmd->detection_period_ms, cmd->scan_period_ms);
3253 
3254 	ret = ath11k_wmi_cmd_send(wmi, skb,
3255 				  WMI_OBSS_COLOR_COLLISION_DET_CONFIG_CMDID);
3256 	if (ret) {
3257 		ath11k_warn(ab, "Failed to send WMI_OBSS_COLOR_COLLISION_DET_CONFIG_CMDID");
3258 		dev_kfree_skb(skb);
3259 	}
3260 	return ret;
3261 }
3262 
3263 int ath11k_wmi_send_bss_color_change_enable_cmd(struct ath11k *ar, u32 vdev_id,
3264 						bool enable)
3265 {
3266 	struct ath11k_pdev_wmi *wmi = ar->wmi;
3267 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3268 	struct wmi_bss_color_change_enable_params_cmd *cmd;
3269 	struct sk_buff *skb;
3270 	int ret, len;
3271 
3272 	len = sizeof(*cmd);
3273 
3274 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3275 	if (!skb)
3276 		return -ENOMEM;
3277 
3278 	cmd = (struct wmi_bss_color_change_enable_params_cmd *)skb->data;
3279 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_BSS_COLOR_CHANGE_ENABLE) |
3280 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3281 	cmd->vdev_id = vdev_id;
3282 	cmd->enable = enable ? 1 : 0;
3283 
3284 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3285 		   "wmi_send_bss_color_change_enable id %d enable %d\n",
3286 		   cmd->vdev_id, cmd->enable);
3287 
3288 	ret = ath11k_wmi_cmd_send(wmi, skb,
3289 				  WMI_BSS_COLOR_CHANGE_ENABLE_CMDID);
3290 	if (ret) {
3291 		ath11k_warn(ab, "Failed to send WMI_BSS_COLOR_CHANGE_ENABLE_CMDID");
3292 		dev_kfree_skb(skb);
3293 	}
3294 	return ret;
3295 }
3296 
3297 int ath11k_wmi_fils_discovery_tmpl(struct ath11k *ar, u32 vdev_id,
3298 				   struct sk_buff *tmpl)
3299 {
3300 	struct wmi_tlv *tlv;
3301 	struct sk_buff *skb;
3302 	void *ptr;
3303 	int ret, len;
3304 	size_t aligned_len;
3305 	struct wmi_fils_discovery_tmpl_cmd *cmd;
3306 
3307 	aligned_len = roundup(tmpl->len, 4);
3308 	len = sizeof(*cmd) + TLV_HDR_SIZE + aligned_len;
3309 
3310 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3311 		   "WMI vdev %i set FILS discovery template\n", vdev_id);
3312 
3313 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, len);
3314 	if (!skb)
3315 		return -ENOMEM;
3316 
3317 	cmd = (struct wmi_fils_discovery_tmpl_cmd *)skb->data;
3318 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3319 				     WMI_TAG_FILS_DISCOVERY_TMPL_CMD) |
3320 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3321 	cmd->vdev_id = vdev_id;
3322 	cmd->buf_len = tmpl->len;
3323 	ptr = skb->data + sizeof(*cmd);
3324 
3325 	tlv = ptr;
3326 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
3327 		      FIELD_PREP(WMI_TLV_LEN, aligned_len);
3328 	memcpy(tlv->value, tmpl->data, tmpl->len);
3329 
3330 	ret = ath11k_wmi_cmd_send(ar->wmi, skb, WMI_FILS_DISCOVERY_TMPL_CMDID);
3331 	if (ret) {
3332 		ath11k_warn(ar->ab,
3333 			    "WMI vdev %i failed to send FILS discovery template command\n",
3334 			    vdev_id);
3335 		dev_kfree_skb(skb);
3336 	}
3337 	return ret;
3338 }
3339 
3340 int ath11k_wmi_probe_resp_tmpl(struct ath11k *ar, u32 vdev_id,
3341 			       struct sk_buff *tmpl)
3342 {
3343 	struct wmi_probe_tmpl_cmd *cmd;
3344 	struct wmi_bcn_prb_info *probe_info;
3345 	struct wmi_tlv *tlv;
3346 	struct sk_buff *skb;
3347 	void *ptr;
3348 	int ret, len;
3349 	size_t aligned_len = roundup(tmpl->len, 4);
3350 
3351 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3352 		   "WMI vdev %i set probe response template\n", vdev_id);
3353 
3354 	len = sizeof(*cmd) + sizeof(*probe_info) + TLV_HDR_SIZE + aligned_len;
3355 
3356 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, len);
3357 	if (!skb)
3358 		return -ENOMEM;
3359 
3360 	cmd = (struct wmi_probe_tmpl_cmd *)skb->data;
3361 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PRB_TMPL_CMD) |
3362 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3363 	cmd->vdev_id = vdev_id;
3364 	cmd->buf_len = tmpl->len;
3365 
3366 	ptr = skb->data + sizeof(*cmd);
3367 
3368 	probe_info = ptr;
3369 	len = sizeof(*probe_info);
3370 	probe_info->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3371 					    WMI_TAG_BCN_PRB_INFO) |
3372 				 FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3373 	probe_info->caps = 0;
3374 	probe_info->erp = 0;
3375 
3376 	ptr += sizeof(*probe_info);
3377 
3378 	tlv = ptr;
3379 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
3380 		      FIELD_PREP(WMI_TLV_LEN, aligned_len);
3381 	memcpy(tlv->value, tmpl->data, tmpl->len);
3382 
3383 	ret = ath11k_wmi_cmd_send(ar->wmi, skb, WMI_PRB_TMPL_CMDID);
3384 	if (ret) {
3385 		ath11k_warn(ar->ab,
3386 			    "WMI vdev %i failed to send probe response template command\n",
3387 			    vdev_id);
3388 		dev_kfree_skb(skb);
3389 	}
3390 	return ret;
3391 }
3392 
3393 int ath11k_wmi_fils_discovery(struct ath11k *ar, u32 vdev_id, u32 interval,
3394 			      bool unsol_bcast_probe_resp_enabled)
3395 {
3396 	struct sk_buff *skb;
3397 	int ret, len;
3398 	struct wmi_fils_discovery_cmd *cmd;
3399 
3400 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3401 		   "WMI vdev %i set %s interval to %u TU\n",
3402 		   vdev_id, unsol_bcast_probe_resp_enabled ?
3403 		   "unsolicited broadcast probe response" : "FILS discovery",
3404 		   interval);
3405 
3406 	len = sizeof(*cmd);
3407 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, len);
3408 	if (!skb)
3409 		return -ENOMEM;
3410 
3411 	cmd = (struct wmi_fils_discovery_cmd *)skb->data;
3412 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ENABLE_FILS_CMD) |
3413 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3414 	cmd->vdev_id = vdev_id;
3415 	cmd->interval = interval;
3416 	cmd->config = unsol_bcast_probe_resp_enabled;
3417 
3418 	ret = ath11k_wmi_cmd_send(ar->wmi, skb, WMI_ENABLE_FILS_CMDID);
3419 	if (ret) {
3420 		ath11k_warn(ar->ab,
3421 			    "WMI vdev %i failed to send FILS discovery enable/disable command\n",
3422 			    vdev_id);
3423 		dev_kfree_skb(skb);
3424 	}
3425 	return ret;
3426 }
3427 
3428 static void
3429 ath11k_fill_band_to_mac_param(struct ath11k_base  *soc,
3430 			      struct wmi_host_pdev_band_to_mac *band_to_mac)
3431 {
3432 	u8 i;
3433 	struct ath11k_hal_reg_capabilities_ext *hal_reg_cap;
3434 	struct ath11k_pdev *pdev;
3435 
3436 	for (i = 0; i < soc->num_radios; i++) {
3437 		pdev = &soc->pdevs[i];
3438 		hal_reg_cap = &soc->hal_reg_cap[i];
3439 		band_to_mac[i].pdev_id = pdev->pdev_id;
3440 
3441 		switch (pdev->cap.supported_bands) {
3442 		case WMI_HOST_WLAN_2G_5G_CAP:
3443 			band_to_mac[i].start_freq = hal_reg_cap->low_2ghz_chan;
3444 			band_to_mac[i].end_freq = hal_reg_cap->high_5ghz_chan;
3445 			break;
3446 		case WMI_HOST_WLAN_2G_CAP:
3447 			band_to_mac[i].start_freq = hal_reg_cap->low_2ghz_chan;
3448 			band_to_mac[i].end_freq = hal_reg_cap->high_2ghz_chan;
3449 			break;
3450 		case WMI_HOST_WLAN_5G_CAP:
3451 			band_to_mac[i].start_freq = hal_reg_cap->low_5ghz_chan;
3452 			band_to_mac[i].end_freq = hal_reg_cap->high_5ghz_chan;
3453 			break;
3454 		default:
3455 			break;
3456 		}
3457 	}
3458 }
3459 
3460 static void
3461 ath11k_wmi_copy_resource_config(struct wmi_resource_config *wmi_cfg,
3462 				struct target_resource_config *tg_cfg)
3463 {
3464 	wmi_cfg->num_vdevs = tg_cfg->num_vdevs;
3465 	wmi_cfg->num_peers = tg_cfg->num_peers;
3466 	wmi_cfg->num_offload_peers = tg_cfg->num_offload_peers;
3467 	wmi_cfg->num_offload_reorder_buffs = tg_cfg->num_offload_reorder_buffs;
3468 	wmi_cfg->num_peer_keys = tg_cfg->num_peer_keys;
3469 	wmi_cfg->num_tids = tg_cfg->num_tids;
3470 	wmi_cfg->ast_skid_limit = tg_cfg->ast_skid_limit;
3471 	wmi_cfg->tx_chain_mask = tg_cfg->tx_chain_mask;
3472 	wmi_cfg->rx_chain_mask = tg_cfg->rx_chain_mask;
3473 	wmi_cfg->rx_timeout_pri[0] = tg_cfg->rx_timeout_pri[0];
3474 	wmi_cfg->rx_timeout_pri[1] = tg_cfg->rx_timeout_pri[1];
3475 	wmi_cfg->rx_timeout_pri[2] = tg_cfg->rx_timeout_pri[2];
3476 	wmi_cfg->rx_timeout_pri[3] = tg_cfg->rx_timeout_pri[3];
3477 	wmi_cfg->rx_decap_mode = tg_cfg->rx_decap_mode;
3478 	wmi_cfg->scan_max_pending_req = tg_cfg->scan_max_pending_req;
3479 	wmi_cfg->bmiss_offload_max_vdev = tg_cfg->bmiss_offload_max_vdev;
3480 	wmi_cfg->roam_offload_max_vdev = tg_cfg->roam_offload_max_vdev;
3481 	wmi_cfg->roam_offload_max_ap_profiles =
3482 		tg_cfg->roam_offload_max_ap_profiles;
3483 	wmi_cfg->num_mcast_groups = tg_cfg->num_mcast_groups;
3484 	wmi_cfg->num_mcast_table_elems = tg_cfg->num_mcast_table_elems;
3485 	wmi_cfg->mcast2ucast_mode = tg_cfg->mcast2ucast_mode;
3486 	wmi_cfg->tx_dbg_log_size = tg_cfg->tx_dbg_log_size;
3487 	wmi_cfg->num_wds_entries = tg_cfg->num_wds_entries;
3488 	wmi_cfg->dma_burst_size = tg_cfg->dma_burst_size;
3489 	wmi_cfg->mac_aggr_delim = tg_cfg->mac_aggr_delim;
3490 	wmi_cfg->rx_skip_defrag_timeout_dup_detection_check =
3491 		tg_cfg->rx_skip_defrag_timeout_dup_detection_check;
3492 	wmi_cfg->vow_config = tg_cfg->vow_config;
3493 	wmi_cfg->gtk_offload_max_vdev = tg_cfg->gtk_offload_max_vdev;
3494 	wmi_cfg->num_msdu_desc = tg_cfg->num_msdu_desc;
3495 	wmi_cfg->max_frag_entries = tg_cfg->max_frag_entries;
3496 	wmi_cfg->num_tdls_vdevs = tg_cfg->num_tdls_vdevs;
3497 	wmi_cfg->num_tdls_conn_table_entries =
3498 		tg_cfg->num_tdls_conn_table_entries;
3499 	wmi_cfg->beacon_tx_offload_max_vdev =
3500 		tg_cfg->beacon_tx_offload_max_vdev;
3501 	wmi_cfg->num_multicast_filter_entries =
3502 		tg_cfg->num_multicast_filter_entries;
3503 	wmi_cfg->num_wow_filters = tg_cfg->num_wow_filters;
3504 	wmi_cfg->num_keep_alive_pattern = tg_cfg->num_keep_alive_pattern;
3505 	wmi_cfg->keep_alive_pattern_size = tg_cfg->keep_alive_pattern_size;
3506 	wmi_cfg->max_tdls_concurrent_sleep_sta =
3507 		tg_cfg->max_tdls_concurrent_sleep_sta;
3508 	wmi_cfg->max_tdls_concurrent_buffer_sta =
3509 		tg_cfg->max_tdls_concurrent_buffer_sta;
3510 	wmi_cfg->wmi_send_separate = tg_cfg->wmi_send_separate;
3511 	wmi_cfg->num_ocb_vdevs = tg_cfg->num_ocb_vdevs;
3512 	wmi_cfg->num_ocb_channels = tg_cfg->num_ocb_channels;
3513 	wmi_cfg->num_ocb_schedules = tg_cfg->num_ocb_schedules;
3514 	wmi_cfg->bpf_instruction_size = tg_cfg->bpf_instruction_size;
3515 	wmi_cfg->max_bssid_rx_filters = tg_cfg->max_bssid_rx_filters;
3516 	wmi_cfg->use_pdev_id = tg_cfg->use_pdev_id;
3517 	wmi_cfg->flag1 = tg_cfg->flag1;
3518 	wmi_cfg->peer_map_unmap_v2_support = tg_cfg->peer_map_unmap_v2_support;
3519 	wmi_cfg->sched_params = tg_cfg->sched_params;
3520 	wmi_cfg->twt_ap_pdev_count = tg_cfg->twt_ap_pdev_count;
3521 	wmi_cfg->twt_ap_sta_count = tg_cfg->twt_ap_sta_count;
3522 }
3523 
3524 static int ath11k_init_cmd_send(struct ath11k_pdev_wmi *wmi,
3525 				struct wmi_init_cmd_param *param)
3526 {
3527 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3528 	struct sk_buff *skb;
3529 	struct wmi_init_cmd *cmd;
3530 	struct wmi_resource_config *cfg;
3531 	struct wmi_pdev_set_hw_mode_cmd_param *hw_mode;
3532 	struct wmi_pdev_band_to_mac *band_to_mac;
3533 	struct wlan_host_mem_chunk *host_mem_chunks;
3534 	struct wmi_tlv *tlv;
3535 	size_t ret, len;
3536 	void *ptr;
3537 	u32 hw_mode_len = 0;
3538 	u16 idx;
3539 
3540 	if (param->hw_mode_id != WMI_HOST_HW_MODE_MAX)
3541 		hw_mode_len = sizeof(*hw_mode) + TLV_HDR_SIZE +
3542 			      (param->num_band_to_mac * sizeof(*band_to_mac));
3543 
3544 	len = sizeof(*cmd) + TLV_HDR_SIZE + sizeof(*cfg) + hw_mode_len +
3545 	      (param->num_mem_chunks ? (sizeof(*host_mem_chunks) * WMI_MAX_MEM_REQS) : 0);
3546 
3547 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3548 	if (!skb)
3549 		return -ENOMEM;
3550 
3551 	cmd = (struct wmi_init_cmd *)skb->data;
3552 
3553 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_INIT_CMD) |
3554 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3555 
3556 	ptr = skb->data + sizeof(*cmd);
3557 	cfg = ptr;
3558 
3559 	ath11k_wmi_copy_resource_config(cfg, param->res_cfg);
3560 
3561 	cfg->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_RESOURCE_CONFIG) |
3562 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cfg) - TLV_HDR_SIZE);
3563 
3564 	ptr += sizeof(*cfg);
3565 	host_mem_chunks = ptr + TLV_HDR_SIZE;
3566 	len = sizeof(struct wlan_host_mem_chunk);
3567 
3568 	for (idx = 0; idx < param->num_mem_chunks; ++idx) {
3569 		host_mem_chunks[idx].tlv_header =
3570 				FIELD_PREP(WMI_TLV_TAG,
3571 					   WMI_TAG_WLAN_HOST_MEMORY_CHUNK) |
3572 				FIELD_PREP(WMI_TLV_LEN, len);
3573 
3574 		host_mem_chunks[idx].ptr = param->mem_chunks[idx].paddr;
3575 		host_mem_chunks[idx].size = param->mem_chunks[idx].len;
3576 		host_mem_chunks[idx].req_id = param->mem_chunks[idx].req_id;
3577 
3578 		ath11k_dbg(ab, ATH11K_DBG_WMI,
3579 			   "WMI host mem chunk req_id %d paddr 0x%llx len %d\n",
3580 			   param->mem_chunks[idx].req_id,
3581 			   (u64)param->mem_chunks[idx].paddr,
3582 			   param->mem_chunks[idx].len);
3583 	}
3584 	cmd->num_host_mem_chunks = param->num_mem_chunks;
3585 	len = sizeof(struct wlan_host_mem_chunk) * param->num_mem_chunks;
3586 
3587 	/* num_mem_chunks is zero */
3588 	tlv = ptr;
3589 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
3590 		      FIELD_PREP(WMI_TLV_LEN, len);
3591 	ptr += TLV_HDR_SIZE + len;
3592 
3593 	if (param->hw_mode_id != WMI_HOST_HW_MODE_MAX) {
3594 		hw_mode = (struct wmi_pdev_set_hw_mode_cmd_param *)ptr;
3595 		hw_mode->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3596 						 WMI_TAG_PDEV_SET_HW_MODE_CMD) |
3597 				      FIELD_PREP(WMI_TLV_LEN,
3598 						 sizeof(*hw_mode) - TLV_HDR_SIZE);
3599 
3600 		hw_mode->hw_mode_index = param->hw_mode_id;
3601 		hw_mode->num_band_to_mac = param->num_band_to_mac;
3602 
3603 		ptr += sizeof(*hw_mode);
3604 
3605 		len = param->num_band_to_mac * sizeof(*band_to_mac);
3606 		tlv = ptr;
3607 		tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
3608 			      FIELD_PREP(WMI_TLV_LEN, len);
3609 
3610 		ptr += TLV_HDR_SIZE;
3611 		len = sizeof(*band_to_mac);
3612 
3613 		for (idx = 0; idx < param->num_band_to_mac; idx++) {
3614 			band_to_mac = (void *)ptr;
3615 
3616 			band_to_mac->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3617 							     WMI_TAG_PDEV_BAND_TO_MAC) |
3618 						  FIELD_PREP(WMI_TLV_LEN,
3619 							     len - TLV_HDR_SIZE);
3620 			band_to_mac->pdev_id = param->band_to_mac[idx].pdev_id;
3621 			band_to_mac->start_freq =
3622 				param->band_to_mac[idx].start_freq;
3623 			band_to_mac->end_freq =
3624 				param->band_to_mac[idx].end_freq;
3625 			ptr += sizeof(*band_to_mac);
3626 		}
3627 	}
3628 
3629 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_INIT_CMDID);
3630 	if (ret) {
3631 		ath11k_warn(ab, "failed to send WMI_INIT_CMDID\n");
3632 		dev_kfree_skb(skb);
3633 	}
3634 
3635 	return ret;
3636 }
3637 
3638 int ath11k_wmi_pdev_lro_cfg(struct ath11k *ar,
3639 			    int pdev_id)
3640 {
3641 	struct ath11k_wmi_pdev_lro_config_cmd *cmd;
3642 	struct sk_buff *skb;
3643 	int ret;
3644 
3645 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
3646 	if (!skb)
3647 		return -ENOMEM;
3648 
3649 	cmd = (struct ath11k_wmi_pdev_lro_config_cmd *)skb->data;
3650 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_LRO_INFO_CMD) |
3651 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3652 
3653 	get_random_bytes(cmd->th_4, sizeof(uint32_t) * ATH11K_IPV4_TH_SEED_SIZE);
3654 	get_random_bytes(cmd->th_6, sizeof(uint32_t) * ATH11K_IPV6_TH_SEED_SIZE);
3655 
3656 	cmd->pdev_id = pdev_id;
3657 
3658 	ret = ath11k_wmi_cmd_send(ar->wmi, skb, WMI_LRO_CONFIG_CMDID);
3659 	if (ret) {
3660 		ath11k_warn(ar->ab,
3661 			    "failed to send lro cfg req wmi cmd\n");
3662 		goto err;
3663 	}
3664 
3665 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3666 		   "WMI lro cfg cmd pdev_id 0x%x\n", pdev_id);
3667 	return 0;
3668 err:
3669 	dev_kfree_skb(skb);
3670 	return ret;
3671 }
3672 
3673 int ath11k_wmi_wait_for_service_ready(struct ath11k_base *ab)
3674 {
3675 	unsigned long time_left;
3676 
3677 	time_left = wait_for_completion_timeout(&ab->wmi_ab.service_ready,
3678 						WMI_SERVICE_READY_TIMEOUT_HZ);
3679 	if (!time_left)
3680 		return -ETIMEDOUT;
3681 
3682 	return 0;
3683 }
3684 
3685 int ath11k_wmi_wait_for_unified_ready(struct ath11k_base *ab)
3686 {
3687 	unsigned long time_left;
3688 
3689 	time_left = wait_for_completion_timeout(&ab->wmi_ab.unified_ready,
3690 						WMI_SERVICE_READY_TIMEOUT_HZ);
3691 	if (!time_left)
3692 		return -ETIMEDOUT;
3693 
3694 	return 0;
3695 }
3696 
3697 int ath11k_wmi_set_hw_mode(struct ath11k_base *ab,
3698 			   enum wmi_host_hw_mode_config_type mode)
3699 {
3700 	struct wmi_pdev_set_hw_mode_cmd_param *cmd;
3701 	struct sk_buff *skb;
3702 	struct ath11k_wmi_base *wmi_ab = &ab->wmi_ab;
3703 	int len;
3704 	int ret;
3705 
3706 	len = sizeof(*cmd);
3707 
3708 	skb = ath11k_wmi_alloc_skb(wmi_ab, len);
3709 	if (!skb)
3710 		return -ENOMEM;
3711 
3712 	cmd = (struct wmi_pdev_set_hw_mode_cmd_param *)skb->data;
3713 
3714 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_SET_HW_MODE_CMD) |
3715 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3716 
3717 	cmd->pdev_id = WMI_PDEV_ID_SOC;
3718 	cmd->hw_mode_index = mode;
3719 
3720 	ret = ath11k_wmi_cmd_send(&wmi_ab->wmi[0], skb, WMI_PDEV_SET_HW_MODE_CMDID);
3721 	if (ret) {
3722 		ath11k_warn(ab, "failed to send WMI_PDEV_SET_HW_MODE_CMDID\n");
3723 		dev_kfree_skb(skb);
3724 	}
3725 
3726 	return ret;
3727 }
3728 
3729 int ath11k_wmi_cmd_init(struct ath11k_base *ab)
3730 {
3731 	struct ath11k_wmi_base *wmi_sc = &ab->wmi_ab;
3732 	struct wmi_init_cmd_param init_param;
3733 	struct target_resource_config  config;
3734 
3735 	memset(&init_param, 0, sizeof(init_param));
3736 	memset(&config, 0, sizeof(config));
3737 
3738 	ab->hw_params.hw_ops->wmi_init_config(ab, &config);
3739 
3740 	memcpy(&wmi_sc->wlan_resource_config, &config, sizeof(config));
3741 
3742 	init_param.res_cfg = &wmi_sc->wlan_resource_config;
3743 	init_param.num_mem_chunks = wmi_sc->num_mem_chunks;
3744 	init_param.hw_mode_id = wmi_sc->preferred_hw_mode;
3745 	init_param.mem_chunks = wmi_sc->mem_chunks;
3746 
3747 	if (ab->hw_params.single_pdev_only)
3748 		init_param.hw_mode_id = WMI_HOST_HW_MODE_MAX;
3749 
3750 	init_param.num_band_to_mac = ab->num_radios;
3751 	ath11k_fill_band_to_mac_param(ab, init_param.band_to_mac);
3752 
3753 	return ath11k_init_cmd_send(&wmi_sc->wmi[0], &init_param);
3754 }
3755 
3756 int ath11k_wmi_vdev_spectral_conf(struct ath11k *ar,
3757 				  struct ath11k_wmi_vdev_spectral_conf_param *param)
3758 {
3759 	struct ath11k_wmi_vdev_spectral_conf_cmd *cmd;
3760 	struct sk_buff *skb;
3761 	int ret;
3762 
3763 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
3764 	if (!skb)
3765 		return -ENOMEM;
3766 
3767 	cmd = (struct ath11k_wmi_vdev_spectral_conf_cmd *)skb->data;
3768 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3769 				     WMI_TAG_VDEV_SPECTRAL_CONFIGURE_CMD) |
3770 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3771 
3772 	memcpy(&cmd->param, param, sizeof(*param));
3773 
3774 	ret = ath11k_wmi_cmd_send(ar->wmi, skb,
3775 				  WMI_VDEV_SPECTRAL_SCAN_CONFIGURE_CMDID);
3776 	if (ret) {
3777 		ath11k_warn(ar->ab,
3778 			    "failed to send spectral scan config wmi cmd\n");
3779 		goto err;
3780 	}
3781 
3782 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3783 		   "WMI spectral scan config cmd vdev_id 0x%x\n",
3784 		   param->vdev_id);
3785 
3786 	return 0;
3787 err:
3788 	dev_kfree_skb(skb);
3789 	return ret;
3790 }
3791 
3792 int ath11k_wmi_vdev_spectral_enable(struct ath11k *ar, u32 vdev_id,
3793 				    u32 trigger, u32 enable)
3794 {
3795 	struct ath11k_wmi_vdev_spectral_enable_cmd *cmd;
3796 	struct sk_buff *skb;
3797 	int ret;
3798 
3799 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
3800 	if (!skb)
3801 		return -ENOMEM;
3802 
3803 	cmd = (struct ath11k_wmi_vdev_spectral_enable_cmd *)skb->data;
3804 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3805 				     WMI_TAG_VDEV_SPECTRAL_ENABLE_CMD) |
3806 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3807 
3808 	cmd->vdev_id = vdev_id;
3809 	cmd->trigger_cmd = trigger;
3810 	cmd->enable_cmd = enable;
3811 
3812 	ret = ath11k_wmi_cmd_send(ar->wmi, skb,
3813 				  WMI_VDEV_SPECTRAL_SCAN_ENABLE_CMDID);
3814 	if (ret) {
3815 		ath11k_warn(ar->ab,
3816 			    "failed to send spectral enable wmi cmd\n");
3817 		goto err;
3818 	}
3819 
3820 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3821 		   "WMI spectral enable cmd vdev id 0x%x\n",
3822 		   vdev_id);
3823 
3824 	return 0;
3825 err:
3826 	dev_kfree_skb(skb);
3827 	return ret;
3828 }
3829 
3830 int ath11k_wmi_pdev_dma_ring_cfg(struct ath11k *ar,
3831 				 struct ath11k_wmi_pdev_dma_ring_cfg_req_cmd *param)
3832 {
3833 	struct ath11k_wmi_pdev_dma_ring_cfg_req_cmd *cmd;
3834 	struct sk_buff *skb;
3835 	int ret;
3836 
3837 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
3838 	if (!skb)
3839 		return -ENOMEM;
3840 
3841 	cmd = (struct ath11k_wmi_pdev_dma_ring_cfg_req_cmd *)skb->data;
3842 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_DMA_RING_CFG_REQ) |
3843 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3844 
3845 	cmd->pdev_id		= param->pdev_id;
3846 	cmd->module_id		= param->module_id;
3847 	cmd->base_paddr_lo	= param->base_paddr_lo;
3848 	cmd->base_paddr_hi	= param->base_paddr_hi;
3849 	cmd->head_idx_paddr_lo	= param->head_idx_paddr_lo;
3850 	cmd->head_idx_paddr_hi	= param->head_idx_paddr_hi;
3851 	cmd->tail_idx_paddr_lo	= param->tail_idx_paddr_lo;
3852 	cmd->tail_idx_paddr_hi	= param->tail_idx_paddr_hi;
3853 	cmd->num_elems		= param->num_elems;
3854 	cmd->buf_size		= param->buf_size;
3855 	cmd->num_resp_per_event	= param->num_resp_per_event;
3856 	cmd->event_timeout_ms	= param->event_timeout_ms;
3857 
3858 	ret = ath11k_wmi_cmd_send(ar->wmi, skb,
3859 				  WMI_PDEV_DMA_RING_CFG_REQ_CMDID);
3860 	if (ret) {
3861 		ath11k_warn(ar->ab,
3862 			    "failed to send dma ring cfg req wmi cmd\n");
3863 		goto err;
3864 	}
3865 
3866 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3867 		   "WMI DMA ring cfg req cmd pdev_id 0x%x\n",
3868 		   param->pdev_id);
3869 
3870 	return 0;
3871 err:
3872 	dev_kfree_skb(skb);
3873 	return ret;
3874 }
3875 
3876 static int ath11k_wmi_tlv_dma_buf_entry_parse(struct ath11k_base *soc,
3877 					      u16 tag, u16 len,
3878 					      const void *ptr, void *data)
3879 {
3880 	struct wmi_tlv_dma_buf_release_parse *parse = data;
3881 
3882 	if (tag != WMI_TAG_DMA_BUF_RELEASE_ENTRY)
3883 		return -EPROTO;
3884 
3885 	if (parse->num_buf_entry >= parse->fixed.num_buf_release_entry)
3886 		return -ENOBUFS;
3887 
3888 	parse->num_buf_entry++;
3889 	return 0;
3890 }
3891 
3892 static int ath11k_wmi_tlv_dma_buf_meta_parse(struct ath11k_base *soc,
3893 					     u16 tag, u16 len,
3894 					     const void *ptr, void *data)
3895 {
3896 	struct wmi_tlv_dma_buf_release_parse *parse = data;
3897 
3898 	if (tag != WMI_TAG_DMA_BUF_RELEASE_SPECTRAL_META_DATA)
3899 		return -EPROTO;
3900 
3901 	if (parse->num_meta >= parse->fixed.num_meta_data_entry)
3902 		return -ENOBUFS;
3903 
3904 	parse->num_meta++;
3905 	return 0;
3906 }
3907 
3908 static int ath11k_wmi_tlv_dma_buf_parse(struct ath11k_base *ab,
3909 					u16 tag, u16 len,
3910 					const void *ptr, void *data)
3911 {
3912 	struct wmi_tlv_dma_buf_release_parse *parse = data;
3913 	int ret;
3914 
3915 	switch (tag) {
3916 	case WMI_TAG_DMA_BUF_RELEASE:
3917 		memcpy(&parse->fixed, ptr,
3918 		       sizeof(struct ath11k_wmi_dma_buf_release_fixed_param));
3919 		parse->fixed.pdev_id = DP_HW2SW_MACID(parse->fixed.pdev_id);
3920 		break;
3921 	case WMI_TAG_ARRAY_STRUCT:
3922 		if (!parse->buf_entry_done) {
3923 			parse->num_buf_entry = 0;
3924 			parse->buf_entry = (struct wmi_dma_buf_release_entry *)ptr;
3925 
3926 			ret = ath11k_wmi_tlv_iter(ab, ptr, len,
3927 						  ath11k_wmi_tlv_dma_buf_entry_parse,
3928 						  parse);
3929 			if (ret) {
3930 				ath11k_warn(ab, "failed to parse dma buf entry tlv %d\n",
3931 					    ret);
3932 				return ret;
3933 			}
3934 
3935 			parse->buf_entry_done = true;
3936 		} else if (!parse->meta_data_done) {
3937 			parse->num_meta = 0;
3938 			parse->meta_data = (struct wmi_dma_buf_release_meta_data *)ptr;
3939 
3940 			ret = ath11k_wmi_tlv_iter(ab, ptr, len,
3941 						  ath11k_wmi_tlv_dma_buf_meta_parse,
3942 						  parse);
3943 			if (ret) {
3944 				ath11k_warn(ab, "failed to parse dma buf meta tlv %d\n",
3945 					    ret);
3946 				return ret;
3947 			}
3948 
3949 			parse->meta_data_done = true;
3950 		}
3951 		break;
3952 	default:
3953 		break;
3954 	}
3955 	return 0;
3956 }
3957 
3958 static void ath11k_wmi_pdev_dma_ring_buf_release_event(struct ath11k_base *ab,
3959 						       struct sk_buff *skb)
3960 {
3961 	struct wmi_tlv_dma_buf_release_parse parse = { };
3962 	struct ath11k_dbring_buf_release_event param;
3963 	int ret;
3964 
3965 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
3966 				  ath11k_wmi_tlv_dma_buf_parse,
3967 				  &parse);
3968 	if (ret) {
3969 		ath11k_warn(ab, "failed to parse dma buf release tlv %d\n", ret);
3970 		return;
3971 	}
3972 
3973 	param.fixed		= parse.fixed;
3974 	param.buf_entry		= parse.buf_entry;
3975 	param.num_buf_entry	= parse.num_buf_entry;
3976 	param.meta_data		= parse.meta_data;
3977 	param.num_meta		= parse.num_meta;
3978 
3979 	ret = ath11k_dbring_buffer_release_event(ab, &param);
3980 	if (ret) {
3981 		ath11k_warn(ab, "failed to handle dma buf release event %d\n", ret);
3982 		return;
3983 	}
3984 }
3985 
3986 static int ath11k_wmi_tlv_hw_mode_caps_parse(struct ath11k_base *soc,
3987 					     u16 tag, u16 len,
3988 					     const void *ptr, void *data)
3989 {
3990 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3991 	struct wmi_hw_mode_capabilities *hw_mode_cap;
3992 	u32 phy_map = 0;
3993 
3994 	if (tag != WMI_TAG_HW_MODE_CAPABILITIES)
3995 		return -EPROTO;
3996 
3997 	if (svc_rdy_ext->n_hw_mode_caps >= svc_rdy_ext->param.num_hw_modes)
3998 		return -ENOBUFS;
3999 
4000 	hw_mode_cap = container_of(ptr, struct wmi_hw_mode_capabilities,
4001 				   hw_mode_id);
4002 	svc_rdy_ext->n_hw_mode_caps++;
4003 
4004 	phy_map = hw_mode_cap->phy_id_map;
4005 	while (phy_map) {
4006 		svc_rdy_ext->tot_phy_id++;
4007 		phy_map = phy_map >> 1;
4008 	}
4009 
4010 	return 0;
4011 }
4012 
4013 static int ath11k_wmi_tlv_hw_mode_caps(struct ath11k_base *soc,
4014 				       u16 len, const void *ptr, void *data)
4015 {
4016 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
4017 	struct wmi_hw_mode_capabilities *hw_mode_caps;
4018 	enum wmi_host_hw_mode_config_type mode, pref;
4019 	u32 i;
4020 	int ret;
4021 
4022 	svc_rdy_ext->n_hw_mode_caps = 0;
4023 	svc_rdy_ext->hw_mode_caps = (struct wmi_hw_mode_capabilities *)ptr;
4024 
4025 	ret = ath11k_wmi_tlv_iter(soc, ptr, len,
4026 				  ath11k_wmi_tlv_hw_mode_caps_parse,
4027 				  svc_rdy_ext);
4028 	if (ret) {
4029 		ath11k_warn(soc, "failed to parse tlv %d\n", ret);
4030 		return ret;
4031 	}
4032 
4033 	i = 0;
4034 	while (i < svc_rdy_ext->n_hw_mode_caps) {
4035 		hw_mode_caps = &svc_rdy_ext->hw_mode_caps[i];
4036 		mode = hw_mode_caps->hw_mode_id;
4037 		pref = soc->wmi_ab.preferred_hw_mode;
4038 
4039 		if (ath11k_hw_mode_pri_map[mode] < ath11k_hw_mode_pri_map[pref]) {
4040 			svc_rdy_ext->pref_hw_mode_caps = *hw_mode_caps;
4041 			soc->wmi_ab.preferred_hw_mode = mode;
4042 		}
4043 		i++;
4044 	}
4045 
4046 	ath11k_dbg(soc, ATH11K_DBG_WMI, "preferred_hw_mode:%d\n",
4047 		   soc->wmi_ab.preferred_hw_mode);
4048 	if (soc->wmi_ab.preferred_hw_mode == WMI_HOST_HW_MODE_MAX)
4049 		return -EINVAL;
4050 
4051 	return 0;
4052 }
4053 
4054 static int ath11k_wmi_tlv_mac_phy_caps_parse(struct ath11k_base *soc,
4055 					     u16 tag, u16 len,
4056 					     const void *ptr, void *data)
4057 {
4058 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
4059 
4060 	if (tag != WMI_TAG_MAC_PHY_CAPABILITIES)
4061 		return -EPROTO;
4062 
4063 	if (svc_rdy_ext->n_mac_phy_caps >= svc_rdy_ext->tot_phy_id)
4064 		return -ENOBUFS;
4065 
4066 	len = min_t(u16, len, sizeof(struct wmi_mac_phy_capabilities));
4067 	if (!svc_rdy_ext->n_mac_phy_caps) {
4068 		svc_rdy_ext->mac_phy_caps = kzalloc((svc_rdy_ext->tot_phy_id) * len,
4069 						    GFP_ATOMIC);
4070 		if (!svc_rdy_ext->mac_phy_caps)
4071 			return -ENOMEM;
4072 	}
4073 
4074 	memcpy(svc_rdy_ext->mac_phy_caps + svc_rdy_ext->n_mac_phy_caps, ptr, len);
4075 	svc_rdy_ext->n_mac_phy_caps++;
4076 	return 0;
4077 }
4078 
4079 static int ath11k_wmi_tlv_ext_hal_reg_caps_parse(struct ath11k_base *soc,
4080 						 u16 tag, u16 len,
4081 						 const void *ptr, void *data)
4082 {
4083 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
4084 
4085 	if (tag != WMI_TAG_HAL_REG_CAPABILITIES_EXT)
4086 		return -EPROTO;
4087 
4088 	if (svc_rdy_ext->n_ext_hal_reg_caps >= svc_rdy_ext->param.num_phy)
4089 		return -ENOBUFS;
4090 
4091 	svc_rdy_ext->n_ext_hal_reg_caps++;
4092 	return 0;
4093 }
4094 
4095 static int ath11k_wmi_tlv_ext_hal_reg_caps(struct ath11k_base *soc,
4096 					   u16 len, const void *ptr, void *data)
4097 {
4098 	struct ath11k_pdev_wmi *wmi_handle = &soc->wmi_ab.wmi[0];
4099 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
4100 	struct ath11k_hal_reg_capabilities_ext reg_cap;
4101 	int ret;
4102 	u32 i;
4103 
4104 	svc_rdy_ext->n_ext_hal_reg_caps = 0;
4105 	svc_rdy_ext->ext_hal_reg_caps = (struct wmi_hal_reg_capabilities_ext *)ptr;
4106 	ret = ath11k_wmi_tlv_iter(soc, ptr, len,
4107 				  ath11k_wmi_tlv_ext_hal_reg_caps_parse,
4108 				  svc_rdy_ext);
4109 	if (ret) {
4110 		ath11k_warn(soc, "failed to parse tlv %d\n", ret);
4111 		return ret;
4112 	}
4113 
4114 	for (i = 0; i < svc_rdy_ext->param.num_phy; i++) {
4115 		ret = ath11k_pull_reg_cap_svc_rdy_ext(wmi_handle,
4116 						      svc_rdy_ext->soc_hal_reg_caps,
4117 						      svc_rdy_ext->ext_hal_reg_caps, i,
4118 						      &reg_cap);
4119 		if (ret) {
4120 			ath11k_warn(soc, "failed to extract reg cap %d\n", i);
4121 			return ret;
4122 		}
4123 
4124 		memcpy(&soc->hal_reg_cap[reg_cap.phy_id],
4125 		       &reg_cap, sizeof(reg_cap));
4126 	}
4127 	return 0;
4128 }
4129 
4130 static int ath11k_wmi_tlv_ext_soc_hal_reg_caps_parse(struct ath11k_base *soc,
4131 						     u16 len, const void *ptr,
4132 						     void *data)
4133 {
4134 	struct ath11k_pdev_wmi *wmi_handle = &soc->wmi_ab.wmi[0];
4135 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
4136 	u8 hw_mode_id = svc_rdy_ext->pref_hw_mode_caps.hw_mode_id;
4137 	u32 phy_id_map;
4138 	int pdev_index = 0;
4139 	int ret;
4140 
4141 	svc_rdy_ext->soc_hal_reg_caps = (struct wmi_soc_hal_reg_capabilities *)ptr;
4142 	svc_rdy_ext->param.num_phy = svc_rdy_ext->soc_hal_reg_caps->num_phy;
4143 
4144 	soc->num_radios = 0;
4145 	phy_id_map = svc_rdy_ext->pref_hw_mode_caps.phy_id_map;
4146 
4147 	while (phy_id_map && soc->num_radios < MAX_RADIOS) {
4148 		ret = ath11k_pull_mac_phy_cap_svc_ready_ext(wmi_handle,
4149 							    svc_rdy_ext->hw_caps,
4150 							    svc_rdy_ext->hw_mode_caps,
4151 							    svc_rdy_ext->soc_hal_reg_caps,
4152 							    svc_rdy_ext->mac_phy_caps,
4153 							    hw_mode_id, soc->num_radios,
4154 							    &soc->pdevs[pdev_index]);
4155 		if (ret) {
4156 			ath11k_warn(soc, "failed to extract mac caps, idx :%d\n",
4157 				    soc->num_radios);
4158 			return ret;
4159 		}
4160 
4161 		soc->num_radios++;
4162 
4163 		/* For QCA6390, save mac_phy capability in the same pdev */
4164 		if (soc->hw_params.single_pdev_only)
4165 			pdev_index = 0;
4166 		else
4167 			pdev_index = soc->num_radios;
4168 
4169 		/* TODO: mac_phy_cap prints */
4170 		phy_id_map >>= 1;
4171 	}
4172 
4173 	/* For QCA6390, set num_radios to 1 because host manages
4174 	 * both 2G and 5G radio in one pdev.
4175 	 * Set pdev_id = 0 and 0 means soc level.
4176 	 */
4177 	if (soc->hw_params.single_pdev_only) {
4178 		soc->num_radios = 1;
4179 		soc->pdevs[0].pdev_id = 0;
4180 	}
4181 
4182 	return 0;
4183 }
4184 
4185 static int ath11k_wmi_tlv_dma_ring_caps_parse(struct ath11k_base *soc,
4186 					      u16 tag, u16 len,
4187 					      const void *ptr, void *data)
4188 {
4189 	struct wmi_tlv_dma_ring_caps_parse *parse = data;
4190 
4191 	if (tag != WMI_TAG_DMA_RING_CAPABILITIES)
4192 		return -EPROTO;
4193 
4194 	parse->n_dma_ring_caps++;
4195 	return 0;
4196 }
4197 
4198 static int ath11k_wmi_alloc_dbring_caps(struct ath11k_base *ab,
4199 					u32 num_cap)
4200 {
4201 	size_t sz;
4202 	void *ptr;
4203 
4204 	sz = num_cap * sizeof(struct ath11k_dbring_cap);
4205 	ptr = kzalloc(sz, GFP_ATOMIC);
4206 	if (!ptr)
4207 		return -ENOMEM;
4208 
4209 	ab->db_caps = ptr;
4210 	ab->num_db_cap = num_cap;
4211 
4212 	return 0;
4213 }
4214 
4215 static void ath11k_wmi_free_dbring_caps(struct ath11k_base *ab)
4216 {
4217 	kfree(ab->db_caps);
4218 	ab->db_caps = NULL;
4219 }
4220 
4221 static int ath11k_wmi_tlv_dma_ring_caps(struct ath11k_base *ab,
4222 					u16 len, const void *ptr, void *data)
4223 {
4224 	struct wmi_tlv_dma_ring_caps_parse *dma_caps_parse = data;
4225 	struct wmi_dma_ring_capabilities *dma_caps;
4226 	struct ath11k_dbring_cap *dir_buff_caps;
4227 	int ret;
4228 	u32 i;
4229 
4230 	dma_caps_parse->n_dma_ring_caps = 0;
4231 	dma_caps = (struct wmi_dma_ring_capabilities *)ptr;
4232 	ret = ath11k_wmi_tlv_iter(ab, ptr, len,
4233 				  ath11k_wmi_tlv_dma_ring_caps_parse,
4234 				  dma_caps_parse);
4235 	if (ret) {
4236 		ath11k_warn(ab, "failed to parse dma ring caps tlv %d\n", ret);
4237 		return ret;
4238 	}
4239 
4240 	if (!dma_caps_parse->n_dma_ring_caps)
4241 		return 0;
4242 
4243 	if (ab->num_db_cap) {
4244 		ath11k_warn(ab, "Already processed, so ignoring dma ring caps\n");
4245 		return 0;
4246 	}
4247 
4248 	ret = ath11k_wmi_alloc_dbring_caps(ab, dma_caps_parse->n_dma_ring_caps);
4249 	if (ret)
4250 		return ret;
4251 
4252 	dir_buff_caps = ab->db_caps;
4253 	for (i = 0; i < dma_caps_parse->n_dma_ring_caps; i++) {
4254 		if (dma_caps[i].module_id >= WMI_DIRECT_BUF_MAX) {
4255 			ath11k_warn(ab, "Invalid module id %d\n", dma_caps[i].module_id);
4256 			ret = -EINVAL;
4257 			goto free_dir_buff;
4258 		}
4259 
4260 		dir_buff_caps[i].id = dma_caps[i].module_id;
4261 		dir_buff_caps[i].pdev_id = DP_HW2SW_MACID(dma_caps[i].pdev_id);
4262 		dir_buff_caps[i].min_elem = dma_caps[i].min_elem;
4263 		dir_buff_caps[i].min_buf_sz = dma_caps[i].min_buf_sz;
4264 		dir_buff_caps[i].min_buf_align = dma_caps[i].min_buf_align;
4265 	}
4266 
4267 	return 0;
4268 
4269 free_dir_buff:
4270 	ath11k_wmi_free_dbring_caps(ab);
4271 	return ret;
4272 }
4273 
4274 static int ath11k_wmi_tlv_svc_rdy_ext_parse(struct ath11k_base *ab,
4275 					    u16 tag, u16 len,
4276 					    const void *ptr, void *data)
4277 {
4278 	struct ath11k_pdev_wmi *wmi_handle = &ab->wmi_ab.wmi[0];
4279 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
4280 	int ret;
4281 
4282 	switch (tag) {
4283 	case WMI_TAG_SERVICE_READY_EXT_EVENT:
4284 		ret = ath11k_pull_svc_ready_ext(wmi_handle, ptr,
4285 						&svc_rdy_ext->param);
4286 		if (ret) {
4287 			ath11k_warn(ab, "unable to extract ext params\n");
4288 			return ret;
4289 		}
4290 		break;
4291 
4292 	case WMI_TAG_SOC_MAC_PHY_HW_MODE_CAPS:
4293 		svc_rdy_ext->hw_caps = (struct wmi_soc_mac_phy_hw_mode_caps *)ptr;
4294 		svc_rdy_ext->param.num_hw_modes = svc_rdy_ext->hw_caps->num_hw_modes;
4295 		break;
4296 
4297 	case WMI_TAG_SOC_HAL_REG_CAPABILITIES:
4298 		ret = ath11k_wmi_tlv_ext_soc_hal_reg_caps_parse(ab, len, ptr,
4299 								svc_rdy_ext);
4300 		if (ret)
4301 			return ret;
4302 		break;
4303 
4304 	case WMI_TAG_ARRAY_STRUCT:
4305 		if (!svc_rdy_ext->hw_mode_done) {
4306 			ret = ath11k_wmi_tlv_hw_mode_caps(ab, len, ptr,
4307 							  svc_rdy_ext);
4308 			if (ret)
4309 				return ret;
4310 
4311 			svc_rdy_ext->hw_mode_done = true;
4312 		} else if (!svc_rdy_ext->mac_phy_done) {
4313 			svc_rdy_ext->n_mac_phy_caps = 0;
4314 			ret = ath11k_wmi_tlv_iter(ab, ptr, len,
4315 						  ath11k_wmi_tlv_mac_phy_caps_parse,
4316 						  svc_rdy_ext);
4317 			if (ret) {
4318 				ath11k_warn(ab, "failed to parse tlv %d\n", ret);
4319 				return ret;
4320 			}
4321 
4322 			svc_rdy_ext->mac_phy_done = true;
4323 		} else if (!svc_rdy_ext->ext_hal_reg_done) {
4324 			ret = ath11k_wmi_tlv_ext_hal_reg_caps(ab, len, ptr,
4325 							      svc_rdy_ext);
4326 			if (ret)
4327 				return ret;
4328 
4329 			svc_rdy_ext->ext_hal_reg_done = true;
4330 		} else if (!svc_rdy_ext->mac_phy_chainmask_combo_done) {
4331 			svc_rdy_ext->mac_phy_chainmask_combo_done = true;
4332 		} else if (!svc_rdy_ext->mac_phy_chainmask_cap_done) {
4333 			svc_rdy_ext->mac_phy_chainmask_cap_done = true;
4334 		} else if (!svc_rdy_ext->oem_dma_ring_cap_done) {
4335 			svc_rdy_ext->oem_dma_ring_cap_done = true;
4336 		} else if (!svc_rdy_ext->dma_ring_cap_done) {
4337 			ret = ath11k_wmi_tlv_dma_ring_caps(ab, len, ptr,
4338 							   &svc_rdy_ext->dma_caps_parse);
4339 			if (ret)
4340 				return ret;
4341 
4342 			svc_rdy_ext->dma_ring_cap_done = true;
4343 		}
4344 		break;
4345 
4346 	default:
4347 		break;
4348 	}
4349 	return 0;
4350 }
4351 
4352 static int ath11k_service_ready_ext_event(struct ath11k_base *ab,
4353 					  struct sk_buff *skb)
4354 {
4355 	struct wmi_tlv_svc_rdy_ext_parse svc_rdy_ext = { };
4356 	int ret;
4357 
4358 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
4359 				  ath11k_wmi_tlv_svc_rdy_ext_parse,
4360 				  &svc_rdy_ext);
4361 	if (ret) {
4362 		ath11k_warn(ab, "failed to parse tlv %d\n", ret);
4363 		goto err;
4364 	}
4365 
4366 	if (!test_bit(WMI_TLV_SERVICE_EXT2_MSG, ab->wmi_ab.svc_map))
4367 		complete(&ab->wmi_ab.service_ready);
4368 
4369 	kfree(svc_rdy_ext.mac_phy_caps);
4370 	return 0;
4371 
4372 err:
4373 	ath11k_wmi_free_dbring_caps(ab);
4374 	return ret;
4375 }
4376 
4377 static int ath11k_wmi_tlv_svc_rdy_ext2_parse(struct ath11k_base *ab,
4378 					     u16 tag, u16 len,
4379 					     const void *ptr, void *data)
4380 {
4381 	struct wmi_tlv_svc_rdy_ext2_parse *parse = data;
4382 	int ret;
4383 
4384 	switch (tag) {
4385 	case WMI_TAG_ARRAY_STRUCT:
4386 		if (!parse->dma_ring_cap_done) {
4387 			ret = ath11k_wmi_tlv_dma_ring_caps(ab, len, ptr,
4388 							   &parse->dma_caps_parse);
4389 			if (ret)
4390 				return ret;
4391 
4392 			parse->dma_ring_cap_done = true;
4393 		}
4394 		break;
4395 	default:
4396 		break;
4397 	}
4398 
4399 	return 0;
4400 }
4401 
4402 static int ath11k_service_ready_ext2_event(struct ath11k_base *ab,
4403 					   struct sk_buff *skb)
4404 {
4405 	struct wmi_tlv_svc_rdy_ext2_parse svc_rdy_ext2 = { };
4406 	int ret;
4407 
4408 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
4409 				  ath11k_wmi_tlv_svc_rdy_ext2_parse,
4410 				  &svc_rdy_ext2);
4411 	if (ret) {
4412 		ath11k_warn(ab, "failed to parse ext2 event tlv %d\n", ret);
4413 		goto err;
4414 	}
4415 
4416 	complete(&ab->wmi_ab.service_ready);
4417 
4418 	return 0;
4419 
4420 err:
4421 	ath11k_wmi_free_dbring_caps(ab);
4422 	return ret;
4423 }
4424 
4425 static int ath11k_pull_vdev_start_resp_tlv(struct ath11k_base *ab, struct sk_buff *skb,
4426 					   struct wmi_vdev_start_resp_event *vdev_rsp)
4427 {
4428 	const void **tb;
4429 	const struct wmi_vdev_start_resp_event *ev;
4430 	int ret;
4431 
4432 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4433 	if (IS_ERR(tb)) {
4434 		ret = PTR_ERR(tb);
4435 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4436 		return ret;
4437 	}
4438 
4439 	ev = tb[WMI_TAG_VDEV_START_RESPONSE_EVENT];
4440 	if (!ev) {
4441 		ath11k_warn(ab, "failed to fetch vdev start resp ev");
4442 		kfree(tb);
4443 		return -EPROTO;
4444 	}
4445 
4446 	memset(vdev_rsp, 0, sizeof(*vdev_rsp));
4447 
4448 	vdev_rsp->vdev_id = ev->vdev_id;
4449 	vdev_rsp->requestor_id = ev->requestor_id;
4450 	vdev_rsp->resp_type = ev->resp_type;
4451 	vdev_rsp->status = ev->status;
4452 	vdev_rsp->chain_mask = ev->chain_mask;
4453 	vdev_rsp->smps_mode = ev->smps_mode;
4454 	vdev_rsp->mac_id = ev->mac_id;
4455 	vdev_rsp->cfgd_tx_streams = ev->cfgd_tx_streams;
4456 	vdev_rsp->cfgd_rx_streams = ev->cfgd_rx_streams;
4457 
4458 	kfree(tb);
4459 	return 0;
4460 }
4461 
4462 static struct cur_reg_rule
4463 *create_reg_rules_from_wmi(u32 num_reg_rules,
4464 			   struct wmi_regulatory_rule_struct *wmi_reg_rule)
4465 {
4466 	struct cur_reg_rule *reg_rule_ptr;
4467 	u32 count;
4468 
4469 	reg_rule_ptr =  kzalloc((num_reg_rules * sizeof(*reg_rule_ptr)),
4470 				GFP_ATOMIC);
4471 
4472 	if (!reg_rule_ptr)
4473 		return NULL;
4474 
4475 	for (count = 0; count < num_reg_rules; count++) {
4476 		reg_rule_ptr[count].start_freq =
4477 			FIELD_GET(REG_RULE_START_FREQ,
4478 				  wmi_reg_rule[count].freq_info);
4479 		reg_rule_ptr[count].end_freq =
4480 			FIELD_GET(REG_RULE_END_FREQ,
4481 				  wmi_reg_rule[count].freq_info);
4482 		reg_rule_ptr[count].max_bw =
4483 			FIELD_GET(REG_RULE_MAX_BW,
4484 				  wmi_reg_rule[count].bw_pwr_info);
4485 		reg_rule_ptr[count].reg_power =
4486 			FIELD_GET(REG_RULE_REG_PWR,
4487 				  wmi_reg_rule[count].bw_pwr_info);
4488 		reg_rule_ptr[count].ant_gain =
4489 			FIELD_GET(REG_RULE_ANT_GAIN,
4490 				  wmi_reg_rule[count].bw_pwr_info);
4491 		reg_rule_ptr[count].flags =
4492 			FIELD_GET(REG_RULE_FLAGS,
4493 				  wmi_reg_rule[count].flag_info);
4494 	}
4495 
4496 	return reg_rule_ptr;
4497 }
4498 
4499 static int ath11k_pull_reg_chan_list_update_ev(struct ath11k_base *ab,
4500 					       struct sk_buff *skb,
4501 					       struct cur_regulatory_info *reg_info)
4502 {
4503 	const void **tb;
4504 	const struct wmi_reg_chan_list_cc_event *chan_list_event_hdr;
4505 	struct wmi_regulatory_rule_struct *wmi_reg_rule;
4506 	u32 num_2g_reg_rules, num_5g_reg_rules;
4507 	int ret;
4508 
4509 	ath11k_dbg(ab, ATH11K_DBG_WMI, "processing regulatory channel list\n");
4510 
4511 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4512 	if (IS_ERR(tb)) {
4513 		ret = PTR_ERR(tb);
4514 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4515 		return ret;
4516 	}
4517 
4518 	chan_list_event_hdr = tb[WMI_TAG_REG_CHAN_LIST_CC_EVENT];
4519 	if (!chan_list_event_hdr) {
4520 		ath11k_warn(ab, "failed to fetch reg chan list update ev\n");
4521 		kfree(tb);
4522 		return -EPROTO;
4523 	}
4524 
4525 	reg_info->num_2g_reg_rules = chan_list_event_hdr->num_2g_reg_rules;
4526 	reg_info->num_5g_reg_rules = chan_list_event_hdr->num_5g_reg_rules;
4527 
4528 	if (!(reg_info->num_2g_reg_rules + reg_info->num_5g_reg_rules)) {
4529 		ath11k_warn(ab, "No regulatory rules available in the event info\n");
4530 		kfree(tb);
4531 		return -EINVAL;
4532 	}
4533 
4534 	memcpy(reg_info->alpha2, &chan_list_event_hdr->alpha2,
4535 	       REG_ALPHA2_LEN);
4536 	reg_info->dfs_region = chan_list_event_hdr->dfs_region;
4537 	reg_info->phybitmap = chan_list_event_hdr->phybitmap;
4538 	reg_info->num_phy = chan_list_event_hdr->num_phy;
4539 	reg_info->phy_id = chan_list_event_hdr->phy_id;
4540 	reg_info->ctry_code = chan_list_event_hdr->country_id;
4541 	reg_info->reg_dmn_pair = chan_list_event_hdr->domain_code;
4542 	if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_STATUS_PASS)
4543 		reg_info->status_code = REG_SET_CC_STATUS_PASS;
4544 	else if (chan_list_event_hdr->status_code == WMI_REG_CURRENT_ALPHA2_NOT_FOUND)
4545 		reg_info->status_code = REG_CURRENT_ALPHA2_NOT_FOUND;
4546 	else if (chan_list_event_hdr->status_code == WMI_REG_INIT_ALPHA2_NOT_FOUND)
4547 		reg_info->status_code = REG_INIT_ALPHA2_NOT_FOUND;
4548 	else if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_CHANGE_NOT_ALLOWED)
4549 		reg_info->status_code = REG_SET_CC_CHANGE_NOT_ALLOWED;
4550 	else if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_STATUS_NO_MEMORY)
4551 		reg_info->status_code = REG_SET_CC_STATUS_NO_MEMORY;
4552 	else if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_STATUS_FAIL)
4553 		reg_info->status_code = REG_SET_CC_STATUS_FAIL;
4554 
4555 	reg_info->min_bw_2g = chan_list_event_hdr->min_bw_2g;
4556 	reg_info->max_bw_2g = chan_list_event_hdr->max_bw_2g;
4557 	reg_info->min_bw_5g = chan_list_event_hdr->min_bw_5g;
4558 	reg_info->max_bw_5g = chan_list_event_hdr->max_bw_5g;
4559 
4560 	num_2g_reg_rules = reg_info->num_2g_reg_rules;
4561 	num_5g_reg_rules = reg_info->num_5g_reg_rules;
4562 
4563 	ath11k_dbg(ab, ATH11K_DBG_WMI,
4564 		   "%s:cc %s dsf %d BW: min_2g %d max_2g %d min_5g %d max_5g %d",
4565 		   __func__, reg_info->alpha2, reg_info->dfs_region,
4566 		   reg_info->min_bw_2g, reg_info->max_bw_2g,
4567 		   reg_info->min_bw_5g, reg_info->max_bw_5g);
4568 
4569 	ath11k_dbg(ab, ATH11K_DBG_WMI,
4570 		   "%s: num_2g_reg_rules %d num_5g_reg_rules %d", __func__,
4571 		   num_2g_reg_rules, num_5g_reg_rules);
4572 
4573 	wmi_reg_rule =
4574 		(struct wmi_regulatory_rule_struct *)((u8 *)chan_list_event_hdr
4575 						+ sizeof(*chan_list_event_hdr)
4576 						+ sizeof(struct wmi_tlv));
4577 
4578 	if (num_2g_reg_rules) {
4579 		reg_info->reg_rules_2g_ptr = create_reg_rules_from_wmi(num_2g_reg_rules,
4580 								       wmi_reg_rule);
4581 		if (!reg_info->reg_rules_2g_ptr) {
4582 			kfree(tb);
4583 			ath11k_warn(ab, "Unable to Allocate memory for 2g rules\n");
4584 			return -ENOMEM;
4585 		}
4586 	}
4587 
4588 	if (num_5g_reg_rules) {
4589 		wmi_reg_rule += num_2g_reg_rules;
4590 		reg_info->reg_rules_5g_ptr = create_reg_rules_from_wmi(num_5g_reg_rules,
4591 								       wmi_reg_rule);
4592 		if (!reg_info->reg_rules_5g_ptr) {
4593 			kfree(tb);
4594 			ath11k_warn(ab, "Unable to Allocate memory for 5g rules\n");
4595 			return -ENOMEM;
4596 		}
4597 	}
4598 
4599 	ath11k_dbg(ab, ATH11K_DBG_WMI, "processed regulatory channel list\n");
4600 
4601 	kfree(tb);
4602 	return 0;
4603 }
4604 
4605 static int ath11k_pull_peer_del_resp_ev(struct ath11k_base *ab, struct sk_buff *skb,
4606 					struct wmi_peer_delete_resp_event *peer_del_resp)
4607 {
4608 	const void **tb;
4609 	const struct wmi_peer_delete_resp_event *ev;
4610 	int ret;
4611 
4612 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4613 	if (IS_ERR(tb)) {
4614 		ret = PTR_ERR(tb);
4615 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4616 		return ret;
4617 	}
4618 
4619 	ev = tb[WMI_TAG_PEER_DELETE_RESP_EVENT];
4620 	if (!ev) {
4621 		ath11k_warn(ab, "failed to fetch peer delete resp ev");
4622 		kfree(tb);
4623 		return -EPROTO;
4624 	}
4625 
4626 	memset(peer_del_resp, 0, sizeof(*peer_del_resp));
4627 
4628 	peer_del_resp->vdev_id = ev->vdev_id;
4629 	ether_addr_copy(peer_del_resp->peer_macaddr.addr,
4630 			ev->peer_macaddr.addr);
4631 
4632 	kfree(tb);
4633 	return 0;
4634 }
4635 
4636 static int ath11k_pull_vdev_del_resp_ev(struct ath11k_base *ab,
4637 					struct sk_buff *skb,
4638 					u32 *vdev_id)
4639 {
4640 	const void **tb;
4641 	const struct wmi_vdev_delete_resp_event *ev;
4642 	int ret;
4643 
4644 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4645 	if (IS_ERR(tb)) {
4646 		ret = PTR_ERR(tb);
4647 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4648 		return ret;
4649 	}
4650 
4651 	ev = tb[WMI_TAG_VDEV_DELETE_RESP_EVENT];
4652 	if (!ev) {
4653 		ath11k_warn(ab, "failed to fetch vdev delete resp ev");
4654 		kfree(tb);
4655 		return -EPROTO;
4656 	}
4657 
4658 	*vdev_id = ev->vdev_id;
4659 
4660 	kfree(tb);
4661 	return 0;
4662 }
4663 
4664 static int ath11k_pull_bcn_tx_status_ev(struct ath11k_base *ab, void *evt_buf,
4665 					u32 len, u32 *vdev_id,
4666 					u32 *tx_status)
4667 {
4668 	const void **tb;
4669 	const struct wmi_bcn_tx_status_event *ev;
4670 	int ret;
4671 
4672 	tb = ath11k_wmi_tlv_parse_alloc(ab, evt_buf, len, GFP_ATOMIC);
4673 	if (IS_ERR(tb)) {
4674 		ret = PTR_ERR(tb);
4675 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4676 		return ret;
4677 	}
4678 
4679 	ev = tb[WMI_TAG_OFFLOAD_BCN_TX_STATUS_EVENT];
4680 	if (!ev) {
4681 		ath11k_warn(ab, "failed to fetch bcn tx status ev");
4682 		kfree(tb);
4683 		return -EPROTO;
4684 	}
4685 
4686 	*vdev_id   = ev->vdev_id;
4687 	*tx_status = ev->tx_status;
4688 
4689 	kfree(tb);
4690 	return 0;
4691 }
4692 
4693 static int ath11k_pull_vdev_stopped_param_tlv(struct ath11k_base *ab, struct sk_buff *skb,
4694 					      u32 *vdev_id)
4695 {
4696 	const void **tb;
4697 	const struct wmi_vdev_stopped_event *ev;
4698 	int ret;
4699 
4700 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4701 	if (IS_ERR(tb)) {
4702 		ret = PTR_ERR(tb);
4703 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4704 		return ret;
4705 	}
4706 
4707 	ev = tb[WMI_TAG_VDEV_STOPPED_EVENT];
4708 	if (!ev) {
4709 		ath11k_warn(ab, "failed to fetch vdev stop ev");
4710 		kfree(tb);
4711 		return -EPROTO;
4712 	}
4713 
4714 	*vdev_id =  ev->vdev_id;
4715 
4716 	kfree(tb);
4717 	return 0;
4718 }
4719 
4720 static int ath11k_pull_mgmt_rx_params_tlv(struct ath11k_base *ab,
4721 					  struct sk_buff *skb,
4722 					  struct mgmt_rx_event_params *hdr)
4723 {
4724 	const void **tb;
4725 	const struct wmi_mgmt_rx_hdr *ev;
4726 	const u8 *frame;
4727 	int ret;
4728 
4729 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4730 	if (IS_ERR(tb)) {
4731 		ret = PTR_ERR(tb);
4732 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4733 		return ret;
4734 	}
4735 
4736 	ev = tb[WMI_TAG_MGMT_RX_HDR];
4737 	frame = tb[WMI_TAG_ARRAY_BYTE];
4738 
4739 	if (!ev || !frame) {
4740 		ath11k_warn(ab, "failed to fetch mgmt rx hdr");
4741 		kfree(tb);
4742 		return -EPROTO;
4743 	}
4744 
4745 	hdr->pdev_id =  ev->pdev_id;
4746 	hdr->chan_freq = ev->chan_freq;
4747 	hdr->channel =  ev->channel;
4748 	hdr->snr =  ev->snr;
4749 	hdr->rate =  ev->rate;
4750 	hdr->phy_mode =  ev->phy_mode;
4751 	hdr->buf_len =  ev->buf_len;
4752 	hdr->status =  ev->status;
4753 	hdr->flags =  ev->flags;
4754 	hdr->rssi =  ev->rssi;
4755 	hdr->tsf_delta =  ev->tsf_delta;
4756 	memcpy(hdr->rssi_ctl, ev->rssi_ctl, sizeof(hdr->rssi_ctl));
4757 
4758 	if (skb->len < (frame - skb->data) + hdr->buf_len) {
4759 		ath11k_warn(ab, "invalid length in mgmt rx hdr ev");
4760 		kfree(tb);
4761 		return -EPROTO;
4762 	}
4763 
4764 	/* shift the sk_buff to point to `frame` */
4765 	skb_trim(skb, 0);
4766 	skb_put(skb, frame - skb->data);
4767 	skb_pull(skb, frame - skb->data);
4768 	skb_put(skb, hdr->buf_len);
4769 
4770 	ath11k_ce_byte_swap(skb->data, hdr->buf_len);
4771 
4772 	kfree(tb);
4773 	return 0;
4774 }
4775 
4776 static int wmi_process_mgmt_tx_comp(struct ath11k *ar, u32 desc_id,
4777 				    u32 status)
4778 {
4779 	struct sk_buff *msdu;
4780 	struct ieee80211_tx_info *info;
4781 	struct ath11k_skb_cb *skb_cb;
4782 
4783 	spin_lock_bh(&ar->txmgmt_idr_lock);
4784 	msdu = idr_find(&ar->txmgmt_idr, desc_id);
4785 
4786 	if (!msdu) {
4787 		ath11k_warn(ar->ab, "received mgmt tx compl for invalid msdu_id: %d\n",
4788 			    desc_id);
4789 		spin_unlock_bh(&ar->txmgmt_idr_lock);
4790 		return -ENOENT;
4791 	}
4792 
4793 	idr_remove(&ar->txmgmt_idr, desc_id);
4794 	spin_unlock_bh(&ar->txmgmt_idr_lock);
4795 
4796 	skb_cb = ATH11K_SKB_CB(msdu);
4797 	dma_unmap_single(ar->ab->dev, skb_cb->paddr, msdu->len, DMA_TO_DEVICE);
4798 
4799 	info = IEEE80211_SKB_CB(msdu);
4800 	if ((!(info->flags & IEEE80211_TX_CTL_NO_ACK)) && !status)
4801 		info->flags |= IEEE80211_TX_STAT_ACK;
4802 
4803 	ieee80211_tx_status_irqsafe(ar->hw, msdu);
4804 
4805 	/* WARN when we received this event without doing any mgmt tx */
4806 	if (atomic_dec_if_positive(&ar->num_pending_mgmt_tx) < 0)
4807 		WARN_ON_ONCE(1);
4808 
4809 	return 0;
4810 }
4811 
4812 static int ath11k_pull_mgmt_tx_compl_param_tlv(struct ath11k_base *ab,
4813 					       struct sk_buff *skb,
4814 					       struct wmi_mgmt_tx_compl_event *param)
4815 {
4816 	const void **tb;
4817 	const struct wmi_mgmt_tx_compl_event *ev;
4818 	int ret;
4819 
4820 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4821 	if (IS_ERR(tb)) {
4822 		ret = PTR_ERR(tb);
4823 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4824 		return ret;
4825 	}
4826 
4827 	ev = tb[WMI_TAG_MGMT_TX_COMPL_EVENT];
4828 	if (!ev) {
4829 		ath11k_warn(ab, "failed to fetch mgmt tx compl ev");
4830 		kfree(tb);
4831 		return -EPROTO;
4832 	}
4833 
4834 	param->pdev_id = ev->pdev_id;
4835 	param->desc_id = ev->desc_id;
4836 	param->status = ev->status;
4837 
4838 	kfree(tb);
4839 	return 0;
4840 }
4841 
4842 static void ath11k_wmi_event_scan_started(struct ath11k *ar)
4843 {
4844 	lockdep_assert_held(&ar->data_lock);
4845 
4846 	switch (ar->scan.state) {
4847 	case ATH11K_SCAN_IDLE:
4848 	case ATH11K_SCAN_RUNNING:
4849 	case ATH11K_SCAN_ABORTING:
4850 		ath11k_warn(ar->ab, "received scan started event in an invalid scan state: %s (%d)\n",
4851 			    ath11k_scan_state_str(ar->scan.state),
4852 			    ar->scan.state);
4853 		break;
4854 	case ATH11K_SCAN_STARTING:
4855 		ar->scan.state = ATH11K_SCAN_RUNNING;
4856 		complete(&ar->scan.started);
4857 		break;
4858 	}
4859 }
4860 
4861 static void ath11k_wmi_event_scan_start_failed(struct ath11k *ar)
4862 {
4863 	lockdep_assert_held(&ar->data_lock);
4864 
4865 	switch (ar->scan.state) {
4866 	case ATH11K_SCAN_IDLE:
4867 	case ATH11K_SCAN_RUNNING:
4868 	case ATH11K_SCAN_ABORTING:
4869 		ath11k_warn(ar->ab, "received scan start failed event in an invalid scan state: %s (%d)\n",
4870 			    ath11k_scan_state_str(ar->scan.state),
4871 			    ar->scan.state);
4872 		break;
4873 	case ATH11K_SCAN_STARTING:
4874 		complete(&ar->scan.started);
4875 		__ath11k_mac_scan_finish(ar);
4876 		break;
4877 	}
4878 }
4879 
4880 static void ath11k_wmi_event_scan_completed(struct ath11k *ar)
4881 {
4882 	lockdep_assert_held(&ar->data_lock);
4883 
4884 	switch (ar->scan.state) {
4885 	case ATH11K_SCAN_IDLE:
4886 	case ATH11K_SCAN_STARTING:
4887 		/* One suspected reason scan can be completed while starting is
4888 		 * if firmware fails to deliver all scan events to the host,
4889 		 * e.g. when transport pipe is full. This has been observed
4890 		 * with spectral scan phyerr events starving wmi transport
4891 		 * pipe. In such case the "scan completed" event should be (and
4892 		 * is) ignored by the host as it may be just firmware's scan
4893 		 * state machine recovering.
4894 		 */
4895 		ath11k_warn(ar->ab, "received scan completed event in an invalid scan state: %s (%d)\n",
4896 			    ath11k_scan_state_str(ar->scan.state),
4897 			    ar->scan.state);
4898 		break;
4899 	case ATH11K_SCAN_RUNNING:
4900 	case ATH11K_SCAN_ABORTING:
4901 		__ath11k_mac_scan_finish(ar);
4902 		break;
4903 	}
4904 }
4905 
4906 static void ath11k_wmi_event_scan_bss_chan(struct ath11k *ar)
4907 {
4908 	lockdep_assert_held(&ar->data_lock);
4909 
4910 	switch (ar->scan.state) {
4911 	case ATH11K_SCAN_IDLE:
4912 	case ATH11K_SCAN_STARTING:
4913 		ath11k_warn(ar->ab, "received scan bss chan event in an invalid scan state: %s (%d)\n",
4914 			    ath11k_scan_state_str(ar->scan.state),
4915 			    ar->scan.state);
4916 		break;
4917 	case ATH11K_SCAN_RUNNING:
4918 	case ATH11K_SCAN_ABORTING:
4919 		ar->scan_channel = NULL;
4920 		break;
4921 	}
4922 }
4923 
4924 static void ath11k_wmi_event_scan_foreign_chan(struct ath11k *ar, u32 freq)
4925 {
4926 	lockdep_assert_held(&ar->data_lock);
4927 
4928 	switch (ar->scan.state) {
4929 	case ATH11K_SCAN_IDLE:
4930 	case ATH11K_SCAN_STARTING:
4931 		ath11k_warn(ar->ab, "received scan foreign chan event in an invalid scan state: %s (%d)\n",
4932 			    ath11k_scan_state_str(ar->scan.state),
4933 			    ar->scan.state);
4934 		break;
4935 	case ATH11K_SCAN_RUNNING:
4936 	case ATH11K_SCAN_ABORTING:
4937 		ar->scan_channel = ieee80211_get_channel(ar->hw->wiphy, freq);
4938 		break;
4939 	}
4940 }
4941 
4942 static const char *
4943 ath11k_wmi_event_scan_type_str(enum wmi_scan_event_type type,
4944 			       enum wmi_scan_completion_reason reason)
4945 {
4946 	switch (type) {
4947 	case WMI_SCAN_EVENT_STARTED:
4948 		return "started";
4949 	case WMI_SCAN_EVENT_COMPLETED:
4950 		switch (reason) {
4951 		case WMI_SCAN_REASON_COMPLETED:
4952 			return "completed";
4953 		case WMI_SCAN_REASON_CANCELLED:
4954 			return "completed [cancelled]";
4955 		case WMI_SCAN_REASON_PREEMPTED:
4956 			return "completed [preempted]";
4957 		case WMI_SCAN_REASON_TIMEDOUT:
4958 			return "completed [timedout]";
4959 		case WMI_SCAN_REASON_INTERNAL_FAILURE:
4960 			return "completed [internal err]";
4961 		case WMI_SCAN_REASON_MAX:
4962 			break;
4963 		}
4964 		return "completed [unknown]";
4965 	case WMI_SCAN_EVENT_BSS_CHANNEL:
4966 		return "bss channel";
4967 	case WMI_SCAN_EVENT_FOREIGN_CHAN:
4968 		return "foreign channel";
4969 	case WMI_SCAN_EVENT_DEQUEUED:
4970 		return "dequeued";
4971 	case WMI_SCAN_EVENT_PREEMPTED:
4972 		return "preempted";
4973 	case WMI_SCAN_EVENT_START_FAILED:
4974 		return "start failed";
4975 	case WMI_SCAN_EVENT_RESTARTED:
4976 		return "restarted";
4977 	case WMI_SCAN_EVENT_FOREIGN_CHAN_EXIT:
4978 		return "foreign channel exit";
4979 	default:
4980 		return "unknown";
4981 	}
4982 }
4983 
4984 static int ath11k_pull_scan_ev(struct ath11k_base *ab, struct sk_buff *skb,
4985 			       struct wmi_scan_event *scan_evt_param)
4986 {
4987 	const void **tb;
4988 	const struct wmi_scan_event *ev;
4989 	int ret;
4990 
4991 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4992 	if (IS_ERR(tb)) {
4993 		ret = PTR_ERR(tb);
4994 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4995 		return ret;
4996 	}
4997 
4998 	ev = tb[WMI_TAG_SCAN_EVENT];
4999 	if (!ev) {
5000 		ath11k_warn(ab, "failed to fetch scan ev");
5001 		kfree(tb);
5002 		return -EPROTO;
5003 	}
5004 
5005 	scan_evt_param->event_type = ev->event_type;
5006 	scan_evt_param->reason = ev->reason;
5007 	scan_evt_param->channel_freq = ev->channel_freq;
5008 	scan_evt_param->scan_req_id = ev->scan_req_id;
5009 	scan_evt_param->scan_id = ev->scan_id;
5010 	scan_evt_param->vdev_id = ev->vdev_id;
5011 	scan_evt_param->tsf_timestamp = ev->tsf_timestamp;
5012 
5013 	kfree(tb);
5014 	return 0;
5015 }
5016 
5017 static int ath11k_pull_peer_sta_kickout_ev(struct ath11k_base *ab, struct sk_buff *skb,
5018 					   struct wmi_peer_sta_kickout_arg *arg)
5019 {
5020 	const void **tb;
5021 	const struct wmi_peer_sta_kickout_event *ev;
5022 	int ret;
5023 
5024 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
5025 	if (IS_ERR(tb)) {
5026 		ret = PTR_ERR(tb);
5027 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5028 		return ret;
5029 	}
5030 
5031 	ev = tb[WMI_TAG_PEER_STA_KICKOUT_EVENT];
5032 	if (!ev) {
5033 		ath11k_warn(ab, "failed to fetch peer sta kickout ev");
5034 		kfree(tb);
5035 		return -EPROTO;
5036 	}
5037 
5038 	arg->mac_addr = ev->peer_macaddr.addr;
5039 
5040 	kfree(tb);
5041 	return 0;
5042 }
5043 
5044 static int ath11k_pull_roam_ev(struct ath11k_base *ab, struct sk_buff *skb,
5045 			       struct wmi_roam_event *roam_ev)
5046 {
5047 	const void **tb;
5048 	const struct wmi_roam_event *ev;
5049 	int ret;
5050 
5051 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
5052 	if (IS_ERR(tb)) {
5053 		ret = PTR_ERR(tb);
5054 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5055 		return ret;
5056 	}
5057 
5058 	ev = tb[WMI_TAG_ROAM_EVENT];
5059 	if (!ev) {
5060 		ath11k_warn(ab, "failed to fetch roam ev");
5061 		kfree(tb);
5062 		return -EPROTO;
5063 	}
5064 
5065 	roam_ev->vdev_id = ev->vdev_id;
5066 	roam_ev->reason = ev->reason;
5067 	roam_ev->rssi = ev->rssi;
5068 
5069 	kfree(tb);
5070 	return 0;
5071 }
5072 
5073 static int freq_to_idx(struct ath11k *ar, int freq)
5074 {
5075 	struct ieee80211_supported_band *sband;
5076 	int band, ch, idx = 0;
5077 
5078 	for (band = NL80211_BAND_2GHZ; band < NUM_NL80211_BANDS; band++) {
5079 		sband = ar->hw->wiphy->bands[band];
5080 		if (!sband)
5081 			continue;
5082 
5083 		for (ch = 0; ch < sband->n_channels; ch++, idx++)
5084 			if (sband->channels[ch].center_freq == freq)
5085 				goto exit;
5086 	}
5087 
5088 exit:
5089 	return idx;
5090 }
5091 
5092 static int ath11k_pull_chan_info_ev(struct ath11k_base *ab, u8 *evt_buf,
5093 				    u32 len, struct wmi_chan_info_event *ch_info_ev)
5094 {
5095 	const void **tb;
5096 	const struct wmi_chan_info_event *ev;
5097 	int ret;
5098 
5099 	tb = ath11k_wmi_tlv_parse_alloc(ab, evt_buf, len, GFP_ATOMIC);
5100 	if (IS_ERR(tb)) {
5101 		ret = PTR_ERR(tb);
5102 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5103 		return ret;
5104 	}
5105 
5106 	ev = tb[WMI_TAG_CHAN_INFO_EVENT];
5107 	if (!ev) {
5108 		ath11k_warn(ab, "failed to fetch chan info ev");
5109 		kfree(tb);
5110 		return -EPROTO;
5111 	}
5112 
5113 	ch_info_ev->err_code = ev->err_code;
5114 	ch_info_ev->freq = ev->freq;
5115 	ch_info_ev->cmd_flags = ev->cmd_flags;
5116 	ch_info_ev->noise_floor = ev->noise_floor;
5117 	ch_info_ev->rx_clear_count = ev->rx_clear_count;
5118 	ch_info_ev->cycle_count = ev->cycle_count;
5119 	ch_info_ev->chan_tx_pwr_range = ev->chan_tx_pwr_range;
5120 	ch_info_ev->chan_tx_pwr_tp = ev->chan_tx_pwr_tp;
5121 	ch_info_ev->rx_frame_count = ev->rx_frame_count;
5122 	ch_info_ev->tx_frame_cnt = ev->tx_frame_cnt;
5123 	ch_info_ev->mac_clk_mhz = ev->mac_clk_mhz;
5124 	ch_info_ev->vdev_id = ev->vdev_id;
5125 
5126 	kfree(tb);
5127 	return 0;
5128 }
5129 
5130 static int
5131 ath11k_pull_pdev_bss_chan_info_ev(struct ath11k_base *ab, struct sk_buff *skb,
5132 				  struct wmi_pdev_bss_chan_info_event *bss_ch_info_ev)
5133 {
5134 	const void **tb;
5135 	const struct wmi_pdev_bss_chan_info_event *ev;
5136 	int ret;
5137 
5138 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
5139 	if (IS_ERR(tb)) {
5140 		ret = PTR_ERR(tb);
5141 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5142 		return ret;
5143 	}
5144 
5145 	ev = tb[WMI_TAG_PDEV_BSS_CHAN_INFO_EVENT];
5146 	if (!ev) {
5147 		ath11k_warn(ab, "failed to fetch pdev bss chan info ev");
5148 		kfree(tb);
5149 		return -EPROTO;
5150 	}
5151 
5152 	bss_ch_info_ev->pdev_id = ev->pdev_id;
5153 	bss_ch_info_ev->freq = ev->freq;
5154 	bss_ch_info_ev->noise_floor = ev->noise_floor;
5155 	bss_ch_info_ev->rx_clear_count_low = ev->rx_clear_count_low;
5156 	bss_ch_info_ev->rx_clear_count_high = ev->rx_clear_count_high;
5157 	bss_ch_info_ev->cycle_count_low = ev->cycle_count_low;
5158 	bss_ch_info_ev->cycle_count_high = ev->cycle_count_high;
5159 	bss_ch_info_ev->tx_cycle_count_low = ev->tx_cycle_count_low;
5160 	bss_ch_info_ev->tx_cycle_count_high = ev->tx_cycle_count_high;
5161 	bss_ch_info_ev->rx_cycle_count_low = ev->rx_cycle_count_low;
5162 	bss_ch_info_ev->rx_cycle_count_high = ev->rx_cycle_count_high;
5163 	bss_ch_info_ev->rx_bss_cycle_count_low = ev->rx_bss_cycle_count_low;
5164 	bss_ch_info_ev->rx_bss_cycle_count_high = ev->rx_bss_cycle_count_high;
5165 
5166 	kfree(tb);
5167 	return 0;
5168 }
5169 
5170 static int
5171 ath11k_pull_vdev_install_key_compl_ev(struct ath11k_base *ab, struct sk_buff *skb,
5172 				      struct wmi_vdev_install_key_complete_arg *arg)
5173 {
5174 	const void **tb;
5175 	const struct wmi_vdev_install_key_compl_event *ev;
5176 	int ret;
5177 
5178 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
5179 	if (IS_ERR(tb)) {
5180 		ret = PTR_ERR(tb);
5181 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5182 		return ret;
5183 	}
5184 
5185 	ev = tb[WMI_TAG_VDEV_INSTALL_KEY_COMPLETE_EVENT];
5186 	if (!ev) {
5187 		ath11k_warn(ab, "failed to fetch vdev install key compl ev");
5188 		kfree(tb);
5189 		return -EPROTO;
5190 	}
5191 
5192 	arg->vdev_id = ev->vdev_id;
5193 	arg->macaddr = ev->peer_macaddr.addr;
5194 	arg->key_idx = ev->key_idx;
5195 	arg->key_flags = ev->key_flags;
5196 	arg->status = ev->status;
5197 
5198 	kfree(tb);
5199 	return 0;
5200 }
5201 
5202 static int ath11k_pull_peer_assoc_conf_ev(struct ath11k_base *ab, struct sk_buff *skb,
5203 					  struct wmi_peer_assoc_conf_arg *peer_assoc_conf)
5204 {
5205 	const void **tb;
5206 	const struct wmi_peer_assoc_conf_event *ev;
5207 	int ret;
5208 
5209 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
5210 	if (IS_ERR(tb)) {
5211 		ret = PTR_ERR(tb);
5212 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5213 		return ret;
5214 	}
5215 
5216 	ev = tb[WMI_TAG_PEER_ASSOC_CONF_EVENT];
5217 	if (!ev) {
5218 		ath11k_warn(ab, "failed to fetch peer assoc conf ev");
5219 		kfree(tb);
5220 		return -EPROTO;
5221 	}
5222 
5223 	peer_assoc_conf->vdev_id = ev->vdev_id;
5224 	peer_assoc_conf->macaddr = ev->peer_macaddr.addr;
5225 
5226 	kfree(tb);
5227 	return 0;
5228 }
5229 
5230 static void ath11k_wmi_pull_pdev_stats_base(const struct wmi_pdev_stats_base *src,
5231 					    struct ath11k_fw_stats_pdev *dst)
5232 {
5233 	dst->ch_noise_floor = src->chan_nf;
5234 	dst->tx_frame_count = src->tx_frame_count;
5235 	dst->rx_frame_count = src->rx_frame_count;
5236 	dst->rx_clear_count = src->rx_clear_count;
5237 	dst->cycle_count = src->cycle_count;
5238 	dst->phy_err_count = src->phy_err_count;
5239 	dst->chan_tx_power = src->chan_tx_pwr;
5240 }
5241 
5242 static void
5243 ath11k_wmi_pull_pdev_stats_tx(const struct wmi_pdev_stats_tx *src,
5244 			      struct ath11k_fw_stats_pdev *dst)
5245 {
5246 	dst->comp_queued = src->comp_queued;
5247 	dst->comp_delivered = src->comp_delivered;
5248 	dst->msdu_enqued = src->msdu_enqued;
5249 	dst->mpdu_enqued = src->mpdu_enqued;
5250 	dst->wmm_drop = src->wmm_drop;
5251 	dst->local_enqued = src->local_enqued;
5252 	dst->local_freed = src->local_freed;
5253 	dst->hw_queued = src->hw_queued;
5254 	dst->hw_reaped = src->hw_reaped;
5255 	dst->underrun = src->underrun;
5256 	dst->hw_paused = src->hw_paused;
5257 	dst->tx_abort = src->tx_abort;
5258 	dst->mpdus_requeued = src->mpdus_requeued;
5259 	dst->tx_ko = src->tx_ko;
5260 	dst->tx_xretry = src->tx_xretry;
5261 	dst->data_rc = src->data_rc;
5262 	dst->self_triggers = src->self_triggers;
5263 	dst->sw_retry_failure = src->sw_retry_failure;
5264 	dst->illgl_rate_phy_err = src->illgl_rate_phy_err;
5265 	dst->pdev_cont_xretry = src->pdev_cont_xretry;
5266 	dst->pdev_tx_timeout = src->pdev_tx_timeout;
5267 	dst->pdev_resets = src->pdev_resets;
5268 	dst->stateless_tid_alloc_failure = src->stateless_tid_alloc_failure;
5269 	dst->phy_underrun = src->phy_underrun;
5270 	dst->txop_ovf = src->txop_ovf;
5271 	dst->seq_posted = src->seq_posted;
5272 	dst->seq_failed_queueing = src->seq_failed_queueing;
5273 	dst->seq_completed = src->seq_completed;
5274 	dst->seq_restarted = src->seq_restarted;
5275 	dst->mu_seq_posted = src->mu_seq_posted;
5276 	dst->mpdus_sw_flush = src->mpdus_sw_flush;
5277 	dst->mpdus_hw_filter = src->mpdus_hw_filter;
5278 	dst->mpdus_truncated = src->mpdus_truncated;
5279 	dst->mpdus_ack_failed = src->mpdus_ack_failed;
5280 	dst->mpdus_expired = src->mpdus_expired;
5281 }
5282 
5283 static void ath11k_wmi_pull_pdev_stats_rx(const struct wmi_pdev_stats_rx *src,
5284 					  struct ath11k_fw_stats_pdev *dst)
5285 {
5286 	dst->mid_ppdu_route_change = src->mid_ppdu_route_change;
5287 	dst->status_rcvd = src->status_rcvd;
5288 	dst->r0_frags = src->r0_frags;
5289 	dst->r1_frags = src->r1_frags;
5290 	dst->r2_frags = src->r2_frags;
5291 	dst->r3_frags = src->r3_frags;
5292 	dst->htt_msdus = src->htt_msdus;
5293 	dst->htt_mpdus = src->htt_mpdus;
5294 	dst->loc_msdus = src->loc_msdus;
5295 	dst->loc_mpdus = src->loc_mpdus;
5296 	dst->oversize_amsdu = src->oversize_amsdu;
5297 	dst->phy_errs = src->phy_errs;
5298 	dst->phy_err_drop = src->phy_err_drop;
5299 	dst->mpdu_errs = src->mpdu_errs;
5300 	dst->rx_ovfl_errs = src->rx_ovfl_errs;
5301 }
5302 
5303 static void
5304 ath11k_wmi_pull_vdev_stats(const struct wmi_vdev_stats *src,
5305 			   struct ath11k_fw_stats_vdev *dst)
5306 {
5307 	int i;
5308 
5309 	dst->vdev_id = src->vdev_id;
5310 	dst->beacon_snr = src->beacon_snr;
5311 	dst->data_snr = src->data_snr;
5312 	dst->num_rx_frames = src->num_rx_frames;
5313 	dst->num_rts_fail = src->num_rts_fail;
5314 	dst->num_rts_success = src->num_rts_success;
5315 	dst->num_rx_err = src->num_rx_err;
5316 	dst->num_rx_discard = src->num_rx_discard;
5317 	dst->num_tx_not_acked = src->num_tx_not_acked;
5318 
5319 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames); i++)
5320 		dst->num_tx_frames[i] = src->num_tx_frames[i];
5321 
5322 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_retries); i++)
5323 		dst->num_tx_frames_retries[i] = src->num_tx_frames_retries[i];
5324 
5325 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_failures); i++)
5326 		dst->num_tx_frames_failures[i] = src->num_tx_frames_failures[i];
5327 
5328 	for (i = 0; i < ARRAY_SIZE(src->tx_rate_history); i++)
5329 		dst->tx_rate_history[i] = src->tx_rate_history[i];
5330 
5331 	for (i = 0; i < ARRAY_SIZE(src->beacon_rssi_history); i++)
5332 		dst->beacon_rssi_history[i] = src->beacon_rssi_history[i];
5333 }
5334 
5335 static void
5336 ath11k_wmi_pull_bcn_stats(const struct wmi_bcn_stats *src,
5337 			  struct ath11k_fw_stats_bcn *dst)
5338 {
5339 	dst->vdev_id = src->vdev_id;
5340 	dst->tx_bcn_succ_cnt = src->tx_bcn_succ_cnt;
5341 	dst->tx_bcn_outage_cnt = src->tx_bcn_outage_cnt;
5342 }
5343 
5344 int ath11k_wmi_pull_fw_stats(struct ath11k_base *ab, struct sk_buff *skb,
5345 			     struct ath11k_fw_stats *stats)
5346 {
5347 	const void **tb;
5348 	const struct wmi_stats_event *ev;
5349 	const void *data;
5350 	int i, ret;
5351 	u32 len = skb->len;
5352 
5353 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, len, GFP_ATOMIC);
5354 	if (IS_ERR(tb)) {
5355 		ret = PTR_ERR(tb);
5356 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5357 		return ret;
5358 	}
5359 
5360 	ev = tb[WMI_TAG_STATS_EVENT];
5361 	data = tb[WMI_TAG_ARRAY_BYTE];
5362 	if (!ev || !data) {
5363 		ath11k_warn(ab, "failed to fetch update stats ev");
5364 		kfree(tb);
5365 		return -EPROTO;
5366 	}
5367 
5368 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5369 		   "wmi stats update ev pdev_id %d pdev %i vdev %i bcn %i\n",
5370 		   ev->pdev_id,
5371 		   ev->num_pdev_stats, ev->num_vdev_stats,
5372 		   ev->num_bcn_stats);
5373 
5374 	stats->pdev_id = ev->pdev_id;
5375 	stats->stats_id = 0;
5376 
5377 	for (i = 0; i < ev->num_pdev_stats; i++) {
5378 		const struct wmi_pdev_stats *src;
5379 		struct ath11k_fw_stats_pdev *dst;
5380 
5381 		src = data;
5382 		if (len < sizeof(*src)) {
5383 			kfree(tb);
5384 			return -EPROTO;
5385 		}
5386 
5387 		stats->stats_id = WMI_REQUEST_PDEV_STAT;
5388 
5389 		data += sizeof(*src);
5390 		len -= sizeof(*src);
5391 
5392 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
5393 		if (!dst)
5394 			continue;
5395 
5396 		ath11k_wmi_pull_pdev_stats_base(&src->base, dst);
5397 		ath11k_wmi_pull_pdev_stats_tx(&src->tx, dst);
5398 		ath11k_wmi_pull_pdev_stats_rx(&src->rx, dst);
5399 		list_add_tail(&dst->list, &stats->pdevs);
5400 	}
5401 
5402 	for (i = 0; i < ev->num_vdev_stats; i++) {
5403 		const struct wmi_vdev_stats *src;
5404 		struct ath11k_fw_stats_vdev *dst;
5405 
5406 		src = data;
5407 		if (len < sizeof(*src)) {
5408 			kfree(tb);
5409 			return -EPROTO;
5410 		}
5411 
5412 		stats->stats_id = WMI_REQUEST_VDEV_STAT;
5413 
5414 		data += sizeof(*src);
5415 		len -= sizeof(*src);
5416 
5417 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
5418 		if (!dst)
5419 			continue;
5420 
5421 		ath11k_wmi_pull_vdev_stats(src, dst);
5422 		list_add_tail(&dst->list, &stats->vdevs);
5423 	}
5424 
5425 	for (i = 0; i < ev->num_bcn_stats; i++) {
5426 		const struct wmi_bcn_stats *src;
5427 		struct ath11k_fw_stats_bcn *dst;
5428 
5429 		src = data;
5430 		if (len < sizeof(*src)) {
5431 			kfree(tb);
5432 			return -EPROTO;
5433 		}
5434 
5435 		stats->stats_id = WMI_REQUEST_BCN_STAT;
5436 
5437 		data += sizeof(*src);
5438 		len -= sizeof(*src);
5439 
5440 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
5441 		if (!dst)
5442 			continue;
5443 
5444 		ath11k_wmi_pull_bcn_stats(src, dst);
5445 		list_add_tail(&dst->list, &stats->bcn);
5446 	}
5447 
5448 	kfree(tb);
5449 	return 0;
5450 }
5451 
5452 size_t ath11k_wmi_fw_stats_num_vdevs(struct list_head *head)
5453 {
5454 	struct ath11k_fw_stats_vdev *i;
5455 	size_t num = 0;
5456 
5457 	list_for_each_entry(i, head, list)
5458 		++num;
5459 
5460 	return num;
5461 }
5462 
5463 static size_t ath11k_wmi_fw_stats_num_bcn(struct list_head *head)
5464 {
5465 	struct ath11k_fw_stats_bcn *i;
5466 	size_t num = 0;
5467 
5468 	list_for_each_entry(i, head, list)
5469 		++num;
5470 
5471 	return num;
5472 }
5473 
5474 static void
5475 ath11k_wmi_fw_pdev_base_stats_fill(const struct ath11k_fw_stats_pdev *pdev,
5476 				   char *buf, u32 *length)
5477 {
5478 	u32 len = *length;
5479 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5480 
5481 	len += scnprintf(buf + len, buf_len - len, "\n");
5482 	len += scnprintf(buf + len, buf_len - len, "%30s\n",
5483 			"ath11k PDEV stats");
5484 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5485 			"=================");
5486 
5487 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5488 			"Channel noise floor", pdev->ch_noise_floor);
5489 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5490 			"Channel TX power", pdev->chan_tx_power);
5491 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5492 			"TX frame count", pdev->tx_frame_count);
5493 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5494 			"RX frame count", pdev->rx_frame_count);
5495 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5496 			"RX clear count", pdev->rx_clear_count);
5497 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5498 			"Cycle count", pdev->cycle_count);
5499 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5500 			"PHY error count", pdev->phy_err_count);
5501 
5502 	*length = len;
5503 }
5504 
5505 static void
5506 ath11k_wmi_fw_pdev_tx_stats_fill(const struct ath11k_fw_stats_pdev *pdev,
5507 				 char *buf, u32 *length)
5508 {
5509 	u32 len = *length;
5510 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5511 
5512 	len += scnprintf(buf + len, buf_len - len, "\n%30s\n",
5513 			 "ath11k PDEV TX stats");
5514 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5515 			 "====================");
5516 
5517 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5518 			 "HTT cookies queued", pdev->comp_queued);
5519 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5520 			 "HTT cookies disp.", pdev->comp_delivered);
5521 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5522 			 "MSDU queued", pdev->msdu_enqued);
5523 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5524 			 "MPDU queued", pdev->mpdu_enqued);
5525 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5526 			 "MSDUs dropped", pdev->wmm_drop);
5527 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5528 			 "Local enqued", pdev->local_enqued);
5529 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5530 			 "Local freed", pdev->local_freed);
5531 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5532 			 "HW queued", pdev->hw_queued);
5533 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5534 			 "PPDUs reaped", pdev->hw_reaped);
5535 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5536 			 "Num underruns", pdev->underrun);
5537 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5538 			 "Num HW Paused", pdev->hw_paused);
5539 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5540 			 "PPDUs cleaned", pdev->tx_abort);
5541 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5542 			 "MPDUs requeued", pdev->mpdus_requeued);
5543 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5544 			 "PPDU OK", pdev->tx_ko);
5545 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5546 			 "Excessive retries", pdev->tx_xretry);
5547 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5548 			 "HW rate", pdev->data_rc);
5549 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5550 			 "Sched self triggers", pdev->self_triggers);
5551 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5552 			 "Dropped due to SW retries",
5553 			 pdev->sw_retry_failure);
5554 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5555 			 "Illegal rate phy errors",
5556 			 pdev->illgl_rate_phy_err);
5557 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5558 			 "PDEV continuous xretry", pdev->pdev_cont_xretry);
5559 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5560 			 "TX timeout", pdev->pdev_tx_timeout);
5561 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5562 			 "PDEV resets", pdev->pdev_resets);
5563 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5564 			 "Stateless TIDs alloc failures",
5565 			 pdev->stateless_tid_alloc_failure);
5566 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5567 			 "PHY underrun", pdev->phy_underrun);
5568 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5569 			 "MPDU is more than txop limit", pdev->txop_ovf);
5570 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5571 			 "Num sequences posted", pdev->seq_posted);
5572 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5573 			 "Num seq failed queueing ", pdev->seq_failed_queueing);
5574 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5575 			 "Num sequences completed ", pdev->seq_completed);
5576 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5577 			 "Num sequences restarted ", pdev->seq_restarted);
5578 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5579 			 "Num of MU sequences posted ", pdev->mu_seq_posted);
5580 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5581 			 "Num of MPDUS SW flushed ", pdev->mpdus_sw_flush);
5582 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5583 			 "Num of MPDUS HW filtered ", pdev->mpdus_hw_filter);
5584 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5585 			 "Num of MPDUS truncated ", pdev->mpdus_truncated);
5586 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5587 			 "Num of MPDUS ACK failed ", pdev->mpdus_ack_failed);
5588 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5589 			 "Num of MPDUS expired ", pdev->mpdus_expired);
5590 	*length = len;
5591 }
5592 
5593 static void
5594 ath11k_wmi_fw_pdev_rx_stats_fill(const struct ath11k_fw_stats_pdev *pdev,
5595 				 char *buf, u32 *length)
5596 {
5597 	u32 len = *length;
5598 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5599 
5600 	len += scnprintf(buf + len, buf_len - len, "\n%30s\n",
5601 			 "ath11k PDEV RX stats");
5602 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5603 			 "====================");
5604 
5605 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5606 			 "Mid PPDU route change",
5607 			 pdev->mid_ppdu_route_change);
5608 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5609 			 "Tot. number of statuses", pdev->status_rcvd);
5610 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5611 			 "Extra frags on rings 0", pdev->r0_frags);
5612 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5613 			 "Extra frags on rings 1", pdev->r1_frags);
5614 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5615 			 "Extra frags on rings 2", pdev->r2_frags);
5616 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5617 			 "Extra frags on rings 3", pdev->r3_frags);
5618 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5619 			 "MSDUs delivered to HTT", pdev->htt_msdus);
5620 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5621 			 "MPDUs delivered to HTT", pdev->htt_mpdus);
5622 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5623 			 "MSDUs delivered to stack", pdev->loc_msdus);
5624 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5625 			 "MPDUs delivered to stack", pdev->loc_mpdus);
5626 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5627 			 "Oversized AMSUs", pdev->oversize_amsdu);
5628 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5629 			 "PHY errors", pdev->phy_errs);
5630 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5631 			 "PHY errors drops", pdev->phy_err_drop);
5632 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5633 			 "MPDU errors (FCS, MIC, ENC)", pdev->mpdu_errs);
5634 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5635 			 "Overflow errors", pdev->rx_ovfl_errs);
5636 	*length = len;
5637 }
5638 
5639 static void
5640 ath11k_wmi_fw_vdev_stats_fill(struct ath11k *ar,
5641 			      const struct ath11k_fw_stats_vdev *vdev,
5642 			      char *buf, u32 *length)
5643 {
5644 	u32 len = *length;
5645 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5646 	struct ath11k_vif *arvif = ath11k_mac_get_arvif(ar, vdev->vdev_id);
5647 	u8 *vif_macaddr;
5648 	int i;
5649 
5650 	/* VDEV stats has all the active VDEVs of other PDEVs as well,
5651 	 * ignoring those not part of requested PDEV
5652 	 */
5653 	if (!arvif)
5654 		return;
5655 
5656 	vif_macaddr = arvif->vif->addr;
5657 
5658 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5659 			 "VDEV ID", vdev->vdev_id);
5660 	len += scnprintf(buf + len, buf_len - len, "%30s %pM\n",
5661 			 "VDEV MAC address", vif_macaddr);
5662 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5663 			 "beacon snr", vdev->beacon_snr);
5664 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5665 			 "data snr", vdev->data_snr);
5666 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5667 			 "num rx frames", vdev->num_rx_frames);
5668 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5669 			 "num rts fail", vdev->num_rts_fail);
5670 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5671 			 "num rts success", vdev->num_rts_success);
5672 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5673 			 "num rx err", vdev->num_rx_err);
5674 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5675 			 "num rx discard", vdev->num_rx_discard);
5676 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5677 			 "num tx not acked", vdev->num_tx_not_acked);
5678 
5679 	for (i = 0 ; i < ARRAY_SIZE(vdev->num_tx_frames); i++)
5680 		len += scnprintf(buf + len, buf_len - len,
5681 				"%25s [%02d] %u\n",
5682 				"num tx frames", i,
5683 				vdev->num_tx_frames[i]);
5684 
5685 	for (i = 0 ; i < ARRAY_SIZE(vdev->num_tx_frames_retries); i++)
5686 		len += scnprintf(buf + len, buf_len - len,
5687 				"%25s [%02d] %u\n",
5688 				"num tx frames retries", i,
5689 				vdev->num_tx_frames_retries[i]);
5690 
5691 	for (i = 0 ; i < ARRAY_SIZE(vdev->num_tx_frames_failures); i++)
5692 		len += scnprintf(buf + len, buf_len - len,
5693 				"%25s [%02d] %u\n",
5694 				"num tx frames failures", i,
5695 				vdev->num_tx_frames_failures[i]);
5696 
5697 	for (i = 0 ; i < ARRAY_SIZE(vdev->tx_rate_history); i++)
5698 		len += scnprintf(buf + len, buf_len - len,
5699 				"%25s [%02d] 0x%08x\n",
5700 				"tx rate history", i,
5701 				vdev->tx_rate_history[i]);
5702 
5703 	for (i = 0 ; i < ARRAY_SIZE(vdev->beacon_rssi_history); i++)
5704 		len += scnprintf(buf + len, buf_len - len,
5705 				"%25s [%02d] %u\n",
5706 				"beacon rssi history", i,
5707 				vdev->beacon_rssi_history[i]);
5708 
5709 	len += scnprintf(buf + len, buf_len - len, "\n");
5710 	*length = len;
5711 }
5712 
5713 static void
5714 ath11k_wmi_fw_bcn_stats_fill(struct ath11k *ar,
5715 			     const struct ath11k_fw_stats_bcn *bcn,
5716 			     char *buf, u32 *length)
5717 {
5718 	u32 len = *length;
5719 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5720 	struct ath11k_vif *arvif = ath11k_mac_get_arvif(ar, bcn->vdev_id);
5721 	u8 *vdev_macaddr;
5722 
5723 	if (!arvif) {
5724 		ath11k_warn(ar->ab, "invalid vdev id %d in bcn stats",
5725 			    bcn->vdev_id);
5726 		return;
5727 	}
5728 
5729 	vdev_macaddr = arvif->vif->addr;
5730 
5731 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5732 			 "VDEV ID", bcn->vdev_id);
5733 	len += scnprintf(buf + len, buf_len - len, "%30s %pM\n",
5734 			 "VDEV MAC address", vdev_macaddr);
5735 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5736 			 "================");
5737 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5738 			 "Num of beacon tx success", bcn->tx_bcn_succ_cnt);
5739 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5740 			 "Num of beacon tx failures", bcn->tx_bcn_outage_cnt);
5741 
5742 	len += scnprintf(buf + len, buf_len - len, "\n");
5743 	*length = len;
5744 }
5745 
5746 void ath11k_wmi_fw_stats_fill(struct ath11k *ar,
5747 			      struct ath11k_fw_stats *fw_stats,
5748 			      u32 stats_id, char *buf)
5749 {
5750 	u32 len = 0;
5751 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5752 	const struct ath11k_fw_stats_pdev *pdev;
5753 	const struct ath11k_fw_stats_vdev *vdev;
5754 	const struct ath11k_fw_stats_bcn *bcn;
5755 	size_t num_bcn;
5756 
5757 	spin_lock_bh(&ar->data_lock);
5758 
5759 	if (stats_id == WMI_REQUEST_PDEV_STAT) {
5760 		pdev = list_first_entry_or_null(&fw_stats->pdevs,
5761 						struct ath11k_fw_stats_pdev, list);
5762 		if (!pdev) {
5763 			ath11k_warn(ar->ab, "failed to get pdev stats\n");
5764 			goto unlock;
5765 		}
5766 
5767 		ath11k_wmi_fw_pdev_base_stats_fill(pdev, buf, &len);
5768 		ath11k_wmi_fw_pdev_tx_stats_fill(pdev, buf, &len);
5769 		ath11k_wmi_fw_pdev_rx_stats_fill(pdev, buf, &len);
5770 	}
5771 
5772 	if (stats_id == WMI_REQUEST_VDEV_STAT) {
5773 		len += scnprintf(buf + len, buf_len - len, "\n");
5774 		len += scnprintf(buf + len, buf_len - len, "%30s\n",
5775 				 "ath11k VDEV stats");
5776 		len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5777 				 "=================");
5778 
5779 		list_for_each_entry(vdev, &fw_stats->vdevs, list)
5780 			ath11k_wmi_fw_vdev_stats_fill(ar, vdev, buf, &len);
5781 	}
5782 
5783 	if (stats_id == WMI_REQUEST_BCN_STAT) {
5784 		num_bcn = ath11k_wmi_fw_stats_num_bcn(&fw_stats->bcn);
5785 
5786 		len += scnprintf(buf + len, buf_len - len, "\n");
5787 		len += scnprintf(buf + len, buf_len - len, "%30s (%zu)\n",
5788 				 "ath11k Beacon stats", num_bcn);
5789 		len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5790 				 "===================");
5791 
5792 		list_for_each_entry(bcn, &fw_stats->bcn, list)
5793 			ath11k_wmi_fw_bcn_stats_fill(ar, bcn, buf, &len);
5794 	}
5795 
5796 unlock:
5797 	spin_unlock_bh(&ar->data_lock);
5798 
5799 	if (len >= buf_len)
5800 		buf[len - 1] = 0;
5801 	else
5802 		buf[len] = 0;
5803 }
5804 
5805 static void ath11k_wmi_op_ep_tx_credits(struct ath11k_base *ab)
5806 {
5807 	/* try to send pending beacons first. they take priority */
5808 	wake_up(&ab->wmi_ab.tx_credits_wq);
5809 }
5810 
5811 static void ath11k_wmi_htc_tx_complete(struct ath11k_base *ab,
5812 				       struct sk_buff *skb)
5813 {
5814 	dev_kfree_skb(skb);
5815 }
5816 
5817 static bool ath11k_reg_is_world_alpha(char *alpha)
5818 {
5819 	return alpha[0] == '0' && alpha[1] == '0';
5820 }
5821 
5822 static int ath11k_reg_chan_list_event(struct ath11k_base *ab, struct sk_buff *skb)
5823 {
5824 	struct cur_regulatory_info *reg_info = NULL;
5825 	struct ieee80211_regdomain *regd = NULL;
5826 	bool intersect = false;
5827 	int ret = 0, pdev_idx;
5828 	struct ath11k *ar;
5829 
5830 	reg_info = kzalloc(sizeof(*reg_info), GFP_ATOMIC);
5831 	if (!reg_info) {
5832 		ret = -ENOMEM;
5833 		goto fallback;
5834 	}
5835 
5836 	ret = ath11k_pull_reg_chan_list_update_ev(ab, skb, reg_info);
5837 	if (ret) {
5838 		ath11k_warn(ab, "failed to extract regulatory info from received event\n");
5839 		goto fallback;
5840 	}
5841 
5842 	if (reg_info->status_code != REG_SET_CC_STATUS_PASS) {
5843 		/* In case of failure to set the requested ctry,
5844 		 * fw retains the current regd. We print a failure info
5845 		 * and return from here.
5846 		 */
5847 		ath11k_warn(ab, "Failed to set the requested Country regulatory setting\n");
5848 		goto mem_free;
5849 	}
5850 
5851 	pdev_idx = reg_info->phy_id;
5852 
5853 	/* Avoid default reg rule updates sent during FW recovery if
5854 	 * it is already available
5855 	 */
5856 	spin_lock(&ab->base_lock);
5857 	if (test_bit(ATH11K_FLAG_RECOVERY, &ab->dev_flags) &&
5858 	    ab->default_regd[pdev_idx]) {
5859 		spin_unlock(&ab->base_lock);
5860 		goto mem_free;
5861 	}
5862 	spin_unlock(&ab->base_lock);
5863 
5864 	if (pdev_idx >= ab->num_radios) {
5865 		/* Process the event for phy0 only if single_pdev_only
5866 		 * is true. If pdev_idx is valid but not 0, discard the
5867 		 * event. Otherwise, it goes to fallback.
5868 		 */
5869 		if (ab->hw_params.single_pdev_only &&
5870 		    pdev_idx < ab->hw_params.num_rxmda_per_pdev)
5871 			goto mem_free;
5872 		else
5873 			goto fallback;
5874 	}
5875 
5876 	/* Avoid multiple overwrites to default regd, during core
5877 	 * stop-start after mac registration.
5878 	 */
5879 	if (ab->default_regd[pdev_idx] && !ab->new_regd[pdev_idx] &&
5880 	    !memcmp((char *)ab->default_regd[pdev_idx]->alpha2,
5881 		    (char *)reg_info->alpha2, 2))
5882 		goto mem_free;
5883 
5884 	/* Intersect new rules with default regd if a new country setting was
5885 	 * requested, i.e a default regd was already set during initialization
5886 	 * and the regd coming from this event has a valid country info.
5887 	 */
5888 	if (ab->default_regd[pdev_idx] &&
5889 	    !ath11k_reg_is_world_alpha((char *)
5890 		ab->default_regd[pdev_idx]->alpha2) &&
5891 	    !ath11k_reg_is_world_alpha((char *)reg_info->alpha2))
5892 		intersect = true;
5893 
5894 	regd = ath11k_reg_build_regd(ab, reg_info, intersect);
5895 	if (!regd) {
5896 		ath11k_warn(ab, "failed to build regd from reg_info\n");
5897 		goto fallback;
5898 	}
5899 
5900 	spin_lock(&ab->base_lock);
5901 	if (ab->default_regd[pdev_idx]) {
5902 		/* The initial rules from FW after WMI Init is to build
5903 		 * the default regd. From then on, any rules updated for
5904 		 * the pdev could be due to user reg changes.
5905 		 * Free previously built regd before assigning the newly
5906 		 * generated regd to ar. NULL pointer handling will be
5907 		 * taken care by kfree itself.
5908 		 */
5909 		ar = ab->pdevs[pdev_idx].ar;
5910 		kfree(ab->new_regd[pdev_idx]);
5911 		ab->new_regd[pdev_idx] = regd;
5912 		ieee80211_queue_work(ar->hw, &ar->regd_update_work);
5913 	} else {
5914 		/* This regd would be applied during mac registration and is
5915 		 * held constant throughout for regd intersection purpose
5916 		 */
5917 		ab->default_regd[pdev_idx] = regd;
5918 	}
5919 	ab->dfs_region = reg_info->dfs_region;
5920 	spin_unlock(&ab->base_lock);
5921 
5922 	goto mem_free;
5923 
5924 fallback:
5925 	/* Fallback to older reg (by sending previous country setting
5926 	 * again if fw has succeded and we failed to process here.
5927 	 * The Regdomain should be uniform across driver and fw. Since the
5928 	 * FW has processed the command and sent a success status, we expect
5929 	 * this function to succeed as well. If it doesn't, CTRY needs to be
5930 	 * reverted at the fw and the old SCAN_CHAN_LIST cmd needs to be sent.
5931 	 */
5932 	/* TODO: This is rare, but still should also be handled */
5933 	WARN_ON(1);
5934 mem_free:
5935 	if (reg_info) {
5936 		kfree(reg_info->reg_rules_2g_ptr);
5937 		kfree(reg_info->reg_rules_5g_ptr);
5938 		kfree(reg_info);
5939 	}
5940 	return ret;
5941 }
5942 
5943 static int ath11k_wmi_tlv_rdy_parse(struct ath11k_base *ab, u16 tag, u16 len,
5944 				    const void *ptr, void *data)
5945 {
5946 	struct wmi_tlv_rdy_parse *rdy_parse = data;
5947 	struct wmi_ready_event fixed_param;
5948 	struct wmi_mac_addr *addr_list;
5949 	struct ath11k_pdev *pdev;
5950 	u32 num_mac_addr;
5951 	int i;
5952 
5953 	switch (tag) {
5954 	case WMI_TAG_READY_EVENT:
5955 		memset(&fixed_param, 0, sizeof(fixed_param));
5956 		memcpy(&fixed_param, (struct wmi_ready_event *)ptr,
5957 		       min_t(u16, sizeof(fixed_param), len));
5958 		ab->wlan_init_status = fixed_param.ready_event_min.status;
5959 		rdy_parse->num_extra_mac_addr =
5960 			fixed_param.ready_event_min.num_extra_mac_addr;
5961 
5962 		ether_addr_copy(ab->mac_addr,
5963 				fixed_param.ready_event_min.mac_addr.addr);
5964 		ab->pktlog_defs_checksum = fixed_param.pktlog_defs_checksum;
5965 		ab->wmi_ready = true;
5966 		break;
5967 	case WMI_TAG_ARRAY_FIXED_STRUCT:
5968 		addr_list = (struct wmi_mac_addr *)ptr;
5969 		num_mac_addr = rdy_parse->num_extra_mac_addr;
5970 
5971 		if (!(ab->num_radios > 1 && num_mac_addr >= ab->num_radios))
5972 			break;
5973 
5974 		for (i = 0; i < ab->num_radios; i++) {
5975 			pdev = &ab->pdevs[i];
5976 			ether_addr_copy(pdev->mac_addr, addr_list[i].addr);
5977 		}
5978 		ab->pdevs_macaddr_valid = true;
5979 		break;
5980 	default:
5981 		break;
5982 	}
5983 
5984 	return 0;
5985 }
5986 
5987 static int ath11k_ready_event(struct ath11k_base *ab, struct sk_buff *skb)
5988 {
5989 	struct wmi_tlv_rdy_parse rdy_parse = { };
5990 	int ret;
5991 
5992 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
5993 				  ath11k_wmi_tlv_rdy_parse, &rdy_parse);
5994 	if (ret) {
5995 		ath11k_warn(ab, "failed to parse tlv %d\n", ret);
5996 		return ret;
5997 	}
5998 
5999 	complete(&ab->wmi_ab.unified_ready);
6000 	return 0;
6001 }
6002 
6003 static void ath11k_peer_delete_resp_event(struct ath11k_base *ab, struct sk_buff *skb)
6004 {
6005 	struct wmi_peer_delete_resp_event peer_del_resp;
6006 	struct ath11k *ar;
6007 
6008 	if (ath11k_pull_peer_del_resp_ev(ab, skb, &peer_del_resp) != 0) {
6009 		ath11k_warn(ab, "failed to extract peer delete resp");
6010 		return;
6011 	}
6012 
6013 	rcu_read_lock();
6014 	ar = ath11k_mac_get_ar_by_vdev_id(ab, peer_del_resp.vdev_id);
6015 	if (!ar) {
6016 		ath11k_warn(ab, "invalid vdev id in peer delete resp ev %d",
6017 			    peer_del_resp.vdev_id);
6018 		rcu_read_unlock();
6019 		return;
6020 	}
6021 
6022 	complete(&ar->peer_delete_done);
6023 	rcu_read_unlock();
6024 	ath11k_dbg(ab, ATH11K_DBG_WMI, "peer delete resp for vdev id %d addr %pM\n",
6025 		   peer_del_resp.vdev_id, peer_del_resp.peer_macaddr.addr);
6026 }
6027 
6028 static void ath11k_vdev_delete_resp_event(struct ath11k_base *ab,
6029 					  struct sk_buff *skb)
6030 {
6031 	struct ath11k *ar;
6032 	u32 vdev_id = 0;
6033 
6034 	if (ath11k_pull_vdev_del_resp_ev(ab, skb, &vdev_id) != 0) {
6035 		ath11k_warn(ab, "failed to extract vdev delete resp");
6036 		return;
6037 	}
6038 
6039 	rcu_read_lock();
6040 	ar = ath11k_mac_get_ar_by_vdev_id(ab, vdev_id);
6041 	if (!ar) {
6042 		ath11k_warn(ab, "invalid vdev id in vdev delete resp ev %d",
6043 			    vdev_id);
6044 		rcu_read_unlock();
6045 		return;
6046 	}
6047 
6048 	complete(&ar->vdev_delete_done);
6049 
6050 	rcu_read_unlock();
6051 
6052 	ath11k_dbg(ab, ATH11K_DBG_WMI, "vdev delete resp for vdev id %d\n",
6053 		   vdev_id);
6054 }
6055 
6056 static inline const char *ath11k_wmi_vdev_resp_print(u32 vdev_resp_status)
6057 {
6058 	switch (vdev_resp_status) {
6059 	case WMI_VDEV_START_RESPONSE_INVALID_VDEVID:
6060 		return "invalid vdev id";
6061 	case WMI_VDEV_START_RESPONSE_NOT_SUPPORTED:
6062 		return "not supported";
6063 	case WMI_VDEV_START_RESPONSE_DFS_VIOLATION:
6064 		return "dfs violation";
6065 	case WMI_VDEV_START_RESPONSE_INVALID_REGDOMAIN:
6066 		return "invalid regdomain";
6067 	default:
6068 		return "unknown";
6069 	}
6070 }
6071 
6072 static void ath11k_vdev_start_resp_event(struct ath11k_base *ab, struct sk_buff *skb)
6073 {
6074 	struct wmi_vdev_start_resp_event vdev_start_resp;
6075 	struct ath11k *ar;
6076 	u32 status;
6077 
6078 	if (ath11k_pull_vdev_start_resp_tlv(ab, skb, &vdev_start_resp) != 0) {
6079 		ath11k_warn(ab, "failed to extract vdev start resp");
6080 		return;
6081 	}
6082 
6083 	rcu_read_lock();
6084 	ar = ath11k_mac_get_ar_by_vdev_id(ab, vdev_start_resp.vdev_id);
6085 	if (!ar) {
6086 		ath11k_warn(ab, "invalid vdev id in vdev start resp ev %d",
6087 			    vdev_start_resp.vdev_id);
6088 		rcu_read_unlock();
6089 		return;
6090 	}
6091 
6092 	ar->last_wmi_vdev_start_status = 0;
6093 
6094 	status = vdev_start_resp.status;
6095 
6096 	if (WARN_ON_ONCE(status)) {
6097 		ath11k_warn(ab, "vdev start resp error status %d (%s)\n",
6098 			    status, ath11k_wmi_vdev_resp_print(status));
6099 		ar->last_wmi_vdev_start_status = status;
6100 	}
6101 
6102 	complete(&ar->vdev_setup_done);
6103 
6104 	rcu_read_unlock();
6105 
6106 	ath11k_dbg(ab, ATH11K_DBG_WMI, "vdev start resp for vdev id %d",
6107 		   vdev_start_resp.vdev_id);
6108 }
6109 
6110 static void ath11k_bcn_tx_status_event(struct ath11k_base *ab, struct sk_buff *skb)
6111 {
6112 	u32 vdev_id, tx_status;
6113 
6114 	if (ath11k_pull_bcn_tx_status_ev(ab, skb->data, skb->len,
6115 					 &vdev_id, &tx_status) != 0) {
6116 		ath11k_warn(ab, "failed to extract bcn tx status");
6117 		return;
6118 	}
6119 }
6120 
6121 static void ath11k_vdev_stopped_event(struct ath11k_base *ab, struct sk_buff *skb)
6122 {
6123 	struct ath11k *ar;
6124 	u32 vdev_id = 0;
6125 
6126 	if (ath11k_pull_vdev_stopped_param_tlv(ab, skb, &vdev_id) != 0) {
6127 		ath11k_warn(ab, "failed to extract vdev stopped event");
6128 		return;
6129 	}
6130 
6131 	rcu_read_lock();
6132 	ar = ath11k_mac_get_ar_by_vdev_id(ab, vdev_id);
6133 	if (!ar) {
6134 		ath11k_warn(ab, "invalid vdev id in vdev stopped ev %d",
6135 			    vdev_id);
6136 		rcu_read_unlock();
6137 		return;
6138 	}
6139 
6140 	complete(&ar->vdev_setup_done);
6141 
6142 	rcu_read_unlock();
6143 
6144 	ath11k_dbg(ab, ATH11K_DBG_WMI, "vdev stopped for vdev id %d", vdev_id);
6145 }
6146 
6147 static void ath11k_mgmt_rx_event(struct ath11k_base *ab, struct sk_buff *skb)
6148 {
6149 	struct mgmt_rx_event_params rx_ev = {0};
6150 	struct ath11k *ar;
6151 	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
6152 	struct ieee80211_hdr *hdr;
6153 	u16 fc;
6154 	struct ieee80211_supported_band *sband;
6155 
6156 	if (ath11k_pull_mgmt_rx_params_tlv(ab, skb, &rx_ev) != 0) {
6157 		ath11k_warn(ab, "failed to extract mgmt rx event");
6158 		dev_kfree_skb(skb);
6159 		return;
6160 	}
6161 
6162 	memset(status, 0, sizeof(*status));
6163 
6164 	ath11k_dbg(ab, ATH11K_DBG_MGMT, "mgmt rx event status %08x\n",
6165 		   rx_ev.status);
6166 
6167 	rcu_read_lock();
6168 	ar = ath11k_mac_get_ar_by_pdev_id(ab, rx_ev.pdev_id);
6169 
6170 	if (!ar) {
6171 		ath11k_warn(ab, "invalid pdev_id %d in mgmt_rx_event\n",
6172 			    rx_ev.pdev_id);
6173 		dev_kfree_skb(skb);
6174 		goto exit;
6175 	}
6176 
6177 	if ((test_bit(ATH11K_CAC_RUNNING, &ar->dev_flags)) ||
6178 	    (rx_ev.status & (WMI_RX_STATUS_ERR_DECRYPT |
6179 	    WMI_RX_STATUS_ERR_KEY_CACHE_MISS | WMI_RX_STATUS_ERR_CRC))) {
6180 		dev_kfree_skb(skb);
6181 		goto exit;
6182 	}
6183 
6184 	if (rx_ev.status & WMI_RX_STATUS_ERR_MIC)
6185 		status->flag |= RX_FLAG_MMIC_ERROR;
6186 
6187 	if (rx_ev.chan_freq >= ATH11K_MIN_6G_FREQ &&
6188 	    rx_ev.chan_freq <= ATH11K_MAX_6G_FREQ) {
6189 		status->band = NL80211_BAND_6GHZ;
6190 		status->freq = rx_ev.chan_freq;
6191 	} else if (rx_ev.channel >= 1 && rx_ev.channel <= 14) {
6192 		status->band = NL80211_BAND_2GHZ;
6193 	} else if (rx_ev.channel >= 36 && rx_ev.channel <= ATH11K_MAX_5G_CHAN) {
6194 		status->band = NL80211_BAND_5GHZ;
6195 	} else {
6196 		/* Shouldn't happen unless list of advertised channels to
6197 		 * mac80211 has been changed.
6198 		 */
6199 		WARN_ON_ONCE(1);
6200 		dev_kfree_skb(skb);
6201 		goto exit;
6202 	}
6203 
6204 	if (rx_ev.phy_mode == MODE_11B &&
6205 	    (status->band == NL80211_BAND_5GHZ || status->band == NL80211_BAND_6GHZ))
6206 		ath11k_dbg(ab, ATH11K_DBG_WMI,
6207 			   "wmi mgmt rx 11b (CCK) on 5/6GHz, band = %d\n", status->band);
6208 
6209 	sband = &ar->mac.sbands[status->band];
6210 
6211 	if (status->band != NL80211_BAND_6GHZ)
6212 		status->freq = ieee80211_channel_to_frequency(rx_ev.channel,
6213 							      status->band);
6214 
6215 	status->signal = rx_ev.snr + ATH11K_DEFAULT_NOISE_FLOOR;
6216 	status->rate_idx = ath11k_mac_bitrate_to_idx(sband, rx_ev.rate / 100);
6217 
6218 	hdr = (struct ieee80211_hdr *)skb->data;
6219 	fc = le16_to_cpu(hdr->frame_control);
6220 
6221 	/* Firmware is guaranteed to report all essential management frames via
6222 	 * WMI while it can deliver some extra via HTT. Since there can be
6223 	 * duplicates split the reporting wrt monitor/sniffing.
6224 	 */
6225 	status->flag |= RX_FLAG_SKIP_MONITOR;
6226 
6227 	/* In case of PMF, FW delivers decrypted frames with Protected Bit set.
6228 	 * Don't clear that. Also, FW delivers broadcast management frames
6229 	 * (ex: group privacy action frames in mesh) as encrypted payload.
6230 	 */
6231 	if (ieee80211_has_protected(hdr->frame_control) &&
6232 	    !is_multicast_ether_addr(ieee80211_get_DA(hdr))) {
6233 		status->flag |= RX_FLAG_DECRYPTED;
6234 
6235 		if (!ieee80211_is_robust_mgmt_frame(skb)) {
6236 			status->flag |= RX_FLAG_IV_STRIPPED |
6237 					RX_FLAG_MMIC_STRIPPED;
6238 			hdr->frame_control = __cpu_to_le16(fc &
6239 					     ~IEEE80211_FCTL_PROTECTED);
6240 		}
6241 	}
6242 
6243 	if (ieee80211_is_beacon(hdr->frame_control))
6244 		ath11k_mac_handle_beacon(ar, skb);
6245 
6246 	ath11k_dbg(ab, ATH11K_DBG_MGMT,
6247 		   "event mgmt rx skb %pK len %d ftype %02x stype %02x\n",
6248 		   skb, skb->len,
6249 		   fc & IEEE80211_FCTL_FTYPE, fc & IEEE80211_FCTL_STYPE);
6250 
6251 	ath11k_dbg(ab, ATH11K_DBG_MGMT,
6252 		   "event mgmt rx freq %d band %d snr %d, rate_idx %d\n",
6253 		   status->freq, status->band, status->signal,
6254 		   status->rate_idx);
6255 
6256 	ieee80211_rx_ni(ar->hw, skb);
6257 
6258 exit:
6259 	rcu_read_unlock();
6260 }
6261 
6262 static void ath11k_mgmt_tx_compl_event(struct ath11k_base *ab, struct sk_buff *skb)
6263 {
6264 	struct wmi_mgmt_tx_compl_event tx_compl_param = {0};
6265 	struct ath11k *ar;
6266 
6267 	if (ath11k_pull_mgmt_tx_compl_param_tlv(ab, skb, &tx_compl_param) != 0) {
6268 		ath11k_warn(ab, "failed to extract mgmt tx compl event");
6269 		return;
6270 	}
6271 
6272 	rcu_read_lock();
6273 	ar = ath11k_mac_get_ar_by_pdev_id(ab, tx_compl_param.pdev_id);
6274 	if (!ar) {
6275 		ath11k_warn(ab, "invalid pdev id %d in mgmt_tx_compl_event\n",
6276 			    tx_compl_param.pdev_id);
6277 		goto exit;
6278 	}
6279 
6280 	wmi_process_mgmt_tx_comp(ar, tx_compl_param.desc_id,
6281 				 tx_compl_param.status);
6282 
6283 	ath11k_dbg(ab, ATH11K_DBG_MGMT,
6284 		   "mgmt tx compl ev pdev_id %d, desc_id %d, status %d",
6285 		   tx_compl_param.pdev_id, tx_compl_param.desc_id,
6286 		   tx_compl_param.status);
6287 
6288 exit:
6289 	rcu_read_unlock();
6290 }
6291 
6292 static struct ath11k *ath11k_get_ar_on_scan_state(struct ath11k_base *ab,
6293 						  u32 vdev_id,
6294 						  enum ath11k_scan_state state)
6295 {
6296 	int i;
6297 	struct ath11k_pdev *pdev;
6298 	struct ath11k *ar;
6299 
6300 	for (i = 0; i < ab->num_radios; i++) {
6301 		pdev = rcu_dereference(ab->pdevs_active[i]);
6302 		if (pdev && pdev->ar) {
6303 			ar = pdev->ar;
6304 
6305 			spin_lock_bh(&ar->data_lock);
6306 			if (ar->scan.state == state &&
6307 			    ar->scan.vdev_id == vdev_id) {
6308 				spin_unlock_bh(&ar->data_lock);
6309 				return ar;
6310 			}
6311 			spin_unlock_bh(&ar->data_lock);
6312 		}
6313 	}
6314 	return NULL;
6315 }
6316 
6317 static void ath11k_scan_event(struct ath11k_base *ab, struct sk_buff *skb)
6318 {
6319 	struct ath11k *ar;
6320 	struct wmi_scan_event scan_ev = {0};
6321 
6322 	if (ath11k_pull_scan_ev(ab, skb, &scan_ev) != 0) {
6323 		ath11k_warn(ab, "failed to extract scan event");
6324 		return;
6325 	}
6326 
6327 	rcu_read_lock();
6328 
6329 	/* In case the scan was cancelled, ex. during interface teardown,
6330 	 * the interface will not be found in active interfaces.
6331 	 * Rather, in such scenarios, iterate over the active pdev's to
6332 	 * search 'ar' if the corresponding 'ar' scan is ABORTING and the
6333 	 * aborting scan's vdev id matches this event info.
6334 	 */
6335 	if (scan_ev.event_type == WMI_SCAN_EVENT_COMPLETED &&
6336 	    scan_ev.reason == WMI_SCAN_REASON_CANCELLED) {
6337 		ar = ath11k_get_ar_on_scan_state(ab, scan_ev.vdev_id,
6338 						 ATH11K_SCAN_ABORTING);
6339 		if (!ar)
6340 			ar = ath11k_get_ar_on_scan_state(ab, scan_ev.vdev_id,
6341 							 ATH11K_SCAN_RUNNING);
6342 	} else {
6343 		ar = ath11k_mac_get_ar_by_vdev_id(ab, scan_ev.vdev_id);
6344 	}
6345 
6346 	if (!ar) {
6347 		ath11k_warn(ab, "Received scan event for unknown vdev");
6348 		rcu_read_unlock();
6349 		return;
6350 	}
6351 
6352 	spin_lock_bh(&ar->data_lock);
6353 
6354 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6355 		   "scan event %s type %d reason %d freq %d req_id %d scan_id %d vdev_id %d state %s (%d)\n",
6356 		   ath11k_wmi_event_scan_type_str(scan_ev.event_type, scan_ev.reason),
6357 		   scan_ev.event_type, scan_ev.reason, scan_ev.channel_freq,
6358 		   scan_ev.scan_req_id, scan_ev.scan_id, scan_ev.vdev_id,
6359 		   ath11k_scan_state_str(ar->scan.state), ar->scan.state);
6360 
6361 	switch (scan_ev.event_type) {
6362 	case WMI_SCAN_EVENT_STARTED:
6363 		ath11k_wmi_event_scan_started(ar);
6364 		break;
6365 	case WMI_SCAN_EVENT_COMPLETED:
6366 		ath11k_wmi_event_scan_completed(ar);
6367 		break;
6368 	case WMI_SCAN_EVENT_BSS_CHANNEL:
6369 		ath11k_wmi_event_scan_bss_chan(ar);
6370 		break;
6371 	case WMI_SCAN_EVENT_FOREIGN_CHAN:
6372 		ath11k_wmi_event_scan_foreign_chan(ar, scan_ev.channel_freq);
6373 		break;
6374 	case WMI_SCAN_EVENT_START_FAILED:
6375 		ath11k_warn(ab, "received scan start failure event\n");
6376 		ath11k_wmi_event_scan_start_failed(ar);
6377 		break;
6378 	case WMI_SCAN_EVENT_DEQUEUED:
6379 		__ath11k_mac_scan_finish(ar);
6380 		break;
6381 	case WMI_SCAN_EVENT_PREEMPTED:
6382 	case WMI_SCAN_EVENT_RESTARTED:
6383 	case WMI_SCAN_EVENT_FOREIGN_CHAN_EXIT:
6384 	default:
6385 		break;
6386 	}
6387 
6388 	spin_unlock_bh(&ar->data_lock);
6389 
6390 	rcu_read_unlock();
6391 }
6392 
6393 static void ath11k_peer_sta_kickout_event(struct ath11k_base *ab, struct sk_buff *skb)
6394 {
6395 	struct wmi_peer_sta_kickout_arg arg = {};
6396 	struct ieee80211_sta *sta;
6397 	struct ath11k_peer *peer;
6398 	struct ath11k *ar;
6399 
6400 	if (ath11k_pull_peer_sta_kickout_ev(ab, skb, &arg) != 0) {
6401 		ath11k_warn(ab, "failed to extract peer sta kickout event");
6402 		return;
6403 	}
6404 
6405 	rcu_read_lock();
6406 
6407 	spin_lock_bh(&ab->base_lock);
6408 
6409 	peer = ath11k_peer_find_by_addr(ab, arg.mac_addr);
6410 
6411 	if (!peer) {
6412 		ath11k_warn(ab, "peer not found %pM\n",
6413 			    arg.mac_addr);
6414 		goto exit;
6415 	}
6416 
6417 	ar = ath11k_mac_get_ar_by_vdev_id(ab, peer->vdev_id);
6418 	if (!ar) {
6419 		ath11k_warn(ab, "invalid vdev id in peer sta kickout ev %d",
6420 			    peer->vdev_id);
6421 		goto exit;
6422 	}
6423 
6424 	sta = ieee80211_find_sta_by_ifaddr(ar->hw,
6425 					   arg.mac_addr, NULL);
6426 	if (!sta) {
6427 		ath11k_warn(ab, "Spurious quick kickout for STA %pM\n",
6428 			    arg.mac_addr);
6429 		goto exit;
6430 	}
6431 
6432 	ath11k_dbg(ab, ATH11K_DBG_WMI, "peer sta kickout event %pM",
6433 		   arg.mac_addr);
6434 
6435 	ieee80211_report_low_ack(sta, 10);
6436 
6437 exit:
6438 	spin_unlock_bh(&ab->base_lock);
6439 	rcu_read_unlock();
6440 }
6441 
6442 static void ath11k_roam_event(struct ath11k_base *ab, struct sk_buff *skb)
6443 {
6444 	struct wmi_roam_event roam_ev = {};
6445 	struct ath11k *ar;
6446 
6447 	if (ath11k_pull_roam_ev(ab, skb, &roam_ev) != 0) {
6448 		ath11k_warn(ab, "failed to extract roam event");
6449 		return;
6450 	}
6451 
6452 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6453 		   "wmi roam event vdev %u reason 0x%08x rssi %d\n",
6454 		   roam_ev.vdev_id, roam_ev.reason, roam_ev.rssi);
6455 
6456 	rcu_read_lock();
6457 	ar = ath11k_mac_get_ar_by_vdev_id(ab, roam_ev.vdev_id);
6458 	if (!ar) {
6459 		ath11k_warn(ab, "invalid vdev id in roam ev %d",
6460 			    roam_ev.vdev_id);
6461 		rcu_read_unlock();
6462 		return;
6463 	}
6464 
6465 	if (roam_ev.reason >= WMI_ROAM_REASON_MAX)
6466 		ath11k_warn(ab, "ignoring unknown roam event reason %d on vdev %i\n",
6467 			    roam_ev.reason, roam_ev.vdev_id);
6468 
6469 	switch (roam_ev.reason) {
6470 	case WMI_ROAM_REASON_BEACON_MISS:
6471 		ath11k_mac_handle_beacon_miss(ar, roam_ev.vdev_id);
6472 		break;
6473 	case WMI_ROAM_REASON_BETTER_AP:
6474 	case WMI_ROAM_REASON_LOW_RSSI:
6475 	case WMI_ROAM_REASON_SUITABLE_AP_FOUND:
6476 	case WMI_ROAM_REASON_HO_FAILED:
6477 		ath11k_warn(ab, "ignoring not implemented roam event reason %d on vdev %i\n",
6478 			    roam_ev.reason, roam_ev.vdev_id);
6479 		break;
6480 	}
6481 
6482 	rcu_read_unlock();
6483 }
6484 
6485 static void ath11k_chan_info_event(struct ath11k_base *ab, struct sk_buff *skb)
6486 {
6487 	struct wmi_chan_info_event ch_info_ev = {0};
6488 	struct ath11k *ar;
6489 	struct survey_info *survey;
6490 	int idx;
6491 	/* HW channel counters frequency value in hertz */
6492 	u32 cc_freq_hz = ab->cc_freq_hz;
6493 
6494 	if (ath11k_pull_chan_info_ev(ab, skb->data, skb->len, &ch_info_ev) != 0) {
6495 		ath11k_warn(ab, "failed to extract chan info event");
6496 		return;
6497 	}
6498 
6499 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6500 		   "chan info vdev_id %d err_code %d freq %d cmd_flags %d noise_floor %d rx_clear_count %d cycle_count %d mac_clk_mhz %d\n",
6501 		   ch_info_ev.vdev_id, ch_info_ev.err_code, ch_info_ev.freq,
6502 		   ch_info_ev.cmd_flags, ch_info_ev.noise_floor,
6503 		   ch_info_ev.rx_clear_count, ch_info_ev.cycle_count,
6504 		   ch_info_ev.mac_clk_mhz);
6505 
6506 	if (ch_info_ev.cmd_flags == WMI_CHAN_INFO_END_RESP) {
6507 		ath11k_dbg(ab, ATH11K_DBG_WMI, "chan info report completed\n");
6508 		return;
6509 	}
6510 
6511 	rcu_read_lock();
6512 	ar = ath11k_mac_get_ar_by_vdev_id(ab, ch_info_ev.vdev_id);
6513 	if (!ar) {
6514 		ath11k_warn(ab, "invalid vdev id in chan info ev %d",
6515 			    ch_info_ev.vdev_id);
6516 		rcu_read_unlock();
6517 		return;
6518 	}
6519 	spin_lock_bh(&ar->data_lock);
6520 
6521 	switch (ar->scan.state) {
6522 	case ATH11K_SCAN_IDLE:
6523 	case ATH11K_SCAN_STARTING:
6524 		ath11k_warn(ab, "received chan info event without a scan request, ignoring\n");
6525 		goto exit;
6526 	case ATH11K_SCAN_RUNNING:
6527 	case ATH11K_SCAN_ABORTING:
6528 		break;
6529 	}
6530 
6531 	idx = freq_to_idx(ar, ch_info_ev.freq);
6532 	if (idx >= ARRAY_SIZE(ar->survey)) {
6533 		ath11k_warn(ab, "chan info: invalid frequency %d (idx %d out of bounds)\n",
6534 			    ch_info_ev.freq, idx);
6535 		goto exit;
6536 	}
6537 
6538 	/* If FW provides MAC clock frequency in Mhz, overriding the initialized
6539 	 * HW channel counters frequency value
6540 	 */
6541 	if (ch_info_ev.mac_clk_mhz)
6542 		cc_freq_hz = (ch_info_ev.mac_clk_mhz * 1000);
6543 
6544 	if (ch_info_ev.cmd_flags == WMI_CHAN_INFO_START_RESP) {
6545 		survey = &ar->survey[idx];
6546 		memset(survey, 0, sizeof(*survey));
6547 		survey->noise = ch_info_ev.noise_floor;
6548 		survey->filled = SURVEY_INFO_NOISE_DBM | SURVEY_INFO_TIME |
6549 				 SURVEY_INFO_TIME_BUSY;
6550 		survey->time = div_u64(ch_info_ev.cycle_count, cc_freq_hz);
6551 		survey->time_busy = div_u64(ch_info_ev.rx_clear_count, cc_freq_hz);
6552 	}
6553 exit:
6554 	spin_unlock_bh(&ar->data_lock);
6555 	rcu_read_unlock();
6556 }
6557 
6558 static void
6559 ath11k_pdev_bss_chan_info_event(struct ath11k_base *ab, struct sk_buff *skb)
6560 {
6561 	struct wmi_pdev_bss_chan_info_event bss_ch_info_ev = {};
6562 	struct survey_info *survey;
6563 	struct ath11k *ar;
6564 	u32 cc_freq_hz = ab->cc_freq_hz;
6565 	u64 busy, total, tx, rx, rx_bss;
6566 	int idx;
6567 
6568 	if (ath11k_pull_pdev_bss_chan_info_ev(ab, skb, &bss_ch_info_ev) != 0) {
6569 		ath11k_warn(ab, "failed to extract pdev bss chan info event");
6570 		return;
6571 	}
6572 
6573 	busy = (u64)(bss_ch_info_ev.rx_clear_count_high) << 32 |
6574 			bss_ch_info_ev.rx_clear_count_low;
6575 
6576 	total = (u64)(bss_ch_info_ev.cycle_count_high) << 32 |
6577 			bss_ch_info_ev.cycle_count_low;
6578 
6579 	tx = (u64)(bss_ch_info_ev.tx_cycle_count_high) << 32 |
6580 			bss_ch_info_ev.tx_cycle_count_low;
6581 
6582 	rx = (u64)(bss_ch_info_ev.rx_cycle_count_high) << 32 |
6583 			bss_ch_info_ev.rx_cycle_count_low;
6584 
6585 	rx_bss = (u64)(bss_ch_info_ev.rx_bss_cycle_count_high) << 32 |
6586 			bss_ch_info_ev.rx_bss_cycle_count_low;
6587 
6588 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6589 		   "pdev bss chan info:\n pdev_id: %d freq: %d noise: %d cycle: busy %llu total %llu tx %llu rx %llu rx_bss %llu\n",
6590 		   bss_ch_info_ev.pdev_id, bss_ch_info_ev.freq,
6591 		   bss_ch_info_ev.noise_floor, busy, total,
6592 		   tx, rx, rx_bss);
6593 
6594 	rcu_read_lock();
6595 	ar = ath11k_mac_get_ar_by_pdev_id(ab, bss_ch_info_ev.pdev_id);
6596 
6597 	if (!ar) {
6598 		ath11k_warn(ab, "invalid pdev id %d in bss_chan_info event\n",
6599 			    bss_ch_info_ev.pdev_id);
6600 		rcu_read_unlock();
6601 		return;
6602 	}
6603 
6604 	spin_lock_bh(&ar->data_lock);
6605 	idx = freq_to_idx(ar, bss_ch_info_ev.freq);
6606 	if (idx >= ARRAY_SIZE(ar->survey)) {
6607 		ath11k_warn(ab, "bss chan info: invalid frequency %d (idx %d out of bounds)\n",
6608 			    bss_ch_info_ev.freq, idx);
6609 		goto exit;
6610 	}
6611 
6612 	survey = &ar->survey[idx];
6613 
6614 	survey->noise     = bss_ch_info_ev.noise_floor;
6615 	survey->time      = div_u64(total, cc_freq_hz);
6616 	survey->time_busy = div_u64(busy, cc_freq_hz);
6617 	survey->time_rx   = div_u64(rx_bss, cc_freq_hz);
6618 	survey->time_tx   = div_u64(tx, cc_freq_hz);
6619 	survey->filled   |= (SURVEY_INFO_NOISE_DBM |
6620 			     SURVEY_INFO_TIME |
6621 			     SURVEY_INFO_TIME_BUSY |
6622 			     SURVEY_INFO_TIME_RX |
6623 			     SURVEY_INFO_TIME_TX);
6624 exit:
6625 	spin_unlock_bh(&ar->data_lock);
6626 	complete(&ar->bss_survey_done);
6627 
6628 	rcu_read_unlock();
6629 }
6630 
6631 static void ath11k_vdev_install_key_compl_event(struct ath11k_base *ab,
6632 						struct sk_buff *skb)
6633 {
6634 	struct wmi_vdev_install_key_complete_arg install_key_compl = {0};
6635 	struct ath11k *ar;
6636 
6637 	if (ath11k_pull_vdev_install_key_compl_ev(ab, skb, &install_key_compl) != 0) {
6638 		ath11k_warn(ab, "failed to extract install key compl event");
6639 		return;
6640 	}
6641 
6642 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6643 		   "vdev install key ev idx %d flags %08x macaddr %pM status %d\n",
6644 		   install_key_compl.key_idx, install_key_compl.key_flags,
6645 		   install_key_compl.macaddr, install_key_compl.status);
6646 
6647 	rcu_read_lock();
6648 	ar = ath11k_mac_get_ar_by_vdev_id(ab, install_key_compl.vdev_id);
6649 	if (!ar) {
6650 		ath11k_warn(ab, "invalid vdev id in install key compl ev %d",
6651 			    install_key_compl.vdev_id);
6652 		rcu_read_unlock();
6653 		return;
6654 	}
6655 
6656 	ar->install_key_status = 0;
6657 
6658 	if (install_key_compl.status != WMI_VDEV_INSTALL_KEY_COMPL_STATUS_SUCCESS) {
6659 		ath11k_warn(ab, "install key failed for %pM status %d\n",
6660 			    install_key_compl.macaddr, install_key_compl.status);
6661 		ar->install_key_status = install_key_compl.status;
6662 	}
6663 
6664 	complete(&ar->install_key_done);
6665 	rcu_read_unlock();
6666 }
6667 
6668 static void ath11k_service_available_event(struct ath11k_base *ab, struct sk_buff *skb)
6669 {
6670 	const void **tb;
6671 	const struct wmi_service_available_event *ev;
6672 	int ret;
6673 	int i, j;
6674 
6675 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6676 	if (IS_ERR(tb)) {
6677 		ret = PTR_ERR(tb);
6678 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
6679 		return;
6680 	}
6681 
6682 	ev = tb[WMI_TAG_SERVICE_AVAILABLE_EVENT];
6683 	if (!ev) {
6684 		ath11k_warn(ab, "failed to fetch svc available ev");
6685 		kfree(tb);
6686 		return;
6687 	}
6688 
6689 	/* TODO: Use wmi_service_segment_offset information to get the service
6690 	 * especially when more services are advertised in multiple sevice
6691 	 * available events.
6692 	 */
6693 	for (i = 0, j = WMI_MAX_SERVICE;
6694 	     i < WMI_SERVICE_SEGMENT_BM_SIZE32 && j < WMI_MAX_EXT_SERVICE;
6695 	     i++) {
6696 		do {
6697 			if (ev->wmi_service_segment_bitmap[i] &
6698 			    BIT(j % WMI_AVAIL_SERVICE_BITS_IN_SIZE32))
6699 				set_bit(j, ab->wmi_ab.svc_map);
6700 		} while (++j % WMI_AVAIL_SERVICE_BITS_IN_SIZE32);
6701 	}
6702 
6703 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6704 		   "wmi_ext_service_bitmap 0:0x%x, 1:0x%x, 2:0x%x, 3:0x%x",
6705 		   ev->wmi_service_segment_bitmap[0], ev->wmi_service_segment_bitmap[1],
6706 		   ev->wmi_service_segment_bitmap[2], ev->wmi_service_segment_bitmap[3]);
6707 
6708 	kfree(tb);
6709 }
6710 
6711 static void ath11k_peer_assoc_conf_event(struct ath11k_base *ab, struct sk_buff *skb)
6712 {
6713 	struct wmi_peer_assoc_conf_arg peer_assoc_conf = {0};
6714 	struct ath11k *ar;
6715 
6716 	if (ath11k_pull_peer_assoc_conf_ev(ab, skb, &peer_assoc_conf) != 0) {
6717 		ath11k_warn(ab, "failed to extract peer assoc conf event");
6718 		return;
6719 	}
6720 
6721 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6722 		   "peer assoc conf ev vdev id %d macaddr %pM\n",
6723 		   peer_assoc_conf.vdev_id, peer_assoc_conf.macaddr);
6724 
6725 	rcu_read_lock();
6726 	ar = ath11k_mac_get_ar_by_vdev_id(ab, peer_assoc_conf.vdev_id);
6727 
6728 	if (!ar) {
6729 		ath11k_warn(ab, "invalid vdev id in peer assoc conf ev %d",
6730 			    peer_assoc_conf.vdev_id);
6731 		rcu_read_unlock();
6732 		return;
6733 	}
6734 
6735 	complete(&ar->peer_assoc_done);
6736 	rcu_read_unlock();
6737 }
6738 
6739 static void ath11k_update_stats_event(struct ath11k_base *ab, struct sk_buff *skb)
6740 {
6741 	ath11k_debugfs_fw_stats_process(ab, skb);
6742 }
6743 
6744 /* PDEV_CTL_FAILSAFE_CHECK_EVENT is received from FW when the frequency scanned
6745  * is not part of BDF CTL(Conformance test limits) table entries.
6746  */
6747 static void ath11k_pdev_ctl_failsafe_check_event(struct ath11k_base *ab,
6748 						 struct sk_buff *skb)
6749 {
6750 	const void **tb;
6751 	const struct wmi_pdev_ctl_failsafe_chk_event *ev;
6752 	int ret;
6753 
6754 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6755 	if (IS_ERR(tb)) {
6756 		ret = PTR_ERR(tb);
6757 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
6758 		return;
6759 	}
6760 
6761 	ev = tb[WMI_TAG_PDEV_CTL_FAILSAFE_CHECK_EVENT];
6762 	if (!ev) {
6763 		ath11k_warn(ab, "failed to fetch pdev ctl failsafe check ev");
6764 		kfree(tb);
6765 		return;
6766 	}
6767 
6768 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6769 		   "pdev ctl failsafe check ev status %d\n",
6770 		   ev->ctl_failsafe_status);
6771 
6772 	/* If ctl_failsafe_status is set to 1 FW will max out the Transmit power
6773 	 * to 10 dBm else the CTL power entry in the BDF would be picked up.
6774 	 */
6775 	if (ev->ctl_failsafe_status != 0)
6776 		ath11k_warn(ab, "pdev ctl failsafe failure status %d",
6777 			    ev->ctl_failsafe_status);
6778 
6779 	kfree(tb);
6780 }
6781 
6782 static void
6783 ath11k_wmi_process_csa_switch_count_event(struct ath11k_base *ab,
6784 					  const struct wmi_pdev_csa_switch_ev *ev,
6785 					  const u32 *vdev_ids)
6786 {
6787 	int i;
6788 	struct ath11k_vif *arvif;
6789 
6790 	/* Finish CSA once the switch count becomes NULL */
6791 	if (ev->current_switch_count)
6792 		return;
6793 
6794 	rcu_read_lock();
6795 	for (i = 0; i < ev->num_vdevs; i++) {
6796 		arvif = ath11k_mac_get_arvif_by_vdev_id(ab, vdev_ids[i]);
6797 
6798 		if (!arvif) {
6799 			ath11k_warn(ab, "Recvd csa status for unknown vdev %d",
6800 				    vdev_ids[i]);
6801 			continue;
6802 		}
6803 
6804 		if (arvif->is_up && arvif->vif->csa_active)
6805 			ieee80211_csa_finish(arvif->vif);
6806 	}
6807 	rcu_read_unlock();
6808 }
6809 
6810 static void
6811 ath11k_wmi_pdev_csa_switch_count_status_event(struct ath11k_base *ab,
6812 					      struct sk_buff *skb)
6813 {
6814 	const void **tb;
6815 	const struct wmi_pdev_csa_switch_ev *ev;
6816 	const u32 *vdev_ids;
6817 	int ret;
6818 
6819 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6820 	if (IS_ERR(tb)) {
6821 		ret = PTR_ERR(tb);
6822 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
6823 		return;
6824 	}
6825 
6826 	ev = tb[WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT];
6827 	vdev_ids = tb[WMI_TAG_ARRAY_UINT32];
6828 
6829 	if (!ev || !vdev_ids) {
6830 		ath11k_warn(ab, "failed to fetch pdev csa switch count ev");
6831 		kfree(tb);
6832 		return;
6833 	}
6834 
6835 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6836 		   "pdev csa switch count %d for pdev %d, num_vdevs %d",
6837 		   ev->current_switch_count, ev->pdev_id,
6838 		   ev->num_vdevs);
6839 
6840 	ath11k_wmi_process_csa_switch_count_event(ab, ev, vdev_ids);
6841 
6842 	kfree(tb);
6843 }
6844 
6845 static void
6846 ath11k_wmi_pdev_dfs_radar_detected_event(struct ath11k_base *ab, struct sk_buff *skb)
6847 {
6848 	const void **tb;
6849 	const struct wmi_pdev_radar_ev *ev;
6850 	struct ath11k *ar;
6851 	int ret;
6852 
6853 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6854 	if (IS_ERR(tb)) {
6855 		ret = PTR_ERR(tb);
6856 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
6857 		return;
6858 	}
6859 
6860 	ev = tb[WMI_TAG_PDEV_DFS_RADAR_DETECTION_EVENT];
6861 
6862 	if (!ev) {
6863 		ath11k_warn(ab, "failed to fetch pdev dfs radar detected ev");
6864 		kfree(tb);
6865 		return;
6866 	}
6867 
6868 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6869 		   "pdev dfs radar detected on pdev %d, detection mode %d, chan freq %d, chan_width %d, detector id %d, seg id %d, timestamp %d, chirp %d, freq offset %d, sidx %d",
6870 		   ev->pdev_id, ev->detection_mode, ev->chan_freq, ev->chan_width,
6871 		   ev->detector_id, ev->segment_id, ev->timestamp, ev->is_chirp,
6872 		   ev->freq_offset, ev->sidx);
6873 
6874 	ar = ath11k_mac_get_ar_by_pdev_id(ab, ev->pdev_id);
6875 
6876 	if (!ar) {
6877 		ath11k_warn(ab, "radar detected in invalid pdev %d\n",
6878 			    ev->pdev_id);
6879 		goto exit;
6880 	}
6881 
6882 	ath11k_dbg(ar->ab, ATH11K_DBG_REG, "DFS Radar Detected in pdev %d\n",
6883 		   ev->pdev_id);
6884 
6885 	if (ar->dfs_block_radar_events)
6886 		ath11k_info(ab, "DFS Radar detected, but ignored as requested\n");
6887 	else
6888 		ieee80211_radar_detected(ar->hw);
6889 
6890 exit:
6891 	kfree(tb);
6892 }
6893 
6894 static void
6895 ath11k_wmi_pdev_temperature_event(struct ath11k_base *ab,
6896 				  struct sk_buff *skb)
6897 {
6898 	struct ath11k *ar;
6899 	const void **tb;
6900 	const struct wmi_pdev_temperature_event *ev;
6901 	int ret;
6902 
6903 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6904 	if (IS_ERR(tb)) {
6905 		ret = PTR_ERR(tb);
6906 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
6907 		return;
6908 	}
6909 
6910 	ev = tb[WMI_TAG_PDEV_TEMPERATURE_EVENT];
6911 	if (!ev) {
6912 		ath11k_warn(ab, "failed to fetch pdev temp ev");
6913 		kfree(tb);
6914 		return;
6915 	}
6916 
6917 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6918 		   "pdev temperature ev temp %d pdev_id %d\n", ev->temp, ev->pdev_id);
6919 
6920 	ar = ath11k_mac_get_ar_by_pdev_id(ab, ev->pdev_id);
6921 	if (!ar) {
6922 		ath11k_warn(ab, "invalid pdev id in pdev temperature ev %d", ev->pdev_id);
6923 		kfree(tb);
6924 		return;
6925 	}
6926 
6927 	ath11k_thermal_event_temperature(ar, ev->temp);
6928 
6929 	kfree(tb);
6930 }
6931 
6932 static void ath11k_fils_discovery_event(struct ath11k_base *ab,
6933 					struct sk_buff *skb)
6934 {
6935 	const void **tb;
6936 	const struct wmi_fils_discovery_event *ev;
6937 	int ret;
6938 
6939 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6940 	if (IS_ERR(tb)) {
6941 		ret = PTR_ERR(tb);
6942 		ath11k_warn(ab,
6943 			    "failed to parse FILS discovery event tlv %d\n",
6944 			    ret);
6945 		return;
6946 	}
6947 
6948 	ev = tb[WMI_TAG_HOST_SWFDA_EVENT];
6949 	if (!ev) {
6950 		ath11k_warn(ab, "failed to fetch FILS discovery event\n");
6951 		kfree(tb);
6952 		return;
6953 	}
6954 
6955 	ath11k_warn(ab,
6956 		    "FILS discovery frame expected from host for vdev_id: %u, transmission scheduled at %u, next TBTT: %u\n",
6957 		    ev->vdev_id, ev->fils_tt, ev->tbtt);
6958 
6959 	kfree(tb);
6960 }
6961 
6962 static void ath11k_probe_resp_tx_status_event(struct ath11k_base *ab,
6963 					      struct sk_buff *skb)
6964 {
6965 	const void **tb;
6966 	const struct wmi_probe_resp_tx_status_event *ev;
6967 	int ret;
6968 
6969 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6970 	if (IS_ERR(tb)) {
6971 		ret = PTR_ERR(tb);
6972 		ath11k_warn(ab,
6973 			    "failed to parse probe response transmission status event tlv: %d\n",
6974 			    ret);
6975 		return;
6976 	}
6977 
6978 	ev = tb[WMI_TAG_OFFLOAD_PRB_RSP_TX_STATUS_EVENT];
6979 	if (!ev) {
6980 		ath11k_warn(ab,
6981 			    "failed to fetch probe response transmission status event");
6982 		kfree(tb);
6983 		return;
6984 	}
6985 
6986 	if (ev->tx_status)
6987 		ath11k_warn(ab,
6988 			    "Probe response transmission failed for vdev_id %u, status %u\n",
6989 			    ev->vdev_id, ev->tx_status);
6990 
6991 	kfree(tb);
6992 }
6993 
6994 static int ath11k_wmi_tlv_wow_wakeup_host_parse(struct ath11k_base *ab,
6995 						u16 tag, u16 len,
6996 						const void *ptr, void *data)
6997 {
6998 	struct wmi_wow_ev_arg *ev = data;
6999 	const char *wow_pg_fault;
7000 	int wow_pg_len;
7001 
7002 	switch (tag) {
7003 	case WMI_TAG_WOW_EVENT_INFO:
7004 		memcpy(ev, ptr, sizeof(*ev));
7005 		ath11k_dbg(ab, ATH11K_DBG_WMI, "wow wakeup host reason %d %s\n",
7006 			   ev->wake_reason, wow_reason(ev->wake_reason));
7007 		break;
7008 
7009 	case WMI_TAG_ARRAY_BYTE:
7010 		if (ev && ev->wake_reason == WOW_REASON_PAGE_FAULT) {
7011 			wow_pg_fault = ptr;
7012 			/* the first 4 bytes are length */
7013 			wow_pg_len = *(int *)wow_pg_fault;
7014 			wow_pg_fault += sizeof(int);
7015 			ath11k_dbg(ab, ATH11K_DBG_WMI, "wow data_len = %d\n",
7016 				   wow_pg_len);
7017 			ath11k_dbg_dump(ab, ATH11K_DBG_WMI,
7018 					"wow_event_info_type packet present",
7019 					"wow_pg_fault ",
7020 					wow_pg_fault,
7021 					wow_pg_len);
7022 		}
7023 		break;
7024 	default:
7025 		break;
7026 	}
7027 
7028 	return 0;
7029 }
7030 
7031 static void ath11k_wmi_event_wow_wakeup_host(struct ath11k_base *ab, struct sk_buff *skb)
7032 {
7033 	struct wmi_wow_ev_arg ev = { };
7034 	int ret;
7035 
7036 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
7037 				  ath11k_wmi_tlv_wow_wakeup_host_parse,
7038 				  &ev);
7039 	if (ret) {
7040 		ath11k_warn(ab, "failed to parse wmi wow tlv: %d\n", ret);
7041 		return;
7042 	}
7043 
7044 	complete(&ab->wow.wakeup_completed);
7045 }
7046 
7047 static void ath11k_wmi_tlv_op_rx(struct ath11k_base *ab, struct sk_buff *skb)
7048 {
7049 	struct wmi_cmd_hdr *cmd_hdr;
7050 	enum wmi_tlv_event_id id;
7051 
7052 	cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
7053 	id = FIELD_GET(WMI_CMD_HDR_CMD_ID, (cmd_hdr->cmd_id));
7054 
7055 	if (skb_pull(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
7056 		goto out;
7057 
7058 	switch (id) {
7059 		/* Process all the WMI events here */
7060 	case WMI_SERVICE_READY_EVENTID:
7061 		ath11k_service_ready_event(ab, skb);
7062 		break;
7063 	case WMI_SERVICE_READY_EXT_EVENTID:
7064 		ath11k_service_ready_ext_event(ab, skb);
7065 		break;
7066 	case WMI_SERVICE_READY_EXT2_EVENTID:
7067 		ath11k_service_ready_ext2_event(ab, skb);
7068 		break;
7069 	case WMI_REG_CHAN_LIST_CC_EVENTID:
7070 		ath11k_reg_chan_list_event(ab, skb);
7071 		break;
7072 	case WMI_READY_EVENTID:
7073 		ath11k_ready_event(ab, skb);
7074 		break;
7075 	case WMI_PEER_DELETE_RESP_EVENTID:
7076 		ath11k_peer_delete_resp_event(ab, skb);
7077 		break;
7078 	case WMI_VDEV_START_RESP_EVENTID:
7079 		ath11k_vdev_start_resp_event(ab, skb);
7080 		break;
7081 	case WMI_OFFLOAD_BCN_TX_STATUS_EVENTID:
7082 		ath11k_bcn_tx_status_event(ab, skb);
7083 		break;
7084 	case WMI_VDEV_STOPPED_EVENTID:
7085 		ath11k_vdev_stopped_event(ab, skb);
7086 		break;
7087 	case WMI_MGMT_RX_EVENTID:
7088 		ath11k_mgmt_rx_event(ab, skb);
7089 		/* mgmt_rx_event() owns the skb now! */
7090 		return;
7091 	case WMI_MGMT_TX_COMPLETION_EVENTID:
7092 		ath11k_mgmt_tx_compl_event(ab, skb);
7093 		break;
7094 	case WMI_SCAN_EVENTID:
7095 		ath11k_scan_event(ab, skb);
7096 		break;
7097 	case WMI_PEER_STA_KICKOUT_EVENTID:
7098 		ath11k_peer_sta_kickout_event(ab, skb);
7099 		break;
7100 	case WMI_ROAM_EVENTID:
7101 		ath11k_roam_event(ab, skb);
7102 		break;
7103 	case WMI_CHAN_INFO_EVENTID:
7104 		ath11k_chan_info_event(ab, skb);
7105 		break;
7106 	case WMI_PDEV_BSS_CHAN_INFO_EVENTID:
7107 		ath11k_pdev_bss_chan_info_event(ab, skb);
7108 		break;
7109 	case WMI_VDEV_INSTALL_KEY_COMPLETE_EVENTID:
7110 		ath11k_vdev_install_key_compl_event(ab, skb);
7111 		break;
7112 	case WMI_SERVICE_AVAILABLE_EVENTID:
7113 		ath11k_service_available_event(ab, skb);
7114 		break;
7115 	case WMI_PEER_ASSOC_CONF_EVENTID:
7116 		ath11k_peer_assoc_conf_event(ab, skb);
7117 		break;
7118 	case WMI_UPDATE_STATS_EVENTID:
7119 		ath11k_update_stats_event(ab, skb);
7120 		break;
7121 	case WMI_PDEV_CTL_FAILSAFE_CHECK_EVENTID:
7122 		ath11k_pdev_ctl_failsafe_check_event(ab, skb);
7123 		break;
7124 	case WMI_PDEV_CSA_SWITCH_COUNT_STATUS_EVENTID:
7125 		ath11k_wmi_pdev_csa_switch_count_status_event(ab, skb);
7126 		break;
7127 	case WMI_PDEV_TEMPERATURE_EVENTID:
7128 		ath11k_wmi_pdev_temperature_event(ab, skb);
7129 		break;
7130 	case WMI_PDEV_DMA_RING_BUF_RELEASE_EVENTID:
7131 		ath11k_wmi_pdev_dma_ring_buf_release_event(ab, skb);
7132 		break;
7133 	case WMI_HOST_FILS_DISCOVERY_EVENTID:
7134 		ath11k_fils_discovery_event(ab, skb);
7135 		break;
7136 	case WMI_OFFLOAD_PROB_RESP_TX_STATUS_EVENTID:
7137 		ath11k_probe_resp_tx_status_event(ab, skb);
7138 		break;
7139 	/* add Unsupported events here */
7140 	case WMI_TBTTOFFSET_EXT_UPDATE_EVENTID:
7141 	case WMI_PEER_OPER_MODE_CHANGE_EVENTID:
7142 	case WMI_TWT_ENABLE_EVENTID:
7143 	case WMI_TWT_DISABLE_EVENTID:
7144 	case WMI_PDEV_DMA_RING_CFG_RSP_EVENTID:
7145 	case WMI_PEER_CREATE_CONF_EVENTID:
7146 		ath11k_dbg(ab, ATH11K_DBG_WMI,
7147 			   "ignoring unsupported event 0x%x\n", id);
7148 		break;
7149 	case WMI_PDEV_DFS_RADAR_DETECTION_EVENTID:
7150 		ath11k_wmi_pdev_dfs_radar_detected_event(ab, skb);
7151 		break;
7152 	case WMI_VDEV_DELETE_RESP_EVENTID:
7153 		ath11k_vdev_delete_resp_event(ab, skb);
7154 		break;
7155 	case WMI_WOW_WAKEUP_HOST_EVENTID:
7156 		ath11k_wmi_event_wow_wakeup_host(ab, skb);
7157 		break;
7158 	/* TODO: Add remaining events */
7159 	default:
7160 		ath11k_dbg(ab, ATH11K_DBG_WMI, "Unknown eventid: 0x%x\n", id);
7161 		break;
7162 	}
7163 
7164 out:
7165 	dev_kfree_skb(skb);
7166 }
7167 
7168 static int ath11k_connect_pdev_htc_service(struct ath11k_base *ab,
7169 					   u32 pdev_idx)
7170 {
7171 	int status;
7172 	u32 svc_id[] = { ATH11K_HTC_SVC_ID_WMI_CONTROL,
7173 			 ATH11K_HTC_SVC_ID_WMI_CONTROL_MAC1,
7174 			 ATH11K_HTC_SVC_ID_WMI_CONTROL_MAC2 };
7175 
7176 	struct ath11k_htc_svc_conn_req conn_req;
7177 	struct ath11k_htc_svc_conn_resp conn_resp;
7178 
7179 	memset(&conn_req, 0, sizeof(conn_req));
7180 	memset(&conn_resp, 0, sizeof(conn_resp));
7181 
7182 	/* these fields are the same for all service endpoints */
7183 	conn_req.ep_ops.ep_tx_complete = ath11k_wmi_htc_tx_complete;
7184 	conn_req.ep_ops.ep_rx_complete = ath11k_wmi_tlv_op_rx;
7185 	conn_req.ep_ops.ep_tx_credits = ath11k_wmi_op_ep_tx_credits;
7186 
7187 	/* connect to control service */
7188 	conn_req.service_id = svc_id[pdev_idx];
7189 
7190 	status = ath11k_htc_connect_service(&ab->htc, &conn_req, &conn_resp);
7191 	if (status) {
7192 		ath11k_warn(ab, "failed to connect to WMI CONTROL service status: %d\n",
7193 			    status);
7194 		return status;
7195 	}
7196 
7197 	ab->wmi_ab.wmi_endpoint_id[pdev_idx] = conn_resp.eid;
7198 	ab->wmi_ab.wmi[pdev_idx].eid = conn_resp.eid;
7199 	ab->wmi_ab.max_msg_len[pdev_idx] = conn_resp.max_msg_len;
7200 
7201 	return 0;
7202 }
7203 
7204 static int
7205 ath11k_wmi_send_unit_test_cmd(struct ath11k *ar,
7206 			      struct wmi_unit_test_cmd ut_cmd,
7207 			      u32 *test_args)
7208 {
7209 	struct ath11k_pdev_wmi *wmi = ar->wmi;
7210 	struct wmi_unit_test_cmd *cmd;
7211 	struct sk_buff *skb;
7212 	struct wmi_tlv *tlv;
7213 	void *ptr;
7214 	u32 *ut_cmd_args;
7215 	int buf_len, arg_len;
7216 	int ret;
7217 	int i;
7218 
7219 	arg_len = sizeof(u32) * ut_cmd.num_args;
7220 	buf_len = sizeof(ut_cmd) + arg_len + TLV_HDR_SIZE;
7221 
7222 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, buf_len);
7223 	if (!skb)
7224 		return -ENOMEM;
7225 
7226 	cmd = (struct wmi_unit_test_cmd *)skb->data;
7227 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_UNIT_TEST_CMD) |
7228 			  FIELD_PREP(WMI_TLV_LEN, sizeof(ut_cmd) - TLV_HDR_SIZE);
7229 
7230 	cmd->vdev_id = ut_cmd.vdev_id;
7231 	cmd->module_id = ut_cmd.module_id;
7232 	cmd->num_args = ut_cmd.num_args;
7233 	cmd->diag_token = ut_cmd.diag_token;
7234 
7235 	ptr = skb->data + sizeof(ut_cmd);
7236 
7237 	tlv = ptr;
7238 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_UINT32) |
7239 		      FIELD_PREP(WMI_TLV_LEN, arg_len);
7240 
7241 	ptr += TLV_HDR_SIZE;
7242 
7243 	ut_cmd_args = ptr;
7244 	for (i = 0; i < ut_cmd.num_args; i++)
7245 		ut_cmd_args[i] = test_args[i];
7246 
7247 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_UNIT_TEST_CMDID);
7248 
7249 	if (ret) {
7250 		ath11k_warn(ar->ab, "failed to send WMI_UNIT_TEST CMD :%d\n",
7251 			    ret);
7252 		dev_kfree_skb(skb);
7253 	}
7254 
7255 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
7256 		   "WMI unit test : module %d vdev %d n_args %d token %d\n",
7257 		   cmd->module_id, cmd->vdev_id, cmd->num_args,
7258 		   cmd->diag_token);
7259 
7260 	return ret;
7261 }
7262 
7263 int ath11k_wmi_simulate_radar(struct ath11k *ar)
7264 {
7265 	struct ath11k_vif *arvif;
7266 	u32 dfs_args[DFS_MAX_TEST_ARGS];
7267 	struct wmi_unit_test_cmd wmi_ut;
7268 	bool arvif_found = false;
7269 
7270 	list_for_each_entry(arvif, &ar->arvifs, list) {
7271 		if (arvif->is_started && arvif->vdev_type == WMI_VDEV_TYPE_AP) {
7272 			arvif_found = true;
7273 			break;
7274 		}
7275 	}
7276 
7277 	if (!arvif_found)
7278 		return -EINVAL;
7279 
7280 	dfs_args[DFS_TEST_CMDID] = 0;
7281 	dfs_args[DFS_TEST_PDEV_ID] = ar->pdev->pdev_id;
7282 	/* Currently we could pass segment_id(b0 - b1), chirp(b2)
7283 	 * freq offset (b3 - b10) to unit test. For simulation
7284 	 * purpose this can be set to 0 which is valid.
7285 	 */
7286 	dfs_args[DFS_TEST_RADAR_PARAM] = 0;
7287 
7288 	wmi_ut.vdev_id = arvif->vdev_id;
7289 	wmi_ut.module_id = DFS_UNIT_TEST_MODULE;
7290 	wmi_ut.num_args = DFS_MAX_TEST_ARGS;
7291 	wmi_ut.diag_token = DFS_UNIT_TEST_TOKEN;
7292 
7293 	ath11k_dbg(ar->ab, ATH11K_DBG_REG, "Triggering Radar Simulation\n");
7294 
7295 	return ath11k_wmi_send_unit_test_cmd(ar, wmi_ut, dfs_args);
7296 }
7297 
7298 int ath11k_wmi_connect(struct ath11k_base *ab)
7299 {
7300 	u32 i;
7301 	u8 wmi_ep_count;
7302 
7303 	wmi_ep_count = ab->htc.wmi_ep_count;
7304 	if (wmi_ep_count > ab->hw_params.max_radios)
7305 		return -1;
7306 
7307 	for (i = 0; i < wmi_ep_count; i++)
7308 		ath11k_connect_pdev_htc_service(ab, i);
7309 
7310 	return 0;
7311 }
7312 
7313 static void ath11k_wmi_pdev_detach(struct ath11k_base *ab, u8 pdev_id)
7314 {
7315 	if (WARN_ON(pdev_id >= MAX_RADIOS))
7316 		return;
7317 
7318 	/* TODO: Deinit any pdev specific wmi resource */
7319 }
7320 
7321 int ath11k_wmi_pdev_attach(struct ath11k_base *ab,
7322 			   u8 pdev_id)
7323 {
7324 	struct ath11k_pdev_wmi *wmi_handle;
7325 
7326 	if (pdev_id >= ab->hw_params.max_radios)
7327 		return -EINVAL;
7328 
7329 	wmi_handle = &ab->wmi_ab.wmi[pdev_id];
7330 
7331 	wmi_handle->wmi_ab = &ab->wmi_ab;
7332 
7333 	ab->wmi_ab.ab = ab;
7334 	/* TODO: Init remaining resource specific to pdev */
7335 
7336 	return 0;
7337 }
7338 
7339 int ath11k_wmi_attach(struct ath11k_base *ab)
7340 {
7341 	int ret;
7342 
7343 	ret = ath11k_wmi_pdev_attach(ab, 0);
7344 	if (ret)
7345 		return ret;
7346 
7347 	ab->wmi_ab.ab = ab;
7348 	ab->wmi_ab.preferred_hw_mode = WMI_HOST_HW_MODE_MAX;
7349 
7350 	/* It's overwritten when service_ext_ready is handled */
7351 	if (ab->hw_params.single_pdev_only)
7352 		ab->wmi_ab.preferred_hw_mode = WMI_HOST_HW_MODE_SINGLE;
7353 
7354 	/* TODO: Init remaining wmi soc resources required */
7355 	init_completion(&ab->wmi_ab.service_ready);
7356 	init_completion(&ab->wmi_ab.unified_ready);
7357 
7358 	return 0;
7359 }
7360 
7361 void ath11k_wmi_detach(struct ath11k_base *ab)
7362 {
7363 	int i;
7364 
7365 	/* TODO: Deinit wmi resource specific to SOC as required */
7366 
7367 	for (i = 0; i < ab->htc.wmi_ep_count; i++)
7368 		ath11k_wmi_pdev_detach(ab, i);
7369 
7370 	ath11k_wmi_free_dbring_caps(ab);
7371 }
7372 
7373 int ath11k_wmi_wow_host_wakeup_ind(struct ath11k *ar)
7374 {
7375 	struct wmi_wow_host_wakeup_ind *cmd;
7376 	struct sk_buff *skb;
7377 	size_t len;
7378 
7379 	len = sizeof(*cmd);
7380 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, len);
7381 	if (!skb)
7382 		return -ENOMEM;
7383 
7384 	cmd = (struct wmi_wow_host_wakeup_ind *)skb->data;
7385 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
7386 				     WMI_TAG_WOW_HOSTWAKEUP_FROM_SLEEP_CMD) |
7387 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
7388 
7389 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "wmi tlv wow host wakeup ind\n");
7390 
7391 	return ath11k_wmi_cmd_send(ar->wmi, skb, WMI_WOW_HOSTWAKEUP_FROM_SLEEP_CMDID);
7392 }
7393 
7394 int ath11k_wmi_wow_enable(struct ath11k *ar)
7395 {
7396 	struct wmi_wow_enable_cmd *cmd;
7397 	struct sk_buff *skb;
7398 	int len;
7399 
7400 	len = sizeof(*cmd);
7401 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, len);
7402 	if (!skb)
7403 		return -ENOMEM;
7404 
7405 	cmd = (struct wmi_wow_enable_cmd *)skb->data;
7406 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_WOW_ENABLE_CMD) |
7407 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
7408 
7409 	cmd->enable = 1;
7410 	cmd->pause_iface_config = WOW_IFACE_PAUSE_ENABLED;
7411 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "wmi tlv wow enable\n");
7412 
7413 	return ath11k_wmi_cmd_send(ar->wmi, skb, WMI_WOW_ENABLE_CMDID);
7414 }
7415