1 /*
2  * Copyright (c) 2012-2015 Qualcomm Atheros, Inc.
3  *
4  * Permission to use, copy, modify, and/or distribute this software for any
5  * purpose with or without fee is hereby granted, provided that the above
6  * copyright notice and this permission notice appear in all copies.
7  *
8  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15  */
16 
17 #include <linux/etherdevice.h>
18 #include "wil6210.h"
19 #include "wmi.h"
20 
21 #define CHAN60G(_channel, _flags) {				\
22 	.band			= IEEE80211_BAND_60GHZ,		\
23 	.center_freq		= 56160 + (2160 * (_channel)),	\
24 	.hw_value		= (_channel),			\
25 	.flags			= (_flags),			\
26 	.max_antenna_gain	= 0,				\
27 	.max_power		= 40,				\
28 }
29 
30 static struct ieee80211_channel wil_60ghz_channels[] = {
31 	CHAN60G(1, 0),
32 	CHAN60G(2, 0),
33 	CHAN60G(3, 0),
34 /* channel 4 not supported yet */
35 };
36 
37 static struct ieee80211_supported_band wil_band_60ghz = {
38 	.channels = wil_60ghz_channels,
39 	.n_channels = ARRAY_SIZE(wil_60ghz_channels),
40 	.ht_cap = {
41 		.ht_supported = true,
42 		.cap = 0, /* TODO */
43 		.ampdu_factor = IEEE80211_HT_MAX_AMPDU_64K, /* TODO */
44 		.ampdu_density = IEEE80211_HT_MPDU_DENSITY_8, /* TODO */
45 		.mcs = {
46 				/* MCS 1..12 - SC PHY */
47 			.rx_mask = {0xfe, 0x1f}, /* 1..12 */
48 			.tx_params = IEEE80211_HT_MCS_TX_DEFINED, /* TODO */
49 		},
50 	},
51 };
52 
53 static const struct ieee80211_txrx_stypes
54 wil_mgmt_stypes[NUM_NL80211_IFTYPES] = {
55 	[NL80211_IFTYPE_STATION] = {
56 		.tx = BIT(IEEE80211_STYPE_ACTION >> 4) |
57 		BIT(IEEE80211_STYPE_PROBE_RESP >> 4),
58 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
59 		BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
60 	},
61 	[NL80211_IFTYPE_AP] = {
62 		.tx = BIT(IEEE80211_STYPE_ACTION >> 4) |
63 		BIT(IEEE80211_STYPE_PROBE_RESP >> 4),
64 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
65 		BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
66 	},
67 	[NL80211_IFTYPE_P2P_CLIENT] = {
68 		.tx = BIT(IEEE80211_STYPE_ACTION >> 4) |
69 		BIT(IEEE80211_STYPE_PROBE_RESP >> 4),
70 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
71 		BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
72 	},
73 	[NL80211_IFTYPE_P2P_GO] = {
74 		.tx = BIT(IEEE80211_STYPE_ACTION >> 4) |
75 		BIT(IEEE80211_STYPE_PROBE_RESP >> 4),
76 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
77 		BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
78 	},
79 };
80 
81 static const u32 wil_cipher_suites[] = {
82 	WLAN_CIPHER_SUITE_GCMP,
83 };
84 
85 int wil_iftype_nl2wmi(enum nl80211_iftype type)
86 {
87 	static const struct {
88 		enum nl80211_iftype nl;
89 		enum wmi_network_type wmi;
90 	} __nl2wmi[] = {
91 		{NL80211_IFTYPE_ADHOC,		WMI_NETTYPE_ADHOC},
92 		{NL80211_IFTYPE_STATION,	WMI_NETTYPE_INFRA},
93 		{NL80211_IFTYPE_AP,		WMI_NETTYPE_AP},
94 		{NL80211_IFTYPE_P2P_CLIENT,	WMI_NETTYPE_P2P},
95 		{NL80211_IFTYPE_P2P_GO,		WMI_NETTYPE_P2P},
96 		{NL80211_IFTYPE_MONITOR,	WMI_NETTYPE_ADHOC}, /* FIXME */
97 	};
98 	uint i;
99 
100 	for (i = 0; i < ARRAY_SIZE(__nl2wmi); i++) {
101 		if (__nl2wmi[i].nl == type)
102 			return __nl2wmi[i].wmi;
103 	}
104 
105 	return -EOPNOTSUPP;
106 }
107 
108 int wil_cid_fill_sinfo(struct wil6210_priv *wil, int cid,
109 		       struct station_info *sinfo)
110 {
111 	struct wmi_notify_req_cmd cmd = {
112 		.cid = cid,
113 		.interval_usec = 0,
114 	};
115 	struct {
116 		struct wil6210_mbox_hdr_wmi wmi;
117 		struct wmi_notify_req_done_event evt;
118 	} __packed reply;
119 	struct wil_net_stats *stats = &wil->sta[cid].stats;
120 	int rc;
121 
122 	rc = wmi_call(wil, WMI_NOTIFY_REQ_CMDID, &cmd, sizeof(cmd),
123 		      WMI_NOTIFY_REQ_DONE_EVENTID, &reply, sizeof(reply), 20);
124 	if (rc)
125 		return rc;
126 
127 	wil_dbg_wmi(wil, "Link status for CID %d: {\n"
128 		    "  MCS %d TSF 0x%016llx\n"
129 		    "  BF status 0x%08x SNR 0x%08x SQI %d%%\n"
130 		    "  Tx Tpt %d goodput %d Rx goodput %d\n"
131 		    "  Sectors(rx:tx) my %d:%d peer %d:%d\n""}\n",
132 		    cid, le16_to_cpu(reply.evt.bf_mcs),
133 		    le64_to_cpu(reply.evt.tsf), reply.evt.status,
134 		    le32_to_cpu(reply.evt.snr_val),
135 		    reply.evt.sqi,
136 		    le32_to_cpu(reply.evt.tx_tpt),
137 		    le32_to_cpu(reply.evt.tx_goodput),
138 		    le32_to_cpu(reply.evt.rx_goodput),
139 		    le16_to_cpu(reply.evt.my_rx_sector),
140 		    le16_to_cpu(reply.evt.my_tx_sector),
141 		    le16_to_cpu(reply.evt.other_rx_sector),
142 		    le16_to_cpu(reply.evt.other_tx_sector));
143 
144 	sinfo->generation = wil->sinfo_gen;
145 
146 	sinfo->filled = BIT(NL80211_STA_INFO_RX_BYTES) |
147 			BIT(NL80211_STA_INFO_TX_BYTES) |
148 			BIT(NL80211_STA_INFO_RX_PACKETS) |
149 			BIT(NL80211_STA_INFO_TX_PACKETS) |
150 			BIT(NL80211_STA_INFO_RX_BITRATE) |
151 			BIT(NL80211_STA_INFO_TX_BITRATE) |
152 			BIT(NL80211_STA_INFO_RX_DROP_MISC) |
153 			BIT(NL80211_STA_INFO_TX_FAILED);
154 
155 	sinfo->txrate.flags = RATE_INFO_FLAGS_MCS | RATE_INFO_FLAGS_60G;
156 	sinfo->txrate.mcs = le16_to_cpu(reply.evt.bf_mcs);
157 	sinfo->rxrate.flags = RATE_INFO_FLAGS_MCS | RATE_INFO_FLAGS_60G;
158 	sinfo->rxrate.mcs = stats->last_mcs_rx;
159 	sinfo->rx_bytes = stats->rx_bytes;
160 	sinfo->rx_packets = stats->rx_packets;
161 	sinfo->rx_dropped_misc = stats->rx_dropped;
162 	sinfo->tx_bytes = stats->tx_bytes;
163 	sinfo->tx_packets = stats->tx_packets;
164 	sinfo->tx_failed = stats->tx_errors;
165 
166 	if (test_bit(wil_status_fwconnected, wil->status)) {
167 		sinfo->filled |= BIT(NL80211_STA_INFO_SIGNAL);
168 		sinfo->signal = reply.evt.sqi;
169 	}
170 
171 	return rc;
172 }
173 
174 static int wil_cfg80211_get_station(struct wiphy *wiphy,
175 				    struct net_device *ndev,
176 				    const u8 *mac, struct station_info *sinfo)
177 {
178 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
179 	int rc;
180 
181 	int cid = wil_find_cid(wil, mac);
182 
183 	wil_dbg_misc(wil, "%s(%pM) CID %d\n", __func__, mac, cid);
184 	if (cid < 0)
185 		return cid;
186 
187 	rc = wil_cid_fill_sinfo(wil, cid, sinfo);
188 
189 	return rc;
190 }
191 
192 /*
193  * Find @idx-th active STA for station dump.
194  */
195 static int wil_find_cid_by_idx(struct wil6210_priv *wil, int idx)
196 {
197 	int i;
198 
199 	for (i = 0; i < ARRAY_SIZE(wil->sta); i++) {
200 		if (wil->sta[i].status == wil_sta_unused)
201 			continue;
202 		if (idx == 0)
203 			return i;
204 		idx--;
205 	}
206 
207 	return -ENOENT;
208 }
209 
210 static int wil_cfg80211_dump_station(struct wiphy *wiphy,
211 				     struct net_device *dev, int idx,
212 				     u8 *mac, struct station_info *sinfo)
213 {
214 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
215 	int rc;
216 	int cid = wil_find_cid_by_idx(wil, idx);
217 
218 	if (cid < 0)
219 		return -ENOENT;
220 
221 	ether_addr_copy(mac, wil->sta[cid].addr);
222 	wil_dbg_misc(wil, "%s(%pM) CID %d\n", __func__, mac, cid);
223 
224 	rc = wil_cid_fill_sinfo(wil, cid, sinfo);
225 
226 	return rc;
227 }
228 
229 static int wil_cfg80211_change_iface(struct wiphy *wiphy,
230 				     struct net_device *ndev,
231 				     enum nl80211_iftype type, u32 *flags,
232 				     struct vif_params *params)
233 {
234 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
235 	struct wireless_dev *wdev = wil->wdev;
236 
237 	switch (type) {
238 	case NL80211_IFTYPE_STATION:
239 	case NL80211_IFTYPE_AP:
240 	case NL80211_IFTYPE_P2P_CLIENT:
241 	case NL80211_IFTYPE_P2P_GO:
242 		break;
243 	case NL80211_IFTYPE_MONITOR:
244 		if (flags)
245 			wil->monitor_flags = *flags;
246 		else
247 			wil->monitor_flags = 0;
248 
249 		break;
250 	default:
251 		return -EOPNOTSUPP;
252 	}
253 
254 	wdev->iftype = type;
255 
256 	return 0;
257 }
258 
259 static int wil_cfg80211_scan(struct wiphy *wiphy,
260 			     struct cfg80211_scan_request *request)
261 {
262 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
263 	struct wireless_dev *wdev = wil->wdev;
264 	struct {
265 		struct wmi_start_scan_cmd cmd;
266 		u16 chnl[4];
267 	} __packed cmd;
268 	uint i, n;
269 	int rc;
270 
271 	if (wil->scan_request) {
272 		wil_err(wil, "Already scanning\n");
273 		return -EAGAIN;
274 	}
275 
276 	/* check we are client side */
277 	switch (wdev->iftype) {
278 	case NL80211_IFTYPE_STATION:
279 	case NL80211_IFTYPE_P2P_CLIENT:
280 		break;
281 	default:
282 		return -EOPNOTSUPP;
283 	}
284 
285 	/* FW don't support scan after connection attempt */
286 	if (test_bit(wil_status_dontscan, wil->status)) {
287 		wil_err(wil, "Can't scan now\n");
288 		return -EBUSY;
289 	}
290 
291 	wil_dbg_misc(wil, "Start scan_request 0x%p\n", request);
292 	wil_dbg_misc(wil, "SSID count: %d", request->n_ssids);
293 
294 	for (i = 0; i < request->n_ssids; i++) {
295 		wil_dbg_misc(wil, "SSID[%d]", i);
296 		print_hex_dump_bytes("SSID ", DUMP_PREFIX_OFFSET,
297 				     request->ssids[i].ssid,
298 				     request->ssids[i].ssid_len);
299 	}
300 
301 	if (request->n_ssids)
302 		rc = wmi_set_ssid(wil, request->ssids[0].ssid_len,
303 				  request->ssids[0].ssid);
304 	else
305 		rc = wmi_set_ssid(wil, 0, NULL);
306 
307 	if (rc) {
308 		wil_err(wil, "set SSID for scan request failed: %d\n", rc);
309 		return rc;
310 	}
311 
312 	wil->scan_request = request;
313 	mod_timer(&wil->scan_timer, jiffies + WIL6210_SCAN_TO);
314 
315 	memset(&cmd, 0, sizeof(cmd));
316 	cmd.cmd.num_channels = 0;
317 	n = min(request->n_channels, 4U);
318 	for (i = 0; i < n; i++) {
319 		int ch = request->channels[i]->hw_value;
320 
321 		if (ch == 0) {
322 			wil_err(wil,
323 				"Scan requested for unknown frequency %dMhz\n",
324 				request->channels[i]->center_freq);
325 			continue;
326 		}
327 		/* 0-based channel indexes */
328 		cmd.cmd.channel_list[cmd.cmd.num_channels++].channel = ch - 1;
329 		wil_dbg_misc(wil, "Scan for ch %d  : %d MHz\n", ch,
330 			     request->channels[i]->center_freq);
331 	}
332 
333 	if (request->ie_len)
334 		print_hex_dump_bytes("Scan IE ", DUMP_PREFIX_OFFSET,
335 				     request->ie, request->ie_len);
336 	else
337 		wil_dbg_misc(wil, "Scan has no IE's\n");
338 
339 	rc = wmi_set_ie(wil, WMI_FRAME_PROBE_REQ, request->ie_len,
340 			request->ie);
341 	if (rc) {
342 		wil_err(wil, "Aborting scan, set_ie failed: %d\n", rc);
343 		goto out;
344 	}
345 
346 	rc = wmi_send(wil, WMI_START_SCAN_CMDID, &cmd, sizeof(cmd.cmd) +
347 			cmd.cmd.num_channels * sizeof(cmd.cmd.channel_list[0]));
348 
349 out:
350 	if (rc) {
351 		del_timer_sync(&wil->scan_timer);
352 		wil->scan_request = NULL;
353 	}
354 
355 	return rc;
356 }
357 
358 static void wil_print_crypto(struct wil6210_priv *wil,
359 			     struct cfg80211_crypto_settings *c)
360 {
361 	int i, n;
362 
363 	wil_dbg_misc(wil, "WPA versions: 0x%08x cipher group 0x%08x\n",
364 		     c->wpa_versions, c->cipher_group);
365 	wil_dbg_misc(wil, "Pairwise ciphers [%d] {\n", c->n_ciphers_pairwise);
366 	n = min_t(int, c->n_ciphers_pairwise, ARRAY_SIZE(c->ciphers_pairwise));
367 	for (i = 0; i < n; i++)
368 		wil_dbg_misc(wil, "  [%d] = 0x%08x\n", i,
369 			     c->ciphers_pairwise[i]);
370 	wil_dbg_misc(wil, "}\n");
371 	wil_dbg_misc(wil, "AKM suites [%d] {\n", c->n_akm_suites);
372 	n = min_t(int, c->n_akm_suites, ARRAY_SIZE(c->akm_suites));
373 	for (i = 0; i < n; i++)
374 		wil_dbg_misc(wil, "  [%d] = 0x%08x\n", i,
375 			     c->akm_suites[i]);
376 	wil_dbg_misc(wil, "}\n");
377 	wil_dbg_misc(wil, "Control port : %d, eth_type 0x%04x no_encrypt %d\n",
378 		     c->control_port, be16_to_cpu(c->control_port_ethertype),
379 		     c->control_port_no_encrypt);
380 }
381 
382 static void wil_print_connect_params(struct wil6210_priv *wil,
383 				     struct cfg80211_connect_params *sme)
384 {
385 	wil_info(wil, "Connecting to:\n");
386 	if (sme->channel) {
387 		wil_info(wil, "  Channel: %d freq %d\n",
388 			 sme->channel->hw_value, sme->channel->center_freq);
389 	}
390 	if (sme->bssid)
391 		wil_info(wil, "  BSSID: %pM\n", sme->bssid);
392 	if (sme->ssid)
393 		print_hex_dump(KERN_INFO, "  SSID: ", DUMP_PREFIX_OFFSET,
394 			       16, 1, sme->ssid, sme->ssid_len, true);
395 	wil_info(wil, "  Privacy: %s\n", sme->privacy ? "secure" : "open");
396 	wil_print_crypto(wil, &sme->crypto);
397 }
398 
399 static int wil_cfg80211_connect(struct wiphy *wiphy,
400 				struct net_device *ndev,
401 				struct cfg80211_connect_params *sme)
402 {
403 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
404 	struct cfg80211_bss *bss;
405 	struct wmi_connect_cmd conn;
406 	const u8 *ssid_eid;
407 	const u8 *rsn_eid;
408 	int ch;
409 	int rc = 0;
410 
411 	wil_print_connect_params(wil, sme);
412 
413 	if (test_bit(wil_status_fwconnecting, wil->status) ||
414 	    test_bit(wil_status_fwconnected, wil->status))
415 		return -EALREADY;
416 
417 	if (sme->ie_len > WMI_MAX_IE_LEN) {
418 		wil_err(wil, "IE too large (%td bytes)\n", sme->ie_len);
419 		return -ERANGE;
420 	}
421 
422 	rsn_eid = sme->ie ?
423 			cfg80211_find_ie(WLAN_EID_RSN, sme->ie, sme->ie_len) :
424 			NULL;
425 	if (sme->privacy && !rsn_eid)
426 		wil_info(wil, "WSC connection\n");
427 
428 	bss = cfg80211_get_bss(wiphy, sme->channel, sme->bssid,
429 			       sme->ssid, sme->ssid_len,
430 			       IEEE80211_BSS_TYPE_ESS, IEEE80211_PRIVACY_ANY);
431 	if (!bss) {
432 		wil_err(wil, "Unable to find BSS\n");
433 		return -ENOENT;
434 	}
435 
436 	ssid_eid = ieee80211_bss_get_ie(bss, WLAN_EID_SSID);
437 	if (!ssid_eid) {
438 		wil_err(wil, "No SSID\n");
439 		rc = -ENOENT;
440 		goto out;
441 	}
442 	wil->privacy = sme->privacy;
443 
444 	if (wil->privacy) {
445 		/* For secure assoc, remove old keys */
446 		rc = wmi_del_cipher_key(wil, 0, bss->bssid,
447 					WMI_KEY_USE_PAIRWISE);
448 		if (rc) {
449 			wil_err(wil, "WMI_DELETE_CIPHER_KEY_CMD(PTK) failed\n");
450 			goto out;
451 		}
452 		rc = wmi_del_cipher_key(wil, 0, bss->bssid,
453 					WMI_KEY_USE_RX_GROUP);
454 		if (rc) {
455 			wil_err(wil, "WMI_DELETE_CIPHER_KEY_CMD(GTK) failed\n");
456 			goto out;
457 		}
458 	}
459 
460 	/* WMI_SET_APPIE_CMD. ie may contain rsn info as well as other info
461 	 * elements. Send it also in case it's empty, to erase previously set
462 	 * ies in FW.
463 	 */
464 	rc = wmi_set_ie(wil, WMI_FRAME_ASSOC_REQ, sme->ie_len, sme->ie);
465 	if (rc) {
466 		wil_err(wil, "WMI_SET_APPIE_CMD failed\n");
467 		goto out;
468 	}
469 
470 	/* WMI_CONNECT_CMD */
471 	memset(&conn, 0, sizeof(conn));
472 	switch (bss->capability & WLAN_CAPABILITY_DMG_TYPE_MASK) {
473 	case WLAN_CAPABILITY_DMG_TYPE_AP:
474 		conn.network_type = WMI_NETTYPE_INFRA;
475 		break;
476 	case WLAN_CAPABILITY_DMG_TYPE_PBSS:
477 		conn.network_type = WMI_NETTYPE_P2P;
478 		break;
479 	default:
480 		wil_err(wil, "Unsupported BSS type, capability= 0x%04x\n",
481 			bss->capability);
482 		goto out;
483 	}
484 	if (wil->privacy) {
485 		if (rsn_eid) { /* regular secure connection */
486 			conn.dot11_auth_mode = WMI_AUTH11_SHARED;
487 			conn.auth_mode = WMI_AUTH_WPA2_PSK;
488 			conn.pairwise_crypto_type = WMI_CRYPT_AES_GCMP;
489 			conn.pairwise_crypto_len = 16;
490 			conn.group_crypto_type = WMI_CRYPT_AES_GCMP;
491 			conn.group_crypto_len = 16;
492 		} else { /* WSC */
493 			conn.dot11_auth_mode = WMI_AUTH11_WSC;
494 			conn.auth_mode = WMI_AUTH_NONE;
495 		}
496 	} else { /* insecure connection */
497 		conn.dot11_auth_mode = WMI_AUTH11_OPEN;
498 		conn.auth_mode = WMI_AUTH_NONE;
499 	}
500 
501 	conn.ssid_len = min_t(u8, ssid_eid[1], 32);
502 	memcpy(conn.ssid, ssid_eid+2, conn.ssid_len);
503 
504 	ch = bss->channel->hw_value;
505 	if (ch == 0) {
506 		wil_err(wil, "BSS at unknown frequency %dMhz\n",
507 			bss->channel->center_freq);
508 		rc = -EOPNOTSUPP;
509 		goto out;
510 	}
511 	conn.channel = ch - 1;
512 
513 	ether_addr_copy(conn.bssid, bss->bssid);
514 	ether_addr_copy(conn.dst_mac, bss->bssid);
515 
516 	set_bit(wil_status_fwconnecting, wil->status);
517 
518 	rc = wmi_send(wil, WMI_CONNECT_CMDID, &conn, sizeof(conn));
519 	if (rc == 0) {
520 		netif_carrier_on(ndev);
521 		/* Connect can take lots of time */
522 		mod_timer(&wil->connect_timer,
523 			  jiffies + msecs_to_jiffies(2000));
524 	} else {
525 		clear_bit(wil_status_fwconnecting, wil->status);
526 	}
527 
528  out:
529 	cfg80211_put_bss(wiphy, bss);
530 
531 	return rc;
532 }
533 
534 static int wil_cfg80211_disconnect(struct wiphy *wiphy,
535 				   struct net_device *ndev,
536 				   u16 reason_code)
537 {
538 	int rc;
539 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
540 
541 	wil_dbg_misc(wil, "%s(reason=%d)\n", __func__, reason_code);
542 
543 	rc = wmi_send(wil, WMI_DISCONNECT_CMDID, NULL, 0);
544 
545 	return rc;
546 }
547 
548 int wil_cfg80211_mgmt_tx(struct wiphy *wiphy, struct wireless_dev *wdev,
549 			 struct cfg80211_mgmt_tx_params *params,
550 			 u64 *cookie)
551 {
552 	const u8 *buf = params->buf;
553 	size_t len = params->len;
554 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
555 	int rc;
556 	bool tx_status = false;
557 	struct ieee80211_mgmt *mgmt_frame = (void *)buf;
558 	struct wmi_sw_tx_req_cmd *cmd;
559 	struct {
560 		struct wil6210_mbox_hdr_wmi wmi;
561 		struct wmi_sw_tx_complete_event evt;
562 	} __packed evt;
563 
564 	cmd = kmalloc(sizeof(*cmd) + len, GFP_KERNEL);
565 	if (!cmd) {
566 		rc = -ENOMEM;
567 		goto out;
568 	}
569 
570 	memcpy(cmd->dst_mac, mgmt_frame->da, WMI_MAC_LEN);
571 	cmd->len = cpu_to_le16(len);
572 	memcpy(cmd->payload, buf, len);
573 
574 	rc = wmi_call(wil, WMI_SW_TX_REQ_CMDID, cmd, sizeof(*cmd) + len,
575 		      WMI_SW_TX_COMPLETE_EVENTID, &evt, sizeof(evt), 2000);
576 	if (rc == 0)
577 		tx_status = !evt.evt.status;
578 
579 	kfree(cmd);
580  out:
581 	cfg80211_mgmt_tx_status(wdev, cookie ? *cookie : 0, buf, len,
582 				tx_status, GFP_KERNEL);
583 	return rc;
584 }
585 
586 static int wil_cfg80211_set_channel(struct wiphy *wiphy,
587 				    struct cfg80211_chan_def *chandef)
588 {
589 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
590 	struct wireless_dev *wdev = wil->wdev;
591 
592 	wdev->preset_chandef = *chandef;
593 
594 	return 0;
595 }
596 
597 static enum wmi_key_usage wil_detect_key_usage(struct wil6210_priv *wil,
598 					       bool pairwise)
599 {
600 	struct wireless_dev *wdev = wil->wdev;
601 	enum wmi_key_usage rc;
602 	static const char * const key_usage_str[] = {
603 		[WMI_KEY_USE_PAIRWISE]	= "WMI_KEY_USE_PAIRWISE",
604 		[WMI_KEY_USE_RX_GROUP]	= "WMI_KEY_USE_RX_GROUP",
605 		[WMI_KEY_USE_TX_GROUP]	= "WMI_KEY_USE_TX_GROUP",
606 	};
607 
608 	if (pairwise) {
609 		rc = WMI_KEY_USE_PAIRWISE;
610 	} else {
611 		switch (wdev->iftype) {
612 		case NL80211_IFTYPE_STATION:
613 			rc = WMI_KEY_USE_RX_GROUP;
614 			break;
615 		case NL80211_IFTYPE_AP:
616 			rc = WMI_KEY_USE_TX_GROUP;
617 			break;
618 		default:
619 			/* TODO: Rx GTK or Tx GTK? */
620 			wil_err(wil, "Can't determine GTK type\n");
621 			rc = WMI_KEY_USE_RX_GROUP;
622 			break;
623 		}
624 	}
625 	wil_dbg_misc(wil, "%s() -> %s\n", __func__, key_usage_str[rc]);
626 
627 	return rc;
628 }
629 
630 static int wil_cfg80211_add_key(struct wiphy *wiphy,
631 				struct net_device *ndev,
632 				u8 key_index, bool pairwise,
633 				const u8 *mac_addr,
634 				struct key_params *params)
635 {
636 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
637 	enum wmi_key_usage key_usage = wil_detect_key_usage(wil, pairwise);
638 
639 	wil_dbg_misc(wil, "%s(%pM[%d] %s)\n", __func__, mac_addr, key_index,
640 		     pairwise ? "PTK" : "GTK");
641 
642 	return wmi_add_cipher_key(wil, key_index, mac_addr, params->key_len,
643 				  params->key, key_usage);
644 }
645 
646 static int wil_cfg80211_del_key(struct wiphy *wiphy,
647 				struct net_device *ndev,
648 				u8 key_index, bool pairwise,
649 				const u8 *mac_addr)
650 {
651 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
652 	enum wmi_key_usage key_usage = wil_detect_key_usage(wil, pairwise);
653 
654 	wil_dbg_misc(wil, "%s(%pM[%d] %s)\n", __func__, mac_addr, key_index,
655 		     pairwise ? "PTK" : "GTK");
656 
657 	return wmi_del_cipher_key(wil, key_index, mac_addr, key_usage);
658 }
659 
660 /* Need to be present or wiphy_new() will WARN */
661 static int wil_cfg80211_set_default_key(struct wiphy *wiphy,
662 					struct net_device *ndev,
663 					u8 key_index, bool unicast,
664 					bool multicast)
665 {
666 	return 0;
667 }
668 
669 static int wil_remain_on_channel(struct wiphy *wiphy,
670 				 struct wireless_dev *wdev,
671 				 struct ieee80211_channel *chan,
672 				 unsigned int duration,
673 				 u64 *cookie)
674 {
675 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
676 	int rc;
677 
678 	/* TODO: handle duration */
679 	wil_info(wil, "%s(%d, %d ms)\n", __func__, chan->center_freq, duration);
680 
681 	rc = wmi_set_channel(wil, chan->hw_value);
682 	if (rc)
683 		return rc;
684 
685 	rc = wmi_rxon(wil, true);
686 
687 	return rc;
688 }
689 
690 static int wil_cancel_remain_on_channel(struct wiphy *wiphy,
691 					struct wireless_dev *wdev,
692 					u64 cookie)
693 {
694 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
695 	int rc;
696 
697 	wil_info(wil, "%s()\n", __func__);
698 
699 	rc = wmi_rxon(wil, false);
700 
701 	return rc;
702 }
703 
704 static void wil_print_bcon_data(struct cfg80211_beacon_data *b)
705 {
706 	print_hex_dump_bytes("head     ", DUMP_PREFIX_OFFSET,
707 			     b->head, b->head_len);
708 	print_hex_dump_bytes("tail     ", DUMP_PREFIX_OFFSET,
709 			     b->tail, b->tail_len);
710 	print_hex_dump_bytes("BCON IE  ", DUMP_PREFIX_OFFSET,
711 			     b->beacon_ies, b->beacon_ies_len);
712 	print_hex_dump_bytes("PROBE    ", DUMP_PREFIX_OFFSET,
713 			     b->probe_resp, b->probe_resp_len);
714 	print_hex_dump_bytes("PROBE IE ", DUMP_PREFIX_OFFSET,
715 			     b->proberesp_ies, b->proberesp_ies_len);
716 	print_hex_dump_bytes("ASSOC IE ", DUMP_PREFIX_OFFSET,
717 			     b->assocresp_ies, b->assocresp_ies_len);
718 }
719 
720 static int wil_fix_bcon(struct wil6210_priv *wil,
721 			struct cfg80211_beacon_data *bcon)
722 {
723 	struct ieee80211_mgmt *f = (struct ieee80211_mgmt *)bcon->probe_resp;
724 	size_t hlen = offsetof(struct ieee80211_mgmt, u.probe_resp.variable);
725 	int rc = 0;
726 
727 	if (bcon->probe_resp_len <= hlen)
728 		return 0;
729 
730 	if (!bcon->assocresp_ies) {
731 		bcon->assocresp_ies = f->u.probe_resp.variable;
732 		bcon->assocresp_ies_len = bcon->probe_resp_len - hlen;
733 		rc = 1;
734 	}
735 
736 	return rc;
737 }
738 
739 static int wil_cfg80211_change_beacon(struct wiphy *wiphy,
740 				      struct net_device *ndev,
741 				      struct cfg80211_beacon_data *bcon)
742 {
743 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
744 	struct ieee80211_mgmt *f = (struct ieee80211_mgmt *)bcon->probe_resp;
745 	size_t hlen = offsetof(struct ieee80211_mgmt, u.probe_resp.variable);
746 	const u8 *pr_ies = NULL;
747 	size_t pr_ies_len = 0;
748 	int rc;
749 
750 	wil_dbg_misc(wil, "%s()\n", __func__);
751 	wil_print_bcon_data(bcon);
752 
753 	if (bcon->probe_resp_len > hlen) {
754 		pr_ies = f->u.probe_resp.variable;
755 		pr_ies_len = bcon->probe_resp_len - hlen;
756 	}
757 
758 	if (wil_fix_bcon(wil, bcon)) {
759 		wil_dbg_misc(wil, "Fixed bcon\n");
760 		wil_print_bcon_data(bcon);
761 	}
762 
763 	/* FW do not form regular beacon, so bcon IE's are not set
764 	 * For the DMG bcon, when it will be supported, bcon IE's will
765 	 * be reused; add something like:
766 	 * wmi_set_ie(wil, WMI_FRAME_BEACON, bcon->beacon_ies_len,
767 	 * bcon->beacon_ies);
768 	 */
769 	rc = wmi_set_ie(wil, WMI_FRAME_PROBE_RESP, pr_ies_len, pr_ies);
770 	if (rc) {
771 		wil_err(wil, "set_ie(PROBE_RESP) failed\n");
772 		return rc;
773 	}
774 
775 	rc = wmi_set_ie(wil, WMI_FRAME_ASSOC_RESP,
776 			bcon->assocresp_ies_len,
777 			bcon->assocresp_ies);
778 	if (rc) {
779 		wil_err(wil, "set_ie(ASSOC_RESP) failed\n");
780 		return rc;
781 	}
782 
783 	return 0;
784 }
785 
786 static int wil_cfg80211_start_ap(struct wiphy *wiphy,
787 				 struct net_device *ndev,
788 				 struct cfg80211_ap_settings *info)
789 {
790 	int rc = 0;
791 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
792 	struct wireless_dev *wdev = ndev->ieee80211_ptr;
793 	struct ieee80211_channel *channel = info->chandef.chan;
794 	struct cfg80211_beacon_data *bcon = &info->beacon;
795 	struct cfg80211_crypto_settings *crypto = &info->crypto;
796 	u8 wmi_nettype = wil_iftype_nl2wmi(wdev->iftype);
797 	struct ieee80211_mgmt *f = (struct ieee80211_mgmt *)bcon->probe_resp;
798 	size_t hlen = offsetof(struct ieee80211_mgmt, u.probe_resp.variable);
799 	const u8 *pr_ies = NULL;
800 	size_t pr_ies_len = 0;
801 	u8 hidden_ssid;
802 
803 	wil_dbg_misc(wil, "%s()\n", __func__);
804 
805 	if (!channel) {
806 		wil_err(wil, "AP: No channel???\n");
807 		return -EINVAL;
808 	}
809 
810 	wil_dbg_misc(wil, "AP on Channel %d %d MHz, %s\n", channel->hw_value,
811 		     channel->center_freq, info->privacy ? "secure" : "open");
812 	wil_dbg_misc(wil, "Privacy: %d auth_type %d\n",
813 		     info->privacy, info->auth_type);
814 	wil_dbg_misc(wil, "Hidden SSID mode: %d\n",
815 		     info->hidden_ssid);
816 	wil_dbg_misc(wil, "BI %d DTIM %d\n", info->beacon_interval,
817 		     info->dtim_period);
818 	print_hex_dump_bytes("SSID ", DUMP_PREFIX_OFFSET,
819 			     info->ssid, info->ssid_len);
820 	wil_print_bcon_data(bcon);
821 	wil_print_crypto(wil, crypto);
822 
823 	if (bcon->probe_resp_len > hlen) {
824 		pr_ies = f->u.probe_resp.variable;
825 		pr_ies_len = bcon->probe_resp_len - hlen;
826 	}
827 
828 	if (wil_fix_bcon(wil, bcon)) {
829 		wil_dbg_misc(wil, "Fixed bcon\n");
830 		wil_print_bcon_data(bcon);
831 	}
832 
833 	wil_set_recovery_state(wil, fw_recovery_idle);
834 
835 	mutex_lock(&wil->mutex);
836 
837 	__wil_down(wil);
838 	rc = __wil_up(wil);
839 	if (rc)
840 		goto out;
841 
842 	rc = wmi_set_ssid(wil, info->ssid_len, info->ssid);
843 	if (rc)
844 		goto out;
845 
846 	/* IE's */
847 	/* bcon 'head IE's are not relevant for 60g band */
848 	/*
849 	 * FW do not form regular beacon, so bcon IE's are not set
850 	 * For the DMG bcon, when it will be supported, bcon IE's will
851 	 * be reused; add something like:
852 	 * wmi_set_ie(wil, WMI_FRAME_BEACON, bcon->beacon_ies_len,
853 	 * bcon->beacon_ies);
854 	 */
855 	wmi_set_ie(wil, WMI_FRAME_PROBE_RESP, pr_ies_len, pr_ies);
856 	wmi_set_ie(wil, WMI_FRAME_ASSOC_RESP, bcon->assocresp_ies_len,
857 		   bcon->assocresp_ies);
858 
859 	wil->privacy = info->privacy;
860 
861 	switch (info->hidden_ssid) {
862 	case NL80211_HIDDEN_SSID_NOT_IN_USE:
863 		hidden_ssid = WMI_HIDDEN_SSID_DISABLED;
864 		break;
865 
866 	case NL80211_HIDDEN_SSID_ZERO_LEN:
867 		hidden_ssid = WMI_HIDDEN_SSID_SEND_EMPTY;
868 		break;
869 
870 	case NL80211_HIDDEN_SSID_ZERO_CONTENTS:
871 		hidden_ssid = WMI_HIDDEN_SSID_CLEAR;
872 		break;
873 
874 	default:
875 		rc = -EOPNOTSUPP;
876 		goto out;
877 	}
878 
879 	netif_carrier_on(ndev);
880 
881 	rc = wmi_pcp_start(wil, info->beacon_interval, wmi_nettype,
882 			   channel->hw_value, hidden_ssid);
883 	if (rc)
884 		goto err_pcp_start;
885 
886 	rc = wil_bcast_init(wil);
887 	if (rc)
888 		goto err_bcast;
889 
890 	goto out; /* success */
891 err_bcast:
892 	wmi_pcp_stop(wil);
893 err_pcp_start:
894 	netif_carrier_off(ndev);
895 out:
896 	mutex_unlock(&wil->mutex);
897 	return rc;
898 }
899 
900 static int wil_cfg80211_stop_ap(struct wiphy *wiphy,
901 				struct net_device *ndev)
902 {
903 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
904 
905 	wil_dbg_misc(wil, "%s()\n", __func__);
906 
907 	netif_carrier_off(ndev);
908 	wil_set_recovery_state(wil, fw_recovery_idle);
909 
910 	mutex_lock(&wil->mutex);
911 
912 	wmi_pcp_stop(wil);
913 
914 	__wil_down(wil);
915 
916 	mutex_unlock(&wil->mutex);
917 
918 	return 0;
919 }
920 
921 static int wil_cfg80211_del_station(struct wiphy *wiphy,
922 				    struct net_device *dev,
923 				    struct station_del_parameters *params)
924 {
925 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
926 
927 	wil_dbg_misc(wil, "%s(%pM, reason=%d)\n", __func__, params->mac,
928 		     params->reason_code);
929 
930 	mutex_lock(&wil->mutex);
931 	wil6210_disconnect(wil, params->mac, params->reason_code, false);
932 	mutex_unlock(&wil->mutex);
933 
934 	return 0;
935 }
936 
937 /* probe_client handling */
938 static void wil_probe_client_handle(struct wil6210_priv *wil,
939 				    struct wil_probe_client_req *req)
940 {
941 	struct net_device *ndev = wil_to_ndev(wil);
942 	struct wil_sta_info *sta = &wil->sta[req->cid];
943 	/* assume STA is alive if it is still connected,
944 	 * else FW will disconnect it
945 	 */
946 	bool alive = (sta->status == wil_sta_connected);
947 
948 	cfg80211_probe_status(ndev, sta->addr, req->cookie, alive, GFP_KERNEL);
949 }
950 
951 static struct list_head *next_probe_client(struct wil6210_priv *wil)
952 {
953 	struct list_head *ret = NULL;
954 
955 	mutex_lock(&wil->probe_client_mutex);
956 
957 	if (!list_empty(&wil->probe_client_pending)) {
958 		ret = wil->probe_client_pending.next;
959 		list_del(ret);
960 	}
961 
962 	mutex_unlock(&wil->probe_client_mutex);
963 
964 	return ret;
965 }
966 
967 void wil_probe_client_worker(struct work_struct *work)
968 {
969 	struct wil6210_priv *wil = container_of(work, struct wil6210_priv,
970 						probe_client_worker);
971 	struct wil_probe_client_req *req;
972 	struct list_head *lh;
973 
974 	while ((lh = next_probe_client(wil)) != NULL) {
975 		req = list_entry(lh, struct wil_probe_client_req, list);
976 
977 		wil_probe_client_handle(wil, req);
978 		kfree(req);
979 	}
980 }
981 
982 void wil_probe_client_flush(struct wil6210_priv *wil)
983 {
984 	struct wil_probe_client_req *req, *t;
985 
986 	wil_dbg_misc(wil, "%s()\n", __func__);
987 
988 	mutex_lock(&wil->probe_client_mutex);
989 
990 	list_for_each_entry_safe(req, t, &wil->probe_client_pending, list) {
991 		list_del(&req->list);
992 		kfree(req);
993 	}
994 
995 	mutex_unlock(&wil->probe_client_mutex);
996 }
997 
998 static int wil_cfg80211_probe_client(struct wiphy *wiphy,
999 				     struct net_device *dev,
1000 				     const u8 *peer, u64 *cookie)
1001 {
1002 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1003 	struct wil_probe_client_req *req;
1004 	int cid = wil_find_cid(wil, peer);
1005 
1006 	wil_dbg_misc(wil, "%s(%pM => CID %d)\n", __func__, peer, cid);
1007 
1008 	if (cid < 0)
1009 		return -ENOLINK;
1010 
1011 	req = kzalloc(sizeof(*req), GFP_KERNEL);
1012 	if (!req)
1013 		return -ENOMEM;
1014 
1015 	req->cid = cid;
1016 	req->cookie = cid;
1017 
1018 	mutex_lock(&wil->probe_client_mutex);
1019 	list_add_tail(&req->list, &wil->probe_client_pending);
1020 	mutex_unlock(&wil->probe_client_mutex);
1021 
1022 	*cookie = req->cookie;
1023 	queue_work(wil->wq_service, &wil->probe_client_worker);
1024 	return 0;
1025 }
1026 
1027 static int wil_cfg80211_change_bss(struct wiphy *wiphy,
1028 				   struct net_device *dev,
1029 				   struct bss_parameters *params)
1030 {
1031 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1032 
1033 	if (params->ap_isolate >= 0) {
1034 		wil_dbg_misc(wil, "%s(ap_isolate %d => %d)\n", __func__,
1035 			     wil->ap_isolate, params->ap_isolate);
1036 		wil->ap_isolate = params->ap_isolate;
1037 	}
1038 
1039 	return 0;
1040 }
1041 
1042 static struct cfg80211_ops wil_cfg80211_ops = {
1043 	.scan = wil_cfg80211_scan,
1044 	.connect = wil_cfg80211_connect,
1045 	.disconnect = wil_cfg80211_disconnect,
1046 	.change_virtual_intf = wil_cfg80211_change_iface,
1047 	.get_station = wil_cfg80211_get_station,
1048 	.dump_station = wil_cfg80211_dump_station,
1049 	.remain_on_channel = wil_remain_on_channel,
1050 	.cancel_remain_on_channel = wil_cancel_remain_on_channel,
1051 	.mgmt_tx = wil_cfg80211_mgmt_tx,
1052 	.set_monitor_channel = wil_cfg80211_set_channel,
1053 	.add_key = wil_cfg80211_add_key,
1054 	.del_key = wil_cfg80211_del_key,
1055 	.set_default_key = wil_cfg80211_set_default_key,
1056 	/* AP mode */
1057 	.change_beacon = wil_cfg80211_change_beacon,
1058 	.start_ap = wil_cfg80211_start_ap,
1059 	.stop_ap = wil_cfg80211_stop_ap,
1060 	.del_station = wil_cfg80211_del_station,
1061 	.probe_client = wil_cfg80211_probe_client,
1062 	.change_bss = wil_cfg80211_change_bss,
1063 };
1064 
1065 static void wil_wiphy_init(struct wiphy *wiphy)
1066 {
1067 	wiphy->max_scan_ssids = 1;
1068 	wiphy->max_scan_ie_len = WMI_MAX_IE_LEN;
1069 	wiphy->max_num_pmkids = 0 /* TODO: */;
1070 	wiphy->interface_modes = BIT(NL80211_IFTYPE_STATION) |
1071 				 BIT(NL80211_IFTYPE_AP) |
1072 				 BIT(NL80211_IFTYPE_MONITOR);
1073 	/* TODO: enable P2P when integrated with supplicant:
1074 	 * BIT(NL80211_IFTYPE_P2P_CLIENT) | BIT(NL80211_IFTYPE_P2P_GO)
1075 	 */
1076 	wiphy->flags |= WIPHY_FLAG_HAVE_AP_SME |
1077 			WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD;
1078 	dev_dbg(wiphy_dev(wiphy), "%s : flags = 0x%08x\n",
1079 		__func__, wiphy->flags);
1080 	wiphy->probe_resp_offload =
1081 		NL80211_PROBE_RESP_OFFLOAD_SUPPORT_WPS |
1082 		NL80211_PROBE_RESP_OFFLOAD_SUPPORT_WPS2 |
1083 		NL80211_PROBE_RESP_OFFLOAD_SUPPORT_P2P;
1084 
1085 	wiphy->bands[IEEE80211_BAND_60GHZ] = &wil_band_60ghz;
1086 
1087 	/* TODO: figure this out */
1088 	wiphy->signal_type = CFG80211_SIGNAL_TYPE_UNSPEC;
1089 
1090 	wiphy->cipher_suites = wil_cipher_suites;
1091 	wiphy->n_cipher_suites = ARRAY_SIZE(wil_cipher_suites);
1092 	wiphy->mgmt_stypes = wil_mgmt_stypes;
1093 	wiphy->features |= NL80211_FEATURE_SK_TX_STATUS;
1094 }
1095 
1096 struct wireless_dev *wil_cfg80211_init(struct device *dev)
1097 {
1098 	int rc = 0;
1099 	struct wireless_dev *wdev;
1100 
1101 	dev_dbg(dev, "%s()\n", __func__);
1102 
1103 	wdev = kzalloc(sizeof(*wdev), GFP_KERNEL);
1104 	if (!wdev)
1105 		return ERR_PTR(-ENOMEM);
1106 
1107 	wdev->wiphy = wiphy_new(&wil_cfg80211_ops,
1108 				sizeof(struct wil6210_priv));
1109 	if (!wdev->wiphy) {
1110 		rc = -ENOMEM;
1111 		goto out;
1112 	}
1113 
1114 	set_wiphy_dev(wdev->wiphy, dev);
1115 	wil_wiphy_init(wdev->wiphy);
1116 
1117 	rc = wiphy_register(wdev->wiphy);
1118 	if (rc < 0)
1119 		goto out_failed_reg;
1120 
1121 	return wdev;
1122 
1123 out_failed_reg:
1124 	wiphy_free(wdev->wiphy);
1125 out:
1126 	kfree(wdev);
1127 
1128 	return ERR_PTR(rc);
1129 }
1130 
1131 void wil_wdev_free(struct wil6210_priv *wil)
1132 {
1133 	struct wireless_dev *wdev = wil_to_wdev(wil);
1134 
1135 	dev_dbg(wil_to_dev(wil), "%s()\n", __func__);
1136 
1137 	if (!wdev)
1138 		return;
1139 
1140 	wiphy_unregister(wdev->wiphy);
1141 	wiphy_free(wdev->wiphy);
1142 	kfree(wdev);
1143 }
1144