1 // SPDX-License-Identifier: ISC
2 /* Copyright (C) 2020 MediaTek Inc. */
3 
4 #include <linux/firmware.h>
5 #include <linux/fs.h>
6 #include "mt7915.h"
7 #include "mcu.h"
8 #include "mac.h"
9 #include "eeprom.h"
10 
11 struct mt7915_patch_hdr {
12 	char build_date[16];
13 	char platform[4];
14 	__be32 hw_sw_ver;
15 	__be32 patch_ver;
16 	__be16 checksum;
17 	u16 reserved;
18 	struct {
19 		__be32 patch_ver;
20 		__be32 subsys;
21 		__be32 feature;
22 		__be32 n_region;
23 		__be32 crc;
24 		u32 reserved[11];
25 	} desc;
26 } __packed;
27 
28 struct mt7915_patch_sec {
29 	__be32 type;
30 	__be32 offs;
31 	__be32 size;
32 	union {
33 		__be32 spec[13];
34 		struct {
35 			__be32 addr;
36 			__be32 len;
37 			__be32 sec_key_idx;
38 			__be32 align_len;
39 			u32 reserved[9];
40 		} info;
41 	};
42 } __packed;
43 
44 struct mt7915_fw_trailer {
45 	u8 chip_id;
46 	u8 eco_code;
47 	u8 n_region;
48 	u8 format_ver;
49 	u8 format_flag;
50 	u8 reserved[2];
51 	char fw_ver[10];
52 	char build_date[15];
53 	u32 crc;
54 } __packed;
55 
56 struct mt7915_fw_region {
57 	__le32 decomp_crc;
58 	__le32 decomp_len;
59 	__le32 decomp_blk_sz;
60 	u8 reserved[4];
61 	__le32 addr;
62 	__le32 len;
63 	u8 feature_set;
64 	u8 reserved1[15];
65 } __packed;
66 
67 #define MCU_PATCH_ADDRESS		0x200000
68 
69 #define MT_STA_BFER			BIT(0)
70 #define MT_STA_BFEE			BIT(1)
71 
72 #define FW_FEATURE_SET_ENCRYPT		BIT(0)
73 #define FW_FEATURE_SET_KEY_IDX		GENMASK(2, 1)
74 #define FW_FEATURE_OVERRIDE_ADDR	BIT(5)
75 
76 #define DL_MODE_ENCRYPT			BIT(0)
77 #define DL_MODE_KEY_IDX			GENMASK(2, 1)
78 #define DL_MODE_RESET_SEC_IV		BIT(3)
79 #define DL_MODE_WORKING_PDA_CR4		BIT(4)
80 #define DL_MODE_NEED_RSP		BIT(31)
81 
82 #define FW_START_OVERRIDE		BIT(0)
83 #define FW_START_WORKING_PDA_CR4	BIT(2)
84 
85 #define PATCH_SEC_TYPE_MASK		GENMASK(15, 0)
86 #define PATCH_SEC_TYPE_INFO		0x2
87 
88 #define to_wcid_lo(id)			FIELD_GET(GENMASK(7, 0), (u16)id)
89 #define to_wcid_hi(id)			FIELD_GET(GENMASK(9, 8), (u16)id)
90 
91 #define HE_PHY(p, c)			u8_get_bits(c, IEEE80211_HE_PHY_##p)
92 #define HE_MAC(m, c)			u8_get_bits(c, IEEE80211_HE_MAC_##m)
93 
94 static enum mt7915_cipher_type
95 mt7915_mcu_get_cipher(int cipher)
96 {
97 	switch (cipher) {
98 	case WLAN_CIPHER_SUITE_WEP40:
99 		return MT_CIPHER_WEP40;
100 	case WLAN_CIPHER_SUITE_WEP104:
101 		return MT_CIPHER_WEP104;
102 	case WLAN_CIPHER_SUITE_TKIP:
103 		return MT_CIPHER_TKIP;
104 	case WLAN_CIPHER_SUITE_AES_CMAC:
105 		return MT_CIPHER_BIP_CMAC_128;
106 	case WLAN_CIPHER_SUITE_CCMP:
107 		return MT_CIPHER_AES_CCMP;
108 	case WLAN_CIPHER_SUITE_CCMP_256:
109 		return MT_CIPHER_CCMP_256;
110 	case WLAN_CIPHER_SUITE_GCMP:
111 		return MT_CIPHER_GCMP;
112 	case WLAN_CIPHER_SUITE_GCMP_256:
113 		return MT_CIPHER_GCMP_256;
114 	case WLAN_CIPHER_SUITE_SMS4:
115 		return MT_CIPHER_WAPI;
116 	default:
117 		return MT_CIPHER_NONE;
118 	}
119 }
120 
121 static u8 mt7915_mcu_chan_bw(struct cfg80211_chan_def *chandef)
122 {
123 	static const u8 width_to_bw[] = {
124 		[NL80211_CHAN_WIDTH_40] = CMD_CBW_40MHZ,
125 		[NL80211_CHAN_WIDTH_80] = CMD_CBW_80MHZ,
126 		[NL80211_CHAN_WIDTH_80P80] = CMD_CBW_8080MHZ,
127 		[NL80211_CHAN_WIDTH_160] = CMD_CBW_160MHZ,
128 		[NL80211_CHAN_WIDTH_5] = CMD_CBW_5MHZ,
129 		[NL80211_CHAN_WIDTH_10] = CMD_CBW_10MHZ,
130 		[NL80211_CHAN_WIDTH_20] = CMD_CBW_20MHZ,
131 		[NL80211_CHAN_WIDTH_20_NOHT] = CMD_CBW_20MHZ,
132 	};
133 
134 	if (chandef->width >= ARRAY_SIZE(width_to_bw))
135 		return 0;
136 
137 	return width_to_bw[chandef->width];
138 }
139 
140 static const struct ieee80211_sta_he_cap *
141 mt7915_get_he_phy_cap(struct mt7915_phy *phy, struct ieee80211_vif *vif)
142 {
143 	struct ieee80211_supported_band *sband;
144 	enum nl80211_band band;
145 
146 	band = phy->mt76->chandef.chan->band;
147 	sband = phy->mt76->hw->wiphy->bands[band];
148 
149 	return ieee80211_get_he_iftype_cap(sband, vif->type);
150 }
151 
152 static u8
153 mt7915_get_phy_mode(struct mt7915_dev *dev, struct ieee80211_vif *vif,
154 		    enum nl80211_band band, struct ieee80211_sta *sta)
155 {
156 	struct ieee80211_sta_ht_cap *ht_cap;
157 	struct ieee80211_sta_vht_cap *vht_cap;
158 	const struct ieee80211_sta_he_cap *he_cap;
159 	u8 mode = 0;
160 
161 	if (sta) {
162 		ht_cap = &sta->ht_cap;
163 		vht_cap = &sta->vht_cap;
164 		he_cap = &sta->he_cap;
165 	} else {
166 		struct ieee80211_supported_band *sband;
167 		struct mt7915_phy *phy;
168 		struct mt7915_vif *mvif;
169 
170 		mvif = (struct mt7915_vif *)vif->drv_priv;
171 		phy = mvif->band_idx ? mt7915_ext_phy(dev) : &dev->phy;
172 		sband = phy->mt76->hw->wiphy->bands[band];
173 
174 		ht_cap = &sband->ht_cap;
175 		vht_cap = &sband->vht_cap;
176 		he_cap = ieee80211_get_he_iftype_cap(sband, vif->type);
177 	}
178 
179 	if (band == NL80211_BAND_2GHZ) {
180 		mode |= PHY_MODE_B | PHY_MODE_G;
181 
182 		if (ht_cap->ht_supported)
183 			mode |= PHY_MODE_GN;
184 
185 		if (he_cap->has_he)
186 			mode |= PHY_MODE_AX_24G;
187 	} else if (band == NL80211_BAND_5GHZ) {
188 		mode |= PHY_MODE_A;
189 
190 		if (ht_cap->ht_supported)
191 			mode |= PHY_MODE_AN;
192 
193 		if (vht_cap->vht_supported)
194 			mode |= PHY_MODE_AC;
195 
196 		if (he_cap->has_he)
197 			mode |= PHY_MODE_AX_5G;
198 	}
199 
200 	return mode;
201 }
202 
203 static u8
204 mt7915_mcu_get_sta_nss(u16 mcs_map)
205 {
206 	u8 nss;
207 
208 	for (nss = 8; nss > 0; nss--) {
209 		u8 nss_mcs = (mcs_map >> (2 * (nss - 1))) & 3;
210 
211 		if (nss_mcs != IEEE80211_VHT_MCS_NOT_SUPPORTED)
212 			break;
213 	}
214 
215 	return nss - 1;
216 }
217 
218 static int __mt7915_mcu_msg_send(struct mt7915_dev *dev, struct sk_buff *skb,
219 				 int cmd, int *wait_seq)
220 {
221 	struct mt7915_mcu_txd *mcu_txd;
222 	u8 seq, pkt_fmt, qidx;
223 	enum mt76_txq_id txq;
224 	__le32 *txd;
225 	u32 val;
226 
227 	seq = ++dev->mt76.mcu.msg_seq & 0xf;
228 	if (!seq)
229 		seq = ++dev->mt76.mcu.msg_seq & 0xf;
230 
231 	if (cmd == -MCU_CMD_FW_SCATTER) {
232 		txq = MT_TXQ_FWDL;
233 		goto exit;
234 	}
235 
236 	mcu_txd = (struct mt7915_mcu_txd *)skb_push(skb, sizeof(*mcu_txd));
237 
238 	if (test_bit(MT76_STATE_MCU_RUNNING, &dev->mphy.state)) {
239 		txq = MT_TXQ_MCU_WA;
240 		qidx = MT_TX_MCU_PORT_RX_Q0;
241 		pkt_fmt = MT_TX_TYPE_CMD;
242 	} else {
243 		txq = MT_TXQ_MCU;
244 		qidx = MT_TX_MCU_PORT_RX_Q0;
245 		pkt_fmt = MT_TX_TYPE_CMD;
246 	}
247 
248 	txd = mcu_txd->txd;
249 
250 	val = FIELD_PREP(MT_TXD0_TX_BYTES, skb->len) |
251 	      FIELD_PREP(MT_TXD0_PKT_FMT, pkt_fmt) |
252 	      FIELD_PREP(MT_TXD0_Q_IDX, qidx);
253 	txd[0] = cpu_to_le32(val);
254 
255 	val = MT_TXD1_LONG_FORMAT |
256 	      FIELD_PREP(MT_TXD1_HDR_FORMAT, MT_HDR_FORMAT_CMD);
257 	txd[1] = cpu_to_le32(val);
258 
259 	mcu_txd->len = cpu_to_le16(skb->len - sizeof(mcu_txd->txd));
260 	mcu_txd->pq_id = cpu_to_le16(MCU_PQ_ID(MT_TX_PORT_IDX_MCU, qidx));
261 	mcu_txd->pkt_type = MCU_PKT_ID;
262 	mcu_txd->seq = seq;
263 
264 	if (cmd < 0) {
265 		mcu_txd->set_query = MCU_Q_NA;
266 		mcu_txd->cid = -cmd;
267 	} else {
268 		mcu_txd->cid = MCU_CMD_EXT_CID;
269 		mcu_txd->ext_cid = cmd;
270 		mcu_txd->ext_cid_ack = 1;
271 
272 		/* do not use Q_SET for efuse */
273 		if (cmd == MCU_EXT_CMD_EFUSE_ACCESS)
274 			mcu_txd->set_query = MCU_Q_QUERY;
275 		else
276 			mcu_txd->set_query = MCU_Q_SET;
277 	}
278 
279 	mcu_txd->s2d_index = MCU_S2D_H2N;
280 	WARN_ON(cmd == MCU_EXT_CMD_EFUSE_ACCESS &&
281 		mcu_txd->set_query != MCU_Q_QUERY);
282 
283 exit:
284 	if (wait_seq)
285 		*wait_seq = seq;
286 
287 	return mt76_tx_queue_skb_raw(dev, txq, skb, 0);
288 }
289 
290 static int
291 mt7915_mcu_parse_eeprom(struct mt7915_dev *dev, struct sk_buff *skb)
292 {
293 	struct mt7915_mcu_eeprom_info *res;
294 	u8 *buf;
295 
296 	if (!skb)
297 		return -EINVAL;
298 
299 	skb_pull(skb, sizeof(struct mt7915_mcu_rxd));
300 
301 	res = (struct mt7915_mcu_eeprom_info *)skb->data;
302 	buf = dev->mt76.eeprom.data + le32_to_cpu(res->addr);
303 	memcpy(buf, res->data, 16);
304 
305 	return 0;
306 }
307 
308 static int
309 mt7915_mcu_parse_response(struct mt7915_dev *dev, int cmd,
310 			  struct sk_buff *skb, int seq)
311 {
312 	struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
313 	int ret = 0;
314 
315 	if (seq != rxd->seq)
316 		return -EAGAIN;
317 
318 	switch (cmd) {
319 	case -MCU_CMD_PATCH_SEM_CONTROL:
320 		skb_pull(skb, sizeof(*rxd) - 4);
321 		ret = *skb->data;
322 		break;
323 	case MCU_EXT_CMD_THERMAL_CTRL:
324 		skb_pull(skb, sizeof(*rxd) + 4);
325 		ret = le32_to_cpu(*(__le32 *)skb->data);
326 		break;
327 	case MCU_EXT_CMD_EFUSE_ACCESS:
328 		ret = mt7915_mcu_parse_eeprom(dev, skb);
329 		break;
330 	default:
331 		break;
332 	}
333 	dev_kfree_skb(skb);
334 
335 	return ret;
336 }
337 
338 static int
339 mt7915_mcu_wait_response(struct mt7915_dev *dev, int cmd, int seq)
340 {
341 	unsigned long expires = jiffies + 20 * HZ;
342 	struct sk_buff *skb;
343 	int ret = 0;
344 
345 	while (true) {
346 		skb = mt76_mcu_get_response(&dev->mt76, expires);
347 		if (!skb) {
348 			dev_err(dev->mt76.dev, "Message %d (seq %d) timeout\n",
349 				cmd, seq);
350 			return -ETIMEDOUT;
351 		}
352 
353 		ret = mt7915_mcu_parse_response(dev, cmd, skb, seq);
354 		if (ret != -EAGAIN)
355 			break;
356 	}
357 
358 	return ret;
359 }
360 
361 static int
362 mt7915_mcu_send_message(struct mt76_dev *mdev, struct sk_buff *skb,
363 			int cmd, bool wait_resp)
364 {
365 	struct mt7915_dev *dev = container_of(mdev, struct mt7915_dev, mt76);
366 	int ret, seq;
367 
368 	mutex_lock(&mdev->mcu.mutex);
369 
370 	ret = __mt7915_mcu_msg_send(dev, skb, cmd, &seq);
371 	if (ret)
372 		goto out;
373 
374 	if (wait_resp)
375 		ret = mt7915_mcu_wait_response(dev, cmd, seq);
376 
377 out:
378 	mutex_unlock(&mdev->mcu.mutex);
379 
380 	return ret;
381 }
382 
383 static int
384 mt7915_mcu_msg_send(struct mt76_dev *mdev, int cmd, const void *data,
385 		    int len, bool wait_resp)
386 {
387 	struct sk_buff *skb;
388 
389 	skb = mt76_mcu_msg_alloc(mdev, data, len);
390 	if (!skb)
391 		return -ENOMEM;
392 
393 	return __mt76_mcu_skb_send_msg(mdev, skb, cmd, wait_resp);
394 }
395 
396 static void
397 mt7915_mcu_csa_finish(void *priv, u8 *mac, struct ieee80211_vif *vif)
398 {
399 	if (vif->csa_active)
400 		ieee80211_csa_finish(vif);
401 }
402 
403 static void
404 mt7915_mcu_rx_radar_detected(struct mt7915_dev *dev, struct sk_buff *skb)
405 {
406 	struct mt76_phy *mphy = &dev->mt76.phy;
407 	struct mt7915_mcu_rdd_report *r;
408 
409 	r = (struct mt7915_mcu_rdd_report *)skb->data;
410 
411 	if (r->idx && dev->mt76.phy2)
412 		mphy = dev->mt76.phy2;
413 
414 	ieee80211_radar_detected(mphy->hw);
415 	dev->hw_pattern++;
416 }
417 
418 static void
419 mt7915_mcu_tx_rate_cal(struct mt76_phy *mphy, struct mt7915_mcu_ra_info *ra,
420 		       struct rate_info *rate, u16 r)
421 {
422 	struct ieee80211_supported_band *sband;
423 	u16 ru_idx = le16_to_cpu(ra->ru_idx);
424 	u16 flags = 0;
425 
426 	rate->mcs = FIELD_GET(MT_RA_RATE_MCS, r);
427 	rate->nss = FIELD_GET(MT_RA_RATE_NSS, r) + 1;
428 
429 	switch (FIELD_GET(MT_RA_RATE_TX_MODE, r)) {
430 	case MT_PHY_TYPE_CCK:
431 	case MT_PHY_TYPE_OFDM:
432 		if (mphy->chandef.chan->band == NL80211_BAND_5GHZ)
433 			sband = &mphy->sband_5g.sband;
434 		else
435 			sband = &mphy->sband_2g.sband;
436 
437 		rate->legacy = sband->bitrates[rate->mcs].bitrate;
438 		break;
439 	case MT_PHY_TYPE_HT:
440 	case MT_PHY_TYPE_HT_GF:
441 		rate->mcs += (rate->nss - 1) * 8;
442 		flags |= RATE_INFO_FLAGS_MCS;
443 
444 		if (ra->gi)
445 			flags |= RATE_INFO_FLAGS_SHORT_GI;
446 		break;
447 	case MT_PHY_TYPE_VHT:
448 		flags |= RATE_INFO_FLAGS_VHT_MCS;
449 
450 		if (ra->gi)
451 			flags |= RATE_INFO_FLAGS_SHORT_GI;
452 		break;
453 	case MT_PHY_TYPE_HE_SU:
454 	case MT_PHY_TYPE_HE_EXT_SU:
455 	case MT_PHY_TYPE_HE_TB:
456 	case MT_PHY_TYPE_HE_MU:
457 		rate->he_gi = ra->gi;
458 		rate->he_dcm = FIELD_GET(MT_RA_RATE_DCM_EN, r);
459 
460 		flags |= RATE_INFO_FLAGS_HE_MCS;
461 		break;
462 	default:
463 		break;
464 	}
465 	rate->flags = flags;
466 
467 	if (ru_idx) {
468 		switch (ru_idx) {
469 		case 1 ... 2:
470 			rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_996;
471 			break;
472 		case 3 ... 6:
473 			rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_484;
474 			break;
475 		case 7 ... 14:
476 			rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_242;
477 			break;
478 		default:
479 			rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_106;
480 			break;
481 		}
482 		rate->bw = RATE_INFO_BW_HE_RU;
483 	} else {
484 		u8 bw = mt7915_mcu_chan_bw(&mphy->chandef) -
485 			FIELD_GET(MT_RA_RATE_BW, r);
486 
487 		switch (bw) {
488 		case IEEE80211_STA_RX_BW_160:
489 			rate->bw = RATE_INFO_BW_160;
490 			break;
491 		case IEEE80211_STA_RX_BW_80:
492 			rate->bw = RATE_INFO_BW_80;
493 			break;
494 		case IEEE80211_STA_RX_BW_40:
495 			rate->bw = RATE_INFO_BW_40;
496 			break;
497 		default:
498 			rate->bw = RATE_INFO_BW_20;
499 			break;
500 		}
501 	}
502 }
503 
504 static void
505 mt7915_mcu_tx_rate_report(struct mt7915_dev *dev, struct sk_buff *skb)
506 {
507 	struct mt7915_mcu_ra_info *ra = (struct mt7915_mcu_ra_info *)skb->data;
508 	u16 wcidx = le16_to_cpu(ra->wlan_idx);
509 	struct mt76_wcid *wcid = rcu_dereference(dev->mt76.wcid[wcidx]);
510 	struct mt7915_sta *msta = container_of(wcid, struct mt7915_sta, wcid);
511 	struct mt7915_sta_stats *stats = &msta->stats;
512 	struct mt76_phy *mphy = &dev->mphy;
513 	struct rate_info rate = {}, prob_rate = {};
514 	u16 attempts = le16_to_cpu(ra->attempts);
515 	u16 curr = le16_to_cpu(ra->curr_rate);
516 	u16 probe = le16_to_cpu(ra->prob_up_rate);
517 
518 	if (msta->wcid.ext_phy && dev->mt76.phy2)
519 		mphy = dev->mt76.phy2;
520 
521 	/* current rate */
522 	mt7915_mcu_tx_rate_cal(mphy, ra, &rate, curr);
523 	stats->tx_rate = rate;
524 
525 	/* probing rate */
526 	mt7915_mcu_tx_rate_cal(mphy, ra, &prob_rate, probe);
527 	stats->prob_rate = prob_rate;
528 
529 	if (attempts) {
530 		u16 success = le16_to_cpu(ra->success);
531 
532 		stats->per = 1000 * (attempts - success) / attempts;
533 	}
534 }
535 
536 static void
537 mt7915_mcu_rx_log_message(struct mt7915_dev *dev, struct sk_buff *skb)
538 {
539 	struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
540 	const char *data = (char *)&rxd[1];
541 	const char *type;
542 
543 	switch (rxd->s2d_index) {
544 	case 0:
545 		type = "WM";
546 		break;
547 	case 2:
548 		type = "WA";
549 		break;
550 	default:
551 		type = "unknown";
552 		break;
553 	}
554 
555 	wiphy_info(mt76_hw(dev)->wiphy, "%s: %s", type, data);
556 }
557 
558 static void
559 mt7915_mcu_rx_ext_event(struct mt7915_dev *dev, struct sk_buff *skb)
560 {
561 	struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
562 
563 	switch (rxd->ext_eid) {
564 	case MCU_EXT_EVENT_RDD_REPORT:
565 		mt7915_mcu_rx_radar_detected(dev, skb);
566 		break;
567 	case MCU_EXT_EVENT_CSA_NOTIFY:
568 		ieee80211_iterate_active_interfaces_atomic(dev->mt76.hw,
569 				IEEE80211_IFACE_ITER_RESUME_ALL,
570 				mt7915_mcu_csa_finish, dev);
571 		break;
572 	case MCU_EXT_EVENT_RATE_REPORT:
573 		mt7915_mcu_tx_rate_report(dev, skb);
574 		break;
575 	case MCU_EXT_EVENT_FW_LOG_2_HOST:
576 		mt7915_mcu_rx_log_message(dev, skb);
577 		break;
578 	default:
579 		break;
580 	}
581 }
582 
583 static void
584 mt7915_mcu_rx_unsolicited_event(struct mt7915_dev *dev, struct sk_buff *skb)
585 {
586 	struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
587 
588 	switch (rxd->eid) {
589 	case MCU_EVENT_EXT:
590 		mt7915_mcu_rx_ext_event(dev, skb);
591 		break;
592 	default:
593 		break;
594 	}
595 	dev_kfree_skb(skb);
596 }
597 
598 void mt7915_mcu_rx_event(struct mt7915_dev *dev, struct sk_buff *skb)
599 {
600 	struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
601 
602 	if (rxd->ext_eid == MCU_EXT_EVENT_THERMAL_PROTECT ||
603 	    rxd->ext_eid == MCU_EXT_EVENT_FW_LOG_2_HOST ||
604 	    rxd->ext_eid == MCU_EXT_EVENT_ASSERT_DUMP ||
605 	    rxd->ext_eid == MCU_EXT_EVENT_PS_SYNC ||
606 	    rxd->ext_eid == MCU_EXT_EVENT_RATE_REPORT ||
607 	    !rxd->seq)
608 		mt7915_mcu_rx_unsolicited_event(dev, skb);
609 	else
610 		mt76_mcu_rx_event(&dev->mt76, skb);
611 }
612 
613 static struct sk_buff *
614 mt7915_mcu_alloc_sta_req(struct mt7915_dev *dev, struct mt7915_vif *mvif,
615 			 struct mt7915_sta *msta, int len)
616 {
617 	struct sta_req_hdr hdr = {
618 		.bss_idx = mvif->idx,
619 		.wlan_idx_lo = msta ? to_wcid_lo(msta->wcid.idx) : 0,
620 		.wlan_idx_hi = msta ? to_wcid_hi(msta->wcid.idx) : 0,
621 		.muar_idx = msta ? mvif->omac_idx : 0,
622 		.is_tlv_append = 1,
623 	};
624 	struct sk_buff *skb;
625 
626 	skb = mt76_mcu_msg_alloc(&dev->mt76, NULL, len);
627 	if (!skb)
628 		return ERR_PTR(-ENOMEM);
629 
630 	skb_put_data(skb, &hdr, sizeof(hdr));
631 
632 	return skb;
633 }
634 
635 static struct wtbl_req_hdr *
636 mt7915_mcu_alloc_wtbl_req(struct mt7915_dev *dev, struct mt7915_sta *msta,
637 			  int cmd, void *sta_wtbl, struct sk_buff **skb)
638 {
639 	struct tlv *sta_hdr = sta_wtbl;
640 	struct wtbl_req_hdr hdr = {
641 		.wlan_idx_lo = to_wcid_lo(msta->wcid.idx),
642 		.wlan_idx_hi = to_wcid_hi(msta->wcid.idx),
643 		.operation = cmd,
644 	};
645 	struct sk_buff *nskb = *skb;
646 
647 	if (!nskb) {
648 		nskb = mt76_mcu_msg_alloc(&dev->mt76, NULL,
649 					  MT7915_WTBL_UPDATE_BA_SIZE);
650 		if (!nskb)
651 			return ERR_PTR(-ENOMEM);
652 
653 		*skb = nskb;
654 	}
655 
656 	if (sta_hdr)
657 		sta_hdr->len = cpu_to_le16(sizeof(hdr));
658 
659 	return skb_put_data(nskb, &hdr, sizeof(hdr));
660 }
661 
662 static struct tlv *
663 mt7915_mcu_add_nested_tlv(struct sk_buff *skb, int tag, int len,
664 			  void *sta_ntlv, void *sta_wtbl)
665 {
666 	struct sta_ntlv_hdr *ntlv_hdr = sta_ntlv;
667 	struct tlv *sta_hdr = sta_wtbl;
668 	struct tlv *ptlv, tlv = {
669 		.tag = cpu_to_le16(tag),
670 		.len = cpu_to_le16(len),
671 	};
672 	u16 ntlv;
673 
674 	ptlv = skb_put(skb, len);
675 	memcpy(ptlv, &tlv, sizeof(tlv));
676 
677 	ntlv = le16_to_cpu(ntlv_hdr->tlv_num);
678 	ntlv_hdr->tlv_num = cpu_to_le16(ntlv + 1);
679 
680 	if (sta_hdr) {
681 		u16 size = le16_to_cpu(sta_hdr->len);
682 
683 		sta_hdr->len = cpu_to_le16(size + len);
684 	}
685 
686 	return ptlv;
687 }
688 
689 static struct tlv *
690 mt7915_mcu_add_tlv(struct sk_buff *skb, int tag, int len)
691 {
692 	return mt7915_mcu_add_nested_tlv(skb, tag, len, skb->data, NULL);
693 }
694 
695 static struct tlv *
696 mt7915_mcu_add_nested_subtlv(struct sk_buff *skb, int sub_tag, int sub_len,
697 			     __le16 *sub_ntlv, __le16 *len)
698 {
699 	struct tlv *ptlv, tlv = {
700 		.tag = cpu_to_le16(sub_tag),
701 		.len = cpu_to_le16(sub_len),
702 	};
703 
704 	ptlv = skb_put(skb, sub_len);
705 	memcpy(ptlv, &tlv, sizeof(tlv));
706 
707 	*sub_ntlv = cpu_to_le16(le16_to_cpu(*sub_ntlv) + 1);
708 	*len = cpu_to_le16(le16_to_cpu(*len) + sub_len);
709 
710 	return ptlv;
711 }
712 
713 /** bss info **/
714 static int
715 mt7915_mcu_bss_basic_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
716 			 struct mt7915_phy *phy, bool enable)
717 {
718 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
719 	struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
720 	enum nl80211_band band = chandef->chan->band;
721 	struct bss_info_basic *bss;
722 	u16 wlan_idx = mvif->sta.wcid.idx;
723 	u32 type = NETWORK_INFRA;
724 	struct tlv *tlv;
725 
726 	tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_BASIC, sizeof(*bss));
727 
728 	switch (vif->type) {
729 	case NL80211_IFTYPE_MESH_POINT:
730 	case NL80211_IFTYPE_AP:
731 		break;
732 	case NL80211_IFTYPE_STATION:
733 		/* TODO: enable BSS_INFO_UAPSD & BSS_INFO_PM */
734 		if (enable) {
735 			struct ieee80211_sta *sta;
736 			struct mt7915_sta *msta;
737 
738 			rcu_read_lock();
739 			sta = ieee80211_find_sta(vif, vif->bss_conf.bssid);
740 			if (!sta) {
741 				rcu_read_unlock();
742 				return -EINVAL;
743 			}
744 
745 			msta = (struct mt7915_sta *)sta->drv_priv;
746 			wlan_idx = msta->wcid.idx;
747 			rcu_read_unlock();
748 		}
749 		break;
750 	case NL80211_IFTYPE_ADHOC:
751 		type = NETWORK_IBSS;
752 		break;
753 	default:
754 		WARN_ON(1);
755 		break;
756 	}
757 
758 	bss = (struct bss_info_basic *)tlv;
759 	memcpy(bss->bssid, vif->bss_conf.bssid, ETH_ALEN);
760 	bss->bcn_interval = cpu_to_le16(vif->bss_conf.beacon_int);
761 	bss->network_type = cpu_to_le32(type);
762 	bss->dtim_period = vif->bss_conf.dtim_period;
763 	bss->bmc_wcid_lo = to_wcid_lo(wlan_idx);
764 	bss->bmc_wcid_hi = to_wcid_hi(wlan_idx);
765 	bss->phy_mode = mt7915_get_phy_mode(phy->dev, vif, band, NULL);
766 	bss->wmm_idx = mvif->wmm_idx;
767 	bss->active = enable;
768 
769 	return 0;
770 }
771 
772 static void
773 mt7915_mcu_bss_omac_tlv(struct sk_buff *skb, struct ieee80211_vif *vif)
774 {
775 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
776 	struct bss_info_omac *omac;
777 	struct tlv *tlv;
778 	u32 type = 0;
779 	u8 idx;
780 
781 	tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_OMAC, sizeof(*omac));
782 
783 	switch (vif->type) {
784 	case NL80211_IFTYPE_MESH_POINT:
785 	case NL80211_IFTYPE_AP:
786 		type = CONNECTION_INFRA_AP;
787 		break;
788 	case NL80211_IFTYPE_STATION:
789 		type = CONNECTION_INFRA_STA;
790 		break;
791 	case NL80211_IFTYPE_ADHOC:
792 		type = CONNECTION_IBSS_ADHOC;
793 		break;
794 	default:
795 		WARN_ON(1);
796 		break;
797 	}
798 
799 	omac = (struct bss_info_omac *)tlv;
800 	idx = mvif->omac_idx > EXT_BSSID_START ? HW_BSSID_0 : mvif->omac_idx;
801 	omac->conn_type = cpu_to_le32(type);
802 	omac->omac_idx = mvif->omac_idx;
803 	omac->band_idx = mvif->band_idx;
804 	omac->hw_bss_idx = idx;
805 }
806 
807 struct mt7915_he_obss_narrow_bw_ru_data {
808 	bool tolerated;
809 };
810 
811 static void mt7915_check_he_obss_narrow_bw_ru_iter(struct wiphy *wiphy,
812 						   struct cfg80211_bss *bss,
813 						   void *_data)
814 {
815 	struct mt7915_he_obss_narrow_bw_ru_data *data = _data;
816 	const struct element *elem;
817 
818 	elem = ieee80211_bss_get_elem(bss, WLAN_EID_EXT_CAPABILITY);
819 
820 	if (!elem || elem->datalen < 10 ||
821 	    !(elem->data[10] &
822 	      WLAN_EXT_CAPA10_OBSS_NARROW_BW_RU_TOLERANCE_SUPPORT))
823 		data->tolerated = false;
824 }
825 
826 static bool mt7915_check_he_obss_narrow_bw_ru(struct ieee80211_hw *hw,
827 					      struct ieee80211_vif *vif)
828 {
829 	struct mt7915_he_obss_narrow_bw_ru_data iter_data = {
830 		.tolerated = true,
831 	};
832 
833 	if (!(vif->bss_conf.chandef.chan->flags & IEEE80211_CHAN_RADAR))
834 		return false;
835 
836 	cfg80211_bss_iter(hw->wiphy, &vif->bss_conf.chandef,
837 			  mt7915_check_he_obss_narrow_bw_ru_iter,
838 			  &iter_data);
839 
840 	/*
841 	 * If there is at least one AP on radar channel that cannot
842 	 * tolerate 26-tone RU UL OFDMA transmissions using HE TB PPDU.
843 	 */
844 	return !iter_data.tolerated;
845 }
846 
847 static void
848 mt7915_mcu_bss_rfch_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
849 			struct mt7915_phy *phy)
850 {
851 	struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
852 	struct bss_info_rf_ch *ch;
853 	struct tlv *tlv;
854 	int freq1 = chandef->center_freq1;
855 
856 	tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_RF_CH, sizeof(*ch));
857 
858 	ch = (struct bss_info_rf_ch *)tlv;
859 	ch->pri_ch = chandef->chan->hw_value;
860 	ch->center_ch0 = ieee80211_frequency_to_channel(freq1);
861 	ch->bw = mt7915_mcu_chan_bw(chandef);
862 
863 	if (chandef->width == NL80211_CHAN_WIDTH_80P80) {
864 		int freq2 = chandef->center_freq2;
865 
866 		ch->center_ch1 = ieee80211_frequency_to_channel(freq2);
867 	}
868 
869 	if (vif->bss_conf.he_support && vif->type == NL80211_IFTYPE_STATION) {
870 		struct mt7915_dev *dev = phy->dev;
871 		struct mt76_phy *mphy = &dev->mt76.phy;
872 		bool ext_phy = phy != &dev->phy;
873 
874 		if (ext_phy && dev->mt76.phy2)
875 			mphy = dev->mt76.phy2;
876 
877 		ch->he_ru26_block =
878 			mt7915_check_he_obss_narrow_bw_ru(mphy->hw, vif);
879 		ch->he_all_disable = false;
880 	} else {
881 		ch->he_all_disable = true;
882 	}
883 }
884 
885 static void
886 mt7915_mcu_bss_ra_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
887 		      struct mt7915_phy *phy)
888 {
889 	struct bss_info_ra *ra;
890 	struct tlv *tlv;
891 	int max_nss = hweight8(phy->chainmask);
892 
893 	tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_RA, sizeof(*ra));
894 
895 	ra = (struct bss_info_ra *)tlv;
896 	ra->op_mode = vif->type == NL80211_IFTYPE_AP;
897 	ra->adhoc_en = vif->type == NL80211_IFTYPE_ADHOC;
898 	ra->short_preamble = true;
899 	ra->tx_streams = max_nss;
900 	ra->rx_streams = max_nss;
901 	ra->algo = 4;
902 	ra->train_up_rule = 2;
903 	ra->train_up_high_thres = 110;
904 	ra->train_up_rule_rssi = -70;
905 	ra->low_traffic_thres = 2;
906 	ra->phy_cap = cpu_to_le32(0xfdf);
907 	ra->interval = cpu_to_le32(500);
908 	ra->fast_interval = cpu_to_le32(100);
909 }
910 
911 static void
912 mt7915_mcu_bss_he_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
913 		      struct mt7915_phy *phy)
914 {
915 #define DEFAULT_HE_PE_DURATION		4
916 #define DEFAULT_HE_DURATION_RTS_THRES	1023
917 	const struct ieee80211_sta_he_cap *cap;
918 	struct bss_info_he *he;
919 	struct tlv *tlv;
920 
921 	cap = mt7915_get_he_phy_cap(phy, vif);
922 
923 	tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_HE_BASIC, sizeof(*he));
924 
925 	he = (struct bss_info_he *)tlv;
926 	he->he_pe_duration = vif->bss_conf.htc_trig_based_pkt_ext * 4;
927 	if (!he->he_pe_duration)
928 		he->he_pe_duration = DEFAULT_HE_PE_DURATION;
929 
930 	he->he_rts_thres = cpu_to_le16(vif->bss_conf.frame_time_rts_th * 32);
931 	if (!he->he_rts_thres)
932 		he->he_rts_thres = cpu_to_le16(DEFAULT_HE_DURATION_RTS_THRES);
933 
934 	he->max_nss_mcs[CMD_HE_MCS_BW80] = cap->he_mcs_nss_supp.tx_mcs_80;
935 	he->max_nss_mcs[CMD_HE_MCS_BW160] = cap->he_mcs_nss_supp.tx_mcs_160;
936 	he->max_nss_mcs[CMD_HE_MCS_BW8080] = cap->he_mcs_nss_supp.tx_mcs_80p80;
937 }
938 
939 static void
940 mt7915_mcu_bss_ext_tlv(struct sk_buff *skb, struct mt7915_vif *mvif)
941 {
942 /* SIFS 20us + 512 byte beacon tranmitted by 1Mbps (3906us) */
943 #define BCN_TX_ESTIMATE_TIME	(4096 + 20)
944 	struct bss_info_ext_bss *ext;
945 	int ext_bss_idx, tsf_offset;
946 	struct tlv *tlv;
947 
948 	ext_bss_idx = mvif->omac_idx - EXT_BSSID_START;
949 	if (ext_bss_idx < 0)
950 		return;
951 
952 	tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_EXT_BSS, sizeof(*ext));
953 
954 	ext = (struct bss_info_ext_bss *)tlv;
955 	tsf_offset = ext_bss_idx * BCN_TX_ESTIMATE_TIME;
956 	ext->mbss_tsf_offset = cpu_to_le32(tsf_offset);
957 }
958 
959 static void
960 mt7915_mcu_bss_bmc_tlv(struct sk_buff *skb, struct mt7915_phy *phy)
961 {
962 	struct bss_info_bmc_rate *bmc;
963 	struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
964 	enum nl80211_band band = chandef->chan->band;
965 	struct tlv *tlv;
966 
967 	tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_BMC_RATE, sizeof(*bmc));
968 
969 	bmc = (struct bss_info_bmc_rate *)tlv;
970 	if (band == NL80211_BAND_2GHZ) {
971 		bmc->short_preamble = true;
972 	} else {
973 		bmc->bc_trans = cpu_to_le16(0x2000);
974 		bmc->mc_trans = cpu_to_le16(0x2080);
975 	}
976 }
977 
978 static void
979 mt7915_mcu_bss_sync_tlv(struct sk_buff *skb, struct ieee80211_vif *vif)
980 {
981 	struct bss_info_sync_mode *sync;
982 	struct tlv *tlv;
983 
984 	tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_SYNC_MODE, sizeof(*sync));
985 
986 	sync = (struct bss_info_sync_mode *)tlv;
987 	sync->bcn_interval = cpu_to_le16(vif->bss_conf.beacon_int);
988 	sync->dtim_period = vif->bss_conf.dtim_period;
989 	sync->enable = true;
990 }
991 
992 int mt7915_mcu_add_bss_info(struct mt7915_phy *phy,
993 			    struct ieee80211_vif *vif, int enable)
994 {
995 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
996 	struct sk_buff *skb;
997 
998 	skb = mt7915_mcu_alloc_sta_req(phy->dev, mvif, NULL,
999 				       MT7915_BSS_UPDATE_MAX_SIZE);
1000 	if (IS_ERR(skb))
1001 		return PTR_ERR(skb);
1002 
1003 	/* bss_omac must be first */
1004 	if (enable)
1005 		mt7915_mcu_bss_omac_tlv(skb, vif);
1006 
1007 	mt7915_mcu_bss_basic_tlv(skb, vif, phy, enable);
1008 
1009 	if (enable) {
1010 		mt7915_mcu_bss_rfch_tlv(skb, vif, phy);
1011 		mt7915_mcu_bss_bmc_tlv(skb, phy);
1012 		mt7915_mcu_bss_ra_tlv(skb, vif, phy);
1013 
1014 		if (vif->bss_conf.he_support)
1015 			mt7915_mcu_bss_he_tlv(skb, vif, phy);
1016 
1017 		if (mvif->omac_idx > HW_BSSID_MAX)
1018 			mt7915_mcu_bss_ext_tlv(skb, mvif);
1019 		else
1020 			mt7915_mcu_bss_sync_tlv(skb, vif);
1021 	}
1022 
1023 	return __mt76_mcu_skb_send_msg(&phy->dev->mt76, skb,
1024 				       MCU_EXT_CMD_BSS_INFO_UPDATE, true);
1025 }
1026 
1027 /** starec & wtbl **/
1028 static int
1029 mt7915_mcu_sta_key_tlv(struct sk_buff *skb, struct ieee80211_key_conf *key,
1030 		       enum set_key_cmd cmd)
1031 {
1032 	struct sta_rec_sec *sec;
1033 	struct tlv *tlv;
1034 	u32 len = sizeof(*sec);
1035 
1036 	tlv = mt7915_mcu_add_tlv(skb, STA_REC_KEY_V2, sizeof(*sec));
1037 
1038 	sec = (struct sta_rec_sec *)tlv;
1039 	sec->add = cmd;
1040 
1041 	if (cmd == SET_KEY) {
1042 		struct sec_key *sec_key;
1043 		u8 cipher;
1044 
1045 		cipher = mt7915_mcu_get_cipher(key->cipher);
1046 		if (cipher == MT_CIPHER_NONE)
1047 			return -EOPNOTSUPP;
1048 
1049 		sec_key = &sec->key[0];
1050 		sec_key->cipher_len = sizeof(*sec_key);
1051 		sec_key->key_id = key->keyidx;
1052 
1053 		if (cipher == MT_CIPHER_BIP_CMAC_128) {
1054 			sec_key->cipher_id = MT_CIPHER_AES_CCMP;
1055 			sec_key->key_len = 16;
1056 			memcpy(sec_key->key, key->key, 16);
1057 
1058 			sec_key = &sec->key[1];
1059 			sec_key->cipher_id = MT_CIPHER_BIP_CMAC_128;
1060 			sec_key->cipher_len = sizeof(*sec_key);
1061 			sec_key->key_len = 16;
1062 			memcpy(sec_key->key, key->key + 16, 16);
1063 
1064 			sec->n_cipher = 2;
1065 		} else {
1066 			sec_key->cipher_id = cipher;
1067 			sec_key->key_len = key->keylen;
1068 			memcpy(sec_key->key, key->key, key->keylen);
1069 
1070 			if (cipher == MT_CIPHER_TKIP) {
1071 				/* Rx/Tx MIC keys are swapped */
1072 				memcpy(sec_key->key + 16, key->key + 24, 8);
1073 				memcpy(sec_key->key + 24, key->key + 16, 8);
1074 			}
1075 
1076 			len -= sizeof(*sec_key);
1077 			sec->n_cipher = 1;
1078 		}
1079 	} else {
1080 		len -= sizeof(sec->key);
1081 		sec->n_cipher = 0;
1082 	}
1083 	sec->len = cpu_to_le16(len);
1084 
1085 	return 0;
1086 }
1087 
1088 int mt7915_mcu_add_key(struct mt7915_dev *dev, struct ieee80211_vif *vif,
1089 		       struct mt7915_sta *msta, struct ieee80211_key_conf *key,
1090 		       enum set_key_cmd cmd)
1091 {
1092 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1093 	struct sk_buff *skb;
1094 	int len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_sec);
1095 	int ret;
1096 
1097 	skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
1098 	if (IS_ERR(skb))
1099 		return PTR_ERR(skb);
1100 
1101 	ret = mt7915_mcu_sta_key_tlv(skb, key, cmd);
1102 	if (ret)
1103 		return ret;
1104 
1105 	return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1106 				       MCU_EXT_CMD_STA_REC_UPDATE, true);
1107 }
1108 
1109 static void
1110 mt7915_mcu_sta_ba_tlv(struct sk_buff *skb,
1111 		      struct ieee80211_ampdu_params *params,
1112 		      bool enable, bool tx)
1113 {
1114 	struct sta_rec_ba *ba;
1115 	struct tlv *tlv;
1116 
1117 	tlv = mt7915_mcu_add_tlv(skb, STA_REC_BA, sizeof(*ba));
1118 
1119 	ba = (struct sta_rec_ba *)tlv;
1120 	ba->ba_type = tx ? MT_BA_TYPE_ORIGINATOR : MT_BA_TYPE_RECIPIENT,
1121 	ba->winsize = cpu_to_le16(params->buf_size);
1122 	ba->ssn = cpu_to_le16(params->ssn);
1123 	ba->ba_en = enable << params->tid;
1124 	ba->amsdu = params->amsdu;
1125 	ba->tid = params->tid;
1126 }
1127 
1128 static void
1129 mt7915_mcu_wtbl_ba_tlv(struct sk_buff *skb,
1130 		       struct ieee80211_ampdu_params *params,
1131 		       bool enable, bool tx, void *sta_wtbl,
1132 		       void *wtbl_tlv)
1133 {
1134 	struct wtbl_ba *ba;
1135 	struct tlv *tlv;
1136 
1137 	tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_BA, sizeof(*ba),
1138 					wtbl_tlv, sta_wtbl);
1139 
1140 	ba = (struct wtbl_ba *)tlv;
1141 	ba->tid = params->tid;
1142 
1143 	if (tx) {
1144 		ba->ba_type = MT_BA_TYPE_ORIGINATOR;
1145 		ba->sn = enable ? cpu_to_le16(params->ssn) : 0;
1146 		ba->ba_en = enable;
1147 	} else {
1148 		memcpy(ba->peer_addr, params->sta->addr, ETH_ALEN);
1149 		ba->ba_type = MT_BA_TYPE_RECIPIENT;
1150 		ba->rst_ba_tid = params->tid;
1151 		ba->rst_ba_sel = RST_BA_MAC_TID_MATCH;
1152 		ba->rst_ba_sb = 1;
1153 	}
1154 
1155 	if (enable && tx)
1156 		ba->ba_winsize = cpu_to_le16(params->buf_size);
1157 }
1158 
1159 static int
1160 mt7915_mcu_sta_ba(struct mt7915_dev *dev,
1161 		  struct ieee80211_ampdu_params *params,
1162 		  bool enable, bool tx)
1163 {
1164 	struct mt7915_sta *msta = (struct mt7915_sta *)params->sta->drv_priv;
1165 	struct mt7915_vif *mvif = msta->vif;
1166 	struct wtbl_req_hdr *wtbl_hdr;
1167 	struct tlv *sta_wtbl;
1168 	struct sk_buff *skb;
1169 
1170 	skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
1171 				       MT7915_STA_UPDATE_MAX_SIZE);
1172 	if (IS_ERR(skb))
1173 		return PTR_ERR(skb);
1174 
1175 	mt7915_mcu_sta_ba_tlv(skb, params, enable, tx);
1176 	sta_wtbl = mt7915_mcu_add_tlv(skb, STA_REC_WTBL, sizeof(struct tlv));
1177 
1178 	wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_SET, sta_wtbl,
1179 					     &skb);
1180 	mt7915_mcu_wtbl_ba_tlv(skb, params, enable, tx, sta_wtbl, wtbl_hdr);
1181 
1182 	return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1183 				       MCU_EXT_CMD_STA_REC_UPDATE, true);
1184 }
1185 
1186 int mt7915_mcu_add_tx_ba(struct mt7915_dev *dev,
1187 			 struct ieee80211_ampdu_params *params,
1188 			 bool enable)
1189 {
1190 	return mt7915_mcu_sta_ba(dev, params, enable, true);
1191 }
1192 
1193 int mt7915_mcu_add_rx_ba(struct mt7915_dev *dev,
1194 			 struct ieee80211_ampdu_params *params,
1195 			 bool enable)
1196 {
1197 	return mt7915_mcu_sta_ba(dev, params, enable, false);
1198 }
1199 
1200 static void
1201 mt7915_mcu_wtbl_generic_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
1202 			    struct ieee80211_sta *sta, void *sta_wtbl,
1203 			    void *wtbl_tlv)
1204 {
1205 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1206 	struct wtbl_generic *generic;
1207 	struct wtbl_rx *rx;
1208 	struct tlv *tlv;
1209 
1210 	tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_GENERIC, sizeof(*generic),
1211 					wtbl_tlv, sta_wtbl);
1212 
1213 	generic = (struct wtbl_generic *)tlv;
1214 
1215 	if (sta) {
1216 		memcpy(generic->peer_addr, sta->addr, ETH_ALEN);
1217 		generic->partial_aid = cpu_to_le16(sta->aid);
1218 		generic->muar_idx = mvif->omac_idx;
1219 		generic->qos = sta->wme;
1220 	} else {
1221 		/* use BSSID in station mode */
1222 		if (vif->type == NL80211_IFTYPE_STATION)
1223 			memcpy(generic->peer_addr, vif->bss_conf.bssid,
1224 			       ETH_ALEN);
1225 		else
1226 			eth_broadcast_addr(generic->peer_addr);
1227 
1228 		generic->muar_idx = 0xe;
1229 	}
1230 
1231 	tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_RX, sizeof(*rx),
1232 					wtbl_tlv, sta_wtbl);
1233 
1234 	rx = (struct wtbl_rx *)tlv;
1235 	rx->rca1 = sta ? vif->type != NL80211_IFTYPE_AP : 1;
1236 	rx->rca2 = 1;
1237 	rx->rv = 1;
1238 }
1239 
1240 static void
1241 mt7915_mcu_sta_basic_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
1242 			 struct ieee80211_sta *sta, bool enable)
1243 {
1244 #define EXTRA_INFO_VER          BIT(0)
1245 #define EXTRA_INFO_NEW          BIT(1)
1246 	struct sta_rec_basic *basic;
1247 	struct tlv *tlv;
1248 
1249 	tlv = mt7915_mcu_add_tlv(skb, STA_REC_BASIC, sizeof(*basic));
1250 
1251 	basic = (struct sta_rec_basic *)tlv;
1252 	basic->extra_info = cpu_to_le16(EXTRA_INFO_VER);
1253 
1254 	if (enable) {
1255 		basic->extra_info |= cpu_to_le16(EXTRA_INFO_NEW);
1256 		basic->conn_state = CONN_STATE_PORT_SECURE;
1257 	} else {
1258 		basic->conn_state = CONN_STATE_DISCONNECT;
1259 	}
1260 
1261 	if (!sta) {
1262 		basic->conn_type = cpu_to_le32(CONNECTION_INFRA_BC);
1263 		eth_broadcast_addr(basic->peer_addr);
1264 		return;
1265 	}
1266 
1267 	switch (vif->type) {
1268 	case NL80211_IFTYPE_MESH_POINT:
1269 	case NL80211_IFTYPE_AP:
1270 		basic->conn_type = cpu_to_le32(CONNECTION_INFRA_STA);
1271 		break;
1272 	case NL80211_IFTYPE_STATION:
1273 		basic->conn_type = cpu_to_le32(CONNECTION_INFRA_AP);
1274 		break;
1275 	case NL80211_IFTYPE_ADHOC:
1276 		basic->conn_type = cpu_to_le32(CONNECTION_IBSS_ADHOC);
1277 		break;
1278 	default:
1279 		WARN_ON(1);
1280 		break;
1281 	}
1282 
1283 	memcpy(basic->peer_addr, sta->addr, ETH_ALEN);
1284 	basic->aid = cpu_to_le16(sta->aid);
1285 	basic->qos = sta->wme;
1286 }
1287 
1288 static void
1289 mt7915_mcu_sta_he_tlv(struct sk_buff *skb, struct ieee80211_sta *sta)
1290 {
1291 	struct ieee80211_sta_he_cap *he_cap = &sta->he_cap;
1292 	struct ieee80211_he_cap_elem *elem = &he_cap->he_cap_elem;
1293 	struct sta_rec_he *he;
1294 	struct tlv *tlv;
1295 	u32 cap = 0;
1296 
1297 	tlv = mt7915_mcu_add_tlv(skb, STA_REC_HE, sizeof(*he));
1298 
1299 	he = (struct sta_rec_he *)tlv;
1300 
1301 	if (elem->mac_cap_info[0] & IEEE80211_HE_MAC_CAP0_HTC_HE)
1302 		cap |= STA_REC_HE_CAP_HTC;
1303 
1304 	if (elem->mac_cap_info[2] & IEEE80211_HE_MAC_CAP2_BSR)
1305 		cap |= STA_REC_HE_CAP_BSR;
1306 
1307 	if (elem->mac_cap_info[3] & IEEE80211_HE_MAC_CAP3_OMI_CONTROL)
1308 		cap |= STA_REC_HE_CAP_OM;
1309 
1310 	if (elem->mac_cap_info[4] & IEEE80211_HE_MAC_CAP4_AMDSU_IN_AMPDU)
1311 		cap |= STA_REC_HE_CAP_AMSDU_IN_AMPDU;
1312 
1313 	if (elem->mac_cap_info[4] & IEEE80211_HE_MAC_CAP4_BQR)
1314 		cap |= STA_REC_HE_CAP_BQR;
1315 
1316 	if (elem->phy_cap_info[0] &
1317 	    (IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_RU_MAPPING_IN_2G |
1318 	     IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_RU_MAPPING_IN_5G))
1319 		cap |= STA_REC_HE_CAP_BW20_RU242_SUPPORT;
1320 
1321 	if (elem->phy_cap_info[1] &
1322 	    IEEE80211_HE_PHY_CAP1_LDPC_CODING_IN_PAYLOAD)
1323 		cap |= STA_REC_HE_CAP_LDPC;
1324 
1325 	if (elem->phy_cap_info[1] &
1326 	    IEEE80211_HE_PHY_CAP1_HE_LTF_AND_GI_FOR_HE_PPDUS_0_8US)
1327 		cap |= STA_REC_HE_CAP_SU_PPDU_1LTF_8US_GI;
1328 
1329 	if (elem->phy_cap_info[2] &
1330 	    IEEE80211_HE_PHY_CAP2_NDP_4x_LTF_AND_3_2US)
1331 		cap |= STA_REC_HE_CAP_NDP_4LTF_3DOT2MS_GI;
1332 
1333 	if (elem->phy_cap_info[2] &
1334 	    IEEE80211_HE_PHY_CAP2_STBC_TX_UNDER_80MHZ)
1335 		cap |= STA_REC_HE_CAP_LE_EQ_80M_TX_STBC;
1336 
1337 	if (elem->phy_cap_info[2] &
1338 	    IEEE80211_HE_PHY_CAP2_STBC_RX_UNDER_80MHZ)
1339 		cap |= STA_REC_HE_CAP_LE_EQ_80M_RX_STBC;
1340 
1341 	if (elem->phy_cap_info[6] &
1342 	    IEEE80211_HE_PHY_CAP6_PARTIAL_BW_EXT_RANGE)
1343 		cap |= STA_REC_HE_CAP_PARTIAL_BW_EXT_RANGE;
1344 
1345 	if (elem->phy_cap_info[7] &
1346 	    IEEE80211_HE_PHY_CAP7_HE_SU_MU_PPDU_4XLTF_AND_08_US_GI)
1347 		cap |= STA_REC_HE_CAP_SU_MU_PPDU_4LTF_8US_GI;
1348 
1349 	if (elem->phy_cap_info[7] &
1350 	    IEEE80211_HE_PHY_CAP7_STBC_TX_ABOVE_80MHZ)
1351 		cap |= STA_REC_HE_CAP_GT_80M_TX_STBC;
1352 
1353 	if (elem->phy_cap_info[7] &
1354 	    IEEE80211_HE_PHY_CAP7_STBC_RX_ABOVE_80MHZ)
1355 		cap |= STA_REC_HE_CAP_GT_80M_RX_STBC;
1356 
1357 	if (elem->phy_cap_info[8] &
1358 	    IEEE80211_HE_PHY_CAP8_HE_ER_SU_PPDU_4XLTF_AND_08_US_GI)
1359 		cap |= STA_REC_HE_CAP_ER_SU_PPDU_4LTF_8US_GI;
1360 
1361 	if (elem->phy_cap_info[8] &
1362 	    IEEE80211_HE_PHY_CAP8_HE_ER_SU_1XLTF_AND_08_US_GI)
1363 		cap |= STA_REC_HE_CAP_ER_SU_PPDU_1LTF_8US_GI;
1364 
1365 	if (elem->phy_cap_info[9] &
1366 	    IEEE80211_HE_PHY_CAP9_NON_TRIGGERED_CQI_FEEDBACK)
1367 		cap |= STA_REC_HE_CAP_TRIG_CQI_FK;
1368 
1369 	if (elem->phy_cap_info[9] &
1370 	    IEEE80211_HE_PHY_CAP9_TX_1024_QAM_LESS_THAN_242_TONE_RU)
1371 		cap |= STA_REC_HE_CAP_TX_1024QAM_UNDER_RU242;
1372 
1373 	if (elem->phy_cap_info[9] &
1374 	    IEEE80211_HE_PHY_CAP9_RX_1024_QAM_LESS_THAN_242_TONE_RU)
1375 		cap |= STA_REC_HE_CAP_RX_1024QAM_UNDER_RU242;
1376 
1377 	he->he_cap = cpu_to_le32(cap);
1378 
1379 	switch (sta->bandwidth) {
1380 	case IEEE80211_STA_RX_BW_160:
1381 		if (elem->phy_cap_info[0] &
1382 		    IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_80PLUS80_MHZ_IN_5G)
1383 			he->max_nss_mcs[CMD_HE_MCS_BW8080] =
1384 				he_cap->he_mcs_nss_supp.rx_mcs_80p80;
1385 
1386 		he->max_nss_mcs[CMD_HE_MCS_BW160] =
1387 				he_cap->he_mcs_nss_supp.rx_mcs_160;
1388 		/* fall through */
1389 	default:
1390 		he->max_nss_mcs[CMD_HE_MCS_BW80] =
1391 				he_cap->he_mcs_nss_supp.rx_mcs_80;
1392 		break;
1393 	}
1394 
1395 	he->t_frame_dur =
1396 		HE_MAC(CAP1_TF_MAC_PAD_DUR_MASK, elem->mac_cap_info[1]);
1397 	he->max_ampdu_exp =
1398 		HE_MAC(CAP3_MAX_AMPDU_LEN_EXP_MASK, elem->mac_cap_info[3]);
1399 
1400 	he->bw_set =
1401 		HE_PHY(CAP0_CHANNEL_WIDTH_SET_MASK, elem->phy_cap_info[0]);
1402 	he->device_class =
1403 		HE_PHY(CAP1_DEVICE_CLASS_A, elem->phy_cap_info[1]);
1404 	he->punc_pream_rx =
1405 		HE_PHY(CAP1_PREAMBLE_PUNC_RX_MASK, elem->phy_cap_info[1]);
1406 
1407 	he->dcm_tx_mode =
1408 		HE_PHY(CAP3_DCM_MAX_CONST_TX_MASK, elem->phy_cap_info[3]);
1409 	he->dcm_tx_max_nss =
1410 		HE_PHY(CAP3_DCM_MAX_TX_NSS_2, elem->phy_cap_info[3]);
1411 	he->dcm_rx_mode =
1412 		HE_PHY(CAP3_DCM_MAX_CONST_RX_MASK, elem->phy_cap_info[3]);
1413 	he->dcm_rx_max_nss =
1414 		HE_PHY(CAP3_DCM_MAX_RX_NSS_2, elem->phy_cap_info[3]);
1415 	he->dcm_rx_max_nss =
1416 		HE_PHY(CAP8_DCM_MAX_RU_MASK, elem->phy_cap_info[8]);
1417 
1418 	he->pkt_ext = 2;
1419 }
1420 
1421 static void
1422 mt7915_mcu_sta_muru_tlv(struct sk_buff *skb, struct ieee80211_sta *sta)
1423 {
1424 	struct ieee80211_sta_he_cap *he_cap = &sta->he_cap;
1425 	struct ieee80211_he_cap_elem *elem = &he_cap->he_cap_elem;
1426 	struct sta_rec_muru *muru;
1427 	struct tlv *tlv;
1428 
1429 	tlv = mt7915_mcu_add_tlv(skb, STA_REC_MURU, sizeof(*muru));
1430 
1431 	muru = (struct sta_rec_muru *)tlv;
1432 	muru->cfg.ofdma_dl_en = true;
1433 	muru->cfg.ofdma_ul_en = true;
1434 	muru->cfg.mimo_dl_en = true;
1435 	muru->cfg.mimo_ul_en = true;
1436 
1437 	muru->ofdma_dl.punc_pream_rx =
1438 		HE_PHY(CAP1_PREAMBLE_PUNC_RX_MASK, elem->phy_cap_info[1]);
1439 	muru->ofdma_dl.he_20m_in_40m_2g =
1440 		HE_PHY(CAP8_20MHZ_IN_40MHZ_HE_PPDU_IN_2G, elem->phy_cap_info[8]);
1441 	muru->ofdma_dl.he_20m_in_160m =
1442 		HE_PHY(CAP8_20MHZ_IN_160MHZ_HE_PPDU, elem->phy_cap_info[8]);
1443 	muru->ofdma_dl.he_80m_in_160m =
1444 		HE_PHY(CAP8_80MHZ_IN_160MHZ_HE_PPDU, elem->phy_cap_info[8]);
1445 	muru->ofdma_dl.lt16_sigb = 0;
1446 	muru->ofdma_dl.rx_su_comp_sigb = 0;
1447 	muru->ofdma_dl.rx_su_non_comp_sigb = 0;
1448 
1449 	muru->ofdma_ul.t_frame_dur =
1450 		HE_MAC(CAP1_TF_MAC_PAD_DUR_MASK, elem->mac_cap_info[1]);
1451 	muru->ofdma_ul.mu_cascading =
1452 		HE_MAC(CAP2_MU_CASCADING, elem->mac_cap_info[2]);
1453 	muru->ofdma_ul.uo_ra =
1454 		HE_MAC(CAP3_OFDMA_RA, elem->mac_cap_info[3]);
1455 	muru->ofdma_ul.he_2x996_tone = 0;
1456 	muru->ofdma_ul.rx_t_frame_11ac = 0;
1457 
1458 	muru->mimo_dl.vht_mu_bfee =
1459 		!!(sta->vht_cap.cap & IEEE80211_VHT_CAP_MU_BEAMFORMEE_CAPABLE);
1460 	muru->mimo_dl.partial_bw_dl_mimo =
1461 		HE_PHY(CAP6_PARTIAL_BANDWIDTH_DL_MUMIMO, elem->phy_cap_info[6]);
1462 
1463 	muru->mimo_ul.full_ul_mimo =
1464 		HE_PHY(CAP2_UL_MU_FULL_MU_MIMO, elem->phy_cap_info[2]);
1465 	muru->mimo_ul.partial_ul_mimo =
1466 		HE_PHY(CAP2_UL_MU_PARTIAL_MU_MIMO, elem->phy_cap_info[2]);
1467 }
1468 
1469 static void
1470 mt7915_mcu_sta_tlv(struct mt7915_dev *dev, struct sk_buff *skb,
1471 		   struct ieee80211_sta *sta)
1472 {
1473 	struct tlv *tlv;
1474 
1475 	if (sta->ht_cap.ht_supported) {
1476 		struct sta_rec_ht *ht;
1477 
1478 		/* starec ht */
1479 		tlv = mt7915_mcu_add_tlv(skb, STA_REC_HT, sizeof(*ht));
1480 		ht = (struct sta_rec_ht *)tlv;
1481 		ht->ht_cap = cpu_to_le16(sta->ht_cap.cap);
1482 	}
1483 
1484 	/* starec vht */
1485 	if (sta->vht_cap.vht_supported) {
1486 		struct sta_rec_vht *vht;
1487 
1488 		tlv = mt7915_mcu_add_tlv(skb, STA_REC_VHT, sizeof(*vht));
1489 		vht = (struct sta_rec_vht *)tlv;
1490 		vht->vht_cap = cpu_to_le32(sta->vht_cap.cap);
1491 		vht->vht_rx_mcs_map = sta->vht_cap.vht_mcs.rx_mcs_map;
1492 		vht->vht_tx_mcs_map = sta->vht_cap.vht_mcs.tx_mcs_map;
1493 	}
1494 
1495 	/* starec he */
1496 	if (sta->he_cap.has_he)
1497 		mt7915_mcu_sta_he_tlv(skb, sta);
1498 
1499 	/* starec muru */
1500 	if (sta->he_cap.has_he || sta->vht_cap.vht_supported)
1501 		mt7915_mcu_sta_muru_tlv(skb, sta);
1502 }
1503 
1504 static void
1505 mt7915_mcu_wtbl_smps_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1506 			 void *sta_wtbl, void *wtbl_tlv)
1507 {
1508 	struct wtbl_smps *smps;
1509 	struct tlv *tlv;
1510 
1511 	tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_SMPS, sizeof(*smps),
1512 					wtbl_tlv, sta_wtbl);
1513 	smps = (struct wtbl_smps *)tlv;
1514 
1515 	if (sta->smps_mode == IEEE80211_SMPS_DYNAMIC)
1516 		smps->smps = true;
1517 }
1518 
1519 static void
1520 mt7915_mcu_wtbl_ht_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1521 		       void *sta_wtbl, void *wtbl_tlv)
1522 {
1523 	struct wtbl_ht *ht = NULL;
1524 	struct tlv *tlv;
1525 
1526 	/* wtbl ht */
1527 	if (sta->ht_cap.ht_supported) {
1528 		tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_HT, sizeof(*ht),
1529 						wtbl_tlv, sta_wtbl);
1530 		ht = (struct wtbl_ht *)tlv;
1531 		ht->ldpc = sta->ht_cap.cap & IEEE80211_HT_CAP_LDPC_CODING;
1532 		ht->af = sta->ht_cap.ampdu_factor;
1533 		ht->mm = sta->ht_cap.ampdu_density;
1534 		ht->ht = true;
1535 	}
1536 
1537 	/* wtbl vht */
1538 	if (sta->vht_cap.vht_supported) {
1539 		struct wtbl_vht *vht;
1540 		u8 af;
1541 
1542 		tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_VHT, sizeof(*vht),
1543 						wtbl_tlv, sta_wtbl);
1544 		vht = (struct wtbl_vht *)tlv;
1545 		vht->ldpc = sta->vht_cap.cap & IEEE80211_VHT_CAP_RXLDPC,
1546 		vht->vht = true;
1547 
1548 		af = FIELD_GET(IEEE80211_VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MASK,
1549 			       sta->vht_cap.cap);
1550 		if (ht)
1551 			ht->af = max_t(u8, ht->af, af);
1552 	}
1553 
1554 	mt7915_mcu_wtbl_smps_tlv(skb, sta, sta_wtbl, wtbl_tlv);
1555 }
1556 
1557 int mt7915_mcu_add_smps(struct mt7915_dev *dev, struct ieee80211_vif *vif,
1558 			struct ieee80211_sta *sta)
1559 {
1560 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1561 	struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
1562 	struct wtbl_req_hdr *wtbl_hdr;
1563 	struct tlv *sta_wtbl;
1564 	struct sk_buff *skb;
1565 
1566 	skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
1567 				       MT7915_STA_UPDATE_MAX_SIZE);
1568 	if (IS_ERR(skb))
1569 		return PTR_ERR(skb);
1570 
1571 	sta_wtbl = mt7915_mcu_add_tlv(skb, STA_REC_WTBL, sizeof(struct tlv));
1572 
1573 	wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_SET, sta_wtbl,
1574 					     &skb);
1575 	mt7915_mcu_wtbl_smps_tlv(skb, sta, sta_wtbl, wtbl_hdr);
1576 
1577 	return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1578 				       MCU_EXT_CMD_STA_REC_UPDATE, true);
1579 }
1580 
1581 static void
1582 mt7915_mcu_sta_sounding_rate(struct sta_rec_bf *bf)
1583 {
1584 	bf->sounding_phy = MT_PHY_TYPE_OFDM;
1585 	bf->ndp_rate = 0;				/* mcs0 */
1586 	bf->ndpa_rate = MT7915_CFEND_RATE_DEFAULT;	/* ofdm 24m */
1587 	bf->rept_poll_rate = MT7915_CFEND_RATE_DEFAULT;	/* ofdm 24m */
1588 }
1589 
1590 static void
1591 mt7915_mcu_sta_bfer_ht(struct ieee80211_sta *sta, struct sta_rec_bf *bf)
1592 {
1593 	struct ieee80211_mcs_info *mcs = &sta->ht_cap.mcs;
1594 	u8 n = 0;
1595 
1596 	bf->tx_mode = MT_PHY_TYPE_HT;
1597 	bf->bf_cap |= MT_IBF;
1598 
1599 	if (mcs->tx_params & IEEE80211_HT_MCS_TX_RX_DIFF &&
1600 	    (mcs->tx_params & IEEE80211_HT_MCS_TX_DEFINED))
1601 		n = FIELD_GET(IEEE80211_HT_MCS_TX_MAX_STREAMS_MASK,
1602 			      mcs->tx_params);
1603 	else if (mcs->rx_mask[3])
1604 		n = 3;
1605 	else if (mcs->rx_mask[2])
1606 		n = 2;
1607 	else if (mcs->rx_mask[1])
1608 		n = 1;
1609 
1610 	bf->nc = min_t(u8, bf->nr, n);
1611 	bf->ibf_ncol = bf->nc;
1612 
1613 	if (sta->bandwidth <= IEEE80211_STA_RX_BW_40 && !bf->nc)
1614 		bf->ibf_timeout = 0x48;
1615 }
1616 
1617 static void
1618 mt7915_mcu_sta_bfer_vht(struct ieee80211_sta *sta, struct mt7915_phy *phy,
1619 			struct sta_rec_bf *bf)
1620 {
1621 	struct ieee80211_sta_vht_cap *pc = &sta->vht_cap;
1622 	struct ieee80211_sta_vht_cap *vc = &phy->mt76->sband_5g.sband.vht_cap;
1623 	u8 bfee_nr, bfer_nr, n, tx_ant = hweight8(phy->chainmask) - 1;
1624 	u16 mcs_map;
1625 
1626 	bf->tx_mode = MT_PHY_TYPE_VHT;
1627 	bf->bf_cap |= MT_EBF;
1628 
1629 	mt7915_mcu_sta_sounding_rate(bf);
1630 
1631 	bfee_nr = FIELD_GET(IEEE80211_VHT_CAP_BEAMFORMEE_STS_MASK,
1632 			    pc->cap);
1633 	bfer_nr = FIELD_GET(IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_MASK,
1634 			    vc->cap);
1635 	mcs_map = le16_to_cpu(pc->vht_mcs.rx_mcs_map);
1636 
1637 	n = min_t(u8, bfer_nr, bfee_nr);
1638 	bf->nr = min_t(u8, n, tx_ant);
1639 	n = mt7915_mcu_get_sta_nss(mcs_map);
1640 
1641 	bf->nc = min_t(u8, n, bf->nr);
1642 	bf->ibf_ncol = bf->nc;
1643 
1644 	/* force nr from 4 to 2 */
1645 	if (sta->bandwidth == IEEE80211_STA_RX_BW_160)
1646 		bf->nr = 1;
1647 }
1648 
1649 static void
1650 mt7915_mcu_sta_bfer_he(struct ieee80211_sta *sta, struct ieee80211_vif *vif,
1651 		       struct mt7915_phy *phy, struct sta_rec_bf *bf)
1652 {
1653 	struct ieee80211_sta_he_cap *pc = &sta->he_cap;
1654 	struct ieee80211_he_cap_elem *pe = &pc->he_cap_elem;
1655 	const struct ieee80211_he_cap_elem *ve;
1656 	const struct ieee80211_sta_he_cap *vc;
1657 	u8 bfee_nr, bfer_nr, nss_mcs;
1658 	u16 mcs_map;
1659 
1660 	vc = mt7915_get_he_phy_cap(phy, vif);
1661 	ve = &vc->he_cap_elem;
1662 
1663 	bf->tx_mode = MT_PHY_TYPE_HE_SU;
1664 	bf->bf_cap |= MT_EBF;
1665 
1666 	mt7915_mcu_sta_sounding_rate(bf);
1667 
1668 	bf->trigger_su = HE_PHY(CAP6_TRIG_SU_BEAMFORMER_FB,
1669 				pe->phy_cap_info[6]);
1670 	bf->trigger_mu = HE_PHY(CAP6_TRIG_MU_BEAMFORMER_FB,
1671 				pe->phy_cap_info[6]);
1672 	bfer_nr = HE_PHY(CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_MASK,
1673 			 ve->phy_cap_info[5]);
1674 	bfee_nr = HE_PHY(CAP4_BEAMFORMEE_MAX_STS_UNDER_80MHZ_MASK,
1675 			 pe->phy_cap_info[4]);
1676 
1677 	mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.tx_mcs_80);
1678 	nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
1679 
1680 	bf->nr = min_t(u8, bfer_nr, bfee_nr);
1681 	bf->nc = min_t(u8, nss_mcs, bf->nr);
1682 	bf->ibf_ncol = bf->nc;
1683 
1684 	if (sta->bandwidth != IEEE80211_STA_RX_BW_160)
1685 		return;
1686 
1687 	/* go over for 160MHz and 80p80 */
1688 	if (pe->phy_cap_info[0] &
1689 	    IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_160MHZ_IN_5G) {
1690 		mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.rx_mcs_160);
1691 		nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
1692 
1693 		bf->nc_bw160 = nss_mcs;
1694 	}
1695 
1696 	if (pe->phy_cap_info[0] &
1697 	    IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_80PLUS80_MHZ_IN_5G) {
1698 		mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.rx_mcs_80p80);
1699 		nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
1700 
1701 		if (bf->nc_bw160)
1702 			bf->nc_bw160 = min_t(u8, bf->nc_bw160, nss_mcs);
1703 		else
1704 			bf->nc_bw160 = nss_mcs;
1705 	}
1706 
1707 	bfer_nr = HE_PHY(CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_MASK,
1708 			 ve->phy_cap_info[5]);
1709 	bfee_nr = HE_PHY(CAP4_BEAMFORMEE_MAX_STS_ABOVE_80MHZ_MASK,
1710 			 pe->phy_cap_info[4]);
1711 
1712 	bf->nr_bw160 = min_t(int, bfer_nr, bfee_nr);
1713 }
1714 
1715 static void
1716 mt7915_mcu_sta_bfer_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1717 			struct ieee80211_vif *vif, struct mt7915_phy *phy,
1718 			bool enable)
1719 {
1720 	struct sta_rec_bf *bf;
1721 	struct tlv *tlv;
1722 	int tx_ant = hweight8(phy->chainmask) - 1;
1723 	const u8 matrix[4][4] = {
1724 		{0, 0, 0, 0},
1725 		{1, 1, 0, 0},	/* 2x1, 2x2, 2x3, 2x4 */
1726 		{2, 4, 4, 0},	/* 3x1, 3x2, 3x3, 3x4 */
1727 		{3, 5, 6, 0}	/* 4x1, 4x2, 4x3, 4x4 */
1728 	};
1729 
1730 #define MT_BFER_FREE		cpu_to_le16(GENMASK(15, 0))
1731 
1732 	tlv = mt7915_mcu_add_tlv(skb, STA_REC_BF, sizeof(*bf));
1733 	bf = (struct sta_rec_bf *)tlv;
1734 
1735 	if (!enable) {
1736 		bf->pfmu = MT_BFER_FREE;
1737 		return;
1738 	}
1739 
1740 	bf->bw = sta->bandwidth;
1741 	bf->ibf_dbw = sta->bandwidth;
1742 	bf->ibf_nrow = tx_ant;
1743 	bf->ibf_timeout = 0x18;
1744 
1745 	if (sta->he_cap.has_he)
1746 		mt7915_mcu_sta_bfer_he(sta, vif, phy, bf);
1747 	else if (sta->vht_cap.vht_supported)
1748 		mt7915_mcu_sta_bfer_vht(sta, phy, bf);
1749 	else if (sta->ht_cap.ht_supported)
1750 		mt7915_mcu_sta_bfer_ht(sta, bf);
1751 
1752 	if (bf->bf_cap & MT_EBF && bf->nr != tx_ant)
1753 		bf->mem_20m = matrix[tx_ant][bf->nc];
1754 	else
1755 		bf->mem_20m = matrix[bf->nr][bf->nc];
1756 
1757 	switch (sta->bandwidth) {
1758 	case IEEE80211_STA_RX_BW_160:
1759 	case IEEE80211_STA_RX_BW_80:
1760 		bf->mem_total = bf->mem_20m * 2;
1761 		break;
1762 	case IEEE80211_STA_RX_BW_40:
1763 		bf->mem_total = bf->mem_20m;
1764 		break;
1765 	case IEEE80211_STA_RX_BW_20:
1766 	default:
1767 		break;
1768 	}
1769 }
1770 
1771 static void
1772 mt7915_mcu_sta_bfee_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1773 			struct mt7915_phy *phy)
1774 {
1775 	struct sta_rec_bfee *bfee;
1776 	struct tlv *tlv;
1777 	int tx_ant = hweight8(phy->chainmask) - 1;
1778 	u8 nr = 0;
1779 
1780 	tlv = mt7915_mcu_add_tlv(skb, STA_REC_BFEE, sizeof(*bfee));
1781 	bfee = (struct sta_rec_bfee *)tlv;
1782 
1783 	if (sta->he_cap.has_he) {
1784 		struct ieee80211_he_cap_elem *pe = &sta->he_cap.he_cap_elem;
1785 
1786 		nr = HE_PHY(CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_MASK,
1787 			    pe->phy_cap_info[5]);
1788 	} else if (sta->vht_cap.vht_supported) {
1789 		struct ieee80211_sta_vht_cap *pc = &sta->vht_cap;
1790 
1791 		nr = FIELD_GET(IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_MASK,
1792 			       pc->cap);
1793 	}
1794 
1795 	/* reply with identity matrix to avoid 2x2 BF negative gain */
1796 	if (nr == 1 && tx_ant == 2)
1797 		bfee->fb_identity_matrix = true;
1798 }
1799 
1800 static u8
1801 mt7915_mcu_sta_txbf_type(struct mt7915_phy *phy, struct ieee80211_vif *vif,
1802 			 struct ieee80211_sta *sta)
1803 {
1804 	u8 type = 0;
1805 
1806 	if (vif->type != NL80211_IFTYPE_STATION &&
1807 	    vif->type != NL80211_IFTYPE_AP)
1808 		return 0;
1809 
1810 	if (sta->he_cap.has_he) {
1811 		struct ieee80211_he_cap_elem *pe;
1812 		const struct ieee80211_he_cap_elem *ve;
1813 		const struct ieee80211_sta_he_cap *vc;
1814 
1815 		pe = &sta->he_cap.he_cap_elem;
1816 		vc = mt7915_get_he_phy_cap(phy, vif);
1817 		ve = &vc->he_cap_elem;
1818 
1819 		if ((HE_PHY(CAP3_SU_BEAMFORMER, pe->phy_cap_info[3]) ||
1820 		     HE_PHY(CAP4_MU_BEAMFORMER, pe->phy_cap_info[4])) &&
1821 		    HE_PHY(CAP4_SU_BEAMFORMEE, ve->phy_cap_info[4]))
1822 			type |= MT_STA_BFEE;
1823 
1824 		if ((HE_PHY(CAP3_SU_BEAMFORMER, ve->phy_cap_info[3]) ||
1825 		     HE_PHY(CAP4_MU_BEAMFORMER, ve->phy_cap_info[4])) &&
1826 		    HE_PHY(CAP4_SU_BEAMFORMEE, pe->phy_cap_info[4]))
1827 			type |= MT_STA_BFER;
1828 	} else if (sta->vht_cap.vht_supported) {
1829 		struct ieee80211_sta_vht_cap *pc;
1830 		struct ieee80211_sta_vht_cap *vc;
1831 		u32 cr, ce;
1832 
1833 		pc = &sta->vht_cap;
1834 		vc = &phy->mt76->sband_5g.sband.vht_cap;
1835 		cr = IEEE80211_VHT_CAP_SU_BEAMFORMER_CAPABLE |
1836 		     IEEE80211_VHT_CAP_MU_BEAMFORMER_CAPABLE;
1837 		ce = IEEE80211_VHT_CAP_SU_BEAMFORMEE_CAPABLE |
1838 		     IEEE80211_VHT_CAP_MU_BEAMFORMEE_CAPABLE;
1839 
1840 		if ((pc->cap & cr) && (vc->cap & ce))
1841 			type |= MT_STA_BFEE;
1842 
1843 		if ((vc->cap & cr) && (pc->cap & ce))
1844 			type |= MT_STA_BFER;
1845 	} else if (sta->ht_cap.ht_supported) {
1846 		/* TODO: iBF */
1847 	}
1848 
1849 	return type;
1850 }
1851 
1852 static int
1853 mt7915_mcu_add_txbf(struct mt7915_dev *dev, struct ieee80211_vif *vif,
1854 		    struct ieee80211_sta *sta, bool enable)
1855 {
1856 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1857 	struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
1858 	struct mt7915_phy *phy;
1859 	struct sk_buff *skb;
1860 	int r, len;
1861 	u8 type;
1862 
1863 	phy = mvif->band_idx ? mt7915_ext_phy(dev) : &dev->phy;
1864 
1865 	type = mt7915_mcu_sta_txbf_type(phy, vif, sta);
1866 
1867 	/* must keep each tag independent */
1868 
1869 	/* starec bf */
1870 	if (type & MT_STA_BFER) {
1871 		len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_bf);
1872 
1873 		skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
1874 		if (IS_ERR(skb))
1875 			return PTR_ERR(skb);
1876 
1877 		mt7915_mcu_sta_bfer_tlv(skb, sta, vif, phy, enable);
1878 
1879 		r = __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1880 					    MCU_EXT_CMD_STA_REC_UPDATE, true);
1881 		if (r)
1882 			return r;
1883 	}
1884 
1885 	/* starec bfee */
1886 	if (type & MT_STA_BFEE) {
1887 		len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_bfee);
1888 
1889 		skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
1890 		if (IS_ERR(skb))
1891 			return PTR_ERR(skb);
1892 
1893 		mt7915_mcu_sta_bfee_tlv(skb, sta, phy);
1894 
1895 		r = __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1896 					    MCU_EXT_CMD_STA_REC_UPDATE, true);
1897 		if (r)
1898 			return r;
1899 	}
1900 
1901 	return 0;
1902 }
1903 
1904 static void
1905 mt7915_mcu_sta_rate_ctrl_tlv(struct sk_buff *skb, struct mt7915_dev *dev,
1906 			     struct ieee80211_vif *vif,
1907 			     struct ieee80211_sta *sta)
1908 {
1909 	struct cfg80211_chan_def *chandef = &dev->mphy.chandef;
1910 	struct sta_rec_ra *ra;
1911 	struct tlv *tlv;
1912 	enum nl80211_band band = chandef->chan->band;
1913 	u32 supp_rate = sta->supp_rates[band];
1914 	int n_rates = hweight32(supp_rate);
1915 	u32 cap = sta->wme ? STA_CAP_WMM : 0;
1916 	u8 i, nss = sta->rx_nss, mcs = 0;
1917 
1918 	tlv = mt7915_mcu_add_tlv(skb, STA_REC_RA, sizeof(*ra));
1919 
1920 	ra = (struct sta_rec_ra *)tlv;
1921 	ra->valid = true;
1922 	ra->auto_rate = true;
1923 	ra->phy_mode = mt7915_get_phy_mode(dev, vif, band, sta);
1924 	ra->channel = chandef->chan->hw_value;
1925 	ra->bw = sta->bandwidth;
1926 	ra->rate_len = n_rates;
1927 	ra->phy.bw = sta->bandwidth;
1928 
1929 	if (n_rates) {
1930 		if (band == NL80211_BAND_2GHZ) {
1931 			ra->supp_mode = MODE_CCK;
1932 			ra->supp_cck_rate = supp_rate & GENMASK(3, 0);
1933 			ra->phy.type = MT_PHY_TYPE_CCK;
1934 
1935 			if (n_rates > 4) {
1936 				ra->supp_mode |= MODE_OFDM;
1937 				ra->supp_ofdm_rate = supp_rate >> 4;
1938 				ra->phy.type = MT_PHY_TYPE_OFDM;
1939 			}
1940 		} else {
1941 			ra->supp_mode = MODE_OFDM;
1942 			ra->supp_ofdm_rate = supp_rate;
1943 			ra->phy.type = MT_PHY_TYPE_OFDM;
1944 		}
1945 	}
1946 
1947 	if (sta->ht_cap.ht_supported) {
1948 		for (i = 0; i < nss; i++)
1949 			ra->ht_mcs[i] = sta->ht_cap.mcs.rx_mask[i];
1950 
1951 		ra->supp_ht_mcs = *(__le32 *)ra->ht_mcs;
1952 		ra->supp_mode |= MODE_HT;
1953 		mcs = hweight32(le32_to_cpu(ra->supp_ht_mcs)) - 1;
1954 		ra->af = sta->ht_cap.ampdu_factor;
1955 		ra->ht_gf = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_GRN_FLD);
1956 
1957 		cap |= STA_CAP_HT;
1958 		if (sta->ht_cap.cap & IEEE80211_HT_CAP_SGI_20)
1959 			cap |= STA_CAP_SGI_20;
1960 		if (sta->ht_cap.cap & IEEE80211_HT_CAP_SGI_40)
1961 			cap |= STA_CAP_SGI_40;
1962 		if (sta->ht_cap.cap & IEEE80211_HT_CAP_TX_STBC)
1963 			cap |= STA_CAP_TX_STBC;
1964 		if (sta->ht_cap.cap & IEEE80211_HT_CAP_RX_STBC)
1965 			cap |= STA_CAP_RX_STBC;
1966 		if (sta->ht_cap.cap & IEEE80211_HT_CAP_LDPC_CODING)
1967 			cap |= STA_CAP_LDPC;
1968 	}
1969 
1970 	if (sta->vht_cap.vht_supported) {
1971 		u16 mcs_map = le16_to_cpu(sta->vht_cap.vht_mcs.rx_mcs_map);
1972 		u16 vht_mcs;
1973 		u8 af, mcs_prev;
1974 
1975 		af = FIELD_GET(IEEE80211_VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MASK,
1976 			       sta->vht_cap.cap);
1977 		ra->af = max_t(u8, ra->af, af);
1978 
1979 		cap |= STA_CAP_VHT;
1980 		if (sta->vht_cap.cap & IEEE80211_VHT_CAP_SHORT_GI_80)
1981 			cap |= STA_CAP_VHT_SGI_80;
1982 		if (sta->vht_cap.cap & IEEE80211_VHT_CAP_SHORT_GI_160)
1983 			cap |= STA_CAP_VHT_SGI_160;
1984 		if (sta->vht_cap.cap & IEEE80211_VHT_CAP_TXSTBC)
1985 			cap |= STA_CAP_VHT_TX_STBC;
1986 		if (sta->vht_cap.cap & IEEE80211_VHT_CAP_RXSTBC_1)
1987 			cap |= STA_CAP_VHT_RX_STBC;
1988 		if (sta->vht_cap.cap & IEEE80211_VHT_CAP_RXLDPC)
1989 			cap |= STA_CAP_VHT_LDPC;
1990 
1991 		ra->supp_mode |= MODE_VHT;
1992 		for (mcs = 0, i = 0; i < nss; i++, mcs_map >>= 2) {
1993 			switch (mcs_map & 0x3) {
1994 			case IEEE80211_VHT_MCS_SUPPORT_0_9:
1995 				vht_mcs = GENMASK(9, 0);
1996 				break;
1997 			case IEEE80211_VHT_MCS_SUPPORT_0_8:
1998 				vht_mcs = GENMASK(8, 0);
1999 				break;
2000 			case IEEE80211_VHT_MCS_SUPPORT_0_7:
2001 				vht_mcs = GENMASK(7, 0);
2002 				break;
2003 			default:
2004 				vht_mcs = 0;
2005 			}
2006 
2007 			ra->supp_vht_mcs[i] = cpu_to_le16(vht_mcs);
2008 
2009 			mcs_prev = hweight16(vht_mcs) - 1;
2010 			if (mcs_prev > mcs)
2011 				mcs = mcs_prev;
2012 
2013 			/* only support 2ss on 160MHz */
2014 			if (i > 1 && (ra->bw == CMD_CBW_160MHZ ||
2015 				      ra->bw == CMD_CBW_8080MHZ))
2016 				break;
2017 		}
2018 	}
2019 
2020 	if (sta->he_cap.has_he) {
2021 		ra->supp_mode |= MODE_HE;
2022 		cap |= STA_CAP_HE;
2023 	}
2024 
2025 	ra->sta_status = cpu_to_le32(cap);
2026 
2027 	switch (BIT(fls(ra->supp_mode) - 1)) {
2028 	case MODE_VHT:
2029 		ra->phy.type = MT_PHY_TYPE_VHT;
2030 		ra->phy.mcs = mcs;
2031 		ra->phy.nss = nss;
2032 		ra->phy.stbc = !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_TXSTBC);
2033 		ra->phy.ldpc = !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_RXLDPC);
2034 		ra->phy.sgi =
2035 			!!(sta->vht_cap.cap & IEEE80211_VHT_CAP_SHORT_GI_80);
2036 		break;
2037 	case MODE_HT:
2038 		ra->phy.type = MT_PHY_TYPE_HT;
2039 		ra->phy.mcs = mcs;
2040 		ra->phy.ldpc = sta->ht_cap.cap & IEEE80211_HT_CAP_LDPC_CODING;
2041 		ra->phy.stbc = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_TX_STBC);
2042 		ra->phy.sgi = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_SGI_20);
2043 		break;
2044 	default:
2045 		break;
2046 	}
2047 }
2048 
2049 int mt7915_mcu_add_rate_ctrl(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2050 			     struct ieee80211_sta *sta)
2051 {
2052 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2053 	struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
2054 	struct sk_buff *skb;
2055 	int len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_ra);
2056 
2057 	skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
2058 	if (IS_ERR(skb))
2059 		return PTR_ERR(skb);
2060 
2061 	mt7915_mcu_sta_rate_ctrl_tlv(skb, dev, vif, sta);
2062 
2063 	return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
2064 				       MCU_EXT_CMD_STA_REC_UPDATE, true);
2065 }
2066 
2067 int mt7915_mcu_add_sta_adv(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2068 			   struct ieee80211_sta *sta, bool enable)
2069 {
2070 	int ret;
2071 
2072 	if (!sta)
2073 		return 0;
2074 
2075 	/* must keep the order */
2076 	ret = mt7915_mcu_add_txbf(dev, vif, sta, enable);
2077 	if (ret)
2078 		return ret;
2079 
2080 	if (enable)
2081 		return mt7915_mcu_add_rate_ctrl(dev, vif, sta);
2082 
2083 	return 0;
2084 }
2085 
2086 int mt7915_mcu_add_sta(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2087 		       struct ieee80211_sta *sta, bool enable)
2088 {
2089 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2090 	struct wtbl_req_hdr *wtbl_hdr;
2091 	struct mt7915_sta *msta;
2092 	struct tlv *sta_wtbl;
2093 	struct sk_buff *skb;
2094 
2095 	msta = sta ? (struct mt7915_sta *)sta->drv_priv : &mvif->sta;
2096 
2097 	skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
2098 				       MT7915_STA_UPDATE_MAX_SIZE);
2099 	if (IS_ERR(skb))
2100 		return PTR_ERR(skb);
2101 
2102 	mt7915_mcu_sta_basic_tlv(skb, vif, sta, enable);
2103 	if (enable && sta)
2104 		mt7915_mcu_sta_tlv(dev, skb, sta);
2105 
2106 	sta_wtbl = mt7915_mcu_add_tlv(skb, STA_REC_WTBL, sizeof(struct tlv));
2107 
2108 	wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_RESET_AND_SET,
2109 					     sta_wtbl, &skb);
2110 	if (enable) {
2111 		mt7915_mcu_wtbl_generic_tlv(skb, vif, sta, sta_wtbl, wtbl_hdr);
2112 		if (sta)
2113 			mt7915_mcu_wtbl_ht_tlv(skb, sta, sta_wtbl, wtbl_hdr);
2114 	}
2115 
2116 	return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
2117 				       MCU_EXT_CMD_STA_REC_UPDATE, true);
2118 }
2119 
2120 int mt7915_mcu_set_fixed_rate(struct mt7915_dev *dev,
2121 			      struct ieee80211_sta *sta, u32 rate)
2122 {
2123 	struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
2124 	struct mt7915_vif *mvif = msta->vif;
2125 	struct sta_rec_ra_fixed *ra;
2126 	struct sk_buff *skb;
2127 	struct tlv *tlv;
2128 	int len = sizeof(struct sta_req_hdr) + sizeof(*ra);
2129 
2130 	skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
2131 	if (IS_ERR(skb))
2132 		return PTR_ERR(skb);
2133 
2134 	tlv = mt7915_mcu_add_tlv(skb, STA_REC_RA_UPDATE, sizeof(*ra));
2135 	ra = (struct sta_rec_ra_fixed *)tlv;
2136 
2137 	if (!rate) {
2138 		ra->field = cpu_to_le32(RATE_PARAM_AUTO);
2139 		goto out;
2140 	} else {
2141 		ra->field = cpu_to_le32(RATE_PARAM_FIXED);
2142 	}
2143 
2144 	ra->phy.type = FIELD_GET(RATE_CFG_PHY_TYPE, rate);
2145 	ra->phy.bw = FIELD_GET(RATE_CFG_BW, rate);
2146 	ra->phy.nss = FIELD_GET(RATE_CFG_NSS, rate);
2147 	ra->phy.mcs = FIELD_GET(RATE_CFG_MCS, rate);
2148 	ra->phy.stbc = FIELD_GET(RATE_CFG_STBC, rate);
2149 
2150 	if (ra->phy.bw)
2151 		ra->phy.ldpc = 7;
2152 	else
2153 		ra->phy.ldpc = FIELD_GET(RATE_CFG_LDPC, rate) * 7;
2154 
2155 	/* HT/VHT - SGI: 1, LGI: 0; HE - SGI: 0, MGI: 1, LGI: 2 */
2156 	if (ra->phy.type > MT_PHY_TYPE_VHT)
2157 		ra->phy.sgi = ra->phy.mcs * 85;
2158 	else
2159 		ra->phy.sgi = ra->phy.mcs * 15;
2160 
2161 out:
2162 	return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
2163 				       MCU_EXT_CMD_STA_REC_UPDATE, true);
2164 }
2165 
2166 int mt7915_mcu_add_dev_info(struct mt7915_dev *dev,
2167 			    struct ieee80211_vif *vif, bool enable)
2168 {
2169 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2170 	struct {
2171 		struct req_hdr {
2172 			u8 omac_idx;
2173 			u8 dbdc_idx;
2174 			__le16 tlv_num;
2175 			u8 is_tlv_append;
2176 			u8 rsv[3];
2177 		} __packed hdr;
2178 		struct req_tlv {
2179 			__le16 tag;
2180 			__le16 len;
2181 			u8 active;
2182 			u8 dbdc_idx;
2183 			u8 omac_addr[ETH_ALEN];
2184 		} __packed tlv;
2185 	} data = {
2186 		.hdr = {
2187 			.omac_idx = mvif->omac_idx,
2188 			.dbdc_idx = mvif->band_idx,
2189 			.tlv_num = cpu_to_le16(1),
2190 			.is_tlv_append = 1,
2191 		},
2192 		.tlv = {
2193 			.tag = cpu_to_le16(DEV_INFO_ACTIVE),
2194 			.len = cpu_to_le16(sizeof(struct req_tlv)),
2195 			.active = enable,
2196 			.dbdc_idx = mvif->band_idx,
2197 		},
2198 	};
2199 
2200 	memcpy(data.tlv.omac_addr, vif->addr, ETH_ALEN);
2201 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_DEV_INFO_UPDATE,
2202 				   &data, sizeof(data), true);
2203 }
2204 
2205 static void
2206 mt7915_mcu_beacon_csa(struct sk_buff *rskb, struct sk_buff *skb,
2207 		      struct bss_info_bcn *bcn,
2208 		      struct ieee80211_mutable_offsets *offs)
2209 {
2210 	if (offs->csa_counter_offs[0]) {
2211 		struct tlv *tlv;
2212 		struct bss_info_bcn_csa *csa;
2213 
2214 		tlv = mt7915_mcu_add_nested_subtlv(rskb, BSS_INFO_BCN_CSA,
2215 						   sizeof(*csa), &bcn->sub_ntlv,
2216 						   &bcn->len);
2217 		csa = (struct bss_info_bcn_csa *)tlv;
2218 		csa->cnt = skb->data[offs->csa_counter_offs[0]];
2219 	}
2220 }
2221 
2222 static void
2223 mt7915_mcu_beacon_cont(struct mt7915_dev *dev, struct sk_buff *rskb,
2224 		       struct sk_buff *skb, struct bss_info_bcn *bcn,
2225 		       struct ieee80211_mutable_offsets *offs)
2226 {
2227 	struct mt76_wcid *wcid = &dev->mt76.global_wcid;
2228 	struct bss_info_bcn_cont *cont;
2229 	struct tlv *tlv;
2230 	u8 *buf;
2231 	int len = sizeof(*cont) + MT_TXD_SIZE + skb->len;
2232 
2233 	tlv = mt7915_mcu_add_nested_subtlv(rskb, BSS_INFO_BCN_CONTENT,
2234 					   len, &bcn->sub_ntlv, &bcn->len);
2235 
2236 	cont = (struct bss_info_bcn_cont *)tlv;
2237 	cont->pkt_len = cpu_to_le16(MT_TXD_SIZE + skb->len);
2238 	cont->tim_ofs = cpu_to_le16(offs->tim_offset);
2239 
2240 	if (offs->csa_counter_offs[0])
2241 		cont->csa_ofs = cpu_to_le16(offs->csa_counter_offs[0] - 4);
2242 
2243 	buf = (u8 *)tlv + sizeof(*cont);
2244 	mt7915_mac_write_txwi(dev, (__le32 *)buf, skb, wcid, NULL,
2245 			      true);
2246 	memcpy(buf + MT_TXD_SIZE, skb->data, skb->len);
2247 }
2248 
2249 int mt7915_mcu_add_beacon(struct ieee80211_hw *hw,
2250 			  struct ieee80211_vif *vif, int en)
2251 {
2252 #define MAX_BEACON_SIZE 512
2253 	struct mt7915_dev *dev = mt7915_hw_dev(hw);
2254 	struct mt7915_phy *phy = mt7915_hw_phy(hw);
2255 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2256 	struct ieee80211_mutable_offsets offs;
2257 	struct ieee80211_tx_info *info;
2258 	struct sk_buff *skb, *rskb;
2259 	struct tlv *tlv;
2260 	struct bss_info_bcn *bcn;
2261 	int len = MT7915_BEACON_UPDATE_SIZE + MAX_BEACON_SIZE;
2262 
2263 	rskb = mt7915_mcu_alloc_sta_req(dev, mvif, NULL, len);
2264 	if (IS_ERR(rskb))
2265 		return PTR_ERR(rskb);
2266 
2267 	tlv = mt7915_mcu_add_tlv(rskb, BSS_INFO_OFFLOAD, sizeof(*bcn));
2268 	bcn = (struct bss_info_bcn *)tlv;
2269 	bcn->enable = en;
2270 
2271 	skb = ieee80211_beacon_get_template(hw, vif, &offs);
2272 	if (!skb)
2273 		return -EINVAL;
2274 
2275 	if (skb->len > MAX_BEACON_SIZE - MT_TXD_SIZE) {
2276 		dev_err(dev->mt76.dev, "Bcn size limit exceed\n");
2277 		dev_kfree_skb(skb);
2278 		return -EINVAL;
2279 	}
2280 
2281 	if (mvif->band_idx) {
2282 		info = IEEE80211_SKB_CB(skb);
2283 		info->hw_queue |= MT_TX_HW_QUEUE_EXT_PHY;
2284 	}
2285 
2286 	/* TODO: subtag - bss color count & 11v MBSSID */
2287 	mt7915_mcu_beacon_csa(rskb, skb, bcn, &offs);
2288 	mt7915_mcu_beacon_cont(dev, rskb, skb, bcn, &offs);
2289 	dev_kfree_skb(skb);
2290 
2291 	return __mt76_mcu_skb_send_msg(&phy->dev->mt76, rskb,
2292 				       MCU_EXT_CMD_BSS_INFO_UPDATE, true);
2293 }
2294 
2295 static int mt7915_mcu_send_firmware(struct mt7915_dev *dev, const void *data,
2296 				    int len)
2297 {
2298 	int ret = 0, cur_len;
2299 
2300 	while (len > 0) {
2301 		cur_len = min_t(int, 4096 - sizeof(struct mt7915_mcu_txd),
2302 				len);
2303 
2304 		ret = __mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_FW_SCATTER,
2305 					  data, cur_len, false);
2306 		if (ret)
2307 			break;
2308 
2309 		data += cur_len;
2310 		len -= cur_len;
2311 		mt76_queue_tx_cleanup(dev, MT_TXQ_FWDL, false);
2312 	}
2313 
2314 	return ret;
2315 }
2316 
2317 static int mt7915_mcu_start_firmware(struct mt7915_dev *dev, u32 addr,
2318 				     u32 option)
2319 {
2320 	struct {
2321 		__le32 option;
2322 		__le32 addr;
2323 	} req = {
2324 		.option = cpu_to_le32(option),
2325 		.addr = cpu_to_le32(addr),
2326 	};
2327 
2328 	return __mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_FW_START_REQ,
2329 				   &req, sizeof(req), true);
2330 }
2331 
2332 static int mt7915_mcu_restart(struct mt76_dev *dev)
2333 {
2334 	struct {
2335 		u8 power_mode;
2336 		u8 rsv[3];
2337 	} req = {
2338 		.power_mode = 1,
2339 	};
2340 
2341 	return __mt76_mcu_send_msg(dev, -MCU_CMD_NIC_POWER_CTRL, &req,
2342 				   sizeof(req), false);
2343 }
2344 
2345 static int mt7915_mcu_patch_sem_ctrl(struct mt7915_dev *dev, bool get)
2346 {
2347 	struct {
2348 		__le32 op;
2349 	} req = {
2350 		.op = cpu_to_le32(get ? PATCH_SEM_GET : PATCH_SEM_RELEASE),
2351 	};
2352 
2353 	return __mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_PATCH_SEM_CONTROL,
2354 				   &req, sizeof(req), true);
2355 }
2356 
2357 static int mt7915_mcu_start_patch(struct mt7915_dev *dev)
2358 {
2359 	struct {
2360 		u8 check_crc;
2361 		u8 reserved[3];
2362 	} req = {
2363 		.check_crc = 0,
2364 	};
2365 
2366 	return __mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_PATCH_FINISH_REQ,
2367 				   &req, sizeof(req), true);
2368 }
2369 
2370 static int mt7915_driver_own(struct mt7915_dev *dev)
2371 {
2372 	u32 reg = mt7915_reg_map_l1(dev, MT_TOP_LPCR_HOST_BAND0);
2373 
2374 	mt76_wr(dev, reg, MT_TOP_LPCR_HOST_DRV_OWN);
2375 	if (!mt76_poll_msec(dev, reg, MT_TOP_LPCR_HOST_FW_OWN,
2376 			    0, 500)) {
2377 		dev_err(dev->mt76.dev, "Timeout for driver own\n");
2378 		return -EIO;
2379 	}
2380 
2381 	return 0;
2382 }
2383 
2384 static int mt7915_mcu_init_download(struct mt7915_dev *dev, u32 addr,
2385 				    u32 len, u32 mode)
2386 {
2387 	struct {
2388 		__le32 addr;
2389 		__le32 len;
2390 		__le32 mode;
2391 	} req = {
2392 		.addr = cpu_to_le32(addr),
2393 		.len = cpu_to_le32(len),
2394 		.mode = cpu_to_le32(mode),
2395 	};
2396 	int attr;
2397 
2398 	if (req.addr == cpu_to_le32(MCU_PATCH_ADDRESS))
2399 		attr = -MCU_CMD_PATCH_START_REQ;
2400 	else
2401 		attr = -MCU_CMD_TARGET_ADDRESS_LEN_REQ;
2402 
2403 	return __mt76_mcu_send_msg(&dev->mt76, attr, &req, sizeof(req), true);
2404 }
2405 
2406 static int mt7915_load_patch(struct mt7915_dev *dev)
2407 {
2408 	const struct mt7915_patch_hdr *hdr;
2409 	const struct firmware *fw = NULL;
2410 	int i, ret, sem;
2411 
2412 	sem = mt7915_mcu_patch_sem_ctrl(dev, 1);
2413 	switch (sem) {
2414 	case PATCH_IS_DL:
2415 		return 0;
2416 	case PATCH_NOT_DL_SEM_SUCCESS:
2417 		break;
2418 	default:
2419 		dev_err(dev->mt76.dev, "Failed to get patch semaphore\n");
2420 		return -EAGAIN;
2421 	}
2422 
2423 	ret = request_firmware(&fw, MT7915_ROM_PATCH, dev->mt76.dev);
2424 	if (ret)
2425 		goto out;
2426 
2427 	if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
2428 		dev_err(dev->mt76.dev, "Invalid firmware\n");
2429 		ret = -EINVAL;
2430 		goto out;
2431 	}
2432 
2433 	hdr = (const struct mt7915_patch_hdr *)(fw->data);
2434 
2435 	dev_info(dev->mt76.dev, "HW/SW Version: 0x%x, Build Time: %.16s\n",
2436 		 be32_to_cpu(hdr->hw_sw_ver), hdr->build_date);
2437 
2438 	for (i = 0; i < be32_to_cpu(hdr->desc.n_region); i++) {
2439 		struct mt7915_patch_sec *sec;
2440 		const u8 *dl;
2441 		u32 len, addr;
2442 
2443 		sec = (struct mt7915_patch_sec *)(fw->data + sizeof(*hdr) +
2444 						  i * sizeof(*sec));
2445 		if ((be32_to_cpu(sec->type) & PATCH_SEC_TYPE_MASK) !=
2446 		    PATCH_SEC_TYPE_INFO) {
2447 			ret = -EINVAL;
2448 			goto out;
2449 		}
2450 
2451 		addr = be32_to_cpu(sec->info.addr);
2452 		len = be32_to_cpu(sec->info.len);
2453 		dl = fw->data + be32_to_cpu(sec->offs);
2454 
2455 		ret = mt7915_mcu_init_download(dev, addr, len,
2456 					       DL_MODE_NEED_RSP);
2457 		if (ret) {
2458 			dev_err(dev->mt76.dev, "Download request failed\n");
2459 			goto out;
2460 		}
2461 
2462 		ret = mt7915_mcu_send_firmware(dev, dl, len);
2463 		if (ret) {
2464 			dev_err(dev->mt76.dev, "Failed to send patch\n");
2465 			goto out;
2466 		}
2467 	}
2468 
2469 	ret = mt7915_mcu_start_patch(dev);
2470 	if (ret)
2471 		dev_err(dev->mt76.dev, "Failed to start patch\n");
2472 
2473 out:
2474 	sem = mt7915_mcu_patch_sem_ctrl(dev, 0);
2475 	switch (sem) {
2476 	case PATCH_REL_SEM_SUCCESS:
2477 		break;
2478 	default:
2479 		ret = -EAGAIN;
2480 		dev_err(dev->mt76.dev, "Failed to release patch semaphore\n");
2481 		goto out;
2482 	}
2483 	release_firmware(fw);
2484 
2485 	return ret;
2486 }
2487 
2488 static u32 mt7915_mcu_gen_dl_mode(u8 feature_set, bool is_wa)
2489 {
2490 	u32 ret = 0;
2491 
2492 	ret |= (feature_set & FW_FEATURE_SET_ENCRYPT) ?
2493 	       (DL_MODE_ENCRYPT | DL_MODE_RESET_SEC_IV) : 0;
2494 	ret |= FIELD_PREP(DL_MODE_KEY_IDX,
2495 			  FIELD_GET(FW_FEATURE_SET_KEY_IDX, feature_set));
2496 	ret |= DL_MODE_NEED_RSP;
2497 	ret |= is_wa ? DL_MODE_WORKING_PDA_CR4 : 0;
2498 
2499 	return ret;
2500 }
2501 
2502 static int
2503 mt7915_mcu_send_ram_firmware(struct mt7915_dev *dev,
2504 			     const struct mt7915_fw_trailer *hdr,
2505 			     const u8 *data, bool is_wa)
2506 {
2507 	int i, offset = 0;
2508 	u32 override = 0, option = 0;
2509 
2510 	for (i = 0; i < hdr->n_region; i++) {
2511 		const struct mt7915_fw_region *region;
2512 		int err;
2513 		u32 len, addr, mode;
2514 
2515 		region = (const struct mt7915_fw_region *)((const u8 *)hdr -
2516 			 (hdr->n_region - i) * sizeof(*region));
2517 		mode = mt7915_mcu_gen_dl_mode(region->feature_set, is_wa);
2518 		len = le32_to_cpu(region->len);
2519 		addr = le32_to_cpu(region->addr);
2520 
2521 		if (region->feature_set & FW_FEATURE_OVERRIDE_ADDR)
2522 			override = addr;
2523 
2524 		err = mt7915_mcu_init_download(dev, addr, len, mode);
2525 		if (err) {
2526 			dev_err(dev->mt76.dev, "Download request failed\n");
2527 			return err;
2528 		}
2529 
2530 		err = mt7915_mcu_send_firmware(dev, data + offset, len);
2531 		if (err) {
2532 			dev_err(dev->mt76.dev, "Failed to send firmware.\n");
2533 			return err;
2534 		}
2535 
2536 		offset += len;
2537 	}
2538 
2539 	if (override)
2540 		option |= FW_START_OVERRIDE;
2541 
2542 	if (is_wa)
2543 		option |= FW_START_WORKING_PDA_CR4;
2544 
2545 	return mt7915_mcu_start_firmware(dev, override, option);
2546 }
2547 
2548 static int mt7915_load_ram(struct mt7915_dev *dev)
2549 {
2550 	const struct mt7915_fw_trailer *hdr;
2551 	const struct firmware *fw;
2552 	int ret;
2553 
2554 	ret = request_firmware(&fw, MT7915_FIRMWARE_WM, dev->mt76.dev);
2555 	if (ret)
2556 		return ret;
2557 
2558 	if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
2559 		dev_err(dev->mt76.dev, "Invalid firmware\n");
2560 		ret = -EINVAL;
2561 		goto out;
2562 	}
2563 
2564 	hdr = (const struct mt7915_fw_trailer *)(fw->data + fw->size -
2565 					sizeof(*hdr));
2566 
2567 	dev_info(dev->mt76.dev, "WM Firmware Version: %.10s, Build Time: %.15s\n",
2568 		 hdr->fw_ver, hdr->build_date);
2569 
2570 	ret = mt7915_mcu_send_ram_firmware(dev, hdr, fw->data, false);
2571 	if (ret) {
2572 		dev_err(dev->mt76.dev, "Failed to start WM firmware\n");
2573 		goto out;
2574 	}
2575 
2576 	release_firmware(fw);
2577 
2578 	ret = request_firmware(&fw, MT7915_FIRMWARE_WA, dev->mt76.dev);
2579 	if (ret)
2580 		return ret;
2581 
2582 	if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
2583 		dev_err(dev->mt76.dev, "Invalid firmware\n");
2584 		ret = -EINVAL;
2585 		goto out;
2586 	}
2587 
2588 	hdr = (const struct mt7915_fw_trailer *)(fw->data + fw->size -
2589 					sizeof(*hdr));
2590 
2591 	dev_info(dev->mt76.dev, "WA Firmware Version: %.10s, Build Time: %.15s\n",
2592 		 hdr->fw_ver, hdr->build_date);
2593 
2594 	ret = mt7915_mcu_send_ram_firmware(dev, hdr, fw->data, true);
2595 	if (ret) {
2596 		dev_err(dev->mt76.dev, "Failed to start WA firmware\n");
2597 		goto out;
2598 	}
2599 
2600 	snprintf(dev->mt76.hw->wiphy->fw_version,
2601 		 sizeof(dev->mt76.hw->wiphy->fw_version),
2602 		 "%.10s-%.15s", hdr->fw_ver, hdr->build_date);
2603 
2604 out:
2605 	release_firmware(fw);
2606 
2607 	return ret;
2608 }
2609 
2610 static int mt7915_load_firmware(struct mt7915_dev *dev)
2611 {
2612 	int ret;
2613 	u32 val, reg = mt7915_reg_map_l1(dev, MT_TOP_MISC);
2614 
2615 	val = FIELD_PREP(MT_TOP_MISC_FW_STATE, FW_STATE_FW_DOWNLOAD);
2616 
2617 	if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE, val, 1000)) {
2618 		/* restart firmware once */
2619 		__mt76_mcu_restart(&dev->mt76);
2620 		if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
2621 				    val, 1000)) {
2622 			dev_err(dev->mt76.dev,
2623 				"Firmware is not ready for download\n");
2624 			return -EIO;
2625 		}
2626 	}
2627 
2628 	ret = mt7915_load_patch(dev);
2629 	if (ret)
2630 		return ret;
2631 
2632 	ret = mt7915_load_ram(dev);
2633 	if (ret)
2634 		return ret;
2635 
2636 	if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
2637 			    FIELD_PREP(MT_TOP_MISC_FW_STATE,
2638 				       FW_STATE_WACPU_RDY), 1000)) {
2639 		dev_err(dev->mt76.dev, "Timeout for initializing firmware\n");
2640 		return -EIO;
2641 	}
2642 
2643 	mt76_queue_tx_cleanup(dev, MT_TXQ_FWDL, false);
2644 
2645 	dev_dbg(dev->mt76.dev, "Firmware init done\n");
2646 
2647 	return 0;
2648 }
2649 
2650 int mt7915_mcu_fw_log_2_host(struct mt7915_dev *dev, u8 ctrl)
2651 {
2652 	struct {
2653 		u8 ctrl_val;
2654 		u8 pad[3];
2655 	} data = {
2656 		.ctrl_val = ctrl
2657 	};
2658 
2659 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_FW_LOG_2_HOST,
2660 				   &data, sizeof(data), true);
2661 }
2662 
2663 int mt7915_mcu_fw_dbg_ctrl(struct mt7915_dev *dev, u32 module, u8 level)
2664 {
2665 	struct {
2666 		u8 ver;
2667 		u8 pad;
2668 		u16 len;
2669 		u8 level;
2670 		u8 rsv[3];
2671 		__le32 module_idx;
2672 	} data = {
2673 		.module_idx = cpu_to_le32(module),
2674 		.level = level,
2675 	};
2676 
2677 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_FW_DBG_CTRL,
2678 				   &data, sizeof(data), false);
2679 }
2680 
2681 int mt7915_mcu_init(struct mt7915_dev *dev)
2682 {
2683 	static const struct mt76_mcu_ops mt7915_mcu_ops = {
2684 		.headroom = sizeof(struct mt7915_mcu_txd),
2685 		.mcu_skb_send_msg = mt7915_mcu_send_message,
2686 		.mcu_send_msg = mt7915_mcu_msg_send,
2687 		.mcu_restart = mt7915_mcu_restart,
2688 	};
2689 	int ret;
2690 
2691 	dev->mt76.mcu_ops = &mt7915_mcu_ops,
2692 
2693 	ret = mt7915_driver_own(dev);
2694 	if (ret)
2695 		return ret;
2696 
2697 	ret = mt7915_load_firmware(dev);
2698 	if (ret)
2699 		return ret;
2700 
2701 	set_bit(MT76_STATE_MCU_RUNNING, &dev->mphy.state);
2702 	mt7915_mcu_fw_log_2_host(dev, 0);
2703 
2704 	return 0;
2705 }
2706 
2707 void mt7915_mcu_exit(struct mt7915_dev *dev)
2708 {
2709 	u32 reg = mt7915_reg_map_l1(dev, MT_TOP_MISC);
2710 
2711 	__mt76_mcu_restart(&dev->mt76);
2712 	if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
2713 			    FIELD_PREP(MT_TOP_MISC_FW_STATE,
2714 				       FW_STATE_FW_DOWNLOAD), 1000)) {
2715 		dev_err(dev->mt76.dev, "Failed to exit mcu\n");
2716 		return;
2717 	}
2718 
2719 	reg = mt7915_reg_map_l1(dev, MT_TOP_LPCR_HOST_BAND0);
2720 	mt76_wr(dev, reg, MT_TOP_LPCR_HOST_FW_OWN);
2721 	skb_queue_purge(&dev->mt76.mcu.res_q);
2722 }
2723 
2724 int mt7915_mcu_set_mac(struct mt7915_dev *dev, int band,
2725 		       bool enable, bool hdr_trans)
2726 {
2727 	struct {
2728 		u8 operation;
2729 		u8 enable;
2730 		u8 check_bssid;
2731 		u8 insert_vlan;
2732 		u8 remove_vlan;
2733 		u8 tid;
2734 		u8 mode;
2735 		u8 rsv;
2736 	} __packed req_trans = {
2737 		.enable = hdr_trans,
2738 	};
2739 	struct {
2740 		u8 enable;
2741 		u8 band;
2742 		u8 rsv[2];
2743 	} __packed req_mac = {
2744 		.enable = enable,
2745 		.band = band,
2746 	};
2747 	int ret;
2748 
2749 	ret = __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_RX_HDR_TRANS,
2750 				  &req_trans, sizeof(req_trans), false);
2751 	if (ret)
2752 		return ret;
2753 
2754 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_MAC_INIT_CTRL,
2755 				   &req_mac, sizeof(req_mac), true);
2756 }
2757 
2758 int mt7915_mcu_set_scs(struct mt7915_dev *dev, u8 band, bool enable)
2759 {
2760 	struct {
2761 		__le32 cmd;
2762 		u8 band;
2763 		u8 enable;
2764 	} __packed req = {
2765 		.cmd = cpu_to_le32(SCS_ENABLE),
2766 		.band = band,
2767 		.enable = enable + 1,
2768 	};
2769 
2770 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SCS_CTRL, &req,
2771 				   sizeof(req), false);
2772 }
2773 
2774 int mt7915_mcu_set_rts_thresh(struct mt7915_phy *phy, u32 val)
2775 {
2776 	struct mt7915_dev *dev = phy->dev;
2777 	struct {
2778 		u8 prot_idx;
2779 		u8 band;
2780 		u8 rsv[2];
2781 		__le32 len_thresh;
2782 		__le32 pkt_thresh;
2783 	} __packed req = {
2784 		.prot_idx = 1,
2785 		.band = phy != &dev->phy,
2786 		.len_thresh = cpu_to_le32(val),
2787 		.pkt_thresh = cpu_to_le32(0x2),
2788 	};
2789 
2790 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_PROTECT_CTRL,
2791 				   &req, sizeof(req), true);
2792 }
2793 
2794 int mt7915_mcu_set_tx(struct mt7915_dev *dev, struct ieee80211_vif *vif)
2795 {
2796 #define WMM_AIFS_SET		BIT(0)
2797 #define WMM_CW_MIN_SET		BIT(1)
2798 #define WMM_CW_MAX_SET		BIT(2)
2799 #define WMM_TXOP_SET		BIT(3)
2800 #define WMM_PARAM_SET		GENMASK(3, 0)
2801 #define TX_CMD_MODE		1
2802 	struct edca {
2803 		u8 queue;
2804 		u8 set;
2805 		u8 aifs;
2806 		u8 cw_min;
2807 		__le16 cw_max;
2808 		__le16 txop;
2809 	};
2810 	struct mt7915_mcu_tx {
2811 		u8 total;
2812 		u8 action;
2813 		u8 valid;
2814 		u8 mode;
2815 
2816 		struct edca edca[IEEE80211_NUM_ACS];
2817 	} __packed req = {
2818 		.valid = true,
2819 		.mode = TX_CMD_MODE,
2820 		.total = IEEE80211_NUM_ACS,
2821 	};
2822 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2823 	int ac;
2824 
2825 	for (ac = 0; ac < IEEE80211_NUM_ACS; ac++) {
2826 		struct edca *e = &req.edca[ac];
2827 
2828 		e->queue = ac + mvif->wmm_idx * MT7915_MAX_WMM_SETS;
2829 		e->aifs = mvif->wmm[ac].aifs;
2830 		e->txop = cpu_to_le16(mvif->wmm[ac].txop);
2831 
2832 		if (mvif->wmm[ac].cw_min)
2833 			e->cw_min = fls(mvif->wmm[ac].cw_max);
2834 		else
2835 			e->cw_min = 5;
2836 
2837 		if (mvif->wmm[ac].cw_max)
2838 			e->cw_max = cpu_to_le16(fls(mvif->wmm[ac].cw_max));
2839 		else
2840 			e->cw_max = cpu_to_le16(10);
2841 	}
2842 
2843 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EDCA_UPDATE,
2844 				  &req, sizeof(req), true);
2845 }
2846 
2847 int mt7915_mcu_set_pm(struct mt7915_dev *dev, int band, int enter)
2848 {
2849 #define ENTER_PM_STATE		1
2850 #define EXIT_PM_STATE		2
2851 	struct {
2852 		u8 pm_number;
2853 		u8 pm_state;
2854 		u8 bssid[ETH_ALEN];
2855 		u8 dtim_period;
2856 		u8 wlan_idx_lo;
2857 		__le16 bcn_interval;
2858 		__le32 aid;
2859 		__le32 rx_filter;
2860 		u8 band_idx;
2861 		u8 wlan_idx_hi;
2862 		u8 rsv[2];
2863 		__le32 feature;
2864 		u8 omac_idx;
2865 		u8 wmm_idx;
2866 		u8 bcn_loss_cnt;
2867 		u8 bcn_sp_duration;
2868 	} __packed req = {
2869 		.pm_number = 5,
2870 		.pm_state = (enter) ? ENTER_PM_STATE : EXIT_PM_STATE,
2871 		.band_idx = band,
2872 	};
2873 
2874 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_PM_STATE_CTRL,
2875 				   &req, sizeof(req), true);
2876 }
2877 
2878 int mt7915_mcu_rdd_cmd(struct mt7915_dev *dev,
2879 		       enum mt7915_rdd_cmd cmd, u8 index,
2880 		       u8 rx_sel, u8 val)
2881 {
2882 	struct {
2883 		u8 ctrl;
2884 		u8 rdd_idx;
2885 		u8 rdd_rx_sel;
2886 		u8 val;
2887 		u8 rsv[4];
2888 	} __packed req = {
2889 		.ctrl = cmd,
2890 		.rdd_idx = index,
2891 		.rdd_rx_sel = rx_sel,
2892 		.val = val,
2893 	};
2894 
2895 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_CTRL,
2896 				   &req, sizeof(req), true);
2897 }
2898 
2899 int mt7915_mcu_set_fcc5_lpn(struct mt7915_dev *dev, int val)
2900 {
2901 	struct {
2902 		u32 tag;
2903 		u16 min_lpn;
2904 		u8 rsv[2];
2905 	} __packed req = {
2906 		.tag = 0x1,
2907 		.min_lpn = val,
2908 	};
2909 
2910 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_TH,
2911 				   &req, sizeof(req), true);
2912 }
2913 
2914 int mt7915_mcu_set_pulse_th(struct mt7915_dev *dev,
2915 			    const struct mt7915_dfs_pulse *pulse)
2916 {
2917 	struct {
2918 		u32 tag;
2919 		struct mt7915_dfs_pulse pulse;
2920 	} __packed req = {
2921 		.tag = 0x3,
2922 	};
2923 
2924 	memcpy(&req.pulse, pulse, sizeof(*pulse));
2925 
2926 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_TH,
2927 				   &req, sizeof(req), true);
2928 }
2929 
2930 int mt7915_mcu_set_radar_th(struct mt7915_dev *dev, int index,
2931 			    const struct mt7915_dfs_pattern *pattern)
2932 {
2933 	struct {
2934 		u32 tag;
2935 		u16 radar_type;
2936 		struct mt7915_dfs_pattern pattern;
2937 	} __packed req = {
2938 		.tag = 0x2,
2939 		.radar_type = index,
2940 	};
2941 
2942 	memcpy(&req.pattern, pattern, sizeof(*pattern));
2943 
2944 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_TH,
2945 				   &req, sizeof(req), true);
2946 }
2947 
2948 int mt7915_mcu_set_chan_info(struct mt7915_phy *phy, int cmd)
2949 {
2950 	struct mt7915_dev *dev = phy->dev;
2951 	struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
2952 	int freq1 = chandef->center_freq1;
2953 	struct {
2954 		u8 control_ch;
2955 		u8 center_ch;
2956 		u8 bw;
2957 		u8 tx_streams_num;
2958 		u8 rx_streams;	/* mask or num */
2959 		u8 switch_reason;
2960 		u8 band_idx;
2961 		u8 center_ch2;	/* for 80+80 only */
2962 		__le16 cac_case;
2963 		u8 channel_band;
2964 		u8 rsv0;
2965 		__le32 outband_freq;
2966 		u8 txpower_drop;
2967 		u8 ap_bw;
2968 		u8 ap_center_ch;
2969 		u8 rsv1[57];
2970 	} __packed req = {
2971 		.control_ch = chandef->chan->hw_value,
2972 		.center_ch = ieee80211_frequency_to_channel(freq1),
2973 		.bw = mt7915_mcu_chan_bw(chandef),
2974 		.tx_streams_num = hweight8(phy->mt76->antenna_mask),
2975 		.rx_streams = phy->chainmask,
2976 		.band_idx = phy != &dev->phy,
2977 		.channel_band = chandef->chan->band,
2978 	};
2979 
2980 	if ((chandef->chan->flags & IEEE80211_CHAN_RADAR) &&
2981 	    chandef->chan->dfs_state != NL80211_DFS_AVAILABLE)
2982 		req.switch_reason = CH_SWITCH_DFS;
2983 	else
2984 		req.switch_reason = CH_SWITCH_NORMAL;
2985 
2986 	if (cmd == MCU_EXT_CMD_CHANNEL_SWITCH)
2987 		req.rx_streams = hweight8(req.rx_streams);
2988 
2989 	if (chandef->width == NL80211_CHAN_WIDTH_80P80) {
2990 		int freq2 = chandef->center_freq2;
2991 
2992 		req.center_ch2 = ieee80211_frequency_to_channel(freq2);
2993 	}
2994 
2995 	return __mt76_mcu_send_msg(&dev->mt76, cmd, &req, sizeof(req), true);
2996 }
2997 
2998 int mt7915_mcu_set_eeprom(struct mt7915_dev *dev)
2999 {
3000 	struct req_hdr {
3001 		u8 buffer_mode;
3002 		u8 format;
3003 		__le16 len;
3004 	} __packed req = {
3005 		.buffer_mode = EE_MODE_EFUSE,
3006 		.format = EE_FORMAT_WHOLE,
3007 	};
3008 
3009 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EFUSE_BUFFER_MODE,
3010 				   &req, sizeof(req), true);
3011 }
3012 
3013 int mt7915_mcu_get_eeprom(struct mt7915_dev *dev, u32 offset)
3014 {
3015 	struct mt7915_mcu_eeprom_info req = {
3016 		.addr = cpu_to_le32(round_down(offset, 16)),
3017 	};
3018 
3019 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EFUSE_ACCESS, &req,
3020 				   sizeof(req), true);
3021 }
3022 
3023 int mt7915_mcu_get_temperature(struct mt7915_dev *dev, int index)
3024 {
3025 	struct {
3026 		u8 ctrl_id;
3027 		u8 action;
3028 		u8 band;
3029 		u8 rsv[5];
3030 	} req = {
3031 		.ctrl_id = THERMAL_SENSOR_TEMP_QUERY,
3032 		.action = index,
3033 	};
3034 
3035 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_THERMAL_CTRL, &req,
3036 				   sizeof(req), true);
3037 }
3038 
3039 int mt7915_mcu_get_rate_info(struct mt7915_dev *dev, u32 cmd, u16 wlan_idx)
3040 {
3041 	struct {
3042 		__le32 cmd;
3043 		__le16 wlan_idx;
3044 		__le16 ru_idx;
3045 		__le16 direction;
3046 		__le16 dump_group;
3047 	} req = {
3048 		.cmd = cpu_to_le32(cmd),
3049 		.wlan_idx = cpu_to_le16(wlan_idx),
3050 		.dump_group = cpu_to_le16(1),
3051 	};
3052 
3053 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_RATE_CTRL, &req,
3054 				   sizeof(req), false);
3055 }
3056 
3057 int mt7915_mcu_set_sku(struct mt7915_phy *phy)
3058 {
3059 	struct mt7915_dev *dev = phy->dev;
3060 	struct mt76_phy *mphy = phy->mt76;
3061 	struct ieee80211_hw *hw = mphy->hw;
3062 	struct mt7915_sku_val {
3063 		u8 format_id;
3064 		u8 limit_type;
3065 		u8 dbdc_idx;
3066 		s8 val[MT7915_SKU_RATE_NUM];
3067 	} __packed req = {
3068 		.format_id = 4,
3069 		.dbdc_idx = phy != &dev->phy,
3070 	};
3071 	int i;
3072 	s8 *delta;
3073 
3074 	delta = dev->rate_power[mphy->chandef.chan->band];
3075 	mphy->txpower_cur = hw->conf.power_level * 2 +
3076 			    delta[MT7915_SKU_MAX_DELTA_IDX];
3077 
3078 	for (i = 0; i < MT7915_SKU_RATE_NUM; i++)
3079 		req.val[i] = hw->conf.power_level * 2 + delta[i];
3080 
3081 	return __mt76_mcu_send_msg(&dev->mt76,
3082 				   MCU_EXT_CMD_TX_POWER_FEATURE_CTRL,
3083 				   &req, sizeof(req), true);
3084 }
3085 
3086 int mt7915_mcu_set_sku_en(struct mt7915_phy *phy, bool enable)
3087 {
3088 	struct mt7915_dev *dev = phy->dev;
3089 	struct mt7915_sku {
3090 		u8 format_id;
3091 		u8 sku_enable;
3092 		u8 dbdc_idx;
3093 		u8 rsv;
3094 	} __packed req = {
3095 		.format_id = 0,
3096 		.dbdc_idx = phy != &dev->phy,
3097 		.sku_enable = enable,
3098 	};
3099 
3100 	return __mt76_mcu_send_msg(&dev->mt76,
3101 				   MCU_EXT_CMD_TX_POWER_FEATURE_CTRL,
3102 				   &req, sizeof(req), true);
3103 }
3104 
3105 int mt7915_mcu_set_ser(struct mt7915_dev *dev, u8 action, u8 set, u8 band)
3106 {
3107 	struct {
3108 		u8 action;
3109 		u8 set;
3110 		u8 band;
3111 		u8 rsv;
3112 	} req = {
3113 		.action = action,
3114 		.set = set,
3115 		.band = band,
3116 	};
3117 
3118 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_SER_TRIGGER,
3119 				   &req, sizeof(req), false);
3120 }
3121 
3122 int mt7915_mcu_set_txbf_type(struct mt7915_dev *dev)
3123 {
3124 #define MT_BF_TYPE_UPDATE		20
3125 	struct {
3126 		u8 action;
3127 		bool ebf;
3128 		bool ibf;
3129 		u8 rsv;
3130 	} __packed req = {
3131 		.action = MT_BF_TYPE_UPDATE,
3132 		.ebf = true,
3133 		.ibf = false,
3134 	};
3135 
3136 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_TXBF_ACTION,
3137 				   &req, sizeof(req), true);
3138 }
3139 
3140 int mt7915_mcu_set_txbf_sounding(struct mt7915_dev *dev)
3141 {
3142 #define MT_BF_PROCESSING		4
3143 	struct {
3144 		u8 action;
3145 		u8 snd_mode;
3146 		u8 sta_num;
3147 		u8 rsv;
3148 		u8 wlan_idx[4];
3149 		__le32 snd_period;	/* ms */
3150 	} __packed req = {
3151 		.action = true,
3152 		.snd_mode = MT_BF_PROCESSING,
3153 	};
3154 
3155 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_TXBF_ACTION,
3156 				   &req, sizeof(req), true);
3157 }
3158 
3159 int mt7915_mcu_add_obss_spr(struct mt7915_dev *dev, struct ieee80211_vif *vif,
3160 			    bool enable)
3161 {
3162 #define MT_SPR_ENABLE		1
3163 	struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
3164 	struct {
3165 		u8 action;
3166 		u8 arg_num;
3167 		u8 band_idx;
3168 		u8 status;
3169 		u8 drop_tx_idx;
3170 		u8 sta_idx;	/* 256 sta */
3171 		u8 rsv[2];
3172 		u32 val;
3173 	} __packed req = {
3174 		.action = MT_SPR_ENABLE,
3175 		.arg_num = 1,
3176 		.band_idx = mvif->band_idx,
3177 		.val = enable,
3178 	};
3179 
3180 	return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_SPR,
3181 				   &req, sizeof(req), true);
3182 }
3183