1 // SPDX-License-Identifier: ISC
2 /* Copyright (C) 2020 MediaTek Inc. */
3 
4 #include <linux/firmware.h>
5 #include <linux/fs.h>
6 #include "mt7921.h"
7 #include "mcu.h"
8 #include "mac.h"
9 
10 struct mt7921_patch_hdr {
11 	char build_date[16];
12 	char platform[4];
13 	__be32 hw_sw_ver;
14 	__be32 patch_ver;
15 	__be16 checksum;
16 	u16 reserved;
17 	struct {
18 		__be32 patch_ver;
19 		__be32 subsys;
20 		__be32 feature;
21 		__be32 n_region;
22 		__be32 crc;
23 		u32 reserved[11];
24 	} desc;
25 } __packed;
26 
27 struct mt7921_patch_sec {
28 	__be32 type;
29 	__be32 offs;
30 	__be32 size;
31 	union {
32 		__be32 spec[13];
33 		struct {
34 			__be32 addr;
35 			__be32 len;
36 			__be32 sec_key_idx;
37 			__be32 align_len;
38 			u32 reserved[9];
39 		} info;
40 	};
41 } __packed;
42 
43 struct mt7921_fw_trailer {
44 	u8 chip_id;
45 	u8 eco_code;
46 	u8 n_region;
47 	u8 format_ver;
48 	u8 format_flag;
49 	u8 reserved[2];
50 	char fw_ver[10];
51 	char build_date[15];
52 	u32 crc;
53 } __packed;
54 
55 struct mt7921_fw_region {
56 	__le32 decomp_crc;
57 	__le32 decomp_len;
58 	__le32 decomp_blk_sz;
59 	u8 reserved[4];
60 	__le32 addr;
61 	__le32 len;
62 	u8 feature_set;
63 	u8 reserved1[15];
64 } __packed;
65 
66 #define MT_STA_BFER			BIT(0)
67 #define MT_STA_BFEE			BIT(1)
68 
69 #define FW_FEATURE_SET_ENCRYPT		BIT(0)
70 #define FW_FEATURE_SET_KEY_IDX		GENMASK(2, 1)
71 #define FW_FEATURE_ENCRY_MODE		BIT(4)
72 #define FW_FEATURE_OVERRIDE_ADDR	BIT(5)
73 
74 #define DL_MODE_ENCRYPT			BIT(0)
75 #define DL_MODE_KEY_IDX			GENMASK(2, 1)
76 #define DL_MODE_RESET_SEC_IV		BIT(3)
77 #define DL_MODE_WORKING_PDA_CR4		BIT(4)
78 #define DL_CONFIG_ENCRY_MODE_SEL	BIT(6)
79 #define DL_MODE_NEED_RSP		BIT(31)
80 
81 #define FW_START_OVERRIDE		BIT(0)
82 #define FW_START_WORKING_PDA_CR4	BIT(2)
83 
84 #define PATCH_SEC_TYPE_MASK		GENMASK(15, 0)
85 #define PATCH_SEC_TYPE_INFO		0x2
86 
87 #define to_wcid_lo(id)			FIELD_GET(GENMASK(7, 0), (u16)id)
88 #define to_wcid_hi(id)			FIELD_GET(GENMASK(9, 8), (u16)id)
89 
90 static enum mt7921_cipher_type
91 mt7921_mcu_get_cipher(int cipher)
92 {
93 	switch (cipher) {
94 	case WLAN_CIPHER_SUITE_WEP40:
95 		return MT_CIPHER_WEP40;
96 	case WLAN_CIPHER_SUITE_WEP104:
97 		return MT_CIPHER_WEP104;
98 	case WLAN_CIPHER_SUITE_TKIP:
99 		return MT_CIPHER_TKIP;
100 	case WLAN_CIPHER_SUITE_AES_CMAC:
101 		return MT_CIPHER_BIP_CMAC_128;
102 	case WLAN_CIPHER_SUITE_CCMP:
103 		return MT_CIPHER_AES_CCMP;
104 	case WLAN_CIPHER_SUITE_CCMP_256:
105 		return MT_CIPHER_CCMP_256;
106 	case WLAN_CIPHER_SUITE_GCMP:
107 		return MT_CIPHER_GCMP;
108 	case WLAN_CIPHER_SUITE_GCMP_256:
109 		return MT_CIPHER_GCMP_256;
110 	case WLAN_CIPHER_SUITE_SMS4:
111 		return MT_CIPHER_WAPI;
112 	default:
113 		return MT_CIPHER_NONE;
114 	}
115 }
116 
117 static u8 mt7921_mcu_chan_bw(struct cfg80211_chan_def *chandef)
118 {
119 	static const u8 width_to_bw[] = {
120 		[NL80211_CHAN_WIDTH_40] = CMD_CBW_40MHZ,
121 		[NL80211_CHAN_WIDTH_80] = CMD_CBW_80MHZ,
122 		[NL80211_CHAN_WIDTH_80P80] = CMD_CBW_8080MHZ,
123 		[NL80211_CHAN_WIDTH_160] = CMD_CBW_160MHZ,
124 		[NL80211_CHAN_WIDTH_5] = CMD_CBW_5MHZ,
125 		[NL80211_CHAN_WIDTH_10] = CMD_CBW_10MHZ,
126 		[NL80211_CHAN_WIDTH_20] = CMD_CBW_20MHZ,
127 		[NL80211_CHAN_WIDTH_20_NOHT] = CMD_CBW_20MHZ,
128 	};
129 
130 	if (chandef->width >= ARRAY_SIZE(width_to_bw))
131 		return 0;
132 
133 	return width_to_bw[chandef->width];
134 }
135 
136 static int
137 mt7921_mcu_parse_eeprom(struct mt76_dev *dev, struct sk_buff *skb)
138 {
139 	struct mt7921_mcu_eeprom_info *res;
140 	u8 *buf;
141 
142 	if (!skb)
143 		return -EINVAL;
144 
145 	skb_pull(skb, sizeof(struct mt7921_mcu_rxd));
146 
147 	res = (struct mt7921_mcu_eeprom_info *)skb->data;
148 	buf = dev->eeprom.data + le32_to_cpu(res->addr);
149 	memcpy(buf, res->data, 16);
150 
151 	return 0;
152 }
153 
154 static int
155 mt7921_mcu_parse_response(struct mt76_dev *mdev, int cmd,
156 			  struct sk_buff *skb, int seq)
157 {
158 	struct mt7921_mcu_rxd *rxd;
159 	int ret = 0;
160 
161 	if (!skb) {
162 		dev_err(mdev->dev, "Message %d (seq %d) timeout\n",
163 			cmd, seq);
164 		return -ETIMEDOUT;
165 	}
166 
167 	rxd = (struct mt7921_mcu_rxd *)skb->data;
168 	if (seq != rxd->seq)
169 		return -EAGAIN;
170 
171 	switch (cmd) {
172 	case MCU_CMD_PATCH_SEM_CONTROL:
173 		skb_pull(skb, sizeof(*rxd) - 4);
174 		ret = *skb->data;
175 		break;
176 	case MCU_EXT_CMD_GET_TEMP:
177 		skb_pull(skb, sizeof(*rxd) + 4);
178 		ret = le32_to_cpu(*(__le32 *)skb->data);
179 		break;
180 	case MCU_EXT_CMD_EFUSE_ACCESS:
181 		ret = mt7921_mcu_parse_eeprom(mdev, skb);
182 		break;
183 	case MCU_UNI_CMD_DEV_INFO_UPDATE:
184 	case MCU_UNI_CMD_BSS_INFO_UPDATE:
185 	case MCU_UNI_CMD_STA_REC_UPDATE:
186 	case MCU_UNI_CMD_HIF_CTRL:
187 	case MCU_UNI_CMD_OFFLOAD:
188 	case MCU_UNI_CMD_SUSPEND: {
189 		struct mt7921_mcu_uni_event *event;
190 
191 		skb_pull(skb, sizeof(*rxd));
192 		event = (struct mt7921_mcu_uni_event *)skb->data;
193 		ret = le32_to_cpu(event->status);
194 		break;
195 	}
196 	case MCU_CMD_REG_READ: {
197 		struct mt7921_mcu_reg_event *event;
198 
199 		skb_pull(skb, sizeof(*rxd));
200 		event = (struct mt7921_mcu_reg_event *)skb->data;
201 		ret = (int)le32_to_cpu(event->val);
202 		break;
203 	}
204 	default:
205 		skb_pull(skb, sizeof(struct mt7921_mcu_rxd));
206 		break;
207 	}
208 
209 	return ret;
210 }
211 
212 static int
213 mt7921_mcu_send_message(struct mt76_dev *mdev, struct sk_buff *skb,
214 			int cmd, int *wait_seq)
215 {
216 	struct mt7921_dev *dev = container_of(mdev, struct mt7921_dev, mt76);
217 	int txd_len, mcu_cmd = cmd & MCU_CMD_MASK;
218 	enum mt76_mcuq_id txq = MT_MCUQ_WM;
219 	struct mt7921_uni_txd *uni_txd;
220 	struct mt7921_mcu_txd *mcu_txd;
221 	__le32 *txd;
222 	u32 val;
223 	u8 seq;
224 
225 	/* TODO: make dynamic based on msg type */
226 	mdev->mcu.timeout = 20 * HZ;
227 
228 	seq = ++dev->mt76.mcu.msg_seq & 0xf;
229 	if (!seq)
230 		seq = ++dev->mt76.mcu.msg_seq & 0xf;
231 
232 	if (cmd == MCU_CMD_FW_SCATTER) {
233 		txq = MT_MCUQ_FWDL;
234 		goto exit;
235 	}
236 
237 	txd_len = cmd & MCU_UNI_PREFIX ? sizeof(*uni_txd) : sizeof(*mcu_txd);
238 	txd = (__le32 *)skb_push(skb, txd_len);
239 
240 	val = FIELD_PREP(MT_TXD0_TX_BYTES, skb->len) |
241 	      FIELD_PREP(MT_TXD0_PKT_FMT, MT_TX_TYPE_CMD) |
242 	      FIELD_PREP(MT_TXD0_Q_IDX, MT_TX_MCU_PORT_RX_Q0);
243 	txd[0] = cpu_to_le32(val);
244 
245 	val = MT_TXD1_LONG_FORMAT |
246 	      FIELD_PREP(MT_TXD1_HDR_FORMAT, MT_HDR_FORMAT_CMD);
247 	txd[1] = cpu_to_le32(val);
248 
249 	if (cmd & MCU_UNI_PREFIX) {
250 		uni_txd = (struct mt7921_uni_txd *)txd;
251 		uni_txd->len = cpu_to_le16(skb->len - sizeof(uni_txd->txd));
252 		uni_txd->option = MCU_CMD_UNI_EXT_ACK;
253 		uni_txd->cid = cpu_to_le16(mcu_cmd);
254 		uni_txd->s2d_index = MCU_S2D_H2N;
255 		uni_txd->pkt_type = MCU_PKT_ID;
256 		uni_txd->seq = seq;
257 
258 		goto exit;
259 	}
260 
261 	mcu_txd = (struct mt7921_mcu_txd *)txd;
262 	mcu_txd->len = cpu_to_le16(skb->len - sizeof(mcu_txd->txd));
263 	mcu_txd->pq_id = cpu_to_le16(MCU_PQ_ID(MT_TX_PORT_IDX_MCU,
264 					       MT_TX_MCU_PORT_RX_Q0));
265 	mcu_txd->pkt_type = MCU_PKT_ID;
266 	mcu_txd->seq = seq;
267 
268 	switch (cmd & ~MCU_CMD_MASK) {
269 	case MCU_FW_PREFIX:
270 		mcu_txd->set_query = MCU_Q_NA;
271 		mcu_txd->cid = mcu_cmd;
272 		break;
273 	case MCU_CE_PREFIX:
274 		if (cmd & MCU_QUERY_MASK)
275 			mcu_txd->set_query = MCU_Q_QUERY;
276 		else
277 			mcu_txd->set_query = MCU_Q_SET;
278 		mcu_txd->cid = mcu_cmd;
279 		break;
280 	default:
281 		mcu_txd->cid = MCU_CMD_EXT_CID;
282 		if (cmd & MCU_QUERY_PREFIX || cmd == MCU_EXT_CMD_EFUSE_ACCESS)
283 			mcu_txd->set_query = MCU_Q_QUERY;
284 		else
285 			mcu_txd->set_query = MCU_Q_SET;
286 		mcu_txd->ext_cid = mcu_cmd;
287 		mcu_txd->ext_cid_ack = 1;
288 		break;
289 	}
290 
291 	mcu_txd->s2d_index = MCU_S2D_H2N;
292 	WARN_ON(cmd == MCU_EXT_CMD_EFUSE_ACCESS &&
293 		mcu_txd->set_query != MCU_Q_QUERY);
294 
295 exit:
296 	if (wait_seq)
297 		*wait_seq = seq;
298 
299 	return mt76_tx_queue_skb_raw(dev, mdev->q_mcu[txq], skb, 0);
300 }
301 
302 static void
303 mt7921_mcu_tx_rate_parse(struct mt76_phy *mphy,
304 			 struct mt7921_mcu_peer_cap *peer,
305 			 struct rate_info *rate, u16 r)
306 {
307 	struct ieee80211_supported_band *sband;
308 	u16 flags = 0;
309 	u8 txmode = FIELD_GET(MT_WTBL_RATE_TX_MODE, r);
310 	u8 gi = 0;
311 	u8 bw = 0;
312 
313 	rate->mcs = FIELD_GET(MT_WTBL_RATE_MCS, r);
314 	rate->nss = FIELD_GET(MT_WTBL_RATE_NSS, r) + 1;
315 
316 	switch (peer->bw) {
317 	case IEEE80211_STA_RX_BW_160:
318 		gi = peer->g16;
319 		break;
320 	case IEEE80211_STA_RX_BW_80:
321 		gi = peer->g8;
322 		break;
323 	case IEEE80211_STA_RX_BW_40:
324 		gi = peer->g4;
325 		break;
326 	default:
327 		gi = peer->g2;
328 		break;
329 	}
330 
331 	gi = txmode >= MT_PHY_TYPE_HE_SU ?
332 		FIELD_GET(MT_WTBL_RATE_HE_GI, gi) :
333 		FIELD_GET(MT_WTBL_RATE_GI, gi);
334 
335 	switch (txmode) {
336 	case MT_PHY_TYPE_CCK:
337 	case MT_PHY_TYPE_OFDM:
338 		if (mphy->chandef.chan->band == NL80211_BAND_5GHZ)
339 			sband = &mphy->sband_5g.sband;
340 		else
341 			sband = &mphy->sband_2g.sband;
342 
343 		rate->legacy = sband->bitrates[rate->mcs].bitrate;
344 		break;
345 	case MT_PHY_TYPE_HT:
346 	case MT_PHY_TYPE_HT_GF:
347 		flags |= RATE_INFO_FLAGS_MCS;
348 
349 		if (gi)
350 			flags |= RATE_INFO_FLAGS_SHORT_GI;
351 		break;
352 	case MT_PHY_TYPE_VHT:
353 		flags |= RATE_INFO_FLAGS_VHT_MCS;
354 
355 		if (gi)
356 			flags |= RATE_INFO_FLAGS_SHORT_GI;
357 		break;
358 	case MT_PHY_TYPE_HE_SU:
359 	case MT_PHY_TYPE_HE_EXT_SU:
360 	case MT_PHY_TYPE_HE_TB:
361 	case MT_PHY_TYPE_HE_MU:
362 		rate->he_gi = gi;
363 		rate->he_dcm = FIELD_GET(MT_RA_RATE_DCM_EN, r);
364 
365 		flags |= RATE_INFO_FLAGS_HE_MCS;
366 		break;
367 	default:
368 		break;
369 	}
370 	rate->flags = flags;
371 
372 	bw = mt7921_mcu_chan_bw(&mphy->chandef) - FIELD_GET(MT_RA_RATE_BW, r);
373 
374 	switch (bw) {
375 	case IEEE80211_STA_RX_BW_160:
376 		rate->bw = RATE_INFO_BW_160;
377 		break;
378 	case IEEE80211_STA_RX_BW_80:
379 		rate->bw = RATE_INFO_BW_80;
380 		break;
381 	case IEEE80211_STA_RX_BW_40:
382 		rate->bw = RATE_INFO_BW_40;
383 		break;
384 	default:
385 		rate->bw = RATE_INFO_BW_20;
386 		break;
387 	}
388 }
389 
390 static void
391 mt7921_mcu_tx_rate_report(struct mt7921_dev *dev, struct sk_buff *skb,
392 			  u16 wlan_idx)
393 {
394 	struct mt7921_mcu_wlan_info_event *wtbl_info =
395 		(struct mt7921_mcu_wlan_info_event *)(skb->data);
396 	struct rate_info rate = {};
397 	u8 curr_idx = wtbl_info->rate_info.rate_idx;
398 	u16 curr = le16_to_cpu(wtbl_info->rate_info.rate[curr_idx]);
399 	struct mt7921_mcu_peer_cap peer = wtbl_info->peer_cap;
400 	struct mt76_phy *mphy = &dev->mphy;
401 	struct mt7921_sta_stats *stats;
402 	struct mt7921_sta *msta;
403 	struct mt76_wcid *wcid;
404 
405 	if (wlan_idx >= MT76_N_WCIDS)
406 		return;
407 	wcid = rcu_dereference(dev->mt76.wcid[wlan_idx]);
408 	if (!wcid) {
409 		stats->tx_rate = rate;
410 		return;
411 	}
412 
413 	msta = container_of(wcid, struct mt7921_sta, wcid);
414 	stats = &msta->stats;
415 
416 	/* current rate */
417 	mt7921_mcu_tx_rate_parse(mphy, &peer, &rate, curr);
418 	stats->tx_rate = rate;
419 }
420 
421 static void
422 mt7921_mcu_scan_event(struct mt7921_dev *dev, struct sk_buff *skb)
423 {
424 	struct mt76_phy *mphy = &dev->mt76.phy;
425 	struct mt7921_phy *phy = (struct mt7921_phy *)mphy->priv;
426 
427 	spin_lock_bh(&dev->mt76.lock);
428 	__skb_queue_tail(&phy->scan_event_list, skb);
429 	spin_unlock_bh(&dev->mt76.lock);
430 
431 	ieee80211_queue_delayed_work(mphy->hw, &phy->scan_work,
432 				     MT7921_HW_SCAN_TIMEOUT);
433 }
434 
435 static void
436 mt7921_mcu_beacon_loss_event(struct mt7921_dev *dev, struct sk_buff *skb)
437 {
438 	struct mt76_connac_beacon_loss_event *event;
439 	struct mt76_phy *mphy;
440 	u8 band_idx = 0; /* DBDC support */
441 
442 	skb_pull(skb, sizeof(struct mt7921_mcu_rxd));
443 	event = (struct mt76_connac_beacon_loss_event *)skb->data;
444 	if (band_idx && dev->mt76.phy2)
445 		mphy = dev->mt76.phy2;
446 	else
447 		mphy = &dev->mt76.phy;
448 
449 	ieee80211_iterate_active_interfaces_atomic(mphy->hw,
450 					IEEE80211_IFACE_ITER_RESUME_ALL,
451 					mt76_connac_mcu_beacon_loss_iter, event);
452 }
453 
454 static void
455 mt7921_mcu_bss_event(struct mt7921_dev *dev, struct sk_buff *skb)
456 {
457 	struct mt76_phy *mphy = &dev->mt76.phy;
458 	struct mt76_connac_mcu_bss_event *event;
459 
460 	skb_pull(skb, sizeof(struct mt7921_mcu_rxd));
461 	event = (struct mt76_connac_mcu_bss_event *)skb->data;
462 	if (event->is_absent)
463 		ieee80211_stop_queues(mphy->hw);
464 	else
465 		ieee80211_wake_queues(mphy->hw);
466 }
467 
468 static void
469 mt7921_mcu_debug_msg_event(struct mt7921_dev *dev, struct sk_buff *skb)
470 {
471 	struct mt7921_mcu_rxd *rxd = (struct mt7921_mcu_rxd *)skb->data;
472 	struct debug_msg {
473 		__le16 id;
474 		u8 type;
475 		u8 flag;
476 		__le32 value;
477 		__le16 len;
478 		u8 content[512];
479 	} __packed * debug_msg;
480 	u16 cur_len;
481 	int i;
482 
483 	skb_pull(skb, sizeof(*rxd));
484 	debug_msg = (struct debug_msg *)skb->data;
485 
486 	cur_len = min_t(u16, le16_to_cpu(debug_msg->len), 512);
487 
488 	if (debug_msg->type == 0x3) {
489 		for (i = 0 ; i < cur_len; i++)
490 			if (!debug_msg->content[i])
491 				debug_msg->content[i] = ' ';
492 
493 		dev_dbg(dev->mt76.dev, "%s", debug_msg->content);
494 	}
495 }
496 
497 static void
498 mt7921_mcu_rx_unsolicited_event(struct mt7921_dev *dev, struct sk_buff *skb)
499 {
500 	struct mt7921_mcu_rxd *rxd = (struct mt7921_mcu_rxd *)skb->data;
501 
502 	switch (rxd->eid) {
503 	case MCU_EVENT_BSS_BEACON_LOSS:
504 		mt7921_mcu_beacon_loss_event(dev, skb);
505 		break;
506 	case MCU_EVENT_SCHED_SCAN_DONE:
507 	case MCU_EVENT_SCAN_DONE:
508 		mt7921_mcu_scan_event(dev, skb);
509 		return;
510 	case MCU_EVENT_BSS_ABSENCE:
511 		mt7921_mcu_bss_event(dev, skb);
512 		break;
513 	case MCU_EVENT_DBG_MSG:
514 		mt7921_mcu_debug_msg_event(dev, skb);
515 		break;
516 	case MCU_EVENT_COREDUMP:
517 		mt76_connac_mcu_coredump_event(&dev->mt76, skb,
518 					       &dev->coredump);
519 		return;
520 	default:
521 		break;
522 	}
523 	dev_kfree_skb(skb);
524 }
525 
526 void mt7921_mcu_rx_event(struct mt7921_dev *dev, struct sk_buff *skb)
527 {
528 	struct mt7921_mcu_rxd *rxd = (struct mt7921_mcu_rxd *)skb->data;
529 
530 	if (rxd->eid == 0x6) {
531 		mt76_mcu_rx_event(&dev->mt76, skb);
532 		return;
533 	}
534 
535 	if (rxd->ext_eid == MCU_EXT_EVENT_RATE_REPORT ||
536 	    rxd->eid == MCU_EVENT_BSS_BEACON_LOSS ||
537 	    rxd->eid == MCU_EVENT_SCHED_SCAN_DONE ||
538 	    rxd->eid == MCU_EVENT_BSS_ABSENCE ||
539 	    rxd->eid == MCU_EVENT_SCAN_DONE ||
540 	    rxd->eid == MCU_EVENT_DBG_MSG ||
541 	    rxd->eid == MCU_EVENT_COREDUMP ||
542 	    !rxd->seq)
543 		mt7921_mcu_rx_unsolicited_event(dev, skb);
544 	else
545 		mt76_mcu_rx_event(&dev->mt76, skb);
546 }
547 
548 /** starec & wtbl **/
549 static int
550 mt7921_mcu_sta_key_tlv(struct mt7921_sta *msta, struct sk_buff *skb,
551 		       struct ieee80211_key_conf *key, enum set_key_cmd cmd)
552 {
553 	struct mt7921_sta_key_conf *bip = &msta->bip;
554 	struct sta_rec_sec *sec;
555 	struct tlv *tlv;
556 	u32 len = sizeof(*sec);
557 
558 	tlv = mt76_connac_mcu_add_tlv(skb, STA_REC_KEY_V2, sizeof(*sec));
559 
560 	sec = (struct sta_rec_sec *)tlv;
561 	sec->add = cmd;
562 
563 	if (cmd == SET_KEY) {
564 		struct sec_key *sec_key;
565 		u8 cipher;
566 
567 		cipher = mt7921_mcu_get_cipher(key->cipher);
568 		if (cipher == MT_CIPHER_NONE)
569 			return -EOPNOTSUPP;
570 
571 		sec_key = &sec->key[0];
572 		sec_key->cipher_len = sizeof(*sec_key);
573 
574 		if (cipher == MT_CIPHER_BIP_CMAC_128) {
575 			sec_key->cipher_id = MT_CIPHER_AES_CCMP;
576 			sec_key->key_id = bip->keyidx;
577 			sec_key->key_len = 16;
578 			memcpy(sec_key->key, bip->key, 16);
579 
580 			sec_key = &sec->key[1];
581 			sec_key->cipher_id = MT_CIPHER_BIP_CMAC_128;
582 			sec_key->cipher_len = sizeof(*sec_key);
583 			sec_key->key_len = 16;
584 			memcpy(sec_key->key, key->key, 16);
585 
586 			sec->n_cipher = 2;
587 		} else {
588 			sec_key->cipher_id = cipher;
589 			sec_key->key_id = key->keyidx;
590 			sec_key->key_len = key->keylen;
591 			memcpy(sec_key->key, key->key, key->keylen);
592 
593 			if (cipher == MT_CIPHER_TKIP) {
594 				/* Rx/Tx MIC keys are swapped */
595 				memcpy(sec_key->key + 16, key->key + 24, 8);
596 				memcpy(sec_key->key + 24, key->key + 16, 8);
597 			}
598 
599 			/* store key_conf for BIP batch update */
600 			if (cipher == MT_CIPHER_AES_CCMP) {
601 				memcpy(bip->key, key->key, key->keylen);
602 				bip->keyidx = key->keyidx;
603 			}
604 
605 			len -= sizeof(*sec_key);
606 			sec->n_cipher = 1;
607 		}
608 	} else {
609 		len -= sizeof(sec->key);
610 		sec->n_cipher = 0;
611 	}
612 	sec->len = cpu_to_le16(len);
613 
614 	return 0;
615 }
616 
617 int mt7921_mcu_add_key(struct mt7921_dev *dev, struct ieee80211_vif *vif,
618 		       struct mt7921_sta *msta, struct ieee80211_key_conf *key,
619 		       enum set_key_cmd cmd)
620 {
621 	struct mt7921_vif *mvif = (struct mt7921_vif *)vif->drv_priv;
622 	struct sk_buff *skb;
623 	int ret;
624 
625 	skb = mt76_connac_mcu_alloc_sta_req(&dev->mt76, &mvif->mt76,
626 					    &msta->wcid);
627 	if (IS_ERR(skb))
628 		return PTR_ERR(skb);
629 
630 	ret = mt7921_mcu_sta_key_tlv(msta, skb, key, cmd);
631 	if (ret)
632 		return ret;
633 
634 	return mt76_mcu_skb_send_msg(&dev->mt76, skb,
635 				     MCU_UNI_CMD_STA_REC_UPDATE, true);
636 }
637 
638 int mt7921_mcu_uni_tx_ba(struct mt7921_dev *dev,
639 			 struct ieee80211_ampdu_params *params,
640 			 bool enable)
641 {
642 	struct mt7921_sta *msta = (struct mt7921_sta *)params->sta->drv_priv;
643 
644 	if (enable && !params->amsdu)
645 		msta->wcid.amsdu = false;
646 
647 	return mt76_connac_mcu_sta_ba(&dev->mt76, &msta->vif->mt76, params,
648 				      enable, true);
649 }
650 
651 int mt7921_mcu_uni_rx_ba(struct mt7921_dev *dev,
652 			 struct ieee80211_ampdu_params *params,
653 			 bool enable)
654 {
655 	struct mt7921_sta *msta = (struct mt7921_sta *)params->sta->drv_priv;
656 
657 	return mt76_connac_mcu_sta_ba(&dev->mt76, &msta->vif->mt76, params,
658 				      enable, false);
659 }
660 
661 static int mt7921_mcu_restart(struct mt76_dev *dev)
662 {
663 	struct {
664 		u8 power_mode;
665 		u8 rsv[3];
666 	} req = {
667 		.power_mode = 1,
668 	};
669 
670 	return mt76_mcu_send_msg(dev, MCU_CMD_NIC_POWER_CTRL, &req,
671 				 sizeof(req), false);
672 }
673 
674 static int mt7921_driver_own(struct mt7921_dev *dev)
675 {
676 	u32 reg = mt7921_reg_map_l1(dev, MT_TOP_LPCR_HOST_BAND0);
677 
678 	mt76_wr(dev, reg, MT_TOP_LPCR_HOST_DRV_OWN);
679 	if (!mt76_poll_msec(dev, reg, MT_TOP_LPCR_HOST_FW_OWN,
680 			    0, 500)) {
681 		dev_err(dev->mt76.dev, "Timeout for driver own\n");
682 		return -EIO;
683 	}
684 
685 	return 0;
686 }
687 
688 static int mt7921_load_patch(struct mt7921_dev *dev)
689 {
690 	const struct mt7921_patch_hdr *hdr;
691 	const struct firmware *fw = NULL;
692 	int i, ret, sem;
693 
694 	sem = mt76_connac_mcu_patch_sem_ctrl(&dev->mt76, true);
695 	switch (sem) {
696 	case PATCH_IS_DL:
697 		return 0;
698 	case PATCH_NOT_DL_SEM_SUCCESS:
699 		break;
700 	default:
701 		dev_err(dev->mt76.dev, "Failed to get patch semaphore\n");
702 		return -EAGAIN;
703 	}
704 
705 	ret = request_firmware(&fw, MT7921_ROM_PATCH, dev->mt76.dev);
706 	if (ret)
707 		goto out;
708 
709 	if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
710 		dev_err(dev->mt76.dev, "Invalid firmware\n");
711 		ret = -EINVAL;
712 		goto out;
713 	}
714 
715 	hdr = (const struct mt7921_patch_hdr *)(fw->data);
716 
717 	dev_info(dev->mt76.dev, "HW/SW Version: 0x%x, Build Time: %.16s\n",
718 		 be32_to_cpu(hdr->hw_sw_ver), hdr->build_date);
719 
720 	for (i = 0; i < be32_to_cpu(hdr->desc.n_region); i++) {
721 		struct mt7921_patch_sec *sec;
722 		const u8 *dl;
723 		u32 len, addr;
724 
725 		sec = (struct mt7921_patch_sec *)(fw->data + sizeof(*hdr) +
726 						  i * sizeof(*sec));
727 		if ((be32_to_cpu(sec->type) & PATCH_SEC_TYPE_MASK) !=
728 		    PATCH_SEC_TYPE_INFO) {
729 			ret = -EINVAL;
730 			goto out;
731 		}
732 
733 		addr = be32_to_cpu(sec->info.addr);
734 		len = be32_to_cpu(sec->info.len);
735 		dl = fw->data + be32_to_cpu(sec->offs);
736 
737 		ret = mt76_connac_mcu_init_download(&dev->mt76, addr, len,
738 						    DL_MODE_NEED_RSP);
739 		if (ret) {
740 			dev_err(dev->mt76.dev, "Download request failed\n");
741 			goto out;
742 		}
743 
744 		ret = mt76_mcu_send_firmware(&dev->mt76, MCU_CMD_FW_SCATTER,
745 					     dl, len);
746 		if (ret) {
747 			dev_err(dev->mt76.dev, "Failed to send patch\n");
748 			goto out;
749 		}
750 	}
751 
752 	ret = mt76_connac_mcu_start_patch(&dev->mt76);
753 	if (ret)
754 		dev_err(dev->mt76.dev, "Failed to start patch\n");
755 
756 out:
757 	sem = mt76_connac_mcu_patch_sem_ctrl(&dev->mt76, false);
758 	switch (sem) {
759 	case PATCH_REL_SEM_SUCCESS:
760 		break;
761 	default:
762 		ret = -EAGAIN;
763 		dev_err(dev->mt76.dev, "Failed to release patch semaphore\n");
764 		goto out;
765 	}
766 	release_firmware(fw);
767 
768 	return ret;
769 }
770 
771 static u32 mt7921_mcu_gen_dl_mode(u8 feature_set, bool is_wa)
772 {
773 	u32 ret = 0;
774 
775 	ret |= (feature_set & FW_FEATURE_SET_ENCRYPT) ?
776 	       (DL_MODE_ENCRYPT | DL_MODE_RESET_SEC_IV) : 0;
777 	ret |= (feature_set & FW_FEATURE_ENCRY_MODE) ?
778 	       DL_CONFIG_ENCRY_MODE_SEL : 0;
779 	ret |= FIELD_PREP(DL_MODE_KEY_IDX,
780 			  FIELD_GET(FW_FEATURE_SET_KEY_IDX, feature_set));
781 	ret |= DL_MODE_NEED_RSP;
782 	ret |= is_wa ? DL_MODE_WORKING_PDA_CR4 : 0;
783 
784 	return ret;
785 }
786 
787 static int
788 mt7921_mcu_send_ram_firmware(struct mt7921_dev *dev,
789 			     const struct mt7921_fw_trailer *hdr,
790 			     const u8 *data, bool is_wa)
791 {
792 	int i, offset = 0;
793 	u32 override = 0, option = 0;
794 
795 	for (i = 0; i < hdr->n_region; i++) {
796 		const struct mt7921_fw_region *region;
797 		int err;
798 		u32 len, addr, mode;
799 
800 		region = (const struct mt7921_fw_region *)((const u8 *)hdr -
801 			 (hdr->n_region - i) * sizeof(*region));
802 		mode = mt7921_mcu_gen_dl_mode(region->feature_set, is_wa);
803 		len = le32_to_cpu(region->len);
804 		addr = le32_to_cpu(region->addr);
805 
806 		if (region->feature_set & FW_FEATURE_OVERRIDE_ADDR)
807 			override = addr;
808 
809 		err = mt76_connac_mcu_init_download(&dev->mt76, addr, len,
810 						    mode);
811 		if (err) {
812 			dev_err(dev->mt76.dev, "Download request failed\n");
813 			return err;
814 		}
815 
816 		err = mt76_mcu_send_firmware(&dev->mt76, MCU_CMD_FW_SCATTER,
817 					     data + offset, len);
818 		if (err) {
819 			dev_err(dev->mt76.dev, "Failed to send firmware.\n");
820 			return err;
821 		}
822 
823 		offset += len;
824 	}
825 
826 	if (override)
827 		option |= FW_START_OVERRIDE;
828 
829 	if (is_wa)
830 		option |= FW_START_WORKING_PDA_CR4;
831 
832 	return mt76_connac_mcu_start_firmware(&dev->mt76, override, option);
833 }
834 
835 static int mt7921_load_ram(struct mt7921_dev *dev)
836 {
837 	const struct mt7921_fw_trailer *hdr;
838 	const struct firmware *fw;
839 	int ret;
840 
841 	ret = request_firmware(&fw, MT7921_FIRMWARE_WM, dev->mt76.dev);
842 	if (ret)
843 		return ret;
844 
845 	if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
846 		dev_err(dev->mt76.dev, "Invalid firmware\n");
847 		ret = -EINVAL;
848 		goto out;
849 	}
850 
851 	hdr = (const struct mt7921_fw_trailer *)(fw->data + fw->size -
852 					sizeof(*hdr));
853 
854 	dev_info(dev->mt76.dev, "WM Firmware Version: %.10s, Build Time: %.15s\n",
855 		 hdr->fw_ver, hdr->build_date);
856 
857 	ret = mt7921_mcu_send_ram_firmware(dev, hdr, fw->data, false);
858 	if (ret) {
859 		dev_err(dev->mt76.dev, "Failed to start WM firmware\n");
860 		goto out;
861 	}
862 
863 	snprintf(dev->mt76.hw->wiphy->fw_version,
864 		 sizeof(dev->mt76.hw->wiphy->fw_version),
865 		 "%.10s-%.15s", hdr->fw_ver, hdr->build_date);
866 
867 out:
868 	release_firmware(fw);
869 
870 	return ret;
871 }
872 
873 static int mt7921_load_firmware(struct mt7921_dev *dev)
874 {
875 	int ret;
876 
877 	ret = mt76_get_field(dev, MT_CONN_ON_MISC, MT_TOP_MISC2_FW_N9_RDY);
878 	if (ret) {
879 		dev_dbg(dev->mt76.dev, "Firmware is already download\n");
880 		return -EIO;
881 	}
882 
883 	ret = mt7921_load_patch(dev);
884 	if (ret)
885 		return ret;
886 
887 	ret = mt7921_load_ram(dev);
888 	if (ret)
889 		return ret;
890 
891 	if (!mt76_poll_msec(dev, MT_CONN_ON_MISC, MT_TOP_MISC2_FW_N9_RDY,
892 			    MT_TOP_MISC2_FW_N9_RDY, 1500)) {
893 		dev_err(dev->mt76.dev, "Timeout for initializing firmware\n");
894 
895 		return -EIO;
896 	}
897 
898 	mt76_queue_tx_cleanup(dev, dev->mt76.q_mcu[MT_MCUQ_FWDL], false);
899 
900 #ifdef CONFIG_PM
901 	dev->mt76.hw->wiphy->wowlan = &mt76_connac_wowlan_support;
902 #endif /* CONFIG_PM */
903 
904 	clear_bit(MT76_STATE_PM, &dev->mphy.state);
905 
906 	dev_err(dev->mt76.dev, "Firmware init done\n");
907 
908 	return 0;
909 }
910 
911 int mt7921_mcu_fw_log_2_host(struct mt7921_dev *dev, u8 ctrl)
912 {
913 	struct {
914 		u8 ctrl_val;
915 		u8 pad[3];
916 	} data = {
917 		.ctrl_val = ctrl
918 	};
919 
920 	return mt76_mcu_send_msg(&dev->mt76, MCU_CMD_FWLOG_2_HOST, &data,
921 				 sizeof(data), false);
922 }
923 
924 int mt7921_mcu_init(struct mt7921_dev *dev)
925 {
926 	static const struct mt76_mcu_ops mt7921_mcu_ops = {
927 		.headroom = sizeof(struct mt7921_mcu_txd),
928 		.mcu_skb_send_msg = mt7921_mcu_send_message,
929 		.mcu_parse_response = mt7921_mcu_parse_response,
930 		.mcu_restart = mt7921_mcu_restart,
931 	};
932 	int ret;
933 
934 	dev->mt76.mcu_ops = &mt7921_mcu_ops;
935 
936 	ret = mt7921_driver_own(dev);
937 	if (ret)
938 		return ret;
939 
940 	ret = mt7921_load_firmware(dev);
941 	if (ret)
942 		return ret;
943 
944 	set_bit(MT76_STATE_MCU_RUNNING, &dev->mphy.state);
945 	mt7921_mcu_fw_log_2_host(dev, 1);
946 
947 	return 0;
948 }
949 
950 void mt7921_mcu_exit(struct mt7921_dev *dev)
951 {
952 	u32 reg = mt7921_reg_map_l1(dev, MT_TOP_MISC);
953 
954 	__mt76_mcu_restart(&dev->mt76);
955 	if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
956 			    FIELD_PREP(MT_TOP_MISC_FW_STATE,
957 				       FW_STATE_FW_DOWNLOAD), 1000)) {
958 		dev_err(dev->mt76.dev, "Failed to exit mcu\n");
959 		return;
960 	}
961 
962 	reg = mt7921_reg_map_l1(dev, MT_TOP_LPCR_HOST_BAND0);
963 	mt76_wr(dev, reg, MT_TOP_LPCR_HOST_FW_OWN);
964 	skb_queue_purge(&dev->mt76.mcu.res_q);
965 }
966 
967 int mt7921_mcu_set_tx(struct mt7921_dev *dev, struct ieee80211_vif *vif)
968 {
969 #define WMM_AIFS_SET		BIT(0)
970 #define WMM_CW_MIN_SET		BIT(1)
971 #define WMM_CW_MAX_SET		BIT(2)
972 #define WMM_TXOP_SET		BIT(3)
973 #define WMM_PARAM_SET		GENMASK(3, 0)
974 #define TX_CMD_MODE		1
975 	struct edca {
976 		u8 queue;
977 		u8 set;
978 		u8 aifs;
979 		u8 cw_min;
980 		__le16 cw_max;
981 		__le16 txop;
982 	};
983 	struct mt7921_mcu_tx {
984 		u8 total;
985 		u8 action;
986 		u8 valid;
987 		u8 mode;
988 
989 		struct edca edca[IEEE80211_NUM_ACS];
990 	} __packed req = {
991 		.valid = true,
992 		.mode = TX_CMD_MODE,
993 		.total = IEEE80211_NUM_ACS,
994 	};
995 	struct mt7921_vif *mvif = (struct mt7921_vif *)vif->drv_priv;
996 	int ac;
997 
998 	for (ac = 0; ac < IEEE80211_NUM_ACS; ac++) {
999 		struct ieee80211_tx_queue_params *q = &mvif->queue_params[ac];
1000 		struct edca *e = &req.edca[ac];
1001 
1002 		e->set = WMM_PARAM_SET;
1003 		e->queue = ac + mvif->mt76.wmm_idx * MT7921_MAX_WMM_SETS;
1004 		e->aifs = q->aifs;
1005 		e->txop = cpu_to_le16(q->txop);
1006 
1007 		if (q->cw_min)
1008 			e->cw_min = fls(q->cw_min);
1009 		else
1010 			e->cw_min = 5;
1011 
1012 		if (q->cw_max)
1013 			e->cw_max = cpu_to_le16(fls(q->cw_max));
1014 		else
1015 			e->cw_max = cpu_to_le16(10);
1016 	}
1017 	return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EDCA_UPDATE, &req,
1018 				 sizeof(req), true);
1019 }
1020 
1021 int mt7921_mcu_set_chan_info(struct mt7921_phy *phy, int cmd)
1022 {
1023 	struct mt7921_dev *dev = phy->dev;
1024 	struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
1025 	int freq1 = chandef->center_freq1;
1026 	struct {
1027 		u8 control_ch;
1028 		u8 center_ch;
1029 		u8 bw;
1030 		u8 tx_streams_num;
1031 		u8 rx_streams;	/* mask or num */
1032 		u8 switch_reason;
1033 		u8 band_idx;
1034 		u8 center_ch2;	/* for 80+80 only */
1035 		__le16 cac_case;
1036 		u8 channel_band;
1037 		u8 rsv0;
1038 		__le32 outband_freq;
1039 		u8 txpower_drop;
1040 		u8 ap_bw;
1041 		u8 ap_center_ch;
1042 		u8 rsv1[57];
1043 	} __packed req = {
1044 		.control_ch = chandef->chan->hw_value,
1045 		.center_ch = ieee80211_frequency_to_channel(freq1),
1046 		.bw = mt7921_mcu_chan_bw(chandef),
1047 		.tx_streams_num = hweight8(phy->mt76->antenna_mask),
1048 		.rx_streams = phy->mt76->antenna_mask,
1049 		.band_idx = phy != &dev->phy,
1050 		.channel_band = chandef->chan->band,
1051 	};
1052 
1053 	if (dev->mt76.hw->conf.flags & IEEE80211_CONF_OFFCHANNEL)
1054 		req.switch_reason = CH_SWITCH_SCAN_BYPASS_DPD;
1055 	else if ((chandef->chan->flags & IEEE80211_CHAN_RADAR) &&
1056 		 chandef->chan->dfs_state != NL80211_DFS_AVAILABLE)
1057 		req.switch_reason = CH_SWITCH_DFS;
1058 	else
1059 		req.switch_reason = CH_SWITCH_NORMAL;
1060 
1061 	if (cmd == MCU_EXT_CMD_CHANNEL_SWITCH)
1062 		req.rx_streams = hweight8(req.rx_streams);
1063 
1064 	if (chandef->width == NL80211_CHAN_WIDTH_80P80) {
1065 		int freq2 = chandef->center_freq2;
1066 
1067 		req.center_ch2 = ieee80211_frequency_to_channel(freq2);
1068 	}
1069 
1070 	return mt76_mcu_send_msg(&dev->mt76, cmd, &req, sizeof(req), true);
1071 }
1072 
1073 int mt7921_mcu_set_eeprom(struct mt7921_dev *dev)
1074 {
1075 	struct req_hdr {
1076 		u8 buffer_mode;
1077 		u8 format;
1078 		__le16 len;
1079 	} __packed req = {
1080 		.buffer_mode = EE_MODE_EFUSE,
1081 		.format = EE_FORMAT_WHOLE,
1082 	};
1083 
1084 	return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EFUSE_BUFFER_MODE,
1085 				 &req, sizeof(req), true);
1086 }
1087 
1088 int mt7921_mcu_get_eeprom(struct mt7921_dev *dev, u32 offset)
1089 {
1090 	struct mt7921_mcu_eeprom_info req = {
1091 		.addr = cpu_to_le32(round_down(offset, 16)),
1092 	};
1093 	struct mt7921_mcu_eeprom_info *res;
1094 	struct sk_buff *skb;
1095 	int ret;
1096 	u8 *buf;
1097 
1098 	ret = mt76_mcu_send_and_get_msg(&dev->mt76, MCU_EXT_CMD_EFUSE_ACCESS, &req,
1099 					sizeof(req), true, &skb);
1100 	if (ret)
1101 		return ret;
1102 
1103 	res = (struct mt7921_mcu_eeprom_info *)skb->data;
1104 	buf = dev->mt76.eeprom.data + le32_to_cpu(res->addr);
1105 	memcpy(buf, res->data, 16);
1106 	dev_kfree_skb(skb);
1107 
1108 	return 0;
1109 }
1110 
1111 u32 mt7921_get_wtbl_info(struct mt7921_dev *dev, u32 wlan_idx)
1112 {
1113 	struct mt7921_mcu_wlan_info wtbl_info = {
1114 		.wlan_idx = cpu_to_le32(wlan_idx),
1115 	};
1116 	struct sk_buff *skb;
1117 	int ret;
1118 
1119 	ret = mt76_mcu_send_and_get_msg(&dev->mt76, MCU_CMD_GET_WTBL,
1120 					&wtbl_info, sizeof(wtbl_info), true,
1121 					&skb);
1122 	if (ret)
1123 		return ret;
1124 
1125 	mt7921_mcu_tx_rate_report(dev, skb, wlan_idx);
1126 	dev_kfree_skb(skb);
1127 
1128 	return 0;
1129 }
1130 
1131 int mt7921_mcu_uni_bss_ps(struct mt7921_dev *dev, struct ieee80211_vif *vif)
1132 {
1133 	struct mt7921_vif *mvif = (struct mt7921_vif *)vif->drv_priv;
1134 	struct {
1135 		struct {
1136 			u8 bss_idx;
1137 			u8 pad[3];
1138 		} __packed hdr;
1139 		struct ps_tlv {
1140 			__le16 tag;
1141 			__le16 len;
1142 			u8 ps_state; /* 0: device awake
1143 				      * 1: static power save
1144 				      * 2: dynamic power saving
1145 				      * 3: enter TWT power saving
1146 				      * 4: leave TWT power saving
1147 				      */
1148 			u8 pad[3];
1149 		} __packed ps;
1150 	} __packed ps_req = {
1151 		.hdr = {
1152 			.bss_idx = mvif->mt76.idx,
1153 		},
1154 		.ps = {
1155 			.tag = cpu_to_le16(UNI_BSS_INFO_PS),
1156 			.len = cpu_to_le16(sizeof(struct ps_tlv)),
1157 			.ps_state = vif->bss_conf.ps ? 2 : 0,
1158 		},
1159 	};
1160 
1161 	if (vif->type != NL80211_IFTYPE_STATION)
1162 		return -EOPNOTSUPP;
1163 
1164 	return mt76_mcu_send_msg(&dev->mt76, MCU_UNI_CMD_BSS_INFO_UPDATE,
1165 				 &ps_req, sizeof(ps_req), true);
1166 }
1167 
1168 int mt7921_mcu_uni_bss_bcnft(struct mt7921_dev *dev, struct ieee80211_vif *vif,
1169 			     bool enable)
1170 {
1171 	struct mt7921_vif *mvif = (struct mt7921_vif *)vif->drv_priv;
1172 	struct {
1173 		struct {
1174 			u8 bss_idx;
1175 			u8 pad[3];
1176 		} __packed hdr;
1177 		struct bcnft_tlv {
1178 			__le16 tag;
1179 			__le16 len;
1180 			__le16 bcn_interval;
1181 			u8 dtim_period;
1182 			u8 pad;
1183 		} __packed bcnft;
1184 	} __packed bcnft_req = {
1185 		.hdr = {
1186 			.bss_idx = mvif->mt76.idx,
1187 		},
1188 		.bcnft = {
1189 			.tag = cpu_to_le16(UNI_BSS_INFO_BCNFT),
1190 			.len = cpu_to_le16(sizeof(struct bcnft_tlv)),
1191 			.bcn_interval = cpu_to_le16(vif->bss_conf.beacon_int),
1192 			.dtim_period = vif->bss_conf.dtim_period,
1193 		},
1194 	};
1195 
1196 	if (vif->type != NL80211_IFTYPE_STATION)
1197 		return 0;
1198 
1199 	return mt76_mcu_send_msg(&dev->mt76, MCU_UNI_CMD_BSS_INFO_UPDATE,
1200 				 &bcnft_req, sizeof(bcnft_req), true);
1201 }
1202 
1203 int mt7921_mcu_set_bss_pm(struct mt7921_dev *dev, struct ieee80211_vif *vif,
1204 			  bool enable)
1205 {
1206 	struct mt7921_vif *mvif = (struct mt7921_vif *)vif->drv_priv;
1207 	struct {
1208 		u8 bss_idx;
1209 		u8 dtim_period;
1210 		__le16 aid;
1211 		__le16 bcn_interval;
1212 		__le16 atim_window;
1213 		u8 uapsd;
1214 		u8 bmc_delivered_ac;
1215 		u8 bmc_triggered_ac;
1216 		u8 pad;
1217 	} req = {
1218 		.bss_idx = mvif->mt76.idx,
1219 		.aid = cpu_to_le16(vif->bss_conf.aid),
1220 		.dtim_period = vif->bss_conf.dtim_period,
1221 		.bcn_interval = cpu_to_le16(vif->bss_conf.beacon_int),
1222 	};
1223 	struct {
1224 		u8 bss_idx;
1225 		u8 pad[3];
1226 	} req_hdr = {
1227 		.bss_idx = mvif->mt76.idx,
1228 	};
1229 	int err;
1230 
1231 	if (vif->type != NL80211_IFTYPE_STATION)
1232 		return 0;
1233 
1234 	err = mt76_mcu_send_msg(&dev->mt76, MCU_CMD_SET_BSS_ABORT, &req_hdr,
1235 				sizeof(req_hdr), false);
1236 	if (err < 0 || !enable)
1237 		return err;
1238 
1239 	return mt76_mcu_send_msg(&dev->mt76, MCU_CMD_SET_BSS_CONNECTED, &req,
1240 				 sizeof(req), false);
1241 }
1242 
1243 int mt7921_mcu_drv_pmctrl(struct mt7921_dev *dev)
1244 {
1245 	struct mt76_phy *mphy = &dev->mt76.phy;
1246 	int i;
1247 
1248 	if (!test_and_clear_bit(MT76_STATE_PM, &mphy->state))
1249 		goto out;
1250 
1251 	for (i = 0; i < MT7921_DRV_OWN_RETRY_COUNT; i++) {
1252 		mt76_wr(dev, MT_CONN_ON_LPCTL, PCIE_LPCR_HOST_CLR_OWN);
1253 		if (mt76_poll_msec(dev, MT_CONN_ON_LPCTL,
1254 				   PCIE_LPCR_HOST_OWN_SYNC, 0, 50))
1255 			break;
1256 	}
1257 
1258 	if (i == MT7921_DRV_OWN_RETRY_COUNT) {
1259 		dev_err(dev->mt76.dev, "driver own failed\n");
1260 		return -EIO;
1261 	}
1262 
1263 out:
1264 	dev->pm.last_activity = jiffies;
1265 
1266 	return 0;
1267 }
1268 
1269 int mt7921_mcu_fw_pmctrl(struct mt7921_dev *dev)
1270 {
1271 	struct mt76_phy *mphy = &dev->mt76.phy;
1272 	int i;
1273 
1274 	if (test_and_set_bit(MT76_STATE_PM, &mphy->state))
1275 		return 0;
1276 
1277 	for (i = 0; i < MT7921_DRV_OWN_RETRY_COUNT; i++) {
1278 		mt76_wr(dev, MT_CONN_ON_LPCTL, PCIE_LPCR_HOST_SET_OWN);
1279 		if (mt76_poll_msec(dev, MT_CONN_ON_LPCTL,
1280 				   PCIE_LPCR_HOST_OWN_SYNC, 4, 50))
1281 			break;
1282 	}
1283 
1284 	if (i == MT7921_DRV_OWN_RETRY_COUNT) {
1285 		dev_err(dev->mt76.dev, "firmware own failed\n");
1286 		return -EIO;
1287 	}
1288 
1289 	return 0;
1290 }
1291 
1292 void
1293 mt7921_pm_interface_iter(void *priv, u8 *mac, struct ieee80211_vif *vif)
1294 {
1295 	struct mt7921_phy *phy = priv;
1296 	struct mt7921_dev *dev = phy->dev;
1297 
1298 	if (mt7921_mcu_set_bss_pm(dev, vif, dev->pm.enable))
1299 		return;
1300 
1301 	if (dev->pm.enable) {
1302 		vif->driver_flags |= IEEE80211_VIF_BEACON_FILTER;
1303 		mt76_set(dev, MT_WF_RFCR(0), MT_WF_RFCR_DROP_OTHER_BEACON);
1304 	} else {
1305 		vif->driver_flags &= ~IEEE80211_VIF_BEACON_FILTER;
1306 		mt76_clear(dev, MT_WF_RFCR(0), MT_WF_RFCR_DROP_OTHER_BEACON);
1307 	}
1308 }
1309