1 // SPDX-License-Identifier: GPL-2.0+
2 /* Copyright (c) 2015-2016 Quantenna Communications. All rights reserved. */
3 
4 #include <linux/types.h>
5 #include <linux/skbuff.h>
6 
7 #include "cfg80211.h"
8 #include "core.h"
9 #include "qlink.h"
10 #include "qlink_util.h"
11 #include "bus.h"
12 #include "commands.h"
13 
14 static int qtnf_cmd_check_reply_header(const struct qlink_resp *resp,
15 				       u16 cmd_id, u8 mac_id, u8 vif_id,
16 				       size_t resp_size)
17 {
18 	if (unlikely(le16_to_cpu(resp->cmd_id) != cmd_id)) {
19 		pr_warn("VIF%u.%u CMD%x: bad cmd_id in response: 0x%.4X\n",
20 			mac_id, vif_id, cmd_id, le16_to_cpu(resp->cmd_id));
21 		return -EINVAL;
22 	}
23 
24 	if (unlikely(resp->macid != mac_id)) {
25 		pr_warn("VIF%u.%u CMD%x: bad MAC in response: %u\n",
26 			mac_id, vif_id, cmd_id, resp->macid);
27 		return -EINVAL;
28 	}
29 
30 	if (unlikely(resp->vifid != vif_id)) {
31 		pr_warn("VIF%u.%u CMD%x: bad VIF in response: %u\n",
32 			mac_id, vif_id, cmd_id, resp->vifid);
33 		return -EINVAL;
34 	}
35 
36 	if (unlikely(le16_to_cpu(resp->mhdr.len) < resp_size)) {
37 		pr_warn("VIF%u.%u CMD%x: bad response size %u < %zu\n",
38 			mac_id, vif_id, cmd_id,
39 			le16_to_cpu(resp->mhdr.len), resp_size);
40 		return -ENOSPC;
41 	}
42 
43 	return 0;
44 }
45 
46 static int qtnf_cmd_resp_result_decode(enum qlink_cmd_result qcode)
47 {
48 	switch (qcode) {
49 	case QLINK_CMD_RESULT_OK:
50 		return 0;
51 	case QLINK_CMD_RESULT_INVALID:
52 		return -EINVAL;
53 	case QLINK_CMD_RESULT_ENOTSUPP:
54 		return -ENOTSUPP;
55 	case QLINK_CMD_RESULT_ENOTFOUND:
56 		return -ENOENT;
57 	case QLINK_CMD_RESULT_EALREADY:
58 		return -EALREADY;
59 	case QLINK_CMD_RESULT_EADDRINUSE:
60 		return -EADDRINUSE;
61 	case QLINK_CMD_RESULT_EADDRNOTAVAIL:
62 		return -EADDRNOTAVAIL;
63 	case QLINK_CMD_RESULT_EBUSY:
64 		return -EBUSY;
65 	default:
66 		return -EFAULT;
67 	}
68 }
69 
70 static int qtnf_cmd_send_with_reply(struct qtnf_bus *bus,
71 				    struct sk_buff *cmd_skb,
72 				    struct sk_buff **response_skb,
73 				    size_t const_resp_size,
74 				    size_t *var_resp_size)
75 {
76 	struct qlink_cmd *cmd;
77 	struct qlink_resp *resp = NULL;
78 	struct sk_buff *resp_skb = NULL;
79 	u16 cmd_id;
80 	u8 mac_id;
81 	u8 vif_id;
82 	int ret;
83 
84 	cmd = (struct qlink_cmd *)cmd_skb->data;
85 	cmd_id = le16_to_cpu(cmd->cmd_id);
86 	mac_id = cmd->macid;
87 	vif_id = cmd->vifid;
88 	cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
89 
90 	pr_debug("VIF%u.%u cmd=0x%.4X\n", mac_id, vif_id, cmd_id);
91 
92 	if (bus->fw_state != QTNF_FW_STATE_ACTIVE &&
93 	    cmd_id != QLINK_CMD_FW_INIT) {
94 		pr_warn("VIF%u.%u: drop cmd 0x%.4X in fw state %d\n",
95 			mac_id, vif_id, cmd_id, bus->fw_state);
96 		dev_kfree_skb(cmd_skb);
97 		return -ENODEV;
98 	}
99 
100 	ret = qtnf_trans_send_cmd_with_resp(bus, cmd_skb, &resp_skb);
101 	if (ret)
102 		goto out;
103 
104 	if (WARN_ON(!resp_skb || !resp_skb->data)) {
105 		ret = -EFAULT;
106 		goto out;
107 	}
108 
109 	resp = (struct qlink_resp *)resp_skb->data;
110 	ret = qtnf_cmd_check_reply_header(resp, cmd_id, mac_id, vif_id,
111 					  const_resp_size);
112 	if (ret)
113 		goto out;
114 
115 	/* Return length of variable part of response */
116 	if (response_skb && var_resp_size)
117 		*var_resp_size = le16_to_cpu(resp->mhdr.len) - const_resp_size;
118 
119 out:
120 	if (response_skb)
121 		*response_skb = resp_skb;
122 	else
123 		consume_skb(resp_skb);
124 
125 	if (!ret && resp)
126 		return qtnf_cmd_resp_result_decode(le16_to_cpu(resp->result));
127 
128 	pr_warn("VIF%u.%u: cmd 0x%.4X failed: %d\n",
129 		mac_id, vif_id, cmd_id, ret);
130 
131 	return ret;
132 }
133 
134 static inline int qtnf_cmd_send(struct qtnf_bus *bus, struct sk_buff *cmd_skb)
135 {
136 	return qtnf_cmd_send_with_reply(bus, cmd_skb, NULL,
137 					sizeof(struct qlink_resp), NULL);
138 }
139 
140 static struct sk_buff *qtnf_cmd_alloc_new_cmdskb(u8 macid, u8 vifid, u16 cmd_no,
141 						 size_t cmd_size)
142 {
143 	struct qlink_cmd *cmd;
144 	struct sk_buff *cmd_skb;
145 
146 	cmd_skb = __dev_alloc_skb(sizeof(*cmd) +
147 				  QTNF_MAX_CMD_BUF_SIZE, GFP_KERNEL);
148 	if (unlikely(!cmd_skb)) {
149 		pr_err("VIF%u.%u CMD %u: alloc failed\n", macid, vifid, cmd_no);
150 		return NULL;
151 	}
152 
153 	skb_put_zero(cmd_skb, cmd_size);
154 
155 	cmd = (struct qlink_cmd *)cmd_skb->data;
156 	cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
157 	cmd->mhdr.type = cpu_to_le16(QLINK_MSG_TYPE_CMD);
158 	cmd->cmd_id = cpu_to_le16(cmd_no);
159 	cmd->macid = macid;
160 	cmd->vifid = vifid;
161 
162 	return cmd_skb;
163 }
164 
165 static void qtnf_cmd_tlv_ie_set_add(struct sk_buff *cmd_skb, u8 frame_type,
166 				    const u8 *buf, size_t len)
167 {
168 	struct qlink_tlv_ie_set *tlv;
169 
170 	tlv = (struct qlink_tlv_ie_set *)skb_put(cmd_skb, sizeof(*tlv) + len);
171 	tlv->hdr.type = cpu_to_le16(QTN_TLV_ID_IE_SET);
172 	tlv->hdr.len = cpu_to_le16(len + sizeof(*tlv) - sizeof(tlv->hdr));
173 	tlv->type = frame_type;
174 	tlv->flags = 0;
175 
176 	if (len && buf)
177 		memcpy(tlv->ie_data, buf, len);
178 }
179 
180 static inline size_t qtnf_cmd_acl_data_size(const struct cfg80211_acl_data *acl)
181 {
182 	size_t size = sizeof(struct qlink_acl_data) +
183 		      acl->n_acl_entries * sizeof(struct qlink_mac_address);
184 
185 	return size;
186 }
187 
188 static bool qtnf_cmd_start_ap_can_fit(const struct qtnf_vif *vif,
189 				      const struct cfg80211_ap_settings *s)
190 {
191 	unsigned int len = sizeof(struct qlink_cmd_start_ap);
192 
193 	len += s->ssid_len;
194 	len += s->beacon.head_len;
195 	len += s->beacon.tail_len;
196 	len += s->beacon.beacon_ies_len;
197 	len += s->beacon.proberesp_ies_len;
198 	len += s->beacon.assocresp_ies_len;
199 	len += s->beacon.probe_resp_len;
200 
201 	if (cfg80211_chandef_valid(&s->chandef))
202 		len += sizeof(struct qlink_tlv_chandef);
203 
204 	if (s->acl)
205 		len += sizeof(struct qlink_tlv_hdr) +
206 		       qtnf_cmd_acl_data_size(s->acl);
207 
208 	if (len > (sizeof(struct qlink_cmd) + QTNF_MAX_CMD_BUF_SIZE)) {
209 		pr_err("VIF%u.%u: can not fit AP settings: %u\n",
210 		       vif->mac->macid, vif->vifid, len);
211 		return false;
212 	}
213 
214 	return true;
215 }
216 
217 int qtnf_cmd_send_start_ap(struct qtnf_vif *vif,
218 			   const struct cfg80211_ap_settings *s)
219 {
220 	struct sk_buff *cmd_skb;
221 	struct qlink_cmd_start_ap *cmd;
222 	struct qlink_auth_encr *aen;
223 	int ret;
224 	int i;
225 
226 	if (!qtnf_cmd_start_ap_can_fit(vif, s))
227 		return -E2BIG;
228 
229 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
230 					    QLINK_CMD_START_AP,
231 					    sizeof(*cmd));
232 	if (!cmd_skb)
233 		return -ENOMEM;
234 
235 	cmd = (struct qlink_cmd_start_ap *)cmd_skb->data;
236 	cmd->dtim_period = s->dtim_period;
237 	cmd->beacon_interval = cpu_to_le16(s->beacon_interval);
238 	cmd->hidden_ssid = qlink_hidden_ssid_nl2q(s->hidden_ssid);
239 	cmd->inactivity_timeout = cpu_to_le16(s->inactivity_timeout);
240 	cmd->smps_mode = s->smps_mode;
241 	cmd->p2p_ctwindow = s->p2p_ctwindow;
242 	cmd->p2p_opp_ps = s->p2p_opp_ps;
243 	cmd->pbss = s->pbss;
244 	cmd->ht_required = s->ht_required;
245 	cmd->vht_required = s->vht_required;
246 
247 	aen = &cmd->aen;
248 	aen->auth_type = s->auth_type;
249 	aen->privacy = !!s->privacy;
250 	aen->wpa_versions = cpu_to_le32(s->crypto.wpa_versions);
251 	aen->cipher_group = cpu_to_le32(s->crypto.cipher_group);
252 	aen->n_ciphers_pairwise = cpu_to_le32(s->crypto.n_ciphers_pairwise);
253 	for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
254 		aen->ciphers_pairwise[i] =
255 				cpu_to_le32(s->crypto.ciphers_pairwise[i]);
256 	aen->n_akm_suites = cpu_to_le32(s->crypto.n_akm_suites);
257 	for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
258 		aen->akm_suites[i] = cpu_to_le32(s->crypto.akm_suites[i]);
259 	aen->control_port = s->crypto.control_port;
260 	aen->control_port_no_encrypt = s->crypto.control_port_no_encrypt;
261 	aen->control_port_ethertype =
262 		cpu_to_le16(be16_to_cpu(s->crypto.control_port_ethertype));
263 
264 	if (s->ssid && s->ssid_len > 0 && s->ssid_len <= IEEE80211_MAX_SSID_LEN)
265 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, s->ssid,
266 					 s->ssid_len);
267 
268 	if (cfg80211_chandef_valid(&s->chandef)) {
269 		struct qlink_tlv_chandef *chtlv =
270 			(struct qlink_tlv_chandef *)skb_put(cmd_skb,
271 							    sizeof(*chtlv));
272 
273 		chtlv->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANDEF);
274 		chtlv->hdr.len = cpu_to_le16(sizeof(*chtlv) -
275 					     sizeof(chtlv->hdr));
276 		qlink_chandef_cfg2q(&s->chandef, &chtlv->chdef);
277 	}
278 
279 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_HEAD,
280 				s->beacon.head, s->beacon.head_len);
281 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_TAIL,
282 				s->beacon.tail, s->beacon.tail_len);
283 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_IES,
284 				s->beacon.beacon_ies, s->beacon.beacon_ies_len);
285 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_RESP,
286 				s->beacon.probe_resp, s->beacon.probe_resp_len);
287 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_RESP_IES,
288 				s->beacon.proberesp_ies,
289 				s->beacon.proberesp_ies_len);
290 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_ASSOC_RESP,
291 				s->beacon.assocresp_ies,
292 				s->beacon.assocresp_ies_len);
293 
294 	if (s->ht_cap) {
295 		struct qlink_tlv_hdr *tlv = (struct qlink_tlv_hdr *)
296 			skb_put(cmd_skb, sizeof(*tlv) + sizeof(*s->ht_cap));
297 
298 		tlv->type = cpu_to_le16(WLAN_EID_HT_CAPABILITY);
299 		tlv->len = cpu_to_le16(sizeof(*s->ht_cap));
300 		memcpy(tlv->val, s->ht_cap, sizeof(*s->ht_cap));
301 	}
302 
303 	if (s->vht_cap) {
304 		struct qlink_tlv_hdr *tlv = (struct qlink_tlv_hdr *)
305 			skb_put(cmd_skb, sizeof(*tlv) + sizeof(*s->vht_cap));
306 
307 		tlv->type = cpu_to_le16(WLAN_EID_VHT_CAPABILITY);
308 		tlv->len = cpu_to_le16(sizeof(*s->vht_cap));
309 		memcpy(tlv->val, s->vht_cap, sizeof(*s->vht_cap));
310 	}
311 
312 	if (s->acl) {
313 		size_t acl_size = qtnf_cmd_acl_data_size(s->acl);
314 		struct qlink_tlv_hdr *tlv =
315 			skb_put(cmd_skb, sizeof(*tlv) + acl_size);
316 
317 		tlv->type = cpu_to_le16(QTN_TLV_ID_ACL_DATA);
318 		tlv->len = cpu_to_le16(acl_size);
319 		qlink_acl_data_cfg2q(s->acl, (struct qlink_acl_data *)tlv->val);
320 	}
321 
322 	qtnf_bus_lock(vif->mac->bus);
323 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
324 	if (ret)
325 		goto out;
326 
327 	netif_carrier_on(vif->netdev);
328 
329 out:
330 	qtnf_bus_unlock(vif->mac->bus);
331 
332 	return ret;
333 }
334 
335 int qtnf_cmd_send_stop_ap(struct qtnf_vif *vif)
336 {
337 	struct sk_buff *cmd_skb;
338 	int ret;
339 
340 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
341 					    QLINK_CMD_STOP_AP,
342 					    sizeof(struct qlink_cmd));
343 	if (!cmd_skb)
344 		return -ENOMEM;
345 
346 	qtnf_bus_lock(vif->mac->bus);
347 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
348 	if (ret)
349 		goto out;
350 
351 out:
352 	qtnf_bus_unlock(vif->mac->bus);
353 
354 	return ret;
355 }
356 
357 int qtnf_cmd_send_register_mgmt(struct qtnf_vif *vif, u16 frame_type, bool reg)
358 {
359 	struct sk_buff *cmd_skb;
360 	struct qlink_cmd_mgmt_frame_register *cmd;
361 	int ret;
362 
363 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
364 					    QLINK_CMD_REGISTER_MGMT,
365 					    sizeof(*cmd));
366 	if (!cmd_skb)
367 		return -ENOMEM;
368 
369 	qtnf_bus_lock(vif->mac->bus);
370 
371 	cmd = (struct qlink_cmd_mgmt_frame_register *)cmd_skb->data;
372 	cmd->frame_type = cpu_to_le16(frame_type);
373 	cmd->do_register = reg;
374 
375 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
376 	if (ret)
377 		goto out;
378 
379 out:
380 	qtnf_bus_unlock(vif->mac->bus);
381 
382 	return ret;
383 }
384 
385 int qtnf_cmd_send_mgmt_frame(struct qtnf_vif *vif, u32 cookie, u16 flags,
386 			     u16 freq, const u8 *buf, size_t len)
387 {
388 	struct sk_buff *cmd_skb;
389 	struct qlink_cmd_mgmt_frame_tx *cmd;
390 	int ret;
391 
392 	if (sizeof(*cmd) + len > QTNF_MAX_CMD_BUF_SIZE) {
393 		pr_warn("VIF%u.%u: frame is too big: %zu\n", vif->mac->macid,
394 			vif->vifid, len);
395 		return -E2BIG;
396 	}
397 
398 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
399 					    QLINK_CMD_SEND_MGMT_FRAME,
400 					    sizeof(*cmd));
401 	if (!cmd_skb)
402 		return -ENOMEM;
403 
404 	qtnf_bus_lock(vif->mac->bus);
405 
406 	cmd = (struct qlink_cmd_mgmt_frame_tx *)cmd_skb->data;
407 	cmd->cookie = cpu_to_le32(cookie);
408 	cmd->freq = cpu_to_le16(freq);
409 	cmd->flags = cpu_to_le16(flags);
410 
411 	if (len && buf)
412 		qtnf_cmd_skb_put_buffer(cmd_skb, buf, len);
413 
414 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
415 	if (ret)
416 		goto out;
417 
418 out:
419 	qtnf_bus_unlock(vif->mac->bus);
420 
421 	return ret;
422 }
423 
424 int qtnf_cmd_send_mgmt_set_appie(struct qtnf_vif *vif, u8 frame_type,
425 				 const u8 *buf, size_t len)
426 {
427 	struct sk_buff *cmd_skb;
428 	int ret;
429 
430 	if (len > QTNF_MAX_CMD_BUF_SIZE) {
431 		pr_warn("VIF%u.%u: %u frame is too big: %zu\n", vif->mac->macid,
432 			vif->vifid, frame_type, len);
433 		return -E2BIG;
434 	}
435 
436 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
437 					    QLINK_CMD_MGMT_SET_APPIE,
438 					    sizeof(struct qlink_cmd));
439 	if (!cmd_skb)
440 		return -ENOMEM;
441 
442 	qtnf_cmd_tlv_ie_set_add(cmd_skb, frame_type, buf, len);
443 
444 	qtnf_bus_lock(vif->mac->bus);
445 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
446 	if (ret)
447 		goto out;
448 
449 out:
450 	qtnf_bus_unlock(vif->mac->bus);
451 
452 	return ret;
453 }
454 
455 static void
456 qtnf_sta_info_parse_rate(struct rate_info *rate_dst,
457 			 const struct qlink_sta_info_rate *rate_src)
458 {
459 	rate_dst->legacy = get_unaligned_le16(&rate_src->rate) * 10;
460 
461 	rate_dst->mcs = rate_src->mcs;
462 	rate_dst->nss = rate_src->nss;
463 	rate_dst->flags = 0;
464 
465 	switch (rate_src->bw) {
466 	case QLINK_CHAN_WIDTH_5:
467 		rate_dst->bw = RATE_INFO_BW_5;
468 		break;
469 	case QLINK_CHAN_WIDTH_10:
470 		rate_dst->bw = RATE_INFO_BW_10;
471 		break;
472 	case QLINK_CHAN_WIDTH_20:
473 	case QLINK_CHAN_WIDTH_20_NOHT:
474 		rate_dst->bw = RATE_INFO_BW_20;
475 		break;
476 	case QLINK_CHAN_WIDTH_40:
477 		rate_dst->bw = RATE_INFO_BW_40;
478 		break;
479 	case QLINK_CHAN_WIDTH_80:
480 		rate_dst->bw = RATE_INFO_BW_80;
481 		break;
482 	case QLINK_CHAN_WIDTH_160:
483 		rate_dst->bw = RATE_INFO_BW_160;
484 		break;
485 	default:
486 		rate_dst->bw = 0;
487 		break;
488 	}
489 
490 	if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_HT_MCS)
491 		rate_dst->flags |= RATE_INFO_FLAGS_MCS;
492 	else if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_VHT_MCS)
493 		rate_dst->flags |= RATE_INFO_FLAGS_VHT_MCS;
494 
495 	if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_SHORT_GI)
496 		rate_dst->flags |= RATE_INFO_FLAGS_SHORT_GI;
497 }
498 
499 static void
500 qtnf_sta_info_parse_flags(struct nl80211_sta_flag_update *dst,
501 			  const struct qlink_sta_info_state *src)
502 {
503 	u32 mask, value;
504 
505 	dst->mask = 0;
506 	dst->set = 0;
507 
508 	mask = le32_to_cpu(src->mask);
509 	value = le32_to_cpu(src->value);
510 
511 	if (mask & QLINK_STA_FLAG_AUTHORIZED) {
512 		dst->mask |= BIT(NL80211_STA_FLAG_AUTHORIZED);
513 		if (value & QLINK_STA_FLAG_AUTHORIZED)
514 			dst->set |= BIT(NL80211_STA_FLAG_AUTHORIZED);
515 	}
516 
517 	if (mask & QLINK_STA_FLAG_SHORT_PREAMBLE) {
518 		dst->mask |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
519 		if (value & QLINK_STA_FLAG_SHORT_PREAMBLE)
520 			dst->set |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
521 	}
522 
523 	if (mask & QLINK_STA_FLAG_WME) {
524 		dst->mask |= BIT(NL80211_STA_FLAG_WME);
525 		if (value & QLINK_STA_FLAG_WME)
526 			dst->set |= BIT(NL80211_STA_FLAG_WME);
527 	}
528 
529 	if (mask & QLINK_STA_FLAG_MFP) {
530 		dst->mask |= BIT(NL80211_STA_FLAG_MFP);
531 		if (value & QLINK_STA_FLAG_MFP)
532 			dst->set |= BIT(NL80211_STA_FLAG_MFP);
533 	}
534 
535 	if (mask & QLINK_STA_FLAG_AUTHENTICATED) {
536 		dst->mask |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
537 		if (value & QLINK_STA_FLAG_AUTHENTICATED)
538 			dst->set |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
539 	}
540 
541 	if (mask & QLINK_STA_FLAG_TDLS_PEER) {
542 		dst->mask |= BIT(NL80211_STA_FLAG_TDLS_PEER);
543 		if (value & QLINK_STA_FLAG_TDLS_PEER)
544 			dst->set |= BIT(NL80211_STA_FLAG_TDLS_PEER);
545 	}
546 
547 	if (mask & QLINK_STA_FLAG_ASSOCIATED) {
548 		dst->mask |= BIT(NL80211_STA_FLAG_ASSOCIATED);
549 		if (value & QLINK_STA_FLAG_ASSOCIATED)
550 			dst->set |= BIT(NL80211_STA_FLAG_ASSOCIATED);
551 	}
552 }
553 
554 static void
555 qtnf_cmd_sta_info_parse(struct station_info *sinfo,
556 			const struct qlink_tlv_hdr *tlv,
557 			size_t resp_size)
558 {
559 	const struct qlink_sta_stats *stats = NULL;
560 	const u8 *map = NULL;
561 	unsigned int map_len = 0;
562 	unsigned int stats_len = 0;
563 	u16 tlv_len;
564 
565 #define qtnf_sta_stat_avail(stat_name, bitn)	\
566 	(qtnf_utils_is_bit_set(map, bitn, map_len) && \
567 	 (offsetofend(struct qlink_sta_stats, stat_name) <= stats_len))
568 
569 	while (resp_size >= sizeof(*tlv)) {
570 		tlv_len = le16_to_cpu(tlv->len);
571 
572 		switch (le16_to_cpu(tlv->type)) {
573 		case QTN_TLV_ID_STA_STATS_MAP:
574 			map_len = tlv_len;
575 			map = tlv->val;
576 			break;
577 		case QTN_TLV_ID_STA_STATS:
578 			stats_len = tlv_len;
579 			stats = (const struct qlink_sta_stats *)tlv->val;
580 			break;
581 		default:
582 			break;
583 		}
584 
585 		resp_size -= tlv_len + sizeof(*tlv);
586 		tlv = (const struct qlink_tlv_hdr *)(tlv->val + tlv_len);
587 	}
588 
589 	if (!map || !stats)
590 		return;
591 
592 	if (qtnf_sta_stat_avail(inactive_time, QLINK_STA_INFO_INACTIVE_TIME)) {
593 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_INACTIVE_TIME);
594 		sinfo->inactive_time = le32_to_cpu(stats->inactive_time);
595 	}
596 
597 	if (qtnf_sta_stat_avail(connected_time,
598 				QLINK_STA_INFO_CONNECTED_TIME)) {
599 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_CONNECTED_TIME);
600 		sinfo->connected_time = le32_to_cpu(stats->connected_time);
601 	}
602 
603 	if (qtnf_sta_stat_avail(signal, QLINK_STA_INFO_SIGNAL)) {
604 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL);
605 		sinfo->signal = stats->signal - QLINK_RSSI_OFFSET;
606 	}
607 
608 	if (qtnf_sta_stat_avail(signal_avg, QLINK_STA_INFO_SIGNAL_AVG)) {
609 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL_AVG);
610 		sinfo->signal_avg = stats->signal_avg - QLINK_RSSI_OFFSET;
611 	}
612 
613 	if (qtnf_sta_stat_avail(rxrate, QLINK_STA_INFO_RX_BITRATE)) {
614 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BITRATE);
615 		qtnf_sta_info_parse_rate(&sinfo->rxrate, &stats->rxrate);
616 	}
617 
618 	if (qtnf_sta_stat_avail(txrate, QLINK_STA_INFO_TX_BITRATE)) {
619 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BITRATE);
620 		qtnf_sta_info_parse_rate(&sinfo->txrate, &stats->txrate);
621 	}
622 
623 	if (qtnf_sta_stat_avail(sta_flags, QLINK_STA_INFO_STA_FLAGS)) {
624 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_STA_FLAGS);
625 		qtnf_sta_info_parse_flags(&sinfo->sta_flags, &stats->sta_flags);
626 	}
627 
628 	if (qtnf_sta_stat_avail(rx_bytes, QLINK_STA_INFO_RX_BYTES)) {
629 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BYTES);
630 		sinfo->rx_bytes = le64_to_cpu(stats->rx_bytes);
631 	}
632 
633 	if (qtnf_sta_stat_avail(tx_bytes, QLINK_STA_INFO_TX_BYTES)) {
634 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BYTES);
635 		sinfo->tx_bytes = le64_to_cpu(stats->tx_bytes);
636 	}
637 
638 	if (qtnf_sta_stat_avail(rx_bytes, QLINK_STA_INFO_RX_BYTES64)) {
639 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BYTES64);
640 		sinfo->rx_bytes = le64_to_cpu(stats->rx_bytes);
641 	}
642 
643 	if (qtnf_sta_stat_avail(tx_bytes, QLINK_STA_INFO_TX_BYTES64)) {
644 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BYTES64);
645 		sinfo->tx_bytes = le64_to_cpu(stats->tx_bytes);
646 	}
647 
648 	if (qtnf_sta_stat_avail(rx_packets, QLINK_STA_INFO_RX_PACKETS)) {
649 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_PACKETS);
650 		sinfo->rx_packets = le32_to_cpu(stats->rx_packets);
651 	}
652 
653 	if (qtnf_sta_stat_avail(tx_packets, QLINK_STA_INFO_TX_PACKETS)) {
654 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_PACKETS);
655 		sinfo->tx_packets = le32_to_cpu(stats->tx_packets);
656 	}
657 
658 	if (qtnf_sta_stat_avail(rx_beacon, QLINK_STA_INFO_BEACON_RX)) {
659 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_BEACON_RX);
660 		sinfo->rx_beacon = le64_to_cpu(stats->rx_beacon);
661 	}
662 
663 	if (qtnf_sta_stat_avail(rx_dropped_misc, QLINK_STA_INFO_RX_DROP_MISC)) {
664 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_DROP_MISC);
665 		sinfo->rx_dropped_misc = le32_to_cpu(stats->rx_dropped_misc);
666 	}
667 
668 	if (qtnf_sta_stat_avail(tx_failed, QLINK_STA_INFO_TX_FAILED)) {
669 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_FAILED);
670 		sinfo->tx_failed = le32_to_cpu(stats->tx_failed);
671 	}
672 
673 #undef qtnf_sta_stat_avail
674 }
675 
676 int qtnf_cmd_get_sta_info(struct qtnf_vif *vif, const u8 *sta_mac,
677 			  struct station_info *sinfo)
678 {
679 	struct sk_buff *cmd_skb, *resp_skb = NULL;
680 	struct qlink_cmd_get_sta_info *cmd;
681 	const struct qlink_resp_get_sta_info *resp;
682 	size_t var_resp_len = 0;
683 	int ret = 0;
684 
685 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
686 					    QLINK_CMD_GET_STA_INFO,
687 					    sizeof(*cmd));
688 	if (!cmd_skb)
689 		return -ENOMEM;
690 
691 	qtnf_bus_lock(vif->mac->bus);
692 
693 	cmd = (struct qlink_cmd_get_sta_info *)cmd_skb->data;
694 	ether_addr_copy(cmd->sta_addr, sta_mac);
695 
696 	ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
697 				       sizeof(*resp), &var_resp_len);
698 	if (ret)
699 		goto out;
700 
701 	resp = (const struct qlink_resp_get_sta_info *)resp_skb->data;
702 
703 	if (!ether_addr_equal(sta_mac, resp->sta_addr)) {
704 		pr_err("VIF%u.%u: wrong mac in reply: %pM != %pM\n",
705 		       vif->mac->macid, vif->vifid, resp->sta_addr, sta_mac);
706 		ret = -EINVAL;
707 		goto out;
708 	}
709 
710 	qtnf_cmd_sta_info_parse(sinfo,
711 				(const struct qlink_tlv_hdr *)resp->info,
712 				var_resp_len);
713 
714 out:
715 	qtnf_bus_unlock(vif->mac->bus);
716 	consume_skb(resp_skb);
717 
718 	return ret;
719 }
720 
721 static int qtnf_cmd_send_add_change_intf(struct qtnf_vif *vif,
722 					 enum nl80211_iftype iftype,
723 					 int use4addr,
724 					 u8 *mac_addr,
725 					 enum qlink_cmd_type cmd_type)
726 {
727 	struct sk_buff *cmd_skb, *resp_skb = NULL;
728 	struct qlink_cmd_manage_intf *cmd;
729 	const struct qlink_resp_manage_intf *resp;
730 	int ret = 0;
731 
732 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
733 					    cmd_type,
734 					    sizeof(*cmd));
735 	if (!cmd_skb)
736 		return -ENOMEM;
737 
738 	qtnf_bus_lock(vif->mac->bus);
739 
740 	cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
741 	cmd->intf_info.use4addr = use4addr;
742 
743 	switch (iftype) {
744 	case NL80211_IFTYPE_AP:
745 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
746 		break;
747 	case NL80211_IFTYPE_STATION:
748 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
749 		break;
750 	default:
751 		pr_err("VIF%u.%u: unsupported type %d\n", vif->mac->macid,
752 		       vif->vifid, iftype);
753 		ret = -EINVAL;
754 		goto out;
755 	}
756 
757 	if (mac_addr)
758 		ether_addr_copy(cmd->intf_info.mac_addr, mac_addr);
759 	else
760 		eth_zero_addr(cmd->intf_info.mac_addr);
761 
762 	ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
763 				       sizeof(*resp), NULL);
764 	if (ret)
765 		goto out;
766 
767 	resp = (const struct qlink_resp_manage_intf *)resp_skb->data;
768 	ether_addr_copy(vif->mac_addr, resp->intf_info.mac_addr);
769 
770 out:
771 	qtnf_bus_unlock(vif->mac->bus);
772 	consume_skb(resp_skb);
773 
774 	return ret;
775 }
776 
777 int qtnf_cmd_send_add_intf(struct qtnf_vif *vif, enum nl80211_iftype iftype,
778 			   int use4addr, u8 *mac_addr)
779 {
780 	return qtnf_cmd_send_add_change_intf(vif, iftype, use4addr, mac_addr,
781 			QLINK_CMD_ADD_INTF);
782 }
783 
784 int qtnf_cmd_send_change_intf_type(struct qtnf_vif *vif,
785 				   enum nl80211_iftype iftype,
786 				   int use4addr,
787 				   u8 *mac_addr)
788 {
789 	return qtnf_cmd_send_add_change_intf(vif, iftype, use4addr, mac_addr,
790 					     QLINK_CMD_CHANGE_INTF);
791 }
792 
793 int qtnf_cmd_send_del_intf(struct qtnf_vif *vif)
794 {
795 	struct sk_buff *cmd_skb;
796 	struct qlink_cmd_manage_intf *cmd;
797 	int ret = 0;
798 
799 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
800 					    QLINK_CMD_DEL_INTF,
801 					    sizeof(*cmd));
802 	if (!cmd_skb)
803 		return -ENOMEM;
804 
805 	qtnf_bus_lock(vif->mac->bus);
806 
807 	cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
808 
809 	switch (vif->wdev.iftype) {
810 	case NL80211_IFTYPE_AP:
811 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
812 		break;
813 	case NL80211_IFTYPE_STATION:
814 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
815 		break;
816 	default:
817 		pr_warn("VIF%u.%u: unsupported iftype %d\n", vif->mac->macid,
818 			vif->vifid, vif->wdev.iftype);
819 		ret = -EINVAL;
820 		goto out;
821 	}
822 
823 	eth_zero_addr(cmd->intf_info.mac_addr);
824 
825 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
826 	if (ret)
827 		goto out;
828 
829 out:
830 	qtnf_bus_unlock(vif->mac->bus);
831 	return ret;
832 }
833 
834 static u32 qtnf_cmd_resp_reg_rule_flags_parse(u32 qflags)
835 {
836 	u32 flags = 0;
837 
838 	if (qflags & QLINK_RRF_NO_OFDM)
839 		flags |= NL80211_RRF_NO_OFDM;
840 
841 	if (qflags & QLINK_RRF_NO_CCK)
842 		flags |= NL80211_RRF_NO_CCK;
843 
844 	if (qflags & QLINK_RRF_NO_INDOOR)
845 		flags |= NL80211_RRF_NO_INDOOR;
846 
847 	if (qflags & QLINK_RRF_NO_OUTDOOR)
848 		flags |= NL80211_RRF_NO_OUTDOOR;
849 
850 	if (qflags & QLINK_RRF_DFS)
851 		flags |= NL80211_RRF_DFS;
852 
853 	if (qflags & QLINK_RRF_PTP_ONLY)
854 		flags |= NL80211_RRF_PTP_ONLY;
855 
856 	if (qflags & QLINK_RRF_PTMP_ONLY)
857 		flags |= NL80211_RRF_PTMP_ONLY;
858 
859 	if (qflags & QLINK_RRF_NO_IR)
860 		flags |= NL80211_RRF_NO_IR;
861 
862 	if (qflags & QLINK_RRF_AUTO_BW)
863 		flags |= NL80211_RRF_AUTO_BW;
864 
865 	if (qflags & QLINK_RRF_IR_CONCURRENT)
866 		flags |= NL80211_RRF_IR_CONCURRENT;
867 
868 	if (qflags & QLINK_RRF_NO_HT40MINUS)
869 		flags |= NL80211_RRF_NO_HT40MINUS;
870 
871 	if (qflags & QLINK_RRF_NO_HT40PLUS)
872 		flags |= NL80211_RRF_NO_HT40PLUS;
873 
874 	if (qflags & QLINK_RRF_NO_80MHZ)
875 		flags |= NL80211_RRF_NO_80MHZ;
876 
877 	if (qflags & QLINK_RRF_NO_160MHZ)
878 		flags |= NL80211_RRF_NO_160MHZ;
879 
880 	return flags;
881 }
882 
883 static int
884 qtnf_cmd_resp_proc_hw_info(struct qtnf_bus *bus,
885 			   const struct qlink_resp_get_hw_info *resp,
886 			   size_t info_len)
887 {
888 	struct qtnf_hw_info *hwinfo = &bus->hw_info;
889 	const struct qlink_tlv_hdr *tlv;
890 	const struct qlink_tlv_reg_rule *tlv_rule;
891 	const char *bld_name = NULL;
892 	const char *bld_rev = NULL;
893 	const char *bld_type = NULL;
894 	const char *bld_label = NULL;
895 	u32 bld_tmstamp = 0;
896 	u32 plat_id = 0;
897 	const char *hw_id = NULL;
898 	const char *calibration_ver = NULL;
899 	const char *uboot_ver = NULL;
900 	u32 hw_ver = 0;
901 	struct ieee80211_reg_rule *rule;
902 	u16 tlv_type;
903 	u16 tlv_value_len;
904 	unsigned int rule_idx = 0;
905 
906 	if (WARN_ON(resp->n_reg_rules > NL80211_MAX_SUPP_REG_RULES))
907 		return -E2BIG;
908 
909 	hwinfo->rd = kzalloc(struct_size(hwinfo->rd, reg_rules,
910 					 resp->n_reg_rules), GFP_KERNEL);
911 
912 	if (!hwinfo->rd)
913 		return -ENOMEM;
914 
915 	hwinfo->num_mac = resp->num_mac;
916 	hwinfo->mac_bitmap = resp->mac_bitmap;
917 	hwinfo->fw_ver = le32_to_cpu(resp->fw_ver);
918 	hwinfo->ql_proto_ver = le16_to_cpu(resp->ql_proto_ver);
919 	hwinfo->total_tx_chain = resp->total_tx_chain;
920 	hwinfo->total_rx_chain = resp->total_rx_chain;
921 	hwinfo->hw_capab = le32_to_cpu(resp->hw_capab);
922 	hwinfo->rd->n_reg_rules = resp->n_reg_rules;
923 	hwinfo->rd->alpha2[0] = resp->alpha2[0];
924 	hwinfo->rd->alpha2[1] = resp->alpha2[1];
925 
926 	bld_tmstamp = le32_to_cpu(resp->bld_tmstamp);
927 	plat_id = le32_to_cpu(resp->plat_id);
928 	hw_ver = le32_to_cpu(resp->hw_ver);
929 
930 	switch (resp->dfs_region) {
931 	case QLINK_DFS_FCC:
932 		hwinfo->rd->dfs_region = NL80211_DFS_FCC;
933 		break;
934 	case QLINK_DFS_ETSI:
935 		hwinfo->rd->dfs_region = NL80211_DFS_ETSI;
936 		break;
937 	case QLINK_DFS_JP:
938 		hwinfo->rd->dfs_region = NL80211_DFS_JP;
939 		break;
940 	case QLINK_DFS_UNSET:
941 	default:
942 		hwinfo->rd->dfs_region = NL80211_DFS_UNSET;
943 		break;
944 	}
945 
946 	tlv = (const struct qlink_tlv_hdr *)resp->info;
947 
948 	while (info_len >= sizeof(*tlv)) {
949 		tlv_type = le16_to_cpu(tlv->type);
950 		tlv_value_len = le16_to_cpu(tlv->len);
951 
952 		if (tlv_value_len + sizeof(*tlv) > info_len) {
953 			pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
954 				tlv_type, tlv_value_len);
955 			return -EINVAL;
956 		}
957 
958 		switch (tlv_type) {
959 		case QTN_TLV_ID_REG_RULE:
960 			if (rule_idx >= resp->n_reg_rules) {
961 				pr_warn("unexpected number of rules: %u\n",
962 					resp->n_reg_rules);
963 				return -EINVAL;
964 			}
965 
966 			if (tlv_value_len != sizeof(*tlv_rule) - sizeof(*tlv)) {
967 				pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
968 					tlv_type, tlv_value_len);
969 				return -EINVAL;
970 			}
971 
972 			tlv_rule = (const struct qlink_tlv_reg_rule *)tlv;
973 			rule = &hwinfo->rd->reg_rules[rule_idx++];
974 
975 			rule->freq_range.start_freq_khz =
976 				le32_to_cpu(tlv_rule->start_freq_khz);
977 			rule->freq_range.end_freq_khz =
978 				le32_to_cpu(tlv_rule->end_freq_khz);
979 			rule->freq_range.max_bandwidth_khz =
980 				le32_to_cpu(tlv_rule->max_bandwidth_khz);
981 			rule->power_rule.max_antenna_gain =
982 				le32_to_cpu(tlv_rule->max_antenna_gain);
983 			rule->power_rule.max_eirp =
984 				le32_to_cpu(tlv_rule->max_eirp);
985 			rule->dfs_cac_ms =
986 				le32_to_cpu(tlv_rule->dfs_cac_ms);
987 			rule->flags = qtnf_cmd_resp_reg_rule_flags_parse(
988 					le32_to_cpu(tlv_rule->flags));
989 			break;
990 		case QTN_TLV_ID_BUILD_NAME:
991 			bld_name = (const void *)tlv->val;
992 			break;
993 		case QTN_TLV_ID_BUILD_REV:
994 			bld_rev = (const void *)tlv->val;
995 			break;
996 		case QTN_TLV_ID_BUILD_TYPE:
997 			bld_type = (const void *)tlv->val;
998 			break;
999 		case QTN_TLV_ID_BUILD_LABEL:
1000 			bld_label = (const void *)tlv->val;
1001 			break;
1002 		case QTN_TLV_ID_HW_ID:
1003 			hw_id = (const void *)tlv->val;
1004 			break;
1005 		case QTN_TLV_ID_CALIBRATION_VER:
1006 			calibration_ver = (const void *)tlv->val;
1007 			break;
1008 		case QTN_TLV_ID_UBOOT_VER:
1009 			uboot_ver = (const void *)tlv->val;
1010 			break;
1011 		case QTN_TLV_ID_MAX_SCAN_SSIDS:
1012 			hwinfo->max_scan_ssids = *tlv->val;
1013 			break;
1014 		default:
1015 			break;
1016 		}
1017 
1018 		info_len -= tlv_value_len + sizeof(*tlv);
1019 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1020 	}
1021 
1022 	if (rule_idx != resp->n_reg_rules) {
1023 		pr_warn("unexpected number of rules: expected %u got %u\n",
1024 			resp->n_reg_rules, rule_idx);
1025 		kfree(hwinfo->rd);
1026 		hwinfo->rd = NULL;
1027 		return -EINVAL;
1028 	}
1029 
1030 	pr_info("fw_version=%d, MACs map %#x, alpha2=\"%c%c\", chains Tx=%u Rx=%u, capab=0x%x\n",
1031 		hwinfo->fw_ver, hwinfo->mac_bitmap,
1032 		hwinfo->rd->alpha2[0], hwinfo->rd->alpha2[1],
1033 		hwinfo->total_tx_chain, hwinfo->total_rx_chain,
1034 		hwinfo->hw_capab);
1035 
1036 	pr_info("\nBuild name:            %s"  \
1037 		"\nBuild revision:        %s"  \
1038 		"\nBuild type:            %s"  \
1039 		"\nBuild label:           %s"  \
1040 		"\nBuild timestamp:       %lu" \
1041 		"\nPlatform ID:           %lu" \
1042 		"\nHardware ID:           %s"  \
1043 		"\nCalibration version:   %s"  \
1044 		"\nU-Boot version:        %s"  \
1045 		"\nHardware version:      0x%08x",
1046 		bld_name, bld_rev, bld_type, bld_label,
1047 		(unsigned long)bld_tmstamp,
1048 		(unsigned long)plat_id,
1049 		hw_id, calibration_ver, uboot_ver, hw_ver);
1050 
1051 	strlcpy(hwinfo->fw_version, bld_label, sizeof(hwinfo->fw_version));
1052 	hwinfo->hw_version = hw_ver;
1053 
1054 	return 0;
1055 }
1056 
1057 static void
1058 qtnf_parse_wowlan_info(struct qtnf_wmac *mac,
1059 		       const struct qlink_wowlan_capab_data *wowlan)
1060 {
1061 	struct qtnf_mac_info *mac_info = &mac->macinfo;
1062 	const struct qlink_wowlan_support *data1;
1063 	struct wiphy_wowlan_support *supp;
1064 
1065 	supp = kzalloc(sizeof(*supp), GFP_KERNEL);
1066 	if (!supp)
1067 		return;
1068 
1069 	switch (le16_to_cpu(wowlan->version)) {
1070 	case 0x1:
1071 		data1 = (struct qlink_wowlan_support *)wowlan->data;
1072 
1073 		supp->flags = WIPHY_WOWLAN_MAGIC_PKT | WIPHY_WOWLAN_DISCONNECT;
1074 		supp->n_patterns = le32_to_cpu(data1->n_patterns);
1075 		supp->pattern_max_len = le32_to_cpu(data1->pattern_max_len);
1076 		supp->pattern_min_len = le32_to_cpu(data1->pattern_min_len);
1077 
1078 		mac_info->wowlan = supp;
1079 		break;
1080 	default:
1081 		pr_warn("MAC%u: unsupported WoWLAN version 0x%x\n",
1082 			mac->macid, le16_to_cpu(wowlan->version));
1083 		kfree(supp);
1084 		break;
1085 	}
1086 }
1087 
1088 static int qtnf_parse_variable_mac_info(struct qtnf_wmac *mac,
1089 					const u8 *tlv_buf, size_t tlv_buf_size)
1090 {
1091 	struct ieee80211_iface_combination *comb = NULL;
1092 	size_t n_comb = 0;
1093 	struct ieee80211_iface_limit *limits;
1094 	const struct qlink_iface_comb_num *comb_num;
1095 	const struct qlink_iface_limit_record *rec;
1096 	const struct qlink_iface_limit *lim;
1097 	const struct qlink_wowlan_capab_data *wowlan;
1098 	u16 rec_len;
1099 	u16 tlv_type;
1100 	u16 tlv_value_len;
1101 	size_t tlv_full_len;
1102 	const struct qlink_tlv_hdr *tlv;
1103 	u8 *ext_capa = NULL;
1104 	u8 *ext_capa_mask = NULL;
1105 	u8 ext_capa_len = 0;
1106 	u8 ext_capa_mask_len = 0;
1107 	int i = 0;
1108 
1109 	tlv = (const struct qlink_tlv_hdr *)tlv_buf;
1110 	while (tlv_buf_size >= sizeof(struct qlink_tlv_hdr)) {
1111 		tlv_type = le16_to_cpu(tlv->type);
1112 		tlv_value_len = le16_to_cpu(tlv->len);
1113 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1114 		if (tlv_full_len > tlv_buf_size) {
1115 			pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1116 				mac->macid, tlv_type, tlv_value_len);
1117 			return -EINVAL;
1118 		}
1119 
1120 		switch (tlv_type) {
1121 		case QTN_TLV_ID_NUM_IFACE_COMB:
1122 			if (tlv_value_len != sizeof(*comb_num))
1123 				return -EINVAL;
1124 
1125 			comb_num = (void *)tlv->val;
1126 
1127 			/* free earlier iface comb memory */
1128 			qtnf_mac_iface_comb_free(mac);
1129 
1130 			mac->macinfo.n_if_comb =
1131 				le32_to_cpu(comb_num->iface_comb_num);
1132 
1133 			mac->macinfo.if_comb =
1134 				kcalloc(mac->macinfo.n_if_comb,
1135 					sizeof(*mac->macinfo.if_comb),
1136 					GFP_KERNEL);
1137 
1138 			if (!mac->macinfo.if_comb)
1139 				return -ENOMEM;
1140 
1141 			comb = mac->macinfo.if_comb;
1142 
1143 			pr_debug("MAC%u: %zu iface combinations\n",
1144 				 mac->macid, mac->macinfo.n_if_comb);
1145 
1146 			break;
1147 		case QTN_TLV_ID_IFACE_LIMIT:
1148 			if (unlikely(!comb)) {
1149 				pr_warn("MAC%u: no combinations advertised\n",
1150 					mac->macid);
1151 				return -EINVAL;
1152 			}
1153 
1154 			if (n_comb >= mac->macinfo.n_if_comb) {
1155 				pr_warn("MAC%u: combinations count exceeded\n",
1156 					mac->macid);
1157 				n_comb++;
1158 				break;
1159 			}
1160 
1161 			rec = (void *)tlv->val;
1162 			rec_len = sizeof(*rec) + rec->n_limits * sizeof(*lim);
1163 
1164 			if (unlikely(tlv_value_len != rec_len)) {
1165 				pr_warn("MAC%u: record %zu size mismatch\n",
1166 					mac->macid, n_comb);
1167 				return -EINVAL;
1168 			}
1169 
1170 			limits = kcalloc(rec->n_limits, sizeof(*limits),
1171 					 GFP_KERNEL);
1172 			if (!limits)
1173 				return -ENOMEM;
1174 
1175 			comb[n_comb].num_different_channels =
1176 				rec->num_different_channels;
1177 			comb[n_comb].max_interfaces =
1178 				le16_to_cpu(rec->max_interfaces);
1179 			comb[n_comb].n_limits = rec->n_limits;
1180 			comb[n_comb].limits = limits;
1181 
1182 			for (i = 0; i < rec->n_limits; i++) {
1183 				lim = &rec->limits[i];
1184 				limits[i].max = le16_to_cpu(lim->max_num);
1185 				limits[i].types =
1186 					qlink_iface_type_to_nl_mask(le16_to_cpu(lim->type));
1187 				pr_debug("MAC%u: comb[%zu]: MAX:%u TYPES:%.4X\n",
1188 					 mac->macid, n_comb,
1189 					 limits[i].max, limits[i].types);
1190 			}
1191 
1192 			n_comb++;
1193 			break;
1194 		case WLAN_EID_EXT_CAPABILITY:
1195 			if (unlikely(tlv_value_len > U8_MAX))
1196 				return -EINVAL;
1197 			ext_capa = (u8 *)tlv->val;
1198 			ext_capa_len = tlv_value_len;
1199 			break;
1200 		case QTN_TLV_ID_EXT_CAPABILITY_MASK:
1201 			if (unlikely(tlv_value_len > U8_MAX))
1202 				return -EINVAL;
1203 			ext_capa_mask = (u8 *)tlv->val;
1204 			ext_capa_mask_len = tlv_value_len;
1205 			break;
1206 		case QTN_TLV_ID_WOWLAN_CAPAB:
1207 			if (tlv_value_len < sizeof(*wowlan))
1208 				return -EINVAL;
1209 
1210 			wowlan = (void *)tlv->val;
1211 			if (!le16_to_cpu(wowlan->len)) {
1212 				pr_warn("MAC%u: skip empty WoWLAN data\n",
1213 					mac->macid);
1214 				break;
1215 			}
1216 
1217 			rec_len = sizeof(*wowlan) + le16_to_cpu(wowlan->len);
1218 			if (unlikely(tlv_value_len != rec_len)) {
1219 				pr_warn("MAC%u: WoWLAN data size mismatch\n",
1220 					mac->macid);
1221 				return -EINVAL;
1222 			}
1223 
1224 			kfree(mac->macinfo.wowlan);
1225 			mac->macinfo.wowlan = NULL;
1226 			qtnf_parse_wowlan_info(mac, wowlan);
1227 			break;
1228 		default:
1229 			pr_warn("MAC%u: unknown TLV type %u\n",
1230 				mac->macid, tlv_type);
1231 			break;
1232 		}
1233 
1234 		tlv_buf_size -= tlv_full_len;
1235 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1236 	}
1237 
1238 	if (tlv_buf_size) {
1239 		pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1240 			mac->macid, tlv_buf_size);
1241 		return -EINVAL;
1242 	}
1243 
1244 	if (mac->macinfo.n_if_comb != n_comb) {
1245 		pr_err("MAC%u: combination mismatch: reported=%zu parsed=%zu\n",
1246 		       mac->macid, mac->macinfo.n_if_comb, n_comb);
1247 		return -EINVAL;
1248 	}
1249 
1250 	if (ext_capa_len != ext_capa_mask_len) {
1251 		pr_err("MAC%u: ext_capa/_mask lengths mismatch: %u != %u\n",
1252 		       mac->macid, ext_capa_len, ext_capa_mask_len);
1253 		return -EINVAL;
1254 	}
1255 
1256 	if (ext_capa_len > 0) {
1257 		ext_capa = kmemdup(ext_capa, ext_capa_len, GFP_KERNEL);
1258 		if (!ext_capa)
1259 			return -ENOMEM;
1260 
1261 		ext_capa_mask =
1262 			kmemdup(ext_capa_mask, ext_capa_mask_len, GFP_KERNEL);
1263 		if (!ext_capa_mask) {
1264 			kfree(ext_capa);
1265 			return -ENOMEM;
1266 		}
1267 	} else {
1268 		ext_capa = NULL;
1269 		ext_capa_mask = NULL;
1270 	}
1271 
1272 	qtnf_mac_ext_caps_free(mac);
1273 	mac->macinfo.extended_capabilities = ext_capa;
1274 	mac->macinfo.extended_capabilities_mask = ext_capa_mask;
1275 	mac->macinfo.extended_capabilities_len = ext_capa_len;
1276 
1277 	return 0;
1278 }
1279 
1280 static void
1281 qtnf_cmd_resp_proc_mac_info(struct qtnf_wmac *mac,
1282 			    const struct qlink_resp_get_mac_info *resp_info)
1283 {
1284 	struct qtnf_mac_info *mac_info;
1285 	struct qtnf_vif *vif;
1286 
1287 	mac_info = &mac->macinfo;
1288 
1289 	mac_info->bands_cap = resp_info->bands_cap;
1290 	memcpy(&mac_info->dev_mac, &resp_info->dev_mac,
1291 	       sizeof(mac_info->dev_mac));
1292 
1293 	ether_addr_copy(mac->macaddr, mac_info->dev_mac);
1294 
1295 	vif = qtnf_mac_get_base_vif(mac);
1296 	if (vif)
1297 		ether_addr_copy(vif->mac_addr, mac->macaddr);
1298 	else
1299 		pr_err("could not get valid base vif\n");
1300 
1301 	mac_info->num_tx_chain = resp_info->num_tx_chain;
1302 	mac_info->num_rx_chain = resp_info->num_rx_chain;
1303 
1304 	mac_info->max_ap_assoc_sta = le16_to_cpu(resp_info->max_ap_assoc_sta);
1305 	mac_info->radar_detect_widths =
1306 			qlink_chan_width_mask_to_nl(le16_to_cpu(
1307 					resp_info->radar_detect_widths));
1308 	mac_info->max_acl_mac_addrs = le32_to_cpu(resp_info->max_acl_mac_addrs);
1309 
1310 	memcpy(&mac_info->ht_cap_mod_mask, &resp_info->ht_cap_mod_mask,
1311 	       sizeof(mac_info->ht_cap_mod_mask));
1312 	memcpy(&mac_info->vht_cap_mod_mask, &resp_info->vht_cap_mod_mask,
1313 	       sizeof(mac_info->vht_cap_mod_mask));
1314 }
1315 
1316 static void qtnf_cmd_resp_band_fill_htcap(const u8 *info,
1317 					  struct ieee80211_sta_ht_cap *bcap)
1318 {
1319 	const struct ieee80211_ht_cap *ht_cap =
1320 		(const struct ieee80211_ht_cap *)info;
1321 
1322 	bcap->ht_supported = true;
1323 	bcap->cap = le16_to_cpu(ht_cap->cap_info);
1324 	bcap->ampdu_factor =
1325 		ht_cap->ampdu_params_info & IEEE80211_HT_AMPDU_PARM_FACTOR;
1326 	bcap->ampdu_density =
1327 		(ht_cap->ampdu_params_info & IEEE80211_HT_AMPDU_PARM_DENSITY) >>
1328 		IEEE80211_HT_AMPDU_PARM_DENSITY_SHIFT;
1329 	memcpy(&bcap->mcs, &ht_cap->mcs, sizeof(bcap->mcs));
1330 }
1331 
1332 static void qtnf_cmd_resp_band_fill_vhtcap(const u8 *info,
1333 					   struct ieee80211_sta_vht_cap *bcap)
1334 {
1335 	const struct ieee80211_vht_cap *vht_cap =
1336 		(const struct ieee80211_vht_cap *)info;
1337 
1338 	bcap->vht_supported = true;
1339 	bcap->cap = le32_to_cpu(vht_cap->vht_cap_info);
1340 	memcpy(&bcap->vht_mcs, &vht_cap->supp_mcs, sizeof(bcap->vht_mcs));
1341 }
1342 
1343 static int
1344 qtnf_cmd_resp_fill_band_info(struct ieee80211_supported_band *band,
1345 			     struct qlink_resp_band_info_get *resp,
1346 			     size_t payload_len)
1347 {
1348 	u16 tlv_type;
1349 	size_t tlv_len;
1350 	size_t tlv_dlen;
1351 	const struct qlink_tlv_hdr *tlv;
1352 	const struct qlink_channel *qchan;
1353 	struct ieee80211_channel *chan;
1354 	unsigned int chidx = 0;
1355 	u32 qflags;
1356 
1357 	memset(&band->ht_cap, 0, sizeof(band->ht_cap));
1358 	memset(&band->vht_cap, 0, sizeof(band->vht_cap));
1359 
1360 	if (band->channels) {
1361 		if (band->n_channels == resp->num_chans) {
1362 			memset(band->channels, 0,
1363 			       sizeof(*band->channels) * band->n_channels);
1364 		} else {
1365 			kfree(band->channels);
1366 			band->n_channels = 0;
1367 			band->channels = NULL;
1368 		}
1369 	}
1370 
1371 	band->n_channels = resp->num_chans;
1372 	if (band->n_channels == 0)
1373 		return 0;
1374 
1375 	if (!band->channels)
1376 		band->channels = kcalloc(band->n_channels, sizeof(*chan),
1377 					 GFP_KERNEL);
1378 	if (!band->channels) {
1379 		band->n_channels = 0;
1380 		return -ENOMEM;
1381 	}
1382 
1383 	tlv = (struct qlink_tlv_hdr *)resp->info;
1384 
1385 	while (payload_len >= sizeof(*tlv)) {
1386 		tlv_type = le16_to_cpu(tlv->type);
1387 		tlv_dlen = le16_to_cpu(tlv->len);
1388 		tlv_len = tlv_dlen + sizeof(*tlv);
1389 
1390 		if (tlv_len > payload_len) {
1391 			pr_warn("malformed TLV 0x%.2X; LEN: %zu\n",
1392 				tlv_type, tlv_len);
1393 			goto error_ret;
1394 		}
1395 
1396 		switch (tlv_type) {
1397 		case QTN_TLV_ID_CHANNEL:
1398 			if (unlikely(tlv_dlen != sizeof(*qchan))) {
1399 				pr_err("invalid channel TLV len %zu\n",
1400 				       tlv_len);
1401 				goto error_ret;
1402 			}
1403 
1404 			if (chidx == band->n_channels) {
1405 				pr_err("too many channel TLVs\n");
1406 				goto error_ret;
1407 			}
1408 
1409 			qchan = (const struct qlink_channel *)tlv->val;
1410 			chan = &band->channels[chidx++];
1411 			qflags = le32_to_cpu(qchan->flags);
1412 
1413 			chan->hw_value = le16_to_cpu(qchan->hw_value);
1414 			chan->band = band->band;
1415 			chan->center_freq = le16_to_cpu(qchan->center_freq);
1416 			chan->max_antenna_gain = (int)qchan->max_antenna_gain;
1417 			chan->max_power = (int)qchan->max_power;
1418 			chan->max_reg_power = (int)qchan->max_reg_power;
1419 			chan->beacon_found = qchan->beacon_found;
1420 			chan->dfs_cac_ms = le32_to_cpu(qchan->dfs_cac_ms);
1421 			chan->flags = 0;
1422 
1423 			if (qflags & QLINK_CHAN_DISABLED)
1424 				chan->flags |= IEEE80211_CHAN_DISABLED;
1425 
1426 			if (qflags & QLINK_CHAN_NO_IR)
1427 				chan->flags |= IEEE80211_CHAN_NO_IR;
1428 
1429 			if (qflags & QLINK_CHAN_NO_HT40PLUS)
1430 				chan->flags |= IEEE80211_CHAN_NO_HT40PLUS;
1431 
1432 			if (qflags & QLINK_CHAN_NO_HT40MINUS)
1433 				chan->flags |= IEEE80211_CHAN_NO_HT40MINUS;
1434 
1435 			if (qflags & QLINK_CHAN_NO_OFDM)
1436 				chan->flags |= IEEE80211_CHAN_NO_OFDM;
1437 
1438 			if (qflags & QLINK_CHAN_NO_80MHZ)
1439 				chan->flags |= IEEE80211_CHAN_NO_80MHZ;
1440 
1441 			if (qflags & QLINK_CHAN_NO_160MHZ)
1442 				chan->flags |= IEEE80211_CHAN_NO_160MHZ;
1443 
1444 			if (qflags & QLINK_CHAN_INDOOR_ONLY)
1445 				chan->flags |= IEEE80211_CHAN_INDOOR_ONLY;
1446 
1447 			if (qflags & QLINK_CHAN_IR_CONCURRENT)
1448 				chan->flags |= IEEE80211_CHAN_IR_CONCURRENT;
1449 
1450 			if (qflags & QLINK_CHAN_NO_20MHZ)
1451 				chan->flags |= IEEE80211_CHAN_NO_20MHZ;
1452 
1453 			if (qflags & QLINK_CHAN_NO_10MHZ)
1454 				chan->flags |= IEEE80211_CHAN_NO_10MHZ;
1455 
1456 			if (qflags & QLINK_CHAN_RADAR) {
1457 				chan->flags |= IEEE80211_CHAN_RADAR;
1458 				chan->dfs_state_entered = jiffies;
1459 
1460 				if (qchan->dfs_state == QLINK_DFS_USABLE)
1461 					chan->dfs_state = NL80211_DFS_USABLE;
1462 				else if (qchan->dfs_state ==
1463 					QLINK_DFS_AVAILABLE)
1464 					chan->dfs_state = NL80211_DFS_AVAILABLE;
1465 				else
1466 					chan->dfs_state =
1467 						NL80211_DFS_UNAVAILABLE;
1468 			}
1469 
1470 			pr_debug("chan=%d flags=%#x max_pow=%d max_reg_pow=%d\n",
1471 				 chan->hw_value, chan->flags, chan->max_power,
1472 				 chan->max_reg_power);
1473 			break;
1474 		case WLAN_EID_HT_CAPABILITY:
1475 			if (unlikely(tlv_dlen !=
1476 				     sizeof(struct ieee80211_ht_cap))) {
1477 				pr_err("bad HTCAP TLV len %zu\n", tlv_dlen);
1478 				goto error_ret;
1479 			}
1480 
1481 			qtnf_cmd_resp_band_fill_htcap(tlv->val, &band->ht_cap);
1482 			break;
1483 		case WLAN_EID_VHT_CAPABILITY:
1484 			if (unlikely(tlv_dlen !=
1485 				     sizeof(struct ieee80211_vht_cap))) {
1486 				pr_err("bad VHTCAP TLV len %zu\n", tlv_dlen);
1487 				goto error_ret;
1488 			}
1489 
1490 			qtnf_cmd_resp_band_fill_vhtcap(tlv->val,
1491 						       &band->vht_cap);
1492 			break;
1493 		default:
1494 			pr_warn("unknown TLV type: %#x\n", tlv_type);
1495 			break;
1496 		}
1497 
1498 		payload_len -= tlv_len;
1499 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_dlen);
1500 	}
1501 
1502 	if (payload_len) {
1503 		pr_err("malformed TLV buf; bytes left: %zu\n", payload_len);
1504 		goto error_ret;
1505 	}
1506 
1507 	if (band->n_channels != chidx) {
1508 		pr_err("channel count mismatch: reported=%d, parsed=%d\n",
1509 		       band->n_channels, chidx);
1510 		goto error_ret;
1511 	}
1512 
1513 	return 0;
1514 
1515 error_ret:
1516 	kfree(band->channels);
1517 	band->channels = NULL;
1518 	band->n_channels = 0;
1519 
1520 	return -EINVAL;
1521 }
1522 
1523 static int qtnf_cmd_resp_proc_phy_params(struct qtnf_wmac *mac,
1524 					 const u8 *payload, size_t payload_len)
1525 {
1526 	struct qtnf_mac_info *mac_info;
1527 	struct qlink_tlv_frag_rts_thr *phy_thr;
1528 	struct qlink_tlv_rlimit *limit;
1529 	struct qlink_tlv_cclass *class;
1530 	u16 tlv_type;
1531 	u16 tlv_value_len;
1532 	size_t tlv_full_len;
1533 	const struct qlink_tlv_hdr *tlv;
1534 
1535 	mac_info = &mac->macinfo;
1536 
1537 	tlv = (struct qlink_tlv_hdr *)payload;
1538 	while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1539 		tlv_type = le16_to_cpu(tlv->type);
1540 		tlv_value_len = le16_to_cpu(tlv->len);
1541 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1542 
1543 		if (tlv_full_len > payload_len) {
1544 			pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1545 				mac->macid, tlv_type, tlv_value_len);
1546 			return -EINVAL;
1547 		}
1548 
1549 		switch (tlv_type) {
1550 		case QTN_TLV_ID_FRAG_THRESH:
1551 			phy_thr = (void *)tlv;
1552 			mac_info->frag_thr = le32_to_cpu(phy_thr->thr);
1553 			break;
1554 		case QTN_TLV_ID_RTS_THRESH:
1555 			phy_thr = (void *)tlv;
1556 			mac_info->rts_thr = le32_to_cpu(phy_thr->thr);
1557 			break;
1558 		case QTN_TLV_ID_SRETRY_LIMIT:
1559 			limit = (void *)tlv;
1560 			mac_info->sretry_limit = limit->rlimit;
1561 			break;
1562 		case QTN_TLV_ID_LRETRY_LIMIT:
1563 			limit = (void *)tlv;
1564 			mac_info->lretry_limit = limit->rlimit;
1565 			break;
1566 		case QTN_TLV_ID_COVERAGE_CLASS:
1567 			class = (void *)tlv;
1568 			mac_info->coverage_class = class->cclass;
1569 			break;
1570 		default:
1571 			pr_err("MAC%u: Unknown TLV type: %#x\n", mac->macid,
1572 			       le16_to_cpu(tlv->type));
1573 			break;
1574 		}
1575 
1576 		payload_len -= tlv_full_len;
1577 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1578 	}
1579 
1580 	if (payload_len) {
1581 		pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1582 			mac->macid, payload_len);
1583 		return -EINVAL;
1584 	}
1585 
1586 	return 0;
1587 }
1588 
1589 static int
1590 qtnf_cmd_resp_proc_chan_stat_info(struct qtnf_chan_stats *stats,
1591 				  const u8 *payload, size_t payload_len)
1592 {
1593 	struct qlink_chan_stats *qlink_stats;
1594 	const struct qlink_tlv_hdr *tlv;
1595 	size_t tlv_full_len;
1596 	u16 tlv_value_len;
1597 	u16 tlv_type;
1598 
1599 	tlv = (struct qlink_tlv_hdr *)payload;
1600 	while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1601 		tlv_type = le16_to_cpu(tlv->type);
1602 		tlv_value_len = le16_to_cpu(tlv->len);
1603 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1604 		if (tlv_full_len > payload_len) {
1605 			pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
1606 				tlv_type, tlv_value_len);
1607 			return -EINVAL;
1608 		}
1609 		switch (tlv_type) {
1610 		case QTN_TLV_ID_CHANNEL_STATS:
1611 			if (unlikely(tlv_value_len != sizeof(*qlink_stats))) {
1612 				pr_err("invalid CHANNEL_STATS entry size\n");
1613 				return -EINVAL;
1614 			}
1615 
1616 			qlink_stats = (void *)tlv->val;
1617 
1618 			stats->chan_num = le32_to_cpu(qlink_stats->chan_num);
1619 			stats->cca_tx = le32_to_cpu(qlink_stats->cca_tx);
1620 			stats->cca_rx = le32_to_cpu(qlink_stats->cca_rx);
1621 			stats->cca_busy = le32_to_cpu(qlink_stats->cca_busy);
1622 			stats->cca_try = le32_to_cpu(qlink_stats->cca_try);
1623 			stats->chan_noise = qlink_stats->chan_noise;
1624 
1625 			pr_debug("chan(%u) try(%u) busy(%u) noise(%d)\n",
1626 				 stats->chan_num, stats->cca_try,
1627 				 stats->cca_busy, stats->chan_noise);
1628 			break;
1629 		default:
1630 			pr_warn("Unknown TLV type: %#x\n",
1631 				le16_to_cpu(tlv->type));
1632 		}
1633 		payload_len -= tlv_full_len;
1634 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1635 	}
1636 
1637 	if (payload_len) {
1638 		pr_warn("malformed TLV buf; bytes left: %zu\n", payload_len);
1639 		return -EINVAL;
1640 	}
1641 
1642 	return 0;
1643 }
1644 
1645 int qtnf_cmd_get_mac_info(struct qtnf_wmac *mac)
1646 {
1647 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1648 	const struct qlink_resp_get_mac_info *resp;
1649 	size_t var_data_len = 0;
1650 	int ret = 0;
1651 
1652 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
1653 					    QLINK_CMD_MAC_INFO,
1654 					    sizeof(struct qlink_cmd));
1655 	if (!cmd_skb)
1656 		return -ENOMEM;
1657 
1658 	qtnf_bus_lock(mac->bus);
1659 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
1660 				       sizeof(*resp), &var_data_len);
1661 	if (ret)
1662 		goto out;
1663 
1664 	resp = (const struct qlink_resp_get_mac_info *)resp_skb->data;
1665 	qtnf_cmd_resp_proc_mac_info(mac, resp);
1666 	ret = qtnf_parse_variable_mac_info(mac, resp->var_info, var_data_len);
1667 
1668 out:
1669 	qtnf_bus_unlock(mac->bus);
1670 	consume_skb(resp_skb);
1671 
1672 	return ret;
1673 }
1674 
1675 int qtnf_cmd_get_hw_info(struct qtnf_bus *bus)
1676 {
1677 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1678 	const struct qlink_resp_get_hw_info *resp;
1679 	size_t info_len = 0;
1680 	int ret = 0;
1681 
1682 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1683 					    QLINK_CMD_GET_HW_INFO,
1684 					    sizeof(struct qlink_cmd));
1685 	if (!cmd_skb)
1686 		return -ENOMEM;
1687 
1688 	qtnf_bus_lock(bus);
1689 	ret = qtnf_cmd_send_with_reply(bus, cmd_skb, &resp_skb,
1690 				       sizeof(*resp), &info_len);
1691 	if (ret)
1692 		goto out;
1693 
1694 	resp = (const struct qlink_resp_get_hw_info *)resp_skb->data;
1695 	ret = qtnf_cmd_resp_proc_hw_info(bus, resp, info_len);
1696 
1697 out:
1698 	qtnf_bus_unlock(bus);
1699 	consume_skb(resp_skb);
1700 
1701 	return ret;
1702 }
1703 
1704 int qtnf_cmd_band_info_get(struct qtnf_wmac *mac,
1705 			   struct ieee80211_supported_band *band)
1706 {
1707 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1708 	struct qlink_cmd_band_info_get *cmd;
1709 	struct qlink_resp_band_info_get *resp;
1710 	size_t info_len = 0;
1711 	int ret = 0;
1712 	u8 qband;
1713 
1714 	switch (band->band) {
1715 	case NL80211_BAND_2GHZ:
1716 		qband = QLINK_BAND_2GHZ;
1717 		break;
1718 	case NL80211_BAND_5GHZ:
1719 		qband = QLINK_BAND_5GHZ;
1720 		break;
1721 	case NL80211_BAND_60GHZ:
1722 		qband = QLINK_BAND_60GHZ;
1723 		break;
1724 	default:
1725 		return -EINVAL;
1726 	}
1727 
1728 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1729 					    QLINK_CMD_BAND_INFO_GET,
1730 					    sizeof(*cmd));
1731 	if (!cmd_skb)
1732 		return -ENOMEM;
1733 
1734 	cmd = (struct qlink_cmd_band_info_get *)cmd_skb->data;
1735 	cmd->band = qband;
1736 
1737 	qtnf_bus_lock(mac->bus);
1738 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
1739 				       sizeof(*resp), &info_len);
1740 	if (ret)
1741 		goto out;
1742 
1743 	resp = (struct qlink_resp_band_info_get *)resp_skb->data;
1744 	if (resp->band != qband) {
1745 		pr_err("MAC%u: reply band %u != cmd band %u\n", mac->macid,
1746 		       resp->band, qband);
1747 		ret = -EINVAL;
1748 		goto out;
1749 	}
1750 
1751 	ret = qtnf_cmd_resp_fill_band_info(band, resp, info_len);
1752 
1753 out:
1754 	qtnf_bus_unlock(mac->bus);
1755 	consume_skb(resp_skb);
1756 
1757 	return ret;
1758 }
1759 
1760 int qtnf_cmd_send_get_phy_params(struct qtnf_wmac *mac)
1761 {
1762 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1763 	struct qlink_resp_phy_params *resp;
1764 	size_t response_size = 0;
1765 	int ret = 0;
1766 
1767 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1768 					    QLINK_CMD_PHY_PARAMS_GET,
1769 					    sizeof(struct qlink_cmd));
1770 	if (!cmd_skb)
1771 		return -ENOMEM;
1772 
1773 	qtnf_bus_lock(mac->bus);
1774 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
1775 				       sizeof(*resp), &response_size);
1776 	if (ret)
1777 		goto out;
1778 
1779 	resp = (struct qlink_resp_phy_params *)resp_skb->data;
1780 	ret = qtnf_cmd_resp_proc_phy_params(mac, resp->info, response_size);
1781 
1782 out:
1783 	qtnf_bus_unlock(mac->bus);
1784 	consume_skb(resp_skb);
1785 
1786 	return ret;
1787 }
1788 
1789 int qtnf_cmd_send_update_phy_params(struct qtnf_wmac *mac, u32 changed)
1790 {
1791 	struct wiphy *wiphy = priv_to_wiphy(mac);
1792 	struct sk_buff *cmd_skb;
1793 	int ret = 0;
1794 
1795 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1796 					    QLINK_CMD_PHY_PARAMS_SET,
1797 					    sizeof(struct qlink_cmd));
1798 	if (!cmd_skb)
1799 		return -ENOMEM;
1800 
1801 	qtnf_bus_lock(mac->bus);
1802 
1803 	if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1804 		qtnf_cmd_skb_put_tlv_u32(cmd_skb, QTN_TLV_ID_FRAG_THRESH,
1805 					 wiphy->frag_threshold);
1806 	if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1807 		qtnf_cmd_skb_put_tlv_u32(cmd_skb, QTN_TLV_ID_RTS_THRESH,
1808 					 wiphy->rts_threshold);
1809 	if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1810 		qtnf_cmd_skb_put_tlv_u8(cmd_skb, QTN_TLV_ID_COVERAGE_CLASS,
1811 					wiphy->coverage_class);
1812 
1813 	if (changed & WIPHY_PARAM_RETRY_LONG)
1814 		qtnf_cmd_skb_put_tlv_u8(cmd_skb, QTN_TLV_ID_LRETRY_LIMIT,
1815 					wiphy->retry_long);
1816 
1817 	if (changed & WIPHY_PARAM_RETRY_SHORT)
1818 		qtnf_cmd_skb_put_tlv_u8(cmd_skb, QTN_TLV_ID_SRETRY_LIMIT,
1819 					wiphy->retry_short);
1820 
1821 	ret = qtnf_cmd_send(mac->bus, cmd_skb);
1822 	if (ret)
1823 		goto out;
1824 
1825 out:
1826 	qtnf_bus_unlock(mac->bus);
1827 
1828 	return ret;
1829 }
1830 
1831 int qtnf_cmd_send_init_fw(struct qtnf_bus *bus)
1832 {
1833 	struct sk_buff *cmd_skb;
1834 	int ret = 0;
1835 
1836 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1837 					    QLINK_CMD_FW_INIT,
1838 					    sizeof(struct qlink_cmd));
1839 	if (!cmd_skb)
1840 		return -ENOMEM;
1841 
1842 	qtnf_bus_lock(bus);
1843 	ret = qtnf_cmd_send(bus, cmd_skb);
1844 	if (ret)
1845 		goto out;
1846 
1847 out:
1848 	qtnf_bus_unlock(bus);
1849 
1850 	return ret;
1851 }
1852 
1853 void qtnf_cmd_send_deinit_fw(struct qtnf_bus *bus)
1854 {
1855 	struct sk_buff *cmd_skb;
1856 
1857 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1858 					    QLINK_CMD_FW_DEINIT,
1859 					    sizeof(struct qlink_cmd));
1860 	if (!cmd_skb)
1861 		return;
1862 
1863 	qtnf_bus_lock(bus);
1864 	qtnf_cmd_send(bus, cmd_skb);
1865 	qtnf_bus_unlock(bus);
1866 }
1867 
1868 int qtnf_cmd_send_add_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
1869 			  const u8 *mac_addr, struct key_params *params)
1870 {
1871 	struct sk_buff *cmd_skb;
1872 	struct qlink_cmd_add_key *cmd;
1873 	int ret = 0;
1874 
1875 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1876 					    QLINK_CMD_ADD_KEY,
1877 					    sizeof(*cmd));
1878 	if (!cmd_skb)
1879 		return -ENOMEM;
1880 
1881 	qtnf_bus_lock(vif->mac->bus);
1882 
1883 	cmd = (struct qlink_cmd_add_key *)cmd_skb->data;
1884 
1885 	if (mac_addr)
1886 		ether_addr_copy(cmd->addr, mac_addr);
1887 	else
1888 		eth_broadcast_addr(cmd->addr);
1889 
1890 	cmd->cipher = cpu_to_le32(params->cipher);
1891 	cmd->key_index = key_index;
1892 	cmd->pairwise = pairwise;
1893 
1894 	if (params->key && params->key_len > 0)
1895 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_KEY,
1896 					 params->key,
1897 					 params->key_len);
1898 
1899 	if (params->seq && params->seq_len > 0)
1900 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_SEQ,
1901 					 params->seq,
1902 					 params->seq_len);
1903 
1904 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1905 	if (ret)
1906 		goto out;
1907 
1908 out:
1909 	qtnf_bus_unlock(vif->mac->bus);
1910 
1911 	return ret;
1912 }
1913 
1914 int qtnf_cmd_send_del_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
1915 			  const u8 *mac_addr)
1916 {
1917 	struct sk_buff *cmd_skb;
1918 	struct qlink_cmd_del_key *cmd;
1919 	int ret = 0;
1920 
1921 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1922 					    QLINK_CMD_DEL_KEY,
1923 					    sizeof(*cmd));
1924 	if (!cmd_skb)
1925 		return -ENOMEM;
1926 
1927 	qtnf_bus_lock(vif->mac->bus);
1928 
1929 	cmd = (struct qlink_cmd_del_key *)cmd_skb->data;
1930 
1931 	if (mac_addr)
1932 		ether_addr_copy(cmd->addr, mac_addr);
1933 	else
1934 		eth_broadcast_addr(cmd->addr);
1935 
1936 	cmd->key_index = key_index;
1937 	cmd->pairwise = pairwise;
1938 
1939 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1940 	if (ret)
1941 		goto out;
1942 
1943 out:
1944 	qtnf_bus_unlock(vif->mac->bus);
1945 
1946 	return ret;
1947 }
1948 
1949 int qtnf_cmd_send_set_default_key(struct qtnf_vif *vif, u8 key_index,
1950 				  bool unicast, bool multicast)
1951 {
1952 	struct sk_buff *cmd_skb;
1953 	struct qlink_cmd_set_def_key *cmd;
1954 	int ret = 0;
1955 
1956 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1957 					    QLINK_CMD_SET_DEFAULT_KEY,
1958 					    sizeof(*cmd));
1959 	if (!cmd_skb)
1960 		return -ENOMEM;
1961 
1962 	qtnf_bus_lock(vif->mac->bus);
1963 
1964 	cmd = (struct qlink_cmd_set_def_key *)cmd_skb->data;
1965 	cmd->key_index = key_index;
1966 	cmd->unicast = unicast;
1967 	cmd->multicast = multicast;
1968 
1969 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1970 	if (ret)
1971 		goto out;
1972 
1973 out:
1974 	qtnf_bus_unlock(vif->mac->bus);
1975 
1976 	return ret;
1977 }
1978 
1979 int qtnf_cmd_send_set_default_mgmt_key(struct qtnf_vif *vif, u8 key_index)
1980 {
1981 	struct sk_buff *cmd_skb;
1982 	struct qlink_cmd_set_def_mgmt_key *cmd;
1983 	int ret = 0;
1984 
1985 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1986 					    QLINK_CMD_SET_DEFAULT_MGMT_KEY,
1987 					    sizeof(*cmd));
1988 	if (!cmd_skb)
1989 		return -ENOMEM;
1990 
1991 	qtnf_bus_lock(vif->mac->bus);
1992 
1993 	cmd = (struct qlink_cmd_set_def_mgmt_key *)cmd_skb->data;
1994 	cmd->key_index = key_index;
1995 
1996 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1997 	if (ret)
1998 		goto out;
1999 
2000 out:
2001 	qtnf_bus_unlock(vif->mac->bus);
2002 
2003 	return ret;
2004 }
2005 
2006 static u32 qtnf_encode_sta_flags(u32 flags)
2007 {
2008 	u32 code = 0;
2009 
2010 	if (flags & BIT(NL80211_STA_FLAG_AUTHORIZED))
2011 		code |= QLINK_STA_FLAG_AUTHORIZED;
2012 	if (flags & BIT(NL80211_STA_FLAG_SHORT_PREAMBLE))
2013 		code |= QLINK_STA_FLAG_SHORT_PREAMBLE;
2014 	if (flags & BIT(NL80211_STA_FLAG_WME))
2015 		code |= QLINK_STA_FLAG_WME;
2016 	if (flags & BIT(NL80211_STA_FLAG_MFP))
2017 		code |= QLINK_STA_FLAG_MFP;
2018 	if (flags & BIT(NL80211_STA_FLAG_AUTHENTICATED))
2019 		code |= QLINK_STA_FLAG_AUTHENTICATED;
2020 	if (flags & BIT(NL80211_STA_FLAG_TDLS_PEER))
2021 		code |= QLINK_STA_FLAG_TDLS_PEER;
2022 	if (flags & BIT(NL80211_STA_FLAG_ASSOCIATED))
2023 		code |= QLINK_STA_FLAG_ASSOCIATED;
2024 	return code;
2025 }
2026 
2027 int qtnf_cmd_send_change_sta(struct qtnf_vif *vif, const u8 *mac,
2028 			     struct station_parameters *params)
2029 {
2030 	struct sk_buff *cmd_skb;
2031 	struct qlink_cmd_change_sta *cmd;
2032 	int ret = 0;
2033 
2034 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2035 					    QLINK_CMD_CHANGE_STA,
2036 					    sizeof(*cmd));
2037 	if (!cmd_skb)
2038 		return -ENOMEM;
2039 
2040 	qtnf_bus_lock(vif->mac->bus);
2041 
2042 	cmd = (struct qlink_cmd_change_sta *)cmd_skb->data;
2043 	ether_addr_copy(cmd->sta_addr, mac);
2044 	cmd->flag_update.mask =
2045 		cpu_to_le32(qtnf_encode_sta_flags(params->sta_flags_mask));
2046 	cmd->flag_update.value =
2047 		cpu_to_le32(qtnf_encode_sta_flags(params->sta_flags_set));
2048 
2049 	switch (vif->wdev.iftype) {
2050 	case NL80211_IFTYPE_AP:
2051 		cmd->if_type = cpu_to_le16(QLINK_IFTYPE_AP);
2052 		break;
2053 	case NL80211_IFTYPE_STATION:
2054 		cmd->if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
2055 		break;
2056 	default:
2057 		pr_err("unsupported iftype %d\n", vif->wdev.iftype);
2058 		ret = -EINVAL;
2059 		goto out;
2060 	}
2061 
2062 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2063 	if (ret)
2064 		goto out;
2065 
2066 out:
2067 	qtnf_bus_unlock(vif->mac->bus);
2068 
2069 	return ret;
2070 }
2071 
2072 int qtnf_cmd_send_del_sta(struct qtnf_vif *vif,
2073 			  struct station_del_parameters *params)
2074 {
2075 	struct sk_buff *cmd_skb;
2076 	struct qlink_cmd_del_sta *cmd;
2077 	int ret = 0;
2078 
2079 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2080 					    QLINK_CMD_DEL_STA,
2081 					    sizeof(*cmd));
2082 	if (!cmd_skb)
2083 		return -ENOMEM;
2084 
2085 	qtnf_bus_lock(vif->mac->bus);
2086 
2087 	cmd = (struct qlink_cmd_del_sta *)cmd_skb->data;
2088 
2089 	if (params->mac)
2090 		ether_addr_copy(cmd->sta_addr, params->mac);
2091 	else
2092 		eth_broadcast_addr(cmd->sta_addr);	/* flush all stations */
2093 
2094 	cmd->subtype = params->subtype;
2095 	cmd->reason_code = cpu_to_le16(params->reason_code);
2096 
2097 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2098 	if (ret)
2099 		goto out;
2100 
2101 out:
2102 	qtnf_bus_unlock(vif->mac->bus);
2103 
2104 	return ret;
2105 }
2106 
2107 static void qtnf_cmd_channel_tlv_add(struct sk_buff *cmd_skb,
2108 				     const struct ieee80211_channel *sc)
2109 {
2110 	struct qlink_tlv_channel *qchan;
2111 	u32 flags = 0;
2112 
2113 	qchan = skb_put_zero(cmd_skb, sizeof(*qchan));
2114 	qchan->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANNEL);
2115 	qchan->hdr.len = cpu_to_le16(sizeof(*qchan) - sizeof(qchan->hdr));
2116 	qchan->chan.center_freq = cpu_to_le16(sc->center_freq);
2117 	qchan->chan.hw_value = cpu_to_le16(sc->hw_value);
2118 
2119 	if (sc->flags & IEEE80211_CHAN_NO_IR)
2120 		flags |= QLINK_CHAN_NO_IR;
2121 
2122 	if (sc->flags & IEEE80211_CHAN_RADAR)
2123 		flags |= QLINK_CHAN_RADAR;
2124 
2125 	qchan->chan.flags = cpu_to_le32(flags);
2126 }
2127 
2128 static void qtnf_cmd_randmac_tlv_add(struct sk_buff *cmd_skb,
2129 				     const u8 *mac_addr,
2130 				     const u8 *mac_addr_mask)
2131 {
2132 	struct qlink_random_mac_addr *randmac;
2133 	struct qlink_tlv_hdr *hdr =
2134 		skb_put(cmd_skb, sizeof(*hdr) + sizeof(*randmac));
2135 
2136 	hdr->type = cpu_to_le16(QTN_TLV_ID_RANDOM_MAC_ADDR);
2137 	hdr->len = cpu_to_le16(sizeof(*randmac));
2138 	randmac = (struct qlink_random_mac_addr *)hdr->val;
2139 
2140 	memcpy(randmac->mac_addr, mac_addr, ETH_ALEN);
2141 	memcpy(randmac->mac_addr_mask, mac_addr_mask, ETH_ALEN);
2142 }
2143 
2144 int qtnf_cmd_send_scan(struct qtnf_wmac *mac)
2145 {
2146 	struct sk_buff *cmd_skb;
2147 	struct ieee80211_channel *sc;
2148 	struct cfg80211_scan_request *scan_req = mac->scan_req;
2149 	int n_channels;
2150 	int count = 0;
2151 	int ret;
2152 
2153 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
2154 					    QLINK_CMD_SCAN,
2155 					    sizeof(struct qlink_cmd));
2156 	if (!cmd_skb)
2157 		return -ENOMEM;
2158 
2159 	qtnf_bus_lock(mac->bus);
2160 
2161 	if (scan_req->n_ssids != 0) {
2162 		while (count < scan_req->n_ssids) {
2163 			qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID,
2164 				scan_req->ssids[count].ssid,
2165 				scan_req->ssids[count].ssid_len);
2166 			count++;
2167 		}
2168 	}
2169 
2170 	if (scan_req->ie_len != 0)
2171 		qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_REQ,
2172 					scan_req->ie, scan_req->ie_len);
2173 
2174 	if (scan_req->n_channels) {
2175 		n_channels = scan_req->n_channels;
2176 		count = 0;
2177 
2178 		while (n_channels != 0) {
2179 			sc = scan_req->channels[count];
2180 			if (sc->flags & IEEE80211_CHAN_DISABLED) {
2181 				n_channels--;
2182 				continue;
2183 			}
2184 
2185 			pr_debug("MAC%u: scan chan=%d, freq=%d, flags=%#x\n",
2186 				 mac->macid, sc->hw_value, sc->center_freq,
2187 				 sc->flags);
2188 
2189 			qtnf_cmd_channel_tlv_add(cmd_skb, sc);
2190 			n_channels--;
2191 			count++;
2192 		}
2193 	}
2194 
2195 	if (scan_req->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
2196 		pr_debug("MAC%u: scan with random addr=%pM, mask=%pM\n",
2197 			 mac->macid,
2198 			 scan_req->mac_addr, scan_req->mac_addr_mask);
2199 
2200 		qtnf_cmd_randmac_tlv_add(cmd_skb, scan_req->mac_addr,
2201 					 scan_req->mac_addr_mask);
2202 	}
2203 
2204 	if (scan_req->flags & NL80211_SCAN_FLAG_FLUSH) {
2205 		pr_debug("MAC%u: flush cache before scan\n", mac->macid);
2206 
2207 		qtnf_cmd_skb_put_tlv_tag(cmd_skb, QTN_TLV_ID_SCAN_FLUSH);
2208 	}
2209 
2210 	if (scan_req->duration) {
2211 		pr_debug("MAC%u: %s scan duration %u\n", mac->macid,
2212 			 scan_req->duration_mandatory ? "mandatory" : "max",
2213 			 scan_req->duration);
2214 
2215 		qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_SCAN_DWELL,
2216 					 scan_req->duration);
2217 	}
2218 
2219 	ret = qtnf_cmd_send(mac->bus, cmd_skb);
2220 	if (ret)
2221 		goto out;
2222 
2223 out:
2224 	qtnf_bus_unlock(mac->bus);
2225 
2226 	return ret;
2227 }
2228 
2229 int qtnf_cmd_send_connect(struct qtnf_vif *vif,
2230 			  struct cfg80211_connect_params *sme)
2231 {
2232 	struct sk_buff *cmd_skb;
2233 	struct qlink_cmd_connect *cmd;
2234 	struct qlink_auth_encr *aen;
2235 	int ret;
2236 	int i;
2237 	u32 connect_flags = 0;
2238 
2239 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2240 					    QLINK_CMD_CONNECT,
2241 					    sizeof(*cmd));
2242 	if (!cmd_skb)
2243 		return -ENOMEM;
2244 
2245 	cmd = (struct qlink_cmd_connect *)cmd_skb->data;
2246 
2247 	ether_addr_copy(cmd->bssid, vif->bssid);
2248 
2249 	if (sme->bssid_hint)
2250 		ether_addr_copy(cmd->bssid_hint, sme->bssid_hint);
2251 	else
2252 		eth_zero_addr(cmd->bssid_hint);
2253 
2254 	if (sme->prev_bssid)
2255 		ether_addr_copy(cmd->prev_bssid, sme->prev_bssid);
2256 	else
2257 		eth_zero_addr(cmd->prev_bssid);
2258 
2259 	if ((sme->bg_scan_period >= 0) &&
2260 	    (sme->bg_scan_period <= SHRT_MAX))
2261 		cmd->bg_scan_period = cpu_to_le16(sme->bg_scan_period);
2262 	else
2263 		cmd->bg_scan_period = cpu_to_le16(-1); /* use default value */
2264 
2265 	if (sme->flags & ASSOC_REQ_DISABLE_HT)
2266 		connect_flags |= QLINK_STA_CONNECT_DISABLE_HT;
2267 	if (sme->flags & ASSOC_REQ_DISABLE_VHT)
2268 		connect_flags |= QLINK_STA_CONNECT_DISABLE_VHT;
2269 	if (sme->flags & ASSOC_REQ_USE_RRM)
2270 		connect_flags |= QLINK_STA_CONNECT_USE_RRM;
2271 
2272 	cmd->flags = cpu_to_le32(connect_flags);
2273 	memcpy(&cmd->ht_capa, &sme->ht_capa, sizeof(cmd->ht_capa));
2274 	memcpy(&cmd->ht_capa_mask, &sme->ht_capa_mask,
2275 	       sizeof(cmd->ht_capa_mask));
2276 	memcpy(&cmd->vht_capa, &sme->vht_capa, sizeof(cmd->vht_capa));
2277 	memcpy(&cmd->vht_capa_mask, &sme->vht_capa_mask,
2278 	       sizeof(cmd->vht_capa_mask));
2279 	cmd->pbss = sme->pbss;
2280 
2281 	aen = &cmd->aen;
2282 	aen->auth_type = sme->auth_type;
2283 	aen->privacy = !!sme->privacy;
2284 	cmd->mfp = sme->mfp;
2285 	aen->wpa_versions = cpu_to_le32(sme->crypto.wpa_versions);
2286 	aen->cipher_group = cpu_to_le32(sme->crypto.cipher_group);
2287 	aen->n_ciphers_pairwise = cpu_to_le32(sme->crypto.n_ciphers_pairwise);
2288 
2289 	for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
2290 		aen->ciphers_pairwise[i] =
2291 			cpu_to_le32(sme->crypto.ciphers_pairwise[i]);
2292 
2293 	aen->n_akm_suites = cpu_to_le32(sme->crypto.n_akm_suites);
2294 
2295 	for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
2296 		aen->akm_suites[i] = cpu_to_le32(sme->crypto.akm_suites[i]);
2297 
2298 	aen->control_port = sme->crypto.control_port;
2299 	aen->control_port_no_encrypt =
2300 		sme->crypto.control_port_no_encrypt;
2301 	aen->control_port_ethertype =
2302 		cpu_to_le16(be16_to_cpu(sme->crypto.control_port_ethertype));
2303 
2304 	qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, sme->ssid,
2305 				 sme->ssid_len);
2306 
2307 	if (sme->ie_len != 0)
2308 		qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_ASSOC_REQ,
2309 					sme->ie, sme->ie_len);
2310 
2311 	if (sme->channel)
2312 		qtnf_cmd_channel_tlv_add(cmd_skb, sme->channel);
2313 
2314 	qtnf_bus_lock(vif->mac->bus);
2315 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2316 	if (ret)
2317 		goto out;
2318 
2319 out:
2320 	qtnf_bus_unlock(vif->mac->bus);
2321 
2322 	return ret;
2323 }
2324 
2325 int qtnf_cmd_send_external_auth(struct qtnf_vif *vif,
2326 				struct cfg80211_external_auth_params *auth)
2327 {
2328 	struct sk_buff *cmd_skb;
2329 	struct qlink_cmd_external_auth *cmd;
2330 	int ret;
2331 
2332 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2333 					    QLINK_CMD_EXTERNAL_AUTH,
2334 					    sizeof(*cmd));
2335 	if (!cmd_skb)
2336 		return -ENOMEM;
2337 
2338 	cmd = (struct qlink_cmd_external_auth *)cmd_skb->data;
2339 
2340 	ether_addr_copy(cmd->bssid, auth->bssid);
2341 	cmd->status = cpu_to_le16(auth->status);
2342 
2343 	qtnf_bus_lock(vif->mac->bus);
2344 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2345 	if (ret)
2346 		goto out;
2347 
2348 out:
2349 	qtnf_bus_unlock(vif->mac->bus);
2350 
2351 	return ret;
2352 }
2353 
2354 int qtnf_cmd_send_disconnect(struct qtnf_vif *vif, u16 reason_code)
2355 {
2356 	struct sk_buff *cmd_skb;
2357 	struct qlink_cmd_disconnect *cmd;
2358 	int ret;
2359 
2360 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2361 					    QLINK_CMD_DISCONNECT,
2362 					    sizeof(*cmd));
2363 	if (!cmd_skb)
2364 		return -ENOMEM;
2365 
2366 	qtnf_bus_lock(vif->mac->bus);
2367 
2368 	cmd = (struct qlink_cmd_disconnect *)cmd_skb->data;
2369 	cmd->reason = cpu_to_le16(reason_code);
2370 
2371 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2372 	if (ret)
2373 		goto out;
2374 
2375 out:
2376 	qtnf_bus_unlock(vif->mac->bus);
2377 
2378 	return ret;
2379 }
2380 
2381 int qtnf_cmd_send_updown_intf(struct qtnf_vif *vif, bool up)
2382 {
2383 	struct sk_buff *cmd_skb;
2384 	struct qlink_cmd_updown *cmd;
2385 	int ret;
2386 
2387 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2388 					    QLINK_CMD_UPDOWN_INTF,
2389 					    sizeof(*cmd));
2390 	if (!cmd_skb)
2391 		return -ENOMEM;
2392 
2393 	cmd = (struct qlink_cmd_updown *)cmd_skb->data;
2394 	cmd->if_up = !!up;
2395 
2396 	qtnf_bus_lock(vif->mac->bus);
2397 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2398 	if (ret)
2399 		goto out;
2400 
2401 out:
2402 	qtnf_bus_unlock(vif->mac->bus);
2403 
2404 	return ret;
2405 }
2406 
2407 int qtnf_cmd_reg_notify(struct qtnf_bus *bus, struct regulatory_request *req)
2408 {
2409 	struct sk_buff *cmd_skb;
2410 	int ret;
2411 	struct qlink_cmd_reg_notify *cmd;
2412 
2413 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
2414 					    QLINK_CMD_REG_NOTIFY,
2415 					    sizeof(*cmd));
2416 	if (!cmd_skb)
2417 		return -ENOMEM;
2418 
2419 	cmd = (struct qlink_cmd_reg_notify *)cmd_skb->data;
2420 	cmd->alpha2[0] = req->alpha2[0];
2421 	cmd->alpha2[1] = req->alpha2[1];
2422 
2423 	switch (req->initiator) {
2424 	case NL80211_REGDOM_SET_BY_CORE:
2425 		cmd->initiator = QLINK_REGDOM_SET_BY_CORE;
2426 		break;
2427 	case NL80211_REGDOM_SET_BY_USER:
2428 		cmd->initiator = QLINK_REGDOM_SET_BY_USER;
2429 		break;
2430 	case NL80211_REGDOM_SET_BY_DRIVER:
2431 		cmd->initiator = QLINK_REGDOM_SET_BY_DRIVER;
2432 		break;
2433 	case NL80211_REGDOM_SET_BY_COUNTRY_IE:
2434 		cmd->initiator = QLINK_REGDOM_SET_BY_COUNTRY_IE;
2435 		break;
2436 	}
2437 
2438 	switch (req->user_reg_hint_type) {
2439 	case NL80211_USER_REG_HINT_USER:
2440 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_USER;
2441 		break;
2442 	case NL80211_USER_REG_HINT_CELL_BASE:
2443 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_CELL_BASE;
2444 		break;
2445 	case NL80211_USER_REG_HINT_INDOOR:
2446 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_INDOOR;
2447 		break;
2448 	}
2449 
2450 	qtnf_bus_lock(bus);
2451 	ret = qtnf_cmd_send(bus, cmd_skb);
2452 	if (ret)
2453 		goto out;
2454 
2455 out:
2456 	qtnf_bus_unlock(bus);
2457 
2458 	return ret;
2459 }
2460 
2461 int qtnf_cmd_get_chan_stats(struct qtnf_wmac *mac, u16 channel,
2462 			    struct qtnf_chan_stats *stats)
2463 {
2464 	struct sk_buff *cmd_skb, *resp_skb = NULL;
2465 	struct qlink_cmd_get_chan_stats *cmd;
2466 	struct qlink_resp_get_chan_stats *resp;
2467 	size_t var_data_len = 0;
2468 	int ret = 0;
2469 
2470 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
2471 					    QLINK_CMD_CHAN_STATS,
2472 					    sizeof(*cmd));
2473 	if (!cmd_skb)
2474 		return -ENOMEM;
2475 
2476 	qtnf_bus_lock(mac->bus);
2477 
2478 	cmd = (struct qlink_cmd_get_chan_stats *)cmd_skb->data;
2479 	cmd->channel = cpu_to_le16(channel);
2480 
2481 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
2482 				       sizeof(*resp), &var_data_len);
2483 	if (ret)
2484 		goto out;
2485 
2486 	resp = (struct qlink_resp_get_chan_stats *)resp_skb->data;
2487 	ret = qtnf_cmd_resp_proc_chan_stat_info(stats, resp->info,
2488 						var_data_len);
2489 
2490 out:
2491 	qtnf_bus_unlock(mac->bus);
2492 	consume_skb(resp_skb);
2493 
2494 	return ret;
2495 }
2496 
2497 int qtnf_cmd_send_chan_switch(struct qtnf_vif *vif,
2498 			      struct cfg80211_csa_settings *params)
2499 {
2500 	struct qtnf_wmac *mac = vif->mac;
2501 	struct qlink_cmd_chan_switch *cmd;
2502 	struct sk_buff *cmd_skb;
2503 	int ret;
2504 
2505 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, vif->vifid,
2506 					    QLINK_CMD_CHAN_SWITCH,
2507 					    sizeof(*cmd));
2508 	if (!cmd_skb)
2509 		return -ENOMEM;
2510 
2511 	qtnf_bus_lock(mac->bus);
2512 
2513 	cmd = (struct qlink_cmd_chan_switch *)cmd_skb->data;
2514 	cmd->channel = cpu_to_le16(params->chandef.chan->hw_value);
2515 	cmd->radar_required = params->radar_required;
2516 	cmd->block_tx = params->block_tx;
2517 	cmd->beacon_count = params->count;
2518 
2519 	ret = qtnf_cmd_send(mac->bus, cmd_skb);
2520 	if (ret)
2521 		goto out;
2522 
2523 out:
2524 	qtnf_bus_unlock(mac->bus);
2525 
2526 	return ret;
2527 }
2528 
2529 int qtnf_cmd_get_channel(struct qtnf_vif *vif, struct cfg80211_chan_def *chdef)
2530 {
2531 	struct qtnf_bus *bus = vif->mac->bus;
2532 	const struct qlink_resp_channel_get *resp;
2533 	struct sk_buff *cmd_skb;
2534 	struct sk_buff *resp_skb = NULL;
2535 	int ret;
2536 
2537 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2538 					    QLINK_CMD_CHAN_GET,
2539 					    sizeof(struct qlink_cmd));
2540 	if (!cmd_skb)
2541 		return -ENOMEM;
2542 
2543 	qtnf_bus_lock(bus);
2544 	ret = qtnf_cmd_send_with_reply(bus, cmd_skb, &resp_skb,
2545 				       sizeof(*resp), NULL);
2546 	if (ret)
2547 		goto out;
2548 
2549 	resp = (const struct qlink_resp_channel_get *)resp_skb->data;
2550 	qlink_chandef_q2cfg(priv_to_wiphy(vif->mac), &resp->chan, chdef);
2551 
2552 out:
2553 	qtnf_bus_unlock(bus);
2554 	consume_skb(resp_skb);
2555 
2556 	return ret;
2557 }
2558 
2559 int qtnf_cmd_start_cac(const struct qtnf_vif *vif,
2560 		       const struct cfg80211_chan_def *chdef,
2561 		       u32 cac_time_ms)
2562 {
2563 	struct qtnf_bus *bus = vif->mac->bus;
2564 	struct sk_buff *cmd_skb;
2565 	struct qlink_cmd_start_cac *cmd;
2566 	int ret;
2567 
2568 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2569 					    QLINK_CMD_START_CAC,
2570 					    sizeof(*cmd));
2571 	if (!cmd_skb)
2572 		return -ENOMEM;
2573 
2574 	cmd = (struct qlink_cmd_start_cac *)cmd_skb->data;
2575 	cmd->cac_time_ms = cpu_to_le32(cac_time_ms);
2576 	qlink_chandef_cfg2q(chdef, &cmd->chan);
2577 
2578 	qtnf_bus_lock(bus);
2579 	ret = qtnf_cmd_send(bus, cmd_skb);
2580 	if (ret)
2581 		goto out;
2582 
2583 out:
2584 	qtnf_bus_unlock(bus);
2585 
2586 	return ret;
2587 }
2588 
2589 int qtnf_cmd_set_mac_acl(const struct qtnf_vif *vif,
2590 			 const struct cfg80211_acl_data *params)
2591 {
2592 	struct qtnf_bus *bus = vif->mac->bus;
2593 	struct sk_buff *cmd_skb;
2594 	struct qlink_tlv_hdr *tlv;
2595 	size_t acl_size = qtnf_cmd_acl_data_size(params);
2596 	int ret;
2597 
2598 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2599 					    QLINK_CMD_SET_MAC_ACL,
2600 					    sizeof(struct qlink_cmd));
2601 	if (!cmd_skb)
2602 		return -ENOMEM;
2603 
2604 	tlv = skb_put(cmd_skb, sizeof(*tlv) + acl_size);
2605 	tlv->type = cpu_to_le16(QTN_TLV_ID_ACL_DATA);
2606 	tlv->len = cpu_to_le16(acl_size);
2607 	qlink_acl_data_cfg2q(params, (struct qlink_acl_data *)tlv->val);
2608 
2609 	qtnf_bus_lock(bus);
2610 	ret = qtnf_cmd_send(bus, cmd_skb);
2611 	if (ret)
2612 		goto out;
2613 
2614 out:
2615 	qtnf_bus_unlock(bus);
2616 
2617 	return ret;
2618 }
2619 
2620 int qtnf_cmd_send_pm_set(const struct qtnf_vif *vif, u8 pm_mode, int timeout)
2621 {
2622 	struct qtnf_bus *bus = vif->mac->bus;
2623 	struct sk_buff *cmd_skb;
2624 	struct qlink_cmd_pm_set *cmd;
2625 	int ret = 0;
2626 
2627 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2628 					    QLINK_CMD_PM_SET, sizeof(*cmd));
2629 	if (!cmd_skb)
2630 		return -ENOMEM;
2631 
2632 	cmd = (struct qlink_cmd_pm_set *)cmd_skb->data;
2633 	cmd->pm_mode = pm_mode;
2634 	cmd->pm_standby_timer = cpu_to_le32(timeout);
2635 
2636 	qtnf_bus_lock(bus);
2637 
2638 	ret = qtnf_cmd_send(bus, cmd_skb);
2639 	if (ret)
2640 		goto out;
2641 
2642 out:
2643 	qtnf_bus_unlock(bus);
2644 
2645 	return ret;
2646 }
2647 
2648 int qtnf_cmd_send_wowlan_set(const struct qtnf_vif *vif,
2649 			     const struct cfg80211_wowlan *wowl)
2650 {
2651 	struct qtnf_bus *bus = vif->mac->bus;
2652 	struct sk_buff *cmd_skb;
2653 	struct qlink_cmd_wowlan_set *cmd;
2654 	u32 triggers = 0;
2655 	int count = 0;
2656 	int ret = 0;
2657 
2658 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2659 					    QLINK_CMD_WOWLAN_SET, sizeof(*cmd));
2660 	if (!cmd_skb)
2661 		return -ENOMEM;
2662 
2663 	qtnf_bus_lock(bus);
2664 
2665 	cmd = (struct qlink_cmd_wowlan_set *)cmd_skb->data;
2666 
2667 	if (wowl) {
2668 		if (wowl->disconnect)
2669 			triggers |=  QLINK_WOWLAN_TRIG_DISCONNECT;
2670 
2671 		if (wowl->magic_pkt)
2672 			triggers |= QLINK_WOWLAN_TRIG_MAGIC_PKT;
2673 
2674 		if (wowl->n_patterns && wowl->patterns) {
2675 			triggers |= QLINK_WOWLAN_TRIG_PATTERN_PKT;
2676 			while (count < wowl->n_patterns) {
2677 				qtnf_cmd_skb_put_tlv_arr(cmd_skb,
2678 					QTN_TLV_ID_WOWLAN_PATTERN,
2679 					wowl->patterns[count].pattern,
2680 					wowl->patterns[count].pattern_len);
2681 				count++;
2682 			}
2683 		}
2684 	}
2685 
2686 	cmd->triggers = cpu_to_le32(triggers);
2687 
2688 	ret = qtnf_cmd_send(bus, cmd_skb);
2689 	if (ret)
2690 		goto out;
2691 
2692 out:
2693 	qtnf_bus_unlock(bus);
2694 	return ret;
2695 }
2696