1 /*
2  * Copyright (c) 2015-2016 Quantenna Communications, Inc.
3  *
4  * This program is free software; you can redistribute it and/or
5  * modify it under the terms of the GNU General Public License
6  * as published by the Free Software Foundation; either version 2
7  * of the License, or (at your option) any later version.
8  *
9  * This program is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  *
14  */
15 
16 #include <linux/types.h>
17 #include <linux/skbuff.h>
18 
19 #include "cfg80211.h"
20 #include "core.h"
21 #include "qlink.h"
22 #include "qlink_util.h"
23 #include "bus.h"
24 #include "commands.h"
25 
26 static int qtnf_cmd_check_reply_header(const struct qlink_resp *resp,
27 				       u16 cmd_id, u8 mac_id, u8 vif_id,
28 				       size_t resp_size)
29 {
30 	if (unlikely(le16_to_cpu(resp->cmd_id) != cmd_id)) {
31 		pr_warn("VIF%u.%u CMD%x: bad cmd_id in response: 0x%.4X\n",
32 			mac_id, vif_id, cmd_id, le16_to_cpu(resp->cmd_id));
33 		return -EINVAL;
34 	}
35 
36 	if (unlikely(resp->macid != mac_id)) {
37 		pr_warn("VIF%u.%u CMD%x: bad MAC in response: %u\n",
38 			mac_id, vif_id, cmd_id, resp->macid);
39 		return -EINVAL;
40 	}
41 
42 	if (unlikely(resp->vifid != vif_id)) {
43 		pr_warn("VIF%u.%u CMD%x: bad VIF in response: %u\n",
44 			mac_id, vif_id, cmd_id, resp->vifid);
45 		return -EINVAL;
46 	}
47 
48 	if (unlikely(le16_to_cpu(resp->mhdr.len) < resp_size)) {
49 		pr_warn("VIF%u.%u CMD%x: bad response size %u < %zu\n",
50 			mac_id, vif_id, cmd_id,
51 			le16_to_cpu(resp->mhdr.len), resp_size);
52 		return -ENOSPC;
53 	}
54 
55 	return 0;
56 }
57 
58 static int qtnf_cmd_resp_result_decode(enum qlink_cmd_result qcode)
59 {
60 	switch (qcode) {
61 	case QLINK_CMD_RESULT_OK:
62 		return 0;
63 	case QLINK_CMD_RESULT_INVALID:
64 		return -EINVAL;
65 	case QLINK_CMD_RESULT_ENOTSUPP:
66 		return -ENOTSUPP;
67 	case QLINK_CMD_RESULT_ENOTFOUND:
68 		return -ENOENT;
69 	case QLINK_CMD_RESULT_EALREADY:
70 		return -EALREADY;
71 	case QLINK_CMD_RESULT_EADDRINUSE:
72 		return -EADDRINUSE;
73 	case QLINK_CMD_RESULT_EADDRNOTAVAIL:
74 		return -EADDRNOTAVAIL;
75 	default:
76 		return -EFAULT;
77 	}
78 }
79 
80 static int qtnf_cmd_send_with_reply(struct qtnf_bus *bus,
81 				    struct sk_buff *cmd_skb,
82 				    struct sk_buff **response_skb,
83 				    size_t const_resp_size,
84 				    size_t *var_resp_size)
85 {
86 	struct qlink_cmd *cmd;
87 	const struct qlink_resp *resp;
88 	struct sk_buff *resp_skb = NULL;
89 	u16 cmd_id;
90 	u8 mac_id;
91 	u8 vif_id;
92 	int ret;
93 
94 	cmd = (struct qlink_cmd *)cmd_skb->data;
95 	cmd_id = le16_to_cpu(cmd->cmd_id);
96 	mac_id = cmd->macid;
97 	vif_id = cmd->vifid;
98 	cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
99 
100 	pr_debug("VIF%u.%u cmd=0x%.4X\n", mac_id, vif_id,
101 		 le16_to_cpu(cmd->cmd_id));
102 
103 	if (bus->fw_state != QTNF_FW_STATE_ACTIVE &&
104 	    le16_to_cpu(cmd->cmd_id) != QLINK_CMD_FW_INIT) {
105 		pr_warn("VIF%u.%u: drop cmd 0x%.4X in fw state %d\n",
106 			mac_id, vif_id, le16_to_cpu(cmd->cmd_id),
107 			bus->fw_state);
108 		dev_kfree_skb(cmd_skb);
109 		return -ENODEV;
110 	}
111 
112 	ret = qtnf_trans_send_cmd_with_resp(bus, cmd_skb, &resp_skb);
113 	if (ret)
114 		goto out;
115 
116 	resp = (const struct qlink_resp *)resp_skb->data;
117 	ret = qtnf_cmd_check_reply_header(resp, cmd_id, mac_id, vif_id,
118 					  const_resp_size);
119 	if (ret)
120 		goto out;
121 
122 	/* Return length of variable part of response */
123 	if (response_skb && var_resp_size)
124 		*var_resp_size = le16_to_cpu(resp->mhdr.len) - const_resp_size;
125 
126 out:
127 	if (response_skb)
128 		*response_skb = resp_skb;
129 	else
130 		consume_skb(resp_skb);
131 
132 	if (!ret && resp)
133 		return qtnf_cmd_resp_result_decode(le16_to_cpu(resp->result));
134 
135 	pr_warn("VIF%u.%u: cmd 0x%.4X failed: %d\n",
136 		mac_id, vif_id, le16_to_cpu(cmd->cmd_id), ret);
137 
138 	return ret;
139 }
140 
141 static inline int qtnf_cmd_send(struct qtnf_bus *bus, struct sk_buff *cmd_skb)
142 {
143 	return qtnf_cmd_send_with_reply(bus, cmd_skb, NULL,
144 					sizeof(struct qlink_resp), NULL);
145 }
146 
147 static struct sk_buff *qtnf_cmd_alloc_new_cmdskb(u8 macid, u8 vifid, u16 cmd_no,
148 						 size_t cmd_size)
149 {
150 	struct qlink_cmd *cmd;
151 	struct sk_buff *cmd_skb;
152 
153 	cmd_skb = __dev_alloc_skb(sizeof(*cmd) +
154 				  QTNF_MAX_CMD_BUF_SIZE, GFP_KERNEL);
155 	if (unlikely(!cmd_skb)) {
156 		pr_err("VIF%u.%u CMD %u: alloc failed\n", macid, vifid, cmd_no);
157 		return NULL;
158 	}
159 
160 	skb_put_zero(cmd_skb, cmd_size);
161 
162 	cmd = (struct qlink_cmd *)cmd_skb->data;
163 	cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
164 	cmd->mhdr.type = cpu_to_le16(QLINK_MSG_TYPE_CMD);
165 	cmd->cmd_id = cpu_to_le16(cmd_no);
166 	cmd->macid = macid;
167 	cmd->vifid = vifid;
168 
169 	return cmd_skb;
170 }
171 
172 static void qtnf_cmd_tlv_ie_set_add(struct sk_buff *cmd_skb, u8 frame_type,
173 				    const u8 *buf, size_t len)
174 {
175 	struct qlink_tlv_ie_set *tlv;
176 
177 	tlv = (struct qlink_tlv_ie_set *)skb_put(cmd_skb, sizeof(*tlv) + len);
178 	tlv->hdr.type = cpu_to_le16(QTN_TLV_ID_IE_SET);
179 	tlv->hdr.len = cpu_to_le16(len + sizeof(*tlv) - sizeof(tlv->hdr));
180 	tlv->type = frame_type;
181 	tlv->flags = 0;
182 
183 	if (len && buf)
184 		memcpy(tlv->ie_data, buf, len);
185 }
186 
187 static inline size_t qtnf_cmd_acl_data_size(const struct cfg80211_acl_data *acl)
188 {
189 	size_t size = sizeof(struct qlink_acl_data) +
190 		      acl->n_acl_entries * sizeof(struct qlink_mac_address);
191 
192 	return size;
193 }
194 
195 static bool qtnf_cmd_start_ap_can_fit(const struct qtnf_vif *vif,
196 				      const struct cfg80211_ap_settings *s)
197 {
198 	unsigned int len = sizeof(struct qlink_cmd_start_ap);
199 
200 	len += s->ssid_len;
201 	len += s->beacon.head_len;
202 	len += s->beacon.tail_len;
203 	len += s->beacon.beacon_ies_len;
204 	len += s->beacon.proberesp_ies_len;
205 	len += s->beacon.assocresp_ies_len;
206 	len += s->beacon.probe_resp_len;
207 
208 	if (cfg80211_chandef_valid(&s->chandef))
209 		len += sizeof(struct qlink_tlv_chandef);
210 
211 	if (s->acl)
212 		len += sizeof(struct qlink_tlv_hdr) +
213 		       qtnf_cmd_acl_data_size(s->acl);
214 
215 	if (len > (sizeof(struct qlink_cmd) + QTNF_MAX_CMD_BUF_SIZE)) {
216 		pr_err("VIF%u.%u: can not fit AP settings: %u\n",
217 		       vif->mac->macid, vif->vifid, len);
218 		return false;
219 	}
220 
221 	return true;
222 }
223 
224 int qtnf_cmd_send_start_ap(struct qtnf_vif *vif,
225 			   const struct cfg80211_ap_settings *s)
226 {
227 	struct sk_buff *cmd_skb;
228 	struct qlink_cmd_start_ap *cmd;
229 	struct qlink_auth_encr *aen;
230 	int ret;
231 	int i;
232 
233 	if (!qtnf_cmd_start_ap_can_fit(vif, s))
234 		return -E2BIG;
235 
236 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
237 					    QLINK_CMD_START_AP,
238 					    sizeof(*cmd));
239 	if (!cmd_skb)
240 		return -ENOMEM;
241 
242 	cmd = (struct qlink_cmd_start_ap *)cmd_skb->data;
243 	cmd->dtim_period = s->dtim_period;
244 	cmd->beacon_interval = cpu_to_le16(s->beacon_interval);
245 	cmd->hidden_ssid = qlink_hidden_ssid_nl2q(s->hidden_ssid);
246 	cmd->inactivity_timeout = cpu_to_le16(s->inactivity_timeout);
247 	cmd->smps_mode = s->smps_mode;
248 	cmd->p2p_ctwindow = s->p2p_ctwindow;
249 	cmd->p2p_opp_ps = s->p2p_opp_ps;
250 	cmd->pbss = s->pbss;
251 	cmd->ht_required = s->ht_required;
252 	cmd->vht_required = s->vht_required;
253 
254 	aen = &cmd->aen;
255 	aen->auth_type = s->auth_type;
256 	aen->privacy = !!s->privacy;
257 	aen->wpa_versions = cpu_to_le32(s->crypto.wpa_versions);
258 	aen->cipher_group = cpu_to_le32(s->crypto.cipher_group);
259 	aen->n_ciphers_pairwise = cpu_to_le32(s->crypto.n_ciphers_pairwise);
260 	for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
261 		aen->ciphers_pairwise[i] =
262 				cpu_to_le32(s->crypto.ciphers_pairwise[i]);
263 	aen->n_akm_suites = cpu_to_le32(s->crypto.n_akm_suites);
264 	for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
265 		aen->akm_suites[i] = cpu_to_le32(s->crypto.akm_suites[i]);
266 	aen->control_port = s->crypto.control_port;
267 	aen->control_port_no_encrypt = s->crypto.control_port_no_encrypt;
268 	aen->control_port_ethertype =
269 		cpu_to_le16(be16_to_cpu(s->crypto.control_port_ethertype));
270 
271 	if (s->ssid && s->ssid_len > 0 && s->ssid_len <= IEEE80211_MAX_SSID_LEN)
272 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, s->ssid,
273 					 s->ssid_len);
274 
275 	if (cfg80211_chandef_valid(&s->chandef)) {
276 		struct qlink_tlv_chandef *chtlv =
277 			(struct qlink_tlv_chandef *)skb_put(cmd_skb,
278 							    sizeof(*chtlv));
279 
280 		chtlv->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANDEF);
281 		chtlv->hdr.len = cpu_to_le16(sizeof(*chtlv) -
282 					     sizeof(chtlv->hdr));
283 		qlink_chandef_cfg2q(&s->chandef, &chtlv->chdef);
284 	}
285 
286 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_HEAD,
287 				s->beacon.head, s->beacon.head_len);
288 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_TAIL,
289 				s->beacon.tail, s->beacon.tail_len);
290 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_IES,
291 				s->beacon.beacon_ies, s->beacon.beacon_ies_len);
292 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_RESP,
293 				s->beacon.probe_resp, s->beacon.probe_resp_len);
294 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_RESP_IES,
295 				s->beacon.proberesp_ies,
296 				s->beacon.proberesp_ies_len);
297 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_ASSOC_RESP,
298 				s->beacon.assocresp_ies,
299 				s->beacon.assocresp_ies_len);
300 
301 	if (s->ht_cap) {
302 		struct qlink_tlv_hdr *tlv = (struct qlink_tlv_hdr *)
303 			skb_put(cmd_skb, sizeof(*tlv) + sizeof(*s->ht_cap));
304 
305 		tlv->type = cpu_to_le16(WLAN_EID_HT_CAPABILITY);
306 		tlv->len = cpu_to_le16(sizeof(*s->ht_cap));
307 		memcpy(tlv->val, s->ht_cap, sizeof(*s->ht_cap));
308 	}
309 
310 	if (s->vht_cap) {
311 		struct qlink_tlv_hdr *tlv = (struct qlink_tlv_hdr *)
312 			skb_put(cmd_skb, sizeof(*tlv) + sizeof(*s->vht_cap));
313 
314 		tlv->type = cpu_to_le16(WLAN_EID_VHT_CAPABILITY);
315 		tlv->len = cpu_to_le16(sizeof(*s->vht_cap));
316 		memcpy(tlv->val, s->vht_cap, sizeof(*s->vht_cap));
317 	}
318 
319 	if (s->acl) {
320 		size_t acl_size = qtnf_cmd_acl_data_size(s->acl);
321 		struct qlink_tlv_hdr *tlv =
322 			skb_put(cmd_skb, sizeof(*tlv) + acl_size);
323 
324 		tlv->type = cpu_to_le16(QTN_TLV_ID_ACL_DATA);
325 		tlv->len = cpu_to_le16(acl_size);
326 		qlink_acl_data_cfg2q(s->acl, (struct qlink_acl_data *)tlv->val);
327 	}
328 
329 	qtnf_bus_lock(vif->mac->bus);
330 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
331 	if (ret)
332 		goto out;
333 
334 	netif_carrier_on(vif->netdev);
335 
336 out:
337 	qtnf_bus_unlock(vif->mac->bus);
338 
339 	return ret;
340 }
341 
342 int qtnf_cmd_send_stop_ap(struct qtnf_vif *vif)
343 {
344 	struct sk_buff *cmd_skb;
345 	int ret;
346 
347 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
348 					    QLINK_CMD_STOP_AP,
349 					    sizeof(struct qlink_cmd));
350 	if (!cmd_skb)
351 		return -ENOMEM;
352 
353 	qtnf_bus_lock(vif->mac->bus);
354 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
355 	if (ret)
356 		goto out;
357 
358 out:
359 	qtnf_bus_unlock(vif->mac->bus);
360 
361 	return ret;
362 }
363 
364 int qtnf_cmd_send_register_mgmt(struct qtnf_vif *vif, u16 frame_type, bool reg)
365 {
366 	struct sk_buff *cmd_skb;
367 	struct qlink_cmd_mgmt_frame_register *cmd;
368 	int ret;
369 
370 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
371 					    QLINK_CMD_REGISTER_MGMT,
372 					    sizeof(*cmd));
373 	if (!cmd_skb)
374 		return -ENOMEM;
375 
376 	qtnf_bus_lock(vif->mac->bus);
377 
378 	cmd = (struct qlink_cmd_mgmt_frame_register *)cmd_skb->data;
379 	cmd->frame_type = cpu_to_le16(frame_type);
380 	cmd->do_register = reg;
381 
382 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
383 	if (ret)
384 		goto out;
385 
386 out:
387 	qtnf_bus_unlock(vif->mac->bus);
388 
389 	return ret;
390 }
391 
392 int qtnf_cmd_send_mgmt_frame(struct qtnf_vif *vif, u32 cookie, u16 flags,
393 			     u16 freq, const u8 *buf, size_t len)
394 {
395 	struct sk_buff *cmd_skb;
396 	struct qlink_cmd_mgmt_frame_tx *cmd;
397 	int ret;
398 
399 	if (sizeof(*cmd) + len > QTNF_MAX_CMD_BUF_SIZE) {
400 		pr_warn("VIF%u.%u: frame is too big: %zu\n", vif->mac->macid,
401 			vif->vifid, len);
402 		return -E2BIG;
403 	}
404 
405 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
406 					    QLINK_CMD_SEND_MGMT_FRAME,
407 					    sizeof(*cmd));
408 	if (!cmd_skb)
409 		return -ENOMEM;
410 
411 	qtnf_bus_lock(vif->mac->bus);
412 
413 	cmd = (struct qlink_cmd_mgmt_frame_tx *)cmd_skb->data;
414 	cmd->cookie = cpu_to_le32(cookie);
415 	cmd->freq = cpu_to_le16(freq);
416 	cmd->flags = cpu_to_le16(flags);
417 
418 	if (len && buf)
419 		qtnf_cmd_skb_put_buffer(cmd_skb, buf, len);
420 
421 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
422 	if (ret)
423 		goto out;
424 
425 out:
426 	qtnf_bus_unlock(vif->mac->bus);
427 
428 	return ret;
429 }
430 
431 int qtnf_cmd_send_mgmt_set_appie(struct qtnf_vif *vif, u8 frame_type,
432 				 const u8 *buf, size_t len)
433 {
434 	struct sk_buff *cmd_skb;
435 	int ret;
436 
437 	if (len > QTNF_MAX_CMD_BUF_SIZE) {
438 		pr_warn("VIF%u.%u: %u frame is too big: %zu\n", vif->mac->macid,
439 			vif->vifid, frame_type, len);
440 		return -E2BIG;
441 	}
442 
443 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
444 					    QLINK_CMD_MGMT_SET_APPIE,
445 					    sizeof(struct qlink_cmd));
446 	if (!cmd_skb)
447 		return -ENOMEM;
448 
449 	qtnf_cmd_tlv_ie_set_add(cmd_skb, frame_type, buf, len);
450 
451 	qtnf_bus_lock(vif->mac->bus);
452 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
453 	if (ret)
454 		goto out;
455 
456 out:
457 	qtnf_bus_unlock(vif->mac->bus);
458 
459 	return ret;
460 }
461 
462 static void
463 qtnf_sta_info_parse_rate(struct rate_info *rate_dst,
464 			 const struct qlink_sta_info_rate *rate_src)
465 {
466 	rate_dst->legacy = get_unaligned_le16(&rate_src->rate) * 10;
467 
468 	rate_dst->mcs = rate_src->mcs;
469 	rate_dst->nss = rate_src->nss;
470 	rate_dst->flags = 0;
471 
472 	switch (rate_src->bw) {
473 	case QLINK_CHAN_WIDTH_5:
474 		rate_dst->bw = RATE_INFO_BW_5;
475 		break;
476 	case QLINK_CHAN_WIDTH_10:
477 		rate_dst->bw = RATE_INFO_BW_10;
478 		break;
479 	case QLINK_CHAN_WIDTH_20:
480 	case QLINK_CHAN_WIDTH_20_NOHT:
481 		rate_dst->bw = RATE_INFO_BW_20;
482 		break;
483 	case QLINK_CHAN_WIDTH_40:
484 		rate_dst->bw = RATE_INFO_BW_40;
485 		break;
486 	case QLINK_CHAN_WIDTH_80:
487 		rate_dst->bw = RATE_INFO_BW_80;
488 		break;
489 	case QLINK_CHAN_WIDTH_160:
490 		rate_dst->bw = RATE_INFO_BW_160;
491 		break;
492 	default:
493 		rate_dst->bw = 0;
494 		break;
495 	}
496 
497 	if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_HT_MCS)
498 		rate_dst->flags |= RATE_INFO_FLAGS_MCS;
499 	else if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_VHT_MCS)
500 		rate_dst->flags |= RATE_INFO_FLAGS_VHT_MCS;
501 
502 	if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_SHORT_GI)
503 		rate_dst->flags |= RATE_INFO_FLAGS_SHORT_GI;
504 }
505 
506 static void
507 qtnf_sta_info_parse_flags(struct nl80211_sta_flag_update *dst,
508 			  const struct qlink_sta_info_state *src)
509 {
510 	u32 mask, value;
511 
512 	dst->mask = 0;
513 	dst->set = 0;
514 
515 	mask = le32_to_cpu(src->mask);
516 	value = le32_to_cpu(src->value);
517 
518 	if (mask & QLINK_STA_FLAG_AUTHORIZED) {
519 		dst->mask |= BIT(NL80211_STA_FLAG_AUTHORIZED);
520 		if (value & QLINK_STA_FLAG_AUTHORIZED)
521 			dst->set |= BIT(NL80211_STA_FLAG_AUTHORIZED);
522 	}
523 
524 	if (mask & QLINK_STA_FLAG_SHORT_PREAMBLE) {
525 		dst->mask |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
526 		if (value & QLINK_STA_FLAG_SHORT_PREAMBLE)
527 			dst->set |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
528 	}
529 
530 	if (mask & QLINK_STA_FLAG_WME) {
531 		dst->mask |= BIT(NL80211_STA_FLAG_WME);
532 		if (value & QLINK_STA_FLAG_WME)
533 			dst->set |= BIT(NL80211_STA_FLAG_WME);
534 	}
535 
536 	if (mask & QLINK_STA_FLAG_MFP) {
537 		dst->mask |= BIT(NL80211_STA_FLAG_MFP);
538 		if (value & QLINK_STA_FLAG_MFP)
539 			dst->set |= BIT(NL80211_STA_FLAG_MFP);
540 	}
541 
542 	if (mask & QLINK_STA_FLAG_AUTHENTICATED) {
543 		dst->mask |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
544 		if (value & QLINK_STA_FLAG_AUTHENTICATED)
545 			dst->set |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
546 	}
547 
548 	if (mask & QLINK_STA_FLAG_TDLS_PEER) {
549 		dst->mask |= BIT(NL80211_STA_FLAG_TDLS_PEER);
550 		if (value & QLINK_STA_FLAG_TDLS_PEER)
551 			dst->set |= BIT(NL80211_STA_FLAG_TDLS_PEER);
552 	}
553 
554 	if (mask & QLINK_STA_FLAG_ASSOCIATED) {
555 		dst->mask |= BIT(NL80211_STA_FLAG_ASSOCIATED);
556 		if (value & QLINK_STA_FLAG_ASSOCIATED)
557 			dst->set |= BIT(NL80211_STA_FLAG_ASSOCIATED);
558 	}
559 }
560 
561 static void
562 qtnf_cmd_sta_info_parse(struct station_info *sinfo,
563 			const struct qlink_tlv_hdr *tlv,
564 			size_t resp_size)
565 {
566 	const struct qlink_sta_stats *stats = NULL;
567 	const u8 *map = NULL;
568 	unsigned int map_len = 0;
569 	unsigned int stats_len = 0;
570 	u16 tlv_len;
571 
572 #define qtnf_sta_stat_avail(stat_name, bitn)	\
573 	(qtnf_utils_is_bit_set(map, bitn, map_len) && \
574 	 (offsetofend(struct qlink_sta_stats, stat_name) <= stats_len))
575 
576 	while (resp_size >= sizeof(*tlv)) {
577 		tlv_len = le16_to_cpu(tlv->len);
578 
579 		switch (le16_to_cpu(tlv->type)) {
580 		case QTN_TLV_ID_STA_STATS_MAP:
581 			map_len = tlv_len;
582 			map = tlv->val;
583 			break;
584 		case QTN_TLV_ID_STA_STATS:
585 			stats_len = tlv_len;
586 			stats = (const struct qlink_sta_stats *)tlv->val;
587 			break;
588 		default:
589 			break;
590 		}
591 
592 		resp_size -= tlv_len + sizeof(*tlv);
593 		tlv = (const struct qlink_tlv_hdr *)(tlv->val + tlv_len);
594 	}
595 
596 	if (!map || !stats)
597 		return;
598 
599 	if (qtnf_sta_stat_avail(inactive_time, QLINK_STA_INFO_INACTIVE_TIME)) {
600 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_INACTIVE_TIME);
601 		sinfo->inactive_time = le32_to_cpu(stats->inactive_time);
602 	}
603 
604 	if (qtnf_sta_stat_avail(connected_time,
605 				QLINK_STA_INFO_CONNECTED_TIME)) {
606 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_CONNECTED_TIME);
607 		sinfo->connected_time = le32_to_cpu(stats->connected_time);
608 	}
609 
610 	if (qtnf_sta_stat_avail(signal, QLINK_STA_INFO_SIGNAL)) {
611 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL);
612 		sinfo->signal = stats->signal - QLINK_RSSI_OFFSET;
613 	}
614 
615 	if (qtnf_sta_stat_avail(signal_avg, QLINK_STA_INFO_SIGNAL_AVG)) {
616 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL_AVG);
617 		sinfo->signal_avg = stats->signal_avg - QLINK_RSSI_OFFSET;
618 	}
619 
620 	if (qtnf_sta_stat_avail(rxrate, QLINK_STA_INFO_RX_BITRATE)) {
621 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BITRATE);
622 		qtnf_sta_info_parse_rate(&sinfo->rxrate, &stats->rxrate);
623 	}
624 
625 	if (qtnf_sta_stat_avail(txrate, QLINK_STA_INFO_TX_BITRATE)) {
626 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BITRATE);
627 		qtnf_sta_info_parse_rate(&sinfo->txrate, &stats->txrate);
628 	}
629 
630 	if (qtnf_sta_stat_avail(sta_flags, QLINK_STA_INFO_STA_FLAGS)) {
631 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_STA_FLAGS);
632 		qtnf_sta_info_parse_flags(&sinfo->sta_flags, &stats->sta_flags);
633 	}
634 
635 	if (qtnf_sta_stat_avail(rx_bytes, QLINK_STA_INFO_RX_BYTES)) {
636 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BYTES);
637 		sinfo->rx_bytes = le64_to_cpu(stats->rx_bytes);
638 	}
639 
640 	if (qtnf_sta_stat_avail(tx_bytes, QLINK_STA_INFO_TX_BYTES)) {
641 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BYTES);
642 		sinfo->tx_bytes = le64_to_cpu(stats->tx_bytes);
643 	}
644 
645 	if (qtnf_sta_stat_avail(rx_bytes, QLINK_STA_INFO_RX_BYTES64)) {
646 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BYTES64);
647 		sinfo->rx_bytes = le64_to_cpu(stats->rx_bytes);
648 	}
649 
650 	if (qtnf_sta_stat_avail(tx_bytes, QLINK_STA_INFO_TX_BYTES64)) {
651 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BYTES64);
652 		sinfo->tx_bytes = le64_to_cpu(stats->tx_bytes);
653 	}
654 
655 	if (qtnf_sta_stat_avail(rx_packets, QLINK_STA_INFO_RX_PACKETS)) {
656 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_PACKETS);
657 		sinfo->rx_packets = le32_to_cpu(stats->rx_packets);
658 	}
659 
660 	if (qtnf_sta_stat_avail(tx_packets, QLINK_STA_INFO_TX_PACKETS)) {
661 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_PACKETS);
662 		sinfo->tx_packets = le32_to_cpu(stats->tx_packets);
663 	}
664 
665 	if (qtnf_sta_stat_avail(rx_beacon, QLINK_STA_INFO_BEACON_RX)) {
666 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_BEACON_RX);
667 		sinfo->rx_beacon = le64_to_cpu(stats->rx_beacon);
668 	}
669 
670 	if (qtnf_sta_stat_avail(rx_dropped_misc, QLINK_STA_INFO_RX_DROP_MISC)) {
671 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_DROP_MISC);
672 		sinfo->rx_dropped_misc = le32_to_cpu(stats->rx_dropped_misc);
673 	}
674 
675 	if (qtnf_sta_stat_avail(tx_failed, QLINK_STA_INFO_TX_FAILED)) {
676 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_FAILED);
677 		sinfo->tx_failed = le32_to_cpu(stats->tx_failed);
678 	}
679 
680 #undef qtnf_sta_stat_avail
681 }
682 
683 int qtnf_cmd_get_sta_info(struct qtnf_vif *vif, const u8 *sta_mac,
684 			  struct station_info *sinfo)
685 {
686 	struct sk_buff *cmd_skb, *resp_skb = NULL;
687 	struct qlink_cmd_get_sta_info *cmd;
688 	const struct qlink_resp_get_sta_info *resp;
689 	size_t var_resp_len;
690 	int ret = 0;
691 
692 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
693 					    QLINK_CMD_GET_STA_INFO,
694 					    sizeof(*cmd));
695 	if (!cmd_skb)
696 		return -ENOMEM;
697 
698 	qtnf_bus_lock(vif->mac->bus);
699 
700 	cmd = (struct qlink_cmd_get_sta_info *)cmd_skb->data;
701 	ether_addr_copy(cmd->sta_addr, sta_mac);
702 
703 	ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
704 				       sizeof(*resp), &var_resp_len);
705 	if (ret)
706 		goto out;
707 
708 	resp = (const struct qlink_resp_get_sta_info *)resp_skb->data;
709 
710 	if (!ether_addr_equal(sta_mac, resp->sta_addr)) {
711 		pr_err("VIF%u.%u: wrong mac in reply: %pM != %pM\n",
712 		       vif->mac->macid, vif->vifid, resp->sta_addr, sta_mac);
713 		ret = -EINVAL;
714 		goto out;
715 	}
716 
717 	qtnf_cmd_sta_info_parse(sinfo,
718 				(const struct qlink_tlv_hdr *)resp->info,
719 				var_resp_len);
720 
721 out:
722 	qtnf_bus_unlock(vif->mac->bus);
723 	consume_skb(resp_skb);
724 
725 	return ret;
726 }
727 
728 static int qtnf_cmd_send_add_change_intf(struct qtnf_vif *vif,
729 					 enum nl80211_iftype iftype,
730 					 u8 *mac_addr,
731 					 enum qlink_cmd_type cmd_type)
732 {
733 	struct sk_buff *cmd_skb, *resp_skb = NULL;
734 	struct qlink_cmd_manage_intf *cmd;
735 	const struct qlink_resp_manage_intf *resp;
736 	int ret = 0;
737 
738 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
739 					    cmd_type,
740 					    sizeof(*cmd));
741 	if (!cmd_skb)
742 		return -ENOMEM;
743 
744 	qtnf_bus_lock(vif->mac->bus);
745 
746 	cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
747 
748 	switch (iftype) {
749 	case NL80211_IFTYPE_AP:
750 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
751 		break;
752 	case NL80211_IFTYPE_STATION:
753 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
754 		break;
755 	default:
756 		pr_err("VIF%u.%u: unsupported type %d\n", vif->mac->macid,
757 		       vif->vifid, iftype);
758 		ret = -EINVAL;
759 		goto out;
760 	}
761 
762 	if (mac_addr)
763 		ether_addr_copy(cmd->intf_info.mac_addr, mac_addr);
764 	else
765 		eth_zero_addr(cmd->intf_info.mac_addr);
766 
767 	ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
768 				       sizeof(*resp), NULL);
769 	if (ret)
770 		goto out;
771 
772 	resp = (const struct qlink_resp_manage_intf *)resp_skb->data;
773 	ether_addr_copy(vif->mac_addr, resp->intf_info.mac_addr);
774 
775 out:
776 	qtnf_bus_unlock(vif->mac->bus);
777 	consume_skb(resp_skb);
778 
779 	return ret;
780 }
781 
782 int qtnf_cmd_send_add_intf(struct qtnf_vif *vif,
783 			   enum nl80211_iftype iftype, u8 *mac_addr)
784 {
785 	return qtnf_cmd_send_add_change_intf(vif, iftype, mac_addr,
786 			QLINK_CMD_ADD_INTF);
787 }
788 
789 int qtnf_cmd_send_change_intf_type(struct qtnf_vif *vif,
790 				   enum nl80211_iftype iftype, u8 *mac_addr)
791 {
792 	return qtnf_cmd_send_add_change_intf(vif, iftype, mac_addr,
793 					     QLINK_CMD_CHANGE_INTF);
794 }
795 
796 int qtnf_cmd_send_del_intf(struct qtnf_vif *vif)
797 {
798 	struct sk_buff *cmd_skb;
799 	struct qlink_cmd_manage_intf *cmd;
800 	int ret = 0;
801 
802 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
803 					    QLINK_CMD_DEL_INTF,
804 					    sizeof(*cmd));
805 	if (!cmd_skb)
806 		return -ENOMEM;
807 
808 	qtnf_bus_lock(vif->mac->bus);
809 
810 	cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
811 
812 	switch (vif->wdev.iftype) {
813 	case NL80211_IFTYPE_AP:
814 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
815 		break;
816 	case NL80211_IFTYPE_STATION:
817 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
818 		break;
819 	default:
820 		pr_warn("VIF%u.%u: unsupported iftype %d\n", vif->mac->macid,
821 			vif->vifid, vif->wdev.iftype);
822 		ret = -EINVAL;
823 		goto out;
824 	}
825 
826 	eth_zero_addr(cmd->intf_info.mac_addr);
827 
828 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
829 	if (ret)
830 		goto out;
831 
832 out:
833 	qtnf_bus_unlock(vif->mac->bus);
834 	return ret;
835 }
836 
837 static u32 qtnf_cmd_resp_reg_rule_flags_parse(u32 qflags)
838 {
839 	u32 flags = 0;
840 
841 	if (qflags & QLINK_RRF_NO_OFDM)
842 		flags |= NL80211_RRF_NO_OFDM;
843 
844 	if (qflags & QLINK_RRF_NO_CCK)
845 		flags |= NL80211_RRF_NO_CCK;
846 
847 	if (qflags & QLINK_RRF_NO_INDOOR)
848 		flags |= NL80211_RRF_NO_INDOOR;
849 
850 	if (qflags & QLINK_RRF_NO_OUTDOOR)
851 		flags |= NL80211_RRF_NO_OUTDOOR;
852 
853 	if (qflags & QLINK_RRF_DFS)
854 		flags |= NL80211_RRF_DFS;
855 
856 	if (qflags & QLINK_RRF_PTP_ONLY)
857 		flags |= NL80211_RRF_PTP_ONLY;
858 
859 	if (qflags & QLINK_RRF_PTMP_ONLY)
860 		flags |= NL80211_RRF_PTMP_ONLY;
861 
862 	if (qflags & QLINK_RRF_NO_IR)
863 		flags |= NL80211_RRF_NO_IR;
864 
865 	if (qflags & QLINK_RRF_AUTO_BW)
866 		flags |= NL80211_RRF_AUTO_BW;
867 
868 	if (qflags & QLINK_RRF_IR_CONCURRENT)
869 		flags |= NL80211_RRF_IR_CONCURRENT;
870 
871 	if (qflags & QLINK_RRF_NO_HT40MINUS)
872 		flags |= NL80211_RRF_NO_HT40MINUS;
873 
874 	if (qflags & QLINK_RRF_NO_HT40PLUS)
875 		flags |= NL80211_RRF_NO_HT40PLUS;
876 
877 	if (qflags & QLINK_RRF_NO_80MHZ)
878 		flags |= NL80211_RRF_NO_80MHZ;
879 
880 	if (qflags & QLINK_RRF_NO_160MHZ)
881 		flags |= NL80211_RRF_NO_160MHZ;
882 
883 	return flags;
884 }
885 
886 static int
887 qtnf_cmd_resp_proc_hw_info(struct qtnf_bus *bus,
888 			   const struct qlink_resp_get_hw_info *resp,
889 			   size_t info_len)
890 {
891 	struct qtnf_hw_info *hwinfo = &bus->hw_info;
892 	const struct qlink_tlv_hdr *tlv;
893 	const struct qlink_tlv_reg_rule *tlv_rule;
894 	const char *bld_name = NULL;
895 	const char *bld_rev = NULL;
896 	const char *bld_type = NULL;
897 	const char *bld_label = NULL;
898 	u32 bld_tmstamp = 0;
899 	u32 plat_id = 0;
900 	const char *hw_id = NULL;
901 	const char *calibration_ver = NULL;
902 	const char *uboot_ver = NULL;
903 	u32 hw_ver = 0;
904 	struct ieee80211_reg_rule *rule;
905 	u16 tlv_type;
906 	u16 tlv_value_len;
907 	unsigned int rule_idx = 0;
908 
909 	if (WARN_ON(resp->n_reg_rules > NL80211_MAX_SUPP_REG_RULES))
910 		return -E2BIG;
911 
912 	hwinfo->rd = kzalloc(sizeof(*hwinfo->rd)
913 			     + sizeof(struct ieee80211_reg_rule)
914 			     * resp->n_reg_rules, GFP_KERNEL);
915 
916 	if (!hwinfo->rd)
917 		return -ENOMEM;
918 
919 	hwinfo->num_mac = resp->num_mac;
920 	hwinfo->mac_bitmap = resp->mac_bitmap;
921 	hwinfo->fw_ver = le32_to_cpu(resp->fw_ver);
922 	hwinfo->ql_proto_ver = le16_to_cpu(resp->ql_proto_ver);
923 	hwinfo->total_tx_chain = resp->total_tx_chain;
924 	hwinfo->total_rx_chain = resp->total_rx_chain;
925 	hwinfo->hw_capab = le32_to_cpu(resp->hw_capab);
926 	hwinfo->rd->n_reg_rules = resp->n_reg_rules;
927 	hwinfo->rd->alpha2[0] = resp->alpha2[0];
928 	hwinfo->rd->alpha2[1] = resp->alpha2[1];
929 
930 	bld_tmstamp = le32_to_cpu(resp->bld_tmstamp);
931 	plat_id = le32_to_cpu(resp->plat_id);
932 	hw_ver = le32_to_cpu(resp->hw_ver);
933 
934 	switch (resp->dfs_region) {
935 	case QLINK_DFS_FCC:
936 		hwinfo->rd->dfs_region = NL80211_DFS_FCC;
937 		break;
938 	case QLINK_DFS_ETSI:
939 		hwinfo->rd->dfs_region = NL80211_DFS_ETSI;
940 		break;
941 	case QLINK_DFS_JP:
942 		hwinfo->rd->dfs_region = NL80211_DFS_JP;
943 		break;
944 	case QLINK_DFS_UNSET:
945 	default:
946 		hwinfo->rd->dfs_region = NL80211_DFS_UNSET;
947 		break;
948 	}
949 
950 	tlv = (const struct qlink_tlv_hdr *)resp->info;
951 
952 	while (info_len >= sizeof(*tlv)) {
953 		tlv_type = le16_to_cpu(tlv->type);
954 		tlv_value_len = le16_to_cpu(tlv->len);
955 
956 		if (tlv_value_len + sizeof(*tlv) > info_len) {
957 			pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
958 				tlv_type, tlv_value_len);
959 			return -EINVAL;
960 		}
961 
962 		switch (tlv_type) {
963 		case QTN_TLV_ID_REG_RULE:
964 			if (rule_idx >= resp->n_reg_rules) {
965 				pr_warn("unexpected number of rules: %u\n",
966 					resp->n_reg_rules);
967 				return -EINVAL;
968 			}
969 
970 			if (tlv_value_len != sizeof(*tlv_rule) - sizeof(*tlv)) {
971 				pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
972 					tlv_type, tlv_value_len);
973 				return -EINVAL;
974 			}
975 
976 			tlv_rule = (const struct qlink_tlv_reg_rule *)tlv;
977 			rule = &hwinfo->rd->reg_rules[rule_idx++];
978 
979 			rule->freq_range.start_freq_khz =
980 				le32_to_cpu(tlv_rule->start_freq_khz);
981 			rule->freq_range.end_freq_khz =
982 				le32_to_cpu(tlv_rule->end_freq_khz);
983 			rule->freq_range.max_bandwidth_khz =
984 				le32_to_cpu(tlv_rule->max_bandwidth_khz);
985 			rule->power_rule.max_antenna_gain =
986 				le32_to_cpu(tlv_rule->max_antenna_gain);
987 			rule->power_rule.max_eirp =
988 				le32_to_cpu(tlv_rule->max_eirp);
989 			rule->dfs_cac_ms =
990 				le32_to_cpu(tlv_rule->dfs_cac_ms);
991 			rule->flags = qtnf_cmd_resp_reg_rule_flags_parse(
992 					le32_to_cpu(tlv_rule->flags));
993 			break;
994 		case QTN_TLV_ID_BUILD_NAME:
995 			bld_name = (const void *)tlv->val;
996 			break;
997 		case QTN_TLV_ID_BUILD_REV:
998 			bld_rev = (const void *)tlv->val;
999 			break;
1000 		case QTN_TLV_ID_BUILD_TYPE:
1001 			bld_type = (const void *)tlv->val;
1002 			break;
1003 		case QTN_TLV_ID_BUILD_LABEL:
1004 			bld_label = (const void *)tlv->val;
1005 			break;
1006 		case QTN_TLV_ID_HW_ID:
1007 			hw_id = (const void *)tlv->val;
1008 			break;
1009 		case QTN_TLV_ID_CALIBRATION_VER:
1010 			calibration_ver = (const void *)tlv->val;
1011 			break;
1012 		case QTN_TLV_ID_UBOOT_VER:
1013 			uboot_ver = (const void *)tlv->val;
1014 			break;
1015 		case QTN_TLV_ID_MAX_SCAN_SSIDS:
1016 			hwinfo->max_scan_ssids = *tlv->val;
1017 			break;
1018 		default:
1019 			break;
1020 		}
1021 
1022 		info_len -= tlv_value_len + sizeof(*tlv);
1023 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1024 	}
1025 
1026 	if (rule_idx != resp->n_reg_rules) {
1027 		pr_warn("unexpected number of rules: expected %u got %u\n",
1028 			resp->n_reg_rules, rule_idx);
1029 		kfree(hwinfo->rd);
1030 		hwinfo->rd = NULL;
1031 		return -EINVAL;
1032 	}
1033 
1034 	pr_info("fw_version=%d, MACs map %#x, alpha2=\"%c%c\", chains Tx=%u Rx=%u, capab=0x%x\n",
1035 		hwinfo->fw_ver, hwinfo->mac_bitmap,
1036 		hwinfo->rd->alpha2[0], hwinfo->rd->alpha2[1],
1037 		hwinfo->total_tx_chain, hwinfo->total_rx_chain,
1038 		hwinfo->hw_capab);
1039 
1040 	pr_info("\nBuild name:            %s"  \
1041 		"\nBuild revision:        %s"  \
1042 		"\nBuild type:            %s"  \
1043 		"\nBuild label:           %s"  \
1044 		"\nBuild timestamp:       %lu" \
1045 		"\nPlatform ID:           %lu" \
1046 		"\nHardware ID:           %s"  \
1047 		"\nCalibration version:   %s"  \
1048 		"\nU-Boot version:        %s"  \
1049 		"\nHardware version:      0x%08x",
1050 		bld_name, bld_rev, bld_type, bld_label,
1051 		(unsigned long)bld_tmstamp,
1052 		(unsigned long)plat_id,
1053 		hw_id, calibration_ver, uboot_ver, hw_ver);
1054 
1055 	strlcpy(hwinfo->fw_version, bld_label, sizeof(hwinfo->fw_version));
1056 	hwinfo->hw_version = hw_ver;
1057 
1058 	return 0;
1059 }
1060 
1061 static void
1062 qtnf_parse_wowlan_info(struct qtnf_wmac *mac,
1063 		       const struct qlink_wowlan_capab_data *wowlan)
1064 {
1065 	struct qtnf_mac_info *mac_info = &mac->macinfo;
1066 	const struct qlink_wowlan_support *data1;
1067 	struct wiphy_wowlan_support *supp;
1068 
1069 	supp = kzalloc(sizeof(*supp), GFP_KERNEL);
1070 	if (!supp)
1071 		return;
1072 
1073 	switch (le16_to_cpu(wowlan->version)) {
1074 	case 0x1:
1075 		data1 = (struct qlink_wowlan_support *)wowlan->data;
1076 
1077 		supp->flags = WIPHY_WOWLAN_MAGIC_PKT | WIPHY_WOWLAN_DISCONNECT;
1078 		supp->n_patterns = le32_to_cpu(data1->n_patterns);
1079 		supp->pattern_max_len = le32_to_cpu(data1->pattern_max_len);
1080 		supp->pattern_min_len = le32_to_cpu(data1->pattern_min_len);
1081 
1082 		mac_info->wowlan = supp;
1083 		break;
1084 	default:
1085 		pr_warn("MAC%u: unsupported WoWLAN version 0x%x\n",
1086 			mac->macid, le16_to_cpu(wowlan->version));
1087 		kfree(supp);
1088 		break;
1089 	}
1090 }
1091 
1092 static int qtnf_parse_variable_mac_info(struct qtnf_wmac *mac,
1093 					const u8 *tlv_buf, size_t tlv_buf_size)
1094 {
1095 	struct ieee80211_iface_combination *comb = NULL;
1096 	size_t n_comb = 0;
1097 	struct ieee80211_iface_limit *limits;
1098 	const struct qlink_iface_comb_num *comb_num;
1099 	const struct qlink_iface_limit_record *rec;
1100 	const struct qlink_iface_limit *lim;
1101 	const struct qlink_wowlan_capab_data *wowlan;
1102 	u16 rec_len;
1103 	u16 tlv_type;
1104 	u16 tlv_value_len;
1105 	size_t tlv_full_len;
1106 	const struct qlink_tlv_hdr *tlv;
1107 	u8 *ext_capa = NULL;
1108 	u8 *ext_capa_mask = NULL;
1109 	u8 ext_capa_len = 0;
1110 	u8 ext_capa_mask_len = 0;
1111 	int i = 0;
1112 
1113 	tlv = (const struct qlink_tlv_hdr *)tlv_buf;
1114 	while (tlv_buf_size >= sizeof(struct qlink_tlv_hdr)) {
1115 		tlv_type = le16_to_cpu(tlv->type);
1116 		tlv_value_len = le16_to_cpu(tlv->len);
1117 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1118 		if (tlv_full_len > tlv_buf_size) {
1119 			pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1120 				mac->macid, tlv_type, tlv_value_len);
1121 			return -EINVAL;
1122 		}
1123 
1124 		switch (tlv_type) {
1125 		case QTN_TLV_ID_NUM_IFACE_COMB:
1126 			if (tlv_value_len != sizeof(*comb_num))
1127 				return -EINVAL;
1128 
1129 			comb_num = (void *)tlv->val;
1130 
1131 			/* free earlier iface comb memory */
1132 			qtnf_mac_iface_comb_free(mac);
1133 
1134 			mac->macinfo.n_if_comb =
1135 				le32_to_cpu(comb_num->iface_comb_num);
1136 
1137 			mac->macinfo.if_comb =
1138 				kcalloc(mac->macinfo.n_if_comb,
1139 					sizeof(*mac->macinfo.if_comb),
1140 					GFP_KERNEL);
1141 
1142 			if (!mac->macinfo.if_comb)
1143 				return -ENOMEM;
1144 
1145 			comb = mac->macinfo.if_comb;
1146 
1147 			pr_debug("MAC%u: %zu iface combinations\n",
1148 				 mac->macid, mac->macinfo.n_if_comb);
1149 
1150 			break;
1151 		case QTN_TLV_ID_IFACE_LIMIT:
1152 			if (unlikely(!comb)) {
1153 				pr_warn("MAC%u: no combinations advertised\n",
1154 					mac->macid);
1155 				return -EINVAL;
1156 			}
1157 
1158 			if (n_comb >= mac->macinfo.n_if_comb) {
1159 				pr_warn("MAC%u: combinations count exceeded\n",
1160 					mac->macid);
1161 				n_comb++;
1162 				break;
1163 			}
1164 
1165 			rec = (void *)tlv->val;
1166 			rec_len = sizeof(*rec) + rec->n_limits * sizeof(*lim);
1167 
1168 			if (unlikely(tlv_value_len != rec_len)) {
1169 				pr_warn("MAC%u: record %zu size mismatch\n",
1170 					mac->macid, n_comb);
1171 				return -EINVAL;
1172 			}
1173 
1174 			limits = kcalloc(rec->n_limits, sizeof(*limits),
1175 					 GFP_KERNEL);
1176 			if (!limits)
1177 				return -ENOMEM;
1178 
1179 			comb[n_comb].num_different_channels =
1180 				rec->num_different_channels;
1181 			comb[n_comb].max_interfaces =
1182 				le16_to_cpu(rec->max_interfaces);
1183 			comb[n_comb].n_limits = rec->n_limits;
1184 			comb[n_comb].limits = limits;
1185 
1186 			for (i = 0; i < rec->n_limits; i++) {
1187 				lim = &rec->limits[i];
1188 				limits[i].max = le16_to_cpu(lim->max_num);
1189 				limits[i].types =
1190 					qlink_iface_type_to_nl_mask(le16_to_cpu(lim->type));
1191 				pr_debug("MAC%u: comb[%zu]: MAX:%u TYPES:%.4X\n",
1192 					 mac->macid, n_comb,
1193 					 limits[i].max, limits[i].types);
1194 			}
1195 
1196 			n_comb++;
1197 			break;
1198 		case WLAN_EID_EXT_CAPABILITY:
1199 			if (unlikely(tlv_value_len > U8_MAX))
1200 				return -EINVAL;
1201 			ext_capa = (u8 *)tlv->val;
1202 			ext_capa_len = tlv_value_len;
1203 			break;
1204 		case QTN_TLV_ID_EXT_CAPABILITY_MASK:
1205 			if (unlikely(tlv_value_len > U8_MAX))
1206 				return -EINVAL;
1207 			ext_capa_mask = (u8 *)tlv->val;
1208 			ext_capa_mask_len = tlv_value_len;
1209 			break;
1210 		case QTN_TLV_ID_WOWLAN_CAPAB:
1211 			if (tlv_value_len < sizeof(*wowlan))
1212 				return -EINVAL;
1213 
1214 			wowlan = (void *)tlv->val;
1215 			if (!le16_to_cpu(wowlan->len)) {
1216 				pr_warn("MAC%u: skip empty WoWLAN data\n",
1217 					mac->macid);
1218 				break;
1219 			}
1220 
1221 			rec_len = sizeof(*wowlan) + le16_to_cpu(wowlan->len);
1222 			if (unlikely(tlv_value_len != rec_len)) {
1223 				pr_warn("MAC%u: WoWLAN data size mismatch\n",
1224 					mac->macid);
1225 				return -EINVAL;
1226 			}
1227 
1228 			kfree(mac->macinfo.wowlan);
1229 			mac->macinfo.wowlan = NULL;
1230 			qtnf_parse_wowlan_info(mac, wowlan);
1231 			break;
1232 		default:
1233 			pr_warn("MAC%u: unknown TLV type %u\n",
1234 				mac->macid, tlv_type);
1235 			break;
1236 		}
1237 
1238 		tlv_buf_size -= tlv_full_len;
1239 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1240 	}
1241 
1242 	if (tlv_buf_size) {
1243 		pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1244 			mac->macid, tlv_buf_size);
1245 		return -EINVAL;
1246 	}
1247 
1248 	if (mac->macinfo.n_if_comb != n_comb) {
1249 		pr_err("MAC%u: combination mismatch: reported=%zu parsed=%zu\n",
1250 		       mac->macid, mac->macinfo.n_if_comb, n_comb);
1251 		return -EINVAL;
1252 	}
1253 
1254 	if (ext_capa_len != ext_capa_mask_len) {
1255 		pr_err("MAC%u: ext_capa/_mask lengths mismatch: %u != %u\n",
1256 		       mac->macid, ext_capa_len, ext_capa_mask_len);
1257 		return -EINVAL;
1258 	}
1259 
1260 	if (ext_capa_len > 0) {
1261 		ext_capa = kmemdup(ext_capa, ext_capa_len, GFP_KERNEL);
1262 		if (!ext_capa)
1263 			return -ENOMEM;
1264 
1265 		ext_capa_mask =
1266 			kmemdup(ext_capa_mask, ext_capa_mask_len, GFP_KERNEL);
1267 		if (!ext_capa_mask) {
1268 			kfree(ext_capa);
1269 			return -ENOMEM;
1270 		}
1271 	} else {
1272 		ext_capa = NULL;
1273 		ext_capa_mask = NULL;
1274 	}
1275 
1276 	qtnf_mac_ext_caps_free(mac);
1277 	mac->macinfo.extended_capabilities = ext_capa;
1278 	mac->macinfo.extended_capabilities_mask = ext_capa_mask;
1279 	mac->macinfo.extended_capabilities_len = ext_capa_len;
1280 
1281 	return 0;
1282 }
1283 
1284 static void
1285 qtnf_cmd_resp_proc_mac_info(struct qtnf_wmac *mac,
1286 			    const struct qlink_resp_get_mac_info *resp_info)
1287 {
1288 	struct qtnf_mac_info *mac_info;
1289 	struct qtnf_vif *vif;
1290 
1291 	mac_info = &mac->macinfo;
1292 
1293 	mac_info->bands_cap = resp_info->bands_cap;
1294 	memcpy(&mac_info->dev_mac, &resp_info->dev_mac,
1295 	       sizeof(mac_info->dev_mac));
1296 
1297 	ether_addr_copy(mac->macaddr, mac_info->dev_mac);
1298 
1299 	vif = qtnf_mac_get_base_vif(mac);
1300 	if (vif)
1301 		ether_addr_copy(vif->mac_addr, mac->macaddr);
1302 	else
1303 		pr_err("could not get valid base vif\n");
1304 
1305 	mac_info->num_tx_chain = resp_info->num_tx_chain;
1306 	mac_info->num_rx_chain = resp_info->num_rx_chain;
1307 
1308 	mac_info->max_ap_assoc_sta = le16_to_cpu(resp_info->max_ap_assoc_sta);
1309 	mac_info->radar_detect_widths =
1310 			qlink_chan_width_mask_to_nl(le16_to_cpu(
1311 					resp_info->radar_detect_widths));
1312 	mac_info->max_acl_mac_addrs = le32_to_cpu(resp_info->max_acl_mac_addrs);
1313 
1314 	memcpy(&mac_info->ht_cap_mod_mask, &resp_info->ht_cap_mod_mask,
1315 	       sizeof(mac_info->ht_cap_mod_mask));
1316 	memcpy(&mac_info->vht_cap_mod_mask, &resp_info->vht_cap_mod_mask,
1317 	       sizeof(mac_info->vht_cap_mod_mask));
1318 }
1319 
1320 static void qtnf_cmd_resp_band_fill_htcap(const u8 *info,
1321 					  struct ieee80211_sta_ht_cap *bcap)
1322 {
1323 	const struct ieee80211_ht_cap *ht_cap =
1324 		(const struct ieee80211_ht_cap *)info;
1325 
1326 	bcap->ht_supported = true;
1327 	bcap->cap = le16_to_cpu(ht_cap->cap_info);
1328 	bcap->ampdu_factor =
1329 		ht_cap->ampdu_params_info & IEEE80211_HT_AMPDU_PARM_FACTOR;
1330 	bcap->ampdu_density =
1331 		(ht_cap->ampdu_params_info & IEEE80211_HT_AMPDU_PARM_DENSITY) >>
1332 		IEEE80211_HT_AMPDU_PARM_DENSITY_SHIFT;
1333 	memcpy(&bcap->mcs, &ht_cap->mcs, sizeof(bcap->mcs));
1334 }
1335 
1336 static void qtnf_cmd_resp_band_fill_vhtcap(const u8 *info,
1337 					   struct ieee80211_sta_vht_cap *bcap)
1338 {
1339 	const struct ieee80211_vht_cap *vht_cap =
1340 		(const struct ieee80211_vht_cap *)info;
1341 
1342 	bcap->vht_supported = true;
1343 	bcap->cap = le32_to_cpu(vht_cap->vht_cap_info);
1344 	memcpy(&bcap->vht_mcs, &vht_cap->supp_mcs, sizeof(bcap->vht_mcs));
1345 }
1346 
1347 static int
1348 qtnf_cmd_resp_fill_band_info(struct ieee80211_supported_band *band,
1349 			     struct qlink_resp_band_info_get *resp,
1350 			     size_t payload_len)
1351 {
1352 	u16 tlv_type;
1353 	size_t tlv_len;
1354 	size_t tlv_dlen;
1355 	const struct qlink_tlv_hdr *tlv;
1356 	const struct qlink_channel *qchan;
1357 	struct ieee80211_channel *chan;
1358 	unsigned int chidx = 0;
1359 	u32 qflags;
1360 
1361 	memset(&band->ht_cap, 0, sizeof(band->ht_cap));
1362 	memset(&band->vht_cap, 0, sizeof(band->vht_cap));
1363 
1364 	if (band->channels) {
1365 		if (band->n_channels == resp->num_chans) {
1366 			memset(band->channels, 0,
1367 			       sizeof(*band->channels) * band->n_channels);
1368 		} else {
1369 			kfree(band->channels);
1370 			band->n_channels = 0;
1371 			band->channels = NULL;
1372 		}
1373 	}
1374 
1375 	band->n_channels = resp->num_chans;
1376 	if (band->n_channels == 0)
1377 		return 0;
1378 
1379 	if (!band->channels)
1380 		band->channels = kcalloc(band->n_channels, sizeof(*chan),
1381 					 GFP_KERNEL);
1382 	if (!band->channels) {
1383 		band->n_channels = 0;
1384 		return -ENOMEM;
1385 	}
1386 
1387 	tlv = (struct qlink_tlv_hdr *)resp->info;
1388 
1389 	while (payload_len >= sizeof(*tlv)) {
1390 		tlv_type = le16_to_cpu(tlv->type);
1391 		tlv_dlen = le16_to_cpu(tlv->len);
1392 		tlv_len = tlv_dlen + sizeof(*tlv);
1393 
1394 		if (tlv_len > payload_len) {
1395 			pr_warn("malformed TLV 0x%.2X; LEN: %zu\n",
1396 				tlv_type, tlv_len);
1397 			goto error_ret;
1398 		}
1399 
1400 		switch (tlv_type) {
1401 		case QTN_TLV_ID_CHANNEL:
1402 			if (unlikely(tlv_dlen != sizeof(*qchan))) {
1403 				pr_err("invalid channel TLV len %zu\n",
1404 				       tlv_len);
1405 				goto error_ret;
1406 			}
1407 
1408 			if (chidx == band->n_channels) {
1409 				pr_err("too many channel TLVs\n");
1410 				goto error_ret;
1411 			}
1412 
1413 			qchan = (const struct qlink_channel *)tlv->val;
1414 			chan = &band->channels[chidx++];
1415 			qflags = le32_to_cpu(qchan->flags);
1416 
1417 			chan->hw_value = le16_to_cpu(qchan->hw_value);
1418 			chan->band = band->band;
1419 			chan->center_freq = le16_to_cpu(qchan->center_freq);
1420 			chan->max_antenna_gain = (int)qchan->max_antenna_gain;
1421 			chan->max_power = (int)qchan->max_power;
1422 			chan->max_reg_power = (int)qchan->max_reg_power;
1423 			chan->beacon_found = qchan->beacon_found;
1424 			chan->dfs_cac_ms = le32_to_cpu(qchan->dfs_cac_ms);
1425 			chan->flags = 0;
1426 
1427 			if (qflags & QLINK_CHAN_DISABLED)
1428 				chan->flags |= IEEE80211_CHAN_DISABLED;
1429 
1430 			if (qflags & QLINK_CHAN_NO_IR)
1431 				chan->flags |= IEEE80211_CHAN_NO_IR;
1432 
1433 			if (qflags & QLINK_CHAN_NO_HT40PLUS)
1434 				chan->flags |= IEEE80211_CHAN_NO_HT40PLUS;
1435 
1436 			if (qflags & QLINK_CHAN_NO_HT40MINUS)
1437 				chan->flags |= IEEE80211_CHAN_NO_HT40MINUS;
1438 
1439 			if (qflags & QLINK_CHAN_NO_OFDM)
1440 				chan->flags |= IEEE80211_CHAN_NO_OFDM;
1441 
1442 			if (qflags & QLINK_CHAN_NO_80MHZ)
1443 				chan->flags |= IEEE80211_CHAN_NO_80MHZ;
1444 
1445 			if (qflags & QLINK_CHAN_NO_160MHZ)
1446 				chan->flags |= IEEE80211_CHAN_NO_160MHZ;
1447 
1448 			if (qflags & QLINK_CHAN_INDOOR_ONLY)
1449 				chan->flags |= IEEE80211_CHAN_INDOOR_ONLY;
1450 
1451 			if (qflags & QLINK_CHAN_IR_CONCURRENT)
1452 				chan->flags |= IEEE80211_CHAN_IR_CONCURRENT;
1453 
1454 			if (qflags & QLINK_CHAN_NO_20MHZ)
1455 				chan->flags |= IEEE80211_CHAN_NO_20MHZ;
1456 
1457 			if (qflags & QLINK_CHAN_NO_10MHZ)
1458 				chan->flags |= IEEE80211_CHAN_NO_10MHZ;
1459 
1460 			if (qflags & QLINK_CHAN_RADAR) {
1461 				chan->flags |= IEEE80211_CHAN_RADAR;
1462 				chan->dfs_state_entered = jiffies;
1463 
1464 				if (qchan->dfs_state == QLINK_DFS_USABLE)
1465 					chan->dfs_state = NL80211_DFS_USABLE;
1466 				else if (qchan->dfs_state ==
1467 					QLINK_DFS_AVAILABLE)
1468 					chan->dfs_state = NL80211_DFS_AVAILABLE;
1469 				else
1470 					chan->dfs_state =
1471 						NL80211_DFS_UNAVAILABLE;
1472 			}
1473 
1474 			pr_debug("chan=%d flags=%#x max_pow=%d max_reg_pow=%d\n",
1475 				 chan->hw_value, chan->flags, chan->max_power,
1476 				 chan->max_reg_power);
1477 			break;
1478 		case WLAN_EID_HT_CAPABILITY:
1479 			if (unlikely(tlv_dlen !=
1480 				     sizeof(struct ieee80211_ht_cap))) {
1481 				pr_err("bad HTCAP TLV len %zu\n", tlv_dlen);
1482 				goto error_ret;
1483 			}
1484 
1485 			qtnf_cmd_resp_band_fill_htcap(tlv->val, &band->ht_cap);
1486 			break;
1487 		case WLAN_EID_VHT_CAPABILITY:
1488 			if (unlikely(tlv_dlen !=
1489 				     sizeof(struct ieee80211_vht_cap))) {
1490 				pr_err("bad VHTCAP TLV len %zu\n", tlv_dlen);
1491 				goto error_ret;
1492 			}
1493 
1494 			qtnf_cmd_resp_band_fill_vhtcap(tlv->val,
1495 						       &band->vht_cap);
1496 			break;
1497 		default:
1498 			pr_warn("unknown TLV type: %#x\n", tlv_type);
1499 			break;
1500 		}
1501 
1502 		payload_len -= tlv_len;
1503 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_dlen);
1504 	}
1505 
1506 	if (payload_len) {
1507 		pr_err("malformed TLV buf; bytes left: %zu\n", payload_len);
1508 		goto error_ret;
1509 	}
1510 
1511 	if (band->n_channels != chidx) {
1512 		pr_err("channel count mismatch: reported=%d, parsed=%d\n",
1513 		       band->n_channels, chidx);
1514 		goto error_ret;
1515 	}
1516 
1517 	return 0;
1518 
1519 error_ret:
1520 	kfree(band->channels);
1521 	band->channels = NULL;
1522 	band->n_channels = 0;
1523 
1524 	return -EINVAL;
1525 }
1526 
1527 static int qtnf_cmd_resp_proc_phy_params(struct qtnf_wmac *mac,
1528 					 const u8 *payload, size_t payload_len)
1529 {
1530 	struct qtnf_mac_info *mac_info;
1531 	struct qlink_tlv_frag_rts_thr *phy_thr;
1532 	struct qlink_tlv_rlimit *limit;
1533 	struct qlink_tlv_cclass *class;
1534 	u16 tlv_type;
1535 	u16 tlv_value_len;
1536 	size_t tlv_full_len;
1537 	const struct qlink_tlv_hdr *tlv;
1538 
1539 	mac_info = &mac->macinfo;
1540 
1541 	tlv = (struct qlink_tlv_hdr *)payload;
1542 	while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1543 		tlv_type = le16_to_cpu(tlv->type);
1544 		tlv_value_len = le16_to_cpu(tlv->len);
1545 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1546 
1547 		if (tlv_full_len > payload_len) {
1548 			pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1549 				mac->macid, tlv_type, tlv_value_len);
1550 			return -EINVAL;
1551 		}
1552 
1553 		switch (tlv_type) {
1554 		case QTN_TLV_ID_FRAG_THRESH:
1555 			phy_thr = (void *)tlv;
1556 			mac_info->frag_thr = (u32)le16_to_cpu(phy_thr->thr);
1557 			break;
1558 		case QTN_TLV_ID_RTS_THRESH:
1559 			phy_thr = (void *)tlv;
1560 			mac_info->rts_thr = (u32)le16_to_cpu(phy_thr->thr);
1561 			break;
1562 		case QTN_TLV_ID_SRETRY_LIMIT:
1563 			limit = (void *)tlv;
1564 			mac_info->sretry_limit = limit->rlimit;
1565 			break;
1566 		case QTN_TLV_ID_LRETRY_LIMIT:
1567 			limit = (void *)tlv;
1568 			mac_info->lretry_limit = limit->rlimit;
1569 			break;
1570 		case QTN_TLV_ID_COVERAGE_CLASS:
1571 			class = (void *)tlv;
1572 			mac_info->coverage_class = class->cclass;
1573 			break;
1574 		default:
1575 			pr_err("MAC%u: Unknown TLV type: %#x\n", mac->macid,
1576 			       le16_to_cpu(tlv->type));
1577 			break;
1578 		}
1579 
1580 		payload_len -= tlv_full_len;
1581 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1582 	}
1583 
1584 	if (payload_len) {
1585 		pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1586 			mac->macid, payload_len);
1587 		return -EINVAL;
1588 	}
1589 
1590 	return 0;
1591 }
1592 
1593 static int
1594 qtnf_cmd_resp_proc_chan_stat_info(struct qtnf_chan_stats *stats,
1595 				  const u8 *payload, size_t payload_len)
1596 {
1597 	struct qlink_chan_stats *qlink_stats;
1598 	const struct qlink_tlv_hdr *tlv;
1599 	size_t tlv_full_len;
1600 	u16 tlv_value_len;
1601 	u16 tlv_type;
1602 
1603 	tlv = (struct qlink_tlv_hdr *)payload;
1604 	while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1605 		tlv_type = le16_to_cpu(tlv->type);
1606 		tlv_value_len = le16_to_cpu(tlv->len);
1607 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1608 		if (tlv_full_len > payload_len) {
1609 			pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
1610 				tlv_type, tlv_value_len);
1611 			return -EINVAL;
1612 		}
1613 		switch (tlv_type) {
1614 		case QTN_TLV_ID_CHANNEL_STATS:
1615 			if (unlikely(tlv_value_len != sizeof(*qlink_stats))) {
1616 				pr_err("invalid CHANNEL_STATS entry size\n");
1617 				return -EINVAL;
1618 			}
1619 
1620 			qlink_stats = (void *)tlv->val;
1621 
1622 			stats->chan_num = le32_to_cpu(qlink_stats->chan_num);
1623 			stats->cca_tx = le32_to_cpu(qlink_stats->cca_tx);
1624 			stats->cca_rx = le32_to_cpu(qlink_stats->cca_rx);
1625 			stats->cca_busy = le32_to_cpu(qlink_stats->cca_busy);
1626 			stats->cca_try = le32_to_cpu(qlink_stats->cca_try);
1627 			stats->chan_noise = qlink_stats->chan_noise;
1628 
1629 			pr_debug("chan(%u) try(%u) busy(%u) noise(%d)\n",
1630 				 stats->chan_num, stats->cca_try,
1631 				 stats->cca_busy, stats->chan_noise);
1632 			break;
1633 		default:
1634 			pr_warn("Unknown TLV type: %#x\n",
1635 				le16_to_cpu(tlv->type));
1636 		}
1637 		payload_len -= tlv_full_len;
1638 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1639 	}
1640 
1641 	if (payload_len) {
1642 		pr_warn("malformed TLV buf; bytes left: %zu\n", payload_len);
1643 		return -EINVAL;
1644 	}
1645 
1646 	return 0;
1647 }
1648 
1649 int qtnf_cmd_get_mac_info(struct qtnf_wmac *mac)
1650 {
1651 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1652 	const struct qlink_resp_get_mac_info *resp;
1653 	size_t var_data_len;
1654 	int ret = 0;
1655 
1656 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
1657 					    QLINK_CMD_MAC_INFO,
1658 					    sizeof(struct qlink_cmd));
1659 	if (!cmd_skb)
1660 		return -ENOMEM;
1661 
1662 	qtnf_bus_lock(mac->bus);
1663 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
1664 				       sizeof(*resp), &var_data_len);
1665 	if (ret)
1666 		goto out;
1667 
1668 	resp = (const struct qlink_resp_get_mac_info *)resp_skb->data;
1669 	qtnf_cmd_resp_proc_mac_info(mac, resp);
1670 	ret = qtnf_parse_variable_mac_info(mac, resp->var_info, var_data_len);
1671 
1672 out:
1673 	qtnf_bus_unlock(mac->bus);
1674 	consume_skb(resp_skb);
1675 
1676 	return ret;
1677 }
1678 
1679 int qtnf_cmd_get_hw_info(struct qtnf_bus *bus)
1680 {
1681 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1682 	const struct qlink_resp_get_hw_info *resp;
1683 	int ret = 0;
1684 	size_t info_len;
1685 
1686 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1687 					    QLINK_CMD_GET_HW_INFO,
1688 					    sizeof(struct qlink_cmd));
1689 	if (!cmd_skb)
1690 		return -ENOMEM;
1691 
1692 	qtnf_bus_lock(bus);
1693 	ret = qtnf_cmd_send_with_reply(bus, cmd_skb, &resp_skb,
1694 				       sizeof(*resp), &info_len);
1695 	if (ret)
1696 		goto out;
1697 
1698 	resp = (const struct qlink_resp_get_hw_info *)resp_skb->data;
1699 	ret = qtnf_cmd_resp_proc_hw_info(bus, resp, info_len);
1700 
1701 out:
1702 	qtnf_bus_unlock(bus);
1703 	consume_skb(resp_skb);
1704 
1705 	return ret;
1706 }
1707 
1708 int qtnf_cmd_band_info_get(struct qtnf_wmac *mac,
1709 			   struct ieee80211_supported_band *band)
1710 {
1711 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1712 	size_t info_len;
1713 	struct qlink_cmd_band_info_get *cmd;
1714 	struct qlink_resp_band_info_get *resp;
1715 	int ret = 0;
1716 	u8 qband;
1717 
1718 	switch (band->band) {
1719 	case NL80211_BAND_2GHZ:
1720 		qband = QLINK_BAND_2GHZ;
1721 		break;
1722 	case NL80211_BAND_5GHZ:
1723 		qband = QLINK_BAND_5GHZ;
1724 		break;
1725 	case NL80211_BAND_60GHZ:
1726 		qband = QLINK_BAND_60GHZ;
1727 		break;
1728 	default:
1729 		return -EINVAL;
1730 	}
1731 
1732 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1733 					    QLINK_CMD_BAND_INFO_GET,
1734 					    sizeof(*cmd));
1735 	if (!cmd_skb)
1736 		return -ENOMEM;
1737 
1738 	cmd = (struct qlink_cmd_band_info_get *)cmd_skb->data;
1739 	cmd->band = qband;
1740 
1741 	qtnf_bus_lock(mac->bus);
1742 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
1743 				       sizeof(*resp), &info_len);
1744 	if (ret)
1745 		goto out;
1746 
1747 	resp = (struct qlink_resp_band_info_get *)resp_skb->data;
1748 	if (resp->band != qband) {
1749 		pr_err("MAC%u: reply band %u != cmd band %u\n", mac->macid,
1750 		       resp->band, qband);
1751 		ret = -EINVAL;
1752 		goto out;
1753 	}
1754 
1755 	ret = qtnf_cmd_resp_fill_band_info(band, resp, info_len);
1756 
1757 out:
1758 	qtnf_bus_unlock(mac->bus);
1759 	consume_skb(resp_skb);
1760 
1761 	return ret;
1762 }
1763 
1764 int qtnf_cmd_send_get_phy_params(struct qtnf_wmac *mac)
1765 {
1766 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1767 	size_t response_size;
1768 	struct qlink_resp_phy_params *resp;
1769 	int ret = 0;
1770 
1771 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1772 					    QLINK_CMD_PHY_PARAMS_GET,
1773 					    sizeof(struct qlink_cmd));
1774 	if (!cmd_skb)
1775 		return -ENOMEM;
1776 
1777 	qtnf_bus_lock(mac->bus);
1778 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
1779 				       sizeof(*resp), &response_size);
1780 	if (ret)
1781 		goto out;
1782 
1783 	resp = (struct qlink_resp_phy_params *)resp_skb->data;
1784 	ret = qtnf_cmd_resp_proc_phy_params(mac, resp->info, response_size);
1785 
1786 out:
1787 	qtnf_bus_unlock(mac->bus);
1788 	consume_skb(resp_skb);
1789 
1790 	return ret;
1791 }
1792 
1793 int qtnf_cmd_send_update_phy_params(struct qtnf_wmac *mac, u32 changed)
1794 {
1795 	struct wiphy *wiphy = priv_to_wiphy(mac);
1796 	struct sk_buff *cmd_skb;
1797 	int ret = 0;
1798 
1799 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1800 					    QLINK_CMD_PHY_PARAMS_SET,
1801 					    sizeof(struct qlink_cmd));
1802 	if (!cmd_skb)
1803 		return -ENOMEM;
1804 
1805 	qtnf_bus_lock(mac->bus);
1806 
1807 	if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1808 		qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_FRAG_THRESH,
1809 					 wiphy->frag_threshold);
1810 	if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1811 		qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_RTS_THRESH,
1812 					 wiphy->rts_threshold);
1813 	if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1814 		qtnf_cmd_skb_put_tlv_u8(cmd_skb, QTN_TLV_ID_COVERAGE_CLASS,
1815 					wiphy->coverage_class);
1816 
1817 	ret = qtnf_cmd_send(mac->bus, cmd_skb);
1818 	if (ret)
1819 		goto out;
1820 
1821 out:
1822 	qtnf_bus_unlock(mac->bus);
1823 
1824 	return ret;
1825 }
1826 
1827 int qtnf_cmd_send_init_fw(struct qtnf_bus *bus)
1828 {
1829 	struct sk_buff *cmd_skb;
1830 	int ret = 0;
1831 
1832 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1833 					    QLINK_CMD_FW_INIT,
1834 					    sizeof(struct qlink_cmd));
1835 	if (!cmd_skb)
1836 		return -ENOMEM;
1837 
1838 	qtnf_bus_lock(bus);
1839 	ret = qtnf_cmd_send(bus, cmd_skb);
1840 	if (ret)
1841 		goto out;
1842 
1843 out:
1844 	qtnf_bus_unlock(bus);
1845 
1846 	return ret;
1847 }
1848 
1849 void qtnf_cmd_send_deinit_fw(struct qtnf_bus *bus)
1850 {
1851 	struct sk_buff *cmd_skb;
1852 
1853 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1854 					    QLINK_CMD_FW_DEINIT,
1855 					    sizeof(struct qlink_cmd));
1856 	if (!cmd_skb)
1857 		return;
1858 
1859 	qtnf_bus_lock(bus);
1860 	qtnf_cmd_send(bus, cmd_skb);
1861 	qtnf_bus_unlock(bus);
1862 }
1863 
1864 int qtnf_cmd_send_add_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
1865 			  const u8 *mac_addr, struct key_params *params)
1866 {
1867 	struct sk_buff *cmd_skb;
1868 	struct qlink_cmd_add_key *cmd;
1869 	int ret = 0;
1870 
1871 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1872 					    QLINK_CMD_ADD_KEY,
1873 					    sizeof(*cmd));
1874 	if (!cmd_skb)
1875 		return -ENOMEM;
1876 
1877 	qtnf_bus_lock(vif->mac->bus);
1878 
1879 	cmd = (struct qlink_cmd_add_key *)cmd_skb->data;
1880 
1881 	if (mac_addr)
1882 		ether_addr_copy(cmd->addr, mac_addr);
1883 	else
1884 		eth_broadcast_addr(cmd->addr);
1885 
1886 	cmd->cipher = cpu_to_le32(params->cipher);
1887 	cmd->key_index = key_index;
1888 	cmd->pairwise = pairwise;
1889 
1890 	if (params->key && params->key_len > 0)
1891 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_KEY,
1892 					 params->key,
1893 					 params->key_len);
1894 
1895 	if (params->seq && params->seq_len > 0)
1896 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_SEQ,
1897 					 params->seq,
1898 					 params->seq_len);
1899 
1900 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1901 	if (ret)
1902 		goto out;
1903 
1904 out:
1905 	qtnf_bus_unlock(vif->mac->bus);
1906 
1907 	return ret;
1908 }
1909 
1910 int qtnf_cmd_send_del_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
1911 			  const u8 *mac_addr)
1912 {
1913 	struct sk_buff *cmd_skb;
1914 	struct qlink_cmd_del_key *cmd;
1915 	int ret = 0;
1916 
1917 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1918 					    QLINK_CMD_DEL_KEY,
1919 					    sizeof(*cmd));
1920 	if (!cmd_skb)
1921 		return -ENOMEM;
1922 
1923 	qtnf_bus_lock(vif->mac->bus);
1924 
1925 	cmd = (struct qlink_cmd_del_key *)cmd_skb->data;
1926 
1927 	if (mac_addr)
1928 		ether_addr_copy(cmd->addr, mac_addr);
1929 	else
1930 		eth_broadcast_addr(cmd->addr);
1931 
1932 	cmd->key_index = key_index;
1933 	cmd->pairwise = pairwise;
1934 
1935 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1936 	if (ret)
1937 		goto out;
1938 
1939 out:
1940 	qtnf_bus_unlock(vif->mac->bus);
1941 
1942 	return ret;
1943 }
1944 
1945 int qtnf_cmd_send_set_default_key(struct qtnf_vif *vif, u8 key_index,
1946 				  bool unicast, bool multicast)
1947 {
1948 	struct sk_buff *cmd_skb;
1949 	struct qlink_cmd_set_def_key *cmd;
1950 	int ret = 0;
1951 
1952 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1953 					    QLINK_CMD_SET_DEFAULT_KEY,
1954 					    sizeof(*cmd));
1955 	if (!cmd_skb)
1956 		return -ENOMEM;
1957 
1958 	qtnf_bus_lock(vif->mac->bus);
1959 
1960 	cmd = (struct qlink_cmd_set_def_key *)cmd_skb->data;
1961 	cmd->key_index = key_index;
1962 	cmd->unicast = unicast;
1963 	cmd->multicast = multicast;
1964 
1965 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1966 	if (ret)
1967 		goto out;
1968 
1969 out:
1970 	qtnf_bus_unlock(vif->mac->bus);
1971 
1972 	return ret;
1973 }
1974 
1975 int qtnf_cmd_send_set_default_mgmt_key(struct qtnf_vif *vif, u8 key_index)
1976 {
1977 	struct sk_buff *cmd_skb;
1978 	struct qlink_cmd_set_def_mgmt_key *cmd;
1979 	int ret = 0;
1980 
1981 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1982 					    QLINK_CMD_SET_DEFAULT_MGMT_KEY,
1983 					    sizeof(*cmd));
1984 	if (!cmd_skb)
1985 		return -ENOMEM;
1986 
1987 	qtnf_bus_lock(vif->mac->bus);
1988 
1989 	cmd = (struct qlink_cmd_set_def_mgmt_key *)cmd_skb->data;
1990 	cmd->key_index = key_index;
1991 
1992 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1993 	if (ret)
1994 		goto out;
1995 
1996 out:
1997 	qtnf_bus_unlock(vif->mac->bus);
1998 
1999 	return ret;
2000 }
2001 
2002 static u32 qtnf_encode_sta_flags(u32 flags)
2003 {
2004 	u32 code = 0;
2005 
2006 	if (flags & BIT(NL80211_STA_FLAG_AUTHORIZED))
2007 		code |= QLINK_STA_FLAG_AUTHORIZED;
2008 	if (flags & BIT(NL80211_STA_FLAG_SHORT_PREAMBLE))
2009 		code |= QLINK_STA_FLAG_SHORT_PREAMBLE;
2010 	if (flags & BIT(NL80211_STA_FLAG_WME))
2011 		code |= QLINK_STA_FLAG_WME;
2012 	if (flags & BIT(NL80211_STA_FLAG_MFP))
2013 		code |= QLINK_STA_FLAG_MFP;
2014 	if (flags & BIT(NL80211_STA_FLAG_AUTHENTICATED))
2015 		code |= QLINK_STA_FLAG_AUTHENTICATED;
2016 	if (flags & BIT(NL80211_STA_FLAG_TDLS_PEER))
2017 		code |= QLINK_STA_FLAG_TDLS_PEER;
2018 	if (flags & BIT(NL80211_STA_FLAG_ASSOCIATED))
2019 		code |= QLINK_STA_FLAG_ASSOCIATED;
2020 	return code;
2021 }
2022 
2023 int qtnf_cmd_send_change_sta(struct qtnf_vif *vif, const u8 *mac,
2024 			     struct station_parameters *params)
2025 {
2026 	struct sk_buff *cmd_skb;
2027 	struct qlink_cmd_change_sta *cmd;
2028 	int ret = 0;
2029 
2030 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2031 					    QLINK_CMD_CHANGE_STA,
2032 					    sizeof(*cmd));
2033 	if (!cmd_skb)
2034 		return -ENOMEM;
2035 
2036 	qtnf_bus_lock(vif->mac->bus);
2037 
2038 	cmd = (struct qlink_cmd_change_sta *)cmd_skb->data;
2039 	ether_addr_copy(cmd->sta_addr, mac);
2040 	cmd->flag_update.mask =
2041 		cpu_to_le32(qtnf_encode_sta_flags(params->sta_flags_mask));
2042 	cmd->flag_update.value =
2043 		cpu_to_le32(qtnf_encode_sta_flags(params->sta_flags_set));
2044 
2045 	switch (vif->wdev.iftype) {
2046 	case NL80211_IFTYPE_AP:
2047 		cmd->if_type = cpu_to_le16(QLINK_IFTYPE_AP);
2048 		break;
2049 	case NL80211_IFTYPE_STATION:
2050 		cmd->if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
2051 		break;
2052 	default:
2053 		pr_err("unsupported iftype %d\n", vif->wdev.iftype);
2054 		ret = -EINVAL;
2055 		goto out;
2056 	}
2057 
2058 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2059 	if (ret)
2060 		goto out;
2061 
2062 out:
2063 	qtnf_bus_unlock(vif->mac->bus);
2064 
2065 	return ret;
2066 }
2067 
2068 int qtnf_cmd_send_del_sta(struct qtnf_vif *vif,
2069 			  struct station_del_parameters *params)
2070 {
2071 	struct sk_buff *cmd_skb;
2072 	struct qlink_cmd_del_sta *cmd;
2073 	int ret = 0;
2074 
2075 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2076 					    QLINK_CMD_DEL_STA,
2077 					    sizeof(*cmd));
2078 	if (!cmd_skb)
2079 		return -ENOMEM;
2080 
2081 	qtnf_bus_lock(vif->mac->bus);
2082 
2083 	cmd = (struct qlink_cmd_del_sta *)cmd_skb->data;
2084 
2085 	if (params->mac)
2086 		ether_addr_copy(cmd->sta_addr, params->mac);
2087 	else
2088 		eth_broadcast_addr(cmd->sta_addr);	/* flush all stations */
2089 
2090 	cmd->subtype = params->subtype;
2091 	cmd->reason_code = cpu_to_le16(params->reason_code);
2092 
2093 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2094 	if (ret)
2095 		goto out;
2096 
2097 out:
2098 	qtnf_bus_unlock(vif->mac->bus);
2099 
2100 	return ret;
2101 }
2102 
2103 static void qtnf_cmd_channel_tlv_add(struct sk_buff *cmd_skb,
2104 				     const struct ieee80211_channel *sc)
2105 {
2106 	struct qlink_tlv_channel *qchan;
2107 	u32 flags = 0;
2108 
2109 	qchan = skb_put_zero(cmd_skb, sizeof(*qchan));
2110 	qchan->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANNEL);
2111 	qchan->hdr.len = cpu_to_le16(sizeof(*qchan) - sizeof(qchan->hdr));
2112 	qchan->chan.center_freq = cpu_to_le16(sc->center_freq);
2113 	qchan->chan.hw_value = cpu_to_le16(sc->hw_value);
2114 
2115 	if (sc->flags & IEEE80211_CHAN_NO_IR)
2116 		flags |= QLINK_CHAN_NO_IR;
2117 
2118 	if (sc->flags & IEEE80211_CHAN_RADAR)
2119 		flags |= QLINK_CHAN_RADAR;
2120 
2121 	qchan->chan.flags = cpu_to_le32(flags);
2122 }
2123 
2124 static void qtnf_cmd_randmac_tlv_add(struct sk_buff *cmd_skb,
2125 				     const u8 *mac_addr,
2126 				     const u8 *mac_addr_mask)
2127 {
2128 	struct qlink_random_mac_addr *randmac;
2129 	struct qlink_tlv_hdr *hdr =
2130 		skb_put(cmd_skb, sizeof(*hdr) + sizeof(*randmac));
2131 
2132 	hdr->type = cpu_to_le16(QTN_TLV_ID_RANDOM_MAC_ADDR);
2133 	hdr->len = cpu_to_le16(sizeof(*randmac));
2134 	randmac = (struct qlink_random_mac_addr *)hdr->val;
2135 
2136 	memcpy(randmac->mac_addr, mac_addr, ETH_ALEN);
2137 	memcpy(randmac->mac_addr_mask, mac_addr_mask, ETH_ALEN);
2138 }
2139 
2140 int qtnf_cmd_send_scan(struct qtnf_wmac *mac)
2141 {
2142 	struct sk_buff *cmd_skb;
2143 	struct ieee80211_channel *sc;
2144 	struct cfg80211_scan_request *scan_req = mac->scan_req;
2145 	int n_channels;
2146 	int count = 0;
2147 	int ret;
2148 
2149 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
2150 					    QLINK_CMD_SCAN,
2151 					    sizeof(struct qlink_cmd));
2152 	if (!cmd_skb)
2153 		return -ENOMEM;
2154 
2155 	qtnf_bus_lock(mac->bus);
2156 
2157 	if (scan_req->n_ssids != 0) {
2158 		while (count < scan_req->n_ssids) {
2159 			qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID,
2160 				scan_req->ssids[count].ssid,
2161 				scan_req->ssids[count].ssid_len);
2162 			count++;
2163 		}
2164 	}
2165 
2166 	if (scan_req->ie_len != 0)
2167 		qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_REQ,
2168 					scan_req->ie, scan_req->ie_len);
2169 
2170 	if (scan_req->n_channels) {
2171 		n_channels = scan_req->n_channels;
2172 		count = 0;
2173 
2174 		while (n_channels != 0) {
2175 			sc = scan_req->channels[count];
2176 			if (sc->flags & IEEE80211_CHAN_DISABLED) {
2177 				n_channels--;
2178 				continue;
2179 			}
2180 
2181 			pr_debug("MAC%u: scan chan=%d, freq=%d, flags=%#x\n",
2182 				 mac->macid, sc->hw_value, sc->center_freq,
2183 				 sc->flags);
2184 
2185 			qtnf_cmd_channel_tlv_add(cmd_skb, sc);
2186 			n_channels--;
2187 			count++;
2188 		}
2189 	}
2190 
2191 	if (scan_req->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
2192 		pr_debug("MAC%u: scan with random addr=%pM, mask=%pM\n",
2193 			 mac->macid,
2194 			 scan_req->mac_addr, scan_req->mac_addr_mask);
2195 
2196 		qtnf_cmd_randmac_tlv_add(cmd_skb, scan_req->mac_addr,
2197 					 scan_req->mac_addr_mask);
2198 	}
2199 
2200 	if (scan_req->flags & NL80211_SCAN_FLAG_FLUSH) {
2201 		pr_debug("MAC%u: flush cache before scan\n", mac->macid);
2202 
2203 		qtnf_cmd_skb_put_tlv_tag(cmd_skb, QTN_TLV_ID_SCAN_FLUSH);
2204 	}
2205 
2206 	if (scan_req->duration) {
2207 		pr_debug("MAC%u: %s scan duration %u\n", mac->macid,
2208 			 scan_req->duration_mandatory ? "mandatory" : "max",
2209 			 scan_req->duration);
2210 
2211 		qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_SCAN_DWELL,
2212 					 scan_req->duration);
2213 	}
2214 
2215 	ret = qtnf_cmd_send(mac->bus, cmd_skb);
2216 	if (ret)
2217 		goto out;
2218 
2219 out:
2220 	qtnf_bus_unlock(mac->bus);
2221 
2222 	return ret;
2223 }
2224 
2225 int qtnf_cmd_send_connect(struct qtnf_vif *vif,
2226 			  struct cfg80211_connect_params *sme)
2227 {
2228 	struct sk_buff *cmd_skb;
2229 	struct qlink_cmd_connect *cmd;
2230 	struct qlink_auth_encr *aen;
2231 	int ret;
2232 	int i;
2233 	u32 connect_flags = 0;
2234 
2235 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2236 					    QLINK_CMD_CONNECT,
2237 					    sizeof(*cmd));
2238 	if (!cmd_skb)
2239 		return -ENOMEM;
2240 
2241 	cmd = (struct qlink_cmd_connect *)cmd_skb->data;
2242 
2243 	ether_addr_copy(cmd->bssid, vif->bssid);
2244 
2245 	if (sme->bssid_hint)
2246 		ether_addr_copy(cmd->bssid_hint, sme->bssid_hint);
2247 	else
2248 		eth_zero_addr(cmd->bssid_hint);
2249 
2250 	if (sme->prev_bssid)
2251 		ether_addr_copy(cmd->prev_bssid, sme->prev_bssid);
2252 	else
2253 		eth_zero_addr(cmd->prev_bssid);
2254 
2255 	if ((sme->bg_scan_period >= 0) &&
2256 	    (sme->bg_scan_period <= SHRT_MAX))
2257 		cmd->bg_scan_period = cpu_to_le16(sme->bg_scan_period);
2258 	else
2259 		cmd->bg_scan_period = cpu_to_le16(-1); /* use default value */
2260 
2261 	if (sme->flags & ASSOC_REQ_DISABLE_HT)
2262 		connect_flags |= QLINK_STA_CONNECT_DISABLE_HT;
2263 	if (sme->flags & ASSOC_REQ_DISABLE_VHT)
2264 		connect_flags |= QLINK_STA_CONNECT_DISABLE_VHT;
2265 	if (sme->flags & ASSOC_REQ_USE_RRM)
2266 		connect_flags |= QLINK_STA_CONNECT_USE_RRM;
2267 
2268 	cmd->flags = cpu_to_le32(connect_flags);
2269 	memcpy(&cmd->ht_capa, &sme->ht_capa, sizeof(cmd->ht_capa));
2270 	memcpy(&cmd->ht_capa_mask, &sme->ht_capa_mask,
2271 	       sizeof(cmd->ht_capa_mask));
2272 	memcpy(&cmd->vht_capa, &sme->vht_capa, sizeof(cmd->vht_capa));
2273 	memcpy(&cmd->vht_capa_mask, &sme->vht_capa_mask,
2274 	       sizeof(cmd->vht_capa_mask));
2275 	cmd->pbss = sme->pbss;
2276 
2277 	aen = &cmd->aen;
2278 	aen->auth_type = sme->auth_type;
2279 	aen->privacy = !!sme->privacy;
2280 	cmd->mfp = sme->mfp;
2281 	aen->wpa_versions = cpu_to_le32(sme->crypto.wpa_versions);
2282 	aen->cipher_group = cpu_to_le32(sme->crypto.cipher_group);
2283 	aen->n_ciphers_pairwise = cpu_to_le32(sme->crypto.n_ciphers_pairwise);
2284 
2285 	for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
2286 		aen->ciphers_pairwise[i] =
2287 			cpu_to_le32(sme->crypto.ciphers_pairwise[i]);
2288 
2289 	aen->n_akm_suites = cpu_to_le32(sme->crypto.n_akm_suites);
2290 
2291 	for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
2292 		aen->akm_suites[i] = cpu_to_le32(sme->crypto.akm_suites[i]);
2293 
2294 	aen->control_port = sme->crypto.control_port;
2295 	aen->control_port_no_encrypt =
2296 		sme->crypto.control_port_no_encrypt;
2297 	aen->control_port_ethertype =
2298 		cpu_to_le16(be16_to_cpu(sme->crypto.control_port_ethertype));
2299 
2300 	qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, sme->ssid,
2301 				 sme->ssid_len);
2302 
2303 	if (sme->ie_len != 0)
2304 		qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_ASSOC_REQ,
2305 					sme->ie, sme->ie_len);
2306 
2307 	if (sme->channel)
2308 		qtnf_cmd_channel_tlv_add(cmd_skb, sme->channel);
2309 
2310 	qtnf_bus_lock(vif->mac->bus);
2311 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2312 	if (ret)
2313 		goto out;
2314 
2315 out:
2316 	qtnf_bus_unlock(vif->mac->bus);
2317 
2318 	return ret;
2319 }
2320 
2321 int qtnf_cmd_send_disconnect(struct qtnf_vif *vif, u16 reason_code)
2322 {
2323 	struct sk_buff *cmd_skb;
2324 	struct qlink_cmd_disconnect *cmd;
2325 	int ret;
2326 
2327 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2328 					    QLINK_CMD_DISCONNECT,
2329 					    sizeof(*cmd));
2330 	if (!cmd_skb)
2331 		return -ENOMEM;
2332 
2333 	qtnf_bus_lock(vif->mac->bus);
2334 
2335 	cmd = (struct qlink_cmd_disconnect *)cmd_skb->data;
2336 	cmd->reason = cpu_to_le16(reason_code);
2337 
2338 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2339 	if (ret)
2340 		goto out;
2341 
2342 out:
2343 	qtnf_bus_unlock(vif->mac->bus);
2344 
2345 	return ret;
2346 }
2347 
2348 int qtnf_cmd_send_updown_intf(struct qtnf_vif *vif, bool up)
2349 {
2350 	struct sk_buff *cmd_skb;
2351 	struct qlink_cmd_updown *cmd;
2352 	int ret;
2353 
2354 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2355 					    QLINK_CMD_UPDOWN_INTF,
2356 					    sizeof(*cmd));
2357 	if (!cmd_skb)
2358 		return -ENOMEM;
2359 
2360 	cmd = (struct qlink_cmd_updown *)cmd_skb->data;
2361 	cmd->if_up = !!up;
2362 
2363 	qtnf_bus_lock(vif->mac->bus);
2364 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2365 	if (ret)
2366 		goto out;
2367 
2368 out:
2369 	qtnf_bus_unlock(vif->mac->bus);
2370 
2371 	return ret;
2372 }
2373 
2374 int qtnf_cmd_reg_notify(struct qtnf_bus *bus, struct regulatory_request *req)
2375 {
2376 	struct sk_buff *cmd_skb;
2377 	int ret;
2378 	struct qlink_cmd_reg_notify *cmd;
2379 
2380 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
2381 					    QLINK_CMD_REG_NOTIFY,
2382 					    sizeof(*cmd));
2383 	if (!cmd_skb)
2384 		return -ENOMEM;
2385 
2386 	cmd = (struct qlink_cmd_reg_notify *)cmd_skb->data;
2387 	cmd->alpha2[0] = req->alpha2[0];
2388 	cmd->alpha2[1] = req->alpha2[1];
2389 
2390 	switch (req->initiator) {
2391 	case NL80211_REGDOM_SET_BY_CORE:
2392 		cmd->initiator = QLINK_REGDOM_SET_BY_CORE;
2393 		break;
2394 	case NL80211_REGDOM_SET_BY_USER:
2395 		cmd->initiator = QLINK_REGDOM_SET_BY_USER;
2396 		break;
2397 	case NL80211_REGDOM_SET_BY_DRIVER:
2398 		cmd->initiator = QLINK_REGDOM_SET_BY_DRIVER;
2399 		break;
2400 	case NL80211_REGDOM_SET_BY_COUNTRY_IE:
2401 		cmd->initiator = QLINK_REGDOM_SET_BY_COUNTRY_IE;
2402 		break;
2403 	}
2404 
2405 	switch (req->user_reg_hint_type) {
2406 	case NL80211_USER_REG_HINT_USER:
2407 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_USER;
2408 		break;
2409 	case NL80211_USER_REG_HINT_CELL_BASE:
2410 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_CELL_BASE;
2411 		break;
2412 	case NL80211_USER_REG_HINT_INDOOR:
2413 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_INDOOR;
2414 		break;
2415 	}
2416 
2417 	qtnf_bus_lock(bus);
2418 	ret = qtnf_cmd_send(bus, cmd_skb);
2419 	if (ret)
2420 		goto out;
2421 
2422 out:
2423 	qtnf_bus_unlock(bus);
2424 
2425 	return ret;
2426 }
2427 
2428 int qtnf_cmd_get_chan_stats(struct qtnf_wmac *mac, u16 channel,
2429 			    struct qtnf_chan_stats *stats)
2430 {
2431 	struct sk_buff *cmd_skb, *resp_skb = NULL;
2432 	struct qlink_cmd_get_chan_stats *cmd;
2433 	struct qlink_resp_get_chan_stats *resp;
2434 	size_t var_data_len;
2435 	int ret = 0;
2436 
2437 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
2438 					    QLINK_CMD_CHAN_STATS,
2439 					    sizeof(*cmd));
2440 	if (!cmd_skb)
2441 		return -ENOMEM;
2442 
2443 	qtnf_bus_lock(mac->bus);
2444 
2445 	cmd = (struct qlink_cmd_get_chan_stats *)cmd_skb->data;
2446 	cmd->channel = cpu_to_le16(channel);
2447 
2448 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
2449 				       sizeof(*resp), &var_data_len);
2450 	if (ret)
2451 		goto out;
2452 
2453 	resp = (struct qlink_resp_get_chan_stats *)resp_skb->data;
2454 	ret = qtnf_cmd_resp_proc_chan_stat_info(stats, resp->info,
2455 						var_data_len);
2456 
2457 out:
2458 	qtnf_bus_unlock(mac->bus);
2459 	consume_skb(resp_skb);
2460 
2461 	return ret;
2462 }
2463 
2464 int qtnf_cmd_send_chan_switch(struct qtnf_vif *vif,
2465 			      struct cfg80211_csa_settings *params)
2466 {
2467 	struct qtnf_wmac *mac = vif->mac;
2468 	struct qlink_cmd_chan_switch *cmd;
2469 	struct sk_buff *cmd_skb;
2470 	int ret;
2471 
2472 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, vif->vifid,
2473 					    QLINK_CMD_CHAN_SWITCH,
2474 					    sizeof(*cmd));
2475 	if (!cmd_skb)
2476 		return -ENOMEM;
2477 
2478 	qtnf_bus_lock(mac->bus);
2479 
2480 	cmd = (struct qlink_cmd_chan_switch *)cmd_skb->data;
2481 	cmd->channel = cpu_to_le16(params->chandef.chan->hw_value);
2482 	cmd->radar_required = params->radar_required;
2483 	cmd->block_tx = params->block_tx;
2484 	cmd->beacon_count = params->count;
2485 
2486 	ret = qtnf_cmd_send(mac->bus, cmd_skb);
2487 	if (ret)
2488 		goto out;
2489 
2490 out:
2491 	qtnf_bus_unlock(mac->bus);
2492 
2493 	return ret;
2494 }
2495 
2496 int qtnf_cmd_get_channel(struct qtnf_vif *vif, struct cfg80211_chan_def *chdef)
2497 {
2498 	struct qtnf_bus *bus = vif->mac->bus;
2499 	const struct qlink_resp_channel_get *resp;
2500 	struct sk_buff *cmd_skb;
2501 	struct sk_buff *resp_skb = NULL;
2502 	int ret;
2503 
2504 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2505 					    QLINK_CMD_CHAN_GET,
2506 					    sizeof(struct qlink_cmd));
2507 	if (!cmd_skb)
2508 		return -ENOMEM;
2509 
2510 	qtnf_bus_lock(bus);
2511 	ret = qtnf_cmd_send_with_reply(bus, cmd_skb, &resp_skb,
2512 				       sizeof(*resp), NULL);
2513 	if (ret)
2514 		goto out;
2515 
2516 	resp = (const struct qlink_resp_channel_get *)resp_skb->data;
2517 	qlink_chandef_q2cfg(priv_to_wiphy(vif->mac), &resp->chan, chdef);
2518 
2519 out:
2520 	qtnf_bus_unlock(bus);
2521 	consume_skb(resp_skb);
2522 
2523 	return ret;
2524 }
2525 
2526 int qtnf_cmd_start_cac(const struct qtnf_vif *vif,
2527 		       const struct cfg80211_chan_def *chdef,
2528 		       u32 cac_time_ms)
2529 {
2530 	struct qtnf_bus *bus = vif->mac->bus;
2531 	struct sk_buff *cmd_skb;
2532 	struct qlink_cmd_start_cac *cmd;
2533 	int ret;
2534 
2535 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2536 					    QLINK_CMD_START_CAC,
2537 					    sizeof(*cmd));
2538 	if (!cmd_skb)
2539 		return -ENOMEM;
2540 
2541 	cmd = (struct qlink_cmd_start_cac *)cmd_skb->data;
2542 	cmd->cac_time_ms = cpu_to_le32(cac_time_ms);
2543 	qlink_chandef_cfg2q(chdef, &cmd->chan);
2544 
2545 	qtnf_bus_lock(bus);
2546 	ret = qtnf_cmd_send(bus, cmd_skb);
2547 	if (ret)
2548 		goto out;
2549 
2550 out:
2551 	qtnf_bus_unlock(bus);
2552 
2553 	return ret;
2554 }
2555 
2556 int qtnf_cmd_set_mac_acl(const struct qtnf_vif *vif,
2557 			 const struct cfg80211_acl_data *params)
2558 {
2559 	struct qtnf_bus *bus = vif->mac->bus;
2560 	struct sk_buff *cmd_skb;
2561 	struct qlink_tlv_hdr *tlv;
2562 	size_t acl_size = qtnf_cmd_acl_data_size(params);
2563 	int ret;
2564 
2565 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2566 					    QLINK_CMD_SET_MAC_ACL,
2567 					    sizeof(struct qlink_cmd));
2568 	if (!cmd_skb)
2569 		return -ENOMEM;
2570 
2571 	tlv = skb_put(cmd_skb, sizeof(*tlv) + acl_size);
2572 	tlv->type = cpu_to_le16(QTN_TLV_ID_ACL_DATA);
2573 	tlv->len = cpu_to_le16(acl_size);
2574 	qlink_acl_data_cfg2q(params, (struct qlink_acl_data *)tlv->val);
2575 
2576 	qtnf_bus_lock(bus);
2577 	ret = qtnf_cmd_send(bus, cmd_skb);
2578 	if (ret)
2579 		goto out;
2580 
2581 out:
2582 	qtnf_bus_unlock(bus);
2583 
2584 	return ret;
2585 }
2586 
2587 int qtnf_cmd_send_pm_set(const struct qtnf_vif *vif, u8 pm_mode, int timeout)
2588 {
2589 	struct qtnf_bus *bus = vif->mac->bus;
2590 	struct sk_buff *cmd_skb;
2591 	struct qlink_cmd_pm_set *cmd;
2592 	int ret = 0;
2593 
2594 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2595 					    QLINK_CMD_PM_SET, sizeof(*cmd));
2596 	if (!cmd_skb)
2597 		return -ENOMEM;
2598 
2599 	cmd = (struct qlink_cmd_pm_set *)cmd_skb->data;
2600 	cmd->pm_mode = pm_mode;
2601 	cmd->pm_standby_timer = cpu_to_le32(timeout);
2602 
2603 	qtnf_bus_lock(bus);
2604 
2605 	ret = qtnf_cmd_send(bus, cmd_skb);
2606 	if (ret)
2607 		goto out;
2608 
2609 out:
2610 	qtnf_bus_unlock(bus);
2611 
2612 	return ret;
2613 }
2614 
2615 int qtnf_cmd_send_wowlan_set(const struct qtnf_vif *vif,
2616 			     const struct cfg80211_wowlan *wowl)
2617 {
2618 	struct qtnf_bus *bus = vif->mac->bus;
2619 	struct sk_buff *cmd_skb;
2620 	struct qlink_cmd_wowlan_set *cmd;
2621 	u32 triggers = 0;
2622 	int count = 0;
2623 	int ret = 0;
2624 
2625 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2626 					    QLINK_CMD_WOWLAN_SET, sizeof(*cmd));
2627 	if (!cmd_skb)
2628 		return -ENOMEM;
2629 
2630 	qtnf_bus_lock(bus);
2631 
2632 	cmd = (struct qlink_cmd_wowlan_set *)cmd_skb->data;
2633 
2634 	if (wowl) {
2635 		if (wowl->disconnect)
2636 			triggers |=  QLINK_WOWLAN_TRIG_DISCONNECT;
2637 
2638 		if (wowl->magic_pkt)
2639 			triggers |= QLINK_WOWLAN_TRIG_MAGIC_PKT;
2640 
2641 		if (wowl->n_patterns && wowl->patterns) {
2642 			triggers |= QLINK_WOWLAN_TRIG_PATTERN_PKT;
2643 			while (count < wowl->n_patterns) {
2644 				qtnf_cmd_skb_put_tlv_arr(cmd_skb,
2645 					QTN_TLV_ID_WOWLAN_PATTERN,
2646 					wowl->patterns[count].pattern,
2647 					wowl->patterns[count].pattern_len);
2648 				count++;
2649 			}
2650 		}
2651 	}
2652 
2653 	cmd->triggers = cpu_to_le32(triggers);
2654 
2655 	ret = qtnf_cmd_send(bus, cmd_skb);
2656 	if (ret)
2657 		goto out;
2658 
2659 out:
2660 	qtnf_bus_unlock(bus);
2661 	return ret;
2662 }
2663