1 /*
2  * Copyright (c) 2015-2016 Quantenna Communications, Inc.
3  *
4  * This program is free software; you can redistribute it and/or
5  * modify it under the terms of the GNU General Public License
6  * as published by the Free Software Foundation; either version 2
7  * of the License, or (at your option) any later version.
8  *
9  * This program is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  *
14  */
15 
16 #include <linux/types.h>
17 #include <linux/skbuff.h>
18 
19 #include "cfg80211.h"
20 #include "core.h"
21 #include "qlink.h"
22 #include "qlink_util.h"
23 #include "bus.h"
24 #include "commands.h"
25 
26 static int qtnf_cmd_check_reply_header(const struct qlink_resp *resp,
27 				       u16 cmd_id, u8 mac_id, u8 vif_id,
28 				       size_t resp_size)
29 {
30 	if (unlikely(le16_to_cpu(resp->cmd_id) != cmd_id)) {
31 		pr_warn("VIF%u.%u CMD%x: bad cmd_id in response: 0x%.4X\n",
32 			mac_id, vif_id, cmd_id, le16_to_cpu(resp->cmd_id));
33 		return -EINVAL;
34 	}
35 
36 	if (unlikely(resp->macid != mac_id)) {
37 		pr_warn("VIF%u.%u CMD%x: bad MAC in response: %u\n",
38 			mac_id, vif_id, cmd_id, resp->macid);
39 		return -EINVAL;
40 	}
41 
42 	if (unlikely(resp->vifid != vif_id)) {
43 		pr_warn("VIF%u.%u CMD%x: bad VIF in response: %u\n",
44 			mac_id, vif_id, cmd_id, resp->vifid);
45 		return -EINVAL;
46 	}
47 
48 	if (unlikely(le16_to_cpu(resp->mhdr.len) < resp_size)) {
49 		pr_warn("VIF%u.%u CMD%x: bad response size %u < %zu\n",
50 			mac_id, vif_id, cmd_id,
51 			le16_to_cpu(resp->mhdr.len), resp_size);
52 		return -ENOSPC;
53 	}
54 
55 	return 0;
56 }
57 
58 static int qtnf_cmd_resp_result_decode(enum qlink_cmd_result qcode)
59 {
60 	switch (qcode) {
61 	case QLINK_CMD_RESULT_OK:
62 		return 0;
63 	case QLINK_CMD_RESULT_INVALID:
64 		return -EINVAL;
65 	case QLINK_CMD_RESULT_ENOTSUPP:
66 		return -ENOTSUPP;
67 	case QLINK_CMD_RESULT_ENOTFOUND:
68 		return -ENOENT;
69 	case QLINK_CMD_RESULT_EALREADY:
70 		return -EALREADY;
71 	case QLINK_CMD_RESULT_EADDRINUSE:
72 		return -EADDRINUSE;
73 	case QLINK_CMD_RESULT_EADDRNOTAVAIL:
74 		return -EADDRNOTAVAIL;
75 	default:
76 		return -EFAULT;
77 	}
78 }
79 
80 static int qtnf_cmd_send_with_reply(struct qtnf_bus *bus,
81 				    struct sk_buff *cmd_skb,
82 				    struct sk_buff **response_skb,
83 				    size_t const_resp_size,
84 				    size_t *var_resp_size)
85 {
86 	struct qlink_cmd *cmd;
87 	struct qlink_resp *resp = NULL;
88 	struct sk_buff *resp_skb = NULL;
89 	u16 cmd_id;
90 	u8 mac_id;
91 	u8 vif_id;
92 	int ret;
93 
94 	cmd = (struct qlink_cmd *)cmd_skb->data;
95 	cmd_id = le16_to_cpu(cmd->cmd_id);
96 	mac_id = cmd->macid;
97 	vif_id = cmd->vifid;
98 	cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
99 
100 	pr_debug("VIF%u.%u cmd=0x%.4X\n", mac_id, vif_id,
101 		 le16_to_cpu(cmd->cmd_id));
102 
103 	if (bus->fw_state != QTNF_FW_STATE_ACTIVE &&
104 	    le16_to_cpu(cmd->cmd_id) != QLINK_CMD_FW_INIT) {
105 		pr_warn("VIF%u.%u: drop cmd 0x%.4X in fw state %d\n",
106 			mac_id, vif_id, le16_to_cpu(cmd->cmd_id),
107 			bus->fw_state);
108 		dev_kfree_skb(cmd_skb);
109 		return -ENODEV;
110 	}
111 
112 	ret = qtnf_trans_send_cmd_with_resp(bus, cmd_skb, &resp_skb);
113 	if (ret)
114 		goto out;
115 
116 	if (WARN_ON(!resp_skb || !resp_skb->data)) {
117 		ret = -EFAULT;
118 		goto out;
119 	}
120 
121 	resp = (struct qlink_resp *)resp_skb->data;
122 	ret = qtnf_cmd_check_reply_header(resp, cmd_id, mac_id, vif_id,
123 					  const_resp_size);
124 	if (ret)
125 		goto out;
126 
127 	/* Return length of variable part of response */
128 	if (response_skb && var_resp_size)
129 		*var_resp_size = le16_to_cpu(resp->mhdr.len) - const_resp_size;
130 
131 out:
132 	if (response_skb)
133 		*response_skb = resp_skb;
134 	else
135 		consume_skb(resp_skb);
136 
137 	if (!ret && resp)
138 		return qtnf_cmd_resp_result_decode(le16_to_cpu(resp->result));
139 
140 	pr_warn("VIF%u.%u: cmd 0x%.4X failed: %d\n",
141 		mac_id, vif_id, le16_to_cpu(cmd->cmd_id), ret);
142 
143 	return ret;
144 }
145 
146 static inline int qtnf_cmd_send(struct qtnf_bus *bus, struct sk_buff *cmd_skb)
147 {
148 	return qtnf_cmd_send_with_reply(bus, cmd_skb, NULL,
149 					sizeof(struct qlink_resp), NULL);
150 }
151 
152 static struct sk_buff *qtnf_cmd_alloc_new_cmdskb(u8 macid, u8 vifid, u16 cmd_no,
153 						 size_t cmd_size)
154 {
155 	struct qlink_cmd *cmd;
156 	struct sk_buff *cmd_skb;
157 
158 	cmd_skb = __dev_alloc_skb(sizeof(*cmd) +
159 				  QTNF_MAX_CMD_BUF_SIZE, GFP_KERNEL);
160 	if (unlikely(!cmd_skb)) {
161 		pr_err("VIF%u.%u CMD %u: alloc failed\n", macid, vifid, cmd_no);
162 		return NULL;
163 	}
164 
165 	skb_put_zero(cmd_skb, cmd_size);
166 
167 	cmd = (struct qlink_cmd *)cmd_skb->data;
168 	cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
169 	cmd->mhdr.type = cpu_to_le16(QLINK_MSG_TYPE_CMD);
170 	cmd->cmd_id = cpu_to_le16(cmd_no);
171 	cmd->macid = macid;
172 	cmd->vifid = vifid;
173 
174 	return cmd_skb;
175 }
176 
177 static void qtnf_cmd_tlv_ie_set_add(struct sk_buff *cmd_skb, u8 frame_type,
178 				    const u8 *buf, size_t len)
179 {
180 	struct qlink_tlv_ie_set *tlv;
181 
182 	tlv = (struct qlink_tlv_ie_set *)skb_put(cmd_skb, sizeof(*tlv) + len);
183 	tlv->hdr.type = cpu_to_le16(QTN_TLV_ID_IE_SET);
184 	tlv->hdr.len = cpu_to_le16(len + sizeof(*tlv) - sizeof(tlv->hdr));
185 	tlv->type = frame_type;
186 	tlv->flags = 0;
187 
188 	if (len && buf)
189 		memcpy(tlv->ie_data, buf, len);
190 }
191 
192 static inline size_t qtnf_cmd_acl_data_size(const struct cfg80211_acl_data *acl)
193 {
194 	size_t size = sizeof(struct qlink_acl_data) +
195 		      acl->n_acl_entries * sizeof(struct qlink_mac_address);
196 
197 	return size;
198 }
199 
200 static bool qtnf_cmd_start_ap_can_fit(const struct qtnf_vif *vif,
201 				      const struct cfg80211_ap_settings *s)
202 {
203 	unsigned int len = sizeof(struct qlink_cmd_start_ap);
204 
205 	len += s->ssid_len;
206 	len += s->beacon.head_len;
207 	len += s->beacon.tail_len;
208 	len += s->beacon.beacon_ies_len;
209 	len += s->beacon.proberesp_ies_len;
210 	len += s->beacon.assocresp_ies_len;
211 	len += s->beacon.probe_resp_len;
212 
213 	if (cfg80211_chandef_valid(&s->chandef))
214 		len += sizeof(struct qlink_tlv_chandef);
215 
216 	if (s->acl)
217 		len += sizeof(struct qlink_tlv_hdr) +
218 		       qtnf_cmd_acl_data_size(s->acl);
219 
220 	if (len > (sizeof(struct qlink_cmd) + QTNF_MAX_CMD_BUF_SIZE)) {
221 		pr_err("VIF%u.%u: can not fit AP settings: %u\n",
222 		       vif->mac->macid, vif->vifid, len);
223 		return false;
224 	}
225 
226 	return true;
227 }
228 
229 int qtnf_cmd_send_start_ap(struct qtnf_vif *vif,
230 			   const struct cfg80211_ap_settings *s)
231 {
232 	struct sk_buff *cmd_skb;
233 	struct qlink_cmd_start_ap *cmd;
234 	struct qlink_auth_encr *aen;
235 	int ret;
236 	int i;
237 
238 	if (!qtnf_cmd_start_ap_can_fit(vif, s))
239 		return -E2BIG;
240 
241 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
242 					    QLINK_CMD_START_AP,
243 					    sizeof(*cmd));
244 	if (!cmd_skb)
245 		return -ENOMEM;
246 
247 	cmd = (struct qlink_cmd_start_ap *)cmd_skb->data;
248 	cmd->dtim_period = s->dtim_period;
249 	cmd->beacon_interval = cpu_to_le16(s->beacon_interval);
250 	cmd->hidden_ssid = qlink_hidden_ssid_nl2q(s->hidden_ssid);
251 	cmd->inactivity_timeout = cpu_to_le16(s->inactivity_timeout);
252 	cmd->smps_mode = s->smps_mode;
253 	cmd->p2p_ctwindow = s->p2p_ctwindow;
254 	cmd->p2p_opp_ps = s->p2p_opp_ps;
255 	cmd->pbss = s->pbss;
256 	cmd->ht_required = s->ht_required;
257 	cmd->vht_required = s->vht_required;
258 
259 	aen = &cmd->aen;
260 	aen->auth_type = s->auth_type;
261 	aen->privacy = !!s->privacy;
262 	aen->wpa_versions = cpu_to_le32(s->crypto.wpa_versions);
263 	aen->cipher_group = cpu_to_le32(s->crypto.cipher_group);
264 	aen->n_ciphers_pairwise = cpu_to_le32(s->crypto.n_ciphers_pairwise);
265 	for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
266 		aen->ciphers_pairwise[i] =
267 				cpu_to_le32(s->crypto.ciphers_pairwise[i]);
268 	aen->n_akm_suites = cpu_to_le32(s->crypto.n_akm_suites);
269 	for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
270 		aen->akm_suites[i] = cpu_to_le32(s->crypto.akm_suites[i]);
271 	aen->control_port = s->crypto.control_port;
272 	aen->control_port_no_encrypt = s->crypto.control_port_no_encrypt;
273 	aen->control_port_ethertype =
274 		cpu_to_le16(be16_to_cpu(s->crypto.control_port_ethertype));
275 
276 	if (s->ssid && s->ssid_len > 0 && s->ssid_len <= IEEE80211_MAX_SSID_LEN)
277 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, s->ssid,
278 					 s->ssid_len);
279 
280 	if (cfg80211_chandef_valid(&s->chandef)) {
281 		struct qlink_tlv_chandef *chtlv =
282 			(struct qlink_tlv_chandef *)skb_put(cmd_skb,
283 							    sizeof(*chtlv));
284 
285 		chtlv->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANDEF);
286 		chtlv->hdr.len = cpu_to_le16(sizeof(*chtlv) -
287 					     sizeof(chtlv->hdr));
288 		qlink_chandef_cfg2q(&s->chandef, &chtlv->chdef);
289 	}
290 
291 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_HEAD,
292 				s->beacon.head, s->beacon.head_len);
293 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_TAIL,
294 				s->beacon.tail, s->beacon.tail_len);
295 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_IES,
296 				s->beacon.beacon_ies, s->beacon.beacon_ies_len);
297 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_RESP,
298 				s->beacon.probe_resp, s->beacon.probe_resp_len);
299 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_RESP_IES,
300 				s->beacon.proberesp_ies,
301 				s->beacon.proberesp_ies_len);
302 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_ASSOC_RESP,
303 				s->beacon.assocresp_ies,
304 				s->beacon.assocresp_ies_len);
305 
306 	if (s->ht_cap) {
307 		struct qlink_tlv_hdr *tlv = (struct qlink_tlv_hdr *)
308 			skb_put(cmd_skb, sizeof(*tlv) + sizeof(*s->ht_cap));
309 
310 		tlv->type = cpu_to_le16(WLAN_EID_HT_CAPABILITY);
311 		tlv->len = cpu_to_le16(sizeof(*s->ht_cap));
312 		memcpy(tlv->val, s->ht_cap, sizeof(*s->ht_cap));
313 	}
314 
315 	if (s->vht_cap) {
316 		struct qlink_tlv_hdr *tlv = (struct qlink_tlv_hdr *)
317 			skb_put(cmd_skb, sizeof(*tlv) + sizeof(*s->vht_cap));
318 
319 		tlv->type = cpu_to_le16(WLAN_EID_VHT_CAPABILITY);
320 		tlv->len = cpu_to_le16(sizeof(*s->vht_cap));
321 		memcpy(tlv->val, s->vht_cap, sizeof(*s->vht_cap));
322 	}
323 
324 	if (s->acl) {
325 		size_t acl_size = qtnf_cmd_acl_data_size(s->acl);
326 		struct qlink_tlv_hdr *tlv =
327 			skb_put(cmd_skb, sizeof(*tlv) + acl_size);
328 
329 		tlv->type = cpu_to_le16(QTN_TLV_ID_ACL_DATA);
330 		tlv->len = cpu_to_le16(acl_size);
331 		qlink_acl_data_cfg2q(s->acl, (struct qlink_acl_data *)tlv->val);
332 	}
333 
334 	qtnf_bus_lock(vif->mac->bus);
335 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
336 	if (ret)
337 		goto out;
338 
339 	netif_carrier_on(vif->netdev);
340 
341 out:
342 	qtnf_bus_unlock(vif->mac->bus);
343 
344 	return ret;
345 }
346 
347 int qtnf_cmd_send_stop_ap(struct qtnf_vif *vif)
348 {
349 	struct sk_buff *cmd_skb;
350 	int ret;
351 
352 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
353 					    QLINK_CMD_STOP_AP,
354 					    sizeof(struct qlink_cmd));
355 	if (!cmd_skb)
356 		return -ENOMEM;
357 
358 	qtnf_bus_lock(vif->mac->bus);
359 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
360 	if (ret)
361 		goto out;
362 
363 out:
364 	qtnf_bus_unlock(vif->mac->bus);
365 
366 	return ret;
367 }
368 
369 int qtnf_cmd_send_register_mgmt(struct qtnf_vif *vif, u16 frame_type, bool reg)
370 {
371 	struct sk_buff *cmd_skb;
372 	struct qlink_cmd_mgmt_frame_register *cmd;
373 	int ret;
374 
375 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
376 					    QLINK_CMD_REGISTER_MGMT,
377 					    sizeof(*cmd));
378 	if (!cmd_skb)
379 		return -ENOMEM;
380 
381 	qtnf_bus_lock(vif->mac->bus);
382 
383 	cmd = (struct qlink_cmd_mgmt_frame_register *)cmd_skb->data;
384 	cmd->frame_type = cpu_to_le16(frame_type);
385 	cmd->do_register = reg;
386 
387 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
388 	if (ret)
389 		goto out;
390 
391 out:
392 	qtnf_bus_unlock(vif->mac->bus);
393 
394 	return ret;
395 }
396 
397 int qtnf_cmd_send_mgmt_frame(struct qtnf_vif *vif, u32 cookie, u16 flags,
398 			     u16 freq, const u8 *buf, size_t len)
399 {
400 	struct sk_buff *cmd_skb;
401 	struct qlink_cmd_mgmt_frame_tx *cmd;
402 	int ret;
403 
404 	if (sizeof(*cmd) + len > QTNF_MAX_CMD_BUF_SIZE) {
405 		pr_warn("VIF%u.%u: frame is too big: %zu\n", vif->mac->macid,
406 			vif->vifid, len);
407 		return -E2BIG;
408 	}
409 
410 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
411 					    QLINK_CMD_SEND_MGMT_FRAME,
412 					    sizeof(*cmd));
413 	if (!cmd_skb)
414 		return -ENOMEM;
415 
416 	qtnf_bus_lock(vif->mac->bus);
417 
418 	cmd = (struct qlink_cmd_mgmt_frame_tx *)cmd_skb->data;
419 	cmd->cookie = cpu_to_le32(cookie);
420 	cmd->freq = cpu_to_le16(freq);
421 	cmd->flags = cpu_to_le16(flags);
422 
423 	if (len && buf)
424 		qtnf_cmd_skb_put_buffer(cmd_skb, buf, len);
425 
426 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
427 	if (ret)
428 		goto out;
429 
430 out:
431 	qtnf_bus_unlock(vif->mac->bus);
432 
433 	return ret;
434 }
435 
436 int qtnf_cmd_send_mgmt_set_appie(struct qtnf_vif *vif, u8 frame_type,
437 				 const u8 *buf, size_t len)
438 {
439 	struct sk_buff *cmd_skb;
440 	int ret;
441 
442 	if (len > QTNF_MAX_CMD_BUF_SIZE) {
443 		pr_warn("VIF%u.%u: %u frame is too big: %zu\n", vif->mac->macid,
444 			vif->vifid, frame_type, len);
445 		return -E2BIG;
446 	}
447 
448 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
449 					    QLINK_CMD_MGMT_SET_APPIE,
450 					    sizeof(struct qlink_cmd));
451 	if (!cmd_skb)
452 		return -ENOMEM;
453 
454 	qtnf_cmd_tlv_ie_set_add(cmd_skb, frame_type, buf, len);
455 
456 	qtnf_bus_lock(vif->mac->bus);
457 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
458 	if (ret)
459 		goto out;
460 
461 out:
462 	qtnf_bus_unlock(vif->mac->bus);
463 
464 	return ret;
465 }
466 
467 static void
468 qtnf_sta_info_parse_rate(struct rate_info *rate_dst,
469 			 const struct qlink_sta_info_rate *rate_src)
470 {
471 	rate_dst->legacy = get_unaligned_le16(&rate_src->rate) * 10;
472 
473 	rate_dst->mcs = rate_src->mcs;
474 	rate_dst->nss = rate_src->nss;
475 	rate_dst->flags = 0;
476 
477 	switch (rate_src->bw) {
478 	case QLINK_CHAN_WIDTH_5:
479 		rate_dst->bw = RATE_INFO_BW_5;
480 		break;
481 	case QLINK_CHAN_WIDTH_10:
482 		rate_dst->bw = RATE_INFO_BW_10;
483 		break;
484 	case QLINK_CHAN_WIDTH_20:
485 	case QLINK_CHAN_WIDTH_20_NOHT:
486 		rate_dst->bw = RATE_INFO_BW_20;
487 		break;
488 	case QLINK_CHAN_WIDTH_40:
489 		rate_dst->bw = RATE_INFO_BW_40;
490 		break;
491 	case QLINK_CHAN_WIDTH_80:
492 		rate_dst->bw = RATE_INFO_BW_80;
493 		break;
494 	case QLINK_CHAN_WIDTH_160:
495 		rate_dst->bw = RATE_INFO_BW_160;
496 		break;
497 	default:
498 		rate_dst->bw = 0;
499 		break;
500 	}
501 
502 	if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_HT_MCS)
503 		rate_dst->flags |= RATE_INFO_FLAGS_MCS;
504 	else if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_VHT_MCS)
505 		rate_dst->flags |= RATE_INFO_FLAGS_VHT_MCS;
506 
507 	if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_SHORT_GI)
508 		rate_dst->flags |= RATE_INFO_FLAGS_SHORT_GI;
509 }
510 
511 static void
512 qtnf_sta_info_parse_flags(struct nl80211_sta_flag_update *dst,
513 			  const struct qlink_sta_info_state *src)
514 {
515 	u32 mask, value;
516 
517 	dst->mask = 0;
518 	dst->set = 0;
519 
520 	mask = le32_to_cpu(src->mask);
521 	value = le32_to_cpu(src->value);
522 
523 	if (mask & QLINK_STA_FLAG_AUTHORIZED) {
524 		dst->mask |= BIT(NL80211_STA_FLAG_AUTHORIZED);
525 		if (value & QLINK_STA_FLAG_AUTHORIZED)
526 			dst->set |= BIT(NL80211_STA_FLAG_AUTHORIZED);
527 	}
528 
529 	if (mask & QLINK_STA_FLAG_SHORT_PREAMBLE) {
530 		dst->mask |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
531 		if (value & QLINK_STA_FLAG_SHORT_PREAMBLE)
532 			dst->set |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
533 	}
534 
535 	if (mask & QLINK_STA_FLAG_WME) {
536 		dst->mask |= BIT(NL80211_STA_FLAG_WME);
537 		if (value & QLINK_STA_FLAG_WME)
538 			dst->set |= BIT(NL80211_STA_FLAG_WME);
539 	}
540 
541 	if (mask & QLINK_STA_FLAG_MFP) {
542 		dst->mask |= BIT(NL80211_STA_FLAG_MFP);
543 		if (value & QLINK_STA_FLAG_MFP)
544 			dst->set |= BIT(NL80211_STA_FLAG_MFP);
545 	}
546 
547 	if (mask & QLINK_STA_FLAG_AUTHENTICATED) {
548 		dst->mask |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
549 		if (value & QLINK_STA_FLAG_AUTHENTICATED)
550 			dst->set |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
551 	}
552 
553 	if (mask & QLINK_STA_FLAG_TDLS_PEER) {
554 		dst->mask |= BIT(NL80211_STA_FLAG_TDLS_PEER);
555 		if (value & QLINK_STA_FLAG_TDLS_PEER)
556 			dst->set |= BIT(NL80211_STA_FLAG_TDLS_PEER);
557 	}
558 
559 	if (mask & QLINK_STA_FLAG_ASSOCIATED) {
560 		dst->mask |= BIT(NL80211_STA_FLAG_ASSOCIATED);
561 		if (value & QLINK_STA_FLAG_ASSOCIATED)
562 			dst->set |= BIT(NL80211_STA_FLAG_ASSOCIATED);
563 	}
564 }
565 
566 static void
567 qtnf_cmd_sta_info_parse(struct station_info *sinfo,
568 			const struct qlink_tlv_hdr *tlv,
569 			size_t resp_size)
570 {
571 	const struct qlink_sta_stats *stats = NULL;
572 	const u8 *map = NULL;
573 	unsigned int map_len = 0;
574 	unsigned int stats_len = 0;
575 	u16 tlv_len;
576 
577 #define qtnf_sta_stat_avail(stat_name, bitn)	\
578 	(qtnf_utils_is_bit_set(map, bitn, map_len) && \
579 	 (offsetofend(struct qlink_sta_stats, stat_name) <= stats_len))
580 
581 	while (resp_size >= sizeof(*tlv)) {
582 		tlv_len = le16_to_cpu(tlv->len);
583 
584 		switch (le16_to_cpu(tlv->type)) {
585 		case QTN_TLV_ID_STA_STATS_MAP:
586 			map_len = tlv_len;
587 			map = tlv->val;
588 			break;
589 		case QTN_TLV_ID_STA_STATS:
590 			stats_len = tlv_len;
591 			stats = (const struct qlink_sta_stats *)tlv->val;
592 			break;
593 		default:
594 			break;
595 		}
596 
597 		resp_size -= tlv_len + sizeof(*tlv);
598 		tlv = (const struct qlink_tlv_hdr *)(tlv->val + tlv_len);
599 	}
600 
601 	if (!map || !stats)
602 		return;
603 
604 	if (qtnf_sta_stat_avail(inactive_time, QLINK_STA_INFO_INACTIVE_TIME)) {
605 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_INACTIVE_TIME);
606 		sinfo->inactive_time = le32_to_cpu(stats->inactive_time);
607 	}
608 
609 	if (qtnf_sta_stat_avail(connected_time,
610 				QLINK_STA_INFO_CONNECTED_TIME)) {
611 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_CONNECTED_TIME);
612 		sinfo->connected_time = le32_to_cpu(stats->connected_time);
613 	}
614 
615 	if (qtnf_sta_stat_avail(signal, QLINK_STA_INFO_SIGNAL)) {
616 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL);
617 		sinfo->signal = stats->signal - QLINK_RSSI_OFFSET;
618 	}
619 
620 	if (qtnf_sta_stat_avail(signal_avg, QLINK_STA_INFO_SIGNAL_AVG)) {
621 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL_AVG);
622 		sinfo->signal_avg = stats->signal_avg - QLINK_RSSI_OFFSET;
623 	}
624 
625 	if (qtnf_sta_stat_avail(rxrate, QLINK_STA_INFO_RX_BITRATE)) {
626 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BITRATE);
627 		qtnf_sta_info_parse_rate(&sinfo->rxrate, &stats->rxrate);
628 	}
629 
630 	if (qtnf_sta_stat_avail(txrate, QLINK_STA_INFO_TX_BITRATE)) {
631 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BITRATE);
632 		qtnf_sta_info_parse_rate(&sinfo->txrate, &stats->txrate);
633 	}
634 
635 	if (qtnf_sta_stat_avail(sta_flags, QLINK_STA_INFO_STA_FLAGS)) {
636 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_STA_FLAGS);
637 		qtnf_sta_info_parse_flags(&sinfo->sta_flags, &stats->sta_flags);
638 	}
639 
640 	if (qtnf_sta_stat_avail(rx_bytes, QLINK_STA_INFO_RX_BYTES)) {
641 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BYTES);
642 		sinfo->rx_bytes = le64_to_cpu(stats->rx_bytes);
643 	}
644 
645 	if (qtnf_sta_stat_avail(tx_bytes, QLINK_STA_INFO_TX_BYTES)) {
646 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BYTES);
647 		sinfo->tx_bytes = le64_to_cpu(stats->tx_bytes);
648 	}
649 
650 	if (qtnf_sta_stat_avail(rx_bytes, QLINK_STA_INFO_RX_BYTES64)) {
651 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BYTES64);
652 		sinfo->rx_bytes = le64_to_cpu(stats->rx_bytes);
653 	}
654 
655 	if (qtnf_sta_stat_avail(tx_bytes, QLINK_STA_INFO_TX_BYTES64)) {
656 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BYTES64);
657 		sinfo->tx_bytes = le64_to_cpu(stats->tx_bytes);
658 	}
659 
660 	if (qtnf_sta_stat_avail(rx_packets, QLINK_STA_INFO_RX_PACKETS)) {
661 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_PACKETS);
662 		sinfo->rx_packets = le32_to_cpu(stats->rx_packets);
663 	}
664 
665 	if (qtnf_sta_stat_avail(tx_packets, QLINK_STA_INFO_TX_PACKETS)) {
666 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_PACKETS);
667 		sinfo->tx_packets = le32_to_cpu(stats->tx_packets);
668 	}
669 
670 	if (qtnf_sta_stat_avail(rx_beacon, QLINK_STA_INFO_BEACON_RX)) {
671 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_BEACON_RX);
672 		sinfo->rx_beacon = le64_to_cpu(stats->rx_beacon);
673 	}
674 
675 	if (qtnf_sta_stat_avail(rx_dropped_misc, QLINK_STA_INFO_RX_DROP_MISC)) {
676 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_DROP_MISC);
677 		sinfo->rx_dropped_misc = le32_to_cpu(stats->rx_dropped_misc);
678 	}
679 
680 	if (qtnf_sta_stat_avail(tx_failed, QLINK_STA_INFO_TX_FAILED)) {
681 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_FAILED);
682 		sinfo->tx_failed = le32_to_cpu(stats->tx_failed);
683 	}
684 
685 #undef qtnf_sta_stat_avail
686 }
687 
688 int qtnf_cmd_get_sta_info(struct qtnf_vif *vif, const u8 *sta_mac,
689 			  struct station_info *sinfo)
690 {
691 	struct sk_buff *cmd_skb, *resp_skb = NULL;
692 	struct qlink_cmd_get_sta_info *cmd;
693 	const struct qlink_resp_get_sta_info *resp;
694 	size_t var_resp_len = 0;
695 	int ret = 0;
696 
697 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
698 					    QLINK_CMD_GET_STA_INFO,
699 					    sizeof(*cmd));
700 	if (!cmd_skb)
701 		return -ENOMEM;
702 
703 	qtnf_bus_lock(vif->mac->bus);
704 
705 	cmd = (struct qlink_cmd_get_sta_info *)cmd_skb->data;
706 	ether_addr_copy(cmd->sta_addr, sta_mac);
707 
708 	ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
709 				       sizeof(*resp), &var_resp_len);
710 	if (ret)
711 		goto out;
712 
713 	resp = (const struct qlink_resp_get_sta_info *)resp_skb->data;
714 
715 	if (!ether_addr_equal(sta_mac, resp->sta_addr)) {
716 		pr_err("VIF%u.%u: wrong mac in reply: %pM != %pM\n",
717 		       vif->mac->macid, vif->vifid, resp->sta_addr, sta_mac);
718 		ret = -EINVAL;
719 		goto out;
720 	}
721 
722 	qtnf_cmd_sta_info_parse(sinfo,
723 				(const struct qlink_tlv_hdr *)resp->info,
724 				var_resp_len);
725 
726 out:
727 	qtnf_bus_unlock(vif->mac->bus);
728 	consume_skb(resp_skb);
729 
730 	return ret;
731 }
732 
733 static int qtnf_cmd_send_add_change_intf(struct qtnf_vif *vif,
734 					 enum nl80211_iftype iftype,
735 					 u8 *mac_addr,
736 					 enum qlink_cmd_type cmd_type)
737 {
738 	struct sk_buff *cmd_skb, *resp_skb = NULL;
739 	struct qlink_cmd_manage_intf *cmd;
740 	const struct qlink_resp_manage_intf *resp;
741 	int ret = 0;
742 
743 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
744 					    cmd_type,
745 					    sizeof(*cmd));
746 	if (!cmd_skb)
747 		return -ENOMEM;
748 
749 	qtnf_bus_lock(vif->mac->bus);
750 
751 	cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
752 
753 	switch (iftype) {
754 	case NL80211_IFTYPE_AP:
755 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
756 		break;
757 	case NL80211_IFTYPE_STATION:
758 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
759 		break;
760 	default:
761 		pr_err("VIF%u.%u: unsupported type %d\n", vif->mac->macid,
762 		       vif->vifid, iftype);
763 		ret = -EINVAL;
764 		goto out;
765 	}
766 
767 	if (mac_addr)
768 		ether_addr_copy(cmd->intf_info.mac_addr, mac_addr);
769 	else
770 		eth_zero_addr(cmd->intf_info.mac_addr);
771 
772 	ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
773 				       sizeof(*resp), NULL);
774 	if (ret)
775 		goto out;
776 
777 	resp = (const struct qlink_resp_manage_intf *)resp_skb->data;
778 	ether_addr_copy(vif->mac_addr, resp->intf_info.mac_addr);
779 
780 out:
781 	qtnf_bus_unlock(vif->mac->bus);
782 	consume_skb(resp_skb);
783 
784 	return ret;
785 }
786 
787 int qtnf_cmd_send_add_intf(struct qtnf_vif *vif,
788 			   enum nl80211_iftype iftype, u8 *mac_addr)
789 {
790 	return qtnf_cmd_send_add_change_intf(vif, iftype, mac_addr,
791 			QLINK_CMD_ADD_INTF);
792 }
793 
794 int qtnf_cmd_send_change_intf_type(struct qtnf_vif *vif,
795 				   enum nl80211_iftype iftype, u8 *mac_addr)
796 {
797 	return qtnf_cmd_send_add_change_intf(vif, iftype, mac_addr,
798 					     QLINK_CMD_CHANGE_INTF);
799 }
800 
801 int qtnf_cmd_send_del_intf(struct qtnf_vif *vif)
802 {
803 	struct sk_buff *cmd_skb;
804 	struct qlink_cmd_manage_intf *cmd;
805 	int ret = 0;
806 
807 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
808 					    QLINK_CMD_DEL_INTF,
809 					    sizeof(*cmd));
810 	if (!cmd_skb)
811 		return -ENOMEM;
812 
813 	qtnf_bus_lock(vif->mac->bus);
814 
815 	cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
816 
817 	switch (vif->wdev.iftype) {
818 	case NL80211_IFTYPE_AP:
819 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
820 		break;
821 	case NL80211_IFTYPE_STATION:
822 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
823 		break;
824 	default:
825 		pr_warn("VIF%u.%u: unsupported iftype %d\n", vif->mac->macid,
826 			vif->vifid, vif->wdev.iftype);
827 		ret = -EINVAL;
828 		goto out;
829 	}
830 
831 	eth_zero_addr(cmd->intf_info.mac_addr);
832 
833 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
834 	if (ret)
835 		goto out;
836 
837 out:
838 	qtnf_bus_unlock(vif->mac->bus);
839 	return ret;
840 }
841 
842 static u32 qtnf_cmd_resp_reg_rule_flags_parse(u32 qflags)
843 {
844 	u32 flags = 0;
845 
846 	if (qflags & QLINK_RRF_NO_OFDM)
847 		flags |= NL80211_RRF_NO_OFDM;
848 
849 	if (qflags & QLINK_RRF_NO_CCK)
850 		flags |= NL80211_RRF_NO_CCK;
851 
852 	if (qflags & QLINK_RRF_NO_INDOOR)
853 		flags |= NL80211_RRF_NO_INDOOR;
854 
855 	if (qflags & QLINK_RRF_NO_OUTDOOR)
856 		flags |= NL80211_RRF_NO_OUTDOOR;
857 
858 	if (qflags & QLINK_RRF_DFS)
859 		flags |= NL80211_RRF_DFS;
860 
861 	if (qflags & QLINK_RRF_PTP_ONLY)
862 		flags |= NL80211_RRF_PTP_ONLY;
863 
864 	if (qflags & QLINK_RRF_PTMP_ONLY)
865 		flags |= NL80211_RRF_PTMP_ONLY;
866 
867 	if (qflags & QLINK_RRF_NO_IR)
868 		flags |= NL80211_RRF_NO_IR;
869 
870 	if (qflags & QLINK_RRF_AUTO_BW)
871 		flags |= NL80211_RRF_AUTO_BW;
872 
873 	if (qflags & QLINK_RRF_IR_CONCURRENT)
874 		flags |= NL80211_RRF_IR_CONCURRENT;
875 
876 	if (qflags & QLINK_RRF_NO_HT40MINUS)
877 		flags |= NL80211_RRF_NO_HT40MINUS;
878 
879 	if (qflags & QLINK_RRF_NO_HT40PLUS)
880 		flags |= NL80211_RRF_NO_HT40PLUS;
881 
882 	if (qflags & QLINK_RRF_NO_80MHZ)
883 		flags |= NL80211_RRF_NO_80MHZ;
884 
885 	if (qflags & QLINK_RRF_NO_160MHZ)
886 		flags |= NL80211_RRF_NO_160MHZ;
887 
888 	return flags;
889 }
890 
891 static int
892 qtnf_cmd_resp_proc_hw_info(struct qtnf_bus *bus,
893 			   const struct qlink_resp_get_hw_info *resp,
894 			   size_t info_len)
895 {
896 	struct qtnf_hw_info *hwinfo = &bus->hw_info;
897 	const struct qlink_tlv_hdr *tlv;
898 	const struct qlink_tlv_reg_rule *tlv_rule;
899 	const char *bld_name = NULL;
900 	const char *bld_rev = NULL;
901 	const char *bld_type = NULL;
902 	const char *bld_label = NULL;
903 	u32 bld_tmstamp = 0;
904 	u32 plat_id = 0;
905 	const char *hw_id = NULL;
906 	const char *calibration_ver = NULL;
907 	const char *uboot_ver = NULL;
908 	u32 hw_ver = 0;
909 	struct ieee80211_reg_rule *rule;
910 	u16 tlv_type;
911 	u16 tlv_value_len;
912 	unsigned int rule_idx = 0;
913 
914 	if (WARN_ON(resp->n_reg_rules > NL80211_MAX_SUPP_REG_RULES))
915 		return -E2BIG;
916 
917 	hwinfo->rd = kzalloc(sizeof(*hwinfo->rd)
918 			     + sizeof(struct ieee80211_reg_rule)
919 			     * resp->n_reg_rules, GFP_KERNEL);
920 
921 	if (!hwinfo->rd)
922 		return -ENOMEM;
923 
924 	hwinfo->num_mac = resp->num_mac;
925 	hwinfo->mac_bitmap = resp->mac_bitmap;
926 	hwinfo->fw_ver = le32_to_cpu(resp->fw_ver);
927 	hwinfo->ql_proto_ver = le16_to_cpu(resp->ql_proto_ver);
928 	hwinfo->total_tx_chain = resp->total_tx_chain;
929 	hwinfo->total_rx_chain = resp->total_rx_chain;
930 	hwinfo->hw_capab = le32_to_cpu(resp->hw_capab);
931 	hwinfo->rd->n_reg_rules = resp->n_reg_rules;
932 	hwinfo->rd->alpha2[0] = resp->alpha2[0];
933 	hwinfo->rd->alpha2[1] = resp->alpha2[1];
934 
935 	bld_tmstamp = le32_to_cpu(resp->bld_tmstamp);
936 	plat_id = le32_to_cpu(resp->plat_id);
937 	hw_ver = le32_to_cpu(resp->hw_ver);
938 
939 	switch (resp->dfs_region) {
940 	case QLINK_DFS_FCC:
941 		hwinfo->rd->dfs_region = NL80211_DFS_FCC;
942 		break;
943 	case QLINK_DFS_ETSI:
944 		hwinfo->rd->dfs_region = NL80211_DFS_ETSI;
945 		break;
946 	case QLINK_DFS_JP:
947 		hwinfo->rd->dfs_region = NL80211_DFS_JP;
948 		break;
949 	case QLINK_DFS_UNSET:
950 	default:
951 		hwinfo->rd->dfs_region = NL80211_DFS_UNSET;
952 		break;
953 	}
954 
955 	tlv = (const struct qlink_tlv_hdr *)resp->info;
956 
957 	while (info_len >= sizeof(*tlv)) {
958 		tlv_type = le16_to_cpu(tlv->type);
959 		tlv_value_len = le16_to_cpu(tlv->len);
960 
961 		if (tlv_value_len + sizeof(*tlv) > info_len) {
962 			pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
963 				tlv_type, tlv_value_len);
964 			return -EINVAL;
965 		}
966 
967 		switch (tlv_type) {
968 		case QTN_TLV_ID_REG_RULE:
969 			if (rule_idx >= resp->n_reg_rules) {
970 				pr_warn("unexpected number of rules: %u\n",
971 					resp->n_reg_rules);
972 				return -EINVAL;
973 			}
974 
975 			if (tlv_value_len != sizeof(*tlv_rule) - sizeof(*tlv)) {
976 				pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
977 					tlv_type, tlv_value_len);
978 				return -EINVAL;
979 			}
980 
981 			tlv_rule = (const struct qlink_tlv_reg_rule *)tlv;
982 			rule = &hwinfo->rd->reg_rules[rule_idx++];
983 
984 			rule->freq_range.start_freq_khz =
985 				le32_to_cpu(tlv_rule->start_freq_khz);
986 			rule->freq_range.end_freq_khz =
987 				le32_to_cpu(tlv_rule->end_freq_khz);
988 			rule->freq_range.max_bandwidth_khz =
989 				le32_to_cpu(tlv_rule->max_bandwidth_khz);
990 			rule->power_rule.max_antenna_gain =
991 				le32_to_cpu(tlv_rule->max_antenna_gain);
992 			rule->power_rule.max_eirp =
993 				le32_to_cpu(tlv_rule->max_eirp);
994 			rule->dfs_cac_ms =
995 				le32_to_cpu(tlv_rule->dfs_cac_ms);
996 			rule->flags = qtnf_cmd_resp_reg_rule_flags_parse(
997 					le32_to_cpu(tlv_rule->flags));
998 			break;
999 		case QTN_TLV_ID_BUILD_NAME:
1000 			bld_name = (const void *)tlv->val;
1001 			break;
1002 		case QTN_TLV_ID_BUILD_REV:
1003 			bld_rev = (const void *)tlv->val;
1004 			break;
1005 		case QTN_TLV_ID_BUILD_TYPE:
1006 			bld_type = (const void *)tlv->val;
1007 			break;
1008 		case QTN_TLV_ID_BUILD_LABEL:
1009 			bld_label = (const void *)tlv->val;
1010 			break;
1011 		case QTN_TLV_ID_HW_ID:
1012 			hw_id = (const void *)tlv->val;
1013 			break;
1014 		case QTN_TLV_ID_CALIBRATION_VER:
1015 			calibration_ver = (const void *)tlv->val;
1016 			break;
1017 		case QTN_TLV_ID_UBOOT_VER:
1018 			uboot_ver = (const void *)tlv->val;
1019 			break;
1020 		case QTN_TLV_ID_MAX_SCAN_SSIDS:
1021 			hwinfo->max_scan_ssids = *tlv->val;
1022 			break;
1023 		default:
1024 			break;
1025 		}
1026 
1027 		info_len -= tlv_value_len + sizeof(*tlv);
1028 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1029 	}
1030 
1031 	if (rule_idx != resp->n_reg_rules) {
1032 		pr_warn("unexpected number of rules: expected %u got %u\n",
1033 			resp->n_reg_rules, rule_idx);
1034 		kfree(hwinfo->rd);
1035 		hwinfo->rd = NULL;
1036 		return -EINVAL;
1037 	}
1038 
1039 	pr_info("fw_version=%d, MACs map %#x, alpha2=\"%c%c\", chains Tx=%u Rx=%u, capab=0x%x\n",
1040 		hwinfo->fw_ver, hwinfo->mac_bitmap,
1041 		hwinfo->rd->alpha2[0], hwinfo->rd->alpha2[1],
1042 		hwinfo->total_tx_chain, hwinfo->total_rx_chain,
1043 		hwinfo->hw_capab);
1044 
1045 	pr_info("\nBuild name:            %s"  \
1046 		"\nBuild revision:        %s"  \
1047 		"\nBuild type:            %s"  \
1048 		"\nBuild label:           %s"  \
1049 		"\nBuild timestamp:       %lu" \
1050 		"\nPlatform ID:           %lu" \
1051 		"\nHardware ID:           %s"  \
1052 		"\nCalibration version:   %s"  \
1053 		"\nU-Boot version:        %s"  \
1054 		"\nHardware version:      0x%08x",
1055 		bld_name, bld_rev, bld_type, bld_label,
1056 		(unsigned long)bld_tmstamp,
1057 		(unsigned long)plat_id,
1058 		hw_id, calibration_ver, uboot_ver, hw_ver);
1059 
1060 	strlcpy(hwinfo->fw_version, bld_label, sizeof(hwinfo->fw_version));
1061 	hwinfo->hw_version = hw_ver;
1062 
1063 	return 0;
1064 }
1065 
1066 static void
1067 qtnf_parse_wowlan_info(struct qtnf_wmac *mac,
1068 		       const struct qlink_wowlan_capab_data *wowlan)
1069 {
1070 	struct qtnf_mac_info *mac_info = &mac->macinfo;
1071 	const struct qlink_wowlan_support *data1;
1072 	struct wiphy_wowlan_support *supp;
1073 
1074 	supp = kzalloc(sizeof(*supp), GFP_KERNEL);
1075 	if (!supp)
1076 		return;
1077 
1078 	switch (le16_to_cpu(wowlan->version)) {
1079 	case 0x1:
1080 		data1 = (struct qlink_wowlan_support *)wowlan->data;
1081 
1082 		supp->flags = WIPHY_WOWLAN_MAGIC_PKT | WIPHY_WOWLAN_DISCONNECT;
1083 		supp->n_patterns = le32_to_cpu(data1->n_patterns);
1084 		supp->pattern_max_len = le32_to_cpu(data1->pattern_max_len);
1085 		supp->pattern_min_len = le32_to_cpu(data1->pattern_min_len);
1086 
1087 		mac_info->wowlan = supp;
1088 		break;
1089 	default:
1090 		pr_warn("MAC%u: unsupported WoWLAN version 0x%x\n",
1091 			mac->macid, le16_to_cpu(wowlan->version));
1092 		kfree(supp);
1093 		break;
1094 	}
1095 }
1096 
1097 static int qtnf_parse_variable_mac_info(struct qtnf_wmac *mac,
1098 					const u8 *tlv_buf, size_t tlv_buf_size)
1099 {
1100 	struct ieee80211_iface_combination *comb = NULL;
1101 	size_t n_comb = 0;
1102 	struct ieee80211_iface_limit *limits;
1103 	const struct qlink_iface_comb_num *comb_num;
1104 	const struct qlink_iface_limit_record *rec;
1105 	const struct qlink_iface_limit *lim;
1106 	const struct qlink_wowlan_capab_data *wowlan;
1107 	u16 rec_len;
1108 	u16 tlv_type;
1109 	u16 tlv_value_len;
1110 	size_t tlv_full_len;
1111 	const struct qlink_tlv_hdr *tlv;
1112 	u8 *ext_capa = NULL;
1113 	u8 *ext_capa_mask = NULL;
1114 	u8 ext_capa_len = 0;
1115 	u8 ext_capa_mask_len = 0;
1116 	int i = 0;
1117 
1118 	tlv = (const struct qlink_tlv_hdr *)tlv_buf;
1119 	while (tlv_buf_size >= sizeof(struct qlink_tlv_hdr)) {
1120 		tlv_type = le16_to_cpu(tlv->type);
1121 		tlv_value_len = le16_to_cpu(tlv->len);
1122 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1123 		if (tlv_full_len > tlv_buf_size) {
1124 			pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1125 				mac->macid, tlv_type, tlv_value_len);
1126 			return -EINVAL;
1127 		}
1128 
1129 		switch (tlv_type) {
1130 		case QTN_TLV_ID_NUM_IFACE_COMB:
1131 			if (tlv_value_len != sizeof(*comb_num))
1132 				return -EINVAL;
1133 
1134 			comb_num = (void *)tlv->val;
1135 
1136 			/* free earlier iface comb memory */
1137 			qtnf_mac_iface_comb_free(mac);
1138 
1139 			mac->macinfo.n_if_comb =
1140 				le32_to_cpu(comb_num->iface_comb_num);
1141 
1142 			mac->macinfo.if_comb =
1143 				kcalloc(mac->macinfo.n_if_comb,
1144 					sizeof(*mac->macinfo.if_comb),
1145 					GFP_KERNEL);
1146 
1147 			if (!mac->macinfo.if_comb)
1148 				return -ENOMEM;
1149 
1150 			comb = mac->macinfo.if_comb;
1151 
1152 			pr_debug("MAC%u: %zu iface combinations\n",
1153 				 mac->macid, mac->macinfo.n_if_comb);
1154 
1155 			break;
1156 		case QTN_TLV_ID_IFACE_LIMIT:
1157 			if (unlikely(!comb)) {
1158 				pr_warn("MAC%u: no combinations advertised\n",
1159 					mac->macid);
1160 				return -EINVAL;
1161 			}
1162 
1163 			if (n_comb >= mac->macinfo.n_if_comb) {
1164 				pr_warn("MAC%u: combinations count exceeded\n",
1165 					mac->macid);
1166 				n_comb++;
1167 				break;
1168 			}
1169 
1170 			rec = (void *)tlv->val;
1171 			rec_len = sizeof(*rec) + rec->n_limits * sizeof(*lim);
1172 
1173 			if (unlikely(tlv_value_len != rec_len)) {
1174 				pr_warn("MAC%u: record %zu size mismatch\n",
1175 					mac->macid, n_comb);
1176 				return -EINVAL;
1177 			}
1178 
1179 			limits = kcalloc(rec->n_limits, sizeof(*limits),
1180 					 GFP_KERNEL);
1181 			if (!limits)
1182 				return -ENOMEM;
1183 
1184 			comb[n_comb].num_different_channels =
1185 				rec->num_different_channels;
1186 			comb[n_comb].max_interfaces =
1187 				le16_to_cpu(rec->max_interfaces);
1188 			comb[n_comb].n_limits = rec->n_limits;
1189 			comb[n_comb].limits = limits;
1190 
1191 			for (i = 0; i < rec->n_limits; i++) {
1192 				lim = &rec->limits[i];
1193 				limits[i].max = le16_to_cpu(lim->max_num);
1194 				limits[i].types =
1195 					qlink_iface_type_to_nl_mask(le16_to_cpu(lim->type));
1196 				pr_debug("MAC%u: comb[%zu]: MAX:%u TYPES:%.4X\n",
1197 					 mac->macid, n_comb,
1198 					 limits[i].max, limits[i].types);
1199 			}
1200 
1201 			n_comb++;
1202 			break;
1203 		case WLAN_EID_EXT_CAPABILITY:
1204 			if (unlikely(tlv_value_len > U8_MAX))
1205 				return -EINVAL;
1206 			ext_capa = (u8 *)tlv->val;
1207 			ext_capa_len = tlv_value_len;
1208 			break;
1209 		case QTN_TLV_ID_EXT_CAPABILITY_MASK:
1210 			if (unlikely(tlv_value_len > U8_MAX))
1211 				return -EINVAL;
1212 			ext_capa_mask = (u8 *)tlv->val;
1213 			ext_capa_mask_len = tlv_value_len;
1214 			break;
1215 		case QTN_TLV_ID_WOWLAN_CAPAB:
1216 			if (tlv_value_len < sizeof(*wowlan))
1217 				return -EINVAL;
1218 
1219 			wowlan = (void *)tlv->val;
1220 			if (!le16_to_cpu(wowlan->len)) {
1221 				pr_warn("MAC%u: skip empty WoWLAN data\n",
1222 					mac->macid);
1223 				break;
1224 			}
1225 
1226 			rec_len = sizeof(*wowlan) + le16_to_cpu(wowlan->len);
1227 			if (unlikely(tlv_value_len != rec_len)) {
1228 				pr_warn("MAC%u: WoWLAN data size mismatch\n",
1229 					mac->macid);
1230 				return -EINVAL;
1231 			}
1232 
1233 			kfree(mac->macinfo.wowlan);
1234 			mac->macinfo.wowlan = NULL;
1235 			qtnf_parse_wowlan_info(mac, wowlan);
1236 			break;
1237 		default:
1238 			pr_warn("MAC%u: unknown TLV type %u\n",
1239 				mac->macid, tlv_type);
1240 			break;
1241 		}
1242 
1243 		tlv_buf_size -= tlv_full_len;
1244 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1245 	}
1246 
1247 	if (tlv_buf_size) {
1248 		pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1249 			mac->macid, tlv_buf_size);
1250 		return -EINVAL;
1251 	}
1252 
1253 	if (mac->macinfo.n_if_comb != n_comb) {
1254 		pr_err("MAC%u: combination mismatch: reported=%zu parsed=%zu\n",
1255 		       mac->macid, mac->macinfo.n_if_comb, n_comb);
1256 		return -EINVAL;
1257 	}
1258 
1259 	if (ext_capa_len != ext_capa_mask_len) {
1260 		pr_err("MAC%u: ext_capa/_mask lengths mismatch: %u != %u\n",
1261 		       mac->macid, ext_capa_len, ext_capa_mask_len);
1262 		return -EINVAL;
1263 	}
1264 
1265 	if (ext_capa_len > 0) {
1266 		ext_capa = kmemdup(ext_capa, ext_capa_len, GFP_KERNEL);
1267 		if (!ext_capa)
1268 			return -ENOMEM;
1269 
1270 		ext_capa_mask =
1271 			kmemdup(ext_capa_mask, ext_capa_mask_len, GFP_KERNEL);
1272 		if (!ext_capa_mask) {
1273 			kfree(ext_capa);
1274 			return -ENOMEM;
1275 		}
1276 	} else {
1277 		ext_capa = NULL;
1278 		ext_capa_mask = NULL;
1279 	}
1280 
1281 	qtnf_mac_ext_caps_free(mac);
1282 	mac->macinfo.extended_capabilities = ext_capa;
1283 	mac->macinfo.extended_capabilities_mask = ext_capa_mask;
1284 	mac->macinfo.extended_capabilities_len = ext_capa_len;
1285 
1286 	return 0;
1287 }
1288 
1289 static void
1290 qtnf_cmd_resp_proc_mac_info(struct qtnf_wmac *mac,
1291 			    const struct qlink_resp_get_mac_info *resp_info)
1292 {
1293 	struct qtnf_mac_info *mac_info;
1294 	struct qtnf_vif *vif;
1295 
1296 	mac_info = &mac->macinfo;
1297 
1298 	mac_info->bands_cap = resp_info->bands_cap;
1299 	memcpy(&mac_info->dev_mac, &resp_info->dev_mac,
1300 	       sizeof(mac_info->dev_mac));
1301 
1302 	ether_addr_copy(mac->macaddr, mac_info->dev_mac);
1303 
1304 	vif = qtnf_mac_get_base_vif(mac);
1305 	if (vif)
1306 		ether_addr_copy(vif->mac_addr, mac->macaddr);
1307 	else
1308 		pr_err("could not get valid base vif\n");
1309 
1310 	mac_info->num_tx_chain = resp_info->num_tx_chain;
1311 	mac_info->num_rx_chain = resp_info->num_rx_chain;
1312 
1313 	mac_info->max_ap_assoc_sta = le16_to_cpu(resp_info->max_ap_assoc_sta);
1314 	mac_info->radar_detect_widths =
1315 			qlink_chan_width_mask_to_nl(le16_to_cpu(
1316 					resp_info->radar_detect_widths));
1317 	mac_info->max_acl_mac_addrs = le32_to_cpu(resp_info->max_acl_mac_addrs);
1318 
1319 	memcpy(&mac_info->ht_cap_mod_mask, &resp_info->ht_cap_mod_mask,
1320 	       sizeof(mac_info->ht_cap_mod_mask));
1321 	memcpy(&mac_info->vht_cap_mod_mask, &resp_info->vht_cap_mod_mask,
1322 	       sizeof(mac_info->vht_cap_mod_mask));
1323 }
1324 
1325 static void qtnf_cmd_resp_band_fill_htcap(const u8 *info,
1326 					  struct ieee80211_sta_ht_cap *bcap)
1327 {
1328 	const struct ieee80211_ht_cap *ht_cap =
1329 		(const struct ieee80211_ht_cap *)info;
1330 
1331 	bcap->ht_supported = true;
1332 	bcap->cap = le16_to_cpu(ht_cap->cap_info);
1333 	bcap->ampdu_factor =
1334 		ht_cap->ampdu_params_info & IEEE80211_HT_AMPDU_PARM_FACTOR;
1335 	bcap->ampdu_density =
1336 		(ht_cap->ampdu_params_info & IEEE80211_HT_AMPDU_PARM_DENSITY) >>
1337 		IEEE80211_HT_AMPDU_PARM_DENSITY_SHIFT;
1338 	memcpy(&bcap->mcs, &ht_cap->mcs, sizeof(bcap->mcs));
1339 }
1340 
1341 static void qtnf_cmd_resp_band_fill_vhtcap(const u8 *info,
1342 					   struct ieee80211_sta_vht_cap *bcap)
1343 {
1344 	const struct ieee80211_vht_cap *vht_cap =
1345 		(const struct ieee80211_vht_cap *)info;
1346 
1347 	bcap->vht_supported = true;
1348 	bcap->cap = le32_to_cpu(vht_cap->vht_cap_info);
1349 	memcpy(&bcap->vht_mcs, &vht_cap->supp_mcs, sizeof(bcap->vht_mcs));
1350 }
1351 
1352 static int
1353 qtnf_cmd_resp_fill_band_info(struct ieee80211_supported_band *band,
1354 			     struct qlink_resp_band_info_get *resp,
1355 			     size_t payload_len)
1356 {
1357 	u16 tlv_type;
1358 	size_t tlv_len;
1359 	size_t tlv_dlen;
1360 	const struct qlink_tlv_hdr *tlv;
1361 	const struct qlink_channel *qchan;
1362 	struct ieee80211_channel *chan;
1363 	unsigned int chidx = 0;
1364 	u32 qflags;
1365 
1366 	memset(&band->ht_cap, 0, sizeof(band->ht_cap));
1367 	memset(&band->vht_cap, 0, sizeof(band->vht_cap));
1368 
1369 	if (band->channels) {
1370 		if (band->n_channels == resp->num_chans) {
1371 			memset(band->channels, 0,
1372 			       sizeof(*band->channels) * band->n_channels);
1373 		} else {
1374 			kfree(band->channels);
1375 			band->n_channels = 0;
1376 			band->channels = NULL;
1377 		}
1378 	}
1379 
1380 	band->n_channels = resp->num_chans;
1381 	if (band->n_channels == 0)
1382 		return 0;
1383 
1384 	if (!band->channels)
1385 		band->channels = kcalloc(band->n_channels, sizeof(*chan),
1386 					 GFP_KERNEL);
1387 	if (!band->channels) {
1388 		band->n_channels = 0;
1389 		return -ENOMEM;
1390 	}
1391 
1392 	tlv = (struct qlink_tlv_hdr *)resp->info;
1393 
1394 	while (payload_len >= sizeof(*tlv)) {
1395 		tlv_type = le16_to_cpu(tlv->type);
1396 		tlv_dlen = le16_to_cpu(tlv->len);
1397 		tlv_len = tlv_dlen + sizeof(*tlv);
1398 
1399 		if (tlv_len > payload_len) {
1400 			pr_warn("malformed TLV 0x%.2X; LEN: %zu\n",
1401 				tlv_type, tlv_len);
1402 			goto error_ret;
1403 		}
1404 
1405 		switch (tlv_type) {
1406 		case QTN_TLV_ID_CHANNEL:
1407 			if (unlikely(tlv_dlen != sizeof(*qchan))) {
1408 				pr_err("invalid channel TLV len %zu\n",
1409 				       tlv_len);
1410 				goto error_ret;
1411 			}
1412 
1413 			if (chidx == band->n_channels) {
1414 				pr_err("too many channel TLVs\n");
1415 				goto error_ret;
1416 			}
1417 
1418 			qchan = (const struct qlink_channel *)tlv->val;
1419 			chan = &band->channels[chidx++];
1420 			qflags = le32_to_cpu(qchan->flags);
1421 
1422 			chan->hw_value = le16_to_cpu(qchan->hw_value);
1423 			chan->band = band->band;
1424 			chan->center_freq = le16_to_cpu(qchan->center_freq);
1425 			chan->max_antenna_gain = (int)qchan->max_antenna_gain;
1426 			chan->max_power = (int)qchan->max_power;
1427 			chan->max_reg_power = (int)qchan->max_reg_power;
1428 			chan->beacon_found = qchan->beacon_found;
1429 			chan->dfs_cac_ms = le32_to_cpu(qchan->dfs_cac_ms);
1430 			chan->flags = 0;
1431 
1432 			if (qflags & QLINK_CHAN_DISABLED)
1433 				chan->flags |= IEEE80211_CHAN_DISABLED;
1434 
1435 			if (qflags & QLINK_CHAN_NO_IR)
1436 				chan->flags |= IEEE80211_CHAN_NO_IR;
1437 
1438 			if (qflags & QLINK_CHAN_NO_HT40PLUS)
1439 				chan->flags |= IEEE80211_CHAN_NO_HT40PLUS;
1440 
1441 			if (qflags & QLINK_CHAN_NO_HT40MINUS)
1442 				chan->flags |= IEEE80211_CHAN_NO_HT40MINUS;
1443 
1444 			if (qflags & QLINK_CHAN_NO_OFDM)
1445 				chan->flags |= IEEE80211_CHAN_NO_OFDM;
1446 
1447 			if (qflags & QLINK_CHAN_NO_80MHZ)
1448 				chan->flags |= IEEE80211_CHAN_NO_80MHZ;
1449 
1450 			if (qflags & QLINK_CHAN_NO_160MHZ)
1451 				chan->flags |= IEEE80211_CHAN_NO_160MHZ;
1452 
1453 			if (qflags & QLINK_CHAN_INDOOR_ONLY)
1454 				chan->flags |= IEEE80211_CHAN_INDOOR_ONLY;
1455 
1456 			if (qflags & QLINK_CHAN_IR_CONCURRENT)
1457 				chan->flags |= IEEE80211_CHAN_IR_CONCURRENT;
1458 
1459 			if (qflags & QLINK_CHAN_NO_20MHZ)
1460 				chan->flags |= IEEE80211_CHAN_NO_20MHZ;
1461 
1462 			if (qflags & QLINK_CHAN_NO_10MHZ)
1463 				chan->flags |= IEEE80211_CHAN_NO_10MHZ;
1464 
1465 			if (qflags & QLINK_CHAN_RADAR) {
1466 				chan->flags |= IEEE80211_CHAN_RADAR;
1467 				chan->dfs_state_entered = jiffies;
1468 
1469 				if (qchan->dfs_state == QLINK_DFS_USABLE)
1470 					chan->dfs_state = NL80211_DFS_USABLE;
1471 				else if (qchan->dfs_state ==
1472 					QLINK_DFS_AVAILABLE)
1473 					chan->dfs_state = NL80211_DFS_AVAILABLE;
1474 				else
1475 					chan->dfs_state =
1476 						NL80211_DFS_UNAVAILABLE;
1477 			}
1478 
1479 			pr_debug("chan=%d flags=%#x max_pow=%d max_reg_pow=%d\n",
1480 				 chan->hw_value, chan->flags, chan->max_power,
1481 				 chan->max_reg_power);
1482 			break;
1483 		case WLAN_EID_HT_CAPABILITY:
1484 			if (unlikely(tlv_dlen !=
1485 				     sizeof(struct ieee80211_ht_cap))) {
1486 				pr_err("bad HTCAP TLV len %zu\n", tlv_dlen);
1487 				goto error_ret;
1488 			}
1489 
1490 			qtnf_cmd_resp_band_fill_htcap(tlv->val, &band->ht_cap);
1491 			break;
1492 		case WLAN_EID_VHT_CAPABILITY:
1493 			if (unlikely(tlv_dlen !=
1494 				     sizeof(struct ieee80211_vht_cap))) {
1495 				pr_err("bad VHTCAP TLV len %zu\n", tlv_dlen);
1496 				goto error_ret;
1497 			}
1498 
1499 			qtnf_cmd_resp_band_fill_vhtcap(tlv->val,
1500 						       &band->vht_cap);
1501 			break;
1502 		default:
1503 			pr_warn("unknown TLV type: %#x\n", tlv_type);
1504 			break;
1505 		}
1506 
1507 		payload_len -= tlv_len;
1508 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_dlen);
1509 	}
1510 
1511 	if (payload_len) {
1512 		pr_err("malformed TLV buf; bytes left: %zu\n", payload_len);
1513 		goto error_ret;
1514 	}
1515 
1516 	if (band->n_channels != chidx) {
1517 		pr_err("channel count mismatch: reported=%d, parsed=%d\n",
1518 		       band->n_channels, chidx);
1519 		goto error_ret;
1520 	}
1521 
1522 	return 0;
1523 
1524 error_ret:
1525 	kfree(band->channels);
1526 	band->channels = NULL;
1527 	band->n_channels = 0;
1528 
1529 	return -EINVAL;
1530 }
1531 
1532 static int qtnf_cmd_resp_proc_phy_params(struct qtnf_wmac *mac,
1533 					 const u8 *payload, size_t payload_len)
1534 {
1535 	struct qtnf_mac_info *mac_info;
1536 	struct qlink_tlv_frag_rts_thr *phy_thr;
1537 	struct qlink_tlv_rlimit *limit;
1538 	struct qlink_tlv_cclass *class;
1539 	u16 tlv_type;
1540 	u16 tlv_value_len;
1541 	size_t tlv_full_len;
1542 	const struct qlink_tlv_hdr *tlv;
1543 
1544 	mac_info = &mac->macinfo;
1545 
1546 	tlv = (struct qlink_tlv_hdr *)payload;
1547 	while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1548 		tlv_type = le16_to_cpu(tlv->type);
1549 		tlv_value_len = le16_to_cpu(tlv->len);
1550 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1551 
1552 		if (tlv_full_len > payload_len) {
1553 			pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1554 				mac->macid, tlv_type, tlv_value_len);
1555 			return -EINVAL;
1556 		}
1557 
1558 		switch (tlv_type) {
1559 		case QTN_TLV_ID_FRAG_THRESH:
1560 			phy_thr = (void *)tlv;
1561 			mac_info->frag_thr = (u32)le16_to_cpu(phy_thr->thr);
1562 			break;
1563 		case QTN_TLV_ID_RTS_THRESH:
1564 			phy_thr = (void *)tlv;
1565 			mac_info->rts_thr = (u32)le16_to_cpu(phy_thr->thr);
1566 			break;
1567 		case QTN_TLV_ID_SRETRY_LIMIT:
1568 			limit = (void *)tlv;
1569 			mac_info->sretry_limit = limit->rlimit;
1570 			break;
1571 		case QTN_TLV_ID_LRETRY_LIMIT:
1572 			limit = (void *)tlv;
1573 			mac_info->lretry_limit = limit->rlimit;
1574 			break;
1575 		case QTN_TLV_ID_COVERAGE_CLASS:
1576 			class = (void *)tlv;
1577 			mac_info->coverage_class = class->cclass;
1578 			break;
1579 		default:
1580 			pr_err("MAC%u: Unknown TLV type: %#x\n", mac->macid,
1581 			       le16_to_cpu(tlv->type));
1582 			break;
1583 		}
1584 
1585 		payload_len -= tlv_full_len;
1586 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1587 	}
1588 
1589 	if (payload_len) {
1590 		pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1591 			mac->macid, payload_len);
1592 		return -EINVAL;
1593 	}
1594 
1595 	return 0;
1596 }
1597 
1598 static int
1599 qtnf_cmd_resp_proc_chan_stat_info(struct qtnf_chan_stats *stats,
1600 				  const u8 *payload, size_t payload_len)
1601 {
1602 	struct qlink_chan_stats *qlink_stats;
1603 	const struct qlink_tlv_hdr *tlv;
1604 	size_t tlv_full_len;
1605 	u16 tlv_value_len;
1606 	u16 tlv_type;
1607 
1608 	tlv = (struct qlink_tlv_hdr *)payload;
1609 	while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1610 		tlv_type = le16_to_cpu(tlv->type);
1611 		tlv_value_len = le16_to_cpu(tlv->len);
1612 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1613 		if (tlv_full_len > payload_len) {
1614 			pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
1615 				tlv_type, tlv_value_len);
1616 			return -EINVAL;
1617 		}
1618 		switch (tlv_type) {
1619 		case QTN_TLV_ID_CHANNEL_STATS:
1620 			if (unlikely(tlv_value_len != sizeof(*qlink_stats))) {
1621 				pr_err("invalid CHANNEL_STATS entry size\n");
1622 				return -EINVAL;
1623 			}
1624 
1625 			qlink_stats = (void *)tlv->val;
1626 
1627 			stats->chan_num = le32_to_cpu(qlink_stats->chan_num);
1628 			stats->cca_tx = le32_to_cpu(qlink_stats->cca_tx);
1629 			stats->cca_rx = le32_to_cpu(qlink_stats->cca_rx);
1630 			stats->cca_busy = le32_to_cpu(qlink_stats->cca_busy);
1631 			stats->cca_try = le32_to_cpu(qlink_stats->cca_try);
1632 			stats->chan_noise = qlink_stats->chan_noise;
1633 
1634 			pr_debug("chan(%u) try(%u) busy(%u) noise(%d)\n",
1635 				 stats->chan_num, stats->cca_try,
1636 				 stats->cca_busy, stats->chan_noise);
1637 			break;
1638 		default:
1639 			pr_warn("Unknown TLV type: %#x\n",
1640 				le16_to_cpu(tlv->type));
1641 		}
1642 		payload_len -= tlv_full_len;
1643 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1644 	}
1645 
1646 	if (payload_len) {
1647 		pr_warn("malformed TLV buf; bytes left: %zu\n", payload_len);
1648 		return -EINVAL;
1649 	}
1650 
1651 	return 0;
1652 }
1653 
1654 int qtnf_cmd_get_mac_info(struct qtnf_wmac *mac)
1655 {
1656 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1657 	const struct qlink_resp_get_mac_info *resp;
1658 	size_t var_data_len = 0;
1659 	int ret = 0;
1660 
1661 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
1662 					    QLINK_CMD_MAC_INFO,
1663 					    sizeof(struct qlink_cmd));
1664 	if (!cmd_skb)
1665 		return -ENOMEM;
1666 
1667 	qtnf_bus_lock(mac->bus);
1668 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
1669 				       sizeof(*resp), &var_data_len);
1670 	if (ret)
1671 		goto out;
1672 
1673 	resp = (const struct qlink_resp_get_mac_info *)resp_skb->data;
1674 	qtnf_cmd_resp_proc_mac_info(mac, resp);
1675 	ret = qtnf_parse_variable_mac_info(mac, resp->var_info, var_data_len);
1676 
1677 out:
1678 	qtnf_bus_unlock(mac->bus);
1679 	consume_skb(resp_skb);
1680 
1681 	return ret;
1682 }
1683 
1684 int qtnf_cmd_get_hw_info(struct qtnf_bus *bus)
1685 {
1686 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1687 	const struct qlink_resp_get_hw_info *resp;
1688 	size_t info_len = 0;
1689 	int ret = 0;
1690 
1691 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1692 					    QLINK_CMD_GET_HW_INFO,
1693 					    sizeof(struct qlink_cmd));
1694 	if (!cmd_skb)
1695 		return -ENOMEM;
1696 
1697 	qtnf_bus_lock(bus);
1698 	ret = qtnf_cmd_send_with_reply(bus, cmd_skb, &resp_skb,
1699 				       sizeof(*resp), &info_len);
1700 	if (ret)
1701 		goto out;
1702 
1703 	resp = (const struct qlink_resp_get_hw_info *)resp_skb->data;
1704 	ret = qtnf_cmd_resp_proc_hw_info(bus, resp, info_len);
1705 
1706 out:
1707 	qtnf_bus_unlock(bus);
1708 	consume_skb(resp_skb);
1709 
1710 	return ret;
1711 }
1712 
1713 int qtnf_cmd_band_info_get(struct qtnf_wmac *mac,
1714 			   struct ieee80211_supported_band *band)
1715 {
1716 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1717 	struct qlink_cmd_band_info_get *cmd;
1718 	struct qlink_resp_band_info_get *resp;
1719 	size_t info_len = 0;
1720 	int ret = 0;
1721 	u8 qband;
1722 
1723 	switch (band->band) {
1724 	case NL80211_BAND_2GHZ:
1725 		qband = QLINK_BAND_2GHZ;
1726 		break;
1727 	case NL80211_BAND_5GHZ:
1728 		qband = QLINK_BAND_5GHZ;
1729 		break;
1730 	case NL80211_BAND_60GHZ:
1731 		qband = QLINK_BAND_60GHZ;
1732 		break;
1733 	default:
1734 		return -EINVAL;
1735 	}
1736 
1737 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1738 					    QLINK_CMD_BAND_INFO_GET,
1739 					    sizeof(*cmd));
1740 	if (!cmd_skb)
1741 		return -ENOMEM;
1742 
1743 	cmd = (struct qlink_cmd_band_info_get *)cmd_skb->data;
1744 	cmd->band = qband;
1745 
1746 	qtnf_bus_lock(mac->bus);
1747 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
1748 				       sizeof(*resp), &info_len);
1749 	if (ret)
1750 		goto out;
1751 
1752 	resp = (struct qlink_resp_band_info_get *)resp_skb->data;
1753 	if (resp->band != qband) {
1754 		pr_err("MAC%u: reply band %u != cmd band %u\n", mac->macid,
1755 		       resp->band, qband);
1756 		ret = -EINVAL;
1757 		goto out;
1758 	}
1759 
1760 	ret = qtnf_cmd_resp_fill_band_info(band, resp, info_len);
1761 
1762 out:
1763 	qtnf_bus_unlock(mac->bus);
1764 	consume_skb(resp_skb);
1765 
1766 	return ret;
1767 }
1768 
1769 int qtnf_cmd_send_get_phy_params(struct qtnf_wmac *mac)
1770 {
1771 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1772 	struct qlink_resp_phy_params *resp;
1773 	size_t response_size = 0;
1774 	int ret = 0;
1775 
1776 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1777 					    QLINK_CMD_PHY_PARAMS_GET,
1778 					    sizeof(struct qlink_cmd));
1779 	if (!cmd_skb)
1780 		return -ENOMEM;
1781 
1782 	qtnf_bus_lock(mac->bus);
1783 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
1784 				       sizeof(*resp), &response_size);
1785 	if (ret)
1786 		goto out;
1787 
1788 	resp = (struct qlink_resp_phy_params *)resp_skb->data;
1789 	ret = qtnf_cmd_resp_proc_phy_params(mac, resp->info, response_size);
1790 
1791 out:
1792 	qtnf_bus_unlock(mac->bus);
1793 	consume_skb(resp_skb);
1794 
1795 	return ret;
1796 }
1797 
1798 int qtnf_cmd_send_update_phy_params(struct qtnf_wmac *mac, u32 changed)
1799 {
1800 	struct wiphy *wiphy = priv_to_wiphy(mac);
1801 	struct sk_buff *cmd_skb;
1802 	int ret = 0;
1803 
1804 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1805 					    QLINK_CMD_PHY_PARAMS_SET,
1806 					    sizeof(struct qlink_cmd));
1807 	if (!cmd_skb)
1808 		return -ENOMEM;
1809 
1810 	qtnf_bus_lock(mac->bus);
1811 
1812 	if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1813 		qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_FRAG_THRESH,
1814 					 wiphy->frag_threshold);
1815 	if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1816 		qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_RTS_THRESH,
1817 					 wiphy->rts_threshold);
1818 	if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1819 		qtnf_cmd_skb_put_tlv_u8(cmd_skb, QTN_TLV_ID_COVERAGE_CLASS,
1820 					wiphy->coverage_class);
1821 
1822 	ret = qtnf_cmd_send(mac->bus, cmd_skb);
1823 	if (ret)
1824 		goto out;
1825 
1826 out:
1827 	qtnf_bus_unlock(mac->bus);
1828 
1829 	return ret;
1830 }
1831 
1832 int qtnf_cmd_send_init_fw(struct qtnf_bus *bus)
1833 {
1834 	struct sk_buff *cmd_skb;
1835 	int ret = 0;
1836 
1837 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1838 					    QLINK_CMD_FW_INIT,
1839 					    sizeof(struct qlink_cmd));
1840 	if (!cmd_skb)
1841 		return -ENOMEM;
1842 
1843 	qtnf_bus_lock(bus);
1844 	ret = qtnf_cmd_send(bus, cmd_skb);
1845 	if (ret)
1846 		goto out;
1847 
1848 out:
1849 	qtnf_bus_unlock(bus);
1850 
1851 	return ret;
1852 }
1853 
1854 void qtnf_cmd_send_deinit_fw(struct qtnf_bus *bus)
1855 {
1856 	struct sk_buff *cmd_skb;
1857 
1858 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1859 					    QLINK_CMD_FW_DEINIT,
1860 					    sizeof(struct qlink_cmd));
1861 	if (!cmd_skb)
1862 		return;
1863 
1864 	qtnf_bus_lock(bus);
1865 	qtnf_cmd_send(bus, cmd_skb);
1866 	qtnf_bus_unlock(bus);
1867 }
1868 
1869 int qtnf_cmd_send_add_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
1870 			  const u8 *mac_addr, struct key_params *params)
1871 {
1872 	struct sk_buff *cmd_skb;
1873 	struct qlink_cmd_add_key *cmd;
1874 	int ret = 0;
1875 
1876 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1877 					    QLINK_CMD_ADD_KEY,
1878 					    sizeof(*cmd));
1879 	if (!cmd_skb)
1880 		return -ENOMEM;
1881 
1882 	qtnf_bus_lock(vif->mac->bus);
1883 
1884 	cmd = (struct qlink_cmd_add_key *)cmd_skb->data;
1885 
1886 	if (mac_addr)
1887 		ether_addr_copy(cmd->addr, mac_addr);
1888 	else
1889 		eth_broadcast_addr(cmd->addr);
1890 
1891 	cmd->cipher = cpu_to_le32(params->cipher);
1892 	cmd->key_index = key_index;
1893 	cmd->pairwise = pairwise;
1894 
1895 	if (params->key && params->key_len > 0)
1896 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_KEY,
1897 					 params->key,
1898 					 params->key_len);
1899 
1900 	if (params->seq && params->seq_len > 0)
1901 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_SEQ,
1902 					 params->seq,
1903 					 params->seq_len);
1904 
1905 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1906 	if (ret)
1907 		goto out;
1908 
1909 out:
1910 	qtnf_bus_unlock(vif->mac->bus);
1911 
1912 	return ret;
1913 }
1914 
1915 int qtnf_cmd_send_del_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
1916 			  const u8 *mac_addr)
1917 {
1918 	struct sk_buff *cmd_skb;
1919 	struct qlink_cmd_del_key *cmd;
1920 	int ret = 0;
1921 
1922 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1923 					    QLINK_CMD_DEL_KEY,
1924 					    sizeof(*cmd));
1925 	if (!cmd_skb)
1926 		return -ENOMEM;
1927 
1928 	qtnf_bus_lock(vif->mac->bus);
1929 
1930 	cmd = (struct qlink_cmd_del_key *)cmd_skb->data;
1931 
1932 	if (mac_addr)
1933 		ether_addr_copy(cmd->addr, mac_addr);
1934 	else
1935 		eth_broadcast_addr(cmd->addr);
1936 
1937 	cmd->key_index = key_index;
1938 	cmd->pairwise = pairwise;
1939 
1940 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1941 	if (ret)
1942 		goto out;
1943 
1944 out:
1945 	qtnf_bus_unlock(vif->mac->bus);
1946 
1947 	return ret;
1948 }
1949 
1950 int qtnf_cmd_send_set_default_key(struct qtnf_vif *vif, u8 key_index,
1951 				  bool unicast, bool multicast)
1952 {
1953 	struct sk_buff *cmd_skb;
1954 	struct qlink_cmd_set_def_key *cmd;
1955 	int ret = 0;
1956 
1957 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1958 					    QLINK_CMD_SET_DEFAULT_KEY,
1959 					    sizeof(*cmd));
1960 	if (!cmd_skb)
1961 		return -ENOMEM;
1962 
1963 	qtnf_bus_lock(vif->mac->bus);
1964 
1965 	cmd = (struct qlink_cmd_set_def_key *)cmd_skb->data;
1966 	cmd->key_index = key_index;
1967 	cmd->unicast = unicast;
1968 	cmd->multicast = multicast;
1969 
1970 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1971 	if (ret)
1972 		goto out;
1973 
1974 out:
1975 	qtnf_bus_unlock(vif->mac->bus);
1976 
1977 	return ret;
1978 }
1979 
1980 int qtnf_cmd_send_set_default_mgmt_key(struct qtnf_vif *vif, u8 key_index)
1981 {
1982 	struct sk_buff *cmd_skb;
1983 	struct qlink_cmd_set_def_mgmt_key *cmd;
1984 	int ret = 0;
1985 
1986 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1987 					    QLINK_CMD_SET_DEFAULT_MGMT_KEY,
1988 					    sizeof(*cmd));
1989 	if (!cmd_skb)
1990 		return -ENOMEM;
1991 
1992 	qtnf_bus_lock(vif->mac->bus);
1993 
1994 	cmd = (struct qlink_cmd_set_def_mgmt_key *)cmd_skb->data;
1995 	cmd->key_index = key_index;
1996 
1997 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
1998 	if (ret)
1999 		goto out;
2000 
2001 out:
2002 	qtnf_bus_unlock(vif->mac->bus);
2003 
2004 	return ret;
2005 }
2006 
2007 static u32 qtnf_encode_sta_flags(u32 flags)
2008 {
2009 	u32 code = 0;
2010 
2011 	if (flags & BIT(NL80211_STA_FLAG_AUTHORIZED))
2012 		code |= QLINK_STA_FLAG_AUTHORIZED;
2013 	if (flags & BIT(NL80211_STA_FLAG_SHORT_PREAMBLE))
2014 		code |= QLINK_STA_FLAG_SHORT_PREAMBLE;
2015 	if (flags & BIT(NL80211_STA_FLAG_WME))
2016 		code |= QLINK_STA_FLAG_WME;
2017 	if (flags & BIT(NL80211_STA_FLAG_MFP))
2018 		code |= QLINK_STA_FLAG_MFP;
2019 	if (flags & BIT(NL80211_STA_FLAG_AUTHENTICATED))
2020 		code |= QLINK_STA_FLAG_AUTHENTICATED;
2021 	if (flags & BIT(NL80211_STA_FLAG_TDLS_PEER))
2022 		code |= QLINK_STA_FLAG_TDLS_PEER;
2023 	if (flags & BIT(NL80211_STA_FLAG_ASSOCIATED))
2024 		code |= QLINK_STA_FLAG_ASSOCIATED;
2025 	return code;
2026 }
2027 
2028 int qtnf_cmd_send_change_sta(struct qtnf_vif *vif, const u8 *mac,
2029 			     struct station_parameters *params)
2030 {
2031 	struct sk_buff *cmd_skb;
2032 	struct qlink_cmd_change_sta *cmd;
2033 	int ret = 0;
2034 
2035 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2036 					    QLINK_CMD_CHANGE_STA,
2037 					    sizeof(*cmd));
2038 	if (!cmd_skb)
2039 		return -ENOMEM;
2040 
2041 	qtnf_bus_lock(vif->mac->bus);
2042 
2043 	cmd = (struct qlink_cmd_change_sta *)cmd_skb->data;
2044 	ether_addr_copy(cmd->sta_addr, mac);
2045 	cmd->flag_update.mask =
2046 		cpu_to_le32(qtnf_encode_sta_flags(params->sta_flags_mask));
2047 	cmd->flag_update.value =
2048 		cpu_to_le32(qtnf_encode_sta_flags(params->sta_flags_set));
2049 
2050 	switch (vif->wdev.iftype) {
2051 	case NL80211_IFTYPE_AP:
2052 		cmd->if_type = cpu_to_le16(QLINK_IFTYPE_AP);
2053 		break;
2054 	case NL80211_IFTYPE_STATION:
2055 		cmd->if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
2056 		break;
2057 	default:
2058 		pr_err("unsupported iftype %d\n", vif->wdev.iftype);
2059 		ret = -EINVAL;
2060 		goto out;
2061 	}
2062 
2063 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2064 	if (ret)
2065 		goto out;
2066 
2067 out:
2068 	qtnf_bus_unlock(vif->mac->bus);
2069 
2070 	return ret;
2071 }
2072 
2073 int qtnf_cmd_send_del_sta(struct qtnf_vif *vif,
2074 			  struct station_del_parameters *params)
2075 {
2076 	struct sk_buff *cmd_skb;
2077 	struct qlink_cmd_del_sta *cmd;
2078 	int ret = 0;
2079 
2080 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2081 					    QLINK_CMD_DEL_STA,
2082 					    sizeof(*cmd));
2083 	if (!cmd_skb)
2084 		return -ENOMEM;
2085 
2086 	qtnf_bus_lock(vif->mac->bus);
2087 
2088 	cmd = (struct qlink_cmd_del_sta *)cmd_skb->data;
2089 
2090 	if (params->mac)
2091 		ether_addr_copy(cmd->sta_addr, params->mac);
2092 	else
2093 		eth_broadcast_addr(cmd->sta_addr);	/* flush all stations */
2094 
2095 	cmd->subtype = params->subtype;
2096 	cmd->reason_code = cpu_to_le16(params->reason_code);
2097 
2098 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2099 	if (ret)
2100 		goto out;
2101 
2102 out:
2103 	qtnf_bus_unlock(vif->mac->bus);
2104 
2105 	return ret;
2106 }
2107 
2108 static void qtnf_cmd_channel_tlv_add(struct sk_buff *cmd_skb,
2109 				     const struct ieee80211_channel *sc)
2110 {
2111 	struct qlink_tlv_channel *qchan;
2112 	u32 flags = 0;
2113 
2114 	qchan = skb_put_zero(cmd_skb, sizeof(*qchan));
2115 	qchan->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANNEL);
2116 	qchan->hdr.len = cpu_to_le16(sizeof(*qchan) - sizeof(qchan->hdr));
2117 	qchan->chan.center_freq = cpu_to_le16(sc->center_freq);
2118 	qchan->chan.hw_value = cpu_to_le16(sc->hw_value);
2119 
2120 	if (sc->flags & IEEE80211_CHAN_NO_IR)
2121 		flags |= QLINK_CHAN_NO_IR;
2122 
2123 	if (sc->flags & IEEE80211_CHAN_RADAR)
2124 		flags |= QLINK_CHAN_RADAR;
2125 
2126 	qchan->chan.flags = cpu_to_le32(flags);
2127 }
2128 
2129 static void qtnf_cmd_randmac_tlv_add(struct sk_buff *cmd_skb,
2130 				     const u8 *mac_addr,
2131 				     const u8 *mac_addr_mask)
2132 {
2133 	struct qlink_random_mac_addr *randmac;
2134 	struct qlink_tlv_hdr *hdr =
2135 		skb_put(cmd_skb, sizeof(*hdr) + sizeof(*randmac));
2136 
2137 	hdr->type = cpu_to_le16(QTN_TLV_ID_RANDOM_MAC_ADDR);
2138 	hdr->len = cpu_to_le16(sizeof(*randmac));
2139 	randmac = (struct qlink_random_mac_addr *)hdr->val;
2140 
2141 	memcpy(randmac->mac_addr, mac_addr, ETH_ALEN);
2142 	memcpy(randmac->mac_addr_mask, mac_addr_mask, ETH_ALEN);
2143 }
2144 
2145 int qtnf_cmd_send_scan(struct qtnf_wmac *mac)
2146 {
2147 	struct sk_buff *cmd_skb;
2148 	struct ieee80211_channel *sc;
2149 	struct cfg80211_scan_request *scan_req = mac->scan_req;
2150 	int n_channels;
2151 	int count = 0;
2152 	int ret;
2153 
2154 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
2155 					    QLINK_CMD_SCAN,
2156 					    sizeof(struct qlink_cmd));
2157 	if (!cmd_skb)
2158 		return -ENOMEM;
2159 
2160 	qtnf_bus_lock(mac->bus);
2161 
2162 	if (scan_req->n_ssids != 0) {
2163 		while (count < scan_req->n_ssids) {
2164 			qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID,
2165 				scan_req->ssids[count].ssid,
2166 				scan_req->ssids[count].ssid_len);
2167 			count++;
2168 		}
2169 	}
2170 
2171 	if (scan_req->ie_len != 0)
2172 		qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_REQ,
2173 					scan_req->ie, scan_req->ie_len);
2174 
2175 	if (scan_req->n_channels) {
2176 		n_channels = scan_req->n_channels;
2177 		count = 0;
2178 
2179 		while (n_channels != 0) {
2180 			sc = scan_req->channels[count];
2181 			if (sc->flags & IEEE80211_CHAN_DISABLED) {
2182 				n_channels--;
2183 				continue;
2184 			}
2185 
2186 			pr_debug("MAC%u: scan chan=%d, freq=%d, flags=%#x\n",
2187 				 mac->macid, sc->hw_value, sc->center_freq,
2188 				 sc->flags);
2189 
2190 			qtnf_cmd_channel_tlv_add(cmd_skb, sc);
2191 			n_channels--;
2192 			count++;
2193 		}
2194 	}
2195 
2196 	if (scan_req->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
2197 		pr_debug("MAC%u: scan with random addr=%pM, mask=%pM\n",
2198 			 mac->macid,
2199 			 scan_req->mac_addr, scan_req->mac_addr_mask);
2200 
2201 		qtnf_cmd_randmac_tlv_add(cmd_skb, scan_req->mac_addr,
2202 					 scan_req->mac_addr_mask);
2203 	}
2204 
2205 	if (scan_req->flags & NL80211_SCAN_FLAG_FLUSH) {
2206 		pr_debug("MAC%u: flush cache before scan\n", mac->macid);
2207 
2208 		qtnf_cmd_skb_put_tlv_tag(cmd_skb, QTN_TLV_ID_SCAN_FLUSH);
2209 	}
2210 
2211 	if (scan_req->duration) {
2212 		pr_debug("MAC%u: %s scan duration %u\n", mac->macid,
2213 			 scan_req->duration_mandatory ? "mandatory" : "max",
2214 			 scan_req->duration);
2215 
2216 		qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_SCAN_DWELL,
2217 					 scan_req->duration);
2218 	}
2219 
2220 	ret = qtnf_cmd_send(mac->bus, cmd_skb);
2221 	if (ret)
2222 		goto out;
2223 
2224 out:
2225 	qtnf_bus_unlock(mac->bus);
2226 
2227 	return ret;
2228 }
2229 
2230 int qtnf_cmd_send_connect(struct qtnf_vif *vif,
2231 			  struct cfg80211_connect_params *sme)
2232 {
2233 	struct sk_buff *cmd_skb;
2234 	struct qlink_cmd_connect *cmd;
2235 	struct qlink_auth_encr *aen;
2236 	int ret;
2237 	int i;
2238 	u32 connect_flags = 0;
2239 
2240 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2241 					    QLINK_CMD_CONNECT,
2242 					    sizeof(*cmd));
2243 	if (!cmd_skb)
2244 		return -ENOMEM;
2245 
2246 	cmd = (struct qlink_cmd_connect *)cmd_skb->data;
2247 
2248 	ether_addr_copy(cmd->bssid, vif->bssid);
2249 
2250 	if (sme->bssid_hint)
2251 		ether_addr_copy(cmd->bssid_hint, sme->bssid_hint);
2252 	else
2253 		eth_zero_addr(cmd->bssid_hint);
2254 
2255 	if (sme->prev_bssid)
2256 		ether_addr_copy(cmd->prev_bssid, sme->prev_bssid);
2257 	else
2258 		eth_zero_addr(cmd->prev_bssid);
2259 
2260 	if ((sme->bg_scan_period >= 0) &&
2261 	    (sme->bg_scan_period <= SHRT_MAX))
2262 		cmd->bg_scan_period = cpu_to_le16(sme->bg_scan_period);
2263 	else
2264 		cmd->bg_scan_period = cpu_to_le16(-1); /* use default value */
2265 
2266 	if (sme->flags & ASSOC_REQ_DISABLE_HT)
2267 		connect_flags |= QLINK_STA_CONNECT_DISABLE_HT;
2268 	if (sme->flags & ASSOC_REQ_DISABLE_VHT)
2269 		connect_flags |= QLINK_STA_CONNECT_DISABLE_VHT;
2270 	if (sme->flags & ASSOC_REQ_USE_RRM)
2271 		connect_flags |= QLINK_STA_CONNECT_USE_RRM;
2272 
2273 	cmd->flags = cpu_to_le32(connect_flags);
2274 	memcpy(&cmd->ht_capa, &sme->ht_capa, sizeof(cmd->ht_capa));
2275 	memcpy(&cmd->ht_capa_mask, &sme->ht_capa_mask,
2276 	       sizeof(cmd->ht_capa_mask));
2277 	memcpy(&cmd->vht_capa, &sme->vht_capa, sizeof(cmd->vht_capa));
2278 	memcpy(&cmd->vht_capa_mask, &sme->vht_capa_mask,
2279 	       sizeof(cmd->vht_capa_mask));
2280 	cmd->pbss = sme->pbss;
2281 
2282 	aen = &cmd->aen;
2283 	aen->auth_type = sme->auth_type;
2284 	aen->privacy = !!sme->privacy;
2285 	cmd->mfp = sme->mfp;
2286 	aen->wpa_versions = cpu_to_le32(sme->crypto.wpa_versions);
2287 	aen->cipher_group = cpu_to_le32(sme->crypto.cipher_group);
2288 	aen->n_ciphers_pairwise = cpu_to_le32(sme->crypto.n_ciphers_pairwise);
2289 
2290 	for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
2291 		aen->ciphers_pairwise[i] =
2292 			cpu_to_le32(sme->crypto.ciphers_pairwise[i]);
2293 
2294 	aen->n_akm_suites = cpu_to_le32(sme->crypto.n_akm_suites);
2295 
2296 	for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
2297 		aen->akm_suites[i] = cpu_to_le32(sme->crypto.akm_suites[i]);
2298 
2299 	aen->control_port = sme->crypto.control_port;
2300 	aen->control_port_no_encrypt =
2301 		sme->crypto.control_port_no_encrypt;
2302 	aen->control_port_ethertype =
2303 		cpu_to_le16(be16_to_cpu(sme->crypto.control_port_ethertype));
2304 
2305 	qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, sme->ssid,
2306 				 sme->ssid_len);
2307 
2308 	if (sme->ie_len != 0)
2309 		qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_ASSOC_REQ,
2310 					sme->ie, sme->ie_len);
2311 
2312 	if (sme->channel)
2313 		qtnf_cmd_channel_tlv_add(cmd_skb, sme->channel);
2314 
2315 	qtnf_bus_lock(vif->mac->bus);
2316 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2317 	if (ret)
2318 		goto out;
2319 
2320 out:
2321 	qtnf_bus_unlock(vif->mac->bus);
2322 
2323 	return ret;
2324 }
2325 
2326 int qtnf_cmd_send_disconnect(struct qtnf_vif *vif, u16 reason_code)
2327 {
2328 	struct sk_buff *cmd_skb;
2329 	struct qlink_cmd_disconnect *cmd;
2330 	int ret;
2331 
2332 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2333 					    QLINK_CMD_DISCONNECT,
2334 					    sizeof(*cmd));
2335 	if (!cmd_skb)
2336 		return -ENOMEM;
2337 
2338 	qtnf_bus_lock(vif->mac->bus);
2339 
2340 	cmd = (struct qlink_cmd_disconnect *)cmd_skb->data;
2341 	cmd->reason = cpu_to_le16(reason_code);
2342 
2343 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2344 	if (ret)
2345 		goto out;
2346 
2347 out:
2348 	qtnf_bus_unlock(vif->mac->bus);
2349 
2350 	return ret;
2351 }
2352 
2353 int qtnf_cmd_send_updown_intf(struct qtnf_vif *vif, bool up)
2354 {
2355 	struct sk_buff *cmd_skb;
2356 	struct qlink_cmd_updown *cmd;
2357 	int ret;
2358 
2359 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2360 					    QLINK_CMD_UPDOWN_INTF,
2361 					    sizeof(*cmd));
2362 	if (!cmd_skb)
2363 		return -ENOMEM;
2364 
2365 	cmd = (struct qlink_cmd_updown *)cmd_skb->data;
2366 	cmd->if_up = !!up;
2367 
2368 	qtnf_bus_lock(vif->mac->bus);
2369 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb);
2370 	if (ret)
2371 		goto out;
2372 
2373 out:
2374 	qtnf_bus_unlock(vif->mac->bus);
2375 
2376 	return ret;
2377 }
2378 
2379 int qtnf_cmd_reg_notify(struct qtnf_bus *bus, struct regulatory_request *req)
2380 {
2381 	struct sk_buff *cmd_skb;
2382 	int ret;
2383 	struct qlink_cmd_reg_notify *cmd;
2384 
2385 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
2386 					    QLINK_CMD_REG_NOTIFY,
2387 					    sizeof(*cmd));
2388 	if (!cmd_skb)
2389 		return -ENOMEM;
2390 
2391 	cmd = (struct qlink_cmd_reg_notify *)cmd_skb->data;
2392 	cmd->alpha2[0] = req->alpha2[0];
2393 	cmd->alpha2[1] = req->alpha2[1];
2394 
2395 	switch (req->initiator) {
2396 	case NL80211_REGDOM_SET_BY_CORE:
2397 		cmd->initiator = QLINK_REGDOM_SET_BY_CORE;
2398 		break;
2399 	case NL80211_REGDOM_SET_BY_USER:
2400 		cmd->initiator = QLINK_REGDOM_SET_BY_USER;
2401 		break;
2402 	case NL80211_REGDOM_SET_BY_DRIVER:
2403 		cmd->initiator = QLINK_REGDOM_SET_BY_DRIVER;
2404 		break;
2405 	case NL80211_REGDOM_SET_BY_COUNTRY_IE:
2406 		cmd->initiator = QLINK_REGDOM_SET_BY_COUNTRY_IE;
2407 		break;
2408 	}
2409 
2410 	switch (req->user_reg_hint_type) {
2411 	case NL80211_USER_REG_HINT_USER:
2412 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_USER;
2413 		break;
2414 	case NL80211_USER_REG_HINT_CELL_BASE:
2415 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_CELL_BASE;
2416 		break;
2417 	case NL80211_USER_REG_HINT_INDOOR:
2418 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_INDOOR;
2419 		break;
2420 	}
2421 
2422 	qtnf_bus_lock(bus);
2423 	ret = qtnf_cmd_send(bus, cmd_skb);
2424 	if (ret)
2425 		goto out;
2426 
2427 out:
2428 	qtnf_bus_unlock(bus);
2429 
2430 	return ret;
2431 }
2432 
2433 int qtnf_cmd_get_chan_stats(struct qtnf_wmac *mac, u16 channel,
2434 			    struct qtnf_chan_stats *stats)
2435 {
2436 	struct sk_buff *cmd_skb, *resp_skb = NULL;
2437 	struct qlink_cmd_get_chan_stats *cmd;
2438 	struct qlink_resp_get_chan_stats *resp;
2439 	size_t var_data_len = 0;
2440 	int ret = 0;
2441 
2442 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
2443 					    QLINK_CMD_CHAN_STATS,
2444 					    sizeof(*cmd));
2445 	if (!cmd_skb)
2446 		return -ENOMEM;
2447 
2448 	qtnf_bus_lock(mac->bus);
2449 
2450 	cmd = (struct qlink_cmd_get_chan_stats *)cmd_skb->data;
2451 	cmd->channel = cpu_to_le16(channel);
2452 
2453 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb,
2454 				       sizeof(*resp), &var_data_len);
2455 	if (ret)
2456 		goto out;
2457 
2458 	resp = (struct qlink_resp_get_chan_stats *)resp_skb->data;
2459 	ret = qtnf_cmd_resp_proc_chan_stat_info(stats, resp->info,
2460 						var_data_len);
2461 
2462 out:
2463 	qtnf_bus_unlock(mac->bus);
2464 	consume_skb(resp_skb);
2465 
2466 	return ret;
2467 }
2468 
2469 int qtnf_cmd_send_chan_switch(struct qtnf_vif *vif,
2470 			      struct cfg80211_csa_settings *params)
2471 {
2472 	struct qtnf_wmac *mac = vif->mac;
2473 	struct qlink_cmd_chan_switch *cmd;
2474 	struct sk_buff *cmd_skb;
2475 	int ret;
2476 
2477 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, vif->vifid,
2478 					    QLINK_CMD_CHAN_SWITCH,
2479 					    sizeof(*cmd));
2480 	if (!cmd_skb)
2481 		return -ENOMEM;
2482 
2483 	qtnf_bus_lock(mac->bus);
2484 
2485 	cmd = (struct qlink_cmd_chan_switch *)cmd_skb->data;
2486 	cmd->channel = cpu_to_le16(params->chandef.chan->hw_value);
2487 	cmd->radar_required = params->radar_required;
2488 	cmd->block_tx = params->block_tx;
2489 	cmd->beacon_count = params->count;
2490 
2491 	ret = qtnf_cmd_send(mac->bus, cmd_skb);
2492 	if (ret)
2493 		goto out;
2494 
2495 out:
2496 	qtnf_bus_unlock(mac->bus);
2497 
2498 	return ret;
2499 }
2500 
2501 int qtnf_cmd_get_channel(struct qtnf_vif *vif, struct cfg80211_chan_def *chdef)
2502 {
2503 	struct qtnf_bus *bus = vif->mac->bus;
2504 	const struct qlink_resp_channel_get *resp;
2505 	struct sk_buff *cmd_skb;
2506 	struct sk_buff *resp_skb = NULL;
2507 	int ret;
2508 
2509 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2510 					    QLINK_CMD_CHAN_GET,
2511 					    sizeof(struct qlink_cmd));
2512 	if (!cmd_skb)
2513 		return -ENOMEM;
2514 
2515 	qtnf_bus_lock(bus);
2516 	ret = qtnf_cmd_send_with_reply(bus, cmd_skb, &resp_skb,
2517 				       sizeof(*resp), NULL);
2518 	if (ret)
2519 		goto out;
2520 
2521 	resp = (const struct qlink_resp_channel_get *)resp_skb->data;
2522 	qlink_chandef_q2cfg(priv_to_wiphy(vif->mac), &resp->chan, chdef);
2523 
2524 out:
2525 	qtnf_bus_unlock(bus);
2526 	consume_skb(resp_skb);
2527 
2528 	return ret;
2529 }
2530 
2531 int qtnf_cmd_start_cac(const struct qtnf_vif *vif,
2532 		       const struct cfg80211_chan_def *chdef,
2533 		       u32 cac_time_ms)
2534 {
2535 	struct qtnf_bus *bus = vif->mac->bus;
2536 	struct sk_buff *cmd_skb;
2537 	struct qlink_cmd_start_cac *cmd;
2538 	int ret;
2539 
2540 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2541 					    QLINK_CMD_START_CAC,
2542 					    sizeof(*cmd));
2543 	if (!cmd_skb)
2544 		return -ENOMEM;
2545 
2546 	cmd = (struct qlink_cmd_start_cac *)cmd_skb->data;
2547 	cmd->cac_time_ms = cpu_to_le32(cac_time_ms);
2548 	qlink_chandef_cfg2q(chdef, &cmd->chan);
2549 
2550 	qtnf_bus_lock(bus);
2551 	ret = qtnf_cmd_send(bus, cmd_skb);
2552 	if (ret)
2553 		goto out;
2554 
2555 out:
2556 	qtnf_bus_unlock(bus);
2557 
2558 	return ret;
2559 }
2560 
2561 int qtnf_cmd_set_mac_acl(const struct qtnf_vif *vif,
2562 			 const struct cfg80211_acl_data *params)
2563 {
2564 	struct qtnf_bus *bus = vif->mac->bus;
2565 	struct sk_buff *cmd_skb;
2566 	struct qlink_tlv_hdr *tlv;
2567 	size_t acl_size = qtnf_cmd_acl_data_size(params);
2568 	int ret;
2569 
2570 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2571 					    QLINK_CMD_SET_MAC_ACL,
2572 					    sizeof(struct qlink_cmd));
2573 	if (!cmd_skb)
2574 		return -ENOMEM;
2575 
2576 	tlv = skb_put(cmd_skb, sizeof(*tlv) + acl_size);
2577 	tlv->type = cpu_to_le16(QTN_TLV_ID_ACL_DATA);
2578 	tlv->len = cpu_to_le16(acl_size);
2579 	qlink_acl_data_cfg2q(params, (struct qlink_acl_data *)tlv->val);
2580 
2581 	qtnf_bus_lock(bus);
2582 	ret = qtnf_cmd_send(bus, cmd_skb);
2583 	if (ret)
2584 		goto out;
2585 
2586 out:
2587 	qtnf_bus_unlock(bus);
2588 
2589 	return ret;
2590 }
2591 
2592 int qtnf_cmd_send_pm_set(const struct qtnf_vif *vif, u8 pm_mode, int timeout)
2593 {
2594 	struct qtnf_bus *bus = vif->mac->bus;
2595 	struct sk_buff *cmd_skb;
2596 	struct qlink_cmd_pm_set *cmd;
2597 	int ret = 0;
2598 
2599 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2600 					    QLINK_CMD_PM_SET, sizeof(*cmd));
2601 	if (!cmd_skb)
2602 		return -ENOMEM;
2603 
2604 	cmd = (struct qlink_cmd_pm_set *)cmd_skb->data;
2605 	cmd->pm_mode = pm_mode;
2606 	cmd->pm_standby_timer = cpu_to_le32(timeout);
2607 
2608 	qtnf_bus_lock(bus);
2609 
2610 	ret = qtnf_cmd_send(bus, cmd_skb);
2611 	if (ret)
2612 		goto out;
2613 
2614 out:
2615 	qtnf_bus_unlock(bus);
2616 
2617 	return ret;
2618 }
2619 
2620 int qtnf_cmd_send_wowlan_set(const struct qtnf_vif *vif,
2621 			     const struct cfg80211_wowlan *wowl)
2622 {
2623 	struct qtnf_bus *bus = vif->mac->bus;
2624 	struct sk_buff *cmd_skb;
2625 	struct qlink_cmd_wowlan_set *cmd;
2626 	u32 triggers = 0;
2627 	int count = 0;
2628 	int ret = 0;
2629 
2630 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2631 					    QLINK_CMD_WOWLAN_SET, sizeof(*cmd));
2632 	if (!cmd_skb)
2633 		return -ENOMEM;
2634 
2635 	qtnf_bus_lock(bus);
2636 
2637 	cmd = (struct qlink_cmd_wowlan_set *)cmd_skb->data;
2638 
2639 	if (wowl) {
2640 		if (wowl->disconnect)
2641 			triggers |=  QLINK_WOWLAN_TRIG_DISCONNECT;
2642 
2643 		if (wowl->magic_pkt)
2644 			triggers |= QLINK_WOWLAN_TRIG_MAGIC_PKT;
2645 
2646 		if (wowl->n_patterns && wowl->patterns) {
2647 			triggers |= QLINK_WOWLAN_TRIG_PATTERN_PKT;
2648 			while (count < wowl->n_patterns) {
2649 				qtnf_cmd_skb_put_tlv_arr(cmd_skb,
2650 					QTN_TLV_ID_WOWLAN_PATTERN,
2651 					wowl->patterns[count].pattern,
2652 					wowl->patterns[count].pattern_len);
2653 				count++;
2654 			}
2655 		}
2656 	}
2657 
2658 	cmd->triggers = cpu_to_le32(triggers);
2659 
2660 	ret = qtnf_cmd_send(bus, cmd_skb);
2661 	if (ret)
2662 		goto out;
2663 
2664 out:
2665 	qtnf_bus_unlock(bus);
2666 	return ret;
2667 }
2668