1 // SPDX-License-Identifier: GPL-2.0 OR BSD-3-Clause
2 /* Copyright(c) 2018-2019  Realtek Corporation
3  */
4 
5 #include <linux/iopoll.h>
6 
7 #include "main.h"
8 #include "coex.h"
9 #include "fw.h"
10 #include "tx.h"
11 #include "reg.h"
12 #include "sec.h"
13 #include "debug.h"
14 #include "util.h"
15 #include "wow.h"
16 #include "ps.h"
17 
18 static void rtw_fw_c2h_cmd_handle_ext(struct rtw_dev *rtwdev,
19 				      struct sk_buff *skb)
20 {
21 	struct rtw_c2h_cmd *c2h;
22 	u8 sub_cmd_id;
23 
24 	c2h = get_c2h_from_skb(skb);
25 	sub_cmd_id = c2h->payload[0];
26 
27 	switch (sub_cmd_id) {
28 	case C2H_CCX_RPT:
29 		rtw_tx_report_handle(rtwdev, skb, C2H_CCX_RPT);
30 		break;
31 	case C2H_SCAN_STATUS_RPT:
32 		rtw_hw_scan_status_report(rtwdev, skb);
33 		break;
34 	case C2H_CHAN_SWITCH:
35 		rtw_hw_scan_chan_switch(rtwdev, skb);
36 		break;
37 	default:
38 		break;
39 	}
40 }
41 
42 static u16 get_max_amsdu_len(u32 bit_rate)
43 {
44 	/* lower than ofdm, do not aggregate */
45 	if (bit_rate < 550)
46 		return 1;
47 
48 	/* lower than 20M 2ss mcs8, make it small */
49 	if (bit_rate < 1800)
50 		return 1200;
51 
52 	/* lower than 40M 2ss mcs9, make it medium */
53 	if (bit_rate < 4000)
54 		return 2600;
55 
56 	/* not yet 80M 2ss mcs8/9, make it twice regular packet size */
57 	if (bit_rate < 7000)
58 		return 3500;
59 
60 	/* unlimited */
61 	return 0;
62 }
63 
64 struct rtw_fw_iter_ra_data {
65 	struct rtw_dev *rtwdev;
66 	u8 *payload;
67 };
68 
69 static void rtw_fw_ra_report_iter(void *data, struct ieee80211_sta *sta)
70 {
71 	struct rtw_fw_iter_ra_data *ra_data = data;
72 	struct rtw_sta_info *si = (struct rtw_sta_info *)sta->drv_priv;
73 	u8 mac_id, rate, sgi, bw;
74 	u8 mcs, nss;
75 	u32 bit_rate;
76 
77 	mac_id = GET_RA_REPORT_MACID(ra_data->payload);
78 	if (si->mac_id != mac_id)
79 		return;
80 
81 	si->ra_report.txrate.flags = 0;
82 
83 	rate = GET_RA_REPORT_RATE(ra_data->payload);
84 	sgi = GET_RA_REPORT_SGI(ra_data->payload);
85 	bw = GET_RA_REPORT_BW(ra_data->payload);
86 
87 	if (rate < DESC_RATEMCS0) {
88 		si->ra_report.txrate.legacy = rtw_desc_to_bitrate(rate);
89 		goto legacy;
90 	}
91 
92 	rtw_desc_to_mcsrate(rate, &mcs, &nss);
93 	if (rate >= DESC_RATEVHT1SS_MCS0)
94 		si->ra_report.txrate.flags |= RATE_INFO_FLAGS_VHT_MCS;
95 	else if (rate >= DESC_RATEMCS0)
96 		si->ra_report.txrate.flags |= RATE_INFO_FLAGS_MCS;
97 
98 	if (rate >= DESC_RATEMCS0) {
99 		si->ra_report.txrate.mcs = mcs;
100 		si->ra_report.txrate.nss = nss;
101 	}
102 
103 	if (sgi)
104 		si->ra_report.txrate.flags |= RATE_INFO_FLAGS_SHORT_GI;
105 
106 	if (bw == RTW_CHANNEL_WIDTH_80)
107 		si->ra_report.txrate.bw = RATE_INFO_BW_80;
108 	else if (bw == RTW_CHANNEL_WIDTH_40)
109 		si->ra_report.txrate.bw = RATE_INFO_BW_40;
110 	else
111 		si->ra_report.txrate.bw = RATE_INFO_BW_20;
112 
113 legacy:
114 	bit_rate = cfg80211_calculate_bitrate(&si->ra_report.txrate);
115 
116 	si->ra_report.desc_rate = rate;
117 	si->ra_report.bit_rate = bit_rate;
118 
119 	sta->max_rc_amsdu_len = get_max_amsdu_len(bit_rate);
120 }
121 
122 static void rtw_fw_ra_report_handle(struct rtw_dev *rtwdev, u8 *payload,
123 				    u8 length)
124 {
125 	struct rtw_fw_iter_ra_data ra_data;
126 
127 	if (WARN(length < 7, "invalid ra report c2h length\n"))
128 		return;
129 
130 	rtwdev->dm_info.tx_rate = GET_RA_REPORT_RATE(payload);
131 	ra_data.rtwdev = rtwdev;
132 	ra_data.payload = payload;
133 	rtw_iterate_stas_atomic(rtwdev, rtw_fw_ra_report_iter, &ra_data);
134 }
135 
136 struct rtw_beacon_filter_iter_data {
137 	struct rtw_dev *rtwdev;
138 	u8 *payload;
139 };
140 
141 static void rtw_fw_bcn_filter_notify_vif_iter(void *data, u8 *mac,
142 					      struct ieee80211_vif *vif)
143 {
144 	struct rtw_beacon_filter_iter_data *iter_data = data;
145 	struct rtw_dev *rtwdev = iter_data->rtwdev;
146 	u8 *payload = iter_data->payload;
147 	u8 type = GET_BCN_FILTER_NOTIFY_TYPE(payload);
148 	u8 event = GET_BCN_FILTER_NOTIFY_EVENT(payload);
149 	s8 sig = (s8)GET_BCN_FILTER_NOTIFY_RSSI(payload);
150 
151 	switch (type) {
152 	case BCN_FILTER_NOTIFY_SIGNAL_CHANGE:
153 		event = event ? NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH :
154 			NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW;
155 		ieee80211_cqm_rssi_notify(vif, event, sig, GFP_KERNEL);
156 		break;
157 	case BCN_FILTER_CONNECTION_LOSS:
158 		ieee80211_connection_loss(vif);
159 		break;
160 	case BCN_FILTER_CONNECTED:
161 		rtwdev->beacon_loss = false;
162 		break;
163 	case BCN_FILTER_NOTIFY_BEACON_LOSS:
164 		rtwdev->beacon_loss = true;
165 		rtw_leave_lps(rtwdev);
166 		break;
167 	}
168 }
169 
170 static void rtw_fw_bcn_filter_notify(struct rtw_dev *rtwdev, u8 *payload,
171 				     u8 length)
172 {
173 	struct rtw_beacon_filter_iter_data dev_iter_data;
174 
175 	dev_iter_data.rtwdev = rtwdev;
176 	dev_iter_data.payload = payload;
177 	rtw_iterate_vifs(rtwdev, rtw_fw_bcn_filter_notify_vif_iter,
178 			 &dev_iter_data);
179 }
180 
181 static void rtw_fw_scan_result(struct rtw_dev *rtwdev, u8 *payload,
182 			       u8 length)
183 {
184 	struct rtw_dm_info *dm_info = &rtwdev->dm_info;
185 
186 	dm_info->scan_density = payload[0];
187 
188 	rtw_dbg(rtwdev, RTW_DBG_FW, "scan.density = %x\n",
189 		dm_info->scan_density);
190 }
191 
192 static void rtw_fw_adaptivity_result(struct rtw_dev *rtwdev, u8 *payload,
193 				     u8 length)
194 {
195 	struct rtw_hw_reg_offset *edcca_th = rtwdev->chip->edcca_th;
196 	struct rtw_c2h_adaptivity *result = (struct rtw_c2h_adaptivity *)payload;
197 
198 	rtw_dbg(rtwdev, RTW_DBG_ADAPTIVITY,
199 		"Adaptivity: density %x igi %x l2h_th_init %x l2h %x h2l %x option %x\n",
200 		result->density, result->igi, result->l2h_th_init, result->l2h,
201 		result->h2l, result->option);
202 
203 	rtw_dbg(rtwdev, RTW_DBG_ADAPTIVITY, "Reg Setting: L2H %x H2L %x\n",
204 		rtw_read32_mask(rtwdev, edcca_th[EDCCA_TH_L2H_IDX].hw_reg.addr,
205 				edcca_th[EDCCA_TH_L2H_IDX].hw_reg.mask),
206 		rtw_read32_mask(rtwdev, edcca_th[EDCCA_TH_H2L_IDX].hw_reg.addr,
207 				edcca_th[EDCCA_TH_H2L_IDX].hw_reg.mask));
208 
209 	rtw_dbg(rtwdev, RTW_DBG_ADAPTIVITY, "EDCCA Flag %s\n",
210 		rtw_read32_mask(rtwdev, REG_EDCCA_REPORT, BIT_EDCCA_FLAG) ?
211 		"Set" : "Unset");
212 }
213 
214 void rtw_fw_c2h_cmd_handle(struct rtw_dev *rtwdev, struct sk_buff *skb)
215 {
216 	struct rtw_c2h_cmd *c2h;
217 	u32 pkt_offset;
218 	u8 len;
219 
220 	pkt_offset = *((u32 *)skb->cb);
221 	c2h = (struct rtw_c2h_cmd *)(skb->data + pkt_offset);
222 	len = skb->len - pkt_offset - 2;
223 
224 	mutex_lock(&rtwdev->mutex);
225 
226 	if (!test_bit(RTW_FLAG_RUNNING, rtwdev->flags))
227 		goto unlock;
228 
229 	switch (c2h->id) {
230 	case C2H_CCX_TX_RPT:
231 		rtw_tx_report_handle(rtwdev, skb, C2H_CCX_TX_RPT);
232 		break;
233 	case C2H_BT_INFO:
234 		rtw_coex_bt_info_notify(rtwdev, c2h->payload, len);
235 		break;
236 	case C2H_WLAN_INFO:
237 		rtw_coex_wl_fwdbginfo_notify(rtwdev, c2h->payload, len);
238 		break;
239 	case C2H_BCN_FILTER_NOTIFY:
240 		rtw_fw_bcn_filter_notify(rtwdev, c2h->payload, len);
241 		break;
242 	case C2H_HALMAC:
243 		rtw_fw_c2h_cmd_handle_ext(rtwdev, skb);
244 		break;
245 	case C2H_RA_RPT:
246 		rtw_fw_ra_report_handle(rtwdev, c2h->payload, len);
247 		break;
248 	default:
249 		rtw_dbg(rtwdev, RTW_DBG_FW, "C2H 0x%x isn't handled\n", c2h->id);
250 		break;
251 	}
252 
253 unlock:
254 	mutex_unlock(&rtwdev->mutex);
255 }
256 
257 void rtw_fw_c2h_cmd_rx_irqsafe(struct rtw_dev *rtwdev, u32 pkt_offset,
258 			       struct sk_buff *skb)
259 {
260 	struct rtw_c2h_cmd *c2h;
261 	u8 len;
262 
263 	c2h = (struct rtw_c2h_cmd *)(skb->data + pkt_offset);
264 	len = skb->len - pkt_offset - 2;
265 	*((u32 *)skb->cb) = pkt_offset;
266 
267 	rtw_dbg(rtwdev, RTW_DBG_FW, "recv C2H, id=0x%02x, seq=0x%02x, len=%d\n",
268 		c2h->id, c2h->seq, len);
269 
270 	switch (c2h->id) {
271 	case C2H_BT_MP_INFO:
272 		rtw_coex_info_response(rtwdev, skb);
273 		break;
274 	case C2H_WLAN_RFON:
275 		complete(&rtwdev->lps_leave_check);
276 		dev_kfree_skb_any(skb);
277 		break;
278 	case C2H_SCAN_RESULT:
279 		complete(&rtwdev->fw_scan_density);
280 		rtw_fw_scan_result(rtwdev, c2h->payload, len);
281 		dev_kfree_skb_any(skb);
282 		break;
283 	case C2H_ADAPTIVITY:
284 		rtw_fw_adaptivity_result(rtwdev, c2h->payload, len);
285 		dev_kfree_skb_any(skb);
286 		break;
287 	default:
288 		/* pass offset for further operation */
289 		*((u32 *)skb->cb) = pkt_offset;
290 		skb_queue_tail(&rtwdev->c2h_queue, skb);
291 		ieee80211_queue_work(rtwdev->hw, &rtwdev->c2h_work);
292 		break;
293 	}
294 }
295 EXPORT_SYMBOL(rtw_fw_c2h_cmd_rx_irqsafe);
296 
297 void rtw_fw_c2h_cmd_isr(struct rtw_dev *rtwdev)
298 {
299 	if (rtw_read8(rtwdev, REG_MCU_TST_CFG) == VAL_FW_TRIGGER)
300 		rtw_fw_recovery(rtwdev);
301 	else
302 		rtw_warn(rtwdev, "unhandled firmware c2h interrupt\n");
303 }
304 EXPORT_SYMBOL(rtw_fw_c2h_cmd_isr);
305 
306 static void rtw_fw_send_h2c_command(struct rtw_dev *rtwdev,
307 				    u8 *h2c)
308 {
309 	u8 box;
310 	u8 box_state;
311 	u32 box_reg, box_ex_reg;
312 	int idx;
313 	int ret;
314 
315 	rtw_dbg(rtwdev, RTW_DBG_FW,
316 		"send H2C content %02x%02x%02x%02x %02x%02x%02x%02x\n",
317 		h2c[3], h2c[2], h2c[1], h2c[0],
318 		h2c[7], h2c[6], h2c[5], h2c[4]);
319 
320 	spin_lock(&rtwdev->h2c.lock);
321 
322 	box = rtwdev->h2c.last_box_num;
323 	switch (box) {
324 	case 0:
325 		box_reg = REG_HMEBOX0;
326 		box_ex_reg = REG_HMEBOX0_EX;
327 		break;
328 	case 1:
329 		box_reg = REG_HMEBOX1;
330 		box_ex_reg = REG_HMEBOX1_EX;
331 		break;
332 	case 2:
333 		box_reg = REG_HMEBOX2;
334 		box_ex_reg = REG_HMEBOX2_EX;
335 		break;
336 	case 3:
337 		box_reg = REG_HMEBOX3;
338 		box_ex_reg = REG_HMEBOX3_EX;
339 		break;
340 	default:
341 		WARN(1, "invalid h2c mail box number\n");
342 		goto out;
343 	}
344 
345 	ret = read_poll_timeout_atomic(rtw_read8, box_state,
346 				       !((box_state >> box) & 0x1), 100, 3000,
347 				       false, rtwdev, REG_HMETFR);
348 
349 	if (ret) {
350 		rtw_err(rtwdev, "failed to send h2c command\n");
351 		goto out;
352 	}
353 
354 	for (idx = 0; idx < 4; idx++)
355 		rtw_write8(rtwdev, box_reg + idx, h2c[idx]);
356 	for (idx = 0; idx < 4; idx++)
357 		rtw_write8(rtwdev, box_ex_reg + idx, h2c[idx + 4]);
358 
359 	if (++rtwdev->h2c.last_box_num >= 4)
360 		rtwdev->h2c.last_box_num = 0;
361 
362 out:
363 	spin_unlock(&rtwdev->h2c.lock);
364 }
365 
366 void rtw_fw_h2c_cmd_dbg(struct rtw_dev *rtwdev, u8 *h2c)
367 {
368 	rtw_fw_send_h2c_command(rtwdev, h2c);
369 }
370 
371 static void rtw_fw_send_h2c_packet(struct rtw_dev *rtwdev, u8 *h2c_pkt)
372 {
373 	int ret;
374 
375 	spin_lock(&rtwdev->h2c.lock);
376 
377 	FW_OFFLOAD_H2C_SET_SEQ_NUM(h2c_pkt, rtwdev->h2c.seq);
378 	ret = rtw_hci_write_data_h2c(rtwdev, h2c_pkt, H2C_PKT_SIZE);
379 	if (ret)
380 		rtw_err(rtwdev, "failed to send h2c packet\n");
381 	rtwdev->h2c.seq++;
382 
383 	spin_unlock(&rtwdev->h2c.lock);
384 }
385 
386 void
387 rtw_fw_send_general_info(struct rtw_dev *rtwdev)
388 {
389 	struct rtw_fifo_conf *fifo = &rtwdev->fifo;
390 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
391 	u16 total_size = H2C_PKT_HDR_SIZE + 4;
392 
393 	if (rtw_chip_wcpu_11n(rtwdev))
394 		return;
395 
396 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_GENERAL_INFO);
397 
398 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
399 
400 	GENERAL_INFO_SET_FW_TX_BOUNDARY(h2c_pkt,
401 					fifo->rsvd_fw_txbuf_addr -
402 					fifo->rsvd_boundary);
403 
404 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
405 }
406 
407 void
408 rtw_fw_send_phydm_info(struct rtw_dev *rtwdev)
409 {
410 	struct rtw_hal *hal = &rtwdev->hal;
411 	struct rtw_efuse *efuse = &rtwdev->efuse;
412 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
413 	u16 total_size = H2C_PKT_HDR_SIZE + 8;
414 	u8 fw_rf_type = 0;
415 
416 	if (rtw_chip_wcpu_11n(rtwdev))
417 		return;
418 
419 	if (hal->rf_type == RF_1T1R)
420 		fw_rf_type = FW_RF_1T1R;
421 	else if (hal->rf_type == RF_2T2R)
422 		fw_rf_type = FW_RF_2T2R;
423 
424 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_PHYDM_INFO);
425 
426 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
427 	PHYDM_INFO_SET_REF_TYPE(h2c_pkt, efuse->rfe_option);
428 	PHYDM_INFO_SET_RF_TYPE(h2c_pkt, fw_rf_type);
429 	PHYDM_INFO_SET_CUT_VER(h2c_pkt, hal->cut_version);
430 	PHYDM_INFO_SET_RX_ANT_STATUS(h2c_pkt, hal->antenna_tx);
431 	PHYDM_INFO_SET_TX_ANT_STATUS(h2c_pkt, hal->antenna_rx);
432 
433 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
434 }
435 
436 void rtw_fw_do_iqk(struct rtw_dev *rtwdev, struct rtw_iqk_para *para)
437 {
438 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
439 	u16 total_size = H2C_PKT_HDR_SIZE + 1;
440 
441 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_IQK);
442 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
443 	IQK_SET_CLEAR(h2c_pkt, para->clear);
444 	IQK_SET_SEGMENT_IQK(h2c_pkt, para->segment_iqk);
445 
446 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
447 }
448 EXPORT_SYMBOL(rtw_fw_do_iqk);
449 
450 void rtw_fw_inform_rfk_status(struct rtw_dev *rtwdev, bool start)
451 {
452 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
453 
454 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_WIFI_CALIBRATION);
455 
456 	RFK_SET_INFORM_START(h2c_pkt, start);
457 
458 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
459 }
460 EXPORT_SYMBOL(rtw_fw_inform_rfk_status);
461 
462 void rtw_fw_query_bt_info(struct rtw_dev *rtwdev)
463 {
464 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
465 
466 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_QUERY_BT_INFO);
467 
468 	SET_QUERY_BT_INFO(h2c_pkt, true);
469 
470 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
471 }
472 
473 void rtw_fw_wl_ch_info(struct rtw_dev *rtwdev, u8 link, u8 ch, u8 bw)
474 {
475 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
476 
477 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_WL_CH_INFO);
478 
479 	SET_WL_CH_INFO_LINK(h2c_pkt, link);
480 	SET_WL_CH_INFO_CHNL(h2c_pkt, ch);
481 	SET_WL_CH_INFO_BW(h2c_pkt, bw);
482 
483 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
484 }
485 
486 void rtw_fw_query_bt_mp_info(struct rtw_dev *rtwdev,
487 			     struct rtw_coex_info_req *req)
488 {
489 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
490 
491 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_QUERY_BT_MP_INFO);
492 
493 	SET_BT_MP_INFO_SEQ(h2c_pkt, req->seq);
494 	SET_BT_MP_INFO_OP_CODE(h2c_pkt, req->op_code);
495 	SET_BT_MP_INFO_PARA1(h2c_pkt, req->para1);
496 	SET_BT_MP_INFO_PARA2(h2c_pkt, req->para2);
497 	SET_BT_MP_INFO_PARA3(h2c_pkt, req->para3);
498 
499 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
500 }
501 
502 void rtw_fw_force_bt_tx_power(struct rtw_dev *rtwdev, u8 bt_pwr_dec_lvl)
503 {
504 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
505 	u8 index = 0 - bt_pwr_dec_lvl;
506 
507 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_FORCE_BT_TX_POWER);
508 
509 	SET_BT_TX_POWER_INDEX(h2c_pkt, index);
510 
511 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
512 }
513 
514 void rtw_fw_bt_ignore_wlan_action(struct rtw_dev *rtwdev, bool enable)
515 {
516 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
517 
518 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_IGNORE_WLAN_ACTION);
519 
520 	SET_IGNORE_WLAN_ACTION_EN(h2c_pkt, enable);
521 
522 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
523 }
524 
525 void rtw_fw_coex_tdma_type(struct rtw_dev *rtwdev,
526 			   u8 para1, u8 para2, u8 para3, u8 para4, u8 para5)
527 {
528 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
529 
530 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_COEX_TDMA_TYPE);
531 
532 	SET_COEX_TDMA_TYPE_PARA1(h2c_pkt, para1);
533 	SET_COEX_TDMA_TYPE_PARA2(h2c_pkt, para2);
534 	SET_COEX_TDMA_TYPE_PARA3(h2c_pkt, para3);
535 	SET_COEX_TDMA_TYPE_PARA4(h2c_pkt, para4);
536 	SET_COEX_TDMA_TYPE_PARA5(h2c_pkt, para5);
537 
538 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
539 }
540 
541 void rtw_fw_bt_wifi_control(struct rtw_dev *rtwdev, u8 op_code, u8 *data)
542 {
543 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
544 
545 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_BT_WIFI_CONTROL);
546 
547 	SET_BT_WIFI_CONTROL_OP_CODE(h2c_pkt, op_code);
548 
549 	SET_BT_WIFI_CONTROL_DATA1(h2c_pkt, *data);
550 	SET_BT_WIFI_CONTROL_DATA2(h2c_pkt, *(data + 1));
551 	SET_BT_WIFI_CONTROL_DATA3(h2c_pkt, *(data + 2));
552 	SET_BT_WIFI_CONTROL_DATA4(h2c_pkt, *(data + 3));
553 	SET_BT_WIFI_CONTROL_DATA5(h2c_pkt, *(data + 4));
554 
555 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
556 }
557 
558 void rtw_fw_send_rssi_info(struct rtw_dev *rtwdev, struct rtw_sta_info *si)
559 {
560 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
561 	u8 rssi = ewma_rssi_read(&si->avg_rssi);
562 	bool stbc_en = si->stbc_en ? true : false;
563 
564 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_RSSI_MONITOR);
565 
566 	SET_RSSI_INFO_MACID(h2c_pkt, si->mac_id);
567 	SET_RSSI_INFO_RSSI(h2c_pkt, rssi);
568 	SET_RSSI_INFO_STBC(h2c_pkt, stbc_en);
569 
570 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
571 }
572 
573 void rtw_fw_send_ra_info(struct rtw_dev *rtwdev, struct rtw_sta_info *si)
574 {
575 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
576 	bool no_update = si->updated;
577 	bool disable_pt = true;
578 
579 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_RA_INFO);
580 
581 	SET_RA_INFO_MACID(h2c_pkt, si->mac_id);
582 	SET_RA_INFO_RATE_ID(h2c_pkt, si->rate_id);
583 	SET_RA_INFO_INIT_RA_LVL(h2c_pkt, si->init_ra_lv);
584 	SET_RA_INFO_SGI_EN(h2c_pkt, si->sgi_enable);
585 	SET_RA_INFO_BW_MODE(h2c_pkt, si->bw_mode);
586 	SET_RA_INFO_LDPC(h2c_pkt, !!si->ldpc_en);
587 	SET_RA_INFO_NO_UPDATE(h2c_pkt, no_update);
588 	SET_RA_INFO_VHT_EN(h2c_pkt, si->vht_enable);
589 	SET_RA_INFO_DIS_PT(h2c_pkt, disable_pt);
590 	SET_RA_INFO_RA_MASK0(h2c_pkt, (si->ra_mask & 0xff));
591 	SET_RA_INFO_RA_MASK1(h2c_pkt, (si->ra_mask & 0xff00) >> 8);
592 	SET_RA_INFO_RA_MASK2(h2c_pkt, (si->ra_mask & 0xff0000) >> 16);
593 	SET_RA_INFO_RA_MASK3(h2c_pkt, (si->ra_mask & 0xff000000) >> 24);
594 
595 	si->init_ra_lv = 0;
596 	si->updated = true;
597 
598 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
599 }
600 
601 void rtw_fw_media_status_report(struct rtw_dev *rtwdev, u8 mac_id, bool connect)
602 {
603 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
604 
605 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_MEDIA_STATUS_RPT);
606 	MEDIA_STATUS_RPT_SET_OP_MODE(h2c_pkt, connect);
607 	MEDIA_STATUS_RPT_SET_MACID(h2c_pkt, mac_id);
608 
609 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
610 }
611 
612 void rtw_fw_update_wl_phy_info(struct rtw_dev *rtwdev)
613 {
614 	struct rtw_traffic_stats *stats = &rtwdev->stats;
615 	struct rtw_dm_info *dm_info = &rtwdev->dm_info;
616 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
617 
618 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_WL_PHY_INFO);
619 	SET_WL_PHY_INFO_TX_TP(h2c_pkt, stats->tx_throughput);
620 	SET_WL_PHY_INFO_RX_TP(h2c_pkt, stats->rx_throughput);
621 	SET_WL_PHY_INFO_TX_RATE_DESC(h2c_pkt, dm_info->tx_rate);
622 	SET_WL_PHY_INFO_RX_RATE_DESC(h2c_pkt, dm_info->curr_rx_rate);
623 	SET_WL_PHY_INFO_RX_EVM(h2c_pkt, dm_info->rx_evm_dbm[RF_PATH_A]);
624 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
625 }
626 
627 void rtw_fw_beacon_filter_config(struct rtw_dev *rtwdev, bool connect,
628 				 struct ieee80211_vif *vif)
629 {
630 	struct ieee80211_bss_conf *bss_conf = &vif->bss_conf;
631 	struct ieee80211_sta *sta = ieee80211_find_sta(vif, bss_conf->bssid);
632 	static const u8 rssi_min = 0, rssi_max = 100, rssi_offset = 100;
633 	struct rtw_sta_info *si =
634 		sta ? (struct rtw_sta_info *)sta->drv_priv : NULL;
635 	s32 threshold = bss_conf->cqm_rssi_thold + rssi_offset;
636 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
637 
638 	if (!rtw_fw_feature_check(&rtwdev->fw, FW_FEATURE_BCN_FILTER) || !si)
639 		return;
640 
641 	if (!connect) {
642 		SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_BCN_FILTER_OFFLOAD_P1);
643 		SET_BCN_FILTER_OFFLOAD_P1_ENABLE(h2c_pkt, connect);
644 		rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
645 
646 		return;
647 	}
648 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_BCN_FILTER_OFFLOAD_P0);
649 	ether_addr_copy(&h2c_pkt[1], bss_conf->bssid);
650 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
651 
652 	memset(h2c_pkt, 0, sizeof(h2c_pkt));
653 	threshold = clamp_t(s32, threshold, rssi_min, rssi_max);
654 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_BCN_FILTER_OFFLOAD_P1);
655 	SET_BCN_FILTER_OFFLOAD_P1_ENABLE(h2c_pkt, connect);
656 	SET_BCN_FILTER_OFFLOAD_P1_OFFLOAD_MODE(h2c_pkt,
657 					       BCN_FILTER_OFFLOAD_MODE_DEFAULT);
658 	SET_BCN_FILTER_OFFLOAD_P1_THRESHOLD(h2c_pkt, (u8)threshold);
659 	SET_BCN_FILTER_OFFLOAD_P1_BCN_LOSS_CNT(h2c_pkt, BCN_LOSS_CNT);
660 	SET_BCN_FILTER_OFFLOAD_P1_MACID(h2c_pkt, si->mac_id);
661 	SET_BCN_FILTER_OFFLOAD_P1_HYST(h2c_pkt, bss_conf->cqm_rssi_hyst);
662 	SET_BCN_FILTER_OFFLOAD_P1_BCN_INTERVAL(h2c_pkt, bss_conf->beacon_int);
663 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
664 }
665 
666 void rtw_fw_set_pwr_mode(struct rtw_dev *rtwdev)
667 {
668 	struct rtw_lps_conf *conf = &rtwdev->lps_conf;
669 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
670 
671 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_SET_PWR_MODE);
672 
673 	SET_PWR_MODE_SET_MODE(h2c_pkt, conf->mode);
674 	SET_PWR_MODE_SET_RLBM(h2c_pkt, conf->rlbm);
675 	SET_PWR_MODE_SET_SMART_PS(h2c_pkt, conf->smart_ps);
676 	SET_PWR_MODE_SET_AWAKE_INTERVAL(h2c_pkt, conf->awake_interval);
677 	SET_PWR_MODE_SET_PORT_ID(h2c_pkt, conf->port_id);
678 	SET_PWR_MODE_SET_PWR_STATE(h2c_pkt, conf->state);
679 
680 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
681 }
682 
683 void rtw_fw_set_keep_alive_cmd(struct rtw_dev *rtwdev, bool enable)
684 {
685 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
686 	struct rtw_fw_wow_keep_alive_para mode = {
687 		.adopt = true,
688 		.pkt_type = KEEP_ALIVE_NULL_PKT,
689 		.period = 5,
690 	};
691 
692 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_KEEP_ALIVE);
693 	SET_KEEP_ALIVE_ENABLE(h2c_pkt, enable);
694 	SET_KEEP_ALIVE_ADOPT(h2c_pkt, mode.adopt);
695 	SET_KEEP_ALIVE_PKT_TYPE(h2c_pkt, mode.pkt_type);
696 	SET_KEEP_ALIVE_CHECK_PERIOD(h2c_pkt, mode.period);
697 
698 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
699 }
700 
701 void rtw_fw_set_disconnect_decision_cmd(struct rtw_dev *rtwdev, bool enable)
702 {
703 	struct rtw_wow_param *rtw_wow = &rtwdev->wow;
704 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
705 	struct rtw_fw_wow_disconnect_para mode = {
706 		.adopt = true,
707 		.period = 30,
708 		.retry_count = 5,
709 	};
710 
711 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_DISCONNECT_DECISION);
712 
713 	if (test_bit(RTW_WOW_FLAG_EN_DISCONNECT, rtw_wow->flags)) {
714 		SET_DISCONNECT_DECISION_ENABLE(h2c_pkt, enable);
715 		SET_DISCONNECT_DECISION_ADOPT(h2c_pkt, mode.adopt);
716 		SET_DISCONNECT_DECISION_CHECK_PERIOD(h2c_pkt, mode.period);
717 		SET_DISCONNECT_DECISION_TRY_PKT_NUM(h2c_pkt, mode.retry_count);
718 	}
719 
720 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
721 }
722 
723 void rtw_fw_set_wowlan_ctrl_cmd(struct rtw_dev *rtwdev, bool enable)
724 {
725 	struct rtw_wow_param *rtw_wow = &rtwdev->wow;
726 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
727 
728 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_WOWLAN);
729 
730 	SET_WOWLAN_FUNC_ENABLE(h2c_pkt, enable);
731 	if (rtw_wow_mgd_linked(rtwdev)) {
732 		if (test_bit(RTW_WOW_FLAG_EN_MAGIC_PKT, rtw_wow->flags))
733 			SET_WOWLAN_MAGIC_PKT_ENABLE(h2c_pkt, enable);
734 		if (test_bit(RTW_WOW_FLAG_EN_DISCONNECT, rtw_wow->flags))
735 			SET_WOWLAN_DEAUTH_WAKEUP_ENABLE(h2c_pkt, enable);
736 		if (test_bit(RTW_WOW_FLAG_EN_REKEY_PKT, rtw_wow->flags))
737 			SET_WOWLAN_REKEY_WAKEUP_ENABLE(h2c_pkt, enable);
738 		if (rtw_wow->pattern_cnt)
739 			SET_WOWLAN_PATTERN_MATCH_ENABLE(h2c_pkt, enable);
740 	}
741 
742 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
743 }
744 
745 void rtw_fw_set_aoac_global_info_cmd(struct rtw_dev *rtwdev,
746 				     u8 pairwise_key_enc,
747 				     u8 group_key_enc)
748 {
749 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
750 
751 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_AOAC_GLOBAL_INFO);
752 
753 	SET_AOAC_GLOBAL_INFO_PAIRWISE_ENC_ALG(h2c_pkt, pairwise_key_enc);
754 	SET_AOAC_GLOBAL_INFO_GROUP_ENC_ALG(h2c_pkt, group_key_enc);
755 
756 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
757 }
758 
759 void rtw_fw_set_remote_wake_ctrl_cmd(struct rtw_dev *rtwdev, bool enable)
760 {
761 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
762 
763 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_REMOTE_WAKE_CTRL);
764 
765 	SET_REMOTE_WAKECTRL_ENABLE(h2c_pkt, enable);
766 
767 	if (rtw_wow_no_link(rtwdev))
768 		SET_REMOTE_WAKE_CTRL_NLO_OFFLOAD_EN(h2c_pkt, enable);
769 
770 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
771 }
772 
773 static u8 rtw_get_rsvd_page_location(struct rtw_dev *rtwdev,
774 				     enum rtw_rsvd_packet_type type)
775 {
776 	struct rtw_rsvd_page *rsvd_pkt;
777 	u8 location = 0;
778 
779 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
780 		if (type == rsvd_pkt->type)
781 			location = rsvd_pkt->page;
782 	}
783 
784 	return location;
785 }
786 
787 void rtw_fw_set_nlo_info(struct rtw_dev *rtwdev, bool enable)
788 {
789 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
790 	u8 loc_nlo;
791 
792 	loc_nlo = rtw_get_rsvd_page_location(rtwdev, RSVD_NLO_INFO);
793 
794 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_NLO_INFO);
795 
796 	SET_NLO_FUN_EN(h2c_pkt, enable);
797 	if (enable) {
798 		if (rtw_get_lps_deep_mode(rtwdev) != LPS_DEEP_MODE_NONE)
799 			SET_NLO_PS_32K(h2c_pkt, enable);
800 		SET_NLO_IGNORE_SECURITY(h2c_pkt, enable);
801 		SET_NLO_LOC_NLO_INFO(h2c_pkt, loc_nlo);
802 	}
803 
804 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
805 }
806 
807 void rtw_fw_set_pg_info(struct rtw_dev *rtwdev)
808 {
809 	struct rtw_lps_conf *conf = &rtwdev->lps_conf;
810 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
811 	u8 loc_pg, loc_dpk;
812 
813 	loc_pg = rtw_get_rsvd_page_location(rtwdev, RSVD_LPS_PG_INFO);
814 	loc_dpk = rtw_get_rsvd_page_location(rtwdev, RSVD_LPS_PG_DPK);
815 
816 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_LPS_PG_INFO);
817 
818 	LPS_PG_INFO_LOC(h2c_pkt, loc_pg);
819 	LPS_PG_DPK_LOC(h2c_pkt, loc_dpk);
820 	LPS_PG_SEC_CAM_EN(h2c_pkt, conf->sec_cam_backup);
821 	LPS_PG_PATTERN_CAM_EN(h2c_pkt, conf->pattern_cam_backup);
822 
823 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
824 }
825 
826 static u8 rtw_get_rsvd_page_probe_req_location(struct rtw_dev *rtwdev,
827 					       struct cfg80211_ssid *ssid)
828 {
829 	struct rtw_rsvd_page *rsvd_pkt;
830 	u8 location = 0;
831 
832 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
833 		if (rsvd_pkt->type != RSVD_PROBE_REQ)
834 			continue;
835 		if ((!ssid && !rsvd_pkt->ssid) ||
836 		    rtw_ssid_equal(rsvd_pkt->ssid, ssid))
837 			location = rsvd_pkt->page;
838 	}
839 
840 	return location;
841 }
842 
843 static u16 rtw_get_rsvd_page_probe_req_size(struct rtw_dev *rtwdev,
844 					    struct cfg80211_ssid *ssid)
845 {
846 	struct rtw_rsvd_page *rsvd_pkt;
847 	u16 size = 0;
848 
849 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
850 		if (rsvd_pkt->type != RSVD_PROBE_REQ)
851 			continue;
852 		if ((!ssid && !rsvd_pkt->ssid) ||
853 		    rtw_ssid_equal(rsvd_pkt->ssid, ssid))
854 			size = rsvd_pkt->probe_req_size;
855 	}
856 
857 	return size;
858 }
859 
860 void rtw_send_rsvd_page_h2c(struct rtw_dev *rtwdev)
861 {
862 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
863 	u8 location = 0;
864 
865 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_RSVD_PAGE);
866 
867 	location = rtw_get_rsvd_page_location(rtwdev, RSVD_PROBE_RESP);
868 	*(h2c_pkt + 1) = location;
869 	rtw_dbg(rtwdev, RTW_DBG_FW, "RSVD_PROBE_RESP loc: %d\n", location);
870 
871 	location = rtw_get_rsvd_page_location(rtwdev, RSVD_PS_POLL);
872 	*(h2c_pkt + 2) = location;
873 	rtw_dbg(rtwdev, RTW_DBG_FW, "RSVD_PS_POLL loc: %d\n", location);
874 
875 	location = rtw_get_rsvd_page_location(rtwdev, RSVD_NULL);
876 	*(h2c_pkt + 3) = location;
877 	rtw_dbg(rtwdev, RTW_DBG_FW, "RSVD_NULL loc: %d\n", location);
878 
879 	location = rtw_get_rsvd_page_location(rtwdev, RSVD_QOS_NULL);
880 	*(h2c_pkt + 4) = location;
881 	rtw_dbg(rtwdev, RTW_DBG_FW, "RSVD_QOS_NULL loc: %d\n", location);
882 
883 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
884 }
885 
886 static struct sk_buff *rtw_nlo_info_get(struct ieee80211_hw *hw)
887 {
888 	struct rtw_dev *rtwdev = hw->priv;
889 	struct rtw_chip_info *chip = rtwdev->chip;
890 	struct rtw_pno_request *pno_req = &rtwdev->wow.pno_req;
891 	struct rtw_nlo_info_hdr *nlo_hdr;
892 	struct cfg80211_ssid *ssid;
893 	struct sk_buff *skb;
894 	u8 *pos, loc;
895 	u32 size;
896 	int i;
897 
898 	if (!pno_req->inited || !pno_req->match_set_cnt)
899 		return NULL;
900 
901 	size = sizeof(struct rtw_nlo_info_hdr) + pno_req->match_set_cnt *
902 		      IEEE80211_MAX_SSID_LEN + chip->tx_pkt_desc_sz;
903 
904 	skb = alloc_skb(size, GFP_KERNEL);
905 	if (!skb)
906 		return NULL;
907 
908 	skb_reserve(skb, chip->tx_pkt_desc_sz);
909 
910 	nlo_hdr = skb_put_zero(skb, sizeof(struct rtw_nlo_info_hdr));
911 
912 	nlo_hdr->nlo_count = pno_req->match_set_cnt;
913 	nlo_hdr->hidden_ap_count = pno_req->match_set_cnt;
914 
915 	/* pattern check for firmware */
916 	memset(nlo_hdr->pattern_check, 0xA5, FW_NLO_INFO_CHECK_SIZE);
917 
918 	for (i = 0; i < pno_req->match_set_cnt; i++)
919 		nlo_hdr->ssid_len[i] = pno_req->match_sets[i].ssid.ssid_len;
920 
921 	for (i = 0; i < pno_req->match_set_cnt; i++) {
922 		ssid = &pno_req->match_sets[i].ssid;
923 		loc  = rtw_get_rsvd_page_probe_req_location(rtwdev, ssid);
924 		if (!loc) {
925 			rtw_err(rtwdev, "failed to get probe req rsvd loc\n");
926 			kfree_skb(skb);
927 			return NULL;
928 		}
929 		nlo_hdr->location[i] = loc;
930 	}
931 
932 	for (i = 0; i < pno_req->match_set_cnt; i++) {
933 		pos = skb_put_zero(skb, IEEE80211_MAX_SSID_LEN);
934 		memcpy(pos, pno_req->match_sets[i].ssid.ssid,
935 		       pno_req->match_sets[i].ssid.ssid_len);
936 	}
937 
938 	return skb;
939 }
940 
941 static struct sk_buff *rtw_cs_channel_info_get(struct ieee80211_hw *hw)
942 {
943 	struct rtw_dev *rtwdev = hw->priv;
944 	struct rtw_chip_info *chip = rtwdev->chip;
945 	struct rtw_pno_request *pno_req = &rtwdev->wow.pno_req;
946 	struct ieee80211_channel *channels = pno_req->channels;
947 	struct sk_buff *skb;
948 	int count =  pno_req->channel_cnt;
949 	u8 *pos;
950 	int i = 0;
951 
952 	skb = alloc_skb(4 * count + chip->tx_pkt_desc_sz, GFP_KERNEL);
953 	if (!skb)
954 		return NULL;
955 
956 	skb_reserve(skb, chip->tx_pkt_desc_sz);
957 
958 	for (i = 0; i < count; i++) {
959 		pos = skb_put_zero(skb, 4);
960 
961 		CHSW_INFO_SET_CH(pos, channels[i].hw_value);
962 
963 		if (channels[i].flags & IEEE80211_CHAN_RADAR)
964 			CHSW_INFO_SET_ACTION_ID(pos, 0);
965 		else
966 			CHSW_INFO_SET_ACTION_ID(pos, 1);
967 		CHSW_INFO_SET_TIMEOUT(pos, 1);
968 		CHSW_INFO_SET_PRI_CH_IDX(pos, 1);
969 		CHSW_INFO_SET_BW(pos, 0);
970 	}
971 
972 	return skb;
973 }
974 
975 static struct sk_buff *rtw_lps_pg_dpk_get(struct ieee80211_hw *hw)
976 {
977 	struct rtw_dev *rtwdev = hw->priv;
978 	struct rtw_chip_info *chip = rtwdev->chip;
979 	struct rtw_dpk_info *dpk_info = &rtwdev->dm_info.dpk_info;
980 	struct rtw_lps_pg_dpk_hdr *dpk_hdr;
981 	struct sk_buff *skb;
982 	u32 size;
983 
984 	size = chip->tx_pkt_desc_sz + sizeof(*dpk_hdr);
985 	skb = alloc_skb(size, GFP_KERNEL);
986 	if (!skb)
987 		return NULL;
988 
989 	skb_reserve(skb, chip->tx_pkt_desc_sz);
990 	dpk_hdr = skb_put_zero(skb, sizeof(*dpk_hdr));
991 	dpk_hdr->dpk_ch = dpk_info->dpk_ch;
992 	dpk_hdr->dpk_path_ok = dpk_info->dpk_path_ok[0];
993 	memcpy(dpk_hdr->dpk_txagc, dpk_info->dpk_txagc, 2);
994 	memcpy(dpk_hdr->dpk_gs, dpk_info->dpk_gs, 4);
995 	memcpy(dpk_hdr->coef, dpk_info->coef, 160);
996 
997 	return skb;
998 }
999 
1000 static struct sk_buff *rtw_lps_pg_info_get(struct ieee80211_hw *hw)
1001 {
1002 	struct rtw_dev *rtwdev = hw->priv;
1003 	struct rtw_chip_info *chip = rtwdev->chip;
1004 	struct rtw_lps_conf *conf = &rtwdev->lps_conf;
1005 	struct rtw_lps_pg_info_hdr *pg_info_hdr;
1006 	struct rtw_wow_param *rtw_wow = &rtwdev->wow;
1007 	struct sk_buff *skb;
1008 	u32 size;
1009 
1010 	size = chip->tx_pkt_desc_sz + sizeof(*pg_info_hdr);
1011 	skb = alloc_skb(size, GFP_KERNEL);
1012 	if (!skb)
1013 		return NULL;
1014 
1015 	skb_reserve(skb, chip->tx_pkt_desc_sz);
1016 	pg_info_hdr = skb_put_zero(skb, sizeof(*pg_info_hdr));
1017 	pg_info_hdr->tx_bu_page_count = rtwdev->fifo.rsvd_drv_pg_num;
1018 	pg_info_hdr->macid = find_first_bit(rtwdev->mac_id_map, RTW_MAX_MAC_ID_NUM);
1019 	pg_info_hdr->sec_cam_count =
1020 		rtw_sec_cam_pg_backup(rtwdev, pg_info_hdr->sec_cam);
1021 	pg_info_hdr->pattern_count = rtw_wow->pattern_cnt;
1022 
1023 	conf->sec_cam_backup = pg_info_hdr->sec_cam_count != 0;
1024 	conf->pattern_cam_backup = rtw_wow->pattern_cnt != 0;
1025 
1026 	return skb;
1027 }
1028 
1029 static struct sk_buff *rtw_get_rsvd_page_skb(struct ieee80211_hw *hw,
1030 					     struct rtw_rsvd_page *rsvd_pkt)
1031 {
1032 	struct ieee80211_vif *vif;
1033 	struct rtw_vif *rtwvif;
1034 	struct sk_buff *skb_new;
1035 	struct cfg80211_ssid *ssid;
1036 
1037 	if (rsvd_pkt->type == RSVD_DUMMY) {
1038 		skb_new = alloc_skb(1, GFP_KERNEL);
1039 		if (!skb_new)
1040 			return NULL;
1041 
1042 		skb_put(skb_new, 1);
1043 		return skb_new;
1044 	}
1045 
1046 	rtwvif = rsvd_pkt->rtwvif;
1047 	if (!rtwvif)
1048 		return NULL;
1049 
1050 	vif = rtwvif_to_vif(rtwvif);
1051 
1052 	switch (rsvd_pkt->type) {
1053 	case RSVD_BEACON:
1054 		skb_new = ieee80211_beacon_get(hw, vif);
1055 		break;
1056 	case RSVD_PS_POLL:
1057 		skb_new = ieee80211_pspoll_get(hw, vif);
1058 		break;
1059 	case RSVD_PROBE_RESP:
1060 		skb_new = ieee80211_proberesp_get(hw, vif);
1061 		break;
1062 	case RSVD_NULL:
1063 		skb_new = ieee80211_nullfunc_get(hw, vif, false);
1064 		break;
1065 	case RSVD_QOS_NULL:
1066 		skb_new = ieee80211_nullfunc_get(hw, vif, true);
1067 		break;
1068 	case RSVD_LPS_PG_DPK:
1069 		skb_new = rtw_lps_pg_dpk_get(hw);
1070 		break;
1071 	case RSVD_LPS_PG_INFO:
1072 		skb_new = rtw_lps_pg_info_get(hw);
1073 		break;
1074 	case RSVD_PROBE_REQ:
1075 		ssid = (struct cfg80211_ssid *)rsvd_pkt->ssid;
1076 		if (ssid)
1077 			skb_new = ieee80211_probereq_get(hw, vif->addr,
1078 							 ssid->ssid,
1079 							 ssid->ssid_len, 0);
1080 		else
1081 			skb_new = ieee80211_probereq_get(hw, vif->addr, NULL, 0, 0);
1082 		if (skb_new)
1083 			rsvd_pkt->probe_req_size = (u16)skb_new->len;
1084 		break;
1085 	case RSVD_NLO_INFO:
1086 		skb_new = rtw_nlo_info_get(hw);
1087 		break;
1088 	case RSVD_CH_INFO:
1089 		skb_new = rtw_cs_channel_info_get(hw);
1090 		break;
1091 	default:
1092 		return NULL;
1093 	}
1094 
1095 	if (!skb_new)
1096 		return NULL;
1097 
1098 	return skb_new;
1099 }
1100 
1101 static void rtw_fill_rsvd_page_desc(struct rtw_dev *rtwdev, struct sk_buff *skb,
1102 				    enum rtw_rsvd_packet_type type)
1103 {
1104 	struct rtw_tx_pkt_info pkt_info = {0};
1105 	struct rtw_chip_info *chip = rtwdev->chip;
1106 	u8 *pkt_desc;
1107 
1108 	rtw_tx_rsvd_page_pkt_info_update(rtwdev, &pkt_info, skb, type);
1109 	pkt_desc = skb_push(skb, chip->tx_pkt_desc_sz);
1110 	memset(pkt_desc, 0, chip->tx_pkt_desc_sz);
1111 	rtw_tx_fill_tx_desc(&pkt_info, skb);
1112 }
1113 
1114 static inline u8 rtw_len_to_page(unsigned int len, u8 page_size)
1115 {
1116 	return DIV_ROUND_UP(len, page_size);
1117 }
1118 
1119 static void rtw_rsvd_page_list_to_buf(struct rtw_dev *rtwdev, u8 page_size,
1120 				      u8 page_margin, u32 page, u8 *buf,
1121 				      struct rtw_rsvd_page *rsvd_pkt)
1122 {
1123 	struct sk_buff *skb = rsvd_pkt->skb;
1124 
1125 	if (page >= 1)
1126 		memcpy(buf + page_margin + page_size * (page - 1),
1127 		       skb->data, skb->len);
1128 	else
1129 		memcpy(buf, skb->data, skb->len);
1130 }
1131 
1132 static struct rtw_rsvd_page *rtw_alloc_rsvd_page(struct rtw_dev *rtwdev,
1133 						 enum rtw_rsvd_packet_type type,
1134 						 bool txdesc)
1135 {
1136 	struct rtw_rsvd_page *rsvd_pkt = NULL;
1137 
1138 	rsvd_pkt = kzalloc(sizeof(*rsvd_pkt), GFP_KERNEL);
1139 
1140 	if (!rsvd_pkt)
1141 		return NULL;
1142 
1143 	INIT_LIST_HEAD(&rsvd_pkt->vif_list);
1144 	INIT_LIST_HEAD(&rsvd_pkt->build_list);
1145 	rsvd_pkt->type = type;
1146 	rsvd_pkt->add_txdesc = txdesc;
1147 
1148 	return rsvd_pkt;
1149 }
1150 
1151 static void rtw_insert_rsvd_page(struct rtw_dev *rtwdev,
1152 				 struct rtw_vif *rtwvif,
1153 				 struct rtw_rsvd_page *rsvd_pkt)
1154 {
1155 	lockdep_assert_held(&rtwdev->mutex);
1156 
1157 	list_add_tail(&rsvd_pkt->vif_list, &rtwvif->rsvd_page_list);
1158 }
1159 
1160 static void rtw_add_rsvd_page(struct rtw_dev *rtwdev,
1161 			      struct rtw_vif *rtwvif,
1162 			      enum rtw_rsvd_packet_type type,
1163 			      bool txdesc)
1164 {
1165 	struct rtw_rsvd_page *rsvd_pkt;
1166 
1167 	rsvd_pkt = rtw_alloc_rsvd_page(rtwdev, type, txdesc);
1168 	if (!rsvd_pkt) {
1169 		rtw_err(rtwdev, "failed to alloc rsvd page %d\n", type);
1170 		return;
1171 	}
1172 
1173 	rsvd_pkt->rtwvif = rtwvif;
1174 	rtw_insert_rsvd_page(rtwdev, rtwvif, rsvd_pkt);
1175 }
1176 
1177 static void rtw_add_rsvd_page_probe_req(struct rtw_dev *rtwdev,
1178 					struct rtw_vif *rtwvif,
1179 					struct cfg80211_ssid *ssid)
1180 {
1181 	struct rtw_rsvd_page *rsvd_pkt;
1182 
1183 	rsvd_pkt = rtw_alloc_rsvd_page(rtwdev, RSVD_PROBE_REQ, true);
1184 	if (!rsvd_pkt) {
1185 		rtw_err(rtwdev, "failed to alloc probe req rsvd page\n");
1186 		return;
1187 	}
1188 
1189 	rsvd_pkt->rtwvif = rtwvif;
1190 	rsvd_pkt->ssid = ssid;
1191 	rtw_insert_rsvd_page(rtwdev, rtwvif, rsvd_pkt);
1192 }
1193 
1194 void rtw_remove_rsvd_page(struct rtw_dev *rtwdev,
1195 			  struct rtw_vif *rtwvif)
1196 {
1197 	struct rtw_rsvd_page *rsvd_pkt, *tmp;
1198 
1199 	lockdep_assert_held(&rtwdev->mutex);
1200 
1201 	/* remove all of the rsvd pages for vif */
1202 	list_for_each_entry_safe(rsvd_pkt, tmp, &rtwvif->rsvd_page_list,
1203 				 vif_list) {
1204 		list_del(&rsvd_pkt->vif_list);
1205 		if (!list_empty(&rsvd_pkt->build_list))
1206 			list_del(&rsvd_pkt->build_list);
1207 		kfree(rsvd_pkt);
1208 	}
1209 }
1210 
1211 void rtw_add_rsvd_page_bcn(struct rtw_dev *rtwdev,
1212 			   struct rtw_vif *rtwvif)
1213 {
1214 	struct ieee80211_vif *vif = rtwvif_to_vif(rtwvif);
1215 
1216 	if (vif->type != NL80211_IFTYPE_AP &&
1217 	    vif->type != NL80211_IFTYPE_ADHOC &&
1218 	    vif->type != NL80211_IFTYPE_MESH_POINT) {
1219 		rtw_warn(rtwdev, "Cannot add beacon rsvd page for %d\n",
1220 			 vif->type);
1221 		return;
1222 	}
1223 
1224 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_BEACON, false);
1225 }
1226 
1227 void rtw_add_rsvd_page_pno(struct rtw_dev *rtwdev,
1228 			   struct rtw_vif *rtwvif)
1229 {
1230 	struct ieee80211_vif *vif = rtwvif_to_vif(rtwvif);
1231 	struct rtw_wow_param *rtw_wow = &rtwdev->wow;
1232 	struct rtw_pno_request *rtw_pno_req = &rtw_wow->pno_req;
1233 	struct cfg80211_ssid *ssid;
1234 	int i;
1235 
1236 	if (vif->type != NL80211_IFTYPE_STATION) {
1237 		rtw_warn(rtwdev, "Cannot add PNO rsvd page for %d\n",
1238 			 vif->type);
1239 		return;
1240 	}
1241 
1242 	for (i = 0 ; i < rtw_pno_req->match_set_cnt; i++) {
1243 		ssid = &rtw_pno_req->match_sets[i].ssid;
1244 		rtw_add_rsvd_page_probe_req(rtwdev, rtwvif, ssid);
1245 	}
1246 
1247 	rtw_add_rsvd_page_probe_req(rtwdev, rtwvif, NULL);
1248 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_NLO_INFO, false);
1249 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_CH_INFO, true);
1250 }
1251 
1252 void rtw_add_rsvd_page_sta(struct rtw_dev *rtwdev,
1253 			   struct rtw_vif *rtwvif)
1254 {
1255 	struct ieee80211_vif *vif = rtwvif_to_vif(rtwvif);
1256 
1257 	if (vif->type != NL80211_IFTYPE_STATION) {
1258 		rtw_warn(rtwdev, "Cannot add sta rsvd page for %d\n",
1259 			 vif->type);
1260 		return;
1261 	}
1262 
1263 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_PS_POLL, true);
1264 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_QOS_NULL, true);
1265 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_NULL, true);
1266 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_LPS_PG_DPK, true);
1267 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_LPS_PG_INFO, true);
1268 }
1269 
1270 int rtw_fw_write_data_rsvd_page(struct rtw_dev *rtwdev, u16 pg_addr,
1271 				u8 *buf, u32 size)
1272 {
1273 	u8 bckp[2];
1274 	u8 val;
1275 	u16 rsvd_pg_head;
1276 	u32 bcn_valid_addr;
1277 	u32 bcn_valid_mask;
1278 	int ret;
1279 
1280 	lockdep_assert_held(&rtwdev->mutex);
1281 
1282 	if (!size)
1283 		return -EINVAL;
1284 
1285 	if (rtw_chip_wcpu_11n(rtwdev)) {
1286 		rtw_write32_set(rtwdev, REG_DWBCN0_CTRL, BIT_BCN_VALID);
1287 	} else {
1288 		pg_addr &= BIT_MASK_BCN_HEAD_1_V1;
1289 		pg_addr |= BIT_BCN_VALID_V1;
1290 		rtw_write16(rtwdev, REG_FIFOPAGE_CTRL_2, pg_addr);
1291 	}
1292 
1293 	val = rtw_read8(rtwdev, REG_CR + 1);
1294 	bckp[0] = val;
1295 	val |= BIT_ENSWBCN >> 8;
1296 	rtw_write8(rtwdev, REG_CR + 1, val);
1297 
1298 	val = rtw_read8(rtwdev, REG_FWHW_TXQ_CTRL + 2);
1299 	bckp[1] = val;
1300 	val &= ~(BIT_EN_BCNQ_DL >> 16);
1301 	rtw_write8(rtwdev, REG_FWHW_TXQ_CTRL + 2, val);
1302 
1303 	ret = rtw_hci_write_data_rsvd_page(rtwdev, buf, size);
1304 	if (ret) {
1305 		rtw_err(rtwdev, "failed to write data to rsvd page\n");
1306 		goto restore;
1307 	}
1308 
1309 	if (rtw_chip_wcpu_11n(rtwdev)) {
1310 		bcn_valid_addr = REG_DWBCN0_CTRL;
1311 		bcn_valid_mask = BIT_BCN_VALID;
1312 	} else {
1313 		bcn_valid_addr = REG_FIFOPAGE_CTRL_2;
1314 		bcn_valid_mask = BIT_BCN_VALID_V1;
1315 	}
1316 
1317 	if (!check_hw_ready(rtwdev, bcn_valid_addr, bcn_valid_mask, 1)) {
1318 		rtw_err(rtwdev, "error beacon valid\n");
1319 		ret = -EBUSY;
1320 	}
1321 
1322 restore:
1323 	rsvd_pg_head = rtwdev->fifo.rsvd_boundary;
1324 	rtw_write16(rtwdev, REG_FIFOPAGE_CTRL_2,
1325 		    rsvd_pg_head | BIT_BCN_VALID_V1);
1326 	rtw_write8(rtwdev, REG_FWHW_TXQ_CTRL + 2, bckp[1]);
1327 	rtw_write8(rtwdev, REG_CR + 1, bckp[0]);
1328 
1329 	return ret;
1330 }
1331 
1332 static int rtw_download_drv_rsvd_page(struct rtw_dev *rtwdev, u8 *buf, u32 size)
1333 {
1334 	u32 pg_size;
1335 	u32 pg_num = 0;
1336 	u16 pg_addr = 0;
1337 
1338 	pg_size = rtwdev->chip->page_size;
1339 	pg_num = size / pg_size + ((size & (pg_size - 1)) ? 1 : 0);
1340 	if (pg_num > rtwdev->fifo.rsvd_drv_pg_num)
1341 		return -ENOMEM;
1342 
1343 	pg_addr = rtwdev->fifo.rsvd_drv_addr;
1344 
1345 	return rtw_fw_write_data_rsvd_page(rtwdev, pg_addr, buf, size);
1346 }
1347 
1348 static void __rtw_build_rsvd_page_reset(struct rtw_dev *rtwdev)
1349 {
1350 	struct rtw_rsvd_page *rsvd_pkt, *tmp;
1351 
1352 	list_for_each_entry_safe(rsvd_pkt, tmp, &rtwdev->rsvd_page_list,
1353 				 build_list) {
1354 		list_del_init(&rsvd_pkt->build_list);
1355 
1356 		/* Don't free except for the dummy rsvd page,
1357 		 * others will be freed when removing vif
1358 		 */
1359 		if (rsvd_pkt->type == RSVD_DUMMY)
1360 			kfree(rsvd_pkt);
1361 	}
1362 }
1363 
1364 static void rtw_build_rsvd_page_iter(void *data, u8 *mac,
1365 				     struct ieee80211_vif *vif)
1366 {
1367 	struct rtw_dev *rtwdev = data;
1368 	struct rtw_vif *rtwvif = (struct rtw_vif *)vif->drv_priv;
1369 	struct rtw_rsvd_page *rsvd_pkt;
1370 
1371 	list_for_each_entry(rsvd_pkt, &rtwvif->rsvd_page_list, vif_list) {
1372 		if (rsvd_pkt->type == RSVD_BEACON)
1373 			list_add(&rsvd_pkt->build_list,
1374 				 &rtwdev->rsvd_page_list);
1375 		else
1376 			list_add_tail(&rsvd_pkt->build_list,
1377 				      &rtwdev->rsvd_page_list);
1378 	}
1379 }
1380 
1381 static int  __rtw_build_rsvd_page_from_vifs(struct rtw_dev *rtwdev)
1382 {
1383 	struct rtw_rsvd_page *rsvd_pkt;
1384 
1385 	__rtw_build_rsvd_page_reset(rtwdev);
1386 
1387 	/* gather rsvd page from vifs */
1388 	rtw_iterate_vifs_atomic(rtwdev, rtw_build_rsvd_page_iter, rtwdev);
1389 
1390 	rsvd_pkt = list_first_entry_or_null(&rtwdev->rsvd_page_list,
1391 					    struct rtw_rsvd_page, build_list);
1392 	if (!rsvd_pkt) {
1393 		WARN(1, "Should not have an empty reserved page\n");
1394 		return -EINVAL;
1395 	}
1396 
1397 	/* the first rsvd should be beacon, otherwise add a dummy one */
1398 	if (rsvd_pkt->type != RSVD_BEACON) {
1399 		struct rtw_rsvd_page *dummy_pkt;
1400 
1401 		dummy_pkt = rtw_alloc_rsvd_page(rtwdev, RSVD_DUMMY, false);
1402 		if (!dummy_pkt) {
1403 			rtw_err(rtwdev, "failed to alloc dummy rsvd page\n");
1404 			return -ENOMEM;
1405 		}
1406 
1407 		list_add(&dummy_pkt->build_list, &rtwdev->rsvd_page_list);
1408 	}
1409 
1410 	return 0;
1411 }
1412 
1413 static u8 *rtw_build_rsvd_page(struct rtw_dev *rtwdev, u32 *size)
1414 {
1415 	struct ieee80211_hw *hw = rtwdev->hw;
1416 	struct rtw_chip_info *chip = rtwdev->chip;
1417 	struct sk_buff *iter;
1418 	struct rtw_rsvd_page *rsvd_pkt;
1419 	u32 page = 0;
1420 	u8 total_page = 0;
1421 	u8 page_size, page_margin, tx_desc_sz;
1422 	u8 *buf;
1423 	int ret;
1424 
1425 	page_size = chip->page_size;
1426 	tx_desc_sz = chip->tx_pkt_desc_sz;
1427 	page_margin = page_size - tx_desc_sz;
1428 
1429 	ret = __rtw_build_rsvd_page_from_vifs(rtwdev);
1430 	if (ret) {
1431 		rtw_err(rtwdev,
1432 			"failed to build rsvd page from vifs, ret %d\n", ret);
1433 		return NULL;
1434 	}
1435 
1436 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
1437 		iter = rtw_get_rsvd_page_skb(hw, rsvd_pkt);
1438 		if (!iter) {
1439 			rtw_err(rtwdev, "failed to build rsvd packet\n");
1440 			goto release_skb;
1441 		}
1442 
1443 		/* Fill the tx_desc for the rsvd pkt that requires one.
1444 		 * And iter->len will be added with size of tx_desc_sz.
1445 		 */
1446 		if (rsvd_pkt->add_txdesc)
1447 			rtw_fill_rsvd_page_desc(rtwdev, iter, rsvd_pkt->type);
1448 
1449 		rsvd_pkt->skb = iter;
1450 		rsvd_pkt->page = total_page;
1451 
1452 		/* Reserved page is downloaded via TX path, and TX path will
1453 		 * generate a tx_desc at the header to describe length of
1454 		 * the buffer. If we are not counting page numbers with the
1455 		 * size of tx_desc added at the first rsvd_pkt (usually a
1456 		 * beacon, firmware default refer to the first page as the
1457 		 * content of beacon), we could generate a buffer which size
1458 		 * is smaller than the actual size of the whole rsvd_page
1459 		 */
1460 		if (total_page == 0) {
1461 			if (rsvd_pkt->type != RSVD_BEACON &&
1462 			    rsvd_pkt->type != RSVD_DUMMY) {
1463 				rtw_err(rtwdev, "first page should be a beacon\n");
1464 				goto release_skb;
1465 			}
1466 			total_page += rtw_len_to_page(iter->len + tx_desc_sz,
1467 						      page_size);
1468 		} else {
1469 			total_page += rtw_len_to_page(iter->len, page_size);
1470 		}
1471 	}
1472 
1473 	if (total_page > rtwdev->fifo.rsvd_drv_pg_num) {
1474 		rtw_err(rtwdev, "rsvd page over size: %d\n", total_page);
1475 		goto release_skb;
1476 	}
1477 
1478 	*size = (total_page - 1) * page_size + page_margin;
1479 	buf = kzalloc(*size, GFP_KERNEL);
1480 	if (!buf)
1481 		goto release_skb;
1482 
1483 	/* Copy the content of each rsvd_pkt to the buf, and they should
1484 	 * be aligned to the pages.
1485 	 *
1486 	 * Note that the first rsvd_pkt is a beacon no matter what vif->type.
1487 	 * And that rsvd_pkt does not require tx_desc because when it goes
1488 	 * through TX path, the TX path will generate one for it.
1489 	 */
1490 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
1491 		rtw_rsvd_page_list_to_buf(rtwdev, page_size, page_margin,
1492 					  page, buf, rsvd_pkt);
1493 		if (page == 0)
1494 			page += rtw_len_to_page(rsvd_pkt->skb->len +
1495 						tx_desc_sz, page_size);
1496 		else
1497 			page += rtw_len_to_page(rsvd_pkt->skb->len, page_size);
1498 
1499 		kfree_skb(rsvd_pkt->skb);
1500 		rsvd_pkt->skb = NULL;
1501 	}
1502 
1503 	return buf;
1504 
1505 release_skb:
1506 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
1507 		kfree_skb(rsvd_pkt->skb);
1508 		rsvd_pkt->skb = NULL;
1509 	}
1510 
1511 	return NULL;
1512 }
1513 
1514 static int rtw_download_beacon(struct rtw_dev *rtwdev)
1515 {
1516 	struct ieee80211_hw *hw = rtwdev->hw;
1517 	struct rtw_rsvd_page *rsvd_pkt;
1518 	struct sk_buff *skb;
1519 	int ret = 0;
1520 
1521 	rsvd_pkt = list_first_entry_or_null(&rtwdev->rsvd_page_list,
1522 					    struct rtw_rsvd_page, build_list);
1523 	if (!rsvd_pkt) {
1524 		rtw_err(rtwdev, "failed to get rsvd page from build list\n");
1525 		return -ENOENT;
1526 	}
1527 
1528 	if (rsvd_pkt->type != RSVD_BEACON &&
1529 	    rsvd_pkt->type != RSVD_DUMMY) {
1530 		rtw_err(rtwdev, "invalid rsvd page type %d, should be beacon or dummy\n",
1531 			rsvd_pkt->type);
1532 		return -EINVAL;
1533 	}
1534 
1535 	skb = rtw_get_rsvd_page_skb(hw, rsvd_pkt);
1536 	if (!skb) {
1537 		rtw_err(rtwdev, "failed to get beacon skb\n");
1538 		return -ENOMEM;
1539 	}
1540 
1541 	ret = rtw_download_drv_rsvd_page(rtwdev, skb->data, skb->len);
1542 	if (ret)
1543 		rtw_err(rtwdev, "failed to download drv rsvd page\n");
1544 
1545 	dev_kfree_skb(skb);
1546 
1547 	return ret;
1548 }
1549 
1550 int rtw_fw_download_rsvd_page(struct rtw_dev *rtwdev)
1551 {
1552 	u8 *buf;
1553 	u32 size;
1554 	int ret;
1555 
1556 	buf = rtw_build_rsvd_page(rtwdev, &size);
1557 	if (!buf) {
1558 		rtw_err(rtwdev, "failed to build rsvd page pkt\n");
1559 		return -ENOMEM;
1560 	}
1561 
1562 	ret = rtw_download_drv_rsvd_page(rtwdev, buf, size);
1563 	if (ret) {
1564 		rtw_err(rtwdev, "failed to download drv rsvd page\n");
1565 		goto free;
1566 	}
1567 
1568 	/* The last thing is to download the *ONLY* beacon again, because
1569 	 * the previous tx_desc is to describe the total rsvd page. Download
1570 	 * the beacon again to replace the TX desc header, and we will get
1571 	 * a correct tx_desc for the beacon in the rsvd page.
1572 	 */
1573 	ret = rtw_download_beacon(rtwdev);
1574 	if (ret) {
1575 		rtw_err(rtwdev, "failed to download beacon\n");
1576 		goto free;
1577 	}
1578 
1579 free:
1580 	kfree(buf);
1581 
1582 	return ret;
1583 }
1584 
1585 static void rtw_fw_read_fifo_page(struct rtw_dev *rtwdev, u32 offset, u32 size,
1586 				  u32 *buf, u32 residue, u16 start_pg)
1587 {
1588 	u32 i;
1589 	u16 idx = 0;
1590 	u16 ctl;
1591 
1592 	ctl = rtw_read16(rtwdev, REG_PKTBUF_DBG_CTRL) & 0xf000;
1593 	/* disable rx clock gate */
1594 	rtw_write32_set(rtwdev, REG_RCR, BIT_DISGCLK);
1595 
1596 	do {
1597 		rtw_write16(rtwdev, REG_PKTBUF_DBG_CTRL, start_pg | ctl);
1598 
1599 		for (i = FIFO_DUMP_ADDR + residue;
1600 		     i < FIFO_DUMP_ADDR + FIFO_PAGE_SIZE; i += 4) {
1601 			buf[idx++] = rtw_read32(rtwdev, i);
1602 			size -= 4;
1603 			if (size == 0)
1604 				goto out;
1605 		}
1606 
1607 		residue = 0;
1608 		start_pg++;
1609 	} while (size);
1610 
1611 out:
1612 	rtw_write16(rtwdev, REG_PKTBUF_DBG_CTRL, ctl);
1613 	/* restore rx clock gate */
1614 	rtw_write32_clr(rtwdev, REG_RCR, BIT_DISGCLK);
1615 }
1616 
1617 static void rtw_fw_read_fifo(struct rtw_dev *rtwdev, enum rtw_fw_fifo_sel sel,
1618 			     u32 offset, u32 size, u32 *buf)
1619 {
1620 	struct rtw_chip_info *chip = rtwdev->chip;
1621 	u32 start_pg, residue;
1622 
1623 	if (sel >= RTW_FW_FIFO_MAX) {
1624 		rtw_dbg(rtwdev, RTW_DBG_FW, "wrong fw fifo sel\n");
1625 		return;
1626 	}
1627 	if (sel == RTW_FW_FIFO_SEL_RSVD_PAGE)
1628 		offset += rtwdev->fifo.rsvd_boundary << TX_PAGE_SIZE_SHIFT;
1629 	residue = offset & (FIFO_PAGE_SIZE - 1);
1630 	start_pg = (offset >> FIFO_PAGE_SIZE_SHIFT) + chip->fw_fifo_addr[sel];
1631 
1632 	rtw_fw_read_fifo_page(rtwdev, offset, size, buf, residue, start_pg);
1633 }
1634 
1635 static bool rtw_fw_dump_check_size(struct rtw_dev *rtwdev,
1636 				   enum rtw_fw_fifo_sel sel,
1637 				   u32 start_addr, u32 size)
1638 {
1639 	switch (sel) {
1640 	case RTW_FW_FIFO_SEL_TX:
1641 	case RTW_FW_FIFO_SEL_RX:
1642 		if ((start_addr + size) > rtwdev->chip->fw_fifo_addr[sel])
1643 			return false;
1644 		fallthrough;
1645 	default:
1646 		return true;
1647 	}
1648 }
1649 
1650 int rtw_fw_dump_fifo(struct rtw_dev *rtwdev, u8 fifo_sel, u32 addr, u32 size,
1651 		     u32 *buffer)
1652 {
1653 	if (!rtwdev->chip->fw_fifo_addr[0]) {
1654 		rtw_dbg(rtwdev, RTW_DBG_FW, "chip not support dump fw fifo\n");
1655 		return -ENOTSUPP;
1656 	}
1657 
1658 	if (size == 0 || !buffer)
1659 		return -EINVAL;
1660 
1661 	if (size & 0x3) {
1662 		rtw_dbg(rtwdev, RTW_DBG_FW, "not 4byte alignment\n");
1663 		return -EINVAL;
1664 	}
1665 
1666 	if (!rtw_fw_dump_check_size(rtwdev, fifo_sel, addr, size)) {
1667 		rtw_dbg(rtwdev, RTW_DBG_FW, "fw fifo dump size overflow\n");
1668 		return -EINVAL;
1669 	}
1670 
1671 	rtw_fw_read_fifo(rtwdev, fifo_sel, addr, size, buffer);
1672 
1673 	return 0;
1674 }
1675 
1676 static void __rtw_fw_update_pkt(struct rtw_dev *rtwdev, u8 pkt_id, u16 size,
1677 				u8 location)
1678 {
1679 	struct rtw_chip_info *chip = rtwdev->chip;
1680 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1681 	u16 total_size = H2C_PKT_HDR_SIZE + H2C_PKT_UPDATE_PKT_LEN;
1682 
1683 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_UPDATE_PKT);
1684 
1685 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
1686 	UPDATE_PKT_SET_PKT_ID(h2c_pkt, pkt_id);
1687 	UPDATE_PKT_SET_LOCATION(h2c_pkt, location);
1688 
1689 	/* include txdesc size */
1690 	size += chip->tx_pkt_desc_sz;
1691 	UPDATE_PKT_SET_SIZE(h2c_pkt, size);
1692 
1693 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
1694 }
1695 
1696 void rtw_fw_update_pkt_probe_req(struct rtw_dev *rtwdev,
1697 				 struct cfg80211_ssid *ssid)
1698 {
1699 	u8 loc;
1700 	u16 size;
1701 
1702 	loc = rtw_get_rsvd_page_probe_req_location(rtwdev, ssid);
1703 	if (!loc) {
1704 		rtw_err(rtwdev, "failed to get probe_req rsvd loc\n");
1705 		return;
1706 	}
1707 
1708 	size = rtw_get_rsvd_page_probe_req_size(rtwdev, ssid);
1709 	if (!size) {
1710 		rtw_err(rtwdev, "failed to get probe_req rsvd size\n");
1711 		return;
1712 	}
1713 
1714 	__rtw_fw_update_pkt(rtwdev, RTW_PACKET_PROBE_REQ, size, loc);
1715 }
1716 
1717 void rtw_fw_channel_switch(struct rtw_dev *rtwdev, bool enable)
1718 {
1719 	struct rtw_pno_request *rtw_pno_req = &rtwdev->wow.pno_req;
1720 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1721 	u16 total_size = H2C_PKT_HDR_SIZE + H2C_PKT_CH_SWITCH_LEN;
1722 	u8 loc_ch_info;
1723 	const struct rtw_ch_switch_option cs_option = {
1724 		.dest_ch_en = 1,
1725 		.dest_ch = 1,
1726 		.periodic_option = 2,
1727 		.normal_period = 5,
1728 		.normal_period_sel = 0,
1729 		.normal_cycle = 10,
1730 		.slow_period = 1,
1731 		.slow_period_sel = 1,
1732 	};
1733 
1734 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_CH_SWITCH);
1735 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
1736 
1737 	CH_SWITCH_SET_START(h2c_pkt, enable);
1738 	CH_SWITCH_SET_DEST_CH_EN(h2c_pkt, cs_option.dest_ch_en);
1739 	CH_SWITCH_SET_DEST_CH(h2c_pkt, cs_option.dest_ch);
1740 	CH_SWITCH_SET_NORMAL_PERIOD(h2c_pkt, cs_option.normal_period);
1741 	CH_SWITCH_SET_NORMAL_PERIOD_SEL(h2c_pkt, cs_option.normal_period_sel);
1742 	CH_SWITCH_SET_SLOW_PERIOD(h2c_pkt, cs_option.slow_period);
1743 	CH_SWITCH_SET_SLOW_PERIOD_SEL(h2c_pkt, cs_option.slow_period_sel);
1744 	CH_SWITCH_SET_NORMAL_CYCLE(h2c_pkt, cs_option.normal_cycle);
1745 	CH_SWITCH_SET_PERIODIC_OPT(h2c_pkt, cs_option.periodic_option);
1746 
1747 	CH_SWITCH_SET_CH_NUM(h2c_pkt, rtw_pno_req->channel_cnt);
1748 	CH_SWITCH_SET_INFO_SIZE(h2c_pkt, rtw_pno_req->channel_cnt * 4);
1749 
1750 	loc_ch_info = rtw_get_rsvd_page_location(rtwdev, RSVD_CH_INFO);
1751 	CH_SWITCH_SET_INFO_LOC(h2c_pkt, loc_ch_info);
1752 
1753 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
1754 }
1755 
1756 void rtw_fw_adaptivity(struct rtw_dev *rtwdev)
1757 {
1758 	struct rtw_dm_info *dm_info = &rtwdev->dm_info;
1759 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1760 
1761 	if (!rtw_edcca_enabled) {
1762 		dm_info->edcca_mode = RTW_EDCCA_NORMAL;
1763 		rtw_dbg(rtwdev, RTW_DBG_ADAPTIVITY,
1764 			"EDCCA disabled by debugfs\n");
1765 	}
1766 
1767 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_ADAPTIVITY);
1768 	SET_ADAPTIVITY_MODE(h2c_pkt, dm_info->edcca_mode);
1769 	SET_ADAPTIVITY_OPTION(h2c_pkt, 2);
1770 	SET_ADAPTIVITY_IGI(h2c_pkt, dm_info->igi_history[0]);
1771 	SET_ADAPTIVITY_L2H(h2c_pkt, dm_info->l2h_th_ini);
1772 	SET_ADAPTIVITY_DENSITY(h2c_pkt, dm_info->scan_density);
1773 
1774 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
1775 }
1776 
1777 void rtw_fw_scan_notify(struct rtw_dev *rtwdev, bool start)
1778 {
1779 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1780 
1781 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_SCAN);
1782 	SET_SCAN_START(h2c_pkt, start);
1783 
1784 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
1785 }
1786 
1787 static void rtw_append_probe_req_ie(struct rtw_dev *rtwdev, struct sk_buff *skb,
1788 				    struct sk_buff_head *list,
1789 				    struct rtw_vif *rtwvif)
1790 {
1791 	struct ieee80211_scan_ies *ies = rtwvif->scan_ies;
1792 	struct rtw_chip_info *chip = rtwdev->chip;
1793 	struct sk_buff *new;
1794 	u8 idx;
1795 
1796 	for (idx = NL80211_BAND_2GHZ; idx < NUM_NL80211_BANDS; idx++) {
1797 		if (!(BIT(idx) & chip->band))
1798 			continue;
1799 		new = skb_copy(skb, GFP_KERNEL);
1800 		skb_put_data(new, ies->ies[idx], ies->len[idx]);
1801 		skb_put_data(new, ies->common_ies, ies->common_ie_len);
1802 		skb_queue_tail(list, new);
1803 	}
1804 }
1805 
1806 static int _rtw_hw_scan_update_probe_req(struct rtw_dev *rtwdev, u8 num_ssids,
1807 					 struct sk_buff_head *probe_req_list)
1808 {
1809 	struct rtw_chip_info *chip = rtwdev->chip;
1810 	struct sk_buff *skb, *tmp;
1811 	u8 page_offset = 1, *buf, page_size = chip->page_size;
1812 	u8 pages = page_offset + num_ssids * RTW_PROBE_PG_CNT;
1813 	u16 pg_addr = rtwdev->fifo.rsvd_h2c_info_addr, loc;
1814 	u16 buf_offset = page_size * page_offset;
1815 	u8 tx_desc_sz = chip->tx_pkt_desc_sz;
1816 	unsigned int pkt_len;
1817 	int ret;
1818 
1819 	buf = kzalloc(page_size * pages, GFP_KERNEL);
1820 	if (!buf)
1821 		return -ENOMEM;
1822 
1823 	buf_offset -= tx_desc_sz;
1824 	skb_queue_walk_safe(probe_req_list, skb, tmp) {
1825 		skb_unlink(skb, probe_req_list);
1826 		rtw_fill_rsvd_page_desc(rtwdev, skb, RSVD_PROBE_REQ);
1827 		if (skb->len > page_size * RTW_PROBE_PG_CNT) {
1828 			ret = -EINVAL;
1829 			goto out;
1830 		}
1831 
1832 		memcpy(buf + buf_offset, skb->data, skb->len);
1833 		pkt_len = skb->len - tx_desc_sz;
1834 		loc = pg_addr - rtwdev->fifo.rsvd_boundary + page_offset;
1835 		__rtw_fw_update_pkt(rtwdev, RTW_PACKET_PROBE_REQ, pkt_len, loc);
1836 
1837 		buf_offset += RTW_PROBE_PG_CNT * page_size;
1838 		page_offset += RTW_PROBE_PG_CNT;
1839 		kfree_skb(skb);
1840 	}
1841 
1842 	ret = rtw_fw_write_data_rsvd_page(rtwdev, pg_addr, buf, buf_offset);
1843 	if (ret) {
1844 		rtw_err(rtwdev, "Download probe request to firmware failed\n");
1845 		goto out;
1846 	}
1847 
1848 	rtwdev->scan_info.probe_pg_size = page_offset;
1849 out:
1850 	kfree(buf);
1851 
1852 	return ret;
1853 }
1854 
1855 static int rtw_hw_scan_update_probe_req(struct rtw_dev *rtwdev,
1856 					struct rtw_vif *rtwvif)
1857 {
1858 	struct cfg80211_scan_request *req = rtwvif->scan_req;
1859 	struct sk_buff_head list;
1860 	struct sk_buff *skb;
1861 	u8 num = req->n_ssids, i;
1862 
1863 	skb_queue_head_init(&list);
1864 	for (i = 0; i < num; i++) {
1865 		skb = ieee80211_probereq_get(rtwdev->hw, rtwvif->mac_addr,
1866 					     req->ssids[i].ssid,
1867 					     req->ssids[i].ssid_len,
1868 					     req->ie_len);
1869 		rtw_append_probe_req_ie(rtwdev, skb, &list, rtwvif);
1870 		kfree_skb(skb);
1871 	}
1872 
1873 	return _rtw_hw_scan_update_probe_req(rtwdev, num, &list);
1874 }
1875 
1876 static int rtw_add_chan_info(struct rtw_dev *rtwdev, struct rtw_chan_info *info,
1877 			     struct rtw_chan_list *list, u8 *buf)
1878 {
1879 	u8 *chan = &buf[list->size];
1880 	u8 info_size = RTW_CH_INFO_SIZE;
1881 
1882 	if (list->size > list->buf_size)
1883 		return -ENOMEM;
1884 
1885 	CH_INFO_SET_CH(chan, info->channel);
1886 	CH_INFO_SET_PRI_CH_IDX(chan, info->pri_ch_idx);
1887 	CH_INFO_SET_BW(chan, info->bw);
1888 	CH_INFO_SET_TIMEOUT(chan, info->timeout);
1889 	CH_INFO_SET_ACTION_ID(chan, info->action_id);
1890 	CH_INFO_SET_EXTRA_INFO(chan, info->extra_info);
1891 	if (info->extra_info) {
1892 		EXTRA_CH_INFO_SET_ID(chan, RTW_SCAN_EXTRA_ID_DFS);
1893 		EXTRA_CH_INFO_SET_INFO(chan, RTW_SCAN_EXTRA_ACTION_SCAN);
1894 		EXTRA_CH_INFO_SET_SIZE(chan, RTW_EX_CH_INFO_SIZE -
1895 				       RTW_EX_CH_INFO_HDR_SIZE);
1896 		EXTRA_CH_INFO_SET_DFS_EXT_TIME(chan, RTW_DFS_CHAN_TIME);
1897 		info_size += RTW_EX_CH_INFO_SIZE;
1898 	}
1899 	list->size += info_size;
1900 	list->ch_num++;
1901 
1902 	return 0;
1903 }
1904 
1905 static int rtw_add_chan_list(struct rtw_dev *rtwdev, struct rtw_vif *rtwvif,
1906 			     struct rtw_chan_list *list, u8 *buf)
1907 {
1908 	struct cfg80211_scan_request *req = rtwvif->scan_req;
1909 	struct rtw_fifo_conf *fifo = &rtwdev->fifo;
1910 	struct ieee80211_channel *channel;
1911 	int i, ret = 0;
1912 
1913 	for (i = 0; i < req->n_channels; i++) {
1914 		struct rtw_chan_info ch_info = {0};
1915 
1916 		channel = req->channels[i];
1917 		ch_info.channel = channel->hw_value;
1918 		ch_info.bw = RTW_SCAN_WIDTH;
1919 		ch_info.pri_ch_idx = RTW_PRI_CH_IDX;
1920 		ch_info.timeout = req->duration_mandatory ?
1921 				  req->duration : RTW_CHANNEL_TIME;
1922 
1923 		if (channel->flags & (IEEE80211_CHAN_RADAR | IEEE80211_CHAN_NO_IR)) {
1924 			ch_info.action_id = RTW_CHANNEL_RADAR;
1925 			ch_info.extra_info = 1;
1926 			/* Overwrite duration for passive scans if necessary */
1927 			ch_info.timeout = ch_info.timeout > RTW_PASS_CHAN_TIME ?
1928 					  ch_info.timeout : RTW_PASS_CHAN_TIME;
1929 		} else {
1930 			ch_info.action_id = RTW_CHANNEL_ACTIVE;
1931 		}
1932 
1933 		ret = rtw_add_chan_info(rtwdev, &ch_info, list, buf);
1934 		if (ret)
1935 			return ret;
1936 	}
1937 
1938 	if (list->size > fifo->rsvd_pg_num << TX_PAGE_SIZE_SHIFT) {
1939 		rtw_err(rtwdev, "List exceeds rsvd page total size\n");
1940 		return -EINVAL;
1941 	}
1942 
1943 	list->addr = fifo->rsvd_h2c_info_addr + rtwdev->scan_info.probe_pg_size;
1944 	ret = rtw_fw_write_data_rsvd_page(rtwdev, list->addr, buf, list->size);
1945 	if (ret)
1946 		rtw_err(rtwdev, "Download channel list failed\n");
1947 
1948 	return ret;
1949 }
1950 
1951 static void rtw_fw_set_scan_offload(struct rtw_dev *rtwdev,
1952 				    struct rtw_ch_switch_option *opt,
1953 				    struct rtw_vif *rtwvif,
1954 				    struct rtw_chan_list *list)
1955 {
1956 	struct rtw_hw_scan_info *scan_info = &rtwdev->scan_info;
1957 	struct cfg80211_scan_request *req = rtwvif->scan_req;
1958 	struct rtw_fifo_conf *fifo = &rtwdev->fifo;
1959 	/* reserve one dummy page at the beginning for tx descriptor */
1960 	u8 pkt_loc = fifo->rsvd_h2c_info_addr - fifo->rsvd_boundary + 1;
1961 	bool random_seq = req->flags & NL80211_SCAN_FLAG_RANDOM_SN;
1962 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1963 
1964 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_SCAN_OFFLOAD);
1965 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, H2C_PKT_CH_SWITCH_LEN);
1966 
1967 	SCAN_OFFLOAD_SET_START(h2c_pkt, opt->switch_en);
1968 	SCAN_OFFLOAD_SET_BACK_OP_EN(h2c_pkt, opt->back_op_en);
1969 	SCAN_OFFLOAD_SET_RANDOM_SEQ_EN(h2c_pkt, random_seq);
1970 	SCAN_OFFLOAD_SET_NO_CCK_EN(h2c_pkt, req->no_cck);
1971 	SCAN_OFFLOAD_SET_CH_NUM(h2c_pkt, list->ch_num);
1972 	SCAN_OFFLOAD_SET_CH_INFO_SIZE(h2c_pkt, list->size);
1973 	SCAN_OFFLOAD_SET_CH_INFO_LOC(h2c_pkt, list->addr - fifo->rsvd_boundary);
1974 	SCAN_OFFLOAD_SET_OP_CH(h2c_pkt, scan_info->op_chan);
1975 	SCAN_OFFLOAD_SET_OP_PRI_CH_IDX(h2c_pkt, scan_info->op_pri_ch_idx);
1976 	SCAN_OFFLOAD_SET_OP_BW(h2c_pkt, scan_info->op_bw);
1977 	SCAN_OFFLOAD_SET_OP_PORT_ID(h2c_pkt, rtwvif->port);
1978 	SCAN_OFFLOAD_SET_OP_DWELL_TIME(h2c_pkt, req->duration_mandatory ?
1979 				       req->duration : RTW_CHANNEL_TIME);
1980 	SCAN_OFFLOAD_SET_OP_GAP_TIME(h2c_pkt, RTW_OFF_CHAN_TIME);
1981 	SCAN_OFFLOAD_SET_SSID_NUM(h2c_pkt, req->n_ssids);
1982 	SCAN_OFFLOAD_SET_PKT_LOC(h2c_pkt, pkt_loc);
1983 
1984 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
1985 }
1986 
1987 void rtw_hw_scan_start(struct rtw_dev *rtwdev, struct ieee80211_vif *vif,
1988 		       struct ieee80211_scan_request *scan_req)
1989 {
1990 	struct rtw_vif *rtwvif = (struct rtw_vif *)vif->drv_priv;
1991 	struct cfg80211_scan_request *req = &scan_req->req;
1992 	u8 mac_addr[ETH_ALEN];
1993 
1994 	rtwdev->scan_info.scanning_vif = vif;
1995 	rtwvif->scan_ies = &scan_req->ies;
1996 	rtwvif->scan_req = req;
1997 
1998 	ieee80211_stop_queues(rtwdev->hw);
1999 	if (req->flags & NL80211_SCAN_FLAG_RANDOM_ADDR)
2000 		get_random_mask_addr(mac_addr, req->mac_addr,
2001 				     req->mac_addr_mask);
2002 	else
2003 		ether_addr_copy(mac_addr, vif->addr);
2004 
2005 	rtw_core_scan_start(rtwdev, rtwvif, mac_addr, true);
2006 
2007 	rtwdev->hal.rcr &= ~BIT_CBSSID_BCN;
2008 	rtw_write32(rtwdev, REG_RCR, rtwdev->hal.rcr);
2009 }
2010 
2011 void rtw_hw_scan_complete(struct rtw_dev *rtwdev, struct ieee80211_vif *vif,
2012 			  bool aborted)
2013 {
2014 	struct cfg80211_scan_info info = {
2015 		.aborted = aborted,
2016 	};
2017 	struct rtw_vif *rtwvif;
2018 
2019 	if (!vif)
2020 		return;
2021 
2022 	rtwdev->hal.rcr |= BIT_CBSSID_BCN;
2023 	rtw_write32(rtwdev, REG_RCR, rtwdev->hal.rcr);
2024 
2025 	rtw_core_scan_complete(rtwdev, vif);
2026 
2027 	ieee80211_wake_queues(rtwdev->hw);
2028 	ieee80211_scan_completed(rtwdev->hw, &info);
2029 
2030 	rtwvif = (struct rtw_vif *)vif->drv_priv;
2031 	rtwvif->scan_req = NULL;
2032 	rtwvif->scan_ies = NULL;
2033 	rtwdev->scan_info.scanning_vif = NULL;
2034 }
2035 
2036 static int rtw_hw_scan_prehandle(struct rtw_dev *rtwdev, struct rtw_vif *rtwvif,
2037 				 struct rtw_chan_list *list)
2038 {
2039 	struct cfg80211_scan_request *req = rtwvif->scan_req;
2040 	int size = req->n_channels * (RTW_CH_INFO_SIZE + RTW_EX_CH_INFO_SIZE);
2041 	u8 *buf;
2042 	int ret;
2043 
2044 	buf = kmalloc(size, GFP_KERNEL);
2045 	if (!buf)
2046 		return -ENOMEM;
2047 
2048 	ret = rtw_hw_scan_update_probe_req(rtwdev, rtwvif);
2049 	if (ret) {
2050 		rtw_err(rtwdev, "Update probe request failed\n");
2051 		goto out;
2052 	}
2053 
2054 	list->buf_size = size;
2055 	list->size = 0;
2056 	list->ch_num = 0;
2057 	ret = rtw_add_chan_list(rtwdev, rtwvif, list, buf);
2058 out:
2059 	kfree(buf);
2060 
2061 	return ret;
2062 }
2063 
2064 int rtw_hw_scan_offload(struct rtw_dev *rtwdev, struct ieee80211_vif *vif,
2065 			bool enable)
2066 {
2067 	struct rtw_vif *rtwvif = vif ? (struct rtw_vif *)vif->drv_priv : NULL;
2068 	struct rtw_ch_switch_option cs_option = {0};
2069 	struct rtw_chan_list chan_list = {0};
2070 	int ret = 0;
2071 
2072 	if (!rtwvif)
2073 		return -EINVAL;
2074 
2075 	cs_option.switch_en = enable;
2076 	cs_option.back_op_en = rtwvif->net_type == RTW_NET_MGD_LINKED;
2077 	if (enable) {
2078 		ret = rtw_hw_scan_prehandle(rtwdev, rtwvif, &chan_list);
2079 		if (ret)
2080 			goto out;
2081 	}
2082 	rtw_fw_set_scan_offload(rtwdev, &cs_option, rtwvif, &chan_list);
2083 out:
2084 	return ret;
2085 }
2086 
2087 void rtw_hw_scan_abort(struct rtw_dev *rtwdev, struct ieee80211_vif *vif)
2088 {
2089 	if (!rtw_fw_feature_check(&rtwdev->fw, FW_FEATURE_SCAN_OFFLOAD))
2090 		return;
2091 
2092 	rtw_hw_scan_offload(rtwdev, vif, false);
2093 	rtw_hw_scan_complete(rtwdev, vif, true);
2094 }
2095 
2096 void rtw_hw_scan_status_report(struct rtw_dev *rtwdev, struct sk_buff *skb)
2097 {
2098 	struct ieee80211_vif *vif = rtwdev->scan_info.scanning_vif;
2099 	struct rtw_c2h_cmd *c2h;
2100 	bool aborted;
2101 	u8 rc;
2102 
2103 	if (!test_bit(RTW_FLAG_SCANNING, rtwdev->flags))
2104 		return;
2105 
2106 	c2h = get_c2h_from_skb(skb);
2107 	rc = GET_SCAN_REPORT_RETURN_CODE(c2h->payload);
2108 	aborted = rc != RTW_SCAN_REPORT_SUCCESS;
2109 	rtw_hw_scan_complete(rtwdev, vif, aborted);
2110 
2111 	if (aborted)
2112 		rtw_info(rtwdev, "HW scan aborted with code: %d\n", rc);
2113 }
2114 
2115 void rtw_store_op_chan(struct rtw_dev *rtwdev)
2116 {
2117 	struct rtw_hw_scan_info *scan_info = &rtwdev->scan_info;
2118 	struct rtw_hal *hal = &rtwdev->hal;
2119 
2120 	scan_info->op_chan = hal->current_channel;
2121 	scan_info->op_bw = hal->current_band_width;
2122 	scan_info->op_pri_ch_idx = hal->current_primary_channel_index;
2123 }
2124 
2125 static bool rtw_is_op_chan(struct rtw_dev *rtwdev, u8 channel)
2126 {
2127 	struct rtw_hw_scan_info *scan_info = &rtwdev->scan_info;
2128 
2129 	return channel == scan_info->op_chan;
2130 }
2131 
2132 void rtw_hw_scan_chan_switch(struct rtw_dev *rtwdev, struct sk_buff *skb)
2133 {
2134 	struct rtw_hal *hal = &rtwdev->hal;
2135 	struct rtw_c2h_cmd *c2h;
2136 	enum rtw_scan_notify_id id;
2137 	u8 chan, status;
2138 
2139 	c2h = get_c2h_from_skb(skb);
2140 	chan = GET_CHAN_SWITCH_CENTRAL_CH(c2h->payload);
2141 	id = GET_CHAN_SWITCH_ID(c2h->payload);
2142 	status = GET_CHAN_SWITCH_STATUS(c2h->payload);
2143 
2144 	if (id == RTW_SCAN_NOTIFY_ID_POSTSWITCH) {
2145 		if (rtw_is_op_chan(rtwdev, chan))
2146 			ieee80211_wake_queues(rtwdev->hw);
2147 		hal->current_channel = chan;
2148 		hal->current_band_type = chan > 14 ? RTW_BAND_5G : RTW_BAND_2G;
2149 	} else if (id == RTW_SCAN_NOTIFY_ID_PRESWITCH) {
2150 		if (IS_CH_5G_BAND(chan)) {
2151 			rtw_coex_switchband_notify(rtwdev, COEX_SWITCH_TO_5G);
2152 		} else if (IS_CH_2G_BAND(chan)) {
2153 			u8 chan_type;
2154 
2155 			if (test_bit(RTW_FLAG_SCANNING, rtwdev->flags))
2156 				chan_type = COEX_SWITCH_TO_24G;
2157 			else
2158 				chan_type = COEX_SWITCH_TO_24G_NOFORSCAN;
2159 			rtw_coex_switchband_notify(rtwdev, chan_type);
2160 		}
2161 		if (rtw_is_op_chan(rtwdev, chan))
2162 			ieee80211_stop_queues(rtwdev->hw);
2163 	}
2164 
2165 	rtw_dbg(rtwdev, RTW_DBG_HW_SCAN,
2166 		"Chan switch: %x, id: %x, status: %x\n", chan, id, status);
2167 }
2168