xref: /linux/drivers/net/wireless/realtek/rtw88/fw.c (revision d5e6f353ce1e1c25b8458ea390ed09d2377412c5)
1 // SPDX-License-Identifier: GPL-2.0 OR BSD-3-Clause
2 /* Copyright(c) 2018-2019  Realtek Corporation
3  */
4 
5 #include <linux/iopoll.h>
6 
7 #include "main.h"
8 #include "coex.h"
9 #include "fw.h"
10 #include "tx.h"
11 #include "reg.h"
12 #include "sec.h"
13 #include "debug.h"
14 #include "util.h"
15 #include "wow.h"
16 #include "ps.h"
17 #include "phy.h"
18 #include "mac.h"
19 
20 static const struct rtw_hw_reg_desc fw_h2c_regs[] = {
21 	{REG_FWIMR, MASKDWORD, "FWIMR"},
22 	{REG_FWIMR, BIT_FS_H2CCMD_INT_EN, "FWIMR enable"},
23 	{REG_FWISR, MASKDWORD, "FWISR"},
24 	{REG_FWISR, BIT_FS_H2CCMD_INT, "FWISR enable"},
25 	{REG_HMETFR, BIT_INT_BOX_ALL, "BoxBitMap"},
26 	{REG_HMEBOX0, MASKDWORD, "MSG 0"},
27 	{REG_HMEBOX0_EX, MASKDWORD, "MSG_EX 0"},
28 	{REG_HMEBOX1, MASKDWORD, "MSG 1"},
29 	{REG_HMEBOX1_EX, MASKDWORD, "MSG_EX 1"},
30 	{REG_HMEBOX2, MASKDWORD, "MSG 2"},
31 	{REG_HMEBOX2_EX, MASKDWORD, "MSG_EX 2"},
32 	{REG_HMEBOX3, MASKDWORD, "MSG 3"},
33 	{REG_HMEBOX3_EX, MASKDWORD, "MSG_EX 3"},
34 	{REG_FT1IMR, MASKDWORD, "FT1IMR"},
35 	{REG_FT1IMR, BIT_FS_H2C_CMD_OK_INT_EN, "FT1IMR enable"},
36 	{REG_FT1ISR, MASKDWORD, "FT1ISR"},
37 	{REG_FT1ISR, BIT_FS_H2C_CMD_OK_INT, "FT1ISR enable "},
38 };
39 
40 static const struct rtw_hw_reg_desc fw_c2h_regs[] = {
41 	{REG_FWIMR, MASKDWORD, "FWIMR"},
42 	{REG_FWIMR, BIT_FS_H2CCMD_INT_EN, "CPWM"},
43 	{REG_FWIMR, BIT_FS_HRCV_INT_EN, "HRECV"},
44 	{REG_FWISR, MASKDWORD, "FWISR"},
45 	{REG_FWISR, BIT_FS_H2CCMD_INT, "CPWM"},
46 	{REG_FWISR, BIT_FS_HRCV_INT, "HRECV"},
47 	{REG_CPWM, MASKDWORD, "REG_CPWM"},
48 };
49 
50 static const struct rtw_hw_reg_desc fw_core_regs[] = {
51 	{REG_ARFR2_V1, MASKDWORD, "EPC"},
52 	{REG_ARFRH2_V1, MASKDWORD, "BADADDR"},
53 	{REG_ARFR3_V1, MASKDWORD, "CAUSE"},
54 	{REG_ARFR3_V1, BIT_EXC_CODE, "ExcCode"},
55 	{REG_ARFRH3_V1, MASKDWORD, "Status"},
56 	{REG_ARFR4, MASKDWORD, "SP"},
57 	{REG_ARFRH4, MASKDWORD, "RA"},
58 	{REG_FW_DBG6, MASKDWORD, "DBG 6"},
59 	{REG_FW_DBG7, MASKDWORD, "DBG 7"},
60 };
61 
62 static void _rtw_fw_dump_dbg_info(struct rtw_dev *rtwdev,
63 				  const struct rtw_hw_reg_desc regs[], u32 size)
64 {
65 	const struct rtw_hw_reg_desc *reg;
66 	u32 val;
67 	int i;
68 
69 	for (i = 0;  i < size; i++) {
70 		reg = &regs[i];
71 		val = rtw_read32_mask(rtwdev, reg->addr, reg->mask);
72 
73 		rtw_dbg(rtwdev, RTW_DBG_FW, "[%s]addr:0x%x mask:0x%x value:0x%x\n",
74 			reg->desc, reg->addr, reg->mask, val);
75 	}
76 }
77 
78 void rtw_fw_dump_dbg_info(struct rtw_dev *rtwdev)
79 {
80 	int i;
81 
82 	if (!rtw_dbg_is_enabled(rtwdev, RTW_DBG_FW))
83 		return;
84 
85 	_rtw_fw_dump_dbg_info(rtwdev, fw_h2c_regs, ARRAY_SIZE(fw_h2c_regs));
86 	_rtw_fw_dump_dbg_info(rtwdev, fw_c2h_regs, ARRAY_SIZE(fw_c2h_regs));
87 	for (i = 0 ; i < RTW_DEBUG_DUMP_TIMES; i++) {
88 		rtw_dbg(rtwdev, RTW_DBG_FW, "Firmware Coredump %dth\n", i + 1);
89 		_rtw_fw_dump_dbg_info(rtwdev, fw_core_regs, ARRAY_SIZE(fw_core_regs));
90 	}
91 }
92 
93 static void rtw_fw_c2h_cmd_handle_ext(struct rtw_dev *rtwdev,
94 				      struct sk_buff *skb)
95 {
96 	struct rtw_c2h_cmd *c2h;
97 	u8 sub_cmd_id;
98 
99 	c2h = get_c2h_from_skb(skb);
100 	sub_cmd_id = c2h->payload[0];
101 
102 	switch (sub_cmd_id) {
103 	case C2H_CCX_RPT:
104 		rtw_tx_report_handle(rtwdev, skb, C2H_CCX_RPT);
105 		break;
106 	case C2H_SCAN_STATUS_RPT:
107 		rtw_hw_scan_status_report(rtwdev, skb);
108 		break;
109 	case C2H_CHAN_SWITCH:
110 		rtw_hw_scan_chan_switch(rtwdev, skb);
111 		break;
112 	default:
113 		break;
114 	}
115 }
116 
117 static u16 get_max_amsdu_len(u32 bit_rate)
118 {
119 	/* lower than ofdm, do not aggregate */
120 	if (bit_rate < 550)
121 		return 1;
122 
123 	/* lower than 20M 2ss mcs8, make it small */
124 	if (bit_rate < 1800)
125 		return 1200;
126 
127 	/* lower than 40M 2ss mcs9, make it medium */
128 	if (bit_rate < 4000)
129 		return 2600;
130 
131 	/* not yet 80M 2ss mcs8/9, make it twice regular packet size */
132 	if (bit_rate < 7000)
133 		return 3500;
134 
135 	/* unlimited */
136 	return 0;
137 }
138 
139 struct rtw_fw_iter_ra_data {
140 	struct rtw_dev *rtwdev;
141 	u8 *payload;
142 	u8 length;
143 };
144 
145 static void rtw_fw_ra_report_iter(void *data, struct ieee80211_sta *sta)
146 {
147 	struct rtw_fw_iter_ra_data *ra_data = data;
148 	struct rtw_c2h_ra_rpt *ra_rpt = (struct rtw_c2h_ra_rpt *)ra_data->payload;
149 	struct rtw_sta_info *si = (struct rtw_sta_info *)sta->drv_priv;
150 	u8 mac_id, rate, sgi, bw;
151 	u8 mcs, nss;
152 	u32 bit_rate;
153 
154 	mac_id = ra_rpt->mac_id;
155 	if (si->mac_id != mac_id)
156 		return;
157 
158 	si->ra_report.txrate.flags = 0;
159 
160 	rate = u8_get_bits(ra_rpt->rate_sgi, RTW_C2H_RA_RPT_RATE);
161 	sgi = u8_get_bits(ra_rpt->rate_sgi, RTW_C2H_RA_RPT_SGI);
162 	if (ra_data->length >= offsetofend(typeof(*ra_rpt), bw))
163 		bw = ra_rpt->bw;
164 	else
165 		bw = si->bw_mode;
166 
167 	if (rate < DESC_RATEMCS0) {
168 		si->ra_report.txrate.legacy = rtw_desc_to_bitrate(rate);
169 		goto legacy;
170 	}
171 
172 	rtw_desc_to_mcsrate(rate, &mcs, &nss);
173 	if (rate >= DESC_RATEVHT1SS_MCS0)
174 		si->ra_report.txrate.flags |= RATE_INFO_FLAGS_VHT_MCS;
175 	else if (rate >= DESC_RATEMCS0)
176 		si->ra_report.txrate.flags |= RATE_INFO_FLAGS_MCS;
177 
178 	if (rate >= DESC_RATEMCS0) {
179 		si->ra_report.txrate.mcs = mcs;
180 		si->ra_report.txrate.nss = nss;
181 	}
182 
183 	if (sgi)
184 		si->ra_report.txrate.flags |= RATE_INFO_FLAGS_SHORT_GI;
185 
186 	if (bw == RTW_CHANNEL_WIDTH_80)
187 		si->ra_report.txrate.bw = RATE_INFO_BW_80;
188 	else if (bw == RTW_CHANNEL_WIDTH_40)
189 		si->ra_report.txrate.bw = RATE_INFO_BW_40;
190 	else
191 		si->ra_report.txrate.bw = RATE_INFO_BW_20;
192 
193 legacy:
194 	bit_rate = cfg80211_calculate_bitrate(&si->ra_report.txrate);
195 
196 	si->ra_report.desc_rate = rate;
197 	si->ra_report.bit_rate = bit_rate;
198 
199 	sta->deflink.agg.max_rc_amsdu_len = get_max_amsdu_len(bit_rate);
200 }
201 
202 static void rtw_fw_ra_report_handle(struct rtw_dev *rtwdev, u8 *payload,
203 				    u8 length)
204 {
205 	struct rtw_c2h_ra_rpt *ra_rpt = (struct rtw_c2h_ra_rpt *)payload;
206 	struct rtw_fw_iter_ra_data ra_data;
207 
208 	if (WARN(length < rtwdev->chip->c2h_ra_report_size,
209 		 "invalid ra report c2h length %d\n", length))
210 		return;
211 
212 	rtwdev->dm_info.tx_rate = u8_get_bits(ra_rpt->rate_sgi,
213 					      RTW_C2H_RA_RPT_RATE);
214 	ra_data.rtwdev = rtwdev;
215 	ra_data.payload = payload;
216 	ra_data.length = length;
217 	rtw_iterate_stas_atomic(rtwdev, rtw_fw_ra_report_iter, &ra_data);
218 }
219 
220 struct rtw_beacon_filter_iter_data {
221 	struct rtw_dev *rtwdev;
222 	u8 *payload;
223 };
224 
225 static void rtw_fw_bcn_filter_notify_vif_iter(void *data,
226 					      struct ieee80211_vif *vif)
227 {
228 	struct rtw_beacon_filter_iter_data *iter_data = data;
229 	struct rtw_dev *rtwdev = iter_data->rtwdev;
230 	u8 *payload = iter_data->payload;
231 	u8 type = GET_BCN_FILTER_NOTIFY_TYPE(payload);
232 	u8 event = GET_BCN_FILTER_NOTIFY_EVENT(payload);
233 	s8 sig = (s8)GET_BCN_FILTER_NOTIFY_RSSI(payload);
234 
235 	switch (type) {
236 	case BCN_FILTER_NOTIFY_SIGNAL_CHANGE:
237 		event = event ? NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH :
238 			NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW;
239 		ieee80211_cqm_rssi_notify(vif, event, sig, GFP_KERNEL);
240 		break;
241 	case BCN_FILTER_CONNECTION_LOSS:
242 		ieee80211_connection_loss(vif);
243 		break;
244 	case BCN_FILTER_CONNECTED:
245 		rtwdev->beacon_loss = false;
246 		break;
247 	case BCN_FILTER_NOTIFY_BEACON_LOSS:
248 		rtwdev->beacon_loss = true;
249 		rtw_leave_lps(rtwdev);
250 		break;
251 	}
252 }
253 
254 static void rtw_fw_bcn_filter_notify(struct rtw_dev *rtwdev, u8 *payload,
255 				     u8 length)
256 {
257 	struct rtw_beacon_filter_iter_data dev_iter_data;
258 
259 	dev_iter_data.rtwdev = rtwdev;
260 	dev_iter_data.payload = payload;
261 	rtw_iterate_vifs(rtwdev, rtw_fw_bcn_filter_notify_vif_iter,
262 			 &dev_iter_data);
263 }
264 
265 static void rtw_fw_scan_result(struct rtw_dev *rtwdev, u8 *payload,
266 			       u8 length)
267 {
268 	struct rtw_dm_info *dm_info = &rtwdev->dm_info;
269 
270 	dm_info->scan_density = payload[0];
271 
272 	rtw_dbg(rtwdev, RTW_DBG_FW, "scan.density = %x\n",
273 		dm_info->scan_density);
274 }
275 
276 static void rtw_fw_adaptivity_result(struct rtw_dev *rtwdev, u8 *payload,
277 				     u8 length)
278 {
279 	const struct rtw_hw_reg_offset *edcca_th = rtwdev->chip->edcca_th;
280 	struct rtw_c2h_adaptivity *result = (struct rtw_c2h_adaptivity *)payload;
281 
282 	if (!edcca_th)
283 		return;
284 
285 	rtw_dbg(rtwdev, RTW_DBG_ADAPTIVITY,
286 		"Adaptivity: density %x igi %x l2h_th_init %x l2h %x h2l %x option %x\n",
287 		result->density, result->igi, result->l2h_th_init, result->l2h,
288 		result->h2l, result->option);
289 
290 	rtw_dbg(rtwdev, RTW_DBG_ADAPTIVITY, "Reg Setting: L2H %x H2L %x\n",
291 		rtw_read32_mask(rtwdev, edcca_th[EDCCA_TH_L2H_IDX].hw_reg.addr,
292 				edcca_th[EDCCA_TH_L2H_IDX].hw_reg.mask),
293 		rtw_read32_mask(rtwdev, edcca_th[EDCCA_TH_H2L_IDX].hw_reg.addr,
294 				edcca_th[EDCCA_TH_H2L_IDX].hw_reg.mask));
295 
296 	rtw_dbg(rtwdev, RTW_DBG_ADAPTIVITY, "EDCCA Flag %s\n",
297 		rtw_read32_mask(rtwdev, REG_EDCCA_REPORT, BIT_EDCCA_FLAG) ?
298 		"Set" : "Unset");
299 }
300 
301 void rtw_fw_c2h_cmd_handle(struct rtw_dev *rtwdev, struct sk_buff *skb)
302 {
303 	struct rtw_c2h_cmd *c2h;
304 	u32 pkt_offset;
305 	u8 len;
306 
307 	pkt_offset = *((u32 *)skb->cb);
308 	c2h = (struct rtw_c2h_cmd *)(skb->data + pkt_offset);
309 	len = skb->len - pkt_offset - 2;
310 
311 	mutex_lock(&rtwdev->mutex);
312 
313 	if (!test_bit(RTW_FLAG_RUNNING, rtwdev->flags))
314 		goto unlock;
315 
316 	switch (c2h->id) {
317 	case C2H_CCX_TX_RPT:
318 		rtw_tx_report_handle(rtwdev, skb, C2H_CCX_TX_RPT);
319 		break;
320 	case C2H_BT_INFO:
321 		rtw_coex_bt_info_notify(rtwdev, c2h->payload, len);
322 		break;
323 	case C2H_BT_HID_INFO:
324 		rtw_coex_bt_hid_info_notify(rtwdev, c2h->payload, len);
325 		break;
326 	case C2H_WLAN_INFO:
327 		rtw_coex_wl_fwdbginfo_notify(rtwdev, c2h->payload, len);
328 		break;
329 	case C2H_BCN_FILTER_NOTIFY:
330 		rtw_fw_bcn_filter_notify(rtwdev, c2h->payload, len);
331 		break;
332 	case C2H_HALMAC:
333 		rtw_fw_c2h_cmd_handle_ext(rtwdev, skb);
334 		break;
335 	case C2H_RA_RPT:
336 		rtw_fw_ra_report_handle(rtwdev, c2h->payload, len);
337 		break;
338 	case C2H_ADAPTIVITY:
339 		rtw_fw_adaptivity_result(rtwdev, c2h->payload, len);
340 		break;
341 	default:
342 		rtw_dbg(rtwdev, RTW_DBG_FW, "C2H 0x%x isn't handled\n", c2h->id);
343 		break;
344 	}
345 
346 unlock:
347 	mutex_unlock(&rtwdev->mutex);
348 }
349 
350 void rtw_fw_c2h_cmd_rx_irqsafe(struct rtw_dev *rtwdev, u32 pkt_offset,
351 			       struct sk_buff *skb)
352 {
353 	struct rtw_c2h_cmd *c2h;
354 	u8 len;
355 
356 	c2h = (struct rtw_c2h_cmd *)(skb->data + pkt_offset);
357 	len = skb->len - pkt_offset - 2;
358 	*((u32 *)skb->cb) = pkt_offset;
359 
360 	rtw_dbg(rtwdev, RTW_DBG_FW, "recv C2H, id=0x%02x, seq=0x%02x, len=%d\n",
361 		c2h->id, c2h->seq, len);
362 
363 	switch (c2h->id) {
364 	case C2H_BT_MP_INFO:
365 		rtw_coex_info_response(rtwdev, skb);
366 		break;
367 	case C2H_WLAN_RFON:
368 		complete(&rtwdev->lps_leave_check);
369 		dev_kfree_skb_any(skb);
370 		break;
371 	case C2H_SCAN_RESULT:
372 		complete(&rtwdev->fw_scan_density);
373 		rtw_fw_scan_result(rtwdev, c2h->payload, len);
374 		dev_kfree_skb_any(skb);
375 		break;
376 	default:
377 		/* pass offset for further operation */
378 		*((u32 *)skb->cb) = pkt_offset;
379 		skb_queue_tail(&rtwdev->c2h_queue, skb);
380 		ieee80211_queue_work(rtwdev->hw, &rtwdev->c2h_work);
381 		break;
382 	}
383 }
384 EXPORT_SYMBOL(rtw_fw_c2h_cmd_rx_irqsafe);
385 
386 void rtw_fw_c2h_cmd_isr(struct rtw_dev *rtwdev)
387 {
388 	if (rtw_read8(rtwdev, REG_MCU_TST_CFG) == VAL_FW_TRIGGER)
389 		rtw_fw_recovery(rtwdev);
390 	else
391 		rtw_warn(rtwdev, "unhandled firmware c2h interrupt\n");
392 }
393 EXPORT_SYMBOL(rtw_fw_c2h_cmd_isr);
394 
395 static void rtw_fw_send_h2c_command_register(struct rtw_dev *rtwdev,
396 					     struct rtw_h2c_register *h2c)
397 {
398 	u32 box_reg, box_ex_reg;
399 	u8 box_state, box;
400 	int ret;
401 
402 	rtw_dbg(rtwdev, RTW_DBG_FW, "send H2C content %08x %08x\n", h2c->w0,
403 		h2c->w1);
404 
405 	lockdep_assert_held(&rtwdev->mutex);
406 
407 	box = rtwdev->h2c.last_box_num;
408 	switch (box) {
409 	case 0:
410 		box_reg = REG_HMEBOX0;
411 		box_ex_reg = REG_HMEBOX0_EX;
412 		break;
413 	case 1:
414 		box_reg = REG_HMEBOX1;
415 		box_ex_reg = REG_HMEBOX1_EX;
416 		break;
417 	case 2:
418 		box_reg = REG_HMEBOX2;
419 		box_ex_reg = REG_HMEBOX2_EX;
420 		break;
421 	case 3:
422 		box_reg = REG_HMEBOX3;
423 		box_ex_reg = REG_HMEBOX3_EX;
424 		break;
425 	default:
426 		WARN(1, "invalid h2c mail box number\n");
427 		return;
428 	}
429 
430 	ret = read_poll_timeout_atomic(rtw_read8, box_state,
431 				       !((box_state >> box) & 0x1), 100, 3000,
432 				       false, rtwdev, REG_HMETFR);
433 
434 	if (ret) {
435 		rtw_err(rtwdev, "failed to send h2c command\n");
436 		rtw_fw_dump_dbg_info(rtwdev);
437 		return;
438 	}
439 
440 	rtw_write32(rtwdev, box_ex_reg, h2c->w1);
441 	rtw_write32(rtwdev, box_reg, h2c->w0);
442 
443 	if (++rtwdev->h2c.last_box_num >= 4)
444 		rtwdev->h2c.last_box_num = 0;
445 }
446 
447 static void rtw_fw_send_h2c_command(struct rtw_dev *rtwdev,
448 				    u8 *h2c)
449 {
450 	struct rtw_h2c_cmd *h2c_cmd = (struct rtw_h2c_cmd *)h2c;
451 	u8 box;
452 	u8 box_state;
453 	u32 box_reg, box_ex_reg;
454 	int ret;
455 
456 	rtw_dbg(rtwdev, RTW_DBG_FW,
457 		"send H2C content %02x%02x%02x%02x %02x%02x%02x%02x\n",
458 		h2c[3], h2c[2], h2c[1], h2c[0],
459 		h2c[7], h2c[6], h2c[5], h2c[4]);
460 
461 	lockdep_assert_held(&rtwdev->mutex);
462 
463 	box = rtwdev->h2c.last_box_num;
464 	switch (box) {
465 	case 0:
466 		box_reg = REG_HMEBOX0;
467 		box_ex_reg = REG_HMEBOX0_EX;
468 		break;
469 	case 1:
470 		box_reg = REG_HMEBOX1;
471 		box_ex_reg = REG_HMEBOX1_EX;
472 		break;
473 	case 2:
474 		box_reg = REG_HMEBOX2;
475 		box_ex_reg = REG_HMEBOX2_EX;
476 		break;
477 	case 3:
478 		box_reg = REG_HMEBOX3;
479 		box_ex_reg = REG_HMEBOX3_EX;
480 		break;
481 	default:
482 		WARN(1, "invalid h2c mail box number\n");
483 		return;
484 	}
485 
486 	ret = read_poll_timeout_atomic(rtw_read8, box_state,
487 				       !((box_state >> box) & 0x1), 100, 3000,
488 				       false, rtwdev, REG_HMETFR);
489 
490 	if (ret) {
491 		rtw_err(rtwdev, "failed to send h2c command\n");
492 		return;
493 	}
494 
495 	rtw_write32(rtwdev, box_ex_reg, le32_to_cpu(h2c_cmd->msg_ext));
496 	rtw_write32(rtwdev, box_reg, le32_to_cpu(h2c_cmd->msg));
497 
498 	if (++rtwdev->h2c.last_box_num >= 4)
499 		rtwdev->h2c.last_box_num = 0;
500 }
501 
502 void rtw_fw_h2c_cmd_dbg(struct rtw_dev *rtwdev, u8 *h2c)
503 {
504 	rtw_fw_send_h2c_command(rtwdev, h2c);
505 }
506 
507 static void rtw_fw_send_h2c_packet(struct rtw_dev *rtwdev, u8 *h2c_pkt)
508 {
509 	int ret;
510 
511 	lockdep_assert_held(&rtwdev->mutex);
512 
513 	FW_OFFLOAD_H2C_SET_SEQ_NUM(h2c_pkt, rtwdev->h2c.seq);
514 	ret = rtw_hci_write_data_h2c(rtwdev, h2c_pkt, H2C_PKT_SIZE);
515 	if (ret)
516 		rtw_err(rtwdev, "failed to send h2c packet\n");
517 	rtwdev->h2c.seq++;
518 }
519 
520 void
521 rtw_fw_send_general_info(struct rtw_dev *rtwdev)
522 {
523 	struct rtw_fifo_conf *fifo = &rtwdev->fifo;
524 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
525 	u16 total_size = H2C_PKT_HDR_SIZE + 4;
526 
527 	if (rtw_chip_wcpu_8051(rtwdev))
528 		return;
529 
530 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_GENERAL_INFO);
531 
532 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
533 
534 	GENERAL_INFO_SET_FW_TX_BOUNDARY(h2c_pkt,
535 					fifo->rsvd_fw_txbuf_addr -
536 					fifo->rsvd_boundary);
537 
538 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
539 }
540 
541 void
542 rtw_fw_send_phydm_info(struct rtw_dev *rtwdev)
543 {
544 	struct rtw_hal *hal = &rtwdev->hal;
545 	struct rtw_efuse *efuse = &rtwdev->efuse;
546 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
547 	u16 total_size = H2C_PKT_HDR_SIZE + 8;
548 	u8 fw_rf_type = 0;
549 
550 	if (rtw_chip_wcpu_8051(rtwdev))
551 		return;
552 
553 	if (hal->rf_type == RF_1T1R)
554 		fw_rf_type = FW_RF_1T1R;
555 	else if (hal->rf_type == RF_2T2R)
556 		fw_rf_type = FW_RF_2T2R;
557 
558 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_PHYDM_INFO);
559 
560 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
561 	PHYDM_INFO_SET_REF_TYPE(h2c_pkt, efuse->rfe_option);
562 	PHYDM_INFO_SET_RF_TYPE(h2c_pkt, fw_rf_type);
563 	PHYDM_INFO_SET_CUT_VER(h2c_pkt, hal->cut_version);
564 	PHYDM_INFO_SET_RX_ANT_STATUS(h2c_pkt, hal->antenna_tx);
565 	PHYDM_INFO_SET_TX_ANT_STATUS(h2c_pkt, hal->antenna_rx);
566 
567 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
568 }
569 
570 void rtw_fw_do_iqk(struct rtw_dev *rtwdev, struct rtw_iqk_para *para)
571 {
572 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
573 	u16 total_size = H2C_PKT_HDR_SIZE + 1;
574 
575 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_IQK);
576 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
577 	IQK_SET_CLEAR(h2c_pkt, para->clear);
578 	IQK_SET_SEGMENT_IQK(h2c_pkt, para->segment_iqk);
579 
580 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
581 }
582 EXPORT_SYMBOL(rtw_fw_do_iqk);
583 
584 void rtw_fw_inform_rfk_status(struct rtw_dev *rtwdev, bool start)
585 {
586 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
587 
588 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_WIFI_CALIBRATION);
589 
590 	RFK_SET_INFORM_START(h2c_pkt, start);
591 
592 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
593 }
594 EXPORT_SYMBOL(rtw_fw_inform_rfk_status);
595 
596 void rtw_fw_query_bt_info(struct rtw_dev *rtwdev)
597 {
598 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
599 
600 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_QUERY_BT_INFO);
601 
602 	SET_QUERY_BT_INFO(h2c_pkt, true);
603 
604 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
605 }
606 
607 void rtw_fw_default_port(struct rtw_dev *rtwdev, struct rtw_vif *rtwvif)
608 {
609 	struct rtw_h2c_register h2c = {};
610 
611 	if (rtwvif->net_type != RTW_NET_MGD_LINKED)
612 		return;
613 
614 	/* Leave LPS before default port H2C so FW timer is correct */
615 	rtw_leave_lps(rtwdev);
616 
617 	h2c.w0 = u32_encode_bits(H2C_CMD_DEFAULT_PORT, RTW_H2C_W0_CMDID) |
618 		 u32_encode_bits(rtwvif->port, RTW_H2C_DEFAULT_PORT_W0_PORTID) |
619 		 u32_encode_bits(rtwvif->mac_id, RTW_H2C_DEFAULT_PORT_W0_MACID);
620 
621 	rtw_fw_send_h2c_command_register(rtwdev, &h2c);
622 }
623 
624 void rtw_fw_wl_ch_info(struct rtw_dev *rtwdev, u8 link, u8 ch, u8 bw)
625 {
626 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
627 
628 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_WL_CH_INFO);
629 
630 	SET_WL_CH_INFO_LINK(h2c_pkt, link);
631 	SET_WL_CH_INFO_CHNL(h2c_pkt, ch);
632 	SET_WL_CH_INFO_BW(h2c_pkt, bw);
633 
634 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
635 }
636 
637 void rtw_fw_query_bt_mp_info(struct rtw_dev *rtwdev,
638 			     struct rtw_coex_info_req *req)
639 {
640 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
641 
642 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_QUERY_BT_MP_INFO);
643 
644 	SET_BT_MP_INFO_SEQ(h2c_pkt, req->seq);
645 	SET_BT_MP_INFO_OP_CODE(h2c_pkt, req->op_code);
646 	SET_BT_MP_INFO_PARA1(h2c_pkt, req->para1);
647 	SET_BT_MP_INFO_PARA2(h2c_pkt, req->para2);
648 	SET_BT_MP_INFO_PARA3(h2c_pkt, req->para3);
649 
650 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
651 }
652 
653 void rtw_fw_force_bt_tx_power(struct rtw_dev *rtwdev, u8 bt_pwr_dec_lvl)
654 {
655 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
656 	u8 index = 0 - bt_pwr_dec_lvl;
657 
658 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_FORCE_BT_TX_POWER);
659 
660 	SET_BT_TX_POWER_INDEX(h2c_pkt, index);
661 
662 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
663 }
664 
665 void rtw_fw_bt_ignore_wlan_action(struct rtw_dev *rtwdev, bool enable)
666 {
667 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
668 
669 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_IGNORE_WLAN_ACTION);
670 
671 	SET_IGNORE_WLAN_ACTION_EN(h2c_pkt, enable);
672 
673 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
674 }
675 
676 void rtw_fw_coex_tdma_type(struct rtw_dev *rtwdev,
677 			   u8 para1, u8 para2, u8 para3, u8 para4, u8 para5)
678 {
679 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
680 
681 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_COEX_TDMA_TYPE);
682 
683 	SET_COEX_TDMA_TYPE_PARA1(h2c_pkt, para1);
684 	SET_COEX_TDMA_TYPE_PARA2(h2c_pkt, para2);
685 	SET_COEX_TDMA_TYPE_PARA3(h2c_pkt, para3);
686 	SET_COEX_TDMA_TYPE_PARA4(h2c_pkt, para4);
687 	SET_COEX_TDMA_TYPE_PARA5(h2c_pkt, para5);
688 
689 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
690 }
691 
692 void rtw_fw_coex_query_hid_info(struct rtw_dev *rtwdev, u8 sub_id, u8 data)
693 {
694 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
695 
696 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_QUERY_BT_HID_INFO);
697 
698 	SET_COEX_QUERY_HID_INFO_SUBID(h2c_pkt, sub_id);
699 	SET_COEX_QUERY_HID_INFO_DATA1(h2c_pkt, data);
700 
701 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
702 }
703 
704 void rtw_fw_bt_wifi_control(struct rtw_dev *rtwdev, u8 op_code, u8 *data)
705 {
706 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
707 
708 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_BT_WIFI_CONTROL);
709 
710 	SET_BT_WIFI_CONTROL_OP_CODE(h2c_pkt, op_code);
711 
712 	SET_BT_WIFI_CONTROL_DATA1(h2c_pkt, *data);
713 	SET_BT_WIFI_CONTROL_DATA2(h2c_pkt, *(data + 1));
714 	SET_BT_WIFI_CONTROL_DATA3(h2c_pkt, *(data + 2));
715 	SET_BT_WIFI_CONTROL_DATA4(h2c_pkt, *(data + 3));
716 	SET_BT_WIFI_CONTROL_DATA5(h2c_pkt, *(data + 4));
717 
718 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
719 }
720 
721 void rtw_fw_send_rssi_info(struct rtw_dev *rtwdev, struct rtw_sta_info *si)
722 {
723 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
724 	u8 rssi = ewma_rssi_read(&si->avg_rssi);
725 	bool stbc_en = si->stbc_en ? true : false;
726 
727 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_RSSI_MONITOR);
728 
729 	SET_RSSI_INFO_MACID(h2c_pkt, si->mac_id);
730 	SET_RSSI_INFO_RSSI(h2c_pkt, rssi);
731 	SET_RSSI_INFO_STBC(h2c_pkt, stbc_en);
732 
733 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
734 }
735 
736 void rtw_fw_send_ra_info(struct rtw_dev *rtwdev, struct rtw_sta_info *si,
737 			 bool reset_ra_mask)
738 {
739 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
740 	bool disable_pt = true;
741 	u32 mask_hi;
742 
743 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_RA_INFO);
744 
745 	SET_RA_INFO_MACID(h2c_pkt, si->mac_id);
746 	SET_RA_INFO_RATE_ID(h2c_pkt, si->rate_id);
747 	SET_RA_INFO_INIT_RA_LVL(h2c_pkt, si->init_ra_lv);
748 	SET_RA_INFO_SGI_EN(h2c_pkt, si->sgi_enable);
749 	SET_RA_INFO_BW_MODE(h2c_pkt, si->bw_mode);
750 	SET_RA_INFO_LDPC(h2c_pkt, !!si->ldpc_en);
751 	SET_RA_INFO_NO_UPDATE(h2c_pkt, !reset_ra_mask);
752 	SET_RA_INFO_VHT_EN(h2c_pkt, si->vht_enable);
753 	SET_RA_INFO_DIS_PT(h2c_pkt, disable_pt);
754 	SET_RA_INFO_RA_MASK0(h2c_pkt, (si->ra_mask & 0xff));
755 	SET_RA_INFO_RA_MASK1(h2c_pkt, (si->ra_mask & 0xff00) >> 8);
756 	SET_RA_INFO_RA_MASK2(h2c_pkt, (si->ra_mask & 0xff0000) >> 16);
757 	SET_RA_INFO_RA_MASK3(h2c_pkt, (si->ra_mask & 0xff000000) >> 24);
758 
759 	si->init_ra_lv = 0;
760 
761 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
762 
763 	if (rtwdev->chip->id != RTW_CHIP_TYPE_8814A)
764 		return;
765 
766 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_RA_INFO_HI);
767 
768 	mask_hi = si->ra_mask >> 32;
769 
770 	SET_RA_INFO_RA_MASK0(h2c_pkt, (mask_hi & 0xff));
771 	SET_RA_INFO_RA_MASK1(h2c_pkt, (mask_hi & 0xff00) >> 8);
772 	SET_RA_INFO_RA_MASK2(h2c_pkt, (mask_hi & 0xff0000) >> 16);
773 	SET_RA_INFO_RA_MASK3(h2c_pkt, (mask_hi & 0xff000000) >> 24);
774 
775 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
776 }
777 
778 void rtw_fw_media_status_report(struct rtw_dev *rtwdev, u8 mac_id, bool connect)
779 {
780 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
781 
782 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_MEDIA_STATUS_RPT);
783 	MEDIA_STATUS_RPT_SET_OP_MODE(h2c_pkt, connect);
784 	MEDIA_STATUS_RPT_SET_MACID(h2c_pkt, mac_id);
785 
786 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
787 }
788 
789 void rtw_fw_update_wl_phy_info(struct rtw_dev *rtwdev)
790 {
791 	struct rtw_traffic_stats *stats = &rtwdev->stats;
792 	struct rtw_dm_info *dm_info = &rtwdev->dm_info;
793 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
794 
795 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_WL_PHY_INFO);
796 	SET_WL_PHY_INFO_TX_TP(h2c_pkt, stats->tx_throughput);
797 	SET_WL_PHY_INFO_RX_TP(h2c_pkt, stats->rx_throughput);
798 	SET_WL_PHY_INFO_TX_RATE_DESC(h2c_pkt, dm_info->tx_rate);
799 	SET_WL_PHY_INFO_RX_RATE_DESC(h2c_pkt, dm_info->curr_rx_rate);
800 	SET_WL_PHY_INFO_RX_EVM(h2c_pkt, dm_info->rx_evm_dbm[RF_PATH_A]);
801 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
802 }
803 
804 void rtw_fw_beacon_filter_config(struct rtw_dev *rtwdev, bool connect,
805 				 struct ieee80211_vif *vif)
806 {
807 	struct ieee80211_bss_conf *bss_conf = &vif->bss_conf;
808 	struct ieee80211_sta *sta = ieee80211_find_sta(vif, bss_conf->bssid);
809 	static const u8 rssi_min = 0, rssi_max = 100, rssi_offset = 100;
810 	struct rtw_sta_info *si =
811 		sta ? (struct rtw_sta_info *)sta->drv_priv : NULL;
812 	s32 thold = RTW_DEFAULT_CQM_THOLD;
813 	u32 hyst = RTW_DEFAULT_CQM_HYST;
814 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
815 
816 	if (!rtw_fw_feature_check(&rtwdev->fw, FW_FEATURE_BCN_FILTER))
817 		return;
818 
819 	if (bss_conf->cqm_rssi_thold)
820 		thold = bss_conf->cqm_rssi_thold;
821 	if (bss_conf->cqm_rssi_hyst)
822 		hyst = bss_conf->cqm_rssi_hyst;
823 
824 	if (!connect) {
825 		SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_BCN_FILTER_OFFLOAD_P1);
826 		SET_BCN_FILTER_OFFLOAD_P1_ENABLE(h2c_pkt, connect);
827 		rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
828 
829 		return;
830 	}
831 
832 	if (!si)
833 		return;
834 
835 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_BCN_FILTER_OFFLOAD_P0);
836 	ether_addr_copy(&h2c_pkt[1], bss_conf->bssid);
837 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
838 
839 	memset(h2c_pkt, 0, sizeof(h2c_pkt));
840 	thold = clamp_t(s32, thold + rssi_offset, rssi_min, rssi_max);
841 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_BCN_FILTER_OFFLOAD_P1);
842 	SET_BCN_FILTER_OFFLOAD_P1_ENABLE(h2c_pkt, connect);
843 	SET_BCN_FILTER_OFFLOAD_P1_OFFLOAD_MODE(h2c_pkt,
844 					       BCN_FILTER_OFFLOAD_MODE_DEFAULT);
845 	SET_BCN_FILTER_OFFLOAD_P1_THRESHOLD(h2c_pkt, thold);
846 	SET_BCN_FILTER_OFFLOAD_P1_BCN_LOSS_CNT(h2c_pkt, BCN_LOSS_CNT);
847 	SET_BCN_FILTER_OFFLOAD_P1_MACID(h2c_pkt, si->mac_id);
848 	SET_BCN_FILTER_OFFLOAD_P1_HYST(h2c_pkt, hyst);
849 	SET_BCN_FILTER_OFFLOAD_P1_BCN_INTERVAL(h2c_pkt, bss_conf->beacon_int);
850 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
851 }
852 
853 void rtw_fw_set_pwr_mode(struct rtw_dev *rtwdev)
854 {
855 	struct rtw_lps_conf *conf = &rtwdev->lps_conf;
856 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
857 
858 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_SET_PWR_MODE);
859 
860 	SET_PWR_MODE_SET_MODE(h2c_pkt, conf->mode);
861 	SET_PWR_MODE_SET_RLBM(h2c_pkt, conf->rlbm);
862 	SET_PWR_MODE_SET_SMART_PS(h2c_pkt, conf->smart_ps);
863 	SET_PWR_MODE_SET_AWAKE_INTERVAL(h2c_pkt, conf->awake_interval);
864 	SET_PWR_MODE_SET_PORT_ID(h2c_pkt, conf->port_id);
865 	SET_PWR_MODE_SET_PWR_STATE(h2c_pkt, conf->state);
866 
867 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
868 }
869 
870 void rtw_fw_set_keep_alive_cmd(struct rtw_dev *rtwdev, bool enable)
871 {
872 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
873 	struct rtw_fw_wow_keep_alive_para mode = {
874 		.adopt = true,
875 		.pkt_type = KEEP_ALIVE_NULL_PKT,
876 		.period = 5,
877 	};
878 
879 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_KEEP_ALIVE);
880 	SET_KEEP_ALIVE_ENABLE(h2c_pkt, enable);
881 	SET_KEEP_ALIVE_ADOPT(h2c_pkt, mode.adopt);
882 	SET_KEEP_ALIVE_PKT_TYPE(h2c_pkt, mode.pkt_type);
883 	SET_KEEP_ALIVE_CHECK_PERIOD(h2c_pkt, mode.period);
884 
885 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
886 }
887 
888 void rtw_fw_set_disconnect_decision_cmd(struct rtw_dev *rtwdev, bool enable)
889 {
890 	struct rtw_wow_param *rtw_wow = &rtwdev->wow;
891 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
892 	struct rtw_fw_wow_disconnect_para mode = {
893 		.adopt = true,
894 		.period = 30,
895 		.retry_count = 5,
896 	};
897 
898 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_DISCONNECT_DECISION);
899 
900 	if (test_bit(RTW_WOW_FLAG_EN_DISCONNECT, rtw_wow->flags)) {
901 		SET_DISCONNECT_DECISION_ENABLE(h2c_pkt, enable);
902 		SET_DISCONNECT_DECISION_ADOPT(h2c_pkt, mode.adopt);
903 		SET_DISCONNECT_DECISION_CHECK_PERIOD(h2c_pkt, mode.period);
904 		SET_DISCONNECT_DECISION_TRY_PKT_NUM(h2c_pkt, mode.retry_count);
905 	}
906 
907 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
908 }
909 
910 void rtw_fw_set_wowlan_ctrl_cmd(struct rtw_dev *rtwdev, bool enable)
911 {
912 	struct rtw_wow_param *rtw_wow = &rtwdev->wow;
913 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
914 
915 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_WOWLAN);
916 
917 	SET_WOWLAN_FUNC_ENABLE(h2c_pkt, enable);
918 	if (rtw_wow_mgd_linked(rtwdev)) {
919 		if (test_bit(RTW_WOW_FLAG_EN_MAGIC_PKT, rtw_wow->flags))
920 			SET_WOWLAN_MAGIC_PKT_ENABLE(h2c_pkt, enable);
921 		if (test_bit(RTW_WOW_FLAG_EN_DISCONNECT, rtw_wow->flags))
922 			SET_WOWLAN_DEAUTH_WAKEUP_ENABLE(h2c_pkt, enable);
923 		if (test_bit(RTW_WOW_FLAG_EN_REKEY_PKT, rtw_wow->flags))
924 			SET_WOWLAN_REKEY_WAKEUP_ENABLE(h2c_pkt, enable);
925 		if (rtw_wow->pattern_cnt)
926 			SET_WOWLAN_PATTERN_MATCH_ENABLE(h2c_pkt, enable);
927 	}
928 
929 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
930 }
931 
932 void rtw_fw_set_aoac_global_info_cmd(struct rtw_dev *rtwdev,
933 				     u8 pairwise_key_enc,
934 				     u8 group_key_enc)
935 {
936 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
937 
938 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_AOAC_GLOBAL_INFO);
939 
940 	SET_AOAC_GLOBAL_INFO_PAIRWISE_ENC_ALG(h2c_pkt, pairwise_key_enc);
941 	SET_AOAC_GLOBAL_INFO_GROUP_ENC_ALG(h2c_pkt, group_key_enc);
942 
943 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
944 }
945 
946 void rtw_fw_set_remote_wake_ctrl_cmd(struct rtw_dev *rtwdev, bool enable)
947 {
948 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
949 
950 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_REMOTE_WAKE_CTRL);
951 
952 	SET_REMOTE_WAKECTRL_ENABLE(h2c_pkt, enable);
953 
954 	if (rtw_wow_no_link(rtwdev))
955 		SET_REMOTE_WAKE_CTRL_NLO_OFFLOAD_EN(h2c_pkt, enable);
956 
957 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
958 }
959 
960 static u8 rtw_get_rsvd_page_location(struct rtw_dev *rtwdev,
961 				     enum rtw_rsvd_packet_type type)
962 {
963 	struct rtw_rsvd_page *rsvd_pkt;
964 	u8 location = 0;
965 
966 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
967 		if (type == rsvd_pkt->type)
968 			location = rsvd_pkt->page;
969 	}
970 
971 	return location;
972 }
973 
974 void rtw_fw_set_nlo_info(struct rtw_dev *rtwdev, bool enable)
975 {
976 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
977 	u8 loc_nlo;
978 
979 	loc_nlo = rtw_get_rsvd_page_location(rtwdev, RSVD_NLO_INFO);
980 
981 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_NLO_INFO);
982 
983 	SET_NLO_FUN_EN(h2c_pkt, enable);
984 	if (enable) {
985 		if (rtw_get_lps_deep_mode(rtwdev) != LPS_DEEP_MODE_NONE)
986 			SET_NLO_PS_32K(h2c_pkt, enable);
987 		SET_NLO_IGNORE_SECURITY(h2c_pkt, enable);
988 		SET_NLO_LOC_NLO_INFO(h2c_pkt, loc_nlo);
989 	}
990 
991 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
992 }
993 
994 void rtw_fw_set_recover_bt_device(struct rtw_dev *rtwdev)
995 {
996 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
997 
998 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_RECOVER_BT_DEV);
999 	SET_RECOVER_BT_DEV_EN(h2c_pkt, 1);
1000 
1001 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
1002 }
1003 
1004 void rtw_fw_set_pg_info(struct rtw_dev *rtwdev)
1005 {
1006 	struct rtw_lps_conf *conf = &rtwdev->lps_conf;
1007 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1008 	u8 loc_pg, loc_dpk;
1009 
1010 	loc_pg = rtw_get_rsvd_page_location(rtwdev, RSVD_LPS_PG_INFO);
1011 	loc_dpk = rtw_get_rsvd_page_location(rtwdev, RSVD_LPS_PG_DPK);
1012 
1013 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_LPS_PG_INFO);
1014 
1015 	LPS_PG_INFO_LOC(h2c_pkt, loc_pg);
1016 	LPS_PG_DPK_LOC(h2c_pkt, loc_dpk);
1017 	LPS_PG_SEC_CAM_EN(h2c_pkt, conf->sec_cam_backup);
1018 	LPS_PG_PATTERN_CAM_EN(h2c_pkt, conf->pattern_cam_backup);
1019 
1020 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
1021 }
1022 
1023 static u8 rtw_get_rsvd_page_probe_req_location(struct rtw_dev *rtwdev,
1024 					       struct cfg80211_ssid *ssid)
1025 {
1026 	struct rtw_rsvd_page *rsvd_pkt;
1027 	u8 location = 0;
1028 
1029 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
1030 		if (rsvd_pkt->type != RSVD_PROBE_REQ)
1031 			continue;
1032 		if ((!ssid && !rsvd_pkt->ssid) ||
1033 		    cfg80211_ssid_eq(rsvd_pkt->ssid, ssid))
1034 			location = rsvd_pkt->page;
1035 	}
1036 
1037 	return location;
1038 }
1039 
1040 static u16 rtw_get_rsvd_page_probe_req_size(struct rtw_dev *rtwdev,
1041 					    struct cfg80211_ssid *ssid)
1042 {
1043 	struct rtw_rsvd_page *rsvd_pkt;
1044 	u16 size = 0;
1045 
1046 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
1047 		if (rsvd_pkt->type != RSVD_PROBE_REQ)
1048 			continue;
1049 		if ((!ssid && !rsvd_pkt->ssid) ||
1050 		    cfg80211_ssid_eq(rsvd_pkt->ssid, ssid))
1051 			size = rsvd_pkt->probe_req_size;
1052 	}
1053 
1054 	return size;
1055 }
1056 
1057 void rtw_send_rsvd_page_h2c(struct rtw_dev *rtwdev)
1058 {
1059 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1060 	u8 location = 0;
1061 
1062 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_RSVD_PAGE);
1063 
1064 	location = rtw_get_rsvd_page_location(rtwdev, RSVD_PROBE_RESP);
1065 	*(h2c_pkt + 1) = location;
1066 	rtw_dbg(rtwdev, RTW_DBG_FW, "RSVD_PROBE_RESP loc: %d\n", location);
1067 
1068 	location = rtw_get_rsvd_page_location(rtwdev, RSVD_PS_POLL);
1069 	*(h2c_pkt + 2) = location;
1070 	rtw_dbg(rtwdev, RTW_DBG_FW, "RSVD_PS_POLL loc: %d\n", location);
1071 
1072 	location = rtw_get_rsvd_page_location(rtwdev, RSVD_NULL);
1073 	*(h2c_pkt + 3) = location;
1074 	rtw_dbg(rtwdev, RTW_DBG_FW, "RSVD_NULL loc: %d\n", location);
1075 
1076 	location = rtw_get_rsvd_page_location(rtwdev, RSVD_QOS_NULL);
1077 	*(h2c_pkt + 4) = location;
1078 	rtw_dbg(rtwdev, RTW_DBG_FW, "RSVD_QOS_NULL loc: %d\n", location);
1079 
1080 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
1081 }
1082 
1083 static struct sk_buff *rtw_nlo_info_get(struct ieee80211_hw *hw)
1084 {
1085 	struct rtw_dev *rtwdev = hw->priv;
1086 	const struct rtw_chip_info *chip = rtwdev->chip;
1087 	struct rtw_pno_request *pno_req = &rtwdev->wow.pno_req;
1088 	struct rtw_nlo_info_hdr *nlo_hdr;
1089 	struct cfg80211_ssid *ssid;
1090 	struct sk_buff *skb;
1091 	u8 *pos, loc;
1092 	u32 size;
1093 	int i;
1094 
1095 	if (!pno_req->inited || !pno_req->match_set_cnt)
1096 		return NULL;
1097 
1098 	size = sizeof(struct rtw_nlo_info_hdr) + pno_req->match_set_cnt *
1099 		      IEEE80211_MAX_SSID_LEN + chip->tx_pkt_desc_sz;
1100 
1101 	skb = alloc_skb(size, GFP_KERNEL);
1102 	if (!skb)
1103 		return NULL;
1104 
1105 	skb_reserve(skb, chip->tx_pkt_desc_sz);
1106 
1107 	nlo_hdr = skb_put_zero(skb, sizeof(struct rtw_nlo_info_hdr));
1108 
1109 	nlo_hdr->nlo_count = pno_req->match_set_cnt;
1110 	nlo_hdr->hidden_ap_count = pno_req->match_set_cnt;
1111 
1112 	/* pattern check for firmware */
1113 	memset(nlo_hdr->pattern_check, 0xA5, FW_NLO_INFO_CHECK_SIZE);
1114 
1115 	for (i = 0; i < pno_req->match_set_cnt; i++)
1116 		nlo_hdr->ssid_len[i] = pno_req->match_sets[i].ssid.ssid_len;
1117 
1118 	for (i = 0; i < pno_req->match_set_cnt; i++) {
1119 		ssid = &pno_req->match_sets[i].ssid;
1120 		loc  = rtw_get_rsvd_page_probe_req_location(rtwdev, ssid);
1121 		if (!loc) {
1122 			rtw_err(rtwdev, "failed to get probe req rsvd loc\n");
1123 			kfree_skb(skb);
1124 			return NULL;
1125 		}
1126 		nlo_hdr->location[i] = loc;
1127 	}
1128 
1129 	for (i = 0; i < pno_req->match_set_cnt; i++) {
1130 		pos = skb_put_zero(skb, IEEE80211_MAX_SSID_LEN);
1131 		memcpy(pos, pno_req->match_sets[i].ssid.ssid,
1132 		       pno_req->match_sets[i].ssid.ssid_len);
1133 	}
1134 
1135 	return skb;
1136 }
1137 
1138 static struct sk_buff *rtw_cs_channel_info_get(struct ieee80211_hw *hw)
1139 {
1140 	struct rtw_dev *rtwdev = hw->priv;
1141 	const struct rtw_chip_info *chip = rtwdev->chip;
1142 	struct rtw_pno_request *pno_req = &rtwdev->wow.pno_req;
1143 	struct ieee80211_channel *channels = pno_req->channels;
1144 	struct sk_buff *skb;
1145 	int count =  pno_req->channel_cnt;
1146 	u8 *pos;
1147 	int i = 0;
1148 
1149 	skb = alloc_skb(4 * count + chip->tx_pkt_desc_sz, GFP_KERNEL);
1150 	if (!skb)
1151 		return NULL;
1152 
1153 	skb_reserve(skb, chip->tx_pkt_desc_sz);
1154 
1155 	for (i = 0; i < count; i++) {
1156 		pos = skb_put_zero(skb, 4);
1157 
1158 		CHSW_INFO_SET_CH(pos, channels[i].hw_value);
1159 
1160 		if (channels[i].flags & IEEE80211_CHAN_RADAR)
1161 			CHSW_INFO_SET_ACTION_ID(pos, 0);
1162 		else
1163 			CHSW_INFO_SET_ACTION_ID(pos, 1);
1164 		CHSW_INFO_SET_TIMEOUT(pos, 1);
1165 		CHSW_INFO_SET_PRI_CH_IDX(pos, 1);
1166 		CHSW_INFO_SET_BW(pos, 0);
1167 	}
1168 
1169 	return skb;
1170 }
1171 
1172 static struct sk_buff *rtw_lps_pg_dpk_get(struct ieee80211_hw *hw)
1173 {
1174 	struct rtw_dev *rtwdev = hw->priv;
1175 	const struct rtw_chip_info *chip = rtwdev->chip;
1176 	struct rtw_dpk_info *dpk_info = &rtwdev->dm_info.dpk_info;
1177 	struct rtw_lps_pg_dpk_hdr *dpk_hdr;
1178 	struct sk_buff *skb;
1179 	u32 size;
1180 
1181 	size = chip->tx_pkt_desc_sz + sizeof(*dpk_hdr);
1182 	skb = alloc_skb(size, GFP_KERNEL);
1183 	if (!skb)
1184 		return NULL;
1185 
1186 	skb_reserve(skb, chip->tx_pkt_desc_sz);
1187 	dpk_hdr = skb_put_zero(skb, sizeof(*dpk_hdr));
1188 	dpk_hdr->dpk_ch = dpk_info->dpk_ch;
1189 	dpk_hdr->dpk_path_ok = dpk_info->dpk_path_ok[0];
1190 	memcpy(dpk_hdr->dpk_txagc, dpk_info->dpk_txagc, 2);
1191 	memcpy(dpk_hdr->dpk_gs, dpk_info->dpk_gs, 4);
1192 	memcpy(dpk_hdr->coef, dpk_info->coef, 160);
1193 
1194 	return skb;
1195 }
1196 
1197 static struct sk_buff *rtw_lps_pg_info_get(struct ieee80211_hw *hw)
1198 {
1199 	struct rtw_dev *rtwdev = hw->priv;
1200 	const struct rtw_chip_info *chip = rtwdev->chip;
1201 	struct rtw_lps_conf *conf = &rtwdev->lps_conf;
1202 	struct rtw_lps_pg_info_hdr *pg_info_hdr;
1203 	struct rtw_wow_param *rtw_wow = &rtwdev->wow;
1204 	struct sk_buff *skb;
1205 	u32 size;
1206 
1207 	size = chip->tx_pkt_desc_sz + sizeof(*pg_info_hdr);
1208 	skb = alloc_skb(size, GFP_KERNEL);
1209 	if (!skb)
1210 		return NULL;
1211 
1212 	skb_reserve(skb, chip->tx_pkt_desc_sz);
1213 	pg_info_hdr = skb_put_zero(skb, sizeof(*pg_info_hdr));
1214 	pg_info_hdr->tx_bu_page_count = rtwdev->fifo.rsvd_drv_pg_num;
1215 	pg_info_hdr->macid = find_first_bit(rtwdev->mac_id_map, RTW_MAX_MAC_ID_NUM);
1216 	pg_info_hdr->sec_cam_count =
1217 		rtw_sec_cam_pg_backup(rtwdev, pg_info_hdr->sec_cam);
1218 	pg_info_hdr->pattern_count = rtw_wow->pattern_cnt;
1219 
1220 	conf->sec_cam_backup = pg_info_hdr->sec_cam_count != 0;
1221 	conf->pattern_cam_backup = rtw_wow->pattern_cnt != 0;
1222 
1223 	return skb;
1224 }
1225 
1226 static struct sk_buff *rtw_get_rsvd_page_skb(struct ieee80211_hw *hw,
1227 					     struct rtw_rsvd_page *rsvd_pkt)
1228 {
1229 	struct ieee80211_vif *vif;
1230 	struct rtw_vif *rtwvif;
1231 	struct sk_buff *skb_new;
1232 	struct cfg80211_ssid *ssid;
1233 	u16 tim_offset = 0;
1234 
1235 	if (rsvd_pkt->type == RSVD_DUMMY) {
1236 		skb_new = alloc_skb(1, GFP_KERNEL);
1237 		if (!skb_new)
1238 			return NULL;
1239 
1240 		skb_put(skb_new, 1);
1241 		return skb_new;
1242 	}
1243 
1244 	rtwvif = rsvd_pkt->rtwvif;
1245 	if (!rtwvif)
1246 		return NULL;
1247 
1248 	vif = rtwvif_to_vif(rtwvif);
1249 
1250 	switch (rsvd_pkt->type) {
1251 	case RSVD_BEACON:
1252 		skb_new = ieee80211_beacon_get_tim(hw, vif, &tim_offset, NULL, 0);
1253 		rsvd_pkt->tim_offset = tim_offset;
1254 		break;
1255 	case RSVD_PS_POLL:
1256 		skb_new = ieee80211_pspoll_get(hw, vif);
1257 		break;
1258 	case RSVD_PROBE_RESP:
1259 		skb_new = ieee80211_proberesp_get(hw, vif);
1260 		break;
1261 	case RSVD_NULL:
1262 		skb_new = ieee80211_nullfunc_get(hw, vif, -1, false);
1263 		break;
1264 	case RSVD_QOS_NULL:
1265 		skb_new = ieee80211_nullfunc_get(hw, vif, -1, true);
1266 		break;
1267 	case RSVD_LPS_PG_DPK:
1268 		skb_new = rtw_lps_pg_dpk_get(hw);
1269 		break;
1270 	case RSVD_LPS_PG_INFO:
1271 		skb_new = rtw_lps_pg_info_get(hw);
1272 		break;
1273 	case RSVD_PROBE_REQ:
1274 		ssid = (struct cfg80211_ssid *)rsvd_pkt->ssid;
1275 		if (ssid)
1276 			skb_new = ieee80211_probereq_get(hw, vif->addr,
1277 							 ssid->ssid,
1278 							 ssid->ssid_len, 0);
1279 		else
1280 			skb_new = ieee80211_probereq_get(hw, vif->addr, NULL, 0, 0);
1281 		if (skb_new)
1282 			rsvd_pkt->probe_req_size = (u16)skb_new->len;
1283 		break;
1284 	case RSVD_NLO_INFO:
1285 		skb_new = rtw_nlo_info_get(hw);
1286 		break;
1287 	case RSVD_CH_INFO:
1288 		skb_new = rtw_cs_channel_info_get(hw);
1289 		break;
1290 	default:
1291 		return NULL;
1292 	}
1293 
1294 	if (!skb_new)
1295 		return NULL;
1296 
1297 	return skb_new;
1298 }
1299 
1300 static void rtw_fill_rsvd_page_desc(struct rtw_dev *rtwdev, struct sk_buff *skb,
1301 				    enum rtw_rsvd_packet_type type)
1302 {
1303 	struct rtw_tx_pkt_info pkt_info = {0};
1304 	const struct rtw_chip_info *chip = rtwdev->chip;
1305 	u8 *pkt_desc;
1306 
1307 	rtw_tx_rsvd_page_pkt_info_update(rtwdev, &pkt_info, skb, type);
1308 	pkt_desc = skb_push(skb, chip->tx_pkt_desc_sz);
1309 	memset(pkt_desc, 0, chip->tx_pkt_desc_sz);
1310 	rtw_tx_fill_tx_desc(rtwdev, &pkt_info, skb);
1311 }
1312 
1313 static inline u8 rtw_len_to_page(unsigned int len, u16 page_size)
1314 {
1315 	return DIV_ROUND_UP(len, page_size);
1316 }
1317 
1318 static void rtw_rsvd_page_list_to_buf(struct rtw_dev *rtwdev, u16 page_size,
1319 				      u16 page_margin, u32 page, u8 *buf,
1320 				      struct rtw_rsvd_page *rsvd_pkt)
1321 {
1322 	struct sk_buff *skb = rsvd_pkt->skb;
1323 
1324 	if (page >= 1)
1325 		memcpy(buf + page_margin + page_size * (page - 1),
1326 		       skb->data, skb->len);
1327 	else
1328 		memcpy(buf, skb->data, skb->len);
1329 }
1330 
1331 static struct rtw_rsvd_page *rtw_alloc_rsvd_page(struct rtw_dev *rtwdev,
1332 						 enum rtw_rsvd_packet_type type,
1333 						 bool txdesc)
1334 {
1335 	struct rtw_rsvd_page *rsvd_pkt = NULL;
1336 
1337 	rsvd_pkt = kzalloc_obj(*rsvd_pkt);
1338 
1339 	if (!rsvd_pkt)
1340 		return NULL;
1341 
1342 	INIT_LIST_HEAD(&rsvd_pkt->vif_list);
1343 	INIT_LIST_HEAD(&rsvd_pkt->build_list);
1344 	rsvd_pkt->type = type;
1345 	rsvd_pkt->add_txdesc = txdesc;
1346 
1347 	return rsvd_pkt;
1348 }
1349 
1350 static void rtw_insert_rsvd_page(struct rtw_dev *rtwdev,
1351 				 struct rtw_vif *rtwvif,
1352 				 struct rtw_rsvd_page *rsvd_pkt)
1353 {
1354 	lockdep_assert_held(&rtwdev->mutex);
1355 
1356 	list_add_tail(&rsvd_pkt->vif_list, &rtwvif->rsvd_page_list);
1357 }
1358 
1359 static void rtw_add_rsvd_page(struct rtw_dev *rtwdev,
1360 			      struct rtw_vif *rtwvif,
1361 			      enum rtw_rsvd_packet_type type,
1362 			      bool txdesc)
1363 {
1364 	struct rtw_rsvd_page *rsvd_pkt;
1365 
1366 	rsvd_pkt = rtw_alloc_rsvd_page(rtwdev, type, txdesc);
1367 	if (!rsvd_pkt) {
1368 		rtw_err(rtwdev, "failed to alloc rsvd page %d\n", type);
1369 		return;
1370 	}
1371 
1372 	rsvd_pkt->rtwvif = rtwvif;
1373 	rtw_insert_rsvd_page(rtwdev, rtwvif, rsvd_pkt);
1374 }
1375 
1376 static void rtw_add_rsvd_page_probe_req(struct rtw_dev *rtwdev,
1377 					struct rtw_vif *rtwvif,
1378 					struct cfg80211_ssid *ssid)
1379 {
1380 	struct rtw_rsvd_page *rsvd_pkt;
1381 
1382 	rsvd_pkt = rtw_alloc_rsvd_page(rtwdev, RSVD_PROBE_REQ, true);
1383 	if (!rsvd_pkt) {
1384 		rtw_err(rtwdev, "failed to alloc probe req rsvd page\n");
1385 		return;
1386 	}
1387 
1388 	rsvd_pkt->rtwvif = rtwvif;
1389 	rsvd_pkt->ssid = ssid;
1390 	rtw_insert_rsvd_page(rtwdev, rtwvif, rsvd_pkt);
1391 }
1392 
1393 void rtw_remove_rsvd_page(struct rtw_dev *rtwdev,
1394 			  struct rtw_vif *rtwvif)
1395 {
1396 	struct rtw_rsvd_page *rsvd_pkt, *tmp;
1397 
1398 	lockdep_assert_held(&rtwdev->mutex);
1399 
1400 	/* remove all of the rsvd pages for vif */
1401 	list_for_each_entry_safe(rsvd_pkt, tmp, &rtwvif->rsvd_page_list,
1402 				 vif_list) {
1403 		list_del(&rsvd_pkt->vif_list);
1404 		if (!list_empty(&rsvd_pkt->build_list))
1405 			list_del(&rsvd_pkt->build_list);
1406 		kfree(rsvd_pkt);
1407 	}
1408 }
1409 
1410 void rtw_add_rsvd_page_bcn(struct rtw_dev *rtwdev,
1411 			   struct rtw_vif *rtwvif)
1412 {
1413 	struct ieee80211_vif *vif = rtwvif_to_vif(rtwvif);
1414 
1415 	if (vif->type != NL80211_IFTYPE_AP &&
1416 	    vif->type != NL80211_IFTYPE_ADHOC &&
1417 	    vif->type != NL80211_IFTYPE_MESH_POINT) {
1418 		rtw_warn(rtwdev, "Cannot add beacon rsvd page for %d\n",
1419 			 vif->type);
1420 		return;
1421 	}
1422 
1423 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_BEACON, false);
1424 }
1425 
1426 void rtw_add_rsvd_page_pno(struct rtw_dev *rtwdev,
1427 			   struct rtw_vif *rtwvif)
1428 {
1429 	struct ieee80211_vif *vif = rtwvif_to_vif(rtwvif);
1430 	struct rtw_wow_param *rtw_wow = &rtwdev->wow;
1431 	struct rtw_pno_request *rtw_pno_req = &rtw_wow->pno_req;
1432 	struct cfg80211_ssid *ssid;
1433 	int i;
1434 
1435 	if (vif->type != NL80211_IFTYPE_STATION) {
1436 		rtw_warn(rtwdev, "Cannot add PNO rsvd page for %d\n",
1437 			 vif->type);
1438 		return;
1439 	}
1440 
1441 	for (i = 0 ; i < rtw_pno_req->match_set_cnt; i++) {
1442 		ssid = &rtw_pno_req->match_sets[i].ssid;
1443 		rtw_add_rsvd_page_probe_req(rtwdev, rtwvif, ssid);
1444 	}
1445 
1446 	rtw_add_rsvd_page_probe_req(rtwdev, rtwvif, NULL);
1447 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_NLO_INFO, false);
1448 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_CH_INFO, true);
1449 }
1450 
1451 void rtw_add_rsvd_page_sta(struct rtw_dev *rtwdev,
1452 			   struct rtw_vif *rtwvif)
1453 {
1454 	struct ieee80211_vif *vif = rtwvif_to_vif(rtwvif);
1455 
1456 	if (vif->type != NL80211_IFTYPE_STATION) {
1457 		rtw_warn(rtwdev, "Cannot add sta rsvd page for %d\n",
1458 			 vif->type);
1459 		return;
1460 	}
1461 
1462 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_PS_POLL, true);
1463 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_QOS_NULL, true);
1464 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_NULL, true);
1465 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_LPS_PG_DPK, true);
1466 	rtw_add_rsvd_page(rtwdev, rtwvif, RSVD_LPS_PG_INFO, true);
1467 }
1468 
1469 int rtw_fw_write_data_rsvd_page(struct rtw_dev *rtwdev, u16 pg_addr,
1470 				u8 *buf, u32 size)
1471 {
1472 	u8 bckp[3];
1473 	u8 val;
1474 	u16 rsvd_pg_head;
1475 	u32 bcn_valid_addr;
1476 	u32 bcn_valid_mask;
1477 	int ret;
1478 
1479 	lockdep_assert_held(&rtwdev->mutex);
1480 
1481 	if (!size)
1482 		return -EINVAL;
1483 
1484 	bckp[2] = rtw_read8(rtwdev, REG_BCN_CTRL);
1485 
1486 	if (rtw_chip_wcpu_8051(rtwdev)) {
1487 		rtw_write32_set(rtwdev, REG_DWBCN0_CTRL, BIT_BCN_VALID);
1488 	} else {
1489 		pg_addr &= BIT_MASK_BCN_HEAD_1_V1;
1490 		pg_addr |= BIT_BCN_VALID_V1;
1491 		rtw_write16(rtwdev, REG_FIFOPAGE_CTRL_2, pg_addr);
1492 	}
1493 
1494 	val = rtw_read8(rtwdev, REG_CR + 1);
1495 	bckp[0] = val;
1496 	val |= BIT_ENSWBCN >> 8;
1497 	rtw_write8(rtwdev, REG_CR + 1, val);
1498 
1499 	rtw_write8(rtwdev, REG_BCN_CTRL,
1500 		   (bckp[2] & ~BIT_EN_BCN_FUNCTION) | BIT_DIS_TSF_UDT);
1501 
1502 	if (rtw_hci_type(rtwdev) == RTW_HCI_TYPE_PCIE) {
1503 		val = rtw_read8(rtwdev, REG_FWHW_TXQ_CTRL + 2);
1504 		bckp[1] = val;
1505 		val &= ~(BIT_EN_BCNQ_DL >> 16);
1506 		rtw_write8(rtwdev, REG_FWHW_TXQ_CTRL + 2, val);
1507 	}
1508 
1509 	ret = rtw_hci_write_data_rsvd_page(rtwdev, buf, size);
1510 	if (ret) {
1511 		rtw_err(rtwdev, "failed to write data to rsvd page\n");
1512 		goto restore;
1513 	}
1514 
1515 	if (rtw_chip_wcpu_8051(rtwdev)) {
1516 		bcn_valid_addr = REG_DWBCN0_CTRL;
1517 		bcn_valid_mask = BIT_BCN_VALID;
1518 	} else {
1519 		bcn_valid_addr = REG_FIFOPAGE_CTRL_2;
1520 		bcn_valid_mask = BIT_BCN_VALID_V1;
1521 	}
1522 
1523 	if (!check_hw_ready(rtwdev, bcn_valid_addr, bcn_valid_mask, 1)) {
1524 		rtw_err(rtwdev, "error beacon valid\n");
1525 		ret = -EBUSY;
1526 	}
1527 
1528 restore:
1529 	rsvd_pg_head = rtwdev->fifo.rsvd_boundary;
1530 	rtw_write16(rtwdev, REG_FIFOPAGE_CTRL_2,
1531 		    rsvd_pg_head | BIT_BCN_VALID_V1);
1532 	rtw_write8(rtwdev, REG_BCN_CTRL, bckp[2]);
1533 	if (rtw_hci_type(rtwdev) == RTW_HCI_TYPE_PCIE)
1534 		rtw_write8(rtwdev, REG_FWHW_TXQ_CTRL + 2, bckp[1]);
1535 	rtw_write8(rtwdev, REG_CR + 1, bckp[0]);
1536 
1537 	return ret;
1538 }
1539 
1540 static int rtw_download_drv_rsvd_page(struct rtw_dev *rtwdev, u8 *buf, u32 size)
1541 {
1542 	u32 pg_size;
1543 	u32 pg_num = 0;
1544 	u16 pg_addr = 0;
1545 
1546 	pg_size = rtwdev->chip->page_size;
1547 	pg_num = size / pg_size + ((size & (pg_size - 1)) ? 1 : 0);
1548 	if (pg_num > rtwdev->fifo.rsvd_drv_pg_num)
1549 		return -ENOMEM;
1550 
1551 	pg_addr = rtwdev->fifo.rsvd_drv_addr;
1552 
1553 	return rtw_fw_write_data_rsvd_page(rtwdev, pg_addr, buf, size);
1554 }
1555 
1556 static void __rtw_build_rsvd_page_reset(struct rtw_dev *rtwdev)
1557 {
1558 	struct rtw_rsvd_page *rsvd_pkt, *tmp;
1559 
1560 	list_for_each_entry_safe(rsvd_pkt, tmp, &rtwdev->rsvd_page_list,
1561 				 build_list) {
1562 		list_del_init(&rsvd_pkt->build_list);
1563 
1564 		/* Don't free except for the dummy rsvd page,
1565 		 * others will be freed when removing vif
1566 		 */
1567 		if (rsvd_pkt->type == RSVD_DUMMY)
1568 			kfree(rsvd_pkt);
1569 	}
1570 }
1571 
1572 static void rtw_build_rsvd_page_iter(void *data, u8 *mac,
1573 				     struct ieee80211_vif *vif)
1574 {
1575 	struct rtw_dev *rtwdev = data;
1576 	struct rtw_vif *rtwvif = (struct rtw_vif *)vif->drv_priv;
1577 	struct rtw_rsvd_page *rsvd_pkt;
1578 
1579 	/* AP not yet started, don't gather its rsvd pages */
1580 	if (vif->type == NL80211_IFTYPE_AP && !rtwdev->ap_active)
1581 		return;
1582 
1583 	list_for_each_entry(rsvd_pkt, &rtwvif->rsvd_page_list, vif_list) {
1584 		if (rsvd_pkt->type == RSVD_BEACON)
1585 			list_add(&rsvd_pkt->build_list,
1586 				 &rtwdev->rsvd_page_list);
1587 		else
1588 			list_add_tail(&rsvd_pkt->build_list,
1589 				      &rtwdev->rsvd_page_list);
1590 	}
1591 }
1592 
1593 static int  __rtw_build_rsvd_page_from_vifs(struct rtw_dev *rtwdev)
1594 {
1595 	struct rtw_rsvd_page *rsvd_pkt;
1596 
1597 	__rtw_build_rsvd_page_reset(rtwdev);
1598 
1599 	/* gather rsvd page from vifs */
1600 	rtw_iterate_vifs_atomic(rtwdev, rtw_build_rsvd_page_iter, rtwdev);
1601 
1602 	rsvd_pkt = list_first_entry_or_null(&rtwdev->rsvd_page_list,
1603 					    struct rtw_rsvd_page, build_list);
1604 	if (!rsvd_pkt) {
1605 		WARN(1, "Should not have an empty reserved page\n");
1606 		return -EINVAL;
1607 	}
1608 
1609 	/* the first rsvd should be beacon, otherwise add a dummy one */
1610 	if (rsvd_pkt->type != RSVD_BEACON) {
1611 		struct rtw_rsvd_page *dummy_pkt;
1612 
1613 		dummy_pkt = rtw_alloc_rsvd_page(rtwdev, RSVD_DUMMY, false);
1614 		if (!dummy_pkt) {
1615 			rtw_err(rtwdev, "failed to alloc dummy rsvd page\n");
1616 			return -ENOMEM;
1617 		}
1618 
1619 		list_add(&dummy_pkt->build_list, &rtwdev->rsvd_page_list);
1620 	}
1621 
1622 	return 0;
1623 }
1624 
1625 static u8 *rtw_build_rsvd_page(struct rtw_dev *rtwdev, u32 *size)
1626 {
1627 	const struct rtw_chip_info *chip = rtwdev->chip;
1628 	struct ieee80211_hw *hw = rtwdev->hw;
1629 	struct rtw_rsvd_page *rsvd_pkt;
1630 	struct sk_buff *iter;
1631 	u16 page_size, page_margin, tx_desc_sz;
1632 	u8 total_page = 0;
1633 	u32 page = 0;
1634 	u8 *buf;
1635 	int ret;
1636 
1637 	page_size = chip->page_size;
1638 	tx_desc_sz = chip->tx_pkt_desc_sz;
1639 	page_margin = page_size - tx_desc_sz;
1640 
1641 	ret = __rtw_build_rsvd_page_from_vifs(rtwdev);
1642 	if (ret) {
1643 		rtw_err(rtwdev,
1644 			"failed to build rsvd page from vifs, ret %d\n", ret);
1645 		return NULL;
1646 	}
1647 
1648 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
1649 		iter = rtw_get_rsvd_page_skb(hw, rsvd_pkt);
1650 		if (!iter) {
1651 			rtw_err(rtwdev, "failed to build rsvd packet\n");
1652 			goto release_skb;
1653 		}
1654 
1655 		/* Fill the tx_desc for the rsvd pkt that requires one.
1656 		 * And iter->len will be added with size of tx_desc_sz.
1657 		 */
1658 		if (rsvd_pkt->add_txdesc)
1659 			rtw_fill_rsvd_page_desc(rtwdev, iter, rsvd_pkt->type);
1660 
1661 		rsvd_pkt->skb = iter;
1662 		rsvd_pkt->page = total_page;
1663 
1664 		/* Reserved page is downloaded via TX path, and TX path will
1665 		 * generate a tx_desc at the header to describe length of
1666 		 * the buffer. If we are not counting page numbers with the
1667 		 * size of tx_desc added at the first rsvd_pkt (usually a
1668 		 * beacon, firmware default refer to the first page as the
1669 		 * content of beacon), we could generate a buffer which size
1670 		 * is smaller than the actual size of the whole rsvd_page
1671 		 */
1672 		if (total_page == 0) {
1673 			if (rsvd_pkt->type != RSVD_BEACON &&
1674 			    rsvd_pkt->type != RSVD_DUMMY) {
1675 				rtw_err(rtwdev, "first page should be a beacon\n");
1676 				goto release_skb;
1677 			}
1678 			total_page += rtw_len_to_page(iter->len + tx_desc_sz,
1679 						      page_size);
1680 		} else {
1681 			total_page += rtw_len_to_page(iter->len, page_size);
1682 		}
1683 	}
1684 
1685 	if (total_page > rtwdev->fifo.rsvd_drv_pg_num) {
1686 		rtw_err(rtwdev, "rsvd page over size: %d\n", total_page);
1687 		goto release_skb;
1688 	}
1689 
1690 	*size = (total_page - 1) * page_size + page_margin;
1691 	buf = kzalloc(*size, GFP_KERNEL);
1692 	if (!buf)
1693 		goto release_skb;
1694 
1695 	/* Copy the content of each rsvd_pkt to the buf, and they should
1696 	 * be aligned to the pages.
1697 	 *
1698 	 * Note that the first rsvd_pkt is a beacon no matter what vif->type.
1699 	 * And that rsvd_pkt does not require tx_desc because when it goes
1700 	 * through TX path, the TX path will generate one for it.
1701 	 */
1702 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
1703 		rtw_rsvd_page_list_to_buf(rtwdev, page_size, page_margin,
1704 					  page, buf, rsvd_pkt);
1705 		if (page == 0)
1706 			page += rtw_len_to_page(rsvd_pkt->skb->len +
1707 						tx_desc_sz, page_size);
1708 		else
1709 			page += rtw_len_to_page(rsvd_pkt->skb->len, page_size);
1710 
1711 		kfree_skb(rsvd_pkt->skb);
1712 		rsvd_pkt->skb = NULL;
1713 	}
1714 
1715 	return buf;
1716 
1717 release_skb:
1718 	list_for_each_entry(rsvd_pkt, &rtwdev->rsvd_page_list, build_list) {
1719 		kfree_skb(rsvd_pkt->skb);
1720 		rsvd_pkt->skb = NULL;
1721 	}
1722 
1723 	return NULL;
1724 }
1725 
1726 static int rtw_download_beacon(struct rtw_dev *rtwdev)
1727 {
1728 	struct ieee80211_hw *hw = rtwdev->hw;
1729 	struct rtw_rsvd_page *rsvd_pkt;
1730 	struct sk_buff *skb;
1731 	int ret = 0;
1732 
1733 	rsvd_pkt = list_first_entry_or_null(&rtwdev->rsvd_page_list,
1734 					    struct rtw_rsvd_page, build_list);
1735 	if (!rsvd_pkt) {
1736 		rtw_err(rtwdev, "failed to get rsvd page from build list\n");
1737 		return -ENOENT;
1738 	}
1739 
1740 	if (rsvd_pkt->type != RSVD_BEACON &&
1741 	    rsvd_pkt->type != RSVD_DUMMY) {
1742 		rtw_err(rtwdev, "invalid rsvd page type %d, should be beacon or dummy\n",
1743 			rsvd_pkt->type);
1744 		return -EINVAL;
1745 	}
1746 
1747 	skb = rtw_get_rsvd_page_skb(hw, rsvd_pkt);
1748 	if (!skb) {
1749 		rtw_err(rtwdev, "failed to get beacon skb\n");
1750 		return -ENOMEM;
1751 	}
1752 
1753 	ret = rtw_download_drv_rsvd_page(rtwdev, skb->data, skb->len);
1754 	if (ret)
1755 		rtw_err(rtwdev, "failed to download drv rsvd page\n");
1756 
1757 	dev_kfree_skb(skb);
1758 
1759 	return ret;
1760 }
1761 
1762 int rtw_fw_download_rsvd_page(struct rtw_dev *rtwdev)
1763 {
1764 	u8 *buf;
1765 	u32 size;
1766 	int ret;
1767 
1768 	buf = rtw_build_rsvd_page(rtwdev, &size);
1769 	if (!buf) {
1770 		rtw_err(rtwdev, "failed to build rsvd page pkt\n");
1771 		return -ENOMEM;
1772 	}
1773 
1774 	ret = rtw_download_drv_rsvd_page(rtwdev, buf, size);
1775 	if (ret) {
1776 		rtw_err(rtwdev, "failed to download drv rsvd page\n");
1777 		goto free;
1778 	}
1779 
1780 	/* The last thing is to download the *ONLY* beacon again, because
1781 	 * the previous tx_desc is to describe the total rsvd page. Download
1782 	 * the beacon again to replace the TX desc header, and we will get
1783 	 * a correct tx_desc for the beacon in the rsvd page.
1784 	 */
1785 	ret = rtw_download_beacon(rtwdev);
1786 	if (ret) {
1787 		rtw_err(rtwdev, "failed to download beacon\n");
1788 		goto free;
1789 	}
1790 
1791 free:
1792 	kfree(buf);
1793 
1794 	return ret;
1795 }
1796 
1797 void rtw_fw_update_beacon_work(struct work_struct *work)
1798 {
1799 	struct rtw_dev *rtwdev = container_of(work, struct rtw_dev,
1800 					      update_beacon_work);
1801 
1802 	mutex_lock(&rtwdev->mutex);
1803 	rtw_fw_download_rsvd_page(rtwdev);
1804 	rtw_send_rsvd_page_h2c(rtwdev);
1805 	mutex_unlock(&rtwdev->mutex);
1806 }
1807 
1808 static void rtw_fw_read_fifo_page(struct rtw_dev *rtwdev, u32 offset, u32 size,
1809 				  u32 *buf, u32 residue, u16 start_pg)
1810 {
1811 	u32 i;
1812 	u16 idx = 0;
1813 	u16 ctl;
1814 
1815 	ctl = rtw_read16(rtwdev, REG_PKTBUF_DBG_CTRL) & 0xf000;
1816 	/* disable rx clock gate */
1817 	rtw_write32_set(rtwdev, REG_RCR, BIT_DISGCLK);
1818 
1819 	do {
1820 		rtw_write16(rtwdev, REG_PKTBUF_DBG_CTRL, start_pg | ctl);
1821 
1822 		for (i = FIFO_DUMP_ADDR + residue;
1823 		     i < FIFO_DUMP_ADDR + FIFO_PAGE_SIZE; i += 4) {
1824 			buf[idx++] = rtw_read32(rtwdev, i);
1825 			size -= 4;
1826 			if (size == 0)
1827 				goto out;
1828 		}
1829 
1830 		residue = 0;
1831 		start_pg++;
1832 	} while (size);
1833 
1834 out:
1835 	rtw_write16(rtwdev, REG_PKTBUF_DBG_CTRL, ctl);
1836 	/* restore rx clock gate */
1837 	rtw_write32_clr(rtwdev, REG_RCR, BIT_DISGCLK);
1838 }
1839 
1840 static void rtw_fw_read_fifo(struct rtw_dev *rtwdev, enum rtw_fw_fifo_sel sel,
1841 			     u32 offset, u32 size, u32 *buf)
1842 {
1843 	const struct rtw_chip_info *chip = rtwdev->chip;
1844 	u32 start_pg, residue;
1845 
1846 	if (sel >= RTW_FW_FIFO_MAX) {
1847 		rtw_dbg(rtwdev, RTW_DBG_FW, "wrong fw fifo sel\n");
1848 		return;
1849 	}
1850 	if (sel == RTW_FW_FIFO_SEL_RSVD_PAGE)
1851 		offset += rtwdev->fifo.rsvd_boundary << TX_PAGE_SIZE_SHIFT;
1852 	residue = offset & (FIFO_PAGE_SIZE - 1);
1853 	start_pg = (offset >> FIFO_PAGE_SIZE_SHIFT) + chip->fw_fifo_addr[sel];
1854 
1855 	rtw_fw_read_fifo_page(rtwdev, offset, size, buf, residue, start_pg);
1856 }
1857 
1858 static bool rtw_fw_dump_check_size(struct rtw_dev *rtwdev,
1859 				   enum rtw_fw_fifo_sel sel,
1860 				   u32 start_addr, u32 size)
1861 {
1862 	switch (sel) {
1863 	case RTW_FW_FIFO_SEL_TX:
1864 	case RTW_FW_FIFO_SEL_RX:
1865 		if ((start_addr + size) > rtwdev->chip->fw_fifo_addr[sel])
1866 			return false;
1867 		fallthrough;
1868 	default:
1869 		return true;
1870 	}
1871 }
1872 
1873 int rtw_fw_dump_fifo(struct rtw_dev *rtwdev, u8 fifo_sel, u32 addr, u32 size,
1874 		     u32 *buffer)
1875 {
1876 	if (!rtwdev->chip->fw_fifo_addr[0]) {
1877 		rtw_dbg(rtwdev, RTW_DBG_FW, "chip not support dump fw fifo\n");
1878 		return -ENOTSUPP;
1879 	}
1880 
1881 	if (size == 0 || !buffer)
1882 		return -EINVAL;
1883 
1884 	if (size & 0x3) {
1885 		rtw_dbg(rtwdev, RTW_DBG_FW, "not 4byte alignment\n");
1886 		return -EINVAL;
1887 	}
1888 
1889 	if (!rtw_fw_dump_check_size(rtwdev, fifo_sel, addr, size)) {
1890 		rtw_dbg(rtwdev, RTW_DBG_FW, "fw fifo dump size overflow\n");
1891 		return -EINVAL;
1892 	}
1893 
1894 	rtw_fw_read_fifo(rtwdev, fifo_sel, addr, size, buffer);
1895 
1896 	return 0;
1897 }
1898 
1899 static void __rtw_fw_update_pkt(struct rtw_dev *rtwdev, u8 pkt_id, u16 size,
1900 				u8 location)
1901 {
1902 	const struct rtw_chip_info *chip = rtwdev->chip;
1903 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1904 	u16 total_size = H2C_PKT_HDR_SIZE + H2C_PKT_UPDATE_PKT_LEN;
1905 
1906 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_UPDATE_PKT);
1907 
1908 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
1909 	UPDATE_PKT_SET_PKT_ID(h2c_pkt, pkt_id);
1910 	UPDATE_PKT_SET_LOCATION(h2c_pkt, location);
1911 
1912 	/* include txdesc size */
1913 	size += chip->tx_pkt_desc_sz;
1914 	UPDATE_PKT_SET_SIZE(h2c_pkt, size);
1915 
1916 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
1917 }
1918 
1919 void rtw_fw_update_pkt_probe_req(struct rtw_dev *rtwdev,
1920 				 struct cfg80211_ssid *ssid)
1921 {
1922 	u8 loc;
1923 	u16 size;
1924 
1925 	loc = rtw_get_rsvd_page_probe_req_location(rtwdev, ssid);
1926 	if (!loc) {
1927 		rtw_err(rtwdev, "failed to get probe_req rsvd loc\n");
1928 		return;
1929 	}
1930 
1931 	size = rtw_get_rsvd_page_probe_req_size(rtwdev, ssid);
1932 	if (!size) {
1933 		rtw_err(rtwdev, "failed to get probe_req rsvd size\n");
1934 		return;
1935 	}
1936 
1937 	__rtw_fw_update_pkt(rtwdev, RTW_PACKET_PROBE_REQ, size, loc);
1938 }
1939 
1940 void rtw_fw_channel_switch(struct rtw_dev *rtwdev, bool enable)
1941 {
1942 	struct rtw_pno_request *rtw_pno_req = &rtwdev->wow.pno_req;
1943 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1944 	u16 total_size = H2C_PKT_HDR_SIZE + H2C_PKT_CH_SWITCH_LEN;
1945 	u8 loc_ch_info;
1946 	const struct rtw_ch_switch_option cs_option = {
1947 		.dest_ch_en = 1,
1948 		.dest_ch = 1,
1949 		.periodic_option = 2,
1950 		.normal_period = 5,
1951 		.normal_period_sel = 0,
1952 		.normal_cycle = 10,
1953 		.slow_period = 1,
1954 		.slow_period_sel = 1,
1955 	};
1956 
1957 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_CH_SWITCH);
1958 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, total_size);
1959 
1960 	CH_SWITCH_SET_START(h2c_pkt, enable);
1961 	CH_SWITCH_SET_DEST_CH_EN(h2c_pkt, cs_option.dest_ch_en);
1962 	CH_SWITCH_SET_DEST_CH(h2c_pkt, cs_option.dest_ch);
1963 	CH_SWITCH_SET_NORMAL_PERIOD(h2c_pkt, cs_option.normal_period);
1964 	CH_SWITCH_SET_NORMAL_PERIOD_SEL(h2c_pkt, cs_option.normal_period_sel);
1965 	CH_SWITCH_SET_SLOW_PERIOD(h2c_pkt, cs_option.slow_period);
1966 	CH_SWITCH_SET_SLOW_PERIOD_SEL(h2c_pkt, cs_option.slow_period_sel);
1967 	CH_SWITCH_SET_NORMAL_CYCLE(h2c_pkt, cs_option.normal_cycle);
1968 	CH_SWITCH_SET_PERIODIC_OPT(h2c_pkt, cs_option.periodic_option);
1969 
1970 	CH_SWITCH_SET_CH_NUM(h2c_pkt, rtw_pno_req->channel_cnt);
1971 	CH_SWITCH_SET_INFO_SIZE(h2c_pkt, rtw_pno_req->channel_cnt * 4);
1972 
1973 	loc_ch_info = rtw_get_rsvd_page_location(rtwdev, RSVD_CH_INFO);
1974 	CH_SWITCH_SET_INFO_LOC(h2c_pkt, loc_ch_info);
1975 
1976 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
1977 }
1978 
1979 void rtw_fw_adaptivity(struct rtw_dev *rtwdev)
1980 {
1981 	struct rtw_dm_info *dm_info = &rtwdev->dm_info;
1982 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
1983 
1984 	if (!rtw_edcca_enabled) {
1985 		dm_info->edcca_mode = RTW_EDCCA_NORMAL;
1986 		rtw_dbg(rtwdev, RTW_DBG_ADAPTIVITY,
1987 			"EDCCA disabled by debugfs\n");
1988 	}
1989 
1990 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_ADAPTIVITY);
1991 	SET_ADAPTIVITY_MODE(h2c_pkt, dm_info->edcca_mode);
1992 	SET_ADAPTIVITY_OPTION(h2c_pkt, 1);
1993 	SET_ADAPTIVITY_IGI(h2c_pkt, dm_info->igi_history[0]);
1994 	SET_ADAPTIVITY_L2H(h2c_pkt, dm_info->l2h_th_ini);
1995 	SET_ADAPTIVITY_DENSITY(h2c_pkt, dm_info->scan_density);
1996 
1997 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
1998 }
1999 
2000 void rtw_fw_scan_notify(struct rtw_dev *rtwdev, bool start)
2001 {
2002 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
2003 
2004 	SET_H2C_CMD_ID_CLASS(h2c_pkt, H2C_CMD_SCAN);
2005 	SET_SCAN_START(h2c_pkt, start);
2006 
2007 	rtw_fw_send_h2c_command(rtwdev, h2c_pkt);
2008 }
2009 
2010 static int rtw_append_probe_req_ie(struct rtw_dev *rtwdev, struct sk_buff *skb,
2011 				   struct sk_buff_head *list, u8 *bands,
2012 				   struct rtw_vif *rtwvif)
2013 {
2014 	const struct rtw_chip_info *chip = rtwdev->chip;
2015 	struct ieee80211_scan_ies *ies = rtwvif->scan_ies;
2016 	struct sk_buff *new;
2017 	u8 idx;
2018 
2019 	for (idx = NL80211_BAND_2GHZ; idx < NUM_NL80211_BANDS; idx++) {
2020 		if (!(BIT(idx) & chip->band))
2021 			continue;
2022 		new = skb_copy(skb, GFP_KERNEL);
2023 		if (!new)
2024 			return -ENOMEM;
2025 		skb_put_data(new, ies->ies[idx], ies->len[idx]);
2026 		skb_put_data(new, ies->common_ies, ies->common_ie_len);
2027 		skb_queue_tail(list, new);
2028 		(*bands)++;
2029 	}
2030 
2031 	return 0;
2032 }
2033 
2034 static int _rtw_hw_scan_update_probe_req(struct rtw_dev *rtwdev, u8 num_probes,
2035 					 struct sk_buff_head *probe_req_list)
2036 {
2037 	const struct rtw_chip_info *chip = rtwdev->chip;
2038 	struct sk_buff *skb, *tmp;
2039 	u16 pg_addr = rtwdev->fifo.rsvd_h2c_info_addr, loc;
2040 	u8 tx_desc_sz = chip->tx_pkt_desc_sz;
2041 	u16 page_size = chip->page_size;
2042 	u8 page_offset = 1, *buf;
2043 	u16 buf_offset = page_size * page_offset;
2044 	unsigned int pkt_len;
2045 	u8 page_cnt, pages;
2046 	int ret;
2047 
2048 	if (rtw_fw_feature_ext_check(&rtwdev->fw, FW_FEATURE_EXT_OLD_PAGE_NUM))
2049 		page_cnt = RTW_OLD_PROBE_PG_CNT;
2050 	else
2051 		page_cnt = RTW_PROBE_PG_CNT;
2052 
2053 	pages = page_offset + num_probes * page_cnt;
2054 
2055 	buf = kzalloc(page_size * pages, GFP_KERNEL);
2056 	if (!buf)
2057 		return -ENOMEM;
2058 
2059 	buf_offset -= tx_desc_sz;
2060 	skb_queue_walk_safe(probe_req_list, skb, tmp) {
2061 		skb_unlink(skb, probe_req_list);
2062 		rtw_fill_rsvd_page_desc(rtwdev, skb, RSVD_PROBE_REQ);
2063 		if (skb->len > page_size * page_cnt) {
2064 			ret = -EINVAL;
2065 			goto out;
2066 		}
2067 
2068 		memcpy(buf + buf_offset, skb->data, skb->len);
2069 		pkt_len = skb->len - tx_desc_sz;
2070 		loc = pg_addr - rtwdev->fifo.rsvd_boundary + page_offset;
2071 		__rtw_fw_update_pkt(rtwdev, RTW_PACKET_PROBE_REQ, pkt_len, loc);
2072 
2073 		buf_offset += page_cnt * page_size;
2074 		page_offset += page_cnt;
2075 		kfree_skb(skb);
2076 	}
2077 
2078 	ret = rtw_fw_write_data_rsvd_page(rtwdev, pg_addr, buf, buf_offset);
2079 	if (ret) {
2080 		rtw_err(rtwdev, "Download probe request to firmware failed\n");
2081 		goto out;
2082 	}
2083 
2084 	rtwdev->scan_info.probe_pg_size = page_offset;
2085 out:
2086 	kfree(buf);
2087 	skb_queue_walk_safe(probe_req_list, skb, tmp)
2088 		kfree_skb(skb);
2089 
2090 	return ret;
2091 }
2092 
2093 static int rtw_hw_scan_update_probe_req(struct rtw_dev *rtwdev,
2094 					struct rtw_vif *rtwvif)
2095 {
2096 	struct cfg80211_scan_request *req = rtwvif->scan_req;
2097 	struct sk_buff_head list;
2098 	struct sk_buff *skb, *tmp;
2099 	u8 num = req->n_ssids, i, bands = 0;
2100 	int ret;
2101 
2102 	skb_queue_head_init(&list);
2103 	for (i = 0; i < num; i++) {
2104 		skb = ieee80211_probereq_get(rtwdev->hw, rtwvif->mac_addr,
2105 					     req->ssids[i].ssid,
2106 					     req->ssids[i].ssid_len,
2107 					     req->ie_len);
2108 		if (!skb) {
2109 			ret = -ENOMEM;
2110 			goto out;
2111 		}
2112 		ret = rtw_append_probe_req_ie(rtwdev, skb, &list, &bands,
2113 					      rtwvif);
2114 		if (ret)
2115 			goto out;
2116 
2117 		kfree_skb(skb);
2118 	}
2119 
2120 	return _rtw_hw_scan_update_probe_req(rtwdev, num * bands, &list);
2121 
2122 out:
2123 	skb_queue_walk_safe(&list, skb, tmp)
2124 		kfree_skb(skb);
2125 
2126 	return ret;
2127 }
2128 
2129 static int rtw_add_chan_info(struct rtw_dev *rtwdev, struct rtw_chan_info *info,
2130 			     struct rtw_chan_list *list, u8 *buf)
2131 {
2132 	u8 *chan = &buf[list->size];
2133 	u8 info_size = RTW_CH_INFO_SIZE;
2134 
2135 	if (list->size > list->buf_size)
2136 		return -ENOMEM;
2137 
2138 	CH_INFO_SET_CH(chan, info->channel);
2139 	CH_INFO_SET_PRI_CH_IDX(chan, info->pri_ch_idx);
2140 	CH_INFO_SET_BW(chan, info->bw);
2141 	CH_INFO_SET_TIMEOUT(chan, info->timeout);
2142 	CH_INFO_SET_ACTION_ID(chan, info->action_id);
2143 	CH_INFO_SET_EXTRA_INFO(chan, info->extra_info);
2144 	if (info->extra_info) {
2145 		EXTRA_CH_INFO_SET_ID(chan, RTW_SCAN_EXTRA_ID_DFS);
2146 		EXTRA_CH_INFO_SET_INFO(chan, RTW_SCAN_EXTRA_ACTION_SCAN);
2147 		EXTRA_CH_INFO_SET_SIZE(chan, RTW_EX_CH_INFO_SIZE -
2148 				       RTW_EX_CH_INFO_HDR_SIZE);
2149 		EXTRA_CH_INFO_SET_DFS_EXT_TIME(chan, RTW_DFS_CHAN_TIME);
2150 		info_size += RTW_EX_CH_INFO_SIZE;
2151 	}
2152 	list->size += info_size;
2153 	list->ch_num++;
2154 
2155 	return 0;
2156 }
2157 
2158 static int rtw_add_chan_list(struct rtw_dev *rtwdev, struct rtw_vif *rtwvif,
2159 			     struct rtw_chan_list *list, u8 *buf)
2160 {
2161 	struct cfg80211_scan_request *req = rtwvif->scan_req;
2162 	struct rtw_fifo_conf *fifo = &rtwdev->fifo;
2163 	struct ieee80211_channel *channel;
2164 	int i, ret = 0;
2165 
2166 	for (i = 0; i < req->n_channels; i++) {
2167 		struct rtw_chan_info ch_info = {0};
2168 
2169 		channel = req->channels[i];
2170 		ch_info.channel = channel->hw_value;
2171 		ch_info.bw = RTW_SCAN_WIDTH;
2172 		ch_info.pri_ch_idx = RTW_PRI_CH_IDX;
2173 		ch_info.timeout = req->duration_mandatory ?
2174 				  req->duration : RTW_CHANNEL_TIME;
2175 
2176 		if (channel->flags & (IEEE80211_CHAN_RADAR | IEEE80211_CHAN_NO_IR)) {
2177 			ch_info.action_id = RTW_CHANNEL_RADAR;
2178 			ch_info.extra_info = 1;
2179 			/* Overwrite duration for passive scans if necessary */
2180 			ch_info.timeout = ch_info.timeout > RTW_PASS_CHAN_TIME ?
2181 					  ch_info.timeout : RTW_PASS_CHAN_TIME;
2182 		} else {
2183 			ch_info.action_id = RTW_CHANNEL_ACTIVE;
2184 		}
2185 
2186 		ret = rtw_add_chan_info(rtwdev, &ch_info, list, buf);
2187 		if (ret)
2188 			return ret;
2189 	}
2190 
2191 	if (list->size > fifo->rsvd_pg_num << TX_PAGE_SIZE_SHIFT) {
2192 		rtw_err(rtwdev, "List exceeds rsvd page total size\n");
2193 		return -EINVAL;
2194 	}
2195 
2196 	list->addr = fifo->rsvd_h2c_info_addr + rtwdev->scan_info.probe_pg_size;
2197 	ret = rtw_fw_write_data_rsvd_page(rtwdev, list->addr, buf, list->size);
2198 	if (ret)
2199 		rtw_err(rtwdev, "Download channel list failed\n");
2200 
2201 	return ret;
2202 }
2203 
2204 static void rtw_fw_set_scan_offload(struct rtw_dev *rtwdev,
2205 				    struct rtw_ch_switch_option *opt,
2206 				    struct rtw_vif *rtwvif,
2207 				    struct rtw_chan_list *list)
2208 {
2209 	struct rtw_hw_scan_info *scan_info = &rtwdev->scan_info;
2210 	struct cfg80211_scan_request *req = rtwvif->scan_req;
2211 	struct rtw_fifo_conf *fifo = &rtwdev->fifo;
2212 	/* reserve one dummy page at the beginning for tx descriptor */
2213 	u8 pkt_loc = fifo->rsvd_h2c_info_addr - fifo->rsvd_boundary + 1;
2214 	bool random_seq = req->flags & NL80211_SCAN_FLAG_RANDOM_SN;
2215 	u8 h2c_pkt[H2C_PKT_SIZE] = {0};
2216 
2217 	rtw_h2c_pkt_set_header(h2c_pkt, H2C_PKT_SCAN_OFFLOAD);
2218 	SET_PKT_H2C_TOTAL_LEN(h2c_pkt, H2C_PKT_CH_SWITCH_LEN);
2219 
2220 	SCAN_OFFLOAD_SET_START(h2c_pkt, opt->switch_en);
2221 	SCAN_OFFLOAD_SET_BACK_OP_EN(h2c_pkt, opt->back_op_en);
2222 	SCAN_OFFLOAD_SET_RANDOM_SEQ_EN(h2c_pkt, random_seq);
2223 	SCAN_OFFLOAD_SET_NO_CCK_EN(h2c_pkt, req->no_cck);
2224 	SCAN_OFFLOAD_SET_CH_NUM(h2c_pkt, list->ch_num);
2225 	SCAN_OFFLOAD_SET_CH_INFO_SIZE(h2c_pkt, list->size);
2226 	SCAN_OFFLOAD_SET_CH_INFO_LOC(h2c_pkt, list->addr - fifo->rsvd_boundary);
2227 	SCAN_OFFLOAD_SET_OP_CH(h2c_pkt, scan_info->op_chan);
2228 	SCAN_OFFLOAD_SET_OP_PRI_CH_IDX(h2c_pkt, scan_info->op_pri_ch_idx);
2229 	SCAN_OFFLOAD_SET_OP_BW(h2c_pkt, scan_info->op_bw);
2230 	SCAN_OFFLOAD_SET_OP_PORT_ID(h2c_pkt, rtwvif->port);
2231 	SCAN_OFFLOAD_SET_OP_DWELL_TIME(h2c_pkt, req->duration_mandatory ?
2232 				       req->duration : RTW_CHANNEL_TIME);
2233 	SCAN_OFFLOAD_SET_OP_GAP_TIME(h2c_pkt, RTW_OFF_CHAN_TIME);
2234 	SCAN_OFFLOAD_SET_SSID_NUM(h2c_pkt, req->n_ssids);
2235 	SCAN_OFFLOAD_SET_PKT_LOC(h2c_pkt, pkt_loc);
2236 
2237 	rtw_fw_send_h2c_packet(rtwdev, h2c_pkt);
2238 }
2239 
2240 void rtw_hw_scan_start(struct rtw_dev *rtwdev, struct ieee80211_vif *vif,
2241 		       struct ieee80211_scan_request *scan_req)
2242 {
2243 	struct rtw_vif *rtwvif = (struct rtw_vif *)vif->drv_priv;
2244 	struct cfg80211_scan_request *req = &scan_req->req;
2245 	u8 mac_addr[ETH_ALEN];
2246 
2247 	rtwdev->scan_info.scanning_vif = vif;
2248 	rtwvif->scan_ies = &scan_req->ies;
2249 	rtwvif->scan_req = req;
2250 
2251 	ieee80211_stop_queues(rtwdev->hw);
2252 	rtw_leave_lps_deep(rtwdev);
2253 	rtw_hci_flush_all_queues(rtwdev, false);
2254 	rtw_mac_flush_all_queues(rtwdev, false);
2255 	if (req->flags & NL80211_SCAN_FLAG_RANDOM_ADDR)
2256 		get_random_mask_addr(mac_addr, req->mac_addr,
2257 				     req->mac_addr_mask);
2258 	else
2259 		ether_addr_copy(mac_addr, vif->addr);
2260 
2261 	rtw_core_scan_start(rtwdev, rtwvif, mac_addr, true);
2262 
2263 	rtwdev->hal.rcr &= ~BIT_CBSSID_BCN;
2264 	rtw_write32(rtwdev, REG_RCR, rtwdev->hal.rcr);
2265 }
2266 
2267 void rtw_hw_scan_complete(struct rtw_dev *rtwdev, struct ieee80211_vif *vif,
2268 			  bool aborted)
2269 {
2270 	struct cfg80211_scan_info info = {
2271 		.aborted = aborted,
2272 	};
2273 	struct rtw_hw_scan_info *scan_info = &rtwdev->scan_info;
2274 	struct rtw_hal *hal = &rtwdev->hal;
2275 	struct rtw_vif *rtwvif;
2276 	u8 chan = scan_info->op_chan;
2277 
2278 	if (!vif)
2279 		return;
2280 
2281 	rtwdev->hal.rcr |= BIT_CBSSID_BCN;
2282 	rtw_write32(rtwdev, REG_RCR, rtwdev->hal.rcr);
2283 
2284 	rtw_core_scan_complete(rtwdev, vif, true);
2285 
2286 	rtwvif = (struct rtw_vif *)vif->drv_priv;
2287 	if (chan)
2288 		rtw_store_op_chan(rtwdev, false);
2289 	rtw_phy_set_tx_power_level(rtwdev, hal->current_channel);
2290 	ieee80211_wake_queues(rtwdev->hw);
2291 	ieee80211_scan_completed(rtwdev->hw, &info);
2292 
2293 	rtwvif->scan_req = NULL;
2294 	rtwvif->scan_ies = NULL;
2295 	rtwdev->scan_info.scanning_vif = NULL;
2296 }
2297 
2298 static int rtw_hw_scan_prehandle(struct rtw_dev *rtwdev, struct rtw_vif *rtwvif,
2299 				 struct rtw_chan_list *list)
2300 {
2301 	struct cfg80211_scan_request *req = rtwvif->scan_req;
2302 	int size = req->n_channels * (RTW_CH_INFO_SIZE + RTW_EX_CH_INFO_SIZE);
2303 	u8 *buf;
2304 	int ret;
2305 
2306 	buf = kmalloc(size, GFP_KERNEL);
2307 	if (!buf)
2308 		return -ENOMEM;
2309 
2310 	ret = rtw_hw_scan_update_probe_req(rtwdev, rtwvif);
2311 	if (ret) {
2312 		rtw_err(rtwdev, "Update probe request failed\n");
2313 		goto out;
2314 	}
2315 
2316 	list->buf_size = size;
2317 	list->size = 0;
2318 	list->ch_num = 0;
2319 	ret = rtw_add_chan_list(rtwdev, rtwvif, list, buf);
2320 out:
2321 	kfree(buf);
2322 
2323 	return ret;
2324 }
2325 
2326 int rtw_hw_scan_offload(struct rtw_dev *rtwdev, struct ieee80211_vif *vif,
2327 			bool enable)
2328 {
2329 	struct rtw_vif *rtwvif = vif ? (struct rtw_vif *)vif->drv_priv : NULL;
2330 	struct rtw_hw_scan_info *scan_info = &rtwdev->scan_info;
2331 	struct rtw_ch_switch_option cs_option = {0};
2332 	struct rtw_chan_list chan_list = {0};
2333 	int ret = 0;
2334 
2335 	if (!rtwvif)
2336 		return -EINVAL;
2337 
2338 	cs_option.switch_en = enable;
2339 	cs_option.back_op_en = scan_info->op_chan != 0;
2340 	if (enable) {
2341 		ret = rtw_hw_scan_prehandle(rtwdev, rtwvif, &chan_list);
2342 		if (ret)
2343 			goto out;
2344 	}
2345 	rtw_fw_set_scan_offload(rtwdev, &cs_option, rtwvif, &chan_list);
2346 out:
2347 	if (rtwdev->ap_active) {
2348 		ret = rtw_download_beacon(rtwdev);
2349 		if (ret)
2350 			rtw_err(rtwdev, "HW scan download beacon failed\n");
2351 	}
2352 
2353 	return ret;
2354 }
2355 
2356 void rtw_hw_scan_abort(struct rtw_dev *rtwdev)
2357 {
2358 	struct ieee80211_vif *vif = rtwdev->scan_info.scanning_vif;
2359 
2360 	if (!rtw_fw_feature_check(&rtwdev->fw, FW_FEATURE_SCAN_OFFLOAD))
2361 		return;
2362 
2363 	rtw_hw_scan_offload(rtwdev, vif, false);
2364 	rtw_hw_scan_complete(rtwdev, vif, true);
2365 }
2366 
2367 void rtw_hw_scan_status_report(struct rtw_dev *rtwdev, struct sk_buff *skb)
2368 {
2369 	struct ieee80211_vif *vif = rtwdev->scan_info.scanning_vif;
2370 	struct rtw_c2h_cmd *c2h;
2371 	bool aborted;
2372 	u8 rc;
2373 
2374 	if (!test_bit(RTW_FLAG_SCANNING, rtwdev->flags))
2375 		return;
2376 
2377 	c2h = get_c2h_from_skb(skb);
2378 	rc = GET_SCAN_REPORT_RETURN_CODE(c2h->payload);
2379 	aborted = rc != RTW_SCAN_REPORT_SUCCESS;
2380 	rtw_hw_scan_complete(rtwdev, vif, aborted);
2381 
2382 	if (aborted)
2383 		rtw_dbg(rtwdev, RTW_DBG_HW_SCAN, "HW scan aborted with code: %d\n", rc);
2384 }
2385 
2386 void rtw_store_op_chan(struct rtw_dev *rtwdev, bool backup)
2387 {
2388 	struct rtw_hw_scan_info *scan_info = &rtwdev->scan_info;
2389 	struct rtw_hal *hal = &rtwdev->hal;
2390 	u8 band;
2391 
2392 	if (backup) {
2393 		scan_info->op_chan = hal->current_channel;
2394 		scan_info->op_bw = hal->current_band_width;
2395 		scan_info->op_pri_ch_idx = hal->current_primary_channel_index;
2396 		scan_info->op_pri_ch = hal->primary_channel;
2397 	} else {
2398 		band = scan_info->op_chan > 14 ? RTW_BAND_5G : RTW_BAND_2G;
2399 		rtw_update_channel(rtwdev, scan_info->op_chan,
2400 				   scan_info->op_pri_ch,
2401 				   band, scan_info->op_bw);
2402 	}
2403 }
2404 
2405 void rtw_clear_op_chan(struct rtw_dev *rtwdev)
2406 {
2407 	struct rtw_hw_scan_info *scan_info = &rtwdev->scan_info;
2408 
2409 	scan_info->op_chan = 0;
2410 	scan_info->op_bw = 0;
2411 	scan_info->op_pri_ch_idx = 0;
2412 	scan_info->op_pri_ch = 0;
2413 }
2414 
2415 static bool rtw_is_op_chan(struct rtw_dev *rtwdev, u8 channel)
2416 {
2417 	struct rtw_hw_scan_info *scan_info = &rtwdev->scan_info;
2418 
2419 	return channel == scan_info->op_chan;
2420 }
2421 
2422 void rtw_hw_scan_chan_switch(struct rtw_dev *rtwdev, struct sk_buff *skb)
2423 {
2424 	struct rtw_hal *hal = &rtwdev->hal;
2425 	struct rtw_c2h_cmd *c2h;
2426 	enum rtw_scan_notify_id id;
2427 	u8 chan, band, status;
2428 
2429 	if (!test_bit(RTW_FLAG_SCANNING, rtwdev->flags))
2430 		return;
2431 
2432 	c2h = get_c2h_from_skb(skb);
2433 	chan = GET_CHAN_SWITCH_CENTRAL_CH(c2h->payload);
2434 	id = GET_CHAN_SWITCH_ID(c2h->payload);
2435 	status = GET_CHAN_SWITCH_STATUS(c2h->payload);
2436 
2437 	if (id == RTW_SCAN_NOTIFY_ID_POSTSWITCH) {
2438 		band = chan > 14 ? RTW_BAND_5G : RTW_BAND_2G;
2439 		rtw_update_channel(rtwdev, chan, chan, band,
2440 				   RTW_CHANNEL_WIDTH_20);
2441 		if (rtw_is_op_chan(rtwdev, chan)) {
2442 			rtw_store_op_chan(rtwdev, false);
2443 			ieee80211_wake_queues(rtwdev->hw);
2444 			rtw_core_enable_beacon(rtwdev, true);
2445 		}
2446 	} else if (id == RTW_SCAN_NOTIFY_ID_PRESWITCH) {
2447 		if (IS_CH_5G_BAND(chan)) {
2448 			rtw_coex_switchband_notify(rtwdev, COEX_SWITCH_TO_5G);
2449 		} else if (IS_CH_2G_BAND(chan)) {
2450 			u8 chan_type;
2451 
2452 			if (test_bit(RTW_FLAG_SCANNING, rtwdev->flags))
2453 				chan_type = COEX_SWITCH_TO_24G;
2454 			else
2455 				chan_type = COEX_SWITCH_TO_24G_NOFORSCAN;
2456 			rtw_coex_switchband_notify(rtwdev, chan_type);
2457 		}
2458 		/* The channel of C2H RTW_SCAN_NOTIFY_ID_PRESWITCH is next
2459 		 * channel that hardware will switch. We need to stop queue
2460 		 * if next channel is non-op channel.
2461 		 */
2462 		if (!rtw_is_op_chan(rtwdev, chan) &&
2463 		    rtw_is_op_chan(rtwdev, hal->current_channel)) {
2464 			rtw_core_enable_beacon(rtwdev, false);
2465 			ieee80211_stop_queues(rtwdev->hw);
2466 		}
2467 	}
2468 
2469 	rtw_dbg(rtwdev, RTW_DBG_HW_SCAN,
2470 		"Chan switch: %x, id: %x, status: %x\n", chan, id, status);
2471 }
2472