xref: /linux/drivers/net/wireless/ath/ath11k/wmi.c (revision 7f356166aebb0d956d367dfe55e19d7783277d09)
1 // SPDX-License-Identifier: BSD-3-Clause-Clear
2 /*
3  * Copyright (c) 2018-2019 The Linux Foundation. All rights reserved.
4  */
5 #include <linux/skbuff.h>
6 #include <linux/ctype.h>
7 #include <net/mac80211.h>
8 #include <net/cfg80211.h>
9 #include <linux/completion.h>
10 #include <linux/if_ether.h>
11 #include <linux/types.h>
12 #include <linux/pci.h>
13 #include <linux/uuid.h>
14 #include <linux/time.h>
15 #include <linux/of.h>
16 #include "core.h"
17 #include "debug.h"
18 #include "mac.h"
19 #include "hw.h"
20 #include "peer.h"
21 
22 struct wmi_tlv_policy {
23 	size_t min_len;
24 };
25 
26 struct wmi_tlv_svc_ready_parse {
27 	bool wmi_svc_bitmap_done;
28 };
29 
30 struct wmi_tlv_dma_ring_caps_parse {
31 	struct wmi_dma_ring_capabilities *dma_ring_caps;
32 	u32 n_dma_ring_caps;
33 };
34 
35 struct wmi_tlv_svc_rdy_ext_parse {
36 	struct ath11k_service_ext_param param;
37 	struct wmi_soc_mac_phy_hw_mode_caps *hw_caps;
38 	struct wmi_hw_mode_capabilities *hw_mode_caps;
39 	u32 n_hw_mode_caps;
40 	u32 tot_phy_id;
41 	struct wmi_hw_mode_capabilities pref_hw_mode_caps;
42 	struct wmi_mac_phy_capabilities *mac_phy_caps;
43 	u32 n_mac_phy_caps;
44 	struct wmi_soc_hal_reg_capabilities *soc_hal_reg_caps;
45 	struct wmi_hal_reg_capabilities_ext *ext_hal_reg_caps;
46 	u32 n_ext_hal_reg_caps;
47 	struct wmi_tlv_dma_ring_caps_parse dma_caps_parse;
48 	bool hw_mode_done;
49 	bool mac_phy_done;
50 	bool ext_hal_reg_done;
51 	bool mac_phy_chainmask_combo_done;
52 	bool mac_phy_chainmask_cap_done;
53 	bool oem_dma_ring_cap_done;
54 	bool dma_ring_cap_done;
55 };
56 
57 struct wmi_tlv_svc_rdy_ext2_parse {
58 	struct wmi_tlv_dma_ring_caps_parse dma_caps_parse;
59 	bool dma_ring_cap_done;
60 };
61 
62 struct wmi_tlv_rdy_parse {
63 	u32 num_extra_mac_addr;
64 };
65 
66 struct wmi_tlv_dma_buf_release_parse {
67 	struct ath11k_wmi_dma_buf_release_fixed_param fixed;
68 	struct wmi_dma_buf_release_entry *buf_entry;
69 	struct wmi_dma_buf_release_meta_data *meta_data;
70 	u32 num_buf_entry;
71 	u32 num_meta;
72 	bool buf_entry_done;
73 	bool meta_data_done;
74 };
75 
76 static const struct wmi_tlv_policy wmi_tlv_policies[] = {
77 	[WMI_TAG_ARRAY_BYTE]
78 		= { .min_len = 0 },
79 	[WMI_TAG_ARRAY_UINT32]
80 		= { .min_len = 0 },
81 	[WMI_TAG_SERVICE_READY_EVENT]
82 		= { .min_len = sizeof(struct wmi_service_ready_event) },
83 	[WMI_TAG_SERVICE_READY_EXT_EVENT]
84 		= { .min_len =  sizeof(struct wmi_service_ready_ext_event) },
85 	[WMI_TAG_SOC_MAC_PHY_HW_MODE_CAPS]
86 		= { .min_len = sizeof(struct wmi_soc_mac_phy_hw_mode_caps) },
87 	[WMI_TAG_SOC_HAL_REG_CAPABILITIES]
88 		= { .min_len = sizeof(struct wmi_soc_hal_reg_capabilities) },
89 	[WMI_TAG_VDEV_START_RESPONSE_EVENT]
90 		= { .min_len = sizeof(struct wmi_vdev_start_resp_event) },
91 	[WMI_TAG_PEER_DELETE_RESP_EVENT]
92 		= { .min_len = sizeof(struct wmi_peer_delete_resp_event) },
93 	[WMI_TAG_OFFLOAD_BCN_TX_STATUS_EVENT]
94 		= { .min_len = sizeof(struct wmi_bcn_tx_status_event) },
95 	[WMI_TAG_VDEV_STOPPED_EVENT]
96 		= { .min_len = sizeof(struct wmi_vdev_stopped_event) },
97 	[WMI_TAG_REG_CHAN_LIST_CC_EVENT]
98 		= { .min_len = sizeof(struct wmi_reg_chan_list_cc_event) },
99 	[WMI_TAG_MGMT_RX_HDR]
100 		= { .min_len = sizeof(struct wmi_mgmt_rx_hdr) },
101 	[WMI_TAG_MGMT_TX_COMPL_EVENT]
102 		= { .min_len = sizeof(struct wmi_mgmt_tx_compl_event) },
103 	[WMI_TAG_SCAN_EVENT]
104 		= { .min_len = sizeof(struct wmi_scan_event) },
105 	[WMI_TAG_PEER_STA_KICKOUT_EVENT]
106 		= { .min_len = sizeof(struct wmi_peer_sta_kickout_event) },
107 	[WMI_TAG_ROAM_EVENT]
108 		= { .min_len = sizeof(struct wmi_roam_event) },
109 	[WMI_TAG_CHAN_INFO_EVENT]
110 		= { .min_len = sizeof(struct wmi_chan_info_event) },
111 	[WMI_TAG_PDEV_BSS_CHAN_INFO_EVENT]
112 		= { .min_len = sizeof(struct wmi_pdev_bss_chan_info_event) },
113 	[WMI_TAG_VDEV_INSTALL_KEY_COMPLETE_EVENT]
114 		= { .min_len = sizeof(struct wmi_vdev_install_key_compl_event) },
115 	[WMI_TAG_READY_EVENT] = {
116 		.min_len = sizeof(struct wmi_ready_event_min) },
117 	[WMI_TAG_SERVICE_AVAILABLE_EVENT]
118 		= {.min_len = sizeof(struct wmi_service_available_event) },
119 	[WMI_TAG_PEER_ASSOC_CONF_EVENT]
120 		= { .min_len = sizeof(struct wmi_peer_assoc_conf_event) },
121 	[WMI_TAG_STATS_EVENT]
122 		= { .min_len = sizeof(struct wmi_stats_event) },
123 	[WMI_TAG_PDEV_CTL_FAILSAFE_CHECK_EVENT]
124 		= { .min_len = sizeof(struct wmi_pdev_ctl_failsafe_chk_event) },
125 	[WMI_TAG_HOST_SWFDA_EVENT] = {
126 		.min_len = sizeof(struct wmi_fils_discovery_event) },
127 	[WMI_TAG_OFFLOAD_PRB_RSP_TX_STATUS_EVENT] = {
128 		.min_len = sizeof(struct wmi_probe_resp_tx_status_event) },
129 	[WMI_TAG_VDEV_DELETE_RESP_EVENT] = {
130 		.min_len = sizeof(struct wmi_vdev_delete_resp_event) },
131 };
132 
133 #define PRIMAP(_hw_mode_) \
134 	[_hw_mode_] = _hw_mode_##_PRI
135 
136 static const int ath11k_hw_mode_pri_map[] = {
137 	PRIMAP(WMI_HOST_HW_MODE_SINGLE),
138 	PRIMAP(WMI_HOST_HW_MODE_DBS),
139 	PRIMAP(WMI_HOST_HW_MODE_SBS_PASSIVE),
140 	PRIMAP(WMI_HOST_HW_MODE_SBS),
141 	PRIMAP(WMI_HOST_HW_MODE_DBS_SBS),
142 	PRIMAP(WMI_HOST_HW_MODE_DBS_OR_SBS),
143 	/* keep last */
144 	PRIMAP(WMI_HOST_HW_MODE_MAX),
145 };
146 
147 static int
148 ath11k_wmi_tlv_iter(struct ath11k_base *ab, const void *ptr, size_t len,
149 		    int (*iter)(struct ath11k_base *ab, u16 tag, u16 len,
150 				const void *ptr, void *data),
151 		    void *data)
152 {
153 	const void *begin = ptr;
154 	const struct wmi_tlv *tlv;
155 	u16 tlv_tag, tlv_len;
156 	int ret;
157 
158 	while (len > 0) {
159 		if (len < sizeof(*tlv)) {
160 			ath11k_err(ab, "wmi tlv parse failure at byte %zd (%zu bytes left, %zu expected)\n",
161 				   ptr - begin, len, sizeof(*tlv));
162 			return -EINVAL;
163 		}
164 
165 		tlv = ptr;
166 		tlv_tag = FIELD_GET(WMI_TLV_TAG, tlv->header);
167 		tlv_len = FIELD_GET(WMI_TLV_LEN, tlv->header);
168 		ptr += sizeof(*tlv);
169 		len -= sizeof(*tlv);
170 
171 		if (tlv_len > len) {
172 			ath11k_err(ab, "wmi tlv parse failure of tag %hhu at byte %zd (%zu bytes left, %hhu expected)\n",
173 				   tlv_tag, ptr - begin, len, tlv_len);
174 			return -EINVAL;
175 		}
176 
177 		if (tlv_tag < ARRAY_SIZE(wmi_tlv_policies) &&
178 		    wmi_tlv_policies[tlv_tag].min_len &&
179 		    wmi_tlv_policies[tlv_tag].min_len > tlv_len) {
180 			ath11k_err(ab, "wmi tlv parse failure of tag %hhu at byte %zd (%hhu bytes is less than min length %zu)\n",
181 				   tlv_tag, ptr - begin, tlv_len,
182 				   wmi_tlv_policies[tlv_tag].min_len);
183 			return -EINVAL;
184 		}
185 
186 		ret = iter(ab, tlv_tag, tlv_len, ptr, data);
187 		if (ret)
188 			return ret;
189 
190 		ptr += tlv_len;
191 		len -= tlv_len;
192 	}
193 
194 	return 0;
195 }
196 
197 static int ath11k_wmi_tlv_iter_parse(struct ath11k_base *ab, u16 tag, u16 len,
198 				     const void *ptr, void *data)
199 {
200 	const void **tb = data;
201 
202 	if (tag < WMI_TAG_MAX)
203 		tb[tag] = ptr;
204 
205 	return 0;
206 }
207 
208 static int ath11k_wmi_tlv_parse(struct ath11k_base *ar, const void **tb,
209 				const void *ptr, size_t len)
210 {
211 	return ath11k_wmi_tlv_iter(ar, ptr, len, ath11k_wmi_tlv_iter_parse,
212 				   (void *)tb);
213 }
214 
215 static const void **
216 ath11k_wmi_tlv_parse_alloc(struct ath11k_base *ab, const void *ptr,
217 			   size_t len, gfp_t gfp)
218 {
219 	const void **tb;
220 	int ret;
221 
222 	tb = kcalloc(WMI_TAG_MAX, sizeof(*tb), gfp);
223 	if (!tb)
224 		return ERR_PTR(-ENOMEM);
225 
226 	ret = ath11k_wmi_tlv_parse(ab, tb, ptr, len);
227 	if (ret) {
228 		kfree(tb);
229 		return ERR_PTR(ret);
230 	}
231 
232 	return tb;
233 }
234 
235 static int ath11k_wmi_cmd_send_nowait(struct ath11k_pdev_wmi *wmi, struct sk_buff *skb,
236 				      u32 cmd_id)
237 {
238 	struct ath11k_skb_cb *skb_cb = ATH11K_SKB_CB(skb);
239 	struct ath11k_base *ab = wmi->wmi_ab->ab;
240 	struct wmi_cmd_hdr *cmd_hdr;
241 	int ret;
242 	u32 cmd = 0;
243 
244 	if (skb_push(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
245 		return -ENOMEM;
246 
247 	cmd |= FIELD_PREP(WMI_CMD_HDR_CMD_ID, cmd_id);
248 
249 	cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
250 	cmd_hdr->cmd_id = cmd;
251 
252 	memset(skb_cb, 0, sizeof(*skb_cb));
253 	ret = ath11k_htc_send(&ab->htc, wmi->eid, skb);
254 
255 	if (ret)
256 		goto err_pull;
257 
258 	return 0;
259 
260 err_pull:
261 	skb_pull(skb, sizeof(struct wmi_cmd_hdr));
262 	return ret;
263 }
264 
265 int ath11k_wmi_cmd_send(struct ath11k_pdev_wmi *wmi, struct sk_buff *skb,
266 			u32 cmd_id)
267 {
268 	struct ath11k_wmi_base *wmi_sc = wmi->wmi_ab;
269 	int ret = -EOPNOTSUPP;
270 
271 	might_sleep();
272 
273 	wait_event_timeout(wmi_sc->tx_credits_wq, ({
274 		ret = ath11k_wmi_cmd_send_nowait(wmi, skb, cmd_id);
275 
276 		if (ret && test_bit(ATH11K_FLAG_CRASH_FLUSH, &wmi_sc->ab->dev_flags))
277 			ret = -ESHUTDOWN;
278 
279 		(ret != -EAGAIN);
280 	}), WMI_SEND_TIMEOUT_HZ);
281 
282 	if (ret == -EAGAIN)
283 		ath11k_warn(wmi_sc->ab, "wmi command %d timeout\n", cmd_id);
284 
285 	return ret;
286 }
287 
288 static int ath11k_pull_svc_ready_ext(struct ath11k_pdev_wmi *wmi_handle,
289 				     const void *ptr,
290 				     struct ath11k_service_ext_param *param)
291 {
292 	const struct wmi_service_ready_ext_event *ev = ptr;
293 
294 	if (!ev)
295 		return -EINVAL;
296 
297 	/* Move this to host based bitmap */
298 	param->default_conc_scan_config_bits = ev->default_conc_scan_config_bits;
299 	param->default_fw_config_bits =	ev->default_fw_config_bits;
300 	param->he_cap_info = ev->he_cap_info;
301 	param->mpdu_density = ev->mpdu_density;
302 	param->max_bssid_rx_filters = ev->max_bssid_rx_filters;
303 	memcpy(&param->ppet, &ev->ppet, sizeof(param->ppet));
304 
305 	return 0;
306 }
307 
308 static int
309 ath11k_pull_mac_phy_cap_svc_ready_ext(struct ath11k_pdev_wmi *wmi_handle,
310 				      struct wmi_soc_mac_phy_hw_mode_caps *hw_caps,
311 				      struct wmi_hw_mode_capabilities *wmi_hw_mode_caps,
312 				      struct wmi_soc_hal_reg_capabilities *hal_reg_caps,
313 				      struct wmi_mac_phy_capabilities *wmi_mac_phy_caps,
314 				      u8 hw_mode_id, u8 phy_id,
315 				      struct ath11k_pdev *pdev)
316 {
317 	struct wmi_mac_phy_capabilities *mac_phy_caps;
318 	struct ath11k_band_cap *cap_band;
319 	struct ath11k_pdev_cap *pdev_cap = &pdev->cap;
320 	u32 phy_map;
321 	u32 hw_idx, phy_idx = 0;
322 
323 	if (!hw_caps || !wmi_hw_mode_caps || !hal_reg_caps)
324 		return -EINVAL;
325 
326 	for (hw_idx = 0; hw_idx < hw_caps->num_hw_modes; hw_idx++) {
327 		if (hw_mode_id == wmi_hw_mode_caps[hw_idx].hw_mode_id)
328 			break;
329 
330 		phy_map = wmi_hw_mode_caps[hw_idx].phy_id_map;
331 		while (phy_map) {
332 			phy_map >>= 1;
333 			phy_idx++;
334 		}
335 	}
336 
337 	if (hw_idx == hw_caps->num_hw_modes)
338 		return -EINVAL;
339 
340 	phy_idx += phy_id;
341 	if (phy_id >= hal_reg_caps->num_phy)
342 		return -EINVAL;
343 
344 	mac_phy_caps = wmi_mac_phy_caps + phy_idx;
345 
346 	pdev->pdev_id = mac_phy_caps->pdev_id;
347 	pdev_cap->supported_bands |= mac_phy_caps->supported_bands;
348 	pdev_cap->ampdu_density = mac_phy_caps->ampdu_density;
349 
350 	/* Take non-zero tx/rx chainmask. If tx/rx chainmask differs from
351 	 * band to band for a single radio, need to see how this should be
352 	 * handled.
353 	 */
354 	if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_2G_CAP) {
355 		pdev_cap->tx_chain_mask = mac_phy_caps->tx_chain_mask_2g;
356 		pdev_cap->rx_chain_mask = mac_phy_caps->rx_chain_mask_2g;
357 	} else if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_5G_CAP) {
358 		pdev_cap->vht_cap = mac_phy_caps->vht_cap_info_5g;
359 		pdev_cap->vht_mcs = mac_phy_caps->vht_supp_mcs_5g;
360 		pdev_cap->he_mcs = mac_phy_caps->he_supp_mcs_5g;
361 		pdev_cap->tx_chain_mask = mac_phy_caps->tx_chain_mask_5g;
362 		pdev_cap->rx_chain_mask = mac_phy_caps->rx_chain_mask_5g;
363 	} else {
364 		return -EINVAL;
365 	}
366 
367 	/* tx/rx chainmask reported from fw depends on the actual hw chains used,
368 	 * For example, for 4x4 capable macphys, first 4 chains can be used for first
369 	 * mac and the remaing 4 chains can be used for the second mac or vice-versa.
370 	 * In this case, tx/rx chainmask 0xf will be advertised for first mac and 0xf0
371 	 * will be advertised for second mac or vice-versa. Compute the shift value
372 	 * for tx/rx chainmask which will be used to advertise supported ht/vht rates to
373 	 * mac80211.
374 	 */
375 	pdev_cap->tx_chain_mask_shift =
376 			find_first_bit((unsigned long *)&pdev_cap->tx_chain_mask, 32);
377 	pdev_cap->rx_chain_mask_shift =
378 			find_first_bit((unsigned long *)&pdev_cap->rx_chain_mask, 32);
379 
380 	if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_2G_CAP) {
381 		cap_band = &pdev_cap->band[NL80211_BAND_2GHZ];
382 		cap_band->phy_id = mac_phy_caps->phy_id;
383 		cap_band->max_bw_supported = mac_phy_caps->max_bw_supported_2g;
384 		cap_band->ht_cap_info = mac_phy_caps->ht_cap_info_2g;
385 		cap_band->he_cap_info[0] = mac_phy_caps->he_cap_info_2g;
386 		cap_band->he_cap_info[1] = mac_phy_caps->he_cap_info_2g_ext;
387 		cap_band->he_mcs = mac_phy_caps->he_supp_mcs_2g;
388 		memcpy(cap_band->he_cap_phy_info, &mac_phy_caps->he_cap_phy_info_2g,
389 		       sizeof(u32) * PSOC_HOST_MAX_PHY_SIZE);
390 		memcpy(&cap_band->he_ppet, &mac_phy_caps->he_ppet2g,
391 		       sizeof(struct ath11k_ppe_threshold));
392 	}
393 
394 	if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_5G_CAP) {
395 		cap_band = &pdev_cap->band[NL80211_BAND_5GHZ];
396 		cap_band->phy_id = mac_phy_caps->phy_id;
397 		cap_band->max_bw_supported = mac_phy_caps->max_bw_supported_5g;
398 		cap_band->ht_cap_info = mac_phy_caps->ht_cap_info_5g;
399 		cap_band->he_cap_info[0] = mac_phy_caps->he_cap_info_5g;
400 		cap_band->he_cap_info[1] = mac_phy_caps->he_cap_info_5g_ext;
401 		cap_band->he_mcs = mac_phy_caps->he_supp_mcs_5g;
402 		memcpy(cap_band->he_cap_phy_info, &mac_phy_caps->he_cap_phy_info_5g,
403 		       sizeof(u32) * PSOC_HOST_MAX_PHY_SIZE);
404 		memcpy(&cap_band->he_ppet, &mac_phy_caps->he_ppet5g,
405 		       sizeof(struct ath11k_ppe_threshold));
406 	}
407 
408 	cap_band = &pdev_cap->band[NL80211_BAND_6GHZ];
409 	cap_band->max_bw_supported = mac_phy_caps->max_bw_supported_5g;
410 	cap_band->ht_cap_info = mac_phy_caps->ht_cap_info_5g;
411 	cap_band->he_cap_info[0] = mac_phy_caps->he_cap_info_5g;
412 	cap_band->he_cap_info[1] = mac_phy_caps->he_cap_info_5g_ext;
413 	cap_band->he_mcs = mac_phy_caps->he_supp_mcs_5g;
414 	memcpy(cap_band->he_cap_phy_info, &mac_phy_caps->he_cap_phy_info_5g,
415 	       sizeof(u32) * PSOC_HOST_MAX_PHY_SIZE);
416 	memcpy(&cap_band->he_ppet, &mac_phy_caps->he_ppet5g,
417 	       sizeof(struct ath11k_ppe_threshold));
418 
419 	return 0;
420 }
421 
422 static int
423 ath11k_pull_reg_cap_svc_rdy_ext(struct ath11k_pdev_wmi *wmi_handle,
424 				struct wmi_soc_hal_reg_capabilities *reg_caps,
425 				struct wmi_hal_reg_capabilities_ext *wmi_ext_reg_cap,
426 				u8 phy_idx,
427 				struct ath11k_hal_reg_capabilities_ext *param)
428 {
429 	struct wmi_hal_reg_capabilities_ext *ext_reg_cap;
430 
431 	if (!reg_caps || !wmi_ext_reg_cap)
432 		return -EINVAL;
433 
434 	if (phy_idx >= reg_caps->num_phy)
435 		return -EINVAL;
436 
437 	ext_reg_cap = &wmi_ext_reg_cap[phy_idx];
438 
439 	param->phy_id = ext_reg_cap->phy_id;
440 	param->eeprom_reg_domain = ext_reg_cap->eeprom_reg_domain;
441 	param->eeprom_reg_domain_ext =
442 			      ext_reg_cap->eeprom_reg_domain_ext;
443 	param->regcap1 = ext_reg_cap->regcap1;
444 	param->regcap2 = ext_reg_cap->regcap2;
445 	/* check if param->wireless_mode is needed */
446 	param->low_2ghz_chan = ext_reg_cap->low_2ghz_chan;
447 	param->high_2ghz_chan = ext_reg_cap->high_2ghz_chan;
448 	param->low_5ghz_chan = ext_reg_cap->low_5ghz_chan;
449 	param->high_5ghz_chan = ext_reg_cap->high_5ghz_chan;
450 
451 	return 0;
452 }
453 
454 static int ath11k_pull_service_ready_tlv(struct ath11k_base *ab,
455 					 const void *evt_buf,
456 					 struct ath11k_targ_cap *cap)
457 {
458 	const struct wmi_service_ready_event *ev = evt_buf;
459 
460 	if (!ev) {
461 		ath11k_err(ab, "%s: failed by NULL param\n",
462 			   __func__);
463 		return -EINVAL;
464 	}
465 
466 	cap->phy_capability = ev->phy_capability;
467 	cap->max_frag_entry = ev->max_frag_entry;
468 	cap->num_rf_chains = ev->num_rf_chains;
469 	cap->ht_cap_info = ev->ht_cap_info;
470 	cap->vht_cap_info = ev->vht_cap_info;
471 	cap->vht_supp_mcs = ev->vht_supp_mcs;
472 	cap->hw_min_tx_power = ev->hw_min_tx_power;
473 	cap->hw_max_tx_power = ev->hw_max_tx_power;
474 	cap->sys_cap_info = ev->sys_cap_info;
475 	cap->min_pkt_size_enable = ev->min_pkt_size_enable;
476 	cap->max_bcn_ie_size = ev->max_bcn_ie_size;
477 	cap->max_num_scan_channels = ev->max_num_scan_channels;
478 	cap->max_supported_macs = ev->max_supported_macs;
479 	cap->wmi_fw_sub_feat_caps = ev->wmi_fw_sub_feat_caps;
480 	cap->txrx_chainmask = ev->txrx_chainmask;
481 	cap->default_dbs_hw_mode_index = ev->default_dbs_hw_mode_index;
482 	cap->num_msdu_desc = ev->num_msdu_desc;
483 
484 	return 0;
485 }
486 
487 /* Save the wmi_service_bitmap into a linear bitmap. The wmi_services in
488  * wmi_service ready event are advertised in b0-b3 (LSB 4-bits) of each
489  * 4-byte word.
490  */
491 static void ath11k_wmi_service_bitmap_copy(struct ath11k_pdev_wmi *wmi,
492 					   const u32 *wmi_svc_bm)
493 {
494 	int i, j;
495 
496 	for (i = 0, j = 0; i < WMI_SERVICE_BM_SIZE && j < WMI_MAX_SERVICE; i++) {
497 		do {
498 			if (wmi_svc_bm[i] & BIT(j % WMI_SERVICE_BITS_IN_SIZE32))
499 				set_bit(j, wmi->wmi_ab->svc_map);
500 		} while (++j % WMI_SERVICE_BITS_IN_SIZE32);
501 	}
502 }
503 
504 static int ath11k_wmi_tlv_svc_rdy_parse(struct ath11k_base *ab, u16 tag, u16 len,
505 					const void *ptr, void *data)
506 {
507 	struct wmi_tlv_svc_ready_parse *svc_ready = data;
508 	struct ath11k_pdev_wmi *wmi_handle = &ab->wmi_ab.wmi[0];
509 	u16 expect_len;
510 
511 	switch (tag) {
512 	case WMI_TAG_SERVICE_READY_EVENT:
513 		if (ath11k_pull_service_ready_tlv(ab, ptr, &ab->target_caps))
514 			return -EINVAL;
515 		break;
516 
517 	case WMI_TAG_ARRAY_UINT32:
518 		if (!svc_ready->wmi_svc_bitmap_done) {
519 			expect_len = WMI_SERVICE_BM_SIZE * sizeof(u32);
520 			if (len < expect_len) {
521 				ath11k_warn(ab, "invalid len %d for the tag 0x%x\n",
522 					    len, tag);
523 				return -EINVAL;
524 			}
525 
526 			ath11k_wmi_service_bitmap_copy(wmi_handle, ptr);
527 
528 			svc_ready->wmi_svc_bitmap_done = true;
529 		}
530 		break;
531 	default:
532 		break;
533 	}
534 
535 	return 0;
536 }
537 
538 static int ath11k_service_ready_event(struct ath11k_base *ab, struct sk_buff *skb)
539 {
540 	struct wmi_tlv_svc_ready_parse svc_ready = { };
541 	int ret;
542 
543 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
544 				  ath11k_wmi_tlv_svc_rdy_parse,
545 				  &svc_ready);
546 	if (ret) {
547 		ath11k_warn(ab, "failed to parse tlv %d\n", ret);
548 		return ret;
549 	}
550 
551 	return 0;
552 }
553 
554 struct sk_buff *ath11k_wmi_alloc_skb(struct ath11k_wmi_base *wmi_sc, u32 len)
555 {
556 	struct sk_buff *skb;
557 	struct ath11k_base *ab = wmi_sc->ab;
558 	u32 round_len = roundup(len, 4);
559 
560 	skb = ath11k_htc_alloc_skb(ab, WMI_SKB_HEADROOM + round_len);
561 	if (!skb)
562 		return NULL;
563 
564 	skb_reserve(skb, WMI_SKB_HEADROOM);
565 	if (!IS_ALIGNED((unsigned long)skb->data, 4))
566 		ath11k_warn(ab, "unaligned WMI skb data\n");
567 
568 	skb_put(skb, round_len);
569 	memset(skb->data, 0, round_len);
570 
571 	return skb;
572 }
573 
574 int ath11k_wmi_mgmt_send(struct ath11k *ar, u32 vdev_id, u32 buf_id,
575 			 struct sk_buff *frame)
576 {
577 	struct ath11k_pdev_wmi *wmi = ar->wmi;
578 	struct wmi_mgmt_send_cmd *cmd;
579 	struct wmi_tlv *frame_tlv;
580 	struct sk_buff *skb;
581 	u32 buf_len;
582 	int ret, len;
583 
584 	buf_len = frame->len < WMI_MGMT_SEND_DOWNLD_LEN ?
585 		  frame->len : WMI_MGMT_SEND_DOWNLD_LEN;
586 
587 	len = sizeof(*cmd) + sizeof(*frame_tlv) + roundup(buf_len, 4);
588 
589 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
590 	if (!skb)
591 		return -ENOMEM;
592 
593 	cmd = (struct wmi_mgmt_send_cmd *)skb->data;
594 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_MGMT_TX_SEND_CMD) |
595 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
596 	cmd->vdev_id = vdev_id;
597 	cmd->desc_id = buf_id;
598 	cmd->chanfreq = 0;
599 	cmd->paddr_lo = lower_32_bits(ATH11K_SKB_CB(frame)->paddr);
600 	cmd->paddr_hi = upper_32_bits(ATH11K_SKB_CB(frame)->paddr);
601 	cmd->frame_len = frame->len;
602 	cmd->buf_len = buf_len;
603 	cmd->tx_params_valid = 0;
604 
605 	frame_tlv = (struct wmi_tlv *)(skb->data + sizeof(*cmd));
606 	frame_tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
607 			    FIELD_PREP(WMI_TLV_LEN, buf_len);
608 
609 	memcpy(frame_tlv->value, frame->data, buf_len);
610 
611 	ath11k_ce_byte_swap(frame_tlv->value, buf_len);
612 
613 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_MGMT_TX_SEND_CMDID);
614 	if (ret) {
615 		ath11k_warn(ar->ab,
616 			    "failed to submit WMI_MGMT_TX_SEND_CMDID cmd\n");
617 		dev_kfree_skb(skb);
618 	}
619 
620 	return ret;
621 }
622 
623 int ath11k_wmi_vdev_create(struct ath11k *ar, u8 *macaddr,
624 			   struct vdev_create_params *param)
625 {
626 	struct ath11k_pdev_wmi *wmi = ar->wmi;
627 	struct wmi_vdev_create_cmd *cmd;
628 	struct sk_buff *skb;
629 	struct wmi_vdev_txrx_streams *txrx_streams;
630 	struct wmi_tlv *tlv;
631 	int ret, len;
632 	void *ptr;
633 
634 	/* It can be optimized my sending tx/rx chain configuration
635 	 * only for supported bands instead of always sending it for
636 	 * both the bands.
637 	 */
638 	len = sizeof(*cmd) + TLV_HDR_SIZE +
639 		(WMI_NUM_SUPPORTED_BAND_MAX * sizeof(*txrx_streams));
640 
641 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
642 	if (!skb)
643 		return -ENOMEM;
644 
645 	cmd = (struct wmi_vdev_create_cmd *)skb->data;
646 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_CREATE_CMD) |
647 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
648 
649 	cmd->vdev_id = param->if_id;
650 	cmd->vdev_type = param->type;
651 	cmd->vdev_subtype = param->subtype;
652 	cmd->num_cfg_txrx_streams = WMI_NUM_SUPPORTED_BAND_MAX;
653 	cmd->pdev_id = param->pdev_id;
654 	ether_addr_copy(cmd->vdev_macaddr.addr, macaddr);
655 
656 	ptr = skb->data + sizeof(*cmd);
657 	len = WMI_NUM_SUPPORTED_BAND_MAX * sizeof(*txrx_streams);
658 
659 	tlv = ptr;
660 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
661 		      FIELD_PREP(WMI_TLV_LEN, len);
662 
663 	ptr += TLV_HDR_SIZE;
664 	txrx_streams = ptr;
665 	len = sizeof(*txrx_streams);
666 	txrx_streams->tlv_header =
667 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_TXRX_STREAMS) |
668 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
669 	txrx_streams->band = WMI_TPC_CHAINMASK_CONFIG_BAND_2G;
670 	txrx_streams->supported_tx_streams =
671 				 param->chains[NL80211_BAND_2GHZ].tx;
672 	txrx_streams->supported_rx_streams =
673 				 param->chains[NL80211_BAND_2GHZ].rx;
674 
675 	txrx_streams++;
676 	txrx_streams->tlv_header =
677 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_TXRX_STREAMS) |
678 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
679 	txrx_streams->band = WMI_TPC_CHAINMASK_CONFIG_BAND_5G;
680 	txrx_streams->supported_tx_streams =
681 				 param->chains[NL80211_BAND_5GHZ].tx;
682 	txrx_streams->supported_rx_streams =
683 				 param->chains[NL80211_BAND_5GHZ].rx;
684 
685 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_CREATE_CMDID);
686 	if (ret) {
687 		ath11k_warn(ar->ab,
688 			    "failed to submit WMI_VDEV_CREATE_CMDID\n");
689 		dev_kfree_skb(skb);
690 	}
691 
692 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
693 		   "WMI vdev create: id %d type %d subtype %d macaddr %pM pdevid %d\n",
694 		   param->if_id, param->type, param->subtype,
695 		   macaddr, param->pdev_id);
696 
697 	return ret;
698 }
699 
700 int ath11k_wmi_vdev_delete(struct ath11k *ar, u8 vdev_id)
701 {
702 	struct ath11k_pdev_wmi *wmi = ar->wmi;
703 	struct wmi_vdev_delete_cmd *cmd;
704 	struct sk_buff *skb;
705 	int ret;
706 
707 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
708 	if (!skb)
709 		return -ENOMEM;
710 
711 	cmd = (struct wmi_vdev_delete_cmd *)skb->data;
712 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_DELETE_CMD) |
713 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
714 	cmd->vdev_id = vdev_id;
715 
716 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_DELETE_CMDID);
717 	if (ret) {
718 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_DELETE_CMDID\n");
719 		dev_kfree_skb(skb);
720 	}
721 
722 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "WMI vdev delete id %d\n", vdev_id);
723 
724 	return ret;
725 }
726 
727 int ath11k_wmi_vdev_stop(struct ath11k *ar, u8 vdev_id)
728 {
729 	struct ath11k_pdev_wmi *wmi = ar->wmi;
730 	struct wmi_vdev_stop_cmd *cmd;
731 	struct sk_buff *skb;
732 	int ret;
733 
734 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
735 	if (!skb)
736 		return -ENOMEM;
737 
738 	cmd = (struct wmi_vdev_stop_cmd *)skb->data;
739 
740 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_STOP_CMD) |
741 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
742 	cmd->vdev_id = vdev_id;
743 
744 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_STOP_CMDID);
745 	if (ret) {
746 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_STOP cmd\n");
747 		dev_kfree_skb(skb);
748 	}
749 
750 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "WMI vdev stop id 0x%x\n", vdev_id);
751 
752 	return ret;
753 }
754 
755 int ath11k_wmi_vdev_down(struct ath11k *ar, u8 vdev_id)
756 {
757 	struct ath11k_pdev_wmi *wmi = ar->wmi;
758 	struct wmi_vdev_down_cmd *cmd;
759 	struct sk_buff *skb;
760 	int ret;
761 
762 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
763 	if (!skb)
764 		return -ENOMEM;
765 
766 	cmd = (struct wmi_vdev_down_cmd *)skb->data;
767 
768 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_DOWN_CMD) |
769 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
770 	cmd->vdev_id = vdev_id;
771 
772 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_DOWN_CMDID);
773 	if (ret) {
774 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_DOWN cmd\n");
775 		dev_kfree_skb(skb);
776 	}
777 
778 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "WMI vdev down id 0x%x\n", vdev_id);
779 
780 	return ret;
781 }
782 
783 static void ath11k_wmi_put_wmi_channel(struct wmi_channel *chan,
784 				       struct wmi_vdev_start_req_arg *arg)
785 {
786 	memset(chan, 0, sizeof(*chan));
787 
788 	chan->mhz = arg->channel.freq;
789 	chan->band_center_freq1 = arg->channel.band_center_freq1;
790 	if (arg->channel.mode == MODE_11AC_VHT80_80)
791 		chan->band_center_freq2 = arg->channel.band_center_freq2;
792 	else
793 		chan->band_center_freq2 = 0;
794 
795 	chan->info |= FIELD_PREP(WMI_CHAN_INFO_MODE, arg->channel.mode);
796 	if (arg->channel.passive)
797 		chan->info |= WMI_CHAN_INFO_PASSIVE;
798 	if (arg->channel.allow_ibss)
799 		chan->info |= WMI_CHAN_INFO_ADHOC_ALLOWED;
800 	if (arg->channel.allow_ht)
801 		chan->info |= WMI_CHAN_INFO_ALLOW_HT;
802 	if (arg->channel.allow_vht)
803 		chan->info |= WMI_CHAN_INFO_ALLOW_VHT;
804 	if (arg->channel.allow_he)
805 		chan->info |= WMI_CHAN_INFO_ALLOW_HE;
806 	if (arg->channel.ht40plus)
807 		chan->info |= WMI_CHAN_INFO_HT40_PLUS;
808 	if (arg->channel.chan_radar)
809 		chan->info |= WMI_CHAN_INFO_DFS;
810 	if (arg->channel.freq2_radar)
811 		chan->info |= WMI_CHAN_INFO_DFS_FREQ2;
812 
813 	chan->reg_info_1 = FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_PWR,
814 				      arg->channel.max_power) |
815 		FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_REG_PWR,
816 			   arg->channel.max_reg_power);
817 
818 	chan->reg_info_2 = FIELD_PREP(WMI_CHAN_REG_INFO2_ANT_MAX,
819 				      arg->channel.max_antenna_gain) |
820 		FIELD_PREP(WMI_CHAN_REG_INFO2_MAX_TX_PWR,
821 			   arg->channel.max_power);
822 }
823 
824 int ath11k_wmi_vdev_start(struct ath11k *ar, struct wmi_vdev_start_req_arg *arg,
825 			  bool restart)
826 {
827 	struct ath11k_pdev_wmi *wmi = ar->wmi;
828 	struct wmi_vdev_start_request_cmd *cmd;
829 	struct sk_buff *skb;
830 	struct wmi_channel *chan;
831 	struct wmi_tlv *tlv;
832 	void *ptr;
833 	int ret, len;
834 
835 	if (WARN_ON(arg->ssid_len > sizeof(cmd->ssid.ssid)))
836 		return -EINVAL;
837 
838 	len = sizeof(*cmd) + sizeof(*chan) + TLV_HDR_SIZE;
839 
840 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
841 	if (!skb)
842 		return -ENOMEM;
843 
844 	cmd = (struct wmi_vdev_start_request_cmd *)skb->data;
845 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
846 				     WMI_TAG_VDEV_START_REQUEST_CMD) |
847 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
848 	cmd->vdev_id = arg->vdev_id;
849 	cmd->beacon_interval = arg->bcn_intval;
850 	cmd->bcn_tx_rate = arg->bcn_tx_rate;
851 	cmd->dtim_period = arg->dtim_period;
852 	cmd->num_noa_descriptors = arg->num_noa_descriptors;
853 	cmd->preferred_rx_streams = arg->pref_rx_streams;
854 	cmd->preferred_tx_streams = arg->pref_tx_streams;
855 	cmd->cac_duration_ms = arg->cac_duration_ms;
856 	cmd->regdomain = arg->regdomain;
857 	cmd->he_ops = arg->he_ops;
858 
859 	if (!restart) {
860 		if (arg->ssid) {
861 			cmd->ssid.ssid_len = arg->ssid_len;
862 			memcpy(cmd->ssid.ssid, arg->ssid, arg->ssid_len);
863 		}
864 		if (arg->hidden_ssid)
865 			cmd->flags |= WMI_VDEV_START_HIDDEN_SSID;
866 		if (arg->pmf_enabled)
867 			cmd->flags |= WMI_VDEV_START_PMF_ENABLED;
868 	}
869 
870 	cmd->flags |= WMI_VDEV_START_LDPC_RX_ENABLED;
871 
872 	ptr = skb->data + sizeof(*cmd);
873 	chan = ptr;
874 
875 	ath11k_wmi_put_wmi_channel(chan, arg);
876 
877 	chan->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_CHANNEL) |
878 			   FIELD_PREP(WMI_TLV_LEN,
879 				      sizeof(*chan) - TLV_HDR_SIZE);
880 	ptr += sizeof(*chan);
881 
882 	tlv = ptr;
883 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
884 		      FIELD_PREP(WMI_TLV_LEN, 0);
885 
886 	/* Note: This is a nested TLV containing:
887 	 * [wmi_tlv][wmi_p2p_noa_descriptor][wmi_tlv]..
888 	 */
889 
890 	ptr += sizeof(*tlv);
891 
892 	if (restart)
893 		ret = ath11k_wmi_cmd_send(wmi, skb,
894 					  WMI_VDEV_RESTART_REQUEST_CMDID);
895 	else
896 		ret = ath11k_wmi_cmd_send(wmi, skb,
897 					  WMI_VDEV_START_REQUEST_CMDID);
898 	if (ret) {
899 		ath11k_warn(ar->ab, "failed to submit vdev_%s cmd\n",
900 			    restart ? "restart" : "start");
901 		dev_kfree_skb(skb);
902 	}
903 
904 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "vdev %s id 0x%x freq 0x%x mode 0x%x\n",
905 		   restart ? "restart" : "start", arg->vdev_id,
906 		   arg->channel.freq, arg->channel.mode);
907 
908 	return ret;
909 }
910 
911 int ath11k_wmi_vdev_up(struct ath11k *ar, u32 vdev_id, u32 aid, const u8 *bssid)
912 {
913 	struct ath11k_pdev_wmi *wmi = ar->wmi;
914 	struct wmi_vdev_up_cmd *cmd;
915 	struct sk_buff *skb;
916 	int ret;
917 
918 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
919 	if (!skb)
920 		return -ENOMEM;
921 
922 	cmd = (struct wmi_vdev_up_cmd *)skb->data;
923 
924 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_UP_CMD) |
925 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
926 	cmd->vdev_id = vdev_id;
927 	cmd->vdev_assoc_id = aid;
928 
929 	ether_addr_copy(cmd->vdev_bssid.addr, bssid);
930 
931 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_UP_CMDID);
932 	if (ret) {
933 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_UP cmd\n");
934 		dev_kfree_skb(skb);
935 	}
936 
937 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
938 		   "WMI mgmt vdev up id 0x%x assoc id %d bssid %pM\n",
939 		   vdev_id, aid, bssid);
940 
941 	return ret;
942 }
943 
944 int ath11k_wmi_send_peer_create_cmd(struct ath11k *ar,
945 				    struct peer_create_params *param)
946 {
947 	struct ath11k_pdev_wmi *wmi = ar->wmi;
948 	struct wmi_peer_create_cmd *cmd;
949 	struct sk_buff *skb;
950 	int ret;
951 
952 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
953 	if (!skb)
954 		return -ENOMEM;
955 
956 	cmd = (struct wmi_peer_create_cmd *)skb->data;
957 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_CREATE_CMD) |
958 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
959 
960 	ether_addr_copy(cmd->peer_macaddr.addr, param->peer_addr);
961 	cmd->peer_type = param->peer_type;
962 	cmd->vdev_id = param->vdev_id;
963 
964 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_CREATE_CMDID);
965 	if (ret) {
966 		ath11k_warn(ar->ab, "failed to submit WMI_PEER_CREATE cmd\n");
967 		dev_kfree_skb(skb);
968 	}
969 
970 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
971 		   "WMI peer create vdev_id %d peer_addr %pM\n",
972 		   param->vdev_id, param->peer_addr);
973 
974 	return ret;
975 }
976 
977 int ath11k_wmi_send_peer_delete_cmd(struct ath11k *ar,
978 				    const u8 *peer_addr, u8 vdev_id)
979 {
980 	struct ath11k_pdev_wmi *wmi = ar->wmi;
981 	struct wmi_peer_delete_cmd *cmd;
982 	struct sk_buff *skb;
983 	int ret;
984 
985 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
986 	if (!skb)
987 		return -ENOMEM;
988 
989 	cmd = (struct wmi_peer_delete_cmd *)skb->data;
990 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_DELETE_CMD) |
991 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
992 
993 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
994 	cmd->vdev_id = vdev_id;
995 
996 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
997 		   "WMI peer delete vdev_id %d peer_addr %pM\n",
998 		   vdev_id,  peer_addr);
999 
1000 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_DELETE_CMDID);
1001 	if (ret) {
1002 		ath11k_warn(ar->ab, "failed to send WMI_PEER_DELETE cmd\n");
1003 		dev_kfree_skb(skb);
1004 	}
1005 
1006 	return ret;
1007 }
1008 
1009 int ath11k_wmi_send_pdev_set_regdomain(struct ath11k *ar,
1010 				       struct pdev_set_regdomain_params *param)
1011 {
1012 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1013 	struct wmi_pdev_set_regdomain_cmd *cmd;
1014 	struct sk_buff *skb;
1015 	int ret;
1016 
1017 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1018 	if (!skb)
1019 		return -ENOMEM;
1020 
1021 	cmd = (struct wmi_pdev_set_regdomain_cmd *)skb->data;
1022 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1023 				     WMI_TAG_PDEV_SET_REGDOMAIN_CMD) |
1024 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1025 
1026 	cmd->reg_domain = param->current_rd_in_use;
1027 	cmd->reg_domain_2g = param->current_rd_2g;
1028 	cmd->reg_domain_5g = param->current_rd_5g;
1029 	cmd->conformance_test_limit_2g = param->ctl_2g;
1030 	cmd->conformance_test_limit_5g = param->ctl_5g;
1031 	cmd->dfs_domain = param->dfs_domain;
1032 	cmd->pdev_id = param->pdev_id;
1033 
1034 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1035 		   "WMI pdev regd rd %d rd2g %d rd5g %d domain %d pdev id %d\n",
1036 		   param->current_rd_in_use, param->current_rd_2g,
1037 		   param->current_rd_5g, param->dfs_domain, param->pdev_id);
1038 
1039 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_SET_REGDOMAIN_CMDID);
1040 	if (ret) {
1041 		ath11k_warn(ar->ab,
1042 			    "failed to send WMI_PDEV_SET_REGDOMAIN cmd\n");
1043 		dev_kfree_skb(skb);
1044 	}
1045 
1046 	return ret;
1047 }
1048 
1049 int ath11k_wmi_set_peer_param(struct ath11k *ar, const u8 *peer_addr,
1050 			      u32 vdev_id, u32 param_id, u32 param_val)
1051 {
1052 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1053 	struct wmi_peer_set_param_cmd *cmd;
1054 	struct sk_buff *skb;
1055 	int ret;
1056 
1057 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1058 	if (!skb)
1059 		return -ENOMEM;
1060 
1061 	cmd = (struct wmi_peer_set_param_cmd *)skb->data;
1062 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_SET_PARAM_CMD) |
1063 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1064 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1065 	cmd->vdev_id = vdev_id;
1066 	cmd->param_id = param_id;
1067 	cmd->param_value = param_val;
1068 
1069 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_SET_PARAM_CMDID);
1070 	if (ret) {
1071 		ath11k_warn(ar->ab, "failed to send WMI_PEER_SET_PARAM cmd\n");
1072 		dev_kfree_skb(skb);
1073 	}
1074 
1075 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1076 		   "WMI vdev %d peer 0x%pM set param %d value %d\n",
1077 		   vdev_id, peer_addr, param_id, param_val);
1078 
1079 	return ret;
1080 }
1081 
1082 int ath11k_wmi_send_peer_flush_tids_cmd(struct ath11k *ar,
1083 					u8 peer_addr[ETH_ALEN],
1084 					struct peer_flush_params *param)
1085 {
1086 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1087 	struct wmi_peer_flush_tids_cmd *cmd;
1088 	struct sk_buff *skb;
1089 	int ret;
1090 
1091 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1092 	if (!skb)
1093 		return -ENOMEM;
1094 
1095 	cmd = (struct wmi_peer_flush_tids_cmd *)skb->data;
1096 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_FLUSH_TIDS_CMD) |
1097 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1098 
1099 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1100 	cmd->peer_tid_bitmap = param->peer_tid_bitmap;
1101 	cmd->vdev_id = param->vdev_id;
1102 
1103 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_FLUSH_TIDS_CMDID);
1104 	if (ret) {
1105 		ath11k_warn(ar->ab,
1106 			    "failed to send WMI_PEER_FLUSH_TIDS cmd\n");
1107 		dev_kfree_skb(skb);
1108 	}
1109 
1110 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1111 		   "WMI peer flush vdev_id %d peer_addr %pM tids %08x\n",
1112 		   param->vdev_id, peer_addr, param->peer_tid_bitmap);
1113 
1114 	return ret;
1115 }
1116 
1117 int ath11k_wmi_peer_rx_reorder_queue_setup(struct ath11k *ar,
1118 					   int vdev_id, const u8 *addr,
1119 					   dma_addr_t paddr, u8 tid,
1120 					   u8 ba_window_size_valid,
1121 					   u32 ba_window_size)
1122 {
1123 	struct wmi_peer_reorder_queue_setup_cmd *cmd;
1124 	struct sk_buff *skb;
1125 	int ret;
1126 
1127 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
1128 	if (!skb)
1129 		return -ENOMEM;
1130 
1131 	cmd = (struct wmi_peer_reorder_queue_setup_cmd *)skb->data;
1132 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1133 				     WMI_TAG_REORDER_QUEUE_SETUP_CMD) |
1134 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1135 
1136 	ether_addr_copy(cmd->peer_macaddr.addr, addr);
1137 	cmd->vdev_id = vdev_id;
1138 	cmd->tid = tid;
1139 	cmd->queue_ptr_lo = lower_32_bits(paddr);
1140 	cmd->queue_ptr_hi = upper_32_bits(paddr);
1141 	cmd->queue_no = tid;
1142 	cmd->ba_window_size_valid = ba_window_size_valid;
1143 	cmd->ba_window_size = ba_window_size;
1144 
1145 	ret = ath11k_wmi_cmd_send(ar->wmi, skb,
1146 				  WMI_PEER_REORDER_QUEUE_SETUP_CMDID);
1147 	if (ret) {
1148 		ath11k_warn(ar->ab,
1149 			    "failed to send WMI_PEER_REORDER_QUEUE_SETUP\n");
1150 		dev_kfree_skb(skb);
1151 	}
1152 
1153 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1154 		   "wmi rx reorder queue setup addr %pM vdev_id %d tid %d\n",
1155 		   addr, vdev_id, tid);
1156 
1157 	return ret;
1158 }
1159 
1160 int
1161 ath11k_wmi_rx_reord_queue_remove(struct ath11k *ar,
1162 				 struct rx_reorder_queue_remove_params *param)
1163 {
1164 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1165 	struct wmi_peer_reorder_queue_remove_cmd *cmd;
1166 	struct sk_buff *skb;
1167 	int ret;
1168 
1169 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1170 	if (!skb)
1171 		return -ENOMEM;
1172 
1173 	cmd = (struct wmi_peer_reorder_queue_remove_cmd *)skb->data;
1174 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1175 				     WMI_TAG_REORDER_QUEUE_REMOVE_CMD) |
1176 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1177 
1178 	ether_addr_copy(cmd->peer_macaddr.addr, param->peer_macaddr);
1179 	cmd->vdev_id = param->vdev_id;
1180 	cmd->tid_mask = param->peer_tid_bitmap;
1181 
1182 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1183 		   "%s: peer_macaddr %pM vdev_id %d, tid_map %d", __func__,
1184 		   param->peer_macaddr, param->vdev_id, param->peer_tid_bitmap);
1185 
1186 	ret = ath11k_wmi_cmd_send(wmi, skb,
1187 				  WMI_PEER_REORDER_QUEUE_REMOVE_CMDID);
1188 	if (ret) {
1189 		ath11k_warn(ar->ab,
1190 			    "failed to send WMI_PEER_REORDER_QUEUE_REMOVE_CMDID");
1191 		dev_kfree_skb(skb);
1192 	}
1193 
1194 	return ret;
1195 }
1196 
1197 int ath11k_wmi_pdev_set_param(struct ath11k *ar, u32 param_id,
1198 			      u32 param_value, u8 pdev_id)
1199 {
1200 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1201 	struct wmi_pdev_set_param_cmd *cmd;
1202 	struct sk_buff *skb;
1203 	int ret;
1204 
1205 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1206 	if (!skb)
1207 		return -ENOMEM;
1208 
1209 	cmd = (struct wmi_pdev_set_param_cmd *)skb->data;
1210 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_SET_PARAM_CMD) |
1211 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1212 	cmd->pdev_id = pdev_id;
1213 	cmd->param_id = param_id;
1214 	cmd->param_value = param_value;
1215 
1216 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_SET_PARAM_CMDID);
1217 	if (ret) {
1218 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_SET_PARAM cmd\n");
1219 		dev_kfree_skb(skb);
1220 	}
1221 
1222 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1223 		   "WMI pdev set param %d pdev id %d value %d\n",
1224 		   param_id, pdev_id, param_value);
1225 
1226 	return ret;
1227 }
1228 
1229 int ath11k_wmi_pdev_set_ps_mode(struct ath11k *ar, int vdev_id, u32 enable)
1230 {
1231 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1232 	struct wmi_pdev_set_ps_mode_cmd *cmd;
1233 	struct sk_buff *skb;
1234 	int ret;
1235 
1236 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1237 	if (!skb)
1238 		return -ENOMEM;
1239 
1240 	cmd = (struct wmi_pdev_set_ps_mode_cmd *)skb->data;
1241 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_STA_POWERSAVE_MODE_CMD) |
1242 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1243 	cmd->vdev_id = vdev_id;
1244 	cmd->sta_ps_mode = enable;
1245 
1246 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_STA_POWERSAVE_MODE_CMDID);
1247 	if (ret) {
1248 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_SET_PARAM cmd\n");
1249 		dev_kfree_skb(skb);
1250 	}
1251 
1252 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1253 		   "WMI vdev set psmode %d vdev id %d\n",
1254 		   enable, vdev_id);
1255 
1256 	return ret;
1257 }
1258 
1259 int ath11k_wmi_pdev_suspend(struct ath11k *ar, u32 suspend_opt,
1260 			    u32 pdev_id)
1261 {
1262 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1263 	struct wmi_pdev_suspend_cmd *cmd;
1264 	struct sk_buff *skb;
1265 	int ret;
1266 
1267 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1268 	if (!skb)
1269 		return -ENOMEM;
1270 
1271 	cmd = (struct wmi_pdev_suspend_cmd *)skb->data;
1272 
1273 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_SUSPEND_CMD) |
1274 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1275 
1276 	cmd->suspend_opt = suspend_opt;
1277 	cmd->pdev_id = pdev_id;
1278 
1279 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_SUSPEND_CMDID);
1280 	if (ret) {
1281 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_SUSPEND cmd\n");
1282 		dev_kfree_skb(skb);
1283 	}
1284 
1285 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1286 		   "WMI pdev suspend pdev_id %d\n", pdev_id);
1287 
1288 	return ret;
1289 }
1290 
1291 int ath11k_wmi_pdev_resume(struct ath11k *ar, u32 pdev_id)
1292 {
1293 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1294 	struct wmi_pdev_resume_cmd *cmd;
1295 	struct sk_buff *skb;
1296 	int ret;
1297 
1298 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1299 	if (!skb)
1300 		return -ENOMEM;
1301 
1302 	cmd = (struct wmi_pdev_resume_cmd *)skb->data;
1303 
1304 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_RESUME_CMD) |
1305 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1306 	cmd->pdev_id = pdev_id;
1307 
1308 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1309 		   "WMI pdev resume pdev id %d\n", pdev_id);
1310 
1311 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_RESUME_CMDID);
1312 	if (ret) {
1313 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_RESUME cmd\n");
1314 		dev_kfree_skb(skb);
1315 	}
1316 
1317 	return ret;
1318 }
1319 
1320 /* TODO FW Support for the cmd is not available yet.
1321  * Can be tested once the command and corresponding
1322  * event is implemented in FW
1323  */
1324 int ath11k_wmi_pdev_bss_chan_info_request(struct ath11k *ar,
1325 					  enum wmi_bss_chan_info_req_type type)
1326 {
1327 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1328 	struct wmi_pdev_bss_chan_info_req_cmd *cmd;
1329 	struct sk_buff *skb;
1330 	int ret;
1331 
1332 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1333 	if (!skb)
1334 		return -ENOMEM;
1335 
1336 	cmd = (struct wmi_pdev_bss_chan_info_req_cmd *)skb->data;
1337 
1338 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1339 				     WMI_TAG_PDEV_BSS_CHAN_INFO_REQUEST) |
1340 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1341 	cmd->req_type = type;
1342 
1343 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1344 		   "WMI bss chan info req type %d\n", type);
1345 
1346 	ret = ath11k_wmi_cmd_send(wmi, skb,
1347 				  WMI_PDEV_BSS_CHAN_INFO_REQUEST_CMDID);
1348 	if (ret) {
1349 		ath11k_warn(ar->ab,
1350 			    "failed to send WMI_PDEV_BSS_CHAN_INFO_REQUEST cmd\n");
1351 		dev_kfree_skb(skb);
1352 	}
1353 
1354 	return ret;
1355 }
1356 
1357 int ath11k_wmi_send_set_ap_ps_param_cmd(struct ath11k *ar, u8 *peer_addr,
1358 					struct ap_ps_params *param)
1359 {
1360 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1361 	struct wmi_ap_ps_peer_cmd *cmd;
1362 	struct sk_buff *skb;
1363 	int ret;
1364 
1365 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1366 	if (!skb)
1367 		return -ENOMEM;
1368 
1369 	cmd = (struct wmi_ap_ps_peer_cmd *)skb->data;
1370 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_AP_PS_PEER_CMD) |
1371 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1372 
1373 	cmd->vdev_id = param->vdev_id;
1374 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1375 	cmd->param = param->param;
1376 	cmd->value = param->value;
1377 
1378 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_AP_PS_PEER_PARAM_CMDID);
1379 	if (ret) {
1380 		ath11k_warn(ar->ab,
1381 			    "failed to send WMI_AP_PS_PEER_PARAM_CMDID\n");
1382 		dev_kfree_skb(skb);
1383 	}
1384 
1385 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1386 		   "WMI set ap ps vdev id %d peer %pM param %d value %d\n",
1387 		   param->vdev_id, peer_addr, param->param, param->value);
1388 
1389 	return ret;
1390 }
1391 
1392 int ath11k_wmi_set_sta_ps_param(struct ath11k *ar, u32 vdev_id,
1393 				u32 param, u32 param_value)
1394 {
1395 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1396 	struct wmi_sta_powersave_param_cmd *cmd;
1397 	struct sk_buff *skb;
1398 	int ret;
1399 
1400 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1401 	if (!skb)
1402 		return -ENOMEM;
1403 
1404 	cmd = (struct wmi_sta_powersave_param_cmd *)skb->data;
1405 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1406 				     WMI_TAG_STA_POWERSAVE_PARAM_CMD) |
1407 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1408 
1409 	cmd->vdev_id = vdev_id;
1410 	cmd->param = param;
1411 	cmd->value = param_value;
1412 
1413 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1414 		   "WMI set sta ps vdev_id %d param %d value %d\n",
1415 		   vdev_id, param, param_value);
1416 
1417 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_STA_POWERSAVE_PARAM_CMDID);
1418 	if (ret) {
1419 		ath11k_warn(ar->ab, "failed to send WMI_STA_POWERSAVE_PARAM_CMDID");
1420 		dev_kfree_skb(skb);
1421 	}
1422 
1423 	return ret;
1424 }
1425 
1426 int ath11k_wmi_force_fw_hang_cmd(struct ath11k *ar, u32 type, u32 delay_time_ms)
1427 {
1428 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1429 	struct wmi_force_fw_hang_cmd *cmd;
1430 	struct sk_buff *skb;
1431 	int ret, len;
1432 
1433 	len = sizeof(*cmd);
1434 
1435 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
1436 	if (!skb)
1437 		return -ENOMEM;
1438 
1439 	cmd = (struct wmi_force_fw_hang_cmd *)skb->data;
1440 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_FORCE_FW_HANG_CMD) |
1441 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
1442 
1443 	cmd->type = type;
1444 	cmd->delay_time_ms = delay_time_ms;
1445 
1446 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_FORCE_FW_HANG_CMDID);
1447 
1448 	if (ret) {
1449 		ath11k_warn(ar->ab, "Failed to send WMI_FORCE_FW_HANG_CMDID");
1450 		dev_kfree_skb(skb);
1451 	}
1452 	return ret;
1453 }
1454 
1455 int ath11k_wmi_vdev_set_param_cmd(struct ath11k *ar, u32 vdev_id,
1456 				  u32 param_id, u32 param_value)
1457 {
1458 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1459 	struct wmi_vdev_set_param_cmd *cmd;
1460 	struct sk_buff *skb;
1461 	int ret;
1462 
1463 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1464 	if (!skb)
1465 		return -ENOMEM;
1466 
1467 	cmd = (struct wmi_vdev_set_param_cmd *)skb->data;
1468 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_SET_PARAM_CMD) |
1469 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1470 
1471 	cmd->vdev_id = vdev_id;
1472 	cmd->param_id = param_id;
1473 	cmd->param_value = param_value;
1474 
1475 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_SET_PARAM_CMDID);
1476 	if (ret) {
1477 		ath11k_warn(ar->ab,
1478 			    "failed to send WMI_VDEV_SET_PARAM_CMDID\n");
1479 		dev_kfree_skb(skb);
1480 	}
1481 
1482 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1483 		   "WMI vdev id 0x%x set param %d value %d\n",
1484 		   vdev_id, param_id, param_value);
1485 
1486 	return ret;
1487 }
1488 
1489 int ath11k_wmi_send_stats_request_cmd(struct ath11k *ar,
1490 				      struct stats_request_params *param)
1491 {
1492 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1493 	struct wmi_request_stats_cmd *cmd;
1494 	struct sk_buff *skb;
1495 	int ret;
1496 
1497 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1498 	if (!skb)
1499 		return -ENOMEM;
1500 
1501 	cmd = (struct wmi_request_stats_cmd *)skb->data;
1502 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_REQUEST_STATS_CMD) |
1503 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1504 
1505 	cmd->stats_id = param->stats_id;
1506 	cmd->vdev_id = param->vdev_id;
1507 	cmd->pdev_id = param->pdev_id;
1508 
1509 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_REQUEST_STATS_CMDID);
1510 	if (ret) {
1511 		ath11k_warn(ar->ab, "failed to send WMI_REQUEST_STATS cmd\n");
1512 		dev_kfree_skb(skb);
1513 	}
1514 
1515 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1516 		   "WMI request stats 0x%x vdev id %d pdev id %d\n",
1517 		   param->stats_id, param->vdev_id, param->pdev_id);
1518 
1519 	return ret;
1520 }
1521 
1522 int ath11k_wmi_send_pdev_temperature_cmd(struct ath11k *ar)
1523 {
1524 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1525 	struct wmi_get_pdev_temperature_cmd *cmd;
1526 	struct sk_buff *skb;
1527 	int ret;
1528 
1529 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1530 	if (!skb)
1531 		return -ENOMEM;
1532 
1533 	cmd = (struct wmi_get_pdev_temperature_cmd *)skb->data;
1534 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_GET_TEMPERATURE_CMD) |
1535 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1536 	cmd->pdev_id = ar->pdev->pdev_id;
1537 
1538 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_GET_TEMPERATURE_CMDID);
1539 	if (ret) {
1540 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_GET_TEMPERATURE cmd\n");
1541 		dev_kfree_skb(skb);
1542 	}
1543 
1544 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1545 		   "WMI pdev get temperature for pdev_id %d\n", ar->pdev->pdev_id);
1546 
1547 	return ret;
1548 }
1549 
1550 int ath11k_wmi_send_bcn_offload_control_cmd(struct ath11k *ar,
1551 					    u32 vdev_id, u32 bcn_ctrl_op)
1552 {
1553 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1554 	struct wmi_bcn_offload_ctrl_cmd *cmd;
1555 	struct sk_buff *skb;
1556 	int ret;
1557 
1558 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
1559 	if (!skb)
1560 		return -ENOMEM;
1561 
1562 	cmd = (struct wmi_bcn_offload_ctrl_cmd *)skb->data;
1563 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1564 				     WMI_TAG_BCN_OFFLOAD_CTRL_CMD) |
1565 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1566 
1567 	cmd->vdev_id = vdev_id;
1568 	cmd->bcn_ctrl_op = bcn_ctrl_op;
1569 
1570 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1571 		   "WMI bcn ctrl offload vdev id %d ctrl_op %d\n",
1572 		   vdev_id, bcn_ctrl_op);
1573 
1574 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_BCN_OFFLOAD_CTRL_CMDID);
1575 	if (ret) {
1576 		ath11k_warn(ar->ab,
1577 			    "failed to send WMI_BCN_OFFLOAD_CTRL_CMDID\n");
1578 		dev_kfree_skb(skb);
1579 	}
1580 
1581 	return ret;
1582 }
1583 
1584 int ath11k_wmi_bcn_tmpl(struct ath11k *ar, u32 vdev_id,
1585 			struct ieee80211_mutable_offsets *offs,
1586 			struct sk_buff *bcn)
1587 {
1588 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1589 	struct wmi_bcn_tmpl_cmd *cmd;
1590 	struct wmi_bcn_prb_info *bcn_prb_info;
1591 	struct wmi_tlv *tlv;
1592 	struct sk_buff *skb;
1593 	void *ptr;
1594 	int ret, len;
1595 	size_t aligned_len = roundup(bcn->len, 4);
1596 
1597 	len = sizeof(*cmd) + sizeof(*bcn_prb_info) + TLV_HDR_SIZE + aligned_len;
1598 
1599 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
1600 	if (!skb)
1601 		return -ENOMEM;
1602 
1603 	cmd = (struct wmi_bcn_tmpl_cmd *)skb->data;
1604 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_BCN_TMPL_CMD) |
1605 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1606 	cmd->vdev_id = vdev_id;
1607 	cmd->tim_ie_offset = offs->tim_offset;
1608 	cmd->csa_switch_count_offset = offs->cntdwn_counter_offs[0];
1609 	cmd->ext_csa_switch_count_offset = offs->cntdwn_counter_offs[1];
1610 	cmd->buf_len = bcn->len;
1611 
1612 	ptr = skb->data + sizeof(*cmd);
1613 
1614 	bcn_prb_info = ptr;
1615 	len = sizeof(*bcn_prb_info);
1616 	bcn_prb_info->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1617 					      WMI_TAG_BCN_PRB_INFO) |
1618 				   FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
1619 	bcn_prb_info->caps = 0;
1620 	bcn_prb_info->erp = 0;
1621 
1622 	ptr += sizeof(*bcn_prb_info);
1623 
1624 	tlv = ptr;
1625 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1626 		      FIELD_PREP(WMI_TLV_LEN, aligned_len);
1627 	memcpy(tlv->value, bcn->data, bcn->len);
1628 
1629 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_BCN_TMPL_CMDID);
1630 	if (ret) {
1631 		ath11k_warn(ar->ab, "failed to send WMI_BCN_TMPL_CMDID\n");
1632 		dev_kfree_skb(skb);
1633 	}
1634 
1635 	return ret;
1636 }
1637 
1638 int ath11k_wmi_vdev_install_key(struct ath11k *ar,
1639 				struct wmi_vdev_install_key_arg *arg)
1640 {
1641 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1642 	struct wmi_vdev_install_key_cmd *cmd;
1643 	struct wmi_tlv *tlv;
1644 	struct sk_buff *skb;
1645 	int ret, len;
1646 	int key_len_aligned = roundup(arg->key_len, sizeof(uint32_t));
1647 
1648 	len = sizeof(*cmd) + TLV_HDR_SIZE + key_len_aligned;
1649 
1650 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
1651 	if (!skb)
1652 		return -ENOMEM;
1653 
1654 	cmd = (struct wmi_vdev_install_key_cmd *)skb->data;
1655 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_INSTALL_KEY_CMD) |
1656 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1657 	cmd->vdev_id = arg->vdev_id;
1658 	ether_addr_copy(cmd->peer_macaddr.addr, arg->macaddr);
1659 	cmd->key_idx = arg->key_idx;
1660 	cmd->key_flags = arg->key_flags;
1661 	cmd->key_cipher = arg->key_cipher;
1662 	cmd->key_len = arg->key_len;
1663 	cmd->key_txmic_len = arg->key_txmic_len;
1664 	cmd->key_rxmic_len = arg->key_rxmic_len;
1665 
1666 	if (arg->key_rsc_counter)
1667 		memcpy(&cmd->key_rsc_counter, &arg->key_rsc_counter,
1668 		       sizeof(struct wmi_key_seq_counter));
1669 
1670 	tlv = (struct wmi_tlv *)(skb->data + sizeof(*cmd));
1671 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1672 		      FIELD_PREP(WMI_TLV_LEN, key_len_aligned);
1673 	memcpy(tlv->value, (u8 *)arg->key_data, key_len_aligned);
1674 
1675 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_INSTALL_KEY_CMDID);
1676 	if (ret) {
1677 		ath11k_warn(ar->ab,
1678 			    "failed to send WMI_VDEV_INSTALL_KEY cmd\n");
1679 		dev_kfree_skb(skb);
1680 	}
1681 
1682 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1683 		   "WMI vdev install key idx %d cipher %d len %d\n",
1684 		   arg->key_idx, arg->key_cipher, arg->key_len);
1685 
1686 	return ret;
1687 }
1688 
1689 static inline void
1690 ath11k_wmi_copy_peer_flags(struct wmi_peer_assoc_complete_cmd *cmd,
1691 			   struct peer_assoc_params *param)
1692 {
1693 	cmd->peer_flags = 0;
1694 
1695 	if (param->is_wme_set) {
1696 		if (param->qos_flag)
1697 			cmd->peer_flags |= WMI_PEER_QOS;
1698 		if (param->apsd_flag)
1699 			cmd->peer_flags |= WMI_PEER_APSD;
1700 		if (param->ht_flag)
1701 			cmd->peer_flags |= WMI_PEER_HT;
1702 		if (param->bw_40)
1703 			cmd->peer_flags |= WMI_PEER_40MHZ;
1704 		if (param->bw_80)
1705 			cmd->peer_flags |= WMI_PEER_80MHZ;
1706 		if (param->bw_160)
1707 			cmd->peer_flags |= WMI_PEER_160MHZ;
1708 
1709 		/* Typically if STBC is enabled for VHT it should be enabled
1710 		 * for HT as well
1711 		 **/
1712 		if (param->stbc_flag)
1713 			cmd->peer_flags |= WMI_PEER_STBC;
1714 
1715 		/* Typically if LDPC is enabled for VHT it should be enabled
1716 		 * for HT as well
1717 		 **/
1718 		if (param->ldpc_flag)
1719 			cmd->peer_flags |= WMI_PEER_LDPC;
1720 
1721 		if (param->static_mimops_flag)
1722 			cmd->peer_flags |= WMI_PEER_STATIC_MIMOPS;
1723 		if (param->dynamic_mimops_flag)
1724 			cmd->peer_flags |= WMI_PEER_DYN_MIMOPS;
1725 		if (param->spatial_mux_flag)
1726 			cmd->peer_flags |= WMI_PEER_SPATIAL_MUX;
1727 		if (param->vht_flag)
1728 			cmd->peer_flags |= WMI_PEER_VHT;
1729 		if (param->he_flag)
1730 			cmd->peer_flags |= WMI_PEER_HE;
1731 		if (param->twt_requester)
1732 			cmd->peer_flags |= WMI_PEER_TWT_REQ;
1733 		if (param->twt_responder)
1734 			cmd->peer_flags |= WMI_PEER_TWT_RESP;
1735 	}
1736 
1737 	/* Suppress authorization for all AUTH modes that need 4-way handshake
1738 	 * (during re-association).
1739 	 * Authorization will be done for these modes on key installation.
1740 	 */
1741 	if (param->auth_flag)
1742 		cmd->peer_flags |= WMI_PEER_AUTH;
1743 	if (param->need_ptk_4_way) {
1744 		cmd->peer_flags |= WMI_PEER_NEED_PTK_4_WAY;
1745 		cmd->peer_flags &= ~WMI_PEER_AUTH;
1746 	}
1747 	if (param->need_gtk_2_way)
1748 		cmd->peer_flags |= WMI_PEER_NEED_GTK_2_WAY;
1749 	/* safe mode bypass the 4-way handshake */
1750 	if (param->safe_mode_enabled)
1751 		cmd->peer_flags &= ~(WMI_PEER_NEED_PTK_4_WAY |
1752 				     WMI_PEER_NEED_GTK_2_WAY);
1753 
1754 	if (param->is_pmf_enabled)
1755 		cmd->peer_flags |= WMI_PEER_PMF;
1756 
1757 	/* Disable AMSDU for station transmit, if user configures it */
1758 	/* Disable AMSDU for AP transmit to 11n Stations, if user configures
1759 	 * it
1760 	 * if (param->amsdu_disable) Add after FW support
1761 	 **/
1762 
1763 	/* Target asserts if node is marked HT and all MCS is set to 0.
1764 	 * Mark the node as non-HT if all the mcs rates are disabled through
1765 	 * iwpriv
1766 	 **/
1767 	if (param->peer_ht_rates.num_rates == 0)
1768 		cmd->peer_flags &= ~WMI_PEER_HT;
1769 }
1770 
1771 int ath11k_wmi_send_peer_assoc_cmd(struct ath11k *ar,
1772 				   struct peer_assoc_params *param)
1773 {
1774 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1775 	struct wmi_peer_assoc_complete_cmd *cmd;
1776 	struct wmi_vht_rate_set *mcs;
1777 	struct wmi_he_rate_set *he_mcs;
1778 	struct sk_buff *skb;
1779 	struct wmi_tlv *tlv;
1780 	void *ptr;
1781 	u32 peer_legacy_rates_align;
1782 	u32 peer_ht_rates_align;
1783 	int i, ret, len;
1784 
1785 	peer_legacy_rates_align = roundup(param->peer_legacy_rates.num_rates,
1786 					  sizeof(u32));
1787 	peer_ht_rates_align = roundup(param->peer_ht_rates.num_rates,
1788 				      sizeof(u32));
1789 
1790 	len = sizeof(*cmd) +
1791 	      TLV_HDR_SIZE + (peer_legacy_rates_align * sizeof(u8)) +
1792 	      TLV_HDR_SIZE + (peer_ht_rates_align * sizeof(u8)) +
1793 	      sizeof(*mcs) + TLV_HDR_SIZE +
1794 	      (sizeof(*he_mcs) * param->peer_he_mcs_count);
1795 
1796 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
1797 	if (!skb)
1798 		return -ENOMEM;
1799 
1800 	ptr = skb->data;
1801 
1802 	cmd = ptr;
1803 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1804 				     WMI_TAG_PEER_ASSOC_COMPLETE_CMD) |
1805 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1806 
1807 	cmd->vdev_id = param->vdev_id;
1808 
1809 	cmd->peer_new_assoc = param->peer_new_assoc;
1810 	cmd->peer_associd = param->peer_associd;
1811 
1812 	ath11k_wmi_copy_peer_flags(cmd, param);
1813 
1814 	ether_addr_copy(cmd->peer_macaddr.addr, param->peer_mac);
1815 
1816 	cmd->peer_rate_caps = param->peer_rate_caps;
1817 	cmd->peer_caps = param->peer_caps;
1818 	cmd->peer_listen_intval = param->peer_listen_intval;
1819 	cmd->peer_ht_caps = param->peer_ht_caps;
1820 	cmd->peer_max_mpdu = param->peer_max_mpdu;
1821 	cmd->peer_mpdu_density = param->peer_mpdu_density;
1822 	cmd->peer_vht_caps = param->peer_vht_caps;
1823 	cmd->peer_phymode = param->peer_phymode;
1824 
1825 	/* Update 11ax capabilities */
1826 	cmd->peer_he_cap_info = param->peer_he_cap_macinfo[0];
1827 	cmd->peer_he_cap_info_ext = param->peer_he_cap_macinfo[1];
1828 	cmd->peer_he_cap_info_internal = param->peer_he_cap_macinfo_internal;
1829 	cmd->peer_he_caps_6ghz = param->peer_he_caps_6ghz;
1830 	cmd->peer_he_ops = param->peer_he_ops;
1831 	memcpy(&cmd->peer_he_cap_phy, &param->peer_he_cap_phyinfo,
1832 	       sizeof(param->peer_he_cap_phyinfo));
1833 	memcpy(&cmd->peer_ppet, &param->peer_ppet,
1834 	       sizeof(param->peer_ppet));
1835 
1836 	/* Update peer legacy rate information */
1837 	ptr += sizeof(*cmd);
1838 
1839 	tlv = ptr;
1840 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1841 		      FIELD_PREP(WMI_TLV_LEN, peer_legacy_rates_align);
1842 
1843 	ptr += TLV_HDR_SIZE;
1844 
1845 	cmd->num_peer_legacy_rates = param->peer_legacy_rates.num_rates;
1846 	memcpy(ptr, param->peer_legacy_rates.rates,
1847 	       param->peer_legacy_rates.num_rates);
1848 
1849 	/* Update peer HT rate information */
1850 	ptr += peer_legacy_rates_align;
1851 
1852 	tlv = ptr;
1853 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1854 		      FIELD_PREP(WMI_TLV_LEN, peer_ht_rates_align);
1855 	ptr += TLV_HDR_SIZE;
1856 	cmd->num_peer_ht_rates = param->peer_ht_rates.num_rates;
1857 	memcpy(ptr, param->peer_ht_rates.rates,
1858 	       param->peer_ht_rates.num_rates);
1859 
1860 	/* VHT Rates */
1861 	ptr += peer_ht_rates_align;
1862 
1863 	mcs = ptr;
1864 
1865 	mcs->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VHT_RATE_SET) |
1866 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*mcs) - TLV_HDR_SIZE);
1867 
1868 	cmd->peer_nss = param->peer_nss;
1869 
1870 	/* Update bandwidth-NSS mapping */
1871 	cmd->peer_bw_rxnss_override = 0;
1872 	cmd->peer_bw_rxnss_override |= param->peer_bw_rxnss_override;
1873 
1874 	if (param->vht_capable) {
1875 		mcs->rx_max_rate = param->rx_max_rate;
1876 		mcs->rx_mcs_set = param->rx_mcs_set;
1877 		mcs->tx_max_rate = param->tx_max_rate;
1878 		mcs->tx_mcs_set = param->tx_mcs_set;
1879 	}
1880 
1881 	/* HE Rates */
1882 	cmd->peer_he_mcs = param->peer_he_mcs_count;
1883 	cmd->min_data_rate = param->min_data_rate;
1884 
1885 	ptr += sizeof(*mcs);
1886 
1887 	len = param->peer_he_mcs_count * sizeof(*he_mcs);
1888 
1889 	tlv = ptr;
1890 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
1891 		      FIELD_PREP(WMI_TLV_LEN, len);
1892 	ptr += TLV_HDR_SIZE;
1893 
1894 	/* Loop through the HE rate set */
1895 	for (i = 0; i < param->peer_he_mcs_count; i++) {
1896 		he_mcs = ptr;
1897 		he_mcs->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1898 						WMI_TAG_HE_RATE_SET) |
1899 				     FIELD_PREP(WMI_TLV_LEN,
1900 						sizeof(*he_mcs) - TLV_HDR_SIZE);
1901 
1902 		he_mcs->rx_mcs_set = param->peer_he_rx_mcs_set[i];
1903 		he_mcs->tx_mcs_set = param->peer_he_tx_mcs_set[i];
1904 		ptr += sizeof(*he_mcs);
1905 	}
1906 
1907 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_ASSOC_CMDID);
1908 	if (ret) {
1909 		ath11k_warn(ar->ab,
1910 			    "failed to send WMI_PEER_ASSOC_CMDID\n");
1911 		dev_kfree_skb(skb);
1912 	}
1913 
1914 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1915 		   "wmi peer assoc vdev id %d assoc id %d peer mac %pM peer_flags %x rate_caps %x peer_caps %x listen_intval %d ht_caps %x max_mpdu %d nss %d phymode %d peer_mpdu_density %d vht_caps %x he cap_info %x he ops %x he cap_info_ext %x he phy %x %x %x peer_bw_rxnss_override %x\n",
1916 		   cmd->vdev_id, cmd->peer_associd, param->peer_mac,
1917 		   cmd->peer_flags, cmd->peer_rate_caps, cmd->peer_caps,
1918 		   cmd->peer_listen_intval, cmd->peer_ht_caps,
1919 		   cmd->peer_max_mpdu, cmd->peer_nss, cmd->peer_phymode,
1920 		   cmd->peer_mpdu_density,
1921 		   cmd->peer_vht_caps, cmd->peer_he_cap_info,
1922 		   cmd->peer_he_ops, cmd->peer_he_cap_info_ext,
1923 		   cmd->peer_he_cap_phy[0], cmd->peer_he_cap_phy[1],
1924 		   cmd->peer_he_cap_phy[2],
1925 		   cmd->peer_bw_rxnss_override);
1926 
1927 	return ret;
1928 }
1929 
1930 void ath11k_wmi_start_scan_init(struct ath11k *ar,
1931 				struct scan_req_params *arg)
1932 {
1933 	/* setup commonly used values */
1934 	arg->scan_req_id = 1;
1935 	arg->scan_priority = WMI_SCAN_PRIORITY_LOW;
1936 	arg->dwell_time_active = 50;
1937 	arg->dwell_time_active_2g = 0;
1938 	arg->dwell_time_passive = 150;
1939 	arg->dwell_time_active_6g = 40;
1940 	arg->dwell_time_passive_6g = 30;
1941 	arg->min_rest_time = 50;
1942 	arg->max_rest_time = 500;
1943 	arg->repeat_probe_time = 0;
1944 	arg->probe_spacing_time = 0;
1945 	arg->idle_time = 0;
1946 	arg->max_scan_time = 20000;
1947 	arg->probe_delay = 5;
1948 	arg->notify_scan_events = WMI_SCAN_EVENT_STARTED |
1949 				  WMI_SCAN_EVENT_COMPLETED |
1950 				  WMI_SCAN_EVENT_BSS_CHANNEL |
1951 				  WMI_SCAN_EVENT_FOREIGN_CHAN |
1952 				  WMI_SCAN_EVENT_DEQUEUED;
1953 	arg->scan_flags |= WMI_SCAN_CHAN_STAT_EVENT;
1954 	arg->num_bssid = 1;
1955 
1956 	/* fill bssid_list[0] with 0xff, otherwise bssid and RA will be
1957 	 * ZEROs in probe request
1958 	 */
1959 	eth_broadcast_addr(arg->bssid_list[0].addr);
1960 }
1961 
1962 static inline void
1963 ath11k_wmi_copy_scan_event_cntrl_flags(struct wmi_start_scan_cmd *cmd,
1964 				       struct scan_req_params *param)
1965 {
1966 	/* Scan events subscription */
1967 	if (param->scan_ev_started)
1968 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_STARTED;
1969 	if (param->scan_ev_completed)
1970 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_COMPLETED;
1971 	if (param->scan_ev_bss_chan)
1972 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_BSS_CHANNEL;
1973 	if (param->scan_ev_foreign_chan)
1974 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_FOREIGN_CHAN;
1975 	if (param->scan_ev_dequeued)
1976 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_DEQUEUED;
1977 	if (param->scan_ev_preempted)
1978 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_PREEMPTED;
1979 	if (param->scan_ev_start_failed)
1980 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_START_FAILED;
1981 	if (param->scan_ev_restarted)
1982 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_RESTARTED;
1983 	if (param->scan_ev_foreign_chn_exit)
1984 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_FOREIGN_CHAN_EXIT;
1985 	if (param->scan_ev_suspended)
1986 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_SUSPENDED;
1987 	if (param->scan_ev_resumed)
1988 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_RESUMED;
1989 
1990 	/** Set scan control flags */
1991 	cmd->scan_ctrl_flags = 0;
1992 	if (param->scan_f_passive)
1993 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_PASSIVE;
1994 	if (param->scan_f_strict_passive_pch)
1995 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_STRICT_PASSIVE_ON_PCHN;
1996 	if (param->scan_f_promisc_mode)
1997 		cmd->scan_ctrl_flags |=  WMI_SCAN_FILTER_PROMISCUOS;
1998 	if (param->scan_f_capture_phy_err)
1999 		cmd->scan_ctrl_flags |=  WMI_SCAN_CAPTURE_PHY_ERROR;
2000 	if (param->scan_f_half_rate)
2001 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_HALF_RATE_SUPPORT;
2002 	if (param->scan_f_quarter_rate)
2003 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_QUARTER_RATE_SUPPORT;
2004 	if (param->scan_f_cck_rates)
2005 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_CCK_RATES;
2006 	if (param->scan_f_ofdm_rates)
2007 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_OFDM_RATES;
2008 	if (param->scan_f_chan_stat_evnt)
2009 		cmd->scan_ctrl_flags |=  WMI_SCAN_CHAN_STAT_EVENT;
2010 	if (param->scan_f_filter_prb_req)
2011 		cmd->scan_ctrl_flags |=  WMI_SCAN_FILTER_PROBE_REQ;
2012 	if (param->scan_f_bcast_probe)
2013 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_BCAST_PROBE_REQ;
2014 	if (param->scan_f_offchan_mgmt_tx)
2015 		cmd->scan_ctrl_flags |=  WMI_SCAN_OFFCHAN_MGMT_TX;
2016 	if (param->scan_f_offchan_data_tx)
2017 		cmd->scan_ctrl_flags |=  WMI_SCAN_OFFCHAN_DATA_TX;
2018 	if (param->scan_f_force_active_dfs_chn)
2019 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_FORCE_ACTIVE_ON_DFS;
2020 	if (param->scan_f_add_tpc_ie_in_probe)
2021 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_TPC_IE_IN_PROBE_REQ;
2022 	if (param->scan_f_add_ds_ie_in_probe)
2023 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_DS_IE_IN_PROBE_REQ;
2024 	if (param->scan_f_add_spoofed_mac_in_probe)
2025 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_SPOOF_MAC_IN_PROBE_REQ;
2026 	if (param->scan_f_add_rand_seq_in_probe)
2027 		cmd->scan_ctrl_flags |=  WMI_SCAN_RANDOM_SEQ_NO_IN_PROBE_REQ;
2028 	if (param->scan_f_en_ie_whitelist_in_probe)
2029 		cmd->scan_ctrl_flags |=
2030 			 WMI_SCAN_ENABLE_IE_WHTELIST_IN_PROBE_REQ;
2031 
2032 	/* for adaptive scan mode using 3 bits (21 - 23 bits) */
2033 	WMI_SCAN_SET_DWELL_MODE(cmd->scan_ctrl_flags,
2034 				param->adaptive_dwell_time_mode);
2035 }
2036 
2037 int ath11k_wmi_send_scan_start_cmd(struct ath11k *ar,
2038 				   struct scan_req_params *params)
2039 {
2040 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2041 	struct wmi_start_scan_cmd *cmd;
2042 	struct wmi_ssid *ssid = NULL;
2043 	struct wmi_mac_addr *bssid;
2044 	struct sk_buff *skb;
2045 	struct wmi_tlv *tlv;
2046 	void *ptr;
2047 	int i, ret, len;
2048 	u32 *tmp_ptr;
2049 	u8 extraie_len_with_pad = 0;
2050 	struct hint_short_ssid *s_ssid = NULL;
2051 	struct hint_bssid *hint_bssid = NULL;
2052 
2053 	len = sizeof(*cmd);
2054 
2055 	len += TLV_HDR_SIZE;
2056 	if (params->num_chan)
2057 		len += params->num_chan * sizeof(u32);
2058 
2059 	len += TLV_HDR_SIZE;
2060 	if (params->num_ssids)
2061 		len += params->num_ssids * sizeof(*ssid);
2062 
2063 	len += TLV_HDR_SIZE;
2064 	if (params->num_bssid)
2065 		len += sizeof(*bssid) * params->num_bssid;
2066 
2067 	len += TLV_HDR_SIZE;
2068 	if (params->extraie.len)
2069 		extraie_len_with_pad =
2070 			roundup(params->extraie.len, sizeof(u32));
2071 	len += extraie_len_with_pad;
2072 
2073 	if (params->num_hint_bssid)
2074 		len += TLV_HDR_SIZE +
2075 		       params->num_hint_bssid * sizeof(struct hint_bssid);
2076 
2077 	if (params->num_hint_s_ssid)
2078 		len += TLV_HDR_SIZE +
2079 		       params->num_hint_s_ssid * sizeof(struct hint_short_ssid);
2080 
2081 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2082 	if (!skb)
2083 		return -ENOMEM;
2084 
2085 	ptr = skb->data;
2086 
2087 	cmd = ptr;
2088 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_START_SCAN_CMD) |
2089 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2090 
2091 	cmd->scan_id = params->scan_id;
2092 	cmd->scan_req_id = params->scan_req_id;
2093 	cmd->vdev_id = params->vdev_id;
2094 	cmd->scan_priority = params->scan_priority;
2095 	cmd->notify_scan_events = params->notify_scan_events;
2096 
2097 	ath11k_wmi_copy_scan_event_cntrl_flags(cmd, params);
2098 
2099 	cmd->dwell_time_active = params->dwell_time_active;
2100 	cmd->dwell_time_active_2g = params->dwell_time_active_2g;
2101 	cmd->dwell_time_passive = params->dwell_time_passive;
2102 	cmd->dwell_time_active_6g = params->dwell_time_active_6g;
2103 	cmd->dwell_time_passive_6g = params->dwell_time_passive_6g;
2104 	cmd->min_rest_time = params->min_rest_time;
2105 	cmd->max_rest_time = params->max_rest_time;
2106 	cmd->repeat_probe_time = params->repeat_probe_time;
2107 	cmd->probe_spacing_time = params->probe_spacing_time;
2108 	cmd->idle_time = params->idle_time;
2109 	cmd->max_scan_time = params->max_scan_time;
2110 	cmd->probe_delay = params->probe_delay;
2111 	cmd->burst_duration = params->burst_duration;
2112 	cmd->num_chan = params->num_chan;
2113 	cmd->num_bssid = params->num_bssid;
2114 	cmd->num_ssids = params->num_ssids;
2115 	cmd->ie_len = params->extraie.len;
2116 	cmd->n_probes = params->n_probes;
2117 
2118 	ptr += sizeof(*cmd);
2119 
2120 	len = params->num_chan * sizeof(u32);
2121 
2122 	tlv = ptr;
2123 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_UINT32) |
2124 		      FIELD_PREP(WMI_TLV_LEN, len);
2125 	ptr += TLV_HDR_SIZE;
2126 	tmp_ptr = (u32 *)ptr;
2127 
2128 	for (i = 0; i < params->num_chan; ++i)
2129 		tmp_ptr[i] = params->chan_list[i];
2130 
2131 	ptr += len;
2132 
2133 	len = params->num_ssids * sizeof(*ssid);
2134 	tlv = ptr;
2135 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2136 		      FIELD_PREP(WMI_TLV_LEN, len);
2137 
2138 	ptr += TLV_HDR_SIZE;
2139 
2140 	if (params->num_ssids) {
2141 		ssid = ptr;
2142 		for (i = 0; i < params->num_ssids; ++i) {
2143 			ssid->ssid_len = params->ssid[i].length;
2144 			memcpy(ssid->ssid, params->ssid[i].ssid,
2145 			       params->ssid[i].length);
2146 			ssid++;
2147 		}
2148 	}
2149 
2150 	ptr += (params->num_ssids * sizeof(*ssid));
2151 	len = params->num_bssid * sizeof(*bssid);
2152 	tlv = ptr;
2153 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2154 		      FIELD_PREP(WMI_TLV_LEN, len);
2155 
2156 	ptr += TLV_HDR_SIZE;
2157 	bssid = ptr;
2158 
2159 	if (params->num_bssid) {
2160 		for (i = 0; i < params->num_bssid; ++i) {
2161 			ether_addr_copy(bssid->addr,
2162 					params->bssid_list[i].addr);
2163 			bssid++;
2164 		}
2165 	}
2166 
2167 	ptr += params->num_bssid * sizeof(*bssid);
2168 
2169 	len = extraie_len_with_pad;
2170 	tlv = ptr;
2171 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
2172 		      FIELD_PREP(WMI_TLV_LEN, len);
2173 	ptr += TLV_HDR_SIZE;
2174 
2175 	if (params->extraie.len)
2176 		memcpy(ptr, params->extraie.ptr,
2177 		       params->extraie.len);
2178 
2179 	ptr += extraie_len_with_pad;
2180 
2181 	if (params->num_hint_s_ssid) {
2182 		len = params->num_hint_s_ssid * sizeof(struct hint_short_ssid);
2183 		tlv = ptr;
2184 		tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2185 			      FIELD_PREP(WMI_TLV_LEN, len);
2186 		ptr += TLV_HDR_SIZE;
2187 		s_ssid = ptr;
2188 		for (i = 0; i < params->num_hint_s_ssid; ++i) {
2189 			s_ssid->freq_flags = params->hint_s_ssid[i].freq_flags;
2190 			s_ssid->short_ssid = params->hint_s_ssid[i].short_ssid;
2191 			s_ssid++;
2192 		}
2193 		ptr += len;
2194 	}
2195 
2196 	if (params->num_hint_bssid) {
2197 		len = params->num_hint_bssid * sizeof(struct hint_bssid);
2198 		tlv = ptr;
2199 		tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2200 			      FIELD_PREP(WMI_TLV_LEN, len);
2201 		ptr += TLV_HDR_SIZE;
2202 		hint_bssid = ptr;
2203 		for (i = 0; i < params->num_hint_bssid; ++i) {
2204 			hint_bssid->freq_flags =
2205 				params->hint_bssid[i].freq_flags;
2206 			ether_addr_copy(&params->hint_bssid[i].bssid.addr[0],
2207 					&hint_bssid->bssid.addr[0]);
2208 			hint_bssid++;
2209 		}
2210 	}
2211 
2212 	len = params->num_hint_s_ssid * sizeof(struct hint_short_ssid);
2213 	tlv = ptr;
2214 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2215 		      FIELD_PREP(WMI_TLV_LEN, len);
2216 	ptr += TLV_HDR_SIZE;
2217 	if (params->num_hint_s_ssid) {
2218 		s_ssid = ptr;
2219 		for (i = 0; i < params->num_hint_s_ssid; ++i) {
2220 			s_ssid->freq_flags = params->hint_s_ssid[i].freq_flags;
2221 			s_ssid->short_ssid = params->hint_s_ssid[i].short_ssid;
2222 			s_ssid++;
2223 		}
2224 	}
2225 	ptr += len;
2226 
2227 	len = params->num_hint_bssid * sizeof(struct hint_bssid);
2228 	tlv = ptr;
2229 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2230 		      FIELD_PREP(WMI_TLV_LEN, len);
2231 	ptr += TLV_HDR_SIZE;
2232 	if (params->num_hint_bssid) {
2233 		hint_bssid = ptr;
2234 		for (i = 0; i < params->num_hint_bssid; ++i) {
2235 			hint_bssid->freq_flags =
2236 				params->hint_bssid[i].freq_flags;
2237 			ether_addr_copy(&params->hint_bssid[i].bssid.addr[0],
2238 					&hint_bssid->bssid.addr[0]);
2239 			hint_bssid++;
2240 		}
2241 	}
2242 
2243 	ret = ath11k_wmi_cmd_send(wmi, skb,
2244 				  WMI_START_SCAN_CMDID);
2245 	if (ret) {
2246 		ath11k_warn(ar->ab, "failed to send WMI_START_SCAN_CMDID\n");
2247 		dev_kfree_skb(skb);
2248 	}
2249 
2250 	return ret;
2251 }
2252 
2253 int ath11k_wmi_send_scan_stop_cmd(struct ath11k *ar,
2254 				  struct scan_cancel_param *param)
2255 {
2256 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2257 	struct wmi_stop_scan_cmd *cmd;
2258 	struct sk_buff *skb;
2259 	int ret;
2260 
2261 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2262 	if (!skb)
2263 		return -ENOMEM;
2264 
2265 	cmd = (struct wmi_stop_scan_cmd *)skb->data;
2266 
2267 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_STOP_SCAN_CMD) |
2268 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2269 
2270 	cmd->vdev_id = param->vdev_id;
2271 	cmd->requestor = param->requester;
2272 	cmd->scan_id = param->scan_id;
2273 	cmd->pdev_id = param->pdev_id;
2274 	/* stop the scan with the corresponding scan_id */
2275 	if (param->req_type == WLAN_SCAN_CANCEL_PDEV_ALL) {
2276 		/* Cancelling all scans */
2277 		cmd->req_type =  WMI_SCAN_STOP_ALL;
2278 	} else if (param->req_type == WLAN_SCAN_CANCEL_VDEV_ALL) {
2279 		/* Cancelling VAP scans */
2280 		cmd->req_type =  WMI_SCN_STOP_VAP_ALL;
2281 	} else if (param->req_type == WLAN_SCAN_CANCEL_SINGLE) {
2282 		/* Cancelling specific scan */
2283 		cmd->req_type =  WMI_SCAN_STOP_ONE;
2284 	} else {
2285 		ath11k_warn(ar->ab, "invalid scan cancel param %d",
2286 			    param->req_type);
2287 		dev_kfree_skb(skb);
2288 		return -EINVAL;
2289 	}
2290 
2291 	ret = ath11k_wmi_cmd_send(wmi, skb,
2292 				  WMI_STOP_SCAN_CMDID);
2293 	if (ret) {
2294 		ath11k_warn(ar->ab, "failed to send WMI_STOP_SCAN_CMDID\n");
2295 		dev_kfree_skb(skb);
2296 	}
2297 
2298 	return ret;
2299 }
2300 
2301 int ath11k_wmi_send_scan_chan_list_cmd(struct ath11k *ar,
2302 				       struct scan_chan_list_params *chan_list)
2303 {
2304 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2305 	struct wmi_scan_chan_list_cmd *cmd;
2306 	struct sk_buff *skb;
2307 	struct wmi_channel *chan_info;
2308 	struct channel_param *tchan_info;
2309 	struct wmi_tlv *tlv;
2310 	void *ptr;
2311 	int i, ret, len;
2312 	u16 num_send_chans, num_sends = 0, max_chan_limit = 0;
2313 	u32 *reg1, *reg2;
2314 
2315 	tchan_info = &chan_list->ch_param[0];
2316 	while (chan_list->nallchans) {
2317 		len = sizeof(*cmd) + TLV_HDR_SIZE;
2318 		max_chan_limit = (wmi->wmi_ab->max_msg_len[ar->pdev_idx] - len) /
2319 			sizeof(*chan_info);
2320 
2321 		if (chan_list->nallchans > max_chan_limit)
2322 			num_send_chans = max_chan_limit;
2323 		else
2324 			num_send_chans = chan_list->nallchans;
2325 
2326 		chan_list->nallchans -= num_send_chans;
2327 		len += sizeof(*chan_info) * num_send_chans;
2328 
2329 		skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2330 		if (!skb)
2331 			return -ENOMEM;
2332 
2333 		cmd = (struct wmi_scan_chan_list_cmd *)skb->data;
2334 		cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_SCAN_CHAN_LIST_CMD) |
2335 			FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2336 		cmd->pdev_id = chan_list->pdev_id;
2337 		cmd->num_scan_chans = num_send_chans;
2338 		if (num_sends)
2339 			cmd->flags |= WMI_APPEND_TO_EXISTING_CHAN_LIST_FLAG;
2340 
2341 		ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2342 			   "WMI no.of chan = %d len = %d pdev_id = %d num_sends = %d\n",
2343 			   num_send_chans, len, cmd->pdev_id, num_sends);
2344 
2345 		ptr = skb->data + sizeof(*cmd);
2346 
2347 		len = sizeof(*chan_info) * num_send_chans;
2348 		tlv = ptr;
2349 		tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2350 			      FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2351 		ptr += TLV_HDR_SIZE;
2352 
2353 		for (i = 0; i < num_send_chans; ++i) {
2354 			chan_info = ptr;
2355 			memset(chan_info, 0, sizeof(*chan_info));
2356 			len = sizeof(*chan_info);
2357 			chan_info->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2358 							   WMI_TAG_CHANNEL) |
2359 						FIELD_PREP(WMI_TLV_LEN,
2360 							   len - TLV_HDR_SIZE);
2361 
2362 			reg1 = &chan_info->reg_info_1;
2363 			reg2 = &chan_info->reg_info_2;
2364 			chan_info->mhz = tchan_info->mhz;
2365 			chan_info->band_center_freq1 = tchan_info->cfreq1;
2366 			chan_info->band_center_freq2 = tchan_info->cfreq2;
2367 
2368 			if (tchan_info->is_chan_passive)
2369 				chan_info->info |= WMI_CHAN_INFO_PASSIVE;
2370 			if (tchan_info->allow_he)
2371 				chan_info->info |= WMI_CHAN_INFO_ALLOW_HE;
2372 			else if (tchan_info->allow_vht)
2373 				chan_info->info |= WMI_CHAN_INFO_ALLOW_VHT;
2374 			else if (tchan_info->allow_ht)
2375 				chan_info->info |= WMI_CHAN_INFO_ALLOW_HT;
2376 			if (tchan_info->half_rate)
2377 				chan_info->info |= WMI_CHAN_INFO_HALF_RATE;
2378 			if (tchan_info->quarter_rate)
2379 				chan_info->info |= WMI_CHAN_INFO_QUARTER_RATE;
2380 			if (tchan_info->psc_channel)
2381 				chan_info->info |= WMI_CHAN_INFO_PSC;
2382 
2383 			chan_info->info |= FIELD_PREP(WMI_CHAN_INFO_MODE,
2384 						      tchan_info->phy_mode);
2385 			*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_MIN_PWR,
2386 					    tchan_info->minpower);
2387 			*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_PWR,
2388 					    tchan_info->maxpower);
2389 			*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_REG_PWR,
2390 					    tchan_info->maxregpower);
2391 			*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_REG_CLS,
2392 					    tchan_info->reg_class_id);
2393 			*reg2 |= FIELD_PREP(WMI_CHAN_REG_INFO2_ANT_MAX,
2394 					    tchan_info->antennamax);
2395 
2396 			ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2397 				   "WMI chan scan list chan[%d] = %u, chan_info->info %8x\n",
2398 				   i, chan_info->mhz, chan_info->info);
2399 
2400 			ptr += sizeof(*chan_info);
2401 
2402 			tchan_info++;
2403 		}
2404 
2405 		ret = ath11k_wmi_cmd_send(wmi, skb, WMI_SCAN_CHAN_LIST_CMDID);
2406 		if (ret) {
2407 			ath11k_warn(ar->ab, "failed to send WMI_SCAN_CHAN_LIST cmd\n");
2408 			dev_kfree_skb(skb);
2409 			return ret;
2410 		}
2411 
2412 		num_sends++;
2413 	}
2414 
2415 	return 0;
2416 }
2417 
2418 int ath11k_wmi_send_wmm_update_cmd_tlv(struct ath11k *ar, u32 vdev_id,
2419 				       struct wmi_wmm_params_all_arg *param)
2420 {
2421 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2422 	struct wmi_vdev_set_wmm_params_cmd *cmd;
2423 	struct wmi_wmm_params *wmm_param;
2424 	struct wmi_wmm_params_arg *wmi_wmm_arg;
2425 	struct sk_buff *skb;
2426 	int ret, ac;
2427 
2428 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2429 	if (!skb)
2430 		return -ENOMEM;
2431 
2432 	cmd = (struct wmi_vdev_set_wmm_params_cmd *)skb->data;
2433 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2434 				     WMI_TAG_VDEV_SET_WMM_PARAMS_CMD) |
2435 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2436 
2437 	cmd->vdev_id = vdev_id;
2438 	cmd->wmm_param_type = 0;
2439 
2440 	for (ac = 0; ac < WME_NUM_AC; ac++) {
2441 		switch (ac) {
2442 		case WME_AC_BE:
2443 			wmi_wmm_arg = &param->ac_be;
2444 			break;
2445 		case WME_AC_BK:
2446 			wmi_wmm_arg = &param->ac_bk;
2447 			break;
2448 		case WME_AC_VI:
2449 			wmi_wmm_arg = &param->ac_vi;
2450 			break;
2451 		case WME_AC_VO:
2452 			wmi_wmm_arg = &param->ac_vo;
2453 			break;
2454 		}
2455 
2456 		wmm_param = (struct wmi_wmm_params *)&cmd->wmm_params[ac];
2457 		wmm_param->tlv_header =
2458 				FIELD_PREP(WMI_TLV_TAG,
2459 					   WMI_TAG_VDEV_SET_WMM_PARAMS_CMD) |
2460 				FIELD_PREP(WMI_TLV_LEN,
2461 					   sizeof(*wmm_param) - TLV_HDR_SIZE);
2462 
2463 		wmm_param->aifs = wmi_wmm_arg->aifs;
2464 		wmm_param->cwmin = wmi_wmm_arg->cwmin;
2465 		wmm_param->cwmax = wmi_wmm_arg->cwmax;
2466 		wmm_param->txoplimit = wmi_wmm_arg->txop;
2467 		wmm_param->acm = wmi_wmm_arg->acm;
2468 		wmm_param->no_ack = wmi_wmm_arg->no_ack;
2469 
2470 		ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2471 			   "wmi wmm set ac %d aifs %d cwmin %d cwmax %d txop %d acm %d no_ack %d\n",
2472 			   ac, wmm_param->aifs, wmm_param->cwmin,
2473 			   wmm_param->cwmax, wmm_param->txoplimit,
2474 			   wmm_param->acm, wmm_param->no_ack);
2475 	}
2476 	ret = ath11k_wmi_cmd_send(wmi, skb,
2477 				  WMI_VDEV_SET_WMM_PARAMS_CMDID);
2478 	if (ret) {
2479 		ath11k_warn(ar->ab,
2480 			    "failed to send WMI_VDEV_SET_WMM_PARAMS_CMDID");
2481 		dev_kfree_skb(skb);
2482 	}
2483 
2484 	return ret;
2485 }
2486 
2487 int ath11k_wmi_send_dfs_phyerr_offload_enable_cmd(struct ath11k *ar,
2488 						  u32 pdev_id)
2489 {
2490 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2491 	struct wmi_dfs_phyerr_offload_cmd *cmd;
2492 	struct sk_buff *skb;
2493 	int ret;
2494 
2495 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2496 	if (!skb)
2497 		return -ENOMEM;
2498 
2499 	cmd = (struct wmi_dfs_phyerr_offload_cmd *)skb->data;
2500 	cmd->tlv_header =
2501 		FIELD_PREP(WMI_TLV_TAG,
2502 			   WMI_TAG_PDEV_DFS_PHYERR_OFFLOAD_ENABLE_CMD) |
2503 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2504 
2505 	cmd->pdev_id = pdev_id;
2506 
2507 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2508 		   "WMI dfs phy err offload enable pdev id %d\n", pdev_id);
2509 
2510 	ret = ath11k_wmi_cmd_send(wmi, skb,
2511 				  WMI_PDEV_DFS_PHYERR_OFFLOAD_ENABLE_CMDID);
2512 	if (ret) {
2513 		ath11k_warn(ar->ab,
2514 			    "failed to send WMI_PDEV_DFS_PHYERR_OFFLOAD_ENABLE cmd\n");
2515 		dev_kfree_skb(skb);
2516 	}
2517 
2518 	return ret;
2519 }
2520 
2521 int ath11k_wmi_delba_send(struct ath11k *ar, u32 vdev_id, const u8 *mac,
2522 			  u32 tid, u32 initiator, u32 reason)
2523 {
2524 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2525 	struct wmi_delba_send_cmd *cmd;
2526 	struct sk_buff *skb;
2527 	int ret;
2528 
2529 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2530 	if (!skb)
2531 		return -ENOMEM;
2532 
2533 	cmd = (struct wmi_delba_send_cmd *)skb->data;
2534 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_DELBA_SEND_CMD) |
2535 			FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2536 	cmd->vdev_id = vdev_id;
2537 	ether_addr_copy(cmd->peer_macaddr.addr, mac);
2538 	cmd->tid = tid;
2539 	cmd->initiator = initiator;
2540 	cmd->reasoncode = reason;
2541 
2542 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2543 		   "wmi delba send vdev_id 0x%X mac_addr %pM tid %u initiator %u reason %u\n",
2544 		   vdev_id, mac, tid, initiator, reason);
2545 
2546 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_DELBA_SEND_CMDID);
2547 
2548 	if (ret) {
2549 		ath11k_warn(ar->ab,
2550 			    "failed to send WMI_DELBA_SEND_CMDID cmd\n");
2551 		dev_kfree_skb(skb);
2552 	}
2553 
2554 	return ret;
2555 }
2556 
2557 int ath11k_wmi_addba_set_resp(struct ath11k *ar, u32 vdev_id, const u8 *mac,
2558 			      u32 tid, u32 status)
2559 {
2560 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2561 	struct wmi_addba_setresponse_cmd *cmd;
2562 	struct sk_buff *skb;
2563 	int ret;
2564 
2565 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2566 	if (!skb)
2567 		return -ENOMEM;
2568 
2569 	cmd = (struct wmi_addba_setresponse_cmd *)skb->data;
2570 	cmd->tlv_header =
2571 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ADDBA_SETRESPONSE_CMD) |
2572 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2573 	cmd->vdev_id = vdev_id;
2574 	ether_addr_copy(cmd->peer_macaddr.addr, mac);
2575 	cmd->tid = tid;
2576 	cmd->statuscode = status;
2577 
2578 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2579 		   "wmi addba set resp vdev_id 0x%X mac_addr %pM tid %u status %u\n",
2580 		   vdev_id, mac, tid, status);
2581 
2582 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_ADDBA_SET_RESP_CMDID);
2583 
2584 	if (ret) {
2585 		ath11k_warn(ar->ab,
2586 			    "failed to send WMI_ADDBA_SET_RESP_CMDID cmd\n");
2587 		dev_kfree_skb(skb);
2588 	}
2589 
2590 	return ret;
2591 }
2592 
2593 int ath11k_wmi_addba_send(struct ath11k *ar, u32 vdev_id, const u8 *mac,
2594 			  u32 tid, u32 buf_size)
2595 {
2596 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2597 	struct wmi_addba_send_cmd *cmd;
2598 	struct sk_buff *skb;
2599 	int ret;
2600 
2601 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2602 	if (!skb)
2603 		return -ENOMEM;
2604 
2605 	cmd = (struct wmi_addba_send_cmd *)skb->data;
2606 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ADDBA_SEND_CMD) |
2607 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2608 	cmd->vdev_id = vdev_id;
2609 	ether_addr_copy(cmd->peer_macaddr.addr, mac);
2610 	cmd->tid = tid;
2611 	cmd->buffersize = buf_size;
2612 
2613 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2614 		   "wmi addba send vdev_id 0x%X mac_addr %pM tid %u bufsize %u\n",
2615 		   vdev_id, mac, tid, buf_size);
2616 
2617 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_ADDBA_SEND_CMDID);
2618 
2619 	if (ret) {
2620 		ath11k_warn(ar->ab,
2621 			    "failed to send WMI_ADDBA_SEND_CMDID cmd\n");
2622 		dev_kfree_skb(skb);
2623 	}
2624 
2625 	return ret;
2626 }
2627 
2628 int ath11k_wmi_addba_clear_resp(struct ath11k *ar, u32 vdev_id, const u8 *mac)
2629 {
2630 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2631 	struct wmi_addba_clear_resp_cmd *cmd;
2632 	struct sk_buff *skb;
2633 	int ret;
2634 
2635 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2636 	if (!skb)
2637 		return -ENOMEM;
2638 
2639 	cmd = (struct wmi_addba_clear_resp_cmd *)skb->data;
2640 	cmd->tlv_header =
2641 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ADDBA_CLEAR_RESP_CMD) |
2642 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2643 	cmd->vdev_id = vdev_id;
2644 	ether_addr_copy(cmd->peer_macaddr.addr, mac);
2645 
2646 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2647 		   "wmi addba clear resp vdev_id 0x%X mac_addr %pM\n",
2648 		   vdev_id, mac);
2649 
2650 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_ADDBA_CLEAR_RESP_CMDID);
2651 
2652 	if (ret) {
2653 		ath11k_warn(ar->ab,
2654 			    "failed to send WMI_ADDBA_CLEAR_RESP_CMDID cmd\n");
2655 		dev_kfree_skb(skb);
2656 	}
2657 
2658 	return ret;
2659 }
2660 
2661 int ath11k_wmi_pdev_peer_pktlog_filter(struct ath11k *ar, u8 *addr, u8 enable)
2662 {
2663 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2664 	struct wmi_pdev_pktlog_filter_cmd *cmd;
2665 	struct wmi_pdev_pktlog_filter_info *info;
2666 	struct sk_buff *skb;
2667 	struct wmi_tlv *tlv;
2668 	void *ptr;
2669 	int ret, len;
2670 
2671 	len = sizeof(*cmd) + sizeof(*info) + TLV_HDR_SIZE;
2672 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2673 	if (!skb)
2674 		return -ENOMEM;
2675 
2676 	cmd = (struct wmi_pdev_pktlog_filter_cmd *)skb->data;
2677 
2678 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PEER_PKTLOG_FILTER_CMD) |
2679 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2680 
2681 	cmd->pdev_id = DP_HW2SW_MACID(ar->pdev->pdev_id);
2682 	cmd->num_mac = 1;
2683 	cmd->enable = enable;
2684 
2685 	ptr = skb->data + sizeof(*cmd);
2686 
2687 	tlv = ptr;
2688 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2689 		      FIELD_PREP(WMI_TLV_LEN, sizeof(*info));
2690 
2691 	ptr += TLV_HDR_SIZE;
2692 	info = ptr;
2693 
2694 	ether_addr_copy(info->peer_macaddr.addr, addr);
2695 	info->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PEER_PKTLOG_FILTER_INFO) |
2696 			   FIELD_PREP(WMI_TLV_LEN,
2697 				      sizeof(*info) - TLV_HDR_SIZE);
2698 
2699 	ret = ath11k_wmi_cmd_send(wmi, skb,
2700 				  WMI_PDEV_PKTLOG_FILTER_CMDID);
2701 	if (ret) {
2702 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_PKTLOG_ENABLE_CMDID\n");
2703 		dev_kfree_skb(skb);
2704 	}
2705 
2706 	return ret;
2707 }
2708 
2709 int
2710 ath11k_wmi_send_init_country_cmd(struct ath11k *ar,
2711 				 struct wmi_init_country_params init_cc_params)
2712 {
2713 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2714 	struct wmi_init_country_cmd *cmd;
2715 	struct sk_buff *skb;
2716 	int ret;
2717 
2718 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2719 	if (!skb)
2720 		return -ENOMEM;
2721 
2722 	cmd = (struct wmi_init_country_cmd *)skb->data;
2723 	cmd->tlv_header =
2724 		FIELD_PREP(WMI_TLV_TAG,
2725 			   WMI_TAG_SET_INIT_COUNTRY_CMD) |
2726 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2727 
2728 	cmd->pdev_id = ar->pdev->pdev_id;
2729 
2730 	switch (init_cc_params.flags) {
2731 	case ALPHA_IS_SET:
2732 		cmd->init_cc_type = WMI_COUNTRY_INFO_TYPE_ALPHA;
2733 		memcpy((u8 *)&cmd->cc_info.alpha2,
2734 		       init_cc_params.cc_info.alpha2, 3);
2735 		break;
2736 	case CC_IS_SET:
2737 		cmd->init_cc_type = WMI_COUNTRY_INFO_TYPE_COUNTRY_CODE;
2738 		cmd->cc_info.country_code = init_cc_params.cc_info.country_code;
2739 		break;
2740 	case REGDMN_IS_SET:
2741 		cmd->init_cc_type = WMI_COUNTRY_INFO_TYPE_REGDOMAIN;
2742 		cmd->cc_info.regdom_id = init_cc_params.cc_info.regdom_id;
2743 		break;
2744 	default:
2745 		ret = -EINVAL;
2746 		goto out;
2747 	}
2748 
2749 	ret = ath11k_wmi_cmd_send(wmi, skb,
2750 				  WMI_SET_INIT_COUNTRY_CMDID);
2751 
2752 out:
2753 	if (ret) {
2754 		ath11k_warn(ar->ab,
2755 			    "failed to send WMI_SET_INIT_COUNTRY CMD :%d\n",
2756 			    ret);
2757 		dev_kfree_skb(skb);
2758 	}
2759 
2760 	return ret;
2761 }
2762 
2763 int
2764 ath11k_wmi_send_thermal_mitigation_param_cmd(struct ath11k *ar,
2765 					     struct thermal_mitigation_params *param)
2766 {
2767 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2768 	struct wmi_therm_throt_config_request_cmd *cmd;
2769 	struct wmi_therm_throt_level_config_info *lvl_conf;
2770 	struct wmi_tlv *tlv;
2771 	struct sk_buff *skb;
2772 	int i, ret, len;
2773 
2774 	len = sizeof(*cmd) + TLV_HDR_SIZE +
2775 	      THERMAL_LEVELS * sizeof(struct wmi_therm_throt_level_config_info);
2776 
2777 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2778 	if (!skb)
2779 		return -ENOMEM;
2780 
2781 	cmd = (struct wmi_therm_throt_config_request_cmd *)skb->data;
2782 
2783 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_THERM_THROT_CONFIG_REQUEST) |
2784 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2785 
2786 	cmd->pdev_id = ar->pdev->pdev_id;
2787 	cmd->enable = param->enable;
2788 	cmd->dc = param->dc;
2789 	cmd->dc_per_event = param->dc_per_event;
2790 	cmd->therm_throt_levels = THERMAL_LEVELS;
2791 
2792 	tlv = (struct wmi_tlv *)(skb->data + sizeof(*cmd));
2793 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2794 		      FIELD_PREP(WMI_TLV_LEN,
2795 				 (THERMAL_LEVELS *
2796 				  sizeof(struct wmi_therm_throt_level_config_info)));
2797 
2798 	lvl_conf = (struct wmi_therm_throt_level_config_info *)(skb->data +
2799 								sizeof(*cmd) +
2800 								TLV_HDR_SIZE);
2801 	for (i = 0; i < THERMAL_LEVELS; i++) {
2802 		lvl_conf->tlv_header =
2803 			FIELD_PREP(WMI_TLV_TAG, WMI_TAG_THERM_THROT_LEVEL_CONFIG_INFO) |
2804 			FIELD_PREP(WMI_TLV_LEN, sizeof(*lvl_conf) - TLV_HDR_SIZE);
2805 
2806 		lvl_conf->temp_lwm = param->levelconf[i].tmplwm;
2807 		lvl_conf->temp_hwm = param->levelconf[i].tmphwm;
2808 		lvl_conf->dc_off_percent = param->levelconf[i].dcoffpercent;
2809 		lvl_conf->prio = param->levelconf[i].priority;
2810 		lvl_conf++;
2811 	}
2812 
2813 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_THERM_THROT_SET_CONF_CMDID);
2814 	if (ret) {
2815 		ath11k_warn(ar->ab, "failed to send THERM_THROT_SET_CONF cmd\n");
2816 		dev_kfree_skb(skb);
2817 	}
2818 
2819 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2820 		   "WMI vdev set thermal throt pdev_id %d enable %d dc %d dc_per_event %x levels %d\n",
2821 		   ar->pdev->pdev_id, param->enable, param->dc,
2822 		   param->dc_per_event, THERMAL_LEVELS);
2823 
2824 	return ret;
2825 }
2826 
2827 int ath11k_wmi_pdev_pktlog_enable(struct ath11k *ar, u32 pktlog_filter)
2828 {
2829 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2830 	struct wmi_pktlog_enable_cmd *cmd;
2831 	struct sk_buff *skb;
2832 	int ret;
2833 
2834 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2835 	if (!skb)
2836 		return -ENOMEM;
2837 
2838 	cmd = (struct wmi_pktlog_enable_cmd *)skb->data;
2839 
2840 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PKTLOG_ENABLE_CMD) |
2841 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2842 
2843 	cmd->pdev_id = DP_HW2SW_MACID(ar->pdev->pdev_id);
2844 	cmd->evlist = pktlog_filter;
2845 	cmd->enable = ATH11K_WMI_PKTLOG_ENABLE_FORCE;
2846 
2847 	ret = ath11k_wmi_cmd_send(wmi, skb,
2848 				  WMI_PDEV_PKTLOG_ENABLE_CMDID);
2849 	if (ret) {
2850 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_PKTLOG_ENABLE_CMDID\n");
2851 		dev_kfree_skb(skb);
2852 	}
2853 
2854 	return ret;
2855 }
2856 
2857 int ath11k_wmi_pdev_pktlog_disable(struct ath11k *ar)
2858 {
2859 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2860 	struct wmi_pktlog_disable_cmd *cmd;
2861 	struct sk_buff *skb;
2862 	int ret;
2863 
2864 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, sizeof(*cmd));
2865 	if (!skb)
2866 		return -ENOMEM;
2867 
2868 	cmd = (struct wmi_pktlog_disable_cmd *)skb->data;
2869 
2870 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PKTLOG_DISABLE_CMD) |
2871 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2872 
2873 	cmd->pdev_id = DP_HW2SW_MACID(ar->pdev->pdev_id);
2874 
2875 	ret = ath11k_wmi_cmd_send(wmi, skb,
2876 				  WMI_PDEV_PKTLOG_DISABLE_CMDID);
2877 	if (ret) {
2878 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_PKTLOG_ENABLE_CMDID\n");
2879 		dev_kfree_skb(skb);
2880 	}
2881 
2882 	return ret;
2883 }
2884 
2885 int
2886 ath11k_wmi_send_twt_enable_cmd(struct ath11k *ar, u32 pdev_id)
2887 {
2888 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2889 	struct ath11k_base *ab = wmi->wmi_ab->ab;
2890 	struct wmi_twt_enable_params_cmd *cmd;
2891 	struct sk_buff *skb;
2892 	int ret, len;
2893 
2894 	len = sizeof(*cmd);
2895 
2896 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2897 	if (!skb)
2898 		return -ENOMEM;
2899 
2900 	cmd = (struct wmi_twt_enable_params_cmd *)skb->data;
2901 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_TWT_ENABLE_CMD) |
2902 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2903 	cmd->pdev_id = pdev_id;
2904 	cmd->sta_cong_timer_ms = ATH11K_TWT_DEF_STA_CONG_TIMER_MS;
2905 	cmd->default_slot_size = ATH11K_TWT_DEF_DEFAULT_SLOT_SIZE;
2906 	cmd->congestion_thresh_setup = ATH11K_TWT_DEF_CONGESTION_THRESH_SETUP;
2907 	cmd->congestion_thresh_teardown =
2908 		ATH11K_TWT_DEF_CONGESTION_THRESH_TEARDOWN;
2909 	cmd->congestion_thresh_critical =
2910 		ATH11K_TWT_DEF_CONGESTION_THRESH_CRITICAL;
2911 	cmd->interference_thresh_teardown =
2912 		ATH11K_TWT_DEF_INTERFERENCE_THRESH_TEARDOWN;
2913 	cmd->interference_thresh_setup =
2914 		ATH11K_TWT_DEF_INTERFERENCE_THRESH_SETUP;
2915 	cmd->min_no_sta_setup = ATH11K_TWT_DEF_MIN_NO_STA_SETUP;
2916 	cmd->min_no_sta_teardown = ATH11K_TWT_DEF_MIN_NO_STA_TEARDOWN;
2917 	cmd->no_of_bcast_mcast_slots = ATH11K_TWT_DEF_NO_OF_BCAST_MCAST_SLOTS;
2918 	cmd->min_no_twt_slots = ATH11K_TWT_DEF_MIN_NO_TWT_SLOTS;
2919 	cmd->max_no_sta_twt = ATH11K_TWT_DEF_MAX_NO_STA_TWT;
2920 	cmd->mode_check_interval = ATH11K_TWT_DEF_MODE_CHECK_INTERVAL;
2921 	cmd->add_sta_slot_interval = ATH11K_TWT_DEF_ADD_STA_SLOT_INTERVAL;
2922 	cmd->remove_sta_slot_interval =
2923 		ATH11K_TWT_DEF_REMOVE_STA_SLOT_INTERVAL;
2924 	/* TODO add MBSSID support */
2925 	cmd->mbss_support = 0;
2926 
2927 	ret = ath11k_wmi_cmd_send(wmi, skb,
2928 				  WMI_TWT_ENABLE_CMDID);
2929 	if (ret) {
2930 		ath11k_warn(ab, "Failed to send WMI_TWT_ENABLE_CMDID");
2931 		dev_kfree_skb(skb);
2932 	}
2933 	return ret;
2934 }
2935 
2936 int
2937 ath11k_wmi_send_twt_disable_cmd(struct ath11k *ar, u32 pdev_id)
2938 {
2939 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2940 	struct ath11k_base *ab = wmi->wmi_ab->ab;
2941 	struct wmi_twt_disable_params_cmd *cmd;
2942 	struct sk_buff *skb;
2943 	int ret, len;
2944 
2945 	len = sizeof(*cmd);
2946 
2947 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2948 	if (!skb)
2949 		return -ENOMEM;
2950 
2951 	cmd = (struct wmi_twt_disable_params_cmd *)skb->data;
2952 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_TWT_DISABLE_CMD) |
2953 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2954 	cmd->pdev_id = pdev_id;
2955 
2956 	ret = ath11k_wmi_cmd_send(wmi, skb,
2957 				  WMI_TWT_DISABLE_CMDID);
2958 	if (ret) {
2959 		ath11k_warn(ab, "Failed to send WMI_TWT_DISABLE_CMDID");
2960 		dev_kfree_skb(skb);
2961 	}
2962 	return ret;
2963 }
2964 
2965 int
2966 ath11k_wmi_send_obss_spr_cmd(struct ath11k *ar, u32 vdev_id,
2967 			     struct ieee80211_he_obss_pd *he_obss_pd)
2968 {
2969 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2970 	struct ath11k_base *ab = wmi->wmi_ab->ab;
2971 	struct wmi_obss_spatial_reuse_params_cmd *cmd;
2972 	struct sk_buff *skb;
2973 	int ret, len;
2974 
2975 	len = sizeof(*cmd);
2976 
2977 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
2978 	if (!skb)
2979 		return -ENOMEM;
2980 
2981 	cmd = (struct wmi_obss_spatial_reuse_params_cmd *)skb->data;
2982 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2983 				     WMI_TAG_OBSS_SPATIAL_REUSE_SET_CMD) |
2984 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2985 	cmd->vdev_id = vdev_id;
2986 	cmd->enable = he_obss_pd->enable;
2987 	cmd->obss_min = he_obss_pd->min_offset;
2988 	cmd->obss_max = he_obss_pd->max_offset;
2989 
2990 	ret = ath11k_wmi_cmd_send(wmi, skb,
2991 				  WMI_PDEV_OBSS_PD_SPATIAL_REUSE_CMDID);
2992 	if (ret) {
2993 		ath11k_warn(ab,
2994 			    "Failed to send WMI_PDEV_OBSS_PD_SPATIAL_REUSE_CMDID");
2995 		dev_kfree_skb(skb);
2996 	}
2997 	return ret;
2998 }
2999 
3000 int
3001 ath11k_wmi_send_obss_color_collision_cfg_cmd(struct ath11k *ar, u32 vdev_id,
3002 					     u8 bss_color, u32 period,
3003 					     bool enable)
3004 {
3005 	struct ath11k_pdev_wmi *wmi = ar->wmi;
3006 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3007 	struct wmi_obss_color_collision_cfg_params_cmd *cmd;
3008 	struct sk_buff *skb;
3009 	int ret, len;
3010 
3011 	len = sizeof(*cmd);
3012 
3013 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3014 	if (!skb)
3015 		return -ENOMEM;
3016 
3017 	cmd = (struct wmi_obss_color_collision_cfg_params_cmd *)skb->data;
3018 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3019 				     WMI_TAG_OBSS_COLOR_COLLISION_DET_CONFIG) |
3020 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3021 	cmd->vdev_id = vdev_id;
3022 	cmd->evt_type = enable ? ATH11K_OBSS_COLOR_COLLISION_DETECTION :
3023 				 ATH11K_OBSS_COLOR_COLLISION_DETECTION_DISABLE;
3024 	cmd->current_bss_color = bss_color;
3025 	cmd->detection_period_ms = period;
3026 	cmd->scan_period_ms = ATH11K_BSS_COLOR_COLLISION_SCAN_PERIOD_MS;
3027 	cmd->free_slot_expiry_time_ms = 0;
3028 	cmd->flags = 0;
3029 
3030 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3031 		   "wmi_send_obss_color_collision_cfg id %d type %d bss_color %d detect_period %d scan_period %d\n",
3032 		   cmd->vdev_id, cmd->evt_type, cmd->current_bss_color,
3033 		   cmd->detection_period_ms, cmd->scan_period_ms);
3034 
3035 	ret = ath11k_wmi_cmd_send(wmi, skb,
3036 				  WMI_OBSS_COLOR_COLLISION_DET_CONFIG_CMDID);
3037 	if (ret) {
3038 		ath11k_warn(ab, "Failed to send WMI_OBSS_COLOR_COLLISION_DET_CONFIG_CMDID");
3039 		dev_kfree_skb(skb);
3040 	}
3041 	return ret;
3042 }
3043 
3044 int ath11k_wmi_send_bss_color_change_enable_cmd(struct ath11k *ar, u32 vdev_id,
3045 						bool enable)
3046 {
3047 	struct ath11k_pdev_wmi *wmi = ar->wmi;
3048 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3049 	struct wmi_bss_color_change_enable_params_cmd *cmd;
3050 	struct sk_buff *skb;
3051 	int ret, len;
3052 
3053 	len = sizeof(*cmd);
3054 
3055 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3056 	if (!skb)
3057 		return -ENOMEM;
3058 
3059 	cmd = (struct wmi_bss_color_change_enable_params_cmd *)skb->data;
3060 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_BSS_COLOR_CHANGE_ENABLE) |
3061 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3062 	cmd->vdev_id = vdev_id;
3063 	cmd->enable = enable ? 1 : 0;
3064 
3065 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3066 		   "wmi_send_bss_color_change_enable id %d enable %d\n",
3067 		   cmd->vdev_id, cmd->enable);
3068 
3069 	ret = ath11k_wmi_cmd_send(wmi, skb,
3070 				  WMI_BSS_COLOR_CHANGE_ENABLE_CMDID);
3071 	if (ret) {
3072 		ath11k_warn(ab, "Failed to send WMI_BSS_COLOR_CHANGE_ENABLE_CMDID");
3073 		dev_kfree_skb(skb);
3074 	}
3075 	return ret;
3076 }
3077 
3078 int ath11k_wmi_fils_discovery_tmpl(struct ath11k *ar, u32 vdev_id,
3079 				   struct sk_buff *tmpl)
3080 {
3081 	struct wmi_tlv *tlv;
3082 	struct sk_buff *skb;
3083 	void *ptr;
3084 	int ret, len;
3085 	size_t aligned_len;
3086 	struct wmi_fils_discovery_tmpl_cmd *cmd;
3087 
3088 	aligned_len = roundup(tmpl->len, 4);
3089 	len = sizeof(*cmd) + TLV_HDR_SIZE + aligned_len;
3090 
3091 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3092 		   "WMI vdev %i set FILS discovery template\n", vdev_id);
3093 
3094 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, len);
3095 	if (!skb)
3096 		return -ENOMEM;
3097 
3098 	cmd = (struct wmi_fils_discovery_tmpl_cmd *)skb->data;
3099 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3100 				     WMI_TAG_FILS_DISCOVERY_TMPL_CMD) |
3101 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3102 	cmd->vdev_id = vdev_id;
3103 	cmd->buf_len = tmpl->len;
3104 	ptr = skb->data + sizeof(*cmd);
3105 
3106 	tlv = ptr;
3107 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
3108 		      FIELD_PREP(WMI_TLV_LEN, aligned_len);
3109 	memcpy(tlv->value, tmpl->data, tmpl->len);
3110 
3111 	ret = ath11k_wmi_cmd_send(ar->wmi, skb, WMI_FILS_DISCOVERY_TMPL_CMDID);
3112 	if (ret) {
3113 		ath11k_warn(ar->ab,
3114 			    "WMI vdev %i failed to send FILS discovery template command\n",
3115 			    vdev_id);
3116 		dev_kfree_skb(skb);
3117 	}
3118 	return ret;
3119 }
3120 
3121 int ath11k_wmi_probe_resp_tmpl(struct ath11k *ar, u32 vdev_id,
3122 			       struct sk_buff *tmpl)
3123 {
3124 	struct wmi_probe_tmpl_cmd *cmd;
3125 	struct wmi_bcn_prb_info *probe_info;
3126 	struct wmi_tlv *tlv;
3127 	struct sk_buff *skb;
3128 	void *ptr;
3129 	int ret, len;
3130 	size_t aligned_len = roundup(tmpl->len, 4);
3131 
3132 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3133 		   "WMI vdev %i set probe response template\n", vdev_id);
3134 
3135 	len = sizeof(*cmd) + sizeof(*probe_info) + TLV_HDR_SIZE + aligned_len;
3136 
3137 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, len);
3138 	if (!skb)
3139 		return -ENOMEM;
3140 
3141 	cmd = (struct wmi_probe_tmpl_cmd *)skb->data;
3142 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PRB_TMPL_CMD) |
3143 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3144 	cmd->vdev_id = vdev_id;
3145 	cmd->buf_len = tmpl->len;
3146 
3147 	ptr = skb->data + sizeof(*cmd);
3148 
3149 	probe_info = ptr;
3150 	len = sizeof(*probe_info);
3151 	probe_info->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3152 					    WMI_TAG_BCN_PRB_INFO) |
3153 				 FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3154 	probe_info->caps = 0;
3155 	probe_info->erp = 0;
3156 
3157 	ptr += sizeof(*probe_info);
3158 
3159 	tlv = ptr;
3160 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
3161 		      FIELD_PREP(WMI_TLV_LEN, aligned_len);
3162 	memcpy(tlv->value, tmpl->data, tmpl->len);
3163 
3164 	ret = ath11k_wmi_cmd_send(ar->wmi, skb, WMI_PRB_TMPL_CMDID);
3165 	if (ret) {
3166 		ath11k_warn(ar->ab,
3167 			    "WMI vdev %i failed to send probe response template command\n",
3168 			    vdev_id);
3169 		dev_kfree_skb(skb);
3170 	}
3171 	return ret;
3172 }
3173 
3174 int ath11k_wmi_fils_discovery(struct ath11k *ar, u32 vdev_id, u32 interval,
3175 			      bool unsol_bcast_probe_resp_enabled)
3176 {
3177 	struct sk_buff *skb;
3178 	int ret, len;
3179 	struct wmi_fils_discovery_cmd *cmd;
3180 
3181 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3182 		   "WMI vdev %i set %s interval to %u TU\n",
3183 		   vdev_id, unsol_bcast_probe_resp_enabled ?
3184 		   "unsolicited broadcast probe response" : "FILS discovery",
3185 		   interval);
3186 
3187 	len = sizeof(*cmd);
3188 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, len);
3189 	if (!skb)
3190 		return -ENOMEM;
3191 
3192 	cmd = (struct wmi_fils_discovery_cmd *)skb->data;
3193 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ENABLE_FILS_CMD) |
3194 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
3195 	cmd->vdev_id = vdev_id;
3196 	cmd->interval = interval;
3197 	cmd->config = unsol_bcast_probe_resp_enabled;
3198 
3199 	ret = ath11k_wmi_cmd_send(ar->wmi, skb, WMI_ENABLE_FILS_CMDID);
3200 	if (ret) {
3201 		ath11k_warn(ar->ab,
3202 			    "WMI vdev %i failed to send FILS discovery enable/disable command\n",
3203 			    vdev_id);
3204 		dev_kfree_skb(skb);
3205 	}
3206 	return ret;
3207 }
3208 
3209 static void
3210 ath11k_fill_band_to_mac_param(struct ath11k_base  *soc,
3211 			      struct wmi_host_pdev_band_to_mac *band_to_mac)
3212 {
3213 	u8 i;
3214 	struct ath11k_hal_reg_capabilities_ext *hal_reg_cap;
3215 	struct ath11k_pdev *pdev;
3216 
3217 	for (i = 0; i < soc->num_radios; i++) {
3218 		pdev = &soc->pdevs[i];
3219 		hal_reg_cap = &soc->hal_reg_cap[i];
3220 		band_to_mac[i].pdev_id = pdev->pdev_id;
3221 
3222 		switch (pdev->cap.supported_bands) {
3223 		case WMI_HOST_WLAN_2G_5G_CAP:
3224 			band_to_mac[i].start_freq = hal_reg_cap->low_2ghz_chan;
3225 			band_to_mac[i].end_freq = hal_reg_cap->high_5ghz_chan;
3226 			break;
3227 		case WMI_HOST_WLAN_2G_CAP:
3228 			band_to_mac[i].start_freq = hal_reg_cap->low_2ghz_chan;
3229 			band_to_mac[i].end_freq = hal_reg_cap->high_2ghz_chan;
3230 			break;
3231 		case WMI_HOST_WLAN_5G_CAP:
3232 			band_to_mac[i].start_freq = hal_reg_cap->low_5ghz_chan;
3233 			band_to_mac[i].end_freq = hal_reg_cap->high_5ghz_chan;
3234 			break;
3235 		default:
3236 			break;
3237 		}
3238 	}
3239 }
3240 
3241 static void
3242 ath11k_wmi_copy_resource_config(struct wmi_resource_config *wmi_cfg,
3243 				struct target_resource_config *tg_cfg)
3244 {
3245 	wmi_cfg->num_vdevs = tg_cfg->num_vdevs;
3246 	wmi_cfg->num_peers = tg_cfg->num_peers;
3247 	wmi_cfg->num_offload_peers = tg_cfg->num_offload_peers;
3248 	wmi_cfg->num_offload_reorder_buffs = tg_cfg->num_offload_reorder_buffs;
3249 	wmi_cfg->num_peer_keys = tg_cfg->num_peer_keys;
3250 	wmi_cfg->num_tids = tg_cfg->num_tids;
3251 	wmi_cfg->ast_skid_limit = tg_cfg->ast_skid_limit;
3252 	wmi_cfg->tx_chain_mask = tg_cfg->tx_chain_mask;
3253 	wmi_cfg->rx_chain_mask = tg_cfg->rx_chain_mask;
3254 	wmi_cfg->rx_timeout_pri[0] = tg_cfg->rx_timeout_pri[0];
3255 	wmi_cfg->rx_timeout_pri[1] = tg_cfg->rx_timeout_pri[1];
3256 	wmi_cfg->rx_timeout_pri[2] = tg_cfg->rx_timeout_pri[2];
3257 	wmi_cfg->rx_timeout_pri[3] = tg_cfg->rx_timeout_pri[3];
3258 	wmi_cfg->rx_decap_mode = tg_cfg->rx_decap_mode;
3259 	wmi_cfg->scan_max_pending_req = tg_cfg->scan_max_pending_req;
3260 	wmi_cfg->bmiss_offload_max_vdev = tg_cfg->bmiss_offload_max_vdev;
3261 	wmi_cfg->roam_offload_max_vdev = tg_cfg->roam_offload_max_vdev;
3262 	wmi_cfg->roam_offload_max_ap_profiles =
3263 		tg_cfg->roam_offload_max_ap_profiles;
3264 	wmi_cfg->num_mcast_groups = tg_cfg->num_mcast_groups;
3265 	wmi_cfg->num_mcast_table_elems = tg_cfg->num_mcast_table_elems;
3266 	wmi_cfg->mcast2ucast_mode = tg_cfg->mcast2ucast_mode;
3267 	wmi_cfg->tx_dbg_log_size = tg_cfg->tx_dbg_log_size;
3268 	wmi_cfg->num_wds_entries = tg_cfg->num_wds_entries;
3269 	wmi_cfg->dma_burst_size = tg_cfg->dma_burst_size;
3270 	wmi_cfg->mac_aggr_delim = tg_cfg->mac_aggr_delim;
3271 	wmi_cfg->rx_skip_defrag_timeout_dup_detection_check =
3272 		tg_cfg->rx_skip_defrag_timeout_dup_detection_check;
3273 	wmi_cfg->vow_config = tg_cfg->vow_config;
3274 	wmi_cfg->gtk_offload_max_vdev = tg_cfg->gtk_offload_max_vdev;
3275 	wmi_cfg->num_msdu_desc = tg_cfg->num_msdu_desc;
3276 	wmi_cfg->max_frag_entries = tg_cfg->max_frag_entries;
3277 	wmi_cfg->num_tdls_vdevs = tg_cfg->num_tdls_vdevs;
3278 	wmi_cfg->num_tdls_conn_table_entries =
3279 		tg_cfg->num_tdls_conn_table_entries;
3280 	wmi_cfg->beacon_tx_offload_max_vdev =
3281 		tg_cfg->beacon_tx_offload_max_vdev;
3282 	wmi_cfg->num_multicast_filter_entries =
3283 		tg_cfg->num_multicast_filter_entries;
3284 	wmi_cfg->num_wow_filters = tg_cfg->num_wow_filters;
3285 	wmi_cfg->num_keep_alive_pattern = tg_cfg->num_keep_alive_pattern;
3286 	wmi_cfg->keep_alive_pattern_size = tg_cfg->keep_alive_pattern_size;
3287 	wmi_cfg->max_tdls_concurrent_sleep_sta =
3288 		tg_cfg->max_tdls_concurrent_sleep_sta;
3289 	wmi_cfg->max_tdls_concurrent_buffer_sta =
3290 		tg_cfg->max_tdls_concurrent_buffer_sta;
3291 	wmi_cfg->wmi_send_separate = tg_cfg->wmi_send_separate;
3292 	wmi_cfg->num_ocb_vdevs = tg_cfg->num_ocb_vdevs;
3293 	wmi_cfg->num_ocb_channels = tg_cfg->num_ocb_channels;
3294 	wmi_cfg->num_ocb_schedules = tg_cfg->num_ocb_schedules;
3295 	wmi_cfg->bpf_instruction_size = tg_cfg->bpf_instruction_size;
3296 	wmi_cfg->max_bssid_rx_filters = tg_cfg->max_bssid_rx_filters;
3297 	wmi_cfg->use_pdev_id = tg_cfg->use_pdev_id;
3298 	wmi_cfg->flag1 = tg_cfg->atf_config;
3299 	wmi_cfg->peer_map_unmap_v2_support = tg_cfg->peer_map_unmap_v2_support;
3300 	wmi_cfg->sched_params = tg_cfg->sched_params;
3301 	wmi_cfg->twt_ap_pdev_count = tg_cfg->twt_ap_pdev_count;
3302 	wmi_cfg->twt_ap_sta_count = tg_cfg->twt_ap_sta_count;
3303 }
3304 
3305 static int ath11k_init_cmd_send(struct ath11k_pdev_wmi *wmi,
3306 				struct wmi_init_cmd_param *param)
3307 {
3308 	struct ath11k_base *ab = wmi->wmi_ab->ab;
3309 	struct sk_buff *skb;
3310 	struct wmi_init_cmd *cmd;
3311 	struct wmi_resource_config *cfg;
3312 	struct wmi_pdev_set_hw_mode_cmd_param *hw_mode;
3313 	struct wmi_pdev_band_to_mac *band_to_mac;
3314 	struct wlan_host_mem_chunk *host_mem_chunks;
3315 	struct wmi_tlv *tlv;
3316 	size_t ret, len;
3317 	void *ptr;
3318 	u32 hw_mode_len = 0;
3319 	u16 idx;
3320 
3321 	if (param->hw_mode_id != WMI_HOST_HW_MODE_MAX)
3322 		hw_mode_len = sizeof(*hw_mode) + TLV_HDR_SIZE +
3323 			      (param->num_band_to_mac * sizeof(*band_to_mac));
3324 
3325 	len = sizeof(*cmd) + TLV_HDR_SIZE + sizeof(*cfg) + hw_mode_len +
3326 	      (param->num_mem_chunks ? (sizeof(*host_mem_chunks) * WMI_MAX_MEM_REQS) : 0);
3327 
3328 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, len);
3329 	if (!skb)
3330 		return -ENOMEM;
3331 
3332 	cmd = (struct wmi_init_cmd *)skb->data;
3333 
3334 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_INIT_CMD) |
3335 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3336 
3337 	ptr = skb->data + sizeof(*cmd);
3338 	cfg = ptr;
3339 
3340 	ath11k_wmi_copy_resource_config(cfg, param->res_cfg);
3341 
3342 	cfg->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_RESOURCE_CONFIG) |
3343 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cfg) - TLV_HDR_SIZE);
3344 
3345 	ptr += sizeof(*cfg);
3346 	host_mem_chunks = ptr + TLV_HDR_SIZE;
3347 	len = sizeof(struct wlan_host_mem_chunk);
3348 
3349 	for (idx = 0; idx < param->num_mem_chunks; ++idx) {
3350 		host_mem_chunks[idx].tlv_header =
3351 				FIELD_PREP(WMI_TLV_TAG,
3352 					   WMI_TAG_WLAN_HOST_MEMORY_CHUNK) |
3353 				FIELD_PREP(WMI_TLV_LEN, len);
3354 
3355 		host_mem_chunks[idx].ptr = param->mem_chunks[idx].paddr;
3356 		host_mem_chunks[idx].size = param->mem_chunks[idx].len;
3357 		host_mem_chunks[idx].req_id = param->mem_chunks[idx].req_id;
3358 
3359 		ath11k_dbg(ab, ATH11K_DBG_WMI,
3360 			   "WMI host mem chunk req_id %d paddr 0x%llx len %d\n",
3361 			   param->mem_chunks[idx].req_id,
3362 			   (u64)param->mem_chunks[idx].paddr,
3363 			   param->mem_chunks[idx].len);
3364 	}
3365 	cmd->num_host_mem_chunks = param->num_mem_chunks;
3366 	len = sizeof(struct wlan_host_mem_chunk) * param->num_mem_chunks;
3367 
3368 	/* num_mem_chunks is zero */
3369 	tlv = ptr;
3370 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
3371 		      FIELD_PREP(WMI_TLV_LEN, len);
3372 	ptr += TLV_HDR_SIZE + len;
3373 
3374 	if (param->hw_mode_id != WMI_HOST_HW_MODE_MAX) {
3375 		hw_mode = (struct wmi_pdev_set_hw_mode_cmd_param *)ptr;
3376 		hw_mode->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3377 						 WMI_TAG_PDEV_SET_HW_MODE_CMD) |
3378 				      FIELD_PREP(WMI_TLV_LEN,
3379 						 sizeof(*hw_mode) - TLV_HDR_SIZE);
3380 
3381 		hw_mode->hw_mode_index = param->hw_mode_id;
3382 		hw_mode->num_band_to_mac = param->num_band_to_mac;
3383 
3384 		ptr += sizeof(*hw_mode);
3385 
3386 		len = param->num_band_to_mac * sizeof(*band_to_mac);
3387 		tlv = ptr;
3388 		tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
3389 			      FIELD_PREP(WMI_TLV_LEN, len);
3390 
3391 		ptr += TLV_HDR_SIZE;
3392 		len = sizeof(*band_to_mac);
3393 
3394 		for (idx = 0; idx < param->num_band_to_mac; idx++) {
3395 			band_to_mac = (void *)ptr;
3396 
3397 			band_to_mac->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3398 							     WMI_TAG_PDEV_BAND_TO_MAC) |
3399 						  FIELD_PREP(WMI_TLV_LEN,
3400 							     len - TLV_HDR_SIZE);
3401 			band_to_mac->pdev_id = param->band_to_mac[idx].pdev_id;
3402 			band_to_mac->start_freq =
3403 				param->band_to_mac[idx].start_freq;
3404 			band_to_mac->end_freq =
3405 				param->band_to_mac[idx].end_freq;
3406 			ptr += sizeof(*band_to_mac);
3407 		}
3408 	}
3409 
3410 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_INIT_CMDID);
3411 	if (ret) {
3412 		ath11k_warn(ab, "failed to send WMI_INIT_CMDID\n");
3413 		dev_kfree_skb(skb);
3414 	}
3415 
3416 	return ret;
3417 }
3418 
3419 int ath11k_wmi_pdev_lro_cfg(struct ath11k *ar,
3420 			    int pdev_id)
3421 {
3422 	struct ath11k_wmi_pdev_lro_config_cmd *cmd;
3423 	struct sk_buff *skb;
3424 	int ret;
3425 
3426 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
3427 	if (!skb)
3428 		return -ENOMEM;
3429 
3430 	cmd = (struct ath11k_wmi_pdev_lro_config_cmd *)skb->data;
3431 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_LRO_INFO_CMD) |
3432 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3433 
3434 	get_random_bytes(cmd->th_4, sizeof(uint32_t) * ATH11K_IPV4_TH_SEED_SIZE);
3435 	get_random_bytes(cmd->th_6, sizeof(uint32_t) * ATH11K_IPV6_TH_SEED_SIZE);
3436 
3437 	cmd->pdev_id = pdev_id;
3438 
3439 	ret = ath11k_wmi_cmd_send(ar->wmi, skb, WMI_LRO_CONFIG_CMDID);
3440 	if (ret) {
3441 		ath11k_warn(ar->ab,
3442 			    "failed to send lro cfg req wmi cmd\n");
3443 		goto err;
3444 	}
3445 
3446 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3447 		   "WMI lro cfg cmd pdev_id 0x%x\n", pdev_id);
3448 	return 0;
3449 err:
3450 	dev_kfree_skb(skb);
3451 	return ret;
3452 }
3453 
3454 int ath11k_wmi_wait_for_service_ready(struct ath11k_base *ab)
3455 {
3456 	unsigned long time_left;
3457 
3458 	time_left = wait_for_completion_timeout(&ab->wmi_ab.service_ready,
3459 						WMI_SERVICE_READY_TIMEOUT_HZ);
3460 	if (!time_left)
3461 		return -ETIMEDOUT;
3462 
3463 	return 0;
3464 }
3465 
3466 int ath11k_wmi_wait_for_unified_ready(struct ath11k_base *ab)
3467 {
3468 	unsigned long time_left;
3469 
3470 	time_left = wait_for_completion_timeout(&ab->wmi_ab.unified_ready,
3471 						WMI_SERVICE_READY_TIMEOUT_HZ);
3472 	if (!time_left)
3473 		return -ETIMEDOUT;
3474 
3475 	return 0;
3476 }
3477 
3478 int ath11k_wmi_cmd_init(struct ath11k_base *ab)
3479 {
3480 	struct ath11k_wmi_base *wmi_sc = &ab->wmi_ab;
3481 	struct wmi_init_cmd_param init_param;
3482 	struct target_resource_config  config;
3483 
3484 	memset(&init_param, 0, sizeof(init_param));
3485 	memset(&config, 0, sizeof(config));
3486 
3487 	ab->hw_params.hw_ops->wmi_init_config(ab, &config);
3488 
3489 	memcpy(&wmi_sc->wlan_resource_config, &config, sizeof(config));
3490 
3491 	init_param.res_cfg = &wmi_sc->wlan_resource_config;
3492 	init_param.num_mem_chunks = wmi_sc->num_mem_chunks;
3493 	init_param.hw_mode_id = wmi_sc->preferred_hw_mode;
3494 	init_param.mem_chunks = wmi_sc->mem_chunks;
3495 
3496 	if (ab->hw_params.needs_band_to_mac) {
3497 		init_param.num_band_to_mac = ab->num_radios;
3498 		ath11k_fill_band_to_mac_param(ab, init_param.band_to_mac);
3499 	}
3500 
3501 	return ath11k_init_cmd_send(&wmi_sc->wmi[0], &init_param);
3502 }
3503 
3504 int ath11k_wmi_vdev_spectral_conf(struct ath11k *ar,
3505 				  struct ath11k_wmi_vdev_spectral_conf_param *param)
3506 {
3507 	struct ath11k_wmi_vdev_spectral_conf_cmd *cmd;
3508 	struct sk_buff *skb;
3509 	int ret;
3510 
3511 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
3512 	if (!skb)
3513 		return -ENOMEM;
3514 
3515 	cmd = (struct ath11k_wmi_vdev_spectral_conf_cmd *)skb->data;
3516 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3517 				     WMI_TAG_VDEV_SPECTRAL_CONFIGURE_CMD) |
3518 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3519 
3520 	memcpy(&cmd->param, param, sizeof(*param));
3521 
3522 	ret = ath11k_wmi_cmd_send(ar->wmi, skb,
3523 				  WMI_VDEV_SPECTRAL_SCAN_CONFIGURE_CMDID);
3524 	if (ret) {
3525 		ath11k_warn(ar->ab,
3526 			    "failed to send spectral scan config wmi cmd\n");
3527 		goto err;
3528 	}
3529 
3530 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3531 		   "WMI spectral scan config cmd vdev_id 0x%x\n",
3532 		   param->vdev_id);
3533 
3534 	return 0;
3535 err:
3536 	dev_kfree_skb(skb);
3537 	return ret;
3538 }
3539 
3540 int ath11k_wmi_vdev_spectral_enable(struct ath11k *ar, u32 vdev_id,
3541 				    u32 trigger, u32 enable)
3542 {
3543 	struct ath11k_wmi_vdev_spectral_enable_cmd *cmd;
3544 	struct sk_buff *skb;
3545 	int ret;
3546 
3547 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
3548 	if (!skb)
3549 		return -ENOMEM;
3550 
3551 	cmd = (struct ath11k_wmi_vdev_spectral_enable_cmd *)skb->data;
3552 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
3553 				     WMI_TAG_VDEV_SPECTRAL_ENABLE_CMD) |
3554 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3555 
3556 	cmd->vdev_id = vdev_id;
3557 	cmd->trigger_cmd = trigger;
3558 	cmd->enable_cmd = enable;
3559 
3560 	ret = ath11k_wmi_cmd_send(ar->wmi, skb,
3561 				  WMI_VDEV_SPECTRAL_SCAN_ENABLE_CMDID);
3562 	if (ret) {
3563 		ath11k_warn(ar->ab,
3564 			    "failed to send spectral enable wmi cmd\n");
3565 		goto err;
3566 	}
3567 
3568 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3569 		   "WMI spectral enable cmd vdev id 0x%x\n",
3570 		   vdev_id);
3571 
3572 	return 0;
3573 err:
3574 	dev_kfree_skb(skb);
3575 	return ret;
3576 }
3577 
3578 int ath11k_wmi_pdev_dma_ring_cfg(struct ath11k *ar,
3579 				 struct ath11k_wmi_pdev_dma_ring_cfg_req_cmd *param)
3580 {
3581 	struct ath11k_wmi_pdev_dma_ring_cfg_req_cmd *cmd;
3582 	struct sk_buff *skb;
3583 	int ret;
3584 
3585 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_ab, sizeof(*cmd));
3586 	if (!skb)
3587 		return -ENOMEM;
3588 
3589 	cmd = (struct ath11k_wmi_pdev_dma_ring_cfg_req_cmd *)skb->data;
3590 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_DMA_RING_CFG_REQ) |
3591 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
3592 
3593 	cmd->pdev_id		= param->pdev_id;
3594 	cmd->module_id		= param->module_id;
3595 	cmd->base_paddr_lo	= param->base_paddr_lo;
3596 	cmd->base_paddr_hi	= param->base_paddr_hi;
3597 	cmd->head_idx_paddr_lo	= param->head_idx_paddr_lo;
3598 	cmd->head_idx_paddr_hi	= param->head_idx_paddr_hi;
3599 	cmd->tail_idx_paddr_lo	= param->tail_idx_paddr_lo;
3600 	cmd->tail_idx_paddr_hi	= param->tail_idx_paddr_hi;
3601 	cmd->num_elems		= param->num_elems;
3602 	cmd->buf_size		= param->buf_size;
3603 	cmd->num_resp_per_event	= param->num_resp_per_event;
3604 	cmd->event_timeout_ms	= param->event_timeout_ms;
3605 
3606 	ret = ath11k_wmi_cmd_send(ar->wmi, skb,
3607 				  WMI_PDEV_DMA_RING_CFG_REQ_CMDID);
3608 	if (ret) {
3609 		ath11k_warn(ar->ab,
3610 			    "failed to send dma ring cfg req wmi cmd\n");
3611 		goto err;
3612 	}
3613 
3614 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
3615 		   "WMI DMA ring cfg req cmd pdev_id 0x%x\n",
3616 		   param->pdev_id);
3617 
3618 	return 0;
3619 err:
3620 	dev_kfree_skb(skb);
3621 	return ret;
3622 }
3623 
3624 static int ath11k_wmi_tlv_dma_buf_entry_parse(struct ath11k_base *soc,
3625 					      u16 tag, u16 len,
3626 					      const void *ptr, void *data)
3627 {
3628 	struct wmi_tlv_dma_buf_release_parse *parse = data;
3629 
3630 	if (tag != WMI_TAG_DMA_BUF_RELEASE_ENTRY)
3631 		return -EPROTO;
3632 
3633 	if (parse->num_buf_entry >= parse->fixed.num_buf_release_entry)
3634 		return -ENOBUFS;
3635 
3636 	parse->num_buf_entry++;
3637 	return 0;
3638 }
3639 
3640 static int ath11k_wmi_tlv_dma_buf_meta_parse(struct ath11k_base *soc,
3641 					     u16 tag, u16 len,
3642 					     const void *ptr, void *data)
3643 {
3644 	struct wmi_tlv_dma_buf_release_parse *parse = data;
3645 
3646 	if (tag != WMI_TAG_DMA_BUF_RELEASE_SPECTRAL_META_DATA)
3647 		return -EPROTO;
3648 
3649 	if (parse->num_meta >= parse->fixed.num_meta_data_entry)
3650 		return -ENOBUFS;
3651 
3652 	parse->num_meta++;
3653 	return 0;
3654 }
3655 
3656 static int ath11k_wmi_tlv_dma_buf_parse(struct ath11k_base *ab,
3657 					u16 tag, u16 len,
3658 					const void *ptr, void *data)
3659 {
3660 	struct wmi_tlv_dma_buf_release_parse *parse = data;
3661 	int ret;
3662 
3663 	switch (tag) {
3664 	case WMI_TAG_DMA_BUF_RELEASE:
3665 		memcpy(&parse->fixed, ptr,
3666 		       sizeof(struct ath11k_wmi_dma_buf_release_fixed_param));
3667 		parse->fixed.pdev_id = DP_HW2SW_MACID(parse->fixed.pdev_id);
3668 		break;
3669 	case WMI_TAG_ARRAY_STRUCT:
3670 		if (!parse->buf_entry_done) {
3671 			parse->num_buf_entry = 0;
3672 			parse->buf_entry = (struct wmi_dma_buf_release_entry *)ptr;
3673 
3674 			ret = ath11k_wmi_tlv_iter(ab, ptr, len,
3675 						  ath11k_wmi_tlv_dma_buf_entry_parse,
3676 						  parse);
3677 			if (ret) {
3678 				ath11k_warn(ab, "failed to parse dma buf entry tlv %d\n",
3679 					    ret);
3680 				return ret;
3681 			}
3682 
3683 			parse->buf_entry_done = true;
3684 		} else if (!parse->meta_data_done) {
3685 			parse->num_meta = 0;
3686 			parse->meta_data = (struct wmi_dma_buf_release_meta_data *)ptr;
3687 
3688 			ret = ath11k_wmi_tlv_iter(ab, ptr, len,
3689 						  ath11k_wmi_tlv_dma_buf_meta_parse,
3690 						  parse);
3691 			if (ret) {
3692 				ath11k_warn(ab, "failed to parse dma buf meta tlv %d\n",
3693 					    ret);
3694 				return ret;
3695 			}
3696 
3697 			parse->meta_data_done = true;
3698 		}
3699 		break;
3700 	default:
3701 		break;
3702 	}
3703 	return 0;
3704 }
3705 
3706 static void ath11k_wmi_pdev_dma_ring_buf_release_event(struct ath11k_base *ab,
3707 						       struct sk_buff *skb)
3708 {
3709 	struct wmi_tlv_dma_buf_release_parse parse = { };
3710 	struct ath11k_dbring_buf_release_event param;
3711 	int ret;
3712 
3713 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
3714 				  ath11k_wmi_tlv_dma_buf_parse,
3715 				  &parse);
3716 	if (ret) {
3717 		ath11k_warn(ab, "failed to parse dma buf release tlv %d\n", ret);
3718 		return;
3719 	}
3720 
3721 	param.fixed		= parse.fixed;
3722 	param.buf_entry		= parse.buf_entry;
3723 	param.num_buf_entry	= parse.num_buf_entry;
3724 	param.meta_data		= parse.meta_data;
3725 	param.num_meta		= parse.num_meta;
3726 
3727 	ret = ath11k_dbring_buffer_release_event(ab, &param);
3728 	if (ret) {
3729 		ath11k_warn(ab, "failed to handle dma buf release event %d\n", ret);
3730 		return;
3731 	}
3732 }
3733 
3734 static int ath11k_wmi_tlv_hw_mode_caps_parse(struct ath11k_base *soc,
3735 					     u16 tag, u16 len,
3736 					     const void *ptr, void *data)
3737 {
3738 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3739 	struct wmi_hw_mode_capabilities *hw_mode_cap;
3740 	u32 phy_map = 0;
3741 
3742 	if (tag != WMI_TAG_HW_MODE_CAPABILITIES)
3743 		return -EPROTO;
3744 
3745 	if (svc_rdy_ext->n_hw_mode_caps >= svc_rdy_ext->param.num_hw_modes)
3746 		return -ENOBUFS;
3747 
3748 	hw_mode_cap = container_of(ptr, struct wmi_hw_mode_capabilities,
3749 				   hw_mode_id);
3750 	svc_rdy_ext->n_hw_mode_caps++;
3751 
3752 	phy_map = hw_mode_cap->phy_id_map;
3753 	while (phy_map) {
3754 		svc_rdy_ext->tot_phy_id++;
3755 		phy_map = phy_map >> 1;
3756 	}
3757 
3758 	return 0;
3759 }
3760 
3761 static int ath11k_wmi_tlv_hw_mode_caps(struct ath11k_base *soc,
3762 				       u16 len, const void *ptr, void *data)
3763 {
3764 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3765 	struct wmi_hw_mode_capabilities *hw_mode_caps;
3766 	enum wmi_host_hw_mode_config_type mode, pref;
3767 	u32 i;
3768 	int ret;
3769 
3770 	svc_rdy_ext->n_hw_mode_caps = 0;
3771 	svc_rdy_ext->hw_mode_caps = (struct wmi_hw_mode_capabilities *)ptr;
3772 
3773 	ret = ath11k_wmi_tlv_iter(soc, ptr, len,
3774 				  ath11k_wmi_tlv_hw_mode_caps_parse,
3775 				  svc_rdy_ext);
3776 	if (ret) {
3777 		ath11k_warn(soc, "failed to parse tlv %d\n", ret);
3778 		return ret;
3779 	}
3780 
3781 	i = 0;
3782 	while (i < svc_rdy_ext->n_hw_mode_caps) {
3783 		hw_mode_caps = &svc_rdy_ext->hw_mode_caps[i];
3784 		mode = hw_mode_caps->hw_mode_id;
3785 		pref = soc->wmi_ab.preferred_hw_mode;
3786 
3787 		if (ath11k_hw_mode_pri_map[mode] < ath11k_hw_mode_pri_map[pref]) {
3788 			svc_rdy_ext->pref_hw_mode_caps = *hw_mode_caps;
3789 			soc->wmi_ab.preferred_hw_mode = mode;
3790 		}
3791 		i++;
3792 	}
3793 
3794 	ath11k_dbg(soc, ATH11K_DBG_WMI, "preferred_hw_mode:%d\n",
3795 		   soc->wmi_ab.preferred_hw_mode);
3796 	if (soc->wmi_ab.preferred_hw_mode == WMI_HOST_HW_MODE_MAX)
3797 		return -EINVAL;
3798 
3799 	return 0;
3800 }
3801 
3802 static int ath11k_wmi_tlv_mac_phy_caps_parse(struct ath11k_base *soc,
3803 					     u16 tag, u16 len,
3804 					     const void *ptr, void *data)
3805 {
3806 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3807 
3808 	if (tag != WMI_TAG_MAC_PHY_CAPABILITIES)
3809 		return -EPROTO;
3810 
3811 	if (svc_rdy_ext->n_mac_phy_caps >= svc_rdy_ext->tot_phy_id)
3812 		return -ENOBUFS;
3813 
3814 	len = min_t(u16, len, sizeof(struct wmi_mac_phy_capabilities));
3815 	if (!svc_rdy_ext->n_mac_phy_caps) {
3816 		svc_rdy_ext->mac_phy_caps = kzalloc((svc_rdy_ext->tot_phy_id) * len,
3817 						    GFP_ATOMIC);
3818 		if (!svc_rdy_ext->mac_phy_caps)
3819 			return -ENOMEM;
3820 	}
3821 
3822 	memcpy(svc_rdy_ext->mac_phy_caps + svc_rdy_ext->n_mac_phy_caps, ptr, len);
3823 	svc_rdy_ext->n_mac_phy_caps++;
3824 	return 0;
3825 }
3826 
3827 static int ath11k_wmi_tlv_ext_hal_reg_caps_parse(struct ath11k_base *soc,
3828 						 u16 tag, u16 len,
3829 						 const void *ptr, void *data)
3830 {
3831 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3832 
3833 	if (tag != WMI_TAG_HAL_REG_CAPABILITIES_EXT)
3834 		return -EPROTO;
3835 
3836 	if (svc_rdy_ext->n_ext_hal_reg_caps >= svc_rdy_ext->param.num_phy)
3837 		return -ENOBUFS;
3838 
3839 	svc_rdy_ext->n_ext_hal_reg_caps++;
3840 	return 0;
3841 }
3842 
3843 static int ath11k_wmi_tlv_ext_hal_reg_caps(struct ath11k_base *soc,
3844 					   u16 len, const void *ptr, void *data)
3845 {
3846 	struct ath11k_pdev_wmi *wmi_handle = &soc->wmi_ab.wmi[0];
3847 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3848 	struct ath11k_hal_reg_capabilities_ext reg_cap;
3849 	int ret;
3850 	u32 i;
3851 
3852 	svc_rdy_ext->n_ext_hal_reg_caps = 0;
3853 	svc_rdy_ext->ext_hal_reg_caps = (struct wmi_hal_reg_capabilities_ext *)ptr;
3854 	ret = ath11k_wmi_tlv_iter(soc, ptr, len,
3855 				  ath11k_wmi_tlv_ext_hal_reg_caps_parse,
3856 				  svc_rdy_ext);
3857 	if (ret) {
3858 		ath11k_warn(soc, "failed to parse tlv %d\n", ret);
3859 		return ret;
3860 	}
3861 
3862 	for (i = 0; i < svc_rdy_ext->param.num_phy; i++) {
3863 		ret = ath11k_pull_reg_cap_svc_rdy_ext(wmi_handle,
3864 						      svc_rdy_ext->soc_hal_reg_caps,
3865 						      svc_rdy_ext->ext_hal_reg_caps, i,
3866 						      &reg_cap);
3867 		if (ret) {
3868 			ath11k_warn(soc, "failed to extract reg cap %d\n", i);
3869 			return ret;
3870 		}
3871 
3872 		memcpy(&soc->hal_reg_cap[reg_cap.phy_id],
3873 		       &reg_cap, sizeof(reg_cap));
3874 	}
3875 	return 0;
3876 }
3877 
3878 static int ath11k_wmi_tlv_ext_soc_hal_reg_caps_parse(struct ath11k_base *soc,
3879 						     u16 len, const void *ptr,
3880 						     void *data)
3881 {
3882 	struct ath11k_pdev_wmi *wmi_handle = &soc->wmi_ab.wmi[0];
3883 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3884 	u8 hw_mode_id = svc_rdy_ext->pref_hw_mode_caps.hw_mode_id;
3885 	u32 phy_id_map;
3886 	int pdev_index = 0;
3887 	int ret;
3888 
3889 	svc_rdy_ext->soc_hal_reg_caps = (struct wmi_soc_hal_reg_capabilities *)ptr;
3890 	svc_rdy_ext->param.num_phy = svc_rdy_ext->soc_hal_reg_caps->num_phy;
3891 
3892 	soc->num_radios = 0;
3893 	phy_id_map = svc_rdy_ext->pref_hw_mode_caps.phy_id_map;
3894 
3895 	while (phy_id_map && soc->num_radios < MAX_RADIOS) {
3896 		ret = ath11k_pull_mac_phy_cap_svc_ready_ext(wmi_handle,
3897 							    svc_rdy_ext->hw_caps,
3898 							    svc_rdy_ext->hw_mode_caps,
3899 							    svc_rdy_ext->soc_hal_reg_caps,
3900 							    svc_rdy_ext->mac_phy_caps,
3901 							    hw_mode_id, soc->num_radios,
3902 							    &soc->pdevs[pdev_index]);
3903 		if (ret) {
3904 			ath11k_warn(soc, "failed to extract mac caps, idx :%d\n",
3905 				    soc->num_radios);
3906 			return ret;
3907 		}
3908 
3909 		soc->num_radios++;
3910 
3911 		/* For QCA6390, save mac_phy capability in the same pdev */
3912 		if (soc->hw_params.single_pdev_only)
3913 			pdev_index = 0;
3914 		else
3915 			pdev_index = soc->num_radios;
3916 
3917 		/* TODO: mac_phy_cap prints */
3918 		phy_id_map >>= 1;
3919 	}
3920 
3921 	/* For QCA6390, set num_radios to 1 because host manages
3922 	 * both 2G and 5G radio in one pdev.
3923 	 * Set pdev_id = 0 and 0 means soc level.
3924 	 */
3925 	if (soc->hw_params.single_pdev_only) {
3926 		soc->num_radios = 1;
3927 		soc->pdevs[0].pdev_id = 0;
3928 	}
3929 
3930 	return 0;
3931 }
3932 
3933 static int ath11k_wmi_tlv_dma_ring_caps_parse(struct ath11k_base *soc,
3934 					      u16 tag, u16 len,
3935 					      const void *ptr, void *data)
3936 {
3937 	struct wmi_tlv_dma_ring_caps_parse *parse = data;
3938 
3939 	if (tag != WMI_TAG_DMA_RING_CAPABILITIES)
3940 		return -EPROTO;
3941 
3942 	parse->n_dma_ring_caps++;
3943 	return 0;
3944 }
3945 
3946 static int ath11k_wmi_alloc_dbring_caps(struct ath11k_base *ab,
3947 					u32 num_cap)
3948 {
3949 	size_t sz;
3950 	void *ptr;
3951 
3952 	sz = num_cap * sizeof(struct ath11k_dbring_cap);
3953 	ptr = kzalloc(sz, GFP_ATOMIC);
3954 	if (!ptr)
3955 		return -ENOMEM;
3956 
3957 	ab->db_caps = ptr;
3958 	ab->num_db_cap = num_cap;
3959 
3960 	return 0;
3961 }
3962 
3963 static void ath11k_wmi_free_dbring_caps(struct ath11k_base *ab)
3964 {
3965 	kfree(ab->db_caps);
3966 	ab->db_caps = NULL;
3967 }
3968 
3969 static int ath11k_wmi_tlv_dma_ring_caps(struct ath11k_base *ab,
3970 					u16 len, const void *ptr, void *data)
3971 {
3972 	struct wmi_tlv_dma_ring_caps_parse *dma_caps_parse = data;
3973 	struct wmi_dma_ring_capabilities *dma_caps;
3974 	struct ath11k_dbring_cap *dir_buff_caps;
3975 	int ret;
3976 	u32 i;
3977 
3978 	dma_caps_parse->n_dma_ring_caps = 0;
3979 	dma_caps = (struct wmi_dma_ring_capabilities *)ptr;
3980 	ret = ath11k_wmi_tlv_iter(ab, ptr, len,
3981 				  ath11k_wmi_tlv_dma_ring_caps_parse,
3982 				  dma_caps_parse);
3983 	if (ret) {
3984 		ath11k_warn(ab, "failed to parse dma ring caps tlv %d\n", ret);
3985 		return ret;
3986 	}
3987 
3988 	if (!dma_caps_parse->n_dma_ring_caps)
3989 		return 0;
3990 
3991 	if (ab->num_db_cap) {
3992 		ath11k_warn(ab, "Already processed, so ignoring dma ring caps\n");
3993 		return 0;
3994 	}
3995 
3996 	ret = ath11k_wmi_alloc_dbring_caps(ab, dma_caps_parse->n_dma_ring_caps);
3997 	if (ret)
3998 		return ret;
3999 
4000 	dir_buff_caps = ab->db_caps;
4001 	for (i = 0; i < dma_caps_parse->n_dma_ring_caps; i++) {
4002 		if (dma_caps[i].module_id >= WMI_DIRECT_BUF_MAX) {
4003 			ath11k_warn(ab, "Invalid module id %d\n", dma_caps[i].module_id);
4004 			ret = -EINVAL;
4005 			goto free_dir_buff;
4006 		}
4007 
4008 		dir_buff_caps[i].id = dma_caps[i].module_id;
4009 		dir_buff_caps[i].pdev_id = DP_HW2SW_MACID(dma_caps[i].pdev_id);
4010 		dir_buff_caps[i].min_elem = dma_caps[i].min_elem;
4011 		dir_buff_caps[i].min_buf_sz = dma_caps[i].min_buf_sz;
4012 		dir_buff_caps[i].min_buf_align = dma_caps[i].min_buf_align;
4013 	}
4014 
4015 	return 0;
4016 
4017 free_dir_buff:
4018 	ath11k_wmi_free_dbring_caps(ab);
4019 	return ret;
4020 }
4021 
4022 static int ath11k_wmi_tlv_svc_rdy_ext_parse(struct ath11k_base *ab,
4023 					    u16 tag, u16 len,
4024 					    const void *ptr, void *data)
4025 {
4026 	struct ath11k_pdev_wmi *wmi_handle = &ab->wmi_ab.wmi[0];
4027 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
4028 	int ret;
4029 
4030 	switch (tag) {
4031 	case WMI_TAG_SERVICE_READY_EXT_EVENT:
4032 		ret = ath11k_pull_svc_ready_ext(wmi_handle, ptr,
4033 						&svc_rdy_ext->param);
4034 		if (ret) {
4035 			ath11k_warn(ab, "unable to extract ext params\n");
4036 			return ret;
4037 		}
4038 		break;
4039 
4040 	case WMI_TAG_SOC_MAC_PHY_HW_MODE_CAPS:
4041 		svc_rdy_ext->hw_caps = (struct wmi_soc_mac_phy_hw_mode_caps *)ptr;
4042 		svc_rdy_ext->param.num_hw_modes = svc_rdy_ext->hw_caps->num_hw_modes;
4043 		break;
4044 
4045 	case WMI_TAG_SOC_HAL_REG_CAPABILITIES:
4046 		ret = ath11k_wmi_tlv_ext_soc_hal_reg_caps_parse(ab, len, ptr,
4047 								svc_rdy_ext);
4048 		if (ret)
4049 			return ret;
4050 		break;
4051 
4052 	case WMI_TAG_ARRAY_STRUCT:
4053 		if (!svc_rdy_ext->hw_mode_done) {
4054 			ret = ath11k_wmi_tlv_hw_mode_caps(ab, len, ptr,
4055 							  svc_rdy_ext);
4056 			if (ret)
4057 				return ret;
4058 
4059 			svc_rdy_ext->hw_mode_done = true;
4060 		} else if (!svc_rdy_ext->mac_phy_done) {
4061 			svc_rdy_ext->n_mac_phy_caps = 0;
4062 			ret = ath11k_wmi_tlv_iter(ab, ptr, len,
4063 						  ath11k_wmi_tlv_mac_phy_caps_parse,
4064 						  svc_rdy_ext);
4065 			if (ret) {
4066 				ath11k_warn(ab, "failed to parse tlv %d\n", ret);
4067 				return ret;
4068 			}
4069 
4070 			svc_rdy_ext->mac_phy_done = true;
4071 		} else if (!svc_rdy_ext->ext_hal_reg_done) {
4072 			ret = ath11k_wmi_tlv_ext_hal_reg_caps(ab, len, ptr,
4073 							      svc_rdy_ext);
4074 			if (ret)
4075 				return ret;
4076 
4077 			svc_rdy_ext->ext_hal_reg_done = true;
4078 		} else if (!svc_rdy_ext->mac_phy_chainmask_combo_done) {
4079 			svc_rdy_ext->mac_phy_chainmask_combo_done = true;
4080 		} else if (!svc_rdy_ext->mac_phy_chainmask_cap_done) {
4081 			svc_rdy_ext->mac_phy_chainmask_cap_done = true;
4082 		} else if (!svc_rdy_ext->oem_dma_ring_cap_done) {
4083 			svc_rdy_ext->oem_dma_ring_cap_done = true;
4084 		} else if (!svc_rdy_ext->dma_ring_cap_done) {
4085 			ret = ath11k_wmi_tlv_dma_ring_caps(ab, len, ptr,
4086 							   &svc_rdy_ext->dma_caps_parse);
4087 			if (ret)
4088 				return ret;
4089 
4090 			svc_rdy_ext->dma_ring_cap_done = true;
4091 		}
4092 		break;
4093 
4094 	default:
4095 		break;
4096 	}
4097 	return 0;
4098 }
4099 
4100 static int ath11k_service_ready_ext_event(struct ath11k_base *ab,
4101 					  struct sk_buff *skb)
4102 {
4103 	struct wmi_tlv_svc_rdy_ext_parse svc_rdy_ext = { };
4104 	int ret;
4105 
4106 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
4107 				  ath11k_wmi_tlv_svc_rdy_ext_parse,
4108 				  &svc_rdy_ext);
4109 	if (ret) {
4110 		ath11k_warn(ab, "failed to parse tlv %d\n", ret);
4111 		goto err;
4112 	}
4113 
4114 	if (!test_bit(WMI_TLV_SERVICE_EXT2_MSG, ab->wmi_ab.svc_map))
4115 		complete(&ab->wmi_ab.service_ready);
4116 
4117 	kfree(svc_rdy_ext.mac_phy_caps);
4118 	return 0;
4119 
4120 err:
4121 	ath11k_wmi_free_dbring_caps(ab);
4122 	return ret;
4123 }
4124 
4125 static int ath11k_wmi_tlv_svc_rdy_ext2_parse(struct ath11k_base *ab,
4126 					     u16 tag, u16 len,
4127 					     const void *ptr, void *data)
4128 {
4129 	struct wmi_tlv_svc_rdy_ext2_parse *parse = data;
4130 	int ret;
4131 
4132 	switch (tag) {
4133 	case WMI_TAG_ARRAY_STRUCT:
4134 		if (!parse->dma_ring_cap_done) {
4135 			ret = ath11k_wmi_tlv_dma_ring_caps(ab, len, ptr,
4136 							   &parse->dma_caps_parse);
4137 			if (ret)
4138 				return ret;
4139 
4140 			parse->dma_ring_cap_done = true;
4141 		}
4142 		break;
4143 	default:
4144 		break;
4145 	}
4146 
4147 	return 0;
4148 }
4149 
4150 static int ath11k_service_ready_ext2_event(struct ath11k_base *ab,
4151 					   struct sk_buff *skb)
4152 {
4153 	struct wmi_tlv_svc_rdy_ext2_parse svc_rdy_ext2 = { };
4154 	int ret;
4155 
4156 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
4157 				  ath11k_wmi_tlv_svc_rdy_ext2_parse,
4158 				  &svc_rdy_ext2);
4159 	if (ret) {
4160 		ath11k_warn(ab, "failed to parse ext2 event tlv %d\n", ret);
4161 		goto err;
4162 	}
4163 
4164 	complete(&ab->wmi_ab.service_ready);
4165 
4166 	return 0;
4167 
4168 err:
4169 	ath11k_wmi_free_dbring_caps(ab);
4170 	return ret;
4171 }
4172 
4173 static int ath11k_pull_vdev_start_resp_tlv(struct ath11k_base *ab, struct sk_buff *skb,
4174 					   struct wmi_vdev_start_resp_event *vdev_rsp)
4175 {
4176 	const void **tb;
4177 	const struct wmi_vdev_start_resp_event *ev;
4178 	int ret;
4179 
4180 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4181 	if (IS_ERR(tb)) {
4182 		ret = PTR_ERR(tb);
4183 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4184 		return ret;
4185 	}
4186 
4187 	ev = tb[WMI_TAG_VDEV_START_RESPONSE_EVENT];
4188 	if (!ev) {
4189 		ath11k_warn(ab, "failed to fetch vdev start resp ev");
4190 		kfree(tb);
4191 		return -EPROTO;
4192 	}
4193 
4194 	memset(vdev_rsp, 0, sizeof(*vdev_rsp));
4195 
4196 	vdev_rsp->vdev_id = ev->vdev_id;
4197 	vdev_rsp->requestor_id = ev->requestor_id;
4198 	vdev_rsp->resp_type = ev->resp_type;
4199 	vdev_rsp->status = ev->status;
4200 	vdev_rsp->chain_mask = ev->chain_mask;
4201 	vdev_rsp->smps_mode = ev->smps_mode;
4202 	vdev_rsp->mac_id = ev->mac_id;
4203 	vdev_rsp->cfgd_tx_streams = ev->cfgd_tx_streams;
4204 	vdev_rsp->cfgd_rx_streams = ev->cfgd_rx_streams;
4205 
4206 	kfree(tb);
4207 	return 0;
4208 }
4209 
4210 static struct cur_reg_rule
4211 *create_reg_rules_from_wmi(u32 num_reg_rules,
4212 			   struct wmi_regulatory_rule_struct *wmi_reg_rule)
4213 {
4214 	struct cur_reg_rule *reg_rule_ptr;
4215 	u32 count;
4216 
4217 	reg_rule_ptr =  kzalloc((num_reg_rules * sizeof(*reg_rule_ptr)),
4218 				GFP_ATOMIC);
4219 
4220 	if (!reg_rule_ptr)
4221 		return NULL;
4222 
4223 	for (count = 0; count < num_reg_rules; count++) {
4224 		reg_rule_ptr[count].start_freq =
4225 			FIELD_GET(REG_RULE_START_FREQ,
4226 				  wmi_reg_rule[count].freq_info);
4227 		reg_rule_ptr[count].end_freq =
4228 			FIELD_GET(REG_RULE_END_FREQ,
4229 				  wmi_reg_rule[count].freq_info);
4230 		reg_rule_ptr[count].max_bw =
4231 			FIELD_GET(REG_RULE_MAX_BW,
4232 				  wmi_reg_rule[count].bw_pwr_info);
4233 		reg_rule_ptr[count].reg_power =
4234 			FIELD_GET(REG_RULE_REG_PWR,
4235 				  wmi_reg_rule[count].bw_pwr_info);
4236 		reg_rule_ptr[count].ant_gain =
4237 			FIELD_GET(REG_RULE_ANT_GAIN,
4238 				  wmi_reg_rule[count].bw_pwr_info);
4239 		reg_rule_ptr[count].flags =
4240 			FIELD_GET(REG_RULE_FLAGS,
4241 				  wmi_reg_rule[count].flag_info);
4242 	}
4243 
4244 	return reg_rule_ptr;
4245 }
4246 
4247 static int ath11k_pull_reg_chan_list_update_ev(struct ath11k_base *ab,
4248 					       struct sk_buff *skb,
4249 					       struct cur_regulatory_info *reg_info)
4250 {
4251 	const void **tb;
4252 	const struct wmi_reg_chan_list_cc_event *chan_list_event_hdr;
4253 	struct wmi_regulatory_rule_struct *wmi_reg_rule;
4254 	u32 num_2g_reg_rules, num_5g_reg_rules;
4255 	int ret;
4256 
4257 	ath11k_dbg(ab, ATH11K_DBG_WMI, "processing regulatory channel list\n");
4258 
4259 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4260 	if (IS_ERR(tb)) {
4261 		ret = PTR_ERR(tb);
4262 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4263 		return ret;
4264 	}
4265 
4266 	chan_list_event_hdr = tb[WMI_TAG_REG_CHAN_LIST_CC_EVENT];
4267 	if (!chan_list_event_hdr) {
4268 		ath11k_warn(ab, "failed to fetch reg chan list update ev\n");
4269 		kfree(tb);
4270 		return -EPROTO;
4271 	}
4272 
4273 	reg_info->num_2g_reg_rules = chan_list_event_hdr->num_2g_reg_rules;
4274 	reg_info->num_5g_reg_rules = chan_list_event_hdr->num_5g_reg_rules;
4275 
4276 	if (!(reg_info->num_2g_reg_rules + reg_info->num_5g_reg_rules)) {
4277 		ath11k_warn(ab, "No regulatory rules available in the event info\n");
4278 		kfree(tb);
4279 		return -EINVAL;
4280 	}
4281 
4282 	memcpy(reg_info->alpha2, &chan_list_event_hdr->alpha2,
4283 	       REG_ALPHA2_LEN);
4284 	reg_info->dfs_region = chan_list_event_hdr->dfs_region;
4285 	reg_info->phybitmap = chan_list_event_hdr->phybitmap;
4286 	reg_info->num_phy = chan_list_event_hdr->num_phy;
4287 	reg_info->phy_id = chan_list_event_hdr->phy_id;
4288 	reg_info->ctry_code = chan_list_event_hdr->country_id;
4289 	reg_info->reg_dmn_pair = chan_list_event_hdr->domain_code;
4290 	if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_STATUS_PASS)
4291 		reg_info->status_code = REG_SET_CC_STATUS_PASS;
4292 	else if (chan_list_event_hdr->status_code == WMI_REG_CURRENT_ALPHA2_NOT_FOUND)
4293 		reg_info->status_code = REG_CURRENT_ALPHA2_NOT_FOUND;
4294 	else if (chan_list_event_hdr->status_code == WMI_REG_INIT_ALPHA2_NOT_FOUND)
4295 		reg_info->status_code = REG_INIT_ALPHA2_NOT_FOUND;
4296 	else if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_CHANGE_NOT_ALLOWED)
4297 		reg_info->status_code = REG_SET_CC_CHANGE_NOT_ALLOWED;
4298 	else if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_STATUS_NO_MEMORY)
4299 		reg_info->status_code = REG_SET_CC_STATUS_NO_MEMORY;
4300 	else if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_STATUS_FAIL)
4301 		reg_info->status_code = REG_SET_CC_STATUS_FAIL;
4302 
4303 	reg_info->min_bw_2g = chan_list_event_hdr->min_bw_2g;
4304 	reg_info->max_bw_2g = chan_list_event_hdr->max_bw_2g;
4305 	reg_info->min_bw_5g = chan_list_event_hdr->min_bw_5g;
4306 	reg_info->max_bw_5g = chan_list_event_hdr->max_bw_5g;
4307 
4308 	num_2g_reg_rules = reg_info->num_2g_reg_rules;
4309 	num_5g_reg_rules = reg_info->num_5g_reg_rules;
4310 
4311 	ath11k_dbg(ab, ATH11K_DBG_WMI,
4312 		   "%s:cc %s dsf %d BW: min_2g %d max_2g %d min_5g %d max_5g %d",
4313 		   __func__, reg_info->alpha2, reg_info->dfs_region,
4314 		   reg_info->min_bw_2g, reg_info->max_bw_2g,
4315 		   reg_info->min_bw_5g, reg_info->max_bw_5g);
4316 
4317 	ath11k_dbg(ab, ATH11K_DBG_WMI,
4318 		   "%s: num_2g_reg_rules %d num_5g_reg_rules %d", __func__,
4319 		   num_2g_reg_rules, num_5g_reg_rules);
4320 
4321 	wmi_reg_rule =
4322 		(struct wmi_regulatory_rule_struct *)((u8 *)chan_list_event_hdr
4323 						+ sizeof(*chan_list_event_hdr)
4324 						+ sizeof(struct wmi_tlv));
4325 
4326 	if (num_2g_reg_rules) {
4327 		reg_info->reg_rules_2g_ptr = create_reg_rules_from_wmi(num_2g_reg_rules,
4328 								       wmi_reg_rule);
4329 		if (!reg_info->reg_rules_2g_ptr) {
4330 			kfree(tb);
4331 			ath11k_warn(ab, "Unable to Allocate memory for 2g rules\n");
4332 			return -ENOMEM;
4333 		}
4334 	}
4335 
4336 	if (num_5g_reg_rules) {
4337 		wmi_reg_rule += num_2g_reg_rules;
4338 		reg_info->reg_rules_5g_ptr = create_reg_rules_from_wmi(num_5g_reg_rules,
4339 								       wmi_reg_rule);
4340 		if (!reg_info->reg_rules_5g_ptr) {
4341 			kfree(tb);
4342 			ath11k_warn(ab, "Unable to Allocate memory for 5g rules\n");
4343 			return -ENOMEM;
4344 		}
4345 	}
4346 
4347 	ath11k_dbg(ab, ATH11K_DBG_WMI, "processed regulatory channel list\n");
4348 
4349 	kfree(tb);
4350 	return 0;
4351 }
4352 
4353 static int ath11k_pull_peer_del_resp_ev(struct ath11k_base *ab, struct sk_buff *skb,
4354 					struct wmi_peer_delete_resp_event *peer_del_resp)
4355 {
4356 	const void **tb;
4357 	const struct wmi_peer_delete_resp_event *ev;
4358 	int ret;
4359 
4360 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4361 	if (IS_ERR(tb)) {
4362 		ret = PTR_ERR(tb);
4363 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4364 		return ret;
4365 	}
4366 
4367 	ev = tb[WMI_TAG_PEER_DELETE_RESP_EVENT];
4368 	if (!ev) {
4369 		ath11k_warn(ab, "failed to fetch peer delete resp ev");
4370 		kfree(tb);
4371 		return -EPROTO;
4372 	}
4373 
4374 	memset(peer_del_resp, 0, sizeof(*peer_del_resp));
4375 
4376 	peer_del_resp->vdev_id = ev->vdev_id;
4377 	ether_addr_copy(peer_del_resp->peer_macaddr.addr,
4378 			ev->peer_macaddr.addr);
4379 
4380 	kfree(tb);
4381 	return 0;
4382 }
4383 
4384 static int ath11k_pull_vdev_del_resp_ev(struct ath11k_base *ab,
4385 					struct sk_buff *skb,
4386 					u32 *vdev_id)
4387 {
4388 	const void **tb;
4389 	const struct wmi_vdev_delete_resp_event *ev;
4390 	int ret;
4391 
4392 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4393 	if (IS_ERR(tb)) {
4394 		ret = PTR_ERR(tb);
4395 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4396 		return ret;
4397 	}
4398 
4399 	ev = tb[WMI_TAG_VDEV_DELETE_RESP_EVENT];
4400 	if (!ev) {
4401 		ath11k_warn(ab, "failed to fetch vdev delete resp ev");
4402 		kfree(tb);
4403 		return -EPROTO;
4404 	}
4405 
4406 	*vdev_id = ev->vdev_id;
4407 
4408 	kfree(tb);
4409 	return 0;
4410 }
4411 
4412 static int ath11k_pull_bcn_tx_status_ev(struct ath11k_base *ab, void *evt_buf,
4413 					u32 len, u32 *vdev_id,
4414 					u32 *tx_status)
4415 {
4416 	const void **tb;
4417 	const struct wmi_bcn_tx_status_event *ev;
4418 	int ret;
4419 
4420 	tb = ath11k_wmi_tlv_parse_alloc(ab, evt_buf, len, GFP_ATOMIC);
4421 	if (IS_ERR(tb)) {
4422 		ret = PTR_ERR(tb);
4423 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4424 		return ret;
4425 	}
4426 
4427 	ev = tb[WMI_TAG_OFFLOAD_BCN_TX_STATUS_EVENT];
4428 	if (!ev) {
4429 		ath11k_warn(ab, "failed to fetch bcn tx status ev");
4430 		kfree(tb);
4431 		return -EPROTO;
4432 	}
4433 
4434 	*vdev_id   = ev->vdev_id;
4435 	*tx_status = ev->tx_status;
4436 
4437 	kfree(tb);
4438 	return 0;
4439 }
4440 
4441 static int ath11k_pull_vdev_stopped_param_tlv(struct ath11k_base *ab, struct sk_buff *skb,
4442 					      u32 *vdev_id)
4443 {
4444 	const void **tb;
4445 	const struct wmi_vdev_stopped_event *ev;
4446 	int ret;
4447 
4448 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4449 	if (IS_ERR(tb)) {
4450 		ret = PTR_ERR(tb);
4451 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4452 		return ret;
4453 	}
4454 
4455 	ev = tb[WMI_TAG_VDEV_STOPPED_EVENT];
4456 	if (!ev) {
4457 		ath11k_warn(ab, "failed to fetch vdev stop ev");
4458 		kfree(tb);
4459 		return -EPROTO;
4460 	}
4461 
4462 	*vdev_id =  ev->vdev_id;
4463 
4464 	kfree(tb);
4465 	return 0;
4466 }
4467 
4468 static int ath11k_pull_mgmt_rx_params_tlv(struct ath11k_base *ab,
4469 					  struct sk_buff *skb,
4470 					  struct mgmt_rx_event_params *hdr)
4471 {
4472 	const void **tb;
4473 	const struct wmi_mgmt_rx_hdr *ev;
4474 	const u8 *frame;
4475 	int ret;
4476 
4477 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4478 	if (IS_ERR(tb)) {
4479 		ret = PTR_ERR(tb);
4480 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4481 		return ret;
4482 	}
4483 
4484 	ev = tb[WMI_TAG_MGMT_RX_HDR];
4485 	frame = tb[WMI_TAG_ARRAY_BYTE];
4486 
4487 	if (!ev || !frame) {
4488 		ath11k_warn(ab, "failed to fetch mgmt rx hdr");
4489 		kfree(tb);
4490 		return -EPROTO;
4491 	}
4492 
4493 	hdr->pdev_id =  ev->pdev_id;
4494 	hdr->chan_freq = ev->chan_freq;
4495 	hdr->channel =  ev->channel;
4496 	hdr->snr =  ev->snr;
4497 	hdr->rate =  ev->rate;
4498 	hdr->phy_mode =  ev->phy_mode;
4499 	hdr->buf_len =  ev->buf_len;
4500 	hdr->status =  ev->status;
4501 	hdr->flags =  ev->flags;
4502 	hdr->rssi =  ev->rssi;
4503 	hdr->tsf_delta =  ev->tsf_delta;
4504 	memcpy(hdr->rssi_ctl, ev->rssi_ctl, sizeof(hdr->rssi_ctl));
4505 
4506 	if (skb->len < (frame - skb->data) + hdr->buf_len) {
4507 		ath11k_warn(ab, "invalid length in mgmt rx hdr ev");
4508 		kfree(tb);
4509 		return -EPROTO;
4510 	}
4511 
4512 	/* shift the sk_buff to point to `frame` */
4513 	skb_trim(skb, 0);
4514 	skb_put(skb, frame - skb->data);
4515 	skb_pull(skb, frame - skb->data);
4516 	skb_put(skb, hdr->buf_len);
4517 
4518 	ath11k_ce_byte_swap(skb->data, hdr->buf_len);
4519 
4520 	kfree(tb);
4521 	return 0;
4522 }
4523 
4524 static int wmi_process_mgmt_tx_comp(struct ath11k *ar, u32 desc_id,
4525 				    u32 status)
4526 {
4527 	struct sk_buff *msdu;
4528 	struct ieee80211_tx_info *info;
4529 	struct ath11k_skb_cb *skb_cb;
4530 
4531 	spin_lock_bh(&ar->txmgmt_idr_lock);
4532 	msdu = idr_find(&ar->txmgmt_idr, desc_id);
4533 
4534 	if (!msdu) {
4535 		ath11k_warn(ar->ab, "received mgmt tx compl for invalid msdu_id: %d\n",
4536 			    desc_id);
4537 		spin_unlock_bh(&ar->txmgmt_idr_lock);
4538 		return -ENOENT;
4539 	}
4540 
4541 	idr_remove(&ar->txmgmt_idr, desc_id);
4542 	spin_unlock_bh(&ar->txmgmt_idr_lock);
4543 
4544 	skb_cb = ATH11K_SKB_CB(msdu);
4545 	dma_unmap_single(ar->ab->dev, skb_cb->paddr, msdu->len, DMA_TO_DEVICE);
4546 
4547 	info = IEEE80211_SKB_CB(msdu);
4548 	if ((!(info->flags & IEEE80211_TX_CTL_NO_ACK)) && !status)
4549 		info->flags |= IEEE80211_TX_STAT_ACK;
4550 
4551 	ieee80211_tx_status_irqsafe(ar->hw, msdu);
4552 
4553 	/* WARN when we received this event without doing any mgmt tx */
4554 	if (atomic_dec_if_positive(&ar->num_pending_mgmt_tx) < 0)
4555 		WARN_ON_ONCE(1);
4556 
4557 	return 0;
4558 }
4559 
4560 static int ath11k_pull_mgmt_tx_compl_param_tlv(struct ath11k_base *ab,
4561 					       struct sk_buff *skb,
4562 					       struct wmi_mgmt_tx_compl_event *param)
4563 {
4564 	const void **tb;
4565 	const struct wmi_mgmt_tx_compl_event *ev;
4566 	int ret;
4567 
4568 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4569 	if (IS_ERR(tb)) {
4570 		ret = PTR_ERR(tb);
4571 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4572 		return ret;
4573 	}
4574 
4575 	ev = tb[WMI_TAG_MGMT_TX_COMPL_EVENT];
4576 	if (!ev) {
4577 		ath11k_warn(ab, "failed to fetch mgmt tx compl ev");
4578 		kfree(tb);
4579 		return -EPROTO;
4580 	}
4581 
4582 	param->pdev_id = ev->pdev_id;
4583 	param->desc_id = ev->desc_id;
4584 	param->status = ev->status;
4585 
4586 	kfree(tb);
4587 	return 0;
4588 }
4589 
4590 static void ath11k_wmi_event_scan_started(struct ath11k *ar)
4591 {
4592 	lockdep_assert_held(&ar->data_lock);
4593 
4594 	switch (ar->scan.state) {
4595 	case ATH11K_SCAN_IDLE:
4596 	case ATH11K_SCAN_RUNNING:
4597 	case ATH11K_SCAN_ABORTING:
4598 		ath11k_warn(ar->ab, "received scan started event in an invalid scan state: %s (%d)\n",
4599 			    ath11k_scan_state_str(ar->scan.state),
4600 			    ar->scan.state);
4601 		break;
4602 	case ATH11K_SCAN_STARTING:
4603 		ar->scan.state = ATH11K_SCAN_RUNNING;
4604 		complete(&ar->scan.started);
4605 		break;
4606 	}
4607 }
4608 
4609 static void ath11k_wmi_event_scan_start_failed(struct ath11k *ar)
4610 {
4611 	lockdep_assert_held(&ar->data_lock);
4612 
4613 	switch (ar->scan.state) {
4614 	case ATH11K_SCAN_IDLE:
4615 	case ATH11K_SCAN_RUNNING:
4616 	case ATH11K_SCAN_ABORTING:
4617 		ath11k_warn(ar->ab, "received scan start failed event in an invalid scan state: %s (%d)\n",
4618 			    ath11k_scan_state_str(ar->scan.state),
4619 			    ar->scan.state);
4620 		break;
4621 	case ATH11K_SCAN_STARTING:
4622 		complete(&ar->scan.started);
4623 		__ath11k_mac_scan_finish(ar);
4624 		break;
4625 	}
4626 }
4627 
4628 static void ath11k_wmi_event_scan_completed(struct ath11k *ar)
4629 {
4630 	lockdep_assert_held(&ar->data_lock);
4631 
4632 	switch (ar->scan.state) {
4633 	case ATH11K_SCAN_IDLE:
4634 	case ATH11K_SCAN_STARTING:
4635 		/* One suspected reason scan can be completed while starting is
4636 		 * if firmware fails to deliver all scan events to the host,
4637 		 * e.g. when transport pipe is full. This has been observed
4638 		 * with spectral scan phyerr events starving wmi transport
4639 		 * pipe. In such case the "scan completed" event should be (and
4640 		 * is) ignored by the host as it may be just firmware's scan
4641 		 * state machine recovering.
4642 		 */
4643 		ath11k_warn(ar->ab, "received scan completed event in an invalid scan state: %s (%d)\n",
4644 			    ath11k_scan_state_str(ar->scan.state),
4645 			    ar->scan.state);
4646 		break;
4647 	case ATH11K_SCAN_RUNNING:
4648 	case ATH11K_SCAN_ABORTING:
4649 		__ath11k_mac_scan_finish(ar);
4650 		break;
4651 	}
4652 }
4653 
4654 static void ath11k_wmi_event_scan_bss_chan(struct ath11k *ar)
4655 {
4656 	lockdep_assert_held(&ar->data_lock);
4657 
4658 	switch (ar->scan.state) {
4659 	case ATH11K_SCAN_IDLE:
4660 	case ATH11K_SCAN_STARTING:
4661 		ath11k_warn(ar->ab, "received scan bss chan event in an invalid scan state: %s (%d)\n",
4662 			    ath11k_scan_state_str(ar->scan.state),
4663 			    ar->scan.state);
4664 		break;
4665 	case ATH11K_SCAN_RUNNING:
4666 	case ATH11K_SCAN_ABORTING:
4667 		ar->scan_channel = NULL;
4668 		break;
4669 	}
4670 }
4671 
4672 static void ath11k_wmi_event_scan_foreign_chan(struct ath11k *ar, u32 freq)
4673 {
4674 	lockdep_assert_held(&ar->data_lock);
4675 
4676 	switch (ar->scan.state) {
4677 	case ATH11K_SCAN_IDLE:
4678 	case ATH11K_SCAN_STARTING:
4679 		ath11k_warn(ar->ab, "received scan foreign chan event in an invalid scan state: %s (%d)\n",
4680 			    ath11k_scan_state_str(ar->scan.state),
4681 			    ar->scan.state);
4682 		break;
4683 	case ATH11K_SCAN_RUNNING:
4684 	case ATH11K_SCAN_ABORTING:
4685 		ar->scan_channel = ieee80211_get_channel(ar->hw->wiphy, freq);
4686 		break;
4687 	}
4688 }
4689 
4690 static const char *
4691 ath11k_wmi_event_scan_type_str(enum wmi_scan_event_type type,
4692 			       enum wmi_scan_completion_reason reason)
4693 {
4694 	switch (type) {
4695 	case WMI_SCAN_EVENT_STARTED:
4696 		return "started";
4697 	case WMI_SCAN_EVENT_COMPLETED:
4698 		switch (reason) {
4699 		case WMI_SCAN_REASON_COMPLETED:
4700 			return "completed";
4701 		case WMI_SCAN_REASON_CANCELLED:
4702 			return "completed [cancelled]";
4703 		case WMI_SCAN_REASON_PREEMPTED:
4704 			return "completed [preempted]";
4705 		case WMI_SCAN_REASON_TIMEDOUT:
4706 			return "completed [timedout]";
4707 		case WMI_SCAN_REASON_INTERNAL_FAILURE:
4708 			return "completed [internal err]";
4709 		case WMI_SCAN_REASON_MAX:
4710 			break;
4711 		}
4712 		return "completed [unknown]";
4713 	case WMI_SCAN_EVENT_BSS_CHANNEL:
4714 		return "bss channel";
4715 	case WMI_SCAN_EVENT_FOREIGN_CHAN:
4716 		return "foreign channel";
4717 	case WMI_SCAN_EVENT_DEQUEUED:
4718 		return "dequeued";
4719 	case WMI_SCAN_EVENT_PREEMPTED:
4720 		return "preempted";
4721 	case WMI_SCAN_EVENT_START_FAILED:
4722 		return "start failed";
4723 	case WMI_SCAN_EVENT_RESTARTED:
4724 		return "restarted";
4725 	case WMI_SCAN_EVENT_FOREIGN_CHAN_EXIT:
4726 		return "foreign channel exit";
4727 	default:
4728 		return "unknown";
4729 	}
4730 }
4731 
4732 static int ath11k_pull_scan_ev(struct ath11k_base *ab, struct sk_buff *skb,
4733 			       struct wmi_scan_event *scan_evt_param)
4734 {
4735 	const void **tb;
4736 	const struct wmi_scan_event *ev;
4737 	int ret;
4738 
4739 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4740 	if (IS_ERR(tb)) {
4741 		ret = PTR_ERR(tb);
4742 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4743 		return ret;
4744 	}
4745 
4746 	ev = tb[WMI_TAG_SCAN_EVENT];
4747 	if (!ev) {
4748 		ath11k_warn(ab, "failed to fetch scan ev");
4749 		kfree(tb);
4750 		return -EPROTO;
4751 	}
4752 
4753 	scan_evt_param->event_type = ev->event_type;
4754 	scan_evt_param->reason = ev->reason;
4755 	scan_evt_param->channel_freq = ev->channel_freq;
4756 	scan_evt_param->scan_req_id = ev->scan_req_id;
4757 	scan_evt_param->scan_id = ev->scan_id;
4758 	scan_evt_param->vdev_id = ev->vdev_id;
4759 	scan_evt_param->tsf_timestamp = ev->tsf_timestamp;
4760 
4761 	kfree(tb);
4762 	return 0;
4763 }
4764 
4765 static int ath11k_pull_peer_sta_kickout_ev(struct ath11k_base *ab, struct sk_buff *skb,
4766 					   struct wmi_peer_sta_kickout_arg *arg)
4767 {
4768 	const void **tb;
4769 	const struct wmi_peer_sta_kickout_event *ev;
4770 	int ret;
4771 
4772 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4773 	if (IS_ERR(tb)) {
4774 		ret = PTR_ERR(tb);
4775 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4776 		return ret;
4777 	}
4778 
4779 	ev = tb[WMI_TAG_PEER_STA_KICKOUT_EVENT];
4780 	if (!ev) {
4781 		ath11k_warn(ab, "failed to fetch peer sta kickout ev");
4782 		kfree(tb);
4783 		return -EPROTO;
4784 	}
4785 
4786 	arg->mac_addr = ev->peer_macaddr.addr;
4787 
4788 	kfree(tb);
4789 	return 0;
4790 }
4791 
4792 static int ath11k_pull_roam_ev(struct ath11k_base *ab, struct sk_buff *skb,
4793 			       struct wmi_roam_event *roam_ev)
4794 {
4795 	const void **tb;
4796 	const struct wmi_roam_event *ev;
4797 	int ret;
4798 
4799 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4800 	if (IS_ERR(tb)) {
4801 		ret = PTR_ERR(tb);
4802 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4803 		return ret;
4804 	}
4805 
4806 	ev = tb[WMI_TAG_ROAM_EVENT];
4807 	if (!ev) {
4808 		ath11k_warn(ab, "failed to fetch roam ev");
4809 		kfree(tb);
4810 		return -EPROTO;
4811 	}
4812 
4813 	roam_ev->vdev_id = ev->vdev_id;
4814 	roam_ev->reason = ev->reason;
4815 	roam_ev->rssi = ev->rssi;
4816 
4817 	kfree(tb);
4818 	return 0;
4819 }
4820 
4821 static int freq_to_idx(struct ath11k *ar, int freq)
4822 {
4823 	struct ieee80211_supported_band *sband;
4824 	int band, ch, idx = 0;
4825 
4826 	for (band = NL80211_BAND_2GHZ; band < NUM_NL80211_BANDS; band++) {
4827 		sband = ar->hw->wiphy->bands[band];
4828 		if (!sband)
4829 			continue;
4830 
4831 		for (ch = 0; ch < sband->n_channels; ch++, idx++)
4832 			if (sband->channels[ch].center_freq == freq)
4833 				goto exit;
4834 	}
4835 
4836 exit:
4837 	return idx;
4838 }
4839 
4840 static int ath11k_pull_chan_info_ev(struct ath11k_base *ab, u8 *evt_buf,
4841 				    u32 len, struct wmi_chan_info_event *ch_info_ev)
4842 {
4843 	const void **tb;
4844 	const struct wmi_chan_info_event *ev;
4845 	int ret;
4846 
4847 	tb = ath11k_wmi_tlv_parse_alloc(ab, evt_buf, len, GFP_ATOMIC);
4848 	if (IS_ERR(tb)) {
4849 		ret = PTR_ERR(tb);
4850 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4851 		return ret;
4852 	}
4853 
4854 	ev = tb[WMI_TAG_CHAN_INFO_EVENT];
4855 	if (!ev) {
4856 		ath11k_warn(ab, "failed to fetch chan info ev");
4857 		kfree(tb);
4858 		return -EPROTO;
4859 	}
4860 
4861 	ch_info_ev->err_code = ev->err_code;
4862 	ch_info_ev->freq = ev->freq;
4863 	ch_info_ev->cmd_flags = ev->cmd_flags;
4864 	ch_info_ev->noise_floor = ev->noise_floor;
4865 	ch_info_ev->rx_clear_count = ev->rx_clear_count;
4866 	ch_info_ev->cycle_count = ev->cycle_count;
4867 	ch_info_ev->chan_tx_pwr_range = ev->chan_tx_pwr_range;
4868 	ch_info_ev->chan_tx_pwr_tp = ev->chan_tx_pwr_tp;
4869 	ch_info_ev->rx_frame_count = ev->rx_frame_count;
4870 	ch_info_ev->tx_frame_cnt = ev->tx_frame_cnt;
4871 	ch_info_ev->mac_clk_mhz = ev->mac_clk_mhz;
4872 	ch_info_ev->vdev_id = ev->vdev_id;
4873 
4874 	kfree(tb);
4875 	return 0;
4876 }
4877 
4878 static int
4879 ath11k_pull_pdev_bss_chan_info_ev(struct ath11k_base *ab, struct sk_buff *skb,
4880 				  struct wmi_pdev_bss_chan_info_event *bss_ch_info_ev)
4881 {
4882 	const void **tb;
4883 	const struct wmi_pdev_bss_chan_info_event *ev;
4884 	int ret;
4885 
4886 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4887 	if (IS_ERR(tb)) {
4888 		ret = PTR_ERR(tb);
4889 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4890 		return ret;
4891 	}
4892 
4893 	ev = tb[WMI_TAG_PDEV_BSS_CHAN_INFO_EVENT];
4894 	if (!ev) {
4895 		ath11k_warn(ab, "failed to fetch pdev bss chan info ev");
4896 		kfree(tb);
4897 		return -EPROTO;
4898 	}
4899 
4900 	bss_ch_info_ev->pdev_id = ev->pdev_id;
4901 	bss_ch_info_ev->freq = ev->freq;
4902 	bss_ch_info_ev->noise_floor = ev->noise_floor;
4903 	bss_ch_info_ev->rx_clear_count_low = ev->rx_clear_count_low;
4904 	bss_ch_info_ev->rx_clear_count_high = ev->rx_clear_count_high;
4905 	bss_ch_info_ev->cycle_count_low = ev->cycle_count_low;
4906 	bss_ch_info_ev->cycle_count_high = ev->cycle_count_high;
4907 	bss_ch_info_ev->tx_cycle_count_low = ev->tx_cycle_count_low;
4908 	bss_ch_info_ev->tx_cycle_count_high = ev->tx_cycle_count_high;
4909 	bss_ch_info_ev->rx_cycle_count_low = ev->rx_cycle_count_low;
4910 	bss_ch_info_ev->rx_cycle_count_high = ev->rx_cycle_count_high;
4911 	bss_ch_info_ev->rx_bss_cycle_count_low = ev->rx_bss_cycle_count_low;
4912 	bss_ch_info_ev->rx_bss_cycle_count_high = ev->rx_bss_cycle_count_high;
4913 
4914 	kfree(tb);
4915 	return 0;
4916 }
4917 
4918 static int
4919 ath11k_pull_vdev_install_key_compl_ev(struct ath11k_base *ab, struct sk_buff *skb,
4920 				      struct wmi_vdev_install_key_complete_arg *arg)
4921 {
4922 	const void **tb;
4923 	const struct wmi_vdev_install_key_compl_event *ev;
4924 	int ret;
4925 
4926 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4927 	if (IS_ERR(tb)) {
4928 		ret = PTR_ERR(tb);
4929 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4930 		return ret;
4931 	}
4932 
4933 	ev = tb[WMI_TAG_VDEV_INSTALL_KEY_COMPLETE_EVENT];
4934 	if (!ev) {
4935 		ath11k_warn(ab, "failed to fetch vdev install key compl ev");
4936 		kfree(tb);
4937 		return -EPROTO;
4938 	}
4939 
4940 	arg->vdev_id = ev->vdev_id;
4941 	arg->macaddr = ev->peer_macaddr.addr;
4942 	arg->key_idx = ev->key_idx;
4943 	arg->key_flags = ev->key_flags;
4944 	arg->status = ev->status;
4945 
4946 	kfree(tb);
4947 	return 0;
4948 }
4949 
4950 static int ath11k_pull_peer_assoc_conf_ev(struct ath11k_base *ab, struct sk_buff *skb,
4951 					  struct wmi_peer_assoc_conf_arg *peer_assoc_conf)
4952 {
4953 	const void **tb;
4954 	const struct wmi_peer_assoc_conf_event *ev;
4955 	int ret;
4956 
4957 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
4958 	if (IS_ERR(tb)) {
4959 		ret = PTR_ERR(tb);
4960 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4961 		return ret;
4962 	}
4963 
4964 	ev = tb[WMI_TAG_PEER_ASSOC_CONF_EVENT];
4965 	if (!ev) {
4966 		ath11k_warn(ab, "failed to fetch peer assoc conf ev");
4967 		kfree(tb);
4968 		return -EPROTO;
4969 	}
4970 
4971 	peer_assoc_conf->vdev_id = ev->vdev_id;
4972 	peer_assoc_conf->macaddr = ev->peer_macaddr.addr;
4973 
4974 	kfree(tb);
4975 	return 0;
4976 }
4977 
4978 static void ath11k_wmi_pull_pdev_stats_base(const struct wmi_pdev_stats_base *src,
4979 					    struct ath11k_fw_stats_pdev *dst)
4980 {
4981 	dst->ch_noise_floor = src->chan_nf;
4982 	dst->tx_frame_count = src->tx_frame_count;
4983 	dst->rx_frame_count = src->rx_frame_count;
4984 	dst->rx_clear_count = src->rx_clear_count;
4985 	dst->cycle_count = src->cycle_count;
4986 	dst->phy_err_count = src->phy_err_count;
4987 	dst->chan_tx_power = src->chan_tx_pwr;
4988 }
4989 
4990 static void
4991 ath11k_wmi_pull_pdev_stats_tx(const struct wmi_pdev_stats_tx *src,
4992 			      struct ath11k_fw_stats_pdev *dst)
4993 {
4994 	dst->comp_queued = src->comp_queued;
4995 	dst->comp_delivered = src->comp_delivered;
4996 	dst->msdu_enqued = src->msdu_enqued;
4997 	dst->mpdu_enqued = src->mpdu_enqued;
4998 	dst->wmm_drop = src->wmm_drop;
4999 	dst->local_enqued = src->local_enqued;
5000 	dst->local_freed = src->local_freed;
5001 	dst->hw_queued = src->hw_queued;
5002 	dst->hw_reaped = src->hw_reaped;
5003 	dst->underrun = src->underrun;
5004 	dst->tx_abort = src->tx_abort;
5005 	dst->mpdus_requed = src->mpdus_requed;
5006 	dst->tx_ko = src->tx_ko;
5007 	dst->data_rc = src->data_rc;
5008 	dst->self_triggers = src->self_triggers;
5009 	dst->sw_retry_failure = src->sw_retry_failure;
5010 	dst->illgl_rate_phy_err = src->illgl_rate_phy_err;
5011 	dst->pdev_cont_xretry = src->pdev_cont_xretry;
5012 	dst->pdev_tx_timeout = src->pdev_tx_timeout;
5013 	dst->pdev_resets = src->pdev_resets;
5014 	dst->stateless_tid_alloc_failure = src->stateless_tid_alloc_failure;
5015 	dst->phy_underrun = src->phy_underrun;
5016 	dst->txop_ovf = src->txop_ovf;
5017 }
5018 
5019 static void ath11k_wmi_pull_pdev_stats_rx(const struct wmi_pdev_stats_rx *src,
5020 					  struct ath11k_fw_stats_pdev *dst)
5021 {
5022 	dst->mid_ppdu_route_change = src->mid_ppdu_route_change;
5023 	dst->status_rcvd = src->status_rcvd;
5024 	dst->r0_frags = src->r0_frags;
5025 	dst->r1_frags = src->r1_frags;
5026 	dst->r2_frags = src->r2_frags;
5027 	dst->r3_frags = src->r3_frags;
5028 	dst->htt_msdus = src->htt_msdus;
5029 	dst->htt_mpdus = src->htt_mpdus;
5030 	dst->loc_msdus = src->loc_msdus;
5031 	dst->loc_mpdus = src->loc_mpdus;
5032 	dst->oversize_amsdu = src->oversize_amsdu;
5033 	dst->phy_errs = src->phy_errs;
5034 	dst->phy_err_drop = src->phy_err_drop;
5035 	dst->mpdu_errs = src->mpdu_errs;
5036 }
5037 
5038 static void
5039 ath11k_wmi_pull_vdev_stats(const struct wmi_vdev_stats *src,
5040 			   struct ath11k_fw_stats_vdev *dst)
5041 {
5042 	int i;
5043 
5044 	dst->vdev_id = src->vdev_id;
5045 	dst->beacon_snr = src->beacon_snr;
5046 	dst->data_snr = src->data_snr;
5047 	dst->num_rx_frames = src->num_rx_frames;
5048 	dst->num_rts_fail = src->num_rts_fail;
5049 	dst->num_rts_success = src->num_rts_success;
5050 	dst->num_rx_err = src->num_rx_err;
5051 	dst->num_rx_discard = src->num_rx_discard;
5052 	dst->num_tx_not_acked = src->num_tx_not_acked;
5053 
5054 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames); i++)
5055 		dst->num_tx_frames[i] = src->num_tx_frames[i];
5056 
5057 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_retries); i++)
5058 		dst->num_tx_frames_retries[i] = src->num_tx_frames_retries[i];
5059 
5060 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_failures); i++)
5061 		dst->num_tx_frames_failures[i] = src->num_tx_frames_failures[i];
5062 
5063 	for (i = 0; i < ARRAY_SIZE(src->tx_rate_history); i++)
5064 		dst->tx_rate_history[i] = src->tx_rate_history[i];
5065 
5066 	for (i = 0; i < ARRAY_SIZE(src->beacon_rssi_history); i++)
5067 		dst->beacon_rssi_history[i] = src->beacon_rssi_history[i];
5068 }
5069 
5070 static void
5071 ath11k_wmi_pull_bcn_stats(const struct wmi_bcn_stats *src,
5072 			  struct ath11k_fw_stats_bcn *dst)
5073 {
5074 	dst->vdev_id = src->vdev_id;
5075 	dst->tx_bcn_succ_cnt = src->tx_bcn_succ_cnt;
5076 	dst->tx_bcn_outage_cnt = src->tx_bcn_outage_cnt;
5077 }
5078 
5079 int ath11k_wmi_pull_fw_stats(struct ath11k_base *ab, struct sk_buff *skb,
5080 			     struct ath11k_fw_stats *stats)
5081 {
5082 	const void **tb;
5083 	const struct wmi_stats_event *ev;
5084 	const void *data;
5085 	int i, ret;
5086 	u32 len = skb->len;
5087 
5088 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, len, GFP_ATOMIC);
5089 	if (IS_ERR(tb)) {
5090 		ret = PTR_ERR(tb);
5091 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5092 		return ret;
5093 	}
5094 
5095 	ev = tb[WMI_TAG_STATS_EVENT];
5096 	data = tb[WMI_TAG_ARRAY_BYTE];
5097 	if (!ev || !data) {
5098 		ath11k_warn(ab, "failed to fetch update stats ev");
5099 		kfree(tb);
5100 		return -EPROTO;
5101 	}
5102 
5103 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5104 		   "wmi stats update ev pdev_id %d pdev %i vdev %i bcn %i\n",
5105 		   ev->pdev_id,
5106 		   ev->num_pdev_stats, ev->num_vdev_stats,
5107 		   ev->num_bcn_stats);
5108 
5109 	stats->pdev_id = ev->pdev_id;
5110 	stats->stats_id = 0;
5111 
5112 	for (i = 0; i < ev->num_pdev_stats; i++) {
5113 		const struct wmi_pdev_stats *src;
5114 		struct ath11k_fw_stats_pdev *dst;
5115 
5116 		src = data;
5117 		if (len < sizeof(*src)) {
5118 			kfree(tb);
5119 			return -EPROTO;
5120 		}
5121 
5122 		stats->stats_id = WMI_REQUEST_PDEV_STAT;
5123 
5124 		data += sizeof(*src);
5125 		len -= sizeof(*src);
5126 
5127 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
5128 		if (!dst)
5129 			continue;
5130 
5131 		ath11k_wmi_pull_pdev_stats_base(&src->base, dst);
5132 		ath11k_wmi_pull_pdev_stats_tx(&src->tx, dst);
5133 		ath11k_wmi_pull_pdev_stats_rx(&src->rx, dst);
5134 		list_add_tail(&dst->list, &stats->pdevs);
5135 	}
5136 
5137 	for (i = 0; i < ev->num_vdev_stats; i++) {
5138 		const struct wmi_vdev_stats *src;
5139 		struct ath11k_fw_stats_vdev *dst;
5140 
5141 		src = data;
5142 		if (len < sizeof(*src)) {
5143 			kfree(tb);
5144 			return -EPROTO;
5145 		}
5146 
5147 		stats->stats_id = WMI_REQUEST_VDEV_STAT;
5148 
5149 		data += sizeof(*src);
5150 		len -= sizeof(*src);
5151 
5152 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
5153 		if (!dst)
5154 			continue;
5155 
5156 		ath11k_wmi_pull_vdev_stats(src, dst);
5157 		list_add_tail(&dst->list, &stats->vdevs);
5158 	}
5159 
5160 	for (i = 0; i < ev->num_bcn_stats; i++) {
5161 		const struct wmi_bcn_stats *src;
5162 		struct ath11k_fw_stats_bcn *dst;
5163 
5164 		src = data;
5165 		if (len < sizeof(*src)) {
5166 			kfree(tb);
5167 			return -EPROTO;
5168 		}
5169 
5170 		stats->stats_id = WMI_REQUEST_BCN_STAT;
5171 
5172 		data += sizeof(*src);
5173 		len -= sizeof(*src);
5174 
5175 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
5176 		if (!dst)
5177 			continue;
5178 
5179 		ath11k_wmi_pull_bcn_stats(src, dst);
5180 		list_add_tail(&dst->list, &stats->bcn);
5181 	}
5182 
5183 	kfree(tb);
5184 	return 0;
5185 }
5186 
5187 static int
5188 ath11k_pull_pdev_temp_ev(struct ath11k_base *ab, u8 *evt_buf,
5189 			 u32 len, const struct wmi_pdev_temperature_event *ev)
5190 {
5191 	const void **tb;
5192 	int ret;
5193 
5194 	tb = ath11k_wmi_tlv_parse_alloc(ab, evt_buf, len, GFP_ATOMIC);
5195 	if (IS_ERR(tb)) {
5196 		ret = PTR_ERR(tb);
5197 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5198 		return ret;
5199 	}
5200 
5201 	ev = tb[WMI_TAG_PDEV_TEMPERATURE_EVENT];
5202 	if (!ev) {
5203 		ath11k_warn(ab, "failed to fetch pdev temp ev");
5204 		kfree(tb);
5205 		return -EPROTO;
5206 	}
5207 
5208 	kfree(tb);
5209 	return 0;
5210 }
5211 
5212 size_t ath11k_wmi_fw_stats_num_vdevs(struct list_head *head)
5213 {
5214 	struct ath11k_fw_stats_vdev *i;
5215 	size_t num = 0;
5216 
5217 	list_for_each_entry(i, head, list)
5218 		++num;
5219 
5220 	return num;
5221 }
5222 
5223 static size_t ath11k_wmi_fw_stats_num_bcn(struct list_head *head)
5224 {
5225 	struct ath11k_fw_stats_bcn *i;
5226 	size_t num = 0;
5227 
5228 	list_for_each_entry(i, head, list)
5229 		++num;
5230 
5231 	return num;
5232 }
5233 
5234 static void
5235 ath11k_wmi_fw_pdev_base_stats_fill(const struct ath11k_fw_stats_pdev *pdev,
5236 				   char *buf, u32 *length)
5237 {
5238 	u32 len = *length;
5239 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5240 
5241 	len += scnprintf(buf + len, buf_len - len, "\n");
5242 	len += scnprintf(buf + len, buf_len - len, "%30s\n",
5243 			"ath11k PDEV stats");
5244 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5245 			"=================");
5246 
5247 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5248 			"Channel noise floor", pdev->ch_noise_floor);
5249 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5250 			"Channel TX power", pdev->chan_tx_power);
5251 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5252 			"TX frame count", pdev->tx_frame_count);
5253 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5254 			"RX frame count", pdev->rx_frame_count);
5255 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5256 			"RX clear count", pdev->rx_clear_count);
5257 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5258 			"Cycle count", pdev->cycle_count);
5259 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5260 			"PHY error count", pdev->phy_err_count);
5261 
5262 	*length = len;
5263 }
5264 
5265 static void
5266 ath11k_wmi_fw_pdev_tx_stats_fill(const struct ath11k_fw_stats_pdev *pdev,
5267 				 char *buf, u32 *length)
5268 {
5269 	u32 len = *length;
5270 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5271 
5272 	len += scnprintf(buf + len, buf_len - len, "\n%30s\n",
5273 			 "ath11k PDEV TX stats");
5274 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5275 			 "====================");
5276 
5277 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5278 			 "HTT cookies queued", pdev->comp_queued);
5279 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5280 			 "HTT cookies disp.", pdev->comp_delivered);
5281 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5282 			 "MSDU queued", pdev->msdu_enqued);
5283 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5284 			 "MPDU queued", pdev->mpdu_enqued);
5285 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5286 			 "MSDUs dropped", pdev->wmm_drop);
5287 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5288 			 "Local enqued", pdev->local_enqued);
5289 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5290 			 "Local freed", pdev->local_freed);
5291 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5292 			 "HW queued", pdev->hw_queued);
5293 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5294 			 "PPDUs reaped", pdev->hw_reaped);
5295 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5296 			 "Num underruns", pdev->underrun);
5297 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5298 			 "PPDUs cleaned", pdev->tx_abort);
5299 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5300 			 "MPDUs requed", pdev->mpdus_requed);
5301 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5302 			 "Excessive retries", pdev->tx_ko);
5303 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5304 			 "HW rate", pdev->data_rc);
5305 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5306 			 "Sched self triggers", pdev->self_triggers);
5307 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5308 			 "Dropped due to SW retries",
5309 			 pdev->sw_retry_failure);
5310 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5311 			 "Illegal rate phy errors",
5312 			 pdev->illgl_rate_phy_err);
5313 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5314 			 "PDEV continuous xretry", pdev->pdev_cont_xretry);
5315 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5316 			 "TX timeout", pdev->pdev_tx_timeout);
5317 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5318 			 "PDEV resets", pdev->pdev_resets);
5319 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5320 			 "Stateless TIDs alloc failures",
5321 			 pdev->stateless_tid_alloc_failure);
5322 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5323 			 "PHY underrun", pdev->phy_underrun);
5324 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
5325 			 "MPDU is more than txop limit", pdev->txop_ovf);
5326 	*length = len;
5327 }
5328 
5329 static void
5330 ath11k_wmi_fw_pdev_rx_stats_fill(const struct ath11k_fw_stats_pdev *pdev,
5331 				 char *buf, u32 *length)
5332 {
5333 	u32 len = *length;
5334 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5335 
5336 	len += scnprintf(buf + len, buf_len - len, "\n%30s\n",
5337 			 "ath11k PDEV RX stats");
5338 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5339 			 "====================");
5340 
5341 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5342 			 "Mid PPDU route change",
5343 			 pdev->mid_ppdu_route_change);
5344 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5345 			 "Tot. number of statuses", pdev->status_rcvd);
5346 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5347 			 "Extra frags on rings 0", pdev->r0_frags);
5348 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5349 			 "Extra frags on rings 1", pdev->r1_frags);
5350 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5351 			 "Extra frags on rings 2", pdev->r2_frags);
5352 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5353 			 "Extra frags on rings 3", pdev->r3_frags);
5354 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5355 			 "MSDUs delivered to HTT", pdev->htt_msdus);
5356 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5357 			 "MPDUs delivered to HTT", pdev->htt_mpdus);
5358 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5359 			 "MSDUs delivered to stack", pdev->loc_msdus);
5360 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5361 			 "MPDUs delivered to stack", pdev->loc_mpdus);
5362 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5363 			 "Oversized AMSUs", pdev->oversize_amsdu);
5364 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5365 			 "PHY errors", pdev->phy_errs);
5366 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5367 			 "PHY errors drops", pdev->phy_err_drop);
5368 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
5369 			 "MPDU errors (FCS, MIC, ENC)", pdev->mpdu_errs);
5370 	*length = len;
5371 }
5372 
5373 static void
5374 ath11k_wmi_fw_vdev_stats_fill(struct ath11k *ar,
5375 			      const struct ath11k_fw_stats_vdev *vdev,
5376 			      char *buf, u32 *length)
5377 {
5378 	u32 len = *length;
5379 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5380 	struct ath11k_vif *arvif = ath11k_mac_get_arvif(ar, vdev->vdev_id);
5381 	u8 *vif_macaddr;
5382 	int i;
5383 
5384 	/* VDEV stats has all the active VDEVs of other PDEVs as well,
5385 	 * ignoring those not part of requested PDEV
5386 	 */
5387 	if (!arvif)
5388 		return;
5389 
5390 	vif_macaddr = arvif->vif->addr;
5391 
5392 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5393 			 "VDEV ID", vdev->vdev_id);
5394 	len += scnprintf(buf + len, buf_len - len, "%30s %pM\n",
5395 			 "VDEV MAC address", vif_macaddr);
5396 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5397 			 "beacon snr", vdev->beacon_snr);
5398 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5399 			 "data snr", vdev->data_snr);
5400 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5401 			 "num rx frames", vdev->num_rx_frames);
5402 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5403 			 "num rts fail", vdev->num_rts_fail);
5404 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5405 			 "num rts success", vdev->num_rts_success);
5406 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5407 			 "num rx err", vdev->num_rx_err);
5408 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5409 			 "num rx discard", vdev->num_rx_discard);
5410 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5411 			 "num tx not acked", vdev->num_tx_not_acked);
5412 
5413 	for (i = 0 ; i < ARRAY_SIZE(vdev->num_tx_frames); i++)
5414 		len += scnprintf(buf + len, buf_len - len,
5415 				"%25s [%02d] %u\n",
5416 				"num tx frames", i,
5417 				vdev->num_tx_frames[i]);
5418 
5419 	for (i = 0 ; i < ARRAY_SIZE(vdev->num_tx_frames_retries); i++)
5420 		len += scnprintf(buf + len, buf_len - len,
5421 				"%25s [%02d] %u\n",
5422 				"num tx frames retries", i,
5423 				vdev->num_tx_frames_retries[i]);
5424 
5425 	for (i = 0 ; i < ARRAY_SIZE(vdev->num_tx_frames_failures); i++)
5426 		len += scnprintf(buf + len, buf_len - len,
5427 				"%25s [%02d] %u\n",
5428 				"num tx frames failures", i,
5429 				vdev->num_tx_frames_failures[i]);
5430 
5431 	for (i = 0 ; i < ARRAY_SIZE(vdev->tx_rate_history); i++)
5432 		len += scnprintf(buf + len, buf_len - len,
5433 				"%25s [%02d] 0x%08x\n",
5434 				"tx rate history", i,
5435 				vdev->tx_rate_history[i]);
5436 
5437 	for (i = 0 ; i < ARRAY_SIZE(vdev->beacon_rssi_history); i++)
5438 		len += scnprintf(buf + len, buf_len - len,
5439 				"%25s [%02d] %u\n",
5440 				"beacon rssi history", i,
5441 				vdev->beacon_rssi_history[i]);
5442 
5443 	len += scnprintf(buf + len, buf_len - len, "\n");
5444 	*length = len;
5445 }
5446 
5447 static void
5448 ath11k_wmi_fw_bcn_stats_fill(struct ath11k *ar,
5449 			     const struct ath11k_fw_stats_bcn *bcn,
5450 			     char *buf, u32 *length)
5451 {
5452 	u32 len = *length;
5453 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5454 	struct ath11k_vif *arvif = ath11k_mac_get_arvif(ar, bcn->vdev_id);
5455 	u8 *vdev_macaddr;
5456 
5457 	if (!arvif) {
5458 		ath11k_warn(ar->ab, "invalid vdev id %d in bcn stats",
5459 			    bcn->vdev_id);
5460 		return;
5461 	}
5462 
5463 	vdev_macaddr = arvif->vif->addr;
5464 
5465 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5466 			 "VDEV ID", bcn->vdev_id);
5467 	len += scnprintf(buf + len, buf_len - len, "%30s %pM\n",
5468 			 "VDEV MAC address", vdev_macaddr);
5469 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5470 			 "================");
5471 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5472 			 "Num of beacon tx success", bcn->tx_bcn_succ_cnt);
5473 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
5474 			 "Num of beacon tx failures", bcn->tx_bcn_outage_cnt);
5475 
5476 	len += scnprintf(buf + len, buf_len - len, "\n");
5477 	*length = len;
5478 }
5479 
5480 void ath11k_wmi_fw_stats_fill(struct ath11k *ar,
5481 			      struct ath11k_fw_stats *fw_stats,
5482 			      u32 stats_id, char *buf)
5483 {
5484 	u32 len = 0;
5485 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
5486 	const struct ath11k_fw_stats_pdev *pdev;
5487 	const struct ath11k_fw_stats_vdev *vdev;
5488 	const struct ath11k_fw_stats_bcn *bcn;
5489 	size_t num_bcn;
5490 
5491 	spin_lock_bh(&ar->data_lock);
5492 
5493 	if (stats_id == WMI_REQUEST_PDEV_STAT) {
5494 		pdev = list_first_entry_or_null(&fw_stats->pdevs,
5495 						struct ath11k_fw_stats_pdev, list);
5496 		if (!pdev) {
5497 			ath11k_warn(ar->ab, "failed to get pdev stats\n");
5498 			goto unlock;
5499 		}
5500 
5501 		ath11k_wmi_fw_pdev_base_stats_fill(pdev, buf, &len);
5502 		ath11k_wmi_fw_pdev_tx_stats_fill(pdev, buf, &len);
5503 		ath11k_wmi_fw_pdev_rx_stats_fill(pdev, buf, &len);
5504 	}
5505 
5506 	if (stats_id == WMI_REQUEST_VDEV_STAT) {
5507 		len += scnprintf(buf + len, buf_len - len, "\n");
5508 		len += scnprintf(buf + len, buf_len - len, "%30s\n",
5509 				 "ath11k VDEV stats");
5510 		len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5511 				 "=================");
5512 
5513 		list_for_each_entry(vdev, &fw_stats->vdevs, list)
5514 			ath11k_wmi_fw_vdev_stats_fill(ar, vdev, buf, &len);
5515 	}
5516 
5517 	if (stats_id == WMI_REQUEST_BCN_STAT) {
5518 		num_bcn = ath11k_wmi_fw_stats_num_bcn(&fw_stats->bcn);
5519 
5520 		len += scnprintf(buf + len, buf_len - len, "\n");
5521 		len += scnprintf(buf + len, buf_len - len, "%30s (%zu)\n",
5522 				 "ath11k Beacon stats", num_bcn);
5523 		len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
5524 				 "===================");
5525 
5526 		list_for_each_entry(bcn, &fw_stats->bcn, list)
5527 			ath11k_wmi_fw_bcn_stats_fill(ar, bcn, buf, &len);
5528 	}
5529 
5530 unlock:
5531 	spin_unlock_bh(&ar->data_lock);
5532 
5533 	if (len >= buf_len)
5534 		buf[len - 1] = 0;
5535 	else
5536 		buf[len] = 0;
5537 }
5538 
5539 static void ath11k_wmi_op_ep_tx_credits(struct ath11k_base *ab)
5540 {
5541 	/* try to send pending beacons first. they take priority */
5542 	wake_up(&ab->wmi_ab.tx_credits_wq);
5543 }
5544 
5545 static void ath11k_wmi_htc_tx_complete(struct ath11k_base *ab,
5546 				       struct sk_buff *skb)
5547 {
5548 	dev_kfree_skb(skb);
5549 }
5550 
5551 static bool ath11k_reg_is_world_alpha(char *alpha)
5552 {
5553 	return alpha[0] == '0' && alpha[1] == '0';
5554 }
5555 
5556 static int ath11k_reg_chan_list_event(struct ath11k_base *ab, struct sk_buff *skb)
5557 {
5558 	struct cur_regulatory_info *reg_info = NULL;
5559 	struct ieee80211_regdomain *regd = NULL;
5560 	bool intersect = false;
5561 	int ret = 0, pdev_idx;
5562 	struct ath11k *ar;
5563 
5564 	reg_info = kzalloc(sizeof(*reg_info), GFP_ATOMIC);
5565 	if (!reg_info) {
5566 		ret = -ENOMEM;
5567 		goto fallback;
5568 	}
5569 
5570 	ret = ath11k_pull_reg_chan_list_update_ev(ab, skb, reg_info);
5571 	if (ret) {
5572 		ath11k_warn(ab, "failed to extract regulatory info from received event\n");
5573 		goto fallback;
5574 	}
5575 
5576 	if (reg_info->status_code != REG_SET_CC_STATUS_PASS) {
5577 		/* In case of failure to set the requested ctry,
5578 		 * fw retains the current regd. We print a failure info
5579 		 * and return from here.
5580 		 */
5581 		ath11k_warn(ab, "Failed to set the requested Country regulatory setting\n");
5582 		goto mem_free;
5583 	}
5584 
5585 	pdev_idx = reg_info->phy_id;
5586 
5587 	if (pdev_idx >= ab->num_radios) {
5588 		/* Process the event for phy0 only if single_pdev_only
5589 		 * is true. If pdev_idx is valid but not 0, discard the
5590 		 * event. Otherwise, it goes to fallback.
5591 		 */
5592 		if (ab->hw_params.single_pdev_only &&
5593 		    pdev_idx < ab->hw_params.num_rxmda_per_pdev)
5594 			goto mem_free;
5595 		else
5596 			goto fallback;
5597 	}
5598 
5599 	/* Avoid multiple overwrites to default regd, during core
5600 	 * stop-start after mac registration.
5601 	 */
5602 	if (ab->default_regd[pdev_idx] && !ab->new_regd[pdev_idx] &&
5603 	    !memcmp((char *)ab->default_regd[pdev_idx]->alpha2,
5604 		    (char *)reg_info->alpha2, 2))
5605 		goto mem_free;
5606 
5607 	/* Intersect new rules with default regd if a new country setting was
5608 	 * requested, i.e a default regd was already set during initialization
5609 	 * and the regd coming from this event has a valid country info.
5610 	 */
5611 	if (ab->default_regd[pdev_idx] &&
5612 	    !ath11k_reg_is_world_alpha((char *)
5613 		ab->default_regd[pdev_idx]->alpha2) &&
5614 	    !ath11k_reg_is_world_alpha((char *)reg_info->alpha2))
5615 		intersect = true;
5616 
5617 	regd = ath11k_reg_build_regd(ab, reg_info, intersect);
5618 	if (!regd) {
5619 		ath11k_warn(ab, "failed to build regd from reg_info\n");
5620 		goto fallback;
5621 	}
5622 
5623 	spin_lock(&ab->base_lock);
5624 	if (test_bit(ATH11K_FLAG_REGISTERED, &ab->dev_flags)) {
5625 		/* Once mac is registered, ar is valid and all CC events from
5626 		 * fw is considered to be received due to user requests
5627 		 * currently.
5628 		 * Free previously built regd before assigning the newly
5629 		 * generated regd to ar. NULL pointer handling will be
5630 		 * taken care by kfree itself.
5631 		 */
5632 		ar = ab->pdevs[pdev_idx].ar;
5633 		kfree(ab->new_regd[pdev_idx]);
5634 		ab->new_regd[pdev_idx] = regd;
5635 		ieee80211_queue_work(ar->hw, &ar->regd_update_work);
5636 	} else {
5637 		/* Multiple events for the same *ar is not expected. But we
5638 		 * can still clear any previously stored default_regd if we
5639 		 * are receiving this event for the same radio by mistake.
5640 		 * NULL pointer handling will be taken care by kfree itself.
5641 		 */
5642 		kfree(ab->default_regd[pdev_idx]);
5643 		/* This regd would be applied during mac registration */
5644 		ab->default_regd[pdev_idx] = regd;
5645 	}
5646 	ab->dfs_region = reg_info->dfs_region;
5647 	spin_unlock(&ab->base_lock);
5648 
5649 	goto mem_free;
5650 
5651 fallback:
5652 	/* Fallback to older reg (by sending previous country setting
5653 	 * again if fw has succeded and we failed to process here.
5654 	 * The Regdomain should be uniform across driver and fw. Since the
5655 	 * FW has processed the command and sent a success status, we expect
5656 	 * this function to succeed as well. If it doesn't, CTRY needs to be
5657 	 * reverted at the fw and the old SCAN_CHAN_LIST cmd needs to be sent.
5658 	 */
5659 	/* TODO: This is rare, but still should also be handled */
5660 	WARN_ON(1);
5661 mem_free:
5662 	if (reg_info) {
5663 		kfree(reg_info->reg_rules_2g_ptr);
5664 		kfree(reg_info->reg_rules_5g_ptr);
5665 		kfree(reg_info);
5666 	}
5667 	return ret;
5668 }
5669 
5670 static int ath11k_wmi_tlv_rdy_parse(struct ath11k_base *ab, u16 tag, u16 len,
5671 				    const void *ptr, void *data)
5672 {
5673 	struct wmi_tlv_rdy_parse *rdy_parse = data;
5674 	struct wmi_ready_event fixed_param;
5675 	struct wmi_mac_addr *addr_list;
5676 	struct ath11k_pdev *pdev;
5677 	u32 num_mac_addr;
5678 	int i;
5679 
5680 	switch (tag) {
5681 	case WMI_TAG_READY_EVENT:
5682 		memset(&fixed_param, 0, sizeof(fixed_param));
5683 		memcpy(&fixed_param, (struct wmi_ready_event *)ptr,
5684 		       min_t(u16, sizeof(fixed_param), len));
5685 		ab->wlan_init_status = fixed_param.ready_event_min.status;
5686 		rdy_parse->num_extra_mac_addr =
5687 			fixed_param.ready_event_min.num_extra_mac_addr;
5688 
5689 		ether_addr_copy(ab->mac_addr,
5690 				fixed_param.ready_event_min.mac_addr.addr);
5691 		ab->pktlog_defs_checksum = fixed_param.pktlog_defs_checksum;
5692 		ab->wmi_ready = true;
5693 		break;
5694 	case WMI_TAG_ARRAY_FIXED_STRUCT:
5695 		addr_list = (struct wmi_mac_addr *)ptr;
5696 		num_mac_addr = rdy_parse->num_extra_mac_addr;
5697 
5698 		if (!(ab->num_radios > 1 && num_mac_addr >= ab->num_radios))
5699 			break;
5700 
5701 		for (i = 0; i < ab->num_radios; i++) {
5702 			pdev = &ab->pdevs[i];
5703 			ether_addr_copy(pdev->mac_addr, addr_list[i].addr);
5704 		}
5705 		ab->pdevs_macaddr_valid = true;
5706 		break;
5707 	default:
5708 		break;
5709 	}
5710 
5711 	return 0;
5712 }
5713 
5714 static int ath11k_ready_event(struct ath11k_base *ab, struct sk_buff *skb)
5715 {
5716 	struct wmi_tlv_rdy_parse rdy_parse = { };
5717 	int ret;
5718 
5719 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
5720 				  ath11k_wmi_tlv_rdy_parse, &rdy_parse);
5721 	if (ret) {
5722 		ath11k_warn(ab, "failed to parse tlv %d\n", ret);
5723 		return ret;
5724 	}
5725 
5726 	complete(&ab->wmi_ab.unified_ready);
5727 	return 0;
5728 }
5729 
5730 static void ath11k_peer_delete_resp_event(struct ath11k_base *ab, struct sk_buff *skb)
5731 {
5732 	struct wmi_peer_delete_resp_event peer_del_resp;
5733 	struct ath11k *ar;
5734 
5735 	if (ath11k_pull_peer_del_resp_ev(ab, skb, &peer_del_resp) != 0) {
5736 		ath11k_warn(ab, "failed to extract peer delete resp");
5737 		return;
5738 	}
5739 
5740 	rcu_read_lock();
5741 	ar = ath11k_mac_get_ar_by_vdev_id(ab, peer_del_resp.vdev_id);
5742 	if (!ar) {
5743 		ath11k_warn(ab, "invalid vdev id in peer delete resp ev %d",
5744 			    peer_del_resp.vdev_id);
5745 		rcu_read_unlock();
5746 		return;
5747 	}
5748 
5749 	complete(&ar->peer_delete_done);
5750 	rcu_read_unlock();
5751 	ath11k_dbg(ab, ATH11K_DBG_WMI, "peer delete resp for vdev id %d addr %pM\n",
5752 		   peer_del_resp.vdev_id, peer_del_resp.peer_macaddr.addr);
5753 }
5754 
5755 static void ath11k_vdev_delete_resp_event(struct ath11k_base *ab,
5756 					  struct sk_buff *skb)
5757 {
5758 	struct ath11k *ar;
5759 	u32 vdev_id = 0;
5760 
5761 	if (ath11k_pull_vdev_del_resp_ev(ab, skb, &vdev_id) != 0) {
5762 		ath11k_warn(ab, "failed to extract vdev delete resp");
5763 		return;
5764 	}
5765 
5766 	rcu_read_lock();
5767 	ar = ath11k_mac_get_ar_by_vdev_id(ab, vdev_id);
5768 	if (!ar) {
5769 		ath11k_warn(ab, "invalid vdev id in vdev delete resp ev %d",
5770 			    vdev_id);
5771 		rcu_read_unlock();
5772 		return;
5773 	}
5774 
5775 	complete(&ar->vdev_delete_done);
5776 
5777 	rcu_read_unlock();
5778 
5779 	ath11k_dbg(ab, ATH11K_DBG_WMI, "vdev delete resp for vdev id %d\n",
5780 		   vdev_id);
5781 }
5782 
5783 static inline const char *ath11k_wmi_vdev_resp_print(u32 vdev_resp_status)
5784 {
5785 	switch (vdev_resp_status) {
5786 	case WMI_VDEV_START_RESPONSE_INVALID_VDEVID:
5787 		return "invalid vdev id";
5788 	case WMI_VDEV_START_RESPONSE_NOT_SUPPORTED:
5789 		return "not supported";
5790 	case WMI_VDEV_START_RESPONSE_DFS_VIOLATION:
5791 		return "dfs violation";
5792 	case WMI_VDEV_START_RESPONSE_INVALID_REGDOMAIN:
5793 		return "invalid regdomain";
5794 	default:
5795 		return "unknown";
5796 	}
5797 }
5798 
5799 static void ath11k_vdev_start_resp_event(struct ath11k_base *ab, struct sk_buff *skb)
5800 {
5801 	struct wmi_vdev_start_resp_event vdev_start_resp;
5802 	struct ath11k *ar;
5803 	u32 status;
5804 
5805 	if (ath11k_pull_vdev_start_resp_tlv(ab, skb, &vdev_start_resp) != 0) {
5806 		ath11k_warn(ab, "failed to extract vdev start resp");
5807 		return;
5808 	}
5809 
5810 	rcu_read_lock();
5811 	ar = ath11k_mac_get_ar_by_vdev_id(ab, vdev_start_resp.vdev_id);
5812 	if (!ar) {
5813 		ath11k_warn(ab, "invalid vdev id in vdev start resp ev %d",
5814 			    vdev_start_resp.vdev_id);
5815 		rcu_read_unlock();
5816 		return;
5817 	}
5818 
5819 	ar->last_wmi_vdev_start_status = 0;
5820 
5821 	status = vdev_start_resp.status;
5822 
5823 	if (WARN_ON_ONCE(status)) {
5824 		ath11k_warn(ab, "vdev start resp error status %d (%s)\n",
5825 			    status, ath11k_wmi_vdev_resp_print(status));
5826 		ar->last_wmi_vdev_start_status = status;
5827 	}
5828 
5829 	complete(&ar->vdev_setup_done);
5830 
5831 	rcu_read_unlock();
5832 
5833 	ath11k_dbg(ab, ATH11K_DBG_WMI, "vdev start resp for vdev id %d",
5834 		   vdev_start_resp.vdev_id);
5835 }
5836 
5837 static void ath11k_bcn_tx_status_event(struct ath11k_base *ab, struct sk_buff *skb)
5838 {
5839 	u32 vdev_id, tx_status;
5840 
5841 	if (ath11k_pull_bcn_tx_status_ev(ab, skb->data, skb->len,
5842 					 &vdev_id, &tx_status) != 0) {
5843 		ath11k_warn(ab, "failed to extract bcn tx status");
5844 		return;
5845 	}
5846 }
5847 
5848 static void ath11k_vdev_stopped_event(struct ath11k_base *ab, struct sk_buff *skb)
5849 {
5850 	struct ath11k *ar;
5851 	u32 vdev_id = 0;
5852 
5853 	if (ath11k_pull_vdev_stopped_param_tlv(ab, skb, &vdev_id) != 0) {
5854 		ath11k_warn(ab, "failed to extract vdev stopped event");
5855 		return;
5856 	}
5857 
5858 	rcu_read_lock();
5859 	ar = ath11k_mac_get_ar_by_vdev_id(ab, vdev_id);
5860 	if (!ar) {
5861 		ath11k_warn(ab, "invalid vdev id in vdev stopped ev %d",
5862 			    vdev_id);
5863 		rcu_read_unlock();
5864 		return;
5865 	}
5866 
5867 	complete(&ar->vdev_setup_done);
5868 
5869 	rcu_read_unlock();
5870 
5871 	ath11k_dbg(ab, ATH11K_DBG_WMI, "vdev stopped for vdev id %d", vdev_id);
5872 }
5873 
5874 static void ath11k_mgmt_rx_event(struct ath11k_base *ab, struct sk_buff *skb)
5875 {
5876 	struct mgmt_rx_event_params rx_ev = {0};
5877 	struct ath11k *ar;
5878 	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
5879 	struct ieee80211_hdr *hdr;
5880 	u16 fc;
5881 	struct ieee80211_supported_band *sband;
5882 
5883 	if (ath11k_pull_mgmt_rx_params_tlv(ab, skb, &rx_ev) != 0) {
5884 		ath11k_warn(ab, "failed to extract mgmt rx event");
5885 		dev_kfree_skb(skb);
5886 		return;
5887 	}
5888 
5889 	memset(status, 0, sizeof(*status));
5890 
5891 	ath11k_dbg(ab, ATH11K_DBG_MGMT, "mgmt rx event status %08x\n",
5892 		   rx_ev.status);
5893 
5894 	rcu_read_lock();
5895 	ar = ath11k_mac_get_ar_by_pdev_id(ab, rx_ev.pdev_id);
5896 
5897 	if (!ar) {
5898 		ath11k_warn(ab, "invalid pdev_id %d in mgmt_rx_event\n",
5899 			    rx_ev.pdev_id);
5900 		dev_kfree_skb(skb);
5901 		goto exit;
5902 	}
5903 
5904 	if ((test_bit(ATH11K_CAC_RUNNING, &ar->dev_flags)) ||
5905 	    (rx_ev.status & (WMI_RX_STATUS_ERR_DECRYPT |
5906 	    WMI_RX_STATUS_ERR_KEY_CACHE_MISS | WMI_RX_STATUS_ERR_CRC))) {
5907 		dev_kfree_skb(skb);
5908 		goto exit;
5909 	}
5910 
5911 	if (rx_ev.status & WMI_RX_STATUS_ERR_MIC)
5912 		status->flag |= RX_FLAG_MMIC_ERROR;
5913 
5914 	if (rx_ev.chan_freq >= ATH11K_MIN_6G_FREQ) {
5915 		status->band = NL80211_BAND_6GHZ;
5916 	} else if (rx_ev.channel >= 1 && rx_ev.channel <= 14) {
5917 		status->band = NL80211_BAND_2GHZ;
5918 	} else if (rx_ev.channel >= 36 && rx_ev.channel <= ATH11K_MAX_5G_CHAN) {
5919 		status->band = NL80211_BAND_5GHZ;
5920 	} else {
5921 		/* Shouldn't happen unless list of advertised channels to
5922 		 * mac80211 has been changed.
5923 		 */
5924 		WARN_ON_ONCE(1);
5925 		dev_kfree_skb(skb);
5926 		goto exit;
5927 	}
5928 
5929 	if (rx_ev.phy_mode == MODE_11B &&
5930 	    (status->band == NL80211_BAND_5GHZ || status->band == NL80211_BAND_6GHZ))
5931 		ath11k_dbg(ab, ATH11K_DBG_WMI,
5932 			   "wmi mgmt rx 11b (CCK) on 5/6GHz, band = %d\n", status->band);
5933 
5934 	sband = &ar->mac.sbands[status->band];
5935 
5936 	status->freq = ieee80211_channel_to_frequency(rx_ev.channel,
5937 						      status->band);
5938 	status->signal = rx_ev.snr + ATH11K_DEFAULT_NOISE_FLOOR;
5939 	status->rate_idx = ath11k_mac_bitrate_to_idx(sband, rx_ev.rate / 100);
5940 
5941 	hdr = (struct ieee80211_hdr *)skb->data;
5942 	fc = le16_to_cpu(hdr->frame_control);
5943 
5944 	/* Firmware is guaranteed to report all essential management frames via
5945 	 * WMI while it can deliver some extra via HTT. Since there can be
5946 	 * duplicates split the reporting wrt monitor/sniffing.
5947 	 */
5948 	status->flag |= RX_FLAG_SKIP_MONITOR;
5949 
5950 	/* In case of PMF, FW delivers decrypted frames with Protected Bit set.
5951 	 * Don't clear that. Also, FW delivers broadcast management frames
5952 	 * (ex: group privacy action frames in mesh) as encrypted payload.
5953 	 */
5954 	if (ieee80211_has_protected(hdr->frame_control) &&
5955 	    !is_multicast_ether_addr(ieee80211_get_DA(hdr))) {
5956 		status->flag |= RX_FLAG_DECRYPTED;
5957 
5958 		if (!ieee80211_is_robust_mgmt_frame(skb)) {
5959 			status->flag |= RX_FLAG_IV_STRIPPED |
5960 					RX_FLAG_MMIC_STRIPPED;
5961 			hdr->frame_control = __cpu_to_le16(fc &
5962 					     ~IEEE80211_FCTL_PROTECTED);
5963 		}
5964 	}
5965 
5966 	/* TODO: Pending handle beacon implementation
5967 	 *if (ieee80211_is_beacon(hdr->frame_control))
5968 	 *	ath11k_mac_handle_beacon(ar, skb);
5969 	 */
5970 
5971 	ath11k_dbg(ab, ATH11K_DBG_MGMT,
5972 		   "event mgmt rx skb %pK len %d ftype %02x stype %02x\n",
5973 		   skb, skb->len,
5974 		   fc & IEEE80211_FCTL_FTYPE, fc & IEEE80211_FCTL_STYPE);
5975 
5976 	ath11k_dbg(ab, ATH11K_DBG_MGMT,
5977 		   "event mgmt rx freq %d band %d snr %d, rate_idx %d\n",
5978 		   status->freq, status->band, status->signal,
5979 		   status->rate_idx);
5980 
5981 	ieee80211_rx_ni(ar->hw, skb);
5982 
5983 exit:
5984 	rcu_read_unlock();
5985 }
5986 
5987 static void ath11k_mgmt_tx_compl_event(struct ath11k_base *ab, struct sk_buff *skb)
5988 {
5989 	struct wmi_mgmt_tx_compl_event tx_compl_param = {0};
5990 	struct ath11k *ar;
5991 
5992 	if (ath11k_pull_mgmt_tx_compl_param_tlv(ab, skb, &tx_compl_param) != 0) {
5993 		ath11k_warn(ab, "failed to extract mgmt tx compl event");
5994 		return;
5995 	}
5996 
5997 	rcu_read_lock();
5998 	ar = ath11k_mac_get_ar_by_pdev_id(ab, tx_compl_param.pdev_id);
5999 	if (!ar) {
6000 		ath11k_warn(ab, "invalid pdev id %d in mgmt_tx_compl_event\n",
6001 			    tx_compl_param.pdev_id);
6002 		goto exit;
6003 	}
6004 
6005 	wmi_process_mgmt_tx_comp(ar, tx_compl_param.desc_id,
6006 				 tx_compl_param.status);
6007 
6008 	ath11k_dbg(ab, ATH11K_DBG_MGMT,
6009 		   "mgmt tx compl ev pdev_id %d, desc_id %d, status %d",
6010 		   tx_compl_param.pdev_id, tx_compl_param.desc_id,
6011 		   tx_compl_param.status);
6012 
6013 exit:
6014 	rcu_read_unlock();
6015 }
6016 
6017 static struct ath11k *ath11k_get_ar_on_scan_abort(struct ath11k_base *ab,
6018 						  u32 vdev_id)
6019 {
6020 	int i;
6021 	struct ath11k_pdev *pdev;
6022 	struct ath11k *ar;
6023 
6024 	for (i = 0; i < ab->num_radios; i++) {
6025 		pdev = rcu_dereference(ab->pdevs_active[i]);
6026 		if (pdev && pdev->ar) {
6027 			ar = pdev->ar;
6028 
6029 			spin_lock_bh(&ar->data_lock);
6030 			if (ar->scan.state == ATH11K_SCAN_ABORTING &&
6031 			    ar->scan.vdev_id == vdev_id) {
6032 				spin_unlock_bh(&ar->data_lock);
6033 				return ar;
6034 			}
6035 			spin_unlock_bh(&ar->data_lock);
6036 		}
6037 	}
6038 	return NULL;
6039 }
6040 
6041 static void ath11k_scan_event(struct ath11k_base *ab, struct sk_buff *skb)
6042 {
6043 	struct ath11k *ar;
6044 	struct wmi_scan_event scan_ev = {0};
6045 
6046 	if (ath11k_pull_scan_ev(ab, skb, &scan_ev) != 0) {
6047 		ath11k_warn(ab, "failed to extract scan event");
6048 		return;
6049 	}
6050 
6051 	rcu_read_lock();
6052 
6053 	/* In case the scan was cancelled, ex. during interface teardown,
6054 	 * the interface will not be found in active interfaces.
6055 	 * Rather, in such scenarios, iterate over the active pdev's to
6056 	 * search 'ar' if the corresponding 'ar' scan is ABORTING and the
6057 	 * aborting scan's vdev id matches this event info.
6058 	 */
6059 	if (scan_ev.event_type == WMI_SCAN_EVENT_COMPLETED &&
6060 	    scan_ev.reason == WMI_SCAN_REASON_CANCELLED)
6061 		ar = ath11k_get_ar_on_scan_abort(ab, scan_ev.vdev_id);
6062 	else
6063 		ar = ath11k_mac_get_ar_by_vdev_id(ab, scan_ev.vdev_id);
6064 
6065 	if (!ar) {
6066 		ath11k_warn(ab, "Received scan event for unknown vdev");
6067 		rcu_read_unlock();
6068 		return;
6069 	}
6070 
6071 	spin_lock_bh(&ar->data_lock);
6072 
6073 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6074 		   "scan event %s type %d reason %d freq %d req_id %d scan_id %d vdev_id %d state %s (%d)\n",
6075 		   ath11k_wmi_event_scan_type_str(scan_ev.event_type, scan_ev.reason),
6076 		   scan_ev.event_type, scan_ev.reason, scan_ev.channel_freq,
6077 		   scan_ev.scan_req_id, scan_ev.scan_id, scan_ev.vdev_id,
6078 		   ath11k_scan_state_str(ar->scan.state), ar->scan.state);
6079 
6080 	switch (scan_ev.event_type) {
6081 	case WMI_SCAN_EVENT_STARTED:
6082 		ath11k_wmi_event_scan_started(ar);
6083 		break;
6084 	case WMI_SCAN_EVENT_COMPLETED:
6085 		ath11k_wmi_event_scan_completed(ar);
6086 		break;
6087 	case WMI_SCAN_EVENT_BSS_CHANNEL:
6088 		ath11k_wmi_event_scan_bss_chan(ar);
6089 		break;
6090 	case WMI_SCAN_EVENT_FOREIGN_CHAN:
6091 		ath11k_wmi_event_scan_foreign_chan(ar, scan_ev.channel_freq);
6092 		break;
6093 	case WMI_SCAN_EVENT_START_FAILED:
6094 		ath11k_warn(ab, "received scan start failure event\n");
6095 		ath11k_wmi_event_scan_start_failed(ar);
6096 		break;
6097 	case WMI_SCAN_EVENT_DEQUEUED:
6098 	case WMI_SCAN_EVENT_PREEMPTED:
6099 	case WMI_SCAN_EVENT_RESTARTED:
6100 	case WMI_SCAN_EVENT_FOREIGN_CHAN_EXIT:
6101 	default:
6102 		break;
6103 	}
6104 
6105 	spin_unlock_bh(&ar->data_lock);
6106 
6107 	rcu_read_unlock();
6108 }
6109 
6110 static void ath11k_peer_sta_kickout_event(struct ath11k_base *ab, struct sk_buff *skb)
6111 {
6112 	struct wmi_peer_sta_kickout_arg arg = {};
6113 	struct ieee80211_sta *sta;
6114 	struct ath11k_peer *peer;
6115 	struct ath11k *ar;
6116 
6117 	if (ath11k_pull_peer_sta_kickout_ev(ab, skb, &arg) != 0) {
6118 		ath11k_warn(ab, "failed to extract peer sta kickout event");
6119 		return;
6120 	}
6121 
6122 	rcu_read_lock();
6123 
6124 	spin_lock_bh(&ab->base_lock);
6125 
6126 	peer = ath11k_peer_find_by_addr(ab, arg.mac_addr);
6127 
6128 	if (!peer) {
6129 		ath11k_warn(ab, "peer not found %pM\n",
6130 			    arg.mac_addr);
6131 		goto exit;
6132 	}
6133 
6134 	ar = ath11k_mac_get_ar_by_vdev_id(ab, peer->vdev_id);
6135 	if (!ar) {
6136 		ath11k_warn(ab, "invalid vdev id in peer sta kickout ev %d",
6137 			    peer->vdev_id);
6138 		goto exit;
6139 	}
6140 
6141 	sta = ieee80211_find_sta_by_ifaddr(ar->hw,
6142 					   arg.mac_addr, NULL);
6143 	if (!sta) {
6144 		ath11k_warn(ab, "Spurious quick kickout for STA %pM\n",
6145 			    arg.mac_addr);
6146 		goto exit;
6147 	}
6148 
6149 	ath11k_dbg(ab, ATH11K_DBG_WMI, "peer sta kickout event %pM",
6150 		   arg.mac_addr);
6151 
6152 	ieee80211_report_low_ack(sta, 10);
6153 
6154 exit:
6155 	spin_unlock_bh(&ab->base_lock);
6156 	rcu_read_unlock();
6157 }
6158 
6159 static void ath11k_roam_event(struct ath11k_base *ab, struct sk_buff *skb)
6160 {
6161 	struct wmi_roam_event roam_ev = {};
6162 	struct ath11k *ar;
6163 
6164 	if (ath11k_pull_roam_ev(ab, skb, &roam_ev) != 0) {
6165 		ath11k_warn(ab, "failed to extract roam event");
6166 		return;
6167 	}
6168 
6169 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6170 		   "wmi roam event vdev %u reason 0x%08x rssi %d\n",
6171 		   roam_ev.vdev_id, roam_ev.reason, roam_ev.rssi);
6172 
6173 	rcu_read_lock();
6174 	ar = ath11k_mac_get_ar_by_vdev_id(ab, roam_ev.vdev_id);
6175 	if (!ar) {
6176 		ath11k_warn(ab, "invalid vdev id in roam ev %d",
6177 			    roam_ev.vdev_id);
6178 		rcu_read_unlock();
6179 		return;
6180 	}
6181 
6182 	if (roam_ev.reason >= WMI_ROAM_REASON_MAX)
6183 		ath11k_warn(ab, "ignoring unknown roam event reason %d on vdev %i\n",
6184 			    roam_ev.reason, roam_ev.vdev_id);
6185 
6186 	switch (roam_ev.reason) {
6187 	case WMI_ROAM_REASON_BEACON_MISS:
6188 		/* TODO: Pending beacon miss and connection_loss_work
6189 		 * implementation
6190 		 * ath11k_mac_handle_beacon_miss(ar, vdev_id);
6191 		 */
6192 		break;
6193 	case WMI_ROAM_REASON_BETTER_AP:
6194 	case WMI_ROAM_REASON_LOW_RSSI:
6195 	case WMI_ROAM_REASON_SUITABLE_AP_FOUND:
6196 	case WMI_ROAM_REASON_HO_FAILED:
6197 		ath11k_warn(ab, "ignoring not implemented roam event reason %d on vdev %i\n",
6198 			    roam_ev.reason, roam_ev.vdev_id);
6199 		break;
6200 	}
6201 
6202 	rcu_read_unlock();
6203 }
6204 
6205 static void ath11k_chan_info_event(struct ath11k_base *ab, struct sk_buff *skb)
6206 {
6207 	struct wmi_chan_info_event ch_info_ev = {0};
6208 	struct ath11k *ar;
6209 	struct survey_info *survey;
6210 	int idx;
6211 	/* HW channel counters frequency value in hertz */
6212 	u32 cc_freq_hz = ab->cc_freq_hz;
6213 
6214 	if (ath11k_pull_chan_info_ev(ab, skb->data, skb->len, &ch_info_ev) != 0) {
6215 		ath11k_warn(ab, "failed to extract chan info event");
6216 		return;
6217 	}
6218 
6219 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6220 		   "chan info vdev_id %d err_code %d freq %d cmd_flags %d noise_floor %d rx_clear_count %d cycle_count %d mac_clk_mhz %d\n",
6221 		   ch_info_ev.vdev_id, ch_info_ev.err_code, ch_info_ev.freq,
6222 		   ch_info_ev.cmd_flags, ch_info_ev.noise_floor,
6223 		   ch_info_ev.rx_clear_count, ch_info_ev.cycle_count,
6224 		   ch_info_ev.mac_clk_mhz);
6225 
6226 	if (ch_info_ev.cmd_flags == WMI_CHAN_INFO_END_RESP) {
6227 		ath11k_dbg(ab, ATH11K_DBG_WMI, "chan info report completed\n");
6228 		return;
6229 	}
6230 
6231 	rcu_read_lock();
6232 	ar = ath11k_mac_get_ar_by_vdev_id(ab, ch_info_ev.vdev_id);
6233 	if (!ar) {
6234 		ath11k_warn(ab, "invalid vdev id in chan info ev %d",
6235 			    ch_info_ev.vdev_id);
6236 		rcu_read_unlock();
6237 		return;
6238 	}
6239 	spin_lock_bh(&ar->data_lock);
6240 
6241 	switch (ar->scan.state) {
6242 	case ATH11K_SCAN_IDLE:
6243 	case ATH11K_SCAN_STARTING:
6244 		ath11k_warn(ab, "received chan info event without a scan request, ignoring\n");
6245 		goto exit;
6246 	case ATH11K_SCAN_RUNNING:
6247 	case ATH11K_SCAN_ABORTING:
6248 		break;
6249 	}
6250 
6251 	idx = freq_to_idx(ar, ch_info_ev.freq);
6252 	if (idx >= ARRAY_SIZE(ar->survey)) {
6253 		ath11k_warn(ab, "chan info: invalid frequency %d (idx %d out of bounds)\n",
6254 			    ch_info_ev.freq, idx);
6255 		goto exit;
6256 	}
6257 
6258 	/* If FW provides MAC clock frequency in Mhz, overriding the initialized
6259 	 * HW channel counters frequency value
6260 	 */
6261 	if (ch_info_ev.mac_clk_mhz)
6262 		cc_freq_hz = (ch_info_ev.mac_clk_mhz * 1000);
6263 
6264 	if (ch_info_ev.cmd_flags == WMI_CHAN_INFO_START_RESP) {
6265 		survey = &ar->survey[idx];
6266 		memset(survey, 0, sizeof(*survey));
6267 		survey->noise = ch_info_ev.noise_floor;
6268 		survey->filled = SURVEY_INFO_NOISE_DBM | SURVEY_INFO_TIME |
6269 				 SURVEY_INFO_TIME_BUSY;
6270 		survey->time = div_u64(ch_info_ev.cycle_count, cc_freq_hz);
6271 		survey->time_busy = div_u64(ch_info_ev.rx_clear_count, cc_freq_hz);
6272 	}
6273 exit:
6274 	spin_unlock_bh(&ar->data_lock);
6275 	rcu_read_unlock();
6276 }
6277 
6278 static void
6279 ath11k_pdev_bss_chan_info_event(struct ath11k_base *ab, struct sk_buff *skb)
6280 {
6281 	struct wmi_pdev_bss_chan_info_event bss_ch_info_ev = {};
6282 	struct survey_info *survey;
6283 	struct ath11k *ar;
6284 	u32 cc_freq_hz = ab->cc_freq_hz;
6285 	u64 busy, total, tx, rx, rx_bss;
6286 	int idx;
6287 
6288 	if (ath11k_pull_pdev_bss_chan_info_ev(ab, skb, &bss_ch_info_ev) != 0) {
6289 		ath11k_warn(ab, "failed to extract pdev bss chan info event");
6290 		return;
6291 	}
6292 
6293 	busy = (u64)(bss_ch_info_ev.rx_clear_count_high) << 32 |
6294 			bss_ch_info_ev.rx_clear_count_low;
6295 
6296 	total = (u64)(bss_ch_info_ev.cycle_count_high) << 32 |
6297 			bss_ch_info_ev.cycle_count_low;
6298 
6299 	tx = (u64)(bss_ch_info_ev.tx_cycle_count_high) << 32 |
6300 			bss_ch_info_ev.tx_cycle_count_low;
6301 
6302 	rx = (u64)(bss_ch_info_ev.rx_cycle_count_high) << 32 |
6303 			bss_ch_info_ev.rx_cycle_count_low;
6304 
6305 	rx_bss = (u64)(bss_ch_info_ev.rx_bss_cycle_count_high) << 32 |
6306 			bss_ch_info_ev.rx_bss_cycle_count_low;
6307 
6308 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6309 		   "pdev bss chan info:\n pdev_id: %d freq: %d noise: %d cycle: busy %llu total %llu tx %llu rx %llu rx_bss %llu\n",
6310 		   bss_ch_info_ev.pdev_id, bss_ch_info_ev.freq,
6311 		   bss_ch_info_ev.noise_floor, busy, total,
6312 		   tx, rx, rx_bss);
6313 
6314 	rcu_read_lock();
6315 	ar = ath11k_mac_get_ar_by_pdev_id(ab, bss_ch_info_ev.pdev_id);
6316 
6317 	if (!ar) {
6318 		ath11k_warn(ab, "invalid pdev id %d in bss_chan_info event\n",
6319 			    bss_ch_info_ev.pdev_id);
6320 		rcu_read_unlock();
6321 		return;
6322 	}
6323 
6324 	spin_lock_bh(&ar->data_lock);
6325 	idx = freq_to_idx(ar, bss_ch_info_ev.freq);
6326 	if (idx >= ARRAY_SIZE(ar->survey)) {
6327 		ath11k_warn(ab, "bss chan info: invalid frequency %d (idx %d out of bounds)\n",
6328 			    bss_ch_info_ev.freq, idx);
6329 		goto exit;
6330 	}
6331 
6332 	survey = &ar->survey[idx];
6333 
6334 	survey->noise     = bss_ch_info_ev.noise_floor;
6335 	survey->time      = div_u64(total, cc_freq_hz);
6336 	survey->time_busy = div_u64(busy, cc_freq_hz);
6337 	survey->time_rx   = div_u64(rx_bss, cc_freq_hz);
6338 	survey->time_tx   = div_u64(tx, cc_freq_hz);
6339 	survey->filled   |= (SURVEY_INFO_NOISE_DBM |
6340 			     SURVEY_INFO_TIME |
6341 			     SURVEY_INFO_TIME_BUSY |
6342 			     SURVEY_INFO_TIME_RX |
6343 			     SURVEY_INFO_TIME_TX);
6344 exit:
6345 	spin_unlock_bh(&ar->data_lock);
6346 	complete(&ar->bss_survey_done);
6347 
6348 	rcu_read_unlock();
6349 }
6350 
6351 static void ath11k_vdev_install_key_compl_event(struct ath11k_base *ab,
6352 						struct sk_buff *skb)
6353 {
6354 	struct wmi_vdev_install_key_complete_arg install_key_compl = {0};
6355 	struct ath11k *ar;
6356 
6357 	if (ath11k_pull_vdev_install_key_compl_ev(ab, skb, &install_key_compl) != 0) {
6358 		ath11k_warn(ab, "failed to extract install key compl event");
6359 		return;
6360 	}
6361 
6362 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6363 		   "vdev install key ev idx %d flags %08x macaddr %pM status %d\n",
6364 		   install_key_compl.key_idx, install_key_compl.key_flags,
6365 		   install_key_compl.macaddr, install_key_compl.status);
6366 
6367 	rcu_read_lock();
6368 	ar = ath11k_mac_get_ar_by_vdev_id(ab, install_key_compl.vdev_id);
6369 	if (!ar) {
6370 		ath11k_warn(ab, "invalid vdev id in install key compl ev %d",
6371 			    install_key_compl.vdev_id);
6372 		rcu_read_unlock();
6373 		return;
6374 	}
6375 
6376 	ar->install_key_status = 0;
6377 
6378 	if (install_key_compl.status != WMI_VDEV_INSTALL_KEY_COMPL_STATUS_SUCCESS) {
6379 		ath11k_warn(ab, "install key failed for %pM status %d\n",
6380 			    install_key_compl.macaddr, install_key_compl.status);
6381 		ar->install_key_status = install_key_compl.status;
6382 	}
6383 
6384 	complete(&ar->install_key_done);
6385 	rcu_read_unlock();
6386 }
6387 
6388 static void ath11k_service_available_event(struct ath11k_base *ab, struct sk_buff *skb)
6389 {
6390 	const void **tb;
6391 	const struct wmi_service_available_event *ev;
6392 	int ret;
6393 	int i, j;
6394 
6395 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6396 	if (IS_ERR(tb)) {
6397 		ret = PTR_ERR(tb);
6398 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
6399 		return;
6400 	}
6401 
6402 	ev = tb[WMI_TAG_SERVICE_AVAILABLE_EVENT];
6403 	if (!ev) {
6404 		ath11k_warn(ab, "failed to fetch svc available ev");
6405 		kfree(tb);
6406 		return;
6407 	}
6408 
6409 	/* TODO: Use wmi_service_segment_offset information to get the service
6410 	 * especially when more services are advertised in multiple sevice
6411 	 * available events.
6412 	 */
6413 	for (i = 0, j = WMI_MAX_SERVICE;
6414 	     i < WMI_SERVICE_SEGMENT_BM_SIZE32 && j < WMI_MAX_EXT_SERVICE;
6415 	     i++) {
6416 		do {
6417 			if (ev->wmi_service_segment_bitmap[i] &
6418 			    BIT(j % WMI_AVAIL_SERVICE_BITS_IN_SIZE32))
6419 				set_bit(j, ab->wmi_ab.svc_map);
6420 		} while (++j % WMI_AVAIL_SERVICE_BITS_IN_SIZE32);
6421 	}
6422 
6423 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6424 		   "wmi_ext_service_bitmap 0:0x%x, 1:0x%x, 2:0x%x, 3:0x%x",
6425 		   ev->wmi_service_segment_bitmap[0], ev->wmi_service_segment_bitmap[1],
6426 		   ev->wmi_service_segment_bitmap[2], ev->wmi_service_segment_bitmap[3]);
6427 
6428 	kfree(tb);
6429 }
6430 
6431 static void ath11k_peer_assoc_conf_event(struct ath11k_base *ab, struct sk_buff *skb)
6432 {
6433 	struct wmi_peer_assoc_conf_arg peer_assoc_conf = {0};
6434 	struct ath11k *ar;
6435 
6436 	if (ath11k_pull_peer_assoc_conf_ev(ab, skb, &peer_assoc_conf) != 0) {
6437 		ath11k_warn(ab, "failed to extract peer assoc conf event");
6438 		return;
6439 	}
6440 
6441 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6442 		   "peer assoc conf ev vdev id %d macaddr %pM\n",
6443 		   peer_assoc_conf.vdev_id, peer_assoc_conf.macaddr);
6444 
6445 	rcu_read_lock();
6446 	ar = ath11k_mac_get_ar_by_vdev_id(ab, peer_assoc_conf.vdev_id);
6447 
6448 	if (!ar) {
6449 		ath11k_warn(ab, "invalid vdev id in peer assoc conf ev %d",
6450 			    peer_assoc_conf.vdev_id);
6451 		rcu_read_unlock();
6452 		return;
6453 	}
6454 
6455 	complete(&ar->peer_assoc_done);
6456 	rcu_read_unlock();
6457 }
6458 
6459 static void ath11k_update_stats_event(struct ath11k_base *ab, struct sk_buff *skb)
6460 {
6461 	ath11k_debugfs_fw_stats_process(ab, skb);
6462 }
6463 
6464 /* PDEV_CTL_FAILSAFE_CHECK_EVENT is received from FW when the frequency scanned
6465  * is not part of BDF CTL(Conformance test limits) table entries.
6466  */
6467 static void ath11k_pdev_ctl_failsafe_check_event(struct ath11k_base *ab,
6468 						 struct sk_buff *skb)
6469 {
6470 	const void **tb;
6471 	const struct wmi_pdev_ctl_failsafe_chk_event *ev;
6472 	int ret;
6473 
6474 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6475 	if (IS_ERR(tb)) {
6476 		ret = PTR_ERR(tb);
6477 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
6478 		return;
6479 	}
6480 
6481 	ev = tb[WMI_TAG_PDEV_CTL_FAILSAFE_CHECK_EVENT];
6482 	if (!ev) {
6483 		ath11k_warn(ab, "failed to fetch pdev ctl failsafe check ev");
6484 		kfree(tb);
6485 		return;
6486 	}
6487 
6488 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6489 		   "pdev ctl failsafe check ev status %d\n",
6490 		   ev->ctl_failsafe_status);
6491 
6492 	/* If ctl_failsafe_status is set to 1 FW will max out the Transmit power
6493 	 * to 10 dBm else the CTL power entry in the BDF would be picked up.
6494 	 */
6495 	if (ev->ctl_failsafe_status != 0)
6496 		ath11k_warn(ab, "pdev ctl failsafe failure status %d",
6497 			    ev->ctl_failsafe_status);
6498 
6499 	kfree(tb);
6500 }
6501 
6502 static void
6503 ath11k_wmi_process_csa_switch_count_event(struct ath11k_base *ab,
6504 					  const struct wmi_pdev_csa_switch_ev *ev,
6505 					  const u32 *vdev_ids)
6506 {
6507 	int i;
6508 	struct ath11k_vif *arvif;
6509 
6510 	/* Finish CSA once the switch count becomes NULL */
6511 	if (ev->current_switch_count)
6512 		return;
6513 
6514 	rcu_read_lock();
6515 	for (i = 0; i < ev->num_vdevs; i++) {
6516 		arvif = ath11k_mac_get_arvif_by_vdev_id(ab, vdev_ids[i]);
6517 
6518 		if (!arvif) {
6519 			ath11k_warn(ab, "Recvd csa status for unknown vdev %d",
6520 				    vdev_ids[i]);
6521 			continue;
6522 		}
6523 
6524 		if (arvif->is_up && arvif->vif->csa_active)
6525 			ieee80211_csa_finish(arvif->vif);
6526 	}
6527 	rcu_read_unlock();
6528 }
6529 
6530 static void
6531 ath11k_wmi_pdev_csa_switch_count_status_event(struct ath11k_base *ab,
6532 					      struct sk_buff *skb)
6533 {
6534 	const void **tb;
6535 	const struct wmi_pdev_csa_switch_ev *ev;
6536 	const u32 *vdev_ids;
6537 	int ret;
6538 
6539 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6540 	if (IS_ERR(tb)) {
6541 		ret = PTR_ERR(tb);
6542 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
6543 		return;
6544 	}
6545 
6546 	ev = tb[WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT];
6547 	vdev_ids = tb[WMI_TAG_ARRAY_UINT32];
6548 
6549 	if (!ev || !vdev_ids) {
6550 		ath11k_warn(ab, "failed to fetch pdev csa switch count ev");
6551 		kfree(tb);
6552 		return;
6553 	}
6554 
6555 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6556 		   "pdev csa switch count %d for pdev %d, num_vdevs %d",
6557 		   ev->current_switch_count, ev->pdev_id,
6558 		   ev->num_vdevs);
6559 
6560 	ath11k_wmi_process_csa_switch_count_event(ab, ev, vdev_ids);
6561 
6562 	kfree(tb);
6563 }
6564 
6565 static void
6566 ath11k_wmi_pdev_dfs_radar_detected_event(struct ath11k_base *ab, struct sk_buff *skb)
6567 {
6568 	const void **tb;
6569 	const struct wmi_pdev_radar_ev *ev;
6570 	struct ath11k *ar;
6571 	int ret;
6572 
6573 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6574 	if (IS_ERR(tb)) {
6575 		ret = PTR_ERR(tb);
6576 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
6577 		return;
6578 	}
6579 
6580 	ev = tb[WMI_TAG_PDEV_DFS_RADAR_DETECTION_EVENT];
6581 
6582 	if (!ev) {
6583 		ath11k_warn(ab, "failed to fetch pdev dfs radar detected ev");
6584 		kfree(tb);
6585 		return;
6586 	}
6587 
6588 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6589 		   "pdev dfs radar detected on pdev %d, detection mode %d, chan freq %d, chan_width %d, detector id %d, seg id %d, timestamp %d, chirp %d, freq offset %d, sidx %d",
6590 		   ev->pdev_id, ev->detection_mode, ev->chan_freq, ev->chan_width,
6591 		   ev->detector_id, ev->segment_id, ev->timestamp, ev->is_chirp,
6592 		   ev->freq_offset, ev->sidx);
6593 
6594 	ar = ath11k_mac_get_ar_by_pdev_id(ab, ev->pdev_id);
6595 
6596 	if (!ar) {
6597 		ath11k_warn(ab, "radar detected in invalid pdev %d\n",
6598 			    ev->pdev_id);
6599 		goto exit;
6600 	}
6601 
6602 	ath11k_dbg(ar->ab, ATH11K_DBG_REG, "DFS Radar Detected in pdev %d\n",
6603 		   ev->pdev_id);
6604 
6605 	if (ar->dfs_block_radar_events)
6606 		ath11k_info(ab, "DFS Radar detected, but ignored as requested\n");
6607 	else
6608 		ieee80211_radar_detected(ar->hw);
6609 
6610 exit:
6611 	kfree(tb);
6612 }
6613 
6614 static void
6615 ath11k_wmi_pdev_temperature_event(struct ath11k_base *ab,
6616 				  struct sk_buff *skb)
6617 {
6618 	struct ath11k *ar;
6619 	struct wmi_pdev_temperature_event ev = {0};
6620 
6621 	if (ath11k_pull_pdev_temp_ev(ab, skb->data, skb->len, &ev) != 0) {
6622 		ath11k_warn(ab, "failed to extract pdev temperature event");
6623 		return;
6624 	}
6625 
6626 	ath11k_dbg(ab, ATH11K_DBG_WMI,
6627 		   "pdev temperature ev temp %d pdev_id %d\n", ev.temp, ev.pdev_id);
6628 
6629 	ar = ath11k_mac_get_ar_by_pdev_id(ab, ev.pdev_id);
6630 	if (!ar) {
6631 		ath11k_warn(ab, "invalid pdev id in pdev temperature ev %d", ev.pdev_id);
6632 		return;
6633 	}
6634 
6635 	ath11k_thermal_event_temperature(ar, ev.temp);
6636 }
6637 
6638 static void ath11k_fils_discovery_event(struct ath11k_base *ab,
6639 					struct sk_buff *skb)
6640 {
6641 	const void **tb;
6642 	const struct wmi_fils_discovery_event *ev;
6643 	int ret;
6644 
6645 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6646 	if (IS_ERR(tb)) {
6647 		ret = PTR_ERR(tb);
6648 		ath11k_warn(ab,
6649 			    "failed to parse FILS discovery event tlv %d\n",
6650 			    ret);
6651 		return;
6652 	}
6653 
6654 	ev = tb[WMI_TAG_HOST_SWFDA_EVENT];
6655 	if (!ev) {
6656 		ath11k_warn(ab, "failed to fetch FILS discovery event\n");
6657 		kfree(tb);
6658 		return;
6659 	}
6660 
6661 	ath11k_warn(ab,
6662 		    "FILS discovery frame expected from host for vdev_id: %u, transmission scheduled at %u, next TBTT: %u\n",
6663 		    ev->vdev_id, ev->fils_tt, ev->tbtt);
6664 
6665 	kfree(tb);
6666 }
6667 
6668 static void ath11k_probe_resp_tx_status_event(struct ath11k_base *ab,
6669 					      struct sk_buff *skb)
6670 {
6671 	const void **tb;
6672 	const struct wmi_probe_resp_tx_status_event *ev;
6673 	int ret;
6674 
6675 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
6676 	if (IS_ERR(tb)) {
6677 		ret = PTR_ERR(tb);
6678 		ath11k_warn(ab,
6679 			    "failed to parse probe response transmission status event tlv: %d\n",
6680 			    ret);
6681 		return;
6682 	}
6683 
6684 	ev = tb[WMI_TAG_OFFLOAD_PRB_RSP_TX_STATUS_EVENT];
6685 	if (!ev) {
6686 		ath11k_warn(ab,
6687 			    "failed to fetch probe response transmission status event");
6688 		kfree(tb);
6689 		return;
6690 	}
6691 
6692 	if (ev->tx_status)
6693 		ath11k_warn(ab,
6694 			    "Probe response transmission failed for vdev_id %u, status %u\n",
6695 			    ev->vdev_id, ev->tx_status);
6696 
6697 	kfree(tb);
6698 }
6699 
6700 static void ath11k_wmi_tlv_op_rx(struct ath11k_base *ab, struct sk_buff *skb)
6701 {
6702 	struct wmi_cmd_hdr *cmd_hdr;
6703 	enum wmi_tlv_event_id id;
6704 
6705 	cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
6706 	id = FIELD_GET(WMI_CMD_HDR_CMD_ID, (cmd_hdr->cmd_id));
6707 
6708 	if (skb_pull(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
6709 		goto out;
6710 
6711 	switch (id) {
6712 		/* Process all the WMI events here */
6713 	case WMI_SERVICE_READY_EVENTID:
6714 		ath11k_service_ready_event(ab, skb);
6715 		break;
6716 	case WMI_SERVICE_READY_EXT_EVENTID:
6717 		ath11k_service_ready_ext_event(ab, skb);
6718 		break;
6719 	case WMI_SERVICE_READY_EXT2_EVENTID:
6720 		ath11k_service_ready_ext2_event(ab, skb);
6721 		break;
6722 	case WMI_REG_CHAN_LIST_CC_EVENTID:
6723 		ath11k_reg_chan_list_event(ab, skb);
6724 		break;
6725 	case WMI_READY_EVENTID:
6726 		ath11k_ready_event(ab, skb);
6727 		break;
6728 	case WMI_PEER_DELETE_RESP_EVENTID:
6729 		ath11k_peer_delete_resp_event(ab, skb);
6730 		break;
6731 	case WMI_VDEV_START_RESP_EVENTID:
6732 		ath11k_vdev_start_resp_event(ab, skb);
6733 		break;
6734 	case WMI_OFFLOAD_BCN_TX_STATUS_EVENTID:
6735 		ath11k_bcn_tx_status_event(ab, skb);
6736 		break;
6737 	case WMI_VDEV_STOPPED_EVENTID:
6738 		ath11k_vdev_stopped_event(ab, skb);
6739 		break;
6740 	case WMI_MGMT_RX_EVENTID:
6741 		ath11k_mgmt_rx_event(ab, skb);
6742 		/* mgmt_rx_event() owns the skb now! */
6743 		return;
6744 	case WMI_MGMT_TX_COMPLETION_EVENTID:
6745 		ath11k_mgmt_tx_compl_event(ab, skb);
6746 		break;
6747 	case WMI_SCAN_EVENTID:
6748 		ath11k_scan_event(ab, skb);
6749 		break;
6750 	case WMI_PEER_STA_KICKOUT_EVENTID:
6751 		ath11k_peer_sta_kickout_event(ab, skb);
6752 		break;
6753 	case WMI_ROAM_EVENTID:
6754 		ath11k_roam_event(ab, skb);
6755 		break;
6756 	case WMI_CHAN_INFO_EVENTID:
6757 		ath11k_chan_info_event(ab, skb);
6758 		break;
6759 	case WMI_PDEV_BSS_CHAN_INFO_EVENTID:
6760 		ath11k_pdev_bss_chan_info_event(ab, skb);
6761 		break;
6762 	case WMI_VDEV_INSTALL_KEY_COMPLETE_EVENTID:
6763 		ath11k_vdev_install_key_compl_event(ab, skb);
6764 		break;
6765 	case WMI_SERVICE_AVAILABLE_EVENTID:
6766 		ath11k_service_available_event(ab, skb);
6767 		break;
6768 	case WMI_PEER_ASSOC_CONF_EVENTID:
6769 		ath11k_peer_assoc_conf_event(ab, skb);
6770 		break;
6771 	case WMI_UPDATE_STATS_EVENTID:
6772 		ath11k_update_stats_event(ab, skb);
6773 		break;
6774 	case WMI_PDEV_CTL_FAILSAFE_CHECK_EVENTID:
6775 		ath11k_pdev_ctl_failsafe_check_event(ab, skb);
6776 		break;
6777 	case WMI_PDEV_CSA_SWITCH_COUNT_STATUS_EVENTID:
6778 		ath11k_wmi_pdev_csa_switch_count_status_event(ab, skb);
6779 		break;
6780 	case WMI_PDEV_TEMPERATURE_EVENTID:
6781 		ath11k_wmi_pdev_temperature_event(ab, skb);
6782 		break;
6783 	case WMI_PDEV_DMA_RING_BUF_RELEASE_EVENTID:
6784 		ath11k_wmi_pdev_dma_ring_buf_release_event(ab, skb);
6785 		break;
6786 	case WMI_HOST_FILS_DISCOVERY_EVENTID:
6787 		ath11k_fils_discovery_event(ab, skb);
6788 		break;
6789 	case WMI_OFFLOAD_PROB_RESP_TX_STATUS_EVENTID:
6790 		ath11k_probe_resp_tx_status_event(ab, skb);
6791 		break;
6792 	/* add Unsupported events here */
6793 	case WMI_TBTTOFFSET_EXT_UPDATE_EVENTID:
6794 	case WMI_PEER_OPER_MODE_CHANGE_EVENTID:
6795 	case WMI_TWT_ENABLE_EVENTID:
6796 	case WMI_TWT_DISABLE_EVENTID:
6797 	case WMI_PDEV_DMA_RING_CFG_RSP_EVENTID:
6798 		ath11k_dbg(ab, ATH11K_DBG_WMI,
6799 			   "ignoring unsupported event 0x%x\n", id);
6800 		break;
6801 	case WMI_PDEV_DFS_RADAR_DETECTION_EVENTID:
6802 		ath11k_wmi_pdev_dfs_radar_detected_event(ab, skb);
6803 		break;
6804 	case WMI_VDEV_DELETE_RESP_EVENTID:
6805 		ath11k_vdev_delete_resp_event(ab, skb);
6806 		break;
6807 	/* TODO: Add remaining events */
6808 	default:
6809 		ath11k_dbg(ab, ATH11K_DBG_WMI, "Unknown eventid: 0x%x\n", id);
6810 		break;
6811 	}
6812 
6813 out:
6814 	dev_kfree_skb(skb);
6815 }
6816 
6817 static int ath11k_connect_pdev_htc_service(struct ath11k_base *ab,
6818 					   u32 pdev_idx)
6819 {
6820 	int status;
6821 	u32 svc_id[] = { ATH11K_HTC_SVC_ID_WMI_CONTROL,
6822 			 ATH11K_HTC_SVC_ID_WMI_CONTROL_MAC1,
6823 			 ATH11K_HTC_SVC_ID_WMI_CONTROL_MAC2 };
6824 
6825 	struct ath11k_htc_svc_conn_req conn_req;
6826 	struct ath11k_htc_svc_conn_resp conn_resp;
6827 
6828 	memset(&conn_req, 0, sizeof(conn_req));
6829 	memset(&conn_resp, 0, sizeof(conn_resp));
6830 
6831 	/* these fields are the same for all service endpoints */
6832 	conn_req.ep_ops.ep_tx_complete = ath11k_wmi_htc_tx_complete;
6833 	conn_req.ep_ops.ep_rx_complete = ath11k_wmi_tlv_op_rx;
6834 	conn_req.ep_ops.ep_tx_credits = ath11k_wmi_op_ep_tx_credits;
6835 
6836 	/* connect to control service */
6837 	conn_req.service_id = svc_id[pdev_idx];
6838 
6839 	status = ath11k_htc_connect_service(&ab->htc, &conn_req, &conn_resp);
6840 	if (status) {
6841 		ath11k_warn(ab, "failed to connect to WMI CONTROL service status: %d\n",
6842 			    status);
6843 		return status;
6844 	}
6845 
6846 	ab->wmi_ab.wmi_endpoint_id[pdev_idx] = conn_resp.eid;
6847 	ab->wmi_ab.wmi[pdev_idx].eid = conn_resp.eid;
6848 	ab->wmi_ab.max_msg_len[pdev_idx] = conn_resp.max_msg_len;
6849 
6850 	return 0;
6851 }
6852 
6853 static int
6854 ath11k_wmi_send_unit_test_cmd(struct ath11k *ar,
6855 			      struct wmi_unit_test_cmd ut_cmd,
6856 			      u32 *test_args)
6857 {
6858 	struct ath11k_pdev_wmi *wmi = ar->wmi;
6859 	struct wmi_unit_test_cmd *cmd;
6860 	struct sk_buff *skb;
6861 	struct wmi_tlv *tlv;
6862 	void *ptr;
6863 	u32 *ut_cmd_args;
6864 	int buf_len, arg_len;
6865 	int ret;
6866 	int i;
6867 
6868 	arg_len = sizeof(u32) * ut_cmd.num_args;
6869 	buf_len = sizeof(ut_cmd) + arg_len + TLV_HDR_SIZE;
6870 
6871 	skb = ath11k_wmi_alloc_skb(wmi->wmi_ab, buf_len);
6872 	if (!skb)
6873 		return -ENOMEM;
6874 
6875 	cmd = (struct wmi_unit_test_cmd *)skb->data;
6876 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_UNIT_TEST_CMD) |
6877 			  FIELD_PREP(WMI_TLV_LEN, sizeof(ut_cmd) - TLV_HDR_SIZE);
6878 
6879 	cmd->vdev_id = ut_cmd.vdev_id;
6880 	cmd->module_id = ut_cmd.module_id;
6881 	cmd->num_args = ut_cmd.num_args;
6882 	cmd->diag_token = ut_cmd.diag_token;
6883 
6884 	ptr = skb->data + sizeof(ut_cmd);
6885 
6886 	tlv = ptr;
6887 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_UINT32) |
6888 		      FIELD_PREP(WMI_TLV_LEN, arg_len);
6889 
6890 	ptr += TLV_HDR_SIZE;
6891 
6892 	ut_cmd_args = ptr;
6893 	for (i = 0; i < ut_cmd.num_args; i++)
6894 		ut_cmd_args[i] = test_args[i];
6895 
6896 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_UNIT_TEST_CMDID);
6897 
6898 	if (ret) {
6899 		ath11k_warn(ar->ab, "failed to send WMI_UNIT_TEST CMD :%d\n",
6900 			    ret);
6901 		dev_kfree_skb(skb);
6902 	}
6903 
6904 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
6905 		   "WMI unit test : module %d vdev %d n_args %d token %d\n",
6906 		   cmd->module_id, cmd->vdev_id, cmd->num_args,
6907 		   cmd->diag_token);
6908 
6909 	return ret;
6910 }
6911 
6912 int ath11k_wmi_simulate_radar(struct ath11k *ar)
6913 {
6914 	struct ath11k_vif *arvif;
6915 	u32 dfs_args[DFS_MAX_TEST_ARGS];
6916 	struct wmi_unit_test_cmd wmi_ut;
6917 	bool arvif_found = false;
6918 
6919 	list_for_each_entry(arvif, &ar->arvifs, list) {
6920 		if (arvif->is_started && arvif->vdev_type == WMI_VDEV_TYPE_AP) {
6921 			arvif_found = true;
6922 			break;
6923 		}
6924 	}
6925 
6926 	if (!arvif_found)
6927 		return -EINVAL;
6928 
6929 	dfs_args[DFS_TEST_CMDID] = 0;
6930 	dfs_args[DFS_TEST_PDEV_ID] = ar->pdev->pdev_id;
6931 	/* Currently we could pass segment_id(b0 - b1), chirp(b2)
6932 	 * freq offset (b3 - b10) to unit test. For simulation
6933 	 * purpose this can be set to 0 which is valid.
6934 	 */
6935 	dfs_args[DFS_TEST_RADAR_PARAM] = 0;
6936 
6937 	wmi_ut.vdev_id = arvif->vdev_id;
6938 	wmi_ut.module_id = DFS_UNIT_TEST_MODULE;
6939 	wmi_ut.num_args = DFS_MAX_TEST_ARGS;
6940 	wmi_ut.diag_token = DFS_UNIT_TEST_TOKEN;
6941 
6942 	ath11k_dbg(ar->ab, ATH11K_DBG_REG, "Triggering Radar Simulation\n");
6943 
6944 	return ath11k_wmi_send_unit_test_cmd(ar, wmi_ut, dfs_args);
6945 }
6946 
6947 int ath11k_wmi_connect(struct ath11k_base *ab)
6948 {
6949 	u32 i;
6950 	u8 wmi_ep_count;
6951 
6952 	wmi_ep_count = ab->htc.wmi_ep_count;
6953 	if (wmi_ep_count > ab->hw_params.max_radios)
6954 		return -1;
6955 
6956 	for (i = 0; i < wmi_ep_count; i++)
6957 		ath11k_connect_pdev_htc_service(ab, i);
6958 
6959 	return 0;
6960 }
6961 
6962 static void ath11k_wmi_pdev_detach(struct ath11k_base *ab, u8 pdev_id)
6963 {
6964 	if (WARN_ON(pdev_id >= MAX_RADIOS))
6965 		return;
6966 
6967 	/* TODO: Deinit any pdev specific wmi resource */
6968 }
6969 
6970 int ath11k_wmi_pdev_attach(struct ath11k_base *ab,
6971 			   u8 pdev_id)
6972 {
6973 	struct ath11k_pdev_wmi *wmi_handle;
6974 
6975 	if (pdev_id >= ab->hw_params.max_radios)
6976 		return -EINVAL;
6977 
6978 	wmi_handle = &ab->wmi_ab.wmi[pdev_id];
6979 
6980 	wmi_handle->wmi_ab = &ab->wmi_ab;
6981 
6982 	ab->wmi_ab.ab = ab;
6983 	/* TODO: Init remaining resource specific to pdev */
6984 
6985 	return 0;
6986 }
6987 
6988 int ath11k_wmi_attach(struct ath11k_base *ab)
6989 {
6990 	int ret;
6991 
6992 	ret = ath11k_wmi_pdev_attach(ab, 0);
6993 	if (ret)
6994 		return ret;
6995 
6996 	ab->wmi_ab.ab = ab;
6997 	ab->wmi_ab.preferred_hw_mode = WMI_HOST_HW_MODE_MAX;
6998 
6999 	/* It's overwritten when service_ext_ready is handled */
7000 	if (ab->hw_params.single_pdev_only)
7001 		ab->wmi_ab.preferred_hw_mode = WMI_HOST_HW_MODE_SINGLE;
7002 
7003 	/* TODO: Init remaining wmi soc resources required */
7004 	init_completion(&ab->wmi_ab.service_ready);
7005 	init_completion(&ab->wmi_ab.unified_ready);
7006 
7007 	return 0;
7008 }
7009 
7010 void ath11k_wmi_detach(struct ath11k_base *ab)
7011 {
7012 	int i;
7013 
7014 	/* TODO: Deinit wmi resource specific to SOC as required */
7015 
7016 	for (i = 0; i < ab->htc.wmi_ep_count; i++)
7017 		ath11k_wmi_pdev_detach(ab, i);
7018 
7019 	ath11k_wmi_free_dbring_caps(ab);
7020 }
7021