xref: /linux/drivers/net/wireless/mediatek/mt76/mt7925/mac.c (revision 90d32e92011eaae8e70a9169b4e7acf4ca8f9d3a)
1 // SPDX-License-Identifier: ISC
2 /* Copyright (C) 2023 MediaTek Inc. */
3 
4 #include <linux/devcoredump.h>
5 #include <linux/etherdevice.h>
6 #include <linux/timekeeping.h>
7 #include "mt7925.h"
8 #include "../dma.h"
9 #include "mac.h"
10 #include "mcu.h"
11 
12 bool mt7925_mac_wtbl_update(struct mt792x_dev *dev, int idx, u32 mask)
13 {
14 	mt76_rmw(dev, MT_WTBL_UPDATE, MT_WTBL_UPDATE_WLAN_IDX,
15 		 FIELD_PREP(MT_WTBL_UPDATE_WLAN_IDX, idx) | mask);
16 
17 	return mt76_poll(dev, MT_WTBL_UPDATE, MT_WTBL_UPDATE_BUSY,
18 			 0, 5000);
19 }
20 
21 static void mt7925_mac_sta_poll(struct mt792x_dev *dev)
22 {
23 	static const u8 ac_to_tid[] = {
24 		[IEEE80211_AC_BE] = 0,
25 		[IEEE80211_AC_BK] = 1,
26 		[IEEE80211_AC_VI] = 4,
27 		[IEEE80211_AC_VO] = 6
28 	};
29 	struct ieee80211_sta *sta;
30 	struct mt792x_sta *msta;
31 	u32 tx_time[IEEE80211_NUM_ACS], rx_time[IEEE80211_NUM_ACS];
32 	LIST_HEAD(sta_poll_list);
33 	struct rate_info *rate;
34 	s8 rssi[4];
35 	int i;
36 
37 	spin_lock_bh(&dev->mt76.sta_poll_lock);
38 	list_splice_init(&dev->mt76.sta_poll_list, &sta_poll_list);
39 	spin_unlock_bh(&dev->mt76.sta_poll_lock);
40 
41 	while (true) {
42 		bool clear = false;
43 		u32 addr, val;
44 		u16 idx;
45 		u8 bw;
46 
47 		if (list_empty(&sta_poll_list))
48 			break;
49 		msta = list_first_entry(&sta_poll_list,
50 					struct mt792x_sta, wcid.poll_list);
51 		spin_lock_bh(&dev->mt76.sta_poll_lock);
52 		list_del_init(&msta->wcid.poll_list);
53 		spin_unlock_bh(&dev->mt76.sta_poll_lock);
54 
55 		idx = msta->wcid.idx;
56 		addr = mt7925_mac_wtbl_lmac_addr(dev, idx, MT_WTBL_AC0_CTT_OFFSET);
57 
58 		for (i = 0; i < IEEE80211_NUM_ACS; i++) {
59 			u32 tx_last = msta->airtime_ac[i];
60 			u32 rx_last = msta->airtime_ac[i + 4];
61 
62 			msta->airtime_ac[i] = mt76_rr(dev, addr);
63 			msta->airtime_ac[i + 4] = mt76_rr(dev, addr + 4);
64 
65 			tx_time[i] = msta->airtime_ac[i] - tx_last;
66 			rx_time[i] = msta->airtime_ac[i + 4] - rx_last;
67 
68 			if ((tx_last | rx_last) & BIT(30))
69 				clear = true;
70 
71 			addr += 8;
72 		}
73 
74 		if (clear) {
75 			mt7925_mac_wtbl_update(dev, idx,
76 					       MT_WTBL_UPDATE_ADM_COUNT_CLEAR);
77 			memset(msta->airtime_ac, 0, sizeof(msta->airtime_ac));
78 		}
79 
80 		if (!msta->wcid.sta)
81 			continue;
82 
83 		sta = container_of((void *)msta, struct ieee80211_sta,
84 				   drv_priv);
85 		for (i = 0; i < IEEE80211_NUM_ACS; i++) {
86 			u8 q = mt76_connac_lmac_mapping(i);
87 			u32 tx_cur = tx_time[q];
88 			u32 rx_cur = rx_time[q];
89 			u8 tid = ac_to_tid[i];
90 
91 			if (!tx_cur && !rx_cur)
92 				continue;
93 
94 			ieee80211_sta_register_airtime(sta, tid, tx_cur,
95 						       rx_cur);
96 		}
97 
98 		/* We don't support reading GI info from txs packets.
99 		 * For accurate tx status reporting and AQL improvement,
100 		 * we need to make sure that flags match so polling GI
101 		 * from per-sta counters directly.
102 		 */
103 		rate = &msta->wcid.rate;
104 
105 		switch (rate->bw) {
106 		case RATE_INFO_BW_160:
107 			bw = IEEE80211_STA_RX_BW_160;
108 			break;
109 		case RATE_INFO_BW_80:
110 			bw = IEEE80211_STA_RX_BW_80;
111 			break;
112 		case RATE_INFO_BW_40:
113 			bw = IEEE80211_STA_RX_BW_40;
114 			break;
115 		default:
116 			bw = IEEE80211_STA_RX_BW_20;
117 			break;
118 		}
119 
120 		addr = mt7925_mac_wtbl_lmac_addr(dev, idx, 6);
121 		val = mt76_rr(dev, addr);
122 		if (rate->flags & RATE_INFO_FLAGS_EHT_MCS) {
123 			addr = mt7925_mac_wtbl_lmac_addr(dev, idx, 5);
124 			val = mt76_rr(dev, addr);
125 			rate->eht_gi = FIELD_GET(GENMASK(25, 24), val);
126 		} else if (rate->flags & RATE_INFO_FLAGS_HE_MCS) {
127 			u8 offs = MT_WTBL_TXRX_RATE_G2_HE + 2 * bw;
128 
129 			rate->he_gi = (val & (0x3 << offs)) >> offs;
130 		} else if (rate->flags &
131 			   (RATE_INFO_FLAGS_VHT_MCS | RATE_INFO_FLAGS_MCS)) {
132 			if (val & BIT(MT_WTBL_TXRX_RATE_G2 + bw))
133 				rate->flags |= RATE_INFO_FLAGS_SHORT_GI;
134 			else
135 				rate->flags &= ~RATE_INFO_FLAGS_SHORT_GI;
136 		}
137 
138 		/* get signal strength of resp frames (CTS/BA/ACK) */
139 		addr = mt7925_mac_wtbl_lmac_addr(dev, idx, 34);
140 		val = mt76_rr(dev, addr);
141 
142 		rssi[0] = to_rssi(GENMASK(7, 0), val);
143 		rssi[1] = to_rssi(GENMASK(15, 8), val);
144 		rssi[2] = to_rssi(GENMASK(23, 16), val);
145 		rssi[3] = to_rssi(GENMASK(31, 14), val);
146 
147 		msta->ack_signal =
148 			mt76_rx_signal(msta->vif->phy->mt76->antenna_mask, rssi);
149 
150 		ewma_avg_signal_add(&msta->avg_ack_signal, -msta->ack_signal);
151 	}
152 }
153 
154 void mt7925_mac_set_fixed_rate_table(struct mt792x_dev *dev,
155 				     u8 tbl_idx, u16 rate_idx)
156 {
157 	u32 ctrl = MT_WTBL_ITCR_WR | MT_WTBL_ITCR_EXEC | tbl_idx;
158 
159 	mt76_wr(dev, MT_WTBL_ITDR0, rate_idx);
160 	/* use wtbl spe idx */
161 	mt76_wr(dev, MT_WTBL_ITDR1, MT_WTBL_SPE_IDX_SEL);
162 	mt76_wr(dev, MT_WTBL_ITCR, ctrl);
163 }
164 
165 /* The HW does not translate the mac header to 802.3 for mesh point */
166 static int mt7925_reverse_frag0_hdr_trans(struct sk_buff *skb, u16 hdr_gap)
167 {
168 	struct mt76_rx_status *status = (struct mt76_rx_status *)skb->cb;
169 	struct ethhdr *eth_hdr = (struct ethhdr *)(skb->data + hdr_gap);
170 	struct mt792x_sta *msta = (struct mt792x_sta *)status->wcid;
171 	__le32 *rxd = (__le32 *)skb->data;
172 	struct ieee80211_sta *sta;
173 	struct ieee80211_vif *vif;
174 	struct ieee80211_hdr hdr;
175 	u16 frame_control;
176 
177 	if (le32_get_bits(rxd[3], MT_RXD3_NORMAL_ADDR_TYPE) !=
178 	    MT_RXD3_NORMAL_U2M)
179 		return -EINVAL;
180 
181 	if (!(le32_to_cpu(rxd[1]) & MT_RXD1_NORMAL_GROUP_4))
182 		return -EINVAL;
183 
184 	if (!msta || !msta->vif)
185 		return -EINVAL;
186 
187 	sta = container_of((void *)msta, struct ieee80211_sta, drv_priv);
188 	vif = container_of((void *)msta->vif, struct ieee80211_vif, drv_priv);
189 
190 	/* store the info from RXD and ethhdr to avoid being overridden */
191 	frame_control = le32_get_bits(rxd[8], MT_RXD8_FRAME_CONTROL);
192 	hdr.frame_control = cpu_to_le16(frame_control);
193 	hdr.seq_ctrl = cpu_to_le16(le32_get_bits(rxd[10], MT_RXD10_SEQ_CTRL));
194 	hdr.duration_id = 0;
195 
196 	ether_addr_copy(hdr.addr1, vif->addr);
197 	ether_addr_copy(hdr.addr2, sta->addr);
198 	switch (frame_control & (IEEE80211_FCTL_TODS |
199 				 IEEE80211_FCTL_FROMDS)) {
200 	case 0:
201 		ether_addr_copy(hdr.addr3, vif->bss_conf.bssid);
202 		break;
203 	case IEEE80211_FCTL_FROMDS:
204 		ether_addr_copy(hdr.addr3, eth_hdr->h_source);
205 		break;
206 	case IEEE80211_FCTL_TODS:
207 		ether_addr_copy(hdr.addr3, eth_hdr->h_dest);
208 		break;
209 	case IEEE80211_FCTL_TODS | IEEE80211_FCTL_FROMDS:
210 		ether_addr_copy(hdr.addr3, eth_hdr->h_dest);
211 		ether_addr_copy(hdr.addr4, eth_hdr->h_source);
212 		break;
213 	default:
214 		break;
215 	}
216 
217 	skb_pull(skb, hdr_gap + sizeof(struct ethhdr) - 2);
218 	if (eth_hdr->h_proto == cpu_to_be16(ETH_P_AARP) ||
219 	    eth_hdr->h_proto == cpu_to_be16(ETH_P_IPX))
220 		ether_addr_copy(skb_push(skb, ETH_ALEN), bridge_tunnel_header);
221 	else if (be16_to_cpu(eth_hdr->h_proto) >= ETH_P_802_3_MIN)
222 		ether_addr_copy(skb_push(skb, ETH_ALEN), rfc1042_header);
223 	else
224 		skb_pull(skb, 2);
225 
226 	if (ieee80211_has_order(hdr.frame_control))
227 		memcpy(skb_push(skb, IEEE80211_HT_CTL_LEN), &rxd[11],
228 		       IEEE80211_HT_CTL_LEN);
229 	if (ieee80211_is_data_qos(hdr.frame_control)) {
230 		__le16 qos_ctrl;
231 
232 		qos_ctrl = cpu_to_le16(le32_get_bits(rxd[10], MT_RXD10_QOS_CTL));
233 		memcpy(skb_push(skb, IEEE80211_QOS_CTL_LEN), &qos_ctrl,
234 		       IEEE80211_QOS_CTL_LEN);
235 	}
236 
237 	if (ieee80211_has_a4(hdr.frame_control))
238 		memcpy(skb_push(skb, sizeof(hdr)), &hdr, sizeof(hdr));
239 	else
240 		memcpy(skb_push(skb, sizeof(hdr) - 6), &hdr, sizeof(hdr) - 6);
241 
242 	return 0;
243 }
244 
245 static int
246 mt7925_mac_fill_rx_rate(struct mt792x_dev *dev,
247 			struct mt76_rx_status *status,
248 			struct ieee80211_supported_band *sband,
249 			__le32 *rxv, u8 *mode)
250 {
251 	u32 v0, v2;
252 	u8 stbc, gi, bw, dcm, nss;
253 	int i, idx;
254 	bool cck = false;
255 
256 	v0 = le32_to_cpu(rxv[0]);
257 	v2 = le32_to_cpu(rxv[2]);
258 
259 	idx = FIELD_GET(MT_PRXV_TX_RATE, v0);
260 	i = idx;
261 	nss = FIELD_GET(MT_PRXV_NSTS, v0) + 1;
262 
263 	stbc = FIELD_GET(MT_PRXV_HT_STBC, v2);
264 	gi = FIELD_GET(MT_PRXV_HT_SHORT_GI, v2);
265 	*mode = FIELD_GET(MT_PRXV_TX_MODE, v2);
266 	dcm = FIELD_GET(MT_PRXV_DCM, v2);
267 	bw = FIELD_GET(MT_PRXV_FRAME_MODE, v2);
268 
269 	switch (*mode) {
270 	case MT_PHY_TYPE_CCK:
271 		cck = true;
272 		fallthrough;
273 	case MT_PHY_TYPE_OFDM:
274 		i = mt76_get_rate(&dev->mt76, sband, i, cck);
275 		break;
276 	case MT_PHY_TYPE_HT_GF:
277 	case MT_PHY_TYPE_HT:
278 		status->encoding = RX_ENC_HT;
279 		if (gi)
280 			status->enc_flags |= RX_ENC_FLAG_SHORT_GI;
281 		if (i > 31)
282 			return -EINVAL;
283 		break;
284 	case MT_PHY_TYPE_VHT:
285 		status->nss = nss;
286 		status->encoding = RX_ENC_VHT;
287 		if (gi)
288 			status->enc_flags |= RX_ENC_FLAG_SHORT_GI;
289 		if (i > 11)
290 			return -EINVAL;
291 		break;
292 	case MT_PHY_TYPE_HE_MU:
293 	case MT_PHY_TYPE_HE_SU:
294 	case MT_PHY_TYPE_HE_EXT_SU:
295 	case MT_PHY_TYPE_HE_TB:
296 		status->nss = nss;
297 		status->encoding = RX_ENC_HE;
298 		i &= GENMASK(3, 0);
299 
300 		if (gi <= NL80211_RATE_INFO_HE_GI_3_2)
301 			status->he_gi = gi;
302 
303 		status->he_dcm = dcm;
304 		break;
305 	case MT_PHY_TYPE_EHT_SU:
306 	case MT_PHY_TYPE_EHT_TRIG:
307 	case MT_PHY_TYPE_EHT_MU:
308 		status->nss = nss;
309 		status->encoding = RX_ENC_EHT;
310 		i &= GENMASK(3, 0);
311 
312 		if (gi <= NL80211_RATE_INFO_EHT_GI_3_2)
313 			status->eht.gi = gi;
314 		break;
315 	default:
316 		return -EINVAL;
317 	}
318 	status->rate_idx = i;
319 
320 	switch (bw) {
321 	case IEEE80211_STA_RX_BW_20:
322 		break;
323 	case IEEE80211_STA_RX_BW_40:
324 		if (*mode & MT_PHY_TYPE_HE_EXT_SU &&
325 		    (idx & MT_PRXV_TX_ER_SU_106T)) {
326 			status->bw = RATE_INFO_BW_HE_RU;
327 			status->he_ru =
328 				NL80211_RATE_INFO_HE_RU_ALLOC_106;
329 		} else {
330 			status->bw = RATE_INFO_BW_40;
331 		}
332 		break;
333 	case IEEE80211_STA_RX_BW_80:
334 		status->bw = RATE_INFO_BW_80;
335 		break;
336 	case IEEE80211_STA_RX_BW_160:
337 		status->bw = RATE_INFO_BW_160;
338 		break;
339 	default:
340 		return -EINVAL;
341 	}
342 
343 	status->enc_flags |= RX_ENC_FLAG_STBC_MASK * stbc;
344 	if (*mode < MT_PHY_TYPE_HE_SU && gi)
345 		status->enc_flags |= RX_ENC_FLAG_SHORT_GI;
346 
347 	return 0;
348 }
349 
350 static int
351 mt7925_mac_fill_rx(struct mt792x_dev *dev, struct sk_buff *skb)
352 {
353 	u32 csum_mask = MT_RXD0_NORMAL_IP_SUM | MT_RXD0_NORMAL_UDP_TCP_SUM;
354 	struct mt76_rx_status *status = (struct mt76_rx_status *)skb->cb;
355 	bool hdr_trans, unicast, insert_ccmp_hdr = false;
356 	u8 chfreq, qos_ctl = 0, remove_pad, amsdu_info;
357 	u16 hdr_gap;
358 	__le32 *rxv = NULL, *rxd = (__le32 *)skb->data;
359 	struct mt76_phy *mphy = &dev->mt76.phy;
360 	struct mt792x_phy *phy = &dev->phy;
361 	struct ieee80211_supported_band *sband;
362 	u32 csum_status = *(u32 *)skb->cb;
363 	u32 rxd0 = le32_to_cpu(rxd[0]);
364 	u32 rxd1 = le32_to_cpu(rxd[1]);
365 	u32 rxd2 = le32_to_cpu(rxd[2]);
366 	u32 rxd3 = le32_to_cpu(rxd[3]);
367 	u32 rxd4 = le32_to_cpu(rxd[4]);
368 	struct mt792x_sta *msta = NULL;
369 	u8 mode = 0; /* , band_idx; */
370 	u16 seq_ctrl = 0;
371 	__le16 fc = 0;
372 	int idx;
373 
374 	memset(status, 0, sizeof(*status));
375 
376 	if (!test_bit(MT76_STATE_RUNNING, &mphy->state))
377 		return -EINVAL;
378 
379 	if (rxd2 & MT_RXD2_NORMAL_AMSDU_ERR)
380 		return -EINVAL;
381 
382 	hdr_trans = rxd2 & MT_RXD2_NORMAL_HDR_TRANS;
383 	if (hdr_trans && (rxd1 & MT_RXD1_NORMAL_CM))
384 		return -EINVAL;
385 
386 	/* ICV error or CCMP/BIP/WPI MIC error */
387 	if (rxd1 & MT_RXD1_NORMAL_ICV_ERR)
388 		status->flag |= RX_FLAG_ONLY_MONITOR;
389 
390 	chfreq = FIELD_GET(MT_RXD3_NORMAL_CH_FREQ, rxd3);
391 	unicast = FIELD_GET(MT_RXD3_NORMAL_ADDR_TYPE, rxd3) == MT_RXD3_NORMAL_U2M;
392 	idx = FIELD_GET(MT_RXD1_NORMAL_WLAN_IDX, rxd1);
393 	status->wcid = mt792x_rx_get_wcid(dev, idx, unicast);
394 
395 	if (status->wcid) {
396 		msta = container_of(status->wcid, struct mt792x_sta, wcid);
397 		spin_lock_bh(&dev->mt76.sta_poll_lock);
398 		if (list_empty(&msta->wcid.poll_list))
399 			list_add_tail(&msta->wcid.poll_list,
400 				      &dev->mt76.sta_poll_list);
401 		spin_unlock_bh(&dev->mt76.sta_poll_lock);
402 	}
403 
404 	mt792x_get_status_freq_info(status, chfreq);
405 
406 	switch (status->band) {
407 	case NL80211_BAND_5GHZ:
408 		sband = &mphy->sband_5g.sband;
409 		break;
410 	case NL80211_BAND_6GHZ:
411 		sband = &mphy->sband_6g.sband;
412 		break;
413 	default:
414 		sband = &mphy->sband_2g.sband;
415 		break;
416 	}
417 
418 	if (!sband->channels)
419 		return -EINVAL;
420 
421 	if (mt76_is_mmio(&dev->mt76) && (rxd0 & csum_mask) == csum_mask &&
422 	    !(csum_status & (BIT(0) | BIT(2) | BIT(3))))
423 		skb->ip_summed = CHECKSUM_UNNECESSARY;
424 
425 	if (rxd3 & MT_RXD3_NORMAL_FCS_ERR)
426 		status->flag |= RX_FLAG_FAILED_FCS_CRC;
427 
428 	if (rxd1 & MT_RXD1_NORMAL_TKIP_MIC_ERR)
429 		status->flag |= RX_FLAG_MMIC_ERROR;
430 
431 	if (FIELD_GET(MT_RXD2_NORMAL_SEC_MODE, rxd2) != 0 &&
432 	    !(rxd1 & (MT_RXD1_NORMAL_CLM | MT_RXD1_NORMAL_CM))) {
433 		status->flag |= RX_FLAG_DECRYPTED;
434 		status->flag |= RX_FLAG_IV_STRIPPED;
435 		status->flag |= RX_FLAG_MMIC_STRIPPED | RX_FLAG_MIC_STRIPPED;
436 	}
437 
438 	remove_pad = FIELD_GET(MT_RXD2_NORMAL_HDR_OFFSET, rxd2);
439 
440 	if (rxd2 & MT_RXD2_NORMAL_MAX_LEN_ERROR)
441 		return -EINVAL;
442 
443 	rxd += 8;
444 	if (rxd1 & MT_RXD1_NORMAL_GROUP_4) {
445 		u32 v0 = le32_to_cpu(rxd[0]);
446 		u32 v2 = le32_to_cpu(rxd[2]);
447 
448 		/* TODO: need to map rxd address */
449 		fc = cpu_to_le16(FIELD_GET(MT_RXD8_FRAME_CONTROL, v0));
450 		seq_ctrl = FIELD_GET(MT_RXD10_SEQ_CTRL, v2);
451 		qos_ctl = FIELD_GET(MT_RXD10_QOS_CTL, v2);
452 
453 		rxd += 4;
454 		if ((u8 *)rxd - skb->data >= skb->len)
455 			return -EINVAL;
456 	}
457 
458 	if (rxd1 & MT_RXD1_NORMAL_GROUP_1) {
459 		u8 *data = (u8 *)rxd;
460 
461 		if (status->flag & RX_FLAG_DECRYPTED) {
462 			switch (FIELD_GET(MT_RXD2_NORMAL_SEC_MODE, rxd2)) {
463 			case MT_CIPHER_AES_CCMP:
464 			case MT_CIPHER_CCMP_CCX:
465 			case MT_CIPHER_CCMP_256:
466 				insert_ccmp_hdr =
467 					FIELD_GET(MT_RXD2_NORMAL_FRAG, rxd2);
468 				fallthrough;
469 			case MT_CIPHER_TKIP:
470 			case MT_CIPHER_TKIP_NO_MIC:
471 			case MT_CIPHER_GCMP:
472 			case MT_CIPHER_GCMP_256:
473 				status->iv[0] = data[5];
474 				status->iv[1] = data[4];
475 				status->iv[2] = data[3];
476 				status->iv[3] = data[2];
477 				status->iv[4] = data[1];
478 				status->iv[5] = data[0];
479 				break;
480 			default:
481 				break;
482 			}
483 		}
484 		rxd += 4;
485 		if ((u8 *)rxd - skb->data >= skb->len)
486 			return -EINVAL;
487 	}
488 
489 	if (rxd1 & MT_RXD1_NORMAL_GROUP_2) {
490 		status->timestamp = le32_to_cpu(rxd[0]);
491 		status->flag |= RX_FLAG_MACTIME_START;
492 
493 		if (!(rxd2 & MT_RXD2_NORMAL_NON_AMPDU)) {
494 			status->flag |= RX_FLAG_AMPDU_DETAILS;
495 
496 			/* all subframes of an A-MPDU have the same timestamp */
497 			if (phy->rx_ampdu_ts != status->timestamp) {
498 				if (!++phy->ampdu_ref)
499 					phy->ampdu_ref++;
500 			}
501 			phy->rx_ampdu_ts = status->timestamp;
502 
503 			status->ampdu_ref = phy->ampdu_ref;
504 		}
505 
506 		rxd += 4;
507 		if ((u8 *)rxd - skb->data >= skb->len)
508 			return -EINVAL;
509 	}
510 
511 	/* RXD Group 3 - P-RXV */
512 	if (rxd1 & MT_RXD1_NORMAL_GROUP_3) {
513 		u32 v3;
514 		int ret;
515 
516 		rxv = rxd;
517 		rxd += 4;
518 		if ((u8 *)rxd - skb->data >= skb->len)
519 			return -EINVAL;
520 
521 		v3 = le32_to_cpu(rxv[3]);
522 
523 		status->chains = mphy->antenna_mask;
524 		status->chain_signal[0] = to_rssi(MT_PRXV_RCPI0, v3);
525 		status->chain_signal[1] = to_rssi(MT_PRXV_RCPI1, v3);
526 		status->chain_signal[2] = to_rssi(MT_PRXV_RCPI2, v3);
527 		status->chain_signal[3] = to_rssi(MT_PRXV_RCPI3, v3);
528 
529 		/* RXD Group 5 - C-RXV */
530 		if (rxd1 & MT_RXD1_NORMAL_GROUP_5) {
531 			rxd += 24;
532 			if ((u8 *)rxd - skb->data >= skb->len)
533 				return -EINVAL;
534 		}
535 
536 		ret = mt7925_mac_fill_rx_rate(dev, status, sband, rxv, &mode);
537 		if (ret < 0)
538 			return ret;
539 	}
540 
541 	amsdu_info = FIELD_GET(MT_RXD4_NORMAL_PAYLOAD_FORMAT, rxd4);
542 	status->amsdu = !!amsdu_info;
543 	if (status->amsdu) {
544 		status->first_amsdu = amsdu_info == MT_RXD4_FIRST_AMSDU_FRAME;
545 		status->last_amsdu = amsdu_info == MT_RXD4_LAST_AMSDU_FRAME;
546 	}
547 
548 	hdr_gap = (u8 *)rxd - skb->data + 2 * remove_pad;
549 	if (hdr_trans && ieee80211_has_morefrags(fc)) {
550 		if (mt7925_reverse_frag0_hdr_trans(skb, hdr_gap))
551 			return -EINVAL;
552 		hdr_trans = false;
553 	} else {
554 		int pad_start = 0;
555 
556 		skb_pull(skb, hdr_gap);
557 		if (!hdr_trans && status->amsdu) {
558 			pad_start = ieee80211_get_hdrlen_from_skb(skb);
559 		} else if (hdr_trans && (rxd2 & MT_RXD2_NORMAL_HDR_TRANS_ERROR)) {
560 			/* When header translation failure is indicated,
561 			 * the hardware will insert an extra 2-byte field
562 			 * containing the data length after the protocol
563 			 * type field.
564 			 */
565 			pad_start = 12;
566 			if (get_unaligned_be16(skb->data + pad_start) == ETH_P_8021Q)
567 				pad_start += 4;
568 			else
569 				pad_start = 0;
570 		}
571 
572 		if (pad_start) {
573 			memmove(skb->data + 2, skb->data, pad_start);
574 			skb_pull(skb, 2);
575 		}
576 	}
577 
578 	if (!hdr_trans) {
579 		struct ieee80211_hdr *hdr;
580 
581 		if (insert_ccmp_hdr) {
582 			u8 key_id = FIELD_GET(MT_RXD1_NORMAL_KEY_ID, rxd1);
583 
584 			mt76_insert_ccmp_hdr(skb, key_id);
585 		}
586 
587 		hdr = mt76_skb_get_hdr(skb);
588 		fc = hdr->frame_control;
589 		if (ieee80211_is_data_qos(fc)) {
590 			seq_ctrl = le16_to_cpu(hdr->seq_ctrl);
591 			qos_ctl = *ieee80211_get_qos_ctl(hdr);
592 		}
593 		skb_set_mac_header(skb, (unsigned char *)hdr - skb->data);
594 	} else {
595 		status->flag |= RX_FLAG_8023;
596 	}
597 
598 	mt792x_mac_assoc_rssi(dev, skb);
599 
600 	if (rxv && !(status->flag & RX_FLAG_8023)) {
601 		switch (status->encoding) {
602 		case RX_ENC_EHT:
603 			mt76_connac3_mac_decode_eht_radiotap(skb, rxv, mode);
604 			break;
605 		case RX_ENC_HE:
606 			mt76_connac3_mac_decode_he_radiotap(skb, rxv, mode);
607 			break;
608 		default:
609 			break;
610 		}
611 	}
612 
613 	if (!status->wcid || !ieee80211_is_data_qos(fc))
614 		return 0;
615 
616 	status->aggr = unicast && !ieee80211_is_qos_nullfunc(fc);
617 	status->seqno = IEEE80211_SEQ_TO_SN(seq_ctrl);
618 	status->qos_ctl = qos_ctl;
619 
620 	return 0;
621 }
622 
623 static void
624 mt7925_mac_write_txwi_8023(__le32 *txwi, struct sk_buff *skb,
625 			   struct mt76_wcid *wcid)
626 {
627 	u8 tid = skb->priority & IEEE80211_QOS_CTL_TID_MASK;
628 	u8 fc_type, fc_stype;
629 	u16 ethertype;
630 	bool wmm = false;
631 	u32 val;
632 
633 	if (wcid->sta) {
634 		struct ieee80211_sta *sta;
635 
636 		sta = container_of((void *)wcid, struct ieee80211_sta, drv_priv);
637 		wmm = sta->wme;
638 	}
639 
640 	val = FIELD_PREP(MT_TXD1_HDR_FORMAT, MT_HDR_FORMAT_802_3) |
641 	      FIELD_PREP(MT_TXD1_TID, tid);
642 
643 	ethertype = get_unaligned_be16(&skb->data[12]);
644 	if (ethertype >= ETH_P_802_3_MIN)
645 		val |= MT_TXD1_ETH_802_3;
646 
647 	txwi[1] |= cpu_to_le32(val);
648 
649 	fc_type = IEEE80211_FTYPE_DATA >> 2;
650 	fc_stype = wmm ? IEEE80211_STYPE_QOS_DATA >> 4 : 0;
651 
652 	val = FIELD_PREP(MT_TXD2_FRAME_TYPE, fc_type) |
653 	      FIELD_PREP(MT_TXD2_SUB_TYPE, fc_stype);
654 
655 	txwi[2] |= cpu_to_le32(val);
656 }
657 
658 static void
659 mt7925_mac_write_txwi_80211(struct mt76_dev *dev, __le32 *txwi,
660 			    struct sk_buff *skb,
661 			    struct ieee80211_key_conf *key)
662 {
663 	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
664 	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *)skb->data;
665 	struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
666 	bool multicast = is_multicast_ether_addr(hdr->addr1);
667 	u8 tid = skb->priority & IEEE80211_QOS_CTL_TID_MASK;
668 	__le16 fc = hdr->frame_control;
669 	u8 fc_type, fc_stype;
670 	u32 val;
671 
672 	if (ieee80211_is_action(fc) &&
673 	    mgmt->u.action.category == WLAN_CATEGORY_BACK &&
674 	    mgmt->u.action.u.addba_req.action_code == WLAN_ACTION_ADDBA_REQ)
675 		tid = MT_TX_ADDBA;
676 	else if (ieee80211_is_mgmt(hdr->frame_control))
677 		tid = MT_TX_NORMAL;
678 
679 	val = FIELD_PREP(MT_TXD1_HDR_FORMAT, MT_HDR_FORMAT_802_11) |
680 	      FIELD_PREP(MT_TXD1_HDR_INFO,
681 			 ieee80211_get_hdrlen_from_skb(skb) / 2) |
682 	      FIELD_PREP(MT_TXD1_TID, tid);
683 
684 	if (!ieee80211_is_data(fc) || multicast ||
685 	    info->flags & IEEE80211_TX_CTL_USE_MINRATE)
686 		val |= MT_TXD1_FIXED_RATE;
687 
688 	if (key && multicast && ieee80211_is_robust_mgmt_frame(skb) &&
689 	    key->cipher == WLAN_CIPHER_SUITE_AES_CMAC) {
690 		val |= MT_TXD1_BIP;
691 		txwi[3] &= ~cpu_to_le32(MT_TXD3_PROTECT_FRAME);
692 	}
693 
694 	txwi[1] |= cpu_to_le32(val);
695 
696 	fc_type = (le16_to_cpu(fc) & IEEE80211_FCTL_FTYPE) >> 2;
697 	fc_stype = (le16_to_cpu(fc) & IEEE80211_FCTL_STYPE) >> 4;
698 
699 	val = FIELD_PREP(MT_TXD2_FRAME_TYPE, fc_type) |
700 	      FIELD_PREP(MT_TXD2_SUB_TYPE, fc_stype);
701 
702 	txwi[2] |= cpu_to_le32(val);
703 
704 	txwi[3] |= cpu_to_le32(FIELD_PREP(MT_TXD3_BCM, multicast));
705 	if (ieee80211_is_beacon(fc))
706 		txwi[3] |= cpu_to_le32(MT_TXD3_REM_TX_COUNT);
707 
708 	if (info->flags & IEEE80211_TX_CTL_INJECTED) {
709 		u16 seqno = le16_to_cpu(hdr->seq_ctrl);
710 
711 		if (ieee80211_is_back_req(hdr->frame_control)) {
712 			struct ieee80211_bar *bar;
713 
714 			bar = (struct ieee80211_bar *)skb->data;
715 			seqno = le16_to_cpu(bar->start_seq_num);
716 		}
717 
718 		val = MT_TXD3_SN_VALID |
719 		      FIELD_PREP(MT_TXD3_SEQ, IEEE80211_SEQ_TO_SN(seqno));
720 		txwi[3] |= cpu_to_le32(val);
721 		txwi[3] &= ~cpu_to_le32(MT_TXD3_HW_AMSDU);
722 	}
723 }
724 
725 void
726 mt7925_mac_write_txwi(struct mt76_dev *dev, __le32 *txwi,
727 		      struct sk_buff *skb, struct mt76_wcid *wcid,
728 		      struct ieee80211_key_conf *key, int pid,
729 		      enum mt76_txq_id qid, u32 changed)
730 {
731 	struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
732 	struct ieee80211_vif *vif = info->control.vif;
733 	u8 p_fmt, q_idx, omac_idx = 0, wmm_idx = 0, band_idx = 0;
734 	u32 val, sz_txd = mt76_is_mmio(dev) ? MT_TXD_SIZE : MT_SDIO_TXD_SIZE;
735 	bool is_8023 = info->flags & IEEE80211_TX_CTL_HW_80211_ENCAP;
736 	struct mt76_vif *mvif;
737 	bool beacon = !!(changed & (BSS_CHANGED_BEACON |
738 				    BSS_CHANGED_BEACON_ENABLED));
739 	bool inband_disc = !!(changed & (BSS_CHANGED_UNSOL_BCAST_PROBE_RESP |
740 					 BSS_CHANGED_FILS_DISCOVERY));
741 
742 	mvif = vif ? (struct mt76_vif *)vif->drv_priv : NULL;
743 	if (mvif) {
744 		omac_idx = mvif->omac_idx;
745 		wmm_idx = mvif->wmm_idx;
746 		band_idx = mvif->band_idx;
747 	}
748 
749 	if (inband_disc) {
750 		p_fmt = MT_TX_TYPE_FW;
751 		q_idx = MT_LMAC_ALTX0;
752 	} else if (beacon) {
753 		p_fmt = MT_TX_TYPE_FW;
754 		q_idx = MT_LMAC_BCN0;
755 	} else if (qid >= MT_TXQ_PSD) {
756 		p_fmt = mt76_is_mmio(dev) ? MT_TX_TYPE_CT : MT_TX_TYPE_SF;
757 		q_idx = MT_LMAC_ALTX0;
758 	} else {
759 		p_fmt = mt76_is_mmio(dev) ? MT_TX_TYPE_CT : MT_TX_TYPE_SF;
760 		q_idx = wmm_idx * MT76_CONNAC_MAX_WMM_SETS +
761 			mt76_connac_lmac_mapping(skb_get_queue_mapping(skb));
762 
763 		/* counting non-offloading skbs */
764 		wcid->stats.tx_bytes += skb->len;
765 		wcid->stats.tx_packets++;
766 	}
767 
768 	val = FIELD_PREP(MT_TXD0_TX_BYTES, skb->len + sz_txd) |
769 	      FIELD_PREP(MT_TXD0_PKT_FMT, p_fmt) |
770 	      FIELD_PREP(MT_TXD0_Q_IDX, q_idx);
771 	txwi[0] = cpu_to_le32(val);
772 
773 	val = FIELD_PREP(MT_TXD1_WLAN_IDX, wcid->idx) |
774 	      FIELD_PREP(MT_TXD1_OWN_MAC, omac_idx);
775 
776 	if (band_idx)
777 		val |= FIELD_PREP(MT_TXD1_TGID, band_idx);
778 
779 	txwi[1] = cpu_to_le32(val);
780 	txwi[2] = 0;
781 
782 	val = FIELD_PREP(MT_TXD3_REM_TX_COUNT, 15);
783 
784 	if (key)
785 		val |= MT_TXD3_PROTECT_FRAME;
786 	if (info->flags & IEEE80211_TX_CTL_NO_ACK)
787 		val |= MT_TXD3_NO_ACK;
788 	if (wcid->amsdu)
789 		val |= MT_TXD3_HW_AMSDU;
790 
791 	txwi[3] = cpu_to_le32(val);
792 	txwi[4] = 0;
793 
794 	val = FIELD_PREP(MT_TXD5_PID, pid);
795 	if (pid >= MT_PACKET_ID_FIRST) {
796 		val |= MT_TXD5_TX_STATUS_HOST;
797 		txwi[3] |= cpu_to_le32(MT_TXD3_BA_DISABLE);
798 		txwi[3] &= ~cpu_to_le32(MT_TXD3_HW_AMSDU);
799 	}
800 
801 	txwi[5] = cpu_to_le32(val);
802 
803 	val = MT_TXD6_DIS_MAT | MT_TXD6_DAS |
804 	      FIELD_PREP(MT_TXD6_MSDU_CNT, 1);
805 	txwi[6] = cpu_to_le32(val);
806 	txwi[7] = 0;
807 
808 	if (is_8023)
809 		mt7925_mac_write_txwi_8023(txwi, skb, wcid);
810 	else
811 		mt7925_mac_write_txwi_80211(dev, txwi, skb, key);
812 
813 	if (txwi[1] & cpu_to_le32(MT_TXD1_FIXED_RATE)) {
814 		struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
815 		bool mcast = ieee80211_is_data(hdr->frame_control) &&
816 			     is_multicast_ether_addr(hdr->addr1);
817 		u8 idx = MT792x_BASIC_RATES_TBL;
818 
819 		if (mvif) {
820 			if (mcast && mvif->mcast_rates_idx)
821 				idx = mvif->mcast_rates_idx;
822 			else if (beacon && mvif->beacon_rates_idx)
823 				idx = mvif->beacon_rates_idx;
824 			else
825 				idx = mvif->basic_rates_idx;
826 		}
827 
828 		txwi[6] |= cpu_to_le32(FIELD_PREP(MT_TXD6_TX_RATE, idx));
829 		txwi[3] |= cpu_to_le32(MT_TXD3_BA_DISABLE);
830 	}
831 }
832 EXPORT_SYMBOL_GPL(mt7925_mac_write_txwi);
833 
834 static void mt7925_tx_check_aggr(struct ieee80211_sta *sta, __le32 *txwi)
835 {
836 	struct mt792x_sta *msta;
837 	u16 fc, tid;
838 	u32 val;
839 
840 	if (!sta || !(sta->deflink.ht_cap.ht_supported || sta->deflink.he_cap.has_he))
841 		return;
842 
843 	tid = le32_get_bits(txwi[1], MT_TXD1_TID);
844 	if (tid >= 6) /* skip VO queue */
845 		return;
846 
847 	val = le32_to_cpu(txwi[2]);
848 	fc = FIELD_GET(MT_TXD2_FRAME_TYPE, val) << 2 |
849 	     FIELD_GET(MT_TXD2_SUB_TYPE, val) << 4;
850 	if (unlikely(fc != (IEEE80211_FTYPE_DATA | IEEE80211_STYPE_QOS_DATA)))
851 		return;
852 
853 	msta = (struct mt792x_sta *)sta->drv_priv;
854 	if (!test_and_set_bit(tid, &msta->wcid.ampdu_state))
855 		ieee80211_start_tx_ba_session(sta, tid, 0);
856 }
857 
858 static bool
859 mt7925_mac_add_txs_skb(struct mt792x_dev *dev, struct mt76_wcid *wcid,
860 		       int pid, __le32 *txs_data)
861 {
862 	struct mt76_sta_stats *stats = &wcid->stats;
863 	struct ieee80211_supported_band *sband;
864 	struct mt76_dev *mdev = &dev->mt76;
865 	struct mt76_phy *mphy;
866 	struct ieee80211_tx_info *info;
867 	struct sk_buff_head list;
868 	struct rate_info rate = {};
869 	struct sk_buff *skb;
870 	bool cck = false;
871 	u32 txrate, txs, mode, stbc;
872 
873 	mt76_tx_status_lock(mdev, &list);
874 	skb = mt76_tx_status_skb_get(mdev, wcid, pid, &list);
875 	if (!skb)
876 		goto out_no_skb;
877 
878 	txs = le32_to_cpu(txs_data[0]);
879 
880 	info = IEEE80211_SKB_CB(skb);
881 	if (!(txs & MT_TXS0_ACK_ERROR_MASK))
882 		info->flags |= IEEE80211_TX_STAT_ACK;
883 
884 	info->status.ampdu_len = 1;
885 	info->status.ampdu_ack_len = !!(info->flags &
886 					IEEE80211_TX_STAT_ACK);
887 
888 	info->status.rates[0].idx = -1;
889 
890 	txrate = FIELD_GET(MT_TXS0_TX_RATE, txs);
891 
892 	rate.mcs = FIELD_GET(MT_TX_RATE_IDX, txrate);
893 	rate.nss = FIELD_GET(MT_TX_RATE_NSS, txrate) + 1;
894 	stbc = le32_get_bits(txs_data[3], MT_TXS3_RATE_STBC);
895 
896 	if (stbc && rate.nss > 1)
897 		rate.nss >>= 1;
898 
899 	if (rate.nss - 1 < ARRAY_SIZE(stats->tx_nss))
900 		stats->tx_nss[rate.nss - 1]++;
901 	if (rate.mcs < ARRAY_SIZE(stats->tx_mcs))
902 		stats->tx_mcs[rate.mcs]++;
903 
904 	mode = FIELD_GET(MT_TX_RATE_MODE, txrate);
905 	switch (mode) {
906 	case MT_PHY_TYPE_CCK:
907 		cck = true;
908 		fallthrough;
909 	case MT_PHY_TYPE_OFDM:
910 		mphy = mt76_dev_phy(mdev, wcid->phy_idx);
911 
912 		if (mphy->chandef.chan->band == NL80211_BAND_5GHZ)
913 			sband = &mphy->sband_5g.sband;
914 		else if (mphy->chandef.chan->band == NL80211_BAND_6GHZ)
915 			sband = &mphy->sband_6g.sband;
916 		else
917 			sband = &mphy->sband_2g.sband;
918 
919 		rate.mcs = mt76_get_rate(mphy->dev, sband, rate.mcs, cck);
920 		rate.legacy = sband->bitrates[rate.mcs].bitrate;
921 		break;
922 	case MT_PHY_TYPE_HT:
923 	case MT_PHY_TYPE_HT_GF:
924 		if (rate.mcs > 31)
925 			goto out;
926 
927 		rate.flags = RATE_INFO_FLAGS_MCS;
928 		if (wcid->rate.flags & RATE_INFO_FLAGS_SHORT_GI)
929 			rate.flags |= RATE_INFO_FLAGS_SHORT_GI;
930 		break;
931 	case MT_PHY_TYPE_VHT:
932 		if (rate.mcs > 9)
933 			goto out;
934 
935 		rate.flags = RATE_INFO_FLAGS_VHT_MCS;
936 		break;
937 	case MT_PHY_TYPE_HE_SU:
938 	case MT_PHY_TYPE_HE_EXT_SU:
939 	case MT_PHY_TYPE_HE_TB:
940 	case MT_PHY_TYPE_HE_MU:
941 		if (rate.mcs > 11)
942 			goto out;
943 
944 		rate.he_gi = wcid->rate.he_gi;
945 		rate.he_dcm = FIELD_GET(MT_TX_RATE_DCM, txrate);
946 		rate.flags = RATE_INFO_FLAGS_HE_MCS;
947 		break;
948 	case MT_PHY_TYPE_EHT_SU:
949 	case MT_PHY_TYPE_EHT_TRIG:
950 	case MT_PHY_TYPE_EHT_MU:
951 		if (rate.mcs > 13)
952 			goto out;
953 
954 		rate.eht_gi = wcid->rate.eht_gi;
955 		rate.flags = RATE_INFO_FLAGS_EHT_MCS;
956 		break;
957 	default:
958 		goto out;
959 	}
960 
961 	stats->tx_mode[mode]++;
962 
963 	switch (FIELD_GET(MT_TXS0_BW, txs)) {
964 	case IEEE80211_STA_RX_BW_160:
965 		rate.bw = RATE_INFO_BW_160;
966 		stats->tx_bw[3]++;
967 		break;
968 	case IEEE80211_STA_RX_BW_80:
969 		rate.bw = RATE_INFO_BW_80;
970 		stats->tx_bw[2]++;
971 		break;
972 	case IEEE80211_STA_RX_BW_40:
973 		rate.bw = RATE_INFO_BW_40;
974 		stats->tx_bw[1]++;
975 		break;
976 	default:
977 		rate.bw = RATE_INFO_BW_20;
978 		stats->tx_bw[0]++;
979 		break;
980 	}
981 	wcid->rate = rate;
982 
983 out:
984 	mt76_tx_status_skb_done(mdev, skb, &list);
985 
986 out_no_skb:
987 	mt76_tx_status_unlock(mdev, &list);
988 
989 	return !!skb;
990 }
991 
992 void mt7925_mac_add_txs(struct mt792x_dev *dev, void *data)
993 {
994 	struct mt792x_sta *msta = NULL;
995 	struct mt76_wcid *wcid;
996 	__le32 *txs_data = data;
997 	u16 wcidx;
998 	u8 pid;
999 
1000 	if (le32_get_bits(txs_data[0], MT_TXS0_TXS_FORMAT) > 1)
1001 		return;
1002 
1003 	wcidx = le32_get_bits(txs_data[2], MT_TXS2_WCID);
1004 	pid = le32_get_bits(txs_data[3], MT_TXS3_PID);
1005 
1006 	if (pid < MT_PACKET_ID_FIRST)
1007 		return;
1008 
1009 	if (wcidx >= MT792x_WTBL_SIZE)
1010 		return;
1011 
1012 	rcu_read_lock();
1013 
1014 	wcid = rcu_dereference(dev->mt76.wcid[wcidx]);
1015 	if (!wcid)
1016 		goto out;
1017 
1018 	msta = container_of(wcid, struct mt792x_sta, wcid);
1019 
1020 	mt7925_mac_add_txs_skb(dev, wcid, pid, txs_data);
1021 	if (!wcid->sta)
1022 		goto out;
1023 
1024 	spin_lock_bh(&dev->mt76.sta_poll_lock);
1025 	if (list_empty(&msta->wcid.poll_list))
1026 		list_add_tail(&msta->wcid.poll_list, &dev->mt76.sta_poll_list);
1027 	spin_unlock_bh(&dev->mt76.sta_poll_lock);
1028 
1029 out:
1030 	rcu_read_unlock();
1031 }
1032 
1033 void mt7925_txwi_free(struct mt792x_dev *dev, struct mt76_txwi_cache *t,
1034 		      struct ieee80211_sta *sta, bool clear_status,
1035 		      struct list_head *free_list)
1036 {
1037 	struct mt76_dev *mdev = &dev->mt76;
1038 	__le32 *txwi;
1039 	u16 wcid_idx;
1040 
1041 	mt76_connac_txp_skb_unmap(mdev, t);
1042 	if (!t->skb)
1043 		goto out;
1044 
1045 	txwi = (__le32 *)mt76_get_txwi_ptr(mdev, t);
1046 	if (sta) {
1047 		struct mt76_wcid *wcid = (struct mt76_wcid *)sta->drv_priv;
1048 
1049 		if (likely(t->skb->protocol != cpu_to_be16(ETH_P_PAE)))
1050 			mt7925_tx_check_aggr(sta, txwi);
1051 
1052 		wcid_idx = wcid->idx;
1053 	} else {
1054 		wcid_idx = le32_get_bits(txwi[1], MT_TXD1_WLAN_IDX);
1055 	}
1056 
1057 	__mt76_tx_complete_skb(mdev, wcid_idx, t->skb, free_list);
1058 out:
1059 	t->skb = NULL;
1060 	mt76_put_txwi(mdev, t);
1061 }
1062 EXPORT_SYMBOL_GPL(mt7925_txwi_free);
1063 
1064 static void
1065 mt7925_mac_tx_free(struct mt792x_dev *dev, void *data, int len)
1066 {
1067 	__le32 *tx_free = (__le32 *)data, *cur_info;
1068 	struct mt76_dev *mdev = &dev->mt76;
1069 	struct mt76_txwi_cache *txwi;
1070 	struct ieee80211_sta *sta = NULL;
1071 	struct mt76_wcid *wcid = NULL;
1072 	LIST_HEAD(free_list);
1073 	struct sk_buff *skb, *tmp;
1074 	void *end = data + len;
1075 	bool wake = false;
1076 	u16 total, count = 0;
1077 
1078 	/* clean DMA queues and unmap buffers first */
1079 	mt76_queue_tx_cleanup(dev, dev->mphy.q_tx[MT_TXQ_PSD], false);
1080 	mt76_queue_tx_cleanup(dev, dev->mphy.q_tx[MT_TXQ_BE], false);
1081 
1082 	if (WARN_ON_ONCE(le32_get_bits(tx_free[1], MT_TXFREE1_VER) < 4))
1083 		return;
1084 
1085 	total = le32_get_bits(tx_free[0], MT_TXFREE0_MSDU_CNT);
1086 	for (cur_info = &tx_free[2]; count < total; cur_info++) {
1087 		u32 msdu, info;
1088 		u8 i;
1089 
1090 		if (WARN_ON_ONCE((void *)cur_info >= end))
1091 			return;
1092 		/* 1'b1: new wcid pair.
1093 		 * 1'b0: msdu_id with the same 'wcid pair' as above.
1094 		 */
1095 		info = le32_to_cpu(*cur_info);
1096 		if (info & MT_TXFREE_INFO_PAIR) {
1097 			struct mt792x_sta *msta;
1098 			u16 idx;
1099 
1100 			idx = FIELD_GET(MT_TXFREE_INFO_WLAN_ID, info);
1101 			wcid = rcu_dereference(dev->mt76.wcid[idx]);
1102 			sta = wcid_to_sta(wcid);
1103 			if (!sta)
1104 				continue;
1105 
1106 			msta = container_of(wcid, struct mt792x_sta, wcid);
1107 			spin_lock_bh(&mdev->sta_poll_lock);
1108 			if (list_empty(&msta->wcid.poll_list))
1109 				list_add_tail(&msta->wcid.poll_list,
1110 					      &mdev->sta_poll_list);
1111 			spin_unlock_bh(&mdev->sta_poll_lock);
1112 			continue;
1113 		}
1114 
1115 		if (info & MT_TXFREE_INFO_HEADER) {
1116 			if (wcid) {
1117 				wcid->stats.tx_retries +=
1118 					FIELD_GET(MT_TXFREE_INFO_COUNT, info) - 1;
1119 				wcid->stats.tx_failed +=
1120 					!!FIELD_GET(MT_TXFREE_INFO_STAT, info);
1121 			}
1122 			continue;
1123 		}
1124 
1125 		for (i = 0; i < 2; i++) {
1126 			msdu = (info >> (15 * i)) & MT_TXFREE_INFO_MSDU_ID;
1127 			if (msdu == MT_TXFREE_INFO_MSDU_ID)
1128 				continue;
1129 
1130 			count++;
1131 			txwi = mt76_token_release(mdev, msdu, &wake);
1132 			if (!txwi)
1133 				continue;
1134 
1135 			mt7925_txwi_free(dev, txwi, sta, 0, &free_list);
1136 		}
1137 	}
1138 
1139 	mt7925_mac_sta_poll(dev);
1140 
1141 	if (wake)
1142 		mt76_set_tx_blocked(&dev->mt76, false);
1143 
1144 	mt76_worker_schedule(&dev->mt76.tx_worker);
1145 
1146 	list_for_each_entry_safe(skb, tmp, &free_list, list) {
1147 		skb_list_del_init(skb);
1148 		napi_consume_skb(skb, 1);
1149 	}
1150 }
1151 
1152 bool mt7925_rx_check(struct mt76_dev *mdev, void *data, int len)
1153 {
1154 	struct mt792x_dev *dev = container_of(mdev, struct mt792x_dev, mt76);
1155 	__le32 *rxd = (__le32 *)data;
1156 	__le32 *end = (__le32 *)&rxd[len / 4];
1157 	enum rx_pkt_type type;
1158 
1159 	type = le32_get_bits(rxd[0], MT_RXD0_PKT_TYPE);
1160 	if (type != PKT_TYPE_NORMAL) {
1161 		u32 sw_type = le32_get_bits(rxd[0], MT_RXD0_SW_PKT_TYPE_MASK);
1162 
1163 		if (unlikely((sw_type & MT_RXD0_SW_PKT_TYPE_MAP) ==
1164 			     MT_RXD0_SW_PKT_TYPE_FRAME))
1165 			return true;
1166 	}
1167 
1168 	switch (type) {
1169 	case PKT_TYPE_TXRX_NOTIFY:
1170 		/* PKT_TYPE_TXRX_NOTIFY can be received only by mmio devices */
1171 		mt7925_mac_tx_free(dev, data, len); /* mmio */
1172 		return false;
1173 	case PKT_TYPE_TXS:
1174 		for (rxd += 4; rxd + 12 <= end; rxd += 12)
1175 			mt7925_mac_add_txs(dev, rxd);
1176 		return false;
1177 	default:
1178 		return true;
1179 	}
1180 }
1181 EXPORT_SYMBOL_GPL(mt7925_rx_check);
1182 
1183 void mt7925_queue_rx_skb(struct mt76_dev *mdev, enum mt76_rxq_id q,
1184 			 struct sk_buff *skb, u32 *info)
1185 {
1186 	struct mt792x_dev *dev = container_of(mdev, struct mt792x_dev, mt76);
1187 	__le32 *rxd = (__le32 *)skb->data;
1188 	__le32 *end = (__le32 *)&skb->data[skb->len];
1189 	enum rx_pkt_type type;
1190 	u16 flag;
1191 
1192 	type = le32_get_bits(rxd[0], MT_RXD0_PKT_TYPE);
1193 	flag = le32_get_bits(rxd[0], MT_RXD0_PKT_FLAG);
1194 	if (type != PKT_TYPE_NORMAL) {
1195 		u32 sw_type = le32_get_bits(rxd[0], MT_RXD0_SW_PKT_TYPE_MASK);
1196 
1197 		if (unlikely((sw_type & MT_RXD0_SW_PKT_TYPE_MAP) ==
1198 			     MT_RXD0_SW_PKT_TYPE_FRAME))
1199 			type = PKT_TYPE_NORMAL;
1200 	}
1201 
1202 	if (type == PKT_TYPE_RX_EVENT && flag == 0x1)
1203 		type = PKT_TYPE_NORMAL_MCU;
1204 
1205 	switch (type) {
1206 	case PKT_TYPE_TXRX_NOTIFY:
1207 		/* PKT_TYPE_TXRX_NOTIFY can be received only by mmio devices */
1208 		mt7925_mac_tx_free(dev, skb->data, skb->len);
1209 		napi_consume_skb(skb, 1);
1210 		break;
1211 	case PKT_TYPE_RX_EVENT:
1212 		mt7925_mcu_rx_event(dev, skb);
1213 		break;
1214 	case PKT_TYPE_TXS:
1215 		for (rxd += 2; rxd + 8 <= end; rxd += 8)
1216 			mt7925_mac_add_txs(dev, rxd);
1217 		dev_kfree_skb(skb);
1218 		break;
1219 	case PKT_TYPE_NORMAL_MCU:
1220 	case PKT_TYPE_NORMAL:
1221 		if (!mt7925_mac_fill_rx(dev, skb)) {
1222 			mt76_rx(&dev->mt76, q, skb);
1223 			return;
1224 		}
1225 		fallthrough;
1226 	default:
1227 		dev_kfree_skb(skb);
1228 		break;
1229 	}
1230 }
1231 EXPORT_SYMBOL_GPL(mt7925_queue_rx_skb);
1232 
1233 static void
1234 mt7925_vif_connect_iter(void *priv, u8 *mac,
1235 			struct ieee80211_vif *vif)
1236 {
1237 	struct mt792x_vif *mvif = (struct mt792x_vif *)vif->drv_priv;
1238 	struct mt792x_dev *dev = mvif->phy->dev;
1239 	struct ieee80211_hw *hw = mt76_hw(dev);
1240 
1241 	if (vif->type == NL80211_IFTYPE_STATION)
1242 		ieee80211_disconnect(vif, true);
1243 
1244 	mt76_connac_mcu_uni_add_dev(&dev->mphy, vif, &mvif->sta.wcid, true);
1245 	mt7925_mcu_set_tx(dev, vif);
1246 
1247 	if (vif->type == NL80211_IFTYPE_AP) {
1248 		mt76_connac_mcu_uni_add_bss(dev->phy.mt76, vif, &mvif->sta.wcid,
1249 					    true, NULL);
1250 		mt7925_mcu_sta_update(dev, NULL, vif, true,
1251 				      MT76_STA_INFO_STATE_NONE);
1252 		mt7925_mcu_uni_add_beacon_offload(dev, hw, vif, true);
1253 	}
1254 }
1255 
1256 /* system error recovery */
1257 void mt7925_mac_reset_work(struct work_struct *work)
1258 {
1259 	struct mt792x_dev *dev = container_of(work, struct mt792x_dev,
1260 					      reset_work);
1261 	struct ieee80211_hw *hw = mt76_hw(dev);
1262 	struct mt76_connac_pm *pm = &dev->pm;
1263 	int i, ret;
1264 
1265 	dev_dbg(dev->mt76.dev, "chip reset\n");
1266 	dev->hw_full_reset = true;
1267 	ieee80211_stop_queues(hw);
1268 
1269 	cancel_delayed_work_sync(&dev->mphy.mac_work);
1270 	cancel_delayed_work_sync(&pm->ps_work);
1271 	cancel_work_sync(&pm->wake_work);
1272 
1273 	for (i = 0; i < 10; i++) {
1274 		mutex_lock(&dev->mt76.mutex);
1275 		ret = mt792x_dev_reset(dev);
1276 		mutex_unlock(&dev->mt76.mutex);
1277 
1278 		if (!ret)
1279 			break;
1280 	}
1281 
1282 	if (i == 10)
1283 		dev_err(dev->mt76.dev, "chip reset failed\n");
1284 
1285 	if (test_and_clear_bit(MT76_HW_SCANNING, &dev->mphy.state)) {
1286 		struct cfg80211_scan_info info = {
1287 			.aborted = true,
1288 		};
1289 
1290 		ieee80211_scan_completed(dev->mphy.hw, &info);
1291 	}
1292 
1293 	dev->hw_full_reset = false;
1294 	pm->suspended = false;
1295 	ieee80211_wake_queues(hw);
1296 	ieee80211_iterate_active_interfaces(hw,
1297 					    IEEE80211_IFACE_ITER_RESUME_ALL,
1298 					    mt7925_vif_connect_iter, NULL);
1299 	mt76_connac_power_save_sched(&dev->mt76.phy, pm);
1300 }
1301 
1302 void mt7925_coredump_work(struct work_struct *work)
1303 {
1304 	struct mt792x_dev *dev;
1305 	char *dump, *data;
1306 
1307 	dev = (struct mt792x_dev *)container_of(work, struct mt792x_dev,
1308 						coredump.work.work);
1309 
1310 	if (time_is_after_jiffies(dev->coredump.last_activity +
1311 				  4 * MT76_CONNAC_COREDUMP_TIMEOUT)) {
1312 		queue_delayed_work(dev->mt76.wq, &dev->coredump.work,
1313 				   MT76_CONNAC_COREDUMP_TIMEOUT);
1314 		return;
1315 	}
1316 
1317 	dump = vzalloc(MT76_CONNAC_COREDUMP_SZ);
1318 	data = dump;
1319 
1320 	while (true) {
1321 		struct sk_buff *skb;
1322 
1323 		spin_lock_bh(&dev->mt76.lock);
1324 		skb = __skb_dequeue(&dev->coredump.msg_list);
1325 		spin_unlock_bh(&dev->mt76.lock);
1326 
1327 		if (!skb)
1328 			break;
1329 
1330 		skb_pull(skb, sizeof(struct mt7925_mcu_rxd) + 8);
1331 		if (!dump || data + skb->len - dump > MT76_CONNAC_COREDUMP_SZ) {
1332 			dev_kfree_skb(skb);
1333 			continue;
1334 		}
1335 
1336 		memcpy(data, skb->data, skb->len);
1337 		data += skb->len;
1338 
1339 		dev_kfree_skb(skb);
1340 	}
1341 
1342 	if (dump)
1343 		dev_coredumpv(dev->mt76.dev, dump, MT76_CONNAC_COREDUMP_SZ,
1344 			      GFP_KERNEL);
1345 
1346 	mt792x_reset(&dev->mt76);
1347 }
1348 
1349 /* usb_sdio */
1350 static void
1351 mt7925_usb_sdio_write_txwi(struct mt792x_dev *dev, struct mt76_wcid *wcid,
1352 			   enum mt76_txq_id qid, struct ieee80211_sta *sta,
1353 			   struct ieee80211_key_conf *key, int pid,
1354 			   struct sk_buff *skb)
1355 {
1356 	__le32 *txwi = (__le32 *)(skb->data - MT_SDIO_TXD_SIZE);
1357 
1358 	memset(txwi, 0, MT_SDIO_TXD_SIZE);
1359 	mt7925_mac_write_txwi(&dev->mt76, txwi, skb, wcid, key, pid, qid, 0);
1360 	skb_push(skb, MT_SDIO_TXD_SIZE);
1361 }
1362 
1363 int mt7925_usb_sdio_tx_prepare_skb(struct mt76_dev *mdev, void *txwi_ptr,
1364 				   enum mt76_txq_id qid, struct mt76_wcid *wcid,
1365 				   struct ieee80211_sta *sta,
1366 				   struct mt76_tx_info *tx_info)
1367 {
1368 	struct mt792x_dev *dev = container_of(mdev, struct mt792x_dev, mt76);
1369 	struct ieee80211_tx_info *info = IEEE80211_SKB_CB(tx_info->skb);
1370 	struct ieee80211_key_conf *key = info->control.hw_key;
1371 	struct sk_buff *skb = tx_info->skb;
1372 	int err, pad, pktid;
1373 
1374 	if (unlikely(tx_info->skb->len <= ETH_HLEN))
1375 		return -EINVAL;
1376 
1377 	if (!wcid)
1378 		wcid = &dev->mt76.global_wcid;
1379 
1380 	if (sta) {
1381 		struct mt792x_sta *msta = (struct mt792x_sta *)sta->drv_priv;
1382 
1383 		if (time_after(jiffies, msta->last_txs + HZ / 4)) {
1384 			info->flags |= IEEE80211_TX_CTL_REQ_TX_STATUS;
1385 			msta->last_txs = jiffies;
1386 		}
1387 	}
1388 
1389 	pktid = mt76_tx_status_skb_add(&dev->mt76, wcid, skb);
1390 	mt7925_usb_sdio_write_txwi(dev, wcid, qid, sta, key, pktid, skb);
1391 
1392 	mt792x_skb_add_usb_sdio_hdr(dev, skb, 0);
1393 	pad = round_up(skb->len, 4) - skb->len;
1394 	if (mt76_is_usb(mdev))
1395 		pad += 4;
1396 
1397 	err = mt76_skb_adjust_pad(skb, pad);
1398 	if (err)
1399 		/* Release pktid in case of error. */
1400 		idr_remove(&wcid->pktid, pktid);
1401 
1402 	return err;
1403 }
1404 EXPORT_SYMBOL_GPL(mt7925_usb_sdio_tx_prepare_skb);
1405 
1406 void mt7925_usb_sdio_tx_complete_skb(struct mt76_dev *mdev,
1407 				     struct mt76_queue_entry *e)
1408 {
1409 	__le32 *txwi = (__le32 *)(e->skb->data + MT_SDIO_HDR_SIZE);
1410 	unsigned int headroom = MT_SDIO_TXD_SIZE + MT_SDIO_HDR_SIZE;
1411 	struct ieee80211_sta *sta;
1412 	struct mt76_wcid *wcid;
1413 	u16 idx;
1414 
1415 	idx = le32_get_bits(txwi[1], MT_TXD1_WLAN_IDX);
1416 	wcid = rcu_dereference(mdev->wcid[idx]);
1417 	sta = wcid_to_sta(wcid);
1418 
1419 	if (sta && likely(e->skb->protocol != cpu_to_be16(ETH_P_PAE)))
1420 		mt7925_tx_check_aggr(sta, txwi);
1421 
1422 	skb_pull(e->skb, headroom);
1423 	mt76_tx_complete_skb(mdev, e->wcid, e->skb);
1424 }
1425 EXPORT_SYMBOL_GPL(mt7925_usb_sdio_tx_complete_skb);
1426 
1427 bool mt7925_usb_sdio_tx_status_data(struct mt76_dev *mdev, u8 *update)
1428 {
1429 	struct mt792x_dev *dev = container_of(mdev, struct mt792x_dev, mt76);
1430 
1431 	mt792x_mutex_acquire(dev);
1432 	mt7925_mac_sta_poll(dev);
1433 	mt792x_mutex_release(dev);
1434 
1435 	return false;
1436 }
1437 EXPORT_SYMBOL_GPL(mt7925_usb_sdio_tx_status_data);
1438 
1439 #if IS_ENABLED(CONFIG_IPV6)
1440 void mt7925_set_ipv6_ns_work(struct work_struct *work)
1441 {
1442 	struct mt792x_dev *dev = container_of(work, struct mt792x_dev,
1443 						ipv6_ns_work);
1444 	struct sk_buff *skb;
1445 	int ret = 0;
1446 
1447 	do {
1448 		skb = skb_dequeue(&dev->ipv6_ns_list);
1449 
1450 		if (!skb)
1451 			break;
1452 
1453 		mt792x_mutex_acquire(dev);
1454 		ret = mt76_mcu_skb_send_msg(&dev->mt76, skb,
1455 					    MCU_UNI_CMD(OFFLOAD), true);
1456 		mt792x_mutex_release(dev);
1457 
1458 	} while (!ret);
1459 
1460 	if (ret)
1461 		skb_queue_purge(&dev->ipv6_ns_list);
1462 }
1463 #endif
1464