xref: /linux/drivers/net/wireless/quantenna/qtnfmac/commands.c (revision e9f0878c4b2004ac19581274c1ae4c61ae3ca70e)
1 /*
2  * Copyright (c) 2015-2016 Quantenna Communications, Inc.
3  *
4  * This program is free software; you can redistribute it and/or
5  * modify it under the terms of the GNU General Public License
6  * as published by the Free Software Foundation; either version 2
7  * of the License, or (at your option) any later version.
8  *
9  * This program is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  *
14  */
15 
16 #include <linux/types.h>
17 #include <linux/skbuff.h>
18 
19 #include "cfg80211.h"
20 #include "core.h"
21 #include "qlink.h"
22 #include "qlink_util.h"
23 #include "bus.h"
24 #include "commands.h"
25 
26 static int qtnf_cmd_check_reply_header(const struct qlink_resp *resp,
27 				       u16 cmd_id, u8 mac_id, u8 vif_id,
28 				       size_t resp_size)
29 {
30 	if (unlikely(le16_to_cpu(resp->cmd_id) != cmd_id)) {
31 		pr_warn("VIF%u.%u CMD%x: bad cmd_id in response: 0x%.4X\n",
32 			mac_id, vif_id, cmd_id, le16_to_cpu(resp->cmd_id));
33 		return -EINVAL;
34 	}
35 
36 	if (unlikely(resp->macid != mac_id)) {
37 		pr_warn("VIF%u.%u CMD%x: bad MAC in response: %u\n",
38 			mac_id, vif_id, cmd_id, resp->macid);
39 		return -EINVAL;
40 	}
41 
42 	if (unlikely(resp->vifid != vif_id)) {
43 		pr_warn("VIF%u.%u CMD%x: bad VIF in response: %u\n",
44 			mac_id, vif_id, cmd_id, resp->vifid);
45 		return -EINVAL;
46 	}
47 
48 	if (unlikely(le16_to_cpu(resp->mhdr.len) < resp_size)) {
49 		pr_warn("VIF%u.%u CMD%x: bad response size %u < %zu\n",
50 			mac_id, vif_id, cmd_id,
51 			le16_to_cpu(resp->mhdr.len), resp_size);
52 		return -ENOSPC;
53 	}
54 
55 	return 0;
56 }
57 
58 static int qtnf_cmd_resp_result_decode(enum qlink_cmd_result qcode)
59 {
60 	switch (qcode) {
61 	case QLINK_CMD_RESULT_OK:
62 		return 0;
63 	case QLINK_CMD_RESULT_INVALID:
64 		return -EINVAL;
65 	case QLINK_CMD_RESULT_ENOTSUPP:
66 		return -ENOTSUPP;
67 	case QLINK_CMD_RESULT_ENOTFOUND:
68 		return -ENOENT;
69 	case QLINK_CMD_RESULT_EALREADY:
70 		return -EALREADY;
71 	case QLINK_CMD_RESULT_EADDRINUSE:
72 		return -EADDRINUSE;
73 	case QLINK_CMD_RESULT_EADDRNOTAVAIL:
74 		return -EADDRNOTAVAIL;
75 	default:
76 		return -EFAULT;
77 	}
78 }
79 
80 static int qtnf_cmd_send_with_reply(struct qtnf_bus *bus,
81 				    struct sk_buff *cmd_skb,
82 				    struct sk_buff **response_skb,
83 				    u16 *result_code,
84 				    size_t const_resp_size,
85 				    size_t *var_resp_size)
86 {
87 	struct qlink_cmd *cmd;
88 	const struct qlink_resp *resp;
89 	struct sk_buff *resp_skb = NULL;
90 	u16 cmd_id;
91 	u8 mac_id, vif_id;
92 	int ret;
93 
94 	cmd = (struct qlink_cmd *)cmd_skb->data;
95 	cmd_id = le16_to_cpu(cmd->cmd_id);
96 	mac_id = cmd->macid;
97 	vif_id = cmd->vifid;
98 	cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
99 
100 	if (unlikely(bus->fw_state != QTNF_FW_STATE_ACTIVE &&
101 		     le16_to_cpu(cmd->cmd_id) != QLINK_CMD_FW_INIT)) {
102 		pr_warn("VIF%u.%u: drop cmd 0x%.4X in fw state %d\n",
103 			mac_id, vif_id, le16_to_cpu(cmd->cmd_id),
104 			bus->fw_state);
105 		dev_kfree_skb(cmd_skb);
106 		return -ENODEV;
107 	}
108 
109 	pr_debug("VIF%u.%u cmd=0x%.4X\n", mac_id, vif_id,
110 		 le16_to_cpu(cmd->cmd_id));
111 
112 	ret = qtnf_trans_send_cmd_with_resp(bus, cmd_skb, &resp_skb);
113 
114 	if (unlikely(ret))
115 		goto out;
116 
117 	resp = (const struct qlink_resp *)resp_skb->data;
118 	ret = qtnf_cmd_check_reply_header(resp, cmd_id, mac_id, vif_id,
119 					  const_resp_size);
120 
121 	if (unlikely(ret))
122 		goto out;
123 
124 	if (likely(result_code))
125 		*result_code = le16_to_cpu(resp->result);
126 
127 	/* Return length of variable part of response */
128 	if (response_skb && var_resp_size)
129 		*var_resp_size = le16_to_cpu(resp->mhdr.len) - const_resp_size;
130 
131 out:
132 	if (response_skb)
133 		*response_skb = resp_skb;
134 	else
135 		consume_skb(resp_skb);
136 
137 	return ret;
138 }
139 
140 static inline int qtnf_cmd_send(struct qtnf_bus *bus,
141 				struct sk_buff *cmd_skb,
142 				u16 *result_code)
143 {
144 	return qtnf_cmd_send_with_reply(bus, cmd_skb, NULL, result_code,
145 					sizeof(struct qlink_resp), NULL);
146 }
147 
148 static struct sk_buff *qtnf_cmd_alloc_new_cmdskb(u8 macid, u8 vifid, u16 cmd_no,
149 						 size_t cmd_size)
150 {
151 	struct qlink_cmd *cmd;
152 	struct sk_buff *cmd_skb;
153 
154 	cmd_skb = __dev_alloc_skb(sizeof(*cmd) +
155 				  QTNF_MAX_CMD_BUF_SIZE, GFP_KERNEL);
156 	if (unlikely(!cmd_skb)) {
157 		pr_err("VIF%u.%u CMD %u: alloc failed\n", macid, vifid, cmd_no);
158 		return NULL;
159 	}
160 
161 	skb_put_zero(cmd_skb, cmd_size);
162 
163 	cmd = (struct qlink_cmd *)cmd_skb->data;
164 	cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
165 	cmd->mhdr.type = cpu_to_le16(QLINK_MSG_TYPE_CMD);
166 	cmd->cmd_id = cpu_to_le16(cmd_no);
167 	cmd->macid = macid;
168 	cmd->vifid = vifid;
169 
170 	return cmd_skb;
171 }
172 
173 static void qtnf_cmd_tlv_ie_set_add(struct sk_buff *cmd_skb, u8 frame_type,
174 				    const u8 *buf, size_t len)
175 {
176 	struct qlink_tlv_ie_set *tlv;
177 
178 	tlv = (struct qlink_tlv_ie_set *)skb_put(cmd_skb, sizeof(*tlv) + len);
179 	tlv->hdr.type = cpu_to_le16(QTN_TLV_ID_IE_SET);
180 	tlv->hdr.len = cpu_to_le16(len + sizeof(*tlv) - sizeof(tlv->hdr));
181 	tlv->type = frame_type;
182 	tlv->flags = 0;
183 
184 	if (len && buf)
185 		memcpy(tlv->ie_data, buf, len);
186 }
187 
188 static inline size_t qtnf_cmd_acl_data_size(const struct cfg80211_acl_data *acl)
189 {
190 	size_t size = sizeof(struct qlink_acl_data) +
191 		      acl->n_acl_entries * sizeof(struct qlink_mac_address);
192 
193 	return size;
194 }
195 
196 static bool qtnf_cmd_start_ap_can_fit(const struct qtnf_vif *vif,
197 				      const struct cfg80211_ap_settings *s)
198 {
199 	unsigned int len = sizeof(struct qlink_cmd_start_ap);
200 
201 	len += s->ssid_len;
202 	len += s->beacon.head_len;
203 	len += s->beacon.tail_len;
204 	len += s->beacon.beacon_ies_len;
205 	len += s->beacon.proberesp_ies_len;
206 	len += s->beacon.assocresp_ies_len;
207 	len += s->beacon.probe_resp_len;
208 
209 	if (cfg80211_chandef_valid(&s->chandef))
210 		len += sizeof(struct qlink_tlv_chandef);
211 
212 	if (s->acl)
213 		len += sizeof(struct qlink_tlv_hdr) +
214 		       qtnf_cmd_acl_data_size(s->acl);
215 
216 	if (len > (sizeof(struct qlink_cmd) + QTNF_MAX_CMD_BUF_SIZE)) {
217 		pr_err("VIF%u.%u: can not fit AP settings: %u\n",
218 		       vif->mac->macid, vif->vifid, len);
219 		return false;
220 	}
221 
222 	return true;
223 }
224 
225 int qtnf_cmd_send_start_ap(struct qtnf_vif *vif,
226 			   const struct cfg80211_ap_settings *s)
227 {
228 	struct sk_buff *cmd_skb;
229 	struct qlink_cmd_start_ap *cmd;
230 	struct qlink_auth_encr *aen;
231 	u16 res_code = QLINK_CMD_RESULT_OK;
232 	int ret;
233 	int i;
234 
235 	if (!qtnf_cmd_start_ap_can_fit(vif, s))
236 		return -E2BIG;
237 
238 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
239 					    QLINK_CMD_START_AP,
240 					    sizeof(*cmd));
241 	if (!cmd_skb)
242 		return -ENOMEM;
243 
244 	cmd = (struct qlink_cmd_start_ap *)cmd_skb->data;
245 	cmd->dtim_period = s->dtim_period;
246 	cmd->beacon_interval = cpu_to_le16(s->beacon_interval);
247 	cmd->hidden_ssid = qlink_hidden_ssid_nl2q(s->hidden_ssid);
248 	cmd->inactivity_timeout = cpu_to_le16(s->inactivity_timeout);
249 	cmd->smps_mode = s->smps_mode;
250 	cmd->p2p_ctwindow = s->p2p_ctwindow;
251 	cmd->p2p_opp_ps = s->p2p_opp_ps;
252 	cmd->pbss = s->pbss;
253 	cmd->ht_required = s->ht_required;
254 	cmd->vht_required = s->vht_required;
255 
256 	aen = &cmd->aen;
257 	aen->auth_type = s->auth_type;
258 	aen->privacy = !!s->privacy;
259 	aen->wpa_versions = cpu_to_le32(s->crypto.wpa_versions);
260 	aen->cipher_group = cpu_to_le32(s->crypto.cipher_group);
261 	aen->n_ciphers_pairwise = cpu_to_le32(s->crypto.n_ciphers_pairwise);
262 	for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
263 		aen->ciphers_pairwise[i] =
264 				cpu_to_le32(s->crypto.ciphers_pairwise[i]);
265 	aen->n_akm_suites = cpu_to_le32(s->crypto.n_akm_suites);
266 	for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
267 		aen->akm_suites[i] = cpu_to_le32(s->crypto.akm_suites[i]);
268 	aen->control_port = s->crypto.control_port;
269 	aen->control_port_no_encrypt = s->crypto.control_port_no_encrypt;
270 	aen->control_port_ethertype =
271 		cpu_to_le16(be16_to_cpu(s->crypto.control_port_ethertype));
272 
273 	if (s->ssid && s->ssid_len > 0 && s->ssid_len <= IEEE80211_MAX_SSID_LEN)
274 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, s->ssid,
275 					 s->ssid_len);
276 
277 	if (cfg80211_chandef_valid(&s->chandef)) {
278 		struct qlink_tlv_chandef *chtlv =
279 			(struct qlink_tlv_chandef *)skb_put(cmd_skb,
280 							    sizeof(*chtlv));
281 
282 		chtlv->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANDEF);
283 		chtlv->hdr.len = cpu_to_le16(sizeof(*chtlv) -
284 					     sizeof(chtlv->hdr));
285 		qlink_chandef_cfg2q(&s->chandef, &chtlv->chdef);
286 	}
287 
288 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_HEAD,
289 				s->beacon.head, s->beacon.head_len);
290 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_TAIL,
291 				s->beacon.tail, s->beacon.tail_len);
292 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_BEACON_IES,
293 				s->beacon.beacon_ies, s->beacon.beacon_ies_len);
294 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_RESP,
295 				s->beacon.probe_resp, s->beacon.probe_resp_len);
296 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_RESP_IES,
297 				s->beacon.proberesp_ies,
298 				s->beacon.proberesp_ies_len);
299 	qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_ASSOC_RESP,
300 				s->beacon.assocresp_ies,
301 				s->beacon.assocresp_ies_len);
302 
303 	if (s->ht_cap) {
304 		struct qlink_tlv_hdr *tlv = (struct qlink_tlv_hdr *)
305 			skb_put(cmd_skb, sizeof(*tlv) + sizeof(*s->ht_cap));
306 
307 		tlv->type = cpu_to_le16(WLAN_EID_HT_CAPABILITY);
308 		tlv->len = cpu_to_le16(sizeof(*s->ht_cap));
309 		memcpy(tlv->val, s->ht_cap, sizeof(*s->ht_cap));
310 	}
311 
312 	if (s->vht_cap) {
313 		struct qlink_tlv_hdr *tlv = (struct qlink_tlv_hdr *)
314 			skb_put(cmd_skb, sizeof(*tlv) + sizeof(*s->vht_cap));
315 
316 		tlv->type = cpu_to_le16(WLAN_EID_VHT_CAPABILITY);
317 		tlv->len = cpu_to_le16(sizeof(*s->vht_cap));
318 		memcpy(tlv->val, s->vht_cap, sizeof(*s->vht_cap));
319 	}
320 
321 	if (s->acl) {
322 		size_t acl_size = qtnf_cmd_acl_data_size(s->acl);
323 		struct qlink_tlv_hdr *tlv =
324 			skb_put(cmd_skb, sizeof(*tlv) + acl_size);
325 
326 		tlv->type = cpu_to_le16(QTN_TLV_ID_ACL_DATA);
327 		tlv->len = cpu_to_le16(acl_size);
328 		qlink_acl_data_cfg2q(s->acl, (struct qlink_acl_data *)tlv->val);
329 	}
330 
331 	qtnf_bus_lock(vif->mac->bus);
332 
333 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
334 
335 	if (unlikely(ret))
336 		goto out;
337 
338 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
339 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
340 		       vif->vifid, res_code);
341 		ret = -EFAULT;
342 		goto out;
343 	}
344 
345 	netif_carrier_on(vif->netdev);
346 
347 out:
348 	qtnf_bus_unlock(vif->mac->bus);
349 	return ret;
350 }
351 
352 int qtnf_cmd_send_stop_ap(struct qtnf_vif *vif)
353 {
354 	struct sk_buff *cmd_skb;
355 	u16 res_code = QLINK_CMD_RESULT_OK;
356 	int ret;
357 
358 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
359 					    QLINK_CMD_STOP_AP,
360 					    sizeof(struct qlink_cmd));
361 	if (!cmd_skb)
362 		return -ENOMEM;
363 
364 	qtnf_bus_lock(vif->mac->bus);
365 
366 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
367 
368 	if (unlikely(ret))
369 		goto out;
370 
371 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
372 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
373 		       vif->vifid, res_code);
374 		ret = -EFAULT;
375 		goto out;
376 	}
377 
378 	netif_carrier_off(vif->netdev);
379 
380 out:
381 	qtnf_bus_unlock(vif->mac->bus);
382 	return ret;
383 }
384 
385 int qtnf_cmd_send_register_mgmt(struct qtnf_vif *vif, u16 frame_type, bool reg)
386 {
387 	struct sk_buff *cmd_skb;
388 	struct qlink_cmd_mgmt_frame_register *cmd;
389 	u16 res_code = QLINK_CMD_RESULT_OK;
390 	int ret;
391 
392 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
393 					    QLINK_CMD_REGISTER_MGMT,
394 					    sizeof(*cmd));
395 	if (!cmd_skb)
396 		return -ENOMEM;
397 
398 	qtnf_bus_lock(vif->mac->bus);
399 
400 	cmd = (struct qlink_cmd_mgmt_frame_register *)cmd_skb->data;
401 	cmd->frame_type = cpu_to_le16(frame_type);
402 	cmd->do_register = reg;
403 
404 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
405 
406 	if (unlikely(ret))
407 		goto out;
408 
409 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
410 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
411 		       vif->vifid, res_code);
412 		ret = -EFAULT;
413 		goto out;
414 	}
415 
416 out:
417 	qtnf_bus_unlock(vif->mac->bus);
418 	return ret;
419 }
420 
421 int qtnf_cmd_send_mgmt_frame(struct qtnf_vif *vif, u32 cookie, u16 flags,
422 			     u16 freq, const u8 *buf, size_t len)
423 {
424 	struct sk_buff *cmd_skb;
425 	struct qlink_cmd_mgmt_frame_tx *cmd;
426 	u16 res_code = QLINK_CMD_RESULT_OK;
427 	int ret;
428 
429 	if (sizeof(*cmd) + len > QTNF_MAX_CMD_BUF_SIZE) {
430 		pr_warn("VIF%u.%u: frame is too big: %zu\n", vif->mac->macid,
431 			vif->vifid, len);
432 		return -E2BIG;
433 	}
434 
435 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
436 					    QLINK_CMD_SEND_MGMT_FRAME,
437 					    sizeof(*cmd));
438 	if (!cmd_skb)
439 		return -ENOMEM;
440 
441 	qtnf_bus_lock(vif->mac->bus);
442 
443 	cmd = (struct qlink_cmd_mgmt_frame_tx *)cmd_skb->data;
444 	cmd->cookie = cpu_to_le32(cookie);
445 	cmd->freq = cpu_to_le16(freq);
446 	cmd->flags = cpu_to_le16(flags);
447 
448 	if (len && buf)
449 		qtnf_cmd_skb_put_buffer(cmd_skb, buf, len);
450 
451 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
452 
453 	if (unlikely(ret))
454 		goto out;
455 
456 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
457 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
458 		       vif->vifid, res_code);
459 		ret = -EFAULT;
460 		goto out;
461 	}
462 
463 out:
464 	qtnf_bus_unlock(vif->mac->bus);
465 	return ret;
466 }
467 
468 int qtnf_cmd_send_mgmt_set_appie(struct qtnf_vif *vif, u8 frame_type,
469 				 const u8 *buf, size_t len)
470 {
471 	struct sk_buff *cmd_skb;
472 	u16 res_code = QLINK_CMD_RESULT_OK;
473 	int ret;
474 
475 	if (len > QTNF_MAX_CMD_BUF_SIZE) {
476 		pr_warn("VIF%u.%u: %u frame is too big: %zu\n", vif->mac->macid,
477 			vif->vifid, frame_type, len);
478 		return -E2BIG;
479 	}
480 
481 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
482 					    QLINK_CMD_MGMT_SET_APPIE,
483 					    sizeof(struct qlink_cmd));
484 	if (!cmd_skb)
485 		return -ENOMEM;
486 
487 	qtnf_cmd_tlv_ie_set_add(cmd_skb, frame_type, buf, len);
488 
489 	qtnf_bus_lock(vif->mac->bus);
490 
491 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
492 
493 	if (unlikely(ret))
494 		goto out;
495 
496 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
497 		pr_err("VIF%u.%u frame %u: CMD failed: %u\n", vif->mac->macid,
498 		       vif->vifid, frame_type, res_code);
499 		ret = -EFAULT;
500 		goto out;
501 	}
502 
503 out:
504 	qtnf_bus_unlock(vif->mac->bus);
505 	return ret;
506 }
507 
508 static void
509 qtnf_sta_info_parse_rate(struct rate_info *rate_dst,
510 			 const struct qlink_sta_info_rate *rate_src)
511 {
512 	rate_dst->legacy = get_unaligned_le16(&rate_src->rate) * 10;
513 
514 	rate_dst->mcs = rate_src->mcs;
515 	rate_dst->nss = rate_src->nss;
516 	rate_dst->flags = 0;
517 
518 	switch (rate_src->bw) {
519 	case QLINK_CHAN_WIDTH_5:
520 		rate_dst->bw = RATE_INFO_BW_5;
521 		break;
522 	case QLINK_CHAN_WIDTH_10:
523 		rate_dst->bw = RATE_INFO_BW_10;
524 		break;
525 	case QLINK_CHAN_WIDTH_20:
526 	case QLINK_CHAN_WIDTH_20_NOHT:
527 		rate_dst->bw = RATE_INFO_BW_20;
528 		break;
529 	case QLINK_CHAN_WIDTH_40:
530 		rate_dst->bw = RATE_INFO_BW_40;
531 		break;
532 	case QLINK_CHAN_WIDTH_80:
533 		rate_dst->bw = RATE_INFO_BW_80;
534 		break;
535 	case QLINK_CHAN_WIDTH_160:
536 		rate_dst->bw = RATE_INFO_BW_160;
537 		break;
538 	default:
539 		rate_dst->bw = 0;
540 		break;
541 	}
542 
543 	if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_HT_MCS)
544 		rate_dst->flags |= RATE_INFO_FLAGS_MCS;
545 	else if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_VHT_MCS)
546 		rate_dst->flags |= RATE_INFO_FLAGS_VHT_MCS;
547 }
548 
549 static void
550 qtnf_sta_info_parse_flags(struct nl80211_sta_flag_update *dst,
551 			  const struct qlink_sta_info_state *src)
552 {
553 	u32 mask, value;
554 
555 	dst->mask = 0;
556 	dst->set = 0;
557 
558 	mask = le32_to_cpu(src->mask);
559 	value = le32_to_cpu(src->value);
560 
561 	if (mask & QLINK_STA_FLAG_AUTHORIZED) {
562 		dst->mask |= BIT(NL80211_STA_FLAG_AUTHORIZED);
563 		if (value & QLINK_STA_FLAG_AUTHORIZED)
564 			dst->set |= BIT(NL80211_STA_FLAG_AUTHORIZED);
565 	}
566 
567 	if (mask & QLINK_STA_FLAG_SHORT_PREAMBLE) {
568 		dst->mask |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
569 		if (value & QLINK_STA_FLAG_SHORT_PREAMBLE)
570 			dst->set |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
571 	}
572 
573 	if (mask & QLINK_STA_FLAG_WME) {
574 		dst->mask |= BIT(NL80211_STA_FLAG_WME);
575 		if (value & QLINK_STA_FLAG_WME)
576 			dst->set |= BIT(NL80211_STA_FLAG_WME);
577 	}
578 
579 	if (mask & QLINK_STA_FLAG_MFP) {
580 		dst->mask |= BIT(NL80211_STA_FLAG_MFP);
581 		if (value & QLINK_STA_FLAG_MFP)
582 			dst->set |= BIT(NL80211_STA_FLAG_MFP);
583 	}
584 
585 	if (mask & QLINK_STA_FLAG_AUTHENTICATED) {
586 		dst->mask |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
587 		if (value & QLINK_STA_FLAG_AUTHENTICATED)
588 			dst->set |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
589 	}
590 
591 	if (mask & QLINK_STA_FLAG_TDLS_PEER) {
592 		dst->mask |= BIT(NL80211_STA_FLAG_TDLS_PEER);
593 		if (value & QLINK_STA_FLAG_TDLS_PEER)
594 			dst->set |= BIT(NL80211_STA_FLAG_TDLS_PEER);
595 	}
596 
597 	if (mask & QLINK_STA_FLAG_ASSOCIATED) {
598 		dst->mask |= BIT(NL80211_STA_FLAG_ASSOCIATED);
599 		if (value & QLINK_STA_FLAG_ASSOCIATED)
600 			dst->set |= BIT(NL80211_STA_FLAG_ASSOCIATED);
601 	}
602 }
603 
604 static void
605 qtnf_cmd_sta_info_parse(struct station_info *sinfo,
606 			const struct qlink_tlv_hdr *tlv,
607 			size_t resp_size)
608 {
609 	const struct qlink_sta_stats *stats = NULL;
610 	const u8 *map = NULL;
611 	unsigned int map_len = 0;
612 	unsigned int stats_len = 0;
613 	u16 tlv_len;
614 
615 #define qtnf_sta_stat_avail(stat_name, bitn)	\
616 	(qtnf_utils_is_bit_set(map, bitn, map_len) && \
617 	 (offsetofend(struct qlink_sta_stats, stat_name) <= stats_len))
618 
619 	while (resp_size >= sizeof(*tlv)) {
620 		tlv_len = le16_to_cpu(tlv->len);
621 
622 		switch (le16_to_cpu(tlv->type)) {
623 		case QTN_TLV_ID_STA_STATS_MAP:
624 			map_len = tlv_len;
625 			map = tlv->val;
626 			break;
627 		case QTN_TLV_ID_STA_STATS:
628 			stats_len = tlv_len;
629 			stats = (const struct qlink_sta_stats *)tlv->val;
630 			break;
631 		default:
632 			break;
633 		}
634 
635 		resp_size -= tlv_len + sizeof(*tlv);
636 		tlv = (const struct qlink_tlv_hdr *)(tlv->val + tlv_len);
637 	}
638 
639 	if (!map || !stats)
640 		return;
641 
642 	if (qtnf_sta_stat_avail(inactive_time, QLINK_STA_INFO_INACTIVE_TIME)) {
643 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_INACTIVE_TIME);
644 		sinfo->inactive_time = le32_to_cpu(stats->inactive_time);
645 	}
646 
647 	if (qtnf_sta_stat_avail(connected_time,
648 				QLINK_STA_INFO_CONNECTED_TIME)) {
649 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_CONNECTED_TIME);
650 		sinfo->connected_time = le32_to_cpu(stats->connected_time);
651 	}
652 
653 	if (qtnf_sta_stat_avail(signal, QLINK_STA_INFO_SIGNAL)) {
654 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL);
655 		sinfo->signal = stats->signal - QLINK_RSSI_OFFSET;
656 	}
657 
658 	if (qtnf_sta_stat_avail(signal_avg, QLINK_STA_INFO_SIGNAL_AVG)) {
659 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL_AVG);
660 		sinfo->signal_avg = stats->signal_avg - QLINK_RSSI_OFFSET;
661 	}
662 
663 	if (qtnf_sta_stat_avail(rxrate, QLINK_STA_INFO_RX_BITRATE)) {
664 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BITRATE);
665 		qtnf_sta_info_parse_rate(&sinfo->rxrate, &stats->rxrate);
666 	}
667 
668 	if (qtnf_sta_stat_avail(txrate, QLINK_STA_INFO_TX_BITRATE)) {
669 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BITRATE);
670 		qtnf_sta_info_parse_rate(&sinfo->txrate, &stats->txrate);
671 	}
672 
673 	if (qtnf_sta_stat_avail(sta_flags, QLINK_STA_INFO_STA_FLAGS)) {
674 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_STA_FLAGS);
675 		qtnf_sta_info_parse_flags(&sinfo->sta_flags, &stats->sta_flags);
676 	}
677 
678 	if (qtnf_sta_stat_avail(rx_bytes, QLINK_STA_INFO_RX_BYTES)) {
679 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BYTES);
680 		sinfo->rx_bytes = le64_to_cpu(stats->rx_bytes);
681 	}
682 
683 	if (qtnf_sta_stat_avail(tx_bytes, QLINK_STA_INFO_TX_BYTES)) {
684 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BYTES);
685 		sinfo->tx_bytes = le64_to_cpu(stats->tx_bytes);
686 	}
687 
688 	if (qtnf_sta_stat_avail(rx_bytes, QLINK_STA_INFO_RX_BYTES64)) {
689 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BYTES64);
690 		sinfo->rx_bytes = le64_to_cpu(stats->rx_bytes);
691 	}
692 
693 	if (qtnf_sta_stat_avail(tx_bytes, QLINK_STA_INFO_TX_BYTES64)) {
694 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BYTES64);
695 		sinfo->tx_bytes = le64_to_cpu(stats->tx_bytes);
696 	}
697 
698 	if (qtnf_sta_stat_avail(rx_packets, QLINK_STA_INFO_RX_PACKETS)) {
699 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_PACKETS);
700 		sinfo->rx_packets = le32_to_cpu(stats->rx_packets);
701 	}
702 
703 	if (qtnf_sta_stat_avail(tx_packets, QLINK_STA_INFO_TX_PACKETS)) {
704 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_PACKETS);
705 		sinfo->tx_packets = le32_to_cpu(stats->tx_packets);
706 	}
707 
708 	if (qtnf_sta_stat_avail(rx_beacon, QLINK_STA_INFO_BEACON_RX)) {
709 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_BEACON_RX);
710 		sinfo->rx_beacon = le64_to_cpu(stats->rx_beacon);
711 	}
712 
713 	if (qtnf_sta_stat_avail(rx_dropped_misc, QLINK_STA_INFO_RX_DROP_MISC)) {
714 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_DROP_MISC);
715 		sinfo->rx_dropped_misc = le32_to_cpu(stats->rx_dropped_misc);
716 	}
717 
718 	if (qtnf_sta_stat_avail(tx_failed, QLINK_STA_INFO_TX_FAILED)) {
719 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_FAILED);
720 		sinfo->tx_failed = le32_to_cpu(stats->tx_failed);
721 	}
722 
723 #undef qtnf_sta_stat_avail
724 }
725 
726 int qtnf_cmd_get_sta_info(struct qtnf_vif *vif, const u8 *sta_mac,
727 			  struct station_info *sinfo)
728 {
729 	struct sk_buff *cmd_skb, *resp_skb = NULL;
730 	struct qlink_cmd_get_sta_info *cmd;
731 	const struct qlink_resp_get_sta_info *resp;
732 	size_t var_resp_len;
733 	u16 res_code = QLINK_CMD_RESULT_OK;
734 	int ret = 0;
735 
736 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
737 					    QLINK_CMD_GET_STA_INFO,
738 					    sizeof(*cmd));
739 	if (!cmd_skb)
740 		return -ENOMEM;
741 
742 	qtnf_bus_lock(vif->mac->bus);
743 
744 	cmd = (struct qlink_cmd_get_sta_info *)cmd_skb->data;
745 	ether_addr_copy(cmd->sta_addr, sta_mac);
746 
747 	ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
748 				       &res_code, sizeof(*resp),
749 				       &var_resp_len);
750 
751 	if (unlikely(ret))
752 		goto out;
753 
754 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
755 		switch (res_code) {
756 		case QLINK_CMD_RESULT_ENOTFOUND:
757 			pr_warn("VIF%u.%u: %pM STA not found\n",
758 				vif->mac->macid, vif->vifid, sta_mac);
759 			ret = -ENOENT;
760 			break;
761 		default:
762 			pr_err("VIF%u.%u: can't get info for %pM: %u\n",
763 			       vif->mac->macid, vif->vifid, sta_mac, res_code);
764 			ret = -EFAULT;
765 			break;
766 		}
767 		goto out;
768 	}
769 
770 	resp = (const struct qlink_resp_get_sta_info *)resp_skb->data;
771 
772 	if (unlikely(!ether_addr_equal(sta_mac, resp->sta_addr))) {
773 		pr_err("VIF%u.%u: wrong mac in reply: %pM != %pM\n",
774 		       vif->mac->macid, vif->vifid, resp->sta_addr, sta_mac);
775 		ret = -EINVAL;
776 		goto out;
777 	}
778 
779 	qtnf_cmd_sta_info_parse(sinfo,
780 				(const struct qlink_tlv_hdr *)resp->info,
781 				var_resp_len);
782 
783 out:
784 	qtnf_bus_unlock(vif->mac->bus);
785 	consume_skb(resp_skb);
786 
787 	return ret;
788 }
789 
790 static int qtnf_cmd_send_add_change_intf(struct qtnf_vif *vif,
791 					 enum nl80211_iftype iftype,
792 					 u8 *mac_addr,
793 					 enum qlink_cmd_type cmd_type)
794 {
795 	struct sk_buff *cmd_skb, *resp_skb = NULL;
796 	struct qlink_cmd_manage_intf *cmd;
797 	const struct qlink_resp_manage_intf *resp;
798 	u16 res_code = QLINK_CMD_RESULT_OK;
799 	int ret = 0;
800 
801 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
802 					    cmd_type,
803 					    sizeof(*cmd));
804 	if (!cmd_skb)
805 		return -ENOMEM;
806 
807 	qtnf_bus_lock(vif->mac->bus);
808 
809 	cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
810 
811 	switch (iftype) {
812 	case NL80211_IFTYPE_AP:
813 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
814 		break;
815 	case NL80211_IFTYPE_STATION:
816 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
817 		break;
818 	default:
819 		pr_err("VIF%u.%u: unsupported type %d\n", vif->mac->macid,
820 		       vif->vifid, iftype);
821 		ret = -EINVAL;
822 		goto out;
823 	}
824 
825 	if (mac_addr)
826 		ether_addr_copy(cmd->intf_info.mac_addr, mac_addr);
827 	else
828 		eth_zero_addr(cmd->intf_info.mac_addr);
829 
830 	ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
831 				       &res_code, sizeof(*resp), NULL);
832 
833 	if (unlikely(ret))
834 		goto out;
835 
836 	ret = qtnf_cmd_resp_result_decode(res_code);
837 	if (ret) {
838 		pr_err("VIF%u.%u: CMD %d failed: %u\n", vif->mac->macid,
839 		       vif->vifid, cmd_type, res_code);
840 		goto out;
841 	}
842 
843 	resp = (const struct qlink_resp_manage_intf *)resp_skb->data;
844 	ether_addr_copy(vif->mac_addr, resp->intf_info.mac_addr);
845 
846 out:
847 	qtnf_bus_unlock(vif->mac->bus);
848 	consume_skb(resp_skb);
849 
850 	return ret;
851 }
852 
853 int qtnf_cmd_send_add_intf(struct qtnf_vif *vif,
854 			   enum nl80211_iftype iftype, u8 *mac_addr)
855 {
856 	return qtnf_cmd_send_add_change_intf(vif, iftype, mac_addr,
857 			QLINK_CMD_ADD_INTF);
858 }
859 
860 int qtnf_cmd_send_change_intf_type(struct qtnf_vif *vif,
861 				   enum nl80211_iftype iftype, u8 *mac_addr)
862 {
863 	return qtnf_cmd_send_add_change_intf(vif, iftype, mac_addr,
864 					     QLINK_CMD_CHANGE_INTF);
865 }
866 
867 int qtnf_cmd_send_del_intf(struct qtnf_vif *vif)
868 {
869 	struct sk_buff *cmd_skb;
870 	struct qlink_cmd_manage_intf *cmd;
871 	u16 res_code = QLINK_CMD_RESULT_OK;
872 	int ret = 0;
873 
874 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
875 					    QLINK_CMD_DEL_INTF,
876 					    sizeof(*cmd));
877 	if (!cmd_skb)
878 		return -ENOMEM;
879 
880 	qtnf_bus_lock(vif->mac->bus);
881 
882 	cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
883 
884 	switch (vif->wdev.iftype) {
885 	case NL80211_IFTYPE_AP:
886 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
887 		break;
888 	case NL80211_IFTYPE_STATION:
889 		cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
890 		break;
891 	default:
892 		pr_warn("VIF%u.%u: unsupported iftype %d\n", vif->mac->macid,
893 			vif->vifid, vif->wdev.iftype);
894 		ret = -EINVAL;
895 		goto out;
896 	}
897 
898 	eth_zero_addr(cmd->intf_info.mac_addr);
899 
900 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
901 
902 	if (unlikely(ret))
903 		goto out;
904 
905 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
906 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
907 		       vif->vifid, res_code);
908 		ret = -EFAULT;
909 		goto out;
910 	}
911 
912 out:
913 	qtnf_bus_unlock(vif->mac->bus);
914 	return ret;
915 }
916 
917 static u32 qtnf_cmd_resp_reg_rule_flags_parse(u32 qflags)
918 {
919 	u32 flags = 0;
920 
921 	if (qflags & QLINK_RRF_NO_OFDM)
922 		flags |= NL80211_RRF_NO_OFDM;
923 
924 	if (qflags & QLINK_RRF_NO_CCK)
925 		flags |= NL80211_RRF_NO_CCK;
926 
927 	if (qflags & QLINK_RRF_NO_INDOOR)
928 		flags |= NL80211_RRF_NO_INDOOR;
929 
930 	if (qflags & QLINK_RRF_NO_OUTDOOR)
931 		flags |= NL80211_RRF_NO_OUTDOOR;
932 
933 	if (qflags & QLINK_RRF_DFS)
934 		flags |= NL80211_RRF_DFS;
935 
936 	if (qflags & QLINK_RRF_PTP_ONLY)
937 		flags |= NL80211_RRF_PTP_ONLY;
938 
939 	if (qflags & QLINK_RRF_PTMP_ONLY)
940 		flags |= NL80211_RRF_PTMP_ONLY;
941 
942 	if (qflags & QLINK_RRF_NO_IR)
943 		flags |= NL80211_RRF_NO_IR;
944 
945 	if (qflags & QLINK_RRF_AUTO_BW)
946 		flags |= NL80211_RRF_AUTO_BW;
947 
948 	if (qflags & QLINK_RRF_IR_CONCURRENT)
949 		flags |= NL80211_RRF_IR_CONCURRENT;
950 
951 	if (qflags & QLINK_RRF_NO_HT40MINUS)
952 		flags |= NL80211_RRF_NO_HT40MINUS;
953 
954 	if (qflags & QLINK_RRF_NO_HT40PLUS)
955 		flags |= NL80211_RRF_NO_HT40PLUS;
956 
957 	if (qflags & QLINK_RRF_NO_80MHZ)
958 		flags |= NL80211_RRF_NO_80MHZ;
959 
960 	if (qflags & QLINK_RRF_NO_160MHZ)
961 		flags |= NL80211_RRF_NO_160MHZ;
962 
963 	return flags;
964 }
965 
966 static int
967 qtnf_cmd_resp_proc_hw_info(struct qtnf_bus *bus,
968 			   const struct qlink_resp_get_hw_info *resp,
969 			   size_t info_len)
970 {
971 	struct qtnf_hw_info *hwinfo = &bus->hw_info;
972 	const struct qlink_tlv_hdr *tlv;
973 	const struct qlink_tlv_reg_rule *tlv_rule;
974 	const char *bld_name = NULL;
975 	const char *bld_rev = NULL;
976 	const char *bld_type = NULL;
977 	const char *bld_label = NULL;
978 	u32 bld_tmstamp = 0;
979 	u32 plat_id = 0;
980 	const char *hw_id = NULL;
981 	const char *calibration_ver = NULL;
982 	const char *uboot_ver = NULL;
983 	u32 hw_ver = 0;
984 	struct ieee80211_reg_rule *rule;
985 	u16 tlv_type;
986 	u16 tlv_value_len;
987 	unsigned int rule_idx = 0;
988 
989 	if (WARN_ON(resp->n_reg_rules > NL80211_MAX_SUPP_REG_RULES))
990 		return -E2BIG;
991 
992 	hwinfo->rd = kzalloc(sizeof(*hwinfo->rd)
993 			     + sizeof(struct ieee80211_reg_rule)
994 			     * resp->n_reg_rules, GFP_KERNEL);
995 
996 	if (!hwinfo->rd)
997 		return -ENOMEM;
998 
999 	hwinfo->num_mac = resp->num_mac;
1000 	hwinfo->mac_bitmap = resp->mac_bitmap;
1001 	hwinfo->fw_ver = le32_to_cpu(resp->fw_ver);
1002 	hwinfo->ql_proto_ver = le16_to_cpu(resp->ql_proto_ver);
1003 	hwinfo->total_tx_chain = resp->total_tx_chain;
1004 	hwinfo->total_rx_chain = resp->total_rx_chain;
1005 	hwinfo->hw_capab = le32_to_cpu(resp->hw_capab);
1006 	hwinfo->rd->n_reg_rules = resp->n_reg_rules;
1007 	hwinfo->rd->alpha2[0] = resp->alpha2[0];
1008 	hwinfo->rd->alpha2[1] = resp->alpha2[1];
1009 
1010 	bld_tmstamp = le32_to_cpu(resp->bld_tmstamp);
1011 	plat_id = le32_to_cpu(resp->plat_id);
1012 	hw_ver = le32_to_cpu(resp->hw_ver);
1013 
1014 	switch (resp->dfs_region) {
1015 	case QLINK_DFS_FCC:
1016 		hwinfo->rd->dfs_region = NL80211_DFS_FCC;
1017 		break;
1018 	case QLINK_DFS_ETSI:
1019 		hwinfo->rd->dfs_region = NL80211_DFS_ETSI;
1020 		break;
1021 	case QLINK_DFS_JP:
1022 		hwinfo->rd->dfs_region = NL80211_DFS_JP;
1023 		break;
1024 	case QLINK_DFS_UNSET:
1025 	default:
1026 		hwinfo->rd->dfs_region = NL80211_DFS_UNSET;
1027 		break;
1028 	}
1029 
1030 	tlv = (const struct qlink_tlv_hdr *)resp->info;
1031 
1032 	while (info_len >= sizeof(*tlv)) {
1033 		tlv_type = le16_to_cpu(tlv->type);
1034 		tlv_value_len = le16_to_cpu(tlv->len);
1035 
1036 		if (tlv_value_len + sizeof(*tlv) > info_len) {
1037 			pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
1038 				tlv_type, tlv_value_len);
1039 			return -EINVAL;
1040 		}
1041 
1042 		switch (tlv_type) {
1043 		case QTN_TLV_ID_REG_RULE:
1044 			if (rule_idx >= resp->n_reg_rules) {
1045 				pr_warn("unexpected number of rules: %u\n",
1046 					resp->n_reg_rules);
1047 				return -EINVAL;
1048 			}
1049 
1050 			if (tlv_value_len != sizeof(*tlv_rule) - sizeof(*tlv)) {
1051 				pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
1052 					tlv_type, tlv_value_len);
1053 				return -EINVAL;
1054 			}
1055 
1056 			tlv_rule = (const struct qlink_tlv_reg_rule *)tlv;
1057 			rule = &hwinfo->rd->reg_rules[rule_idx++];
1058 
1059 			rule->freq_range.start_freq_khz =
1060 				le32_to_cpu(tlv_rule->start_freq_khz);
1061 			rule->freq_range.end_freq_khz =
1062 				le32_to_cpu(tlv_rule->end_freq_khz);
1063 			rule->freq_range.max_bandwidth_khz =
1064 				le32_to_cpu(tlv_rule->max_bandwidth_khz);
1065 			rule->power_rule.max_antenna_gain =
1066 				le32_to_cpu(tlv_rule->max_antenna_gain);
1067 			rule->power_rule.max_eirp =
1068 				le32_to_cpu(tlv_rule->max_eirp);
1069 			rule->dfs_cac_ms =
1070 				le32_to_cpu(tlv_rule->dfs_cac_ms);
1071 			rule->flags = qtnf_cmd_resp_reg_rule_flags_parse(
1072 					le32_to_cpu(tlv_rule->flags));
1073 			break;
1074 		case QTN_TLV_ID_BUILD_NAME:
1075 			bld_name = (const void *)tlv->val;
1076 			break;
1077 		case QTN_TLV_ID_BUILD_REV:
1078 			bld_rev = (const void *)tlv->val;
1079 			break;
1080 		case QTN_TLV_ID_BUILD_TYPE:
1081 			bld_type = (const void *)tlv->val;
1082 			break;
1083 		case QTN_TLV_ID_BUILD_LABEL:
1084 			bld_label = (const void *)tlv->val;
1085 			break;
1086 		case QTN_TLV_ID_HW_ID:
1087 			hw_id = (const void *)tlv->val;
1088 			break;
1089 		case QTN_TLV_ID_CALIBRATION_VER:
1090 			calibration_ver = (const void *)tlv->val;
1091 			break;
1092 		case QTN_TLV_ID_UBOOT_VER:
1093 			uboot_ver = (const void *)tlv->val;
1094 			break;
1095 		case QTN_TLV_ID_MAX_SCAN_SSIDS:
1096 			hwinfo->max_scan_ssids = *tlv->val;
1097 			break;
1098 		default:
1099 			break;
1100 		}
1101 
1102 		info_len -= tlv_value_len + sizeof(*tlv);
1103 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1104 	}
1105 
1106 	if (rule_idx != resp->n_reg_rules) {
1107 		pr_warn("unexpected number of rules: expected %u got %u\n",
1108 			resp->n_reg_rules, rule_idx);
1109 		kfree(hwinfo->rd);
1110 		hwinfo->rd = NULL;
1111 		return -EINVAL;
1112 	}
1113 
1114 	pr_info("fw_version=%d, MACs map %#x, alpha2=\"%c%c\", chains Tx=%u Rx=%u, capab=0x%x\n",
1115 		hwinfo->fw_ver, hwinfo->mac_bitmap,
1116 		hwinfo->rd->alpha2[0], hwinfo->rd->alpha2[1],
1117 		hwinfo->total_tx_chain, hwinfo->total_rx_chain,
1118 		hwinfo->hw_capab);
1119 
1120 	pr_info("\nBuild name:            %s"  \
1121 		"\nBuild revision:        %s"  \
1122 		"\nBuild type:            %s"  \
1123 		"\nBuild label:           %s"  \
1124 		"\nBuild timestamp:       %lu" \
1125 		"\nPlatform ID:           %lu" \
1126 		"\nHardware ID:           %s"  \
1127 		"\nCalibration version:   %s"  \
1128 		"\nU-Boot version:        %s"  \
1129 		"\nHardware version:      0x%08x",
1130 		bld_name, bld_rev, bld_type, bld_label,
1131 		(unsigned long)bld_tmstamp,
1132 		(unsigned long)plat_id,
1133 		hw_id, calibration_ver, uboot_ver, hw_ver);
1134 
1135 	strlcpy(hwinfo->fw_version, bld_label, sizeof(hwinfo->fw_version));
1136 	hwinfo->hw_version = hw_ver;
1137 
1138 	return 0;
1139 }
1140 
1141 static void
1142 qtnf_parse_wowlan_info(struct qtnf_wmac *mac,
1143 		       const struct qlink_wowlan_capab_data *wowlan)
1144 {
1145 	struct qtnf_mac_info *mac_info = &mac->macinfo;
1146 	const struct qlink_wowlan_support *data1;
1147 	struct wiphy_wowlan_support *supp;
1148 
1149 	supp = kzalloc(sizeof(*supp), GFP_KERNEL);
1150 	if (!supp)
1151 		return;
1152 
1153 	switch (le16_to_cpu(wowlan->version)) {
1154 	case 0x1:
1155 		data1 = (struct qlink_wowlan_support *)wowlan->data;
1156 
1157 		supp->flags = WIPHY_WOWLAN_MAGIC_PKT | WIPHY_WOWLAN_DISCONNECT;
1158 		supp->n_patterns = le32_to_cpu(data1->n_patterns);
1159 		supp->pattern_max_len = le32_to_cpu(data1->pattern_max_len);
1160 		supp->pattern_min_len = le32_to_cpu(data1->pattern_min_len);
1161 
1162 		mac_info->wowlan = supp;
1163 		break;
1164 	default:
1165 		pr_warn("MAC%u: unsupported WoWLAN version 0x%x\n",
1166 			mac->macid, le16_to_cpu(wowlan->version));
1167 		kfree(supp);
1168 		break;
1169 	}
1170 }
1171 
1172 static int qtnf_parse_variable_mac_info(struct qtnf_wmac *mac,
1173 					const u8 *tlv_buf, size_t tlv_buf_size)
1174 {
1175 	struct ieee80211_iface_combination *comb = NULL;
1176 	size_t n_comb = 0;
1177 	struct ieee80211_iface_limit *limits;
1178 	const struct qlink_iface_comb_num *comb_num;
1179 	const struct qlink_iface_limit_record *rec;
1180 	const struct qlink_iface_limit *lim;
1181 	const struct qlink_wowlan_capab_data *wowlan;
1182 	u16 rec_len;
1183 	u16 tlv_type;
1184 	u16 tlv_value_len;
1185 	size_t tlv_full_len;
1186 	const struct qlink_tlv_hdr *tlv;
1187 	u8 *ext_capa = NULL;
1188 	u8 *ext_capa_mask = NULL;
1189 	u8 ext_capa_len = 0;
1190 	u8 ext_capa_mask_len = 0;
1191 	int i = 0;
1192 
1193 	tlv = (const struct qlink_tlv_hdr *)tlv_buf;
1194 	while (tlv_buf_size >= sizeof(struct qlink_tlv_hdr)) {
1195 		tlv_type = le16_to_cpu(tlv->type);
1196 		tlv_value_len = le16_to_cpu(tlv->len);
1197 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1198 		if (tlv_full_len > tlv_buf_size) {
1199 			pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1200 				mac->macid, tlv_type, tlv_value_len);
1201 			return -EINVAL;
1202 		}
1203 
1204 		switch (tlv_type) {
1205 		case QTN_TLV_ID_NUM_IFACE_COMB:
1206 			if (tlv_value_len != sizeof(*comb_num))
1207 				return -EINVAL;
1208 
1209 			comb_num = (void *)tlv->val;
1210 
1211 			/* free earlier iface comb memory */
1212 			qtnf_mac_iface_comb_free(mac);
1213 
1214 			mac->macinfo.n_if_comb =
1215 				le32_to_cpu(comb_num->iface_comb_num);
1216 
1217 			mac->macinfo.if_comb =
1218 				kcalloc(mac->macinfo.n_if_comb,
1219 					sizeof(*mac->macinfo.if_comb),
1220 					GFP_KERNEL);
1221 
1222 			if (!mac->macinfo.if_comb)
1223 				return -ENOMEM;
1224 
1225 			comb = mac->macinfo.if_comb;
1226 
1227 			pr_debug("MAC%u: %zu iface combinations\n",
1228 				 mac->macid, mac->macinfo.n_if_comb);
1229 
1230 			break;
1231 		case QTN_TLV_ID_IFACE_LIMIT:
1232 			if (unlikely(!comb)) {
1233 				pr_warn("MAC%u: no combinations advertised\n",
1234 					mac->macid);
1235 				return -EINVAL;
1236 			}
1237 
1238 			if (n_comb >= mac->macinfo.n_if_comb) {
1239 				pr_warn("MAC%u: combinations count exceeded\n",
1240 					mac->macid);
1241 				n_comb++;
1242 				break;
1243 			}
1244 
1245 			rec = (void *)tlv->val;
1246 			rec_len = sizeof(*rec) + rec->n_limits * sizeof(*lim);
1247 
1248 			if (unlikely(tlv_value_len != rec_len)) {
1249 				pr_warn("MAC%u: record %zu size mismatch\n",
1250 					mac->macid, n_comb);
1251 				return -EINVAL;
1252 			}
1253 
1254 			limits = kcalloc(rec->n_limits, sizeof(*limits),
1255 					 GFP_KERNEL);
1256 			if (!limits)
1257 				return -ENOMEM;
1258 
1259 			comb[n_comb].num_different_channels =
1260 				rec->num_different_channels;
1261 			comb[n_comb].max_interfaces =
1262 				le16_to_cpu(rec->max_interfaces);
1263 			comb[n_comb].n_limits = rec->n_limits;
1264 			comb[n_comb].limits = limits;
1265 
1266 			for (i = 0; i < rec->n_limits; i++) {
1267 				lim = &rec->limits[i];
1268 				limits[i].max = le16_to_cpu(lim->max_num);
1269 				limits[i].types =
1270 					qlink_iface_type_to_nl_mask(le16_to_cpu(lim->type));
1271 				pr_debug("MAC%u: comb[%zu]: MAX:%u TYPES:%.4X\n",
1272 					 mac->macid, n_comb,
1273 					 limits[i].max, limits[i].types);
1274 			}
1275 
1276 			n_comb++;
1277 			break;
1278 		case WLAN_EID_EXT_CAPABILITY:
1279 			if (unlikely(tlv_value_len > U8_MAX))
1280 				return -EINVAL;
1281 			ext_capa = (u8 *)tlv->val;
1282 			ext_capa_len = tlv_value_len;
1283 			break;
1284 		case QTN_TLV_ID_EXT_CAPABILITY_MASK:
1285 			if (unlikely(tlv_value_len > U8_MAX))
1286 				return -EINVAL;
1287 			ext_capa_mask = (u8 *)tlv->val;
1288 			ext_capa_mask_len = tlv_value_len;
1289 			break;
1290 		case QTN_TLV_ID_WOWLAN_CAPAB:
1291 			if (tlv_value_len < sizeof(*wowlan))
1292 				return -EINVAL;
1293 
1294 			wowlan = (void *)tlv->val;
1295 			if (!le16_to_cpu(wowlan->len)) {
1296 				pr_warn("MAC%u: skip empty WoWLAN data\n",
1297 					mac->macid);
1298 				break;
1299 			}
1300 
1301 			rec_len = sizeof(*wowlan) + le16_to_cpu(wowlan->len);
1302 			if (unlikely(tlv_value_len != rec_len)) {
1303 				pr_warn("MAC%u: WoWLAN data size mismatch\n",
1304 					mac->macid);
1305 				return -EINVAL;
1306 			}
1307 
1308 			kfree(mac->macinfo.wowlan);
1309 			mac->macinfo.wowlan = NULL;
1310 			qtnf_parse_wowlan_info(mac, wowlan);
1311 			break;
1312 		default:
1313 			pr_warn("MAC%u: unknown TLV type %u\n",
1314 				mac->macid, tlv_type);
1315 			break;
1316 		}
1317 
1318 		tlv_buf_size -= tlv_full_len;
1319 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1320 	}
1321 
1322 	if (tlv_buf_size) {
1323 		pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1324 			mac->macid, tlv_buf_size);
1325 		return -EINVAL;
1326 	}
1327 
1328 	if (mac->macinfo.n_if_comb != n_comb) {
1329 		pr_err("MAC%u: combination mismatch: reported=%zu parsed=%zu\n",
1330 		       mac->macid, mac->macinfo.n_if_comb, n_comb);
1331 		return -EINVAL;
1332 	}
1333 
1334 	if (ext_capa_len != ext_capa_mask_len) {
1335 		pr_err("MAC%u: ext_capa/_mask lengths mismatch: %u != %u\n",
1336 		       mac->macid, ext_capa_len, ext_capa_mask_len);
1337 		return -EINVAL;
1338 	}
1339 
1340 	if (ext_capa_len > 0) {
1341 		ext_capa = kmemdup(ext_capa, ext_capa_len, GFP_KERNEL);
1342 		if (!ext_capa)
1343 			return -ENOMEM;
1344 
1345 		ext_capa_mask =
1346 			kmemdup(ext_capa_mask, ext_capa_mask_len, GFP_KERNEL);
1347 		if (!ext_capa_mask) {
1348 			kfree(ext_capa);
1349 			return -ENOMEM;
1350 		}
1351 	} else {
1352 		ext_capa = NULL;
1353 		ext_capa_mask = NULL;
1354 	}
1355 
1356 	kfree(mac->macinfo.extended_capabilities);
1357 	kfree(mac->macinfo.extended_capabilities_mask);
1358 	mac->macinfo.extended_capabilities = ext_capa;
1359 	mac->macinfo.extended_capabilities_mask = ext_capa_mask;
1360 	mac->macinfo.extended_capabilities_len = ext_capa_len;
1361 
1362 	return 0;
1363 }
1364 
1365 static void
1366 qtnf_cmd_resp_proc_mac_info(struct qtnf_wmac *mac,
1367 			    const struct qlink_resp_get_mac_info *resp_info)
1368 {
1369 	struct qtnf_mac_info *mac_info;
1370 	struct qtnf_vif *vif;
1371 
1372 	mac_info = &mac->macinfo;
1373 
1374 	mac_info->bands_cap = resp_info->bands_cap;
1375 	memcpy(&mac_info->dev_mac, &resp_info->dev_mac,
1376 	       sizeof(mac_info->dev_mac));
1377 
1378 	ether_addr_copy(mac->macaddr, mac_info->dev_mac);
1379 
1380 	vif = qtnf_mac_get_base_vif(mac);
1381 	if (vif)
1382 		ether_addr_copy(vif->mac_addr, mac->macaddr);
1383 	else
1384 		pr_err("could not get valid base vif\n");
1385 
1386 	mac_info->num_tx_chain = resp_info->num_tx_chain;
1387 	mac_info->num_rx_chain = resp_info->num_rx_chain;
1388 
1389 	mac_info->max_ap_assoc_sta = le16_to_cpu(resp_info->max_ap_assoc_sta);
1390 	mac_info->radar_detect_widths =
1391 			qlink_chan_width_mask_to_nl(le16_to_cpu(
1392 					resp_info->radar_detect_widths));
1393 	mac_info->max_acl_mac_addrs = le32_to_cpu(resp_info->max_acl_mac_addrs);
1394 
1395 	memcpy(&mac_info->ht_cap_mod_mask, &resp_info->ht_cap_mod_mask,
1396 	       sizeof(mac_info->ht_cap_mod_mask));
1397 	memcpy(&mac_info->vht_cap_mod_mask, &resp_info->vht_cap_mod_mask,
1398 	       sizeof(mac_info->vht_cap_mod_mask));
1399 }
1400 
1401 static void qtnf_cmd_resp_band_fill_htcap(const u8 *info,
1402 					  struct ieee80211_sta_ht_cap *bcap)
1403 {
1404 	const struct ieee80211_ht_cap *ht_cap =
1405 		(const struct ieee80211_ht_cap *)info;
1406 
1407 	bcap->ht_supported = true;
1408 	bcap->cap = le16_to_cpu(ht_cap->cap_info);
1409 	bcap->ampdu_factor =
1410 		ht_cap->ampdu_params_info & IEEE80211_HT_AMPDU_PARM_FACTOR;
1411 	bcap->ampdu_density =
1412 		(ht_cap->ampdu_params_info & IEEE80211_HT_AMPDU_PARM_DENSITY) >>
1413 		IEEE80211_HT_AMPDU_PARM_DENSITY_SHIFT;
1414 	memcpy(&bcap->mcs, &ht_cap->mcs, sizeof(bcap->mcs));
1415 }
1416 
1417 static void qtnf_cmd_resp_band_fill_vhtcap(const u8 *info,
1418 					   struct ieee80211_sta_vht_cap *bcap)
1419 {
1420 	const struct ieee80211_vht_cap *vht_cap =
1421 		(const struct ieee80211_vht_cap *)info;
1422 
1423 	bcap->vht_supported = true;
1424 	bcap->cap = le32_to_cpu(vht_cap->vht_cap_info);
1425 	memcpy(&bcap->vht_mcs, &vht_cap->supp_mcs, sizeof(bcap->vht_mcs));
1426 }
1427 
1428 static int
1429 qtnf_cmd_resp_fill_band_info(struct ieee80211_supported_band *band,
1430 			     struct qlink_resp_band_info_get *resp,
1431 			     size_t payload_len)
1432 {
1433 	u16 tlv_type;
1434 	size_t tlv_len;
1435 	size_t tlv_dlen;
1436 	const struct qlink_tlv_hdr *tlv;
1437 	const struct qlink_channel *qchan;
1438 	struct ieee80211_channel *chan;
1439 	unsigned int chidx = 0;
1440 	u32 qflags;
1441 
1442 	memset(&band->ht_cap, 0, sizeof(band->ht_cap));
1443 	memset(&band->vht_cap, 0, sizeof(band->vht_cap));
1444 
1445 	if (band->channels) {
1446 		if (band->n_channels == resp->num_chans) {
1447 			memset(band->channels, 0,
1448 			       sizeof(*band->channels) * band->n_channels);
1449 		} else {
1450 			kfree(band->channels);
1451 			band->n_channels = 0;
1452 			band->channels = NULL;
1453 		}
1454 	}
1455 
1456 	band->n_channels = resp->num_chans;
1457 	if (band->n_channels == 0)
1458 		return 0;
1459 
1460 	if (!band->channels)
1461 		band->channels = kcalloc(band->n_channels, sizeof(*chan),
1462 					 GFP_KERNEL);
1463 	if (!band->channels) {
1464 		band->n_channels = 0;
1465 		return -ENOMEM;
1466 	}
1467 
1468 	tlv = (struct qlink_tlv_hdr *)resp->info;
1469 
1470 	while (payload_len >= sizeof(*tlv)) {
1471 		tlv_type = le16_to_cpu(tlv->type);
1472 		tlv_dlen = le16_to_cpu(tlv->len);
1473 		tlv_len = tlv_dlen + sizeof(*tlv);
1474 
1475 		if (tlv_len > payload_len) {
1476 			pr_warn("malformed TLV 0x%.2X; LEN: %zu\n",
1477 				tlv_type, tlv_len);
1478 			goto error_ret;
1479 		}
1480 
1481 		switch (tlv_type) {
1482 		case QTN_TLV_ID_CHANNEL:
1483 			if (unlikely(tlv_dlen != sizeof(*qchan))) {
1484 				pr_err("invalid channel TLV len %zu\n",
1485 				       tlv_len);
1486 				goto error_ret;
1487 			}
1488 
1489 			if (chidx == band->n_channels) {
1490 				pr_err("too many channel TLVs\n");
1491 				goto error_ret;
1492 			}
1493 
1494 			qchan = (const struct qlink_channel *)tlv->val;
1495 			chan = &band->channels[chidx++];
1496 			qflags = le32_to_cpu(qchan->flags);
1497 
1498 			chan->hw_value = le16_to_cpu(qchan->hw_value);
1499 			chan->band = band->band;
1500 			chan->center_freq = le16_to_cpu(qchan->center_freq);
1501 			chan->max_antenna_gain = (int)qchan->max_antenna_gain;
1502 			chan->max_power = (int)qchan->max_power;
1503 			chan->max_reg_power = (int)qchan->max_reg_power;
1504 			chan->beacon_found = qchan->beacon_found;
1505 			chan->dfs_cac_ms = le32_to_cpu(qchan->dfs_cac_ms);
1506 			chan->flags = 0;
1507 
1508 			if (qflags & QLINK_CHAN_DISABLED)
1509 				chan->flags |= IEEE80211_CHAN_DISABLED;
1510 
1511 			if (qflags & QLINK_CHAN_NO_IR)
1512 				chan->flags |= IEEE80211_CHAN_NO_IR;
1513 
1514 			if (qflags & QLINK_CHAN_NO_HT40PLUS)
1515 				chan->flags |= IEEE80211_CHAN_NO_HT40PLUS;
1516 
1517 			if (qflags & QLINK_CHAN_NO_HT40MINUS)
1518 				chan->flags |= IEEE80211_CHAN_NO_HT40MINUS;
1519 
1520 			if (qflags & QLINK_CHAN_NO_OFDM)
1521 				chan->flags |= IEEE80211_CHAN_NO_OFDM;
1522 
1523 			if (qflags & QLINK_CHAN_NO_80MHZ)
1524 				chan->flags |= IEEE80211_CHAN_NO_80MHZ;
1525 
1526 			if (qflags & QLINK_CHAN_NO_160MHZ)
1527 				chan->flags |= IEEE80211_CHAN_NO_160MHZ;
1528 
1529 			if (qflags & QLINK_CHAN_INDOOR_ONLY)
1530 				chan->flags |= IEEE80211_CHAN_INDOOR_ONLY;
1531 
1532 			if (qflags & QLINK_CHAN_IR_CONCURRENT)
1533 				chan->flags |= IEEE80211_CHAN_IR_CONCURRENT;
1534 
1535 			if (qflags & QLINK_CHAN_NO_20MHZ)
1536 				chan->flags |= IEEE80211_CHAN_NO_20MHZ;
1537 
1538 			if (qflags & QLINK_CHAN_NO_10MHZ)
1539 				chan->flags |= IEEE80211_CHAN_NO_10MHZ;
1540 
1541 			if (qflags & QLINK_CHAN_RADAR) {
1542 				chan->flags |= IEEE80211_CHAN_RADAR;
1543 				chan->dfs_state_entered = jiffies;
1544 
1545 				if (qchan->dfs_state == QLINK_DFS_USABLE)
1546 					chan->dfs_state = NL80211_DFS_USABLE;
1547 				else if (qchan->dfs_state ==
1548 					QLINK_DFS_AVAILABLE)
1549 					chan->dfs_state = NL80211_DFS_AVAILABLE;
1550 				else
1551 					chan->dfs_state =
1552 						NL80211_DFS_UNAVAILABLE;
1553 			}
1554 
1555 			pr_debug("chan=%d flags=%#x max_pow=%d max_reg_pow=%d\n",
1556 				 chan->hw_value, chan->flags, chan->max_power,
1557 				 chan->max_reg_power);
1558 			break;
1559 		case WLAN_EID_HT_CAPABILITY:
1560 			if (unlikely(tlv_dlen !=
1561 				     sizeof(struct ieee80211_ht_cap))) {
1562 				pr_err("bad HTCAP TLV len %zu\n", tlv_dlen);
1563 				goto error_ret;
1564 			}
1565 
1566 			qtnf_cmd_resp_band_fill_htcap(tlv->val, &band->ht_cap);
1567 			break;
1568 		case WLAN_EID_VHT_CAPABILITY:
1569 			if (unlikely(tlv_dlen !=
1570 				     sizeof(struct ieee80211_vht_cap))) {
1571 				pr_err("bad VHTCAP TLV len %zu\n", tlv_dlen);
1572 				goto error_ret;
1573 			}
1574 
1575 			qtnf_cmd_resp_band_fill_vhtcap(tlv->val,
1576 						       &band->vht_cap);
1577 			break;
1578 		default:
1579 			pr_warn("unknown TLV type: %#x\n", tlv_type);
1580 			break;
1581 		}
1582 
1583 		payload_len -= tlv_len;
1584 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_dlen);
1585 	}
1586 
1587 	if (payload_len) {
1588 		pr_err("malformed TLV buf; bytes left: %zu\n", payload_len);
1589 		goto error_ret;
1590 	}
1591 
1592 	if (band->n_channels != chidx) {
1593 		pr_err("channel count mismatch: reported=%d, parsed=%d\n",
1594 		       band->n_channels, chidx);
1595 		goto error_ret;
1596 	}
1597 
1598 	return 0;
1599 
1600 error_ret:
1601 	kfree(band->channels);
1602 	band->channels = NULL;
1603 	band->n_channels = 0;
1604 
1605 	return -EINVAL;
1606 }
1607 
1608 static int qtnf_cmd_resp_proc_phy_params(struct qtnf_wmac *mac,
1609 					 const u8 *payload, size_t payload_len)
1610 {
1611 	struct qtnf_mac_info *mac_info;
1612 	struct qlink_tlv_frag_rts_thr *phy_thr;
1613 	struct qlink_tlv_rlimit *limit;
1614 	struct qlink_tlv_cclass *class;
1615 	u16 tlv_type;
1616 	u16 tlv_value_len;
1617 	size_t tlv_full_len;
1618 	const struct qlink_tlv_hdr *tlv;
1619 
1620 	mac_info = &mac->macinfo;
1621 
1622 	tlv = (struct qlink_tlv_hdr *)payload;
1623 	while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1624 		tlv_type = le16_to_cpu(tlv->type);
1625 		tlv_value_len = le16_to_cpu(tlv->len);
1626 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1627 
1628 		if (tlv_full_len > payload_len) {
1629 			pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1630 				mac->macid, tlv_type, tlv_value_len);
1631 			return -EINVAL;
1632 		}
1633 
1634 		switch (tlv_type) {
1635 		case QTN_TLV_ID_FRAG_THRESH:
1636 			phy_thr = (void *)tlv;
1637 			mac_info->frag_thr = (u32)le16_to_cpu(phy_thr->thr);
1638 			break;
1639 		case QTN_TLV_ID_RTS_THRESH:
1640 			phy_thr = (void *)tlv;
1641 			mac_info->rts_thr = (u32)le16_to_cpu(phy_thr->thr);
1642 			break;
1643 		case QTN_TLV_ID_SRETRY_LIMIT:
1644 			limit = (void *)tlv;
1645 			mac_info->sretry_limit = limit->rlimit;
1646 			break;
1647 		case QTN_TLV_ID_LRETRY_LIMIT:
1648 			limit = (void *)tlv;
1649 			mac_info->lretry_limit = limit->rlimit;
1650 			break;
1651 		case QTN_TLV_ID_COVERAGE_CLASS:
1652 			class = (void *)tlv;
1653 			mac_info->coverage_class = class->cclass;
1654 			break;
1655 		default:
1656 			pr_err("MAC%u: Unknown TLV type: %#x\n", mac->macid,
1657 			       le16_to_cpu(tlv->type));
1658 			break;
1659 		}
1660 
1661 		payload_len -= tlv_full_len;
1662 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1663 	}
1664 
1665 	if (payload_len) {
1666 		pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1667 			mac->macid, payload_len);
1668 		return -EINVAL;
1669 	}
1670 
1671 	return 0;
1672 }
1673 
1674 static int
1675 qtnf_cmd_resp_proc_chan_stat_info(struct qtnf_chan_stats *stats,
1676 				  const u8 *payload, size_t payload_len)
1677 {
1678 	struct qlink_chan_stats *qlink_stats;
1679 	const struct qlink_tlv_hdr *tlv;
1680 	size_t tlv_full_len;
1681 	u16 tlv_value_len;
1682 	u16 tlv_type;
1683 
1684 	tlv = (struct qlink_tlv_hdr *)payload;
1685 	while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1686 		tlv_type = le16_to_cpu(tlv->type);
1687 		tlv_value_len = le16_to_cpu(tlv->len);
1688 		tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1689 		if (tlv_full_len > payload_len) {
1690 			pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
1691 				tlv_type, tlv_value_len);
1692 			return -EINVAL;
1693 		}
1694 		switch (tlv_type) {
1695 		case QTN_TLV_ID_CHANNEL_STATS:
1696 			if (unlikely(tlv_value_len != sizeof(*qlink_stats))) {
1697 				pr_err("invalid CHANNEL_STATS entry size\n");
1698 				return -EINVAL;
1699 			}
1700 
1701 			qlink_stats = (void *)tlv->val;
1702 
1703 			stats->chan_num = le32_to_cpu(qlink_stats->chan_num);
1704 			stats->cca_tx = le32_to_cpu(qlink_stats->cca_tx);
1705 			stats->cca_rx = le32_to_cpu(qlink_stats->cca_rx);
1706 			stats->cca_busy = le32_to_cpu(qlink_stats->cca_busy);
1707 			stats->cca_try = le32_to_cpu(qlink_stats->cca_try);
1708 			stats->chan_noise = qlink_stats->chan_noise;
1709 
1710 			pr_debug("chan(%u) try(%u) busy(%u) noise(%d)\n",
1711 				 stats->chan_num, stats->cca_try,
1712 				 stats->cca_busy, stats->chan_noise);
1713 			break;
1714 		default:
1715 			pr_warn("Unknown TLV type: %#x\n",
1716 				le16_to_cpu(tlv->type));
1717 		}
1718 		payload_len -= tlv_full_len;
1719 		tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1720 	}
1721 
1722 	if (payload_len) {
1723 		pr_warn("malformed TLV buf; bytes left: %zu\n", payload_len);
1724 		return -EINVAL;
1725 	}
1726 
1727 	return 0;
1728 }
1729 
1730 int qtnf_cmd_get_mac_info(struct qtnf_wmac *mac)
1731 {
1732 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1733 	const struct qlink_resp_get_mac_info *resp;
1734 	size_t var_data_len;
1735 	u16 res_code = QLINK_CMD_RESULT_OK;
1736 	int ret = 0;
1737 
1738 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
1739 					    QLINK_CMD_MAC_INFO,
1740 					    sizeof(struct qlink_cmd));
1741 	if (!cmd_skb)
1742 		return -ENOMEM;
1743 
1744 	qtnf_bus_lock(mac->bus);
1745 
1746 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb, &res_code,
1747 				       sizeof(*resp), &var_data_len);
1748 	if (unlikely(ret))
1749 		goto out;
1750 
1751 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1752 		pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
1753 		ret = -EFAULT;
1754 		goto out;
1755 	}
1756 
1757 	resp = (const struct qlink_resp_get_mac_info *)resp_skb->data;
1758 	qtnf_cmd_resp_proc_mac_info(mac, resp);
1759 	ret = qtnf_parse_variable_mac_info(mac, resp->var_info, var_data_len);
1760 
1761 out:
1762 	qtnf_bus_unlock(mac->bus);
1763 	consume_skb(resp_skb);
1764 
1765 	return ret;
1766 }
1767 
1768 int qtnf_cmd_get_hw_info(struct qtnf_bus *bus)
1769 {
1770 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1771 	const struct qlink_resp_get_hw_info *resp;
1772 	u16 res_code = QLINK_CMD_RESULT_OK;
1773 	int ret = 0;
1774 	size_t info_len;
1775 
1776 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1777 					    QLINK_CMD_GET_HW_INFO,
1778 					    sizeof(struct qlink_cmd));
1779 	if (!cmd_skb)
1780 		return -ENOMEM;
1781 
1782 	qtnf_bus_lock(bus);
1783 
1784 	ret = qtnf_cmd_send_with_reply(bus, cmd_skb, &resp_skb, &res_code,
1785 				       sizeof(*resp), &info_len);
1786 
1787 	if (unlikely(ret))
1788 		goto out;
1789 
1790 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1791 		pr_err("cmd exec failed: 0x%.4X\n", res_code);
1792 		ret = -EFAULT;
1793 		goto out;
1794 	}
1795 
1796 	resp = (const struct qlink_resp_get_hw_info *)resp_skb->data;
1797 	ret = qtnf_cmd_resp_proc_hw_info(bus, resp, info_len);
1798 
1799 out:
1800 	qtnf_bus_unlock(bus);
1801 	consume_skb(resp_skb);
1802 
1803 	return ret;
1804 }
1805 
1806 int qtnf_cmd_band_info_get(struct qtnf_wmac *mac,
1807 			   struct ieee80211_supported_band *band)
1808 {
1809 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1810 	size_t info_len;
1811 	struct qlink_cmd_band_info_get *cmd;
1812 	struct qlink_resp_band_info_get *resp;
1813 	u16 res_code = QLINK_CMD_RESULT_OK;
1814 	int ret = 0;
1815 	u8 qband;
1816 
1817 	switch (band->band) {
1818 	case NL80211_BAND_2GHZ:
1819 		qband = QLINK_BAND_2GHZ;
1820 		break;
1821 	case NL80211_BAND_5GHZ:
1822 		qband = QLINK_BAND_5GHZ;
1823 		break;
1824 	case NL80211_BAND_60GHZ:
1825 		qband = QLINK_BAND_60GHZ;
1826 		break;
1827 	default:
1828 		return -EINVAL;
1829 	}
1830 
1831 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1832 					    QLINK_CMD_BAND_INFO_GET,
1833 					    sizeof(*cmd));
1834 	if (!cmd_skb)
1835 		return -ENOMEM;
1836 
1837 	cmd = (struct qlink_cmd_band_info_get *)cmd_skb->data;
1838 	cmd->band = qband;
1839 
1840 	qtnf_bus_lock(mac->bus);
1841 
1842 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb, &res_code,
1843 				       sizeof(*resp), &info_len);
1844 
1845 	if (unlikely(ret))
1846 		goto out;
1847 
1848 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1849 		pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
1850 		ret = -EFAULT;
1851 		goto out;
1852 	}
1853 
1854 	resp = (struct qlink_resp_band_info_get *)resp_skb->data;
1855 	if (resp->band != qband) {
1856 		pr_err("MAC%u: reply band %u != cmd band %u\n", mac->macid,
1857 		       resp->band, qband);
1858 		ret = -EINVAL;
1859 		goto out;
1860 	}
1861 
1862 	ret = qtnf_cmd_resp_fill_band_info(band, resp, info_len);
1863 
1864 out:
1865 	qtnf_bus_unlock(mac->bus);
1866 	consume_skb(resp_skb);
1867 
1868 	return ret;
1869 }
1870 
1871 int qtnf_cmd_send_get_phy_params(struct qtnf_wmac *mac)
1872 {
1873 	struct sk_buff *cmd_skb, *resp_skb = NULL;
1874 	size_t response_size;
1875 	struct qlink_resp_phy_params *resp;
1876 	u16 res_code = QLINK_CMD_RESULT_OK;
1877 	int ret = 0;
1878 
1879 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1880 					    QLINK_CMD_PHY_PARAMS_GET,
1881 					    sizeof(struct qlink_cmd));
1882 	if (!cmd_skb)
1883 		return -ENOMEM;
1884 
1885 	qtnf_bus_lock(mac->bus);
1886 
1887 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb, &res_code,
1888 				       sizeof(*resp), &response_size);
1889 
1890 	if (unlikely(ret))
1891 		goto out;
1892 
1893 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1894 		pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
1895 		ret = -EFAULT;
1896 		goto out;
1897 	}
1898 
1899 	resp = (struct qlink_resp_phy_params *)resp_skb->data;
1900 	ret = qtnf_cmd_resp_proc_phy_params(mac, resp->info, response_size);
1901 
1902 out:
1903 	qtnf_bus_unlock(mac->bus);
1904 	consume_skb(resp_skb);
1905 
1906 	return ret;
1907 }
1908 
1909 int qtnf_cmd_send_update_phy_params(struct qtnf_wmac *mac, u32 changed)
1910 {
1911 	struct wiphy *wiphy = priv_to_wiphy(mac);
1912 	struct sk_buff *cmd_skb;
1913 	u16 res_code = QLINK_CMD_RESULT_OK;
1914 	int ret = 0;
1915 
1916 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1917 					    QLINK_CMD_PHY_PARAMS_SET,
1918 					    sizeof(struct qlink_cmd));
1919 	if (!cmd_skb)
1920 		return -ENOMEM;
1921 
1922 	qtnf_bus_lock(mac->bus);
1923 
1924 	if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1925 		qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_FRAG_THRESH,
1926 					 wiphy->frag_threshold);
1927 	if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1928 		qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_RTS_THRESH,
1929 					 wiphy->rts_threshold);
1930 	if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1931 		qtnf_cmd_skb_put_tlv_u8(cmd_skb, QTN_TLV_ID_COVERAGE_CLASS,
1932 					wiphy->coverage_class);
1933 
1934 	ret = qtnf_cmd_send(mac->bus, cmd_skb, &res_code);
1935 
1936 	if (unlikely(ret))
1937 		goto out;
1938 
1939 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1940 		pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
1941 		ret = -EFAULT;
1942 		goto out;
1943 	}
1944 
1945 out:
1946 	qtnf_bus_unlock(mac->bus);
1947 	return ret;
1948 }
1949 
1950 int qtnf_cmd_send_init_fw(struct qtnf_bus *bus)
1951 {
1952 	struct sk_buff *cmd_skb;
1953 	u16 res_code = QLINK_CMD_RESULT_OK;
1954 	int ret = 0;
1955 
1956 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1957 					    QLINK_CMD_FW_INIT,
1958 					    sizeof(struct qlink_cmd));
1959 	if (!cmd_skb)
1960 		return -ENOMEM;
1961 
1962 	qtnf_bus_lock(bus);
1963 
1964 	ret = qtnf_cmd_send(bus, cmd_skb, &res_code);
1965 
1966 	if (unlikely(ret))
1967 		goto out;
1968 
1969 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1970 		pr_err("cmd exec failed: 0x%.4X\n", res_code);
1971 		ret = -EFAULT;
1972 		goto out;
1973 	}
1974 
1975 out:
1976 	qtnf_bus_unlock(bus);
1977 	return ret;
1978 }
1979 
1980 void qtnf_cmd_send_deinit_fw(struct qtnf_bus *bus)
1981 {
1982 	struct sk_buff *cmd_skb;
1983 
1984 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1985 					    QLINK_CMD_FW_DEINIT,
1986 					    sizeof(struct qlink_cmd));
1987 	if (!cmd_skb)
1988 		return;
1989 
1990 	qtnf_bus_lock(bus);
1991 
1992 	qtnf_cmd_send(bus, cmd_skb, NULL);
1993 
1994 	qtnf_bus_unlock(bus);
1995 }
1996 
1997 int qtnf_cmd_send_add_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
1998 			  const u8 *mac_addr, struct key_params *params)
1999 {
2000 	struct sk_buff *cmd_skb;
2001 	struct qlink_cmd_add_key *cmd;
2002 	u16 res_code = QLINK_CMD_RESULT_OK;
2003 	int ret = 0;
2004 
2005 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2006 					    QLINK_CMD_ADD_KEY,
2007 					    sizeof(*cmd));
2008 	if (!cmd_skb)
2009 		return -ENOMEM;
2010 
2011 	qtnf_bus_lock(vif->mac->bus);
2012 
2013 	cmd = (struct qlink_cmd_add_key *)cmd_skb->data;
2014 
2015 	if (mac_addr)
2016 		ether_addr_copy(cmd->addr, mac_addr);
2017 	else
2018 		eth_broadcast_addr(cmd->addr);
2019 
2020 	cmd->cipher = cpu_to_le32(params->cipher);
2021 	cmd->key_index = key_index;
2022 	cmd->pairwise = pairwise;
2023 
2024 	if (params->key && params->key_len > 0)
2025 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_KEY,
2026 					 params->key,
2027 					 params->key_len);
2028 
2029 	if (params->seq && params->seq_len > 0)
2030 		qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_SEQ,
2031 					 params->seq,
2032 					 params->seq_len);
2033 
2034 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2035 	if (unlikely(ret))
2036 		goto out;
2037 
2038 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2039 		pr_err("VIF%u.%u: CMD failed: %u\n",
2040 		       vif->mac->macid, vif->vifid, res_code);
2041 		ret = -EFAULT;
2042 		goto out;
2043 	}
2044 
2045 out:
2046 	qtnf_bus_unlock(vif->mac->bus);
2047 	return ret;
2048 }
2049 
2050 int qtnf_cmd_send_del_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
2051 			  const u8 *mac_addr)
2052 {
2053 	struct sk_buff *cmd_skb;
2054 	struct qlink_cmd_del_key *cmd;
2055 	u16 res_code = QLINK_CMD_RESULT_OK;
2056 	int ret = 0;
2057 
2058 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2059 					    QLINK_CMD_DEL_KEY,
2060 					    sizeof(*cmd));
2061 	if (!cmd_skb)
2062 		return -ENOMEM;
2063 
2064 	qtnf_bus_lock(vif->mac->bus);
2065 
2066 	cmd = (struct qlink_cmd_del_key *)cmd_skb->data;
2067 
2068 	if (mac_addr)
2069 		ether_addr_copy(cmd->addr, mac_addr);
2070 	else
2071 		eth_broadcast_addr(cmd->addr);
2072 
2073 	cmd->key_index = key_index;
2074 	cmd->pairwise = pairwise;
2075 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2076 	if (unlikely(ret))
2077 		goto out;
2078 
2079 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2080 		pr_err("VIF%u.%u: CMD failed: %u\n",
2081 		       vif->mac->macid, vif->vifid, res_code);
2082 		ret = -EFAULT;
2083 		goto out;
2084 	}
2085 
2086 out:
2087 	qtnf_bus_unlock(vif->mac->bus);
2088 	return ret;
2089 }
2090 
2091 int qtnf_cmd_send_set_default_key(struct qtnf_vif *vif, u8 key_index,
2092 				  bool unicast, bool multicast)
2093 {
2094 	struct sk_buff *cmd_skb;
2095 	struct qlink_cmd_set_def_key *cmd;
2096 	u16 res_code = QLINK_CMD_RESULT_OK;
2097 	int ret = 0;
2098 
2099 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2100 					    QLINK_CMD_SET_DEFAULT_KEY,
2101 					    sizeof(*cmd));
2102 	if (!cmd_skb)
2103 		return -ENOMEM;
2104 
2105 	qtnf_bus_lock(vif->mac->bus);
2106 
2107 	cmd = (struct qlink_cmd_set_def_key *)cmd_skb->data;
2108 	cmd->key_index = key_index;
2109 	cmd->unicast = unicast;
2110 	cmd->multicast = multicast;
2111 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2112 	if (unlikely(ret))
2113 		goto out;
2114 
2115 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2116 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2117 		       vif->vifid, res_code);
2118 		ret = -EFAULT;
2119 		goto out;
2120 	}
2121 
2122 out:
2123 	qtnf_bus_unlock(vif->mac->bus);
2124 	return ret;
2125 }
2126 
2127 int qtnf_cmd_send_set_default_mgmt_key(struct qtnf_vif *vif, u8 key_index)
2128 {
2129 	struct sk_buff *cmd_skb;
2130 	struct qlink_cmd_set_def_mgmt_key *cmd;
2131 	u16 res_code = QLINK_CMD_RESULT_OK;
2132 	int ret = 0;
2133 
2134 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2135 					    QLINK_CMD_SET_DEFAULT_MGMT_KEY,
2136 					    sizeof(*cmd));
2137 	if (!cmd_skb)
2138 		return -ENOMEM;
2139 
2140 	qtnf_bus_lock(vif->mac->bus);
2141 
2142 	cmd = (struct qlink_cmd_set_def_mgmt_key *)cmd_skb->data;
2143 	cmd->key_index = key_index;
2144 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2145 	if (unlikely(ret))
2146 		goto out;
2147 
2148 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2149 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2150 		       vif->vifid, res_code);
2151 		ret = -EFAULT;
2152 		goto out;
2153 	}
2154 
2155 out:
2156 	qtnf_bus_unlock(vif->mac->bus);
2157 	return ret;
2158 }
2159 
2160 static u32 qtnf_encode_sta_flags(u32 flags)
2161 {
2162 	u32 code = 0;
2163 
2164 	if (flags & BIT(NL80211_STA_FLAG_AUTHORIZED))
2165 		code |= QLINK_STA_FLAG_AUTHORIZED;
2166 	if (flags & BIT(NL80211_STA_FLAG_SHORT_PREAMBLE))
2167 		code |= QLINK_STA_FLAG_SHORT_PREAMBLE;
2168 	if (flags & BIT(NL80211_STA_FLAG_WME))
2169 		code |= QLINK_STA_FLAG_WME;
2170 	if (flags & BIT(NL80211_STA_FLAG_MFP))
2171 		code |= QLINK_STA_FLAG_MFP;
2172 	if (flags & BIT(NL80211_STA_FLAG_AUTHENTICATED))
2173 		code |= QLINK_STA_FLAG_AUTHENTICATED;
2174 	if (flags & BIT(NL80211_STA_FLAG_TDLS_PEER))
2175 		code |= QLINK_STA_FLAG_TDLS_PEER;
2176 	if (flags & BIT(NL80211_STA_FLAG_ASSOCIATED))
2177 		code |= QLINK_STA_FLAG_ASSOCIATED;
2178 	return code;
2179 }
2180 
2181 int qtnf_cmd_send_change_sta(struct qtnf_vif *vif, const u8 *mac,
2182 			     struct station_parameters *params)
2183 {
2184 	struct sk_buff *cmd_skb;
2185 	struct qlink_cmd_change_sta *cmd;
2186 	u16 res_code = QLINK_CMD_RESULT_OK;
2187 	int ret = 0;
2188 
2189 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2190 					    QLINK_CMD_CHANGE_STA,
2191 					    sizeof(*cmd));
2192 	if (!cmd_skb)
2193 		return -ENOMEM;
2194 
2195 	qtnf_bus_lock(vif->mac->bus);
2196 
2197 	cmd = (struct qlink_cmd_change_sta *)cmd_skb->data;
2198 	ether_addr_copy(cmd->sta_addr, mac);
2199 	cmd->flag_update.mask =
2200 		cpu_to_le32(qtnf_encode_sta_flags(params->sta_flags_mask));
2201 	cmd->flag_update.value =
2202 		cpu_to_le32(qtnf_encode_sta_flags(params->sta_flags_set));
2203 
2204 	switch (vif->wdev.iftype) {
2205 	case NL80211_IFTYPE_AP:
2206 		cmd->if_type = cpu_to_le16(QLINK_IFTYPE_AP);
2207 		break;
2208 	case NL80211_IFTYPE_STATION:
2209 		cmd->if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
2210 		break;
2211 	default:
2212 		pr_err("unsupported iftype %d\n", vif->wdev.iftype);
2213 		ret = -EINVAL;
2214 		goto out;
2215 	}
2216 
2217 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2218 	if (unlikely(ret))
2219 		goto out;
2220 
2221 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2222 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2223 		       vif->vifid, res_code);
2224 		ret = -EFAULT;
2225 		goto out;
2226 	}
2227 
2228 out:
2229 	qtnf_bus_unlock(vif->mac->bus);
2230 	return ret;
2231 }
2232 
2233 int qtnf_cmd_send_del_sta(struct qtnf_vif *vif,
2234 			  struct station_del_parameters *params)
2235 {
2236 	struct sk_buff *cmd_skb;
2237 	struct qlink_cmd_del_sta *cmd;
2238 	u16 res_code = QLINK_CMD_RESULT_OK;
2239 	int ret = 0;
2240 
2241 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2242 					    QLINK_CMD_DEL_STA,
2243 					    sizeof(*cmd));
2244 	if (!cmd_skb)
2245 		return -ENOMEM;
2246 
2247 	qtnf_bus_lock(vif->mac->bus);
2248 
2249 	cmd = (struct qlink_cmd_del_sta *)cmd_skb->data;
2250 
2251 	if (params->mac)
2252 		ether_addr_copy(cmd->sta_addr, params->mac);
2253 	else
2254 		eth_broadcast_addr(cmd->sta_addr);	/* flush all stations */
2255 
2256 	cmd->subtype = params->subtype;
2257 	cmd->reason_code = cpu_to_le16(params->reason_code);
2258 
2259 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2260 	if (unlikely(ret))
2261 		goto out;
2262 
2263 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2264 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2265 		       vif->vifid, res_code);
2266 		ret = -EFAULT;
2267 		goto out;
2268 	}
2269 
2270 out:
2271 	qtnf_bus_unlock(vif->mac->bus);
2272 	return ret;
2273 }
2274 
2275 static void qtnf_cmd_channel_tlv_add(struct sk_buff *cmd_skb,
2276 				     const struct ieee80211_channel *sc)
2277 {
2278 	struct qlink_tlv_channel *qchan;
2279 	u32 flags = 0;
2280 
2281 	qchan = skb_put_zero(cmd_skb, sizeof(*qchan));
2282 	qchan->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANNEL);
2283 	qchan->hdr.len = cpu_to_le16(sizeof(*qchan) - sizeof(qchan->hdr));
2284 	qchan->chan.center_freq = cpu_to_le16(sc->center_freq);
2285 	qchan->chan.hw_value = cpu_to_le16(sc->hw_value);
2286 
2287 	if (sc->flags & IEEE80211_CHAN_NO_IR)
2288 		flags |= QLINK_CHAN_NO_IR;
2289 
2290 	if (sc->flags & IEEE80211_CHAN_RADAR)
2291 		flags |= QLINK_CHAN_RADAR;
2292 
2293 	qchan->chan.flags = cpu_to_le32(flags);
2294 }
2295 
2296 static void qtnf_cmd_randmac_tlv_add(struct sk_buff *cmd_skb,
2297 				     const u8 *mac_addr,
2298 				     const u8 *mac_addr_mask)
2299 {
2300 	struct qlink_random_mac_addr *randmac;
2301 	struct qlink_tlv_hdr *hdr =
2302 		skb_put(cmd_skb, sizeof(*hdr) + sizeof(*randmac));
2303 
2304 	hdr->type = cpu_to_le16(QTN_TLV_ID_RANDOM_MAC_ADDR);
2305 	hdr->len = cpu_to_le16(sizeof(*randmac));
2306 	randmac = (struct qlink_random_mac_addr *)hdr->val;
2307 
2308 	memcpy(randmac->mac_addr, mac_addr, ETH_ALEN);
2309 	memcpy(randmac->mac_addr_mask, mac_addr_mask, ETH_ALEN);
2310 }
2311 
2312 int qtnf_cmd_send_scan(struct qtnf_wmac *mac)
2313 {
2314 	struct sk_buff *cmd_skb;
2315 	u16 res_code = QLINK_CMD_RESULT_OK;
2316 	struct ieee80211_channel *sc;
2317 	struct cfg80211_scan_request *scan_req = mac->scan_req;
2318 	int n_channels;
2319 	int count = 0;
2320 	int ret;
2321 
2322 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
2323 					    QLINK_CMD_SCAN,
2324 					    sizeof(struct qlink_cmd));
2325 	if (!cmd_skb)
2326 		return -ENOMEM;
2327 
2328 	qtnf_bus_lock(mac->bus);
2329 
2330 	if (scan_req->n_ssids != 0) {
2331 		while (count < scan_req->n_ssids) {
2332 			qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID,
2333 				scan_req->ssids[count].ssid,
2334 				scan_req->ssids[count].ssid_len);
2335 			count++;
2336 		}
2337 	}
2338 
2339 	if (scan_req->ie_len != 0)
2340 		qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_PROBE_REQ,
2341 					scan_req->ie, scan_req->ie_len);
2342 
2343 	if (scan_req->n_channels) {
2344 		n_channels = scan_req->n_channels;
2345 		count = 0;
2346 
2347 		while (n_channels != 0) {
2348 			sc = scan_req->channels[count];
2349 			if (sc->flags & IEEE80211_CHAN_DISABLED) {
2350 				n_channels--;
2351 				continue;
2352 			}
2353 
2354 			pr_debug("MAC%u: scan chan=%d, freq=%d, flags=%#x\n",
2355 				 mac->macid, sc->hw_value, sc->center_freq,
2356 				 sc->flags);
2357 
2358 			qtnf_cmd_channel_tlv_add(cmd_skb, sc);
2359 			n_channels--;
2360 			count++;
2361 		}
2362 	}
2363 
2364 	if (scan_req->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
2365 		pr_debug("MAC%u: scan with random addr=%pM, mask=%pM\n",
2366 			 mac->macid,
2367 			 scan_req->mac_addr, scan_req->mac_addr_mask);
2368 
2369 		qtnf_cmd_randmac_tlv_add(cmd_skb, scan_req->mac_addr,
2370 					 scan_req->mac_addr_mask);
2371 	}
2372 
2373 	ret = qtnf_cmd_send(mac->bus, cmd_skb, &res_code);
2374 
2375 	if (unlikely(ret))
2376 		goto out;
2377 
2378 	pr_debug("MAC%u: scan started\n", mac->macid);
2379 
2380 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2381 		pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
2382 		ret = -EFAULT;
2383 		goto out;
2384 	}
2385 out:
2386 	qtnf_bus_unlock(mac->bus);
2387 	return ret;
2388 }
2389 
2390 int qtnf_cmd_send_connect(struct qtnf_vif *vif,
2391 			  struct cfg80211_connect_params *sme)
2392 {
2393 	struct sk_buff *cmd_skb;
2394 	struct qlink_cmd_connect *cmd;
2395 	struct qlink_auth_encr *aen;
2396 	u16 res_code = QLINK_CMD_RESULT_OK;
2397 	int ret;
2398 	int i;
2399 	u32 connect_flags = 0;
2400 
2401 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2402 					    QLINK_CMD_CONNECT,
2403 					    sizeof(*cmd));
2404 	if (!cmd_skb)
2405 		return -ENOMEM;
2406 
2407 	cmd = (struct qlink_cmd_connect *)cmd_skb->data;
2408 
2409 	ether_addr_copy(cmd->bssid, vif->bssid);
2410 
2411 	if (sme->bssid_hint)
2412 		ether_addr_copy(cmd->bssid_hint, sme->bssid_hint);
2413 	else
2414 		eth_zero_addr(cmd->bssid_hint);
2415 
2416 	if (sme->prev_bssid)
2417 		ether_addr_copy(cmd->prev_bssid, sme->prev_bssid);
2418 	else
2419 		eth_zero_addr(cmd->prev_bssid);
2420 
2421 	if ((sme->bg_scan_period >= 0) &&
2422 	    (sme->bg_scan_period <= SHRT_MAX))
2423 		cmd->bg_scan_period = cpu_to_le16(sme->bg_scan_period);
2424 	else
2425 		cmd->bg_scan_period = cpu_to_le16(-1); /* use default value */
2426 
2427 	if (sme->flags & ASSOC_REQ_DISABLE_HT)
2428 		connect_flags |= QLINK_STA_CONNECT_DISABLE_HT;
2429 	if (sme->flags & ASSOC_REQ_DISABLE_VHT)
2430 		connect_flags |= QLINK_STA_CONNECT_DISABLE_VHT;
2431 	if (sme->flags & ASSOC_REQ_USE_RRM)
2432 		connect_flags |= QLINK_STA_CONNECT_USE_RRM;
2433 
2434 	cmd->flags = cpu_to_le32(connect_flags);
2435 	memcpy(&cmd->ht_capa, &sme->ht_capa, sizeof(cmd->ht_capa));
2436 	memcpy(&cmd->ht_capa_mask, &sme->ht_capa_mask,
2437 	       sizeof(cmd->ht_capa_mask));
2438 	memcpy(&cmd->vht_capa, &sme->vht_capa, sizeof(cmd->vht_capa));
2439 	memcpy(&cmd->vht_capa_mask, &sme->vht_capa_mask,
2440 	       sizeof(cmd->vht_capa_mask));
2441 	cmd->pbss = sme->pbss;
2442 
2443 	aen = &cmd->aen;
2444 	aen->auth_type = sme->auth_type;
2445 	aen->privacy = !!sme->privacy;
2446 	cmd->mfp = sme->mfp;
2447 	aen->wpa_versions = cpu_to_le32(sme->crypto.wpa_versions);
2448 	aen->cipher_group = cpu_to_le32(sme->crypto.cipher_group);
2449 	aen->n_ciphers_pairwise = cpu_to_le32(sme->crypto.n_ciphers_pairwise);
2450 
2451 	for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
2452 		aen->ciphers_pairwise[i] =
2453 			cpu_to_le32(sme->crypto.ciphers_pairwise[i]);
2454 
2455 	aen->n_akm_suites = cpu_to_le32(sme->crypto.n_akm_suites);
2456 
2457 	for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
2458 		aen->akm_suites[i] = cpu_to_le32(sme->crypto.akm_suites[i]);
2459 
2460 	aen->control_port = sme->crypto.control_port;
2461 	aen->control_port_no_encrypt =
2462 		sme->crypto.control_port_no_encrypt;
2463 	aen->control_port_ethertype =
2464 		cpu_to_le16(be16_to_cpu(sme->crypto.control_port_ethertype));
2465 
2466 	qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, sme->ssid,
2467 				 sme->ssid_len);
2468 
2469 	if (sme->ie_len != 0)
2470 		qtnf_cmd_tlv_ie_set_add(cmd_skb, QLINK_IE_SET_ASSOC_REQ,
2471 					sme->ie, sme->ie_len);
2472 
2473 	if (sme->channel)
2474 		qtnf_cmd_channel_tlv_add(cmd_skb, sme->channel);
2475 
2476 	qtnf_bus_lock(vif->mac->bus);
2477 
2478 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2479 
2480 	if (unlikely(ret))
2481 		goto out;
2482 
2483 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2484 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2485 		       vif->vifid, res_code);
2486 		ret = -EFAULT;
2487 		goto out;
2488 	}
2489 out:
2490 	qtnf_bus_unlock(vif->mac->bus);
2491 	return ret;
2492 }
2493 
2494 int qtnf_cmd_send_disconnect(struct qtnf_vif *vif, u16 reason_code)
2495 {
2496 	struct sk_buff *cmd_skb;
2497 	struct qlink_cmd_disconnect *cmd;
2498 	u16 res_code = QLINK_CMD_RESULT_OK;
2499 	int ret;
2500 
2501 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2502 					    QLINK_CMD_DISCONNECT,
2503 					    sizeof(*cmd));
2504 	if (!cmd_skb)
2505 		return -ENOMEM;
2506 
2507 	qtnf_bus_lock(vif->mac->bus);
2508 
2509 	cmd = (struct qlink_cmd_disconnect *)cmd_skb->data;
2510 	cmd->reason = cpu_to_le16(reason_code);
2511 
2512 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2513 
2514 	if (unlikely(ret))
2515 		goto out;
2516 
2517 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2518 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2519 		       vif->vifid, res_code);
2520 		ret = -EFAULT;
2521 		goto out;
2522 	}
2523 out:
2524 	qtnf_bus_unlock(vif->mac->bus);
2525 	return ret;
2526 }
2527 
2528 int qtnf_cmd_send_updown_intf(struct qtnf_vif *vif, bool up)
2529 {
2530 	struct sk_buff *cmd_skb;
2531 	struct qlink_cmd_updown *cmd;
2532 	u16 res_code = QLINK_CMD_RESULT_OK;
2533 	int ret;
2534 
2535 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2536 					    QLINK_CMD_UPDOWN_INTF,
2537 					    sizeof(*cmd));
2538 	if (!cmd_skb)
2539 		return -ENOMEM;
2540 
2541 	cmd = (struct qlink_cmd_updown *)cmd_skb->data;
2542 	cmd->if_up = !!up;
2543 
2544 	qtnf_bus_lock(vif->mac->bus);
2545 
2546 	ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2547 
2548 	if (unlikely(ret))
2549 		goto out;
2550 
2551 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2552 		pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2553 		       vif->vifid, res_code);
2554 		ret = -EFAULT;
2555 		goto out;
2556 	}
2557 out:
2558 	qtnf_bus_unlock(vif->mac->bus);
2559 	return ret;
2560 }
2561 
2562 int qtnf_cmd_reg_notify(struct qtnf_bus *bus, struct regulatory_request *req)
2563 {
2564 	struct sk_buff *cmd_skb;
2565 	int ret;
2566 	u16 res_code;
2567 	struct qlink_cmd_reg_notify *cmd;
2568 
2569 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
2570 					    QLINK_CMD_REG_NOTIFY,
2571 					    sizeof(*cmd));
2572 	if (!cmd_skb)
2573 		return -ENOMEM;
2574 
2575 	cmd = (struct qlink_cmd_reg_notify *)cmd_skb->data;
2576 	cmd->alpha2[0] = req->alpha2[0];
2577 	cmd->alpha2[1] = req->alpha2[1];
2578 
2579 	switch (req->initiator) {
2580 	case NL80211_REGDOM_SET_BY_CORE:
2581 		cmd->initiator = QLINK_REGDOM_SET_BY_CORE;
2582 		break;
2583 	case NL80211_REGDOM_SET_BY_USER:
2584 		cmd->initiator = QLINK_REGDOM_SET_BY_USER;
2585 		break;
2586 	case NL80211_REGDOM_SET_BY_DRIVER:
2587 		cmd->initiator = QLINK_REGDOM_SET_BY_DRIVER;
2588 		break;
2589 	case NL80211_REGDOM_SET_BY_COUNTRY_IE:
2590 		cmd->initiator = QLINK_REGDOM_SET_BY_COUNTRY_IE;
2591 		break;
2592 	}
2593 
2594 	switch (req->user_reg_hint_type) {
2595 	case NL80211_USER_REG_HINT_USER:
2596 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_USER;
2597 		break;
2598 	case NL80211_USER_REG_HINT_CELL_BASE:
2599 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_CELL_BASE;
2600 		break;
2601 	case NL80211_USER_REG_HINT_INDOOR:
2602 		cmd->user_reg_hint_type = QLINK_USER_REG_HINT_INDOOR;
2603 		break;
2604 	}
2605 
2606 	qtnf_bus_lock(bus);
2607 
2608 	ret = qtnf_cmd_send(bus, cmd_skb, &res_code);
2609 	if (ret)
2610 		goto out;
2611 
2612 	switch (res_code) {
2613 	case QLINK_CMD_RESULT_ENOTSUPP:
2614 		pr_warn("reg update not supported\n");
2615 		ret = -EOPNOTSUPP;
2616 		break;
2617 	case QLINK_CMD_RESULT_EALREADY:
2618 		pr_info("regulatory domain is already set to %c%c",
2619 			req->alpha2[0], req->alpha2[1]);
2620 		ret = -EALREADY;
2621 		break;
2622 	case QLINK_CMD_RESULT_OK:
2623 		ret = 0;
2624 		break;
2625 	default:
2626 		ret = -EFAULT;
2627 		break;
2628 	}
2629 
2630 out:
2631 	qtnf_bus_unlock(bus);
2632 
2633 	return ret;
2634 }
2635 
2636 int qtnf_cmd_get_chan_stats(struct qtnf_wmac *mac, u16 channel,
2637 			    struct qtnf_chan_stats *stats)
2638 {
2639 	struct sk_buff *cmd_skb, *resp_skb = NULL;
2640 	struct qlink_cmd_get_chan_stats *cmd;
2641 	struct qlink_resp_get_chan_stats *resp;
2642 	size_t var_data_len;
2643 	u16 res_code = QLINK_CMD_RESULT_OK;
2644 	int ret = 0;
2645 
2646 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
2647 					    QLINK_CMD_CHAN_STATS,
2648 					    sizeof(*cmd));
2649 	if (!cmd_skb)
2650 		return -ENOMEM;
2651 
2652 	qtnf_bus_lock(mac->bus);
2653 
2654 	cmd = (struct qlink_cmd_get_chan_stats *)cmd_skb->data;
2655 	cmd->channel = cpu_to_le16(channel);
2656 
2657 	ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb, &res_code,
2658 				       sizeof(*resp), &var_data_len);
2659 	if (unlikely(ret)) {
2660 		qtnf_bus_unlock(mac->bus);
2661 		return ret;
2662 	}
2663 
2664 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2665 		switch (res_code) {
2666 		case QLINK_CMD_RESULT_ENOTFOUND:
2667 			ret = -ENOENT;
2668 			break;
2669 		default:
2670 			pr_err("cmd exec failed: 0x%.4X\n", res_code);
2671 			ret = -EFAULT;
2672 			break;
2673 		}
2674 		goto out;
2675 	}
2676 
2677 	resp = (struct qlink_resp_get_chan_stats *)resp_skb->data;
2678 	ret = qtnf_cmd_resp_proc_chan_stat_info(stats, resp->info,
2679 						var_data_len);
2680 
2681 out:
2682 	qtnf_bus_unlock(mac->bus);
2683 	consume_skb(resp_skb);
2684 	return ret;
2685 }
2686 
2687 int qtnf_cmd_send_chan_switch(struct qtnf_vif *vif,
2688 			      struct cfg80211_csa_settings *params)
2689 {
2690 	struct qtnf_wmac *mac = vif->mac;
2691 	struct qlink_cmd_chan_switch *cmd;
2692 	struct sk_buff *cmd_skb;
2693 	u16 res_code = QLINK_CMD_RESULT_OK;
2694 	int ret;
2695 
2696 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, vif->vifid,
2697 					    QLINK_CMD_CHAN_SWITCH,
2698 					    sizeof(*cmd));
2699 	if (!cmd_skb)
2700 		return -ENOMEM;
2701 
2702 	qtnf_bus_lock(mac->bus);
2703 
2704 	cmd = (struct qlink_cmd_chan_switch *)cmd_skb->data;
2705 	cmd->channel = cpu_to_le16(params->chandef.chan->hw_value);
2706 	cmd->radar_required = params->radar_required;
2707 	cmd->block_tx = params->block_tx;
2708 	cmd->beacon_count = params->count;
2709 
2710 	ret = qtnf_cmd_send(mac->bus, cmd_skb, &res_code);
2711 
2712 	if (unlikely(ret))
2713 		goto out;
2714 
2715 	switch (res_code) {
2716 	case QLINK_CMD_RESULT_OK:
2717 		ret = 0;
2718 		break;
2719 	case QLINK_CMD_RESULT_ENOTFOUND:
2720 		ret = -ENOENT;
2721 		break;
2722 	case QLINK_CMD_RESULT_ENOTSUPP:
2723 		ret = -EOPNOTSUPP;
2724 		break;
2725 	case QLINK_CMD_RESULT_EALREADY:
2726 		ret = -EALREADY;
2727 		break;
2728 	case QLINK_CMD_RESULT_INVALID:
2729 	default:
2730 		ret = -EFAULT;
2731 		break;
2732 	}
2733 
2734 out:
2735 	qtnf_bus_unlock(mac->bus);
2736 	return ret;
2737 }
2738 
2739 int qtnf_cmd_get_channel(struct qtnf_vif *vif, struct cfg80211_chan_def *chdef)
2740 {
2741 	struct qtnf_bus *bus = vif->mac->bus;
2742 	const struct qlink_resp_channel_get *resp;
2743 	struct sk_buff *cmd_skb;
2744 	struct sk_buff *resp_skb = NULL;
2745 	u16 res_code = QLINK_CMD_RESULT_OK;
2746 	int ret;
2747 
2748 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2749 					    QLINK_CMD_CHAN_GET,
2750 					    sizeof(struct qlink_cmd));
2751 	if (!cmd_skb)
2752 		return -ENOMEM;
2753 
2754 	qtnf_bus_lock(bus);
2755 
2756 	ret = qtnf_cmd_send_with_reply(bus, cmd_skb, &resp_skb, &res_code,
2757 				       sizeof(*resp), NULL);
2758 
2759 	qtnf_bus_unlock(bus);
2760 
2761 	if (unlikely(ret))
2762 		goto out;
2763 
2764 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2765 		ret = -ENODATA;
2766 		goto out;
2767 	}
2768 
2769 	resp = (const struct qlink_resp_channel_get *)resp_skb->data;
2770 	qlink_chandef_q2cfg(priv_to_wiphy(vif->mac), &resp->chan, chdef);
2771 
2772 out:
2773 	consume_skb(resp_skb);
2774 	return ret;
2775 }
2776 
2777 int qtnf_cmd_start_cac(const struct qtnf_vif *vif,
2778 		       const struct cfg80211_chan_def *chdef,
2779 		       u32 cac_time_ms)
2780 {
2781 	struct qtnf_bus *bus = vif->mac->bus;
2782 	struct sk_buff *cmd_skb;
2783 	struct qlink_cmd_start_cac *cmd;
2784 	int ret;
2785 	u16 res_code;
2786 
2787 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2788 					    QLINK_CMD_START_CAC,
2789 					    sizeof(*cmd));
2790 	if (!cmd_skb)
2791 		return -ENOMEM;
2792 
2793 	cmd = (struct qlink_cmd_start_cac *)cmd_skb->data;
2794 	cmd->cac_time_ms = cpu_to_le32(cac_time_ms);
2795 	qlink_chandef_cfg2q(chdef, &cmd->chan);
2796 
2797 	qtnf_bus_lock(bus);
2798 	ret = qtnf_cmd_send(bus, cmd_skb, &res_code);
2799 	qtnf_bus_unlock(bus);
2800 
2801 	if (ret)
2802 		return ret;
2803 
2804 	switch (res_code) {
2805 	case QLINK_CMD_RESULT_OK:
2806 		break;
2807 	default:
2808 		ret = -EOPNOTSUPP;
2809 		break;
2810 	}
2811 
2812 	return ret;
2813 }
2814 
2815 int qtnf_cmd_set_mac_acl(const struct qtnf_vif *vif,
2816 			 const struct cfg80211_acl_data *params)
2817 {
2818 	struct qtnf_bus *bus = vif->mac->bus;
2819 	struct sk_buff *cmd_skb;
2820 	struct qlink_tlv_hdr *tlv;
2821 	size_t acl_size = qtnf_cmd_acl_data_size(params);
2822 	u16 res_code;
2823 	int ret;
2824 
2825 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2826 					    QLINK_CMD_SET_MAC_ACL,
2827 					    sizeof(struct qlink_cmd));
2828 	if (!cmd_skb)
2829 		return -ENOMEM;
2830 
2831 	tlv = skb_put(cmd_skb, sizeof(*tlv) + acl_size);
2832 	tlv->type = cpu_to_le16(QTN_TLV_ID_ACL_DATA);
2833 	tlv->len = cpu_to_le16(acl_size);
2834 	qlink_acl_data_cfg2q(params, (struct qlink_acl_data *)tlv->val);
2835 
2836 	qtnf_bus_lock(bus);
2837 	ret = qtnf_cmd_send(bus, cmd_skb, &res_code);
2838 	qtnf_bus_unlock(bus);
2839 
2840 	if (unlikely(ret))
2841 		return ret;
2842 
2843 	switch (res_code) {
2844 	case QLINK_CMD_RESULT_OK:
2845 		break;
2846 	case QLINK_CMD_RESULT_INVALID:
2847 		ret = -EINVAL;
2848 		break;
2849 	default:
2850 		ret = -EOPNOTSUPP;
2851 		break;
2852 	}
2853 
2854 	return ret;
2855 }
2856 
2857 int qtnf_cmd_send_pm_set(const struct qtnf_vif *vif, u8 pm_mode, int timeout)
2858 {
2859 	struct qtnf_bus *bus = vif->mac->bus;
2860 	struct sk_buff *cmd_skb;
2861 	u16 res_code = QLINK_CMD_RESULT_OK;
2862 	struct qlink_cmd_pm_set *cmd;
2863 	int ret = 0;
2864 
2865 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2866 					    QLINK_CMD_PM_SET, sizeof(*cmd));
2867 	if (!cmd_skb)
2868 		return -ENOMEM;
2869 
2870 	cmd = (struct qlink_cmd_pm_set *)cmd_skb->data;
2871 	cmd->pm_mode = pm_mode;
2872 	cmd->pm_standby_timer = cpu_to_le32(timeout);
2873 
2874 	qtnf_bus_lock(bus);
2875 
2876 	ret = qtnf_cmd_send(bus, cmd_skb, &res_code);
2877 
2878 	if (unlikely(ret))
2879 		goto out;
2880 
2881 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2882 		pr_err("cmd exec failed: 0x%.4X\n", res_code);
2883 		ret = -EFAULT;
2884 	}
2885 
2886 out:
2887 	qtnf_bus_unlock(bus);
2888 	return ret;
2889 }
2890 
2891 int qtnf_cmd_send_wowlan_set(const struct qtnf_vif *vif,
2892 			     const struct cfg80211_wowlan *wowl)
2893 {
2894 	struct qtnf_bus *bus = vif->mac->bus;
2895 	struct sk_buff *cmd_skb;
2896 	u16 res_code = QLINK_CMD_RESULT_OK;
2897 	struct qlink_cmd_wowlan_set *cmd;
2898 	u32 triggers = 0;
2899 	int count = 0;
2900 	int ret = 0;
2901 
2902 	cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2903 					    QLINK_CMD_WOWLAN_SET, sizeof(*cmd));
2904 	if (!cmd_skb)
2905 		return -ENOMEM;
2906 
2907 	qtnf_bus_lock(bus);
2908 
2909 	cmd = (struct qlink_cmd_wowlan_set *)cmd_skb->data;
2910 
2911 	if (wowl) {
2912 		if (wowl->disconnect)
2913 			triggers |=  QLINK_WOWLAN_TRIG_DISCONNECT;
2914 
2915 		if (wowl->magic_pkt)
2916 			triggers |= QLINK_WOWLAN_TRIG_MAGIC_PKT;
2917 
2918 		if (wowl->n_patterns && wowl->patterns) {
2919 			triggers |= QLINK_WOWLAN_TRIG_PATTERN_PKT;
2920 			while (count < wowl->n_patterns) {
2921 				qtnf_cmd_skb_put_tlv_arr(cmd_skb,
2922 					QTN_TLV_ID_WOWLAN_PATTERN,
2923 					wowl->patterns[count].pattern,
2924 					wowl->patterns[count].pattern_len);
2925 				count++;
2926 			}
2927 		}
2928 	}
2929 
2930 	cmd->triggers = cpu_to_le32(triggers);
2931 
2932 	ret = qtnf_cmd_send(bus, cmd_skb, &res_code);
2933 
2934 	if (unlikely(ret))
2935 		goto out;
2936 
2937 	if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2938 		pr_err("cmd exec failed: 0x%.4X\n", res_code);
2939 		ret = -EFAULT;
2940 	}
2941 
2942 out:
2943 	qtnf_bus_unlock(bus);
2944 	return ret;
2945 }
2946