xref: /linux/drivers/net/wireless/realtek/rtw89/cam.c (revision 2a52ca7c98960aafb0eca9ef96b2d0c932171357)
1 // SPDX-License-Identifier: GPL-2.0 OR BSD-3-Clause
2 /* Copyright(c) 2019-2020  Realtek Corporation
3  */
4 
5 #include "cam.h"
6 #include "debug.h"
7 #include "fw.h"
8 #include "mac.h"
9 
10 static struct sk_buff *
11 rtw89_cam_get_sec_key_cmd(struct rtw89_dev *rtwdev,
12 			  struct rtw89_sec_cam_entry *sec_cam,
13 			  bool ext_key)
14 {
15 	struct sk_buff *skb;
16 	u32 cmd_len = H2C_SEC_CAM_LEN;
17 	u32 key32[4];
18 	u8 *cmd;
19 	int i, j;
20 
21 	skb = rtw89_fw_h2c_alloc_skb_with_hdr(rtwdev, cmd_len);
22 	if (!skb)
23 		return NULL;
24 
25 	skb_put_zero(skb, cmd_len);
26 
27 	for (i = 0; i < 4; i++) {
28 		j = i * 4;
29 		j += ext_key ? 16 : 0;
30 		key32[i] = FIELD_PREP(GENMASK(7, 0), sec_cam->key[j + 0]) |
31 			   FIELD_PREP(GENMASK(15, 8), sec_cam->key[j + 1]) |
32 			   FIELD_PREP(GENMASK(23, 16), sec_cam->key[j + 2]) |
33 			   FIELD_PREP(GENMASK(31, 24), sec_cam->key[j + 3]);
34 	}
35 
36 	cmd = skb->data;
37 	RTW89_SET_FWCMD_SEC_IDX(cmd, sec_cam->sec_cam_idx + (ext_key ? 1 : 0));
38 	RTW89_SET_FWCMD_SEC_OFFSET(cmd, sec_cam->offset);
39 	RTW89_SET_FWCMD_SEC_LEN(cmd, sec_cam->len);
40 	RTW89_SET_FWCMD_SEC_TYPE(cmd, sec_cam->type);
41 	RTW89_SET_FWCMD_SEC_EXT_KEY(cmd, ext_key);
42 	RTW89_SET_FWCMD_SEC_SPP_MODE(cmd, sec_cam->spp_mode);
43 	RTW89_SET_FWCMD_SEC_KEY0(cmd, key32[0]);
44 	RTW89_SET_FWCMD_SEC_KEY1(cmd, key32[1]);
45 	RTW89_SET_FWCMD_SEC_KEY2(cmd, key32[2]);
46 	RTW89_SET_FWCMD_SEC_KEY3(cmd, key32[3]);
47 
48 	return skb;
49 }
50 
51 static int rtw89_cam_send_sec_key_cmd(struct rtw89_dev *rtwdev,
52 				      struct rtw89_sec_cam_entry *sec_cam)
53 {
54 	struct sk_buff *skb, *ext_skb;
55 	int ret;
56 
57 	skb = rtw89_cam_get_sec_key_cmd(rtwdev, sec_cam, false);
58 	if (!skb) {
59 		rtw89_err(rtwdev, "failed to get sec key command\n");
60 		return -ENOMEM;
61 	}
62 
63 	rtw89_h2c_pkt_set_hdr(rtwdev, skb,
64 			      FWCMD_TYPE_H2C,
65 			      H2C_CAT_MAC,
66 			      H2C_CL_MAC_SEC_CAM,
67 			      H2C_FUNC_MAC_SEC_UPD, 1, 0,
68 			      H2C_SEC_CAM_LEN);
69 	ret = rtw89_h2c_tx(rtwdev, skb, false);
70 	if (ret) {
71 		rtw89_err(rtwdev, "failed to send sec key h2c: %d\n", ret);
72 		dev_kfree_skb(skb);
73 		return ret;
74 	}
75 
76 	if (!sec_cam->ext_key)
77 		return 0;
78 
79 	ext_skb = rtw89_cam_get_sec_key_cmd(rtwdev, sec_cam, true);
80 	if (!ext_skb) {
81 		rtw89_err(rtwdev, "failed to get ext sec key command\n");
82 		return -ENOMEM;
83 	}
84 
85 	rtw89_h2c_pkt_set_hdr(rtwdev, ext_skb,
86 			      FWCMD_TYPE_H2C,
87 			      H2C_CAT_MAC,
88 			      H2C_CL_MAC_SEC_CAM,
89 			      H2C_FUNC_MAC_SEC_UPD,
90 			      1, 0, H2C_SEC_CAM_LEN);
91 	ret = rtw89_h2c_tx(rtwdev, ext_skb, false);
92 	if (ret) {
93 		rtw89_err(rtwdev, "failed to send ext sec key h2c: %d\n", ret);
94 		dev_kfree_skb(ext_skb);
95 		return ret;
96 	}
97 
98 	return 0;
99 }
100 
101 static int rtw89_cam_get_avail_sec_cam(struct rtw89_dev *rtwdev,
102 				       u8 *sec_cam_idx, bool ext_key)
103 {
104 	const struct rtw89_chip_info *chip = rtwdev->chip;
105 	struct rtw89_cam_info *cam_info = &rtwdev->cam_info;
106 	u8 sec_cam_num = chip->scam_num;
107 	u8 idx = 0;
108 
109 	if (!ext_key) {
110 		idx = find_first_zero_bit(cam_info->sec_cam_map, sec_cam_num);
111 		if (idx >= sec_cam_num)
112 			return -EBUSY;
113 
114 		set_bit(idx, cam_info->sec_cam_map);
115 		*sec_cam_idx = idx;
116 
117 		return 0;
118 	}
119 
120 again:
121 	idx = find_next_zero_bit(cam_info->sec_cam_map, sec_cam_num, idx);
122 	if (idx >= sec_cam_num - 1)
123 		return -EBUSY;
124 	/* ext keys need two cam entries for 256-bit key */
125 	if (test_bit(idx + 1, cam_info->sec_cam_map)) {
126 		idx++;
127 		goto again;
128 	}
129 
130 	set_bit(idx, cam_info->sec_cam_map);
131 	set_bit(idx + 1, cam_info->sec_cam_map);
132 	*sec_cam_idx = idx;
133 
134 	return 0;
135 }
136 
137 static int rtw89_cam_get_addr_cam_key_idx(struct rtw89_addr_cam_entry *addr_cam,
138 					  struct rtw89_sec_cam_entry *sec_cam,
139 					  struct ieee80211_key_conf *key,
140 					  u8 *key_idx)
141 {
142 	u8 idx;
143 
144 	/* RTW89_ADDR_CAM_SEC_NONE	: not enabled
145 	 * RTW89_ADDR_CAM_SEC_ALL_UNI	: 0 - 6 unicast
146 	 * RTW89_ADDR_CAM_SEC_NORMAL	: 0 - 1 unicast, 2 - 4 group, 5 - 6 BIP
147 	 * RTW89_ADDR_CAM_SEC_4GROUP	: 0 - 1 unicast, 2 - 5 group, 6 BIP
148 	 */
149 	switch (addr_cam->sec_ent_mode) {
150 	case RTW89_ADDR_CAM_SEC_NONE:
151 		return -EINVAL;
152 	case RTW89_ADDR_CAM_SEC_ALL_UNI:
153 		idx = find_first_zero_bit(addr_cam->sec_cam_map,
154 					  RTW89_SEC_CAM_IN_ADDR_CAM);
155 		if (idx >= RTW89_SEC_CAM_IN_ADDR_CAM)
156 			return -EBUSY;
157 		*key_idx = idx;
158 		break;
159 	case RTW89_ADDR_CAM_SEC_NORMAL:
160 		if (sec_cam->type == RTW89_SEC_KEY_TYPE_BIP_CCMP128) {
161 			idx = find_next_zero_bit(addr_cam->sec_cam_map,
162 						 RTW89_SEC_CAM_IN_ADDR_CAM, 5);
163 			if (idx > 6)
164 				return -EBUSY;
165 			*key_idx = idx;
166 			break;
167 		}
168 
169 		if (key->flags & IEEE80211_KEY_FLAG_PAIRWISE) {
170 			idx = find_next_zero_bit(addr_cam->sec_cam_map,
171 						 RTW89_SEC_CAM_IN_ADDR_CAM, 0);
172 			if (idx > 1)
173 				return -EBUSY;
174 			*key_idx = idx;
175 			break;
176 		}
177 
178 		/* Group keys */
179 		idx = find_next_zero_bit(addr_cam->sec_cam_map,
180 					 RTW89_SEC_CAM_IN_ADDR_CAM, 2);
181 		if (idx > 4)
182 			return -EBUSY;
183 		*key_idx = idx;
184 		break;
185 	case RTW89_ADDR_CAM_SEC_4GROUP:
186 		if (sec_cam->type == RTW89_SEC_KEY_TYPE_BIP_CCMP128) {
187 			if (test_bit(6, addr_cam->sec_cam_map))
188 				return -EINVAL;
189 			*key_idx = 6;
190 			break;
191 		}
192 
193 		if (key->flags & IEEE80211_KEY_FLAG_PAIRWISE) {
194 			idx = find_next_zero_bit(addr_cam->sec_cam_map,
195 						 RTW89_SEC_CAM_IN_ADDR_CAM, 0);
196 			if (idx > 1)
197 				return -EBUSY;
198 			*key_idx = idx;
199 			break;
200 		}
201 
202 		/* Group keys */
203 		idx = find_next_zero_bit(addr_cam->sec_cam_map,
204 					 RTW89_SEC_CAM_IN_ADDR_CAM, 2);
205 		if (idx > 5)
206 			return -EBUSY;
207 		*key_idx = idx;
208 		break;
209 	}
210 
211 	return 0;
212 }
213 
214 static int rtw89_cam_detach_sec_cam(struct rtw89_dev *rtwdev,
215 				    struct ieee80211_vif *vif,
216 				    struct ieee80211_sta *sta,
217 				    const struct rtw89_sec_cam_entry *sec_cam,
218 				    bool inform_fw)
219 {
220 	struct rtw89_sta *rtwsta = sta_to_rtwsta_safe(sta);
221 	struct rtw89_vif *rtwvif;
222 	struct rtw89_addr_cam_entry *addr_cam;
223 	unsigned int i;
224 	int ret = 0;
225 
226 	if (!vif) {
227 		rtw89_err(rtwdev, "No iface for deleting sec cam\n");
228 		return -EINVAL;
229 	}
230 
231 	rtwvif = (struct rtw89_vif *)vif->drv_priv;
232 	addr_cam = rtw89_get_addr_cam_of(rtwvif, rtwsta);
233 
234 	for_each_set_bit(i, addr_cam->sec_cam_map, RTW89_SEC_CAM_IN_ADDR_CAM) {
235 		if (addr_cam->sec_ent[i] != sec_cam->sec_cam_idx)
236 			continue;
237 
238 		clear_bit(i, addr_cam->sec_cam_map);
239 	}
240 
241 	if (inform_fw) {
242 		ret = rtw89_chip_h2c_dctl_sec_cam(rtwdev, rtwvif, rtwsta);
243 		if (ret)
244 			rtw89_err(rtwdev,
245 				  "failed to update dctl cam del key: %d\n", ret);
246 		ret = rtw89_fw_h2c_cam(rtwdev, rtwvif, rtwsta, NULL);
247 		if (ret)
248 			rtw89_err(rtwdev, "failed to update cam del key: %d\n", ret);
249 	}
250 
251 	return ret;
252 }
253 
254 static int rtw89_cam_attach_sec_cam(struct rtw89_dev *rtwdev,
255 				    struct ieee80211_vif *vif,
256 				    struct ieee80211_sta *sta,
257 				    struct ieee80211_key_conf *key,
258 				    struct rtw89_sec_cam_entry *sec_cam)
259 {
260 	struct rtw89_sta *rtwsta = sta_to_rtwsta_safe(sta);
261 	struct rtw89_vif *rtwvif;
262 	struct rtw89_addr_cam_entry *addr_cam;
263 	u8 key_idx = 0;
264 	int ret;
265 
266 	if (!vif) {
267 		rtw89_err(rtwdev, "No iface for adding sec cam\n");
268 		return -EINVAL;
269 	}
270 
271 	rtwvif = (struct rtw89_vif *)vif->drv_priv;
272 	addr_cam = rtw89_get_addr_cam_of(rtwvif, rtwsta);
273 
274 	if (key->cipher == WLAN_CIPHER_SUITE_WEP40 ||
275 	    key->cipher == WLAN_CIPHER_SUITE_WEP104)
276 		addr_cam->sec_ent_mode = RTW89_ADDR_CAM_SEC_ALL_UNI;
277 
278 	ret = rtw89_cam_get_addr_cam_key_idx(addr_cam, sec_cam, key, &key_idx);
279 	if (ret) {
280 		rtw89_err(rtwdev, "failed to get addr cam key idx %d, %d\n",
281 			  addr_cam->sec_ent_mode, sec_cam->type);
282 		return ret;
283 	}
284 
285 	addr_cam->sec_ent_keyid[key_idx] = key->keyidx;
286 	addr_cam->sec_ent[key_idx] = sec_cam->sec_cam_idx;
287 	set_bit(key_idx, addr_cam->sec_cam_map);
288 	ret = rtw89_chip_h2c_dctl_sec_cam(rtwdev, rtwvif, rtwsta);
289 	if (ret) {
290 		rtw89_err(rtwdev, "failed to update dctl cam sec entry: %d\n",
291 			  ret);
292 		return ret;
293 	}
294 	ret = rtw89_fw_h2c_cam(rtwdev, rtwvif, rtwsta, NULL);
295 	if (ret) {
296 		rtw89_err(rtwdev, "failed to update addr cam sec entry: %d\n",
297 			  ret);
298 		clear_bit(key_idx, addr_cam->sec_cam_map);
299 		return ret;
300 	}
301 
302 	return 0;
303 }
304 
305 static int rtw89_cam_sec_key_install(struct rtw89_dev *rtwdev,
306 				     struct ieee80211_vif *vif,
307 				     struct ieee80211_sta *sta,
308 				     struct ieee80211_key_conf *key,
309 				     u8 hw_key_type, bool ext_key)
310 {
311 	struct rtw89_sec_cam_entry *sec_cam = NULL;
312 	struct rtw89_cam_info *cam_info = &rtwdev->cam_info;
313 	u8 sec_cam_idx;
314 	int ret;
315 
316 	/* maximum key length 256-bit */
317 	if (key->keylen > 32) {
318 		rtw89_err(rtwdev, "invalid sec key length %d\n", key->keylen);
319 		return -EINVAL;
320 	}
321 
322 	ret = rtw89_cam_get_avail_sec_cam(rtwdev, &sec_cam_idx, ext_key);
323 	if (ret) {
324 		rtw89_warn(rtwdev, "no available sec cam: %d ext: %d\n",
325 			   ret, ext_key);
326 		return ret;
327 	}
328 
329 	sec_cam = kzalloc(sizeof(*sec_cam), GFP_KERNEL);
330 	if (!sec_cam) {
331 		ret = -ENOMEM;
332 		goto err_release_cam;
333 	}
334 
335 	key->hw_key_idx = sec_cam_idx;
336 	cam_info->sec_entries[sec_cam_idx] = sec_cam;
337 
338 	sec_cam->sec_cam_idx = sec_cam_idx;
339 	sec_cam->type = hw_key_type;
340 	sec_cam->len = RTW89_SEC_CAM_LEN;
341 	sec_cam->ext_key = ext_key;
342 	memcpy(sec_cam->key, key->key, key->keylen);
343 	ret = rtw89_cam_send_sec_key_cmd(rtwdev, sec_cam);
344 	if (ret) {
345 		rtw89_err(rtwdev, "failed to send sec key cmd: %d\n", ret);
346 		goto err_release_cam;
347 	}
348 
349 	/* associate with addr cam */
350 	ret = rtw89_cam_attach_sec_cam(rtwdev, vif, sta, key, sec_cam);
351 	if (ret) {
352 		rtw89_err(rtwdev, "failed to attach sec cam: %d\n", ret);
353 		goto err_release_cam;
354 	}
355 
356 	return 0;
357 
358 err_release_cam:
359 	cam_info->sec_entries[sec_cam_idx] = NULL;
360 	kfree(sec_cam);
361 	clear_bit(sec_cam_idx, cam_info->sec_cam_map);
362 	if (ext_key)
363 		clear_bit(sec_cam_idx + 1, cam_info->sec_cam_map);
364 
365 	return ret;
366 }
367 
368 int rtw89_cam_sec_key_add(struct rtw89_dev *rtwdev,
369 			  struct ieee80211_vif *vif,
370 			  struct ieee80211_sta *sta,
371 			  struct ieee80211_key_conf *key)
372 {
373 	const struct rtw89_chip_info *chip = rtwdev->chip;
374 	u8 hw_key_type;
375 	bool ext_key = false;
376 	int ret;
377 
378 	switch (key->cipher) {
379 	case WLAN_CIPHER_SUITE_WEP40:
380 		hw_key_type = RTW89_SEC_KEY_TYPE_WEP40;
381 		break;
382 	case WLAN_CIPHER_SUITE_WEP104:
383 		hw_key_type = RTW89_SEC_KEY_TYPE_WEP104;
384 		break;
385 	case WLAN_CIPHER_SUITE_CCMP:
386 		hw_key_type = RTW89_SEC_KEY_TYPE_CCMP128;
387 		key->flags |= IEEE80211_KEY_FLAG_SW_MGMT_TX;
388 		break;
389 	case WLAN_CIPHER_SUITE_CCMP_256:
390 		hw_key_type = RTW89_SEC_KEY_TYPE_CCMP256;
391 		key->flags |= IEEE80211_KEY_FLAG_SW_MGMT_TX;
392 		ext_key = true;
393 		break;
394 	case WLAN_CIPHER_SUITE_GCMP:
395 		hw_key_type = RTW89_SEC_KEY_TYPE_GCMP128;
396 		key->flags |= IEEE80211_KEY_FLAG_SW_MGMT_TX;
397 		break;
398 	case WLAN_CIPHER_SUITE_GCMP_256:
399 		hw_key_type = RTW89_SEC_KEY_TYPE_GCMP256;
400 		key->flags |= IEEE80211_KEY_FLAG_SW_MGMT_TX;
401 		ext_key = true;
402 		break;
403 	case WLAN_CIPHER_SUITE_AES_CMAC:
404 		hw_key_type = RTW89_SEC_KEY_TYPE_BIP_CCMP128;
405 		break;
406 	default:
407 		return -EOPNOTSUPP;
408 	}
409 
410 	if (!chip->hw_sec_hdr)
411 		key->flags |= IEEE80211_KEY_FLAG_GENERATE_IV;
412 
413 	ret = rtw89_cam_sec_key_install(rtwdev, vif, sta, key, hw_key_type,
414 					ext_key);
415 	if (ret) {
416 		rtw89_err(rtwdev, "failed to install key type %d ext %d: %d\n",
417 			  hw_key_type, ext_key, ret);
418 		return ret;
419 	}
420 
421 	return 0;
422 }
423 
424 int rtw89_cam_sec_key_del(struct rtw89_dev *rtwdev,
425 			  struct ieee80211_vif *vif,
426 			  struct ieee80211_sta *sta,
427 			  struct ieee80211_key_conf *key,
428 			  bool inform_fw)
429 {
430 	struct rtw89_cam_info *cam_info = &rtwdev->cam_info;
431 	const struct rtw89_sec_cam_entry *sec_cam;
432 	u8 sec_cam_idx;
433 	int ret;
434 
435 	sec_cam_idx = key->hw_key_idx;
436 	sec_cam = cam_info->sec_entries[sec_cam_idx];
437 	if (!sec_cam)
438 		return -EINVAL;
439 
440 	ret = rtw89_cam_detach_sec_cam(rtwdev, vif, sta, sec_cam, inform_fw);
441 
442 	/* clear valid bit in addr cam will disable sec cam,
443 	 * so we don't need to send H2C command again
444 	 */
445 	cam_info->sec_entries[sec_cam_idx] = NULL;
446 	clear_bit(sec_cam_idx, cam_info->sec_cam_map);
447 	if (sec_cam->ext_key)
448 		clear_bit(sec_cam_idx + 1, cam_info->sec_cam_map);
449 
450 	kfree(sec_cam);
451 
452 	return ret;
453 }
454 
455 static void rtw89_cam_reset_key_iter(struct ieee80211_hw *hw,
456 				     struct ieee80211_vif *vif,
457 				     struct ieee80211_sta *sta,
458 				     struct ieee80211_key_conf *key,
459 				     void *data)
460 {
461 	struct rtw89_dev *rtwdev = (struct rtw89_dev *)data;
462 
463 	rtw89_cam_sec_key_del(rtwdev, vif, sta, key, false);
464 }
465 
466 void rtw89_cam_deinit_addr_cam(struct rtw89_dev *rtwdev,
467 			       struct rtw89_addr_cam_entry *addr_cam)
468 {
469 	struct rtw89_cam_info *cam_info = &rtwdev->cam_info;
470 
471 	addr_cam->valid = false;
472 	clear_bit(addr_cam->addr_cam_idx, cam_info->addr_cam_map);
473 }
474 
475 void rtw89_cam_deinit_bssid_cam(struct rtw89_dev *rtwdev,
476 				struct rtw89_bssid_cam_entry *bssid_cam)
477 {
478 	struct rtw89_cam_info *cam_info = &rtwdev->cam_info;
479 
480 	bssid_cam->valid = false;
481 	clear_bit(bssid_cam->bssid_cam_idx, cam_info->bssid_cam_map);
482 }
483 
484 void rtw89_cam_deinit(struct rtw89_dev *rtwdev, struct rtw89_vif *rtwvif)
485 {
486 	struct rtw89_addr_cam_entry *addr_cam = &rtwvif->addr_cam;
487 	struct rtw89_bssid_cam_entry *bssid_cam = &rtwvif->bssid_cam;
488 
489 	rtw89_cam_deinit_addr_cam(rtwdev, addr_cam);
490 	rtw89_cam_deinit_bssid_cam(rtwdev, bssid_cam);
491 }
492 
493 void rtw89_cam_reset_keys(struct rtw89_dev *rtwdev)
494 {
495 	rcu_read_lock();
496 	ieee80211_iter_keys_rcu(rtwdev->hw, NULL, rtw89_cam_reset_key_iter, rtwdev);
497 	rcu_read_unlock();
498 }
499 
500 static int rtw89_cam_get_avail_addr_cam(struct rtw89_dev *rtwdev,
501 					u8 *addr_cam_idx)
502 {
503 	const struct rtw89_chip_info *chip = rtwdev->chip;
504 	struct rtw89_cam_info *cam_info = &rtwdev->cam_info;
505 	u8 addr_cam_num = chip->acam_num;
506 	u8 idx;
507 
508 	idx = find_first_zero_bit(cam_info->addr_cam_map, addr_cam_num);
509 	if (idx >= addr_cam_num)
510 		return -EBUSY;
511 
512 	set_bit(idx, cam_info->addr_cam_map);
513 	*addr_cam_idx = idx;
514 
515 	return 0;
516 }
517 
518 static u8 rtw89_get_addr_cam_entry_size(struct rtw89_dev *rtwdev)
519 {
520 	const struct rtw89_chip_info *chip = rtwdev->chip;
521 
522 	switch (chip->chip_id) {
523 	case RTL8852A:
524 	case RTL8852B:
525 	case RTL8851B:
526 		return ADDR_CAM_ENT_SIZE;
527 	default:
528 		return ADDR_CAM_ENT_SHORT_SIZE;
529 	}
530 }
531 
532 int rtw89_cam_init_addr_cam(struct rtw89_dev *rtwdev,
533 			    struct rtw89_addr_cam_entry *addr_cam,
534 			    const struct rtw89_bssid_cam_entry *bssid_cam)
535 {
536 	u8 addr_cam_idx;
537 	int i;
538 	int ret;
539 
540 	if (unlikely(addr_cam->valid)) {
541 		rtw89_debug(rtwdev, RTW89_DBG_FW,
542 			    "addr cam is already valid; skip init\n");
543 		return 0;
544 	}
545 
546 	ret = rtw89_cam_get_avail_addr_cam(rtwdev, &addr_cam_idx);
547 	if (ret) {
548 		rtw89_err(rtwdev, "failed to get available addr cam\n");
549 		return ret;
550 	}
551 
552 	addr_cam->addr_cam_idx = addr_cam_idx;
553 	addr_cam->len = rtw89_get_addr_cam_entry_size(rtwdev);
554 	addr_cam->offset = 0;
555 	addr_cam->valid = true;
556 	addr_cam->addr_mask = 0;
557 	addr_cam->mask_sel = RTW89_NO_MSK;
558 	addr_cam->sec_ent_mode = RTW89_ADDR_CAM_SEC_NORMAL;
559 	bitmap_zero(addr_cam->sec_cam_map, RTW89_SEC_CAM_IN_ADDR_CAM);
560 
561 	for (i = 0; i < RTW89_SEC_CAM_IN_ADDR_CAM; i++) {
562 		addr_cam->sec_ent_keyid[i] = 0;
563 		addr_cam->sec_ent[i] = 0;
564 	}
565 
566 	/* associate addr cam with bssid cam */
567 	addr_cam->bssid_cam_idx = bssid_cam->bssid_cam_idx;
568 
569 	return 0;
570 }
571 
572 static int rtw89_cam_get_avail_bssid_cam(struct rtw89_dev *rtwdev,
573 					 u8 *bssid_cam_idx)
574 {
575 	const struct rtw89_chip_info *chip = rtwdev->chip;
576 	struct rtw89_cam_info *cam_info = &rtwdev->cam_info;
577 	u8 bssid_cam_num = chip->bcam_num;
578 	u8 idx;
579 
580 	idx = find_first_zero_bit(cam_info->bssid_cam_map, bssid_cam_num);
581 	if (idx >= bssid_cam_num)
582 		return -EBUSY;
583 
584 	set_bit(idx, cam_info->bssid_cam_map);
585 	*bssid_cam_idx = idx;
586 
587 	return 0;
588 }
589 
590 int rtw89_cam_init_bssid_cam(struct rtw89_dev *rtwdev,
591 			     struct rtw89_vif *rtwvif,
592 			     struct rtw89_bssid_cam_entry *bssid_cam,
593 			     const u8 *bssid)
594 {
595 	u8 bssid_cam_idx;
596 	int ret;
597 
598 	if (unlikely(bssid_cam->valid)) {
599 		rtw89_debug(rtwdev, RTW89_DBG_FW,
600 			    "bssid cam is already valid; skip init\n");
601 		return 0;
602 	}
603 
604 	ret = rtw89_cam_get_avail_bssid_cam(rtwdev, &bssid_cam_idx);
605 	if (ret) {
606 		rtw89_err(rtwdev, "failed to get available bssid cam\n");
607 		return ret;
608 	}
609 
610 	bssid_cam->bssid_cam_idx = bssid_cam_idx;
611 	bssid_cam->phy_idx = rtwvif->phy_idx;
612 	bssid_cam->len = BSSID_CAM_ENT_SIZE;
613 	bssid_cam->offset = 0;
614 	bssid_cam->valid = true;
615 	ether_addr_copy(bssid_cam->bssid, bssid);
616 
617 	return 0;
618 }
619 
620 void rtw89_cam_bssid_changed(struct rtw89_dev *rtwdev, struct rtw89_vif *rtwvif)
621 {
622 	struct rtw89_bssid_cam_entry *bssid_cam = &rtwvif->bssid_cam;
623 
624 	ether_addr_copy(bssid_cam->bssid, rtwvif->bssid);
625 }
626 
627 int rtw89_cam_init(struct rtw89_dev *rtwdev, struct rtw89_vif *rtwvif)
628 {
629 	struct rtw89_addr_cam_entry *addr_cam = &rtwvif->addr_cam;
630 	struct rtw89_bssid_cam_entry *bssid_cam = &rtwvif->bssid_cam;
631 	int ret;
632 
633 	ret = rtw89_cam_init_bssid_cam(rtwdev, rtwvif, bssid_cam, rtwvif->bssid);
634 	if (ret) {
635 		rtw89_err(rtwdev, "failed to init bssid cam\n");
636 		return ret;
637 	}
638 
639 	ret = rtw89_cam_init_addr_cam(rtwdev, addr_cam, bssid_cam);
640 	if (ret) {
641 		rtw89_err(rtwdev, "failed to init addr cam\n");
642 		return ret;
643 	}
644 
645 	return 0;
646 }
647 
648 int rtw89_cam_fill_bssid_cam_info(struct rtw89_dev *rtwdev,
649 				  struct rtw89_vif *rtwvif,
650 				  struct rtw89_sta *rtwsta, u8 *cmd)
651 {
652 	struct ieee80211_vif *vif = rtwvif_to_vif(rtwvif);
653 	struct rtw89_bssid_cam_entry *bssid_cam = rtw89_get_bssid_cam_of(rtwvif, rtwsta);
654 	u8 bss_color = vif->bss_conf.he_bss_color.color;
655 	u8 bss_mask;
656 
657 	if (vif->bss_conf.nontransmitted)
658 		bss_mask = RTW89_BSSID_MATCH_5_BYTES;
659 	else
660 		bss_mask = RTW89_BSSID_MATCH_ALL;
661 
662 	FWCMD_SET_ADDR_BSSID_IDX(cmd, bssid_cam->bssid_cam_idx);
663 	FWCMD_SET_ADDR_BSSID_OFFSET(cmd, bssid_cam->offset);
664 	FWCMD_SET_ADDR_BSSID_LEN(cmd, bssid_cam->len);
665 	FWCMD_SET_ADDR_BSSID_VALID(cmd, bssid_cam->valid);
666 	FWCMD_SET_ADDR_BSSID_MASK(cmd, bss_mask);
667 	FWCMD_SET_ADDR_BSSID_BB_SEL(cmd, bssid_cam->phy_idx);
668 	FWCMD_SET_ADDR_BSSID_BSS_COLOR(cmd, bss_color);
669 
670 	FWCMD_SET_ADDR_BSSID_BSSID0(cmd, bssid_cam->bssid[0]);
671 	FWCMD_SET_ADDR_BSSID_BSSID1(cmd, bssid_cam->bssid[1]);
672 	FWCMD_SET_ADDR_BSSID_BSSID2(cmd, bssid_cam->bssid[2]);
673 	FWCMD_SET_ADDR_BSSID_BSSID3(cmd, bssid_cam->bssid[3]);
674 	FWCMD_SET_ADDR_BSSID_BSSID4(cmd, bssid_cam->bssid[4]);
675 	FWCMD_SET_ADDR_BSSID_BSSID5(cmd, bssid_cam->bssid[5]);
676 
677 	return 0;
678 }
679 
680 static u8 rtw89_cam_addr_hash(u8 start, const u8 *addr)
681 {
682 	u8 hash = 0;
683 	u8 i;
684 
685 	for (i = start; i < ETH_ALEN; i++)
686 		hash ^= addr[i];
687 
688 	return hash;
689 }
690 
691 void rtw89_cam_fill_addr_cam_info(struct rtw89_dev *rtwdev,
692 				  struct rtw89_vif *rtwvif,
693 				  struct rtw89_sta *rtwsta,
694 				  const u8 *scan_mac_addr,
695 				  u8 *cmd)
696 {
697 	struct ieee80211_vif *vif = rtwvif_to_vif(rtwvif);
698 	struct rtw89_addr_cam_entry *addr_cam = rtw89_get_addr_cam_of(rtwvif, rtwsta);
699 	struct ieee80211_sta *sta = rtwsta_to_sta_safe(rtwsta);
700 	const u8 *sma = scan_mac_addr ? scan_mac_addr : rtwvif->mac_addr;
701 	u8 sma_hash, tma_hash, addr_msk_start;
702 	u8 sma_start = 0;
703 	u8 tma_start = 0;
704 	u8 *tma = sta ? sta->addr : rtwvif->bssid;
705 
706 	if (addr_cam->addr_mask != 0) {
707 		addr_msk_start = __ffs(addr_cam->addr_mask);
708 		if (addr_cam->mask_sel == RTW89_SMA)
709 			sma_start = addr_msk_start;
710 		else if (addr_cam->mask_sel == RTW89_TMA)
711 			tma_start = addr_msk_start;
712 	}
713 	sma_hash = rtw89_cam_addr_hash(sma_start, sma);
714 	tma_hash = rtw89_cam_addr_hash(tma_start, tma);
715 
716 	FWCMD_SET_ADDR_IDX(cmd, addr_cam->addr_cam_idx);
717 	FWCMD_SET_ADDR_OFFSET(cmd, addr_cam->offset);
718 	FWCMD_SET_ADDR_LEN(cmd, addr_cam->len);
719 
720 	FWCMD_SET_ADDR_VALID(cmd, addr_cam->valid);
721 	FWCMD_SET_ADDR_NET_TYPE(cmd, rtwvif->net_type);
722 	FWCMD_SET_ADDR_BCN_HIT_COND(cmd, rtwvif->bcn_hit_cond);
723 	FWCMD_SET_ADDR_HIT_RULE(cmd, rtwvif->hit_rule);
724 	FWCMD_SET_ADDR_BB_SEL(cmd, rtwvif->phy_idx);
725 	FWCMD_SET_ADDR_ADDR_MASK(cmd, addr_cam->addr_mask);
726 	FWCMD_SET_ADDR_MASK_SEL(cmd, addr_cam->mask_sel);
727 	FWCMD_SET_ADDR_SMA_HASH(cmd, sma_hash);
728 	FWCMD_SET_ADDR_TMA_HASH(cmd, tma_hash);
729 
730 	FWCMD_SET_ADDR_BSSID_CAM_IDX(cmd, addr_cam->bssid_cam_idx);
731 
732 	FWCMD_SET_ADDR_SMA0(cmd, sma[0]);
733 	FWCMD_SET_ADDR_SMA1(cmd, sma[1]);
734 	FWCMD_SET_ADDR_SMA2(cmd, sma[2]);
735 	FWCMD_SET_ADDR_SMA3(cmd, sma[3]);
736 	FWCMD_SET_ADDR_SMA4(cmd, sma[4]);
737 	FWCMD_SET_ADDR_SMA5(cmd, sma[5]);
738 
739 	FWCMD_SET_ADDR_TMA0(cmd, tma[0]);
740 	FWCMD_SET_ADDR_TMA1(cmd, tma[1]);
741 	FWCMD_SET_ADDR_TMA2(cmd, tma[2]);
742 	FWCMD_SET_ADDR_TMA3(cmd, tma[3]);
743 	FWCMD_SET_ADDR_TMA4(cmd, tma[4]);
744 	FWCMD_SET_ADDR_TMA5(cmd, tma[5]);
745 
746 	FWCMD_SET_ADDR_PORT_INT(cmd, rtwvif->port);
747 	FWCMD_SET_ADDR_TSF_SYNC(cmd, rtwvif->port);
748 	FWCMD_SET_ADDR_TF_TRS(cmd, rtwvif->trigger);
749 	FWCMD_SET_ADDR_LSIG_TXOP(cmd, rtwvif->lsig_txop);
750 	FWCMD_SET_ADDR_TGT_IND(cmd, rtwvif->tgt_ind);
751 	FWCMD_SET_ADDR_FRM_TGT_IND(cmd, rtwvif->frm_tgt_ind);
752 	FWCMD_SET_ADDR_MACID(cmd, rtwsta ? rtwsta->mac_id : rtwvif->mac_id);
753 	if (rtwvif->net_type == RTW89_NET_TYPE_INFRA)
754 		FWCMD_SET_ADDR_AID12(cmd, vif->cfg.aid & 0xfff);
755 	else if (rtwvif->net_type == RTW89_NET_TYPE_AP_MODE)
756 		FWCMD_SET_ADDR_AID12(cmd, sta ? sta->aid & 0xfff : 0);
757 	FWCMD_SET_ADDR_WOL_PATTERN(cmd, rtwvif->wowlan_pattern);
758 	FWCMD_SET_ADDR_WOL_UC(cmd, rtwvif->wowlan_uc);
759 	FWCMD_SET_ADDR_WOL_MAGIC(cmd, rtwvif->wowlan_magic);
760 	FWCMD_SET_ADDR_WAPI(cmd, addr_cam->wapi);
761 	FWCMD_SET_ADDR_SEC_ENT_MODE(cmd, addr_cam->sec_ent_mode);
762 	FWCMD_SET_ADDR_SEC_ENT0_KEYID(cmd, addr_cam->sec_ent_keyid[0]);
763 	FWCMD_SET_ADDR_SEC_ENT1_KEYID(cmd, addr_cam->sec_ent_keyid[1]);
764 	FWCMD_SET_ADDR_SEC_ENT2_KEYID(cmd, addr_cam->sec_ent_keyid[2]);
765 	FWCMD_SET_ADDR_SEC_ENT3_KEYID(cmd, addr_cam->sec_ent_keyid[3]);
766 	FWCMD_SET_ADDR_SEC_ENT4_KEYID(cmd, addr_cam->sec_ent_keyid[4]);
767 	FWCMD_SET_ADDR_SEC_ENT5_KEYID(cmd, addr_cam->sec_ent_keyid[5]);
768 	FWCMD_SET_ADDR_SEC_ENT6_KEYID(cmd, addr_cam->sec_ent_keyid[6]);
769 
770 	FWCMD_SET_ADDR_SEC_ENT_VALID(cmd, addr_cam->sec_cam_map[0] & 0xff);
771 	FWCMD_SET_ADDR_SEC_ENT0(cmd, addr_cam->sec_ent[0]);
772 	FWCMD_SET_ADDR_SEC_ENT1(cmd, addr_cam->sec_ent[1]);
773 	FWCMD_SET_ADDR_SEC_ENT2(cmd, addr_cam->sec_ent[2]);
774 	FWCMD_SET_ADDR_SEC_ENT3(cmd, addr_cam->sec_ent[3]);
775 	FWCMD_SET_ADDR_SEC_ENT4(cmd, addr_cam->sec_ent[4]);
776 	FWCMD_SET_ADDR_SEC_ENT5(cmd, addr_cam->sec_ent[5]);
777 	FWCMD_SET_ADDR_SEC_ENT6(cmd, addr_cam->sec_ent[6]);
778 }
779 
780 void rtw89_cam_fill_dctl_sec_cam_info_v1(struct rtw89_dev *rtwdev,
781 					 struct rtw89_vif *rtwvif,
782 					 struct rtw89_sta *rtwsta,
783 					 struct rtw89_h2c_dctlinfo_ud_v1 *h2c)
784 {
785 	struct rtw89_addr_cam_entry *addr_cam = rtw89_get_addr_cam_of(rtwvif, rtwsta);
786 	struct rtw89_wow_param *rtw_wow = &rtwdev->wow;
787 	u8 *ptk_tx_iv = rtw_wow->key_info.ptk_tx_iv;
788 
789 	h2c->c0 = le32_encode_bits(rtwsta ? rtwsta->mac_id : rtwvif->mac_id,
790 				   DCTLINFO_V1_C0_MACID) |
791 		  le32_encode_bits(1, DCTLINFO_V1_C0_OP);
792 
793 	h2c->w4 = le32_encode_bits(addr_cam->sec_ent_keyid[0],
794 				   DCTLINFO_V1_W4_SEC_ENT0_KEYID) |
795 		  le32_encode_bits(addr_cam->sec_ent_keyid[1],
796 				   DCTLINFO_V1_W4_SEC_ENT1_KEYID) |
797 		  le32_encode_bits(addr_cam->sec_ent_keyid[2],
798 				   DCTLINFO_V1_W4_SEC_ENT2_KEYID) |
799 		  le32_encode_bits(addr_cam->sec_ent_keyid[3],
800 				   DCTLINFO_V1_W4_SEC_ENT3_KEYID) |
801 		  le32_encode_bits(addr_cam->sec_ent_keyid[4],
802 				   DCTLINFO_V1_W4_SEC_ENT4_KEYID) |
803 		  le32_encode_bits(addr_cam->sec_ent_keyid[5],
804 				   DCTLINFO_V1_W4_SEC_ENT5_KEYID) |
805 		  le32_encode_bits(addr_cam->sec_ent_keyid[6],
806 				   DCTLINFO_V1_W4_SEC_ENT6_KEYID);
807 	h2c->m4 = cpu_to_le32(DCTLINFO_V1_W4_SEC_ENT0_KEYID |
808 			      DCTLINFO_V1_W4_SEC_ENT1_KEYID |
809 			      DCTLINFO_V1_W4_SEC_ENT2_KEYID |
810 			      DCTLINFO_V1_W4_SEC_ENT3_KEYID |
811 			      DCTLINFO_V1_W4_SEC_ENT4_KEYID |
812 			      DCTLINFO_V1_W4_SEC_ENT5_KEYID |
813 			      DCTLINFO_V1_W4_SEC_ENT6_KEYID);
814 
815 	h2c->w5 = le32_encode_bits(addr_cam->sec_cam_map[0] & 0xff,
816 				   DCTLINFO_V1_W5_SEC_ENT_VALID) |
817 		  le32_encode_bits(addr_cam->sec_ent[0],
818 				   DCTLINFO_V1_W5_SEC_ENT0) |
819 		  le32_encode_bits(addr_cam->sec_ent[1],
820 				   DCTLINFO_V1_W5_SEC_ENT1) |
821 		  le32_encode_bits(addr_cam->sec_ent[2],
822 				   DCTLINFO_V1_W5_SEC_ENT2);
823 	h2c->m5 = cpu_to_le32(DCTLINFO_V1_W5_SEC_ENT_VALID |
824 			      DCTLINFO_V1_W5_SEC_ENT0      |
825 			      DCTLINFO_V1_W5_SEC_ENT1      |
826 			      DCTLINFO_V1_W5_SEC_ENT2);
827 
828 	h2c->w6 = le32_encode_bits(addr_cam->sec_ent[3],
829 				   DCTLINFO_V1_W6_SEC_ENT3) |
830 		  le32_encode_bits(addr_cam->sec_ent[4],
831 				   DCTLINFO_V1_W6_SEC_ENT4) |
832 		  le32_encode_bits(addr_cam->sec_ent[5],
833 				   DCTLINFO_V1_W6_SEC_ENT5) |
834 		  le32_encode_bits(addr_cam->sec_ent[6],
835 				   DCTLINFO_V1_W6_SEC_ENT6);
836 	h2c->m6 = cpu_to_le32(DCTLINFO_V1_W6_SEC_ENT3 |
837 			      DCTLINFO_V1_W6_SEC_ENT4 |
838 			      DCTLINFO_V1_W6_SEC_ENT5 |
839 			      DCTLINFO_V1_W6_SEC_ENT6);
840 
841 	if (rtw_wow->ptk_alg) {
842 		h2c->w0 = le32_encode_bits(ptk_tx_iv[0] | ptk_tx_iv[1] << 8,
843 					   DCTLINFO_V1_W0_AES_IV_L);
844 		h2c->m0 = cpu_to_le32(DCTLINFO_V1_W0_AES_IV_L);
845 
846 		h2c->w1 = le32_encode_bits(ptk_tx_iv[4]       |
847 					   ptk_tx_iv[5] << 8  |
848 					   ptk_tx_iv[6] << 16 |
849 					   ptk_tx_iv[7] << 24,
850 					   DCTLINFO_V1_W1_AES_IV_H);
851 		h2c->m1 = cpu_to_le32(DCTLINFO_V1_W1_AES_IV_H);
852 
853 		h2c->w4 |= le32_encode_bits(rtw_wow->ptk_keyidx,
854 					    DCTLINFO_V1_W4_SEC_KEY_ID);
855 		h2c->m4 |= cpu_to_le32(DCTLINFO_V1_W4_SEC_KEY_ID);
856 	}
857 }
858 
859 void rtw89_cam_fill_dctl_sec_cam_info_v2(struct rtw89_dev *rtwdev,
860 					 struct rtw89_vif *rtwvif,
861 					 struct rtw89_sta *rtwsta,
862 					 struct rtw89_h2c_dctlinfo_ud_v2 *h2c)
863 {
864 	struct rtw89_addr_cam_entry *addr_cam = rtw89_get_addr_cam_of(rtwvif, rtwsta);
865 	struct rtw89_wow_param *rtw_wow = &rtwdev->wow;
866 	u8 *ptk_tx_iv = rtw_wow->key_info.ptk_tx_iv;
867 
868 	h2c->c0 = le32_encode_bits(rtwsta ? rtwsta->mac_id : rtwvif->mac_id,
869 				   DCTLINFO_V2_C0_MACID) |
870 		  le32_encode_bits(1, DCTLINFO_V2_C0_OP);
871 
872 	h2c->w4 = le32_encode_bits(addr_cam->sec_ent_keyid[0],
873 				   DCTLINFO_V2_W4_SEC_ENT0_KEYID) |
874 		  le32_encode_bits(addr_cam->sec_ent_keyid[1],
875 				   DCTLINFO_V2_W4_SEC_ENT1_KEYID) |
876 		  le32_encode_bits(addr_cam->sec_ent_keyid[2],
877 				   DCTLINFO_V2_W4_SEC_ENT2_KEYID) |
878 		  le32_encode_bits(addr_cam->sec_ent_keyid[3],
879 				   DCTLINFO_V2_W4_SEC_ENT3_KEYID) |
880 		  le32_encode_bits(addr_cam->sec_ent_keyid[4],
881 				   DCTLINFO_V2_W4_SEC_ENT4_KEYID) |
882 		  le32_encode_bits(addr_cam->sec_ent_keyid[5],
883 				   DCTLINFO_V2_W4_SEC_ENT5_KEYID) |
884 		  le32_encode_bits(addr_cam->sec_ent_keyid[6],
885 				   DCTLINFO_V2_W4_SEC_ENT6_KEYID);
886 	h2c->m4 = cpu_to_le32(DCTLINFO_V2_W4_SEC_ENT0_KEYID |
887 			      DCTLINFO_V2_W4_SEC_ENT1_KEYID |
888 			      DCTLINFO_V2_W4_SEC_ENT2_KEYID |
889 			      DCTLINFO_V2_W4_SEC_ENT3_KEYID |
890 			      DCTLINFO_V2_W4_SEC_ENT4_KEYID |
891 			      DCTLINFO_V2_W4_SEC_ENT5_KEYID |
892 			      DCTLINFO_V2_W4_SEC_ENT6_KEYID);
893 
894 	h2c->w5 = le32_encode_bits(addr_cam->sec_cam_map[0],
895 				   DCTLINFO_V2_W5_SEC_ENT_VALID_V1) |
896 		  le32_encode_bits(addr_cam->sec_ent[0],
897 				   DCTLINFO_V2_W5_SEC_ENT0_V1);
898 	h2c->m5 = cpu_to_le32(DCTLINFO_V2_W5_SEC_ENT_VALID_V1 |
899 			      DCTLINFO_V2_W5_SEC_ENT0_V1);
900 
901 	h2c->w6 = le32_encode_bits(addr_cam->sec_ent[1],
902 				   DCTLINFO_V2_W6_SEC_ENT1_V1) |
903 		  le32_encode_bits(addr_cam->sec_ent[2],
904 				   DCTLINFO_V2_W6_SEC_ENT2_V1) |
905 		  le32_encode_bits(addr_cam->sec_ent[3],
906 				   DCTLINFO_V2_W6_SEC_ENT3_V1) |
907 		  le32_encode_bits(addr_cam->sec_ent[4],
908 				   DCTLINFO_V2_W6_SEC_ENT4_V1);
909 	h2c->m6 = cpu_to_le32(DCTLINFO_V2_W6_SEC_ENT1_V1 |
910 			      DCTLINFO_V2_W6_SEC_ENT2_V1 |
911 			      DCTLINFO_V2_W6_SEC_ENT3_V1 |
912 			      DCTLINFO_V2_W6_SEC_ENT4_V1);
913 
914 	h2c->w7 = le32_encode_bits(addr_cam->sec_ent[5],
915 				   DCTLINFO_V2_W7_SEC_ENT5_V1) |
916 		  le32_encode_bits(addr_cam->sec_ent[6],
917 				   DCTLINFO_V2_W7_SEC_ENT6_V1);
918 	h2c->m7 = cpu_to_le32(DCTLINFO_V2_W7_SEC_ENT5_V1 |
919 			      DCTLINFO_V2_W7_SEC_ENT6_V1);
920 
921 	if (rtw_wow->ptk_alg) {
922 		h2c->w0 = le32_encode_bits(ptk_tx_iv[0] | ptk_tx_iv[1] << 8,
923 					   DCTLINFO_V2_W0_AES_IV_L);
924 		h2c->m0 = cpu_to_le32(DCTLINFO_V2_W0_AES_IV_L);
925 
926 		h2c->w1 = le32_encode_bits(ptk_tx_iv[4] |
927 					   ptk_tx_iv[5] << 8 |
928 					   ptk_tx_iv[6] << 16 |
929 					   ptk_tx_iv[7] << 24,
930 					   DCTLINFO_V2_W1_AES_IV_H);
931 		h2c->m1 = cpu_to_le32(DCTLINFO_V2_W1_AES_IV_H);
932 
933 		h2c->w4 |= le32_encode_bits(rtw_wow->ptk_keyidx,
934 					    DCTLINFO_V2_W4_SEC_KEY_ID);
935 		h2c->m4 |= cpu_to_le32(DCTLINFO_V2_W4_SEC_KEY_ID);
936 	}
937 }
938