GNU Linux-libre 4.14.266-gnu1
[releases.git] / drivers / net / wireless / quantenna / qtnfmac / commands.c
1 /*
2  * Copyright (c) 2015-2016 Quantenna Communications, Inc.
3  *
4  * This program is free software; you can redistribute it and/or
5  * modify it under the terms of the GNU General Public License
6  * as published by the Free Software Foundation; either version 2
7  * of the License, or (at your option) any later version.
8  *
9  * This program is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  *
14  */
15
16 #include <linux/types.h>
17 #include <linux/skbuff.h>
18
19 #include "cfg80211.h"
20 #include "core.h"
21 #include "qlink.h"
22 #include "qlink_util.h"
23 #include "bus.h"
24 #include "commands.h"
25
26 static int qtnf_cmd_check_reply_header(const struct qlink_resp *resp,
27                                        u16 cmd_id, u8 mac_id, u8 vif_id,
28                                        size_t resp_size)
29 {
30         if (unlikely(le16_to_cpu(resp->cmd_id) != cmd_id)) {
31                 pr_warn("VIF%u.%u CMD%x: bad cmd_id in response: 0x%.4X\n",
32                         mac_id, vif_id, cmd_id, le16_to_cpu(resp->cmd_id));
33                 return -EINVAL;
34         }
35
36         if (unlikely(resp->macid != mac_id)) {
37                 pr_warn("VIF%u.%u CMD%x: bad MAC in response: %u\n",
38                         mac_id, vif_id, cmd_id, resp->macid);
39                 return -EINVAL;
40         }
41
42         if (unlikely(resp->vifid != vif_id)) {
43                 pr_warn("VIF%u.%u CMD%x: bad VIF in response: %u\n",
44                         mac_id, vif_id, cmd_id, resp->vifid);
45                 return -EINVAL;
46         }
47
48         if (unlikely(le16_to_cpu(resp->mhdr.len) < resp_size)) {
49                 pr_warn("VIF%u.%u CMD%x: bad response size %u < %zu\n",
50                         mac_id, vif_id, cmd_id,
51                         le16_to_cpu(resp->mhdr.len), resp_size);
52                 return -ENOSPC;
53         }
54
55         return 0;
56 }
57
58 static int qtnf_cmd_send_with_reply(struct qtnf_bus *bus,
59                                     struct sk_buff *cmd_skb,
60                                     struct sk_buff **response_skb,
61                                     u16 *result_code,
62                                     size_t const_resp_size,
63                                     size_t *var_resp_size)
64 {
65         struct qlink_cmd *cmd;
66         const struct qlink_resp *resp;
67         struct sk_buff *resp_skb = NULL;
68         u16 cmd_id;
69         u8 mac_id, vif_id;
70         int ret;
71
72         cmd = (struct qlink_cmd *)cmd_skb->data;
73         cmd_id = le16_to_cpu(cmd->cmd_id);
74         mac_id = cmd->macid;
75         vif_id = cmd->vifid;
76         cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
77
78         if (unlikely(bus->fw_state != QTNF_FW_STATE_ACTIVE &&
79                      le16_to_cpu(cmd->cmd_id) != QLINK_CMD_FW_INIT)) {
80                 pr_warn("VIF%u.%u: drop cmd 0x%.4X in fw state %d\n",
81                         mac_id, vif_id, le16_to_cpu(cmd->cmd_id),
82                         bus->fw_state);
83                 return -ENODEV;
84         }
85
86         pr_debug("VIF%u.%u cmd=0x%.4X\n", mac_id, vif_id,
87                  le16_to_cpu(cmd->cmd_id));
88
89         ret = qtnf_trans_send_cmd_with_resp(bus, cmd_skb, &resp_skb);
90
91         if (unlikely(ret))
92                 goto out;
93
94         resp = (const struct qlink_resp *)resp_skb->data;
95         ret = qtnf_cmd_check_reply_header(resp, cmd_id, mac_id, vif_id,
96                                           const_resp_size);
97
98         if (unlikely(ret))
99                 goto out;
100
101         if (likely(result_code))
102                 *result_code = le16_to_cpu(resp->result);
103
104         /* Return length of variable part of response */
105         if (response_skb && var_resp_size)
106                 *var_resp_size = le16_to_cpu(resp->mhdr.len) - const_resp_size;
107
108 out:
109         if (response_skb)
110                 *response_skb = resp_skb;
111         else
112                 consume_skb(resp_skb);
113
114         return ret;
115 }
116
117 static inline int qtnf_cmd_send(struct qtnf_bus *bus,
118                                 struct sk_buff *cmd_skb,
119                                 u16 *result_code)
120 {
121         return qtnf_cmd_send_with_reply(bus, cmd_skb, NULL, result_code,
122                                         sizeof(struct qlink_resp), NULL);
123 }
124
125 static struct sk_buff *qtnf_cmd_alloc_new_cmdskb(u8 macid, u8 vifid, u16 cmd_no,
126                                                  size_t cmd_size)
127 {
128         struct qlink_cmd *cmd;
129         struct sk_buff *cmd_skb;
130
131         cmd_skb = __dev_alloc_skb(sizeof(*cmd) +
132                                   QTNF_MAX_CMD_BUF_SIZE, GFP_KERNEL);
133         if (unlikely(!cmd_skb)) {
134                 pr_err("VIF%u.%u CMD %u: alloc failed\n", macid, vifid, cmd_no);
135                 return NULL;
136         }
137
138         skb_put_zero(cmd_skb, cmd_size);
139
140         cmd = (struct qlink_cmd *)cmd_skb->data;
141         cmd->mhdr.len = cpu_to_le16(cmd_skb->len);
142         cmd->mhdr.type = cpu_to_le16(QLINK_MSG_TYPE_CMD);
143         cmd->cmd_id = cpu_to_le16(cmd_no);
144         cmd->macid = macid;
145         cmd->vifid = vifid;
146
147         return cmd_skb;
148 }
149
150 int qtnf_cmd_send_start_ap(struct qtnf_vif *vif)
151 {
152         struct sk_buff *cmd_skb;
153         u16 res_code = QLINK_CMD_RESULT_OK;
154         int ret;
155
156         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
157                                             QLINK_CMD_START_AP,
158                                             sizeof(struct qlink_cmd));
159         if (unlikely(!cmd_skb))
160                 return -ENOMEM;
161
162         qtnf_bus_lock(vif->mac->bus);
163
164         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
165
166         if (unlikely(ret))
167                 goto out;
168
169         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
170                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
171                        vif->vifid, res_code);
172                 ret = -EFAULT;
173                 goto out;
174         }
175
176         vif->bss_status |= QTNF_STATE_AP_START;
177         netif_carrier_on(vif->netdev);
178
179 out:
180         qtnf_bus_unlock(vif->mac->bus);
181         return ret;
182 }
183
184 int qtnf_cmd_send_config_ap(struct qtnf_vif *vif)
185 {
186         struct sk_buff *cmd_skb;
187         struct qtnf_bss_config *bss_cfg = &vif->bss_cfg;
188         struct cfg80211_chan_def *chandef = &vif->mac->chandef;
189         struct qlink_tlv_channel *qchan;
190         struct qlink_auth_encr aen;
191         u16 res_code = QLINK_CMD_RESULT_OK;
192         int ret;
193         int i;
194
195         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
196                                             QLINK_CMD_CONFIG_AP,
197                                             sizeof(struct qlink_cmd));
198         if (unlikely(!cmd_skb))
199                 return -ENOMEM;
200
201         qtnf_bus_lock(vif->mac->bus);
202
203         qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, bss_cfg->ssid,
204                                  bss_cfg->ssid_len);
205         qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_BCN_PERIOD,
206                                  bss_cfg->bcn_period);
207         qtnf_cmd_skb_put_tlv_u8(cmd_skb, QTN_TLV_ID_DTIM, bss_cfg->dtim);
208
209         qchan = skb_put_zero(cmd_skb, sizeof(*qchan));
210         qchan->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANNEL);
211         qchan->hdr.len = cpu_to_le16(sizeof(*qchan) -
212                         sizeof(struct qlink_tlv_hdr));
213         qchan->hw_value = cpu_to_le16(
214                 ieee80211_frequency_to_channel(chandef->chan->center_freq));
215
216         memset(&aen, 0, sizeof(aen));
217         aen.auth_type = bss_cfg->auth_type;
218         aen.privacy = !!bss_cfg->privacy;
219         aen.mfp = bss_cfg->mfp;
220         aen.wpa_versions = cpu_to_le32(bss_cfg->crypto.wpa_versions);
221         aen.cipher_group = cpu_to_le32(bss_cfg->crypto.cipher_group);
222         aen.n_ciphers_pairwise = cpu_to_le32(
223                                         bss_cfg->crypto.n_ciphers_pairwise);
224         for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
225                 aen.ciphers_pairwise[i] = cpu_to_le32(
226                                         bss_cfg->crypto.ciphers_pairwise[i]);
227         aen.n_akm_suites = cpu_to_le32(
228                                         bss_cfg->crypto.n_akm_suites);
229         for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
230                 aen.akm_suites[i] = cpu_to_le32(
231                                         bss_cfg->crypto.akm_suites[i]);
232         aen.control_port = bss_cfg->crypto.control_port;
233         aen.control_port_no_encrypt =
234                         bss_cfg->crypto.control_port_no_encrypt;
235         aen.control_port_ethertype = cpu_to_le16(be16_to_cpu(
236                                 bss_cfg->crypto.control_port_ethertype));
237
238         qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_CRYPTO, (u8 *)&aen,
239                                  sizeof(aen));
240
241         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
242
243         if (unlikely(ret))
244                 goto out;
245
246         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
247                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
248                        vif->vifid, res_code);
249                 ret = -EFAULT;
250                 goto out;
251         }
252
253         vif->bss_status |= QTNF_STATE_AP_CONFIG;
254
255 out:
256         qtnf_bus_unlock(vif->mac->bus);
257         return ret;
258 }
259
260 int qtnf_cmd_send_stop_ap(struct qtnf_vif *vif)
261 {
262         struct sk_buff *cmd_skb;
263         u16 res_code = QLINK_CMD_RESULT_OK;
264         int ret;
265
266         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
267                                             QLINK_CMD_STOP_AP,
268                                             sizeof(struct qlink_cmd));
269         if (unlikely(!cmd_skb))
270                 return -ENOMEM;
271
272         qtnf_bus_lock(vif->mac->bus);
273
274         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
275
276         if (unlikely(ret))
277                 goto out;
278
279         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
280                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
281                        vif->vifid, res_code);
282                 ret = -EFAULT;
283                 goto out;
284         }
285
286         vif->bss_status &= ~QTNF_STATE_AP_START;
287         vif->bss_status &= ~QTNF_STATE_AP_CONFIG;
288
289         netif_carrier_off(vif->netdev);
290
291 out:
292         qtnf_bus_unlock(vif->mac->bus);
293         return ret;
294 }
295
296 int qtnf_cmd_send_register_mgmt(struct qtnf_vif *vif, u16 frame_type, bool reg)
297 {
298         struct sk_buff *cmd_skb;
299         struct qlink_cmd_mgmt_frame_register *cmd;
300         u16 res_code = QLINK_CMD_RESULT_OK;
301         int ret;
302
303         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
304                                             QLINK_CMD_REGISTER_MGMT,
305                                             sizeof(*cmd));
306         if (unlikely(!cmd_skb))
307                 return -ENOMEM;
308
309         qtnf_bus_lock(vif->mac->bus);
310
311         cmd = (struct qlink_cmd_mgmt_frame_register *)cmd_skb->data;
312         cmd->frame_type = cpu_to_le16(frame_type);
313         cmd->do_register = reg;
314
315         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
316
317         if (unlikely(ret))
318                 goto out;
319
320         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
321                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
322                        vif->vifid, res_code);
323                 ret = -EFAULT;
324                 goto out;
325         }
326
327 out:
328         qtnf_bus_unlock(vif->mac->bus);
329         return ret;
330 }
331
332 int qtnf_cmd_send_mgmt_frame(struct qtnf_vif *vif, u32 cookie, u16 flags,
333                              u16 freq, const u8 *buf, size_t len)
334 {
335         struct sk_buff *cmd_skb;
336         struct qlink_cmd_mgmt_frame_tx *cmd;
337         u16 res_code = QLINK_CMD_RESULT_OK;
338         int ret;
339
340         if (sizeof(*cmd) + len > QTNF_MAX_CMD_BUF_SIZE) {
341                 pr_warn("VIF%u.%u: frame is too big: %zu\n", vif->mac->macid,
342                         vif->vifid, len);
343                 return -E2BIG;
344         }
345
346         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
347                                             QLINK_CMD_SEND_MGMT_FRAME,
348                                             sizeof(*cmd));
349         if (unlikely(!cmd_skb))
350                 return -ENOMEM;
351
352         qtnf_bus_lock(vif->mac->bus);
353
354         cmd = (struct qlink_cmd_mgmt_frame_tx *)cmd_skb->data;
355         cmd->cookie = cpu_to_le32(cookie);
356         cmd->freq = cpu_to_le16(freq);
357         cmd->flags = cpu_to_le16(flags);
358
359         if (len && buf)
360                 qtnf_cmd_skb_put_buffer(cmd_skb, buf, len);
361
362         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
363
364         if (unlikely(ret))
365                 goto out;
366
367         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
368                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
369                        vif->vifid, res_code);
370                 ret = -EFAULT;
371                 goto out;
372         }
373
374 out:
375         qtnf_bus_unlock(vif->mac->bus);
376         return ret;
377 }
378
379 int qtnf_cmd_send_mgmt_set_appie(struct qtnf_vif *vif, u8 frame_type,
380                                  const u8 *buf, size_t len)
381 {
382         struct sk_buff *cmd_skb;
383         struct qlink_cmd_mgmt_append_ie *cmd;
384         u16 res_code = QLINK_CMD_RESULT_OK;
385         int ret;
386
387         if (sizeof(*cmd) + len > QTNF_MAX_CMD_BUF_SIZE) {
388                 pr_warn("VIF%u.%u: %u frame is too big: %zu\n", vif->mac->macid,
389                         vif->vifid, frame_type, len);
390                 return -E2BIG;
391         }
392
393         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
394                                             QLINK_CMD_MGMT_SET_APPIE,
395                                             sizeof(*cmd));
396         if (unlikely(!cmd_skb))
397                 return -ENOMEM;
398
399         qtnf_bus_lock(vif->mac->bus);
400
401         cmd = (struct qlink_cmd_mgmt_append_ie *)cmd_skb->data;
402         cmd->type = frame_type;
403         cmd->flags = 0;
404
405         /* If len == 0 then IE buf for specified frame type
406          * should be cleared on EP.
407          */
408         if (len && buf)
409                 qtnf_cmd_skb_put_buffer(cmd_skb, buf, len);
410
411         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
412
413         if (unlikely(ret))
414                 goto out;
415
416         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
417                 pr_err("VIF%u.%u frame %u: CMD failed: %u\n", vif->mac->macid,
418                        vif->vifid, frame_type, res_code);
419                 ret = -EFAULT;
420                 goto out;
421         }
422
423 out:
424         qtnf_bus_unlock(vif->mac->bus);
425         return ret;
426 }
427
428 static void
429 qtnf_sta_info_parse_basic_counters(struct station_info *sinfo,
430                 const struct qlink_sta_stat_basic_counters *counters)
431 {
432         sinfo->filled |= BIT(NL80211_STA_INFO_RX_BYTES) |
433                          BIT(NL80211_STA_INFO_TX_BYTES);
434         sinfo->rx_bytes = get_unaligned_le64(&counters->rx_bytes);
435         sinfo->tx_bytes = get_unaligned_le64(&counters->tx_bytes);
436
437         sinfo->filled |= BIT(NL80211_STA_INFO_RX_PACKETS) |
438                          BIT(NL80211_STA_INFO_TX_PACKETS) |
439                          BIT(NL80211_STA_INFO_BEACON_RX);
440         sinfo->rx_packets = get_unaligned_le32(&counters->rx_packets);
441         sinfo->tx_packets = get_unaligned_le32(&counters->tx_packets);
442         sinfo->rx_beacon = get_unaligned_le64(&counters->rx_beacons);
443
444         sinfo->filled |= BIT(NL80211_STA_INFO_RX_DROP_MISC) |
445                          BIT(NL80211_STA_INFO_TX_FAILED);
446         sinfo->rx_dropped_misc = get_unaligned_le32(&counters->rx_dropped);
447         sinfo->tx_failed = get_unaligned_le32(&counters->tx_failed);
448 }
449
450 static void
451 qtnf_sta_info_parse_rate(struct rate_info *rate_dst,
452                          const struct  qlink_sta_info_rate *rate_src)
453 {
454         rate_dst->legacy = get_unaligned_le16(&rate_src->rate) * 10;
455
456         rate_dst->mcs = rate_src->mcs;
457         rate_dst->nss = rate_src->nss;
458         rate_dst->flags = 0;
459
460         switch (rate_src->bw) {
461         case QLINK_STA_INFO_RATE_BW_5:
462                 rate_dst->bw = RATE_INFO_BW_5;
463                 break;
464         case QLINK_STA_INFO_RATE_BW_10:
465                 rate_dst->bw = RATE_INFO_BW_10;
466                 break;
467         case QLINK_STA_INFO_RATE_BW_20:
468                 rate_dst->bw = RATE_INFO_BW_20;
469                 break;
470         case QLINK_STA_INFO_RATE_BW_40:
471                 rate_dst->bw = RATE_INFO_BW_40;
472                 break;
473         case QLINK_STA_INFO_RATE_BW_80:
474                 rate_dst->bw = RATE_INFO_BW_80;
475                 break;
476         case QLINK_STA_INFO_RATE_BW_160:
477                 rate_dst->bw = RATE_INFO_BW_160;
478                 break;
479         default:
480                 rate_dst->bw = 0;
481                 break;
482         }
483
484         if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_HT_MCS)
485                 rate_dst->flags |= RATE_INFO_FLAGS_MCS;
486         else if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_VHT_MCS)
487                 rate_dst->flags |= RATE_INFO_FLAGS_VHT_MCS;
488
489         if (rate_src->flags & QLINK_STA_INFO_RATE_FLAG_SHORT_GI)
490                 rate_dst->flags |= RATE_INFO_FLAGS_SHORT_GI;
491 }
492
493 static void
494 qtnf_sta_info_parse_flags(struct nl80211_sta_flag_update *dst,
495                           const struct qlink_sta_info_state *src)
496 {
497         u32 mask, value;
498
499         dst->mask = 0;
500         dst->set = 0;
501
502         mask = le32_to_cpu(src->mask);
503         value = le32_to_cpu(src->value);
504
505         if (mask & QLINK_STA_FLAG_AUTHORIZED) {
506                 dst->mask |= BIT(NL80211_STA_FLAG_AUTHORIZED);
507                 if (value & QLINK_STA_FLAG_AUTHORIZED)
508                         dst->set |= BIT(NL80211_STA_FLAG_AUTHORIZED);
509         }
510
511         if (mask & QLINK_STA_FLAG_SHORT_PREAMBLE) {
512                 dst->mask |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
513                 if (value & QLINK_STA_FLAG_SHORT_PREAMBLE)
514                         dst->set |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
515         }
516
517         if (mask & QLINK_STA_FLAG_WME) {
518                 dst->mask |= BIT(NL80211_STA_FLAG_WME);
519                 if (value & QLINK_STA_FLAG_WME)
520                         dst->set |= BIT(NL80211_STA_FLAG_WME);
521         }
522
523         if (mask & QLINK_STA_FLAG_MFP) {
524                 dst->mask |= BIT(NL80211_STA_FLAG_MFP);
525                 if (value & QLINK_STA_FLAG_MFP)
526                         dst->set |= BIT(NL80211_STA_FLAG_MFP);
527         }
528
529         if (mask & QLINK_STA_FLAG_AUTHENTICATED) {
530                 dst->mask |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
531                 if (value & QLINK_STA_FLAG_AUTHENTICATED)
532                         dst->set |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
533         }
534
535         if (mask & QLINK_STA_FLAG_TDLS_PEER) {
536                 dst->mask |= BIT(NL80211_STA_FLAG_TDLS_PEER);
537                 if (value & QLINK_STA_FLAG_TDLS_PEER)
538                         dst->set |= BIT(NL80211_STA_FLAG_TDLS_PEER);
539         }
540
541         if (mask & QLINK_STA_FLAG_ASSOCIATED) {
542                 dst->mask |= BIT(NL80211_STA_FLAG_ASSOCIATED);
543                 if (value & QLINK_STA_FLAG_ASSOCIATED)
544                         dst->set |= BIT(NL80211_STA_FLAG_ASSOCIATED);
545         }
546 }
547
548 static void
549 qtnf_sta_info_parse_generic_info(struct station_info *sinfo,
550                                  const struct qlink_sta_info_generic *info)
551 {
552         sinfo->filled |= BIT(NL80211_STA_INFO_CONNECTED_TIME) |
553                          BIT(NL80211_STA_INFO_INACTIVE_TIME);
554         sinfo->connected_time = get_unaligned_le32(&info->connected_time);
555         sinfo->inactive_time = get_unaligned_le32(&info->inactive_time);
556
557         sinfo->filled |= BIT(NL80211_STA_INFO_SIGNAL) |
558                          BIT(NL80211_STA_INFO_SIGNAL_AVG);
559         sinfo->signal = info->rssi - 120;
560         sinfo->signal_avg = info->rssi_avg - QLINK_RSSI_OFFSET;
561
562         if (info->rx_rate.rate) {
563                 sinfo->filled |= BIT(NL80211_STA_INFO_RX_BITRATE);
564                 qtnf_sta_info_parse_rate(&sinfo->rxrate, &info->rx_rate);
565         }
566
567         if (info->tx_rate.rate) {
568                 sinfo->filled |= BIT(NL80211_STA_INFO_TX_BITRATE);
569                 qtnf_sta_info_parse_rate(&sinfo->txrate, &info->tx_rate);
570         }
571
572         sinfo->filled |= BIT(NL80211_STA_INFO_STA_FLAGS);
573         qtnf_sta_info_parse_flags(&sinfo->sta_flags, &info->state);
574 }
575
576 static int qtnf_cmd_sta_info_parse(struct station_info *sinfo,
577                                    const u8 *payload, size_t payload_size)
578 {
579         const struct qlink_sta_stat_basic_counters *counters;
580         const struct qlink_sta_info_generic *sta_info;
581         u16 tlv_type;
582         u16 tlv_value_len;
583         size_t tlv_full_len;
584         const struct qlink_tlv_hdr *tlv;
585
586         sinfo->filled = 0;
587
588         tlv = (const struct qlink_tlv_hdr *)payload;
589         while (payload_size >= sizeof(struct qlink_tlv_hdr)) {
590                 tlv_type = le16_to_cpu(tlv->type);
591                 tlv_value_len = le16_to_cpu(tlv->len);
592                 tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
593                 if (tlv_full_len > payload_size) {
594                         pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
595                                 tlv_type, tlv_value_len);
596                         return -EINVAL;
597                 }
598                 switch (tlv_type) {
599                 case QTN_TLV_ID_STA_BASIC_COUNTERS:
600                         if (unlikely(tlv_value_len < sizeof(*counters))) {
601                                 pr_err("invalid TLV size %.4X: %u\n",
602                                        tlv_type, tlv_value_len);
603                                 break;
604                         }
605
606                         counters = (void *)tlv->val;
607                         qtnf_sta_info_parse_basic_counters(sinfo, counters);
608                         break;
609                 case QTN_TLV_ID_STA_GENERIC_INFO:
610                         if (unlikely(tlv_value_len < sizeof(*sta_info)))
611                                 break;
612
613                         sta_info = (void *)tlv->val;
614                         qtnf_sta_info_parse_generic_info(sinfo, sta_info);
615                         break;
616                 default:
617                         pr_warn("unexpected TLV type: %.4X\n", tlv_type);
618                         break;
619                 }
620                 payload_size -= tlv_full_len;
621                 tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
622         }
623
624         if (payload_size) {
625                 pr_warn("malformed TLV buf; bytes left: %zu\n", payload_size);
626                 return -EINVAL;
627         }
628
629         return 0;
630 }
631
632 int qtnf_cmd_get_sta_info(struct qtnf_vif *vif, const u8 *sta_mac,
633                           struct station_info *sinfo)
634 {
635         struct sk_buff *cmd_skb, *resp_skb = NULL;
636         struct qlink_cmd_get_sta_info *cmd;
637         const struct qlink_resp_get_sta_info *resp;
638         size_t var_resp_len;
639         u16 res_code = QLINK_CMD_RESULT_OK;
640         int ret = 0;
641
642         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
643                                             QLINK_CMD_GET_STA_INFO,
644                                             sizeof(*cmd));
645
646         if (unlikely(!cmd_skb))
647                 return -ENOMEM;
648
649         qtnf_bus_lock(vif->mac->bus);
650
651         cmd = (struct qlink_cmd_get_sta_info *)cmd_skb->data;
652         ether_addr_copy(cmd->sta_addr, sta_mac);
653
654         ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
655                                        &res_code, sizeof(*resp),
656                                        &var_resp_len);
657
658         if (unlikely(ret))
659                 goto out;
660
661         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
662                 switch (res_code) {
663                 case QLINK_CMD_RESULT_ENOTFOUND:
664                         pr_warn("VIF%u.%u: %pM STA not found\n",
665                                 vif->mac->macid, vif->vifid, sta_mac);
666                         ret = -ENOENT;
667                         break;
668                 default:
669                         pr_err("VIF%u.%u: can't get info for %pM: %u\n",
670                                vif->mac->macid, vif->vifid, sta_mac, res_code);
671                         ret = -EFAULT;
672                         break;
673                 }
674                 goto out;
675         }
676
677         resp = (const struct qlink_resp_get_sta_info *)resp_skb->data;
678
679         if (unlikely(!ether_addr_equal(sta_mac, resp->sta_addr))) {
680                 pr_err("VIF%u.%u: wrong mac in reply: %pM != %pM\n",
681                        vif->mac->macid, vif->vifid, resp->sta_addr, sta_mac);
682                 ret = -EINVAL;
683                 goto out;
684         }
685
686         ret = qtnf_cmd_sta_info_parse(sinfo, resp->info, var_resp_len);
687
688 out:
689         qtnf_bus_unlock(vif->mac->bus);
690         consume_skb(resp_skb);
691
692         return ret;
693 }
694
695 static int qtnf_cmd_send_add_change_intf(struct qtnf_vif *vif,
696                                          enum nl80211_iftype iftype,
697                                          u8 *mac_addr,
698                                          enum qlink_cmd_type cmd_type)
699 {
700         struct sk_buff *cmd_skb, *resp_skb = NULL;
701         struct qlink_cmd_manage_intf *cmd;
702         const struct qlink_resp_manage_intf *resp;
703         u16 res_code = QLINK_CMD_RESULT_OK;
704         int ret = 0;
705
706         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
707                                             cmd_type,
708                                             sizeof(*cmd));
709         if (unlikely(!cmd_skb))
710                 return -ENOMEM;
711
712         qtnf_bus_lock(vif->mac->bus);
713
714         cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
715
716         switch (iftype) {
717         case NL80211_IFTYPE_AP:
718                 cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
719                 break;
720         case NL80211_IFTYPE_STATION:
721                 cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
722                 break;
723         default:
724                 pr_err("VIF%u.%u: unsupported type %d\n", vif->mac->macid,
725                        vif->vifid, iftype);
726                 ret = -EINVAL;
727                 goto out;
728         }
729
730         if (mac_addr)
731                 ether_addr_copy(cmd->intf_info.mac_addr, mac_addr);
732         else
733                 eth_zero_addr(cmd->intf_info.mac_addr);
734
735         ret = qtnf_cmd_send_with_reply(vif->mac->bus, cmd_skb, &resp_skb,
736                                        &res_code, sizeof(*resp), NULL);
737
738         if (unlikely(ret))
739                 goto out;
740
741         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
742                 pr_err("VIF%u.%u: CMD %d failed: %u\n", vif->mac->macid,
743                        vif->vifid, cmd_type, res_code);
744                 ret = -EFAULT;
745                 goto out;
746         }
747
748         resp = (const struct qlink_resp_manage_intf *)resp_skb->data;
749         ether_addr_copy(vif->mac_addr, resp->intf_info.mac_addr);
750
751 out:
752         qtnf_bus_unlock(vif->mac->bus);
753         consume_skb(resp_skb);
754
755         return ret;
756 }
757
758 int qtnf_cmd_send_add_intf(struct qtnf_vif *vif,
759                            enum nl80211_iftype iftype, u8 *mac_addr)
760 {
761         return qtnf_cmd_send_add_change_intf(vif, iftype, mac_addr,
762                         QLINK_CMD_ADD_INTF);
763 }
764
765 int qtnf_cmd_send_change_intf_type(struct qtnf_vif *vif,
766                                    enum nl80211_iftype iftype, u8 *mac_addr)
767 {
768         return qtnf_cmd_send_add_change_intf(vif, iftype, mac_addr,
769                                              QLINK_CMD_CHANGE_INTF);
770 }
771
772 int qtnf_cmd_send_del_intf(struct qtnf_vif *vif)
773 {
774         struct sk_buff *cmd_skb;
775         struct qlink_cmd_manage_intf *cmd;
776         u16 res_code = QLINK_CMD_RESULT_OK;
777         int ret = 0;
778
779         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
780                                             QLINK_CMD_DEL_INTF,
781                                             sizeof(*cmd));
782         if (unlikely(!cmd_skb))
783                 return -ENOMEM;
784
785         qtnf_bus_lock(vif->mac->bus);
786
787         cmd = (struct qlink_cmd_manage_intf *)cmd_skb->data;
788
789         switch (vif->wdev.iftype) {
790         case NL80211_IFTYPE_AP:
791                 cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_AP);
792                 break;
793         case NL80211_IFTYPE_STATION:
794                 cmd->intf_info.if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
795                 break;
796         default:
797                 pr_warn("VIF%u.%u: unsupported iftype %d\n", vif->mac->macid,
798                         vif->vifid, vif->wdev.iftype);
799                 dev_kfree_skb(cmd_skb);
800                 ret = -EINVAL;
801                 goto out;
802         }
803
804         eth_zero_addr(cmd->intf_info.mac_addr);
805
806         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
807
808         if (unlikely(ret))
809                 goto out;
810
811         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
812                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
813                        vif->vifid, res_code);
814                 ret = -EFAULT;
815                 goto out;
816         }
817
818 out:
819         qtnf_bus_unlock(vif->mac->bus);
820         return ret;
821 }
822
823 static u32 qtnf_cmd_resp_reg_rule_flags_parse(u32 qflags)
824 {
825         u32 flags = 0;
826
827         if (qflags & QLINK_RRF_NO_OFDM)
828                 flags |= NL80211_RRF_NO_OFDM;
829
830         if (qflags & QLINK_RRF_NO_CCK)
831                 flags |= NL80211_RRF_NO_CCK;
832
833         if (qflags & QLINK_RRF_NO_INDOOR)
834                 flags |= NL80211_RRF_NO_INDOOR;
835
836         if (qflags & QLINK_RRF_NO_OUTDOOR)
837                 flags |= NL80211_RRF_NO_OUTDOOR;
838
839         if (qflags & QLINK_RRF_DFS)
840                 flags |= NL80211_RRF_DFS;
841
842         if (qflags & QLINK_RRF_PTP_ONLY)
843                 flags |= NL80211_RRF_PTP_ONLY;
844
845         if (qflags & QLINK_RRF_PTMP_ONLY)
846                 flags |= NL80211_RRF_PTMP_ONLY;
847
848         if (qflags & QLINK_RRF_NO_IR)
849                 flags |= NL80211_RRF_NO_IR;
850
851         if (qflags & QLINK_RRF_AUTO_BW)
852                 flags |= NL80211_RRF_AUTO_BW;
853
854         if (qflags & QLINK_RRF_IR_CONCURRENT)
855                 flags |= NL80211_RRF_IR_CONCURRENT;
856
857         if (qflags & QLINK_RRF_NO_HT40MINUS)
858                 flags |= NL80211_RRF_NO_HT40MINUS;
859
860         if (qflags & QLINK_RRF_NO_HT40PLUS)
861                 flags |= NL80211_RRF_NO_HT40PLUS;
862
863         if (qflags & QLINK_RRF_NO_80MHZ)
864                 flags |= NL80211_RRF_NO_80MHZ;
865
866         if (qflags & QLINK_RRF_NO_160MHZ)
867                 flags |= NL80211_RRF_NO_160MHZ;
868
869         return flags;
870 }
871
872 static int
873 qtnf_cmd_resp_proc_hw_info(struct qtnf_bus *bus,
874                            const struct qlink_resp_get_hw_info *resp,
875                            size_t info_len)
876 {
877         struct qtnf_hw_info *hwinfo = &bus->hw_info;
878         const struct qlink_tlv_hdr *tlv;
879         const struct qlink_tlv_reg_rule *tlv_rule;
880         struct ieee80211_reg_rule *rule;
881         u16 tlv_type;
882         u16 tlv_value_len;
883         unsigned int rule_idx = 0;
884
885         if (WARN_ON(resp->n_reg_rules > NL80211_MAX_SUPP_REG_RULES))
886                 return -E2BIG;
887
888         hwinfo->rd = kzalloc(sizeof(*hwinfo->rd)
889                              + sizeof(struct ieee80211_reg_rule)
890                              * resp->n_reg_rules, GFP_KERNEL);
891
892         if (!hwinfo->rd)
893                 return -ENOMEM;
894
895         hwinfo->num_mac = resp->num_mac;
896         hwinfo->mac_bitmap = resp->mac_bitmap;
897         hwinfo->fw_ver = le32_to_cpu(resp->fw_ver);
898         hwinfo->ql_proto_ver = le16_to_cpu(resp->ql_proto_ver);
899         hwinfo->total_tx_chain = resp->total_tx_chain;
900         hwinfo->total_rx_chain = resp->total_rx_chain;
901         hwinfo->hw_capab = le32_to_cpu(resp->hw_capab);
902         hwinfo->rd->n_reg_rules = resp->n_reg_rules;
903         hwinfo->rd->alpha2[0] = resp->alpha2[0];
904         hwinfo->rd->alpha2[1] = resp->alpha2[1];
905
906         switch (resp->dfs_region) {
907         case QLINK_DFS_FCC:
908                 hwinfo->rd->dfs_region = NL80211_DFS_FCC;
909                 break;
910         case QLINK_DFS_ETSI:
911                 hwinfo->rd->dfs_region = NL80211_DFS_ETSI;
912                 break;
913         case QLINK_DFS_JP:
914                 hwinfo->rd->dfs_region = NL80211_DFS_JP;
915                 break;
916         case QLINK_DFS_UNSET:
917         default:
918                 hwinfo->rd->dfs_region = NL80211_DFS_UNSET;
919                 break;
920         }
921
922         tlv = (const struct qlink_tlv_hdr *)resp->info;
923
924         while (info_len >= sizeof(*tlv)) {
925                 tlv_type = le16_to_cpu(tlv->type);
926                 tlv_value_len = le16_to_cpu(tlv->len);
927
928                 if (tlv_value_len + sizeof(*tlv) > info_len) {
929                         pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
930                                 tlv_type, tlv_value_len);
931                         return -EINVAL;
932                 }
933
934                 switch (tlv_type) {
935                 case QTN_TLV_ID_REG_RULE:
936                         if (rule_idx >= resp->n_reg_rules) {
937                                 pr_warn("unexpected number of rules: %u\n",
938                                         resp->n_reg_rules);
939                                 return -EINVAL;
940                         }
941
942                         if (tlv_value_len != sizeof(*tlv_rule) - sizeof(*tlv)) {
943                                 pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
944                                         tlv_type, tlv_value_len);
945                                 return -EINVAL;
946                         }
947
948                         tlv_rule = (const struct qlink_tlv_reg_rule *)tlv;
949                         rule = &hwinfo->rd->reg_rules[rule_idx++];
950
951                         rule->freq_range.start_freq_khz =
952                                 le32_to_cpu(tlv_rule->start_freq_khz);
953                         rule->freq_range.end_freq_khz =
954                                 le32_to_cpu(tlv_rule->end_freq_khz);
955                         rule->freq_range.max_bandwidth_khz =
956                                 le32_to_cpu(tlv_rule->max_bandwidth_khz);
957                         rule->power_rule.max_antenna_gain =
958                                 le32_to_cpu(tlv_rule->max_antenna_gain);
959                         rule->power_rule.max_eirp =
960                                 le32_to_cpu(tlv_rule->max_eirp);
961                         rule->dfs_cac_ms =
962                                 le32_to_cpu(tlv_rule->dfs_cac_ms);
963                         rule->flags = qtnf_cmd_resp_reg_rule_flags_parse(
964                                         le32_to_cpu(tlv_rule->flags));
965                         break;
966                 default:
967                         break;
968                 }
969
970                 info_len -= tlv_value_len + sizeof(*tlv);
971                 tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
972         }
973
974         if (rule_idx != resp->n_reg_rules) {
975                 pr_warn("unexpected number of rules: expected %u got %u\n",
976                         resp->n_reg_rules, rule_idx);
977                 kfree(hwinfo->rd);
978                 hwinfo->rd = NULL;
979                 return -EINVAL;
980         }
981
982         pr_info("fw_version=%d, MACs map %#x, alpha2=\"%c%c\", chains Tx=%u Rx=%u\n",
983                 hwinfo->fw_ver, hwinfo->mac_bitmap,
984                 hwinfo->rd->alpha2[0], hwinfo->rd->alpha2[1],
985                 hwinfo->total_tx_chain, hwinfo->total_rx_chain);
986
987         return 0;
988 }
989
990 static int qtnf_parse_variable_mac_info(struct qtnf_wmac *mac,
991                                         const u8 *tlv_buf, size_t tlv_buf_size)
992 {
993         struct ieee80211_iface_limit *limits = NULL;
994         const struct qlink_iface_limit *limit_record;
995         size_t record_count = 0, rec = 0;
996         u16 tlv_type, tlv_value_len;
997         struct qlink_iface_comb_num *comb;
998         size_t tlv_full_len;
999         const struct qlink_tlv_hdr *tlv;
1000
1001         mac->macinfo.n_limits = 0;
1002
1003         tlv = (const struct qlink_tlv_hdr *)tlv_buf;
1004         while (tlv_buf_size >= sizeof(struct qlink_tlv_hdr)) {
1005                 tlv_type = le16_to_cpu(tlv->type);
1006                 tlv_value_len = le16_to_cpu(tlv->len);
1007                 tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1008                 if (tlv_full_len > tlv_buf_size) {
1009                         pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1010                                 mac->macid, tlv_type, tlv_value_len);
1011                         return -EINVAL;
1012                 }
1013
1014                 switch (tlv_type) {
1015                 case QTN_TLV_ID_NUM_IFACE_COMB:
1016                         if (unlikely(tlv_value_len != sizeof(*comb)))
1017                                 return -EINVAL;
1018
1019                         comb = (void *)tlv->val;
1020                         record_count = le16_to_cpu(comb->iface_comb_num);
1021
1022                         mac->macinfo.n_limits = record_count;
1023                         /* free earlier iface limits memory */
1024                         kfree(mac->macinfo.limits);
1025                         mac->macinfo.limits =
1026                                 kzalloc(sizeof(*mac->macinfo.limits) *
1027                                         record_count, GFP_KERNEL);
1028
1029                         if (unlikely(!mac->macinfo.limits))
1030                                 return -ENOMEM;
1031
1032                         limits = mac->macinfo.limits;
1033                         break;
1034                 case QTN_TLV_ID_IFACE_LIMIT:
1035                         if (unlikely(!limits)) {
1036                                 pr_warn("MAC%u: limits are not inited\n",
1037                                         mac->macid);
1038                                 return -EINVAL;
1039                         }
1040
1041                         if (unlikely(tlv_value_len != sizeof(*limit_record))) {
1042                                 pr_warn("MAC%u: record size mismatch\n",
1043                                         mac->macid);
1044                                 return -EINVAL;
1045                         }
1046
1047                         limit_record = (void *)tlv->val;
1048                         limits[rec].max = le16_to_cpu(limit_record->max_num);
1049                         limits[rec].types = qlink_iface_type_to_nl_mask(
1050                                 le16_to_cpu(limit_record->type));
1051
1052                         /* supported modes: STA, AP */
1053                         limits[rec].types &= BIT(NL80211_IFTYPE_AP) |
1054                                              BIT(NL80211_IFTYPE_AP_VLAN) |
1055                                              BIT(NL80211_IFTYPE_STATION);
1056
1057                         pr_debug("MAC%u: MAX: %u; TYPES: %.4X\n", mac->macid,
1058                                  limits[rec].max, limits[rec].types);
1059
1060                         if (limits[rec].types)
1061                                 rec++;
1062                         break;
1063                 default:
1064                         break;
1065                 }
1066
1067                 tlv_buf_size -= tlv_full_len;
1068                 tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1069         }
1070
1071         if (tlv_buf_size) {
1072                 pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1073                         mac->macid, tlv_buf_size);
1074                 return -EINVAL;
1075         }
1076
1077         if (mac->macinfo.n_limits != rec) {
1078                 pr_err("MAC%u: combination mismatch: reported=%zu parsed=%zu\n",
1079                        mac->macid, mac->macinfo.n_limits, rec);
1080                 return -EINVAL;
1081         }
1082
1083         return 0;
1084 }
1085
1086 static void
1087 qtnf_cmd_resp_proc_mac_info(struct qtnf_wmac *mac,
1088                             const struct qlink_resp_get_mac_info *resp_info)
1089 {
1090         struct qtnf_mac_info *mac_info;
1091         struct qtnf_vif *vif;
1092
1093         mac_info = &mac->macinfo;
1094
1095         mac_info->bands_cap = resp_info->bands_cap;
1096         mac_info->phymode_cap = resp_info->phymode_cap;
1097         memcpy(&mac_info->dev_mac, &resp_info->dev_mac,
1098                sizeof(mac_info->dev_mac));
1099
1100         ether_addr_copy(mac->macaddr, mac_info->dev_mac);
1101
1102         vif = qtnf_mac_get_base_vif(mac);
1103         if (vif)
1104                 ether_addr_copy(vif->mac_addr, mac->macaddr);
1105         else
1106                 pr_err("could not get valid base vif\n");
1107
1108         mac_info->num_tx_chain = resp_info->num_tx_chain;
1109         mac_info->num_rx_chain = resp_info->num_rx_chain;
1110
1111         mac_info->max_ap_assoc_sta = le16_to_cpu(resp_info->max_ap_assoc_sta);
1112         mac_info->radar_detect_widths =
1113                         qlink_chan_width_mask_to_nl(le16_to_cpu(
1114                                         resp_info->radar_detect_widths));
1115
1116         memcpy(&mac_info->ht_cap, &resp_info->ht_cap, sizeof(mac_info->ht_cap));
1117         memcpy(&mac_info->vht_cap, &resp_info->vht_cap,
1118                sizeof(mac_info->vht_cap));
1119 }
1120
1121 static int
1122 qtnf_cmd_resp_fill_channels_info(struct ieee80211_supported_band *band,
1123                                  struct qlink_resp_get_chan_info *resp,
1124                                  size_t payload_len)
1125 {
1126         u16 tlv_type;
1127         size_t tlv_len;
1128         const struct qlink_tlv_hdr *tlv;
1129         const struct qlink_tlv_channel *qchan;
1130         struct ieee80211_channel *chan;
1131         unsigned int chidx = 0;
1132         u32 qflags;
1133
1134         if (band->channels) {
1135                 if (band->n_channels == resp->num_chans) {
1136                         memset(band->channels, 0,
1137                                sizeof(*band->channels) * band->n_channels);
1138                 } else {
1139                         kfree(band->channels);
1140                         band->n_channels = 0;
1141                         band->channels = NULL;
1142                 }
1143         }
1144
1145         band->n_channels = resp->num_chans;
1146         if (band->n_channels == 0)
1147                 return 0;
1148
1149         if (!band->channels)
1150                 band->channels = kcalloc(band->n_channels, sizeof(*chan),
1151                                          GFP_KERNEL);
1152         if (!band->channels) {
1153                 band->n_channels = 0;
1154                 return -ENOMEM;
1155         }
1156
1157         tlv = (struct qlink_tlv_hdr *)resp->info;
1158
1159         while (payload_len >= sizeof(*tlv)) {
1160                 tlv_type = le16_to_cpu(tlv->type);
1161                 tlv_len = le16_to_cpu(tlv->len) + sizeof(*tlv);
1162
1163                 if (tlv_len > payload_len) {
1164                         pr_warn("malformed TLV 0x%.2X; LEN: %zu\n",
1165                                 tlv_type, tlv_len);
1166                         goto error_ret;
1167                 }
1168
1169                 switch (tlv_type) {
1170                 case QTN_TLV_ID_CHANNEL:
1171                         if (unlikely(tlv_len != sizeof(*qchan))) {
1172                                 pr_err("invalid channel TLV len %zu\n",
1173                                        tlv_len);
1174                                 goto error_ret;
1175                         }
1176
1177                         if (chidx == band->n_channels) {
1178                                 pr_err("too many channel TLVs\n");
1179                                 goto error_ret;
1180                         }
1181
1182                         qchan = (const struct qlink_tlv_channel *)tlv;
1183                         chan = &band->channels[chidx++];
1184                         qflags = le32_to_cpu(qchan->flags);
1185
1186                         chan->hw_value = le16_to_cpu(qchan->hw_value);
1187                         chan->band = band->band;
1188                         chan->center_freq = le16_to_cpu(qchan->center_freq);
1189                         chan->max_antenna_gain = (int)qchan->max_antenna_gain;
1190                         chan->max_power = (int)qchan->max_power;
1191                         chan->max_reg_power = (int)qchan->max_reg_power;
1192                         chan->beacon_found = qchan->beacon_found;
1193                         chan->dfs_cac_ms = le32_to_cpu(qchan->dfs_cac_ms);
1194                         chan->flags = 0;
1195
1196                         if (qflags & QLINK_CHAN_DISABLED)
1197                                 chan->flags |= IEEE80211_CHAN_DISABLED;
1198
1199                         if (qflags & QLINK_CHAN_NO_IR)
1200                                 chan->flags |= IEEE80211_CHAN_NO_IR;
1201
1202                         if (qflags & QLINK_CHAN_NO_HT40PLUS)
1203                                 chan->flags |= IEEE80211_CHAN_NO_HT40PLUS;
1204
1205                         if (qflags & QLINK_CHAN_NO_HT40MINUS)
1206                                 chan->flags |= IEEE80211_CHAN_NO_HT40MINUS;
1207
1208                         if (qflags & QLINK_CHAN_NO_OFDM)
1209                                 chan->flags |= IEEE80211_CHAN_NO_OFDM;
1210
1211                         if (qflags & QLINK_CHAN_NO_80MHZ)
1212                                 chan->flags |= IEEE80211_CHAN_NO_80MHZ;
1213
1214                         if (qflags & QLINK_CHAN_NO_160MHZ)
1215                                 chan->flags |= IEEE80211_CHAN_NO_160MHZ;
1216
1217                         if (qflags & QLINK_CHAN_INDOOR_ONLY)
1218                                 chan->flags |= IEEE80211_CHAN_INDOOR_ONLY;
1219
1220                         if (qflags & QLINK_CHAN_IR_CONCURRENT)
1221                                 chan->flags |= IEEE80211_CHAN_IR_CONCURRENT;
1222
1223                         if (qflags & QLINK_CHAN_NO_20MHZ)
1224                                 chan->flags |= IEEE80211_CHAN_NO_20MHZ;
1225
1226                         if (qflags & QLINK_CHAN_NO_10MHZ)
1227                                 chan->flags |= IEEE80211_CHAN_NO_10MHZ;
1228
1229                         if (qflags & QLINK_CHAN_RADAR) {
1230                                 chan->flags |= IEEE80211_CHAN_RADAR;
1231                                 chan->dfs_state_entered = jiffies;
1232
1233                                 if (qchan->dfs_state == QLINK_DFS_USABLE)
1234                                         chan->dfs_state = NL80211_DFS_USABLE;
1235                                 else if (qchan->dfs_state ==
1236                                         QLINK_DFS_AVAILABLE)
1237                                         chan->dfs_state = NL80211_DFS_AVAILABLE;
1238                                 else
1239                                         chan->dfs_state =
1240                                                 NL80211_DFS_UNAVAILABLE;
1241                         }
1242
1243                         pr_debug("chan=%d flags=%#x max_pow=%d max_reg_pow=%d\n",
1244                                  chan->hw_value, chan->flags, chan->max_power,
1245                                  chan->max_reg_power);
1246                         break;
1247                 default:
1248                         pr_warn("unknown TLV type: %#x\n", tlv_type);
1249                         break;
1250                 }
1251
1252                 payload_len -= tlv_len;
1253                 tlv = (struct qlink_tlv_hdr *)((u8 *)tlv + tlv_len);
1254         }
1255
1256         if (payload_len) {
1257                 pr_err("malformed TLV buf; bytes left: %zu\n", payload_len);
1258                 goto error_ret;
1259         }
1260
1261         if (band->n_channels != chidx) {
1262                 pr_err("channel count mismatch: reported=%d, parsed=%d\n",
1263                        band->n_channels, chidx);
1264                 goto error_ret;
1265         }
1266
1267         return 0;
1268
1269 error_ret:
1270         kfree(band->channels);
1271         band->channels = NULL;
1272         band->n_channels = 0;
1273
1274         return -EINVAL;
1275 }
1276
1277 static int qtnf_cmd_resp_proc_phy_params(struct qtnf_wmac *mac,
1278                                          const u8 *payload, size_t payload_len)
1279 {
1280         struct qtnf_mac_info *mac_info;
1281         struct qlink_tlv_frag_rts_thr *phy_thr;
1282         struct qlink_tlv_rlimit *limit;
1283         struct qlink_tlv_cclass *class;
1284         u16 tlv_type;
1285         u16 tlv_value_len;
1286         size_t tlv_full_len;
1287         const struct qlink_tlv_hdr *tlv;
1288
1289         mac_info = &mac->macinfo;
1290
1291         tlv = (struct qlink_tlv_hdr *)payload;
1292         while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1293                 tlv_type = le16_to_cpu(tlv->type);
1294                 tlv_value_len = le16_to_cpu(tlv->len);
1295                 tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1296
1297                 if (tlv_full_len > payload_len) {
1298                         pr_warn("MAC%u: malformed TLV 0x%.2X; LEN: %u\n",
1299                                 mac->macid, tlv_type, tlv_value_len);
1300                         return -EINVAL;
1301                 }
1302
1303                 switch (tlv_type) {
1304                 case QTN_TLV_ID_FRAG_THRESH:
1305                         phy_thr = (void *)tlv;
1306                         mac_info->frag_thr = (u32)le16_to_cpu(phy_thr->thr);
1307                         break;
1308                 case QTN_TLV_ID_RTS_THRESH:
1309                         phy_thr = (void *)tlv;
1310                         mac_info->rts_thr = (u32)le16_to_cpu(phy_thr->thr);
1311                         break;
1312                 case QTN_TLV_ID_SRETRY_LIMIT:
1313                         limit = (void *)tlv;
1314                         mac_info->sretry_limit = limit->rlimit;
1315                         break;
1316                 case QTN_TLV_ID_LRETRY_LIMIT:
1317                         limit = (void *)tlv;
1318                         mac_info->lretry_limit = limit->rlimit;
1319                         break;
1320                 case QTN_TLV_ID_COVERAGE_CLASS:
1321                         class = (void *)tlv;
1322                         mac_info->coverage_class = class->cclass;
1323                         break;
1324                 default:
1325                         pr_err("MAC%u: Unknown TLV type: %#x\n", mac->macid,
1326                                le16_to_cpu(tlv->type));
1327                         break;
1328                 }
1329
1330                 payload_len -= tlv_full_len;
1331                 tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1332         }
1333
1334         if (payload_len) {
1335                 pr_warn("MAC%u: malformed TLV buf; bytes left: %zu\n",
1336                         mac->macid, payload_len);
1337                 return -EINVAL;
1338         }
1339
1340         return 0;
1341 }
1342
1343 static int
1344 qtnf_cmd_resp_proc_chan_stat_info(struct qtnf_chan_stats *stats,
1345                                   const u8 *payload, size_t payload_len)
1346 {
1347         struct qlink_chan_stats *qlink_stats;
1348         const struct qlink_tlv_hdr *tlv;
1349         size_t tlv_full_len;
1350         u16 tlv_value_len;
1351         u16 tlv_type;
1352
1353         tlv = (struct qlink_tlv_hdr *)payload;
1354         while (payload_len >= sizeof(struct qlink_tlv_hdr)) {
1355                 tlv_type = le16_to_cpu(tlv->type);
1356                 tlv_value_len = le16_to_cpu(tlv->len);
1357                 tlv_full_len = tlv_value_len + sizeof(struct qlink_tlv_hdr);
1358                 if (tlv_full_len > payload_len) {
1359                         pr_warn("malformed TLV 0x%.2X; LEN: %u\n",
1360                                 tlv_type, tlv_value_len);
1361                         return -EINVAL;
1362                 }
1363                 switch (tlv_type) {
1364                 case QTN_TLV_ID_CHANNEL_STATS:
1365                         if (unlikely(tlv_value_len != sizeof(*qlink_stats))) {
1366                                 pr_err("invalid CHANNEL_STATS entry size\n");
1367                                 return -EINVAL;
1368                         }
1369
1370                         qlink_stats = (void *)tlv->val;
1371
1372                         stats->chan_num = le32_to_cpu(qlink_stats->chan_num);
1373                         stats->cca_tx = le32_to_cpu(qlink_stats->cca_tx);
1374                         stats->cca_rx = le32_to_cpu(qlink_stats->cca_rx);
1375                         stats->cca_busy = le32_to_cpu(qlink_stats->cca_busy);
1376                         stats->cca_try = le32_to_cpu(qlink_stats->cca_try);
1377                         stats->chan_noise = qlink_stats->chan_noise;
1378
1379                         pr_debug("chan(%u) try(%u) busy(%u) noise(%d)\n",
1380                                  stats->chan_num, stats->cca_try,
1381                                  stats->cca_busy, stats->chan_noise);
1382                         break;
1383                 default:
1384                         pr_warn("Unknown TLV type: %#x\n",
1385                                 le16_to_cpu(tlv->type));
1386                 }
1387                 payload_len -= tlv_full_len;
1388                 tlv = (struct qlink_tlv_hdr *)(tlv->val + tlv_value_len);
1389         }
1390
1391         if (payload_len) {
1392                 pr_warn("malformed TLV buf; bytes left: %zu\n", payload_len);
1393                 return -EINVAL;
1394         }
1395
1396         return 0;
1397 }
1398
1399 int qtnf_cmd_get_mac_info(struct qtnf_wmac *mac)
1400 {
1401         struct sk_buff *cmd_skb, *resp_skb = NULL;
1402         const struct qlink_resp_get_mac_info *resp;
1403         size_t var_data_len;
1404         u16 res_code = QLINK_CMD_RESULT_OK;
1405         int ret = 0;
1406
1407         cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
1408                                             QLINK_CMD_MAC_INFO,
1409                                             sizeof(struct qlink_cmd));
1410         if (unlikely(!cmd_skb))
1411                 return -ENOMEM;
1412
1413         qtnf_bus_lock(mac->bus);
1414
1415         ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb, &res_code,
1416                                        sizeof(*resp), &var_data_len);
1417         if (unlikely(ret))
1418                 goto out;
1419
1420         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1421                 pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
1422                 ret = -EFAULT;
1423                 goto out;
1424         }
1425
1426         resp = (const struct qlink_resp_get_mac_info *)resp_skb->data;
1427         qtnf_cmd_resp_proc_mac_info(mac, resp);
1428         ret = qtnf_parse_variable_mac_info(mac, resp->var_info, var_data_len);
1429
1430 out:
1431         qtnf_bus_unlock(mac->bus);
1432         consume_skb(resp_skb);
1433
1434         return ret;
1435 }
1436
1437 int qtnf_cmd_get_hw_info(struct qtnf_bus *bus)
1438 {
1439         struct sk_buff *cmd_skb, *resp_skb = NULL;
1440         const struct qlink_resp_get_hw_info *resp;
1441         u16 res_code = QLINK_CMD_RESULT_OK;
1442         int ret = 0;
1443         size_t info_len;
1444
1445         cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1446                                             QLINK_CMD_GET_HW_INFO,
1447                                             sizeof(struct qlink_cmd));
1448         if (unlikely(!cmd_skb))
1449                 return -ENOMEM;
1450
1451         qtnf_bus_lock(bus);
1452
1453         ret = qtnf_cmd_send_with_reply(bus, cmd_skb, &resp_skb, &res_code,
1454                                        sizeof(*resp), &info_len);
1455
1456         if (unlikely(ret))
1457                 goto out;
1458
1459         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1460                 pr_err("cmd exec failed: 0x%.4X\n", res_code);
1461                 ret = -EFAULT;
1462                 goto out;
1463         }
1464
1465         resp = (const struct qlink_resp_get_hw_info *)resp_skb->data;
1466         ret = qtnf_cmd_resp_proc_hw_info(bus, resp, info_len);
1467
1468 out:
1469         qtnf_bus_unlock(bus);
1470         consume_skb(resp_skb);
1471
1472         return ret;
1473 }
1474
1475 int qtnf_cmd_get_mac_chan_info(struct qtnf_wmac *mac,
1476                                struct ieee80211_supported_band *band)
1477 {
1478         struct sk_buff *cmd_skb, *resp_skb = NULL;
1479         size_t info_len;
1480         struct qlink_cmd_chans_info_get *cmd;
1481         struct qlink_resp_get_chan_info *resp;
1482         u16 res_code = QLINK_CMD_RESULT_OK;
1483         int ret = 0;
1484         u8 qband;
1485
1486         switch (band->band) {
1487         case NL80211_BAND_2GHZ:
1488                 qband = QLINK_BAND_2GHZ;
1489                 break;
1490         case NL80211_BAND_5GHZ:
1491                 qband = QLINK_BAND_5GHZ;
1492                 break;
1493         case NL80211_BAND_60GHZ:
1494                 qband = QLINK_BAND_60GHZ;
1495                 break;
1496         default:
1497                 return -EINVAL;
1498         }
1499
1500         cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1501                                             QLINK_CMD_CHANS_INFO_GET,
1502                                             sizeof(*cmd));
1503         if (!cmd_skb)
1504                 return -ENOMEM;
1505
1506         cmd = (struct qlink_cmd_chans_info_get *)cmd_skb->data;
1507         cmd->band = qband;
1508
1509         qtnf_bus_lock(mac->bus);
1510
1511         ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb, &res_code,
1512                                        sizeof(*resp), &info_len);
1513
1514         if (unlikely(ret))
1515                 goto out;
1516
1517         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1518                 pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
1519                 ret = -EFAULT;
1520                 goto out;
1521         }
1522
1523         resp = (struct qlink_resp_get_chan_info *)resp_skb->data;
1524         if (resp->band != qband) {
1525                 pr_err("MAC%u: reply band %u != cmd band %u\n", mac->macid,
1526                        resp->band, qband);
1527                 ret = -EINVAL;
1528                 goto out;
1529         }
1530
1531         ret = qtnf_cmd_resp_fill_channels_info(band, resp, info_len);
1532
1533 out:
1534         qtnf_bus_unlock(mac->bus);
1535         consume_skb(resp_skb);
1536
1537         return ret;
1538 }
1539
1540 int qtnf_cmd_send_get_phy_params(struct qtnf_wmac *mac)
1541 {
1542         struct sk_buff *cmd_skb, *resp_skb = NULL;
1543         size_t response_size;
1544         struct qlink_resp_phy_params *resp;
1545         u16 res_code = QLINK_CMD_RESULT_OK;
1546         int ret = 0;
1547
1548         cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1549                                             QLINK_CMD_PHY_PARAMS_GET,
1550                                             sizeof(struct qlink_cmd));
1551         if (!cmd_skb)
1552                 return -ENOMEM;
1553
1554         qtnf_bus_lock(mac->bus);
1555
1556         ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb, &res_code,
1557                                        sizeof(*resp), &response_size);
1558
1559         if (unlikely(ret))
1560                 goto out;
1561
1562         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1563                 pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
1564                 ret = -EFAULT;
1565                 goto out;
1566         }
1567
1568         resp = (struct qlink_resp_phy_params *)resp_skb->data;
1569         ret = qtnf_cmd_resp_proc_phy_params(mac, resp->info, response_size);
1570
1571 out:
1572         qtnf_bus_unlock(mac->bus);
1573         consume_skb(resp_skb);
1574
1575         return ret;
1576 }
1577
1578 int qtnf_cmd_send_update_phy_params(struct qtnf_wmac *mac, u32 changed)
1579 {
1580         struct wiphy *wiphy = priv_to_wiphy(mac);
1581         struct sk_buff *cmd_skb;
1582         u16 res_code = QLINK_CMD_RESULT_OK;
1583         int ret = 0;
1584
1585         cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0,
1586                                             QLINK_CMD_PHY_PARAMS_SET,
1587                                             sizeof(struct qlink_cmd));
1588         if (!cmd_skb)
1589                 return -ENOMEM;
1590
1591         qtnf_bus_lock(mac->bus);
1592
1593         if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1594                 qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_FRAG_THRESH,
1595                                          wiphy->frag_threshold);
1596         if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1597                 qtnf_cmd_skb_put_tlv_u16(cmd_skb, QTN_TLV_ID_RTS_THRESH,
1598                                          wiphy->rts_threshold);
1599         if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1600                 qtnf_cmd_skb_put_tlv_u8(cmd_skb, QTN_TLV_ID_COVERAGE_CLASS,
1601                                         wiphy->coverage_class);
1602
1603         ret = qtnf_cmd_send(mac->bus, cmd_skb, &res_code);
1604
1605         if (unlikely(ret))
1606                 goto out;
1607
1608         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1609                 pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
1610                 ret = -EFAULT;
1611                 goto out;
1612         }
1613
1614 out:
1615         qtnf_bus_unlock(mac->bus);
1616         return ret;
1617 }
1618
1619 int qtnf_cmd_send_init_fw(struct qtnf_bus *bus)
1620 {
1621         struct sk_buff *cmd_skb;
1622         u16 res_code = QLINK_CMD_RESULT_OK;
1623         int ret = 0;
1624
1625         cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1626                                             QLINK_CMD_FW_INIT,
1627                                             sizeof(struct qlink_cmd));
1628         if (unlikely(!cmd_skb))
1629                 return -ENOMEM;
1630
1631         qtnf_bus_lock(bus);
1632
1633         ret = qtnf_cmd_send(bus, cmd_skb, &res_code);
1634
1635         if (unlikely(ret))
1636                 goto out;
1637
1638         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1639                 pr_err("cmd exec failed: 0x%.4X\n", res_code);
1640                 ret = -EFAULT;
1641                 goto out;
1642         }
1643
1644 out:
1645         qtnf_bus_unlock(bus);
1646         return ret;
1647 }
1648
1649 void qtnf_cmd_send_deinit_fw(struct qtnf_bus *bus)
1650 {
1651         struct sk_buff *cmd_skb;
1652
1653         cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
1654                                             QLINK_CMD_FW_DEINIT,
1655                                             sizeof(struct qlink_cmd));
1656         if (!cmd_skb)
1657                 return;
1658
1659         qtnf_bus_lock(bus);
1660
1661         qtnf_cmd_send(bus, cmd_skb, NULL);
1662
1663         qtnf_bus_unlock(bus);
1664 }
1665
1666 int qtnf_cmd_send_add_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
1667                           const u8 *mac_addr, struct key_params *params)
1668 {
1669         struct sk_buff *cmd_skb;
1670         struct qlink_cmd_add_key *cmd;
1671         u16 res_code = QLINK_CMD_RESULT_OK;
1672         int ret = 0;
1673
1674         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1675                                             QLINK_CMD_ADD_KEY,
1676                                             sizeof(*cmd));
1677         if (unlikely(!cmd_skb))
1678                 return -ENOMEM;
1679
1680         qtnf_bus_lock(vif->mac->bus);
1681
1682         cmd = (struct qlink_cmd_add_key *)cmd_skb->data;
1683
1684         if (mac_addr)
1685                 ether_addr_copy(cmd->addr, mac_addr);
1686         else
1687                 eth_broadcast_addr(cmd->addr);
1688
1689         cmd->cipher = cpu_to_le32(params->cipher);
1690         cmd->key_index = key_index;
1691         cmd->pairwise = pairwise;
1692
1693         if (params->key && params->key_len > 0)
1694                 qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_KEY,
1695                                          params->key,
1696                                          params->key_len);
1697
1698         if (params->seq && params->seq_len > 0)
1699                 qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_SEQ,
1700                                          params->seq,
1701                                          params->seq_len);
1702
1703         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
1704         if (unlikely(ret))
1705                 goto out;
1706
1707         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1708                 pr_err("VIF%u.%u: CMD failed: %u\n",
1709                        vif->mac->macid, vif->vifid, res_code);
1710                 ret = -EFAULT;
1711                 goto out;
1712         }
1713
1714 out:
1715         qtnf_bus_unlock(vif->mac->bus);
1716         return ret;
1717 }
1718
1719 int qtnf_cmd_send_del_key(struct qtnf_vif *vif, u8 key_index, bool pairwise,
1720                           const u8 *mac_addr)
1721 {
1722         struct sk_buff *cmd_skb;
1723         struct qlink_cmd_del_key *cmd;
1724         u16 res_code = QLINK_CMD_RESULT_OK;
1725         int ret = 0;
1726
1727         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1728                                             QLINK_CMD_DEL_KEY,
1729                                             sizeof(*cmd));
1730         if (unlikely(!cmd_skb))
1731                 return -ENOMEM;
1732
1733         qtnf_bus_lock(vif->mac->bus);
1734
1735         cmd = (struct qlink_cmd_del_key *)cmd_skb->data;
1736
1737         if (mac_addr)
1738                 ether_addr_copy(cmd->addr, mac_addr);
1739         else
1740                 eth_broadcast_addr(cmd->addr);
1741
1742         cmd->key_index = key_index;
1743         cmd->pairwise = pairwise;
1744         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
1745         if (unlikely(ret))
1746                 goto out;
1747
1748         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1749                 pr_err("VIF%u.%u: CMD failed: %u\n",
1750                        vif->mac->macid, vif->vifid, res_code);
1751                 ret = -EFAULT;
1752                 goto out;
1753         }
1754
1755 out:
1756         qtnf_bus_unlock(vif->mac->bus);
1757         return ret;
1758 }
1759
1760 int qtnf_cmd_send_set_default_key(struct qtnf_vif *vif, u8 key_index,
1761                                   bool unicast, bool multicast)
1762 {
1763         struct sk_buff *cmd_skb;
1764         struct qlink_cmd_set_def_key *cmd;
1765         u16 res_code = QLINK_CMD_RESULT_OK;
1766         int ret = 0;
1767
1768         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1769                                             QLINK_CMD_SET_DEFAULT_KEY,
1770                                             sizeof(*cmd));
1771         if (unlikely(!cmd_skb))
1772                 return -ENOMEM;
1773
1774         qtnf_bus_lock(vif->mac->bus);
1775
1776         cmd = (struct qlink_cmd_set_def_key *)cmd_skb->data;
1777         cmd->key_index = key_index;
1778         cmd->unicast = unicast;
1779         cmd->multicast = multicast;
1780         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
1781         if (unlikely(ret))
1782                 goto out;
1783
1784         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1785                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
1786                        vif->vifid, res_code);
1787                 ret = -EFAULT;
1788                 goto out;
1789         }
1790
1791 out:
1792         qtnf_bus_unlock(vif->mac->bus);
1793         return ret;
1794 }
1795
1796 int qtnf_cmd_send_set_default_mgmt_key(struct qtnf_vif *vif, u8 key_index)
1797 {
1798         struct sk_buff *cmd_skb;
1799         struct qlink_cmd_set_def_mgmt_key *cmd;
1800         u16 res_code = QLINK_CMD_RESULT_OK;
1801         int ret = 0;
1802
1803         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1804                                             QLINK_CMD_SET_DEFAULT_MGMT_KEY,
1805                                             sizeof(*cmd));
1806         if (unlikely(!cmd_skb))
1807                 return -ENOMEM;
1808
1809         qtnf_bus_lock(vif->mac->bus);
1810
1811         cmd = (struct qlink_cmd_set_def_mgmt_key *)cmd_skb->data;
1812         cmd->key_index = key_index;
1813         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
1814         if (unlikely(ret))
1815                 goto out;
1816
1817         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1818                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
1819                        vif->vifid, res_code);
1820                 ret = -EFAULT;
1821                 goto out;
1822         }
1823
1824 out:
1825         qtnf_bus_unlock(vif->mac->bus);
1826         return ret;
1827 }
1828
1829 static u32 qtnf_encode_sta_flags(u32 flags)
1830 {
1831         u32 code = 0;
1832
1833         if (flags & BIT(NL80211_STA_FLAG_AUTHORIZED))
1834                 code |= QLINK_STA_FLAG_AUTHORIZED;
1835         if (flags & BIT(NL80211_STA_FLAG_SHORT_PREAMBLE))
1836                 code |= QLINK_STA_FLAG_SHORT_PREAMBLE;
1837         if (flags & BIT(NL80211_STA_FLAG_WME))
1838                 code |= QLINK_STA_FLAG_WME;
1839         if (flags & BIT(NL80211_STA_FLAG_MFP))
1840                 code |= QLINK_STA_FLAG_MFP;
1841         if (flags & BIT(NL80211_STA_FLAG_AUTHENTICATED))
1842                 code |= QLINK_STA_FLAG_AUTHENTICATED;
1843         if (flags & BIT(NL80211_STA_FLAG_TDLS_PEER))
1844                 code |= QLINK_STA_FLAG_TDLS_PEER;
1845         if (flags & BIT(NL80211_STA_FLAG_ASSOCIATED))
1846                 code |= QLINK_STA_FLAG_ASSOCIATED;
1847         return code;
1848 }
1849
1850 int qtnf_cmd_send_change_sta(struct qtnf_vif *vif, const u8 *mac,
1851                              struct station_parameters *params)
1852 {
1853         struct sk_buff *cmd_skb;
1854         struct qlink_cmd_change_sta *cmd;
1855         u16 res_code = QLINK_CMD_RESULT_OK;
1856         int ret = 0;
1857
1858         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1859                                             QLINK_CMD_CHANGE_STA,
1860                                             sizeof(*cmd));
1861         if (unlikely(!cmd_skb))
1862                 return -ENOMEM;
1863
1864         qtnf_bus_lock(vif->mac->bus);
1865
1866         cmd = (struct qlink_cmd_change_sta *)cmd_skb->data;
1867         ether_addr_copy(cmd->sta_addr, mac);
1868
1869         switch (vif->wdev.iftype) {
1870         case NL80211_IFTYPE_AP:
1871                 cmd->if_type = cpu_to_le16(QLINK_IFTYPE_AP);
1872                 cmd->sta_flags_mask = cpu_to_le32(qtnf_encode_sta_flags(
1873                                                   params->sta_flags_mask));
1874                 cmd->sta_flags_set = cpu_to_le32(qtnf_encode_sta_flags(
1875                                                  params->sta_flags_set));
1876                 break;
1877         case NL80211_IFTYPE_STATION:
1878                 cmd->if_type = cpu_to_le16(QLINK_IFTYPE_STATION);
1879                 cmd->sta_flags_mask = cpu_to_le32(qtnf_encode_sta_flags(
1880                                                   params->sta_flags_mask));
1881                 cmd->sta_flags_set = cpu_to_le32(qtnf_encode_sta_flags(
1882                                                  params->sta_flags_set));
1883                 break;
1884         default:
1885                 pr_err("unsupported iftype %d\n", vif->wdev.iftype);
1886                 dev_kfree_skb(cmd_skb);
1887                 ret = -EINVAL;
1888                 goto out;
1889         }
1890
1891         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
1892         if (unlikely(ret))
1893                 goto out;
1894
1895         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1896                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
1897                        vif->vifid, res_code);
1898                 ret = -EFAULT;
1899                 goto out;
1900         }
1901
1902 out:
1903         qtnf_bus_unlock(vif->mac->bus);
1904         return ret;
1905 }
1906
1907 int qtnf_cmd_send_del_sta(struct qtnf_vif *vif,
1908                           struct station_del_parameters *params)
1909 {
1910         struct sk_buff *cmd_skb;
1911         struct qlink_cmd_del_sta *cmd;
1912         u16 res_code = QLINK_CMD_RESULT_OK;
1913         int ret = 0;
1914
1915         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
1916                                             QLINK_CMD_DEL_STA,
1917                                             sizeof(*cmd));
1918         if (unlikely(!cmd_skb))
1919                 return -ENOMEM;
1920
1921         qtnf_bus_lock(vif->mac->bus);
1922
1923         cmd = (struct qlink_cmd_del_sta *)cmd_skb->data;
1924
1925         if (params->mac)
1926                 ether_addr_copy(cmd->sta_addr, params->mac);
1927         else
1928                 eth_broadcast_addr(cmd->sta_addr);      /* flush all stations */
1929
1930         cmd->subtype = params->subtype;
1931         cmd->reason_code = cpu_to_le16(params->reason_code);
1932
1933         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
1934         if (unlikely(ret))
1935                 goto out;
1936
1937         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
1938                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
1939                        vif->vifid, res_code);
1940                 ret = -EFAULT;
1941                 goto out;
1942         }
1943
1944 out:
1945         qtnf_bus_unlock(vif->mac->bus);
1946         return ret;
1947 }
1948
1949 int qtnf_cmd_send_scan(struct qtnf_wmac *mac)
1950 {
1951         struct sk_buff *cmd_skb;
1952         u16 res_code = QLINK_CMD_RESULT_OK;
1953         struct ieee80211_channel *sc;
1954         struct cfg80211_scan_request *scan_req = mac->scan_req;
1955         struct qlink_tlv_channel *qchan;
1956         int n_channels;
1957         int count = 0;
1958         int ret;
1959         u32 flags;
1960
1961         if (scan_req->n_ssids > QTNF_MAX_SSID_LIST_LENGTH) {
1962                 pr_err("MAC%u: too many SSIDs in scan request\n", mac->macid);
1963                 return -EINVAL;
1964         }
1965
1966         cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
1967                                             QLINK_CMD_SCAN,
1968                                             sizeof(struct qlink_cmd));
1969         if (unlikely(!cmd_skb))
1970                 return -ENOMEM;
1971
1972         qtnf_bus_lock(mac->bus);
1973
1974         if (scan_req->n_ssids != 0) {
1975                 while (count < scan_req->n_ssids) {
1976                         qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID,
1977                                 scan_req->ssids[count].ssid,
1978                                 scan_req->ssids[count].ssid_len);
1979                         count++;
1980                 }
1981         }
1982
1983         if (scan_req->ie_len != 0)
1984                 qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_IE_SET,
1985                                          scan_req->ie,
1986                                          scan_req->ie_len);
1987
1988         if (scan_req->n_channels) {
1989                 n_channels = scan_req->n_channels;
1990                 count = 0;
1991
1992                 while (n_channels != 0) {
1993                         sc = scan_req->channels[count];
1994                         if (sc->flags & IEEE80211_CHAN_DISABLED) {
1995                                 n_channels--;
1996                                 continue;
1997                         }
1998
1999                         pr_debug("MAC%u: scan chan=%d, freq=%d, flags=%#x\n",
2000                                  mac->macid, sc->hw_value, sc->center_freq,
2001                                  sc->flags);
2002                         qchan = skb_put_zero(cmd_skb, sizeof(*qchan));
2003                         flags = 0;
2004
2005                         qchan->hdr.type = cpu_to_le16(QTN_TLV_ID_CHANNEL);
2006                         qchan->hdr.len = cpu_to_le16(sizeof(*qchan) -
2007                                         sizeof(struct qlink_tlv_hdr));
2008                         qchan->center_freq = cpu_to_le16(sc->center_freq);
2009                         qchan->hw_value = cpu_to_le16(sc->hw_value);
2010
2011                         if (sc->flags & IEEE80211_CHAN_NO_IR)
2012                                 flags |= QLINK_CHAN_NO_IR;
2013
2014                         if (sc->flags & IEEE80211_CHAN_RADAR)
2015                                 flags |= QLINK_CHAN_RADAR;
2016
2017                         qchan->flags = cpu_to_le32(flags);
2018                         n_channels--;
2019                         count++;
2020                 }
2021         }
2022
2023         ret = qtnf_cmd_send(mac->bus, cmd_skb, &res_code);
2024
2025         if (unlikely(ret))
2026                 goto out;
2027
2028         pr_debug("MAC%u: scan started\n", mac->macid);
2029
2030         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2031                 pr_err("MAC%u: CMD failed: %u\n", mac->macid, res_code);
2032                 ret = -EFAULT;
2033                 goto out;
2034         }
2035 out:
2036         qtnf_bus_unlock(mac->bus);
2037         return ret;
2038 }
2039
2040 int qtnf_cmd_send_connect(struct qtnf_vif *vif,
2041                           struct cfg80211_connect_params *sme)
2042 {
2043         struct sk_buff *cmd_skb;
2044         struct qlink_cmd_connect *cmd;
2045         struct qtnf_bss_config *bss_cfg = &vif->bss_cfg;
2046         struct qlink_auth_encr aen;
2047         u16 res_code = QLINK_CMD_RESULT_OK;
2048         int ret;
2049         int i;
2050
2051         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2052                                             QLINK_CMD_CONNECT,
2053                                             sizeof(*cmd));
2054         if (unlikely(!cmd_skb))
2055                 return -ENOMEM;
2056
2057         qtnf_bus_lock(vif->mac->bus);
2058
2059         cmd = (struct qlink_cmd_connect *)cmd_skb->data;
2060
2061         ether_addr_copy(cmd->bssid, bss_cfg->bssid);
2062
2063         if (vif->mac->chandef.chan)
2064                 cmd->channel = cpu_to_le16(vif->mac->chandef.chan->hw_value);
2065
2066         cmd->bg_scan_period = cpu_to_le16(bss_cfg->bg_scan_period);
2067
2068         memset(&aen, 0, sizeof(aen));
2069         aen.auth_type = bss_cfg->auth_type;
2070         aen.privacy = !!bss_cfg->privacy;
2071         aen.mfp = bss_cfg->mfp;
2072         aen.wpa_versions = cpu_to_le32(bss_cfg->crypto.wpa_versions);
2073         aen.cipher_group = cpu_to_le32(bss_cfg->crypto.cipher_group);
2074         aen.n_ciphers_pairwise = cpu_to_le32(
2075                                         bss_cfg->crypto.n_ciphers_pairwise);
2076
2077         for (i = 0; i < QLINK_MAX_NR_CIPHER_SUITES; i++)
2078                 aen.ciphers_pairwise[i] = cpu_to_le32(
2079                                         bss_cfg->crypto.ciphers_pairwise[i]);
2080
2081         aen.n_akm_suites = cpu_to_le32(bss_cfg->crypto.n_akm_suites);
2082
2083         for (i = 0; i < QLINK_MAX_NR_AKM_SUITES; i++)
2084                 aen.akm_suites[i] = cpu_to_le32(
2085                                         bss_cfg->crypto.akm_suites[i]);
2086
2087         aen.control_port = bss_cfg->crypto.control_port;
2088         aen.control_port_no_encrypt =
2089                         bss_cfg->crypto.control_port_no_encrypt;
2090         aen.control_port_ethertype = cpu_to_le16(be16_to_cpu(
2091                                 bss_cfg->crypto.control_port_ethertype));
2092
2093         qtnf_cmd_skb_put_tlv_arr(cmd_skb, WLAN_EID_SSID, bss_cfg->ssid,
2094                                  bss_cfg->ssid_len);
2095         qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_CRYPTO, (u8 *)&aen,
2096                                  sizeof(aen));
2097
2098         if (sme->ie_len != 0)
2099                 qtnf_cmd_skb_put_tlv_arr(cmd_skb, QTN_TLV_ID_IE_SET,
2100                                          sme->ie,
2101                                          sme->ie_len);
2102
2103         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2104
2105         if (unlikely(ret))
2106                 goto out;
2107
2108         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2109                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2110                        vif->vifid, res_code);
2111                 ret = -EFAULT;
2112                 goto out;
2113         }
2114 out:
2115         qtnf_bus_unlock(vif->mac->bus);
2116         return ret;
2117 }
2118
2119 int qtnf_cmd_send_disconnect(struct qtnf_vif *vif, u16 reason_code)
2120 {
2121         struct sk_buff *cmd_skb;
2122         struct qlink_cmd_disconnect *cmd;
2123         u16 res_code = QLINK_CMD_RESULT_OK;
2124         int ret;
2125
2126         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2127                                             QLINK_CMD_DISCONNECT,
2128                                             sizeof(*cmd));
2129         if (unlikely(!cmd_skb))
2130                 return -ENOMEM;
2131
2132         qtnf_bus_lock(vif->mac->bus);
2133
2134         cmd = (struct qlink_cmd_disconnect *)cmd_skb->data;
2135         cmd->reason = cpu_to_le16(reason_code);
2136
2137         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2138
2139         if (unlikely(ret))
2140                 goto out;
2141
2142         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2143                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2144                        vif->vifid, res_code);
2145                 ret = -EFAULT;
2146                 goto out;
2147         }
2148 out:
2149         qtnf_bus_unlock(vif->mac->bus);
2150         return ret;
2151 }
2152
2153 int qtnf_cmd_send_updown_intf(struct qtnf_vif *vif, bool up)
2154 {
2155         struct sk_buff *cmd_skb;
2156         struct qlink_cmd_updown *cmd;
2157         u16 res_code = QLINK_CMD_RESULT_OK;
2158         int ret;
2159
2160         cmd_skb = qtnf_cmd_alloc_new_cmdskb(vif->mac->macid, vif->vifid,
2161                                             QLINK_CMD_UPDOWN_INTF,
2162                                             sizeof(*cmd));
2163         if (unlikely(!cmd_skb))
2164                 return -ENOMEM;
2165
2166         cmd = (struct qlink_cmd_updown *)cmd_skb->data;
2167         cmd->if_up = !!up;
2168
2169         qtnf_bus_lock(vif->mac->bus);
2170
2171         ret = qtnf_cmd_send(vif->mac->bus, cmd_skb, &res_code);
2172
2173         if (unlikely(ret))
2174                 goto out;
2175
2176         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2177                 pr_err("VIF%u.%u: CMD failed: %u\n", vif->mac->macid,
2178                        vif->vifid, res_code);
2179                 ret = -EFAULT;
2180                 goto out;
2181         }
2182 out:
2183         qtnf_bus_unlock(vif->mac->bus);
2184         return ret;
2185 }
2186
2187 int qtnf_cmd_reg_notify(struct qtnf_bus *bus, struct regulatory_request *req)
2188 {
2189         struct sk_buff *cmd_skb;
2190         int ret;
2191         u16 res_code;
2192         struct qlink_cmd_reg_notify *cmd;
2193
2194         cmd_skb = qtnf_cmd_alloc_new_cmdskb(QLINK_MACID_RSVD, QLINK_VIFID_RSVD,
2195                                             QLINK_CMD_REG_NOTIFY,
2196                                             sizeof(*cmd));
2197         if (!cmd_skb)
2198                 return -ENOMEM;
2199
2200         cmd = (struct qlink_cmd_reg_notify *)cmd_skb->data;
2201         cmd->alpha2[0] = req->alpha2[0];
2202         cmd->alpha2[1] = req->alpha2[1];
2203
2204         switch (req->initiator) {
2205         case NL80211_REGDOM_SET_BY_CORE:
2206                 cmd->initiator = QLINK_REGDOM_SET_BY_CORE;
2207                 break;
2208         case NL80211_REGDOM_SET_BY_USER:
2209                 cmd->initiator = QLINK_REGDOM_SET_BY_USER;
2210                 break;
2211         case NL80211_REGDOM_SET_BY_DRIVER:
2212                 cmd->initiator = QLINK_REGDOM_SET_BY_DRIVER;
2213                 break;
2214         case NL80211_REGDOM_SET_BY_COUNTRY_IE:
2215                 cmd->initiator = QLINK_REGDOM_SET_BY_COUNTRY_IE;
2216                 break;
2217         }
2218
2219         switch (req->user_reg_hint_type) {
2220         case NL80211_USER_REG_HINT_USER:
2221                 cmd->user_reg_hint_type = QLINK_USER_REG_HINT_USER;
2222                 break;
2223         case NL80211_USER_REG_HINT_CELL_BASE:
2224                 cmd->user_reg_hint_type = QLINK_USER_REG_HINT_CELL_BASE;
2225                 break;
2226         case NL80211_USER_REG_HINT_INDOOR:
2227                 cmd->user_reg_hint_type = QLINK_USER_REG_HINT_INDOOR;
2228                 break;
2229         }
2230
2231         qtnf_bus_lock(bus);
2232
2233         ret = qtnf_cmd_send(bus, cmd_skb, &res_code);
2234         if (ret)
2235                 goto out;
2236
2237         switch (res_code) {
2238         case QLINK_CMD_RESULT_ENOTSUPP:
2239                 pr_warn("reg update not supported\n");
2240                 ret = -EOPNOTSUPP;
2241                 break;
2242         case QLINK_CMD_RESULT_EALREADY:
2243                 pr_info("regulatory domain is already set to %c%c",
2244                         req->alpha2[0], req->alpha2[1]);
2245                 ret = -EALREADY;
2246                 break;
2247         case QLINK_CMD_RESULT_OK:
2248                 ret = 0;
2249                 break;
2250         default:
2251                 ret = -EFAULT;
2252                 break;
2253         }
2254
2255 out:
2256         qtnf_bus_unlock(bus);
2257
2258         return ret;
2259 }
2260
2261 int qtnf_cmd_get_chan_stats(struct qtnf_wmac *mac, u16 channel,
2262                             struct qtnf_chan_stats *stats)
2263 {
2264         struct sk_buff *cmd_skb, *resp_skb = NULL;
2265         struct qlink_cmd_get_chan_stats *cmd;
2266         struct qlink_resp_get_chan_stats *resp;
2267         size_t var_data_len;
2268         u16 res_code = QLINK_CMD_RESULT_OK;
2269         int ret = 0;
2270
2271         cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, QLINK_VIFID_RSVD,
2272                                             QLINK_CMD_CHAN_STATS,
2273                                             sizeof(*cmd));
2274         if (!cmd_skb)
2275                 return -ENOMEM;
2276
2277         qtnf_bus_lock(mac->bus);
2278
2279         cmd = (struct qlink_cmd_get_chan_stats *)cmd_skb->data;
2280         cmd->channel = cpu_to_le16(channel);
2281
2282         ret = qtnf_cmd_send_with_reply(mac->bus, cmd_skb, &resp_skb, &res_code,
2283                                        sizeof(*resp), &var_data_len);
2284         if (unlikely(ret)) {
2285                 qtnf_bus_unlock(mac->bus);
2286                 return ret;
2287         }
2288
2289         if (unlikely(res_code != QLINK_CMD_RESULT_OK)) {
2290                 switch (res_code) {
2291                 case QLINK_CMD_RESULT_ENOTFOUND:
2292                         ret = -ENOENT;
2293                         break;
2294                 default:
2295                         pr_err("cmd exec failed: 0x%.4X\n", res_code);
2296                         ret = -EFAULT;
2297                         break;
2298                 }
2299                 goto out;
2300         }
2301
2302         resp = (struct qlink_resp_get_chan_stats *)resp_skb->data;
2303         ret = qtnf_cmd_resp_proc_chan_stat_info(stats, resp->info,
2304                                                 var_data_len);
2305
2306 out:
2307         qtnf_bus_unlock(mac->bus);
2308         consume_skb(resp_skb);
2309         return ret;
2310 }
2311
2312 int qtnf_cmd_send_chan_switch(struct qtnf_wmac *mac,
2313                               struct cfg80211_csa_settings *params)
2314 {
2315         struct qlink_cmd_chan_switch *cmd;
2316         struct sk_buff *cmd_skb;
2317         u16 res_code = QLINK_CMD_RESULT_OK;
2318         int ret;
2319
2320         cmd_skb = qtnf_cmd_alloc_new_cmdskb(mac->macid, 0x0,
2321                                             QLINK_CMD_CHAN_SWITCH,
2322                                             sizeof(*cmd));
2323
2324         if (unlikely(!cmd_skb))
2325                 return -ENOMEM;
2326
2327         qtnf_bus_lock(mac->bus);
2328
2329         cmd = (struct qlink_cmd_chan_switch *)cmd_skb->data;
2330         cmd->channel = cpu_to_le16(params->chandef.chan->hw_value);
2331         cmd->radar_required = params->radar_required;
2332         cmd->block_tx = params->block_tx;
2333         cmd->beacon_count = params->count;
2334
2335         ret = qtnf_cmd_send(mac->bus, cmd_skb, &res_code);
2336
2337         if (unlikely(ret))
2338                 goto out;
2339
2340         switch (res_code) {
2341         case QLINK_CMD_RESULT_OK:
2342                 memcpy(&mac->csa_chandef, &params->chandef,
2343                        sizeof(mac->csa_chandef));
2344                 mac->status |= QTNF_MAC_CSA_ACTIVE;
2345                 ret = 0;
2346                 break;
2347         case QLINK_CMD_RESULT_ENOTFOUND:
2348                 ret = -ENOENT;
2349                 break;
2350         case QLINK_CMD_RESULT_ENOTSUPP:
2351                 ret = -EOPNOTSUPP;
2352                 break;
2353         case QLINK_CMD_RESULT_EALREADY:
2354                 ret = -EALREADY;
2355                 break;
2356         case QLINK_CMD_RESULT_INVALID:
2357         default:
2358                 ret = -EFAULT;
2359                 break;
2360         }
2361
2362 out:
2363         qtnf_bus_unlock(mac->bus);
2364         return ret;
2365 }