]> git.kernelconcepts.de Git - karo-tx-linux.git/blob - drivers/net/wireless/ath/ath10k/wmi-tlv.c
ath10k: fix potential memory leak in ath10k_wmi_tlv_op_pull_fw_stats()
[karo-tx-linux.git] / drivers / net / wireless / ath / ath10k / wmi-tlv.c
1 /*
2  * Copyright (c) 2005-2011 Atheros Communications Inc.
3  * Copyright (c) 2011-2014 Qualcomm Atheros, Inc.
4  *
5  * Permission to use, copy, modify, and/or distribute this software for any
6  * purpose with or without fee is hereby granted, provided that the above
7  * copyright notice and this permission notice appear in all copies.
8  *
9  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16  */
17 #include "core.h"
18 #include "debug.h"
19 #include "mac.h"
20 #include "hw.h"
21 #include "mac.h"
22 #include "wmi.h"
23 #include "wmi-ops.h"
24 #include "wmi-tlv.h"
25 #include "p2p.h"
26 #include "testmode.h"
27
28 /***************/
29 /* TLV helpers */
30 /**************/
31
32 struct wmi_tlv_policy {
33         size_t min_len;
34 };
35
36 static const struct wmi_tlv_policy wmi_tlv_policies[] = {
37         [WMI_TLV_TAG_ARRAY_BYTE]
38                 = { .min_len = 0 },
39         [WMI_TLV_TAG_ARRAY_UINT32]
40                 = { .min_len = 0 },
41         [WMI_TLV_TAG_STRUCT_SCAN_EVENT]
42                 = { .min_len = sizeof(struct wmi_scan_event) },
43         [WMI_TLV_TAG_STRUCT_MGMT_RX_HDR]
44                 = { .min_len = sizeof(struct wmi_tlv_mgmt_rx_ev) },
45         [WMI_TLV_TAG_STRUCT_CHAN_INFO_EVENT]
46                 = { .min_len = sizeof(struct wmi_chan_info_event) },
47         [WMI_TLV_TAG_STRUCT_VDEV_START_RESPONSE_EVENT]
48                 = { .min_len = sizeof(struct wmi_vdev_start_response_event) },
49         [WMI_TLV_TAG_STRUCT_PEER_STA_KICKOUT_EVENT]
50                 = { .min_len = sizeof(struct wmi_peer_sta_kickout_event) },
51         [WMI_TLV_TAG_STRUCT_HOST_SWBA_EVENT]
52                 = { .min_len = sizeof(struct wmi_host_swba_event) },
53         [WMI_TLV_TAG_STRUCT_TIM_INFO]
54                 = { .min_len = sizeof(struct wmi_tim_info) },
55         [WMI_TLV_TAG_STRUCT_P2P_NOA_INFO]
56                 = { .min_len = sizeof(struct wmi_p2p_noa_info) },
57         [WMI_TLV_TAG_STRUCT_SERVICE_READY_EVENT]
58                 = { .min_len = sizeof(struct wmi_tlv_svc_rdy_ev) },
59         [WMI_TLV_TAG_STRUCT_HAL_REG_CAPABILITIES]
60                 = { .min_len = sizeof(struct hal_reg_capabilities) },
61         [WMI_TLV_TAG_STRUCT_WLAN_HOST_MEM_REQ]
62                 = { .min_len = sizeof(struct wlan_host_mem_req) },
63         [WMI_TLV_TAG_STRUCT_READY_EVENT]
64                 = { .min_len = sizeof(struct wmi_tlv_rdy_ev) },
65         [WMI_TLV_TAG_STRUCT_OFFLOAD_BCN_TX_STATUS_EVENT]
66                 = { .min_len = sizeof(struct wmi_tlv_bcn_tx_status_ev) },
67         [WMI_TLV_TAG_STRUCT_DIAG_DATA_CONTAINER_EVENT]
68                 = { .min_len = sizeof(struct wmi_tlv_diag_data_ev) },
69         [WMI_TLV_TAG_STRUCT_P2P_NOA_EVENT]
70                 = { .min_len = sizeof(struct wmi_tlv_p2p_noa_ev) },
71         [WMI_TLV_TAG_STRUCT_ROAM_EVENT]
72                 = { .min_len = sizeof(struct wmi_tlv_roam_ev) },
73         [WMI_TLV_TAG_STRUCT_WOW_EVENT_INFO]
74                 = { .min_len = sizeof(struct wmi_tlv_wow_event_info) },
75         [WMI_TLV_TAG_STRUCT_TX_PAUSE_EVENT]
76                 = { .min_len = sizeof(struct wmi_tlv_tx_pause_ev) },
77 };
78
79 static int
80 ath10k_wmi_tlv_iter(struct ath10k *ar, const void *ptr, size_t len,
81                     int (*iter)(struct ath10k *ar, u16 tag, u16 len,
82                                 const void *ptr, void *data),
83                     void *data)
84 {
85         const void *begin = ptr;
86         const struct wmi_tlv *tlv;
87         u16 tlv_tag, tlv_len;
88         int ret;
89
90         while (len > 0) {
91                 if (len < sizeof(*tlv)) {
92                         ath10k_dbg(ar, ATH10K_DBG_WMI,
93                                    "wmi tlv parse failure at byte %zd (%zu bytes left, %zu expected)\n",
94                                    ptr - begin, len, sizeof(*tlv));
95                         return -EINVAL;
96                 }
97
98                 tlv = ptr;
99                 tlv_tag = __le16_to_cpu(tlv->tag);
100                 tlv_len = __le16_to_cpu(tlv->len);
101                 ptr += sizeof(*tlv);
102                 len -= sizeof(*tlv);
103
104                 if (tlv_len > len) {
105                         ath10k_dbg(ar, ATH10K_DBG_WMI,
106                                    "wmi tlv parse failure of tag %hhu at byte %zd (%zu bytes left, %hhu expected)\n",
107                                    tlv_tag, ptr - begin, len, tlv_len);
108                         return -EINVAL;
109                 }
110
111                 if (tlv_tag < ARRAY_SIZE(wmi_tlv_policies) &&
112                     wmi_tlv_policies[tlv_tag].min_len &&
113                     wmi_tlv_policies[tlv_tag].min_len > tlv_len) {
114                         ath10k_dbg(ar, ATH10K_DBG_WMI,
115                                    "wmi tlv parse failure of tag %hhu at byte %zd (%hhu bytes is less than min length %zu)\n",
116                                    tlv_tag, ptr - begin, tlv_len,
117                                    wmi_tlv_policies[tlv_tag].min_len);
118                         return -EINVAL;
119                 }
120
121                 ret = iter(ar, tlv_tag, tlv_len, ptr, data);
122                 if (ret)
123                         return ret;
124
125                 ptr += tlv_len;
126                 len -= tlv_len;
127         }
128
129         return 0;
130 }
131
132 static int ath10k_wmi_tlv_iter_parse(struct ath10k *ar, u16 tag, u16 len,
133                                      const void *ptr, void *data)
134 {
135         const void **tb = data;
136
137         if (tag < WMI_TLV_TAG_MAX)
138                 tb[tag] = ptr;
139
140         return 0;
141 }
142
143 static int ath10k_wmi_tlv_parse(struct ath10k *ar, const void **tb,
144                                 const void *ptr, size_t len)
145 {
146         return ath10k_wmi_tlv_iter(ar, ptr, len, ath10k_wmi_tlv_iter_parse,
147                                    (void *)tb);
148 }
149
150 static const void **
151 ath10k_wmi_tlv_parse_alloc(struct ath10k *ar, const void *ptr,
152                            size_t len, gfp_t gfp)
153 {
154         const void **tb;
155         int ret;
156
157         tb = kzalloc(sizeof(*tb) * WMI_TLV_TAG_MAX, gfp);
158         if (!tb)
159                 return ERR_PTR(-ENOMEM);
160
161         ret = ath10k_wmi_tlv_parse(ar, tb, ptr, len);
162         if (ret) {
163                 kfree(tb);
164                 return ERR_PTR(ret);
165         }
166
167         return tb;
168 }
169
170 static u16 ath10k_wmi_tlv_len(const void *ptr)
171 {
172         return __le16_to_cpu((((const struct wmi_tlv *)ptr) - 1)->len);
173 }
174
175 /**************/
176 /* TLV events */
177 /**************/
178 static int ath10k_wmi_tlv_event_bcn_tx_status(struct ath10k *ar,
179                                               struct sk_buff *skb)
180 {
181         const void **tb;
182         const struct wmi_tlv_bcn_tx_status_ev *ev;
183         struct ath10k_vif *arvif;
184         u32 vdev_id, tx_status;
185         int ret;
186
187         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
188         if (IS_ERR(tb)) {
189                 ret = PTR_ERR(tb);
190                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
191                 return ret;
192         }
193
194         ev = tb[WMI_TLV_TAG_STRUCT_OFFLOAD_BCN_TX_STATUS_EVENT];
195         if (!ev) {
196                 kfree(tb);
197                 return -EPROTO;
198         }
199
200         tx_status = __le32_to_cpu(ev->tx_status);
201         vdev_id = __le32_to_cpu(ev->vdev_id);
202
203         switch (tx_status) {
204         case WMI_TLV_BCN_TX_STATUS_OK:
205                 break;
206         case WMI_TLV_BCN_TX_STATUS_XRETRY:
207         case WMI_TLV_BCN_TX_STATUS_DROP:
208         case WMI_TLV_BCN_TX_STATUS_FILTERED:
209                 /* FIXME: It's probably worth telling mac80211 to stop the
210                  * interface as it is crippled.
211                  */
212                 ath10k_warn(ar, "received bcn tmpl tx status on vdev %i: %d",
213                             vdev_id, tx_status);
214                 break;
215         }
216
217         arvif = ath10k_get_arvif(ar, vdev_id);
218         if (arvif && arvif->is_up && arvif->vif->csa_active)
219                 ieee80211_queue_work(ar->hw, &arvif->ap_csa_work);
220
221         kfree(tb);
222         return 0;
223 }
224
225 static int ath10k_wmi_tlv_event_diag_data(struct ath10k *ar,
226                                           struct sk_buff *skb)
227 {
228         const void **tb;
229         const struct wmi_tlv_diag_data_ev *ev;
230         const struct wmi_tlv_diag_item *item;
231         const void *data;
232         int ret, num_items, len;
233
234         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
235         if (IS_ERR(tb)) {
236                 ret = PTR_ERR(tb);
237                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
238                 return ret;
239         }
240
241         ev = tb[WMI_TLV_TAG_STRUCT_DIAG_DATA_CONTAINER_EVENT];
242         data = tb[WMI_TLV_TAG_ARRAY_BYTE];
243         if (!ev || !data) {
244                 kfree(tb);
245                 return -EPROTO;
246         }
247
248         num_items = __le32_to_cpu(ev->num_items);
249         len = ath10k_wmi_tlv_len(data);
250
251         while (num_items--) {
252                 if (len == 0)
253                         break;
254                 if (len < sizeof(*item)) {
255                         ath10k_warn(ar, "failed to parse diag data: can't fit item header\n");
256                         break;
257                 }
258
259                 item = data;
260
261                 if (len < sizeof(*item) + __le16_to_cpu(item->len)) {
262                         ath10k_warn(ar, "failed to parse diag data: item is too long\n");
263                         break;
264                 }
265
266                 trace_ath10k_wmi_diag_container(ar,
267                                                 item->type,
268                                                 __le32_to_cpu(item->timestamp),
269                                                 __le32_to_cpu(item->code),
270                                                 __le16_to_cpu(item->len),
271                                                 item->payload);
272
273                 len -= sizeof(*item);
274                 len -= roundup(__le16_to_cpu(item->len), 4);
275
276                 data += sizeof(*item);
277                 data += roundup(__le16_to_cpu(item->len), 4);
278         }
279
280         if (num_items != -1 || len != 0)
281                 ath10k_warn(ar, "failed to parse diag data event: num_items %d len %d\n",
282                             num_items, len);
283
284         kfree(tb);
285         return 0;
286 }
287
288 static int ath10k_wmi_tlv_event_diag(struct ath10k *ar,
289                                      struct sk_buff *skb)
290 {
291         const void **tb;
292         const void *data;
293         int ret, len;
294
295         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
296         if (IS_ERR(tb)) {
297                 ret = PTR_ERR(tb);
298                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
299                 return ret;
300         }
301
302         data = tb[WMI_TLV_TAG_ARRAY_BYTE];
303         if (!data) {
304                 kfree(tb);
305                 return -EPROTO;
306         }
307         len = ath10k_wmi_tlv_len(data);
308
309         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv diag event len %d\n", len);
310         trace_ath10k_wmi_diag(ar, data, len);
311
312         kfree(tb);
313         return 0;
314 }
315
316 static int ath10k_wmi_tlv_event_p2p_noa(struct ath10k *ar,
317                                         struct sk_buff *skb)
318 {
319         const void **tb;
320         const struct wmi_tlv_p2p_noa_ev *ev;
321         const struct wmi_p2p_noa_info *noa;
322         int ret, vdev_id;
323
324         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
325         if (IS_ERR(tb)) {
326                 ret = PTR_ERR(tb);
327                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
328                 return ret;
329         }
330
331         ev = tb[WMI_TLV_TAG_STRUCT_P2P_NOA_EVENT];
332         noa = tb[WMI_TLV_TAG_STRUCT_P2P_NOA_INFO];
333
334         if (!ev || !noa) {
335                 kfree(tb);
336                 return -EPROTO;
337         }
338
339         vdev_id = __le32_to_cpu(ev->vdev_id);
340
341         ath10k_dbg(ar, ATH10K_DBG_WMI,
342                    "wmi tlv p2p noa vdev_id %i descriptors %hhu\n",
343                    vdev_id, noa->num_descriptors);
344
345         ath10k_p2p_noa_update_by_vdev_id(ar, vdev_id, noa);
346         kfree(tb);
347         return 0;
348 }
349
350 static int ath10k_wmi_tlv_event_tx_pause(struct ath10k *ar,
351                                          struct sk_buff *skb)
352 {
353         const void **tb;
354         const struct wmi_tlv_tx_pause_ev *ev;
355         int ret, vdev_id;
356         u32 pause_id, action, vdev_map, peer_id, tid_map;
357
358         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
359         if (IS_ERR(tb)) {
360                 ret = PTR_ERR(tb);
361                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
362                 return ret;
363         }
364
365         ev = tb[WMI_TLV_TAG_STRUCT_TX_PAUSE_EVENT];
366         if (!ev) {
367                 kfree(tb);
368                 return -EPROTO;
369         }
370
371         pause_id = __le32_to_cpu(ev->pause_id);
372         action = __le32_to_cpu(ev->action);
373         vdev_map = __le32_to_cpu(ev->vdev_map);
374         peer_id = __le32_to_cpu(ev->peer_id);
375         tid_map = __le32_to_cpu(ev->tid_map);
376
377         ath10k_dbg(ar, ATH10K_DBG_WMI,
378                    "wmi tlv tx pause pause_id %u action %u vdev_map 0x%08x peer_id %u tid_map 0x%08x\n",
379                    pause_id, action, vdev_map, peer_id, tid_map);
380
381         switch (pause_id) {
382         case WMI_TLV_TX_PAUSE_ID_MCC:
383         case WMI_TLV_TX_PAUSE_ID_P2P_CLI_NOA:
384         case WMI_TLV_TX_PAUSE_ID_P2P_GO_PS:
385         case WMI_TLV_TX_PAUSE_ID_AP_PS:
386         case WMI_TLV_TX_PAUSE_ID_IBSS_PS:
387                 for (vdev_id = 0; vdev_map; vdev_id++) {
388                         if (!(vdev_map & BIT(vdev_id)))
389                                 continue;
390
391                         vdev_map &= ~BIT(vdev_id);
392                         ath10k_mac_handle_tx_pause_vdev(ar, vdev_id, pause_id,
393                                                         action);
394                 }
395                 break;
396         case WMI_TLV_TX_PAUSE_ID_AP_PEER_PS:
397         case WMI_TLV_TX_PAUSE_ID_AP_PEER_UAPSD:
398         case WMI_TLV_TX_PAUSE_ID_STA_ADD_BA:
399         case WMI_TLV_TX_PAUSE_ID_HOST:
400                 ath10k_dbg(ar, ATH10K_DBG_MAC,
401                            "mac ignoring unsupported tx pause id %d\n",
402                            pause_id);
403                 break;
404         default:
405                 ath10k_dbg(ar, ATH10K_DBG_MAC,
406                            "mac ignoring unknown tx pause vdev %d\n",
407                            pause_id);
408                 break;
409         }
410
411         kfree(tb);
412         return 0;
413 }
414
415 /***********/
416 /* TLV ops */
417 /***********/
418
419 static void ath10k_wmi_tlv_op_rx(struct ath10k *ar, struct sk_buff *skb)
420 {
421         struct wmi_cmd_hdr *cmd_hdr;
422         enum wmi_tlv_event_id id;
423         bool consumed;
424
425         cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
426         id = MS(__le32_to_cpu(cmd_hdr->cmd_id), WMI_CMD_HDR_CMD_ID);
427
428         if (skb_pull(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
429                 goto out;
430
431         trace_ath10k_wmi_event(ar, id, skb->data, skb->len);
432
433         consumed = ath10k_tm_event_wmi(ar, id, skb);
434
435         /* Ready event must be handled normally also in UTF mode so that we
436          * know the UTF firmware has booted, others we are just bypass WMI
437          * events to testmode.
438          */
439         if (consumed && id != WMI_TLV_READY_EVENTID) {
440                 ath10k_dbg(ar, ATH10K_DBG_WMI,
441                            "wmi tlv testmode consumed 0x%x\n", id);
442                 goto out;
443         }
444
445         switch (id) {
446         case WMI_TLV_MGMT_RX_EVENTID:
447                 ath10k_wmi_event_mgmt_rx(ar, skb);
448                 /* mgmt_rx() owns the skb now! */
449                 return;
450         case WMI_TLV_SCAN_EVENTID:
451                 ath10k_wmi_event_scan(ar, skb);
452                 break;
453         case WMI_TLV_CHAN_INFO_EVENTID:
454                 ath10k_wmi_event_chan_info(ar, skb);
455                 break;
456         case WMI_TLV_ECHO_EVENTID:
457                 ath10k_wmi_event_echo(ar, skb);
458                 break;
459         case WMI_TLV_DEBUG_MESG_EVENTID:
460                 ath10k_wmi_event_debug_mesg(ar, skb);
461                 break;
462         case WMI_TLV_UPDATE_STATS_EVENTID:
463                 ath10k_wmi_event_update_stats(ar, skb);
464                 break;
465         case WMI_TLV_VDEV_START_RESP_EVENTID:
466                 ath10k_wmi_event_vdev_start_resp(ar, skb);
467                 break;
468         case WMI_TLV_VDEV_STOPPED_EVENTID:
469                 ath10k_wmi_event_vdev_stopped(ar, skb);
470                 break;
471         case WMI_TLV_PEER_STA_KICKOUT_EVENTID:
472                 ath10k_wmi_event_peer_sta_kickout(ar, skb);
473                 break;
474         case WMI_TLV_HOST_SWBA_EVENTID:
475                 ath10k_wmi_event_host_swba(ar, skb);
476                 break;
477         case WMI_TLV_TBTTOFFSET_UPDATE_EVENTID:
478                 ath10k_wmi_event_tbttoffset_update(ar, skb);
479                 break;
480         case WMI_TLV_PHYERR_EVENTID:
481                 ath10k_wmi_event_phyerr(ar, skb);
482                 break;
483         case WMI_TLV_ROAM_EVENTID:
484                 ath10k_wmi_event_roam(ar, skb);
485                 break;
486         case WMI_TLV_PROFILE_MATCH:
487                 ath10k_wmi_event_profile_match(ar, skb);
488                 break;
489         case WMI_TLV_DEBUG_PRINT_EVENTID:
490                 ath10k_wmi_event_debug_print(ar, skb);
491                 break;
492         case WMI_TLV_PDEV_QVIT_EVENTID:
493                 ath10k_wmi_event_pdev_qvit(ar, skb);
494                 break;
495         case WMI_TLV_WLAN_PROFILE_DATA_EVENTID:
496                 ath10k_wmi_event_wlan_profile_data(ar, skb);
497                 break;
498         case WMI_TLV_RTT_MEASUREMENT_REPORT_EVENTID:
499                 ath10k_wmi_event_rtt_measurement_report(ar, skb);
500                 break;
501         case WMI_TLV_TSF_MEASUREMENT_REPORT_EVENTID:
502                 ath10k_wmi_event_tsf_measurement_report(ar, skb);
503                 break;
504         case WMI_TLV_RTT_ERROR_REPORT_EVENTID:
505                 ath10k_wmi_event_rtt_error_report(ar, skb);
506                 break;
507         case WMI_TLV_WOW_WAKEUP_HOST_EVENTID:
508                 ath10k_wmi_event_wow_wakeup_host(ar, skb);
509                 break;
510         case WMI_TLV_DCS_INTERFERENCE_EVENTID:
511                 ath10k_wmi_event_dcs_interference(ar, skb);
512                 break;
513         case WMI_TLV_PDEV_TPC_CONFIG_EVENTID:
514                 ath10k_wmi_event_pdev_tpc_config(ar, skb);
515                 break;
516         case WMI_TLV_PDEV_FTM_INTG_EVENTID:
517                 ath10k_wmi_event_pdev_ftm_intg(ar, skb);
518                 break;
519         case WMI_TLV_GTK_OFFLOAD_STATUS_EVENTID:
520                 ath10k_wmi_event_gtk_offload_status(ar, skb);
521                 break;
522         case WMI_TLV_GTK_REKEY_FAIL_EVENTID:
523                 ath10k_wmi_event_gtk_rekey_fail(ar, skb);
524                 break;
525         case WMI_TLV_TX_DELBA_COMPLETE_EVENTID:
526                 ath10k_wmi_event_delba_complete(ar, skb);
527                 break;
528         case WMI_TLV_TX_ADDBA_COMPLETE_EVENTID:
529                 ath10k_wmi_event_addba_complete(ar, skb);
530                 break;
531         case WMI_TLV_VDEV_INSTALL_KEY_COMPLETE_EVENTID:
532                 ath10k_wmi_event_vdev_install_key_complete(ar, skb);
533                 break;
534         case WMI_TLV_SERVICE_READY_EVENTID:
535                 ath10k_wmi_event_service_ready(ar, skb);
536                 return;
537         case WMI_TLV_READY_EVENTID:
538                 ath10k_wmi_event_ready(ar, skb);
539                 break;
540         case WMI_TLV_OFFLOAD_BCN_TX_STATUS_EVENTID:
541                 ath10k_wmi_tlv_event_bcn_tx_status(ar, skb);
542                 break;
543         case WMI_TLV_DIAG_DATA_CONTAINER_EVENTID:
544                 ath10k_wmi_tlv_event_diag_data(ar, skb);
545                 break;
546         case WMI_TLV_DIAG_EVENTID:
547                 ath10k_wmi_tlv_event_diag(ar, skb);
548                 break;
549         case WMI_TLV_P2P_NOA_EVENTID:
550                 ath10k_wmi_tlv_event_p2p_noa(ar, skb);
551                 break;
552         case WMI_TLV_TX_PAUSE_EVENTID:
553                 ath10k_wmi_tlv_event_tx_pause(ar, skb);
554                 break;
555         default:
556                 ath10k_warn(ar, "Unknown eventid: %d\n", id);
557                 break;
558         }
559
560 out:
561         dev_kfree_skb(skb);
562 }
563
564 static int ath10k_wmi_tlv_op_pull_scan_ev(struct ath10k *ar,
565                                           struct sk_buff *skb,
566                                           struct wmi_scan_ev_arg *arg)
567 {
568         const void **tb;
569         const struct wmi_scan_event *ev;
570         int ret;
571
572         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
573         if (IS_ERR(tb)) {
574                 ret = PTR_ERR(tb);
575                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
576                 return ret;
577         }
578
579         ev = tb[WMI_TLV_TAG_STRUCT_SCAN_EVENT];
580         if (!ev) {
581                 kfree(tb);
582                 return -EPROTO;
583         }
584
585         arg->event_type = ev->event_type;
586         arg->reason = ev->reason;
587         arg->channel_freq = ev->channel_freq;
588         arg->scan_req_id = ev->scan_req_id;
589         arg->scan_id = ev->scan_id;
590         arg->vdev_id = ev->vdev_id;
591
592         kfree(tb);
593         return 0;
594 }
595
596 static int ath10k_wmi_tlv_op_pull_mgmt_rx_ev(struct ath10k *ar,
597                                              struct sk_buff *skb,
598                                              struct wmi_mgmt_rx_ev_arg *arg)
599 {
600         const void **tb;
601         const struct wmi_tlv_mgmt_rx_ev *ev;
602         const u8 *frame;
603         u32 msdu_len;
604         int ret;
605
606         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
607         if (IS_ERR(tb)) {
608                 ret = PTR_ERR(tb);
609                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
610                 return ret;
611         }
612
613         ev = tb[WMI_TLV_TAG_STRUCT_MGMT_RX_HDR];
614         frame = tb[WMI_TLV_TAG_ARRAY_BYTE];
615
616         if (!ev || !frame) {
617                 kfree(tb);
618                 return -EPROTO;
619         }
620
621         arg->channel = ev->channel;
622         arg->buf_len = ev->buf_len;
623         arg->status = ev->status;
624         arg->snr = ev->snr;
625         arg->phy_mode = ev->phy_mode;
626         arg->rate = ev->rate;
627
628         msdu_len = __le32_to_cpu(arg->buf_len);
629
630         if (skb->len < (frame - skb->data) + msdu_len) {
631                 kfree(tb);
632                 return -EPROTO;
633         }
634
635         /* shift the sk_buff to point to `frame` */
636         skb_trim(skb, 0);
637         skb_put(skb, frame - skb->data);
638         skb_pull(skb, frame - skb->data);
639         skb_put(skb, msdu_len);
640
641         kfree(tb);
642         return 0;
643 }
644
645 static int ath10k_wmi_tlv_op_pull_ch_info_ev(struct ath10k *ar,
646                                              struct sk_buff *skb,
647                                              struct wmi_ch_info_ev_arg *arg)
648 {
649         const void **tb;
650         const struct wmi_chan_info_event *ev;
651         int ret;
652
653         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
654         if (IS_ERR(tb)) {
655                 ret = PTR_ERR(tb);
656                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
657                 return ret;
658         }
659
660         ev = tb[WMI_TLV_TAG_STRUCT_CHAN_INFO_EVENT];
661         if (!ev) {
662                 kfree(tb);
663                 return -EPROTO;
664         }
665
666         arg->err_code = ev->err_code;
667         arg->freq = ev->freq;
668         arg->cmd_flags = ev->cmd_flags;
669         arg->noise_floor = ev->noise_floor;
670         arg->rx_clear_count = ev->rx_clear_count;
671         arg->cycle_count = ev->cycle_count;
672
673         kfree(tb);
674         return 0;
675 }
676
677 static int
678 ath10k_wmi_tlv_op_pull_vdev_start_ev(struct ath10k *ar, struct sk_buff *skb,
679                                      struct wmi_vdev_start_ev_arg *arg)
680 {
681         const void **tb;
682         const struct wmi_vdev_start_response_event *ev;
683         int ret;
684
685         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
686         if (IS_ERR(tb)) {
687                 ret = PTR_ERR(tb);
688                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
689                 return ret;
690         }
691
692         ev = tb[WMI_TLV_TAG_STRUCT_VDEV_START_RESPONSE_EVENT];
693         if (!ev) {
694                 kfree(tb);
695                 return -EPROTO;
696         }
697
698         skb_pull(skb, sizeof(*ev));
699         arg->vdev_id = ev->vdev_id;
700         arg->req_id = ev->req_id;
701         arg->resp_type = ev->resp_type;
702         arg->status = ev->status;
703
704         kfree(tb);
705         return 0;
706 }
707
708 static int ath10k_wmi_tlv_op_pull_peer_kick_ev(struct ath10k *ar,
709                                                struct sk_buff *skb,
710                                                struct wmi_peer_kick_ev_arg *arg)
711 {
712         const void **tb;
713         const struct wmi_peer_sta_kickout_event *ev;
714         int ret;
715
716         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
717         if (IS_ERR(tb)) {
718                 ret = PTR_ERR(tb);
719                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
720                 return ret;
721         }
722
723         ev = tb[WMI_TLV_TAG_STRUCT_PEER_STA_KICKOUT_EVENT];
724         if (!ev) {
725                 kfree(tb);
726                 return -EPROTO;
727         }
728
729         arg->mac_addr = ev->peer_macaddr.addr;
730
731         kfree(tb);
732         return 0;
733 }
734
735 struct wmi_tlv_swba_parse {
736         const struct wmi_host_swba_event *ev;
737         bool tim_done;
738         bool noa_done;
739         size_t n_tim;
740         size_t n_noa;
741         struct wmi_swba_ev_arg *arg;
742 };
743
744 static int ath10k_wmi_tlv_swba_tim_parse(struct ath10k *ar, u16 tag, u16 len,
745                                          const void *ptr, void *data)
746 {
747         struct wmi_tlv_swba_parse *swba = data;
748         struct wmi_tim_info_arg *tim_info_arg;
749         const struct wmi_tim_info *tim_info_ev = ptr;
750
751         if (tag != WMI_TLV_TAG_STRUCT_TIM_INFO)
752                 return -EPROTO;
753
754         if (swba->n_tim >= ARRAY_SIZE(swba->arg->tim_info))
755                 return -ENOBUFS;
756
757         if (__le32_to_cpu(tim_info_ev->tim_len) >
758              sizeof(tim_info_ev->tim_bitmap)) {
759                 ath10k_warn(ar, "refusing to parse invalid swba structure\n");
760                 return -EPROTO;
761         }
762
763         tim_info_arg = &swba->arg->tim_info[swba->n_tim];
764         tim_info_arg->tim_len = tim_info_ev->tim_len;
765         tim_info_arg->tim_mcast = tim_info_ev->tim_mcast;
766         tim_info_arg->tim_bitmap = tim_info_ev->tim_bitmap;
767         tim_info_arg->tim_changed = tim_info_ev->tim_changed;
768         tim_info_arg->tim_num_ps_pending = tim_info_ev->tim_num_ps_pending;
769
770         swba->n_tim++;
771
772         return 0;
773 }
774
775 static int ath10k_wmi_tlv_swba_noa_parse(struct ath10k *ar, u16 tag, u16 len,
776                                          const void *ptr, void *data)
777 {
778         struct wmi_tlv_swba_parse *swba = data;
779
780         if (tag != WMI_TLV_TAG_STRUCT_P2P_NOA_INFO)
781                 return -EPROTO;
782
783         if (swba->n_noa >= ARRAY_SIZE(swba->arg->noa_info))
784                 return -ENOBUFS;
785
786         swba->arg->noa_info[swba->n_noa++] = ptr;
787         return 0;
788 }
789
790 static int ath10k_wmi_tlv_swba_parse(struct ath10k *ar, u16 tag, u16 len,
791                                      const void *ptr, void *data)
792 {
793         struct wmi_tlv_swba_parse *swba = data;
794         int ret;
795
796         switch (tag) {
797         case WMI_TLV_TAG_STRUCT_HOST_SWBA_EVENT:
798                 swba->ev = ptr;
799                 break;
800         case WMI_TLV_TAG_ARRAY_STRUCT:
801                 if (!swba->tim_done) {
802                         swba->tim_done = true;
803                         ret = ath10k_wmi_tlv_iter(ar, ptr, len,
804                                                   ath10k_wmi_tlv_swba_tim_parse,
805                                                   swba);
806                         if (ret)
807                                 return ret;
808                 } else if (!swba->noa_done) {
809                         swba->noa_done = true;
810                         ret = ath10k_wmi_tlv_iter(ar, ptr, len,
811                                                   ath10k_wmi_tlv_swba_noa_parse,
812                                                   swba);
813                         if (ret)
814                                 return ret;
815                 }
816                 break;
817         default:
818                 break;
819         }
820         return 0;
821 }
822
823 static int ath10k_wmi_tlv_op_pull_swba_ev(struct ath10k *ar,
824                                           struct sk_buff *skb,
825                                           struct wmi_swba_ev_arg *arg)
826 {
827         struct wmi_tlv_swba_parse swba = { .arg = arg };
828         u32 map;
829         size_t n_vdevs;
830         int ret;
831
832         ret = ath10k_wmi_tlv_iter(ar, skb->data, skb->len,
833                                   ath10k_wmi_tlv_swba_parse, &swba);
834         if (ret) {
835                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
836                 return ret;
837         }
838
839         if (!swba.ev)
840                 return -EPROTO;
841
842         arg->vdev_map = swba.ev->vdev_map;
843
844         for (map = __le32_to_cpu(arg->vdev_map), n_vdevs = 0; map; map >>= 1)
845                 if (map & BIT(0))
846                         n_vdevs++;
847
848         if (n_vdevs != swba.n_tim ||
849             n_vdevs != swba.n_noa)
850                 return -EPROTO;
851
852         return 0;
853 }
854
855 static int ath10k_wmi_tlv_op_pull_phyerr_ev_hdr(struct ath10k *ar,
856                                                 struct sk_buff *skb,
857                                                 struct wmi_phyerr_hdr_arg *arg)
858 {
859         const void **tb;
860         const struct wmi_tlv_phyerr_ev *ev;
861         const void *phyerrs;
862         int ret;
863
864         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
865         if (IS_ERR(tb)) {
866                 ret = PTR_ERR(tb);
867                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
868                 return ret;
869         }
870
871         ev = tb[WMI_TLV_TAG_STRUCT_COMB_PHYERR_RX_HDR];
872         phyerrs = tb[WMI_TLV_TAG_ARRAY_BYTE];
873
874         if (!ev || !phyerrs) {
875                 kfree(tb);
876                 return -EPROTO;
877         }
878
879         arg->num_phyerrs  = __le32_to_cpu(ev->num_phyerrs);
880         arg->tsf_l32 = __le32_to_cpu(ev->tsf_l32);
881         arg->tsf_u32 = __le32_to_cpu(ev->tsf_u32);
882         arg->buf_len = __le32_to_cpu(ev->buf_len);
883         arg->phyerrs = phyerrs;
884
885         kfree(tb);
886         return 0;
887 }
888
889 #define WMI_TLV_ABI_VER_NS0 0x5F414351
890 #define WMI_TLV_ABI_VER_NS1 0x00004C4D
891 #define WMI_TLV_ABI_VER_NS2 0x00000000
892 #define WMI_TLV_ABI_VER_NS3 0x00000000
893
894 #define WMI_TLV_ABI_VER0_MAJOR 1
895 #define WMI_TLV_ABI_VER0_MINOR 0
896 #define WMI_TLV_ABI_VER0 ((((WMI_TLV_ABI_VER0_MAJOR) << 24) & 0xFF000000) | \
897                           (((WMI_TLV_ABI_VER0_MINOR) <<  0) & 0x00FFFFFF))
898 #define WMI_TLV_ABI_VER1 53
899
900 static int
901 ath10k_wmi_tlv_parse_mem_reqs(struct ath10k *ar, u16 tag, u16 len,
902                               const void *ptr, void *data)
903 {
904         struct wmi_svc_rdy_ev_arg *arg = data;
905         int i;
906
907         if (tag != WMI_TLV_TAG_STRUCT_WLAN_HOST_MEM_REQ)
908                 return -EPROTO;
909
910         for (i = 0; i < ARRAY_SIZE(arg->mem_reqs); i++) {
911                 if (!arg->mem_reqs[i]) {
912                         arg->mem_reqs[i] = ptr;
913                         return 0;
914                 }
915         }
916
917         return -ENOMEM;
918 }
919
920 static int ath10k_wmi_tlv_op_pull_svc_rdy_ev(struct ath10k *ar,
921                                              struct sk_buff *skb,
922                                              struct wmi_svc_rdy_ev_arg *arg)
923 {
924         const void **tb;
925         const struct hal_reg_capabilities *reg;
926         const struct wmi_tlv_svc_rdy_ev *ev;
927         const __le32 *svc_bmap;
928         const struct wlan_host_mem_req *mem_reqs;
929         int ret;
930
931         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
932         if (IS_ERR(tb)) {
933                 ret = PTR_ERR(tb);
934                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
935                 return ret;
936         }
937
938         ev = tb[WMI_TLV_TAG_STRUCT_SERVICE_READY_EVENT];
939         reg = tb[WMI_TLV_TAG_STRUCT_HAL_REG_CAPABILITIES];
940         svc_bmap = tb[WMI_TLV_TAG_ARRAY_UINT32];
941         mem_reqs = tb[WMI_TLV_TAG_ARRAY_STRUCT];
942
943         if (!ev || !reg || !svc_bmap || !mem_reqs) {
944                 kfree(tb);
945                 return -EPROTO;
946         }
947
948         /* This is an internal ABI compatibility check for WMI TLV so check it
949          * here instead of the generic WMI code.
950          */
951         ath10k_dbg(ar, ATH10K_DBG_WMI,
952                    "wmi tlv abi 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x\n",
953                    __le32_to_cpu(ev->abi.abi_ver0), WMI_TLV_ABI_VER0,
954                    __le32_to_cpu(ev->abi.abi_ver_ns0), WMI_TLV_ABI_VER_NS0,
955                    __le32_to_cpu(ev->abi.abi_ver_ns1), WMI_TLV_ABI_VER_NS1,
956                    __le32_to_cpu(ev->abi.abi_ver_ns2), WMI_TLV_ABI_VER_NS2,
957                    __le32_to_cpu(ev->abi.abi_ver_ns3), WMI_TLV_ABI_VER_NS3);
958
959         if (__le32_to_cpu(ev->abi.abi_ver0) != WMI_TLV_ABI_VER0 ||
960             __le32_to_cpu(ev->abi.abi_ver_ns0) != WMI_TLV_ABI_VER_NS0 ||
961             __le32_to_cpu(ev->abi.abi_ver_ns1) != WMI_TLV_ABI_VER_NS1 ||
962             __le32_to_cpu(ev->abi.abi_ver_ns2) != WMI_TLV_ABI_VER_NS2 ||
963             __le32_to_cpu(ev->abi.abi_ver_ns3) != WMI_TLV_ABI_VER_NS3) {
964                 kfree(tb);
965                 return -ENOTSUPP;
966         }
967
968         arg->min_tx_power = ev->hw_min_tx_power;
969         arg->max_tx_power = ev->hw_max_tx_power;
970         arg->ht_cap = ev->ht_cap_info;
971         arg->vht_cap = ev->vht_cap_info;
972         arg->sw_ver0 = ev->abi.abi_ver0;
973         arg->sw_ver1 = ev->abi.abi_ver1;
974         arg->fw_build = ev->fw_build_vers;
975         arg->phy_capab = ev->phy_capability;
976         arg->num_rf_chains = ev->num_rf_chains;
977         arg->eeprom_rd = reg->eeprom_rd;
978         arg->num_mem_reqs = ev->num_mem_reqs;
979         arg->service_map = svc_bmap;
980         arg->service_map_len = ath10k_wmi_tlv_len(svc_bmap);
981
982         ret = ath10k_wmi_tlv_iter(ar, mem_reqs, ath10k_wmi_tlv_len(mem_reqs),
983                                   ath10k_wmi_tlv_parse_mem_reqs, arg);
984         if (ret) {
985                 kfree(tb);
986                 ath10k_warn(ar, "failed to parse mem_reqs tlv: %d\n", ret);
987                 return ret;
988         }
989
990         kfree(tb);
991         return 0;
992 }
993
994 static int ath10k_wmi_tlv_op_pull_rdy_ev(struct ath10k *ar,
995                                          struct sk_buff *skb,
996                                          struct wmi_rdy_ev_arg *arg)
997 {
998         const void **tb;
999         const struct wmi_tlv_rdy_ev *ev;
1000         int ret;
1001
1002         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1003         if (IS_ERR(tb)) {
1004                 ret = PTR_ERR(tb);
1005                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1006                 return ret;
1007         }
1008
1009         ev = tb[WMI_TLV_TAG_STRUCT_READY_EVENT];
1010         if (!ev) {
1011                 kfree(tb);
1012                 return -EPROTO;
1013         }
1014
1015         arg->sw_version = ev->abi.abi_ver0;
1016         arg->abi_version = ev->abi.abi_ver1;
1017         arg->status = ev->status;
1018         arg->mac_addr = ev->mac_addr.addr;
1019
1020         kfree(tb);
1021         return 0;
1022 }
1023
1024 static void ath10k_wmi_tlv_pull_vdev_stats(const struct wmi_tlv_vdev_stats *src,
1025                                            struct ath10k_fw_stats_vdev *dst)
1026 {
1027         int i;
1028
1029         dst->vdev_id = __le32_to_cpu(src->vdev_id);
1030         dst->beacon_snr = __le32_to_cpu(src->beacon_snr);
1031         dst->data_snr = __le32_to_cpu(src->data_snr);
1032         dst->num_rx_frames = __le32_to_cpu(src->num_rx_frames);
1033         dst->num_rts_fail = __le32_to_cpu(src->num_rts_fail);
1034         dst->num_rts_success = __le32_to_cpu(src->num_rts_success);
1035         dst->num_rx_err = __le32_to_cpu(src->num_rx_err);
1036         dst->num_rx_discard = __le32_to_cpu(src->num_rx_discard);
1037         dst->num_tx_not_acked = __le32_to_cpu(src->num_tx_not_acked);
1038
1039         for (i = 0; i < ARRAY_SIZE(src->num_tx_frames); i++)
1040                 dst->num_tx_frames[i] =
1041                         __le32_to_cpu(src->num_tx_frames[i]);
1042
1043         for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_retries); i++)
1044                 dst->num_tx_frames_retries[i] =
1045                         __le32_to_cpu(src->num_tx_frames_retries[i]);
1046
1047         for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_failures); i++)
1048                 dst->num_tx_frames_failures[i] =
1049                         __le32_to_cpu(src->num_tx_frames_failures[i]);
1050
1051         for (i = 0; i < ARRAY_SIZE(src->tx_rate_history); i++)
1052                 dst->tx_rate_history[i] =
1053                         __le32_to_cpu(src->tx_rate_history[i]);
1054
1055         for (i = 0; i < ARRAY_SIZE(src->beacon_rssi_history); i++)
1056                 dst->beacon_rssi_history[i] =
1057                         __le32_to_cpu(src->beacon_rssi_history[i]);
1058 }
1059
1060 static int ath10k_wmi_tlv_op_pull_fw_stats(struct ath10k *ar,
1061                                            struct sk_buff *skb,
1062                                            struct ath10k_fw_stats *stats)
1063 {
1064         const void **tb;
1065         const struct wmi_tlv_stats_ev *ev;
1066         const void *data;
1067         u32 num_pdev_stats;
1068         u32 num_vdev_stats;
1069         u32 num_peer_stats;
1070         u32 num_bcnflt_stats;
1071         u32 num_chan_stats;
1072         size_t data_len;
1073         int ret;
1074         int i;
1075
1076         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1077         if (IS_ERR(tb)) {
1078                 ret = PTR_ERR(tb);
1079                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1080                 return ret;
1081         }
1082
1083         ev = tb[WMI_TLV_TAG_STRUCT_STATS_EVENT];
1084         data = tb[WMI_TLV_TAG_ARRAY_BYTE];
1085
1086         if (!ev || !data) {
1087                 kfree(tb);
1088                 return -EPROTO;
1089         }
1090
1091         data_len = ath10k_wmi_tlv_len(data);
1092         num_pdev_stats = __le32_to_cpu(ev->num_pdev_stats);
1093         num_vdev_stats = __le32_to_cpu(ev->num_vdev_stats);
1094         num_peer_stats = __le32_to_cpu(ev->num_peer_stats);
1095         num_bcnflt_stats = __le32_to_cpu(ev->num_bcnflt_stats);
1096         num_chan_stats = __le32_to_cpu(ev->num_chan_stats);
1097
1098         ath10k_dbg(ar, ATH10K_DBG_WMI,
1099                    "wmi tlv stats update pdev %i vdev %i peer %i bcnflt %i chan %i\n",
1100                    num_pdev_stats, num_vdev_stats, num_peer_stats,
1101                    num_bcnflt_stats, num_chan_stats);
1102
1103         for (i = 0; i < num_pdev_stats; i++) {
1104                 const struct wmi_pdev_stats *src;
1105                 struct ath10k_fw_stats_pdev *dst;
1106
1107                 src = data;
1108                 if (data_len < sizeof(*src)) {
1109                         kfree(tb);
1110                         return -EPROTO;
1111                 }
1112
1113                 data += sizeof(*src);
1114                 data_len -= sizeof(*src);
1115
1116                 dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
1117                 if (!dst)
1118                         continue;
1119
1120                 ath10k_wmi_pull_pdev_stats_base(&src->base, dst);
1121                 ath10k_wmi_pull_pdev_stats_tx(&src->tx, dst);
1122                 ath10k_wmi_pull_pdev_stats_rx(&src->rx, dst);
1123                 list_add_tail(&dst->list, &stats->pdevs);
1124         }
1125
1126         for (i = 0; i < num_vdev_stats; i++) {
1127                 const struct wmi_tlv_vdev_stats *src;
1128                 struct ath10k_fw_stats_vdev *dst;
1129
1130                 src = data;
1131                 if (data_len < sizeof(*src)) {
1132                         kfree(tb);
1133                         return -EPROTO;
1134                 }
1135
1136                 data += sizeof(*src);
1137                 data_len -= sizeof(*src);
1138
1139                 dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
1140                 if (!dst)
1141                         continue;
1142
1143                 ath10k_wmi_tlv_pull_vdev_stats(src, dst);
1144                 list_add_tail(&dst->list, &stats->vdevs);
1145         }
1146
1147         for (i = 0; i < num_peer_stats; i++) {
1148                 const struct wmi_10x_peer_stats *src;
1149                 struct ath10k_fw_stats_peer *dst;
1150
1151                 src = data;
1152                 if (data_len < sizeof(*src)) {
1153                         kfree(tb);
1154                         return -EPROTO;
1155                 }
1156
1157                 data += sizeof(*src);
1158                 data_len -= sizeof(*src);
1159
1160                 dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
1161                 if (!dst)
1162                         continue;
1163
1164                 ath10k_wmi_pull_peer_stats(&src->old, dst);
1165                 dst->peer_rx_rate = __le32_to_cpu(src->peer_rx_rate);
1166                 list_add_tail(&dst->list, &stats->peers);
1167         }
1168
1169         kfree(tb);
1170         return 0;
1171 }
1172
1173 static int ath10k_wmi_tlv_op_pull_roam_ev(struct ath10k *ar,
1174                                           struct sk_buff *skb,
1175                                           struct wmi_roam_ev_arg *arg)
1176 {
1177         const void **tb;
1178         const struct wmi_tlv_roam_ev *ev;
1179         int ret;
1180
1181         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1182         if (IS_ERR(tb)) {
1183                 ret = PTR_ERR(tb);
1184                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1185                 return ret;
1186         }
1187
1188         ev = tb[WMI_TLV_TAG_STRUCT_ROAM_EVENT];
1189         if (!ev) {
1190                 kfree(tb);
1191                 return -EPROTO;
1192         }
1193
1194         arg->vdev_id = ev->vdev_id;
1195         arg->reason = ev->reason;
1196         arg->rssi = ev->rssi;
1197
1198         kfree(tb);
1199         return 0;
1200 }
1201
1202 static int
1203 ath10k_wmi_tlv_op_pull_wow_ev(struct ath10k *ar, struct sk_buff *skb,
1204                               struct wmi_wow_ev_arg *arg)
1205 {
1206         const void **tb;
1207         const struct wmi_tlv_wow_event_info *ev;
1208         int ret;
1209
1210         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1211         if (IS_ERR(tb)) {
1212                 ret = PTR_ERR(tb);
1213                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1214                 return ret;
1215         }
1216
1217         ev = tb[WMI_TLV_TAG_STRUCT_WOW_EVENT_INFO];
1218         if (!ev) {
1219                 kfree(tb);
1220                 return -EPROTO;
1221         }
1222
1223         arg->vdev_id = __le32_to_cpu(ev->vdev_id);
1224         arg->flag = __le32_to_cpu(ev->flag);
1225         arg->wake_reason = __le32_to_cpu(ev->wake_reason);
1226         arg->data_len = __le32_to_cpu(ev->data_len);
1227
1228         kfree(tb);
1229         return 0;
1230 }
1231
1232 static int ath10k_wmi_tlv_op_pull_echo_ev(struct ath10k *ar,
1233                                           struct sk_buff *skb,
1234                                           struct wmi_echo_ev_arg *arg)
1235 {
1236         const void **tb;
1237         const struct wmi_echo_event *ev;
1238         int ret;
1239
1240         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1241         if (IS_ERR(tb)) {
1242                 ret = PTR_ERR(tb);
1243                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1244                 return ret;
1245         }
1246
1247         ev = tb[WMI_TLV_TAG_STRUCT_ECHO_EVENT];
1248         if (!ev) {
1249                 kfree(tb);
1250                 return -EPROTO;
1251         }
1252
1253         arg->value = ev->value;
1254
1255         kfree(tb);
1256         return 0;
1257 }
1258
1259 static struct sk_buff *
1260 ath10k_wmi_tlv_op_gen_pdev_suspend(struct ath10k *ar, u32 opt)
1261 {
1262         struct wmi_tlv_pdev_suspend *cmd;
1263         struct wmi_tlv *tlv;
1264         struct sk_buff *skb;
1265
1266         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1267         if (!skb)
1268                 return ERR_PTR(-ENOMEM);
1269
1270         tlv = (void *)skb->data;
1271         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SUSPEND_CMD);
1272         tlv->len = __cpu_to_le16(sizeof(*cmd));
1273         cmd = (void *)tlv->value;
1274         cmd->opt = __cpu_to_le32(opt);
1275
1276         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev suspend\n");
1277         return skb;
1278 }
1279
1280 static struct sk_buff *
1281 ath10k_wmi_tlv_op_gen_pdev_resume(struct ath10k *ar)
1282 {
1283         struct wmi_tlv_resume_cmd *cmd;
1284         struct wmi_tlv *tlv;
1285         struct sk_buff *skb;
1286
1287         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1288         if (!skb)
1289                 return ERR_PTR(-ENOMEM);
1290
1291         tlv = (void *)skb->data;
1292         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_RESUME_CMD);
1293         tlv->len = __cpu_to_le16(sizeof(*cmd));
1294         cmd = (void *)tlv->value;
1295         cmd->reserved = __cpu_to_le32(0);
1296
1297         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev resume\n");
1298         return skb;
1299 }
1300
1301 static struct sk_buff *
1302 ath10k_wmi_tlv_op_gen_pdev_set_rd(struct ath10k *ar,
1303                                   u16 rd, u16 rd2g, u16 rd5g,
1304                                   u16 ctl2g, u16 ctl5g,
1305                                   enum wmi_dfs_region dfs_reg)
1306 {
1307         struct wmi_tlv_pdev_set_rd_cmd *cmd;
1308         struct wmi_tlv *tlv;
1309         struct sk_buff *skb;
1310
1311         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1312         if (!skb)
1313                 return ERR_PTR(-ENOMEM);
1314
1315         tlv = (void *)skb->data;
1316         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_REGDOMAIN_CMD);
1317         tlv->len = __cpu_to_le16(sizeof(*cmd));
1318         cmd = (void *)tlv->value;
1319         cmd->regd = __cpu_to_le32(rd);
1320         cmd->regd_2ghz = __cpu_to_le32(rd2g);
1321         cmd->regd_5ghz = __cpu_to_le32(rd5g);
1322         cmd->conform_limit_2ghz = __cpu_to_le32(ctl2g);
1323         cmd->conform_limit_5ghz = __cpu_to_le32(ctl5g);
1324
1325         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev set rd\n");
1326         return skb;
1327 }
1328
1329 static enum wmi_txbf_conf ath10k_wmi_tlv_txbf_conf_scheme(struct ath10k *ar)
1330 {
1331         return WMI_TXBF_CONF_AFTER_ASSOC;
1332 }
1333
1334 static struct sk_buff *
1335 ath10k_wmi_tlv_op_gen_pdev_set_param(struct ath10k *ar, u32 param_id,
1336                                      u32 param_value)
1337 {
1338         struct wmi_tlv_pdev_set_param_cmd *cmd;
1339         struct wmi_tlv *tlv;
1340         struct sk_buff *skb;
1341
1342         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1343         if (!skb)
1344                 return ERR_PTR(-ENOMEM);
1345
1346         tlv = (void *)skb->data;
1347         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_PARAM_CMD);
1348         tlv->len = __cpu_to_le16(sizeof(*cmd));
1349         cmd = (void *)tlv->value;
1350         cmd->param_id = __cpu_to_le32(param_id);
1351         cmd->param_value = __cpu_to_le32(param_value);
1352
1353         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev set param\n");
1354         return skb;
1355 }
1356
1357 static struct sk_buff *ath10k_wmi_tlv_op_gen_init(struct ath10k *ar)
1358 {
1359         struct sk_buff *skb;
1360         struct wmi_tlv *tlv;
1361         struct wmi_tlv_init_cmd *cmd;
1362         struct wmi_tlv_resource_config *cfg;
1363         struct wmi_host_mem_chunks *chunks;
1364         size_t len, chunks_len;
1365         void *ptr;
1366
1367         chunks_len = ar->wmi.num_mem_chunks * sizeof(struct host_memory_chunk);
1368         len = (sizeof(*tlv) + sizeof(*cmd)) +
1369               (sizeof(*tlv) + sizeof(*cfg)) +
1370               (sizeof(*tlv) + chunks_len);
1371
1372         skb = ath10k_wmi_alloc_skb(ar, len);
1373         if (!skb)
1374                 return ERR_PTR(-ENOMEM);
1375
1376         ptr = skb->data;
1377
1378         tlv = ptr;
1379         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_INIT_CMD);
1380         tlv->len = __cpu_to_le16(sizeof(*cmd));
1381         cmd = (void *)tlv->value;
1382         ptr += sizeof(*tlv);
1383         ptr += sizeof(*cmd);
1384
1385         tlv = ptr;
1386         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_RESOURCE_CONFIG);
1387         tlv->len = __cpu_to_le16(sizeof(*cfg));
1388         cfg = (void *)tlv->value;
1389         ptr += sizeof(*tlv);
1390         ptr += sizeof(*cfg);
1391
1392         tlv = ptr;
1393         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
1394         tlv->len = __cpu_to_le16(chunks_len);
1395         chunks = (void *)tlv->value;
1396
1397         ptr += sizeof(*tlv);
1398         ptr += chunks_len;
1399
1400         cmd->abi.abi_ver0 = __cpu_to_le32(WMI_TLV_ABI_VER0);
1401         cmd->abi.abi_ver1 = __cpu_to_le32(WMI_TLV_ABI_VER1);
1402         cmd->abi.abi_ver_ns0 = __cpu_to_le32(WMI_TLV_ABI_VER_NS0);
1403         cmd->abi.abi_ver_ns1 = __cpu_to_le32(WMI_TLV_ABI_VER_NS1);
1404         cmd->abi.abi_ver_ns2 = __cpu_to_le32(WMI_TLV_ABI_VER_NS2);
1405         cmd->abi.abi_ver_ns3 = __cpu_to_le32(WMI_TLV_ABI_VER_NS3);
1406         cmd->num_host_mem_chunks = __cpu_to_le32(ar->wmi.num_mem_chunks);
1407
1408         cfg->num_vdevs = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1409         cfg->num_peers = __cpu_to_le32(TARGET_TLV_NUM_PEERS);
1410
1411         if (test_bit(WMI_SERVICE_RX_FULL_REORDER, ar->wmi.svc_map)) {
1412                 cfg->num_offload_peers = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1413                 cfg->num_offload_reorder_bufs = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1414         } else {
1415                 cfg->num_offload_peers = __cpu_to_le32(0);
1416                 cfg->num_offload_reorder_bufs = __cpu_to_le32(0);
1417         }
1418
1419         cfg->num_peer_keys = __cpu_to_le32(2);
1420         cfg->num_tids = __cpu_to_le32(TARGET_TLV_NUM_TIDS);
1421         cfg->ast_skid_limit = __cpu_to_le32(0x10);
1422         cfg->tx_chain_mask = __cpu_to_le32(0x7);
1423         cfg->rx_chain_mask = __cpu_to_le32(0x7);
1424         cfg->rx_timeout_pri[0] = __cpu_to_le32(0x64);
1425         cfg->rx_timeout_pri[1] = __cpu_to_le32(0x64);
1426         cfg->rx_timeout_pri[2] = __cpu_to_le32(0x64);
1427         cfg->rx_timeout_pri[3] = __cpu_to_le32(0x28);
1428         cfg->rx_decap_mode = __cpu_to_le32(ar->wmi.rx_decap_mode);
1429         cfg->scan_max_pending_reqs = __cpu_to_le32(4);
1430         cfg->bmiss_offload_max_vdev = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1431         cfg->roam_offload_max_vdev = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1432         cfg->roam_offload_max_ap_profiles = __cpu_to_le32(8);
1433         cfg->num_mcast_groups = __cpu_to_le32(0);
1434         cfg->num_mcast_table_elems = __cpu_to_le32(0);
1435         cfg->mcast2ucast_mode = __cpu_to_le32(0);
1436         cfg->tx_dbg_log_size = __cpu_to_le32(0x400);
1437         cfg->num_wds_entries = __cpu_to_le32(0x20);
1438         cfg->dma_burst_size = __cpu_to_le32(0);
1439         cfg->mac_aggr_delim = __cpu_to_le32(0);
1440         cfg->rx_skip_defrag_timeout_dup_detection_check = __cpu_to_le32(0);
1441         cfg->vow_config = __cpu_to_le32(0);
1442         cfg->gtk_offload_max_vdev = __cpu_to_le32(2);
1443         cfg->num_msdu_desc = __cpu_to_le32(TARGET_TLV_NUM_MSDU_DESC);
1444         cfg->max_frag_entries = __cpu_to_le32(2);
1445         cfg->num_tdls_vdevs = __cpu_to_le32(TARGET_TLV_NUM_TDLS_VDEVS);
1446         cfg->num_tdls_conn_table_entries = __cpu_to_le32(0x20);
1447         cfg->beacon_tx_offload_max_vdev = __cpu_to_le32(2);
1448         cfg->num_multicast_filter_entries = __cpu_to_le32(5);
1449         cfg->num_wow_filters = __cpu_to_le32(ar->wow.max_num_patterns);
1450         cfg->num_keep_alive_pattern = __cpu_to_le32(6);
1451         cfg->keep_alive_pattern_size = __cpu_to_le32(0);
1452         cfg->max_tdls_concurrent_sleep_sta = __cpu_to_le32(1);
1453         cfg->max_tdls_concurrent_buffer_sta = __cpu_to_le32(1);
1454
1455         ath10k_wmi_put_host_mem_chunks(ar, chunks);
1456
1457         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv init\n");
1458         return skb;
1459 }
1460
1461 static struct sk_buff *
1462 ath10k_wmi_tlv_op_gen_start_scan(struct ath10k *ar,
1463                                  const struct wmi_start_scan_arg *arg)
1464 {
1465         struct wmi_tlv_start_scan_cmd *cmd;
1466         struct wmi_tlv *tlv;
1467         struct sk_buff *skb;
1468         size_t len, chan_len, ssid_len, bssid_len, ie_len;
1469         __le32 *chans;
1470         struct wmi_ssid *ssids;
1471         struct wmi_mac_addr *addrs;
1472         void *ptr;
1473         int i, ret;
1474
1475         ret = ath10k_wmi_start_scan_verify(arg);
1476         if (ret)
1477                 return ERR_PTR(ret);
1478
1479         chan_len = arg->n_channels * sizeof(__le32);
1480         ssid_len = arg->n_ssids * sizeof(struct wmi_ssid);
1481         bssid_len = arg->n_bssids * sizeof(struct wmi_mac_addr);
1482         ie_len = roundup(arg->ie_len, 4);
1483         len = (sizeof(*tlv) + sizeof(*cmd)) +
1484               (arg->n_channels ? sizeof(*tlv) + chan_len : 0) +
1485               (arg->n_ssids ? sizeof(*tlv) + ssid_len : 0) +
1486               (arg->n_bssids ? sizeof(*tlv) + bssid_len : 0) +
1487               (arg->ie_len ? sizeof(*tlv) + ie_len : 0);
1488
1489         skb = ath10k_wmi_alloc_skb(ar, len);
1490         if (!skb)
1491                 return ERR_PTR(-ENOMEM);
1492
1493         ptr = (void *)skb->data;
1494         tlv = ptr;
1495         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_START_SCAN_CMD);
1496         tlv->len = __cpu_to_le16(sizeof(*cmd));
1497         cmd = (void *)tlv->value;
1498
1499         ath10k_wmi_put_start_scan_common(&cmd->common, arg);
1500         cmd->burst_duration_ms = __cpu_to_le32(arg->burst_duration_ms);
1501         cmd->num_channels = __cpu_to_le32(arg->n_channels);
1502         cmd->num_ssids = __cpu_to_le32(arg->n_ssids);
1503         cmd->num_bssids = __cpu_to_le32(arg->n_bssids);
1504         cmd->ie_len = __cpu_to_le32(arg->ie_len);
1505         cmd->num_probes = __cpu_to_le32(3);
1506
1507         /* FIXME: There are some scan flag inconsistencies across firmwares,
1508          * e.g. WMI-TLV inverts the logic behind the following flag.
1509          */
1510         cmd->common.scan_ctrl_flags ^= __cpu_to_le32(WMI_SCAN_FILTER_PROBE_REQ);
1511
1512         ptr += sizeof(*tlv);
1513         ptr += sizeof(*cmd);
1514
1515         tlv = ptr;
1516         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
1517         tlv->len = __cpu_to_le16(chan_len);
1518         chans = (void *)tlv->value;
1519         for (i = 0; i < arg->n_channels; i++)
1520                 chans[i] = __cpu_to_le32(arg->channels[i]);
1521
1522         ptr += sizeof(*tlv);
1523         ptr += chan_len;
1524
1525         tlv = ptr;
1526         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_FIXED_STRUCT);
1527         tlv->len = __cpu_to_le16(ssid_len);
1528         ssids = (void *)tlv->value;
1529         for (i = 0; i < arg->n_ssids; i++) {
1530                 ssids[i].ssid_len = __cpu_to_le32(arg->ssids[i].len);
1531                 memcpy(ssids[i].ssid, arg->ssids[i].ssid, arg->ssids[i].len);
1532         }
1533
1534         ptr += sizeof(*tlv);
1535         ptr += ssid_len;
1536
1537         tlv = ptr;
1538         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_FIXED_STRUCT);
1539         tlv->len = __cpu_to_le16(bssid_len);
1540         addrs = (void *)tlv->value;
1541         for (i = 0; i < arg->n_bssids; i++)
1542                 ether_addr_copy(addrs[i].addr, arg->bssids[i].bssid);
1543
1544         ptr += sizeof(*tlv);
1545         ptr += bssid_len;
1546
1547         tlv = ptr;
1548         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
1549         tlv->len = __cpu_to_le16(ie_len);
1550         memcpy(tlv->value, arg->ie, arg->ie_len);
1551
1552         ptr += sizeof(*tlv);
1553         ptr += ie_len;
1554
1555         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv start scan\n");
1556         return skb;
1557 }
1558
1559 static struct sk_buff *
1560 ath10k_wmi_tlv_op_gen_stop_scan(struct ath10k *ar,
1561                                 const struct wmi_stop_scan_arg *arg)
1562 {
1563         struct wmi_stop_scan_cmd *cmd;
1564         struct wmi_tlv *tlv;
1565         struct sk_buff *skb;
1566         u32 scan_id;
1567         u32 req_id;
1568
1569         if (arg->req_id > 0xFFF)
1570                 return ERR_PTR(-EINVAL);
1571         if (arg->req_type == WMI_SCAN_STOP_ONE && arg->u.scan_id > 0xFFF)
1572                 return ERR_PTR(-EINVAL);
1573
1574         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1575         if (!skb)
1576                 return ERR_PTR(-ENOMEM);
1577
1578         scan_id = arg->u.scan_id;
1579         scan_id |= WMI_HOST_SCAN_REQ_ID_PREFIX;
1580
1581         req_id = arg->req_id;
1582         req_id |= WMI_HOST_SCAN_REQUESTOR_ID_PREFIX;
1583
1584         tlv = (void *)skb->data;
1585         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STOP_SCAN_CMD);
1586         tlv->len = __cpu_to_le16(sizeof(*cmd));
1587         cmd = (void *)tlv->value;
1588         cmd->req_type = __cpu_to_le32(arg->req_type);
1589         cmd->vdev_id = __cpu_to_le32(arg->u.vdev_id);
1590         cmd->scan_id = __cpu_to_le32(scan_id);
1591         cmd->scan_req_id = __cpu_to_le32(req_id);
1592
1593         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv stop scan\n");
1594         return skb;
1595 }
1596
1597 static struct sk_buff *
1598 ath10k_wmi_tlv_op_gen_vdev_create(struct ath10k *ar,
1599                                   u32 vdev_id,
1600                                   enum wmi_vdev_type vdev_type,
1601                                   enum wmi_vdev_subtype vdev_subtype,
1602                                   const u8 mac_addr[ETH_ALEN])
1603 {
1604         struct wmi_vdev_create_cmd *cmd;
1605         struct wmi_tlv *tlv;
1606         struct sk_buff *skb;
1607
1608         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1609         if (!skb)
1610                 return ERR_PTR(-ENOMEM);
1611
1612         tlv = (void *)skb->data;
1613         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_CREATE_CMD);
1614         tlv->len = __cpu_to_le16(sizeof(*cmd));
1615         cmd = (void *)tlv->value;
1616         cmd->vdev_id = __cpu_to_le32(vdev_id);
1617         cmd->vdev_type = __cpu_to_le32(vdev_type);
1618         cmd->vdev_subtype = __cpu_to_le32(vdev_subtype);
1619         ether_addr_copy(cmd->vdev_macaddr.addr, mac_addr);
1620
1621         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev create\n");
1622         return skb;
1623 }
1624
1625 static struct sk_buff *
1626 ath10k_wmi_tlv_op_gen_vdev_delete(struct ath10k *ar, u32 vdev_id)
1627 {
1628         struct wmi_vdev_delete_cmd *cmd;
1629         struct wmi_tlv *tlv;
1630         struct sk_buff *skb;
1631
1632         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1633         if (!skb)
1634                 return ERR_PTR(-ENOMEM);
1635
1636         tlv = (void *)skb->data;
1637         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_DELETE_CMD);
1638         tlv->len = __cpu_to_le16(sizeof(*cmd));
1639         cmd = (void *)tlv->value;
1640         cmd->vdev_id = __cpu_to_le32(vdev_id);
1641
1642         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev delete\n");
1643         return skb;
1644 }
1645
1646 static struct sk_buff *
1647 ath10k_wmi_tlv_op_gen_vdev_start(struct ath10k *ar,
1648                                  const struct wmi_vdev_start_request_arg *arg,
1649                                  bool restart)
1650 {
1651         struct wmi_tlv_vdev_start_cmd *cmd;
1652         struct wmi_channel *ch;
1653         struct wmi_p2p_noa_descriptor *noa;
1654         struct wmi_tlv *tlv;
1655         struct sk_buff *skb;
1656         size_t len;
1657         void *ptr;
1658         u32 flags = 0;
1659
1660         if (WARN_ON(arg->hidden_ssid && !arg->ssid))
1661                 return ERR_PTR(-EINVAL);
1662         if (WARN_ON(arg->ssid_len > sizeof(cmd->ssid.ssid)))
1663                 return ERR_PTR(-EINVAL);
1664
1665         len = (sizeof(*tlv) + sizeof(*cmd)) +
1666               (sizeof(*tlv) + sizeof(*ch)) +
1667               (sizeof(*tlv) + 0);
1668         skb = ath10k_wmi_alloc_skb(ar, len);
1669         if (!skb)
1670                 return ERR_PTR(-ENOMEM);
1671
1672         if (arg->hidden_ssid)
1673                 flags |= WMI_VDEV_START_HIDDEN_SSID;
1674         if (arg->pmf_enabled)
1675                 flags |= WMI_VDEV_START_PMF_ENABLED;
1676
1677         ptr = (void *)skb->data;
1678
1679         tlv = ptr;
1680         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_START_REQUEST_CMD);
1681         tlv->len = __cpu_to_le16(sizeof(*cmd));
1682         cmd = (void *)tlv->value;
1683         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
1684         cmd->bcn_intval = __cpu_to_le32(arg->bcn_intval);
1685         cmd->dtim_period = __cpu_to_le32(arg->dtim_period);
1686         cmd->flags = __cpu_to_le32(flags);
1687         cmd->bcn_tx_rate = __cpu_to_le32(arg->bcn_tx_rate);
1688         cmd->bcn_tx_power = __cpu_to_le32(arg->bcn_tx_power);
1689         cmd->disable_hw_ack = __cpu_to_le32(arg->disable_hw_ack);
1690
1691         if (arg->ssid) {
1692                 cmd->ssid.ssid_len = __cpu_to_le32(arg->ssid_len);
1693                 memcpy(cmd->ssid.ssid, arg->ssid, arg->ssid_len);
1694         }
1695
1696         ptr += sizeof(*tlv);
1697         ptr += sizeof(*cmd);
1698
1699         tlv = ptr;
1700         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_CHANNEL);
1701         tlv->len = __cpu_to_le16(sizeof(*ch));
1702         ch = (void *)tlv->value;
1703         ath10k_wmi_put_wmi_channel(ch, &arg->channel);
1704
1705         ptr += sizeof(*tlv);
1706         ptr += sizeof(*ch);
1707
1708         tlv = ptr;
1709         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
1710         tlv->len = 0;
1711         noa = (void *)tlv->value;
1712
1713         /* Note: This is a nested TLV containing:
1714          * [wmi_tlv][wmi_p2p_noa_descriptor][wmi_tlv]..
1715          */
1716
1717         ptr += sizeof(*tlv);
1718         ptr += 0;
1719
1720         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev start\n");
1721         return skb;
1722 }
1723
1724 static struct sk_buff *
1725 ath10k_wmi_tlv_op_gen_vdev_stop(struct ath10k *ar, u32 vdev_id)
1726 {
1727         struct wmi_vdev_stop_cmd *cmd;
1728         struct wmi_tlv *tlv;
1729         struct sk_buff *skb;
1730
1731         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1732         if (!skb)
1733                 return ERR_PTR(-ENOMEM);
1734
1735         tlv = (void *)skb->data;
1736         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_STOP_CMD);
1737         tlv->len = __cpu_to_le16(sizeof(*cmd));
1738         cmd = (void *)tlv->value;
1739         cmd->vdev_id = __cpu_to_le32(vdev_id);
1740
1741         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev stop\n");
1742         return skb;
1743 }
1744
1745 static struct sk_buff *
1746 ath10k_wmi_tlv_op_gen_vdev_up(struct ath10k *ar, u32 vdev_id, u32 aid,
1747                               const u8 *bssid)
1748
1749 {
1750         struct wmi_vdev_up_cmd *cmd;
1751         struct wmi_tlv *tlv;
1752         struct sk_buff *skb;
1753
1754         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1755         if (!skb)
1756                 return ERR_PTR(-ENOMEM);
1757
1758         tlv = (void *)skb->data;
1759         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_UP_CMD);
1760         tlv->len = __cpu_to_le16(sizeof(*cmd));
1761         cmd = (void *)tlv->value;
1762         cmd->vdev_id = __cpu_to_le32(vdev_id);
1763         cmd->vdev_assoc_id = __cpu_to_le32(aid);
1764         ether_addr_copy(cmd->vdev_bssid.addr, bssid);
1765
1766         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev up\n");
1767         return skb;
1768 }
1769
1770 static struct sk_buff *
1771 ath10k_wmi_tlv_op_gen_vdev_down(struct ath10k *ar, u32 vdev_id)
1772 {
1773         struct wmi_vdev_down_cmd *cmd;
1774         struct wmi_tlv *tlv;
1775         struct sk_buff *skb;
1776
1777         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1778         if (!skb)
1779                 return ERR_PTR(-ENOMEM);
1780
1781         tlv = (void *)skb->data;
1782         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_DOWN_CMD);
1783         tlv->len = __cpu_to_le16(sizeof(*cmd));
1784         cmd = (void *)tlv->value;
1785         cmd->vdev_id = __cpu_to_le32(vdev_id);
1786
1787         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev down\n");
1788         return skb;
1789 }
1790
1791 static struct sk_buff *
1792 ath10k_wmi_tlv_op_gen_vdev_set_param(struct ath10k *ar, u32 vdev_id,
1793                                      u32 param_id, u32 param_value)
1794 {
1795         struct wmi_vdev_set_param_cmd *cmd;
1796         struct wmi_tlv *tlv;
1797         struct sk_buff *skb;
1798
1799         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1800         if (!skb)
1801                 return ERR_PTR(-ENOMEM);
1802
1803         tlv = (void *)skb->data;
1804         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SET_PARAM_CMD);
1805         tlv->len = __cpu_to_le16(sizeof(*cmd));
1806         cmd = (void *)tlv->value;
1807         cmd->vdev_id = __cpu_to_le32(vdev_id);
1808         cmd->param_id = __cpu_to_le32(param_id);
1809         cmd->param_value = __cpu_to_le32(param_value);
1810
1811         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev set param\n");
1812         return skb;
1813 }
1814
1815 static struct sk_buff *
1816 ath10k_wmi_tlv_op_gen_vdev_install_key(struct ath10k *ar,
1817                                        const struct wmi_vdev_install_key_arg *arg)
1818 {
1819         struct wmi_vdev_install_key_cmd *cmd;
1820         struct wmi_tlv *tlv;
1821         struct sk_buff *skb;
1822         size_t len;
1823         void *ptr;
1824
1825         if (arg->key_cipher == WMI_CIPHER_NONE && arg->key_data != NULL)
1826                 return ERR_PTR(-EINVAL);
1827         if (arg->key_cipher != WMI_CIPHER_NONE && arg->key_data == NULL)
1828                 return ERR_PTR(-EINVAL);
1829
1830         len = sizeof(*tlv) + sizeof(*cmd) +
1831               sizeof(*tlv) + roundup(arg->key_len, sizeof(__le32));
1832         skb = ath10k_wmi_alloc_skb(ar, len);
1833         if (!skb)
1834                 return ERR_PTR(-ENOMEM);
1835
1836         ptr = (void *)skb->data;
1837         tlv = ptr;
1838         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_INSTALL_KEY_CMD);
1839         tlv->len = __cpu_to_le16(sizeof(*cmd));
1840         cmd = (void *)tlv->value;
1841         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
1842         cmd->key_idx = __cpu_to_le32(arg->key_idx);
1843         cmd->key_flags = __cpu_to_le32(arg->key_flags);
1844         cmd->key_cipher = __cpu_to_le32(arg->key_cipher);
1845         cmd->key_len = __cpu_to_le32(arg->key_len);
1846         cmd->key_txmic_len = __cpu_to_le32(arg->key_txmic_len);
1847         cmd->key_rxmic_len = __cpu_to_le32(arg->key_rxmic_len);
1848
1849         if (arg->macaddr)
1850                 ether_addr_copy(cmd->peer_macaddr.addr, arg->macaddr);
1851
1852         ptr += sizeof(*tlv);
1853         ptr += sizeof(*cmd);
1854
1855         tlv = ptr;
1856         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
1857         tlv->len = __cpu_to_le16(roundup(arg->key_len, sizeof(__le32)));
1858         if (arg->key_data)
1859                 memcpy(tlv->value, arg->key_data, arg->key_len);
1860
1861         ptr += sizeof(*tlv);
1862         ptr += roundup(arg->key_len, sizeof(__le32));
1863
1864         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev install key\n");
1865         return skb;
1866 }
1867
1868 static void *ath10k_wmi_tlv_put_uapsd_ac(struct ath10k *ar, void *ptr,
1869                                          const struct wmi_sta_uapsd_auto_trig_arg *arg)
1870 {
1871         struct wmi_sta_uapsd_auto_trig_param *ac;
1872         struct wmi_tlv *tlv;
1873
1874         tlv = ptr;
1875         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_UAPSD_AUTO_TRIG_PARAM);
1876         tlv->len = __cpu_to_le16(sizeof(*ac));
1877         ac = (void *)tlv->value;
1878
1879         ac->wmm_ac = __cpu_to_le32(arg->wmm_ac);
1880         ac->user_priority = __cpu_to_le32(arg->user_priority);
1881         ac->service_interval = __cpu_to_le32(arg->service_interval);
1882         ac->suspend_interval = __cpu_to_le32(arg->suspend_interval);
1883         ac->delay_interval = __cpu_to_le32(arg->delay_interval);
1884
1885         ath10k_dbg(ar, ATH10K_DBG_WMI,
1886                    "wmi tlv vdev sta uapsd auto trigger ac %d prio %d svc int %d susp int %d delay int %d\n",
1887                    ac->wmm_ac, ac->user_priority, ac->service_interval,
1888                    ac->suspend_interval, ac->delay_interval);
1889
1890         return ptr + sizeof(*tlv) + sizeof(*ac);
1891 }
1892
1893 static struct sk_buff *
1894 ath10k_wmi_tlv_op_gen_vdev_sta_uapsd(struct ath10k *ar, u32 vdev_id,
1895                                      const u8 peer_addr[ETH_ALEN],
1896                                      const struct wmi_sta_uapsd_auto_trig_arg *args,
1897                                      u32 num_ac)
1898 {
1899         struct wmi_sta_uapsd_auto_trig_cmd_fixed_param *cmd;
1900         struct wmi_sta_uapsd_auto_trig_param *ac;
1901         struct wmi_tlv *tlv;
1902         struct sk_buff *skb;
1903         size_t len;
1904         size_t ac_tlv_len;
1905         void *ptr;
1906         int i;
1907
1908         ac_tlv_len = num_ac * (sizeof(*tlv) + sizeof(*ac));
1909         len = sizeof(*tlv) + sizeof(*cmd) +
1910               sizeof(*tlv) + ac_tlv_len;
1911         skb = ath10k_wmi_alloc_skb(ar, len);
1912         if (!skb)
1913                 return ERR_PTR(-ENOMEM);
1914
1915         ptr = (void *)skb->data;
1916         tlv = ptr;
1917         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_UAPSD_AUTO_TRIG_CMD);
1918         tlv->len = __cpu_to_le16(sizeof(*cmd));
1919         cmd = (void *)tlv->value;
1920         cmd->vdev_id = __cpu_to_le32(vdev_id);
1921         cmd->num_ac = __cpu_to_le32(num_ac);
1922         ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1923
1924         ptr += sizeof(*tlv);
1925         ptr += sizeof(*cmd);
1926
1927         tlv = ptr;
1928         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
1929         tlv->len = __cpu_to_le16(ac_tlv_len);
1930         ac = (void *)tlv->value;
1931
1932         ptr += sizeof(*tlv);
1933         for (i = 0; i < num_ac; i++)
1934                 ptr = ath10k_wmi_tlv_put_uapsd_ac(ar, ptr, &args[i]);
1935
1936         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev sta uapsd auto trigger\n");
1937         return skb;
1938 }
1939
1940 static void *ath10k_wmi_tlv_put_wmm(void *ptr,
1941                                     const struct wmi_wmm_params_arg *arg)
1942 {
1943         struct wmi_wmm_params *wmm;
1944         struct wmi_tlv *tlv;
1945
1946         tlv = ptr;
1947         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WMM_PARAMS);
1948         tlv->len = __cpu_to_le16(sizeof(*wmm));
1949         wmm = (void *)tlv->value;
1950         ath10k_wmi_set_wmm_param(wmm, arg);
1951
1952         return ptr + sizeof(*tlv) + sizeof(*wmm);
1953 }
1954
1955 static struct sk_buff *
1956 ath10k_wmi_tlv_op_gen_vdev_wmm_conf(struct ath10k *ar, u32 vdev_id,
1957                                     const struct wmi_wmm_params_all_arg *arg)
1958 {
1959         struct wmi_tlv_vdev_set_wmm_cmd *cmd;
1960         struct wmi_tlv *tlv;
1961         struct sk_buff *skb;
1962         size_t len;
1963         void *ptr;
1964
1965         len = sizeof(*tlv) + sizeof(*cmd);
1966         skb = ath10k_wmi_alloc_skb(ar, len);
1967         if (!skb)
1968                 return ERR_PTR(-ENOMEM);
1969
1970         ptr = (void *)skb->data;
1971         tlv = ptr;
1972         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SET_WMM_PARAMS_CMD);
1973         tlv->len = __cpu_to_le16(sizeof(*cmd));
1974         cmd = (void *)tlv->value;
1975         cmd->vdev_id = __cpu_to_le32(vdev_id);
1976
1977         ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[0].params, &arg->ac_be);
1978         ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[1].params, &arg->ac_bk);
1979         ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[2].params, &arg->ac_vi);
1980         ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[3].params, &arg->ac_vo);
1981
1982         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev wmm conf\n");
1983         return skb;
1984 }
1985
1986 static struct sk_buff *
1987 ath10k_wmi_tlv_op_gen_sta_keepalive(struct ath10k *ar,
1988                                     const struct wmi_sta_keepalive_arg *arg)
1989 {
1990         struct wmi_tlv_sta_keepalive_cmd *cmd;
1991         struct wmi_sta_keepalive_arp_resp *arp;
1992         struct sk_buff *skb;
1993         struct wmi_tlv *tlv;
1994         void *ptr;
1995         size_t len;
1996
1997         len = sizeof(*tlv) + sizeof(*cmd) +
1998               sizeof(*tlv) + sizeof(*arp);
1999         skb = ath10k_wmi_alloc_skb(ar, len);
2000         if (!skb)
2001                 return ERR_PTR(-ENOMEM);
2002
2003         ptr = (void *)skb->data;
2004         tlv = ptr;
2005         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_KEEPALIVE_CMD);
2006         tlv->len = __cpu_to_le16(sizeof(*cmd));
2007         cmd = (void *)tlv->value;
2008         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
2009         cmd->enabled = __cpu_to_le32(arg->enabled);
2010         cmd->method = __cpu_to_le32(arg->method);
2011         cmd->interval = __cpu_to_le32(arg->interval);
2012
2013         ptr += sizeof(*tlv);
2014         ptr += sizeof(*cmd);
2015
2016         tlv = ptr;
2017         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_KEEPALVE_ARP_RESPONSE);
2018         tlv->len = __cpu_to_le16(sizeof(*arp));
2019         arp = (void *)tlv->value;
2020
2021         arp->src_ip4_addr = arg->src_ip4_addr;
2022         arp->dest_ip4_addr = arg->dest_ip4_addr;
2023         ether_addr_copy(arp->dest_mac_addr.addr, arg->dest_mac_addr);
2024
2025         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv sta keepalive vdev %d enabled %d method %d inverval %d\n",
2026                    arg->vdev_id, arg->enabled, arg->method, arg->interval);
2027         return skb;
2028 }
2029
2030 static struct sk_buff *
2031 ath10k_wmi_tlv_op_gen_peer_create(struct ath10k *ar, u32 vdev_id,
2032                                   const u8 peer_addr[ETH_ALEN],
2033                                   enum wmi_peer_type peer_type)
2034 {
2035         struct wmi_tlv_peer_create_cmd *cmd;
2036         struct wmi_tlv *tlv;
2037         struct sk_buff *skb;
2038
2039         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2040         if (!skb)
2041                 return ERR_PTR(-ENOMEM);
2042
2043         tlv = (void *)skb->data;
2044         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_CREATE_CMD);
2045         tlv->len = __cpu_to_le16(sizeof(*cmd));
2046         cmd = (void *)tlv->value;
2047         cmd->vdev_id = __cpu_to_le32(vdev_id);
2048         cmd->peer_type = __cpu_to_le32(peer_type);
2049         ether_addr_copy(cmd->peer_addr.addr, peer_addr);
2050
2051         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer create\n");
2052         return skb;
2053 }
2054
2055 static struct sk_buff *
2056 ath10k_wmi_tlv_op_gen_peer_delete(struct ath10k *ar, u32 vdev_id,
2057                                   const u8 peer_addr[ETH_ALEN])
2058 {
2059         struct wmi_peer_delete_cmd *cmd;
2060         struct wmi_tlv *tlv;
2061         struct sk_buff *skb;
2062
2063         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2064         if (!skb)
2065                 return ERR_PTR(-ENOMEM);
2066
2067         tlv = (void *)skb->data;
2068         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_DELETE_CMD);
2069         tlv->len = __cpu_to_le16(sizeof(*cmd));
2070         cmd = (void *)tlv->value;
2071         cmd->vdev_id = __cpu_to_le32(vdev_id);
2072         ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2073
2074         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer delete\n");
2075         return skb;
2076 }
2077
2078 static struct sk_buff *
2079 ath10k_wmi_tlv_op_gen_peer_flush(struct ath10k *ar, u32 vdev_id,
2080                                  const u8 peer_addr[ETH_ALEN], u32 tid_bitmap)
2081 {
2082         struct wmi_peer_flush_tids_cmd *cmd;
2083         struct wmi_tlv *tlv;
2084         struct sk_buff *skb;
2085
2086         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2087         if (!skb)
2088                 return ERR_PTR(-ENOMEM);
2089
2090         tlv = (void *)skb->data;
2091         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_FLUSH_TIDS_CMD);
2092         tlv->len = __cpu_to_le16(sizeof(*cmd));
2093         cmd = (void *)tlv->value;
2094         cmd->vdev_id = __cpu_to_le32(vdev_id);
2095         cmd->peer_tid_bitmap = __cpu_to_le32(tid_bitmap);
2096         ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2097
2098         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer flush\n");
2099         return skb;
2100 }
2101
2102 static struct sk_buff *
2103 ath10k_wmi_tlv_op_gen_peer_set_param(struct ath10k *ar, u32 vdev_id,
2104                                      const u8 *peer_addr,
2105                                      enum wmi_peer_param param_id,
2106                                      u32 param_value)
2107 {
2108         struct wmi_peer_set_param_cmd *cmd;
2109         struct wmi_tlv *tlv;
2110         struct sk_buff *skb;
2111
2112         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2113         if (!skb)
2114                 return ERR_PTR(-ENOMEM);
2115
2116         tlv = (void *)skb->data;
2117         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_SET_PARAM_CMD);
2118         tlv->len = __cpu_to_le16(sizeof(*cmd));
2119         cmd = (void *)tlv->value;
2120         cmd->vdev_id = __cpu_to_le32(vdev_id);
2121         cmd->param_id = __cpu_to_le32(param_id);
2122         cmd->param_value = __cpu_to_le32(param_value);
2123         ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2124
2125         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer set param\n");
2126         return skb;
2127 }
2128
2129 static struct sk_buff *
2130 ath10k_wmi_tlv_op_gen_peer_assoc(struct ath10k *ar,
2131                                  const struct wmi_peer_assoc_complete_arg *arg)
2132 {
2133         struct wmi_tlv_peer_assoc_cmd *cmd;
2134         struct wmi_vht_rate_set *vht_rate;
2135         struct wmi_tlv *tlv;
2136         struct sk_buff *skb;
2137         size_t len, legacy_rate_len, ht_rate_len;
2138         void *ptr;
2139
2140         if (arg->peer_mpdu_density > 16)
2141                 return ERR_PTR(-EINVAL);
2142         if (arg->peer_legacy_rates.num_rates > MAX_SUPPORTED_RATES)
2143                 return ERR_PTR(-EINVAL);
2144         if (arg->peer_ht_rates.num_rates > MAX_SUPPORTED_RATES)
2145                 return ERR_PTR(-EINVAL);
2146
2147         legacy_rate_len = roundup(arg->peer_legacy_rates.num_rates,
2148                                   sizeof(__le32));
2149         ht_rate_len = roundup(arg->peer_ht_rates.num_rates, sizeof(__le32));
2150         len = (sizeof(*tlv) + sizeof(*cmd)) +
2151               (sizeof(*tlv) + legacy_rate_len) +
2152               (sizeof(*tlv) + ht_rate_len) +
2153               (sizeof(*tlv) + sizeof(*vht_rate));
2154         skb = ath10k_wmi_alloc_skb(ar, len);
2155         if (!skb)
2156                 return ERR_PTR(-ENOMEM);
2157
2158         ptr = (void *)skb->data;
2159         tlv = ptr;
2160         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_ASSOC_COMPLETE_CMD);
2161         tlv->len = __cpu_to_le16(sizeof(*cmd));
2162         cmd = (void *)tlv->value;
2163
2164         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
2165         cmd->new_assoc = __cpu_to_le32(arg->peer_reassoc ? 0 : 1);
2166         cmd->assoc_id = __cpu_to_le32(arg->peer_aid);
2167         cmd->flags = __cpu_to_le32(arg->peer_flags);
2168         cmd->caps = __cpu_to_le32(arg->peer_caps);
2169         cmd->listen_intval = __cpu_to_le32(arg->peer_listen_intval);
2170         cmd->ht_caps = __cpu_to_le32(arg->peer_ht_caps);
2171         cmd->max_mpdu = __cpu_to_le32(arg->peer_max_mpdu);
2172         cmd->mpdu_density = __cpu_to_le32(arg->peer_mpdu_density);
2173         cmd->rate_caps = __cpu_to_le32(arg->peer_rate_caps);
2174         cmd->nss = __cpu_to_le32(arg->peer_num_spatial_streams);
2175         cmd->vht_caps = __cpu_to_le32(arg->peer_vht_caps);
2176         cmd->phy_mode = __cpu_to_le32(arg->peer_phymode);
2177         cmd->num_legacy_rates = __cpu_to_le32(arg->peer_legacy_rates.num_rates);
2178         cmd->num_ht_rates = __cpu_to_le32(arg->peer_ht_rates.num_rates);
2179         ether_addr_copy(cmd->mac_addr.addr, arg->addr);
2180
2181         ptr += sizeof(*tlv);
2182         ptr += sizeof(*cmd);
2183
2184         tlv = ptr;
2185         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2186         tlv->len = __cpu_to_le16(legacy_rate_len);
2187         memcpy(tlv->value, arg->peer_legacy_rates.rates,
2188                arg->peer_legacy_rates.num_rates);
2189
2190         ptr += sizeof(*tlv);
2191         ptr += legacy_rate_len;
2192
2193         tlv = ptr;
2194         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2195         tlv->len = __cpu_to_le16(ht_rate_len);
2196         memcpy(tlv->value, arg->peer_ht_rates.rates,
2197                arg->peer_ht_rates.num_rates);
2198
2199         ptr += sizeof(*tlv);
2200         ptr += ht_rate_len;
2201
2202         tlv = ptr;
2203         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VHT_RATE_SET);
2204         tlv->len = __cpu_to_le16(sizeof(*vht_rate));
2205         vht_rate = (void *)tlv->value;
2206
2207         vht_rate->rx_max_rate = __cpu_to_le32(arg->peer_vht_rates.rx_max_rate);
2208         vht_rate->rx_mcs_set = __cpu_to_le32(arg->peer_vht_rates.rx_mcs_set);
2209         vht_rate->tx_max_rate = __cpu_to_le32(arg->peer_vht_rates.tx_max_rate);
2210         vht_rate->tx_mcs_set = __cpu_to_le32(arg->peer_vht_rates.tx_mcs_set);
2211
2212         ptr += sizeof(*tlv);
2213         ptr += sizeof(*vht_rate);
2214
2215         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer assoc\n");
2216         return skb;
2217 }
2218
2219 static struct sk_buff *
2220 ath10k_wmi_tlv_op_gen_set_psmode(struct ath10k *ar, u32 vdev_id,
2221                                  enum wmi_sta_ps_mode psmode)
2222 {
2223         struct wmi_sta_powersave_mode_cmd *cmd;
2224         struct wmi_tlv *tlv;
2225         struct sk_buff *skb;
2226
2227         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2228         if (!skb)
2229                 return ERR_PTR(-ENOMEM);
2230
2231         tlv = (void *)skb->data;
2232         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_POWERSAVE_MODE_CMD);
2233         tlv->len = __cpu_to_le16(sizeof(*cmd));
2234         cmd = (void *)tlv->value;
2235         cmd->vdev_id = __cpu_to_le32(vdev_id);
2236         cmd->sta_ps_mode = __cpu_to_le32(psmode);
2237
2238         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv set psmode\n");
2239         return skb;
2240 }
2241
2242 static struct sk_buff *
2243 ath10k_wmi_tlv_op_gen_set_sta_ps(struct ath10k *ar, u32 vdev_id,
2244                                  enum wmi_sta_powersave_param param_id,
2245                                  u32 param_value)
2246 {
2247         struct wmi_sta_powersave_param_cmd *cmd;
2248         struct wmi_tlv *tlv;
2249         struct sk_buff *skb;
2250
2251         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2252         if (!skb)
2253                 return ERR_PTR(-ENOMEM);
2254
2255         tlv = (void *)skb->data;
2256         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_POWERSAVE_PARAM_CMD);
2257         tlv->len = __cpu_to_le16(sizeof(*cmd));
2258         cmd = (void *)tlv->value;
2259         cmd->vdev_id = __cpu_to_le32(vdev_id);
2260         cmd->param_id = __cpu_to_le32(param_id);
2261         cmd->param_value = __cpu_to_le32(param_value);
2262
2263         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv set sta ps\n");
2264         return skb;
2265 }
2266
2267 static struct sk_buff *
2268 ath10k_wmi_tlv_op_gen_set_ap_ps(struct ath10k *ar, u32 vdev_id, const u8 *mac,
2269                                 enum wmi_ap_ps_peer_param param_id, u32 value)
2270 {
2271         struct wmi_ap_ps_peer_cmd *cmd;
2272         struct wmi_tlv *tlv;
2273         struct sk_buff *skb;
2274
2275         if (!mac)
2276                 return ERR_PTR(-EINVAL);
2277
2278         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2279         if (!skb)
2280                 return ERR_PTR(-ENOMEM);
2281
2282         tlv = (void *)skb->data;
2283         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_AP_PS_PEER_CMD);
2284         tlv->len = __cpu_to_le16(sizeof(*cmd));
2285         cmd = (void *)tlv->value;
2286         cmd->vdev_id = __cpu_to_le32(vdev_id);
2287         cmd->param_id = __cpu_to_le32(param_id);
2288         cmd->param_value = __cpu_to_le32(value);
2289         ether_addr_copy(cmd->peer_macaddr.addr, mac);
2290
2291         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv ap ps param\n");
2292         return skb;
2293 }
2294
2295 static struct sk_buff *
2296 ath10k_wmi_tlv_op_gen_scan_chan_list(struct ath10k *ar,
2297                                      const struct wmi_scan_chan_list_arg *arg)
2298 {
2299         struct wmi_tlv_scan_chan_list_cmd *cmd;
2300         struct wmi_channel *ci;
2301         struct wmi_channel_arg *ch;
2302         struct wmi_tlv *tlv;
2303         struct sk_buff *skb;
2304         size_t chans_len, len;
2305         int i;
2306         void *ptr, *chans;
2307
2308         chans_len = arg->n_channels * (sizeof(*tlv) + sizeof(*ci));
2309         len = (sizeof(*tlv) + sizeof(*cmd)) +
2310               (sizeof(*tlv) + chans_len);
2311
2312         skb = ath10k_wmi_alloc_skb(ar, len);
2313         if (!skb)
2314                 return ERR_PTR(-ENOMEM);
2315
2316         ptr = (void *)skb->data;
2317         tlv = ptr;
2318         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_SCAN_CHAN_LIST_CMD);
2319         tlv->len = __cpu_to_le16(sizeof(*cmd));
2320         cmd = (void *)tlv->value;
2321         cmd->num_scan_chans = __cpu_to_le32(arg->n_channels);
2322
2323         ptr += sizeof(*tlv);
2324         ptr += sizeof(*cmd);
2325
2326         tlv = ptr;
2327         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
2328         tlv->len = __cpu_to_le16(chans_len);
2329         chans = (void *)tlv->value;
2330
2331         for (i = 0; i < arg->n_channels; i++) {
2332                 ch = &arg->channels[i];
2333
2334                 tlv = chans;
2335                 tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_CHANNEL);
2336                 tlv->len = __cpu_to_le16(sizeof(*ci));
2337                 ci = (void *)tlv->value;
2338
2339                 ath10k_wmi_put_wmi_channel(ci, ch);
2340
2341                 chans += sizeof(*tlv);
2342                 chans += sizeof(*ci);
2343         }
2344
2345         ptr += sizeof(*tlv);
2346         ptr += chans_len;
2347
2348         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv scan chan list\n");
2349         return skb;
2350 }
2351
2352 static struct sk_buff *
2353 ath10k_wmi_tlv_op_gen_beacon_dma(struct ath10k *ar, u32 vdev_id,
2354                                  const void *bcn, size_t bcn_len,
2355                                  u32 bcn_paddr, bool dtim_zero,
2356                                  bool deliver_cab)
2357
2358 {
2359         struct wmi_bcn_tx_ref_cmd *cmd;
2360         struct wmi_tlv *tlv;
2361         struct sk_buff *skb;
2362         struct ieee80211_hdr *hdr;
2363         u16 fc;
2364
2365         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2366         if (!skb)
2367                 return ERR_PTR(-ENOMEM);
2368
2369         hdr = (struct ieee80211_hdr *)bcn;
2370         fc = le16_to_cpu(hdr->frame_control);
2371
2372         tlv = (void *)skb->data;
2373         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_SEND_FROM_HOST_CMD);
2374         tlv->len = __cpu_to_le16(sizeof(*cmd));
2375         cmd = (void *)tlv->value;
2376         cmd->vdev_id = __cpu_to_le32(vdev_id);
2377         cmd->data_len = __cpu_to_le32(bcn_len);
2378         cmd->data_ptr = __cpu_to_le32(bcn_paddr);
2379         cmd->msdu_id = 0;
2380         cmd->frame_control = __cpu_to_le32(fc);
2381         cmd->flags = 0;
2382
2383         if (dtim_zero)
2384                 cmd->flags |= __cpu_to_le32(WMI_BCN_TX_REF_FLAG_DTIM_ZERO);
2385
2386         if (deliver_cab)
2387                 cmd->flags |= __cpu_to_le32(WMI_BCN_TX_REF_FLAG_DELIVER_CAB);
2388
2389         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv beacon dma\n");
2390         return skb;
2391 }
2392
2393 static struct sk_buff *
2394 ath10k_wmi_tlv_op_gen_pdev_set_wmm(struct ath10k *ar,
2395                                    const struct wmi_wmm_params_all_arg *arg)
2396 {
2397         struct wmi_tlv_pdev_set_wmm_cmd *cmd;
2398         struct wmi_wmm_params *wmm;
2399         struct wmi_tlv *tlv;
2400         struct sk_buff *skb;
2401         size_t len;
2402         void *ptr;
2403
2404         len = (sizeof(*tlv) + sizeof(*cmd)) +
2405               (4 * (sizeof(*tlv) + sizeof(*wmm)));
2406         skb = ath10k_wmi_alloc_skb(ar, len);
2407         if (!skb)
2408                 return ERR_PTR(-ENOMEM);
2409
2410         ptr = (void *)skb->data;
2411
2412         tlv = ptr;
2413         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_WMM_PARAMS_CMD);
2414         tlv->len = __cpu_to_le16(sizeof(*cmd));
2415         cmd = (void *)tlv->value;
2416
2417         /* nothing to set here */
2418
2419         ptr += sizeof(*tlv);
2420         ptr += sizeof(*cmd);
2421
2422         ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_be);
2423         ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_bk);
2424         ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_vi);
2425         ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_vo);
2426
2427         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev set wmm\n");
2428         return skb;
2429 }
2430
2431 static struct sk_buff *
2432 ath10k_wmi_tlv_op_gen_request_stats(struct ath10k *ar, u32 stats_mask)
2433 {
2434         struct wmi_request_stats_cmd *cmd;
2435         struct wmi_tlv *tlv;
2436         struct sk_buff *skb;
2437
2438         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2439         if (!skb)
2440                 return ERR_PTR(-ENOMEM);
2441
2442         tlv = (void *)skb->data;
2443         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_REQUEST_STATS_CMD);
2444         tlv->len = __cpu_to_le16(sizeof(*cmd));
2445         cmd = (void *)tlv->value;
2446         cmd->stats_id = __cpu_to_le32(stats_mask);
2447
2448         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv request stats\n");
2449         return skb;
2450 }
2451
2452 static struct sk_buff *
2453 ath10k_wmi_tlv_op_gen_force_fw_hang(struct ath10k *ar,
2454                                     enum wmi_force_fw_hang_type type,
2455                                     u32 delay_ms)
2456 {
2457         struct wmi_force_fw_hang_cmd *cmd;
2458         struct wmi_tlv *tlv;
2459         struct sk_buff *skb;
2460
2461         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2462         if (!skb)
2463                 return ERR_PTR(-ENOMEM);
2464
2465         tlv = (void *)skb->data;
2466         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_FORCE_FW_HANG_CMD);
2467         tlv->len = __cpu_to_le16(sizeof(*cmd));
2468         cmd = (void *)tlv->value;
2469         cmd->type = __cpu_to_le32(type);
2470         cmd->delay_ms = __cpu_to_le32(delay_ms);
2471
2472         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv force fw hang\n");
2473         return skb;
2474 }
2475
2476 static struct sk_buff *
2477 ath10k_wmi_tlv_op_gen_dbglog_cfg(struct ath10k *ar, u64 module_enable,
2478                                  u32 log_level) {
2479         struct wmi_tlv_dbglog_cmd *cmd;
2480         struct wmi_tlv *tlv;
2481         struct sk_buff *skb;
2482         size_t len, bmap_len;
2483         u32 value;
2484         void *ptr;
2485
2486         if (module_enable) {
2487                 value = WMI_TLV_DBGLOG_LOG_LEVEL_VALUE(
2488                                 module_enable,
2489                                 WMI_TLV_DBGLOG_LOG_LEVEL_VERBOSE);
2490         } else {
2491                 value = WMI_TLV_DBGLOG_LOG_LEVEL_VALUE(
2492                                 WMI_TLV_DBGLOG_ALL_MODULES,
2493                                 WMI_TLV_DBGLOG_LOG_LEVEL_WARN);
2494         }
2495
2496         bmap_len = 0;
2497         len = sizeof(*tlv) + sizeof(*cmd) + sizeof(*tlv) + bmap_len;
2498         skb = ath10k_wmi_alloc_skb(ar, len);
2499         if (!skb)
2500                 return ERR_PTR(-ENOMEM);
2501
2502         ptr = (void *)skb->data;
2503
2504         tlv = ptr;
2505         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_DEBUG_LOG_CONFIG_CMD);
2506         tlv->len = __cpu_to_le16(sizeof(*cmd));
2507         cmd = (void *)tlv->value;
2508         cmd->param = __cpu_to_le32(WMI_TLV_DBGLOG_PARAM_LOG_LEVEL);
2509         cmd->value = __cpu_to_le32(value);
2510
2511         ptr += sizeof(*tlv);
2512         ptr += sizeof(*cmd);
2513
2514         tlv = ptr;
2515         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
2516         tlv->len = __cpu_to_le16(bmap_len);
2517
2518         /* nothing to do here */
2519
2520         ptr += sizeof(*tlv);
2521         ptr += sizeof(bmap_len);
2522
2523         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv dbglog value 0x%08x\n", value);
2524         return skb;
2525 }
2526
2527 static struct sk_buff *
2528 ath10k_wmi_tlv_op_gen_pktlog_enable(struct ath10k *ar, u32 filter)
2529 {
2530         struct wmi_tlv_pktlog_enable *cmd;
2531         struct wmi_tlv *tlv;
2532         struct sk_buff *skb;
2533         void *ptr;
2534         size_t len;
2535
2536         len = sizeof(*tlv) + sizeof(*cmd);
2537         skb = ath10k_wmi_alloc_skb(ar, len);
2538         if (!skb)
2539                 return ERR_PTR(-ENOMEM);
2540
2541         ptr = (void *)skb->data;
2542         tlv = ptr;
2543         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_PKTLOG_ENABLE_CMD);
2544         tlv->len = __cpu_to_le16(sizeof(*cmd));
2545         cmd = (void *)tlv->value;
2546         cmd->filter = __cpu_to_le32(filter);
2547
2548         ptr += sizeof(*tlv);
2549         ptr += sizeof(*cmd);
2550
2551         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pktlog enable filter 0x%08x\n",
2552                    filter);
2553         return skb;
2554 }
2555
2556 static struct sk_buff *
2557 ath10k_wmi_tlv_op_gen_pktlog_disable(struct ath10k *ar)
2558 {
2559         struct wmi_tlv_pktlog_disable *cmd;
2560         struct wmi_tlv *tlv;
2561         struct sk_buff *skb;
2562         void *ptr;
2563         size_t len;
2564
2565         len = sizeof(*tlv) + sizeof(*cmd);
2566         skb = ath10k_wmi_alloc_skb(ar, len);
2567         if (!skb)
2568                 return ERR_PTR(-ENOMEM);
2569
2570         ptr = (void *)skb->data;
2571         tlv = ptr;
2572         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_PKTLOG_DISABLE_CMD);
2573         tlv->len = __cpu_to_le16(sizeof(*cmd));
2574         cmd = (void *)tlv->value;
2575
2576         ptr += sizeof(*tlv);
2577         ptr += sizeof(*cmd);
2578
2579         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pktlog disable\n");
2580         return skb;
2581 }
2582
2583 static struct sk_buff *
2584 ath10k_wmi_tlv_op_gen_bcn_tmpl(struct ath10k *ar, u32 vdev_id,
2585                                u32 tim_ie_offset, struct sk_buff *bcn,
2586                                u32 prb_caps, u32 prb_erp, void *prb_ies,
2587                                size_t prb_ies_len)
2588 {
2589         struct wmi_tlv_bcn_tmpl_cmd *cmd;
2590         struct wmi_tlv_bcn_prb_info *info;
2591         struct wmi_tlv *tlv;
2592         struct sk_buff *skb;
2593         void *ptr;
2594         size_t len;
2595
2596         if (WARN_ON(prb_ies_len > 0 && !prb_ies))
2597                 return ERR_PTR(-EINVAL);
2598
2599         len = sizeof(*tlv) + sizeof(*cmd) +
2600               sizeof(*tlv) + sizeof(*info) + prb_ies_len +
2601               sizeof(*tlv) + roundup(bcn->len, 4);
2602         skb = ath10k_wmi_alloc_skb(ar, len);
2603         if (!skb)
2604                 return ERR_PTR(-ENOMEM);
2605
2606         ptr = (void *)skb->data;
2607         tlv = ptr;
2608         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_TMPL_CMD);
2609         tlv->len = __cpu_to_le16(sizeof(*cmd));
2610         cmd = (void *)tlv->value;
2611         cmd->vdev_id = __cpu_to_le32(vdev_id);
2612         cmd->tim_ie_offset = __cpu_to_le32(tim_ie_offset);
2613         cmd->buf_len = __cpu_to_le32(bcn->len);
2614
2615         ptr += sizeof(*tlv);
2616         ptr += sizeof(*cmd);
2617
2618         /* FIXME: prb_ies_len should be probably aligned to 4byte boundary but
2619          * then it is then impossible to pass original ie len.
2620          * This chunk is not used yet so if setting probe resp template yields
2621          * problems with beaconing or crashes firmware look here.
2622          */
2623         tlv = ptr;
2624         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_PRB_INFO);
2625         tlv->len = __cpu_to_le16(sizeof(*info) + prb_ies_len);
2626         info = (void *)tlv->value;
2627         info->caps = __cpu_to_le32(prb_caps);
2628         info->erp = __cpu_to_le32(prb_erp);
2629         memcpy(info->ies, prb_ies, prb_ies_len);
2630
2631         ptr += sizeof(*tlv);
2632         ptr += sizeof(*info);
2633         ptr += prb_ies_len;
2634
2635         tlv = ptr;
2636         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2637         tlv->len = __cpu_to_le16(roundup(bcn->len, 4));
2638         memcpy(tlv->value, bcn->data, bcn->len);
2639
2640         /* FIXME: Adjust TSF? */
2641
2642         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv bcn tmpl vdev_id %i\n",
2643                    vdev_id);
2644         return skb;
2645 }
2646
2647 static struct sk_buff *
2648 ath10k_wmi_tlv_op_gen_prb_tmpl(struct ath10k *ar, u32 vdev_id,
2649                                struct sk_buff *prb)
2650 {
2651         struct wmi_tlv_prb_tmpl_cmd *cmd;
2652         struct wmi_tlv_bcn_prb_info *info;
2653         struct wmi_tlv *tlv;
2654         struct sk_buff *skb;
2655         void *ptr;
2656         size_t len;
2657
2658         len = sizeof(*tlv) + sizeof(*cmd) +
2659               sizeof(*tlv) + sizeof(*info) +
2660               sizeof(*tlv) + roundup(prb->len, 4);
2661         skb = ath10k_wmi_alloc_skb(ar, len);
2662         if (!skb)
2663                 return ERR_PTR(-ENOMEM);
2664
2665         ptr = (void *)skb->data;
2666         tlv = ptr;
2667         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PRB_TMPL_CMD);
2668         tlv->len = __cpu_to_le16(sizeof(*cmd));
2669         cmd = (void *)tlv->value;
2670         cmd->vdev_id = __cpu_to_le32(vdev_id);
2671         cmd->buf_len = __cpu_to_le32(prb->len);
2672
2673         ptr += sizeof(*tlv);
2674         ptr += sizeof(*cmd);
2675
2676         tlv = ptr;
2677         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_PRB_INFO);
2678         tlv->len = __cpu_to_le16(sizeof(*info));
2679         info = (void *)tlv->value;
2680         info->caps = 0;
2681         info->erp = 0;
2682
2683         ptr += sizeof(*tlv);
2684         ptr += sizeof(*info);
2685
2686         tlv = ptr;
2687         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2688         tlv->len = __cpu_to_le16(roundup(prb->len, 4));
2689         memcpy(tlv->value, prb->data, prb->len);
2690
2691         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv prb tmpl vdev_id %i\n",
2692                    vdev_id);
2693         return skb;
2694 }
2695
2696 static struct sk_buff *
2697 ath10k_wmi_tlv_op_gen_p2p_go_bcn_ie(struct ath10k *ar, u32 vdev_id,
2698                                     const u8 *p2p_ie)
2699 {
2700         struct wmi_tlv_p2p_go_bcn_ie *cmd;
2701         struct wmi_tlv *tlv;
2702         struct sk_buff *skb;
2703         void *ptr;
2704         size_t len;
2705
2706         len = sizeof(*tlv) + sizeof(*cmd) +
2707               sizeof(*tlv) + roundup(p2p_ie[1] + 2, 4);
2708         skb = ath10k_wmi_alloc_skb(ar, len);
2709         if (!skb)
2710                 return ERR_PTR(-ENOMEM);
2711
2712         ptr = (void *)skb->data;
2713         tlv = ptr;
2714         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_P2P_GO_SET_BEACON_IE);
2715         tlv->len = __cpu_to_le16(sizeof(*cmd));
2716         cmd = (void *)tlv->value;
2717         cmd->vdev_id = __cpu_to_le32(vdev_id);
2718         cmd->ie_len = __cpu_to_le32(p2p_ie[1] + 2);
2719
2720         ptr += sizeof(*tlv);
2721         ptr += sizeof(*cmd);
2722
2723         tlv = ptr;
2724         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2725         tlv->len = __cpu_to_le16(roundup(p2p_ie[1] + 2, 4));
2726         memcpy(tlv->value, p2p_ie, p2p_ie[1] + 2);
2727
2728         ptr += sizeof(*tlv);
2729         ptr += roundup(p2p_ie[1] + 2, 4);
2730
2731         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv p2p go bcn ie for vdev %i\n",
2732                    vdev_id);
2733         return skb;
2734 }
2735
2736 static struct sk_buff *
2737 ath10k_wmi_tlv_op_gen_update_fw_tdls_state(struct ath10k *ar, u32 vdev_id,
2738                                            enum wmi_tdls_state state)
2739 {
2740         struct wmi_tdls_set_state_cmd *cmd;
2741         struct wmi_tlv *tlv;
2742         struct sk_buff *skb;
2743         void *ptr;
2744         size_t len;
2745         /* Set to options from wmi_tlv_tdls_options,
2746          * for now none of them are enabled.
2747          */
2748         u32 options = 0;
2749
2750         len = sizeof(*tlv) + sizeof(*cmd);
2751         skb = ath10k_wmi_alloc_skb(ar, len);
2752         if (!skb)
2753                 return ERR_PTR(-ENOMEM);
2754
2755         ptr = (void *)skb->data;
2756         tlv = ptr;
2757         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_TDLS_SET_STATE_CMD);
2758         tlv->len = __cpu_to_le16(sizeof(*cmd));
2759
2760         cmd = (void *)tlv->value;
2761         cmd->vdev_id = __cpu_to_le32(vdev_id);
2762         cmd->state = __cpu_to_le32(state);
2763         cmd->notification_interval_ms = __cpu_to_le32(5000);
2764         cmd->tx_discovery_threshold = __cpu_to_le32(100);
2765         cmd->tx_teardown_threshold = __cpu_to_le32(5);
2766         cmd->rssi_teardown_threshold = __cpu_to_le32(-75);
2767         cmd->rssi_delta = __cpu_to_le32(-20);
2768         cmd->tdls_options = __cpu_to_le32(options);
2769         cmd->tdls_peer_traffic_ind_window = __cpu_to_le32(2);
2770         cmd->tdls_peer_traffic_response_timeout_ms = __cpu_to_le32(5000);
2771         cmd->tdls_puapsd_mask = __cpu_to_le32(0xf);
2772         cmd->tdls_puapsd_inactivity_time_ms = __cpu_to_le32(0);
2773         cmd->tdls_puapsd_rx_frame_threshold = __cpu_to_le32(10);
2774
2775         ptr += sizeof(*tlv);
2776         ptr += sizeof(*cmd);
2777
2778         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv update fw tdls state %d for vdev %i\n",
2779                    state, vdev_id);
2780         return skb;
2781 }
2782
2783 static u32 ath10k_wmi_tlv_prepare_peer_qos(u8 uapsd_queues, u8 sp)
2784 {
2785         u32 peer_qos = 0;
2786
2787         if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_VO)
2788                 peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_VO;
2789         if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_VI)
2790                 peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_VI;
2791         if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_BK)
2792                 peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_BK;
2793         if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_BE)
2794                 peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_BE;
2795
2796         peer_qos |= SM(sp, WMI_TLV_TDLS_PEER_SP);
2797
2798         return peer_qos;
2799 }
2800
2801 static struct sk_buff *
2802 ath10k_wmi_tlv_op_gen_tdls_peer_update(struct ath10k *ar,
2803                                        const struct wmi_tdls_peer_update_cmd_arg *arg,
2804                                        const struct wmi_tdls_peer_capab_arg *cap,
2805                                        const struct wmi_channel_arg *chan_arg)
2806 {
2807         struct wmi_tdls_peer_update_cmd *cmd;
2808         struct wmi_tdls_peer_capab *peer_cap;
2809         struct wmi_channel *chan;
2810         struct wmi_tlv *tlv;
2811         struct sk_buff *skb;
2812         u32 peer_qos;
2813         void *ptr;
2814         int len;
2815         int i;
2816
2817         len = sizeof(*tlv) + sizeof(*cmd) +
2818               sizeof(*tlv) + sizeof(*peer_cap) +
2819               sizeof(*tlv) + cap->peer_chan_len * sizeof(*chan);
2820
2821         skb = ath10k_wmi_alloc_skb(ar, len);
2822         if (!skb)
2823                 return ERR_PTR(-ENOMEM);
2824
2825         ptr = (void *)skb->data;
2826         tlv = ptr;
2827         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_TDLS_PEER_UPDATE_CMD);
2828         tlv->len = __cpu_to_le16(sizeof(*cmd));
2829
2830         cmd = (void *)tlv->value;
2831         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
2832         ether_addr_copy(cmd->peer_macaddr.addr, arg->addr);
2833         cmd->peer_state = __cpu_to_le32(arg->peer_state);
2834
2835         ptr += sizeof(*tlv);
2836         ptr += sizeof(*cmd);
2837
2838         tlv = ptr;
2839         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_TDLS_PEER_CAPABILITIES);
2840         tlv->len = __cpu_to_le16(sizeof(*peer_cap));
2841         peer_cap = (void *)tlv->value;
2842         peer_qos = ath10k_wmi_tlv_prepare_peer_qos(cap->peer_uapsd_queues,
2843                                                    cap->peer_max_sp);
2844         peer_cap->peer_qos = __cpu_to_le32(peer_qos);
2845         peer_cap->buff_sta_support = __cpu_to_le32(cap->buff_sta_support);
2846         peer_cap->off_chan_support = __cpu_to_le32(cap->off_chan_support);
2847         peer_cap->peer_curr_operclass = __cpu_to_le32(cap->peer_curr_operclass);
2848         peer_cap->self_curr_operclass = __cpu_to_le32(cap->self_curr_operclass);
2849         peer_cap->peer_chan_len = __cpu_to_le32(cap->peer_chan_len);
2850         peer_cap->peer_operclass_len = __cpu_to_le32(cap->peer_operclass_len);
2851
2852         for (i = 0; i < WMI_TDLS_MAX_SUPP_OPER_CLASSES; i++)
2853                 peer_cap->peer_operclass[i] = cap->peer_operclass[i];
2854
2855         peer_cap->is_peer_responder = __cpu_to_le32(cap->is_peer_responder);
2856         peer_cap->pref_offchan_num = __cpu_to_le32(cap->pref_offchan_num);
2857         peer_cap->pref_offchan_bw = __cpu_to_le32(cap->pref_offchan_bw);
2858
2859         ptr += sizeof(*tlv);
2860         ptr += sizeof(*peer_cap);
2861
2862         tlv = ptr;
2863         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
2864         tlv->len = __cpu_to_le16(cap->peer_chan_len * sizeof(*chan));
2865
2866         ptr += sizeof(*tlv);
2867
2868         for (i = 0; i < cap->peer_chan_len; i++) {
2869                 tlv = ptr;
2870                 tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_CHANNEL);
2871                 tlv->len = __cpu_to_le16(sizeof(*chan));
2872                 chan = (void *)tlv->value;
2873                 ath10k_wmi_put_wmi_channel(chan, &chan_arg[i]);
2874
2875                 ptr += sizeof(*tlv);
2876                 ptr += sizeof(*chan);
2877         }
2878
2879         ath10k_dbg(ar, ATH10K_DBG_WMI,
2880                    "wmi tlv tdls peer update vdev %i state %d n_chans %u\n",
2881                    arg->vdev_id, arg->peer_state, cap->peer_chan_len);
2882         return skb;
2883 }
2884
2885 static struct sk_buff *
2886 ath10k_wmi_tlv_op_gen_wow_enable(struct ath10k *ar)
2887 {
2888         struct wmi_tlv_wow_enable_cmd *cmd;
2889         struct wmi_tlv *tlv;
2890         struct sk_buff *skb;
2891         size_t len;
2892
2893         len = sizeof(*tlv) + sizeof(*cmd);
2894         skb = ath10k_wmi_alloc_skb(ar, len);
2895         if (!skb)
2896                 return ERR_PTR(-ENOMEM);
2897
2898         tlv = (struct wmi_tlv *)skb->data;
2899         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_ENABLE_CMD);
2900         tlv->len = __cpu_to_le16(sizeof(*cmd));
2901         cmd = (void *)tlv->value;
2902
2903         cmd->enable = __cpu_to_le32(1);
2904
2905         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow enable\n");
2906         return skb;
2907 }
2908
2909 static struct sk_buff *
2910 ath10k_wmi_tlv_op_gen_wow_add_wakeup_event(struct ath10k *ar,
2911                                            u32 vdev_id,
2912                                            enum wmi_wow_wakeup_event event,
2913                                            u32 enable)
2914 {
2915         struct wmi_tlv_wow_add_del_event_cmd *cmd;
2916         struct wmi_tlv *tlv;
2917         struct sk_buff *skb;
2918         size_t len;
2919
2920         len = sizeof(*tlv) + sizeof(*cmd);
2921         skb = ath10k_wmi_alloc_skb(ar, len);
2922         if (!skb)
2923                 return ERR_PTR(-ENOMEM);
2924
2925         tlv = (struct wmi_tlv *)skb->data;
2926         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_ADD_DEL_EVT_CMD);
2927         tlv->len = __cpu_to_le16(sizeof(*cmd));
2928         cmd = (void *)tlv->value;
2929
2930         cmd->vdev_id = __cpu_to_le32(vdev_id);
2931         cmd->is_add = __cpu_to_le32(enable);
2932         cmd->event_bitmap = __cpu_to_le32(1 << event);
2933
2934         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow add wakeup event %s enable %d vdev_id %d\n",
2935                    wow_wakeup_event(event), enable, vdev_id);
2936         return skb;
2937 }
2938
2939 static struct sk_buff *
2940 ath10k_wmi_tlv_gen_wow_host_wakeup_ind(struct ath10k *ar)
2941 {
2942         struct wmi_tlv_wow_host_wakeup_ind *cmd;
2943         struct wmi_tlv *tlv;
2944         struct sk_buff *skb;
2945         size_t len;
2946
2947         len = sizeof(*tlv) + sizeof(*cmd);
2948         skb = ath10k_wmi_alloc_skb(ar, len);
2949         if (!skb)
2950                 return ERR_PTR(-ENOMEM);
2951
2952         tlv = (struct wmi_tlv *)skb->data;
2953         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_HOSTWAKEUP_FROM_SLEEP_CMD);
2954         tlv->len = __cpu_to_le16(sizeof(*cmd));
2955         cmd = (void *)tlv->value;
2956
2957         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow host wakeup ind\n");
2958         return skb;
2959 }
2960
2961 static struct sk_buff *
2962 ath10k_wmi_tlv_op_gen_wow_add_pattern(struct ath10k *ar, u32 vdev_id,
2963                                       u32 pattern_id, const u8 *pattern,
2964                                       const u8 *bitmask, int pattern_len,
2965                                       int pattern_offset)
2966 {
2967         struct wmi_tlv_wow_add_pattern_cmd *cmd;
2968         struct wmi_tlv_wow_bitmap_pattern *bitmap;
2969         struct wmi_tlv *tlv;
2970         struct sk_buff *skb;
2971         void *ptr;
2972         size_t len;
2973
2974         len = sizeof(*tlv) + sizeof(*cmd) +
2975               sizeof(*tlv) +                    /* array struct */
2976               sizeof(*tlv) + sizeof(*bitmap) +  /* bitmap */
2977               sizeof(*tlv) +                    /* empty ipv4 sync */
2978               sizeof(*tlv) +                    /* empty ipv6 sync */
2979               sizeof(*tlv) +                    /* empty magic */
2980               sizeof(*tlv) +                    /* empty info timeout */
2981               sizeof(*tlv) + sizeof(u32);       /* ratelimit interval */
2982
2983         skb = ath10k_wmi_alloc_skb(ar, len);
2984         if (!skb)
2985                 return ERR_PTR(-ENOMEM);
2986
2987         /* cmd */
2988         ptr = (void *)skb->data;
2989         tlv = ptr;
2990         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_ADD_PATTERN_CMD);
2991         tlv->len = __cpu_to_le16(sizeof(*cmd));
2992         cmd = (void *)tlv->value;
2993
2994         cmd->vdev_id = __cpu_to_le32(vdev_id);
2995         cmd->pattern_id = __cpu_to_le32(pattern_id);
2996         cmd->pattern_type = __cpu_to_le32(WOW_BITMAP_PATTERN);
2997
2998         ptr += sizeof(*tlv);
2999         ptr += sizeof(*cmd);
3000
3001         /* bitmap */
3002         tlv = ptr;
3003         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3004         tlv->len = __cpu_to_le16(sizeof(*tlv) + sizeof(*bitmap));
3005
3006         ptr += sizeof(*tlv);
3007
3008         tlv = ptr;
3009         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_BITMAP_PATTERN_T);
3010         tlv->len = __cpu_to_le16(sizeof(*bitmap));
3011         bitmap = (void *)tlv->value;
3012
3013         memcpy(bitmap->patternbuf, pattern, pattern_len);
3014         memcpy(bitmap->bitmaskbuf, bitmask, pattern_len);
3015         bitmap->pattern_offset = __cpu_to_le32(pattern_offset);
3016         bitmap->pattern_len = __cpu_to_le32(pattern_len);
3017         bitmap->bitmask_len = __cpu_to_le32(pattern_len);
3018         bitmap->pattern_id = __cpu_to_le32(pattern_id);
3019
3020         ptr += sizeof(*tlv);
3021         ptr += sizeof(*bitmap);
3022
3023         /* ipv4 sync */
3024         tlv = ptr;
3025         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3026         tlv->len = __cpu_to_le16(0);
3027
3028         ptr += sizeof(*tlv);
3029
3030         /* ipv6 sync */
3031         tlv = ptr;
3032         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3033         tlv->len = __cpu_to_le16(0);
3034
3035         ptr += sizeof(*tlv);
3036
3037         /* magic */
3038         tlv = ptr;
3039         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3040         tlv->len = __cpu_to_le16(0);
3041
3042         ptr += sizeof(*tlv);
3043
3044         /* pattern info timeout */
3045         tlv = ptr;
3046         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
3047         tlv->len = __cpu_to_le16(0);
3048
3049         ptr += sizeof(*tlv);
3050
3051         /* ratelimit interval */
3052         tlv = ptr;
3053         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
3054         tlv->len = __cpu_to_le16(sizeof(u32));
3055
3056         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow add pattern vdev_id %d pattern_id %d, pattern_offset %d\n",
3057                    vdev_id, pattern_id, pattern_offset);
3058         return skb;
3059 }
3060
3061 static struct sk_buff *
3062 ath10k_wmi_tlv_op_gen_wow_del_pattern(struct ath10k *ar, u32 vdev_id,
3063                                       u32 pattern_id)
3064 {
3065         struct wmi_tlv_wow_del_pattern_cmd *cmd;
3066         struct wmi_tlv *tlv;
3067         struct sk_buff *skb;
3068         size_t len;
3069
3070         len = sizeof(*tlv) + sizeof(*cmd);
3071         skb = ath10k_wmi_alloc_skb(ar, len);
3072         if (!skb)
3073                 return ERR_PTR(-ENOMEM);
3074
3075         tlv = (struct wmi_tlv *)skb->data;
3076         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_DEL_PATTERN_CMD);
3077         tlv->len = __cpu_to_le16(sizeof(*cmd));
3078         cmd = (void *)tlv->value;
3079
3080         cmd->vdev_id = __cpu_to_le32(vdev_id);
3081         cmd->pattern_id = __cpu_to_le32(pattern_id);
3082         cmd->pattern_type = __cpu_to_le32(WOW_BITMAP_PATTERN);
3083
3084         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow del pattern vdev_id %d pattern_id %d\n",
3085                    vdev_id, pattern_id);
3086         return skb;
3087 }
3088
3089 static struct sk_buff *
3090 ath10k_wmi_tlv_op_gen_adaptive_qcs(struct ath10k *ar, bool enable)
3091 {
3092         struct wmi_tlv_adaptive_qcs *cmd;
3093         struct wmi_tlv *tlv;
3094         struct sk_buff *skb;
3095         void *ptr;
3096         size_t len;
3097
3098         len = sizeof(*tlv) + sizeof(*cmd);
3099         skb = ath10k_wmi_alloc_skb(ar, len);
3100         if (!skb)
3101                 return ERR_PTR(-ENOMEM);
3102
3103         ptr = (void *)skb->data;
3104         tlv = ptr;
3105         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_RESMGR_ADAPTIVE_OCS_CMD);
3106         tlv->len = __cpu_to_le16(sizeof(*cmd));
3107         cmd = (void *)tlv->value;
3108         cmd->enable = __cpu_to_le32(enable ? 1 : 0);
3109
3110         ptr += sizeof(*tlv);
3111         ptr += sizeof(*cmd);
3112
3113         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv adaptive qcs %d\n", enable);
3114         return skb;
3115 }
3116
3117 static struct sk_buff *
3118 ath10k_wmi_tlv_op_gen_echo(struct ath10k *ar, u32 value)
3119 {
3120         struct wmi_echo_cmd *cmd;
3121         struct wmi_tlv *tlv;
3122         struct sk_buff *skb;
3123         void *ptr;
3124         size_t len;
3125
3126         len = sizeof(*tlv) + sizeof(*cmd);
3127         skb = ath10k_wmi_alloc_skb(ar, len);
3128         if (!skb)
3129                 return ERR_PTR(-ENOMEM);
3130
3131         ptr = (void *)skb->data;
3132         tlv = ptr;
3133         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_ECHO_CMD);
3134         tlv->len = __cpu_to_le16(sizeof(*cmd));
3135         cmd = (void *)tlv->value;
3136         cmd->value = cpu_to_le32(value);
3137
3138         ptr += sizeof(*tlv);
3139         ptr += sizeof(*cmd);
3140
3141         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv echo value 0x%08x\n", value);
3142         return skb;
3143 }
3144
3145 static struct sk_buff *
3146 ath10k_wmi_tlv_op_gen_vdev_spectral_conf(struct ath10k *ar,
3147                                          const struct wmi_vdev_spectral_conf_arg *arg)
3148 {
3149         struct wmi_vdev_spectral_conf_cmd *cmd;
3150         struct sk_buff *skb;
3151         struct wmi_tlv *tlv;
3152         void *ptr;
3153         size_t len;
3154
3155         len = sizeof(*tlv) + sizeof(*cmd);
3156         skb = ath10k_wmi_alloc_skb(ar, len);
3157         if (!skb)
3158                 return ERR_PTR(-ENOMEM);
3159
3160         ptr = (void *)skb->data;
3161         tlv = ptr;
3162         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SPECTRAL_CONFIGURE_CMD);
3163         tlv->len = __cpu_to_le16(sizeof(*cmd));
3164         cmd = (void *)tlv->value;
3165         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
3166         cmd->scan_count = __cpu_to_le32(arg->scan_count);
3167         cmd->scan_period = __cpu_to_le32(arg->scan_period);
3168         cmd->scan_priority = __cpu_to_le32(arg->scan_priority);
3169         cmd->scan_fft_size = __cpu_to_le32(arg->scan_fft_size);
3170         cmd->scan_gc_ena = __cpu_to_le32(arg->scan_gc_ena);
3171         cmd->scan_restart_ena = __cpu_to_le32(arg->scan_restart_ena);
3172         cmd->scan_noise_floor_ref = __cpu_to_le32(arg->scan_noise_floor_ref);
3173         cmd->scan_init_delay = __cpu_to_le32(arg->scan_init_delay);
3174         cmd->scan_nb_tone_thr = __cpu_to_le32(arg->scan_nb_tone_thr);
3175         cmd->scan_str_bin_thr = __cpu_to_le32(arg->scan_str_bin_thr);
3176         cmd->scan_wb_rpt_mode = __cpu_to_le32(arg->scan_wb_rpt_mode);
3177         cmd->scan_rssi_rpt_mode = __cpu_to_le32(arg->scan_rssi_rpt_mode);
3178         cmd->scan_rssi_thr = __cpu_to_le32(arg->scan_rssi_thr);
3179         cmd->scan_pwr_format = __cpu_to_le32(arg->scan_pwr_format);
3180         cmd->scan_rpt_mode = __cpu_to_le32(arg->scan_rpt_mode);
3181         cmd->scan_bin_scale = __cpu_to_le32(arg->scan_bin_scale);
3182         cmd->scan_dbm_adj = __cpu_to_le32(arg->scan_dbm_adj);
3183         cmd->scan_chn_mask = __cpu_to_le32(arg->scan_chn_mask);
3184
3185         return skb;
3186 }
3187
3188 static struct sk_buff *
3189 ath10k_wmi_tlv_op_gen_vdev_spectral_enable(struct ath10k *ar, u32 vdev_id,
3190                                            u32 trigger, u32 enable)
3191 {
3192         struct wmi_vdev_spectral_enable_cmd *cmd;
3193         struct sk_buff *skb;
3194         struct wmi_tlv *tlv;
3195         void *ptr;
3196         size_t len;
3197
3198         len = sizeof(*tlv) + sizeof(*cmd);
3199         skb = ath10k_wmi_alloc_skb(ar, len);
3200         if (!skb)
3201                 return ERR_PTR(-ENOMEM);
3202
3203         ptr = (void *)skb->data;
3204         tlv = ptr;
3205         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SPECTRAL_ENABLE_CMD);
3206         tlv->len = __cpu_to_le16(sizeof(*cmd));
3207         cmd = (void *)tlv->value;
3208         cmd->vdev_id = __cpu_to_le32(vdev_id);
3209         cmd->trigger_cmd = __cpu_to_le32(trigger);
3210         cmd->enable_cmd = __cpu_to_le32(enable);
3211
3212         return skb;
3213 }
3214
3215 /****************/
3216 /* TLV mappings */
3217 /****************/
3218
3219 static struct wmi_cmd_map wmi_tlv_cmd_map = {
3220         .init_cmdid = WMI_TLV_INIT_CMDID,
3221         .start_scan_cmdid = WMI_TLV_START_SCAN_CMDID,
3222         .stop_scan_cmdid = WMI_TLV_STOP_SCAN_CMDID,
3223         .scan_chan_list_cmdid = WMI_TLV_SCAN_CHAN_LIST_CMDID,
3224         .scan_sch_prio_tbl_cmdid = WMI_TLV_SCAN_SCH_PRIO_TBL_CMDID,
3225         .pdev_set_regdomain_cmdid = WMI_TLV_PDEV_SET_REGDOMAIN_CMDID,
3226         .pdev_set_channel_cmdid = WMI_TLV_PDEV_SET_CHANNEL_CMDID,
3227         .pdev_set_param_cmdid = WMI_TLV_PDEV_SET_PARAM_CMDID,
3228         .pdev_pktlog_enable_cmdid = WMI_TLV_PDEV_PKTLOG_ENABLE_CMDID,
3229         .pdev_pktlog_disable_cmdid = WMI_TLV_PDEV_PKTLOG_DISABLE_CMDID,
3230         .pdev_set_wmm_params_cmdid = WMI_TLV_PDEV_SET_WMM_PARAMS_CMDID,
3231         .pdev_set_ht_cap_ie_cmdid = WMI_TLV_PDEV_SET_HT_CAP_IE_CMDID,
3232         .pdev_set_vht_cap_ie_cmdid = WMI_TLV_PDEV_SET_VHT_CAP_IE_CMDID,
3233         .pdev_set_dscp_tid_map_cmdid = WMI_TLV_PDEV_SET_DSCP_TID_MAP_CMDID,
3234         .pdev_set_quiet_mode_cmdid = WMI_TLV_PDEV_SET_QUIET_MODE_CMDID,
3235         .pdev_green_ap_ps_enable_cmdid = WMI_TLV_PDEV_GREEN_AP_PS_ENABLE_CMDID,
3236         .pdev_get_tpc_config_cmdid = WMI_TLV_PDEV_GET_TPC_CONFIG_CMDID,
3237         .pdev_set_base_macaddr_cmdid = WMI_TLV_PDEV_SET_BASE_MACADDR_CMDID,
3238         .vdev_create_cmdid = WMI_TLV_VDEV_CREATE_CMDID,
3239         .vdev_delete_cmdid = WMI_TLV_VDEV_DELETE_CMDID,
3240         .vdev_start_request_cmdid = WMI_TLV_VDEV_START_REQUEST_CMDID,
3241         .vdev_restart_request_cmdid = WMI_TLV_VDEV_RESTART_REQUEST_CMDID,
3242         .vdev_up_cmdid = WMI_TLV_VDEV_UP_CMDID,
3243         .vdev_stop_cmdid = WMI_TLV_VDEV_STOP_CMDID,
3244         .vdev_down_cmdid = WMI_TLV_VDEV_DOWN_CMDID,
3245         .vdev_set_param_cmdid = WMI_TLV_VDEV_SET_PARAM_CMDID,
3246         .vdev_install_key_cmdid = WMI_TLV_VDEV_INSTALL_KEY_CMDID,
3247         .peer_create_cmdid = WMI_TLV_PEER_CREATE_CMDID,
3248         .peer_delete_cmdid = WMI_TLV_PEER_DELETE_CMDID,
3249         .peer_flush_tids_cmdid = WMI_TLV_PEER_FLUSH_TIDS_CMDID,
3250         .peer_set_param_cmdid = WMI_TLV_PEER_SET_PARAM_CMDID,
3251         .peer_assoc_cmdid = WMI_TLV_PEER_ASSOC_CMDID,
3252         .peer_add_wds_entry_cmdid = WMI_TLV_PEER_ADD_WDS_ENTRY_CMDID,
3253         .peer_remove_wds_entry_cmdid = WMI_TLV_PEER_REMOVE_WDS_ENTRY_CMDID,
3254         .peer_mcast_group_cmdid = WMI_TLV_PEER_MCAST_GROUP_CMDID,
3255         .bcn_tx_cmdid = WMI_TLV_BCN_TX_CMDID,
3256         .pdev_send_bcn_cmdid = WMI_TLV_PDEV_SEND_BCN_CMDID,
3257         .bcn_tmpl_cmdid = WMI_TLV_BCN_TMPL_CMDID,
3258         .bcn_filter_rx_cmdid = WMI_TLV_BCN_FILTER_RX_CMDID,
3259         .prb_req_filter_rx_cmdid = WMI_TLV_PRB_REQ_FILTER_RX_CMDID,
3260         .mgmt_tx_cmdid = WMI_TLV_MGMT_TX_CMDID,
3261         .prb_tmpl_cmdid = WMI_TLV_PRB_TMPL_CMDID,
3262         .addba_clear_resp_cmdid = WMI_TLV_ADDBA_CLEAR_RESP_CMDID,
3263         .addba_send_cmdid = WMI_TLV_ADDBA_SEND_CMDID,
3264         .addba_status_cmdid = WMI_TLV_ADDBA_STATUS_CMDID,
3265         .delba_send_cmdid = WMI_TLV_DELBA_SEND_CMDID,
3266         .addba_set_resp_cmdid = WMI_TLV_ADDBA_SET_RESP_CMDID,
3267         .send_singleamsdu_cmdid = WMI_TLV_SEND_SINGLEAMSDU_CMDID,
3268         .sta_powersave_mode_cmdid = WMI_TLV_STA_POWERSAVE_MODE_CMDID,
3269         .sta_powersave_param_cmdid = WMI_TLV_STA_POWERSAVE_PARAM_CMDID,
3270         .sta_mimo_ps_mode_cmdid = WMI_TLV_STA_MIMO_PS_MODE_CMDID,
3271         .pdev_dfs_enable_cmdid = WMI_TLV_PDEV_DFS_ENABLE_CMDID,
3272         .pdev_dfs_disable_cmdid = WMI_TLV_PDEV_DFS_DISABLE_CMDID,
3273         .roam_scan_mode = WMI_TLV_ROAM_SCAN_MODE,
3274         .roam_scan_rssi_threshold = WMI_TLV_ROAM_SCAN_RSSI_THRESHOLD,
3275         .roam_scan_period = WMI_TLV_ROAM_SCAN_PERIOD,
3276         .roam_scan_rssi_change_threshold =
3277                                 WMI_TLV_ROAM_SCAN_RSSI_CHANGE_THRESHOLD,
3278         .roam_ap_profile = WMI_TLV_ROAM_AP_PROFILE,
3279         .ofl_scan_add_ap_profile = WMI_TLV_ROAM_AP_PROFILE,
3280         .ofl_scan_remove_ap_profile = WMI_TLV_OFL_SCAN_REMOVE_AP_PROFILE,
3281         .ofl_scan_period = WMI_TLV_OFL_SCAN_PERIOD,
3282         .p2p_dev_set_device_info = WMI_TLV_P2P_DEV_SET_DEVICE_INFO,
3283         .p2p_dev_set_discoverability = WMI_TLV_P2P_DEV_SET_DISCOVERABILITY,
3284         .p2p_go_set_beacon_ie = WMI_TLV_P2P_GO_SET_BEACON_IE,
3285         .p2p_go_set_probe_resp_ie = WMI_TLV_P2P_GO_SET_PROBE_RESP_IE,
3286         .p2p_set_vendor_ie_data_cmdid = WMI_TLV_P2P_SET_VENDOR_IE_DATA_CMDID,
3287         .ap_ps_peer_param_cmdid = WMI_TLV_AP_PS_PEER_PARAM_CMDID,
3288         .ap_ps_peer_uapsd_coex_cmdid = WMI_TLV_AP_PS_PEER_UAPSD_COEX_CMDID,
3289         .peer_rate_retry_sched_cmdid = WMI_TLV_PEER_RATE_RETRY_SCHED_CMDID,
3290         .wlan_profile_trigger_cmdid = WMI_TLV_WLAN_PROFILE_TRIGGER_CMDID,
3291         .wlan_profile_set_hist_intvl_cmdid =
3292                                 WMI_TLV_WLAN_PROFILE_SET_HIST_INTVL_CMDID,
3293         .wlan_profile_get_profile_data_cmdid =
3294                                 WMI_TLV_WLAN_PROFILE_GET_PROFILE_DATA_CMDID,
3295         .wlan_profile_enable_profile_id_cmdid =
3296                                 WMI_TLV_WLAN_PROFILE_ENABLE_PROFILE_ID_CMDID,
3297         .wlan_profile_list_profile_id_cmdid =
3298                                 WMI_TLV_WLAN_PROFILE_LIST_PROFILE_ID_CMDID,
3299         .pdev_suspend_cmdid = WMI_TLV_PDEV_SUSPEND_CMDID,
3300         .pdev_resume_cmdid = WMI_TLV_PDEV_RESUME_CMDID,
3301         .add_bcn_filter_cmdid = WMI_TLV_ADD_BCN_FILTER_CMDID,
3302         .rmv_bcn_filter_cmdid = WMI_TLV_RMV_BCN_FILTER_CMDID,
3303         .wow_add_wake_pattern_cmdid = WMI_TLV_WOW_ADD_WAKE_PATTERN_CMDID,
3304         .wow_del_wake_pattern_cmdid = WMI_TLV_WOW_DEL_WAKE_PATTERN_CMDID,
3305         .wow_enable_disable_wake_event_cmdid =
3306                                 WMI_TLV_WOW_ENABLE_DISABLE_WAKE_EVENT_CMDID,
3307         .wow_enable_cmdid = WMI_TLV_WOW_ENABLE_CMDID,
3308         .wow_hostwakeup_from_sleep_cmdid =
3309                                 WMI_TLV_WOW_HOSTWAKEUP_FROM_SLEEP_CMDID,
3310         .rtt_measreq_cmdid = WMI_TLV_RTT_MEASREQ_CMDID,
3311         .rtt_tsf_cmdid = WMI_TLV_RTT_TSF_CMDID,
3312         .vdev_spectral_scan_configure_cmdid = WMI_TLV_SPECTRAL_SCAN_CONF_CMDID,
3313         .vdev_spectral_scan_enable_cmdid = WMI_TLV_SPECTRAL_SCAN_ENABLE_CMDID,
3314         .request_stats_cmdid = WMI_TLV_REQUEST_STATS_CMDID,
3315         .set_arp_ns_offload_cmdid = WMI_TLV_SET_ARP_NS_OFFLOAD_CMDID,
3316         .network_list_offload_config_cmdid =
3317                                 WMI_TLV_NETWORK_LIST_OFFLOAD_CONFIG_CMDID,
3318         .gtk_offload_cmdid = WMI_TLV_GTK_OFFLOAD_CMDID,
3319         .csa_offload_enable_cmdid = WMI_TLV_CSA_OFFLOAD_ENABLE_CMDID,
3320         .csa_offload_chanswitch_cmdid = WMI_TLV_CSA_OFFLOAD_CHANSWITCH_CMDID,
3321         .chatter_set_mode_cmdid = WMI_TLV_CHATTER_SET_MODE_CMDID,
3322         .peer_tid_addba_cmdid = WMI_TLV_PEER_TID_ADDBA_CMDID,
3323         .peer_tid_delba_cmdid = WMI_TLV_PEER_TID_DELBA_CMDID,
3324         .sta_dtim_ps_method_cmdid = WMI_TLV_STA_DTIM_PS_METHOD_CMDID,
3325         .sta_uapsd_auto_trig_cmdid = WMI_TLV_STA_UAPSD_AUTO_TRIG_CMDID,
3326         .sta_keepalive_cmd = WMI_TLV_STA_KEEPALIVE_CMDID,
3327         .echo_cmdid = WMI_TLV_ECHO_CMDID,
3328         .pdev_utf_cmdid = WMI_TLV_PDEV_UTF_CMDID,
3329         .dbglog_cfg_cmdid = WMI_TLV_DBGLOG_CFG_CMDID,
3330         .pdev_qvit_cmdid = WMI_TLV_PDEV_QVIT_CMDID,
3331         .pdev_ftm_intg_cmdid = WMI_TLV_PDEV_FTM_INTG_CMDID,
3332         .vdev_set_keepalive_cmdid = WMI_TLV_VDEV_SET_KEEPALIVE_CMDID,
3333         .vdev_get_keepalive_cmdid = WMI_TLV_VDEV_GET_KEEPALIVE_CMDID,
3334         .force_fw_hang_cmdid = WMI_TLV_FORCE_FW_HANG_CMDID,
3335         .gpio_config_cmdid = WMI_TLV_GPIO_CONFIG_CMDID,
3336         .gpio_output_cmdid = WMI_TLV_GPIO_OUTPUT_CMDID,
3337         .pdev_get_temperature_cmdid = WMI_TLV_CMD_UNSUPPORTED,
3338         .vdev_set_wmm_params_cmdid = WMI_TLV_VDEV_SET_WMM_PARAMS_CMDID,
3339         .tdls_set_state_cmdid = WMI_TLV_TDLS_SET_STATE_CMDID,
3340         .tdls_peer_update_cmdid = WMI_TLV_TDLS_PEER_UPDATE_CMDID,
3341         .adaptive_qcs_cmdid = WMI_TLV_RESMGR_ADAPTIVE_OCS_CMDID,
3342         .scan_update_request_cmdid = WMI_CMD_UNSUPPORTED,
3343         .vdev_standby_response_cmdid = WMI_CMD_UNSUPPORTED,
3344         .vdev_resume_response_cmdid = WMI_CMD_UNSUPPORTED,
3345         .wlan_peer_caching_add_peer_cmdid = WMI_CMD_UNSUPPORTED,
3346         .wlan_peer_caching_evict_peer_cmdid = WMI_CMD_UNSUPPORTED,
3347         .wlan_peer_caching_restore_peer_cmdid = WMI_CMD_UNSUPPORTED,
3348         .wlan_peer_caching_print_all_peers_info_cmdid = WMI_CMD_UNSUPPORTED,
3349         .peer_update_wds_entry_cmdid = WMI_CMD_UNSUPPORTED,
3350         .peer_add_proxy_sta_entry_cmdid = WMI_CMD_UNSUPPORTED,
3351         .rtt_keepalive_cmdid = WMI_CMD_UNSUPPORTED,
3352         .oem_req_cmdid = WMI_CMD_UNSUPPORTED,
3353         .nan_cmdid = WMI_CMD_UNSUPPORTED,
3354         .vdev_ratemask_cmdid = WMI_CMD_UNSUPPORTED,
3355         .qboost_cfg_cmdid = WMI_CMD_UNSUPPORTED,
3356         .pdev_smart_ant_enable_cmdid = WMI_CMD_UNSUPPORTED,
3357         .pdev_smart_ant_set_rx_antenna_cmdid = WMI_CMD_UNSUPPORTED,
3358         .peer_smart_ant_set_tx_antenna_cmdid = WMI_CMD_UNSUPPORTED,
3359         .peer_smart_ant_set_train_info_cmdid = WMI_CMD_UNSUPPORTED,
3360         .peer_smart_ant_set_node_config_ops_cmdid = WMI_CMD_UNSUPPORTED,
3361         .pdev_set_antenna_switch_table_cmdid = WMI_CMD_UNSUPPORTED,
3362         .pdev_set_ctl_table_cmdid = WMI_CMD_UNSUPPORTED,
3363         .pdev_set_mimogain_table_cmdid = WMI_CMD_UNSUPPORTED,
3364         .pdev_ratepwr_table_cmdid = WMI_CMD_UNSUPPORTED,
3365         .pdev_ratepwr_chainmsk_table_cmdid = WMI_CMD_UNSUPPORTED,
3366         .pdev_fips_cmdid = WMI_CMD_UNSUPPORTED,
3367         .tt_set_conf_cmdid = WMI_CMD_UNSUPPORTED,
3368         .fwtest_cmdid = WMI_CMD_UNSUPPORTED,
3369         .vdev_atf_request_cmdid = WMI_CMD_UNSUPPORTED,
3370         .peer_atf_request_cmdid = WMI_CMD_UNSUPPORTED,
3371         .pdev_get_ani_cck_config_cmdid = WMI_CMD_UNSUPPORTED,
3372         .pdev_get_ani_ofdm_config_cmdid = WMI_CMD_UNSUPPORTED,
3373         .pdev_reserve_ast_entry_cmdid = WMI_CMD_UNSUPPORTED,
3374 };
3375
3376 static struct wmi_pdev_param_map wmi_tlv_pdev_param_map = {
3377         .tx_chain_mask = WMI_TLV_PDEV_PARAM_TX_CHAIN_MASK,
3378         .rx_chain_mask = WMI_TLV_PDEV_PARAM_RX_CHAIN_MASK,
3379         .txpower_limit2g = WMI_TLV_PDEV_PARAM_TXPOWER_LIMIT2G,
3380         .txpower_limit5g = WMI_TLV_PDEV_PARAM_TXPOWER_LIMIT5G,
3381         .txpower_scale = WMI_TLV_PDEV_PARAM_TXPOWER_SCALE,
3382         .beacon_gen_mode = WMI_TLV_PDEV_PARAM_BEACON_GEN_MODE,
3383         .beacon_tx_mode = WMI_TLV_PDEV_PARAM_BEACON_TX_MODE,
3384         .resmgr_offchan_mode = WMI_TLV_PDEV_PARAM_RESMGR_OFFCHAN_MODE,
3385         .protection_mode = WMI_TLV_PDEV_PARAM_PROTECTION_MODE,
3386         .dynamic_bw = WMI_TLV_PDEV_PARAM_DYNAMIC_BW,
3387         .non_agg_sw_retry_th = WMI_TLV_PDEV_PARAM_NON_AGG_SW_RETRY_TH,
3388         .agg_sw_retry_th = WMI_TLV_PDEV_PARAM_AGG_SW_RETRY_TH,
3389         .sta_kickout_th = WMI_TLV_PDEV_PARAM_STA_KICKOUT_TH,
3390         .ac_aggrsize_scaling = WMI_TLV_PDEV_PARAM_AC_AGGRSIZE_SCALING,
3391         .ltr_enable = WMI_TLV_PDEV_PARAM_LTR_ENABLE,
3392         .ltr_ac_latency_be = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_BE,
3393         .ltr_ac_latency_bk = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_BK,
3394         .ltr_ac_latency_vi = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_VI,
3395         .ltr_ac_latency_vo = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_VO,
3396         .ltr_ac_latency_timeout = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_TIMEOUT,
3397         .ltr_sleep_override = WMI_TLV_PDEV_PARAM_LTR_SLEEP_OVERRIDE,
3398         .ltr_rx_override = WMI_TLV_PDEV_PARAM_LTR_RX_OVERRIDE,
3399         .ltr_tx_activity_timeout = WMI_TLV_PDEV_PARAM_LTR_TX_ACTIVITY_TIMEOUT,
3400         .l1ss_enable = WMI_TLV_PDEV_PARAM_L1SS_ENABLE,
3401         .dsleep_enable = WMI_TLV_PDEV_PARAM_DSLEEP_ENABLE,
3402         .pcielp_txbuf_flush = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_FLUSH,
3403         .pcielp_txbuf_watermark = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_TMO_EN,
3404         .pcielp_txbuf_tmo_en = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_TMO_EN,
3405         .pcielp_txbuf_tmo_value = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_TMO_VALUE,
3406         .pdev_stats_update_period = WMI_TLV_PDEV_PARAM_PDEV_STATS_UPDATE_PERIOD,
3407         .vdev_stats_update_period = WMI_TLV_PDEV_PARAM_VDEV_STATS_UPDATE_PERIOD,
3408         .peer_stats_update_period = WMI_TLV_PDEV_PARAM_PEER_STATS_UPDATE_PERIOD,
3409         .bcnflt_stats_update_period =
3410                                 WMI_TLV_PDEV_PARAM_BCNFLT_STATS_UPDATE_PERIOD,
3411         .pmf_qos = WMI_TLV_PDEV_PARAM_PMF_QOS,
3412         .arp_ac_override = WMI_TLV_PDEV_PARAM_ARP_AC_OVERRIDE,
3413         .dcs = WMI_TLV_PDEV_PARAM_DCS,
3414         .ani_enable = WMI_TLV_PDEV_PARAM_ANI_ENABLE,
3415         .ani_poll_period = WMI_TLV_PDEV_PARAM_ANI_POLL_PERIOD,
3416         .ani_listen_period = WMI_TLV_PDEV_PARAM_ANI_LISTEN_PERIOD,
3417         .ani_ofdm_level = WMI_TLV_PDEV_PARAM_ANI_OFDM_LEVEL,
3418         .ani_cck_level = WMI_TLV_PDEV_PARAM_ANI_CCK_LEVEL,
3419         .dyntxchain = WMI_TLV_PDEV_PARAM_DYNTXCHAIN,
3420         .proxy_sta = WMI_TLV_PDEV_PARAM_PROXY_STA,
3421         .idle_ps_config = WMI_TLV_PDEV_PARAM_IDLE_PS_CONFIG,
3422         .power_gating_sleep = WMI_TLV_PDEV_PARAM_POWER_GATING_SLEEP,
3423         .fast_channel_reset = WMI_TLV_PDEV_PARAM_UNSUPPORTED,
3424         .burst_dur = WMI_TLV_PDEV_PARAM_BURST_DUR,
3425         .burst_enable = WMI_TLV_PDEV_PARAM_BURST_ENABLE,
3426         .cal_period = WMI_PDEV_PARAM_UNSUPPORTED,
3427         .aggr_burst = WMI_PDEV_PARAM_UNSUPPORTED,
3428         .rx_decap_mode = WMI_PDEV_PARAM_UNSUPPORTED,
3429         .smart_antenna_default_antenna = WMI_PDEV_PARAM_UNSUPPORTED,
3430         .igmpmld_override = WMI_PDEV_PARAM_UNSUPPORTED,
3431         .igmpmld_tid = WMI_PDEV_PARAM_UNSUPPORTED,
3432         .antenna_gain = WMI_PDEV_PARAM_UNSUPPORTED,
3433         .rx_filter = WMI_PDEV_PARAM_UNSUPPORTED,
3434         .set_mcast_to_ucast_tid = WMI_PDEV_PARAM_UNSUPPORTED,
3435         .proxy_sta_mode = WMI_PDEV_PARAM_UNSUPPORTED,
3436         .set_mcast2ucast_mode = WMI_PDEV_PARAM_UNSUPPORTED,
3437         .set_mcast2ucast_buffer = WMI_PDEV_PARAM_UNSUPPORTED,
3438         .remove_mcast2ucast_buffer = WMI_PDEV_PARAM_UNSUPPORTED,
3439         .peer_sta_ps_statechg_enable = WMI_PDEV_PARAM_UNSUPPORTED,
3440         .igmpmld_ac_override = WMI_PDEV_PARAM_UNSUPPORTED,
3441         .block_interbss = WMI_PDEV_PARAM_UNSUPPORTED,
3442         .set_disable_reset_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3443         .set_msdu_ttl_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3444         .set_ppdu_duration_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3445         .txbf_sound_period_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3446         .set_promisc_mode_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3447         .set_burst_mode_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3448         .en_stats = WMI_PDEV_PARAM_UNSUPPORTED,
3449         .mu_group_policy = WMI_PDEV_PARAM_UNSUPPORTED,
3450         .noise_detection = WMI_PDEV_PARAM_UNSUPPORTED,
3451         .noise_threshold = WMI_PDEV_PARAM_UNSUPPORTED,
3452         .dpd_enable = WMI_PDEV_PARAM_UNSUPPORTED,
3453         .set_mcast_bcast_echo = WMI_PDEV_PARAM_UNSUPPORTED,
3454         .atf_strict_sch = WMI_PDEV_PARAM_UNSUPPORTED,
3455         .atf_sched_duration = WMI_PDEV_PARAM_UNSUPPORTED,
3456         .ant_plzn = WMI_PDEV_PARAM_UNSUPPORTED,
3457         .mgmt_retry_limit = WMI_PDEV_PARAM_UNSUPPORTED,
3458         .sensitivity_level = WMI_PDEV_PARAM_UNSUPPORTED,
3459         .signed_txpower_2g = WMI_PDEV_PARAM_UNSUPPORTED,
3460         .signed_txpower_5g = WMI_PDEV_PARAM_UNSUPPORTED,
3461         .enable_per_tid_amsdu = WMI_PDEV_PARAM_UNSUPPORTED,
3462         .enable_per_tid_ampdu = WMI_PDEV_PARAM_UNSUPPORTED,
3463         .cca_threshold = WMI_PDEV_PARAM_UNSUPPORTED,
3464         .rts_fixed_rate = WMI_PDEV_PARAM_UNSUPPORTED,
3465         .pdev_reset = WMI_PDEV_PARAM_UNSUPPORTED,
3466         .wapi_mbssid_offset = WMI_PDEV_PARAM_UNSUPPORTED,
3467         .arp_srcaddr = WMI_PDEV_PARAM_UNSUPPORTED,
3468         .arp_dstaddr = WMI_PDEV_PARAM_UNSUPPORTED,
3469 };
3470
3471 static struct wmi_vdev_param_map wmi_tlv_vdev_param_map = {
3472         .rts_threshold = WMI_TLV_VDEV_PARAM_RTS_THRESHOLD,
3473         .fragmentation_threshold = WMI_TLV_VDEV_PARAM_FRAGMENTATION_THRESHOLD,
3474         .beacon_interval = WMI_TLV_VDEV_PARAM_BEACON_INTERVAL,
3475         .listen_interval = WMI_TLV_VDEV_PARAM_LISTEN_INTERVAL,
3476         .multicast_rate = WMI_TLV_VDEV_PARAM_MULTICAST_RATE,
3477         .mgmt_tx_rate = WMI_TLV_VDEV_PARAM_MGMT_TX_RATE,
3478         .slot_time = WMI_TLV_VDEV_PARAM_SLOT_TIME,
3479         .preamble = WMI_TLV_VDEV_PARAM_PREAMBLE,
3480         .swba_time = WMI_TLV_VDEV_PARAM_SWBA_TIME,
3481         .wmi_vdev_stats_update_period = WMI_TLV_VDEV_STATS_UPDATE_PERIOD,
3482         .wmi_vdev_pwrsave_ageout_time = WMI_TLV_VDEV_PWRSAVE_AGEOUT_TIME,
3483         .wmi_vdev_host_swba_interval = WMI_TLV_VDEV_HOST_SWBA_INTERVAL,
3484         .dtim_period = WMI_TLV_VDEV_PARAM_DTIM_PERIOD,
3485         .wmi_vdev_oc_scheduler_air_time_limit =
3486                                 WMI_TLV_VDEV_OC_SCHEDULER_AIR_TIME_LIMIT,
3487         .wds = WMI_TLV_VDEV_PARAM_WDS,
3488         .atim_window = WMI_TLV_VDEV_PARAM_ATIM_WINDOW,
3489         .bmiss_count_max = WMI_TLV_VDEV_PARAM_BMISS_COUNT_MAX,
3490         .bmiss_first_bcnt = WMI_TLV_VDEV_PARAM_BMISS_FIRST_BCNT,
3491         .bmiss_final_bcnt = WMI_TLV_VDEV_PARAM_BMISS_FINAL_BCNT,
3492         .feature_wmm = WMI_TLV_VDEV_PARAM_FEATURE_WMM,
3493         .chwidth = WMI_TLV_VDEV_PARAM_CHWIDTH,
3494         .chextoffset = WMI_TLV_VDEV_PARAM_CHEXTOFFSET,
3495         .disable_htprotection = WMI_TLV_VDEV_PARAM_DISABLE_HTPROTECTION,
3496         .sta_quickkickout = WMI_TLV_VDEV_PARAM_STA_QUICKKICKOUT,
3497         .mgmt_rate = WMI_TLV_VDEV_PARAM_MGMT_RATE,
3498         .protection_mode = WMI_TLV_VDEV_PARAM_PROTECTION_MODE,
3499         .fixed_rate = WMI_TLV_VDEV_PARAM_FIXED_RATE,
3500         .sgi = WMI_TLV_VDEV_PARAM_SGI,
3501         .ldpc = WMI_TLV_VDEV_PARAM_LDPC,
3502         .tx_stbc = WMI_TLV_VDEV_PARAM_TX_STBC,
3503         .rx_stbc = WMI_TLV_VDEV_PARAM_RX_STBC,
3504         .intra_bss_fwd = WMI_TLV_VDEV_PARAM_INTRA_BSS_FWD,
3505         .def_keyid = WMI_TLV_VDEV_PARAM_DEF_KEYID,
3506         .nss = WMI_TLV_VDEV_PARAM_NSS,
3507         .bcast_data_rate = WMI_TLV_VDEV_PARAM_BCAST_DATA_RATE,
3508         .mcast_data_rate = WMI_TLV_VDEV_PARAM_MCAST_DATA_RATE,
3509         .mcast_indicate = WMI_TLV_VDEV_PARAM_MCAST_INDICATE,
3510         .dhcp_indicate = WMI_TLV_VDEV_PARAM_DHCP_INDICATE,
3511         .unknown_dest_indicate = WMI_TLV_VDEV_PARAM_UNKNOWN_DEST_INDICATE,
3512         .ap_keepalive_min_idle_inactive_time_secs =
3513                 WMI_TLV_VDEV_PARAM_AP_KEEPALIVE_MIN_IDLE_INACTIVE_TIME_SECS,
3514         .ap_keepalive_max_idle_inactive_time_secs =
3515                 WMI_TLV_VDEV_PARAM_AP_KEEPALIVE_MAX_IDLE_INACTIVE_TIME_SECS,
3516         .ap_keepalive_max_unresponsive_time_secs =
3517                 WMI_TLV_VDEV_PARAM_AP_KEEPALIVE_MAX_UNRESPONSIVE_TIME_SECS,
3518         .ap_enable_nawds = WMI_TLV_VDEV_PARAM_AP_ENABLE_NAWDS,
3519         .mcast2ucast_set = WMI_TLV_VDEV_PARAM_UNSUPPORTED,
3520         .enable_rtscts = WMI_TLV_VDEV_PARAM_ENABLE_RTSCTS,
3521         .txbf = WMI_TLV_VDEV_PARAM_TXBF,
3522         .packet_powersave = WMI_TLV_VDEV_PARAM_PACKET_POWERSAVE,
3523         .drop_unencry = WMI_TLV_VDEV_PARAM_DROP_UNENCRY,
3524         .tx_encap_type = WMI_TLV_VDEV_PARAM_TX_ENCAP_TYPE,
3525         .ap_detect_out_of_sync_sleeping_sta_time_secs =
3526                                         WMI_TLV_VDEV_PARAM_UNSUPPORTED,
3527         .rc_num_retries = WMI_VDEV_PARAM_UNSUPPORTED,
3528         .cabq_maxdur = WMI_VDEV_PARAM_UNSUPPORTED,
3529         .mfptest_set = WMI_VDEV_PARAM_UNSUPPORTED,
3530         .rts_fixed_rate = WMI_VDEV_PARAM_UNSUPPORTED,
3531         .vht_sgimask = WMI_VDEV_PARAM_UNSUPPORTED,
3532         .vht80_ratemask = WMI_VDEV_PARAM_UNSUPPORTED,
3533         .early_rx_adjust_enable = WMI_VDEV_PARAM_UNSUPPORTED,
3534         .early_rx_tgt_bmiss_num = WMI_VDEV_PARAM_UNSUPPORTED,
3535         .early_rx_bmiss_sample_cycle = WMI_VDEV_PARAM_UNSUPPORTED,
3536         .early_rx_slop_step = WMI_VDEV_PARAM_UNSUPPORTED,
3537         .early_rx_init_slop = WMI_VDEV_PARAM_UNSUPPORTED,
3538         .early_rx_adjust_pause = WMI_VDEV_PARAM_UNSUPPORTED,
3539         .proxy_sta = WMI_VDEV_PARAM_UNSUPPORTED,
3540         .meru_vc = WMI_VDEV_PARAM_UNSUPPORTED,
3541         .rx_decap_type = WMI_VDEV_PARAM_UNSUPPORTED,
3542         .bw_nss_ratemask = WMI_VDEV_PARAM_UNSUPPORTED,
3543 };
3544
3545 static const struct wmi_ops wmi_tlv_ops = {
3546         .rx = ath10k_wmi_tlv_op_rx,
3547         .map_svc = wmi_tlv_svc_map,
3548
3549         .pull_scan = ath10k_wmi_tlv_op_pull_scan_ev,
3550         .pull_mgmt_rx = ath10k_wmi_tlv_op_pull_mgmt_rx_ev,
3551         .pull_ch_info = ath10k_wmi_tlv_op_pull_ch_info_ev,
3552         .pull_vdev_start = ath10k_wmi_tlv_op_pull_vdev_start_ev,
3553         .pull_peer_kick = ath10k_wmi_tlv_op_pull_peer_kick_ev,
3554         .pull_swba = ath10k_wmi_tlv_op_pull_swba_ev,
3555         .pull_phyerr_hdr = ath10k_wmi_tlv_op_pull_phyerr_ev_hdr,
3556         .pull_phyerr = ath10k_wmi_op_pull_phyerr_ev,
3557         .pull_svc_rdy = ath10k_wmi_tlv_op_pull_svc_rdy_ev,
3558         .pull_rdy = ath10k_wmi_tlv_op_pull_rdy_ev,
3559         .pull_fw_stats = ath10k_wmi_tlv_op_pull_fw_stats,
3560         .pull_roam_ev = ath10k_wmi_tlv_op_pull_roam_ev,
3561         .pull_wow_event = ath10k_wmi_tlv_op_pull_wow_ev,
3562         .pull_echo_ev = ath10k_wmi_tlv_op_pull_echo_ev,
3563         .get_txbf_conf_scheme = ath10k_wmi_tlv_txbf_conf_scheme,
3564
3565         .gen_pdev_suspend = ath10k_wmi_tlv_op_gen_pdev_suspend,
3566         .gen_pdev_resume = ath10k_wmi_tlv_op_gen_pdev_resume,
3567         .gen_pdev_set_rd = ath10k_wmi_tlv_op_gen_pdev_set_rd,
3568         .gen_pdev_set_param = ath10k_wmi_tlv_op_gen_pdev_set_param,
3569         .gen_init = ath10k_wmi_tlv_op_gen_init,
3570         .gen_start_scan = ath10k_wmi_tlv_op_gen_start_scan,
3571         .gen_stop_scan = ath10k_wmi_tlv_op_gen_stop_scan,
3572         .gen_vdev_create = ath10k_wmi_tlv_op_gen_vdev_create,
3573         .gen_vdev_delete = ath10k_wmi_tlv_op_gen_vdev_delete,
3574         .gen_vdev_start = ath10k_wmi_tlv_op_gen_vdev_start,
3575         .gen_vdev_stop = ath10k_wmi_tlv_op_gen_vdev_stop,
3576         .gen_vdev_up = ath10k_wmi_tlv_op_gen_vdev_up,
3577         .gen_vdev_down = ath10k_wmi_tlv_op_gen_vdev_down,
3578         .gen_vdev_set_param = ath10k_wmi_tlv_op_gen_vdev_set_param,
3579         .gen_vdev_install_key = ath10k_wmi_tlv_op_gen_vdev_install_key,
3580         .gen_vdev_wmm_conf = ath10k_wmi_tlv_op_gen_vdev_wmm_conf,
3581         .gen_peer_create = ath10k_wmi_tlv_op_gen_peer_create,
3582         .gen_peer_delete = ath10k_wmi_tlv_op_gen_peer_delete,
3583         .gen_peer_flush = ath10k_wmi_tlv_op_gen_peer_flush,
3584         .gen_peer_set_param = ath10k_wmi_tlv_op_gen_peer_set_param,
3585         .gen_peer_assoc = ath10k_wmi_tlv_op_gen_peer_assoc,
3586         .gen_set_psmode = ath10k_wmi_tlv_op_gen_set_psmode,
3587         .gen_set_sta_ps = ath10k_wmi_tlv_op_gen_set_sta_ps,
3588         .gen_set_ap_ps = ath10k_wmi_tlv_op_gen_set_ap_ps,
3589         .gen_scan_chan_list = ath10k_wmi_tlv_op_gen_scan_chan_list,
3590         .gen_beacon_dma = ath10k_wmi_tlv_op_gen_beacon_dma,
3591         .gen_pdev_set_wmm = ath10k_wmi_tlv_op_gen_pdev_set_wmm,
3592         .gen_request_stats = ath10k_wmi_tlv_op_gen_request_stats,
3593         .gen_force_fw_hang = ath10k_wmi_tlv_op_gen_force_fw_hang,
3594         /* .gen_mgmt_tx = not implemented; HTT is used */
3595         .gen_dbglog_cfg = ath10k_wmi_tlv_op_gen_dbglog_cfg,
3596         .gen_pktlog_enable = ath10k_wmi_tlv_op_gen_pktlog_enable,
3597         .gen_pktlog_disable = ath10k_wmi_tlv_op_gen_pktlog_disable,
3598         /* .gen_pdev_set_quiet_mode not implemented */
3599         /* .gen_pdev_get_temperature not implemented */
3600         /* .gen_addba_clear_resp not implemented */
3601         /* .gen_addba_send not implemented */
3602         /* .gen_addba_set_resp not implemented */
3603         /* .gen_delba_send not implemented */
3604         .gen_bcn_tmpl = ath10k_wmi_tlv_op_gen_bcn_tmpl,
3605         .gen_prb_tmpl = ath10k_wmi_tlv_op_gen_prb_tmpl,
3606         .gen_p2p_go_bcn_ie = ath10k_wmi_tlv_op_gen_p2p_go_bcn_ie,
3607         .gen_vdev_sta_uapsd = ath10k_wmi_tlv_op_gen_vdev_sta_uapsd,
3608         .gen_sta_keepalive = ath10k_wmi_tlv_op_gen_sta_keepalive,
3609         .gen_wow_enable = ath10k_wmi_tlv_op_gen_wow_enable,
3610         .gen_wow_add_wakeup_event = ath10k_wmi_tlv_op_gen_wow_add_wakeup_event,
3611         .gen_wow_host_wakeup_ind = ath10k_wmi_tlv_gen_wow_host_wakeup_ind,
3612         .gen_wow_add_pattern = ath10k_wmi_tlv_op_gen_wow_add_pattern,
3613         .gen_wow_del_pattern = ath10k_wmi_tlv_op_gen_wow_del_pattern,
3614         .gen_update_fw_tdls_state = ath10k_wmi_tlv_op_gen_update_fw_tdls_state,
3615         .gen_tdls_peer_update = ath10k_wmi_tlv_op_gen_tdls_peer_update,
3616         .gen_adaptive_qcs = ath10k_wmi_tlv_op_gen_adaptive_qcs,
3617         .fw_stats_fill = ath10k_wmi_main_op_fw_stats_fill,
3618         .get_vdev_subtype = ath10k_wmi_op_get_vdev_subtype,
3619         .gen_echo = ath10k_wmi_tlv_op_gen_echo,
3620         .gen_vdev_spectral_conf = ath10k_wmi_tlv_op_gen_vdev_spectral_conf,
3621         .gen_vdev_spectral_enable = ath10k_wmi_tlv_op_gen_vdev_spectral_enable,
3622 };
3623
3624 static const struct wmi_peer_flags_map wmi_tlv_peer_flags_map = {
3625         .auth = WMI_TLV_PEER_AUTH,
3626         .qos = WMI_TLV_PEER_QOS,
3627         .need_ptk_4_way = WMI_TLV_PEER_NEED_PTK_4_WAY,
3628         .need_gtk_2_way = WMI_TLV_PEER_NEED_GTK_2_WAY,
3629         .apsd = WMI_TLV_PEER_APSD,
3630         .ht = WMI_TLV_PEER_HT,
3631         .bw40 = WMI_TLV_PEER_40MHZ,
3632         .stbc = WMI_TLV_PEER_STBC,
3633         .ldbc = WMI_TLV_PEER_LDPC,
3634         .dyn_mimops = WMI_TLV_PEER_DYN_MIMOPS,
3635         .static_mimops = WMI_TLV_PEER_STATIC_MIMOPS,
3636         .spatial_mux = WMI_TLV_PEER_SPATIAL_MUX,
3637         .vht = WMI_TLV_PEER_VHT,
3638         .bw80 = WMI_TLV_PEER_80MHZ,
3639         .pmf = WMI_TLV_PEER_PMF,
3640 };
3641
3642 /************/
3643 /* TLV init */
3644 /************/
3645
3646 void ath10k_wmi_tlv_attach(struct ath10k *ar)
3647 {
3648         ar->wmi.cmd = &wmi_tlv_cmd_map;
3649         ar->wmi.vdev_param = &wmi_tlv_vdev_param_map;
3650         ar->wmi.pdev_param = &wmi_tlv_pdev_param_map;
3651         ar->wmi.ops = &wmi_tlv_ops;
3652         ar->wmi.peer_flags = &wmi_tlv_peer_flags_map;
3653 }