OSDN Git Service

ath10k: fix scan crash due to incorrect length calculation
[android-x86/kernel.git] / drivers / net / wireless / ath / ath10k / wmi-tlv.c
1 /*
2  * Copyright (c) 2005-2011 Atheros Communications Inc.
3  * Copyright (c) 2011-2017 Qualcomm Atheros, Inc.
4  * Copyright (c) 2018, The Linux Foundation. All rights reserved.
5  *
6  * Permission to use, copy, modify, and/or distribute this software for any
7  * purpose with or without fee is hereby granted, provided that the above
8  * copyright notice and this permission notice appear in all copies.
9  *
10  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
11  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
12  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
13  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
14  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
15  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
16  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17  */
18 #include "core.h"
19 #include "debug.h"
20 #include "mac.h"
21 #include "hw.h"
22 #include "mac.h"
23 #include "wmi.h"
24 #include "wmi-ops.h"
25 #include "wmi-tlv.h"
26 #include "p2p.h"
27 #include "testmode.h"
28
29 /***************/
30 /* TLV helpers */
31 /**************/
32
33 struct wmi_tlv_policy {
34         size_t min_len;
35 };
36
37 static const struct wmi_tlv_policy wmi_tlv_policies[] = {
38         [WMI_TLV_TAG_ARRAY_BYTE]
39                 = { .min_len = 0 },
40         [WMI_TLV_TAG_ARRAY_UINT32]
41                 = { .min_len = 0 },
42         [WMI_TLV_TAG_STRUCT_SCAN_EVENT]
43                 = { .min_len = sizeof(struct wmi_scan_event) },
44         [WMI_TLV_TAG_STRUCT_MGMT_RX_HDR]
45                 = { .min_len = sizeof(struct wmi_tlv_mgmt_rx_ev) },
46         [WMI_TLV_TAG_STRUCT_CHAN_INFO_EVENT]
47                 = { .min_len = sizeof(struct wmi_chan_info_event) },
48         [WMI_TLV_TAG_STRUCT_VDEV_START_RESPONSE_EVENT]
49                 = { .min_len = sizeof(struct wmi_vdev_start_response_event) },
50         [WMI_TLV_TAG_STRUCT_PEER_STA_KICKOUT_EVENT]
51                 = { .min_len = sizeof(struct wmi_peer_sta_kickout_event) },
52         [WMI_TLV_TAG_STRUCT_HOST_SWBA_EVENT]
53                 = { .min_len = sizeof(struct wmi_host_swba_event) },
54         [WMI_TLV_TAG_STRUCT_TIM_INFO]
55                 = { .min_len = sizeof(struct wmi_tim_info) },
56         [WMI_TLV_TAG_STRUCT_P2P_NOA_INFO]
57                 = { .min_len = sizeof(struct wmi_p2p_noa_info) },
58         [WMI_TLV_TAG_STRUCT_SERVICE_READY_EVENT]
59                 = { .min_len = sizeof(struct wmi_tlv_svc_rdy_ev) },
60         [WMI_TLV_TAG_STRUCT_HAL_REG_CAPABILITIES]
61                 = { .min_len = sizeof(struct hal_reg_capabilities) },
62         [WMI_TLV_TAG_STRUCT_WLAN_HOST_MEM_REQ]
63                 = { .min_len = sizeof(struct wlan_host_mem_req) },
64         [WMI_TLV_TAG_STRUCT_READY_EVENT]
65                 = { .min_len = sizeof(struct wmi_tlv_rdy_ev) },
66         [WMI_TLV_TAG_STRUCT_OFFLOAD_BCN_TX_STATUS_EVENT]
67                 = { .min_len = sizeof(struct wmi_tlv_bcn_tx_status_ev) },
68         [WMI_TLV_TAG_STRUCT_DIAG_DATA_CONTAINER_EVENT]
69                 = { .min_len = sizeof(struct wmi_tlv_diag_data_ev) },
70         [WMI_TLV_TAG_STRUCT_P2P_NOA_EVENT]
71                 = { .min_len = sizeof(struct wmi_tlv_p2p_noa_ev) },
72         [WMI_TLV_TAG_STRUCT_ROAM_EVENT]
73                 = { .min_len = sizeof(struct wmi_tlv_roam_ev) },
74         [WMI_TLV_TAG_STRUCT_WOW_EVENT_INFO]
75                 = { .min_len = sizeof(struct wmi_tlv_wow_event_info) },
76         [WMI_TLV_TAG_STRUCT_TX_PAUSE_EVENT]
77                 = { .min_len = sizeof(struct wmi_tlv_tx_pause_ev) },
78 };
79
80 static int
81 ath10k_wmi_tlv_iter(struct ath10k *ar, const void *ptr, size_t len,
82                     int (*iter)(struct ath10k *ar, u16 tag, u16 len,
83                                 const void *ptr, void *data),
84                     void *data)
85 {
86         const void *begin = ptr;
87         const struct wmi_tlv *tlv;
88         u16 tlv_tag, tlv_len;
89         int ret;
90
91         while (len > 0) {
92                 if (len < sizeof(*tlv)) {
93                         ath10k_dbg(ar, ATH10K_DBG_WMI,
94                                    "wmi tlv parse failure at byte %zd (%zu bytes left, %zu expected)\n",
95                                    ptr - begin, len, sizeof(*tlv));
96                         return -EINVAL;
97                 }
98
99                 tlv = ptr;
100                 tlv_tag = __le16_to_cpu(tlv->tag);
101                 tlv_len = __le16_to_cpu(tlv->len);
102                 ptr += sizeof(*tlv);
103                 len -= sizeof(*tlv);
104
105                 if (tlv_len > len) {
106                         ath10k_dbg(ar, ATH10K_DBG_WMI,
107                                    "wmi tlv parse failure of tag %hhu at byte %zd (%zu bytes left, %hhu expected)\n",
108                                    tlv_tag, ptr - begin, len, tlv_len);
109                         return -EINVAL;
110                 }
111
112                 if (tlv_tag < ARRAY_SIZE(wmi_tlv_policies) &&
113                     wmi_tlv_policies[tlv_tag].min_len &&
114                     wmi_tlv_policies[tlv_tag].min_len > tlv_len) {
115                         ath10k_dbg(ar, ATH10K_DBG_WMI,
116                                    "wmi tlv parse failure of tag %hhu at byte %zd (%hhu bytes is less than min length %zu)\n",
117                                    tlv_tag, ptr - begin, tlv_len,
118                                    wmi_tlv_policies[tlv_tag].min_len);
119                         return -EINVAL;
120                 }
121
122                 ret = iter(ar, tlv_tag, tlv_len, ptr, data);
123                 if (ret)
124                         return ret;
125
126                 ptr += tlv_len;
127                 len -= tlv_len;
128         }
129
130         return 0;
131 }
132
133 static int ath10k_wmi_tlv_iter_parse(struct ath10k *ar, u16 tag, u16 len,
134                                      const void *ptr, void *data)
135 {
136         const void **tb = data;
137
138         if (tag < WMI_TLV_TAG_MAX)
139                 tb[tag] = ptr;
140
141         return 0;
142 }
143
144 static int ath10k_wmi_tlv_parse(struct ath10k *ar, const void **tb,
145                                 const void *ptr, size_t len)
146 {
147         return ath10k_wmi_tlv_iter(ar, ptr, len, ath10k_wmi_tlv_iter_parse,
148                                    (void *)tb);
149 }
150
151 static const void **
152 ath10k_wmi_tlv_parse_alloc(struct ath10k *ar, const void *ptr,
153                            size_t len, gfp_t gfp)
154 {
155         const void **tb;
156         int ret;
157
158         tb = kcalloc(WMI_TLV_TAG_MAX, sizeof(*tb), gfp);
159         if (!tb)
160                 return ERR_PTR(-ENOMEM);
161
162         ret = ath10k_wmi_tlv_parse(ar, tb, ptr, len);
163         if (ret) {
164                 kfree(tb);
165                 return ERR_PTR(ret);
166         }
167
168         return tb;
169 }
170
171 static u16 ath10k_wmi_tlv_len(const void *ptr)
172 {
173         return __le16_to_cpu((((const struct wmi_tlv *)ptr) - 1)->len);
174 }
175
176 /**************/
177 /* TLV events */
178 /**************/
179 static int ath10k_wmi_tlv_event_bcn_tx_status(struct ath10k *ar,
180                                               struct sk_buff *skb)
181 {
182         const void **tb;
183         const struct wmi_tlv_bcn_tx_status_ev *ev;
184         struct ath10k_vif *arvif;
185         u32 vdev_id, tx_status;
186         int ret;
187
188         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
189         if (IS_ERR(tb)) {
190                 ret = PTR_ERR(tb);
191                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
192                 return ret;
193         }
194
195         ev = tb[WMI_TLV_TAG_STRUCT_OFFLOAD_BCN_TX_STATUS_EVENT];
196         if (!ev) {
197                 kfree(tb);
198                 return -EPROTO;
199         }
200
201         tx_status = __le32_to_cpu(ev->tx_status);
202         vdev_id = __le32_to_cpu(ev->vdev_id);
203
204         switch (tx_status) {
205         case WMI_TLV_BCN_TX_STATUS_OK:
206                 break;
207         case WMI_TLV_BCN_TX_STATUS_XRETRY:
208         case WMI_TLV_BCN_TX_STATUS_DROP:
209         case WMI_TLV_BCN_TX_STATUS_FILTERED:
210                 /* FIXME: It's probably worth telling mac80211 to stop the
211                  * interface as it is crippled.
212                  */
213                 ath10k_warn(ar, "received bcn tmpl tx status on vdev %i: %d",
214                             vdev_id, tx_status);
215                 break;
216         }
217
218         arvif = ath10k_get_arvif(ar, vdev_id);
219         if (arvif && arvif->is_up && arvif->vif->csa_active)
220                 ieee80211_queue_work(ar->hw, &arvif->ap_csa_work);
221
222         kfree(tb);
223         return 0;
224 }
225
226 static int ath10k_wmi_tlv_event_diag_data(struct ath10k *ar,
227                                           struct sk_buff *skb)
228 {
229         const void **tb;
230         const struct wmi_tlv_diag_data_ev *ev;
231         const struct wmi_tlv_diag_item *item;
232         const void *data;
233         int ret, num_items, len;
234
235         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
236         if (IS_ERR(tb)) {
237                 ret = PTR_ERR(tb);
238                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
239                 return ret;
240         }
241
242         ev = tb[WMI_TLV_TAG_STRUCT_DIAG_DATA_CONTAINER_EVENT];
243         data = tb[WMI_TLV_TAG_ARRAY_BYTE];
244         if (!ev || !data) {
245                 kfree(tb);
246                 return -EPROTO;
247         }
248
249         num_items = __le32_to_cpu(ev->num_items);
250         len = ath10k_wmi_tlv_len(data);
251
252         while (num_items--) {
253                 if (len == 0)
254                         break;
255                 if (len < sizeof(*item)) {
256                         ath10k_warn(ar, "failed to parse diag data: can't fit item header\n");
257                         break;
258                 }
259
260                 item = data;
261
262                 if (len < sizeof(*item) + __le16_to_cpu(item->len)) {
263                         ath10k_warn(ar, "failed to parse diag data: item is too long\n");
264                         break;
265                 }
266
267                 trace_ath10k_wmi_diag_container(ar,
268                                                 item->type,
269                                                 __le32_to_cpu(item->timestamp),
270                                                 __le32_to_cpu(item->code),
271                                                 __le16_to_cpu(item->len),
272                                                 item->payload);
273
274                 len -= sizeof(*item);
275                 len -= roundup(__le16_to_cpu(item->len), 4);
276
277                 data += sizeof(*item);
278                 data += roundup(__le16_to_cpu(item->len), 4);
279         }
280
281         if (num_items != -1 || len != 0)
282                 ath10k_warn(ar, "failed to parse diag data event: num_items %d len %d\n",
283                             num_items, len);
284
285         kfree(tb);
286         return 0;
287 }
288
289 static int ath10k_wmi_tlv_event_diag(struct ath10k *ar,
290                                      struct sk_buff *skb)
291 {
292         const void **tb;
293         const void *data;
294         int ret, len;
295
296         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
297         if (IS_ERR(tb)) {
298                 ret = PTR_ERR(tb);
299                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
300                 return ret;
301         }
302
303         data = tb[WMI_TLV_TAG_ARRAY_BYTE];
304         if (!data) {
305                 kfree(tb);
306                 return -EPROTO;
307         }
308         len = ath10k_wmi_tlv_len(data);
309
310         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv diag event len %d\n", len);
311         trace_ath10k_wmi_diag(ar, data, len);
312
313         kfree(tb);
314         return 0;
315 }
316
317 static int ath10k_wmi_tlv_event_p2p_noa(struct ath10k *ar,
318                                         struct sk_buff *skb)
319 {
320         const void **tb;
321         const struct wmi_tlv_p2p_noa_ev *ev;
322         const struct wmi_p2p_noa_info *noa;
323         int ret, vdev_id;
324
325         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
326         if (IS_ERR(tb)) {
327                 ret = PTR_ERR(tb);
328                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
329                 return ret;
330         }
331
332         ev = tb[WMI_TLV_TAG_STRUCT_P2P_NOA_EVENT];
333         noa = tb[WMI_TLV_TAG_STRUCT_P2P_NOA_INFO];
334
335         if (!ev || !noa) {
336                 kfree(tb);
337                 return -EPROTO;
338         }
339
340         vdev_id = __le32_to_cpu(ev->vdev_id);
341
342         ath10k_dbg(ar, ATH10K_DBG_WMI,
343                    "wmi tlv p2p noa vdev_id %i descriptors %hhu\n",
344                    vdev_id, noa->num_descriptors);
345
346         ath10k_p2p_noa_update_by_vdev_id(ar, vdev_id, noa);
347         kfree(tb);
348         return 0;
349 }
350
351 static int ath10k_wmi_tlv_event_tx_pause(struct ath10k *ar,
352                                          struct sk_buff *skb)
353 {
354         const void **tb;
355         const struct wmi_tlv_tx_pause_ev *ev;
356         int ret, vdev_id;
357         u32 pause_id, action, vdev_map, peer_id, tid_map;
358
359         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
360         if (IS_ERR(tb)) {
361                 ret = PTR_ERR(tb);
362                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
363                 return ret;
364         }
365
366         ev = tb[WMI_TLV_TAG_STRUCT_TX_PAUSE_EVENT];
367         if (!ev) {
368                 kfree(tb);
369                 return -EPROTO;
370         }
371
372         pause_id = __le32_to_cpu(ev->pause_id);
373         action = __le32_to_cpu(ev->action);
374         vdev_map = __le32_to_cpu(ev->vdev_map);
375         peer_id = __le32_to_cpu(ev->peer_id);
376         tid_map = __le32_to_cpu(ev->tid_map);
377
378         ath10k_dbg(ar, ATH10K_DBG_WMI,
379                    "wmi tlv tx pause pause_id %u action %u vdev_map 0x%08x peer_id %u tid_map 0x%08x\n",
380                    pause_id, action, vdev_map, peer_id, tid_map);
381
382         switch (pause_id) {
383         case WMI_TLV_TX_PAUSE_ID_MCC:
384         case WMI_TLV_TX_PAUSE_ID_P2P_CLI_NOA:
385         case WMI_TLV_TX_PAUSE_ID_P2P_GO_PS:
386         case WMI_TLV_TX_PAUSE_ID_AP_PS:
387         case WMI_TLV_TX_PAUSE_ID_IBSS_PS:
388                 for (vdev_id = 0; vdev_map; vdev_id++) {
389                         if (!(vdev_map & BIT(vdev_id)))
390                                 continue;
391
392                         vdev_map &= ~BIT(vdev_id);
393                         ath10k_mac_handle_tx_pause_vdev(ar, vdev_id, pause_id,
394                                                         action);
395                 }
396                 break;
397         case WMI_TLV_TX_PAUSE_ID_AP_PEER_PS:
398         case WMI_TLV_TX_PAUSE_ID_AP_PEER_UAPSD:
399         case WMI_TLV_TX_PAUSE_ID_STA_ADD_BA:
400         case WMI_TLV_TX_PAUSE_ID_HOST:
401                 ath10k_dbg(ar, ATH10K_DBG_MAC,
402                            "mac ignoring unsupported tx pause id %d\n",
403                            pause_id);
404                 break;
405         default:
406                 ath10k_dbg(ar, ATH10K_DBG_MAC,
407                            "mac ignoring unknown tx pause vdev %d\n",
408                            pause_id);
409                 break;
410         }
411
412         kfree(tb);
413         return 0;
414 }
415
416 static int ath10k_wmi_tlv_event_temperature(struct ath10k *ar,
417                                             struct sk_buff *skb)
418 {
419         const struct wmi_tlv_pdev_temperature_event *ev;
420
421         ev = (struct wmi_tlv_pdev_temperature_event *)skb->data;
422         if (WARN_ON(skb->len < sizeof(*ev)))
423                 return -EPROTO;
424
425         ath10k_thermal_event_temperature(ar, __le32_to_cpu(ev->temperature));
426         return 0;
427 }
428
429 static void ath10k_wmi_event_tdls_peer(struct ath10k *ar, struct sk_buff *skb)
430 {
431         struct ieee80211_sta *station;
432         const struct wmi_tlv_tdls_peer_event *ev;
433         const void **tb;
434         struct ath10k_vif *arvif;
435
436         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
437         if (IS_ERR(tb)) {
438                 ath10k_warn(ar, "tdls peer failed to parse tlv");
439                 return;
440         }
441         ev = tb[WMI_TLV_TAG_STRUCT_TDLS_PEER_EVENT];
442         if (!ev) {
443                 kfree(tb);
444                 ath10k_warn(ar, "tdls peer NULL event");
445                 return;
446         }
447
448         switch (__le32_to_cpu(ev->peer_reason)) {
449         case WMI_TDLS_TEARDOWN_REASON_TX:
450         case WMI_TDLS_TEARDOWN_REASON_RSSI:
451         case WMI_TDLS_TEARDOWN_REASON_PTR_TIMEOUT:
452                 station = ieee80211_find_sta_by_ifaddr(ar->hw,
453                                                        ev->peer_macaddr.addr,
454                                                        NULL);
455                 if (!station) {
456                         ath10k_warn(ar, "did not find station from tdls peer event");
457                         kfree(tb);
458                         return;
459                 }
460                 arvif = ath10k_get_arvif(ar, __le32_to_cpu(ev->vdev_id));
461                 ieee80211_tdls_oper_request(
462                                         arvif->vif, station->addr,
463                                         NL80211_TDLS_TEARDOWN,
464                                         WLAN_REASON_TDLS_TEARDOWN_UNREACHABLE,
465                                         GFP_ATOMIC
466                                         );
467                 break;
468         }
469         kfree(tb);
470 }
471
472 /***********/
473 /* TLV ops */
474 /***********/
475
476 static void ath10k_wmi_tlv_op_rx(struct ath10k *ar, struct sk_buff *skb)
477 {
478         struct wmi_cmd_hdr *cmd_hdr;
479         enum wmi_tlv_event_id id;
480         bool consumed;
481
482         cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
483         id = MS(__le32_to_cpu(cmd_hdr->cmd_id), WMI_CMD_HDR_CMD_ID);
484
485         if (skb_pull(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
486                 goto out;
487
488         trace_ath10k_wmi_event(ar, id, skb->data, skb->len);
489
490         consumed = ath10k_tm_event_wmi(ar, id, skb);
491
492         /* Ready event must be handled normally also in UTF mode so that we
493          * know the UTF firmware has booted, others we are just bypass WMI
494          * events to testmode.
495          */
496         if (consumed && id != WMI_TLV_READY_EVENTID) {
497                 ath10k_dbg(ar, ATH10K_DBG_WMI,
498                            "wmi tlv testmode consumed 0x%x\n", id);
499                 goto out;
500         }
501
502         switch (id) {
503         case WMI_TLV_MGMT_RX_EVENTID:
504                 ath10k_wmi_event_mgmt_rx(ar, skb);
505                 /* mgmt_rx() owns the skb now! */
506                 return;
507         case WMI_TLV_SCAN_EVENTID:
508                 ath10k_wmi_event_scan(ar, skb);
509                 break;
510         case WMI_TLV_CHAN_INFO_EVENTID:
511                 ath10k_wmi_event_chan_info(ar, skb);
512                 break;
513         case WMI_TLV_ECHO_EVENTID:
514                 ath10k_wmi_event_echo(ar, skb);
515                 break;
516         case WMI_TLV_DEBUG_MESG_EVENTID:
517                 ath10k_wmi_event_debug_mesg(ar, skb);
518                 break;
519         case WMI_TLV_UPDATE_STATS_EVENTID:
520                 ath10k_wmi_event_update_stats(ar, skb);
521                 break;
522         case WMI_TLV_VDEV_START_RESP_EVENTID:
523                 ath10k_wmi_event_vdev_start_resp(ar, skb);
524                 break;
525         case WMI_TLV_VDEV_STOPPED_EVENTID:
526                 ath10k_wmi_event_vdev_stopped(ar, skb);
527                 break;
528         case WMI_TLV_PEER_STA_KICKOUT_EVENTID:
529                 ath10k_wmi_event_peer_sta_kickout(ar, skb);
530                 break;
531         case WMI_TLV_HOST_SWBA_EVENTID:
532                 ath10k_wmi_event_host_swba(ar, skb);
533                 break;
534         case WMI_TLV_TBTTOFFSET_UPDATE_EVENTID:
535                 ath10k_wmi_event_tbttoffset_update(ar, skb);
536                 break;
537         case WMI_TLV_PHYERR_EVENTID:
538                 ath10k_wmi_event_phyerr(ar, skb);
539                 break;
540         case WMI_TLV_ROAM_EVENTID:
541                 ath10k_wmi_event_roam(ar, skb);
542                 break;
543         case WMI_TLV_PROFILE_MATCH:
544                 ath10k_wmi_event_profile_match(ar, skb);
545                 break;
546         case WMI_TLV_DEBUG_PRINT_EVENTID:
547                 ath10k_wmi_event_debug_print(ar, skb);
548                 break;
549         case WMI_TLV_PDEV_QVIT_EVENTID:
550                 ath10k_wmi_event_pdev_qvit(ar, skb);
551                 break;
552         case WMI_TLV_WLAN_PROFILE_DATA_EVENTID:
553                 ath10k_wmi_event_wlan_profile_data(ar, skb);
554                 break;
555         case WMI_TLV_RTT_MEASUREMENT_REPORT_EVENTID:
556                 ath10k_wmi_event_rtt_measurement_report(ar, skb);
557                 break;
558         case WMI_TLV_TSF_MEASUREMENT_REPORT_EVENTID:
559                 ath10k_wmi_event_tsf_measurement_report(ar, skb);
560                 break;
561         case WMI_TLV_RTT_ERROR_REPORT_EVENTID:
562                 ath10k_wmi_event_rtt_error_report(ar, skb);
563                 break;
564         case WMI_TLV_WOW_WAKEUP_HOST_EVENTID:
565                 ath10k_wmi_event_wow_wakeup_host(ar, skb);
566                 break;
567         case WMI_TLV_DCS_INTERFERENCE_EVENTID:
568                 ath10k_wmi_event_dcs_interference(ar, skb);
569                 break;
570         case WMI_TLV_PDEV_TPC_CONFIG_EVENTID:
571                 ath10k_wmi_event_pdev_tpc_config(ar, skb);
572                 break;
573         case WMI_TLV_PDEV_FTM_INTG_EVENTID:
574                 ath10k_wmi_event_pdev_ftm_intg(ar, skb);
575                 break;
576         case WMI_TLV_GTK_OFFLOAD_STATUS_EVENTID:
577                 ath10k_wmi_event_gtk_offload_status(ar, skb);
578                 break;
579         case WMI_TLV_GTK_REKEY_FAIL_EVENTID:
580                 ath10k_wmi_event_gtk_rekey_fail(ar, skb);
581                 break;
582         case WMI_TLV_TX_DELBA_COMPLETE_EVENTID:
583                 ath10k_wmi_event_delba_complete(ar, skb);
584                 break;
585         case WMI_TLV_TX_ADDBA_COMPLETE_EVENTID:
586                 ath10k_wmi_event_addba_complete(ar, skb);
587                 break;
588         case WMI_TLV_VDEV_INSTALL_KEY_COMPLETE_EVENTID:
589                 ath10k_wmi_event_vdev_install_key_complete(ar, skb);
590                 break;
591         case WMI_TLV_SERVICE_READY_EVENTID:
592                 ath10k_wmi_event_service_ready(ar, skb);
593                 return;
594         case WMI_TLV_READY_EVENTID:
595                 ath10k_wmi_event_ready(ar, skb);
596                 break;
597         case WMI_TLV_SERVICE_AVAILABLE_EVENTID:
598                 ath10k_wmi_event_service_available(ar, skb);
599                 break;
600         case WMI_TLV_OFFLOAD_BCN_TX_STATUS_EVENTID:
601                 ath10k_wmi_tlv_event_bcn_tx_status(ar, skb);
602                 break;
603         case WMI_TLV_DIAG_DATA_CONTAINER_EVENTID:
604                 ath10k_wmi_tlv_event_diag_data(ar, skb);
605                 break;
606         case WMI_TLV_DIAG_EVENTID:
607                 ath10k_wmi_tlv_event_diag(ar, skb);
608                 break;
609         case WMI_TLV_P2P_NOA_EVENTID:
610                 ath10k_wmi_tlv_event_p2p_noa(ar, skb);
611                 break;
612         case WMI_TLV_TX_PAUSE_EVENTID:
613                 ath10k_wmi_tlv_event_tx_pause(ar, skb);
614                 break;
615         case WMI_TLV_PDEV_TEMPERATURE_EVENTID:
616                 ath10k_wmi_tlv_event_temperature(ar, skb);
617                 break;
618         case WMI_TLV_TDLS_PEER_EVENTID:
619                 ath10k_wmi_event_tdls_peer(ar, skb);
620                 break;
621         default:
622                 ath10k_warn(ar, "Unknown eventid: %d\n", id);
623                 break;
624         }
625
626 out:
627         dev_kfree_skb(skb);
628 }
629
630 static int ath10k_wmi_tlv_op_pull_scan_ev(struct ath10k *ar,
631                                           struct sk_buff *skb,
632                                           struct wmi_scan_ev_arg *arg)
633 {
634         const void **tb;
635         const struct wmi_scan_event *ev;
636         int ret;
637
638         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
639         if (IS_ERR(tb)) {
640                 ret = PTR_ERR(tb);
641                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
642                 return ret;
643         }
644
645         ev = tb[WMI_TLV_TAG_STRUCT_SCAN_EVENT];
646         if (!ev) {
647                 kfree(tb);
648                 return -EPROTO;
649         }
650
651         arg->event_type = ev->event_type;
652         arg->reason = ev->reason;
653         arg->channel_freq = ev->channel_freq;
654         arg->scan_req_id = ev->scan_req_id;
655         arg->scan_id = ev->scan_id;
656         arg->vdev_id = ev->vdev_id;
657
658         kfree(tb);
659         return 0;
660 }
661
662 static int ath10k_wmi_tlv_op_pull_mgmt_rx_ev(struct ath10k *ar,
663                                              struct sk_buff *skb,
664                                              struct wmi_mgmt_rx_ev_arg *arg)
665 {
666         const void **tb;
667         const struct wmi_tlv_mgmt_rx_ev *ev;
668         const u8 *frame;
669         u32 msdu_len;
670         int ret;
671
672         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
673         if (IS_ERR(tb)) {
674                 ret = PTR_ERR(tb);
675                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
676                 return ret;
677         }
678
679         ev = tb[WMI_TLV_TAG_STRUCT_MGMT_RX_HDR];
680         frame = tb[WMI_TLV_TAG_ARRAY_BYTE];
681
682         if (!ev || !frame) {
683                 kfree(tb);
684                 return -EPROTO;
685         }
686
687         arg->channel = ev->channel;
688         arg->buf_len = ev->buf_len;
689         arg->status = ev->status;
690         arg->snr = ev->snr;
691         arg->phy_mode = ev->phy_mode;
692         arg->rate = ev->rate;
693
694         msdu_len = __le32_to_cpu(arg->buf_len);
695
696         if (skb->len < (frame - skb->data) + msdu_len) {
697                 kfree(tb);
698                 return -EPROTO;
699         }
700
701         /* shift the sk_buff to point to `frame` */
702         skb_trim(skb, 0);
703         skb_put(skb, frame - skb->data);
704         skb_pull(skb, frame - skb->data);
705         skb_put(skb, msdu_len);
706
707         kfree(tb);
708         return 0;
709 }
710
711 static int ath10k_wmi_tlv_op_pull_ch_info_ev(struct ath10k *ar,
712                                              struct sk_buff *skb,
713                                              struct wmi_ch_info_ev_arg *arg)
714 {
715         const void **tb;
716         const struct wmi_chan_info_event *ev;
717         int ret;
718
719         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
720         if (IS_ERR(tb)) {
721                 ret = PTR_ERR(tb);
722                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
723                 return ret;
724         }
725
726         ev = tb[WMI_TLV_TAG_STRUCT_CHAN_INFO_EVENT];
727         if (!ev) {
728                 kfree(tb);
729                 return -EPROTO;
730         }
731
732         arg->err_code = ev->err_code;
733         arg->freq = ev->freq;
734         arg->cmd_flags = ev->cmd_flags;
735         arg->noise_floor = ev->noise_floor;
736         arg->rx_clear_count = ev->rx_clear_count;
737         arg->cycle_count = ev->cycle_count;
738
739         kfree(tb);
740         return 0;
741 }
742
743 static int
744 ath10k_wmi_tlv_op_pull_vdev_start_ev(struct ath10k *ar, struct sk_buff *skb,
745                                      struct wmi_vdev_start_ev_arg *arg)
746 {
747         const void **tb;
748         const struct wmi_vdev_start_response_event *ev;
749         int ret;
750
751         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
752         if (IS_ERR(tb)) {
753                 ret = PTR_ERR(tb);
754                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
755                 return ret;
756         }
757
758         ev = tb[WMI_TLV_TAG_STRUCT_VDEV_START_RESPONSE_EVENT];
759         if (!ev) {
760                 kfree(tb);
761                 return -EPROTO;
762         }
763
764         skb_pull(skb, sizeof(*ev));
765         arg->vdev_id = ev->vdev_id;
766         arg->req_id = ev->req_id;
767         arg->resp_type = ev->resp_type;
768         arg->status = ev->status;
769
770         kfree(tb);
771         return 0;
772 }
773
774 static int ath10k_wmi_tlv_op_pull_peer_kick_ev(struct ath10k *ar,
775                                                struct sk_buff *skb,
776                                                struct wmi_peer_kick_ev_arg *arg)
777 {
778         const void **tb;
779         const struct wmi_peer_sta_kickout_event *ev;
780         int ret;
781
782         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
783         if (IS_ERR(tb)) {
784                 ret = PTR_ERR(tb);
785                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
786                 return ret;
787         }
788
789         ev = tb[WMI_TLV_TAG_STRUCT_PEER_STA_KICKOUT_EVENT];
790         if (!ev) {
791                 kfree(tb);
792                 return -EPROTO;
793         }
794
795         arg->mac_addr = ev->peer_macaddr.addr;
796
797         kfree(tb);
798         return 0;
799 }
800
801 struct wmi_tlv_swba_parse {
802         const struct wmi_host_swba_event *ev;
803         bool tim_done;
804         bool noa_done;
805         size_t n_tim;
806         size_t n_noa;
807         struct wmi_swba_ev_arg *arg;
808 };
809
810 static int ath10k_wmi_tlv_swba_tim_parse(struct ath10k *ar, u16 tag, u16 len,
811                                          const void *ptr, void *data)
812 {
813         struct wmi_tlv_swba_parse *swba = data;
814         struct wmi_tim_info_arg *tim_info_arg;
815         const struct wmi_tim_info *tim_info_ev = ptr;
816
817         if (tag != WMI_TLV_TAG_STRUCT_TIM_INFO)
818                 return -EPROTO;
819
820         if (swba->n_tim >= ARRAY_SIZE(swba->arg->tim_info))
821                 return -ENOBUFS;
822
823         if (__le32_to_cpu(tim_info_ev->tim_len) >
824              sizeof(tim_info_ev->tim_bitmap)) {
825                 ath10k_warn(ar, "refusing to parse invalid swba structure\n");
826                 return -EPROTO;
827         }
828
829         tim_info_arg = &swba->arg->tim_info[swba->n_tim];
830         tim_info_arg->tim_len = tim_info_ev->tim_len;
831         tim_info_arg->tim_mcast = tim_info_ev->tim_mcast;
832         tim_info_arg->tim_bitmap = tim_info_ev->tim_bitmap;
833         tim_info_arg->tim_changed = tim_info_ev->tim_changed;
834         tim_info_arg->tim_num_ps_pending = tim_info_ev->tim_num_ps_pending;
835
836         swba->n_tim++;
837
838         return 0;
839 }
840
841 static int ath10k_wmi_tlv_swba_noa_parse(struct ath10k *ar, u16 tag, u16 len,
842                                          const void *ptr, void *data)
843 {
844         struct wmi_tlv_swba_parse *swba = data;
845
846         if (tag != WMI_TLV_TAG_STRUCT_P2P_NOA_INFO)
847                 return -EPROTO;
848
849         if (swba->n_noa >= ARRAY_SIZE(swba->arg->noa_info))
850                 return -ENOBUFS;
851
852         swba->arg->noa_info[swba->n_noa++] = ptr;
853         return 0;
854 }
855
856 static int ath10k_wmi_tlv_swba_parse(struct ath10k *ar, u16 tag, u16 len,
857                                      const void *ptr, void *data)
858 {
859         struct wmi_tlv_swba_parse *swba = data;
860         int ret;
861
862         switch (tag) {
863         case WMI_TLV_TAG_STRUCT_HOST_SWBA_EVENT:
864                 swba->ev = ptr;
865                 break;
866         case WMI_TLV_TAG_ARRAY_STRUCT:
867                 if (!swba->tim_done) {
868                         swba->tim_done = true;
869                         ret = ath10k_wmi_tlv_iter(ar, ptr, len,
870                                                   ath10k_wmi_tlv_swba_tim_parse,
871                                                   swba);
872                         if (ret)
873                                 return ret;
874                 } else if (!swba->noa_done) {
875                         swba->noa_done = true;
876                         ret = ath10k_wmi_tlv_iter(ar, ptr, len,
877                                                   ath10k_wmi_tlv_swba_noa_parse,
878                                                   swba);
879                         if (ret)
880                                 return ret;
881                 }
882                 break;
883         default:
884                 break;
885         }
886         return 0;
887 }
888
889 static int ath10k_wmi_tlv_op_pull_swba_ev(struct ath10k *ar,
890                                           struct sk_buff *skb,
891                                           struct wmi_swba_ev_arg *arg)
892 {
893         struct wmi_tlv_swba_parse swba = { .arg = arg };
894         u32 map;
895         size_t n_vdevs;
896         int ret;
897
898         ret = ath10k_wmi_tlv_iter(ar, skb->data, skb->len,
899                                   ath10k_wmi_tlv_swba_parse, &swba);
900         if (ret) {
901                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
902                 return ret;
903         }
904
905         if (!swba.ev)
906                 return -EPROTO;
907
908         arg->vdev_map = swba.ev->vdev_map;
909
910         for (map = __le32_to_cpu(arg->vdev_map), n_vdevs = 0; map; map >>= 1)
911                 if (map & BIT(0))
912                         n_vdevs++;
913
914         if (n_vdevs != swba.n_tim ||
915             n_vdevs != swba.n_noa)
916                 return -EPROTO;
917
918         return 0;
919 }
920
921 static int ath10k_wmi_tlv_op_pull_phyerr_ev_hdr(struct ath10k *ar,
922                                                 struct sk_buff *skb,
923                                                 struct wmi_phyerr_hdr_arg *arg)
924 {
925         const void **tb;
926         const struct wmi_tlv_phyerr_ev *ev;
927         const void *phyerrs;
928         int ret;
929
930         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
931         if (IS_ERR(tb)) {
932                 ret = PTR_ERR(tb);
933                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
934                 return ret;
935         }
936
937         ev = tb[WMI_TLV_TAG_STRUCT_COMB_PHYERR_RX_HDR];
938         phyerrs = tb[WMI_TLV_TAG_ARRAY_BYTE];
939
940         if (!ev || !phyerrs) {
941                 kfree(tb);
942                 return -EPROTO;
943         }
944
945         arg->num_phyerrs  = __le32_to_cpu(ev->num_phyerrs);
946         arg->tsf_l32 = __le32_to_cpu(ev->tsf_l32);
947         arg->tsf_u32 = __le32_to_cpu(ev->tsf_u32);
948         arg->buf_len = __le32_to_cpu(ev->buf_len);
949         arg->phyerrs = phyerrs;
950
951         kfree(tb);
952         return 0;
953 }
954
955 #define WMI_TLV_ABI_VER_NS0 0x5F414351
956 #define WMI_TLV_ABI_VER_NS1 0x00004C4D
957 #define WMI_TLV_ABI_VER_NS2 0x00000000
958 #define WMI_TLV_ABI_VER_NS3 0x00000000
959
960 #define WMI_TLV_ABI_VER0_MAJOR 1
961 #define WMI_TLV_ABI_VER0_MINOR 0
962 #define WMI_TLV_ABI_VER0 ((((WMI_TLV_ABI_VER0_MAJOR) << 24) & 0xFF000000) | \
963                           (((WMI_TLV_ABI_VER0_MINOR) <<  0) & 0x00FFFFFF))
964 #define WMI_TLV_ABI_VER1 53
965
966 static int
967 ath10k_wmi_tlv_parse_mem_reqs(struct ath10k *ar, u16 tag, u16 len,
968                               const void *ptr, void *data)
969 {
970         struct wmi_svc_rdy_ev_arg *arg = data;
971         int i;
972
973         if (tag != WMI_TLV_TAG_STRUCT_WLAN_HOST_MEM_REQ)
974                 return -EPROTO;
975
976         for (i = 0; i < ARRAY_SIZE(arg->mem_reqs); i++) {
977                 if (!arg->mem_reqs[i]) {
978                         arg->mem_reqs[i] = ptr;
979                         return 0;
980                 }
981         }
982
983         return -ENOMEM;
984 }
985
986 struct wmi_tlv_svc_rdy_parse {
987         const struct hal_reg_capabilities *reg;
988         const struct wmi_tlv_svc_rdy_ev *ev;
989         const __le32 *svc_bmap;
990         const struct wlan_host_mem_req *mem_reqs;
991         bool svc_bmap_done;
992         bool dbs_hw_mode_done;
993 };
994
995 static int ath10k_wmi_tlv_svc_rdy_parse(struct ath10k *ar, u16 tag, u16 len,
996                                         const void *ptr, void *data)
997 {
998         struct wmi_tlv_svc_rdy_parse *svc_rdy = data;
999
1000         switch (tag) {
1001         case WMI_TLV_TAG_STRUCT_SERVICE_READY_EVENT:
1002                 svc_rdy->ev = ptr;
1003                 break;
1004         case WMI_TLV_TAG_STRUCT_HAL_REG_CAPABILITIES:
1005                 svc_rdy->reg = ptr;
1006                 break;
1007         case WMI_TLV_TAG_ARRAY_STRUCT:
1008                 svc_rdy->mem_reqs = ptr;
1009                 break;
1010         case WMI_TLV_TAG_ARRAY_UINT32:
1011                 if (!svc_rdy->svc_bmap_done) {
1012                         svc_rdy->svc_bmap_done = true;
1013                         svc_rdy->svc_bmap = ptr;
1014                 } else if (!svc_rdy->dbs_hw_mode_done) {
1015                         svc_rdy->dbs_hw_mode_done = true;
1016                 }
1017                 break;
1018         default:
1019                 break;
1020         }
1021         return 0;
1022 }
1023
1024 static int ath10k_wmi_tlv_op_pull_svc_rdy_ev(struct ath10k *ar,
1025                                              struct sk_buff *skb,
1026                                              struct wmi_svc_rdy_ev_arg *arg)
1027 {
1028         const struct hal_reg_capabilities *reg;
1029         const struct wmi_tlv_svc_rdy_ev *ev;
1030         const __le32 *svc_bmap;
1031         const struct wlan_host_mem_req *mem_reqs;
1032         struct wmi_tlv_svc_rdy_parse svc_rdy = { };
1033         int ret;
1034
1035         ret = ath10k_wmi_tlv_iter(ar, skb->data, skb->len,
1036                                   ath10k_wmi_tlv_svc_rdy_parse, &svc_rdy);
1037         if (ret) {
1038                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1039                 return ret;
1040         }
1041
1042         ev = svc_rdy.ev;
1043         reg = svc_rdy.reg;
1044         svc_bmap = svc_rdy.svc_bmap;
1045         mem_reqs = svc_rdy.mem_reqs;
1046
1047         if (!ev || !reg || !svc_bmap || !mem_reqs)
1048                 return -EPROTO;
1049
1050         /* This is an internal ABI compatibility check for WMI TLV so check it
1051          * here instead of the generic WMI code.
1052          */
1053         ath10k_dbg(ar, ATH10K_DBG_WMI,
1054                    "wmi tlv abi 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x\n",
1055                    __le32_to_cpu(ev->abi.abi_ver0), WMI_TLV_ABI_VER0,
1056                    __le32_to_cpu(ev->abi.abi_ver_ns0), WMI_TLV_ABI_VER_NS0,
1057                    __le32_to_cpu(ev->abi.abi_ver_ns1), WMI_TLV_ABI_VER_NS1,
1058                    __le32_to_cpu(ev->abi.abi_ver_ns2), WMI_TLV_ABI_VER_NS2,
1059                    __le32_to_cpu(ev->abi.abi_ver_ns3), WMI_TLV_ABI_VER_NS3);
1060
1061         if (__le32_to_cpu(ev->abi.abi_ver0) != WMI_TLV_ABI_VER0 ||
1062             __le32_to_cpu(ev->abi.abi_ver_ns0) != WMI_TLV_ABI_VER_NS0 ||
1063             __le32_to_cpu(ev->abi.abi_ver_ns1) != WMI_TLV_ABI_VER_NS1 ||
1064             __le32_to_cpu(ev->abi.abi_ver_ns2) != WMI_TLV_ABI_VER_NS2 ||
1065             __le32_to_cpu(ev->abi.abi_ver_ns3) != WMI_TLV_ABI_VER_NS3) {
1066                 return -ENOTSUPP;
1067         }
1068
1069         arg->min_tx_power = ev->hw_min_tx_power;
1070         arg->max_tx_power = ev->hw_max_tx_power;
1071         arg->ht_cap = ev->ht_cap_info;
1072         arg->vht_cap = ev->vht_cap_info;
1073         arg->sw_ver0 = ev->abi.abi_ver0;
1074         arg->sw_ver1 = ev->abi.abi_ver1;
1075         arg->fw_build = ev->fw_build_vers;
1076         arg->phy_capab = ev->phy_capability;
1077         arg->num_rf_chains = ev->num_rf_chains;
1078         arg->eeprom_rd = reg->eeprom_rd;
1079         arg->num_mem_reqs = ev->num_mem_reqs;
1080         arg->service_map = svc_bmap;
1081         arg->service_map_len = ath10k_wmi_tlv_len(svc_bmap);
1082
1083         ret = ath10k_wmi_tlv_iter(ar, mem_reqs, ath10k_wmi_tlv_len(mem_reqs),
1084                                   ath10k_wmi_tlv_parse_mem_reqs, arg);
1085         if (ret) {
1086                 ath10k_warn(ar, "failed to parse mem_reqs tlv: %d\n", ret);
1087                 return ret;
1088         }
1089
1090         return 0;
1091 }
1092
1093 static int ath10k_wmi_tlv_op_pull_rdy_ev(struct ath10k *ar,
1094                                          struct sk_buff *skb,
1095                                          struct wmi_rdy_ev_arg *arg)
1096 {
1097         const void **tb;
1098         const struct wmi_tlv_rdy_ev *ev;
1099         int ret;
1100
1101         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1102         if (IS_ERR(tb)) {
1103                 ret = PTR_ERR(tb);
1104                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1105                 return ret;
1106         }
1107
1108         ev = tb[WMI_TLV_TAG_STRUCT_READY_EVENT];
1109         if (!ev) {
1110                 kfree(tb);
1111                 return -EPROTO;
1112         }
1113
1114         arg->sw_version = ev->abi.abi_ver0;
1115         arg->abi_version = ev->abi.abi_ver1;
1116         arg->status = ev->status;
1117         arg->mac_addr = ev->mac_addr.addr;
1118
1119         kfree(tb);
1120         return 0;
1121 }
1122
1123 static int ath10k_wmi_tlv_svc_avail_parse(struct ath10k *ar, u16 tag, u16 len,
1124                                           const void *ptr, void *data)
1125 {
1126         struct wmi_svc_avail_ev_arg *arg = data;
1127
1128         switch (tag) {
1129         case WMI_TLV_TAG_STRUCT_SERVICE_AVAILABLE_EVENT:
1130                 arg->service_map_ext_len = *(__le32 *)ptr;
1131                 arg->service_map_ext = ptr + sizeof(__le32);
1132                 return 0;
1133         default:
1134                 break;
1135         }
1136         return -EPROTO;
1137 }
1138
1139 static int ath10k_wmi_tlv_op_pull_svc_avail(struct ath10k *ar,
1140                                             struct sk_buff *skb,
1141                                             struct wmi_svc_avail_ev_arg *arg)
1142 {
1143         int ret;
1144
1145         ret = ath10k_wmi_tlv_iter(ar, skb->data, skb->len,
1146                                   ath10k_wmi_tlv_svc_avail_parse, arg);
1147
1148         if (ret) {
1149                 ath10k_warn(ar, "failed to parse svc_avail tlv: %d\n", ret);
1150                 return ret;
1151         }
1152
1153         return 0;
1154 }
1155
1156 static void ath10k_wmi_tlv_pull_vdev_stats(const struct wmi_tlv_vdev_stats *src,
1157                                            struct ath10k_fw_stats_vdev *dst)
1158 {
1159         int i;
1160
1161         dst->vdev_id = __le32_to_cpu(src->vdev_id);
1162         dst->beacon_snr = __le32_to_cpu(src->beacon_snr);
1163         dst->data_snr = __le32_to_cpu(src->data_snr);
1164         dst->num_rx_frames = __le32_to_cpu(src->num_rx_frames);
1165         dst->num_rts_fail = __le32_to_cpu(src->num_rts_fail);
1166         dst->num_rts_success = __le32_to_cpu(src->num_rts_success);
1167         dst->num_rx_err = __le32_to_cpu(src->num_rx_err);
1168         dst->num_rx_discard = __le32_to_cpu(src->num_rx_discard);
1169         dst->num_tx_not_acked = __le32_to_cpu(src->num_tx_not_acked);
1170
1171         for (i = 0; i < ARRAY_SIZE(src->num_tx_frames); i++)
1172                 dst->num_tx_frames[i] =
1173                         __le32_to_cpu(src->num_tx_frames[i]);
1174
1175         for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_retries); i++)
1176                 dst->num_tx_frames_retries[i] =
1177                         __le32_to_cpu(src->num_tx_frames_retries[i]);
1178
1179         for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_failures); i++)
1180                 dst->num_tx_frames_failures[i] =
1181                         __le32_to_cpu(src->num_tx_frames_failures[i]);
1182
1183         for (i = 0; i < ARRAY_SIZE(src->tx_rate_history); i++)
1184                 dst->tx_rate_history[i] =
1185                         __le32_to_cpu(src->tx_rate_history[i]);
1186
1187         for (i = 0; i < ARRAY_SIZE(src->beacon_rssi_history); i++)
1188                 dst->beacon_rssi_history[i] =
1189                         __le32_to_cpu(src->beacon_rssi_history[i]);
1190 }
1191
1192 static int ath10k_wmi_tlv_op_pull_fw_stats(struct ath10k *ar,
1193                                            struct sk_buff *skb,
1194                                            struct ath10k_fw_stats *stats)
1195 {
1196         const void **tb;
1197         const struct wmi_tlv_stats_ev *ev;
1198         const void *data;
1199         u32 num_pdev_stats;
1200         u32 num_vdev_stats;
1201         u32 num_peer_stats;
1202         u32 num_bcnflt_stats;
1203         u32 num_chan_stats;
1204         size_t data_len;
1205         int ret;
1206         int i;
1207
1208         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1209         if (IS_ERR(tb)) {
1210                 ret = PTR_ERR(tb);
1211                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1212                 return ret;
1213         }
1214
1215         ev = tb[WMI_TLV_TAG_STRUCT_STATS_EVENT];
1216         data = tb[WMI_TLV_TAG_ARRAY_BYTE];
1217
1218         if (!ev || !data) {
1219                 kfree(tb);
1220                 return -EPROTO;
1221         }
1222
1223         data_len = ath10k_wmi_tlv_len(data);
1224         num_pdev_stats = __le32_to_cpu(ev->num_pdev_stats);
1225         num_vdev_stats = __le32_to_cpu(ev->num_vdev_stats);
1226         num_peer_stats = __le32_to_cpu(ev->num_peer_stats);
1227         num_bcnflt_stats = __le32_to_cpu(ev->num_bcnflt_stats);
1228         num_chan_stats = __le32_to_cpu(ev->num_chan_stats);
1229
1230         ath10k_dbg(ar, ATH10K_DBG_WMI,
1231                    "wmi tlv stats update pdev %i vdev %i peer %i bcnflt %i chan %i\n",
1232                    num_pdev_stats, num_vdev_stats, num_peer_stats,
1233                    num_bcnflt_stats, num_chan_stats);
1234
1235         for (i = 0; i < num_pdev_stats; i++) {
1236                 const struct wmi_pdev_stats *src;
1237                 struct ath10k_fw_stats_pdev *dst;
1238
1239                 src = data;
1240                 if (data_len < sizeof(*src)) {
1241                         kfree(tb);
1242                         return -EPROTO;
1243                 }
1244
1245                 data += sizeof(*src);
1246                 data_len -= sizeof(*src);
1247
1248                 dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
1249                 if (!dst)
1250                         continue;
1251
1252                 ath10k_wmi_pull_pdev_stats_base(&src->base, dst);
1253                 ath10k_wmi_pull_pdev_stats_tx(&src->tx, dst);
1254                 ath10k_wmi_pull_pdev_stats_rx(&src->rx, dst);
1255                 list_add_tail(&dst->list, &stats->pdevs);
1256         }
1257
1258         for (i = 0; i < num_vdev_stats; i++) {
1259                 const struct wmi_tlv_vdev_stats *src;
1260                 struct ath10k_fw_stats_vdev *dst;
1261
1262                 src = data;
1263                 if (data_len < sizeof(*src)) {
1264                         kfree(tb);
1265                         return -EPROTO;
1266                 }
1267
1268                 data += sizeof(*src);
1269                 data_len -= sizeof(*src);
1270
1271                 dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
1272                 if (!dst)
1273                         continue;
1274
1275                 ath10k_wmi_tlv_pull_vdev_stats(src, dst);
1276                 list_add_tail(&dst->list, &stats->vdevs);
1277         }
1278
1279         for (i = 0; i < num_peer_stats; i++) {
1280                 const struct wmi_10x_peer_stats *src;
1281                 struct ath10k_fw_stats_peer *dst;
1282
1283                 src = data;
1284                 if (data_len < sizeof(*src)) {
1285                         kfree(tb);
1286                         return -EPROTO;
1287                 }
1288
1289                 data += sizeof(*src);
1290                 data_len -= sizeof(*src);
1291
1292                 dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
1293                 if (!dst)
1294                         continue;
1295
1296                 ath10k_wmi_pull_peer_stats(&src->old, dst);
1297                 dst->peer_rx_rate = __le32_to_cpu(src->peer_rx_rate);
1298                 list_add_tail(&dst->list, &stats->peers);
1299         }
1300
1301         kfree(tb);
1302         return 0;
1303 }
1304
1305 static int ath10k_wmi_tlv_op_pull_roam_ev(struct ath10k *ar,
1306                                           struct sk_buff *skb,
1307                                           struct wmi_roam_ev_arg *arg)
1308 {
1309         const void **tb;
1310         const struct wmi_tlv_roam_ev *ev;
1311         int ret;
1312
1313         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1314         if (IS_ERR(tb)) {
1315                 ret = PTR_ERR(tb);
1316                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1317                 return ret;
1318         }
1319
1320         ev = tb[WMI_TLV_TAG_STRUCT_ROAM_EVENT];
1321         if (!ev) {
1322                 kfree(tb);
1323                 return -EPROTO;
1324         }
1325
1326         arg->vdev_id = ev->vdev_id;
1327         arg->reason = ev->reason;
1328         arg->rssi = ev->rssi;
1329
1330         kfree(tb);
1331         return 0;
1332 }
1333
1334 static int
1335 ath10k_wmi_tlv_op_pull_wow_ev(struct ath10k *ar, struct sk_buff *skb,
1336                               struct wmi_wow_ev_arg *arg)
1337 {
1338         const void **tb;
1339         const struct wmi_tlv_wow_event_info *ev;
1340         int ret;
1341
1342         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1343         if (IS_ERR(tb)) {
1344                 ret = PTR_ERR(tb);
1345                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1346                 return ret;
1347         }
1348
1349         ev = tb[WMI_TLV_TAG_STRUCT_WOW_EVENT_INFO];
1350         if (!ev) {
1351                 kfree(tb);
1352                 return -EPROTO;
1353         }
1354
1355         arg->vdev_id = __le32_to_cpu(ev->vdev_id);
1356         arg->flag = __le32_to_cpu(ev->flag);
1357         arg->wake_reason = __le32_to_cpu(ev->wake_reason);
1358         arg->data_len = __le32_to_cpu(ev->data_len);
1359
1360         kfree(tb);
1361         return 0;
1362 }
1363
1364 static int ath10k_wmi_tlv_op_pull_echo_ev(struct ath10k *ar,
1365                                           struct sk_buff *skb,
1366                                           struct wmi_echo_ev_arg *arg)
1367 {
1368         const void **tb;
1369         const struct wmi_echo_event *ev;
1370         int ret;
1371
1372         tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1373         if (IS_ERR(tb)) {
1374                 ret = PTR_ERR(tb);
1375                 ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1376                 return ret;
1377         }
1378
1379         ev = tb[WMI_TLV_TAG_STRUCT_ECHO_EVENT];
1380         if (!ev) {
1381                 kfree(tb);
1382                 return -EPROTO;
1383         }
1384
1385         arg->value = ev->value;
1386
1387         kfree(tb);
1388         return 0;
1389 }
1390
1391 static struct sk_buff *
1392 ath10k_wmi_tlv_op_gen_pdev_suspend(struct ath10k *ar, u32 opt)
1393 {
1394         struct wmi_tlv_pdev_suspend *cmd;
1395         struct wmi_tlv *tlv;
1396         struct sk_buff *skb;
1397
1398         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1399         if (!skb)
1400                 return ERR_PTR(-ENOMEM);
1401
1402         tlv = (void *)skb->data;
1403         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SUSPEND_CMD);
1404         tlv->len = __cpu_to_le16(sizeof(*cmd));
1405         cmd = (void *)tlv->value;
1406         cmd->opt = __cpu_to_le32(opt);
1407
1408         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev suspend\n");
1409         return skb;
1410 }
1411
1412 static struct sk_buff *
1413 ath10k_wmi_tlv_op_gen_pdev_resume(struct ath10k *ar)
1414 {
1415         struct wmi_tlv_resume_cmd *cmd;
1416         struct wmi_tlv *tlv;
1417         struct sk_buff *skb;
1418
1419         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1420         if (!skb)
1421                 return ERR_PTR(-ENOMEM);
1422
1423         tlv = (void *)skb->data;
1424         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_RESUME_CMD);
1425         tlv->len = __cpu_to_le16(sizeof(*cmd));
1426         cmd = (void *)tlv->value;
1427         cmd->reserved = __cpu_to_le32(0);
1428
1429         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev resume\n");
1430         return skb;
1431 }
1432
1433 static struct sk_buff *
1434 ath10k_wmi_tlv_op_gen_pdev_set_rd(struct ath10k *ar,
1435                                   u16 rd, u16 rd2g, u16 rd5g,
1436                                   u16 ctl2g, u16 ctl5g,
1437                                   enum wmi_dfs_region dfs_reg)
1438 {
1439         struct wmi_tlv_pdev_set_rd_cmd *cmd;
1440         struct wmi_tlv *tlv;
1441         struct sk_buff *skb;
1442
1443         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1444         if (!skb)
1445                 return ERR_PTR(-ENOMEM);
1446
1447         tlv = (void *)skb->data;
1448         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_REGDOMAIN_CMD);
1449         tlv->len = __cpu_to_le16(sizeof(*cmd));
1450         cmd = (void *)tlv->value;
1451         cmd->regd = __cpu_to_le32(rd);
1452         cmd->regd_2ghz = __cpu_to_le32(rd2g);
1453         cmd->regd_5ghz = __cpu_to_le32(rd5g);
1454         cmd->conform_limit_2ghz = __cpu_to_le32(ctl2g);
1455         cmd->conform_limit_5ghz = __cpu_to_le32(ctl5g);
1456
1457         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev set rd\n");
1458         return skb;
1459 }
1460
1461 static enum wmi_txbf_conf ath10k_wmi_tlv_txbf_conf_scheme(struct ath10k *ar)
1462 {
1463         return WMI_TXBF_CONF_AFTER_ASSOC;
1464 }
1465
1466 static struct sk_buff *
1467 ath10k_wmi_tlv_op_gen_pdev_set_param(struct ath10k *ar, u32 param_id,
1468                                      u32 param_value)
1469 {
1470         struct wmi_tlv_pdev_set_param_cmd *cmd;
1471         struct wmi_tlv *tlv;
1472         struct sk_buff *skb;
1473
1474         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1475         if (!skb)
1476                 return ERR_PTR(-ENOMEM);
1477
1478         tlv = (void *)skb->data;
1479         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_PARAM_CMD);
1480         tlv->len = __cpu_to_le16(sizeof(*cmd));
1481         cmd = (void *)tlv->value;
1482         cmd->param_id = __cpu_to_le32(param_id);
1483         cmd->param_value = __cpu_to_le32(param_value);
1484
1485         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev set param\n");
1486         return skb;
1487 }
1488
1489 static struct sk_buff *ath10k_wmi_tlv_op_gen_init(struct ath10k *ar)
1490 {
1491         struct sk_buff *skb;
1492         struct wmi_tlv *tlv;
1493         struct wmi_tlv_init_cmd *cmd;
1494         struct wmi_tlv_resource_config *cfg;
1495         struct wmi_host_mem_chunks *chunks;
1496         size_t len, chunks_len;
1497         void *ptr;
1498
1499         chunks_len = ar->wmi.num_mem_chunks * sizeof(struct host_memory_chunk);
1500         len = (sizeof(*tlv) + sizeof(*cmd)) +
1501               (sizeof(*tlv) + sizeof(*cfg)) +
1502               (sizeof(*tlv) + chunks_len);
1503
1504         skb = ath10k_wmi_alloc_skb(ar, len);
1505         if (!skb)
1506                 return ERR_PTR(-ENOMEM);
1507
1508         ptr = skb->data;
1509
1510         tlv = ptr;
1511         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_INIT_CMD);
1512         tlv->len = __cpu_to_le16(sizeof(*cmd));
1513         cmd = (void *)tlv->value;
1514         ptr += sizeof(*tlv);
1515         ptr += sizeof(*cmd);
1516
1517         tlv = ptr;
1518         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_RESOURCE_CONFIG);
1519         tlv->len = __cpu_to_le16(sizeof(*cfg));
1520         cfg = (void *)tlv->value;
1521         ptr += sizeof(*tlv);
1522         ptr += sizeof(*cfg);
1523
1524         tlv = ptr;
1525         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
1526         tlv->len = __cpu_to_le16(chunks_len);
1527         chunks = (void *)tlv->value;
1528
1529         ptr += sizeof(*tlv);
1530         ptr += chunks_len;
1531
1532         cmd->abi.abi_ver0 = __cpu_to_le32(WMI_TLV_ABI_VER0);
1533         cmd->abi.abi_ver1 = __cpu_to_le32(WMI_TLV_ABI_VER1);
1534         cmd->abi.abi_ver_ns0 = __cpu_to_le32(WMI_TLV_ABI_VER_NS0);
1535         cmd->abi.abi_ver_ns1 = __cpu_to_le32(WMI_TLV_ABI_VER_NS1);
1536         cmd->abi.abi_ver_ns2 = __cpu_to_le32(WMI_TLV_ABI_VER_NS2);
1537         cmd->abi.abi_ver_ns3 = __cpu_to_le32(WMI_TLV_ABI_VER_NS3);
1538         cmd->num_host_mem_chunks = __cpu_to_le32(ar->wmi.num_mem_chunks);
1539
1540         cfg->num_vdevs = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1541
1542         cfg->num_peers = __cpu_to_le32(ar->hw_params.num_peers);
1543         cfg->ast_skid_limit = __cpu_to_le32(ar->hw_params.ast_skid_limit);
1544         cfg->num_wds_entries = __cpu_to_le32(ar->hw_params.num_wds_entries);
1545
1546         if (test_bit(WMI_SERVICE_RX_FULL_REORDER, ar->wmi.svc_map)) {
1547                 cfg->num_offload_peers = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1548                 cfg->num_offload_reorder_bufs = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1549         } else {
1550                 cfg->num_offload_peers = __cpu_to_le32(0);
1551                 cfg->num_offload_reorder_bufs = __cpu_to_le32(0);
1552         }
1553
1554         cfg->num_peer_keys = __cpu_to_le32(2);
1555         cfg->num_tids = __cpu_to_le32(TARGET_TLV_NUM_TIDS);
1556         cfg->tx_chain_mask = __cpu_to_le32(0x7);
1557         cfg->rx_chain_mask = __cpu_to_le32(0x7);
1558         cfg->rx_timeout_pri[0] = __cpu_to_le32(0x64);
1559         cfg->rx_timeout_pri[1] = __cpu_to_le32(0x64);
1560         cfg->rx_timeout_pri[2] = __cpu_to_le32(0x64);
1561         cfg->rx_timeout_pri[3] = __cpu_to_le32(0x28);
1562         cfg->rx_decap_mode = __cpu_to_le32(ar->wmi.rx_decap_mode);
1563         cfg->scan_max_pending_reqs = __cpu_to_le32(4);
1564         cfg->bmiss_offload_max_vdev = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1565         cfg->roam_offload_max_vdev = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1566         cfg->roam_offload_max_ap_profiles = __cpu_to_le32(8);
1567         cfg->num_mcast_groups = __cpu_to_le32(0);
1568         cfg->num_mcast_table_elems = __cpu_to_le32(0);
1569         cfg->mcast2ucast_mode = __cpu_to_le32(0);
1570         cfg->tx_dbg_log_size = __cpu_to_le32(0x400);
1571         cfg->dma_burst_size = __cpu_to_le32(0);
1572         cfg->mac_aggr_delim = __cpu_to_le32(0);
1573         cfg->rx_skip_defrag_timeout_dup_detection_check = __cpu_to_le32(0);
1574         cfg->vow_config = __cpu_to_le32(0);
1575         cfg->gtk_offload_max_vdev = __cpu_to_le32(2);
1576         cfg->num_msdu_desc = __cpu_to_le32(TARGET_TLV_NUM_MSDU_DESC);
1577         cfg->max_frag_entries = __cpu_to_le32(2);
1578         cfg->num_tdls_vdevs = __cpu_to_le32(TARGET_TLV_NUM_TDLS_VDEVS);
1579         cfg->num_tdls_conn_table_entries = __cpu_to_le32(0x20);
1580         cfg->beacon_tx_offload_max_vdev = __cpu_to_le32(2);
1581         cfg->num_multicast_filter_entries = __cpu_to_le32(5);
1582         cfg->num_wow_filters = __cpu_to_le32(ar->wow.max_num_patterns);
1583         cfg->num_keep_alive_pattern = __cpu_to_le32(6);
1584         cfg->keep_alive_pattern_size = __cpu_to_le32(0);
1585         cfg->max_tdls_concurrent_sleep_sta = __cpu_to_le32(1);
1586         cfg->max_tdls_concurrent_buffer_sta = __cpu_to_le32(1);
1587         cfg->wmi_send_separate = __cpu_to_le32(0);
1588         cfg->num_ocb_vdevs = __cpu_to_le32(0);
1589         cfg->num_ocb_channels = __cpu_to_le32(0);
1590         cfg->num_ocb_schedules = __cpu_to_le32(0);
1591         cfg->host_capab = __cpu_to_le32(0);
1592
1593         ath10k_wmi_put_host_mem_chunks(ar, chunks);
1594
1595         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv init\n");
1596         return skb;
1597 }
1598
1599 static struct sk_buff *
1600 ath10k_wmi_tlv_op_gen_start_scan(struct ath10k *ar,
1601                                  const struct wmi_start_scan_arg *arg)
1602 {
1603         struct wmi_tlv_start_scan_cmd *cmd;
1604         struct wmi_tlv *tlv;
1605         struct sk_buff *skb;
1606         size_t len, chan_len, ssid_len, bssid_len, ie_len;
1607         __le32 *chans;
1608         struct wmi_ssid *ssids;
1609         struct wmi_mac_addr *addrs;
1610         void *ptr;
1611         int i, ret;
1612
1613         ret = ath10k_wmi_start_scan_verify(arg);
1614         if (ret)
1615                 return ERR_PTR(ret);
1616
1617         chan_len = arg->n_channels * sizeof(__le32);
1618         ssid_len = arg->n_ssids * sizeof(struct wmi_ssid);
1619         bssid_len = arg->n_bssids * sizeof(struct wmi_mac_addr);
1620         ie_len = roundup(arg->ie_len, 4);
1621         len = (sizeof(*tlv) + sizeof(*cmd)) +
1622               sizeof(*tlv) + chan_len +
1623               sizeof(*tlv) + ssid_len +
1624               sizeof(*tlv) + bssid_len +
1625               sizeof(*tlv) + ie_len;
1626
1627         skb = ath10k_wmi_alloc_skb(ar, len);
1628         if (!skb)
1629                 return ERR_PTR(-ENOMEM);
1630
1631         ptr = (void *)skb->data;
1632         tlv = ptr;
1633         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_START_SCAN_CMD);
1634         tlv->len = __cpu_to_le16(sizeof(*cmd));
1635         cmd = (void *)tlv->value;
1636
1637         ath10k_wmi_put_start_scan_common(&cmd->common, arg);
1638         cmd->burst_duration_ms = __cpu_to_le32(arg->burst_duration_ms);
1639         cmd->num_channels = __cpu_to_le32(arg->n_channels);
1640         cmd->num_ssids = __cpu_to_le32(arg->n_ssids);
1641         cmd->num_bssids = __cpu_to_le32(arg->n_bssids);
1642         cmd->ie_len = __cpu_to_le32(arg->ie_len);
1643         cmd->num_probes = __cpu_to_le32(3);
1644         ether_addr_copy(cmd->mac_addr.addr, arg->mac_addr.addr);
1645         ether_addr_copy(cmd->mac_mask.addr, arg->mac_mask.addr);
1646
1647         /* FIXME: There are some scan flag inconsistencies across firmwares,
1648          * e.g. WMI-TLV inverts the logic behind the following flag.
1649          */
1650         cmd->common.scan_ctrl_flags ^= __cpu_to_le32(WMI_SCAN_FILTER_PROBE_REQ);
1651
1652         ptr += sizeof(*tlv);
1653         ptr += sizeof(*cmd);
1654
1655         tlv = ptr;
1656         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
1657         tlv->len = __cpu_to_le16(chan_len);
1658         chans = (void *)tlv->value;
1659         for (i = 0; i < arg->n_channels; i++)
1660                 chans[i] = __cpu_to_le32(arg->channels[i]);
1661
1662         ptr += sizeof(*tlv);
1663         ptr += chan_len;
1664
1665         tlv = ptr;
1666         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_FIXED_STRUCT);
1667         tlv->len = __cpu_to_le16(ssid_len);
1668         ssids = (void *)tlv->value;
1669         for (i = 0; i < arg->n_ssids; i++) {
1670                 ssids[i].ssid_len = __cpu_to_le32(arg->ssids[i].len);
1671                 memcpy(ssids[i].ssid, arg->ssids[i].ssid, arg->ssids[i].len);
1672         }
1673
1674         ptr += sizeof(*tlv);
1675         ptr += ssid_len;
1676
1677         tlv = ptr;
1678         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_FIXED_STRUCT);
1679         tlv->len = __cpu_to_le16(bssid_len);
1680         addrs = (void *)tlv->value;
1681         for (i = 0; i < arg->n_bssids; i++)
1682                 ether_addr_copy(addrs[i].addr, arg->bssids[i].bssid);
1683
1684         ptr += sizeof(*tlv);
1685         ptr += bssid_len;
1686
1687         tlv = ptr;
1688         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
1689         tlv->len = __cpu_to_le16(ie_len);
1690         memcpy(tlv->value, arg->ie, arg->ie_len);
1691
1692         ptr += sizeof(*tlv);
1693         ptr += ie_len;
1694
1695         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv start scan\n");
1696         return skb;
1697 }
1698
1699 static struct sk_buff *
1700 ath10k_wmi_tlv_op_gen_stop_scan(struct ath10k *ar,
1701                                 const struct wmi_stop_scan_arg *arg)
1702 {
1703         struct wmi_stop_scan_cmd *cmd;
1704         struct wmi_tlv *tlv;
1705         struct sk_buff *skb;
1706         u32 scan_id;
1707         u32 req_id;
1708
1709         if (arg->req_id > 0xFFF)
1710                 return ERR_PTR(-EINVAL);
1711         if (arg->req_type == WMI_SCAN_STOP_ONE && arg->u.scan_id > 0xFFF)
1712                 return ERR_PTR(-EINVAL);
1713
1714         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1715         if (!skb)
1716                 return ERR_PTR(-ENOMEM);
1717
1718         scan_id = arg->u.scan_id;
1719         scan_id |= WMI_HOST_SCAN_REQ_ID_PREFIX;
1720
1721         req_id = arg->req_id;
1722         req_id |= WMI_HOST_SCAN_REQUESTOR_ID_PREFIX;
1723
1724         tlv = (void *)skb->data;
1725         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STOP_SCAN_CMD);
1726         tlv->len = __cpu_to_le16(sizeof(*cmd));
1727         cmd = (void *)tlv->value;
1728         cmd->req_type = __cpu_to_le32(arg->req_type);
1729         cmd->vdev_id = __cpu_to_le32(arg->u.vdev_id);
1730         cmd->scan_id = __cpu_to_le32(scan_id);
1731         cmd->scan_req_id = __cpu_to_le32(req_id);
1732
1733         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv stop scan\n");
1734         return skb;
1735 }
1736
1737 static struct sk_buff *
1738 ath10k_wmi_tlv_op_gen_vdev_create(struct ath10k *ar,
1739                                   u32 vdev_id,
1740                                   enum wmi_vdev_type vdev_type,
1741                                   enum wmi_vdev_subtype vdev_subtype,
1742                                   const u8 mac_addr[ETH_ALEN])
1743 {
1744         struct wmi_vdev_create_cmd *cmd;
1745         struct wmi_tlv *tlv;
1746         struct sk_buff *skb;
1747
1748         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1749         if (!skb)
1750                 return ERR_PTR(-ENOMEM);
1751
1752         tlv = (void *)skb->data;
1753         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_CREATE_CMD);
1754         tlv->len = __cpu_to_le16(sizeof(*cmd));
1755         cmd = (void *)tlv->value;
1756         cmd->vdev_id = __cpu_to_le32(vdev_id);
1757         cmd->vdev_type = __cpu_to_le32(vdev_type);
1758         cmd->vdev_subtype = __cpu_to_le32(vdev_subtype);
1759         ether_addr_copy(cmd->vdev_macaddr.addr, mac_addr);
1760
1761         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev create\n");
1762         return skb;
1763 }
1764
1765 static struct sk_buff *
1766 ath10k_wmi_tlv_op_gen_vdev_delete(struct ath10k *ar, u32 vdev_id)
1767 {
1768         struct wmi_vdev_delete_cmd *cmd;
1769         struct wmi_tlv *tlv;
1770         struct sk_buff *skb;
1771
1772         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1773         if (!skb)
1774                 return ERR_PTR(-ENOMEM);
1775
1776         tlv = (void *)skb->data;
1777         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_DELETE_CMD);
1778         tlv->len = __cpu_to_le16(sizeof(*cmd));
1779         cmd = (void *)tlv->value;
1780         cmd->vdev_id = __cpu_to_le32(vdev_id);
1781
1782         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev delete\n");
1783         return skb;
1784 }
1785
1786 static struct sk_buff *
1787 ath10k_wmi_tlv_op_gen_vdev_start(struct ath10k *ar,
1788                                  const struct wmi_vdev_start_request_arg *arg,
1789                                  bool restart)
1790 {
1791         struct wmi_tlv_vdev_start_cmd *cmd;
1792         struct wmi_channel *ch;
1793         struct wmi_p2p_noa_descriptor *noa;
1794         struct wmi_tlv *tlv;
1795         struct sk_buff *skb;
1796         size_t len;
1797         void *ptr;
1798         u32 flags = 0;
1799
1800         if (WARN_ON(arg->hidden_ssid && !arg->ssid))
1801                 return ERR_PTR(-EINVAL);
1802         if (WARN_ON(arg->ssid_len > sizeof(cmd->ssid.ssid)))
1803                 return ERR_PTR(-EINVAL);
1804
1805         len = (sizeof(*tlv) + sizeof(*cmd)) +
1806               (sizeof(*tlv) + sizeof(*ch)) +
1807               (sizeof(*tlv) + 0);
1808         skb = ath10k_wmi_alloc_skb(ar, len);
1809         if (!skb)
1810                 return ERR_PTR(-ENOMEM);
1811
1812         if (arg->hidden_ssid)
1813                 flags |= WMI_VDEV_START_HIDDEN_SSID;
1814         if (arg->pmf_enabled)
1815                 flags |= WMI_VDEV_START_PMF_ENABLED;
1816
1817         ptr = (void *)skb->data;
1818
1819         tlv = ptr;
1820         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_START_REQUEST_CMD);
1821         tlv->len = __cpu_to_le16(sizeof(*cmd));
1822         cmd = (void *)tlv->value;
1823         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
1824         cmd->bcn_intval = __cpu_to_le32(arg->bcn_intval);
1825         cmd->dtim_period = __cpu_to_le32(arg->dtim_period);
1826         cmd->flags = __cpu_to_le32(flags);
1827         cmd->bcn_tx_rate = __cpu_to_le32(arg->bcn_tx_rate);
1828         cmd->bcn_tx_power = __cpu_to_le32(arg->bcn_tx_power);
1829         cmd->disable_hw_ack = __cpu_to_le32(arg->disable_hw_ack);
1830
1831         if (arg->ssid) {
1832                 cmd->ssid.ssid_len = __cpu_to_le32(arg->ssid_len);
1833                 memcpy(cmd->ssid.ssid, arg->ssid, arg->ssid_len);
1834         }
1835
1836         ptr += sizeof(*tlv);
1837         ptr += sizeof(*cmd);
1838
1839         tlv = ptr;
1840         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_CHANNEL);
1841         tlv->len = __cpu_to_le16(sizeof(*ch));
1842         ch = (void *)tlv->value;
1843         ath10k_wmi_put_wmi_channel(ch, &arg->channel);
1844
1845         ptr += sizeof(*tlv);
1846         ptr += sizeof(*ch);
1847
1848         tlv = ptr;
1849         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
1850         tlv->len = 0;
1851         noa = (void *)tlv->value;
1852
1853         /* Note: This is a nested TLV containing:
1854          * [wmi_tlv][wmi_p2p_noa_descriptor][wmi_tlv]..
1855          */
1856
1857         ptr += sizeof(*tlv);
1858         ptr += 0;
1859
1860         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev start\n");
1861         return skb;
1862 }
1863
1864 static struct sk_buff *
1865 ath10k_wmi_tlv_op_gen_vdev_stop(struct ath10k *ar, u32 vdev_id)
1866 {
1867         struct wmi_vdev_stop_cmd *cmd;
1868         struct wmi_tlv *tlv;
1869         struct sk_buff *skb;
1870
1871         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1872         if (!skb)
1873                 return ERR_PTR(-ENOMEM);
1874
1875         tlv = (void *)skb->data;
1876         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_STOP_CMD);
1877         tlv->len = __cpu_to_le16(sizeof(*cmd));
1878         cmd = (void *)tlv->value;
1879         cmd->vdev_id = __cpu_to_le32(vdev_id);
1880
1881         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev stop\n");
1882         return skb;
1883 }
1884
1885 static struct sk_buff *
1886 ath10k_wmi_tlv_op_gen_vdev_up(struct ath10k *ar, u32 vdev_id, u32 aid,
1887                               const u8 *bssid)
1888
1889 {
1890         struct wmi_vdev_up_cmd *cmd;
1891         struct wmi_tlv *tlv;
1892         struct sk_buff *skb;
1893
1894         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1895         if (!skb)
1896                 return ERR_PTR(-ENOMEM);
1897
1898         tlv = (void *)skb->data;
1899         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_UP_CMD);
1900         tlv->len = __cpu_to_le16(sizeof(*cmd));
1901         cmd = (void *)tlv->value;
1902         cmd->vdev_id = __cpu_to_le32(vdev_id);
1903         cmd->vdev_assoc_id = __cpu_to_le32(aid);
1904         ether_addr_copy(cmd->vdev_bssid.addr, bssid);
1905
1906         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev up\n");
1907         return skb;
1908 }
1909
1910 static struct sk_buff *
1911 ath10k_wmi_tlv_op_gen_vdev_down(struct ath10k *ar, u32 vdev_id)
1912 {
1913         struct wmi_vdev_down_cmd *cmd;
1914         struct wmi_tlv *tlv;
1915         struct sk_buff *skb;
1916
1917         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1918         if (!skb)
1919                 return ERR_PTR(-ENOMEM);
1920
1921         tlv = (void *)skb->data;
1922         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_DOWN_CMD);
1923         tlv->len = __cpu_to_le16(sizeof(*cmd));
1924         cmd = (void *)tlv->value;
1925         cmd->vdev_id = __cpu_to_le32(vdev_id);
1926
1927         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev down\n");
1928         return skb;
1929 }
1930
1931 static struct sk_buff *
1932 ath10k_wmi_tlv_op_gen_vdev_set_param(struct ath10k *ar, u32 vdev_id,
1933                                      u32 param_id, u32 param_value)
1934 {
1935         struct wmi_vdev_set_param_cmd *cmd;
1936         struct wmi_tlv *tlv;
1937         struct sk_buff *skb;
1938
1939         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1940         if (!skb)
1941                 return ERR_PTR(-ENOMEM);
1942
1943         tlv = (void *)skb->data;
1944         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SET_PARAM_CMD);
1945         tlv->len = __cpu_to_le16(sizeof(*cmd));
1946         cmd = (void *)tlv->value;
1947         cmd->vdev_id = __cpu_to_le32(vdev_id);
1948         cmd->param_id = __cpu_to_le32(param_id);
1949         cmd->param_value = __cpu_to_le32(param_value);
1950
1951         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev set param\n");
1952         return skb;
1953 }
1954
1955 static struct sk_buff *
1956 ath10k_wmi_tlv_op_gen_vdev_install_key(struct ath10k *ar,
1957                                        const struct wmi_vdev_install_key_arg *arg)
1958 {
1959         struct wmi_vdev_install_key_cmd *cmd;
1960         struct wmi_tlv *tlv;
1961         struct sk_buff *skb;
1962         size_t len;
1963         void *ptr;
1964
1965         if (arg->key_cipher == WMI_CIPHER_NONE && arg->key_data != NULL)
1966                 return ERR_PTR(-EINVAL);
1967         if (arg->key_cipher != WMI_CIPHER_NONE && arg->key_data == NULL)
1968                 return ERR_PTR(-EINVAL);
1969
1970         len = sizeof(*tlv) + sizeof(*cmd) +
1971               sizeof(*tlv) + roundup(arg->key_len, sizeof(__le32));
1972         skb = ath10k_wmi_alloc_skb(ar, len);
1973         if (!skb)
1974                 return ERR_PTR(-ENOMEM);
1975
1976         ptr = (void *)skb->data;
1977         tlv = ptr;
1978         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_INSTALL_KEY_CMD);
1979         tlv->len = __cpu_to_le16(sizeof(*cmd));
1980         cmd = (void *)tlv->value;
1981         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
1982         cmd->key_idx = __cpu_to_le32(arg->key_idx);
1983         cmd->key_flags = __cpu_to_le32(arg->key_flags);
1984         cmd->key_cipher = __cpu_to_le32(arg->key_cipher);
1985         cmd->key_len = __cpu_to_le32(arg->key_len);
1986         cmd->key_txmic_len = __cpu_to_le32(arg->key_txmic_len);
1987         cmd->key_rxmic_len = __cpu_to_le32(arg->key_rxmic_len);
1988
1989         if (arg->macaddr)
1990                 ether_addr_copy(cmd->peer_macaddr.addr, arg->macaddr);
1991
1992         ptr += sizeof(*tlv);
1993         ptr += sizeof(*cmd);
1994
1995         tlv = ptr;
1996         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
1997         tlv->len = __cpu_to_le16(roundup(arg->key_len, sizeof(__le32)));
1998         if (arg->key_data)
1999                 memcpy(tlv->value, arg->key_data, arg->key_len);
2000
2001         ptr += sizeof(*tlv);
2002         ptr += roundup(arg->key_len, sizeof(__le32));
2003
2004         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev install key\n");
2005         return skb;
2006 }
2007
2008 static void *ath10k_wmi_tlv_put_uapsd_ac(struct ath10k *ar, void *ptr,
2009                                          const struct wmi_sta_uapsd_auto_trig_arg *arg)
2010 {
2011         struct wmi_sta_uapsd_auto_trig_param *ac;
2012         struct wmi_tlv *tlv;
2013
2014         tlv = ptr;
2015         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_UAPSD_AUTO_TRIG_PARAM);
2016         tlv->len = __cpu_to_le16(sizeof(*ac));
2017         ac = (void *)tlv->value;
2018
2019         ac->wmm_ac = __cpu_to_le32(arg->wmm_ac);
2020         ac->user_priority = __cpu_to_le32(arg->user_priority);
2021         ac->service_interval = __cpu_to_le32(arg->service_interval);
2022         ac->suspend_interval = __cpu_to_le32(arg->suspend_interval);
2023         ac->delay_interval = __cpu_to_le32(arg->delay_interval);
2024
2025         ath10k_dbg(ar, ATH10K_DBG_WMI,
2026                    "wmi tlv vdev sta uapsd auto trigger ac %d prio %d svc int %d susp int %d delay int %d\n",
2027                    ac->wmm_ac, ac->user_priority, ac->service_interval,
2028                    ac->suspend_interval, ac->delay_interval);
2029
2030         return ptr + sizeof(*tlv) + sizeof(*ac);
2031 }
2032
2033 static struct sk_buff *
2034 ath10k_wmi_tlv_op_gen_vdev_sta_uapsd(struct ath10k *ar, u32 vdev_id,
2035                                      const u8 peer_addr[ETH_ALEN],
2036                                      const struct wmi_sta_uapsd_auto_trig_arg *args,
2037                                      u32 num_ac)
2038 {
2039         struct wmi_sta_uapsd_auto_trig_cmd_fixed_param *cmd;
2040         struct wmi_sta_uapsd_auto_trig_param *ac;
2041         struct wmi_tlv *tlv;
2042         struct sk_buff *skb;
2043         size_t len;
2044         size_t ac_tlv_len;
2045         void *ptr;
2046         int i;
2047
2048         ac_tlv_len = num_ac * (sizeof(*tlv) + sizeof(*ac));
2049         len = sizeof(*tlv) + sizeof(*cmd) +
2050               sizeof(*tlv) + ac_tlv_len;
2051         skb = ath10k_wmi_alloc_skb(ar, len);
2052         if (!skb)
2053                 return ERR_PTR(-ENOMEM);
2054
2055         ptr = (void *)skb->data;
2056         tlv = ptr;
2057         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_UAPSD_AUTO_TRIG_CMD);
2058         tlv->len = __cpu_to_le16(sizeof(*cmd));
2059         cmd = (void *)tlv->value;
2060         cmd->vdev_id = __cpu_to_le32(vdev_id);
2061         cmd->num_ac = __cpu_to_le32(num_ac);
2062         ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2063
2064         ptr += sizeof(*tlv);
2065         ptr += sizeof(*cmd);
2066
2067         tlv = ptr;
2068         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
2069         tlv->len = __cpu_to_le16(ac_tlv_len);
2070         ac = (void *)tlv->value;
2071
2072         ptr += sizeof(*tlv);
2073         for (i = 0; i < num_ac; i++)
2074                 ptr = ath10k_wmi_tlv_put_uapsd_ac(ar, ptr, &args[i]);
2075
2076         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev sta uapsd auto trigger\n");
2077         return skb;
2078 }
2079
2080 static void *ath10k_wmi_tlv_put_wmm(void *ptr,
2081                                     const struct wmi_wmm_params_arg *arg)
2082 {
2083         struct wmi_wmm_params *wmm;
2084         struct wmi_tlv *tlv;
2085
2086         tlv = ptr;
2087         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WMM_PARAMS);
2088         tlv->len = __cpu_to_le16(sizeof(*wmm));
2089         wmm = (void *)tlv->value;
2090         ath10k_wmi_set_wmm_param(wmm, arg);
2091
2092         return ptr + sizeof(*tlv) + sizeof(*wmm);
2093 }
2094
2095 static struct sk_buff *
2096 ath10k_wmi_tlv_op_gen_vdev_wmm_conf(struct ath10k *ar, u32 vdev_id,
2097                                     const struct wmi_wmm_params_all_arg *arg)
2098 {
2099         struct wmi_tlv_vdev_set_wmm_cmd *cmd;
2100         struct wmi_tlv *tlv;
2101         struct sk_buff *skb;
2102         size_t len;
2103         void *ptr;
2104
2105         len = sizeof(*tlv) + sizeof(*cmd);
2106         skb = ath10k_wmi_alloc_skb(ar, len);
2107         if (!skb)
2108                 return ERR_PTR(-ENOMEM);
2109
2110         ptr = (void *)skb->data;
2111         tlv = ptr;
2112         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SET_WMM_PARAMS_CMD);
2113         tlv->len = __cpu_to_le16(sizeof(*cmd));
2114         cmd = (void *)tlv->value;
2115         cmd->vdev_id = __cpu_to_le32(vdev_id);
2116
2117         ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[0].params, &arg->ac_be);
2118         ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[1].params, &arg->ac_bk);
2119         ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[2].params, &arg->ac_vi);
2120         ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[3].params, &arg->ac_vo);
2121
2122         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev wmm conf\n");
2123         return skb;
2124 }
2125
2126 static struct sk_buff *
2127 ath10k_wmi_tlv_op_gen_sta_keepalive(struct ath10k *ar,
2128                                     const struct wmi_sta_keepalive_arg *arg)
2129 {
2130         struct wmi_tlv_sta_keepalive_cmd *cmd;
2131         struct wmi_sta_keepalive_arp_resp *arp;
2132         struct sk_buff *skb;
2133         struct wmi_tlv *tlv;
2134         void *ptr;
2135         size_t len;
2136
2137         len = sizeof(*tlv) + sizeof(*cmd) +
2138               sizeof(*tlv) + sizeof(*arp);
2139         skb = ath10k_wmi_alloc_skb(ar, len);
2140         if (!skb)
2141                 return ERR_PTR(-ENOMEM);
2142
2143         ptr = (void *)skb->data;
2144         tlv = ptr;
2145         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_KEEPALIVE_CMD);
2146         tlv->len = __cpu_to_le16(sizeof(*cmd));
2147         cmd = (void *)tlv->value;
2148         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
2149         cmd->enabled = __cpu_to_le32(arg->enabled);
2150         cmd->method = __cpu_to_le32(arg->method);
2151         cmd->interval = __cpu_to_le32(arg->interval);
2152
2153         ptr += sizeof(*tlv);
2154         ptr += sizeof(*cmd);
2155
2156         tlv = ptr;
2157         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_KEEPALVE_ARP_RESPONSE);
2158         tlv->len = __cpu_to_le16(sizeof(*arp));
2159         arp = (void *)tlv->value;
2160
2161         arp->src_ip4_addr = arg->src_ip4_addr;
2162         arp->dest_ip4_addr = arg->dest_ip4_addr;
2163         ether_addr_copy(arp->dest_mac_addr.addr, arg->dest_mac_addr);
2164
2165         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv sta keepalive vdev %d enabled %d method %d interval %d\n",
2166                    arg->vdev_id, arg->enabled, arg->method, arg->interval);
2167         return skb;
2168 }
2169
2170 static struct sk_buff *
2171 ath10k_wmi_tlv_op_gen_peer_create(struct ath10k *ar, u32 vdev_id,
2172                                   const u8 peer_addr[ETH_ALEN],
2173                                   enum wmi_peer_type peer_type)
2174 {
2175         struct wmi_tlv_peer_create_cmd *cmd;
2176         struct wmi_tlv *tlv;
2177         struct sk_buff *skb;
2178
2179         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2180         if (!skb)
2181                 return ERR_PTR(-ENOMEM);
2182
2183         tlv = (void *)skb->data;
2184         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_CREATE_CMD);
2185         tlv->len = __cpu_to_le16(sizeof(*cmd));
2186         cmd = (void *)tlv->value;
2187         cmd->vdev_id = __cpu_to_le32(vdev_id);
2188         cmd->peer_type = __cpu_to_le32(peer_type);
2189         ether_addr_copy(cmd->peer_addr.addr, peer_addr);
2190
2191         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer create\n");
2192         return skb;
2193 }
2194
2195 static struct sk_buff *
2196 ath10k_wmi_tlv_op_gen_peer_delete(struct ath10k *ar, u32 vdev_id,
2197                                   const u8 peer_addr[ETH_ALEN])
2198 {
2199         struct wmi_peer_delete_cmd *cmd;
2200         struct wmi_tlv *tlv;
2201         struct sk_buff *skb;
2202
2203         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2204         if (!skb)
2205                 return ERR_PTR(-ENOMEM);
2206
2207         tlv = (void *)skb->data;
2208         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_DELETE_CMD);
2209         tlv->len = __cpu_to_le16(sizeof(*cmd));
2210         cmd = (void *)tlv->value;
2211         cmd->vdev_id = __cpu_to_le32(vdev_id);
2212         ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2213
2214         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer delete\n");
2215         return skb;
2216 }
2217
2218 static struct sk_buff *
2219 ath10k_wmi_tlv_op_gen_peer_flush(struct ath10k *ar, u32 vdev_id,
2220                                  const u8 peer_addr[ETH_ALEN], u32 tid_bitmap)
2221 {
2222         struct wmi_peer_flush_tids_cmd *cmd;
2223         struct wmi_tlv *tlv;
2224         struct sk_buff *skb;
2225
2226         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2227         if (!skb)
2228                 return ERR_PTR(-ENOMEM);
2229
2230         tlv = (void *)skb->data;
2231         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_FLUSH_TIDS_CMD);
2232         tlv->len = __cpu_to_le16(sizeof(*cmd));
2233         cmd = (void *)tlv->value;
2234         cmd->vdev_id = __cpu_to_le32(vdev_id);
2235         cmd->peer_tid_bitmap = __cpu_to_le32(tid_bitmap);
2236         ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2237
2238         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer flush\n");
2239         return skb;
2240 }
2241
2242 static struct sk_buff *
2243 ath10k_wmi_tlv_op_gen_peer_set_param(struct ath10k *ar, u32 vdev_id,
2244                                      const u8 *peer_addr,
2245                                      enum wmi_peer_param param_id,
2246                                      u32 param_value)
2247 {
2248         struct wmi_peer_set_param_cmd *cmd;
2249         struct wmi_tlv *tlv;
2250         struct sk_buff *skb;
2251
2252         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2253         if (!skb)
2254                 return ERR_PTR(-ENOMEM);
2255
2256         tlv = (void *)skb->data;
2257         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_SET_PARAM_CMD);
2258         tlv->len = __cpu_to_le16(sizeof(*cmd));
2259         cmd = (void *)tlv->value;
2260         cmd->vdev_id = __cpu_to_le32(vdev_id);
2261         cmd->param_id = __cpu_to_le32(param_id);
2262         cmd->param_value = __cpu_to_le32(param_value);
2263         ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2264
2265         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer set param\n");
2266         return skb;
2267 }
2268
2269 static struct sk_buff *
2270 ath10k_wmi_tlv_op_gen_peer_assoc(struct ath10k *ar,
2271                                  const struct wmi_peer_assoc_complete_arg *arg)
2272 {
2273         struct wmi_tlv_peer_assoc_cmd *cmd;
2274         struct wmi_vht_rate_set *vht_rate;
2275         struct wmi_tlv *tlv;
2276         struct sk_buff *skb;
2277         size_t len, legacy_rate_len, ht_rate_len;
2278         void *ptr;
2279
2280         if (arg->peer_mpdu_density > 16)
2281                 return ERR_PTR(-EINVAL);
2282         if (arg->peer_legacy_rates.num_rates > MAX_SUPPORTED_RATES)
2283                 return ERR_PTR(-EINVAL);
2284         if (arg->peer_ht_rates.num_rates > MAX_SUPPORTED_RATES)
2285                 return ERR_PTR(-EINVAL);
2286
2287         legacy_rate_len = roundup(arg->peer_legacy_rates.num_rates,
2288                                   sizeof(__le32));
2289         ht_rate_len = roundup(arg->peer_ht_rates.num_rates, sizeof(__le32));
2290         len = (sizeof(*tlv) + sizeof(*cmd)) +
2291               (sizeof(*tlv) + legacy_rate_len) +
2292               (sizeof(*tlv) + ht_rate_len) +
2293               (sizeof(*tlv) + sizeof(*vht_rate));
2294         skb = ath10k_wmi_alloc_skb(ar, len);
2295         if (!skb)
2296                 return ERR_PTR(-ENOMEM);
2297
2298         ptr = (void *)skb->data;
2299         tlv = ptr;
2300         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_ASSOC_COMPLETE_CMD);
2301         tlv->len = __cpu_to_le16(sizeof(*cmd));
2302         cmd = (void *)tlv->value;
2303
2304         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
2305         cmd->new_assoc = __cpu_to_le32(arg->peer_reassoc ? 0 : 1);
2306         cmd->assoc_id = __cpu_to_le32(arg->peer_aid);
2307         cmd->flags = __cpu_to_le32(arg->peer_flags);
2308         cmd->caps = __cpu_to_le32(arg->peer_caps);
2309         cmd->listen_intval = __cpu_to_le32(arg->peer_listen_intval);
2310         cmd->ht_caps = __cpu_to_le32(arg->peer_ht_caps);
2311         cmd->max_mpdu = __cpu_to_le32(arg->peer_max_mpdu);
2312         cmd->mpdu_density = __cpu_to_le32(arg->peer_mpdu_density);
2313         cmd->rate_caps = __cpu_to_le32(arg->peer_rate_caps);
2314         cmd->nss = __cpu_to_le32(arg->peer_num_spatial_streams);
2315         cmd->vht_caps = __cpu_to_le32(arg->peer_vht_caps);
2316         cmd->phy_mode = __cpu_to_le32(arg->peer_phymode);
2317         cmd->num_legacy_rates = __cpu_to_le32(arg->peer_legacy_rates.num_rates);
2318         cmd->num_ht_rates = __cpu_to_le32(arg->peer_ht_rates.num_rates);
2319         ether_addr_copy(cmd->mac_addr.addr, arg->addr);
2320
2321         ptr += sizeof(*tlv);
2322         ptr += sizeof(*cmd);
2323
2324         tlv = ptr;
2325         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2326         tlv->len = __cpu_to_le16(legacy_rate_len);
2327         memcpy(tlv->value, arg->peer_legacy_rates.rates,
2328                arg->peer_legacy_rates.num_rates);
2329
2330         ptr += sizeof(*tlv);
2331         ptr += legacy_rate_len;
2332
2333         tlv = ptr;
2334         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2335         tlv->len = __cpu_to_le16(ht_rate_len);
2336         memcpy(tlv->value, arg->peer_ht_rates.rates,
2337                arg->peer_ht_rates.num_rates);
2338
2339         ptr += sizeof(*tlv);
2340         ptr += ht_rate_len;
2341
2342         tlv = ptr;
2343         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VHT_RATE_SET);
2344         tlv->len = __cpu_to_le16(sizeof(*vht_rate));
2345         vht_rate = (void *)tlv->value;
2346
2347         vht_rate->rx_max_rate = __cpu_to_le32(arg->peer_vht_rates.rx_max_rate);
2348         vht_rate->rx_mcs_set = __cpu_to_le32(arg->peer_vht_rates.rx_mcs_set);
2349         vht_rate->tx_max_rate = __cpu_to_le32(arg->peer_vht_rates.tx_max_rate);
2350         vht_rate->tx_mcs_set = __cpu_to_le32(arg->peer_vht_rates.tx_mcs_set);
2351
2352         ptr += sizeof(*tlv);
2353         ptr += sizeof(*vht_rate);
2354
2355         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer assoc\n");
2356         return skb;
2357 }
2358
2359 static struct sk_buff *
2360 ath10k_wmi_tlv_op_gen_set_psmode(struct ath10k *ar, u32 vdev_id,
2361                                  enum wmi_sta_ps_mode psmode)
2362 {
2363         struct wmi_sta_powersave_mode_cmd *cmd;
2364         struct wmi_tlv *tlv;
2365         struct sk_buff *skb;
2366
2367         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2368         if (!skb)
2369                 return ERR_PTR(-ENOMEM);
2370
2371         tlv = (void *)skb->data;
2372         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_POWERSAVE_MODE_CMD);
2373         tlv->len = __cpu_to_le16(sizeof(*cmd));
2374         cmd = (void *)tlv->value;
2375         cmd->vdev_id = __cpu_to_le32(vdev_id);
2376         cmd->sta_ps_mode = __cpu_to_le32(psmode);
2377
2378         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv set psmode\n");
2379         return skb;
2380 }
2381
2382 static struct sk_buff *
2383 ath10k_wmi_tlv_op_gen_set_sta_ps(struct ath10k *ar, u32 vdev_id,
2384                                  enum wmi_sta_powersave_param param_id,
2385                                  u32 param_value)
2386 {
2387         struct wmi_sta_powersave_param_cmd *cmd;
2388         struct wmi_tlv *tlv;
2389         struct sk_buff *skb;
2390
2391         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2392         if (!skb)
2393                 return ERR_PTR(-ENOMEM);
2394
2395         tlv = (void *)skb->data;
2396         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_POWERSAVE_PARAM_CMD);
2397         tlv->len = __cpu_to_le16(sizeof(*cmd));
2398         cmd = (void *)tlv->value;
2399         cmd->vdev_id = __cpu_to_le32(vdev_id);
2400         cmd->param_id = __cpu_to_le32(param_id);
2401         cmd->param_value = __cpu_to_le32(param_value);
2402
2403         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv set sta ps\n");
2404         return skb;
2405 }
2406
2407 static struct sk_buff *
2408 ath10k_wmi_tlv_op_gen_set_ap_ps(struct ath10k *ar, u32 vdev_id, const u8 *mac,
2409                                 enum wmi_ap_ps_peer_param param_id, u32 value)
2410 {
2411         struct wmi_ap_ps_peer_cmd *cmd;
2412         struct wmi_tlv *tlv;
2413         struct sk_buff *skb;
2414
2415         if (!mac)
2416                 return ERR_PTR(-EINVAL);
2417
2418         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2419         if (!skb)
2420                 return ERR_PTR(-ENOMEM);
2421
2422         tlv = (void *)skb->data;
2423         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_AP_PS_PEER_CMD);
2424         tlv->len = __cpu_to_le16(sizeof(*cmd));
2425         cmd = (void *)tlv->value;
2426         cmd->vdev_id = __cpu_to_le32(vdev_id);
2427         cmd->param_id = __cpu_to_le32(param_id);
2428         cmd->param_value = __cpu_to_le32(value);
2429         ether_addr_copy(cmd->peer_macaddr.addr, mac);
2430
2431         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv ap ps param\n");
2432         return skb;
2433 }
2434
2435 static struct sk_buff *
2436 ath10k_wmi_tlv_op_gen_scan_chan_list(struct ath10k *ar,
2437                                      const struct wmi_scan_chan_list_arg *arg)
2438 {
2439         struct wmi_tlv_scan_chan_list_cmd *cmd;
2440         struct wmi_channel *ci;
2441         struct wmi_channel_arg *ch;
2442         struct wmi_tlv *tlv;
2443         struct sk_buff *skb;
2444         size_t chans_len, len;
2445         int i;
2446         void *ptr, *chans;
2447
2448         chans_len = arg->n_channels * (sizeof(*tlv) + sizeof(*ci));
2449         len = (sizeof(*tlv) + sizeof(*cmd)) +
2450               (sizeof(*tlv) + chans_len);
2451
2452         skb = ath10k_wmi_alloc_skb(ar, len);
2453         if (!skb)
2454                 return ERR_PTR(-ENOMEM);
2455
2456         ptr = (void *)skb->data;
2457         tlv = ptr;
2458         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_SCAN_CHAN_LIST_CMD);
2459         tlv->len = __cpu_to_le16(sizeof(*cmd));
2460         cmd = (void *)tlv->value;
2461         cmd->num_scan_chans = __cpu_to_le32(arg->n_channels);
2462
2463         ptr += sizeof(*tlv);
2464         ptr += sizeof(*cmd);
2465
2466         tlv = ptr;
2467         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
2468         tlv->len = __cpu_to_le16(chans_len);
2469         chans = (void *)tlv->value;
2470
2471         for (i = 0; i < arg->n_channels; i++) {
2472                 ch = &arg->channels[i];
2473
2474                 tlv = chans;
2475                 tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_CHANNEL);
2476                 tlv->len = __cpu_to_le16(sizeof(*ci));
2477                 ci = (void *)tlv->value;
2478
2479                 ath10k_wmi_put_wmi_channel(ci, ch);
2480
2481                 chans += sizeof(*tlv);
2482                 chans += sizeof(*ci);
2483         }
2484
2485         ptr += sizeof(*tlv);
2486         ptr += chans_len;
2487
2488         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv scan chan list\n");
2489         return skb;
2490 }
2491
2492 static struct sk_buff *
2493 ath10k_wmi_tlv_op_gen_scan_prob_req_oui(struct ath10k *ar, u32 prob_req_oui)
2494 {
2495         struct wmi_scan_prob_req_oui_cmd *cmd;
2496         struct wmi_tlv *tlv;
2497         struct sk_buff *skb;
2498
2499         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2500         if (!skb)
2501                 return ERR_PTR(-ENOMEM);
2502
2503         tlv = (void *)skb->data;
2504         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_SCAN_PROB_REQ_OUI_CMD);
2505         tlv->len = __cpu_to_le16(sizeof(*cmd));
2506         cmd = (void *)tlv->value;
2507         cmd->prob_req_oui = __cpu_to_le32(prob_req_oui);
2508
2509         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv scan prob req oui\n");
2510         return skb;
2511 }
2512
2513 static struct sk_buff *
2514 ath10k_wmi_tlv_op_gen_beacon_dma(struct ath10k *ar, u32 vdev_id,
2515                                  const void *bcn, size_t bcn_len,
2516                                  u32 bcn_paddr, bool dtim_zero,
2517                                  bool deliver_cab)
2518
2519 {
2520         struct wmi_bcn_tx_ref_cmd *cmd;
2521         struct wmi_tlv *tlv;
2522         struct sk_buff *skb;
2523         struct ieee80211_hdr *hdr;
2524         u16 fc;
2525
2526         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2527         if (!skb)
2528                 return ERR_PTR(-ENOMEM);
2529
2530         hdr = (struct ieee80211_hdr *)bcn;
2531         fc = le16_to_cpu(hdr->frame_control);
2532
2533         tlv = (void *)skb->data;
2534         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_SEND_FROM_HOST_CMD);
2535         tlv->len = __cpu_to_le16(sizeof(*cmd));
2536         cmd = (void *)tlv->value;
2537         cmd->vdev_id = __cpu_to_le32(vdev_id);
2538         cmd->data_len = __cpu_to_le32(bcn_len);
2539         cmd->data_ptr = __cpu_to_le32(bcn_paddr);
2540         cmd->msdu_id = 0;
2541         cmd->frame_control = __cpu_to_le32(fc);
2542         cmd->flags = 0;
2543
2544         if (dtim_zero)
2545                 cmd->flags |= __cpu_to_le32(WMI_BCN_TX_REF_FLAG_DTIM_ZERO);
2546
2547         if (deliver_cab)
2548                 cmd->flags |= __cpu_to_le32(WMI_BCN_TX_REF_FLAG_DELIVER_CAB);
2549
2550         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv beacon dma\n");
2551         return skb;
2552 }
2553
2554 static struct sk_buff *
2555 ath10k_wmi_tlv_op_gen_pdev_set_wmm(struct ath10k *ar,
2556                                    const struct wmi_wmm_params_all_arg *arg)
2557 {
2558         struct wmi_tlv_pdev_set_wmm_cmd *cmd;
2559         struct wmi_wmm_params *wmm;
2560         struct wmi_tlv *tlv;
2561         struct sk_buff *skb;
2562         size_t len;
2563         void *ptr;
2564
2565         len = (sizeof(*tlv) + sizeof(*cmd)) +
2566               (4 * (sizeof(*tlv) + sizeof(*wmm)));
2567         skb = ath10k_wmi_alloc_skb(ar, len);
2568         if (!skb)
2569                 return ERR_PTR(-ENOMEM);
2570
2571         ptr = (void *)skb->data;
2572
2573         tlv = ptr;
2574         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_WMM_PARAMS_CMD);
2575         tlv->len = __cpu_to_le16(sizeof(*cmd));
2576         cmd = (void *)tlv->value;
2577
2578         /* nothing to set here */
2579
2580         ptr += sizeof(*tlv);
2581         ptr += sizeof(*cmd);
2582
2583         ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_be);
2584         ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_bk);
2585         ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_vi);
2586         ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_vo);
2587
2588         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev set wmm\n");
2589         return skb;
2590 }
2591
2592 static struct sk_buff *
2593 ath10k_wmi_tlv_op_gen_request_stats(struct ath10k *ar, u32 stats_mask)
2594 {
2595         struct wmi_request_stats_cmd *cmd;
2596         struct wmi_tlv *tlv;
2597         struct sk_buff *skb;
2598
2599         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2600         if (!skb)
2601                 return ERR_PTR(-ENOMEM);
2602
2603         tlv = (void *)skb->data;
2604         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_REQUEST_STATS_CMD);
2605         tlv->len = __cpu_to_le16(sizeof(*cmd));
2606         cmd = (void *)tlv->value;
2607         cmd->stats_id = __cpu_to_le32(stats_mask);
2608
2609         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv request stats\n");
2610         return skb;
2611 }
2612
2613 static struct sk_buff *
2614 ath10k_wmi_tlv_op_gen_mgmt_tx_send(struct ath10k *ar, struct sk_buff *msdu,
2615                                    dma_addr_t paddr)
2616 {
2617         struct ath10k_skb_cb *cb = ATH10K_SKB_CB(msdu);
2618         struct wmi_tlv_mgmt_tx_cmd *cmd;
2619         struct ieee80211_hdr *hdr;
2620         struct ath10k_vif *arvif;
2621         u32 buf_len = msdu->len;
2622         struct wmi_tlv *tlv;
2623         struct sk_buff *skb;
2624         u32 vdev_id;
2625         void *ptr;
2626         int len;
2627
2628         if (!cb->vif)
2629                 return ERR_PTR(-EINVAL);
2630
2631         hdr = (struct ieee80211_hdr *)msdu->data;
2632         arvif = (void *)cb->vif->drv_priv;
2633         vdev_id = arvif->vdev_id;
2634
2635         if (WARN_ON_ONCE(!ieee80211_is_mgmt(hdr->frame_control)))
2636                 return ERR_PTR(-EINVAL);
2637
2638         len = sizeof(*cmd) + 2 * sizeof(*tlv);
2639
2640         if ((ieee80211_is_action(hdr->frame_control) ||
2641              ieee80211_is_deauth(hdr->frame_control) ||
2642              ieee80211_is_disassoc(hdr->frame_control)) &&
2643              ieee80211_has_protected(hdr->frame_control)) {
2644                 len += IEEE80211_CCMP_MIC_LEN;
2645                 buf_len += IEEE80211_CCMP_MIC_LEN;
2646         }
2647
2648         buf_len = min_t(u32, buf_len, WMI_TLV_MGMT_TX_FRAME_MAX_LEN);
2649         buf_len = round_up(buf_len, 4);
2650
2651         len += buf_len;
2652         len = round_up(len, 4);
2653         skb = ath10k_wmi_alloc_skb(ar, len);
2654         if (!skb)
2655                 return ERR_PTR(-ENOMEM);
2656
2657         ptr = (void *)skb->data;
2658         tlv = ptr;
2659         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_MGMT_TX_CMD);
2660         tlv->len = __cpu_to_le16(sizeof(*cmd));
2661         cmd = (void *)tlv->value;
2662         cmd->vdev_id = __cpu_to_le32(vdev_id);
2663         cmd->desc_id = 0;
2664         cmd->chanfreq = 0;
2665         cmd->buf_len = __cpu_to_le32(buf_len);
2666         cmd->frame_len = __cpu_to_le32(msdu->len);
2667         cmd->paddr = __cpu_to_le64(paddr);
2668
2669         ptr += sizeof(*tlv);
2670         ptr += sizeof(*cmd);
2671
2672         tlv = ptr;
2673         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2674         tlv->len = __cpu_to_le16(buf_len);
2675
2676         ptr += sizeof(*tlv);
2677         memcpy(ptr, msdu->data, buf_len);
2678
2679         return skb;
2680 }
2681
2682 static struct sk_buff *
2683 ath10k_wmi_tlv_op_gen_force_fw_hang(struct ath10k *ar,
2684                                     enum wmi_force_fw_hang_type type,
2685                                     u32 delay_ms)
2686 {
2687         struct wmi_force_fw_hang_cmd *cmd;
2688         struct wmi_tlv *tlv;
2689         struct sk_buff *skb;
2690
2691         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2692         if (!skb)
2693                 return ERR_PTR(-ENOMEM);
2694
2695         tlv = (void *)skb->data;
2696         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_FORCE_FW_HANG_CMD);
2697         tlv->len = __cpu_to_le16(sizeof(*cmd));
2698         cmd = (void *)tlv->value;
2699         cmd->type = __cpu_to_le32(type);
2700         cmd->delay_ms = __cpu_to_le32(delay_ms);
2701
2702         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv force fw hang\n");
2703         return skb;
2704 }
2705
2706 static struct sk_buff *
2707 ath10k_wmi_tlv_op_gen_dbglog_cfg(struct ath10k *ar, u64 module_enable,
2708                                  u32 log_level) {
2709         struct wmi_tlv_dbglog_cmd *cmd;
2710         struct wmi_tlv *tlv;
2711         struct sk_buff *skb;
2712         size_t len, bmap_len;
2713         u32 value;
2714         void *ptr;
2715
2716         if (module_enable) {
2717                 value = WMI_TLV_DBGLOG_LOG_LEVEL_VALUE(
2718                                 module_enable,
2719                                 WMI_TLV_DBGLOG_LOG_LEVEL_VERBOSE);
2720         } else {
2721                 value = WMI_TLV_DBGLOG_LOG_LEVEL_VALUE(
2722                                 WMI_TLV_DBGLOG_ALL_MODULES,
2723                                 WMI_TLV_DBGLOG_LOG_LEVEL_WARN);
2724         }
2725
2726         bmap_len = 0;
2727         len = sizeof(*tlv) + sizeof(*cmd) + sizeof(*tlv) + bmap_len;
2728         skb = ath10k_wmi_alloc_skb(ar, len);
2729         if (!skb)
2730                 return ERR_PTR(-ENOMEM);
2731
2732         ptr = (void *)skb->data;
2733
2734         tlv = ptr;
2735         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_DEBUG_LOG_CONFIG_CMD);
2736         tlv->len = __cpu_to_le16(sizeof(*cmd));
2737         cmd = (void *)tlv->value;
2738         cmd->param = __cpu_to_le32(WMI_TLV_DBGLOG_PARAM_LOG_LEVEL);
2739         cmd->value = __cpu_to_le32(value);
2740
2741         ptr += sizeof(*tlv);
2742         ptr += sizeof(*cmd);
2743
2744         tlv = ptr;
2745         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
2746         tlv->len = __cpu_to_le16(bmap_len);
2747
2748         /* nothing to do here */
2749
2750         ptr += sizeof(*tlv);
2751         ptr += sizeof(bmap_len);
2752
2753         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv dbglog value 0x%08x\n", value);
2754         return skb;
2755 }
2756
2757 static struct sk_buff *
2758 ath10k_wmi_tlv_op_gen_pktlog_enable(struct ath10k *ar, u32 filter)
2759 {
2760         struct wmi_tlv_pktlog_enable *cmd;
2761         struct wmi_tlv *tlv;
2762         struct sk_buff *skb;
2763         void *ptr;
2764         size_t len;
2765
2766         len = sizeof(*tlv) + sizeof(*cmd);
2767         skb = ath10k_wmi_alloc_skb(ar, len);
2768         if (!skb)
2769                 return ERR_PTR(-ENOMEM);
2770
2771         ptr = (void *)skb->data;
2772         tlv = ptr;
2773         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_PKTLOG_ENABLE_CMD);
2774         tlv->len = __cpu_to_le16(sizeof(*cmd));
2775         cmd = (void *)tlv->value;
2776         cmd->filter = __cpu_to_le32(filter);
2777
2778         ptr += sizeof(*tlv);
2779         ptr += sizeof(*cmd);
2780
2781         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pktlog enable filter 0x%08x\n",
2782                    filter);
2783         return skb;
2784 }
2785
2786 static struct sk_buff *
2787 ath10k_wmi_tlv_op_gen_pdev_get_temperature(struct ath10k *ar)
2788 {
2789         struct wmi_tlv_pdev_get_temp_cmd *cmd;
2790         struct wmi_tlv *tlv;
2791         struct sk_buff *skb;
2792
2793         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2794         if (!skb)
2795                 return ERR_PTR(-ENOMEM);
2796
2797         tlv = (void *)skb->data;
2798         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_GET_TEMPERATURE_CMD);
2799         tlv->len = __cpu_to_le16(sizeof(*cmd));
2800         cmd = (void *)tlv->value;
2801         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi pdev get temperature tlv\n");
2802         return skb;
2803 }
2804
2805 static struct sk_buff *
2806 ath10k_wmi_tlv_op_gen_pktlog_disable(struct ath10k *ar)
2807 {
2808         struct wmi_tlv_pktlog_disable *cmd;
2809         struct wmi_tlv *tlv;
2810         struct sk_buff *skb;
2811         void *ptr;
2812         size_t len;
2813
2814         len = sizeof(*tlv) + sizeof(*cmd);
2815         skb = ath10k_wmi_alloc_skb(ar, len);
2816         if (!skb)
2817                 return ERR_PTR(-ENOMEM);
2818
2819         ptr = (void *)skb->data;
2820         tlv = ptr;
2821         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_PKTLOG_DISABLE_CMD);
2822         tlv->len = __cpu_to_le16(sizeof(*cmd));
2823         cmd = (void *)tlv->value;
2824
2825         ptr += sizeof(*tlv);
2826         ptr += sizeof(*cmd);
2827
2828         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pktlog disable\n");
2829         return skb;
2830 }
2831
2832 static struct sk_buff *
2833 ath10k_wmi_tlv_op_gen_bcn_tmpl(struct ath10k *ar, u32 vdev_id,
2834                                u32 tim_ie_offset, struct sk_buff *bcn,
2835                                u32 prb_caps, u32 prb_erp, void *prb_ies,
2836                                size_t prb_ies_len)
2837 {
2838         struct wmi_tlv_bcn_tmpl_cmd *cmd;
2839         struct wmi_tlv_bcn_prb_info *info;
2840         struct wmi_tlv *tlv;
2841         struct sk_buff *skb;
2842         void *ptr;
2843         size_t len;
2844
2845         if (WARN_ON(prb_ies_len > 0 && !prb_ies))
2846                 return ERR_PTR(-EINVAL);
2847
2848         len = sizeof(*tlv) + sizeof(*cmd) +
2849               sizeof(*tlv) + sizeof(*info) + prb_ies_len +
2850               sizeof(*tlv) + roundup(bcn->len, 4);
2851         skb = ath10k_wmi_alloc_skb(ar, len);
2852         if (!skb)
2853                 return ERR_PTR(-ENOMEM);
2854
2855         ptr = (void *)skb->data;
2856         tlv = ptr;
2857         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_TMPL_CMD);
2858         tlv->len = __cpu_to_le16(sizeof(*cmd));
2859         cmd = (void *)tlv->value;
2860         cmd->vdev_id = __cpu_to_le32(vdev_id);
2861         cmd->tim_ie_offset = __cpu_to_le32(tim_ie_offset);
2862         cmd->buf_len = __cpu_to_le32(bcn->len);
2863
2864         ptr += sizeof(*tlv);
2865         ptr += sizeof(*cmd);
2866
2867         /* FIXME: prb_ies_len should be probably aligned to 4byte boundary but
2868          * then it is then impossible to pass original ie len.
2869          * This chunk is not used yet so if setting probe resp template yields
2870          * problems with beaconing or crashes firmware look here.
2871          */
2872         tlv = ptr;
2873         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_PRB_INFO);
2874         tlv->len = __cpu_to_le16(sizeof(*info) + prb_ies_len);
2875         info = (void *)tlv->value;
2876         info->caps = __cpu_to_le32(prb_caps);
2877         info->erp = __cpu_to_le32(prb_erp);
2878         memcpy(info->ies, prb_ies, prb_ies_len);
2879
2880         ptr += sizeof(*tlv);
2881         ptr += sizeof(*info);
2882         ptr += prb_ies_len;
2883
2884         tlv = ptr;
2885         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2886         tlv->len = __cpu_to_le16(roundup(bcn->len, 4));
2887         memcpy(tlv->value, bcn->data, bcn->len);
2888
2889         /* FIXME: Adjust TSF? */
2890
2891         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv bcn tmpl vdev_id %i\n",
2892                    vdev_id);
2893         return skb;
2894 }
2895
2896 static struct sk_buff *
2897 ath10k_wmi_tlv_op_gen_prb_tmpl(struct ath10k *ar, u32 vdev_id,
2898                                struct sk_buff *prb)
2899 {
2900         struct wmi_tlv_prb_tmpl_cmd *cmd;
2901         struct wmi_tlv_bcn_prb_info *info;
2902         struct wmi_tlv *tlv;
2903         struct sk_buff *skb;
2904         void *ptr;
2905         size_t len;
2906
2907         len = sizeof(*tlv) + sizeof(*cmd) +
2908               sizeof(*tlv) + sizeof(*info) +
2909               sizeof(*tlv) + roundup(prb->len, 4);
2910         skb = ath10k_wmi_alloc_skb(ar, len);
2911         if (!skb)
2912                 return ERR_PTR(-ENOMEM);
2913
2914         ptr = (void *)skb->data;
2915         tlv = ptr;
2916         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PRB_TMPL_CMD);
2917         tlv->len = __cpu_to_le16(sizeof(*cmd));
2918         cmd = (void *)tlv->value;
2919         cmd->vdev_id = __cpu_to_le32(vdev_id);
2920         cmd->buf_len = __cpu_to_le32(prb->len);
2921
2922         ptr += sizeof(*tlv);
2923         ptr += sizeof(*cmd);
2924
2925         tlv = ptr;
2926         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_PRB_INFO);
2927         tlv->len = __cpu_to_le16(sizeof(*info));
2928         info = (void *)tlv->value;
2929         info->caps = 0;
2930         info->erp = 0;
2931
2932         ptr += sizeof(*tlv);
2933         ptr += sizeof(*info);
2934
2935         tlv = ptr;
2936         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2937         tlv->len = __cpu_to_le16(roundup(prb->len, 4));
2938         memcpy(tlv->value, prb->data, prb->len);
2939
2940         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv prb tmpl vdev_id %i\n",
2941                    vdev_id);
2942         return skb;
2943 }
2944
2945 static struct sk_buff *
2946 ath10k_wmi_tlv_op_gen_p2p_go_bcn_ie(struct ath10k *ar, u32 vdev_id,
2947                                     const u8 *p2p_ie)
2948 {
2949         struct wmi_tlv_p2p_go_bcn_ie *cmd;
2950         struct wmi_tlv *tlv;
2951         struct sk_buff *skb;
2952         void *ptr;
2953         size_t len;
2954
2955         len = sizeof(*tlv) + sizeof(*cmd) +
2956               sizeof(*tlv) + roundup(p2p_ie[1] + 2, 4);
2957         skb = ath10k_wmi_alloc_skb(ar, len);
2958         if (!skb)
2959                 return ERR_PTR(-ENOMEM);
2960
2961         ptr = (void *)skb->data;
2962         tlv = ptr;
2963         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_P2P_GO_SET_BEACON_IE);
2964         tlv->len = __cpu_to_le16(sizeof(*cmd));
2965         cmd = (void *)tlv->value;
2966         cmd->vdev_id = __cpu_to_le32(vdev_id);
2967         cmd->ie_len = __cpu_to_le32(p2p_ie[1] + 2);
2968
2969         ptr += sizeof(*tlv);
2970         ptr += sizeof(*cmd);
2971
2972         tlv = ptr;
2973         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2974         tlv->len = __cpu_to_le16(roundup(p2p_ie[1] + 2, 4));
2975         memcpy(tlv->value, p2p_ie, p2p_ie[1] + 2);
2976
2977         ptr += sizeof(*tlv);
2978         ptr += roundup(p2p_ie[1] + 2, 4);
2979
2980         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv p2p go bcn ie for vdev %i\n",
2981                    vdev_id);
2982         return skb;
2983 }
2984
2985 static struct sk_buff *
2986 ath10k_wmi_tlv_op_gen_update_fw_tdls_state(struct ath10k *ar, u32 vdev_id,
2987                                            enum wmi_tdls_state state)
2988 {
2989         struct wmi_tdls_set_state_cmd *cmd;
2990         struct wmi_tlv *tlv;
2991         struct sk_buff *skb;
2992         void *ptr;
2993         size_t len;
2994         /* Set to options from wmi_tlv_tdls_options,
2995          * for now none of them are enabled.
2996          */
2997         u32 options = 0;
2998
2999         if (test_bit(WMI_SERVICE_TDLS_UAPSD_BUFFER_STA, ar->wmi.svc_map))
3000                 options |=  WMI_TLV_TDLS_BUFFER_STA_EN;
3001
3002         /* WMI_TDLS_ENABLE_ACTIVE_EXTERNAL_CONTROL means firm will handle TDLS
3003          * link inactivity detecting logic.
3004          */
3005         if (state == WMI_TDLS_ENABLE_ACTIVE)
3006                 state = WMI_TDLS_ENABLE_ACTIVE_EXTERNAL_CONTROL;
3007
3008         len = sizeof(*tlv) + sizeof(*cmd);
3009         skb = ath10k_wmi_alloc_skb(ar, len);
3010         if (!skb)
3011                 return ERR_PTR(-ENOMEM);
3012
3013         ptr = (void *)skb->data;
3014         tlv = ptr;
3015         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_TDLS_SET_STATE_CMD);
3016         tlv->len = __cpu_to_le16(sizeof(*cmd));
3017
3018         cmd = (void *)tlv->value;
3019         cmd->vdev_id = __cpu_to_le32(vdev_id);
3020         cmd->state = __cpu_to_le32(state);
3021         cmd->notification_interval_ms = __cpu_to_le32(5000);
3022         cmd->tx_discovery_threshold = __cpu_to_le32(100);
3023         cmd->tx_teardown_threshold = __cpu_to_le32(5);
3024         cmd->rssi_teardown_threshold = __cpu_to_le32(-75);
3025         cmd->rssi_delta = __cpu_to_le32(-20);
3026         cmd->tdls_options = __cpu_to_le32(options);
3027         cmd->tdls_peer_traffic_ind_window = __cpu_to_le32(2);
3028         cmd->tdls_peer_traffic_response_timeout_ms = __cpu_to_le32(5000);
3029         cmd->tdls_puapsd_mask = __cpu_to_le32(0xf);
3030         cmd->tdls_puapsd_inactivity_time_ms = __cpu_to_le32(0);
3031         cmd->tdls_puapsd_rx_frame_threshold = __cpu_to_le32(10);
3032
3033         ptr += sizeof(*tlv);
3034         ptr += sizeof(*cmd);
3035
3036         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv update fw tdls state %d for vdev %i\n",
3037                    state, vdev_id);
3038         return skb;
3039 }
3040
3041 static u32 ath10k_wmi_tlv_prepare_peer_qos(u8 uapsd_queues, u8 sp)
3042 {
3043         u32 peer_qos = 0;
3044
3045         if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_VO)
3046                 peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_VO;
3047         if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_VI)
3048                 peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_VI;
3049         if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_BK)
3050                 peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_BK;
3051         if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_BE)
3052                 peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_BE;
3053
3054         peer_qos |= SM(sp, WMI_TLV_TDLS_PEER_SP);
3055
3056         return peer_qos;
3057 }
3058
3059 static struct sk_buff *
3060 ath10k_wmi_tlv_op_gen_tdls_peer_update(struct ath10k *ar,
3061                                        const struct wmi_tdls_peer_update_cmd_arg *arg,
3062                                        const struct wmi_tdls_peer_capab_arg *cap,
3063                                        const struct wmi_channel_arg *chan_arg)
3064 {
3065         struct wmi_tdls_peer_update_cmd *cmd;
3066         struct wmi_tdls_peer_capab *peer_cap;
3067         struct wmi_channel *chan;
3068         struct wmi_tlv *tlv;
3069         struct sk_buff *skb;
3070         u32 peer_qos;
3071         void *ptr;
3072         int len;
3073         int i;
3074
3075         len = sizeof(*tlv) + sizeof(*cmd) +
3076               sizeof(*tlv) + sizeof(*peer_cap) +
3077               sizeof(*tlv) + cap->peer_chan_len * sizeof(*chan);
3078
3079         skb = ath10k_wmi_alloc_skb(ar, len);
3080         if (!skb)
3081                 return ERR_PTR(-ENOMEM);
3082
3083         ptr = (void *)skb->data;
3084         tlv = ptr;
3085         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_TDLS_PEER_UPDATE_CMD);
3086         tlv->len = __cpu_to_le16(sizeof(*cmd));
3087
3088         cmd = (void *)tlv->value;
3089         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
3090         ether_addr_copy(cmd->peer_macaddr.addr, arg->addr);
3091         cmd->peer_state = __cpu_to_le32(arg->peer_state);
3092
3093         ptr += sizeof(*tlv);
3094         ptr += sizeof(*cmd);
3095
3096         tlv = ptr;
3097         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_TDLS_PEER_CAPABILITIES);
3098         tlv->len = __cpu_to_le16(sizeof(*peer_cap));
3099         peer_cap = (void *)tlv->value;
3100         peer_qos = ath10k_wmi_tlv_prepare_peer_qos(cap->peer_uapsd_queues,
3101                                                    cap->peer_max_sp);
3102         peer_cap->peer_qos = __cpu_to_le32(peer_qos);
3103         peer_cap->buff_sta_support = __cpu_to_le32(cap->buff_sta_support);
3104         peer_cap->off_chan_support = __cpu_to_le32(cap->off_chan_support);
3105         peer_cap->peer_curr_operclass = __cpu_to_le32(cap->peer_curr_operclass);
3106         peer_cap->self_curr_operclass = __cpu_to_le32(cap->self_curr_operclass);
3107         peer_cap->peer_chan_len = __cpu_to_le32(cap->peer_chan_len);
3108         peer_cap->peer_operclass_len = __cpu_to_le32(cap->peer_operclass_len);
3109
3110         for (i = 0; i < WMI_TDLS_MAX_SUPP_OPER_CLASSES; i++)
3111                 peer_cap->peer_operclass[i] = cap->peer_operclass[i];
3112
3113         peer_cap->is_peer_responder = __cpu_to_le32(cap->is_peer_responder);
3114         peer_cap->pref_offchan_num = __cpu_to_le32(cap->pref_offchan_num);
3115         peer_cap->pref_offchan_bw = __cpu_to_le32(cap->pref_offchan_bw);
3116
3117         ptr += sizeof(*tlv);
3118         ptr += sizeof(*peer_cap);
3119
3120         tlv = ptr;
3121         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3122         tlv->len = __cpu_to_le16(cap->peer_chan_len * sizeof(*chan));
3123
3124         ptr += sizeof(*tlv);
3125
3126         for (i = 0; i < cap->peer_chan_len; i++) {
3127                 tlv = ptr;
3128                 tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_CHANNEL);
3129                 tlv->len = __cpu_to_le16(sizeof(*chan));
3130                 chan = (void *)tlv->value;
3131                 ath10k_wmi_put_wmi_channel(chan, &chan_arg[i]);
3132
3133                 ptr += sizeof(*tlv);
3134                 ptr += sizeof(*chan);
3135         }
3136
3137         ath10k_dbg(ar, ATH10K_DBG_WMI,
3138                    "wmi tlv tdls peer update vdev %i state %d n_chans %u\n",
3139                    arg->vdev_id, arg->peer_state, cap->peer_chan_len);
3140         return skb;
3141 }
3142
3143 static struct sk_buff *
3144 ath10k_wmi_tlv_op_gen_pdev_set_quiet_mode(struct ath10k *ar, u32 period,
3145                                           u32 duration, u32 next_offset,
3146                                           u32 enabled)
3147 {
3148         struct wmi_tlv_set_quiet_cmd *cmd;
3149         struct wmi_tlv *tlv;
3150         struct sk_buff *skb;
3151
3152         skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
3153         if (!skb)
3154                 return ERR_PTR(-ENOMEM);
3155
3156         tlv = (void *)skb->data;
3157         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_QUIET_CMD);
3158         tlv->len = __cpu_to_le16(sizeof(*cmd));
3159         cmd = (void *)tlv->value;
3160
3161         /* vdev_id is not in use, set to 0 */
3162         cmd->vdev_id = __cpu_to_le32(0);
3163         cmd->period = __cpu_to_le32(period);
3164         cmd->duration = __cpu_to_le32(duration);
3165         cmd->next_start = __cpu_to_le32(next_offset);
3166         cmd->enabled = __cpu_to_le32(enabled);
3167
3168         ath10k_dbg(ar, ATH10K_DBG_WMI,
3169                    "wmi tlv quiet param: period %u duration %u enabled %d\n",
3170                    period, duration, enabled);
3171         return skb;
3172 }
3173
3174 static struct sk_buff *
3175 ath10k_wmi_tlv_op_gen_wow_enable(struct ath10k *ar)
3176 {
3177         struct wmi_tlv_wow_enable_cmd *cmd;
3178         struct wmi_tlv *tlv;
3179         struct sk_buff *skb;
3180         size_t len;
3181
3182         len = sizeof(*tlv) + sizeof(*cmd);
3183         skb = ath10k_wmi_alloc_skb(ar, len);
3184         if (!skb)
3185                 return ERR_PTR(-ENOMEM);
3186
3187         tlv = (struct wmi_tlv *)skb->data;
3188         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_ENABLE_CMD);
3189         tlv->len = __cpu_to_le16(sizeof(*cmd));
3190         cmd = (void *)tlv->value;
3191
3192         cmd->enable = __cpu_to_le32(1);
3193
3194         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow enable\n");
3195         return skb;
3196 }
3197
3198 static struct sk_buff *
3199 ath10k_wmi_tlv_op_gen_wow_add_wakeup_event(struct ath10k *ar,
3200                                            u32 vdev_id,
3201                                            enum wmi_wow_wakeup_event event,
3202                                            u32 enable)
3203 {
3204         struct wmi_tlv_wow_add_del_event_cmd *cmd;
3205         struct wmi_tlv *tlv;
3206         struct sk_buff *skb;
3207         size_t len;
3208
3209         len = sizeof(*tlv) + sizeof(*cmd);
3210         skb = ath10k_wmi_alloc_skb(ar, len);
3211         if (!skb)
3212                 return ERR_PTR(-ENOMEM);
3213
3214         tlv = (struct wmi_tlv *)skb->data;
3215         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_ADD_DEL_EVT_CMD);
3216         tlv->len = __cpu_to_le16(sizeof(*cmd));
3217         cmd = (void *)tlv->value;
3218
3219         cmd->vdev_id = __cpu_to_le32(vdev_id);
3220         cmd->is_add = __cpu_to_le32(enable);
3221         cmd->event_bitmap = __cpu_to_le32(1 << event);
3222
3223         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow add wakeup event %s enable %d vdev_id %d\n",
3224                    wow_wakeup_event(event), enable, vdev_id);
3225         return skb;
3226 }
3227
3228 static struct sk_buff *
3229 ath10k_wmi_tlv_gen_wow_host_wakeup_ind(struct ath10k *ar)
3230 {
3231         struct wmi_tlv_wow_host_wakeup_ind *cmd;
3232         struct wmi_tlv *tlv;
3233         struct sk_buff *skb;
3234         size_t len;
3235
3236         len = sizeof(*tlv) + sizeof(*cmd);
3237         skb = ath10k_wmi_alloc_skb(ar, len);
3238         if (!skb)
3239                 return ERR_PTR(-ENOMEM);
3240
3241         tlv = (struct wmi_tlv *)skb->data;
3242         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_HOSTWAKEUP_FROM_SLEEP_CMD);
3243         tlv->len = __cpu_to_le16(sizeof(*cmd));
3244         cmd = (void *)tlv->value;
3245
3246         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow host wakeup ind\n");
3247         return skb;
3248 }
3249
3250 static struct sk_buff *
3251 ath10k_wmi_tlv_op_gen_wow_add_pattern(struct ath10k *ar, u32 vdev_id,
3252                                       u32 pattern_id, const u8 *pattern,
3253                                       const u8 *bitmask, int pattern_len,
3254                                       int pattern_offset)
3255 {
3256         struct wmi_tlv_wow_add_pattern_cmd *cmd;
3257         struct wmi_tlv_wow_bitmap_pattern *bitmap;
3258         struct wmi_tlv *tlv;
3259         struct sk_buff *skb;
3260         void *ptr;
3261         size_t len;
3262
3263         len = sizeof(*tlv) + sizeof(*cmd) +
3264               sizeof(*tlv) +                    /* array struct */
3265               sizeof(*tlv) + sizeof(*bitmap) +  /* bitmap */
3266               sizeof(*tlv) +                    /* empty ipv4 sync */
3267               sizeof(*tlv) +                    /* empty ipv6 sync */
3268               sizeof(*tlv) +                    /* empty magic */
3269               sizeof(*tlv) +                    /* empty info timeout */
3270               sizeof(*tlv) + sizeof(u32);       /* ratelimit interval */
3271
3272         skb = ath10k_wmi_alloc_skb(ar, len);
3273         if (!skb)
3274                 return ERR_PTR(-ENOMEM);
3275
3276         /* cmd */
3277         ptr = (void *)skb->data;
3278         tlv = ptr;
3279         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_ADD_PATTERN_CMD);
3280         tlv->len = __cpu_to_le16(sizeof(*cmd));
3281         cmd = (void *)tlv->value;
3282
3283         cmd->vdev_id = __cpu_to_le32(vdev_id);
3284         cmd->pattern_id = __cpu_to_le32(pattern_id);
3285         cmd->pattern_type = __cpu_to_le32(WOW_BITMAP_PATTERN);
3286
3287         ptr += sizeof(*tlv);
3288         ptr += sizeof(*cmd);
3289
3290         /* bitmap */
3291         tlv = ptr;
3292         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3293         tlv->len = __cpu_to_le16(sizeof(*tlv) + sizeof(*bitmap));
3294
3295         ptr += sizeof(*tlv);
3296
3297         tlv = ptr;
3298         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_BITMAP_PATTERN_T);
3299         tlv->len = __cpu_to_le16(sizeof(*bitmap));
3300         bitmap = (void *)tlv->value;
3301
3302         memcpy(bitmap->patternbuf, pattern, pattern_len);
3303         memcpy(bitmap->bitmaskbuf, bitmask, pattern_len);
3304         bitmap->pattern_offset = __cpu_to_le32(pattern_offset);
3305         bitmap->pattern_len = __cpu_to_le32(pattern_len);
3306         bitmap->bitmask_len = __cpu_to_le32(pattern_len);
3307         bitmap->pattern_id = __cpu_to_le32(pattern_id);
3308
3309         ptr += sizeof(*tlv);
3310         ptr += sizeof(*bitmap);
3311
3312         /* ipv4 sync */
3313         tlv = ptr;
3314         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3315         tlv->len = __cpu_to_le16(0);
3316
3317         ptr += sizeof(*tlv);
3318
3319         /* ipv6 sync */
3320         tlv = ptr;
3321         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3322         tlv->len = __cpu_to_le16(0);
3323
3324         ptr += sizeof(*tlv);
3325
3326         /* magic */
3327         tlv = ptr;
3328         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3329         tlv->len = __cpu_to_le16(0);
3330
3331         ptr += sizeof(*tlv);
3332
3333         /* pattern info timeout */
3334         tlv = ptr;
3335         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
3336         tlv->len = __cpu_to_le16(0);
3337
3338         ptr += sizeof(*tlv);
3339
3340         /* ratelimit interval */
3341         tlv = ptr;
3342         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
3343         tlv->len = __cpu_to_le16(sizeof(u32));
3344
3345         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow add pattern vdev_id %d pattern_id %d, pattern_offset %d\n",
3346                    vdev_id, pattern_id, pattern_offset);
3347         return skb;
3348 }
3349
3350 static struct sk_buff *
3351 ath10k_wmi_tlv_op_gen_wow_del_pattern(struct ath10k *ar, u32 vdev_id,
3352                                       u32 pattern_id)
3353 {
3354         struct wmi_tlv_wow_del_pattern_cmd *cmd;
3355         struct wmi_tlv *tlv;
3356         struct sk_buff *skb;
3357         size_t len;
3358
3359         len = sizeof(*tlv) + sizeof(*cmd);
3360         skb = ath10k_wmi_alloc_skb(ar, len);
3361         if (!skb)
3362                 return ERR_PTR(-ENOMEM);
3363
3364         tlv = (struct wmi_tlv *)skb->data;
3365         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_DEL_PATTERN_CMD);
3366         tlv->len = __cpu_to_le16(sizeof(*cmd));
3367         cmd = (void *)tlv->value;
3368
3369         cmd->vdev_id = __cpu_to_le32(vdev_id);
3370         cmd->pattern_id = __cpu_to_le32(pattern_id);
3371         cmd->pattern_type = __cpu_to_le32(WOW_BITMAP_PATTERN);
3372
3373         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow del pattern vdev_id %d pattern_id %d\n",
3374                    vdev_id, pattern_id);
3375         return skb;
3376 }
3377
3378 static struct sk_buff *
3379 ath10k_wmi_tlv_op_gen_adaptive_qcs(struct ath10k *ar, bool enable)
3380 {
3381         struct wmi_tlv_adaptive_qcs *cmd;
3382         struct wmi_tlv *tlv;
3383         struct sk_buff *skb;
3384         void *ptr;
3385         size_t len;
3386
3387         len = sizeof(*tlv) + sizeof(*cmd);
3388         skb = ath10k_wmi_alloc_skb(ar, len);
3389         if (!skb)
3390                 return ERR_PTR(-ENOMEM);
3391
3392         ptr = (void *)skb->data;
3393         tlv = ptr;
3394         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_RESMGR_ADAPTIVE_OCS_CMD);
3395         tlv->len = __cpu_to_le16(sizeof(*cmd));
3396         cmd = (void *)tlv->value;
3397         cmd->enable = __cpu_to_le32(enable ? 1 : 0);
3398
3399         ptr += sizeof(*tlv);
3400         ptr += sizeof(*cmd);
3401
3402         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv adaptive qcs %d\n", enable);
3403         return skb;
3404 }
3405
3406 static struct sk_buff *
3407 ath10k_wmi_tlv_op_gen_echo(struct ath10k *ar, u32 value)
3408 {
3409         struct wmi_echo_cmd *cmd;
3410         struct wmi_tlv *tlv;
3411         struct sk_buff *skb;
3412         void *ptr;
3413         size_t len;
3414
3415         len = sizeof(*tlv) + sizeof(*cmd);
3416         skb = ath10k_wmi_alloc_skb(ar, len);
3417         if (!skb)
3418                 return ERR_PTR(-ENOMEM);
3419
3420         ptr = (void *)skb->data;
3421         tlv = ptr;
3422         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_ECHO_CMD);
3423         tlv->len = __cpu_to_le16(sizeof(*cmd));
3424         cmd = (void *)tlv->value;
3425         cmd->value = cpu_to_le32(value);
3426
3427         ptr += sizeof(*tlv);
3428         ptr += sizeof(*cmd);
3429
3430         ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv echo value 0x%08x\n", value);
3431         return skb;
3432 }
3433
3434 static struct sk_buff *
3435 ath10k_wmi_tlv_op_gen_vdev_spectral_conf(struct ath10k *ar,
3436                                          const struct wmi_vdev_spectral_conf_arg *arg)
3437 {
3438         struct wmi_vdev_spectral_conf_cmd *cmd;
3439         struct sk_buff *skb;
3440         struct wmi_tlv *tlv;
3441         void *ptr;
3442         size_t len;
3443
3444         len = sizeof(*tlv) + sizeof(*cmd);
3445         skb = ath10k_wmi_alloc_skb(ar, len);
3446         if (!skb)
3447                 return ERR_PTR(-ENOMEM);
3448
3449         ptr = (void *)skb->data;
3450         tlv = ptr;
3451         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SPECTRAL_CONFIGURE_CMD);
3452         tlv->len = __cpu_to_le16(sizeof(*cmd));
3453         cmd = (void *)tlv->value;
3454         cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
3455         cmd->scan_count = __cpu_to_le32(arg->scan_count);
3456         cmd->scan_period = __cpu_to_le32(arg->scan_period);
3457         cmd->scan_priority = __cpu_to_le32(arg->scan_priority);
3458         cmd->scan_fft_size = __cpu_to_le32(arg->scan_fft_size);
3459         cmd->scan_gc_ena = __cpu_to_le32(arg->scan_gc_ena);
3460         cmd->scan_restart_ena = __cpu_to_le32(arg->scan_restart_ena);
3461         cmd->scan_noise_floor_ref = __cpu_to_le32(arg->scan_noise_floor_ref);
3462         cmd->scan_init_delay = __cpu_to_le32(arg->scan_init_delay);
3463         cmd->scan_nb_tone_thr = __cpu_to_le32(arg->scan_nb_tone_thr);
3464         cmd->scan_str_bin_thr = __cpu_to_le32(arg->scan_str_bin_thr);
3465         cmd->scan_wb_rpt_mode = __cpu_to_le32(arg->scan_wb_rpt_mode);
3466         cmd->scan_rssi_rpt_mode = __cpu_to_le32(arg->scan_rssi_rpt_mode);
3467         cmd->scan_rssi_thr = __cpu_to_le32(arg->scan_rssi_thr);
3468         cmd->scan_pwr_format = __cpu_to_le32(arg->scan_pwr_format);
3469         cmd->scan_rpt_mode = __cpu_to_le32(arg->scan_rpt_mode);
3470         cmd->scan_bin_scale = __cpu_to_le32(arg->scan_bin_scale);
3471         cmd->scan_dbm_adj = __cpu_to_le32(arg->scan_dbm_adj);
3472         cmd->scan_chn_mask = __cpu_to_le32(arg->scan_chn_mask);
3473
3474         return skb;
3475 }
3476
3477 static struct sk_buff *
3478 ath10k_wmi_tlv_op_gen_vdev_spectral_enable(struct ath10k *ar, u32 vdev_id,
3479                                            u32 trigger, u32 enable)
3480 {
3481         struct wmi_vdev_spectral_enable_cmd *cmd;
3482         struct sk_buff *skb;
3483         struct wmi_tlv *tlv;
3484         void *ptr;
3485         size_t len;
3486
3487         len = sizeof(*tlv) + sizeof(*cmd);
3488         skb = ath10k_wmi_alloc_skb(ar, len);
3489         if (!skb)
3490                 return ERR_PTR(-ENOMEM);
3491
3492         ptr = (void *)skb->data;
3493         tlv = ptr;
3494         tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SPECTRAL_ENABLE_CMD);
3495         tlv->len = __cpu_to_le16(sizeof(*cmd));
3496         cmd = (void *)tlv->value;
3497         cmd->vdev_id = __cpu_to_le32(vdev_id);
3498         cmd->trigger_cmd = __cpu_to_le32(trigger);
3499         cmd->enable_cmd = __cpu_to_le32(enable);
3500
3501         return skb;
3502 }
3503
3504 /****************/
3505 /* TLV mappings */
3506 /****************/
3507
3508 static struct wmi_cmd_map wmi_tlv_cmd_map = {
3509         .init_cmdid = WMI_TLV_INIT_CMDID,
3510         .start_scan_cmdid = WMI_TLV_START_SCAN_CMDID,
3511         .stop_scan_cmdid = WMI_TLV_STOP_SCAN_CMDID,
3512         .scan_chan_list_cmdid = WMI_TLV_SCAN_CHAN_LIST_CMDID,
3513         .scan_sch_prio_tbl_cmdid = WMI_TLV_SCAN_SCH_PRIO_TBL_CMDID,
3514         .scan_prob_req_oui_cmdid = WMI_TLV_SCAN_PROB_REQ_OUI_CMDID,
3515         .pdev_set_regdomain_cmdid = WMI_TLV_PDEV_SET_REGDOMAIN_CMDID,
3516         .pdev_set_channel_cmdid = WMI_TLV_PDEV_SET_CHANNEL_CMDID,
3517         .pdev_set_param_cmdid = WMI_TLV_PDEV_SET_PARAM_CMDID,
3518         .pdev_pktlog_enable_cmdid = WMI_TLV_PDEV_PKTLOG_ENABLE_CMDID,
3519         .pdev_pktlog_disable_cmdid = WMI_TLV_PDEV_PKTLOG_DISABLE_CMDID,
3520         .pdev_set_wmm_params_cmdid = WMI_TLV_PDEV_SET_WMM_PARAMS_CMDID,
3521         .pdev_set_ht_cap_ie_cmdid = WMI_TLV_PDEV_SET_HT_CAP_IE_CMDID,
3522         .pdev_set_vht_cap_ie_cmdid = WMI_TLV_PDEV_SET_VHT_CAP_IE_CMDID,
3523         .pdev_set_dscp_tid_map_cmdid = WMI_TLV_PDEV_SET_DSCP_TID_MAP_CMDID,
3524         .pdev_set_quiet_mode_cmdid = WMI_TLV_PDEV_SET_QUIET_MODE_CMDID,
3525         .pdev_green_ap_ps_enable_cmdid = WMI_TLV_PDEV_GREEN_AP_PS_ENABLE_CMDID,
3526         .pdev_get_tpc_config_cmdid = WMI_TLV_PDEV_GET_TPC_CONFIG_CMDID,
3527         .pdev_set_base_macaddr_cmdid = WMI_TLV_PDEV_SET_BASE_MACADDR_CMDID,
3528         .vdev_create_cmdid = WMI_TLV_VDEV_CREATE_CMDID,
3529         .vdev_delete_cmdid = WMI_TLV_VDEV_DELETE_CMDID,
3530         .vdev_start_request_cmdid = WMI_TLV_VDEV_START_REQUEST_CMDID,
3531         .vdev_restart_request_cmdid = WMI_TLV_VDEV_RESTART_REQUEST_CMDID,
3532         .vdev_up_cmdid = WMI_TLV_VDEV_UP_CMDID,
3533         .vdev_stop_cmdid = WMI_TLV_VDEV_STOP_CMDID,
3534         .vdev_down_cmdid = WMI_TLV_VDEV_DOWN_CMDID,
3535         .vdev_set_param_cmdid = WMI_TLV_VDEV_SET_PARAM_CMDID,
3536         .vdev_install_key_cmdid = WMI_TLV_VDEV_INSTALL_KEY_CMDID,
3537         .peer_create_cmdid = WMI_TLV_PEER_CREATE_CMDID,
3538         .peer_delete_cmdid = WMI_TLV_PEER_DELETE_CMDID,
3539         .peer_flush_tids_cmdid = WMI_TLV_PEER_FLUSH_TIDS_CMDID,
3540         .peer_set_param_cmdid = WMI_TLV_PEER_SET_PARAM_CMDID,
3541         .peer_assoc_cmdid = WMI_TLV_PEER_ASSOC_CMDID,
3542         .peer_add_wds_entry_cmdid = WMI_TLV_PEER_ADD_WDS_ENTRY_CMDID,
3543         .peer_remove_wds_entry_cmdid = WMI_TLV_PEER_REMOVE_WDS_ENTRY_CMDID,
3544         .peer_mcast_group_cmdid = WMI_TLV_PEER_MCAST_GROUP_CMDID,
3545         .bcn_tx_cmdid = WMI_TLV_BCN_TX_CMDID,
3546         .pdev_send_bcn_cmdid = WMI_TLV_PDEV_SEND_BCN_CMDID,
3547         .bcn_tmpl_cmdid = WMI_TLV_BCN_TMPL_CMDID,
3548         .bcn_filter_rx_cmdid = WMI_TLV_BCN_FILTER_RX_CMDID,
3549         .prb_req_filter_rx_cmdid = WMI_TLV_PRB_REQ_FILTER_RX_CMDID,
3550         .mgmt_tx_cmdid = WMI_TLV_MGMT_TX_CMDID,
3551         .mgmt_tx_send_cmdid = WMI_TLV_MGMT_TX_SEND_CMD,
3552         .prb_tmpl_cmdid = WMI_TLV_PRB_TMPL_CMDID,
3553         .addba_clear_resp_cmdid = WMI_TLV_ADDBA_CLEAR_RESP_CMDID,
3554         .addba_send_cmdid = WMI_TLV_ADDBA_SEND_CMDID,
3555         .addba_status_cmdid = WMI_TLV_ADDBA_STATUS_CMDID,
3556         .delba_send_cmdid = WMI_TLV_DELBA_SEND_CMDID,
3557         .addba_set_resp_cmdid = WMI_TLV_ADDBA_SET_RESP_CMDID,
3558         .send_singleamsdu_cmdid = WMI_TLV_SEND_SINGLEAMSDU_CMDID,
3559         .sta_powersave_mode_cmdid = WMI_TLV_STA_POWERSAVE_MODE_CMDID,
3560         .sta_powersave_param_cmdid = WMI_TLV_STA_POWERSAVE_PARAM_CMDID,
3561         .sta_mimo_ps_mode_cmdid = WMI_TLV_STA_MIMO_PS_MODE_CMDID,
3562         .pdev_dfs_enable_cmdid = WMI_TLV_PDEV_DFS_ENABLE_CMDID,
3563         .pdev_dfs_disable_cmdid = WMI_TLV_PDEV_DFS_DISABLE_CMDID,
3564         .roam_scan_mode = WMI_TLV_ROAM_SCAN_MODE,
3565         .roam_scan_rssi_threshold = WMI_TLV_ROAM_SCAN_RSSI_THRESHOLD,
3566         .roam_scan_period = WMI_TLV_ROAM_SCAN_PERIOD,
3567         .roam_scan_rssi_change_threshold =
3568                                 WMI_TLV_ROAM_SCAN_RSSI_CHANGE_THRESHOLD,
3569         .roam_ap_profile = WMI_TLV_ROAM_AP_PROFILE,
3570         .ofl_scan_add_ap_profile = WMI_TLV_ROAM_AP_PROFILE,
3571         .ofl_scan_remove_ap_profile = WMI_TLV_OFL_SCAN_REMOVE_AP_PROFILE,
3572         .ofl_scan_period = WMI_TLV_OFL_SCAN_PERIOD,
3573         .p2p_dev_set_device_info = WMI_TLV_P2P_DEV_SET_DEVICE_INFO,
3574         .p2p_dev_set_discoverability = WMI_TLV_P2P_DEV_SET_DISCOVERABILITY,
3575         .p2p_go_set_beacon_ie = WMI_TLV_P2P_GO_SET_BEACON_IE,
3576         .p2p_go_set_probe_resp_ie = WMI_TLV_P2P_GO_SET_PROBE_RESP_IE,
3577         .p2p_set_vendor_ie_data_cmdid = WMI_TLV_P2P_SET_VENDOR_IE_DATA_CMDID,
3578         .ap_ps_peer_param_cmdid = WMI_TLV_AP_PS_PEER_PARAM_CMDID,
3579         .ap_ps_peer_uapsd_coex_cmdid = WMI_TLV_AP_PS_PEER_UAPSD_COEX_CMDID,
3580         .peer_rate_retry_sched_cmdid = WMI_TLV_PEER_RATE_RETRY_SCHED_CMDID,
3581         .wlan_profile_trigger_cmdid = WMI_TLV_WLAN_PROFILE_TRIGGER_CMDID,
3582         .wlan_profile_set_hist_intvl_cmdid =
3583                                 WMI_TLV_WLAN_PROFILE_SET_HIST_INTVL_CMDID,
3584         .wlan_profile_get_profile_data_cmdid =
3585                                 WMI_TLV_WLAN_PROFILE_GET_PROFILE_DATA_CMDID,
3586         .wlan_profile_enable_profile_id_cmdid =
3587                                 WMI_TLV_WLAN_PROFILE_ENABLE_PROFILE_ID_CMDID,
3588         .wlan_profile_list_profile_id_cmdid =
3589                                 WMI_TLV_WLAN_PROFILE_LIST_PROFILE_ID_CMDID,
3590         .pdev_suspend_cmdid = WMI_TLV_PDEV_SUSPEND_CMDID,
3591         .pdev_resume_cmdid = WMI_TLV_PDEV_RESUME_CMDID,
3592         .add_bcn_filter_cmdid = WMI_TLV_ADD_BCN_FILTER_CMDID,
3593         .rmv_bcn_filter_cmdid = WMI_TLV_RMV_BCN_FILTER_CMDID,
3594         .wow_add_wake_pattern_cmdid = WMI_TLV_WOW_ADD_WAKE_PATTERN_CMDID,
3595         .wow_del_wake_pattern_cmdid = WMI_TLV_WOW_DEL_WAKE_PATTERN_CMDID,
3596         .wow_enable_disable_wake_event_cmdid =
3597                                 WMI_TLV_WOW_ENABLE_DISABLE_WAKE_EVENT_CMDID,
3598         .wow_enable_cmdid = WMI_TLV_WOW_ENABLE_CMDID,
3599         .wow_hostwakeup_from_sleep_cmdid =
3600                                 WMI_TLV_WOW_HOSTWAKEUP_FROM_SLEEP_CMDID,
3601         .rtt_measreq_cmdid = WMI_TLV_RTT_MEASREQ_CMDID,
3602         .rtt_tsf_cmdid = WMI_TLV_RTT_TSF_CMDID,
3603         .vdev_spectral_scan_configure_cmdid = WMI_TLV_SPECTRAL_SCAN_CONF_CMDID,
3604         .vdev_spectral_scan_enable_cmdid = WMI_TLV_SPECTRAL_SCAN_ENABLE_CMDID,
3605         .request_stats_cmdid = WMI_TLV_REQUEST_STATS_CMDID,
3606         .set_arp_ns_offload_cmdid = WMI_TLV_SET_ARP_NS_OFFLOAD_CMDID,
3607         .network_list_offload_config_cmdid =
3608                                 WMI_TLV_NETWORK_LIST_OFFLOAD_CONFIG_CMDID,
3609         .gtk_offload_cmdid = WMI_TLV_GTK_OFFLOAD_CMDID,
3610         .csa_offload_enable_cmdid = WMI_TLV_CSA_OFFLOAD_ENABLE_CMDID,
3611         .csa_offload_chanswitch_cmdid = WMI_TLV_CSA_OFFLOAD_CHANSWITCH_CMDID,
3612         .chatter_set_mode_cmdid = WMI_TLV_CHATTER_SET_MODE_CMDID,
3613         .peer_tid_addba_cmdid = WMI_TLV_PEER_TID_ADDBA_CMDID,
3614         .peer_tid_delba_cmdid = WMI_TLV_PEER_TID_DELBA_CMDID,
3615         .sta_dtim_ps_method_cmdid = WMI_TLV_STA_DTIM_PS_METHOD_CMDID,
3616         .sta_uapsd_auto_trig_cmdid = WMI_TLV_STA_UAPSD_AUTO_TRIG_CMDID,
3617         .sta_keepalive_cmd = WMI_TLV_STA_KEEPALIVE_CMDID,
3618         .echo_cmdid = WMI_TLV_ECHO_CMDID,
3619         .pdev_utf_cmdid = WMI_TLV_PDEV_UTF_CMDID,
3620         .dbglog_cfg_cmdid = WMI_TLV_DBGLOG_CFG_CMDID,
3621         .pdev_qvit_cmdid = WMI_TLV_PDEV_QVIT_CMDID,
3622         .pdev_ftm_intg_cmdid = WMI_TLV_PDEV_FTM_INTG_CMDID,
3623         .vdev_set_keepalive_cmdid = WMI_TLV_VDEV_SET_KEEPALIVE_CMDID,
3624         .vdev_get_keepalive_cmdid = WMI_TLV_VDEV_GET_KEEPALIVE_CMDID,
3625         .force_fw_hang_cmdid = WMI_TLV_FORCE_FW_HANG_CMDID,
3626         .gpio_config_cmdid = WMI_TLV_GPIO_CONFIG_CMDID,
3627         .gpio_output_cmdid = WMI_TLV_GPIO_OUTPUT_CMDID,
3628         .pdev_get_temperature_cmdid = WMI_TLV_PDEV_GET_TEMPERATURE_CMDID,
3629         .vdev_set_wmm_params_cmdid = WMI_TLV_VDEV_SET_WMM_PARAMS_CMDID,
3630         .tdls_set_state_cmdid = WMI_TLV_TDLS_SET_STATE_CMDID,
3631         .tdls_peer_update_cmdid = WMI_TLV_TDLS_PEER_UPDATE_CMDID,
3632         .adaptive_qcs_cmdid = WMI_TLV_RESMGR_ADAPTIVE_OCS_CMDID,
3633         .scan_update_request_cmdid = WMI_CMD_UNSUPPORTED,
3634         .vdev_standby_response_cmdid = WMI_CMD_UNSUPPORTED,
3635         .vdev_resume_response_cmdid = WMI_CMD_UNSUPPORTED,
3636         .wlan_peer_caching_add_peer_cmdid = WMI_CMD_UNSUPPORTED,
3637         .wlan_peer_caching_evict_peer_cmdid = WMI_CMD_UNSUPPORTED,
3638         .wlan_peer_caching_restore_peer_cmdid = WMI_CMD_UNSUPPORTED,
3639         .wlan_peer_caching_print_all_peers_info_cmdid = WMI_CMD_UNSUPPORTED,
3640         .peer_update_wds_entry_cmdid = WMI_CMD_UNSUPPORTED,
3641         .peer_add_proxy_sta_entry_cmdid = WMI_CMD_UNSUPPORTED,
3642         .rtt_keepalive_cmdid = WMI_CMD_UNSUPPORTED,
3643         .oem_req_cmdid = WMI_CMD_UNSUPPORTED,
3644         .nan_cmdid = WMI_CMD_UNSUPPORTED,
3645         .vdev_ratemask_cmdid = WMI_CMD_UNSUPPORTED,
3646         .qboost_cfg_cmdid = WMI_CMD_UNSUPPORTED,
3647         .pdev_smart_ant_enable_cmdid = WMI_CMD_UNSUPPORTED,
3648         .pdev_smart_ant_set_rx_antenna_cmdid = WMI_CMD_UNSUPPORTED,
3649         .peer_smart_ant_set_tx_antenna_cmdid = WMI_CMD_UNSUPPORTED,
3650         .peer_smart_ant_set_train_info_cmdid = WMI_CMD_UNSUPPORTED,
3651         .peer_smart_ant_set_node_config_ops_cmdid = WMI_CMD_UNSUPPORTED,
3652         .pdev_set_antenna_switch_table_cmdid = WMI_CMD_UNSUPPORTED,
3653         .pdev_set_ctl_table_cmdid = WMI_CMD_UNSUPPORTED,
3654         .pdev_set_mimogain_table_cmdid = WMI_CMD_UNSUPPORTED,
3655         .pdev_ratepwr_table_cmdid = WMI_CMD_UNSUPPORTED,
3656         .pdev_ratepwr_chainmsk_table_cmdid = WMI_CMD_UNSUPPORTED,
3657         .pdev_fips_cmdid = WMI_CMD_UNSUPPORTED,
3658         .tt_set_conf_cmdid = WMI_CMD_UNSUPPORTED,
3659         .fwtest_cmdid = WMI_CMD_UNSUPPORTED,
3660         .vdev_atf_request_cmdid = WMI_CMD_UNSUPPORTED,
3661         .peer_atf_request_cmdid = WMI_CMD_UNSUPPORTED,
3662         .pdev_get_ani_cck_config_cmdid = WMI_CMD_UNSUPPORTED,
3663         .pdev_get_ani_ofdm_config_cmdid = WMI_CMD_UNSUPPORTED,
3664         .pdev_reserve_ast_entry_cmdid = WMI_CMD_UNSUPPORTED,
3665 };
3666
3667 static struct wmi_pdev_param_map wmi_tlv_pdev_param_map = {
3668         .tx_chain_mask = WMI_TLV_PDEV_PARAM_TX_CHAIN_MASK,
3669         .rx_chain_mask = WMI_TLV_PDEV_PARAM_RX_CHAIN_MASK,
3670         .txpower_limit2g = WMI_TLV_PDEV_PARAM_TXPOWER_LIMIT2G,
3671         .txpower_limit5g = WMI_TLV_PDEV_PARAM_TXPOWER_LIMIT5G,
3672         .txpower_scale = WMI_TLV_PDEV_PARAM_TXPOWER_SCALE,
3673         .beacon_gen_mode = WMI_TLV_PDEV_PARAM_BEACON_GEN_MODE,
3674         .beacon_tx_mode = WMI_TLV_PDEV_PARAM_BEACON_TX_MODE,
3675         .resmgr_offchan_mode = WMI_TLV_PDEV_PARAM_RESMGR_OFFCHAN_MODE,
3676         .protection_mode = WMI_TLV_PDEV_PARAM_PROTECTION_MODE,
3677         .dynamic_bw = WMI_TLV_PDEV_PARAM_DYNAMIC_BW,
3678         .non_agg_sw_retry_th = WMI_TLV_PDEV_PARAM_NON_AGG_SW_RETRY_TH,
3679         .agg_sw_retry_th = WMI_TLV_PDEV_PARAM_AGG_SW_RETRY_TH,
3680         .sta_kickout_th = WMI_TLV_PDEV_PARAM_STA_KICKOUT_TH,
3681         .ac_aggrsize_scaling = WMI_TLV_PDEV_PARAM_AC_AGGRSIZE_SCALING,
3682         .ltr_enable = WMI_TLV_PDEV_PARAM_LTR_ENABLE,
3683         .ltr_ac_latency_be = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_BE,
3684         .ltr_ac_latency_bk = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_BK,
3685         .ltr_ac_latency_vi = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_VI,
3686         .ltr_ac_latency_vo = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_VO,
3687         .ltr_ac_latency_timeout = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_TIMEOUT,
3688         .ltr_sleep_override = WMI_TLV_PDEV_PARAM_LTR_SLEEP_OVERRIDE,
3689         .ltr_rx_override = WMI_TLV_PDEV_PARAM_LTR_RX_OVERRIDE,
3690         .ltr_tx_activity_timeout = WMI_TLV_PDEV_PARAM_LTR_TX_ACTIVITY_TIMEOUT,
3691         .l1ss_enable = WMI_TLV_PDEV_PARAM_L1SS_ENABLE,
3692         .dsleep_enable = WMI_TLV_PDEV_PARAM_DSLEEP_ENABLE,
3693         .pcielp_txbuf_flush = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_FLUSH,
3694         .pcielp_txbuf_watermark = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_TMO_EN,
3695         .pcielp_txbuf_tmo_en = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_TMO_EN,
3696         .pcielp_txbuf_tmo_value = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_TMO_VALUE,
3697         .pdev_stats_update_period = WMI_TLV_PDEV_PARAM_PDEV_STATS_UPDATE_PERIOD,
3698         .vdev_stats_update_period = WMI_TLV_PDEV_PARAM_VDEV_STATS_UPDATE_PERIOD,
3699         .peer_stats_update_period = WMI_TLV_PDEV_PARAM_PEER_STATS_UPDATE_PERIOD,
3700         .bcnflt_stats_update_period =
3701                                 WMI_TLV_PDEV_PARAM_BCNFLT_STATS_UPDATE_PERIOD,
3702         .pmf_qos = WMI_TLV_PDEV_PARAM_PMF_QOS,
3703         .arp_ac_override = WMI_TLV_PDEV_PARAM_ARP_AC_OVERRIDE,
3704         .dcs = WMI_TLV_PDEV_PARAM_DCS,
3705         .ani_enable = WMI_TLV_PDEV_PARAM_ANI_ENABLE,
3706         .ani_poll_period = WMI_TLV_PDEV_PARAM_ANI_POLL_PERIOD,
3707         .ani_listen_period = WMI_TLV_PDEV_PARAM_ANI_LISTEN_PERIOD,
3708         .ani_ofdm_level = WMI_TLV_PDEV_PARAM_ANI_OFDM_LEVEL,
3709         .ani_cck_level = WMI_TLV_PDEV_PARAM_ANI_CCK_LEVEL,
3710         .dyntxchain = WMI_TLV_PDEV_PARAM_DYNTXCHAIN,
3711         .proxy_sta = WMI_TLV_PDEV_PARAM_PROXY_STA,
3712         .idle_ps_config = WMI_TLV_PDEV_PARAM_IDLE_PS_CONFIG,
3713         .power_gating_sleep = WMI_TLV_PDEV_PARAM_POWER_GATING_SLEEP,
3714         .fast_channel_reset = WMI_TLV_PDEV_PARAM_UNSUPPORTED,
3715         .burst_dur = WMI_TLV_PDEV_PARAM_BURST_DUR,
3716         .burst_enable = WMI_TLV_PDEV_PARAM_BURST_ENABLE,
3717         .cal_period = WMI_PDEV_PARAM_UNSUPPORTED,
3718         .aggr_burst = WMI_PDEV_PARAM_UNSUPPORTED,
3719         .rx_decap_mode = WMI_PDEV_PARAM_UNSUPPORTED,
3720         .smart_antenna_default_antenna = WMI_PDEV_PARAM_UNSUPPORTED,
3721         .igmpmld_override = WMI_PDEV_PARAM_UNSUPPORTED,
3722         .igmpmld_tid = WMI_PDEV_PARAM_UNSUPPORTED,
3723         .antenna_gain = WMI_PDEV_PARAM_UNSUPPORTED,
3724         .rx_filter = WMI_PDEV_PARAM_UNSUPPORTED,
3725         .set_mcast_to_ucast_tid = WMI_PDEV_PARAM_UNSUPPORTED,
3726         .proxy_sta_mode = WMI_PDEV_PARAM_UNSUPPORTED,
3727         .set_mcast2ucast_mode = WMI_PDEV_PARAM_UNSUPPORTED,
3728         .set_mcast2ucast_buffer = WMI_PDEV_PARAM_UNSUPPORTED,
3729         .remove_mcast2ucast_buffer = WMI_PDEV_PARAM_UNSUPPORTED,
3730         .peer_sta_ps_statechg_enable = WMI_PDEV_PARAM_UNSUPPORTED,
3731         .igmpmld_ac_override = WMI_PDEV_PARAM_UNSUPPORTED,
3732         .block_interbss = WMI_PDEV_PARAM_UNSUPPORTED,
3733         .set_disable_reset_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3734         .set_msdu_ttl_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3735         .set_ppdu_duration_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3736         .txbf_sound_period_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3737         .set_promisc_mode_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3738         .set_burst_mode_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3739         .en_stats = WMI_PDEV_PARAM_UNSUPPORTED,
3740         .mu_group_policy = WMI_PDEV_PARAM_UNSUPPORTED,
3741         .noise_detection = WMI_PDEV_PARAM_UNSUPPORTED,
3742         .noise_threshold = WMI_PDEV_PARAM_UNSUPPORTED,
3743         .dpd_enable = WMI_PDEV_PARAM_UNSUPPORTED,
3744         .set_mcast_bcast_echo = WMI_PDEV_PARAM_UNSUPPORTED,
3745         .atf_strict_sch = WMI_PDEV_PARAM_UNSUPPORTED,
3746         .atf_sched_duration = WMI_PDEV_PARAM_UNSUPPORTED,
3747         .ant_plzn = WMI_PDEV_PARAM_UNSUPPORTED,
3748         .mgmt_retry_limit = WMI_PDEV_PARAM_UNSUPPORTED,
3749         .sensitivity_level = WMI_PDEV_PARAM_UNSUPPORTED,
3750         .signed_txpower_2g = WMI_PDEV_PARAM_UNSUPPORTED,
3751         .signed_txpower_5g = WMI_PDEV_PARAM_UNSUPPORTED,
3752         .enable_per_tid_amsdu = WMI_PDEV_PARAM_UNSUPPORTED,
3753         .enable_per_tid_ampdu = WMI_PDEV_PARAM_UNSUPPORTED,
3754         .cca_threshold = WMI_PDEV_PARAM_UNSUPPORTED,
3755         .rts_fixed_rate = WMI_PDEV_PARAM_UNSUPPORTED,
3756         .pdev_reset = WMI_PDEV_PARAM_UNSUPPORTED,
3757         .wapi_mbssid_offset = WMI_PDEV_PARAM_UNSUPPORTED,
3758         .arp_srcaddr = WMI_PDEV_PARAM_UNSUPPORTED,
3759         .arp_dstaddr = WMI_PDEV_PARAM_UNSUPPORTED,
3760 };
3761
3762 static struct wmi_vdev_param_map wmi_tlv_vdev_param_map = {
3763         .rts_threshold = WMI_TLV_VDEV_PARAM_RTS_THRESHOLD,
3764         .fragmentation_threshold = WMI_TLV_VDEV_PARAM_FRAGMENTATION_THRESHOLD,
3765         .beacon_interval = WMI_TLV_VDEV_PARAM_BEACON_INTERVAL,
3766         .listen_interval = WMI_TLV_VDEV_PARAM_LISTEN_INTERVAL,
3767         .multicast_rate = WMI_TLV_VDEV_PARAM_MULTICAST_RATE,
3768         .mgmt_tx_rate = WMI_TLV_VDEV_PARAM_MGMT_TX_RATE,
3769         .slot_time = WMI_TLV_VDEV_PARAM_SLOT_TIME,
3770         .preamble = WMI_TLV_VDEV_PARAM_PREAMBLE,
3771         .swba_time = WMI_TLV_VDEV_PARAM_SWBA_TIME,
3772         .wmi_vdev_stats_update_period = WMI_TLV_VDEV_STATS_UPDATE_PERIOD,
3773         .wmi_vdev_pwrsave_ageout_time = WMI_TLV_VDEV_PWRSAVE_AGEOUT_TIME,
3774         .wmi_vdev_host_swba_interval = WMI_TLV_VDEV_HOST_SWBA_INTERVAL,
3775         .dtim_period = WMI_TLV_VDEV_PARAM_DTIM_PERIOD,
3776         .wmi_vdev_oc_scheduler_air_time_limit =
3777                                 WMI_TLV_VDEV_OC_SCHEDULER_AIR_TIME_LIMIT,
3778         .wds = WMI_TLV_VDEV_PARAM_WDS,
3779         .atim_window = WMI_TLV_VDEV_PARAM_ATIM_WINDOW,
3780         .bmiss_count_max = WMI_TLV_VDEV_PARAM_BMISS_COUNT_MAX,
3781         .bmiss_first_bcnt = WMI_TLV_VDEV_PARAM_BMISS_FIRST_BCNT,
3782         .bmiss_final_bcnt = WMI_TLV_VDEV_PARAM_BMISS_FINAL_BCNT,
3783         .feature_wmm = WMI_TLV_VDEV_PARAM_FEATURE_WMM,
3784         .chwidth = WMI_TLV_VDEV_PARAM_CHWIDTH,
3785         .chextoffset = WMI_TLV_VDEV_PARAM_CHEXTOFFSET,
3786         .disable_htprotection = WMI_TLV_VDEV_PARAM_DISABLE_HTPROTECTION,
3787         .sta_quickkickout = WMI_TLV_VDEV_PARAM_STA_QUICKKICKOUT,
3788         .mgmt_rate = WMI_TLV_VDEV_PARAM_MGMT_RATE,
3789         .protection_mode = WMI_TLV_VDEV_PARAM_PROTECTION_MODE,
3790         .fixed_rate = WMI_TLV_VDEV_PARAM_FIXED_RATE,
3791         .sgi = WMI_TLV_VDEV_PARAM_SGI,
3792         .ldpc = WMI_TLV_VDEV_PARAM_LDPC,
3793         .tx_stbc = WMI_TLV_VDEV_PARAM_TX_STBC,
3794         .rx_stbc = WMI_TLV_VDEV_PARAM_RX_STBC,
3795         .intra_bss_fwd = WMI_TLV_VDEV_PARAM_INTRA_BSS_FWD,
3796         .def_keyid = WMI_TLV_VDEV_PARAM_DEF_KEYID,
3797         .nss = WMI_TLV_VDEV_PARAM_NSS,
3798         .bcast_data_rate = WMI_TLV_VDEV_PARAM_BCAST_DATA_RATE,
3799         .mcast_data_rate = WMI_TLV_VDEV_PARAM_MCAST_DATA_RATE,
3800         .mcast_indicate = WMI_TLV_VDEV_PARAM_MCAST_INDICATE,
3801         .dhcp_indicate = WMI_TLV_VDEV_PARAM_DHCP_INDICATE,
3802         .unknown_dest_indicate = WMI_TLV_VDEV_PARAM_UNKNOWN_DEST_INDICATE,
3803         .ap_keepalive_min_idle_inactive_time_secs =
3804                 WMI_TLV_VDEV_PARAM_AP_KEEPALIVE_MIN_IDLE_INACTIVE_TIME_SECS,
3805         .ap_keepalive_max_idle_inactive_time_secs =
3806                 WMI_TLV_VDEV_PARAM_AP_KEEPALIVE_MAX_IDLE_INACTIVE_TIME_SECS,
3807         .ap_keepalive_max_unresponsive_time_secs =
3808                 WMI_TLV_VDEV_PARAM_AP_KEEPALIVE_MAX_UNRESPONSIVE_TIME_SECS,
3809         .ap_enable_nawds = WMI_TLV_VDEV_PARAM_AP_ENABLE_NAWDS,
3810         .mcast2ucast_set = WMI_TLV_VDEV_PARAM_UNSUPPORTED,
3811         .enable_rtscts = WMI_TLV_VDEV_PARAM_ENABLE_RTSCTS,
3812         .txbf = WMI_TLV_VDEV_PARAM_TXBF,
3813         .packet_powersave = WMI_TLV_VDEV_PARAM_PACKET_POWERSAVE,
3814         .drop_unencry = WMI_TLV_VDEV_PARAM_DROP_UNENCRY,
3815         .tx_encap_type = WMI_TLV_VDEV_PARAM_TX_ENCAP_TYPE,
3816         .ap_detect_out_of_sync_sleeping_sta_time_secs =
3817                                         WMI_TLV_VDEV_PARAM_UNSUPPORTED,
3818         .rc_num_retries = WMI_VDEV_PARAM_UNSUPPORTED,
3819         .cabq_maxdur = WMI_VDEV_PARAM_UNSUPPORTED,
3820         .mfptest_set = WMI_VDEV_PARAM_UNSUPPORTED,
3821         .rts_fixed_rate = WMI_VDEV_PARAM_UNSUPPORTED,
3822         .vht_sgimask = WMI_VDEV_PARAM_UNSUPPORTED,
3823         .vht80_ratemask = WMI_VDEV_PARAM_UNSUPPORTED,
3824         .early_rx_adjust_enable = WMI_VDEV_PARAM_UNSUPPORTED,
3825         .early_rx_tgt_bmiss_num = WMI_VDEV_PARAM_UNSUPPORTED,
3826         .early_rx_bmiss_sample_cycle = WMI_VDEV_PARAM_UNSUPPORTED,
3827         .early_rx_slop_step = WMI_VDEV_PARAM_UNSUPPORTED,
3828         .early_rx_init_slop = WMI_VDEV_PARAM_UNSUPPORTED,
3829         .early_rx_adjust_pause = WMI_VDEV_PARAM_UNSUPPORTED,
3830         .proxy_sta = WMI_VDEV_PARAM_UNSUPPORTED,
3831         .meru_vc = WMI_VDEV_PARAM_UNSUPPORTED,
3832         .rx_decap_type = WMI_VDEV_PARAM_UNSUPPORTED,
3833         .bw_nss_ratemask = WMI_VDEV_PARAM_UNSUPPORTED,
3834 };
3835
3836 static const struct wmi_ops wmi_tlv_ops = {
3837         .rx = ath10k_wmi_tlv_op_rx,
3838         .map_svc = wmi_tlv_svc_map,
3839         .map_svc_ext = wmi_tlv_svc_map_ext,
3840
3841         .pull_scan = ath10k_wmi_tlv_op_pull_scan_ev,
3842         .pull_mgmt_rx = ath10k_wmi_tlv_op_pull_mgmt_rx_ev,
3843         .pull_ch_info = ath10k_wmi_tlv_op_pull_ch_info_ev,
3844         .pull_vdev_start = ath10k_wmi_tlv_op_pull_vdev_start_ev,
3845         .pull_peer_kick = ath10k_wmi_tlv_op_pull_peer_kick_ev,
3846         .pull_swba = ath10k_wmi_tlv_op_pull_swba_ev,
3847         .pull_phyerr_hdr = ath10k_wmi_tlv_op_pull_phyerr_ev_hdr,
3848         .pull_phyerr = ath10k_wmi_op_pull_phyerr_ev,
3849         .pull_svc_rdy = ath10k_wmi_tlv_op_pull_svc_rdy_ev,
3850         .pull_rdy = ath10k_wmi_tlv_op_pull_rdy_ev,
3851         .pull_svc_avail = ath10k_wmi_tlv_op_pull_svc_avail,
3852         .pull_fw_stats = ath10k_wmi_tlv_op_pull_fw_stats,
3853         .pull_roam_ev = ath10k_wmi_tlv_op_pull_roam_ev,
3854         .pull_wow_event = ath10k_wmi_tlv_op_pull_wow_ev,
3855         .pull_echo_ev = ath10k_wmi_tlv_op_pull_echo_ev,
3856         .get_txbf_conf_scheme = ath10k_wmi_tlv_txbf_conf_scheme,
3857
3858         .gen_pdev_suspend = ath10k_wmi_tlv_op_gen_pdev_suspend,
3859         .gen_pdev_resume = ath10k_wmi_tlv_op_gen_pdev_resume,
3860         .gen_pdev_set_rd = ath10k_wmi_tlv_op_gen_pdev_set_rd,
3861         .gen_pdev_set_param = ath10k_wmi_tlv_op_gen_pdev_set_param,
3862         .gen_init = ath10k_wmi_tlv_op_gen_init,
3863         .gen_start_scan = ath10k_wmi_tlv_op_gen_start_scan,
3864         .gen_stop_scan = ath10k_wmi_tlv_op_gen_stop_scan,
3865         .gen_vdev_create = ath10k_wmi_tlv_op_gen_vdev_create,
3866         .gen_vdev_delete = ath10k_wmi_tlv_op_gen_vdev_delete,
3867         .gen_vdev_start = ath10k_wmi_tlv_op_gen_vdev_start,
3868         .gen_vdev_stop = ath10k_wmi_tlv_op_gen_vdev_stop,
3869         .gen_vdev_up = ath10k_wmi_tlv_op_gen_vdev_up,
3870         .gen_vdev_down = ath10k_wmi_tlv_op_gen_vdev_down,
3871         .gen_vdev_set_param = ath10k_wmi_tlv_op_gen_vdev_set_param,
3872         .gen_vdev_install_key = ath10k_wmi_tlv_op_gen_vdev_install_key,
3873         .gen_vdev_wmm_conf = ath10k_wmi_tlv_op_gen_vdev_wmm_conf,
3874         .gen_peer_create = ath10k_wmi_tlv_op_gen_peer_create,
3875         .gen_peer_delete = ath10k_wmi_tlv_op_gen_peer_delete,
3876         .gen_peer_flush = ath10k_wmi_tlv_op_gen_peer_flush,
3877         .gen_peer_set_param = ath10k_wmi_tlv_op_gen_peer_set_param,
3878         .gen_peer_assoc = ath10k_wmi_tlv_op_gen_peer_assoc,
3879         .gen_set_psmode = ath10k_wmi_tlv_op_gen_set_psmode,
3880         .gen_set_sta_ps = ath10k_wmi_tlv_op_gen_set_sta_ps,
3881         .gen_set_ap_ps = ath10k_wmi_tlv_op_gen_set_ap_ps,
3882         .gen_scan_chan_list = ath10k_wmi_tlv_op_gen_scan_chan_list,
3883         .gen_scan_prob_req_oui = ath10k_wmi_tlv_op_gen_scan_prob_req_oui,
3884         .gen_beacon_dma = ath10k_wmi_tlv_op_gen_beacon_dma,
3885         .gen_pdev_set_wmm = ath10k_wmi_tlv_op_gen_pdev_set_wmm,
3886         .gen_request_stats = ath10k_wmi_tlv_op_gen_request_stats,
3887         .gen_force_fw_hang = ath10k_wmi_tlv_op_gen_force_fw_hang,
3888         /* .gen_mgmt_tx = not implemented; HTT is used */
3889         .gen_mgmt_tx_send = ath10k_wmi_tlv_op_gen_mgmt_tx_send,
3890         .gen_dbglog_cfg = ath10k_wmi_tlv_op_gen_dbglog_cfg,
3891         .gen_pktlog_enable = ath10k_wmi_tlv_op_gen_pktlog_enable,
3892         .gen_pktlog_disable = ath10k_wmi_tlv_op_gen_pktlog_disable,
3893         .gen_pdev_set_quiet_mode = ath10k_wmi_tlv_op_gen_pdev_set_quiet_mode,
3894         .gen_pdev_get_temperature = ath10k_wmi_tlv_op_gen_pdev_get_temperature,
3895         /* .gen_addba_clear_resp not implemented */
3896         /* .gen_addba_send not implemented */
3897         /* .gen_addba_set_resp not implemented */
3898         /* .gen_delba_send not implemented */
3899         .gen_bcn_tmpl = ath10k_wmi_tlv_op_gen_bcn_tmpl,
3900         .gen_prb_tmpl = ath10k_wmi_tlv_op_gen_prb_tmpl,
3901         .gen_p2p_go_bcn_ie = ath10k_wmi_tlv_op_gen_p2p_go_bcn_ie,
3902         .gen_vdev_sta_uapsd = ath10k_wmi_tlv_op_gen_vdev_sta_uapsd,
3903         .gen_sta_keepalive = ath10k_wmi_tlv_op_gen_sta_keepalive,
3904         .gen_wow_enable = ath10k_wmi_tlv_op_gen_wow_enable,
3905         .gen_wow_add_wakeup_event = ath10k_wmi_tlv_op_gen_wow_add_wakeup_event,
3906         .gen_wow_host_wakeup_ind = ath10k_wmi_tlv_gen_wow_host_wakeup_ind,
3907         .gen_wow_add_pattern = ath10k_wmi_tlv_op_gen_wow_add_pattern,
3908         .gen_wow_del_pattern = ath10k_wmi_tlv_op_gen_wow_del_pattern,
3909         .gen_update_fw_tdls_state = ath10k_wmi_tlv_op_gen_update_fw_tdls_state,
3910         .gen_tdls_peer_update = ath10k_wmi_tlv_op_gen_tdls_peer_update,
3911         .gen_adaptive_qcs = ath10k_wmi_tlv_op_gen_adaptive_qcs,
3912         .fw_stats_fill = ath10k_wmi_main_op_fw_stats_fill,
3913         .get_vdev_subtype = ath10k_wmi_op_get_vdev_subtype,
3914         .gen_echo = ath10k_wmi_tlv_op_gen_echo,
3915         .gen_vdev_spectral_conf = ath10k_wmi_tlv_op_gen_vdev_spectral_conf,
3916         .gen_vdev_spectral_enable = ath10k_wmi_tlv_op_gen_vdev_spectral_enable,
3917 };
3918
3919 static const struct wmi_peer_flags_map wmi_tlv_peer_flags_map = {
3920         .auth = WMI_TLV_PEER_AUTH,
3921         .qos = WMI_TLV_PEER_QOS,
3922         .need_ptk_4_way = WMI_TLV_PEER_NEED_PTK_4_WAY,
3923         .need_gtk_2_way = WMI_TLV_PEER_NEED_GTK_2_WAY,
3924         .apsd = WMI_TLV_PEER_APSD,
3925         .ht = WMI_TLV_PEER_HT,
3926         .bw40 = WMI_TLV_PEER_40MHZ,
3927         .stbc = WMI_TLV_PEER_STBC,
3928         .ldbc = WMI_TLV_PEER_LDPC,
3929         .dyn_mimops = WMI_TLV_PEER_DYN_MIMOPS,
3930         .static_mimops = WMI_TLV_PEER_STATIC_MIMOPS,
3931         .spatial_mux = WMI_TLV_PEER_SPATIAL_MUX,
3932         .vht = WMI_TLV_PEER_VHT,
3933         .bw80 = WMI_TLV_PEER_80MHZ,
3934         .pmf = WMI_TLV_PEER_PMF,
3935         .bw160 = WMI_TLV_PEER_160MHZ,
3936 };
3937
3938 /************/
3939 /* TLV init */
3940 /************/
3941
3942 void ath10k_wmi_tlv_attach(struct ath10k *ar)
3943 {
3944         ar->wmi.cmd = &wmi_tlv_cmd_map;
3945         ar->wmi.vdev_param = &wmi_tlv_vdev_param_map;
3946         ar->wmi.pdev_param = &wmi_tlv_pdev_param_map;
3947         ar->wmi.ops = &wmi_tlv_ops;
3948         ar->wmi.peer_flags = &wmi_tlv_peer_flags_map;
3949 }