8460cd45321376991ce72652d84ea5b59b94b18a
[linux-2.6-microblaze.git] / drivers / net / wireless / mediatek / mt76 / mt7915 / mcu.c
1 // SPDX-License-Identifier: ISC
2 /* Copyright (C) 2020 MediaTek Inc. */
3
4 #include <linux/firmware.h>
5 #include <linux/fs.h>
6 #include "mt7915.h"
7 #include "mcu.h"
8 #include "mac.h"
9 #include "eeprom.h"
10
11 struct mt7915_patch_hdr {
12         char build_date[16];
13         char platform[4];
14         __be32 hw_sw_ver;
15         __be32 patch_ver;
16         __be16 checksum;
17         u16 reserved;
18         struct {
19                 __be32 patch_ver;
20                 __be32 subsys;
21                 __be32 feature;
22                 __be32 n_region;
23                 __be32 crc;
24                 u32 reserved[11];
25         } desc;
26 } __packed;
27
28 struct mt7915_patch_sec {
29         __be32 type;
30         __be32 offs;
31         __be32 size;
32         union {
33                 __be32 spec[13];
34                 struct {
35                         __be32 addr;
36                         __be32 len;
37                         __be32 sec_key_idx;
38                         __be32 align_len;
39                         u32 reserved[9];
40                 } info;
41         };
42 } __packed;
43
44 struct mt7915_fw_trailer {
45         u8 chip_id;
46         u8 eco_code;
47         u8 n_region;
48         u8 format_ver;
49         u8 format_flag;
50         u8 reserved[2];
51         char fw_ver[10];
52         char build_date[15];
53         u32 crc;
54 } __packed;
55
56 struct mt7915_fw_region {
57         __le32 decomp_crc;
58         __le32 decomp_len;
59         __le32 decomp_blk_sz;
60         u8 reserved[4];
61         __le32 addr;
62         __le32 len;
63         u8 feature_set;
64         u8 reserved1[15];
65 } __packed;
66
67 #define MCU_PATCH_ADDRESS               0x200000
68
69 #define MT_STA_BFER                     BIT(0)
70 #define MT_STA_BFEE                     BIT(1)
71
72 #define FW_FEATURE_SET_ENCRYPT          BIT(0)
73 #define FW_FEATURE_SET_KEY_IDX          GENMASK(2, 1)
74 #define FW_FEATURE_OVERRIDE_ADDR        BIT(5)
75
76 #define DL_MODE_ENCRYPT                 BIT(0)
77 #define DL_MODE_KEY_IDX                 GENMASK(2, 1)
78 #define DL_MODE_RESET_SEC_IV            BIT(3)
79 #define DL_MODE_WORKING_PDA_CR4         BIT(4)
80 #define DL_MODE_NEED_RSP                BIT(31)
81
82 #define FW_START_OVERRIDE               BIT(0)
83 #define FW_START_WORKING_PDA_CR4        BIT(2)
84
85 #define PATCH_SEC_TYPE_MASK             GENMASK(15, 0)
86 #define PATCH_SEC_TYPE_INFO             0x2
87
88 #define to_wcid_lo(id)                  FIELD_GET(GENMASK(7, 0), (u16)id)
89 #define to_wcid_hi(id)                  FIELD_GET(GENMASK(9, 8), (u16)id)
90
91 #define HE_PHY(p, c)                    u8_get_bits(c, IEEE80211_HE_PHY_##p)
92 #define HE_MAC(m, c)                    u8_get_bits(c, IEEE80211_HE_MAC_##m)
93
94 static enum mt7915_cipher_type
95 mt7915_mcu_get_cipher(int cipher)
96 {
97         switch (cipher) {
98         case WLAN_CIPHER_SUITE_WEP40:
99                 return MT_CIPHER_WEP40;
100         case WLAN_CIPHER_SUITE_WEP104:
101                 return MT_CIPHER_WEP104;
102         case WLAN_CIPHER_SUITE_TKIP:
103                 return MT_CIPHER_TKIP;
104         case WLAN_CIPHER_SUITE_AES_CMAC:
105                 return MT_CIPHER_BIP_CMAC_128;
106         case WLAN_CIPHER_SUITE_CCMP:
107                 return MT_CIPHER_AES_CCMP;
108         case WLAN_CIPHER_SUITE_CCMP_256:
109                 return MT_CIPHER_CCMP_256;
110         case WLAN_CIPHER_SUITE_GCMP:
111                 return MT_CIPHER_GCMP;
112         case WLAN_CIPHER_SUITE_GCMP_256:
113                 return MT_CIPHER_GCMP_256;
114         case WLAN_CIPHER_SUITE_SMS4:
115                 return MT_CIPHER_WAPI;
116         default:
117                 return MT_CIPHER_NONE;
118         }
119 }
120
121 static u8 mt7915_mcu_chan_bw(struct cfg80211_chan_def *chandef)
122 {
123         static const u8 width_to_bw[] = {
124                 [NL80211_CHAN_WIDTH_40] = CMD_CBW_40MHZ,
125                 [NL80211_CHAN_WIDTH_80] = CMD_CBW_80MHZ,
126                 [NL80211_CHAN_WIDTH_80P80] = CMD_CBW_8080MHZ,
127                 [NL80211_CHAN_WIDTH_160] = CMD_CBW_160MHZ,
128                 [NL80211_CHAN_WIDTH_5] = CMD_CBW_5MHZ,
129                 [NL80211_CHAN_WIDTH_10] = CMD_CBW_10MHZ,
130                 [NL80211_CHAN_WIDTH_20] = CMD_CBW_20MHZ,
131                 [NL80211_CHAN_WIDTH_20_NOHT] = CMD_CBW_20MHZ,
132         };
133
134         if (chandef->width >= ARRAY_SIZE(width_to_bw))
135                 return 0;
136
137         return width_to_bw[chandef->width];
138 }
139
140 static const struct ieee80211_sta_he_cap *
141 mt7915_get_he_phy_cap(struct mt7915_phy *phy, struct ieee80211_vif *vif)
142 {
143         struct ieee80211_supported_band *sband;
144         enum nl80211_band band;
145
146         band = phy->mt76->chandef.chan->band;
147         sband = phy->mt76->hw->wiphy->bands[band];
148
149         return ieee80211_get_he_iftype_cap(sband, vif->type);
150 }
151
152 static u8
153 mt7915_get_phy_mode(struct mt7915_dev *dev, struct ieee80211_vif *vif,
154                     enum nl80211_band band, struct ieee80211_sta *sta)
155 {
156         struct ieee80211_sta_ht_cap *ht_cap;
157         struct ieee80211_sta_vht_cap *vht_cap;
158         const struct ieee80211_sta_he_cap *he_cap;
159         u8 mode = 0;
160
161         if (sta) {
162                 ht_cap = &sta->ht_cap;
163                 vht_cap = &sta->vht_cap;
164                 he_cap = &sta->he_cap;
165         } else {
166                 struct ieee80211_supported_band *sband;
167                 struct mt7915_phy *phy;
168                 struct mt7915_vif *mvif;
169
170                 mvif = (struct mt7915_vif *)vif->drv_priv;
171                 phy = mvif->band_idx ? mt7915_ext_phy(dev) : &dev->phy;
172                 sband = phy->mt76->hw->wiphy->bands[band];
173
174                 ht_cap = &sband->ht_cap;
175                 vht_cap = &sband->vht_cap;
176                 he_cap = ieee80211_get_he_iftype_cap(sband, vif->type);
177         }
178
179         if (band == NL80211_BAND_2GHZ) {
180                 mode |= PHY_MODE_B | PHY_MODE_G;
181
182                 if (ht_cap->ht_supported)
183                         mode |= PHY_MODE_GN;
184
185                 if (he_cap->has_he)
186                         mode |= PHY_MODE_AX_24G;
187         } else if (band == NL80211_BAND_5GHZ) {
188                 mode |= PHY_MODE_A;
189
190                 if (ht_cap->ht_supported)
191                         mode |= PHY_MODE_AN;
192
193                 if (vht_cap->vht_supported)
194                         mode |= PHY_MODE_AC;
195
196                 if (he_cap->has_he)
197                         mode |= PHY_MODE_AX_5G;
198         }
199
200         return mode;
201 }
202
203 static u8
204 mt7915_mcu_get_sta_nss(u16 mcs_map)
205 {
206         u8 nss;
207
208         for (nss = 8; nss > 0; nss--) {
209                 u8 nss_mcs = (mcs_map >> (2 * (nss - 1))) & 3;
210
211                 if (nss_mcs != IEEE80211_VHT_MCS_NOT_SUPPORTED)
212                         break;
213         }
214
215         return nss - 1;
216 }
217
218 static int __mt7915_mcu_msg_send(struct mt7915_dev *dev, struct sk_buff *skb,
219                                  int cmd, int *wait_seq)
220 {
221         struct mt7915_mcu_txd *mcu_txd;
222         u8 seq, pkt_fmt, qidx;
223         enum mt76_txq_id txq;
224         __le32 *txd;
225         u32 val;
226
227         seq = ++dev->mt76.mcu.msg_seq & 0xf;
228         if (!seq)
229                 seq = ++dev->mt76.mcu.msg_seq & 0xf;
230
231         if (cmd == -MCU_CMD_FW_SCATTER) {
232                 txq = MT_TXQ_FWDL;
233                 goto exit;
234         }
235
236         mcu_txd = (struct mt7915_mcu_txd *)skb_push(skb, sizeof(*mcu_txd));
237
238         if (test_bit(MT76_STATE_MCU_RUNNING, &dev->mphy.state)) {
239                 txq = MT_TXQ_MCU_WA;
240                 qidx = MT_TX_MCU_PORT_RX_Q0;
241                 pkt_fmt = MT_TX_TYPE_CMD;
242         } else {
243                 txq = MT_TXQ_MCU;
244                 qidx = MT_TX_MCU_PORT_RX_Q0;
245                 pkt_fmt = MT_TX_TYPE_CMD;
246         }
247
248         txd = mcu_txd->txd;
249
250         val = FIELD_PREP(MT_TXD0_TX_BYTES, skb->len) |
251               FIELD_PREP(MT_TXD0_PKT_FMT, pkt_fmt) |
252               FIELD_PREP(MT_TXD0_Q_IDX, qidx);
253         txd[0] = cpu_to_le32(val);
254
255         val = MT_TXD1_LONG_FORMAT |
256               FIELD_PREP(MT_TXD1_HDR_FORMAT, MT_HDR_FORMAT_CMD);
257         txd[1] = cpu_to_le32(val);
258
259         mcu_txd->len = cpu_to_le16(skb->len - sizeof(mcu_txd->txd));
260         mcu_txd->pq_id = cpu_to_le16(MCU_PQ_ID(MT_TX_PORT_IDX_MCU, qidx));
261         mcu_txd->pkt_type = MCU_PKT_ID;
262         mcu_txd->seq = seq;
263
264         if (cmd < 0) {
265                 mcu_txd->set_query = MCU_Q_NA;
266                 mcu_txd->cid = -cmd;
267         } else {
268                 mcu_txd->cid = MCU_CMD_EXT_CID;
269                 mcu_txd->ext_cid = cmd;
270                 mcu_txd->ext_cid_ack = 1;
271
272                 /* do not use Q_SET for efuse */
273                 if (cmd == MCU_EXT_CMD_EFUSE_ACCESS)
274                         mcu_txd->set_query = MCU_Q_QUERY;
275                 else
276                         mcu_txd->set_query = MCU_Q_SET;
277         }
278
279         mcu_txd->s2d_index = MCU_S2D_H2N;
280         WARN_ON(cmd == MCU_EXT_CMD_EFUSE_ACCESS &&
281                 mcu_txd->set_query != MCU_Q_QUERY);
282
283 exit:
284         if (wait_seq)
285                 *wait_seq = seq;
286
287         return mt76_tx_queue_skb_raw(dev, txq, skb, 0);
288 }
289
290 static int
291 mt7915_mcu_parse_eeprom(struct mt7915_dev *dev, struct sk_buff *skb)
292 {
293         struct mt7915_mcu_eeprom_info *res;
294         u8 *buf;
295
296         if (!skb)
297                 return -EINVAL;
298
299         skb_pull(skb, sizeof(struct mt7915_mcu_rxd));
300
301         res = (struct mt7915_mcu_eeprom_info *)skb->data;
302         buf = dev->mt76.eeprom.data + le32_to_cpu(res->addr);
303         memcpy(buf, res->data, 16);
304
305         return 0;
306 }
307
308 static int
309 mt7915_mcu_parse_response(struct mt7915_dev *dev, int cmd,
310                           struct sk_buff *skb, int seq)
311 {
312         struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
313         int ret = 0;
314
315         if (seq != rxd->seq)
316                 return -EAGAIN;
317
318         switch (cmd) {
319         case -MCU_CMD_PATCH_SEM_CONTROL:
320                 skb_pull(skb, sizeof(*rxd) - 4);
321                 ret = *skb->data;
322                 break;
323         case MCU_EXT_CMD_THERMAL_CTRL:
324                 skb_pull(skb, sizeof(*rxd) + 4);
325                 ret = le32_to_cpu(*(__le32 *)skb->data);
326                 break;
327         case MCU_EXT_CMD_EFUSE_ACCESS:
328                 ret = mt7915_mcu_parse_eeprom(dev, skb);
329                 break;
330         default:
331                 break;
332         }
333         dev_kfree_skb(skb);
334
335         return ret;
336 }
337
338 static int
339 mt7915_mcu_wait_response(struct mt7915_dev *dev, int cmd, int seq)
340 {
341         unsigned long expires = jiffies + 20 * HZ;
342         struct sk_buff *skb;
343         int ret = 0;
344
345         while (true) {
346                 skb = mt76_mcu_get_response(&dev->mt76, expires);
347                 if (!skb) {
348                         dev_err(dev->mt76.dev, "Message %d (seq %d) timeout\n",
349                                 cmd, seq);
350                         return -ETIMEDOUT;
351                 }
352
353                 ret = mt7915_mcu_parse_response(dev, cmd, skb, seq);
354                 if (ret != -EAGAIN)
355                         break;
356         }
357
358         return ret;
359 }
360
361 static int
362 mt7915_mcu_send_message(struct mt76_dev *mdev, struct sk_buff *skb,
363                         int cmd, bool wait_resp)
364 {
365         struct mt7915_dev *dev = container_of(mdev, struct mt7915_dev, mt76);
366         int ret, seq;
367
368         mutex_lock(&mdev->mcu.mutex);
369
370         ret = __mt7915_mcu_msg_send(dev, skb, cmd, &seq);
371         if (ret)
372                 goto out;
373
374         if (wait_resp)
375                 ret = mt7915_mcu_wait_response(dev, cmd, seq);
376
377 out:
378         mutex_unlock(&mdev->mcu.mutex);
379
380         return ret;
381 }
382
383 static int
384 mt7915_mcu_msg_send(struct mt76_dev *mdev, int cmd, const void *data,
385                     int len, bool wait_resp)
386 {
387         struct sk_buff *skb;
388
389         skb = mt76_mcu_msg_alloc(mdev, data, len);
390         if (!skb)
391                 return -ENOMEM;
392
393         return __mt76_mcu_skb_send_msg(mdev, skb, cmd, wait_resp);
394 }
395
396 static void
397 mt7915_mcu_csa_finish(void *priv, u8 *mac, struct ieee80211_vif *vif)
398 {
399         if (vif->csa_active)
400                 ieee80211_csa_finish(vif);
401 }
402
403 static void
404 mt7915_mcu_rx_radar_detected(struct mt7915_dev *dev, struct sk_buff *skb)
405 {
406         struct mt76_phy *mphy = &dev->mt76.phy;
407         struct mt7915_mcu_rdd_report *r;
408
409         r = (struct mt7915_mcu_rdd_report *)skb->data;
410
411         if (r->idx && dev->mt76.phy2)
412                 mphy = dev->mt76.phy2;
413
414         ieee80211_radar_detected(mphy->hw);
415         dev->hw_pattern++;
416 }
417
418 static void
419 mt7915_mcu_tx_rate_cal(struct mt76_phy *mphy, struct mt7915_mcu_ra_info *ra,
420                        struct rate_info *rate, u16 r)
421 {
422         struct ieee80211_supported_band *sband;
423         u16 ru_idx = le16_to_cpu(ra->ru_idx);
424         u16 flags = 0;
425
426         rate->mcs = FIELD_GET(MT_RA_RATE_MCS, r);
427         rate->nss = FIELD_GET(MT_RA_RATE_NSS, r) + 1;
428
429         switch (FIELD_GET(MT_RA_RATE_TX_MODE, r)) {
430         case MT_PHY_TYPE_CCK:
431         case MT_PHY_TYPE_OFDM:
432                 if (mphy->chandef.chan->band == NL80211_BAND_5GHZ)
433                         sband = &mphy->sband_5g.sband;
434                 else
435                         sband = &mphy->sband_2g.sband;
436
437                 rate->legacy = sband->bitrates[rate->mcs].bitrate;
438                 break;
439         case MT_PHY_TYPE_HT:
440         case MT_PHY_TYPE_HT_GF:
441                 rate->mcs += (rate->nss - 1) * 8;
442                 flags |= RATE_INFO_FLAGS_MCS;
443
444                 if (ra->gi)
445                         flags |= RATE_INFO_FLAGS_SHORT_GI;
446                 break;
447         case MT_PHY_TYPE_VHT:
448                 flags |= RATE_INFO_FLAGS_VHT_MCS;
449
450                 if (ra->gi)
451                         flags |= RATE_INFO_FLAGS_SHORT_GI;
452                 break;
453         case MT_PHY_TYPE_HE_SU:
454         case MT_PHY_TYPE_HE_EXT_SU:
455         case MT_PHY_TYPE_HE_TB:
456         case MT_PHY_TYPE_HE_MU:
457                 rate->he_gi = ra->gi;
458                 rate->he_dcm = FIELD_GET(MT_RA_RATE_DCM_EN, r);
459
460                 flags |= RATE_INFO_FLAGS_HE_MCS;
461                 break;
462         default:
463                 break;
464         }
465         rate->flags = flags;
466
467         if (ru_idx) {
468                 switch (ru_idx) {
469                 case 1 ... 2:
470                         rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_996;
471                         break;
472                 case 3 ... 6:
473                         rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_484;
474                         break;
475                 case 7 ... 14:
476                         rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_242;
477                         break;
478                 default:
479                         rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_106;
480                         break;
481                 }
482                 rate->bw = RATE_INFO_BW_HE_RU;
483         } else {
484                 u8 bw = mt7915_mcu_chan_bw(&mphy->chandef) -
485                         FIELD_GET(MT_RA_RATE_BW, r);
486
487                 switch (bw) {
488                 case IEEE80211_STA_RX_BW_160:
489                         rate->bw = RATE_INFO_BW_160;
490                         break;
491                 case IEEE80211_STA_RX_BW_80:
492                         rate->bw = RATE_INFO_BW_80;
493                         break;
494                 case IEEE80211_STA_RX_BW_40:
495                         rate->bw = RATE_INFO_BW_40;
496                         break;
497                 default:
498                         rate->bw = RATE_INFO_BW_20;
499                         break;
500                 }
501         }
502 }
503
504 static void
505 mt7915_mcu_tx_rate_report(struct mt7915_dev *dev, struct sk_buff *skb)
506 {
507         struct mt7915_mcu_ra_info *ra = (struct mt7915_mcu_ra_info *)skb->data;
508         u16 wcidx = le16_to_cpu(ra->wlan_idx);
509         struct mt76_wcid *wcid = rcu_dereference(dev->mt76.wcid[wcidx]);
510         struct mt7915_sta *msta = container_of(wcid, struct mt7915_sta, wcid);
511         struct mt7915_sta_stats *stats = &msta->stats;
512         struct mt76_phy *mphy = &dev->mphy;
513         struct rate_info rate = {}, prob_rate = {};
514         u16 attempts = le16_to_cpu(ra->attempts);
515         u16 curr = le16_to_cpu(ra->curr_rate);
516         u16 probe = le16_to_cpu(ra->prob_up_rate);
517
518         if (msta->wcid.ext_phy && dev->mt76.phy2)
519                 mphy = dev->mt76.phy2;
520
521         /* current rate */
522         mt7915_mcu_tx_rate_cal(mphy, ra, &rate, curr);
523         stats->tx_rate = rate;
524
525         /* probing rate */
526         mt7915_mcu_tx_rate_cal(mphy, ra, &prob_rate, probe);
527         stats->prob_rate = prob_rate;
528
529         if (attempts) {
530                 u16 success = le16_to_cpu(ra->success);
531
532                 stats->per = 1000 * (attempts - success) / attempts;
533         }
534 }
535
536 static void
537 mt7915_mcu_rx_log_message(struct mt7915_dev *dev, struct sk_buff *skb)
538 {
539         struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
540         const char *data = (char *)&rxd[1];
541         const char *type;
542
543         switch (rxd->s2d_index) {
544         case 0:
545                 type = "WM";
546                 break;
547         case 2:
548                 type = "WA";
549                 break;
550         default:
551                 type = "unknown";
552                 break;
553         }
554
555         wiphy_info(mt76_hw(dev)->wiphy, "%s: %s", type, data);
556 }
557
558 static void
559 mt7915_mcu_rx_ext_event(struct mt7915_dev *dev, struct sk_buff *skb)
560 {
561         struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
562
563         switch (rxd->ext_eid) {
564         case MCU_EXT_EVENT_RDD_REPORT:
565                 mt7915_mcu_rx_radar_detected(dev, skb);
566                 break;
567         case MCU_EXT_EVENT_CSA_NOTIFY:
568                 ieee80211_iterate_active_interfaces_atomic(dev->mt76.hw,
569                                 IEEE80211_IFACE_ITER_RESUME_ALL,
570                                 mt7915_mcu_csa_finish, dev);
571                 break;
572         case MCU_EXT_EVENT_RATE_REPORT:
573                 mt7915_mcu_tx_rate_report(dev, skb);
574                 break;
575         case MCU_EXT_EVENT_FW_LOG_2_HOST:
576                 mt7915_mcu_rx_log_message(dev, skb);
577                 break;
578         default:
579                 break;
580         }
581 }
582
583 static void
584 mt7915_mcu_rx_unsolicited_event(struct mt7915_dev *dev, struct sk_buff *skb)
585 {
586         struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
587
588         switch (rxd->eid) {
589         case MCU_EVENT_EXT:
590                 mt7915_mcu_rx_ext_event(dev, skb);
591                 break;
592         default:
593                 break;
594         }
595         dev_kfree_skb(skb);
596 }
597
598 void mt7915_mcu_rx_event(struct mt7915_dev *dev, struct sk_buff *skb)
599 {
600         struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
601
602         if (rxd->ext_eid == MCU_EXT_EVENT_THERMAL_PROTECT ||
603             rxd->ext_eid == MCU_EXT_EVENT_FW_LOG_2_HOST ||
604             rxd->ext_eid == MCU_EXT_EVENT_ASSERT_DUMP ||
605             rxd->ext_eid == MCU_EXT_EVENT_PS_SYNC ||
606             rxd->ext_eid == MCU_EXT_EVENT_RATE_REPORT ||
607             !rxd->seq)
608                 mt7915_mcu_rx_unsolicited_event(dev, skb);
609         else
610                 mt76_mcu_rx_event(&dev->mt76, skb);
611 }
612
613 static struct sk_buff *
614 mt7915_mcu_alloc_sta_req(struct mt7915_dev *dev, struct mt7915_vif *mvif,
615                          struct mt7915_sta *msta, int len)
616 {
617         struct sta_req_hdr hdr = {
618                 .bss_idx = mvif->idx,
619                 .wlan_idx_lo = msta ? to_wcid_lo(msta->wcid.idx) : 0,
620                 .wlan_idx_hi = msta ? to_wcid_hi(msta->wcid.idx) : 0,
621                 .muar_idx = msta ? mvif->omac_idx : 0,
622                 .is_tlv_append = 1,
623         };
624         struct sk_buff *skb;
625
626         skb = mt76_mcu_msg_alloc(&dev->mt76, NULL, len);
627         if (!skb)
628                 return ERR_PTR(-ENOMEM);
629
630         skb_put_data(skb, &hdr, sizeof(hdr));
631
632         return skb;
633 }
634
635 static struct wtbl_req_hdr *
636 mt7915_mcu_alloc_wtbl_req(struct mt7915_dev *dev, struct mt7915_sta *msta,
637                           int cmd, void *sta_wtbl, struct sk_buff **skb)
638 {
639         struct tlv *sta_hdr = sta_wtbl;
640         struct wtbl_req_hdr hdr = {
641                 .wlan_idx_lo = to_wcid_lo(msta->wcid.idx),
642                 .wlan_idx_hi = to_wcid_hi(msta->wcid.idx),
643                 .operation = cmd,
644         };
645         struct sk_buff *nskb = *skb;
646
647         if (!nskb) {
648                 nskb = mt76_mcu_msg_alloc(&dev->mt76, NULL,
649                                           MT7915_WTBL_UPDATE_BA_SIZE);
650                 if (!nskb)
651                         return ERR_PTR(-ENOMEM);
652
653                 *skb = nskb;
654         }
655
656         if (sta_hdr)
657                 sta_hdr->len = cpu_to_le16(sizeof(hdr));
658
659         return skb_put_data(nskb, &hdr, sizeof(hdr));
660 }
661
662 static struct tlv *
663 mt7915_mcu_add_nested_tlv(struct sk_buff *skb, int tag, int len,
664                           void *sta_ntlv, void *sta_wtbl)
665 {
666         struct sta_ntlv_hdr *ntlv_hdr = sta_ntlv;
667         struct tlv *sta_hdr = sta_wtbl;
668         struct tlv *ptlv, tlv = {
669                 .tag = cpu_to_le16(tag),
670                 .len = cpu_to_le16(len),
671         };
672         u16 ntlv;
673
674         ptlv = skb_put(skb, len);
675         memcpy(ptlv, &tlv, sizeof(tlv));
676
677         ntlv = le16_to_cpu(ntlv_hdr->tlv_num);
678         ntlv_hdr->tlv_num = cpu_to_le16(ntlv + 1);
679
680         if (sta_hdr) {
681                 u16 size = le16_to_cpu(sta_hdr->len);
682
683                 sta_hdr->len = cpu_to_le16(size + len);
684         }
685
686         return ptlv;
687 }
688
689 static struct tlv *
690 mt7915_mcu_add_tlv(struct sk_buff *skb, int tag, int len)
691 {
692         return mt7915_mcu_add_nested_tlv(skb, tag, len, skb->data, NULL);
693 }
694
695 static struct tlv *
696 mt7915_mcu_add_nested_subtlv(struct sk_buff *skb, int sub_tag, int sub_len,
697                              __le16 *sub_ntlv, __le16 *len)
698 {
699         struct tlv *ptlv, tlv = {
700                 .tag = cpu_to_le16(sub_tag),
701                 .len = cpu_to_le16(sub_len),
702         };
703
704         ptlv = skb_put(skb, sub_len);
705         memcpy(ptlv, &tlv, sizeof(tlv));
706
707         *sub_ntlv = cpu_to_le16(le16_to_cpu(*sub_ntlv) + 1);
708         *len = cpu_to_le16(le16_to_cpu(*len) + sub_len);
709
710         return ptlv;
711 }
712
713 /** bss info **/
714 static int
715 mt7915_mcu_bss_basic_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
716                          struct mt7915_phy *phy, bool enable)
717 {
718         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
719         struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
720         enum nl80211_band band = chandef->chan->band;
721         struct bss_info_basic *bss;
722         u16 wlan_idx = mvif->sta.wcid.idx;
723         u32 type = NETWORK_INFRA;
724         struct tlv *tlv;
725
726         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_BASIC, sizeof(*bss));
727
728         switch (vif->type) {
729         case NL80211_IFTYPE_MESH_POINT:
730         case NL80211_IFTYPE_AP:
731                 break;
732         case NL80211_IFTYPE_STATION:
733                 /* TODO: enable BSS_INFO_UAPSD & BSS_INFO_PM */
734                 if (enable) {
735                         struct ieee80211_sta *sta;
736                         struct mt7915_sta *msta;
737
738                         rcu_read_lock();
739                         sta = ieee80211_find_sta(vif, vif->bss_conf.bssid);
740                         if (!sta) {
741                                 rcu_read_unlock();
742                                 return -EINVAL;
743                         }
744
745                         msta = (struct mt7915_sta *)sta->drv_priv;
746                         wlan_idx = msta->wcid.idx;
747                         rcu_read_unlock();
748                 }
749                 break;
750         case NL80211_IFTYPE_ADHOC:
751                 type = NETWORK_IBSS;
752                 break;
753         default:
754                 WARN_ON(1);
755                 break;
756         }
757
758         bss = (struct bss_info_basic *)tlv;
759         memcpy(bss->bssid, vif->bss_conf.bssid, ETH_ALEN);
760         bss->bcn_interval = cpu_to_le16(vif->bss_conf.beacon_int);
761         bss->network_type = cpu_to_le32(type);
762         bss->dtim_period = vif->bss_conf.dtim_period;
763         bss->bmc_wcid_lo = to_wcid_lo(wlan_idx);
764         bss->bmc_wcid_hi = to_wcid_hi(wlan_idx);
765         bss->phy_mode = mt7915_get_phy_mode(phy->dev, vif, band, NULL);
766         bss->wmm_idx = mvif->wmm_idx;
767         bss->active = enable;
768
769         return 0;
770 }
771
772 static void
773 mt7915_mcu_bss_omac_tlv(struct sk_buff *skb, struct ieee80211_vif *vif)
774 {
775         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
776         struct bss_info_omac *omac;
777         struct tlv *tlv;
778         u32 type = 0;
779         u8 idx;
780
781         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_OMAC, sizeof(*omac));
782
783         switch (vif->type) {
784         case NL80211_IFTYPE_MESH_POINT:
785         case NL80211_IFTYPE_AP:
786                 type = CONNECTION_INFRA_AP;
787                 break;
788         case NL80211_IFTYPE_STATION:
789                 type = CONNECTION_INFRA_STA;
790                 break;
791         case NL80211_IFTYPE_ADHOC:
792                 type = CONNECTION_IBSS_ADHOC;
793                 break;
794         default:
795                 WARN_ON(1);
796                 break;
797         }
798
799         omac = (struct bss_info_omac *)tlv;
800         idx = mvif->omac_idx > EXT_BSSID_START ? HW_BSSID_0 : mvif->omac_idx;
801         omac->conn_type = cpu_to_le32(type);
802         omac->omac_idx = mvif->omac_idx;
803         omac->band_idx = mvif->band_idx;
804         omac->hw_bss_idx = idx;
805 }
806
807 struct mt7915_he_obss_narrow_bw_ru_data {
808         bool tolerated;
809 };
810
811 static void mt7915_check_he_obss_narrow_bw_ru_iter(struct wiphy *wiphy,
812                                                    struct cfg80211_bss *bss,
813                                                    void *_data)
814 {
815         struct mt7915_he_obss_narrow_bw_ru_data *data = _data;
816         const struct element *elem;
817
818         elem = ieee80211_bss_get_elem(bss, WLAN_EID_EXT_CAPABILITY);
819
820         if (!elem || elem->datalen < 10 ||
821             !(elem->data[10] &
822               WLAN_EXT_CAPA10_OBSS_NARROW_BW_RU_TOLERANCE_SUPPORT))
823                 data->tolerated = false;
824 }
825
826 static bool mt7915_check_he_obss_narrow_bw_ru(struct ieee80211_hw *hw,
827                                               struct ieee80211_vif *vif)
828 {
829         struct mt7915_he_obss_narrow_bw_ru_data iter_data = {
830                 .tolerated = true,
831         };
832
833         if (!(vif->bss_conf.chandef.chan->flags & IEEE80211_CHAN_RADAR))
834                 return false;
835
836         cfg80211_bss_iter(hw->wiphy, &vif->bss_conf.chandef,
837                           mt7915_check_he_obss_narrow_bw_ru_iter,
838                           &iter_data);
839
840         /*
841          * If there is at least one AP on radar channel that cannot
842          * tolerate 26-tone RU UL OFDMA transmissions using HE TB PPDU.
843          */
844         return !iter_data.tolerated;
845 }
846
847 static void
848 mt7915_mcu_bss_rfch_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
849                         struct mt7915_phy *phy)
850 {
851         struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
852         struct bss_info_rf_ch *ch;
853         struct tlv *tlv;
854         int freq1 = chandef->center_freq1;
855
856         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_RF_CH, sizeof(*ch));
857
858         ch = (struct bss_info_rf_ch *)tlv;
859         ch->pri_ch = chandef->chan->hw_value;
860         ch->center_ch0 = ieee80211_frequency_to_channel(freq1);
861         ch->bw = mt7915_mcu_chan_bw(chandef);
862
863         if (chandef->width == NL80211_CHAN_WIDTH_80P80) {
864                 int freq2 = chandef->center_freq2;
865
866                 ch->center_ch1 = ieee80211_frequency_to_channel(freq2);
867         }
868
869         if (vif->bss_conf.he_support && vif->type == NL80211_IFTYPE_STATION) {
870                 struct mt7915_dev *dev = phy->dev;
871                 struct mt76_phy *mphy = &dev->mt76.phy;
872                 bool ext_phy = phy != &dev->phy;
873
874                 if (ext_phy && dev->mt76.phy2)
875                         mphy = dev->mt76.phy2;
876
877                 ch->he_ru26_block =
878                         mt7915_check_he_obss_narrow_bw_ru(mphy->hw, vif);
879                 ch->he_all_disable = false;
880         } else {
881                 ch->he_all_disable = true;
882         }
883 }
884
885 static void
886 mt7915_mcu_bss_ra_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
887                       struct mt7915_phy *phy)
888 {
889         struct bss_info_ra *ra;
890         struct tlv *tlv;
891         int max_nss = hweight8(phy->chainmask);
892
893         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_RA, sizeof(*ra));
894
895         ra = (struct bss_info_ra *)tlv;
896         ra->op_mode = vif->type == NL80211_IFTYPE_AP;
897         ra->adhoc_en = vif->type == NL80211_IFTYPE_ADHOC;
898         ra->short_preamble = true;
899         ra->tx_streams = max_nss;
900         ra->rx_streams = max_nss;
901         ra->algo = 4;
902         ra->train_up_rule = 2;
903         ra->train_up_high_thres = 110;
904         ra->train_up_rule_rssi = -70;
905         ra->low_traffic_thres = 2;
906         ra->phy_cap = cpu_to_le32(0xfdf);
907         ra->interval = cpu_to_le32(500);
908         ra->fast_interval = cpu_to_le32(100);
909 }
910
911 static void
912 mt7915_mcu_bss_he_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
913                       struct mt7915_phy *phy)
914 {
915 #define DEFAULT_HE_PE_DURATION          4
916 #define DEFAULT_HE_DURATION_RTS_THRES   1023
917         const struct ieee80211_sta_he_cap *cap;
918         struct bss_info_he *he;
919         struct tlv *tlv;
920
921         cap = mt7915_get_he_phy_cap(phy, vif);
922
923         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_HE_BASIC, sizeof(*he));
924
925         he = (struct bss_info_he *)tlv;
926         he->he_pe_duration = vif->bss_conf.htc_trig_based_pkt_ext * 4;
927         if (!he->he_pe_duration)
928                 he->he_pe_duration = DEFAULT_HE_PE_DURATION;
929
930         he->he_rts_thres = cpu_to_le16(vif->bss_conf.frame_time_rts_th * 32);
931         if (!he->he_rts_thres)
932                 he->he_rts_thres = cpu_to_le16(DEFAULT_HE_DURATION_RTS_THRES);
933
934         he->max_nss_mcs[CMD_HE_MCS_BW80] = cap->he_mcs_nss_supp.tx_mcs_80;
935         he->max_nss_mcs[CMD_HE_MCS_BW160] = cap->he_mcs_nss_supp.tx_mcs_160;
936         he->max_nss_mcs[CMD_HE_MCS_BW8080] = cap->he_mcs_nss_supp.tx_mcs_80p80;
937 }
938
939 static void
940 mt7915_mcu_bss_ext_tlv(struct sk_buff *skb, struct mt7915_vif *mvif)
941 {
942 /* SIFS 20us + 512 byte beacon tranmitted by 1Mbps (3906us) */
943 #define BCN_TX_ESTIMATE_TIME    (4096 + 20)
944         struct bss_info_ext_bss *ext;
945         int ext_bss_idx, tsf_offset;
946         struct tlv *tlv;
947
948         ext_bss_idx = mvif->omac_idx - EXT_BSSID_START;
949         if (ext_bss_idx < 0)
950                 return;
951
952         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_EXT_BSS, sizeof(*ext));
953
954         ext = (struct bss_info_ext_bss *)tlv;
955         tsf_offset = ext_bss_idx * BCN_TX_ESTIMATE_TIME;
956         ext->mbss_tsf_offset = cpu_to_le32(tsf_offset);
957 }
958
959 static void
960 mt7915_mcu_bss_bmc_tlv(struct sk_buff *skb, struct mt7915_phy *phy)
961 {
962         struct bss_info_bmc_rate *bmc;
963         struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
964         enum nl80211_band band = chandef->chan->band;
965         struct tlv *tlv;
966
967         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_BMC_RATE, sizeof(*bmc));
968
969         bmc = (struct bss_info_bmc_rate *)tlv;
970         if (band == NL80211_BAND_2GHZ) {
971                 bmc->short_preamble = true;
972         } else {
973                 bmc->bc_trans = cpu_to_le16(0x2000);
974                 bmc->mc_trans = cpu_to_le16(0x2080);
975         }
976 }
977
978 static void
979 mt7915_mcu_bss_sync_tlv(struct sk_buff *skb, struct ieee80211_vif *vif)
980 {
981         struct bss_info_sync_mode *sync;
982         struct tlv *tlv;
983
984         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_SYNC_MODE, sizeof(*sync));
985
986         sync = (struct bss_info_sync_mode *)tlv;
987         sync->bcn_interval = cpu_to_le16(vif->bss_conf.beacon_int);
988         sync->dtim_period = vif->bss_conf.dtim_period;
989         sync->enable = true;
990 }
991
992 int mt7915_mcu_add_bss_info(struct mt7915_phy *phy,
993                             struct ieee80211_vif *vif, int enable)
994 {
995         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
996         struct sk_buff *skb;
997
998         skb = mt7915_mcu_alloc_sta_req(phy->dev, mvif, NULL,
999                                        MT7915_BSS_UPDATE_MAX_SIZE);
1000         if (IS_ERR(skb))
1001                 return PTR_ERR(skb);
1002
1003         /* bss_omac must be first */
1004         if (enable)
1005                 mt7915_mcu_bss_omac_tlv(skb, vif);
1006
1007         mt7915_mcu_bss_basic_tlv(skb, vif, phy, enable);
1008
1009         if (enable) {
1010                 mt7915_mcu_bss_rfch_tlv(skb, vif, phy);
1011                 mt7915_mcu_bss_bmc_tlv(skb, phy);
1012                 mt7915_mcu_bss_ra_tlv(skb, vif, phy);
1013
1014                 if (vif->bss_conf.he_support)
1015                         mt7915_mcu_bss_he_tlv(skb, vif, phy);
1016
1017                 if (mvif->omac_idx > HW_BSSID_MAX)
1018                         mt7915_mcu_bss_ext_tlv(skb, mvif);
1019                 else
1020                         mt7915_mcu_bss_sync_tlv(skb, vif);
1021         }
1022
1023         return __mt76_mcu_skb_send_msg(&phy->dev->mt76, skb,
1024                                        MCU_EXT_CMD_BSS_INFO_UPDATE, true);
1025 }
1026
1027 /** starec & wtbl **/
1028 static int
1029 mt7915_mcu_sta_key_tlv(struct sk_buff *skb, struct ieee80211_key_conf *key,
1030                        enum set_key_cmd cmd)
1031 {
1032         struct sta_rec_sec *sec;
1033         struct tlv *tlv;
1034         u32 len = sizeof(*sec);
1035
1036         tlv = mt7915_mcu_add_tlv(skb, STA_REC_KEY_V2, sizeof(*sec));
1037
1038         sec = (struct sta_rec_sec *)tlv;
1039         sec->add = cmd;
1040
1041         if (cmd == SET_KEY) {
1042                 struct sec_key *sec_key;
1043                 u8 cipher;
1044
1045                 cipher = mt7915_mcu_get_cipher(key->cipher);
1046                 if (cipher == MT_CIPHER_NONE)
1047                         return -EOPNOTSUPP;
1048
1049                 sec_key = &sec->key[0];
1050                 sec_key->cipher_len = sizeof(*sec_key);
1051                 sec_key->key_id = key->keyidx;
1052
1053                 if (cipher == MT_CIPHER_BIP_CMAC_128) {
1054                         sec_key->cipher_id = MT_CIPHER_AES_CCMP;
1055                         sec_key->key_len = 16;
1056                         memcpy(sec_key->key, key->key, 16);
1057
1058                         sec_key = &sec->key[1];
1059                         sec_key->cipher_id = MT_CIPHER_BIP_CMAC_128;
1060                         sec_key->cipher_len = sizeof(*sec_key);
1061                         sec_key->key_len = 16;
1062                         memcpy(sec_key->key, key->key + 16, 16);
1063
1064                         sec->n_cipher = 2;
1065                 } else {
1066                         sec_key->cipher_id = cipher;
1067                         sec_key->key_len = key->keylen;
1068                         memcpy(sec_key->key, key->key, key->keylen);
1069
1070                         if (cipher == MT_CIPHER_TKIP) {
1071                                 /* Rx/Tx MIC keys are swapped */
1072                                 memcpy(sec_key->key + 16, key->key + 24, 8);
1073                                 memcpy(sec_key->key + 24, key->key + 16, 8);
1074                         }
1075
1076                         len -= sizeof(*sec_key);
1077                         sec->n_cipher = 1;
1078                 }
1079         } else {
1080                 len -= sizeof(sec->key);
1081                 sec->n_cipher = 0;
1082         }
1083         sec->len = cpu_to_le16(len);
1084
1085         return 0;
1086 }
1087
1088 int mt7915_mcu_add_key(struct mt7915_dev *dev, struct ieee80211_vif *vif,
1089                        struct mt7915_sta *msta, struct ieee80211_key_conf *key,
1090                        enum set_key_cmd cmd)
1091 {
1092         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1093         struct sk_buff *skb;
1094         int len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_sec);
1095         int ret;
1096
1097         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
1098         if (IS_ERR(skb))
1099                 return PTR_ERR(skb);
1100
1101         ret = mt7915_mcu_sta_key_tlv(skb, key, cmd);
1102         if (ret)
1103                 return ret;
1104
1105         return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1106                                        MCU_EXT_CMD_STA_REC_UPDATE, true);
1107 }
1108
1109 static void
1110 mt7915_mcu_sta_ba_tlv(struct sk_buff *skb,
1111                       struct ieee80211_ampdu_params *params,
1112                       bool enable, bool tx)
1113 {
1114         struct sta_rec_ba *ba;
1115         struct tlv *tlv;
1116
1117         tlv = mt7915_mcu_add_tlv(skb, STA_REC_BA, sizeof(*ba));
1118
1119         ba = (struct sta_rec_ba *)tlv;
1120         ba->ba_type = tx ? MT_BA_TYPE_ORIGINATOR : MT_BA_TYPE_RECIPIENT,
1121         ba->winsize = cpu_to_le16(params->buf_size);
1122         ba->ssn = cpu_to_le16(params->ssn);
1123         ba->ba_en = enable << params->tid;
1124         ba->amsdu = params->amsdu;
1125         ba->tid = params->tid;
1126 }
1127
1128 static void
1129 mt7915_mcu_wtbl_ba_tlv(struct sk_buff *skb,
1130                        struct ieee80211_ampdu_params *params,
1131                        bool enable, bool tx, void *sta_wtbl,
1132                        void *wtbl_tlv)
1133 {
1134         struct wtbl_ba *ba;
1135         struct tlv *tlv;
1136
1137         tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_BA, sizeof(*ba),
1138                                         wtbl_tlv, sta_wtbl);
1139
1140         ba = (struct wtbl_ba *)tlv;
1141         ba->tid = params->tid;
1142
1143         if (tx) {
1144                 ba->ba_type = MT_BA_TYPE_ORIGINATOR;
1145                 ba->sn = enable ? cpu_to_le16(params->ssn) : 0;
1146                 ba->ba_en = enable;
1147         } else {
1148                 memcpy(ba->peer_addr, params->sta->addr, ETH_ALEN);
1149                 ba->ba_type = MT_BA_TYPE_RECIPIENT;
1150                 ba->rst_ba_tid = params->tid;
1151                 ba->rst_ba_sel = RST_BA_MAC_TID_MATCH;
1152                 ba->rst_ba_sb = 1;
1153         }
1154
1155         if (enable && tx)
1156                 ba->ba_winsize = cpu_to_le16(params->buf_size);
1157 }
1158
1159 static int
1160 mt7915_mcu_sta_ba(struct mt7915_dev *dev,
1161                   struct ieee80211_ampdu_params *params,
1162                   bool enable, bool tx)
1163 {
1164         struct mt7915_sta *msta = (struct mt7915_sta *)params->sta->drv_priv;
1165         struct mt7915_vif *mvif = msta->vif;
1166         struct wtbl_req_hdr *wtbl_hdr;
1167         struct tlv *sta_wtbl;
1168         struct sk_buff *skb;
1169
1170         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
1171                                        MT7915_STA_UPDATE_MAX_SIZE);
1172         if (IS_ERR(skb))
1173                 return PTR_ERR(skb);
1174
1175         mt7915_mcu_sta_ba_tlv(skb, params, enable, tx);
1176         sta_wtbl = mt7915_mcu_add_tlv(skb, STA_REC_WTBL, sizeof(struct tlv));
1177
1178         wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_SET, sta_wtbl,
1179                                              &skb);
1180         mt7915_mcu_wtbl_ba_tlv(skb, params, enable, tx, sta_wtbl, wtbl_hdr);
1181
1182         return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1183                                        MCU_EXT_CMD_STA_REC_UPDATE, true);
1184 }
1185
1186 int mt7915_mcu_add_tx_ba(struct mt7915_dev *dev,
1187                          struct ieee80211_ampdu_params *params,
1188                          bool enable)
1189 {
1190         return mt7915_mcu_sta_ba(dev, params, enable, true);
1191 }
1192
1193 int mt7915_mcu_add_rx_ba(struct mt7915_dev *dev,
1194                          struct ieee80211_ampdu_params *params,
1195                          bool enable)
1196 {
1197         return mt7915_mcu_sta_ba(dev, params, enable, false);
1198 }
1199
1200 static void
1201 mt7915_mcu_wtbl_generic_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
1202                             struct ieee80211_sta *sta, void *sta_wtbl,
1203                             void *wtbl_tlv)
1204 {
1205         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1206         struct wtbl_generic *generic;
1207         struct wtbl_rx *rx;
1208         struct tlv *tlv;
1209
1210         tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_GENERIC, sizeof(*generic),
1211                                         wtbl_tlv, sta_wtbl);
1212
1213         generic = (struct wtbl_generic *)tlv;
1214
1215         if (sta) {
1216                 memcpy(generic->peer_addr, sta->addr, ETH_ALEN);
1217                 generic->partial_aid = cpu_to_le16(sta->aid);
1218                 generic->muar_idx = mvif->omac_idx;
1219                 generic->qos = sta->wme;
1220         } else {
1221                 /* use BSSID in station mode */
1222                 if (vif->type == NL80211_IFTYPE_STATION)
1223                         memcpy(generic->peer_addr, vif->bss_conf.bssid,
1224                                ETH_ALEN);
1225                 else
1226                         eth_broadcast_addr(generic->peer_addr);
1227
1228                 generic->muar_idx = 0xe;
1229         }
1230
1231         tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_RX, sizeof(*rx),
1232                                         wtbl_tlv, sta_wtbl);
1233
1234         rx = (struct wtbl_rx *)tlv;
1235         rx->rca1 = sta ? vif->type != NL80211_IFTYPE_AP : 1;
1236         rx->rca2 = 1;
1237         rx->rv = 1;
1238 }
1239
1240 static void
1241 mt7915_mcu_sta_basic_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
1242                          struct ieee80211_sta *sta, bool enable)
1243 {
1244 #define EXTRA_INFO_VER          BIT(0)
1245 #define EXTRA_INFO_NEW          BIT(1)
1246         struct sta_rec_basic *basic;
1247         struct tlv *tlv;
1248
1249         tlv = mt7915_mcu_add_tlv(skb, STA_REC_BASIC, sizeof(*basic));
1250
1251         basic = (struct sta_rec_basic *)tlv;
1252         basic->extra_info = cpu_to_le16(EXTRA_INFO_VER);
1253
1254         if (enable) {
1255                 basic->extra_info |= cpu_to_le16(EXTRA_INFO_NEW);
1256                 basic->conn_state = CONN_STATE_PORT_SECURE;
1257         } else {
1258                 basic->conn_state = CONN_STATE_DISCONNECT;
1259         }
1260
1261         if (!sta) {
1262                 basic->conn_type = cpu_to_le32(CONNECTION_INFRA_BC);
1263                 eth_broadcast_addr(basic->peer_addr);
1264                 return;
1265         }
1266
1267         switch (vif->type) {
1268         case NL80211_IFTYPE_MESH_POINT:
1269         case NL80211_IFTYPE_AP:
1270                 basic->conn_type = cpu_to_le32(CONNECTION_INFRA_STA);
1271                 break;
1272         case NL80211_IFTYPE_STATION:
1273                 basic->conn_type = cpu_to_le32(CONNECTION_INFRA_AP);
1274                 break;
1275         case NL80211_IFTYPE_ADHOC:
1276                 basic->conn_type = cpu_to_le32(CONNECTION_IBSS_ADHOC);
1277                 break;
1278         default:
1279                 WARN_ON(1);
1280                 break;
1281         }
1282
1283         memcpy(basic->peer_addr, sta->addr, ETH_ALEN);
1284         basic->aid = cpu_to_le16(sta->aid);
1285         basic->qos = sta->wme;
1286 }
1287
1288 static void
1289 mt7915_mcu_sta_he_tlv(struct sk_buff *skb, struct ieee80211_sta *sta)
1290 {
1291         struct ieee80211_sta_he_cap *he_cap = &sta->he_cap;
1292         struct ieee80211_he_cap_elem *elem = &he_cap->he_cap_elem;
1293         struct sta_rec_he *he;
1294         struct tlv *tlv;
1295         u32 cap = 0;
1296
1297         tlv = mt7915_mcu_add_tlv(skb, STA_REC_HE, sizeof(*he));
1298
1299         he = (struct sta_rec_he *)tlv;
1300
1301         if (elem->mac_cap_info[0] & IEEE80211_HE_MAC_CAP0_HTC_HE)
1302                 cap |= STA_REC_HE_CAP_HTC;
1303
1304         if (elem->mac_cap_info[2] & IEEE80211_HE_MAC_CAP2_BSR)
1305                 cap |= STA_REC_HE_CAP_BSR;
1306
1307         if (elem->mac_cap_info[3] & IEEE80211_HE_MAC_CAP3_OMI_CONTROL)
1308                 cap |= STA_REC_HE_CAP_OM;
1309
1310         if (elem->mac_cap_info[4] & IEEE80211_HE_MAC_CAP4_AMDSU_IN_AMPDU)
1311                 cap |= STA_REC_HE_CAP_AMSDU_IN_AMPDU;
1312
1313         if (elem->mac_cap_info[4] & IEEE80211_HE_MAC_CAP4_BQR)
1314                 cap |= STA_REC_HE_CAP_BQR;
1315
1316         if (elem->phy_cap_info[0] &
1317             (IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_RU_MAPPING_IN_2G |
1318              IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_RU_MAPPING_IN_5G))
1319                 cap |= STA_REC_HE_CAP_BW20_RU242_SUPPORT;
1320
1321         if (elem->phy_cap_info[1] &
1322             IEEE80211_HE_PHY_CAP1_LDPC_CODING_IN_PAYLOAD)
1323                 cap |= STA_REC_HE_CAP_LDPC;
1324
1325         if (elem->phy_cap_info[1] &
1326             IEEE80211_HE_PHY_CAP1_HE_LTF_AND_GI_FOR_HE_PPDUS_0_8US)
1327                 cap |= STA_REC_HE_CAP_SU_PPDU_1LTF_8US_GI;
1328
1329         if (elem->phy_cap_info[2] &
1330             IEEE80211_HE_PHY_CAP2_NDP_4x_LTF_AND_3_2US)
1331                 cap |= STA_REC_HE_CAP_NDP_4LTF_3DOT2MS_GI;
1332
1333         if (elem->phy_cap_info[2] &
1334             IEEE80211_HE_PHY_CAP2_STBC_TX_UNDER_80MHZ)
1335                 cap |= STA_REC_HE_CAP_LE_EQ_80M_TX_STBC;
1336
1337         if (elem->phy_cap_info[2] &
1338             IEEE80211_HE_PHY_CAP2_STBC_RX_UNDER_80MHZ)
1339                 cap |= STA_REC_HE_CAP_LE_EQ_80M_RX_STBC;
1340
1341         if (elem->phy_cap_info[6] &
1342             IEEE80211_HE_PHY_CAP6_PARTIAL_BW_EXT_RANGE)
1343                 cap |= STA_REC_HE_CAP_PARTIAL_BW_EXT_RANGE;
1344
1345         if (elem->phy_cap_info[7] &
1346             IEEE80211_HE_PHY_CAP7_HE_SU_MU_PPDU_4XLTF_AND_08_US_GI)
1347                 cap |= STA_REC_HE_CAP_SU_MU_PPDU_4LTF_8US_GI;
1348
1349         if (elem->phy_cap_info[7] &
1350             IEEE80211_HE_PHY_CAP7_STBC_TX_ABOVE_80MHZ)
1351                 cap |= STA_REC_HE_CAP_GT_80M_TX_STBC;
1352
1353         if (elem->phy_cap_info[7] &
1354             IEEE80211_HE_PHY_CAP7_STBC_RX_ABOVE_80MHZ)
1355                 cap |= STA_REC_HE_CAP_GT_80M_RX_STBC;
1356
1357         if (elem->phy_cap_info[8] &
1358             IEEE80211_HE_PHY_CAP8_HE_ER_SU_PPDU_4XLTF_AND_08_US_GI)
1359                 cap |= STA_REC_HE_CAP_ER_SU_PPDU_4LTF_8US_GI;
1360
1361         if (elem->phy_cap_info[8] &
1362             IEEE80211_HE_PHY_CAP8_HE_ER_SU_1XLTF_AND_08_US_GI)
1363                 cap |= STA_REC_HE_CAP_ER_SU_PPDU_1LTF_8US_GI;
1364
1365         if (elem->phy_cap_info[9] &
1366             IEEE80211_HE_PHY_CAP9_NON_TRIGGERED_CQI_FEEDBACK)
1367                 cap |= STA_REC_HE_CAP_TRIG_CQI_FK;
1368
1369         if (elem->phy_cap_info[9] &
1370             IEEE80211_HE_PHY_CAP9_TX_1024_QAM_LESS_THAN_242_TONE_RU)
1371                 cap |= STA_REC_HE_CAP_TX_1024QAM_UNDER_RU242;
1372
1373         if (elem->phy_cap_info[9] &
1374             IEEE80211_HE_PHY_CAP9_RX_1024_QAM_LESS_THAN_242_TONE_RU)
1375                 cap |= STA_REC_HE_CAP_RX_1024QAM_UNDER_RU242;
1376
1377         he->he_cap = cpu_to_le32(cap);
1378
1379         switch (sta->bandwidth) {
1380         case IEEE80211_STA_RX_BW_160:
1381                 if (elem->phy_cap_info[0] &
1382                     IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_80PLUS80_MHZ_IN_5G)
1383                         he->max_nss_mcs[CMD_HE_MCS_BW8080] =
1384                                 he_cap->he_mcs_nss_supp.rx_mcs_80p80;
1385
1386                 he->max_nss_mcs[CMD_HE_MCS_BW160] =
1387                                 he_cap->he_mcs_nss_supp.rx_mcs_160;
1388                 /* fall through */
1389         default:
1390                 he->max_nss_mcs[CMD_HE_MCS_BW80] =
1391                                 he_cap->he_mcs_nss_supp.rx_mcs_80;
1392                 break;
1393         }
1394
1395         he->t_frame_dur =
1396                 HE_MAC(CAP1_TF_MAC_PAD_DUR_MASK, elem->mac_cap_info[1]);
1397         he->max_ampdu_exp =
1398                 HE_MAC(CAP3_MAX_AMPDU_LEN_EXP_MASK, elem->mac_cap_info[3]);
1399
1400         he->bw_set =
1401                 HE_PHY(CAP0_CHANNEL_WIDTH_SET_MASK, elem->phy_cap_info[0]);
1402         he->device_class =
1403                 HE_PHY(CAP1_DEVICE_CLASS_A, elem->phy_cap_info[1]);
1404         he->punc_pream_rx =
1405                 HE_PHY(CAP1_PREAMBLE_PUNC_RX_MASK, elem->phy_cap_info[1]);
1406
1407         he->dcm_tx_mode =
1408                 HE_PHY(CAP3_DCM_MAX_CONST_TX_MASK, elem->phy_cap_info[3]);
1409         he->dcm_tx_max_nss =
1410                 HE_PHY(CAP3_DCM_MAX_TX_NSS_2, elem->phy_cap_info[3]);
1411         he->dcm_rx_mode =
1412                 HE_PHY(CAP3_DCM_MAX_CONST_RX_MASK, elem->phy_cap_info[3]);
1413         he->dcm_rx_max_nss =
1414                 HE_PHY(CAP3_DCM_MAX_RX_NSS_2, elem->phy_cap_info[3]);
1415         he->dcm_rx_max_nss =
1416                 HE_PHY(CAP8_DCM_MAX_RU_MASK, elem->phy_cap_info[8]);
1417
1418         he->pkt_ext = 2;
1419 }
1420
1421 static void
1422 mt7915_mcu_sta_muru_tlv(struct sk_buff *skb, struct ieee80211_sta *sta)
1423 {
1424         struct ieee80211_sta_he_cap *he_cap = &sta->he_cap;
1425         struct ieee80211_he_cap_elem *elem = &he_cap->he_cap_elem;
1426         struct sta_rec_muru *muru;
1427         struct tlv *tlv;
1428
1429         tlv = mt7915_mcu_add_tlv(skb, STA_REC_MURU, sizeof(*muru));
1430
1431         muru = (struct sta_rec_muru *)tlv;
1432         muru->cfg.ofdma_dl_en = true;
1433         muru->cfg.ofdma_ul_en = true;
1434         muru->cfg.mimo_dl_en = true;
1435         muru->cfg.mimo_ul_en = true;
1436
1437         muru->ofdma_dl.punc_pream_rx =
1438                 HE_PHY(CAP1_PREAMBLE_PUNC_RX_MASK, elem->phy_cap_info[1]);
1439         muru->ofdma_dl.he_20m_in_40m_2g =
1440                 HE_PHY(CAP8_20MHZ_IN_40MHZ_HE_PPDU_IN_2G, elem->phy_cap_info[8]);
1441         muru->ofdma_dl.he_20m_in_160m =
1442                 HE_PHY(CAP8_20MHZ_IN_160MHZ_HE_PPDU, elem->phy_cap_info[8]);
1443         muru->ofdma_dl.he_80m_in_160m =
1444                 HE_PHY(CAP8_80MHZ_IN_160MHZ_HE_PPDU, elem->phy_cap_info[8]);
1445         muru->ofdma_dl.lt16_sigb = 0;
1446         muru->ofdma_dl.rx_su_comp_sigb = 0;
1447         muru->ofdma_dl.rx_su_non_comp_sigb = 0;
1448
1449         muru->ofdma_ul.t_frame_dur =
1450                 HE_MAC(CAP1_TF_MAC_PAD_DUR_MASK, elem->mac_cap_info[1]);
1451         muru->ofdma_ul.mu_cascading =
1452                 HE_MAC(CAP2_MU_CASCADING, elem->mac_cap_info[2]);
1453         muru->ofdma_ul.uo_ra =
1454                 HE_MAC(CAP3_OFDMA_RA, elem->mac_cap_info[3]);
1455         muru->ofdma_ul.he_2x996_tone = 0;
1456         muru->ofdma_ul.rx_t_frame_11ac = 0;
1457
1458         muru->mimo_dl.vht_mu_bfee =
1459                 !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_MU_BEAMFORMEE_CAPABLE);
1460         muru->mimo_dl.partial_bw_dl_mimo =
1461                 HE_PHY(CAP6_PARTIAL_BANDWIDTH_DL_MUMIMO, elem->phy_cap_info[6]);
1462
1463         muru->mimo_ul.full_ul_mimo =
1464                 HE_PHY(CAP2_UL_MU_FULL_MU_MIMO, elem->phy_cap_info[2]);
1465         muru->mimo_ul.partial_ul_mimo =
1466                 HE_PHY(CAP2_UL_MU_PARTIAL_MU_MIMO, elem->phy_cap_info[2]);
1467 }
1468
1469 static void
1470 mt7915_mcu_sta_tlv(struct mt7915_dev *dev, struct sk_buff *skb,
1471                    struct ieee80211_sta *sta)
1472 {
1473         struct tlv *tlv;
1474
1475         if (sta->ht_cap.ht_supported) {
1476                 struct sta_rec_ht *ht;
1477
1478                 /* starec ht */
1479                 tlv = mt7915_mcu_add_tlv(skb, STA_REC_HT, sizeof(*ht));
1480                 ht = (struct sta_rec_ht *)tlv;
1481                 ht->ht_cap = cpu_to_le16(sta->ht_cap.cap);
1482         }
1483
1484         /* starec vht */
1485         if (sta->vht_cap.vht_supported) {
1486                 struct sta_rec_vht *vht;
1487
1488                 tlv = mt7915_mcu_add_tlv(skb, STA_REC_VHT, sizeof(*vht));
1489                 vht = (struct sta_rec_vht *)tlv;
1490                 vht->vht_cap = cpu_to_le32(sta->vht_cap.cap);
1491                 vht->vht_rx_mcs_map = sta->vht_cap.vht_mcs.rx_mcs_map;
1492                 vht->vht_tx_mcs_map = sta->vht_cap.vht_mcs.tx_mcs_map;
1493         }
1494
1495         /* starec he */
1496         if (sta->he_cap.has_he)
1497                 mt7915_mcu_sta_he_tlv(skb, sta);
1498
1499         /* starec muru */
1500         if (sta->he_cap.has_he || sta->vht_cap.vht_supported)
1501                 mt7915_mcu_sta_muru_tlv(skb, sta);
1502 }
1503
1504 static void
1505 mt7915_mcu_wtbl_smps_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1506                          void *sta_wtbl, void *wtbl_tlv)
1507 {
1508         struct wtbl_smps *smps;
1509         struct tlv *tlv;
1510
1511         tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_SMPS, sizeof(*smps),
1512                                         wtbl_tlv, sta_wtbl);
1513         smps = (struct wtbl_smps *)tlv;
1514
1515         if (sta->smps_mode == IEEE80211_SMPS_DYNAMIC)
1516                 smps->smps = true;
1517 }
1518
1519 static void
1520 mt7915_mcu_wtbl_ht_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1521                        void *sta_wtbl, void *wtbl_tlv)
1522 {
1523         struct wtbl_ht *ht = NULL;
1524         struct tlv *tlv;
1525
1526         /* wtbl ht */
1527         if (sta->ht_cap.ht_supported) {
1528                 tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_HT, sizeof(*ht),
1529                                                 wtbl_tlv, sta_wtbl);
1530                 ht = (struct wtbl_ht *)tlv;
1531                 ht->ldpc = sta->ht_cap.cap & IEEE80211_HT_CAP_LDPC_CODING;
1532                 ht->af = sta->ht_cap.ampdu_factor;
1533                 ht->mm = sta->ht_cap.ampdu_density;
1534                 ht->ht = true;
1535         }
1536
1537         /* wtbl vht */
1538         if (sta->vht_cap.vht_supported) {
1539                 struct wtbl_vht *vht;
1540                 u8 af;
1541
1542                 tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_VHT, sizeof(*vht),
1543                                                 wtbl_tlv, sta_wtbl);
1544                 vht = (struct wtbl_vht *)tlv;
1545                 vht->ldpc = sta->vht_cap.cap & IEEE80211_VHT_CAP_RXLDPC,
1546                 vht->vht = true;
1547
1548                 af = FIELD_GET(IEEE80211_VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MASK,
1549                                sta->vht_cap.cap);
1550                 if (ht)
1551                         ht->af = max_t(u8, ht->af, af);
1552         }
1553
1554         mt7915_mcu_wtbl_smps_tlv(skb, sta, sta_wtbl, wtbl_tlv);
1555 }
1556
1557 int mt7915_mcu_add_smps(struct mt7915_dev *dev, struct ieee80211_vif *vif,
1558                         struct ieee80211_sta *sta)
1559 {
1560         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1561         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
1562         struct wtbl_req_hdr *wtbl_hdr;
1563         struct tlv *sta_wtbl;
1564         struct sk_buff *skb;
1565
1566         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
1567                                        MT7915_STA_UPDATE_MAX_SIZE);
1568         if (IS_ERR(skb))
1569                 return PTR_ERR(skb);
1570
1571         sta_wtbl = mt7915_mcu_add_tlv(skb, STA_REC_WTBL, sizeof(struct tlv));
1572
1573         wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_SET, sta_wtbl,
1574                                              &skb);
1575         mt7915_mcu_wtbl_smps_tlv(skb, sta, sta_wtbl, wtbl_hdr);
1576
1577         return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1578                                        MCU_EXT_CMD_STA_REC_UPDATE, true);
1579 }
1580
1581 static void
1582 mt7915_mcu_sta_sounding_rate(struct sta_rec_bf *bf)
1583 {
1584         bf->sounding_phy = MT_PHY_TYPE_OFDM;
1585         bf->ndp_rate = 0;                               /* mcs0 */
1586         bf->ndpa_rate = MT7915_CFEND_RATE_DEFAULT;      /* ofdm 24m */
1587         bf->rept_poll_rate = MT7915_CFEND_RATE_DEFAULT; /* ofdm 24m */
1588 }
1589
1590 static void
1591 mt7915_mcu_sta_bfer_ht(struct ieee80211_sta *sta, struct sta_rec_bf *bf)
1592 {
1593         struct ieee80211_mcs_info *mcs = &sta->ht_cap.mcs;
1594         u8 n = 0;
1595
1596         bf->tx_mode = MT_PHY_TYPE_HT;
1597         bf->bf_cap |= MT_IBF;
1598
1599         if (mcs->tx_params & IEEE80211_HT_MCS_TX_RX_DIFF &&
1600             (mcs->tx_params & IEEE80211_HT_MCS_TX_DEFINED))
1601                 n = FIELD_GET(IEEE80211_HT_MCS_TX_MAX_STREAMS_MASK,
1602                               mcs->tx_params);
1603         else if (mcs->rx_mask[3])
1604                 n = 3;
1605         else if (mcs->rx_mask[2])
1606                 n = 2;
1607         else if (mcs->rx_mask[1])
1608                 n = 1;
1609
1610         bf->nc = min_t(u8, bf->nr, n);
1611         bf->ibf_ncol = bf->nc;
1612
1613         if (sta->bandwidth <= IEEE80211_STA_RX_BW_40 && !bf->nc)
1614                 bf->ibf_timeout = 0x48;
1615 }
1616
1617 static void
1618 mt7915_mcu_sta_bfer_vht(struct ieee80211_sta *sta, struct mt7915_phy *phy,
1619                         struct sta_rec_bf *bf)
1620 {
1621         struct ieee80211_sta_vht_cap *pc = &sta->vht_cap;
1622         struct ieee80211_sta_vht_cap *vc = &phy->mt76->sband_5g.sband.vht_cap;
1623         u8 bfee_nr, bfer_nr, n, tx_ant = hweight8(phy->chainmask) - 1;
1624         u16 mcs_map;
1625
1626         bf->tx_mode = MT_PHY_TYPE_VHT;
1627         bf->bf_cap |= MT_EBF;
1628
1629         mt7915_mcu_sta_sounding_rate(bf);
1630
1631         bfee_nr = FIELD_GET(IEEE80211_VHT_CAP_BEAMFORMEE_STS_MASK,
1632                             pc->cap);
1633         bfer_nr = FIELD_GET(IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_MASK,
1634                             vc->cap);
1635         mcs_map = le16_to_cpu(pc->vht_mcs.rx_mcs_map);
1636
1637         n = min_t(u8, bfer_nr, bfee_nr);
1638         bf->nr = min_t(u8, n, tx_ant);
1639         n = mt7915_mcu_get_sta_nss(mcs_map);
1640
1641         bf->nc = min_t(u8, n, bf->nr);
1642         bf->ibf_ncol = bf->nc;
1643
1644         /* force nr from 4 to 2 */
1645         if (sta->bandwidth == IEEE80211_STA_RX_BW_160)
1646                 bf->nr = 1;
1647 }
1648
1649 static void
1650 mt7915_mcu_sta_bfer_he(struct ieee80211_sta *sta, struct ieee80211_vif *vif,
1651                        struct mt7915_phy *phy, struct sta_rec_bf *bf)
1652 {
1653         struct ieee80211_sta_he_cap *pc = &sta->he_cap;
1654         struct ieee80211_he_cap_elem *pe = &pc->he_cap_elem;
1655         const struct ieee80211_he_cap_elem *ve;
1656         const struct ieee80211_sta_he_cap *vc;
1657         u8 bfee_nr, bfer_nr, nss_mcs;
1658         u16 mcs_map;
1659
1660         vc = mt7915_get_he_phy_cap(phy, vif);
1661         ve = &vc->he_cap_elem;
1662
1663         bf->tx_mode = MT_PHY_TYPE_HE_SU;
1664         bf->bf_cap |= MT_EBF;
1665
1666         mt7915_mcu_sta_sounding_rate(bf);
1667
1668         bf->trigger_su = HE_PHY(CAP6_TRIG_SU_BEAMFORMER_FB,
1669                                 pe->phy_cap_info[6]);
1670         bf->trigger_mu = HE_PHY(CAP6_TRIG_MU_BEAMFORMER_FB,
1671                                 pe->phy_cap_info[6]);
1672         bfer_nr = HE_PHY(CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_MASK,
1673                          ve->phy_cap_info[5]);
1674         bfee_nr = HE_PHY(CAP4_BEAMFORMEE_MAX_STS_UNDER_80MHZ_MASK,
1675                          pe->phy_cap_info[4]);
1676
1677         mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.tx_mcs_80);
1678         nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
1679
1680         bf->nr = min_t(u8, bfer_nr, bfee_nr);
1681         bf->nc = min_t(u8, nss_mcs, bf->nr);
1682         bf->ibf_ncol = bf->nc;
1683
1684         if (sta->bandwidth != IEEE80211_STA_RX_BW_160)
1685                 return;
1686
1687         /* go over for 160MHz and 80p80 */
1688         if (pe->phy_cap_info[0] &
1689             IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_160MHZ_IN_5G) {
1690                 mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.rx_mcs_160);
1691                 nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
1692
1693                 bf->nc_bw160 = nss_mcs;
1694         }
1695
1696         if (pe->phy_cap_info[0] &
1697             IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_80PLUS80_MHZ_IN_5G) {
1698                 mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.rx_mcs_80p80);
1699                 nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
1700
1701                 if (bf->nc_bw160)
1702                         bf->nc_bw160 = min_t(u8, bf->nc_bw160, nss_mcs);
1703                 else
1704                         bf->nc_bw160 = nss_mcs;
1705         }
1706
1707         bfer_nr = HE_PHY(CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_MASK,
1708                          ve->phy_cap_info[5]);
1709         bfee_nr = HE_PHY(CAP4_BEAMFORMEE_MAX_STS_ABOVE_80MHZ_MASK,
1710                          pe->phy_cap_info[4]);
1711
1712         bf->nr_bw160 = min_t(int, bfer_nr, bfee_nr);
1713 }
1714
1715 static void
1716 mt7915_mcu_sta_bfer_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1717                         struct ieee80211_vif *vif, struct mt7915_phy *phy,
1718                         bool enable)
1719 {
1720         struct sta_rec_bf *bf;
1721         struct tlv *tlv;
1722         int tx_ant = hweight8(phy->chainmask) - 1;
1723         const u8 matrix[4][4] = {
1724                 {0, 0, 0, 0},
1725                 {1, 1, 0, 0},   /* 2x1, 2x2, 2x3, 2x4 */
1726                 {2, 4, 4, 0},   /* 3x1, 3x2, 3x3, 3x4 */
1727                 {3, 5, 6, 0}    /* 4x1, 4x2, 4x3, 4x4 */
1728         };
1729
1730 #define MT_BFER_FREE            cpu_to_le16(GENMASK(15, 0))
1731
1732         tlv = mt7915_mcu_add_tlv(skb, STA_REC_BF, sizeof(*bf));
1733         bf = (struct sta_rec_bf *)tlv;
1734
1735         if (!enable) {
1736                 bf->pfmu = MT_BFER_FREE;
1737                 return;
1738         }
1739
1740         bf->bw = sta->bandwidth;
1741         bf->ibf_dbw = sta->bandwidth;
1742         bf->ibf_nrow = tx_ant;
1743         bf->ibf_timeout = 0x18;
1744
1745         if (sta->he_cap.has_he)
1746                 mt7915_mcu_sta_bfer_he(sta, vif, phy, bf);
1747         else if (sta->vht_cap.vht_supported)
1748                 mt7915_mcu_sta_bfer_vht(sta, phy, bf);
1749         else if (sta->ht_cap.ht_supported)
1750                 mt7915_mcu_sta_bfer_ht(sta, bf);
1751
1752         if (bf->bf_cap & MT_EBF && bf->nr != tx_ant)
1753                 bf->mem_20m = matrix[tx_ant][bf->nc];
1754         else
1755                 bf->mem_20m = matrix[bf->nr][bf->nc];
1756
1757         switch (sta->bandwidth) {
1758         case IEEE80211_STA_RX_BW_160:
1759         case IEEE80211_STA_RX_BW_80:
1760                 bf->mem_total = bf->mem_20m * 2;
1761                 break;
1762         case IEEE80211_STA_RX_BW_40:
1763                 bf->mem_total = bf->mem_20m;
1764                 break;
1765         case IEEE80211_STA_RX_BW_20:
1766         default:
1767                 break;
1768         }
1769 }
1770
1771 static void
1772 mt7915_mcu_sta_bfee_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1773                         struct mt7915_phy *phy)
1774 {
1775         struct sta_rec_bfee *bfee;
1776         struct tlv *tlv;
1777         int tx_ant = hweight8(phy->chainmask) - 1;
1778         u8 nr = 0;
1779
1780         tlv = mt7915_mcu_add_tlv(skb, STA_REC_BFEE, sizeof(*bfee));
1781         bfee = (struct sta_rec_bfee *)tlv;
1782
1783         if (sta->he_cap.has_he) {
1784                 struct ieee80211_he_cap_elem *pe = &sta->he_cap.he_cap_elem;
1785
1786                 nr = HE_PHY(CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_MASK,
1787                             pe->phy_cap_info[5]);
1788         } else if (sta->vht_cap.vht_supported) {
1789                 struct ieee80211_sta_vht_cap *pc = &sta->vht_cap;
1790
1791                 nr = FIELD_GET(IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_MASK,
1792                                pc->cap);
1793         }
1794
1795         /* reply with identity matrix to avoid 2x2 BF negative gain */
1796         if (nr == 1 && tx_ant == 2)
1797                 bfee->fb_identity_matrix = true;
1798 }
1799
1800 static u8
1801 mt7915_mcu_sta_txbf_type(struct mt7915_phy *phy, struct ieee80211_vif *vif,
1802                          struct ieee80211_sta *sta)
1803 {
1804         struct mt7915_sta *msta;
1805         u8 type = 0;
1806
1807         if (vif->type != NL80211_IFTYPE_STATION &&
1808             vif->type != NL80211_IFTYPE_AP)
1809                 return 0;
1810
1811         msta = (struct mt7915_sta *)sta->drv_priv;
1812
1813         if (sta->he_cap.has_he) {
1814                 struct ieee80211_he_cap_elem *pe;
1815                 const struct ieee80211_he_cap_elem *ve;
1816                 const struct ieee80211_sta_he_cap *vc;
1817
1818                 pe = &sta->he_cap.he_cap_elem;
1819                 vc = mt7915_get_he_phy_cap(phy, vif);
1820                 ve = &vc->he_cap_elem;
1821
1822                 if ((HE_PHY(CAP3_SU_BEAMFORMER, pe->phy_cap_info[3]) ||
1823                      HE_PHY(CAP4_MU_BEAMFORMER, pe->phy_cap_info[4])) &&
1824                     HE_PHY(CAP4_SU_BEAMFORMEE, ve->phy_cap_info[4]))
1825                         type |= MT_STA_BFEE;
1826
1827                 if ((HE_PHY(CAP3_SU_BEAMFORMER, ve->phy_cap_info[3]) ||
1828                      HE_PHY(CAP4_MU_BEAMFORMER, ve->phy_cap_info[4])) &&
1829                     HE_PHY(CAP4_SU_BEAMFORMEE, pe->phy_cap_info[4]))
1830                         type |= MT_STA_BFER;
1831         } else if (sta->vht_cap.vht_supported) {
1832                 struct ieee80211_sta_vht_cap *pc;
1833                 struct ieee80211_sta_vht_cap *vc;
1834                 u32 cr, ce;
1835
1836                 pc = &sta->vht_cap;
1837                 vc = &phy->mt76->sband_5g.sband.vht_cap;
1838                 cr = IEEE80211_VHT_CAP_SU_BEAMFORMER_CAPABLE |
1839                      IEEE80211_VHT_CAP_MU_BEAMFORMER_CAPABLE;
1840                 ce = IEEE80211_VHT_CAP_SU_BEAMFORMEE_CAPABLE |
1841                      IEEE80211_VHT_CAP_MU_BEAMFORMEE_CAPABLE;
1842
1843                 if ((pc->cap & cr) && (vc->cap & ce))
1844                         type |= MT_STA_BFEE;
1845
1846                 if ((vc->cap & cr) && (pc->cap & ce))
1847                         type |= MT_STA_BFER;
1848         } else if (sta->ht_cap.ht_supported) {
1849                 /* TODO: iBF */
1850         }
1851
1852         return type;
1853 }
1854
1855 static int
1856 mt7915_mcu_add_txbf(struct mt7915_dev *dev, struct ieee80211_vif *vif,
1857                     struct ieee80211_sta *sta, bool enable)
1858 {
1859         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1860         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
1861         struct mt7915_phy *phy;
1862         struct sk_buff *skb;
1863         int r, len;
1864         u8 type;
1865
1866         phy = mvif->band_idx ? mt7915_ext_phy(dev) : &dev->phy;
1867
1868         type = mt7915_mcu_sta_txbf_type(phy, vif, sta);
1869
1870         /* must keep each tag independent */
1871
1872         /* starec bf */
1873         if (type & MT_STA_BFER) {
1874                 len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_bf);
1875
1876                 skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
1877                 if (IS_ERR(skb))
1878                         return PTR_ERR(skb);
1879
1880                 mt7915_mcu_sta_bfer_tlv(skb, sta, vif, phy, enable);
1881
1882                 r = __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1883                                             MCU_EXT_CMD_STA_REC_UPDATE, true);
1884                 if (r)
1885                         return r;
1886         }
1887
1888         /* starec bfee */
1889         if (type & MT_STA_BFEE) {
1890                 len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_bfee);
1891
1892                 skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
1893                 if (IS_ERR(skb))
1894                         return PTR_ERR(skb);
1895
1896                 mt7915_mcu_sta_bfee_tlv(skb, sta, phy);
1897
1898                 r = __mt76_mcu_skb_send_msg(&dev->mt76, skb,
1899                                             MCU_EXT_CMD_STA_REC_UPDATE, true);
1900                 if (r)
1901                         return r;
1902         }
1903
1904         return 0;
1905 }
1906
1907 static void
1908 mt7915_mcu_sta_rate_ctrl_tlv(struct sk_buff *skb, struct mt7915_dev *dev,
1909                              struct ieee80211_vif *vif,
1910                              struct ieee80211_sta *sta)
1911 {
1912         struct cfg80211_chan_def *chandef = &dev->mphy.chandef;
1913         struct sta_rec_ra *ra;
1914         struct tlv *tlv;
1915         enum nl80211_band band = chandef->chan->band;
1916         u32 supp_rate = sta->supp_rates[band];
1917         int n_rates = hweight32(supp_rate);
1918         u32 cap = sta->wme ? STA_CAP_WMM : 0;
1919         u8 i, nss = sta->rx_nss, mcs = 0;
1920
1921         tlv = mt7915_mcu_add_tlv(skb, STA_REC_RA, sizeof(*ra));
1922
1923         ra = (struct sta_rec_ra *)tlv;
1924         ra->valid = true;
1925         ra->auto_rate = true;
1926         ra->phy_mode = mt7915_get_phy_mode(dev, vif, band, sta);
1927         ra->channel = chandef->chan->hw_value;
1928         ra->bw = sta->bandwidth;
1929         ra->rate_len = n_rates;
1930         ra->phy.bw = sta->bandwidth;
1931
1932         if (n_rates) {
1933                 if (band == NL80211_BAND_2GHZ) {
1934                         ra->supp_mode = MODE_CCK;
1935                         ra->supp_cck_rate = supp_rate & GENMASK(3, 0);
1936                         ra->phy.type = MT_PHY_TYPE_CCK;
1937
1938                         if (n_rates > 4) {
1939                                 ra->supp_mode |= MODE_OFDM;
1940                                 ra->supp_ofdm_rate = supp_rate >> 4;
1941                                 ra->phy.type = MT_PHY_TYPE_OFDM;
1942                         }
1943                 } else {
1944                         ra->supp_mode = MODE_OFDM;
1945                         ra->supp_ofdm_rate = supp_rate;
1946                         ra->phy.type = MT_PHY_TYPE_OFDM;
1947                 }
1948         }
1949
1950         if (sta->ht_cap.ht_supported) {
1951                 for (i = 0; i < nss; i++)
1952                         ra->ht_mcs[i] = sta->ht_cap.mcs.rx_mask[i];
1953
1954                 ra->supp_ht_mcs = *(__le32 *)ra->ht_mcs;
1955                 ra->supp_mode |= MODE_HT;
1956                 mcs = hweight32(le32_to_cpu(ra->supp_ht_mcs)) - 1;
1957                 ra->af = sta->ht_cap.ampdu_factor;
1958                 ra->ht_gf = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_GRN_FLD);
1959
1960                 cap |= STA_CAP_HT;
1961                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_SGI_20)
1962                         cap |= STA_CAP_SGI_20;
1963                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_SGI_40)
1964                         cap |= STA_CAP_SGI_40;
1965                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_TX_STBC)
1966                         cap |= STA_CAP_TX_STBC;
1967                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_RX_STBC)
1968                         cap |= STA_CAP_RX_STBC;
1969                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_LDPC_CODING)
1970                         cap |= STA_CAP_LDPC;
1971         }
1972
1973         if (sta->vht_cap.vht_supported) {
1974                 u16 mcs_map = le16_to_cpu(sta->vht_cap.vht_mcs.rx_mcs_map);
1975                 u16 vht_mcs;
1976                 u8 af, mcs_prev;
1977
1978                 af = FIELD_GET(IEEE80211_VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MASK,
1979                                sta->vht_cap.cap);
1980                 ra->af = max_t(u8, ra->af, af);
1981
1982                 cap |= STA_CAP_VHT;
1983                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_SHORT_GI_80)
1984                         cap |= STA_CAP_VHT_SGI_80;
1985                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_SHORT_GI_160)
1986                         cap |= STA_CAP_VHT_SGI_160;
1987                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_TXSTBC)
1988                         cap |= STA_CAP_VHT_TX_STBC;
1989                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_RXSTBC_1)
1990                         cap |= STA_CAP_VHT_RX_STBC;
1991                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_RXLDPC)
1992                         cap |= STA_CAP_VHT_LDPC;
1993
1994                 ra->supp_mode |= MODE_VHT;
1995                 for (mcs = 0, i = 0; i < nss; i++, mcs_map >>= 2) {
1996                         switch (mcs_map & 0x3) {
1997                         case IEEE80211_VHT_MCS_SUPPORT_0_9:
1998                                 vht_mcs = GENMASK(9, 0);
1999                                 break;
2000                         case IEEE80211_VHT_MCS_SUPPORT_0_8:
2001                                 vht_mcs = GENMASK(8, 0);
2002                                 break;
2003                         case IEEE80211_VHT_MCS_SUPPORT_0_7:
2004                                 vht_mcs = GENMASK(7, 0);
2005                                 break;
2006                         default:
2007                                 vht_mcs = 0;
2008                         }
2009
2010                         ra->supp_vht_mcs[i] = cpu_to_le16(vht_mcs);
2011
2012                         mcs_prev = hweight16(vht_mcs) - 1;
2013                         if (mcs_prev > mcs)
2014                                 mcs = mcs_prev;
2015
2016                         /* only support 2ss on 160MHz */
2017                         if (i > 1 && (ra->bw == CMD_CBW_160MHZ ||
2018                                       ra->bw == CMD_CBW_8080MHZ))
2019                                 break;
2020                 }
2021         }
2022
2023         if (sta->he_cap.has_he) {
2024                 ra->supp_mode |= MODE_HE;
2025                 cap |= STA_CAP_HE;
2026         }
2027
2028         ra->sta_status = cpu_to_le32(cap);
2029
2030         switch (BIT(fls(ra->supp_mode) - 1)) {
2031         case MODE_VHT:
2032                 ra->phy.type = MT_PHY_TYPE_VHT;
2033                 ra->phy.mcs = mcs;
2034                 ra->phy.nss = nss;
2035                 ra->phy.stbc = !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_TXSTBC);
2036                 ra->phy.ldpc = !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_RXLDPC);
2037                 ra->phy.sgi =
2038                         !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_SHORT_GI_80);
2039                 break;
2040         case MODE_HT:
2041                 ra->phy.type = MT_PHY_TYPE_HT;
2042                 ra->phy.mcs = mcs;
2043                 ra->phy.ldpc = sta->ht_cap.cap & IEEE80211_HT_CAP_LDPC_CODING;
2044                 ra->phy.stbc = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_TX_STBC);
2045                 ra->phy.sgi = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_SGI_20);
2046                 break;
2047         default:
2048                 break;
2049         }
2050 }
2051
2052 int mt7915_mcu_add_rate_ctrl(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2053                              struct ieee80211_sta *sta)
2054 {
2055         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2056         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
2057         struct sk_buff *skb;
2058         int len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_ra);
2059
2060         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
2061         if (IS_ERR(skb))
2062                 return PTR_ERR(skb);
2063
2064         mt7915_mcu_sta_rate_ctrl_tlv(skb, dev, vif, sta);
2065
2066         return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
2067                                        MCU_EXT_CMD_STA_REC_UPDATE, true);
2068 }
2069
2070 int mt7915_mcu_add_sta_adv(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2071                            struct ieee80211_sta *sta, bool enable)
2072 {
2073         int ret;
2074
2075         if (!sta)
2076                 return 0;
2077
2078         /* must keep the order */
2079         ret = mt7915_mcu_add_txbf(dev, vif, sta, enable);
2080         if (ret)
2081                 return ret;
2082
2083         if (enable)
2084                 return mt7915_mcu_add_rate_ctrl(dev, vif, sta);
2085
2086         return 0;
2087 }
2088
2089 int mt7915_mcu_add_sta(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2090                        struct ieee80211_sta *sta, bool enable)
2091 {
2092         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2093         struct wtbl_req_hdr *wtbl_hdr;
2094         struct mt7915_sta *msta;
2095         struct tlv *sta_wtbl;
2096         struct sk_buff *skb;
2097
2098         msta = sta ? (struct mt7915_sta *)sta->drv_priv : &mvif->sta;
2099
2100         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
2101                                        MT7915_STA_UPDATE_MAX_SIZE);
2102         if (IS_ERR(skb))
2103                 return PTR_ERR(skb);
2104
2105         mt7915_mcu_sta_basic_tlv(skb, vif, sta, enable);
2106         if (enable && sta)
2107                 mt7915_mcu_sta_tlv(dev, skb, sta);
2108
2109         sta_wtbl = mt7915_mcu_add_tlv(skb, STA_REC_WTBL, sizeof(struct tlv));
2110
2111         wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_RESET_AND_SET,
2112                                              sta_wtbl, &skb);
2113         if (enable) {
2114                 mt7915_mcu_wtbl_generic_tlv(skb, vif, sta, sta_wtbl, wtbl_hdr);
2115                 if (sta)
2116                         mt7915_mcu_wtbl_ht_tlv(skb, sta, sta_wtbl, wtbl_hdr);
2117         }
2118
2119         return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
2120                                        MCU_EXT_CMD_STA_REC_UPDATE, true);
2121 }
2122
2123 int mt7915_mcu_set_fixed_rate(struct mt7915_dev *dev,
2124                               struct ieee80211_sta *sta, u32 rate)
2125 {
2126         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
2127         struct mt7915_vif *mvif = msta->vif;
2128         struct sta_rec_ra_fixed *ra;
2129         struct sk_buff *skb;
2130         struct tlv *tlv;
2131         int len = sizeof(struct sta_req_hdr) + sizeof(*ra);
2132
2133         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
2134         if (IS_ERR(skb))
2135                 return PTR_ERR(skb);
2136
2137         tlv = mt7915_mcu_add_tlv(skb, STA_REC_RA_UPDATE, sizeof(*ra));
2138         ra = (struct sta_rec_ra_fixed *)tlv;
2139
2140         if (!rate) {
2141                 ra->field = cpu_to_le32(RATE_PARAM_AUTO);
2142                 goto out;
2143         } else {
2144                 ra->field = cpu_to_le32(RATE_PARAM_FIXED);
2145         }
2146
2147         ra->phy.type = FIELD_GET(RATE_CFG_PHY_TYPE, rate);
2148         ra->phy.bw = FIELD_GET(RATE_CFG_BW, rate);
2149         ra->phy.nss = FIELD_GET(RATE_CFG_NSS, rate);
2150         ra->phy.mcs = FIELD_GET(RATE_CFG_MCS, rate);
2151         ra->phy.stbc = FIELD_GET(RATE_CFG_STBC, rate);
2152
2153         if (ra->phy.bw)
2154                 ra->phy.ldpc = 7;
2155         else
2156                 ra->phy.ldpc = FIELD_GET(RATE_CFG_LDPC, rate) * 7;
2157
2158         /* HT/VHT - SGI: 1, LGI: 0; HE - SGI: 0, MGI: 1, LGI: 2 */
2159         if (ra->phy.type > MT_PHY_TYPE_VHT)
2160                 ra->phy.sgi = ra->phy.mcs * 85;
2161         else
2162                 ra->phy.sgi = ra->phy.mcs * 15;
2163
2164 out:
2165         return __mt76_mcu_skb_send_msg(&dev->mt76, skb,
2166                                        MCU_EXT_CMD_STA_REC_UPDATE, true);
2167 }
2168
2169 int mt7915_mcu_add_dev_info(struct mt7915_dev *dev,
2170                             struct ieee80211_vif *vif, bool enable)
2171 {
2172         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2173         struct {
2174                 struct req_hdr {
2175                         u8 omac_idx;
2176                         u8 dbdc_idx;
2177                         __le16 tlv_num;
2178                         u8 is_tlv_append;
2179                         u8 rsv[3];
2180                 } __packed hdr;
2181                 struct req_tlv {
2182                         __le16 tag;
2183                         __le16 len;
2184                         u8 active;
2185                         u8 dbdc_idx;
2186                         u8 omac_addr[ETH_ALEN];
2187                 } __packed tlv;
2188         } data = {
2189                 .hdr = {
2190                         .omac_idx = mvif->omac_idx,
2191                         .dbdc_idx = mvif->band_idx,
2192                         .tlv_num = cpu_to_le16(1),
2193                         .is_tlv_append = 1,
2194                 },
2195                 .tlv = {
2196                         .tag = cpu_to_le16(DEV_INFO_ACTIVE),
2197                         .len = cpu_to_le16(sizeof(struct req_tlv)),
2198                         .active = enable,
2199                         .dbdc_idx = mvif->band_idx,
2200                 },
2201         };
2202
2203         memcpy(data.tlv.omac_addr, vif->addr, ETH_ALEN);
2204         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_DEV_INFO_UPDATE,
2205                                    &data, sizeof(data), true);
2206 }
2207
2208 static void
2209 mt7915_mcu_beacon_csa(struct sk_buff *rskb, struct sk_buff *skb,
2210                       struct bss_info_bcn *bcn,
2211                       struct ieee80211_mutable_offsets *offs)
2212 {
2213         if (offs->csa_counter_offs[0]) {
2214                 struct tlv *tlv;
2215                 struct bss_info_bcn_csa *csa;
2216
2217                 tlv = mt7915_mcu_add_nested_subtlv(rskb, BSS_INFO_BCN_CSA,
2218                                                    sizeof(*csa), &bcn->sub_ntlv,
2219                                                    &bcn->len);
2220                 csa = (struct bss_info_bcn_csa *)tlv;
2221                 csa->cnt = skb->data[offs->csa_counter_offs[0]];
2222         }
2223 }
2224
2225 static void
2226 mt7915_mcu_beacon_cont(struct mt7915_dev *dev, struct sk_buff *rskb,
2227                        struct sk_buff *skb, struct bss_info_bcn *bcn,
2228                        struct ieee80211_mutable_offsets *offs)
2229 {
2230         struct mt76_wcid *wcid = &dev->mt76.global_wcid;
2231         struct bss_info_bcn_cont *cont;
2232         struct tlv *tlv;
2233         u8 *buf;
2234         int len = sizeof(*cont) + MT_TXD_SIZE + skb->len;
2235
2236         tlv = mt7915_mcu_add_nested_subtlv(rskb, BSS_INFO_BCN_CONTENT,
2237                                            len, &bcn->sub_ntlv, &bcn->len);
2238
2239         cont = (struct bss_info_bcn_cont *)tlv;
2240         cont->pkt_len = cpu_to_le16(MT_TXD_SIZE + skb->len);
2241         cont->tim_ofs = cpu_to_le16(offs->tim_offset);
2242
2243         if (offs->csa_counter_offs[0])
2244                 cont->csa_ofs = cpu_to_le16(offs->csa_counter_offs[0] - 4);
2245
2246         buf = (u8 *)tlv + sizeof(*cont);
2247         mt7915_mac_write_txwi(dev, (__le32 *)buf, skb, wcid, NULL,
2248                               true);
2249         memcpy(buf + MT_TXD_SIZE, skb->data, skb->len);
2250 }
2251
2252 int mt7915_mcu_add_beacon(struct ieee80211_hw *hw,
2253                           struct ieee80211_vif *vif, int en)
2254 {
2255 #define MAX_BEACON_SIZE 512
2256         struct mt7915_dev *dev = mt7915_hw_dev(hw);
2257         struct mt7915_phy *phy = mt7915_hw_phy(hw);
2258         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2259         struct ieee80211_mutable_offsets offs;
2260         struct ieee80211_tx_info *info;
2261         struct sk_buff *skb, *rskb;
2262         struct tlv *tlv;
2263         struct bss_info_bcn *bcn;
2264         int len = MT7915_BEACON_UPDATE_SIZE + MAX_BEACON_SIZE;
2265
2266         rskb = mt7915_mcu_alloc_sta_req(dev, mvif, NULL, len);
2267         if (IS_ERR(rskb))
2268                 return PTR_ERR(rskb);
2269
2270         tlv = mt7915_mcu_add_tlv(rskb, BSS_INFO_OFFLOAD, sizeof(*bcn));
2271         bcn = (struct bss_info_bcn *)tlv;
2272         bcn->enable = en;
2273
2274         skb = ieee80211_beacon_get_template(hw, vif, &offs);
2275         if (!skb)
2276                 return -EINVAL;
2277
2278         if (skb->len > MAX_BEACON_SIZE - MT_TXD_SIZE) {
2279                 dev_err(dev->mt76.dev, "Bcn size limit exceed\n");
2280                 dev_kfree_skb(skb);
2281                 return -EINVAL;
2282         }
2283
2284         if (mvif->band_idx) {
2285                 info = IEEE80211_SKB_CB(skb);
2286                 info->hw_queue |= MT_TX_HW_QUEUE_EXT_PHY;
2287         }
2288
2289         /* TODO: subtag - bss color count & 11v MBSSID */
2290         mt7915_mcu_beacon_csa(rskb, skb, bcn, &offs);
2291         mt7915_mcu_beacon_cont(dev, rskb, skb, bcn, &offs);
2292         dev_kfree_skb(skb);
2293
2294         return __mt76_mcu_skb_send_msg(&phy->dev->mt76, rskb,
2295                                        MCU_EXT_CMD_BSS_INFO_UPDATE, true);
2296 }
2297
2298 static int mt7915_mcu_send_firmware(struct mt7915_dev *dev, const void *data,
2299                                     int len)
2300 {
2301         int ret = 0, cur_len;
2302
2303         while (len > 0) {
2304                 cur_len = min_t(int, 4096 - sizeof(struct mt7915_mcu_txd),
2305                                 len);
2306
2307                 ret = __mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_FW_SCATTER,
2308                                           data, cur_len, false);
2309                 if (ret)
2310                         break;
2311
2312                 data += cur_len;
2313                 len -= cur_len;
2314                 mt76_queue_tx_cleanup(dev, MT_TXQ_FWDL, false);
2315         }
2316
2317         return ret;
2318 }
2319
2320 static int mt7915_mcu_start_firmware(struct mt7915_dev *dev, u32 addr,
2321                                      u32 option)
2322 {
2323         struct {
2324                 __le32 option;
2325                 __le32 addr;
2326         } req = {
2327                 .option = cpu_to_le32(option),
2328                 .addr = cpu_to_le32(addr),
2329         };
2330
2331         return __mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_FW_START_REQ,
2332                                    &req, sizeof(req), true);
2333 }
2334
2335 static int mt7915_mcu_restart(struct mt76_dev *dev)
2336 {
2337         struct {
2338                 u8 power_mode;
2339                 u8 rsv[3];
2340         } req = {
2341                 .power_mode = 1,
2342         };
2343
2344         return __mt76_mcu_send_msg(dev, -MCU_CMD_NIC_POWER_CTRL, &req,
2345                                    sizeof(req), false);
2346 }
2347
2348 static int mt7915_mcu_patch_sem_ctrl(struct mt7915_dev *dev, bool get)
2349 {
2350         struct {
2351                 __le32 op;
2352         } req = {
2353                 .op = cpu_to_le32(get ? PATCH_SEM_GET : PATCH_SEM_RELEASE),
2354         };
2355
2356         return __mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_PATCH_SEM_CONTROL,
2357                                    &req, sizeof(req), true);
2358 }
2359
2360 static int mt7915_mcu_start_patch(struct mt7915_dev *dev)
2361 {
2362         struct {
2363                 u8 check_crc;
2364                 u8 reserved[3];
2365         } req = {
2366                 .check_crc = 0,
2367         };
2368
2369         return __mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_PATCH_FINISH_REQ,
2370                                    &req, sizeof(req), true);
2371 }
2372
2373 static int mt7915_driver_own(struct mt7915_dev *dev)
2374 {
2375         u32 reg = mt7915_reg_map_l1(dev, MT_TOP_LPCR_HOST_BAND0);
2376
2377         mt76_wr(dev, reg, MT_TOP_LPCR_HOST_DRV_OWN);
2378         if (!mt76_poll_msec(dev, reg, MT_TOP_LPCR_HOST_FW_OWN,
2379                             0, 500)) {
2380                 dev_err(dev->mt76.dev, "Timeout for driver own\n");
2381                 return -EIO;
2382         }
2383
2384         return 0;
2385 }
2386
2387 static int mt7915_mcu_init_download(struct mt7915_dev *dev, u32 addr,
2388                                     u32 len, u32 mode)
2389 {
2390         struct {
2391                 __le32 addr;
2392                 __le32 len;
2393                 __le32 mode;
2394         } req = {
2395                 .addr = cpu_to_le32(addr),
2396                 .len = cpu_to_le32(len),
2397                 .mode = cpu_to_le32(mode),
2398         };
2399         int attr;
2400
2401         if (req.addr == cpu_to_le32(MCU_PATCH_ADDRESS))
2402                 attr = -MCU_CMD_PATCH_START_REQ;
2403         else
2404                 attr = -MCU_CMD_TARGET_ADDRESS_LEN_REQ;
2405
2406         return __mt76_mcu_send_msg(&dev->mt76, attr, &req, sizeof(req), true);
2407 }
2408
2409 static int mt7915_load_patch(struct mt7915_dev *dev)
2410 {
2411         const struct mt7915_patch_hdr *hdr;
2412         const struct firmware *fw = NULL;
2413         int i, ret, sem;
2414
2415         sem = mt7915_mcu_patch_sem_ctrl(dev, 1);
2416         switch (sem) {
2417         case PATCH_IS_DL:
2418                 return 0;
2419         case PATCH_NOT_DL_SEM_SUCCESS:
2420                 break;
2421         default:
2422                 dev_err(dev->mt76.dev, "Failed to get patch semaphore\n");
2423                 return -EAGAIN;
2424         }
2425
2426         ret = request_firmware(&fw, MT7915_ROM_PATCH, dev->mt76.dev);
2427         if (ret)
2428                 goto out;
2429
2430         if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
2431                 dev_err(dev->mt76.dev, "Invalid firmware\n");
2432                 ret = -EINVAL;
2433                 goto out;
2434         }
2435
2436         hdr = (const struct mt7915_patch_hdr *)(fw->data);
2437
2438         dev_info(dev->mt76.dev, "HW/SW Version: 0x%x, Build Time: %.16s\n",
2439                  be32_to_cpu(hdr->hw_sw_ver), hdr->build_date);
2440
2441         for (i = 0; i < be32_to_cpu(hdr->desc.n_region); i++) {
2442                 struct mt7915_patch_sec *sec;
2443                 const u8 *dl;
2444                 u32 len, addr;
2445
2446                 sec = (struct mt7915_patch_sec *)(fw->data + sizeof(*hdr) +
2447                                                   i * sizeof(*sec));
2448                 if ((be32_to_cpu(sec->type) & PATCH_SEC_TYPE_MASK) !=
2449                     PATCH_SEC_TYPE_INFO) {
2450                         ret = -EINVAL;
2451                         goto out;
2452                 }
2453
2454                 addr = be32_to_cpu(sec->info.addr);
2455                 len = be32_to_cpu(sec->info.len);
2456                 dl = fw->data + be32_to_cpu(sec->offs);
2457
2458                 ret = mt7915_mcu_init_download(dev, addr, len,
2459                                                DL_MODE_NEED_RSP);
2460                 if (ret) {
2461                         dev_err(dev->mt76.dev, "Download request failed\n");
2462                         goto out;
2463                 }
2464
2465                 ret = mt7915_mcu_send_firmware(dev, dl, len);
2466                 if (ret) {
2467                         dev_err(dev->mt76.dev, "Failed to send patch\n");
2468                         goto out;
2469                 }
2470         }
2471
2472         ret = mt7915_mcu_start_patch(dev);
2473         if (ret)
2474                 dev_err(dev->mt76.dev, "Failed to start patch\n");
2475
2476 out:
2477         sem = mt7915_mcu_patch_sem_ctrl(dev, 0);
2478         switch (sem) {
2479         case PATCH_REL_SEM_SUCCESS:
2480                 break;
2481         default:
2482                 ret = -EAGAIN;
2483                 dev_err(dev->mt76.dev, "Failed to release patch semaphore\n");
2484                 goto out;
2485         }
2486         release_firmware(fw);
2487
2488         return ret;
2489 }
2490
2491 static u32 mt7915_mcu_gen_dl_mode(u8 feature_set, bool is_wa)
2492 {
2493         u32 ret = 0;
2494
2495         ret |= (feature_set & FW_FEATURE_SET_ENCRYPT) ?
2496                (DL_MODE_ENCRYPT | DL_MODE_RESET_SEC_IV) : 0;
2497         ret |= FIELD_PREP(DL_MODE_KEY_IDX,
2498                           FIELD_GET(FW_FEATURE_SET_KEY_IDX, feature_set));
2499         ret |= DL_MODE_NEED_RSP;
2500         ret |= is_wa ? DL_MODE_WORKING_PDA_CR4 : 0;
2501
2502         return ret;
2503 }
2504
2505 static int
2506 mt7915_mcu_send_ram_firmware(struct mt7915_dev *dev,
2507                              const struct mt7915_fw_trailer *hdr,
2508                              const u8 *data, bool is_wa)
2509 {
2510         int i, offset = 0;
2511         u32 override = 0, option = 0;
2512
2513         for (i = 0; i < hdr->n_region; i++) {
2514                 const struct mt7915_fw_region *region;
2515                 int err;
2516                 u32 len, addr, mode;
2517
2518                 region = (const struct mt7915_fw_region *)((const u8 *)hdr -
2519                          (hdr->n_region - i) * sizeof(*region));
2520                 mode = mt7915_mcu_gen_dl_mode(region->feature_set, is_wa);
2521                 len = le32_to_cpu(region->len);
2522                 addr = le32_to_cpu(region->addr);
2523
2524                 if (region->feature_set & FW_FEATURE_OVERRIDE_ADDR)
2525                         override = addr;
2526
2527                 err = mt7915_mcu_init_download(dev, addr, len, mode);
2528                 if (err) {
2529                         dev_err(dev->mt76.dev, "Download request failed\n");
2530                         return err;
2531                 }
2532
2533                 err = mt7915_mcu_send_firmware(dev, data + offset, len);
2534                 if (err) {
2535                         dev_err(dev->mt76.dev, "Failed to send firmware.\n");
2536                         return err;
2537                 }
2538
2539                 offset += len;
2540         }
2541
2542         if (override)
2543                 option |= FW_START_OVERRIDE;
2544
2545         if (is_wa)
2546                 option |= FW_START_WORKING_PDA_CR4;
2547
2548         return mt7915_mcu_start_firmware(dev, override, option);
2549 }
2550
2551 static int mt7915_load_ram(struct mt7915_dev *dev)
2552 {
2553         const struct mt7915_fw_trailer *hdr;
2554         const struct firmware *fw;
2555         int ret;
2556
2557         ret = request_firmware(&fw, MT7915_FIRMWARE_WM, dev->mt76.dev);
2558         if (ret)
2559                 return ret;
2560
2561         if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
2562                 dev_err(dev->mt76.dev, "Invalid firmware\n");
2563                 ret = -EINVAL;
2564                 goto out;
2565         }
2566
2567         hdr = (const struct mt7915_fw_trailer *)(fw->data + fw->size -
2568                                         sizeof(*hdr));
2569
2570         dev_info(dev->mt76.dev, "WM Firmware Version: %.10s, Build Time: %.15s\n",
2571                  hdr->fw_ver, hdr->build_date);
2572
2573         ret = mt7915_mcu_send_ram_firmware(dev, hdr, fw->data, false);
2574         if (ret) {
2575                 dev_err(dev->mt76.dev, "Failed to start WM firmware\n");
2576                 goto out;
2577         }
2578
2579         release_firmware(fw);
2580
2581         ret = request_firmware(&fw, MT7915_FIRMWARE_WA, dev->mt76.dev);
2582         if (ret)
2583                 return ret;
2584
2585         if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
2586                 dev_err(dev->mt76.dev, "Invalid firmware\n");
2587                 ret = -EINVAL;
2588                 goto out;
2589         }
2590
2591         hdr = (const struct mt7915_fw_trailer *)(fw->data + fw->size -
2592                                         sizeof(*hdr));
2593
2594         dev_info(dev->mt76.dev, "WA Firmware Version: %.10s, Build Time: %.15s\n",
2595                  hdr->fw_ver, hdr->build_date);
2596
2597         ret = mt7915_mcu_send_ram_firmware(dev, hdr, fw->data, true);
2598         if (ret) {
2599                 dev_err(dev->mt76.dev, "Failed to start WA firmware\n");
2600                 goto out;
2601         }
2602
2603         snprintf(dev->mt76.hw->wiphy->fw_version,
2604                  sizeof(dev->mt76.hw->wiphy->fw_version),
2605                  "%.10s-%.15s", hdr->fw_ver, hdr->build_date);
2606
2607 out:
2608         release_firmware(fw);
2609
2610         return ret;
2611 }
2612
2613 static int mt7915_load_firmware(struct mt7915_dev *dev)
2614 {
2615         int ret;
2616         u32 val, reg = mt7915_reg_map_l1(dev, MT_TOP_MISC);
2617
2618         val = FIELD_PREP(MT_TOP_MISC_FW_STATE, FW_STATE_FW_DOWNLOAD);
2619
2620         if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE, val, 1000)) {
2621                 /* restart firmware once */
2622                 __mt76_mcu_restart(&dev->mt76);
2623                 if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
2624                                     val, 1000)) {
2625                         dev_err(dev->mt76.dev,
2626                                 "Firmware is not ready for download\n");
2627                         return -EIO;
2628                 }
2629         }
2630
2631         ret = mt7915_load_patch(dev);
2632         if (ret)
2633                 return ret;
2634
2635         ret = mt7915_load_ram(dev);
2636         if (ret)
2637                 return ret;
2638
2639         if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
2640                             FIELD_PREP(MT_TOP_MISC_FW_STATE,
2641                                        FW_STATE_WACPU_RDY), 1000)) {
2642                 dev_err(dev->mt76.dev, "Timeout for initializing firmware\n");
2643                 return -EIO;
2644         }
2645
2646         mt76_queue_tx_cleanup(dev, MT_TXQ_FWDL, false);
2647
2648         dev_dbg(dev->mt76.dev, "Firmware init done\n");
2649
2650         return 0;
2651 }
2652
2653 int mt7915_mcu_fw_log_2_host(struct mt7915_dev *dev, u8 ctrl)
2654 {
2655         struct {
2656                 u8 ctrl_val;
2657                 u8 pad[3];
2658         } data = {
2659                 .ctrl_val = ctrl
2660         };
2661
2662         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_FW_LOG_2_HOST,
2663                                    &data, sizeof(data), true);
2664 }
2665
2666 int mt7915_mcu_fw_dbg_ctrl(struct mt7915_dev *dev, u32 module, u8 level)
2667 {
2668         struct {
2669                 u8 ver;
2670                 u8 pad;
2671                 u16 len;
2672                 u8 level;
2673                 u8 rsv[3];
2674                 __le32 module_idx;
2675         } data = {
2676                 .module_idx = cpu_to_le32(module),
2677                 .level = level,
2678         };
2679
2680         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_FW_DBG_CTRL,
2681                                    &data, sizeof(data), false);
2682 }
2683
2684 int mt7915_mcu_init(struct mt7915_dev *dev)
2685 {
2686         static const struct mt76_mcu_ops mt7915_mcu_ops = {
2687                 .headroom = sizeof(struct mt7915_mcu_txd),
2688                 .mcu_skb_send_msg = mt7915_mcu_send_message,
2689                 .mcu_send_msg = mt7915_mcu_msg_send,
2690                 .mcu_restart = mt7915_mcu_restart,
2691         };
2692         int ret;
2693
2694         dev->mt76.mcu_ops = &mt7915_mcu_ops,
2695
2696         ret = mt7915_driver_own(dev);
2697         if (ret)
2698                 return ret;
2699
2700         ret = mt7915_load_firmware(dev);
2701         if (ret)
2702                 return ret;
2703
2704         set_bit(MT76_STATE_MCU_RUNNING, &dev->mphy.state);
2705         mt7915_mcu_fw_log_2_host(dev, 0);
2706
2707         return 0;
2708 }
2709
2710 void mt7915_mcu_exit(struct mt7915_dev *dev)
2711 {
2712         u32 reg = mt7915_reg_map_l1(dev, MT_TOP_MISC);
2713
2714         __mt76_mcu_restart(&dev->mt76);
2715         if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
2716                             FIELD_PREP(MT_TOP_MISC_FW_STATE,
2717                                        FW_STATE_FW_DOWNLOAD), 1000)) {
2718                 dev_err(dev->mt76.dev, "Failed to exit mcu\n");
2719                 return;
2720         }
2721
2722         reg = mt7915_reg_map_l1(dev, MT_TOP_LPCR_HOST_BAND0);
2723         mt76_wr(dev, reg, MT_TOP_LPCR_HOST_FW_OWN);
2724         skb_queue_purge(&dev->mt76.mcu.res_q);
2725 }
2726
2727 int mt7915_mcu_set_mac(struct mt7915_dev *dev, int band,
2728                        bool enable, bool hdr_trans)
2729 {
2730         struct {
2731                 u8 operation;
2732                 u8 enable;
2733                 u8 check_bssid;
2734                 u8 insert_vlan;
2735                 u8 remove_vlan;
2736                 u8 tid;
2737                 u8 mode;
2738                 u8 rsv;
2739         } __packed req_trans = {
2740                 .enable = hdr_trans,
2741         };
2742         struct {
2743                 u8 enable;
2744                 u8 band;
2745                 u8 rsv[2];
2746         } __packed req_mac = {
2747                 .enable = enable,
2748                 .band = band,
2749         };
2750         int ret;
2751
2752         ret = __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_RX_HDR_TRANS,
2753                                   &req_trans, sizeof(req_trans), false);
2754         if (ret)
2755                 return ret;
2756
2757         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_MAC_INIT_CTRL,
2758                                    &req_mac, sizeof(req_mac), true);
2759 }
2760
2761 int mt7915_mcu_set_scs(struct mt7915_dev *dev, u8 band, bool enable)
2762 {
2763         struct {
2764                 __le32 cmd;
2765                 u8 band;
2766                 u8 enable;
2767         } __packed req = {
2768                 .cmd = cpu_to_le32(SCS_ENABLE),
2769                 .band = band,
2770                 .enable = enable + 1,
2771         };
2772
2773         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SCS_CTRL, &req,
2774                                    sizeof(req), false);
2775 }
2776
2777 int mt7915_mcu_set_rts_thresh(struct mt7915_phy *phy, u32 val)
2778 {
2779         struct mt7915_dev *dev = phy->dev;
2780         struct {
2781                 u8 prot_idx;
2782                 u8 band;
2783                 u8 rsv[2];
2784                 __le32 len_thresh;
2785                 __le32 pkt_thresh;
2786         } __packed req = {
2787                 .prot_idx = 1,
2788                 .band = phy != &dev->phy,
2789                 .len_thresh = cpu_to_le32(val),
2790                 .pkt_thresh = cpu_to_le32(0x2),
2791         };
2792
2793         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_PROTECT_CTRL,
2794                                    &req, sizeof(req), true);
2795 }
2796
2797 int mt7915_mcu_set_tx(struct mt7915_dev *dev, struct ieee80211_vif *vif)
2798 {
2799 #define WMM_AIFS_SET            BIT(0)
2800 #define WMM_CW_MIN_SET          BIT(1)
2801 #define WMM_CW_MAX_SET          BIT(2)
2802 #define WMM_TXOP_SET            BIT(3)
2803 #define WMM_PARAM_SET           GENMASK(3, 0)
2804 #define TX_CMD_MODE             1
2805         struct edca {
2806                 u8 queue;
2807                 u8 set;
2808                 u8 aifs;
2809                 u8 cw_min;
2810                 __le16 cw_max;
2811                 __le16 txop;
2812         };
2813         struct mt7915_mcu_tx {
2814                 u8 total;
2815                 u8 action;
2816                 u8 valid;
2817                 u8 mode;
2818
2819                 struct edca edca[IEEE80211_NUM_ACS];
2820         } __packed req = {
2821                 .valid = true,
2822                 .mode = TX_CMD_MODE,
2823                 .total = IEEE80211_NUM_ACS,
2824         };
2825         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2826         int ac;
2827
2828         for (ac = 0; ac < IEEE80211_NUM_ACS; ac++) {
2829                 struct edca *e = &req.edca[ac];
2830
2831                 e->queue = ac + mvif->wmm_idx * MT7915_MAX_WMM_SETS;
2832                 e->aifs = mvif->wmm[ac].aifs;
2833                 e->txop = cpu_to_le16(mvif->wmm[ac].txop);
2834
2835                 if (mvif->wmm[ac].cw_min)
2836                         e->cw_min = fls(mvif->wmm[ac].cw_max);
2837                 else
2838                         e->cw_min = 5;
2839
2840                 if (mvif->wmm[ac].cw_max)
2841                         e->cw_max = cpu_to_le16(fls(mvif->wmm[ac].cw_max));
2842                 else
2843                         e->cw_max = cpu_to_le16(10);
2844         }
2845
2846         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EDCA_UPDATE,
2847                                   &req, sizeof(req), true);
2848 }
2849
2850 int mt7915_mcu_set_pm(struct mt7915_dev *dev, int band, int enter)
2851 {
2852 #define ENTER_PM_STATE          1
2853 #define EXIT_PM_STATE           2
2854         struct {
2855                 u8 pm_number;
2856                 u8 pm_state;
2857                 u8 bssid[ETH_ALEN];
2858                 u8 dtim_period;
2859                 u8 wlan_idx_lo;
2860                 __le16 bcn_interval;
2861                 __le32 aid;
2862                 __le32 rx_filter;
2863                 u8 band_idx;
2864                 u8 wlan_idx_hi;
2865                 u8 rsv[2];
2866                 __le32 feature;
2867                 u8 omac_idx;
2868                 u8 wmm_idx;
2869                 u8 bcn_loss_cnt;
2870                 u8 bcn_sp_duration;
2871         } __packed req = {
2872                 .pm_number = 5,
2873                 .pm_state = (enter) ? ENTER_PM_STATE : EXIT_PM_STATE,
2874                 .band_idx = band,
2875         };
2876
2877         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_PM_STATE_CTRL,
2878                                    &req, sizeof(req), true);
2879 }
2880
2881 int mt7915_mcu_rdd_cmd(struct mt7915_dev *dev,
2882                        enum mt7915_rdd_cmd cmd, u8 index,
2883                        u8 rx_sel, u8 val)
2884 {
2885         struct {
2886                 u8 ctrl;
2887                 u8 rdd_idx;
2888                 u8 rdd_rx_sel;
2889                 u8 val;
2890                 u8 rsv[4];
2891         } __packed req = {
2892                 .ctrl = cmd,
2893                 .rdd_idx = index,
2894                 .rdd_rx_sel = rx_sel,
2895                 .val = val,
2896         };
2897
2898         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_CTRL,
2899                                    &req, sizeof(req), true);
2900 }
2901
2902 int mt7915_mcu_set_fcc5_lpn(struct mt7915_dev *dev, int val)
2903 {
2904         struct {
2905                 u32 tag;
2906                 u16 min_lpn;
2907                 u8 rsv[2];
2908         } __packed req = {
2909                 .tag = 0x1,
2910                 .min_lpn = val,
2911         };
2912
2913         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_TH,
2914                                    &req, sizeof(req), true);
2915 }
2916
2917 int mt7915_mcu_set_pulse_th(struct mt7915_dev *dev,
2918                             const struct mt7915_dfs_pulse *pulse)
2919 {
2920         struct {
2921                 u32 tag;
2922                 struct mt7915_dfs_pulse pulse;
2923         } __packed req = {
2924                 .tag = 0x3,
2925         };
2926
2927         memcpy(&req.pulse, pulse, sizeof(*pulse));
2928
2929         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_TH,
2930                                    &req, sizeof(req), true);
2931 }
2932
2933 int mt7915_mcu_set_radar_th(struct mt7915_dev *dev, int index,
2934                             const struct mt7915_dfs_pattern *pattern)
2935 {
2936         struct {
2937                 u32 tag;
2938                 u16 radar_type;
2939                 struct mt7915_dfs_pattern pattern;
2940         } __packed req = {
2941                 .tag = 0x2,
2942                 .radar_type = index,
2943         };
2944
2945         memcpy(&req.pattern, pattern, sizeof(*pattern));
2946
2947         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_TH,
2948                                    &req, sizeof(req), true);
2949 }
2950
2951 int mt7915_mcu_set_chan_info(struct mt7915_phy *phy, int cmd)
2952 {
2953         struct mt7915_dev *dev = phy->dev;
2954         struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
2955         int freq1 = chandef->center_freq1;
2956         struct {
2957                 u8 control_ch;
2958                 u8 center_ch;
2959                 u8 bw;
2960                 u8 tx_streams_num;
2961                 u8 rx_streams;  /* mask or num */
2962                 u8 switch_reason;
2963                 u8 band_idx;
2964                 u8 center_ch2;  /* for 80+80 only */
2965                 __le16 cac_case;
2966                 u8 channel_band;
2967                 u8 rsv0;
2968                 __le32 outband_freq;
2969                 u8 txpower_drop;
2970                 u8 ap_bw;
2971                 u8 ap_center_ch;
2972                 u8 rsv1[57];
2973         } __packed req = {
2974                 .control_ch = chandef->chan->hw_value,
2975                 .center_ch = ieee80211_frequency_to_channel(freq1),
2976                 .bw = mt7915_mcu_chan_bw(chandef),
2977                 .tx_streams_num = hweight8(phy->mt76->antenna_mask),
2978                 .rx_streams = phy->chainmask,
2979                 .band_idx = phy != &dev->phy,
2980                 .channel_band = chandef->chan->band,
2981         };
2982
2983         if ((chandef->chan->flags & IEEE80211_CHAN_RADAR) &&
2984             chandef->chan->dfs_state != NL80211_DFS_AVAILABLE)
2985                 req.switch_reason = CH_SWITCH_DFS;
2986         else
2987                 req.switch_reason = CH_SWITCH_NORMAL;
2988
2989         if (cmd == MCU_EXT_CMD_CHANNEL_SWITCH)
2990                 req.rx_streams = hweight8(req.rx_streams);
2991
2992         if (chandef->width == NL80211_CHAN_WIDTH_80P80) {
2993                 int freq2 = chandef->center_freq2;
2994
2995                 req.center_ch2 = ieee80211_frequency_to_channel(freq2);
2996         }
2997
2998         return __mt76_mcu_send_msg(&dev->mt76, cmd, &req, sizeof(req), true);
2999 }
3000
3001 int mt7915_mcu_set_eeprom(struct mt7915_dev *dev)
3002 {
3003         struct req_hdr {
3004                 u8 buffer_mode;
3005                 u8 format;
3006                 __le16 len;
3007         } __packed req = {
3008                 .buffer_mode = EE_MODE_EFUSE,
3009                 .format = EE_FORMAT_WHOLE,
3010         };
3011
3012         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EFUSE_BUFFER_MODE,
3013                                    &req, sizeof(req), true);
3014 }
3015
3016 int mt7915_mcu_get_eeprom(struct mt7915_dev *dev, u32 offset)
3017 {
3018         struct mt7915_mcu_eeprom_info req = {
3019                 .addr = cpu_to_le32(round_down(offset, 16)),
3020         };
3021
3022         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EFUSE_ACCESS, &req,
3023                                    sizeof(req), true);
3024 }
3025
3026 int mt7915_mcu_get_temperature(struct mt7915_dev *dev, int index)
3027 {
3028         struct {
3029                 u8 ctrl_id;
3030                 u8 action;
3031                 u8 band;
3032                 u8 rsv[5];
3033         } req = {
3034                 .ctrl_id = THERMAL_SENSOR_TEMP_QUERY,
3035                 .action = index,
3036         };
3037
3038         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_THERMAL_CTRL, &req,
3039                                    sizeof(req), true);
3040 }
3041
3042 int mt7915_mcu_get_rate_info(struct mt7915_dev *dev, u32 cmd, u16 wlan_idx)
3043 {
3044         struct {
3045                 __le32 cmd;
3046                 __le16 wlan_idx;
3047                 __le16 ru_idx;
3048                 __le16 direction;
3049                 __le16 dump_group;
3050         } req = {
3051                 .cmd = cpu_to_le32(cmd),
3052                 .wlan_idx = cpu_to_le16(wlan_idx),
3053                 .dump_group = cpu_to_le16(1),
3054         };
3055
3056         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_RATE_CTRL, &req,
3057                                    sizeof(req), false);
3058 }
3059
3060 int mt7915_mcu_set_sku(struct mt7915_phy *phy)
3061 {
3062         struct mt7915_dev *dev = phy->dev;
3063         struct mt76_phy *mphy = phy->mt76;
3064         struct ieee80211_hw *hw = mphy->hw;
3065         struct mt7915_sku_val {
3066                 u8 format_id;
3067                 u8 limit_type;
3068                 u8 dbdc_idx;
3069                 s8 val[MT7915_SKU_RATE_NUM];
3070         } __packed req = {
3071                 .format_id = 4,
3072                 .dbdc_idx = phy != &dev->phy,
3073         };
3074         int i;
3075         s8 *delta;
3076
3077         delta = dev->rate_power[mphy->chandef.chan->band];
3078         mphy->txpower_cur = hw->conf.power_level * 2 +
3079                             delta[MT7915_SKU_MAX_DELTA_IDX];
3080
3081         for (i = 0; i < MT7915_SKU_RATE_NUM; i++)
3082                 req.val[i] = hw->conf.power_level * 2 + delta[i];
3083
3084         return __mt76_mcu_send_msg(&dev->mt76,
3085                                    MCU_EXT_CMD_TX_POWER_FEATURE_CTRL,
3086                                    &req, sizeof(req), true);
3087 }
3088
3089 int mt7915_mcu_set_sku_en(struct mt7915_phy *phy, bool enable)
3090 {
3091         struct mt7915_dev *dev = phy->dev;
3092         struct mt7915_sku {
3093                 u8 format_id;
3094                 u8 sku_enable;
3095                 u8 dbdc_idx;
3096                 u8 rsv;
3097         } __packed req = {
3098                 .format_id = 0,
3099                 .dbdc_idx = phy != &dev->phy,
3100                 .sku_enable = enable,
3101         };
3102
3103         return __mt76_mcu_send_msg(&dev->mt76,
3104                                    MCU_EXT_CMD_TX_POWER_FEATURE_CTRL,
3105                                    &req, sizeof(req), true);
3106 }
3107
3108 int mt7915_mcu_set_ser(struct mt7915_dev *dev, u8 action, u8 set, u8 band)
3109 {
3110         struct {
3111                 u8 action;
3112                 u8 set;
3113                 u8 band;
3114                 u8 rsv;
3115         } req = {
3116                 .action = action,
3117                 .set = set,
3118                 .band = band,
3119         };
3120
3121         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_SER_TRIGGER,
3122                                    &req, sizeof(req), false);
3123 }
3124
3125 int mt7915_mcu_set_txbf_type(struct mt7915_dev *dev)
3126 {
3127 #define MT_BF_TYPE_UPDATE               20
3128         struct {
3129                 u8 action;
3130                 bool ebf;
3131                 bool ibf;
3132                 u8 rsv;
3133         } __packed req = {
3134                 .action = MT_BF_TYPE_UPDATE,
3135                 .ebf = true,
3136                 .ibf = false,
3137         };
3138
3139         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_TXBF_ACTION,
3140                                    &req, sizeof(req), true);
3141 }
3142
3143 int mt7915_mcu_set_txbf_sounding(struct mt7915_dev *dev)
3144 {
3145 #define MT_BF_PROCESSING                4
3146         struct {
3147                 u8 action;
3148                 u8 snd_mode;
3149                 u8 sta_num;
3150                 u8 rsv;
3151                 u8 wlan_idx[4];
3152                 __le32 snd_period;      /* ms */
3153         } __packed req = {
3154                 .action = true,
3155                 .snd_mode = MT_BF_PROCESSING,
3156         };
3157
3158         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_TXBF_ACTION,
3159                                    &req, sizeof(req), true);
3160 }
3161
3162 int mt7915_mcu_add_obss_spr(struct mt7915_dev *dev, struct ieee80211_vif *vif,
3163                             bool enable)
3164 {
3165 #define MT_SPR_ENABLE           1
3166         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
3167         struct {
3168                 u8 action;
3169                 u8 arg_num;
3170                 u8 band_idx;
3171                 u8 status;
3172                 u8 drop_tx_idx;
3173                 u8 sta_idx;     /* 256 sta */
3174                 u8 rsv[2];
3175                 u32 val;
3176         } __packed req = {
3177                 .action = MT_SPR_ENABLE,
3178                 .arg_num = 1,
3179                 .band_idx = mvif->band_idx,
3180                 .val = enable,
3181         };
3182
3183         return __mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_SPR,
3184                                    &req, sizeof(req), true);
3185 }