mt76: mt7915: fix endianness warning in mt7915_mcu_set_radar_th
[linux-2.6-microblaze.git] / drivers / net / wireless / mediatek / mt76 / mt7915 / mcu.c
1 // SPDX-License-Identifier: ISC
2 /* Copyright (C) 2020 MediaTek Inc. */
3
4 #include <linux/firmware.h>
5 #include <linux/fs.h>
6 #include "mt7915.h"
7 #include "mcu.h"
8 #include "mac.h"
9 #include "eeprom.h"
10
11 struct mt7915_patch_hdr {
12         char build_date[16];
13         char platform[4];
14         __be32 hw_sw_ver;
15         __be32 patch_ver;
16         __be16 checksum;
17         u16 reserved;
18         struct {
19                 __be32 patch_ver;
20                 __be32 subsys;
21                 __be32 feature;
22                 __be32 n_region;
23                 __be32 crc;
24                 u32 reserved[11];
25         } desc;
26 } __packed;
27
28 struct mt7915_patch_sec {
29         __be32 type;
30         __be32 offs;
31         __be32 size;
32         union {
33                 __be32 spec[13];
34                 struct {
35                         __be32 addr;
36                         __be32 len;
37                         __be32 sec_key_idx;
38                         __be32 align_len;
39                         u32 reserved[9];
40                 } info;
41         };
42 } __packed;
43
44 struct mt7915_fw_trailer {
45         u8 chip_id;
46         u8 eco_code;
47         u8 n_region;
48         u8 format_ver;
49         u8 format_flag;
50         u8 reserved[2];
51         char fw_ver[10];
52         char build_date[15];
53         u32 crc;
54 } __packed;
55
56 struct mt7915_fw_region {
57         __le32 decomp_crc;
58         __le32 decomp_len;
59         __le32 decomp_blk_sz;
60         u8 reserved[4];
61         __le32 addr;
62         __le32 len;
63         u8 feature_set;
64         u8 reserved1[15];
65 } __packed;
66
67 #define MCU_PATCH_ADDRESS               0x200000
68
69 #define MT_STA_BFER                     BIT(0)
70 #define MT_STA_BFEE                     BIT(1)
71
72 #define FW_FEATURE_SET_ENCRYPT          BIT(0)
73 #define FW_FEATURE_SET_KEY_IDX          GENMASK(2, 1)
74 #define FW_FEATURE_OVERRIDE_ADDR        BIT(5)
75
76 #define DL_MODE_ENCRYPT                 BIT(0)
77 #define DL_MODE_KEY_IDX                 GENMASK(2, 1)
78 #define DL_MODE_RESET_SEC_IV            BIT(3)
79 #define DL_MODE_WORKING_PDA_CR4         BIT(4)
80 #define DL_MODE_NEED_RSP                BIT(31)
81
82 #define FW_START_OVERRIDE               BIT(0)
83 #define FW_START_WORKING_PDA_CR4        BIT(2)
84
85 #define PATCH_SEC_TYPE_MASK             GENMASK(15, 0)
86 #define PATCH_SEC_TYPE_INFO             0x2
87
88 #define to_wcid_lo(id)                  FIELD_GET(GENMASK(7, 0), (u16)id)
89 #define to_wcid_hi(id)                  FIELD_GET(GENMASK(9, 8), (u16)id)
90
91 #define HE_PHY(p, c)                    u8_get_bits(c, IEEE80211_HE_PHY_##p)
92 #define HE_MAC(m, c)                    u8_get_bits(c, IEEE80211_HE_MAC_##m)
93
94 static enum mt7915_cipher_type
95 mt7915_mcu_get_cipher(int cipher)
96 {
97         switch (cipher) {
98         case WLAN_CIPHER_SUITE_WEP40:
99                 return MT_CIPHER_WEP40;
100         case WLAN_CIPHER_SUITE_WEP104:
101                 return MT_CIPHER_WEP104;
102         case WLAN_CIPHER_SUITE_TKIP:
103                 return MT_CIPHER_TKIP;
104         case WLAN_CIPHER_SUITE_AES_CMAC:
105                 return MT_CIPHER_BIP_CMAC_128;
106         case WLAN_CIPHER_SUITE_CCMP:
107                 return MT_CIPHER_AES_CCMP;
108         case WLAN_CIPHER_SUITE_CCMP_256:
109                 return MT_CIPHER_CCMP_256;
110         case WLAN_CIPHER_SUITE_GCMP:
111                 return MT_CIPHER_GCMP;
112         case WLAN_CIPHER_SUITE_GCMP_256:
113                 return MT_CIPHER_GCMP_256;
114         case WLAN_CIPHER_SUITE_SMS4:
115                 return MT_CIPHER_WAPI;
116         default:
117                 return MT_CIPHER_NONE;
118         }
119 }
120
121 static u8 mt7915_mcu_chan_bw(struct cfg80211_chan_def *chandef)
122 {
123         static const u8 width_to_bw[] = {
124                 [NL80211_CHAN_WIDTH_40] = CMD_CBW_40MHZ,
125                 [NL80211_CHAN_WIDTH_80] = CMD_CBW_80MHZ,
126                 [NL80211_CHAN_WIDTH_80P80] = CMD_CBW_8080MHZ,
127                 [NL80211_CHAN_WIDTH_160] = CMD_CBW_160MHZ,
128                 [NL80211_CHAN_WIDTH_5] = CMD_CBW_5MHZ,
129                 [NL80211_CHAN_WIDTH_10] = CMD_CBW_10MHZ,
130                 [NL80211_CHAN_WIDTH_20] = CMD_CBW_20MHZ,
131                 [NL80211_CHAN_WIDTH_20_NOHT] = CMD_CBW_20MHZ,
132         };
133
134         if (chandef->width >= ARRAY_SIZE(width_to_bw))
135                 return 0;
136
137         return width_to_bw[chandef->width];
138 }
139
140 static const struct ieee80211_sta_he_cap *
141 mt7915_get_he_phy_cap(struct mt7915_phy *phy, struct ieee80211_vif *vif)
142 {
143         struct ieee80211_supported_band *sband;
144         enum nl80211_band band;
145
146         band = phy->mt76->chandef.chan->band;
147         sband = phy->mt76->hw->wiphy->bands[band];
148
149         return ieee80211_get_he_iftype_cap(sband, vif->type);
150 }
151
152 static u8
153 mt7915_get_phy_mode(struct mt7915_dev *dev, struct ieee80211_vif *vif,
154                     enum nl80211_band band, struct ieee80211_sta *sta)
155 {
156         struct ieee80211_sta_ht_cap *ht_cap;
157         struct ieee80211_sta_vht_cap *vht_cap;
158         const struct ieee80211_sta_he_cap *he_cap;
159         u8 mode = 0;
160
161         if (sta) {
162                 ht_cap = &sta->ht_cap;
163                 vht_cap = &sta->vht_cap;
164                 he_cap = &sta->he_cap;
165         } else {
166                 struct ieee80211_supported_band *sband;
167                 struct mt7915_phy *phy;
168                 struct mt7915_vif *mvif;
169
170                 mvif = (struct mt7915_vif *)vif->drv_priv;
171                 phy = mvif->band_idx ? mt7915_ext_phy(dev) : &dev->phy;
172                 sband = phy->mt76->hw->wiphy->bands[band];
173
174                 ht_cap = &sband->ht_cap;
175                 vht_cap = &sband->vht_cap;
176                 he_cap = ieee80211_get_he_iftype_cap(sband, vif->type);
177         }
178
179         if (band == NL80211_BAND_2GHZ) {
180                 mode |= PHY_MODE_B | PHY_MODE_G;
181
182                 if (ht_cap->ht_supported)
183                         mode |= PHY_MODE_GN;
184
185                 if (he_cap->has_he)
186                         mode |= PHY_MODE_AX_24G;
187         } else if (band == NL80211_BAND_5GHZ) {
188                 mode |= PHY_MODE_A;
189
190                 if (ht_cap->ht_supported)
191                         mode |= PHY_MODE_AN;
192
193                 if (vht_cap->vht_supported)
194                         mode |= PHY_MODE_AC;
195
196                 if (he_cap->has_he)
197                         mode |= PHY_MODE_AX_5G;
198         }
199
200         return mode;
201 }
202
203 static u8
204 mt7915_mcu_get_sta_nss(u16 mcs_map)
205 {
206         u8 nss;
207
208         for (nss = 8; nss > 0; nss--) {
209                 u8 nss_mcs = (mcs_map >> (2 * (nss - 1))) & 3;
210
211                 if (nss_mcs != IEEE80211_VHT_MCS_NOT_SUPPORTED)
212                         break;
213         }
214
215         return nss - 1;
216 }
217
218 static int
219 mt7915_mcu_parse_response(struct mt76_dev *mdev, int cmd,
220                           struct sk_buff *skb, int seq)
221 {
222         struct mt7915_mcu_rxd *rxd;
223         int ret = 0;
224
225         if (!skb) {
226                 dev_err(mdev->dev, "Message %d (seq %d) timeout\n",
227                         cmd, seq);
228                 return -ETIMEDOUT;
229         }
230
231         rxd = (struct mt7915_mcu_rxd *)skb->data;
232         if (seq != rxd->seq)
233                 return -EAGAIN;
234
235         switch (cmd) {
236         case -MCU_CMD_PATCH_SEM_CONTROL:
237                 skb_pull(skb, sizeof(*rxd) - 4);
238                 ret = *skb->data;
239                 break;
240         case MCU_EXT_CMD_THERMAL_CTRL:
241                 skb_pull(skb, sizeof(*rxd) + 4);
242                 ret = le32_to_cpu(*(__le32 *)skb->data);
243                 break;
244         default:
245                 skb_pull(skb, sizeof(struct mt7915_mcu_rxd));
246                 break;
247         }
248
249         return ret;
250 }
251
252 static int
253 mt7915_mcu_send_message(struct mt76_dev *mdev, struct sk_buff *skb,
254                         int cmd, int *wait_seq)
255 {
256         struct mt7915_dev *dev = container_of(mdev, struct mt7915_dev, mt76);
257         struct mt7915_mcu_txd *mcu_txd;
258         u8 seq, pkt_fmt, qidx;
259         enum mt76_txq_id txq;
260         __le32 *txd;
261         u32 val;
262
263         /* TODO: make dynamic based on msg type */
264         mdev->mcu.timeout = 20 * HZ;
265
266         seq = ++dev->mt76.mcu.msg_seq & 0xf;
267         if (!seq)
268                 seq = ++dev->mt76.mcu.msg_seq & 0xf;
269
270         if (cmd == -MCU_CMD_FW_SCATTER) {
271                 txq = MT_MCUQ_FWDL;
272                 goto exit;
273         }
274
275         mcu_txd = (struct mt7915_mcu_txd *)skb_push(skb, sizeof(*mcu_txd));
276
277         if (test_bit(MT76_STATE_MCU_RUNNING, &dev->mphy.state)) {
278                 txq = MT_MCUQ_WA;
279                 qidx = MT_TX_MCU_PORT_RX_Q0;
280                 pkt_fmt = MT_TX_TYPE_CMD;
281         } else {
282                 txq = MT_MCUQ_WM;
283                 qidx = MT_TX_MCU_PORT_RX_Q0;
284                 pkt_fmt = MT_TX_TYPE_CMD;
285         }
286
287         txd = mcu_txd->txd;
288
289         val = FIELD_PREP(MT_TXD0_TX_BYTES, skb->len) |
290               FIELD_PREP(MT_TXD0_PKT_FMT, pkt_fmt) |
291               FIELD_PREP(MT_TXD0_Q_IDX, qidx);
292         txd[0] = cpu_to_le32(val);
293
294         val = MT_TXD1_LONG_FORMAT |
295               FIELD_PREP(MT_TXD1_HDR_FORMAT, MT_HDR_FORMAT_CMD);
296         txd[1] = cpu_to_le32(val);
297
298         mcu_txd->len = cpu_to_le16(skb->len - sizeof(mcu_txd->txd));
299         mcu_txd->pq_id = cpu_to_le16(MCU_PQ_ID(MT_TX_PORT_IDX_MCU, qidx));
300         mcu_txd->pkt_type = MCU_PKT_ID;
301         mcu_txd->seq = seq;
302
303         if (cmd < 0) {
304                 mcu_txd->set_query = MCU_Q_NA;
305                 mcu_txd->cid = -cmd;
306         } else {
307                 mcu_txd->cid = MCU_CMD_EXT_CID;
308                 mcu_txd->ext_cid = cmd;
309                 mcu_txd->ext_cid_ack = 1;
310
311                 /* do not use Q_SET for efuse */
312                 if (cmd == MCU_EXT_CMD_EFUSE_ACCESS)
313                         mcu_txd->set_query = MCU_Q_QUERY;
314                 else
315                         mcu_txd->set_query = MCU_Q_SET;
316         }
317
318         if (cmd == MCU_EXT_CMD_MWDS_SUPPORT)
319                 mcu_txd->s2d_index = MCU_S2D_H2C;
320         else
321                 mcu_txd->s2d_index = MCU_S2D_H2N;
322         WARN_ON(cmd == MCU_EXT_CMD_EFUSE_ACCESS &&
323                 mcu_txd->set_query != MCU_Q_QUERY);
324
325 exit:
326         if (wait_seq)
327                 *wait_seq = seq;
328
329         return mt76_tx_queue_skb_raw(dev, mdev->q_mcu[txq], skb, 0);
330 }
331
332 static void
333 mt7915_mcu_csa_finish(void *priv, u8 *mac, struct ieee80211_vif *vif)
334 {
335         if (vif->csa_active)
336                 ieee80211_csa_finish(vif);
337 }
338
339 static void
340 mt7915_mcu_rx_radar_detected(struct mt7915_dev *dev, struct sk_buff *skb)
341 {
342         struct mt76_phy *mphy = &dev->mt76.phy;
343         struct mt7915_mcu_rdd_report *r;
344
345         r = (struct mt7915_mcu_rdd_report *)skb->data;
346
347         if (r->idx && dev->mt76.phy2)
348                 mphy = dev->mt76.phy2;
349
350         ieee80211_radar_detected(mphy->hw);
351         dev->hw_pattern++;
352 }
353
354 static void
355 mt7915_mcu_tx_rate_parse(struct mt76_phy *mphy, struct mt7915_mcu_ra_info *ra,
356                          struct rate_info *rate, u16 r)
357 {
358         struct ieee80211_supported_band *sband;
359         u16 ru_idx = le16_to_cpu(ra->ru_idx);
360         u16 flags = 0;
361
362         rate->mcs = FIELD_GET(MT_RA_RATE_MCS, r);
363         rate->nss = FIELD_GET(MT_RA_RATE_NSS, r) + 1;
364
365         switch (FIELD_GET(MT_RA_RATE_TX_MODE, r)) {
366         case MT_PHY_TYPE_CCK:
367         case MT_PHY_TYPE_OFDM:
368                 if (mphy->chandef.chan->band == NL80211_BAND_5GHZ)
369                         sband = &mphy->sband_5g.sband;
370                 else
371                         sband = &mphy->sband_2g.sband;
372
373                 rate->legacy = sband->bitrates[rate->mcs].bitrate;
374                 break;
375         case MT_PHY_TYPE_HT:
376         case MT_PHY_TYPE_HT_GF:
377                 rate->mcs += (rate->nss - 1) * 8;
378                 flags |= RATE_INFO_FLAGS_MCS;
379
380                 if (ra->gi)
381                         flags |= RATE_INFO_FLAGS_SHORT_GI;
382                 break;
383         case MT_PHY_TYPE_VHT:
384                 flags |= RATE_INFO_FLAGS_VHT_MCS;
385
386                 if (ra->gi)
387                         flags |= RATE_INFO_FLAGS_SHORT_GI;
388                 break;
389         case MT_PHY_TYPE_HE_SU:
390         case MT_PHY_TYPE_HE_EXT_SU:
391         case MT_PHY_TYPE_HE_TB:
392         case MT_PHY_TYPE_HE_MU:
393                 rate->he_gi = ra->gi;
394                 rate->he_dcm = FIELD_GET(MT_RA_RATE_DCM_EN, r);
395
396                 flags |= RATE_INFO_FLAGS_HE_MCS;
397                 break;
398         default:
399                 break;
400         }
401         rate->flags = flags;
402
403         if (ru_idx) {
404                 switch (ru_idx) {
405                 case 1 ... 2:
406                         rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_996;
407                         break;
408                 case 3 ... 6:
409                         rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_484;
410                         break;
411                 case 7 ... 14:
412                         rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_242;
413                         break;
414                 default:
415                         rate->he_ru_alloc = NL80211_RATE_INFO_HE_RU_ALLOC_106;
416                         break;
417                 }
418                 rate->bw = RATE_INFO_BW_HE_RU;
419         } else {
420                 u8 bw = mt7915_mcu_chan_bw(&mphy->chandef) -
421                         FIELD_GET(MT_RA_RATE_BW, r);
422
423                 switch (bw) {
424                 case IEEE80211_STA_RX_BW_160:
425                         rate->bw = RATE_INFO_BW_160;
426                         break;
427                 case IEEE80211_STA_RX_BW_80:
428                         rate->bw = RATE_INFO_BW_80;
429                         break;
430                 case IEEE80211_STA_RX_BW_40:
431                         rate->bw = RATE_INFO_BW_40;
432                         break;
433                 default:
434                         rate->bw = RATE_INFO_BW_20;
435                         break;
436                 }
437         }
438 }
439
440 static void
441 mt7915_mcu_tx_rate_report(struct mt7915_dev *dev, struct sk_buff *skb)
442 {
443         struct mt7915_mcu_ra_info *ra = (struct mt7915_mcu_ra_info *)skb->data;
444         struct rate_info rate = {}, prob_rate = {};
445         u16 probe = le16_to_cpu(ra->prob_up_rate);
446         u16 attempts = le16_to_cpu(ra->attempts);
447         u16 curr = le16_to_cpu(ra->curr_rate);
448         u16 wcidx = le16_to_cpu(ra->wlan_idx);
449         struct mt76_phy *mphy = &dev->mphy;
450         struct mt7915_sta_stats *stats;
451         struct mt7915_sta *msta;
452         struct mt76_wcid *wcid;
453
454         if (wcidx >= MT76_N_WCIDS)
455                 return;
456
457         wcid = rcu_dereference(dev->mt76.wcid[wcidx]);
458         if (!wcid)
459                 return;
460
461         msta = container_of(wcid, struct mt7915_sta, wcid);
462         stats = &msta->stats;
463
464         if (msta->wcid.ext_phy && dev->mt76.phy2)
465                 mphy = dev->mt76.phy2;
466
467         /* current rate */
468         mt7915_mcu_tx_rate_parse(mphy, ra, &rate, curr);
469         stats->tx_rate = rate;
470
471         /* probing rate */
472         mt7915_mcu_tx_rate_parse(mphy, ra, &prob_rate, probe);
473         stats->prob_rate = prob_rate;
474
475         if (attempts) {
476                 u16 success = le16_to_cpu(ra->success);
477
478                 stats->per = 1000 * (attempts - success) / attempts;
479         }
480 }
481
482 static void
483 mt7915_mcu_rx_log_message(struct mt7915_dev *dev, struct sk_buff *skb)
484 {
485         struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
486         const char *data = (char *)&rxd[1];
487         const char *type;
488
489         switch (rxd->s2d_index) {
490         case 0:
491                 type = "WM";
492                 break;
493         case 2:
494                 type = "WA";
495                 break;
496         default:
497                 type = "unknown";
498                 break;
499         }
500
501         wiphy_info(mt76_hw(dev)->wiphy, "%s: %s", type, data);
502 }
503
504 static void
505 mt7915_mcu_rx_ext_event(struct mt7915_dev *dev, struct sk_buff *skb)
506 {
507         struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
508
509         switch (rxd->ext_eid) {
510         case MCU_EXT_EVENT_RDD_REPORT:
511                 mt7915_mcu_rx_radar_detected(dev, skb);
512                 break;
513         case MCU_EXT_EVENT_CSA_NOTIFY:
514                 ieee80211_iterate_active_interfaces_atomic(dev->mt76.hw,
515                                 IEEE80211_IFACE_ITER_RESUME_ALL,
516                                 mt7915_mcu_csa_finish, dev);
517                 break;
518         case MCU_EXT_EVENT_RATE_REPORT:
519                 mt7915_mcu_tx_rate_report(dev, skb);
520                 break;
521         case MCU_EXT_EVENT_FW_LOG_2_HOST:
522                 mt7915_mcu_rx_log_message(dev, skb);
523                 break;
524         default:
525                 break;
526         }
527 }
528
529 static void
530 mt7915_mcu_rx_unsolicited_event(struct mt7915_dev *dev, struct sk_buff *skb)
531 {
532         struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
533
534         switch (rxd->eid) {
535         case MCU_EVENT_EXT:
536                 mt7915_mcu_rx_ext_event(dev, skb);
537                 break;
538         default:
539                 break;
540         }
541         dev_kfree_skb(skb);
542 }
543
544 void mt7915_mcu_rx_event(struct mt7915_dev *dev, struct sk_buff *skb)
545 {
546         struct mt7915_mcu_rxd *rxd = (struct mt7915_mcu_rxd *)skb->data;
547
548         if (rxd->ext_eid == MCU_EXT_EVENT_THERMAL_PROTECT ||
549             rxd->ext_eid == MCU_EXT_EVENT_FW_LOG_2_HOST ||
550             rxd->ext_eid == MCU_EXT_EVENT_ASSERT_DUMP ||
551             rxd->ext_eid == MCU_EXT_EVENT_PS_SYNC ||
552             rxd->ext_eid == MCU_EXT_EVENT_RATE_REPORT ||
553             !rxd->seq)
554                 mt7915_mcu_rx_unsolicited_event(dev, skb);
555         else
556                 mt76_mcu_rx_event(&dev->mt76, skb);
557 }
558
559 static struct sk_buff *
560 mt7915_mcu_alloc_sta_req(struct mt7915_dev *dev, struct mt7915_vif *mvif,
561                          struct mt7915_sta *msta, int len)
562 {
563         struct sta_req_hdr hdr = {
564                 .bss_idx = mvif->idx,
565                 .wlan_idx_lo = msta ? to_wcid_lo(msta->wcid.idx) : 0,
566                 .wlan_idx_hi = msta ? to_wcid_hi(msta->wcid.idx) : 0,
567                 .muar_idx = msta ? mvif->omac_idx : 0,
568                 .is_tlv_append = 1,
569         };
570         struct sk_buff *skb;
571
572         skb = mt76_mcu_msg_alloc(&dev->mt76, NULL, len);
573         if (!skb)
574                 return ERR_PTR(-ENOMEM);
575
576         skb_put_data(skb, &hdr, sizeof(hdr));
577
578         return skb;
579 }
580
581 static struct wtbl_req_hdr *
582 mt7915_mcu_alloc_wtbl_req(struct mt7915_dev *dev, struct mt7915_sta *msta,
583                           int cmd, void *sta_wtbl, struct sk_buff **skb)
584 {
585         struct tlv *sta_hdr = sta_wtbl;
586         struct wtbl_req_hdr hdr = {
587                 .wlan_idx_lo = to_wcid_lo(msta->wcid.idx),
588                 .wlan_idx_hi = to_wcid_hi(msta->wcid.idx),
589                 .operation = cmd,
590         };
591         struct sk_buff *nskb = *skb;
592
593         if (!nskb) {
594                 nskb = mt76_mcu_msg_alloc(&dev->mt76, NULL,
595                                           MT7915_WTBL_UPDATE_BA_SIZE);
596                 if (!nskb)
597                         return ERR_PTR(-ENOMEM);
598
599                 *skb = nskb;
600         }
601
602         if (sta_hdr)
603                 sta_hdr->len = cpu_to_le16(sizeof(hdr));
604
605         return skb_put_data(nskb, &hdr, sizeof(hdr));
606 }
607
608 static struct tlv *
609 mt7915_mcu_add_nested_tlv(struct sk_buff *skb, int tag, int len,
610                           void *sta_ntlv, void *sta_wtbl)
611 {
612         struct sta_ntlv_hdr *ntlv_hdr = sta_ntlv;
613         struct tlv *sta_hdr = sta_wtbl;
614         struct tlv *ptlv, tlv = {
615                 .tag = cpu_to_le16(tag),
616                 .len = cpu_to_le16(len),
617         };
618         u16 ntlv;
619
620         ptlv = skb_put(skb, len);
621         memcpy(ptlv, &tlv, sizeof(tlv));
622
623         ntlv = le16_to_cpu(ntlv_hdr->tlv_num);
624         ntlv_hdr->tlv_num = cpu_to_le16(ntlv + 1);
625
626         if (sta_hdr) {
627                 u16 size = le16_to_cpu(sta_hdr->len);
628
629                 sta_hdr->len = cpu_to_le16(size + len);
630         }
631
632         return ptlv;
633 }
634
635 static struct tlv *
636 mt7915_mcu_add_tlv(struct sk_buff *skb, int tag, int len)
637 {
638         return mt7915_mcu_add_nested_tlv(skb, tag, len, skb->data, NULL);
639 }
640
641 static struct tlv *
642 mt7915_mcu_add_nested_subtlv(struct sk_buff *skb, int sub_tag, int sub_len,
643                              __le16 *sub_ntlv, __le16 *len)
644 {
645         struct tlv *ptlv, tlv = {
646                 .tag = cpu_to_le16(sub_tag),
647                 .len = cpu_to_le16(sub_len),
648         };
649
650         ptlv = skb_put(skb, sub_len);
651         memcpy(ptlv, &tlv, sizeof(tlv));
652
653         le16_add_cpu(sub_ntlv, 1);
654         le16_add_cpu(len, sub_len);
655
656         return ptlv;
657 }
658
659 /** bss info **/
660 static int
661 mt7915_mcu_bss_basic_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
662                          struct mt7915_phy *phy, bool enable)
663 {
664         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
665         struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
666         enum nl80211_band band = chandef->chan->band;
667         struct bss_info_basic *bss;
668         u16 wlan_idx = mvif->sta.wcid.idx;
669         u32 type = NETWORK_INFRA;
670         struct tlv *tlv;
671
672         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_BASIC, sizeof(*bss));
673
674         switch (vif->type) {
675         case NL80211_IFTYPE_MESH_POINT:
676         case NL80211_IFTYPE_AP:
677                 break;
678         case NL80211_IFTYPE_STATION:
679                 /* TODO: enable BSS_INFO_UAPSD & BSS_INFO_PM */
680                 if (enable) {
681                         struct ieee80211_sta *sta;
682                         struct mt7915_sta *msta;
683
684                         rcu_read_lock();
685                         sta = ieee80211_find_sta(vif, vif->bss_conf.bssid);
686                         if (!sta) {
687                                 rcu_read_unlock();
688                                 return -EINVAL;
689                         }
690
691                         msta = (struct mt7915_sta *)sta->drv_priv;
692                         wlan_idx = msta->wcid.idx;
693                         rcu_read_unlock();
694                 }
695                 break;
696         case NL80211_IFTYPE_ADHOC:
697                 type = NETWORK_IBSS;
698                 break;
699         default:
700                 WARN_ON(1);
701                 break;
702         }
703
704         bss = (struct bss_info_basic *)tlv;
705         memcpy(bss->bssid, vif->bss_conf.bssid, ETH_ALEN);
706         bss->bcn_interval = cpu_to_le16(vif->bss_conf.beacon_int);
707         bss->network_type = cpu_to_le32(type);
708         bss->dtim_period = vif->bss_conf.dtim_period;
709         bss->bmc_wcid_lo = to_wcid_lo(wlan_idx);
710         bss->bmc_wcid_hi = to_wcid_hi(wlan_idx);
711         bss->phy_mode = mt7915_get_phy_mode(phy->dev, vif, band, NULL);
712         bss->wmm_idx = mvif->wmm_idx;
713         bss->active = enable;
714
715         return 0;
716 }
717
718 static void
719 mt7915_mcu_bss_omac_tlv(struct sk_buff *skb, struct ieee80211_vif *vif)
720 {
721         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
722         struct bss_info_omac *omac;
723         struct tlv *tlv;
724         u32 type = 0;
725         u8 idx;
726
727         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_OMAC, sizeof(*omac));
728
729         switch (vif->type) {
730         case NL80211_IFTYPE_MESH_POINT:
731         case NL80211_IFTYPE_AP:
732                 type = CONNECTION_INFRA_AP;
733                 break;
734         case NL80211_IFTYPE_STATION:
735                 type = CONNECTION_INFRA_STA;
736                 break;
737         case NL80211_IFTYPE_ADHOC:
738                 type = CONNECTION_IBSS_ADHOC;
739                 break;
740         default:
741                 WARN_ON(1);
742                 break;
743         }
744
745         omac = (struct bss_info_omac *)tlv;
746         idx = mvif->omac_idx > EXT_BSSID_START ? HW_BSSID_0 : mvif->omac_idx;
747         omac->conn_type = cpu_to_le32(type);
748         omac->omac_idx = mvif->omac_idx;
749         omac->band_idx = mvif->band_idx;
750         omac->hw_bss_idx = idx;
751 }
752
753 struct mt7915_he_obss_narrow_bw_ru_data {
754         bool tolerated;
755 };
756
757 static void mt7915_check_he_obss_narrow_bw_ru_iter(struct wiphy *wiphy,
758                                                    struct cfg80211_bss *bss,
759                                                    void *_data)
760 {
761         struct mt7915_he_obss_narrow_bw_ru_data *data = _data;
762         const struct element *elem;
763
764         elem = ieee80211_bss_get_elem(bss, WLAN_EID_EXT_CAPABILITY);
765
766         if (!elem || elem->datalen < 10 ||
767             !(elem->data[10] &
768               WLAN_EXT_CAPA10_OBSS_NARROW_BW_RU_TOLERANCE_SUPPORT))
769                 data->tolerated = false;
770 }
771
772 static bool mt7915_check_he_obss_narrow_bw_ru(struct ieee80211_hw *hw,
773                                               struct ieee80211_vif *vif)
774 {
775         struct mt7915_he_obss_narrow_bw_ru_data iter_data = {
776                 .tolerated = true,
777         };
778
779         if (!(vif->bss_conf.chandef.chan->flags & IEEE80211_CHAN_RADAR))
780                 return false;
781
782         cfg80211_bss_iter(hw->wiphy, &vif->bss_conf.chandef,
783                           mt7915_check_he_obss_narrow_bw_ru_iter,
784                           &iter_data);
785
786         /*
787          * If there is at least one AP on radar channel that cannot
788          * tolerate 26-tone RU UL OFDMA transmissions using HE TB PPDU.
789          */
790         return !iter_data.tolerated;
791 }
792
793 static void
794 mt7915_mcu_bss_rfch_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
795                         struct mt7915_phy *phy)
796 {
797         struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
798         struct bss_info_rf_ch *ch;
799         struct tlv *tlv;
800         int freq1 = chandef->center_freq1;
801
802         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_RF_CH, sizeof(*ch));
803
804         ch = (struct bss_info_rf_ch *)tlv;
805         ch->pri_ch = chandef->chan->hw_value;
806         ch->center_ch0 = ieee80211_frequency_to_channel(freq1);
807         ch->bw = mt7915_mcu_chan_bw(chandef);
808
809         if (chandef->width == NL80211_CHAN_WIDTH_80P80) {
810                 int freq2 = chandef->center_freq2;
811
812                 ch->center_ch1 = ieee80211_frequency_to_channel(freq2);
813         }
814
815         if (vif->bss_conf.he_support && vif->type == NL80211_IFTYPE_STATION) {
816                 struct mt7915_dev *dev = phy->dev;
817                 struct mt76_phy *mphy = &dev->mt76.phy;
818                 bool ext_phy = phy != &dev->phy;
819
820                 if (ext_phy && dev->mt76.phy2)
821                         mphy = dev->mt76.phy2;
822
823                 ch->he_ru26_block =
824                         mt7915_check_he_obss_narrow_bw_ru(mphy->hw, vif);
825                 ch->he_all_disable = false;
826         } else {
827                 ch->he_all_disable = true;
828         }
829 }
830
831 static void
832 mt7915_mcu_bss_ra_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
833                       struct mt7915_phy *phy)
834 {
835         struct bss_info_ra *ra;
836         struct tlv *tlv;
837         int max_nss = hweight8(phy->chainmask);
838
839         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_RA, sizeof(*ra));
840
841         ra = (struct bss_info_ra *)tlv;
842         ra->op_mode = vif->type == NL80211_IFTYPE_AP;
843         ra->adhoc_en = vif->type == NL80211_IFTYPE_ADHOC;
844         ra->short_preamble = true;
845         ra->tx_streams = max_nss;
846         ra->rx_streams = max_nss;
847         ra->algo = 4;
848         ra->train_up_rule = 2;
849         ra->train_up_high_thres = 110;
850         ra->train_up_rule_rssi = -70;
851         ra->low_traffic_thres = 2;
852         ra->phy_cap = cpu_to_le32(0xfdf);
853         ra->interval = cpu_to_le32(500);
854         ra->fast_interval = cpu_to_le32(100);
855 }
856
857 static void
858 mt7915_mcu_bss_he_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
859                       struct mt7915_phy *phy)
860 {
861 #define DEFAULT_HE_PE_DURATION          4
862 #define DEFAULT_HE_DURATION_RTS_THRES   1023
863         const struct ieee80211_sta_he_cap *cap;
864         struct bss_info_he *he;
865         struct tlv *tlv;
866
867         cap = mt7915_get_he_phy_cap(phy, vif);
868
869         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_HE_BASIC, sizeof(*he));
870
871         he = (struct bss_info_he *)tlv;
872         he->he_pe_duration = vif->bss_conf.htc_trig_based_pkt_ext;
873         if (!he->he_pe_duration)
874                 he->he_pe_duration = DEFAULT_HE_PE_DURATION;
875
876         he->he_rts_thres = cpu_to_le16(vif->bss_conf.frame_time_rts_th);
877         if (!he->he_rts_thres)
878                 he->he_rts_thres = cpu_to_le16(DEFAULT_HE_DURATION_RTS_THRES);
879
880         he->max_nss_mcs[CMD_HE_MCS_BW80] = cap->he_mcs_nss_supp.tx_mcs_80;
881         he->max_nss_mcs[CMD_HE_MCS_BW160] = cap->he_mcs_nss_supp.tx_mcs_160;
882         he->max_nss_mcs[CMD_HE_MCS_BW8080] = cap->he_mcs_nss_supp.tx_mcs_80p80;
883 }
884
885 static void
886 mt7915_mcu_bss_hw_amsdu_tlv(struct sk_buff *skb)
887 {
888 #define TXD_CMP_MAP1            GENMASK(15, 0)
889 #define TXD_CMP_MAP2            (GENMASK(31, 0) & ~BIT(23))
890         struct bss_info_hw_amsdu *amsdu;
891         struct tlv *tlv;
892
893         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_HW_AMSDU, sizeof(*amsdu));
894
895         amsdu = (struct bss_info_hw_amsdu *)tlv;
896         amsdu->cmp_bitmap_0 = cpu_to_le32(TXD_CMP_MAP1);
897         amsdu->cmp_bitmap_1 = cpu_to_le32(TXD_CMP_MAP2);
898         amsdu->trig_thres = cpu_to_le16(2);
899         amsdu->enable = true;
900 }
901
902 static void
903 mt7915_mcu_bss_ext_tlv(struct sk_buff *skb, struct mt7915_vif *mvif)
904 {
905 /* SIFS 20us + 512 byte beacon tranmitted by 1Mbps (3906us) */
906 #define BCN_TX_ESTIMATE_TIME    (4096 + 20)
907         struct bss_info_ext_bss *ext;
908         int ext_bss_idx, tsf_offset;
909         struct tlv *tlv;
910
911         ext_bss_idx = mvif->omac_idx - EXT_BSSID_START;
912         if (ext_bss_idx < 0)
913                 return;
914
915         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_EXT_BSS, sizeof(*ext));
916
917         ext = (struct bss_info_ext_bss *)tlv;
918         tsf_offset = ext_bss_idx * BCN_TX_ESTIMATE_TIME;
919         ext->mbss_tsf_offset = cpu_to_le32(tsf_offset);
920 }
921
922 static void
923 mt7915_mcu_bss_bmc_tlv(struct sk_buff *skb, struct mt7915_phy *phy)
924 {
925         struct bss_info_bmc_rate *bmc;
926         struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
927         enum nl80211_band band = chandef->chan->band;
928         struct tlv *tlv;
929
930         tlv = mt7915_mcu_add_tlv(skb, BSS_INFO_BMC_RATE, sizeof(*bmc));
931
932         bmc = (struct bss_info_bmc_rate *)tlv;
933         if (band == NL80211_BAND_2GHZ) {
934                 bmc->short_preamble = true;
935         } else {
936                 bmc->bc_trans = cpu_to_le16(0x2000);
937                 bmc->mc_trans = cpu_to_le16(0x2080);
938         }
939 }
940
941 static int
942 mt7915_mcu_muar_config(struct mt7915_phy *phy, struct ieee80211_vif *vif,
943                        bool bssid, bool enable)
944 {
945         struct mt7915_dev *dev = phy->dev;
946         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
947         u32 idx = mvif->omac_idx - REPEATER_BSSID_START;
948         u32 mask = phy->omac_mask >> 32 & ~BIT(idx);
949         const u8 *addr = vif->addr;
950         struct {
951                 u8 mode;
952                 u8 force_clear;
953                 u8 clear_bitmap[8];
954                 u8 entry_count;
955                 u8 write;
956                 u8 band;
957
958                 u8 index;
959                 u8 bssid;
960                 u8 addr[ETH_ALEN];
961         } __packed req = {
962                 .mode = !!mask || enable,
963                 .entry_count = 1,
964                 .write = 1,
965                 .band = phy != &dev->phy,
966                 .index = idx * 2 + bssid,
967         };
968
969         if (bssid)
970                 addr = vif->bss_conf.bssid;
971
972         if (enable)
973                 ether_addr_copy(req.addr, addr);
974
975         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_MUAR_UPDATE, &req,
976                                  sizeof(req), true);
977 }
978
979 int mt7915_mcu_add_bss_info(struct mt7915_phy *phy,
980                             struct ieee80211_vif *vif, int enable)
981 {
982         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
983         struct sk_buff *skb;
984
985         if (mvif->omac_idx >= REPEATER_BSSID_START)
986                 mt7915_mcu_muar_config(phy, vif, true, enable);
987
988         skb = mt7915_mcu_alloc_sta_req(phy->dev, mvif, NULL,
989                                        MT7915_BSS_UPDATE_MAX_SIZE);
990         if (IS_ERR(skb))
991                 return PTR_ERR(skb);
992
993         /* bss_omac must be first */
994         if (enable)
995                 mt7915_mcu_bss_omac_tlv(skb, vif);
996
997         mt7915_mcu_bss_basic_tlv(skb, vif, phy, enable);
998
999         if (enable) {
1000                 mt7915_mcu_bss_rfch_tlv(skb, vif, phy);
1001                 mt7915_mcu_bss_bmc_tlv(skb, phy);
1002                 mt7915_mcu_bss_ra_tlv(skb, vif, phy);
1003                 mt7915_mcu_bss_hw_amsdu_tlv(skb);
1004
1005                 if (vif->bss_conf.he_support)
1006                         mt7915_mcu_bss_he_tlv(skb, vif, phy);
1007
1008                 if (mvif->omac_idx >= EXT_BSSID_START &&
1009                     mvif->omac_idx < REPEATER_BSSID_START)
1010                         mt7915_mcu_bss_ext_tlv(skb, mvif);
1011         }
1012
1013         return mt76_mcu_skb_send_msg(&phy->dev->mt76, skb,
1014                                      MCU_EXT_CMD_BSS_INFO_UPDATE, true);
1015 }
1016
1017 /** starec & wtbl **/
1018 static int
1019 mt7915_mcu_sta_key_tlv(struct mt7915_sta *msta, struct sk_buff *skb,
1020                        struct ieee80211_key_conf *key, enum set_key_cmd cmd)
1021 {
1022         struct mt7915_sta_key_conf *bip = &msta->bip;
1023         struct sta_rec_sec *sec;
1024         struct tlv *tlv;
1025         u32 len = sizeof(*sec);
1026
1027         tlv = mt7915_mcu_add_tlv(skb, STA_REC_KEY_V2, sizeof(*sec));
1028
1029         sec = (struct sta_rec_sec *)tlv;
1030         sec->add = cmd;
1031
1032         if (cmd == SET_KEY) {
1033                 struct sec_key *sec_key;
1034                 u8 cipher;
1035
1036                 cipher = mt7915_mcu_get_cipher(key->cipher);
1037                 if (cipher == MT_CIPHER_NONE)
1038                         return -EOPNOTSUPP;
1039
1040                 sec_key = &sec->key[0];
1041                 sec_key->cipher_len = sizeof(*sec_key);
1042
1043                 if (cipher == MT_CIPHER_BIP_CMAC_128) {
1044                         sec_key->cipher_id = MT_CIPHER_AES_CCMP;
1045                         sec_key->key_id = bip->keyidx;
1046                         sec_key->key_len = 16;
1047                         memcpy(sec_key->key, bip->key, 16);
1048
1049                         sec_key = &sec->key[1];
1050                         sec_key->cipher_id = MT_CIPHER_BIP_CMAC_128;
1051                         sec_key->cipher_len = sizeof(*sec_key);
1052                         sec_key->key_len = 16;
1053                         memcpy(sec_key->key, key->key, 16);
1054
1055                         sec->n_cipher = 2;
1056                 } else {
1057                         sec_key->cipher_id = cipher;
1058                         sec_key->key_id = key->keyidx;
1059                         sec_key->key_len = key->keylen;
1060                         memcpy(sec_key->key, key->key, key->keylen);
1061
1062                         if (cipher == MT_CIPHER_TKIP) {
1063                                 /* Rx/Tx MIC keys are swapped */
1064                                 memcpy(sec_key->key + 16, key->key + 24, 8);
1065                                 memcpy(sec_key->key + 24, key->key + 16, 8);
1066                         }
1067
1068                         /* store key_conf for BIP batch update */
1069                         if (cipher == MT_CIPHER_AES_CCMP) {
1070                                 memcpy(bip->key, key->key, key->keylen);
1071                                 bip->keyidx = key->keyidx;
1072                         }
1073
1074                         len -= sizeof(*sec_key);
1075                         sec->n_cipher = 1;
1076                 }
1077         } else {
1078                 len -= sizeof(sec->key);
1079                 sec->n_cipher = 0;
1080         }
1081         sec->len = cpu_to_le16(len);
1082
1083         return 0;
1084 }
1085
1086 int mt7915_mcu_add_key(struct mt7915_dev *dev, struct ieee80211_vif *vif,
1087                        struct mt7915_sta *msta, struct ieee80211_key_conf *key,
1088                        enum set_key_cmd cmd)
1089 {
1090         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1091         struct sk_buff *skb;
1092         int len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_sec);
1093         int ret;
1094
1095         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
1096         if (IS_ERR(skb))
1097                 return PTR_ERR(skb);
1098
1099         ret = mt7915_mcu_sta_key_tlv(msta, skb, key, cmd);
1100         if (ret)
1101                 return ret;
1102
1103         return mt76_mcu_skb_send_msg(&dev->mt76, skb,
1104                                      MCU_EXT_CMD_STA_REC_UPDATE, true);
1105 }
1106
1107 static void
1108 mt7915_mcu_sta_ba_tlv(struct sk_buff *skb,
1109                       struct ieee80211_ampdu_params *params,
1110                       bool enable, bool tx)
1111 {
1112         struct sta_rec_ba *ba;
1113         struct tlv *tlv;
1114
1115         tlv = mt7915_mcu_add_tlv(skb, STA_REC_BA, sizeof(*ba));
1116
1117         ba = (struct sta_rec_ba *)tlv;
1118         ba->ba_type = tx ? MT_BA_TYPE_ORIGINATOR : MT_BA_TYPE_RECIPIENT;
1119         ba->winsize = cpu_to_le16(params->buf_size);
1120         ba->ssn = cpu_to_le16(params->ssn);
1121         ba->ba_en = enable << params->tid;
1122         ba->amsdu = params->amsdu;
1123         ba->tid = params->tid;
1124 }
1125
1126 static void
1127 mt7915_mcu_wtbl_ba_tlv(struct sk_buff *skb,
1128                        struct ieee80211_ampdu_params *params,
1129                        bool enable, bool tx, void *sta_wtbl,
1130                        void *wtbl_tlv)
1131 {
1132         struct wtbl_ba *ba;
1133         struct tlv *tlv;
1134
1135         tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_BA, sizeof(*ba),
1136                                         wtbl_tlv, sta_wtbl);
1137
1138         ba = (struct wtbl_ba *)tlv;
1139         ba->tid = params->tid;
1140
1141         if (tx) {
1142                 ba->ba_type = MT_BA_TYPE_ORIGINATOR;
1143                 ba->sn = enable ? cpu_to_le16(params->ssn) : 0;
1144                 ba->ba_en = enable;
1145         } else {
1146                 memcpy(ba->peer_addr, params->sta->addr, ETH_ALEN);
1147                 ba->ba_type = MT_BA_TYPE_RECIPIENT;
1148                 ba->rst_ba_tid = params->tid;
1149                 ba->rst_ba_sel = RST_BA_MAC_TID_MATCH;
1150                 ba->rst_ba_sb = 1;
1151         }
1152
1153         if (enable && tx)
1154                 ba->ba_winsize = cpu_to_le16(params->buf_size);
1155 }
1156
1157 static int
1158 mt7915_mcu_sta_ba(struct mt7915_dev *dev,
1159                   struct ieee80211_ampdu_params *params,
1160                   bool enable, bool tx)
1161 {
1162         struct mt7915_sta *msta = (struct mt7915_sta *)params->sta->drv_priv;
1163         struct mt7915_vif *mvif = msta->vif;
1164         struct wtbl_req_hdr *wtbl_hdr;
1165         struct tlv *sta_wtbl;
1166         struct sk_buff *skb;
1167         int ret;
1168
1169         if (enable && tx && !params->amsdu)
1170                 msta->wcid.amsdu = false;
1171
1172         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
1173                                        MT7915_STA_UPDATE_MAX_SIZE);
1174         if (IS_ERR(skb))
1175                 return PTR_ERR(skb);
1176
1177         sta_wtbl = mt7915_mcu_add_tlv(skb, STA_REC_WTBL, sizeof(struct tlv));
1178
1179         wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_SET, sta_wtbl,
1180                                              &skb);
1181         mt7915_mcu_wtbl_ba_tlv(skb, params, enable, tx, sta_wtbl, wtbl_hdr);
1182
1183         ret = mt76_mcu_skb_send_msg(&dev->mt76, skb,
1184                                     MCU_EXT_CMD_STA_REC_UPDATE, true);
1185         if (ret)
1186                 return ret;
1187
1188         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
1189                                        MT7915_STA_UPDATE_MAX_SIZE);
1190         if (IS_ERR(skb))
1191                 return PTR_ERR(skb);
1192
1193         mt7915_mcu_sta_ba_tlv(skb, params, enable, tx);
1194
1195         return mt76_mcu_skb_send_msg(&dev->mt76, skb,
1196                                      MCU_EXT_CMD_STA_REC_UPDATE, true);
1197 }
1198
1199 int mt7915_mcu_add_tx_ba(struct mt7915_dev *dev,
1200                          struct ieee80211_ampdu_params *params,
1201                          bool enable)
1202 {
1203         return mt7915_mcu_sta_ba(dev, params, enable, true);
1204 }
1205
1206 int mt7915_mcu_add_rx_ba(struct mt7915_dev *dev,
1207                          struct ieee80211_ampdu_params *params,
1208                          bool enable)
1209 {
1210         return mt7915_mcu_sta_ba(dev, params, enable, false);
1211 }
1212
1213 static void
1214 mt7915_mcu_wtbl_generic_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
1215                             struct ieee80211_sta *sta, void *sta_wtbl,
1216                             void *wtbl_tlv)
1217 {
1218         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1219         struct wtbl_generic *generic;
1220         struct wtbl_rx *rx;
1221         struct tlv *tlv;
1222
1223         tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_GENERIC, sizeof(*generic),
1224                                         wtbl_tlv, sta_wtbl);
1225
1226         generic = (struct wtbl_generic *)tlv;
1227
1228         if (sta) {
1229                 memcpy(generic->peer_addr, sta->addr, ETH_ALEN);
1230                 generic->partial_aid = cpu_to_le16(sta->aid);
1231                 generic->muar_idx = mvif->omac_idx;
1232                 generic->qos = sta->wme;
1233         } else {
1234                 /* use BSSID in station mode */
1235                 if (vif->type == NL80211_IFTYPE_STATION)
1236                         memcpy(generic->peer_addr, vif->bss_conf.bssid,
1237                                ETH_ALEN);
1238                 else
1239                         eth_broadcast_addr(generic->peer_addr);
1240
1241                 generic->muar_idx = 0xe;
1242         }
1243
1244         tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_RX, sizeof(*rx),
1245                                         wtbl_tlv, sta_wtbl);
1246
1247         rx = (struct wtbl_rx *)tlv;
1248         rx->rca1 = sta ? vif->type != NL80211_IFTYPE_AP : 1;
1249         rx->rca2 = 1;
1250         rx->rv = 1;
1251 }
1252
1253 static void
1254 mt7915_mcu_sta_basic_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
1255                          struct ieee80211_sta *sta, bool enable)
1256 {
1257 #define EXTRA_INFO_VER          BIT(0)
1258 #define EXTRA_INFO_NEW          BIT(1)
1259         struct sta_rec_basic *basic;
1260         struct tlv *tlv;
1261
1262         tlv = mt7915_mcu_add_tlv(skb, STA_REC_BASIC, sizeof(*basic));
1263
1264         basic = (struct sta_rec_basic *)tlv;
1265         basic->extra_info = cpu_to_le16(EXTRA_INFO_VER);
1266
1267         if (enable) {
1268                 basic->extra_info |= cpu_to_le16(EXTRA_INFO_NEW);
1269                 basic->conn_state = CONN_STATE_PORT_SECURE;
1270         } else {
1271                 basic->conn_state = CONN_STATE_DISCONNECT;
1272         }
1273
1274         if (!sta) {
1275                 basic->conn_type = cpu_to_le32(CONNECTION_INFRA_BC);
1276                 eth_broadcast_addr(basic->peer_addr);
1277                 return;
1278         }
1279
1280         switch (vif->type) {
1281         case NL80211_IFTYPE_MESH_POINT:
1282         case NL80211_IFTYPE_AP:
1283                 basic->conn_type = cpu_to_le32(CONNECTION_INFRA_STA);
1284                 break;
1285         case NL80211_IFTYPE_STATION:
1286                 basic->conn_type = cpu_to_le32(CONNECTION_INFRA_AP);
1287                 break;
1288         case NL80211_IFTYPE_ADHOC:
1289                 basic->conn_type = cpu_to_le32(CONNECTION_IBSS_ADHOC);
1290                 break;
1291         default:
1292                 WARN_ON(1);
1293                 break;
1294         }
1295
1296         memcpy(basic->peer_addr, sta->addr, ETH_ALEN);
1297         basic->aid = cpu_to_le16(sta->aid);
1298         basic->qos = sta->wme;
1299 }
1300
1301 static void
1302 mt7915_mcu_sta_he_tlv(struct sk_buff *skb, struct ieee80211_sta *sta)
1303 {
1304         struct ieee80211_sta_he_cap *he_cap = &sta->he_cap;
1305         struct ieee80211_he_cap_elem *elem = &he_cap->he_cap_elem;
1306         struct sta_rec_he *he;
1307         struct tlv *tlv;
1308         u32 cap = 0;
1309
1310         tlv = mt7915_mcu_add_tlv(skb, STA_REC_HE, sizeof(*he));
1311
1312         he = (struct sta_rec_he *)tlv;
1313
1314         if (elem->mac_cap_info[0] & IEEE80211_HE_MAC_CAP0_HTC_HE)
1315                 cap |= STA_REC_HE_CAP_HTC;
1316
1317         if (elem->mac_cap_info[2] & IEEE80211_HE_MAC_CAP2_BSR)
1318                 cap |= STA_REC_HE_CAP_BSR;
1319
1320         if (elem->mac_cap_info[3] & IEEE80211_HE_MAC_CAP3_OMI_CONTROL)
1321                 cap |= STA_REC_HE_CAP_OM;
1322
1323         if (elem->mac_cap_info[4] & IEEE80211_HE_MAC_CAP4_AMDSU_IN_AMPDU)
1324                 cap |= STA_REC_HE_CAP_AMSDU_IN_AMPDU;
1325
1326         if (elem->mac_cap_info[4] & IEEE80211_HE_MAC_CAP4_BQR)
1327                 cap |= STA_REC_HE_CAP_BQR;
1328
1329         if (elem->phy_cap_info[0] &
1330             (IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_RU_MAPPING_IN_2G |
1331              IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_RU_MAPPING_IN_5G))
1332                 cap |= STA_REC_HE_CAP_BW20_RU242_SUPPORT;
1333
1334         if (elem->phy_cap_info[1] &
1335             IEEE80211_HE_PHY_CAP1_LDPC_CODING_IN_PAYLOAD)
1336                 cap |= STA_REC_HE_CAP_LDPC;
1337
1338         if (elem->phy_cap_info[1] &
1339             IEEE80211_HE_PHY_CAP1_HE_LTF_AND_GI_FOR_HE_PPDUS_0_8US)
1340                 cap |= STA_REC_HE_CAP_SU_PPDU_1LTF_8US_GI;
1341
1342         if (elem->phy_cap_info[2] &
1343             IEEE80211_HE_PHY_CAP2_NDP_4x_LTF_AND_3_2US)
1344                 cap |= STA_REC_HE_CAP_NDP_4LTF_3DOT2MS_GI;
1345
1346         if (elem->phy_cap_info[2] &
1347             IEEE80211_HE_PHY_CAP2_STBC_TX_UNDER_80MHZ)
1348                 cap |= STA_REC_HE_CAP_LE_EQ_80M_TX_STBC;
1349
1350         if (elem->phy_cap_info[2] &
1351             IEEE80211_HE_PHY_CAP2_STBC_RX_UNDER_80MHZ)
1352                 cap |= STA_REC_HE_CAP_LE_EQ_80M_RX_STBC;
1353
1354         if (elem->phy_cap_info[6] &
1355             IEEE80211_HE_PHY_CAP6_PARTIAL_BW_EXT_RANGE)
1356                 cap |= STA_REC_HE_CAP_PARTIAL_BW_EXT_RANGE;
1357
1358         if (elem->phy_cap_info[7] &
1359             IEEE80211_HE_PHY_CAP7_HE_SU_MU_PPDU_4XLTF_AND_08_US_GI)
1360                 cap |= STA_REC_HE_CAP_SU_MU_PPDU_4LTF_8US_GI;
1361
1362         if (elem->phy_cap_info[7] &
1363             IEEE80211_HE_PHY_CAP7_STBC_TX_ABOVE_80MHZ)
1364                 cap |= STA_REC_HE_CAP_GT_80M_TX_STBC;
1365
1366         if (elem->phy_cap_info[7] &
1367             IEEE80211_HE_PHY_CAP7_STBC_RX_ABOVE_80MHZ)
1368                 cap |= STA_REC_HE_CAP_GT_80M_RX_STBC;
1369
1370         if (elem->phy_cap_info[8] &
1371             IEEE80211_HE_PHY_CAP8_HE_ER_SU_PPDU_4XLTF_AND_08_US_GI)
1372                 cap |= STA_REC_HE_CAP_ER_SU_PPDU_4LTF_8US_GI;
1373
1374         if (elem->phy_cap_info[8] &
1375             IEEE80211_HE_PHY_CAP8_HE_ER_SU_1XLTF_AND_08_US_GI)
1376                 cap |= STA_REC_HE_CAP_ER_SU_PPDU_1LTF_8US_GI;
1377
1378         if (elem->phy_cap_info[9] &
1379             IEEE80211_HE_PHY_CAP9_NON_TRIGGERED_CQI_FEEDBACK)
1380                 cap |= STA_REC_HE_CAP_TRIG_CQI_FK;
1381
1382         if (elem->phy_cap_info[9] &
1383             IEEE80211_HE_PHY_CAP9_TX_1024_QAM_LESS_THAN_242_TONE_RU)
1384                 cap |= STA_REC_HE_CAP_TX_1024QAM_UNDER_RU242;
1385
1386         if (elem->phy_cap_info[9] &
1387             IEEE80211_HE_PHY_CAP9_RX_1024_QAM_LESS_THAN_242_TONE_RU)
1388                 cap |= STA_REC_HE_CAP_RX_1024QAM_UNDER_RU242;
1389
1390         he->he_cap = cpu_to_le32(cap);
1391
1392         switch (sta->bandwidth) {
1393         case IEEE80211_STA_RX_BW_160:
1394                 if (elem->phy_cap_info[0] &
1395                     IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_80PLUS80_MHZ_IN_5G)
1396                         he->max_nss_mcs[CMD_HE_MCS_BW8080] =
1397                                 he_cap->he_mcs_nss_supp.rx_mcs_80p80;
1398
1399                 he->max_nss_mcs[CMD_HE_MCS_BW160] =
1400                                 he_cap->he_mcs_nss_supp.rx_mcs_160;
1401                 fallthrough;
1402         default:
1403                 he->max_nss_mcs[CMD_HE_MCS_BW80] =
1404                                 he_cap->he_mcs_nss_supp.rx_mcs_80;
1405                 break;
1406         }
1407
1408         he->t_frame_dur =
1409                 HE_MAC(CAP1_TF_MAC_PAD_DUR_MASK, elem->mac_cap_info[1]);
1410         he->max_ampdu_exp =
1411                 HE_MAC(CAP3_MAX_AMPDU_LEN_EXP_MASK, elem->mac_cap_info[3]);
1412
1413         he->bw_set =
1414                 HE_PHY(CAP0_CHANNEL_WIDTH_SET_MASK, elem->phy_cap_info[0]);
1415         he->device_class =
1416                 HE_PHY(CAP1_DEVICE_CLASS_A, elem->phy_cap_info[1]);
1417         he->punc_pream_rx =
1418                 HE_PHY(CAP1_PREAMBLE_PUNC_RX_MASK, elem->phy_cap_info[1]);
1419
1420         he->dcm_tx_mode =
1421                 HE_PHY(CAP3_DCM_MAX_CONST_TX_MASK, elem->phy_cap_info[3]);
1422         he->dcm_tx_max_nss =
1423                 HE_PHY(CAP3_DCM_MAX_TX_NSS_2, elem->phy_cap_info[3]);
1424         he->dcm_rx_mode =
1425                 HE_PHY(CAP3_DCM_MAX_CONST_RX_MASK, elem->phy_cap_info[3]);
1426         he->dcm_rx_max_nss =
1427                 HE_PHY(CAP3_DCM_MAX_RX_NSS_2, elem->phy_cap_info[3]);
1428         he->dcm_rx_max_nss =
1429                 HE_PHY(CAP8_DCM_MAX_RU_MASK, elem->phy_cap_info[8]);
1430
1431         he->pkt_ext = 2;
1432 }
1433
1434 static void
1435 mt7915_mcu_sta_uapsd_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1436                      struct ieee80211_vif *vif)
1437 {
1438         struct sta_rec_uapsd *uapsd;
1439         struct tlv *tlv;
1440
1441         if (vif->type != NL80211_IFTYPE_AP || !sta->wme)
1442                 return;
1443
1444         tlv = mt7915_mcu_add_tlv(skb, STA_REC_APPS, sizeof(*uapsd));
1445         uapsd = (struct sta_rec_uapsd *)tlv;
1446
1447         if (sta->uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_VO) {
1448                 uapsd->dac_map |= BIT(3);
1449                 uapsd->tac_map |= BIT(3);
1450         }
1451         if (sta->uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_VI) {
1452                 uapsd->dac_map |= BIT(2);
1453                 uapsd->tac_map |= BIT(2);
1454         }
1455         if (sta->uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_BE) {
1456                 uapsd->dac_map |= BIT(1);
1457                 uapsd->tac_map |= BIT(1);
1458         }
1459         if (sta->uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_BK) {
1460                 uapsd->dac_map |= BIT(0);
1461                 uapsd->tac_map |= BIT(0);
1462         }
1463         uapsd->max_sp = sta->max_sp;
1464 }
1465
1466 static void
1467 mt7915_mcu_sta_muru_tlv(struct sk_buff *skb, struct ieee80211_sta *sta)
1468 {
1469         struct ieee80211_sta_he_cap *he_cap = &sta->he_cap;
1470         struct ieee80211_he_cap_elem *elem = &he_cap->he_cap_elem;
1471         struct sta_rec_muru *muru;
1472         struct tlv *tlv;
1473
1474         tlv = mt7915_mcu_add_tlv(skb, STA_REC_MURU, sizeof(*muru));
1475
1476         muru = (struct sta_rec_muru *)tlv;
1477         muru->cfg.ofdma_dl_en = true;
1478         muru->cfg.mimo_dl_en = true;
1479
1480         muru->ofdma_dl.punc_pream_rx =
1481                 HE_PHY(CAP1_PREAMBLE_PUNC_RX_MASK, elem->phy_cap_info[1]);
1482         muru->ofdma_dl.he_20m_in_40m_2g =
1483                 HE_PHY(CAP8_20MHZ_IN_40MHZ_HE_PPDU_IN_2G, elem->phy_cap_info[8]);
1484         muru->ofdma_dl.he_20m_in_160m =
1485                 HE_PHY(CAP8_20MHZ_IN_160MHZ_HE_PPDU, elem->phy_cap_info[8]);
1486         muru->ofdma_dl.he_80m_in_160m =
1487                 HE_PHY(CAP8_80MHZ_IN_160MHZ_HE_PPDU, elem->phy_cap_info[8]);
1488         muru->ofdma_dl.lt16_sigb = 0;
1489         muru->ofdma_dl.rx_su_comp_sigb = 0;
1490         muru->ofdma_dl.rx_su_non_comp_sigb = 0;
1491
1492         muru->ofdma_ul.t_frame_dur =
1493                 HE_MAC(CAP1_TF_MAC_PAD_DUR_MASK, elem->mac_cap_info[1]);
1494         muru->ofdma_ul.mu_cascading =
1495                 HE_MAC(CAP2_MU_CASCADING, elem->mac_cap_info[2]);
1496         muru->ofdma_ul.uo_ra =
1497                 HE_MAC(CAP3_OFDMA_RA, elem->mac_cap_info[3]);
1498         muru->ofdma_ul.he_2x996_tone = 0;
1499         muru->ofdma_ul.rx_t_frame_11ac = 0;
1500
1501         muru->mimo_dl.vht_mu_bfee =
1502                 !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_MU_BEAMFORMEE_CAPABLE);
1503         muru->mimo_dl.partial_bw_dl_mimo =
1504                 HE_PHY(CAP6_PARTIAL_BANDWIDTH_DL_MUMIMO, elem->phy_cap_info[6]);
1505
1506         muru->mimo_ul.full_ul_mimo =
1507                 HE_PHY(CAP2_UL_MU_FULL_MU_MIMO, elem->phy_cap_info[2]);
1508         muru->mimo_ul.partial_ul_mimo =
1509                 HE_PHY(CAP2_UL_MU_PARTIAL_MU_MIMO, elem->phy_cap_info[2]);
1510 }
1511
1512 static int
1513 mt7915_mcu_add_mu(struct mt7915_dev *dev, struct ieee80211_vif *vif,
1514                   struct ieee80211_sta *sta)
1515 {
1516         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1517         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
1518         struct sk_buff *skb;
1519         int len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_muru);
1520
1521         if (!sta->vht_cap.vht_supported && !sta->he_cap.has_he)
1522                 return 0;
1523
1524         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
1525         if (IS_ERR(skb))
1526                 return PTR_ERR(skb);
1527
1528         /* starec muru */
1529         mt7915_mcu_sta_muru_tlv(skb, sta);
1530
1531         return mt76_mcu_skb_send_msg(&dev->mt76, skb,
1532                                      MCU_EXT_CMD_STA_REC_UPDATE, true);
1533 }
1534
1535 static void
1536 mt7915_mcu_sta_amsdu_tlv(struct sk_buff *skb, struct ieee80211_sta *sta)
1537 {
1538         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
1539         struct sta_rec_amsdu *amsdu;
1540         struct tlv *tlv;
1541
1542         if (!sta->max_amsdu_len)
1543             return;
1544
1545         tlv = mt7915_mcu_add_tlv(skb, STA_REC_HW_AMSDU, sizeof(*amsdu));
1546         amsdu = (struct sta_rec_amsdu *)tlv;
1547         amsdu->max_amsdu_num = 8;
1548         amsdu->amsdu_en = true;
1549         amsdu->max_mpdu_size = sta->max_amsdu_len >=
1550                                IEEE80211_MAX_MPDU_LEN_VHT_7991;
1551         msta->wcid.amsdu = true;
1552 }
1553
1554 static bool
1555 mt7915_hw_amsdu_supported(struct ieee80211_vif *vif)
1556 {
1557         switch (vif->type) {
1558         case NL80211_IFTYPE_AP:
1559         case NL80211_IFTYPE_STATION:
1560                 return true;
1561         default:
1562                 return false;
1563         }
1564 }
1565
1566 static void
1567 mt7915_mcu_sta_tlv(struct mt7915_dev *dev, struct sk_buff *skb,
1568                    struct ieee80211_sta *sta, struct ieee80211_vif *vif)
1569 {
1570         struct tlv *tlv;
1571
1572         /* starec ht */
1573         if (sta->ht_cap.ht_supported) {
1574                 struct sta_rec_ht *ht;
1575
1576                 tlv = mt7915_mcu_add_tlv(skb, STA_REC_HT, sizeof(*ht));
1577                 ht = (struct sta_rec_ht *)tlv;
1578                 ht->ht_cap = cpu_to_le16(sta->ht_cap.cap);
1579
1580                 if (mt7915_hw_amsdu_supported(vif))
1581                         mt7915_mcu_sta_amsdu_tlv(skb, sta);
1582         }
1583
1584         /* starec vht */
1585         if (sta->vht_cap.vht_supported) {
1586                 struct sta_rec_vht *vht;
1587
1588                 tlv = mt7915_mcu_add_tlv(skb, STA_REC_VHT, sizeof(*vht));
1589                 vht = (struct sta_rec_vht *)tlv;
1590                 vht->vht_cap = cpu_to_le32(sta->vht_cap.cap);
1591                 vht->vht_rx_mcs_map = sta->vht_cap.vht_mcs.rx_mcs_map;
1592                 vht->vht_tx_mcs_map = sta->vht_cap.vht_mcs.tx_mcs_map;
1593         }
1594
1595         /* starec he */
1596         if (sta->he_cap.has_he)
1597                 mt7915_mcu_sta_he_tlv(skb, sta);
1598
1599         /* starec uapsd */
1600         mt7915_mcu_sta_uapsd_tlv(skb, sta, vif);
1601 }
1602
1603 static void
1604 mt7915_mcu_wtbl_smps_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1605                          void *sta_wtbl, void *wtbl_tlv)
1606 {
1607         struct wtbl_smps *smps;
1608         struct tlv *tlv;
1609
1610         tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_SMPS, sizeof(*smps),
1611                                         wtbl_tlv, sta_wtbl);
1612         smps = (struct wtbl_smps *)tlv;
1613
1614         if (sta->smps_mode == IEEE80211_SMPS_DYNAMIC)
1615                 smps->smps = true;
1616 }
1617
1618 static void
1619 mt7915_mcu_wtbl_ht_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1620                        void *sta_wtbl, void *wtbl_tlv)
1621 {
1622         struct wtbl_ht *ht = NULL;
1623         struct tlv *tlv;
1624
1625         /* wtbl ht */
1626         if (sta->ht_cap.ht_supported) {
1627                 tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_HT, sizeof(*ht),
1628                                                 wtbl_tlv, sta_wtbl);
1629                 ht = (struct wtbl_ht *)tlv;
1630                 ht->ldpc = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_LDPC_CODING);
1631                 ht->af = sta->ht_cap.ampdu_factor;
1632                 ht->mm = sta->ht_cap.ampdu_density;
1633                 ht->ht = true;
1634         }
1635
1636         /* wtbl vht */
1637         if (sta->vht_cap.vht_supported) {
1638                 struct wtbl_vht *vht;
1639                 u8 af;
1640
1641                 tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_VHT, sizeof(*vht),
1642                                                 wtbl_tlv, sta_wtbl);
1643                 vht = (struct wtbl_vht *)tlv;
1644                 vht->ldpc = !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_RXLDPC);
1645                 vht->vht = true;
1646
1647                 af = FIELD_GET(IEEE80211_VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MASK,
1648                                sta->vht_cap.cap);
1649                 if (ht)
1650                         ht->af = max_t(u8, ht->af, af);
1651         }
1652
1653         mt7915_mcu_wtbl_smps_tlv(skb, sta, sta_wtbl, wtbl_tlv);
1654 }
1655
1656 static void
1657 mt7915_mcu_wtbl_hdr_trans_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
1658                               struct ieee80211_sta *sta,
1659                               void *sta_wtbl, void *wtbl_tlv)
1660 {
1661         struct mt7915_sta *msta;
1662         struct wtbl_hdr_trans *htr = NULL;
1663         struct tlv *tlv;
1664
1665         tlv = mt7915_mcu_add_nested_tlv(skb, WTBL_HDR_TRANS, sizeof(*htr),
1666                                         wtbl_tlv, sta_wtbl);
1667         htr = (struct wtbl_hdr_trans *)tlv;
1668         htr->no_rx_trans = true;
1669         if (vif->type == NL80211_IFTYPE_STATION)
1670                 htr->to_ds = true;
1671         else
1672                 htr->from_ds = true;
1673
1674         if (!sta)
1675                 return;
1676
1677         msta = (struct mt7915_sta *)sta->drv_priv;
1678         if (test_bit(MT_WCID_FLAG_4ADDR, &msta->wcid.flags)) {
1679                 htr->to_ds = true;
1680                 htr->from_ds = true;
1681         }
1682 }
1683
1684 int mt7915_mcu_sta_update_hdr_trans(struct mt7915_dev *dev,
1685                                     struct ieee80211_vif *vif,
1686                                     struct ieee80211_sta *sta)
1687 {
1688         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
1689         struct wtbl_req_hdr *wtbl_hdr;
1690         struct sk_buff *skb;
1691
1692         skb = mt76_mcu_msg_alloc(&dev->mt76, NULL, MT7915_WTBL_UPDATE_MAX_SIZE);
1693         if (!skb)
1694                 return -ENOMEM;
1695
1696         wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_SET, NULL, &skb);
1697         mt7915_mcu_wtbl_hdr_trans_tlv(skb, vif, sta, NULL, wtbl_hdr);
1698
1699         return mt76_mcu_skb_send_msg(&dev->mt76, skb, MCU_EXT_CMD_WTBL_UPDATE,
1700                                      true);
1701 }
1702
1703 int mt7915_mcu_add_smps(struct mt7915_dev *dev, struct ieee80211_vif *vif,
1704                         struct ieee80211_sta *sta)
1705 {
1706         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
1707         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
1708         struct wtbl_req_hdr *wtbl_hdr;
1709         struct tlv *sta_wtbl;
1710         struct sk_buff *skb;
1711
1712         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
1713                                        MT7915_STA_UPDATE_MAX_SIZE);
1714         if (IS_ERR(skb))
1715                 return PTR_ERR(skb);
1716
1717         sta_wtbl = mt7915_mcu_add_tlv(skb, STA_REC_WTBL, sizeof(struct tlv));
1718
1719         wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_SET, sta_wtbl,
1720                                              &skb);
1721         mt7915_mcu_wtbl_smps_tlv(skb, sta, sta_wtbl, wtbl_hdr);
1722
1723         return mt76_mcu_skb_send_msg(&dev->mt76, skb,
1724                                      MCU_EXT_CMD_STA_REC_UPDATE, true);
1725 }
1726
1727 static void
1728 mt7915_mcu_sta_sounding_rate(struct sta_rec_bf *bf)
1729 {
1730         bf->sounding_phy = MT_PHY_TYPE_OFDM;
1731         bf->ndp_rate = 0;                               /* mcs0 */
1732         bf->ndpa_rate = MT7915_CFEND_RATE_DEFAULT;      /* ofdm 24m */
1733         bf->rept_poll_rate = MT7915_CFEND_RATE_DEFAULT; /* ofdm 24m */
1734 }
1735
1736 static void
1737 mt7915_mcu_sta_bfer_ht(struct ieee80211_sta *sta, struct sta_rec_bf *bf)
1738 {
1739         struct ieee80211_mcs_info *mcs = &sta->ht_cap.mcs;
1740         u8 n = 0;
1741
1742         bf->tx_mode = MT_PHY_TYPE_HT;
1743         bf->bf_cap |= MT_IBF;
1744
1745         if (mcs->tx_params & IEEE80211_HT_MCS_TX_RX_DIFF &&
1746             (mcs->tx_params & IEEE80211_HT_MCS_TX_DEFINED))
1747                 n = FIELD_GET(IEEE80211_HT_MCS_TX_MAX_STREAMS_MASK,
1748                               mcs->tx_params);
1749         else if (mcs->rx_mask[3])
1750                 n = 3;
1751         else if (mcs->rx_mask[2])
1752                 n = 2;
1753         else if (mcs->rx_mask[1])
1754                 n = 1;
1755
1756         bf->nc = min_t(u8, bf->nr, n);
1757         bf->ibf_ncol = bf->nc;
1758
1759         if (sta->bandwidth <= IEEE80211_STA_RX_BW_40 && !bf->nc)
1760                 bf->ibf_timeout = 0x48;
1761 }
1762
1763 static void
1764 mt7915_mcu_sta_bfer_vht(struct ieee80211_sta *sta, struct mt7915_phy *phy,
1765                         struct sta_rec_bf *bf)
1766 {
1767         struct ieee80211_sta_vht_cap *pc = &sta->vht_cap;
1768         struct ieee80211_sta_vht_cap *vc = &phy->mt76->sband_5g.sband.vht_cap;
1769         u8 bfee_nr, bfer_nr, n, tx_ant = hweight8(phy->chainmask) - 1;
1770         u16 mcs_map;
1771
1772         bf->tx_mode = MT_PHY_TYPE_VHT;
1773         bf->bf_cap |= MT_EBF;
1774
1775         mt7915_mcu_sta_sounding_rate(bf);
1776
1777         bfee_nr = FIELD_GET(IEEE80211_VHT_CAP_BEAMFORMEE_STS_MASK,
1778                             pc->cap);
1779         bfer_nr = FIELD_GET(IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_MASK,
1780                             vc->cap);
1781         mcs_map = le16_to_cpu(pc->vht_mcs.rx_mcs_map);
1782
1783         n = min_t(u8, bfer_nr, bfee_nr);
1784         bf->nr = min_t(u8, n, tx_ant);
1785         n = mt7915_mcu_get_sta_nss(mcs_map);
1786
1787         bf->nc = min_t(u8, n, bf->nr);
1788         bf->ibf_ncol = bf->nc;
1789
1790         /* force nr from 4 to 2 */
1791         if (sta->bandwidth == IEEE80211_STA_RX_BW_160)
1792                 bf->nr = 1;
1793 }
1794
1795 static void
1796 mt7915_mcu_sta_bfer_he(struct ieee80211_sta *sta, struct ieee80211_vif *vif,
1797                        struct mt7915_phy *phy, struct sta_rec_bf *bf)
1798 {
1799         struct ieee80211_sta_he_cap *pc = &sta->he_cap;
1800         struct ieee80211_he_cap_elem *pe = &pc->he_cap_elem;
1801         const struct ieee80211_he_cap_elem *ve;
1802         const struct ieee80211_sta_he_cap *vc;
1803         u8 bfee_nr, bfer_nr, nss_mcs;
1804         u16 mcs_map;
1805
1806         vc = mt7915_get_he_phy_cap(phy, vif);
1807         ve = &vc->he_cap_elem;
1808
1809         bf->tx_mode = MT_PHY_TYPE_HE_SU;
1810         bf->bf_cap |= MT_EBF;
1811
1812         mt7915_mcu_sta_sounding_rate(bf);
1813
1814         bf->trigger_su = HE_PHY(CAP6_TRIG_SU_BEAMFORMER_FB,
1815                                 pe->phy_cap_info[6]);
1816         bf->trigger_mu = HE_PHY(CAP6_TRIG_MU_BEAMFORMER_FB,
1817                                 pe->phy_cap_info[6]);
1818         bfer_nr = HE_PHY(CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_MASK,
1819                          ve->phy_cap_info[5]);
1820         bfee_nr = HE_PHY(CAP4_BEAMFORMEE_MAX_STS_UNDER_80MHZ_MASK,
1821                          pe->phy_cap_info[4]);
1822
1823         mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.tx_mcs_80);
1824         nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
1825
1826         bf->nr = min_t(u8, bfer_nr, bfee_nr);
1827         bf->nc = min_t(u8, nss_mcs, bf->nr);
1828         bf->ibf_ncol = bf->nc;
1829
1830         if (sta->bandwidth != IEEE80211_STA_RX_BW_160)
1831                 return;
1832
1833         /* go over for 160MHz and 80p80 */
1834         if (pe->phy_cap_info[0] &
1835             IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_160MHZ_IN_5G) {
1836                 mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.rx_mcs_160);
1837                 nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
1838
1839                 bf->nc_bw160 = nss_mcs;
1840         }
1841
1842         if (pe->phy_cap_info[0] &
1843             IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_80PLUS80_MHZ_IN_5G) {
1844                 mcs_map = le16_to_cpu(pc->he_mcs_nss_supp.rx_mcs_80p80);
1845                 nss_mcs = mt7915_mcu_get_sta_nss(mcs_map);
1846
1847                 if (bf->nc_bw160)
1848                         bf->nc_bw160 = min_t(u8, bf->nc_bw160, nss_mcs);
1849                 else
1850                         bf->nc_bw160 = nss_mcs;
1851         }
1852
1853         bfer_nr = HE_PHY(CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_MASK,
1854                          ve->phy_cap_info[5]);
1855         bfee_nr = HE_PHY(CAP4_BEAMFORMEE_MAX_STS_ABOVE_80MHZ_MASK,
1856                          pe->phy_cap_info[4]);
1857
1858         bf->nr_bw160 = min_t(int, bfer_nr, bfee_nr);
1859 }
1860
1861 static void
1862 mt7915_mcu_sta_bfer_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1863                         struct ieee80211_vif *vif, struct mt7915_phy *phy,
1864                         bool enable)
1865 {
1866         struct sta_rec_bf *bf;
1867         struct tlv *tlv;
1868         int tx_ant = hweight8(phy->chainmask) - 1;
1869         const u8 matrix[4][4] = {
1870                 {0, 0, 0, 0},
1871                 {1, 1, 0, 0},   /* 2x1, 2x2, 2x3, 2x4 */
1872                 {2, 4, 4, 0},   /* 3x1, 3x2, 3x3, 3x4 */
1873                 {3, 5, 6, 0}    /* 4x1, 4x2, 4x3, 4x4 */
1874         };
1875
1876 #define MT_BFER_FREE            cpu_to_le16(GENMASK(15, 0))
1877
1878         tlv = mt7915_mcu_add_tlv(skb, STA_REC_BF, sizeof(*bf));
1879         bf = (struct sta_rec_bf *)tlv;
1880
1881         if (!enable) {
1882                 bf->pfmu = MT_BFER_FREE;
1883                 return;
1884         }
1885
1886         bf->bw = sta->bandwidth;
1887         bf->ibf_dbw = sta->bandwidth;
1888         bf->ibf_nrow = tx_ant;
1889         bf->ibf_timeout = 0x18;
1890
1891         if (sta->he_cap.has_he)
1892                 mt7915_mcu_sta_bfer_he(sta, vif, phy, bf);
1893         else if (sta->vht_cap.vht_supported)
1894                 mt7915_mcu_sta_bfer_vht(sta, phy, bf);
1895         else if (sta->ht_cap.ht_supported)
1896                 mt7915_mcu_sta_bfer_ht(sta, bf);
1897
1898         if (bf->bf_cap & MT_EBF && bf->nr != tx_ant)
1899                 bf->mem_20m = matrix[tx_ant][bf->nc];
1900         else
1901                 bf->mem_20m = matrix[bf->nr][bf->nc];
1902
1903         switch (sta->bandwidth) {
1904         case IEEE80211_STA_RX_BW_160:
1905         case IEEE80211_STA_RX_BW_80:
1906                 bf->mem_total = bf->mem_20m * 2;
1907                 break;
1908         case IEEE80211_STA_RX_BW_40:
1909                 bf->mem_total = bf->mem_20m;
1910                 break;
1911         case IEEE80211_STA_RX_BW_20:
1912         default:
1913                 break;
1914         }
1915 }
1916
1917 static void
1918 mt7915_mcu_sta_bfee_tlv(struct sk_buff *skb, struct ieee80211_sta *sta,
1919                         struct mt7915_phy *phy)
1920 {
1921         struct sta_rec_bfee *bfee;
1922         struct tlv *tlv;
1923         int tx_ant = hweight8(phy->chainmask) - 1;
1924         u8 nr = 0;
1925
1926         tlv = mt7915_mcu_add_tlv(skb, STA_REC_BFEE, sizeof(*bfee));
1927         bfee = (struct sta_rec_bfee *)tlv;
1928
1929         if (sta->he_cap.has_he) {
1930                 struct ieee80211_he_cap_elem *pe = &sta->he_cap.he_cap_elem;
1931
1932                 nr = HE_PHY(CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_MASK,
1933                             pe->phy_cap_info[5]);
1934         } else if (sta->vht_cap.vht_supported) {
1935                 struct ieee80211_sta_vht_cap *pc = &sta->vht_cap;
1936
1937                 nr = FIELD_GET(IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_MASK,
1938                                pc->cap);
1939         }
1940
1941         /* reply with identity matrix to avoid 2x2 BF negative gain */
1942         if (nr == 1 && tx_ant == 2)
1943                 bfee->fb_identity_matrix = true;
1944 }
1945
1946 static u8
1947 mt7915_mcu_sta_txbf_type(struct mt7915_phy *phy, struct ieee80211_vif *vif,
1948                          struct ieee80211_sta *sta)
1949 {
1950         u8 type = 0;
1951
1952         if (vif->type != NL80211_IFTYPE_STATION &&
1953             vif->type != NL80211_IFTYPE_AP)
1954                 return 0;
1955
1956         if (sta->he_cap.has_he) {
1957                 struct ieee80211_he_cap_elem *pe;
1958                 const struct ieee80211_he_cap_elem *ve;
1959                 const struct ieee80211_sta_he_cap *vc;
1960
1961                 pe = &sta->he_cap.he_cap_elem;
1962                 vc = mt7915_get_he_phy_cap(phy, vif);
1963                 ve = &vc->he_cap_elem;
1964
1965                 if ((HE_PHY(CAP3_SU_BEAMFORMER, pe->phy_cap_info[3]) ||
1966                      HE_PHY(CAP4_MU_BEAMFORMER, pe->phy_cap_info[4])) &&
1967                     HE_PHY(CAP4_SU_BEAMFORMEE, ve->phy_cap_info[4]))
1968                         type |= MT_STA_BFEE;
1969
1970                 if ((HE_PHY(CAP3_SU_BEAMFORMER, ve->phy_cap_info[3]) ||
1971                      HE_PHY(CAP4_MU_BEAMFORMER, ve->phy_cap_info[4])) &&
1972                     HE_PHY(CAP4_SU_BEAMFORMEE, pe->phy_cap_info[4]))
1973                         type |= MT_STA_BFER;
1974         } else if (sta->vht_cap.vht_supported) {
1975                 struct ieee80211_sta_vht_cap *pc;
1976                 struct ieee80211_sta_vht_cap *vc;
1977                 u32 cr, ce;
1978
1979                 pc = &sta->vht_cap;
1980                 vc = &phy->mt76->sband_5g.sband.vht_cap;
1981                 cr = IEEE80211_VHT_CAP_SU_BEAMFORMER_CAPABLE |
1982                      IEEE80211_VHT_CAP_MU_BEAMFORMER_CAPABLE;
1983                 ce = IEEE80211_VHT_CAP_SU_BEAMFORMEE_CAPABLE |
1984                      IEEE80211_VHT_CAP_MU_BEAMFORMEE_CAPABLE;
1985
1986                 if ((pc->cap & cr) && (vc->cap & ce))
1987                         type |= MT_STA_BFEE;
1988
1989                 if ((vc->cap & cr) && (pc->cap & ce))
1990                         type |= MT_STA_BFER;
1991         } else if (sta->ht_cap.ht_supported) {
1992                 /* TODO: iBF */
1993         }
1994
1995         return type;
1996 }
1997
1998 static int
1999 mt7915_mcu_add_txbf(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2000                     struct ieee80211_sta *sta, bool enable)
2001 {
2002         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2003         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
2004         struct mt7915_phy *phy;
2005         struct sk_buff *skb;
2006         int r, len;
2007         u8 type;
2008
2009         phy = mvif->band_idx ? mt7915_ext_phy(dev) : &dev->phy;
2010
2011         type = mt7915_mcu_sta_txbf_type(phy, vif, sta);
2012
2013         /* must keep each tag independent */
2014
2015         /* starec bf */
2016         if (type & MT_STA_BFER) {
2017                 len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_bf);
2018
2019                 skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
2020                 if (IS_ERR(skb))
2021                         return PTR_ERR(skb);
2022
2023                 mt7915_mcu_sta_bfer_tlv(skb, sta, vif, phy, enable);
2024
2025                 r = mt76_mcu_skb_send_msg(&dev->mt76, skb,
2026                                           MCU_EXT_CMD_STA_REC_UPDATE, true);
2027                 if (r)
2028                         return r;
2029         }
2030
2031         /* starec bfee */
2032         if (type & MT_STA_BFEE) {
2033                 len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_bfee);
2034
2035                 skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
2036                 if (IS_ERR(skb))
2037                         return PTR_ERR(skb);
2038
2039                 mt7915_mcu_sta_bfee_tlv(skb, sta, phy);
2040
2041                 r = mt76_mcu_skb_send_msg(&dev->mt76, skb,
2042                                           MCU_EXT_CMD_STA_REC_UPDATE, true);
2043                 if (r)
2044                         return r;
2045         }
2046
2047         return 0;
2048 }
2049
2050 static void
2051 mt7915_mcu_sta_rate_ctrl_tlv(struct sk_buff *skb, struct mt7915_dev *dev,
2052                              struct ieee80211_vif *vif,
2053                              struct ieee80211_sta *sta)
2054 {
2055         struct cfg80211_chan_def *chandef = &dev->mphy.chandef;
2056         struct sta_rec_ra *ra;
2057         struct tlv *tlv;
2058         enum nl80211_band band = chandef->chan->band;
2059         u32 supp_rate = sta->supp_rates[band];
2060         int n_rates = hweight32(supp_rate);
2061         u32 cap = sta->wme ? STA_CAP_WMM : 0;
2062         u8 i, nss = sta->rx_nss, mcs = 0;
2063
2064         tlv = mt7915_mcu_add_tlv(skb, STA_REC_RA, sizeof(*ra));
2065
2066         ra = (struct sta_rec_ra *)tlv;
2067         ra->valid = true;
2068         ra->auto_rate = true;
2069         ra->phy_mode = mt7915_get_phy_mode(dev, vif, band, sta);
2070         ra->channel = chandef->chan->hw_value;
2071         ra->bw = sta->bandwidth;
2072         ra->rate_len = n_rates;
2073         ra->phy.bw = sta->bandwidth;
2074
2075         if (n_rates) {
2076                 if (band == NL80211_BAND_2GHZ) {
2077                         ra->supp_mode = MODE_CCK;
2078                         ra->supp_cck_rate = supp_rate & GENMASK(3, 0);
2079                         ra->phy.type = MT_PHY_TYPE_CCK;
2080
2081                         if (n_rates > 4) {
2082                                 ra->supp_mode |= MODE_OFDM;
2083                                 ra->supp_ofdm_rate = supp_rate >> 4;
2084                                 ra->phy.type = MT_PHY_TYPE_OFDM;
2085                         }
2086                 } else {
2087                         ra->supp_mode = MODE_OFDM;
2088                         ra->supp_ofdm_rate = supp_rate;
2089                         ra->phy.type = MT_PHY_TYPE_OFDM;
2090                 }
2091         }
2092
2093         if (sta->ht_cap.ht_supported) {
2094                 for (i = 0; i < nss; i++)
2095                         ra->ht_mcs[i] = sta->ht_cap.mcs.rx_mask[i];
2096
2097                 ra->supp_ht_mcs = *(__le32 *)ra->ht_mcs;
2098                 ra->supp_mode |= MODE_HT;
2099                 mcs = hweight32(le32_to_cpu(ra->supp_ht_mcs)) - 1;
2100                 ra->af = sta->ht_cap.ampdu_factor;
2101                 ra->ht_gf = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_GRN_FLD);
2102
2103                 cap |= STA_CAP_HT;
2104                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_SGI_20)
2105                         cap |= STA_CAP_SGI_20;
2106                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_SGI_40)
2107                         cap |= STA_CAP_SGI_40;
2108                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_TX_STBC)
2109                         cap |= STA_CAP_TX_STBC;
2110                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_RX_STBC)
2111                         cap |= STA_CAP_RX_STBC;
2112                 if (sta->ht_cap.cap & IEEE80211_HT_CAP_LDPC_CODING)
2113                         cap |= STA_CAP_LDPC;
2114         }
2115
2116         if (sta->vht_cap.vht_supported) {
2117                 u16 mcs_map = le16_to_cpu(sta->vht_cap.vht_mcs.rx_mcs_map);
2118                 u16 vht_mcs;
2119                 u8 af, mcs_prev;
2120
2121                 af = FIELD_GET(IEEE80211_VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MASK,
2122                                sta->vht_cap.cap);
2123                 ra->af = max_t(u8, ra->af, af);
2124
2125                 cap |= STA_CAP_VHT;
2126                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_SHORT_GI_80)
2127                         cap |= STA_CAP_VHT_SGI_80;
2128                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_SHORT_GI_160)
2129                         cap |= STA_CAP_VHT_SGI_160;
2130                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_TXSTBC)
2131                         cap |= STA_CAP_VHT_TX_STBC;
2132                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_RXSTBC_1)
2133                         cap |= STA_CAP_VHT_RX_STBC;
2134                 if (sta->vht_cap.cap & IEEE80211_VHT_CAP_RXLDPC)
2135                         cap |= STA_CAP_VHT_LDPC;
2136
2137                 ra->supp_mode |= MODE_VHT;
2138                 for (mcs = 0, i = 0; i < nss; i++, mcs_map >>= 2) {
2139                         switch (mcs_map & 0x3) {
2140                         case IEEE80211_VHT_MCS_SUPPORT_0_9:
2141                                 vht_mcs = GENMASK(9, 0);
2142                                 break;
2143                         case IEEE80211_VHT_MCS_SUPPORT_0_8:
2144                                 vht_mcs = GENMASK(8, 0);
2145                                 break;
2146                         case IEEE80211_VHT_MCS_SUPPORT_0_7:
2147                                 vht_mcs = GENMASK(7, 0);
2148                                 break;
2149                         default:
2150                                 vht_mcs = 0;
2151                         }
2152
2153                         ra->supp_vht_mcs[i] = cpu_to_le16(vht_mcs);
2154
2155                         mcs_prev = hweight16(vht_mcs) - 1;
2156                         if (mcs_prev > mcs)
2157                                 mcs = mcs_prev;
2158
2159                         /* only support 2ss on 160MHz */
2160                         if (i > 1 && (ra->bw == CMD_CBW_160MHZ ||
2161                                       ra->bw == CMD_CBW_8080MHZ))
2162                                 break;
2163                 }
2164         }
2165
2166         if (sta->he_cap.has_he) {
2167                 ra->supp_mode |= MODE_HE;
2168                 cap |= STA_CAP_HE;
2169         }
2170
2171         ra->sta_status = cpu_to_le32(cap);
2172
2173         switch (BIT(fls(ra->supp_mode) - 1)) {
2174         case MODE_VHT:
2175                 ra->phy.type = MT_PHY_TYPE_VHT;
2176                 ra->phy.mcs = mcs;
2177                 ra->phy.nss = nss;
2178                 ra->phy.stbc = !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_TXSTBC);
2179                 ra->phy.ldpc = !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_RXLDPC);
2180                 ra->phy.sgi =
2181                         !!(sta->vht_cap.cap & IEEE80211_VHT_CAP_SHORT_GI_80);
2182                 break;
2183         case MODE_HT:
2184                 ra->phy.type = MT_PHY_TYPE_HT;
2185                 ra->phy.mcs = mcs;
2186                 ra->phy.ldpc = sta->ht_cap.cap & IEEE80211_HT_CAP_LDPC_CODING;
2187                 ra->phy.stbc = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_TX_STBC);
2188                 ra->phy.sgi = !!(sta->ht_cap.cap & IEEE80211_HT_CAP_SGI_20);
2189                 break;
2190         default:
2191                 break;
2192         }
2193 }
2194
2195 int mt7915_mcu_add_rate_ctrl(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2196                              struct ieee80211_sta *sta)
2197 {
2198         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2199         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
2200         struct sk_buff *skb;
2201         int len = sizeof(struct sta_req_hdr) + sizeof(struct sta_rec_ra);
2202
2203         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
2204         if (IS_ERR(skb))
2205                 return PTR_ERR(skb);
2206
2207         mt7915_mcu_sta_rate_ctrl_tlv(skb, dev, vif, sta);
2208
2209         return mt76_mcu_skb_send_msg(&dev->mt76, skb,
2210                                      MCU_EXT_CMD_STA_REC_UPDATE, true);
2211 }
2212
2213 static int
2214 mt7915_mcu_add_group(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2215                      struct ieee80211_sta *sta)
2216 {
2217 #define MT_STA_BSS_GROUP                1
2218         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2219         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
2220         struct {
2221                 __le32 action;
2222                 u8 wlan_idx_lo;
2223                 u8 status;
2224                 u8 wlan_idx_hi;
2225                 u8 rsv0[5];
2226                 __le32 val;
2227                 u8 rsv1[8];
2228         } __packed req = {
2229                 .action = cpu_to_le32(MT_STA_BSS_GROUP),
2230                 .wlan_idx_lo = to_wcid_lo(msta->wcid.idx),
2231                 .wlan_idx_hi = to_wcid_hi(msta->wcid.idx),
2232                 .val = cpu_to_le32(mvif->idx % 16),
2233         };
2234
2235         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_DRR_CTRL, &req,
2236                                  sizeof(req), true);
2237 }
2238
2239 int mt7915_mcu_add_sta_adv(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2240                            struct ieee80211_sta *sta, bool enable)
2241 {
2242         int ret;
2243
2244         if (!sta)
2245                 return 0;
2246
2247         /* must keep the order */
2248         ret = mt7915_mcu_add_group(dev, vif, sta);
2249         if (ret)
2250                 return ret;
2251
2252         ret = mt7915_mcu_add_txbf(dev, vif, sta, enable);
2253         if (ret)
2254                 return ret;
2255
2256         ret = mt7915_mcu_add_mu(dev, vif, sta);
2257         if (ret)
2258                 return ret;
2259
2260         if (enable)
2261                 return mt7915_mcu_add_rate_ctrl(dev, vif, sta);
2262
2263         return 0;
2264 }
2265
2266 int mt7915_mcu_add_sta(struct mt7915_dev *dev, struct ieee80211_vif *vif,
2267                        struct ieee80211_sta *sta, bool enable)
2268 {
2269         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2270         struct wtbl_req_hdr *wtbl_hdr;
2271         struct mt7915_sta *msta;
2272         struct tlv *sta_wtbl;
2273         struct sk_buff *skb;
2274
2275         msta = sta ? (struct mt7915_sta *)sta->drv_priv : &mvif->sta;
2276
2277         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta,
2278                                        MT7915_STA_UPDATE_MAX_SIZE);
2279         if (IS_ERR(skb))
2280                 return PTR_ERR(skb);
2281
2282         mt7915_mcu_sta_basic_tlv(skb, vif, sta, enable);
2283         if (enable && sta)
2284                 mt7915_mcu_sta_tlv(dev, skb, sta, vif);
2285
2286         sta_wtbl = mt7915_mcu_add_tlv(skb, STA_REC_WTBL, sizeof(struct tlv));
2287
2288         wtbl_hdr = mt7915_mcu_alloc_wtbl_req(dev, msta, WTBL_RESET_AND_SET,
2289                                              sta_wtbl, &skb);
2290         if (enable) {
2291                 mt7915_mcu_wtbl_generic_tlv(skb, vif, sta, sta_wtbl, wtbl_hdr);
2292                 mt7915_mcu_wtbl_hdr_trans_tlv(skb, vif, sta, sta_wtbl, wtbl_hdr);
2293                 if (sta)
2294                         mt7915_mcu_wtbl_ht_tlv(skb, sta, sta_wtbl, wtbl_hdr);
2295         }
2296
2297         return mt76_mcu_skb_send_msg(&dev->mt76, skb,
2298                                      MCU_EXT_CMD_STA_REC_UPDATE, true);
2299 }
2300
2301 int mt7915_mcu_set_fixed_rate(struct mt7915_dev *dev,
2302                               struct ieee80211_sta *sta, u32 rate)
2303 {
2304         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
2305         struct mt7915_vif *mvif = msta->vif;
2306         struct sta_rec_ra_fixed *ra;
2307         struct sk_buff *skb;
2308         struct tlv *tlv;
2309         int len = sizeof(struct sta_req_hdr) + sizeof(*ra);
2310
2311         skb = mt7915_mcu_alloc_sta_req(dev, mvif, msta, len);
2312         if (IS_ERR(skb))
2313                 return PTR_ERR(skb);
2314
2315         tlv = mt7915_mcu_add_tlv(skb, STA_REC_RA_UPDATE, sizeof(*ra));
2316         ra = (struct sta_rec_ra_fixed *)tlv;
2317
2318         if (!rate) {
2319                 ra->field = cpu_to_le32(RATE_PARAM_AUTO);
2320                 goto out;
2321         } else {
2322                 ra->field = cpu_to_le32(RATE_PARAM_FIXED);
2323         }
2324
2325         ra->phy.type = FIELD_GET(RATE_CFG_PHY_TYPE, rate);
2326         ra->phy.bw = FIELD_GET(RATE_CFG_BW, rate);
2327         ra->phy.nss = FIELD_GET(RATE_CFG_NSS, rate);
2328         ra->phy.mcs = FIELD_GET(RATE_CFG_MCS, rate);
2329         ra->phy.stbc = FIELD_GET(RATE_CFG_STBC, rate);
2330
2331         if (ra->phy.bw)
2332                 ra->phy.ldpc = 7;
2333         else
2334                 ra->phy.ldpc = FIELD_GET(RATE_CFG_LDPC, rate) * 7;
2335
2336         /* HT/VHT - SGI: 1, LGI: 0; HE - SGI: 0, MGI: 1, LGI: 2 */
2337         if (ra->phy.type > MT_PHY_TYPE_VHT)
2338                 ra->phy.sgi = ra->phy.mcs * 85;
2339         else
2340                 ra->phy.sgi = ra->phy.mcs * 15;
2341
2342 out:
2343         return mt76_mcu_skb_send_msg(&dev->mt76, skb,
2344                                      MCU_EXT_CMD_STA_REC_UPDATE, true);
2345 }
2346
2347 int mt7915_mcu_add_dev_info(struct mt7915_phy *phy,
2348                             struct ieee80211_vif *vif, bool enable)
2349 {
2350         struct mt7915_dev *dev = phy->dev;
2351         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2352         struct {
2353                 struct req_hdr {
2354                         u8 omac_idx;
2355                         u8 dbdc_idx;
2356                         __le16 tlv_num;
2357                         u8 is_tlv_append;
2358                         u8 rsv[3];
2359                 } __packed hdr;
2360                 struct req_tlv {
2361                         __le16 tag;
2362                         __le16 len;
2363                         u8 active;
2364                         u8 dbdc_idx;
2365                         u8 omac_addr[ETH_ALEN];
2366                 } __packed tlv;
2367         } data = {
2368                 .hdr = {
2369                         .omac_idx = mvif->omac_idx,
2370                         .dbdc_idx = mvif->band_idx,
2371                         .tlv_num = cpu_to_le16(1),
2372                         .is_tlv_append = 1,
2373                 },
2374                 .tlv = {
2375                         .tag = cpu_to_le16(DEV_INFO_ACTIVE),
2376                         .len = cpu_to_le16(sizeof(struct req_tlv)),
2377                         .active = enable,
2378                         .dbdc_idx = mvif->band_idx,
2379                 },
2380         };
2381
2382         if (mvif->omac_idx >= REPEATER_BSSID_START)
2383                 return mt7915_mcu_muar_config(phy, vif, false, enable);
2384
2385         memcpy(data.tlv.omac_addr, vif->addr, ETH_ALEN);
2386         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_DEV_INFO_UPDATE,
2387                                  &data, sizeof(data), true);
2388 }
2389
2390 static void
2391 mt7915_mcu_beacon_csa(struct sk_buff *rskb, struct sk_buff *skb,
2392                       struct bss_info_bcn *bcn,
2393                       struct ieee80211_mutable_offsets *offs)
2394 {
2395         if (offs->cntdwn_counter_offs[0]) {
2396                 struct tlv *tlv;
2397                 struct bss_info_bcn_csa *csa;
2398
2399                 tlv = mt7915_mcu_add_nested_subtlv(rskb, BSS_INFO_BCN_CSA,
2400                                                    sizeof(*csa), &bcn->sub_ntlv,
2401                                                    &bcn->len);
2402                 csa = (struct bss_info_bcn_csa *)tlv;
2403                 csa->cnt = skb->data[offs->cntdwn_counter_offs[0]];
2404         }
2405 }
2406
2407 static void
2408 mt7915_mcu_beacon_cont(struct mt7915_dev *dev, struct sk_buff *rskb,
2409                        struct sk_buff *skb, struct bss_info_bcn *bcn,
2410                        struct ieee80211_mutable_offsets *offs)
2411 {
2412         struct mt76_wcid *wcid = &dev->mt76.global_wcid;
2413         struct bss_info_bcn_cont *cont;
2414         struct tlv *tlv;
2415         u8 *buf;
2416         int len = sizeof(*cont) + MT_TXD_SIZE + skb->len;
2417
2418         tlv = mt7915_mcu_add_nested_subtlv(rskb, BSS_INFO_BCN_CONTENT,
2419                                            len, &bcn->sub_ntlv, &bcn->len);
2420
2421         cont = (struct bss_info_bcn_cont *)tlv;
2422         cont->pkt_len = cpu_to_le16(MT_TXD_SIZE + skb->len);
2423         cont->tim_ofs = cpu_to_le16(offs->tim_offset);
2424
2425         if (offs->cntdwn_counter_offs[0])
2426                 cont->csa_ofs = cpu_to_le16(offs->cntdwn_counter_offs[0] - 4);
2427
2428         buf = (u8 *)tlv + sizeof(*cont);
2429         mt7915_mac_write_txwi(dev, (__le32 *)buf, skb, wcid, NULL,
2430                               true);
2431         memcpy(buf + MT_TXD_SIZE, skb->data, skb->len);
2432 }
2433
2434 int mt7915_mcu_add_beacon(struct ieee80211_hw *hw,
2435                           struct ieee80211_vif *vif, int en)
2436 {
2437 #define MAX_BEACON_SIZE 512
2438         struct mt7915_dev *dev = mt7915_hw_dev(hw);
2439         struct mt7915_phy *phy = mt7915_hw_phy(hw);
2440         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
2441         struct ieee80211_mutable_offsets offs;
2442         struct ieee80211_tx_info *info;
2443         struct sk_buff *skb, *rskb;
2444         struct tlv *tlv;
2445         struct bss_info_bcn *bcn;
2446         int len = MT7915_BEACON_UPDATE_SIZE + MAX_BEACON_SIZE;
2447
2448         skb = ieee80211_beacon_get_template(hw, vif, &offs);
2449         if (!skb)
2450                 return -EINVAL;
2451
2452         if (skb->len > MAX_BEACON_SIZE - MT_TXD_SIZE) {
2453                 dev_err(dev->mt76.dev, "Bcn size limit exceed\n");
2454                 dev_kfree_skb(skb);
2455                 return -EINVAL;
2456         }
2457
2458         rskb = mt7915_mcu_alloc_sta_req(dev, mvif, NULL, len);
2459         if (IS_ERR(rskb)) {
2460                 dev_kfree_skb(skb);
2461                 return PTR_ERR(rskb);
2462         }
2463
2464         tlv = mt7915_mcu_add_tlv(rskb, BSS_INFO_OFFLOAD, sizeof(*bcn));
2465         bcn = (struct bss_info_bcn *)tlv;
2466         bcn->enable = en;
2467
2468         if (mvif->band_idx) {
2469                 info = IEEE80211_SKB_CB(skb);
2470                 info->hw_queue |= MT_TX_HW_QUEUE_EXT_PHY;
2471         }
2472
2473         /* TODO: subtag - bss color count & 11v MBSSID */
2474         mt7915_mcu_beacon_csa(rskb, skb, bcn, &offs);
2475         mt7915_mcu_beacon_cont(dev, rskb, skb, bcn, &offs);
2476         dev_kfree_skb(skb);
2477
2478         return mt76_mcu_skb_send_msg(&phy->dev->mt76, rskb,
2479                                      MCU_EXT_CMD_BSS_INFO_UPDATE, true);
2480 }
2481
2482 static int mt7915_mcu_start_firmware(struct mt7915_dev *dev, u32 addr,
2483                                      u32 option)
2484 {
2485         struct {
2486                 __le32 option;
2487                 __le32 addr;
2488         } req = {
2489                 .option = cpu_to_le32(option),
2490                 .addr = cpu_to_le32(addr),
2491         };
2492
2493         return mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_FW_START_REQ, &req,
2494                                  sizeof(req), true);
2495 }
2496
2497 static int mt7915_mcu_restart(struct mt76_dev *dev)
2498 {
2499         struct {
2500                 u8 power_mode;
2501                 u8 rsv[3];
2502         } req = {
2503                 .power_mode = 1,
2504         };
2505
2506         return mt76_mcu_send_msg(dev, -MCU_CMD_NIC_POWER_CTRL, &req,
2507                                  sizeof(req), false);
2508 }
2509
2510 static int mt7915_mcu_patch_sem_ctrl(struct mt7915_dev *dev, bool get)
2511 {
2512         struct {
2513                 __le32 op;
2514         } req = {
2515                 .op = cpu_to_le32(get ? PATCH_SEM_GET : PATCH_SEM_RELEASE),
2516         };
2517
2518         return mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_PATCH_SEM_CONTROL, &req,
2519                                  sizeof(req), true);
2520 }
2521
2522 static int mt7915_mcu_start_patch(struct mt7915_dev *dev)
2523 {
2524         struct {
2525                 u8 check_crc;
2526                 u8 reserved[3];
2527         } req = {
2528                 .check_crc = 0,
2529         };
2530
2531         return mt76_mcu_send_msg(&dev->mt76, -MCU_CMD_PATCH_FINISH_REQ, &req,
2532                                  sizeof(req), true);
2533 }
2534
2535 static int mt7915_driver_own(struct mt7915_dev *dev)
2536 {
2537         u32 reg = mt7915_reg_map_l1(dev, MT_TOP_LPCR_HOST_BAND0);
2538
2539         mt76_wr(dev, reg, MT_TOP_LPCR_HOST_DRV_OWN);
2540         if (!mt76_poll_msec(dev, reg, MT_TOP_LPCR_HOST_FW_OWN,
2541                             0, 500)) {
2542                 dev_err(dev->mt76.dev, "Timeout for driver own\n");
2543                 return -EIO;
2544         }
2545
2546         return 0;
2547 }
2548
2549 static int mt7915_mcu_init_download(struct mt7915_dev *dev, u32 addr,
2550                                     u32 len, u32 mode)
2551 {
2552         struct {
2553                 __le32 addr;
2554                 __le32 len;
2555                 __le32 mode;
2556         } req = {
2557                 .addr = cpu_to_le32(addr),
2558                 .len = cpu_to_le32(len),
2559                 .mode = cpu_to_le32(mode),
2560         };
2561         int attr;
2562
2563         if (req.addr == cpu_to_le32(MCU_PATCH_ADDRESS))
2564                 attr = -MCU_CMD_PATCH_START_REQ;
2565         else
2566                 attr = -MCU_CMD_TARGET_ADDRESS_LEN_REQ;
2567
2568         return mt76_mcu_send_msg(&dev->mt76, attr, &req, sizeof(req), true);
2569 }
2570
2571 static int mt7915_load_patch(struct mt7915_dev *dev)
2572 {
2573         const struct mt7915_patch_hdr *hdr;
2574         const struct firmware *fw = NULL;
2575         int i, ret, sem;
2576
2577         sem = mt7915_mcu_patch_sem_ctrl(dev, 1);
2578         switch (sem) {
2579         case PATCH_IS_DL:
2580                 return 0;
2581         case PATCH_NOT_DL_SEM_SUCCESS:
2582                 break;
2583         default:
2584                 dev_err(dev->mt76.dev, "Failed to get patch semaphore\n");
2585                 return -EAGAIN;
2586         }
2587
2588         ret = request_firmware(&fw, MT7915_ROM_PATCH, dev->mt76.dev);
2589         if (ret)
2590                 goto out;
2591
2592         if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
2593                 dev_err(dev->mt76.dev, "Invalid firmware\n");
2594                 ret = -EINVAL;
2595                 goto out;
2596         }
2597
2598         hdr = (const struct mt7915_patch_hdr *)(fw->data);
2599
2600         dev_info(dev->mt76.dev, "HW/SW Version: 0x%x, Build Time: %.16s\n",
2601                  be32_to_cpu(hdr->hw_sw_ver), hdr->build_date);
2602
2603         for (i = 0; i < be32_to_cpu(hdr->desc.n_region); i++) {
2604                 struct mt7915_patch_sec *sec;
2605                 const u8 *dl;
2606                 u32 len, addr;
2607
2608                 sec = (struct mt7915_patch_sec *)(fw->data + sizeof(*hdr) +
2609                                                   i * sizeof(*sec));
2610                 if ((be32_to_cpu(sec->type) & PATCH_SEC_TYPE_MASK) !=
2611                     PATCH_SEC_TYPE_INFO) {
2612                         ret = -EINVAL;
2613                         goto out;
2614                 }
2615
2616                 addr = be32_to_cpu(sec->info.addr);
2617                 len = be32_to_cpu(sec->info.len);
2618                 dl = fw->data + be32_to_cpu(sec->offs);
2619
2620                 ret = mt7915_mcu_init_download(dev, addr, len,
2621                                                DL_MODE_NEED_RSP);
2622                 if (ret) {
2623                         dev_err(dev->mt76.dev, "Download request failed\n");
2624                         goto out;
2625                 }
2626
2627                 ret = mt76_mcu_send_firmware(&dev->mt76, -MCU_CMD_FW_SCATTER,
2628                                              dl, len);
2629                 if (ret) {
2630                         dev_err(dev->mt76.dev, "Failed to send patch\n");
2631                         goto out;
2632                 }
2633         }
2634
2635         ret = mt7915_mcu_start_patch(dev);
2636         if (ret)
2637                 dev_err(dev->mt76.dev, "Failed to start patch\n");
2638
2639 out:
2640         sem = mt7915_mcu_patch_sem_ctrl(dev, 0);
2641         switch (sem) {
2642         case PATCH_REL_SEM_SUCCESS:
2643                 break;
2644         default:
2645                 ret = -EAGAIN;
2646                 dev_err(dev->mt76.dev, "Failed to release patch semaphore\n");
2647                 goto out;
2648         }
2649         release_firmware(fw);
2650
2651         return ret;
2652 }
2653
2654 static u32 mt7915_mcu_gen_dl_mode(u8 feature_set, bool is_wa)
2655 {
2656         u32 ret = 0;
2657
2658         ret |= (feature_set & FW_FEATURE_SET_ENCRYPT) ?
2659                (DL_MODE_ENCRYPT | DL_MODE_RESET_SEC_IV) : 0;
2660         ret |= FIELD_PREP(DL_MODE_KEY_IDX,
2661                           FIELD_GET(FW_FEATURE_SET_KEY_IDX, feature_set));
2662         ret |= DL_MODE_NEED_RSP;
2663         ret |= is_wa ? DL_MODE_WORKING_PDA_CR4 : 0;
2664
2665         return ret;
2666 }
2667
2668 static int
2669 mt7915_mcu_send_ram_firmware(struct mt7915_dev *dev,
2670                              const struct mt7915_fw_trailer *hdr,
2671                              const u8 *data, bool is_wa)
2672 {
2673         int i, offset = 0;
2674         u32 override = 0, option = 0;
2675
2676         for (i = 0; i < hdr->n_region; i++) {
2677                 const struct mt7915_fw_region *region;
2678                 int err;
2679                 u32 len, addr, mode;
2680
2681                 region = (const struct mt7915_fw_region *)((const u8 *)hdr -
2682                          (hdr->n_region - i) * sizeof(*region));
2683                 mode = mt7915_mcu_gen_dl_mode(region->feature_set, is_wa);
2684                 len = le32_to_cpu(region->len);
2685                 addr = le32_to_cpu(region->addr);
2686
2687                 if (region->feature_set & FW_FEATURE_OVERRIDE_ADDR)
2688                         override = addr;
2689
2690                 err = mt7915_mcu_init_download(dev, addr, len, mode);
2691                 if (err) {
2692                         dev_err(dev->mt76.dev, "Download request failed\n");
2693                         return err;
2694                 }
2695
2696                 err = mt76_mcu_send_firmware(&dev->mt76, -MCU_CMD_FW_SCATTER,
2697                                              data + offset, len);
2698                 if (err) {
2699                         dev_err(dev->mt76.dev, "Failed to send firmware.\n");
2700                         return err;
2701                 }
2702
2703                 offset += len;
2704         }
2705
2706         if (override)
2707                 option |= FW_START_OVERRIDE;
2708
2709         if (is_wa)
2710                 option |= FW_START_WORKING_PDA_CR4;
2711
2712         return mt7915_mcu_start_firmware(dev, override, option);
2713 }
2714
2715 static int mt7915_load_ram(struct mt7915_dev *dev)
2716 {
2717         const struct mt7915_fw_trailer *hdr;
2718         const struct firmware *fw;
2719         int ret;
2720
2721         ret = request_firmware(&fw, MT7915_FIRMWARE_WM, dev->mt76.dev);
2722         if (ret)
2723                 return ret;
2724
2725         if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
2726                 dev_err(dev->mt76.dev, "Invalid firmware\n");
2727                 ret = -EINVAL;
2728                 goto out;
2729         }
2730
2731         hdr = (const struct mt7915_fw_trailer *)(fw->data + fw->size -
2732                                         sizeof(*hdr));
2733
2734         dev_info(dev->mt76.dev, "WM Firmware Version: %.10s, Build Time: %.15s\n",
2735                  hdr->fw_ver, hdr->build_date);
2736
2737         ret = mt7915_mcu_send_ram_firmware(dev, hdr, fw->data, false);
2738         if (ret) {
2739                 dev_err(dev->mt76.dev, "Failed to start WM firmware\n");
2740                 goto out;
2741         }
2742
2743         release_firmware(fw);
2744
2745         ret = request_firmware(&fw, MT7915_FIRMWARE_WA, dev->mt76.dev);
2746         if (ret)
2747                 return ret;
2748
2749         if (!fw || !fw->data || fw->size < sizeof(*hdr)) {
2750                 dev_err(dev->mt76.dev, "Invalid firmware\n");
2751                 ret = -EINVAL;
2752                 goto out;
2753         }
2754
2755         hdr = (const struct mt7915_fw_trailer *)(fw->data + fw->size -
2756                                         sizeof(*hdr));
2757
2758         dev_info(dev->mt76.dev, "WA Firmware Version: %.10s, Build Time: %.15s\n",
2759                  hdr->fw_ver, hdr->build_date);
2760
2761         ret = mt7915_mcu_send_ram_firmware(dev, hdr, fw->data, true);
2762         if (ret) {
2763                 dev_err(dev->mt76.dev, "Failed to start WA firmware\n");
2764                 goto out;
2765         }
2766
2767         snprintf(dev->mt76.hw->wiphy->fw_version,
2768                  sizeof(dev->mt76.hw->wiphy->fw_version),
2769                  "%.10s-%.15s", hdr->fw_ver, hdr->build_date);
2770
2771 out:
2772         release_firmware(fw);
2773
2774         return ret;
2775 }
2776
2777 static int mt7915_load_firmware(struct mt7915_dev *dev)
2778 {
2779         int ret;
2780         u32 val, reg = mt7915_reg_map_l1(dev, MT_TOP_MISC);
2781
2782         val = FIELD_PREP(MT_TOP_MISC_FW_STATE, FW_STATE_FW_DOWNLOAD);
2783
2784         if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE, val, 1000)) {
2785                 /* restart firmware once */
2786                 __mt76_mcu_restart(&dev->mt76);
2787                 if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
2788                                     val, 1000)) {
2789                         dev_err(dev->mt76.dev,
2790                                 "Firmware is not ready for download\n");
2791                         return -EIO;
2792                 }
2793         }
2794
2795         ret = mt7915_load_patch(dev);
2796         if (ret)
2797                 return ret;
2798
2799         ret = mt7915_load_ram(dev);
2800         if (ret)
2801                 return ret;
2802
2803         if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
2804                             FIELD_PREP(MT_TOP_MISC_FW_STATE,
2805                                        FW_STATE_WACPU_RDY), 1000)) {
2806                 dev_err(dev->mt76.dev, "Timeout for initializing firmware\n");
2807                 return -EIO;
2808         }
2809
2810         mt76_queue_tx_cleanup(dev, dev->mt76.q_mcu[MT_MCUQ_FWDL], false);
2811
2812         dev_dbg(dev->mt76.dev, "Firmware init done\n");
2813
2814         return 0;
2815 }
2816
2817 int mt7915_mcu_fw_log_2_host(struct mt7915_dev *dev, u8 ctrl)
2818 {
2819         struct {
2820                 u8 ctrl_val;
2821                 u8 pad[3];
2822         } data = {
2823                 .ctrl_val = ctrl
2824         };
2825
2826         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_FW_LOG_2_HOST, &data,
2827                                  sizeof(data), true);
2828 }
2829
2830 int mt7915_mcu_fw_dbg_ctrl(struct mt7915_dev *dev, u32 module, u8 level)
2831 {
2832         struct {
2833                 u8 ver;
2834                 u8 pad;
2835                 __le16 len;
2836                 u8 level;
2837                 u8 rsv[3];
2838                 __le32 module_idx;
2839         } data = {
2840                 .module_idx = cpu_to_le32(module),
2841                 .level = level,
2842         };
2843
2844         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_FW_DBG_CTRL, &data,
2845                                  sizeof(data), false);
2846 }
2847
2848 static int mt7915_mcu_set_mwds(struct mt7915_dev *dev, bool enabled)
2849 {
2850         struct {
2851                 u8 enable;
2852                 u8 _rsv[3];
2853         } __packed req = {
2854                 .enable = enabled
2855         };
2856
2857         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_MWDS_SUPPORT, &req,
2858                                  sizeof(req), false);
2859 }
2860
2861 int mt7915_mcu_init(struct mt7915_dev *dev)
2862 {
2863         static const struct mt76_mcu_ops mt7915_mcu_ops = {
2864                 .headroom = sizeof(struct mt7915_mcu_txd),
2865                 .mcu_skb_send_msg = mt7915_mcu_send_message,
2866                 .mcu_parse_response = mt7915_mcu_parse_response,
2867                 .mcu_restart = mt7915_mcu_restart,
2868         };
2869         int ret;
2870
2871         dev->mt76.mcu_ops = &mt7915_mcu_ops;
2872
2873         ret = mt7915_driver_own(dev);
2874         if (ret)
2875                 return ret;
2876
2877         ret = mt7915_load_firmware(dev);
2878         if (ret)
2879                 return ret;
2880
2881         set_bit(MT76_STATE_MCU_RUNNING, &dev->mphy.state);
2882         mt7915_mcu_fw_log_2_host(dev, 0);
2883         mt7915_mcu_set_mwds(dev, 1);
2884
2885         return 0;
2886 }
2887
2888 void mt7915_mcu_exit(struct mt7915_dev *dev)
2889 {
2890         u32 reg = mt7915_reg_map_l1(dev, MT_TOP_MISC);
2891
2892         __mt76_mcu_restart(&dev->mt76);
2893         if (!mt76_poll_msec(dev, reg, MT_TOP_MISC_FW_STATE,
2894                             FIELD_PREP(MT_TOP_MISC_FW_STATE,
2895                                        FW_STATE_FW_DOWNLOAD), 1000)) {
2896                 dev_err(dev->mt76.dev, "Failed to exit mcu\n");
2897                 return;
2898         }
2899
2900         reg = mt7915_reg_map_l1(dev, MT_TOP_LPCR_HOST_BAND0);
2901         mt76_wr(dev, reg, MT_TOP_LPCR_HOST_FW_OWN);
2902         skb_queue_purge(&dev->mt76.mcu.res_q);
2903 }
2904
2905 int mt7915_mcu_set_mac(struct mt7915_dev *dev, int band,
2906                        bool enable, bool hdr_trans)
2907 {
2908         struct {
2909                 u8 operation;
2910                 u8 enable;
2911                 u8 check_bssid;
2912                 u8 insert_vlan;
2913                 u8 remove_vlan;
2914                 u8 tid;
2915                 u8 mode;
2916                 u8 rsv;
2917         } __packed req_trans = {
2918                 .enable = hdr_trans,
2919         };
2920         struct {
2921                 u8 enable;
2922                 u8 band;
2923                 u8 rsv[2];
2924         } __packed req_mac = {
2925                 .enable = enable,
2926                 .band = band,
2927         };
2928         int ret;
2929
2930         ret = mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_RX_HDR_TRANS,
2931                                 &req_trans, sizeof(req_trans), false);
2932         if (ret)
2933                 return ret;
2934
2935         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_MAC_INIT_CTRL,
2936                                  &req_mac, sizeof(req_mac), true);
2937 }
2938
2939 int mt7915_mcu_set_scs(struct mt7915_dev *dev, u8 band, bool enable)
2940 {
2941         struct {
2942                 __le32 cmd;
2943                 u8 band;
2944                 u8 enable;
2945         } __packed req = {
2946                 .cmd = cpu_to_le32(SCS_ENABLE),
2947                 .band = band,
2948                 .enable = enable + 1,
2949         };
2950
2951         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SCS_CTRL, &req,
2952                                  sizeof(req), false);
2953 }
2954
2955 int mt7915_mcu_set_rts_thresh(struct mt7915_phy *phy, u32 val)
2956 {
2957         struct mt7915_dev *dev = phy->dev;
2958         struct {
2959                 u8 prot_idx;
2960                 u8 band;
2961                 u8 rsv[2];
2962                 __le32 len_thresh;
2963                 __le32 pkt_thresh;
2964         } __packed req = {
2965                 .prot_idx = 1,
2966                 .band = phy != &dev->phy,
2967                 .len_thresh = cpu_to_le32(val),
2968                 .pkt_thresh = cpu_to_le32(0x2),
2969         };
2970
2971         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_PROTECT_CTRL, &req,
2972                                  sizeof(req), true);
2973 }
2974
2975 int mt7915_mcu_set_tx(struct mt7915_dev *dev, struct ieee80211_vif *vif)
2976 {
2977 #define WMM_AIFS_SET            BIT(0)
2978 #define WMM_CW_MIN_SET          BIT(1)
2979 #define WMM_CW_MAX_SET          BIT(2)
2980 #define WMM_TXOP_SET            BIT(3)
2981 #define WMM_PARAM_SET           GENMASK(3, 0)
2982 #define TX_CMD_MODE             1
2983         struct edca {
2984                 u8 queue;
2985                 u8 set;
2986                 u8 aifs;
2987                 u8 cw_min;
2988                 __le16 cw_max;
2989                 __le16 txop;
2990         };
2991         struct mt7915_mcu_tx {
2992                 u8 total;
2993                 u8 action;
2994                 u8 valid;
2995                 u8 mode;
2996
2997                 struct edca edca[IEEE80211_NUM_ACS];
2998         } __packed req = {
2999                 .valid = true,
3000                 .mode = TX_CMD_MODE,
3001                 .total = IEEE80211_NUM_ACS,
3002         };
3003         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
3004         int ac;
3005
3006         for (ac = 0; ac < IEEE80211_NUM_ACS; ac++) {
3007                 struct ieee80211_tx_queue_params *q = &mvif->queue_params[ac];
3008                 struct edca *e = &req.edca[ac];
3009
3010                 e->set = WMM_PARAM_SET;
3011                 e->queue = ac + mvif->wmm_idx * MT7915_MAX_WMM_SETS;
3012                 e->aifs = q->aifs;
3013                 e->txop = cpu_to_le16(q->txop);
3014
3015                 if (q->cw_min)
3016                         e->cw_min = fls(q->cw_min);
3017                 else
3018                         e->cw_min = 5;
3019
3020                 if (q->cw_max)
3021                         e->cw_max = cpu_to_le16(fls(q->cw_max));
3022                 else
3023                         e->cw_max = cpu_to_le16(10);
3024         }
3025         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EDCA_UPDATE, &req,
3026                                  sizeof(req), true);
3027 }
3028
3029 int mt7915_mcu_set_pm(struct mt7915_dev *dev, int band, int enter)
3030 {
3031 #define ENTER_PM_STATE          1
3032 #define EXIT_PM_STATE           2
3033         struct {
3034                 u8 pm_number;
3035                 u8 pm_state;
3036                 u8 bssid[ETH_ALEN];
3037                 u8 dtim_period;
3038                 u8 wlan_idx_lo;
3039                 __le16 bcn_interval;
3040                 __le32 aid;
3041                 __le32 rx_filter;
3042                 u8 band_idx;
3043                 u8 wlan_idx_hi;
3044                 u8 rsv[2];
3045                 __le32 feature;
3046                 u8 omac_idx;
3047                 u8 wmm_idx;
3048                 u8 bcn_loss_cnt;
3049                 u8 bcn_sp_duration;
3050         } __packed req = {
3051                 .pm_number = 5,
3052                 .pm_state = (enter) ? ENTER_PM_STATE : EXIT_PM_STATE,
3053                 .band_idx = band,
3054         };
3055
3056         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_PM_STATE_CTRL, &req,
3057                                  sizeof(req), true);
3058 }
3059
3060 int mt7915_mcu_rdd_cmd(struct mt7915_dev *dev,
3061                        enum mt7915_rdd_cmd cmd, u8 index,
3062                        u8 rx_sel, u8 val)
3063 {
3064         struct {
3065                 u8 ctrl;
3066                 u8 rdd_idx;
3067                 u8 rdd_rx_sel;
3068                 u8 val;
3069                 u8 rsv[4];
3070         } __packed req = {
3071                 .ctrl = cmd,
3072                 .rdd_idx = index,
3073                 .rdd_rx_sel = rx_sel,
3074                 .val = val,
3075         };
3076
3077         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_CTRL, &req,
3078                                  sizeof(req), true);
3079 }
3080
3081 int mt7915_mcu_set_fcc5_lpn(struct mt7915_dev *dev, int val)
3082 {
3083         struct {
3084                 __le32 tag;
3085                 __le16 min_lpn;
3086                 u8 rsv[2];
3087         } __packed req = {
3088                 .tag = cpu_to_le32(0x1),
3089                 .min_lpn = cpu_to_le16(val),
3090         };
3091
3092         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_TH, &req,
3093                                  sizeof(req), true);
3094 }
3095
3096 int mt7915_mcu_set_pulse_th(struct mt7915_dev *dev,
3097                             const struct mt7915_dfs_pulse *pulse)
3098 {
3099         struct {
3100                 __le32 tag;
3101
3102                 __le32 max_width;               /* us */
3103                 __le32 max_pwr;                 /* dbm */
3104                 __le32 min_pwr;                 /* dbm */
3105                 __le32 min_stgr_pri;            /* us */
3106                 __le32 max_stgr_pri;            /* us */
3107                 __le32 min_cr_pri;              /* us */
3108                 __le32 max_cr_pri;              /* us */
3109         } __packed req = {
3110                 .tag = cpu_to_le32(0x3),
3111
3112 #define __req_field(field) .field = cpu_to_le32(pulse->field)
3113                 __req_field(max_width),
3114                 __req_field(max_pwr),
3115                 __req_field(min_pwr),
3116                 __req_field(min_stgr_pri),
3117                 __req_field(max_stgr_pri),
3118                 __req_field(min_cr_pri),
3119                 __req_field(max_cr_pri),
3120 #undef __req_field
3121         };
3122
3123         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_TH, &req,
3124                                  sizeof(req), true);
3125 }
3126
3127 int mt7915_mcu_set_radar_th(struct mt7915_dev *dev, int index,
3128                             const struct mt7915_dfs_pattern *pattern)
3129 {
3130         struct {
3131                 __le32 tag;
3132                 __le16 radar_type;
3133
3134                 u8 enb;
3135                 u8 stgr;
3136                 u8 min_crpn;
3137                 u8 max_crpn;
3138                 u8 min_crpr;
3139                 u8 min_pw;
3140                 __le32 min_pri;
3141                 __le32 max_pri;
3142                 u8 max_pw;
3143                 u8 min_crbn;
3144                 u8 max_crbn;
3145                 u8 min_stgpn;
3146                 u8 max_stgpn;
3147                 u8 min_stgpr;
3148                 u8 rsv[2];
3149                 __le32 min_stgpr_diff;
3150         } __packed req = {
3151                 .tag = cpu_to_le32(0x2),
3152                 .radar_type = cpu_to_le16(index),
3153
3154 #define __req_field_u8(field) .field = pattern->field
3155 #define __req_field_u32(field) .field = cpu_to_le32(pattern->field)
3156                 __req_field_u8(enb),
3157                 __req_field_u8(stgr),
3158                 __req_field_u8(min_crpn),
3159                 __req_field_u8(max_crpn),
3160                 __req_field_u8(min_crpr),
3161                 __req_field_u8(min_pw),
3162                 __req_field_u32(min_pri),
3163                 __req_field_u32(max_pri),
3164                 __req_field_u8(max_pw),
3165                 __req_field_u8(min_crbn),
3166                 __req_field_u8(max_crbn),
3167                 __req_field_u8(min_stgpn),
3168                 __req_field_u8(max_stgpn),
3169                 __req_field_u8(min_stgpr),
3170                 __req_field_u32(min_stgpr_diff),
3171 #undef __req_field_u8
3172 #undef __req_field_u32
3173         };
3174
3175         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_RDD_TH, &req,
3176                                  sizeof(req), true);
3177 }
3178
3179 int mt7915_mcu_set_chan_info(struct mt7915_phy *phy, int cmd)
3180 {
3181         struct mt7915_dev *dev = phy->dev;
3182         struct cfg80211_chan_def *chandef = &phy->mt76->chandef;
3183         int freq1 = chandef->center_freq1;
3184         struct {
3185                 u8 control_ch;
3186                 u8 center_ch;
3187                 u8 bw;
3188                 u8 tx_streams_num;
3189                 u8 rx_streams;  /* mask or num */
3190                 u8 switch_reason;
3191                 u8 band_idx;
3192                 u8 center_ch2;  /* for 80+80 only */
3193                 __le16 cac_case;
3194                 u8 channel_band;
3195                 u8 rsv0;
3196                 __le32 outband_freq;
3197                 u8 txpower_drop;
3198                 u8 ap_bw;
3199                 u8 ap_center_ch;
3200                 u8 rsv1[57];
3201         } __packed req = {
3202                 .control_ch = chandef->chan->hw_value,
3203                 .center_ch = ieee80211_frequency_to_channel(freq1),
3204                 .bw = mt7915_mcu_chan_bw(chandef),
3205                 .tx_streams_num = hweight8(phy->mt76->antenna_mask),
3206                 .rx_streams = phy->mt76->antenna_mask,
3207                 .band_idx = phy != &dev->phy,
3208                 .channel_band = chandef->chan->band,
3209         };
3210
3211 #ifdef CONFIG_NL80211_TESTMODE
3212         if (dev->mt76.test.tx_antenna_mask &&
3213             (dev->mt76.test.state == MT76_TM_STATE_TX_FRAMES ||
3214              dev->mt76.test.state == MT76_TM_STATE_RX_FRAMES)) {
3215                 req.tx_streams_num = fls(dev->mt76.test.tx_antenna_mask);
3216                 req.rx_streams = dev->mt76.test.tx_antenna_mask;
3217         }
3218 #endif
3219
3220         if (dev->mt76.hw->conf.flags & IEEE80211_CONF_OFFCHANNEL)
3221                 req.switch_reason = CH_SWITCH_SCAN_BYPASS_DPD;
3222         else if ((chandef->chan->flags & IEEE80211_CHAN_RADAR) &&
3223                  chandef->chan->dfs_state != NL80211_DFS_AVAILABLE)
3224                 req.switch_reason = CH_SWITCH_DFS;
3225         else
3226                 req.switch_reason = CH_SWITCH_NORMAL;
3227
3228         if (cmd == MCU_EXT_CMD_CHANNEL_SWITCH)
3229                 req.rx_streams = hweight8(req.rx_streams);
3230
3231         if (chandef->width == NL80211_CHAN_WIDTH_80P80) {
3232                 int freq2 = chandef->center_freq2;
3233
3234                 req.center_ch2 = ieee80211_frequency_to_channel(freq2);
3235         }
3236
3237         return mt76_mcu_send_msg(&dev->mt76, cmd, &req, sizeof(req), true);
3238 }
3239
3240 static int mt7915_mcu_set_eeprom_flash(struct mt7915_dev *dev)
3241 {
3242 #define TOTAL_PAGE_MASK         GENMASK(7, 5)
3243 #define PAGE_IDX_MASK           GENMASK(4, 2)
3244 #define PER_PAGE_SIZE           0x400
3245         struct mt7915_mcu_eeprom req = { .buffer_mode = EE_MODE_BUFFER };
3246         u8 total = MT7915_EEPROM_SIZE / PER_PAGE_SIZE;
3247         u8 *eep = (u8 *)dev->mt76.eeprom.data;
3248         int eep_len;
3249         int i;
3250
3251         for (i = 0; i <= total; i++, eep += eep_len) {
3252                 struct sk_buff *skb;
3253                 int ret;
3254
3255                 if (i == total)
3256                         eep_len = MT7915_EEPROM_SIZE % PER_PAGE_SIZE;
3257                 else
3258                         eep_len = PER_PAGE_SIZE;
3259
3260                 skb = mt76_mcu_msg_alloc(&dev->mt76, NULL,
3261                                          sizeof(req) + eep_len);
3262                 if (!skb)
3263                         return -ENOMEM;
3264
3265                 req.format = FIELD_PREP(TOTAL_PAGE_MASK, total) |
3266                              FIELD_PREP(PAGE_IDX_MASK, i) | EE_FORMAT_WHOLE;
3267                 req.len = cpu_to_le16(eep_len);
3268
3269                 skb_put_data(skb, &req, sizeof(req));
3270                 skb_put_data(skb, eep, eep_len);
3271
3272                 ret = mt76_mcu_skb_send_msg(&dev->mt76, skb,
3273                                             MCU_EXT_CMD_EFUSE_BUFFER_MODE, true);
3274                 if (ret)
3275                         return ret;
3276         }
3277
3278         return 0;
3279 }
3280
3281 int mt7915_mcu_set_eeprom(struct mt7915_dev *dev)
3282 {
3283         struct mt7915_mcu_eeprom req = {
3284                 .buffer_mode = EE_MODE_EFUSE,
3285                 .format = EE_FORMAT_WHOLE,
3286         };
3287
3288         if (dev->flash_mode)
3289                 return mt7915_mcu_set_eeprom_flash(dev);
3290
3291         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_EFUSE_BUFFER_MODE,
3292                                  &req, sizeof(req), true);
3293 }
3294
3295 int mt7915_mcu_get_eeprom(struct mt7915_dev *dev, u32 offset)
3296 {
3297         struct mt7915_mcu_eeprom_info req = {
3298                 .addr = cpu_to_le32(round_down(offset, 16)),
3299         };
3300         struct mt7915_mcu_eeprom_info *res;
3301         struct sk_buff *skb;
3302         int ret;
3303         u8 *buf;
3304
3305         ret = mt76_mcu_send_and_get_msg(&dev->mt76, MCU_EXT_CMD_EFUSE_ACCESS, &req,
3306                                 sizeof(req), true, &skb);
3307         if (ret)
3308                 return ret;
3309
3310         res = (struct mt7915_mcu_eeprom_info *)skb->data;
3311         buf = dev->mt76.eeprom.data + le32_to_cpu(res->addr);
3312         memcpy(buf, res->data, 16);
3313         dev_kfree_skb(skb);
3314
3315         return 0;
3316 }
3317
3318 int mt7915_mcu_get_temperature(struct mt7915_dev *dev, int index)
3319 {
3320         struct {
3321                 u8 ctrl_id;
3322                 u8 action;
3323                 u8 band;
3324                 u8 rsv[5];
3325         } req = {
3326                 .ctrl_id = THERMAL_SENSOR_TEMP_QUERY,
3327                 .action = index,
3328         };
3329
3330         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_THERMAL_CTRL, &req,
3331                                  sizeof(req), true);
3332 }
3333
3334 int mt7915_mcu_get_tx_rate(struct mt7915_dev *dev, u32 cmd, u16 wlan_idx)
3335 {
3336         struct {
3337                 __le32 cmd;
3338                 __le16 wlan_idx;
3339                 __le16 ru_idx;
3340                 __le16 direction;
3341                 __le16 dump_group;
3342         } req = {
3343                 .cmd = cpu_to_le32(cmd),
3344                 .wlan_idx = cpu_to_le16(wlan_idx),
3345                 .dump_group = cpu_to_le16(1),
3346         };
3347
3348         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_RATE_CTRL, &req,
3349                                  sizeof(req), false);
3350 }
3351
3352 int mt7915_mcu_set_sku(struct mt7915_phy *phy)
3353 {
3354         struct mt7915_dev *dev = phy->dev;
3355         struct mt76_phy *mphy = phy->mt76;
3356         struct ieee80211_hw *hw = mphy->hw;
3357         struct mt7915_sku_val {
3358                 u8 format_id;
3359                 u8 limit_type;
3360                 u8 dbdc_idx;
3361                 s8 val[MT7915_SKU_RATE_NUM];
3362         } __packed req = {
3363                 .format_id = 4,
3364                 .dbdc_idx = phy != &dev->phy,
3365         };
3366         int i;
3367         s8 *delta;
3368
3369         delta = dev->rate_power[mphy->chandef.chan->band];
3370         mphy->txpower_cur = hw->conf.power_level * 2 +
3371                             delta[MT7915_SKU_MAX_DELTA_IDX];
3372
3373         for (i = 0; i < MT7915_SKU_RATE_NUM; i++)
3374                 req.val[i] = hw->conf.power_level * 2 + delta[i];
3375
3376         return mt76_mcu_send_msg(&dev->mt76,
3377                                  MCU_EXT_CMD_TX_POWER_FEATURE_CTRL, &req,
3378                                  sizeof(req), true);
3379 }
3380
3381 int mt7915_mcu_set_test_param(struct mt7915_dev *dev, u8 param, bool test_mode,
3382                               u8 en)
3383 {
3384         struct {
3385                 u8 test_mode_en;
3386                 u8 param_idx;
3387                 u8 _rsv[2];
3388
3389                 u8 enable;
3390                 u8 _rsv2[3];
3391
3392                 u8 pad[8];
3393         } __packed req = {
3394                 .test_mode_en = test_mode,
3395                 .param_idx = param,
3396                 .enable = en,
3397         };
3398
3399         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_ATE_CTRL, &req,
3400                                  sizeof(req), false);
3401 }
3402
3403 int mt7915_mcu_set_sku_en(struct mt7915_phy *phy, bool enable)
3404 {
3405         struct mt7915_dev *dev = phy->dev;
3406         struct mt7915_sku {
3407                 u8 format_id;
3408                 u8 sku_enable;
3409                 u8 dbdc_idx;
3410                 u8 rsv;
3411         } __packed req = {
3412                 .format_id = 0,
3413                 .dbdc_idx = phy != &dev->phy,
3414                 .sku_enable = enable,
3415         };
3416
3417         return mt76_mcu_send_msg(&dev->mt76,
3418                                  MCU_EXT_CMD_TX_POWER_FEATURE_CTRL, &req,
3419                                  sizeof(req), true);
3420 }
3421
3422 int mt7915_mcu_set_ser(struct mt7915_dev *dev, u8 action, u8 set, u8 band)
3423 {
3424         struct {
3425                 u8 action;
3426                 u8 set;
3427                 u8 band;
3428                 u8 rsv;
3429         } req = {
3430                 .action = action,
3431                 .set = set,
3432                 .band = band,
3433         };
3434
3435         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_SER_TRIGGER,
3436                                  &req, sizeof(req), false);
3437 }
3438
3439 int mt7915_mcu_set_txbf_type(struct mt7915_dev *dev)
3440 {
3441 #define MT_BF_TYPE_UPDATE               20
3442         struct {
3443                 u8 action;
3444                 bool ebf;
3445                 bool ibf;
3446                 u8 rsv;
3447         } __packed req = {
3448                 .action = MT_BF_TYPE_UPDATE,
3449                 .ebf = true,
3450                 .ibf = false,
3451         };
3452
3453         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_TXBF_ACTION, &req,
3454                                  sizeof(req), true);
3455 }
3456
3457 int mt7915_mcu_set_txbf_sounding(struct mt7915_dev *dev)
3458 {
3459 #define MT_BF_PROCESSING                4
3460         struct {
3461                 u8 action;
3462                 u8 snd_mode;
3463                 u8 sta_num;
3464                 u8 rsv;
3465                 u8 wlan_idx[4];
3466                 __le32 snd_period;      /* ms */
3467         } __packed req = {
3468                 .action = true,
3469                 .snd_mode = MT_BF_PROCESSING,
3470         };
3471
3472         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_TXBF_ACTION, &req,
3473                                  sizeof(req), true);
3474 }
3475
3476 int mt7915_mcu_add_obss_spr(struct mt7915_dev *dev, struct ieee80211_vif *vif,
3477                             bool enable)
3478 {
3479 #define MT_SPR_ENABLE           1
3480         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
3481         struct {
3482                 u8 action;
3483                 u8 arg_num;
3484                 u8 band_idx;
3485                 u8 status;
3486                 u8 drop_tx_idx;
3487                 u8 sta_idx;     /* 256 sta */
3488                 u8 rsv[2];
3489                 __le32 val;
3490         } __packed req = {
3491                 .action = MT_SPR_ENABLE,
3492                 .arg_num = 1,
3493                 .band_idx = mvif->band_idx,
3494                 .val = cpu_to_le32(enable),
3495         };
3496
3497         return mt76_mcu_send_msg(&dev->mt76, MCU_EXT_CMD_SET_SPR, &req,
3498                                  sizeof(req), true);
3499 }
3500
3501 int mt7915_mcu_get_rx_rate(struct mt7915_phy *phy, struct ieee80211_vif *vif,
3502                            struct ieee80211_sta *sta, struct rate_info *rate)
3503 {
3504         struct mt7915_vif *mvif = (struct mt7915_vif *)vif->drv_priv;
3505         struct mt7915_sta *msta = (struct mt7915_sta *)sta->drv_priv;
3506         struct mt7915_dev *dev = phy->dev;
3507         struct mt76_phy *mphy = phy->mt76;
3508         struct {
3509                 u8 category;
3510                 u8 band;
3511                 __le16 wcid;
3512         } __packed req = {
3513                 .category = MCU_PHY_STATE_CONTENTION_RX_RATE,
3514                 .band = mvif->band_idx,
3515                 .wcid = cpu_to_le16(msta->wcid.idx),
3516         };
3517         struct ieee80211_supported_band *sband;
3518         struct mt7915_mcu_phy_rx_info *res;
3519         struct sk_buff *skb;
3520         u16 flags = 0;
3521         int ret;
3522         int i;
3523
3524         ret = mt76_mcu_send_and_get_msg(&dev->mt76, MCU_EXT_CMD_PHY_STAT_INFO,
3525                                         &req, sizeof(req), true, &skb);
3526         if (ret)
3527                 return ret;
3528
3529         res = (struct mt7915_mcu_phy_rx_info *)skb->data;
3530
3531         rate->mcs = res->rate;
3532         rate->nss = res->nsts + 1;
3533
3534         switch (res->mode) {
3535         case MT_PHY_TYPE_CCK:
3536         case MT_PHY_TYPE_OFDM:
3537                 if (mphy->chandef.chan->band == NL80211_BAND_5GHZ)
3538                         sband = &mphy->sband_5g.sband;
3539                 else
3540                         sband = &mphy->sband_2g.sband;
3541
3542                 for (i = 0; i < sband->n_bitrates; i++) {
3543                         if (rate->mcs != (sband->bitrates[i].hw_value & 0xf))
3544                                 continue;
3545
3546                         rate->legacy = sband->bitrates[i].bitrate;
3547                         break;
3548                 }
3549                 break;
3550         case MT_PHY_TYPE_HT:
3551         case MT_PHY_TYPE_HT_GF:
3552                 if (rate->mcs > 31)
3553                         return -EINVAL;
3554
3555                 flags |= RATE_INFO_FLAGS_MCS;
3556
3557                 if (res->gi)
3558                         flags |= RATE_INFO_FLAGS_SHORT_GI;
3559                 break;
3560         case MT_PHY_TYPE_VHT:
3561                 flags |= RATE_INFO_FLAGS_VHT_MCS;
3562
3563                 if (res->gi)
3564                         flags |= RATE_INFO_FLAGS_SHORT_GI;
3565                 break;
3566         case MT_PHY_TYPE_HE_SU:
3567         case MT_PHY_TYPE_HE_EXT_SU:
3568         case MT_PHY_TYPE_HE_TB:
3569         case MT_PHY_TYPE_HE_MU:
3570                 rate->he_gi = res->gi;
3571
3572                 flags |= RATE_INFO_FLAGS_HE_MCS;
3573                 break;
3574         default:
3575                 break;
3576         }
3577         rate->flags = flags;
3578
3579         switch (res->bw) {
3580         case IEEE80211_STA_RX_BW_160:
3581                 rate->bw = RATE_INFO_BW_160;
3582                 break;
3583         case IEEE80211_STA_RX_BW_80:
3584                 rate->bw = RATE_INFO_BW_80;
3585                 break;
3586         case IEEE80211_STA_RX_BW_40:
3587                 rate->bw = RATE_INFO_BW_40;
3588                 break;
3589         default:
3590                 rate->bw = RATE_INFO_BW_20;
3591                 break;
3592         }
3593
3594         dev_kfree_skb(skb);
3595
3596         return 0;
3597 }