xref: /OK3568_Linux_fs/kernel/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun // SPDX-License-Identifier: ISC
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun  * Copyright (c) 2010 Broadcom Corporation
4*4882a593Smuzhiyun  */
5*4882a593Smuzhiyun 
6*4882a593Smuzhiyun /* Toplevel file. Relies on dhd_linux.c to send commands to the dongle. */
7*4882a593Smuzhiyun 
8*4882a593Smuzhiyun #include <linux/kernel.h>
9*4882a593Smuzhiyun #include <linux/etherdevice.h>
10*4882a593Smuzhiyun #include <linux/module.h>
11*4882a593Smuzhiyun #include <linux/vmalloc.h>
12*4882a593Smuzhiyun #include <net/cfg80211.h>
13*4882a593Smuzhiyun #include <net/netlink.h>
14*4882a593Smuzhiyun #include <uapi/linux/if_arp.h>
15*4882a593Smuzhiyun 
16*4882a593Smuzhiyun #include <brcmu_utils.h>
17*4882a593Smuzhiyun #include <defs.h>
18*4882a593Smuzhiyun #include <brcmu_wifi.h>
19*4882a593Smuzhiyun #include "core.h"
20*4882a593Smuzhiyun #include "debug.h"
21*4882a593Smuzhiyun #include "tracepoint.h"
22*4882a593Smuzhiyun #include "fwil_types.h"
23*4882a593Smuzhiyun #include "p2p.h"
24*4882a593Smuzhiyun #include "btcoex.h"
25*4882a593Smuzhiyun #include "pno.h"
26*4882a593Smuzhiyun #include "fwsignal.h"
27*4882a593Smuzhiyun #include "cfg80211.h"
28*4882a593Smuzhiyun #include "feature.h"
29*4882a593Smuzhiyun #include "fwil.h"
30*4882a593Smuzhiyun #include "proto.h"
31*4882a593Smuzhiyun #include "vendor.h"
32*4882a593Smuzhiyun #include "bus.h"
33*4882a593Smuzhiyun #include "common.h"
34*4882a593Smuzhiyun 
35*4882a593Smuzhiyun #define BRCMF_SCAN_IE_LEN_MAX		2048
36*4882a593Smuzhiyun 
37*4882a593Smuzhiyun #define WPA_OUI				"\x00\x50\xF2"	/* WPA OUI */
38*4882a593Smuzhiyun #define WPA_OUI_TYPE			1
39*4882a593Smuzhiyun #define RSN_OUI				"\x00\x0F\xAC"	/* RSN OUI */
40*4882a593Smuzhiyun #define	WME_OUI_TYPE			2
41*4882a593Smuzhiyun #define WPS_OUI_TYPE			4
42*4882a593Smuzhiyun 
43*4882a593Smuzhiyun #define VS_IE_FIXED_HDR_LEN		6
44*4882a593Smuzhiyun #define WPA_IE_VERSION_LEN		2
45*4882a593Smuzhiyun #define WPA_IE_MIN_OUI_LEN		4
46*4882a593Smuzhiyun #define WPA_IE_SUITE_COUNT_LEN		2
47*4882a593Smuzhiyun 
48*4882a593Smuzhiyun #define WPA_CIPHER_NONE			0	/* None */
49*4882a593Smuzhiyun #define WPA_CIPHER_WEP_40		1	/* WEP (40-bit) */
50*4882a593Smuzhiyun #define WPA_CIPHER_TKIP			2	/* TKIP: default for WPA */
51*4882a593Smuzhiyun #define WPA_CIPHER_AES_CCM		4	/* AES (CCM) */
52*4882a593Smuzhiyun #define WPA_CIPHER_WEP_104		5	/* WEP (104-bit) */
53*4882a593Smuzhiyun 
54*4882a593Smuzhiyun #define RSN_AKM_NONE			0	/* None (IBSS) */
55*4882a593Smuzhiyun #define RSN_AKM_UNSPECIFIED		1	/* Over 802.1x */
56*4882a593Smuzhiyun #define RSN_AKM_PSK			2	/* Pre-shared Key */
57*4882a593Smuzhiyun #define RSN_AKM_SHA256_1X		5	/* SHA256, 802.1X */
58*4882a593Smuzhiyun #define RSN_AKM_SHA256_PSK		6	/* SHA256, Pre-shared Key */
59*4882a593Smuzhiyun #define RSN_AKM_SAE			8	/* SAE */
60*4882a593Smuzhiyun #define RSN_CAP_LEN			2	/* Length of RSN capabilities */
61*4882a593Smuzhiyun #define RSN_CAP_PTK_REPLAY_CNTR_MASK	(BIT(2) | BIT(3))
62*4882a593Smuzhiyun #define RSN_CAP_MFPR_MASK		BIT(6)
63*4882a593Smuzhiyun #define RSN_CAP_MFPC_MASK		BIT(7)
64*4882a593Smuzhiyun #define RSN_PMKID_COUNT_LEN		2
65*4882a593Smuzhiyun 
66*4882a593Smuzhiyun #define VNDR_IE_CMD_LEN			4	/* length of the set command
67*4882a593Smuzhiyun 						 * string :"add", "del" (+ NUL)
68*4882a593Smuzhiyun 						 */
69*4882a593Smuzhiyun #define VNDR_IE_COUNT_OFFSET		4
70*4882a593Smuzhiyun #define VNDR_IE_PKTFLAG_OFFSET		8
71*4882a593Smuzhiyun #define VNDR_IE_VSIE_OFFSET		12
72*4882a593Smuzhiyun #define VNDR_IE_HDR_SIZE		12
73*4882a593Smuzhiyun #define VNDR_IE_PARSE_LIMIT		5
74*4882a593Smuzhiyun 
75*4882a593Smuzhiyun #define	DOT11_MGMT_HDR_LEN		24	/* d11 management header len */
76*4882a593Smuzhiyun #define	DOT11_BCN_PRB_FIXED_LEN		12	/* beacon/probe fixed length */
77*4882a593Smuzhiyun 
78*4882a593Smuzhiyun #define BRCMF_SCAN_JOIN_ACTIVE_DWELL_TIME_MS	320
79*4882a593Smuzhiyun #define BRCMF_SCAN_JOIN_PASSIVE_DWELL_TIME_MS	400
80*4882a593Smuzhiyun #define BRCMF_SCAN_JOIN_PROBE_INTERVAL_MS	20
81*4882a593Smuzhiyun 
82*4882a593Smuzhiyun #define BRCMF_SCAN_CHANNEL_TIME		40
83*4882a593Smuzhiyun #define BRCMF_SCAN_UNASSOC_TIME		40
84*4882a593Smuzhiyun #define BRCMF_SCAN_PASSIVE_TIME		120
85*4882a593Smuzhiyun 
86*4882a593Smuzhiyun #define BRCMF_ND_INFO_TIMEOUT		msecs_to_jiffies(2000)
87*4882a593Smuzhiyun 
88*4882a593Smuzhiyun #define BRCMF_PS_MAX_TIMEOUT_MS		2000
89*4882a593Smuzhiyun 
90*4882a593Smuzhiyun #define BRCMF_ASSOC_PARAMS_FIXED_SIZE \
91*4882a593Smuzhiyun 	(sizeof(struct brcmf_assoc_params_le) - sizeof(u16))
92*4882a593Smuzhiyun 
check_vif_up(struct brcmf_cfg80211_vif * vif)93*4882a593Smuzhiyun static bool check_vif_up(struct brcmf_cfg80211_vif *vif)
94*4882a593Smuzhiyun {
95*4882a593Smuzhiyun 	if (!test_bit(BRCMF_VIF_STATUS_READY, &vif->sme_state)) {
96*4882a593Smuzhiyun 		brcmf_dbg(INFO, "device is not ready : status (%lu)\n",
97*4882a593Smuzhiyun 			  vif->sme_state);
98*4882a593Smuzhiyun 		return false;
99*4882a593Smuzhiyun 	}
100*4882a593Smuzhiyun 	return true;
101*4882a593Smuzhiyun }
102*4882a593Smuzhiyun 
103*4882a593Smuzhiyun #define RATE_TO_BASE100KBPS(rate)   (((rate) * 10) / 2)
104*4882a593Smuzhiyun #define RATETAB_ENT(_rateid, _flags) \
105*4882a593Smuzhiyun 	{                                                               \
106*4882a593Smuzhiyun 		.bitrate        = RATE_TO_BASE100KBPS(_rateid),     \
107*4882a593Smuzhiyun 		.hw_value       = (_rateid),                            \
108*4882a593Smuzhiyun 		.flags          = (_flags),                             \
109*4882a593Smuzhiyun 	}
110*4882a593Smuzhiyun 
111*4882a593Smuzhiyun static struct ieee80211_rate __wl_rates[] = {
112*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_1M, 0),
113*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_2M, IEEE80211_RATE_SHORT_PREAMBLE),
114*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_5M5, IEEE80211_RATE_SHORT_PREAMBLE),
115*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_11M, IEEE80211_RATE_SHORT_PREAMBLE),
116*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_6M, 0),
117*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_9M, 0),
118*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_12M, 0),
119*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_18M, 0),
120*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_24M, 0),
121*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_36M, 0),
122*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_48M, 0),
123*4882a593Smuzhiyun 	RATETAB_ENT(BRCM_RATE_54M, 0),
124*4882a593Smuzhiyun };
125*4882a593Smuzhiyun 
126*4882a593Smuzhiyun #define wl_g_rates		(__wl_rates + 0)
127*4882a593Smuzhiyun #define wl_g_rates_size		ARRAY_SIZE(__wl_rates)
128*4882a593Smuzhiyun #define wl_a_rates		(__wl_rates + 4)
129*4882a593Smuzhiyun #define wl_a_rates_size		(wl_g_rates_size - 4)
130*4882a593Smuzhiyun 
131*4882a593Smuzhiyun #define CHAN2G(_channel, _freq) {				\
132*4882a593Smuzhiyun 	.band			= NL80211_BAND_2GHZ,		\
133*4882a593Smuzhiyun 	.center_freq		= (_freq),			\
134*4882a593Smuzhiyun 	.hw_value		= (_channel),			\
135*4882a593Smuzhiyun 	.max_antenna_gain	= 0,				\
136*4882a593Smuzhiyun 	.max_power		= 30,				\
137*4882a593Smuzhiyun }
138*4882a593Smuzhiyun 
139*4882a593Smuzhiyun #define CHAN5G(_channel) {					\
140*4882a593Smuzhiyun 	.band			= NL80211_BAND_5GHZ,		\
141*4882a593Smuzhiyun 	.center_freq		= 5000 + (5 * (_channel)),	\
142*4882a593Smuzhiyun 	.hw_value		= (_channel),			\
143*4882a593Smuzhiyun 	.max_antenna_gain	= 0,				\
144*4882a593Smuzhiyun 	.max_power		= 30,				\
145*4882a593Smuzhiyun }
146*4882a593Smuzhiyun 
147*4882a593Smuzhiyun static struct ieee80211_channel __wl_2ghz_channels[] = {
148*4882a593Smuzhiyun 	CHAN2G(1, 2412), CHAN2G(2, 2417), CHAN2G(3, 2422), CHAN2G(4, 2427),
149*4882a593Smuzhiyun 	CHAN2G(5, 2432), CHAN2G(6, 2437), CHAN2G(7, 2442), CHAN2G(8, 2447),
150*4882a593Smuzhiyun 	CHAN2G(9, 2452), CHAN2G(10, 2457), CHAN2G(11, 2462), CHAN2G(12, 2467),
151*4882a593Smuzhiyun 	CHAN2G(13, 2472), CHAN2G(14, 2484)
152*4882a593Smuzhiyun };
153*4882a593Smuzhiyun 
154*4882a593Smuzhiyun static struct ieee80211_channel __wl_5ghz_channels[] = {
155*4882a593Smuzhiyun 	CHAN5G(34), CHAN5G(36), CHAN5G(38), CHAN5G(40), CHAN5G(42),
156*4882a593Smuzhiyun 	CHAN5G(44), CHAN5G(46), CHAN5G(48), CHAN5G(52), CHAN5G(56),
157*4882a593Smuzhiyun 	CHAN5G(60), CHAN5G(64), CHAN5G(100), CHAN5G(104), CHAN5G(108),
158*4882a593Smuzhiyun 	CHAN5G(112), CHAN5G(116), CHAN5G(120), CHAN5G(124), CHAN5G(128),
159*4882a593Smuzhiyun 	CHAN5G(132), CHAN5G(136), CHAN5G(140), CHAN5G(144), CHAN5G(149),
160*4882a593Smuzhiyun 	CHAN5G(153), CHAN5G(157), CHAN5G(161), CHAN5G(165)
161*4882a593Smuzhiyun };
162*4882a593Smuzhiyun 
163*4882a593Smuzhiyun /* Band templates duplicated per wiphy. The channel info
164*4882a593Smuzhiyun  * above is added to the band during setup.
165*4882a593Smuzhiyun  */
166*4882a593Smuzhiyun static const struct ieee80211_supported_band __wl_band_2ghz = {
167*4882a593Smuzhiyun 	.band = NL80211_BAND_2GHZ,
168*4882a593Smuzhiyun 	.bitrates = wl_g_rates,
169*4882a593Smuzhiyun 	.n_bitrates = wl_g_rates_size,
170*4882a593Smuzhiyun };
171*4882a593Smuzhiyun 
172*4882a593Smuzhiyun static const struct ieee80211_supported_band __wl_band_5ghz = {
173*4882a593Smuzhiyun 	.band = NL80211_BAND_5GHZ,
174*4882a593Smuzhiyun 	.bitrates = wl_a_rates,
175*4882a593Smuzhiyun 	.n_bitrates = wl_a_rates_size,
176*4882a593Smuzhiyun };
177*4882a593Smuzhiyun 
178*4882a593Smuzhiyun /* This is to override regulatory domains defined in cfg80211 module (reg.c)
179*4882a593Smuzhiyun  * By default world regulatory domain defined in reg.c puts the flags
180*4882a593Smuzhiyun  * NL80211_RRF_NO_IR for 5GHz channels (for * 36..48 and 149..165).
181*4882a593Smuzhiyun  * With respect to these flags, wpa_supplicant doesn't * start p2p
182*4882a593Smuzhiyun  * operations on 5GHz channels. All the changes in world regulatory
183*4882a593Smuzhiyun  * domain are to be done here.
184*4882a593Smuzhiyun  */
185*4882a593Smuzhiyun static const struct ieee80211_regdomain brcmf_regdom = {
186*4882a593Smuzhiyun 	.n_reg_rules = 4,
187*4882a593Smuzhiyun 	.alpha2 =  "99",
188*4882a593Smuzhiyun 	.reg_rules = {
189*4882a593Smuzhiyun 		/* IEEE 802.11b/g, channels 1..11 */
190*4882a593Smuzhiyun 		REG_RULE(2412-10, 2472+10, 40, 6, 20, 0),
191*4882a593Smuzhiyun 		/* If any */
192*4882a593Smuzhiyun 		/* IEEE 802.11 channel 14 - Only JP enables
193*4882a593Smuzhiyun 		 * this and for 802.11b only
194*4882a593Smuzhiyun 		 */
195*4882a593Smuzhiyun 		REG_RULE(2484-10, 2484+10, 20, 6, 20, 0),
196*4882a593Smuzhiyun 		/* IEEE 802.11a, channel 36..64 */
197*4882a593Smuzhiyun 		REG_RULE(5150-10, 5350+10, 160, 6, 20, 0),
198*4882a593Smuzhiyun 		/* IEEE 802.11a, channel 100..165 */
199*4882a593Smuzhiyun 		REG_RULE(5470-10, 5850+10, 160, 6, 20, 0), }
200*4882a593Smuzhiyun };
201*4882a593Smuzhiyun 
202*4882a593Smuzhiyun /* Note: brcmf_cipher_suites is an array of int defining which cipher suites
203*4882a593Smuzhiyun  * are supported. A pointer to this array and the number of entries is passed
204*4882a593Smuzhiyun  * on to upper layers. AES_CMAC defines whether or not the driver supports MFP.
205*4882a593Smuzhiyun  * So the cipher suite AES_CMAC has to be the last one in the array, and when
206*4882a593Smuzhiyun  * device does not support MFP then the number of suites will be decreased by 1
207*4882a593Smuzhiyun  */
208*4882a593Smuzhiyun static const u32 brcmf_cipher_suites[] = {
209*4882a593Smuzhiyun 	WLAN_CIPHER_SUITE_WEP40,
210*4882a593Smuzhiyun 	WLAN_CIPHER_SUITE_WEP104,
211*4882a593Smuzhiyun 	WLAN_CIPHER_SUITE_TKIP,
212*4882a593Smuzhiyun 	WLAN_CIPHER_SUITE_CCMP,
213*4882a593Smuzhiyun 	/* Keep as last entry: */
214*4882a593Smuzhiyun 	WLAN_CIPHER_SUITE_AES_CMAC
215*4882a593Smuzhiyun };
216*4882a593Smuzhiyun 
217*4882a593Smuzhiyun /* Vendor specific ie. id = 221, oui and type defines exact ie */
218*4882a593Smuzhiyun struct brcmf_vs_tlv {
219*4882a593Smuzhiyun 	u8 id;
220*4882a593Smuzhiyun 	u8 len;
221*4882a593Smuzhiyun 	u8 oui[3];
222*4882a593Smuzhiyun 	u8 oui_type;
223*4882a593Smuzhiyun };
224*4882a593Smuzhiyun 
225*4882a593Smuzhiyun struct parsed_vndr_ie_info {
226*4882a593Smuzhiyun 	u8 *ie_ptr;
227*4882a593Smuzhiyun 	u32 ie_len;	/* total length including id & length field */
228*4882a593Smuzhiyun 	struct brcmf_vs_tlv vndrie;
229*4882a593Smuzhiyun };
230*4882a593Smuzhiyun 
231*4882a593Smuzhiyun struct parsed_vndr_ies {
232*4882a593Smuzhiyun 	u32 count;
233*4882a593Smuzhiyun 	struct parsed_vndr_ie_info ie_info[VNDR_IE_PARSE_LIMIT];
234*4882a593Smuzhiyun };
235*4882a593Smuzhiyun 
nl80211_band_to_fwil(enum nl80211_band band)236*4882a593Smuzhiyun static u8 nl80211_band_to_fwil(enum nl80211_band band)
237*4882a593Smuzhiyun {
238*4882a593Smuzhiyun 	switch (band) {
239*4882a593Smuzhiyun 	case NL80211_BAND_2GHZ:
240*4882a593Smuzhiyun 		return WLC_BAND_2G;
241*4882a593Smuzhiyun 	case NL80211_BAND_5GHZ:
242*4882a593Smuzhiyun 		return WLC_BAND_5G;
243*4882a593Smuzhiyun 	default:
244*4882a593Smuzhiyun 		WARN_ON(1);
245*4882a593Smuzhiyun 		break;
246*4882a593Smuzhiyun 	}
247*4882a593Smuzhiyun 	return 0;
248*4882a593Smuzhiyun }
249*4882a593Smuzhiyun 
chandef_to_chanspec(struct brcmu_d11inf * d11inf,struct cfg80211_chan_def * ch)250*4882a593Smuzhiyun static u16 chandef_to_chanspec(struct brcmu_d11inf *d11inf,
251*4882a593Smuzhiyun 			       struct cfg80211_chan_def *ch)
252*4882a593Smuzhiyun {
253*4882a593Smuzhiyun 	struct brcmu_chan ch_inf;
254*4882a593Smuzhiyun 	s32 primary_offset;
255*4882a593Smuzhiyun 
256*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "chandef: control %d center %d width %d\n",
257*4882a593Smuzhiyun 		  ch->chan->center_freq, ch->center_freq1, ch->width);
258*4882a593Smuzhiyun 	ch_inf.chnum = ieee80211_frequency_to_channel(ch->center_freq1);
259*4882a593Smuzhiyun 	primary_offset = ch->chan->center_freq - ch->center_freq1;
260*4882a593Smuzhiyun 	switch (ch->width) {
261*4882a593Smuzhiyun 	case NL80211_CHAN_WIDTH_20:
262*4882a593Smuzhiyun 	case NL80211_CHAN_WIDTH_20_NOHT:
263*4882a593Smuzhiyun 		ch_inf.bw = BRCMU_CHAN_BW_20;
264*4882a593Smuzhiyun 		WARN_ON(primary_offset != 0);
265*4882a593Smuzhiyun 		break;
266*4882a593Smuzhiyun 	case NL80211_CHAN_WIDTH_40:
267*4882a593Smuzhiyun 		ch_inf.bw = BRCMU_CHAN_BW_40;
268*4882a593Smuzhiyun 		if (primary_offset > 0)
269*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_U;
270*4882a593Smuzhiyun 		else
271*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_L;
272*4882a593Smuzhiyun 		break;
273*4882a593Smuzhiyun 	case NL80211_CHAN_WIDTH_80:
274*4882a593Smuzhiyun 		ch_inf.bw = BRCMU_CHAN_BW_80;
275*4882a593Smuzhiyun 		if (primary_offset == -30)
276*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_LL;
277*4882a593Smuzhiyun 		else if (primary_offset == -10)
278*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_LU;
279*4882a593Smuzhiyun 		else if (primary_offset == 10)
280*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_UL;
281*4882a593Smuzhiyun 		else
282*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_UU;
283*4882a593Smuzhiyun 		break;
284*4882a593Smuzhiyun 	case NL80211_CHAN_WIDTH_160:
285*4882a593Smuzhiyun 		ch_inf.bw = BRCMU_CHAN_BW_160;
286*4882a593Smuzhiyun 		if (primary_offset == -70)
287*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_LLL;
288*4882a593Smuzhiyun 		else if (primary_offset == -50)
289*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_LLU;
290*4882a593Smuzhiyun 		else if (primary_offset == -30)
291*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_LUL;
292*4882a593Smuzhiyun 		else if (primary_offset == -10)
293*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_LUU;
294*4882a593Smuzhiyun 		else if (primary_offset == 10)
295*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_ULL;
296*4882a593Smuzhiyun 		else if (primary_offset == 30)
297*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_ULU;
298*4882a593Smuzhiyun 		else if (primary_offset == 50)
299*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_UUL;
300*4882a593Smuzhiyun 		else
301*4882a593Smuzhiyun 			ch_inf.sb = BRCMU_CHAN_SB_UUU;
302*4882a593Smuzhiyun 		break;
303*4882a593Smuzhiyun 	case NL80211_CHAN_WIDTH_80P80:
304*4882a593Smuzhiyun 	case NL80211_CHAN_WIDTH_5:
305*4882a593Smuzhiyun 	case NL80211_CHAN_WIDTH_10:
306*4882a593Smuzhiyun 	default:
307*4882a593Smuzhiyun 		WARN_ON_ONCE(1);
308*4882a593Smuzhiyun 	}
309*4882a593Smuzhiyun 	switch (ch->chan->band) {
310*4882a593Smuzhiyun 	case NL80211_BAND_2GHZ:
311*4882a593Smuzhiyun 		ch_inf.band = BRCMU_CHAN_BAND_2G;
312*4882a593Smuzhiyun 		break;
313*4882a593Smuzhiyun 	case NL80211_BAND_5GHZ:
314*4882a593Smuzhiyun 		ch_inf.band = BRCMU_CHAN_BAND_5G;
315*4882a593Smuzhiyun 		break;
316*4882a593Smuzhiyun 	case NL80211_BAND_60GHZ:
317*4882a593Smuzhiyun 	default:
318*4882a593Smuzhiyun 		WARN_ON_ONCE(1);
319*4882a593Smuzhiyun 	}
320*4882a593Smuzhiyun 	d11inf->encchspec(&ch_inf);
321*4882a593Smuzhiyun 
322*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "chanspec: 0x%x\n", ch_inf.chspec);
323*4882a593Smuzhiyun 	return ch_inf.chspec;
324*4882a593Smuzhiyun }
325*4882a593Smuzhiyun 
channel_to_chanspec(struct brcmu_d11inf * d11inf,struct ieee80211_channel * ch)326*4882a593Smuzhiyun u16 channel_to_chanspec(struct brcmu_d11inf *d11inf,
327*4882a593Smuzhiyun 			struct ieee80211_channel *ch)
328*4882a593Smuzhiyun {
329*4882a593Smuzhiyun 	struct brcmu_chan ch_inf;
330*4882a593Smuzhiyun 
331*4882a593Smuzhiyun 	ch_inf.chnum = ieee80211_frequency_to_channel(ch->center_freq);
332*4882a593Smuzhiyun 	ch_inf.bw = BRCMU_CHAN_BW_20;
333*4882a593Smuzhiyun 	d11inf->encchspec(&ch_inf);
334*4882a593Smuzhiyun 
335*4882a593Smuzhiyun 	return ch_inf.chspec;
336*4882a593Smuzhiyun }
337*4882a593Smuzhiyun 
338*4882a593Smuzhiyun /* Traverse a string of 1-byte tag/1-byte length/variable-length value
339*4882a593Smuzhiyun  * triples, returning a pointer to the substring whose first element
340*4882a593Smuzhiyun  * matches tag
341*4882a593Smuzhiyun  */
342*4882a593Smuzhiyun static const struct brcmf_tlv *
brcmf_parse_tlvs(const void * buf,int buflen,uint key)343*4882a593Smuzhiyun brcmf_parse_tlvs(const void *buf, int buflen, uint key)
344*4882a593Smuzhiyun {
345*4882a593Smuzhiyun 	const struct brcmf_tlv *elt = buf;
346*4882a593Smuzhiyun 	int totlen = buflen;
347*4882a593Smuzhiyun 
348*4882a593Smuzhiyun 	/* find tagged parameter */
349*4882a593Smuzhiyun 	while (totlen >= TLV_HDR_LEN) {
350*4882a593Smuzhiyun 		int len = elt->len;
351*4882a593Smuzhiyun 
352*4882a593Smuzhiyun 		/* validate remaining totlen */
353*4882a593Smuzhiyun 		if ((elt->id == key) && (totlen >= (len + TLV_HDR_LEN)))
354*4882a593Smuzhiyun 			return elt;
355*4882a593Smuzhiyun 
356*4882a593Smuzhiyun 		elt = (struct brcmf_tlv *)((u8 *)elt + (len + TLV_HDR_LEN));
357*4882a593Smuzhiyun 		totlen -= (len + TLV_HDR_LEN);
358*4882a593Smuzhiyun 	}
359*4882a593Smuzhiyun 
360*4882a593Smuzhiyun 	return NULL;
361*4882a593Smuzhiyun }
362*4882a593Smuzhiyun 
363*4882a593Smuzhiyun /* Is any of the tlvs the expected entry? If
364*4882a593Smuzhiyun  * not update the tlvs buffer pointer/length.
365*4882a593Smuzhiyun  */
366*4882a593Smuzhiyun static bool
brcmf_tlv_has_ie(const u8 * ie,const u8 ** tlvs,u32 * tlvs_len,const u8 * oui,u32 oui_len,u8 type)367*4882a593Smuzhiyun brcmf_tlv_has_ie(const u8 *ie, const u8 **tlvs, u32 *tlvs_len,
368*4882a593Smuzhiyun 		 const u8 *oui, u32 oui_len, u8 type)
369*4882a593Smuzhiyun {
370*4882a593Smuzhiyun 	/* If the contents match the OUI and the type */
371*4882a593Smuzhiyun 	if (ie[TLV_LEN_OFF] >= oui_len + 1 &&
372*4882a593Smuzhiyun 	    !memcmp(&ie[TLV_BODY_OFF], oui, oui_len) &&
373*4882a593Smuzhiyun 	    type == ie[TLV_BODY_OFF + oui_len]) {
374*4882a593Smuzhiyun 		return true;
375*4882a593Smuzhiyun 	}
376*4882a593Smuzhiyun 
377*4882a593Smuzhiyun 	if (tlvs == NULL)
378*4882a593Smuzhiyun 		return false;
379*4882a593Smuzhiyun 	/* point to the next ie */
380*4882a593Smuzhiyun 	ie += ie[TLV_LEN_OFF] + TLV_HDR_LEN;
381*4882a593Smuzhiyun 	/* calculate the length of the rest of the buffer */
382*4882a593Smuzhiyun 	*tlvs_len -= (int)(ie - *tlvs);
383*4882a593Smuzhiyun 	/* update the pointer to the start of the buffer */
384*4882a593Smuzhiyun 	*tlvs = ie;
385*4882a593Smuzhiyun 
386*4882a593Smuzhiyun 	return false;
387*4882a593Smuzhiyun }
388*4882a593Smuzhiyun 
389*4882a593Smuzhiyun static struct brcmf_vs_tlv *
brcmf_find_wpaie(const u8 * parse,u32 len)390*4882a593Smuzhiyun brcmf_find_wpaie(const u8 *parse, u32 len)
391*4882a593Smuzhiyun {
392*4882a593Smuzhiyun 	const struct brcmf_tlv *ie;
393*4882a593Smuzhiyun 
394*4882a593Smuzhiyun 	while ((ie = brcmf_parse_tlvs(parse, len, WLAN_EID_VENDOR_SPECIFIC))) {
395*4882a593Smuzhiyun 		if (brcmf_tlv_has_ie((const u8 *)ie, &parse, &len,
396*4882a593Smuzhiyun 				     WPA_OUI, TLV_OUI_LEN, WPA_OUI_TYPE))
397*4882a593Smuzhiyun 			return (struct brcmf_vs_tlv *)ie;
398*4882a593Smuzhiyun 	}
399*4882a593Smuzhiyun 	return NULL;
400*4882a593Smuzhiyun }
401*4882a593Smuzhiyun 
402*4882a593Smuzhiyun static struct brcmf_vs_tlv *
brcmf_find_wpsie(const u8 * parse,u32 len)403*4882a593Smuzhiyun brcmf_find_wpsie(const u8 *parse, u32 len)
404*4882a593Smuzhiyun {
405*4882a593Smuzhiyun 	const struct brcmf_tlv *ie;
406*4882a593Smuzhiyun 
407*4882a593Smuzhiyun 	while ((ie = brcmf_parse_tlvs(parse, len, WLAN_EID_VENDOR_SPECIFIC))) {
408*4882a593Smuzhiyun 		if (brcmf_tlv_has_ie((u8 *)ie, &parse, &len,
409*4882a593Smuzhiyun 				     WPA_OUI, TLV_OUI_LEN, WPS_OUI_TYPE))
410*4882a593Smuzhiyun 			return (struct brcmf_vs_tlv *)ie;
411*4882a593Smuzhiyun 	}
412*4882a593Smuzhiyun 	return NULL;
413*4882a593Smuzhiyun }
414*4882a593Smuzhiyun 
brcmf_vif_change_validate(struct brcmf_cfg80211_info * cfg,struct brcmf_cfg80211_vif * vif,enum nl80211_iftype new_type)415*4882a593Smuzhiyun static int brcmf_vif_change_validate(struct brcmf_cfg80211_info *cfg,
416*4882a593Smuzhiyun 				     struct brcmf_cfg80211_vif *vif,
417*4882a593Smuzhiyun 				     enum nl80211_iftype new_type)
418*4882a593Smuzhiyun {
419*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *pos;
420*4882a593Smuzhiyun 	bool check_combos = false;
421*4882a593Smuzhiyun 	int ret = 0;
422*4882a593Smuzhiyun 	struct iface_combination_params params = {
423*4882a593Smuzhiyun 		.num_different_channels = 1,
424*4882a593Smuzhiyun 	};
425*4882a593Smuzhiyun 
426*4882a593Smuzhiyun 	list_for_each_entry(pos, &cfg->vif_list, list)
427*4882a593Smuzhiyun 		if (pos == vif) {
428*4882a593Smuzhiyun 			params.iftype_num[new_type]++;
429*4882a593Smuzhiyun 		} else {
430*4882a593Smuzhiyun 			/* concurrent interfaces so need check combinations */
431*4882a593Smuzhiyun 			check_combos = true;
432*4882a593Smuzhiyun 			params.iftype_num[pos->wdev.iftype]++;
433*4882a593Smuzhiyun 		}
434*4882a593Smuzhiyun 
435*4882a593Smuzhiyun 	if (check_combos)
436*4882a593Smuzhiyun 		ret = cfg80211_check_combinations(cfg->wiphy, &params);
437*4882a593Smuzhiyun 
438*4882a593Smuzhiyun 	return ret;
439*4882a593Smuzhiyun }
440*4882a593Smuzhiyun 
brcmf_vif_add_validate(struct brcmf_cfg80211_info * cfg,enum nl80211_iftype new_type)441*4882a593Smuzhiyun static int brcmf_vif_add_validate(struct brcmf_cfg80211_info *cfg,
442*4882a593Smuzhiyun 				  enum nl80211_iftype new_type)
443*4882a593Smuzhiyun {
444*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *pos;
445*4882a593Smuzhiyun 	struct iface_combination_params params = {
446*4882a593Smuzhiyun 		.num_different_channels = 1,
447*4882a593Smuzhiyun 	};
448*4882a593Smuzhiyun 
449*4882a593Smuzhiyun 	list_for_each_entry(pos, &cfg->vif_list, list)
450*4882a593Smuzhiyun 		params.iftype_num[pos->wdev.iftype]++;
451*4882a593Smuzhiyun 
452*4882a593Smuzhiyun 	params.iftype_num[new_type]++;
453*4882a593Smuzhiyun 	return cfg80211_check_combinations(cfg->wiphy, &params);
454*4882a593Smuzhiyun }
455*4882a593Smuzhiyun 
convert_key_from_CPU(struct brcmf_wsec_key * key,struct brcmf_wsec_key_le * key_le)456*4882a593Smuzhiyun static void convert_key_from_CPU(struct brcmf_wsec_key *key,
457*4882a593Smuzhiyun 				 struct brcmf_wsec_key_le *key_le)
458*4882a593Smuzhiyun {
459*4882a593Smuzhiyun 	key_le->index = cpu_to_le32(key->index);
460*4882a593Smuzhiyun 	key_le->len = cpu_to_le32(key->len);
461*4882a593Smuzhiyun 	key_le->algo = cpu_to_le32(key->algo);
462*4882a593Smuzhiyun 	key_le->flags = cpu_to_le32(key->flags);
463*4882a593Smuzhiyun 	key_le->rxiv.hi = cpu_to_le32(key->rxiv.hi);
464*4882a593Smuzhiyun 	key_le->rxiv.lo = cpu_to_le16(key->rxiv.lo);
465*4882a593Smuzhiyun 	key_le->iv_initialized = cpu_to_le32(key->iv_initialized);
466*4882a593Smuzhiyun 	memcpy(key_le->data, key->data, sizeof(key->data));
467*4882a593Smuzhiyun 	memcpy(key_le->ea, key->ea, sizeof(key->ea));
468*4882a593Smuzhiyun }
469*4882a593Smuzhiyun 
470*4882a593Smuzhiyun static int
send_key_to_dongle(struct brcmf_if * ifp,struct brcmf_wsec_key * key)471*4882a593Smuzhiyun send_key_to_dongle(struct brcmf_if *ifp, struct brcmf_wsec_key *key)
472*4882a593Smuzhiyun {
473*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
474*4882a593Smuzhiyun 	int err;
475*4882a593Smuzhiyun 	struct brcmf_wsec_key_le key_le;
476*4882a593Smuzhiyun 
477*4882a593Smuzhiyun 	convert_key_from_CPU(key, &key_le);
478*4882a593Smuzhiyun 
479*4882a593Smuzhiyun 	brcmf_netdev_wait_pend8021x(ifp);
480*4882a593Smuzhiyun 
481*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_data_set(ifp, "wsec_key", &key_le,
482*4882a593Smuzhiyun 					sizeof(key_le));
483*4882a593Smuzhiyun 
484*4882a593Smuzhiyun 	if (err)
485*4882a593Smuzhiyun 		bphy_err(drvr, "wsec_key error (%d)\n", err);
486*4882a593Smuzhiyun 	return err;
487*4882a593Smuzhiyun }
488*4882a593Smuzhiyun 
489*4882a593Smuzhiyun static void
brcmf_cfg80211_update_proto_addr_mode(struct wireless_dev * wdev)490*4882a593Smuzhiyun brcmf_cfg80211_update_proto_addr_mode(struct wireless_dev *wdev)
491*4882a593Smuzhiyun {
492*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
493*4882a593Smuzhiyun 	struct brcmf_if *ifp;
494*4882a593Smuzhiyun 
495*4882a593Smuzhiyun 	vif = container_of(wdev, struct brcmf_cfg80211_vif, wdev);
496*4882a593Smuzhiyun 	ifp = vif->ifp;
497*4882a593Smuzhiyun 
498*4882a593Smuzhiyun 	if ((wdev->iftype == NL80211_IFTYPE_ADHOC) ||
499*4882a593Smuzhiyun 	    (wdev->iftype == NL80211_IFTYPE_AP) ||
500*4882a593Smuzhiyun 	    (wdev->iftype == NL80211_IFTYPE_P2P_GO))
501*4882a593Smuzhiyun 		brcmf_proto_configure_addr_mode(ifp->drvr, ifp->ifidx,
502*4882a593Smuzhiyun 						ADDR_DIRECT);
503*4882a593Smuzhiyun 	else
504*4882a593Smuzhiyun 		brcmf_proto_configure_addr_mode(ifp->drvr, ifp->ifidx,
505*4882a593Smuzhiyun 						ADDR_INDIRECT);
506*4882a593Smuzhiyun }
507*4882a593Smuzhiyun 
brcmf_get_first_free_bsscfgidx(struct brcmf_pub * drvr)508*4882a593Smuzhiyun static int brcmf_get_first_free_bsscfgidx(struct brcmf_pub *drvr)
509*4882a593Smuzhiyun {
510*4882a593Smuzhiyun 	int bsscfgidx;
511*4882a593Smuzhiyun 
512*4882a593Smuzhiyun 	for (bsscfgidx = 0; bsscfgidx < BRCMF_MAX_IFS; bsscfgidx++) {
513*4882a593Smuzhiyun 		/* bsscfgidx 1 is reserved for legacy P2P */
514*4882a593Smuzhiyun 		if (bsscfgidx == 1)
515*4882a593Smuzhiyun 			continue;
516*4882a593Smuzhiyun 		if (!drvr->iflist[bsscfgidx])
517*4882a593Smuzhiyun 			return bsscfgidx;
518*4882a593Smuzhiyun 	}
519*4882a593Smuzhiyun 
520*4882a593Smuzhiyun 	return -ENOMEM;
521*4882a593Smuzhiyun }
522*4882a593Smuzhiyun 
brcmf_cfg80211_request_ap_if(struct brcmf_if * ifp)523*4882a593Smuzhiyun static int brcmf_cfg80211_request_ap_if(struct brcmf_if *ifp)
524*4882a593Smuzhiyun {
525*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
526*4882a593Smuzhiyun 	struct brcmf_mbss_ssid_le mbss_ssid_le;
527*4882a593Smuzhiyun 	int bsscfgidx;
528*4882a593Smuzhiyun 	int err;
529*4882a593Smuzhiyun 
530*4882a593Smuzhiyun 	memset(&mbss_ssid_le, 0, sizeof(mbss_ssid_le));
531*4882a593Smuzhiyun 	bsscfgidx = brcmf_get_first_free_bsscfgidx(ifp->drvr);
532*4882a593Smuzhiyun 	if (bsscfgidx < 0)
533*4882a593Smuzhiyun 		return bsscfgidx;
534*4882a593Smuzhiyun 
535*4882a593Smuzhiyun 	mbss_ssid_le.bsscfgidx = cpu_to_le32(bsscfgidx);
536*4882a593Smuzhiyun 	mbss_ssid_le.SSID_len = cpu_to_le32(5);
537*4882a593Smuzhiyun 	sprintf(mbss_ssid_le.SSID, "ssid%d" , bsscfgidx);
538*4882a593Smuzhiyun 
539*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_data_set(ifp, "bsscfg:ssid", &mbss_ssid_le,
540*4882a593Smuzhiyun 					sizeof(mbss_ssid_le));
541*4882a593Smuzhiyun 	if (err < 0)
542*4882a593Smuzhiyun 		bphy_err(drvr, "setting ssid failed %d\n", err);
543*4882a593Smuzhiyun 
544*4882a593Smuzhiyun 	return err;
545*4882a593Smuzhiyun }
546*4882a593Smuzhiyun 
547*4882a593Smuzhiyun /**
548*4882a593Smuzhiyun  * brcmf_ap_add_vif() - create a new AP virtual interface for multiple BSS
549*4882a593Smuzhiyun  *
550*4882a593Smuzhiyun  * @wiphy: wiphy device of new interface.
551*4882a593Smuzhiyun  * @name: name of the new interface.
552*4882a593Smuzhiyun  * @params: contains mac address for AP device.
553*4882a593Smuzhiyun  */
554*4882a593Smuzhiyun static
brcmf_ap_add_vif(struct wiphy * wiphy,const char * name,struct vif_params * params)555*4882a593Smuzhiyun struct wireless_dev *brcmf_ap_add_vif(struct wiphy *wiphy, const char *name,
556*4882a593Smuzhiyun 				      struct vif_params *params)
557*4882a593Smuzhiyun {
558*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
559*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(cfg_to_ndev(cfg));
560*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
561*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
562*4882a593Smuzhiyun 	int err;
563*4882a593Smuzhiyun 
564*4882a593Smuzhiyun 	if (brcmf_cfg80211_vif_event_armed(cfg))
565*4882a593Smuzhiyun 		return ERR_PTR(-EBUSY);
566*4882a593Smuzhiyun 
567*4882a593Smuzhiyun 	brcmf_dbg(INFO, "Adding vif \"%s\"\n", name);
568*4882a593Smuzhiyun 
569*4882a593Smuzhiyun 	vif = brcmf_alloc_vif(cfg, NL80211_IFTYPE_AP);
570*4882a593Smuzhiyun 	if (IS_ERR(vif))
571*4882a593Smuzhiyun 		return (struct wireless_dev *)vif;
572*4882a593Smuzhiyun 
573*4882a593Smuzhiyun 	brcmf_cfg80211_arm_vif_event(cfg, vif);
574*4882a593Smuzhiyun 
575*4882a593Smuzhiyun 	err = brcmf_cfg80211_request_ap_if(ifp);
576*4882a593Smuzhiyun 	if (err) {
577*4882a593Smuzhiyun 		brcmf_cfg80211_arm_vif_event(cfg, NULL);
578*4882a593Smuzhiyun 		goto fail;
579*4882a593Smuzhiyun 	}
580*4882a593Smuzhiyun 
581*4882a593Smuzhiyun 	/* wait for firmware event */
582*4882a593Smuzhiyun 	err = brcmf_cfg80211_wait_vif_event(cfg, BRCMF_E_IF_ADD,
583*4882a593Smuzhiyun 					    BRCMF_VIF_EVENT_TIMEOUT);
584*4882a593Smuzhiyun 	brcmf_cfg80211_arm_vif_event(cfg, NULL);
585*4882a593Smuzhiyun 	if (!err) {
586*4882a593Smuzhiyun 		bphy_err(drvr, "timeout occurred\n");
587*4882a593Smuzhiyun 		err = -EIO;
588*4882a593Smuzhiyun 		goto fail;
589*4882a593Smuzhiyun 	}
590*4882a593Smuzhiyun 
591*4882a593Smuzhiyun 	/* interface created in firmware */
592*4882a593Smuzhiyun 	ifp = vif->ifp;
593*4882a593Smuzhiyun 	if (!ifp) {
594*4882a593Smuzhiyun 		bphy_err(drvr, "no if pointer provided\n");
595*4882a593Smuzhiyun 		err = -ENOENT;
596*4882a593Smuzhiyun 		goto fail;
597*4882a593Smuzhiyun 	}
598*4882a593Smuzhiyun 
599*4882a593Smuzhiyun 	strncpy(ifp->ndev->name, name, sizeof(ifp->ndev->name) - 1);
600*4882a593Smuzhiyun 	err = brcmf_net_attach(ifp, true);
601*4882a593Smuzhiyun 	if (err) {
602*4882a593Smuzhiyun 		bphy_err(drvr, "Registering netdevice failed\n");
603*4882a593Smuzhiyun 		free_netdev(ifp->ndev);
604*4882a593Smuzhiyun 		goto fail;
605*4882a593Smuzhiyun 	}
606*4882a593Smuzhiyun 
607*4882a593Smuzhiyun 	return &ifp->vif->wdev;
608*4882a593Smuzhiyun 
609*4882a593Smuzhiyun fail:
610*4882a593Smuzhiyun 	brcmf_free_vif(vif);
611*4882a593Smuzhiyun 	return ERR_PTR(err);
612*4882a593Smuzhiyun }
613*4882a593Smuzhiyun 
brcmf_is_apmode(struct brcmf_cfg80211_vif * vif)614*4882a593Smuzhiyun static bool brcmf_is_apmode(struct brcmf_cfg80211_vif *vif)
615*4882a593Smuzhiyun {
616*4882a593Smuzhiyun 	enum nl80211_iftype iftype;
617*4882a593Smuzhiyun 
618*4882a593Smuzhiyun 	iftype = vif->wdev.iftype;
619*4882a593Smuzhiyun 	return iftype == NL80211_IFTYPE_AP || iftype == NL80211_IFTYPE_P2P_GO;
620*4882a593Smuzhiyun }
621*4882a593Smuzhiyun 
brcmf_is_ibssmode(struct brcmf_cfg80211_vif * vif)622*4882a593Smuzhiyun static bool brcmf_is_ibssmode(struct brcmf_cfg80211_vif *vif)
623*4882a593Smuzhiyun {
624*4882a593Smuzhiyun 	return vif->wdev.iftype == NL80211_IFTYPE_ADHOC;
625*4882a593Smuzhiyun }
626*4882a593Smuzhiyun 
627*4882a593Smuzhiyun /**
628*4882a593Smuzhiyun  * brcmf_mon_add_vif() - create monitor mode virtual interface
629*4882a593Smuzhiyun  *
630*4882a593Smuzhiyun  * @wiphy: wiphy device of new interface.
631*4882a593Smuzhiyun  * @name: name of the new interface.
632*4882a593Smuzhiyun  */
brcmf_mon_add_vif(struct wiphy * wiphy,const char * name)633*4882a593Smuzhiyun static struct wireless_dev *brcmf_mon_add_vif(struct wiphy *wiphy,
634*4882a593Smuzhiyun 					      const char *name)
635*4882a593Smuzhiyun {
636*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
637*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
638*4882a593Smuzhiyun 	struct net_device *ndev;
639*4882a593Smuzhiyun 	struct brcmf_if *ifp;
640*4882a593Smuzhiyun 	int err;
641*4882a593Smuzhiyun 
642*4882a593Smuzhiyun 	if (cfg->pub->mon_if) {
643*4882a593Smuzhiyun 		err = -EEXIST;
644*4882a593Smuzhiyun 		goto err_out;
645*4882a593Smuzhiyun 	}
646*4882a593Smuzhiyun 
647*4882a593Smuzhiyun 	vif = brcmf_alloc_vif(cfg, NL80211_IFTYPE_MONITOR);
648*4882a593Smuzhiyun 	if (IS_ERR(vif)) {
649*4882a593Smuzhiyun 		err = PTR_ERR(vif);
650*4882a593Smuzhiyun 		goto err_out;
651*4882a593Smuzhiyun 	}
652*4882a593Smuzhiyun 
653*4882a593Smuzhiyun 	ndev = alloc_netdev(sizeof(*ifp), name, NET_NAME_UNKNOWN, ether_setup);
654*4882a593Smuzhiyun 	if (!ndev) {
655*4882a593Smuzhiyun 		err = -ENOMEM;
656*4882a593Smuzhiyun 		goto err_free_vif;
657*4882a593Smuzhiyun 	}
658*4882a593Smuzhiyun 	ndev->type = ARPHRD_IEEE80211_RADIOTAP;
659*4882a593Smuzhiyun 	ndev->ieee80211_ptr = &vif->wdev;
660*4882a593Smuzhiyun 	ndev->needs_free_netdev = true;
661*4882a593Smuzhiyun 	ndev->priv_destructor = brcmf_cfg80211_free_netdev;
662*4882a593Smuzhiyun 	SET_NETDEV_DEV(ndev, wiphy_dev(cfg->wiphy));
663*4882a593Smuzhiyun 
664*4882a593Smuzhiyun 	ifp = netdev_priv(ndev);
665*4882a593Smuzhiyun 	ifp->vif = vif;
666*4882a593Smuzhiyun 	ifp->ndev = ndev;
667*4882a593Smuzhiyun 	ifp->drvr = cfg->pub;
668*4882a593Smuzhiyun 
669*4882a593Smuzhiyun 	vif->ifp = ifp;
670*4882a593Smuzhiyun 	vif->wdev.netdev = ndev;
671*4882a593Smuzhiyun 
672*4882a593Smuzhiyun 	err = brcmf_net_mon_attach(ifp);
673*4882a593Smuzhiyun 	if (err) {
674*4882a593Smuzhiyun 		brcmf_err("Failed to attach %s device\n", ndev->name);
675*4882a593Smuzhiyun 		free_netdev(ndev);
676*4882a593Smuzhiyun 		goto err_free_vif;
677*4882a593Smuzhiyun 	}
678*4882a593Smuzhiyun 
679*4882a593Smuzhiyun 	cfg->pub->mon_if = ifp;
680*4882a593Smuzhiyun 
681*4882a593Smuzhiyun 	return &vif->wdev;
682*4882a593Smuzhiyun 
683*4882a593Smuzhiyun err_free_vif:
684*4882a593Smuzhiyun 	brcmf_free_vif(vif);
685*4882a593Smuzhiyun err_out:
686*4882a593Smuzhiyun 	return ERR_PTR(err);
687*4882a593Smuzhiyun }
688*4882a593Smuzhiyun 
brcmf_mon_del_vif(struct wiphy * wiphy,struct wireless_dev * wdev)689*4882a593Smuzhiyun static int brcmf_mon_del_vif(struct wiphy *wiphy, struct wireless_dev *wdev)
690*4882a593Smuzhiyun {
691*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
692*4882a593Smuzhiyun 	struct net_device *ndev = wdev->netdev;
693*4882a593Smuzhiyun 
694*4882a593Smuzhiyun 	ndev->netdev_ops->ndo_stop(ndev);
695*4882a593Smuzhiyun 
696*4882a593Smuzhiyun 	brcmf_net_detach(ndev, true);
697*4882a593Smuzhiyun 
698*4882a593Smuzhiyun 	cfg->pub->mon_if = NULL;
699*4882a593Smuzhiyun 
700*4882a593Smuzhiyun 	return 0;
701*4882a593Smuzhiyun }
702*4882a593Smuzhiyun 
brcmf_cfg80211_add_iface(struct wiphy * wiphy,const char * name,unsigned char name_assign_type,enum nl80211_iftype type,struct vif_params * params)703*4882a593Smuzhiyun static struct wireless_dev *brcmf_cfg80211_add_iface(struct wiphy *wiphy,
704*4882a593Smuzhiyun 						     const char *name,
705*4882a593Smuzhiyun 						     unsigned char name_assign_type,
706*4882a593Smuzhiyun 						     enum nl80211_iftype type,
707*4882a593Smuzhiyun 						     struct vif_params *params)
708*4882a593Smuzhiyun {
709*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
710*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
711*4882a593Smuzhiyun 	struct wireless_dev *wdev;
712*4882a593Smuzhiyun 	int err;
713*4882a593Smuzhiyun 
714*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "enter: %s type %d\n", name, type);
715*4882a593Smuzhiyun 	err = brcmf_vif_add_validate(wiphy_to_cfg(wiphy), type);
716*4882a593Smuzhiyun 	if (err) {
717*4882a593Smuzhiyun 		bphy_err(drvr, "iface validation failed: err=%d\n", err);
718*4882a593Smuzhiyun 		return ERR_PTR(err);
719*4882a593Smuzhiyun 	}
720*4882a593Smuzhiyun 	switch (type) {
721*4882a593Smuzhiyun 	case NL80211_IFTYPE_ADHOC:
722*4882a593Smuzhiyun 	case NL80211_IFTYPE_STATION:
723*4882a593Smuzhiyun 	case NL80211_IFTYPE_AP_VLAN:
724*4882a593Smuzhiyun 	case NL80211_IFTYPE_WDS:
725*4882a593Smuzhiyun 	case NL80211_IFTYPE_MESH_POINT:
726*4882a593Smuzhiyun 		return ERR_PTR(-EOPNOTSUPP);
727*4882a593Smuzhiyun 	case NL80211_IFTYPE_MONITOR:
728*4882a593Smuzhiyun 		return brcmf_mon_add_vif(wiphy, name);
729*4882a593Smuzhiyun 	case NL80211_IFTYPE_AP:
730*4882a593Smuzhiyun 		wdev = brcmf_ap_add_vif(wiphy, name, params);
731*4882a593Smuzhiyun 		break;
732*4882a593Smuzhiyun 	case NL80211_IFTYPE_P2P_CLIENT:
733*4882a593Smuzhiyun 	case NL80211_IFTYPE_P2P_GO:
734*4882a593Smuzhiyun 	case NL80211_IFTYPE_P2P_DEVICE:
735*4882a593Smuzhiyun 		wdev = brcmf_p2p_add_vif(wiphy, name, name_assign_type, type, params);
736*4882a593Smuzhiyun 		break;
737*4882a593Smuzhiyun 	case NL80211_IFTYPE_UNSPECIFIED:
738*4882a593Smuzhiyun 	default:
739*4882a593Smuzhiyun 		return ERR_PTR(-EINVAL);
740*4882a593Smuzhiyun 	}
741*4882a593Smuzhiyun 
742*4882a593Smuzhiyun 	if (IS_ERR(wdev))
743*4882a593Smuzhiyun 		bphy_err(drvr, "add iface %s type %d failed: err=%d\n", name,
744*4882a593Smuzhiyun 			 type, (int)PTR_ERR(wdev));
745*4882a593Smuzhiyun 	else
746*4882a593Smuzhiyun 		brcmf_cfg80211_update_proto_addr_mode(wdev);
747*4882a593Smuzhiyun 
748*4882a593Smuzhiyun 	return wdev;
749*4882a593Smuzhiyun }
750*4882a593Smuzhiyun 
brcmf_scan_config_mpc(struct brcmf_if * ifp,int mpc)751*4882a593Smuzhiyun static void brcmf_scan_config_mpc(struct brcmf_if *ifp, int mpc)
752*4882a593Smuzhiyun {
753*4882a593Smuzhiyun 	if (brcmf_feat_is_quirk_enabled(ifp, BRCMF_FEAT_QUIRK_NEED_MPC))
754*4882a593Smuzhiyun 		brcmf_set_mpc(ifp, mpc);
755*4882a593Smuzhiyun }
756*4882a593Smuzhiyun 
brcmf_set_mpc(struct brcmf_if * ifp,int mpc)757*4882a593Smuzhiyun void brcmf_set_mpc(struct brcmf_if *ifp, int mpc)
758*4882a593Smuzhiyun {
759*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
760*4882a593Smuzhiyun 	s32 err = 0;
761*4882a593Smuzhiyun 
762*4882a593Smuzhiyun 	if (check_vif_up(ifp->vif)) {
763*4882a593Smuzhiyun 		err = brcmf_fil_iovar_int_set(ifp, "mpc", mpc);
764*4882a593Smuzhiyun 		if (err) {
765*4882a593Smuzhiyun 			bphy_err(drvr, "fail to set mpc\n");
766*4882a593Smuzhiyun 			return;
767*4882a593Smuzhiyun 		}
768*4882a593Smuzhiyun 		brcmf_dbg(INFO, "MPC : %d\n", mpc);
769*4882a593Smuzhiyun 	}
770*4882a593Smuzhiyun }
771*4882a593Smuzhiyun 
brcmf_notify_escan_complete(struct brcmf_cfg80211_info * cfg,struct brcmf_if * ifp,bool aborted,bool fw_abort)772*4882a593Smuzhiyun s32 brcmf_notify_escan_complete(struct brcmf_cfg80211_info *cfg,
773*4882a593Smuzhiyun 				struct brcmf_if *ifp, bool aborted,
774*4882a593Smuzhiyun 				bool fw_abort)
775*4882a593Smuzhiyun {
776*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
777*4882a593Smuzhiyun 	struct brcmf_scan_params_le params_le;
778*4882a593Smuzhiyun 	struct cfg80211_scan_request *scan_request;
779*4882a593Smuzhiyun 	u64 reqid;
780*4882a593Smuzhiyun 	u32 bucket;
781*4882a593Smuzhiyun 	s32 err = 0;
782*4882a593Smuzhiyun 
783*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "Enter\n");
784*4882a593Smuzhiyun 
785*4882a593Smuzhiyun 	/* clear scan request, because the FW abort can cause a second call */
786*4882a593Smuzhiyun 	/* to this functon and might cause a double cfg80211_scan_done      */
787*4882a593Smuzhiyun 	scan_request = cfg->scan_request;
788*4882a593Smuzhiyun 	cfg->scan_request = NULL;
789*4882a593Smuzhiyun 
790*4882a593Smuzhiyun 	if (timer_pending(&cfg->escan_timeout))
791*4882a593Smuzhiyun 		del_timer_sync(&cfg->escan_timeout);
792*4882a593Smuzhiyun 
793*4882a593Smuzhiyun 	if (fw_abort) {
794*4882a593Smuzhiyun 		/* Do a scan abort to stop the driver's scan engine */
795*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "ABORT scan in firmware\n");
796*4882a593Smuzhiyun 		memset(&params_le, 0, sizeof(params_le));
797*4882a593Smuzhiyun 		eth_broadcast_addr(params_le.bssid);
798*4882a593Smuzhiyun 		params_le.bss_type = DOT11_BSSTYPE_ANY;
799*4882a593Smuzhiyun 		params_le.scan_type = 0;
800*4882a593Smuzhiyun 		params_le.channel_num = cpu_to_le32(1);
801*4882a593Smuzhiyun 		params_le.nprobes = cpu_to_le32(1);
802*4882a593Smuzhiyun 		params_le.active_time = cpu_to_le32(-1);
803*4882a593Smuzhiyun 		params_le.passive_time = cpu_to_le32(-1);
804*4882a593Smuzhiyun 		params_le.home_time = cpu_to_le32(-1);
805*4882a593Smuzhiyun 		/* Scan is aborted by setting channel_list[0] to -1 */
806*4882a593Smuzhiyun 		params_le.channel_list[0] = cpu_to_le16(-1);
807*4882a593Smuzhiyun 		/* E-Scan (or anyother type) can be aborted by SCAN */
808*4882a593Smuzhiyun 		err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SCAN,
809*4882a593Smuzhiyun 					     &params_le, sizeof(params_le));
810*4882a593Smuzhiyun 		if (err)
811*4882a593Smuzhiyun 			bphy_err(drvr, "Scan abort failed\n");
812*4882a593Smuzhiyun 	}
813*4882a593Smuzhiyun 
814*4882a593Smuzhiyun 	brcmf_scan_config_mpc(ifp, 1);
815*4882a593Smuzhiyun 
816*4882a593Smuzhiyun 	/*
817*4882a593Smuzhiyun 	 * e-scan can be initiated internally
818*4882a593Smuzhiyun 	 * which takes precedence.
819*4882a593Smuzhiyun 	 */
820*4882a593Smuzhiyun 	if (cfg->int_escan_map) {
821*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "scheduled scan completed (%x)\n",
822*4882a593Smuzhiyun 			  cfg->int_escan_map);
823*4882a593Smuzhiyun 		while (cfg->int_escan_map) {
824*4882a593Smuzhiyun 			bucket = __ffs(cfg->int_escan_map);
825*4882a593Smuzhiyun 			cfg->int_escan_map &= ~BIT(bucket);
826*4882a593Smuzhiyun 			reqid = brcmf_pno_find_reqid_by_bucket(cfg->pno,
827*4882a593Smuzhiyun 							       bucket);
828*4882a593Smuzhiyun 			if (!aborted) {
829*4882a593Smuzhiyun 				brcmf_dbg(SCAN, "report results: reqid=%llu\n",
830*4882a593Smuzhiyun 					  reqid);
831*4882a593Smuzhiyun 				cfg80211_sched_scan_results(cfg_to_wiphy(cfg),
832*4882a593Smuzhiyun 							    reqid);
833*4882a593Smuzhiyun 			}
834*4882a593Smuzhiyun 		}
835*4882a593Smuzhiyun 	} else if (scan_request) {
836*4882a593Smuzhiyun 		struct cfg80211_scan_info info = {
837*4882a593Smuzhiyun 			.aborted = aborted,
838*4882a593Smuzhiyun 		};
839*4882a593Smuzhiyun 
840*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "ESCAN Completed scan: %s\n",
841*4882a593Smuzhiyun 			  aborted ? "Aborted" : "Done");
842*4882a593Smuzhiyun 		cfg80211_scan_done(scan_request, &info);
843*4882a593Smuzhiyun 	}
844*4882a593Smuzhiyun 	if (!test_and_clear_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status))
845*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "Scan complete, probably P2P scan\n");
846*4882a593Smuzhiyun 
847*4882a593Smuzhiyun 	return err;
848*4882a593Smuzhiyun }
849*4882a593Smuzhiyun 
brcmf_cfg80211_del_ap_iface(struct wiphy * wiphy,struct wireless_dev * wdev)850*4882a593Smuzhiyun static int brcmf_cfg80211_del_ap_iface(struct wiphy *wiphy,
851*4882a593Smuzhiyun 				       struct wireless_dev *wdev)
852*4882a593Smuzhiyun {
853*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
854*4882a593Smuzhiyun 	struct net_device *ndev = wdev->netdev;
855*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
856*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
857*4882a593Smuzhiyun 	int ret;
858*4882a593Smuzhiyun 	int err;
859*4882a593Smuzhiyun 
860*4882a593Smuzhiyun 	brcmf_cfg80211_arm_vif_event(cfg, ifp->vif);
861*4882a593Smuzhiyun 
862*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_data_set(ifp, "interface_remove", NULL, 0);
863*4882a593Smuzhiyun 	if (err) {
864*4882a593Smuzhiyun 		bphy_err(drvr, "interface_remove failed %d\n", err);
865*4882a593Smuzhiyun 		goto err_unarm;
866*4882a593Smuzhiyun 	}
867*4882a593Smuzhiyun 
868*4882a593Smuzhiyun 	/* wait for firmware event */
869*4882a593Smuzhiyun 	ret = brcmf_cfg80211_wait_vif_event(cfg, BRCMF_E_IF_DEL,
870*4882a593Smuzhiyun 					    BRCMF_VIF_EVENT_TIMEOUT);
871*4882a593Smuzhiyun 	if (!ret) {
872*4882a593Smuzhiyun 		bphy_err(drvr, "timeout occurred\n");
873*4882a593Smuzhiyun 		err = -EIO;
874*4882a593Smuzhiyun 		goto err_unarm;
875*4882a593Smuzhiyun 	}
876*4882a593Smuzhiyun 
877*4882a593Smuzhiyun 	brcmf_remove_interface(ifp, true);
878*4882a593Smuzhiyun 
879*4882a593Smuzhiyun err_unarm:
880*4882a593Smuzhiyun 	brcmf_cfg80211_arm_vif_event(cfg, NULL);
881*4882a593Smuzhiyun 	return err;
882*4882a593Smuzhiyun }
883*4882a593Smuzhiyun 
884*4882a593Smuzhiyun static
brcmf_cfg80211_del_iface(struct wiphy * wiphy,struct wireless_dev * wdev)885*4882a593Smuzhiyun int brcmf_cfg80211_del_iface(struct wiphy *wiphy, struct wireless_dev *wdev)
886*4882a593Smuzhiyun {
887*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
888*4882a593Smuzhiyun 	struct net_device *ndev = wdev->netdev;
889*4882a593Smuzhiyun 
890*4882a593Smuzhiyun 	if (ndev && ndev == cfg_to_ndev(cfg))
891*4882a593Smuzhiyun 		return -ENOTSUPP;
892*4882a593Smuzhiyun 
893*4882a593Smuzhiyun 	/* vif event pending in firmware */
894*4882a593Smuzhiyun 	if (brcmf_cfg80211_vif_event_armed(cfg))
895*4882a593Smuzhiyun 		return -EBUSY;
896*4882a593Smuzhiyun 
897*4882a593Smuzhiyun 	if (ndev) {
898*4882a593Smuzhiyun 		if (test_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status) &&
899*4882a593Smuzhiyun 		    cfg->escan_info.ifp == netdev_priv(ndev))
900*4882a593Smuzhiyun 			brcmf_notify_escan_complete(cfg, netdev_priv(ndev),
901*4882a593Smuzhiyun 						    true, true);
902*4882a593Smuzhiyun 
903*4882a593Smuzhiyun 		brcmf_fil_iovar_int_set(netdev_priv(ndev), "mpc", 1);
904*4882a593Smuzhiyun 	}
905*4882a593Smuzhiyun 
906*4882a593Smuzhiyun 	switch (wdev->iftype) {
907*4882a593Smuzhiyun 	case NL80211_IFTYPE_ADHOC:
908*4882a593Smuzhiyun 	case NL80211_IFTYPE_STATION:
909*4882a593Smuzhiyun 	case NL80211_IFTYPE_AP_VLAN:
910*4882a593Smuzhiyun 	case NL80211_IFTYPE_WDS:
911*4882a593Smuzhiyun 	case NL80211_IFTYPE_MESH_POINT:
912*4882a593Smuzhiyun 		return -EOPNOTSUPP;
913*4882a593Smuzhiyun 	case NL80211_IFTYPE_MONITOR:
914*4882a593Smuzhiyun 		return brcmf_mon_del_vif(wiphy, wdev);
915*4882a593Smuzhiyun 	case NL80211_IFTYPE_AP:
916*4882a593Smuzhiyun 		return brcmf_cfg80211_del_ap_iface(wiphy, wdev);
917*4882a593Smuzhiyun 	case NL80211_IFTYPE_P2P_CLIENT:
918*4882a593Smuzhiyun 	case NL80211_IFTYPE_P2P_GO:
919*4882a593Smuzhiyun 	case NL80211_IFTYPE_P2P_DEVICE:
920*4882a593Smuzhiyun 		return brcmf_p2p_del_vif(wiphy, wdev);
921*4882a593Smuzhiyun 	case NL80211_IFTYPE_UNSPECIFIED:
922*4882a593Smuzhiyun 	default:
923*4882a593Smuzhiyun 		return -EINVAL;
924*4882a593Smuzhiyun 	}
925*4882a593Smuzhiyun 	return -EOPNOTSUPP;
926*4882a593Smuzhiyun }
927*4882a593Smuzhiyun 
928*4882a593Smuzhiyun static s32
brcmf_cfg80211_change_iface(struct wiphy * wiphy,struct net_device * ndev,enum nl80211_iftype type,struct vif_params * params)929*4882a593Smuzhiyun brcmf_cfg80211_change_iface(struct wiphy *wiphy, struct net_device *ndev,
930*4882a593Smuzhiyun 			 enum nl80211_iftype type,
931*4882a593Smuzhiyun 			 struct vif_params *params)
932*4882a593Smuzhiyun {
933*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
934*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
935*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif = ifp->vif;
936*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
937*4882a593Smuzhiyun 	s32 infra = 0;
938*4882a593Smuzhiyun 	s32 ap = 0;
939*4882a593Smuzhiyun 	s32 err = 0;
940*4882a593Smuzhiyun 
941*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter, bsscfgidx=%d, type=%d\n", ifp->bsscfgidx,
942*4882a593Smuzhiyun 		  type);
943*4882a593Smuzhiyun 
944*4882a593Smuzhiyun 	/* WAR: There are a number of p2p interface related problems which
945*4882a593Smuzhiyun 	 * need to be handled initially (before doing the validate).
946*4882a593Smuzhiyun 	 * wpa_supplicant tends to do iface changes on p2p device/client/go
947*4882a593Smuzhiyun 	 * which are not always possible/allowed. However we need to return
948*4882a593Smuzhiyun 	 * OK otherwise the wpa_supplicant wont start. The situation differs
949*4882a593Smuzhiyun 	 * on configuration and setup (p2pon=1 module param). The first check
950*4882a593Smuzhiyun 	 * is to see if the request is a change to station for p2p iface.
951*4882a593Smuzhiyun 	 */
952*4882a593Smuzhiyun 	if ((type == NL80211_IFTYPE_STATION) &&
953*4882a593Smuzhiyun 	    ((vif->wdev.iftype == NL80211_IFTYPE_P2P_CLIENT) ||
954*4882a593Smuzhiyun 	     (vif->wdev.iftype == NL80211_IFTYPE_P2P_GO) ||
955*4882a593Smuzhiyun 	     (vif->wdev.iftype == NL80211_IFTYPE_P2P_DEVICE))) {
956*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "Ignoring cmd for p2p if\n");
957*4882a593Smuzhiyun 		/* Now depending on whether module param p2pon=1 was used the
958*4882a593Smuzhiyun 		 * response needs to be either 0 or EOPNOTSUPP. The reason is
959*4882a593Smuzhiyun 		 * that if p2pon=1 is used, but a newer supplicant is used then
960*4882a593Smuzhiyun 		 * we should return an error, as this combination wont work.
961*4882a593Smuzhiyun 		 * In other situations 0 is returned and supplicant will start
962*4882a593Smuzhiyun 		 * normally. It will give a trace in cfg80211, but it is the
963*4882a593Smuzhiyun 		 * only way to get it working. Unfortunately this will result
964*4882a593Smuzhiyun 		 * in situation where we wont support new supplicant in
965*4882a593Smuzhiyun 		 * combination with module param p2pon=1, but that is the way
966*4882a593Smuzhiyun 		 * it is. If the user tries this then unloading of driver might
967*4882a593Smuzhiyun 		 * fail/lock.
968*4882a593Smuzhiyun 		 */
969*4882a593Smuzhiyun 		if (cfg->p2p.p2pdev_dynamically)
970*4882a593Smuzhiyun 			return -EOPNOTSUPP;
971*4882a593Smuzhiyun 		else
972*4882a593Smuzhiyun 			return 0;
973*4882a593Smuzhiyun 	}
974*4882a593Smuzhiyun 	err = brcmf_vif_change_validate(wiphy_to_cfg(wiphy), vif, type);
975*4882a593Smuzhiyun 	if (err) {
976*4882a593Smuzhiyun 		bphy_err(drvr, "iface validation failed: err=%d\n", err);
977*4882a593Smuzhiyun 		return err;
978*4882a593Smuzhiyun 	}
979*4882a593Smuzhiyun 	switch (type) {
980*4882a593Smuzhiyun 	case NL80211_IFTYPE_MONITOR:
981*4882a593Smuzhiyun 	case NL80211_IFTYPE_WDS:
982*4882a593Smuzhiyun 		bphy_err(drvr, "type (%d) : currently we do not support this type\n",
983*4882a593Smuzhiyun 			 type);
984*4882a593Smuzhiyun 		return -EOPNOTSUPP;
985*4882a593Smuzhiyun 	case NL80211_IFTYPE_ADHOC:
986*4882a593Smuzhiyun 		infra = 0;
987*4882a593Smuzhiyun 		break;
988*4882a593Smuzhiyun 	case NL80211_IFTYPE_STATION:
989*4882a593Smuzhiyun 		infra = 1;
990*4882a593Smuzhiyun 		break;
991*4882a593Smuzhiyun 	case NL80211_IFTYPE_AP:
992*4882a593Smuzhiyun 	case NL80211_IFTYPE_P2P_GO:
993*4882a593Smuzhiyun 		ap = 1;
994*4882a593Smuzhiyun 		break;
995*4882a593Smuzhiyun 	default:
996*4882a593Smuzhiyun 		err = -EINVAL;
997*4882a593Smuzhiyun 		goto done;
998*4882a593Smuzhiyun 	}
999*4882a593Smuzhiyun 
1000*4882a593Smuzhiyun 	if (ap) {
1001*4882a593Smuzhiyun 		if (type == NL80211_IFTYPE_P2P_GO) {
1002*4882a593Smuzhiyun 			brcmf_dbg(INFO, "IF Type = P2P GO\n");
1003*4882a593Smuzhiyun 			err = brcmf_p2p_ifchange(cfg, BRCMF_FIL_P2P_IF_GO);
1004*4882a593Smuzhiyun 		}
1005*4882a593Smuzhiyun 		if (!err) {
1006*4882a593Smuzhiyun 			brcmf_dbg(INFO, "IF Type = AP\n");
1007*4882a593Smuzhiyun 		}
1008*4882a593Smuzhiyun 	} else {
1009*4882a593Smuzhiyun 		err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_INFRA, infra);
1010*4882a593Smuzhiyun 		if (err) {
1011*4882a593Smuzhiyun 			bphy_err(drvr, "WLC_SET_INFRA error (%d)\n", err);
1012*4882a593Smuzhiyun 			err = -EAGAIN;
1013*4882a593Smuzhiyun 			goto done;
1014*4882a593Smuzhiyun 		}
1015*4882a593Smuzhiyun 		brcmf_dbg(INFO, "IF Type = %s\n", brcmf_is_ibssmode(vif) ?
1016*4882a593Smuzhiyun 			  "Adhoc" : "Infra");
1017*4882a593Smuzhiyun 	}
1018*4882a593Smuzhiyun 	ndev->ieee80211_ptr->iftype = type;
1019*4882a593Smuzhiyun 
1020*4882a593Smuzhiyun 	brcmf_cfg80211_update_proto_addr_mode(&vif->wdev);
1021*4882a593Smuzhiyun 
1022*4882a593Smuzhiyun done:
1023*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
1024*4882a593Smuzhiyun 
1025*4882a593Smuzhiyun 	return err;
1026*4882a593Smuzhiyun }
1027*4882a593Smuzhiyun 
brcmf_escan_prep(struct brcmf_cfg80211_info * cfg,struct brcmf_scan_params_le * params_le,struct cfg80211_scan_request * request)1028*4882a593Smuzhiyun static void brcmf_escan_prep(struct brcmf_cfg80211_info *cfg,
1029*4882a593Smuzhiyun 			     struct brcmf_scan_params_le *params_le,
1030*4882a593Smuzhiyun 			     struct cfg80211_scan_request *request)
1031*4882a593Smuzhiyun {
1032*4882a593Smuzhiyun 	u32 n_ssids;
1033*4882a593Smuzhiyun 	u32 n_channels;
1034*4882a593Smuzhiyun 	s32 i;
1035*4882a593Smuzhiyun 	s32 offset;
1036*4882a593Smuzhiyun 	u16 chanspec;
1037*4882a593Smuzhiyun 	char *ptr;
1038*4882a593Smuzhiyun 	struct brcmf_ssid_le ssid_le;
1039*4882a593Smuzhiyun 
1040*4882a593Smuzhiyun 	eth_broadcast_addr(params_le->bssid);
1041*4882a593Smuzhiyun 	params_le->bss_type = DOT11_BSSTYPE_ANY;
1042*4882a593Smuzhiyun 	params_le->scan_type = BRCMF_SCANTYPE_ACTIVE;
1043*4882a593Smuzhiyun 	params_le->channel_num = 0;
1044*4882a593Smuzhiyun 	params_le->nprobes = cpu_to_le32(-1);
1045*4882a593Smuzhiyun 	params_le->active_time = cpu_to_le32(-1);
1046*4882a593Smuzhiyun 	params_le->passive_time = cpu_to_le32(-1);
1047*4882a593Smuzhiyun 	params_le->home_time = cpu_to_le32(-1);
1048*4882a593Smuzhiyun 	memset(&params_le->ssid_le, 0, sizeof(params_le->ssid_le));
1049*4882a593Smuzhiyun 
1050*4882a593Smuzhiyun 	n_ssids = request->n_ssids;
1051*4882a593Smuzhiyun 	n_channels = request->n_channels;
1052*4882a593Smuzhiyun 
1053*4882a593Smuzhiyun 	/* Copy channel array if applicable */
1054*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "### List of channelspecs to scan ### %d\n",
1055*4882a593Smuzhiyun 		  n_channels);
1056*4882a593Smuzhiyun 	if (n_channels > 0) {
1057*4882a593Smuzhiyun 		for (i = 0; i < n_channels; i++) {
1058*4882a593Smuzhiyun 			chanspec = channel_to_chanspec(&cfg->d11inf,
1059*4882a593Smuzhiyun 						       request->channels[i]);
1060*4882a593Smuzhiyun 			brcmf_dbg(SCAN, "Chan : %d, Channel spec: %x\n",
1061*4882a593Smuzhiyun 				  request->channels[i]->hw_value, chanspec);
1062*4882a593Smuzhiyun 			params_le->channel_list[i] = cpu_to_le16(chanspec);
1063*4882a593Smuzhiyun 		}
1064*4882a593Smuzhiyun 	} else {
1065*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "Scanning all channels\n");
1066*4882a593Smuzhiyun 	}
1067*4882a593Smuzhiyun 	/* Copy ssid array if applicable */
1068*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "### List of SSIDs to scan ### %d\n", n_ssids);
1069*4882a593Smuzhiyun 	if (n_ssids > 0) {
1070*4882a593Smuzhiyun 		offset = offsetof(struct brcmf_scan_params_le, channel_list) +
1071*4882a593Smuzhiyun 				n_channels * sizeof(u16);
1072*4882a593Smuzhiyun 		offset = roundup(offset, sizeof(u32));
1073*4882a593Smuzhiyun 		ptr = (char *)params_le + offset;
1074*4882a593Smuzhiyun 		for (i = 0; i < n_ssids; i++) {
1075*4882a593Smuzhiyun 			memset(&ssid_le, 0, sizeof(ssid_le));
1076*4882a593Smuzhiyun 			ssid_le.SSID_len =
1077*4882a593Smuzhiyun 					cpu_to_le32(request->ssids[i].ssid_len);
1078*4882a593Smuzhiyun 			memcpy(ssid_le.SSID, request->ssids[i].ssid,
1079*4882a593Smuzhiyun 			       request->ssids[i].ssid_len);
1080*4882a593Smuzhiyun 			if (!ssid_le.SSID_len)
1081*4882a593Smuzhiyun 				brcmf_dbg(SCAN, "%d: Broadcast scan\n", i);
1082*4882a593Smuzhiyun 			else
1083*4882a593Smuzhiyun 				brcmf_dbg(SCAN, "%d: scan for  %.32s size=%d\n",
1084*4882a593Smuzhiyun 					  i, ssid_le.SSID, ssid_le.SSID_len);
1085*4882a593Smuzhiyun 			memcpy(ptr, &ssid_le, sizeof(ssid_le));
1086*4882a593Smuzhiyun 			ptr += sizeof(ssid_le);
1087*4882a593Smuzhiyun 		}
1088*4882a593Smuzhiyun 	} else {
1089*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "Performing passive scan\n");
1090*4882a593Smuzhiyun 		params_le->scan_type = BRCMF_SCANTYPE_PASSIVE;
1091*4882a593Smuzhiyun 	}
1092*4882a593Smuzhiyun 	/* Adding mask to channel numbers */
1093*4882a593Smuzhiyun 	params_le->channel_num =
1094*4882a593Smuzhiyun 		cpu_to_le32((n_ssids << BRCMF_SCAN_PARAMS_NSSID_SHIFT) |
1095*4882a593Smuzhiyun 			(n_channels & BRCMF_SCAN_PARAMS_COUNT_MASK));
1096*4882a593Smuzhiyun }
1097*4882a593Smuzhiyun 
1098*4882a593Smuzhiyun static s32
brcmf_run_escan(struct brcmf_cfg80211_info * cfg,struct brcmf_if * ifp,struct cfg80211_scan_request * request)1099*4882a593Smuzhiyun brcmf_run_escan(struct brcmf_cfg80211_info *cfg, struct brcmf_if *ifp,
1100*4882a593Smuzhiyun 		struct cfg80211_scan_request *request)
1101*4882a593Smuzhiyun {
1102*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
1103*4882a593Smuzhiyun 	s32 params_size = BRCMF_SCAN_PARAMS_FIXED_SIZE +
1104*4882a593Smuzhiyun 			  offsetof(struct brcmf_escan_params_le, params_le);
1105*4882a593Smuzhiyun 	struct brcmf_escan_params_le *params;
1106*4882a593Smuzhiyun 	s32 err = 0;
1107*4882a593Smuzhiyun 
1108*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "E-SCAN START\n");
1109*4882a593Smuzhiyun 
1110*4882a593Smuzhiyun 	if (request != NULL) {
1111*4882a593Smuzhiyun 		/* Allocate space for populating ssids in struct */
1112*4882a593Smuzhiyun 		params_size += sizeof(u32) * ((request->n_channels + 1) / 2);
1113*4882a593Smuzhiyun 
1114*4882a593Smuzhiyun 		/* Allocate space for populating ssids in struct */
1115*4882a593Smuzhiyun 		params_size += sizeof(struct brcmf_ssid_le) * request->n_ssids;
1116*4882a593Smuzhiyun 	}
1117*4882a593Smuzhiyun 
1118*4882a593Smuzhiyun 	params = kzalloc(params_size, GFP_KERNEL);
1119*4882a593Smuzhiyun 	if (!params) {
1120*4882a593Smuzhiyun 		err = -ENOMEM;
1121*4882a593Smuzhiyun 		goto exit;
1122*4882a593Smuzhiyun 	}
1123*4882a593Smuzhiyun 	BUG_ON(params_size + sizeof("escan") >= BRCMF_DCMD_MEDLEN);
1124*4882a593Smuzhiyun 	brcmf_escan_prep(cfg, &params->params_le, request);
1125*4882a593Smuzhiyun 	params->version = cpu_to_le32(BRCMF_ESCAN_REQ_VERSION);
1126*4882a593Smuzhiyun 	params->action = cpu_to_le16(WL_ESCAN_ACTION_START);
1127*4882a593Smuzhiyun 	params->sync_id = cpu_to_le16(0x1234);
1128*4882a593Smuzhiyun 
1129*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_set(ifp, "escan", params, params_size);
1130*4882a593Smuzhiyun 	if (err) {
1131*4882a593Smuzhiyun 		if (err == -EBUSY)
1132*4882a593Smuzhiyun 			brcmf_dbg(INFO, "system busy : escan canceled\n");
1133*4882a593Smuzhiyun 		else
1134*4882a593Smuzhiyun 			bphy_err(drvr, "error (%d)\n", err);
1135*4882a593Smuzhiyun 	}
1136*4882a593Smuzhiyun 
1137*4882a593Smuzhiyun 	kfree(params);
1138*4882a593Smuzhiyun exit:
1139*4882a593Smuzhiyun 	return err;
1140*4882a593Smuzhiyun }
1141*4882a593Smuzhiyun 
1142*4882a593Smuzhiyun static s32
brcmf_do_escan(struct brcmf_if * ifp,struct cfg80211_scan_request * request)1143*4882a593Smuzhiyun brcmf_do_escan(struct brcmf_if *ifp, struct cfg80211_scan_request *request)
1144*4882a593Smuzhiyun {
1145*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = ifp->drvr->config;
1146*4882a593Smuzhiyun 	s32 err;
1147*4882a593Smuzhiyun 	struct brcmf_scan_results *results;
1148*4882a593Smuzhiyun 	struct escan_info *escan = &cfg->escan_info;
1149*4882a593Smuzhiyun 
1150*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "Enter\n");
1151*4882a593Smuzhiyun 	escan->ifp = ifp;
1152*4882a593Smuzhiyun 	escan->wiphy = cfg->wiphy;
1153*4882a593Smuzhiyun 	escan->escan_state = WL_ESCAN_STATE_SCANNING;
1154*4882a593Smuzhiyun 
1155*4882a593Smuzhiyun 	brcmf_scan_config_mpc(ifp, 0);
1156*4882a593Smuzhiyun 	results = (struct brcmf_scan_results *)cfg->escan_info.escan_buf;
1157*4882a593Smuzhiyun 	results->version = 0;
1158*4882a593Smuzhiyun 	results->count = 0;
1159*4882a593Smuzhiyun 	results->buflen = WL_ESCAN_RESULTS_FIXED_SIZE;
1160*4882a593Smuzhiyun 
1161*4882a593Smuzhiyun 	err = escan->run(cfg, ifp, request);
1162*4882a593Smuzhiyun 	if (err)
1163*4882a593Smuzhiyun 		brcmf_scan_config_mpc(ifp, 1);
1164*4882a593Smuzhiyun 	return err;
1165*4882a593Smuzhiyun }
1166*4882a593Smuzhiyun 
1167*4882a593Smuzhiyun static s32
brcmf_cfg80211_scan(struct wiphy * wiphy,struct cfg80211_scan_request * request)1168*4882a593Smuzhiyun brcmf_cfg80211_scan(struct wiphy *wiphy, struct cfg80211_scan_request *request)
1169*4882a593Smuzhiyun {
1170*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
1171*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
1172*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
1173*4882a593Smuzhiyun 	s32 err = 0;
1174*4882a593Smuzhiyun 
1175*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
1176*4882a593Smuzhiyun 	vif = container_of(request->wdev, struct brcmf_cfg80211_vif, wdev);
1177*4882a593Smuzhiyun 	if (!check_vif_up(vif))
1178*4882a593Smuzhiyun 		return -EIO;
1179*4882a593Smuzhiyun 
1180*4882a593Smuzhiyun 	if (test_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status)) {
1181*4882a593Smuzhiyun 		bphy_err(drvr, "Scanning already: status (%lu)\n",
1182*4882a593Smuzhiyun 			 cfg->scan_status);
1183*4882a593Smuzhiyun 		return -EAGAIN;
1184*4882a593Smuzhiyun 	}
1185*4882a593Smuzhiyun 	if (test_bit(BRCMF_SCAN_STATUS_ABORT, &cfg->scan_status)) {
1186*4882a593Smuzhiyun 		bphy_err(drvr, "Scanning being aborted: status (%lu)\n",
1187*4882a593Smuzhiyun 			 cfg->scan_status);
1188*4882a593Smuzhiyun 		return -EAGAIN;
1189*4882a593Smuzhiyun 	}
1190*4882a593Smuzhiyun 	if (test_bit(BRCMF_SCAN_STATUS_SUPPRESS, &cfg->scan_status)) {
1191*4882a593Smuzhiyun 		bphy_err(drvr, "Scanning suppressed: status (%lu)\n",
1192*4882a593Smuzhiyun 			 cfg->scan_status);
1193*4882a593Smuzhiyun 		return -EAGAIN;
1194*4882a593Smuzhiyun 	}
1195*4882a593Smuzhiyun 	if (test_bit(BRCMF_VIF_STATUS_CONNECTING, &vif->sme_state)) {
1196*4882a593Smuzhiyun 		bphy_err(drvr, "Connecting: status (%lu)\n", vif->sme_state);
1197*4882a593Smuzhiyun 		return -EAGAIN;
1198*4882a593Smuzhiyun 	}
1199*4882a593Smuzhiyun 
1200*4882a593Smuzhiyun 	/* If scan req comes for p2p0, send it over primary I/F */
1201*4882a593Smuzhiyun 	if (vif == cfg->p2p.bss_idx[P2PAPI_BSSCFG_DEVICE].vif)
1202*4882a593Smuzhiyun 		vif = cfg->p2p.bss_idx[P2PAPI_BSSCFG_PRIMARY].vif;
1203*4882a593Smuzhiyun 
1204*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "START ESCAN\n");
1205*4882a593Smuzhiyun 
1206*4882a593Smuzhiyun 	cfg->scan_request = request;
1207*4882a593Smuzhiyun 	set_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status);
1208*4882a593Smuzhiyun 
1209*4882a593Smuzhiyun 	cfg->escan_info.run = brcmf_run_escan;
1210*4882a593Smuzhiyun 	err = brcmf_p2p_scan_prep(wiphy, request, vif);
1211*4882a593Smuzhiyun 	if (err)
1212*4882a593Smuzhiyun 		goto scan_out;
1213*4882a593Smuzhiyun 
1214*4882a593Smuzhiyun 	err = brcmf_vif_set_mgmt_ie(vif, BRCMF_VNDR_IE_PRBREQ_FLAG,
1215*4882a593Smuzhiyun 				    request->ie, request->ie_len);
1216*4882a593Smuzhiyun 	if (err)
1217*4882a593Smuzhiyun 		goto scan_out;
1218*4882a593Smuzhiyun 
1219*4882a593Smuzhiyun 	err = brcmf_do_escan(vif->ifp, request);
1220*4882a593Smuzhiyun 	if (err)
1221*4882a593Smuzhiyun 		goto scan_out;
1222*4882a593Smuzhiyun 
1223*4882a593Smuzhiyun 	/* Arm scan timeout timer */
1224*4882a593Smuzhiyun 	mod_timer(&cfg->escan_timeout,
1225*4882a593Smuzhiyun 		  jiffies + msecs_to_jiffies(BRCMF_ESCAN_TIMER_INTERVAL_MS));
1226*4882a593Smuzhiyun 
1227*4882a593Smuzhiyun 	return 0;
1228*4882a593Smuzhiyun 
1229*4882a593Smuzhiyun scan_out:
1230*4882a593Smuzhiyun 	bphy_err(drvr, "scan error (%d)\n", err);
1231*4882a593Smuzhiyun 	clear_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status);
1232*4882a593Smuzhiyun 	cfg->scan_request = NULL;
1233*4882a593Smuzhiyun 	return err;
1234*4882a593Smuzhiyun }
1235*4882a593Smuzhiyun 
brcmf_set_rts(struct net_device * ndev,u32 rts_threshold)1236*4882a593Smuzhiyun static s32 brcmf_set_rts(struct net_device *ndev, u32 rts_threshold)
1237*4882a593Smuzhiyun {
1238*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1239*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1240*4882a593Smuzhiyun 	s32 err = 0;
1241*4882a593Smuzhiyun 
1242*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_set(ifp, "rtsthresh", rts_threshold);
1243*4882a593Smuzhiyun 	if (err)
1244*4882a593Smuzhiyun 		bphy_err(drvr, "Error (%d)\n", err);
1245*4882a593Smuzhiyun 
1246*4882a593Smuzhiyun 	return err;
1247*4882a593Smuzhiyun }
1248*4882a593Smuzhiyun 
brcmf_set_frag(struct net_device * ndev,u32 frag_threshold)1249*4882a593Smuzhiyun static s32 brcmf_set_frag(struct net_device *ndev, u32 frag_threshold)
1250*4882a593Smuzhiyun {
1251*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1252*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1253*4882a593Smuzhiyun 	s32 err = 0;
1254*4882a593Smuzhiyun 
1255*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_set(ifp, "fragthresh",
1256*4882a593Smuzhiyun 				      frag_threshold);
1257*4882a593Smuzhiyun 	if (err)
1258*4882a593Smuzhiyun 		bphy_err(drvr, "Error (%d)\n", err);
1259*4882a593Smuzhiyun 
1260*4882a593Smuzhiyun 	return err;
1261*4882a593Smuzhiyun }
1262*4882a593Smuzhiyun 
brcmf_set_retry(struct net_device * ndev,u32 retry,bool l)1263*4882a593Smuzhiyun static s32 brcmf_set_retry(struct net_device *ndev, u32 retry, bool l)
1264*4882a593Smuzhiyun {
1265*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1266*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1267*4882a593Smuzhiyun 	s32 err = 0;
1268*4882a593Smuzhiyun 	u32 cmd = (l ? BRCMF_C_SET_LRL : BRCMF_C_SET_SRL);
1269*4882a593Smuzhiyun 
1270*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_set(ifp, cmd, retry);
1271*4882a593Smuzhiyun 	if (err) {
1272*4882a593Smuzhiyun 		bphy_err(drvr, "cmd (%d) , error (%d)\n", cmd, err);
1273*4882a593Smuzhiyun 		return err;
1274*4882a593Smuzhiyun 	}
1275*4882a593Smuzhiyun 	return err;
1276*4882a593Smuzhiyun }
1277*4882a593Smuzhiyun 
brcmf_cfg80211_set_wiphy_params(struct wiphy * wiphy,u32 changed)1278*4882a593Smuzhiyun static s32 brcmf_cfg80211_set_wiphy_params(struct wiphy *wiphy, u32 changed)
1279*4882a593Smuzhiyun {
1280*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
1281*4882a593Smuzhiyun 	struct net_device *ndev = cfg_to_ndev(cfg);
1282*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1283*4882a593Smuzhiyun 	s32 err = 0;
1284*4882a593Smuzhiyun 
1285*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
1286*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
1287*4882a593Smuzhiyun 		return -EIO;
1288*4882a593Smuzhiyun 
1289*4882a593Smuzhiyun 	if (changed & WIPHY_PARAM_RTS_THRESHOLD &&
1290*4882a593Smuzhiyun 	    (cfg->conf->rts_threshold != wiphy->rts_threshold)) {
1291*4882a593Smuzhiyun 		cfg->conf->rts_threshold = wiphy->rts_threshold;
1292*4882a593Smuzhiyun 		err = brcmf_set_rts(ndev, cfg->conf->rts_threshold);
1293*4882a593Smuzhiyun 		if (!err)
1294*4882a593Smuzhiyun 			goto done;
1295*4882a593Smuzhiyun 	}
1296*4882a593Smuzhiyun 	if (changed & WIPHY_PARAM_FRAG_THRESHOLD &&
1297*4882a593Smuzhiyun 	    (cfg->conf->frag_threshold != wiphy->frag_threshold)) {
1298*4882a593Smuzhiyun 		cfg->conf->frag_threshold = wiphy->frag_threshold;
1299*4882a593Smuzhiyun 		err = brcmf_set_frag(ndev, cfg->conf->frag_threshold);
1300*4882a593Smuzhiyun 		if (!err)
1301*4882a593Smuzhiyun 			goto done;
1302*4882a593Smuzhiyun 	}
1303*4882a593Smuzhiyun 	if (changed & WIPHY_PARAM_RETRY_LONG
1304*4882a593Smuzhiyun 	    && (cfg->conf->retry_long != wiphy->retry_long)) {
1305*4882a593Smuzhiyun 		cfg->conf->retry_long = wiphy->retry_long;
1306*4882a593Smuzhiyun 		err = brcmf_set_retry(ndev, cfg->conf->retry_long, true);
1307*4882a593Smuzhiyun 		if (!err)
1308*4882a593Smuzhiyun 			goto done;
1309*4882a593Smuzhiyun 	}
1310*4882a593Smuzhiyun 	if (changed & WIPHY_PARAM_RETRY_SHORT
1311*4882a593Smuzhiyun 	    && (cfg->conf->retry_short != wiphy->retry_short)) {
1312*4882a593Smuzhiyun 		cfg->conf->retry_short = wiphy->retry_short;
1313*4882a593Smuzhiyun 		err = brcmf_set_retry(ndev, cfg->conf->retry_short, false);
1314*4882a593Smuzhiyun 		if (!err)
1315*4882a593Smuzhiyun 			goto done;
1316*4882a593Smuzhiyun 	}
1317*4882a593Smuzhiyun 
1318*4882a593Smuzhiyun done:
1319*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
1320*4882a593Smuzhiyun 	return err;
1321*4882a593Smuzhiyun }
1322*4882a593Smuzhiyun 
brcmf_init_prof(struct brcmf_cfg80211_profile * prof)1323*4882a593Smuzhiyun static void brcmf_init_prof(struct brcmf_cfg80211_profile *prof)
1324*4882a593Smuzhiyun {
1325*4882a593Smuzhiyun 	memset(prof, 0, sizeof(*prof));
1326*4882a593Smuzhiyun }
1327*4882a593Smuzhiyun 
brcmf_map_fw_linkdown_reason(const struct brcmf_event_msg * e)1328*4882a593Smuzhiyun static u16 brcmf_map_fw_linkdown_reason(const struct brcmf_event_msg *e)
1329*4882a593Smuzhiyun {
1330*4882a593Smuzhiyun 	u16 reason;
1331*4882a593Smuzhiyun 
1332*4882a593Smuzhiyun 	switch (e->event_code) {
1333*4882a593Smuzhiyun 	case BRCMF_E_DEAUTH:
1334*4882a593Smuzhiyun 	case BRCMF_E_DEAUTH_IND:
1335*4882a593Smuzhiyun 	case BRCMF_E_DISASSOC_IND:
1336*4882a593Smuzhiyun 		reason = e->reason;
1337*4882a593Smuzhiyun 		break;
1338*4882a593Smuzhiyun 	case BRCMF_E_LINK:
1339*4882a593Smuzhiyun 	default:
1340*4882a593Smuzhiyun 		reason = 0;
1341*4882a593Smuzhiyun 		break;
1342*4882a593Smuzhiyun 	}
1343*4882a593Smuzhiyun 	return reason;
1344*4882a593Smuzhiyun }
1345*4882a593Smuzhiyun 
brcmf_set_pmk(struct brcmf_if * ifp,const u8 * pmk_data,u16 pmk_len)1346*4882a593Smuzhiyun static int brcmf_set_pmk(struct brcmf_if *ifp, const u8 *pmk_data, u16 pmk_len)
1347*4882a593Smuzhiyun {
1348*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1349*4882a593Smuzhiyun 	struct brcmf_wsec_pmk_le pmk;
1350*4882a593Smuzhiyun 	int i, err;
1351*4882a593Smuzhiyun 
1352*4882a593Smuzhiyun 	/* convert to firmware key format */
1353*4882a593Smuzhiyun 	pmk.key_len = cpu_to_le16(pmk_len << 1);
1354*4882a593Smuzhiyun 	pmk.flags = cpu_to_le16(BRCMF_WSEC_PASSPHRASE);
1355*4882a593Smuzhiyun 	for (i = 0; i < pmk_len; i++)
1356*4882a593Smuzhiyun 		snprintf(&pmk.key[2 * i], 3, "%02x", pmk_data[i]);
1357*4882a593Smuzhiyun 
1358*4882a593Smuzhiyun 	/* store psk in firmware */
1359*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SET_WSEC_PMK,
1360*4882a593Smuzhiyun 				     &pmk, sizeof(pmk));
1361*4882a593Smuzhiyun 	if (err < 0)
1362*4882a593Smuzhiyun 		bphy_err(drvr, "failed to change PSK in firmware (len=%u)\n",
1363*4882a593Smuzhiyun 			 pmk_len);
1364*4882a593Smuzhiyun 
1365*4882a593Smuzhiyun 	return err;
1366*4882a593Smuzhiyun }
1367*4882a593Smuzhiyun 
brcmf_set_sae_password(struct brcmf_if * ifp,const u8 * pwd_data,u16 pwd_len)1368*4882a593Smuzhiyun static int brcmf_set_sae_password(struct brcmf_if *ifp, const u8 *pwd_data,
1369*4882a593Smuzhiyun 				  u16 pwd_len)
1370*4882a593Smuzhiyun {
1371*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1372*4882a593Smuzhiyun 	struct brcmf_wsec_sae_pwd_le sae_pwd;
1373*4882a593Smuzhiyun 	int err;
1374*4882a593Smuzhiyun 
1375*4882a593Smuzhiyun 	if (pwd_len > BRCMF_WSEC_MAX_SAE_PASSWORD_LEN) {
1376*4882a593Smuzhiyun 		bphy_err(drvr, "sae_password must be less than %d\n",
1377*4882a593Smuzhiyun 			 BRCMF_WSEC_MAX_SAE_PASSWORD_LEN);
1378*4882a593Smuzhiyun 		return -EINVAL;
1379*4882a593Smuzhiyun 	}
1380*4882a593Smuzhiyun 
1381*4882a593Smuzhiyun 	sae_pwd.key_len = cpu_to_le16(pwd_len);
1382*4882a593Smuzhiyun 	memcpy(sae_pwd.key, pwd_data, pwd_len);
1383*4882a593Smuzhiyun 
1384*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_set(ifp, "sae_password", &sae_pwd,
1385*4882a593Smuzhiyun 				       sizeof(sae_pwd));
1386*4882a593Smuzhiyun 	if (err < 0)
1387*4882a593Smuzhiyun 		bphy_err(drvr, "failed to set SAE password in firmware (len=%u)\n",
1388*4882a593Smuzhiyun 			 pwd_len);
1389*4882a593Smuzhiyun 
1390*4882a593Smuzhiyun 	return err;
1391*4882a593Smuzhiyun }
1392*4882a593Smuzhiyun 
brcmf_link_down(struct brcmf_cfg80211_vif * vif,u16 reason,bool locally_generated)1393*4882a593Smuzhiyun static void brcmf_link_down(struct brcmf_cfg80211_vif *vif, u16 reason,
1394*4882a593Smuzhiyun 			    bool locally_generated)
1395*4882a593Smuzhiyun {
1396*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(vif->wdev.wiphy);
1397*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
1398*4882a593Smuzhiyun 	bool bus_up = drvr->bus_if->state == BRCMF_BUS_UP;
1399*4882a593Smuzhiyun 	s32 err = 0;
1400*4882a593Smuzhiyun 
1401*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
1402*4882a593Smuzhiyun 
1403*4882a593Smuzhiyun 	if (test_and_clear_bit(BRCMF_VIF_STATUS_CONNECTED, &vif->sme_state)) {
1404*4882a593Smuzhiyun 		if (bus_up) {
1405*4882a593Smuzhiyun 			brcmf_dbg(INFO, "Call WLC_DISASSOC to stop excess roaming\n");
1406*4882a593Smuzhiyun 			err = brcmf_fil_cmd_data_set(vif->ifp,
1407*4882a593Smuzhiyun 						     BRCMF_C_DISASSOC, NULL, 0);
1408*4882a593Smuzhiyun 			if (err)
1409*4882a593Smuzhiyun 				bphy_err(drvr, "WLC_DISASSOC failed (%d)\n",
1410*4882a593Smuzhiyun 					 err);
1411*4882a593Smuzhiyun 		}
1412*4882a593Smuzhiyun 
1413*4882a593Smuzhiyun 		if ((vif->wdev.iftype == NL80211_IFTYPE_STATION) ||
1414*4882a593Smuzhiyun 		    (vif->wdev.iftype == NL80211_IFTYPE_P2P_CLIENT))
1415*4882a593Smuzhiyun 			cfg80211_disconnected(vif->wdev.netdev, reason, NULL, 0,
1416*4882a593Smuzhiyun 					      locally_generated, GFP_KERNEL);
1417*4882a593Smuzhiyun 	}
1418*4882a593Smuzhiyun 	clear_bit(BRCMF_VIF_STATUS_CONNECTING, &vif->sme_state);
1419*4882a593Smuzhiyun 	clear_bit(BRCMF_SCAN_STATUS_SUPPRESS, &cfg->scan_status);
1420*4882a593Smuzhiyun 	brcmf_btcoex_set_mode(vif, BRCMF_BTCOEX_ENABLED, 0);
1421*4882a593Smuzhiyun 	if (vif->profile.use_fwsup != BRCMF_PROFILE_FWSUP_NONE) {
1422*4882a593Smuzhiyun 		if (bus_up)
1423*4882a593Smuzhiyun 			brcmf_set_pmk(vif->ifp, NULL, 0);
1424*4882a593Smuzhiyun 		vif->profile.use_fwsup = BRCMF_PROFILE_FWSUP_NONE;
1425*4882a593Smuzhiyun 	}
1426*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
1427*4882a593Smuzhiyun }
1428*4882a593Smuzhiyun 
1429*4882a593Smuzhiyun static s32
brcmf_cfg80211_join_ibss(struct wiphy * wiphy,struct net_device * ndev,struct cfg80211_ibss_params * params)1430*4882a593Smuzhiyun brcmf_cfg80211_join_ibss(struct wiphy *wiphy, struct net_device *ndev,
1431*4882a593Smuzhiyun 		      struct cfg80211_ibss_params *params)
1432*4882a593Smuzhiyun {
1433*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
1434*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1435*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
1436*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
1437*4882a593Smuzhiyun 	struct brcmf_join_params join_params;
1438*4882a593Smuzhiyun 	size_t join_params_size = 0;
1439*4882a593Smuzhiyun 	s32 err = 0;
1440*4882a593Smuzhiyun 	s32 wsec = 0;
1441*4882a593Smuzhiyun 	s32 bcnprd;
1442*4882a593Smuzhiyun 	u16 chanspec;
1443*4882a593Smuzhiyun 	u32 ssid_len;
1444*4882a593Smuzhiyun 
1445*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
1446*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
1447*4882a593Smuzhiyun 		return -EIO;
1448*4882a593Smuzhiyun 
1449*4882a593Smuzhiyun 	if (params->ssid)
1450*4882a593Smuzhiyun 		brcmf_dbg(CONN, "SSID: %s\n", params->ssid);
1451*4882a593Smuzhiyun 	else {
1452*4882a593Smuzhiyun 		brcmf_dbg(CONN, "SSID: NULL, Not supported\n");
1453*4882a593Smuzhiyun 		return -EOPNOTSUPP;
1454*4882a593Smuzhiyun 	}
1455*4882a593Smuzhiyun 
1456*4882a593Smuzhiyun 	set_bit(BRCMF_VIF_STATUS_CONNECTING, &ifp->vif->sme_state);
1457*4882a593Smuzhiyun 
1458*4882a593Smuzhiyun 	if (params->bssid)
1459*4882a593Smuzhiyun 		brcmf_dbg(CONN, "BSSID: %pM\n", params->bssid);
1460*4882a593Smuzhiyun 	else
1461*4882a593Smuzhiyun 		brcmf_dbg(CONN, "No BSSID specified\n");
1462*4882a593Smuzhiyun 
1463*4882a593Smuzhiyun 	if (params->chandef.chan)
1464*4882a593Smuzhiyun 		brcmf_dbg(CONN, "channel: %d\n",
1465*4882a593Smuzhiyun 			  params->chandef.chan->center_freq);
1466*4882a593Smuzhiyun 	else
1467*4882a593Smuzhiyun 		brcmf_dbg(CONN, "no channel specified\n");
1468*4882a593Smuzhiyun 
1469*4882a593Smuzhiyun 	if (params->channel_fixed)
1470*4882a593Smuzhiyun 		brcmf_dbg(CONN, "fixed channel required\n");
1471*4882a593Smuzhiyun 	else
1472*4882a593Smuzhiyun 		brcmf_dbg(CONN, "no fixed channel required\n");
1473*4882a593Smuzhiyun 
1474*4882a593Smuzhiyun 	if (params->ie && params->ie_len)
1475*4882a593Smuzhiyun 		brcmf_dbg(CONN, "ie len: %d\n", params->ie_len);
1476*4882a593Smuzhiyun 	else
1477*4882a593Smuzhiyun 		brcmf_dbg(CONN, "no ie specified\n");
1478*4882a593Smuzhiyun 
1479*4882a593Smuzhiyun 	if (params->beacon_interval)
1480*4882a593Smuzhiyun 		brcmf_dbg(CONN, "beacon interval: %d\n",
1481*4882a593Smuzhiyun 			  params->beacon_interval);
1482*4882a593Smuzhiyun 	else
1483*4882a593Smuzhiyun 		brcmf_dbg(CONN, "no beacon interval specified\n");
1484*4882a593Smuzhiyun 
1485*4882a593Smuzhiyun 	if (params->basic_rates)
1486*4882a593Smuzhiyun 		brcmf_dbg(CONN, "basic rates: %08X\n", params->basic_rates);
1487*4882a593Smuzhiyun 	else
1488*4882a593Smuzhiyun 		brcmf_dbg(CONN, "no basic rates specified\n");
1489*4882a593Smuzhiyun 
1490*4882a593Smuzhiyun 	if (params->privacy)
1491*4882a593Smuzhiyun 		brcmf_dbg(CONN, "privacy required\n");
1492*4882a593Smuzhiyun 	else
1493*4882a593Smuzhiyun 		brcmf_dbg(CONN, "no privacy required\n");
1494*4882a593Smuzhiyun 
1495*4882a593Smuzhiyun 	/* Configure Privacy for starter */
1496*4882a593Smuzhiyun 	if (params->privacy)
1497*4882a593Smuzhiyun 		wsec |= WEP_ENABLED;
1498*4882a593Smuzhiyun 
1499*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_set(ifp, "wsec", wsec);
1500*4882a593Smuzhiyun 	if (err) {
1501*4882a593Smuzhiyun 		bphy_err(drvr, "wsec failed (%d)\n", err);
1502*4882a593Smuzhiyun 		goto done;
1503*4882a593Smuzhiyun 	}
1504*4882a593Smuzhiyun 
1505*4882a593Smuzhiyun 	/* Configure Beacon Interval for starter */
1506*4882a593Smuzhiyun 	if (params->beacon_interval)
1507*4882a593Smuzhiyun 		bcnprd = params->beacon_interval;
1508*4882a593Smuzhiyun 	else
1509*4882a593Smuzhiyun 		bcnprd = 100;
1510*4882a593Smuzhiyun 
1511*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_BCNPRD, bcnprd);
1512*4882a593Smuzhiyun 	if (err) {
1513*4882a593Smuzhiyun 		bphy_err(drvr, "WLC_SET_BCNPRD failed (%d)\n", err);
1514*4882a593Smuzhiyun 		goto done;
1515*4882a593Smuzhiyun 	}
1516*4882a593Smuzhiyun 
1517*4882a593Smuzhiyun 	/* Configure required join parameter */
1518*4882a593Smuzhiyun 	memset(&join_params, 0, sizeof(struct brcmf_join_params));
1519*4882a593Smuzhiyun 
1520*4882a593Smuzhiyun 	/* SSID */
1521*4882a593Smuzhiyun 	ssid_len = min_t(u32, params->ssid_len, IEEE80211_MAX_SSID_LEN);
1522*4882a593Smuzhiyun 	memcpy(join_params.ssid_le.SSID, params->ssid, ssid_len);
1523*4882a593Smuzhiyun 	join_params.ssid_le.SSID_len = cpu_to_le32(ssid_len);
1524*4882a593Smuzhiyun 	join_params_size = sizeof(join_params.ssid_le);
1525*4882a593Smuzhiyun 
1526*4882a593Smuzhiyun 	/* BSSID */
1527*4882a593Smuzhiyun 	if (params->bssid) {
1528*4882a593Smuzhiyun 		memcpy(join_params.params_le.bssid, params->bssid, ETH_ALEN);
1529*4882a593Smuzhiyun 		join_params_size += BRCMF_ASSOC_PARAMS_FIXED_SIZE;
1530*4882a593Smuzhiyun 		memcpy(profile->bssid, params->bssid, ETH_ALEN);
1531*4882a593Smuzhiyun 	} else {
1532*4882a593Smuzhiyun 		eth_broadcast_addr(join_params.params_le.bssid);
1533*4882a593Smuzhiyun 		eth_zero_addr(profile->bssid);
1534*4882a593Smuzhiyun 	}
1535*4882a593Smuzhiyun 
1536*4882a593Smuzhiyun 	/* Channel */
1537*4882a593Smuzhiyun 	if (params->chandef.chan) {
1538*4882a593Smuzhiyun 		u32 target_channel;
1539*4882a593Smuzhiyun 
1540*4882a593Smuzhiyun 		cfg->channel =
1541*4882a593Smuzhiyun 			ieee80211_frequency_to_channel(
1542*4882a593Smuzhiyun 				params->chandef.chan->center_freq);
1543*4882a593Smuzhiyun 		if (params->channel_fixed) {
1544*4882a593Smuzhiyun 			/* adding chanspec */
1545*4882a593Smuzhiyun 			chanspec = chandef_to_chanspec(&cfg->d11inf,
1546*4882a593Smuzhiyun 						       &params->chandef);
1547*4882a593Smuzhiyun 			join_params.params_le.chanspec_list[0] =
1548*4882a593Smuzhiyun 				cpu_to_le16(chanspec);
1549*4882a593Smuzhiyun 			join_params.params_le.chanspec_num = cpu_to_le32(1);
1550*4882a593Smuzhiyun 			join_params_size += sizeof(join_params.params_le);
1551*4882a593Smuzhiyun 		}
1552*4882a593Smuzhiyun 
1553*4882a593Smuzhiyun 		/* set channel for starter */
1554*4882a593Smuzhiyun 		target_channel = cfg->channel;
1555*4882a593Smuzhiyun 		err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_CHANNEL,
1556*4882a593Smuzhiyun 					    target_channel);
1557*4882a593Smuzhiyun 		if (err) {
1558*4882a593Smuzhiyun 			bphy_err(drvr, "WLC_SET_CHANNEL failed (%d)\n", err);
1559*4882a593Smuzhiyun 			goto done;
1560*4882a593Smuzhiyun 		}
1561*4882a593Smuzhiyun 	} else
1562*4882a593Smuzhiyun 		cfg->channel = 0;
1563*4882a593Smuzhiyun 
1564*4882a593Smuzhiyun 	cfg->ibss_starter = false;
1565*4882a593Smuzhiyun 
1566*4882a593Smuzhiyun 
1567*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SET_SSID,
1568*4882a593Smuzhiyun 				     &join_params, join_params_size);
1569*4882a593Smuzhiyun 	if (err) {
1570*4882a593Smuzhiyun 		bphy_err(drvr, "WLC_SET_SSID failed (%d)\n", err);
1571*4882a593Smuzhiyun 		goto done;
1572*4882a593Smuzhiyun 	}
1573*4882a593Smuzhiyun 
1574*4882a593Smuzhiyun done:
1575*4882a593Smuzhiyun 	if (err)
1576*4882a593Smuzhiyun 		clear_bit(BRCMF_VIF_STATUS_CONNECTING, &ifp->vif->sme_state);
1577*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
1578*4882a593Smuzhiyun 	return err;
1579*4882a593Smuzhiyun }
1580*4882a593Smuzhiyun 
1581*4882a593Smuzhiyun static s32
brcmf_cfg80211_leave_ibss(struct wiphy * wiphy,struct net_device * ndev)1582*4882a593Smuzhiyun brcmf_cfg80211_leave_ibss(struct wiphy *wiphy, struct net_device *ndev)
1583*4882a593Smuzhiyun {
1584*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1585*4882a593Smuzhiyun 
1586*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
1587*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif)) {
1588*4882a593Smuzhiyun 		/* When driver is being unloaded, it can end up here. If an
1589*4882a593Smuzhiyun 		 * error is returned then later on a debug trace in the wireless
1590*4882a593Smuzhiyun 		 * core module will be printed. To avoid this 0 is returned.
1591*4882a593Smuzhiyun 		 */
1592*4882a593Smuzhiyun 		return 0;
1593*4882a593Smuzhiyun 	}
1594*4882a593Smuzhiyun 
1595*4882a593Smuzhiyun 	brcmf_link_down(ifp->vif, WLAN_REASON_DEAUTH_LEAVING, true);
1596*4882a593Smuzhiyun 	brcmf_net_setcarrier(ifp, false);
1597*4882a593Smuzhiyun 
1598*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
1599*4882a593Smuzhiyun 
1600*4882a593Smuzhiyun 	return 0;
1601*4882a593Smuzhiyun }
1602*4882a593Smuzhiyun 
brcmf_set_wpa_version(struct net_device * ndev,struct cfg80211_connect_params * sme)1603*4882a593Smuzhiyun static s32 brcmf_set_wpa_version(struct net_device *ndev,
1604*4882a593Smuzhiyun 				 struct cfg80211_connect_params *sme)
1605*4882a593Smuzhiyun {
1606*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1607*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = ndev_to_prof(ndev);
1608*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1609*4882a593Smuzhiyun 	struct brcmf_cfg80211_security *sec;
1610*4882a593Smuzhiyun 	s32 val = 0;
1611*4882a593Smuzhiyun 	s32 err = 0;
1612*4882a593Smuzhiyun 
1613*4882a593Smuzhiyun 	if (sme->crypto.wpa_versions & NL80211_WPA_VERSION_1)
1614*4882a593Smuzhiyun 		val = WPA_AUTH_PSK | WPA_AUTH_UNSPECIFIED;
1615*4882a593Smuzhiyun 	else if (sme->crypto.wpa_versions & NL80211_WPA_VERSION_2)
1616*4882a593Smuzhiyun 		val = WPA2_AUTH_PSK | WPA2_AUTH_UNSPECIFIED;
1617*4882a593Smuzhiyun 	else if (sme->crypto.wpa_versions & NL80211_WPA_VERSION_3)
1618*4882a593Smuzhiyun 		val = WPA3_AUTH_SAE_PSK;
1619*4882a593Smuzhiyun 	else
1620*4882a593Smuzhiyun 		val = WPA_AUTH_DISABLED;
1621*4882a593Smuzhiyun 	brcmf_dbg(CONN, "setting wpa_auth to 0x%0x\n", val);
1622*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "wpa_auth", val);
1623*4882a593Smuzhiyun 	if (err) {
1624*4882a593Smuzhiyun 		bphy_err(drvr, "set wpa_auth failed (%d)\n", err);
1625*4882a593Smuzhiyun 		return err;
1626*4882a593Smuzhiyun 	}
1627*4882a593Smuzhiyun 	sec = &profile->sec;
1628*4882a593Smuzhiyun 	sec->wpa_versions = sme->crypto.wpa_versions;
1629*4882a593Smuzhiyun 	return err;
1630*4882a593Smuzhiyun }
1631*4882a593Smuzhiyun 
brcmf_set_auth_type(struct net_device * ndev,struct cfg80211_connect_params * sme)1632*4882a593Smuzhiyun static s32 brcmf_set_auth_type(struct net_device *ndev,
1633*4882a593Smuzhiyun 			       struct cfg80211_connect_params *sme)
1634*4882a593Smuzhiyun {
1635*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1636*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = ndev_to_prof(ndev);
1637*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1638*4882a593Smuzhiyun 	struct brcmf_cfg80211_security *sec;
1639*4882a593Smuzhiyun 	s32 val = 0;
1640*4882a593Smuzhiyun 	s32 err = 0;
1641*4882a593Smuzhiyun 
1642*4882a593Smuzhiyun 	switch (sme->auth_type) {
1643*4882a593Smuzhiyun 	case NL80211_AUTHTYPE_OPEN_SYSTEM:
1644*4882a593Smuzhiyun 		val = 0;
1645*4882a593Smuzhiyun 		brcmf_dbg(CONN, "open system\n");
1646*4882a593Smuzhiyun 		break;
1647*4882a593Smuzhiyun 	case NL80211_AUTHTYPE_SHARED_KEY:
1648*4882a593Smuzhiyun 		val = 1;
1649*4882a593Smuzhiyun 		brcmf_dbg(CONN, "shared key\n");
1650*4882a593Smuzhiyun 		break;
1651*4882a593Smuzhiyun 	case NL80211_AUTHTYPE_SAE:
1652*4882a593Smuzhiyun 		val = 3;
1653*4882a593Smuzhiyun 		brcmf_dbg(CONN, "SAE authentication\n");
1654*4882a593Smuzhiyun 		break;
1655*4882a593Smuzhiyun 	default:
1656*4882a593Smuzhiyun 		val = 2;
1657*4882a593Smuzhiyun 		brcmf_dbg(CONN, "automatic, auth type (%d)\n", sme->auth_type);
1658*4882a593Smuzhiyun 		break;
1659*4882a593Smuzhiyun 	}
1660*4882a593Smuzhiyun 
1661*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "auth", val);
1662*4882a593Smuzhiyun 	if (err) {
1663*4882a593Smuzhiyun 		bphy_err(drvr, "set auth failed (%d)\n", err);
1664*4882a593Smuzhiyun 		return err;
1665*4882a593Smuzhiyun 	}
1666*4882a593Smuzhiyun 	sec = &profile->sec;
1667*4882a593Smuzhiyun 	sec->auth_type = sme->auth_type;
1668*4882a593Smuzhiyun 	return err;
1669*4882a593Smuzhiyun }
1670*4882a593Smuzhiyun 
1671*4882a593Smuzhiyun static s32
brcmf_set_wsec_mode(struct net_device * ndev,struct cfg80211_connect_params * sme)1672*4882a593Smuzhiyun brcmf_set_wsec_mode(struct net_device *ndev,
1673*4882a593Smuzhiyun 		    struct cfg80211_connect_params *sme)
1674*4882a593Smuzhiyun {
1675*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1676*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = ndev_to_prof(ndev);
1677*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1678*4882a593Smuzhiyun 	struct brcmf_cfg80211_security *sec;
1679*4882a593Smuzhiyun 	s32 pval = 0;
1680*4882a593Smuzhiyun 	s32 gval = 0;
1681*4882a593Smuzhiyun 	s32 wsec;
1682*4882a593Smuzhiyun 	s32 err = 0;
1683*4882a593Smuzhiyun 
1684*4882a593Smuzhiyun 	if (sme->crypto.n_ciphers_pairwise) {
1685*4882a593Smuzhiyun 		switch (sme->crypto.ciphers_pairwise[0]) {
1686*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_WEP40:
1687*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_WEP104:
1688*4882a593Smuzhiyun 			pval = WEP_ENABLED;
1689*4882a593Smuzhiyun 			break;
1690*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_TKIP:
1691*4882a593Smuzhiyun 			pval = TKIP_ENABLED;
1692*4882a593Smuzhiyun 			break;
1693*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_CCMP:
1694*4882a593Smuzhiyun 			pval = AES_ENABLED;
1695*4882a593Smuzhiyun 			break;
1696*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_AES_CMAC:
1697*4882a593Smuzhiyun 			pval = AES_ENABLED;
1698*4882a593Smuzhiyun 			break;
1699*4882a593Smuzhiyun 		default:
1700*4882a593Smuzhiyun 			bphy_err(drvr, "invalid cipher pairwise (%d)\n",
1701*4882a593Smuzhiyun 				 sme->crypto.ciphers_pairwise[0]);
1702*4882a593Smuzhiyun 			return -EINVAL;
1703*4882a593Smuzhiyun 		}
1704*4882a593Smuzhiyun 	}
1705*4882a593Smuzhiyun 	if (sme->crypto.cipher_group) {
1706*4882a593Smuzhiyun 		switch (sme->crypto.cipher_group) {
1707*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_WEP40:
1708*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_WEP104:
1709*4882a593Smuzhiyun 			gval = WEP_ENABLED;
1710*4882a593Smuzhiyun 			break;
1711*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_TKIP:
1712*4882a593Smuzhiyun 			gval = TKIP_ENABLED;
1713*4882a593Smuzhiyun 			break;
1714*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_CCMP:
1715*4882a593Smuzhiyun 			gval = AES_ENABLED;
1716*4882a593Smuzhiyun 			break;
1717*4882a593Smuzhiyun 		case WLAN_CIPHER_SUITE_AES_CMAC:
1718*4882a593Smuzhiyun 			gval = AES_ENABLED;
1719*4882a593Smuzhiyun 			break;
1720*4882a593Smuzhiyun 		default:
1721*4882a593Smuzhiyun 			bphy_err(drvr, "invalid cipher group (%d)\n",
1722*4882a593Smuzhiyun 				 sme->crypto.cipher_group);
1723*4882a593Smuzhiyun 			return -EINVAL;
1724*4882a593Smuzhiyun 		}
1725*4882a593Smuzhiyun 	}
1726*4882a593Smuzhiyun 
1727*4882a593Smuzhiyun 	brcmf_dbg(CONN, "pval (%d) gval (%d)\n", pval, gval);
1728*4882a593Smuzhiyun 	/* In case of privacy, but no security and WPS then simulate */
1729*4882a593Smuzhiyun 	/* setting AES. WPS-2.0 allows no security                   */
1730*4882a593Smuzhiyun 	if (brcmf_find_wpsie(sme->ie, sme->ie_len) && !pval && !gval &&
1731*4882a593Smuzhiyun 	    sme->privacy)
1732*4882a593Smuzhiyun 		pval = AES_ENABLED;
1733*4882a593Smuzhiyun 
1734*4882a593Smuzhiyun 	wsec = pval | gval;
1735*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "wsec", wsec);
1736*4882a593Smuzhiyun 	if (err) {
1737*4882a593Smuzhiyun 		bphy_err(drvr, "error (%d)\n", err);
1738*4882a593Smuzhiyun 		return err;
1739*4882a593Smuzhiyun 	}
1740*4882a593Smuzhiyun 
1741*4882a593Smuzhiyun 	sec = &profile->sec;
1742*4882a593Smuzhiyun 	sec->cipher_pairwise = sme->crypto.ciphers_pairwise[0];
1743*4882a593Smuzhiyun 	sec->cipher_group = sme->crypto.cipher_group;
1744*4882a593Smuzhiyun 
1745*4882a593Smuzhiyun 	return err;
1746*4882a593Smuzhiyun }
1747*4882a593Smuzhiyun 
1748*4882a593Smuzhiyun static s32
brcmf_set_key_mgmt(struct net_device * ndev,struct cfg80211_connect_params * sme)1749*4882a593Smuzhiyun brcmf_set_key_mgmt(struct net_device *ndev, struct cfg80211_connect_params *sme)
1750*4882a593Smuzhiyun {
1751*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1752*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
1753*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1754*4882a593Smuzhiyun 	s32 val;
1755*4882a593Smuzhiyun 	s32 err;
1756*4882a593Smuzhiyun 	const struct brcmf_tlv *rsn_ie;
1757*4882a593Smuzhiyun 	const u8 *ie;
1758*4882a593Smuzhiyun 	u32 ie_len;
1759*4882a593Smuzhiyun 	u32 offset;
1760*4882a593Smuzhiyun 	u16 rsn_cap;
1761*4882a593Smuzhiyun 	u32 mfp;
1762*4882a593Smuzhiyun 	u16 count;
1763*4882a593Smuzhiyun 
1764*4882a593Smuzhiyun 	profile->use_fwsup = BRCMF_PROFILE_FWSUP_NONE;
1765*4882a593Smuzhiyun 	profile->is_ft = false;
1766*4882a593Smuzhiyun 
1767*4882a593Smuzhiyun 	if (!sme->crypto.n_akm_suites)
1768*4882a593Smuzhiyun 		return 0;
1769*4882a593Smuzhiyun 
1770*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_get(netdev_priv(ndev), "wpa_auth", &val);
1771*4882a593Smuzhiyun 	if (err) {
1772*4882a593Smuzhiyun 		bphy_err(drvr, "could not get wpa_auth (%d)\n", err);
1773*4882a593Smuzhiyun 		return err;
1774*4882a593Smuzhiyun 	}
1775*4882a593Smuzhiyun 	if (val & (WPA_AUTH_PSK | WPA_AUTH_UNSPECIFIED)) {
1776*4882a593Smuzhiyun 		switch (sme->crypto.akm_suites[0]) {
1777*4882a593Smuzhiyun 		case WLAN_AKM_SUITE_8021X:
1778*4882a593Smuzhiyun 			val = WPA_AUTH_UNSPECIFIED;
1779*4882a593Smuzhiyun 			if (sme->want_1x)
1780*4882a593Smuzhiyun 				profile->use_fwsup = BRCMF_PROFILE_FWSUP_1X;
1781*4882a593Smuzhiyun 			break;
1782*4882a593Smuzhiyun 		case WLAN_AKM_SUITE_PSK:
1783*4882a593Smuzhiyun 			val = WPA_AUTH_PSK;
1784*4882a593Smuzhiyun 			break;
1785*4882a593Smuzhiyun 		default:
1786*4882a593Smuzhiyun 			bphy_err(drvr, "invalid cipher group (%d)\n",
1787*4882a593Smuzhiyun 				 sme->crypto.cipher_group);
1788*4882a593Smuzhiyun 			return -EINVAL;
1789*4882a593Smuzhiyun 		}
1790*4882a593Smuzhiyun 	} else if (val & (WPA2_AUTH_PSK | WPA2_AUTH_UNSPECIFIED)) {
1791*4882a593Smuzhiyun 		switch (sme->crypto.akm_suites[0]) {
1792*4882a593Smuzhiyun 		case WLAN_AKM_SUITE_8021X:
1793*4882a593Smuzhiyun 			val = WPA2_AUTH_UNSPECIFIED;
1794*4882a593Smuzhiyun 			if (sme->want_1x)
1795*4882a593Smuzhiyun 				profile->use_fwsup = BRCMF_PROFILE_FWSUP_1X;
1796*4882a593Smuzhiyun 			break;
1797*4882a593Smuzhiyun 		case WLAN_AKM_SUITE_8021X_SHA256:
1798*4882a593Smuzhiyun 			val = WPA2_AUTH_1X_SHA256;
1799*4882a593Smuzhiyun 			if (sme->want_1x)
1800*4882a593Smuzhiyun 				profile->use_fwsup = BRCMF_PROFILE_FWSUP_1X;
1801*4882a593Smuzhiyun 			break;
1802*4882a593Smuzhiyun 		case WLAN_AKM_SUITE_PSK_SHA256:
1803*4882a593Smuzhiyun 			val = WPA2_AUTH_PSK_SHA256;
1804*4882a593Smuzhiyun 			break;
1805*4882a593Smuzhiyun 		case WLAN_AKM_SUITE_PSK:
1806*4882a593Smuzhiyun 			val = WPA2_AUTH_PSK;
1807*4882a593Smuzhiyun 			break;
1808*4882a593Smuzhiyun 		case WLAN_AKM_SUITE_FT_8021X:
1809*4882a593Smuzhiyun 			val = WPA2_AUTH_UNSPECIFIED | WPA2_AUTH_FT;
1810*4882a593Smuzhiyun 			profile->is_ft = true;
1811*4882a593Smuzhiyun 			if (sme->want_1x)
1812*4882a593Smuzhiyun 				profile->use_fwsup = BRCMF_PROFILE_FWSUP_1X;
1813*4882a593Smuzhiyun 			break;
1814*4882a593Smuzhiyun 		case WLAN_AKM_SUITE_FT_PSK:
1815*4882a593Smuzhiyun 			val = WPA2_AUTH_PSK | WPA2_AUTH_FT;
1816*4882a593Smuzhiyun 			profile->is_ft = true;
1817*4882a593Smuzhiyun 			break;
1818*4882a593Smuzhiyun 		default:
1819*4882a593Smuzhiyun 			bphy_err(drvr, "invalid cipher group (%d)\n",
1820*4882a593Smuzhiyun 				 sme->crypto.cipher_group);
1821*4882a593Smuzhiyun 			return -EINVAL;
1822*4882a593Smuzhiyun 		}
1823*4882a593Smuzhiyun 	} else if (val & WPA3_AUTH_SAE_PSK) {
1824*4882a593Smuzhiyun 		switch (sme->crypto.akm_suites[0]) {
1825*4882a593Smuzhiyun 		case WLAN_AKM_SUITE_SAE:
1826*4882a593Smuzhiyun 			val = WPA3_AUTH_SAE_PSK;
1827*4882a593Smuzhiyun 			if (sme->crypto.sae_pwd) {
1828*4882a593Smuzhiyun 				brcmf_dbg(INFO, "using SAE offload\n");
1829*4882a593Smuzhiyun 				profile->use_fwsup = BRCMF_PROFILE_FWSUP_SAE;
1830*4882a593Smuzhiyun 			}
1831*4882a593Smuzhiyun 			break;
1832*4882a593Smuzhiyun 		default:
1833*4882a593Smuzhiyun 			bphy_err(drvr, "invalid cipher group (%d)\n",
1834*4882a593Smuzhiyun 				 sme->crypto.cipher_group);
1835*4882a593Smuzhiyun 			return -EINVAL;
1836*4882a593Smuzhiyun 		}
1837*4882a593Smuzhiyun 	}
1838*4882a593Smuzhiyun 
1839*4882a593Smuzhiyun 	if (profile->use_fwsup == BRCMF_PROFILE_FWSUP_1X)
1840*4882a593Smuzhiyun 		brcmf_dbg(INFO, "using 1X offload\n");
1841*4882a593Smuzhiyun 
1842*4882a593Smuzhiyun 	if (!brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MFP))
1843*4882a593Smuzhiyun 		goto skip_mfp_config;
1844*4882a593Smuzhiyun 	/* The MFP mode (1 or 2) needs to be determined, parse IEs. The
1845*4882a593Smuzhiyun 	 * IE will not be verified, just a quick search for MFP config
1846*4882a593Smuzhiyun 	 */
1847*4882a593Smuzhiyun 	rsn_ie = brcmf_parse_tlvs((const u8 *)sme->ie, sme->ie_len,
1848*4882a593Smuzhiyun 				  WLAN_EID_RSN);
1849*4882a593Smuzhiyun 	if (!rsn_ie)
1850*4882a593Smuzhiyun 		goto skip_mfp_config;
1851*4882a593Smuzhiyun 	ie = (const u8 *)rsn_ie;
1852*4882a593Smuzhiyun 	ie_len = rsn_ie->len + TLV_HDR_LEN;
1853*4882a593Smuzhiyun 	/* Skip unicast suite */
1854*4882a593Smuzhiyun 	offset = TLV_HDR_LEN + WPA_IE_VERSION_LEN + WPA_IE_MIN_OUI_LEN;
1855*4882a593Smuzhiyun 	if (offset + WPA_IE_SUITE_COUNT_LEN >= ie_len)
1856*4882a593Smuzhiyun 		goto skip_mfp_config;
1857*4882a593Smuzhiyun 	/* Skip multicast suite */
1858*4882a593Smuzhiyun 	count = ie[offset] + (ie[offset + 1] << 8);
1859*4882a593Smuzhiyun 	offset += WPA_IE_SUITE_COUNT_LEN + (count * WPA_IE_MIN_OUI_LEN);
1860*4882a593Smuzhiyun 	if (offset + WPA_IE_SUITE_COUNT_LEN >= ie_len)
1861*4882a593Smuzhiyun 		goto skip_mfp_config;
1862*4882a593Smuzhiyun 	/* Skip auth key management suite(s) */
1863*4882a593Smuzhiyun 	count = ie[offset] + (ie[offset + 1] << 8);
1864*4882a593Smuzhiyun 	offset += WPA_IE_SUITE_COUNT_LEN + (count * WPA_IE_MIN_OUI_LEN);
1865*4882a593Smuzhiyun 	if (offset + WPA_IE_SUITE_COUNT_LEN > ie_len)
1866*4882a593Smuzhiyun 		goto skip_mfp_config;
1867*4882a593Smuzhiyun 	/* Ready to read capabilities */
1868*4882a593Smuzhiyun 	mfp = BRCMF_MFP_NONE;
1869*4882a593Smuzhiyun 	rsn_cap = ie[offset] + (ie[offset + 1] << 8);
1870*4882a593Smuzhiyun 	if (rsn_cap & RSN_CAP_MFPR_MASK)
1871*4882a593Smuzhiyun 		mfp = BRCMF_MFP_REQUIRED;
1872*4882a593Smuzhiyun 	else if (rsn_cap & RSN_CAP_MFPC_MASK)
1873*4882a593Smuzhiyun 		mfp = BRCMF_MFP_CAPABLE;
1874*4882a593Smuzhiyun 	brcmf_fil_bsscfg_int_set(netdev_priv(ndev), "mfp", mfp);
1875*4882a593Smuzhiyun 
1876*4882a593Smuzhiyun skip_mfp_config:
1877*4882a593Smuzhiyun 	brcmf_dbg(CONN, "setting wpa_auth to %d\n", val);
1878*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(netdev_priv(ndev), "wpa_auth", val);
1879*4882a593Smuzhiyun 	if (err) {
1880*4882a593Smuzhiyun 		bphy_err(drvr, "could not set wpa_auth (%d)\n", err);
1881*4882a593Smuzhiyun 		return err;
1882*4882a593Smuzhiyun 	}
1883*4882a593Smuzhiyun 
1884*4882a593Smuzhiyun 	return err;
1885*4882a593Smuzhiyun }
1886*4882a593Smuzhiyun 
1887*4882a593Smuzhiyun static s32
brcmf_set_sharedkey(struct net_device * ndev,struct cfg80211_connect_params * sme)1888*4882a593Smuzhiyun brcmf_set_sharedkey(struct net_device *ndev,
1889*4882a593Smuzhiyun 		    struct cfg80211_connect_params *sme)
1890*4882a593Smuzhiyun {
1891*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
1892*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1893*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = ndev_to_prof(ndev);
1894*4882a593Smuzhiyun 	struct brcmf_cfg80211_security *sec;
1895*4882a593Smuzhiyun 	struct brcmf_wsec_key key;
1896*4882a593Smuzhiyun 	s32 val;
1897*4882a593Smuzhiyun 	s32 err = 0;
1898*4882a593Smuzhiyun 
1899*4882a593Smuzhiyun 	brcmf_dbg(CONN, "key len (%d)\n", sme->key_len);
1900*4882a593Smuzhiyun 
1901*4882a593Smuzhiyun 	if (sme->key_len == 0)
1902*4882a593Smuzhiyun 		return 0;
1903*4882a593Smuzhiyun 
1904*4882a593Smuzhiyun 	sec = &profile->sec;
1905*4882a593Smuzhiyun 	brcmf_dbg(CONN, "wpa_versions 0x%x cipher_pairwise 0x%x\n",
1906*4882a593Smuzhiyun 		  sec->wpa_versions, sec->cipher_pairwise);
1907*4882a593Smuzhiyun 
1908*4882a593Smuzhiyun 	if (sec->wpa_versions & (NL80211_WPA_VERSION_1 | NL80211_WPA_VERSION_2 |
1909*4882a593Smuzhiyun 				 NL80211_WPA_VERSION_3))
1910*4882a593Smuzhiyun 		return 0;
1911*4882a593Smuzhiyun 
1912*4882a593Smuzhiyun 	if (!(sec->cipher_pairwise &
1913*4882a593Smuzhiyun 	    (WLAN_CIPHER_SUITE_WEP40 | WLAN_CIPHER_SUITE_WEP104)))
1914*4882a593Smuzhiyun 		return 0;
1915*4882a593Smuzhiyun 
1916*4882a593Smuzhiyun 	memset(&key, 0, sizeof(key));
1917*4882a593Smuzhiyun 	key.len = (u32) sme->key_len;
1918*4882a593Smuzhiyun 	key.index = (u32) sme->key_idx;
1919*4882a593Smuzhiyun 	if (key.len > sizeof(key.data)) {
1920*4882a593Smuzhiyun 		bphy_err(drvr, "Too long key length (%u)\n", key.len);
1921*4882a593Smuzhiyun 		return -EINVAL;
1922*4882a593Smuzhiyun 	}
1923*4882a593Smuzhiyun 	memcpy(key.data, sme->key, key.len);
1924*4882a593Smuzhiyun 	key.flags = BRCMF_PRIMARY_KEY;
1925*4882a593Smuzhiyun 	switch (sec->cipher_pairwise) {
1926*4882a593Smuzhiyun 	case WLAN_CIPHER_SUITE_WEP40:
1927*4882a593Smuzhiyun 		key.algo = CRYPTO_ALGO_WEP1;
1928*4882a593Smuzhiyun 		break;
1929*4882a593Smuzhiyun 	case WLAN_CIPHER_SUITE_WEP104:
1930*4882a593Smuzhiyun 		key.algo = CRYPTO_ALGO_WEP128;
1931*4882a593Smuzhiyun 		break;
1932*4882a593Smuzhiyun 	default:
1933*4882a593Smuzhiyun 		bphy_err(drvr, "Invalid algorithm (%d)\n",
1934*4882a593Smuzhiyun 			 sme->crypto.ciphers_pairwise[0]);
1935*4882a593Smuzhiyun 		return -EINVAL;
1936*4882a593Smuzhiyun 	}
1937*4882a593Smuzhiyun 	/* Set the new key/index */
1938*4882a593Smuzhiyun 	brcmf_dbg(CONN, "key length (%d) key index (%d) algo (%d)\n",
1939*4882a593Smuzhiyun 		  key.len, key.index, key.algo);
1940*4882a593Smuzhiyun 	brcmf_dbg(CONN, "key \"%s\"\n", key.data);
1941*4882a593Smuzhiyun 	err = send_key_to_dongle(ifp, &key);
1942*4882a593Smuzhiyun 	if (err)
1943*4882a593Smuzhiyun 		return err;
1944*4882a593Smuzhiyun 
1945*4882a593Smuzhiyun 	if (sec->auth_type == NL80211_AUTHTYPE_SHARED_KEY) {
1946*4882a593Smuzhiyun 		brcmf_dbg(CONN, "set auth_type to shared key\n");
1947*4882a593Smuzhiyun 		val = WL_AUTH_SHARED_KEY;	/* shared key */
1948*4882a593Smuzhiyun 		err = brcmf_fil_bsscfg_int_set(ifp, "auth", val);
1949*4882a593Smuzhiyun 		if (err)
1950*4882a593Smuzhiyun 			bphy_err(drvr, "set auth failed (%d)\n", err);
1951*4882a593Smuzhiyun 	}
1952*4882a593Smuzhiyun 	return err;
1953*4882a593Smuzhiyun }
1954*4882a593Smuzhiyun 
1955*4882a593Smuzhiyun static
brcmf_war_auth_type(struct brcmf_if * ifp,enum nl80211_auth_type type)1956*4882a593Smuzhiyun enum nl80211_auth_type brcmf_war_auth_type(struct brcmf_if *ifp,
1957*4882a593Smuzhiyun 					   enum nl80211_auth_type type)
1958*4882a593Smuzhiyun {
1959*4882a593Smuzhiyun 	if (type == NL80211_AUTHTYPE_AUTOMATIC &&
1960*4882a593Smuzhiyun 	    brcmf_feat_is_quirk_enabled(ifp, BRCMF_FEAT_QUIRK_AUTO_AUTH)) {
1961*4882a593Smuzhiyun 		brcmf_dbg(CONN, "WAR: use OPEN instead of AUTO\n");
1962*4882a593Smuzhiyun 		type = NL80211_AUTHTYPE_OPEN_SYSTEM;
1963*4882a593Smuzhiyun 	}
1964*4882a593Smuzhiyun 	return type;
1965*4882a593Smuzhiyun }
1966*4882a593Smuzhiyun 
brcmf_set_join_pref(struct brcmf_if * ifp,struct cfg80211_bss_selection * bss_select)1967*4882a593Smuzhiyun static void brcmf_set_join_pref(struct brcmf_if *ifp,
1968*4882a593Smuzhiyun 				struct cfg80211_bss_selection *bss_select)
1969*4882a593Smuzhiyun {
1970*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
1971*4882a593Smuzhiyun 	struct brcmf_join_pref_params join_pref_params[2];
1972*4882a593Smuzhiyun 	enum nl80211_band band;
1973*4882a593Smuzhiyun 	int err, i = 0;
1974*4882a593Smuzhiyun 
1975*4882a593Smuzhiyun 	join_pref_params[i].len = 2;
1976*4882a593Smuzhiyun 	join_pref_params[i].rssi_gain = 0;
1977*4882a593Smuzhiyun 
1978*4882a593Smuzhiyun 	if (bss_select->behaviour != NL80211_BSS_SELECT_ATTR_BAND_PREF)
1979*4882a593Smuzhiyun 		brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_ASSOC_PREFER, WLC_BAND_AUTO);
1980*4882a593Smuzhiyun 
1981*4882a593Smuzhiyun 	switch (bss_select->behaviour) {
1982*4882a593Smuzhiyun 	case __NL80211_BSS_SELECT_ATTR_INVALID:
1983*4882a593Smuzhiyun 		brcmf_c_set_joinpref_default(ifp);
1984*4882a593Smuzhiyun 		return;
1985*4882a593Smuzhiyun 	case NL80211_BSS_SELECT_ATTR_BAND_PREF:
1986*4882a593Smuzhiyun 		join_pref_params[i].type = BRCMF_JOIN_PREF_BAND;
1987*4882a593Smuzhiyun 		band = bss_select->param.band_pref;
1988*4882a593Smuzhiyun 		join_pref_params[i].band = nl80211_band_to_fwil(band);
1989*4882a593Smuzhiyun 		i++;
1990*4882a593Smuzhiyun 		break;
1991*4882a593Smuzhiyun 	case NL80211_BSS_SELECT_ATTR_RSSI_ADJUST:
1992*4882a593Smuzhiyun 		join_pref_params[i].type = BRCMF_JOIN_PREF_RSSI_DELTA;
1993*4882a593Smuzhiyun 		band = bss_select->param.adjust.band;
1994*4882a593Smuzhiyun 		join_pref_params[i].band = nl80211_band_to_fwil(band);
1995*4882a593Smuzhiyun 		join_pref_params[i].rssi_gain = bss_select->param.adjust.delta;
1996*4882a593Smuzhiyun 		i++;
1997*4882a593Smuzhiyun 		break;
1998*4882a593Smuzhiyun 	case NL80211_BSS_SELECT_ATTR_RSSI:
1999*4882a593Smuzhiyun 	default:
2000*4882a593Smuzhiyun 		break;
2001*4882a593Smuzhiyun 	}
2002*4882a593Smuzhiyun 	join_pref_params[i].type = BRCMF_JOIN_PREF_RSSI;
2003*4882a593Smuzhiyun 	join_pref_params[i].len = 2;
2004*4882a593Smuzhiyun 	join_pref_params[i].rssi_gain = 0;
2005*4882a593Smuzhiyun 	join_pref_params[i].band = 0;
2006*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_set(ifp, "join_pref", join_pref_params,
2007*4882a593Smuzhiyun 				       sizeof(join_pref_params));
2008*4882a593Smuzhiyun 	if (err)
2009*4882a593Smuzhiyun 		bphy_err(drvr, "Set join_pref error (%d)\n", err);
2010*4882a593Smuzhiyun }
2011*4882a593Smuzhiyun 
2012*4882a593Smuzhiyun static s32
brcmf_cfg80211_connect(struct wiphy * wiphy,struct net_device * ndev,struct cfg80211_connect_params * sme)2013*4882a593Smuzhiyun brcmf_cfg80211_connect(struct wiphy *wiphy, struct net_device *ndev,
2014*4882a593Smuzhiyun 		       struct cfg80211_connect_params *sme)
2015*4882a593Smuzhiyun {
2016*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
2017*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2018*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
2019*4882a593Smuzhiyun 	struct ieee80211_channel *chan = sme->channel;
2020*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
2021*4882a593Smuzhiyun 	struct brcmf_join_params join_params;
2022*4882a593Smuzhiyun 	size_t join_params_size;
2023*4882a593Smuzhiyun 	const struct brcmf_tlv *rsn_ie;
2024*4882a593Smuzhiyun 	const struct brcmf_vs_tlv *wpa_ie;
2025*4882a593Smuzhiyun 	const void *ie;
2026*4882a593Smuzhiyun 	u32 ie_len;
2027*4882a593Smuzhiyun 	struct brcmf_ext_join_params_le *ext_join_params;
2028*4882a593Smuzhiyun 	u16 chanspec;
2029*4882a593Smuzhiyun 	s32 err = 0;
2030*4882a593Smuzhiyun 	u32 ssid_len;
2031*4882a593Smuzhiyun 
2032*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
2033*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
2034*4882a593Smuzhiyun 		return -EIO;
2035*4882a593Smuzhiyun 
2036*4882a593Smuzhiyun 	if (!sme->ssid) {
2037*4882a593Smuzhiyun 		bphy_err(drvr, "Invalid ssid\n");
2038*4882a593Smuzhiyun 		return -EOPNOTSUPP;
2039*4882a593Smuzhiyun 	}
2040*4882a593Smuzhiyun 
2041*4882a593Smuzhiyun 	if (ifp->vif == cfg->p2p.bss_idx[P2PAPI_BSSCFG_PRIMARY].vif) {
2042*4882a593Smuzhiyun 		/* A normal (non P2P) connection request setup. */
2043*4882a593Smuzhiyun 		ie = NULL;
2044*4882a593Smuzhiyun 		ie_len = 0;
2045*4882a593Smuzhiyun 		/* find the WPA_IE */
2046*4882a593Smuzhiyun 		wpa_ie = brcmf_find_wpaie((u8 *)sme->ie, sme->ie_len);
2047*4882a593Smuzhiyun 		if (wpa_ie) {
2048*4882a593Smuzhiyun 			ie = wpa_ie;
2049*4882a593Smuzhiyun 			ie_len = wpa_ie->len + TLV_HDR_LEN;
2050*4882a593Smuzhiyun 		} else {
2051*4882a593Smuzhiyun 			/* find the RSN_IE */
2052*4882a593Smuzhiyun 			rsn_ie = brcmf_parse_tlvs((const u8 *)sme->ie,
2053*4882a593Smuzhiyun 						  sme->ie_len,
2054*4882a593Smuzhiyun 						  WLAN_EID_RSN);
2055*4882a593Smuzhiyun 			if (rsn_ie) {
2056*4882a593Smuzhiyun 				ie = rsn_ie;
2057*4882a593Smuzhiyun 				ie_len = rsn_ie->len + TLV_HDR_LEN;
2058*4882a593Smuzhiyun 			}
2059*4882a593Smuzhiyun 		}
2060*4882a593Smuzhiyun 		brcmf_fil_iovar_data_set(ifp, "wpaie", ie, ie_len);
2061*4882a593Smuzhiyun 	}
2062*4882a593Smuzhiyun 
2063*4882a593Smuzhiyun 	err = brcmf_vif_set_mgmt_ie(ifp->vif, BRCMF_VNDR_IE_ASSOCREQ_FLAG,
2064*4882a593Smuzhiyun 				    sme->ie, sme->ie_len);
2065*4882a593Smuzhiyun 	if (err)
2066*4882a593Smuzhiyun 		bphy_err(drvr, "Set Assoc REQ IE Failed\n");
2067*4882a593Smuzhiyun 	else
2068*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "Applied Vndr IEs for Assoc request\n");
2069*4882a593Smuzhiyun 
2070*4882a593Smuzhiyun 	set_bit(BRCMF_VIF_STATUS_CONNECTING, &ifp->vif->sme_state);
2071*4882a593Smuzhiyun 
2072*4882a593Smuzhiyun 	if (chan) {
2073*4882a593Smuzhiyun 		cfg->channel =
2074*4882a593Smuzhiyun 			ieee80211_frequency_to_channel(chan->center_freq);
2075*4882a593Smuzhiyun 		chanspec = channel_to_chanspec(&cfg->d11inf, chan);
2076*4882a593Smuzhiyun 		brcmf_dbg(CONN, "channel=%d, center_req=%d, chanspec=0x%04x\n",
2077*4882a593Smuzhiyun 			  cfg->channel, chan->center_freq, chanspec);
2078*4882a593Smuzhiyun 	} else {
2079*4882a593Smuzhiyun 		cfg->channel = 0;
2080*4882a593Smuzhiyun 		chanspec = 0;
2081*4882a593Smuzhiyun 	}
2082*4882a593Smuzhiyun 
2083*4882a593Smuzhiyun 	brcmf_dbg(INFO, "ie (%p), ie_len (%zd)\n", sme->ie, sme->ie_len);
2084*4882a593Smuzhiyun 
2085*4882a593Smuzhiyun 	err = brcmf_set_wpa_version(ndev, sme);
2086*4882a593Smuzhiyun 	if (err) {
2087*4882a593Smuzhiyun 		bphy_err(drvr, "wl_set_wpa_version failed (%d)\n", err);
2088*4882a593Smuzhiyun 		goto done;
2089*4882a593Smuzhiyun 	}
2090*4882a593Smuzhiyun 
2091*4882a593Smuzhiyun 	sme->auth_type = brcmf_war_auth_type(ifp, sme->auth_type);
2092*4882a593Smuzhiyun 	err = brcmf_set_auth_type(ndev, sme);
2093*4882a593Smuzhiyun 	if (err) {
2094*4882a593Smuzhiyun 		bphy_err(drvr, "wl_set_auth_type failed (%d)\n", err);
2095*4882a593Smuzhiyun 		goto done;
2096*4882a593Smuzhiyun 	}
2097*4882a593Smuzhiyun 
2098*4882a593Smuzhiyun 	err = brcmf_set_wsec_mode(ndev, sme);
2099*4882a593Smuzhiyun 	if (err) {
2100*4882a593Smuzhiyun 		bphy_err(drvr, "wl_set_set_cipher failed (%d)\n", err);
2101*4882a593Smuzhiyun 		goto done;
2102*4882a593Smuzhiyun 	}
2103*4882a593Smuzhiyun 
2104*4882a593Smuzhiyun 	err = brcmf_set_key_mgmt(ndev, sme);
2105*4882a593Smuzhiyun 	if (err) {
2106*4882a593Smuzhiyun 		bphy_err(drvr, "wl_set_key_mgmt failed (%d)\n", err);
2107*4882a593Smuzhiyun 		goto done;
2108*4882a593Smuzhiyun 	}
2109*4882a593Smuzhiyun 
2110*4882a593Smuzhiyun 	err = brcmf_set_sharedkey(ndev, sme);
2111*4882a593Smuzhiyun 	if (err) {
2112*4882a593Smuzhiyun 		bphy_err(drvr, "brcmf_set_sharedkey failed (%d)\n", err);
2113*4882a593Smuzhiyun 		goto done;
2114*4882a593Smuzhiyun 	}
2115*4882a593Smuzhiyun 
2116*4882a593Smuzhiyun 	if (sme->crypto.psk &&
2117*4882a593Smuzhiyun 	    profile->use_fwsup != BRCMF_PROFILE_FWSUP_SAE) {
2118*4882a593Smuzhiyun 		if (WARN_ON(profile->use_fwsup != BRCMF_PROFILE_FWSUP_NONE)) {
2119*4882a593Smuzhiyun 			err = -EINVAL;
2120*4882a593Smuzhiyun 			goto done;
2121*4882a593Smuzhiyun 		}
2122*4882a593Smuzhiyun 		brcmf_dbg(INFO, "using PSK offload\n");
2123*4882a593Smuzhiyun 		profile->use_fwsup = BRCMF_PROFILE_FWSUP_PSK;
2124*4882a593Smuzhiyun 	}
2125*4882a593Smuzhiyun 
2126*4882a593Smuzhiyun 	if (profile->use_fwsup != BRCMF_PROFILE_FWSUP_NONE) {
2127*4882a593Smuzhiyun 		/* enable firmware supplicant for this interface */
2128*4882a593Smuzhiyun 		err = brcmf_fil_iovar_int_set(ifp, "sup_wpa", 1);
2129*4882a593Smuzhiyun 		if (err < 0) {
2130*4882a593Smuzhiyun 			bphy_err(drvr, "failed to enable fw supplicant\n");
2131*4882a593Smuzhiyun 			goto done;
2132*4882a593Smuzhiyun 		}
2133*4882a593Smuzhiyun 	}
2134*4882a593Smuzhiyun 
2135*4882a593Smuzhiyun 	if (profile->use_fwsup == BRCMF_PROFILE_FWSUP_PSK)
2136*4882a593Smuzhiyun 		err = brcmf_set_pmk(ifp, sme->crypto.psk,
2137*4882a593Smuzhiyun 				    BRCMF_WSEC_MAX_PSK_LEN);
2138*4882a593Smuzhiyun 	else if (profile->use_fwsup == BRCMF_PROFILE_FWSUP_SAE) {
2139*4882a593Smuzhiyun 		/* clean up user-space RSNE */
2140*4882a593Smuzhiyun 		err = brcmf_fil_iovar_data_set(ifp, "wpaie", NULL, 0);
2141*4882a593Smuzhiyun 		if (err) {
2142*4882a593Smuzhiyun 			bphy_err(drvr, "failed to clean up user-space RSNE\n");
2143*4882a593Smuzhiyun 			goto done;
2144*4882a593Smuzhiyun 		}
2145*4882a593Smuzhiyun 		err = brcmf_set_sae_password(ifp, sme->crypto.sae_pwd,
2146*4882a593Smuzhiyun 					     sme->crypto.sae_pwd_len);
2147*4882a593Smuzhiyun 		if (!err && sme->crypto.psk)
2148*4882a593Smuzhiyun 			err = brcmf_set_pmk(ifp, sme->crypto.psk,
2149*4882a593Smuzhiyun 					    BRCMF_WSEC_MAX_PSK_LEN);
2150*4882a593Smuzhiyun 	}
2151*4882a593Smuzhiyun 	if (err)
2152*4882a593Smuzhiyun 		goto done;
2153*4882a593Smuzhiyun 
2154*4882a593Smuzhiyun 	/* Join with specific BSSID and cached SSID
2155*4882a593Smuzhiyun 	 * If SSID is zero join based on BSSID only
2156*4882a593Smuzhiyun 	 */
2157*4882a593Smuzhiyun 	join_params_size = offsetof(struct brcmf_ext_join_params_le, assoc_le) +
2158*4882a593Smuzhiyun 		offsetof(struct brcmf_assoc_params_le, chanspec_list);
2159*4882a593Smuzhiyun 	if (cfg->channel)
2160*4882a593Smuzhiyun 		join_params_size += sizeof(u16);
2161*4882a593Smuzhiyun 	ext_join_params = kzalloc(join_params_size, GFP_KERNEL);
2162*4882a593Smuzhiyun 	if (ext_join_params == NULL) {
2163*4882a593Smuzhiyun 		err = -ENOMEM;
2164*4882a593Smuzhiyun 		goto done;
2165*4882a593Smuzhiyun 	}
2166*4882a593Smuzhiyun 	ssid_len = min_t(u32, sme->ssid_len, IEEE80211_MAX_SSID_LEN);
2167*4882a593Smuzhiyun 	ext_join_params->ssid_le.SSID_len = cpu_to_le32(ssid_len);
2168*4882a593Smuzhiyun 	memcpy(&ext_join_params->ssid_le.SSID, sme->ssid, ssid_len);
2169*4882a593Smuzhiyun 	if (ssid_len < IEEE80211_MAX_SSID_LEN)
2170*4882a593Smuzhiyun 		brcmf_dbg(CONN, "SSID \"%s\", len (%d)\n",
2171*4882a593Smuzhiyun 			  ext_join_params->ssid_le.SSID, ssid_len);
2172*4882a593Smuzhiyun 
2173*4882a593Smuzhiyun 	/* Set up join scan parameters */
2174*4882a593Smuzhiyun 	ext_join_params->scan_le.scan_type = -1;
2175*4882a593Smuzhiyun 	ext_join_params->scan_le.home_time = cpu_to_le32(-1);
2176*4882a593Smuzhiyun 
2177*4882a593Smuzhiyun 	if (sme->bssid)
2178*4882a593Smuzhiyun 		memcpy(&ext_join_params->assoc_le.bssid, sme->bssid, ETH_ALEN);
2179*4882a593Smuzhiyun 	else
2180*4882a593Smuzhiyun 		eth_broadcast_addr(ext_join_params->assoc_le.bssid);
2181*4882a593Smuzhiyun 
2182*4882a593Smuzhiyun 	if (cfg->channel) {
2183*4882a593Smuzhiyun 		ext_join_params->assoc_le.chanspec_num = cpu_to_le32(1);
2184*4882a593Smuzhiyun 
2185*4882a593Smuzhiyun 		ext_join_params->assoc_le.chanspec_list[0] =
2186*4882a593Smuzhiyun 			cpu_to_le16(chanspec);
2187*4882a593Smuzhiyun 		/* Increase dwell time to receive probe response or detect
2188*4882a593Smuzhiyun 		 * beacon from target AP at a noisy air only during connect
2189*4882a593Smuzhiyun 		 * command.
2190*4882a593Smuzhiyun 		 */
2191*4882a593Smuzhiyun 		ext_join_params->scan_le.active_time =
2192*4882a593Smuzhiyun 			cpu_to_le32(BRCMF_SCAN_JOIN_ACTIVE_DWELL_TIME_MS);
2193*4882a593Smuzhiyun 		ext_join_params->scan_le.passive_time =
2194*4882a593Smuzhiyun 			cpu_to_le32(BRCMF_SCAN_JOIN_PASSIVE_DWELL_TIME_MS);
2195*4882a593Smuzhiyun 		/* To sync with presence period of VSDB GO send probe request
2196*4882a593Smuzhiyun 		 * more frequently. Probe request will be stopped when it gets
2197*4882a593Smuzhiyun 		 * probe response from target AP/GO.
2198*4882a593Smuzhiyun 		 */
2199*4882a593Smuzhiyun 		ext_join_params->scan_le.nprobes =
2200*4882a593Smuzhiyun 			cpu_to_le32(BRCMF_SCAN_JOIN_ACTIVE_DWELL_TIME_MS /
2201*4882a593Smuzhiyun 				    BRCMF_SCAN_JOIN_PROBE_INTERVAL_MS);
2202*4882a593Smuzhiyun 	} else {
2203*4882a593Smuzhiyun 		ext_join_params->scan_le.active_time = cpu_to_le32(-1);
2204*4882a593Smuzhiyun 		ext_join_params->scan_le.passive_time = cpu_to_le32(-1);
2205*4882a593Smuzhiyun 		ext_join_params->scan_le.nprobes = cpu_to_le32(-1);
2206*4882a593Smuzhiyun 	}
2207*4882a593Smuzhiyun 
2208*4882a593Smuzhiyun 	brcmf_set_join_pref(ifp, &sme->bss_select);
2209*4882a593Smuzhiyun 
2210*4882a593Smuzhiyun 	err  = brcmf_fil_bsscfg_data_set(ifp, "join", ext_join_params,
2211*4882a593Smuzhiyun 					 join_params_size);
2212*4882a593Smuzhiyun 	kfree(ext_join_params);
2213*4882a593Smuzhiyun 	if (!err)
2214*4882a593Smuzhiyun 		/* This is it. join command worked, we are done */
2215*4882a593Smuzhiyun 		goto done;
2216*4882a593Smuzhiyun 
2217*4882a593Smuzhiyun 	/* join command failed, fallback to set ssid */
2218*4882a593Smuzhiyun 	memset(&join_params, 0, sizeof(join_params));
2219*4882a593Smuzhiyun 	join_params_size = sizeof(join_params.ssid_le);
2220*4882a593Smuzhiyun 
2221*4882a593Smuzhiyun 	memcpy(&join_params.ssid_le.SSID, sme->ssid, ssid_len);
2222*4882a593Smuzhiyun 	join_params.ssid_le.SSID_len = cpu_to_le32(ssid_len);
2223*4882a593Smuzhiyun 
2224*4882a593Smuzhiyun 	if (sme->bssid)
2225*4882a593Smuzhiyun 		memcpy(join_params.params_le.bssid, sme->bssid, ETH_ALEN);
2226*4882a593Smuzhiyun 	else
2227*4882a593Smuzhiyun 		eth_broadcast_addr(join_params.params_le.bssid);
2228*4882a593Smuzhiyun 
2229*4882a593Smuzhiyun 	if (cfg->channel) {
2230*4882a593Smuzhiyun 		join_params.params_le.chanspec_list[0] = cpu_to_le16(chanspec);
2231*4882a593Smuzhiyun 		join_params.params_le.chanspec_num = cpu_to_le32(1);
2232*4882a593Smuzhiyun 		join_params_size += sizeof(join_params.params_le);
2233*4882a593Smuzhiyun 	}
2234*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SET_SSID,
2235*4882a593Smuzhiyun 				     &join_params, join_params_size);
2236*4882a593Smuzhiyun 	if (err)
2237*4882a593Smuzhiyun 		bphy_err(drvr, "BRCMF_C_SET_SSID failed (%d)\n", err);
2238*4882a593Smuzhiyun 
2239*4882a593Smuzhiyun done:
2240*4882a593Smuzhiyun 	if (err)
2241*4882a593Smuzhiyun 		clear_bit(BRCMF_VIF_STATUS_CONNECTING, &ifp->vif->sme_state);
2242*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
2243*4882a593Smuzhiyun 	return err;
2244*4882a593Smuzhiyun }
2245*4882a593Smuzhiyun 
2246*4882a593Smuzhiyun static s32
brcmf_cfg80211_disconnect(struct wiphy * wiphy,struct net_device * ndev,u16 reason_code)2247*4882a593Smuzhiyun brcmf_cfg80211_disconnect(struct wiphy *wiphy, struct net_device *ndev,
2248*4882a593Smuzhiyun 		       u16 reason_code)
2249*4882a593Smuzhiyun {
2250*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
2251*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2252*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
2253*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
2254*4882a593Smuzhiyun 	struct brcmf_scb_val_le scbval;
2255*4882a593Smuzhiyun 	s32 err = 0;
2256*4882a593Smuzhiyun 
2257*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter. Reason code = %d\n", reason_code);
2258*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
2259*4882a593Smuzhiyun 		return -EIO;
2260*4882a593Smuzhiyun 
2261*4882a593Smuzhiyun 	clear_bit(BRCMF_VIF_STATUS_CONNECTED, &ifp->vif->sme_state);
2262*4882a593Smuzhiyun 	clear_bit(BRCMF_VIF_STATUS_CONNECTING, &ifp->vif->sme_state);
2263*4882a593Smuzhiyun 	cfg80211_disconnected(ndev, reason_code, NULL, 0, true, GFP_KERNEL);
2264*4882a593Smuzhiyun 
2265*4882a593Smuzhiyun 	memcpy(&scbval.ea, &profile->bssid, ETH_ALEN);
2266*4882a593Smuzhiyun 	scbval.val = cpu_to_le32(reason_code);
2267*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_DISASSOC,
2268*4882a593Smuzhiyun 				     &scbval, sizeof(scbval));
2269*4882a593Smuzhiyun 	if (err)
2270*4882a593Smuzhiyun 		bphy_err(drvr, "error (%d)\n", err);
2271*4882a593Smuzhiyun 
2272*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
2273*4882a593Smuzhiyun 	return err;
2274*4882a593Smuzhiyun }
2275*4882a593Smuzhiyun 
2276*4882a593Smuzhiyun static s32
brcmf_cfg80211_set_tx_power(struct wiphy * wiphy,struct wireless_dev * wdev,enum nl80211_tx_power_setting type,s32 mbm)2277*4882a593Smuzhiyun brcmf_cfg80211_set_tx_power(struct wiphy *wiphy, struct wireless_dev *wdev,
2278*4882a593Smuzhiyun 			    enum nl80211_tx_power_setting type, s32 mbm)
2279*4882a593Smuzhiyun {
2280*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
2281*4882a593Smuzhiyun 	struct net_device *ndev = cfg_to_ndev(cfg);
2282*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2283*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
2284*4882a593Smuzhiyun 	s32 err;
2285*4882a593Smuzhiyun 	s32 disable;
2286*4882a593Smuzhiyun 	u32 qdbm = 127;
2287*4882a593Smuzhiyun 
2288*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter %d %d\n", type, mbm);
2289*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
2290*4882a593Smuzhiyun 		return -EIO;
2291*4882a593Smuzhiyun 
2292*4882a593Smuzhiyun 	switch (type) {
2293*4882a593Smuzhiyun 	case NL80211_TX_POWER_AUTOMATIC:
2294*4882a593Smuzhiyun 		break;
2295*4882a593Smuzhiyun 	case NL80211_TX_POWER_LIMITED:
2296*4882a593Smuzhiyun 	case NL80211_TX_POWER_FIXED:
2297*4882a593Smuzhiyun 		if (mbm < 0) {
2298*4882a593Smuzhiyun 			bphy_err(drvr, "TX_POWER_FIXED - dbm is negative\n");
2299*4882a593Smuzhiyun 			err = -EINVAL;
2300*4882a593Smuzhiyun 			goto done;
2301*4882a593Smuzhiyun 		}
2302*4882a593Smuzhiyun 		qdbm =  MBM_TO_DBM(4 * mbm);
2303*4882a593Smuzhiyun 		if (qdbm > 127)
2304*4882a593Smuzhiyun 			qdbm = 127;
2305*4882a593Smuzhiyun 		qdbm |= WL_TXPWR_OVERRIDE;
2306*4882a593Smuzhiyun 		break;
2307*4882a593Smuzhiyun 	default:
2308*4882a593Smuzhiyun 		bphy_err(drvr, "Unsupported type %d\n", type);
2309*4882a593Smuzhiyun 		err = -EINVAL;
2310*4882a593Smuzhiyun 		goto done;
2311*4882a593Smuzhiyun 	}
2312*4882a593Smuzhiyun 	/* Make sure radio is off or on as far as software is concerned */
2313*4882a593Smuzhiyun 	disable = WL_RADIO_SW_DISABLE << 16;
2314*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_RADIO, disable);
2315*4882a593Smuzhiyun 	if (err)
2316*4882a593Smuzhiyun 		bphy_err(drvr, "WLC_SET_RADIO error (%d)\n", err);
2317*4882a593Smuzhiyun 
2318*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_set(ifp, "qtxpower", qdbm);
2319*4882a593Smuzhiyun 	if (err)
2320*4882a593Smuzhiyun 		bphy_err(drvr, "qtxpower error (%d)\n", err);
2321*4882a593Smuzhiyun 
2322*4882a593Smuzhiyun done:
2323*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit %d (qdbm)\n", qdbm & ~WL_TXPWR_OVERRIDE);
2324*4882a593Smuzhiyun 	return err;
2325*4882a593Smuzhiyun }
2326*4882a593Smuzhiyun 
2327*4882a593Smuzhiyun static s32
brcmf_cfg80211_get_tx_power(struct wiphy * wiphy,struct wireless_dev * wdev,s32 * dbm)2328*4882a593Smuzhiyun brcmf_cfg80211_get_tx_power(struct wiphy *wiphy, struct wireless_dev *wdev,
2329*4882a593Smuzhiyun 			    s32 *dbm)
2330*4882a593Smuzhiyun {
2331*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
2332*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif = wdev_to_vif(wdev);
2333*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
2334*4882a593Smuzhiyun 	s32 qdbm = 0;
2335*4882a593Smuzhiyun 	s32 err;
2336*4882a593Smuzhiyun 
2337*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
2338*4882a593Smuzhiyun 	if (!check_vif_up(vif))
2339*4882a593Smuzhiyun 		return -EIO;
2340*4882a593Smuzhiyun 
2341*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_get(vif->ifp, "qtxpower", &qdbm);
2342*4882a593Smuzhiyun 	if (err) {
2343*4882a593Smuzhiyun 		bphy_err(drvr, "error (%d)\n", err);
2344*4882a593Smuzhiyun 		goto done;
2345*4882a593Smuzhiyun 	}
2346*4882a593Smuzhiyun 	*dbm = (qdbm & ~WL_TXPWR_OVERRIDE) / 4;
2347*4882a593Smuzhiyun 
2348*4882a593Smuzhiyun done:
2349*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit (0x%x %d)\n", qdbm, *dbm);
2350*4882a593Smuzhiyun 	return err;
2351*4882a593Smuzhiyun }
2352*4882a593Smuzhiyun 
2353*4882a593Smuzhiyun static s32
brcmf_cfg80211_config_default_key(struct wiphy * wiphy,struct net_device * ndev,u8 key_idx,bool unicast,bool multicast)2354*4882a593Smuzhiyun brcmf_cfg80211_config_default_key(struct wiphy *wiphy, struct net_device *ndev,
2355*4882a593Smuzhiyun 				  u8 key_idx, bool unicast, bool multicast)
2356*4882a593Smuzhiyun {
2357*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2358*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
2359*4882a593Smuzhiyun 	u32 index;
2360*4882a593Smuzhiyun 	u32 wsec;
2361*4882a593Smuzhiyun 	s32 err = 0;
2362*4882a593Smuzhiyun 
2363*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
2364*4882a593Smuzhiyun 	brcmf_dbg(CONN, "key index (%d)\n", key_idx);
2365*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
2366*4882a593Smuzhiyun 		return -EIO;
2367*4882a593Smuzhiyun 
2368*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_get(ifp, "wsec", &wsec);
2369*4882a593Smuzhiyun 	if (err) {
2370*4882a593Smuzhiyun 		bphy_err(drvr, "WLC_GET_WSEC error (%d)\n", err);
2371*4882a593Smuzhiyun 		goto done;
2372*4882a593Smuzhiyun 	}
2373*4882a593Smuzhiyun 
2374*4882a593Smuzhiyun 	if (wsec & WEP_ENABLED) {
2375*4882a593Smuzhiyun 		/* Just select a new current key */
2376*4882a593Smuzhiyun 		index = key_idx;
2377*4882a593Smuzhiyun 		err = brcmf_fil_cmd_int_set(ifp,
2378*4882a593Smuzhiyun 					    BRCMF_C_SET_KEY_PRIMARY, index);
2379*4882a593Smuzhiyun 		if (err)
2380*4882a593Smuzhiyun 			bphy_err(drvr, "error (%d)\n", err);
2381*4882a593Smuzhiyun 	}
2382*4882a593Smuzhiyun done:
2383*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
2384*4882a593Smuzhiyun 	return err;
2385*4882a593Smuzhiyun }
2386*4882a593Smuzhiyun 
2387*4882a593Smuzhiyun static s32
brcmf_cfg80211_del_key(struct wiphy * wiphy,struct net_device * ndev,u8 key_idx,bool pairwise,const u8 * mac_addr)2388*4882a593Smuzhiyun brcmf_cfg80211_del_key(struct wiphy *wiphy, struct net_device *ndev,
2389*4882a593Smuzhiyun 		       u8 key_idx, bool pairwise, const u8 *mac_addr)
2390*4882a593Smuzhiyun {
2391*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2392*4882a593Smuzhiyun 	struct brcmf_wsec_key *key;
2393*4882a593Smuzhiyun 	s32 err;
2394*4882a593Smuzhiyun 
2395*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
2396*4882a593Smuzhiyun 	brcmf_dbg(CONN, "key index (%d)\n", key_idx);
2397*4882a593Smuzhiyun 
2398*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
2399*4882a593Smuzhiyun 		return -EIO;
2400*4882a593Smuzhiyun 
2401*4882a593Smuzhiyun 	if (key_idx >= BRCMF_MAX_DEFAULT_KEYS) {
2402*4882a593Smuzhiyun 		/* we ignore this key index in this case */
2403*4882a593Smuzhiyun 		return -EINVAL;
2404*4882a593Smuzhiyun 	}
2405*4882a593Smuzhiyun 
2406*4882a593Smuzhiyun 	key = &ifp->vif->profile.key[key_idx];
2407*4882a593Smuzhiyun 
2408*4882a593Smuzhiyun 	if (key->algo == CRYPTO_ALGO_OFF) {
2409*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Ignore clearing of (never configured) key\n");
2410*4882a593Smuzhiyun 		return -EINVAL;
2411*4882a593Smuzhiyun 	}
2412*4882a593Smuzhiyun 
2413*4882a593Smuzhiyun 	memset(key, 0, sizeof(*key));
2414*4882a593Smuzhiyun 	key->index = (u32)key_idx;
2415*4882a593Smuzhiyun 	key->flags = BRCMF_PRIMARY_KEY;
2416*4882a593Smuzhiyun 
2417*4882a593Smuzhiyun 	/* Clear the key/index */
2418*4882a593Smuzhiyun 	err = send_key_to_dongle(ifp, key);
2419*4882a593Smuzhiyun 
2420*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
2421*4882a593Smuzhiyun 	return err;
2422*4882a593Smuzhiyun }
2423*4882a593Smuzhiyun 
2424*4882a593Smuzhiyun static s32
brcmf_cfg80211_add_key(struct wiphy * wiphy,struct net_device * ndev,u8 key_idx,bool pairwise,const u8 * mac_addr,struct key_params * params)2425*4882a593Smuzhiyun brcmf_cfg80211_add_key(struct wiphy *wiphy, struct net_device *ndev,
2426*4882a593Smuzhiyun 		       u8 key_idx, bool pairwise, const u8 *mac_addr,
2427*4882a593Smuzhiyun 		       struct key_params *params)
2428*4882a593Smuzhiyun {
2429*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
2430*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2431*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
2432*4882a593Smuzhiyun 	struct brcmf_wsec_key *key;
2433*4882a593Smuzhiyun 	s32 val;
2434*4882a593Smuzhiyun 	s32 wsec;
2435*4882a593Smuzhiyun 	s32 err;
2436*4882a593Smuzhiyun 	u8 keybuf[8];
2437*4882a593Smuzhiyun 	bool ext_key;
2438*4882a593Smuzhiyun 
2439*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
2440*4882a593Smuzhiyun 	brcmf_dbg(CONN, "key index (%d)\n", key_idx);
2441*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
2442*4882a593Smuzhiyun 		return -EIO;
2443*4882a593Smuzhiyun 
2444*4882a593Smuzhiyun 	if (key_idx >= BRCMF_MAX_DEFAULT_KEYS) {
2445*4882a593Smuzhiyun 		/* we ignore this key index in this case */
2446*4882a593Smuzhiyun 		bphy_err(drvr, "invalid key index (%d)\n", key_idx);
2447*4882a593Smuzhiyun 		return -EINVAL;
2448*4882a593Smuzhiyun 	}
2449*4882a593Smuzhiyun 
2450*4882a593Smuzhiyun 	if (params->key_len == 0)
2451*4882a593Smuzhiyun 		return brcmf_cfg80211_del_key(wiphy, ndev, key_idx, pairwise,
2452*4882a593Smuzhiyun 					      mac_addr);
2453*4882a593Smuzhiyun 
2454*4882a593Smuzhiyun 	if (params->key_len > sizeof(key->data)) {
2455*4882a593Smuzhiyun 		bphy_err(drvr, "Too long key length (%u)\n", params->key_len);
2456*4882a593Smuzhiyun 		return -EINVAL;
2457*4882a593Smuzhiyun 	}
2458*4882a593Smuzhiyun 
2459*4882a593Smuzhiyun 	ext_key = false;
2460*4882a593Smuzhiyun 	if (mac_addr && (params->cipher != WLAN_CIPHER_SUITE_WEP40) &&
2461*4882a593Smuzhiyun 	    (params->cipher != WLAN_CIPHER_SUITE_WEP104)) {
2462*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "Ext key, mac %pM", mac_addr);
2463*4882a593Smuzhiyun 		ext_key = true;
2464*4882a593Smuzhiyun 	}
2465*4882a593Smuzhiyun 
2466*4882a593Smuzhiyun 	key = &ifp->vif->profile.key[key_idx];
2467*4882a593Smuzhiyun 	memset(key, 0, sizeof(*key));
2468*4882a593Smuzhiyun 	if ((ext_key) && (!is_multicast_ether_addr(mac_addr)))
2469*4882a593Smuzhiyun 		memcpy((char *)&key->ea, (void *)mac_addr, ETH_ALEN);
2470*4882a593Smuzhiyun 	key->len = params->key_len;
2471*4882a593Smuzhiyun 	key->index = key_idx;
2472*4882a593Smuzhiyun 	memcpy(key->data, params->key, key->len);
2473*4882a593Smuzhiyun 	if (!ext_key)
2474*4882a593Smuzhiyun 		key->flags = BRCMF_PRIMARY_KEY;
2475*4882a593Smuzhiyun 
2476*4882a593Smuzhiyun 	if (params->seq && params->seq_len == 6) {
2477*4882a593Smuzhiyun 		/* rx iv */
2478*4882a593Smuzhiyun 		u8 *ivptr;
2479*4882a593Smuzhiyun 
2480*4882a593Smuzhiyun 		ivptr = (u8 *)params->seq;
2481*4882a593Smuzhiyun 		key->rxiv.hi = (ivptr[5] << 24) | (ivptr[4] << 16) |
2482*4882a593Smuzhiyun 			(ivptr[3] << 8) | ivptr[2];
2483*4882a593Smuzhiyun 		key->rxiv.lo = (ivptr[1] << 8) | ivptr[0];
2484*4882a593Smuzhiyun 		key->iv_initialized = true;
2485*4882a593Smuzhiyun 	}
2486*4882a593Smuzhiyun 
2487*4882a593Smuzhiyun 	switch (params->cipher) {
2488*4882a593Smuzhiyun 	case WLAN_CIPHER_SUITE_WEP40:
2489*4882a593Smuzhiyun 		key->algo = CRYPTO_ALGO_WEP1;
2490*4882a593Smuzhiyun 		val = WEP_ENABLED;
2491*4882a593Smuzhiyun 		brcmf_dbg(CONN, "WLAN_CIPHER_SUITE_WEP40\n");
2492*4882a593Smuzhiyun 		break;
2493*4882a593Smuzhiyun 	case WLAN_CIPHER_SUITE_WEP104:
2494*4882a593Smuzhiyun 		key->algo = CRYPTO_ALGO_WEP128;
2495*4882a593Smuzhiyun 		val = WEP_ENABLED;
2496*4882a593Smuzhiyun 		brcmf_dbg(CONN, "WLAN_CIPHER_SUITE_WEP104\n");
2497*4882a593Smuzhiyun 		break;
2498*4882a593Smuzhiyun 	case WLAN_CIPHER_SUITE_TKIP:
2499*4882a593Smuzhiyun 		if (!brcmf_is_apmode(ifp->vif)) {
2500*4882a593Smuzhiyun 			brcmf_dbg(CONN, "Swapping RX/TX MIC key\n");
2501*4882a593Smuzhiyun 			memcpy(keybuf, &key->data[24], sizeof(keybuf));
2502*4882a593Smuzhiyun 			memcpy(&key->data[24], &key->data[16], sizeof(keybuf));
2503*4882a593Smuzhiyun 			memcpy(&key->data[16], keybuf, sizeof(keybuf));
2504*4882a593Smuzhiyun 		}
2505*4882a593Smuzhiyun 		key->algo = CRYPTO_ALGO_TKIP;
2506*4882a593Smuzhiyun 		val = TKIP_ENABLED;
2507*4882a593Smuzhiyun 		brcmf_dbg(CONN, "WLAN_CIPHER_SUITE_TKIP\n");
2508*4882a593Smuzhiyun 		break;
2509*4882a593Smuzhiyun 	case WLAN_CIPHER_SUITE_AES_CMAC:
2510*4882a593Smuzhiyun 		key->algo = CRYPTO_ALGO_AES_CCM;
2511*4882a593Smuzhiyun 		val = AES_ENABLED;
2512*4882a593Smuzhiyun 		brcmf_dbg(CONN, "WLAN_CIPHER_SUITE_AES_CMAC\n");
2513*4882a593Smuzhiyun 		break;
2514*4882a593Smuzhiyun 	case WLAN_CIPHER_SUITE_CCMP:
2515*4882a593Smuzhiyun 		key->algo = CRYPTO_ALGO_AES_CCM;
2516*4882a593Smuzhiyun 		val = AES_ENABLED;
2517*4882a593Smuzhiyun 		brcmf_dbg(CONN, "WLAN_CIPHER_SUITE_CCMP\n");
2518*4882a593Smuzhiyun 		break;
2519*4882a593Smuzhiyun 	default:
2520*4882a593Smuzhiyun 		bphy_err(drvr, "Invalid cipher (0x%x)\n", params->cipher);
2521*4882a593Smuzhiyun 		err = -EINVAL;
2522*4882a593Smuzhiyun 		goto done;
2523*4882a593Smuzhiyun 	}
2524*4882a593Smuzhiyun 
2525*4882a593Smuzhiyun 	err = send_key_to_dongle(ifp, key);
2526*4882a593Smuzhiyun 	if (ext_key || err)
2527*4882a593Smuzhiyun 		goto done;
2528*4882a593Smuzhiyun 
2529*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_get(ifp, "wsec", &wsec);
2530*4882a593Smuzhiyun 	if (err) {
2531*4882a593Smuzhiyun 		bphy_err(drvr, "get wsec error (%d)\n", err);
2532*4882a593Smuzhiyun 		goto done;
2533*4882a593Smuzhiyun 	}
2534*4882a593Smuzhiyun 	wsec |= val;
2535*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "wsec", wsec);
2536*4882a593Smuzhiyun 	if (err) {
2537*4882a593Smuzhiyun 		bphy_err(drvr, "set wsec error (%d)\n", err);
2538*4882a593Smuzhiyun 		goto done;
2539*4882a593Smuzhiyun 	}
2540*4882a593Smuzhiyun 
2541*4882a593Smuzhiyun done:
2542*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
2543*4882a593Smuzhiyun 	return err;
2544*4882a593Smuzhiyun }
2545*4882a593Smuzhiyun 
2546*4882a593Smuzhiyun static s32
brcmf_cfg80211_get_key(struct wiphy * wiphy,struct net_device * ndev,u8 key_idx,bool pairwise,const u8 * mac_addr,void * cookie,void (* callback)(void * cookie,struct key_params * params))2547*4882a593Smuzhiyun brcmf_cfg80211_get_key(struct wiphy *wiphy, struct net_device *ndev, u8 key_idx,
2548*4882a593Smuzhiyun 		       bool pairwise, const u8 *mac_addr, void *cookie,
2549*4882a593Smuzhiyun 		       void (*callback)(void *cookie,
2550*4882a593Smuzhiyun 					struct key_params *params))
2551*4882a593Smuzhiyun {
2552*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
2553*4882a593Smuzhiyun 	struct key_params params;
2554*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2555*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
2556*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
2557*4882a593Smuzhiyun 	struct brcmf_cfg80211_security *sec;
2558*4882a593Smuzhiyun 	s32 wsec;
2559*4882a593Smuzhiyun 	s32 err = 0;
2560*4882a593Smuzhiyun 
2561*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
2562*4882a593Smuzhiyun 	brcmf_dbg(CONN, "key index (%d)\n", key_idx);
2563*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
2564*4882a593Smuzhiyun 		return -EIO;
2565*4882a593Smuzhiyun 
2566*4882a593Smuzhiyun 	memset(&params, 0, sizeof(params));
2567*4882a593Smuzhiyun 
2568*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_get(ifp, "wsec", &wsec);
2569*4882a593Smuzhiyun 	if (err) {
2570*4882a593Smuzhiyun 		bphy_err(drvr, "WLC_GET_WSEC error (%d)\n", err);
2571*4882a593Smuzhiyun 		/* Ignore this error, may happen during DISASSOC */
2572*4882a593Smuzhiyun 		err = -EAGAIN;
2573*4882a593Smuzhiyun 		goto done;
2574*4882a593Smuzhiyun 	}
2575*4882a593Smuzhiyun 	if (wsec & WEP_ENABLED) {
2576*4882a593Smuzhiyun 		sec = &profile->sec;
2577*4882a593Smuzhiyun 		if (sec->cipher_pairwise & WLAN_CIPHER_SUITE_WEP40) {
2578*4882a593Smuzhiyun 			params.cipher = WLAN_CIPHER_SUITE_WEP40;
2579*4882a593Smuzhiyun 			brcmf_dbg(CONN, "WLAN_CIPHER_SUITE_WEP40\n");
2580*4882a593Smuzhiyun 		} else if (sec->cipher_pairwise & WLAN_CIPHER_SUITE_WEP104) {
2581*4882a593Smuzhiyun 			params.cipher = WLAN_CIPHER_SUITE_WEP104;
2582*4882a593Smuzhiyun 			brcmf_dbg(CONN, "WLAN_CIPHER_SUITE_WEP104\n");
2583*4882a593Smuzhiyun 		}
2584*4882a593Smuzhiyun 	} else if (wsec & TKIP_ENABLED) {
2585*4882a593Smuzhiyun 		params.cipher = WLAN_CIPHER_SUITE_TKIP;
2586*4882a593Smuzhiyun 		brcmf_dbg(CONN, "WLAN_CIPHER_SUITE_TKIP\n");
2587*4882a593Smuzhiyun 	} else if (wsec & AES_ENABLED) {
2588*4882a593Smuzhiyun 		params.cipher = WLAN_CIPHER_SUITE_AES_CMAC;
2589*4882a593Smuzhiyun 		brcmf_dbg(CONN, "WLAN_CIPHER_SUITE_AES_CMAC\n");
2590*4882a593Smuzhiyun 	} else  {
2591*4882a593Smuzhiyun 		bphy_err(drvr, "Invalid algo (0x%x)\n", wsec);
2592*4882a593Smuzhiyun 		err = -EINVAL;
2593*4882a593Smuzhiyun 		goto done;
2594*4882a593Smuzhiyun 	}
2595*4882a593Smuzhiyun 	callback(cookie, &params);
2596*4882a593Smuzhiyun 
2597*4882a593Smuzhiyun done:
2598*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
2599*4882a593Smuzhiyun 	return err;
2600*4882a593Smuzhiyun }
2601*4882a593Smuzhiyun 
2602*4882a593Smuzhiyun static s32
brcmf_cfg80211_config_default_mgmt_key(struct wiphy * wiphy,struct net_device * ndev,u8 key_idx)2603*4882a593Smuzhiyun brcmf_cfg80211_config_default_mgmt_key(struct wiphy *wiphy,
2604*4882a593Smuzhiyun 				       struct net_device *ndev, u8 key_idx)
2605*4882a593Smuzhiyun {
2606*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2607*4882a593Smuzhiyun 
2608*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter key_idx %d\n", key_idx);
2609*4882a593Smuzhiyun 
2610*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MFP))
2611*4882a593Smuzhiyun 		return 0;
2612*4882a593Smuzhiyun 
2613*4882a593Smuzhiyun 	brcmf_dbg(INFO, "Not supported\n");
2614*4882a593Smuzhiyun 
2615*4882a593Smuzhiyun 	return -EOPNOTSUPP;
2616*4882a593Smuzhiyun }
2617*4882a593Smuzhiyun 
2618*4882a593Smuzhiyun static void
brcmf_cfg80211_reconfigure_wep(struct brcmf_if * ifp)2619*4882a593Smuzhiyun brcmf_cfg80211_reconfigure_wep(struct brcmf_if *ifp)
2620*4882a593Smuzhiyun {
2621*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
2622*4882a593Smuzhiyun 	s32 err;
2623*4882a593Smuzhiyun 	u8 key_idx;
2624*4882a593Smuzhiyun 	struct brcmf_wsec_key *key;
2625*4882a593Smuzhiyun 	s32 wsec;
2626*4882a593Smuzhiyun 
2627*4882a593Smuzhiyun 	for (key_idx = 0; key_idx < BRCMF_MAX_DEFAULT_KEYS; key_idx++) {
2628*4882a593Smuzhiyun 		key = &ifp->vif->profile.key[key_idx];
2629*4882a593Smuzhiyun 		if ((key->algo == CRYPTO_ALGO_WEP1) ||
2630*4882a593Smuzhiyun 		    (key->algo == CRYPTO_ALGO_WEP128))
2631*4882a593Smuzhiyun 			break;
2632*4882a593Smuzhiyun 	}
2633*4882a593Smuzhiyun 	if (key_idx == BRCMF_MAX_DEFAULT_KEYS)
2634*4882a593Smuzhiyun 		return;
2635*4882a593Smuzhiyun 
2636*4882a593Smuzhiyun 	err = send_key_to_dongle(ifp, key);
2637*4882a593Smuzhiyun 	if (err) {
2638*4882a593Smuzhiyun 		bphy_err(drvr, "Setting WEP key failed (%d)\n", err);
2639*4882a593Smuzhiyun 		return;
2640*4882a593Smuzhiyun 	}
2641*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_get(ifp, "wsec", &wsec);
2642*4882a593Smuzhiyun 	if (err) {
2643*4882a593Smuzhiyun 		bphy_err(drvr, "get wsec error (%d)\n", err);
2644*4882a593Smuzhiyun 		return;
2645*4882a593Smuzhiyun 	}
2646*4882a593Smuzhiyun 	wsec |= WEP_ENABLED;
2647*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "wsec", wsec);
2648*4882a593Smuzhiyun 	if (err)
2649*4882a593Smuzhiyun 		bphy_err(drvr, "set wsec error (%d)\n", err);
2650*4882a593Smuzhiyun }
2651*4882a593Smuzhiyun 
brcmf_convert_sta_flags(u32 fw_sta_flags,struct station_info * si)2652*4882a593Smuzhiyun static void brcmf_convert_sta_flags(u32 fw_sta_flags, struct station_info *si)
2653*4882a593Smuzhiyun {
2654*4882a593Smuzhiyun 	struct nl80211_sta_flag_update *sfu;
2655*4882a593Smuzhiyun 
2656*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "flags %08x\n", fw_sta_flags);
2657*4882a593Smuzhiyun 	si->filled |= BIT_ULL(NL80211_STA_INFO_STA_FLAGS);
2658*4882a593Smuzhiyun 	sfu = &si->sta_flags;
2659*4882a593Smuzhiyun 	sfu->mask = BIT(NL80211_STA_FLAG_WME) |
2660*4882a593Smuzhiyun 		    BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2661*4882a593Smuzhiyun 		    BIT(NL80211_STA_FLAG_ASSOCIATED) |
2662*4882a593Smuzhiyun 		    BIT(NL80211_STA_FLAG_AUTHORIZED);
2663*4882a593Smuzhiyun 	if (fw_sta_flags & BRCMF_STA_WME)
2664*4882a593Smuzhiyun 		sfu->set |= BIT(NL80211_STA_FLAG_WME);
2665*4882a593Smuzhiyun 	if (fw_sta_flags & BRCMF_STA_AUTHE)
2666*4882a593Smuzhiyun 		sfu->set |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
2667*4882a593Smuzhiyun 	if (fw_sta_flags & BRCMF_STA_ASSOC)
2668*4882a593Smuzhiyun 		sfu->set |= BIT(NL80211_STA_FLAG_ASSOCIATED);
2669*4882a593Smuzhiyun 	if (fw_sta_flags & BRCMF_STA_AUTHO)
2670*4882a593Smuzhiyun 		sfu->set |= BIT(NL80211_STA_FLAG_AUTHORIZED);
2671*4882a593Smuzhiyun }
2672*4882a593Smuzhiyun 
brcmf_fill_bss_param(struct brcmf_if * ifp,struct station_info * si)2673*4882a593Smuzhiyun static void brcmf_fill_bss_param(struct brcmf_if *ifp, struct station_info *si)
2674*4882a593Smuzhiyun {
2675*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
2676*4882a593Smuzhiyun 	struct {
2677*4882a593Smuzhiyun 		__le32 len;
2678*4882a593Smuzhiyun 		struct brcmf_bss_info_le bss_le;
2679*4882a593Smuzhiyun 	} *buf;
2680*4882a593Smuzhiyun 	u16 capability;
2681*4882a593Smuzhiyun 	int err;
2682*4882a593Smuzhiyun 
2683*4882a593Smuzhiyun 	buf = kzalloc(WL_BSS_INFO_MAX, GFP_KERNEL);
2684*4882a593Smuzhiyun 	if (!buf)
2685*4882a593Smuzhiyun 		return;
2686*4882a593Smuzhiyun 
2687*4882a593Smuzhiyun 	buf->len = cpu_to_le32(WL_BSS_INFO_MAX);
2688*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_get(ifp, BRCMF_C_GET_BSS_INFO, buf,
2689*4882a593Smuzhiyun 				     WL_BSS_INFO_MAX);
2690*4882a593Smuzhiyun 	if (err) {
2691*4882a593Smuzhiyun 		bphy_err(drvr, "Failed to get bss info (%d)\n", err);
2692*4882a593Smuzhiyun 		goto out_kfree;
2693*4882a593Smuzhiyun 	}
2694*4882a593Smuzhiyun 	si->filled |= BIT_ULL(NL80211_STA_INFO_BSS_PARAM);
2695*4882a593Smuzhiyun 	si->bss_param.beacon_interval = le16_to_cpu(buf->bss_le.beacon_period);
2696*4882a593Smuzhiyun 	si->bss_param.dtim_period = buf->bss_le.dtim_period;
2697*4882a593Smuzhiyun 	capability = le16_to_cpu(buf->bss_le.capability);
2698*4882a593Smuzhiyun 	if (capability & IEEE80211_HT_STBC_PARAM_DUAL_CTS_PROT)
2699*4882a593Smuzhiyun 		si->bss_param.flags |= BSS_PARAM_FLAGS_CTS_PROT;
2700*4882a593Smuzhiyun 	if (capability & WLAN_CAPABILITY_SHORT_PREAMBLE)
2701*4882a593Smuzhiyun 		si->bss_param.flags |= BSS_PARAM_FLAGS_SHORT_PREAMBLE;
2702*4882a593Smuzhiyun 	if (capability & WLAN_CAPABILITY_SHORT_SLOT_TIME)
2703*4882a593Smuzhiyun 		si->bss_param.flags |= BSS_PARAM_FLAGS_SHORT_SLOT_TIME;
2704*4882a593Smuzhiyun 
2705*4882a593Smuzhiyun out_kfree:
2706*4882a593Smuzhiyun 	kfree(buf);
2707*4882a593Smuzhiyun }
2708*4882a593Smuzhiyun 
2709*4882a593Smuzhiyun static s32
brcmf_cfg80211_get_station_ibss(struct brcmf_if * ifp,struct station_info * sinfo)2710*4882a593Smuzhiyun brcmf_cfg80211_get_station_ibss(struct brcmf_if *ifp,
2711*4882a593Smuzhiyun 				struct station_info *sinfo)
2712*4882a593Smuzhiyun {
2713*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
2714*4882a593Smuzhiyun 	struct brcmf_scb_val_le scbval;
2715*4882a593Smuzhiyun 	struct brcmf_pktcnt_le pktcnt;
2716*4882a593Smuzhiyun 	s32 err;
2717*4882a593Smuzhiyun 	u32 rate;
2718*4882a593Smuzhiyun 	u32 rssi;
2719*4882a593Smuzhiyun 
2720*4882a593Smuzhiyun 	/* Get the current tx rate */
2721*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_get(ifp, BRCMF_C_GET_RATE, &rate);
2722*4882a593Smuzhiyun 	if (err < 0) {
2723*4882a593Smuzhiyun 		bphy_err(drvr, "BRCMF_C_GET_RATE error (%d)\n", err);
2724*4882a593Smuzhiyun 		return err;
2725*4882a593Smuzhiyun 	}
2726*4882a593Smuzhiyun 	sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BITRATE);
2727*4882a593Smuzhiyun 	sinfo->txrate.legacy = rate * 5;
2728*4882a593Smuzhiyun 
2729*4882a593Smuzhiyun 	memset(&scbval, 0, sizeof(scbval));
2730*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_get(ifp, BRCMF_C_GET_RSSI, &scbval,
2731*4882a593Smuzhiyun 				     sizeof(scbval));
2732*4882a593Smuzhiyun 	if (err) {
2733*4882a593Smuzhiyun 		bphy_err(drvr, "BRCMF_C_GET_RSSI error (%d)\n", err);
2734*4882a593Smuzhiyun 		return err;
2735*4882a593Smuzhiyun 	}
2736*4882a593Smuzhiyun 	rssi = le32_to_cpu(scbval.val);
2737*4882a593Smuzhiyun 	sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL);
2738*4882a593Smuzhiyun 	sinfo->signal = rssi;
2739*4882a593Smuzhiyun 
2740*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_get(ifp, BRCMF_C_GET_GET_PKTCNTS, &pktcnt,
2741*4882a593Smuzhiyun 				     sizeof(pktcnt));
2742*4882a593Smuzhiyun 	if (err) {
2743*4882a593Smuzhiyun 		bphy_err(drvr, "BRCMF_C_GET_GET_PKTCNTS error (%d)\n", err);
2744*4882a593Smuzhiyun 		return err;
2745*4882a593Smuzhiyun 	}
2746*4882a593Smuzhiyun 	sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_PACKETS) |
2747*4882a593Smuzhiyun 			 BIT_ULL(NL80211_STA_INFO_RX_DROP_MISC) |
2748*4882a593Smuzhiyun 			 BIT_ULL(NL80211_STA_INFO_TX_PACKETS) |
2749*4882a593Smuzhiyun 			 BIT_ULL(NL80211_STA_INFO_TX_FAILED);
2750*4882a593Smuzhiyun 	sinfo->rx_packets = le32_to_cpu(pktcnt.rx_good_pkt);
2751*4882a593Smuzhiyun 	sinfo->rx_dropped_misc = le32_to_cpu(pktcnt.rx_bad_pkt);
2752*4882a593Smuzhiyun 	sinfo->tx_packets = le32_to_cpu(pktcnt.tx_good_pkt);
2753*4882a593Smuzhiyun 	sinfo->tx_failed  = le32_to_cpu(pktcnt.tx_bad_pkt);
2754*4882a593Smuzhiyun 
2755*4882a593Smuzhiyun 	return 0;
2756*4882a593Smuzhiyun }
2757*4882a593Smuzhiyun 
2758*4882a593Smuzhiyun static s32
brcmf_cfg80211_get_station(struct wiphy * wiphy,struct net_device * ndev,const u8 * mac,struct station_info * sinfo)2759*4882a593Smuzhiyun brcmf_cfg80211_get_station(struct wiphy *wiphy, struct net_device *ndev,
2760*4882a593Smuzhiyun 			   const u8 *mac, struct station_info *sinfo)
2761*4882a593Smuzhiyun {
2762*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
2763*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2764*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
2765*4882a593Smuzhiyun 	struct brcmf_scb_val_le scb_val;
2766*4882a593Smuzhiyun 	s32 err = 0;
2767*4882a593Smuzhiyun 	struct brcmf_sta_info_le sta_info_le;
2768*4882a593Smuzhiyun 	u32 sta_flags;
2769*4882a593Smuzhiyun 	u32 is_tdls_peer;
2770*4882a593Smuzhiyun 	s32 total_rssi_avg = 0;
2771*4882a593Smuzhiyun 	s32 total_rssi = 0;
2772*4882a593Smuzhiyun 	s32 count_rssi = 0;
2773*4882a593Smuzhiyun 	int rssi;
2774*4882a593Smuzhiyun 	u32 i;
2775*4882a593Smuzhiyun 
2776*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter, MAC %pM\n", mac);
2777*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
2778*4882a593Smuzhiyun 		return -EIO;
2779*4882a593Smuzhiyun 
2780*4882a593Smuzhiyun 	if (brcmf_is_ibssmode(ifp->vif))
2781*4882a593Smuzhiyun 		return brcmf_cfg80211_get_station_ibss(ifp, sinfo);
2782*4882a593Smuzhiyun 
2783*4882a593Smuzhiyun 	memset(&sta_info_le, 0, sizeof(sta_info_le));
2784*4882a593Smuzhiyun 	memcpy(&sta_info_le, mac, ETH_ALEN);
2785*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_get(ifp, "tdls_sta_info",
2786*4882a593Smuzhiyun 				       &sta_info_le,
2787*4882a593Smuzhiyun 				       sizeof(sta_info_le));
2788*4882a593Smuzhiyun 	is_tdls_peer = !err;
2789*4882a593Smuzhiyun 	if (err) {
2790*4882a593Smuzhiyun 		err = brcmf_fil_iovar_data_get(ifp, "sta_info",
2791*4882a593Smuzhiyun 					       &sta_info_le,
2792*4882a593Smuzhiyun 					       sizeof(sta_info_le));
2793*4882a593Smuzhiyun 		if (err < 0) {
2794*4882a593Smuzhiyun 			bphy_err(drvr, "GET STA INFO failed, %d\n", err);
2795*4882a593Smuzhiyun 			goto done;
2796*4882a593Smuzhiyun 		}
2797*4882a593Smuzhiyun 	}
2798*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "version %d\n", le16_to_cpu(sta_info_le.ver));
2799*4882a593Smuzhiyun 	sinfo->filled = BIT_ULL(NL80211_STA_INFO_INACTIVE_TIME);
2800*4882a593Smuzhiyun 	sinfo->inactive_time = le32_to_cpu(sta_info_le.idle) * 1000;
2801*4882a593Smuzhiyun 	sta_flags = le32_to_cpu(sta_info_le.flags);
2802*4882a593Smuzhiyun 	brcmf_convert_sta_flags(sta_flags, sinfo);
2803*4882a593Smuzhiyun 	sinfo->sta_flags.mask |= BIT(NL80211_STA_FLAG_TDLS_PEER);
2804*4882a593Smuzhiyun 	if (is_tdls_peer)
2805*4882a593Smuzhiyun 		sinfo->sta_flags.set |= BIT(NL80211_STA_FLAG_TDLS_PEER);
2806*4882a593Smuzhiyun 	else
2807*4882a593Smuzhiyun 		sinfo->sta_flags.set &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
2808*4882a593Smuzhiyun 	if (sta_flags & BRCMF_STA_ASSOC) {
2809*4882a593Smuzhiyun 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_CONNECTED_TIME);
2810*4882a593Smuzhiyun 		sinfo->connected_time = le32_to_cpu(sta_info_le.in);
2811*4882a593Smuzhiyun 		brcmf_fill_bss_param(ifp, sinfo);
2812*4882a593Smuzhiyun 	}
2813*4882a593Smuzhiyun 	if (sta_flags & BRCMF_STA_SCBSTATS) {
2814*4882a593Smuzhiyun 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_FAILED);
2815*4882a593Smuzhiyun 		sinfo->tx_failed = le32_to_cpu(sta_info_le.tx_failures);
2816*4882a593Smuzhiyun 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_PACKETS);
2817*4882a593Smuzhiyun 		sinfo->tx_packets = le32_to_cpu(sta_info_le.tx_pkts);
2818*4882a593Smuzhiyun 		sinfo->tx_packets += le32_to_cpu(sta_info_le.tx_mcast_pkts);
2819*4882a593Smuzhiyun 		sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_PACKETS);
2820*4882a593Smuzhiyun 		sinfo->rx_packets = le32_to_cpu(sta_info_le.rx_ucast_pkts);
2821*4882a593Smuzhiyun 		sinfo->rx_packets += le32_to_cpu(sta_info_le.rx_mcast_pkts);
2822*4882a593Smuzhiyun 		if (sinfo->tx_packets) {
2823*4882a593Smuzhiyun 			sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BITRATE);
2824*4882a593Smuzhiyun 			sinfo->txrate.legacy =
2825*4882a593Smuzhiyun 				le32_to_cpu(sta_info_le.tx_rate) / 100;
2826*4882a593Smuzhiyun 		}
2827*4882a593Smuzhiyun 		if (sinfo->rx_packets) {
2828*4882a593Smuzhiyun 			sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BITRATE);
2829*4882a593Smuzhiyun 			sinfo->rxrate.legacy =
2830*4882a593Smuzhiyun 				le32_to_cpu(sta_info_le.rx_rate) / 100;
2831*4882a593Smuzhiyun 		}
2832*4882a593Smuzhiyun 		if (le16_to_cpu(sta_info_le.ver) >= 4) {
2833*4882a593Smuzhiyun 			sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BYTES);
2834*4882a593Smuzhiyun 			sinfo->tx_bytes = le64_to_cpu(sta_info_le.tx_tot_bytes);
2835*4882a593Smuzhiyun 			sinfo->filled |= BIT_ULL(NL80211_STA_INFO_RX_BYTES);
2836*4882a593Smuzhiyun 			sinfo->rx_bytes = le64_to_cpu(sta_info_le.rx_tot_bytes);
2837*4882a593Smuzhiyun 		}
2838*4882a593Smuzhiyun 		for (i = 0; i < BRCMF_ANT_MAX; i++) {
2839*4882a593Smuzhiyun 			if (sta_info_le.rssi[i] == 0 ||
2840*4882a593Smuzhiyun 			    sta_info_le.rx_lastpkt_rssi[i] == 0)
2841*4882a593Smuzhiyun 				continue;
2842*4882a593Smuzhiyun 			sinfo->chains |= BIT(count_rssi);
2843*4882a593Smuzhiyun 			sinfo->chain_signal[count_rssi] =
2844*4882a593Smuzhiyun 				sta_info_le.rx_lastpkt_rssi[i];
2845*4882a593Smuzhiyun 			sinfo->chain_signal_avg[count_rssi] =
2846*4882a593Smuzhiyun 				sta_info_le.rssi[i];
2847*4882a593Smuzhiyun 			total_rssi += sta_info_le.rx_lastpkt_rssi[i];
2848*4882a593Smuzhiyun 			total_rssi_avg += sta_info_le.rssi[i];
2849*4882a593Smuzhiyun 			count_rssi++;
2850*4882a593Smuzhiyun 		}
2851*4882a593Smuzhiyun 		if (count_rssi) {
2852*4882a593Smuzhiyun 			sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL);
2853*4882a593Smuzhiyun 			sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL_AVG);
2854*4882a593Smuzhiyun 			sinfo->filled |= BIT_ULL(NL80211_STA_INFO_CHAIN_SIGNAL);
2855*4882a593Smuzhiyun 			sinfo->filled |=
2856*4882a593Smuzhiyun 				BIT_ULL(NL80211_STA_INFO_CHAIN_SIGNAL_AVG);
2857*4882a593Smuzhiyun 			sinfo->signal = total_rssi / count_rssi;
2858*4882a593Smuzhiyun 			sinfo->signal_avg = total_rssi_avg / count_rssi;
2859*4882a593Smuzhiyun 		} else if (test_bit(BRCMF_VIF_STATUS_CONNECTED,
2860*4882a593Smuzhiyun 			&ifp->vif->sme_state)) {
2861*4882a593Smuzhiyun 			memset(&scb_val, 0, sizeof(scb_val));
2862*4882a593Smuzhiyun 			err = brcmf_fil_cmd_data_get(ifp, BRCMF_C_GET_RSSI,
2863*4882a593Smuzhiyun 						     &scb_val, sizeof(scb_val));
2864*4882a593Smuzhiyun 			if (err) {
2865*4882a593Smuzhiyun 				bphy_err(drvr, "Could not get rssi (%d)\n",
2866*4882a593Smuzhiyun 					 err);
2867*4882a593Smuzhiyun 				goto done;
2868*4882a593Smuzhiyun 			} else {
2869*4882a593Smuzhiyun 				rssi = le32_to_cpu(scb_val.val);
2870*4882a593Smuzhiyun 				sinfo->filled |= BIT_ULL(NL80211_STA_INFO_SIGNAL);
2871*4882a593Smuzhiyun 				sinfo->signal = rssi;
2872*4882a593Smuzhiyun 				brcmf_dbg(CONN, "RSSI %d dBm\n", rssi);
2873*4882a593Smuzhiyun 			}
2874*4882a593Smuzhiyun 		}
2875*4882a593Smuzhiyun 	}
2876*4882a593Smuzhiyun done:
2877*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
2878*4882a593Smuzhiyun 	return err;
2879*4882a593Smuzhiyun }
2880*4882a593Smuzhiyun 
2881*4882a593Smuzhiyun static int
brcmf_cfg80211_dump_station(struct wiphy * wiphy,struct net_device * ndev,int idx,u8 * mac,struct station_info * sinfo)2882*4882a593Smuzhiyun brcmf_cfg80211_dump_station(struct wiphy *wiphy, struct net_device *ndev,
2883*4882a593Smuzhiyun 			    int idx, u8 *mac, struct station_info *sinfo)
2884*4882a593Smuzhiyun {
2885*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
2886*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2887*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
2888*4882a593Smuzhiyun 	s32 err;
2889*4882a593Smuzhiyun 
2890*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter, idx %d\n", idx);
2891*4882a593Smuzhiyun 
2892*4882a593Smuzhiyun 	if (idx == 0) {
2893*4882a593Smuzhiyun 		cfg->assoclist.count = cpu_to_le32(BRCMF_MAX_ASSOCLIST);
2894*4882a593Smuzhiyun 		err = brcmf_fil_cmd_data_get(ifp, BRCMF_C_GET_ASSOCLIST,
2895*4882a593Smuzhiyun 					     &cfg->assoclist,
2896*4882a593Smuzhiyun 					     sizeof(cfg->assoclist));
2897*4882a593Smuzhiyun 		if (err) {
2898*4882a593Smuzhiyun 			bphy_err(drvr, "BRCMF_C_GET_ASSOCLIST unsupported, err=%d\n",
2899*4882a593Smuzhiyun 				 err);
2900*4882a593Smuzhiyun 			cfg->assoclist.count = 0;
2901*4882a593Smuzhiyun 			return -EOPNOTSUPP;
2902*4882a593Smuzhiyun 		}
2903*4882a593Smuzhiyun 	}
2904*4882a593Smuzhiyun 	if (idx < le32_to_cpu(cfg->assoclist.count)) {
2905*4882a593Smuzhiyun 		memcpy(mac, cfg->assoclist.mac[idx], ETH_ALEN);
2906*4882a593Smuzhiyun 		return brcmf_cfg80211_get_station(wiphy, ndev, mac, sinfo);
2907*4882a593Smuzhiyun 	}
2908*4882a593Smuzhiyun 	return -ENOENT;
2909*4882a593Smuzhiyun }
2910*4882a593Smuzhiyun 
2911*4882a593Smuzhiyun static s32
brcmf_cfg80211_set_power_mgmt(struct wiphy * wiphy,struct net_device * ndev,bool enabled,s32 timeout)2912*4882a593Smuzhiyun brcmf_cfg80211_set_power_mgmt(struct wiphy *wiphy, struct net_device *ndev,
2913*4882a593Smuzhiyun 			   bool enabled, s32 timeout)
2914*4882a593Smuzhiyun {
2915*4882a593Smuzhiyun 	s32 pm;
2916*4882a593Smuzhiyun 	s32 err = 0;
2917*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
2918*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
2919*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
2920*4882a593Smuzhiyun 
2921*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
2922*4882a593Smuzhiyun 
2923*4882a593Smuzhiyun 	/*
2924*4882a593Smuzhiyun 	 * Powersave enable/disable request is coming from the
2925*4882a593Smuzhiyun 	 * cfg80211 even before the interface is up. In that
2926*4882a593Smuzhiyun 	 * scenario, driver will be storing the power save
2927*4882a593Smuzhiyun 	 * preference in cfg struct to apply this to
2928*4882a593Smuzhiyun 	 * FW later while initializing the dongle
2929*4882a593Smuzhiyun 	 */
2930*4882a593Smuzhiyun 	cfg->pwr_save = enabled;
2931*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif)) {
2932*4882a593Smuzhiyun 
2933*4882a593Smuzhiyun 		brcmf_dbg(INFO, "Device is not ready, storing the value in cfg_info struct\n");
2934*4882a593Smuzhiyun 		goto done;
2935*4882a593Smuzhiyun 	}
2936*4882a593Smuzhiyun 
2937*4882a593Smuzhiyun 	pm = enabled ? PM_FAST : PM_OFF;
2938*4882a593Smuzhiyun 	/* Do not enable the power save after assoc if it is a p2p interface */
2939*4882a593Smuzhiyun 	if (ifp->vif->wdev.iftype == NL80211_IFTYPE_P2P_CLIENT) {
2940*4882a593Smuzhiyun 		brcmf_dbg(INFO, "Do not enable power save for P2P clients\n");
2941*4882a593Smuzhiyun 		pm = PM_OFF;
2942*4882a593Smuzhiyun 	}
2943*4882a593Smuzhiyun 	brcmf_dbg(INFO, "power save %s\n", (pm ? "enabled" : "disabled"));
2944*4882a593Smuzhiyun 
2945*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_PM, pm);
2946*4882a593Smuzhiyun 	if (err) {
2947*4882a593Smuzhiyun 		if (err == -ENODEV)
2948*4882a593Smuzhiyun 			bphy_err(drvr, "net_device is not ready yet\n");
2949*4882a593Smuzhiyun 		else
2950*4882a593Smuzhiyun 			bphy_err(drvr, "error (%d)\n", err);
2951*4882a593Smuzhiyun 	}
2952*4882a593Smuzhiyun 
2953*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_set(ifp, "pm2_sleep_ret",
2954*4882a593Smuzhiyun 				min_t(u32, timeout, BRCMF_PS_MAX_TIMEOUT_MS));
2955*4882a593Smuzhiyun 	if (err)
2956*4882a593Smuzhiyun 		bphy_err(drvr, "Unable to set pm timeout, (%d)\n", err);
2957*4882a593Smuzhiyun 
2958*4882a593Smuzhiyun done:
2959*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
2960*4882a593Smuzhiyun 	return err;
2961*4882a593Smuzhiyun }
2962*4882a593Smuzhiyun 
brcmf_inform_single_bss(struct brcmf_cfg80211_info * cfg,struct brcmf_bss_info_le * bi)2963*4882a593Smuzhiyun static s32 brcmf_inform_single_bss(struct brcmf_cfg80211_info *cfg,
2964*4882a593Smuzhiyun 				   struct brcmf_bss_info_le *bi)
2965*4882a593Smuzhiyun {
2966*4882a593Smuzhiyun 	struct wiphy *wiphy = cfg_to_wiphy(cfg);
2967*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
2968*4882a593Smuzhiyun 	struct cfg80211_bss *bss;
2969*4882a593Smuzhiyun 	enum nl80211_band band;
2970*4882a593Smuzhiyun 	struct brcmu_chan ch;
2971*4882a593Smuzhiyun 	u16 channel;
2972*4882a593Smuzhiyun 	u32 freq;
2973*4882a593Smuzhiyun 	u16 notify_capability;
2974*4882a593Smuzhiyun 	u16 notify_interval;
2975*4882a593Smuzhiyun 	u8 *notify_ie;
2976*4882a593Smuzhiyun 	size_t notify_ielen;
2977*4882a593Smuzhiyun 	struct cfg80211_inform_bss bss_data = {};
2978*4882a593Smuzhiyun 
2979*4882a593Smuzhiyun 	if (le32_to_cpu(bi->length) > WL_BSS_INFO_MAX) {
2980*4882a593Smuzhiyun 		bphy_err(drvr, "Bss info is larger than buffer. Discarding\n");
2981*4882a593Smuzhiyun 		return -EINVAL;
2982*4882a593Smuzhiyun 	}
2983*4882a593Smuzhiyun 
2984*4882a593Smuzhiyun 	if (!bi->ctl_ch) {
2985*4882a593Smuzhiyun 		ch.chspec = le16_to_cpu(bi->chanspec);
2986*4882a593Smuzhiyun 		cfg->d11inf.decchspec(&ch);
2987*4882a593Smuzhiyun 		bi->ctl_ch = ch.control_ch_num;
2988*4882a593Smuzhiyun 	}
2989*4882a593Smuzhiyun 	channel = bi->ctl_ch;
2990*4882a593Smuzhiyun 
2991*4882a593Smuzhiyun 	if (channel <= CH_MAX_2G_CHANNEL)
2992*4882a593Smuzhiyun 		band = NL80211_BAND_2GHZ;
2993*4882a593Smuzhiyun 	else
2994*4882a593Smuzhiyun 		band = NL80211_BAND_5GHZ;
2995*4882a593Smuzhiyun 
2996*4882a593Smuzhiyun 	freq = ieee80211_channel_to_frequency(channel, band);
2997*4882a593Smuzhiyun 	bss_data.chan = ieee80211_get_channel(wiphy, freq);
2998*4882a593Smuzhiyun 	bss_data.scan_width = NL80211_BSS_CHAN_WIDTH_20;
2999*4882a593Smuzhiyun 	bss_data.boottime_ns = ktime_to_ns(ktime_get_boottime());
3000*4882a593Smuzhiyun 
3001*4882a593Smuzhiyun 	notify_capability = le16_to_cpu(bi->capability);
3002*4882a593Smuzhiyun 	notify_interval = le16_to_cpu(bi->beacon_period);
3003*4882a593Smuzhiyun 	notify_ie = (u8 *)bi + le16_to_cpu(bi->ie_offset);
3004*4882a593Smuzhiyun 	notify_ielen = le32_to_cpu(bi->ie_length);
3005*4882a593Smuzhiyun 	bss_data.signal = (s16)le16_to_cpu(bi->RSSI) * 100;
3006*4882a593Smuzhiyun 
3007*4882a593Smuzhiyun 	brcmf_dbg(CONN, "bssid: %pM\n", bi->BSSID);
3008*4882a593Smuzhiyun 	brcmf_dbg(CONN, "Channel: %d(%d)\n", channel, freq);
3009*4882a593Smuzhiyun 	brcmf_dbg(CONN, "Capability: %X\n", notify_capability);
3010*4882a593Smuzhiyun 	brcmf_dbg(CONN, "Beacon interval: %d\n", notify_interval);
3011*4882a593Smuzhiyun 	brcmf_dbg(CONN, "Signal: %d\n", bss_data.signal);
3012*4882a593Smuzhiyun 
3013*4882a593Smuzhiyun 	bss = cfg80211_inform_bss_data(wiphy, &bss_data,
3014*4882a593Smuzhiyun 				       CFG80211_BSS_FTYPE_UNKNOWN,
3015*4882a593Smuzhiyun 				       (const u8 *)bi->BSSID,
3016*4882a593Smuzhiyun 				       0, notify_capability,
3017*4882a593Smuzhiyun 				       notify_interval, notify_ie,
3018*4882a593Smuzhiyun 				       notify_ielen, GFP_KERNEL);
3019*4882a593Smuzhiyun 
3020*4882a593Smuzhiyun 	if (!bss)
3021*4882a593Smuzhiyun 		return -ENOMEM;
3022*4882a593Smuzhiyun 
3023*4882a593Smuzhiyun 	cfg80211_put_bss(wiphy, bss);
3024*4882a593Smuzhiyun 
3025*4882a593Smuzhiyun 	return 0;
3026*4882a593Smuzhiyun }
3027*4882a593Smuzhiyun 
3028*4882a593Smuzhiyun static struct brcmf_bss_info_le *
next_bss_le(struct brcmf_scan_results * list,struct brcmf_bss_info_le * bss)3029*4882a593Smuzhiyun next_bss_le(struct brcmf_scan_results *list, struct brcmf_bss_info_le *bss)
3030*4882a593Smuzhiyun {
3031*4882a593Smuzhiyun 	if (bss == NULL)
3032*4882a593Smuzhiyun 		return list->bss_info_le;
3033*4882a593Smuzhiyun 	return (struct brcmf_bss_info_le *)((unsigned long)bss +
3034*4882a593Smuzhiyun 					    le32_to_cpu(bss->length));
3035*4882a593Smuzhiyun }
3036*4882a593Smuzhiyun 
brcmf_inform_bss(struct brcmf_cfg80211_info * cfg)3037*4882a593Smuzhiyun static s32 brcmf_inform_bss(struct brcmf_cfg80211_info *cfg)
3038*4882a593Smuzhiyun {
3039*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
3040*4882a593Smuzhiyun 	struct brcmf_scan_results *bss_list;
3041*4882a593Smuzhiyun 	struct brcmf_bss_info_le *bi = NULL;	/* must be initialized */
3042*4882a593Smuzhiyun 	s32 err = 0;
3043*4882a593Smuzhiyun 	int i;
3044*4882a593Smuzhiyun 
3045*4882a593Smuzhiyun 	bss_list = (struct brcmf_scan_results *)cfg->escan_info.escan_buf;
3046*4882a593Smuzhiyun 	if (bss_list->count != 0 &&
3047*4882a593Smuzhiyun 	    bss_list->version != BRCMF_BSS_INFO_VERSION) {
3048*4882a593Smuzhiyun 		bphy_err(drvr, "Version %d != WL_BSS_INFO_VERSION\n",
3049*4882a593Smuzhiyun 			 bss_list->version);
3050*4882a593Smuzhiyun 		return -EOPNOTSUPP;
3051*4882a593Smuzhiyun 	}
3052*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "scanned AP count (%d)\n", bss_list->count);
3053*4882a593Smuzhiyun 	for (i = 0; i < bss_list->count; i++) {
3054*4882a593Smuzhiyun 		bi = next_bss_le(bss_list, bi);
3055*4882a593Smuzhiyun 		err = brcmf_inform_single_bss(cfg, bi);
3056*4882a593Smuzhiyun 		if (err)
3057*4882a593Smuzhiyun 			break;
3058*4882a593Smuzhiyun 	}
3059*4882a593Smuzhiyun 	return err;
3060*4882a593Smuzhiyun }
3061*4882a593Smuzhiyun 
brcmf_inform_ibss(struct brcmf_cfg80211_info * cfg,struct net_device * ndev,const u8 * bssid)3062*4882a593Smuzhiyun static s32 brcmf_inform_ibss(struct brcmf_cfg80211_info *cfg,
3063*4882a593Smuzhiyun 			     struct net_device *ndev, const u8 *bssid)
3064*4882a593Smuzhiyun {
3065*4882a593Smuzhiyun 	struct wiphy *wiphy = cfg_to_wiphy(cfg);
3066*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
3067*4882a593Smuzhiyun 	struct ieee80211_channel *notify_channel;
3068*4882a593Smuzhiyun 	struct brcmf_bss_info_le *bi = NULL;
3069*4882a593Smuzhiyun 	struct ieee80211_supported_band *band;
3070*4882a593Smuzhiyun 	struct cfg80211_bss *bss;
3071*4882a593Smuzhiyun 	struct brcmu_chan ch;
3072*4882a593Smuzhiyun 	u8 *buf = NULL;
3073*4882a593Smuzhiyun 	s32 err = 0;
3074*4882a593Smuzhiyun 	u32 freq;
3075*4882a593Smuzhiyun 	u16 notify_capability;
3076*4882a593Smuzhiyun 	u16 notify_interval;
3077*4882a593Smuzhiyun 	u8 *notify_ie;
3078*4882a593Smuzhiyun 	size_t notify_ielen;
3079*4882a593Smuzhiyun 	s32 notify_signal;
3080*4882a593Smuzhiyun 
3081*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
3082*4882a593Smuzhiyun 
3083*4882a593Smuzhiyun 	buf = kzalloc(WL_BSS_INFO_MAX, GFP_KERNEL);
3084*4882a593Smuzhiyun 	if (buf == NULL) {
3085*4882a593Smuzhiyun 		err = -ENOMEM;
3086*4882a593Smuzhiyun 		goto CleanUp;
3087*4882a593Smuzhiyun 	}
3088*4882a593Smuzhiyun 
3089*4882a593Smuzhiyun 	*(__le32 *)buf = cpu_to_le32(WL_BSS_INFO_MAX);
3090*4882a593Smuzhiyun 
3091*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_get(netdev_priv(ndev), BRCMF_C_GET_BSS_INFO,
3092*4882a593Smuzhiyun 				     buf, WL_BSS_INFO_MAX);
3093*4882a593Smuzhiyun 	if (err) {
3094*4882a593Smuzhiyun 		bphy_err(drvr, "WLC_GET_BSS_INFO failed: %d\n", err);
3095*4882a593Smuzhiyun 		goto CleanUp;
3096*4882a593Smuzhiyun 	}
3097*4882a593Smuzhiyun 
3098*4882a593Smuzhiyun 	bi = (struct brcmf_bss_info_le *)(buf + 4);
3099*4882a593Smuzhiyun 
3100*4882a593Smuzhiyun 	ch.chspec = le16_to_cpu(bi->chanspec);
3101*4882a593Smuzhiyun 	cfg->d11inf.decchspec(&ch);
3102*4882a593Smuzhiyun 
3103*4882a593Smuzhiyun 	if (ch.band == BRCMU_CHAN_BAND_2G)
3104*4882a593Smuzhiyun 		band = wiphy->bands[NL80211_BAND_2GHZ];
3105*4882a593Smuzhiyun 	else
3106*4882a593Smuzhiyun 		band = wiphy->bands[NL80211_BAND_5GHZ];
3107*4882a593Smuzhiyun 
3108*4882a593Smuzhiyun 	freq = ieee80211_channel_to_frequency(ch.control_ch_num, band->band);
3109*4882a593Smuzhiyun 	cfg->channel = freq;
3110*4882a593Smuzhiyun 	notify_channel = ieee80211_get_channel(wiphy, freq);
3111*4882a593Smuzhiyun 
3112*4882a593Smuzhiyun 	notify_capability = le16_to_cpu(bi->capability);
3113*4882a593Smuzhiyun 	notify_interval = le16_to_cpu(bi->beacon_period);
3114*4882a593Smuzhiyun 	notify_ie = (u8 *)bi + le16_to_cpu(bi->ie_offset);
3115*4882a593Smuzhiyun 	notify_ielen = le32_to_cpu(bi->ie_length);
3116*4882a593Smuzhiyun 	notify_signal = (s16)le16_to_cpu(bi->RSSI) * 100;
3117*4882a593Smuzhiyun 
3118*4882a593Smuzhiyun 	brcmf_dbg(CONN, "channel: %d(%d)\n", ch.control_ch_num, freq);
3119*4882a593Smuzhiyun 	brcmf_dbg(CONN, "capability: %X\n", notify_capability);
3120*4882a593Smuzhiyun 	brcmf_dbg(CONN, "beacon interval: %d\n", notify_interval);
3121*4882a593Smuzhiyun 	brcmf_dbg(CONN, "signal: %d\n", notify_signal);
3122*4882a593Smuzhiyun 
3123*4882a593Smuzhiyun 	bss = cfg80211_inform_bss(wiphy, notify_channel,
3124*4882a593Smuzhiyun 				  CFG80211_BSS_FTYPE_UNKNOWN, bssid, 0,
3125*4882a593Smuzhiyun 				  notify_capability, notify_interval,
3126*4882a593Smuzhiyun 				  notify_ie, notify_ielen, notify_signal,
3127*4882a593Smuzhiyun 				  GFP_KERNEL);
3128*4882a593Smuzhiyun 
3129*4882a593Smuzhiyun 	if (!bss) {
3130*4882a593Smuzhiyun 		err = -ENOMEM;
3131*4882a593Smuzhiyun 		goto CleanUp;
3132*4882a593Smuzhiyun 	}
3133*4882a593Smuzhiyun 
3134*4882a593Smuzhiyun 	cfg80211_put_bss(wiphy, bss);
3135*4882a593Smuzhiyun 
3136*4882a593Smuzhiyun CleanUp:
3137*4882a593Smuzhiyun 
3138*4882a593Smuzhiyun 	kfree(buf);
3139*4882a593Smuzhiyun 
3140*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
3141*4882a593Smuzhiyun 
3142*4882a593Smuzhiyun 	return err;
3143*4882a593Smuzhiyun }
3144*4882a593Smuzhiyun 
brcmf_update_bss_info(struct brcmf_cfg80211_info * cfg,struct brcmf_if * ifp)3145*4882a593Smuzhiyun static s32 brcmf_update_bss_info(struct brcmf_cfg80211_info *cfg,
3146*4882a593Smuzhiyun 				 struct brcmf_if *ifp)
3147*4882a593Smuzhiyun {
3148*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
3149*4882a593Smuzhiyun 	struct brcmf_bss_info_le *bi;
3150*4882a593Smuzhiyun 	const struct brcmf_tlv *tim;
3151*4882a593Smuzhiyun 	size_t ie_len;
3152*4882a593Smuzhiyun 	u8 *ie;
3153*4882a593Smuzhiyun 	s32 err = 0;
3154*4882a593Smuzhiyun 
3155*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
3156*4882a593Smuzhiyun 	if (brcmf_is_ibssmode(ifp->vif))
3157*4882a593Smuzhiyun 		return err;
3158*4882a593Smuzhiyun 
3159*4882a593Smuzhiyun 	*(__le32 *)cfg->extra_buf = cpu_to_le32(WL_EXTRA_BUF_MAX);
3160*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_get(ifp, BRCMF_C_GET_BSS_INFO,
3161*4882a593Smuzhiyun 				     cfg->extra_buf, WL_EXTRA_BUF_MAX);
3162*4882a593Smuzhiyun 	if (err) {
3163*4882a593Smuzhiyun 		bphy_err(drvr, "Could not get bss info %d\n", err);
3164*4882a593Smuzhiyun 		goto update_bss_info_out;
3165*4882a593Smuzhiyun 	}
3166*4882a593Smuzhiyun 
3167*4882a593Smuzhiyun 	bi = (struct brcmf_bss_info_le *)(cfg->extra_buf + 4);
3168*4882a593Smuzhiyun 	err = brcmf_inform_single_bss(cfg, bi);
3169*4882a593Smuzhiyun 	if (err)
3170*4882a593Smuzhiyun 		goto update_bss_info_out;
3171*4882a593Smuzhiyun 
3172*4882a593Smuzhiyun 	ie = ((u8 *)bi) + le16_to_cpu(bi->ie_offset);
3173*4882a593Smuzhiyun 	ie_len = le32_to_cpu(bi->ie_length);
3174*4882a593Smuzhiyun 
3175*4882a593Smuzhiyun 	tim = brcmf_parse_tlvs(ie, ie_len, WLAN_EID_TIM);
3176*4882a593Smuzhiyun 	if (!tim) {
3177*4882a593Smuzhiyun 		/*
3178*4882a593Smuzhiyun 		* active scan was done so we could not get dtim
3179*4882a593Smuzhiyun 		* information out of probe response.
3180*4882a593Smuzhiyun 		* so we speficially query dtim information to dongle.
3181*4882a593Smuzhiyun 		*/
3182*4882a593Smuzhiyun 		u32 var;
3183*4882a593Smuzhiyun 		err = brcmf_fil_iovar_int_get(ifp, "dtim_assoc", &var);
3184*4882a593Smuzhiyun 		if (err) {
3185*4882a593Smuzhiyun 			bphy_err(drvr, "wl dtim_assoc failed (%d)\n", err);
3186*4882a593Smuzhiyun 			goto update_bss_info_out;
3187*4882a593Smuzhiyun 		}
3188*4882a593Smuzhiyun 	}
3189*4882a593Smuzhiyun 
3190*4882a593Smuzhiyun update_bss_info_out:
3191*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit");
3192*4882a593Smuzhiyun 	return err;
3193*4882a593Smuzhiyun }
3194*4882a593Smuzhiyun 
brcmf_abort_scanning(struct brcmf_cfg80211_info * cfg)3195*4882a593Smuzhiyun void brcmf_abort_scanning(struct brcmf_cfg80211_info *cfg)
3196*4882a593Smuzhiyun {
3197*4882a593Smuzhiyun 	struct escan_info *escan = &cfg->escan_info;
3198*4882a593Smuzhiyun 
3199*4882a593Smuzhiyun 	set_bit(BRCMF_SCAN_STATUS_ABORT, &cfg->scan_status);
3200*4882a593Smuzhiyun 	if (cfg->int_escan_map || cfg->scan_request) {
3201*4882a593Smuzhiyun 		escan->escan_state = WL_ESCAN_STATE_IDLE;
3202*4882a593Smuzhiyun 		brcmf_notify_escan_complete(cfg, escan->ifp, true, true);
3203*4882a593Smuzhiyun 	}
3204*4882a593Smuzhiyun 	clear_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status);
3205*4882a593Smuzhiyun 	clear_bit(BRCMF_SCAN_STATUS_ABORT, &cfg->scan_status);
3206*4882a593Smuzhiyun }
3207*4882a593Smuzhiyun 
brcmf_cfg80211_escan_timeout_worker(struct work_struct * work)3208*4882a593Smuzhiyun static void brcmf_cfg80211_escan_timeout_worker(struct work_struct *work)
3209*4882a593Smuzhiyun {
3210*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg =
3211*4882a593Smuzhiyun 			container_of(work, struct brcmf_cfg80211_info,
3212*4882a593Smuzhiyun 				     escan_timeout_work);
3213*4882a593Smuzhiyun 
3214*4882a593Smuzhiyun 	brcmf_inform_bss(cfg);
3215*4882a593Smuzhiyun 	brcmf_notify_escan_complete(cfg, cfg->escan_info.ifp, true, true);
3216*4882a593Smuzhiyun }
3217*4882a593Smuzhiyun 
brcmf_escan_timeout(struct timer_list * t)3218*4882a593Smuzhiyun static void brcmf_escan_timeout(struct timer_list *t)
3219*4882a593Smuzhiyun {
3220*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg =
3221*4882a593Smuzhiyun 			from_timer(cfg, t, escan_timeout);
3222*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
3223*4882a593Smuzhiyun 
3224*4882a593Smuzhiyun 	if (cfg->int_escan_map || cfg->scan_request) {
3225*4882a593Smuzhiyun 		bphy_err(drvr, "timer expired\n");
3226*4882a593Smuzhiyun 		schedule_work(&cfg->escan_timeout_work);
3227*4882a593Smuzhiyun 	}
3228*4882a593Smuzhiyun }
3229*4882a593Smuzhiyun 
3230*4882a593Smuzhiyun static s32
brcmf_compare_update_same_bss(struct brcmf_cfg80211_info * cfg,struct brcmf_bss_info_le * bss,struct brcmf_bss_info_le * bss_info_le)3231*4882a593Smuzhiyun brcmf_compare_update_same_bss(struct brcmf_cfg80211_info *cfg,
3232*4882a593Smuzhiyun 			      struct brcmf_bss_info_le *bss,
3233*4882a593Smuzhiyun 			      struct brcmf_bss_info_le *bss_info_le)
3234*4882a593Smuzhiyun {
3235*4882a593Smuzhiyun 	struct brcmu_chan ch_bss, ch_bss_info_le;
3236*4882a593Smuzhiyun 
3237*4882a593Smuzhiyun 	ch_bss.chspec = le16_to_cpu(bss->chanspec);
3238*4882a593Smuzhiyun 	cfg->d11inf.decchspec(&ch_bss);
3239*4882a593Smuzhiyun 	ch_bss_info_le.chspec = le16_to_cpu(bss_info_le->chanspec);
3240*4882a593Smuzhiyun 	cfg->d11inf.decchspec(&ch_bss_info_le);
3241*4882a593Smuzhiyun 
3242*4882a593Smuzhiyun 	if (!memcmp(&bss_info_le->BSSID, &bss->BSSID, ETH_ALEN) &&
3243*4882a593Smuzhiyun 		ch_bss.band == ch_bss_info_le.band &&
3244*4882a593Smuzhiyun 		bss_info_le->SSID_len == bss->SSID_len &&
3245*4882a593Smuzhiyun 		!memcmp(bss_info_le->SSID, bss->SSID, bss_info_le->SSID_len)) {
3246*4882a593Smuzhiyun 		if ((bss->flags & BRCMF_BSS_RSSI_ON_CHANNEL) ==
3247*4882a593Smuzhiyun 			(bss_info_le->flags & BRCMF_BSS_RSSI_ON_CHANNEL)) {
3248*4882a593Smuzhiyun 			s16 bss_rssi = le16_to_cpu(bss->RSSI);
3249*4882a593Smuzhiyun 			s16 bss_info_rssi = le16_to_cpu(bss_info_le->RSSI);
3250*4882a593Smuzhiyun 
3251*4882a593Smuzhiyun 			/* preserve max RSSI if the measurements are
3252*4882a593Smuzhiyun 			* both on-channel or both off-channel
3253*4882a593Smuzhiyun 			*/
3254*4882a593Smuzhiyun 			if (bss_info_rssi > bss_rssi)
3255*4882a593Smuzhiyun 				bss->RSSI = bss_info_le->RSSI;
3256*4882a593Smuzhiyun 		} else if ((bss->flags & BRCMF_BSS_RSSI_ON_CHANNEL) &&
3257*4882a593Smuzhiyun 			(bss_info_le->flags & BRCMF_BSS_RSSI_ON_CHANNEL) == 0) {
3258*4882a593Smuzhiyun 			/* preserve the on-channel rssi measurement
3259*4882a593Smuzhiyun 			* if the new measurement is off channel
3260*4882a593Smuzhiyun 			*/
3261*4882a593Smuzhiyun 			bss->RSSI = bss_info_le->RSSI;
3262*4882a593Smuzhiyun 			bss->flags |= BRCMF_BSS_RSSI_ON_CHANNEL;
3263*4882a593Smuzhiyun 		}
3264*4882a593Smuzhiyun 		return 1;
3265*4882a593Smuzhiyun 	}
3266*4882a593Smuzhiyun 	return 0;
3267*4882a593Smuzhiyun }
3268*4882a593Smuzhiyun 
3269*4882a593Smuzhiyun static s32
brcmf_cfg80211_escan_handler(struct brcmf_if * ifp,const struct brcmf_event_msg * e,void * data)3270*4882a593Smuzhiyun brcmf_cfg80211_escan_handler(struct brcmf_if *ifp,
3271*4882a593Smuzhiyun 			     const struct brcmf_event_msg *e, void *data)
3272*4882a593Smuzhiyun {
3273*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
3274*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = drvr->config;
3275*4882a593Smuzhiyun 	s32 status;
3276*4882a593Smuzhiyun 	struct brcmf_escan_result_le *escan_result_le;
3277*4882a593Smuzhiyun 	u32 escan_buflen;
3278*4882a593Smuzhiyun 	struct brcmf_bss_info_le *bss_info_le;
3279*4882a593Smuzhiyun 	struct brcmf_bss_info_le *bss = NULL;
3280*4882a593Smuzhiyun 	u32 bi_length;
3281*4882a593Smuzhiyun 	struct brcmf_scan_results *list;
3282*4882a593Smuzhiyun 	u32 i;
3283*4882a593Smuzhiyun 	bool aborted;
3284*4882a593Smuzhiyun 
3285*4882a593Smuzhiyun 	status = e->status;
3286*4882a593Smuzhiyun 
3287*4882a593Smuzhiyun 	if (status == BRCMF_E_STATUS_ABORT)
3288*4882a593Smuzhiyun 		goto exit;
3289*4882a593Smuzhiyun 
3290*4882a593Smuzhiyun 	if (!test_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status)) {
3291*4882a593Smuzhiyun 		bphy_err(drvr, "scan not ready, bsscfgidx=%d\n",
3292*4882a593Smuzhiyun 			 ifp->bsscfgidx);
3293*4882a593Smuzhiyun 		return -EPERM;
3294*4882a593Smuzhiyun 	}
3295*4882a593Smuzhiyun 
3296*4882a593Smuzhiyun 	if (status == BRCMF_E_STATUS_PARTIAL) {
3297*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "ESCAN Partial result\n");
3298*4882a593Smuzhiyun 		if (e->datalen < sizeof(*escan_result_le)) {
3299*4882a593Smuzhiyun 			bphy_err(drvr, "invalid event data length\n");
3300*4882a593Smuzhiyun 			goto exit;
3301*4882a593Smuzhiyun 		}
3302*4882a593Smuzhiyun 		escan_result_le = (struct brcmf_escan_result_le *) data;
3303*4882a593Smuzhiyun 		if (!escan_result_le) {
3304*4882a593Smuzhiyun 			bphy_err(drvr, "Invalid escan result (NULL pointer)\n");
3305*4882a593Smuzhiyun 			goto exit;
3306*4882a593Smuzhiyun 		}
3307*4882a593Smuzhiyun 		escan_buflen = le32_to_cpu(escan_result_le->buflen);
3308*4882a593Smuzhiyun 		if (escan_buflen > BRCMF_ESCAN_BUF_SIZE ||
3309*4882a593Smuzhiyun 		    escan_buflen > e->datalen ||
3310*4882a593Smuzhiyun 		    escan_buflen < sizeof(*escan_result_le)) {
3311*4882a593Smuzhiyun 			bphy_err(drvr, "Invalid escan buffer length: %d\n",
3312*4882a593Smuzhiyun 				 escan_buflen);
3313*4882a593Smuzhiyun 			goto exit;
3314*4882a593Smuzhiyun 		}
3315*4882a593Smuzhiyun 		if (le16_to_cpu(escan_result_le->bss_count) != 1) {
3316*4882a593Smuzhiyun 			bphy_err(drvr, "Invalid bss_count %d: ignoring\n",
3317*4882a593Smuzhiyun 				 escan_result_le->bss_count);
3318*4882a593Smuzhiyun 			goto exit;
3319*4882a593Smuzhiyun 		}
3320*4882a593Smuzhiyun 		bss_info_le = &escan_result_le->bss_info_le;
3321*4882a593Smuzhiyun 
3322*4882a593Smuzhiyun 		if (brcmf_p2p_scan_finding_common_channel(cfg, bss_info_le))
3323*4882a593Smuzhiyun 			goto exit;
3324*4882a593Smuzhiyun 
3325*4882a593Smuzhiyun 		if (!cfg->int_escan_map && !cfg->scan_request) {
3326*4882a593Smuzhiyun 			brcmf_dbg(SCAN, "result without cfg80211 request\n");
3327*4882a593Smuzhiyun 			goto exit;
3328*4882a593Smuzhiyun 		}
3329*4882a593Smuzhiyun 
3330*4882a593Smuzhiyun 		bi_length = le32_to_cpu(bss_info_le->length);
3331*4882a593Smuzhiyun 		if (bi_length != escan_buflen -	WL_ESCAN_RESULTS_FIXED_SIZE) {
3332*4882a593Smuzhiyun 			bphy_err(drvr, "Ignoring invalid bss_info length: %d\n",
3333*4882a593Smuzhiyun 				 bi_length);
3334*4882a593Smuzhiyun 			goto exit;
3335*4882a593Smuzhiyun 		}
3336*4882a593Smuzhiyun 
3337*4882a593Smuzhiyun 		if (!(cfg_to_wiphy(cfg)->interface_modes &
3338*4882a593Smuzhiyun 					BIT(NL80211_IFTYPE_ADHOC))) {
3339*4882a593Smuzhiyun 			if (le16_to_cpu(bss_info_le->capability) &
3340*4882a593Smuzhiyun 						WLAN_CAPABILITY_IBSS) {
3341*4882a593Smuzhiyun 				bphy_err(drvr, "Ignoring IBSS result\n");
3342*4882a593Smuzhiyun 				goto exit;
3343*4882a593Smuzhiyun 			}
3344*4882a593Smuzhiyun 		}
3345*4882a593Smuzhiyun 
3346*4882a593Smuzhiyun 		list = (struct brcmf_scan_results *)
3347*4882a593Smuzhiyun 				cfg->escan_info.escan_buf;
3348*4882a593Smuzhiyun 		if (bi_length > BRCMF_ESCAN_BUF_SIZE - list->buflen) {
3349*4882a593Smuzhiyun 			bphy_err(drvr, "Buffer is too small: ignoring\n");
3350*4882a593Smuzhiyun 			goto exit;
3351*4882a593Smuzhiyun 		}
3352*4882a593Smuzhiyun 
3353*4882a593Smuzhiyun 		for (i = 0; i < list->count; i++) {
3354*4882a593Smuzhiyun 			bss = bss ? (struct brcmf_bss_info_le *)
3355*4882a593Smuzhiyun 				((unsigned char *)bss +
3356*4882a593Smuzhiyun 				le32_to_cpu(bss->length)) : list->bss_info_le;
3357*4882a593Smuzhiyun 			if (brcmf_compare_update_same_bss(cfg, bss,
3358*4882a593Smuzhiyun 							  bss_info_le))
3359*4882a593Smuzhiyun 				goto exit;
3360*4882a593Smuzhiyun 		}
3361*4882a593Smuzhiyun 		memcpy(&cfg->escan_info.escan_buf[list->buflen], bss_info_le,
3362*4882a593Smuzhiyun 		       bi_length);
3363*4882a593Smuzhiyun 		list->version = le32_to_cpu(bss_info_le->version);
3364*4882a593Smuzhiyun 		list->buflen += bi_length;
3365*4882a593Smuzhiyun 		list->count++;
3366*4882a593Smuzhiyun 	} else {
3367*4882a593Smuzhiyun 		cfg->escan_info.escan_state = WL_ESCAN_STATE_IDLE;
3368*4882a593Smuzhiyun 		if (brcmf_p2p_scan_finding_common_channel(cfg, NULL))
3369*4882a593Smuzhiyun 			goto exit;
3370*4882a593Smuzhiyun 		if (cfg->int_escan_map || cfg->scan_request) {
3371*4882a593Smuzhiyun 			brcmf_inform_bss(cfg);
3372*4882a593Smuzhiyun 			aborted = status != BRCMF_E_STATUS_SUCCESS;
3373*4882a593Smuzhiyun 			brcmf_notify_escan_complete(cfg, ifp, aborted, false);
3374*4882a593Smuzhiyun 		} else
3375*4882a593Smuzhiyun 			brcmf_dbg(SCAN, "Ignored scan complete result 0x%x\n",
3376*4882a593Smuzhiyun 				  status);
3377*4882a593Smuzhiyun 	}
3378*4882a593Smuzhiyun exit:
3379*4882a593Smuzhiyun 	return 0;
3380*4882a593Smuzhiyun }
3381*4882a593Smuzhiyun 
brcmf_init_escan(struct brcmf_cfg80211_info * cfg)3382*4882a593Smuzhiyun static void brcmf_init_escan(struct brcmf_cfg80211_info *cfg)
3383*4882a593Smuzhiyun {
3384*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_ESCAN_RESULT,
3385*4882a593Smuzhiyun 			    brcmf_cfg80211_escan_handler);
3386*4882a593Smuzhiyun 	cfg->escan_info.escan_state = WL_ESCAN_STATE_IDLE;
3387*4882a593Smuzhiyun 	/* Init scan_timeout timer */
3388*4882a593Smuzhiyun 	timer_setup(&cfg->escan_timeout, brcmf_escan_timeout, 0);
3389*4882a593Smuzhiyun 	INIT_WORK(&cfg->escan_timeout_work,
3390*4882a593Smuzhiyun 		  brcmf_cfg80211_escan_timeout_worker);
3391*4882a593Smuzhiyun }
3392*4882a593Smuzhiyun 
3393*4882a593Smuzhiyun static struct cfg80211_scan_request *
brcmf_alloc_internal_escan_request(struct wiphy * wiphy,u32 n_netinfo)3394*4882a593Smuzhiyun brcmf_alloc_internal_escan_request(struct wiphy *wiphy, u32 n_netinfo) {
3395*4882a593Smuzhiyun 	struct cfg80211_scan_request *req;
3396*4882a593Smuzhiyun 	size_t req_size;
3397*4882a593Smuzhiyun 
3398*4882a593Smuzhiyun 	req_size = sizeof(*req) +
3399*4882a593Smuzhiyun 		   n_netinfo * sizeof(req->channels[0]) +
3400*4882a593Smuzhiyun 		   n_netinfo * sizeof(*req->ssids);
3401*4882a593Smuzhiyun 
3402*4882a593Smuzhiyun 	req = kzalloc(req_size, GFP_KERNEL);
3403*4882a593Smuzhiyun 	if (req) {
3404*4882a593Smuzhiyun 		req->wiphy = wiphy;
3405*4882a593Smuzhiyun 		req->ssids = (void *)(&req->channels[0]) +
3406*4882a593Smuzhiyun 			     n_netinfo * sizeof(req->channels[0]);
3407*4882a593Smuzhiyun 	}
3408*4882a593Smuzhiyun 	return req;
3409*4882a593Smuzhiyun }
3410*4882a593Smuzhiyun 
brcmf_internal_escan_add_info(struct cfg80211_scan_request * req,u8 * ssid,u8 ssid_len,u8 channel)3411*4882a593Smuzhiyun static int brcmf_internal_escan_add_info(struct cfg80211_scan_request *req,
3412*4882a593Smuzhiyun 					 u8 *ssid, u8 ssid_len, u8 channel)
3413*4882a593Smuzhiyun {
3414*4882a593Smuzhiyun 	struct ieee80211_channel *chan;
3415*4882a593Smuzhiyun 	enum nl80211_band band;
3416*4882a593Smuzhiyun 	int freq, i;
3417*4882a593Smuzhiyun 
3418*4882a593Smuzhiyun 	if (channel <= CH_MAX_2G_CHANNEL)
3419*4882a593Smuzhiyun 		band = NL80211_BAND_2GHZ;
3420*4882a593Smuzhiyun 	else
3421*4882a593Smuzhiyun 		band = NL80211_BAND_5GHZ;
3422*4882a593Smuzhiyun 
3423*4882a593Smuzhiyun 	freq = ieee80211_channel_to_frequency(channel, band);
3424*4882a593Smuzhiyun 	if (!freq)
3425*4882a593Smuzhiyun 		return -EINVAL;
3426*4882a593Smuzhiyun 
3427*4882a593Smuzhiyun 	chan = ieee80211_get_channel(req->wiphy, freq);
3428*4882a593Smuzhiyun 	if (!chan)
3429*4882a593Smuzhiyun 		return -EINVAL;
3430*4882a593Smuzhiyun 
3431*4882a593Smuzhiyun 	for (i = 0; i < req->n_channels; i++) {
3432*4882a593Smuzhiyun 		if (req->channels[i] == chan)
3433*4882a593Smuzhiyun 			break;
3434*4882a593Smuzhiyun 	}
3435*4882a593Smuzhiyun 	if (i == req->n_channels)
3436*4882a593Smuzhiyun 		req->channels[req->n_channels++] = chan;
3437*4882a593Smuzhiyun 
3438*4882a593Smuzhiyun 	for (i = 0; i < req->n_ssids; i++) {
3439*4882a593Smuzhiyun 		if (req->ssids[i].ssid_len == ssid_len &&
3440*4882a593Smuzhiyun 		    !memcmp(req->ssids[i].ssid, ssid, ssid_len))
3441*4882a593Smuzhiyun 			break;
3442*4882a593Smuzhiyun 	}
3443*4882a593Smuzhiyun 	if (i == req->n_ssids) {
3444*4882a593Smuzhiyun 		memcpy(req->ssids[req->n_ssids].ssid, ssid, ssid_len);
3445*4882a593Smuzhiyun 		req->ssids[req->n_ssids++].ssid_len = ssid_len;
3446*4882a593Smuzhiyun 	}
3447*4882a593Smuzhiyun 	return 0;
3448*4882a593Smuzhiyun }
3449*4882a593Smuzhiyun 
brcmf_start_internal_escan(struct brcmf_if * ifp,u32 fwmap,struct cfg80211_scan_request * request)3450*4882a593Smuzhiyun static int brcmf_start_internal_escan(struct brcmf_if *ifp, u32 fwmap,
3451*4882a593Smuzhiyun 				      struct cfg80211_scan_request *request)
3452*4882a593Smuzhiyun {
3453*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = ifp->drvr->config;
3454*4882a593Smuzhiyun 	int err;
3455*4882a593Smuzhiyun 
3456*4882a593Smuzhiyun 	if (test_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status)) {
3457*4882a593Smuzhiyun 		if (cfg->int_escan_map)
3458*4882a593Smuzhiyun 			brcmf_dbg(SCAN, "aborting internal scan: map=%u\n",
3459*4882a593Smuzhiyun 				  cfg->int_escan_map);
3460*4882a593Smuzhiyun 		/* Abort any on-going scan */
3461*4882a593Smuzhiyun 		brcmf_abort_scanning(cfg);
3462*4882a593Smuzhiyun 	}
3463*4882a593Smuzhiyun 
3464*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "start internal scan: map=%u\n", fwmap);
3465*4882a593Smuzhiyun 	set_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status);
3466*4882a593Smuzhiyun 	cfg->escan_info.run = brcmf_run_escan;
3467*4882a593Smuzhiyun 	err = brcmf_do_escan(ifp, request);
3468*4882a593Smuzhiyun 	if (err) {
3469*4882a593Smuzhiyun 		clear_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status);
3470*4882a593Smuzhiyun 		return err;
3471*4882a593Smuzhiyun 	}
3472*4882a593Smuzhiyun 	cfg->int_escan_map = fwmap;
3473*4882a593Smuzhiyun 	return 0;
3474*4882a593Smuzhiyun }
3475*4882a593Smuzhiyun 
3476*4882a593Smuzhiyun static struct brcmf_pno_net_info_le *
brcmf_get_netinfo_array(struct brcmf_pno_scanresults_le * pfn_v1)3477*4882a593Smuzhiyun brcmf_get_netinfo_array(struct brcmf_pno_scanresults_le *pfn_v1)
3478*4882a593Smuzhiyun {
3479*4882a593Smuzhiyun 	struct brcmf_pno_scanresults_v2_le *pfn_v2;
3480*4882a593Smuzhiyun 	struct brcmf_pno_net_info_le *netinfo;
3481*4882a593Smuzhiyun 
3482*4882a593Smuzhiyun 	switch (pfn_v1->version) {
3483*4882a593Smuzhiyun 	default:
3484*4882a593Smuzhiyun 		WARN_ON(1);
3485*4882a593Smuzhiyun 		fallthrough;
3486*4882a593Smuzhiyun 	case cpu_to_le32(1):
3487*4882a593Smuzhiyun 		netinfo = (struct brcmf_pno_net_info_le *)(pfn_v1 + 1);
3488*4882a593Smuzhiyun 		break;
3489*4882a593Smuzhiyun 	case cpu_to_le32(2):
3490*4882a593Smuzhiyun 		pfn_v2 = (struct brcmf_pno_scanresults_v2_le *)pfn_v1;
3491*4882a593Smuzhiyun 		netinfo = (struct brcmf_pno_net_info_le *)(pfn_v2 + 1);
3492*4882a593Smuzhiyun 		break;
3493*4882a593Smuzhiyun 	}
3494*4882a593Smuzhiyun 
3495*4882a593Smuzhiyun 	return netinfo;
3496*4882a593Smuzhiyun }
3497*4882a593Smuzhiyun 
3498*4882a593Smuzhiyun /* PFN result doesn't have all the info which are required by the supplicant
3499*4882a593Smuzhiyun  * (For e.g IEs) Do a target Escan so that sched scan results are reported
3500*4882a593Smuzhiyun  * via wl_inform_single_bss in the required format. Escan does require the
3501*4882a593Smuzhiyun  * scan request in the form of cfg80211_scan_request. For timebeing, create
3502*4882a593Smuzhiyun  * cfg80211_scan_request one out of the received PNO event.
3503*4882a593Smuzhiyun  */
3504*4882a593Smuzhiyun static s32
brcmf_notify_sched_scan_results(struct brcmf_if * ifp,const struct brcmf_event_msg * e,void * data)3505*4882a593Smuzhiyun brcmf_notify_sched_scan_results(struct brcmf_if *ifp,
3506*4882a593Smuzhiyun 				const struct brcmf_event_msg *e, void *data)
3507*4882a593Smuzhiyun {
3508*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
3509*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = drvr->config;
3510*4882a593Smuzhiyun 	struct brcmf_pno_net_info_le *netinfo, *netinfo_start;
3511*4882a593Smuzhiyun 	struct cfg80211_scan_request *request = NULL;
3512*4882a593Smuzhiyun 	struct wiphy *wiphy = cfg_to_wiphy(cfg);
3513*4882a593Smuzhiyun 	int i, err = 0;
3514*4882a593Smuzhiyun 	struct brcmf_pno_scanresults_le *pfn_result;
3515*4882a593Smuzhiyun 	u32 bucket_map;
3516*4882a593Smuzhiyun 	u32 result_count;
3517*4882a593Smuzhiyun 	u32 status;
3518*4882a593Smuzhiyun 	u32 datalen;
3519*4882a593Smuzhiyun 
3520*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "Enter\n");
3521*4882a593Smuzhiyun 
3522*4882a593Smuzhiyun 	if (e->datalen < (sizeof(*pfn_result) + sizeof(*netinfo))) {
3523*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "Event data to small. Ignore\n");
3524*4882a593Smuzhiyun 		return 0;
3525*4882a593Smuzhiyun 	}
3526*4882a593Smuzhiyun 
3527*4882a593Smuzhiyun 	if (e->event_code == BRCMF_E_PFN_NET_LOST) {
3528*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "PFN NET LOST event. Do Nothing\n");
3529*4882a593Smuzhiyun 		return 0;
3530*4882a593Smuzhiyun 	}
3531*4882a593Smuzhiyun 
3532*4882a593Smuzhiyun 	pfn_result = (struct brcmf_pno_scanresults_le *)data;
3533*4882a593Smuzhiyun 	result_count = le32_to_cpu(pfn_result->count);
3534*4882a593Smuzhiyun 	status = le32_to_cpu(pfn_result->status);
3535*4882a593Smuzhiyun 
3536*4882a593Smuzhiyun 	/* PFN event is limited to fit 512 bytes so we may get
3537*4882a593Smuzhiyun 	 * multiple NET_FOUND events. For now place a warning here.
3538*4882a593Smuzhiyun 	 */
3539*4882a593Smuzhiyun 	WARN_ON(status != BRCMF_PNO_SCAN_COMPLETE);
3540*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "PFN NET FOUND event. count: %d\n", result_count);
3541*4882a593Smuzhiyun 	if (!result_count) {
3542*4882a593Smuzhiyun 		bphy_err(drvr, "FALSE PNO Event. (pfn_count == 0)\n");
3543*4882a593Smuzhiyun 		goto out_err;
3544*4882a593Smuzhiyun 	}
3545*4882a593Smuzhiyun 
3546*4882a593Smuzhiyun 	netinfo_start = brcmf_get_netinfo_array(pfn_result);
3547*4882a593Smuzhiyun 	datalen = e->datalen - ((void *)netinfo_start - (void *)pfn_result);
3548*4882a593Smuzhiyun 	if (datalen < result_count * sizeof(*netinfo)) {
3549*4882a593Smuzhiyun 		bphy_err(drvr, "insufficient event data\n");
3550*4882a593Smuzhiyun 		goto out_err;
3551*4882a593Smuzhiyun 	}
3552*4882a593Smuzhiyun 
3553*4882a593Smuzhiyun 	request = brcmf_alloc_internal_escan_request(wiphy,
3554*4882a593Smuzhiyun 						     result_count);
3555*4882a593Smuzhiyun 	if (!request) {
3556*4882a593Smuzhiyun 		err = -ENOMEM;
3557*4882a593Smuzhiyun 		goto out_err;
3558*4882a593Smuzhiyun 	}
3559*4882a593Smuzhiyun 
3560*4882a593Smuzhiyun 	bucket_map = 0;
3561*4882a593Smuzhiyun 	for (i = 0; i < result_count; i++) {
3562*4882a593Smuzhiyun 		netinfo = &netinfo_start[i];
3563*4882a593Smuzhiyun 
3564*4882a593Smuzhiyun 		if (netinfo->SSID_len > IEEE80211_MAX_SSID_LEN)
3565*4882a593Smuzhiyun 			netinfo->SSID_len = IEEE80211_MAX_SSID_LEN;
3566*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "SSID:%.32s Channel:%d\n",
3567*4882a593Smuzhiyun 			  netinfo->SSID, netinfo->channel);
3568*4882a593Smuzhiyun 		bucket_map |= brcmf_pno_get_bucket_map(cfg->pno, netinfo);
3569*4882a593Smuzhiyun 		err = brcmf_internal_escan_add_info(request,
3570*4882a593Smuzhiyun 						    netinfo->SSID,
3571*4882a593Smuzhiyun 						    netinfo->SSID_len,
3572*4882a593Smuzhiyun 						    netinfo->channel);
3573*4882a593Smuzhiyun 		if (err)
3574*4882a593Smuzhiyun 			goto out_err;
3575*4882a593Smuzhiyun 	}
3576*4882a593Smuzhiyun 
3577*4882a593Smuzhiyun 	if (!bucket_map)
3578*4882a593Smuzhiyun 		goto free_req;
3579*4882a593Smuzhiyun 
3580*4882a593Smuzhiyun 	err = brcmf_start_internal_escan(ifp, bucket_map, request);
3581*4882a593Smuzhiyun 	if (!err)
3582*4882a593Smuzhiyun 		goto free_req;
3583*4882a593Smuzhiyun 
3584*4882a593Smuzhiyun out_err:
3585*4882a593Smuzhiyun 	cfg80211_sched_scan_stopped(wiphy, 0);
3586*4882a593Smuzhiyun free_req:
3587*4882a593Smuzhiyun 	kfree(request);
3588*4882a593Smuzhiyun 	return err;
3589*4882a593Smuzhiyun }
3590*4882a593Smuzhiyun 
3591*4882a593Smuzhiyun static int
brcmf_cfg80211_sched_scan_start(struct wiphy * wiphy,struct net_device * ndev,struct cfg80211_sched_scan_request * req)3592*4882a593Smuzhiyun brcmf_cfg80211_sched_scan_start(struct wiphy *wiphy,
3593*4882a593Smuzhiyun 				struct net_device *ndev,
3594*4882a593Smuzhiyun 				struct cfg80211_sched_scan_request *req)
3595*4882a593Smuzhiyun {
3596*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
3597*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
3598*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
3599*4882a593Smuzhiyun 
3600*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "Enter: n_match_sets=%d n_ssids=%d\n",
3601*4882a593Smuzhiyun 		  req->n_match_sets, req->n_ssids);
3602*4882a593Smuzhiyun 
3603*4882a593Smuzhiyun 	if (test_bit(BRCMF_SCAN_STATUS_SUPPRESS, &cfg->scan_status)) {
3604*4882a593Smuzhiyun 		bphy_err(drvr, "Scanning suppressed: status=%lu\n",
3605*4882a593Smuzhiyun 			 cfg->scan_status);
3606*4882a593Smuzhiyun 		return -EAGAIN;
3607*4882a593Smuzhiyun 	}
3608*4882a593Smuzhiyun 
3609*4882a593Smuzhiyun 	if (req->n_match_sets <= 0) {
3610*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "invalid number of matchsets specified: %d\n",
3611*4882a593Smuzhiyun 			  req->n_match_sets);
3612*4882a593Smuzhiyun 		return -EINVAL;
3613*4882a593Smuzhiyun 	}
3614*4882a593Smuzhiyun 
3615*4882a593Smuzhiyun 	return brcmf_pno_start_sched_scan(ifp, req);
3616*4882a593Smuzhiyun }
3617*4882a593Smuzhiyun 
brcmf_cfg80211_sched_scan_stop(struct wiphy * wiphy,struct net_device * ndev,u64 reqid)3618*4882a593Smuzhiyun static int brcmf_cfg80211_sched_scan_stop(struct wiphy *wiphy,
3619*4882a593Smuzhiyun 					  struct net_device *ndev, u64 reqid)
3620*4882a593Smuzhiyun {
3621*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
3622*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
3623*4882a593Smuzhiyun 
3624*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "enter\n");
3625*4882a593Smuzhiyun 	brcmf_pno_stop_sched_scan(ifp, reqid);
3626*4882a593Smuzhiyun 	if (cfg->int_escan_map)
3627*4882a593Smuzhiyun 		brcmf_notify_escan_complete(cfg, ifp, true, true);
3628*4882a593Smuzhiyun 	return 0;
3629*4882a593Smuzhiyun }
3630*4882a593Smuzhiyun 
brcmf_delay(u32 ms)3631*4882a593Smuzhiyun static __always_inline void brcmf_delay(u32 ms)
3632*4882a593Smuzhiyun {
3633*4882a593Smuzhiyun 	if (ms < 1000 / HZ) {
3634*4882a593Smuzhiyun 		cond_resched();
3635*4882a593Smuzhiyun 		mdelay(ms);
3636*4882a593Smuzhiyun 	} else {
3637*4882a593Smuzhiyun 		msleep(ms);
3638*4882a593Smuzhiyun 	}
3639*4882a593Smuzhiyun }
3640*4882a593Smuzhiyun 
brcmf_config_wowl_pattern(struct brcmf_if * ifp,u8 cmd[4],u8 * pattern,u32 patternsize,u8 * mask,u32 packet_offset)3641*4882a593Smuzhiyun static s32 brcmf_config_wowl_pattern(struct brcmf_if *ifp, u8 cmd[4],
3642*4882a593Smuzhiyun 				     u8 *pattern, u32 patternsize, u8 *mask,
3643*4882a593Smuzhiyun 				     u32 packet_offset)
3644*4882a593Smuzhiyun {
3645*4882a593Smuzhiyun 	struct brcmf_fil_wowl_pattern_le *filter;
3646*4882a593Smuzhiyun 	u32 masksize;
3647*4882a593Smuzhiyun 	u32 patternoffset;
3648*4882a593Smuzhiyun 	u8 *buf;
3649*4882a593Smuzhiyun 	u32 bufsize;
3650*4882a593Smuzhiyun 	s32 ret;
3651*4882a593Smuzhiyun 
3652*4882a593Smuzhiyun 	masksize = (patternsize + 7) / 8;
3653*4882a593Smuzhiyun 	patternoffset = sizeof(*filter) - sizeof(filter->cmd) + masksize;
3654*4882a593Smuzhiyun 
3655*4882a593Smuzhiyun 	bufsize = sizeof(*filter) + patternsize + masksize;
3656*4882a593Smuzhiyun 	buf = kzalloc(bufsize, GFP_KERNEL);
3657*4882a593Smuzhiyun 	if (!buf)
3658*4882a593Smuzhiyun 		return -ENOMEM;
3659*4882a593Smuzhiyun 	filter = (struct brcmf_fil_wowl_pattern_le *)buf;
3660*4882a593Smuzhiyun 
3661*4882a593Smuzhiyun 	memcpy(filter->cmd, cmd, 4);
3662*4882a593Smuzhiyun 	filter->masksize = cpu_to_le32(masksize);
3663*4882a593Smuzhiyun 	filter->offset = cpu_to_le32(packet_offset);
3664*4882a593Smuzhiyun 	filter->patternoffset = cpu_to_le32(patternoffset);
3665*4882a593Smuzhiyun 	filter->patternsize = cpu_to_le32(patternsize);
3666*4882a593Smuzhiyun 	filter->type = cpu_to_le32(BRCMF_WOWL_PATTERN_TYPE_BITMAP);
3667*4882a593Smuzhiyun 
3668*4882a593Smuzhiyun 	if ((mask) && (masksize))
3669*4882a593Smuzhiyun 		memcpy(buf + sizeof(*filter), mask, masksize);
3670*4882a593Smuzhiyun 	if ((pattern) && (patternsize))
3671*4882a593Smuzhiyun 		memcpy(buf + sizeof(*filter) + masksize, pattern, patternsize);
3672*4882a593Smuzhiyun 
3673*4882a593Smuzhiyun 	ret = brcmf_fil_iovar_data_set(ifp, "wowl_pattern", buf, bufsize);
3674*4882a593Smuzhiyun 
3675*4882a593Smuzhiyun 	kfree(buf);
3676*4882a593Smuzhiyun 	return ret;
3677*4882a593Smuzhiyun }
3678*4882a593Smuzhiyun 
3679*4882a593Smuzhiyun static s32
brcmf_wowl_nd_results(struct brcmf_if * ifp,const struct brcmf_event_msg * e,void * data)3680*4882a593Smuzhiyun brcmf_wowl_nd_results(struct brcmf_if *ifp, const struct brcmf_event_msg *e,
3681*4882a593Smuzhiyun 		      void *data)
3682*4882a593Smuzhiyun {
3683*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
3684*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = drvr->config;
3685*4882a593Smuzhiyun 	struct brcmf_pno_scanresults_le *pfn_result;
3686*4882a593Smuzhiyun 	struct brcmf_pno_net_info_le *netinfo;
3687*4882a593Smuzhiyun 
3688*4882a593Smuzhiyun 	brcmf_dbg(SCAN, "Enter\n");
3689*4882a593Smuzhiyun 
3690*4882a593Smuzhiyun 	if (e->datalen < (sizeof(*pfn_result) + sizeof(*netinfo))) {
3691*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "Event data to small. Ignore\n");
3692*4882a593Smuzhiyun 		return 0;
3693*4882a593Smuzhiyun 	}
3694*4882a593Smuzhiyun 
3695*4882a593Smuzhiyun 	pfn_result = (struct brcmf_pno_scanresults_le *)data;
3696*4882a593Smuzhiyun 
3697*4882a593Smuzhiyun 	if (e->event_code == BRCMF_E_PFN_NET_LOST) {
3698*4882a593Smuzhiyun 		brcmf_dbg(SCAN, "PFN NET LOST event. Ignore\n");
3699*4882a593Smuzhiyun 		return 0;
3700*4882a593Smuzhiyun 	}
3701*4882a593Smuzhiyun 
3702*4882a593Smuzhiyun 	if (le32_to_cpu(pfn_result->count) < 1) {
3703*4882a593Smuzhiyun 		bphy_err(drvr, "Invalid result count, expected 1 (%d)\n",
3704*4882a593Smuzhiyun 			 le32_to_cpu(pfn_result->count));
3705*4882a593Smuzhiyun 		return -EINVAL;
3706*4882a593Smuzhiyun 	}
3707*4882a593Smuzhiyun 
3708*4882a593Smuzhiyun 	netinfo = brcmf_get_netinfo_array(pfn_result);
3709*4882a593Smuzhiyun 	if (netinfo->SSID_len > IEEE80211_MAX_SSID_LEN)
3710*4882a593Smuzhiyun 		netinfo->SSID_len = IEEE80211_MAX_SSID_LEN;
3711*4882a593Smuzhiyun 	memcpy(cfg->wowl.nd->ssid.ssid, netinfo->SSID, netinfo->SSID_len);
3712*4882a593Smuzhiyun 	cfg->wowl.nd->ssid.ssid_len = netinfo->SSID_len;
3713*4882a593Smuzhiyun 	cfg->wowl.nd->n_channels = 1;
3714*4882a593Smuzhiyun 	cfg->wowl.nd->channels[0] =
3715*4882a593Smuzhiyun 		ieee80211_channel_to_frequency(netinfo->channel,
3716*4882a593Smuzhiyun 			netinfo->channel <= CH_MAX_2G_CHANNEL ?
3717*4882a593Smuzhiyun 					NL80211_BAND_2GHZ : NL80211_BAND_5GHZ);
3718*4882a593Smuzhiyun 	cfg->wowl.nd_info->n_matches = 1;
3719*4882a593Smuzhiyun 	cfg->wowl.nd_info->matches[0] = cfg->wowl.nd;
3720*4882a593Smuzhiyun 
3721*4882a593Smuzhiyun 	/* Inform (the resume task) that the net detect information was recvd */
3722*4882a593Smuzhiyun 	cfg->wowl.nd_data_completed = true;
3723*4882a593Smuzhiyun 	wake_up(&cfg->wowl.nd_data_wait);
3724*4882a593Smuzhiyun 
3725*4882a593Smuzhiyun 	return 0;
3726*4882a593Smuzhiyun }
3727*4882a593Smuzhiyun 
3728*4882a593Smuzhiyun #ifdef CONFIG_PM
3729*4882a593Smuzhiyun 
brcmf_report_wowl_wakeind(struct wiphy * wiphy,struct brcmf_if * ifp)3730*4882a593Smuzhiyun static void brcmf_report_wowl_wakeind(struct wiphy *wiphy, struct brcmf_if *ifp)
3731*4882a593Smuzhiyun {
3732*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
3733*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
3734*4882a593Smuzhiyun 	struct brcmf_wowl_wakeind_le wake_ind_le;
3735*4882a593Smuzhiyun 	struct cfg80211_wowlan_wakeup wakeup_data;
3736*4882a593Smuzhiyun 	struct cfg80211_wowlan_wakeup *wakeup;
3737*4882a593Smuzhiyun 	u32 wakeind;
3738*4882a593Smuzhiyun 	s32 err;
3739*4882a593Smuzhiyun 	int timeout;
3740*4882a593Smuzhiyun 
3741*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_get(ifp, "wowl_wakeind", &wake_ind_le,
3742*4882a593Smuzhiyun 				       sizeof(wake_ind_le));
3743*4882a593Smuzhiyun 	if (err) {
3744*4882a593Smuzhiyun 		bphy_err(drvr, "Get wowl_wakeind failed, err = %d\n", err);
3745*4882a593Smuzhiyun 		return;
3746*4882a593Smuzhiyun 	}
3747*4882a593Smuzhiyun 
3748*4882a593Smuzhiyun 	wakeind = le32_to_cpu(wake_ind_le.ucode_wakeind);
3749*4882a593Smuzhiyun 	if (wakeind & (BRCMF_WOWL_MAGIC | BRCMF_WOWL_DIS | BRCMF_WOWL_BCN |
3750*4882a593Smuzhiyun 		       BRCMF_WOWL_RETR | BRCMF_WOWL_NET |
3751*4882a593Smuzhiyun 		       BRCMF_WOWL_PFN_FOUND)) {
3752*4882a593Smuzhiyun 		wakeup = &wakeup_data;
3753*4882a593Smuzhiyun 		memset(&wakeup_data, 0, sizeof(wakeup_data));
3754*4882a593Smuzhiyun 		wakeup_data.pattern_idx = -1;
3755*4882a593Smuzhiyun 
3756*4882a593Smuzhiyun 		if (wakeind & BRCMF_WOWL_MAGIC) {
3757*4882a593Smuzhiyun 			brcmf_dbg(INFO, "WOWL Wake indicator: BRCMF_WOWL_MAGIC\n");
3758*4882a593Smuzhiyun 			wakeup_data.magic_pkt = true;
3759*4882a593Smuzhiyun 		}
3760*4882a593Smuzhiyun 		if (wakeind & BRCMF_WOWL_DIS) {
3761*4882a593Smuzhiyun 			brcmf_dbg(INFO, "WOWL Wake indicator: BRCMF_WOWL_DIS\n");
3762*4882a593Smuzhiyun 			wakeup_data.disconnect = true;
3763*4882a593Smuzhiyun 		}
3764*4882a593Smuzhiyun 		if (wakeind & BRCMF_WOWL_BCN) {
3765*4882a593Smuzhiyun 			brcmf_dbg(INFO, "WOWL Wake indicator: BRCMF_WOWL_BCN\n");
3766*4882a593Smuzhiyun 			wakeup_data.disconnect = true;
3767*4882a593Smuzhiyun 		}
3768*4882a593Smuzhiyun 		if (wakeind & BRCMF_WOWL_RETR) {
3769*4882a593Smuzhiyun 			brcmf_dbg(INFO, "WOWL Wake indicator: BRCMF_WOWL_RETR\n");
3770*4882a593Smuzhiyun 			wakeup_data.disconnect = true;
3771*4882a593Smuzhiyun 		}
3772*4882a593Smuzhiyun 		if (wakeind & BRCMF_WOWL_NET) {
3773*4882a593Smuzhiyun 			brcmf_dbg(INFO, "WOWL Wake indicator: BRCMF_WOWL_NET\n");
3774*4882a593Smuzhiyun 			/* For now always map to pattern 0, no API to get
3775*4882a593Smuzhiyun 			 * correct information available at the moment.
3776*4882a593Smuzhiyun 			 */
3777*4882a593Smuzhiyun 			wakeup_data.pattern_idx = 0;
3778*4882a593Smuzhiyun 		}
3779*4882a593Smuzhiyun 		if (wakeind & BRCMF_WOWL_PFN_FOUND) {
3780*4882a593Smuzhiyun 			brcmf_dbg(INFO, "WOWL Wake indicator: BRCMF_WOWL_PFN_FOUND\n");
3781*4882a593Smuzhiyun 			timeout = wait_event_timeout(cfg->wowl.nd_data_wait,
3782*4882a593Smuzhiyun 				cfg->wowl.nd_data_completed,
3783*4882a593Smuzhiyun 				BRCMF_ND_INFO_TIMEOUT);
3784*4882a593Smuzhiyun 			if (!timeout)
3785*4882a593Smuzhiyun 				bphy_err(drvr, "No result for wowl net detect\n");
3786*4882a593Smuzhiyun 			else
3787*4882a593Smuzhiyun 				wakeup_data.net_detect = cfg->wowl.nd_info;
3788*4882a593Smuzhiyun 		}
3789*4882a593Smuzhiyun 		if (wakeind & BRCMF_WOWL_GTK_FAILURE) {
3790*4882a593Smuzhiyun 			brcmf_dbg(INFO, "WOWL Wake indicator: BRCMF_WOWL_GTK_FAILURE\n");
3791*4882a593Smuzhiyun 			wakeup_data.gtk_rekey_failure = true;
3792*4882a593Smuzhiyun 		}
3793*4882a593Smuzhiyun 	} else {
3794*4882a593Smuzhiyun 		wakeup = NULL;
3795*4882a593Smuzhiyun 	}
3796*4882a593Smuzhiyun 	cfg80211_report_wowlan_wakeup(&ifp->vif->wdev, wakeup, GFP_KERNEL);
3797*4882a593Smuzhiyun }
3798*4882a593Smuzhiyun 
3799*4882a593Smuzhiyun #else
3800*4882a593Smuzhiyun 
brcmf_report_wowl_wakeind(struct wiphy * wiphy,struct brcmf_if * ifp)3801*4882a593Smuzhiyun static void brcmf_report_wowl_wakeind(struct wiphy *wiphy, struct brcmf_if *ifp)
3802*4882a593Smuzhiyun {
3803*4882a593Smuzhiyun }
3804*4882a593Smuzhiyun 
3805*4882a593Smuzhiyun #endif /* CONFIG_PM */
3806*4882a593Smuzhiyun 
brcmf_cfg80211_resume(struct wiphy * wiphy)3807*4882a593Smuzhiyun static s32 brcmf_cfg80211_resume(struct wiphy *wiphy)
3808*4882a593Smuzhiyun {
3809*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
3810*4882a593Smuzhiyun 	struct net_device *ndev = cfg_to_ndev(cfg);
3811*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
3812*4882a593Smuzhiyun 
3813*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
3814*4882a593Smuzhiyun 
3815*4882a593Smuzhiyun 	if (cfg->wowl.active) {
3816*4882a593Smuzhiyun 		brcmf_report_wowl_wakeind(wiphy, ifp);
3817*4882a593Smuzhiyun 		brcmf_fil_iovar_int_set(ifp, "wowl_clear", 0);
3818*4882a593Smuzhiyun 		brcmf_config_wowl_pattern(ifp, "clr", NULL, 0, NULL, 0);
3819*4882a593Smuzhiyun 		if (!brcmf_feat_is_enabled(ifp, BRCMF_FEAT_WOWL_ARP_ND))
3820*4882a593Smuzhiyun 			brcmf_configure_arp_nd_offload(ifp, true);
3821*4882a593Smuzhiyun 		brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_PM,
3822*4882a593Smuzhiyun 				      cfg->wowl.pre_pmmode);
3823*4882a593Smuzhiyun 		cfg->wowl.active = false;
3824*4882a593Smuzhiyun 		if (cfg->wowl.nd_enabled) {
3825*4882a593Smuzhiyun 			brcmf_cfg80211_sched_scan_stop(cfg->wiphy, ifp->ndev, 0);
3826*4882a593Smuzhiyun 			brcmf_fweh_unregister(cfg->pub, BRCMF_E_PFN_NET_FOUND);
3827*4882a593Smuzhiyun 			brcmf_fweh_register(cfg->pub, BRCMF_E_PFN_NET_FOUND,
3828*4882a593Smuzhiyun 					    brcmf_notify_sched_scan_results);
3829*4882a593Smuzhiyun 			cfg->wowl.nd_enabled = false;
3830*4882a593Smuzhiyun 		}
3831*4882a593Smuzhiyun 	}
3832*4882a593Smuzhiyun 	return 0;
3833*4882a593Smuzhiyun }
3834*4882a593Smuzhiyun 
brcmf_configure_wowl(struct brcmf_cfg80211_info * cfg,struct brcmf_if * ifp,struct cfg80211_wowlan * wowl)3835*4882a593Smuzhiyun static void brcmf_configure_wowl(struct brcmf_cfg80211_info *cfg,
3836*4882a593Smuzhiyun 				 struct brcmf_if *ifp,
3837*4882a593Smuzhiyun 				 struct cfg80211_wowlan *wowl)
3838*4882a593Smuzhiyun {
3839*4882a593Smuzhiyun 	u32 wowl_config;
3840*4882a593Smuzhiyun 	struct brcmf_wowl_wakeind_le wowl_wakeind;
3841*4882a593Smuzhiyun 	u32 i;
3842*4882a593Smuzhiyun 
3843*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Suspend, wowl config.\n");
3844*4882a593Smuzhiyun 
3845*4882a593Smuzhiyun 	if (!brcmf_feat_is_enabled(ifp, BRCMF_FEAT_WOWL_ARP_ND))
3846*4882a593Smuzhiyun 		brcmf_configure_arp_nd_offload(ifp, false);
3847*4882a593Smuzhiyun 	brcmf_fil_cmd_int_get(ifp, BRCMF_C_GET_PM, &cfg->wowl.pre_pmmode);
3848*4882a593Smuzhiyun 	brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_PM, PM_MAX);
3849*4882a593Smuzhiyun 
3850*4882a593Smuzhiyun 	wowl_config = 0;
3851*4882a593Smuzhiyun 	if (wowl->disconnect)
3852*4882a593Smuzhiyun 		wowl_config = BRCMF_WOWL_DIS | BRCMF_WOWL_BCN | BRCMF_WOWL_RETR;
3853*4882a593Smuzhiyun 	if (wowl->magic_pkt)
3854*4882a593Smuzhiyun 		wowl_config |= BRCMF_WOWL_MAGIC;
3855*4882a593Smuzhiyun 	if ((wowl->patterns) && (wowl->n_patterns)) {
3856*4882a593Smuzhiyun 		wowl_config |= BRCMF_WOWL_NET;
3857*4882a593Smuzhiyun 		for (i = 0; i < wowl->n_patterns; i++) {
3858*4882a593Smuzhiyun 			brcmf_config_wowl_pattern(ifp, "add",
3859*4882a593Smuzhiyun 				(u8 *)wowl->patterns[i].pattern,
3860*4882a593Smuzhiyun 				wowl->patterns[i].pattern_len,
3861*4882a593Smuzhiyun 				(u8 *)wowl->patterns[i].mask,
3862*4882a593Smuzhiyun 				wowl->patterns[i].pkt_offset);
3863*4882a593Smuzhiyun 		}
3864*4882a593Smuzhiyun 	}
3865*4882a593Smuzhiyun 	if (wowl->nd_config) {
3866*4882a593Smuzhiyun 		brcmf_cfg80211_sched_scan_start(cfg->wiphy, ifp->ndev,
3867*4882a593Smuzhiyun 						wowl->nd_config);
3868*4882a593Smuzhiyun 		wowl_config |= BRCMF_WOWL_PFN_FOUND;
3869*4882a593Smuzhiyun 
3870*4882a593Smuzhiyun 		cfg->wowl.nd_data_completed = false;
3871*4882a593Smuzhiyun 		cfg->wowl.nd_enabled = true;
3872*4882a593Smuzhiyun 		/* Now reroute the event for PFN to the wowl function. */
3873*4882a593Smuzhiyun 		brcmf_fweh_unregister(cfg->pub, BRCMF_E_PFN_NET_FOUND);
3874*4882a593Smuzhiyun 		brcmf_fweh_register(cfg->pub, BRCMF_E_PFN_NET_FOUND,
3875*4882a593Smuzhiyun 				    brcmf_wowl_nd_results);
3876*4882a593Smuzhiyun 	}
3877*4882a593Smuzhiyun 	if (wowl->gtk_rekey_failure)
3878*4882a593Smuzhiyun 		wowl_config |= BRCMF_WOWL_GTK_FAILURE;
3879*4882a593Smuzhiyun 	if (!test_bit(BRCMF_VIF_STATUS_CONNECTED, &ifp->vif->sme_state))
3880*4882a593Smuzhiyun 		wowl_config |= BRCMF_WOWL_UNASSOC;
3881*4882a593Smuzhiyun 
3882*4882a593Smuzhiyun 	memcpy(&wowl_wakeind, "clear", 6);
3883*4882a593Smuzhiyun 	brcmf_fil_iovar_data_set(ifp, "wowl_wakeind", &wowl_wakeind,
3884*4882a593Smuzhiyun 				 sizeof(wowl_wakeind));
3885*4882a593Smuzhiyun 	brcmf_fil_iovar_int_set(ifp, "wowl", wowl_config);
3886*4882a593Smuzhiyun 	brcmf_fil_iovar_int_set(ifp, "wowl_activate", 1);
3887*4882a593Smuzhiyun 	brcmf_bus_wowl_config(cfg->pub->bus_if, true);
3888*4882a593Smuzhiyun 	cfg->wowl.active = true;
3889*4882a593Smuzhiyun }
3890*4882a593Smuzhiyun 
brcmf_cfg80211_suspend(struct wiphy * wiphy,struct cfg80211_wowlan * wowl)3891*4882a593Smuzhiyun static s32 brcmf_cfg80211_suspend(struct wiphy *wiphy,
3892*4882a593Smuzhiyun 				  struct cfg80211_wowlan *wowl)
3893*4882a593Smuzhiyun {
3894*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
3895*4882a593Smuzhiyun 	struct net_device *ndev = cfg_to_ndev(cfg);
3896*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
3897*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
3898*4882a593Smuzhiyun 
3899*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
3900*4882a593Smuzhiyun 
3901*4882a593Smuzhiyun 	/* if the primary net_device is not READY there is nothing
3902*4882a593Smuzhiyun 	 * we can do but pray resume goes smoothly.
3903*4882a593Smuzhiyun 	 */
3904*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
3905*4882a593Smuzhiyun 		goto exit;
3906*4882a593Smuzhiyun 
3907*4882a593Smuzhiyun 	/* Stop scheduled scan */
3908*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_PNO))
3909*4882a593Smuzhiyun 		brcmf_cfg80211_sched_scan_stop(wiphy, ndev, 0);
3910*4882a593Smuzhiyun 
3911*4882a593Smuzhiyun 	/* end any scanning */
3912*4882a593Smuzhiyun 	if (test_bit(BRCMF_SCAN_STATUS_BUSY, &cfg->scan_status))
3913*4882a593Smuzhiyun 		brcmf_abort_scanning(cfg);
3914*4882a593Smuzhiyun 
3915*4882a593Smuzhiyun 	if (wowl == NULL) {
3916*4882a593Smuzhiyun 		brcmf_bus_wowl_config(cfg->pub->bus_if, false);
3917*4882a593Smuzhiyun 		list_for_each_entry(vif, &cfg->vif_list, list) {
3918*4882a593Smuzhiyun 			if (!test_bit(BRCMF_VIF_STATUS_READY, &vif->sme_state))
3919*4882a593Smuzhiyun 				continue;
3920*4882a593Smuzhiyun 			/* While going to suspend if associated with AP
3921*4882a593Smuzhiyun 			 * disassociate from AP to save power while system is
3922*4882a593Smuzhiyun 			 * in suspended state
3923*4882a593Smuzhiyun 			 */
3924*4882a593Smuzhiyun 			brcmf_link_down(vif, WLAN_REASON_UNSPECIFIED, true);
3925*4882a593Smuzhiyun 			/* Make sure WPA_Supplicant receives all the event
3926*4882a593Smuzhiyun 			 * generated due to DISASSOC call to the fw to keep
3927*4882a593Smuzhiyun 			 * the state fw and WPA_Supplicant state consistent
3928*4882a593Smuzhiyun 			 */
3929*4882a593Smuzhiyun 			brcmf_delay(500);
3930*4882a593Smuzhiyun 		}
3931*4882a593Smuzhiyun 		/* Configure MPC */
3932*4882a593Smuzhiyun 		brcmf_set_mpc(ifp, 1);
3933*4882a593Smuzhiyun 
3934*4882a593Smuzhiyun 	} else {
3935*4882a593Smuzhiyun 		/* Configure WOWL paramaters */
3936*4882a593Smuzhiyun 		brcmf_configure_wowl(cfg, ifp, wowl);
3937*4882a593Smuzhiyun 	}
3938*4882a593Smuzhiyun 
3939*4882a593Smuzhiyun exit:
3940*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
3941*4882a593Smuzhiyun 	/* clear any scanning activity */
3942*4882a593Smuzhiyun 	cfg->scan_status = 0;
3943*4882a593Smuzhiyun 	return 0;
3944*4882a593Smuzhiyun }
3945*4882a593Smuzhiyun 
3946*4882a593Smuzhiyun static __used s32
brcmf_update_pmklist(struct brcmf_cfg80211_info * cfg,struct brcmf_if * ifp)3947*4882a593Smuzhiyun brcmf_update_pmklist(struct brcmf_cfg80211_info *cfg, struct brcmf_if *ifp)
3948*4882a593Smuzhiyun {
3949*4882a593Smuzhiyun 	struct brcmf_pmk_list_le *pmk_list;
3950*4882a593Smuzhiyun 	int i;
3951*4882a593Smuzhiyun 	u32 npmk;
3952*4882a593Smuzhiyun 	s32 err;
3953*4882a593Smuzhiyun 
3954*4882a593Smuzhiyun 	pmk_list = &cfg->pmk_list;
3955*4882a593Smuzhiyun 	npmk = le32_to_cpu(pmk_list->npmk);
3956*4882a593Smuzhiyun 
3957*4882a593Smuzhiyun 	brcmf_dbg(CONN, "No of elements %d\n", npmk);
3958*4882a593Smuzhiyun 	for (i = 0; i < npmk; i++)
3959*4882a593Smuzhiyun 		brcmf_dbg(CONN, "PMK[%d]: %pM\n", i, &pmk_list->pmk[i].bssid);
3960*4882a593Smuzhiyun 
3961*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_set(ifp, "pmkid_info", pmk_list,
3962*4882a593Smuzhiyun 				       sizeof(*pmk_list));
3963*4882a593Smuzhiyun 
3964*4882a593Smuzhiyun 	return err;
3965*4882a593Smuzhiyun }
3966*4882a593Smuzhiyun 
3967*4882a593Smuzhiyun static s32
brcmf_cfg80211_set_pmksa(struct wiphy * wiphy,struct net_device * ndev,struct cfg80211_pmksa * pmksa)3968*4882a593Smuzhiyun brcmf_cfg80211_set_pmksa(struct wiphy *wiphy, struct net_device *ndev,
3969*4882a593Smuzhiyun 			 struct cfg80211_pmksa *pmksa)
3970*4882a593Smuzhiyun {
3971*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
3972*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
3973*4882a593Smuzhiyun 	struct brcmf_pmksa *pmk = &cfg->pmk_list.pmk[0];
3974*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
3975*4882a593Smuzhiyun 	s32 err;
3976*4882a593Smuzhiyun 	u32 npmk, i;
3977*4882a593Smuzhiyun 
3978*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
3979*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
3980*4882a593Smuzhiyun 		return -EIO;
3981*4882a593Smuzhiyun 
3982*4882a593Smuzhiyun 	npmk = le32_to_cpu(cfg->pmk_list.npmk);
3983*4882a593Smuzhiyun 	for (i = 0; i < npmk; i++)
3984*4882a593Smuzhiyun 		if (!memcmp(pmksa->bssid, pmk[i].bssid, ETH_ALEN))
3985*4882a593Smuzhiyun 			break;
3986*4882a593Smuzhiyun 	if (i < BRCMF_MAXPMKID) {
3987*4882a593Smuzhiyun 		memcpy(pmk[i].bssid, pmksa->bssid, ETH_ALEN);
3988*4882a593Smuzhiyun 		memcpy(pmk[i].pmkid, pmksa->pmkid, WLAN_PMKID_LEN);
3989*4882a593Smuzhiyun 		if (i == npmk) {
3990*4882a593Smuzhiyun 			npmk++;
3991*4882a593Smuzhiyun 			cfg->pmk_list.npmk = cpu_to_le32(npmk);
3992*4882a593Smuzhiyun 		}
3993*4882a593Smuzhiyun 	} else {
3994*4882a593Smuzhiyun 		bphy_err(drvr, "Too many PMKSA entries cached %d\n", npmk);
3995*4882a593Smuzhiyun 		return -EINVAL;
3996*4882a593Smuzhiyun 	}
3997*4882a593Smuzhiyun 
3998*4882a593Smuzhiyun 	brcmf_dbg(CONN, "set_pmksa - PMK bssid: %pM =\n", pmk[npmk].bssid);
3999*4882a593Smuzhiyun 	brcmf_dbg(CONN, "%*ph\n", WLAN_PMKID_LEN, pmk[npmk].pmkid);
4000*4882a593Smuzhiyun 
4001*4882a593Smuzhiyun 	err = brcmf_update_pmklist(cfg, ifp);
4002*4882a593Smuzhiyun 
4003*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
4004*4882a593Smuzhiyun 	return err;
4005*4882a593Smuzhiyun }
4006*4882a593Smuzhiyun 
4007*4882a593Smuzhiyun static s32
brcmf_cfg80211_del_pmksa(struct wiphy * wiphy,struct net_device * ndev,struct cfg80211_pmksa * pmksa)4008*4882a593Smuzhiyun brcmf_cfg80211_del_pmksa(struct wiphy *wiphy, struct net_device *ndev,
4009*4882a593Smuzhiyun 			 struct cfg80211_pmksa *pmksa)
4010*4882a593Smuzhiyun {
4011*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
4012*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
4013*4882a593Smuzhiyun 	struct brcmf_pmksa *pmk = &cfg->pmk_list.pmk[0];
4014*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
4015*4882a593Smuzhiyun 	s32 err;
4016*4882a593Smuzhiyun 	u32 npmk, i;
4017*4882a593Smuzhiyun 
4018*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
4019*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
4020*4882a593Smuzhiyun 		return -EIO;
4021*4882a593Smuzhiyun 
4022*4882a593Smuzhiyun 	brcmf_dbg(CONN, "del_pmksa - PMK bssid = %pM\n", pmksa->bssid);
4023*4882a593Smuzhiyun 
4024*4882a593Smuzhiyun 	npmk = le32_to_cpu(cfg->pmk_list.npmk);
4025*4882a593Smuzhiyun 	for (i = 0; i < npmk; i++)
4026*4882a593Smuzhiyun 		if (!memcmp(pmksa->bssid, pmk[i].bssid, ETH_ALEN))
4027*4882a593Smuzhiyun 			break;
4028*4882a593Smuzhiyun 
4029*4882a593Smuzhiyun 	if ((npmk > 0) && (i < npmk)) {
4030*4882a593Smuzhiyun 		for (; i < (npmk - 1); i++) {
4031*4882a593Smuzhiyun 			memcpy(&pmk[i].bssid, &pmk[i + 1].bssid, ETH_ALEN);
4032*4882a593Smuzhiyun 			memcpy(&pmk[i].pmkid, &pmk[i + 1].pmkid,
4033*4882a593Smuzhiyun 			       WLAN_PMKID_LEN);
4034*4882a593Smuzhiyun 		}
4035*4882a593Smuzhiyun 		memset(&pmk[i], 0, sizeof(*pmk));
4036*4882a593Smuzhiyun 		cfg->pmk_list.npmk = cpu_to_le32(npmk - 1);
4037*4882a593Smuzhiyun 	} else {
4038*4882a593Smuzhiyun 		bphy_err(drvr, "Cache entry not found\n");
4039*4882a593Smuzhiyun 		return -EINVAL;
4040*4882a593Smuzhiyun 	}
4041*4882a593Smuzhiyun 
4042*4882a593Smuzhiyun 	err = brcmf_update_pmklist(cfg, ifp);
4043*4882a593Smuzhiyun 
4044*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
4045*4882a593Smuzhiyun 	return err;
4046*4882a593Smuzhiyun 
4047*4882a593Smuzhiyun }
4048*4882a593Smuzhiyun 
4049*4882a593Smuzhiyun static s32
brcmf_cfg80211_flush_pmksa(struct wiphy * wiphy,struct net_device * ndev)4050*4882a593Smuzhiyun brcmf_cfg80211_flush_pmksa(struct wiphy *wiphy, struct net_device *ndev)
4051*4882a593Smuzhiyun {
4052*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
4053*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
4054*4882a593Smuzhiyun 	s32 err;
4055*4882a593Smuzhiyun 
4056*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
4057*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
4058*4882a593Smuzhiyun 		return -EIO;
4059*4882a593Smuzhiyun 
4060*4882a593Smuzhiyun 	memset(&cfg->pmk_list, 0, sizeof(cfg->pmk_list));
4061*4882a593Smuzhiyun 	err = brcmf_update_pmklist(cfg, ifp);
4062*4882a593Smuzhiyun 
4063*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
4064*4882a593Smuzhiyun 	return err;
4065*4882a593Smuzhiyun 
4066*4882a593Smuzhiyun }
4067*4882a593Smuzhiyun 
brcmf_configure_opensecurity(struct brcmf_if * ifp)4068*4882a593Smuzhiyun static s32 brcmf_configure_opensecurity(struct brcmf_if *ifp)
4069*4882a593Smuzhiyun {
4070*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
4071*4882a593Smuzhiyun 	s32 err;
4072*4882a593Smuzhiyun 	s32 wpa_val;
4073*4882a593Smuzhiyun 
4074*4882a593Smuzhiyun 	/* set auth */
4075*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "auth", 0);
4076*4882a593Smuzhiyun 	if (err < 0) {
4077*4882a593Smuzhiyun 		bphy_err(drvr, "auth error %d\n", err);
4078*4882a593Smuzhiyun 		return err;
4079*4882a593Smuzhiyun 	}
4080*4882a593Smuzhiyun 	/* set wsec */
4081*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "wsec", 0);
4082*4882a593Smuzhiyun 	if (err < 0) {
4083*4882a593Smuzhiyun 		bphy_err(drvr, "wsec error %d\n", err);
4084*4882a593Smuzhiyun 		return err;
4085*4882a593Smuzhiyun 	}
4086*4882a593Smuzhiyun 	/* set upper-layer auth */
4087*4882a593Smuzhiyun 	if (brcmf_is_ibssmode(ifp->vif))
4088*4882a593Smuzhiyun 		wpa_val = WPA_AUTH_NONE;
4089*4882a593Smuzhiyun 	else
4090*4882a593Smuzhiyun 		wpa_val = WPA_AUTH_DISABLED;
4091*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "wpa_auth", wpa_val);
4092*4882a593Smuzhiyun 	if (err < 0) {
4093*4882a593Smuzhiyun 		bphy_err(drvr, "wpa_auth error %d\n", err);
4094*4882a593Smuzhiyun 		return err;
4095*4882a593Smuzhiyun 	}
4096*4882a593Smuzhiyun 
4097*4882a593Smuzhiyun 	return 0;
4098*4882a593Smuzhiyun }
4099*4882a593Smuzhiyun 
brcmf_valid_wpa_oui(u8 * oui,bool is_rsn_ie)4100*4882a593Smuzhiyun static bool brcmf_valid_wpa_oui(u8 *oui, bool is_rsn_ie)
4101*4882a593Smuzhiyun {
4102*4882a593Smuzhiyun 	if (is_rsn_ie)
4103*4882a593Smuzhiyun 		return (memcmp(oui, RSN_OUI, TLV_OUI_LEN) == 0);
4104*4882a593Smuzhiyun 
4105*4882a593Smuzhiyun 	return (memcmp(oui, WPA_OUI, TLV_OUI_LEN) == 0);
4106*4882a593Smuzhiyun }
4107*4882a593Smuzhiyun 
4108*4882a593Smuzhiyun static s32
brcmf_configure_wpaie(struct brcmf_if * ifp,const struct brcmf_vs_tlv * wpa_ie,bool is_rsn_ie)4109*4882a593Smuzhiyun brcmf_configure_wpaie(struct brcmf_if *ifp,
4110*4882a593Smuzhiyun 		      const struct brcmf_vs_tlv *wpa_ie,
4111*4882a593Smuzhiyun 		      bool is_rsn_ie)
4112*4882a593Smuzhiyun {
4113*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
4114*4882a593Smuzhiyun 	u32 auth = 0; /* d11 open authentication */
4115*4882a593Smuzhiyun 	u16 count;
4116*4882a593Smuzhiyun 	s32 err = 0;
4117*4882a593Smuzhiyun 	s32 len;
4118*4882a593Smuzhiyun 	u32 i;
4119*4882a593Smuzhiyun 	u32 wsec;
4120*4882a593Smuzhiyun 	u32 pval = 0;
4121*4882a593Smuzhiyun 	u32 gval = 0;
4122*4882a593Smuzhiyun 	u32 wpa_auth = 0;
4123*4882a593Smuzhiyun 	u32 offset;
4124*4882a593Smuzhiyun 	u8 *data;
4125*4882a593Smuzhiyun 	u16 rsn_cap;
4126*4882a593Smuzhiyun 	u32 wme_bss_disable;
4127*4882a593Smuzhiyun 	u32 mfp;
4128*4882a593Smuzhiyun 
4129*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
4130*4882a593Smuzhiyun 	if (wpa_ie == NULL)
4131*4882a593Smuzhiyun 		goto exit;
4132*4882a593Smuzhiyun 
4133*4882a593Smuzhiyun 	len = wpa_ie->len + TLV_HDR_LEN;
4134*4882a593Smuzhiyun 	data = (u8 *)wpa_ie;
4135*4882a593Smuzhiyun 	offset = TLV_HDR_LEN;
4136*4882a593Smuzhiyun 	if (!is_rsn_ie)
4137*4882a593Smuzhiyun 		offset += VS_IE_FIXED_HDR_LEN;
4138*4882a593Smuzhiyun 	else
4139*4882a593Smuzhiyun 		offset += WPA_IE_VERSION_LEN;
4140*4882a593Smuzhiyun 
4141*4882a593Smuzhiyun 	/* check for multicast cipher suite */
4142*4882a593Smuzhiyun 	if (offset + WPA_IE_MIN_OUI_LEN > len) {
4143*4882a593Smuzhiyun 		err = -EINVAL;
4144*4882a593Smuzhiyun 		bphy_err(drvr, "no multicast cipher suite\n");
4145*4882a593Smuzhiyun 		goto exit;
4146*4882a593Smuzhiyun 	}
4147*4882a593Smuzhiyun 
4148*4882a593Smuzhiyun 	if (!brcmf_valid_wpa_oui(&data[offset], is_rsn_ie)) {
4149*4882a593Smuzhiyun 		err = -EINVAL;
4150*4882a593Smuzhiyun 		bphy_err(drvr, "ivalid OUI\n");
4151*4882a593Smuzhiyun 		goto exit;
4152*4882a593Smuzhiyun 	}
4153*4882a593Smuzhiyun 	offset += TLV_OUI_LEN;
4154*4882a593Smuzhiyun 
4155*4882a593Smuzhiyun 	/* pick up multicast cipher */
4156*4882a593Smuzhiyun 	switch (data[offset]) {
4157*4882a593Smuzhiyun 	case WPA_CIPHER_NONE:
4158*4882a593Smuzhiyun 		gval = 0;
4159*4882a593Smuzhiyun 		break;
4160*4882a593Smuzhiyun 	case WPA_CIPHER_WEP_40:
4161*4882a593Smuzhiyun 	case WPA_CIPHER_WEP_104:
4162*4882a593Smuzhiyun 		gval = WEP_ENABLED;
4163*4882a593Smuzhiyun 		break;
4164*4882a593Smuzhiyun 	case WPA_CIPHER_TKIP:
4165*4882a593Smuzhiyun 		gval = TKIP_ENABLED;
4166*4882a593Smuzhiyun 		break;
4167*4882a593Smuzhiyun 	case WPA_CIPHER_AES_CCM:
4168*4882a593Smuzhiyun 		gval = AES_ENABLED;
4169*4882a593Smuzhiyun 		break;
4170*4882a593Smuzhiyun 	default:
4171*4882a593Smuzhiyun 		err = -EINVAL;
4172*4882a593Smuzhiyun 		bphy_err(drvr, "Invalid multi cast cipher info\n");
4173*4882a593Smuzhiyun 		goto exit;
4174*4882a593Smuzhiyun 	}
4175*4882a593Smuzhiyun 
4176*4882a593Smuzhiyun 	offset++;
4177*4882a593Smuzhiyun 	/* walk thru unicast cipher list and pick up what we recognize */
4178*4882a593Smuzhiyun 	count = data[offset] + (data[offset + 1] << 8);
4179*4882a593Smuzhiyun 	offset += WPA_IE_SUITE_COUNT_LEN;
4180*4882a593Smuzhiyun 	/* Check for unicast suite(s) */
4181*4882a593Smuzhiyun 	if (offset + (WPA_IE_MIN_OUI_LEN * count) > len) {
4182*4882a593Smuzhiyun 		err = -EINVAL;
4183*4882a593Smuzhiyun 		bphy_err(drvr, "no unicast cipher suite\n");
4184*4882a593Smuzhiyun 		goto exit;
4185*4882a593Smuzhiyun 	}
4186*4882a593Smuzhiyun 	for (i = 0; i < count; i++) {
4187*4882a593Smuzhiyun 		if (!brcmf_valid_wpa_oui(&data[offset], is_rsn_ie)) {
4188*4882a593Smuzhiyun 			err = -EINVAL;
4189*4882a593Smuzhiyun 			bphy_err(drvr, "ivalid OUI\n");
4190*4882a593Smuzhiyun 			goto exit;
4191*4882a593Smuzhiyun 		}
4192*4882a593Smuzhiyun 		offset += TLV_OUI_LEN;
4193*4882a593Smuzhiyun 		switch (data[offset]) {
4194*4882a593Smuzhiyun 		case WPA_CIPHER_NONE:
4195*4882a593Smuzhiyun 			break;
4196*4882a593Smuzhiyun 		case WPA_CIPHER_WEP_40:
4197*4882a593Smuzhiyun 		case WPA_CIPHER_WEP_104:
4198*4882a593Smuzhiyun 			pval |= WEP_ENABLED;
4199*4882a593Smuzhiyun 			break;
4200*4882a593Smuzhiyun 		case WPA_CIPHER_TKIP:
4201*4882a593Smuzhiyun 			pval |= TKIP_ENABLED;
4202*4882a593Smuzhiyun 			break;
4203*4882a593Smuzhiyun 		case WPA_CIPHER_AES_CCM:
4204*4882a593Smuzhiyun 			pval |= AES_ENABLED;
4205*4882a593Smuzhiyun 			break;
4206*4882a593Smuzhiyun 		default:
4207*4882a593Smuzhiyun 			bphy_err(drvr, "Invalid unicast security info\n");
4208*4882a593Smuzhiyun 		}
4209*4882a593Smuzhiyun 		offset++;
4210*4882a593Smuzhiyun 	}
4211*4882a593Smuzhiyun 	/* walk thru auth management suite list and pick up what we recognize */
4212*4882a593Smuzhiyun 	count = data[offset] + (data[offset + 1] << 8);
4213*4882a593Smuzhiyun 	offset += WPA_IE_SUITE_COUNT_LEN;
4214*4882a593Smuzhiyun 	/* Check for auth key management suite(s) */
4215*4882a593Smuzhiyun 	if (offset + (WPA_IE_MIN_OUI_LEN * count) > len) {
4216*4882a593Smuzhiyun 		err = -EINVAL;
4217*4882a593Smuzhiyun 		bphy_err(drvr, "no auth key mgmt suite\n");
4218*4882a593Smuzhiyun 		goto exit;
4219*4882a593Smuzhiyun 	}
4220*4882a593Smuzhiyun 	for (i = 0; i < count; i++) {
4221*4882a593Smuzhiyun 		if (!brcmf_valid_wpa_oui(&data[offset], is_rsn_ie)) {
4222*4882a593Smuzhiyun 			err = -EINVAL;
4223*4882a593Smuzhiyun 			bphy_err(drvr, "ivalid OUI\n");
4224*4882a593Smuzhiyun 			goto exit;
4225*4882a593Smuzhiyun 		}
4226*4882a593Smuzhiyun 		offset += TLV_OUI_LEN;
4227*4882a593Smuzhiyun 		switch (data[offset]) {
4228*4882a593Smuzhiyun 		case RSN_AKM_NONE:
4229*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "RSN_AKM_NONE\n");
4230*4882a593Smuzhiyun 			wpa_auth |= WPA_AUTH_NONE;
4231*4882a593Smuzhiyun 			break;
4232*4882a593Smuzhiyun 		case RSN_AKM_UNSPECIFIED:
4233*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "RSN_AKM_UNSPECIFIED\n");
4234*4882a593Smuzhiyun 			is_rsn_ie ? (wpa_auth |= WPA2_AUTH_UNSPECIFIED) :
4235*4882a593Smuzhiyun 				    (wpa_auth |= WPA_AUTH_UNSPECIFIED);
4236*4882a593Smuzhiyun 			break;
4237*4882a593Smuzhiyun 		case RSN_AKM_PSK:
4238*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "RSN_AKM_PSK\n");
4239*4882a593Smuzhiyun 			is_rsn_ie ? (wpa_auth |= WPA2_AUTH_PSK) :
4240*4882a593Smuzhiyun 				    (wpa_auth |= WPA_AUTH_PSK);
4241*4882a593Smuzhiyun 			break;
4242*4882a593Smuzhiyun 		case RSN_AKM_SHA256_PSK:
4243*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "RSN_AKM_MFP_PSK\n");
4244*4882a593Smuzhiyun 			wpa_auth |= WPA2_AUTH_PSK_SHA256;
4245*4882a593Smuzhiyun 			break;
4246*4882a593Smuzhiyun 		case RSN_AKM_SHA256_1X:
4247*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "RSN_AKM_MFP_1X\n");
4248*4882a593Smuzhiyun 			wpa_auth |= WPA2_AUTH_1X_SHA256;
4249*4882a593Smuzhiyun 			break;
4250*4882a593Smuzhiyun 		case RSN_AKM_SAE:
4251*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "RSN_AKM_SAE\n");
4252*4882a593Smuzhiyun 			wpa_auth |= WPA3_AUTH_SAE_PSK;
4253*4882a593Smuzhiyun 			break;
4254*4882a593Smuzhiyun 		default:
4255*4882a593Smuzhiyun 			bphy_err(drvr, "Invalid key mgmt info\n");
4256*4882a593Smuzhiyun 		}
4257*4882a593Smuzhiyun 		offset++;
4258*4882a593Smuzhiyun 	}
4259*4882a593Smuzhiyun 
4260*4882a593Smuzhiyun 	mfp = BRCMF_MFP_NONE;
4261*4882a593Smuzhiyun 	if (is_rsn_ie) {
4262*4882a593Smuzhiyun 		wme_bss_disable = 1;
4263*4882a593Smuzhiyun 		if ((offset + RSN_CAP_LEN) <= len) {
4264*4882a593Smuzhiyun 			rsn_cap = data[offset] + (data[offset + 1] << 8);
4265*4882a593Smuzhiyun 			if (rsn_cap & RSN_CAP_PTK_REPLAY_CNTR_MASK)
4266*4882a593Smuzhiyun 				wme_bss_disable = 0;
4267*4882a593Smuzhiyun 			if (rsn_cap & RSN_CAP_MFPR_MASK) {
4268*4882a593Smuzhiyun 				brcmf_dbg(TRACE, "MFP Required\n");
4269*4882a593Smuzhiyun 				mfp = BRCMF_MFP_REQUIRED;
4270*4882a593Smuzhiyun 				/* Firmware only supports mfp required in
4271*4882a593Smuzhiyun 				 * combination with WPA2_AUTH_PSK_SHA256,
4272*4882a593Smuzhiyun 				 * WPA2_AUTH_1X_SHA256, or WPA3_AUTH_SAE_PSK.
4273*4882a593Smuzhiyun 				 */
4274*4882a593Smuzhiyun 				if (!(wpa_auth & (WPA2_AUTH_PSK_SHA256 |
4275*4882a593Smuzhiyun 						  WPA2_AUTH_1X_SHA256 |
4276*4882a593Smuzhiyun 						  WPA3_AUTH_SAE_PSK))) {
4277*4882a593Smuzhiyun 					err = -EINVAL;
4278*4882a593Smuzhiyun 					goto exit;
4279*4882a593Smuzhiyun 				}
4280*4882a593Smuzhiyun 				/* Firmware has requirement that WPA2_AUTH_PSK/
4281*4882a593Smuzhiyun 				 * WPA2_AUTH_UNSPECIFIED be set, if SHA256 OUI
4282*4882a593Smuzhiyun 				 * is to be included in the rsn ie.
4283*4882a593Smuzhiyun 				 */
4284*4882a593Smuzhiyun 				if (wpa_auth & WPA2_AUTH_PSK_SHA256)
4285*4882a593Smuzhiyun 					wpa_auth |= WPA2_AUTH_PSK;
4286*4882a593Smuzhiyun 				else if (wpa_auth & WPA2_AUTH_1X_SHA256)
4287*4882a593Smuzhiyun 					wpa_auth |= WPA2_AUTH_UNSPECIFIED;
4288*4882a593Smuzhiyun 			} else if (rsn_cap & RSN_CAP_MFPC_MASK) {
4289*4882a593Smuzhiyun 				brcmf_dbg(TRACE, "MFP Capable\n");
4290*4882a593Smuzhiyun 				mfp = BRCMF_MFP_CAPABLE;
4291*4882a593Smuzhiyun 			}
4292*4882a593Smuzhiyun 		}
4293*4882a593Smuzhiyun 		offset += RSN_CAP_LEN;
4294*4882a593Smuzhiyun 		/* set wme_bss_disable to sync RSN Capabilities */
4295*4882a593Smuzhiyun 		err = brcmf_fil_bsscfg_int_set(ifp, "wme_bss_disable",
4296*4882a593Smuzhiyun 					       wme_bss_disable);
4297*4882a593Smuzhiyun 		if (err < 0) {
4298*4882a593Smuzhiyun 			bphy_err(drvr, "wme_bss_disable error %d\n", err);
4299*4882a593Smuzhiyun 			goto exit;
4300*4882a593Smuzhiyun 		}
4301*4882a593Smuzhiyun 
4302*4882a593Smuzhiyun 		/* Skip PMKID cnt as it is know to be 0 for AP. */
4303*4882a593Smuzhiyun 		offset += RSN_PMKID_COUNT_LEN;
4304*4882a593Smuzhiyun 
4305*4882a593Smuzhiyun 		/* See if there is BIP wpa suite left for MFP */
4306*4882a593Smuzhiyun 		if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MFP) &&
4307*4882a593Smuzhiyun 		    ((offset + WPA_IE_MIN_OUI_LEN) <= len)) {
4308*4882a593Smuzhiyun 			err = brcmf_fil_bsscfg_data_set(ifp, "bip",
4309*4882a593Smuzhiyun 							&data[offset],
4310*4882a593Smuzhiyun 							WPA_IE_MIN_OUI_LEN);
4311*4882a593Smuzhiyun 			if (err < 0) {
4312*4882a593Smuzhiyun 				bphy_err(drvr, "bip error %d\n", err);
4313*4882a593Smuzhiyun 				goto exit;
4314*4882a593Smuzhiyun 			}
4315*4882a593Smuzhiyun 		}
4316*4882a593Smuzhiyun 	}
4317*4882a593Smuzhiyun 	/* FOR WPS , set SES_OW_ENABLED */
4318*4882a593Smuzhiyun 	wsec = (pval | gval | SES_OW_ENABLED);
4319*4882a593Smuzhiyun 
4320*4882a593Smuzhiyun 	/* set auth */
4321*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "auth", auth);
4322*4882a593Smuzhiyun 	if (err < 0) {
4323*4882a593Smuzhiyun 		bphy_err(drvr, "auth error %d\n", err);
4324*4882a593Smuzhiyun 		goto exit;
4325*4882a593Smuzhiyun 	}
4326*4882a593Smuzhiyun 	/* set wsec */
4327*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "wsec", wsec);
4328*4882a593Smuzhiyun 	if (err < 0) {
4329*4882a593Smuzhiyun 		bphy_err(drvr, "wsec error %d\n", err);
4330*4882a593Smuzhiyun 		goto exit;
4331*4882a593Smuzhiyun 	}
4332*4882a593Smuzhiyun 	/* Configure MFP, this needs to go after wsec otherwise the wsec command
4333*4882a593Smuzhiyun 	 * will overwrite the values set by MFP
4334*4882a593Smuzhiyun 	 */
4335*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MFP)) {
4336*4882a593Smuzhiyun 		err = brcmf_fil_bsscfg_int_set(ifp, "mfp", mfp);
4337*4882a593Smuzhiyun 		if (err < 0) {
4338*4882a593Smuzhiyun 			bphy_err(drvr, "mfp error %d\n", err);
4339*4882a593Smuzhiyun 			goto exit;
4340*4882a593Smuzhiyun 		}
4341*4882a593Smuzhiyun 	}
4342*4882a593Smuzhiyun 	/* set upper-layer auth */
4343*4882a593Smuzhiyun 	err = brcmf_fil_bsscfg_int_set(ifp, "wpa_auth", wpa_auth);
4344*4882a593Smuzhiyun 	if (err < 0) {
4345*4882a593Smuzhiyun 		bphy_err(drvr, "wpa_auth error %d\n", err);
4346*4882a593Smuzhiyun 		goto exit;
4347*4882a593Smuzhiyun 	}
4348*4882a593Smuzhiyun 
4349*4882a593Smuzhiyun exit:
4350*4882a593Smuzhiyun 	return err;
4351*4882a593Smuzhiyun }
4352*4882a593Smuzhiyun 
4353*4882a593Smuzhiyun static s32
brcmf_parse_vndr_ies(const u8 * vndr_ie_buf,u32 vndr_ie_len,struct parsed_vndr_ies * vndr_ies)4354*4882a593Smuzhiyun brcmf_parse_vndr_ies(const u8 *vndr_ie_buf, u32 vndr_ie_len,
4355*4882a593Smuzhiyun 		     struct parsed_vndr_ies *vndr_ies)
4356*4882a593Smuzhiyun {
4357*4882a593Smuzhiyun 	struct brcmf_vs_tlv *vndrie;
4358*4882a593Smuzhiyun 	struct brcmf_tlv *ie;
4359*4882a593Smuzhiyun 	struct parsed_vndr_ie_info *parsed_info;
4360*4882a593Smuzhiyun 	s32 remaining_len;
4361*4882a593Smuzhiyun 
4362*4882a593Smuzhiyun 	remaining_len = (s32)vndr_ie_len;
4363*4882a593Smuzhiyun 	memset(vndr_ies, 0, sizeof(*vndr_ies));
4364*4882a593Smuzhiyun 
4365*4882a593Smuzhiyun 	ie = (struct brcmf_tlv *)vndr_ie_buf;
4366*4882a593Smuzhiyun 	while (ie) {
4367*4882a593Smuzhiyun 		if (ie->id != WLAN_EID_VENDOR_SPECIFIC)
4368*4882a593Smuzhiyun 			goto next;
4369*4882a593Smuzhiyun 		vndrie = (struct brcmf_vs_tlv *)ie;
4370*4882a593Smuzhiyun 		/* len should be bigger than OUI length + one */
4371*4882a593Smuzhiyun 		if (vndrie->len < (VS_IE_FIXED_HDR_LEN - TLV_HDR_LEN + 1)) {
4372*4882a593Smuzhiyun 			brcmf_err("invalid vndr ie. length is too small %d\n",
4373*4882a593Smuzhiyun 				  vndrie->len);
4374*4882a593Smuzhiyun 			goto next;
4375*4882a593Smuzhiyun 		}
4376*4882a593Smuzhiyun 		/* if wpa or wme ie, do not add ie */
4377*4882a593Smuzhiyun 		if (!memcmp(vndrie->oui, (u8 *)WPA_OUI, TLV_OUI_LEN) &&
4378*4882a593Smuzhiyun 		    ((vndrie->oui_type == WPA_OUI_TYPE) ||
4379*4882a593Smuzhiyun 		    (vndrie->oui_type == WME_OUI_TYPE))) {
4380*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "Found WPA/WME oui. Do not add it\n");
4381*4882a593Smuzhiyun 			goto next;
4382*4882a593Smuzhiyun 		}
4383*4882a593Smuzhiyun 
4384*4882a593Smuzhiyun 		parsed_info = &vndr_ies->ie_info[vndr_ies->count];
4385*4882a593Smuzhiyun 
4386*4882a593Smuzhiyun 		/* save vndr ie information */
4387*4882a593Smuzhiyun 		parsed_info->ie_ptr = (char *)vndrie;
4388*4882a593Smuzhiyun 		parsed_info->ie_len = vndrie->len + TLV_HDR_LEN;
4389*4882a593Smuzhiyun 		memcpy(&parsed_info->vndrie, vndrie, sizeof(*vndrie));
4390*4882a593Smuzhiyun 
4391*4882a593Smuzhiyun 		vndr_ies->count++;
4392*4882a593Smuzhiyun 
4393*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "** OUI %3ph, type 0x%02x\n",
4394*4882a593Smuzhiyun 			  parsed_info->vndrie.oui,
4395*4882a593Smuzhiyun 			  parsed_info->vndrie.oui_type);
4396*4882a593Smuzhiyun 
4397*4882a593Smuzhiyun 		if (vndr_ies->count >= VNDR_IE_PARSE_LIMIT)
4398*4882a593Smuzhiyun 			break;
4399*4882a593Smuzhiyun next:
4400*4882a593Smuzhiyun 		remaining_len -= (ie->len + TLV_HDR_LEN);
4401*4882a593Smuzhiyun 		if (remaining_len <= TLV_HDR_LEN)
4402*4882a593Smuzhiyun 			ie = NULL;
4403*4882a593Smuzhiyun 		else
4404*4882a593Smuzhiyun 			ie = (struct brcmf_tlv *)(((u8 *)ie) + ie->len +
4405*4882a593Smuzhiyun 				TLV_HDR_LEN);
4406*4882a593Smuzhiyun 	}
4407*4882a593Smuzhiyun 	return 0;
4408*4882a593Smuzhiyun }
4409*4882a593Smuzhiyun 
4410*4882a593Smuzhiyun static u32
brcmf_vndr_ie(u8 * iebuf,s32 pktflag,u8 * ie_ptr,u32 ie_len,s8 * add_del_cmd)4411*4882a593Smuzhiyun brcmf_vndr_ie(u8 *iebuf, s32 pktflag, u8 *ie_ptr, u32 ie_len, s8 *add_del_cmd)
4412*4882a593Smuzhiyun {
4413*4882a593Smuzhiyun 	strscpy(iebuf, add_del_cmd, VNDR_IE_CMD_LEN);
4414*4882a593Smuzhiyun 
4415*4882a593Smuzhiyun 	put_unaligned_le32(1, &iebuf[VNDR_IE_COUNT_OFFSET]);
4416*4882a593Smuzhiyun 
4417*4882a593Smuzhiyun 	put_unaligned_le32(pktflag, &iebuf[VNDR_IE_PKTFLAG_OFFSET]);
4418*4882a593Smuzhiyun 
4419*4882a593Smuzhiyun 	memcpy(&iebuf[VNDR_IE_VSIE_OFFSET], ie_ptr, ie_len);
4420*4882a593Smuzhiyun 
4421*4882a593Smuzhiyun 	return ie_len + VNDR_IE_HDR_SIZE;
4422*4882a593Smuzhiyun }
4423*4882a593Smuzhiyun 
brcmf_vif_set_mgmt_ie(struct brcmf_cfg80211_vif * vif,s32 pktflag,const u8 * vndr_ie_buf,u32 vndr_ie_len)4424*4882a593Smuzhiyun s32 brcmf_vif_set_mgmt_ie(struct brcmf_cfg80211_vif *vif, s32 pktflag,
4425*4882a593Smuzhiyun 			  const u8 *vndr_ie_buf, u32 vndr_ie_len)
4426*4882a593Smuzhiyun {
4427*4882a593Smuzhiyun 	struct brcmf_pub *drvr;
4428*4882a593Smuzhiyun 	struct brcmf_if *ifp;
4429*4882a593Smuzhiyun 	struct vif_saved_ie *saved_ie;
4430*4882a593Smuzhiyun 	s32 err = 0;
4431*4882a593Smuzhiyun 	u8  *iovar_ie_buf;
4432*4882a593Smuzhiyun 	u8  *curr_ie_buf;
4433*4882a593Smuzhiyun 	u8  *mgmt_ie_buf = NULL;
4434*4882a593Smuzhiyun 	int mgmt_ie_buf_len;
4435*4882a593Smuzhiyun 	u32 *mgmt_ie_len;
4436*4882a593Smuzhiyun 	u32 del_add_ie_buf_len = 0;
4437*4882a593Smuzhiyun 	u32 total_ie_buf_len = 0;
4438*4882a593Smuzhiyun 	u32 parsed_ie_buf_len = 0;
4439*4882a593Smuzhiyun 	struct parsed_vndr_ies old_vndr_ies;
4440*4882a593Smuzhiyun 	struct parsed_vndr_ies new_vndr_ies;
4441*4882a593Smuzhiyun 	struct parsed_vndr_ie_info *vndrie_info;
4442*4882a593Smuzhiyun 	s32 i;
4443*4882a593Smuzhiyun 	u8 *ptr;
4444*4882a593Smuzhiyun 	int remained_buf_len;
4445*4882a593Smuzhiyun 
4446*4882a593Smuzhiyun 	if (!vif)
4447*4882a593Smuzhiyun 		return -ENODEV;
4448*4882a593Smuzhiyun 	ifp = vif->ifp;
4449*4882a593Smuzhiyun 	drvr = ifp->drvr;
4450*4882a593Smuzhiyun 	saved_ie = &vif->saved_ie;
4451*4882a593Smuzhiyun 
4452*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "bsscfgidx %d, pktflag : 0x%02X\n", ifp->bsscfgidx,
4453*4882a593Smuzhiyun 		  pktflag);
4454*4882a593Smuzhiyun 	iovar_ie_buf = kzalloc(WL_EXTRA_BUF_MAX, GFP_KERNEL);
4455*4882a593Smuzhiyun 	if (!iovar_ie_buf)
4456*4882a593Smuzhiyun 		return -ENOMEM;
4457*4882a593Smuzhiyun 	curr_ie_buf = iovar_ie_buf;
4458*4882a593Smuzhiyun 	switch (pktflag) {
4459*4882a593Smuzhiyun 	case BRCMF_VNDR_IE_PRBREQ_FLAG:
4460*4882a593Smuzhiyun 		mgmt_ie_buf = saved_ie->probe_req_ie;
4461*4882a593Smuzhiyun 		mgmt_ie_len = &saved_ie->probe_req_ie_len;
4462*4882a593Smuzhiyun 		mgmt_ie_buf_len = sizeof(saved_ie->probe_req_ie);
4463*4882a593Smuzhiyun 		break;
4464*4882a593Smuzhiyun 	case BRCMF_VNDR_IE_PRBRSP_FLAG:
4465*4882a593Smuzhiyun 		mgmt_ie_buf = saved_ie->probe_res_ie;
4466*4882a593Smuzhiyun 		mgmt_ie_len = &saved_ie->probe_res_ie_len;
4467*4882a593Smuzhiyun 		mgmt_ie_buf_len = sizeof(saved_ie->probe_res_ie);
4468*4882a593Smuzhiyun 		break;
4469*4882a593Smuzhiyun 	case BRCMF_VNDR_IE_BEACON_FLAG:
4470*4882a593Smuzhiyun 		mgmt_ie_buf = saved_ie->beacon_ie;
4471*4882a593Smuzhiyun 		mgmt_ie_len = &saved_ie->beacon_ie_len;
4472*4882a593Smuzhiyun 		mgmt_ie_buf_len = sizeof(saved_ie->beacon_ie);
4473*4882a593Smuzhiyun 		break;
4474*4882a593Smuzhiyun 	case BRCMF_VNDR_IE_ASSOCREQ_FLAG:
4475*4882a593Smuzhiyun 		mgmt_ie_buf = saved_ie->assoc_req_ie;
4476*4882a593Smuzhiyun 		mgmt_ie_len = &saved_ie->assoc_req_ie_len;
4477*4882a593Smuzhiyun 		mgmt_ie_buf_len = sizeof(saved_ie->assoc_req_ie);
4478*4882a593Smuzhiyun 		break;
4479*4882a593Smuzhiyun 	case BRCMF_VNDR_IE_ASSOCRSP_FLAG:
4480*4882a593Smuzhiyun 		mgmt_ie_buf = saved_ie->assoc_res_ie;
4481*4882a593Smuzhiyun 		mgmt_ie_len = &saved_ie->assoc_res_ie_len;
4482*4882a593Smuzhiyun 		mgmt_ie_buf_len = sizeof(saved_ie->assoc_res_ie);
4483*4882a593Smuzhiyun 		break;
4484*4882a593Smuzhiyun 	default:
4485*4882a593Smuzhiyun 		err = -EPERM;
4486*4882a593Smuzhiyun 		bphy_err(drvr, "not suitable type\n");
4487*4882a593Smuzhiyun 		goto exit;
4488*4882a593Smuzhiyun 	}
4489*4882a593Smuzhiyun 
4490*4882a593Smuzhiyun 	if (vndr_ie_len > mgmt_ie_buf_len) {
4491*4882a593Smuzhiyun 		err = -ENOMEM;
4492*4882a593Smuzhiyun 		bphy_err(drvr, "extra IE size too big\n");
4493*4882a593Smuzhiyun 		goto exit;
4494*4882a593Smuzhiyun 	}
4495*4882a593Smuzhiyun 
4496*4882a593Smuzhiyun 	/* parse and save new vndr_ie in curr_ie_buff before comparing it */
4497*4882a593Smuzhiyun 	if (vndr_ie_buf && vndr_ie_len && curr_ie_buf) {
4498*4882a593Smuzhiyun 		ptr = curr_ie_buf;
4499*4882a593Smuzhiyun 		brcmf_parse_vndr_ies(vndr_ie_buf, vndr_ie_len, &new_vndr_ies);
4500*4882a593Smuzhiyun 		for (i = 0; i < new_vndr_ies.count; i++) {
4501*4882a593Smuzhiyun 			vndrie_info = &new_vndr_ies.ie_info[i];
4502*4882a593Smuzhiyun 			memcpy(ptr + parsed_ie_buf_len, vndrie_info->ie_ptr,
4503*4882a593Smuzhiyun 			       vndrie_info->ie_len);
4504*4882a593Smuzhiyun 			parsed_ie_buf_len += vndrie_info->ie_len;
4505*4882a593Smuzhiyun 		}
4506*4882a593Smuzhiyun 	}
4507*4882a593Smuzhiyun 
4508*4882a593Smuzhiyun 	if (mgmt_ie_buf && *mgmt_ie_len) {
4509*4882a593Smuzhiyun 		if (parsed_ie_buf_len && (parsed_ie_buf_len == *mgmt_ie_len) &&
4510*4882a593Smuzhiyun 		    (memcmp(mgmt_ie_buf, curr_ie_buf,
4511*4882a593Smuzhiyun 			    parsed_ie_buf_len) == 0)) {
4512*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "Previous mgmt IE equals to current IE\n");
4513*4882a593Smuzhiyun 			goto exit;
4514*4882a593Smuzhiyun 		}
4515*4882a593Smuzhiyun 
4516*4882a593Smuzhiyun 		/* parse old vndr_ie */
4517*4882a593Smuzhiyun 		brcmf_parse_vndr_ies(mgmt_ie_buf, *mgmt_ie_len, &old_vndr_ies);
4518*4882a593Smuzhiyun 
4519*4882a593Smuzhiyun 		/* make a command to delete old ie */
4520*4882a593Smuzhiyun 		for (i = 0; i < old_vndr_ies.count; i++) {
4521*4882a593Smuzhiyun 			vndrie_info = &old_vndr_ies.ie_info[i];
4522*4882a593Smuzhiyun 
4523*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "DEL ID : %d, Len: %d , OUI:%3ph\n",
4524*4882a593Smuzhiyun 				  vndrie_info->vndrie.id,
4525*4882a593Smuzhiyun 				  vndrie_info->vndrie.len,
4526*4882a593Smuzhiyun 				  vndrie_info->vndrie.oui);
4527*4882a593Smuzhiyun 
4528*4882a593Smuzhiyun 			del_add_ie_buf_len = brcmf_vndr_ie(curr_ie_buf, pktflag,
4529*4882a593Smuzhiyun 							   vndrie_info->ie_ptr,
4530*4882a593Smuzhiyun 							   vndrie_info->ie_len,
4531*4882a593Smuzhiyun 							   "del");
4532*4882a593Smuzhiyun 			curr_ie_buf += del_add_ie_buf_len;
4533*4882a593Smuzhiyun 			total_ie_buf_len += del_add_ie_buf_len;
4534*4882a593Smuzhiyun 		}
4535*4882a593Smuzhiyun 	}
4536*4882a593Smuzhiyun 
4537*4882a593Smuzhiyun 	*mgmt_ie_len = 0;
4538*4882a593Smuzhiyun 	/* Add if there is any extra IE */
4539*4882a593Smuzhiyun 	if (mgmt_ie_buf && parsed_ie_buf_len) {
4540*4882a593Smuzhiyun 		ptr = mgmt_ie_buf;
4541*4882a593Smuzhiyun 
4542*4882a593Smuzhiyun 		remained_buf_len = mgmt_ie_buf_len;
4543*4882a593Smuzhiyun 
4544*4882a593Smuzhiyun 		/* make a command to add new ie */
4545*4882a593Smuzhiyun 		for (i = 0; i < new_vndr_ies.count; i++) {
4546*4882a593Smuzhiyun 			vndrie_info = &new_vndr_ies.ie_info[i];
4547*4882a593Smuzhiyun 
4548*4882a593Smuzhiyun 			/* verify remained buf size before copy data */
4549*4882a593Smuzhiyun 			if (remained_buf_len < (vndrie_info->vndrie.len +
4550*4882a593Smuzhiyun 							VNDR_IE_VSIE_OFFSET)) {
4551*4882a593Smuzhiyun 				bphy_err(drvr, "no space in mgmt_ie_buf: len left %d",
4552*4882a593Smuzhiyun 					 remained_buf_len);
4553*4882a593Smuzhiyun 				break;
4554*4882a593Smuzhiyun 			}
4555*4882a593Smuzhiyun 			remained_buf_len -= (vndrie_info->ie_len +
4556*4882a593Smuzhiyun 					     VNDR_IE_VSIE_OFFSET);
4557*4882a593Smuzhiyun 
4558*4882a593Smuzhiyun 			brcmf_dbg(TRACE, "ADDED ID : %d, Len: %d, OUI:%3ph\n",
4559*4882a593Smuzhiyun 				  vndrie_info->vndrie.id,
4560*4882a593Smuzhiyun 				  vndrie_info->vndrie.len,
4561*4882a593Smuzhiyun 				  vndrie_info->vndrie.oui);
4562*4882a593Smuzhiyun 
4563*4882a593Smuzhiyun 			del_add_ie_buf_len = brcmf_vndr_ie(curr_ie_buf, pktflag,
4564*4882a593Smuzhiyun 							   vndrie_info->ie_ptr,
4565*4882a593Smuzhiyun 							   vndrie_info->ie_len,
4566*4882a593Smuzhiyun 							   "add");
4567*4882a593Smuzhiyun 
4568*4882a593Smuzhiyun 			/* save the parsed IE in wl struct */
4569*4882a593Smuzhiyun 			memcpy(ptr + (*mgmt_ie_len), vndrie_info->ie_ptr,
4570*4882a593Smuzhiyun 			       vndrie_info->ie_len);
4571*4882a593Smuzhiyun 			*mgmt_ie_len += vndrie_info->ie_len;
4572*4882a593Smuzhiyun 
4573*4882a593Smuzhiyun 			curr_ie_buf += del_add_ie_buf_len;
4574*4882a593Smuzhiyun 			total_ie_buf_len += del_add_ie_buf_len;
4575*4882a593Smuzhiyun 		}
4576*4882a593Smuzhiyun 	}
4577*4882a593Smuzhiyun 	if (total_ie_buf_len) {
4578*4882a593Smuzhiyun 		err  = brcmf_fil_bsscfg_data_set(ifp, "vndr_ie", iovar_ie_buf,
4579*4882a593Smuzhiyun 						 total_ie_buf_len);
4580*4882a593Smuzhiyun 		if (err)
4581*4882a593Smuzhiyun 			bphy_err(drvr, "vndr ie set error : %d\n", err);
4582*4882a593Smuzhiyun 	}
4583*4882a593Smuzhiyun 
4584*4882a593Smuzhiyun exit:
4585*4882a593Smuzhiyun 	kfree(iovar_ie_buf);
4586*4882a593Smuzhiyun 	return err;
4587*4882a593Smuzhiyun }
4588*4882a593Smuzhiyun 
brcmf_vif_clear_mgmt_ies(struct brcmf_cfg80211_vif * vif)4589*4882a593Smuzhiyun s32 brcmf_vif_clear_mgmt_ies(struct brcmf_cfg80211_vif *vif)
4590*4882a593Smuzhiyun {
4591*4882a593Smuzhiyun 	s32 pktflags[] = {
4592*4882a593Smuzhiyun 		BRCMF_VNDR_IE_PRBREQ_FLAG,
4593*4882a593Smuzhiyun 		BRCMF_VNDR_IE_PRBRSP_FLAG,
4594*4882a593Smuzhiyun 		BRCMF_VNDR_IE_BEACON_FLAG
4595*4882a593Smuzhiyun 	};
4596*4882a593Smuzhiyun 	int i;
4597*4882a593Smuzhiyun 
4598*4882a593Smuzhiyun 	for (i = 0; i < ARRAY_SIZE(pktflags); i++)
4599*4882a593Smuzhiyun 		brcmf_vif_set_mgmt_ie(vif, pktflags[i], NULL, 0);
4600*4882a593Smuzhiyun 
4601*4882a593Smuzhiyun 	memset(&vif->saved_ie, 0, sizeof(vif->saved_ie));
4602*4882a593Smuzhiyun 	return 0;
4603*4882a593Smuzhiyun }
4604*4882a593Smuzhiyun 
4605*4882a593Smuzhiyun static s32
brcmf_config_ap_mgmt_ie(struct brcmf_cfg80211_vif * vif,struct cfg80211_beacon_data * beacon)4606*4882a593Smuzhiyun brcmf_config_ap_mgmt_ie(struct brcmf_cfg80211_vif *vif,
4607*4882a593Smuzhiyun 			struct cfg80211_beacon_data *beacon)
4608*4882a593Smuzhiyun {
4609*4882a593Smuzhiyun 	struct brcmf_pub *drvr = vif->ifp->drvr;
4610*4882a593Smuzhiyun 	s32 err;
4611*4882a593Smuzhiyun 
4612*4882a593Smuzhiyun 	/* Set Beacon IEs to FW */
4613*4882a593Smuzhiyun 	err = brcmf_vif_set_mgmt_ie(vif, BRCMF_VNDR_IE_BEACON_FLAG,
4614*4882a593Smuzhiyun 				    beacon->tail, beacon->tail_len);
4615*4882a593Smuzhiyun 	if (err) {
4616*4882a593Smuzhiyun 		bphy_err(drvr, "Set Beacon IE Failed\n");
4617*4882a593Smuzhiyun 		return err;
4618*4882a593Smuzhiyun 	}
4619*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Applied Vndr IEs for Beacon\n");
4620*4882a593Smuzhiyun 
4621*4882a593Smuzhiyun 	/* Set Probe Response IEs to FW */
4622*4882a593Smuzhiyun 	err = brcmf_vif_set_mgmt_ie(vif, BRCMF_VNDR_IE_PRBRSP_FLAG,
4623*4882a593Smuzhiyun 				    beacon->proberesp_ies,
4624*4882a593Smuzhiyun 				    beacon->proberesp_ies_len);
4625*4882a593Smuzhiyun 	if (err)
4626*4882a593Smuzhiyun 		bphy_err(drvr, "Set Probe Resp IE Failed\n");
4627*4882a593Smuzhiyun 	else
4628*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "Applied Vndr IEs for Probe Resp\n");
4629*4882a593Smuzhiyun 
4630*4882a593Smuzhiyun 	/* Set Assoc Response IEs to FW */
4631*4882a593Smuzhiyun 	err = brcmf_vif_set_mgmt_ie(vif, BRCMF_VNDR_IE_ASSOCRSP_FLAG,
4632*4882a593Smuzhiyun 				    beacon->assocresp_ies,
4633*4882a593Smuzhiyun 				    beacon->assocresp_ies_len);
4634*4882a593Smuzhiyun 	if (err)
4635*4882a593Smuzhiyun 		brcmf_err("Set Assoc Resp IE Failed\n");
4636*4882a593Smuzhiyun 	else
4637*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "Applied Vndr IEs for Assoc Resp\n");
4638*4882a593Smuzhiyun 
4639*4882a593Smuzhiyun 	return err;
4640*4882a593Smuzhiyun }
4641*4882a593Smuzhiyun 
4642*4882a593Smuzhiyun static s32
brcmf_parse_configure_security(struct brcmf_if * ifp,struct cfg80211_ap_settings * settings,enum nl80211_iftype dev_role)4643*4882a593Smuzhiyun brcmf_parse_configure_security(struct brcmf_if *ifp,
4644*4882a593Smuzhiyun 			       struct cfg80211_ap_settings *settings,
4645*4882a593Smuzhiyun 			       enum nl80211_iftype dev_role)
4646*4882a593Smuzhiyun {
4647*4882a593Smuzhiyun 	const struct brcmf_tlv *rsn_ie;
4648*4882a593Smuzhiyun 	const struct brcmf_vs_tlv *wpa_ie;
4649*4882a593Smuzhiyun 	s32 err = 0;
4650*4882a593Smuzhiyun 
4651*4882a593Smuzhiyun 	/* find the RSN_IE */
4652*4882a593Smuzhiyun 	rsn_ie = brcmf_parse_tlvs((u8 *)settings->beacon.tail,
4653*4882a593Smuzhiyun 				  settings->beacon.tail_len, WLAN_EID_RSN);
4654*4882a593Smuzhiyun 
4655*4882a593Smuzhiyun 	/* find the WPA_IE */
4656*4882a593Smuzhiyun 	wpa_ie = brcmf_find_wpaie((u8 *)settings->beacon.tail,
4657*4882a593Smuzhiyun 				  settings->beacon.tail_len);
4658*4882a593Smuzhiyun 
4659*4882a593Smuzhiyun 	if (wpa_ie || rsn_ie) {
4660*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "WPA(2) IE is found\n");
4661*4882a593Smuzhiyun 		if (wpa_ie) {
4662*4882a593Smuzhiyun 			/* WPA IE */
4663*4882a593Smuzhiyun 			err = brcmf_configure_wpaie(ifp, wpa_ie, false);
4664*4882a593Smuzhiyun 			if (err < 0)
4665*4882a593Smuzhiyun 				return err;
4666*4882a593Smuzhiyun 		} else {
4667*4882a593Smuzhiyun 			struct brcmf_vs_tlv *tmp_ie;
4668*4882a593Smuzhiyun 
4669*4882a593Smuzhiyun 			tmp_ie = (struct brcmf_vs_tlv *)rsn_ie;
4670*4882a593Smuzhiyun 
4671*4882a593Smuzhiyun 			/* RSN IE */
4672*4882a593Smuzhiyun 			err = brcmf_configure_wpaie(ifp, tmp_ie, true);
4673*4882a593Smuzhiyun 			if (err < 0)
4674*4882a593Smuzhiyun 				return err;
4675*4882a593Smuzhiyun 		}
4676*4882a593Smuzhiyun 	} else {
4677*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "No WPA(2) IEs found\n");
4678*4882a593Smuzhiyun 		brcmf_configure_opensecurity(ifp);
4679*4882a593Smuzhiyun 	}
4680*4882a593Smuzhiyun 
4681*4882a593Smuzhiyun 	return err;
4682*4882a593Smuzhiyun }
4683*4882a593Smuzhiyun 
4684*4882a593Smuzhiyun static s32
brcmf_cfg80211_start_ap(struct wiphy * wiphy,struct net_device * ndev,struct cfg80211_ap_settings * settings)4685*4882a593Smuzhiyun brcmf_cfg80211_start_ap(struct wiphy *wiphy, struct net_device *ndev,
4686*4882a593Smuzhiyun 			struct cfg80211_ap_settings *settings)
4687*4882a593Smuzhiyun {
4688*4882a593Smuzhiyun 	s32 ie_offset;
4689*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
4690*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
4691*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
4692*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
4693*4882a593Smuzhiyun 	struct cfg80211_crypto_settings *crypto = &settings->crypto;
4694*4882a593Smuzhiyun 	const struct brcmf_tlv *ssid_ie;
4695*4882a593Smuzhiyun 	const struct brcmf_tlv *country_ie;
4696*4882a593Smuzhiyun 	struct brcmf_ssid_le ssid_le;
4697*4882a593Smuzhiyun 	s32 err = -EPERM;
4698*4882a593Smuzhiyun 	struct brcmf_join_params join_params;
4699*4882a593Smuzhiyun 	enum nl80211_iftype dev_role;
4700*4882a593Smuzhiyun 	struct brcmf_fil_bss_enable_le bss_enable;
4701*4882a593Smuzhiyun 	u16 chanspec = chandef_to_chanspec(&cfg->d11inf, &settings->chandef);
4702*4882a593Smuzhiyun 	bool mbss;
4703*4882a593Smuzhiyun 	int is_11d;
4704*4882a593Smuzhiyun 	bool supports_11d;
4705*4882a593Smuzhiyun 
4706*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "ctrlchn=%d, center=%d, bw=%d, beacon_interval=%d, dtim_period=%d,\n",
4707*4882a593Smuzhiyun 		  settings->chandef.chan->hw_value,
4708*4882a593Smuzhiyun 		  settings->chandef.center_freq1, settings->chandef.width,
4709*4882a593Smuzhiyun 		  settings->beacon_interval, settings->dtim_period);
4710*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "ssid=%s(%zu), auth_type=%d, inactivity_timeout=%d\n",
4711*4882a593Smuzhiyun 		  settings->ssid, settings->ssid_len, settings->auth_type,
4712*4882a593Smuzhiyun 		  settings->inactivity_timeout);
4713*4882a593Smuzhiyun 	dev_role = ifp->vif->wdev.iftype;
4714*4882a593Smuzhiyun 	mbss = ifp->vif->mbss;
4715*4882a593Smuzhiyun 
4716*4882a593Smuzhiyun 	/* store current 11d setting */
4717*4882a593Smuzhiyun 	if (brcmf_fil_cmd_int_get(ifp, BRCMF_C_GET_REGULATORY,
4718*4882a593Smuzhiyun 				  &ifp->vif->is_11d)) {
4719*4882a593Smuzhiyun 		is_11d = supports_11d = false;
4720*4882a593Smuzhiyun 	} else {
4721*4882a593Smuzhiyun 		country_ie = brcmf_parse_tlvs((u8 *)settings->beacon.tail,
4722*4882a593Smuzhiyun 					      settings->beacon.tail_len,
4723*4882a593Smuzhiyun 					      WLAN_EID_COUNTRY);
4724*4882a593Smuzhiyun 		is_11d = country_ie ? 1 : 0;
4725*4882a593Smuzhiyun 		supports_11d = true;
4726*4882a593Smuzhiyun 	}
4727*4882a593Smuzhiyun 
4728*4882a593Smuzhiyun 	memset(&ssid_le, 0, sizeof(ssid_le));
4729*4882a593Smuzhiyun 	if (settings->ssid == NULL || settings->ssid_len == 0) {
4730*4882a593Smuzhiyun 		ie_offset = DOT11_MGMT_HDR_LEN + DOT11_BCN_PRB_FIXED_LEN;
4731*4882a593Smuzhiyun 		ssid_ie = brcmf_parse_tlvs(
4732*4882a593Smuzhiyun 				(u8 *)&settings->beacon.head[ie_offset],
4733*4882a593Smuzhiyun 				settings->beacon.head_len - ie_offset,
4734*4882a593Smuzhiyun 				WLAN_EID_SSID);
4735*4882a593Smuzhiyun 		if (!ssid_ie || ssid_ie->len > IEEE80211_MAX_SSID_LEN)
4736*4882a593Smuzhiyun 			return -EINVAL;
4737*4882a593Smuzhiyun 
4738*4882a593Smuzhiyun 		memcpy(ssid_le.SSID, ssid_ie->data, ssid_ie->len);
4739*4882a593Smuzhiyun 		ssid_le.SSID_len = cpu_to_le32(ssid_ie->len);
4740*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "SSID is (%s) in Head\n", ssid_le.SSID);
4741*4882a593Smuzhiyun 	} else {
4742*4882a593Smuzhiyun 		memcpy(ssid_le.SSID, settings->ssid, settings->ssid_len);
4743*4882a593Smuzhiyun 		ssid_le.SSID_len = cpu_to_le32((u32)settings->ssid_len);
4744*4882a593Smuzhiyun 	}
4745*4882a593Smuzhiyun 
4746*4882a593Smuzhiyun 	if (!mbss) {
4747*4882a593Smuzhiyun 		brcmf_set_mpc(ifp, 0);
4748*4882a593Smuzhiyun 		brcmf_configure_arp_nd_offload(ifp, false);
4749*4882a593Smuzhiyun 	}
4750*4882a593Smuzhiyun 
4751*4882a593Smuzhiyun 	/* Parameters shared by all radio interfaces */
4752*4882a593Smuzhiyun 	if (!mbss) {
4753*4882a593Smuzhiyun 		if ((supports_11d) && (is_11d != ifp->vif->is_11d)) {
4754*4882a593Smuzhiyun 			err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_REGULATORY,
4755*4882a593Smuzhiyun 						    is_11d);
4756*4882a593Smuzhiyun 			if (err < 0) {
4757*4882a593Smuzhiyun 				bphy_err(drvr, "Regulatory Set Error, %d\n",
4758*4882a593Smuzhiyun 					 err);
4759*4882a593Smuzhiyun 				goto exit;
4760*4882a593Smuzhiyun 			}
4761*4882a593Smuzhiyun 		}
4762*4882a593Smuzhiyun 		if (settings->beacon_interval) {
4763*4882a593Smuzhiyun 			err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_BCNPRD,
4764*4882a593Smuzhiyun 						    settings->beacon_interval);
4765*4882a593Smuzhiyun 			if (err < 0) {
4766*4882a593Smuzhiyun 				bphy_err(drvr, "Beacon Interval Set Error, %d\n",
4767*4882a593Smuzhiyun 					 err);
4768*4882a593Smuzhiyun 				goto exit;
4769*4882a593Smuzhiyun 			}
4770*4882a593Smuzhiyun 		}
4771*4882a593Smuzhiyun 		if (settings->dtim_period) {
4772*4882a593Smuzhiyun 			err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_DTIMPRD,
4773*4882a593Smuzhiyun 						    settings->dtim_period);
4774*4882a593Smuzhiyun 			if (err < 0) {
4775*4882a593Smuzhiyun 				bphy_err(drvr, "DTIM Interval Set Error, %d\n",
4776*4882a593Smuzhiyun 					 err);
4777*4882a593Smuzhiyun 				goto exit;
4778*4882a593Smuzhiyun 			}
4779*4882a593Smuzhiyun 		}
4780*4882a593Smuzhiyun 
4781*4882a593Smuzhiyun 		if ((dev_role == NL80211_IFTYPE_AP) &&
4782*4882a593Smuzhiyun 		    ((ifp->ifidx == 0) ||
4783*4882a593Smuzhiyun 		     (!brcmf_feat_is_enabled(ifp, BRCMF_FEAT_RSDB) &&
4784*4882a593Smuzhiyun 		      !brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MCHAN)))) {
4785*4882a593Smuzhiyun 			err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_DOWN, 1);
4786*4882a593Smuzhiyun 			if (err < 0) {
4787*4882a593Smuzhiyun 				bphy_err(drvr, "BRCMF_C_DOWN error %d\n",
4788*4882a593Smuzhiyun 					 err);
4789*4882a593Smuzhiyun 				goto exit;
4790*4882a593Smuzhiyun 			}
4791*4882a593Smuzhiyun 			brcmf_fil_iovar_int_set(ifp, "apsta", 0);
4792*4882a593Smuzhiyun 		}
4793*4882a593Smuzhiyun 
4794*4882a593Smuzhiyun 		err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_INFRA, 1);
4795*4882a593Smuzhiyun 		if (err < 0) {
4796*4882a593Smuzhiyun 			bphy_err(drvr, "SET INFRA error %d\n", err);
4797*4882a593Smuzhiyun 			goto exit;
4798*4882a593Smuzhiyun 		}
4799*4882a593Smuzhiyun 	} else if (WARN_ON(supports_11d && (is_11d != ifp->vif->is_11d))) {
4800*4882a593Smuzhiyun 		/* Multiple-BSS should use same 11d configuration */
4801*4882a593Smuzhiyun 		err = -EINVAL;
4802*4882a593Smuzhiyun 		goto exit;
4803*4882a593Smuzhiyun 	}
4804*4882a593Smuzhiyun 
4805*4882a593Smuzhiyun 	/* Interface specific setup */
4806*4882a593Smuzhiyun 	if (dev_role == NL80211_IFTYPE_AP) {
4807*4882a593Smuzhiyun 		if ((brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MBSS)) && (!mbss))
4808*4882a593Smuzhiyun 			brcmf_fil_iovar_int_set(ifp, "mbss", 1);
4809*4882a593Smuzhiyun 
4810*4882a593Smuzhiyun 		err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_AP, 1);
4811*4882a593Smuzhiyun 		if (err < 0) {
4812*4882a593Smuzhiyun 			bphy_err(drvr, "setting AP mode failed %d\n",
4813*4882a593Smuzhiyun 				 err);
4814*4882a593Smuzhiyun 			goto exit;
4815*4882a593Smuzhiyun 		}
4816*4882a593Smuzhiyun 		if (!mbss) {
4817*4882a593Smuzhiyun 			/* Firmware 10.x requires setting channel after enabling
4818*4882a593Smuzhiyun 			 * AP and before bringing interface up.
4819*4882a593Smuzhiyun 			 */
4820*4882a593Smuzhiyun 			err = brcmf_fil_iovar_int_set(ifp, "chanspec", chanspec);
4821*4882a593Smuzhiyun 			if (err < 0) {
4822*4882a593Smuzhiyun 				bphy_err(drvr, "Set Channel failed: chspec=%d, %d\n",
4823*4882a593Smuzhiyun 					 chanspec, err);
4824*4882a593Smuzhiyun 				goto exit;
4825*4882a593Smuzhiyun 			}
4826*4882a593Smuzhiyun 		}
4827*4882a593Smuzhiyun 		err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_UP, 1);
4828*4882a593Smuzhiyun 		if (err < 0) {
4829*4882a593Smuzhiyun 			bphy_err(drvr, "BRCMF_C_UP error (%d)\n", err);
4830*4882a593Smuzhiyun 			goto exit;
4831*4882a593Smuzhiyun 		}
4832*4882a593Smuzhiyun 
4833*4882a593Smuzhiyun 		if (crypto->psk) {
4834*4882a593Smuzhiyun 			brcmf_dbg(INFO, "using PSK offload\n");
4835*4882a593Smuzhiyun 			profile->use_fwauth |= BIT(BRCMF_PROFILE_FWAUTH_PSK);
4836*4882a593Smuzhiyun 			err = brcmf_set_pmk(ifp, crypto->psk,
4837*4882a593Smuzhiyun 					    BRCMF_WSEC_MAX_PSK_LEN);
4838*4882a593Smuzhiyun 			if (err < 0)
4839*4882a593Smuzhiyun 				goto exit;
4840*4882a593Smuzhiyun 		}
4841*4882a593Smuzhiyun 		if (crypto->sae_pwd) {
4842*4882a593Smuzhiyun 			brcmf_dbg(INFO, "using SAE offload\n");
4843*4882a593Smuzhiyun 			profile->use_fwauth |= BIT(BRCMF_PROFILE_FWAUTH_SAE);
4844*4882a593Smuzhiyun 			err = brcmf_set_sae_password(ifp, crypto->sae_pwd,
4845*4882a593Smuzhiyun 						     crypto->sae_pwd_len);
4846*4882a593Smuzhiyun 			if (err < 0)
4847*4882a593Smuzhiyun 				goto exit;
4848*4882a593Smuzhiyun 		}
4849*4882a593Smuzhiyun 		if (profile->use_fwauth == 0)
4850*4882a593Smuzhiyun 			profile->use_fwauth = BIT(BRCMF_PROFILE_FWAUTH_NONE);
4851*4882a593Smuzhiyun 
4852*4882a593Smuzhiyun 		err = brcmf_parse_configure_security(ifp, settings,
4853*4882a593Smuzhiyun 						     NL80211_IFTYPE_AP);
4854*4882a593Smuzhiyun 		if (err < 0) {
4855*4882a593Smuzhiyun 			bphy_err(drvr, "brcmf_parse_configure_security error\n");
4856*4882a593Smuzhiyun 			goto exit;
4857*4882a593Smuzhiyun 		}
4858*4882a593Smuzhiyun 
4859*4882a593Smuzhiyun 		/* On DOWN the firmware removes the WEP keys, reconfigure
4860*4882a593Smuzhiyun 		 * them if they were set.
4861*4882a593Smuzhiyun 		 */
4862*4882a593Smuzhiyun 		brcmf_cfg80211_reconfigure_wep(ifp);
4863*4882a593Smuzhiyun 
4864*4882a593Smuzhiyun 		memset(&join_params, 0, sizeof(join_params));
4865*4882a593Smuzhiyun 		/* join parameters starts with ssid */
4866*4882a593Smuzhiyun 		memcpy(&join_params.ssid_le, &ssid_le, sizeof(ssid_le));
4867*4882a593Smuzhiyun 		/* create softap */
4868*4882a593Smuzhiyun 		err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SET_SSID,
4869*4882a593Smuzhiyun 					     &join_params, sizeof(join_params));
4870*4882a593Smuzhiyun 		if (err < 0) {
4871*4882a593Smuzhiyun 			bphy_err(drvr, "SET SSID error (%d)\n", err);
4872*4882a593Smuzhiyun 			goto exit;
4873*4882a593Smuzhiyun 		}
4874*4882a593Smuzhiyun 
4875*4882a593Smuzhiyun 		err = brcmf_fil_iovar_int_set(ifp, "closednet",
4876*4882a593Smuzhiyun 					      settings->hidden_ssid);
4877*4882a593Smuzhiyun 		if (err) {
4878*4882a593Smuzhiyun 			bphy_err(drvr, "%s closednet error (%d)\n",
4879*4882a593Smuzhiyun 				 settings->hidden_ssid ?
4880*4882a593Smuzhiyun 				 "enabled" : "disabled",
4881*4882a593Smuzhiyun 				 err);
4882*4882a593Smuzhiyun 			goto exit;
4883*4882a593Smuzhiyun 		}
4884*4882a593Smuzhiyun 
4885*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "AP mode configuration complete\n");
4886*4882a593Smuzhiyun 	} else if (dev_role == NL80211_IFTYPE_P2P_GO) {
4887*4882a593Smuzhiyun 		err = brcmf_fil_iovar_int_set(ifp, "chanspec", chanspec);
4888*4882a593Smuzhiyun 		if (err < 0) {
4889*4882a593Smuzhiyun 			bphy_err(drvr, "Set Channel failed: chspec=%d, %d\n",
4890*4882a593Smuzhiyun 				 chanspec, err);
4891*4882a593Smuzhiyun 			goto exit;
4892*4882a593Smuzhiyun 		}
4893*4882a593Smuzhiyun 
4894*4882a593Smuzhiyun 		err = brcmf_parse_configure_security(ifp, settings,
4895*4882a593Smuzhiyun 						     NL80211_IFTYPE_P2P_GO);
4896*4882a593Smuzhiyun 		if (err < 0) {
4897*4882a593Smuzhiyun 			brcmf_err("brcmf_parse_configure_security error\n");
4898*4882a593Smuzhiyun 			goto exit;
4899*4882a593Smuzhiyun 		}
4900*4882a593Smuzhiyun 
4901*4882a593Smuzhiyun 		err = brcmf_fil_bsscfg_data_set(ifp, "ssid", &ssid_le,
4902*4882a593Smuzhiyun 						sizeof(ssid_le));
4903*4882a593Smuzhiyun 		if (err < 0) {
4904*4882a593Smuzhiyun 			bphy_err(drvr, "setting ssid failed %d\n", err);
4905*4882a593Smuzhiyun 			goto exit;
4906*4882a593Smuzhiyun 		}
4907*4882a593Smuzhiyun 		bss_enable.bsscfgidx = cpu_to_le32(ifp->bsscfgidx);
4908*4882a593Smuzhiyun 		bss_enable.enable = cpu_to_le32(1);
4909*4882a593Smuzhiyun 		err = brcmf_fil_iovar_data_set(ifp, "bss", &bss_enable,
4910*4882a593Smuzhiyun 					       sizeof(bss_enable));
4911*4882a593Smuzhiyun 		if (err < 0) {
4912*4882a593Smuzhiyun 			bphy_err(drvr, "bss_enable config failed %d\n", err);
4913*4882a593Smuzhiyun 			goto exit;
4914*4882a593Smuzhiyun 		}
4915*4882a593Smuzhiyun 
4916*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "GO mode configuration complete\n");
4917*4882a593Smuzhiyun 	} else {
4918*4882a593Smuzhiyun 		WARN_ON(1);
4919*4882a593Smuzhiyun 	}
4920*4882a593Smuzhiyun 
4921*4882a593Smuzhiyun 	brcmf_config_ap_mgmt_ie(ifp->vif, &settings->beacon);
4922*4882a593Smuzhiyun 	set_bit(BRCMF_VIF_STATUS_AP_CREATED, &ifp->vif->sme_state);
4923*4882a593Smuzhiyun 	brcmf_net_setcarrier(ifp, true);
4924*4882a593Smuzhiyun 
4925*4882a593Smuzhiyun exit:
4926*4882a593Smuzhiyun 	if ((err) && (!mbss)) {
4927*4882a593Smuzhiyun 		brcmf_set_mpc(ifp, 1);
4928*4882a593Smuzhiyun 		brcmf_configure_arp_nd_offload(ifp, true);
4929*4882a593Smuzhiyun 	}
4930*4882a593Smuzhiyun 	return err;
4931*4882a593Smuzhiyun }
4932*4882a593Smuzhiyun 
brcmf_cfg80211_stop_ap(struct wiphy * wiphy,struct net_device * ndev)4933*4882a593Smuzhiyun static int brcmf_cfg80211_stop_ap(struct wiphy *wiphy, struct net_device *ndev)
4934*4882a593Smuzhiyun {
4935*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
4936*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
4937*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
4938*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
4939*4882a593Smuzhiyun 	s32 err;
4940*4882a593Smuzhiyun 	struct brcmf_fil_bss_enable_le bss_enable;
4941*4882a593Smuzhiyun 	struct brcmf_join_params join_params;
4942*4882a593Smuzhiyun 
4943*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
4944*4882a593Smuzhiyun 
4945*4882a593Smuzhiyun 	if (ifp->vif->wdev.iftype == NL80211_IFTYPE_AP) {
4946*4882a593Smuzhiyun 		/* Due to most likely deauths outstanding we sleep */
4947*4882a593Smuzhiyun 		/* first to make sure they get processed by fw. */
4948*4882a593Smuzhiyun 		msleep(400);
4949*4882a593Smuzhiyun 
4950*4882a593Smuzhiyun 		if (profile->use_fwauth != BIT(BRCMF_PROFILE_FWAUTH_NONE)) {
4951*4882a593Smuzhiyun 			if (profile->use_fwauth & BIT(BRCMF_PROFILE_FWAUTH_PSK))
4952*4882a593Smuzhiyun 				brcmf_set_pmk(ifp, NULL, 0);
4953*4882a593Smuzhiyun 			if (profile->use_fwauth & BIT(BRCMF_PROFILE_FWAUTH_SAE))
4954*4882a593Smuzhiyun 				brcmf_set_sae_password(ifp, NULL, 0);
4955*4882a593Smuzhiyun 			profile->use_fwauth = BIT(BRCMF_PROFILE_FWAUTH_NONE);
4956*4882a593Smuzhiyun 		}
4957*4882a593Smuzhiyun 
4958*4882a593Smuzhiyun 		if (ifp->vif->mbss) {
4959*4882a593Smuzhiyun 			err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_DOWN, 1);
4960*4882a593Smuzhiyun 			return err;
4961*4882a593Smuzhiyun 		}
4962*4882a593Smuzhiyun 
4963*4882a593Smuzhiyun 		/* First BSS doesn't get a full reset */
4964*4882a593Smuzhiyun 		if (ifp->bsscfgidx == 0)
4965*4882a593Smuzhiyun 			brcmf_fil_iovar_int_set(ifp, "closednet", 0);
4966*4882a593Smuzhiyun 
4967*4882a593Smuzhiyun 		memset(&join_params, 0, sizeof(join_params));
4968*4882a593Smuzhiyun 		err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SET_SSID,
4969*4882a593Smuzhiyun 					     &join_params, sizeof(join_params));
4970*4882a593Smuzhiyun 		if (err < 0)
4971*4882a593Smuzhiyun 			bphy_err(drvr, "SET SSID error (%d)\n", err);
4972*4882a593Smuzhiyun 		err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_DOWN, 1);
4973*4882a593Smuzhiyun 		if (err < 0)
4974*4882a593Smuzhiyun 			bphy_err(drvr, "BRCMF_C_DOWN error %d\n", err);
4975*4882a593Smuzhiyun 		err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_AP, 0);
4976*4882a593Smuzhiyun 		if (err < 0)
4977*4882a593Smuzhiyun 			bphy_err(drvr, "setting AP mode failed %d\n", err);
4978*4882a593Smuzhiyun 		if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MBSS))
4979*4882a593Smuzhiyun 			brcmf_fil_iovar_int_set(ifp, "mbss", 0);
4980*4882a593Smuzhiyun 		brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_REGULATORY,
4981*4882a593Smuzhiyun 				      ifp->vif->is_11d);
4982*4882a593Smuzhiyun 		/* Bring device back up so it can be used again */
4983*4882a593Smuzhiyun 		err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_UP, 1);
4984*4882a593Smuzhiyun 		if (err < 0)
4985*4882a593Smuzhiyun 			bphy_err(drvr, "BRCMF_C_UP error %d\n", err);
4986*4882a593Smuzhiyun 
4987*4882a593Smuzhiyun 		brcmf_vif_clear_mgmt_ies(ifp->vif);
4988*4882a593Smuzhiyun 	} else {
4989*4882a593Smuzhiyun 		bss_enable.bsscfgidx = cpu_to_le32(ifp->bsscfgidx);
4990*4882a593Smuzhiyun 		bss_enable.enable = cpu_to_le32(0);
4991*4882a593Smuzhiyun 		err = brcmf_fil_iovar_data_set(ifp, "bss", &bss_enable,
4992*4882a593Smuzhiyun 					       sizeof(bss_enable));
4993*4882a593Smuzhiyun 		if (err < 0)
4994*4882a593Smuzhiyun 			bphy_err(drvr, "bss_enable config failed %d\n", err);
4995*4882a593Smuzhiyun 	}
4996*4882a593Smuzhiyun 	brcmf_set_mpc(ifp, 1);
4997*4882a593Smuzhiyun 	brcmf_configure_arp_nd_offload(ifp, true);
4998*4882a593Smuzhiyun 	clear_bit(BRCMF_VIF_STATUS_AP_CREATED, &ifp->vif->sme_state);
4999*4882a593Smuzhiyun 	brcmf_net_setcarrier(ifp, false);
5000*4882a593Smuzhiyun 
5001*4882a593Smuzhiyun 	return err;
5002*4882a593Smuzhiyun }
5003*4882a593Smuzhiyun 
5004*4882a593Smuzhiyun static s32
brcmf_cfg80211_change_beacon(struct wiphy * wiphy,struct net_device * ndev,struct cfg80211_beacon_data * info)5005*4882a593Smuzhiyun brcmf_cfg80211_change_beacon(struct wiphy *wiphy, struct net_device *ndev,
5006*4882a593Smuzhiyun 			     struct cfg80211_beacon_data *info)
5007*4882a593Smuzhiyun {
5008*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
5009*4882a593Smuzhiyun 	s32 err;
5010*4882a593Smuzhiyun 
5011*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
5012*4882a593Smuzhiyun 
5013*4882a593Smuzhiyun 	err = brcmf_config_ap_mgmt_ie(ifp->vif, info);
5014*4882a593Smuzhiyun 
5015*4882a593Smuzhiyun 	return err;
5016*4882a593Smuzhiyun }
5017*4882a593Smuzhiyun 
5018*4882a593Smuzhiyun static int
brcmf_cfg80211_del_station(struct wiphy * wiphy,struct net_device * ndev,struct station_del_parameters * params)5019*4882a593Smuzhiyun brcmf_cfg80211_del_station(struct wiphy *wiphy, struct net_device *ndev,
5020*4882a593Smuzhiyun 			   struct station_del_parameters *params)
5021*4882a593Smuzhiyun {
5022*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5023*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
5024*4882a593Smuzhiyun 	struct brcmf_scb_val_le scbval;
5025*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
5026*4882a593Smuzhiyun 	s32 err;
5027*4882a593Smuzhiyun 
5028*4882a593Smuzhiyun 	if (!params->mac)
5029*4882a593Smuzhiyun 		return -EFAULT;
5030*4882a593Smuzhiyun 
5031*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter %pM\n", params->mac);
5032*4882a593Smuzhiyun 
5033*4882a593Smuzhiyun 	if (ifp->vif == cfg->p2p.bss_idx[P2PAPI_BSSCFG_DEVICE].vif)
5034*4882a593Smuzhiyun 		ifp = cfg->p2p.bss_idx[P2PAPI_BSSCFG_PRIMARY].vif->ifp;
5035*4882a593Smuzhiyun 	if (!check_vif_up(ifp->vif))
5036*4882a593Smuzhiyun 		return -EIO;
5037*4882a593Smuzhiyun 
5038*4882a593Smuzhiyun 	memcpy(&scbval.ea, params->mac, ETH_ALEN);
5039*4882a593Smuzhiyun 	scbval.val = cpu_to_le32(params->reason_code);
5040*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SCB_DEAUTHENTICATE_FOR_REASON,
5041*4882a593Smuzhiyun 				     &scbval, sizeof(scbval));
5042*4882a593Smuzhiyun 	if (err)
5043*4882a593Smuzhiyun 		bphy_err(drvr, "SCB_DEAUTHENTICATE_FOR_REASON failed %d\n",
5044*4882a593Smuzhiyun 			 err);
5045*4882a593Smuzhiyun 
5046*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
5047*4882a593Smuzhiyun 	return err;
5048*4882a593Smuzhiyun }
5049*4882a593Smuzhiyun 
5050*4882a593Smuzhiyun static int
brcmf_cfg80211_change_station(struct wiphy * wiphy,struct net_device * ndev,const u8 * mac,struct station_parameters * params)5051*4882a593Smuzhiyun brcmf_cfg80211_change_station(struct wiphy *wiphy, struct net_device *ndev,
5052*4882a593Smuzhiyun 			      const u8 *mac, struct station_parameters *params)
5053*4882a593Smuzhiyun {
5054*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5055*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
5056*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
5057*4882a593Smuzhiyun 	s32 err;
5058*4882a593Smuzhiyun 
5059*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter, MAC %pM, mask 0x%04x set 0x%04x\n", mac,
5060*4882a593Smuzhiyun 		  params->sta_flags_mask, params->sta_flags_set);
5061*4882a593Smuzhiyun 
5062*4882a593Smuzhiyun 	/* Ignore all 00 MAC */
5063*4882a593Smuzhiyun 	if (is_zero_ether_addr(mac))
5064*4882a593Smuzhiyun 		return 0;
5065*4882a593Smuzhiyun 
5066*4882a593Smuzhiyun 	if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
5067*4882a593Smuzhiyun 		return 0;
5068*4882a593Smuzhiyun 
5069*4882a593Smuzhiyun 	if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED))
5070*4882a593Smuzhiyun 		err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SET_SCB_AUTHORIZE,
5071*4882a593Smuzhiyun 					     (void *)mac, ETH_ALEN);
5072*4882a593Smuzhiyun 	else
5073*4882a593Smuzhiyun 		err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SET_SCB_DEAUTHORIZE,
5074*4882a593Smuzhiyun 					     (void *)mac, ETH_ALEN);
5075*4882a593Smuzhiyun 	if (err < 0)
5076*4882a593Smuzhiyun 		bphy_err(drvr, "Setting SCB (de-)authorize failed, %d\n", err);
5077*4882a593Smuzhiyun 
5078*4882a593Smuzhiyun 	return err;
5079*4882a593Smuzhiyun }
5080*4882a593Smuzhiyun 
5081*4882a593Smuzhiyun static void
brcmf_cfg80211_update_mgmt_frame_registrations(struct wiphy * wiphy,struct wireless_dev * wdev,struct mgmt_frame_regs * upd)5082*4882a593Smuzhiyun brcmf_cfg80211_update_mgmt_frame_registrations(struct wiphy *wiphy,
5083*4882a593Smuzhiyun 					       struct wireless_dev *wdev,
5084*4882a593Smuzhiyun 					       struct mgmt_frame_regs *upd)
5085*4882a593Smuzhiyun {
5086*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
5087*4882a593Smuzhiyun 
5088*4882a593Smuzhiyun 	vif = container_of(wdev, struct brcmf_cfg80211_vif, wdev);
5089*4882a593Smuzhiyun 
5090*4882a593Smuzhiyun 	vif->mgmt_rx_reg = upd->interface_stypes;
5091*4882a593Smuzhiyun }
5092*4882a593Smuzhiyun 
5093*4882a593Smuzhiyun 
5094*4882a593Smuzhiyun static int
brcmf_cfg80211_mgmt_tx(struct wiphy * wiphy,struct wireless_dev * wdev,struct cfg80211_mgmt_tx_params * params,u64 * cookie)5095*4882a593Smuzhiyun brcmf_cfg80211_mgmt_tx(struct wiphy *wiphy, struct wireless_dev *wdev,
5096*4882a593Smuzhiyun 		       struct cfg80211_mgmt_tx_params *params, u64 *cookie)
5097*4882a593Smuzhiyun {
5098*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5099*4882a593Smuzhiyun 	struct ieee80211_channel *chan = params->chan;
5100*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
5101*4882a593Smuzhiyun 	const u8 *buf = params->buf;
5102*4882a593Smuzhiyun 	size_t len = params->len;
5103*4882a593Smuzhiyun 	const struct ieee80211_mgmt *mgmt;
5104*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
5105*4882a593Smuzhiyun 	s32 err = 0;
5106*4882a593Smuzhiyun 	s32 ie_offset;
5107*4882a593Smuzhiyun 	s32 ie_len;
5108*4882a593Smuzhiyun 	struct brcmf_fil_action_frame_le *action_frame;
5109*4882a593Smuzhiyun 	struct brcmf_fil_af_params_le *af_params;
5110*4882a593Smuzhiyun 	bool ack;
5111*4882a593Smuzhiyun 	s32 chan_nr;
5112*4882a593Smuzhiyun 	u32 freq;
5113*4882a593Smuzhiyun 
5114*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
5115*4882a593Smuzhiyun 
5116*4882a593Smuzhiyun 	*cookie = 0;
5117*4882a593Smuzhiyun 
5118*4882a593Smuzhiyun 	mgmt = (const struct ieee80211_mgmt *)buf;
5119*4882a593Smuzhiyun 
5120*4882a593Smuzhiyun 	if (!ieee80211_is_mgmt(mgmt->frame_control)) {
5121*4882a593Smuzhiyun 		bphy_err(drvr, "Driver only allows MGMT packet type\n");
5122*4882a593Smuzhiyun 		return -EPERM;
5123*4882a593Smuzhiyun 	}
5124*4882a593Smuzhiyun 
5125*4882a593Smuzhiyun 	vif = container_of(wdev, struct brcmf_cfg80211_vif, wdev);
5126*4882a593Smuzhiyun 
5127*4882a593Smuzhiyun 	if (ieee80211_is_probe_resp(mgmt->frame_control)) {
5128*4882a593Smuzhiyun 		/* Right now the only reason to get a probe response */
5129*4882a593Smuzhiyun 		/* is for p2p listen response or for p2p GO from     */
5130*4882a593Smuzhiyun 		/* wpa_supplicant. Unfortunately the probe is send   */
5131*4882a593Smuzhiyun 		/* on primary ndev, while dongle wants it on the p2p */
5132*4882a593Smuzhiyun 		/* vif. Since this is only reason for a probe        */
5133*4882a593Smuzhiyun 		/* response to be sent, the vif is taken from cfg.   */
5134*4882a593Smuzhiyun 		/* If ever desired to send proberesp for non p2p     */
5135*4882a593Smuzhiyun 		/* response then data should be checked for          */
5136*4882a593Smuzhiyun 		/* "DIRECT-". Note in future supplicant will take    */
5137*4882a593Smuzhiyun 		/* dedicated p2p wdev to do this and then this 'hack'*/
5138*4882a593Smuzhiyun 		/* is not needed anymore.                            */
5139*4882a593Smuzhiyun 		ie_offset =  DOT11_MGMT_HDR_LEN +
5140*4882a593Smuzhiyun 			     DOT11_BCN_PRB_FIXED_LEN;
5141*4882a593Smuzhiyun 		ie_len = len - ie_offset;
5142*4882a593Smuzhiyun 		if (vif == cfg->p2p.bss_idx[P2PAPI_BSSCFG_PRIMARY].vif)
5143*4882a593Smuzhiyun 			vif = cfg->p2p.bss_idx[P2PAPI_BSSCFG_DEVICE].vif;
5144*4882a593Smuzhiyun 		err = brcmf_vif_set_mgmt_ie(vif,
5145*4882a593Smuzhiyun 					    BRCMF_VNDR_IE_PRBRSP_FLAG,
5146*4882a593Smuzhiyun 					    &buf[ie_offset],
5147*4882a593Smuzhiyun 					    ie_len);
5148*4882a593Smuzhiyun 		cfg80211_mgmt_tx_status(wdev, *cookie, buf, len, true,
5149*4882a593Smuzhiyun 					GFP_KERNEL);
5150*4882a593Smuzhiyun 	} else if (ieee80211_is_action(mgmt->frame_control)) {
5151*4882a593Smuzhiyun 		if (len > BRCMF_FIL_ACTION_FRAME_SIZE + DOT11_MGMT_HDR_LEN) {
5152*4882a593Smuzhiyun 			bphy_err(drvr, "invalid action frame length\n");
5153*4882a593Smuzhiyun 			err = -EINVAL;
5154*4882a593Smuzhiyun 			goto exit;
5155*4882a593Smuzhiyun 		}
5156*4882a593Smuzhiyun 		af_params = kzalloc(sizeof(*af_params), GFP_KERNEL);
5157*4882a593Smuzhiyun 		if (af_params == NULL) {
5158*4882a593Smuzhiyun 			bphy_err(drvr, "unable to allocate frame\n");
5159*4882a593Smuzhiyun 			err = -ENOMEM;
5160*4882a593Smuzhiyun 			goto exit;
5161*4882a593Smuzhiyun 		}
5162*4882a593Smuzhiyun 		action_frame = &af_params->action_frame;
5163*4882a593Smuzhiyun 		/* Add the packet Id */
5164*4882a593Smuzhiyun 		action_frame->packet_id = cpu_to_le32(*cookie);
5165*4882a593Smuzhiyun 		/* Add BSSID */
5166*4882a593Smuzhiyun 		memcpy(&action_frame->da[0], &mgmt->da[0], ETH_ALEN);
5167*4882a593Smuzhiyun 		memcpy(&af_params->bssid[0], &mgmt->bssid[0], ETH_ALEN);
5168*4882a593Smuzhiyun 		/* Add the length exepted for 802.11 header  */
5169*4882a593Smuzhiyun 		action_frame->len = cpu_to_le16(len - DOT11_MGMT_HDR_LEN);
5170*4882a593Smuzhiyun 		/* Add the channel. Use the one specified as parameter if any or
5171*4882a593Smuzhiyun 		 * the current one (got from the firmware) otherwise
5172*4882a593Smuzhiyun 		 */
5173*4882a593Smuzhiyun 		if (chan)
5174*4882a593Smuzhiyun 			freq = chan->center_freq;
5175*4882a593Smuzhiyun 		else
5176*4882a593Smuzhiyun 			brcmf_fil_cmd_int_get(vif->ifp, BRCMF_C_GET_CHANNEL,
5177*4882a593Smuzhiyun 					      &freq);
5178*4882a593Smuzhiyun 		chan_nr = ieee80211_frequency_to_channel(freq);
5179*4882a593Smuzhiyun 		af_params->channel = cpu_to_le32(chan_nr);
5180*4882a593Smuzhiyun 		af_params->dwell_time = cpu_to_le32(params->wait);
5181*4882a593Smuzhiyun 		memcpy(action_frame->data, &buf[DOT11_MGMT_HDR_LEN],
5182*4882a593Smuzhiyun 		       le16_to_cpu(action_frame->len));
5183*4882a593Smuzhiyun 
5184*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "Action frame, cookie=%lld, len=%d, freq=%d\n",
5185*4882a593Smuzhiyun 			  *cookie, le16_to_cpu(action_frame->len), freq);
5186*4882a593Smuzhiyun 
5187*4882a593Smuzhiyun 		ack = brcmf_p2p_send_action_frame(cfg, cfg_to_ndev(cfg),
5188*4882a593Smuzhiyun 						  af_params);
5189*4882a593Smuzhiyun 
5190*4882a593Smuzhiyun 		cfg80211_mgmt_tx_status(wdev, *cookie, buf, len, ack,
5191*4882a593Smuzhiyun 					GFP_KERNEL);
5192*4882a593Smuzhiyun 		kfree(af_params);
5193*4882a593Smuzhiyun 	} else {
5194*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "Unhandled, fc=%04x!!\n", mgmt->frame_control);
5195*4882a593Smuzhiyun 		brcmf_dbg_hex_dump(true, buf, len, "payload, len=%zu\n", len);
5196*4882a593Smuzhiyun 	}
5197*4882a593Smuzhiyun 
5198*4882a593Smuzhiyun exit:
5199*4882a593Smuzhiyun 	return err;
5200*4882a593Smuzhiyun }
5201*4882a593Smuzhiyun 
5202*4882a593Smuzhiyun 
5203*4882a593Smuzhiyun static int
brcmf_cfg80211_cancel_remain_on_channel(struct wiphy * wiphy,struct wireless_dev * wdev,u64 cookie)5204*4882a593Smuzhiyun brcmf_cfg80211_cancel_remain_on_channel(struct wiphy *wiphy,
5205*4882a593Smuzhiyun 					struct wireless_dev *wdev,
5206*4882a593Smuzhiyun 					u64 cookie)
5207*4882a593Smuzhiyun {
5208*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5209*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
5210*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
5211*4882a593Smuzhiyun 	int err = 0;
5212*4882a593Smuzhiyun 
5213*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter p2p listen cancel\n");
5214*4882a593Smuzhiyun 
5215*4882a593Smuzhiyun 	vif = cfg->p2p.bss_idx[P2PAPI_BSSCFG_DEVICE].vif;
5216*4882a593Smuzhiyun 	if (vif == NULL) {
5217*4882a593Smuzhiyun 		bphy_err(drvr, "No p2p device available for probe response\n");
5218*4882a593Smuzhiyun 		err = -ENODEV;
5219*4882a593Smuzhiyun 		goto exit;
5220*4882a593Smuzhiyun 	}
5221*4882a593Smuzhiyun 	brcmf_p2p_cancel_remain_on_channel(vif->ifp);
5222*4882a593Smuzhiyun exit:
5223*4882a593Smuzhiyun 	return err;
5224*4882a593Smuzhiyun }
5225*4882a593Smuzhiyun 
brcmf_cfg80211_get_channel(struct wiphy * wiphy,struct wireless_dev * wdev,struct cfg80211_chan_def * chandef)5226*4882a593Smuzhiyun static int brcmf_cfg80211_get_channel(struct wiphy *wiphy,
5227*4882a593Smuzhiyun 				      struct wireless_dev *wdev,
5228*4882a593Smuzhiyun 				      struct cfg80211_chan_def *chandef)
5229*4882a593Smuzhiyun {
5230*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5231*4882a593Smuzhiyun 	struct net_device *ndev = wdev->netdev;
5232*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
5233*4882a593Smuzhiyun 	struct brcmu_chan ch;
5234*4882a593Smuzhiyun 	enum nl80211_band band = 0;
5235*4882a593Smuzhiyun 	enum nl80211_chan_width width = 0;
5236*4882a593Smuzhiyun 	u32 chanspec;
5237*4882a593Smuzhiyun 	int freq, err;
5238*4882a593Smuzhiyun 
5239*4882a593Smuzhiyun 	if (!ndev || drvr->bus_if->state != BRCMF_BUS_UP)
5240*4882a593Smuzhiyun 		return -ENODEV;
5241*4882a593Smuzhiyun 
5242*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_get(netdev_priv(ndev), "chanspec", &chanspec);
5243*4882a593Smuzhiyun 	if (err) {
5244*4882a593Smuzhiyun 		bphy_err(drvr, "chanspec failed (%d)\n", err);
5245*4882a593Smuzhiyun 		return err;
5246*4882a593Smuzhiyun 	}
5247*4882a593Smuzhiyun 
5248*4882a593Smuzhiyun 	ch.chspec = chanspec;
5249*4882a593Smuzhiyun 	cfg->d11inf.decchspec(&ch);
5250*4882a593Smuzhiyun 
5251*4882a593Smuzhiyun 	switch (ch.band) {
5252*4882a593Smuzhiyun 	case BRCMU_CHAN_BAND_2G:
5253*4882a593Smuzhiyun 		band = NL80211_BAND_2GHZ;
5254*4882a593Smuzhiyun 		break;
5255*4882a593Smuzhiyun 	case BRCMU_CHAN_BAND_5G:
5256*4882a593Smuzhiyun 		band = NL80211_BAND_5GHZ;
5257*4882a593Smuzhiyun 		break;
5258*4882a593Smuzhiyun 	}
5259*4882a593Smuzhiyun 
5260*4882a593Smuzhiyun 	switch (ch.bw) {
5261*4882a593Smuzhiyun 	case BRCMU_CHAN_BW_80:
5262*4882a593Smuzhiyun 		width = NL80211_CHAN_WIDTH_80;
5263*4882a593Smuzhiyun 		break;
5264*4882a593Smuzhiyun 	case BRCMU_CHAN_BW_40:
5265*4882a593Smuzhiyun 		width = NL80211_CHAN_WIDTH_40;
5266*4882a593Smuzhiyun 		break;
5267*4882a593Smuzhiyun 	case BRCMU_CHAN_BW_20:
5268*4882a593Smuzhiyun 		width = NL80211_CHAN_WIDTH_20;
5269*4882a593Smuzhiyun 		break;
5270*4882a593Smuzhiyun 	case BRCMU_CHAN_BW_80P80:
5271*4882a593Smuzhiyun 		width = NL80211_CHAN_WIDTH_80P80;
5272*4882a593Smuzhiyun 		break;
5273*4882a593Smuzhiyun 	case BRCMU_CHAN_BW_160:
5274*4882a593Smuzhiyun 		width = NL80211_CHAN_WIDTH_160;
5275*4882a593Smuzhiyun 		break;
5276*4882a593Smuzhiyun 	}
5277*4882a593Smuzhiyun 
5278*4882a593Smuzhiyun 	freq = ieee80211_channel_to_frequency(ch.control_ch_num, band);
5279*4882a593Smuzhiyun 	chandef->chan = ieee80211_get_channel(wiphy, freq);
5280*4882a593Smuzhiyun 	chandef->width = width;
5281*4882a593Smuzhiyun 	chandef->center_freq1 = ieee80211_channel_to_frequency(ch.chnum, band);
5282*4882a593Smuzhiyun 	chandef->center_freq2 = 0;
5283*4882a593Smuzhiyun 
5284*4882a593Smuzhiyun 	return 0;
5285*4882a593Smuzhiyun }
5286*4882a593Smuzhiyun 
brcmf_cfg80211_crit_proto_start(struct wiphy * wiphy,struct wireless_dev * wdev,enum nl80211_crit_proto_id proto,u16 duration)5287*4882a593Smuzhiyun static int brcmf_cfg80211_crit_proto_start(struct wiphy *wiphy,
5288*4882a593Smuzhiyun 					   struct wireless_dev *wdev,
5289*4882a593Smuzhiyun 					   enum nl80211_crit_proto_id proto,
5290*4882a593Smuzhiyun 					   u16 duration)
5291*4882a593Smuzhiyun {
5292*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5293*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
5294*4882a593Smuzhiyun 
5295*4882a593Smuzhiyun 	vif = container_of(wdev, struct brcmf_cfg80211_vif, wdev);
5296*4882a593Smuzhiyun 
5297*4882a593Smuzhiyun 	/* only DHCP support for now */
5298*4882a593Smuzhiyun 	if (proto != NL80211_CRIT_PROTO_DHCP)
5299*4882a593Smuzhiyun 		return -EINVAL;
5300*4882a593Smuzhiyun 
5301*4882a593Smuzhiyun 	/* suppress and abort scanning */
5302*4882a593Smuzhiyun 	set_bit(BRCMF_SCAN_STATUS_SUPPRESS, &cfg->scan_status);
5303*4882a593Smuzhiyun 	brcmf_abort_scanning(cfg);
5304*4882a593Smuzhiyun 
5305*4882a593Smuzhiyun 	return brcmf_btcoex_set_mode(vif, BRCMF_BTCOEX_DISABLED, duration);
5306*4882a593Smuzhiyun }
5307*4882a593Smuzhiyun 
brcmf_cfg80211_crit_proto_stop(struct wiphy * wiphy,struct wireless_dev * wdev)5308*4882a593Smuzhiyun static void brcmf_cfg80211_crit_proto_stop(struct wiphy *wiphy,
5309*4882a593Smuzhiyun 					   struct wireless_dev *wdev)
5310*4882a593Smuzhiyun {
5311*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5312*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
5313*4882a593Smuzhiyun 
5314*4882a593Smuzhiyun 	vif = container_of(wdev, struct brcmf_cfg80211_vif, wdev);
5315*4882a593Smuzhiyun 
5316*4882a593Smuzhiyun 	brcmf_btcoex_set_mode(vif, BRCMF_BTCOEX_ENABLED, 0);
5317*4882a593Smuzhiyun 	clear_bit(BRCMF_SCAN_STATUS_SUPPRESS, &cfg->scan_status);
5318*4882a593Smuzhiyun }
5319*4882a593Smuzhiyun 
5320*4882a593Smuzhiyun static s32
brcmf_notify_tdls_peer_event(struct brcmf_if * ifp,const struct brcmf_event_msg * e,void * data)5321*4882a593Smuzhiyun brcmf_notify_tdls_peer_event(struct brcmf_if *ifp,
5322*4882a593Smuzhiyun 			     const struct brcmf_event_msg *e, void *data)
5323*4882a593Smuzhiyun {
5324*4882a593Smuzhiyun 	switch (e->reason) {
5325*4882a593Smuzhiyun 	case BRCMF_E_REASON_TDLS_PEER_DISCOVERED:
5326*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "TDLS Peer Discovered\n");
5327*4882a593Smuzhiyun 		break;
5328*4882a593Smuzhiyun 	case BRCMF_E_REASON_TDLS_PEER_CONNECTED:
5329*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "TDLS Peer Connected\n");
5330*4882a593Smuzhiyun 		brcmf_proto_add_tdls_peer(ifp->drvr, ifp->ifidx, (u8 *)e->addr);
5331*4882a593Smuzhiyun 		break;
5332*4882a593Smuzhiyun 	case BRCMF_E_REASON_TDLS_PEER_DISCONNECTED:
5333*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "TDLS Peer Disconnected\n");
5334*4882a593Smuzhiyun 		brcmf_proto_delete_peer(ifp->drvr, ifp->ifidx, (u8 *)e->addr);
5335*4882a593Smuzhiyun 		break;
5336*4882a593Smuzhiyun 	}
5337*4882a593Smuzhiyun 
5338*4882a593Smuzhiyun 	return 0;
5339*4882a593Smuzhiyun }
5340*4882a593Smuzhiyun 
brcmf_convert_nl80211_tdls_oper(enum nl80211_tdls_operation oper)5341*4882a593Smuzhiyun static int brcmf_convert_nl80211_tdls_oper(enum nl80211_tdls_operation oper)
5342*4882a593Smuzhiyun {
5343*4882a593Smuzhiyun 	int ret;
5344*4882a593Smuzhiyun 
5345*4882a593Smuzhiyun 	switch (oper) {
5346*4882a593Smuzhiyun 	case NL80211_TDLS_DISCOVERY_REQ:
5347*4882a593Smuzhiyun 		ret = BRCMF_TDLS_MANUAL_EP_DISCOVERY;
5348*4882a593Smuzhiyun 		break;
5349*4882a593Smuzhiyun 	case NL80211_TDLS_SETUP:
5350*4882a593Smuzhiyun 		ret = BRCMF_TDLS_MANUAL_EP_CREATE;
5351*4882a593Smuzhiyun 		break;
5352*4882a593Smuzhiyun 	case NL80211_TDLS_TEARDOWN:
5353*4882a593Smuzhiyun 		ret = BRCMF_TDLS_MANUAL_EP_DELETE;
5354*4882a593Smuzhiyun 		break;
5355*4882a593Smuzhiyun 	default:
5356*4882a593Smuzhiyun 		brcmf_err("unsupported operation: %d\n", oper);
5357*4882a593Smuzhiyun 		ret = -EOPNOTSUPP;
5358*4882a593Smuzhiyun 	}
5359*4882a593Smuzhiyun 	return ret;
5360*4882a593Smuzhiyun }
5361*4882a593Smuzhiyun 
brcmf_cfg80211_tdls_oper(struct wiphy * wiphy,struct net_device * ndev,const u8 * peer,enum nl80211_tdls_operation oper)5362*4882a593Smuzhiyun static int brcmf_cfg80211_tdls_oper(struct wiphy *wiphy,
5363*4882a593Smuzhiyun 				    struct net_device *ndev, const u8 *peer,
5364*4882a593Smuzhiyun 				    enum nl80211_tdls_operation oper)
5365*4882a593Smuzhiyun {
5366*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5367*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
5368*4882a593Smuzhiyun 	struct brcmf_if *ifp;
5369*4882a593Smuzhiyun 	struct brcmf_tdls_iovar_le info;
5370*4882a593Smuzhiyun 	int ret = 0;
5371*4882a593Smuzhiyun 
5372*4882a593Smuzhiyun 	ret = brcmf_convert_nl80211_tdls_oper(oper);
5373*4882a593Smuzhiyun 	if (ret < 0)
5374*4882a593Smuzhiyun 		return ret;
5375*4882a593Smuzhiyun 
5376*4882a593Smuzhiyun 	ifp = netdev_priv(ndev);
5377*4882a593Smuzhiyun 	memset(&info, 0, sizeof(info));
5378*4882a593Smuzhiyun 	info.mode = (u8)ret;
5379*4882a593Smuzhiyun 	if (peer)
5380*4882a593Smuzhiyun 		memcpy(info.ea, peer, ETH_ALEN);
5381*4882a593Smuzhiyun 
5382*4882a593Smuzhiyun 	ret = brcmf_fil_iovar_data_set(ifp, "tdls_endpoint",
5383*4882a593Smuzhiyun 				       &info, sizeof(info));
5384*4882a593Smuzhiyun 	if (ret < 0)
5385*4882a593Smuzhiyun 		bphy_err(drvr, "tdls_endpoint iovar failed: ret=%d\n", ret);
5386*4882a593Smuzhiyun 
5387*4882a593Smuzhiyun 	return ret;
5388*4882a593Smuzhiyun }
5389*4882a593Smuzhiyun 
5390*4882a593Smuzhiyun static int
brcmf_cfg80211_update_conn_params(struct wiphy * wiphy,struct net_device * ndev,struct cfg80211_connect_params * sme,u32 changed)5391*4882a593Smuzhiyun brcmf_cfg80211_update_conn_params(struct wiphy *wiphy,
5392*4882a593Smuzhiyun 				  struct net_device *ndev,
5393*4882a593Smuzhiyun 				  struct cfg80211_connect_params *sme,
5394*4882a593Smuzhiyun 				  u32 changed)
5395*4882a593Smuzhiyun {
5396*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5397*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
5398*4882a593Smuzhiyun 	struct brcmf_if *ifp;
5399*4882a593Smuzhiyun 	int err;
5400*4882a593Smuzhiyun 
5401*4882a593Smuzhiyun 	if (!(changed & UPDATE_ASSOC_IES))
5402*4882a593Smuzhiyun 		return 0;
5403*4882a593Smuzhiyun 
5404*4882a593Smuzhiyun 	ifp = netdev_priv(ndev);
5405*4882a593Smuzhiyun 	err = brcmf_vif_set_mgmt_ie(ifp->vif, BRCMF_VNDR_IE_ASSOCREQ_FLAG,
5406*4882a593Smuzhiyun 				    sme->ie, sme->ie_len);
5407*4882a593Smuzhiyun 	if (err)
5408*4882a593Smuzhiyun 		bphy_err(drvr, "Set Assoc REQ IE Failed\n");
5409*4882a593Smuzhiyun 	else
5410*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "Applied Vndr IEs for Assoc request\n");
5411*4882a593Smuzhiyun 
5412*4882a593Smuzhiyun 	return err;
5413*4882a593Smuzhiyun }
5414*4882a593Smuzhiyun 
5415*4882a593Smuzhiyun #ifdef CONFIG_PM
5416*4882a593Smuzhiyun static int
brcmf_cfg80211_set_rekey_data(struct wiphy * wiphy,struct net_device * ndev,struct cfg80211_gtk_rekey_data * gtk)5417*4882a593Smuzhiyun brcmf_cfg80211_set_rekey_data(struct wiphy *wiphy, struct net_device *ndev,
5418*4882a593Smuzhiyun 			      struct cfg80211_gtk_rekey_data *gtk)
5419*4882a593Smuzhiyun {
5420*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
5421*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
5422*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
5423*4882a593Smuzhiyun 	struct brcmf_gtk_keyinfo_le gtk_le;
5424*4882a593Smuzhiyun 	int ret;
5425*4882a593Smuzhiyun 
5426*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter, bssidx=%d\n", ifp->bsscfgidx);
5427*4882a593Smuzhiyun 
5428*4882a593Smuzhiyun 	memcpy(gtk_le.kck, gtk->kck, sizeof(gtk_le.kck));
5429*4882a593Smuzhiyun 	memcpy(gtk_le.kek, gtk->kek, sizeof(gtk_le.kek));
5430*4882a593Smuzhiyun 	memcpy(gtk_le.replay_counter, gtk->replay_ctr,
5431*4882a593Smuzhiyun 	       sizeof(gtk_le.replay_counter));
5432*4882a593Smuzhiyun 
5433*4882a593Smuzhiyun 	ret = brcmf_fil_iovar_data_set(ifp, "gtk_key_info", &gtk_le,
5434*4882a593Smuzhiyun 				       sizeof(gtk_le));
5435*4882a593Smuzhiyun 	if (ret < 0)
5436*4882a593Smuzhiyun 		bphy_err(drvr, "gtk_key_info iovar failed: ret=%d\n", ret);
5437*4882a593Smuzhiyun 
5438*4882a593Smuzhiyun 	return ret;
5439*4882a593Smuzhiyun }
5440*4882a593Smuzhiyun #endif
5441*4882a593Smuzhiyun 
brcmf_cfg80211_set_pmk(struct wiphy * wiphy,struct net_device * dev,const struct cfg80211_pmk_conf * conf)5442*4882a593Smuzhiyun static int brcmf_cfg80211_set_pmk(struct wiphy *wiphy, struct net_device *dev,
5443*4882a593Smuzhiyun 				  const struct cfg80211_pmk_conf *conf)
5444*4882a593Smuzhiyun {
5445*4882a593Smuzhiyun 	struct brcmf_if *ifp;
5446*4882a593Smuzhiyun 
5447*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "enter\n");
5448*4882a593Smuzhiyun 
5449*4882a593Smuzhiyun 	/* expect using firmware supplicant for 1X */
5450*4882a593Smuzhiyun 	ifp = netdev_priv(dev);
5451*4882a593Smuzhiyun 	if (WARN_ON(ifp->vif->profile.use_fwsup != BRCMF_PROFILE_FWSUP_1X))
5452*4882a593Smuzhiyun 		return -EINVAL;
5453*4882a593Smuzhiyun 
5454*4882a593Smuzhiyun 	if (conf->pmk_len > BRCMF_WSEC_MAX_PSK_LEN)
5455*4882a593Smuzhiyun 		return -ERANGE;
5456*4882a593Smuzhiyun 
5457*4882a593Smuzhiyun 	return brcmf_set_pmk(ifp, conf->pmk, conf->pmk_len);
5458*4882a593Smuzhiyun }
5459*4882a593Smuzhiyun 
brcmf_cfg80211_del_pmk(struct wiphy * wiphy,struct net_device * dev,const u8 * aa)5460*4882a593Smuzhiyun static int brcmf_cfg80211_del_pmk(struct wiphy *wiphy, struct net_device *dev,
5461*4882a593Smuzhiyun 				  const u8 *aa)
5462*4882a593Smuzhiyun {
5463*4882a593Smuzhiyun 	struct brcmf_if *ifp;
5464*4882a593Smuzhiyun 
5465*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "enter\n");
5466*4882a593Smuzhiyun 	ifp = netdev_priv(dev);
5467*4882a593Smuzhiyun 	if (WARN_ON(ifp->vif->profile.use_fwsup != BRCMF_PROFILE_FWSUP_1X))
5468*4882a593Smuzhiyun 		return -EINVAL;
5469*4882a593Smuzhiyun 
5470*4882a593Smuzhiyun 	return brcmf_set_pmk(ifp, NULL, 0);
5471*4882a593Smuzhiyun }
5472*4882a593Smuzhiyun 
5473*4882a593Smuzhiyun static struct cfg80211_ops brcmf_cfg80211_ops = {
5474*4882a593Smuzhiyun 	.add_virtual_intf = brcmf_cfg80211_add_iface,
5475*4882a593Smuzhiyun 	.del_virtual_intf = brcmf_cfg80211_del_iface,
5476*4882a593Smuzhiyun 	.change_virtual_intf = brcmf_cfg80211_change_iface,
5477*4882a593Smuzhiyun 	.scan = brcmf_cfg80211_scan,
5478*4882a593Smuzhiyun 	.set_wiphy_params = brcmf_cfg80211_set_wiphy_params,
5479*4882a593Smuzhiyun 	.join_ibss = brcmf_cfg80211_join_ibss,
5480*4882a593Smuzhiyun 	.leave_ibss = brcmf_cfg80211_leave_ibss,
5481*4882a593Smuzhiyun 	.get_station = brcmf_cfg80211_get_station,
5482*4882a593Smuzhiyun 	.dump_station = brcmf_cfg80211_dump_station,
5483*4882a593Smuzhiyun 	.set_tx_power = brcmf_cfg80211_set_tx_power,
5484*4882a593Smuzhiyun 	.get_tx_power = brcmf_cfg80211_get_tx_power,
5485*4882a593Smuzhiyun 	.add_key = brcmf_cfg80211_add_key,
5486*4882a593Smuzhiyun 	.del_key = brcmf_cfg80211_del_key,
5487*4882a593Smuzhiyun 	.get_key = brcmf_cfg80211_get_key,
5488*4882a593Smuzhiyun 	.set_default_key = brcmf_cfg80211_config_default_key,
5489*4882a593Smuzhiyun 	.set_default_mgmt_key = brcmf_cfg80211_config_default_mgmt_key,
5490*4882a593Smuzhiyun 	.set_power_mgmt = brcmf_cfg80211_set_power_mgmt,
5491*4882a593Smuzhiyun 	.connect = brcmf_cfg80211_connect,
5492*4882a593Smuzhiyun 	.disconnect = brcmf_cfg80211_disconnect,
5493*4882a593Smuzhiyun 	.suspend = brcmf_cfg80211_suspend,
5494*4882a593Smuzhiyun 	.resume = brcmf_cfg80211_resume,
5495*4882a593Smuzhiyun 	.set_pmksa = brcmf_cfg80211_set_pmksa,
5496*4882a593Smuzhiyun 	.del_pmksa = brcmf_cfg80211_del_pmksa,
5497*4882a593Smuzhiyun 	.flush_pmksa = brcmf_cfg80211_flush_pmksa,
5498*4882a593Smuzhiyun 	.start_ap = brcmf_cfg80211_start_ap,
5499*4882a593Smuzhiyun 	.stop_ap = brcmf_cfg80211_stop_ap,
5500*4882a593Smuzhiyun 	.change_beacon = brcmf_cfg80211_change_beacon,
5501*4882a593Smuzhiyun 	.del_station = brcmf_cfg80211_del_station,
5502*4882a593Smuzhiyun 	.change_station = brcmf_cfg80211_change_station,
5503*4882a593Smuzhiyun 	.sched_scan_start = brcmf_cfg80211_sched_scan_start,
5504*4882a593Smuzhiyun 	.sched_scan_stop = brcmf_cfg80211_sched_scan_stop,
5505*4882a593Smuzhiyun 	.update_mgmt_frame_registrations =
5506*4882a593Smuzhiyun 		brcmf_cfg80211_update_mgmt_frame_registrations,
5507*4882a593Smuzhiyun 	.mgmt_tx = brcmf_cfg80211_mgmt_tx,
5508*4882a593Smuzhiyun 	.remain_on_channel = brcmf_p2p_remain_on_channel,
5509*4882a593Smuzhiyun 	.cancel_remain_on_channel = brcmf_cfg80211_cancel_remain_on_channel,
5510*4882a593Smuzhiyun 	.get_channel = brcmf_cfg80211_get_channel,
5511*4882a593Smuzhiyun 	.start_p2p_device = brcmf_p2p_start_device,
5512*4882a593Smuzhiyun 	.stop_p2p_device = brcmf_p2p_stop_device,
5513*4882a593Smuzhiyun 	.crit_proto_start = brcmf_cfg80211_crit_proto_start,
5514*4882a593Smuzhiyun 	.crit_proto_stop = brcmf_cfg80211_crit_proto_stop,
5515*4882a593Smuzhiyun 	.tdls_oper = brcmf_cfg80211_tdls_oper,
5516*4882a593Smuzhiyun 	.update_connect_params = brcmf_cfg80211_update_conn_params,
5517*4882a593Smuzhiyun 	.set_pmk = brcmf_cfg80211_set_pmk,
5518*4882a593Smuzhiyun 	.del_pmk = brcmf_cfg80211_del_pmk,
5519*4882a593Smuzhiyun };
5520*4882a593Smuzhiyun 
brcmf_cfg80211_get_ops(struct brcmf_mp_device * settings)5521*4882a593Smuzhiyun struct cfg80211_ops *brcmf_cfg80211_get_ops(struct brcmf_mp_device *settings)
5522*4882a593Smuzhiyun {
5523*4882a593Smuzhiyun 	struct cfg80211_ops *ops;
5524*4882a593Smuzhiyun 
5525*4882a593Smuzhiyun 	ops = kmemdup(&brcmf_cfg80211_ops, sizeof(brcmf_cfg80211_ops),
5526*4882a593Smuzhiyun 		       GFP_KERNEL);
5527*4882a593Smuzhiyun 
5528*4882a593Smuzhiyun 	if (ops && settings->roamoff)
5529*4882a593Smuzhiyun 		ops->update_connect_params = NULL;
5530*4882a593Smuzhiyun 
5531*4882a593Smuzhiyun 	return ops;
5532*4882a593Smuzhiyun }
5533*4882a593Smuzhiyun 
brcmf_alloc_vif(struct brcmf_cfg80211_info * cfg,enum nl80211_iftype type)5534*4882a593Smuzhiyun struct brcmf_cfg80211_vif *brcmf_alloc_vif(struct brcmf_cfg80211_info *cfg,
5535*4882a593Smuzhiyun 					   enum nl80211_iftype type)
5536*4882a593Smuzhiyun {
5537*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif_walk;
5538*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
5539*4882a593Smuzhiyun 	bool mbss;
5540*4882a593Smuzhiyun 	struct brcmf_if *ifp = brcmf_get_ifp(cfg->pub, 0);
5541*4882a593Smuzhiyun 
5542*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "allocating virtual interface (size=%zu)\n",
5543*4882a593Smuzhiyun 		  sizeof(*vif));
5544*4882a593Smuzhiyun 	vif = kzalloc(sizeof(*vif), GFP_KERNEL);
5545*4882a593Smuzhiyun 	if (!vif)
5546*4882a593Smuzhiyun 		return ERR_PTR(-ENOMEM);
5547*4882a593Smuzhiyun 
5548*4882a593Smuzhiyun 	vif->wdev.wiphy = cfg->wiphy;
5549*4882a593Smuzhiyun 	vif->wdev.iftype = type;
5550*4882a593Smuzhiyun 
5551*4882a593Smuzhiyun 	brcmf_init_prof(&vif->profile);
5552*4882a593Smuzhiyun 
5553*4882a593Smuzhiyun 	if (type == NL80211_IFTYPE_AP &&
5554*4882a593Smuzhiyun 	    brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MBSS)) {
5555*4882a593Smuzhiyun 		mbss = false;
5556*4882a593Smuzhiyun 		list_for_each_entry(vif_walk, &cfg->vif_list, list) {
5557*4882a593Smuzhiyun 			if (vif_walk->wdev.iftype == NL80211_IFTYPE_AP) {
5558*4882a593Smuzhiyun 				mbss = true;
5559*4882a593Smuzhiyun 				break;
5560*4882a593Smuzhiyun 			}
5561*4882a593Smuzhiyun 		}
5562*4882a593Smuzhiyun 		vif->mbss = mbss;
5563*4882a593Smuzhiyun 	}
5564*4882a593Smuzhiyun 
5565*4882a593Smuzhiyun 	list_add_tail(&vif->list, &cfg->vif_list);
5566*4882a593Smuzhiyun 	return vif;
5567*4882a593Smuzhiyun }
5568*4882a593Smuzhiyun 
brcmf_free_vif(struct brcmf_cfg80211_vif * vif)5569*4882a593Smuzhiyun void brcmf_free_vif(struct brcmf_cfg80211_vif *vif)
5570*4882a593Smuzhiyun {
5571*4882a593Smuzhiyun 	list_del(&vif->list);
5572*4882a593Smuzhiyun 	kfree(vif);
5573*4882a593Smuzhiyun }
5574*4882a593Smuzhiyun 
brcmf_cfg80211_free_netdev(struct net_device * ndev)5575*4882a593Smuzhiyun void brcmf_cfg80211_free_netdev(struct net_device *ndev)
5576*4882a593Smuzhiyun {
5577*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
5578*4882a593Smuzhiyun 	struct brcmf_if *ifp;
5579*4882a593Smuzhiyun 
5580*4882a593Smuzhiyun 	ifp = netdev_priv(ndev);
5581*4882a593Smuzhiyun 	vif = ifp->vif;
5582*4882a593Smuzhiyun 
5583*4882a593Smuzhiyun 	if (vif)
5584*4882a593Smuzhiyun 		brcmf_free_vif(vif);
5585*4882a593Smuzhiyun }
5586*4882a593Smuzhiyun 
brcmf_is_linkup(struct brcmf_cfg80211_vif * vif,const struct brcmf_event_msg * e)5587*4882a593Smuzhiyun static bool brcmf_is_linkup(struct brcmf_cfg80211_vif *vif,
5588*4882a593Smuzhiyun 			    const struct brcmf_event_msg *e)
5589*4882a593Smuzhiyun {
5590*4882a593Smuzhiyun 	u32 event = e->event_code;
5591*4882a593Smuzhiyun 	u32 status = e->status;
5592*4882a593Smuzhiyun 
5593*4882a593Smuzhiyun 	if ((vif->profile.use_fwsup == BRCMF_PROFILE_FWSUP_PSK ||
5594*4882a593Smuzhiyun 	     vif->profile.use_fwsup == BRCMF_PROFILE_FWSUP_SAE) &&
5595*4882a593Smuzhiyun 	    event == BRCMF_E_PSK_SUP &&
5596*4882a593Smuzhiyun 	    status == BRCMF_E_STATUS_FWSUP_COMPLETED)
5597*4882a593Smuzhiyun 		set_bit(BRCMF_VIF_STATUS_EAP_SUCCESS, &vif->sme_state);
5598*4882a593Smuzhiyun 	if (event == BRCMF_E_SET_SSID && status == BRCMF_E_STATUS_SUCCESS) {
5599*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Processing set ssid\n");
5600*4882a593Smuzhiyun 		memcpy(vif->profile.bssid, e->addr, ETH_ALEN);
5601*4882a593Smuzhiyun 		if (vif->profile.use_fwsup != BRCMF_PROFILE_FWSUP_PSK &&
5602*4882a593Smuzhiyun 		    vif->profile.use_fwsup != BRCMF_PROFILE_FWSUP_SAE)
5603*4882a593Smuzhiyun 			return true;
5604*4882a593Smuzhiyun 
5605*4882a593Smuzhiyun 		set_bit(BRCMF_VIF_STATUS_ASSOC_SUCCESS, &vif->sme_state);
5606*4882a593Smuzhiyun 	}
5607*4882a593Smuzhiyun 
5608*4882a593Smuzhiyun 	if (test_bit(BRCMF_VIF_STATUS_EAP_SUCCESS, &vif->sme_state) &&
5609*4882a593Smuzhiyun 	    test_bit(BRCMF_VIF_STATUS_ASSOC_SUCCESS, &vif->sme_state)) {
5610*4882a593Smuzhiyun 		clear_bit(BRCMF_VIF_STATUS_EAP_SUCCESS, &vif->sme_state);
5611*4882a593Smuzhiyun 		clear_bit(BRCMF_VIF_STATUS_ASSOC_SUCCESS, &vif->sme_state);
5612*4882a593Smuzhiyun 		return true;
5613*4882a593Smuzhiyun 	}
5614*4882a593Smuzhiyun 	return false;
5615*4882a593Smuzhiyun }
5616*4882a593Smuzhiyun 
brcmf_is_linkdown(struct brcmf_cfg80211_vif * vif,const struct brcmf_event_msg * e)5617*4882a593Smuzhiyun static bool brcmf_is_linkdown(struct brcmf_cfg80211_vif *vif,
5618*4882a593Smuzhiyun 			    const struct brcmf_event_msg *e)
5619*4882a593Smuzhiyun {
5620*4882a593Smuzhiyun 	u32 event = e->event_code;
5621*4882a593Smuzhiyun 	u16 flags = e->flags;
5622*4882a593Smuzhiyun 
5623*4882a593Smuzhiyun 	if ((event == BRCMF_E_DEAUTH) || (event == BRCMF_E_DEAUTH_IND) ||
5624*4882a593Smuzhiyun 	    (event == BRCMF_E_DISASSOC_IND) ||
5625*4882a593Smuzhiyun 	    ((event == BRCMF_E_LINK) && (!(flags & BRCMF_EVENT_MSG_LINK)))) {
5626*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Processing link down\n");
5627*4882a593Smuzhiyun 		clear_bit(BRCMF_VIF_STATUS_EAP_SUCCESS, &vif->sme_state);
5628*4882a593Smuzhiyun 		clear_bit(BRCMF_VIF_STATUS_ASSOC_SUCCESS, &vif->sme_state);
5629*4882a593Smuzhiyun 		return true;
5630*4882a593Smuzhiyun 	}
5631*4882a593Smuzhiyun 	return false;
5632*4882a593Smuzhiyun }
5633*4882a593Smuzhiyun 
brcmf_is_nonetwork(struct brcmf_cfg80211_info * cfg,const struct brcmf_event_msg * e)5634*4882a593Smuzhiyun static bool brcmf_is_nonetwork(struct brcmf_cfg80211_info *cfg,
5635*4882a593Smuzhiyun 			       const struct brcmf_event_msg *e)
5636*4882a593Smuzhiyun {
5637*4882a593Smuzhiyun 	u32 event = e->event_code;
5638*4882a593Smuzhiyun 	u32 status = e->status;
5639*4882a593Smuzhiyun 
5640*4882a593Smuzhiyun 	if (event == BRCMF_E_LINK && status == BRCMF_E_STATUS_NO_NETWORKS) {
5641*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Processing Link %s & no network found\n",
5642*4882a593Smuzhiyun 			  e->flags & BRCMF_EVENT_MSG_LINK ? "up" : "down");
5643*4882a593Smuzhiyun 		return true;
5644*4882a593Smuzhiyun 	}
5645*4882a593Smuzhiyun 
5646*4882a593Smuzhiyun 	if (event == BRCMF_E_SET_SSID && status != BRCMF_E_STATUS_SUCCESS) {
5647*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Processing connecting & no network found\n");
5648*4882a593Smuzhiyun 		return true;
5649*4882a593Smuzhiyun 	}
5650*4882a593Smuzhiyun 
5651*4882a593Smuzhiyun 	if (event == BRCMF_E_PSK_SUP &&
5652*4882a593Smuzhiyun 	    status != BRCMF_E_STATUS_FWSUP_COMPLETED) {
5653*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Processing failed supplicant state: %u\n",
5654*4882a593Smuzhiyun 			  status);
5655*4882a593Smuzhiyun 		return true;
5656*4882a593Smuzhiyun 	}
5657*4882a593Smuzhiyun 
5658*4882a593Smuzhiyun 	return false;
5659*4882a593Smuzhiyun }
5660*4882a593Smuzhiyun 
brcmf_clear_assoc_ies(struct brcmf_cfg80211_info * cfg)5661*4882a593Smuzhiyun static void brcmf_clear_assoc_ies(struct brcmf_cfg80211_info *cfg)
5662*4882a593Smuzhiyun {
5663*4882a593Smuzhiyun 	struct brcmf_cfg80211_connect_info *conn_info = cfg_to_conn(cfg);
5664*4882a593Smuzhiyun 
5665*4882a593Smuzhiyun 	kfree(conn_info->req_ie);
5666*4882a593Smuzhiyun 	conn_info->req_ie = NULL;
5667*4882a593Smuzhiyun 	conn_info->req_ie_len = 0;
5668*4882a593Smuzhiyun 	kfree(conn_info->resp_ie);
5669*4882a593Smuzhiyun 	conn_info->resp_ie = NULL;
5670*4882a593Smuzhiyun 	conn_info->resp_ie_len = 0;
5671*4882a593Smuzhiyun }
5672*4882a593Smuzhiyun 
brcmf_map_prio_to_prec(void * config,u8 prio)5673*4882a593Smuzhiyun u8 brcmf_map_prio_to_prec(void *config, u8 prio)
5674*4882a593Smuzhiyun {
5675*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = (struct brcmf_cfg80211_info *)config;
5676*4882a593Smuzhiyun 
5677*4882a593Smuzhiyun 	if (!cfg)
5678*4882a593Smuzhiyun 		return (prio == PRIO_8021D_NONE || prio == PRIO_8021D_BE) ?
5679*4882a593Smuzhiyun 		       (prio ^ 2) : prio;
5680*4882a593Smuzhiyun 
5681*4882a593Smuzhiyun 	/* For those AC(s) with ACM flag set to 1, convert its 4-level priority
5682*4882a593Smuzhiyun 	 * to an 8-level precedence which is the same as BE's
5683*4882a593Smuzhiyun 	 */
5684*4882a593Smuzhiyun 	if (prio > PRIO_8021D_EE &&
5685*4882a593Smuzhiyun 	    cfg->ac_priority[prio] == cfg->ac_priority[PRIO_8021D_BE])
5686*4882a593Smuzhiyun 		return cfg->ac_priority[prio] * 2;
5687*4882a593Smuzhiyun 
5688*4882a593Smuzhiyun 	/* Conversion of 4-level priority to 8-level precedence */
5689*4882a593Smuzhiyun 	if (prio == PRIO_8021D_BE || prio == PRIO_8021D_BK ||
5690*4882a593Smuzhiyun 	    prio == PRIO_8021D_CL || prio == PRIO_8021D_VO)
5691*4882a593Smuzhiyun 		return cfg->ac_priority[prio] * 2;
5692*4882a593Smuzhiyun 	else
5693*4882a593Smuzhiyun 		return cfg->ac_priority[prio] * 2 + 1;
5694*4882a593Smuzhiyun }
5695*4882a593Smuzhiyun 
brcmf_map_prio_to_aci(void * config,u8 prio)5696*4882a593Smuzhiyun u8 brcmf_map_prio_to_aci(void *config, u8 prio)
5697*4882a593Smuzhiyun {
5698*4882a593Smuzhiyun 	/* Prio here refers to the 802.1d priority in range of 0 to 7.
5699*4882a593Smuzhiyun 	 * ACI here refers to the WLAN AC Index in range of 0 to 3.
5700*4882a593Smuzhiyun 	 * This function will return ACI corresponding to input prio.
5701*4882a593Smuzhiyun 	 */
5702*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = (struct brcmf_cfg80211_info *)config;
5703*4882a593Smuzhiyun 
5704*4882a593Smuzhiyun 	if (cfg)
5705*4882a593Smuzhiyun 		return cfg->ac_priority[prio];
5706*4882a593Smuzhiyun 
5707*4882a593Smuzhiyun 	return prio;
5708*4882a593Smuzhiyun }
5709*4882a593Smuzhiyun 
brcmf_init_wmm_prio(u8 * priority)5710*4882a593Smuzhiyun static void brcmf_init_wmm_prio(u8 *priority)
5711*4882a593Smuzhiyun {
5712*4882a593Smuzhiyun 	/* Initialize AC priority array to default
5713*4882a593Smuzhiyun 	 * 802.1d priority as per following table:
5714*4882a593Smuzhiyun 	 * 802.1d prio 0,3 maps to BE
5715*4882a593Smuzhiyun 	 * 802.1d prio 1,2 maps to BK
5716*4882a593Smuzhiyun 	 * 802.1d prio 4,5 maps to VI
5717*4882a593Smuzhiyun 	 * 802.1d prio 6,7 maps to VO
5718*4882a593Smuzhiyun 	 */
5719*4882a593Smuzhiyun 	priority[0] = BRCMF_FWS_FIFO_AC_BE;
5720*4882a593Smuzhiyun 	priority[3] = BRCMF_FWS_FIFO_AC_BE;
5721*4882a593Smuzhiyun 	priority[1] = BRCMF_FWS_FIFO_AC_BK;
5722*4882a593Smuzhiyun 	priority[2] = BRCMF_FWS_FIFO_AC_BK;
5723*4882a593Smuzhiyun 	priority[4] = BRCMF_FWS_FIFO_AC_VI;
5724*4882a593Smuzhiyun 	priority[5] = BRCMF_FWS_FIFO_AC_VI;
5725*4882a593Smuzhiyun 	priority[6] = BRCMF_FWS_FIFO_AC_VO;
5726*4882a593Smuzhiyun 	priority[7] = BRCMF_FWS_FIFO_AC_VO;
5727*4882a593Smuzhiyun }
5728*4882a593Smuzhiyun 
brcmf_wifi_prioritize_acparams(const struct brcmf_cfg80211_edcf_acparam * acp,u8 * priority)5729*4882a593Smuzhiyun static void brcmf_wifi_prioritize_acparams(const
5730*4882a593Smuzhiyun 	struct brcmf_cfg80211_edcf_acparam *acp, u8 *priority)
5731*4882a593Smuzhiyun {
5732*4882a593Smuzhiyun 	u8 aci;
5733*4882a593Smuzhiyun 	u8 aifsn;
5734*4882a593Smuzhiyun 	u8 ecwmin;
5735*4882a593Smuzhiyun 	u8 ecwmax;
5736*4882a593Smuzhiyun 	u8 acm;
5737*4882a593Smuzhiyun 	u8 ranking_basis[EDCF_AC_COUNT];
5738*4882a593Smuzhiyun 	u8 aci_prio[EDCF_AC_COUNT]; /* AC_BE, AC_BK, AC_VI, AC_VO */
5739*4882a593Smuzhiyun 	u8 index;
5740*4882a593Smuzhiyun 
5741*4882a593Smuzhiyun 	for (aci = 0; aci < EDCF_AC_COUNT; aci++, acp++) {
5742*4882a593Smuzhiyun 		aifsn  = acp->ACI & EDCF_AIFSN_MASK;
5743*4882a593Smuzhiyun 		acm = (acp->ACI & EDCF_ACM_MASK) ? 1 : 0;
5744*4882a593Smuzhiyun 		ecwmin = acp->ECW & EDCF_ECWMIN_MASK;
5745*4882a593Smuzhiyun 		ecwmax = (acp->ECW & EDCF_ECWMAX_MASK) >> EDCF_ECWMAX_SHIFT;
5746*4882a593Smuzhiyun 		brcmf_dbg(CONN, "ACI %d aifsn %d acm %d ecwmin %d ecwmax %d\n",
5747*4882a593Smuzhiyun 			  aci, aifsn, acm, ecwmin, ecwmax);
5748*4882a593Smuzhiyun 		/* Default AC_VO will be the lowest ranking value */
5749*4882a593Smuzhiyun 		ranking_basis[aci] = aifsn + ecwmin + ecwmax;
5750*4882a593Smuzhiyun 		/* Initialise priority starting at 0 (AC_BE) */
5751*4882a593Smuzhiyun 		aci_prio[aci] = 0;
5752*4882a593Smuzhiyun 
5753*4882a593Smuzhiyun 		/* If ACM is set, STA can't use this AC as per 802.11.
5754*4882a593Smuzhiyun 		 * Change the ranking to BE
5755*4882a593Smuzhiyun 		 */
5756*4882a593Smuzhiyun 		if (aci != AC_BE && aci != AC_BK && acm == 1)
5757*4882a593Smuzhiyun 			ranking_basis[aci] = ranking_basis[AC_BE];
5758*4882a593Smuzhiyun 	}
5759*4882a593Smuzhiyun 
5760*4882a593Smuzhiyun 	/* Ranking method which works for AC priority
5761*4882a593Smuzhiyun 	 * swapping when values for cwmin, cwmax and aifsn are varied
5762*4882a593Smuzhiyun 	 * Compare each aci_prio against each other aci_prio
5763*4882a593Smuzhiyun 	 */
5764*4882a593Smuzhiyun 	for (aci = 0; aci < EDCF_AC_COUNT; aci++) {
5765*4882a593Smuzhiyun 		for (index = 0; index < EDCF_AC_COUNT; index++) {
5766*4882a593Smuzhiyun 			if (index != aci) {
5767*4882a593Smuzhiyun 				/* Smaller ranking value has higher priority,
5768*4882a593Smuzhiyun 				 * so increment priority for each ACI which has
5769*4882a593Smuzhiyun 				 * a higher ranking value
5770*4882a593Smuzhiyun 				 */
5771*4882a593Smuzhiyun 				if (ranking_basis[aci] < ranking_basis[index])
5772*4882a593Smuzhiyun 					aci_prio[aci]++;
5773*4882a593Smuzhiyun 			}
5774*4882a593Smuzhiyun 		}
5775*4882a593Smuzhiyun 	}
5776*4882a593Smuzhiyun 
5777*4882a593Smuzhiyun 	/* By now, aci_prio[] will be in range of 0 to 3.
5778*4882a593Smuzhiyun 	 * Use ACI prio to get the new priority value for
5779*4882a593Smuzhiyun 	 * each 802.1d traffic type, in this range.
5780*4882a593Smuzhiyun 	 */
5781*4882a593Smuzhiyun 	if (!(aci_prio[AC_BE] == aci_prio[AC_BK] &&
5782*4882a593Smuzhiyun 	      aci_prio[AC_BK] == aci_prio[AC_VI] &&
5783*4882a593Smuzhiyun 	      aci_prio[AC_VI] == aci_prio[AC_VO])) {
5784*4882a593Smuzhiyun 		/* 802.1d 0,3 maps to BE */
5785*4882a593Smuzhiyun 		priority[0] = aci_prio[AC_BE];
5786*4882a593Smuzhiyun 		priority[3] = aci_prio[AC_BE];
5787*4882a593Smuzhiyun 
5788*4882a593Smuzhiyun 		/* 802.1d 1,2 maps to BK */
5789*4882a593Smuzhiyun 		priority[1] = aci_prio[AC_BK];
5790*4882a593Smuzhiyun 		priority[2] = aci_prio[AC_BK];
5791*4882a593Smuzhiyun 
5792*4882a593Smuzhiyun 		/* 802.1d 4,5 maps to VO */
5793*4882a593Smuzhiyun 		priority[4] = aci_prio[AC_VI];
5794*4882a593Smuzhiyun 		priority[5] = aci_prio[AC_VI];
5795*4882a593Smuzhiyun 
5796*4882a593Smuzhiyun 		/* 802.1d 6,7 maps to VO */
5797*4882a593Smuzhiyun 		priority[6] = aci_prio[AC_VO];
5798*4882a593Smuzhiyun 		priority[7] = aci_prio[AC_VO];
5799*4882a593Smuzhiyun 	} else {
5800*4882a593Smuzhiyun 		/* Initialize to default priority */
5801*4882a593Smuzhiyun 		brcmf_init_wmm_prio(priority);
5802*4882a593Smuzhiyun 	}
5803*4882a593Smuzhiyun 
5804*4882a593Smuzhiyun 	brcmf_dbg(CONN, "Adj prio BE 0->%d, BK 1->%d, BK 2->%d, BE 3->%d\n",
5805*4882a593Smuzhiyun 		  priority[0], priority[1], priority[2], priority[3]);
5806*4882a593Smuzhiyun 
5807*4882a593Smuzhiyun 	brcmf_dbg(CONN, "Adj prio VI 4->%d, VI 5->%d, VO 6->%d, VO 7->%d\n",
5808*4882a593Smuzhiyun 		  priority[4], priority[5], priority[6], priority[7]);
5809*4882a593Smuzhiyun }
5810*4882a593Smuzhiyun 
brcmf_get_assoc_ies(struct brcmf_cfg80211_info * cfg,struct brcmf_if * ifp)5811*4882a593Smuzhiyun static s32 brcmf_get_assoc_ies(struct brcmf_cfg80211_info *cfg,
5812*4882a593Smuzhiyun 			       struct brcmf_if *ifp)
5813*4882a593Smuzhiyun {
5814*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
5815*4882a593Smuzhiyun 	struct brcmf_cfg80211_assoc_ielen_le *assoc_info;
5816*4882a593Smuzhiyun 	struct brcmf_cfg80211_connect_info *conn_info = cfg_to_conn(cfg);
5817*4882a593Smuzhiyun 	struct brcmf_cfg80211_edcf_acparam edcf_acparam_info[EDCF_AC_COUNT];
5818*4882a593Smuzhiyun 	u32 req_len;
5819*4882a593Smuzhiyun 	u32 resp_len;
5820*4882a593Smuzhiyun 	s32 err = 0;
5821*4882a593Smuzhiyun 
5822*4882a593Smuzhiyun 	brcmf_clear_assoc_ies(cfg);
5823*4882a593Smuzhiyun 
5824*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_get(ifp, "assoc_info",
5825*4882a593Smuzhiyun 				       cfg->extra_buf, WL_ASSOC_INFO_MAX);
5826*4882a593Smuzhiyun 	if (err) {
5827*4882a593Smuzhiyun 		bphy_err(drvr, "could not get assoc info (%d)\n", err);
5828*4882a593Smuzhiyun 		return err;
5829*4882a593Smuzhiyun 	}
5830*4882a593Smuzhiyun 	assoc_info =
5831*4882a593Smuzhiyun 		(struct brcmf_cfg80211_assoc_ielen_le *)cfg->extra_buf;
5832*4882a593Smuzhiyun 	req_len = le32_to_cpu(assoc_info->req_len);
5833*4882a593Smuzhiyun 	resp_len = le32_to_cpu(assoc_info->resp_len);
5834*4882a593Smuzhiyun 	if (req_len) {
5835*4882a593Smuzhiyun 		err = brcmf_fil_iovar_data_get(ifp, "assoc_req_ies",
5836*4882a593Smuzhiyun 					       cfg->extra_buf,
5837*4882a593Smuzhiyun 					       WL_ASSOC_INFO_MAX);
5838*4882a593Smuzhiyun 		if (err) {
5839*4882a593Smuzhiyun 			bphy_err(drvr, "could not get assoc req (%d)\n", err);
5840*4882a593Smuzhiyun 			return err;
5841*4882a593Smuzhiyun 		}
5842*4882a593Smuzhiyun 		conn_info->req_ie_len = req_len;
5843*4882a593Smuzhiyun 		conn_info->req_ie =
5844*4882a593Smuzhiyun 		    kmemdup(cfg->extra_buf, conn_info->req_ie_len,
5845*4882a593Smuzhiyun 			    GFP_KERNEL);
5846*4882a593Smuzhiyun 		if (!conn_info->req_ie)
5847*4882a593Smuzhiyun 			conn_info->req_ie_len = 0;
5848*4882a593Smuzhiyun 	} else {
5849*4882a593Smuzhiyun 		conn_info->req_ie_len = 0;
5850*4882a593Smuzhiyun 		conn_info->req_ie = NULL;
5851*4882a593Smuzhiyun 	}
5852*4882a593Smuzhiyun 	if (resp_len) {
5853*4882a593Smuzhiyun 		err = brcmf_fil_iovar_data_get(ifp, "assoc_resp_ies",
5854*4882a593Smuzhiyun 					       cfg->extra_buf,
5855*4882a593Smuzhiyun 					       WL_ASSOC_INFO_MAX);
5856*4882a593Smuzhiyun 		if (err) {
5857*4882a593Smuzhiyun 			bphy_err(drvr, "could not get assoc resp (%d)\n", err);
5858*4882a593Smuzhiyun 			return err;
5859*4882a593Smuzhiyun 		}
5860*4882a593Smuzhiyun 		conn_info->resp_ie_len = resp_len;
5861*4882a593Smuzhiyun 		conn_info->resp_ie =
5862*4882a593Smuzhiyun 		    kmemdup(cfg->extra_buf, conn_info->resp_ie_len,
5863*4882a593Smuzhiyun 			    GFP_KERNEL);
5864*4882a593Smuzhiyun 		if (!conn_info->resp_ie)
5865*4882a593Smuzhiyun 			conn_info->resp_ie_len = 0;
5866*4882a593Smuzhiyun 
5867*4882a593Smuzhiyun 		err = brcmf_fil_iovar_data_get(ifp, "wme_ac_sta",
5868*4882a593Smuzhiyun 					       edcf_acparam_info,
5869*4882a593Smuzhiyun 					       sizeof(edcf_acparam_info));
5870*4882a593Smuzhiyun 		if (err) {
5871*4882a593Smuzhiyun 			brcmf_err("could not get wme_ac_sta (%d)\n", err);
5872*4882a593Smuzhiyun 			return err;
5873*4882a593Smuzhiyun 		}
5874*4882a593Smuzhiyun 
5875*4882a593Smuzhiyun 		brcmf_wifi_prioritize_acparams(edcf_acparam_info,
5876*4882a593Smuzhiyun 					       cfg->ac_priority);
5877*4882a593Smuzhiyun 	} else {
5878*4882a593Smuzhiyun 		conn_info->resp_ie_len = 0;
5879*4882a593Smuzhiyun 		conn_info->resp_ie = NULL;
5880*4882a593Smuzhiyun 	}
5881*4882a593Smuzhiyun 	brcmf_dbg(CONN, "req len (%d) resp len (%d)\n",
5882*4882a593Smuzhiyun 		  conn_info->req_ie_len, conn_info->resp_ie_len);
5883*4882a593Smuzhiyun 
5884*4882a593Smuzhiyun 	return err;
5885*4882a593Smuzhiyun }
5886*4882a593Smuzhiyun 
5887*4882a593Smuzhiyun static s32
brcmf_bss_roaming_done(struct brcmf_cfg80211_info * cfg,struct net_device * ndev,const struct brcmf_event_msg * e)5888*4882a593Smuzhiyun brcmf_bss_roaming_done(struct brcmf_cfg80211_info *cfg,
5889*4882a593Smuzhiyun 		       struct net_device *ndev,
5890*4882a593Smuzhiyun 		       const struct brcmf_event_msg *e)
5891*4882a593Smuzhiyun {
5892*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
5893*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
5894*4882a593Smuzhiyun 	struct brcmf_cfg80211_connect_info *conn_info = cfg_to_conn(cfg);
5895*4882a593Smuzhiyun 	struct wiphy *wiphy = cfg_to_wiphy(cfg);
5896*4882a593Smuzhiyun 	struct ieee80211_channel *notify_channel = NULL;
5897*4882a593Smuzhiyun 	struct ieee80211_supported_band *band;
5898*4882a593Smuzhiyun 	struct brcmf_bss_info_le *bi;
5899*4882a593Smuzhiyun 	struct brcmu_chan ch;
5900*4882a593Smuzhiyun 	struct cfg80211_roam_info roam_info = {};
5901*4882a593Smuzhiyun 	u32 freq;
5902*4882a593Smuzhiyun 	s32 err = 0;
5903*4882a593Smuzhiyun 	u8 *buf;
5904*4882a593Smuzhiyun 
5905*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
5906*4882a593Smuzhiyun 
5907*4882a593Smuzhiyun 	brcmf_get_assoc_ies(cfg, ifp);
5908*4882a593Smuzhiyun 	memcpy(profile->bssid, e->addr, ETH_ALEN);
5909*4882a593Smuzhiyun 	brcmf_update_bss_info(cfg, ifp);
5910*4882a593Smuzhiyun 
5911*4882a593Smuzhiyun 	buf = kzalloc(WL_BSS_INFO_MAX, GFP_KERNEL);
5912*4882a593Smuzhiyun 	if (buf == NULL) {
5913*4882a593Smuzhiyun 		err = -ENOMEM;
5914*4882a593Smuzhiyun 		goto done;
5915*4882a593Smuzhiyun 	}
5916*4882a593Smuzhiyun 
5917*4882a593Smuzhiyun 	/* data sent to dongle has to be little endian */
5918*4882a593Smuzhiyun 	*(__le32 *)buf = cpu_to_le32(WL_BSS_INFO_MAX);
5919*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_get(ifp, BRCMF_C_GET_BSS_INFO,
5920*4882a593Smuzhiyun 				     buf, WL_BSS_INFO_MAX);
5921*4882a593Smuzhiyun 
5922*4882a593Smuzhiyun 	if (err)
5923*4882a593Smuzhiyun 		goto done;
5924*4882a593Smuzhiyun 
5925*4882a593Smuzhiyun 	bi = (struct brcmf_bss_info_le *)(buf + 4);
5926*4882a593Smuzhiyun 	ch.chspec = le16_to_cpu(bi->chanspec);
5927*4882a593Smuzhiyun 	cfg->d11inf.decchspec(&ch);
5928*4882a593Smuzhiyun 
5929*4882a593Smuzhiyun 	if (ch.band == BRCMU_CHAN_BAND_2G)
5930*4882a593Smuzhiyun 		band = wiphy->bands[NL80211_BAND_2GHZ];
5931*4882a593Smuzhiyun 	else
5932*4882a593Smuzhiyun 		band = wiphy->bands[NL80211_BAND_5GHZ];
5933*4882a593Smuzhiyun 
5934*4882a593Smuzhiyun 	freq = ieee80211_channel_to_frequency(ch.control_ch_num, band->band);
5935*4882a593Smuzhiyun 	notify_channel = ieee80211_get_channel(wiphy, freq);
5936*4882a593Smuzhiyun 
5937*4882a593Smuzhiyun done:
5938*4882a593Smuzhiyun 	kfree(buf);
5939*4882a593Smuzhiyun 
5940*4882a593Smuzhiyun 	roam_info.channel = notify_channel;
5941*4882a593Smuzhiyun 	roam_info.bssid = profile->bssid;
5942*4882a593Smuzhiyun 	roam_info.req_ie = conn_info->req_ie;
5943*4882a593Smuzhiyun 	roam_info.req_ie_len = conn_info->req_ie_len;
5944*4882a593Smuzhiyun 	roam_info.resp_ie = conn_info->resp_ie;
5945*4882a593Smuzhiyun 	roam_info.resp_ie_len = conn_info->resp_ie_len;
5946*4882a593Smuzhiyun 
5947*4882a593Smuzhiyun 	cfg80211_roamed(ndev, &roam_info, GFP_KERNEL);
5948*4882a593Smuzhiyun 	brcmf_dbg(CONN, "Report roaming result\n");
5949*4882a593Smuzhiyun 
5950*4882a593Smuzhiyun 	if (profile->use_fwsup == BRCMF_PROFILE_FWSUP_1X && profile->is_ft) {
5951*4882a593Smuzhiyun 		cfg80211_port_authorized(ndev, profile->bssid, GFP_KERNEL);
5952*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Report port authorized\n");
5953*4882a593Smuzhiyun 	}
5954*4882a593Smuzhiyun 
5955*4882a593Smuzhiyun 	set_bit(BRCMF_VIF_STATUS_CONNECTED, &ifp->vif->sme_state);
5956*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
5957*4882a593Smuzhiyun 	return err;
5958*4882a593Smuzhiyun }
5959*4882a593Smuzhiyun 
5960*4882a593Smuzhiyun static s32
brcmf_bss_connect_done(struct brcmf_cfg80211_info * cfg,struct net_device * ndev,const struct brcmf_event_msg * e,bool completed)5961*4882a593Smuzhiyun brcmf_bss_connect_done(struct brcmf_cfg80211_info *cfg,
5962*4882a593Smuzhiyun 		       struct net_device *ndev, const struct brcmf_event_msg *e,
5963*4882a593Smuzhiyun 		       bool completed)
5964*4882a593Smuzhiyun {
5965*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
5966*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
5967*4882a593Smuzhiyun 	struct brcmf_cfg80211_connect_info *conn_info = cfg_to_conn(cfg);
5968*4882a593Smuzhiyun 	struct cfg80211_connect_resp_params conn_params;
5969*4882a593Smuzhiyun 
5970*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter\n");
5971*4882a593Smuzhiyun 
5972*4882a593Smuzhiyun 	if (test_and_clear_bit(BRCMF_VIF_STATUS_CONNECTING,
5973*4882a593Smuzhiyun 			       &ifp->vif->sme_state)) {
5974*4882a593Smuzhiyun 		memset(&conn_params, 0, sizeof(conn_params));
5975*4882a593Smuzhiyun 		if (completed) {
5976*4882a593Smuzhiyun 			brcmf_get_assoc_ies(cfg, ifp);
5977*4882a593Smuzhiyun 			brcmf_update_bss_info(cfg, ifp);
5978*4882a593Smuzhiyun 			set_bit(BRCMF_VIF_STATUS_CONNECTED,
5979*4882a593Smuzhiyun 				&ifp->vif->sme_state);
5980*4882a593Smuzhiyun 			conn_params.status = WLAN_STATUS_SUCCESS;
5981*4882a593Smuzhiyun 		} else {
5982*4882a593Smuzhiyun 			conn_params.status = WLAN_STATUS_AUTH_TIMEOUT;
5983*4882a593Smuzhiyun 		}
5984*4882a593Smuzhiyun 		conn_params.bssid = profile->bssid;
5985*4882a593Smuzhiyun 		conn_params.req_ie = conn_info->req_ie;
5986*4882a593Smuzhiyun 		conn_params.req_ie_len = conn_info->req_ie_len;
5987*4882a593Smuzhiyun 		conn_params.resp_ie = conn_info->resp_ie;
5988*4882a593Smuzhiyun 		conn_params.resp_ie_len = conn_info->resp_ie_len;
5989*4882a593Smuzhiyun 		cfg80211_connect_done(ndev, &conn_params, GFP_KERNEL);
5990*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Report connect result - connection %s\n",
5991*4882a593Smuzhiyun 			  completed ? "succeeded" : "failed");
5992*4882a593Smuzhiyun 	}
5993*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Exit\n");
5994*4882a593Smuzhiyun 	return 0;
5995*4882a593Smuzhiyun }
5996*4882a593Smuzhiyun 
5997*4882a593Smuzhiyun static s32
brcmf_notify_connect_status_ap(struct brcmf_cfg80211_info * cfg,struct net_device * ndev,const struct brcmf_event_msg * e,void * data)5998*4882a593Smuzhiyun brcmf_notify_connect_status_ap(struct brcmf_cfg80211_info *cfg,
5999*4882a593Smuzhiyun 			       struct net_device *ndev,
6000*4882a593Smuzhiyun 			       const struct brcmf_event_msg *e, void *data)
6001*4882a593Smuzhiyun {
6002*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
6003*4882a593Smuzhiyun 	static int generation;
6004*4882a593Smuzhiyun 	u32 event = e->event_code;
6005*4882a593Smuzhiyun 	u32 reason = e->reason;
6006*4882a593Smuzhiyun 	struct station_info *sinfo;
6007*4882a593Smuzhiyun 
6008*4882a593Smuzhiyun 	brcmf_dbg(CONN, "event %s (%u), reason %d\n",
6009*4882a593Smuzhiyun 		  brcmf_fweh_event_name(event), event, reason);
6010*4882a593Smuzhiyun 	if (event == BRCMF_E_LINK && reason == BRCMF_E_REASON_LINK_BSSCFG_DIS &&
6011*4882a593Smuzhiyun 	    ndev != cfg_to_ndev(cfg)) {
6012*4882a593Smuzhiyun 		brcmf_dbg(CONN, "AP mode link down\n");
6013*4882a593Smuzhiyun 		complete(&cfg->vif_disabled);
6014*4882a593Smuzhiyun 		return 0;
6015*4882a593Smuzhiyun 	}
6016*4882a593Smuzhiyun 
6017*4882a593Smuzhiyun 	if (((event == BRCMF_E_ASSOC_IND) || (event == BRCMF_E_REASSOC_IND)) &&
6018*4882a593Smuzhiyun 	    (reason == BRCMF_E_STATUS_SUCCESS)) {
6019*4882a593Smuzhiyun 		if (!data) {
6020*4882a593Smuzhiyun 			bphy_err(drvr, "No IEs present in ASSOC/REASSOC_IND\n");
6021*4882a593Smuzhiyun 			return -EINVAL;
6022*4882a593Smuzhiyun 		}
6023*4882a593Smuzhiyun 
6024*4882a593Smuzhiyun 		sinfo = kzalloc(sizeof(*sinfo), GFP_KERNEL);
6025*4882a593Smuzhiyun 		if (!sinfo)
6026*4882a593Smuzhiyun 			return -ENOMEM;
6027*4882a593Smuzhiyun 
6028*4882a593Smuzhiyun 		sinfo->assoc_req_ies = data;
6029*4882a593Smuzhiyun 		sinfo->assoc_req_ies_len = e->datalen;
6030*4882a593Smuzhiyun 		generation++;
6031*4882a593Smuzhiyun 		sinfo->generation = generation;
6032*4882a593Smuzhiyun 		cfg80211_new_sta(ndev, e->addr, sinfo, GFP_KERNEL);
6033*4882a593Smuzhiyun 
6034*4882a593Smuzhiyun 		kfree(sinfo);
6035*4882a593Smuzhiyun 	} else if ((event == BRCMF_E_DISASSOC_IND) ||
6036*4882a593Smuzhiyun 		   (event == BRCMF_E_DEAUTH_IND) ||
6037*4882a593Smuzhiyun 		   (event == BRCMF_E_DEAUTH)) {
6038*4882a593Smuzhiyun 		cfg80211_del_sta(ndev, e->addr, GFP_KERNEL);
6039*4882a593Smuzhiyun 	}
6040*4882a593Smuzhiyun 	return 0;
6041*4882a593Smuzhiyun }
6042*4882a593Smuzhiyun 
6043*4882a593Smuzhiyun static s32
brcmf_notify_connect_status(struct brcmf_if * ifp,const struct brcmf_event_msg * e,void * data)6044*4882a593Smuzhiyun brcmf_notify_connect_status(struct brcmf_if *ifp,
6045*4882a593Smuzhiyun 			    const struct brcmf_event_msg *e, void *data)
6046*4882a593Smuzhiyun {
6047*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = ifp->drvr->config;
6048*4882a593Smuzhiyun 	struct net_device *ndev = ifp->ndev;
6049*4882a593Smuzhiyun 	struct brcmf_cfg80211_profile *profile = &ifp->vif->profile;
6050*4882a593Smuzhiyun 	struct ieee80211_channel *chan;
6051*4882a593Smuzhiyun 	s32 err = 0;
6052*4882a593Smuzhiyun 
6053*4882a593Smuzhiyun 	if ((e->event_code == BRCMF_E_DEAUTH) ||
6054*4882a593Smuzhiyun 	    (e->event_code == BRCMF_E_DEAUTH_IND) ||
6055*4882a593Smuzhiyun 	    (e->event_code == BRCMF_E_DISASSOC_IND) ||
6056*4882a593Smuzhiyun 	    ((e->event_code == BRCMF_E_LINK) && (!e->flags))) {
6057*4882a593Smuzhiyun 		brcmf_proto_delete_peer(ifp->drvr, ifp->ifidx, (u8 *)e->addr);
6058*4882a593Smuzhiyun 	}
6059*4882a593Smuzhiyun 
6060*4882a593Smuzhiyun 	if (brcmf_is_apmode(ifp->vif)) {
6061*4882a593Smuzhiyun 		err = brcmf_notify_connect_status_ap(cfg, ndev, e, data);
6062*4882a593Smuzhiyun 	} else if (brcmf_is_linkup(ifp->vif, e)) {
6063*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Linkup\n");
6064*4882a593Smuzhiyun 		if (brcmf_is_ibssmode(ifp->vif)) {
6065*4882a593Smuzhiyun 			brcmf_inform_ibss(cfg, ndev, e->addr);
6066*4882a593Smuzhiyun 			chan = ieee80211_get_channel(cfg->wiphy, cfg->channel);
6067*4882a593Smuzhiyun 			memcpy(profile->bssid, e->addr, ETH_ALEN);
6068*4882a593Smuzhiyun 			cfg80211_ibss_joined(ndev, e->addr, chan, GFP_KERNEL);
6069*4882a593Smuzhiyun 			clear_bit(BRCMF_VIF_STATUS_CONNECTING,
6070*4882a593Smuzhiyun 				  &ifp->vif->sme_state);
6071*4882a593Smuzhiyun 			set_bit(BRCMF_VIF_STATUS_CONNECTED,
6072*4882a593Smuzhiyun 				&ifp->vif->sme_state);
6073*4882a593Smuzhiyun 		} else
6074*4882a593Smuzhiyun 			brcmf_bss_connect_done(cfg, ndev, e, true);
6075*4882a593Smuzhiyun 		brcmf_net_setcarrier(ifp, true);
6076*4882a593Smuzhiyun 	} else if (brcmf_is_linkdown(ifp->vif, e)) {
6077*4882a593Smuzhiyun 		brcmf_dbg(CONN, "Linkdown\n");
6078*4882a593Smuzhiyun 		if (!brcmf_is_ibssmode(ifp->vif) &&
6079*4882a593Smuzhiyun 		    test_bit(BRCMF_VIF_STATUS_CONNECTED,
6080*4882a593Smuzhiyun 			     &ifp->vif->sme_state)) {
6081*4882a593Smuzhiyun 			if (memcmp(profile->bssid, e->addr, ETH_ALEN))
6082*4882a593Smuzhiyun 				return err;
6083*4882a593Smuzhiyun 
6084*4882a593Smuzhiyun 			brcmf_bss_connect_done(cfg, ndev, e, false);
6085*4882a593Smuzhiyun 			brcmf_link_down(ifp->vif,
6086*4882a593Smuzhiyun 					brcmf_map_fw_linkdown_reason(e),
6087*4882a593Smuzhiyun 					e->event_code &
6088*4882a593Smuzhiyun 					(BRCMF_E_DEAUTH_IND |
6089*4882a593Smuzhiyun 					BRCMF_E_DISASSOC_IND)
6090*4882a593Smuzhiyun 					? false : true);
6091*4882a593Smuzhiyun 			brcmf_init_prof(ndev_to_prof(ndev));
6092*4882a593Smuzhiyun 			if (ndev != cfg_to_ndev(cfg))
6093*4882a593Smuzhiyun 				complete(&cfg->vif_disabled);
6094*4882a593Smuzhiyun 			brcmf_net_setcarrier(ifp, false);
6095*4882a593Smuzhiyun 		}
6096*4882a593Smuzhiyun 	} else if (brcmf_is_nonetwork(cfg, e)) {
6097*4882a593Smuzhiyun 		if (brcmf_is_ibssmode(ifp->vif))
6098*4882a593Smuzhiyun 			clear_bit(BRCMF_VIF_STATUS_CONNECTING,
6099*4882a593Smuzhiyun 				  &ifp->vif->sme_state);
6100*4882a593Smuzhiyun 		else
6101*4882a593Smuzhiyun 			brcmf_bss_connect_done(cfg, ndev, e, false);
6102*4882a593Smuzhiyun 	}
6103*4882a593Smuzhiyun 
6104*4882a593Smuzhiyun 	return err;
6105*4882a593Smuzhiyun }
6106*4882a593Smuzhiyun 
6107*4882a593Smuzhiyun static s32
brcmf_notify_roaming_status(struct brcmf_if * ifp,const struct brcmf_event_msg * e,void * data)6108*4882a593Smuzhiyun brcmf_notify_roaming_status(struct brcmf_if *ifp,
6109*4882a593Smuzhiyun 			    const struct brcmf_event_msg *e, void *data)
6110*4882a593Smuzhiyun {
6111*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = ifp->drvr->config;
6112*4882a593Smuzhiyun 	u32 event = e->event_code;
6113*4882a593Smuzhiyun 	u32 status = e->status;
6114*4882a593Smuzhiyun 
6115*4882a593Smuzhiyun 	if (event == BRCMF_E_ROAM && status == BRCMF_E_STATUS_SUCCESS) {
6116*4882a593Smuzhiyun 		if (test_bit(BRCMF_VIF_STATUS_CONNECTED,
6117*4882a593Smuzhiyun 			     &ifp->vif->sme_state)) {
6118*4882a593Smuzhiyun 			brcmf_bss_roaming_done(cfg, ifp->ndev, e);
6119*4882a593Smuzhiyun 		} else {
6120*4882a593Smuzhiyun 			brcmf_bss_connect_done(cfg, ifp->ndev, e, true);
6121*4882a593Smuzhiyun 			brcmf_net_setcarrier(ifp, true);
6122*4882a593Smuzhiyun 		}
6123*4882a593Smuzhiyun 	}
6124*4882a593Smuzhiyun 
6125*4882a593Smuzhiyun 	return 0;
6126*4882a593Smuzhiyun }
6127*4882a593Smuzhiyun 
6128*4882a593Smuzhiyun static s32
brcmf_notify_mic_status(struct brcmf_if * ifp,const struct brcmf_event_msg * e,void * data)6129*4882a593Smuzhiyun brcmf_notify_mic_status(struct brcmf_if *ifp,
6130*4882a593Smuzhiyun 			const struct brcmf_event_msg *e, void *data)
6131*4882a593Smuzhiyun {
6132*4882a593Smuzhiyun 	u16 flags = e->flags;
6133*4882a593Smuzhiyun 	enum nl80211_key_type key_type;
6134*4882a593Smuzhiyun 
6135*4882a593Smuzhiyun 	if (flags & BRCMF_EVENT_MSG_GROUP)
6136*4882a593Smuzhiyun 		key_type = NL80211_KEYTYPE_GROUP;
6137*4882a593Smuzhiyun 	else
6138*4882a593Smuzhiyun 		key_type = NL80211_KEYTYPE_PAIRWISE;
6139*4882a593Smuzhiyun 
6140*4882a593Smuzhiyun 	cfg80211_michael_mic_failure(ifp->ndev, (u8 *)&e->addr, key_type, -1,
6141*4882a593Smuzhiyun 				     NULL, GFP_KERNEL);
6142*4882a593Smuzhiyun 
6143*4882a593Smuzhiyun 	return 0;
6144*4882a593Smuzhiyun }
6145*4882a593Smuzhiyun 
brcmf_notify_vif_event(struct brcmf_if * ifp,const struct brcmf_event_msg * e,void * data)6146*4882a593Smuzhiyun static s32 brcmf_notify_vif_event(struct brcmf_if *ifp,
6147*4882a593Smuzhiyun 				  const struct brcmf_event_msg *e, void *data)
6148*4882a593Smuzhiyun {
6149*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = ifp->drvr->config;
6150*4882a593Smuzhiyun 	struct brcmf_if_event *ifevent = (struct brcmf_if_event *)data;
6151*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif_event *event = &cfg->vif_event;
6152*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
6153*4882a593Smuzhiyun 
6154*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter: action %u flags %u ifidx %u bsscfgidx %u\n",
6155*4882a593Smuzhiyun 		  ifevent->action, ifevent->flags, ifevent->ifidx,
6156*4882a593Smuzhiyun 		  ifevent->bsscfgidx);
6157*4882a593Smuzhiyun 
6158*4882a593Smuzhiyun 	spin_lock(&event->vif_event_lock);
6159*4882a593Smuzhiyun 	event->action = ifevent->action;
6160*4882a593Smuzhiyun 	vif = event->vif;
6161*4882a593Smuzhiyun 
6162*4882a593Smuzhiyun 	switch (ifevent->action) {
6163*4882a593Smuzhiyun 	case BRCMF_E_IF_ADD:
6164*4882a593Smuzhiyun 		/* waiting process may have timed out */
6165*4882a593Smuzhiyun 		if (!cfg->vif_event.vif) {
6166*4882a593Smuzhiyun 			spin_unlock(&event->vif_event_lock);
6167*4882a593Smuzhiyun 			return -EBADF;
6168*4882a593Smuzhiyun 		}
6169*4882a593Smuzhiyun 
6170*4882a593Smuzhiyun 		ifp->vif = vif;
6171*4882a593Smuzhiyun 		vif->ifp = ifp;
6172*4882a593Smuzhiyun 		if (ifp->ndev) {
6173*4882a593Smuzhiyun 			vif->wdev.netdev = ifp->ndev;
6174*4882a593Smuzhiyun 			ifp->ndev->ieee80211_ptr = &vif->wdev;
6175*4882a593Smuzhiyun 			SET_NETDEV_DEV(ifp->ndev, wiphy_dev(cfg->wiphy));
6176*4882a593Smuzhiyun 		}
6177*4882a593Smuzhiyun 		spin_unlock(&event->vif_event_lock);
6178*4882a593Smuzhiyun 		wake_up(&event->vif_wq);
6179*4882a593Smuzhiyun 		return 0;
6180*4882a593Smuzhiyun 
6181*4882a593Smuzhiyun 	case BRCMF_E_IF_DEL:
6182*4882a593Smuzhiyun 		spin_unlock(&event->vif_event_lock);
6183*4882a593Smuzhiyun 		/* event may not be upon user request */
6184*4882a593Smuzhiyun 		if (brcmf_cfg80211_vif_event_armed(cfg))
6185*4882a593Smuzhiyun 			wake_up(&event->vif_wq);
6186*4882a593Smuzhiyun 		return 0;
6187*4882a593Smuzhiyun 
6188*4882a593Smuzhiyun 	case BRCMF_E_IF_CHANGE:
6189*4882a593Smuzhiyun 		spin_unlock(&event->vif_event_lock);
6190*4882a593Smuzhiyun 		wake_up(&event->vif_wq);
6191*4882a593Smuzhiyun 		return 0;
6192*4882a593Smuzhiyun 
6193*4882a593Smuzhiyun 	default:
6194*4882a593Smuzhiyun 		spin_unlock(&event->vif_event_lock);
6195*4882a593Smuzhiyun 		break;
6196*4882a593Smuzhiyun 	}
6197*4882a593Smuzhiyun 	return -EINVAL;
6198*4882a593Smuzhiyun }
6199*4882a593Smuzhiyun 
brcmf_init_conf(struct brcmf_cfg80211_conf * conf)6200*4882a593Smuzhiyun static void brcmf_init_conf(struct brcmf_cfg80211_conf *conf)
6201*4882a593Smuzhiyun {
6202*4882a593Smuzhiyun 	conf->frag_threshold = (u32)-1;
6203*4882a593Smuzhiyun 	conf->rts_threshold = (u32)-1;
6204*4882a593Smuzhiyun 	conf->retry_short = (u32)-1;
6205*4882a593Smuzhiyun 	conf->retry_long = (u32)-1;
6206*4882a593Smuzhiyun }
6207*4882a593Smuzhiyun 
brcmf_register_event_handlers(struct brcmf_cfg80211_info * cfg)6208*4882a593Smuzhiyun static void brcmf_register_event_handlers(struct brcmf_cfg80211_info *cfg)
6209*4882a593Smuzhiyun {
6210*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_LINK,
6211*4882a593Smuzhiyun 			    brcmf_notify_connect_status);
6212*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_DEAUTH_IND,
6213*4882a593Smuzhiyun 			    brcmf_notify_connect_status);
6214*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_DEAUTH,
6215*4882a593Smuzhiyun 			    brcmf_notify_connect_status);
6216*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_DISASSOC_IND,
6217*4882a593Smuzhiyun 			    brcmf_notify_connect_status);
6218*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_ASSOC_IND,
6219*4882a593Smuzhiyun 			    brcmf_notify_connect_status);
6220*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_REASSOC_IND,
6221*4882a593Smuzhiyun 			    brcmf_notify_connect_status);
6222*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_ROAM,
6223*4882a593Smuzhiyun 			    brcmf_notify_roaming_status);
6224*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_MIC_ERROR,
6225*4882a593Smuzhiyun 			    brcmf_notify_mic_status);
6226*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_SET_SSID,
6227*4882a593Smuzhiyun 			    brcmf_notify_connect_status);
6228*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_PFN_NET_FOUND,
6229*4882a593Smuzhiyun 			    brcmf_notify_sched_scan_results);
6230*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_IF,
6231*4882a593Smuzhiyun 			    brcmf_notify_vif_event);
6232*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_P2P_PROBEREQ_MSG,
6233*4882a593Smuzhiyun 			    brcmf_p2p_notify_rx_mgmt_p2p_probereq);
6234*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_P2P_DISC_LISTEN_COMPLETE,
6235*4882a593Smuzhiyun 			    brcmf_p2p_notify_listen_complete);
6236*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_ACTION_FRAME_RX,
6237*4882a593Smuzhiyun 			    brcmf_p2p_notify_action_frame_rx);
6238*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_ACTION_FRAME_COMPLETE,
6239*4882a593Smuzhiyun 			    brcmf_p2p_notify_action_tx_complete);
6240*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_ACTION_FRAME_OFF_CHAN_COMPLETE,
6241*4882a593Smuzhiyun 			    brcmf_p2p_notify_action_tx_complete);
6242*4882a593Smuzhiyun 	brcmf_fweh_register(cfg->pub, BRCMF_E_PSK_SUP,
6243*4882a593Smuzhiyun 			    brcmf_notify_connect_status);
6244*4882a593Smuzhiyun }
6245*4882a593Smuzhiyun 
brcmf_deinit_priv_mem(struct brcmf_cfg80211_info * cfg)6246*4882a593Smuzhiyun static void brcmf_deinit_priv_mem(struct brcmf_cfg80211_info *cfg)
6247*4882a593Smuzhiyun {
6248*4882a593Smuzhiyun 	kfree(cfg->conf);
6249*4882a593Smuzhiyun 	cfg->conf = NULL;
6250*4882a593Smuzhiyun 	kfree(cfg->extra_buf);
6251*4882a593Smuzhiyun 	cfg->extra_buf = NULL;
6252*4882a593Smuzhiyun 	kfree(cfg->wowl.nd);
6253*4882a593Smuzhiyun 	cfg->wowl.nd = NULL;
6254*4882a593Smuzhiyun 	kfree(cfg->wowl.nd_info);
6255*4882a593Smuzhiyun 	cfg->wowl.nd_info = NULL;
6256*4882a593Smuzhiyun 	kfree(cfg->escan_info.escan_buf);
6257*4882a593Smuzhiyun 	cfg->escan_info.escan_buf = NULL;
6258*4882a593Smuzhiyun }
6259*4882a593Smuzhiyun 
brcmf_init_priv_mem(struct brcmf_cfg80211_info * cfg)6260*4882a593Smuzhiyun static s32 brcmf_init_priv_mem(struct brcmf_cfg80211_info *cfg)
6261*4882a593Smuzhiyun {
6262*4882a593Smuzhiyun 	cfg->conf = kzalloc(sizeof(*cfg->conf), GFP_KERNEL);
6263*4882a593Smuzhiyun 	if (!cfg->conf)
6264*4882a593Smuzhiyun 		goto init_priv_mem_out;
6265*4882a593Smuzhiyun 	cfg->extra_buf = kzalloc(WL_EXTRA_BUF_MAX, GFP_KERNEL);
6266*4882a593Smuzhiyun 	if (!cfg->extra_buf)
6267*4882a593Smuzhiyun 		goto init_priv_mem_out;
6268*4882a593Smuzhiyun 	cfg->wowl.nd = kzalloc(sizeof(*cfg->wowl.nd) + sizeof(u32), GFP_KERNEL);
6269*4882a593Smuzhiyun 	if (!cfg->wowl.nd)
6270*4882a593Smuzhiyun 		goto init_priv_mem_out;
6271*4882a593Smuzhiyun 	cfg->wowl.nd_info = kzalloc(sizeof(*cfg->wowl.nd_info) +
6272*4882a593Smuzhiyun 				    sizeof(struct cfg80211_wowlan_nd_match *),
6273*4882a593Smuzhiyun 				    GFP_KERNEL);
6274*4882a593Smuzhiyun 	if (!cfg->wowl.nd_info)
6275*4882a593Smuzhiyun 		goto init_priv_mem_out;
6276*4882a593Smuzhiyun 	cfg->escan_info.escan_buf = kzalloc(BRCMF_ESCAN_BUF_SIZE, GFP_KERNEL);
6277*4882a593Smuzhiyun 	if (!cfg->escan_info.escan_buf)
6278*4882a593Smuzhiyun 		goto init_priv_mem_out;
6279*4882a593Smuzhiyun 
6280*4882a593Smuzhiyun 	return 0;
6281*4882a593Smuzhiyun 
6282*4882a593Smuzhiyun init_priv_mem_out:
6283*4882a593Smuzhiyun 	brcmf_deinit_priv_mem(cfg);
6284*4882a593Smuzhiyun 
6285*4882a593Smuzhiyun 	return -ENOMEM;
6286*4882a593Smuzhiyun }
6287*4882a593Smuzhiyun 
wl_init_priv(struct brcmf_cfg80211_info * cfg)6288*4882a593Smuzhiyun static s32 wl_init_priv(struct brcmf_cfg80211_info *cfg)
6289*4882a593Smuzhiyun {
6290*4882a593Smuzhiyun 	s32 err = 0;
6291*4882a593Smuzhiyun 
6292*4882a593Smuzhiyun 	cfg->scan_request = NULL;
6293*4882a593Smuzhiyun 	cfg->pwr_save = true;
6294*4882a593Smuzhiyun 	cfg->dongle_up = false;		/* dongle is not up yet */
6295*4882a593Smuzhiyun 	err = brcmf_init_priv_mem(cfg);
6296*4882a593Smuzhiyun 	if (err)
6297*4882a593Smuzhiyun 		return err;
6298*4882a593Smuzhiyun 	brcmf_register_event_handlers(cfg);
6299*4882a593Smuzhiyun 	mutex_init(&cfg->usr_sync);
6300*4882a593Smuzhiyun 	brcmf_init_escan(cfg);
6301*4882a593Smuzhiyun 	brcmf_init_conf(cfg->conf);
6302*4882a593Smuzhiyun 	brcmf_init_wmm_prio(cfg->ac_priority);
6303*4882a593Smuzhiyun 	init_completion(&cfg->vif_disabled);
6304*4882a593Smuzhiyun 	return err;
6305*4882a593Smuzhiyun }
6306*4882a593Smuzhiyun 
wl_deinit_priv(struct brcmf_cfg80211_info * cfg)6307*4882a593Smuzhiyun static void wl_deinit_priv(struct brcmf_cfg80211_info *cfg)
6308*4882a593Smuzhiyun {
6309*4882a593Smuzhiyun 	cfg->dongle_up = false;	/* dongle down */
6310*4882a593Smuzhiyun 	brcmf_abort_scanning(cfg);
6311*4882a593Smuzhiyun 	brcmf_deinit_priv_mem(cfg);
6312*4882a593Smuzhiyun }
6313*4882a593Smuzhiyun 
init_vif_event(struct brcmf_cfg80211_vif_event * event)6314*4882a593Smuzhiyun static void init_vif_event(struct brcmf_cfg80211_vif_event *event)
6315*4882a593Smuzhiyun {
6316*4882a593Smuzhiyun 	init_waitqueue_head(&event->vif_wq);
6317*4882a593Smuzhiyun 	spin_lock_init(&event->vif_event_lock);
6318*4882a593Smuzhiyun }
6319*4882a593Smuzhiyun 
brcmf_dongle_roam(struct brcmf_if * ifp)6320*4882a593Smuzhiyun static s32 brcmf_dongle_roam(struct brcmf_if *ifp)
6321*4882a593Smuzhiyun {
6322*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
6323*4882a593Smuzhiyun 	s32 err;
6324*4882a593Smuzhiyun 	u32 bcn_timeout;
6325*4882a593Smuzhiyun 	__le32 roamtrigger[2];
6326*4882a593Smuzhiyun 	__le32 roam_delta[2];
6327*4882a593Smuzhiyun 
6328*4882a593Smuzhiyun 	/* Configure beacon timeout value based upon roaming setting */
6329*4882a593Smuzhiyun 	if (ifp->drvr->settings->roamoff)
6330*4882a593Smuzhiyun 		bcn_timeout = BRCMF_DEFAULT_BCN_TIMEOUT_ROAM_OFF;
6331*4882a593Smuzhiyun 	else
6332*4882a593Smuzhiyun 		bcn_timeout = BRCMF_DEFAULT_BCN_TIMEOUT_ROAM_ON;
6333*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_set(ifp, "bcn_timeout", bcn_timeout);
6334*4882a593Smuzhiyun 	if (err) {
6335*4882a593Smuzhiyun 		bphy_err(drvr, "bcn_timeout error (%d)\n", err);
6336*4882a593Smuzhiyun 		goto roam_setup_done;
6337*4882a593Smuzhiyun 	}
6338*4882a593Smuzhiyun 
6339*4882a593Smuzhiyun 	/* Enable/Disable built-in roaming to allow supplicant to take care of
6340*4882a593Smuzhiyun 	 * roaming.
6341*4882a593Smuzhiyun 	 */
6342*4882a593Smuzhiyun 	brcmf_dbg(INFO, "Internal Roaming = %s\n",
6343*4882a593Smuzhiyun 		  ifp->drvr->settings->roamoff ? "Off" : "On");
6344*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_set(ifp, "roam_off",
6345*4882a593Smuzhiyun 				      ifp->drvr->settings->roamoff);
6346*4882a593Smuzhiyun 	if (err) {
6347*4882a593Smuzhiyun 		bphy_err(drvr, "roam_off error (%d)\n", err);
6348*4882a593Smuzhiyun 		goto roam_setup_done;
6349*4882a593Smuzhiyun 	}
6350*4882a593Smuzhiyun 
6351*4882a593Smuzhiyun 	roamtrigger[0] = cpu_to_le32(WL_ROAM_TRIGGER_LEVEL);
6352*4882a593Smuzhiyun 	roamtrigger[1] = cpu_to_le32(BRCM_BAND_ALL);
6353*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SET_ROAM_TRIGGER,
6354*4882a593Smuzhiyun 				     (void *)roamtrigger, sizeof(roamtrigger));
6355*4882a593Smuzhiyun 	if (err)
6356*4882a593Smuzhiyun 		bphy_err(drvr, "WLC_SET_ROAM_TRIGGER error (%d)\n", err);
6357*4882a593Smuzhiyun 
6358*4882a593Smuzhiyun 	roam_delta[0] = cpu_to_le32(WL_ROAM_DELTA);
6359*4882a593Smuzhiyun 	roam_delta[1] = cpu_to_le32(BRCM_BAND_ALL);
6360*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_SET_ROAM_DELTA,
6361*4882a593Smuzhiyun 				     (void *)roam_delta, sizeof(roam_delta));
6362*4882a593Smuzhiyun 	if (err)
6363*4882a593Smuzhiyun 		bphy_err(drvr, "WLC_SET_ROAM_DELTA error (%d)\n", err);
6364*4882a593Smuzhiyun 
6365*4882a593Smuzhiyun 	return 0;
6366*4882a593Smuzhiyun 
6367*4882a593Smuzhiyun roam_setup_done:
6368*4882a593Smuzhiyun 	return err;
6369*4882a593Smuzhiyun }
6370*4882a593Smuzhiyun 
6371*4882a593Smuzhiyun static s32
brcmf_dongle_scantime(struct brcmf_if * ifp)6372*4882a593Smuzhiyun brcmf_dongle_scantime(struct brcmf_if *ifp)
6373*4882a593Smuzhiyun {
6374*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
6375*4882a593Smuzhiyun 	s32 err = 0;
6376*4882a593Smuzhiyun 
6377*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_SCAN_CHANNEL_TIME,
6378*4882a593Smuzhiyun 				    BRCMF_SCAN_CHANNEL_TIME);
6379*4882a593Smuzhiyun 	if (err) {
6380*4882a593Smuzhiyun 		bphy_err(drvr, "Scan assoc time error (%d)\n", err);
6381*4882a593Smuzhiyun 		goto dongle_scantime_out;
6382*4882a593Smuzhiyun 	}
6383*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_SCAN_UNASSOC_TIME,
6384*4882a593Smuzhiyun 				    BRCMF_SCAN_UNASSOC_TIME);
6385*4882a593Smuzhiyun 	if (err) {
6386*4882a593Smuzhiyun 		bphy_err(drvr, "Scan unassoc time error (%d)\n", err);
6387*4882a593Smuzhiyun 		goto dongle_scantime_out;
6388*4882a593Smuzhiyun 	}
6389*4882a593Smuzhiyun 
6390*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_SCAN_PASSIVE_TIME,
6391*4882a593Smuzhiyun 				    BRCMF_SCAN_PASSIVE_TIME);
6392*4882a593Smuzhiyun 	if (err) {
6393*4882a593Smuzhiyun 		bphy_err(drvr, "Scan passive time error (%d)\n", err);
6394*4882a593Smuzhiyun 		goto dongle_scantime_out;
6395*4882a593Smuzhiyun 	}
6396*4882a593Smuzhiyun 
6397*4882a593Smuzhiyun dongle_scantime_out:
6398*4882a593Smuzhiyun 	return err;
6399*4882a593Smuzhiyun }
6400*4882a593Smuzhiyun 
brcmf_update_bw40_channel_flag(struct ieee80211_channel * channel,struct brcmu_chan * ch)6401*4882a593Smuzhiyun static void brcmf_update_bw40_channel_flag(struct ieee80211_channel *channel,
6402*4882a593Smuzhiyun 					   struct brcmu_chan *ch)
6403*4882a593Smuzhiyun {
6404*4882a593Smuzhiyun 	u32 ht40_flag;
6405*4882a593Smuzhiyun 
6406*4882a593Smuzhiyun 	ht40_flag = channel->flags & IEEE80211_CHAN_NO_HT40;
6407*4882a593Smuzhiyun 	if (ch->sb == BRCMU_CHAN_SB_U) {
6408*4882a593Smuzhiyun 		if (ht40_flag == IEEE80211_CHAN_NO_HT40)
6409*4882a593Smuzhiyun 			channel->flags &= ~IEEE80211_CHAN_NO_HT40;
6410*4882a593Smuzhiyun 		channel->flags |= IEEE80211_CHAN_NO_HT40PLUS;
6411*4882a593Smuzhiyun 	} else {
6412*4882a593Smuzhiyun 		/* It should be one of
6413*4882a593Smuzhiyun 		 * IEEE80211_CHAN_NO_HT40 or
6414*4882a593Smuzhiyun 		 * IEEE80211_CHAN_NO_HT40PLUS
6415*4882a593Smuzhiyun 		 */
6416*4882a593Smuzhiyun 		channel->flags &= ~IEEE80211_CHAN_NO_HT40;
6417*4882a593Smuzhiyun 		if (ht40_flag == IEEE80211_CHAN_NO_HT40)
6418*4882a593Smuzhiyun 			channel->flags |= IEEE80211_CHAN_NO_HT40MINUS;
6419*4882a593Smuzhiyun 	}
6420*4882a593Smuzhiyun }
6421*4882a593Smuzhiyun 
brcmf_construct_chaninfo(struct brcmf_cfg80211_info * cfg,u32 bw_cap[])6422*4882a593Smuzhiyun static int brcmf_construct_chaninfo(struct brcmf_cfg80211_info *cfg,
6423*4882a593Smuzhiyun 				    u32 bw_cap[])
6424*4882a593Smuzhiyun {
6425*4882a593Smuzhiyun 	struct wiphy *wiphy = cfg_to_wiphy(cfg);
6426*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
6427*4882a593Smuzhiyun 	struct brcmf_if *ifp = brcmf_get_ifp(drvr, 0);
6428*4882a593Smuzhiyun 	struct ieee80211_supported_band *band;
6429*4882a593Smuzhiyun 	struct ieee80211_channel *channel;
6430*4882a593Smuzhiyun 	struct brcmf_chanspec_list *list;
6431*4882a593Smuzhiyun 	struct brcmu_chan ch;
6432*4882a593Smuzhiyun 	int err;
6433*4882a593Smuzhiyun 	u8 *pbuf;
6434*4882a593Smuzhiyun 	u32 i, j;
6435*4882a593Smuzhiyun 	u32 total;
6436*4882a593Smuzhiyun 	u32 chaninfo;
6437*4882a593Smuzhiyun 
6438*4882a593Smuzhiyun 	pbuf = kzalloc(BRCMF_DCMD_MEDLEN, GFP_KERNEL);
6439*4882a593Smuzhiyun 
6440*4882a593Smuzhiyun 	if (pbuf == NULL)
6441*4882a593Smuzhiyun 		return -ENOMEM;
6442*4882a593Smuzhiyun 
6443*4882a593Smuzhiyun 	list = (struct brcmf_chanspec_list *)pbuf;
6444*4882a593Smuzhiyun 
6445*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_get(ifp, "chanspecs", pbuf,
6446*4882a593Smuzhiyun 				       BRCMF_DCMD_MEDLEN);
6447*4882a593Smuzhiyun 	if (err) {
6448*4882a593Smuzhiyun 		bphy_err(drvr, "get chanspecs error (%d)\n", err);
6449*4882a593Smuzhiyun 		goto fail_pbuf;
6450*4882a593Smuzhiyun 	}
6451*4882a593Smuzhiyun 
6452*4882a593Smuzhiyun 	band = wiphy->bands[NL80211_BAND_2GHZ];
6453*4882a593Smuzhiyun 	if (band)
6454*4882a593Smuzhiyun 		for (i = 0; i < band->n_channels; i++)
6455*4882a593Smuzhiyun 			band->channels[i].flags = IEEE80211_CHAN_DISABLED;
6456*4882a593Smuzhiyun 	band = wiphy->bands[NL80211_BAND_5GHZ];
6457*4882a593Smuzhiyun 	if (band)
6458*4882a593Smuzhiyun 		for (i = 0; i < band->n_channels; i++)
6459*4882a593Smuzhiyun 			band->channels[i].flags = IEEE80211_CHAN_DISABLED;
6460*4882a593Smuzhiyun 
6461*4882a593Smuzhiyun 	total = le32_to_cpu(list->count);
6462*4882a593Smuzhiyun 	for (i = 0; i < total; i++) {
6463*4882a593Smuzhiyun 		ch.chspec = (u16)le32_to_cpu(list->element[i]);
6464*4882a593Smuzhiyun 		cfg->d11inf.decchspec(&ch);
6465*4882a593Smuzhiyun 
6466*4882a593Smuzhiyun 		if (ch.band == BRCMU_CHAN_BAND_2G) {
6467*4882a593Smuzhiyun 			band = wiphy->bands[NL80211_BAND_2GHZ];
6468*4882a593Smuzhiyun 		} else if (ch.band == BRCMU_CHAN_BAND_5G) {
6469*4882a593Smuzhiyun 			band = wiphy->bands[NL80211_BAND_5GHZ];
6470*4882a593Smuzhiyun 		} else {
6471*4882a593Smuzhiyun 			bphy_err(drvr, "Invalid channel Spec. 0x%x.\n",
6472*4882a593Smuzhiyun 				 ch.chspec);
6473*4882a593Smuzhiyun 			continue;
6474*4882a593Smuzhiyun 		}
6475*4882a593Smuzhiyun 		if (!band)
6476*4882a593Smuzhiyun 			continue;
6477*4882a593Smuzhiyun 		if (!(bw_cap[band->band] & WLC_BW_40MHZ_BIT) &&
6478*4882a593Smuzhiyun 		    ch.bw == BRCMU_CHAN_BW_40)
6479*4882a593Smuzhiyun 			continue;
6480*4882a593Smuzhiyun 		if (!(bw_cap[band->band] & WLC_BW_80MHZ_BIT) &&
6481*4882a593Smuzhiyun 		    ch.bw == BRCMU_CHAN_BW_80)
6482*4882a593Smuzhiyun 			continue;
6483*4882a593Smuzhiyun 
6484*4882a593Smuzhiyun 		channel = NULL;
6485*4882a593Smuzhiyun 		for (j = 0; j < band->n_channels; j++) {
6486*4882a593Smuzhiyun 			if (band->channels[j].hw_value == ch.control_ch_num) {
6487*4882a593Smuzhiyun 				channel = &band->channels[j];
6488*4882a593Smuzhiyun 				break;
6489*4882a593Smuzhiyun 			}
6490*4882a593Smuzhiyun 		}
6491*4882a593Smuzhiyun 		if (!channel) {
6492*4882a593Smuzhiyun 			/* It seems firmware supports some channel we never
6493*4882a593Smuzhiyun 			 * considered. Something new in IEEE standard?
6494*4882a593Smuzhiyun 			 */
6495*4882a593Smuzhiyun 			bphy_err(drvr, "Ignoring unexpected firmware channel %d\n",
6496*4882a593Smuzhiyun 				 ch.control_ch_num);
6497*4882a593Smuzhiyun 			continue;
6498*4882a593Smuzhiyun 		}
6499*4882a593Smuzhiyun 
6500*4882a593Smuzhiyun 		if (channel->orig_flags & IEEE80211_CHAN_DISABLED)
6501*4882a593Smuzhiyun 			continue;
6502*4882a593Smuzhiyun 
6503*4882a593Smuzhiyun 		/* assuming the chanspecs order is HT20,
6504*4882a593Smuzhiyun 		 * HT40 upper, HT40 lower, and VHT80.
6505*4882a593Smuzhiyun 		 */
6506*4882a593Smuzhiyun 		switch (ch.bw) {
6507*4882a593Smuzhiyun 		case BRCMU_CHAN_BW_160:
6508*4882a593Smuzhiyun 			channel->flags &= ~IEEE80211_CHAN_NO_160MHZ;
6509*4882a593Smuzhiyun 			break;
6510*4882a593Smuzhiyun 		case BRCMU_CHAN_BW_80:
6511*4882a593Smuzhiyun 			channel->flags &= ~IEEE80211_CHAN_NO_80MHZ;
6512*4882a593Smuzhiyun 			break;
6513*4882a593Smuzhiyun 		case BRCMU_CHAN_BW_40:
6514*4882a593Smuzhiyun 			brcmf_update_bw40_channel_flag(channel, &ch);
6515*4882a593Smuzhiyun 			break;
6516*4882a593Smuzhiyun 		default:
6517*4882a593Smuzhiyun 			wiphy_warn(wiphy, "Firmware reported unsupported bandwidth %d\n",
6518*4882a593Smuzhiyun 				   ch.bw);
6519*4882a593Smuzhiyun 			fallthrough;
6520*4882a593Smuzhiyun 		case BRCMU_CHAN_BW_20:
6521*4882a593Smuzhiyun 			/* enable the channel and disable other bandwidths
6522*4882a593Smuzhiyun 			 * for now as mentioned order assure they are enabled
6523*4882a593Smuzhiyun 			 * for subsequent chanspecs.
6524*4882a593Smuzhiyun 			 */
6525*4882a593Smuzhiyun 			channel->flags = IEEE80211_CHAN_NO_HT40 |
6526*4882a593Smuzhiyun 					 IEEE80211_CHAN_NO_80MHZ |
6527*4882a593Smuzhiyun 					 IEEE80211_CHAN_NO_160MHZ;
6528*4882a593Smuzhiyun 			ch.bw = BRCMU_CHAN_BW_20;
6529*4882a593Smuzhiyun 			cfg->d11inf.encchspec(&ch);
6530*4882a593Smuzhiyun 			chaninfo = ch.chspec;
6531*4882a593Smuzhiyun 			err = brcmf_fil_bsscfg_int_get(ifp, "per_chan_info",
6532*4882a593Smuzhiyun 						       &chaninfo);
6533*4882a593Smuzhiyun 			if (!err) {
6534*4882a593Smuzhiyun 				if (chaninfo & WL_CHAN_RADAR)
6535*4882a593Smuzhiyun 					channel->flags |=
6536*4882a593Smuzhiyun 						(IEEE80211_CHAN_RADAR |
6537*4882a593Smuzhiyun 						 IEEE80211_CHAN_NO_IR);
6538*4882a593Smuzhiyun 				if (chaninfo & WL_CHAN_PASSIVE)
6539*4882a593Smuzhiyun 					channel->flags |=
6540*4882a593Smuzhiyun 						IEEE80211_CHAN_NO_IR;
6541*4882a593Smuzhiyun 			}
6542*4882a593Smuzhiyun 		}
6543*4882a593Smuzhiyun 	}
6544*4882a593Smuzhiyun 
6545*4882a593Smuzhiyun fail_pbuf:
6546*4882a593Smuzhiyun 	kfree(pbuf);
6547*4882a593Smuzhiyun 	return err;
6548*4882a593Smuzhiyun }
6549*4882a593Smuzhiyun 
brcmf_enable_bw40_2g(struct brcmf_cfg80211_info * cfg)6550*4882a593Smuzhiyun static int brcmf_enable_bw40_2g(struct brcmf_cfg80211_info *cfg)
6551*4882a593Smuzhiyun {
6552*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
6553*4882a593Smuzhiyun 	struct brcmf_if *ifp = brcmf_get_ifp(drvr, 0);
6554*4882a593Smuzhiyun 	struct ieee80211_supported_band *band;
6555*4882a593Smuzhiyun 	struct brcmf_fil_bwcap_le band_bwcap;
6556*4882a593Smuzhiyun 	struct brcmf_chanspec_list *list;
6557*4882a593Smuzhiyun 	u8 *pbuf;
6558*4882a593Smuzhiyun 	u32 val;
6559*4882a593Smuzhiyun 	int err;
6560*4882a593Smuzhiyun 	struct brcmu_chan ch;
6561*4882a593Smuzhiyun 	u32 num_chan;
6562*4882a593Smuzhiyun 	int i, j;
6563*4882a593Smuzhiyun 
6564*4882a593Smuzhiyun 	/* verify support for bw_cap command */
6565*4882a593Smuzhiyun 	val = WLC_BAND_5G;
6566*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_get(ifp, "bw_cap", &val);
6567*4882a593Smuzhiyun 
6568*4882a593Smuzhiyun 	if (!err) {
6569*4882a593Smuzhiyun 		/* only set 2G bandwidth using bw_cap command */
6570*4882a593Smuzhiyun 		band_bwcap.band = cpu_to_le32(WLC_BAND_2G);
6571*4882a593Smuzhiyun 		band_bwcap.bw_cap = cpu_to_le32(WLC_BW_CAP_40MHZ);
6572*4882a593Smuzhiyun 		err = brcmf_fil_iovar_data_set(ifp, "bw_cap", &band_bwcap,
6573*4882a593Smuzhiyun 					       sizeof(band_bwcap));
6574*4882a593Smuzhiyun 	} else {
6575*4882a593Smuzhiyun 		brcmf_dbg(INFO, "fallback to mimo_bw_cap\n");
6576*4882a593Smuzhiyun 		val = WLC_N_BW_40ALL;
6577*4882a593Smuzhiyun 		err = brcmf_fil_iovar_int_set(ifp, "mimo_bw_cap", val);
6578*4882a593Smuzhiyun 	}
6579*4882a593Smuzhiyun 
6580*4882a593Smuzhiyun 	if (!err) {
6581*4882a593Smuzhiyun 		/* update channel info in 2G band */
6582*4882a593Smuzhiyun 		pbuf = kzalloc(BRCMF_DCMD_MEDLEN, GFP_KERNEL);
6583*4882a593Smuzhiyun 
6584*4882a593Smuzhiyun 		if (pbuf == NULL)
6585*4882a593Smuzhiyun 			return -ENOMEM;
6586*4882a593Smuzhiyun 
6587*4882a593Smuzhiyun 		ch.band = BRCMU_CHAN_BAND_2G;
6588*4882a593Smuzhiyun 		ch.bw = BRCMU_CHAN_BW_40;
6589*4882a593Smuzhiyun 		ch.sb = BRCMU_CHAN_SB_NONE;
6590*4882a593Smuzhiyun 		ch.chnum = 0;
6591*4882a593Smuzhiyun 		cfg->d11inf.encchspec(&ch);
6592*4882a593Smuzhiyun 
6593*4882a593Smuzhiyun 		/* pass encoded chanspec in query */
6594*4882a593Smuzhiyun 		*(__le16 *)pbuf = cpu_to_le16(ch.chspec);
6595*4882a593Smuzhiyun 
6596*4882a593Smuzhiyun 		err = brcmf_fil_iovar_data_get(ifp, "chanspecs", pbuf,
6597*4882a593Smuzhiyun 					       BRCMF_DCMD_MEDLEN);
6598*4882a593Smuzhiyun 		if (err) {
6599*4882a593Smuzhiyun 			bphy_err(drvr, "get chanspecs error (%d)\n", err);
6600*4882a593Smuzhiyun 			kfree(pbuf);
6601*4882a593Smuzhiyun 			return err;
6602*4882a593Smuzhiyun 		}
6603*4882a593Smuzhiyun 
6604*4882a593Smuzhiyun 		band = cfg_to_wiphy(cfg)->bands[NL80211_BAND_2GHZ];
6605*4882a593Smuzhiyun 		list = (struct brcmf_chanspec_list *)pbuf;
6606*4882a593Smuzhiyun 		num_chan = le32_to_cpu(list->count);
6607*4882a593Smuzhiyun 		for (i = 0; i < num_chan; i++) {
6608*4882a593Smuzhiyun 			ch.chspec = (u16)le32_to_cpu(list->element[i]);
6609*4882a593Smuzhiyun 			cfg->d11inf.decchspec(&ch);
6610*4882a593Smuzhiyun 			if (WARN_ON(ch.band != BRCMU_CHAN_BAND_2G))
6611*4882a593Smuzhiyun 				continue;
6612*4882a593Smuzhiyun 			if (WARN_ON(ch.bw != BRCMU_CHAN_BW_40))
6613*4882a593Smuzhiyun 				continue;
6614*4882a593Smuzhiyun 			for (j = 0; j < band->n_channels; j++) {
6615*4882a593Smuzhiyun 				if (band->channels[j].hw_value == ch.control_ch_num)
6616*4882a593Smuzhiyun 					break;
6617*4882a593Smuzhiyun 			}
6618*4882a593Smuzhiyun 			if (WARN_ON(j == band->n_channels))
6619*4882a593Smuzhiyun 				continue;
6620*4882a593Smuzhiyun 
6621*4882a593Smuzhiyun 			brcmf_update_bw40_channel_flag(&band->channels[j], &ch);
6622*4882a593Smuzhiyun 		}
6623*4882a593Smuzhiyun 		kfree(pbuf);
6624*4882a593Smuzhiyun 	}
6625*4882a593Smuzhiyun 	return err;
6626*4882a593Smuzhiyun }
6627*4882a593Smuzhiyun 
brcmf_get_bwcap(struct brcmf_if * ifp,u32 bw_cap[])6628*4882a593Smuzhiyun static void brcmf_get_bwcap(struct brcmf_if *ifp, u32 bw_cap[])
6629*4882a593Smuzhiyun {
6630*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
6631*4882a593Smuzhiyun 	u32 band, mimo_bwcap;
6632*4882a593Smuzhiyun 	int err;
6633*4882a593Smuzhiyun 
6634*4882a593Smuzhiyun 	band = WLC_BAND_2G;
6635*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_get(ifp, "bw_cap", &band);
6636*4882a593Smuzhiyun 	if (!err) {
6637*4882a593Smuzhiyun 		bw_cap[NL80211_BAND_2GHZ] = band;
6638*4882a593Smuzhiyun 		band = WLC_BAND_5G;
6639*4882a593Smuzhiyun 		err = brcmf_fil_iovar_int_get(ifp, "bw_cap", &band);
6640*4882a593Smuzhiyun 		if (!err) {
6641*4882a593Smuzhiyun 			bw_cap[NL80211_BAND_5GHZ] = band;
6642*4882a593Smuzhiyun 			return;
6643*4882a593Smuzhiyun 		}
6644*4882a593Smuzhiyun 		WARN_ON(1);
6645*4882a593Smuzhiyun 		return;
6646*4882a593Smuzhiyun 	}
6647*4882a593Smuzhiyun 	brcmf_dbg(INFO, "fallback to mimo_bw_cap info\n");
6648*4882a593Smuzhiyun 	mimo_bwcap = 0;
6649*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_get(ifp, "mimo_bw_cap", &mimo_bwcap);
6650*4882a593Smuzhiyun 	if (err)
6651*4882a593Smuzhiyun 		/* assume 20MHz if firmware does not give a clue */
6652*4882a593Smuzhiyun 		mimo_bwcap = WLC_N_BW_20ALL;
6653*4882a593Smuzhiyun 
6654*4882a593Smuzhiyun 	switch (mimo_bwcap) {
6655*4882a593Smuzhiyun 	case WLC_N_BW_40ALL:
6656*4882a593Smuzhiyun 		bw_cap[NL80211_BAND_2GHZ] |= WLC_BW_40MHZ_BIT;
6657*4882a593Smuzhiyun 		fallthrough;
6658*4882a593Smuzhiyun 	case WLC_N_BW_20IN2G_40IN5G:
6659*4882a593Smuzhiyun 		bw_cap[NL80211_BAND_5GHZ] |= WLC_BW_40MHZ_BIT;
6660*4882a593Smuzhiyun 		fallthrough;
6661*4882a593Smuzhiyun 	case WLC_N_BW_20ALL:
6662*4882a593Smuzhiyun 		bw_cap[NL80211_BAND_2GHZ] |= WLC_BW_20MHZ_BIT;
6663*4882a593Smuzhiyun 		bw_cap[NL80211_BAND_5GHZ] |= WLC_BW_20MHZ_BIT;
6664*4882a593Smuzhiyun 		break;
6665*4882a593Smuzhiyun 	default:
6666*4882a593Smuzhiyun 		bphy_err(drvr, "invalid mimo_bw_cap value\n");
6667*4882a593Smuzhiyun 	}
6668*4882a593Smuzhiyun }
6669*4882a593Smuzhiyun 
brcmf_update_ht_cap(struct ieee80211_supported_band * band,u32 bw_cap[2],u32 nchain)6670*4882a593Smuzhiyun static void brcmf_update_ht_cap(struct ieee80211_supported_band *band,
6671*4882a593Smuzhiyun 				u32 bw_cap[2], u32 nchain)
6672*4882a593Smuzhiyun {
6673*4882a593Smuzhiyun 	band->ht_cap.ht_supported = true;
6674*4882a593Smuzhiyun 	if (bw_cap[band->band] & WLC_BW_40MHZ_BIT) {
6675*4882a593Smuzhiyun 		band->ht_cap.cap |= IEEE80211_HT_CAP_SGI_40;
6676*4882a593Smuzhiyun 		band->ht_cap.cap |= IEEE80211_HT_CAP_SUP_WIDTH_20_40;
6677*4882a593Smuzhiyun 	}
6678*4882a593Smuzhiyun 	band->ht_cap.cap |= IEEE80211_HT_CAP_SGI_20;
6679*4882a593Smuzhiyun 	band->ht_cap.cap |= IEEE80211_HT_CAP_DSSSCCK40;
6680*4882a593Smuzhiyun 	band->ht_cap.ampdu_factor = IEEE80211_HT_MAX_AMPDU_64K;
6681*4882a593Smuzhiyun 	band->ht_cap.ampdu_density = IEEE80211_HT_MPDU_DENSITY_16;
6682*4882a593Smuzhiyun 	memset(band->ht_cap.mcs.rx_mask, 0xff, nchain);
6683*4882a593Smuzhiyun 	band->ht_cap.mcs.tx_params = IEEE80211_HT_MCS_TX_DEFINED;
6684*4882a593Smuzhiyun }
6685*4882a593Smuzhiyun 
brcmf_get_mcs_map(u32 nchain,enum ieee80211_vht_mcs_support supp)6686*4882a593Smuzhiyun static __le16 brcmf_get_mcs_map(u32 nchain, enum ieee80211_vht_mcs_support supp)
6687*4882a593Smuzhiyun {
6688*4882a593Smuzhiyun 	u16 mcs_map;
6689*4882a593Smuzhiyun 	int i;
6690*4882a593Smuzhiyun 
6691*4882a593Smuzhiyun 	for (i = 0, mcs_map = 0xFFFF; i < nchain; i++)
6692*4882a593Smuzhiyun 		mcs_map = (mcs_map << 2) | supp;
6693*4882a593Smuzhiyun 
6694*4882a593Smuzhiyun 	return cpu_to_le16(mcs_map);
6695*4882a593Smuzhiyun }
6696*4882a593Smuzhiyun 
brcmf_update_vht_cap(struct ieee80211_supported_band * band,u32 bw_cap[2],u32 nchain,u32 txstreams,u32 txbf_bfe_cap,u32 txbf_bfr_cap)6697*4882a593Smuzhiyun static void brcmf_update_vht_cap(struct ieee80211_supported_band *band,
6698*4882a593Smuzhiyun 				 u32 bw_cap[2], u32 nchain, u32 txstreams,
6699*4882a593Smuzhiyun 				 u32 txbf_bfe_cap, u32 txbf_bfr_cap)
6700*4882a593Smuzhiyun {
6701*4882a593Smuzhiyun 	__le16 mcs_map;
6702*4882a593Smuzhiyun 
6703*4882a593Smuzhiyun 	/* not allowed in 2.4G band */
6704*4882a593Smuzhiyun 	if (band->band == NL80211_BAND_2GHZ)
6705*4882a593Smuzhiyun 		return;
6706*4882a593Smuzhiyun 
6707*4882a593Smuzhiyun 	band->vht_cap.vht_supported = true;
6708*4882a593Smuzhiyun 	/* 80MHz is mandatory */
6709*4882a593Smuzhiyun 	band->vht_cap.cap |= IEEE80211_VHT_CAP_SHORT_GI_80;
6710*4882a593Smuzhiyun 	if (bw_cap[band->band] & WLC_BW_160MHZ_BIT) {
6711*4882a593Smuzhiyun 		band->vht_cap.cap |= IEEE80211_VHT_CAP_SUPP_CHAN_WIDTH_160MHZ;
6712*4882a593Smuzhiyun 		band->vht_cap.cap |= IEEE80211_VHT_CAP_SHORT_GI_160;
6713*4882a593Smuzhiyun 	}
6714*4882a593Smuzhiyun 	/* all support 256-QAM */
6715*4882a593Smuzhiyun 	mcs_map = brcmf_get_mcs_map(nchain, IEEE80211_VHT_MCS_SUPPORT_0_9);
6716*4882a593Smuzhiyun 	band->vht_cap.vht_mcs.rx_mcs_map = mcs_map;
6717*4882a593Smuzhiyun 	band->vht_cap.vht_mcs.tx_mcs_map = mcs_map;
6718*4882a593Smuzhiyun 
6719*4882a593Smuzhiyun 	/* Beamforming support information */
6720*4882a593Smuzhiyun 	if (txbf_bfe_cap & BRCMF_TXBF_SU_BFE_CAP)
6721*4882a593Smuzhiyun 		band->vht_cap.cap |= IEEE80211_VHT_CAP_SU_BEAMFORMEE_CAPABLE;
6722*4882a593Smuzhiyun 	if (txbf_bfe_cap & BRCMF_TXBF_MU_BFE_CAP)
6723*4882a593Smuzhiyun 		band->vht_cap.cap |= IEEE80211_VHT_CAP_MU_BEAMFORMEE_CAPABLE;
6724*4882a593Smuzhiyun 	if (txbf_bfr_cap & BRCMF_TXBF_SU_BFR_CAP)
6725*4882a593Smuzhiyun 		band->vht_cap.cap |= IEEE80211_VHT_CAP_SU_BEAMFORMER_CAPABLE;
6726*4882a593Smuzhiyun 	if (txbf_bfr_cap & BRCMF_TXBF_MU_BFR_CAP)
6727*4882a593Smuzhiyun 		band->vht_cap.cap |= IEEE80211_VHT_CAP_MU_BEAMFORMER_CAPABLE;
6728*4882a593Smuzhiyun 
6729*4882a593Smuzhiyun 	if ((txbf_bfe_cap || txbf_bfr_cap) && (txstreams > 1)) {
6730*4882a593Smuzhiyun 		band->vht_cap.cap |=
6731*4882a593Smuzhiyun 			(2 << IEEE80211_VHT_CAP_BEAMFORMEE_STS_SHIFT);
6732*4882a593Smuzhiyun 		band->vht_cap.cap |= ((txstreams - 1) <<
6733*4882a593Smuzhiyun 				IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_SHIFT);
6734*4882a593Smuzhiyun 		band->vht_cap.cap |=
6735*4882a593Smuzhiyun 			IEEE80211_VHT_CAP_VHT_LINK_ADAPTATION_VHT_MRQ_MFB;
6736*4882a593Smuzhiyun 	}
6737*4882a593Smuzhiyun }
6738*4882a593Smuzhiyun 
brcmf_setup_wiphybands(struct brcmf_cfg80211_info * cfg)6739*4882a593Smuzhiyun static int brcmf_setup_wiphybands(struct brcmf_cfg80211_info *cfg)
6740*4882a593Smuzhiyun {
6741*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
6742*4882a593Smuzhiyun 	struct brcmf_if *ifp = brcmf_get_ifp(drvr, 0);
6743*4882a593Smuzhiyun 	struct wiphy *wiphy = cfg_to_wiphy(cfg);
6744*4882a593Smuzhiyun 	u32 nmode = 0;
6745*4882a593Smuzhiyun 	u32 vhtmode = 0;
6746*4882a593Smuzhiyun 	u32 bw_cap[2] = { WLC_BW_20MHZ_BIT, WLC_BW_20MHZ_BIT };
6747*4882a593Smuzhiyun 	u32 rxchain;
6748*4882a593Smuzhiyun 	u32 nchain;
6749*4882a593Smuzhiyun 	int err;
6750*4882a593Smuzhiyun 	s32 i;
6751*4882a593Smuzhiyun 	struct ieee80211_supported_band *band;
6752*4882a593Smuzhiyun 	u32 txstreams = 0;
6753*4882a593Smuzhiyun 	u32 txbf_bfe_cap = 0;
6754*4882a593Smuzhiyun 	u32 txbf_bfr_cap = 0;
6755*4882a593Smuzhiyun 
6756*4882a593Smuzhiyun 	(void)brcmf_fil_iovar_int_get(ifp, "vhtmode", &vhtmode);
6757*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_get(ifp, "nmode", &nmode);
6758*4882a593Smuzhiyun 	if (err) {
6759*4882a593Smuzhiyun 		bphy_err(drvr, "nmode error (%d)\n", err);
6760*4882a593Smuzhiyun 	} else {
6761*4882a593Smuzhiyun 		brcmf_get_bwcap(ifp, bw_cap);
6762*4882a593Smuzhiyun 	}
6763*4882a593Smuzhiyun 	brcmf_dbg(INFO, "nmode=%d, vhtmode=%d, bw_cap=(%d, %d)\n",
6764*4882a593Smuzhiyun 		  nmode, vhtmode, bw_cap[NL80211_BAND_2GHZ],
6765*4882a593Smuzhiyun 		  bw_cap[NL80211_BAND_5GHZ]);
6766*4882a593Smuzhiyun 
6767*4882a593Smuzhiyun 	err = brcmf_fil_iovar_int_get(ifp, "rxchain", &rxchain);
6768*4882a593Smuzhiyun 	if (err) {
6769*4882a593Smuzhiyun 		bphy_err(drvr, "rxchain error (%d)\n", err);
6770*4882a593Smuzhiyun 		nchain = 1;
6771*4882a593Smuzhiyun 	} else {
6772*4882a593Smuzhiyun 		for (nchain = 0; rxchain; nchain++)
6773*4882a593Smuzhiyun 			rxchain = rxchain & (rxchain - 1);
6774*4882a593Smuzhiyun 	}
6775*4882a593Smuzhiyun 	brcmf_dbg(INFO, "nchain=%d\n", nchain);
6776*4882a593Smuzhiyun 
6777*4882a593Smuzhiyun 	err = brcmf_construct_chaninfo(cfg, bw_cap);
6778*4882a593Smuzhiyun 	if (err) {
6779*4882a593Smuzhiyun 		bphy_err(drvr, "brcmf_construct_chaninfo failed (%d)\n", err);
6780*4882a593Smuzhiyun 		return err;
6781*4882a593Smuzhiyun 	}
6782*4882a593Smuzhiyun 
6783*4882a593Smuzhiyun 	if (vhtmode) {
6784*4882a593Smuzhiyun 		(void)brcmf_fil_iovar_int_get(ifp, "txstreams", &txstreams);
6785*4882a593Smuzhiyun 		(void)brcmf_fil_iovar_int_get(ifp, "txbf_bfe_cap",
6786*4882a593Smuzhiyun 					      &txbf_bfe_cap);
6787*4882a593Smuzhiyun 		(void)brcmf_fil_iovar_int_get(ifp, "txbf_bfr_cap",
6788*4882a593Smuzhiyun 					      &txbf_bfr_cap);
6789*4882a593Smuzhiyun 	}
6790*4882a593Smuzhiyun 
6791*4882a593Smuzhiyun 	for (i = 0; i < ARRAY_SIZE(wiphy->bands); i++) {
6792*4882a593Smuzhiyun 		band = wiphy->bands[i];
6793*4882a593Smuzhiyun 		if (band == NULL)
6794*4882a593Smuzhiyun 			continue;
6795*4882a593Smuzhiyun 
6796*4882a593Smuzhiyun 		if (nmode)
6797*4882a593Smuzhiyun 			brcmf_update_ht_cap(band, bw_cap, nchain);
6798*4882a593Smuzhiyun 		if (vhtmode)
6799*4882a593Smuzhiyun 			brcmf_update_vht_cap(band, bw_cap, nchain, txstreams,
6800*4882a593Smuzhiyun 					     txbf_bfe_cap, txbf_bfr_cap);
6801*4882a593Smuzhiyun 	}
6802*4882a593Smuzhiyun 
6803*4882a593Smuzhiyun 	return 0;
6804*4882a593Smuzhiyun }
6805*4882a593Smuzhiyun 
6806*4882a593Smuzhiyun static const struct ieee80211_txrx_stypes
6807*4882a593Smuzhiyun brcmf_txrx_stypes[NUM_NL80211_IFTYPES] = {
6808*4882a593Smuzhiyun 	[NL80211_IFTYPE_STATION] = {
6809*4882a593Smuzhiyun 		.tx = 0xffff,
6810*4882a593Smuzhiyun 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
6811*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
6812*4882a593Smuzhiyun 	},
6813*4882a593Smuzhiyun 	[NL80211_IFTYPE_P2P_CLIENT] = {
6814*4882a593Smuzhiyun 		.tx = 0xffff,
6815*4882a593Smuzhiyun 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
6816*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
6817*4882a593Smuzhiyun 	},
6818*4882a593Smuzhiyun 	[NL80211_IFTYPE_P2P_GO] = {
6819*4882a593Smuzhiyun 		.tx = 0xffff,
6820*4882a593Smuzhiyun 		.rx = BIT(IEEE80211_STYPE_ASSOC_REQ >> 4) |
6821*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_REASSOC_REQ >> 4) |
6822*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_PROBE_REQ >> 4) |
6823*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_DISASSOC >> 4) |
6824*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_AUTH >> 4) |
6825*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_DEAUTH >> 4) |
6826*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_ACTION >> 4)
6827*4882a593Smuzhiyun 	},
6828*4882a593Smuzhiyun 	[NL80211_IFTYPE_P2P_DEVICE] = {
6829*4882a593Smuzhiyun 		.tx = 0xffff,
6830*4882a593Smuzhiyun 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
6831*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
6832*4882a593Smuzhiyun 	},
6833*4882a593Smuzhiyun 	[NL80211_IFTYPE_AP] = {
6834*4882a593Smuzhiyun 		.tx = 0xffff,
6835*4882a593Smuzhiyun 		.rx = BIT(IEEE80211_STYPE_ASSOC_REQ >> 4) |
6836*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_REASSOC_REQ >> 4) |
6837*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_PROBE_REQ >> 4) |
6838*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_DISASSOC >> 4) |
6839*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_AUTH >> 4) |
6840*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_DEAUTH >> 4) |
6841*4882a593Smuzhiyun 		      BIT(IEEE80211_STYPE_ACTION >> 4)
6842*4882a593Smuzhiyun 	}
6843*4882a593Smuzhiyun };
6844*4882a593Smuzhiyun 
6845*4882a593Smuzhiyun /**
6846*4882a593Smuzhiyun  * brcmf_setup_ifmodes() - determine interface modes and combinations.
6847*4882a593Smuzhiyun  *
6848*4882a593Smuzhiyun  * @wiphy: wiphy object.
6849*4882a593Smuzhiyun  * @ifp: interface object needed for feat module api.
6850*4882a593Smuzhiyun  *
6851*4882a593Smuzhiyun  * The interface modes and combinations are determined dynamically here
6852*4882a593Smuzhiyun  * based on firmware functionality.
6853*4882a593Smuzhiyun  *
6854*4882a593Smuzhiyun  * no p2p and no mbss:
6855*4882a593Smuzhiyun  *
6856*4882a593Smuzhiyun  *	#STA <= 1, #AP <= 1, channels = 1, 2 total
6857*4882a593Smuzhiyun  *
6858*4882a593Smuzhiyun  * no p2p and mbss:
6859*4882a593Smuzhiyun  *
6860*4882a593Smuzhiyun  *	#STA <= 1, #AP <= 1, channels = 1, 2 total
6861*4882a593Smuzhiyun  *	#AP <= 4, matching BI, channels = 1, 4 total
6862*4882a593Smuzhiyun  *
6863*4882a593Smuzhiyun  * no p2p and rsdb:
6864*4882a593Smuzhiyun  *	#STA <= 1, #AP <= 2, channels = 2, 4 total
6865*4882a593Smuzhiyun  *
6866*4882a593Smuzhiyun  * p2p, no mchan, and mbss:
6867*4882a593Smuzhiyun  *
6868*4882a593Smuzhiyun  *	#STA <= 1, #P2P-DEV <= 1, #{P2P-CL, P2P-GO} <= 1, channels = 1, 3 total
6869*4882a593Smuzhiyun  *	#STA <= 1, #P2P-DEV <= 1, #AP <= 1, #P2P-CL <= 1, channels = 1, 4 total
6870*4882a593Smuzhiyun  *	#AP <= 4, matching BI, channels = 1, 4 total
6871*4882a593Smuzhiyun  *
6872*4882a593Smuzhiyun  * p2p, mchan, and mbss:
6873*4882a593Smuzhiyun  *
6874*4882a593Smuzhiyun  *	#STA <= 1, #P2P-DEV <= 1, #{P2P-CL, P2P-GO} <= 1, channels = 2, 3 total
6875*4882a593Smuzhiyun  *	#STA <= 1, #P2P-DEV <= 1, #AP <= 1, #P2P-CL <= 1, channels = 1, 4 total
6876*4882a593Smuzhiyun  *	#AP <= 4, matching BI, channels = 1, 4 total
6877*4882a593Smuzhiyun  *
6878*4882a593Smuzhiyun  * p2p, rsdb, and no mbss:
6879*4882a593Smuzhiyun  *	#STA <= 1, #P2P-DEV <= 1, #{P2P-CL, P2P-GO} <= 2, AP <= 2,
6880*4882a593Smuzhiyun  *	 channels = 2, 4 total
6881*4882a593Smuzhiyun  */
brcmf_setup_ifmodes(struct wiphy * wiphy,struct brcmf_if * ifp)6882*4882a593Smuzhiyun static int brcmf_setup_ifmodes(struct wiphy *wiphy, struct brcmf_if *ifp)
6883*4882a593Smuzhiyun {
6884*4882a593Smuzhiyun 	struct ieee80211_iface_combination *combo = NULL;
6885*4882a593Smuzhiyun 	struct ieee80211_iface_limit *c0_limits = NULL;
6886*4882a593Smuzhiyun 	struct ieee80211_iface_limit *p2p_limits = NULL;
6887*4882a593Smuzhiyun 	struct ieee80211_iface_limit *mbss_limits = NULL;
6888*4882a593Smuzhiyun 	bool mon_flag, mbss, p2p, rsdb, mchan;
6889*4882a593Smuzhiyun 	int i, c, n_combos, n_limits;
6890*4882a593Smuzhiyun 
6891*4882a593Smuzhiyun 	mon_flag = brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MONITOR_FLAG);
6892*4882a593Smuzhiyun 	mbss = brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MBSS);
6893*4882a593Smuzhiyun 	p2p = brcmf_feat_is_enabled(ifp, BRCMF_FEAT_P2P);
6894*4882a593Smuzhiyun 	rsdb = brcmf_feat_is_enabled(ifp, BRCMF_FEAT_RSDB);
6895*4882a593Smuzhiyun 	mchan = brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MCHAN);
6896*4882a593Smuzhiyun 
6897*4882a593Smuzhiyun 	n_combos = 1 + !!(p2p && !rsdb) + !!mbss;
6898*4882a593Smuzhiyun 	combo = kcalloc(n_combos, sizeof(*combo), GFP_KERNEL);
6899*4882a593Smuzhiyun 	if (!combo)
6900*4882a593Smuzhiyun 		goto err;
6901*4882a593Smuzhiyun 
6902*4882a593Smuzhiyun 	wiphy->interface_modes = BIT(NL80211_IFTYPE_STATION) |
6903*4882a593Smuzhiyun 				 BIT(NL80211_IFTYPE_ADHOC) |
6904*4882a593Smuzhiyun 				 BIT(NL80211_IFTYPE_AP);
6905*4882a593Smuzhiyun 	if (mon_flag)
6906*4882a593Smuzhiyun 		wiphy->interface_modes |= BIT(NL80211_IFTYPE_MONITOR);
6907*4882a593Smuzhiyun 	if (p2p)
6908*4882a593Smuzhiyun 		wiphy->interface_modes |= BIT(NL80211_IFTYPE_P2P_CLIENT) |
6909*4882a593Smuzhiyun 					  BIT(NL80211_IFTYPE_P2P_GO) |
6910*4882a593Smuzhiyun 					  BIT(NL80211_IFTYPE_P2P_DEVICE);
6911*4882a593Smuzhiyun 
6912*4882a593Smuzhiyun 	c = 0;
6913*4882a593Smuzhiyun 	i = 0;
6914*4882a593Smuzhiyun 	n_limits = 1 + mon_flag + (p2p ? 2 : 0) + (rsdb || !p2p);
6915*4882a593Smuzhiyun 	c0_limits = kcalloc(n_limits, sizeof(*c0_limits), GFP_KERNEL);
6916*4882a593Smuzhiyun 	if (!c0_limits)
6917*4882a593Smuzhiyun 		goto err;
6918*4882a593Smuzhiyun 
6919*4882a593Smuzhiyun 	combo[c].num_different_channels = 1 + (rsdb || (p2p && mchan));
6920*4882a593Smuzhiyun 	c0_limits[i].max = 1;
6921*4882a593Smuzhiyun 	c0_limits[i++].types = BIT(NL80211_IFTYPE_STATION);
6922*4882a593Smuzhiyun 	if (mon_flag) {
6923*4882a593Smuzhiyun 		c0_limits[i].max = 1;
6924*4882a593Smuzhiyun 		c0_limits[i++].types = BIT(NL80211_IFTYPE_MONITOR);
6925*4882a593Smuzhiyun 	}
6926*4882a593Smuzhiyun 	if (p2p) {
6927*4882a593Smuzhiyun 		c0_limits[i].max = 1;
6928*4882a593Smuzhiyun 		c0_limits[i++].types = BIT(NL80211_IFTYPE_P2P_DEVICE);
6929*4882a593Smuzhiyun 		c0_limits[i].max = 1 + rsdb;
6930*4882a593Smuzhiyun 		c0_limits[i++].types = BIT(NL80211_IFTYPE_P2P_CLIENT) |
6931*4882a593Smuzhiyun 				       BIT(NL80211_IFTYPE_P2P_GO);
6932*4882a593Smuzhiyun 	}
6933*4882a593Smuzhiyun 	if (p2p && rsdb) {
6934*4882a593Smuzhiyun 		c0_limits[i].max = 2;
6935*4882a593Smuzhiyun 		c0_limits[i++].types = BIT(NL80211_IFTYPE_AP);
6936*4882a593Smuzhiyun 		combo[c].max_interfaces = 4;
6937*4882a593Smuzhiyun 	} else if (p2p) {
6938*4882a593Smuzhiyun 		combo[c].max_interfaces = i;
6939*4882a593Smuzhiyun 	} else if (rsdb) {
6940*4882a593Smuzhiyun 		c0_limits[i].max = 2;
6941*4882a593Smuzhiyun 		c0_limits[i++].types = BIT(NL80211_IFTYPE_AP);
6942*4882a593Smuzhiyun 		combo[c].max_interfaces = 3;
6943*4882a593Smuzhiyun 	} else {
6944*4882a593Smuzhiyun 		c0_limits[i].max = 1;
6945*4882a593Smuzhiyun 		c0_limits[i++].types = BIT(NL80211_IFTYPE_AP);
6946*4882a593Smuzhiyun 		combo[c].max_interfaces = i;
6947*4882a593Smuzhiyun 	}
6948*4882a593Smuzhiyun 	combo[c].n_limits = i;
6949*4882a593Smuzhiyun 	combo[c].limits = c0_limits;
6950*4882a593Smuzhiyun 
6951*4882a593Smuzhiyun 	if (p2p && !rsdb) {
6952*4882a593Smuzhiyun 		c++;
6953*4882a593Smuzhiyun 		i = 0;
6954*4882a593Smuzhiyun 		p2p_limits = kcalloc(4, sizeof(*p2p_limits), GFP_KERNEL);
6955*4882a593Smuzhiyun 		if (!p2p_limits)
6956*4882a593Smuzhiyun 			goto err;
6957*4882a593Smuzhiyun 		p2p_limits[i].max = 1;
6958*4882a593Smuzhiyun 		p2p_limits[i++].types = BIT(NL80211_IFTYPE_STATION);
6959*4882a593Smuzhiyun 		p2p_limits[i].max = 1;
6960*4882a593Smuzhiyun 		p2p_limits[i++].types = BIT(NL80211_IFTYPE_AP);
6961*4882a593Smuzhiyun 		p2p_limits[i].max = 1;
6962*4882a593Smuzhiyun 		p2p_limits[i++].types = BIT(NL80211_IFTYPE_P2P_CLIENT);
6963*4882a593Smuzhiyun 		p2p_limits[i].max = 1;
6964*4882a593Smuzhiyun 		p2p_limits[i++].types = BIT(NL80211_IFTYPE_P2P_DEVICE);
6965*4882a593Smuzhiyun 		combo[c].num_different_channels = 1;
6966*4882a593Smuzhiyun 		combo[c].max_interfaces = i;
6967*4882a593Smuzhiyun 		combo[c].n_limits = i;
6968*4882a593Smuzhiyun 		combo[c].limits = p2p_limits;
6969*4882a593Smuzhiyun 	}
6970*4882a593Smuzhiyun 
6971*4882a593Smuzhiyun 	if (mbss) {
6972*4882a593Smuzhiyun 		c++;
6973*4882a593Smuzhiyun 		i = 0;
6974*4882a593Smuzhiyun 		n_limits = 1 + mon_flag;
6975*4882a593Smuzhiyun 		mbss_limits = kcalloc(n_limits, sizeof(*mbss_limits),
6976*4882a593Smuzhiyun 				      GFP_KERNEL);
6977*4882a593Smuzhiyun 		if (!mbss_limits)
6978*4882a593Smuzhiyun 			goto err;
6979*4882a593Smuzhiyun 		mbss_limits[i].max = 4;
6980*4882a593Smuzhiyun 		mbss_limits[i++].types = BIT(NL80211_IFTYPE_AP);
6981*4882a593Smuzhiyun 		if (mon_flag) {
6982*4882a593Smuzhiyun 			mbss_limits[i].max = 1;
6983*4882a593Smuzhiyun 			mbss_limits[i++].types = BIT(NL80211_IFTYPE_MONITOR);
6984*4882a593Smuzhiyun 		}
6985*4882a593Smuzhiyun 		combo[c].beacon_int_infra_match = true;
6986*4882a593Smuzhiyun 		combo[c].num_different_channels = 1;
6987*4882a593Smuzhiyun 		combo[c].max_interfaces = 4 + mon_flag;
6988*4882a593Smuzhiyun 		combo[c].n_limits = i;
6989*4882a593Smuzhiyun 		combo[c].limits = mbss_limits;
6990*4882a593Smuzhiyun 	}
6991*4882a593Smuzhiyun 
6992*4882a593Smuzhiyun 	wiphy->n_iface_combinations = n_combos;
6993*4882a593Smuzhiyun 	wiphy->iface_combinations = combo;
6994*4882a593Smuzhiyun 	return 0;
6995*4882a593Smuzhiyun 
6996*4882a593Smuzhiyun err:
6997*4882a593Smuzhiyun 	kfree(c0_limits);
6998*4882a593Smuzhiyun 	kfree(p2p_limits);
6999*4882a593Smuzhiyun 	kfree(mbss_limits);
7000*4882a593Smuzhiyun 	kfree(combo);
7001*4882a593Smuzhiyun 	return -ENOMEM;
7002*4882a593Smuzhiyun }
7003*4882a593Smuzhiyun 
7004*4882a593Smuzhiyun #ifdef CONFIG_PM
7005*4882a593Smuzhiyun static const struct wiphy_wowlan_support brcmf_wowlan_support = {
7006*4882a593Smuzhiyun 	.flags = WIPHY_WOWLAN_MAGIC_PKT | WIPHY_WOWLAN_DISCONNECT,
7007*4882a593Smuzhiyun 	.n_patterns = BRCMF_WOWL_MAXPATTERNS,
7008*4882a593Smuzhiyun 	.pattern_max_len = BRCMF_WOWL_MAXPATTERNSIZE,
7009*4882a593Smuzhiyun 	.pattern_min_len = 1,
7010*4882a593Smuzhiyun 	.max_pkt_offset = 1500,
7011*4882a593Smuzhiyun };
7012*4882a593Smuzhiyun #endif
7013*4882a593Smuzhiyun 
brcmf_wiphy_wowl_params(struct wiphy * wiphy,struct brcmf_if * ifp)7014*4882a593Smuzhiyun static void brcmf_wiphy_wowl_params(struct wiphy *wiphy, struct brcmf_if *ifp)
7015*4882a593Smuzhiyun {
7016*4882a593Smuzhiyun #ifdef CONFIG_PM
7017*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
7018*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
7019*4882a593Smuzhiyun 	struct wiphy_wowlan_support *wowl;
7020*4882a593Smuzhiyun 
7021*4882a593Smuzhiyun 	wowl = kmemdup(&brcmf_wowlan_support, sizeof(brcmf_wowlan_support),
7022*4882a593Smuzhiyun 		       GFP_KERNEL);
7023*4882a593Smuzhiyun 	if (!wowl) {
7024*4882a593Smuzhiyun 		bphy_err(drvr, "only support basic wowlan features\n");
7025*4882a593Smuzhiyun 		wiphy->wowlan = &brcmf_wowlan_support;
7026*4882a593Smuzhiyun 		return;
7027*4882a593Smuzhiyun 	}
7028*4882a593Smuzhiyun 
7029*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_PNO)) {
7030*4882a593Smuzhiyun 		if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_WOWL_ND)) {
7031*4882a593Smuzhiyun 			wowl->flags |= WIPHY_WOWLAN_NET_DETECT;
7032*4882a593Smuzhiyun 			wowl->max_nd_match_sets = BRCMF_PNO_MAX_PFN_COUNT;
7033*4882a593Smuzhiyun 			init_waitqueue_head(&cfg->wowl.nd_data_wait);
7034*4882a593Smuzhiyun 		}
7035*4882a593Smuzhiyun 	}
7036*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_WOWL_GTK)) {
7037*4882a593Smuzhiyun 		wowl->flags |= WIPHY_WOWLAN_SUPPORTS_GTK_REKEY;
7038*4882a593Smuzhiyun 		wowl->flags |= WIPHY_WOWLAN_GTK_REKEY_FAILURE;
7039*4882a593Smuzhiyun 	}
7040*4882a593Smuzhiyun 
7041*4882a593Smuzhiyun 	wiphy->wowlan = wowl;
7042*4882a593Smuzhiyun #endif
7043*4882a593Smuzhiyun }
7044*4882a593Smuzhiyun 
brcmf_setup_wiphy(struct wiphy * wiphy,struct brcmf_if * ifp)7045*4882a593Smuzhiyun static int brcmf_setup_wiphy(struct wiphy *wiphy, struct brcmf_if *ifp)
7046*4882a593Smuzhiyun {
7047*4882a593Smuzhiyun 	struct brcmf_pub *drvr = ifp->drvr;
7048*4882a593Smuzhiyun 	const struct ieee80211_iface_combination *combo;
7049*4882a593Smuzhiyun 	struct ieee80211_supported_band *band;
7050*4882a593Smuzhiyun 	u16 max_interfaces = 0;
7051*4882a593Smuzhiyun 	bool gscan;
7052*4882a593Smuzhiyun 	__le32 bandlist[3];
7053*4882a593Smuzhiyun 	u32 n_bands;
7054*4882a593Smuzhiyun 	int err, i;
7055*4882a593Smuzhiyun 
7056*4882a593Smuzhiyun 	wiphy->max_scan_ssids = WL_NUM_SCAN_MAX;
7057*4882a593Smuzhiyun 	wiphy->max_scan_ie_len = BRCMF_SCAN_IE_LEN_MAX;
7058*4882a593Smuzhiyun 	wiphy->max_num_pmkids = BRCMF_MAXPMKID;
7059*4882a593Smuzhiyun 
7060*4882a593Smuzhiyun 	err = brcmf_setup_ifmodes(wiphy, ifp);
7061*4882a593Smuzhiyun 	if (err)
7062*4882a593Smuzhiyun 		return err;
7063*4882a593Smuzhiyun 
7064*4882a593Smuzhiyun 	for (i = 0, combo = wiphy->iface_combinations;
7065*4882a593Smuzhiyun 	     i < wiphy->n_iface_combinations; i++, combo++) {
7066*4882a593Smuzhiyun 		max_interfaces = max(max_interfaces, combo->max_interfaces);
7067*4882a593Smuzhiyun 	}
7068*4882a593Smuzhiyun 
7069*4882a593Smuzhiyun 	for (i = 0; i < max_interfaces && i < ARRAY_SIZE(drvr->addresses);
7070*4882a593Smuzhiyun 	     i++) {
7071*4882a593Smuzhiyun 		u8 *addr = drvr->addresses[i].addr;
7072*4882a593Smuzhiyun 
7073*4882a593Smuzhiyun 		memcpy(addr, drvr->mac, ETH_ALEN);
7074*4882a593Smuzhiyun 		if (i) {
7075*4882a593Smuzhiyun 			addr[0] |= BIT(1);
7076*4882a593Smuzhiyun 			addr[ETH_ALEN - 1] ^= i;
7077*4882a593Smuzhiyun 		}
7078*4882a593Smuzhiyun 	}
7079*4882a593Smuzhiyun 	wiphy->addresses = drvr->addresses;
7080*4882a593Smuzhiyun 	wiphy->n_addresses = i;
7081*4882a593Smuzhiyun 
7082*4882a593Smuzhiyun 	wiphy->signal_type = CFG80211_SIGNAL_TYPE_MBM;
7083*4882a593Smuzhiyun 	wiphy->cipher_suites = brcmf_cipher_suites;
7084*4882a593Smuzhiyun 	wiphy->n_cipher_suites = ARRAY_SIZE(brcmf_cipher_suites);
7085*4882a593Smuzhiyun 	if (!brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MFP))
7086*4882a593Smuzhiyun 		wiphy->n_cipher_suites--;
7087*4882a593Smuzhiyun 	wiphy->bss_select_support = BIT(NL80211_BSS_SELECT_ATTR_RSSI) |
7088*4882a593Smuzhiyun 				    BIT(NL80211_BSS_SELECT_ATTR_BAND_PREF) |
7089*4882a593Smuzhiyun 				    BIT(NL80211_BSS_SELECT_ATTR_RSSI_ADJUST);
7090*4882a593Smuzhiyun 
7091*4882a593Smuzhiyun 	wiphy->flags |= WIPHY_FLAG_NETNS_OK |
7092*4882a593Smuzhiyun 			WIPHY_FLAG_PS_ON_BY_DEFAULT |
7093*4882a593Smuzhiyun 			WIPHY_FLAG_HAVE_AP_SME |
7094*4882a593Smuzhiyun 			WIPHY_FLAG_OFFCHAN_TX |
7095*4882a593Smuzhiyun 			WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL;
7096*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_TDLS))
7097*4882a593Smuzhiyun 		wiphy->flags |= WIPHY_FLAG_SUPPORTS_TDLS;
7098*4882a593Smuzhiyun 	if (!ifp->drvr->settings->roamoff)
7099*4882a593Smuzhiyun 		wiphy->flags |= WIPHY_FLAG_SUPPORTS_FW_ROAM;
7100*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_FWSUP)) {
7101*4882a593Smuzhiyun 		wiphy_ext_feature_set(wiphy,
7102*4882a593Smuzhiyun 				      NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_PSK);
7103*4882a593Smuzhiyun 		wiphy_ext_feature_set(wiphy,
7104*4882a593Smuzhiyun 				      NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X);
7105*4882a593Smuzhiyun 		if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_SAE))
7106*4882a593Smuzhiyun 			wiphy_ext_feature_set(wiphy,
7107*4882a593Smuzhiyun 					      NL80211_EXT_FEATURE_SAE_OFFLOAD);
7108*4882a593Smuzhiyun 	}
7109*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_FWAUTH)) {
7110*4882a593Smuzhiyun 		wiphy_ext_feature_set(wiphy,
7111*4882a593Smuzhiyun 				      NL80211_EXT_FEATURE_4WAY_HANDSHAKE_AP_PSK);
7112*4882a593Smuzhiyun 		if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_SAE))
7113*4882a593Smuzhiyun 			wiphy_ext_feature_set(wiphy,
7114*4882a593Smuzhiyun 					      NL80211_EXT_FEATURE_SAE_OFFLOAD_AP);
7115*4882a593Smuzhiyun 	}
7116*4882a593Smuzhiyun 	wiphy->mgmt_stypes = brcmf_txrx_stypes;
7117*4882a593Smuzhiyun 	wiphy->max_remain_on_channel_duration = 5000;
7118*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_PNO)) {
7119*4882a593Smuzhiyun 		gscan = brcmf_feat_is_enabled(ifp, BRCMF_FEAT_GSCAN);
7120*4882a593Smuzhiyun 		brcmf_pno_wiphy_params(wiphy, gscan);
7121*4882a593Smuzhiyun 	}
7122*4882a593Smuzhiyun 	/* vendor commands/events support */
7123*4882a593Smuzhiyun 	wiphy->vendor_commands = brcmf_vendor_cmds;
7124*4882a593Smuzhiyun 	wiphy->n_vendor_commands = BRCMF_VNDR_CMDS_LAST - 1;
7125*4882a593Smuzhiyun 
7126*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_WOWL))
7127*4882a593Smuzhiyun 		brcmf_wiphy_wowl_params(wiphy, ifp);
7128*4882a593Smuzhiyun 	err = brcmf_fil_cmd_data_get(ifp, BRCMF_C_GET_BANDLIST, &bandlist,
7129*4882a593Smuzhiyun 				     sizeof(bandlist));
7130*4882a593Smuzhiyun 	if (err) {
7131*4882a593Smuzhiyun 		bphy_err(drvr, "could not obtain band info: err=%d\n", err);
7132*4882a593Smuzhiyun 		return err;
7133*4882a593Smuzhiyun 	}
7134*4882a593Smuzhiyun 	/* first entry in bandlist is number of bands */
7135*4882a593Smuzhiyun 	n_bands = le32_to_cpu(bandlist[0]);
7136*4882a593Smuzhiyun 	for (i = 1; i <= n_bands && i < ARRAY_SIZE(bandlist); i++) {
7137*4882a593Smuzhiyun 		if (bandlist[i] == cpu_to_le32(WLC_BAND_2G)) {
7138*4882a593Smuzhiyun 			band = kmemdup(&__wl_band_2ghz, sizeof(__wl_band_2ghz),
7139*4882a593Smuzhiyun 				       GFP_KERNEL);
7140*4882a593Smuzhiyun 			if (!band)
7141*4882a593Smuzhiyun 				return -ENOMEM;
7142*4882a593Smuzhiyun 
7143*4882a593Smuzhiyun 			band->channels = kmemdup(&__wl_2ghz_channels,
7144*4882a593Smuzhiyun 						 sizeof(__wl_2ghz_channels),
7145*4882a593Smuzhiyun 						 GFP_KERNEL);
7146*4882a593Smuzhiyun 			if (!band->channels) {
7147*4882a593Smuzhiyun 				kfree(band);
7148*4882a593Smuzhiyun 				return -ENOMEM;
7149*4882a593Smuzhiyun 			}
7150*4882a593Smuzhiyun 
7151*4882a593Smuzhiyun 			band->n_channels = ARRAY_SIZE(__wl_2ghz_channels);
7152*4882a593Smuzhiyun 			wiphy->bands[NL80211_BAND_2GHZ] = band;
7153*4882a593Smuzhiyun 		}
7154*4882a593Smuzhiyun 		if (bandlist[i] == cpu_to_le32(WLC_BAND_5G)) {
7155*4882a593Smuzhiyun 			band = kmemdup(&__wl_band_5ghz, sizeof(__wl_band_5ghz),
7156*4882a593Smuzhiyun 				       GFP_KERNEL);
7157*4882a593Smuzhiyun 			if (!band)
7158*4882a593Smuzhiyun 				return -ENOMEM;
7159*4882a593Smuzhiyun 
7160*4882a593Smuzhiyun 			band->channels = kmemdup(&__wl_5ghz_channels,
7161*4882a593Smuzhiyun 						 sizeof(__wl_5ghz_channels),
7162*4882a593Smuzhiyun 						 GFP_KERNEL);
7163*4882a593Smuzhiyun 			if (!band->channels) {
7164*4882a593Smuzhiyun 				kfree(band);
7165*4882a593Smuzhiyun 				return -ENOMEM;
7166*4882a593Smuzhiyun 			}
7167*4882a593Smuzhiyun 
7168*4882a593Smuzhiyun 			band->n_channels = ARRAY_SIZE(__wl_5ghz_channels);
7169*4882a593Smuzhiyun 			wiphy->bands[NL80211_BAND_5GHZ] = band;
7170*4882a593Smuzhiyun 		}
7171*4882a593Smuzhiyun 	}
7172*4882a593Smuzhiyun 
7173*4882a593Smuzhiyun 	if (wiphy->bands[NL80211_BAND_5GHZ] &&
7174*4882a593Smuzhiyun 	    brcmf_feat_is_enabled(ifp, BRCMF_FEAT_DOT11H))
7175*4882a593Smuzhiyun 		wiphy_ext_feature_set(wiphy,
7176*4882a593Smuzhiyun 				      NL80211_EXT_FEATURE_DFS_OFFLOAD);
7177*4882a593Smuzhiyun 
7178*4882a593Smuzhiyun 	wiphy_read_of_freq_limits(wiphy);
7179*4882a593Smuzhiyun 
7180*4882a593Smuzhiyun 	return 0;
7181*4882a593Smuzhiyun }
7182*4882a593Smuzhiyun 
brcmf_config_dongle(struct brcmf_cfg80211_info * cfg)7183*4882a593Smuzhiyun static s32 brcmf_config_dongle(struct brcmf_cfg80211_info *cfg)
7184*4882a593Smuzhiyun {
7185*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
7186*4882a593Smuzhiyun 	struct net_device *ndev;
7187*4882a593Smuzhiyun 	struct wireless_dev *wdev;
7188*4882a593Smuzhiyun 	struct brcmf_if *ifp;
7189*4882a593Smuzhiyun 	s32 power_mode;
7190*4882a593Smuzhiyun 	s32 err = 0;
7191*4882a593Smuzhiyun 
7192*4882a593Smuzhiyun 	if (cfg->dongle_up)
7193*4882a593Smuzhiyun 		return err;
7194*4882a593Smuzhiyun 
7195*4882a593Smuzhiyun 	ndev = cfg_to_ndev(cfg);
7196*4882a593Smuzhiyun 	wdev = ndev->ieee80211_ptr;
7197*4882a593Smuzhiyun 	ifp = netdev_priv(ndev);
7198*4882a593Smuzhiyun 
7199*4882a593Smuzhiyun 	/* make sure RF is ready for work */
7200*4882a593Smuzhiyun 	brcmf_fil_cmd_int_set(ifp, BRCMF_C_UP, 0);
7201*4882a593Smuzhiyun 
7202*4882a593Smuzhiyun 	brcmf_dongle_scantime(ifp);
7203*4882a593Smuzhiyun 
7204*4882a593Smuzhiyun 	power_mode = cfg->pwr_save ? PM_FAST : PM_OFF;
7205*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_PM, power_mode);
7206*4882a593Smuzhiyun 	if (err)
7207*4882a593Smuzhiyun 		goto default_conf_out;
7208*4882a593Smuzhiyun 	brcmf_dbg(INFO, "power save set to %s\n",
7209*4882a593Smuzhiyun 		  (power_mode ? "enabled" : "disabled"));
7210*4882a593Smuzhiyun 
7211*4882a593Smuzhiyun 	err = brcmf_dongle_roam(ifp);
7212*4882a593Smuzhiyun 	if (err)
7213*4882a593Smuzhiyun 		goto default_conf_out;
7214*4882a593Smuzhiyun 	err = brcmf_cfg80211_change_iface(wdev->wiphy, ndev, wdev->iftype,
7215*4882a593Smuzhiyun 					  NULL);
7216*4882a593Smuzhiyun 	if (err)
7217*4882a593Smuzhiyun 		goto default_conf_out;
7218*4882a593Smuzhiyun 
7219*4882a593Smuzhiyun 	brcmf_configure_arp_nd_offload(ifp, true);
7220*4882a593Smuzhiyun 
7221*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_set(ifp, BRCMF_C_SET_FAKEFRAG, 1);
7222*4882a593Smuzhiyun 	if (err) {
7223*4882a593Smuzhiyun 		bphy_err(drvr, "failed to set frameburst mode\n");
7224*4882a593Smuzhiyun 		goto default_conf_out;
7225*4882a593Smuzhiyun 	}
7226*4882a593Smuzhiyun 
7227*4882a593Smuzhiyun 	cfg->dongle_up = true;
7228*4882a593Smuzhiyun default_conf_out:
7229*4882a593Smuzhiyun 
7230*4882a593Smuzhiyun 	return err;
7231*4882a593Smuzhiyun 
7232*4882a593Smuzhiyun }
7233*4882a593Smuzhiyun 
__brcmf_cfg80211_up(struct brcmf_if * ifp)7234*4882a593Smuzhiyun static s32 __brcmf_cfg80211_up(struct brcmf_if *ifp)
7235*4882a593Smuzhiyun {
7236*4882a593Smuzhiyun 	set_bit(BRCMF_VIF_STATUS_READY, &ifp->vif->sme_state);
7237*4882a593Smuzhiyun 
7238*4882a593Smuzhiyun 	return brcmf_config_dongle(ifp->drvr->config);
7239*4882a593Smuzhiyun }
7240*4882a593Smuzhiyun 
__brcmf_cfg80211_down(struct brcmf_if * ifp)7241*4882a593Smuzhiyun static s32 __brcmf_cfg80211_down(struct brcmf_if *ifp)
7242*4882a593Smuzhiyun {
7243*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = ifp->drvr->config;
7244*4882a593Smuzhiyun 
7245*4882a593Smuzhiyun 	/*
7246*4882a593Smuzhiyun 	 * While going down, if associated with AP disassociate
7247*4882a593Smuzhiyun 	 * from AP to save power
7248*4882a593Smuzhiyun 	 */
7249*4882a593Smuzhiyun 	if (check_vif_up(ifp->vif)) {
7250*4882a593Smuzhiyun 		brcmf_link_down(ifp->vif, WLAN_REASON_UNSPECIFIED, true);
7251*4882a593Smuzhiyun 
7252*4882a593Smuzhiyun 		/* Make sure WPA_Supplicant receives all the event
7253*4882a593Smuzhiyun 		   generated due to DISASSOC call to the fw to keep
7254*4882a593Smuzhiyun 		   the state fw and WPA_Supplicant state consistent
7255*4882a593Smuzhiyun 		 */
7256*4882a593Smuzhiyun 		brcmf_delay(500);
7257*4882a593Smuzhiyun 	}
7258*4882a593Smuzhiyun 
7259*4882a593Smuzhiyun 	brcmf_abort_scanning(cfg);
7260*4882a593Smuzhiyun 	clear_bit(BRCMF_VIF_STATUS_READY, &ifp->vif->sme_state);
7261*4882a593Smuzhiyun 
7262*4882a593Smuzhiyun 	return 0;
7263*4882a593Smuzhiyun }
7264*4882a593Smuzhiyun 
brcmf_cfg80211_up(struct net_device * ndev)7265*4882a593Smuzhiyun s32 brcmf_cfg80211_up(struct net_device *ndev)
7266*4882a593Smuzhiyun {
7267*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
7268*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = ifp->drvr->config;
7269*4882a593Smuzhiyun 	s32 err = 0;
7270*4882a593Smuzhiyun 
7271*4882a593Smuzhiyun 	mutex_lock(&cfg->usr_sync);
7272*4882a593Smuzhiyun 	err = __brcmf_cfg80211_up(ifp);
7273*4882a593Smuzhiyun 	mutex_unlock(&cfg->usr_sync);
7274*4882a593Smuzhiyun 
7275*4882a593Smuzhiyun 	return err;
7276*4882a593Smuzhiyun }
7277*4882a593Smuzhiyun 
brcmf_cfg80211_down(struct net_device * ndev)7278*4882a593Smuzhiyun s32 brcmf_cfg80211_down(struct net_device *ndev)
7279*4882a593Smuzhiyun {
7280*4882a593Smuzhiyun 	struct brcmf_if *ifp = netdev_priv(ndev);
7281*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = ifp->drvr->config;
7282*4882a593Smuzhiyun 	s32 err = 0;
7283*4882a593Smuzhiyun 
7284*4882a593Smuzhiyun 	mutex_lock(&cfg->usr_sync);
7285*4882a593Smuzhiyun 	err = __brcmf_cfg80211_down(ifp);
7286*4882a593Smuzhiyun 	mutex_unlock(&cfg->usr_sync);
7287*4882a593Smuzhiyun 
7288*4882a593Smuzhiyun 	return err;
7289*4882a593Smuzhiyun }
7290*4882a593Smuzhiyun 
brcmf_cfg80211_get_iftype(struct brcmf_if * ifp)7291*4882a593Smuzhiyun enum nl80211_iftype brcmf_cfg80211_get_iftype(struct brcmf_if *ifp)
7292*4882a593Smuzhiyun {
7293*4882a593Smuzhiyun 	struct wireless_dev *wdev = &ifp->vif->wdev;
7294*4882a593Smuzhiyun 
7295*4882a593Smuzhiyun 	return wdev->iftype;
7296*4882a593Smuzhiyun }
7297*4882a593Smuzhiyun 
brcmf_get_vif_state_any(struct brcmf_cfg80211_info * cfg,unsigned long state)7298*4882a593Smuzhiyun bool brcmf_get_vif_state_any(struct brcmf_cfg80211_info *cfg,
7299*4882a593Smuzhiyun 			     unsigned long state)
7300*4882a593Smuzhiyun {
7301*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
7302*4882a593Smuzhiyun 
7303*4882a593Smuzhiyun 	list_for_each_entry(vif, &cfg->vif_list, list) {
7304*4882a593Smuzhiyun 		if (test_bit(state, &vif->sme_state))
7305*4882a593Smuzhiyun 			return true;
7306*4882a593Smuzhiyun 	}
7307*4882a593Smuzhiyun 	return false;
7308*4882a593Smuzhiyun }
7309*4882a593Smuzhiyun 
vif_event_equals(struct brcmf_cfg80211_vif_event * event,u8 action)7310*4882a593Smuzhiyun static inline bool vif_event_equals(struct brcmf_cfg80211_vif_event *event,
7311*4882a593Smuzhiyun 				    u8 action)
7312*4882a593Smuzhiyun {
7313*4882a593Smuzhiyun 	u8 evt_action;
7314*4882a593Smuzhiyun 
7315*4882a593Smuzhiyun 	spin_lock(&event->vif_event_lock);
7316*4882a593Smuzhiyun 	evt_action = event->action;
7317*4882a593Smuzhiyun 	spin_unlock(&event->vif_event_lock);
7318*4882a593Smuzhiyun 	return evt_action == action;
7319*4882a593Smuzhiyun }
7320*4882a593Smuzhiyun 
brcmf_cfg80211_arm_vif_event(struct brcmf_cfg80211_info * cfg,struct brcmf_cfg80211_vif * vif)7321*4882a593Smuzhiyun void brcmf_cfg80211_arm_vif_event(struct brcmf_cfg80211_info *cfg,
7322*4882a593Smuzhiyun 				  struct brcmf_cfg80211_vif *vif)
7323*4882a593Smuzhiyun {
7324*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif_event *event = &cfg->vif_event;
7325*4882a593Smuzhiyun 
7326*4882a593Smuzhiyun 	spin_lock(&event->vif_event_lock);
7327*4882a593Smuzhiyun 	event->vif = vif;
7328*4882a593Smuzhiyun 	event->action = 0;
7329*4882a593Smuzhiyun 	spin_unlock(&event->vif_event_lock);
7330*4882a593Smuzhiyun }
7331*4882a593Smuzhiyun 
brcmf_cfg80211_vif_event_armed(struct brcmf_cfg80211_info * cfg)7332*4882a593Smuzhiyun bool brcmf_cfg80211_vif_event_armed(struct brcmf_cfg80211_info *cfg)
7333*4882a593Smuzhiyun {
7334*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif_event *event = &cfg->vif_event;
7335*4882a593Smuzhiyun 	bool armed;
7336*4882a593Smuzhiyun 
7337*4882a593Smuzhiyun 	spin_lock(&event->vif_event_lock);
7338*4882a593Smuzhiyun 	armed = event->vif != NULL;
7339*4882a593Smuzhiyun 	spin_unlock(&event->vif_event_lock);
7340*4882a593Smuzhiyun 
7341*4882a593Smuzhiyun 	return armed;
7342*4882a593Smuzhiyun }
7343*4882a593Smuzhiyun 
brcmf_cfg80211_wait_vif_event(struct brcmf_cfg80211_info * cfg,u8 action,ulong timeout)7344*4882a593Smuzhiyun int brcmf_cfg80211_wait_vif_event(struct brcmf_cfg80211_info *cfg,
7345*4882a593Smuzhiyun 				  u8 action, ulong timeout)
7346*4882a593Smuzhiyun {
7347*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif_event *event = &cfg->vif_event;
7348*4882a593Smuzhiyun 
7349*4882a593Smuzhiyun 	return wait_event_timeout(event->vif_wq,
7350*4882a593Smuzhiyun 				  vif_event_equals(event, action), timeout);
7351*4882a593Smuzhiyun }
7352*4882a593Smuzhiyun 
brcmf_translate_country_code(struct brcmf_pub * drvr,char alpha2[2],struct brcmf_fil_country_le * ccreq)7353*4882a593Smuzhiyun static s32 brcmf_translate_country_code(struct brcmf_pub *drvr, char alpha2[2],
7354*4882a593Smuzhiyun 					struct brcmf_fil_country_le *ccreq)
7355*4882a593Smuzhiyun {
7356*4882a593Smuzhiyun 	struct brcmfmac_pd_cc *country_codes;
7357*4882a593Smuzhiyun 	struct brcmfmac_pd_cc_entry *cc;
7358*4882a593Smuzhiyun 	s32 found_index;
7359*4882a593Smuzhiyun 	int i;
7360*4882a593Smuzhiyun 
7361*4882a593Smuzhiyun 	country_codes = drvr->settings->country_codes;
7362*4882a593Smuzhiyun 	if (!country_codes) {
7363*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "No country codes configured for device\n");
7364*4882a593Smuzhiyun 		return -EINVAL;
7365*4882a593Smuzhiyun 	}
7366*4882a593Smuzhiyun 
7367*4882a593Smuzhiyun 	if ((alpha2[0] == ccreq->country_abbrev[0]) &&
7368*4882a593Smuzhiyun 	    (alpha2[1] == ccreq->country_abbrev[1])) {
7369*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "Country code already set\n");
7370*4882a593Smuzhiyun 		return -EAGAIN;
7371*4882a593Smuzhiyun 	}
7372*4882a593Smuzhiyun 
7373*4882a593Smuzhiyun 	found_index = -1;
7374*4882a593Smuzhiyun 	for (i = 0; i < country_codes->table_size; i++) {
7375*4882a593Smuzhiyun 		cc = &country_codes->table[i];
7376*4882a593Smuzhiyun 		if ((cc->iso3166[0] == '\0') && (found_index == -1))
7377*4882a593Smuzhiyun 			found_index = i;
7378*4882a593Smuzhiyun 		if ((cc->iso3166[0] == alpha2[0]) &&
7379*4882a593Smuzhiyun 		    (cc->iso3166[1] == alpha2[1])) {
7380*4882a593Smuzhiyun 			found_index = i;
7381*4882a593Smuzhiyun 			break;
7382*4882a593Smuzhiyun 		}
7383*4882a593Smuzhiyun 	}
7384*4882a593Smuzhiyun 	if (found_index == -1) {
7385*4882a593Smuzhiyun 		brcmf_dbg(TRACE, "No country code match found\n");
7386*4882a593Smuzhiyun 		return -EINVAL;
7387*4882a593Smuzhiyun 	}
7388*4882a593Smuzhiyun 	memset(ccreq, 0, sizeof(*ccreq));
7389*4882a593Smuzhiyun 	ccreq->rev = cpu_to_le32(country_codes->table[found_index].rev);
7390*4882a593Smuzhiyun 	memcpy(ccreq->ccode, country_codes->table[found_index].cc,
7391*4882a593Smuzhiyun 	       BRCMF_COUNTRY_BUF_SZ);
7392*4882a593Smuzhiyun 	ccreq->country_abbrev[0] = alpha2[0];
7393*4882a593Smuzhiyun 	ccreq->country_abbrev[1] = alpha2[1];
7394*4882a593Smuzhiyun 	ccreq->country_abbrev[2] = 0;
7395*4882a593Smuzhiyun 
7396*4882a593Smuzhiyun 	return 0;
7397*4882a593Smuzhiyun }
7398*4882a593Smuzhiyun 
brcmf_cfg80211_reg_notifier(struct wiphy * wiphy,struct regulatory_request * req)7399*4882a593Smuzhiyun static void brcmf_cfg80211_reg_notifier(struct wiphy *wiphy,
7400*4882a593Smuzhiyun 					struct regulatory_request *req)
7401*4882a593Smuzhiyun {
7402*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg = wiphy_to_cfg(wiphy);
7403*4882a593Smuzhiyun 	struct brcmf_if *ifp = brcmf_get_ifp(cfg->pub, 0);
7404*4882a593Smuzhiyun 	struct brcmf_pub *drvr = cfg->pub;
7405*4882a593Smuzhiyun 	struct brcmf_fil_country_le ccreq;
7406*4882a593Smuzhiyun 	s32 err;
7407*4882a593Smuzhiyun 	int i;
7408*4882a593Smuzhiyun 
7409*4882a593Smuzhiyun 	/* The country code gets set to "00" by default at boot, ignore */
7410*4882a593Smuzhiyun 	if (req->alpha2[0] == '0' && req->alpha2[1] == '0')
7411*4882a593Smuzhiyun 		return;
7412*4882a593Smuzhiyun 
7413*4882a593Smuzhiyun 	/* ignore non-ISO3166 country codes */
7414*4882a593Smuzhiyun 	for (i = 0; i < 2; i++)
7415*4882a593Smuzhiyun 		if (req->alpha2[i] < 'A' || req->alpha2[i] > 'Z') {
7416*4882a593Smuzhiyun 			bphy_err(drvr, "not an ISO3166 code (0x%02x 0x%02x)\n",
7417*4882a593Smuzhiyun 				 req->alpha2[0], req->alpha2[1]);
7418*4882a593Smuzhiyun 			return;
7419*4882a593Smuzhiyun 		}
7420*4882a593Smuzhiyun 
7421*4882a593Smuzhiyun 	brcmf_dbg(TRACE, "Enter: initiator=%d, alpha=%c%c\n", req->initiator,
7422*4882a593Smuzhiyun 		  req->alpha2[0], req->alpha2[1]);
7423*4882a593Smuzhiyun 
7424*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_get(ifp, "country", &ccreq, sizeof(ccreq));
7425*4882a593Smuzhiyun 	if (err) {
7426*4882a593Smuzhiyun 		bphy_err(drvr, "Country code iovar returned err = %d\n", err);
7427*4882a593Smuzhiyun 		return;
7428*4882a593Smuzhiyun 	}
7429*4882a593Smuzhiyun 
7430*4882a593Smuzhiyun 	err = brcmf_translate_country_code(ifp->drvr, req->alpha2, &ccreq);
7431*4882a593Smuzhiyun 	if (err)
7432*4882a593Smuzhiyun 		return;
7433*4882a593Smuzhiyun 
7434*4882a593Smuzhiyun 	err = brcmf_fil_iovar_data_set(ifp, "country", &ccreq, sizeof(ccreq));
7435*4882a593Smuzhiyun 	if (err) {
7436*4882a593Smuzhiyun 		bphy_err(drvr, "Firmware rejected country setting\n");
7437*4882a593Smuzhiyun 		return;
7438*4882a593Smuzhiyun 	}
7439*4882a593Smuzhiyun 	brcmf_setup_wiphybands(cfg);
7440*4882a593Smuzhiyun }
7441*4882a593Smuzhiyun 
brcmf_free_wiphy(struct wiphy * wiphy)7442*4882a593Smuzhiyun static void brcmf_free_wiphy(struct wiphy *wiphy)
7443*4882a593Smuzhiyun {
7444*4882a593Smuzhiyun 	int i;
7445*4882a593Smuzhiyun 
7446*4882a593Smuzhiyun 	if (!wiphy)
7447*4882a593Smuzhiyun 		return;
7448*4882a593Smuzhiyun 
7449*4882a593Smuzhiyun 	if (wiphy->iface_combinations) {
7450*4882a593Smuzhiyun 		for (i = 0; i < wiphy->n_iface_combinations; i++)
7451*4882a593Smuzhiyun 			kfree(wiphy->iface_combinations[i].limits);
7452*4882a593Smuzhiyun 	}
7453*4882a593Smuzhiyun 	kfree(wiphy->iface_combinations);
7454*4882a593Smuzhiyun 	if (wiphy->bands[NL80211_BAND_2GHZ]) {
7455*4882a593Smuzhiyun 		kfree(wiphy->bands[NL80211_BAND_2GHZ]->channels);
7456*4882a593Smuzhiyun 		kfree(wiphy->bands[NL80211_BAND_2GHZ]);
7457*4882a593Smuzhiyun 	}
7458*4882a593Smuzhiyun 	if (wiphy->bands[NL80211_BAND_5GHZ]) {
7459*4882a593Smuzhiyun 		kfree(wiphy->bands[NL80211_BAND_5GHZ]->channels);
7460*4882a593Smuzhiyun 		kfree(wiphy->bands[NL80211_BAND_5GHZ]);
7461*4882a593Smuzhiyun 	}
7462*4882a593Smuzhiyun #if IS_ENABLED(CONFIG_PM)
7463*4882a593Smuzhiyun 	if (wiphy->wowlan != &brcmf_wowlan_support)
7464*4882a593Smuzhiyun 		kfree(wiphy->wowlan);
7465*4882a593Smuzhiyun #endif
7466*4882a593Smuzhiyun }
7467*4882a593Smuzhiyun 
brcmf_cfg80211_attach(struct brcmf_pub * drvr,struct cfg80211_ops * ops,bool p2pdev_forced)7468*4882a593Smuzhiyun struct brcmf_cfg80211_info *brcmf_cfg80211_attach(struct brcmf_pub *drvr,
7469*4882a593Smuzhiyun 						  struct cfg80211_ops *ops,
7470*4882a593Smuzhiyun 						  bool p2pdev_forced)
7471*4882a593Smuzhiyun {
7472*4882a593Smuzhiyun 	struct wiphy *wiphy = drvr->wiphy;
7473*4882a593Smuzhiyun 	struct net_device *ndev = brcmf_get_ifp(drvr, 0)->ndev;
7474*4882a593Smuzhiyun 	struct brcmf_cfg80211_info *cfg;
7475*4882a593Smuzhiyun 	struct brcmf_cfg80211_vif *vif;
7476*4882a593Smuzhiyun 	struct brcmf_if *ifp;
7477*4882a593Smuzhiyun 	s32 err = 0;
7478*4882a593Smuzhiyun 	s32 io_type;
7479*4882a593Smuzhiyun 	u16 *cap = NULL;
7480*4882a593Smuzhiyun 
7481*4882a593Smuzhiyun 	if (!ndev) {
7482*4882a593Smuzhiyun 		bphy_err(drvr, "ndev is invalid\n");
7483*4882a593Smuzhiyun 		return NULL;
7484*4882a593Smuzhiyun 	}
7485*4882a593Smuzhiyun 
7486*4882a593Smuzhiyun 	cfg = kzalloc(sizeof(*cfg), GFP_KERNEL);
7487*4882a593Smuzhiyun 	if (!cfg) {
7488*4882a593Smuzhiyun 		bphy_err(drvr, "Could not allocate wiphy device\n");
7489*4882a593Smuzhiyun 		return NULL;
7490*4882a593Smuzhiyun 	}
7491*4882a593Smuzhiyun 
7492*4882a593Smuzhiyun 	cfg->wiphy = wiphy;
7493*4882a593Smuzhiyun 	cfg->pub = drvr;
7494*4882a593Smuzhiyun 	init_vif_event(&cfg->vif_event);
7495*4882a593Smuzhiyun 	INIT_LIST_HEAD(&cfg->vif_list);
7496*4882a593Smuzhiyun 
7497*4882a593Smuzhiyun 	vif = brcmf_alloc_vif(cfg, NL80211_IFTYPE_STATION);
7498*4882a593Smuzhiyun 	if (IS_ERR(vif))
7499*4882a593Smuzhiyun 		goto wiphy_out;
7500*4882a593Smuzhiyun 
7501*4882a593Smuzhiyun 	ifp = netdev_priv(ndev);
7502*4882a593Smuzhiyun 	vif->ifp = ifp;
7503*4882a593Smuzhiyun 	vif->wdev.netdev = ndev;
7504*4882a593Smuzhiyun 	ndev->ieee80211_ptr = &vif->wdev;
7505*4882a593Smuzhiyun 	SET_NETDEV_DEV(ndev, wiphy_dev(cfg->wiphy));
7506*4882a593Smuzhiyun 
7507*4882a593Smuzhiyun 	err = wl_init_priv(cfg);
7508*4882a593Smuzhiyun 	if (err) {
7509*4882a593Smuzhiyun 		bphy_err(drvr, "Failed to init iwm_priv (%d)\n", err);
7510*4882a593Smuzhiyun 		brcmf_free_vif(vif);
7511*4882a593Smuzhiyun 		goto wiphy_out;
7512*4882a593Smuzhiyun 	}
7513*4882a593Smuzhiyun 	ifp->vif = vif;
7514*4882a593Smuzhiyun 
7515*4882a593Smuzhiyun 	/* determine d11 io type before wiphy setup */
7516*4882a593Smuzhiyun 	err = brcmf_fil_cmd_int_get(ifp, BRCMF_C_GET_VERSION, &io_type);
7517*4882a593Smuzhiyun 	if (err) {
7518*4882a593Smuzhiyun 		bphy_err(drvr, "Failed to get D11 version (%d)\n", err);
7519*4882a593Smuzhiyun 		goto priv_out;
7520*4882a593Smuzhiyun 	}
7521*4882a593Smuzhiyun 	cfg->d11inf.io_type = (u8)io_type;
7522*4882a593Smuzhiyun 	brcmu_d11_attach(&cfg->d11inf);
7523*4882a593Smuzhiyun 
7524*4882a593Smuzhiyun 	/* regulatory notifer below needs access to cfg so
7525*4882a593Smuzhiyun 	 * assign it now.
7526*4882a593Smuzhiyun 	 */
7527*4882a593Smuzhiyun 	drvr->config = cfg;
7528*4882a593Smuzhiyun 
7529*4882a593Smuzhiyun 	err = brcmf_setup_wiphy(wiphy, ifp);
7530*4882a593Smuzhiyun 	if (err < 0)
7531*4882a593Smuzhiyun 		goto priv_out;
7532*4882a593Smuzhiyun 
7533*4882a593Smuzhiyun 	brcmf_dbg(INFO, "Registering custom regulatory\n");
7534*4882a593Smuzhiyun 	wiphy->reg_notifier = brcmf_cfg80211_reg_notifier;
7535*4882a593Smuzhiyun 	wiphy->regulatory_flags |= REGULATORY_CUSTOM_REG;
7536*4882a593Smuzhiyun 	wiphy_apply_custom_regulatory(wiphy, &brcmf_regdom);
7537*4882a593Smuzhiyun 
7538*4882a593Smuzhiyun 	/* firmware defaults to 40MHz disabled in 2G band. We signal
7539*4882a593Smuzhiyun 	 * cfg80211 here that we do and have it decide we can enable
7540*4882a593Smuzhiyun 	 * it. But first check if device does support 2G operation.
7541*4882a593Smuzhiyun 	 */
7542*4882a593Smuzhiyun 	if (wiphy->bands[NL80211_BAND_2GHZ]) {
7543*4882a593Smuzhiyun 		cap = &wiphy->bands[NL80211_BAND_2GHZ]->ht_cap.cap;
7544*4882a593Smuzhiyun 		*cap |= IEEE80211_HT_CAP_SUP_WIDTH_20_40;
7545*4882a593Smuzhiyun 	}
7546*4882a593Smuzhiyun #ifdef CONFIG_PM
7547*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_WOWL_GTK))
7548*4882a593Smuzhiyun 		ops->set_rekey_data = brcmf_cfg80211_set_rekey_data;
7549*4882a593Smuzhiyun #endif
7550*4882a593Smuzhiyun 	err = wiphy_register(wiphy);
7551*4882a593Smuzhiyun 	if (err < 0) {
7552*4882a593Smuzhiyun 		bphy_err(drvr, "Could not register wiphy device (%d)\n", err);
7553*4882a593Smuzhiyun 		goto priv_out;
7554*4882a593Smuzhiyun 	}
7555*4882a593Smuzhiyun 
7556*4882a593Smuzhiyun 	err = brcmf_setup_wiphybands(cfg);
7557*4882a593Smuzhiyun 	if (err) {
7558*4882a593Smuzhiyun 		bphy_err(drvr, "Setting wiphy bands failed (%d)\n", err);
7559*4882a593Smuzhiyun 		goto wiphy_unreg_out;
7560*4882a593Smuzhiyun 	}
7561*4882a593Smuzhiyun 
7562*4882a593Smuzhiyun 	/* If cfg80211 didn't disable 40MHz HT CAP in wiphy_register(),
7563*4882a593Smuzhiyun 	 * setup 40MHz in 2GHz band and enable OBSS scanning.
7564*4882a593Smuzhiyun 	 */
7565*4882a593Smuzhiyun 	if (cap && (*cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40)) {
7566*4882a593Smuzhiyun 		err = brcmf_enable_bw40_2g(cfg);
7567*4882a593Smuzhiyun 		if (!err)
7568*4882a593Smuzhiyun 			err = brcmf_fil_iovar_int_set(ifp, "obss_coex",
7569*4882a593Smuzhiyun 						      BRCMF_OBSS_COEX_AUTO);
7570*4882a593Smuzhiyun 		else
7571*4882a593Smuzhiyun 			*cap &= ~IEEE80211_HT_CAP_SUP_WIDTH_20_40;
7572*4882a593Smuzhiyun 	}
7573*4882a593Smuzhiyun 
7574*4882a593Smuzhiyun 	err = brcmf_fweh_activate_events(ifp);
7575*4882a593Smuzhiyun 	if (err) {
7576*4882a593Smuzhiyun 		bphy_err(drvr, "FWEH activation failed (%d)\n", err);
7577*4882a593Smuzhiyun 		goto wiphy_unreg_out;
7578*4882a593Smuzhiyun 	}
7579*4882a593Smuzhiyun 
7580*4882a593Smuzhiyun 	err = brcmf_p2p_attach(cfg, p2pdev_forced);
7581*4882a593Smuzhiyun 	if (err) {
7582*4882a593Smuzhiyun 		bphy_err(drvr, "P2P initialisation failed (%d)\n", err);
7583*4882a593Smuzhiyun 		goto wiphy_unreg_out;
7584*4882a593Smuzhiyun 	}
7585*4882a593Smuzhiyun 	err = brcmf_btcoex_attach(cfg);
7586*4882a593Smuzhiyun 	if (err) {
7587*4882a593Smuzhiyun 		bphy_err(drvr, "BT-coex initialisation failed (%d)\n", err);
7588*4882a593Smuzhiyun 		brcmf_p2p_detach(&cfg->p2p);
7589*4882a593Smuzhiyun 		goto wiphy_unreg_out;
7590*4882a593Smuzhiyun 	}
7591*4882a593Smuzhiyun 	err = brcmf_pno_attach(cfg);
7592*4882a593Smuzhiyun 	if (err) {
7593*4882a593Smuzhiyun 		bphy_err(drvr, "PNO initialisation failed (%d)\n", err);
7594*4882a593Smuzhiyun 		brcmf_btcoex_detach(cfg);
7595*4882a593Smuzhiyun 		brcmf_p2p_detach(&cfg->p2p);
7596*4882a593Smuzhiyun 		goto wiphy_unreg_out;
7597*4882a593Smuzhiyun 	}
7598*4882a593Smuzhiyun 
7599*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_TDLS)) {
7600*4882a593Smuzhiyun 		err = brcmf_fil_iovar_int_set(ifp, "tdls_enable", 1);
7601*4882a593Smuzhiyun 		if (err) {
7602*4882a593Smuzhiyun 			brcmf_dbg(INFO, "TDLS not enabled (%d)\n", err);
7603*4882a593Smuzhiyun 			wiphy->flags &= ~WIPHY_FLAG_SUPPORTS_TDLS;
7604*4882a593Smuzhiyun 		} else {
7605*4882a593Smuzhiyun 			brcmf_fweh_register(cfg->pub, BRCMF_E_TDLS_PEER_EVENT,
7606*4882a593Smuzhiyun 					    brcmf_notify_tdls_peer_event);
7607*4882a593Smuzhiyun 		}
7608*4882a593Smuzhiyun 	}
7609*4882a593Smuzhiyun 
7610*4882a593Smuzhiyun 	/* (re-) activate FWEH event handling */
7611*4882a593Smuzhiyun 	err = brcmf_fweh_activate_events(ifp);
7612*4882a593Smuzhiyun 	if (err) {
7613*4882a593Smuzhiyun 		bphy_err(drvr, "FWEH activation failed (%d)\n", err);
7614*4882a593Smuzhiyun 		goto detach;
7615*4882a593Smuzhiyun 	}
7616*4882a593Smuzhiyun 
7617*4882a593Smuzhiyun 	/* Fill in some of the advertised nl80211 supported features */
7618*4882a593Smuzhiyun 	if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_SCAN_RANDOM_MAC)) {
7619*4882a593Smuzhiyun 		wiphy->features |= NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR;
7620*4882a593Smuzhiyun #ifdef CONFIG_PM
7621*4882a593Smuzhiyun 		if (wiphy->wowlan &&
7622*4882a593Smuzhiyun 		    wiphy->wowlan->flags & WIPHY_WOWLAN_NET_DETECT)
7623*4882a593Smuzhiyun 			wiphy->features |= NL80211_FEATURE_ND_RANDOM_MAC_ADDR;
7624*4882a593Smuzhiyun #endif
7625*4882a593Smuzhiyun 	}
7626*4882a593Smuzhiyun 
7627*4882a593Smuzhiyun 	return cfg;
7628*4882a593Smuzhiyun 
7629*4882a593Smuzhiyun detach:
7630*4882a593Smuzhiyun 	brcmf_pno_detach(cfg);
7631*4882a593Smuzhiyun 	brcmf_btcoex_detach(cfg);
7632*4882a593Smuzhiyun 	brcmf_p2p_detach(&cfg->p2p);
7633*4882a593Smuzhiyun wiphy_unreg_out:
7634*4882a593Smuzhiyun 	wiphy_unregister(cfg->wiphy);
7635*4882a593Smuzhiyun priv_out:
7636*4882a593Smuzhiyun 	wl_deinit_priv(cfg);
7637*4882a593Smuzhiyun 	brcmf_free_vif(vif);
7638*4882a593Smuzhiyun 	ifp->vif = NULL;
7639*4882a593Smuzhiyun wiphy_out:
7640*4882a593Smuzhiyun 	brcmf_free_wiphy(wiphy);
7641*4882a593Smuzhiyun 	kfree(cfg);
7642*4882a593Smuzhiyun 	return NULL;
7643*4882a593Smuzhiyun }
7644*4882a593Smuzhiyun 
brcmf_cfg80211_detach(struct brcmf_cfg80211_info * cfg)7645*4882a593Smuzhiyun void brcmf_cfg80211_detach(struct brcmf_cfg80211_info *cfg)
7646*4882a593Smuzhiyun {
7647*4882a593Smuzhiyun 	if (!cfg)
7648*4882a593Smuzhiyun 		return;
7649*4882a593Smuzhiyun 
7650*4882a593Smuzhiyun 	brcmf_pno_detach(cfg);
7651*4882a593Smuzhiyun 	brcmf_btcoex_detach(cfg);
7652*4882a593Smuzhiyun 	wiphy_unregister(cfg->wiphy);
7653*4882a593Smuzhiyun 	wl_deinit_priv(cfg);
7654*4882a593Smuzhiyun 	brcmf_free_wiphy(cfg->wiphy);
7655*4882a593Smuzhiyun 	kfree(cfg);
7656*4882a593Smuzhiyun }
7657