xref: /OK3568_Linux_fs/kernel/drivers/net/wireless/rockchip_wlan/rkwifi/bcmdhd/include/802.11.h (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1 /*
2  * Fundamental types and constants relating to 802.11
3  *
4  * Copyright (C) 2020, Broadcom.
5  *
6  *      Unless you and Broadcom execute a separate written software license
7  * agreement governing use of this software, this software is licensed to you
8  * under the terms of the GNU General Public License version 2 (the "GPL"),
9  * available at http://www.broadcom.com/licenses/GPLv2.php, with the
10  * following added to such license:
11  *
12  *      As a special exception, the copyright holders of this software give you
13  * permission to link this software with independent modules, and to copy and
14  * distribute the resulting executable under terms of your choice, provided that
15  * you also meet, for each linked independent module, the terms and conditions of
16  * the license of that module.  An independent module is a module which is not
17  * derived from this software.  The special exception does not apply to any
18  * modifications of the software.
19  *
20  *
21  * <<Broadcom-WL-IPTag/Dual:>>
22  */
23 
24 #ifndef _802_11_H_
25 #define _802_11_H_
26 
27 #ifndef _TYPEDEFS_H_
28 #include <typedefs.h>
29 #endif
30 
31 #ifndef _NET_ETHERNET_H_
32 #include <ethernet.h>
33 #endif
34 
35 /* Include WPA definitions here for compatibility */
36 #include <wpa.h>
37 
38 /* This marks the start of a packed structure section. */
39 #include <packed_section_start.h>
40 
41 #define DOT11_TU_TO_US			1024	/* 802.11 Time Unit is 1024 microseconds */
42 #define DOT11_SEC_TO_TU			977u	/* 1000000 / DOT11_TU_TO_US = ~977 TU */
43 
44 /* Generic 802.11 frame constants */
45 #define DOT11_A3_HDR_LEN		24	/* d11 header length with A3 */
46 #define DOT11_A4_HDR_LEN		30	/* d11 header length with A4 */
47 #define DOT11_MAC_HDR_LEN		DOT11_A3_HDR_LEN	/* MAC header length */
48 #define DOT11_FCS_LEN			4u	/* d11 FCS length */
49 #define DOT11_ICV_LEN			4	/* d11 ICV length */
50 #define DOT11_ICV_AES_LEN		8	/* d11 ICV/AES length */
51 #define DOT11_MAX_ICV_AES_LEN		16	/* d11 MAX ICV/AES length */
52 #define DOT11_QOS_LEN			2	/* d11 QoS length */
53 #define DOT11_HTC_LEN			4	/* d11 HT Control field length */
54 
55 #define DOT11_KEY_INDEX_SHIFT		6	/* d11 key index shift */
56 #define DOT11_IV_LEN			4	/* d11 IV length */
57 #define DOT11_IV_TKIP_LEN		8	/* d11 IV TKIP length */
58 #define DOT11_IV_AES_OCB_LEN		4	/* d11 IV/AES/OCB length */
59 #define DOT11_IV_AES_CCM_LEN		8	/* d11 IV/AES/CCM length */
60 #define DOT11_IV_WAPI_LEN		18	/* d11 IV WAPI length */
61 /* TODO: Need to change DOT11_IV_MAX_LEN to 18, but currently unable to change as the old
62  * branches are still referencing to this component.
63  */
64 #define DOT11_IV_MAX_LEN		8	/* maximum iv len for any encryption */
65 
66 /* Includes MIC */
67 #define DOT11_MAX_MPDU_BODY_LEN		2304	/* max MPDU body length */
68 /* A4 header + QoS + CCMP + PDU + ICV + FCS = 2352 */
69 #define DOT11_MAX_MPDU_LEN		(DOT11_A4_HDR_LEN + \
70 					 DOT11_QOS_LEN + \
71 					 DOT11_IV_AES_CCM_LEN + \
72 					 DOT11_MAX_MPDU_BODY_LEN + \
73 					 DOT11_ICV_LEN + \
74 					 DOT11_FCS_LEN)	/* d11 max MPDU length */
75 
76 #define DOT11_MAX_SSID_LEN		32	/* d11 max ssid length */
77 
78 /* dot11RTSThreshold */
79 #define DOT11_DEFAULT_RTS_LEN		2347	/* d11 default RTS length */
80 #define DOT11_MAX_RTS_LEN		2347	/* d11 max RTS length */
81 
82 /* dot11FragmentationThreshold */
83 #define DOT11_MIN_FRAG_LEN		256	/* d11 min fragmentation length */
84 #define DOT11_MAX_FRAG_LEN		2346	/* Max frag is also limited by aMPDUMaxLength
85 						* of the attached PHY
86 						*/
87 #define DOT11_DEFAULT_FRAG_LEN		2346	/* d11 default fragmentation length */
88 
89 /* dot11BeaconPeriod */
90 #define DOT11_MIN_BEACON_PERIOD		1	/* d11 min beacon period */
91 #define DOT11_MAX_BEACON_PERIOD		0xFFFF	/* d11 max beacon period */
92 
93 /* dot11DTIMPeriod */
94 #define DOT11_MIN_DTIM_PERIOD		1	/* d11 min DTIM period */
95 #define DOT11_MAX_DTIM_PERIOD		0xFF	/* d11 max DTIM period */
96 
97 /** 802.2 LLC/SNAP header used by 802.11 per 802.1H */
98 #define DOT11_LLC_SNAP_HDR_LEN		8	/* d11 LLC/SNAP header length */
99 /* minimum LLC header length; DSAP, SSAP, 8 bit Control (unnumbered) */
100 #define DOT11_LLC_HDR_LEN_MIN		3
101 #define DOT11_OUI_LEN			3	/* d11 OUI length */
102 BWL_PRE_PACKED_STRUCT struct dot11_llc_snap_header {
103 	uint8	dsap;				/* always 0xAA */
104 	uint8	ssap;				/* always 0xAA */
105 	uint8	ctl;				/* always 0x03 */
106 	uint8	oui[DOT11_OUI_LEN];		/* RFC1042: 0x00 0x00 0x00
107 						 * Bridge-Tunnel: 0x00 0x00 0xF8
108 						 */
109 	uint16	type;				/* ethertype */
110 } BWL_POST_PACKED_STRUCT;
111 
112 /* RFC1042 header used by 802.11 per 802.1H */
113 #define RFC1042_HDR_LEN	(ETHER_HDR_LEN + DOT11_LLC_SNAP_HDR_LEN)	/* RCF1042 header length */
114 
115 #define SFH_LLC_SNAP_SZ	(RFC1042_HDR_LEN)
116 
117 #define COPY_SFH_LLCSNAP(dst, src) \
118 	do { \
119 		*((uint32 *)dst + 0) = *((uint32 *)src + 0); \
120 		*((uint32 *)dst + 1) = *((uint32 *)src + 1); \
121 		*((uint32 *)dst + 2) = *((uint32 *)src + 2); \
122 		*((uint32 *)dst + 3) = *((uint32 *)src + 3); \
123 		*((uint32 *)dst + 4) = *((uint32 *)src + 4); \
124 		*(uint16 *)((uint32 *)dst + 5) = *(uint16 *)((uint32 *)src + 5); \
125 	} while (0)
126 
127 /* Generic 802.11 MAC header */
128 /**
129  * N.B.: This struct reflects the full 4 address 802.11 MAC header.
130  *		 The fields are defined such that the shorter 1, 2, and 3
131  *		 address headers just use the first k fields.
132  */
133 BWL_PRE_PACKED_STRUCT struct dot11_header {
134 	uint16			fc;		/* frame control */
135 	uint16			durid;		/* duration/ID */
136 	struct ether_addr	a1;		/* address 1 */
137 	struct ether_addr	a2;		/* address 2 */
138 	struct ether_addr	a3;		/* address 3 */
139 	uint16			seq;		/* sequence control */
140 	struct ether_addr	a4;		/* address 4 */
141 } BWL_POST_PACKED_STRUCT;
142 
143 /* Control frames */
144 
145 BWL_PRE_PACKED_STRUCT struct dot11_rts_frame {
146 	uint16			fc;		/* frame control */
147 	uint16			durid;		/* duration/ID */
148 	struct ether_addr	ra;		/* receiver address */
149 	struct ether_addr	ta;		/* transmitter address */
150 } BWL_POST_PACKED_STRUCT;
151 #define	DOT11_RTS_LEN		16		/* d11 RTS frame length */
152 
153 BWL_PRE_PACKED_STRUCT struct dot11_cts_frame {
154 	uint16			fc;		/* frame control */
155 	uint16			durid;		/* duration/ID */
156 	struct ether_addr	ra;		/* receiver address */
157 } BWL_POST_PACKED_STRUCT;
158 #define	DOT11_CTS_LEN		10u		/* d11 CTS frame length */
159 
160 BWL_PRE_PACKED_STRUCT struct dot11_ack_frame {
161 	uint16			fc;		/* frame control */
162 	uint16			durid;		/* duration/ID */
163 	struct ether_addr	ra;		/* receiver address */
164 } BWL_POST_PACKED_STRUCT;
165 #define	DOT11_ACK_LEN		10		/* d11 ACK frame length */
166 
167 BWL_PRE_PACKED_STRUCT struct dot11_ps_poll_frame {
168 	uint16			fc;		/* frame control */
169 	uint16			durid;		/* AID */
170 	struct ether_addr	bssid;		/* receiver address, STA in AP */
171 	struct ether_addr	ta;		/* transmitter address */
172 } BWL_POST_PACKED_STRUCT;
173 #define	DOT11_PS_POLL_LEN	16		/* d11 PS poll frame length */
174 
175 BWL_PRE_PACKED_STRUCT struct dot11_cf_end_frame {
176 	uint16			fc;		/* frame control */
177 	uint16			durid;		/* duration/ID */
178 	struct ether_addr	ra;		/* receiver address */
179 	struct ether_addr	bssid;		/* transmitter address, STA in AP */
180 } BWL_POST_PACKED_STRUCT;
181 #define	DOT11_CS_END_LEN	16		/* d11 CF-END frame length */
182 
183 /**
184  * RWL wifi protocol: The Vendor Specific Action frame is defined for vendor-specific signaling
185  *  category+OUI+vendor specific content ( this can be variable)
186  */
187 BWL_PRE_PACKED_STRUCT struct dot11_action_wifi_vendor_specific {
188 	uint8	category;
189 	uint8	OUI[3];
190 	uint8	type;
191 	uint8	subtype;
192 	uint8	data[1040];
193 } BWL_POST_PACKED_STRUCT;
194 typedef struct dot11_action_wifi_vendor_specific dot11_action_wifi_vendor_specific_t;
195 
196 /** generic vendor specific action frame with variable length */
197 BWL_PRE_PACKED_STRUCT struct dot11_action_vs_frmhdr {
198 	uint8	category;
199 	uint8	OUI[3];
200 	uint8	type;
201 	uint8	subtype;
202 	uint8	data[1];
203 } BWL_POST_PACKED_STRUCT;
204 typedef struct dot11_action_vs_frmhdr dot11_action_vs_frmhdr_t;
205 
206 #define DOT11_ACTION_VS_HDR_LEN	6
207 
208 #define BCM_ACTION_OUI_BYTE0	0x00
209 #define BCM_ACTION_OUI_BYTE1	0x90
210 #define BCM_ACTION_OUI_BYTE2	0x4c
211 
212 /* BA/BAR Control parameters */
213 #define DOT11_BA_CTL_POLICY_NORMAL	0x0000	/* normal ack */
214 #define DOT11_BA_CTL_POLICY_NOACK	0x0001	/* no ack */
215 #define DOT11_BA_CTL_POLICY_MASK	0x0001	/* ack policy mask */
216 
217 #define DOT11_BA_CTL_MTID		0x0002	/* multi tid BA */
218 #define DOT11_BA_CTL_COMPRESSED		0x0004	/* compressed bitmap */
219 
220 #define DOT11_BA_CTL_NUMMSDU_MASK	0x0FC0	/* num msdu in bitmap mask */
221 #define DOT11_BA_CTL_NUMMSDU_SHIFT	6	/* num msdu in bitmap shift */
222 
223 #define DOT11_BA_CTL_TID_MASK		0xF000	/* tid mask */
224 #define DOT11_BA_CTL_TID_SHIFT		12	/* tid shift */
225 
226 /** control frame header (BA/BAR) */
227 BWL_PRE_PACKED_STRUCT struct dot11_ctl_header {
228 	uint16			fc;		/* frame control */
229 	uint16			durid;		/* duration/ID */
230 	struct ether_addr	ra;		/* receiver address */
231 	struct ether_addr	ta;		/* transmitter address */
232 } BWL_POST_PACKED_STRUCT;
233 #define DOT11_CTL_HDR_LEN	16		/* control frame hdr len */
234 
235 /** BAR frame payload */
236 BWL_PRE_PACKED_STRUCT struct dot11_bar {
237 	uint16			bar_control;	/* BAR Control */
238 	uint16			seqnum;		/* Starting Sequence control */
239 } BWL_POST_PACKED_STRUCT;
240 #define DOT11_BAR_LEN		4		/* BAR frame payload length */
241 
242 #define DOT11_BA_BITMAP_LEN	128		/* bitmap length */
243 #define DOT11_BA_CMP_BITMAP_LEN	8		/* compressed bitmap length */
244 /** BA frame payload */
245 BWL_PRE_PACKED_STRUCT struct dot11_ba {
246 	uint16			ba_control;	/* BA Control */
247 	uint16			seqnum;		/* Starting Sequence control */
248 	uint8			bitmap[DOT11_BA_BITMAP_LEN];	/* Block Ack Bitmap */
249 } BWL_POST_PACKED_STRUCT;
250 #define DOT11_BA_LEN		4		/* BA frame payload len (wo bitmap) */
251 
252 /** Management frame header */
253 BWL_PRE_PACKED_STRUCT struct dot11_management_header {
254 	uint16			fc;		/* frame control */
255 	uint16			durid;		/* duration/ID */
256 	struct ether_addr	da;		/* receiver address */
257 	struct ether_addr	sa;		/* transmitter address */
258 	struct ether_addr	bssid;		/* BSS ID */
259 	uint16			seq;		/* sequence control */
260 } BWL_POST_PACKED_STRUCT;
261 typedef struct dot11_management_header dot11_management_header_t;
262 #define	DOT11_MGMT_HDR_LEN	24u		/* d11 management header length */
263 
264 /* Management frame payloads */
265 
266 BWL_PRE_PACKED_STRUCT struct dot11_bcn_prb {
267 	uint32			timestamp[2];
268 	uint16			beacon_interval;
269 	uint16			capability;
270 	uint8			ies[];
271 } BWL_POST_PACKED_STRUCT;
272 #define	DOT11_BCN_PRB_LEN	12		/* 802.11 beacon/probe frame fixed length */
273 #define	DOT11_BCN_PRB_FIXED_LEN	12u		/* 802.11 beacon/probe frame fixed length */
274 
275 BWL_PRE_PACKED_STRUCT struct dot11_auth {
276 	uint16			alg;		/* algorithm */
277 	uint16			seq;		/* sequence control */
278 	uint16			status;		/* status code */
279 } BWL_POST_PACKED_STRUCT;
280 #define DOT11_AUTH_FIXED_LEN		6	/* length of auth frame without challenge IE */
281 #define DOT11_AUTH_SEQ_STATUS_LEN	4	/* length of auth frame without challenge IE and
282 						 * without algorithm
283 						 */
284 
285 BWL_PRE_PACKED_STRUCT struct dot11_assoc_req {
286 	uint16			capability;	/* capability information */
287 	uint16			listen;		/* listen interval */
288 } BWL_POST_PACKED_STRUCT;
289 #define DOT11_ASSOC_REQ_FIXED_LEN	4	/* length of assoc frame without info elts */
290 
291 BWL_PRE_PACKED_STRUCT struct dot11_reassoc_req {
292 	uint16			capability;	/* capability information */
293 	uint16			listen;		/* listen interval */
294 	struct ether_addr	ap;		/* Current AP address */
295 } BWL_POST_PACKED_STRUCT;
296 #define DOT11_REASSOC_REQ_FIXED_LEN	10	/* length of assoc frame without info elts */
297 
298 BWL_PRE_PACKED_STRUCT struct dot11_assoc_resp {
299 	uint16			capability;	/* capability information */
300 	uint16			status;		/* status code */
301 	uint16			aid;		/* association ID */
302 } BWL_POST_PACKED_STRUCT;
303 #define DOT11_ASSOC_RESP_FIXED_LEN	6	/* length of assoc resp frame without info elts */
304 
305 BWL_PRE_PACKED_STRUCT struct dot11_action_measure {
306 	uint8	category;
307 	uint8	action;
308 	uint8	token;
309 	uint8	data[1];
310 } BWL_POST_PACKED_STRUCT;
311 #define DOT11_ACTION_MEASURE_LEN	3	/* d11 action measurement header length */
312 
313 BWL_PRE_PACKED_STRUCT struct dot11_action_ht_ch_width {
314 	uint8	category;
315 	uint8	action;
316 	uint8	ch_width;
317 } BWL_POST_PACKED_STRUCT;
318 
319 BWL_PRE_PACKED_STRUCT struct dot11_action_ht_mimops {
320 	uint8	category;
321 	uint8	action;
322 	uint8	control;
323 } BWL_POST_PACKED_STRUCT;
324 
325 BWL_PRE_PACKED_STRUCT struct dot11_action_sa_query {
326 	uint8	category;
327 	uint8	action;
328 	uint16	id;
329 } BWL_POST_PACKED_STRUCT;
330 
331 BWL_PRE_PACKED_STRUCT struct dot11_action_vht_oper_mode {
332 	uint8	category;
333 	uint8	action;
334 	uint8	mode;
335 } BWL_POST_PACKED_STRUCT;
336 
337 /* These lengths assume 64 MU groups, as specified in 802.11ac-2013 */
338 #define DOT11_ACTION_GID_MEMBERSHIP_LEN  8    /* bytes */
339 #define DOT11_ACTION_GID_USER_POS_LEN   16    /* bytes */
340 BWL_PRE_PACKED_STRUCT struct dot11_action_group_id {
341 	uint8   category;
342 	uint8   action;
343 	uint8   membership_status[DOT11_ACTION_GID_MEMBERSHIP_LEN];
344 	uint8   user_position[DOT11_ACTION_GID_USER_POS_LEN];
345 } BWL_POST_PACKED_STRUCT;
346 
347 #define SM_PWRSAVE_ENABLE	1
348 #define SM_PWRSAVE_MODE		2
349 
350 /* ************* 802.11h related definitions. ************* */
351 BWL_PRE_PACKED_STRUCT struct dot11_power_cnst {
352 	uint8 id;
353 	uint8 len;
354 	uint8 power;
355 } BWL_POST_PACKED_STRUCT;
356 typedef struct dot11_power_cnst dot11_power_cnst_t;
357 
358 BWL_PRE_PACKED_STRUCT struct dot11_power_cap {
359 	int8 min;
360 	int8 max;
361 } BWL_POST_PACKED_STRUCT;
362 typedef struct dot11_power_cap dot11_power_cap_t;
363 
364 BWL_PRE_PACKED_STRUCT struct dot11_tpc_rep {
365 	uint8 id;
366 	uint8 len;
367 	uint8 tx_pwr;
368 	uint8 margin;
369 } BWL_POST_PACKED_STRUCT;
370 typedef struct dot11_tpc_rep dot11_tpc_rep_t;
371 #define DOT11_MNG_IE_TPC_REPORT_SIZE	(sizeof(dot11_tpc_rep_t))
372 #define DOT11_MNG_IE_TPC_REPORT_LEN	2	/* length of IE data, not including 2 byte header */
373 
374 BWL_PRE_PACKED_STRUCT struct dot11_supp_channels {
375 	uint8 id;
376 	uint8 len;
377 	uint8 first_channel;
378 	uint8 num_channels;
379 } BWL_POST_PACKED_STRUCT;
380 typedef struct dot11_supp_channels dot11_supp_channels_t;
381 
382 /**
383  * Extension Channel Offset IE: 802.11n-D1.0 spec. added sideband
384  * offset for 40MHz operation.  The possible 3 values are:
385  * 1 = above control channel
386  * 3 = below control channel
387  * 0 = no extension channel
388  */
389 BWL_PRE_PACKED_STRUCT struct dot11_extch {
390 	uint8	id;		/* IE ID, 62, DOT11_MNG_EXT_CHANNEL_OFFSET */
391 	uint8	len;		/* IE length */
392 	uint8	extch;
393 } BWL_POST_PACKED_STRUCT;
394 typedef struct dot11_extch dot11_extch_ie_t;
395 
396 BWL_PRE_PACKED_STRUCT struct dot11_brcm_extch {
397 	uint8	id;		/* IE ID, 221, DOT11_MNG_PROPR_ID */
398 	uint8	len;		/* IE length */
399 	uint8	oui[3];		/* Proprietary OUI, BRCM_PROP_OUI */
400 	uint8	type;           /* type indicates what follows */
401 	uint8	extch;
402 } BWL_POST_PACKED_STRUCT;
403 typedef struct dot11_brcm_extch dot11_brcm_extch_ie_t;
404 
405 #define BRCM_EXTCH_IE_LEN	5
406 #define BRCM_EXTCH_IE_TYPE	53	/* 802.11n ID not yet assigned */
407 #define DOT11_EXTCH_IE_LEN	1
408 #define DOT11_EXT_CH_MASK	0x03	/* extension channel mask */
409 #define DOT11_EXT_CH_UPPER	0x01	/* ext. ch. on upper sb */
410 #define DOT11_EXT_CH_LOWER	0x03	/* ext. ch. on lower sb */
411 #define DOT11_EXT_CH_NONE	0x00	/* no extension ch.  */
412 
413 BWL_PRE_PACKED_STRUCT struct dot11_action_frmhdr {
414 	uint8	category;
415 	uint8	action;
416 	uint8	data[1];
417 } BWL_POST_PACKED_STRUCT;
418 typedef struct dot11_action_frmhdr dot11_action_frmhdr_t;
419 
420 /* Action Field length */
421 #define DOT11_ACTION_CATEGORY_LEN	1u
422 #define DOT11_ACTION_ACTION_LEN		1u
423 #define DOT11_ACTION_DIALOG_TOKEN_LEN	1u
424 #define DOT11_ACTION_CAPABILITY_LEN	2u
425 #define DOT11_ACTION_STATUS_CODE_LEN	2u
426 #define DOT11_ACTION_REASON_CODE_LEN	2u
427 #define DOT11_ACTION_TARGET_CH_LEN	1u
428 #define DOT11_ACTION_OPER_CLASS_LEN	1u
429 
430 #define DOT11_ACTION_FRMHDR_LEN	2
431 
432 /** CSA IE data structure */
433 BWL_PRE_PACKED_STRUCT struct dot11_channel_switch {
434 	uint8 id;	/* id DOT11_MNG_CHANNEL_SWITCH_ID */
435 	uint8 len;	/* length of IE */
436 	uint8 mode;	/* mode 0 or 1 */
437 	uint8 channel;	/* channel switch to */
438 	uint8 count;	/* number of beacons before switching */
439 } BWL_POST_PACKED_STRUCT;
440 typedef struct dot11_channel_switch dot11_chan_switch_ie_t;
441 
442 #define DOT11_SWITCH_IE_LEN	3	/* length of IE data, not including 2 byte header */
443 /* CSA mode - 802.11h-2003 $7.3.2.20 */
444 #define DOT11_CSA_MODE_ADVISORY		0	/* no DOT11_CSA_MODE_NO_TX restriction imposed */
445 #define DOT11_CSA_MODE_NO_TX		1	/* no transmission upon receiving CSA frame. */
446 
447 BWL_PRE_PACKED_STRUCT struct dot11_action_switch_channel {
448 	uint8	category;
449 	uint8	action;
450 	dot11_chan_switch_ie_t chan_switch_ie;	/* for switch IE */
451 	dot11_brcm_extch_ie_t extch_ie;		/* extension channel offset */
452 } BWL_POST_PACKED_STRUCT;
453 
454 BWL_PRE_PACKED_STRUCT struct dot11_csa_body {
455 	uint8 mode;	/* mode 0 or 1 */
456 	uint8 reg;	/* regulatory class */
457 	uint8 channel;	/* channel switch to */
458 	uint8 count;	/* number of beacons before switching */
459 } BWL_POST_PACKED_STRUCT;
460 
461 /** 11n Extended Channel Switch IE data structure */
462 BWL_PRE_PACKED_STRUCT struct dot11_ext_csa {
463 	uint8 id;	/* id DOT11_MNG_EXT_CSA_ID */
464 	uint8 len;	/* length of IE */
465 	struct dot11_csa_body b;	/* body of the ie */
466 } BWL_POST_PACKED_STRUCT;
467 typedef struct dot11_ext_csa dot11_ext_csa_ie_t;
468 #define DOT11_EXT_CSA_IE_LEN	4	/* length of extended channel switch IE body */
469 
470 BWL_PRE_PACKED_STRUCT struct dot11_action_ext_csa {
471 	uint8	category;
472 	uint8	action;
473 	dot11_ext_csa_ie_t chan_switch_ie;	/* for switch IE */
474 } BWL_POST_PACKED_STRUCT;
475 
476 BWL_PRE_PACKED_STRUCT struct dot11y_action_ext_csa {
477 	uint8	category;
478 	uint8	action;
479 	struct dot11_csa_body b;	/* body of the ie */
480 } BWL_POST_PACKED_STRUCT;
481 
482 /**  Wide Bandwidth Channel Switch IE data structure */
483 BWL_PRE_PACKED_STRUCT struct dot11_wide_bw_channel_switch {
484 	uint8 id;				/* id DOT11_MNG_WIDE_BW_CHANNEL_SWITCH_ID */
485 	uint8 len;				/* length of IE */
486 	uint8 channel_width;			/* new channel width */
487 	uint8 center_frequency_segment_0;	/* center frequency segment 0 */
488 	uint8 center_frequency_segment_1;	/* center frequency segment 1 */
489 } BWL_POST_PACKED_STRUCT;
490 typedef struct dot11_wide_bw_channel_switch dot11_wide_bw_chan_switch_ie_t;
491 
492 #define DOT11_WIDE_BW_SWITCH_IE_LEN     3       /* length of IE data, not including 2 byte header */
493 
494 /** Channel Switch Wrapper IE data structure */
495 BWL_PRE_PACKED_STRUCT struct dot11_channel_switch_wrapper {
496 	uint8 id;				/* id DOT11_MNG_WIDE_BW_CHANNEL_SWITCH_ID */
497 	uint8 len;				/* length of IE */
498 	dot11_wide_bw_chan_switch_ie_t wb_chan_switch_ie;
499 } BWL_POST_PACKED_STRUCT;
500 typedef struct dot11_channel_switch_wrapper dot11_chan_switch_wrapper_ie_t;
501 
502 /* Proposed wide bandwidth channel IE */
503 typedef enum wide_bw_chan_width {
504 	WIDE_BW_CHAN_WIDTH_20	= 0,
505 	WIDE_BW_CHAN_WIDTH_40	= 1,
506 	WIDE_BW_CHAN_WIDTH_80	= 2,
507 	WIDE_BW_CHAN_WIDTH_160	= 3,
508 	WIDE_BW_CHAN_WIDTH_80_80	= 4
509 } wide_bw_chan_width_t;
510 
511 /**  Wide Bandwidth Channel IE data structure */
512 BWL_PRE_PACKED_STRUCT struct dot11_wide_bw_channel {
513 	uint8 id;				/* id DOT11_MNG_WIDE_BW_CHANNEL_ID */
514 	uint8 len;				/* length of IE */
515 	uint8 channel_width;			/* channel width */
516 	uint8 center_frequency_segment_0;	/* center frequency segment 0 */
517 	uint8 center_frequency_segment_1;	/* center frequency segment 1 */
518 } BWL_POST_PACKED_STRUCT;
519 typedef struct dot11_wide_bw_channel dot11_wide_bw_chan_ie_t;
520 
521 #define DOT11_WIDE_BW_IE_LEN     3       /* length of IE data, not including 2 byte header */
522 /** VHT Transmit Power Envelope IE data structure */
523 BWL_PRE_PACKED_STRUCT struct dot11_vht_transmit_power_envelope {
524 	uint8 id;				/* id DOT11_MNG_WIDE_BW_CHANNEL_SWITCH_ID */
525 	uint8 len;				/* length of IE */
526 	uint8 transmit_power_info;
527 	uint8 local_max_transmit_power_20;
528 } BWL_POST_PACKED_STRUCT;
529 typedef struct dot11_vht_transmit_power_envelope dot11_vht_transmit_power_envelope_ie_t;
530 
531 /* vht transmit power envelope IE length depends on channel width */
532 #define DOT11_VHT_TRANSMIT_PWR_ENVELOPE_IE_LEN_40MHZ	1
533 #define DOT11_VHT_TRANSMIT_PWR_ENVELOPE_IE_LEN_80MHZ	2
534 #define DOT11_VHT_TRANSMIT_PWR_ENVELOPE_IE_LEN_160MHZ	3
535 
536 /* TPE Transmit Power Information Field */
537 #define DOT11_TPE_INFO_MAX_TX_PWR_CNT_MASK               0x07u
538 #define DOT11_TPE_INFO_MAX_TX_PWR_INTRPN_MASK            0x38u
539 #define DOT11_TPE_INFO_MAX_TX_PWR_INTRPN_SHIFT           3u
540 #define DOT11_TPE_INFO_MAX_TX_PWR_CAT_MASK               0xC0u
541 #define DOT11_TPE_INFO_MAX_TX_PWR_CAT_SHIFT              6u
542 
543 /* TPE Transmit Power Information Field Accessor */
544 #define DOT11_TPE_INFO_MAX_TX_PWR_CNT(x) \
545 	(x & DOT11_TPE_INFO_MAX_TX_PWR_CNT_MASK)
546 #define DOT11_TPE_INFO_MAX_TX_PWR_INTRPN(x) \
547 	(((x) & DOT11_TPE_INFO_MAX_TX_PWR_INTRPN_MASK) >> \
548 	DOT11_TPE_INFO_MAX_TX_PWR_INTRPN_SHIFT)
549 #define DOT11_TPE_INFO_MAX_TX_PWR_CAT(x) \
550 	(((x) & DOT11_TPE_INFO_MAX_TX_PWR_CAT_MASK) >> \
551 	DOT11_TPE_INFO_MAX_TX_PWR_CAT_SHIFT)
552 
553 /* Maximum Transmit Power Interpretation subfield */
554 #define DOT11_TPE_MAX_TX_PWR_INTRPN_LOCAL_EIRP              0u
555 #define DOT11_TPE_MAX_TX_PWR_INTRPN_LOCAL_EIRP_PSD          1u
556 #define DOT11_TPE_MAX_TX_PWR_INTRPN_REG_CLIENT_EIRP         2u
557 #define DOT11_TPE_MAX_TX_PWR_INTRPN_REG_CLIENT_EIRP_PSD     3u
558 
559 /* Maximum Transmit Power category subfield  */
560 #define DOT11_TPE_MAX_TX_PWR_CAT_DEFAULT                 0u
561 
562 /* Maximum Transmit Power category subfield in US */
563 #define DOT11_TPE_MAX_TX_PWR_CAT_US_DEFAULT              0u
564 #define DOT11_TPE_MAX_TX_PWR_CAT_US_SUB_DEV              1u
565 
566 /* Maximum Transmit Power Count subfield values when
567  * Maximum Transmit Power Interpretation subfield is 0 or 2
568  */
569 #define DOT11_TPE_INFO_MAX_TX_CNT_EIRP_20_MHZ                  0u
570 #define DOT11_TPE_INFO_MAX_TX_CNT_EIRP_20_40_MHZ               1u
571 #define DOT11_TPE_INFO_MAX_TX_CNT_EIRP_20_40_80_MHZ            2u
572 #define DOT11_TPE_INFO_MAX_TX_CNT_EIRP_20_40_80_160_MHZ        3u
573 
574 /* Maximum Transmit Power Count subfield values when
575  * Maximum Transmit Power Interpretation subfield is 1 or 3
576  */
577 #define DOT11_TPE_INFO_MAX_TX_CNT_PSD_VAL_0                 0u
578 #define DOT11_TPE_INFO_MAX_TX_CNT_PSD_VAL_1                 1u
579 #define DOT11_TPE_INFO_MAX_TX_CNT_PSD_VAL_2                 2u
580 #define DOT11_TPE_INFO_MAX_TX_CNT_PSD_VAL_3                 4u
581 #define DOT11_TPE_INFO_MAX_TX_CNT_PSD_VAL_4                 8u
582 
583 #define DOT11_TPE_MAX_TX_PWR_EIRP_MIN                    -128 /* 0.5 db step */
584 #define DOT11_TPE_MAX_TX_PWR_EIRP_MAX                     126  /* 0.5 db step */
585 #define DOT11_TPE_MAX_TX_PWR_EIRP_NO_LIMIT                127  /* 0.5 db step */
586 
587 #define DOT11_TPE_MAX_TX_PWR_PSD_BLOCKED                 -128
588 #define DOT11_TPE_MAX_TX_PWR_PSD_NO_LIMIT                 127u
589 /** Transmit Power Envelope IE data structure as per 11ax draft */
590 BWL_PRE_PACKED_STRUCT struct dot11_transmit_power_envelope {
591 	uint8 id;				/* id DOT11_MNG_WIDE_BW_CHANNEL_SWITCH_ID */
592 	uint8 len;				/* length of IE */
593 	uint8 transmit_power_info;
594 	uint8 max_transmit_power[]; /* Variable length */
595 } BWL_POST_PACKED_STRUCT;
596 typedef struct dot11_transmit_power_envelope dot11_transmit_power_envelope_ie_t;
597 /* id (1) + len (1) + transmit_power_info(1) + max_transmit_power(1) */
598 #define DOT11_TPE_ELEM_MIN_LEN  4u
599 
600 BWL_PRE_PACKED_STRUCT struct dot11_obss_coex {
601 	uint8	id;
602 	uint8	len;
603 	uint8	info;
604 } BWL_POST_PACKED_STRUCT;
605 typedef struct dot11_obss_coex dot11_obss_coex_t;
606 #define DOT11_OBSS_COEXINFO_LEN	1	/* length of OBSS Coexistence INFO IE */
607 
608 #define	DOT11_OBSS_COEX_INFO_REQ		0x01
609 #define	DOT11_OBSS_COEX_40MHZ_INTOLERANT	0x02
610 #define	DOT11_OBSS_COEX_20MHZ_WIDTH_REQ	0x04
611 
612 BWL_PRE_PACKED_STRUCT struct dot11_obss_chanlist {
613 	uint8	id;
614 	uint8	len;
615 	uint8	regclass;
616 	uint8	chanlist[1];
617 } BWL_POST_PACKED_STRUCT;
618 typedef struct dot11_obss_chanlist dot11_obss_chanlist_t;
619 #define DOT11_OBSS_CHANLIST_FIXED_LEN	1	/* fixed length of regclass */
620 
621 BWL_PRE_PACKED_STRUCT struct dot11_extcap_ie {
622 	uint8 id;
623 	uint8 len;
624 	uint8 cap[1];
625 } BWL_POST_PACKED_STRUCT;
626 typedef struct dot11_extcap_ie dot11_extcap_ie_t;
627 
628 #define DOT11_EXTCAP_LEN_COEX	1
629 #define DOT11_EXTCAP_LEN_BT	3
630 #define DOT11_EXTCAP_LEN_IW	4
631 #define DOT11_EXTCAP_LEN_SI	6
632 
633 #define DOT11_EXTCAP_LEN_TDLS	5
634 #define DOT11_11AC_EXTCAP_LEN_TDLS	8
635 
636 #define DOT11_EXTCAP_LEN_FMS			2
637 #define DOT11_EXTCAP_LEN_PROXY_ARP		2
638 #define DOT11_EXTCAP_LEN_TFS			3
639 #define DOT11_EXTCAP_LEN_WNM_SLEEP		3
640 #define DOT11_EXTCAP_LEN_TIMBC			3
641 #define DOT11_EXTCAP_LEN_BSSTRANS		3
642 #define DOT11_EXTCAP_LEN_DMS			4
643 #define DOT11_EXTCAP_LEN_WNM_NOTIFICATION	6
644 #define DOT11_EXTCAP_LEN_TDLS_WBW		8
645 #define DOT11_EXTCAP_LEN_OPMODE_NOTIFICATION	8
646 #define DOT11_EXTCAP_LEN_TWT			10u
647 #define DOT11_EXTCAP_LEN_BCN_PROT		11u
648 
649 /* TDLS Capabilities */
650 #define DOT11_TDLS_CAP_TDLS			37	/* TDLS support */
651 #define DOT11_TDLS_CAP_PU_BUFFER_STA		28	/* TDLS Peer U-APSD buffer STA support */
652 #define DOT11_TDLS_CAP_PEER_PSM			20	/* TDLS Peer PSM support */
653 #define DOT11_TDLS_CAP_CH_SW			30	/* TDLS Channel switch */
654 #define DOT11_TDLS_CAP_PROH			38	/* TDLS prohibited */
655 #define DOT11_TDLS_CAP_CH_SW_PROH		39	/* TDLS Channel switch prohibited */
656 #define DOT11_TDLS_CAP_TDLS_WIDER_BW		61	/* TDLS Wider Band-Width */
657 
658 #define TDLS_CAP_MAX_BIT			39	/* TDLS max bit defined in ext cap */
659 
660 /* FIXME: remove redundant DOT11_CAP_SAE_HASH_TO_ELEMENT */
661 #define DOT11_CAP_SAE_HASH_TO_ELEMENT		5u	/* SAE Hash-to-element support */
662 #define DOT11_EXT_RSN_CAP_SAE_H2E		5u	/* SAE Hash-to-element support */
663 /* FIXME: Use these temporary IDs until ANA assigns IDs */
664 #define DOT11_EXT_RSN_CAP_SAE_PK		6u	/* SAE-PK support */
665 /* Last bit in extended rsn capabilities (RSNXE) */
666 #define DOT11_EXT_RSN_CAP_MAX_BIT		DOT11_EXT_RSN_CAP_SAE_PK
667 
668 BWL_PRE_PACKED_STRUCT struct dot11_rsnxe {
669 	uint8 id;	/* id DOT11_MNG_RSNXE_ID */
670 	uint8 len;
671 	uint8 cap[1];
672 } BWL_POST_PACKED_STRUCT;
673 typedef struct dot11_rsnxe dot11_rsnxe_t;
674 
675 #define RSNXE_CAP_LENGTH_MASK		(0x0f)
676 #define RSNXE_CAP_LENGTH(cap)		((uint8)(cap) & RSNXE_CAP_LENGTH_MASK)
677 #define RSNXE_SET_CAP_LENGTH(cap, len)\
678 		(cap = (cap & ~RSNXE_CAP_LENGTH_MASK) | ((uint8)(len) & RSNXE_CAP_LENGTH_MASK))
679 
680 BWL_PRE_PACKED_STRUCT struct dot11_rejected_groups_ie {
681 	uint8 id;	/* DOT11_MNG_EXT_ID */
682 	uint8 len;
683 	uint8 id_ext; /* DOT11_MNG_REJECTED_GROUPS_ID */
684 	uint16 groups[];
685 } BWL_POST_PACKED_STRUCT;
686 typedef struct dot11_rejected_groups_ie dot11_rejected_groups_ie_t;
687 
688 /* 802.11h/802.11k Measurement Request/Report IEs */
689 /* Measurement Type field */
690 #define DOT11_MEASURE_TYPE_BASIC	0   /* d11 measurement basic type */
691 #define DOT11_MEASURE_TYPE_CCA		1   /* d11 measurement CCA type */
692 #define DOT11_MEASURE_TYPE_RPI		2   /* d11 measurement RPI type */
693 #define DOT11_MEASURE_TYPE_CHLOAD	3   /* d11 measurement Channel Load type */
694 #define DOT11_MEASURE_TYPE_NOISE	4   /* d11 measurement Noise Histogram type */
695 #define DOT11_MEASURE_TYPE_BEACON	5   /* d11 measurement Beacon type */
696 #define DOT11_MEASURE_TYPE_FRAME	6   /* d11 measurement Frame type */
697 #define DOT11_MEASURE_TYPE_STAT		7   /* d11 measurement STA Statistics type */
698 #define DOT11_MEASURE_TYPE_LCI		8   /* d11 measurement LCI type */
699 #define DOT11_MEASURE_TYPE_TXSTREAM	9   /* d11 measurement TX Stream type */
700 #define DOT11_MEASURE_TYPE_MCDIAGS	10  /* d11 measurement multicast diagnostics */
701 #define DOT11_MEASURE_TYPE_CIVICLOC	11  /* d11 measurement location civic */
702 #define DOT11_MEASURE_TYPE_LOC_ID	12  /* d11 measurement location identifier */
703 #define DOT11_MEASURE_TYPE_DIRCHANQ	13  /* d11 measurement dir channel quality */
704 #define DOT11_MEASURE_TYPE_DIRMEAS	14  /* d11 measurement directional */
705 #define DOT11_MEASURE_TYPE_DIRSTATS	15  /* d11 measurement directional stats */
706 #define DOT11_MEASURE_TYPE_FTMRANGE	16  /* d11 measurement Fine Timing */
707 #define DOT11_MEASURE_TYPE_PAUSE	255	/* d11 measurement pause type */
708 
709 /* Measurement Request Modes */
710 #define DOT11_MEASURE_MODE_PARALLEL	(1<<0)	/* d11 measurement parallel */
711 #define DOT11_MEASURE_MODE_ENABLE	(1<<1)	/* d11 measurement enable */
712 #define DOT11_MEASURE_MODE_REQUEST	(1<<2)	/* d11 measurement request */
713 #define DOT11_MEASURE_MODE_REPORT	(1<<3)	/* d11 measurement report */
714 #define DOT11_MEASURE_MODE_DUR		(1<<4)	/* d11 measurement dur mandatory */
715 /* Measurement Report Modes */
716 #define DOT11_MEASURE_MODE_LATE		(1<<0)	/* d11 measurement late */
717 #define DOT11_MEASURE_MODE_INCAPABLE	(1<<1)	/* d11 measurement incapable */
718 #define DOT11_MEASURE_MODE_REFUSED	(1<<2)	/* d11 measurement refuse */
719 /* Basic Measurement Map bits */
720 #define DOT11_MEASURE_BASIC_MAP_BSS	((uint8)(1<<0))	/* d11 measurement basic map BSS */
721 #define DOT11_MEASURE_BASIC_MAP_OFDM	((uint8)(1<<1))	/* d11 measurement map OFDM */
722 #define DOT11_MEASURE_BASIC_MAP_UKNOWN	((uint8)(1<<2))	/* d11 measurement map unknown */
723 #define DOT11_MEASURE_BASIC_MAP_RADAR	((uint8)(1<<3))	/* d11 measurement map radar */
724 #define DOT11_MEASURE_BASIC_MAP_UNMEAS	((uint8)(1<<4))	/* d11 measurement map unmeasuremnt */
725 
726 BWL_PRE_PACKED_STRUCT struct dot11_meas_req {
727 	uint8 id;
728 	uint8 len;
729 	uint8 token;
730 	uint8 mode;
731 	uint8 type;
732 	uint8 channel;
733 	uint8 start_time[8];
734 	uint16 duration;
735 } BWL_POST_PACKED_STRUCT;
736 typedef struct dot11_meas_req dot11_meas_req_t;
737 #define DOT11_MNG_IE_MREQ_LEN 14	/* d11 measurement request IE length */
738 /* length of Measure Request IE data not including variable len */
739 #define DOT11_MNG_IE_MREQ_FIXED_LEN 3	/* d11 measurement request IE fixed length */
740 
741 BWL_PRE_PACKED_STRUCT struct dot11_meas_req_loc {
742 	uint8 id;
743 	uint8 len;
744 	uint8 token;
745 	uint8 mode;
746 	uint8 type;
747 	BWL_PRE_PACKED_STRUCT union
748 	{
749 		BWL_PRE_PACKED_STRUCT struct {
750 			uint8 subject;
751 			uint8 data[1];
752 		} BWL_POST_PACKED_STRUCT lci;
753 		BWL_PRE_PACKED_STRUCT struct {
754 			uint8 subject;
755 			uint8 type;  /* type of civic location */
756 			uint8 siu;   /* service interval units */
757 			uint16 si; /* service interval */
758 			uint8 data[1];
759 		} BWL_POST_PACKED_STRUCT civic;
760 		BWL_PRE_PACKED_STRUCT struct {
761 			uint8 subject;
762 			uint8 siu;   /* service interval units */
763 			uint16 si; /* service interval */
764 			uint8 data[1];
765 		} BWL_POST_PACKED_STRUCT locid;
766 		BWL_PRE_PACKED_STRUCT struct {
767 			uint16 max_init_delay;		/* maximum random initial delay */
768 			uint8 min_ap_count;
769 			uint8 data[1];
770 		} BWL_POST_PACKED_STRUCT ftm_range;
771 	} BWL_POST_PACKED_STRUCT req;
772 } BWL_POST_PACKED_STRUCT;
773 typedef struct dot11_meas_req_loc dot11_meas_req_loc_t;
774 #define DOT11_MNG_IE_MREQ_MIN_LEN           4	/* d11 measurement report IE length */
775 #define DOT11_MNG_IE_MREQ_LCI_FIXED_LEN     4	/* d11 measurement report IE length */
776 #define DOT11_MNG_IE_MREQ_CIVIC_FIXED_LEN   8	/* d11 measurement report IE length */
777 #define DOT11_MNG_IE_MREQ_FRNG_FIXED_LEN    6	/* d11 measurement report IE length */
778 
779 BWL_PRE_PACKED_STRUCT struct dot11_lci_subelement {
780 	uint8 subelement;
781 	uint8 length;
782 	uint8 lci_data[1];
783 } BWL_POST_PACKED_STRUCT;
784 typedef struct dot11_lci_subelement dot11_lci_subelement_t;
785 
786 BWL_PRE_PACKED_STRUCT struct dot11_colocated_bssid_list_se {
787 	uint8 sub_id;
788 	uint8 length;
789 	uint8 max_bssid_ind; /* MaxBSSID Indicator */
790 	struct ether_addr bssid[1]; /* variable */
791 } BWL_POST_PACKED_STRUCT;
792 typedef struct dot11_colocated_bssid_list_se dot11_colocated_bssid_list_se_t;
793 #define DOT11_LCI_COLOCATED_BSSID_LIST_FIXED_LEN     3
794 #define DOT11_LCI_COLOCATED_BSSID_SUBELEM_ID         7
795 
796 BWL_PRE_PACKED_STRUCT struct dot11_civic_subelement {
797 	uint8 type;  /* type of civic location */
798 	uint8 subelement;
799 	uint8 length;
800 	uint8 civic_data[1];
801 } BWL_POST_PACKED_STRUCT;
802 typedef struct dot11_civic_subelement dot11_civic_subelement_t;
803 
804 BWL_PRE_PACKED_STRUCT struct dot11_meas_rep {
805 	uint8 id;
806 	uint8 len;
807 	uint8 token;
808 	uint8 mode;
809 	uint8 type;
810 	BWL_PRE_PACKED_STRUCT union
811 	{
812 		BWL_PRE_PACKED_STRUCT struct {
813 			uint8 channel;
814 			uint8 start_time[8];
815 			uint16 duration;
816 			uint8 map;
817 		} BWL_POST_PACKED_STRUCT basic;
818 		BWL_PRE_PACKED_STRUCT struct {
819 			uint8 subelement;
820 			uint8 length;
821 			uint8 data[1];
822 		} BWL_POST_PACKED_STRUCT lci;
823 		BWL_PRE_PACKED_STRUCT struct {
824 			uint8 type;  /* type of civic location */
825 			uint8 subelement;
826 			uint8 length;
827 			uint8 data[1];
828 		} BWL_POST_PACKED_STRUCT civic;
829 		BWL_PRE_PACKED_STRUCT struct {
830 			uint8 exp_tsf[8];
831 			uint8 subelement;
832 			uint8 length;
833 			uint8 data[1];
834 		} BWL_POST_PACKED_STRUCT locid;
835 		BWL_PRE_PACKED_STRUCT struct {
836 			uint8 entry_count;
837 			uint8 data[1];
838 		} BWL_POST_PACKED_STRUCT ftm_range;
839 		uint8 data[1];
840 	} BWL_POST_PACKED_STRUCT rep;
841 } BWL_POST_PACKED_STRUCT;
842 typedef struct dot11_meas_rep dot11_meas_rep_t;
843 #define DOT11_MNG_IE_MREP_MIN_LEN           5	/* d11 measurement report IE length */
844 #define DOT11_MNG_IE_MREP_LCI_FIXED_LEN     5	/* d11 measurement report IE length */
845 #define DOT11_MNG_IE_MREP_CIVIC_FIXED_LEN   6	/* d11 measurement report IE length */
846 #define DOT11_MNG_IE_MREP_LOCID_FIXED_LEN   13	/* d11 measurement report IE length */
847 #define DOT11_MNG_IE_MREP_BASIC_FIXED_LEN   15	/* d11 measurement report IE length */
848 #define DOT11_MNG_IE_MREP_FRNG_FIXED_LEN    4
849 
850 /* length of Measure Report IE data not including variable len */
851 #define DOT11_MNG_IE_MREP_FIXED_LEN	3	/* d11 measurement response IE fixed length */
852 
853 BWL_PRE_PACKED_STRUCT struct dot11_meas_rep_basic {
854 	uint8 channel;
855 	uint8 start_time[8];
856 	uint16 duration;
857 	uint8 map;
858 } BWL_POST_PACKED_STRUCT;
859 typedef struct dot11_meas_rep_basic dot11_meas_rep_basic_t;
860 #define DOT11_MEASURE_BASIC_REP_LEN	12	/* d11 measurement basic report length */
861 
862 BWL_PRE_PACKED_STRUCT struct dot11_quiet {
863 	uint8 id;
864 	uint8 len;
865 	uint8 count;	/* TBTTs until beacon interval in quiet starts */
866 	uint8 period;	/* Beacon intervals between periodic quiet periods ? */
867 	uint16 duration;	/* Length of quiet period, in TU's */
868 	uint16 offset;	/* TU's offset from TBTT in Count field */
869 } BWL_POST_PACKED_STRUCT;
870 typedef struct dot11_quiet dot11_quiet_t;
871 
872 BWL_PRE_PACKED_STRUCT struct chan_map_tuple {
873 	uint8 channel;
874 	uint8 map;
875 } BWL_POST_PACKED_STRUCT;
876 typedef struct chan_map_tuple chan_map_tuple_t;
877 
878 BWL_PRE_PACKED_STRUCT struct dot11_ibss_dfs {
879 	uint8 id;
880 	uint8 len;
881 	uint8 eaddr[ETHER_ADDR_LEN];
882 	uint8 interval;
883 	chan_map_tuple_t map[1];
884 } BWL_POST_PACKED_STRUCT;
885 typedef struct dot11_ibss_dfs dot11_ibss_dfs_t;
886 
887 /* WME Elements */
888 #define WME_OUI			"\x00\x50\xf2"	/* WME OUI */
889 #define WME_OUI_LEN		3
890 #define WME_OUI_TYPE		2	/* WME type */
891 #define WME_TYPE		2	/* WME type, deprecated */
892 #define WME_SUBTYPE_IE		0	/* Information Element */
893 #define WME_SUBTYPE_PARAM_IE	1	/* Parameter Element */
894 #define WME_SUBTYPE_TSPEC	2	/* Traffic Specification */
895 #define WME_VER			1	/* WME version */
896 
897 /* WME Access Category Indices (ACIs) */
898 #define AC_BE			0	/* Best Effort */
899 #define AC_BK			1	/* Background */
900 #define AC_VI			2	/* Video */
901 #define AC_VO			3	/* Voice */
902 #define AC_COUNT		4	/* number of ACs */
903 
904 typedef uint8 ac_bitmap_t;	/* AC bitmap of (1 << AC_xx) */
905 
906 #define AC_BITMAP_NONE		0x0	/* No ACs */
907 #define AC_BITMAP_ALL		0xf	/* All ACs */
908 #define AC_BITMAP_TST(ab, ac)	(((ab) & (1 << (ac))) != 0)
909 #define AC_BITMAP_SET(ab, ac)	(((ab) |= (1 << (ac))))
910 #define AC_BITMAP_RESET(ab, ac) (((ab) &= ~(1 << (ac))))
911 
912 /* Management PKT Lifetime indices */
913 /* Removing flag checks 'WLTEST'
914  * while merging MERGE BIS120RC4 to DINGO2
915  */
916 #define MGMT_ALL		0xffff
917 #define MGMT_AUTH_LT	FC_SUBTYPE_AUTH
918 #define MGMT_ASSOC_LT	FC_SUBTYPE_ASSOC_REQ
919 
920 /** WME Information Element (IE) */
921 BWL_PRE_PACKED_STRUCT struct wme_ie {
922 	uint8 oui[3];
923 	uint8 type;
924 	uint8 subtype;
925 	uint8 version;
926 	uint8 qosinfo;
927 } BWL_POST_PACKED_STRUCT;
928 typedef struct wme_ie wme_ie_t;
929 #define WME_IE_LEN 7	/* WME IE length */
930 
931 BWL_PRE_PACKED_STRUCT struct edcf_acparam {
932 	uint8	ACI;
933 	uint8	ECW;
934 	uint16  TXOP;		/* stored in network order (ls octet first) */
935 } BWL_POST_PACKED_STRUCT;
936 typedef struct edcf_acparam edcf_acparam_t;
937 
938 /** WME Parameter Element (PE) */
939 BWL_PRE_PACKED_STRUCT struct wme_param_ie {
940 	uint8 oui[3];
941 	uint8 type;
942 	uint8 subtype;
943 	uint8 version;
944 	uint8 qosinfo;
945 	uint8 rsvd;
946 	edcf_acparam_t acparam[AC_COUNT];
947 } BWL_POST_PACKED_STRUCT;
948 typedef struct wme_param_ie wme_param_ie_t;
949 #define WME_PARAM_IE_LEN            24          /* WME Parameter IE length */
950 
951 /* QoS Info field for IE as sent from AP */
952 #define WME_QI_AP_APSD_MASK         0x80        /* U-APSD Supported mask */
953 #define WME_QI_AP_APSD_SHIFT        7           /* U-APSD Supported shift */
954 #define WME_QI_AP_COUNT_MASK        0x0f        /* Parameter set count mask */
955 #define WME_QI_AP_COUNT_SHIFT       0           /* Parameter set count shift */
956 
957 /* QoS Info field for IE as sent from STA */
958 #define WME_QI_STA_MAXSPLEN_MASK    0x60        /* Max Service Period Length mask */
959 #define WME_QI_STA_MAXSPLEN_SHIFT   5           /* Max Service Period Length shift */
960 #define WME_QI_STA_APSD_ALL_MASK    0xf         /* APSD all AC bits mask */
961 #define WME_QI_STA_APSD_ALL_SHIFT   0           /* APSD all AC bits shift */
962 #define WME_QI_STA_APSD_BE_MASK     0x8         /* APSD AC_BE mask */
963 #define WME_QI_STA_APSD_BE_SHIFT    3           /* APSD AC_BE shift */
964 #define WME_QI_STA_APSD_BK_MASK     0x4         /* APSD AC_BK mask */
965 #define WME_QI_STA_APSD_BK_SHIFT    2           /* APSD AC_BK shift */
966 #define WME_QI_STA_APSD_VI_MASK     0x2         /* APSD AC_VI mask */
967 #define WME_QI_STA_APSD_VI_SHIFT    1           /* APSD AC_VI shift */
968 #define WME_QI_STA_APSD_VO_MASK     0x1         /* APSD AC_VO mask */
969 #define WME_QI_STA_APSD_VO_SHIFT    0           /* APSD AC_VO shift */
970 
971 /* ACI */
972 #define EDCF_AIFSN_MIN               1           /* AIFSN minimum value */
973 #define EDCF_AIFSN_MAX               15          /* AIFSN maximum value */
974 #define EDCF_AIFSN_MASK              0x0f        /* AIFSN mask */
975 #define EDCF_ACM_MASK                0x10        /* ACM mask */
976 #define EDCF_ACI_MASK                0x60        /* ACI mask */
977 #define EDCF_ACI_SHIFT               5           /* ACI shift */
978 #define EDCF_AIFSN_SHIFT             12          /* 4 MSB(0xFFF) in ifs_ctl for AC idx */
979 
980 /* ECW */
981 #define EDCF_ECW_MIN                 0           /* cwmin/cwmax exponent minimum value */
982 #define EDCF_ECW_MAX                 15          /* cwmin/cwmax exponent maximum value */
983 #define EDCF_ECW2CW(exp)             ((1 << (exp)) - 1)
984 #define EDCF_ECWMIN_MASK             0x0f        /* cwmin exponent form mask */
985 #define EDCF_ECWMAX_MASK             0xf0        /* cwmax exponent form mask */
986 #define EDCF_ECWMAX_SHIFT            4           /* cwmax exponent form shift */
987 
988 /* TXOP */
989 #define EDCF_TXOP_MIN                0           /* TXOP minimum value */
990 #define EDCF_TXOP_MAX                65535       /* TXOP maximum value */
991 #define EDCF_TXOP2USEC(txop)         ((txop) << 5)
992 
993 /* Default BE ACI value for non-WME connection STA */
994 #define NON_EDCF_AC_BE_ACI_STA          0x02
995 
996 /* Default EDCF parameters that AP advertises for STA to use; WMM draft Table 12 */
997 #define EDCF_AC_BE_ACI_STA           0x03	/* STA ACI value for best effort AC */
998 #define EDCF_AC_BE_ECW_STA           0xA4	/* STA ECW value for best effort AC */
999 #define EDCF_AC_BE_TXOP_STA          0x0000	/* STA TXOP value for best effort AC */
1000 #define EDCF_AC_BK_ACI_STA           0x27	/* STA ACI value for background AC */
1001 #define EDCF_AC_BK_ECW_STA           0xA4	/* STA ECW value for background AC */
1002 #define EDCF_AC_BK_TXOP_STA          0x0000	/* STA TXOP value for background AC */
1003 #define EDCF_AC_VI_ACI_STA           0x42	/* STA ACI value for video AC */
1004 #define EDCF_AC_VI_ECW_STA           0x43	/* STA ECW value for video AC */
1005 #define EDCF_AC_VI_TXOP_STA          0x005e	/* STA TXOP value for video AC */
1006 #define EDCF_AC_VO_ACI_STA           0x62	/* STA ACI value for audio AC */
1007 #define EDCF_AC_VO_ECW_STA           0x32	/* STA ECW value for audio AC */
1008 #define EDCF_AC_VO_TXOP_STA          0x002f	/* STA TXOP value for audio AC */
1009 
1010 /* Default EDCF parameters that AP uses; WMM draft Table 14 */
1011 #define EDCF_AC_BE_ACI_AP            0x03	/* AP ACI value for best effort AC */
1012 #define EDCF_AC_BE_ECW_AP            0x64	/* AP ECW value for best effort AC */
1013 #define EDCF_AC_BE_TXOP_AP           0x0000	/* AP TXOP value for best effort AC */
1014 #define EDCF_AC_BK_ACI_AP            0x27	/* AP ACI value for background AC */
1015 #define EDCF_AC_BK_ECW_AP            0xA4	/* AP ECW value for background AC */
1016 #define EDCF_AC_BK_TXOP_AP           0x0000	/* AP TXOP value for background AC */
1017 #define EDCF_AC_VI_ACI_AP            0x41	/* AP ACI value for video AC */
1018 #define EDCF_AC_VI_ECW_AP            0x43	/* AP ECW value for video AC */
1019 #define EDCF_AC_VI_TXOP_AP           0x005e	/* AP TXOP value for video AC */
1020 #define EDCF_AC_VO_ACI_AP            0x61	/* AP ACI value for audio AC */
1021 #define EDCF_AC_VO_ECW_AP            0x32	/* AP ECW value for audio AC */
1022 #define EDCF_AC_VO_TXOP_AP           0x002f	/* AP TXOP value for audio AC */
1023 
1024 /** EDCA Parameter IE */
1025 BWL_PRE_PACKED_STRUCT struct edca_param_ie {
1026 	uint8 qosinfo;
1027 	uint8 rsvd;
1028 	edcf_acparam_t acparam[AC_COUNT];
1029 } BWL_POST_PACKED_STRUCT;
1030 typedef struct edca_param_ie edca_param_ie_t;
1031 #define EDCA_PARAM_IE_LEN            18          /* EDCA Parameter IE length */
1032 
1033 /** QoS Capability IE */
1034 BWL_PRE_PACKED_STRUCT struct qos_cap_ie {
1035 	uint8 qosinfo;
1036 } BWL_POST_PACKED_STRUCT;
1037 typedef struct qos_cap_ie qos_cap_ie_t;
1038 
1039 BWL_PRE_PACKED_STRUCT struct dot11_qbss_load_ie {
1040 	uint8 id;			/* 11, DOT11_MNG_QBSS_LOAD_ID */
1041 	uint8 length;
1042 	uint16 station_count;		/* total number of STAs associated */
1043 	uint8 channel_utilization;	/* % of time, normalized to 255, QAP sensed medium busy */
1044 	uint16 aac;			/* available admission capacity */
1045 } BWL_POST_PACKED_STRUCT;
1046 typedef struct dot11_qbss_load_ie dot11_qbss_load_ie_t;
1047 #define BSS_LOAD_IE_SIZE	7	/* BSS load IE size */
1048 
1049 #define WLC_QBSS_LOAD_CHAN_FREE_MAX	0xff	/* max for channel free score */
1050 
1051 /* Estimated Service Parameters (ESP) IE - 802.11-2016 9.4.2.174 */
1052 typedef BWL_PRE_PACKED_STRUCT struct dot11_esp_ie {
1053 	uint8		id;
1054 	uint8		length;
1055 	uint8		id_ext;
1056 	/* variable len info */
1057 	uint8		esp_info_lists[];
1058 } BWL_POST_PACKED_STRUCT dot11_esp_ie_t;
1059 
1060 #define DOT11_ESP_IE_HDR_SIZE	(OFFSETOF(dot11_esp_ie_t, esp_info_lists))
1061 
1062 /* ESP Information list - 802.11-2016 9.4.2.174 */
1063 typedef BWL_PRE_PACKED_STRUCT struct dot11_esp_ie_info_list {
1064 	/* acess category, data format, ba win size */
1065 	uint8		ac_df_baws;
1066 	/* estimated air time fraction */
1067 	uint8		eat_frac;
1068 	/* data PPDU duration target (50us units) */
1069 	uint8		ppdu_dur;
1070 } BWL_POST_PACKED_STRUCT dot11_esp_ie_info_list_t;
1071 
1072 #define DOT11_ESP_IE_INFO_LIST_SIZE	(sizeof(dot11_esp_ie_info_list_t))
1073 
1074 #define DOT11_ESP_NBR_INFO_LISTS	4u	/* max nbr of esp information lists */
1075 #define DOT11_ESP_INFO_LIST_AC_BK	0u	/* access category of esp information list AC_BK */
1076 #define DOT11_ESP_INFO_LIST_AC_BE	1u	/* access category of esp information list AC_BE */
1077 #define DOT11_ESP_INFO_LIST_AC_VI	2u	/* access category of esp information list AC_VI */
1078 #define DOT11_ESP_INFO_LIST_AC_VO	3u	/* access category of esp information list AC_VO */
1079 
1080 #define DOT11_ESP_INFO_LIST_DF_MASK    0x18		/* Data Format Mask */
1081 #define DOT11_ESP_INFO_LIST_BAWS_MASK  0xE0		/* BA window size mask */
1082 
1083 /* nom_msdu_size */
1084 #define FIXED_MSDU_SIZE 0x8000		/* MSDU size is fixed */
1085 #define MSDU_SIZE_MASK	0x7fff		/* (Nominal or fixed) MSDU size */
1086 
1087 /* surplus_bandwidth */
1088 /* Represented as 3 bits of integer, binary point, 13 bits fraction */
1089 #define	INTEGER_SHIFT	13	/* integer shift */
1090 #define FRACTION_MASK	0x1FFF	/* fraction mask */
1091 
1092 /** Management Notification Frame */
1093 BWL_PRE_PACKED_STRUCT struct dot11_management_notification {
1094 	uint8 category;			/* DOT11_ACTION_NOTIFICATION */
1095 	uint8 action;
1096 	uint8 token;
1097 	uint8 status;
1098 	uint8 data[1];			/* Elements */
1099 } BWL_POST_PACKED_STRUCT;
1100 #define DOT11_MGMT_NOTIFICATION_LEN 4	/* Fixed length */
1101 
1102 /** Timeout Interval IE */
1103 BWL_PRE_PACKED_STRUCT struct ti_ie {
1104 	uint8 ti_type;
1105 	uint32 ti_val;
1106 } BWL_POST_PACKED_STRUCT;
1107 typedef struct ti_ie ti_ie_t;
1108 #define TI_TYPE_REASSOC_DEADLINE	1
1109 #define TI_TYPE_KEY_LIFETIME		2
1110 
1111 #ifndef CISCO_AIRONET_OUI
1112 #define CISCO_AIRONET_OUI	"\x00\x40\x96"	/* Cisco AIRONET OUI */
1113 #endif
1114 /* QoS FastLane IE. */
1115 BWL_PRE_PACKED_STRUCT struct ccx_qfl_ie {
1116 	uint8	id;		/* 221, DOT11_MNG_VS_ID */
1117 	uint8	length;		/* 5 */
1118 	uint8	oui[3];		/* 00:40:96 */
1119 	uint8	type;		/* 11 */
1120 	uint8	data;
1121 } BWL_POST_PACKED_STRUCT;
1122 typedef struct ccx_qfl_ie ccx_qfl_ie_t;
1123 #define CCX_QFL_IE_TYPE	11
1124 #define CCX_QFL_ENABLE_SHIFT	5
1125 #define CCX_QFL_ENALBE (1 << CCX_QFL_ENABLE_SHIFT)
1126 
1127 /* WME Action Codes */
1128 #define WME_ADDTS_REQUEST	0	/* WME ADDTS request */
1129 #define WME_ADDTS_RESPONSE	1	/* WME ADDTS response */
1130 #define WME_DELTS_REQUEST	2	/* WME DELTS request */
1131 
1132 /* WME Setup Response Status Codes */
1133 #define WME_ADMISSION_ACCEPTED		0	/* WME admission accepted */
1134 #define WME_INVALID_PARAMETERS		1	/* WME invalide parameters */
1135 #define WME_ADMISSION_REFUSED		3	/* WME admission refused */
1136 
1137 /* Macro to take a pointer to a beacon or probe response
1138  * body and return the char* pointer to the SSID info element
1139  */
1140 #define BCN_PRB_SSID(body) ((char*)(body) + DOT11_BCN_PRB_LEN)
1141 
1142 /* Authentication frame payload constants */
1143 #define DOT11_OPEN_SYSTEM	0	/* d11 open authentication */
1144 #define DOT11_SHARED_KEY	1	/* d11 shared authentication */
1145 #define DOT11_FAST_BSS		2	/* d11 fast bss authentication */
1146 #define DOT11_SAE		3	/* d11 simultaneous authentication of equals */
1147 #define DOT11_FILS_SKEY		4	/* d11 fils shared key authentication w/o pfs */
1148 #define DOT11_FILS_SKEY_PFS	5	/* d11 fils shared key authentication w/ pfs */
1149 #define DOT11_FILS_PKEY		6	/* d11 fils public key authentication */
1150 #define DOT11_MAX_AUTH_ALG  DOT11_FILS_PKEY /* maximum value of an auth alg */
1151 #define DOT11_CHALLENGE_LEN	128	/* d11 challenge text length */
1152 
1153 /* Frame control macros */
1154 #define FC_PVER_MASK		0x3	/* PVER mask */
1155 #define FC_PVER_SHIFT		0	/* PVER shift */
1156 #define FC_TYPE_MASK		0xC	/* type mask */
1157 #define FC_TYPE_SHIFT		2	/* type shift */
1158 #define FC_SUBTYPE_MASK		0xF0	/* subtype mask */
1159 #define FC_SUBTYPE_SHIFT	4	/* subtype shift */
1160 #define FC_TODS			0x100	/* to DS */
1161 #define FC_TODS_SHIFT		8	/* to DS shift */
1162 #define FC_FROMDS		0x200	/* from DS */
1163 #define FC_FROMDS_SHIFT		9	/* from DS shift */
1164 #define FC_MOREFRAG		0x400	/* more frag. */
1165 #define FC_MOREFRAG_SHIFT	10	/* more frag. shift */
1166 #define FC_RETRY		0x800	/* retry */
1167 #define FC_RETRY_SHIFT		11	/* retry shift */
1168 #define FC_PM			0x1000	/* PM */
1169 #define FC_PM_SHIFT		12	/* PM shift */
1170 #define FC_MOREDATA		0x2000	/* more data */
1171 #define FC_MOREDATA_SHIFT	13	/* more data shift */
1172 #define FC_WEP			0x4000	/* WEP */
1173 #define FC_WEP_SHIFT		14	/* WEP shift */
1174 #define FC_ORDER		0x8000	/* order */
1175 #define FC_ORDER_SHIFT		15	/* order shift */
1176 
1177 /* sequence control macros */
1178 #define SEQNUM_SHIFT		4	/* seq. number shift */
1179 #define SEQNUM_MAX		0x1000	/* max seqnum + 1 */
1180 #define FRAGNUM_MASK		0xF	/* frag. number mask */
1181 
1182 /* Frame Control type/subtype defs */
1183 
1184 /* FC Types */
1185 #define FC_TYPE_MNG		0	/* management type */
1186 #define FC_TYPE_CTL		1	/* control type */
1187 #define FC_TYPE_DATA		2	/* data type */
1188 
1189 /* Management Subtypes */
1190 #define FC_SUBTYPE_ASSOC_REQ		0	/* assoc. request */
1191 #define FC_SUBTYPE_ASSOC_RESP		1	/* assoc. response */
1192 #define FC_SUBTYPE_REASSOC_REQ		2	/* reassoc. request */
1193 #define FC_SUBTYPE_REASSOC_RESP		3	/* reassoc. response */
1194 #define FC_SUBTYPE_PROBE_REQ		4	/* probe request */
1195 #define FC_SUBTYPE_PROBE_RESP		5	/* probe response */
1196 #define FC_SUBTYPE_BEACON		8	/* beacon */
1197 #define FC_SUBTYPE_ATIM			9	/* ATIM */
1198 #define FC_SUBTYPE_DISASSOC		10	/* disassoc. */
1199 #define FC_SUBTYPE_AUTH			11	/* authentication */
1200 #define FC_SUBTYPE_DEAUTH		12	/* de-authentication */
1201 #define FC_SUBTYPE_ACTION		13	/* action */
1202 #define FC_SUBTYPE_ACTION_NOACK		14	/* action no-ack */
1203 
1204 /* Control Subtypes */
1205 #define FC_SUBTYPE_TRIGGER		2	/* Trigger frame */
1206 #define FC_SUBTYPE_NDPA                 5	/* NDPA  */
1207 #define FC_SUBTYPE_CTL_WRAPPER		7	/* Control Wrapper */
1208 #define FC_SUBTYPE_BLOCKACK_REQ		8	/* Block Ack Req */
1209 #define FC_SUBTYPE_BLOCKACK		9	/* Block Ack */
1210 #define FC_SUBTYPE_PS_POLL		10	/* PS poll */
1211 #define FC_SUBTYPE_RTS			11	/* RTS */
1212 #define FC_SUBTYPE_CTS			12	/* CTS */
1213 #define FC_SUBTYPE_ACK			13	/* ACK */
1214 #define FC_SUBTYPE_CF_END		14	/* CF-END */
1215 #define FC_SUBTYPE_CF_END_ACK		15	/* CF-END ACK */
1216 
1217 /* Data Subtypes */
1218 #define FC_SUBTYPE_DATA			0	/* Data */
1219 #define FC_SUBTYPE_DATA_CF_ACK		1	/* Data + CF-ACK */
1220 #define FC_SUBTYPE_DATA_CF_POLL		2	/* Data + CF-Poll */
1221 #define FC_SUBTYPE_DATA_CF_ACK_POLL	3	/* Data + CF-Ack + CF-Poll */
1222 #define FC_SUBTYPE_NULL			4	/* Null */
1223 #define FC_SUBTYPE_CF_ACK		5	/* CF-Ack */
1224 #define FC_SUBTYPE_CF_POLL		6	/* CF-Poll */
1225 #define FC_SUBTYPE_CF_ACK_POLL		7	/* CF-Ack + CF-Poll */
1226 #define FC_SUBTYPE_QOS_DATA		8	/* QoS Data */
1227 #define FC_SUBTYPE_QOS_DATA_CF_ACK	9	/* QoS Data + CF-Ack */
1228 #define FC_SUBTYPE_QOS_DATA_CF_POLL	10	/* QoS Data + CF-Poll */
1229 #define FC_SUBTYPE_QOS_DATA_CF_ACK_POLL	11	/* QoS Data + CF-Ack + CF-Poll */
1230 #define FC_SUBTYPE_QOS_NULL		12	/* QoS Null */
1231 #define FC_SUBTYPE_QOS_CF_POLL		14	/* QoS CF-Poll */
1232 #define FC_SUBTYPE_QOS_CF_ACK_POLL	15	/* QoS CF-Ack + CF-Poll */
1233 
1234 /* Data Subtype Groups */
1235 #define FC_SUBTYPE_ANY_QOS(s)		(((s) & 8) != 0)
1236 #define FC_SUBTYPE_ANY_NULL(s)		(((s) & 4) != 0)
1237 #define FC_SUBTYPE_ANY_CF_POLL(s)	(((s) & 2) != 0)
1238 #define FC_SUBTYPE_ANY_CF_ACK(s)	(((s) & 1) != 0)
1239 #define FC_SUBTYPE_ANY_PSPOLL(s)	(((s) & 10) != 0)
1240 
1241 /* Type/Subtype Combos */
1242 #define FC_KIND_MASK		(FC_TYPE_MASK | FC_SUBTYPE_MASK)	/* FC kind mask */
1243 
1244 #define FC_KIND(t, s)	(((t) << FC_TYPE_SHIFT) | ((s) << FC_SUBTYPE_SHIFT))	/* FC kind */
1245 
1246 #define FC_SUBTYPE(fc)	(((fc) & FC_SUBTYPE_MASK) >> FC_SUBTYPE_SHIFT)	/* Subtype from FC */
1247 #define FC_TYPE(fc)	(((fc) & FC_TYPE_MASK) >> FC_TYPE_SHIFT)	/* Type from FC */
1248 
1249 #define FC_ASSOC_REQ	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_ASSOC_REQ)	/* assoc. request */
1250 #define FC_ASSOC_RESP	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_ASSOC_RESP)	/* assoc. response */
1251 #define FC_REASSOC_REQ	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_REASSOC_REQ)	/* reassoc. request */
1252 #define FC_REASSOC_RESP	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_REASSOC_RESP)	/* reassoc. response */
1253 #define FC_PROBE_REQ	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_PROBE_REQ)	/* probe request */
1254 #define FC_PROBE_RESP	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_PROBE_RESP)	/* probe response */
1255 #define FC_BEACON	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_BEACON)		/* beacon */
1256 #define FC_ATIM		FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_ATIM)		/* ATIM */
1257 #define FC_DISASSOC	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_DISASSOC)	/* disassoc */
1258 #define FC_AUTH		FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_AUTH)		/* authentication */
1259 #define FC_DEAUTH	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_DEAUTH)		/* deauthentication */
1260 #define FC_ACTION	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_ACTION)		/* action */
1261 #define FC_ACTION_NOACK	FC_KIND(FC_TYPE_MNG, FC_SUBTYPE_ACTION_NOACK)	/* action no-ack */
1262 
1263 #define FC_CTL_TRIGGER	FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_TRIGGER)	/* Trigger frame */
1264 #define FC_CTL_NDPA	FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_NDPA)	/* NDPA frame */
1265 #define FC_CTL_WRAPPER	FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_CTL_WRAPPER)	/* Control Wrapper */
1266 #define FC_BLOCKACK_REQ	FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_BLOCKACK_REQ)	/* Block Ack Req */
1267 #define FC_BLOCKACK	FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_BLOCKACK)	/* Block Ack */
1268 #define FC_PS_POLL	FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_PS_POLL)	/* PS poll */
1269 #define FC_RTS		FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_RTS)		/* RTS */
1270 #define FC_CTS		FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_CTS)		/* CTS */
1271 #define FC_ACK		FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_ACK)		/* ACK */
1272 #define FC_CF_END	FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_CF_END)		/* CF-END */
1273 #define FC_CF_END_ACK	FC_KIND(FC_TYPE_CTL, FC_SUBTYPE_CF_END_ACK)	/* CF-END ACK */
1274 
1275 #define FC_DATA		FC_KIND(FC_TYPE_DATA, FC_SUBTYPE_DATA)		/* data */
1276 #define FC_NULL_DATA	FC_KIND(FC_TYPE_DATA, FC_SUBTYPE_NULL)		/* null data */
1277 #define FC_DATA_CF_ACK	FC_KIND(FC_TYPE_DATA, FC_SUBTYPE_DATA_CF_ACK)	/* data CF ACK */
1278 #define FC_QOS_DATA	FC_KIND(FC_TYPE_DATA, FC_SUBTYPE_QOS_DATA)	/* QoS data */
1279 #define FC_QOS_NULL	FC_KIND(FC_TYPE_DATA, FC_SUBTYPE_QOS_NULL)	/* QoS null */
1280 
1281 /* QoS Control Field */
1282 
1283 /* 802.1D Priority */
1284 #define QOS_PRIO_SHIFT		0	/* QoS priority shift */
1285 #define QOS_PRIO_MASK		0x0007	/* QoS priority mask */
1286 #define QOS_PRIO(qos)		(((qos) & QOS_PRIO_MASK) >> QOS_PRIO_SHIFT)	/* QoS priority */
1287 
1288 /* Traffic Identifier */
1289 #define QOS_TID_SHIFT		0	/* QoS TID shift */
1290 #define QOS_TID_MASK		0x000f	/* QoS TID mask */
1291 #define QOS_TID(qos)		(((qos) & QOS_TID_MASK) >> QOS_TID_SHIFT)	/* QoS TID */
1292 
1293 /* End of Service Period (U-APSD) */
1294 #define QOS_EOSP_SHIFT		4	/* QoS End of Service Period shift */
1295 #define QOS_EOSP_MASK		0x0010	/* QoS End of Service Period mask */
1296 #define QOS_EOSP(qos)		(((qos) & QOS_EOSP_MASK) >> QOS_EOSP_SHIFT)	/* Qos EOSP */
1297 
1298 /* Ack Policy */
1299 #define QOS_ACK_NORMAL_ACK	0	/* Normal Ack */
1300 #define QOS_ACK_NO_ACK		1	/* No Ack (eg mcast) */
1301 #define QOS_ACK_NO_EXP_ACK	2	/* No Explicit Ack */
1302 #define QOS_ACK_BLOCK_ACK	3	/* Block Ack */
1303 #define QOS_ACK_SHIFT		5	/* QoS ACK shift */
1304 #define QOS_ACK_MASK		0x0060	/* QoS ACK mask */
1305 #define QOS_ACK(qos)		(((qos) & QOS_ACK_MASK) >> QOS_ACK_SHIFT)	/* QoS ACK */
1306 
1307 /* A-MSDU flag */
1308 #define QOS_AMSDU_SHIFT		7	/* AMSDU shift */
1309 #define QOS_AMSDU_MASK		0x0080	/* AMSDU mask */
1310 
1311 /* QOS Mesh Flags */
1312 #define QOS_MESH_CTL_FLAG       0x0100u // Mesh Control Present
1313 #define QOS_MESH_PSL_FLAG       0x0200u // Mesh Power Save Level
1314 #define QOS_MESH_RSPI_FLAG      0x0400u // Mesh RSPI
1315 
1316 /* QOS Mesh Accessor macros */
1317 #define QOS_MESH_CTL(qos)       (((qos) & QOS_MESH_CTL_FLAG) != 0)
1318 #define QOS_MESH_PSL(qos)       (((qos) & QOS_MESH_PSL_FLAG) != 0)
1319 #define QOS_MESH_RSPI(qos)      (((qos) & QOS_MESH_RSPI_FLAG) != 0)
1320 
1321 /* Management Frames */
1322 
1323 /* Management Frame Constants */
1324 
1325 /* Fixed fields */
1326 #define DOT11_MNG_AUTH_ALGO_LEN		2	/* d11 management auth. algo. length */
1327 #define DOT11_MNG_AUTH_SEQ_LEN		2	/* d11 management auth. seq. length */
1328 #define DOT11_MNG_BEACON_INT_LEN	2	/* d11 management beacon interval length */
1329 #define DOT11_MNG_CAP_LEN		2	/* d11 management cap. length */
1330 #define DOT11_MNG_AP_ADDR_LEN		6	/* d11 management AP address length */
1331 #define DOT11_MNG_LISTEN_INT_LEN	2	/* d11 management listen interval length */
1332 #define DOT11_MNG_REASON_LEN		2	/* d11 management reason length */
1333 #define DOT11_MNG_AID_LEN		2	/* d11 management AID length */
1334 #define DOT11_MNG_STATUS_LEN		2	/* d11 management status length */
1335 #define DOT11_MNG_TIMESTAMP_LEN		8	/* d11 management timestamp length */
1336 
1337 /* DUR/ID field in assoc resp is 0xc000 | AID */
1338 #define DOT11_AID_MASK				0x3fff	/* d11 AID mask */
1339 #define DOT11_AID_OCTET_VAL_SHIFT		3u	/* AID octet value shift */
1340 #define DOT11_AID_BIT_POS_IN_OCTET		0x07	/* AID bit position in octet */
1341 
1342 /* Reason Codes */
1343 #define DOT11_RC_RESERVED		0	/* d11 RC reserved */
1344 #define DOT11_RC_UNSPECIFIED		1	/* Unspecified reason */
1345 #define DOT11_RC_AUTH_INVAL		2	/* Previous authentication no longer valid */
1346 #define DOT11_RC_DEAUTH_LEAVING		3	/* Deauthenticated because sending station
1347 						 * is leaving (or has left) IBSS or ESS
1348 						 */
1349 #define DOT11_RC_INACTIVITY		4	/* Disassociated due to inactivity */
1350 #define DOT11_RC_BUSY			5	/* Disassociated because AP is unable to handle
1351 						 * all currently associated stations
1352 						 */
1353 #define DOT11_RC_INVAL_CLASS_2		6	/* Class 2 frame received from
1354 						 * nonauthenticated station
1355 						 */
1356 #define DOT11_RC_INVAL_CLASS_3		7	/* Class 3 frame received from
1357 						 *  nonassociated station
1358 						 */
1359 #define DOT11_RC_DISASSOC_LEAVING	8	/* Disassociated because sending station is
1360 						 * leaving (or has left) BSS
1361 						 */
1362 #define DOT11_RC_NOT_AUTH		9	/* Station requesting (re)association is not
1363 						 * authenticated with responding station
1364 						 */
1365 #define DOT11_RC_BAD_PC			10	/* Unacceptable power capability element */
1366 #define DOT11_RC_BAD_CHANNELS		11	/* Unacceptable supported channels element */
1367 
1368 /* 12 is unused by STA but could be used by AP/GO */
1369 #define DOT11_RC_DISASSOC_BTM		12	/* Disassociated due to BSS Transition Magmt */
1370 
1371 /* 13-23 are WPA/802.11i reason codes defined in wpa.h */
1372 
1373 /* 32-39 are QSTA specific reasons added in 11e */
1374 #define DOT11_RC_UNSPECIFIED_QOS	32	/* unspecified QoS-related reason */
1375 #define DOT11_RC_INSUFFCIENT_BW		33	/* QAP lacks sufficient bandwidth */
1376 #define DOT11_RC_EXCESSIVE_FRAMES	34	/* excessive number of frames need ack */
1377 #define DOT11_RC_TX_OUTSIDE_TXOP	35	/* transmitting outside the limits of txop */
1378 #define DOT11_RC_LEAVING_QBSS		36	/* QSTA is leaving the QBSS (or restting) */
1379 #define DOT11_RC_BAD_MECHANISM		37	/* does not want to use the mechanism */
1380 #define DOT11_RC_SETUP_NEEDED		38	/* mechanism needs a setup */
1381 #define DOT11_RC_TIMEOUT		39	/* timeout */
1382 
1383 #define DOT11_RC_MESH_PEERING_CANCELLED		52
1384 #define DOT11_RC_MESH_MAX_PEERS			53
1385 #define DOT11_RC_MESH_CONFIG_POLICY_VIOLN	54
1386 #define DOT11_RC_MESH_CLOSE_RECVD		55
1387 #define DOT11_RC_MESH_MAX_RETRIES		56
1388 #define DOT11_RC_MESH_CONFIRM_TIMEOUT		57
1389 #define DOT11_RC_MESH_INVALID_GTK		58
1390 #define DOT11_RC_MESH_INCONSISTENT_PARAMS	59
1391 
1392 #define DOT11_RC_MESH_INVALID_SEC_CAP		60
1393 #define DOT11_RC_MESH_PATHERR_NOPROXYINFO	61
1394 #define DOT11_RC_MESH_PATHERR_NOFWINFO		62
1395 #define DOT11_RC_MESH_PATHERR_DSTUNREACH	63
1396 #define DOT11_RC_MESH_MBSSMAC_EXISTS		64
1397 #define DOT11_RC_MESH_CHANSWITCH_REGREQ		65
1398 #define DOT11_RC_MESH_CHANSWITCH_UNSPEC		66
1399 
1400 #define DOT11_RC_POOR_RSSI_CONDITIONS		71	/* Poor RSSI */
1401 #define DOT11_RC_MAX			71	/* Reason codes > 71 are reserved */
1402 
1403 #define DOT11_RC_TDLS_PEER_UNREACH	25
1404 #define DOT11_RC_TDLS_DOWN_UNSPECIFIED	26
1405 
1406 /* Status Codes */
1407 #define DOT11_SC_SUCCESS		0	/* Successful */
1408 #define DOT11_SC_FAILURE		1	/* Unspecified failure */
1409 #define DOT11_SC_TDLS_WAKEUP_SCH_ALT 2	/* TDLS wakeup schedule rejected but alternative  */
1410 					/* schedule provided */
1411 #define DOT11_SC_TDLS_WAKEUP_SCH_REJ 3	/* TDLS wakeup schedule rejected */
1412 #define DOT11_SC_TDLS_SEC_DISABLED	5	/* TDLS Security disabled */
1413 #define DOT11_SC_LIFETIME_REJ		6	/* Unacceptable lifetime */
1414 #define DOT11_SC_NOT_SAME_BSS		7	/* Not in same BSS */
1415 #define DOT11_SC_CAP_MISMATCH		10	/* Cannot support all requested
1416 						 * capabilities in the Capability
1417 						 * Information field
1418 						 */
1419 #define DOT11_SC_REASSOC_FAIL		11	/* Reassociation denied due to inability
1420 						 * to confirm that association exists
1421 						 */
1422 #define DOT11_SC_ASSOC_FAIL		12	/* Association denied due to reason
1423 						 * outside the scope of this standard
1424 						 */
1425 #define DOT11_SC_AUTH_MISMATCH		13	/* Responding station does not support
1426 						 * the specified authentication
1427 						 * algorithm
1428 						 */
1429 #define DOT11_SC_AUTH_SEQ		14	/* Received an Authentication frame
1430 						 * with authentication transaction
1431 						 * sequence number out of expected
1432 						 * sequence
1433 						 */
1434 #define DOT11_SC_AUTH_CHALLENGE_FAIL	15	/* Authentication rejected because of
1435 						 * challenge failure
1436 						 */
1437 #define DOT11_SC_AUTH_TIMEOUT		16	/* Authentication rejected due to timeout
1438 						 * waiting for next frame in sequence
1439 						 */
1440 #define DOT11_SC_ASSOC_BUSY_FAIL	17	/* Association denied because AP is
1441 						 * unable to handle additional
1442 						 * associated stations
1443 						 */
1444 #define DOT11_SC_ASSOC_RATE_MISMATCH	18	/* Association denied due to requesting
1445 						 * station not supporting all of the
1446 						 * data rates in the BSSBasicRateSet
1447 						 * parameter
1448 						 */
1449 #define DOT11_SC_ASSOC_SHORT_REQUIRED	19	/* Association denied due to requesting
1450 						 * station not supporting the Short
1451 						 * Preamble option
1452 						 */
1453 #define DOT11_SC_ASSOC_PBCC_REQUIRED	20	/* Association denied due to requesting
1454 						 * station not supporting the PBCC
1455 						 * Modulation option
1456 						 */
1457 #define DOT11_SC_ASSOC_AGILITY_REQUIRED	21	/* Association denied due to requesting
1458 						 * station not supporting the Channel
1459 						 * Agility option
1460 						 */
1461 #define DOT11_SC_ASSOC_SPECTRUM_REQUIRED	22	/* Association denied because Spectrum
1462 							 * Management capability is required.
1463 							 */
1464 #define DOT11_SC_ASSOC_BAD_POWER_CAP	23	/* Association denied because the info
1465 						 * in the Power Cap element is
1466 						 * unacceptable.
1467 						 */
1468 #define DOT11_SC_ASSOC_BAD_SUP_CHANNELS	24	/* Association denied because the info
1469 						 * in the Supported Channel element is
1470 						 * unacceptable
1471 						 */
1472 #define DOT11_SC_ASSOC_SHORTSLOT_REQUIRED	25	/* Association denied due to requesting
1473 							 * station not supporting the Short Slot
1474 							 * Time option
1475 							 */
1476 #define DOT11_SC_ASSOC_DSSSOFDM_REQUIRED 26	/* Association denied because requesting station
1477 						 * does not support the DSSS-OFDM option
1478 						 */
1479 #define DOT11_SC_ASSOC_HT_REQUIRED	27	/* Association denied because the requesting
1480 						 * station does not support HT features
1481 						 */
1482 #define DOT11_SC_ASSOC_R0KH_UNREACHABLE	28	/* Association denied due to AP
1483 						 * being unable to reach the R0 Key Holder
1484 						 */
1485 #define DOT11_SC_ASSOC_TRY_LATER	30	/* Association denied temporarily, try again later
1486 						 */
1487 #define DOT11_SC_ASSOC_MFP_VIOLATION	31	/* Association denied due to Robust Management
1488 						 * frame policy violation
1489 						 */
1490 
1491 #define DOT11_SC_POOR_RSSI_CONDN	34	/* Association denied due to poor RSSI */
1492 #define	DOT11_SC_DECLINED		37	/* request declined */
1493 #define	DOT11_SC_INVALID_PARAMS		38	/* One or more params have invalid values */
1494 #define DOT11_SC_INVALID_PAIRWISE_CIPHER	42 /* invalid pairwise cipher */
1495 #define	DOT11_SC_INVALID_AKMP		43	/* Association denied due to invalid AKMP */
1496 #define DOT11_SC_INVALID_RSNIE_CAP	45	/* invalid RSN IE capabilities */
1497 #define DOT11_SC_DLS_NOT_ALLOWED	48	/* DLS is not allowed in the BSS by policy */
1498 #define	DOT11_SC_INVALID_PMKID		53	/* Association denied due to invalid PMKID */
1499 #define	DOT11_SC_INVALID_MDID		54	/* Association denied due to invalid MDID */
1500 #define	DOT11_SC_INVALID_FTIE		55	/* Association denied due to invalid FTIE */
1501 
1502 #define DOT11_SC_ADV_PROTO_NOT_SUPPORTED	59	/* ad proto not supported */
1503 #define DOT11_SC_NO_OUTSTAND_REQ			60	/* no outstanding req */
1504 #define DOT11_SC_RSP_NOT_RX_FROM_SERVER		61	/* no response from server */
1505 #define DOT11_SC_TIMEOUT					62	/* timeout */
1506 #define DOT11_SC_QUERY_RSP_TOO_LARGE		63	/* query rsp too large */
1507 #define DOT11_SC_SERVER_UNREACHABLE			65	/* server unreachable */
1508 
1509 #define DOT11_SC_UNEXP_MSG			70	/* Unexpected message */
1510 #define DOT11_SC_INVALID_SNONCE		71	/* Invalid SNonce */
1511 #define DOT11_SC_INVALID_RSNIE		72	/* Invalid contents of RSNIE */
1512 
1513 #define DOT11_SC_ANTICLOG_TOCKEN_REQUIRED	76	/* Anti-clogging tocken required */
1514 #define DOT11_SC_INVALID_FINITE_CYCLIC_GRP	77	/* Invalid contents of RSNIE */
1515 #define DOT11_SC_TRANSMIT_FAILURE		79      /* transmission failure */
1516 
1517 #define DOT11_SC_TCLAS_RESOURCES_EXHAUSTED	81u	/* TCLAS resources exhausted */
1518 
1519 #define DOT11_SC_TCLAS_PROCESSING_TERMINATED	97	/* End traffic classification */
1520 
1521 #define DOT11_SC_ASSOC_VHT_REQUIRED		104	/* Association denied because the requesting
1522 							 * station does not support VHT features.
1523 							 */
1524 #define DOT11_SC_UNKNOWN_PASSWORD_IDENTIFIER	123u	/* mismatch of password id */
1525 
1526 #define DOT11_SC_SAE_HASH_TO_ELEMENT		126u	/* SAE Hash-to-element PWE required */
1527 #define DOT11_SC_SAE_PK				127u	/* SAE PK required */
1528 
1529 /* Requested TCLAS processing has been terminated by the AP due to insufficient QoS capacity. */
1530 #define DOT11_SC_TCLAS_PROCESSING_TERMINATED_INSUFFICIENT_QOS	128u
1531 
1532 /* Requested TCLAS processing has been terminated by the AP due to conflict with
1533  * higher layer QoS policies.
1534  */
1535 #define DOT11_SC_TCLAS_PROCESSING_TERMINATED_POLICY_CONFLICT	129u
1536 
1537 /* Info Elts, length of INFORMATION portion of Info Elts */
1538 #define DOT11_MNG_DS_PARAM_LEN			1	/* d11 management DS parameter length */
1539 #define DOT11_MNG_IBSS_PARAM_LEN		2	/* d11 management IBSS parameter length */
1540 
1541 /* TIM Info element has 3 bytes fixed info in INFORMATION field,
1542  * followed by 1 to 251 bytes of Partial Virtual Bitmap
1543  */
1544 #define DOT11_MNG_TIM_FIXED_LEN			3	/* d11 management TIM fixed length */
1545 #define DOT11_MNG_TIM_DTIM_COUNT		0	/* d11 management DTIM count */
1546 #define DOT11_MNG_TIM_DTIM_PERIOD		1	/* d11 management DTIM period */
1547 #define DOT11_MNG_TIM_BITMAP_CTL		2	/* d11 management TIM BITMAP control  */
1548 #define DOT11_MNG_TIM_PVB			3	/* d11 management TIM PVB */
1549 
1550 #define DOT11_MNG_TIM_BITMAP_CTL_BCMC_MASK	0x01	/* Mask for bcmc bit in tim bitmap ctrl */
1551 #define DOT11_MNG_TIM_BITMAP_CTL_PVBOFF_MASK	0xFE	/* Mask for partial virtual bitmap */
1552 
1553 /* TLV defines */
1554 #define TLV_TAG_OFF         0	/* tag offset */
1555 #define TLV_LEN_OFF         1	/* length offset */
1556 #define TLV_HDR_LEN         2	/* header length */
1557 #define TLV_BODY_OFF        2	/* body offset */
1558 #define TLV_BODY_LEN_MAX    255	/* max body length */
1559 #define TLV_EXT_HDR_LEN     3u  /* extended IE header length */
1560 #define TLV_EXT_BODY_OFF    3u  /* extended IE body offset */
1561 
1562 /* Management Frame Information Element IDs */
1563 enum dot11_tag_ids {
1564 	DOT11_MNG_SSID_ID			= 0,	/* d11 management SSID id */
1565 	DOT11_MNG_RATES_ID			= 1,	/* d11 management rates id */
1566 	DOT11_MNG_FH_PARMS_ID			= 2,	/* d11 management FH parameter id */
1567 	DOT11_MNG_DS_PARMS_ID			= 3,	/* d11 management DS parameter id */
1568 	DOT11_MNG_CF_PARMS_ID			= 4,	/* d11 management CF parameter id */
1569 	DOT11_MNG_TIM_ID			= 5,	/* d11 management TIM id */
1570 	DOT11_MNG_IBSS_PARMS_ID			= 6,	/* d11 management IBSS parameter id */
1571 	DOT11_MNG_COUNTRY_ID			= 7,	/* d11 management country id */
1572 	DOT11_MNG_HOPPING_PARMS_ID		= 8,	/* d11 management hopping parameter id */
1573 	DOT11_MNG_HOPPING_TABLE_ID		= 9,	/* d11 management hopping table id */
1574 	DOT11_MNG_FTM_SYNC_INFO_ID		= 9,	/* 11mc D4.3 */
1575 	DOT11_MNG_REQUEST_ID			= 10,	/* d11 management request id */
1576 	DOT11_MNG_QBSS_LOAD_ID			= 11,	/* d11 management QBSS Load id */
1577 	DOT11_MNG_EDCA_PARAM_ID			= 12,	/* 11E EDCA Parameter id */
1578 	DOT11_MNG_TSPEC_ID			= 13,	/* d11 management TSPEC id */
1579 	DOT11_MNG_TCLAS_ID			= 14,	/* d11 management TCLAS id */
1580 	DOT11_MNG_CHALLENGE_ID			= 16,	/* d11 management chanllenge id */
1581 	DOT11_MNG_PWR_CONSTRAINT_ID		= 32,	/* 11H PowerConstraint */
1582 	DOT11_MNG_PWR_CAP_ID			= 33,	/* 11H PowerCapability */
1583 	DOT11_MNG_TPC_REQUEST_ID		= 34,	/* 11H TPC Request */
1584 	DOT11_MNG_TPC_REPORT_ID			= 35,	/* 11H TPC Report */
1585 	DOT11_MNG_SUPP_CHANNELS_ID		= 36,	/* 11H Supported Channels */
1586 	DOT11_MNG_CHANNEL_SWITCH_ID		= 37,	/* 11H ChannelSwitch Announcement */
1587 	DOT11_MNG_MEASURE_REQUEST_ID		= 38,	/* 11H MeasurementRequest */
1588 	DOT11_MNG_MEASURE_REPORT_ID		= 39,	/* 11H MeasurementReport */
1589 	DOT11_MNG_QUIET_ID			= 40,	/* 11H Quiet */
1590 	DOT11_MNG_IBSS_DFS_ID			= 41,	/* 11H IBSS_DFS */
1591 	DOT11_MNG_ERP_ID			= 42,	/* d11 management ERP id */
1592 	DOT11_MNG_TS_DELAY_ID			= 43,	/* d11 management TS Delay id */
1593 	DOT11_MNG_TCLAS_PROC_ID			= 44,	/* d11 management TCLAS processing id */
1594 	DOT11_MNG_HT_CAP			= 45,	/* d11 mgmt HT cap id */
1595 	DOT11_MNG_QOS_CAP_ID			= 46,	/* 11E QoS Capability id */
1596 	DOT11_MNG_NONERP_ID			= 47,	/* d11 management NON-ERP id */
1597 	DOT11_MNG_RSN_ID			= 48,	/* d11 management RSN id */
1598 	DOT11_MNG_EXT_RATES_ID			= 50,	/* d11 management ext. rates id */
1599 	DOT11_MNG_AP_CHREP_ID			= 51,	/* 11k AP Channel report id */
1600 	DOT11_MNG_NEIGHBOR_REP_ID		= 52,	/* 11k & 11v Neighbor report id */
1601 	DOT11_MNG_RCPI_ID			= 53,	/* 11k RCPI */
1602 	DOT11_MNG_MDIE_ID			= 54,	/* 11r Mobility domain id */
1603 	DOT11_MNG_FTIE_ID			= 55,	/* 11r Fast Bss Transition id */
1604 	DOT11_MNG_FT_TI_ID			= 56,	/* 11r Timeout Interval id */
1605 	DOT11_MNG_RDE_ID			= 57,	/* 11r RIC Data Element id */
1606 	DOT11_MNG_REGCLASS_ID			= 59,	/* d11 management regulatory class id */
1607 	DOT11_MNG_EXT_CSA_ID			= 60,	/* d11 Extended CSA */
1608 	DOT11_MNG_HT_ADD			= 61,	/* d11 mgmt additional HT info */
1609 	DOT11_MNG_EXT_CHANNEL_OFFSET		= 62,	/* d11 mgmt ext channel offset */
1610 	DOT11_MNG_BSS_AVR_ACCESS_DELAY_ID	= 63,	/* 11k bss average access delay */
1611 	DOT11_MNG_ANTENNA_ID			= 64,	/* 11k antenna id */
1612 	DOT11_MNG_RSNI_ID			= 65,	/* 11k RSNI id */
1613 	DOT11_MNG_MEASUREMENT_PILOT_TX_ID	= 66,	/* 11k measurement pilot tx info id */
1614 	DOT11_MNG_BSS_AVAL_ADMISSION_CAP_ID	= 67,	/* 11k bss aval admission cap id */
1615 	DOT11_MNG_BSS_AC_ACCESS_DELAY_ID	= 68,	/* 11k bss AC access delay id */
1616 	DOT11_MNG_WAPI_ID			= 68,	/* d11 management WAPI id */
1617 	DOT11_MNG_TIME_ADVERTISE_ID		= 69,	/* 11p time advertisement */
1618 	DOT11_MNG_RRM_CAP_ID			= 70,	/* 11k radio measurement capability */
1619 	DOT11_MNG_MULTIPLE_BSSID_ID		= 71,	/* 11k multiple BSSID id */
1620 	DOT11_MNG_HT_BSS_COEXINFO_ID		= 72,	/* d11 mgmt OBSS Coexistence INFO */
1621 	DOT11_MNG_HT_BSS_CHANNEL_REPORT_ID	= 73,	/* d11 mgmt OBSS Intolerant Channel list */
1622 	DOT11_MNG_HT_OBSS_ID			= 74,	/* d11 mgmt OBSS HT info */
1623 	DOT11_MNG_MMIE_ID			= 76,	/* d11 mgmt MIC IE */
1624 	DOT11_MNG_NONTRANS_BSSID_CAP_ID		= 83,	/* 11k nontransmitted BSSID capability */
1625 	DOT11_MNG_MULTIPLE_BSSIDINDEX_ID	= 85,	/* 11k multiple BSSID index */
1626 	DOT11_MNG_FMS_DESCR_ID			= 86,	/* 11v FMS descriptor */
1627 	DOT11_MNG_FMS_REQ_ID			= 87,	/* 11v FMS request id */
1628 	DOT11_MNG_FMS_RESP_ID			= 88,	/* 11v FMS response id */
1629 	DOT11_MNG_BSS_MAX_IDLE_PERIOD_ID	= 90,	/* 11v bss max idle id */
1630 	DOT11_MNG_TFS_REQUEST_ID		= 91,	/* 11v tfs request id */
1631 	DOT11_MNG_TFS_RESPONSE_ID		= 92,	/* 11v tfs response id */
1632 	DOT11_MNG_WNM_SLEEP_MODE_ID		= 93,	/* 11v wnm-sleep mode id */
1633 	DOT11_MNG_TIMBC_REQ_ID			= 94,	/* 11v TIM broadcast request id */
1634 	DOT11_MNG_TIMBC_RESP_ID			= 95,	/* 11v TIM broadcast response id */
1635 	DOT11_MNG_CHANNEL_USAGE			= 97,	/* 11v channel usage */
1636 	DOT11_MNG_TIME_ZONE_ID			= 98,	/* 11v time zone */
1637 	DOT11_MNG_DMS_REQUEST_ID		= 99,	/* 11v dms request id */
1638 	DOT11_MNG_DMS_RESPONSE_ID		= 100,	/* 11v dms response id */
1639 	DOT11_MNG_LINK_IDENTIFIER_ID		= 101,	/* 11z TDLS Link Identifier IE */
1640 	DOT11_MNG_WAKEUP_SCHEDULE_ID		= 102,	/* 11z TDLS Wakeup Schedule IE */
1641 	DOT11_MNG_CHANNEL_SWITCH_TIMING_ID	= 104,	/* 11z TDLS Channel Switch Timing IE */
1642 	DOT11_MNG_PTI_CONTROL_ID		= 105,	/* 11z TDLS PTI Control IE */
1643 	DOT11_MNG_PU_BUFFER_STATUS_ID		= 106,	/* 11z TDLS PU Buffer Status IE */
1644 	DOT11_MNG_INTERWORKING_ID		= 107,	/* 11u interworking */
1645 	DOT11_MNG_ADVERTISEMENT_ID		= 108,	/* 11u advertisement protocol */
1646 	DOT11_MNG_EXP_BW_REQ_ID			= 109,	/* 11u expedited bandwith request */
1647 	DOT11_MNG_QOS_MAP_ID			= 110,	/* 11u QoS map set */
1648 	DOT11_MNG_ROAM_CONSORT_ID		= 111,	/* 11u roaming consortium */
1649 	DOT11_MNG_EMERGCY_ALERT_ID		= 112,	/* 11u emergency alert identifier */
1650 	DOT11_MNG_MESH_CONFIG			= 113,	/* Mesh Configuration */
1651 	DOT11_MNG_MESH_ID			= 114,	/* Mesh ID */
1652 	DOT11_MNG_MESH_PEER_MGMT_ID		= 117,	/* Mesh PEER MGMT IE */
1653 	DOT11_MNG_EXT_CAP_ID			= 127,	/* d11 mgmt ext capability */
1654 	DOT11_MNG_EXT_PREQ_ID			= 130,	/* Mesh PREQ IE */
1655 	DOT11_MNG_EXT_PREP_ID			= 131,	/* Mesh PREP IE */
1656 	DOT11_MNG_EXT_PERR_ID			= 132,	/* Mesh PERR IE */
1657 	DOT11_MNG_VHT_CAP_ID			= 191,	/* d11 mgmt VHT cap id */
1658 	DOT11_MNG_VHT_OPERATION_ID		= 192,	/* d11 mgmt VHT op id */
1659 	DOT11_MNG_EXT_BSSLOAD_ID		= 193,	/* d11 mgmt VHT extended bss load id */
1660 	DOT11_MNG_WIDE_BW_CHANNEL_SWITCH_ID	= 194,	/* Wide BW Channel Switch IE */
1661 	DOT11_MNG_VHT_TRANSMIT_POWER_ENVELOPE_ID= 195,	/* VHT transmit Power Envelope IE */
1662 	DOT11_MNG_CHANNEL_SWITCH_WRAPPER_ID	= 196,	/* Channel Switch Wrapper IE */
1663 	DOT11_MNG_AID_ID			= 197,	/* Association ID  IE */
1664 	DOT11_MNG_OPER_MODE_NOTIF_ID		= 199,	/* d11 mgmt VHT oper mode notif */
1665 	DOT11_MNG_RNR_ID			= 201,
1666 	/* FIXME: Use these temp. IDs until ANA assigns IDs */
1667 	DOT11_MNG_FTM_PARAMS_ID			= 206,	/* mcd3.2/2014 this is not final yet */
1668 	DOT11_MNG_TWT_ID			= 216,	/* 11ah D5.0 */
1669 	DOT11_MNG_WPA_ID			= 221,	/* d11 management WPA id */
1670 	DOT11_MNG_PROPR_ID			= 221,	/* d11 management proprietary id */
1671 	/* should start using this one instead of above two */
1672 	DOT11_MNG_VS_ID				= 221,	/* d11 management Vendor Specific IE */
1673 	DOT11_MNG_MESH_CSP_ID			= 222,	/* d11 Mesh Channel Switch Parameter */
1674 	DOT11_MNG_FILS_IND_ID			= 240,	/* 11ai FILS Indication element */
1675 	DOT11_MNG_FRAGMENT_ID			= 242, /* IE's fragment ID */
1676 	DOT11_MNG_RSNXE_ID			= 244, /* RSN Extension Element (RSNXE) ID */
1677 
1678 	/* The follwing ID extensions should be defined >= 255
1679 	 * i.e. the values should include 255 (DOT11_MNG_ID_EXT_ID + ID Extension).
1680 	 */
1681 	DOT11_MNG_ID_EXT_ID			= 255	/* Element ID Extension 11mc D4.3 */
1682 };
1683 
1684 /* FILS and OCE ext ids */
1685 #define FILS_EXTID_MNG_REQ_PARAMS		2u	/* FILS Request Parameters element */
1686 #define DOT11_MNG_FILS_REQ_PARAMS		(DOT11_MNG_ID_EXT_ID + FILS_EXTID_MNG_REQ_PARAMS)
1687 #define FILS_EXTID_MNG_KEY_CONFIRMATION_ID	3u	/* FILS Key Confirmation element */
1688 #define DOT11_MNG_FILS_KEY_CONFIRMATION		(DOT11_MNG_ID_EXT_ID + \
1689 						 FILS_EXTID_MNG_KEY_CONFIRMATION_ID)
1690 #define FILS_EXTID_MNG_SESSION_ID		4u	/* FILS Session element */
1691 #define DOT11_MNG_FILS_SESSION			(DOT11_MNG_ID_EXT_ID + FILS_EXTID_MNG_SESSION_ID)
1692 #define FILS_EXTID_MNG_HLP_CONTAINER_ID		5u	/* FILS HLP Container element */
1693 #define DOT11_MNG_FILS_HLP_CONTAINER		(DOT11_MNG_ID_EXT_ID + \
1694 						 FILS_EXTID_MNG_HLP_CONTAINER_ID)
1695 #define FILS_EXTID_MNG_KEY_DELIVERY_ID		7u	/* FILS Key Delivery element */
1696 #define DOT11_MNG_FILS_KEY_DELIVERY		(DOT11_MNG_ID_EXT_ID + \
1697 						 FILS_EXTID_MNG_KEY_DELIVERY_ID)
1698 #define FILS_EXTID_MNG_WRAPPED_DATA_ID		8u	/* FILS Wrapped Data element */
1699 #define DOT11_MNG_FILS_WRAPPED_DATA		(DOT11_MNG_ID_EXT_ID + \
1700 						 FILS_EXTID_MNG_WRAPPED_DATA_ID)
1701 
1702 #define OCE_EXTID_MNG_ESP_ID			11u	/* Estimated Service Parameters element */
1703 #define DOT11_MNG_ESP				(DOT11_MNG_ID_EXT_ID + OCE_EXTID_MNG_ESP_ID)
1704 #define FILS_EXTID_MNG_PUBLIC_KEY_ID		12u	/* FILS Public Key element */
1705 #define DOT11_MNG_FILS_PUBLIC_KEY		(DOT11_MNG_ID_EXT_ID + FILS_EXTID_MNG_PUBLIC_KEY_ID)
1706 #define FILS_EXTID_MNG_NONCE_ID			13u	/* FILS Nonce element */
1707 #define DOT11_MNG_FILS_NONCE			(DOT11_MNG_ID_EXT_ID + FILS_EXTID_MNG_NONCE_ID)
1708 
1709 #define EXT_MNG_OWE_DH_PARAM_ID			32u	/* OWE DH Param ID - RFC 8110 */
1710 #define DOT11_MNG_OWE_DH_PARAM_ID		(DOT11_MNG_ID_EXT_ID + EXT_MNG_OWE_DH_PARAM_ID)
1711 #define EXT_MSG_PASSWORD_IDENTIFIER_ID		33u	/* Password ID EID */
1712 #define DOT11_MSG_PASSWORD_IDENTIFIER_ID	(DOT11_MNG_ID_EXT_ID + \
1713 						 EXT_MSG_PASSWORD_IDENTIFIER_ID)
1714 #define EXT_MNG_HE_CAP_ID			35u	/* HE Capabilities, 11ax */
1715 #define DOT11_MNG_HE_CAP_ID			(DOT11_MNG_ID_EXT_ID + EXT_MNG_HE_CAP_ID)
1716 #define EXT_MNG_HE_OP_ID			36u	/* HE Operation IE, 11ax */
1717 #define DOT11_MNG_HE_OP_ID			(DOT11_MNG_ID_EXT_ID + EXT_MNG_HE_OP_ID)
1718 #define EXT_MNG_UORA_ID				37u	/* UORA Parameter Set */
1719 #define DOT11_MNG_UORA_ID			(DOT11_MNG_ID_EXT_ID + EXT_MNG_UORA_ID)
1720 #define EXT_MNG_MU_EDCA_ID			38u	/* MU EDCA Parameter Set */
1721 #define DOT11_MNG_MU_EDCA_ID			(DOT11_MNG_ID_EXT_ID + EXT_MNG_MU_EDCA_ID)
1722 #define EXT_MNG_SRPS_ID				39u	/* Spatial Reuse Parameter Set */
1723 #define DOT11_MNG_SRPS_ID			(DOT11_MNG_ID_EXT_ID + EXT_MNG_SRPS_ID)
1724 #define EXT_MNG_BSSCOLOR_CHANGE_ID		42u	/* BSS Color Change Announcement */
1725 #define DOT11_MNG_BSSCOLOR_CHANGE_ID		(DOT11_MNG_ID_EXT_ID + EXT_MNG_BSSCOLOR_CHANGE_ID)
1726 #define OCV_EXTID_MNG_OCI_ID			54u     /* OCI element */
1727 #define DOT11_MNG_OCI_ID			(DOT11_MNG_ID_EXT_ID + OCV_EXT_OCI_ID)
1728 #define EXT_MNG_SHORT_SSID_ID			58u	/* SHORT SSID ELEMENT */
1729 #define DOT11_MNG_SHORT_SSID_LIST_ID		(DOT11_MNG_ID_EXT_ID + EXT_MNG_SHORT_SSID_ID)
1730 #define EXT_MNG_HE_6G_CAP_ID			59u	/* HE Extended Capabilities, 11ax */
1731 #define DOT11_MNG_HE_6G_CAP_ID			(DOT11_MNG_ID_EXT_ID + EXT_MNG_HE_6G_CAP_ID)
1732 
1733 #define MSCS_EXTID_MNG_DESCR_ID			88u	/* Ext ID for the MSCS descriptor */
1734 #define DOT11_MNG_MSCS_DESCR_ID			(DOT11_MNG_ID_EXT_ID + MSCS_EXTID_MNG_DESCR_ID)
1735 
1736 #define TCLAS_EXTID_MNG_MASK_ID			89u	/* Ext ID for the TCLAS Mask element */
1737 #define DOT11_MNG_TCLASS_MASK_ID		(DOT11_MNG_ID_EXT_ID + TCLAS_EXTID_MNG_MASK_ID)
1738 
1739 #define SAE_EXT_REJECTED_GROUPS_ID		92u	/* SAE Rejected Groups element */
1740 #define DOT11_MNG_REJECTED_GROUPS_ID		(DOT11_MNG_ID_EXT_ID + SAE_EXT_REJECTED_GROUPS_ID)
1741 #define SAE_EXT_ANTICLOG_TOKEN_CONTAINER_ID	93u	/* SAE Anti-clogging token container */
1742 #define DOT11_MNG_ANTICLOG_TOKEN_CONTAINER_ID	(DOT11_MNG_ID_EXT_ID + \
1743 						 SAE_EXT_ANTICLOG_TOKEN_CONTAINER_ID)
1744 #define EXT_MNG_EHT_CAP_ID			100u	/* EHT Capabilities IE FIXME */
1745 #define DOT11_MNG_EHT_CAP_ID			(DOT11_MNG_ID_EXT_ID + EXT_MNG_EHT_CAP_ID)
1746 #define EXT_MNG_EHT_OP_ID			101u	/* EHT Operation IE # FIXME */
1747 #define DOT11_MNG_EHT_OP_ID			(DOT11_MNG_ID_EXT_ID + EXT_MNG_EHT_OP_ID)
1748 
1749 /* unassigned IDs for ranging parameter elements. To be updated after final
1750  * assignement.
1751  */
1752 #define DOT11_MNG_FTM_RANGING_EXT_ID		100u /* 11AZ sounding mode parameter element */
1753 #define DOT11_MNG_FTM_ISTA_AVAIL_EXT_ID		101u /* 11 AZ TN ISTA avaialability window */
1754 #define DOT11_MNG_FTM_RSTA_AVAIL_EXT_ID		102u /* 11 AZ TN RSTA avaialability window */
1755 #define DOT11_MNG_FTM_SECURE_LTF_EXT_ID		103u /* 11 AZ Secure LTF parameter element */
1756 
1757 #define DOT11_FTM_NTB_SUB_ELT_ID		0u /* non-TB ranging parameter sub-element ID */
1758 #define DOT11_FTM_TB_SUB_ELT_ID			1u /* TB ranging parameter sub-element ID */
1759 
1760 /* deprecated definitions, do not use, to be deleted later */
1761 #define FILS_HLP_CONTAINER_EXT_ID		FILS_EXTID_MNG_HLP_CONTAINER_ID
1762 #define DOT11_ESP_EXT_ID			OCE_EXTID_MNG_ESP_ID
1763 #define FILS_REQ_PARAMS_EXT_ID			FILS_EXTID_MNG_REQ_PARAMS
1764 #define EXT_MNG_RAPS_ID				37u	/* OFDMA Random Access Parameter Set */
1765 #define DOT11_MNG_RAPS_ID			(DOT11_MNG_ID_EXT_ID + EXT_MNG_RAPS_ID)
1766 /* End of deprecated definitions */
1767 
1768 #define DOT11_MNG_IE_ID_EXT_MATCH(_ie, _id) (\
1769 	((_ie)->id == DOT11_MNG_ID_EXT_ID) && \
1770 	((_ie)->len > 0) && \
1771 	((_id) == ((uint8 *)(_ie) + TLV_HDR_LEN)[0]))
1772 
1773 #define DOT11_MNG_IE_ID_EXT_INIT(_ie, _id, _len) do {\
1774 		(_ie)->id = DOT11_MNG_ID_EXT_ID; \
1775 		(_ie)->len = _len; \
1776 		(_ie)->id_ext = _id; \
1777 	} while (0)
1778 
1779 /* Rate Defines */
1780 
1781 /* Valid rates for the Supported Rates and Extended Supported Rates IEs.
1782  * Encoding is the rate in 500kbps units, rouding up for fractional values.
1783  * 802.11-2012, section 6.5.5.2, DATA_RATE parameter enumerates all the values.
1784  * The rate values cover DSSS, HR/DSSS, ERP, and OFDM phy rates.
1785  * The defines below do not cover the rates specific to 10MHz, {3, 4.5, 27},
1786  * and 5MHz, {1.5, 2.25, 3, 4.5, 13.5}, which are not supported by Broadcom devices.
1787  */
1788 
1789 #define DOT11_RATE_1M   2       /* 1  Mbps in 500kbps units */
1790 #define DOT11_RATE_2M   4       /* 2  Mbps in 500kbps units */
1791 #define DOT11_RATE_5M5  11      /* 5.5 Mbps in 500kbps units */
1792 #define DOT11_RATE_11M  22      /* 11 Mbps in 500kbps units */
1793 #define DOT11_RATE_6M   12      /* 6  Mbps in 500kbps units */
1794 #define DOT11_RATE_9M   18      /* 9  Mbps in 500kbps units */
1795 #define DOT11_RATE_12M  24      /* 12 Mbps in 500kbps units */
1796 #define DOT11_RATE_18M  36      /* 18 Mbps in 500kbps units */
1797 #define DOT11_RATE_24M  48      /* 24 Mbps in 500kbps units */
1798 #define DOT11_RATE_36M  72      /* 36 Mbps in 500kbps units */
1799 #define DOT11_RATE_48M  96      /* 48 Mbps in 500kbps units */
1800 #define DOT11_RATE_54M  108     /* 54 Mbps in 500kbps units */
1801 #define DOT11_RATE_MAX  108     /* highest rate (54 Mbps) in 500kbps units */
1802 
1803 /* Supported Rates and Extended Supported Rates IEs
1804  * The supported rates octets are defined a the MSB indicatin a Basic Rate
1805  * and bits 0-6 as the rate value
1806  */
1807 #define DOT11_RATE_BASIC                0x80 /* flag for a Basic Rate */
1808 #define DOT11_RATE_MASK                 0x7F /* mask for numeric part of rate */
1809 
1810 /* BSS Membership Selector parameters
1811  * 802.11-2016 (and 802.11ax-D1.1), Sec 9.4.2.3
1812  * These selector values are advertised in Supported Rates and Extended Supported Rates IEs
1813  * in the supported rates list with the Basic rate bit set.
1814  * Constants below include the basic bit.
1815  */
1816 #define DOT11_BSS_MEMBERSHIP_HT         0xFF  /* Basic 0x80 + 127, HT Required to join */
1817 #define DOT11_BSS_MEMBERSHIP_VHT        0xFE  /* Basic 0x80 + 126, VHT Required to join */
1818 #define DOT11_BSS_MEMBERSHIP_HE         0xFD  /* Basic 0x80 + 125, HE Required to join */
1819 #define DOT11_BSS_SAE_HASH_TO_ELEMENT	123u	/* SAE Hash-to-element Required to join */
1820 
1821 /* ERP info element bit values */
1822 #define DOT11_MNG_ERP_LEN			1	/* ERP is currently 1 byte long */
1823 #define DOT11_MNG_NONERP_PRESENT		0x01	/* NonERP (802.11b) STAs are present
1824 							 *in the BSS
1825 							 */
1826 #define DOT11_MNG_USE_PROTECTION		0x02	/* Use protection mechanisms for
1827 							 *ERP-OFDM frames
1828 							 */
1829 #define DOT11_MNG_BARKER_PREAMBLE		0x04	/* Short Preambles: 0 == allowed,
1830 							 * 1 == not allowed
1831 							 */
1832 /* TS Delay element offset & size */
1833 #define DOT11_MGN_TS_DELAY_LEN		4	/* length of TS DELAY IE */
1834 #define TS_DELAY_FIELD_SIZE			4	/* TS DELAY field size */
1835 
1836 /* Capability Information Field */
1837 #define DOT11_CAP_ESS				0x0001	/* d11 cap. ESS */
1838 #define DOT11_CAP_IBSS				0x0002	/* d11 cap. IBSS */
1839 #define DOT11_CAP_POLLABLE			0x0004	/* d11 cap. pollable */
1840 #define DOT11_CAP_POLL_RQ			0x0008	/* d11 cap. poll request */
1841 #define DOT11_CAP_PRIVACY			0x0010	/* d11 cap. privacy */
1842 #define DOT11_CAP_SHORT				0x0020	/* d11 cap. short */
1843 #define DOT11_CAP_PBCC				0x0040	/* d11 cap. PBCC */
1844 #define DOT11_CAP_AGILITY			0x0080	/* d11 cap. agility */
1845 #define DOT11_CAP_SPECTRUM			0x0100	/* d11 cap. spectrum */
1846 #define DOT11_CAP_QOS				0x0200	/* d11 cap. qos */
1847 #define DOT11_CAP_SHORTSLOT			0x0400	/* d11 cap. shortslot */
1848 #define DOT11_CAP_APSD				0x0800	/* d11 cap. apsd */
1849 #define DOT11_CAP_RRM				0x1000	/* d11 cap. 11k radio measurement */
1850 #define DOT11_CAP_CCK_OFDM			0x2000	/* d11 cap. CCK/OFDM */
1851 #define DOT11_CAP_DELAY_BA			0x4000	/* d11 cap. delayed block ack */
1852 #define DOT11_CAP_IMMEDIATE_BA			0x8000	/* d11 cap. immediate block ack */
1853 
1854 /* Extended capabilities IE bitfields */
1855 /* 20/40 BSS Coexistence Management support bit position */
1856 #define DOT11_EXT_CAP_OBSS_COEX_MGMT		0u
1857 /* Extended Channel Switching support bit position */
1858 #define DOT11_EXT_CAP_EXT_CHAN_SWITCHING	2u
1859 /* scheduled PSMP support bit position */
1860 #define DOT11_EXT_CAP_SPSMP			6u
1861 /*  Flexible Multicast Service */
1862 #define DOT11_EXT_CAP_FMS			11u
1863 /* proxy ARP service support bit position */
1864 #define DOT11_EXT_CAP_PROXY_ARP			12u
1865 /* Civic Location */
1866 #define DOT11_EXT_CAP_CIVIC_LOC			14u
1867 /* Geospatial Location */
1868 #define DOT11_EXT_CAP_LCI			15u
1869 /* Traffic Filter Service */
1870 #define DOT11_EXT_CAP_TFS			16u
1871 /* WNM-Sleep Mode */
1872 #define DOT11_EXT_CAP_WNM_SLEEP			17u
1873 /* TIM Broadcast service */
1874 #define DOT11_EXT_CAP_TIMBC			18u
1875 /* BSS Transition Management support bit position */
1876 #define DOT11_EXT_CAP_BSSTRANS_MGMT		19u
1877 /* Multiple BSSID support position */
1878 #define DOT11_EXT_CAP_MULTIBSSID		22u
1879 /* Direct Multicast Service */
1880 #define DOT11_EXT_CAP_DMS			26u
1881 /* Interworking support bit position */
1882 #define DOT11_EXT_CAP_IW			31u
1883 /* QoS map support bit position */
1884 #define DOT11_EXT_CAP_QOS_MAP			32u
1885 /* service Interval granularity bit position and mask */
1886 #define DOT11_EXT_CAP_SI			41u
1887 #define DOT11_EXT_CAP_SI_MASK			0x0E
1888 /* Location Identifier service */
1889 #define DOT11_EXT_CAP_IDENT_LOC			44u
1890 /* WNM notification */
1891 #define DOT11_EXT_CAP_WNM_NOTIF			46u
1892 /* Operating mode notification - VHT (11ac D3.0 - 8.4.2.29) */
1893 #define DOT11_EXT_CAP_OPER_MODE_NOTIF		62u
1894 /* Fine timing measurement - D3.0 */
1895 #define DOT11_EXT_CAP_FTM_RESPONDER		70u
1896 #define DOT11_EXT_CAP_FTM_INITIATOR		71u /* tentative 11mcd3.0 */
1897 #define DOT11_EXT_CAP_FILS			72u /* FILS Capability */
1898 /* TWT support */
1899 #define DOT11_EXT_CAP_TWT_REQUESTER		77u
1900 #define DOT11_EXT_CAP_TWT_RESPONDER		78u
1901 #define DOT11_EXT_CAP_OBSS_NB_RU_OFDMA		79u
1902 /* FIXME: Use these temp. IDs until ANA assigns IDs */
1903 #define DOT11_EXT_CAP_EMBSS_ADVERTISE		80u
1904 /* SAE password ID */
1905 #define DOT11_EXT_CAP_SAE_PWD_ID_INUSE		81u
1906 #define DOT11_EXT_CAP_SAE_PWD_ID_USED_EXCLUSIVE	82u
1907 /* Beacon Protection Enabled 802.11 D3.0 - 9.4.2.26
1908  * This field is reserved for a STA.
1909  */
1910 #define DOT11_EXT_CAP_BCN_PROT			84u
1911 
1912 /* Mirrored SCS (MSCS) support */
1913 #define DOT11_EXT_CAP_MSCS			85u
1914 
1915 /* TODO: Update DOT11_EXT_CAP_MAX_IDX to reflect the highest offset.
1916  * Note: DOT11_EXT_CAP_MAX_IDX must only be used in attach path.
1917  *       It will cause ROM invalidation otherwise.
1918  */
1919 #define DOT11_EXT_CAP_MAX_IDX			85u
1920 
1921 /* Remove this hack (DOT11_EXT_CAP_MAX_BIT_IDX) when no one
1922  * references DOT11_EXTCAP_LEN_MAX
1923  */
1924 #define DOT11_EXT_CAP_MAX_BIT_IDX		95u	/* !!!update this please!!! */
1925 
1926 /* Remove DOT11_EXTCAP_LEN_MAX when no one references it */
1927 /* extended capability */
1928 #ifndef DOT11_EXTCAP_LEN_MAX
1929 #define DOT11_EXTCAP_LEN_MAX ((DOT11_EXT_CAP_MAX_BIT_IDX + 8) >> 3)
1930 #endif
1931 /* Remove dot11_extcap when no one references it */
1932 BWL_PRE_PACKED_STRUCT struct dot11_extcap {
1933 	uint8 extcap[DOT11_EXTCAP_LEN_MAX];
1934 } BWL_POST_PACKED_STRUCT;
1935 typedef struct dot11_extcap dot11_extcap_t;
1936 
1937 /* VHT Operating mode bit fields -  (11ac D8.0/802.11-2016 - 9.4.1.53) */
1938 #define DOT11_OPER_MODE_CHANNEL_WIDTH_SHIFT 0
1939 #define DOT11_OPER_MODE_CHANNEL_WIDTH_MASK 0x3
1940 #define DOT11_OPER_MODE_160_8080_BW_SHIFT 2
1941 #define DOT11_OPER_MODE_160_8080_BW_MASK 0x04
1942 #define DOT11_OPER_MODE_NOLDPC_SHIFT 3
1943 #define DOT11_OPER_MODE_NOLDPC_MASK 0x08
1944 #define DOT11_OPER_MODE_RXNSS_SHIFT 4
1945 #define DOT11_OPER_MODE_RXNSS_MASK 0x70
1946 #define DOT11_OPER_MODE_RXNSS_TYPE_SHIFT 7
1947 #define DOT11_OPER_MODE_RXNSS_TYPE_MASK 0x80
1948 
1949 #define DOT11_OPER_MODE_RESET_CHAN_WIDTH_160MHZ(oper_mode) \
1950 	(oper_mode & (~(DOT11_OPER_MODE_CHANNEL_WIDTH_MASK | \
1951 		DOT11_OPER_MODE_160_8080_BW_MASK)))
1952 #define DOT11_OPER_MODE_SET_CHAN_WIDTH_160MHZ(oper_mode) \
1953 	(oper_mode = (DOT11_OPER_MODE_RESET_CHAN_WIDTH_160MHZ(oper_mode) | \
1954 		(DOT11_OPER_MODE_80MHZ | DOT11_OPER_MODE_160_8080_BW_MASK)))
1955 
1956 #ifdef DOT11_OPER_MODE_LEFT_SHIFT_FIX
1957 
1958 #define DOT11_OPER_MODE(type, nss, chanw) (\
1959 	((type) << DOT11_OPER_MODE_RXNSS_TYPE_SHIFT &\
1960 		 DOT11_OPER_MODE_RXNSS_TYPE_MASK) |\
1961 	(((nss) - 1u) << DOT11_OPER_MODE_RXNSS_SHIFT & DOT11_OPER_MODE_RXNSS_MASK) |\
1962 	((chanw) << DOT11_OPER_MODE_CHANNEL_WIDTH_SHIFT &\
1963 		 DOT11_OPER_MODE_CHANNEL_WIDTH_MASK))
1964 
1965 #define DOT11_D8_OPER_MODE(type, nss, ldpc, bw160_8080, chanw) (\
1966 	((type) << DOT11_OPER_MODE_RXNSS_TYPE_SHIFT &\
1967 		 DOT11_OPER_MODE_RXNSS_TYPE_MASK) |\
1968 	(((nss) - 1u) << DOT11_OPER_MODE_RXNSS_SHIFT & DOT11_OPER_MODE_RXNSS_MASK) |\
1969 	((ldpc) << DOT11_OPER_MODE_NOLDPC_SHIFT & DOT11_OPER_MODE_NOLDPC_MASK) |\
1970 	((bw160_8080) << DOT11_OPER_MODE_160_8080_BW_SHIFT &\
1971 		 DOT11_OPER_MODE_160_8080_BW_MASK) |\
1972 	((chanw) << DOT11_OPER_MODE_CHANNEL_WIDTH_SHIFT &\
1973 		 DOT11_OPER_MODE_CHANNEL_WIDTH_MASK))
1974 
1975 #else
1976 
1977 /* avoid invalidation from above fix on release branches, can be removed when older release
1978  * branches no longer use component/proto from trunk
1979  */
1980 
1981 #define DOT11_OPER_MODE(type, nss, chanw) (\
1982 	((type) << DOT11_OPER_MODE_RXNSS_TYPE_SHIFT &\
1983 		 DOT11_OPER_MODE_RXNSS_TYPE_MASK) |\
1984 	(((nss) - 1) << DOT11_OPER_MODE_RXNSS_SHIFT & DOT11_OPER_MODE_RXNSS_MASK) |\
1985 	((chanw) << DOT11_OPER_MODE_CHANNEL_WIDTH_SHIFT &\
1986 		 DOT11_OPER_MODE_CHANNEL_WIDTH_MASK))
1987 
1988 #define DOT11_D8_OPER_MODE(type, nss, ldpc, bw160_8080, chanw) (\
1989 	((type) << DOT11_OPER_MODE_RXNSS_TYPE_SHIFT &\
1990 		 DOT11_OPER_MODE_RXNSS_TYPE_MASK) |\
1991 	(((nss) - 1) << DOT11_OPER_MODE_RXNSS_SHIFT & DOT11_OPER_MODE_RXNSS_MASK) |\
1992 	((ldpc) << DOT11_OPER_MODE_NOLDPC_SHIFT & DOT11_OPER_MODE_NOLDPC_MASK) |\
1993 	((bw160_8080) << DOT11_OPER_MODE_160_8080_BW_SHIFT &\
1994 		 DOT11_OPER_MODE_160_8080_BW_MASK) |\
1995 	((chanw) << DOT11_OPER_MODE_CHANNEL_WIDTH_SHIFT &\
1996 		 DOT11_OPER_MODE_CHANNEL_WIDTH_MASK))
1997 
1998 #endif /* DOT11_OPER_MODE_LEFT_SHIFT_FIX */
1999 
2000 #define DOT11_OPER_MODE_CHANNEL_WIDTH(mode) \
2001 	(((mode) & DOT11_OPER_MODE_CHANNEL_WIDTH_MASK)\
2002 		>> DOT11_OPER_MODE_CHANNEL_WIDTH_SHIFT)
2003 #define DOT11_OPER_MODE_160_8080(mode) \
2004 	(((mode) & DOT11_OPER_MODE_160_8080_BW_MASK)\
2005 		>> DOT11_OPER_MODE_160_8080_BW_SHIFT)
2006 #define DOT11_OPER_MODE_NOLDPC(mode) \
2007 		(((mode) & DOT11_OPER_MODE_NOLDPC_MASK)\
2008 			>> DOT11_OPER_MODE_NOLDPC_SHIFT)
2009 #define DOT11_OPER_MODE_RXNSS(mode) \
2010 	((((mode) & DOT11_OPER_MODE_RXNSS_MASK)		\
2011 		>> DOT11_OPER_MODE_RXNSS_SHIFT) + 1)
2012 #define DOT11_OPER_MODE_RXNSS_TYPE(mode) \
2013 	(((mode) & DOT11_OPER_MODE_RXNSS_TYPE_MASK)\
2014 		>> DOT11_OPER_MODE_RXNSS_TYPE_SHIFT)
2015 
2016 #define DOT11_OPER_MODE_20MHZ 0
2017 #define DOT11_OPER_MODE_40MHZ 1
2018 #define DOT11_OPER_MODE_80MHZ 2
2019 #define DOT11_OPER_MODE_160MHZ 3
2020 #define DOT11_OPER_MODE_8080MHZ 3
2021 #define DOT11_OPER_MODE_1608080MHZ 1
2022 
2023 #define DOT11_OPER_MODE_CHANNEL_WIDTH_20MHZ(mode) (\
2024 	((mode) & DOT11_OPER_MODE_CHANNEL_WIDTH_MASK) == DOT11_OPER_MODE_20MHZ)
2025 #define DOT11_OPER_MODE_CHANNEL_WIDTH_40MHZ(mode) (\
2026 	((mode) & DOT11_OPER_MODE_CHANNEL_WIDTH_MASK) == DOT11_OPER_MODE_40MHZ)
2027 #define DOT11_OPER_MODE_CHANNEL_WIDTH_80MHZ(mode) (\
2028 	((mode) & DOT11_OPER_MODE_CHANNEL_WIDTH_MASK) == DOT11_OPER_MODE_80MHZ)
2029 #define DOT11_OPER_MODE_CHANNEL_WIDTH_160MHZ(mode) (\
2030 	((mode) & DOT11_OPER_MODE_160_8080_BW_MASK))
2031 #define DOT11_OPER_MODE_CHANNEL_WIDTH_8080MHZ(mode) (\
2032 	((mode) & DOT11_OPER_MODE_160_8080_BW_MASK))
2033 
2034 /* Operating mode information element 802.11ac D3.0 - 8.4.2.168 */
2035 BWL_PRE_PACKED_STRUCT struct dot11_oper_mode_notif_ie {
2036 	uint8 mode;
2037 } BWL_POST_PACKED_STRUCT;
2038 typedef struct dot11_oper_mode_notif_ie dot11_oper_mode_notif_ie_t;
2039 
2040 #define DOT11_OPER_MODE_NOTIF_IE_LEN 1
2041 
2042 /* Extended Capability Information Field */
2043 #define DOT11_OBSS_COEX_MNG_SUPPORT	0x01	/* 20/40 BSS Coexistence Management support */
2044 
2045 /*
2046  * Action Frame Constants
2047  */
2048 #define DOT11_ACTION_HDR_LEN		2	/* action frame category + action field */
2049 #define DOT11_ACTION_CAT_OFF		0	/* category offset */
2050 #define DOT11_ACTION_ACT_OFF		1	/* action offset */
2051 
2052 /* Action Category field (sec 8.4.1.11) */
2053 #define DOT11_ACTION_CAT_ERR_MASK	0x80	/* category error mask */
2054 #define DOT11_ACTION_CAT_MASK		0x7F	/* category mask */
2055 #define DOT11_ACTION_CAT_SPECT_MNG	0	/* category spectrum management */
2056 #define DOT11_ACTION_CAT_QOS		1	/* category QoS */
2057 #define DOT11_ACTION_CAT_DLS		2	/* category DLS */
2058 #define DOT11_ACTION_CAT_BLOCKACK	3	/* category block ack */
2059 #define DOT11_ACTION_CAT_PUBLIC		4	/* category public */
2060 #define DOT11_ACTION_CAT_RRM		5	/* category radio measurements */
2061 #define DOT11_ACTION_CAT_FBT	6	/* category fast bss transition */
2062 #define DOT11_ACTION_CAT_HT		7	/* category for HT */
2063 #define DOT11_ACTION_CAT_SA_QUERY	8	/* security association query */
2064 #define DOT11_ACTION_CAT_PDPA		9	/* protected dual of public action */
2065 #define DOT11_ACTION_CAT_WNM		10	/* category for WNM */
2066 #define DOT11_ACTION_CAT_UWNM		11	/* category for Unprotected WNM */
2067 #define DOT11_ACTION_CAT_MESH		13	/* category for Mesh */
2068 #define DOT11_ACTION_CAT_SELFPROT	15	/* category for Mesh, self protected */
2069 #define DOT11_ACTION_NOTIFICATION	17
2070 
2071 #define DOT11_ACTION_RAV_STREAMING	19	/* category for Robust AV streaming:
2072 						 * SCS, MSCS, etc.
2073 						 */
2074 
2075 #define DOT11_ACTION_CAT_VHT		21	/* VHT action */
2076 #define DOT11_ACTION_CAT_S1G		22	/* S1G action */
2077 /* FIXME: Use temp. ID until ANA assigns one */
2078 #define DOT11_ACTION_CAT_HE		27	/* HE action frame */
2079 #define DOT11_ACTION_CAT_FILS		26	/* FILS action frame */
2080 #define DOT11_ACTION_CAT_VSP		126	/* protected vendor specific */
2081 #define DOT11_ACTION_CAT_VS		127	/* category Vendor Specific */
2082 
2083 /* Spectrum Management Action IDs (sec 7.4.1) */
2084 #define DOT11_SM_ACTION_M_REQ		0	/* d11 action measurement request */
2085 #define DOT11_SM_ACTION_M_REP		1	/* d11 action measurement response */
2086 #define DOT11_SM_ACTION_TPC_REQ		2	/* d11 action TPC request */
2087 #define DOT11_SM_ACTION_TPC_REP		3	/* d11 action TPC response */
2088 #define DOT11_SM_ACTION_CHANNEL_SWITCH	4	/* d11 action channel switch */
2089 #define DOT11_SM_ACTION_EXT_CSA		5	/* d11 extened CSA for 11n */
2090 
2091 /* QoS action ids */
2092 #define DOT11_QOS_ACTION_ADDTS_REQ	0	/* d11 action ADDTS request */
2093 #define DOT11_QOS_ACTION_ADDTS_RESP	1	/* d11 action ADDTS response */
2094 #define DOT11_QOS_ACTION_DELTS		2	/* d11 action DELTS */
2095 #define DOT11_QOS_ACTION_SCHEDULE	3	/* d11 action schedule */
2096 #define DOT11_QOS_ACTION_QOS_MAP	4	/* d11 action QOS map */
2097 
2098 /* HT action ids */
2099 #define DOT11_ACTION_ID_HT_CH_WIDTH	0	/* notify channel width action id */
2100 #define DOT11_ACTION_ID_HT_MIMO_PS	1	/* mimo ps action id */
2101 
2102 /* Public action ids */
2103 #define DOT11_PUB_ACTION_BSS_COEX_MNG	0	/* 20/40 Coexistence Management action id */
2104 #define DOT11_PUB_ACTION_CHANNEL_SWITCH	4	/* d11 action channel switch */
2105 #define DOT11_PUB_ACTION_VENDOR_SPEC	9	/* Vendor specific */
2106 #define DOT11_PUB_ACTION_GAS_CB_REQ	12	/* GAS Comeback Request */
2107 #define DOT11_PUB_ACTION_FTM_REQ	32	/* FTM request */
2108 #define DOT11_PUB_ACTION_FTM		33	/* FTM measurement */
2109 /* unassigned value. Will change after final assignement.
2110  * for now, use 34(same as FILS DISC) due to QT/TB/chipsim support from uCode
2111  */
2112 #define DOT11_PUB_ACTION_FTM_LMR	34	/* FTM 11AZ Location Management Report */
2113 
2114 #define DOT11_PUB_ACTION_FTM_REQ_TRIGGER_START	1u	/* FTM request start trigger */
2115 #define DOT11_PUB_ACTION_FTM_REQ_TRIGGER_STOP	0u	/* FTM request stop trigger */
2116 
2117 /* Block Ack action types */
2118 #define DOT11_BA_ACTION_ADDBA_REQ	0	/* ADDBA Req action frame type */
2119 #define DOT11_BA_ACTION_ADDBA_RESP	1	/* ADDBA Resp action frame type */
2120 #define DOT11_BA_ACTION_DELBA		2	/* DELBA action frame type */
2121 
2122 /* ADDBA action parameters */
2123 #define DOT11_ADDBA_PARAM_AMSDU_SUP	0x0001	/* AMSDU supported under BA */
2124 #define DOT11_ADDBA_PARAM_POLICY_MASK	0x0002	/* policy mask(ack vs delayed) */
2125 #define DOT11_ADDBA_PARAM_POLICY_SHIFT	1	/* policy shift */
2126 #define DOT11_ADDBA_PARAM_TID_MASK	0x003c	/* tid mask */
2127 #define DOT11_ADDBA_PARAM_TID_SHIFT	2	/* tid shift */
2128 #define DOT11_ADDBA_PARAM_BSIZE_MASK	0xffc0	/* buffer size mask */
2129 #define DOT11_ADDBA_PARAM_BSIZE_SHIFT	6	/* buffer size shift */
2130 
2131 #define DOT11_ADDBA_POLICY_DELAYED	0	/* delayed BA policy */
2132 #define DOT11_ADDBA_POLICY_IMMEDIATE	1	/* immediate BA policy */
2133 
2134 /* Fast Transition action types */
2135 #define DOT11_FT_ACTION_FT_RESERVED		0
2136 #define DOT11_FT_ACTION_FT_REQ			1	/* FBT request - for over-the-DS FBT */
2137 #define DOT11_FT_ACTION_FT_RES			2	/* FBT response - for over-the-DS FBT */
2138 #define DOT11_FT_ACTION_FT_CON			3	/* FBT confirm - for OTDS with RRP */
2139 #define DOT11_FT_ACTION_FT_ACK			4	/* FBT ack */
2140 
2141 /* DLS action types */
2142 #define DOT11_DLS_ACTION_REQ			0	/* DLS Request */
2143 #define DOT11_DLS_ACTION_RESP			1	/* DLS Response */
2144 #define DOT11_DLS_ACTION_TD			2	/* DLS Teardown */
2145 
2146 /* Robust Audio Video streaming action types */
2147 #define DOT11_RAV_SCS_REQ			0	/* SCS Request */
2148 #define DOT11_RAV_SCS_RES			1	/* SCS Response */
2149 #define DOT11_RAV_GM_REQ			2	/* Group Membership Request */
2150 #define DOT11_RAV_GM_RES			3	/* Group Membership Response */
2151 #define DOT11_RAV_MSCS_REQ			4	/* MSCS Request */
2152 #define DOT11_RAV_MSCS_RES			5	/* MSCS Response */
2153 
2154 /* Wireless Network Management (WNM) action types */
2155 #define DOT11_WNM_ACTION_EVENT_REQ		0
2156 #define DOT11_WNM_ACTION_EVENT_REP		1
2157 #define DOT11_WNM_ACTION_DIAG_REQ		2
2158 #define DOT11_WNM_ACTION_DIAG_REP		3
2159 #define DOT11_WNM_ACTION_LOC_CFG_REQ		4
2160 #define DOT11_WNM_ACTION_LOC_RFG_RESP		5
2161 #define DOT11_WNM_ACTION_BSSTRANS_QUERY		6
2162 #define DOT11_WNM_ACTION_BSSTRANS_REQ		7
2163 #define DOT11_WNM_ACTION_BSSTRANS_RESP		8
2164 #define DOT11_WNM_ACTION_FMS_REQ		9
2165 #define DOT11_WNM_ACTION_FMS_RESP		10
2166 #define DOT11_WNM_ACTION_COL_INTRFRNCE_REQ	11
2167 #define DOT11_WNM_ACTION_COL_INTRFRNCE_REP	12
2168 #define DOT11_WNM_ACTION_TFS_REQ		13
2169 #define DOT11_WNM_ACTION_TFS_RESP		14
2170 #define DOT11_WNM_ACTION_TFS_NOTIFY_REQ		15
2171 #define DOT11_WNM_ACTION_WNM_SLEEP_REQ		16
2172 #define DOT11_WNM_ACTION_WNM_SLEEP_RESP		17
2173 #define DOT11_WNM_ACTION_TIMBC_REQ		18
2174 #define DOT11_WNM_ACTION_TIMBC_RESP		19
2175 #define DOT11_WNM_ACTION_QOS_TRFC_CAP_UPD	20
2176 #define DOT11_WNM_ACTION_CHAN_USAGE_REQ		21
2177 #define DOT11_WNM_ACTION_CHAN_USAGE_RESP	22
2178 #define DOT11_WNM_ACTION_DMS_REQ		23
2179 #define DOT11_WNM_ACTION_DMS_RESP		24
2180 #define DOT11_WNM_ACTION_TMNG_MEASUR_REQ	25
2181 #define DOT11_WNM_ACTION_NOTFCTN_REQ		26
2182 #define DOT11_WNM_ACTION_NOTFCTN_RESP		27
2183 #define DOT11_WNM_ACTION_TFS_NOTIFY_RESP	28
2184 
2185 /* Unprotected Wireless Network Management (WNM) action types */
2186 #define DOT11_UWNM_ACTION_TIM			0
2187 #define DOT11_UWNM_ACTION_TIMING_MEASUREMENT	1
2188 
2189 #define DOT11_MNG_COUNTRY_ID_LEN 3
2190 
2191 /* VHT category action types - 802.11ac D3.0 - 8.5.23.1 */
2192 #define DOT11_VHT_ACTION_CBF				0	/* Compressed Beamforming */
2193 #define DOT11_VHT_ACTION_GID_MGMT			1	/* Group ID Management */
2194 #define DOT11_VHT_ACTION_OPER_MODE_NOTIF	2	/* Operating mode notif'n */
2195 
2196 /* FILS category action types - 802.11ai D11.0 - 9.6.8.1 */
2197 #define DOT11_FILS_ACTION_DISCOVERY		34	/* FILS Discovery */
2198 
2199 /** DLS Request frame header */
2200 BWL_PRE_PACKED_STRUCT struct dot11_dls_req {
2201 	uint8 category;			/* category of action frame (2) */
2202 	uint8 action;				/* DLS action: req (0) */
2203 	struct ether_addr	da;		/* destination address */
2204 	struct ether_addr	sa;		/* source address */
2205 	uint16 cap;				/* capability */
2206 	uint16 timeout;			/* timeout value */
2207 	uint8 data[1];				/* IE:support rate, extend support rate, HT cap */
2208 } BWL_POST_PACKED_STRUCT;
2209 typedef struct dot11_dls_req dot11_dls_req_t;
2210 #define DOT11_DLS_REQ_LEN 18	/* Fixed length */
2211 
2212 /** DLS response frame header */
2213 BWL_PRE_PACKED_STRUCT struct dot11_dls_resp {
2214 	uint8 category;			/* category of action frame (2) */
2215 	uint8 action;				/* DLS action: req (0) */
2216 	uint16 status;				/* status code field */
2217 	struct ether_addr	da;		/* destination address */
2218 	struct ether_addr	sa;		/* source address */
2219 	uint8 data[1];				/* optional: capability, rate ... */
2220 } BWL_POST_PACKED_STRUCT;
2221 typedef struct dot11_dls_resp dot11_dls_resp_t;
2222 #define DOT11_DLS_RESP_LEN 16	/* Fixed length */
2223 
2224 /* ************* 802.11v related definitions. ************* */
2225 
2226 /** BSS Management Transition Query frame header */
2227 BWL_PRE_PACKED_STRUCT struct dot11_bsstrans_query {
2228 	uint8 category;			/* category of action frame (10) */
2229 	uint8 action;			/* WNM action: trans_query (6) */
2230 	uint8 token;			/* dialog token */
2231 	uint8 reason;			/* transition query reason */
2232 	uint8 data[1];			/* Elements */
2233 } BWL_POST_PACKED_STRUCT;
2234 typedef struct dot11_bsstrans_query dot11_bsstrans_query_t;
2235 #define DOT11_BSSTRANS_QUERY_LEN 4	/* Fixed length */
2236 
2237 /* BTM transition reason */
2238 #define DOT11_BSSTRANS_REASON_UNSPECIFIED		0
2239 #define DOT11_BSSTRANS_REASON_EXC_FRAME_LOSS		1
2240 #define DOT11_BSSTRANS_REASON_EXC_TRAFFIC_DELAY		2
2241 #define DOT11_BSSTRANS_REASON_INSUFF_QOS_CAPACITY	3
2242 #define DOT11_BSSTRANS_REASON_FIRST_ASSOC		4
2243 #define DOT11_BSSTRANS_REASON_LOAD_BALANCING		5
2244 #define DOT11_BSSTRANS_REASON_BETTER_AP_FOUND		6
2245 #define DOT11_BSSTRANS_REASON_DEAUTH_RX			7
2246 #define DOT11_BSSTRANS_REASON_8021X_EAP_AUTH_FAIL	8
2247 #define DOT11_BSSTRANS_REASON_4WAY_HANDSHK_FAIL		9
2248 #define DOT11_BSSTRANS_REASON_MANY_REPLAYCNT_FAIL	10
2249 #define DOT11_BSSTRANS_REASON_MANY_DATAMIC_FAIL		11
2250 #define DOT11_BSSTRANS_REASON_EXCEED_MAX_RETRANS	12
2251 #define DOT11_BSSTRANS_REASON_MANY_BCAST_DISASSOC_RX	13
2252 #define DOT11_BSSTRANS_REASON_MANY_BCAST_DEAUTH_RX	14
2253 #define DOT11_BSSTRANS_REASON_PREV_TRANSITION_FAIL	15
2254 #define DOT11_BSSTRANS_REASON_LOW_RSSI			16
2255 #define DOT11_BSSTRANS_REASON_ROAM_FROM_NON_80211	17
2256 #define DOT11_BSSTRANS_REASON_RX_BTM_REQ		18
2257 #define DOT11_BSSTRANS_REASON_PREF_LIST_INCLUDED	19
2258 #define DOT11_BSSTRANS_REASON_LEAVING_ESS		20
2259 
2260 /** BSS Management Transition Request frame header */
2261 BWL_PRE_PACKED_STRUCT struct dot11_bsstrans_req {
2262 	uint8 category;			/* category of action frame (10) */
2263 	uint8 action;			/* WNM action: trans_req (7) */
2264 	uint8 token;			/* dialog token */
2265 	uint8 reqmode;			/* transition request mode */
2266 	uint16 disassoc_tmr;		/* disassociation timer */
2267 	uint8 validity_intrvl;		/* validity interval */
2268 	uint8 data[1];			/* optional: BSS term duration, ... */
2269 						/* ...session info URL, candidate list */
2270 } BWL_POST_PACKED_STRUCT;
2271 typedef struct dot11_bsstrans_req dot11_bsstrans_req_t;
2272 #define DOT11_BSSTRANS_REQ_LEN 7	/* Fixed length */
2273 #define DOT11_BSSTRANS_REQ_FIXED_LEN 7u	/* Fixed length */
2274 
2275 /* BSS Mgmt Transition Request Mode Field - 802.11v */
2276 #define DOT11_BSSTRANS_REQMODE_PREF_LIST_INCL		0x01
2277 #define DOT11_BSSTRANS_REQMODE_ABRIDGED			0x02
2278 #define DOT11_BSSTRANS_REQMODE_DISASSOC_IMMINENT	0x04
2279 #define DOT11_BSSTRANS_REQMODE_BSS_TERM_INCL		0x08
2280 #define DOT11_BSSTRANS_REQMODE_ESS_DISASSOC_IMNT	0x10
2281 
2282 /** BSS Management transition response frame header */
2283 BWL_PRE_PACKED_STRUCT struct dot11_bsstrans_resp {
2284 	uint8 category;			/* category of action frame (10) */
2285 	uint8 action;			/* WNM action: trans_resp (8) */
2286 	uint8 token;			/* dialog token */
2287 	uint8 status;			/* transition status */
2288 	uint8 term_delay;		/* validity interval */
2289 	uint8 data[1];			/* optional: BSSID target, candidate list */
2290 } BWL_POST_PACKED_STRUCT;
2291 typedef struct dot11_bsstrans_resp dot11_bsstrans_resp_t;
2292 #define DOT11_BSSTRANS_RESP_LEN 5	/* Fixed length */
2293 
2294 /* BSS Mgmt Transition Response Status Field */
2295 #define DOT11_BSSTRANS_RESP_STATUS_ACCEPT			0
2296 #define DOT11_BSSTRANS_RESP_STATUS_REJECT			1
2297 #define DOT11_BSSTRANS_RESP_STATUS_REJ_INSUFF_BCN		2
2298 #define DOT11_BSSTRANS_RESP_STATUS_REJ_INSUFF_CAP		3
2299 #define DOT11_BSSTRANS_RESP_STATUS_REJ_TERM_UNDESIRED		4
2300 #define DOT11_BSSTRANS_RESP_STATUS_REJ_TERM_DELAY_REQ		5
2301 #define DOT11_BSSTRANS_RESP_STATUS_REJ_BSS_LIST_PROVIDED	6
2302 #define DOT11_BSSTRANS_RESP_STATUS_REJ_NO_SUITABLE_BSS		7
2303 #define DOT11_BSSTRANS_RESP_STATUS_REJ_LEAVING_ESS		8
2304 
2305 /** BSS Max Idle Period element */
2306 BWL_PRE_PACKED_STRUCT struct dot11_bss_max_idle_period_ie {
2307 	uint8 id;				/* 90, DOT11_MNG_BSS_MAX_IDLE_PERIOD_ID */
2308 	uint8 len;
2309 	uint16 max_idle_period;			/* in unit of 1000 TUs */
2310 	uint8 idle_opt;
2311 } BWL_POST_PACKED_STRUCT;
2312 typedef struct dot11_bss_max_idle_period_ie dot11_bss_max_idle_period_ie_t;
2313 #define DOT11_BSS_MAX_IDLE_PERIOD_IE_LEN	3	/* bss max idle period IE size */
2314 #define DOT11_BSS_MAX_IDLE_PERIOD_OPT_PROTECTED	1	/* BSS max idle option */
2315 
2316 /** TIM Broadcast request element */
2317 BWL_PRE_PACKED_STRUCT struct dot11_timbc_req_ie {
2318 	uint8 id;				/* 94, DOT11_MNG_TIMBC_REQ_ID */
2319 	uint8 len;
2320 	uint8 interval;				/* in unit of beacon interval */
2321 } BWL_POST_PACKED_STRUCT;
2322 typedef struct dot11_timbc_req_ie dot11_timbc_req_ie_t;
2323 #define DOT11_TIMBC_REQ_IE_LEN		1	/* Fixed length */
2324 
2325 /** TIM Broadcast request frame header */
2326 BWL_PRE_PACKED_STRUCT struct dot11_timbc_req {
2327 	uint8 category;				/* category of action frame (10) */
2328 	uint8 action;				/* WNM action: DOT11_WNM_ACTION_TIMBC_REQ(18) */
2329 	uint8 token;				/* dialog token */
2330 	uint8 data[1];				/* TIM broadcast request element */
2331 } BWL_POST_PACKED_STRUCT;
2332 typedef struct dot11_timbc_req dot11_timbc_req_t;
2333 #define DOT11_TIMBC_REQ_LEN		3	/* Fixed length */
2334 
2335 /** TIM Broadcast response element */
2336 BWL_PRE_PACKED_STRUCT struct dot11_timbc_resp_ie {
2337 	uint8 id;				/* 95, DOT11_MNG_TIM_BROADCAST_RESP_ID */
2338 	uint8 len;
2339 	uint8 status;				/* status of add request */
2340 	uint8 interval;				/* in unit of beacon interval */
2341 	int32 offset;				/* in unit of ms */
2342 	uint16 high_rate;			/* in unit of 0.5 Mb/s */
2343 	uint16 low_rate;			/* in unit of 0.5 Mb/s */
2344 } BWL_POST_PACKED_STRUCT;
2345 typedef struct dot11_timbc_resp_ie dot11_timbc_resp_ie_t;
2346 #define DOT11_TIMBC_DENY_RESP_IE_LEN	1	/* Deny. Fixed length */
2347 #define DOT11_TIMBC_ACCEPT_RESP_IE_LEN	10	/* Accept. Fixed length */
2348 
2349 #define DOT11_TIMBC_STATUS_ACCEPT		0
2350 #define DOT11_TIMBC_STATUS_ACCEPT_TSTAMP	1
2351 #define DOT11_TIMBC_STATUS_DENY			2
2352 #define DOT11_TIMBC_STATUS_OVERRIDDEN		3
2353 #define DOT11_TIMBC_STATUS_RESERVED		4
2354 
2355 /** TIM Broadcast request frame header */
2356 BWL_PRE_PACKED_STRUCT struct dot11_timbc_resp {
2357 	uint8 category;			/* category of action frame (10) */
2358 	uint8 action;			/* action: DOT11_WNM_ACTION_TIMBC_RESP(19) */
2359 	uint8 token;			/* dialog token */
2360 	uint8 data[1];			/* TIM broadcast response element */
2361 } BWL_POST_PACKED_STRUCT;
2362 typedef struct dot11_timbc_resp dot11_timbc_resp_t;
2363 #define DOT11_TIMBC_RESP_LEN	3	/* Fixed length */
2364 
2365 /** TIM element */
2366 BWL_PRE_PACKED_STRUCT struct dot11_tim_ie {
2367 	uint8 id;			/* 5, DOT11_MNG_TIM_ID	 */
2368 	uint8 len;			/* 4 - 255 */
2369 	uint8 dtim_count;		/* DTIM decrementing counter */
2370 	uint8 dtim_period;		/* DTIM period */
2371 	uint8 bitmap_control;		/* AID 0 + bitmap offset */
2372 	uint8 pvb[1];			/* Partial Virtual Bitmap, variable length */
2373 } BWL_POST_PACKED_STRUCT;
2374 typedef struct dot11_tim_ie dot11_tim_ie_t;
2375 #define DOT11_TIM_IE_FIXED_LEN	3	/* Fixed length, without id and len */
2376 #define DOT11_TIM_IE_FIXED_TOTAL_LEN	5	/* Fixed length, with id and len */
2377 
2378 /** TIM Broadcast frame header */
2379 BWL_PRE_PACKED_STRUCT struct dot11_timbc {
2380 	uint8 category;			/* category of action frame (11) */
2381 	uint8 action;			/* action: TIM (0) */
2382 	uint8 check_beacon;		/* need to check-beacon */
2383 	uint8 tsf[8];			/* Time Synchronization Function */
2384 	dot11_tim_ie_t tim_ie;		/* TIM element */
2385 } BWL_POST_PACKED_STRUCT;
2386 typedef struct dot11_timbc dot11_timbc_t;
2387 #define DOT11_TIMBC_HDR_LEN	(sizeof(dot11_timbc_t) - sizeof(dot11_tim_ie_t))
2388 #define DOT11_TIMBC_FIXED_LEN	(sizeof(dot11_timbc_t) - 1)	/* Fixed length */
2389 #define DOT11_TIMBC_LEN			11	/* Fixed length */
2390 
2391 /** TCLAS frame classifier type */
2392 BWL_PRE_PACKED_STRUCT struct dot11_tclas_fc_hdr {
2393 	uint8 type;
2394 	uint8 mask;
2395 	uint8 data[1];
2396 } BWL_POST_PACKED_STRUCT;
2397 typedef struct dot11_tclas_fc_hdr dot11_tclas_fc_hdr_t;
2398 #define DOT11_TCLAS_FC_HDR_LEN		2	/* Fixed length */
2399 
2400 #define DOT11_TCLAS_MASK_0		0x1
2401 #define DOT11_TCLAS_MASK_1		0x2
2402 #define DOT11_TCLAS_MASK_2		0x4
2403 #define DOT11_TCLAS_MASK_3		0x8
2404 #define DOT11_TCLAS_MASK_4		0x10
2405 #define DOT11_TCLAS_MASK_5		0x20
2406 #define DOT11_TCLAS_MASK_6		0x40
2407 #define DOT11_TCLAS_MASK_7		0x80
2408 
2409 #define DOT11_TCLAS_FC_0_ETH		0
2410 #define DOT11_TCLAS_FC_1_IP		1
2411 #define DOT11_TCLAS_FC_2_8021Q		2
2412 #define DOT11_TCLAS_FC_3_OFFSET		3
2413 #define DOT11_TCLAS_FC_4_IP_HIGHER	4
2414 #define DOT11_TCLAS_FC_5_8021D		5
2415 
2416 /** TCLAS frame classifier type 0 parameters for Ethernet */
2417 BWL_PRE_PACKED_STRUCT struct dot11_tclas_fc_0_eth {
2418 	uint8 type;
2419 	uint8 mask;
2420 	uint8 sa[ETHER_ADDR_LEN];
2421 	uint8 da[ETHER_ADDR_LEN];
2422 	uint16 eth_type;
2423 } BWL_POST_PACKED_STRUCT;
2424 typedef struct dot11_tclas_fc_0_eth dot11_tclas_fc_0_eth_t;
2425 #define DOT11_TCLAS_FC_0_ETH_LEN	16
2426 
2427 /** TCLAS frame classifier type 1 parameters for IPV4 */
2428 BWL_PRE_PACKED_STRUCT struct dot11_tclas_fc_1_ipv4 {
2429 	uint8 type;
2430 	uint8 mask;
2431 	uint8 version;
2432 	uint32 src_ip;
2433 	uint32 dst_ip;
2434 	uint16 src_port;
2435 	uint16 dst_port;
2436 	uint8 dscp;
2437 	uint8 protocol;
2438 	uint8 reserved;
2439 } BWL_POST_PACKED_STRUCT;
2440 typedef struct dot11_tclas_fc_1_ipv4 dot11_tclas_fc_1_ipv4_t;
2441 #define DOT11_TCLAS_FC_1_IPV4_LEN	18
2442 
2443 /** TCLAS frame classifier type 2 parameters for 802.1Q */
2444 BWL_PRE_PACKED_STRUCT struct dot11_tclas_fc_2_8021q {
2445 	uint8 type;
2446 	uint8 mask;
2447 	uint16 tci;
2448 } BWL_POST_PACKED_STRUCT;
2449 typedef struct dot11_tclas_fc_2_8021q dot11_tclas_fc_2_8021q_t;
2450 #define DOT11_TCLAS_FC_2_8021Q_LEN	4
2451 
2452 /** TCLAS frame classifier type 3 parameters for filter offset */
2453 BWL_PRE_PACKED_STRUCT struct dot11_tclas_fc_3_filter {
2454 	uint8 type;
2455 	uint8 mask;
2456 	uint16 offset;
2457 	uint8 data[1];
2458 } BWL_POST_PACKED_STRUCT;
2459 typedef struct dot11_tclas_fc_3_filter dot11_tclas_fc_3_filter_t;
2460 #define DOT11_TCLAS_FC_3_FILTER_LEN	4
2461 
2462 /** TCLAS frame classifier type 4 parameters for IPV4 is the same as TCLAS type 1 */
2463 typedef struct dot11_tclas_fc_1_ipv4 dot11_tclas_fc_4_ipv4_t;
2464 #define DOT11_TCLAS_FC_4_IPV4_LEN	DOT11_TCLAS_FC_1_IPV4_LEN
2465 
2466 /** TCLAS frame classifier type 4 parameters for IPV6 */
2467 BWL_PRE_PACKED_STRUCT struct dot11_tclas_fc_4_ipv6 {
2468 	uint8 type;
2469 	uint8 mask;
2470 	uint8 version;
2471 	uint8 saddr[16];
2472 	uint8 daddr[16];
2473 	uint16 src_port;
2474 	uint16 dst_port;
2475 	uint8 dscp;
2476 	uint8 nexthdr;
2477 	uint8 flow_lbl[3];
2478 } BWL_POST_PACKED_STRUCT;
2479 typedef struct dot11_tclas_fc_4_ipv6 dot11_tclas_fc_4_ipv6_t;
2480 #define DOT11_TCLAS_FC_4_IPV6_LEN	44
2481 
2482 /** TCLAS frame classifier type 5 parameters for 802.1D */
2483 BWL_PRE_PACKED_STRUCT struct dot11_tclas_fc_5_8021d {
2484 	uint8 type;
2485 	uint8 mask;
2486 	uint8 pcp;
2487 	uint8 cfi;
2488 	uint16 vid;
2489 } BWL_POST_PACKED_STRUCT;
2490 typedef struct dot11_tclas_fc_5_8021d dot11_tclas_fc_5_8021d_t;
2491 #define DOT11_TCLAS_FC_5_8021D_LEN	6
2492 
2493 /** TCLAS frame classifier type parameters */
2494 BWL_PRE_PACKED_STRUCT union dot11_tclas_fc {
2495 	uint8 data[1];
2496 	dot11_tclas_fc_hdr_t hdr;
2497 	dot11_tclas_fc_0_eth_t t0_eth;
2498 	dot11_tclas_fc_1_ipv4_t	t1_ipv4;
2499 	dot11_tclas_fc_2_8021q_t t2_8021q;
2500 	dot11_tclas_fc_3_filter_t t3_filter;
2501 	dot11_tclas_fc_4_ipv4_t	t4_ipv4;
2502 	dot11_tclas_fc_4_ipv6_t	t4_ipv6;
2503 	dot11_tclas_fc_5_8021d_t t5_8021d;
2504 } BWL_POST_PACKED_STRUCT;
2505 typedef union dot11_tclas_fc dot11_tclas_fc_t;
2506 
2507 #define DOT11_TCLAS_FC_MIN_LEN		4	/* Classifier Type 2 has the min size */
2508 #define DOT11_TCLAS_FC_MAX_LEN		254
2509 
2510 /** TCLAS element */
2511 BWL_PRE_PACKED_STRUCT struct dot11_tclas_ie {
2512 	uint8 id;				/* 14, DOT11_MNG_TCLAS_ID */
2513 	uint8 len;
2514 	uint8 user_priority;
2515 	dot11_tclas_fc_t fc;
2516 } BWL_POST_PACKED_STRUCT;
2517 typedef struct dot11_tclas_ie dot11_tclas_ie_t;
2518 #define DOT11_TCLAS_IE_LEN		3u	/* Fixed length, include id and len */
2519 
2520 /** TCLAS processing element */
2521 BWL_PRE_PACKED_STRUCT struct dot11_tclas_proc_ie {
2522 	uint8 id;				/* 44, DOT11_MNG_TCLAS_PROC_ID */
2523 	uint8 len;
2524 	uint8 process;
2525 } BWL_POST_PACKED_STRUCT;
2526 typedef struct dot11_tclas_proc_ie dot11_tclas_proc_ie_t;
2527 #define DOT11_TCLAS_PROC_IE_LEN		3	/* Fixed length, include id and len */
2528 
2529 #define DOT11_TCLAS_PROC_LEN		1u	/* Proc ie length is always 1 byte */
2530 
2531 #define DOT11_TCLAS_PROC_MATCHALL	0	/* All high level element need to match */
2532 #define DOT11_TCLAS_PROC_MATCHONE	1	/* One high level element need to match */
2533 #define DOT11_TCLAS_PROC_NONMATCH	2	/* Non match to any high level element */
2534 
2535 /* TSPEC element defined in 802.11 std section 8.4.2.32 - Not supported */
2536 #define DOT11_TSPEC_IE_LEN		57	/* Fixed length */
2537 
2538 /** TCLAS Mask element */
2539 BWL_PRE_PACKED_STRUCT struct dot11_tclas_mask_ie {
2540 	uint8 id;				/* DOT11_MNG_ID_EXT_ID (255) */
2541 	uint8 len;
2542 	uint8 id_ext;				/* TCLAS_EXTID_MNG_MASK_ID (89) */
2543 	dot11_tclas_fc_t fc;			/* Variable length frame classifier (fc) */
2544 } BWL_POST_PACKED_STRUCT;
2545 typedef struct dot11_tclas_mask_ie dot11_tclas_mask_ie_t;
2546 #define DOT11_TCLAS_MASK_IE_LEN		1u	/* Fixed length, excludes id and len */
2547 #define DOT11_TCLAS_MASK_IE_HDR_LEN	3u	/* Fixed length */
2548 
2549 /* Bitmap definitions for the User Priority Bitmap
2550  * Each bit in the bitmap corresponds to a user priority.
2551  */
2552 #define DOT11_UP_CTRL_UP_0		0u
2553 #define DOT11_UP_CTRL_UP_1		1u
2554 #define DOT11_UP_CTRL_UP_2		2u
2555 #define DOT11_UP_CTRL_UP_3		3u
2556 #define DOT11_UP_CTRL_UP_4		4u
2557 #define DOT11_UP_CTRL_UP_5		5u
2558 #define DOT11_UP_CTRL_UP_6		6u
2559 #define DOT11_UP_CTRL_UP_7		7u
2560 
2561 /* User priority control (up_ctl)  macros */
2562 #define DOT11_UPC_UP_BITMAP_MASK	0xFFu	/* UP bitmap mask */
2563 #define DOT11_UPC_UP_BITMAP_SHIFT	0u	/* UP bitmap shift */
2564 #define DOT11_UPC_UP_LIMIT_MASK		0x700u	/* UP limit mask */
2565 #define DOT11_UPC_UP_LIMIT_SHIFT	8u	/* UP limit shift */
2566 
2567 /* MSCS Request Types */
2568 #define DOT11_MSCS_REQ_TYPE_ADD		0u
2569 #define DOT11_MSCS_REQ_TYPE_REMOVE	1u
2570 #define DOT11_MSCS_REQ_TYPE_CHANGE	2u
2571 
2572 /** MSCS Descriptor element */
2573 BWL_PRE_PACKED_STRUCT struct dot11_mscs_descr_ie {
2574 	uint8  id;				/* DOT11_MNG_ID_EXT_ID (255) */
2575 	uint8  len;
2576 	uint8  id_ext;				/* MSCS_EXTID_MNG_DESCR_ID (88) */
2577 	uint8  req_type;			/* MSCS request type */
2578 	uint16 up_ctl;				/* User priority control:
2579 						 * Bits 0..7, up_bitmap(8 bits);
2580 						 * Bits 8..10, up_limit (3 bits)
2581 						 * Bits 11..15 reserved (5 bits)
2582 						 */
2583 	uint32 stream_timeout;
2584 	uint8  data[];
2585 	/* optional tclas mask elements */	/* dot11_tclas_mask_ie_t */
2586 	/* optional sub-elements */
2587 } BWL_POST_PACKED_STRUCT;
2588 typedef struct dot11_mscs_descr_ie dot11_mscs_descr_ie_t;
2589 #define DOT11_MSCS_DESCR_IE_LEN		8u	/* Fixed length, exludes id and len */
2590 #define DOT11_MSCS_DESCR_IE_HDR_LEN	10u	/* Entire descriptor header length */
2591 
2592 /** MSCS Request frame, refer section 9.4.18.6 in the spec P802.11REVmd_D3.1 */
2593 BWL_PRE_PACKED_STRUCT struct dot11_mscs_req {
2594 	uint8 category;				/* ACTION_RAV_STREAMING (19) */
2595 	uint8 robust_action;			/* action: MSCS Req (4), MSCS Res (5), etc. */
2596 	uint8 dialog_token;			/* To identify the MSCS request and response */
2597 	dot11_mscs_descr_ie_t mscs_descr;	/* MSCS descriptor */
2598 } BWL_POST_PACKED_STRUCT;
2599 typedef struct dot11_mscs_req dot11_mscs_req_t;
2600 #define DOT11_MSCS_REQ_HDR_LEN		3u	/* Fixed length */
2601 
2602 /** MSCS Response frame, refer section 9.4.18.7 in the spec P802.11REVmd_D3.1 */
2603 BWL_PRE_PACKED_STRUCT struct dot11_mscs_res {
2604 	uint8  category;			/* ACTION_RAV_STREAMING (19) */
2605 	uint8  robust_action;			/* action: MSCS Req (4), MSCS Res (5), etc. */
2606 	uint8  dialog_token;			/* To identify the MSCS request and response */
2607 	uint16 status;				/* status code */
2608 	uint8  data[];				/* optional MSCS descriptor */
2609 } BWL_POST_PACKED_STRUCT;
2610 typedef struct dot11_mscs_res dot11_mscs_res_t;
2611 #define DOT11_MSCS_RES_HDR_LEN		5u	/* Fixed length */
2612 
2613 /* MSCS subelement */
2614 #define DOT11_MSCS_SUBELEM_ID_STATUS	1u	/* MSCS subelement ID for the status */
2615 
2616 BWL_PRE_PACKED_STRUCT struct dot11_mscs_subelement {
2617 	uint8 id;				/* MSCS specific subelement ID */
2618 	uint8 len;				/* Length in bytes */
2619 	uint8 data[];				/* Subelement specific data */
2620 } BWL_POST_PACKED_STRUCT;
2621 typedef struct dot11_mscs_subelement dot11_mscs_subelement_t;
2622 #define DOT11_MSCS_DESCR_SUBELEM_IE_STATUS_LEN	2u	/* Subelement ID status length */
2623 
2624 /** TFS request element */
2625 BWL_PRE_PACKED_STRUCT struct dot11_tfs_req_ie {
2626 	uint8 id;				/* 91, DOT11_MNG_TFS_REQUEST_ID */
2627 	uint8 len;
2628 	uint8 tfs_id;
2629 	uint8 actcode;
2630 	uint8 data[1];
2631 } BWL_POST_PACKED_STRUCT;
2632 typedef struct dot11_tfs_req_ie dot11_tfs_req_ie_t;
2633 #define DOT11_TFS_REQ_IE_LEN		2	/* Fixed length, without id and len */
2634 
2635 /** TFS request action codes (bitfield) */
2636 #define DOT11_TFS_ACTCODE_DELETE	1
2637 #define DOT11_TFS_ACTCODE_NOTIFY	2
2638 
2639 /** TFS request subelement IDs */
2640 #define DOT11_TFS_REQ_TFS_SE_ID		1
2641 #define DOT11_TFS_REQ_VENDOR_SE_ID	221
2642 
2643 /** TFS subelement */
2644 BWL_PRE_PACKED_STRUCT struct dot11_tfs_se {
2645 	uint8 sub_id;
2646 	uint8 len;
2647 	uint8 data[1];				/* TCLAS element(s) + optional TCLAS proc */
2648 } BWL_POST_PACKED_STRUCT;
2649 typedef struct dot11_tfs_se dot11_tfs_se_t;
2650 
2651 /** TFS response element */
2652 BWL_PRE_PACKED_STRUCT struct dot11_tfs_resp_ie {
2653 	uint8 id;				/* 92, DOT11_MNG_TFS_RESPONSE_ID */
2654 	uint8 len;
2655 	uint8 tfs_id;
2656 	uint8 data[1];
2657 } BWL_POST_PACKED_STRUCT;
2658 typedef struct dot11_tfs_resp_ie dot11_tfs_resp_ie_t;
2659 #define DOT11_TFS_RESP_IE_LEN		1u	/* Fixed length, without id and len */
2660 
2661 /** TFS response subelement IDs (same subelments, but different IDs than in TFS request */
2662 #define DOT11_TFS_RESP_TFS_STATUS_SE_ID		1
2663 #define DOT11_TFS_RESP_TFS_SE_ID		2
2664 #define DOT11_TFS_RESP_VENDOR_SE_ID		221
2665 
2666 /** TFS status subelement */
2667 BWL_PRE_PACKED_STRUCT struct dot11_tfs_status_se {
2668 	uint8 sub_id;				/* 92, DOT11_MNG_TFS_RESPONSE_ID */
2669 	uint8 len;
2670 	uint8 resp_st;
2671 	uint8 data[1];				/* Potential dot11_tfs_se_t included */
2672 } BWL_POST_PACKED_STRUCT;
2673 typedef struct dot11_tfs_status_se dot11_tfs_status_se_t;
2674 #define DOT11_TFS_STATUS_SE_LEN			1	/* Fixed length, without id and len */
2675 
2676 /* Following Definition should be merged to FMS_TFS macro below */
2677 /* TFS Response status code. Identical to FMS Element status, without N/A  */
2678 #define DOT11_TFS_STATUS_ACCEPT			0
2679 #define DOT11_TFS_STATUS_DENY_FORMAT		1
2680 #define DOT11_TFS_STATUS_DENY_RESOURCE		2
2681 #define DOT11_TFS_STATUS_DENY_POLICY		4
2682 #define DOT11_TFS_STATUS_DENY_UNSPECIFIED	5
2683 #define DOT11_TFS_STATUS_ALTPREF_POLICY		7
2684 #define DOT11_TFS_STATUS_ALTPREF_TCLAS_UNSUPP	14
2685 
2686 /* FMS Element Status and TFS Response Status Definition */
2687 #define DOT11_FMS_TFS_STATUS_ACCEPT		0
2688 #define DOT11_FMS_TFS_STATUS_DENY_FORMAT	1
2689 #define DOT11_FMS_TFS_STATUS_DENY_RESOURCE	2
2690 #define DOT11_FMS_TFS_STATUS_DENY_MULTIPLE_DI	3
2691 #define DOT11_FMS_TFS_STATUS_DENY_POLICY	4
2692 #define DOT11_FMS_TFS_STATUS_DENY_UNSPECIFIED	5
2693 #define DOT11_FMS_TFS_STATUS_ALT_DIFF_DI	6
2694 #define DOT11_FMS_TFS_STATUS_ALT_POLICY		7
2695 #define DOT11_FMS_TFS_STATUS_ALT_CHANGE_DI	8
2696 #define DOT11_FMS_TFS_STATUS_ALT_MCRATE		9
2697 #define DOT11_FMS_TFS_STATUS_TERM_POLICY	10
2698 #define DOT11_FMS_TFS_STATUS_TERM_RESOURCE	11
2699 #define DOT11_FMS_TFS_STATUS_TERM_HIGHER_PRIO	12
2700 #define DOT11_FMS_TFS_STATUS_ALT_CHANGE_MDI	13
2701 #define DOT11_FMS_TFS_STATUS_ALT_TCLAS_UNSUPP	14
2702 
2703 /** TFS Management Request frame header */
2704 BWL_PRE_PACKED_STRUCT struct dot11_tfs_req {
2705 	uint8 category;				/* category of action frame (10) */
2706 	uint8 action;				/* WNM action: TFS request (13) */
2707 	uint8 token;				/* dialog token */
2708 	uint8 data[1];				/* Elements */
2709 } BWL_POST_PACKED_STRUCT;
2710 typedef struct dot11_tfs_req dot11_tfs_req_t;
2711 #define DOT11_TFS_REQ_LEN		3	/* Fixed length */
2712 
2713 /** TFS Management Response frame header */
2714 BWL_PRE_PACKED_STRUCT struct dot11_tfs_resp {
2715 	uint8 category;				/* category of action frame (10) */
2716 	uint8 action;				/* WNM action: TFS request (14) */
2717 	uint8 token;				/* dialog token */
2718 	uint8 data[1];				/* Elements */
2719 } BWL_POST_PACKED_STRUCT;
2720 typedef struct dot11_tfs_resp dot11_tfs_resp_t;
2721 #define DOT11_TFS_RESP_LEN		3	/* Fixed length */
2722 
2723 /** TFS Management Notify frame request header */
2724 BWL_PRE_PACKED_STRUCT struct dot11_tfs_notify_req {
2725 	uint8 category;				/* category of action frame (10) */
2726 	uint8 action;				/* WNM action: TFS notify request (15) */
2727 	uint8 tfs_id_cnt;			/* TFS IDs count */
2728 	uint8 tfs_id[1];			/* Array of TFS IDs */
2729 } BWL_POST_PACKED_STRUCT;
2730 typedef struct dot11_tfs_notify_req dot11_tfs_notify_req_t;
2731 #define DOT11_TFS_NOTIFY_REQ_LEN	3	/* Fixed length */
2732 
2733 /** TFS Management Notify frame response header */
2734 BWL_PRE_PACKED_STRUCT struct dot11_tfs_notify_resp {
2735 	uint8 category;				/* category of action frame (10) */
2736 	uint8 action;				/* WNM action: TFS notify response (28) */
2737 	uint8 tfs_id_cnt;			/* TFS IDs count */
2738 	uint8 tfs_id[1];			/* Array of TFS IDs */
2739 } BWL_POST_PACKED_STRUCT;
2740 typedef struct dot11_tfs_notify_resp dot11_tfs_notify_resp_t;
2741 #define DOT11_TFS_NOTIFY_RESP_LEN	3	/* Fixed length */
2742 
2743 /** WNM-Sleep Management Request frame header */
2744 BWL_PRE_PACKED_STRUCT struct dot11_wnm_sleep_req {
2745 	uint8 category;				/* category of action frame (10) */
2746 	uint8 action;				/* WNM action: wnm-sleep request (16) */
2747 	uint8 token;				/* dialog token */
2748 	uint8 data[1];				/* Elements */
2749 } BWL_POST_PACKED_STRUCT;
2750 typedef struct dot11_wnm_sleep_req dot11_wnm_sleep_req_t;
2751 #define DOT11_WNM_SLEEP_REQ_LEN		3	/* Fixed length */
2752 
2753 /** WNM-Sleep Management Response frame header */
2754 BWL_PRE_PACKED_STRUCT struct dot11_wnm_sleep_resp {
2755 	uint8 category;				/* category of action frame (10) */
2756 	uint8 action;				/* WNM action: wnm-sleep request (17) */
2757 	uint8 token;				/* dialog token */
2758 	uint16 key_len;				/* key data length */
2759 	uint8 data[1];				/* Elements */
2760 } BWL_POST_PACKED_STRUCT;
2761 typedef struct dot11_wnm_sleep_resp dot11_wnm_sleep_resp_t;
2762 #define DOT11_WNM_SLEEP_RESP_LEN	5	/* Fixed length */
2763 
2764 #define DOT11_WNM_SLEEP_SUBELEM_ID_GTK	0
2765 #define DOT11_WNM_SLEEP_SUBELEM_ID_IGTK	1
2766 
2767 BWL_PRE_PACKED_STRUCT struct dot11_wnm_sleep_subelem_gtk {
2768 	uint8 sub_id;
2769 	uint8 len;
2770 	uint16 key_info;
2771 	uint8 key_length;
2772 	uint8 rsc[8];
2773 	uint8 key[1];
2774 } BWL_POST_PACKED_STRUCT;
2775 typedef struct dot11_wnm_sleep_subelem_gtk dot11_wnm_sleep_subelem_gtk_t;
2776 #define DOT11_WNM_SLEEP_SUBELEM_GTK_FIXED_LEN	11	/* without sub_id, len, and key */
2777 #define DOT11_WNM_SLEEP_SUBELEM_GTK_MAX_LEN	43	/* without sub_id and len */
2778 
2779 BWL_PRE_PACKED_STRUCT struct dot11_wnm_sleep_subelem_igtk {
2780 	uint8 sub_id;
2781 	uint8 len;
2782 	uint16 key_id;
2783 	uint8 pn[6];
2784 	uint8 key[16];
2785 } BWL_POST_PACKED_STRUCT;
2786 typedef struct dot11_wnm_sleep_subelem_igtk dot11_wnm_sleep_subelem_igtk_t;
2787 #define DOT11_WNM_SLEEP_SUBELEM_IGTK_LEN 24	/* Fixed length */
2788 
2789 BWL_PRE_PACKED_STRUCT struct dot11_wnm_sleep_ie {
2790 	uint8 id;				/* 93, DOT11_MNG_WNM_SLEEP_MODE_ID */
2791 	uint8 len;
2792 	uint8 act_type;
2793 	uint8 resp_status;
2794 	uint16 interval;
2795 } BWL_POST_PACKED_STRUCT;
2796 typedef struct dot11_wnm_sleep_ie dot11_wnm_sleep_ie_t;
2797 #define DOT11_WNM_SLEEP_IE_LEN		4	/* Fixed length */
2798 
2799 #define DOT11_WNM_SLEEP_ACT_TYPE_ENTER	0
2800 #define DOT11_WNM_SLEEP_ACT_TYPE_EXIT	1
2801 
2802 #define DOT11_WNM_SLEEP_RESP_ACCEPT	0
2803 #define DOT11_WNM_SLEEP_RESP_UPDATE	1
2804 #define DOT11_WNM_SLEEP_RESP_DENY	2
2805 #define DOT11_WNM_SLEEP_RESP_DENY_TEMP	3
2806 #define DOT11_WNM_SLEEP_RESP_DENY_KEY	4
2807 #define DOT11_WNM_SLEEP_RESP_DENY_INUSE	5
2808 #define DOT11_WNM_SLEEP_RESP_LAST	6
2809 
2810 /** DMS Management Request frame header */
2811 BWL_PRE_PACKED_STRUCT struct dot11_dms_req {
2812 	uint8 category;				/* category of action frame (10) */
2813 	uint8 action;				/* WNM action: dms request (23) */
2814 	uint8 token;				/* dialog token */
2815 	uint8 data[1];				/* Elements */
2816 } BWL_POST_PACKED_STRUCT;
2817 typedef struct dot11_dms_req dot11_dms_req_t;
2818 #define DOT11_DMS_REQ_LEN		3	/* Fixed length */
2819 
2820 /** DMS Management Response frame header */
2821 BWL_PRE_PACKED_STRUCT struct dot11_dms_resp {
2822 	uint8 category;				/* category of action frame (10) */
2823 	uint8 action;				/* WNM action: dms request (24) */
2824 	uint8 token;				/* dialog token */
2825 	uint8 data[1];				/* Elements */
2826 } BWL_POST_PACKED_STRUCT;
2827 typedef struct dot11_dms_resp dot11_dms_resp_t;
2828 #define DOT11_DMS_RESP_LEN		3	/* Fixed length */
2829 
2830 /** DMS request element */
2831 BWL_PRE_PACKED_STRUCT struct dot11_dms_req_ie {
2832 	uint8 id;				/* 99, DOT11_MNG_DMS_REQUEST_ID */
2833 	uint8 len;
2834 	uint8 data[1];
2835 } BWL_POST_PACKED_STRUCT;
2836 typedef struct dot11_dms_req_ie dot11_dms_req_ie_t;
2837 #define DOT11_DMS_REQ_IE_LEN		2	/* Fixed length */
2838 
2839 /** DMS response element */
2840 BWL_PRE_PACKED_STRUCT struct dot11_dms_resp_ie {
2841 	uint8 id;				/* 100, DOT11_MNG_DMS_RESPONSE_ID */
2842 	uint8 len;
2843 	uint8 data[1];
2844 } BWL_POST_PACKED_STRUCT;
2845 typedef struct dot11_dms_resp_ie dot11_dms_resp_ie_t;
2846 #define DOT11_DMS_RESP_IE_LEN		2	/* Fixed length */
2847 
2848 /** DMS request descriptor */
2849 BWL_PRE_PACKED_STRUCT struct dot11_dms_req_desc {
2850 	uint8 dms_id;
2851 	uint8 len;
2852 	uint8 type;
2853 	uint8 data[1];
2854 } BWL_POST_PACKED_STRUCT;
2855 typedef struct dot11_dms_req_desc dot11_dms_req_desc_t;
2856 #define DOT11_DMS_REQ_DESC_LEN		3	/* Fixed length */
2857 
2858 #define DOT11_DMS_REQ_TYPE_ADD		0
2859 #define DOT11_DMS_REQ_TYPE_REMOVE	1
2860 #define DOT11_DMS_REQ_TYPE_CHANGE	2
2861 
2862 /** DMS response status */
2863 BWL_PRE_PACKED_STRUCT struct dot11_dms_resp_st {
2864 	uint8 dms_id;
2865 	uint8 len;
2866 	uint8 type;
2867 	uint16 lsc;
2868 	uint8 data[1];
2869 } BWL_POST_PACKED_STRUCT;
2870 typedef struct dot11_dms_resp_st dot11_dms_resp_st_t;
2871 #define DOT11_DMS_RESP_STATUS_LEN	5	/* Fixed length */
2872 
2873 #define DOT11_DMS_RESP_TYPE_ACCEPT	0
2874 #define DOT11_DMS_RESP_TYPE_DENY	1
2875 #define DOT11_DMS_RESP_TYPE_TERM	2
2876 
2877 #define DOT11_DMS_RESP_LSC_UNSUPPORTED	0xFFFF
2878 
2879 /** WNM-Notification Request frame header */
2880 BWL_PRE_PACKED_STRUCT struct dot11_wnm_notif_req {
2881 	uint8 category;				/* category of action frame (10) */
2882 	uint8 action;				/* WNM action: Notification request (26) */
2883 	uint8 token;				/* dialog token */
2884 	uint8 type;				   /* type */
2885 	uint8 data[1];				/* Sub-elements */
2886 } BWL_POST_PACKED_STRUCT;
2887 typedef struct dot11_wnm_notif_req dot11_wnm_notif_req_t;
2888 #define DOT11_WNM_NOTIF_REQ_LEN		4	/* Fixed length */
2889 
2890 /** FMS Management Request frame header */
2891 BWL_PRE_PACKED_STRUCT struct dot11_fms_req {
2892 	uint8 category;				/* category of action frame (10) */
2893 	uint8 action;				/* WNM action: fms request (9) */
2894 	uint8 token;				/* dialog token */
2895 	uint8 data[1];				/* Elements */
2896 } BWL_POST_PACKED_STRUCT;
2897 typedef struct dot11_fms_req dot11_fms_req_t;
2898 #define DOT11_FMS_REQ_LEN		3	/* Fixed length */
2899 
2900 /** FMS Management Response frame header */
2901 BWL_PRE_PACKED_STRUCT struct dot11_fms_resp {
2902 	uint8 category;				/* category of action frame (10) */
2903 	uint8 action;				/* WNM action: fms request (10) */
2904 	uint8 token;				/* dialog token */
2905 	uint8 data[1];				/* Elements */
2906 } BWL_POST_PACKED_STRUCT;
2907 typedef struct dot11_fms_resp dot11_fms_resp_t;
2908 #define DOT11_FMS_RESP_LEN		3	/* Fixed length */
2909 
2910 /** FMS Descriptor element */
2911 BWL_PRE_PACKED_STRUCT struct dot11_fms_desc {
2912 	uint8 id;
2913 	uint8 len;
2914 	uint8 num_fms_cnt;
2915 	uint8 data[1];
2916 } BWL_POST_PACKED_STRUCT;
2917 typedef struct dot11_fms_desc dot11_fms_desc_t;
2918 #define DOT11_FMS_DESC_LEN		1	/* Fixed length */
2919 
2920 #define DOT11_FMS_CNTR_MAX		0x8
2921 #define DOT11_FMS_CNTR_ID_MASK		0x7
2922 #define DOT11_FMS_CNTR_ID_SHIFT		0x0
2923 #define DOT11_FMS_CNTR_COUNT_MASK	0xf1
2924 #define DOT11_FMS_CNTR_SHIFT		0x3
2925 
2926 /** FMS request element */
2927 BWL_PRE_PACKED_STRUCT struct dot11_fms_req_ie {
2928 	uint8 id;
2929 	uint8 len;
2930 	uint8 fms_token;			/* token used to identify fms stream set */
2931 	uint8 data[1];
2932 } BWL_POST_PACKED_STRUCT;
2933 typedef struct dot11_fms_req_ie dot11_fms_req_ie_t;
2934 #define DOT11_FMS_REQ_IE_FIX_LEN		1	/* Fixed length */
2935 
2936 BWL_PRE_PACKED_STRUCT struct dot11_rate_id_field {
2937 	uint8 mask;
2938 	uint8 mcs_idx;
2939 	uint16 rate;
2940 } BWL_POST_PACKED_STRUCT;
2941 typedef struct dot11_rate_id_field dot11_rate_id_field_t;
2942 #define DOT11_RATE_ID_FIELD_MCS_SEL_MASK	0x7
2943 #define DOT11_RATE_ID_FIELD_MCS_SEL_OFFSET	0
2944 #define DOT11_RATE_ID_FIELD_RATETYPE_MASK	0x18
2945 #define DOT11_RATE_ID_FIELD_RATETYPE_OFFSET	3
2946 #define DOT11_RATE_ID_FIELD_LEN		sizeof(dot11_rate_id_field_t)
2947 
2948 /** FMS request subelements */
2949 BWL_PRE_PACKED_STRUCT struct dot11_fms_se {
2950 	uint8 sub_id;
2951 	uint8 len;
2952 	uint8 interval;
2953 	uint8 max_interval;
2954 	dot11_rate_id_field_t rate;
2955 	uint8 data[1];
2956 } BWL_POST_PACKED_STRUCT;
2957 typedef struct dot11_fms_se dot11_fms_se_t;
2958 #define DOT11_FMS_REQ_SE_LEN		6	/* Fixed length */
2959 
2960 #define DOT11_FMS_REQ_SE_ID_FMS		1	/* FMS subelement */
2961 #define DOT11_FMS_REQ_SE_ID_VS		221	/* Vendor Specific subelement */
2962 
2963 /** FMS response element */
2964 BWL_PRE_PACKED_STRUCT struct dot11_fms_resp_ie {
2965 	uint8 id;
2966 	uint8 len;
2967 	uint8 fms_token;
2968 	uint8 data[1];
2969 } BWL_POST_PACKED_STRUCT;
2970 typedef struct dot11_fms_resp_ie dot11_fms_resp_ie_t;
2971 #define DOT11_FMS_RESP_IE_FIX_LEN		1	/* Fixed length */
2972 
2973 /* FMS status subelements */
2974 #define DOT11_FMS_STATUS_SE_ID_FMS	1	/* FMS Status */
2975 #define DOT11_FMS_STATUS_SE_ID_TCLAS	2	/* TCLAS Status */
2976 #define DOT11_FMS_STATUS_SE_ID_VS	221	/* Vendor Specific subelement */
2977 
2978 /** FMS status subelement */
2979 BWL_PRE_PACKED_STRUCT struct dot11_fms_status_se {
2980 	uint8 sub_id;
2981 	uint8 len;
2982 	uint8 status;
2983 	uint8 interval;
2984 	uint8 max_interval;
2985 	uint8 fmsid;
2986 	uint8 counter;
2987 	dot11_rate_id_field_t rate;
2988 	uint8 mcast_addr[ETHER_ADDR_LEN];
2989 } BWL_POST_PACKED_STRUCT;
2990 typedef struct dot11_fms_status_se dot11_fms_status_se_t;
2991 #define DOT11_FMS_STATUS_SE_LEN		15	/* Fixed length */
2992 
2993 /** TCLAS status subelement */
2994 BWL_PRE_PACKED_STRUCT struct dot11_tclas_status_se {
2995 	uint8 sub_id;
2996 	uint8 len;
2997 	uint8 fmsid;
2998 	uint8 data[1];
2999 } BWL_POST_PACKED_STRUCT;
3000 typedef struct dot11_tclas_status_se dot11_tclas_status_se_t;
3001 #define DOT11_TCLAS_STATUS_SE_LEN		1	/* Fixed length */
3002 
3003 BWL_PRE_PACKED_STRUCT struct dot11_addba_req {
3004 	uint8 category;				/* category of action frame (3) */
3005 	uint8 action;				/* action: addba req */
3006 	uint8 token;				/* identifier */
3007 	uint16 addba_param_set;		/* parameter set */
3008 	uint16 timeout;				/* timeout in seconds */
3009 	uint16 start_seqnum;		/* starting sequence number */
3010 } BWL_POST_PACKED_STRUCT;
3011 typedef struct dot11_addba_req dot11_addba_req_t;
3012 #define DOT11_ADDBA_REQ_LEN		9	/* length of addba req frame */
3013 
3014 BWL_PRE_PACKED_STRUCT struct dot11_addba_resp {
3015 	uint8 category;				/* category of action frame (3) */
3016 	uint8 action;				/* action: addba resp */
3017 	uint8 token;				/* identifier */
3018 	uint16 status;				/* status of add request */
3019 	uint16 addba_param_set;			/* negotiated parameter set */
3020 	uint16 timeout;				/* negotiated timeout in seconds */
3021 } BWL_POST_PACKED_STRUCT;
3022 typedef struct dot11_addba_resp dot11_addba_resp_t;
3023 #define DOT11_ADDBA_RESP_LEN		9	/* length of addba resp frame */
3024 
3025 /* DELBA action parameters */
3026 #define DOT11_DELBA_PARAM_INIT_MASK	0x0800	/* initiator mask */
3027 #define DOT11_DELBA_PARAM_INIT_SHIFT	11	/* initiator shift */
3028 #define DOT11_DELBA_PARAM_TID_MASK	0xf000	/* tid mask */
3029 #define DOT11_DELBA_PARAM_TID_SHIFT	12	/* tid shift */
3030 
3031 BWL_PRE_PACKED_STRUCT struct dot11_delba {
3032 	uint8 category;				/* category of action frame (3) */
3033 	uint8 action;				/* action: addba req */
3034 	uint16 delba_param_set;			/* paarmeter set */
3035 	uint16 reason;				/* reason for dellba */
3036 } BWL_POST_PACKED_STRUCT;
3037 typedef struct dot11_delba dot11_delba_t;
3038 #define DOT11_DELBA_LEN			6	/* length of delba frame */
3039 
3040 /* SA Query action field value */
3041 #define SA_QUERY_REQUEST		0
3042 #define SA_QUERY_RESPONSE		1
3043 
3044 /* ************* 802.11r related definitions. ************* */
3045 
3046 /** Over-the-DS Fast Transition Request frame header */
3047 BWL_PRE_PACKED_STRUCT struct dot11_ft_req {
3048 	uint8 category;			/* category of action frame (6) */
3049 	uint8 action;			/* action: ft req */
3050 	uint8 sta_addr[ETHER_ADDR_LEN];
3051 	uint8 tgt_ap_addr[ETHER_ADDR_LEN];
3052 	uint8 data[1];			/* Elements */
3053 } BWL_POST_PACKED_STRUCT;
3054 typedef struct dot11_ft_req dot11_ft_req_t;
3055 #define DOT11_FT_REQ_FIXED_LEN 14
3056 
3057 /** Over-the-DS Fast Transition Response frame header */
3058 BWL_PRE_PACKED_STRUCT struct dot11_ft_res {
3059 	uint8 category;			/* category of action frame (6) */
3060 	uint8 action;			/* action: ft resp */
3061 	uint8 sta_addr[ETHER_ADDR_LEN];
3062 	uint8 tgt_ap_addr[ETHER_ADDR_LEN];
3063 	uint16 status;			/* status code */
3064 	uint8 data[1];			/* Elements */
3065 } BWL_POST_PACKED_STRUCT;
3066 typedef struct dot11_ft_res dot11_ft_res_t;
3067 #define DOT11_FT_RES_FIXED_LEN 16
3068 
3069 /** RDE RIC Data Element. */
3070 BWL_PRE_PACKED_STRUCT struct dot11_rde_ie {
3071 	uint8 id;			/* 11r, DOT11_MNG_RDE_ID */
3072 	uint8 length;
3073 	uint8 rde_id;			/* RDE identifier. */
3074 	uint8 rd_count;			/* Resource Descriptor Count. */
3075 	uint16 status;			/* Status Code. */
3076 } BWL_POST_PACKED_STRUCT;
3077 typedef struct dot11_rde_ie dot11_rde_ie_t;
3078 
3079 /* 11r - Size of the RDE (RIC Data Element) IE, including TLV header. */
3080 #define DOT11_MNG_RDE_IE_LEN sizeof(dot11_rde_ie_t)
3081 
3082 /* ************* 802.11k related definitions. ************* */
3083 
3084 /* Radio measurements enabled capability ie */
3085 #define DOT11_RRM_CAP_LEN		5	/* length of rrm cap bitmap */
3086 #define RCPI_IE_LEN 1
3087 #define RSNI_IE_LEN 1
3088 BWL_PRE_PACKED_STRUCT struct dot11_rrm_cap_ie {
3089 	uint8 cap[DOT11_RRM_CAP_LEN];
3090 } BWL_POST_PACKED_STRUCT;
3091 typedef struct dot11_rrm_cap_ie dot11_rrm_cap_ie_t;
3092 
3093 /* Bitmap definitions for cap ie */
3094 #define DOT11_RRM_CAP_LINK		0
3095 #define DOT11_RRM_CAP_NEIGHBOR_REPORT	1
3096 #define DOT11_RRM_CAP_PARALLEL		2
3097 #define DOT11_RRM_CAP_REPEATED		3
3098 #define DOT11_RRM_CAP_BCN_PASSIVE	4
3099 #define DOT11_RRM_CAP_BCN_ACTIVE	5
3100 #define DOT11_RRM_CAP_BCN_TABLE		6
3101 #define DOT11_RRM_CAP_BCN_REP_COND	7
3102 #define DOT11_RRM_CAP_FM		8
3103 #define DOT11_RRM_CAP_CLM		9
3104 #define DOT11_RRM_CAP_NHM		10
3105 #define DOT11_RRM_CAP_SM		11
3106 #define DOT11_RRM_CAP_LCIM		12
3107 #define DOT11_RRM_CAP_LCIA		13
3108 #define DOT11_RRM_CAP_TSCM		14
3109 #define DOT11_RRM_CAP_TTSCM		15
3110 #define DOT11_RRM_CAP_AP_CHANREP	16
3111 #define DOT11_RRM_CAP_RMMIB		17
3112 /* bit18-bit23, not used for RRM_IOVAR */
3113 #define DOT11_RRM_CAP_MPC0		24
3114 #define DOT11_RRM_CAP_MPC1		25
3115 #define DOT11_RRM_CAP_MPC2		26
3116 #define DOT11_RRM_CAP_MPTI		27
3117 #define DOT11_RRM_CAP_NBRTSFO		28
3118 #define DOT11_RRM_CAP_RCPI		29
3119 #define DOT11_RRM_CAP_RSNI		30
3120 #define DOT11_RRM_CAP_BSSAAD		31
3121 #define DOT11_RRM_CAP_BSSAAC		32
3122 #define DOT11_RRM_CAP_AI		33
3123 #define DOT11_RRM_CAP_FTM_RANGE		34
3124 #define DOT11_RRM_CAP_CIVIC_LOC		35
3125 #define DOT11_RRM_CAP_IDENT_LOC		36
3126 #define DOT11_RRM_CAP_LAST		36
3127 
3128 #ifdef WL11K_ALL_MEAS
3129 #define DOT11_RRM_CAP_LINK_ENAB			(1 << DOT11_RRM_CAP_LINK)
3130 #define DOT11_RRM_CAP_FM_ENAB			(1 << (DOT11_RRM_CAP_FM - 8))
3131 #define DOT11_RRM_CAP_CLM_ENAB			(1 << (DOT11_RRM_CAP_CLM - 8))
3132 #define DOT11_RRM_CAP_NHM_ENAB			(1 << (DOT11_RRM_CAP_NHM - 8))
3133 #define DOT11_RRM_CAP_SM_ENAB			(1 << (DOT11_RRM_CAP_SM - 8))
3134 #define DOT11_RRM_CAP_LCIM_ENAB			(1 << (DOT11_RRM_CAP_LCIM - 8))
3135 #define DOT11_RRM_CAP_TSCM_ENAB			(1 << (DOT11_RRM_CAP_TSCM - 8))
3136 #ifdef WL11K_AP
3137 #define DOT11_RRM_CAP_MPC0_ENAB			(1 << (DOT11_RRM_CAP_MPC0 - 24))
3138 #define DOT11_RRM_CAP_MPC1_ENAB			(1 << (DOT11_RRM_CAP_MPC1 - 24))
3139 #define DOT11_RRM_CAP_MPC2_ENAB			(1 << (DOT11_RRM_CAP_MPC2 - 24))
3140 #define DOT11_RRM_CAP_MPTI_ENAB			(1 << (DOT11_RRM_CAP_MPTI - 24))
3141 #else
3142 #define DOT11_RRM_CAP_MPC0_ENAB			0
3143 #define DOT11_RRM_CAP_MPC1_ENAB			0
3144 #define DOT11_RRM_CAP_MPC2_ENAB			0
3145 #define DOT11_RRM_CAP_MPTI_ENAB			0
3146 #endif /* WL11K_AP */
3147 #define DOT11_RRM_CAP_CIVIC_LOC_ENAB		(1 << (DOT11_RRM_CAP_CIVIC_LOC - 32))
3148 #define DOT11_RRM_CAP_IDENT_LOC_ENAB		(1 << (DOT11_RRM_CAP_IDENT_LOC - 32))
3149 #else
3150 #define DOT11_RRM_CAP_LINK_ENAB			0
3151 #define DOT11_RRM_CAP_FM_ENAB			0
3152 #define DOT11_RRM_CAP_CLM_ENAB			0
3153 #define DOT11_RRM_CAP_NHM_ENAB			0
3154 #define DOT11_RRM_CAP_SM_ENAB			0
3155 #define DOT11_RRM_CAP_LCIM_ENAB			0
3156 #define DOT11_RRM_CAP_TSCM_ENAB			0
3157 #define DOT11_RRM_CAP_MPC0_ENAB			0
3158 #define DOT11_RRM_CAP_MPC1_ENAB			0
3159 #define DOT11_RRM_CAP_MPC2_ENAB			0
3160 #define DOT11_RRM_CAP_MPTI_ENAB			0
3161 #define DOT11_RRM_CAP_CIVIC_LOC_ENAB		0
3162 #define DOT11_RRM_CAP_IDENT_LOC_ENAB		0
3163 #endif /* WL11K_ALL_MEAS */
3164 #ifdef WL11K_NBR_MEAS
3165 #define DOT11_RRM_CAP_NEIGHBOR_REPORT_ENAB	(1 << DOT11_RRM_CAP_NEIGHBOR_REPORT)
3166 #else
3167 #define DOT11_RRM_CAP_NEIGHBOR_REPORT_ENAB	0
3168 #endif /* WL11K_NBR_MEAS */
3169 #ifdef WL11K_BCN_MEAS
3170 #define DOT11_RRM_CAP_BCN_PASSIVE_ENAB		(1 << DOT11_RRM_CAP_BCN_PASSIVE)
3171 #define DOT11_RRM_CAP_BCN_ACTIVE_ENAB		(1 << DOT11_RRM_CAP_BCN_ACTIVE)
3172 #else
3173 #define DOT11_RRM_CAP_BCN_PASSIVE_ENAB		0
3174 #define DOT11_RRM_CAP_BCN_ACTIVE_ENAB		0
3175 #endif /* WL11K_BCN_MEAS */
3176 #define DOT11_RRM_CAP_MPA_MASK		0x7
3177 /* Operating Class (formerly "Regulatory Class") definitions */
3178 #define DOT11_OP_CLASS_NONE			255
3179 
3180 BWL_PRE_PACKED_STRUCT struct do11_ap_chrep {
3181 	uint8 id;
3182 	uint8 len;
3183 	uint8 reg;
3184 	uint8 chanlist[1];
3185 } BWL_POST_PACKED_STRUCT;
3186 typedef struct do11_ap_chrep dot11_ap_chrep_t;
3187 
3188 /* Radio Measurements action ids */
3189 #define DOT11_RM_ACTION_RM_REQ		0	/* Radio measurement request */
3190 #define DOT11_RM_ACTION_RM_REP		1	/* Radio measurement report */
3191 #define DOT11_RM_ACTION_LM_REQ		2	/* Link measurement request */
3192 #define DOT11_RM_ACTION_LM_REP		3	/* Link measurement report */
3193 #define DOT11_RM_ACTION_NR_REQ		4	/* Neighbor report request */
3194 #define DOT11_RM_ACTION_NR_REP		5	/* Neighbor report response */
3195 #define DOT11_PUB_ACTION_MP		7	/* Measurement Pilot public action id */
3196 
3197 /** Generic radio measurement action frame header */
3198 BWL_PRE_PACKED_STRUCT struct dot11_rm_action {
3199 	uint8 category;				/* category of action frame (5) */
3200 	uint8 action;				/* radio measurement action */
3201 	uint8 token;				/* dialog token */
3202 	uint8 data[1];
3203 } BWL_POST_PACKED_STRUCT;
3204 typedef struct dot11_rm_action dot11_rm_action_t;
3205 #define DOT11_RM_ACTION_LEN 3
3206 
3207 BWL_PRE_PACKED_STRUCT struct dot11_rmreq {
3208 	uint8 category;				/* category of action frame (5) */
3209 	uint8 action;				/* radio measurement action */
3210 	uint8 token;				/* dialog token */
3211 	uint16 reps;				/* no. of repetitions */
3212 	uint8 data[1];
3213 } BWL_POST_PACKED_STRUCT;
3214 typedef struct dot11_rmreq dot11_rmreq_t;
3215 #define DOT11_RMREQ_LEN	5
3216 
3217 BWL_PRE_PACKED_STRUCT struct dot11_rm_ie {
3218 	uint8 id;
3219 	uint8 len;
3220 	uint8 token;
3221 	uint8 mode;
3222 	uint8 type;
3223 } BWL_POST_PACKED_STRUCT;
3224 typedef struct dot11_rm_ie dot11_rm_ie_t;
3225 #define DOT11_RM_IE_LEN	5
3226 
3227 /* Definitions for "mode" bits in rm req */
3228 #define DOT11_RMREQ_MODE_PARALLEL	1
3229 #define DOT11_RMREQ_MODE_ENABLE		2
3230 #define DOT11_RMREQ_MODE_REQUEST	4
3231 #define DOT11_RMREQ_MODE_REPORT		8
3232 #define DOT11_RMREQ_MODE_DURMAND	0x10	/* Duration Mandatory */
3233 
3234 /* Definitions for "mode" bits in rm rep */
3235 #define DOT11_RMREP_MODE_LATE		1
3236 #define DOT11_RMREP_MODE_INCAPABLE	2
3237 #define DOT11_RMREP_MODE_REFUSED	4
3238 
3239 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_bcn {
3240 	uint8 id;		/* use dot11_rm_ie_t ? */
3241 	uint8 len;
3242 	uint8 token;
3243 	uint8 mode;
3244 	uint8 type;
3245 	uint8 reg;
3246 	uint8 channel;
3247 	uint16 interval;
3248 	uint16 duration;
3249 	uint8 bcn_mode;
3250 	struct ether_addr	bssid;
3251 } BWL_POST_PACKED_STRUCT;
3252 typedef struct dot11_rmreq_bcn dot11_rmreq_bcn_t;
3253 #define DOT11_RMREQ_BCN_LEN	18u
3254 
3255 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_bcn {
3256 	uint8 reg;
3257 	uint8 channel;
3258 	uint32 starttime[2];
3259 	uint16 duration;
3260 	uint8 frame_info;
3261 	uint8 rcpi;
3262 	uint8 rsni;
3263 	struct ether_addr	bssid;
3264 	uint8 antenna_id;
3265 	uint32 parent_tsf;
3266 } BWL_POST_PACKED_STRUCT;
3267 typedef struct dot11_rmrep_bcn dot11_rmrep_bcn_t;
3268 #define DOT11_RMREP_BCN_LEN	26
3269 
3270 /* Beacon request measurement mode */
3271 #define DOT11_RMREQ_BCN_PASSIVE	0
3272 #define DOT11_RMREQ_BCN_ACTIVE	1
3273 #define DOT11_RMREQ_BCN_TABLE	2
3274 
3275 /* Sub-element IDs for Beacon Request */
3276 #define DOT11_RMREQ_BCN_SSID_ID 0
3277 #define DOT11_RMREQ_BCN_REPINFO_ID  1
3278 #define DOT11_RMREQ_BCN_REPDET_ID   2
3279 #define DOT11_RMREQ_BCN_REQUEST_ID  10
3280 #define DOT11_RMREQ_BCN_APCHREP_ID  DOT11_MNG_AP_CHREP_ID
3281 #define DOT11_RMREQ_BCN_LAST_RPT_IND_REQ_ID 164
3282 
3283 /* Reporting Detail element definition */
3284 #define DOT11_RMREQ_BCN_REPDET_FIXED	0	/* Fixed length fields only */
3285 #define DOT11_RMREQ_BCN_REPDET_REQUEST	1	/* + requested information elems */
3286 #define DOT11_RMREQ_BCN_REPDET_ALL	2	/* All fields */
3287 
3288 /* Reporting Information (reporting condition) element definition */
3289 #define DOT11_RMREQ_BCN_REPINFO_LEN	2	/* Beacon Reporting Information length */
3290 #define DOT11_RMREQ_BCN_REPCOND_DEFAULT	0	/* Report to be issued after each measurement */
3291 
3292 /* Last Beacon Report Indication Request definition */
3293 #define DOT11_RMREQ_BCN_LAST_RPT_IND_REQ_ENAB  1
3294 
3295 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_last_bcn_rpt_ind_req {
3296 	uint8 id;                       /* DOT11_RMREQ_BCN_LAST_RPT_IND_REQ_ID */
3297 	uint8 len;                      /* length of remaining fields */
3298 	uint8 data;                     /* data = 1 means last bcn rpt ind requested */
3299 } BWL_POST_PACKED_STRUCT;
3300 typedef struct dot11_rmrep_last_bcn_rpt_ind_req dot11_rmrep_last_bcn_rpt_ind_req_t;
3301 
3302 /* Sub-element IDs for Beacon Report */
3303 #define DOT11_RMREP_BCN_FRM_BODY	1
3304 #define DOT11_RMREP_BCN_FRM_BODY_FRAG_ID	2
3305 #define DOT11_RMREP_BCN_LAST_RPT_IND 164
3306 #define DOT11_RMREP_BCN_FRM_BODY_LEN_MAX	224 /* 802.11k-2008 7.3.2.22.6 */
3307 
3308 /* Refer IEEE P802.11-REVmd/D1.0 9.4.2.21.7 Beacon report */
3309 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_bcn_frm_body_fragmt_id {
3310 	uint8 id;                       /* DOT11_RMREP_BCN_FRM_BODY_FRAG_ID */
3311 	uint8 len;                      /* length of remaining fields */
3312 	/* More fragments(B15), fragment Id(B8-B14), Bcn rpt instance ID (B0 - B7) */
3313 	uint16 frag_info_rpt_id;
3314 } BWL_POST_PACKED_STRUCT;
3315 
3316 typedef struct dot11_rmrep_bcn_frm_body_fragmt_id dot11_rmrep_bcn_frm_body_fragmt_id_t;
3317 
3318 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_bcn_frm_body_frag_id {
3319 	uint8 id;                       /* DOT11_RMREP_BCN_FRM_BODY_FRAG_ID */
3320 	uint8 len;                      /* length of remaining fields */
3321 	uint8 bcn_rpt_id;               /* Bcn rpt instance ID */
3322 	uint8 frag_info;                /* fragment Id(7 bits) | More fragments(1 bit) */
3323 } BWL_POST_PACKED_STRUCT;
3324 
3325 typedef struct dot11_rmrep_bcn_frm_body_frag_id dot11_rmrep_bcn_frm_body_frag_id_t;
3326 #define DOT11_RMREP_BCNRPT_FRAG_ID_DATA_LEN  2u
3327 #define DOT11_RMREP_BCNRPT_FRAG_ID_SE_LEN sizeof(dot11_rmrep_bcn_frm_body_frag_id_t)
3328 #define DOT11_RMREP_BCNRPT_FRAG_ID_NUM_SHIFT  1u
3329 #define DOT11_RMREP_BCNRPT_FRAGMT_ID_SE_LEN sizeof(dot11_rmrep_bcn_frm_body_fragmt_id_t)
3330 #define DOT11_RMREP_BCNRPT_BCN_RPT_ID_MASK  0x00FFu
3331 #define DOT11_RMREP_BCNRPT_FRAGMT_ID_NUM_SHIFT  8u
3332 #define DOT11_RMREP_BCNRPT_FRAGMT_ID_NUM_MASK  0x7F00u
3333 #define DOT11_RMREP_BCNRPT_MORE_FRAG_SHIFT  15u
3334 #define DOT11_RMREP_BCNRPT_MORE_FRAG_MASK  0x8000u
3335 
3336 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_last_bcn_rpt_ind {
3337 	uint8 id;                       /* DOT11_RMREP_BCN_LAST_RPT_IND */
3338 	uint8 len;                      /* length of remaining fields */
3339 	uint8 data;                     /* data = 1 is last bcn rpt */
3340 } BWL_POST_PACKED_STRUCT;
3341 
3342 typedef struct dot11_rmrep_last_bcn_rpt_ind dot11_rmrep_last_bcn_rpt_ind_t;
3343 #define DOT11_RMREP_LAST_BCN_RPT_IND_DATA_LEN 1
3344 #define DOT11_RMREP_LAST_BCN_RPT_IND_SE_LEN sizeof(dot11_rmrep_last_bcn_rpt_ind_t)
3345 
3346 /* Sub-element IDs for Frame Report */
3347 #define DOT11_RMREP_FRAME_COUNT_REPORT 1
3348 
3349 /* Channel load request */
3350 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_chanload {
3351 	uint8 id;		/* use dot11_rm_ie_t ? */
3352 	uint8 len;
3353 	uint8 token;
3354 	uint8 mode;
3355 	uint8 type;
3356 	uint8 reg;
3357 	uint8 channel;
3358 	uint16 interval;
3359 	uint16 duration;
3360 } BWL_POST_PACKED_STRUCT;
3361 typedef struct dot11_rmreq_chanload dot11_rmreq_chanload_t;
3362 #define DOT11_RMREQ_CHANLOAD_LEN	11
3363 
3364 /** Channel load report */
3365 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_chanload {
3366 	uint8 reg;
3367 	uint8 channel;
3368 	uint32 starttime[2];
3369 	uint16 duration;
3370 	uint8 channel_load;
3371 } BWL_POST_PACKED_STRUCT;
3372 typedef struct dot11_rmrep_chanload dot11_rmrep_chanload_t;
3373 #define DOT11_RMREP_CHANLOAD_LEN	13
3374 
3375 /** Noise histogram request */
3376 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_noise {
3377 	uint8 id;		/* use dot11_rm_ie_t ? */
3378 	uint8 len;
3379 	uint8 token;
3380 	uint8 mode;
3381 	uint8 type;
3382 	uint8 reg;
3383 	uint8 channel;
3384 	uint16 interval;
3385 	uint16 duration;
3386 } BWL_POST_PACKED_STRUCT;
3387 typedef struct dot11_rmreq_noise dot11_rmreq_noise_t;
3388 #define DOT11_RMREQ_NOISE_LEN 11
3389 
3390 /** Noise histogram report */
3391 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_noise {
3392 	uint8 reg;
3393 	uint8 channel;
3394 	uint32 starttime[2];
3395 	uint16 duration;
3396 	uint8 antid;
3397 	uint8 anpi;
3398 	uint8 ipi0_dens;
3399 	uint8 ipi1_dens;
3400 	uint8 ipi2_dens;
3401 	uint8 ipi3_dens;
3402 	uint8 ipi4_dens;
3403 	uint8 ipi5_dens;
3404 	uint8 ipi6_dens;
3405 	uint8 ipi7_dens;
3406 	uint8 ipi8_dens;
3407 	uint8 ipi9_dens;
3408 	uint8 ipi10_dens;
3409 } BWL_POST_PACKED_STRUCT;
3410 typedef struct dot11_rmrep_noise dot11_rmrep_noise_t;
3411 #define DOT11_RMREP_NOISE_LEN 25
3412 
3413 /** Frame request */
3414 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_frame {
3415 	uint8 id;		/* use dot11_rm_ie_t ? */
3416 	uint8 len;
3417 	uint8 token;
3418 	uint8 mode;
3419 	uint8 type;
3420 	uint8 reg;
3421 	uint8 channel;
3422 	uint16 interval;
3423 	uint16 duration;
3424 	uint8 req_type;
3425 	struct ether_addr	ta;
3426 } BWL_POST_PACKED_STRUCT;
3427 typedef struct dot11_rmreq_frame dot11_rmreq_frame_t;
3428 #define DOT11_RMREQ_FRAME_LEN 18
3429 
3430 /** Frame report */
3431 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_frame {
3432 	uint8 reg;
3433 	uint8 channel;
3434 	uint32 starttime[2];
3435 	uint16 duration;
3436 } BWL_POST_PACKED_STRUCT;
3437 typedef struct dot11_rmrep_frame dot11_rmrep_frame_t;
3438 #define DOT11_RMREP_FRAME_LEN 12
3439 
3440 /** Frame report entry */
3441 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_frmentry {
3442 	struct ether_addr	ta;
3443 	struct ether_addr	bssid;
3444 	uint8 phy_type;
3445 	uint8 avg_rcpi;
3446 	uint8 last_rsni;
3447 	uint8 last_rcpi;
3448 	uint8 ant_id;
3449 	uint16 frame_cnt;
3450 } BWL_POST_PACKED_STRUCT;
3451 typedef struct dot11_rmrep_frmentry dot11_rmrep_frmentry_t;
3452 #define DOT11_RMREP_FRMENTRY_LEN 19
3453 
3454 /** STA statistics request */
3455 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_stat {
3456 	uint8 id;		/* use dot11_rm_ie_t ? */
3457 	uint8 len;
3458 	uint8 token;
3459 	uint8 mode;
3460 	uint8 type;
3461 	struct ether_addr	peer;
3462 	uint16 interval;
3463 	uint16 duration;
3464 	uint8 group_id;
3465 } BWL_POST_PACKED_STRUCT;
3466 typedef struct dot11_rmreq_stat dot11_rmreq_stat_t;
3467 #define DOT11_RMREQ_STAT_LEN 16
3468 
3469 /** STA statistics report */
3470 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_stat {
3471 	uint16 duration;
3472 	uint8 group_id;
3473 } BWL_POST_PACKED_STRUCT;
3474 typedef struct dot11_rmrep_stat dot11_rmrep_stat_t;
3475 
3476 /* Statistics Group Report: Group IDs */
3477 enum {
3478 	DOT11_RRM_STATS_GRP_ID_0 = 0,
3479 	DOT11_RRM_STATS_GRP_ID_1,
3480 	DOT11_RRM_STATS_GRP_ID_2,
3481 	DOT11_RRM_STATS_GRP_ID_3,
3482 	DOT11_RRM_STATS_GRP_ID_4,
3483 	DOT11_RRM_STATS_GRP_ID_5,
3484 	DOT11_RRM_STATS_GRP_ID_6,
3485 	DOT11_RRM_STATS_GRP_ID_7,
3486 	DOT11_RRM_STATS_GRP_ID_8,
3487 	DOT11_RRM_STATS_GRP_ID_9,
3488 	DOT11_RRM_STATS_GRP_ID_10,
3489 	DOT11_RRM_STATS_GRP_ID_11,
3490 	DOT11_RRM_STATS_GRP_ID_12,
3491 	DOT11_RRM_STATS_GRP_ID_13,
3492 	DOT11_RRM_STATS_GRP_ID_14,
3493 	DOT11_RRM_STATS_GRP_ID_15,
3494 	DOT11_RRM_STATS_GRP_ID_16
3495 };
3496 
3497 /* Statistics Group Report: Group Data length  */
3498 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_0	28
3499 typedef struct rrm_stat_group_0 {
3500 	uint32	txfrag;
3501 	uint32	txmulti;
3502 	uint32	txfail;
3503 	uint32	rxframe;
3504 	uint32	rxmulti;
3505 	uint32	rxbadfcs;
3506 	uint32	txframe;
3507 } rrm_stat_group_0_t;
3508 
3509 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_1	24
3510 typedef struct rrm_stat_group_1 {
3511 	uint32	txretry;
3512 	uint32	txretries;
3513 	uint32	rxdup;
3514 	uint32	txrts;
3515 	uint32	rtsfail;
3516 	uint32	ackfail;
3517 } rrm_stat_group_1_t;
3518 
3519 /* group 2-9 use same qos data structure (tid 0-7), total 52 bytes */
3520 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_2_9	52
3521 typedef struct rrm_stat_group_qos {
3522 	uint32	txfrag;
3523 	uint32	txfail;
3524 	uint32	txretry;
3525 	uint32	txretries;
3526 	uint32	rxdup;
3527 	uint32	txrts;
3528 	uint32	rtsfail;
3529 	uint32	ackfail;
3530 	uint32	rxfrag;
3531 	uint32	txframe;
3532 	uint32	txdrop;
3533 	uint32	rxmpdu;
3534 	uint32	rxretries;
3535 } rrm_stat_group_qos_t;
3536 
3537 /* dot11BSSAverageAccessDelay Group (only available at an AP): 8 byte */
3538 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_10	8
3539 typedef BWL_PRE_PACKED_STRUCT struct rrm_stat_group_10 {
3540 	uint8	apavgdelay;
3541 	uint8	avgdelaybe;
3542 	uint8	avgdelaybg;
3543 	uint8	avgdelayvi;
3544 	uint8	avgdelayvo;
3545 	uint16	stacount;
3546 	uint8	chanutil;
3547 } BWL_POST_PACKED_STRUCT rrm_stat_group_10_t;
3548 
3549 /* AMSDU, 40 bytes */
3550 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_11	40
3551 typedef struct rrm_stat_group_11 {
3552 	uint32	txamsdu;
3553 	uint32	amsdufail;
3554 	uint32	amsduretry;
3555 	uint32	amsduretries;
3556 	uint32	txamsdubyte_h;
3557 	uint32	txamsdubyte_l;
3558 	uint32	amsduackfail;
3559 	uint32	rxamsdu;
3560 	uint32	rxamsdubyte_h;
3561 	uint32	rxamsdubyte_l;
3562 } rrm_stat_group_11_t;
3563 
3564 /* AMPDU, 36 bytes */
3565 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_12	36
3566 typedef struct rrm_stat_group_12 {
3567 	uint32	txampdu;
3568 	uint32	txmpdu;
3569 	uint32	txampdubyte_h;
3570 	uint32	txampdubyte_l;
3571 	uint32	rxampdu;
3572 	uint32	rxmpdu;
3573 	uint32	rxampdubyte_h;
3574 	uint32	rxampdubyte_l;
3575 	uint32	ampducrcfail;
3576 } rrm_stat_group_12_t;
3577 
3578 /* BACK etc, 36 bytes */
3579 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_13	36
3580 typedef struct rrm_stat_group_13 {
3581 	uint32	rximpbarfail;
3582 	uint32	rxexpbarfail;
3583 	uint32	chanwidthsw;
3584 	uint32	txframe20mhz;
3585 	uint32	txframe40mhz;
3586 	uint32	rxframe20mhz;
3587 	uint32	rxframe40mhz;
3588 	uint32	psmpgrantdur;
3589 	uint32	psmpuseddur;
3590 } rrm_stat_group_13_t;
3591 
3592 /* RD Dual CTS etc, 36 bytes */
3593 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_14	36
3594 typedef struct rrm_stat_group_14 {
3595 	uint32	grantrdgused;
3596 	uint32	grantrdgunused;
3597 	uint32	txframeingrantrdg;
3598 	uint32	txbyteingrantrdg_h;
3599 	uint32	txbyteingrantrdg_l;
3600 	uint32	dualcts;
3601 	uint32	dualctsfail;
3602 	uint32	rtslsi;
3603 	uint32	rtslsifail;
3604 } rrm_stat_group_14_t;
3605 
3606 /* bf and STBC etc, 20 bytes */
3607 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_15	20
3608 typedef struct rrm_stat_group_15 {
3609 	uint32	bfframe;
3610 	uint32	stbccts;
3611 	uint32	stbcctsfail;
3612 	uint32	nonstbccts;
3613 	uint32	nonstbcctsfail;
3614 } rrm_stat_group_15_t;
3615 
3616 /* RSNA, 28 bytes */
3617 #define DOT11_RRM_STATS_RPT_LEN_GRP_ID_16	28
3618 typedef struct rrm_stat_group_16 {
3619 	uint32	rsnacmacicverr;
3620 	uint32	rsnacmacreplay;
3621 	uint32	rsnarobustmgmtccmpreplay;
3622 	uint32	rsnatkipicverr;
3623 	uint32	rsnatkipicvreplay;
3624 	uint32	rsnaccmpdecrypterr;
3625 	uint32	rsnaccmpreplay;
3626 } rrm_stat_group_16_t;
3627 
3628 /* Transmit stream/category measurement request */
3629 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_tx_stream {
3630 	uint8 id;		/* use dot11_rm_ie_t ? */
3631 	uint8 len;
3632 	uint8 token;
3633 	uint8 mode;
3634 	uint8 type;
3635 	uint16 interval;
3636 	uint16 duration;
3637 	struct ether_addr	peer;
3638 	uint8 traffic_id;
3639 	uint8 bin0_range;
3640 } BWL_POST_PACKED_STRUCT;
3641 typedef struct dot11_rmreq_tx_stream dot11_rmreq_tx_stream_t;
3642 #define DOT11_RMREQ_TXSTREAM_LEN	17
3643 
3644 /** Transmit stream/category measurement report */
3645 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_tx_stream {
3646 	uint32 starttime[2];
3647 	uint16 duration;
3648 	struct ether_addr	peer;
3649 	uint8 traffic_id;
3650 	uint8 reason;
3651 	uint32 txmsdu_cnt;
3652 	uint32 msdu_discarded_cnt;
3653 	uint32 msdufailed_cnt;
3654 	uint32 msduretry_cnt;
3655 	uint32 cfpolls_lost_cnt;
3656 	uint32 avrqueue_delay;
3657 	uint32 avrtx_delay;
3658 	uint8 bin0_range;
3659 	uint32 bin0;
3660 	uint32 bin1;
3661 	uint32 bin2;
3662 	uint32 bin3;
3663 	uint32 bin4;
3664 	uint32 bin5;
3665 } BWL_POST_PACKED_STRUCT;
3666 typedef struct dot11_rmrep_tx_stream dot11_rmrep_tx_stream_t;
3667 #define DOT11_RMREP_TXSTREAM_LEN	71
3668 
3669 typedef struct rrm_tscm {
3670 	uint32 msdu_tx;
3671 	uint32 msdu_exp;
3672 	uint32 msdu_fail;
3673 	uint32 msdu_retries;
3674 	uint32 cfpolls_lost;
3675 	uint32 queue_delay;
3676 	uint32 tx_delay_sum;
3677 	uint32 tx_delay_cnt;
3678 	uint32 bin0_range_us;
3679 	uint32 bin0;
3680 	uint32 bin1;
3681 	uint32 bin2;
3682 	uint32 bin3;
3683 	uint32 bin4;
3684 	uint32 bin5;
3685 } rrm_tscm_t;
3686 enum {
3687 	DOT11_FTM_LOCATION_SUBJ_LOCAL = 0,		/* Where am I? */
3688 	DOT11_FTM_LOCATION_SUBJ_REMOTE = 1,		/* Where are you? */
3689 	DOT11_FTM_LOCATION_SUBJ_THIRDPARTY = 2   /* Where is he/she? */
3690 };
3691 
3692 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_ftm_lci {
3693 	uint8 id;
3694 	uint8 len;
3695 	uint8 token;
3696 	uint8 mode;
3697 	uint8 type;
3698 	uint8 subj;
3699 
3700 	/* Following 3 fields are unused. Keep for ROM compatibility. */
3701 	uint8 lat_res;
3702 	uint8 lon_res;
3703 	uint8 alt_res;
3704 
3705 	/* optional sub-elements */
3706 } BWL_POST_PACKED_STRUCT;
3707 typedef struct dot11_rmreq_ftm_lci dot11_rmreq_ftm_lci_t;
3708 #define DOT11_RMREQ_LCI_LEN	9
3709 
3710 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_ftm_lci {
3711 	uint8 id;
3712 	uint8 len;
3713 	uint8 token;
3714 	uint8 mode;
3715 	uint8 type;
3716 	uint8 lci_sub_id;
3717 	uint8 lci_sub_len;
3718 	/* optional LCI field */
3719 	/* optional sub-elements */
3720 } BWL_POST_PACKED_STRUCT;
3721 typedef struct dot11_rmrep_ftm_lci dot11_rmrep_ftm_lci_t;
3722 
3723 #define DOT11_FTM_LCI_SUBELEM_ID		0
3724 #define DOT11_FTM_LCI_SUBELEM_LEN		2
3725 #define DOT11_FTM_LCI_FIELD_LEN			16
3726 #define DOT11_FTM_LCI_UNKNOWN_LEN		2
3727 
3728 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_ftm_civic {
3729 	uint8 id;
3730 	uint8 len;
3731 	uint8 token;
3732 	uint8 mode;
3733 	uint8 type;
3734 	uint8 subj;
3735 	uint8 civloc_type;
3736 	uint8 siu;	/* service interval units */
3737 	uint16 si;  /* service interval */
3738 	/* optional sub-elements */
3739 } BWL_POST_PACKED_STRUCT;
3740 typedef struct dot11_rmreq_ftm_civic dot11_rmreq_ftm_civic_t;
3741 #define DOT11_RMREQ_CIVIC_LEN	10
3742 
3743 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_ftm_civic {
3744 	uint8 id;
3745 	uint8 len;
3746 	uint8 token;
3747 	uint8 mode;
3748 	uint8 type;
3749 	uint8 civloc_type;
3750 	uint8 civloc_sub_id;
3751 	uint8 civloc_sub_len;
3752 	/* optional location civic field */
3753 	/* optional sub-elements */
3754 } BWL_POST_PACKED_STRUCT;
3755 typedef struct dot11_rmrep_ftm_civic dot11_rmrep_ftm_civic_t;
3756 
3757 #define DOT11_FTM_CIVIC_LOC_TYPE_RFC4776	0
3758 #define DOT11_FTM_CIVIC_SUBELEM_ID		0
3759 #define DOT11_FTM_CIVIC_SUBELEM_LEN		2
3760 #define DOT11_FTM_CIVIC_LOC_SI_NONE		0
3761 #define DOT11_FTM_CIVIC_TYPE_LEN		1
3762 #define DOT11_FTM_CIVIC_UNKNOWN_LEN		3
3763 
3764 /* Location Identifier measurement request */
3765 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_locid {
3766 	uint8 id;
3767 	uint8 len;
3768 	uint8 token;
3769 	uint8 mode;
3770 	uint8 type;
3771 	uint8 subj;
3772 	uint8 siu;
3773 	uint16 si;
3774 } BWL_POST_PACKED_STRUCT;
3775 typedef struct dot11_rmreq_locid dot11_rmreq_locid_t;
3776 #define DOT11_RMREQ_LOCID_LEN	9
3777 
3778 /* Location Identifier measurement report */
3779 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_locid {
3780 	uint8 id;
3781 	uint8 len;
3782 	uint8 token;
3783 	uint8 mode;
3784 	uint8 type;
3785 	uint8 exp_tsf[8];
3786 	uint8 locid_sub_id;
3787 	uint8 locid_sub_len;
3788 	/* optional location identifier field */
3789 	/* optional sub-elements */
3790 } BWL_POST_PACKED_STRUCT;
3791 typedef struct dot11_rmrep_locid dot11_rmrep_locid_t;
3792 #define DOT11_LOCID_UNKNOWN_LEN		10
3793 #define DOT11_LOCID_SUBELEM_ID		0
3794 
3795 BWL_PRE_PACKED_STRUCT struct dot11_ftm_range_subel {
3796 	uint8 id;
3797 	uint8 len;
3798 	uint16 max_age;
3799 } BWL_POST_PACKED_STRUCT;
3800 typedef struct dot11_ftm_range_subel dot11_ftm_range_subel_t;
3801 #define DOT11_FTM_RANGE_SUBELEM_ID      4
3802 #define DOT11_FTM_RANGE_SUBELEM_LEN     2
3803 
3804 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_ftm_range {
3805 	uint8 id;
3806 	uint8 len;
3807 	uint8 token;
3808 	uint8 mode;
3809 	uint8 type;
3810 	uint16 max_init_delay;		/* maximum random initial delay */
3811 	uint8 min_ap_count;
3812 	uint8 data[1];
3813 	/* neighbor report sub-elements */
3814 	/* optional sub-elements */
3815 } BWL_POST_PACKED_STRUCT;
3816 typedef struct dot11_rmreq_ftm_range dot11_rmreq_ftm_range_t;
3817 #define DOT11_RMREQ_FTM_RANGE_LEN 8
3818 
3819 #define DOT11_FTM_RANGE_LEN		3
3820 BWL_PRE_PACKED_STRUCT struct dot11_ftm_range_entry {
3821 	uint32 start_tsf;		/* 4 lsb of tsf */
3822 	struct ether_addr bssid;
3823 	uint8 range[DOT11_FTM_RANGE_LEN];
3824 	uint8 max_err[DOT11_FTM_RANGE_LEN];
3825 	uint8  rsvd;
3826 } BWL_POST_PACKED_STRUCT;
3827 typedef struct dot11_ftm_range_entry dot11_ftm_range_entry_t;
3828 #define DOT11_FTM_RANGE_ENTRY_MAX_COUNT   15
3829 
3830 enum {
3831 	DOT11_FTM_RANGE_ERROR_AP_INCAPABLE = 2,
3832 	DOT11_FTM_RANGE_ERROR_AP_FAILED = 3,
3833 	DOT11_FTM_RANGE_ERROR_TX_FAILED = 8,
3834 	DOT11_FTM_RANGE_ERROR_MAX
3835 };
3836 
3837 BWL_PRE_PACKED_STRUCT struct dot11_ftm_range_error_entry {
3838 	uint32 start_tsf;		/* 4 lsb of tsf */
3839 	struct ether_addr bssid;
3840 	uint8  code;
3841 } BWL_POST_PACKED_STRUCT;
3842 typedef struct dot11_ftm_range_error_entry dot11_ftm_range_error_entry_t;
3843 #define DOT11_FTM_RANGE_ERROR_ENTRY_MAX_COUNT   11
3844 
3845 BWL_PRE_PACKED_STRUCT struct dot11_rmrep_ftm_range {
3846     uint8 id;
3847     uint8 len;
3848     uint8 token;
3849     uint8 mode;
3850     uint8 type;
3851     uint8 entry_count;
3852     uint8 data[2]; /* includes pad */
3853 	/*
3854 	dot11_ftm_range_entry_t entries[entry_count];
3855 	uint8 error_count;
3856 	dot11_ftm_error_entry_t errors[error_count];
3857 	 */
3858 } BWL_POST_PACKED_STRUCT;
3859 typedef struct dot11_rmrep_ftm_range dot11_rmrep_ftm_range_t;
3860 
3861 #define DOT11_FTM_RANGE_REP_MIN_LEN     6       /* No extra byte for error_count */
3862 #define DOT11_FTM_RANGE_ENTRY_CNT_MAX   15
3863 #define DOT11_FTM_RANGE_ERROR_CNT_MAX   11
3864 #define DOT11_FTM_RANGE_REP_FIXED_LEN   1       /* No extra byte for error_count */
3865 /** Measurement pause request */
3866 BWL_PRE_PACKED_STRUCT struct dot11_rmreq_pause_time {
3867 	uint8 id;		/* use dot11_rm_ie_t ? */
3868 	uint8 len;
3869 	uint8 token;
3870 	uint8 mode;
3871 	uint8 type;
3872 	uint16 pause_time;
3873 } BWL_POST_PACKED_STRUCT;
3874 typedef struct dot11_rmreq_pause_time dot11_rmreq_pause_time_t;
3875 #define DOT11_RMREQ_PAUSE_LEN	7
3876 
3877 /* Neighbor Report subelements ID (11k & 11v) */
3878 #define DOT11_NGBR_TSF_INFO_SE_ID	1
3879 #define DOT11_NGBR_CCS_SE_ID		2
3880 #define DOT11_NGBR_BSSTRANS_PREF_SE_ID	3
3881 #define DOT11_NGBR_BSS_TERM_DUR_SE_ID	4
3882 #define DOT11_NGBR_BEARING_SE_ID	5
3883 #define DOT11_NGBR_WIDE_BW_CHAN_SE_ID	6 /* proposed */
3884 
3885 /** Neighbor Report, BSS Transition Candidate Preference subelement */
3886 BWL_PRE_PACKED_STRUCT struct dot11_ngbr_bsstrans_pref_se {
3887 	uint8 sub_id;
3888 	uint8 len;
3889 	uint8 preference;
3890 } BWL_POST_PACKED_STRUCT;
3891 typedef struct dot11_ngbr_bsstrans_pref_se dot11_ngbr_bsstrans_pref_se_t;
3892 #define DOT11_NGBR_BSSTRANS_PREF_SE_LEN		1
3893 #define DOT11_NGBR_BSSTRANS_PREF_SE_IE_LEN	3
3894 #define DOT11_NGBR_BSSTRANS_PREF_SE_HIGHEST	0xff
3895 
3896 /** Neighbor Report, BSS Termination Duration subelement */
3897 BWL_PRE_PACKED_STRUCT struct dot11_ngbr_bss_term_dur_se {
3898 	uint8 sub_id;
3899 	uint8 len;
3900 	uint8 tsf[8];
3901 	uint16 duration;
3902 } BWL_POST_PACKED_STRUCT;
3903 typedef struct dot11_ngbr_bss_term_dur_se dot11_ngbr_bss_term_dur_se_t;
3904 #define DOT11_NGBR_BSS_TERM_DUR_SE_LEN	10
3905 
3906 /* Neighbor Report BSSID Information Field */
3907 #define DOT11_NGBR_BI_REACHABILTY_UNKN	0x0002
3908 #define DOT11_NGBR_BI_REACHABILTY	0x0003
3909 #define DOT11_NGBR_BI_SEC		0x0004
3910 #define DOT11_NGBR_BI_KEY_SCOPE		0x0008
3911 #define DOT11_NGBR_BI_CAP		0x03f0
3912 #define DOT11_NGBR_BI_CAP_SPEC_MGMT	0x0010
3913 #define DOT11_NGBR_BI_CAP_QOS		0x0020
3914 #define DOT11_NGBR_BI_CAP_APSD		0x0040
3915 #define DOT11_NGBR_BI_CAP_RDIO_MSMT	0x0080
3916 #define DOT11_NGBR_BI_CAP_DEL_BA	0x0100
3917 #define DOT11_NGBR_BI_CAP_IMM_BA	0x0200
3918 #define DOT11_NGBR_BI_MOBILITY		0x0400
3919 #define DOT11_NGBR_BI_HT		0x0800
3920 #define DOT11_NGBR_BI_VHT		0x1000
3921 #define DOT11_NGBR_BI_FTM		0x2000
3922 
3923 /** Neighbor Report element (11k & 11v) */
3924 BWL_PRE_PACKED_STRUCT struct dot11_neighbor_rep_ie {
3925 	uint8 id;
3926 	uint8 len;
3927 	struct ether_addr bssid;
3928 	uint32 bssid_info;
3929 	uint8 reg;		/* Operating class */
3930 	uint8 channel;
3931 	uint8 phytype;
3932 	uint8 data[1];		/* Variable size subelements */
3933 } BWL_POST_PACKED_STRUCT;
3934 typedef struct dot11_neighbor_rep_ie dot11_neighbor_rep_ie_t;
3935 #define DOT11_NEIGHBOR_REP_IE_FIXED_LEN	13u
3936 
3937 /* MLME Enumerations */
3938 #define DOT11_BSSTYPE_INFRASTRUCTURE		0	/* d11 infrastructure */
3939 #define DOT11_BSSTYPE_INDEPENDENT		1	/* d11 independent */
3940 #define DOT11_BSSTYPE_ANY			2	/* d11 any BSS type */
3941 #define DOT11_BSSTYPE_MESH			3	/* d11 Mesh */
3942 #define DOT11_SCANTYPE_ACTIVE			0	/* d11 scan active */
3943 #define DOT11_SCANTYPE_PASSIVE			1	/* d11 scan passive */
3944 
3945 /** Link Measurement */
3946 BWL_PRE_PACKED_STRUCT struct dot11_lmreq {
3947 	uint8 category;				/* category of action frame (5) */
3948 	uint8 action;				/* radio measurement action */
3949 	uint8 token;				/* dialog token */
3950 	uint8 txpwr;				/* Transmit Power Used */
3951 	uint8 maxtxpwr;				/* Max Transmit Power */
3952 } BWL_POST_PACKED_STRUCT;
3953 typedef struct dot11_lmreq dot11_lmreq_t;
3954 #define DOT11_LMREQ_LEN	5
3955 
3956 BWL_PRE_PACKED_STRUCT struct dot11_lmrep {
3957 	uint8 category;				/* category of action frame (5) */
3958 	uint8 action;				/* radio measurement action */
3959 	uint8 token;				/* dialog token */
3960 	dot11_tpc_rep_t tpc;			/* TPC element */
3961 	uint8 rxant;				/* Receive Antenna ID */
3962 	uint8 txant;				/* Transmit Antenna ID */
3963 	uint8 rcpi;				/* RCPI */
3964 	uint8 rsni;				/* RSNI */
3965 } BWL_POST_PACKED_STRUCT;
3966 typedef struct dot11_lmrep dot11_lmrep_t;
3967 #define DOT11_LMREP_LEN	11
3968 
3969 #define DOT11_MP_CAP_SPECTRUM			0x01	/* d11 cap. spectrum */
3970 #define DOT11_MP_CAP_SHORTSLOT			0x02	/* d11 cap. shortslot */
3971 /* Measurement Pilot */
3972 BWL_PRE_PACKED_STRUCT struct dot11_mprep {
3973 	uint8 cap_info;				/* Condensed capability Info. */
3974 	uint8 country[2];				/* Condensed country string */
3975 	uint8 opclass;				/* Op. Class */
3976 	uint8 channel;				/* Channel */
3977 	uint8 mp_interval;			/* Measurement Pilot Interval */
3978 } BWL_POST_PACKED_STRUCT;
3979 typedef struct dot11_mprep dot11_mprep_t;
3980 #define DOT11_MPREP_LEN	6
3981 
3982 /* 802.11 BRCM "Compromise" Pre N constants */
3983 #define PREN_PREAMBLE		24	/* green field preamble time */
3984 #define PREN_MM_EXT		12	/* extra mixed mode preamble time */
3985 #define PREN_PREAMBLE_EXT	4	/* extra preamble (multiply by unique_streams-1) */
3986 
3987 /* 802.11N PHY constants */
3988 #define RIFS_11N_TIME		2	/* NPHY RIFS time */
3989 
3990 /* 802.11 HT PLCP format 802.11n-2009, sec 20.3.9.4.3
3991  * HT-SIG is composed of two 24 bit parts, HT-SIG1 and HT-SIG2
3992  */
3993 /* HT-SIG1 */
3994 #define HT_SIG1_MCS_MASK        0x00007F
3995 #define HT_SIG1_CBW             0x000080
3996 #define HT_SIG1_HT_LENGTH       0xFFFF00
3997 
3998 /* HT-SIG2 */
3999 #define HT_SIG2_SMOOTHING       0x000001
4000 #define HT_SIG2_NOT_SOUNDING    0x000002
4001 #define HT_SIG2_RESERVED        0x000004
4002 #define HT_SIG2_AGGREGATION     0x000008
4003 #define HT_SIG2_STBC_MASK       0x000030
4004 #define HT_SIG2_STBC_SHIFT      4
4005 #define HT_SIG2_FEC_CODING      0x000040
4006 #define HT_SIG2_SHORT_GI        0x000080
4007 #define HT_SIG2_ESS_MASK        0x000300
4008 #define HT_SIG2_ESS_SHIFT       8
4009 #define HT_SIG2_CRC             0x03FC00
4010 #define HT_SIG2_TAIL            0x1C0000
4011 
4012 /* HT Timing-related parameters (802.11-2012, sec 20.3.6) */
4013 #define HT_T_LEG_PREAMBLE      16
4014 #define HT_T_L_SIG              4
4015 #define HT_T_SIG                8
4016 #define HT_T_LTF1               4
4017 #define HT_T_GF_LTF1            8
4018 #define HT_T_LTFs               4
4019 #define HT_T_STF                4
4020 #define HT_T_GF_STF             8
4021 #define HT_T_SYML               4
4022 
4023 #define HT_N_SERVICE           16       /* bits in SERVICE field */
4024 #define HT_N_TAIL               6       /* tail bits per BCC encoder */
4025 
4026 /* 802.11 A PHY constants */
4027 #define APHY_SLOT_TIME          9       /* APHY slot time */
4028 #define APHY_SIFS_TIME          16      /* APHY SIFS time */
4029 #define APHY_DIFS_TIME          (APHY_SIFS_TIME + (2 * APHY_SLOT_TIME))  /* APHY DIFS time */
4030 #define APHY_PREAMBLE_TIME      16      /* APHY preamble time */
4031 #define APHY_SIGNAL_TIME        4       /* APHY signal time */
4032 #define APHY_SYMBOL_TIME        4       /* APHY symbol time */
4033 #define APHY_SERVICE_NBITS      16      /* APHY service nbits */
4034 #define APHY_TAIL_NBITS         6       /* APHY tail nbits */
4035 #define APHY_CWMIN              15      /* APHY cwmin */
4036 #define APHY_PHYHDR_DUR		20	/* APHY PHY Header Duration */
4037 
4038 /* 802.11 B PHY constants */
4039 #define BPHY_SLOT_TIME          20      /* BPHY slot time */
4040 #define BPHY_SIFS_TIME          10      /* BPHY SIFS time */
4041 #define BPHY_DIFS_TIME          50      /* BPHY DIFS time */
4042 #define BPHY_PLCP_TIME          192     /* BPHY PLCP time */
4043 #define BPHY_PLCP_SHORT_TIME    96      /* BPHY PLCP short time */
4044 #define BPHY_CWMIN              31      /* BPHY cwmin */
4045 #define BPHY_SHORT_PHYHDR_DUR	96	/* BPHY Short PHY Header Duration */
4046 #define BPHY_LONG_PHYHDR_DUR	192	/* BPHY Long PHY Header Duration */
4047 
4048 /* 802.11 G constants */
4049 #define DOT11_OFDM_SIGNAL_EXTENSION	6	/* d11 OFDM signal extension */
4050 
4051 #define PHY_CWMAX		1023	/* PHY cwmax */
4052 
4053 #define	DOT11_MAXNUMFRAGS	16	/* max # fragments per MSDU */
4054 
4055 /* 802.11 VHT constants */
4056 
4057 typedef int vht_group_id_t;
4058 
4059 /* for VHT-A1 */
4060 /* SIG-A1 reserved bits */
4061 #define VHT_SIGA1_CONST_MASK            0x800004
4062 
4063 #define VHT_SIGA1_BW_MASK               0x000003
4064 #define VHT_SIGA1_20MHZ_VAL             0x000000
4065 #define VHT_SIGA1_40MHZ_VAL             0x000001
4066 #define VHT_SIGA1_80MHZ_VAL             0x000002
4067 #define VHT_SIGA1_160MHZ_VAL            0x000003
4068 
4069 #define VHT_SIGA1_STBC                  0x000008
4070 
4071 #define VHT_SIGA1_GID_MASK              0x0003f0
4072 #define VHT_SIGA1_GID_SHIFT             4
4073 #define VHT_SIGA1_GID_TO_AP             0x00
4074 #define VHT_SIGA1_GID_NOT_TO_AP         0x3f
4075 #define VHT_SIGA1_GID_MAX_GID           0x3f
4076 
4077 #define VHT_SIGA1_NSTS_SHIFT_MASK_USER0 0x001C00
4078 #define VHT_SIGA1_NSTS_SHIFT            10
4079 #define VHT_SIGA1_MAX_USERPOS           3
4080 
4081 #define VHT_SIGA1_PARTIAL_AID_MASK      0x3fe000
4082 #define VHT_SIGA1_PARTIAL_AID_SHIFT     13
4083 
4084 #define VHT_SIGA1_TXOP_PS_NOT_ALLOWED   0x400000
4085 
4086 /* for VHT-A2 */
4087 #define VHT_SIGA2_GI_NONE               0x000000
4088 #define VHT_SIGA2_GI_SHORT              0x000001
4089 #define VHT_SIGA2_GI_W_MOD10            0x000002
4090 #define VHT_SIGA2_CODING_LDPC           0x000004
4091 #define VHT_SIGA2_LDPC_EXTRA_OFDM_SYM   0x000008
4092 #define VHT_SIGA2_BEAMFORM_ENABLE       0x000100
4093 #define VHT_SIGA2_MCS_SHIFT             4
4094 
4095 #define VHT_SIGA2_B9_RESERVED           0x000200
4096 #define VHT_SIGA2_TAIL_MASK             0xfc0000
4097 #define VHT_SIGA2_TAIL_VALUE            0x000000
4098 
4099 /* VHT Timing-related parameters (802.11ac D4.0, sec 22.3.6) */
4100 #define VHT_T_LEG_PREAMBLE      16
4101 #define VHT_T_L_SIG              4
4102 #define VHT_T_SIG_A              8
4103 #define VHT_T_LTF                4
4104 #define VHT_T_STF                4
4105 #define VHT_T_SIG_B              4
4106 #define VHT_T_SYML               4
4107 
4108 #define VHT_N_SERVICE           16	/* bits in SERVICE field */
4109 #define VHT_N_TAIL               6	/* tail bits per BCC encoder */
4110 
4111 /** dot11Counters Table - 802.11 spec., Annex D */
4112 typedef struct d11cnt {
4113 	uint32		txfrag;		/* dot11TransmittedFragmentCount */
4114 	uint32		txmulti;	/* dot11MulticastTransmittedFrameCount */
4115 	uint32		txfail;		/* dot11FailedCount */
4116 	uint32		txretry;	/* dot11RetryCount */
4117 	uint32		txretrie;	/* dot11MultipleRetryCount */
4118 	uint32		rxdup;		/* dot11FrameduplicateCount */
4119 	uint32		txrts;		/* dot11RTSSuccessCount */
4120 	uint32		txnocts;	/* dot11RTSFailureCount */
4121 	uint32		txnoack;	/* dot11ACKFailureCount */
4122 	uint32		rxfrag;		/* dot11ReceivedFragmentCount */
4123 	uint32		rxmulti;	/* dot11MulticastReceivedFrameCount */
4124 	uint32		rxcrc;		/* dot11FCSErrorCount */
4125 	uint32		txfrmsnt;	/* dot11TransmittedFrameCount */
4126 	uint32		rxundec;	/* dot11WEPUndecryptableCount */
4127 } d11cnt_t;
4128 
4129 /* OUI for BRCM proprietary IE */
4130 #define BRCM_PROP_OUI		"\x00\x90\x4C"	/* Broadcom proprietary OUI */
4131 
4132 /* Broadcom Proprietary OUI type list. Please update below page when adding a new type.
4133  * Twiki http://hwnbu-twiki.sj.broadcom.com/bin/view/Mwgroup/WlBrcmPropIE
4134  */
4135 /* The following BRCM_PROP_OUI types are currently in use (defined in
4136  * relevant subsections). Each of them will be in a separate proprietary(221) IE
4137  * #define RWL_WIFI_DEFAULT		0
4138  * #define SES_VNDR_IE_TYPE		1   (defined in src/ses/shared/ses.h)
4139  * #define VHT_FEATURES_IE_TYPE		4
4140  * #define RWL_WIFI_FIND_MY_PEER	9
4141  * #define RWL_WIFI_FOUND_PEER		10
4142  * #define PROXD_IE_TYPE		11
4143  */
4144 
4145 #define BRCM_FTM_IE_TYPE		14
4146 
4147 /* #define HT_CAP_IE_TYPE		51
4148  * #define HT_ADD_IE_TYPE		52
4149  * #define BRCM_EXTCH_IE_TYPE		53
4150  * #define MEMBER_OF_BRCM_PROP_IE_TYPE	54
4151  * #define BRCM_RELMACST_IE_TYPE	55
4152  * #define BRCM_EVT_WL_BSS_INFO		64
4153  * #define RWL_ACTION_WIFI_FRAG_TYPE	85
4154  * #define BTC_INFO_BRCM_PROP_IE_TYPE	90
4155  * #define ULB_BRCM_PROP_IE_TYPE	91
4156  * #define SDB_BRCM_PROP_IE_TYPE	92
4157  */
4158 
4159 /* Action frame type for RWL */
4160 #define RWL_WIFI_DEFAULT		0
4161 #define RWL_WIFI_FIND_MY_PEER		9 /* Used while finding server */
4162 #define RWL_WIFI_FOUND_PEER		10 /* Server response to the client  */
4163 #define RWL_ACTION_WIFI_FRAG_TYPE	85 /* Fragment indicator for receiver */
4164 
4165 #define PROXD_AF_TYPE			11 /* Wifi proximity action frame type */
4166 #define BRCM_RELMACST_AF_TYPE	        12 /* RMC action frame type */
4167 
4168 /* Action frame type for FTM Initiator Report */
4169 #define BRCM_FTM_VS_AF_TYPE	14
4170 enum {
4171 	BRCM_FTM_VS_INITIATOR_RPT_SUBTYPE = 1,	/* FTM Initiator Report */
4172 	BRCM_FTM_VS_COLLECT_SUBTYPE = 2,	/* FTM Collect debug protocol */
4173 };
4174 
4175 /* Action frame type for vendor specific action frames */
4176 #define	VS_AF_TYPE	221
4177 
4178 #ifdef WL_VS_AFTX
4179 /* Vendor specific action frame subtype for transmit using SU EDCA */
4180 #define VS_AF_SUBTYPE_SUEDCA	1
4181 
4182 #define VENDOR_PROP_OUI		"\x00\x17\xF2"
4183 #endif /* WL_VS_AFTX */
4184 
4185 /*
4186  * This BRCM_PROP_OUI types is intended for use in events to embed additional
4187  * data, and would not be expected to appear on the air -- but having an IE
4188  * format allows IE frame data with extra data in events in that allows for
4189  * more flexible parsing.
4190  */
4191 #define BRCM_EVT_WL_BSS_INFO	64
4192 
4193 /**
4194  * Following is the generic structure for brcm_prop_ie (uses BRCM_PROP_OUI).
4195  * DPT uses this format with type set to DPT_IE_TYPE
4196  */
4197 BWL_PRE_PACKED_STRUCT struct brcm_prop_ie_s {
4198 	uint8 id;		/* IE ID, 221, DOT11_MNG_PROPR_ID */
4199 	uint8 len;		/* IE length */
4200 	uint8 oui[3];		/* Proprietary OUI, BRCM_PROP_OUI */
4201 	uint8 type;		/* type of this IE */
4202 	uint16 cap;		/* DPT capabilities */
4203 } BWL_POST_PACKED_STRUCT;
4204 typedef struct brcm_prop_ie_s brcm_prop_ie_t;
4205 
4206 #define BRCM_PROP_IE_LEN	6	/* len of fixed part of brcm_prop ie */
4207 
4208 #define DPT_IE_TYPE             2
4209 
4210 #define BRCM_SYSCAP_IE_TYPE	3
4211 #define WET_TUNNEL_IE_TYPE	3
4212 
4213 /* brcm syscap_ie cap */
4214 #define BRCM_SYSCAP_WET_TUNNEL	0x0100	/* Device with WET_TUNNEL support */
4215 
4216 /* BRCM OUI: Used in the proprietary(221) IE in all broadcom devices */
4217 #define BRCM_OUI		"\x00\x10\x18"	/* Broadcom OUI */
4218 
4219 /** BRCM info element */
4220 BWL_PRE_PACKED_STRUCT struct brcm_ie {
4221 	uint8	id;		/* IE ID, 221, DOT11_MNG_PROPR_ID */
4222 	uint8	len;		/* IE length */
4223 	uint8	oui[3];		/* Proprietary OUI, BRCM_OUI */
4224 	uint8	ver;		/* type/ver of this IE */
4225 	uint8	assoc;		/* # of assoc STAs */
4226 	uint8	flags;		/* misc flags */
4227 	uint8	flags1;		/* misc flags */
4228 	uint16	amsdu_mtu_pref;	/* preferred A-MSDU MTU */
4229 	uint8	flags2;		/* Bit 0: DTPC TX cap, Bit 1: DTPC Recv Cap */
4230 } BWL_POST_PACKED_STRUCT;
4231 typedef	struct brcm_ie brcm_ie_t;
4232 #define BRCM_IE_LEN		12u	/* BRCM IE length */
4233 #define BRCM_IE_VER		2u	/* BRCM IE version */
4234 #define BRCM_IE_LEGACY_AES_VER	1u	/* BRCM IE legacy AES version */
4235 
4236 /* brcm_ie flags */
4237 #define	BRF_ABCAP		0x1	/* afterburner is obsolete,  defined for backward compat */
4238 #define	BRF_ABRQRD		0x2	/* afterburner is obsolete,  defined for backward compat */
4239 #define	BRF_LZWDS		0x4	/* lazy wds enabled */
4240 #define	BRF_BLOCKACK		0x8	/* BlockACK capable */
4241 #define BRF_ABCOUNTER_MASK	0xf0	/* afterburner is obsolete,  defined for backward compat */
4242 #define BRF_PROP_11N_MCS	0x10	/* re-use afterburner bit */
4243 #define BRF_MEDIA_CLIENT	0x20	/* re-use afterburner bit to indicate media client device */
4244 
4245 /**
4246  * Support for Broadcom proprietary HT MCS rates. Re-uses afterburner bits since
4247  * afterburner is not used anymore. Checks for BRF_ABCAP to stay compliant with 'old'
4248  * images in the field.
4249  */
4250 #define GET_BRF_PROP_11N_MCS(brcm_ie) \
4251 	(!((brcm_ie)->flags & BRF_ABCAP) && ((brcm_ie)->flags & BRF_PROP_11N_MCS))
4252 
4253 /* brcm_ie flags1 */
4254 #define	BRF1_AMSDU		0x1	/* A-MSDU capable */
4255 #define	BRF1_WNM		0x2	/* WNM capable */
4256 #define BRF1_WMEPS		0x4	/* AP is capable of handling WME + PS w/o APSD */
4257 #define BRF1_PSOFIX		0x8	/* AP has fixed PS mode out-of-order packets */
4258 #define	BRF1_RX_LARGE_AGG	0x10	/* device can rx large aggregates */
4259 #define BRF1_RFAWARE_DCS	0x20    /* RFAWARE dynamic channel selection (DCS) */
4260 #define BRF1_SOFTAP		0x40    /* Configure as Broadcom SOFTAP */
4261 #define BRF1_DWDS		0x80    /* DWDS capable */
4262 
4263 /* brcm_ie flags2 */
4264 #define BRF2_DTPC_TX		0x1u	/* DTPC: DTPC TX Cap */
4265 #define BRF2_DTPC_RX		0x2u	/* DTPC: DTPC RX Cap */
4266 #define BRF2_DTPC_TX_RX		0x3u	/* DTPC: Enable Both DTPC TX and RX Cap */
4267 
4268 /** Vendor IE structure */
4269 BWL_PRE_PACKED_STRUCT struct vndr_ie {
4270 	uchar id;
4271 	uchar len;
4272 	uchar oui [3];
4273 	uchar data [1];   /* Variable size data */
4274 } BWL_POST_PACKED_STRUCT;
4275 typedef struct vndr_ie vndr_ie_t;
4276 
4277 #define VNDR_IE_HDR_LEN		2u	/* id + len field */
4278 #define VNDR_IE_MIN_LEN		3u	/* size of the oui field */
4279 #define VNDR_IE_FIXED_LEN	(VNDR_IE_HDR_LEN + VNDR_IE_MIN_LEN)
4280 
4281 #define VNDR_IE_MAX_LEN		255u	/* vendor IE max length, without ID and len */
4282 
4283 /** BRCM PROP DEVICE PRIMARY MAC ADDRESS IE */
4284 BWL_PRE_PACKED_STRUCT struct member_of_brcm_prop_ie {
4285 	uchar id;
4286 	uchar len;
4287 	uchar oui[3];
4288 	uint8	type;           /* type indicates what follows */
4289 	struct ether_addr ea;   /* Device Primary MAC Adrress */
4290 } BWL_POST_PACKED_STRUCT;
4291 typedef struct member_of_brcm_prop_ie member_of_brcm_prop_ie_t;
4292 
4293 #define MEMBER_OF_BRCM_PROP_IE_LEN		10	/* IE max length */
4294 #define MEMBER_OF_BRCM_PROP_IE_HDRLEN	        (sizeof(member_of_brcm_prop_ie_t))
4295 #define MEMBER_OF_BRCM_PROP_IE_TYPE		54      /* used in prop IE 221 only */
4296 
4297 /** BRCM Reliable Multicast IE */
4298 BWL_PRE_PACKED_STRUCT struct relmcast_brcm_prop_ie {
4299 	uint8 id;
4300 	uint8 len;
4301 	uint8 oui[3];
4302 	uint8 type;           /* type indicates what follows */
4303 	struct ether_addr ea;   /* The ack sender's MAC Adrress */
4304 	struct ether_addr mcast_ea;  /* The multicast MAC address */
4305 	uint8 updtmo; /* time interval(second) for client to send null packet to report its rssi */
4306 } BWL_POST_PACKED_STRUCT;
4307 typedef struct relmcast_brcm_prop_ie relmcast_brcm_prop_ie_t;
4308 
4309 /* IE length */
4310 /* BRCM_PROP_IE_LEN = sizeof(relmcast_brcm_prop_ie_t)-((sizeof (id) + sizeof (len)))? */
4311 #define RELMCAST_BRCM_PROP_IE_LEN	(sizeof(relmcast_brcm_prop_ie_t)-(2*sizeof(uint8)))
4312 
4313 #define RELMCAST_BRCM_PROP_IE_TYPE	55	/* used in prop IE 221 only */
4314 
4315 /* BRCM BTC IE */
4316 BWL_PRE_PACKED_STRUCT struct btc_brcm_prop_ie {
4317 	uint8 id;
4318 	uint8 len;
4319 	uint8 oui[3];
4320 	uint8 type;           /* type inidicates what follows */
4321 	uint32 info;
4322 } BWL_POST_PACKED_STRUCT;
4323 typedef struct btc_brcm_prop_ie btc_brcm_prop_ie_t;
4324 
4325 #define BTC_INFO_BRCM_PROP_IE_TYPE	90
4326 #define BRCM_BTC_INFO_TYPE_LEN	(sizeof(btc_brcm_prop_ie_t) - (2 * sizeof(uint8)))
4327 
4328 /* ************* HT definitions. ************* */
4329 #define MCSSET_LEN	16	/* 16-bits per 8-bit set to give 128-bits bitmap of MCS Index */
4330 #define MAX_MCS_NUM	(128)	/* max mcs number = 128 */
4331 #define BASIC_HT_MCS	0xFFu	/* HT MCS supported rates */
4332 
4333 BWL_PRE_PACKED_STRUCT struct ht_cap_ie {
4334 	uint16	cap;
4335 	uint8	params;
4336 	uint8	supp_mcs[MCSSET_LEN];
4337 	uint16	ext_htcap;
4338 	uint32	txbf_cap;
4339 	uint8	as_cap;
4340 } BWL_POST_PACKED_STRUCT;
4341 typedef struct ht_cap_ie ht_cap_ie_t;
4342 
4343 BWL_PRE_PACKED_STRUCT struct dot11_ht_cap_ie {
4344 	uint8	id;
4345 	uint8	len;
4346 	ht_cap_ie_t ht_cap;
4347 } BWL_POST_PACKED_STRUCT;
4348 typedef struct dot11_ht_cap_ie dot11_ht_cap_ie_t;
4349 
4350 /* CAP IE: HT 1.0 spec. simply stole a 802.11 IE, we use our prop. IE until this is resolved */
4351 /* the capability IE is primarily used to convey this nodes abilities */
4352 BWL_PRE_PACKED_STRUCT struct ht_prop_cap_ie {
4353 	uint8	id;		/* IE ID, 221, DOT11_MNG_PROPR_ID */
4354 	uint8	len;		/* IE length */
4355 	uint8	oui[3];		/* Proprietary OUI, BRCM_PROP_OUI */
4356 	uint8	type;           /* type indicates what follows */
4357 	ht_cap_ie_t cap_ie;
4358 } BWL_POST_PACKED_STRUCT;
4359 typedef struct ht_prop_cap_ie ht_prop_cap_ie_t;
4360 
4361 #define HT_PROP_IE_OVERHEAD	4	/* overhead bytes for prop oui ie */
4362 #define HT_CAP_IE_LEN		26	/* HT capability len (based on .11n d2.0) */
4363 #define HT_CAP_IE_TYPE		51      /* used in prop IE 221 only */
4364 
4365 #define HT_CAP_LDPC_CODING	0x0001	/* Support for rx of LDPC coded pkts */
4366 #define HT_CAP_40MHZ		0x0002  /* FALSE:20Mhz, TRUE:20/40MHZ supported */
4367 #define HT_CAP_MIMO_PS_MASK	0x000C  /* Mimo PS mask */
4368 #define HT_CAP_MIMO_PS_SHIFT	0x0002	/* Mimo PS shift */
4369 #define HT_CAP_MIMO_PS_OFF	0x0003	/* Mimo PS, no restriction */
4370 #define HT_CAP_MIMO_PS_RTS	0x0001	/* Mimo PS, send RTS/CTS around MIMO frames */
4371 #define HT_CAP_MIMO_PS_ON	0x0000	/* Mimo PS, MIMO disallowed */
4372 #define HT_CAP_GF		0x0010	/* Greenfield preamble support */
4373 #define HT_CAP_SHORT_GI_20	0x0020	/* 20MHZ short guard interval support */
4374 #define HT_CAP_SHORT_GI_40	0x0040	/* 40Mhz short guard interval support */
4375 #define HT_CAP_TX_STBC		0x0080	/* Tx STBC support */
4376 #define HT_CAP_RX_STBC_MASK	0x0300	/* Rx STBC mask */
4377 #define HT_CAP_RX_STBC_SHIFT	8	/* Rx STBC shift */
4378 #define HT_CAP_DELAYED_BA	0x0400	/* delayed BA support */
4379 #define HT_CAP_MAX_AMSDU	0x0800	/* Max AMSDU size in bytes , 0=3839, 1=7935 */
4380 
4381 #define HT_CAP_DSSS_CCK	0x1000	/* DSSS/CCK supported by the BSS */
4382 #define HT_CAP_PSMP		0x2000	/* Power Save Multi Poll support */
4383 #define HT_CAP_40MHZ_INTOLERANT 0x4000	/* 40MHz Intolerant */
4384 #define HT_CAP_LSIG_TXOP	0x8000	/* L-SIG TXOP protection support */
4385 
4386 #define HT_CAP_RX_STBC_NO		0x0	/* no rx STBC support */
4387 #define HT_CAP_RX_STBC_ONE_STREAM	0x1	/* rx STBC support of 1 spatial stream */
4388 #define HT_CAP_RX_STBC_TWO_STREAM	0x2	/* rx STBC support of 1-2 spatial streams */
4389 #define HT_CAP_RX_STBC_THREE_STREAM	0x3	/* rx STBC support of 1-3 spatial streams */
4390 
4391 #define HT_CAP_TXBF_CAP_IMPLICIT_TXBF_RX	0x1
4392 #define HT_CAP_TXBF_CAP_NDP_RX			0x8
4393 #define HT_CAP_TXBF_CAP_NDP_TX			0x10
4394 #define HT_CAP_TXBF_CAP_EXPLICIT_CSI		0x100
4395 #define HT_CAP_TXBF_CAP_EXPLICIT_NC_STEERING	0x200
4396 #define HT_CAP_TXBF_CAP_EXPLICIT_C_STEERING	0x400
4397 #define HT_CAP_TXBF_CAP_EXPLICIT_CSI_FB_MASK	0x1800
4398 #define HT_CAP_TXBF_CAP_EXPLICIT_CSI_FB_SHIFT	11
4399 #define HT_CAP_TXBF_CAP_EXPLICIT_NC_FB_MASK	0x6000
4400 #define HT_CAP_TXBF_CAP_EXPLICIT_NC_FB_SHIFT	13
4401 #define HT_CAP_TXBF_CAP_EXPLICIT_C_FB_MASK	0x18000
4402 #define HT_CAP_TXBF_CAP_EXPLICIT_C_FB_SHIFT	15
4403 #define HT_CAP_TXBF_CAP_CSI_BFR_ANT_SHIFT	19
4404 #define HT_CAP_TXBF_CAP_NC_BFR_ANT_SHIFT	21
4405 #define HT_CAP_TXBF_CAP_C_BFR_ANT_SHIFT		23
4406 #define HT_CAP_TXBF_CAP_C_BFR_ANT_MASK		0x1800000
4407 
4408 #define HT_CAP_TXBF_CAP_CHAN_ESTIM_SHIFT	27
4409 #define HT_CAP_TXBF_CAP_CHAN_ESTIM_MASK		0x18000000
4410 
4411 #define HT_CAP_TXBF_FB_TYPE_NONE	0
4412 #define HT_CAP_TXBF_FB_TYPE_DELAYED	1
4413 #define HT_CAP_TXBF_FB_TYPE_IMMEDIATE	2
4414 #define HT_CAP_TXBF_FB_TYPE_BOTH	3
4415 
4416 #define HT_CAP_TX_BF_CAP_EXPLICIT_CSI_FB_MASK	0x400
4417 #define HT_CAP_TX_BF_CAP_EXPLICIT_CSI_FB_SHIFT	10
4418 #define HT_CAP_TX_BF_CAP_EXPLICIT_COMPRESSED_FB_MASK 0x18000
4419 #define HT_CAP_TX_BF_CAP_EXPLICIT_COMPRESSED_FB_SHIFT 15
4420 
4421 #define HT_CAP_MCS_FLAGS_SUPP_BYTE 12 /* byte offset in HT Cap Supported MCS for various flags */
4422 #define HT_CAP_MCS_RX_8TO15_BYTE_OFFSET                1
4423 #define HT_CAP_MCS_FLAGS_TX_RX_UNEQUAL              0x02
4424 #define HT_CAP_MCS_FLAGS_MAX_SPATIAL_STREAM_MASK    0x0C
4425 
4426 #define VHT_MAX_MPDU		11454	/* max mpdu size for now (bytes) */
4427 #define VHT_MPDU_MSDU_DELTA	56		/* Difference in spec - vht mpdu, amsdu len */
4428 /* Max AMSDU len - per spec */
4429 #define VHT_MAX_AMSDU		(VHT_MAX_MPDU - VHT_MPDU_MSDU_DELTA)
4430 
4431 #define HT_MAX_AMSDU		7935	/* max amsdu size (bytes) per the HT spec */
4432 #define HT_MIN_AMSDU		3835	/* min amsdu size (bytes) per the HT spec */
4433 
4434 #define HT_PARAMS_RX_FACTOR_MASK	0x03	/* ampdu rcv factor mask */
4435 #define HT_PARAMS_DENSITY_MASK		0x1C	/* ampdu density mask */
4436 #define HT_PARAMS_DENSITY_SHIFT	2	/* ampdu density shift */
4437 
4438 /* HT/AMPDU specific define */
4439 #define AMPDU_MAX_MPDU_DENSITY  7       /* max mpdu density; in 1/4 usec units */
4440 #define AMPDU_DENSITY_NONE      0       /* No density requirement */
4441 #define AMPDU_DENSITY_1over4_US 1       /* 1/4 us density */
4442 #define AMPDU_DENSITY_1over2_US 2       /* 1/2 us density */
4443 #define AMPDU_DENSITY_1_US      3       /*   1 us density */
4444 #define AMPDU_DENSITY_2_US      4       /*   2 us density */
4445 #define AMPDU_DENSITY_4_US      5       /*   4 us density */
4446 #define AMPDU_DENSITY_8_US      6       /*   8 us density */
4447 #define AMPDU_DENSITY_16_US     7       /*  16 us density */
4448 #define AMPDU_RX_FACTOR_8K      0       /* max rcv ampdu len (8kb) */
4449 #define AMPDU_RX_FACTOR_16K     1       /* max rcv ampdu len (16kb) */
4450 #define AMPDU_RX_FACTOR_32K     2       /* max rcv ampdu len (32kb) */
4451 #define AMPDU_RX_FACTOR_64K     3       /* max rcv ampdu len (64kb) */
4452 
4453 /* AMPDU RX factors for VHT rates */
4454 #define AMPDU_RX_FACTOR_128K    4       /* max rcv ampdu len (128kb) */
4455 #define AMPDU_RX_FACTOR_256K    5       /* max rcv ampdu len (256kb) */
4456 #define AMPDU_RX_FACTOR_512K    6       /* max rcv ampdu len (512kb) */
4457 #define AMPDU_RX_FACTOR_1024K   7       /* max rcv ampdu len (1024kb) */
4458 
4459 #define AMPDU_RX_FACTOR_BASE    8*1024  /* ampdu factor base for rx len */
4460 #define AMPDU_RX_FACTOR_BASE_PWR	13	/* ampdu factor base for rx len in power of 2 */
4461 
4462 #define AMPDU_DELIMITER_LEN	4u	/* length of ampdu delimiter */
4463 #define AMPDU_DELIMITER_LEN_MAX	63	/* max length of ampdu delimiter(enforced in HW) */
4464 
4465 #define HT_CAP_EXT_PCO			0x0001
4466 #define HT_CAP_EXT_PCO_TTIME_MASK	0x0006
4467 #define HT_CAP_EXT_PCO_TTIME_SHIFT	1
4468 #define HT_CAP_EXT_MCS_FEEDBACK_MASK	0x0300
4469 #define HT_CAP_EXT_MCS_FEEDBACK_SHIFT	8
4470 #define HT_CAP_EXT_HTC			0x0400
4471 #define HT_CAP_EXT_RD_RESP		0x0800
4472 
4473 /** 'ht_add' is called 'HT Operation' information element in the 802.11 standard */
4474 BWL_PRE_PACKED_STRUCT struct ht_add_ie {
4475 	uint8	ctl_ch;			/* control channel number */
4476 	uint8	byte1;			/* ext ch,rec. ch. width, RIFS support */
4477 	uint16	opmode;			/* operation mode */
4478 	uint16	misc_bits;		/* misc bits */
4479 	uint8	basic_mcs[MCSSET_LEN];  /* required MCS set */
4480 } BWL_POST_PACKED_STRUCT;
4481 typedef struct ht_add_ie ht_add_ie_t;
4482 
4483 /* ADD IE: HT 1.0 spec. simply stole a 802.11 IE, we use our prop. IE until this is resolved */
4484 /* the additional IE is primarily used to convey the current BSS configuration */
4485 BWL_PRE_PACKED_STRUCT struct ht_prop_add_ie {
4486 	uint8	id;		/* IE ID, 221, DOT11_MNG_PROPR_ID */
4487 	uint8	len;		/* IE length */
4488 	uint8	oui[3];		/* Proprietary OUI, BRCM_PROP_OUI */
4489 	uint8	type;		/* indicates what follows */
4490 	ht_add_ie_t add_ie;
4491 } BWL_POST_PACKED_STRUCT;
4492 typedef struct ht_prop_add_ie ht_prop_add_ie_t;
4493 
4494 #define HT_ADD_IE_LEN	22	/* HT capability len (based on .11n d1.0) */
4495 #define HT_ADD_IE_TYPE	52	/* faked out as current spec is illegal */
4496 
4497 /* byte1 defn's */
4498 #define HT_BW_ANY		0x04	/* set, STA can use 20 or 40MHz */
4499 #define HT_RIFS_PERMITTED	0x08	/* RIFS allowed */
4500 
4501 /* opmode defn's */
4502 #define HT_OPMODE_MASK	        0x0003	/* protection mode mask */
4503 #define HT_OPMODE_SHIFT		0	/* protection mode shift */
4504 #define HT_OPMODE_PURE		0x0000	/* protection mode PURE */
4505 #define HT_OPMODE_OPTIONAL	0x0001	/* protection mode optional */
4506 #define HT_OPMODE_HT20IN40	0x0002	/* protection mode 20MHz HT in 40MHz BSS */
4507 #define HT_OPMODE_MIXED	0x0003	/* protection mode Mixed Mode */
4508 #define HT_OPMODE_NONGF	0x0004	/* protection mode non-GF */
4509 #define DOT11N_TXBURST		0x0008	/* Tx burst limit */
4510 #define DOT11N_OBSS_NONHT	0x0010	/* OBSS Non-HT STA present */
4511 #define HT_OPMODE_CCFS2_MASK	0x1fe0	/* Channel Center Frequency Segment 2 mask */
4512 #define HT_OPMODE_CCFS2_SHIFT	5	/* Channel Center Frequency Segment 2 shift */
4513 
4514 /* misc_bites defn's */
4515 #define HT_BASIC_STBC_MCS	0x007f	/* basic STBC MCS */
4516 #define HT_DUAL_STBC_PROT	0x0080	/* Dual STBC Protection */
4517 #define HT_SECOND_BCN		0x0100	/* Secondary beacon support */
4518 #define HT_LSIG_TXOP		0x0200	/* L-SIG TXOP Protection full support */
4519 #define HT_PCO_ACTIVE		0x0400	/* PCO active */
4520 #define HT_PCO_PHASE		0x0800	/* PCO phase */
4521 #define HT_DUALCTS_PROTECTION	0x0080	/* DUAL CTS protection needed */
4522 
4523 /* Tx Burst Limits */
4524 #define DOT11N_2G_TXBURST_LIMIT	6160	/* 2G band Tx burst limit per 802.11n Draft 1.10 (usec) */
4525 #define DOT11N_5G_TXBURST_LIMIT	3080	/* 5G band Tx burst limit per 802.11n Draft 1.10 (usec) */
4526 
4527 /* Macros for opmode */
4528 #define GET_HT_OPMODE(add_ie)		((ltoh16_ua(&add_ie->opmode) & HT_OPMODE_MASK) \
4529 					>> HT_OPMODE_SHIFT)
4530 #define HT_MIXEDMODE_PRESENT(add_ie)	((ltoh16_ua(&add_ie->opmode) & HT_OPMODE_MASK) \
4531 					== HT_OPMODE_MIXED)	/* mixed mode present */
4532 #define HT_HT20_PRESENT(add_ie)	((ltoh16_ua(&add_ie->opmode) & HT_OPMODE_MASK) \
4533 					== HT_OPMODE_HT20IN40)	/* 20MHz HT present */
4534 #define HT_OPTIONAL_PRESENT(add_ie)	((ltoh16_ua(&add_ie->opmode) & HT_OPMODE_MASK) \
4535 					== HT_OPMODE_OPTIONAL)	/* Optional protection present */
4536 #define HT_USE_PROTECTION(add_ie)	(HT_HT20_PRESENT((add_ie)) || \
4537 					HT_MIXEDMODE_PRESENT((add_ie))) /* use protection */
4538 #define HT_NONGF_PRESENT(add_ie)	((ltoh16_ua(&add_ie->opmode) & HT_OPMODE_NONGF) \
4539 					== HT_OPMODE_NONGF)	/* non-GF present */
4540 #define DOT11N_TXBURST_PRESENT(add_ie)	((ltoh16_ua(&add_ie->opmode) & DOT11N_TXBURST) \
4541 					== DOT11N_TXBURST)	/* Tx Burst present */
4542 #define DOT11N_OBSS_NONHT_PRESENT(add_ie)	((ltoh16_ua(&add_ie->opmode) & DOT11N_OBSS_NONHT) \
4543 					== DOT11N_OBSS_NONHT)	/* OBSS Non-HT present */
4544 #define HT_OPMODE_CCFS2_GET(add_ie)	((ltoh16_ua(&(add_ie)->opmode) & HT_OPMODE_CCFS2_MASK) \
4545 					>> HT_OPMODE_CCFS2_SHIFT)	/* get CCFS2 */
4546 #define HT_OPMODE_CCFS2_SET(add_ie, ccfs2)	do { /* set CCFS2 */ \
4547 	(add_ie)->opmode &= htol16(~HT_OPMODE_CCFS2_MASK); \
4548 	(add_ie)->opmode |= htol16(((ccfs2) << HT_OPMODE_CCFS2_SHIFT) & HT_OPMODE_CCFS2_MASK); \
4549 } while (0)
4550 
4551 /* Macros for HT MCS field access */
4552 #define HT_CAP_MCS_BITMASK(supp_mcs)                 \
4553 	((supp_mcs)[HT_CAP_MCS_RX_8TO15_BYTE_OFFSET])
4554 #define HT_CAP_MCS_TX_RX_UNEQUAL(supp_mcs)          \
4555 	((supp_mcs)[HT_CAP_MCS_FLAGS_SUPP_BYTE] & HT_CAP_MCS_FLAGS_TX_RX_UNEQUAL)
4556 #define HT_CAP_MCS_TX_STREAM_SUPPORT(supp_mcs)          \
4557 		((supp_mcs)[HT_CAP_MCS_FLAGS_SUPP_BYTE] & HT_CAP_MCS_FLAGS_MAX_SPATIAL_STREAM_MASK)
4558 
4559 BWL_PRE_PACKED_STRUCT struct obss_params {
4560 	uint16	passive_dwell;
4561 	uint16	active_dwell;
4562 	uint16	bss_widthscan_interval;
4563 	uint16	passive_total;
4564 	uint16	active_total;
4565 	uint16	chanwidth_transition_dly;
4566 	uint16	activity_threshold;
4567 } BWL_POST_PACKED_STRUCT;
4568 typedef struct obss_params obss_params_t;
4569 
4570 BWL_PRE_PACKED_STRUCT struct dot11_obss_ie {
4571 	uint8	id;
4572 	uint8	len;
4573 	obss_params_t obss_params;
4574 } BWL_POST_PACKED_STRUCT;
4575 typedef struct dot11_obss_ie dot11_obss_ie_t;
4576 #define DOT11_OBSS_SCAN_IE_LEN	sizeof(obss_params_t)	/* HT OBSS len (based on 802.11n d3.0) */
4577 
4578 /* HT control field */
4579 #define HT_CTRL_LA_TRQ		0x00000002	/* sounding request */
4580 #define HT_CTRL_LA_MAI		0x0000003C	/* MCS request or antenna selection indication */
4581 #define HT_CTRL_LA_MAI_SHIFT	2
4582 #define HT_CTRL_LA_MAI_MRQ	0x00000004	/* MCS request */
4583 #define HT_CTRL_LA_MAI_MSI	0x00000038	/* MCS request sequence identifier */
4584 #define HT_CTRL_LA_MFSI		0x000001C0	/* MFB sequence identifier */
4585 #define HT_CTRL_LA_MFSI_SHIFT	6
4586 #define HT_CTRL_LA_MFB_ASELC	0x0000FE00	/* MCS feedback, antenna selection command/data */
4587 #define HT_CTRL_LA_MFB_ASELC_SH	9
4588 #define HT_CTRL_LA_ASELC_CMD	0x00000C00	/* ASEL command */
4589 #define HT_CTRL_LA_ASELC_DATA	0x0000F000	/* ASEL data */
4590 #define HT_CTRL_CAL_POS		0x00030000	/* Calibration position */
4591 #define HT_CTRL_CAL_SEQ		0x000C0000	/* Calibration sequence */
4592 #define HT_CTRL_CSI_STEERING	0x00C00000	/* CSI/Steering */
4593 #define HT_CTRL_CSI_STEER_SHIFT	22
4594 #define HT_CTRL_CSI_STEER_NFB	0		/* no fedback required */
4595 #define HT_CTRL_CSI_STEER_CSI	1		/* CSI, H matrix */
4596 #define HT_CTRL_CSI_STEER_NCOM	2		/* non-compressed beamforming */
4597 #define HT_CTRL_CSI_STEER_COM	3		/* compressed beamforming */
4598 #define HT_CTRL_NDP_ANNOUNCE	0x01000000	/* NDP announcement */
4599 #define HT_CTRL_AC_CONSTRAINT	0x40000000	/* AC Constraint */
4600 #define HT_CTRL_RDG_MOREPPDU	0x80000000	/* RDG/More PPDU */
4601 
4602 /* ************* VHT definitions. ************* */
4603 
4604 /**
4605  * VHT Capabilites IE (sec 8.4.2.160)
4606  */
4607 
4608 BWL_PRE_PACKED_STRUCT struct vht_cap_ie {
4609 	uint32  vht_cap_info;
4610 	/* supported MCS set - 64 bit field */
4611 	uint16	rx_mcs_map;
4612 	uint16  rx_max_rate;
4613 	uint16  tx_mcs_map;
4614 	uint16	tx_max_rate;
4615 } BWL_POST_PACKED_STRUCT;
4616 typedef struct vht_cap_ie vht_cap_ie_t;
4617 
4618 /* 4B cap_info + 8B supp_mcs */
4619 #define VHT_CAP_IE_LEN 12
4620 
4621 /* VHT Capabilities Info field - 32bit - in VHT Cap IE */
4622 #define VHT_CAP_INFO_MAX_MPDU_LEN_MASK          0x00000003
4623 #define VHT_CAP_INFO_SUPP_CHAN_WIDTH_MASK       0x0000000c
4624 #define VHT_CAP_INFO_LDPC                       0x00000010
4625 #define VHT_CAP_INFO_SGI_80MHZ                  0x00000020
4626 #define VHT_CAP_INFO_SGI_160MHZ                 0x00000040
4627 #define VHT_CAP_INFO_TX_STBC                    0x00000080
4628 #define VHT_CAP_INFO_RX_STBC_MASK               0x00000700
4629 #define VHT_CAP_INFO_RX_STBC_SHIFT              8u
4630 #define VHT_CAP_INFO_SU_BEAMFMR                 0x00000800
4631 #define VHT_CAP_INFO_SU_BEAMFMEE                0x00001000
4632 #define VHT_CAP_INFO_NUM_BMFMR_ANT_MASK         0x0000e000
4633 #define VHT_CAP_INFO_NUM_BMFMR_ANT_SHIFT        13u
4634 #define VHT_CAP_INFO_NUM_SOUNDING_DIM_MASK      0x00070000
4635 #define VHT_CAP_INFO_NUM_SOUNDING_DIM_SHIFT     16u
4636 #define VHT_CAP_INFO_MU_BEAMFMR                 0x00080000
4637 #define VHT_CAP_INFO_MU_BEAMFMEE                0x00100000
4638 #define VHT_CAP_INFO_TXOPPS                     0x00200000
4639 #define VHT_CAP_INFO_HTCVHT                     0x00400000
4640 #define VHT_CAP_INFO_AMPDU_MAXLEN_EXP_MASK      0x03800000
4641 #define VHT_CAP_INFO_AMPDU_MAXLEN_EXP_SHIFT     23u
4642 #define VHT_CAP_INFO_LINK_ADAPT_CAP_MASK        0x0c000000
4643 #define VHT_CAP_INFO_LINK_ADAPT_CAP_SHIFT       26u
4644 #define VHT_CAP_INFO_EXT_NSS_BW_SUP_MASK        0xc0000000
4645 #define VHT_CAP_INFO_EXT_NSS_BW_SUP_SHIFT       30u
4646 
4647 /* get Extended NSS BW Support passing vht cap info */
4648 #define VHT_CAP_EXT_NSS_BW_SUP(cap_info) \
4649 	(((cap_info) & VHT_CAP_INFO_EXT_NSS_BW_SUP_MASK) >> VHT_CAP_INFO_EXT_NSS_BW_SUP_SHIFT)
4650 
4651 /* VHT CAP INFO extended NSS BW support - refer to IEEE 802.11 REVmc D8.0 Figure 9-559 */
4652 #define VHT_CAP_INFO_EXT_NSS_BW_HALF_160	1 /* 160MHz at half NSS CAP */
4653 #define VHT_CAP_INFO_EXT_NSS_BW_HALF_160_80P80	2 /* 160 & 80p80 MHz at half NSS CAP */
4654 
4655 /* VHT Supported MCS Set - 64-bit - in VHT Cap IE */
4656 #define VHT_CAP_SUPP_MCS_RX_HIGHEST_RATE_MASK   0x1fff
4657 #define VHT_CAP_SUPP_MCS_RX_HIGHEST_RATE_SHIFT  0
4658 
4659 #define VHT_CAP_SUPP_MCS_TX_HIGHEST_RATE_MASK   0x1fff
4660 #define VHT_CAP_SUPP_MCS_TX_HIGHEST_RATE_SHIFT  0
4661 
4662 /* defines for field(s) in vht_cap_ie->rx_max_rate */
4663 #define VHT_CAP_MAX_NSTS_MASK			0xe000
4664 #define VHT_CAP_MAX_NSTS_SHIFT			13
4665 
4666 /* defines for field(s) in vht_cap_ie->tx_max_rate */
4667 #define VHT_CAP_EXT_NSS_BW_CAP			0x2000
4668 
4669 #define VHT_CAP_MCS_MAP_0_7                     0
4670 #define VHT_CAP_MCS_MAP_0_8                     1
4671 #define VHT_CAP_MCS_MAP_0_9                     2
4672 #define VHT_CAP_MCS_MAP_NONE                    3
4673 #define VHT_CAP_MCS_MAP_S                       2 /* num bits for 1-stream */
4674 #define VHT_CAP_MCS_MAP_M                       0x3 /* mask for 1-stream */
4675 /* assumes VHT_CAP_MCS_MAP_NONE is 3 and 2 bits are used for encoding */
4676 #define VHT_CAP_MCS_MAP_NONE_ALL                0xffff
4677 
4678 /* VHT rates bitmap */
4679 #define VHT_CAP_MCS_0_7_RATEMAP		0x00ff
4680 #define VHT_CAP_MCS_0_8_RATEMAP		0x01ff
4681 #define VHT_CAP_MCS_0_9_RATEMAP		0x03ff
4682 #define VHT_CAP_MCS_FULL_RATEMAP	VHT_CAP_MCS_0_9_RATEMAP
4683 
4684 #define VHT_PROP_MCS_MAP_10_11                   0
4685 #define VHT_PROP_MCS_MAP_UNUSED1                 1
4686 #define VHT_PROP_MCS_MAP_UNUSED2                 2
4687 #define VHT_PROP_MCS_MAP_NONE                    3
4688 #define VHT_PROP_MCS_MAP_NONE_ALL                0xffff
4689 
4690 /* VHT prop rates bitmap */
4691 #define VHT_PROP_MCS_10_11_RATEMAP	0x0c00
4692 #define VHT_PROP_MCS_FULL_RATEMAP	VHT_PROP_MCS_10_11_RATEMAP
4693 
4694 #if !defined(VHT_CAP_MCS_MAP_0_9_NSS3)
4695 /* remove after moving define to wlc_rate.h */
4696 /* mcsmap with MCS0-9 for Nss = 3 */
4697 #define VHT_CAP_MCS_MAP_0_9_NSS3 \
4698 	        ((VHT_CAP_MCS_MAP_0_9 << VHT_MCS_MAP_GET_SS_IDX(1)) | \
4699 	         (VHT_CAP_MCS_MAP_0_9 << VHT_MCS_MAP_GET_SS_IDX(2)) | \
4700 	         (VHT_CAP_MCS_MAP_0_9 << VHT_MCS_MAP_GET_SS_IDX(3)))
4701 #endif /* !VHT_CAP_MCS_MAP_0_9_NSS3 */
4702 
4703 #define VHT_CAP_MCS_MAP_NSS_MAX                 8
4704 
4705 /* get mcsmap with given mcs for given nss streams */
4706 #define VHT_CAP_MCS_MAP_CREATE(mcsmap, nss, mcs) \
4707 	do { \
4708 		int i; \
4709 		for (i = 1; i <= nss; i++) { \
4710 			VHT_MCS_MAP_SET_MCS_PER_SS(i, mcs, mcsmap); \
4711 		} \
4712 	} while (0)
4713 
4714 /* Map the mcs code to mcs bit map */
4715 #define VHT_MCS_CODE_TO_MCS_MAP(mcs_code) \
4716 	((mcs_code == VHT_CAP_MCS_MAP_0_7) ? VHT_CAP_MCS_0_7_RATEMAP : \
4717 	 (mcs_code == VHT_CAP_MCS_MAP_0_8) ? VHT_CAP_MCS_0_8_RATEMAP : \
4718 	 (mcs_code == VHT_CAP_MCS_MAP_0_9) ? VHT_CAP_MCS_0_9_RATEMAP : 0)
4719 
4720 /* Map the proprietary mcs code to proprietary mcs bitmap */
4721 #define VHT_PROP_MCS_CODE_TO_PROP_MCS_MAP(mcs_code) \
4722 	((mcs_code == VHT_PROP_MCS_MAP_10_11) ? VHT_PROP_MCS_10_11_RATEMAP : 0)
4723 
4724 /* Map the mcs bit map to mcs code */
4725 #define VHT_MCS_MAP_TO_MCS_CODE(mcs_map) \
4726 	((mcs_map == VHT_CAP_MCS_0_7_RATEMAP) ? VHT_CAP_MCS_MAP_0_7 : \
4727 	 (mcs_map == VHT_CAP_MCS_0_8_RATEMAP) ? VHT_CAP_MCS_MAP_0_8 : \
4728 	 (mcs_map == VHT_CAP_MCS_0_9_RATEMAP) ? VHT_CAP_MCS_MAP_0_9 : VHT_CAP_MCS_MAP_NONE)
4729 
4730 /* Map the proprietary mcs map to proprietary mcs code */
4731 #define VHT_PROP_MCS_MAP_TO_PROP_MCS_CODE(mcs_map) \
4732 	(((mcs_map & 0xc00) == 0xc00)  ? VHT_PROP_MCS_MAP_10_11 : VHT_PROP_MCS_MAP_NONE)
4733 
4734 /** VHT Capabilities Supported Channel Width */
4735 typedef enum vht_cap_chan_width {
4736 	VHT_CAP_CHAN_WIDTH_SUPPORT_MANDATORY = 0x00,
4737 	VHT_CAP_CHAN_WIDTH_SUPPORT_160       = 0x04,
4738 	VHT_CAP_CHAN_WIDTH_SUPPORT_160_8080  = 0x08
4739 } vht_cap_chan_width_t;
4740 
4741 /** VHT Capabilities Supported max MPDU LEN (sec 8.4.2.160.2) */
4742 typedef enum vht_cap_max_mpdu_len {
4743 	VHT_CAP_MPDU_MAX_4K     = 0x00,
4744 	VHT_CAP_MPDU_MAX_8K     = 0x01,
4745 	VHT_CAP_MPDU_MAX_11K    = 0x02
4746 } vht_cap_max_mpdu_len_t;
4747 
4748 /* Maximum MPDU Length byte counts for the VHT Capabilities advertised limits */
4749 #define VHT_MPDU_LIMIT_4K        3895
4750 #define VHT_MPDU_LIMIT_8K        7991
4751 #define VHT_MPDU_LIMIT_11K      11454
4752 
4753 /**
4754  * VHT Operation IE (sec 8.4.2.161)
4755  */
4756 
4757 BWL_PRE_PACKED_STRUCT struct vht_op_ie {
4758 	uint8	chan_width;
4759 	uint8	chan1;
4760 	uint8	chan2;
4761 	uint16	supp_mcs;  /*  same def as above in vht cap */
4762 } BWL_POST_PACKED_STRUCT;
4763 typedef struct vht_op_ie vht_op_ie_t;
4764 
4765 /* 3B VHT Op info + 2B Basic MCS */
4766 #define VHT_OP_IE_LEN 5
4767 
4768 typedef enum vht_op_chan_width {
4769 	VHT_OP_CHAN_WIDTH_20_40	= 0,
4770 	VHT_OP_CHAN_WIDTH_80	= 1,
4771 	VHT_OP_CHAN_WIDTH_160	= 2, /* deprecated - IEEE 802.11 REVmc D8.0 Table 11-25 */
4772 	VHT_OP_CHAN_WIDTH_80_80	= 3  /* deprecated - IEEE 802.11 REVmc D8.0 Table 11-25 */
4773 } vht_op_chan_width_t;
4774 
4775 #define VHT_OP_INFO_LEN		3
4776 
4777 /* AID length */
4778 #define AID_IE_LEN		2
4779 /**
4780  * BRCM vht features IE header
4781  * The header if the fixed part of the IE
4782  * On the 5GHz band this is the entire IE,
4783  * on 2.4GHz the VHT IEs as defined in the 802.11ac
4784  * specification follows
4785  *
4786  *
4787  * VHT features rates  bitmap.
4788  * Bit0:		5G MCS 0-9 BW 160MHz
4789  * Bit1:		5G MCS 0-9 support BW 80MHz
4790  * Bit2:		5G MCS 0-9 support BW 20MHz
4791  * Bit3:		2.4G MCS 0-9 support BW 20MHz
4792  * Bits:4-7	Reserved for future use
4793  *
4794  */
4795 #define VHT_FEATURES_IE_TYPE	0x4
4796 BWL_PRE_PACKED_STRUCT struct vht_features_ie_hdr {
4797 	uint8 oui[3];		/* Proprietary OUI, BRCM_PROP_OUI */
4798 	uint8 type;		/* type of this IE = 4 */
4799 	uint8 rate_mask;	/* VHT rate mask */
4800 } BWL_POST_PACKED_STRUCT;
4801 typedef struct vht_features_ie_hdr vht_features_ie_hdr_t;
4802 
4803 /* Def for rx & tx basic mcs maps - ea ss num has 2 bits of info */
4804 #define VHT_MCS_MAP_GET_SS_IDX(nss) (((nss)-1) * VHT_CAP_MCS_MAP_S)
4805 #define VHT_MCS_MAP_GET_MCS_PER_SS(nss, mcsMap) \
4806 	(((mcsMap) >> VHT_MCS_MAP_GET_SS_IDX(nss)) & VHT_CAP_MCS_MAP_M)
4807 #define VHT_MCS_MAP_SET_MCS_PER_SS(nss, numMcs, mcsMap) \
4808 	do { \
4809 	 (mcsMap) &= (~(VHT_CAP_MCS_MAP_M << VHT_MCS_MAP_GET_SS_IDX(nss))); \
4810 	 (mcsMap) |= (((numMcs) & VHT_CAP_MCS_MAP_M) << VHT_MCS_MAP_GET_SS_IDX(nss)); \
4811 	} while (0)
4812 #define VHT_MCS_SS_SUPPORTED(nss, mcsMap) \
4813 		 (VHT_MCS_MAP_GET_MCS_PER_SS((nss), (mcsMap)) != VHT_CAP_MCS_MAP_NONE)
4814 
4815 /* Get the max ss supported from the mcs map */
4816 #define VHT_MAX_SS_SUPPORTED(mcsMap) \
4817 	VHT_MCS_SS_SUPPORTED(8, mcsMap) ? 8 : \
4818 	VHT_MCS_SS_SUPPORTED(7, mcsMap) ? 7 : \
4819 	VHT_MCS_SS_SUPPORTED(6, mcsMap) ? 6 : \
4820 	VHT_MCS_SS_SUPPORTED(5, mcsMap) ? 5 : \
4821 	VHT_MCS_SS_SUPPORTED(4, mcsMap) ? 4 : \
4822 	VHT_MCS_SS_SUPPORTED(3, mcsMap) ? 3 : \
4823 	VHT_MCS_SS_SUPPORTED(2, mcsMap) ? 2 : \
4824 	VHT_MCS_SS_SUPPORTED(1, mcsMap) ? 1 : 0
4825 
4826 #ifdef IBSS_RMC
4827 /* customer's OUI */
4828 #define RMC_PROP_OUI		"\x00\x16\x32"
4829 #endif
4830 
4831 /* ************* WPA definitions. ************* */
4832 #define WPA_OUI			"\x00\x50\xF2"	/* WPA OUI */
4833 #define WPA_OUI_LEN		3		/* WPA OUI length */
4834 #define WPA_OUI_TYPE		1
4835 #define WPA_VERSION		1		/* WPA version */
4836 #define WPA_VERSION_LEN 2 /* WPA version length */
4837 
4838 /* ************* WPA2 definitions. ************* */
4839 #define WPA2_OUI		"\x00\x0F\xAC"	/* WPA2 OUI */
4840 #define WPA2_OUI_LEN		3		/* WPA2 OUI length */
4841 #define WPA2_VERSION		1		/* WPA2 version */
4842 #define WPA2_VERSION_LEN	2		/* WAP2 version length */
4843 #define MAX_RSNE_SUPPORTED_VERSION  WPA2_VERSION /* Max supported version */
4844 
4845 /* ************* WPS definitions. ************* */
4846 #define WPS_OUI			"\x00\x50\xF2"	/* WPS OUI */
4847 #define WPS_OUI_LEN		3		/* WPS OUI length */
4848 #define WPS_OUI_TYPE		4
4849 
4850 /* ************* TPC definitions. ************* */
4851 #define TPC_OUI			"\x00\x50\xF2"	/* TPC OUI */
4852 #define TPC_OUI_LEN		3		/* TPC OUI length */
4853 #define TPC_OUI_TYPE		8
4854 #define WFA_OUI_TYPE_TPC	8		/* deprecated */
4855 
4856 /* ************* WFA definitions. ************* */
4857 #define WFA_OUI			"\x50\x6F\x9A"  /* WFA OUI */
4858 #define WFA_OUI_LEN		3		/* WFA OUI length */
4859 #define WFA_OUI_TYPE_P2P	9
4860 
4861 /* WFA definitions for LEGACY P2P */
4862 #ifdef WL_LEGACY_P2P
4863 #define APPLE_OUI		"\x00\x17\xF2"	/* MACOSX OUI */
4864 #define APPLE_OUI_LEN		3
4865 #define APPLE_OUI_TYPE_P2P	5
4866 #endif /* WL_LEGACY_P2P */
4867 
4868 #ifndef WL_LEGACY_P2P
4869 #define P2P_OUI         WFA_OUI
4870 #define P2P_OUI_LEN     WFA_OUI_LEN
4871 #define P2P_OUI_TYPE    WFA_OUI_TYPE_P2P
4872 #else
4873 #define P2P_OUI         APPLE_OUI
4874 #define P2P_OUI_LEN     APPLE_OUI_LEN
4875 #define P2P_OUI_TYPE    APPLE_OUI_TYPE_P2P
4876 #endif /* !WL_LEGACY_P2P */
4877 
4878 #ifdef WLTDLS
4879 #define WFA_OUI_TYPE_TPQ	4	/* WFD Tunneled Probe ReQuest */
4880 #define WFA_OUI_TYPE_TPS	5	/* WFD Tunneled Probe ReSponse */
4881 #define WFA_OUI_TYPE_WFD	10
4882 #endif /* WTDLS */
4883 #define WFA_OUI_TYPE_HS20		0x10
4884 #define WFA_OUI_TYPE_OSEN		0x12
4885 #define WFA_OUI_TYPE_NAN		0x13
4886 #define WFA_OUI_TYPE_MBO		0x16
4887 #define WFA_OUI_TYPE_MBO_OCE		0x16
4888 #define WFA_OUI_TYPE_OWE		0x1C
4889 #define WFA_OUI_TYPE_SAE_PK		0x1F
4890 #define WFA_OUI_TYPE_TD_INDICATION	0x20
4891 
4892 #define SAE_PK_MOD_LEN		32u
4893 BWL_PRE_PACKED_STRUCT struct dot11_sae_pk_element {
4894 	uint8 id;			/* IE ID, 221, DOT11_MNG_PROPR_ID */
4895 	uint8 len;			/* IE length */
4896 	uint8 oui[WFA_OUI_LEN];		/* WFA_OUI */
4897 	uint8 type;			/* SAE-PK */
4898 	uint8 data[SAE_PK_MOD_LEN];	/* Modifier. 32Byte fixed */
4899 } BWL_POST_PACKED_STRUCT;
4900 typedef struct dot11_sae_pk_element dot11_sae_pk_element_t;
4901 
4902 /* RSN authenticated key managment suite */
4903 #define RSN_AKM_NONE			0	/* None (IBSS) */
4904 #define RSN_AKM_UNSPECIFIED		1	/* Over 802.1x */
4905 #define RSN_AKM_PSK			2	/* Pre-shared Key */
4906 #define RSN_AKM_FBT_1X			3	/* Fast Bss transition using 802.1X */
4907 #define RSN_AKM_FBT_PSK			4	/* Fast Bss transition using Pre-shared Key */
4908 /* RSN_AKM_MFP_1X and RSN_AKM_MFP_PSK are not used any more
4909  * Just kept here to avoid build issue in BISON/CARIBOU branch
4910  */
4911 #define RSN_AKM_MFP_1X			5	/* SHA256 key derivation, using 802.1X */
4912 #define RSN_AKM_MFP_PSK			6	/* SHA256 key derivation, using Pre-shared Key */
4913 #define RSN_AKM_SHA256_1X		5	/* SHA256 key derivation, using 802.1X */
4914 #define RSN_AKM_SHA256_PSK		6	/* SHA256 key derivation, using Pre-shared Key */
4915 #define RSN_AKM_TPK			7	/* TPK(TDLS Peer Key) handshake */
4916 #define RSN_AKM_SAE_PSK			8       /* AKM for SAE with 4-way handshake */
4917 #define RSN_AKM_SAE_FBT			9       /* AKM for SAE with FBT */
4918 #define RSN_AKM_SUITEB_SHA256_1X	11	/* Suite B SHA256 */
4919 #define RSN_AKM_SUITEB_SHA384_1X	12	/* Suite B-192 SHA384 */
4920 #define RSN_AKM_FBT_SHA384_1X		13	/* FBT SHA384 */
4921 #define RSN_AKM_FILS_SHA256		14	/* SHA256 key derivation, using FILS */
4922 #define RSN_AKM_FILS_SHA384		15	/* SHA384 key derivation, using FILS */
4923 #define RSN_AKM_FBT_SHA256_FILS		16
4924 #define RSN_AKM_FBT_SHA384_FILS		17
4925 #define RSN_AKM_OWE			18	/* RFC 8110  OWE */
4926 #define RSN_AKM_FBT_SHA384_PSK		19
4927 #define RSN_AKM_PSK_SHA384		20
4928 /* OSEN authenticated key managment suite */
4929 #define OSEN_AKM_UNSPECIFIED	RSN_AKM_UNSPECIFIED	/* Over 802.1x */
4930 /* WFA DPP RSN authenticated key managment */
4931 #define RSN_AKM_DPP			02u	/* DPP RSN */
4932 
4933 /* Key related defines */
4934 #define DOT11_MAX_DEFAULT_KEYS	4	/* number of default keys */
4935 #define DOT11_MAX_IGTK_KEYS		2
4936 #define DOT11_MAX_BIGTK_KEYS		2
4937 #define DOT11_MAX_KEY_SIZE	32	/* max size of any key */
4938 #define DOT11_MAX_IV_SIZE	16	/* max size of any IV */
4939 #define DOT11_EXT_IV_FLAG	(1<<5)	/* flag to indicate IV is > 4 bytes */
4940 #define DOT11_WPA_KEY_RSC_LEN   8       /* WPA RSC key len */
4941 
4942 #define WEP1_KEY_SIZE		5	/* max size of any WEP key */
4943 #define WEP1_KEY_HEX_SIZE	10	/* size of WEP key in hex. */
4944 #define WEP128_KEY_SIZE		13	/* max size of any WEP key */
4945 #define WEP128_KEY_HEX_SIZE	26	/* size of WEP key in hex. */
4946 #define TKIP_MIC_SIZE		8	/* size of TKIP MIC */
4947 #define TKIP_EOM_SIZE		7	/* max size of TKIP EOM */
4948 #define TKIP_EOM_FLAG		0x5a	/* TKIP EOM flag byte */
4949 #define TKIP_KEY_SIZE		32	/* size of any TKIP key, includs MIC keys */
4950 #define TKIP_TK_SIZE		16
4951 #define TKIP_MIC_KEY_SIZE	8
4952 #define TKIP_MIC_AUTH_TX	16	/* offset to Authenticator MIC TX key */
4953 #define TKIP_MIC_AUTH_RX	24	/* offset to Authenticator MIC RX key */
4954 #define TKIP_MIC_SUP_RX		TKIP_MIC_AUTH_TX	/* offset to Supplicant MIC RX key */
4955 #define TKIP_MIC_SUP_TX		TKIP_MIC_AUTH_RX	/* offset to Supplicant MIC TX key */
4956 #define AES_KEY_SIZE		16	/* size of AES key */
4957 #define AES_MIC_SIZE		8	/* size of AES MIC */
4958 #define BIP_KEY_SIZE		16	/* size of BIP key */
4959 #define BIP_MIC_SIZE		8   /* sizeof BIP MIC */
4960 
4961 #define AES_GCM_MIC_SIZE	16	/* size of MIC for 128-bit GCM - .11adD9 */
4962 
4963 #define AES256_KEY_SIZE		32	/* size of AES 256 key - .11acD5 */
4964 #define AES256_MIC_SIZE		16	/* size of MIC for 256 bit keys, incl BIP */
4965 
4966 /* WCN */
4967 #define WCN_OUI			"\x00\x50\xf2"	/* WCN OUI */
4968 #define WCN_TYPE		4	/* WCN type */
4969 
4970 #ifdef BCMWAPI_WPI
4971 #define SMS4_KEY_LEN		16
4972 #define SMS4_WPI_CBC_MAC_LEN	16
4973 #endif
4974 
4975 /* 802.11r protocol definitions */
4976 
4977 /** Mobility Domain IE */
4978 BWL_PRE_PACKED_STRUCT struct dot11_mdid_ie {
4979 	uint8 id;
4980 	uint8 len;		/* DOT11_MDID_IE_DATA_LEN (3) */
4981 	uint16 mdid;		/* Mobility Domain Id */
4982 	uint8 cap;
4983 } BWL_POST_PACKED_STRUCT;
4984 typedef struct dot11_mdid_ie dot11_mdid_ie_t;
4985 
4986 /* length of data portion of Mobility Domain IE */
4987 #define DOT11_MDID_IE_DATA_LEN	3
4988 #define DOT11_MDID_LEN		2
4989 #define FBT_MDID_CAP_OVERDS	0x01	/* Fast Bss transition over the DS support */
4990 #define FBT_MDID_CAP_RRP	0x02	/* Resource request protocol support */
4991 
4992 /* BITs in FTIE mic control field */
4993 #define DOT11_FTIE_RSNXE_USED	0x1u
4994 
4995 /* Fast Bss Transition IE */
4996 #ifdef FT_IE_VER_V2
4997 typedef BWL_PRE_PACKED_STRUCT struct dot11_ft_ie_v2 {
4998 	uint8 id;
4999 	uint8 len;
5000 	uint16 mic_control;
5001 	/* dynamic offset to following mic[], anonce[], snonce[] */
5002 } BWL_POST_PACKED_STRUCT dot11_ft_ie_v2;
5003 typedef struct dot11_ft_ie_v2 dot11_ft_ie_t;
5004 #else
5005 BWL_PRE_PACKED_STRUCT struct dot11_ft_ie {
5006 	uint8 id;
5007 	uint8 len;			/* At least equal to DOT11_FT_IE_FIXED_LEN (82) */
5008 	uint16 mic_control;		/* Mic Control */
5009 	uint8 mic[16];
5010 	uint8 anonce[32];
5011 	uint8 snonce[32];
5012 	/* Optional sub-elements follow */
5013 } BWL_POST_PACKED_STRUCT;
5014 typedef struct dot11_ft_ie dot11_ft_ie_t;
5015 
5016 /* Fixed length of data portion of Fast BSS Transition IE. There could be
5017  * optional parameters, which if present, could raise the FT IE length to 255.
5018  */
5019 #define DOT11_FT_IE_FIXED_LEN	82
5020 #endif /* FT_IE_VER_V2 */
5021 
5022 #ifdef FT_IE_VER_V2
5023 #define DOT11_FT_IE_LEN(mic_len) (sizeof(dot11_ft_ie_v2) + mic_len + EAPOL_WPA_KEY_NONCE_LEN *2)
5024 #define FT_IE_MIC(pos) ((uint8 *)pos + sizeof(dot11_ft_ie_v2))
5025 #define FT_IE_ANONCE(pos, mic_len) ((uint8 *)pos + sizeof(dot11_ft_ie_v2) + mic_len)
5026 #define FT_IE_SNONCE(pos, mic_len) ((uint8 *)pos + sizeof(dot11_ft_ie_v2) + mic_len + \
5027 	EAPOL_WPA_KEY_NONCE_LEN)
5028 #else
5029 #define DOT11_FT_IE_LEN(mic_len) sizeof(dot11_ft_ie)
5030 #define FT_IE_MIC(pos) ((uint8 *)&pos->mic)
5031 #define FT_IE_ANONCE(pos, mic_len) ((uint8 *)&pos->anonce)
5032 #define FT_IE_SNONCE(pos, mic_len) ((uint8 *)&pos->snonce)
5033 #endif /* FT_IE_VER_V2 */
5034 #define TIE_TYPE_RESERVED		0
5035 #define TIE_TYPE_REASSOC_DEADLINE	1
5036 #define TIE_TYPE_KEY_LIEFTIME		2
5037 #define TIE_TYPE_ASSOC_COMEBACK		3
5038 BWL_PRE_PACKED_STRUCT struct dot11_timeout_ie {
5039 	uint8 id;
5040 	uint8 len;
5041 	uint8 type;		/* timeout interval type */
5042 	uint32 value;		/* timeout interval value */
5043 } BWL_POST_PACKED_STRUCT;
5044 typedef struct dot11_timeout_ie dot11_timeout_ie_t;
5045 
5046 /** GTK ie */
5047 BWL_PRE_PACKED_STRUCT struct dot11_gtk_ie {
5048 	uint8 id;
5049 	uint8 len;
5050 	uint16 key_info;
5051 	uint8 key_len;
5052 	uint8 rsc[8];
5053 	uint8 data[1];
5054 } BWL_POST_PACKED_STRUCT;
5055 typedef struct dot11_gtk_ie dot11_gtk_ie_t;
5056 
5057 /** Management MIC ie */
5058 BWL_PRE_PACKED_STRUCT struct mmic_ie {
5059 	uint8   id;					/* IE ID: DOT11_MNG_MMIE_ID */
5060 	uint8   len;				/* IE length */
5061 	uint16  key_id;				/* key id */
5062 	uint8   ipn[6];				/* ipn */
5063 	uint8   mic[16];			/* mic */
5064 } BWL_POST_PACKED_STRUCT;
5065 typedef struct mmic_ie mmic_ie_t;
5066 
5067 #define DOT11_MMIC_IE_HDR_SIZE (OFFSETOF(mmic_ie_t, mic))
5068 
5069 /* 802.11r-2008, 11A.10.3 - RRB frame format */
5070 BWL_PRE_PACKED_STRUCT struct dot11_ft_rrb_frame {
5071 	uint8  frame_type; /* 1 for RRB */
5072 	uint8  packet_type; /* 0 for Request 1 for Response */
5073 	uint16 len;
5074 	uint8  cur_ap_addr[ETHER_ADDR_LEN];
5075 	uint8  data[1];	/* IEs Received/Sent in FT Action Req/Resp Frame */
5076 } BWL_POST_PACKED_STRUCT;
5077 
5078 typedef struct dot11_ft_rrb_frame dot11_ft_rrb_frame_t;
5079 
5080 #define DOT11_FT_RRB_FIXED_LEN 10
5081 #define DOT11_FT_REMOTE_FRAME_TYPE 1
5082 #define DOT11_FT_PACKET_REQ 0
5083 #define DOT11_FT_PACKET_RESP 1
5084 
5085 #define BSSID_INVALID           "\x00\x00\x00\x00\x00\x00"
5086 #define BSSID_BROADCAST         "\xFF\xFF\xFF\xFF\xFF\xFF"
5087 
5088 #ifdef BCMWAPI_WAI
5089 #define WAPI_IE_MIN_LEN		20	/* WAPI IE min length */
5090 #define WAPI_VERSION		1	/* WAPI version */
5091 #define WAPI_VERSION_LEN	2	/* WAPI version length */
5092 #define WAPI_OUI		"\x00\x14\x72"	/* WAPI OUI */
5093 #define WAPI_OUI_LEN		DOT11_OUI_LEN	/* WAPI OUI length */
5094 #endif /* BCMWAPI_WAI */
5095 
5096 /* ************* WMM Parameter definitions. ************* */
5097 #define WMM_OUI			"\x00\x50\xF2"	/* WNN OUI */
5098 #define WMM_OUI_LEN		3		/* WMM OUI length */
5099 #define WMM_OUI_TYPE	2		/* WMM OUT type */
5100 #define WMM_VERSION		1
5101 #define WMM_VERSION_LEN	1
5102 
5103 /* WMM OUI subtype */
5104 #define WMM_OUI_SUBTYPE_PARAMETER	1
5105 #define WMM_PARAMETER_IE_LEN		24
5106 
5107 /** Link Identifier Element */
5108 BWL_PRE_PACKED_STRUCT struct link_id_ie {
5109 	uint8 id;
5110 	uint8 len;
5111 	struct ether_addr	bssid;
5112 	struct ether_addr	tdls_init_mac;
5113 	struct ether_addr	tdls_resp_mac;
5114 } BWL_POST_PACKED_STRUCT;
5115 typedef struct link_id_ie link_id_ie_t;
5116 #define TDLS_LINK_ID_IE_LEN		18u
5117 
5118 /** Link Wakeup Schedule Element */
5119 BWL_PRE_PACKED_STRUCT struct wakeup_sch_ie {
5120 	uint8 id;
5121 	uint8 len;
5122 	uint32 offset;			/* in ms between TSF0 and start of 1st Awake Window */
5123 	uint32 interval;		/* in ms bwtween the start of 2 Awake Windows */
5124 	uint32 awake_win_slots;	/* in backof slots, duration of Awake Window */
5125 	uint32 max_wake_win;	/* in ms, max duration of Awake Window */
5126 	uint16 idle_cnt;		/* number of consecutive Awake Windows */
5127 } BWL_POST_PACKED_STRUCT;
5128 typedef struct wakeup_sch_ie wakeup_sch_ie_t;
5129 #define TDLS_WAKEUP_SCH_IE_LEN		18
5130 
5131 /** Channel Switch Timing Element */
5132 BWL_PRE_PACKED_STRUCT struct channel_switch_timing_ie {
5133 	uint8 id;
5134 	uint8 len;
5135 	uint16 switch_time;		/* in ms, time to switch channels */
5136 	uint16 switch_timeout;	/* in ms */
5137 } BWL_POST_PACKED_STRUCT;
5138 typedef struct channel_switch_timing_ie channel_switch_timing_ie_t;
5139 #define TDLS_CHANNEL_SWITCH_TIMING_IE_LEN		4
5140 
5141 /** PTI Control Element */
5142 BWL_PRE_PACKED_STRUCT struct pti_control_ie {
5143 	uint8 id;
5144 	uint8 len;
5145 	uint8 tid;
5146 	uint16 seq_control;
5147 } BWL_POST_PACKED_STRUCT;
5148 typedef struct pti_control_ie pti_control_ie_t;
5149 #define TDLS_PTI_CONTROL_IE_LEN		3
5150 
5151 /** PU Buffer Status Element */
5152 BWL_PRE_PACKED_STRUCT struct pu_buffer_status_ie {
5153 	uint8 id;
5154 	uint8 len;
5155 	uint8 status;
5156 } BWL_POST_PACKED_STRUCT;
5157 typedef struct pu_buffer_status_ie pu_buffer_status_ie_t;
5158 #define TDLS_PU_BUFFER_STATUS_IE_LEN	1
5159 #define TDLS_PU_BUFFER_STATUS_AC_BK		1
5160 #define TDLS_PU_BUFFER_STATUS_AC_BE		2
5161 #define TDLS_PU_BUFFER_STATUS_AC_VI		4
5162 #define TDLS_PU_BUFFER_STATUS_AC_VO		8
5163 
5164 /* TDLS Action Field Values */
5165 #define TDLS_SETUP_REQ				0
5166 #define TDLS_SETUP_RESP				1
5167 #define TDLS_SETUP_CONFIRM			2
5168 #define TDLS_TEARDOWN				3
5169 #define TDLS_PEER_TRAFFIC_IND			4
5170 #define TDLS_CHANNEL_SWITCH_REQ			5
5171 #define TDLS_CHANNEL_SWITCH_RESP		6
5172 #define TDLS_PEER_PSM_REQ			7
5173 #define TDLS_PEER_PSM_RESP			8
5174 #define TDLS_PEER_TRAFFIC_RESP			9
5175 #define TDLS_DISCOVERY_REQ			10
5176 
5177 /* 802.11z TDLS Public Action Frame action field */
5178 #define TDLS_DISCOVERY_RESP			14
5179 
5180 /* 802.11u GAS action frames */
5181 #define GAS_REQUEST_ACTION_FRAME				10
5182 #define GAS_RESPONSE_ACTION_FRAME				11
5183 #define GAS_COMEBACK_REQUEST_ACTION_FRAME		12
5184 #define GAS_COMEBACK_RESPONSE_ACTION_FRAME		13
5185 
5186 /* FTM - fine timing measurement public action frames */
5187 BWL_PRE_PACKED_STRUCT struct dot11_ftm_req {
5188 	uint8 category;				/* category of action frame (4) */
5189 	uint8 action;				/* public action (32) */
5190 	uint8 trigger;				/* trigger/continue? */
5191 	/* optional lci, civic loc, ftm params */
5192 } BWL_POST_PACKED_STRUCT;
5193 typedef struct dot11_ftm_req dot11_ftm_req_t;
5194 
5195 BWL_PRE_PACKED_STRUCT struct dot11_ftm {
5196 	uint8 category;				/* category of action frame (4) */
5197 	uint8 action;				/* public action (33) */
5198 	uint8 dialog;				/* dialog token */
5199 	uint8 follow_up;			/* follow up dialog token */
5200 	uint8 tod[6];				/* t1 - last depart timestamp */
5201 	uint8 toa[6];				/* t4 - last ack arrival timestamp */
5202 	uint8 tod_err[2];			/* t1 error */
5203 	uint8 toa_err[2];			/* t4 error */
5204 	/* optional lci report, civic loc report, ftm params */
5205 } BWL_POST_PACKED_STRUCT;
5206 typedef struct dot11_ftm dot11_ftm_t;
5207 
5208 BWL_PRE_PACKED_STRUCT struct dot11_ftm_lmr {
5209 	uint8    category;          /* category of action frame (4) */
5210 	uint8    action;            /* public action (33) */
5211 	uint8    dialog;            /* dialog token */
5212 	uint8    tod[6];            /* RSTA t3 or ISTA t1:
5213 	                             * last departure of NDP
5214 	                             */
5215 	uint8    toa[6];            /* RSTA t2 or ISTA t4:
5216 	                             * last arrival of NDP
5217 	                             */
5218 	uint8    tod_err[2];        /* t3 or t1 error */
5219 	uint8    toa_err[2];        /* t2 or t4 error */
5220 	uint16   cfo;               /* I2R LMR: clock difference between ISTA and RSTA. */
5221 	uint8    sec_ltf_params[];  /* Optional Secure LTF parameters */
5222 	/* no AOA feedback */
5223 } BWL_POST_PACKED_STRUCT;
5224 typedef struct dot11_ftm_lmr dot11_ftm_lmr_t;
5225 
5226 BWL_PRE_PACKED_STRUCT struct dot11_ftm_ranging_ndpa {
5227 	uint16			fc;		/* frame control */
5228 	uint16			durid;		/* duration/ID */
5229 	struct ether_addr	ra;		/* receiver address */
5230 	struct ether_addr	ta;		/* transmitter address */
5231 	uint8           dialog_token; /* sounding dialog token */
5232 } BWL_POST_PACKED_STRUCT;
5233 typedef struct dot11_ftm_ranging_ndpa dot11_ftm_ranging_ndpa_t;
5234 
5235 /* NDPA types = dialog token byte lower 2 bits */
5236 #define DOT11_NDPA_TYPE_MASK     0x03
5237 #define DOT11_NDPA_TYPE_VHT      0x00
5238 #define DOT11_NDPA_TYPE_RANGING  0x01
5239 #define DOT11_NDPA_TYPE_HE       0x02
5240 
5241 #define DOT11_FTM_ERR_NOT_CONT_OFFSET 1
5242 #define DOT11_FTM_ERR_NOT_CONT_MASK 0x80
5243 #define DOT11_FTM_ERR_NOT_CONT_SHIFT 7
5244 #define DOT11_FTM_ERR_NOT_CONT(_err) (((_err)[DOT11_FTM_ERR_NOT_CONT_OFFSET] & \
5245 	DOT11_FTM_ERR_NOT_CONT_MASK) >> DOT11_FTM_ERR_NOT_CONT_SHIFT)
5246 #define DOT11_FTM_ERR_SET_NOT_CONT(_err, _val) do {\
5247 	uint8 _err2 = (_err)[DOT11_FTM_ERR_NOT_CONT_OFFSET]; \
5248 	_err2 &= ~DOT11_FTM_ERR_NOT_CONT_MASK; \
5249 	_err2 |= ((_val) << DOT11_FTM_ERR_NOT_CONT_SHIFT) & DOT11_FTM_ERR_NOT_CONT_MASK; \
5250 	(_err)[DOT11_FTM_ERR_NOT_CONT_OFFSET] = _err2; \
5251 } while (0)
5252 
5253 #define DOT11_FTM_ERR_MAX_ERR_OFFSET 0
5254 #define DOT11_FTM_ERR_MAX_ERR_MASK 0x7fff
5255 #define DOT11_FTM_ERR_MAX_ERR_SHIFT 0
5256 #define DOT11_FTM_ERR_MAX_ERR(_err) (((((_err)[1] & 0x7f) << 8) | (_err)[0]))
5257 #define DOT11_FTM_ERR_SET_MAX_ERR(_err, _val) do {\
5258 	uint16 _val2; \
5259 	uint16 _not_cont; \
5260 	_val2 =  (((_val) & DOT11_FTM_ERR_MAX_ERR_MASK) << DOT11_FTM_ERR_MAX_ERR_SHIFT); \
5261 	_val2 = (_val2 > 0x3fff) ? 0 : _val2; /* not expecting > 16ns error */ \
5262 	_not_cont = DOT11_FTM_ERR_NOT_CONT(_err); \
5263 	(_err)[0] = _val2 & 0xff; \
5264 	(_err)[1] = (_val2 >> 8) & 0xff; \
5265 	DOT11_FTM_ERR_SET_NOT_CONT(_err, _not_cont); \
5266 } while (0)
5267 
5268 #if defined(DOT11_FTM_ERR_ROM_COMPAT)
5269 /* incorrect defs - here for ROM compatibiity */
5270 #undef DOT11_FTM_ERR_NOT_CONT_OFFSET
5271 #undef DOT11_FTM_ERR_NOT_CONT_MASK
5272 #undef DOT11_FTM_ERR_NOT_CONT_SHIFT
5273 #undef DOT11_FTM_ERR_NOT_CONT
5274 #undef DOT11_FTM_ERR_SET_NOT_CONT
5275 
5276 #define DOT11_FTM_ERR_NOT_CONT_OFFSET 0
5277 #define DOT11_FTM_ERR_NOT_CONT_MASK 0x0001
5278 #define DOT11_FTM_ERR_NOT_CONT_SHIFT 0
5279 #define DOT11_FTM_ERR_NOT_CONT(_err) (((_err)[DOT11_FTM_ERR_NOT_CONT_OFFSET] & \
5280 	DOT11_FTM_ERR_NOT_CONT_MASK) >> DOT11_FTM_ERR_NOT_CONT_SHIFT)
5281 #define DOT11_FTM_ERR_SET_NOT_CONT(_err, _val) do {\
5282 	uint8 _err2 = (_err)[DOT11_FTM_ERR_NOT_CONT_OFFSET]; \
5283 	_err2 &= ~DOT11_FTM_ERR_NOT_CONT_MASK; \
5284 	_err2 |= ((_val) << DOT11_FTM_ERR_NOT_CONT_SHIFT) & DOT11_FTM_ERR_NOT_CONT_MASK; \
5285 	(_err)[DOT11_FTM_ERR_NOT_CONT_OFFSET] = _err2; \
5286 } while (0)
5287 
5288 #undef DOT11_FTM_ERR_MAX_ERR_OFFSET
5289 #undef DOT11_FTM_ERR_MAX_ERR_MASK
5290 #undef DOT11_FTM_ERR_MAX_ERR_SHIFT
5291 #undef DOT11_FTM_ERR_MAX_ERR
5292 #undef DOT11_FTM_ERR_SET_MAX_ERR
5293 
5294 #define DOT11_FTM_ERR_MAX_ERR_OFFSET 0
5295 #define DOT11_FTM_ERR_MAX_ERR_MASK 0xfff7
5296 #define DOT11_FTM_ERR_MAX_ERR_SHIFT 1
5297 #define DOT11_FTM_ERR_MAX_ERR(_err) ((((_err)[1] << 7) | (_err)[0]) >> 1)
5298 #define DOT11_FTM_ERR_SET_MAX_ERR(_err, _val) do {\
5299 	uint16 _val2; \
5300 	_val2 =  (((_val) << DOT11_FTM_ERR_MAX_ERR_SHIFT) |\
5301 		 ((_err)[DOT11_FTM_ERR_NOT_CONT_OFFSET] & DOT11_FTM_ERR_NOT_CONT_MASK)); \
5302 	(_err)[0] = _val2 & 0xff; \
5303 	(_err)[1] = _val2 >> 8 & 0xff; \
5304 } while (0)
5305 #endif /* DOT11_FTM_ERR_ROM_COMPAT */
5306 
5307 BWL_PRE_PACKED_STRUCT struct dot11_ftm_params {
5308 	uint8 id;		/* DOT11_MNG_FTM_PARAM_ID 8.4.2.166 11mcd2.6/2014 - revisit */
5309 	uint8 len;
5310 	uint8 info[9];
5311 } BWL_POST_PACKED_STRUCT;
5312 
5313 typedef struct dot11_ftm_params dot11_ftm_params_t;
5314 #define DOT11_FTM_PARAMS_IE_LEN (sizeof(dot11_ftm_params_t) - 2)
5315 
5316 /* common part for both TB and NTB */
5317 BWL_PRE_PACKED_STRUCT struct dot11_ftm_ranging_params {
5318 	uint8 id; /* 255 */
5319 	uint8 len;
5320 	uint8 ext_id; /* DOT11_MNG_FTM_RANGING_EXT_ID */
5321 	uint8 info[6];
5322 } BWL_POST_PACKED_STRUCT;
5323 typedef struct dot11_ftm_ranging_params dot11_ftm_ranging_params_t;
5324 #define DOT11_FTM_CMN_RANGING_PARAMS_IE_LEN (sizeof(dot11_ftm_ranging_params_t) - TLV_EXT_HDR_LEN)
5325 
5326 /* FTM NTB specific */
5327 BWL_PRE_PACKED_STRUCT struct dot11_ftm_ntb_params {
5328 	uint8 id; /* DOT11_FTM_NTB_SUB_ELT_ID */
5329 	uint8 len;
5330 	uint8 info[6];
5331 } BWL_POST_PACKED_STRUCT;
5332 typedef struct dot11_ftm_ntb_params dot11_ftm_ntb_params_t;
5333 
5334 #define DOT11_FTM_NTB_PARAMS_SUB_IE_LEN (sizeof(dot11_ftm_ntb_params_t))
5335 #define DOT11_FTM_NTB_PARAMS_IE_LEN DOT11_FTM_CMN_RANGING_PARAMS_IE_LEN + \
5336 	DOT11_FTM_NTB_PARAMS_SUB_IE_LEN
5337 
5338 /* FTM TB specific */
5339 BWL_PRE_PACKED_STRUCT struct dot11_ftm_tb_params {
5340 	uint8 id; /* DOT11_FTM_TB_SUB_ELT_ID */
5341 	uint8 len;
5342 	uint8 info[1]; /* variable length, minimum 1 */
5343 } BWL_POST_PACKED_STRUCT;
5344 
5345 typedef struct dot11_ftm_tb_params dot11_ftm_tb_params_t;
5346 #define DOT11_FTM_TB_PARAMS_IE_LEN sizeof(dot11_ftm_tb_params_t)
5347 
5348 BWL_PRE_PACKED_STRUCT struct dot11_ftm_sec_ltf_params {
5349 	uint8 id; /* 255 */
5350 	uint8 len;
5351 	uint8 ext_id; /* DOT11_MNG_FTM_SECURE_LTF_EXT_ID */
5352 	uint8 info[11];
5353 } BWL_POST_PACKED_STRUCT;
5354 typedef struct dot11_ftm_sec_ltf_params dot11_ftm_sec_ltf_params_t;
5355 #define DOT11_FTM_SEC_LTF_PARAMS_IE_LEN (sizeof(dot11_ftm_sec_ltf_params_t) - 3)
5356 
5357 #define FTM_PARAMS_FIELD(_p, _off, _mask, _shift) (((_p)->info[(_off)] & (_mask)) >> (_shift))
5358 #define FTM_PARAMS_SET_FIELD(_p, _off, _mask, _shift, _val) do {\
5359 	uint8 _ptmp = (_p)->info[_off] & ~(_mask); \
5360 	(_p)->info[(_off)] = _ptmp | (((_val) << (_shift)) & (_mask)); \
5361 } while (0)
5362 
5363 #define FTM_PARAMS_STATUS_OFFSET 0
5364 #define FTM_PARAMS_STATUS_MASK 0x03
5365 #define FTM_PARAMS_STATUS_SHIFT 0
5366 #define FTM_PARAMS_STATUS(_p) FTM_PARAMS_FIELD(_p, FTM_PARAMS_STATUS_OFFSET, \
5367 	FTM_PARAMS_STATUS_MASK, FTM_PARAMS_STATUS_SHIFT)
5368 #define FTM_PARAMS_SET_STATUS(_p, _status) FTM_PARAMS_SET_FIELD(_p, \
5369 	FTM_PARAMS_STATUS_OFFSET, FTM_PARAMS_STATUS_MASK, FTM_PARAMS_STATUS_SHIFT, _status)
5370 
5371 #define FTM_PARAMS_VALUE_OFFSET 0
5372 #define FTM_PARAMS_VALUE_MASK 0x7c
5373 #define FTM_PARAMS_VALUE_SHIFT 2
5374 #define FTM_PARAMS_VALUE(_p) FTM_PARAMS_FIELD(_p, FTM_PARAMS_VALUE_OFFSET, \
5375 	FTM_PARAMS_VALUE_MASK, FTM_PARAMS_VALUE_SHIFT)
5376 #define FTM_PARAMS_SET_VALUE(_p, _value) FTM_PARAMS_SET_FIELD(_p, \
5377 	FTM_PARAMS_VALUE_OFFSET, FTM_PARAMS_VALUE_MASK, FTM_PARAMS_VALUE_SHIFT, _value)
5378 #define FTM_PARAMS_MAX_VALUE 32
5379 
5380 #define FTM_PARAMS_NBURSTEXP_OFFSET 1
5381 #define FTM_PARAMS_NBURSTEXP_MASK 0x0f
5382 #define FTM_PARAMS_NBURSTEXP_SHIFT 0
5383 #define FTM_PARAMS_NBURSTEXP(_p) FTM_PARAMS_FIELD(_p, FTM_PARAMS_NBURSTEXP_OFFSET, \
5384 	FTM_PARAMS_NBURSTEXP_MASK, FTM_PARAMS_NBURSTEXP_SHIFT)
5385 #define FTM_PARAMS_SET_NBURSTEXP(_p, _bexp) FTM_PARAMS_SET_FIELD(_p, \
5386 	FTM_PARAMS_NBURSTEXP_OFFSET, FTM_PARAMS_NBURSTEXP_MASK, FTM_PARAMS_NBURSTEXP_SHIFT, \
5387 	_bexp)
5388 
5389 #define FTM_PARAMS_NBURST(_p) (1 << FTM_PARAMS_NBURSTEXP(_p))
5390 
5391 enum {
5392 	FTM_PARAMS_NBURSTEXP_NOPREF = 15
5393 };
5394 
5395 enum {
5396 	FTM_PARAMS_BURSTTMO_NOPREF = 15
5397 };
5398 
5399 #define FTM_PARAMS_BURSTTMO_OFFSET 1
5400 #define FTM_PARAMS_BURSTTMO_MASK 0xf0
5401 #define FTM_PARAMS_BURSTTMO_SHIFT 4
5402 #define FTM_PARAMS_BURSTTMO(_p) FTM_PARAMS_FIELD(_p, FTM_PARAMS_BURSTTMO_OFFSET, \
5403 	FTM_PARAMS_BURSTTMO_MASK, FTM_PARAMS_BURSTTMO_SHIFT)
5404 /* set timeout in params using _tmo where timeout = 2^(_tmo) * 250us */
5405 #define FTM_PARAMS_SET_BURSTTMO(_p, _tmo) FTM_PARAMS_SET_FIELD(_p, \
5406 	FTM_PARAMS_BURSTTMO_OFFSET, FTM_PARAMS_BURSTTMO_MASK, FTM_PARAMS_BURSTTMO_SHIFT, (_tmo)+2)
5407 
5408 #define FTM_PARAMS_BURSTTMO_USEC(_val) ((1 << ((_val)-2)) * 250)
5409 #define FTM_PARAMS_BURSTTMO_VALID(_val) ((((_val) < 12 && (_val) > 1)) || \
5410 	(_val) == FTM_PARAMS_BURSTTMO_NOPREF)
5411 #define FTM_PARAMS_BURSTTMO_MAX_MSEC 128 /* 2^9 * 250us */
5412 #define FTM_PARAMS_BURSTTMO_MAX_USEC 128000 /* 2^9 * 250us */
5413 
5414 #define FTM_PARAMS_MINDELTA_OFFSET 2
5415 #define FTM_PARAMS_MINDELTA_USEC(_p) ((_p)->info[FTM_PARAMS_MINDELTA_OFFSET] * 100)
5416 #define FTM_PARAMS_SET_MINDELTA_USEC(_p, _delta) do { \
5417 	(_p)->info[FTM_PARAMS_MINDELTA_OFFSET] = (_delta) / 100; \
5418 } while (0)
5419 
5420 enum {
5421 	FTM_PARAMS_MINDELTA_NOPREF = 0
5422 };
5423 
5424 #define FTM_PARAMS_PARTIAL_TSF(_p) ((_p)->info[4] << 8 | (_p)->info[3])
5425 #define FTM_PARAMS_SET_PARTIAL_TSF(_p, _partial_tsf) do { \
5426 	(_p)->info[3] = (_partial_tsf) & 0xff; \
5427 	(_p)->info[4] = ((_partial_tsf) >> 8) & 0xff; \
5428 } while (0)
5429 
5430 #define FTM_PARAMS_PARTIAL_TSF_MASK 0x0000000003fffc00ULL
5431 #define FTM_PARAMS_PARTIAL_TSF_SHIFT 10
5432 #define FTM_PARAMS_PARTIAL_TSF_BIT_LEN 16
5433 #define FTM_PARAMS_PARTIAL_TSF_MAX 0xffff
5434 
5435 /* FTM can indicate upto 62k TUs forward and 1k TU backward */
5436 #define FTM_PARAMS_TSF_FW_HI (63487 << 10)	/* in micro sec */
5437 #define FTM_PARAMS_TSF_BW_LOW (64512 << 10)	/* in micro sec */
5438 #define FTM_PARAMS_TSF_BW_HI (65535 << 10)	/* in micro sec */
5439 #define FTM_PARAMS_TSF_FW_MAX FTM_PARAMS_TSF_FW_HI
5440 #define FTM_PARAMS_TSF_BW_MAX (FTM_PARAMS_TSF_BW_HI - FTM_PARAMS_TSF_BW_LOW)
5441 
5442 #define FTM_PARAMS_PTSFNOPREF_OFFSET 5
5443 #define FTM_PARAMS_PTSFNOPREF_MASK 0x1
5444 #define FTM_PARAMS_PTSFNOPREF_SHIFT 0
5445 #define FTM_PARAMS_PTSFNOPREF(_p) FTM_PARAMS_FIELD(_p, FTM_PARAMS_PTSFNOPREF_OFFSET, \
5446 	FTM_PARAMS_PTSFNOPREF_MASK, FTM_PARAMS_PTSFNOPREF_SHIFT)
5447 #define FTM_PARAMS_SET_PTSFNOPREF(_p, _nopref) FTM_PARAMS_SET_FIELD(_p, \
5448 	FTM_PARAMS_PTSFNOPREF_OFFSET, FTM_PARAMS_PTSFNOPREF_MASK, \
5449 	FTM_PARAMS_PTSFNOPREF_SHIFT, _nopref)
5450 
5451 #define FTM_PARAMS_ASAP_OFFSET 5
5452 #define FTM_PARAMS_ASAP_MASK 0x4
5453 #define FTM_PARAMS_ASAP_SHIFT 2
5454 #define FTM_PARAMS_ASAP(_p) FTM_PARAMS_FIELD(_p, FTM_PARAMS_ASAP_OFFSET, \
5455 	FTM_PARAMS_ASAP_MASK, FTM_PARAMS_ASAP_SHIFT)
5456 #define FTM_PARAMS_SET_ASAP(_p, _asap) FTM_PARAMS_SET_FIELD(_p, \
5457 	FTM_PARAMS_ASAP_OFFSET, FTM_PARAMS_ASAP_MASK, FTM_PARAMS_ASAP_SHIFT, _asap)
5458 
5459 /* FTM1 - AKA ASAP Capable */
5460 #define FTM_PARAMS_FTM1_OFFSET 5
5461 #define FTM_PARAMS_FTM1_MASK 0x02
5462 #define FTM_PARAMS_FTM1_SHIFT 1
5463 #define FTM_PARAMS_FTM1(_p) FTM_PARAMS_FIELD(_p, FTM_PARAMS_FTM1_OFFSET, \
5464 	FTM_PARAMS_FTM1_MASK, FTM_PARAMS_FTM1_SHIFT)
5465 #define FTM_PARAMS_SET_FTM1(_p, _ftm1) FTM_PARAMS_SET_FIELD(_p, \
5466 	FTM_PARAMS_FTM1_OFFSET, FTM_PARAMS_FTM1_MASK, FTM_PARAMS_FTM1_SHIFT, _ftm1)
5467 
5468 #define FTM_PARAMS_FTMS_PER_BURST_OFFSET 5
5469 #define FTM_PARAMS_FTMS_PER_BURST_MASK 0xf8
5470 #define FTM_PARAMS_FTMS_PER_BURST_SHIFT 3
5471 #define FTM_PARAMS_FTMS_PER_BURST(_p) FTM_PARAMS_FIELD(_p, FTM_PARAMS_FTMS_PER_BURST_OFFSET, \
5472 	FTM_PARAMS_FTMS_PER_BURST_MASK, FTM_PARAMS_FTMS_PER_BURST_SHIFT)
5473 #define FTM_PARAMS_SET_FTMS_PER_BURST(_p, _nftms) FTM_PARAMS_SET_FIELD(_p, \
5474 	FTM_PARAMS_FTMS_PER_BURST_OFFSET, FTM_PARAMS_FTMS_PER_BURST_MASK, \
5475 	FTM_PARAMS_FTMS_PER_BURST_SHIFT, _nftms)
5476 
5477 enum {
5478 	FTM_PARAMS_FTMS_PER_BURST_NOPREF = 0
5479 };
5480 
5481 #define FTM_PARAMS_CHAN_INFO_OFFSET 6
5482 #define FTM_PARAMS_CHAN_INFO_MASK 0xfc
5483 #define FTM_PARAMS_CHAN_INFO_SHIFT 2
5484 #define FTM_PARAMS_CHAN_INFO(_p) FTM_PARAMS_FIELD(_p, FTM_PARAMS_CHAN_INFO_OFFSET, \
5485 	FTM_PARAMS_CHAN_INFO_MASK, FTM_PARAMS_CHAN_INFO_SHIFT)
5486 #define FTM_PARAMS_SET_CHAN_INFO(_p, _ci) FTM_PARAMS_SET_FIELD(_p, \
5487 	FTM_PARAMS_CHAN_INFO_OFFSET, FTM_PARAMS_CHAN_INFO_MASK, FTM_PARAMS_CHAN_INFO_SHIFT, _ci)
5488 
5489 /* burst period - units of 100ms */
5490 #define FTM_PARAMS_BURST_PERIOD(_p) (((_p)->info[8] << 8) | (_p)->info[7])
5491 #define FTM_PARAMS_SET_BURST_PERIOD(_p, _bp) do {\
5492 	(_p)->info[7] = (_bp) & 0xff; \
5493 	(_p)->info[8] = ((_bp) >> 8) & 0xff; \
5494 } while (0)
5495 
5496 #define FTM_PARAMS_BURST_PERIOD_MS(_p) (FTM_PARAMS_BURST_PERIOD(_p) * 100)
5497 
5498 enum {
5499 	FTM_PARAMS_BURST_PERIOD_NOPREF = 0
5500 };
5501 
5502 /* FTM status values - last updated from 11mcD4.0 */
5503 enum {
5504 	FTM_PARAMS_STATUS_RESERVED	= 0,
5505 	FTM_PARAMS_STATUS_SUCCESSFUL = 1,
5506 	FTM_PARAMS_STATUS_INCAPABLE = 2,
5507 	FTM_PARAMS_STATUS_FAILED = 3,
5508 	/* Below are obsolte */
5509 	FTM_PARAMS_STATUS_OVERRIDDEN = 4,
5510 	FTM_PARAMS_STATUS_ASAP_INCAPABLE = 5,
5511 	FTM_PARAMS_STATUS_ASAP_FAILED = 6,
5512 	/* rest are reserved */
5513 };
5514 
5515 enum {
5516 	FTM_PARAMS_CHAN_INFO_NO_PREF		= 0,
5517 	FTM_PARAMS_CHAN_INFO_RESERVE1		= 1,
5518 	FTM_PARAMS_CHAN_INFO_RESERVE2		= 2,
5519 	FTM_PARAMS_CHAN_INFO_RESERVE3		= 3,
5520 	FTM_PARAMS_CHAN_INFO_NON_HT_5		= 4,
5521 	FTM_PARAMS_CHAN_INFO_RESERVE5		= 5,
5522 	FTM_PARAMS_CHAN_INFO_NON_HT_10		= 6,
5523 	FTM_PARAMS_CHAN_INFO_RESERVE7		= 7,
5524 	FTM_PARAMS_CHAN_INFO_NON_HT_20		= 8, /* excludes 2.4G, and High rate DSSS */
5525 	FTM_PARAMS_CHAN_INFO_HT_MF_20		= 9,
5526 	FTM_PARAMS_CHAN_INFO_VHT_20		= 10,
5527 	FTM_PARAMS_CHAN_INFO_HT_MF_40		= 11,
5528 	FTM_PARAMS_CHAN_INFO_VHT_40		= 12,
5529 	FTM_PARAMS_CHAN_INFO_VHT_80		= 13,
5530 	FTM_PARAMS_CHAN_INFO_VHT_80_80		= 14,
5531 	FTM_PARAMS_CHAN_INFO_VHT_160_2_RFLOS	= 15,
5532 	FTM_PARAMS_CHAN_INFO_VHT_160		= 16,
5533 	/* Reserved from 17 - 30 */
5534 	FTM_PARAMS_CHAN_INFO_DMG_2160		= 31,
5535 	/* Reserved from 32 - 63 */
5536 	FTM_PARAMS_CHAN_INFO_MAX		= 63
5537 };
5538 
5539 /* tag_ID/length/value_buffer tuple */
5540 typedef BWL_PRE_PACKED_STRUCT struct {
5541 	uint8	id;
5542 	uint8	len;
5543 	uint8	data[1];
5544 } BWL_POST_PACKED_STRUCT ftm_vs_tlv_t;
5545 
5546 BWL_PRE_PACKED_STRUCT struct dot11_ftm_vs_ie {
5547 	uint8 id;						/* DOT11_MNG_VS_ID */
5548 	uint8 len;						/* length following */
5549 	uint8 oui[3];					/* BRCM_PROP_OUI (or Customer) */
5550 	uint8 sub_type;					/* BRCM_FTM_IE_TYPE (or Customer) */
5551 	uint8 version;
5552 	ftm_vs_tlv_t	tlvs[1];
5553 } BWL_POST_PACKED_STRUCT;
5554 typedef struct dot11_ftm_vs_ie dot11_ftm_vs_ie_t;
5555 
5556 /* same as payload of dot11_ftm_vs_ie.
5557 * This definition helps in having struct access
5558 * of pay load while building FTM VS IE from other modules(NAN)
5559 */
5560 BWL_PRE_PACKED_STRUCT struct dot11_ftm_vs_ie_pyld {
5561 	uint8 sub_type;					/* BRCM_FTM_IE_TYPE (or Customer) */
5562 	uint8 version;
5563 	ftm_vs_tlv_t	tlvs[1];
5564 } BWL_POST_PACKED_STRUCT;
5565 typedef struct dot11_ftm_vs_ie_pyld dot11_ftm_vs_ie_pyld_t;
5566 
5567 /* ftm vs api version */
5568 #define BCM_FTM_VS_PARAMS_VERSION 0x01
5569 
5570 /* ftm vendor specific information tlv types */
5571 enum {
5572 	FTM_VS_TLV_NONE = 0,
5573 	FTM_VS_TLV_REQ_PARAMS = 1,		/* additional request params (in FTM_REQ) */
5574 	FTM_VS_TLV_MEAS_INFO = 2,		/* measurement information (in FTM_MEAS) */
5575 	FTM_VS_TLV_SEC_PARAMS = 3,		/* security parameters (in either) */
5576 	FTM_VS_TLV_SEQ_PARAMS = 4,		/* toast parameters (FTM_REQ, BRCM proprietary) */
5577 	FTM_VS_TLV_MF_BUF = 5,			/* multi frame buffer - may span ftm vs ie's */
5578 	FTM_VS_TLV_TIMING_PARAMS = 6,            /* timing adjustments */
5579 	FTM_VS_TLV_MF_STATS_BUF = 7		/* multi frame statistics buffer */
5580 	/* add additional types above */
5581 };
5582 
5583 /* the following definitions are *DEPRECATED* and moved to implementation files. They
5584  * are retained here because previous (May 2016) some branches use them
5585  */
5586 #define FTM_TPK_LEN				16u
5587 #define FTM_RI_RR_BUF_LEN			32u
5588 #define FTM_TPK_RI_RR_LEN			13
5589 #define FTM_TPK_RI_RR_LEN_SECURE_2_0		28
5590 #define FTM_TPK_RI_PHY_LEN			7u
5591 #define FTM_TPK_RR_PHY_LEN			7u
5592 #define FTM_TPK_DATA_BUFFER_LEN			88u
5593 #define FTM_TPK_LEN_SECURE_2_0			64u
5594 #define FTM_TPK_RI_PHY_LEN_SECURE_2_0		14u
5595 #define FTM_TPK_RR_PHY_LEN_SECURE_2_0		14u
5596 
5597 #define FTM_RI_RR_BUF_LEN_20MHZ			32u
5598 #define FTM_RI_RR_BUF_LEN_80MHZ			64u
5599 
5600 #define FTM_RI_RR_BUF_LEN_FROM_CHANSPEC(chanspec) \
5601 	(CHSPEC_IS20((chanspec)) ? \
5602 	FTM_RI_RR_BUF_LEN_20MHZ : FTM_RI_RR_BUF_LEN_80MHZ)
5603 
5604 #define FTM_TPK_RI_RR_LEN_SECURE_2_0_20MHZ      28u
5605 #define FTM_TPK_RI_RR_LEN_SECURE_2_0_80MHZ      62u
5606 #define FTM_TPK_RI_RR_LEN_SECURE_2_0_2G		FTM_TPK_RI_RR_LEN_SECURE_2_0
5607 #define FTM_TPK_RI_RR_LEN_SECURE_2_0_5G		FTM_TPK_RI_RR_LEN_SECURE_2_0_80MHZ
5608 
5609 #define FTM_TPK_RI_RR_LEN_FROM_CHANSPEC(chanspec) \
5610 	(CHSPEC_IS20((chanspec)) ? FTM_TPK_RI_RR_LEN_SECURE_2_0_20MHZ : \
5611 	FTM_TPK_RI_RR_LEN_SECURE_2_0_80MHZ)
5612 
5613 #define FTM_TPK_RI_PHY_LEN_SECURE_2_0_20MHZ     14u
5614 #define FTM_TPK_RI_PHY_LEN_SECURE_2_0_80MHZ	31u
5615 #define FTM_TPK_RR_PHY_LEN_SECURE_2_0_80MHZ	31u
5616 
5617 #define FTM_TPK_RI_PHY_LEN_FROM_CHANSPEC(chanspec) \
5618 	(CHSPEC_IS20((chanspec)) ? FTM_TPK_RI_PHY_LEN_SECURE_2_0_20MHZ : \
5619 	FTM_TPK_RI_PHY_LEN_SECURE_2_0_80MHZ)
5620 
5621 #define FTM_TPK_RR_PHY_LEN_SECURE_2_0_20MHZ     14u
5622 
5623 #define FTM_TPK_RR_PHY_LEN_FROM_CHANSPEC(chanspec) \
5624 	(CHSPEC_IS20((chanspec)) ? FTM_TPK_RR_PHY_LEN_SECURE_2_0_20MHZ : \
5625 	FTM_TPK_RR_PHY_LEN_SECURE_2_0_80MHZ)
5626 
5627 BWL_PRE_PACKED_STRUCT struct dot11_ftm_vs_params {
5628 	uint8 id;                       /* DOT11_MNG_VS_ID */
5629 	uint8 len;
5630 	uint8 oui[3];                   /* Proprietary OUI, BRCM_PROP_OUI */
5631 	uint8 bcm_vs_id;
5632 	ftm_vs_tlv_t ftm_tpk_ri_rr[1];          /* ftm_TPK_ri_rr place holder */
5633 } BWL_POST_PACKED_STRUCT;
5634 typedef struct dot11_ftm_vs_params dot11_ftm_vs_tpk_ri_rr_params_t;
5635 #define DOT11_FTM_VS_LEN  (sizeof(dot11_ftm_vs_tpk_ri_rr_params_t) - TLV_HDR_LEN)
5636 /* end *DEPRECATED* ftm definitions */
5637 
5638 BWL_PRE_PACKED_STRUCT struct dot11_ftm_sync_info {
5639 	uint8 id;		/* Extended - 255 11mc D4.3  */
5640 	uint8 len;
5641 	uint8 id_ext;
5642 	uint8 tsf_sync_info[4];
5643 } BWL_POST_PACKED_STRUCT;
5644 typedef struct dot11_ftm_sync_info dot11_ftm_sync_info_t;
5645 
5646 /* ftm tsf sync info ie len - includes id ext */
5647 #define DOT11_FTM_SYNC_INFO_IE_LEN (sizeof(dot11_ftm_sync_info_t) - TLV_HDR_LEN)
5648 
5649 #define DOT11_FTM_IS_SYNC_INFO_IE(_ie) (\
5650 	DOT11_MNG_IE_ID_EXT_MATCH(_ie, DOT11_MNG_FTM_SYNC_INFO) && \
5651 	(_ie)->len == DOT11_FTM_SYNC_INFO_IE_LEN)
5652 
5653 BWL_PRE_PACKED_STRUCT struct dot11_dh_param_ie {
5654 	uint8   id;	/* OWE */
5655 	uint8   len;
5656 	uint8   ext_id;	/* EXT_MNG_OWE_DH_PARAM_ID */
5657 	uint16  group;
5658 	uint8   pub_key[0];
5659 } BWL_POST_PACKED_STRUCT;
5660 typedef struct dot11_dh_param_ie dot11_dh_param_ie_t;
5661 
5662 #define DOT11_DH_EXTID_OFFSET   (OFFSETOF(dot11_dh_param_ie_t, ext_id))
5663 
5664 #define DOT11_OWE_DH_PARAM_IE(_ie) (\
5665 	DOT11_MNG_IE_ID_EXT_MATCH(_ie, EXT_MNG_OWE_DH_PARAM_ID))
5666 
5667 #define DOT11_MNG_OWE_IE_ID_EXT_INIT(_ie, _id, _len) do {\
5668 	(_ie)->id = DOT11_MNG_ID_EXT_ID; \
5669 	(_ie)->len = _len; \
5670 	(_ie)->ext_id = _id; \
5671 } while (0)
5672 
5673 /* 802.11u interworking access network options */
5674 #define IW_ANT_MASK					0x0f
5675 #define IW_INTERNET_MASK				0x10
5676 #define IW_ASRA_MASK					0x20
5677 #define IW_ESR_MASK					0x40
5678 #define IW_UESA_MASK					0x80
5679 
5680 /* 802.11u interworking access network type */
5681 #define IW_ANT_PRIVATE_NETWORK				0
5682 #define IW_ANT_PRIVATE_NETWORK_WITH_GUEST		1
5683 #define IW_ANT_CHARGEABLE_PUBLIC_NETWORK		2
5684 #define IW_ANT_FREE_PUBLIC_NETWORK			3
5685 #define IW_ANT_PERSONAL_DEVICE_NETWORK			4
5686 #define IW_ANT_EMERGENCY_SERVICES_NETWORK		5
5687 #define IW_ANT_TEST_NETWORK				14
5688 #define IW_ANT_WILDCARD_NETWORK				15
5689 
5690 #define IW_ANT_LEN			1
5691 #define IW_VENUE_LEN			2
5692 #define IW_HESSID_LEN			6
5693 #define IW_HESSID_OFF			(IW_ANT_LEN + IW_VENUE_LEN)
5694 #define IW_MAX_LEN			(IW_ANT_LEN + IW_VENUE_LEN + IW_HESSID_LEN)
5695 
5696 /* 802.11u advertisement protocol */
5697 #define ADVP_ANQP_PROTOCOL_ID				0
5698 #define ADVP_MIH_PROTOCOL_ID				1
5699 
5700 /* 802.11u advertisement protocol masks */
5701 #define ADVP_QRL_MASK					0x7f
5702 #define ADVP_PAME_BI_MASK				0x80
5703 
5704 /* 802.11u advertisement protocol values */
5705 #define ADVP_QRL_REQUEST				0x00
5706 #define ADVP_QRL_RESPONSE				0x7f
5707 #define ADVP_PAME_BI_DEPENDENT				0x00
5708 #define ADVP_PAME_BI_INDEPENDENT			ADVP_PAME_BI_MASK
5709 
5710 /* 802.11u ANQP information ID */
5711 #define ANQP_ID_QUERY_LIST				256
5712 #define ANQP_ID_CAPABILITY_LIST				257
5713 #define ANQP_ID_VENUE_NAME_INFO				258
5714 #define ANQP_ID_EMERGENCY_CALL_NUMBER_INFO		259
5715 #define ANQP_ID_NETWORK_AUTHENTICATION_TYPE_INFO	260
5716 #define ANQP_ID_ROAMING_CONSORTIUM_LIST			261
5717 #define ANQP_ID_IP_ADDRESS_TYPE_AVAILABILITY_INFO	262
5718 #define ANQP_ID_NAI_REALM_LIST				263
5719 #define ANQP_ID_G3PP_CELLULAR_NETWORK_INFO		264
5720 #define ANQP_ID_AP_GEOSPATIAL_LOCATION			265
5721 #define ANQP_ID_AP_CIVIC_LOCATION			266
5722 #define ANQP_ID_AP_LOCATION_PUBLIC_ID_URI		267
5723 #define ANQP_ID_DOMAIN_NAME_LIST			268
5724 #define ANQP_ID_EMERGENCY_ALERT_ID_URI			269
5725 #define ANQP_ID_EMERGENCY_NAI				271
5726 #define ANQP_ID_NEIGHBOR_REPORT				272
5727 #define ANQP_ID_VENDOR_SPECIFIC_LIST			56797
5728 
5729 /* 802.11u ANQP ID len */
5730 #define ANQP_INFORMATION_ID_LEN				2
5731 
5732 /* 802.11u ANQP OUI */
5733 #define ANQP_OUI_SUBTYPE				9
5734 
5735 /* 802.11u venue name */
5736 #define VENUE_LANGUAGE_CODE_SIZE			3
5737 #define VENUE_NAME_SIZE					255
5738 
5739 /* 802.11u venue groups */
5740 #define VENUE_UNSPECIFIED				0
5741 #define VENUE_ASSEMBLY					1
5742 #define VENUE_BUSINESS					2
5743 #define VENUE_EDUCATIONAL				3
5744 #define VENUE_FACTORY					4
5745 #define VENUE_INSTITUTIONAL				5
5746 #define VENUE_MERCANTILE				6
5747 #define VENUE_RESIDENTIAL				7
5748 #define VENUE_STORAGE					8
5749 #define VENUE_UTILITY					9
5750 #define VENUE_VEHICULAR					10
5751 #define VENUE_OUTDOOR					11
5752 
5753 /* 802.11u network authentication type indicator */
5754 #define NATI_UNSPECIFIED				-1
5755 #define NATI_ACCEPTANCE_OF_TERMS_CONDITIONS		0
5756 #define NATI_ONLINE_ENROLLMENT_SUPPORTED		1
5757 #define NATI_HTTP_HTTPS_REDIRECTION			2
5758 #define NATI_DNS_REDIRECTION				3
5759 
5760 /* 802.11u IP address type availability - IPv6 */
5761 #define IPA_IPV6_SHIFT					0
5762 #define IPA_IPV6_MASK					(0x03 << IPA_IPV6_SHIFT)
5763 #define	IPA_IPV6_NOT_AVAILABLE				0x00
5764 #define IPA_IPV6_AVAILABLE				0x01
5765 #define IPA_IPV6_UNKNOWN_AVAILABILITY			0x02
5766 
5767 /* 802.11u IP address type availability - IPv4 */
5768 #define IPA_IPV4_SHIFT					2
5769 #define IPA_IPV4_MASK					(0x3f << IPA_IPV4_SHIFT)
5770 #define	IPA_IPV4_NOT_AVAILABLE				0x00
5771 #define IPA_IPV4_PUBLIC					0x01
5772 #define IPA_IPV4_PORT_RESTRICT				0x02
5773 #define IPA_IPV4_SINGLE_NAT				0x03
5774 #define IPA_IPV4_DOUBLE_NAT				0x04
5775 #define IPA_IPV4_PORT_RESTRICT_SINGLE_NAT		0x05
5776 #define IPA_IPV4_PORT_RESTRICT_DOUBLE_NAT		0x06
5777 #define IPA_IPV4_UNKNOWN_AVAILABILITY			0x07
5778 
5779 /* 802.11u NAI realm encoding */
5780 #define REALM_ENCODING_RFC4282				0
5781 #define REALM_ENCODING_UTF8				1
5782 
5783 /* 802.11u IANA EAP method type numbers */
5784 #define REALM_EAP_TLS					13
5785 #define REALM_EAP_LEAP					17
5786 #define REALM_EAP_SIM					18
5787 #define REALM_EAP_TTLS					21
5788 #define REALM_EAP_AKA					23
5789 #define REALM_EAP_PEAP					25
5790 #define REALM_EAP_FAST					43
5791 #define REALM_EAP_PSK					47
5792 #define REALM_EAP_AKAP					50
5793 #define REALM_EAP_EXPANDED				254
5794 
5795 /* 802.11u authentication ID */
5796 #define REALM_EXPANDED_EAP				1
5797 #define REALM_NON_EAP_INNER_AUTHENTICATION		2
5798 #define REALM_INNER_AUTHENTICATION_EAP			3
5799 #define REALM_EXPANDED_INNER_EAP			4
5800 #define REALM_CREDENTIAL				5
5801 #define REALM_TUNNELED_EAP_CREDENTIAL			6
5802 #define REALM_VENDOR_SPECIFIC_EAP			221
5803 
5804 /* 802.11u non-EAP inner authentication type */
5805 #define REALM_RESERVED_AUTH				0
5806 #define REALM_PAP					1
5807 #define REALM_CHAP					2
5808 #define REALM_MSCHAP					3
5809 #define REALM_MSCHAPV2					4
5810 
5811 /* 802.11u credential type */
5812 #define REALM_SIM					1
5813 #define REALM_USIM					2
5814 #define REALM_NFC					3
5815 #define REALM_HARDWARE_TOKEN				4
5816 #define REALM_SOFTOKEN					5
5817 #define REALM_CERTIFICATE				6
5818 #define REALM_USERNAME_PASSWORD				7
5819 #define REALM_SERVER_SIDE				8
5820 #define REALM_RESERVED_CRED				9
5821 #define REALM_VENDOR_SPECIFIC_CRED			10
5822 
5823 /* 802.11u 3GPP PLMN */
5824 #define G3PP_GUD_VERSION				0
5825 #define G3PP_PLMN_LIST_IE				0
5826 
5827 /* AP Location Public ID Info encoding */
5828 #define PUBLIC_ID_URI_FQDN_SE_ID		0
5829 /* URI/FQDN Descriptor field values */
5830 #define LOCATION_ENCODING_HELD			1
5831 #define LOCATION_ENCODING_SUPL			2
5832 #define URI_FQDN_SIZE					255
5833 
5834 /** hotspot2.0 indication element (vendor specific) */
5835 BWL_PRE_PACKED_STRUCT struct hs20_ie {
5836 	uint8 oui[3];
5837 	uint8 type;
5838 	uint8 config;
5839 } BWL_POST_PACKED_STRUCT;
5840 typedef struct hs20_ie hs20_ie_t;
5841 #define HS20_IE_LEN 5	/* HS20 IE length */
5842 
5843 /* Short SSID list Extended Capabilities element */
5844 BWL_PRE_PACKED_STRUCT struct short_ssid_list_ie {
5845 	uint8 id;
5846 	uint8 len;
5847 	uint8 id_ext;
5848 	uint8 data[1];    /* Capabilities Information */
5849 } BWL_POST_PACKED_STRUCT;
5850 
5851 typedef struct short_ssid_list_ie short_ssid_list_ie_t;
5852 #define SHORT_SSID_LIST_IE_FIXED_LEN	3	/* SHORT SSID LIST IE LENGTH */
5853 
5854 /** IEEE 802.11 Annex E */
5855 typedef enum {
5856 	DOT11_2GHZ_20MHZ_CLASS_12	= 81,	/* Ch 1-11 */
5857 	DOT11_5GHZ_20MHZ_CLASS_1	= 115,	/* Ch 36-48 */
5858 	DOT11_5GHZ_20MHZ_CLASS_2_DFS	= 118,	/* Ch 52-64 */
5859 	DOT11_5GHZ_20MHZ_CLASS_3	= 124,	/* Ch 149-161 */
5860 	DOT11_5GHZ_20MHZ_CLASS_4_DFS	= 121,	/* Ch 100-140 */
5861 	DOT11_5GHZ_20MHZ_CLASS_5	= 125,	/* Ch 149-165 */
5862 	DOT11_5GHZ_40MHZ_CLASS_22	= 116,	/* Ch 36-44,   lower */
5863 	DOT11_5GHZ_40MHZ_CLASS_23_DFS	= 119,	/* Ch 52-60,   lower */
5864 	DOT11_5GHZ_40MHZ_CLASS_24_DFS	= 122,	/* Ch 100-132, lower */
5865 	DOT11_5GHZ_40MHZ_CLASS_25	= 126,	/* Ch 149-157, lower */
5866 	DOT11_5GHZ_40MHZ_CLASS_27	= 117,	/* Ch 40-48,   upper */
5867 	DOT11_5GHZ_40MHZ_CLASS_28_DFS	= 120,	/* Ch 56-64,   upper */
5868 	DOT11_5GHZ_40MHZ_CLASS_29_DFS	= 123,	/* Ch 104-136, upper */
5869 	DOT11_5GHZ_40MHZ_CLASS_30	= 127,	/* Ch 153-161, upper */
5870 	DOT11_2GHZ_40MHZ_CLASS_32	= 83,	/* Ch 1-7,     lower */
5871 	DOT11_2GHZ_40MHZ_CLASS_33	= 84,	/* Ch 5-11,    upper */
5872 } dot11_op_class_t;
5873 
5874 /* QoS map */
5875 #define QOS_MAP_FIXED_LENGTH	(8 * 2)	/* DSCP ranges fixed with 8 entries */
5876 
5877 /* BCM proprietary IE type for AIBSS */
5878 #define BCM_AIBSS_IE_TYPE 56
5879 
5880 /* BCM proprietary flag type for WL_DISCO_VSIE */
5881 #define SSE_OUI                                  "\x00\x00\xF0"
5882 #define VENDOR_ENTERPRISE_STA_OUI_TYPE           0x22
5883 #define MAX_VSIE_DISASSOC                        (1)
5884 #define DISCO_VSIE_LEN                           0x09u
5885 
5886 /* Single PMK IE */
5887 #define CCX_SPMK_TYPE	3	/* CCX Extended Cap IE type for SPMK */
5888 /* CCX Extended Capability IE */
5889 BWL_PRE_PACKED_STRUCT struct ccx_spmk_cap_ie {
5890 	uint8 id;		/* 221, DOT11_MNG_PROPR_ID */
5891 	uint8 len;
5892 	uint8 oui[DOT11_OUI_LEN];	/* 00:40:96, CISCO_AIRONET_OUI */
5893 	uint8 type;		/* 11 */
5894 	uint8 cap;
5895 } BWL_POST_PACKED_STRUCT;
5896 typedef struct ccx_spmk_cap_ie ccx_spmk_cap_ie_t;
5897 
5898 /* OWE definitions */
5899 /* ID + len + OUI + OI type + BSSID + SSID_len */
5900 #define OWE_TRANS_MODE_IE_FIXED_LEN  13u
5901 
5902 /* Supported Operating Classes element */
5903 BWL_PRE_PACKED_STRUCT struct supp_op_classes_ie {
5904 	uint8 id;
5905 	uint8 len;
5906 	uint8 cur_op_class;
5907 	uint8 op_classes[];    /* Supported Operating Classes */
5908 } BWL_POST_PACKED_STRUCT;
5909 typedef struct supp_op_classes_ie supp_op_classes_ie_t;
5910 
5911 /* Transition mode (bit number) */
5912 #define TRANSISION_MODE_WPA3_PSK		0u
5913 #define TRANSITION_MODE_SAE_PK			1u
5914 #define TRANSITION_MODE_WPA3_ENTERPRISE		2u
5915 #define TRANSITION_MODE_ENHANCED_OPEN		3u
5916 
5917 /* This marks the end of a packed structure section. */
5918 #include <packed_section_end.h>
5919 
5920 #endif /* _802_11_H_ */
5921