1 /** @file mlan_uap_cmdevent.c
2  *
3  *  @brief  This file provides the handling of AP mode command and event
4  *
5  *  Copyright 2008-2024 NXP
6  *
7  *  SPDX-License-Identifier: BSD-3-Clause
8  *
9  */
10 
11 /********************************************************
12 Change log:
13     02/05/2009: initial version
14 ********************************************************/
15 
16 #include <mlan_api.h>
17 
18 /* Additional WMSDK header files */
19 #include <wmerrno.h>
20 #include <osa.h>
21 
22 /* Always keep this include at the end of all include files */
23 #include <mlan_remap_mem_operations.h>
24 
25 /**
26  *  @brief This function prepares command for config uap settings
27  *
28  *  @param pmpriv		A pointer to mlan_private structure
29  *  @param cmd	   		A pointer to HostCmd_DS_COMMAND structure
30  *  @param cmd_action   the action: GET or SET
31  *  @param pioctl_buf   A pointer to mlan_ioctl_req structure
32  *  @return         MLAN_STATUS_SUCCESS or MLAN_STATUS_FAILURE
33  */
wlan_uap_cmd_ap_config(pmlan_private pmpriv,IN HostCmd_DS_COMMAND * cmd,IN t_u16 cmd_action,IN pmlan_ioctl_req pioctl_buf)34 static mlan_status wlan_uap_cmd_ap_config(pmlan_private pmpriv,
35                                           IN HostCmd_DS_COMMAND *cmd,
36                                           IN t_u16 cmd_action,
37                                           IN pmlan_ioctl_req pioctl_buf)
38 {
39     mlan_ds_bss *bss                               = MNULL;
40     HostCmd_DS_SYS_CONFIG *sys_config              = (HostCmd_DS_SYS_CONFIG *)&cmd->params.sys_config;
41     t_u8 *tlv                                      = MNULL;
42     MrvlIEtypes_MacAddr_t *tlv_mac                 = MNULL;
43     MrvlIEtypes_SsIdParamSet_t *tlv_ssid           = MNULL;
44     MrvlIEtypes_beacon_period_t *tlv_beacon_period = MNULL;
45     MrvlIEtypes_ecsa_config_t *tlv_ecsa_config     = MNULL;
46     MrvlIEtypes_dtim_period_t *tlv_dtim_period     = MNULL;
47     MrvlIEtypes_RatesParamSet_t *tlv_rates         = MNULL;
48     MrvlIEtypes_bcast_ssid_t *tlv_bcast_ssid = MNULL;
49     MrvlIEtypes_auth_type_t *tlv_auth_type               = MNULL;
50     MrvlIEtypes_channel_band_t *tlv_chan_band            = MNULL;
51     MrvlIEtypes_ChanListParamSet_t *tlv_chan_list        = MNULL;
52     ChanScanParamSet_t *pscan_chan                       = MNULL;
53     MrvlIEtypes_encrypt_protocol_t *tlv_encrypt_protocol = MNULL;
54     MrvlIEtypes_akmp_t *tlv_akmp                         = MNULL;
55     MrvlIEtypes_pwk_cipher_t *tlv_pwk_cipher             = MNULL;
56     MrvlIEtypes_gwk_cipher_t *tlv_gwk_cipher             = MNULL;
57     MrvlIEtypes_passphrase_t *tlv_passphrase = MNULL;
58     MrvlIEtypes_password_t *tlv_password     = MNULL;
59     MrvlIEtypes_wmm_parameter_t *tlv_wmm_parameter = MNULL;
60 #if (CONFIG_UAP_AMPDU_TX) || (CONFIG_UAP_AMPDU_RX)
61     MrvlIETypes_HTCap_t *tlv_htcap = MNULL;
62 #endif
63     t_u32 cmd_size  = 0;
64     t_u8 zero_mac[] = {0, 0, 0, 0, 0, 0};
65     t_u16 i;
66     t_u16 ac;
67 
68     ENTER();
69     if (pioctl_buf == MNULL)
70     {
71         LEAVE();
72         return MLAN_STATUS_FAILURE;
73     }
74 
75     bss = (mlan_ds_bss *)(void *)pioctl_buf->pbuf;
76 
77     cmd->command       = wlan_cpu_to_le16(HOST_CMD_APCMD_SYS_CONFIGURE);
78     sys_config->action = wlan_cpu_to_le16(cmd_action);
79     cmd_size           = sizeof(HostCmd_DS_SYS_CONFIG) - 1U + S_DS_GEN;
80 
81     tlv = (t_u8 *)sys_config->tlv_buffer;
82     if (__memcmp(pmpriv->adapter, zero_mac, &bss->param.bss_config.mac_addr, MLAN_MAC_ADDR_LENGTH) != 0)
83     {
84         tlv_mac              = (MrvlIEtypes_MacAddr_t *)(void *)tlv;
85         tlv_mac->header.type = wlan_cpu_to_le16(TLV_TYPE_UAP_MAC_ADDRESS);
86         tlv_mac->header.len  = wlan_cpu_to_le16(MLAN_MAC_ADDR_LENGTH);
87         (void)__memcpy(pmpriv->adapter, tlv_mac->mac, &bss->param.bss_config.mac_addr, MLAN_MAC_ADDR_LENGTH);
88         cmd_size += sizeof(MrvlIEtypes_MacAddr_t);
89         tlv += sizeof(MrvlIEtypes_MacAddr_t);
90     }
91 
92     if (bss->param.bss_config.ssid.ssid_len != 0U)
93     {
94         tlv_ssid              = (MrvlIEtypes_SsIdParamSet_t *)(void *)tlv;
95         tlv_ssid->header.type = wlan_cpu_to_le16(TLV_TYPE_SSID);
96         tlv_ssid->header.len  = wlan_cpu_to_le16((t_u16)bss->param.bss_config.ssid.ssid_len);
97         (void)__memcpy(pmpriv->adapter, tlv_ssid->ssid, bss->param.bss_config.ssid.ssid,
98                        bss->param.bss_config.ssid.ssid_len);
99         cmd_size += sizeof(MrvlIEtypesHeader_t) + bss->param.bss_config.ssid.ssid_len;
100         tlv += sizeof(MrvlIEtypesHeader_t) + bss->param.bss_config.ssid.ssid_len;
101     }
102 
103     if ((bss->param.bss_config.beacon_period >= MIN_BEACON_PERIOD) &&
104         (bss->param.bss_config.beacon_period <= MAX_BEACON_PERIOD))
105     {
106         tlv_beacon_period                = (MrvlIEtypes_beacon_period_t *)(void *)tlv;
107         tlv_beacon_period->header.type   = wlan_cpu_to_le16(TLV_TYPE_UAP_BEACON_PERIOD);
108         tlv_beacon_period->header.len    = wlan_cpu_to_le16(sizeof(t_u16));
109         tlv_beacon_period->beacon_period = wlan_cpu_to_le16(bss->param.bss_config.beacon_period);
110         cmd_size += sizeof(MrvlIEtypes_beacon_period_t);
111         tlv += sizeof(MrvlIEtypes_beacon_period_t);
112     }
113 
114     if ((bss->param.bss_config.chan_sw_count >= MIN_CHSW_COUNT) &&
115         (bss->param.bss_config.chan_sw_count <= MAX_CHSW_COUNT))
116     {
117         tlv_ecsa_config                     = (MrvlIEtypes_ecsa_config_t *)(void *)tlv;
118         tlv_ecsa_config->header.type        = wlan_cpu_to_le16(TLV_TYPE_UAP_ECSA_CONFIG);
119         tlv_ecsa_config->header.len         = wlan_cpu_to_le16(sizeof(t_u16) + sizeof(t_u8) + sizeof(t_u8));
120         tlv_ecsa_config->enable             = 1;
121         tlv_ecsa_config->ChannelSwitchMode  = 0;
122         tlv_ecsa_config->ChannelSwitchCount = bss->param.bss_config.chan_sw_count;
123         cmd_size += sizeof(MrvlIEtypes_ecsa_config_t);
124         tlv += sizeof(MrvlIEtypes_ecsa_config_t);
125     }
126 
127     if ((bss->param.bss_config.dtim_period >= MIN_DTIM_PERIOD) &&
128         (bss->param.bss_config.dtim_period <= MAX_DTIM_PERIOD))
129     {
130         tlv_dtim_period              = (MrvlIEtypes_dtim_period_t *)(void *)tlv;
131         tlv_dtim_period->header.type = wlan_cpu_to_le16(TLV_TYPE_UAP_DTIM_PERIOD);
132         tlv_dtim_period->header.len  = wlan_cpu_to_le16(sizeof(t_u8));
133         tlv_dtim_period->dtim_period = bss->param.bss_config.dtim_period;
134         cmd_size += sizeof(MrvlIEtypes_dtim_period_t);
135         tlv += sizeof(MrvlIEtypes_dtim_period_t);
136     }
137 
138     if (bss->param.bss_config.rates[0] != 0U)
139     {
140         tlv_rates              = (MrvlIEtypes_RatesParamSet_t *)(void *)tlv;
141         tlv_rates->header.type = wlan_cpu_to_le16(TLV_TYPE_RATES);
142         for (i = 0; i < MAX_DATA_RATES && bss->param.bss_config.rates[i]; i++)
143         {
144             tlv_rates->rates[i] = bss->param.bss_config.rates[i];
145         }
146         tlv_rates->header.len = wlan_cpu_to_le16(i);
147         cmd_size += sizeof(MrvlIEtypesHeader_t) + i;
148         tlv += sizeof(MrvlIEtypesHeader_t) + i;
149     }
150 
151     if (bss->param.bss_config.bcast_ssid_ctl <= MAX_BCAST_SSID_CTL)
152     {
153         tlv_bcast_ssid                 = (MrvlIEtypes_bcast_ssid_t *)(void *)tlv;
154         tlv_bcast_ssid->header.type    = wlan_cpu_to_le16(TLV_TYPE_UAP_BCAST_SSID_CTL);
155         tlv_bcast_ssid->header.len     = wlan_cpu_to_le16(sizeof(t_u8));
156         tlv_bcast_ssid->bcast_ssid_ctl = bss->param.bss_config.bcast_ssid_ctl;
157         cmd_size += sizeof(MrvlIEtypes_bcast_ssid_t);
158         tlv += sizeof(MrvlIEtypes_bcast_ssid_t);
159     }
160 
161     if ((((bss->param.bss_config.band_cfg & BAND_CONFIG_ACS_MODE) == BAND_CONFIG_MANUAL) &&
162          (bss->param.bss_config.channel > 0U) && (bss->param.bss_config.channel <= MLAN_MAX_CHANNEL)) ||
163         (bss->param.bss_config.band_cfg & BAND_CONFIG_ACS_MODE))
164     {
165         tlv_chan_band              = (MrvlIEtypes_channel_band_t *)(void *)tlv;
166         tlv_chan_band->header.type = wlan_cpu_to_le16(TLV_TYPE_UAP_CHAN_BAND_CONFIG);
167         tlv_chan_band->header.len  = wlan_cpu_to_le16(sizeof(t_u8) + sizeof(t_u8));
168         tlv_chan_band->band_config = bss->param.bss_config.band_cfg;
169         tlv_chan_band->channel     = bss->param.bss_config.channel;
170         cmd_size += sizeof(MrvlIEtypes_channel_band_t);
171         tlv += sizeof(MrvlIEtypes_channel_band_t);
172     }
173 
174     if ((bss->param.bss_config.num_of_chan) && (bss->param.bss_config.num_of_chan <= MLAN_MAX_CHANNEL))
175     {
176         tlv_chan_list              = (MrvlIEtypes_ChanListParamSet_t *)(void *)tlv;
177         tlv_chan_list->header.type = wlan_cpu_to_le16(TLV_TYPE_CHANLIST);
178         tlv_chan_list->header.len =
179             wlan_cpu_to_le16((t_u16)(sizeof(ChanScanParamSet_t) * bss->param.bss_config.num_of_chan));
180         pscan_chan = tlv_chan_list->chan_scan_param;
181         for (i = 0; i < bss->param.bss_config.num_of_chan; i++)
182         {
183             (void)__memset(pmpriv->adapter, pscan_chan, 0x00, sizeof(ChanScanParamSet_t));
184             pscan_chan->chan_number = bss->param.bss_config.chan_list[i].chan_number;
185             pscan_chan->radio_type  = bss->param.bss_config.chan_list[i].band_config_type;
186             pscan_chan++;
187         }
188         cmd_size += sizeof(tlv_chan_list->header) + (sizeof(ChanScanParamSet_t) * bss->param.bss_config.num_of_chan);
189         tlv += sizeof(tlv_chan_list->header) + (sizeof(ChanScanParamSet_t) * bss->param.bss_config.num_of_chan);
190     }
191 
192     if ((bss->param.bss_config.auth_mode <= MLAN_AUTH_MODE_SHARED) ||
193         (bss->param.bss_config.auth_mode == MLAN_AUTH_MODE_AUTO))
194     {
195         tlv_auth_type                 = (MrvlIEtypes_auth_type_t *)tlv;
196         tlv_auth_type->header.type    = wlan_cpu_to_le16(TLV_TYPE_AUTH_TYPE);
197         tlv_auth_type->header.len     = wlan_cpu_to_le16(sizeof(MrvlIEtypes_auth_type_t) - sizeof(MrvlIEtypesHeader_t));
198         tlv_auth_type->auth_type      = (t_u8)bss->param.bss_config.auth_mode;
199         tlv_auth_type->PWE_derivation = (t_u8)bss->param.bss_config.pwe_derivation;
200         tlv_auth_type->transition_disable = (t_u8)bss->param.bss_config.transition_disable;
201         cmd_size += sizeof(MrvlIEtypes_auth_type_t);
202         tlv += sizeof(MrvlIEtypes_auth_type_t);
203     }
204 
205     if (bss->param.bss_config.protocol != 0U)
206     {
207         tlv_encrypt_protocol              = (MrvlIEtypes_encrypt_protocol_t *)(void *)tlv;
208         tlv_encrypt_protocol->header.type = wlan_cpu_to_le16(TLV_TYPE_UAP_ENCRYPT_PROTOCOL);
209         tlv_encrypt_protocol->header.len  = wlan_cpu_to_le16(sizeof(t_u16));
210         tlv_encrypt_protocol->protocol    = wlan_cpu_to_le16(bss->param.bss_config.protocol);
211         cmd_size += sizeof(MrvlIEtypes_encrypt_protocol_t);
212         tlv += sizeof(MrvlIEtypes_encrypt_protocol_t);
213     }
214 
215     if ((bss->param.bss_config.protocol & PROTOCOL_WPA) || (bss->param.bss_config.protocol & PROTOCOL_WPA2) ||
216         (bss->param.bss_config.protocol & PROTOCOL_WPA3_SAE) ||
217 #if CONFIG_DRIVER_OWE
218         (bss->param.bss_config.protocol & PROTOCOL_OWE) ||
219 #endif
220         (bss->param.bss_config.protocol & PROTOCOL_EAP))
221     {
222         tlv_akmp                     = (MrvlIEtypes_akmp_t *)(void *)tlv;
223         tlv_akmp->header.type        = wlan_cpu_to_le16(TLV_TYPE_UAP_AKMP);
224         tlv_akmp->key_mgmt           = wlan_cpu_to_le16(bss->param.bss_config.key_mgmt);
225         tlv_akmp->header.len         = (t_u16)sizeof(t_u16);
226         tlv_akmp->key_mgmt_operation = wlan_cpu_to_le16(bss->param.bss_config.key_mgmt_operation);
227         tlv_akmp->header.len += (t_u16)sizeof(t_u16);
228         tlv_akmp->header.len = wlan_cpu_to_le16(tlv_akmp->header.len);
229         cmd_size += sizeof(MrvlIEtypes_akmp_t);
230         tlv += sizeof(MrvlIEtypes_akmp_t);
231 
232         if ((bss->param.bss_config.wpa_cfg.pairwise_cipher_wpa & VALID_CIPHER_BITMAP) != 0U)
233         {
234             tlv_pwk_cipher                  = (MrvlIEtypes_pwk_cipher_t *)(void *)tlv;
235             tlv_pwk_cipher->header.type     = wlan_cpu_to_le16(TLV_TYPE_PWK_CIPHER);
236             tlv_pwk_cipher->header.len      = wlan_cpu_to_le16(sizeof(t_u16) + sizeof(t_u8) + sizeof(t_u8));
237             tlv_pwk_cipher->protocol        = wlan_cpu_to_le16(PROTOCOL_WPA);
238             tlv_pwk_cipher->pairwise_cipher = bss->param.bss_config.wpa_cfg.pairwise_cipher_wpa;
239             cmd_size += sizeof(MrvlIEtypes_pwk_cipher_t);
240             tlv += sizeof(MrvlIEtypes_pwk_cipher_t);
241         }
242 
243         if ((bss->param.bss_config.wpa_cfg.pairwise_cipher_wpa2 & VALID_CIPHER_BITMAP) != 0U)
244         {
245             tlv_pwk_cipher              = (MrvlIEtypes_pwk_cipher_t *)(void *)tlv;
246             tlv_pwk_cipher->header.type = wlan_cpu_to_le16(TLV_TYPE_PWK_CIPHER);
247             tlv_pwk_cipher->header.len  = wlan_cpu_to_le16(sizeof(t_u16) + sizeof(t_u8) + sizeof(t_u8));
248             if ((bss->param.bss_config.protocol & PROTOCOL_WPA3_SAE) != 0U)
249             {
250                 tlv_pwk_cipher->protocol = wlan_cpu_to_le16(PROTOCOL_WPA3_SAE);
251             }
252             else
253             {
254                 tlv_pwk_cipher->protocol = wlan_cpu_to_le16(PROTOCOL_WPA2);
255             }
256             tlv_pwk_cipher->pairwise_cipher = bss->param.bss_config.wpa_cfg.pairwise_cipher_wpa2;
257             cmd_size += sizeof(MrvlIEtypes_pwk_cipher_t);
258             tlv += sizeof(MrvlIEtypes_pwk_cipher_t);
259         }
260 
261         if ((bss->param.bss_config.wpa_cfg.group_cipher & VALID_CIPHER_BITMAP) != 0U)
262         {
263             tlv_gwk_cipher               = (MrvlIEtypes_gwk_cipher_t *)(void *)tlv;
264             tlv_gwk_cipher->header.type  = wlan_cpu_to_le16(TLV_TYPE_GWK_CIPHER);
265             tlv_gwk_cipher->header.len   = wlan_cpu_to_le16(sizeof(t_u8) + sizeof(t_u8));
266             tlv_gwk_cipher->group_cipher = bss->param.bss_config.wpa_cfg.group_cipher;
267             cmd_size += sizeof(MrvlIEtypes_gwk_cipher_t);
268             tlv += sizeof(MrvlIEtypes_gwk_cipher_t);
269         }
270 
271         if (bss->param.bss_config.wpa_cfg.length != 0U)
272         {
273             tlv_passphrase              = (MrvlIEtypes_passphrase_t *)(void *)tlv;
274             tlv_passphrase->header.type = wlan_cpu_to_le16(TLV_TYPE_UAP_WPA_PASSPHRASE);
275             tlv_passphrase->header.len  = (t_u16)wlan_cpu_to_le16(bss->param.bss_config.wpa_cfg.length);
276             (void)__memcpy(pmpriv->adapter, tlv_passphrase->passphrase, bss->param.bss_config.wpa_cfg.passphrase,
277                            bss->param.bss_config.wpa_cfg.length);
278             cmd_size += sizeof(MrvlIEtypesHeader_t) + bss->param.bss_config.wpa_cfg.length;
279             tlv += sizeof(MrvlIEtypesHeader_t) + bss->param.bss_config.wpa_cfg.length;
280         }
281 
282         if (bss->param.bss_config.wpa_cfg.password_length != 0U)
283         {
284             tlv_password              = (MrvlIEtypes_password_t *)(void *)tlv;
285             tlv_password->header.type = wlan_cpu_to_le16(TLV_TYPE_UAP_WPA3_SAE_PASSWORD);
286             tlv_password->header.len  = (t_u16)wlan_cpu_to_le16(bss->param.bss_config.wpa_cfg.password_length);
287             (void)__memcpy(pmpriv->adapter, tlv_password->password, bss->param.bss_config.wpa_cfg.password,
288                            bss->param.bss_config.wpa_cfg.password_length);
289             cmd_size += sizeof(MrvlIEtypesHeader_t) + bss->param.bss_config.wpa_cfg.password_length;
290             tlv += sizeof(MrvlIEtypesHeader_t) + bss->param.bss_config.wpa_cfg.password_length;
291         }
292     }
293 
294 #if (CONFIG_UAP_AMPDU_TX) || (CONFIG_UAP_AMPDU_RX)
295     if ((bss->param.bss_config.ht_cap_info) != 0U)
296     {
297         /* wmsdk: All the values received will be zero by default. */
298         tlv_htcap                     = (MrvlIETypes_HTCap_t *)(void *)tlv;
299         tlv_htcap->header.type        = wlan_cpu_to_le16(HT_CAPABILITY);
300         tlv_htcap->header.len         = wlan_cpu_to_le16(sizeof(HTCap_t));
301         tlv_htcap->ht_cap.ht_cap_info = wlan_cpu_to_le16(bss->param.bss_config.ht_cap_info);
302         tlv_htcap->ht_cap.ampdu_param = bss->param.bss_config.ampdu_param;
303         (void)__memcpy(pmpriv->adapter, tlv_htcap->ht_cap.supported_mcs_set, bss->param.bss_config.supported_mcs_set,
304                        16);
305 #if CONFIG_WIFI_CAPA
306         /* Disable 802.11n */
307         if (!pmpriv->adapter->usr_dot_11n_enable)
308         {
309             tlv_htcap->ht_cap.supported_mcs_set[0] = 0;
310             tlv_htcap->ht_cap.supported_mcs_set[4] = 0;
311 #ifdef STREAM_2X2
312             tlv_htcap->ht_cap.supported_mcs_set[1] = 0;
313 #endif
314         }
315 #endif
316         tlv_htcap->ht_cap.ht_ext_cap = wlan_cpu_to_le16(bss->param.bss_config.ht_ext_cap);
317         tlv_htcap->ht_cap.tx_bf_cap  = wlan_cpu_to_le32(bss->param.bss_config.tx_bf_cap);
318         tlv_htcap->ht_cap.asel       = bss->param.bss_config.asel;
319         cmd_size += sizeof(MrvlIETypes_HTCap_t);
320         tlv += sizeof(MrvlIETypes_HTCap_t);
321     }
322 #endif
323 
324     if ((bss->param.bss_config.uap_host_based_config == MTRUE) ||
325         (bss->param.bss_config.wmm_para.qos_info & 0x80 || bss->param.bss_config.wmm_para.qos_info == 0x00))
326     {
327         tlv_wmm_parameter              = (MrvlIEtypes_wmm_parameter_t *)tlv;
328         tlv_wmm_parameter->header.type = wlan_cpu_to_le16(TLV_TYPE_VENDOR_SPECIFIC_IE);
329         tlv_wmm_parameter->header.len  = wlan_cpu_to_le16(sizeof(bss->param.bss_config.wmm_para));
330         (void)__memcpy(pmpriv->adapter, tlv_wmm_parameter->wmm_para.ouitype, bss->param.bss_config.wmm_para.ouitype,
331                        sizeof(tlv_wmm_parameter->wmm_para.ouitype));
332         tlv_wmm_parameter->wmm_para.ouisubtype = bss->param.bss_config.wmm_para.ouisubtype;
333         tlv_wmm_parameter->wmm_para.version    = bss->param.bss_config.wmm_para.version;
334         tlv_wmm_parameter->wmm_para.qos_info   = bss->param.bss_config.wmm_para.qos_info;
335         tlv_wmm_parameter->wmm_para.reserved   = 0x00;
336         for (ac = 0; ac < 4; ac++)
337         {
338             tlv_wmm_parameter->wmm_para.ac_params[ac].aci_aifsn.aifsn =
339                 bss->param.bss_config.wmm_para.ac_params[ac].aci_aifsn.aifsn;
340             tlv_wmm_parameter->wmm_para.ac_params[ac].aci_aifsn.acm =
341                 bss->param.bss_config.wmm_para.ac_params[ac].aci_aifsn.acm;
342             tlv_wmm_parameter->wmm_para.ac_params[ac].aci_aifsn.aci =
343                 bss->param.bss_config.wmm_para.ac_params[ac].aci_aifsn.aci;
344             tlv_wmm_parameter->wmm_para.ac_params[ac].ecw.ecw_max =
345                 bss->param.bss_config.wmm_para.ac_params[ac].ecw.ecw_max;
346             tlv_wmm_parameter->wmm_para.ac_params[ac].ecw.ecw_min =
347                 bss->param.bss_config.wmm_para.ac_params[ac].ecw.ecw_min;
348             tlv_wmm_parameter->wmm_para.ac_params[ac].tx_op_limit =
349                 wlan_cpu_to_le16(bss->param.bss_config.wmm_para.ac_params[ac].tx_op_limit);
350         }
351         cmd_size += sizeof(MrvlIEtypes_wmm_parameter_t);
352         tlv += sizeof(MrvlIEtypes_wmm_parameter_t);
353     }
354 
355     cmd->size = (t_u16)wlan_cpu_to_le16(cmd_size);
356     PRINTM(MCMND, "AP config: cmd_size=%d\n", cmd_size);
357 #if CONFIG_WIFI_EXTRA_DEBUG
358     PRINTF("wlan_uap_cmd_ap_config : cmd\r\n");
359     dump_hex(cmd, cmd->size);
360 #endif
361     LEAVE();
362     return MLAN_STATUS_SUCCESS;
363 }
364 
365 /**
366  *  @brief This function prepares command of sys_config
367  *
368  *  @param pmpriv		A pointer to mlan_private structure
369  *  @param cmd	   		A pointer to HostCmd_DS_COMMAND structure
370  *  @param cmd_action   the action: GET or SET
371  *  @param pioctl_buf   A pointer to mlan_ioctl_req structure
372  *  @return         MLAN_STATUS_SUCCESS or MLAN_STATUS_FAILURE
373  */
wlan_uap_cmd_sys_configure(pmlan_private pmpriv,IN HostCmd_DS_COMMAND * cmd,IN t_u16 cmd_action,IN pmlan_ioctl_req pioctl_buf,IN t_void * pdata_buf)374 static mlan_status wlan_uap_cmd_sys_configure(pmlan_private pmpriv,
375                                               IN HostCmd_DS_COMMAND *cmd,
376                                               IN t_u16 cmd_action,
377                                               IN pmlan_ioctl_req pioctl_buf,
378                                               IN t_void *pdata_buf)
379 {
380     mlan_ds_bss *bss                          = MNULL;
381     HostCmd_DS_SYS_CONFIG *sys_config         = (HostCmd_DS_SYS_CONFIG *)&cmd->params.sys_config;
382     MrvlIEtypes_channel_band_t *chan_band_tlv = MNULL, *pdat_tlv_cb = MNULL;
383     MrvlIEtypes_max_sta_count_t *max_sta_cnt_tlv = MNULL, *pdat_tlv_ccb = MNULL;
384     mlan_ds_misc_custom_ie *cust_ie = MNULL;
385     MrvlIEtypesHeader_t *ie_header  = (MrvlIEtypesHeader_t *)sys_config->tlv_buffer;
386     t_u8 *ie                        = (t_u8 *)sys_config->tlv_buffer + sizeof(MrvlIEtypesHeader_t);
387     t_u16 req_len = 0, travel_len = 0;
388     custom_ie *cptr = MNULL;
389 
390 #if CONFIG_ECSA
391     MrvlIEtypes_action_chan_switch_t *tlv_chan_switch = MNULL;
392     IEEEtypes_ChanSwitchAnn_t *csa_ie                 = MNULL;
393     IEEEtypes_ExtChanSwitchAnn_t *ecsa_ie             = MNULL;
394 #endif
395 
396     mlan_status ret = MLAN_STATUS_SUCCESS;
397 
398     ENTER();
399 
400     cmd->command       = wlan_cpu_to_le16(HOST_CMD_APCMD_SYS_CONFIGURE);
401     sys_config->action = wlan_cpu_to_le16(cmd_action);
402     cmd->size          = wlan_cpu_to_le16(sizeof(HostCmd_DS_SYS_CONFIG) - 1U + S_DS_GEN);
403     if (pioctl_buf == MNULL)
404     {
405         if (pdata_buf != NULL)
406         {
407             switch (*(t_u16 *)pdata_buf)
408             {
409                 case TLV_TYPE_UAP_CHAN_BAND_CONFIG:
410                     pdat_tlv_cb                = (MrvlIEtypes_channel_band_t *)pdata_buf;
411                     chan_band_tlv              = (MrvlIEtypes_channel_band_t *)(void *)sys_config->tlv_buffer;
412                     cmd->size                  = wlan_cpu_to_le16(sizeof(HostCmd_DS_SYS_CONFIG) - 1U + S_DS_GEN +
413                                                                   sizeof(MrvlIEtypes_channel_band_t));
414                     chan_band_tlv->header.type = wlan_cpu_to_le16(TLV_TYPE_UAP_CHAN_BAND_CONFIG);
415                     chan_band_tlv->header.len =
416                         wlan_cpu_to_le16(sizeof(MrvlIEtypes_channel_band_t) - sizeof(MrvlIEtypesHeader_t));
417                     if (cmd_action != 0U)
418                     {
419                         chan_band_tlv->band_config = pdat_tlv_cb->band_config;
420                         chan_band_tlv->channel     = pdat_tlv_cb->channel;
421                     }
422                     ret = MLAN_STATUS_SUCCESS;
423                     break;
424                 case TLV_TYPE_UAP_MAX_STA_CNT:
425                     pdat_tlv_ccb                 = (MrvlIEtypes_max_sta_count_t *)pdata_buf;
426                     max_sta_cnt_tlv              = (MrvlIEtypes_max_sta_count_t *)(void *)sys_config->tlv_buffer;
427                     cmd->size                    = wlan_cpu_to_le16(sizeof(HostCmd_DS_SYS_CONFIG) - 1U + S_DS_GEN +
428                                                                     sizeof(MrvlIEtypes_max_sta_count_t));
429                     max_sta_cnt_tlv->header.type = wlan_cpu_to_le16(TLV_TYPE_UAP_MAX_STA_CNT);
430 
431                     if (cmd_action != 0U)
432                     {
433                         max_sta_cnt_tlv->header.len =
434                             wlan_cpu_to_le16(sizeof(MrvlIEtypes_max_sta_count_t) - sizeof(MrvlIEtypesHeader_t));
435                         max_sta_cnt_tlv->max_sta_count = pdat_tlv_ccb->max_sta_count;
436                     }
437                     else
438                     {
439                         max_sta_cnt_tlv->header.len    = 0;
440                         max_sta_cnt_tlv->max_sta_count = 0;
441                     }
442                     ret = MLAN_STATUS_SUCCESS;
443                     break;
444                 case TLV_TYPE_MGMT_IE:
445                     cust_ie         = (mlan_ds_misc_custom_ie *)pdata_buf;
446                     cmd->size       = wlan_cpu_to_le16(sizeof(HostCmd_DS_SYS_CONFIG) - 1 + S_DS_GEN +
447                                                        sizeof(MrvlIEtypesHeader_t) + cust_ie->len);
448                     ie_header->type = wlan_cpu_to_le16(TLV_TYPE_MGMT_IE);
449                     ie_header->len  = wlan_cpu_to_le16(cust_ie->len);
450 
451                     if (ie)
452                     {
453                         req_len    = cust_ie->len;
454                         travel_len = 0;
455                         /* conversion for index, mask, len */
456                         if (req_len == sizeof(t_u16))
457                             cust_ie->ie_data_list[0].ie_index = wlan_cpu_to_le16(cust_ie->ie_data_list[0].ie_index);
458                         while (req_len > sizeof(t_u16))
459                         {
460                             cptr = (custom_ie *)(((t_u8 *)&cust_ie->ie_data_list) + travel_len);
461                             travel_len += cptr->ie_length + sizeof(custom_ie) - MAX_IE_SIZE;
462                             req_len -= cptr->ie_length + sizeof(custom_ie) - MAX_IE_SIZE;
463                             cptr->ie_index          = wlan_cpu_to_le16(cptr->ie_index);
464                             cptr->mgmt_subtype_mask = wlan_cpu_to_le16(cptr->mgmt_subtype_mask);
465                             cptr->ie_length         = wlan_cpu_to_le16(cptr->ie_length);
466                         }
467                         (void)__memcpy(pmpriv->adapter, ie, cust_ie->ie_data_list, cust_ie->len);
468                     }
469                     break;
470                 default:
471                     PRINTM(MERROR, "Wrong data, or missing TLV_TYPE 0x%04x handler.\n", *(t_u16 *)pdata_buf);
472                     break;
473             }
474             goto done;
475         }
476     }
477 
478     if (pioctl_buf->req_id == (t_u32)MLAN_IOCTL_BSS)
479     {
480         bss = (mlan_ds_bss *)(void *)pioctl_buf->pbuf;
481         if ((bss->sub_command == MLAN_OID_UAP_BSS_CONFIG) && (cmd_action == HostCmd_ACT_GEN_SET))
482         {
483             ret = wlan_uap_cmd_ap_config(pmpriv, cmd, cmd_action, pioctl_buf);
484             goto done;
485         }
486 #if CONFIG_ECSA
487         else if (bss->sub_command == MLAN_OID_ACTION_CHAN_SWITCH)
488         {
489             cmd->size       = sizeof(HostCmd_DS_SYS_CONFIG) - 1 + S_DS_GEN + sizeof(MrvlIEtypes_action_chan_switch_t);
490             tlv_chan_switch = (MrvlIEtypes_action_chan_switch_t *)sys_config->tlv_buffer;
491             tlv_chan_switch->header.type = wlan_cpu_to_le16(MRVL_ACTION_CHAN_SWITCH_ANNOUNCE);
492             // mode reserve for future use
493             tlv_chan_switch->mode = 0;
494             if (bss->param.chanswitch.new_oper_class)
495             {
496                 tlv_chan_switch->header.len =
497                     wlan_cpu_to_le16(sizeof(MrvlIEtypes_action_chan_switch_t) - sizeof(MrvlIEtypesHeader_t) +
498                                      sizeof(IEEEtypes_ExtChanSwitchAnn_t));
499                 ecsa_ie                    = (IEEEtypes_ExtChanSwitchAnn_t *)tlv_chan_switch->ie_buf;
500                 ecsa_ie->element_id        = EXTEND_CHANNEL_SWITCH_ANN;
501                 ecsa_ie->len               = sizeof(IEEEtypes_ExtChanSwitchAnn_t) - sizeof(IEEEtypes_Header_t);
502                 ecsa_ie->chan_switch_mode  = bss->param.chanswitch.chan_switch_mode;
503                 ecsa_ie->chan_switch_count = bss->param.chanswitch.chan_switch_count;
504                 ecsa_ie->new_channel_num   = bss->param.chanswitch.new_channel_num;
505                 ecsa_ie->new_oper_class    = bss->param.chanswitch.new_oper_class;
506                 cmd->size += sizeof(IEEEtypes_ExtChanSwitchAnn_t);
507             }
508             else
509             {
510                 tlv_chan_switch->header.len =
511                     wlan_cpu_to_le16(sizeof(MrvlIEtypes_action_chan_switch_t) - sizeof(MrvlIEtypesHeader_t) +
512                                      sizeof(IEEEtypes_ChanSwitchAnn_t));
513                 csa_ie                    = (IEEEtypes_ChanSwitchAnn_t *)tlv_chan_switch->ie_buf;
514                 csa_ie->element_id        = CHANNEL_SWITCH_ANN;
515                 csa_ie->len               = sizeof(IEEEtypes_ChanSwitchAnn_t) - sizeof(IEEEtypes_Header_t);
516                 csa_ie->chan_switch_mode  = bss->param.chanswitch.chan_switch_mode;
517                 csa_ie->chan_switch_count = bss->param.chanswitch.chan_switch_count;
518                 csa_ie->new_channel_num   = bss->param.chanswitch.new_channel_num;
519                 cmd->size += sizeof(IEEEtypes_ChanSwitchAnn_t);
520             }
521             cmd->size = wlan_cpu_to_le16(cmd->size);
522         }
523 #endif
524         else
525         { /* Do Nothing */
526         }
527     }
528     else
529     {
530         goto done;
531     }
532 done:
533     LEAVE();
534     return ret;
535 }
536 
537 /**
538  *  @brief This function prepares command of snmp_mib
539  *
540  *  @param pmpriv		A pointer to mlan_private structure
541  *  @param cmd	   		A pointer to HostCmd_DS_COMMAND structure
542  *  @param cmd_action   the action: GET or SET
543  *  @param cmd_oid      Cmd oid: treated as sub command
544  *  @param pioctl_buf   A pointer to mlan_ioctl_req structure
545  *  @param pdata_buf    A pointer to information buffer
546  *  @return         MLAN_STATUS_SUCCESS or MLAN_STATUS_FAILURE
547  */
wlan_uap_cmd_snmp_mib(pmlan_private pmpriv,IN HostCmd_DS_COMMAND * cmd,IN t_u16 cmd_action,IN t_u32 cmd_oid,IN pmlan_ioctl_req pioctl_buf,IN t_void * pdata_buf)548 static mlan_status wlan_uap_cmd_snmp_mib(pmlan_private pmpriv,
549                                          IN HostCmd_DS_COMMAND *cmd,
550                                          IN t_u16 cmd_action,
551                                          IN t_u32 cmd_oid,
552                                          IN pmlan_ioctl_req pioctl_buf,
553                                          IN t_void *pdata_buf)
554 {
555     HostCmd_DS_802_11_SNMP_MIB *psnmp_mib = &cmd->params.smib;
556     mlan_status ret                       = MLAN_STATUS_SUCCESS;
557     t_u8 *psnmp_oid                       = MNULL;
558 #if (CONFIG_WIFI_FRAG_THRESHOLD) || (CONFIG_WIFI_RTS_THRESHOLD)
559     t_u32 ul_temp;
560 #endif
561     t_u8 i;
562 
563     t_u8 snmp_oids[] = {
564         (t_u8)tkip_mic_failures,
565         (t_u8)ccmp_decrypt_errors,
566         (t_u8)wep_undecryptable_count,
567         (t_u8)wep_icv_error_count,
568         (t_u8)decrypt_failure_count,
569         (t_u8)dot11_mcast_tx_count,
570         (t_u8)dot11_failed_count,
571         (t_u8)dot11_retry_count,
572         (t_u8)dot11_multi_retry_count,
573         (t_u8)dot11_frame_dup_count,
574         (t_u8)dot11_rts_success_count,
575         (t_u8)dot11_rts_failure_count,
576         (t_u8)dot11_ack_failure_count,
577         (t_u8)dot11_rx_fragment_count,
578         (t_u8)dot11_mcast_rx_frame_count,
579         (t_u8)dot11_fcs_error_count,
580         (t_u8)dot11_tx_frame_count,
581         (t_u8)dot11_rsna_tkip_cm_invoked,
582         (t_u8)dot11_rsna_4way_hshk_failures,
583     };
584 
585     ENTER();
586 
587     if (cmd_action == HostCmd_ACT_GEN_GET)
588     {
589         cmd->command          = wlan_cpu_to_le16(HostCmd_CMD_802_11_SNMP_MIB);
590         psnmp_mib->query_type = wlan_cpu_to_le16(HostCmd_ACT_GEN_GET);
591         if (cmd_oid == (t_u32)StopDeauth_i)
592         {
593             psnmp_mib->oid      = wlan_cpu_to_le16((t_u16)StopDeauth_i);
594             psnmp_mib->buf_size = wlan_cpu_to_le16(sizeof(t_u8));
595             cmd->size           = wlan_cpu_to_le16(sizeof(HostCmd_DS_802_11_SNMP_MIB) + S_DS_GEN);
596         }
597         else
598         {
599             cmd->size = wlan_cpu_to_le16(sizeof(t_u16) + S_DS_GEN + sizeof(snmp_oids) * sizeof(MrvlIEtypes_snmp_oid_t));
600             psnmp_oid = (t_u8 *)&psnmp_mib->oid;
601             for (i = 0; i < sizeof(snmp_oids); i++)
602             {
603                 /* SNMP OID header type */
604                 // coverity[overrun-local:SUPPRESS]
605                 *(t_u16 *)(void *)psnmp_oid = wlan_cpu_to_le16(snmp_oids[i]);
606                 psnmp_oid += sizeof(t_u16);
607                 /* SNMP OID header length */
608                 *(t_u16 *)(void *)psnmp_oid = wlan_cpu_to_le16(sizeof(t_u32));
609                 psnmp_oid += sizeof(t_u16) + sizeof(t_u32);
610             }
611         }
612     }
613     else
614     { /* cmd_action == ACT_SET */
615         cmd->command          = wlan_cpu_to_le16(HostCmd_CMD_802_11_SNMP_MIB);
616         cmd->size             = sizeof(HostCmd_DS_802_11_SNMP_MIB) - 1U + S_DS_GEN;
617         psnmp_mib->query_type = wlan_cpu_to_le16(HostCmd_ACT_GEN_SET);
618 
619         switch (cmd_oid)
620         {
621             case Dot11D_i:
622             case Dot11H_i:
623                 psnmp_mib->oid      = wlan_cpu_to_le16((t_u16)cmd_oid);
624                 psnmp_mib->buf_size = wlan_cpu_to_le16(sizeof(t_u16));
625                 // ul_temp = *(t_u32 *) pdata_buf;
626                 //*((t_u16 *) (psnmp_mib->value)) = wlan_cpu_to_le16((t_u16) ul_temp);
627                 cmd->size += (t_u16)sizeof(t_u16);
628                 break;
629             case StopDeauth_i:
630                 psnmp_mib->oid      = wlan_cpu_to_le16((t_u16)cmd_oid);
631                 psnmp_mib->buf_size = wlan_cpu_to_le16(sizeof(t_u8));
632                 psnmp_mib->value[0] = *((t_u8 *)pdata_buf);
633                 cmd->size += (t_u16)sizeof(t_u8);
634                 break;
635 #if CONFIG_WIFI_FRAG_THRESHOLD
636             case FragThresh_i:
637                 psnmp_mib->oid                 = wlan_cpu_to_le16((t_u16)FragThresh_i);
638                 psnmp_mib->buf_size            = wlan_cpu_to_le16(sizeof(t_u16));
639                 ul_temp                        = *((t_u32 *)pdata_buf);
640                 *((t_u16 *)(psnmp_mib->value)) = wlan_cpu_to_le16((t_u16)ul_temp);
641                 cmd->size += sizeof(t_u16);
642                 break;
643 #endif
644 #if CONFIG_WIFI_RTS_THRESHOLD
645             case RtsThresh_i:
646                 psnmp_mib->oid                 = wlan_cpu_to_le16((t_u16)RtsThresh_i);
647                 psnmp_mib->buf_size            = wlan_cpu_to_le16(sizeof(t_u16));
648                 ul_temp                        = *((t_u32 *)pdata_buf);
649                 *((t_u16 *)(psnmp_mib->value)) = wlan_cpu_to_le16((t_u16)ul_temp);
650                 cmd->size += sizeof(t_u16);
651                 break;
652 #endif
653             default:
654                 PRINTM(MERROR, "Unsupported OID.\n");
655                 ret = MLAN_STATUS_FAILURE;
656                 break;
657         }
658         cmd->size = wlan_cpu_to_le16(cmd->size);
659     }
660 
661     LEAVE();
662     return ret;
663 }
664 
665 /**
666  *  @brief This function prepares command of deauth station
667  *
668  *  @param pmpriv		A pointer to mlan_private structure
669  *  @param cmd	   		A pointer to HostCmd_DS_COMMAND structure
670  *  @param pdata_buf    A pointer to data buffer
671  *  @return         MLAN_STATUS_SUCCESS
672  */
wlan_uap_cmd_sta_deauth(pmlan_private pmpriv,IN HostCmd_DS_COMMAND * cmd,IN t_void * pdata_buf)673 static mlan_status wlan_uap_cmd_sta_deauth(pmlan_private pmpriv, IN HostCmd_DS_COMMAND *cmd, IN t_void *pdata_buf)
674 {
675     HostCmd_DS_STA_DEAUTH *pcmd_sta_deauth = (HostCmd_DS_STA_DEAUTH *)&cmd->params.sta_deauth;
676     mlan_deauth_param *deauth              = (mlan_deauth_param *)pdata_buf;
677 
678     ENTER();
679     cmd->command = wlan_cpu_to_le16(HOST_CMD_APCMD_STA_DEAUTH);
680     cmd->size    = wlan_cpu_to_le16(S_DS_GEN + sizeof(HostCmd_DS_STA_DEAUTH));
681     (void)__memcpy(pmpriv->adapter, pcmd_sta_deauth->mac, deauth->mac_addr, MLAN_MAC_ADDR_LENGTH);
682     pcmd_sta_deauth->reason = wlan_cpu_to_le16(deauth->reason_code);
683     LEAVE();
684     return MLAN_STATUS_SUCCESS;
685 }
686 
687 #if defined(WAPI_AP) || defined(HOST_AUTHENTICATOR) || (CONFIG_WPA_SUPP_AP)
688 /**
689  *  @brief This function prepares command of key material
690  *
691  *  @param pmpriv       A pointer to mlan_private structure
692  *  @param cmd          A pointer to HostCmd_DS_COMMAND structure
693  *  @param cmd_action   The action: GET or SET
694  *  @param cmd_oid      OID: ENABLE or DISABLE
695  *  @param pdata_buf    A pointer to data buffer
696  *  @return             MLAN_STATUS_SUCCESS
697  */
wlan_uap_cmd_key_material(pmlan_private pmpriv,HostCmd_DS_COMMAND * cmd,t_u16 cmd_action,t_u16 cmd_oid,t_void * pdata_buf)698 static mlan_status wlan_uap_cmd_key_material(
699     pmlan_private pmpriv, HostCmd_DS_COMMAND *cmd, t_u16 cmd_action, t_u16 cmd_oid, t_void *pdata_buf)
700 {
701     HostCmd_DS_802_11_KEY_MATERIAL *pkey_material = &cmd->params.key_material;
702     mlan_ds_encrypt_key *pkey                     = (mlan_ds_encrypt_key *)pdata_buf;
703     mlan_status ret                               = MLAN_STATUS_SUCCESS;
704 #ifdef WAPI_AP
705     sta_node *sta_ptr = MNULL;
706 #endif
707 
708     ENTER();
709     if (!pkey)
710     {
711         ret = MLAN_STATUS_FAILURE;
712         goto done;
713     }
714     cmd->command          = wlan_cpu_to_le16(HostCmd_CMD_802_11_KEY_MATERIAL);
715     pkey_material->action = wlan_cpu_to_le16(cmd_action);
716     if (cmd_action == HostCmd_ACT_GEN_GET)
717     {
718         cmd->size = wlan_cpu_to_le16(sizeof(pkey_material->action) + S_DS_GEN);
719         goto done;
720     }
721     memset(&pkey_material->key_param_set, 0, sizeof(MrvlIEtype_KeyParamSetV2_t));
722     if (pkey->key_flags & KEY_FLAG_REMOVE_KEY)
723     {
724         pkey_material->action                 = wlan_cpu_to_le16(HostCmd_ACT_GEN_REMOVE);
725         pkey_material->key_param_set.type     = wlan_cpu_to_le16(TLV_TYPE_KEY_PARAM_V2);
726         pkey_material->key_param_set.length   = wlan_cpu_to_le16(KEY_PARAMS_FIXED_LEN);
727         pkey_material->key_param_set.key_idx  = pkey->key_index & KEY_INDEX_MASK;
728         pkey_material->key_param_set.key_info = wlan_cpu_to_le16(KEY_INFO_MCAST_KEY | KEY_INFO_UCAST_KEY);
729         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.mac_addr, pkey->mac_addr, MLAN_MAC_ADDR_LENGTH,
730                    MLAN_MAC_ADDR_LENGTH);
731         cmd->size = wlan_cpu_to_le16(sizeof(MrvlIEtypesHeader_t) + S_DS_GEN + KEY_PARAMS_FIXED_LEN +
732                                      sizeof(pkey_material->action));
733         wifi_d("Remove Key");
734         goto done;
735     }
736     pkey_material->action                 = wlan_cpu_to_le16(HostCmd_ACT_GEN_SET);
737     pkey_material->key_param_set.key_idx  = pkey->key_index & KEY_INDEX_MASK;
738     pkey_material->key_param_set.type     = wlan_cpu_to_le16(TLV_TYPE_KEY_PARAM_V2);
739     pkey_material->key_param_set.key_info = KEY_INFO_ENABLE_KEY;
740     memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.mac_addr, pkey->mac_addr, MLAN_MAC_ADDR_LENGTH,
741                MLAN_MAC_ADDR_LENGTH);
742     if (pkey->key_len <= MAX_WEP_KEY_SIZE)
743     {
744         pkey_material->key_param_set.length   = wlan_cpu_to_le16(KEY_PARAMS_FIXED_LEN + sizeof(wep_param_t));
745         pkey_material->key_param_set.key_type = KEY_TYPE_ID_WEP;
746         pkey_material->key_param_set.key_info |= KEY_INFO_MCAST_KEY | KEY_INFO_UCAST_KEY;
747         if (pkey_material->key_param_set.key_idx == (pmpriv->wep_key_curr_index & KEY_INDEX_MASK))
748             pkey_material->key_param_set.key_info |= KEY_INFO_DEFAULT_KEY;
749         pkey_material->key_param_set.key_info               = wlan_cpu_to_le16(pkey_material->key_param_set.key_info);
750         pkey_material->key_param_set.key_params.wep.key_len = wlan_cpu_to_le16(pkey->key_len);
751         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.wep.key, pkey->key_material, pkey->key_len,
752                    MAX_WEP_KEY_SIZE);
753         cmd->size = wlan_cpu_to_le16(sizeof(MrvlIEtypesHeader_t) + S_DS_GEN + KEY_PARAMS_FIXED_LEN +
754                                      sizeof(wep_param_t) + sizeof(pkey_material->action));
755         wifi_d("Set WEP Key");
756         goto done;
757     }
758     if (pkey->key_flags & KEY_FLAG_GROUP_KEY)
759         pkey_material->key_param_set.key_info |= KEY_INFO_MCAST_KEY;
760     else
761         pkey_material->key_param_set.key_info |= KEY_INFO_UCAST_KEY;
762 #ifdef ENABLE_802_11W
763     if (pkey->key_flags & KEY_FLAG_AES_MCAST_IGTK)
764         pkey_material->key_param_set.key_info |= KEY_INFO_CMAC_AES_KEY;
765 #endif
766     if (pkey->key_flags & KEY_FLAG_SET_TX_KEY)
767         pkey_material->key_param_set.key_info |= KEY_INFO_TX_KEY | KEY_INFO_RX_KEY;
768     else
769         pkey_material->key_param_set.key_info |= KEY_INFO_TX_KEY;
770 #ifdef WAPI_AP
771     if (pkey->is_wapi_key)
772     {
773         pkey_material->key_param_set.key_type = KEY_TYPE_ID_WAPI;
774         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.wapi.pn, pkey->pn, PN_SIZE, PN_SIZE);
775         pkey_material->key_param_set.key_params.wapi.key_len = wlan_cpu_to_le16(MIN(WAPI_KEY_SIZE, pkey->key_len));
776         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.wapi.key, pkey->key_material, pkey->key_len,
777                    WAPI_KEY_SIZE);
778         if (!pmpriv->sec_info.wapi_key_on)
779             pkey_material->key_param_set.key_info |= KEY_INFO_DEFAULT_KEY;
780         if (pkey->key_flags & KEY_FLAG_GROUP_KEY)
781         {
782             pmpriv->sec_info.wapi_key_on = MTRUE;
783         }
784         else
785         {
786             /* WAPI pairwise key: unicast */
787             sta_ptr = wlan_add_station_entry(pmpriv, pkey->mac_addr);
788             if (sta_ptr)
789             {
790                 wifi_d("station: wapi_key_on");
791                 sta_ptr->wapi_key_on = MTRUE;
792             }
793         }
794         pkey_material->key_param_set.key_info = wlan_cpu_to_le16(pkey_material->key_param_set.key_info);
795         pkey_material->key_param_set.length   = wlan_cpu_to_le16(KEY_PARAMS_FIXED_LEN + sizeof(wapi_param));
796         cmd->size = wlan_cpu_to_le16(sizeof(MrvlIEtypesHeader_t) + S_DS_GEN + KEY_PARAMS_FIXED_LEN +
797                                      sizeof(wapi_param) + sizeof(pkey_material->action));
798         wifi_d("Set WAPI Key");
799         goto done;
800     }
801 #endif
802     pkey_material->key_param_set.key_info |= KEY_INFO_DEFAULT_KEY;
803     pkey_material->key_param_set.key_info = wlan_cpu_to_le16(pkey_material->key_param_set.key_info);
804     if (pkey->key_flags & KEY_FLAG_GCMP || pkey->key_flags & KEY_FLAG_GCMP_256)
805     {
806         if (pkey->key_flags & (KEY_FLAG_RX_SEQ_VALID | KEY_FLAG_TX_SEQ_VALID))
807         {
808             memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.gcmp.pn, pkey->pn, SEQ_MAX_SIZE,
809                        WPA_PN_SIZE);
810         }
811         if (pkey->key_flags & KEY_FLAG_GCMP)
812             pkey_material->key_param_set.key_type = KEY_TYPE_ID_GCMP;
813         else
814             pkey_material->key_param_set.key_type = KEY_TYPE_ID_GCMP_256;
815         pkey_material->key_param_set.key_params.gcmp.key_len = wlan_cpu_to_le16(pkey->key_len);
816         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.gcmp.key, pkey->key_material, pkey->key_len,
817                    WPA_GCMP_KEY_LEN);
818         pkey_material->key_param_set.length = wlan_cpu_to_le16(KEY_PARAMS_FIXED_LEN + sizeof(gcmp_param));
819         cmd->size = wlan_cpu_to_le16(sizeof(MrvlIEtypesHeader_t) + S_DS_GEN + KEY_PARAMS_FIXED_LEN +
820                                      sizeof(gcmp_param) + sizeof(pkey_material->action));
821         PRINTM(MCMND, "Set GCMP Key\n");
822         goto done;
823     }
824     if (pkey->key_flags & KEY_FLAG_CCMP_256)
825     {
826         if (pkey->key_flags & (KEY_FLAG_RX_SEQ_VALID | KEY_FLAG_TX_SEQ_VALID))
827         {
828             memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.ccmp256.pn, pkey->pn, SEQ_MAX_SIZE,
829                        WPA_PN_SIZE);
830         }
831         pkey_material->key_param_set.key_type                   = KEY_TYPE_ID_CCMP_256;
832         pkey_material->key_param_set.key_params.ccmp256.key_len = wlan_cpu_to_le16(pkey->key_len);
833         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.ccmp256.key, pkey->key_material,
834                    pkey->key_len, WPA_CCMP_256_KEY_LEN);
835         pkey_material->key_param_set.length = wlan_cpu_to_le16(KEY_PARAMS_FIXED_LEN + sizeof(ccmp_256_param));
836         cmd->size = wlan_cpu_to_le16(sizeof(MrvlIEtypesHeader_t) + S_DS_GEN + KEY_PARAMS_FIXED_LEN +
837                                      sizeof(ccmp_256_param) + sizeof(pkey_material->action));
838         PRINTM(MCMND, "Set CCMP256 Key\n");
839         goto done;
840     }
841 #ifdef ENABLE_802_11W
842     if (pkey->key_len == WPA_AES_KEY_LEN && !(pkey->key_flags & KEY_FLAG_AES_MCAST_IGTK))
843     {
844 #else
845     if (pkey->key_len == WPA_AES_KEY_LEN)
846     {
847 #endif
848         if (pkey->key_flags & (KEY_FLAG_RX_SEQ_VALID | KEY_FLAG_TX_SEQ_VALID))
849             memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.aes.pn, pkey->pn, SEQ_MAX_SIZE,
850                        WPA_PN_SIZE);
851         pkey_material->key_param_set.key_type               = KEY_TYPE_ID_AES;
852         pkey_material->key_param_set.key_params.aes.key_len = wlan_cpu_to_le16(pkey->key_len);
853         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.aes.key, pkey->key_material, pkey->key_len,
854                    WPA_AES_KEY_LEN);
855         pkey_material->key_param_set.length = wlan_cpu_to_le16(KEY_PARAMS_FIXED_LEN + sizeof(aes_param));
856         cmd->size = wlan_cpu_to_le16(sizeof(MrvlIEtypesHeader_t) + S_DS_GEN + KEY_PARAMS_FIXED_LEN + sizeof(aes_param) +
857                                      sizeof(pkey_material->action));
858         wifi_d("Set AES Key");
859         goto done;
860     }
861 #ifdef ENABLE_802_11W
862     if (pkey->key_len == WPA_IGTK_KEY_LEN && (pkey->key_flags & KEY_FLAG_AES_MCAST_IGTK))
863     {
864         if (pkey->key_flags & (KEY_FLAG_RX_SEQ_VALID | KEY_FLAG_TX_SEQ_VALID))
865             memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.cmac_aes.ipn, pkey->pn, SEQ_MAX_SIZE,
866                        IGTK_PN_SIZE);
867         pkey_material->key_param_set.key_info &= ~(wlan_cpu_to_le16(KEY_INFO_MCAST_KEY));
868         pkey_material->key_param_set.key_info |= wlan_cpu_to_le16(KEY_INFO_AES_MCAST_IGTK);
869         if (pkey->key_flags & KEY_FLAG_GMAC_128)
870             pkey_material->key_param_set.key_type = KEY_TYPE_ID_BIP_GMAC_128;
871         else
872             pkey_material->key_param_set.key_type = KEY_TYPE_ID_AES_CMAC;
873         pkey_material->key_param_set.key_params.cmac_aes.key_len = wlan_cpu_to_le16(pkey->key_len);
874         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.cmac_aes.key, pkey->key_material,
875                    pkey->key_len, CMAC_AES_KEY_LEN);
876         pkey_material->key_param_set.length = wlan_cpu_to_le16(KEY_PARAMS_FIXED_LEN + sizeof(cmac_aes_param));
877         cmd->size = wlan_cpu_to_le16(sizeof(MrvlIEtypesHeader_t) + S_DS_GEN + KEY_PARAMS_FIXED_LEN +
878                                      sizeof(cmac_aes_param) + sizeof(pkey_material->action));
879         if (pkey->key_flags & KEY_FLAG_GMAC_128)
880             PRINTM(MCMND, "Set AES 128 GMAC Key\n");
881         else
882             PRINTM(MCMND, "Set CMAC AES Key\n");
883         goto done;
884     }
885     if (pkey->key_len == WPA_IGTK_256_KEY_LEN && (pkey->key_flags & KEY_FLAG_AES_MCAST_IGTK))
886     {
887         if (pkey->key_flags & (KEY_FLAG_RX_SEQ_VALID | KEY_FLAG_TX_SEQ_VALID))
888             memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.gmac_aes.ipn, pkey->pn, SEQ_MAX_SIZE,
889                        IGTK_PN_SIZE);
890         pkey_material->key_param_set.key_info &= ~(wlan_cpu_to_le16(KEY_INFO_MCAST_KEY));
891         pkey_material->key_param_set.key_info |= wlan_cpu_to_le16(KEY_INFO_AES_MCAST_IGTK);
892         pkey_material->key_param_set.key_type                    = KEY_TYPE_ID_BIP_GMAC_256;
893         pkey_material->key_param_set.key_params.gmac_aes.key_len = wlan_cpu_to_le16(pkey->key_len);
894         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.gmac_aes.key, pkey->key_material,
895                    pkey->key_len, WPA_IGTK_256_KEY_LEN);
896         pkey_material->key_param_set.length = wlan_cpu_to_le16(KEY_PARAMS_FIXED_LEN + sizeof(gmac_aes_256_param));
897         cmd->size = wlan_cpu_to_le16(sizeof(MrvlIEtypesHeader_t) + S_DS_GEN + KEY_PARAMS_FIXED_LEN +
898                                      sizeof(gmac_aes_256_param) + sizeof(pkey_material->action));
899         PRINTM(MCMND, "Set AES 256 GMAC Key\n");
900         goto done;
901     }
902 #endif
903     if (pkey->key_len == WPA_TKIP_KEY_LEN)
904     {
905         if (pkey->key_flags & (KEY_FLAG_RX_SEQ_VALID | KEY_FLAG_TX_SEQ_VALID))
906             memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.tkip.pn, pkey->pn, SEQ_MAX_SIZE,
907                        WPA_PN_SIZE);
908         pkey_material->key_param_set.key_type                = KEY_TYPE_ID_TKIP;
909         pkey_material->key_param_set.key_params.tkip.key_len = wlan_cpu_to_le16(pkey->key_len);
910         memcpy_ext(pmpriv->adapter, pkey_material->key_param_set.key_params.tkip.key, pkey->key_material, pkey->key_len,
911                    WPA_TKIP_KEY_LEN);
912         pkey_material->key_param_set.length = wlan_cpu_to_le16(KEY_PARAMS_FIXED_LEN + sizeof(tkip_param));
913         cmd->size = wlan_cpu_to_le16(sizeof(MrvlIEtypesHeader_t) + S_DS_GEN + KEY_PARAMS_FIXED_LEN +
914                                      sizeof(tkip_param) + sizeof(pkey_material->action));
915         PRINTM(MCMND, "Set TKIP Key\n");
916     }
917 done:
918     LEAVE();
919     return ret;
920 }
921 
922 #endif /* WAPI_AP || HOST_AUTHENTICATOR || CONFIG_WPA_SUPP_AP */
923 
924 /**
925  *  @brief This function will search for the specific ie
926  *
927  *
928  *  @param priv    A pointer to mlan_private
929  *  @param pevent  A pointer to event buf
930  *  @param sta_ptr A pointer to sta_node
931  *
932  *  @return	       N/A
933  */
934 void wlan_check_sta_capability(pmlan_private priv, pmlan_buffer pevent, sta_node *sta_ptr)
935 {
936     t_u16 tlv_type, tlv_len;
937     t_u16 frame_control, frame_sub_type = 0;
938     t_u8 *assoc_req_ie = MNULL;
939     t_u8 ie_len = 0, assoc_ie_len = 0;
940     IEEEtypes_HTCap_t *pht_cap = MNULL;
941     int tlv_buf_left           = pevent->data_len - ASSOC_EVENT_FIX_SIZE;
942     MrvlIEtypesHeader_t *tlv   = (MrvlIEtypesHeader_t *)(pevent->pbuf + pevent->data_offset + ASSOC_EVENT_FIX_SIZE);
943     MrvlIETypes_MgmtFrameSet_t *mgmt_tlv = MNULL;
944 
945     ENTER();
946     while (tlv_buf_left >= (int)sizeof(MrvlIEtypesHeader_t))
947     {
948         tlv_type = wlan_le16_to_cpu(tlv->type);
949         tlv_len  = wlan_le16_to_cpu(tlv->len);
950         if ((sizeof(MrvlIEtypesHeader_t) + tlv_len) > (unsigned int)tlv_buf_left)
951         {
952             wifi_d("wrong tlv: tlvLen=%d, tlvBufLeft=%d", tlv_len, tlv_buf_left);
953             break;
954         }
955         if (tlv_type == TLV_TYPE_UAP_MGMT_FRAME)
956         {
957             mgmt_tlv = (MrvlIETypes_MgmtFrameSet_t *)tlv;
958             (void)__memcpy(priv->adapter, &frame_control, (t_u8 *)&(mgmt_tlv->frame_control), sizeof(frame_control));
959             frame_sub_type = IEEE80211_GET_FC_MGMT_FRAME_SUBTYPE(frame_control);
960             if ((mgmt_tlv->frame_control.type == 0) &&
961                 ((frame_sub_type == SUBTYPE_ASSOC_REQUEST) || (frame_sub_type == SUBTYPE_REASSOC_REQUEST)))
962             {
963                 if (frame_sub_type == SUBTYPE_ASSOC_REQUEST)
964                     assoc_ie_len = sizeof(IEEEtypes_AssocRqst_t);
965                 else if (frame_sub_type == SUBTYPE_REASSOC_REQUEST)
966                     assoc_ie_len = sizeof(IEEEtypes_ReAssocRqst_t);
967 
968                 ie_len       = tlv_len - sizeof(IEEEtypes_FrameCtl_t) - assoc_ie_len;
969                 assoc_req_ie = (t_u8 *)tlv + sizeof(MrvlIETypes_MgmtFrameSet_t) + assoc_ie_len;
970                 pht_cap      = (IEEEtypes_HTCap_t *)wlan_get_specific_ie(priv, assoc_req_ie, ie_len, HT_CAPABILITY, 0);
971                 if (pht_cap)
972                 {
973                     wifi_d("STA supports 11n");
974                     sta_ptr->is_11n_enabled = MTRUE;
975                     if (GETHT_MAXAMSDU(pht_cap->ht_cap.ht_cap_info))
976                         sta_ptr->max_amsdu = MLAN_TX_DATA_BUF_SIZE_8K;
977                     else
978                         sta_ptr->max_amsdu = MLAN_TX_DATA_BUF_SIZE_4K;
979                 }
980                 else
981                 {
982                     wifi_d("STA doesn't support 11n");
983                 }
984                 break;
985             }
986         }
987         tlv_buf_left -= (sizeof(MrvlIEtypesHeader_t) + tlv_len);
988         tlv = (MrvlIEtypesHeader_t *)((t_u8 *)tlv + tlv_len + sizeof(MrvlIEtypesHeader_t));
989     }
990     LEAVE();
991 
992     return;
993 }
994 
995 #ifdef UAP_HOST_MLME
996 /**
997  *  @brief	Check 11B support Rates
998  *
999  *
1000  *  @param pmadapter	Private mlan adapter structure
1001  *
1002  *  @return MTRUE/MFALSE
1003  *
1004  */
1005 static t_u8 wlan_check_11B_support_rates(MrvlIEtypes_RatesParamSet_t *prates_tlv)
1006 {
1007     int i;
1008     t_u8 rate;
1009     t_u8 ret = MTRUE;
1010     for (i = 0; i < prates_tlv->header.len; i++)
1011     {
1012         rate = prates_tlv->rates[i] & 0x7f;
1013         if ((rate != 0x02) && (rate != 0x04) && (rate != 0x0b) && (rate != 0x16))
1014         {
1015             ret = MFALSE;
1016             break;
1017         }
1018     }
1019     return ret;
1020 }
1021 
1022 /**
1023  *  @brief This function prepares command of sys_config
1024  *
1025  *  @param pmpriv       A pointer to mlan_private structure
1026  *  @param cmd          A pointer to HostCmd_DS_COMMAND structure
1027  *  @param cmd_action   cmd action
1028  *  @param pioctl_buf   A pointer to mlan_ioctl_req structure
1029  *  @return         MLAN_STATUS_SUCCESS or MLAN_STATUS_FAILURE
1030  */
1031 static mlan_status wlan_uap_cmd_add_station(pmlan_private pmpriv,
1032                                             HostCmd_DS_COMMAND *cmd,
1033                                             t_u16 cmd_action,
1034                                             pmlan_ioctl_req pioctl_buf)
1035 {
1036     mlan_ds_bss *bss                = MNULL;
1037     HostCmd_DS_ADD_STATION *new_sta = (HostCmd_DS_ADD_STATION *)&cmd->params.sta_info;
1038     sta_node *sta_ptr               = MNULL;
1039     t_u16 tlv_buf_left;
1040     t_u8 *pos        = MNULL;
1041     t_u8 *tlv_buf    = MNULL;
1042     t_u16 travel_len = 0;
1043     MrvlIEtypesHeader_t *tlv;
1044     t_u16 tlv_len = 0;
1045     t_u8 b_only   = MFALSE;
1046     MrvlIETypes_HTCap_t *phtcap;
1047 #if CONFIG_11AC
1048     MrvlIETypes_VHTCap_t *pvhtcap;
1049 #endif
1050 #if CONFIG_11AX
1051     MrvlIEtypes_Extension_t *pext_tlv = MNULL;
1052 #endif
1053     MrvlIEtypes_StaFlag_t *pstaflag;
1054     int i;
1055 
1056     ENTER();
1057 
1058     if (!pioctl_buf)
1059     {
1060         LEAVE();
1061         return MLAN_STATUS_FAILURE;
1062     }
1063     (void)__memset(pmpriv->adapter, new_sta, 0x00, sizeof(HostCmd_DS_ADD_STATION));
1064     bss = (mlan_ds_bss *)pioctl_buf->pbuf;
1065 
1066     cmd->command    = wlan_cpu_to_le16(HostCmd_CMD_ADD_NEW_STATION);
1067     new_sta->action = wlan_cpu_to_le16(cmd_action);
1068     cmd->size       = sizeof(HostCmd_DS_ADD_STATION) + S_DS_GEN;
1069     if (cmd_action == HostCmd_ACT_ADD_STA)
1070     {
1071         sta_ptr = wlan_get_station_entry(pmpriv, bss->param.sta_info.peer_mac);
1072         if (!sta_ptr)
1073             sta_ptr = wlan_add_station_entry(pmpriv, bss->param.sta_info.peer_mac);
1074     }
1075     else
1076     {
1077         sta_ptr = wlan_add_station_entry(pmpriv, bss->param.sta_info.peer_mac);
1078     }
1079     if (!sta_ptr)
1080     {
1081         LEAVE();
1082         return MLAN_STATUS_FAILURE;
1083     }
1084 #ifdef EASYMESH
1085     /* Save station aid for multi-ap */
1086     sta_ptr->aid = bss->param.sta_info.aid;
1087 #endif
1088     (void)__memcpy(NULL, new_sta->peer_mac, bss->param.sta_info.peer_mac, MLAN_MAC_ADDR_LENGTH);
1089     if (cmd_action != HostCmd_ACT_ADD_STA)
1090         goto done;
1091     new_sta->aid             = wlan_cpu_to_le16(bss->param.sta_info.aid);
1092     new_sta->listen_interval = wlan_cpu_to_le32(bss->param.sta_info.listen_interval);
1093     if (bss->param.sta_info.cap_info)
1094         new_sta->cap_info = wlan_cpu_to_le16(bss->param.sta_info.cap_info);
1095     else
1096         new_sta->cap_info = wlan_cpu_to_le16(sta_ptr->capability);
1097     tlv_buf_left = bss->param.sta_info.tlv_len;
1098     pos          = new_sta->tlv;
1099     tlv_buf      = bss->param.sta_info.tlv;
1100     tlv          = (MrvlIEtypesHeader_t *)tlv_buf;
1101     if (bss->param.sta_info.sta_flags & STA_FLAG_WME)
1102     {
1103         wifi_d("STA flags supports wmm");
1104         sta_ptr->is_wmm_enabled = MTRUE;
1105     }
1106     // append sta_flag_flags.
1107     pstaflag              = (MrvlIEtypes_StaFlag_t *)pos;
1108     pstaflag->header.type = wlan_cpu_to_le16(TLV_TYPE_UAP_STA_FLAGS);
1109     pstaflag->header.len  = wlan_cpu_to_le16(sizeof(t_u32));
1110     pstaflag->sta_flags   = wlan_cpu_to_le32(bss->param.sta_info.sta_flags);
1111     pos += sizeof(MrvlIEtypes_StaFlag_t);
1112     cmd->size += sizeof(MrvlIEtypes_StaFlag_t);
1113 
1114     while (tlv_buf_left >= sizeof(MrvlIEtypesHeader_t))
1115     {
1116         if (tlv_buf_left < (sizeof(MrvlIEtypesHeader_t) + tlv->len))
1117             break;
1118         switch (tlv->type)
1119         {
1120             case EXT_CAPABILITY:
1121                 break;
1122             case SUPPORTED_RATES:
1123                 b_only = wlan_check_11B_support_rates((MrvlIEtypes_RatesParamSet_t *)tlv);
1124                 break;
1125             case QOS_INFO:
1126                 wifi_d("STA supports wmm");
1127                 sta_ptr->is_wmm_enabled = MTRUE;
1128                 break;
1129             case HT_CAPABILITY:
1130                 wifi_d("STA supports 11n");
1131                 sta_ptr->is_11n_enabled = MTRUE;
1132                 phtcap                  = (MrvlIETypes_HTCap_t *)tlv;
1133                 if (sta_ptr->HTcap.ieee_hdr.element_id == HT_CAPABILITY)
1134                 {
1135                     if (GETHT_40MHZ_INTOLARANT(sta_ptr->HTcap.ht_cap.ht_cap_info))
1136                     {
1137                         wifi_d("SETHT_40MHZ_INTOLARANT");
1138                         SETHT_40MHZ_INTOLARANT(phtcap->ht_cap.ht_cap_info);
1139                     }
1140                 }
1141                 if (GETHT_MAXAMSDU(phtcap->ht_cap.ht_cap_info))
1142                     sta_ptr->max_amsdu = MLAN_TX_DATA_BUF_SIZE_8K;
1143                 else
1144                     sta_ptr->max_amsdu = MLAN_TX_DATA_BUF_SIZE_4K;
1145                 break;
1146 #if CONFIG_11AC
1147             case VHT_CAPABILITY:
1148                 wifi_d("STA supports 11ac");
1149                 sta_ptr->is_11ac_enabled = MTRUE;
1150                 pvhtcap                  = (MrvlIETypes_VHTCap_t *)tlv;
1151                 if (GET_VHTCAP_MAXMPDULEN(pvhtcap->vht_cap.vht_cap_info) == 2)
1152                     sta_ptr->max_amsdu = MLAN_TX_DATA_BUF_SIZE_12K;
1153                 else if (GET_VHTCAP_MAXMPDULEN(pvhtcap->vht_cap.vht_cap_info) == 1)
1154                     sta_ptr->max_amsdu = MLAN_TX_DATA_BUF_SIZE_8K;
1155                 else
1156                     sta_ptr->max_amsdu = MLAN_TX_DATA_BUF_SIZE_4K;
1157                 break;
1158             case OPER_MODE_NTF:
1159                 break;
1160 #endif
1161 #if CONFIG_11AX
1162             case EXTENSION:
1163                 pext_tlv = (MrvlIEtypes_Extension_t *)tlv;
1164                 if (pext_tlv->ext_id == HE_CAPABILITY)
1165                 {
1166                     sta_ptr->is_11ax_enabled = MTRUE;
1167                     wifi_d("STA supports 11ax");
1168                 }
1169 #ifdef ENABLE_802_116E
1170                 else if (pext_tlv->ext_id == HE_6G_CAPABILITY)
1171                 {
1172                     MrvlIEtypes_He_6g_cap_t *phe_6g_cap = MNULL;
1173                     phe_6g_cap                          = (MrvlIEtypes_He_6g_cap_t *)tlv;
1174                     if (GET_6G_BAND_CAP_MAXMPDULEN(phe_6g_cap->capa) == 2)
1175                         pmpriv->max_amsdu = MLAN_TX_DATA_BUF_SIZE_12K;
1176                     else if (GET_6G_BAND_CAP_MAXMPDULEN(phe_6g_cap->capa) == 1)
1177                         pmpriv->max_amsdu = MLAN_TX_DATA_BUF_SIZE_8K;
1178                     else
1179                         pmpriv->max_amsdu = MLAN_TX_DATA_BUF_SIZE_4K;
1180                 }
1181 #endif
1182                 else
1183                 {
1184                     pext_tlv = MNULL;
1185                 }
1186                 break;
1187 #endif
1188             default:
1189                 break;
1190         }
1191         tlv->type = wlan_cpu_to_le16(tlv->type);
1192         tlv->len  = wlan_cpu_to_le16(tlv->len);
1193         tlv_len   = tlv->len;
1194         (void)__memcpy(NULL, pos, (t_u8 *)tlv, sizeof(MrvlIEtypesHeader_t) + tlv_len);
1195         pos += sizeof(MrvlIEtypesHeader_t) + tlv_len;
1196         tlv_buf += sizeof(MrvlIEtypesHeader_t) + tlv_len;
1197         tlv = (MrvlIEtypesHeader_t *)tlv_buf;
1198         travel_len += sizeof(MrvlIEtypesHeader_t) + tlv_len;
1199         tlv_buf_left -= sizeof(MrvlIEtypesHeader_t) + tlv_len;
1200     }
1201 #if CONFIG_11AX
1202     if (sta_ptr->is_11ax_enabled)
1203     {
1204         if (pext_tlv == MNULL)
1205         {
1206             tlv       = (MrvlIEtypesHeader_t *)pos;
1207             tlv->type = wlan_cpu_to_le16(EXTENSION);
1208             tlv->len  = wlan_cpu_to_le16(
1209                 MIN(sta_ptr->he_cap.ieee_hdr.len, sizeof(IEEEtypes_HECap_t) - sizeof(IEEEtypes_Header_t)));
1210 
1211             pos += sizeof(MrvlIEtypesHeader_t);
1212             (void)__memcpy(NULL, pos, (t_u8 *)&sta_ptr->he_cap.ext_id, tlv->len);
1213             travel_len += sizeof(MrvlIEtypesHeader_t) + tlv->len;
1214         }
1215     }
1216 #endif
1217 
1218     if (sta_ptr->is_11n_enabled)
1219     {
1220         if (pmpriv->uap_channel <= 14)
1221             sta_ptr->bandmode = BAND_GN;
1222 #if CONFIG_5GHz_SUPPORT
1223         else
1224             sta_ptr->bandmode = BAND_AN;
1225 #endif
1226     }
1227     else if (!b_only)
1228     {
1229         if (pmpriv->uap_channel <= 14)
1230             sta_ptr->bandmode = BAND_G;
1231 #if CONFIG_5GHz_SUPPORT
1232         else
1233             sta_ptr->bandmode = BAND_A;
1234 #endif
1235     }
1236     else
1237         sta_ptr->bandmode = BAND_B;
1238 #if CONFIG_11AC
1239     if (sta_ptr->is_11ac_enabled)
1240     {
1241         if (pmpriv->uap_channel <= 14)
1242             sta_ptr->bandmode = BAND_GAC;
1243         else
1244             sta_ptr->bandmode = BAND_AAC;
1245     }
1246 #endif
1247 #if CONFIG_11AX
1248     if (sta_ptr->is_11ax_enabled)
1249     {
1250         if (pmpriv->uap_channel <= 14)
1251             sta_ptr->bandmode = BAND_GAX;
1252         else
1253             sta_ptr->bandmode = BAND_AAX;
1254     }
1255 #endif
1256 
1257     for (i = 0; i < MAX_NUM_TID; i++)
1258     {
1259         if (sta_ptr->is_11n_enabled
1260 #if CONFIG_11AX
1261             || sta_ptr->is_11ax_enabled
1262 #endif
1263         )
1264             sta_ptr->ampdu_sta[i] = pmpriv->aggr_prio_tbl[i].ampdu_user;
1265         else
1266             sta_ptr->ampdu_sta[i] = BA_STREAM_NOT_ALLOWED;
1267     }
1268     (void)__memset(pmpriv->adapter, sta_ptr->rx_seq, 0xff, sizeof(sta_ptr->rx_seq));
1269 done:
1270     cmd->size += travel_len;
1271     cmd->size = wlan_cpu_to_le16(cmd->size);
1272     LEAVE();
1273     return MLAN_STATUS_SUCCESS;
1274 }
1275 #endif
1276 
1277 /**
1278  *  @brief This function prepares command of bss_start.
1279  *
1280  * @param pmpriv       A pointer to mlan_private structure
1281  * @param cmd          A pointer to HostCmd_DS_COMMAND structure
1282  *
1283  * @return             MLAN_STATUS_SUCCESS
1284  **/
1285 static mlan_status wlan_uap_cmd_bss_start(pmlan_private pmpriv, HostCmd_DS_COMMAND *cmd)
1286 {
1287 #ifdef UAP_HOST_MLME
1288     MrvlIEtypes_HostMlme_t *tlv;
1289 #endif
1290     ENTER();
1291     cmd->command = wlan_cpu_to_le16(HOST_CMD_APCMD_BSS_START);
1292     cmd->size    = S_DS_GEN;
1293 #ifdef UAP_HOST_MLME
1294     if (pmpriv->uap_host_based)
1295     {
1296         tlv              = (MrvlIEtypes_HostMlme_t *)((t_u8 *)cmd + cmd->size);
1297         tlv->header.type = wlan_cpu_to_le16(TLV_TYPE_HOST_MLME);
1298         tlv->header.len  = wlan_cpu_to_le16(sizeof(tlv->host_mlme));
1299         tlv->host_mlme   = MTRUE;
1300         cmd->size += sizeof(MrvlIEtypes_HostMlme_t);
1301     }
1302 #endif
1303     cmd->size = wlan_cpu_to_le16(cmd->size);
1304     LEAVE();
1305     return MLAN_STATUS_SUCCESS;
1306 }
1307 
1308 /********************************************************
1309     Global Functions
1310 ********************************************************/
1311 /**
1312  *  @brief This function prepare the command before sending to firmware.
1313  *
1314  *  @param priv       A pointer to mlan_private structure
1315  *  @param cmd_no       Command number
1316  *  @param cmd_action   Command action: GET or SET
1317  *  @param cmd_oid      Cmd oid: treated as sub command
1318  *  @param pioctl_buf   A pointer to MLAN IOCTL Request buffer
1319  *  @param pdata_buf    A pointer to information buffer
1320  *  @param pcmd_buf      A pointer to cmd buf
1321  *
1322  *  @return             MLAN_STATUS_SUCCESS or MLAN_STATUS_FAILURE
1323  */
1324 mlan_status wlan_ops_uap_prepare_cmd(IN t_void *priv,
1325                                      IN t_u16 cmd_no,
1326                                      IN t_u16 cmd_action,
1327                                      IN t_u32 cmd_oid,
1328                                      IN t_void *pioctl_buf,
1329                                      IN t_void *pdata_buf,
1330                                      IN t_void *pcmd_buf)
1331 {
1332     HostCmd_DS_COMMAND *cmd_ptr = (HostCmd_DS_COMMAND *)pcmd_buf;
1333     mlan_private *pmpriv        = (mlan_private *)priv;
1334     mlan_status ret             = MLAN_STATUS_SUCCESS;
1335     pmlan_ioctl_req pioctl_req  = (mlan_ioctl_req *)pioctl_buf;
1336 
1337     ENTER();
1338 
1339     /* Prepare command */
1340     switch (cmd_no)
1341     {
1342         case HostCMD_APCMD_ACS_SCAN:
1343         case HostCmd_CMD_SOFT_RESET:
1344         case HOST_CMD_APCMD_BSS_STOP:
1345         case HOST_CMD_APCMD_SYS_INFO:
1346         case HOST_CMD_APCMD_SYS_RESET:
1347         case HOST_CMD_APCMD_STA_LIST:
1348             cmd_ptr->command = wlan_cpu_to_le16(cmd_no);
1349             cmd_ptr->size    = wlan_cpu_to_le16(S_DS_GEN);
1350             break;
1351         case HOST_CMD_APCMD_BSS_START:
1352             ret = wlan_uap_cmd_bss_start(pmpriv, cmd_ptr);
1353             break;
1354         case HOST_CMD_APCMD_SYS_CONFIGURE:
1355             ret = wlan_uap_cmd_sys_configure(pmpriv, cmd_ptr, cmd_action, (pmlan_ioctl_req)pioctl_buf, pdata_buf);
1356             break;
1357         case HostCmd_CMD_802_11_SNMP_MIB:
1358             ret = wlan_uap_cmd_snmp_mib(pmpriv, cmd_ptr, cmd_action, cmd_oid, (pmlan_ioctl_req)pioctl_buf, pdata_buf);
1359             break;
1360         case HostCmd_CMD_802_11D_DOMAIN_INFO:
1361             if (pmpriv->support_11d_APIs != NULL)
1362             {
1363                 ret = pmpriv->support_11d_APIs->wlan_cmd_802_11d_domain_info_p(pmpriv, cmd_ptr, cmd_action);
1364             }
1365             break;
1366         case HOST_CMD_APCMD_STA_DEAUTH:
1367             ret = wlan_uap_cmd_sta_deauth(pmpriv, cmd_ptr, pdata_buf);
1368             break;
1369 #if defined(WAPI_AP) || defined(HOST_AUTHENTICATOR) || (CONFIG_WPA_SUPP_AP)
1370         case HostCmd_CMD_802_11_KEY_MATERIAL:
1371             ret = wlan_uap_cmd_key_material(pmpriv, cmd_ptr, cmd_action, cmd_oid, pdata_buf);
1372             break;
1373 #endif
1374         case HostCmd_CMD_11N_CFG:
1375             ret = wlan_cmd_11n_cfg(pmpriv, cmd_ptr, cmd_action, pdata_buf);
1376             break;
1377         case HostCmd_CMD_11N_ADDBA_REQ:
1378             ret = wlan_cmd_11n_addba_req(pmpriv, cmd_ptr, pdata_buf);
1379             break;
1380         case HostCmd_CMD_11N_DELBA:
1381             ret = wlan_cmd_11n_delba(pmpriv, cmd_ptr, pdata_buf);
1382             break;
1383 #ifdef UAP_HOST_MLME
1384         case HostCmd_CMD_ADD_NEW_STATION:
1385             ret = wlan_uap_cmd_add_station(pmpriv, cmd_ptr, cmd_action, (pmlan_ioctl_req)pioctl_buf);
1386             break;
1387 #endif
1388         case HostCmd_CMD_TX_RATE_CFG:
1389             ret = wlan_cmd_tx_rate_cfg(pmpriv, cmd_ptr, cmd_action, pdata_buf, (pmlan_ioctl_req)pioctl_buf);
1390             break;
1391         case HostCmd_CMD_802_11_TX_RATE_QUERY:
1392             cmd_ptr->command = wlan_cpu_to_le16(HostCmd_CMD_802_11_TX_RATE_QUERY);
1393             cmd_ptr->size    = wlan_cpu_to_le16(sizeof(HostCmd_TX_RATE_QUERY) + S_DS_GEN);
1394             pmpriv->tx_rate  = 0;
1395             ret              = MLAN_STATUS_SUCCESS;
1396             break;
1397         case HostCmd_CMD_11AC_CFG:
1398             ret = wlan_cmd_11ac_cfg(pmpriv, cmd_ptr, cmd_action, pdata_buf);
1399             break;
1400 #if CONFIG_WIFI_CLOCKSYNC
1401         case HostCmd_GPIO_TSF_LATCH_PARAM_CONFIG:
1402             ret = wlan_cmd_gpio_tsf_latch(pmpriv, cmd_ptr, cmd_action, pioctl_buf, pdata_buf);
1403             break;
1404 #endif
1405 #if CONFIG_11AX
1406         case HostCmd_CMD_11AX_CMD:
1407             ret = (mlan_status)wlan_cmd_11ax_cmd(pmpriv, cmd_ptr, cmd_action, pdata_buf);
1408             break;
1409         case HostCmd_CMD_11AX_CFG:
1410             ret = (mlan_status)wlan_cmd_11ax_cfg(pmpriv, cmd_action, pdata_buf);
1411             break;
1412 #if CONFIG_11AX_TWT
1413         case HostCmd_CMD_TWT_CFG:
1414             ret = wlan_cmd_twt_cfg(pmpriv, cmd_ptr, cmd_action, pdata_buf);
1415             break;
1416 #endif /* CONFIG_11AX_TWT */
1417 #endif /* CONFIG_11AX */
1418         default:
1419             PRINTM(MERROR, "PREP_CMD: unknown command- %#x\n", cmd_no);
1420             if (pioctl_req != NULL)
1421             {
1422                 pioctl_req->status_code = MLAN_ERROR_CMD_INVALID;
1423             }
1424             ret = MLAN_STATUS_FAILURE;
1425             break;
1426     }
1427     LEAVE();
1428     return ret;
1429 }
1430