xref: /linux/include/linux/ieee80211.h (revision e5a52fd2b8cdb700b3c07b030e050a49ef3156b9)
1 /* SPDX-License-Identifier: GPL-2.0-only */
2 /*
3  * IEEE 802.11 defines
4  *
5  * Copyright (c) 2001-2002, SSH Communications Security Corp and Jouni Malinen
6  * <jkmaline@cc.hut.fi>
7  * Copyright (c) 2002-2003, Jouni Malinen <jkmaline@cc.hut.fi>
8  * Copyright (c) 2005, Devicescape Software, Inc.
9  * Copyright (c) 2006, Michael Wu <flamingice@sourmilk.net>
10  * Copyright (c) 2013 - 2014 Intel Mobile Communications GmbH
11  * Copyright (c) 2016 - 2017 Intel Deutschland GmbH
12  * Copyright (c) 2018 - 2020 Intel Corporation
13  */
14 
15 #ifndef LINUX_IEEE80211_H
16 #define LINUX_IEEE80211_H
17 
18 #include <linux/types.h>
19 #include <linux/if_ether.h>
20 #include <linux/etherdevice.h>
21 #include <asm/byteorder.h>
22 #include <asm/unaligned.h>
23 
24 /*
25  * DS bit usage
26  *
27  * TA = transmitter address
28  * RA = receiver address
29  * DA = destination address
30  * SA = source address
31  *
32  * ToDS    FromDS  A1(RA)  A2(TA)  A3      A4      Use
33  * -----------------------------------------------------------------
34  *  0       0       DA      SA      BSSID   -       IBSS/DLS
35  *  0       1       DA      BSSID   SA      -       AP -> STA
36  *  1       0       BSSID   SA      DA      -       AP <- STA
37  *  1       1       RA      TA      DA      SA      unspecified (WDS)
38  */
39 
40 #define FCS_LEN 4
41 
42 #define IEEE80211_FCTL_VERS		0x0003
43 #define IEEE80211_FCTL_FTYPE		0x000c
44 #define IEEE80211_FCTL_STYPE		0x00f0
45 #define IEEE80211_FCTL_TODS		0x0100
46 #define IEEE80211_FCTL_FROMDS		0x0200
47 #define IEEE80211_FCTL_MOREFRAGS	0x0400
48 #define IEEE80211_FCTL_RETRY		0x0800
49 #define IEEE80211_FCTL_PM		0x1000
50 #define IEEE80211_FCTL_MOREDATA		0x2000
51 #define IEEE80211_FCTL_PROTECTED	0x4000
52 #define IEEE80211_FCTL_ORDER		0x8000
53 #define IEEE80211_FCTL_CTL_EXT		0x0f00
54 
55 #define IEEE80211_SCTL_FRAG		0x000F
56 #define IEEE80211_SCTL_SEQ		0xFFF0
57 
58 #define IEEE80211_FTYPE_MGMT		0x0000
59 #define IEEE80211_FTYPE_CTL		0x0004
60 #define IEEE80211_FTYPE_DATA		0x0008
61 #define IEEE80211_FTYPE_EXT		0x000c
62 
63 /* management */
64 #define IEEE80211_STYPE_ASSOC_REQ	0x0000
65 #define IEEE80211_STYPE_ASSOC_RESP	0x0010
66 #define IEEE80211_STYPE_REASSOC_REQ	0x0020
67 #define IEEE80211_STYPE_REASSOC_RESP	0x0030
68 #define IEEE80211_STYPE_PROBE_REQ	0x0040
69 #define IEEE80211_STYPE_PROBE_RESP	0x0050
70 #define IEEE80211_STYPE_BEACON		0x0080
71 #define IEEE80211_STYPE_ATIM		0x0090
72 #define IEEE80211_STYPE_DISASSOC	0x00A0
73 #define IEEE80211_STYPE_AUTH		0x00B0
74 #define IEEE80211_STYPE_DEAUTH		0x00C0
75 #define IEEE80211_STYPE_ACTION		0x00D0
76 
77 /* control */
78 #define IEEE80211_STYPE_CTL_EXT		0x0060
79 #define IEEE80211_STYPE_BACK_REQ	0x0080
80 #define IEEE80211_STYPE_BACK		0x0090
81 #define IEEE80211_STYPE_PSPOLL		0x00A0
82 #define IEEE80211_STYPE_RTS		0x00B0
83 #define IEEE80211_STYPE_CTS		0x00C0
84 #define IEEE80211_STYPE_ACK		0x00D0
85 #define IEEE80211_STYPE_CFEND		0x00E0
86 #define IEEE80211_STYPE_CFENDACK	0x00F0
87 
88 /* data */
89 #define IEEE80211_STYPE_DATA			0x0000
90 #define IEEE80211_STYPE_DATA_CFACK		0x0010
91 #define IEEE80211_STYPE_DATA_CFPOLL		0x0020
92 #define IEEE80211_STYPE_DATA_CFACKPOLL		0x0030
93 #define IEEE80211_STYPE_NULLFUNC		0x0040
94 #define IEEE80211_STYPE_CFACK			0x0050
95 #define IEEE80211_STYPE_CFPOLL			0x0060
96 #define IEEE80211_STYPE_CFACKPOLL		0x0070
97 #define IEEE80211_STYPE_QOS_DATA		0x0080
98 #define IEEE80211_STYPE_QOS_DATA_CFACK		0x0090
99 #define IEEE80211_STYPE_QOS_DATA_CFPOLL		0x00A0
100 #define IEEE80211_STYPE_QOS_DATA_CFACKPOLL	0x00B0
101 #define IEEE80211_STYPE_QOS_NULLFUNC		0x00C0
102 #define IEEE80211_STYPE_QOS_CFACK		0x00D0
103 #define IEEE80211_STYPE_QOS_CFPOLL		0x00E0
104 #define IEEE80211_STYPE_QOS_CFACKPOLL		0x00F0
105 
106 /* extension, added by 802.11ad */
107 #define IEEE80211_STYPE_DMG_BEACON		0x0000
108 #define IEEE80211_STYPE_S1G_BEACON		0x0010
109 
110 /* bits unique to S1G beacon */
111 #define IEEE80211_S1G_BCN_NEXT_TBTT	0x100
112 
113 /* see 802.11ah-2016 9.9 NDP CMAC frames */
114 #define IEEE80211_S1G_1MHZ_NDP_BITS	25
115 #define IEEE80211_S1G_1MHZ_NDP_BYTES	4
116 #define IEEE80211_S1G_2MHZ_NDP_BITS	37
117 #define IEEE80211_S1G_2MHZ_NDP_BYTES	5
118 
119 #define IEEE80211_NDP_FTYPE_CTS			0
120 #define IEEE80211_NDP_FTYPE_CF_END		0
121 #define IEEE80211_NDP_FTYPE_PS_POLL		1
122 #define IEEE80211_NDP_FTYPE_ACK			2
123 #define IEEE80211_NDP_FTYPE_PS_POLL_ACK		3
124 #define IEEE80211_NDP_FTYPE_BA			4
125 #define IEEE80211_NDP_FTYPE_BF_REPORT_POLL	5
126 #define IEEE80211_NDP_FTYPE_PAGING		6
127 #define IEEE80211_NDP_FTYPE_PREQ		7
128 
129 #define SM64(f, v)	((((u64)v) << f##_S) & f)
130 
131 /* NDP CMAC frame fields */
132 #define IEEE80211_NDP_FTYPE                    0x0000000000000007
133 #define IEEE80211_NDP_FTYPE_S                  0x0000000000000000
134 
135 /* 1M Probe Request 11ah 9.9.3.1.1 */
136 #define IEEE80211_NDP_1M_PREQ_ANO      0x0000000000000008
137 #define IEEE80211_NDP_1M_PREQ_ANO_S                     3
138 #define IEEE80211_NDP_1M_PREQ_CSSID    0x00000000000FFFF0
139 #define IEEE80211_NDP_1M_PREQ_CSSID_S                   4
140 #define IEEE80211_NDP_1M_PREQ_RTYPE    0x0000000000100000
141 #define IEEE80211_NDP_1M_PREQ_RTYPE_S                  20
142 #define IEEE80211_NDP_1M_PREQ_RSV      0x0000000001E00000
143 #define IEEE80211_NDP_1M_PREQ_RSV      0x0000000001E00000
144 /* 2M Probe Request 11ah 9.9.3.1.2 */
145 #define IEEE80211_NDP_2M_PREQ_ANO      0x0000000000000008
146 #define IEEE80211_NDP_2M_PREQ_ANO_S                     3
147 #define IEEE80211_NDP_2M_PREQ_CSSID    0x0000000FFFFFFFF0
148 #define IEEE80211_NDP_2M_PREQ_CSSID_S                   4
149 #define IEEE80211_NDP_2M_PREQ_RTYPE    0x0000001000000000
150 #define IEEE80211_NDP_2M_PREQ_RTYPE_S                  36
151 
152 #define IEEE80211_ANO_NETTYPE_WILD              15
153 
154 /* control extension - for IEEE80211_FTYPE_CTL | IEEE80211_STYPE_CTL_EXT */
155 #define IEEE80211_CTL_EXT_POLL		0x2000
156 #define IEEE80211_CTL_EXT_SPR		0x3000
157 #define IEEE80211_CTL_EXT_GRANT	0x4000
158 #define IEEE80211_CTL_EXT_DMG_CTS	0x5000
159 #define IEEE80211_CTL_EXT_DMG_DTS	0x6000
160 #define IEEE80211_CTL_EXT_SSW		0x8000
161 #define IEEE80211_CTL_EXT_SSW_FBACK	0x9000
162 #define IEEE80211_CTL_EXT_SSW_ACK	0xa000
163 
164 
165 #define IEEE80211_SN_MASK		((IEEE80211_SCTL_SEQ) >> 4)
166 #define IEEE80211_MAX_SN		IEEE80211_SN_MASK
167 #define IEEE80211_SN_MODULO		(IEEE80211_MAX_SN + 1)
168 
169 
170 /* PV1 Layout 11ah 9.8.3.1 */
171 #define IEEE80211_PV1_FCTL_VERS		0x0003
172 #define IEEE80211_PV1_FCTL_FTYPE	0x001c
173 #define IEEE80211_PV1_FCTL_STYPE	0x00e0
174 #define IEEE80211_PV1_FCTL_TODS		0x0100
175 #define IEEE80211_PV1_FCTL_MOREFRAGS	0x0200
176 #define IEEE80211_PV1_FCTL_PM		0x0400
177 #define IEEE80211_PV1_FCTL_MOREDATA	0x0800
178 #define IEEE80211_PV1_FCTL_PROTECTED	0x1000
179 #define IEEE80211_PV1_FCTL_END_SP       0x2000
180 #define IEEE80211_PV1_FCTL_RELAYED      0x4000
181 #define IEEE80211_PV1_FCTL_ACK_POLICY   0x8000
182 #define IEEE80211_PV1_FCTL_CTL_EXT	0x0f00
183 
184 static inline bool ieee80211_sn_less(u16 sn1, u16 sn2)
185 {
186 	return ((sn1 - sn2) & IEEE80211_SN_MASK) > (IEEE80211_SN_MODULO >> 1);
187 }
188 
189 static inline u16 ieee80211_sn_add(u16 sn1, u16 sn2)
190 {
191 	return (sn1 + sn2) & IEEE80211_SN_MASK;
192 }
193 
194 static inline u16 ieee80211_sn_inc(u16 sn)
195 {
196 	return ieee80211_sn_add(sn, 1);
197 }
198 
199 static inline u16 ieee80211_sn_sub(u16 sn1, u16 sn2)
200 {
201 	return (sn1 - sn2) & IEEE80211_SN_MASK;
202 }
203 
204 #define IEEE80211_SEQ_TO_SN(seq)	(((seq) & IEEE80211_SCTL_SEQ) >> 4)
205 #define IEEE80211_SN_TO_SEQ(ssn)	(((ssn) << 4) & IEEE80211_SCTL_SEQ)
206 
207 /* miscellaneous IEEE 802.11 constants */
208 #define IEEE80211_MAX_FRAG_THRESHOLD	2352
209 #define IEEE80211_MAX_RTS_THRESHOLD	2353
210 #define IEEE80211_MAX_AID		2007
211 #define IEEE80211_MAX_AID_S1G		8191
212 #define IEEE80211_MAX_TIM_LEN		251
213 #define IEEE80211_MAX_MESH_PEERINGS	63
214 /* Maximum size for the MA-UNITDATA primitive, 802.11 standard section
215    6.2.1.1.2.
216 
217    802.11e clarifies the figure in section 7.1.2. The frame body is
218    up to 2304 octets long (maximum MSDU size) plus any crypt overhead. */
219 #define IEEE80211_MAX_DATA_LEN		2304
220 /* 802.11ad extends maximum MSDU size for DMG (freq > 40Ghz) networks
221  * to 7920 bytes, see 8.2.3 General frame format
222  */
223 #define IEEE80211_MAX_DATA_LEN_DMG	7920
224 /* 30 byte 4 addr hdr, 2 byte QoS, 2304 byte MSDU, 12 byte crypt, 4 byte FCS */
225 #define IEEE80211_MAX_FRAME_LEN		2352
226 
227 /* Maximal size of an A-MSDU that can be transported in a HT BA session */
228 #define IEEE80211_MAX_MPDU_LEN_HT_BA		4095
229 
230 /* Maximal size of an A-MSDU */
231 #define IEEE80211_MAX_MPDU_LEN_HT_3839		3839
232 #define IEEE80211_MAX_MPDU_LEN_HT_7935		7935
233 
234 #define IEEE80211_MAX_MPDU_LEN_VHT_3895		3895
235 #define IEEE80211_MAX_MPDU_LEN_VHT_7991		7991
236 #define IEEE80211_MAX_MPDU_LEN_VHT_11454	11454
237 
238 #define IEEE80211_MAX_SSID_LEN		32
239 
240 #define IEEE80211_MAX_MESH_ID_LEN	32
241 
242 #define IEEE80211_FIRST_TSPEC_TSID	8
243 #define IEEE80211_NUM_TIDS		16
244 
245 /* number of user priorities 802.11 uses */
246 #define IEEE80211_NUM_UPS		8
247 /* number of ACs */
248 #define IEEE80211_NUM_ACS		4
249 
250 #define IEEE80211_QOS_CTL_LEN		2
251 /* 1d tag mask */
252 #define IEEE80211_QOS_CTL_TAG1D_MASK		0x0007
253 /* TID mask */
254 #define IEEE80211_QOS_CTL_TID_MASK		0x000f
255 /* EOSP */
256 #define IEEE80211_QOS_CTL_EOSP			0x0010
257 /* ACK policy */
258 #define IEEE80211_QOS_CTL_ACK_POLICY_NORMAL	0x0000
259 #define IEEE80211_QOS_CTL_ACK_POLICY_NOACK	0x0020
260 #define IEEE80211_QOS_CTL_ACK_POLICY_NO_EXPL	0x0040
261 #define IEEE80211_QOS_CTL_ACK_POLICY_BLOCKACK	0x0060
262 #define IEEE80211_QOS_CTL_ACK_POLICY_MASK	0x0060
263 /* A-MSDU 802.11n */
264 #define IEEE80211_QOS_CTL_A_MSDU_PRESENT	0x0080
265 /* Mesh Control 802.11s */
266 #define IEEE80211_QOS_CTL_MESH_CONTROL_PRESENT  0x0100
267 
268 /* Mesh Power Save Level */
269 #define IEEE80211_QOS_CTL_MESH_PS_LEVEL		0x0200
270 /* Mesh Receiver Service Period Initiated */
271 #define IEEE80211_QOS_CTL_RSPI			0x0400
272 
273 /* U-APSD queue for WMM IEs sent by AP */
274 #define IEEE80211_WMM_IE_AP_QOSINFO_UAPSD	(1<<7)
275 #define IEEE80211_WMM_IE_AP_QOSINFO_PARAM_SET_CNT_MASK	0x0f
276 
277 /* U-APSD queues for WMM IEs sent by STA */
278 #define IEEE80211_WMM_IE_STA_QOSINFO_AC_VO	(1<<0)
279 #define IEEE80211_WMM_IE_STA_QOSINFO_AC_VI	(1<<1)
280 #define IEEE80211_WMM_IE_STA_QOSINFO_AC_BK	(1<<2)
281 #define IEEE80211_WMM_IE_STA_QOSINFO_AC_BE	(1<<3)
282 #define IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK	0x0f
283 
284 /* U-APSD max SP length for WMM IEs sent by STA */
285 #define IEEE80211_WMM_IE_STA_QOSINFO_SP_ALL	0x00
286 #define IEEE80211_WMM_IE_STA_QOSINFO_SP_2	0x01
287 #define IEEE80211_WMM_IE_STA_QOSINFO_SP_4	0x02
288 #define IEEE80211_WMM_IE_STA_QOSINFO_SP_6	0x03
289 #define IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK	0x03
290 #define IEEE80211_WMM_IE_STA_QOSINFO_SP_SHIFT	5
291 
292 #define IEEE80211_HT_CTL_LEN		4
293 
294 struct ieee80211_hdr {
295 	__le16 frame_control;
296 	__le16 duration_id;
297 	u8 addr1[ETH_ALEN];
298 	u8 addr2[ETH_ALEN];
299 	u8 addr3[ETH_ALEN];
300 	__le16 seq_ctrl;
301 	u8 addr4[ETH_ALEN];
302 } __packed __aligned(2);
303 
304 struct ieee80211_hdr_3addr {
305 	__le16 frame_control;
306 	__le16 duration_id;
307 	u8 addr1[ETH_ALEN];
308 	u8 addr2[ETH_ALEN];
309 	u8 addr3[ETH_ALEN];
310 	__le16 seq_ctrl;
311 } __packed __aligned(2);
312 
313 struct ieee80211_qos_hdr {
314 	__le16 frame_control;
315 	__le16 duration_id;
316 	u8 addr1[ETH_ALEN];
317 	u8 addr2[ETH_ALEN];
318 	u8 addr3[ETH_ALEN];
319 	__le16 seq_ctrl;
320 	__le16 qos_ctrl;
321 } __packed __aligned(2);
322 
323 /**
324  * ieee80211_has_tods - check if IEEE80211_FCTL_TODS is set
325  * @fc: frame control bytes in little-endian byteorder
326  */
327 static inline bool ieee80211_has_tods(__le16 fc)
328 {
329 	return (fc & cpu_to_le16(IEEE80211_FCTL_TODS)) != 0;
330 }
331 
332 /**
333  * ieee80211_has_fromds - check if IEEE80211_FCTL_FROMDS is set
334  * @fc: frame control bytes in little-endian byteorder
335  */
336 static inline bool ieee80211_has_fromds(__le16 fc)
337 {
338 	return (fc & cpu_to_le16(IEEE80211_FCTL_FROMDS)) != 0;
339 }
340 
341 /**
342  * ieee80211_has_a4 - check if IEEE80211_FCTL_TODS and IEEE80211_FCTL_FROMDS are set
343  * @fc: frame control bytes in little-endian byteorder
344  */
345 static inline bool ieee80211_has_a4(__le16 fc)
346 {
347 	__le16 tmp = cpu_to_le16(IEEE80211_FCTL_TODS | IEEE80211_FCTL_FROMDS);
348 	return (fc & tmp) == tmp;
349 }
350 
351 /**
352  * ieee80211_has_morefrags - check if IEEE80211_FCTL_MOREFRAGS is set
353  * @fc: frame control bytes in little-endian byteorder
354  */
355 static inline bool ieee80211_has_morefrags(__le16 fc)
356 {
357 	return (fc & cpu_to_le16(IEEE80211_FCTL_MOREFRAGS)) != 0;
358 }
359 
360 /**
361  * ieee80211_has_retry - check if IEEE80211_FCTL_RETRY is set
362  * @fc: frame control bytes in little-endian byteorder
363  */
364 static inline bool ieee80211_has_retry(__le16 fc)
365 {
366 	return (fc & cpu_to_le16(IEEE80211_FCTL_RETRY)) != 0;
367 }
368 
369 /**
370  * ieee80211_has_pm - check if IEEE80211_FCTL_PM is set
371  * @fc: frame control bytes in little-endian byteorder
372  */
373 static inline bool ieee80211_has_pm(__le16 fc)
374 {
375 	return (fc & cpu_to_le16(IEEE80211_FCTL_PM)) != 0;
376 }
377 
378 /**
379  * ieee80211_has_moredata - check if IEEE80211_FCTL_MOREDATA is set
380  * @fc: frame control bytes in little-endian byteorder
381  */
382 static inline bool ieee80211_has_moredata(__le16 fc)
383 {
384 	return (fc & cpu_to_le16(IEEE80211_FCTL_MOREDATA)) != 0;
385 }
386 
387 /**
388  * ieee80211_has_protected - check if IEEE80211_FCTL_PROTECTED is set
389  * @fc: frame control bytes in little-endian byteorder
390  */
391 static inline bool ieee80211_has_protected(__le16 fc)
392 {
393 	return (fc & cpu_to_le16(IEEE80211_FCTL_PROTECTED)) != 0;
394 }
395 
396 /**
397  * ieee80211_has_order - check if IEEE80211_FCTL_ORDER is set
398  * @fc: frame control bytes in little-endian byteorder
399  */
400 static inline bool ieee80211_has_order(__le16 fc)
401 {
402 	return (fc & cpu_to_le16(IEEE80211_FCTL_ORDER)) != 0;
403 }
404 
405 /**
406  * ieee80211_is_mgmt - check if type is IEEE80211_FTYPE_MGMT
407  * @fc: frame control bytes in little-endian byteorder
408  */
409 static inline bool ieee80211_is_mgmt(__le16 fc)
410 {
411 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE)) ==
412 	       cpu_to_le16(IEEE80211_FTYPE_MGMT);
413 }
414 
415 /**
416  * ieee80211_is_ctl - check if type is IEEE80211_FTYPE_CTL
417  * @fc: frame control bytes in little-endian byteorder
418  */
419 static inline bool ieee80211_is_ctl(__le16 fc)
420 {
421 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE)) ==
422 	       cpu_to_le16(IEEE80211_FTYPE_CTL);
423 }
424 
425 /**
426  * ieee80211_is_data - check if type is IEEE80211_FTYPE_DATA
427  * @fc: frame control bytes in little-endian byteorder
428  */
429 static inline bool ieee80211_is_data(__le16 fc)
430 {
431 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE)) ==
432 	       cpu_to_le16(IEEE80211_FTYPE_DATA);
433 }
434 
435 /**
436  * ieee80211_is_ext - check if type is IEEE80211_FTYPE_EXT
437  * @fc: frame control bytes in little-endian byteorder
438  */
439 static inline bool ieee80211_is_ext(__le16 fc)
440 {
441 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE)) ==
442 	       cpu_to_le16(IEEE80211_FTYPE_EXT);
443 }
444 
445 
446 /**
447  * ieee80211_is_data_qos - check if type is IEEE80211_FTYPE_DATA and IEEE80211_STYPE_QOS_DATA is set
448  * @fc: frame control bytes in little-endian byteorder
449  */
450 static inline bool ieee80211_is_data_qos(__le16 fc)
451 {
452 	/*
453 	 * mask with QOS_DATA rather than IEEE80211_FCTL_STYPE as we just need
454 	 * to check the one bit
455 	 */
456 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_STYPE_QOS_DATA)) ==
457 	       cpu_to_le16(IEEE80211_FTYPE_DATA | IEEE80211_STYPE_QOS_DATA);
458 }
459 
460 /**
461  * ieee80211_is_data_present - check if type is IEEE80211_FTYPE_DATA and has data
462  * @fc: frame control bytes in little-endian byteorder
463  */
464 static inline bool ieee80211_is_data_present(__le16 fc)
465 {
466 	/*
467 	 * mask with 0x40 and test that that bit is clear to only return true
468 	 * for the data-containing substypes.
469 	 */
470 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | 0x40)) ==
471 	       cpu_to_le16(IEEE80211_FTYPE_DATA);
472 }
473 
474 /**
475  * ieee80211_is_assoc_req - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_ASSOC_REQ
476  * @fc: frame control bytes in little-endian byteorder
477  */
478 static inline bool ieee80211_is_assoc_req(__le16 fc)
479 {
480 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
481 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ASSOC_REQ);
482 }
483 
484 /**
485  * ieee80211_is_assoc_resp - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_ASSOC_RESP
486  * @fc: frame control bytes in little-endian byteorder
487  */
488 static inline bool ieee80211_is_assoc_resp(__le16 fc)
489 {
490 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
491 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ASSOC_RESP);
492 }
493 
494 /**
495  * ieee80211_is_reassoc_req - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_REASSOC_REQ
496  * @fc: frame control bytes in little-endian byteorder
497  */
498 static inline bool ieee80211_is_reassoc_req(__le16 fc)
499 {
500 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
501 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_REASSOC_REQ);
502 }
503 
504 /**
505  * ieee80211_is_reassoc_resp - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_REASSOC_RESP
506  * @fc: frame control bytes in little-endian byteorder
507  */
508 static inline bool ieee80211_is_reassoc_resp(__le16 fc)
509 {
510 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
511 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_REASSOC_RESP);
512 }
513 
514 /**
515  * ieee80211_is_probe_req - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_PROBE_REQ
516  * @fc: frame control bytes in little-endian byteorder
517  */
518 static inline bool ieee80211_is_probe_req(__le16 fc)
519 {
520 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
521 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_PROBE_REQ);
522 }
523 
524 /**
525  * ieee80211_is_probe_resp - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_PROBE_RESP
526  * @fc: frame control bytes in little-endian byteorder
527  */
528 static inline bool ieee80211_is_probe_resp(__le16 fc)
529 {
530 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
531 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_PROBE_RESP);
532 }
533 
534 /**
535  * ieee80211_is_beacon - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_BEACON
536  * @fc: frame control bytes in little-endian byteorder
537  */
538 static inline bool ieee80211_is_beacon(__le16 fc)
539 {
540 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
541 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_BEACON);
542 }
543 
544 /**
545  * ieee80211_is_s1g_beacon - check if IEEE80211_FTYPE_EXT &&
546  * IEEE80211_STYPE_S1G_BEACON
547  * @fc: frame control bytes in little-endian byteorder
548  */
549 static inline bool ieee80211_is_s1g_beacon(__le16 fc)
550 {
551 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE |
552 				 IEEE80211_FCTL_STYPE)) ==
553 	       cpu_to_le16(IEEE80211_FTYPE_EXT | IEEE80211_STYPE_S1G_BEACON);
554 }
555 
556 /**
557  * ieee80211_is_atim - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_ATIM
558  * @fc: frame control bytes in little-endian byteorder
559  */
560 static inline bool ieee80211_is_atim(__le16 fc)
561 {
562 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
563 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ATIM);
564 }
565 
566 /**
567  * ieee80211_is_disassoc - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_DISASSOC
568  * @fc: frame control bytes in little-endian byteorder
569  */
570 static inline bool ieee80211_is_disassoc(__le16 fc)
571 {
572 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
573 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_DISASSOC);
574 }
575 
576 /**
577  * ieee80211_is_auth - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_AUTH
578  * @fc: frame control bytes in little-endian byteorder
579  */
580 static inline bool ieee80211_is_auth(__le16 fc)
581 {
582 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
583 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_AUTH);
584 }
585 
586 /**
587  * ieee80211_is_deauth - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_DEAUTH
588  * @fc: frame control bytes in little-endian byteorder
589  */
590 static inline bool ieee80211_is_deauth(__le16 fc)
591 {
592 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
593 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_DEAUTH);
594 }
595 
596 /**
597  * ieee80211_is_action - check if IEEE80211_FTYPE_MGMT && IEEE80211_STYPE_ACTION
598  * @fc: frame control bytes in little-endian byteorder
599  */
600 static inline bool ieee80211_is_action(__le16 fc)
601 {
602 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
603 	       cpu_to_le16(IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION);
604 }
605 
606 /**
607  * ieee80211_is_back_req - check if IEEE80211_FTYPE_CTL && IEEE80211_STYPE_BACK_REQ
608  * @fc: frame control bytes in little-endian byteorder
609  */
610 static inline bool ieee80211_is_back_req(__le16 fc)
611 {
612 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
613 	       cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_BACK_REQ);
614 }
615 
616 /**
617  * ieee80211_is_back - check if IEEE80211_FTYPE_CTL && IEEE80211_STYPE_BACK
618  * @fc: frame control bytes in little-endian byteorder
619  */
620 static inline bool ieee80211_is_back(__le16 fc)
621 {
622 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
623 	       cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_BACK);
624 }
625 
626 /**
627  * ieee80211_is_pspoll - check if IEEE80211_FTYPE_CTL && IEEE80211_STYPE_PSPOLL
628  * @fc: frame control bytes in little-endian byteorder
629  */
630 static inline bool ieee80211_is_pspoll(__le16 fc)
631 {
632 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
633 	       cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_PSPOLL);
634 }
635 
636 /**
637  * ieee80211_is_rts - check if IEEE80211_FTYPE_CTL && IEEE80211_STYPE_RTS
638  * @fc: frame control bytes in little-endian byteorder
639  */
640 static inline bool ieee80211_is_rts(__le16 fc)
641 {
642 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
643 	       cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_RTS);
644 }
645 
646 /**
647  * ieee80211_is_cts - check if IEEE80211_FTYPE_CTL && IEEE80211_STYPE_CTS
648  * @fc: frame control bytes in little-endian byteorder
649  */
650 static inline bool ieee80211_is_cts(__le16 fc)
651 {
652 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
653 	       cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_CTS);
654 }
655 
656 /**
657  * ieee80211_is_ack - check if IEEE80211_FTYPE_CTL && IEEE80211_STYPE_ACK
658  * @fc: frame control bytes in little-endian byteorder
659  */
660 static inline bool ieee80211_is_ack(__le16 fc)
661 {
662 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
663 	       cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_ACK);
664 }
665 
666 /**
667  * ieee80211_is_cfend - check if IEEE80211_FTYPE_CTL && IEEE80211_STYPE_CFEND
668  * @fc: frame control bytes in little-endian byteorder
669  */
670 static inline bool ieee80211_is_cfend(__le16 fc)
671 {
672 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
673 	       cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_CFEND);
674 }
675 
676 /**
677  * ieee80211_is_cfendack - check if IEEE80211_FTYPE_CTL && IEEE80211_STYPE_CFENDACK
678  * @fc: frame control bytes in little-endian byteorder
679  */
680 static inline bool ieee80211_is_cfendack(__le16 fc)
681 {
682 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
683 	       cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_CFENDACK);
684 }
685 
686 /**
687  * ieee80211_is_nullfunc - check if frame is a regular (non-QoS) nullfunc frame
688  * @fc: frame control bytes in little-endian byteorder
689  */
690 static inline bool ieee80211_is_nullfunc(__le16 fc)
691 {
692 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
693 	       cpu_to_le16(IEEE80211_FTYPE_DATA | IEEE80211_STYPE_NULLFUNC);
694 }
695 
696 /**
697  * ieee80211_is_qos_nullfunc - check if frame is a QoS nullfunc frame
698  * @fc: frame control bytes in little-endian byteorder
699  */
700 static inline bool ieee80211_is_qos_nullfunc(__le16 fc)
701 {
702 	return (fc & cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) ==
703 	       cpu_to_le16(IEEE80211_FTYPE_DATA | IEEE80211_STYPE_QOS_NULLFUNC);
704 }
705 
706 /**
707  * ieee80211_is_any_nullfunc - check if frame is regular or QoS nullfunc frame
708  * @fc: frame control bytes in little-endian byteorder
709  */
710 static inline bool ieee80211_is_any_nullfunc(__le16 fc)
711 {
712 	return (ieee80211_is_nullfunc(fc) || ieee80211_is_qos_nullfunc(fc));
713 }
714 
715 /**
716  * ieee80211_is_bufferable_mmpdu - check if frame is bufferable MMPDU
717  * @fc: frame control field in little-endian byteorder
718  */
719 static inline bool ieee80211_is_bufferable_mmpdu(__le16 fc)
720 {
721 	/* IEEE 802.11-2012, definition of "bufferable management frame";
722 	 * note that this ignores the IBSS special case. */
723 	return ieee80211_is_mgmt(fc) &&
724 	       (ieee80211_is_action(fc) ||
725 		ieee80211_is_disassoc(fc) ||
726 		ieee80211_is_deauth(fc));
727 }
728 
729 /**
730  * ieee80211_is_first_frag - check if IEEE80211_SCTL_FRAG is not set
731  * @seq_ctrl: frame sequence control bytes in little-endian byteorder
732  */
733 static inline bool ieee80211_is_first_frag(__le16 seq_ctrl)
734 {
735 	return (seq_ctrl & cpu_to_le16(IEEE80211_SCTL_FRAG)) == 0;
736 }
737 
738 /**
739  * ieee80211_is_frag - check if a frame is a fragment
740  * @hdr: 802.11 header of the frame
741  */
742 static inline bool ieee80211_is_frag(struct ieee80211_hdr *hdr)
743 {
744 	return ieee80211_has_morefrags(hdr->frame_control) ||
745 	       hdr->seq_ctrl & cpu_to_le16(IEEE80211_SCTL_FRAG);
746 }
747 
748 struct ieee80211s_hdr {
749 	u8 flags;
750 	u8 ttl;
751 	__le32 seqnum;
752 	u8 eaddr1[ETH_ALEN];
753 	u8 eaddr2[ETH_ALEN];
754 } __packed __aligned(2);
755 
756 /* Mesh flags */
757 #define MESH_FLAGS_AE_A4 	0x1
758 #define MESH_FLAGS_AE_A5_A6	0x2
759 #define MESH_FLAGS_AE		0x3
760 #define MESH_FLAGS_PS_DEEP	0x4
761 
762 /**
763  * enum ieee80211_preq_flags - mesh PREQ element flags
764  *
765  * @IEEE80211_PREQ_PROACTIVE_PREP_FLAG: proactive PREP subfield
766  */
767 enum ieee80211_preq_flags {
768 	IEEE80211_PREQ_PROACTIVE_PREP_FLAG	= 1<<2,
769 };
770 
771 /**
772  * enum ieee80211_preq_target_flags - mesh PREQ element per target flags
773  *
774  * @IEEE80211_PREQ_TO_FLAG: target only subfield
775  * @IEEE80211_PREQ_USN_FLAG: unknown target HWMP sequence number subfield
776  */
777 enum ieee80211_preq_target_flags {
778 	IEEE80211_PREQ_TO_FLAG	= 1<<0,
779 	IEEE80211_PREQ_USN_FLAG	= 1<<2,
780 };
781 
782 /**
783  * struct ieee80211_quiet_ie
784  *
785  * This structure refers to "Quiet information element"
786  */
787 struct ieee80211_quiet_ie {
788 	u8 count;
789 	u8 period;
790 	__le16 duration;
791 	__le16 offset;
792 } __packed;
793 
794 /**
795  * struct ieee80211_msrment_ie
796  *
797  * This structure refers to "Measurement Request/Report information element"
798  */
799 struct ieee80211_msrment_ie {
800 	u8 token;
801 	u8 mode;
802 	u8 type;
803 	u8 request[];
804 } __packed;
805 
806 /**
807  * struct ieee80211_channel_sw_ie
808  *
809  * This structure refers to "Channel Switch Announcement information element"
810  */
811 struct ieee80211_channel_sw_ie {
812 	u8 mode;
813 	u8 new_ch_num;
814 	u8 count;
815 } __packed;
816 
817 /**
818  * struct ieee80211_ext_chansw_ie
819  *
820  * This structure represents the "Extended Channel Switch Announcement element"
821  */
822 struct ieee80211_ext_chansw_ie {
823 	u8 mode;
824 	u8 new_operating_class;
825 	u8 new_ch_num;
826 	u8 count;
827 } __packed;
828 
829 /**
830  * struct ieee80211_sec_chan_offs_ie - secondary channel offset IE
831  * @sec_chan_offs: secondary channel offset, uses IEEE80211_HT_PARAM_CHA_SEC_*
832  *	values here
833  * This structure represents the "Secondary Channel Offset element"
834  */
835 struct ieee80211_sec_chan_offs_ie {
836 	u8 sec_chan_offs;
837 } __packed;
838 
839 /**
840  * struct ieee80211_mesh_chansw_params_ie - mesh channel switch parameters IE
841  *
842  * This structure represents the "Mesh Channel Switch Paramters element"
843  */
844 struct ieee80211_mesh_chansw_params_ie {
845 	u8 mesh_ttl;
846 	u8 mesh_flags;
847 	__le16 mesh_reason;
848 	__le16 mesh_pre_value;
849 } __packed;
850 
851 /**
852  * struct ieee80211_wide_bw_chansw_ie - wide bandwidth channel switch IE
853  */
854 struct ieee80211_wide_bw_chansw_ie {
855 	u8 new_channel_width;
856 	u8 new_center_freq_seg0, new_center_freq_seg1;
857 } __packed;
858 
859 /**
860  * struct ieee80211_tim
861  *
862  * This structure refers to "Traffic Indication Map information element"
863  */
864 struct ieee80211_tim_ie {
865 	u8 dtim_count;
866 	u8 dtim_period;
867 	u8 bitmap_ctrl;
868 	/* variable size: 1 - 251 bytes */
869 	u8 virtual_map[1];
870 } __packed;
871 
872 /**
873  * struct ieee80211_meshconf_ie
874  *
875  * This structure refers to "Mesh Configuration information element"
876  */
877 struct ieee80211_meshconf_ie {
878 	u8 meshconf_psel;
879 	u8 meshconf_pmetric;
880 	u8 meshconf_congest;
881 	u8 meshconf_synch;
882 	u8 meshconf_auth;
883 	u8 meshconf_form;
884 	u8 meshconf_cap;
885 } __packed;
886 
887 /**
888  * enum mesh_config_capab_flags - Mesh Configuration IE capability field flags
889  *
890  * @IEEE80211_MESHCONF_CAPAB_ACCEPT_PLINKS: STA is willing to establish
891  *	additional mesh peerings with other mesh STAs
892  * @IEEE80211_MESHCONF_CAPAB_FORWARDING: the STA forwards MSDUs
893  * @IEEE80211_MESHCONF_CAPAB_TBTT_ADJUSTING: TBTT adjustment procedure
894  *	is ongoing
895  * @IEEE80211_MESHCONF_CAPAB_POWER_SAVE_LEVEL: STA is in deep sleep mode or has
896  *	neighbors in deep sleep mode
897  */
898 enum mesh_config_capab_flags {
899 	IEEE80211_MESHCONF_CAPAB_ACCEPT_PLINKS		= 0x01,
900 	IEEE80211_MESHCONF_CAPAB_FORWARDING		= 0x08,
901 	IEEE80211_MESHCONF_CAPAB_TBTT_ADJUSTING		= 0x20,
902 	IEEE80211_MESHCONF_CAPAB_POWER_SAVE_LEVEL	= 0x40,
903 };
904 
905 #define IEEE80211_MESHCONF_FORM_CONNECTED_TO_GATE 0x1
906 
907 /**
908  * mesh channel switch parameters element's flag indicator
909  *
910  */
911 #define WLAN_EID_CHAN_SWITCH_PARAM_TX_RESTRICT BIT(0)
912 #define WLAN_EID_CHAN_SWITCH_PARAM_INITIATOR BIT(1)
913 #define WLAN_EID_CHAN_SWITCH_PARAM_REASON BIT(2)
914 
915 /**
916  * struct ieee80211_rann_ie
917  *
918  * This structure refers to "Root Announcement information element"
919  */
920 struct ieee80211_rann_ie {
921 	u8 rann_flags;
922 	u8 rann_hopcount;
923 	u8 rann_ttl;
924 	u8 rann_addr[ETH_ALEN];
925 	__le32 rann_seq;
926 	__le32 rann_interval;
927 	__le32 rann_metric;
928 } __packed;
929 
930 enum ieee80211_rann_flags {
931 	RANN_FLAG_IS_GATE = 1 << 0,
932 };
933 
934 enum ieee80211_ht_chanwidth_values {
935 	IEEE80211_HT_CHANWIDTH_20MHZ = 0,
936 	IEEE80211_HT_CHANWIDTH_ANY = 1,
937 };
938 
939 /**
940  * enum ieee80211_opmode_bits - VHT operating mode field bits
941  * @IEEE80211_OPMODE_NOTIF_CHANWIDTH_MASK: channel width mask
942  * @IEEE80211_OPMODE_NOTIF_CHANWIDTH_20MHZ: 20 MHz channel width
943  * @IEEE80211_OPMODE_NOTIF_CHANWIDTH_40MHZ: 40 MHz channel width
944  * @IEEE80211_OPMODE_NOTIF_CHANWIDTH_80MHZ: 80 MHz channel width
945  * @IEEE80211_OPMODE_NOTIF_CHANWIDTH_160MHZ: 160 MHz or 80+80 MHz channel width
946  * @IEEE80211_OPMODE_NOTIF_BW_160_80P80: 160 / 80+80 MHz indicator flag
947  * @IEEE80211_OPMODE_NOTIF_RX_NSS_MASK: number of spatial streams mask
948  *	(the NSS value is the value of this field + 1)
949  * @IEEE80211_OPMODE_NOTIF_RX_NSS_SHIFT: number of spatial streams shift
950  * @IEEE80211_OPMODE_NOTIF_RX_NSS_TYPE_BF: indicates streams in SU-MIMO PPDU
951  *	using a beamforming steering matrix
952  */
953 enum ieee80211_vht_opmode_bits {
954 	IEEE80211_OPMODE_NOTIF_CHANWIDTH_MASK	= 0x03,
955 	IEEE80211_OPMODE_NOTIF_CHANWIDTH_20MHZ	= 0,
956 	IEEE80211_OPMODE_NOTIF_CHANWIDTH_40MHZ	= 1,
957 	IEEE80211_OPMODE_NOTIF_CHANWIDTH_80MHZ	= 2,
958 	IEEE80211_OPMODE_NOTIF_CHANWIDTH_160MHZ	= 3,
959 	IEEE80211_OPMODE_NOTIF_BW_160_80P80	= 0x04,
960 	IEEE80211_OPMODE_NOTIF_RX_NSS_MASK	= 0x70,
961 	IEEE80211_OPMODE_NOTIF_RX_NSS_SHIFT	= 4,
962 	IEEE80211_OPMODE_NOTIF_RX_NSS_TYPE_BF	= 0x80,
963 };
964 
965 #define WLAN_SA_QUERY_TR_ID_LEN 2
966 #define WLAN_MEMBERSHIP_LEN 8
967 #define WLAN_USER_POSITION_LEN 16
968 
969 /**
970  * struct ieee80211_tpc_report_ie
971  *
972  * This structure refers to "TPC Report element"
973  */
974 struct ieee80211_tpc_report_ie {
975 	u8 tx_power;
976 	u8 link_margin;
977 } __packed;
978 
979 #define IEEE80211_ADDBA_EXT_FRAG_LEVEL_MASK	GENMASK(2, 1)
980 #define IEEE80211_ADDBA_EXT_FRAG_LEVEL_SHIFT	1
981 #define IEEE80211_ADDBA_EXT_NO_FRAG		BIT(0)
982 
983 struct ieee80211_addba_ext_ie {
984 	u8 data;
985 } __packed;
986 
987 /**
988  * struct ieee80211_s1g_bcn_compat_ie
989  *
990  * S1G Beacon Compatibility element
991  */
992 struct ieee80211_s1g_bcn_compat_ie {
993 	__le16 compat_info;
994 	__le16 beacon_int;
995 	__le32 tsf_completion;
996 } __packed;
997 
998 /**
999  * struct ieee80211_s1g_oper_ie
1000  *
1001  * S1G Operation element
1002  */
1003 struct ieee80211_s1g_oper_ie {
1004 	u8 ch_width;
1005 	u8 oper_class;
1006 	u8 primary_ch;
1007 	u8 oper_ch;
1008 	__le16 basic_mcs_nss;
1009 } __packed;
1010 
1011 /**
1012  * struct ieee80211_aid_response_ie
1013  *
1014  * AID Response element
1015  */
1016 struct ieee80211_aid_response_ie {
1017 	__le16 aid;
1018 	u8 switch_count;
1019 	__le16 response_int;
1020 } __packed;
1021 
1022 struct ieee80211_s1g_cap {
1023 	u8 capab_info[10];
1024 	u8 supp_mcs_nss[5];
1025 } __packed;
1026 
1027 struct ieee80211_ext {
1028 	__le16 frame_control;
1029 	__le16 duration;
1030 	union {
1031 		struct {
1032 			u8 sa[ETH_ALEN];
1033 			__le32 timestamp;
1034 			u8 change_seq;
1035 			u8 variable[0];
1036 		} __packed s1g_beacon;
1037 	} u;
1038 } __packed __aligned(2);
1039 
1040 struct ieee80211_mgmt {
1041 	__le16 frame_control;
1042 	__le16 duration;
1043 	u8 da[ETH_ALEN];
1044 	u8 sa[ETH_ALEN];
1045 	u8 bssid[ETH_ALEN];
1046 	__le16 seq_ctrl;
1047 	union {
1048 		struct {
1049 			__le16 auth_alg;
1050 			__le16 auth_transaction;
1051 			__le16 status_code;
1052 			/* possibly followed by Challenge text */
1053 			u8 variable[0];
1054 		} __packed auth;
1055 		struct {
1056 			__le16 reason_code;
1057 		} __packed deauth;
1058 		struct {
1059 			__le16 capab_info;
1060 			__le16 listen_interval;
1061 			/* followed by SSID and Supported rates */
1062 			u8 variable[0];
1063 		} __packed assoc_req;
1064 		struct {
1065 			__le16 capab_info;
1066 			__le16 status_code;
1067 			__le16 aid;
1068 			/* followed by Supported rates */
1069 			u8 variable[0];
1070 		} __packed assoc_resp, reassoc_resp;
1071 		struct {
1072 			__le16 capab_info;
1073 			__le16 listen_interval;
1074 			u8 current_ap[ETH_ALEN];
1075 			/* followed by SSID and Supported rates */
1076 			u8 variable[0];
1077 		} __packed reassoc_req;
1078 		struct {
1079 			__le16 reason_code;
1080 		} __packed disassoc;
1081 		struct {
1082 			__le64 timestamp;
1083 			__le16 beacon_int;
1084 			__le16 capab_info;
1085 			/* followed by some of SSID, Supported rates,
1086 			 * FH Params, DS Params, CF Params, IBSS Params, TIM */
1087 			u8 variable[0];
1088 		} __packed beacon;
1089 		struct {
1090 			/* only variable items: SSID, Supported rates */
1091 			u8 variable[0];
1092 		} __packed probe_req;
1093 		struct {
1094 			__le64 timestamp;
1095 			__le16 beacon_int;
1096 			__le16 capab_info;
1097 			/* followed by some of SSID, Supported rates,
1098 			 * FH Params, DS Params, CF Params, IBSS Params */
1099 			u8 variable[0];
1100 		} __packed probe_resp;
1101 		struct {
1102 			u8 category;
1103 			union {
1104 				struct {
1105 					u8 action_code;
1106 					u8 dialog_token;
1107 					u8 status_code;
1108 					u8 variable[0];
1109 				} __packed wme_action;
1110 				struct{
1111 					u8 action_code;
1112 					u8 variable[0];
1113 				} __packed chan_switch;
1114 				struct{
1115 					u8 action_code;
1116 					struct ieee80211_ext_chansw_ie data;
1117 					u8 variable[0];
1118 				} __packed ext_chan_switch;
1119 				struct{
1120 					u8 action_code;
1121 					u8 dialog_token;
1122 					u8 element_id;
1123 					u8 length;
1124 					struct ieee80211_msrment_ie msr_elem;
1125 				} __packed measurement;
1126 				struct{
1127 					u8 action_code;
1128 					u8 dialog_token;
1129 					__le16 capab;
1130 					__le16 timeout;
1131 					__le16 start_seq_num;
1132 					/* followed by BA Extension */
1133 					u8 variable[0];
1134 				} __packed addba_req;
1135 				struct{
1136 					u8 action_code;
1137 					u8 dialog_token;
1138 					__le16 status;
1139 					__le16 capab;
1140 					__le16 timeout;
1141 				} __packed addba_resp;
1142 				struct{
1143 					u8 action_code;
1144 					__le16 params;
1145 					__le16 reason_code;
1146 				} __packed delba;
1147 				struct {
1148 					u8 action_code;
1149 					u8 variable[0];
1150 				} __packed self_prot;
1151 				struct{
1152 					u8 action_code;
1153 					u8 variable[0];
1154 				} __packed mesh_action;
1155 				struct {
1156 					u8 action;
1157 					u8 trans_id[WLAN_SA_QUERY_TR_ID_LEN];
1158 				} __packed sa_query;
1159 				struct {
1160 					u8 action;
1161 					u8 smps_control;
1162 				} __packed ht_smps;
1163 				struct {
1164 					u8 action_code;
1165 					u8 chanwidth;
1166 				} __packed ht_notify_cw;
1167 				struct {
1168 					u8 action_code;
1169 					u8 dialog_token;
1170 					__le16 capability;
1171 					u8 variable[0];
1172 				} __packed tdls_discover_resp;
1173 				struct {
1174 					u8 action_code;
1175 					u8 operating_mode;
1176 				} __packed vht_opmode_notif;
1177 				struct {
1178 					u8 action_code;
1179 					u8 membership[WLAN_MEMBERSHIP_LEN];
1180 					u8 position[WLAN_USER_POSITION_LEN];
1181 				} __packed vht_group_notif;
1182 				struct {
1183 					u8 action_code;
1184 					u8 dialog_token;
1185 					u8 tpc_elem_id;
1186 					u8 tpc_elem_length;
1187 					struct ieee80211_tpc_report_ie tpc;
1188 				} __packed tpc_report;
1189 				struct {
1190 					u8 action_code;
1191 					u8 dialog_token;
1192 					u8 follow_up;
1193 					u8 tod[6];
1194 					u8 toa[6];
1195 					__le16 tod_error;
1196 					__le16 toa_error;
1197 					u8 variable[0];
1198 				} __packed ftm;
1199 			} u;
1200 		} __packed action;
1201 	} u;
1202 } __packed __aligned(2);
1203 
1204 /* Supported rates membership selectors */
1205 #define BSS_MEMBERSHIP_SELECTOR_HT_PHY	127
1206 #define BSS_MEMBERSHIP_SELECTOR_VHT_PHY	126
1207 #define BSS_MEMBERSHIP_SELECTOR_HE_PHY	122
1208 
1209 /* mgmt header + 1 byte category code */
1210 #define IEEE80211_MIN_ACTION_SIZE offsetof(struct ieee80211_mgmt, u.action.u)
1211 
1212 
1213 /* Management MIC information element (IEEE 802.11w) */
1214 struct ieee80211_mmie {
1215 	u8 element_id;
1216 	u8 length;
1217 	__le16 key_id;
1218 	u8 sequence_number[6];
1219 	u8 mic[8];
1220 } __packed;
1221 
1222 /* Management MIC information element (IEEE 802.11w) for GMAC and CMAC-256 */
1223 struct ieee80211_mmie_16 {
1224 	u8 element_id;
1225 	u8 length;
1226 	__le16 key_id;
1227 	u8 sequence_number[6];
1228 	u8 mic[16];
1229 } __packed;
1230 
1231 struct ieee80211_vendor_ie {
1232 	u8 element_id;
1233 	u8 len;
1234 	u8 oui[3];
1235 	u8 oui_type;
1236 } __packed;
1237 
1238 struct ieee80211_wmm_ac_param {
1239 	u8 aci_aifsn; /* AIFSN, ACM, ACI */
1240 	u8 cw; /* ECWmin, ECWmax (CW = 2^ECW - 1) */
1241 	__le16 txop_limit;
1242 } __packed;
1243 
1244 struct ieee80211_wmm_param_ie {
1245 	u8 element_id; /* Element ID: 221 (0xdd); */
1246 	u8 len; /* Length: 24 */
1247 	/* required fields for WMM version 1 */
1248 	u8 oui[3]; /* 00:50:f2 */
1249 	u8 oui_type; /* 2 */
1250 	u8 oui_subtype; /* 1 */
1251 	u8 version; /* 1 for WMM version 1.0 */
1252 	u8 qos_info; /* AP/STA specific QoS info */
1253 	u8 reserved; /* 0 */
1254 	/* AC_BE, AC_BK, AC_VI, AC_VO */
1255 	struct ieee80211_wmm_ac_param ac[4];
1256 } __packed;
1257 
1258 /* Control frames */
1259 struct ieee80211_rts {
1260 	__le16 frame_control;
1261 	__le16 duration;
1262 	u8 ra[ETH_ALEN];
1263 	u8 ta[ETH_ALEN];
1264 } __packed __aligned(2);
1265 
1266 struct ieee80211_cts {
1267 	__le16 frame_control;
1268 	__le16 duration;
1269 	u8 ra[ETH_ALEN];
1270 } __packed __aligned(2);
1271 
1272 struct ieee80211_pspoll {
1273 	__le16 frame_control;
1274 	__le16 aid;
1275 	u8 bssid[ETH_ALEN];
1276 	u8 ta[ETH_ALEN];
1277 } __packed __aligned(2);
1278 
1279 /* TDLS */
1280 
1281 /* Channel switch timing */
1282 struct ieee80211_ch_switch_timing {
1283 	__le16 switch_time;
1284 	__le16 switch_timeout;
1285 } __packed;
1286 
1287 /* Link-id information element */
1288 struct ieee80211_tdls_lnkie {
1289 	u8 ie_type; /* Link Identifier IE */
1290 	u8 ie_len;
1291 	u8 bssid[ETH_ALEN];
1292 	u8 init_sta[ETH_ALEN];
1293 	u8 resp_sta[ETH_ALEN];
1294 } __packed;
1295 
1296 struct ieee80211_tdls_data {
1297 	u8 da[ETH_ALEN];
1298 	u8 sa[ETH_ALEN];
1299 	__be16 ether_type;
1300 	u8 payload_type;
1301 	u8 category;
1302 	u8 action_code;
1303 	union {
1304 		struct {
1305 			u8 dialog_token;
1306 			__le16 capability;
1307 			u8 variable[0];
1308 		} __packed setup_req;
1309 		struct {
1310 			__le16 status_code;
1311 			u8 dialog_token;
1312 			__le16 capability;
1313 			u8 variable[0];
1314 		} __packed setup_resp;
1315 		struct {
1316 			__le16 status_code;
1317 			u8 dialog_token;
1318 			u8 variable[0];
1319 		} __packed setup_cfm;
1320 		struct {
1321 			__le16 reason_code;
1322 			u8 variable[0];
1323 		} __packed teardown;
1324 		struct {
1325 			u8 dialog_token;
1326 			u8 variable[0];
1327 		} __packed discover_req;
1328 		struct {
1329 			u8 target_channel;
1330 			u8 oper_class;
1331 			u8 variable[0];
1332 		} __packed chan_switch_req;
1333 		struct {
1334 			__le16 status_code;
1335 			u8 variable[0];
1336 		} __packed chan_switch_resp;
1337 	} u;
1338 } __packed;
1339 
1340 /*
1341  * Peer-to-Peer IE attribute related definitions.
1342  */
1343 /**
1344  * enum ieee80211_p2p_attr_id - identifies type of peer-to-peer attribute.
1345  */
1346 enum ieee80211_p2p_attr_id {
1347 	IEEE80211_P2P_ATTR_STATUS = 0,
1348 	IEEE80211_P2P_ATTR_MINOR_REASON,
1349 	IEEE80211_P2P_ATTR_CAPABILITY,
1350 	IEEE80211_P2P_ATTR_DEVICE_ID,
1351 	IEEE80211_P2P_ATTR_GO_INTENT,
1352 	IEEE80211_P2P_ATTR_GO_CONFIG_TIMEOUT,
1353 	IEEE80211_P2P_ATTR_LISTEN_CHANNEL,
1354 	IEEE80211_P2P_ATTR_GROUP_BSSID,
1355 	IEEE80211_P2P_ATTR_EXT_LISTEN_TIMING,
1356 	IEEE80211_P2P_ATTR_INTENDED_IFACE_ADDR,
1357 	IEEE80211_P2P_ATTR_MANAGABILITY,
1358 	IEEE80211_P2P_ATTR_CHANNEL_LIST,
1359 	IEEE80211_P2P_ATTR_ABSENCE_NOTICE,
1360 	IEEE80211_P2P_ATTR_DEVICE_INFO,
1361 	IEEE80211_P2P_ATTR_GROUP_INFO,
1362 	IEEE80211_P2P_ATTR_GROUP_ID,
1363 	IEEE80211_P2P_ATTR_INTERFACE,
1364 	IEEE80211_P2P_ATTR_OPER_CHANNEL,
1365 	IEEE80211_P2P_ATTR_INVITE_FLAGS,
1366 	/* 19 - 220: Reserved */
1367 	IEEE80211_P2P_ATTR_VENDOR_SPECIFIC = 221,
1368 
1369 	IEEE80211_P2P_ATTR_MAX
1370 };
1371 
1372 /* Notice of Absence attribute - described in P2P spec 4.1.14 */
1373 /* Typical max value used here */
1374 #define IEEE80211_P2P_NOA_DESC_MAX	4
1375 
1376 struct ieee80211_p2p_noa_desc {
1377 	u8 count;
1378 	__le32 duration;
1379 	__le32 interval;
1380 	__le32 start_time;
1381 } __packed;
1382 
1383 struct ieee80211_p2p_noa_attr {
1384 	u8 index;
1385 	u8 oppps_ctwindow;
1386 	struct ieee80211_p2p_noa_desc desc[IEEE80211_P2P_NOA_DESC_MAX];
1387 } __packed;
1388 
1389 #define IEEE80211_P2P_OPPPS_ENABLE_BIT		BIT(7)
1390 #define IEEE80211_P2P_OPPPS_CTWINDOW_MASK	0x7F
1391 
1392 /**
1393  * struct ieee80211_bar - HT Block Ack Request
1394  *
1395  * This structure refers to "HT BlockAckReq" as
1396  * described in 802.11n draft section 7.2.1.7.1
1397  */
1398 struct ieee80211_bar {
1399 	__le16 frame_control;
1400 	__le16 duration;
1401 	__u8 ra[ETH_ALEN];
1402 	__u8 ta[ETH_ALEN];
1403 	__le16 control;
1404 	__le16 start_seq_num;
1405 } __packed;
1406 
1407 /* 802.11 BAR control masks */
1408 #define IEEE80211_BAR_CTRL_ACK_POLICY_NORMAL	0x0000
1409 #define IEEE80211_BAR_CTRL_MULTI_TID		0x0002
1410 #define IEEE80211_BAR_CTRL_CBMTID_COMPRESSED_BA	0x0004
1411 #define IEEE80211_BAR_CTRL_TID_INFO_MASK	0xf000
1412 #define IEEE80211_BAR_CTRL_TID_INFO_SHIFT	12
1413 
1414 #define IEEE80211_HT_MCS_MASK_LEN		10
1415 
1416 /**
1417  * struct ieee80211_mcs_info - MCS information
1418  * @rx_mask: RX mask
1419  * @rx_highest: highest supported RX rate. If set represents
1420  *	the highest supported RX data rate in units of 1 Mbps.
1421  *	If this field is 0 this value should not be used to
1422  *	consider the highest RX data rate supported.
1423  * @tx_params: TX parameters
1424  */
1425 struct ieee80211_mcs_info {
1426 	u8 rx_mask[IEEE80211_HT_MCS_MASK_LEN];
1427 	__le16 rx_highest;
1428 	u8 tx_params;
1429 	u8 reserved[3];
1430 } __packed;
1431 
1432 /* 802.11n HT capability MSC set */
1433 #define IEEE80211_HT_MCS_RX_HIGHEST_MASK	0x3ff
1434 #define IEEE80211_HT_MCS_TX_DEFINED		0x01
1435 #define IEEE80211_HT_MCS_TX_RX_DIFF		0x02
1436 /* value 0 == 1 stream etc */
1437 #define IEEE80211_HT_MCS_TX_MAX_STREAMS_MASK	0x0C
1438 #define IEEE80211_HT_MCS_TX_MAX_STREAMS_SHIFT	2
1439 #define		IEEE80211_HT_MCS_TX_MAX_STREAMS	4
1440 #define IEEE80211_HT_MCS_TX_UNEQUAL_MODULATION	0x10
1441 
1442 /*
1443  * 802.11n D5.0 20.3.5 / 20.6 says:
1444  * - indices 0 to 7 and 32 are single spatial stream
1445  * - 8 to 31 are multiple spatial streams using equal modulation
1446  *   [8..15 for two streams, 16..23 for three and 24..31 for four]
1447  * - remainder are multiple spatial streams using unequal modulation
1448  */
1449 #define IEEE80211_HT_MCS_UNEQUAL_MODULATION_START 33
1450 #define IEEE80211_HT_MCS_UNEQUAL_MODULATION_START_BYTE \
1451 	(IEEE80211_HT_MCS_UNEQUAL_MODULATION_START / 8)
1452 
1453 /**
1454  * struct ieee80211_ht_cap - HT capabilities
1455  *
1456  * This structure is the "HT capabilities element" as
1457  * described in 802.11n D5.0 7.3.2.57
1458  */
1459 struct ieee80211_ht_cap {
1460 	__le16 cap_info;
1461 	u8 ampdu_params_info;
1462 
1463 	/* 16 bytes MCS information */
1464 	struct ieee80211_mcs_info mcs;
1465 
1466 	__le16 extended_ht_cap_info;
1467 	__le32 tx_BF_cap_info;
1468 	u8 antenna_selection_info;
1469 } __packed;
1470 
1471 /* 802.11n HT capabilities masks (for cap_info) */
1472 #define IEEE80211_HT_CAP_LDPC_CODING		0x0001
1473 #define IEEE80211_HT_CAP_SUP_WIDTH_20_40	0x0002
1474 #define IEEE80211_HT_CAP_SM_PS			0x000C
1475 #define		IEEE80211_HT_CAP_SM_PS_SHIFT	2
1476 #define IEEE80211_HT_CAP_GRN_FLD		0x0010
1477 #define IEEE80211_HT_CAP_SGI_20			0x0020
1478 #define IEEE80211_HT_CAP_SGI_40			0x0040
1479 #define IEEE80211_HT_CAP_TX_STBC		0x0080
1480 #define IEEE80211_HT_CAP_RX_STBC		0x0300
1481 #define		IEEE80211_HT_CAP_RX_STBC_SHIFT	8
1482 #define IEEE80211_HT_CAP_DELAY_BA		0x0400
1483 #define IEEE80211_HT_CAP_MAX_AMSDU		0x0800
1484 #define IEEE80211_HT_CAP_DSSSCCK40		0x1000
1485 #define IEEE80211_HT_CAP_RESERVED		0x2000
1486 #define IEEE80211_HT_CAP_40MHZ_INTOLERANT	0x4000
1487 #define IEEE80211_HT_CAP_LSIG_TXOP_PROT		0x8000
1488 
1489 /* 802.11n HT extended capabilities masks (for extended_ht_cap_info) */
1490 #define IEEE80211_HT_EXT_CAP_PCO		0x0001
1491 #define IEEE80211_HT_EXT_CAP_PCO_TIME		0x0006
1492 #define		IEEE80211_HT_EXT_CAP_PCO_TIME_SHIFT	1
1493 #define IEEE80211_HT_EXT_CAP_MCS_FB		0x0300
1494 #define		IEEE80211_HT_EXT_CAP_MCS_FB_SHIFT	8
1495 #define IEEE80211_HT_EXT_CAP_HTC_SUP		0x0400
1496 #define IEEE80211_HT_EXT_CAP_RD_RESPONDER	0x0800
1497 
1498 /* 802.11n HT capability AMPDU settings (for ampdu_params_info) */
1499 #define IEEE80211_HT_AMPDU_PARM_FACTOR		0x03
1500 #define IEEE80211_HT_AMPDU_PARM_DENSITY		0x1C
1501 #define		IEEE80211_HT_AMPDU_PARM_DENSITY_SHIFT	2
1502 
1503 /*
1504  * Maximum length of AMPDU that the STA can receive in high-throughput (HT).
1505  * Length = 2 ^ (13 + max_ampdu_length_exp) - 1 (octets)
1506  */
1507 enum ieee80211_max_ampdu_length_exp {
1508 	IEEE80211_HT_MAX_AMPDU_8K = 0,
1509 	IEEE80211_HT_MAX_AMPDU_16K = 1,
1510 	IEEE80211_HT_MAX_AMPDU_32K = 2,
1511 	IEEE80211_HT_MAX_AMPDU_64K = 3
1512 };
1513 
1514 /*
1515  * Maximum length of AMPDU that the STA can receive in VHT.
1516  * Length = 2 ^ (13 + max_ampdu_length_exp) - 1 (octets)
1517  */
1518 enum ieee80211_vht_max_ampdu_length_exp {
1519 	IEEE80211_VHT_MAX_AMPDU_8K = 0,
1520 	IEEE80211_VHT_MAX_AMPDU_16K = 1,
1521 	IEEE80211_VHT_MAX_AMPDU_32K = 2,
1522 	IEEE80211_VHT_MAX_AMPDU_64K = 3,
1523 	IEEE80211_VHT_MAX_AMPDU_128K = 4,
1524 	IEEE80211_VHT_MAX_AMPDU_256K = 5,
1525 	IEEE80211_VHT_MAX_AMPDU_512K = 6,
1526 	IEEE80211_VHT_MAX_AMPDU_1024K = 7
1527 };
1528 
1529 #define IEEE80211_HT_MAX_AMPDU_FACTOR 13
1530 
1531 /* Minimum MPDU start spacing */
1532 enum ieee80211_min_mpdu_spacing {
1533 	IEEE80211_HT_MPDU_DENSITY_NONE = 0,	/* No restriction */
1534 	IEEE80211_HT_MPDU_DENSITY_0_25 = 1,	/* 1/4 usec */
1535 	IEEE80211_HT_MPDU_DENSITY_0_5 = 2,	/* 1/2 usec */
1536 	IEEE80211_HT_MPDU_DENSITY_1 = 3,	/* 1 usec */
1537 	IEEE80211_HT_MPDU_DENSITY_2 = 4,	/* 2 usec */
1538 	IEEE80211_HT_MPDU_DENSITY_4 = 5,	/* 4 usec */
1539 	IEEE80211_HT_MPDU_DENSITY_8 = 6,	/* 8 usec */
1540 	IEEE80211_HT_MPDU_DENSITY_16 = 7	/* 16 usec */
1541 };
1542 
1543 /**
1544  * struct ieee80211_ht_operation - HT operation IE
1545  *
1546  * This structure is the "HT operation element" as
1547  * described in 802.11n-2009 7.3.2.57
1548  */
1549 struct ieee80211_ht_operation {
1550 	u8 primary_chan;
1551 	u8 ht_param;
1552 	__le16 operation_mode;
1553 	__le16 stbc_param;
1554 	u8 basic_set[16];
1555 } __packed;
1556 
1557 /* for ht_param */
1558 #define IEEE80211_HT_PARAM_CHA_SEC_OFFSET		0x03
1559 #define		IEEE80211_HT_PARAM_CHA_SEC_NONE		0x00
1560 #define		IEEE80211_HT_PARAM_CHA_SEC_ABOVE	0x01
1561 #define		IEEE80211_HT_PARAM_CHA_SEC_BELOW	0x03
1562 #define IEEE80211_HT_PARAM_CHAN_WIDTH_ANY		0x04
1563 #define IEEE80211_HT_PARAM_RIFS_MODE			0x08
1564 
1565 /* for operation_mode */
1566 #define IEEE80211_HT_OP_MODE_PROTECTION			0x0003
1567 #define		IEEE80211_HT_OP_MODE_PROTECTION_NONE		0
1568 #define		IEEE80211_HT_OP_MODE_PROTECTION_NONMEMBER	1
1569 #define		IEEE80211_HT_OP_MODE_PROTECTION_20MHZ		2
1570 #define		IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED	3
1571 #define IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT		0x0004
1572 #define IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT		0x0010
1573 #define IEEE80211_HT_OP_MODE_CCFS2_SHIFT		5
1574 #define IEEE80211_HT_OP_MODE_CCFS2_MASK			0x1fe0
1575 
1576 /* for stbc_param */
1577 #define IEEE80211_HT_STBC_PARAM_DUAL_BEACON		0x0040
1578 #define IEEE80211_HT_STBC_PARAM_DUAL_CTS_PROT		0x0080
1579 #define IEEE80211_HT_STBC_PARAM_STBC_BEACON		0x0100
1580 #define IEEE80211_HT_STBC_PARAM_LSIG_TXOP_FULLPROT	0x0200
1581 #define IEEE80211_HT_STBC_PARAM_PCO_ACTIVE		0x0400
1582 #define IEEE80211_HT_STBC_PARAM_PCO_PHASE		0x0800
1583 
1584 
1585 /* block-ack parameters */
1586 #define IEEE80211_ADDBA_PARAM_AMSDU_MASK 0x0001
1587 #define IEEE80211_ADDBA_PARAM_POLICY_MASK 0x0002
1588 #define IEEE80211_ADDBA_PARAM_TID_MASK 0x003C
1589 #define IEEE80211_ADDBA_PARAM_BUF_SIZE_MASK 0xFFC0
1590 #define IEEE80211_DELBA_PARAM_TID_MASK 0xF000
1591 #define IEEE80211_DELBA_PARAM_INITIATOR_MASK 0x0800
1592 
1593 /*
1594  * A-MPDU buffer sizes
1595  * According to HT size varies from 8 to 64 frames
1596  * HE adds the ability to have up to 256 frames.
1597  */
1598 #define IEEE80211_MIN_AMPDU_BUF		0x8
1599 #define IEEE80211_MAX_AMPDU_BUF_HT	0x40
1600 #define IEEE80211_MAX_AMPDU_BUF		0x100
1601 
1602 
1603 /* Spatial Multiplexing Power Save Modes (for capability) */
1604 #define WLAN_HT_CAP_SM_PS_STATIC	0
1605 #define WLAN_HT_CAP_SM_PS_DYNAMIC	1
1606 #define WLAN_HT_CAP_SM_PS_INVALID	2
1607 #define WLAN_HT_CAP_SM_PS_DISABLED	3
1608 
1609 /* for SM power control field lower two bits */
1610 #define WLAN_HT_SMPS_CONTROL_DISABLED	0
1611 #define WLAN_HT_SMPS_CONTROL_STATIC	1
1612 #define WLAN_HT_SMPS_CONTROL_DYNAMIC	3
1613 
1614 /**
1615  * struct ieee80211_vht_mcs_info - VHT MCS information
1616  * @rx_mcs_map: RX MCS map 2 bits for each stream, total 8 streams
1617  * @rx_highest: Indicates highest long GI VHT PPDU data rate
1618  *	STA can receive. Rate expressed in units of 1 Mbps.
1619  *	If this field is 0 this value should not be used to
1620  *	consider the highest RX data rate supported.
1621  *	The top 3 bits of this field indicate the Maximum NSTS,total
1622  *	(a beamformee capability.)
1623  * @tx_mcs_map: TX MCS map 2 bits for each stream, total 8 streams
1624  * @tx_highest: Indicates highest long GI VHT PPDU data rate
1625  *	STA can transmit. Rate expressed in units of 1 Mbps.
1626  *	If this field is 0 this value should not be used to
1627  *	consider the highest TX data rate supported.
1628  *	The top 2 bits of this field are reserved, the
1629  *	3rd bit from the top indiciates VHT Extended NSS BW
1630  *	Capability.
1631  */
1632 struct ieee80211_vht_mcs_info {
1633 	__le16 rx_mcs_map;
1634 	__le16 rx_highest;
1635 	__le16 tx_mcs_map;
1636 	__le16 tx_highest;
1637 } __packed;
1638 
1639 /* for rx_highest */
1640 #define IEEE80211_VHT_MAX_NSTS_TOTAL_SHIFT	13
1641 #define IEEE80211_VHT_MAX_NSTS_TOTAL_MASK	(7 << IEEE80211_VHT_MAX_NSTS_TOTAL_SHIFT)
1642 
1643 /* for tx_highest */
1644 #define IEEE80211_VHT_EXT_NSS_BW_CAPABLE	(1 << 13)
1645 
1646 /**
1647  * enum ieee80211_vht_mcs_support - VHT MCS support definitions
1648  * @IEEE80211_VHT_MCS_SUPPORT_0_7: MCSes 0-7 are supported for the
1649  *	number of streams
1650  * @IEEE80211_VHT_MCS_SUPPORT_0_8: MCSes 0-8 are supported
1651  * @IEEE80211_VHT_MCS_SUPPORT_0_9: MCSes 0-9 are supported
1652  * @IEEE80211_VHT_MCS_NOT_SUPPORTED: This number of streams isn't supported
1653  *
1654  * These definitions are used in each 2-bit subfield of the @rx_mcs_map
1655  * and @tx_mcs_map fields of &struct ieee80211_vht_mcs_info, which are
1656  * both split into 8 subfields by number of streams. These values indicate
1657  * which MCSes are supported for the number of streams the value appears
1658  * for.
1659  */
1660 enum ieee80211_vht_mcs_support {
1661 	IEEE80211_VHT_MCS_SUPPORT_0_7	= 0,
1662 	IEEE80211_VHT_MCS_SUPPORT_0_8	= 1,
1663 	IEEE80211_VHT_MCS_SUPPORT_0_9	= 2,
1664 	IEEE80211_VHT_MCS_NOT_SUPPORTED	= 3,
1665 };
1666 
1667 /**
1668  * struct ieee80211_vht_cap - VHT capabilities
1669  *
1670  * This structure is the "VHT capabilities element" as
1671  * described in 802.11ac D3.0 8.4.2.160
1672  * @vht_cap_info: VHT capability info
1673  * @supp_mcs: VHT MCS supported rates
1674  */
1675 struct ieee80211_vht_cap {
1676 	__le32 vht_cap_info;
1677 	struct ieee80211_vht_mcs_info supp_mcs;
1678 } __packed;
1679 
1680 /**
1681  * enum ieee80211_vht_chanwidth - VHT channel width
1682  * @IEEE80211_VHT_CHANWIDTH_USE_HT: use the HT operation IE to
1683  *	determine the channel width (20 or 40 MHz)
1684  * @IEEE80211_VHT_CHANWIDTH_80MHZ: 80 MHz bandwidth
1685  * @IEEE80211_VHT_CHANWIDTH_160MHZ: 160 MHz bandwidth
1686  * @IEEE80211_VHT_CHANWIDTH_80P80MHZ: 80+80 MHz bandwidth
1687  */
1688 enum ieee80211_vht_chanwidth {
1689 	IEEE80211_VHT_CHANWIDTH_USE_HT		= 0,
1690 	IEEE80211_VHT_CHANWIDTH_80MHZ		= 1,
1691 	IEEE80211_VHT_CHANWIDTH_160MHZ		= 2,
1692 	IEEE80211_VHT_CHANWIDTH_80P80MHZ	= 3,
1693 };
1694 
1695 /**
1696  * struct ieee80211_vht_operation - VHT operation IE
1697  *
1698  * This structure is the "VHT operation element" as
1699  * described in 802.11ac D3.0 8.4.2.161
1700  * @chan_width: Operating channel width
1701  * @center_freq_seg0_idx: center freq segment 0 index
1702  * @center_freq_seg1_idx: center freq segment 1 index
1703  * @basic_mcs_set: VHT Basic MCS rate set
1704  */
1705 struct ieee80211_vht_operation {
1706 	u8 chan_width;
1707 	u8 center_freq_seg0_idx;
1708 	u8 center_freq_seg1_idx;
1709 	__le16 basic_mcs_set;
1710 } __packed;
1711 
1712 /**
1713  * struct ieee80211_he_cap_elem - HE capabilities element
1714  *
1715  * This structure is the "HE capabilities element" fixed fields as
1716  * described in P802.11ax_D4.0 section 9.4.2.242.2 and 9.4.2.242.3
1717  */
1718 struct ieee80211_he_cap_elem {
1719 	u8 mac_cap_info[6];
1720 	u8 phy_cap_info[11];
1721 } __packed;
1722 
1723 #define IEEE80211_TX_RX_MCS_NSS_DESC_MAX_LEN	5
1724 
1725 /**
1726  * enum ieee80211_he_mcs_support - HE MCS support definitions
1727  * @IEEE80211_HE_MCS_SUPPORT_0_7: MCSes 0-7 are supported for the
1728  *	number of streams
1729  * @IEEE80211_HE_MCS_SUPPORT_0_9: MCSes 0-9 are supported
1730  * @IEEE80211_HE_MCS_SUPPORT_0_11: MCSes 0-11 are supported
1731  * @IEEE80211_HE_MCS_NOT_SUPPORTED: This number of streams isn't supported
1732  *
1733  * These definitions are used in each 2-bit subfield of the rx_mcs_*
1734  * and tx_mcs_* fields of &struct ieee80211_he_mcs_nss_supp, which are
1735  * both split into 8 subfields by number of streams. These values indicate
1736  * which MCSes are supported for the number of streams the value appears
1737  * for.
1738  */
1739 enum ieee80211_he_mcs_support {
1740 	IEEE80211_HE_MCS_SUPPORT_0_7	= 0,
1741 	IEEE80211_HE_MCS_SUPPORT_0_9	= 1,
1742 	IEEE80211_HE_MCS_SUPPORT_0_11	= 2,
1743 	IEEE80211_HE_MCS_NOT_SUPPORTED	= 3,
1744 };
1745 
1746 /**
1747  * struct ieee80211_he_mcs_nss_supp - HE Tx/Rx HE MCS NSS Support Field
1748  *
1749  * This structure holds the data required for the Tx/Rx HE MCS NSS Support Field
1750  * described in P802.11ax_D2.0 section 9.4.2.237.4
1751  *
1752  * @rx_mcs_80: Rx MCS map 2 bits for each stream, total 8 streams, for channel
1753  *     widths less than 80MHz.
1754  * @tx_mcs_80: Tx MCS map 2 bits for each stream, total 8 streams, for channel
1755  *     widths less than 80MHz.
1756  * @rx_mcs_160: Rx MCS map 2 bits for each stream, total 8 streams, for channel
1757  *     width 160MHz.
1758  * @tx_mcs_160: Tx MCS map 2 bits for each stream, total 8 streams, for channel
1759  *     width 160MHz.
1760  * @rx_mcs_80p80: Rx MCS map 2 bits for each stream, total 8 streams, for
1761  *     channel width 80p80MHz.
1762  * @tx_mcs_80p80: Tx MCS map 2 bits for each stream, total 8 streams, for
1763  *     channel width 80p80MHz.
1764  */
1765 struct ieee80211_he_mcs_nss_supp {
1766 	__le16 rx_mcs_80;
1767 	__le16 tx_mcs_80;
1768 	__le16 rx_mcs_160;
1769 	__le16 tx_mcs_160;
1770 	__le16 rx_mcs_80p80;
1771 	__le16 tx_mcs_80p80;
1772 } __packed;
1773 
1774 /**
1775  * struct ieee80211_he_operation - HE capabilities element
1776  *
1777  * This structure is the "HE operation element" fields as
1778  * described in P802.11ax_D4.0 section 9.4.2.243
1779  */
1780 struct ieee80211_he_operation {
1781 	__le32 he_oper_params;
1782 	__le16 he_mcs_nss_set;
1783 	/* Optional 0,1,3,4,5,7 or 8 bytes: depends on @he_oper_params */
1784 	u8 optional[];
1785 } __packed;
1786 
1787 /**
1788  * struct ieee80211_he_spr - HE spatial reuse element
1789  *
1790  * This structure is the "HE spatial reuse element" element as
1791  * described in P802.11ax_D4.0 section 9.4.2.241
1792  */
1793 struct ieee80211_he_spr {
1794 	u8 he_sr_control;
1795 	/* Optional 0 to 19 bytes: depends on @he_sr_control */
1796 	u8 optional[];
1797 } __packed;
1798 
1799 /**
1800  * struct ieee80211_he_mu_edca_param_ac_rec - MU AC Parameter Record field
1801  *
1802  * This structure is the "MU AC Parameter Record" fields as
1803  * described in P802.11ax_D4.0 section 9.4.2.245
1804  */
1805 struct ieee80211_he_mu_edca_param_ac_rec {
1806 	u8 aifsn;
1807 	u8 ecw_min_max;
1808 	u8 mu_edca_timer;
1809 } __packed;
1810 
1811 /**
1812  * struct ieee80211_mu_edca_param_set - MU EDCA Parameter Set element
1813  *
1814  * This structure is the "MU EDCA Parameter Set element" fields as
1815  * described in P802.11ax_D4.0 section 9.4.2.245
1816  */
1817 struct ieee80211_mu_edca_param_set {
1818 	u8 mu_qos_info;
1819 	struct ieee80211_he_mu_edca_param_ac_rec ac_be;
1820 	struct ieee80211_he_mu_edca_param_ac_rec ac_bk;
1821 	struct ieee80211_he_mu_edca_param_ac_rec ac_vi;
1822 	struct ieee80211_he_mu_edca_param_ac_rec ac_vo;
1823 } __packed;
1824 
1825 /* 802.11ac VHT Capabilities */
1826 #define IEEE80211_VHT_CAP_MAX_MPDU_LENGTH_3895			0x00000000
1827 #define IEEE80211_VHT_CAP_MAX_MPDU_LENGTH_7991			0x00000001
1828 #define IEEE80211_VHT_CAP_MAX_MPDU_LENGTH_11454			0x00000002
1829 #define IEEE80211_VHT_CAP_MAX_MPDU_MASK				0x00000003
1830 #define IEEE80211_VHT_CAP_SUPP_CHAN_WIDTH_160MHZ		0x00000004
1831 #define IEEE80211_VHT_CAP_SUPP_CHAN_WIDTH_160_80PLUS80MHZ	0x00000008
1832 #define IEEE80211_VHT_CAP_SUPP_CHAN_WIDTH_MASK			0x0000000C
1833 #define IEEE80211_VHT_CAP_SUPP_CHAN_WIDTH_SHIFT			2
1834 #define IEEE80211_VHT_CAP_RXLDPC				0x00000010
1835 #define IEEE80211_VHT_CAP_SHORT_GI_80				0x00000020
1836 #define IEEE80211_VHT_CAP_SHORT_GI_160				0x00000040
1837 #define IEEE80211_VHT_CAP_TXSTBC				0x00000080
1838 #define IEEE80211_VHT_CAP_RXSTBC_1				0x00000100
1839 #define IEEE80211_VHT_CAP_RXSTBC_2				0x00000200
1840 #define IEEE80211_VHT_CAP_RXSTBC_3				0x00000300
1841 #define IEEE80211_VHT_CAP_RXSTBC_4				0x00000400
1842 #define IEEE80211_VHT_CAP_RXSTBC_MASK				0x00000700
1843 #define IEEE80211_VHT_CAP_RXSTBC_SHIFT				8
1844 #define IEEE80211_VHT_CAP_SU_BEAMFORMER_CAPABLE			0x00000800
1845 #define IEEE80211_VHT_CAP_SU_BEAMFORMEE_CAPABLE			0x00001000
1846 #define IEEE80211_VHT_CAP_BEAMFORMEE_STS_SHIFT                  13
1847 #define IEEE80211_VHT_CAP_BEAMFORMEE_STS_MASK			\
1848 		(7 << IEEE80211_VHT_CAP_BEAMFORMEE_STS_SHIFT)
1849 #define IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_SHIFT		16
1850 #define IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_MASK		\
1851 		(7 << IEEE80211_VHT_CAP_SOUNDING_DIMENSIONS_SHIFT)
1852 #define IEEE80211_VHT_CAP_MU_BEAMFORMER_CAPABLE			0x00080000
1853 #define IEEE80211_VHT_CAP_MU_BEAMFORMEE_CAPABLE			0x00100000
1854 #define IEEE80211_VHT_CAP_VHT_TXOP_PS				0x00200000
1855 #define IEEE80211_VHT_CAP_HTC_VHT				0x00400000
1856 #define IEEE80211_VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_SHIFT	23
1857 #define IEEE80211_VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MASK	\
1858 		(7 << IEEE80211_VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_SHIFT)
1859 #define IEEE80211_VHT_CAP_VHT_LINK_ADAPTATION_VHT_UNSOL_MFB	0x08000000
1860 #define IEEE80211_VHT_CAP_VHT_LINK_ADAPTATION_VHT_MRQ_MFB	0x0c000000
1861 #define IEEE80211_VHT_CAP_RX_ANTENNA_PATTERN			0x10000000
1862 #define IEEE80211_VHT_CAP_TX_ANTENNA_PATTERN			0x20000000
1863 #define IEEE80211_VHT_CAP_EXT_NSS_BW_SHIFT			30
1864 #define IEEE80211_VHT_CAP_EXT_NSS_BW_MASK			0xc0000000
1865 
1866 /**
1867  * ieee80211_get_vht_max_nss - return max NSS for a given bandwidth/MCS
1868  * @cap: VHT capabilities of the peer
1869  * @bw: bandwidth to use
1870  * @mcs: MCS index to use
1871  * @ext_nss_bw_capable: indicates whether or not the local transmitter
1872  *	(rate scaling algorithm) can deal with the new logic
1873  *	(dot11VHTExtendedNSSBWCapable)
1874  * @max_vht_nss: current maximum NSS as advertised by the STA in
1875  *	operating mode notification, can be 0 in which case the
1876  *	capability data will be used to derive this (from MCS support)
1877  *
1878  * Due to the VHT Extended NSS Bandwidth Support, the maximum NSS can
1879  * vary for a given BW/MCS. This function parses the data.
1880  *
1881  * Note: This function is exported by cfg80211.
1882  */
1883 int ieee80211_get_vht_max_nss(struct ieee80211_vht_cap *cap,
1884 			      enum ieee80211_vht_chanwidth bw,
1885 			      int mcs, bool ext_nss_bw_capable,
1886 			      unsigned int max_vht_nss);
1887 
1888 /* 802.11ax HE MAC capabilities */
1889 #define IEEE80211_HE_MAC_CAP0_HTC_HE				0x01
1890 #define IEEE80211_HE_MAC_CAP0_TWT_REQ				0x02
1891 #define IEEE80211_HE_MAC_CAP0_TWT_RES				0x04
1892 #define IEEE80211_HE_MAC_CAP0_DYNAMIC_FRAG_NOT_SUPP		0x00
1893 #define IEEE80211_HE_MAC_CAP0_DYNAMIC_FRAG_LEVEL_1		0x08
1894 #define IEEE80211_HE_MAC_CAP0_DYNAMIC_FRAG_LEVEL_2		0x10
1895 #define IEEE80211_HE_MAC_CAP0_DYNAMIC_FRAG_LEVEL_3		0x18
1896 #define IEEE80211_HE_MAC_CAP0_DYNAMIC_FRAG_MASK			0x18
1897 #define IEEE80211_HE_MAC_CAP0_MAX_NUM_FRAG_MSDU_1		0x00
1898 #define IEEE80211_HE_MAC_CAP0_MAX_NUM_FRAG_MSDU_2		0x20
1899 #define IEEE80211_HE_MAC_CAP0_MAX_NUM_FRAG_MSDU_4		0x40
1900 #define IEEE80211_HE_MAC_CAP0_MAX_NUM_FRAG_MSDU_8		0x60
1901 #define IEEE80211_HE_MAC_CAP0_MAX_NUM_FRAG_MSDU_16		0x80
1902 #define IEEE80211_HE_MAC_CAP0_MAX_NUM_FRAG_MSDU_32		0xa0
1903 #define IEEE80211_HE_MAC_CAP0_MAX_NUM_FRAG_MSDU_64		0xc0
1904 #define IEEE80211_HE_MAC_CAP0_MAX_NUM_FRAG_MSDU_UNLIMITED	0xe0
1905 #define IEEE80211_HE_MAC_CAP0_MAX_NUM_FRAG_MSDU_MASK		0xe0
1906 
1907 #define IEEE80211_HE_MAC_CAP1_MIN_FRAG_SIZE_UNLIMITED		0x00
1908 #define IEEE80211_HE_MAC_CAP1_MIN_FRAG_SIZE_128			0x01
1909 #define IEEE80211_HE_MAC_CAP1_MIN_FRAG_SIZE_256			0x02
1910 #define IEEE80211_HE_MAC_CAP1_MIN_FRAG_SIZE_512			0x03
1911 #define IEEE80211_HE_MAC_CAP1_MIN_FRAG_SIZE_MASK		0x03
1912 #define IEEE80211_HE_MAC_CAP1_TF_MAC_PAD_DUR_0US		0x00
1913 #define IEEE80211_HE_MAC_CAP1_TF_MAC_PAD_DUR_8US		0x04
1914 #define IEEE80211_HE_MAC_CAP1_TF_MAC_PAD_DUR_16US		0x08
1915 #define IEEE80211_HE_MAC_CAP1_TF_MAC_PAD_DUR_MASK		0x0c
1916 #define IEEE80211_HE_MAC_CAP1_MULTI_TID_AGG_RX_QOS_1		0x00
1917 #define IEEE80211_HE_MAC_CAP1_MULTI_TID_AGG_RX_QOS_2		0x10
1918 #define IEEE80211_HE_MAC_CAP1_MULTI_TID_AGG_RX_QOS_3		0x20
1919 #define IEEE80211_HE_MAC_CAP1_MULTI_TID_AGG_RX_QOS_4		0x30
1920 #define IEEE80211_HE_MAC_CAP1_MULTI_TID_AGG_RX_QOS_5		0x40
1921 #define IEEE80211_HE_MAC_CAP1_MULTI_TID_AGG_RX_QOS_6		0x50
1922 #define IEEE80211_HE_MAC_CAP1_MULTI_TID_AGG_RX_QOS_7		0x60
1923 #define IEEE80211_HE_MAC_CAP1_MULTI_TID_AGG_RX_QOS_8		0x70
1924 #define IEEE80211_HE_MAC_CAP1_MULTI_TID_AGG_RX_QOS_MASK		0x70
1925 
1926 /* Link adaptation is split between byte HE_MAC_CAP1 and
1927  * HE_MAC_CAP2. It should be set only if IEEE80211_HE_MAC_CAP0_HTC_HE
1928  * in which case the following values apply:
1929  * 0 = No feedback.
1930  * 1 = reserved.
1931  * 2 = Unsolicited feedback.
1932  * 3 = both
1933  */
1934 #define IEEE80211_HE_MAC_CAP1_LINK_ADAPTATION			0x80
1935 
1936 #define IEEE80211_HE_MAC_CAP2_LINK_ADAPTATION			0x01
1937 #define IEEE80211_HE_MAC_CAP2_ALL_ACK				0x02
1938 #define IEEE80211_HE_MAC_CAP2_TRS				0x04
1939 #define IEEE80211_HE_MAC_CAP2_BSR				0x08
1940 #define IEEE80211_HE_MAC_CAP2_BCAST_TWT				0x10
1941 #define IEEE80211_HE_MAC_CAP2_32BIT_BA_BITMAP			0x20
1942 #define IEEE80211_HE_MAC_CAP2_MU_CASCADING			0x40
1943 #define IEEE80211_HE_MAC_CAP2_ACK_EN				0x80
1944 
1945 #define IEEE80211_HE_MAC_CAP3_OMI_CONTROL			0x02
1946 #define IEEE80211_HE_MAC_CAP3_OFDMA_RA				0x04
1947 
1948 /* The maximum length of an A-MDPU is defined by the combination of the Maximum
1949  * A-MDPU Length Exponent field in the HT capabilities, VHT capabilities and the
1950  * same field in the HE capabilities.
1951  */
1952 #define IEEE80211_HE_MAC_CAP3_MAX_AMPDU_LEN_EXP_USE_VHT	0x00
1953 #define IEEE80211_HE_MAC_CAP3_MAX_AMPDU_LEN_EXP_VHT_1		0x08
1954 #define IEEE80211_HE_MAC_CAP3_MAX_AMPDU_LEN_EXP_VHT_2		0x10
1955 #define IEEE80211_HE_MAC_CAP3_MAX_AMPDU_LEN_EXP_RESERVED	0x18
1956 #define IEEE80211_HE_MAC_CAP3_MAX_AMPDU_LEN_EXP_MASK		0x18
1957 #define IEEE80211_HE_MAC_CAP3_AMSDU_FRAG			0x20
1958 #define IEEE80211_HE_MAC_CAP3_FLEX_TWT_SCHED			0x40
1959 #define IEEE80211_HE_MAC_CAP3_RX_CTRL_FRAME_TO_MULTIBSS		0x80
1960 
1961 #define IEEE80211_HE_MAC_CAP3_MAX_AMPDU_LEN_EXP_SHIFT		3
1962 
1963 #define IEEE80211_HE_MAC_CAP4_BSRP_BQRP_A_MPDU_AGG		0x01
1964 #define IEEE80211_HE_MAC_CAP4_QTP				0x02
1965 #define IEEE80211_HE_MAC_CAP4_BQR				0x04
1966 #define IEEE80211_HE_MAC_CAP4_SRP_RESP				0x08
1967 #define IEEE80211_HE_MAC_CAP4_NDP_FB_REP			0x10
1968 #define IEEE80211_HE_MAC_CAP4_OPS				0x20
1969 #define IEEE80211_HE_MAC_CAP4_AMDSU_IN_AMPDU			0x40
1970 /* Multi TID agg TX is split between byte #4 and #5
1971  * The value is a combination of B39,B40,B41
1972  */
1973 #define IEEE80211_HE_MAC_CAP4_MULTI_TID_AGG_TX_QOS_B39		0x80
1974 
1975 #define IEEE80211_HE_MAC_CAP5_MULTI_TID_AGG_TX_QOS_B40		0x01
1976 #define IEEE80211_HE_MAC_CAP5_MULTI_TID_AGG_TX_QOS_B41		0x02
1977 #define IEEE80211_HE_MAC_CAP5_SUBCHAN_SELECVITE_TRANSMISSION	0x04
1978 #define IEEE80211_HE_MAC_CAP5_UL_2x996_TONE_RU			0x08
1979 #define IEEE80211_HE_MAC_CAP5_OM_CTRL_UL_MU_DATA_DIS_RX		0x10
1980 #define IEEE80211_HE_MAC_CAP5_HE_DYNAMIC_SM_PS			0x20
1981 #define IEEE80211_HE_MAC_CAP5_PUNCTURED_SOUNDING		0x40
1982 #define IEEE80211_HE_MAC_CAP5_HT_VHT_TRIG_FRAME_RX		0x80
1983 
1984 #define IEEE80211_HE_VHT_MAX_AMPDU_FACTOR	20
1985 #define IEEE80211_HE_HT_MAX_AMPDU_FACTOR	16
1986 
1987 /* 802.11ax HE PHY capabilities */
1988 #define IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_40MHZ_IN_2G		0x02
1989 #define IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_40MHZ_80MHZ_IN_5G	0x04
1990 #define IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_160MHZ_IN_5G		0x08
1991 #define IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_80PLUS80_MHZ_IN_5G	0x10
1992 #define IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_RU_MAPPING_IN_2G	0x20
1993 #define IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_RU_MAPPING_IN_5G	0x40
1994 #define IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_MASK			0xfe
1995 
1996 #define IEEE80211_HE_PHY_CAP1_PREAMBLE_PUNC_RX_80MHZ_ONLY_SECOND_20MHZ	0x01
1997 #define IEEE80211_HE_PHY_CAP1_PREAMBLE_PUNC_RX_80MHZ_ONLY_SECOND_40MHZ	0x02
1998 #define IEEE80211_HE_PHY_CAP1_PREAMBLE_PUNC_RX_160MHZ_ONLY_SECOND_20MHZ	0x04
1999 #define IEEE80211_HE_PHY_CAP1_PREAMBLE_PUNC_RX_160MHZ_ONLY_SECOND_40MHZ	0x08
2000 #define IEEE80211_HE_PHY_CAP1_PREAMBLE_PUNC_RX_MASK			0x0f
2001 #define IEEE80211_HE_PHY_CAP1_DEVICE_CLASS_A				0x10
2002 #define IEEE80211_HE_PHY_CAP1_LDPC_CODING_IN_PAYLOAD			0x20
2003 #define IEEE80211_HE_PHY_CAP1_HE_LTF_AND_GI_FOR_HE_PPDUS_0_8US		0x40
2004 /* Midamble RX/TX Max NSTS is split between byte #2 and byte #3 */
2005 #define IEEE80211_HE_PHY_CAP1_MIDAMBLE_RX_TX_MAX_NSTS			0x80
2006 
2007 #define IEEE80211_HE_PHY_CAP2_MIDAMBLE_RX_TX_MAX_NSTS			0x01
2008 #define IEEE80211_HE_PHY_CAP2_NDP_4x_LTF_AND_3_2US			0x02
2009 #define IEEE80211_HE_PHY_CAP2_STBC_TX_UNDER_80MHZ			0x04
2010 #define IEEE80211_HE_PHY_CAP2_STBC_RX_UNDER_80MHZ			0x08
2011 #define IEEE80211_HE_PHY_CAP2_DOPPLER_TX				0x10
2012 #define IEEE80211_HE_PHY_CAP2_DOPPLER_RX				0x20
2013 
2014 /* Note that the meaning of UL MU below is different between an AP and a non-AP
2015  * sta, where in the AP case it indicates support for Rx and in the non-AP sta
2016  * case it indicates support for Tx.
2017  */
2018 #define IEEE80211_HE_PHY_CAP2_UL_MU_FULL_MU_MIMO			0x40
2019 #define IEEE80211_HE_PHY_CAP2_UL_MU_PARTIAL_MU_MIMO			0x80
2020 
2021 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_TX_NO_DCM			0x00
2022 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_TX_BPSK			0x01
2023 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_TX_QPSK			0x02
2024 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_TX_16_QAM			0x03
2025 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_TX_MASK			0x03
2026 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_TX_NSS_1				0x00
2027 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_TX_NSS_2				0x04
2028 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_RX_NO_DCM			0x00
2029 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_RX_BPSK			0x08
2030 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_RX_QPSK			0x10
2031 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_RX_16_QAM			0x18
2032 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_CONST_RX_MASK			0x18
2033 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_RX_NSS_1				0x00
2034 #define IEEE80211_HE_PHY_CAP3_DCM_MAX_RX_NSS_2				0x20
2035 #define IEEE80211_HE_PHY_CAP3_RX_HE_MU_PPDU_FROM_NON_AP_STA		0x40
2036 #define IEEE80211_HE_PHY_CAP3_SU_BEAMFORMER				0x80
2037 
2038 #define IEEE80211_HE_PHY_CAP4_SU_BEAMFORMEE				0x01
2039 #define IEEE80211_HE_PHY_CAP4_MU_BEAMFORMER				0x02
2040 
2041 /* Minimal allowed value of Max STS under 80MHz is 3 */
2042 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_UNDER_80MHZ_4		0x0c
2043 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_UNDER_80MHZ_5		0x10
2044 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_UNDER_80MHZ_6		0x14
2045 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_UNDER_80MHZ_7		0x18
2046 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_UNDER_80MHZ_8		0x1c
2047 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_UNDER_80MHZ_MASK	0x1c
2048 
2049 /* Minimal allowed value of Max STS above 80MHz is 3 */
2050 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_ABOVE_80MHZ_4		0x60
2051 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_ABOVE_80MHZ_5		0x80
2052 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_ABOVE_80MHZ_6		0xa0
2053 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_ABOVE_80MHZ_7		0xc0
2054 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_ABOVE_80MHZ_8		0xe0
2055 #define IEEE80211_HE_PHY_CAP4_BEAMFORMEE_MAX_STS_ABOVE_80MHZ_MASK	0xe0
2056 
2057 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_1	0x00
2058 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_2	0x01
2059 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_3	0x02
2060 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_4	0x03
2061 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_5	0x04
2062 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_6	0x05
2063 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_7	0x06
2064 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_8	0x07
2065 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_UNDER_80MHZ_MASK	0x07
2066 
2067 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_1	0x00
2068 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_2	0x08
2069 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_3	0x10
2070 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_4	0x18
2071 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_5	0x20
2072 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_6	0x28
2073 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_7	0x30
2074 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_8	0x38
2075 #define IEEE80211_HE_PHY_CAP5_BEAMFORMEE_NUM_SND_DIM_ABOVE_80MHZ_MASK	0x38
2076 
2077 #define IEEE80211_HE_PHY_CAP5_NG16_SU_FEEDBACK				0x40
2078 #define IEEE80211_HE_PHY_CAP5_NG16_MU_FEEDBACK				0x80
2079 
2080 #define IEEE80211_HE_PHY_CAP6_CODEBOOK_SIZE_42_SU			0x01
2081 #define IEEE80211_HE_PHY_CAP6_CODEBOOK_SIZE_75_MU			0x02
2082 #define IEEE80211_HE_PHY_CAP6_TRIG_SU_BEAMFORMER_FB			0x04
2083 #define IEEE80211_HE_PHY_CAP6_TRIG_MU_BEAMFORMER_FB			0x08
2084 #define IEEE80211_HE_PHY_CAP6_TRIG_CQI_FB				0x10
2085 #define IEEE80211_HE_PHY_CAP6_PARTIAL_BW_EXT_RANGE			0x20
2086 #define IEEE80211_HE_PHY_CAP6_PARTIAL_BANDWIDTH_DL_MUMIMO		0x40
2087 #define IEEE80211_HE_PHY_CAP6_PPE_THRESHOLD_PRESENT			0x80
2088 
2089 #define IEEE80211_HE_PHY_CAP7_SRP_BASED_SR				0x01
2090 #define IEEE80211_HE_PHY_CAP7_POWER_BOOST_FACTOR_AR			0x02
2091 #define IEEE80211_HE_PHY_CAP7_HE_SU_MU_PPDU_4XLTF_AND_08_US_GI		0x04
2092 #define IEEE80211_HE_PHY_CAP7_MAX_NC_1					0x08
2093 #define IEEE80211_HE_PHY_CAP7_MAX_NC_2					0x10
2094 #define IEEE80211_HE_PHY_CAP7_MAX_NC_3					0x18
2095 #define IEEE80211_HE_PHY_CAP7_MAX_NC_4					0x20
2096 #define IEEE80211_HE_PHY_CAP7_MAX_NC_5					0x28
2097 #define IEEE80211_HE_PHY_CAP7_MAX_NC_6					0x30
2098 #define IEEE80211_HE_PHY_CAP7_MAX_NC_7					0x38
2099 #define IEEE80211_HE_PHY_CAP7_MAX_NC_MASK				0x38
2100 #define IEEE80211_HE_PHY_CAP7_STBC_TX_ABOVE_80MHZ			0x40
2101 #define IEEE80211_HE_PHY_CAP7_STBC_RX_ABOVE_80MHZ			0x80
2102 
2103 #define IEEE80211_HE_PHY_CAP8_HE_ER_SU_PPDU_4XLTF_AND_08_US_GI		0x01
2104 #define IEEE80211_HE_PHY_CAP8_20MHZ_IN_40MHZ_HE_PPDU_IN_2G		0x02
2105 #define IEEE80211_HE_PHY_CAP8_20MHZ_IN_160MHZ_HE_PPDU			0x04
2106 #define IEEE80211_HE_PHY_CAP8_80MHZ_IN_160MHZ_HE_PPDU			0x08
2107 #define IEEE80211_HE_PHY_CAP8_HE_ER_SU_1XLTF_AND_08_US_GI		0x10
2108 #define IEEE80211_HE_PHY_CAP8_MIDAMBLE_RX_TX_2X_AND_1XLTF		0x20
2109 #define IEEE80211_HE_PHY_CAP8_DCM_MAX_RU_242				0x00
2110 #define IEEE80211_HE_PHY_CAP8_DCM_MAX_RU_484				0x40
2111 #define IEEE80211_HE_PHY_CAP8_DCM_MAX_RU_996				0x80
2112 #define IEEE80211_HE_PHY_CAP8_DCM_MAX_RU_2x996				0xc0
2113 #define IEEE80211_HE_PHY_CAP8_DCM_MAX_RU_MASK				0xc0
2114 
2115 #define IEEE80211_HE_PHY_CAP9_LONGER_THAN_16_SIGB_OFDM_SYM		0x01
2116 #define IEEE80211_HE_PHY_CAP9_NON_TRIGGERED_CQI_FEEDBACK		0x02
2117 #define IEEE80211_HE_PHY_CAP9_TX_1024_QAM_LESS_THAN_242_TONE_RU		0x04
2118 #define IEEE80211_HE_PHY_CAP9_RX_1024_QAM_LESS_THAN_242_TONE_RU		0x08
2119 #define IEEE80211_HE_PHY_CAP9_RX_FULL_BW_SU_USING_MU_WITH_COMP_SIGB	0x10
2120 #define IEEE80211_HE_PHY_CAP9_RX_FULL_BW_SU_USING_MU_WITH_NON_COMP_SIGB	0x20
2121 #define IEEE80211_HE_PHY_CAP9_NOMIMAL_PKT_PADDING_0US			0x00
2122 #define IEEE80211_HE_PHY_CAP9_NOMIMAL_PKT_PADDING_8US			0x40
2123 #define IEEE80211_HE_PHY_CAP9_NOMIMAL_PKT_PADDING_16US			0x80
2124 #define IEEE80211_HE_PHY_CAP9_NOMIMAL_PKT_PADDING_RESERVED		0xc0
2125 #define IEEE80211_HE_PHY_CAP9_NOMIMAL_PKT_PADDING_MASK			0xc0
2126 
2127 /* 802.11ax HE TX/RX MCS NSS Support  */
2128 #define IEEE80211_TX_RX_MCS_NSS_SUPP_HIGHEST_MCS_POS			(3)
2129 #define IEEE80211_TX_RX_MCS_NSS_SUPP_TX_BITMAP_POS			(6)
2130 #define IEEE80211_TX_RX_MCS_NSS_SUPP_RX_BITMAP_POS			(11)
2131 #define IEEE80211_TX_RX_MCS_NSS_SUPP_TX_BITMAP_MASK			0x07c0
2132 #define IEEE80211_TX_RX_MCS_NSS_SUPP_RX_BITMAP_MASK			0xf800
2133 
2134 /* TX/RX HE MCS Support field Highest MCS subfield encoding */
2135 enum ieee80211_he_highest_mcs_supported_subfield_enc {
2136 	HIGHEST_MCS_SUPPORTED_MCS7 = 0,
2137 	HIGHEST_MCS_SUPPORTED_MCS8,
2138 	HIGHEST_MCS_SUPPORTED_MCS9,
2139 	HIGHEST_MCS_SUPPORTED_MCS10,
2140 	HIGHEST_MCS_SUPPORTED_MCS11,
2141 };
2142 
2143 /* Calculate 802.11ax HE capabilities IE Tx/Rx HE MCS NSS Support Field size */
2144 static inline u8
2145 ieee80211_he_mcs_nss_size(const struct ieee80211_he_cap_elem *he_cap)
2146 {
2147 	u8 count = 4;
2148 
2149 	if (he_cap->phy_cap_info[0] &
2150 	    IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_160MHZ_IN_5G)
2151 		count += 4;
2152 
2153 	if (he_cap->phy_cap_info[0] &
2154 	    IEEE80211_HE_PHY_CAP0_CHANNEL_WIDTH_SET_80PLUS80_MHZ_IN_5G)
2155 		count += 4;
2156 
2157 	return count;
2158 }
2159 
2160 /* 802.11ax HE PPE Thresholds */
2161 #define IEEE80211_PPE_THRES_NSS_SUPPORT_2NSS			(1)
2162 #define IEEE80211_PPE_THRES_NSS_POS				(0)
2163 #define IEEE80211_PPE_THRES_NSS_MASK				(7)
2164 #define IEEE80211_PPE_THRES_RU_INDEX_BITMASK_2x966_AND_966_RU	\
2165 	(BIT(5) | BIT(6))
2166 #define IEEE80211_PPE_THRES_RU_INDEX_BITMASK_MASK		0x78
2167 #define IEEE80211_PPE_THRES_RU_INDEX_BITMASK_POS		(3)
2168 #define IEEE80211_PPE_THRES_INFO_PPET_SIZE			(3)
2169 
2170 /*
2171  * Calculate 802.11ax HE capabilities IE PPE field size
2172  * Input: Header byte of ppe_thres (first byte), and HE capa IE's PHY cap u8*
2173  */
2174 static inline u8
2175 ieee80211_he_ppe_size(u8 ppe_thres_hdr, const u8 *phy_cap_info)
2176 {
2177 	u8 n;
2178 
2179 	if ((phy_cap_info[6] &
2180 	     IEEE80211_HE_PHY_CAP6_PPE_THRESHOLD_PRESENT) == 0)
2181 		return 0;
2182 
2183 	n = hweight8(ppe_thres_hdr &
2184 		     IEEE80211_PPE_THRES_RU_INDEX_BITMASK_MASK);
2185 	n *= (1 + ((ppe_thres_hdr & IEEE80211_PPE_THRES_NSS_MASK) >>
2186 		   IEEE80211_PPE_THRES_NSS_POS));
2187 
2188 	/*
2189 	 * Each pair is 6 bits, and we need to add the 7 "header" bits to the
2190 	 * total size.
2191 	 */
2192 	n = (n * IEEE80211_PPE_THRES_INFO_PPET_SIZE * 2) + 7;
2193 	n = DIV_ROUND_UP(n, 8);
2194 
2195 	return n;
2196 }
2197 
2198 /* HE Operation defines */
2199 #define IEEE80211_HE_OPERATION_DFLT_PE_DURATION_MASK		0x00000007
2200 #define IEEE80211_HE_OPERATION_TWT_REQUIRED			0x00000008
2201 #define IEEE80211_HE_OPERATION_RTS_THRESHOLD_MASK		0x00003ff0
2202 #define IEEE80211_HE_OPERATION_RTS_THRESHOLD_OFFSET		4
2203 #define IEEE80211_HE_OPERATION_VHT_OPER_INFO			0x00004000
2204 #define IEEE80211_HE_OPERATION_CO_HOSTED_BSS			0x00008000
2205 #define IEEE80211_HE_OPERATION_ER_SU_DISABLE			0x00010000
2206 #define IEEE80211_HE_OPERATION_6GHZ_OP_INFO			0x00020000
2207 #define IEEE80211_HE_OPERATION_BSS_COLOR_MASK			0x3f000000
2208 #define IEEE80211_HE_OPERATION_BSS_COLOR_OFFSET			24
2209 #define IEEE80211_HE_OPERATION_PARTIAL_BSS_COLOR		0x40000000
2210 #define IEEE80211_HE_OPERATION_BSS_COLOR_DISABLED		0x80000000
2211 
2212 /**
2213  * ieee80211_he_6ghz_oper - HE 6 GHz operation Information field
2214  * @primary: primary channel
2215  * @control: control flags
2216  * @ccfs0: channel center frequency segment 0
2217  * @ccfs1: channel center frequency segment 1
2218  * @minrate: minimum rate (in 1 Mbps units)
2219  */
2220 struct ieee80211_he_6ghz_oper {
2221 	u8 primary;
2222 #define IEEE80211_HE_6GHZ_OPER_CTRL_CHANWIDTH	0x3
2223 #define		IEEE80211_HE_6GHZ_OPER_CTRL_CHANWIDTH_20MHZ	0
2224 #define		IEEE80211_HE_6GHZ_OPER_CTRL_CHANWIDTH_40MHZ	1
2225 #define		IEEE80211_HE_6GHZ_OPER_CTRL_CHANWIDTH_80MHZ	2
2226 #define		IEEE80211_HE_6GHZ_OPER_CTRL_CHANWIDTH_160MHZ	3
2227 #define IEEE80211_HE_6GHZ_OPER_CTRL_DUP_BEACON	0x4
2228 	u8 control;
2229 	u8 ccfs0;
2230 	u8 ccfs1;
2231 	u8 minrate;
2232 } __packed;
2233 
2234 /*
2235  * ieee80211_he_oper_size - calculate 802.11ax HE Operations IE size
2236  * @he_oper_ie: byte data of the He Operations IE, stating from the byte
2237  *	after the ext ID byte. It is assumed that he_oper_ie has at least
2238  *	sizeof(struct ieee80211_he_operation) bytes, the caller must have
2239  *	validated this.
2240  * @return the actual size of the IE data (not including header), or 0 on error
2241  */
2242 static inline u8
2243 ieee80211_he_oper_size(const u8 *he_oper_ie)
2244 {
2245 	struct ieee80211_he_operation *he_oper = (void *)he_oper_ie;
2246 	u8 oper_len = sizeof(struct ieee80211_he_operation);
2247 	u32 he_oper_params;
2248 
2249 	/* Make sure the input is not NULL */
2250 	if (!he_oper_ie)
2251 		return 0;
2252 
2253 	/* Calc required length */
2254 	he_oper_params = le32_to_cpu(he_oper->he_oper_params);
2255 	if (he_oper_params & IEEE80211_HE_OPERATION_VHT_OPER_INFO)
2256 		oper_len += 3;
2257 	if (he_oper_params & IEEE80211_HE_OPERATION_CO_HOSTED_BSS)
2258 		oper_len++;
2259 	if (he_oper_params & IEEE80211_HE_OPERATION_6GHZ_OP_INFO)
2260 		oper_len += sizeof(struct ieee80211_he_6ghz_oper);
2261 
2262 	/* Add the first byte (extension ID) to the total length */
2263 	oper_len++;
2264 
2265 	return oper_len;
2266 }
2267 
2268 /**
2269  * ieee80211_he_6ghz_oper - obtain 6 GHz operation field
2270  * @he_oper: HE operation element (must be pre-validated for size)
2271  *	but may be %NULL
2272  *
2273  * Return: a pointer to the 6 GHz operation field, or %NULL
2274  */
2275 static inline const struct ieee80211_he_6ghz_oper *
2276 ieee80211_he_6ghz_oper(const struct ieee80211_he_operation *he_oper)
2277 {
2278 	const u8 *ret = (void *)&he_oper->optional;
2279 	u32 he_oper_params;
2280 
2281 	if (!he_oper)
2282 		return NULL;
2283 
2284 	he_oper_params = le32_to_cpu(he_oper->he_oper_params);
2285 
2286 	if (!(he_oper_params & IEEE80211_HE_OPERATION_6GHZ_OP_INFO))
2287 		return NULL;
2288 	if (he_oper_params & IEEE80211_HE_OPERATION_VHT_OPER_INFO)
2289 		ret += 3;
2290 	if (he_oper_params & IEEE80211_HE_OPERATION_CO_HOSTED_BSS)
2291 		ret++;
2292 
2293 	return (void *)ret;
2294 }
2295 
2296 /* HE Spatial Reuse defines */
2297 #define IEEE80211_HE_SPR_NON_SRG_OFFSET_PRESENT			0x4
2298 #define IEEE80211_HE_SPR_SRG_INFORMATION_PRESENT		0x8
2299 
2300 /*
2301  * ieee80211_he_spr_size - calculate 802.11ax HE Spatial Reuse IE size
2302  * @he_spr_ie: byte data of the He Spatial Reuse IE, stating from the byte
2303  *	after the ext ID byte. It is assumed that he_spr_ie has at least
2304  *	sizeof(struct ieee80211_he_spr) bytes, the caller must have validated
2305  *	this
2306  * @return the actual size of the IE data (not including header), or 0 on error
2307  */
2308 static inline u8
2309 ieee80211_he_spr_size(const u8 *he_spr_ie)
2310 {
2311 	struct ieee80211_he_spr *he_spr = (void *)he_spr_ie;
2312 	u8 spr_len = sizeof(struct ieee80211_he_spr);
2313 	u8 he_spr_params;
2314 
2315 	/* Make sure the input is not NULL */
2316 	if (!he_spr_ie)
2317 		return 0;
2318 
2319 	/* Calc required length */
2320 	he_spr_params = he_spr->he_sr_control;
2321 	if (he_spr_params & IEEE80211_HE_SPR_NON_SRG_OFFSET_PRESENT)
2322 		spr_len++;
2323 	if (he_spr_params & IEEE80211_HE_SPR_SRG_INFORMATION_PRESENT)
2324 		spr_len += 18;
2325 
2326 	/* Add the first byte (extension ID) to the total length */
2327 	spr_len++;
2328 
2329 	return spr_len;
2330 }
2331 
2332 /* S1G Capabilities Information field */
2333 #define S1G_CAPAB_B0_S1G_LONG BIT(0)
2334 #define S1G_CAPAB_B0_SGI_1MHZ BIT(1)
2335 #define S1G_CAPAB_B0_SGI_2MHZ BIT(2)
2336 #define S1G_CAPAB_B0_SGI_4MHZ BIT(3)
2337 #define S1G_CAPAB_B0_SGI_8MHZ BIT(4)
2338 #define S1G_CAPAB_B0_SGI_16MHZ BIT(5)
2339 #define S1G_CAPAB_B0_SUPP_CH_WIDTH_MASK (BIT(6) | BIT(7))
2340 #define S1G_CAPAB_B0_SUPP_CH_WIDTH_SHIFT 6
2341 
2342 #define S1G_CAPAB_B1_RX_LDPC BIT(0)
2343 #define S1G_CAPAB_B1_TX_STBC BIT(1)
2344 #define S1G_CAPAB_B1_RX_STBC BIT(2)
2345 #define S1G_CAPAB_B1_SU_BFER BIT(3)
2346 #define S1G_CAPAB_B1_SU_BFEE BIT(4)
2347 #define S1G_CAPAB_B1_BFEE_STS_MASK (BIT(5) | BIT(6) | BIT(7))
2348 #define S1G_CAPAB_B1_BFEE_STS_SHIFT 5
2349 
2350 #define S1G_CAPAB_B2_SOUNDING_DIMENSIONS_MASK (BIT(0) | BIT(1) | BIT(2))
2351 #define S1G_CAPAB_B2_SOUNDING_DIMENSIONS_SHIFT 0
2352 #define S1G_CAPAB_B2_MU_BFER BIT(3)
2353 #define S1G_CAPAB_B2_MU_BFEE BIT(4)
2354 #define S1G_CAPAB_B2_PLUS_HTC_VHT BIT(5)
2355 #define S1G_CAPAB_B2_TRAVELING_PILOT_MASK (BIT(6) | BIT(7))
2356 #define S1G_CAPAB_B2_TRAVELING_PILOT_SHIFT 6
2357 
2358 #define S1G_CAPAB_B3_RD_RESPONDER BIT(0)
2359 #define S1G_CAPAB_B3_HT_DELAYED_BA BIT(1)
2360 #define S1G_CAPAB_B3_MAX_MPDU_LEN BIT(2)
2361 #define S1G_CAPAB_B3_MAX_AMPDU_LEN_EXP_MASK (BIT(3) | BIT(4))
2362 #define S1G_CAPAB_B3_MAX_AMPDU_LEN_EXP_SHIFT 3
2363 #define S1G_CAPAB_B3_MIN_MPDU_START_MASK (BIT(5) | BIT(6) | BIT(7))
2364 #define S1G_CAPAB_B3_MIN_MPDU_START_SHIFT 5
2365 
2366 #define S1G_CAPAB_B4_UPLINK_SYNC BIT(0)
2367 #define S1G_CAPAB_B4_DYNAMIC_AID BIT(1)
2368 #define S1G_CAPAB_B4_BAT BIT(2)
2369 #define S1G_CAPAB_B4_TIME_ADE BIT(3)
2370 #define S1G_CAPAB_B4_NON_TIM BIT(4)
2371 #define S1G_CAPAB_B4_GROUP_AID BIT(5)
2372 #define S1G_CAPAB_B4_STA_TYPE_MASK (BIT(6) | BIT(7))
2373 #define S1G_CAPAB_B4_STA_TYPE_SHIFT 6
2374 
2375 #define S1G_CAPAB_B5_CENT_AUTH_CONTROL BIT(0)
2376 #define S1G_CAPAB_B5_DIST_AUTH_CONTROL BIT(1)
2377 #define S1G_CAPAB_B5_AMSDU BIT(2)
2378 #define S1G_CAPAB_B5_AMPDU BIT(3)
2379 #define S1G_CAPAB_B5_ASYMMETRIC_BA BIT(4)
2380 #define S1G_CAPAB_B5_FLOW_CONTROL BIT(5)
2381 #define S1G_CAPAB_B5_SECTORIZED_BEAM_MASK (BIT(6) | BIT(7))
2382 #define S1G_CAPAB_B5_SECTORIZED_BEAM_SHIFT 6
2383 
2384 #define S1G_CAPAB_B6_OBSS_MITIGATION BIT(0)
2385 #define S1G_CAPAB_B6_FRAGMENT_BA BIT(1)
2386 #define S1G_CAPAB_B6_NDP_PS_POLL BIT(2)
2387 #define S1G_CAPAB_B6_RAW_OPERATION BIT(3)
2388 #define S1G_CAPAB_B6_PAGE_SLICING BIT(4)
2389 #define S1G_CAPAB_B6_TXOP_SHARING_IMP_ACK BIT(5)
2390 #define S1G_CAPAB_B6_VHT_LINK_ADAPT_MASK (BIT(6) | BIT(7))
2391 #define S1G_CAPAB_B6_VHT_LINK_ADAPT_SHIFT 6
2392 
2393 #define S1G_CAPAB_B7_TACK_AS_PS_POLL BIT(0)
2394 #define S1G_CAPAB_B7_DUP_1MHZ BIT(1)
2395 #define S1G_CAPAB_B7_MCS_NEGOTIATION BIT(2)
2396 #define S1G_CAPAB_B7_1MHZ_CTL_RESPONSE_PREAMBLE BIT(3)
2397 #define S1G_CAPAB_B7_NDP_BFING_REPORT_POLL BIT(4)
2398 #define S1G_CAPAB_B7_UNSOLICITED_DYN_AID BIT(5)
2399 #define S1G_CAPAB_B7_SECTOR_TRAINING_OPERATION BIT(6)
2400 #define S1G_CAPAB_B7_TEMP_PS_MODE_SWITCH BIT(7)
2401 
2402 #define S1G_CAPAB_B8_TWT_GROUPING BIT(0)
2403 #define S1G_CAPAB_B8_BDT BIT(1)
2404 #define S1G_CAPAB_B8_COLOR_MASK (BIT(2) | BIT(3) | BIT(4))
2405 #define S1G_CAPAB_B8_COLOR_SHIFT 2
2406 #define S1G_CAPAB_B8_TWT_REQUEST BIT(5)
2407 #define S1G_CAPAB_B8_TWT_RESPOND BIT(6)
2408 #define S1G_CAPAB_B8_PV1_FRAME BIT(7)
2409 
2410 #define S1G_CAPAB_B9_LINK_ADAPT_PER_CONTROL_RESPONSE BIT(0)
2411 
2412 /* Authentication algorithms */
2413 #define WLAN_AUTH_OPEN 0
2414 #define WLAN_AUTH_SHARED_KEY 1
2415 #define WLAN_AUTH_FT 2
2416 #define WLAN_AUTH_SAE 3
2417 #define WLAN_AUTH_FILS_SK 4
2418 #define WLAN_AUTH_FILS_SK_PFS 5
2419 #define WLAN_AUTH_FILS_PK 6
2420 #define WLAN_AUTH_LEAP 128
2421 
2422 #define WLAN_AUTH_CHALLENGE_LEN 128
2423 
2424 #define WLAN_CAPABILITY_ESS		(1<<0)
2425 #define WLAN_CAPABILITY_IBSS		(1<<1)
2426 
2427 /*
2428  * A mesh STA sets the ESS and IBSS capability bits to zero.
2429  * however, this holds true for p2p probe responses (in the p2p_find
2430  * phase) as well.
2431  */
2432 #define WLAN_CAPABILITY_IS_STA_BSS(cap)	\
2433 	(!((cap) & (WLAN_CAPABILITY_ESS | WLAN_CAPABILITY_IBSS)))
2434 
2435 #define WLAN_CAPABILITY_CF_POLLABLE	(1<<2)
2436 #define WLAN_CAPABILITY_CF_POLL_REQUEST	(1<<3)
2437 #define WLAN_CAPABILITY_PRIVACY		(1<<4)
2438 #define WLAN_CAPABILITY_SHORT_PREAMBLE	(1<<5)
2439 #define WLAN_CAPABILITY_PBCC		(1<<6)
2440 #define WLAN_CAPABILITY_CHANNEL_AGILITY	(1<<7)
2441 
2442 /* 802.11h */
2443 #define WLAN_CAPABILITY_SPECTRUM_MGMT	(1<<8)
2444 #define WLAN_CAPABILITY_QOS		(1<<9)
2445 #define WLAN_CAPABILITY_SHORT_SLOT_TIME	(1<<10)
2446 #define WLAN_CAPABILITY_APSD		(1<<11)
2447 #define WLAN_CAPABILITY_RADIO_MEASURE	(1<<12)
2448 #define WLAN_CAPABILITY_DSSS_OFDM	(1<<13)
2449 #define WLAN_CAPABILITY_DEL_BACK	(1<<14)
2450 #define WLAN_CAPABILITY_IMM_BACK	(1<<15)
2451 
2452 /* DMG (60gHz) 802.11ad */
2453 /* type - bits 0..1 */
2454 #define WLAN_CAPABILITY_DMG_TYPE_MASK		(3<<0)
2455 #define WLAN_CAPABILITY_DMG_TYPE_IBSS		(1<<0) /* Tx by: STA */
2456 #define WLAN_CAPABILITY_DMG_TYPE_PBSS		(2<<0) /* Tx by: PCP */
2457 #define WLAN_CAPABILITY_DMG_TYPE_AP		(3<<0) /* Tx by: AP */
2458 
2459 #define WLAN_CAPABILITY_DMG_CBAP_ONLY		(1<<2)
2460 #define WLAN_CAPABILITY_DMG_CBAP_SOURCE		(1<<3)
2461 #define WLAN_CAPABILITY_DMG_PRIVACY		(1<<4)
2462 #define WLAN_CAPABILITY_DMG_ECPAC		(1<<5)
2463 
2464 #define WLAN_CAPABILITY_DMG_SPECTRUM_MGMT	(1<<8)
2465 #define WLAN_CAPABILITY_DMG_RADIO_MEASURE	(1<<12)
2466 
2467 /* measurement */
2468 #define IEEE80211_SPCT_MSR_RPRT_MODE_LATE	(1<<0)
2469 #define IEEE80211_SPCT_MSR_RPRT_MODE_INCAPABLE	(1<<1)
2470 #define IEEE80211_SPCT_MSR_RPRT_MODE_REFUSED	(1<<2)
2471 
2472 #define IEEE80211_SPCT_MSR_RPRT_TYPE_BASIC	0
2473 #define IEEE80211_SPCT_MSR_RPRT_TYPE_CCA	1
2474 #define IEEE80211_SPCT_MSR_RPRT_TYPE_RPI	2
2475 #define IEEE80211_SPCT_MSR_RPRT_TYPE_LCI	8
2476 #define IEEE80211_SPCT_MSR_RPRT_TYPE_CIVIC	11
2477 
2478 /* 802.11g ERP information element */
2479 #define WLAN_ERP_NON_ERP_PRESENT (1<<0)
2480 #define WLAN_ERP_USE_PROTECTION (1<<1)
2481 #define WLAN_ERP_BARKER_PREAMBLE (1<<2)
2482 
2483 /* WLAN_ERP_BARKER_PREAMBLE values */
2484 enum {
2485 	WLAN_ERP_PREAMBLE_SHORT = 0,
2486 	WLAN_ERP_PREAMBLE_LONG = 1,
2487 };
2488 
2489 /* Band ID, 802.11ad #8.4.1.45 */
2490 enum {
2491 	IEEE80211_BANDID_TV_WS = 0, /* TV white spaces */
2492 	IEEE80211_BANDID_SUB1  = 1, /* Sub-1 GHz (excluding TV white spaces) */
2493 	IEEE80211_BANDID_2G    = 2, /* 2.4 GHz */
2494 	IEEE80211_BANDID_3G    = 3, /* 3.6 GHz */
2495 	IEEE80211_BANDID_5G    = 4, /* 4.9 and 5 GHz */
2496 	IEEE80211_BANDID_60G   = 5, /* 60 GHz */
2497 };
2498 
2499 /* Status codes */
2500 enum ieee80211_statuscode {
2501 	WLAN_STATUS_SUCCESS = 0,
2502 	WLAN_STATUS_UNSPECIFIED_FAILURE = 1,
2503 	WLAN_STATUS_CAPS_UNSUPPORTED = 10,
2504 	WLAN_STATUS_REASSOC_NO_ASSOC = 11,
2505 	WLAN_STATUS_ASSOC_DENIED_UNSPEC = 12,
2506 	WLAN_STATUS_NOT_SUPPORTED_AUTH_ALG = 13,
2507 	WLAN_STATUS_UNKNOWN_AUTH_TRANSACTION = 14,
2508 	WLAN_STATUS_CHALLENGE_FAIL = 15,
2509 	WLAN_STATUS_AUTH_TIMEOUT = 16,
2510 	WLAN_STATUS_AP_UNABLE_TO_HANDLE_NEW_STA = 17,
2511 	WLAN_STATUS_ASSOC_DENIED_RATES = 18,
2512 	/* 802.11b */
2513 	WLAN_STATUS_ASSOC_DENIED_NOSHORTPREAMBLE = 19,
2514 	WLAN_STATUS_ASSOC_DENIED_NOPBCC = 20,
2515 	WLAN_STATUS_ASSOC_DENIED_NOAGILITY = 21,
2516 	/* 802.11h */
2517 	WLAN_STATUS_ASSOC_DENIED_NOSPECTRUM = 22,
2518 	WLAN_STATUS_ASSOC_REJECTED_BAD_POWER = 23,
2519 	WLAN_STATUS_ASSOC_REJECTED_BAD_SUPP_CHAN = 24,
2520 	/* 802.11g */
2521 	WLAN_STATUS_ASSOC_DENIED_NOSHORTTIME = 25,
2522 	WLAN_STATUS_ASSOC_DENIED_NODSSSOFDM = 26,
2523 	/* 802.11w */
2524 	WLAN_STATUS_ASSOC_REJECTED_TEMPORARILY = 30,
2525 	WLAN_STATUS_ROBUST_MGMT_FRAME_POLICY_VIOLATION = 31,
2526 	/* 802.11i */
2527 	WLAN_STATUS_INVALID_IE = 40,
2528 	WLAN_STATUS_INVALID_GROUP_CIPHER = 41,
2529 	WLAN_STATUS_INVALID_PAIRWISE_CIPHER = 42,
2530 	WLAN_STATUS_INVALID_AKMP = 43,
2531 	WLAN_STATUS_UNSUPP_RSN_VERSION = 44,
2532 	WLAN_STATUS_INVALID_RSN_IE_CAP = 45,
2533 	WLAN_STATUS_CIPHER_SUITE_REJECTED = 46,
2534 	/* 802.11e */
2535 	WLAN_STATUS_UNSPECIFIED_QOS = 32,
2536 	WLAN_STATUS_ASSOC_DENIED_NOBANDWIDTH = 33,
2537 	WLAN_STATUS_ASSOC_DENIED_LOWACK = 34,
2538 	WLAN_STATUS_ASSOC_DENIED_UNSUPP_QOS = 35,
2539 	WLAN_STATUS_REQUEST_DECLINED = 37,
2540 	WLAN_STATUS_INVALID_QOS_PARAM = 38,
2541 	WLAN_STATUS_CHANGE_TSPEC = 39,
2542 	WLAN_STATUS_WAIT_TS_DELAY = 47,
2543 	WLAN_STATUS_NO_DIRECT_LINK = 48,
2544 	WLAN_STATUS_STA_NOT_PRESENT = 49,
2545 	WLAN_STATUS_STA_NOT_QSTA = 50,
2546 	/* 802.11s */
2547 	WLAN_STATUS_ANTI_CLOG_REQUIRED = 76,
2548 	WLAN_STATUS_FCG_NOT_SUPP = 78,
2549 	WLAN_STATUS_STA_NO_TBTT = 78,
2550 	/* 802.11ad */
2551 	WLAN_STATUS_REJECTED_WITH_SUGGESTED_CHANGES = 39,
2552 	WLAN_STATUS_REJECTED_FOR_DELAY_PERIOD = 47,
2553 	WLAN_STATUS_REJECT_WITH_SCHEDULE = 83,
2554 	WLAN_STATUS_PENDING_ADMITTING_FST_SESSION = 86,
2555 	WLAN_STATUS_PERFORMING_FST_NOW = 87,
2556 	WLAN_STATUS_PENDING_GAP_IN_BA_WINDOW = 88,
2557 	WLAN_STATUS_REJECT_U_PID_SETTING = 89,
2558 	WLAN_STATUS_REJECT_DSE_BAND = 96,
2559 	WLAN_STATUS_DENIED_WITH_SUGGESTED_BAND_AND_CHANNEL = 99,
2560 	WLAN_STATUS_DENIED_DUE_TO_SPECTRUM_MANAGEMENT = 103,
2561 	/* 802.11ai */
2562 	WLAN_STATUS_FILS_AUTHENTICATION_FAILURE = 108,
2563 	WLAN_STATUS_UNKNOWN_AUTHENTICATION_SERVER = 109,
2564 };
2565 
2566 
2567 /* Reason codes */
2568 enum ieee80211_reasoncode {
2569 	WLAN_REASON_UNSPECIFIED = 1,
2570 	WLAN_REASON_PREV_AUTH_NOT_VALID = 2,
2571 	WLAN_REASON_DEAUTH_LEAVING = 3,
2572 	WLAN_REASON_DISASSOC_DUE_TO_INACTIVITY = 4,
2573 	WLAN_REASON_DISASSOC_AP_BUSY = 5,
2574 	WLAN_REASON_CLASS2_FRAME_FROM_NONAUTH_STA = 6,
2575 	WLAN_REASON_CLASS3_FRAME_FROM_NONASSOC_STA = 7,
2576 	WLAN_REASON_DISASSOC_STA_HAS_LEFT = 8,
2577 	WLAN_REASON_STA_REQ_ASSOC_WITHOUT_AUTH = 9,
2578 	/* 802.11h */
2579 	WLAN_REASON_DISASSOC_BAD_POWER = 10,
2580 	WLAN_REASON_DISASSOC_BAD_SUPP_CHAN = 11,
2581 	/* 802.11i */
2582 	WLAN_REASON_INVALID_IE = 13,
2583 	WLAN_REASON_MIC_FAILURE = 14,
2584 	WLAN_REASON_4WAY_HANDSHAKE_TIMEOUT = 15,
2585 	WLAN_REASON_GROUP_KEY_HANDSHAKE_TIMEOUT = 16,
2586 	WLAN_REASON_IE_DIFFERENT = 17,
2587 	WLAN_REASON_INVALID_GROUP_CIPHER = 18,
2588 	WLAN_REASON_INVALID_PAIRWISE_CIPHER = 19,
2589 	WLAN_REASON_INVALID_AKMP = 20,
2590 	WLAN_REASON_UNSUPP_RSN_VERSION = 21,
2591 	WLAN_REASON_INVALID_RSN_IE_CAP = 22,
2592 	WLAN_REASON_IEEE8021X_FAILED = 23,
2593 	WLAN_REASON_CIPHER_SUITE_REJECTED = 24,
2594 	/* TDLS (802.11z) */
2595 	WLAN_REASON_TDLS_TEARDOWN_UNREACHABLE = 25,
2596 	WLAN_REASON_TDLS_TEARDOWN_UNSPECIFIED = 26,
2597 	/* 802.11e */
2598 	WLAN_REASON_DISASSOC_UNSPECIFIED_QOS = 32,
2599 	WLAN_REASON_DISASSOC_QAP_NO_BANDWIDTH = 33,
2600 	WLAN_REASON_DISASSOC_LOW_ACK = 34,
2601 	WLAN_REASON_DISASSOC_QAP_EXCEED_TXOP = 35,
2602 	WLAN_REASON_QSTA_LEAVE_QBSS = 36,
2603 	WLAN_REASON_QSTA_NOT_USE = 37,
2604 	WLAN_REASON_QSTA_REQUIRE_SETUP = 38,
2605 	WLAN_REASON_QSTA_TIMEOUT = 39,
2606 	WLAN_REASON_QSTA_CIPHER_NOT_SUPP = 45,
2607 	/* 802.11s */
2608 	WLAN_REASON_MESH_PEER_CANCELED = 52,
2609 	WLAN_REASON_MESH_MAX_PEERS = 53,
2610 	WLAN_REASON_MESH_CONFIG = 54,
2611 	WLAN_REASON_MESH_CLOSE = 55,
2612 	WLAN_REASON_MESH_MAX_RETRIES = 56,
2613 	WLAN_REASON_MESH_CONFIRM_TIMEOUT = 57,
2614 	WLAN_REASON_MESH_INVALID_GTK = 58,
2615 	WLAN_REASON_MESH_INCONSISTENT_PARAM = 59,
2616 	WLAN_REASON_MESH_INVALID_SECURITY = 60,
2617 	WLAN_REASON_MESH_PATH_ERROR = 61,
2618 	WLAN_REASON_MESH_PATH_NOFORWARD = 62,
2619 	WLAN_REASON_MESH_PATH_DEST_UNREACHABLE = 63,
2620 	WLAN_REASON_MAC_EXISTS_IN_MBSS = 64,
2621 	WLAN_REASON_MESH_CHAN_REGULATORY = 65,
2622 	WLAN_REASON_MESH_CHAN = 66,
2623 };
2624 
2625 
2626 /* Information Element IDs */
2627 enum ieee80211_eid {
2628 	WLAN_EID_SSID = 0,
2629 	WLAN_EID_SUPP_RATES = 1,
2630 	WLAN_EID_FH_PARAMS = 2, /* reserved now */
2631 	WLAN_EID_DS_PARAMS = 3,
2632 	WLAN_EID_CF_PARAMS = 4,
2633 	WLAN_EID_TIM = 5,
2634 	WLAN_EID_IBSS_PARAMS = 6,
2635 	WLAN_EID_COUNTRY = 7,
2636 	/* 8, 9 reserved */
2637 	WLAN_EID_REQUEST = 10,
2638 	WLAN_EID_QBSS_LOAD = 11,
2639 	WLAN_EID_EDCA_PARAM_SET = 12,
2640 	WLAN_EID_TSPEC = 13,
2641 	WLAN_EID_TCLAS = 14,
2642 	WLAN_EID_SCHEDULE = 15,
2643 	WLAN_EID_CHALLENGE = 16,
2644 	/* 17-31 reserved for challenge text extension */
2645 	WLAN_EID_PWR_CONSTRAINT = 32,
2646 	WLAN_EID_PWR_CAPABILITY = 33,
2647 	WLAN_EID_TPC_REQUEST = 34,
2648 	WLAN_EID_TPC_REPORT = 35,
2649 	WLAN_EID_SUPPORTED_CHANNELS = 36,
2650 	WLAN_EID_CHANNEL_SWITCH = 37,
2651 	WLAN_EID_MEASURE_REQUEST = 38,
2652 	WLAN_EID_MEASURE_REPORT = 39,
2653 	WLAN_EID_QUIET = 40,
2654 	WLAN_EID_IBSS_DFS = 41,
2655 	WLAN_EID_ERP_INFO = 42,
2656 	WLAN_EID_TS_DELAY = 43,
2657 	WLAN_EID_TCLAS_PROCESSING = 44,
2658 	WLAN_EID_HT_CAPABILITY = 45,
2659 	WLAN_EID_QOS_CAPA = 46,
2660 	/* 47 reserved for Broadcom */
2661 	WLAN_EID_RSN = 48,
2662 	WLAN_EID_802_15_COEX = 49,
2663 	WLAN_EID_EXT_SUPP_RATES = 50,
2664 	WLAN_EID_AP_CHAN_REPORT = 51,
2665 	WLAN_EID_NEIGHBOR_REPORT = 52,
2666 	WLAN_EID_RCPI = 53,
2667 	WLAN_EID_MOBILITY_DOMAIN = 54,
2668 	WLAN_EID_FAST_BSS_TRANSITION = 55,
2669 	WLAN_EID_TIMEOUT_INTERVAL = 56,
2670 	WLAN_EID_RIC_DATA = 57,
2671 	WLAN_EID_DSE_REGISTERED_LOCATION = 58,
2672 	WLAN_EID_SUPPORTED_REGULATORY_CLASSES = 59,
2673 	WLAN_EID_EXT_CHANSWITCH_ANN = 60,
2674 	WLAN_EID_HT_OPERATION = 61,
2675 	WLAN_EID_SECONDARY_CHANNEL_OFFSET = 62,
2676 	WLAN_EID_BSS_AVG_ACCESS_DELAY = 63,
2677 	WLAN_EID_ANTENNA_INFO = 64,
2678 	WLAN_EID_RSNI = 65,
2679 	WLAN_EID_MEASUREMENT_PILOT_TX_INFO = 66,
2680 	WLAN_EID_BSS_AVAILABLE_CAPACITY = 67,
2681 	WLAN_EID_BSS_AC_ACCESS_DELAY = 68,
2682 	WLAN_EID_TIME_ADVERTISEMENT = 69,
2683 	WLAN_EID_RRM_ENABLED_CAPABILITIES = 70,
2684 	WLAN_EID_MULTIPLE_BSSID = 71,
2685 	WLAN_EID_BSS_COEX_2040 = 72,
2686 	WLAN_EID_BSS_INTOLERANT_CHL_REPORT = 73,
2687 	WLAN_EID_OVERLAP_BSS_SCAN_PARAM = 74,
2688 	WLAN_EID_RIC_DESCRIPTOR = 75,
2689 	WLAN_EID_MMIE = 76,
2690 	WLAN_EID_ASSOC_COMEBACK_TIME = 77,
2691 	WLAN_EID_EVENT_REQUEST = 78,
2692 	WLAN_EID_EVENT_REPORT = 79,
2693 	WLAN_EID_DIAGNOSTIC_REQUEST = 80,
2694 	WLAN_EID_DIAGNOSTIC_REPORT = 81,
2695 	WLAN_EID_LOCATION_PARAMS = 82,
2696 	WLAN_EID_NON_TX_BSSID_CAP =  83,
2697 	WLAN_EID_SSID_LIST = 84,
2698 	WLAN_EID_MULTI_BSSID_IDX = 85,
2699 	WLAN_EID_FMS_DESCRIPTOR = 86,
2700 	WLAN_EID_FMS_REQUEST = 87,
2701 	WLAN_EID_FMS_RESPONSE = 88,
2702 	WLAN_EID_QOS_TRAFFIC_CAPA = 89,
2703 	WLAN_EID_BSS_MAX_IDLE_PERIOD = 90,
2704 	WLAN_EID_TSF_REQUEST = 91,
2705 	WLAN_EID_TSF_RESPOSNE = 92,
2706 	WLAN_EID_WNM_SLEEP_MODE = 93,
2707 	WLAN_EID_TIM_BCAST_REQ = 94,
2708 	WLAN_EID_TIM_BCAST_RESP = 95,
2709 	WLAN_EID_COLL_IF_REPORT = 96,
2710 	WLAN_EID_CHANNEL_USAGE = 97,
2711 	WLAN_EID_TIME_ZONE = 98,
2712 	WLAN_EID_DMS_REQUEST = 99,
2713 	WLAN_EID_DMS_RESPONSE = 100,
2714 	WLAN_EID_LINK_ID = 101,
2715 	WLAN_EID_WAKEUP_SCHEDUL = 102,
2716 	/* 103 reserved */
2717 	WLAN_EID_CHAN_SWITCH_TIMING = 104,
2718 	WLAN_EID_PTI_CONTROL = 105,
2719 	WLAN_EID_PU_BUFFER_STATUS = 106,
2720 	WLAN_EID_INTERWORKING = 107,
2721 	WLAN_EID_ADVERTISEMENT_PROTOCOL = 108,
2722 	WLAN_EID_EXPEDITED_BW_REQ = 109,
2723 	WLAN_EID_QOS_MAP_SET = 110,
2724 	WLAN_EID_ROAMING_CONSORTIUM = 111,
2725 	WLAN_EID_EMERGENCY_ALERT = 112,
2726 	WLAN_EID_MESH_CONFIG = 113,
2727 	WLAN_EID_MESH_ID = 114,
2728 	WLAN_EID_LINK_METRIC_REPORT = 115,
2729 	WLAN_EID_CONGESTION_NOTIFICATION = 116,
2730 	WLAN_EID_PEER_MGMT = 117,
2731 	WLAN_EID_CHAN_SWITCH_PARAM = 118,
2732 	WLAN_EID_MESH_AWAKE_WINDOW = 119,
2733 	WLAN_EID_BEACON_TIMING = 120,
2734 	WLAN_EID_MCCAOP_SETUP_REQ = 121,
2735 	WLAN_EID_MCCAOP_SETUP_RESP = 122,
2736 	WLAN_EID_MCCAOP_ADVERT = 123,
2737 	WLAN_EID_MCCAOP_TEARDOWN = 124,
2738 	WLAN_EID_GANN = 125,
2739 	WLAN_EID_RANN = 126,
2740 	WLAN_EID_EXT_CAPABILITY = 127,
2741 	/* 128, 129 reserved for Agere */
2742 	WLAN_EID_PREQ = 130,
2743 	WLAN_EID_PREP = 131,
2744 	WLAN_EID_PERR = 132,
2745 	/* 133-136 reserved for Cisco */
2746 	WLAN_EID_PXU = 137,
2747 	WLAN_EID_PXUC = 138,
2748 	WLAN_EID_AUTH_MESH_PEER_EXCH = 139,
2749 	WLAN_EID_MIC = 140,
2750 	WLAN_EID_DESTINATION_URI = 141,
2751 	WLAN_EID_UAPSD_COEX = 142,
2752 	WLAN_EID_WAKEUP_SCHEDULE = 143,
2753 	WLAN_EID_EXT_SCHEDULE = 144,
2754 	WLAN_EID_STA_AVAILABILITY = 145,
2755 	WLAN_EID_DMG_TSPEC = 146,
2756 	WLAN_EID_DMG_AT = 147,
2757 	WLAN_EID_DMG_CAP = 148,
2758 	/* 149 reserved for Cisco */
2759 	WLAN_EID_CISCO_VENDOR_SPECIFIC = 150,
2760 	WLAN_EID_DMG_OPERATION = 151,
2761 	WLAN_EID_DMG_BSS_PARAM_CHANGE = 152,
2762 	WLAN_EID_DMG_BEAM_REFINEMENT = 153,
2763 	WLAN_EID_CHANNEL_MEASURE_FEEDBACK = 154,
2764 	/* 155-156 reserved for Cisco */
2765 	WLAN_EID_AWAKE_WINDOW = 157,
2766 	WLAN_EID_MULTI_BAND = 158,
2767 	WLAN_EID_ADDBA_EXT = 159,
2768 	WLAN_EID_NEXT_PCP_LIST = 160,
2769 	WLAN_EID_PCP_HANDOVER = 161,
2770 	WLAN_EID_DMG_LINK_MARGIN = 162,
2771 	WLAN_EID_SWITCHING_STREAM = 163,
2772 	WLAN_EID_SESSION_TRANSITION = 164,
2773 	WLAN_EID_DYN_TONE_PAIRING_REPORT = 165,
2774 	WLAN_EID_CLUSTER_REPORT = 166,
2775 	WLAN_EID_RELAY_CAP = 167,
2776 	WLAN_EID_RELAY_XFER_PARAM_SET = 168,
2777 	WLAN_EID_BEAM_LINK_MAINT = 169,
2778 	WLAN_EID_MULTIPLE_MAC_ADDR = 170,
2779 	WLAN_EID_U_PID = 171,
2780 	WLAN_EID_DMG_LINK_ADAPT_ACK = 172,
2781 	/* 173 reserved for Symbol */
2782 	WLAN_EID_MCCAOP_ADV_OVERVIEW = 174,
2783 	WLAN_EID_QUIET_PERIOD_REQ = 175,
2784 	/* 176 reserved for Symbol */
2785 	WLAN_EID_QUIET_PERIOD_RESP = 177,
2786 	/* 178-179 reserved for Symbol */
2787 	/* 180 reserved for ISO/IEC 20011 */
2788 	WLAN_EID_EPAC_POLICY = 182,
2789 	WLAN_EID_CLISTER_TIME_OFF = 183,
2790 	WLAN_EID_INTER_AC_PRIO = 184,
2791 	WLAN_EID_SCS_DESCRIPTOR = 185,
2792 	WLAN_EID_QLOAD_REPORT = 186,
2793 	WLAN_EID_HCCA_TXOP_UPDATE_COUNT = 187,
2794 	WLAN_EID_HL_STREAM_ID = 188,
2795 	WLAN_EID_GCR_GROUP_ADDR = 189,
2796 	WLAN_EID_ANTENNA_SECTOR_ID_PATTERN = 190,
2797 	WLAN_EID_VHT_CAPABILITY = 191,
2798 	WLAN_EID_VHT_OPERATION = 192,
2799 	WLAN_EID_EXTENDED_BSS_LOAD = 193,
2800 	WLAN_EID_WIDE_BW_CHANNEL_SWITCH = 194,
2801 	WLAN_EID_VHT_TX_POWER_ENVELOPE = 195,
2802 	WLAN_EID_CHANNEL_SWITCH_WRAPPER = 196,
2803 	WLAN_EID_AID = 197,
2804 	WLAN_EID_QUIET_CHANNEL = 198,
2805 	WLAN_EID_OPMODE_NOTIF = 199,
2806 
2807 	WLAN_EID_REDUCED_NEIGHBOR_REPORT = 201,
2808 
2809 	WLAN_EID_S1G_BCN_COMPAT = 213,
2810 	WLAN_EID_S1G_SHORT_BCN_INTERVAL = 214,
2811 	WLAN_EID_S1G_CAPABILITIES = 217,
2812 	WLAN_EID_VENDOR_SPECIFIC = 221,
2813 	WLAN_EID_QOS_PARAMETER = 222,
2814 	WLAN_EID_S1G_OPERATION = 232,
2815 	WLAN_EID_CAG_NUMBER = 237,
2816 	WLAN_EID_AP_CSN = 239,
2817 	WLAN_EID_FILS_INDICATION = 240,
2818 	WLAN_EID_DILS = 241,
2819 	WLAN_EID_FRAGMENT = 242,
2820 	WLAN_EID_RSNX = 244,
2821 	WLAN_EID_EXTENSION = 255
2822 };
2823 
2824 /* Element ID Extensions for Element ID 255 */
2825 enum ieee80211_eid_ext {
2826 	WLAN_EID_EXT_ASSOC_DELAY_INFO = 1,
2827 	WLAN_EID_EXT_FILS_REQ_PARAMS = 2,
2828 	WLAN_EID_EXT_FILS_KEY_CONFIRM = 3,
2829 	WLAN_EID_EXT_FILS_SESSION = 4,
2830 	WLAN_EID_EXT_FILS_HLP_CONTAINER = 5,
2831 	WLAN_EID_EXT_FILS_IP_ADDR_ASSIGN = 6,
2832 	WLAN_EID_EXT_KEY_DELIVERY = 7,
2833 	WLAN_EID_EXT_FILS_WRAPPED_DATA = 8,
2834 	WLAN_EID_EXT_FILS_PUBLIC_KEY = 12,
2835 	WLAN_EID_EXT_FILS_NONCE = 13,
2836 	WLAN_EID_EXT_FUTURE_CHAN_GUIDANCE = 14,
2837 	WLAN_EID_EXT_HE_CAPABILITY = 35,
2838 	WLAN_EID_EXT_HE_OPERATION = 36,
2839 	WLAN_EID_EXT_UORA = 37,
2840 	WLAN_EID_EXT_HE_MU_EDCA = 38,
2841 	WLAN_EID_EXT_HE_SPR = 39,
2842 	WLAN_EID_EXT_NDP_FEEDBACK_REPORT_PARAMSET = 41,
2843 	WLAN_EID_EXT_BSS_COLOR_CHG_ANN = 42,
2844 	WLAN_EID_EXT_QUIET_TIME_PERIOD_SETUP = 43,
2845 	WLAN_EID_EXT_ESS_REPORT = 45,
2846 	WLAN_EID_EXT_OPS = 46,
2847 	WLAN_EID_EXT_HE_BSS_LOAD = 47,
2848 	WLAN_EID_EXT_MAX_CHANNEL_SWITCH_TIME = 52,
2849 	WLAN_EID_EXT_MULTIPLE_BSSID_CONFIGURATION = 55,
2850 	WLAN_EID_EXT_NON_INHERITANCE = 56,
2851 	WLAN_EID_EXT_KNOWN_BSSID = 57,
2852 	WLAN_EID_EXT_SHORT_SSID_LIST = 58,
2853 	WLAN_EID_EXT_HE_6GHZ_CAPA = 59,
2854 	WLAN_EID_EXT_UL_MU_POWER_CAPA = 60,
2855 };
2856 
2857 /* Action category code */
2858 enum ieee80211_category {
2859 	WLAN_CATEGORY_SPECTRUM_MGMT = 0,
2860 	WLAN_CATEGORY_QOS = 1,
2861 	WLAN_CATEGORY_DLS = 2,
2862 	WLAN_CATEGORY_BACK = 3,
2863 	WLAN_CATEGORY_PUBLIC = 4,
2864 	WLAN_CATEGORY_RADIO_MEASUREMENT = 5,
2865 	WLAN_CATEGORY_HT = 7,
2866 	WLAN_CATEGORY_SA_QUERY = 8,
2867 	WLAN_CATEGORY_PROTECTED_DUAL_OF_ACTION = 9,
2868 	WLAN_CATEGORY_WNM = 10,
2869 	WLAN_CATEGORY_WNM_UNPROTECTED = 11,
2870 	WLAN_CATEGORY_TDLS = 12,
2871 	WLAN_CATEGORY_MESH_ACTION = 13,
2872 	WLAN_CATEGORY_MULTIHOP_ACTION = 14,
2873 	WLAN_CATEGORY_SELF_PROTECTED = 15,
2874 	WLAN_CATEGORY_DMG = 16,
2875 	WLAN_CATEGORY_WMM = 17,
2876 	WLAN_CATEGORY_FST = 18,
2877 	WLAN_CATEGORY_UNPROT_DMG = 20,
2878 	WLAN_CATEGORY_VHT = 21,
2879 	WLAN_CATEGORY_VENDOR_SPECIFIC_PROTECTED = 126,
2880 	WLAN_CATEGORY_VENDOR_SPECIFIC = 127,
2881 };
2882 
2883 /* SPECTRUM_MGMT action code */
2884 enum ieee80211_spectrum_mgmt_actioncode {
2885 	WLAN_ACTION_SPCT_MSR_REQ = 0,
2886 	WLAN_ACTION_SPCT_MSR_RPRT = 1,
2887 	WLAN_ACTION_SPCT_TPC_REQ = 2,
2888 	WLAN_ACTION_SPCT_TPC_RPRT = 3,
2889 	WLAN_ACTION_SPCT_CHL_SWITCH = 4,
2890 };
2891 
2892 /* HT action codes */
2893 enum ieee80211_ht_actioncode {
2894 	WLAN_HT_ACTION_NOTIFY_CHANWIDTH = 0,
2895 	WLAN_HT_ACTION_SMPS = 1,
2896 	WLAN_HT_ACTION_PSMP = 2,
2897 	WLAN_HT_ACTION_PCO_PHASE = 3,
2898 	WLAN_HT_ACTION_CSI = 4,
2899 	WLAN_HT_ACTION_NONCOMPRESSED_BF = 5,
2900 	WLAN_HT_ACTION_COMPRESSED_BF = 6,
2901 	WLAN_HT_ACTION_ASEL_IDX_FEEDBACK = 7,
2902 };
2903 
2904 /* VHT action codes */
2905 enum ieee80211_vht_actioncode {
2906 	WLAN_VHT_ACTION_COMPRESSED_BF = 0,
2907 	WLAN_VHT_ACTION_GROUPID_MGMT = 1,
2908 	WLAN_VHT_ACTION_OPMODE_NOTIF = 2,
2909 };
2910 
2911 /* Self Protected Action codes */
2912 enum ieee80211_self_protected_actioncode {
2913 	WLAN_SP_RESERVED = 0,
2914 	WLAN_SP_MESH_PEERING_OPEN = 1,
2915 	WLAN_SP_MESH_PEERING_CONFIRM = 2,
2916 	WLAN_SP_MESH_PEERING_CLOSE = 3,
2917 	WLAN_SP_MGK_INFORM = 4,
2918 	WLAN_SP_MGK_ACK = 5,
2919 };
2920 
2921 /* Mesh action codes */
2922 enum ieee80211_mesh_actioncode {
2923 	WLAN_MESH_ACTION_LINK_METRIC_REPORT,
2924 	WLAN_MESH_ACTION_HWMP_PATH_SELECTION,
2925 	WLAN_MESH_ACTION_GATE_ANNOUNCEMENT,
2926 	WLAN_MESH_ACTION_CONGESTION_CONTROL_NOTIFICATION,
2927 	WLAN_MESH_ACTION_MCCA_SETUP_REQUEST,
2928 	WLAN_MESH_ACTION_MCCA_SETUP_REPLY,
2929 	WLAN_MESH_ACTION_MCCA_ADVERTISEMENT_REQUEST,
2930 	WLAN_MESH_ACTION_MCCA_ADVERTISEMENT,
2931 	WLAN_MESH_ACTION_MCCA_TEARDOWN,
2932 	WLAN_MESH_ACTION_TBTT_ADJUSTMENT_REQUEST,
2933 	WLAN_MESH_ACTION_TBTT_ADJUSTMENT_RESPONSE,
2934 };
2935 
2936 /* Security key length */
2937 enum ieee80211_key_len {
2938 	WLAN_KEY_LEN_WEP40 = 5,
2939 	WLAN_KEY_LEN_WEP104 = 13,
2940 	WLAN_KEY_LEN_CCMP = 16,
2941 	WLAN_KEY_LEN_CCMP_256 = 32,
2942 	WLAN_KEY_LEN_TKIP = 32,
2943 	WLAN_KEY_LEN_AES_CMAC = 16,
2944 	WLAN_KEY_LEN_SMS4 = 32,
2945 	WLAN_KEY_LEN_GCMP = 16,
2946 	WLAN_KEY_LEN_GCMP_256 = 32,
2947 	WLAN_KEY_LEN_BIP_CMAC_256 = 32,
2948 	WLAN_KEY_LEN_BIP_GMAC_128 = 16,
2949 	WLAN_KEY_LEN_BIP_GMAC_256 = 32,
2950 };
2951 
2952 #define IEEE80211_WEP_IV_LEN		4
2953 #define IEEE80211_WEP_ICV_LEN		4
2954 #define IEEE80211_CCMP_HDR_LEN		8
2955 #define IEEE80211_CCMP_MIC_LEN		8
2956 #define IEEE80211_CCMP_PN_LEN		6
2957 #define IEEE80211_CCMP_256_HDR_LEN	8
2958 #define IEEE80211_CCMP_256_MIC_LEN	16
2959 #define IEEE80211_CCMP_256_PN_LEN	6
2960 #define IEEE80211_TKIP_IV_LEN		8
2961 #define IEEE80211_TKIP_ICV_LEN		4
2962 #define IEEE80211_CMAC_PN_LEN		6
2963 #define IEEE80211_GMAC_PN_LEN		6
2964 #define IEEE80211_GCMP_HDR_LEN		8
2965 #define IEEE80211_GCMP_MIC_LEN		16
2966 #define IEEE80211_GCMP_PN_LEN		6
2967 
2968 #define FILS_NONCE_LEN			16
2969 #define FILS_MAX_KEK_LEN		64
2970 
2971 #define FILS_ERP_MAX_USERNAME_LEN	16
2972 #define FILS_ERP_MAX_REALM_LEN		253
2973 #define FILS_ERP_MAX_RRK_LEN		64
2974 
2975 #define PMK_MAX_LEN			64
2976 #define SAE_PASSWORD_MAX_LEN		128
2977 
2978 /* Public action codes (IEEE Std 802.11-2016, 9.6.8.1, Table 9-307) */
2979 enum ieee80211_pub_actioncode {
2980 	WLAN_PUB_ACTION_20_40_BSS_COEX = 0,
2981 	WLAN_PUB_ACTION_DSE_ENABLEMENT = 1,
2982 	WLAN_PUB_ACTION_DSE_DEENABLEMENT = 2,
2983 	WLAN_PUB_ACTION_DSE_REG_LOC_ANN = 3,
2984 	WLAN_PUB_ACTION_EXT_CHANSW_ANN = 4,
2985 	WLAN_PUB_ACTION_DSE_MSMT_REQ = 5,
2986 	WLAN_PUB_ACTION_DSE_MSMT_RESP = 6,
2987 	WLAN_PUB_ACTION_MSMT_PILOT = 7,
2988 	WLAN_PUB_ACTION_DSE_PC = 8,
2989 	WLAN_PUB_ACTION_VENDOR_SPECIFIC = 9,
2990 	WLAN_PUB_ACTION_GAS_INITIAL_REQ = 10,
2991 	WLAN_PUB_ACTION_GAS_INITIAL_RESP = 11,
2992 	WLAN_PUB_ACTION_GAS_COMEBACK_REQ = 12,
2993 	WLAN_PUB_ACTION_GAS_COMEBACK_RESP = 13,
2994 	WLAN_PUB_ACTION_TDLS_DISCOVER_RES = 14,
2995 	WLAN_PUB_ACTION_LOC_TRACK_NOTI = 15,
2996 	WLAN_PUB_ACTION_QAB_REQUEST_FRAME = 16,
2997 	WLAN_PUB_ACTION_QAB_RESPONSE_FRAME = 17,
2998 	WLAN_PUB_ACTION_QMF_POLICY = 18,
2999 	WLAN_PUB_ACTION_QMF_POLICY_CHANGE = 19,
3000 	WLAN_PUB_ACTION_QLOAD_REQUEST = 20,
3001 	WLAN_PUB_ACTION_QLOAD_REPORT = 21,
3002 	WLAN_PUB_ACTION_HCCA_TXOP_ADVERT = 22,
3003 	WLAN_PUB_ACTION_HCCA_TXOP_RESPONSE = 23,
3004 	WLAN_PUB_ACTION_PUBLIC_KEY = 24,
3005 	WLAN_PUB_ACTION_CHANNEL_AVAIL_QUERY = 25,
3006 	WLAN_PUB_ACTION_CHANNEL_SCHEDULE_MGMT = 26,
3007 	WLAN_PUB_ACTION_CONTACT_VERI_SIGNAL = 27,
3008 	WLAN_PUB_ACTION_GDD_ENABLEMENT_REQ = 28,
3009 	WLAN_PUB_ACTION_GDD_ENABLEMENT_RESP = 29,
3010 	WLAN_PUB_ACTION_NETWORK_CHANNEL_CONTROL = 30,
3011 	WLAN_PUB_ACTION_WHITE_SPACE_MAP_ANN = 31,
3012 	WLAN_PUB_ACTION_FTM_REQUEST = 32,
3013 	WLAN_PUB_ACTION_FTM = 33,
3014 	WLAN_PUB_ACTION_FILS_DISCOVERY = 34,
3015 };
3016 
3017 /* TDLS action codes */
3018 enum ieee80211_tdls_actioncode {
3019 	WLAN_TDLS_SETUP_REQUEST = 0,
3020 	WLAN_TDLS_SETUP_RESPONSE = 1,
3021 	WLAN_TDLS_SETUP_CONFIRM = 2,
3022 	WLAN_TDLS_TEARDOWN = 3,
3023 	WLAN_TDLS_PEER_TRAFFIC_INDICATION = 4,
3024 	WLAN_TDLS_CHANNEL_SWITCH_REQUEST = 5,
3025 	WLAN_TDLS_CHANNEL_SWITCH_RESPONSE = 6,
3026 	WLAN_TDLS_PEER_PSM_REQUEST = 7,
3027 	WLAN_TDLS_PEER_PSM_RESPONSE = 8,
3028 	WLAN_TDLS_PEER_TRAFFIC_RESPONSE = 9,
3029 	WLAN_TDLS_DISCOVERY_REQUEST = 10,
3030 };
3031 
3032 /* Extended Channel Switching capability to be set in the 1st byte of
3033  * the @WLAN_EID_EXT_CAPABILITY information element
3034  */
3035 #define WLAN_EXT_CAPA1_EXT_CHANNEL_SWITCHING	BIT(2)
3036 
3037 /* Multiple BSSID capability is set in the 6th bit of 3rd byte of the
3038  * @WLAN_EID_EXT_CAPABILITY information element
3039  */
3040 #define WLAN_EXT_CAPA3_MULTI_BSSID_SUPPORT	BIT(6)
3041 
3042 /* TDLS capabilities in the 4th byte of @WLAN_EID_EXT_CAPABILITY */
3043 #define WLAN_EXT_CAPA4_TDLS_BUFFER_STA		BIT(4)
3044 #define WLAN_EXT_CAPA4_TDLS_PEER_PSM		BIT(5)
3045 #define WLAN_EXT_CAPA4_TDLS_CHAN_SWITCH		BIT(6)
3046 
3047 /* Interworking capabilities are set in 7th bit of 4th byte of the
3048  * @WLAN_EID_EXT_CAPABILITY information element
3049  */
3050 #define WLAN_EXT_CAPA4_INTERWORKING_ENABLED	BIT(7)
3051 
3052 /*
3053  * TDLS capabililites to be enabled in the 5th byte of the
3054  * @WLAN_EID_EXT_CAPABILITY information element
3055  */
3056 #define WLAN_EXT_CAPA5_TDLS_ENABLED	BIT(5)
3057 #define WLAN_EXT_CAPA5_TDLS_PROHIBITED	BIT(6)
3058 #define WLAN_EXT_CAPA5_TDLS_CH_SW_PROHIBITED	BIT(7)
3059 
3060 #define WLAN_EXT_CAPA8_TDLS_WIDE_BW_ENABLED	BIT(5)
3061 #define WLAN_EXT_CAPA8_OPMODE_NOTIF	BIT(6)
3062 
3063 /* Defines the maximal number of MSDUs in an A-MSDU. */
3064 #define WLAN_EXT_CAPA8_MAX_MSDU_IN_AMSDU_LSB	BIT(7)
3065 #define WLAN_EXT_CAPA9_MAX_MSDU_IN_AMSDU_MSB	BIT(0)
3066 
3067 /*
3068  * Fine Timing Measurement Initiator - bit 71 of @WLAN_EID_EXT_CAPABILITY
3069  * information element
3070  */
3071 #define WLAN_EXT_CAPA9_FTM_INITIATOR	BIT(7)
3072 
3073 /* Defines support for TWT Requester and TWT Responder */
3074 #define WLAN_EXT_CAPA10_TWT_REQUESTER_SUPPORT	BIT(5)
3075 #define WLAN_EXT_CAPA10_TWT_RESPONDER_SUPPORT	BIT(6)
3076 
3077 /*
3078  * When set, indicates that the AP is able to tolerate 26-tone RU UL
3079  * OFDMA transmissions using HE TB PPDU from OBSS (not falsely classify the
3080  * 26-tone RU UL OFDMA transmissions as radar pulses).
3081  */
3082 #define WLAN_EXT_CAPA10_OBSS_NARROW_BW_RU_TOLERANCE_SUPPORT BIT(7)
3083 
3084 /* Defines support for enhanced multi-bssid advertisement*/
3085 #define WLAN_EXT_CAPA11_EMA_SUPPORT	BIT(3)
3086 
3087 /* TDLS specific payload type in the LLC/SNAP header */
3088 #define WLAN_TDLS_SNAP_RFTYPE	0x2
3089 
3090 /* BSS Coex IE information field bits */
3091 #define WLAN_BSS_COEX_INFORMATION_REQUEST	BIT(0)
3092 
3093 /**
3094  * enum ieee80211_mesh_sync_method - mesh synchronization method identifier
3095  *
3096  * @IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET: the default synchronization method
3097  * @IEEE80211_SYNC_METHOD_VENDOR: a vendor specific synchronization method
3098  *	that will be specified in a vendor specific information element
3099  */
3100 enum ieee80211_mesh_sync_method {
3101 	IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET = 1,
3102 	IEEE80211_SYNC_METHOD_VENDOR = 255,
3103 };
3104 
3105 /**
3106  * enum ieee80211_mesh_path_protocol - mesh path selection protocol identifier
3107  *
3108  * @IEEE80211_PATH_PROTOCOL_HWMP: the default path selection protocol
3109  * @IEEE80211_PATH_PROTOCOL_VENDOR: a vendor specific protocol that will
3110  *	be specified in a vendor specific information element
3111  */
3112 enum ieee80211_mesh_path_protocol {
3113 	IEEE80211_PATH_PROTOCOL_HWMP = 1,
3114 	IEEE80211_PATH_PROTOCOL_VENDOR = 255,
3115 };
3116 
3117 /**
3118  * enum ieee80211_mesh_path_metric - mesh path selection metric identifier
3119  *
3120  * @IEEE80211_PATH_METRIC_AIRTIME: the default path selection metric
3121  * @IEEE80211_PATH_METRIC_VENDOR: a vendor specific metric that will be
3122  *	specified in a vendor specific information element
3123  */
3124 enum ieee80211_mesh_path_metric {
3125 	IEEE80211_PATH_METRIC_AIRTIME = 1,
3126 	IEEE80211_PATH_METRIC_VENDOR = 255,
3127 };
3128 
3129 /**
3130  * enum ieee80211_root_mode_identifier - root mesh STA mode identifier
3131  *
3132  * These attribute are used by dot11MeshHWMPRootMode to set root mesh STA mode
3133  *
3134  * @IEEE80211_ROOTMODE_NO_ROOT: the mesh STA is not a root mesh STA (default)
3135  * @IEEE80211_ROOTMODE_ROOT: the mesh STA is a root mesh STA if greater than
3136  *	this value
3137  * @IEEE80211_PROACTIVE_PREQ_NO_PREP: the mesh STA is a root mesh STA supports
3138  *	the proactive PREQ with proactive PREP subfield set to 0
3139  * @IEEE80211_PROACTIVE_PREQ_WITH_PREP: the mesh STA is a root mesh STA
3140  *	supports the proactive PREQ with proactive PREP subfield set to 1
3141  * @IEEE80211_PROACTIVE_RANN: the mesh STA is a root mesh STA supports
3142  *	the proactive RANN
3143  */
3144 enum ieee80211_root_mode_identifier {
3145 	IEEE80211_ROOTMODE_NO_ROOT = 0,
3146 	IEEE80211_ROOTMODE_ROOT = 1,
3147 	IEEE80211_PROACTIVE_PREQ_NO_PREP = 2,
3148 	IEEE80211_PROACTIVE_PREQ_WITH_PREP = 3,
3149 	IEEE80211_PROACTIVE_RANN = 4,
3150 };
3151 
3152 /*
3153  * IEEE 802.11-2007 7.3.2.9 Country information element
3154  *
3155  * Minimum length is 8 octets, ie len must be evenly
3156  * divisible by 2
3157  */
3158 
3159 /* Although the spec says 8 I'm seeing 6 in practice */
3160 #define IEEE80211_COUNTRY_IE_MIN_LEN	6
3161 
3162 /* The Country String field of the element shall be 3 octets in length */
3163 #define IEEE80211_COUNTRY_STRING_LEN	3
3164 
3165 /*
3166  * For regulatory extension stuff see IEEE 802.11-2007
3167  * Annex I (page 1141) and Annex J (page 1147). Also
3168  * review 7.3.2.9.
3169  *
3170  * When dot11RegulatoryClassesRequired is true and the
3171  * first_channel/reg_extension_id is >= 201 then the IE
3172  * compromises of the 'ext' struct represented below:
3173  *
3174  *  - Regulatory extension ID - when generating IE this just needs
3175  *    to be monotonically increasing for each triplet passed in
3176  *    the IE
3177  *  - Regulatory class - index into set of rules
3178  *  - Coverage class - index into air propagation time (Table 7-27),
3179  *    in microseconds, you can compute the air propagation time from
3180  *    the index by multiplying by 3, so index 10 yields a propagation
3181  *    of 10 us. Valid values are 0-31, values 32-255 are not defined
3182  *    yet. A value of 0 inicates air propagation of <= 1 us.
3183  *
3184  *  See also Table I.2 for Emission limit sets and table
3185  *  I.3 for Behavior limit sets. Table J.1 indicates how to map
3186  *  a reg_class to an emission limit set and behavior limit set.
3187  */
3188 #define IEEE80211_COUNTRY_EXTENSION_ID 201
3189 
3190 /*
3191  *  Channels numbers in the IE must be monotonically increasing
3192  *  if dot11RegulatoryClassesRequired is not true.
3193  *
3194  *  If dot11RegulatoryClassesRequired is true consecutive
3195  *  subband triplets following a regulatory triplet shall
3196  *  have monotonically increasing first_channel number fields.
3197  *
3198  *  Channel numbers shall not overlap.
3199  *
3200  *  Note that max_power is signed.
3201  */
3202 struct ieee80211_country_ie_triplet {
3203 	union {
3204 		struct {
3205 			u8 first_channel;
3206 			u8 num_channels;
3207 			s8 max_power;
3208 		} __packed chans;
3209 		struct {
3210 			u8 reg_extension_id;
3211 			u8 reg_class;
3212 			u8 coverage_class;
3213 		} __packed ext;
3214 	};
3215 } __packed;
3216 
3217 enum ieee80211_timeout_interval_type {
3218 	WLAN_TIMEOUT_REASSOC_DEADLINE = 1 /* 802.11r */,
3219 	WLAN_TIMEOUT_KEY_LIFETIME = 2 /* 802.11r */,
3220 	WLAN_TIMEOUT_ASSOC_COMEBACK = 3 /* 802.11w */,
3221 };
3222 
3223 /**
3224  * struct ieee80211_timeout_interval_ie - Timeout Interval element
3225  * @type: type, see &enum ieee80211_timeout_interval_type
3226  * @value: timeout interval value
3227  */
3228 struct ieee80211_timeout_interval_ie {
3229 	u8 type;
3230 	__le32 value;
3231 } __packed;
3232 
3233 /**
3234  * enum ieee80211_idle_options - BSS idle options
3235  * @WLAN_IDLE_OPTIONS_PROTECTED_KEEP_ALIVE: the station should send an RSN
3236  *	protected frame to the AP to reset the idle timer at the AP for
3237  *	the station.
3238  */
3239 enum ieee80211_idle_options {
3240 	WLAN_IDLE_OPTIONS_PROTECTED_KEEP_ALIVE = BIT(0),
3241 };
3242 
3243 /**
3244  * struct ieee80211_bss_max_idle_period_ie
3245  *
3246  * This structure refers to "BSS Max idle period element"
3247  *
3248  * @max_idle_period: indicates the time period during which a station can
3249  *	refrain from transmitting frames to its associated AP without being
3250  *	disassociated. In units of 1000 TUs.
3251  * @idle_options: indicates the options associated with the BSS idle capability
3252  *	as specified in &enum ieee80211_idle_options.
3253  */
3254 struct ieee80211_bss_max_idle_period_ie {
3255 	__le16 max_idle_period;
3256 	u8 idle_options;
3257 } __packed;
3258 
3259 /* BACK action code */
3260 enum ieee80211_back_actioncode {
3261 	WLAN_ACTION_ADDBA_REQ = 0,
3262 	WLAN_ACTION_ADDBA_RESP = 1,
3263 	WLAN_ACTION_DELBA = 2,
3264 };
3265 
3266 /* BACK (block-ack) parties */
3267 enum ieee80211_back_parties {
3268 	WLAN_BACK_RECIPIENT = 0,
3269 	WLAN_BACK_INITIATOR = 1,
3270 };
3271 
3272 /* SA Query action */
3273 enum ieee80211_sa_query_action {
3274 	WLAN_ACTION_SA_QUERY_REQUEST = 0,
3275 	WLAN_ACTION_SA_QUERY_RESPONSE = 1,
3276 };
3277 
3278 /**
3279  * struct ieee80211_bssid_index
3280  *
3281  * This structure refers to "Multiple BSSID-index element"
3282  *
3283  * @bssid_index: BSSID index
3284  * @dtim_period: optional, overrides transmitted BSS dtim period
3285  * @dtim_count: optional, overrides transmitted BSS dtim count
3286  */
3287 struct ieee80211_bssid_index {
3288 	u8 bssid_index;
3289 	u8 dtim_period;
3290 	u8 dtim_count;
3291 };
3292 
3293 /**
3294  * struct ieee80211_multiple_bssid_configuration
3295  *
3296  * This structure refers to "Multiple BSSID Configuration element"
3297  *
3298  * @bssid_count: total number of active BSSIDs in the set
3299  * @profile_periodicity: the least number of beacon frames need to be received
3300  *	in order to discover all the nontransmitted BSSIDs in the set.
3301  */
3302 struct ieee80211_multiple_bssid_configuration {
3303 	u8 bssid_count;
3304 	u8 profile_periodicity;
3305 };
3306 
3307 #define SUITE(oui, id)	(((oui) << 8) | (id))
3308 
3309 /* cipher suite selectors */
3310 #define WLAN_CIPHER_SUITE_USE_GROUP	SUITE(0x000FAC, 0)
3311 #define WLAN_CIPHER_SUITE_WEP40		SUITE(0x000FAC, 1)
3312 #define WLAN_CIPHER_SUITE_TKIP		SUITE(0x000FAC, 2)
3313 /* reserved: 				SUITE(0x000FAC, 3) */
3314 #define WLAN_CIPHER_SUITE_CCMP		SUITE(0x000FAC, 4)
3315 #define WLAN_CIPHER_SUITE_WEP104	SUITE(0x000FAC, 5)
3316 #define WLAN_CIPHER_SUITE_AES_CMAC	SUITE(0x000FAC, 6)
3317 #define WLAN_CIPHER_SUITE_GCMP		SUITE(0x000FAC, 8)
3318 #define WLAN_CIPHER_SUITE_GCMP_256	SUITE(0x000FAC, 9)
3319 #define WLAN_CIPHER_SUITE_CCMP_256	SUITE(0x000FAC, 10)
3320 #define WLAN_CIPHER_SUITE_BIP_GMAC_128	SUITE(0x000FAC, 11)
3321 #define WLAN_CIPHER_SUITE_BIP_GMAC_256	SUITE(0x000FAC, 12)
3322 #define WLAN_CIPHER_SUITE_BIP_CMAC_256	SUITE(0x000FAC, 13)
3323 
3324 #define WLAN_CIPHER_SUITE_SMS4		SUITE(0x001472, 1)
3325 
3326 /* AKM suite selectors */
3327 #define WLAN_AKM_SUITE_8021X			SUITE(0x000FAC, 1)
3328 #define WLAN_AKM_SUITE_PSK			SUITE(0x000FAC, 2)
3329 #define WLAN_AKM_SUITE_FT_8021X			SUITE(0x000FAC, 3)
3330 #define WLAN_AKM_SUITE_FT_PSK			SUITE(0x000FAC, 4)
3331 #define WLAN_AKM_SUITE_8021X_SHA256		SUITE(0x000FAC, 5)
3332 #define WLAN_AKM_SUITE_PSK_SHA256		SUITE(0x000FAC, 6)
3333 #define WLAN_AKM_SUITE_TDLS			SUITE(0x000FAC, 7)
3334 #define WLAN_AKM_SUITE_SAE			SUITE(0x000FAC, 8)
3335 #define WLAN_AKM_SUITE_FT_OVER_SAE		SUITE(0x000FAC, 9)
3336 #define WLAN_AKM_SUITE_AP_PEER_KEY		SUITE(0x000FAC, 10)
3337 #define WLAN_AKM_SUITE_8021X_SUITE_B		SUITE(0x000FAC, 11)
3338 #define WLAN_AKM_SUITE_8021X_SUITE_B_192	SUITE(0x000FAC, 12)
3339 #define WLAN_AKM_SUITE_FT_8021X_SHA384		SUITE(0x000FAC, 13)
3340 #define WLAN_AKM_SUITE_FILS_SHA256		SUITE(0x000FAC, 14)
3341 #define WLAN_AKM_SUITE_FILS_SHA384		SUITE(0x000FAC, 15)
3342 #define WLAN_AKM_SUITE_FT_FILS_SHA256		SUITE(0x000FAC, 16)
3343 #define WLAN_AKM_SUITE_FT_FILS_SHA384		SUITE(0x000FAC, 17)
3344 #define WLAN_AKM_SUITE_OWE			SUITE(0x000FAC, 18)
3345 #define WLAN_AKM_SUITE_FT_PSK_SHA384		SUITE(0x000FAC, 19)
3346 #define WLAN_AKM_SUITE_PSK_SHA384		SUITE(0x000FAC, 20)
3347 
3348 #define WLAN_MAX_KEY_LEN		32
3349 
3350 #define WLAN_PMK_NAME_LEN		16
3351 #define WLAN_PMKID_LEN			16
3352 #define WLAN_PMK_LEN_EAP_LEAP		16
3353 #define WLAN_PMK_LEN			32
3354 #define WLAN_PMK_LEN_SUITE_B_192	48
3355 
3356 #define WLAN_OUI_WFA			0x506f9a
3357 #define WLAN_OUI_TYPE_WFA_P2P		9
3358 #define WLAN_OUI_MICROSOFT		0x0050f2
3359 #define WLAN_OUI_TYPE_MICROSOFT_WPA	1
3360 #define WLAN_OUI_TYPE_MICROSOFT_WMM	2
3361 #define WLAN_OUI_TYPE_MICROSOFT_WPS	4
3362 #define WLAN_OUI_TYPE_MICROSOFT_TPC	8
3363 
3364 /*
3365  * WMM/802.11e Tspec Element
3366  */
3367 #define IEEE80211_WMM_IE_TSPEC_TID_MASK		0x0F
3368 #define IEEE80211_WMM_IE_TSPEC_TID_SHIFT	1
3369 
3370 enum ieee80211_tspec_status_code {
3371 	IEEE80211_TSPEC_STATUS_ADMISS_ACCEPTED = 0,
3372 	IEEE80211_TSPEC_STATUS_ADDTS_INVAL_PARAMS = 0x1,
3373 };
3374 
3375 struct ieee80211_tspec_ie {
3376 	u8 element_id;
3377 	u8 len;
3378 	u8 oui[3];
3379 	u8 oui_type;
3380 	u8 oui_subtype;
3381 	u8 version;
3382 	__le16 tsinfo;
3383 	u8 tsinfo_resvd;
3384 	__le16 nominal_msdu;
3385 	__le16 max_msdu;
3386 	__le32 min_service_int;
3387 	__le32 max_service_int;
3388 	__le32 inactivity_int;
3389 	__le32 suspension_int;
3390 	__le32 service_start_time;
3391 	__le32 min_data_rate;
3392 	__le32 mean_data_rate;
3393 	__le32 peak_data_rate;
3394 	__le32 max_burst_size;
3395 	__le32 delay_bound;
3396 	__le32 min_phy_rate;
3397 	__le16 sba;
3398 	__le16 medium_time;
3399 } __packed;
3400 
3401 struct ieee80211_he_6ghz_capa {
3402 	/* uses IEEE80211_HE_6GHZ_CAP_* below */
3403 	__le16 capa;
3404 } __packed;
3405 
3406 /* HE 6 GHz band capabilities */
3407 /* uses enum ieee80211_min_mpdu_spacing values */
3408 #define IEEE80211_HE_6GHZ_CAP_MIN_MPDU_START	0x0007
3409 /* uses enum ieee80211_vht_max_ampdu_length_exp values */
3410 #define IEEE80211_HE_6GHZ_CAP_MAX_AMPDU_LEN_EXP	0x0038
3411 /* uses IEEE80211_VHT_CAP_MAX_MPDU_LENGTH_* values */
3412 #define IEEE80211_HE_6GHZ_CAP_MAX_MPDU_LEN	0x00c0
3413 /* WLAN_HT_CAP_SM_PS_* values */
3414 #define IEEE80211_HE_6GHZ_CAP_SM_PS		0x0600
3415 #define IEEE80211_HE_6GHZ_CAP_RD_RESPONDER	0x0800
3416 #define IEEE80211_HE_6GHZ_CAP_RX_ANTPAT_CONS	0x1000
3417 #define IEEE80211_HE_6GHZ_CAP_TX_ANTPAT_CONS	0x2000
3418 
3419 /**
3420  * ieee80211_get_qos_ctl - get pointer to qos control bytes
3421  * @hdr: the frame
3422  *
3423  * The qos ctrl bytes come after the frame_control, duration, seq_num
3424  * and 3 or 4 addresses of length ETH_ALEN.
3425  * 3 addr: 2 + 2 + 2 + 3*6 = 24
3426  * 4 addr: 2 + 2 + 2 + 4*6 = 30
3427  */
3428 static inline u8 *ieee80211_get_qos_ctl(struct ieee80211_hdr *hdr)
3429 {
3430 	if (ieee80211_has_a4(hdr->frame_control))
3431 		return (u8 *)hdr + 30;
3432 	else
3433 		return (u8 *)hdr + 24;
3434 }
3435 
3436 /**
3437  * ieee80211_get_tid - get qos TID
3438  * @hdr: the frame
3439  */
3440 static inline u8 ieee80211_get_tid(struct ieee80211_hdr *hdr)
3441 {
3442 	u8 *qc = ieee80211_get_qos_ctl(hdr);
3443 
3444 	return qc[0] & IEEE80211_QOS_CTL_TID_MASK;
3445 }
3446 
3447 /**
3448  * ieee80211_get_SA - get pointer to SA
3449  * @hdr: the frame
3450  *
3451  * Given an 802.11 frame, this function returns the offset
3452  * to the source address (SA). It does not verify that the
3453  * header is long enough to contain the address, and the
3454  * header must be long enough to contain the frame control
3455  * field.
3456  */
3457 static inline u8 *ieee80211_get_SA(struct ieee80211_hdr *hdr)
3458 {
3459 	if (ieee80211_has_a4(hdr->frame_control))
3460 		return hdr->addr4;
3461 	if (ieee80211_has_fromds(hdr->frame_control))
3462 		return hdr->addr3;
3463 	return hdr->addr2;
3464 }
3465 
3466 /**
3467  * ieee80211_get_DA - get pointer to DA
3468  * @hdr: the frame
3469  *
3470  * Given an 802.11 frame, this function returns the offset
3471  * to the destination address (DA). It does not verify that
3472  * the header is long enough to contain the address, and the
3473  * header must be long enough to contain the frame control
3474  * field.
3475  */
3476 static inline u8 *ieee80211_get_DA(struct ieee80211_hdr *hdr)
3477 {
3478 	if (ieee80211_has_tods(hdr->frame_control))
3479 		return hdr->addr3;
3480 	else
3481 		return hdr->addr1;
3482 }
3483 
3484 /**
3485  * _ieee80211_is_robust_mgmt_frame - check if frame is a robust management frame
3486  * @hdr: the frame (buffer must include at least the first octet of payload)
3487  */
3488 static inline bool _ieee80211_is_robust_mgmt_frame(struct ieee80211_hdr *hdr)
3489 {
3490 	if (ieee80211_is_disassoc(hdr->frame_control) ||
3491 	    ieee80211_is_deauth(hdr->frame_control))
3492 		return true;
3493 
3494 	if (ieee80211_is_action(hdr->frame_control)) {
3495 		u8 *category;
3496 
3497 		/*
3498 		 * Action frames, excluding Public Action frames, are Robust
3499 		 * Management Frames. However, if we are looking at a Protected
3500 		 * frame, skip the check since the data may be encrypted and
3501 		 * the frame has already been found to be a Robust Management
3502 		 * Frame (by the other end).
3503 		 */
3504 		if (ieee80211_has_protected(hdr->frame_control))
3505 			return true;
3506 		category = ((u8 *) hdr) + 24;
3507 		return *category != WLAN_CATEGORY_PUBLIC &&
3508 			*category != WLAN_CATEGORY_HT &&
3509 			*category != WLAN_CATEGORY_WNM_UNPROTECTED &&
3510 			*category != WLAN_CATEGORY_SELF_PROTECTED &&
3511 			*category != WLAN_CATEGORY_UNPROT_DMG &&
3512 			*category != WLAN_CATEGORY_VHT &&
3513 			*category != WLAN_CATEGORY_VENDOR_SPECIFIC;
3514 	}
3515 
3516 	return false;
3517 }
3518 
3519 /**
3520  * ieee80211_is_robust_mgmt_frame - check if skb contains a robust mgmt frame
3521  * @skb: the skb containing the frame, length will be checked
3522  */
3523 static inline bool ieee80211_is_robust_mgmt_frame(struct sk_buff *skb)
3524 {
3525 	if (skb->len < IEEE80211_MIN_ACTION_SIZE)
3526 		return false;
3527 	return _ieee80211_is_robust_mgmt_frame((void *)skb->data);
3528 }
3529 
3530 /**
3531  * ieee80211_is_public_action - check if frame is a public action frame
3532  * @hdr: the frame
3533  * @len: length of the frame
3534  */
3535 static inline bool ieee80211_is_public_action(struct ieee80211_hdr *hdr,
3536 					      size_t len)
3537 {
3538 	struct ieee80211_mgmt *mgmt = (void *)hdr;
3539 
3540 	if (len < IEEE80211_MIN_ACTION_SIZE)
3541 		return false;
3542 	if (!ieee80211_is_action(hdr->frame_control))
3543 		return false;
3544 	return mgmt->u.action.category == WLAN_CATEGORY_PUBLIC;
3545 }
3546 
3547 /**
3548  * _ieee80211_is_group_privacy_action - check if frame is a group addressed
3549  * privacy action frame
3550  * @hdr: the frame
3551  */
3552 static inline bool _ieee80211_is_group_privacy_action(struct ieee80211_hdr *hdr)
3553 {
3554 	struct ieee80211_mgmt *mgmt = (void *)hdr;
3555 
3556 	if (!ieee80211_is_action(hdr->frame_control) ||
3557 	    !is_multicast_ether_addr(hdr->addr1))
3558 		return false;
3559 
3560 	return mgmt->u.action.category == WLAN_CATEGORY_MESH_ACTION ||
3561 	       mgmt->u.action.category == WLAN_CATEGORY_MULTIHOP_ACTION;
3562 }
3563 
3564 /**
3565  * ieee80211_is_group_privacy_action - check if frame is a group addressed
3566  * privacy action frame
3567  * @skb: the skb containing the frame, length will be checked
3568  */
3569 static inline bool ieee80211_is_group_privacy_action(struct sk_buff *skb)
3570 {
3571 	if (skb->len < IEEE80211_MIN_ACTION_SIZE)
3572 		return false;
3573 	return _ieee80211_is_group_privacy_action((void *)skb->data);
3574 }
3575 
3576 /**
3577  * ieee80211_tu_to_usec - convert time units (TU) to microseconds
3578  * @tu: the TUs
3579  */
3580 static inline unsigned long ieee80211_tu_to_usec(unsigned long tu)
3581 {
3582 	return 1024 * tu;
3583 }
3584 
3585 /**
3586  * ieee80211_check_tim - check if AID bit is set in TIM
3587  * @tim: the TIM IE
3588  * @tim_len: length of the TIM IE
3589  * @aid: the AID to look for
3590  */
3591 static inline bool ieee80211_check_tim(const struct ieee80211_tim_ie *tim,
3592 				       u8 tim_len, u16 aid)
3593 {
3594 	u8 mask;
3595 	u8 index, indexn1, indexn2;
3596 
3597 	if (unlikely(!tim || tim_len < sizeof(*tim)))
3598 		return false;
3599 
3600 	aid &= 0x3fff;
3601 	index = aid / 8;
3602 	mask  = 1 << (aid & 7);
3603 
3604 	indexn1 = tim->bitmap_ctrl & 0xfe;
3605 	indexn2 = tim_len + indexn1 - 4;
3606 
3607 	if (index < indexn1 || index > indexn2)
3608 		return false;
3609 
3610 	index -= indexn1;
3611 
3612 	return !!(tim->virtual_map[index] & mask);
3613 }
3614 
3615 /**
3616  * ieee80211_get_tdls_action - get tdls packet action (or -1, if not tdls packet)
3617  * @skb: the skb containing the frame, length will not be checked
3618  * @hdr_size: the size of the ieee80211_hdr that starts at skb->data
3619  *
3620  * This function assumes the frame is a data frame, and that the network header
3621  * is in the correct place.
3622  */
3623 static inline int ieee80211_get_tdls_action(struct sk_buff *skb, u32 hdr_size)
3624 {
3625 	if (!skb_is_nonlinear(skb) &&
3626 	    skb->len > (skb_network_offset(skb) + 2)) {
3627 		/* Point to where the indication of TDLS should start */
3628 		const u8 *tdls_data = skb_network_header(skb) - 2;
3629 
3630 		if (get_unaligned_be16(tdls_data) == ETH_P_TDLS &&
3631 		    tdls_data[2] == WLAN_TDLS_SNAP_RFTYPE &&
3632 		    tdls_data[3] == WLAN_CATEGORY_TDLS)
3633 			return tdls_data[4];
3634 	}
3635 
3636 	return -1;
3637 }
3638 
3639 /* convert time units */
3640 #define TU_TO_JIFFIES(x)	(usecs_to_jiffies((x) * 1024))
3641 #define TU_TO_EXP_TIME(x)	(jiffies + TU_TO_JIFFIES(x))
3642 
3643 /* convert frequencies */
3644 #define MHZ_TO_KHZ(freq) ((freq) * 1000)
3645 #define KHZ_TO_MHZ(freq) ((freq) / 1000)
3646 #define PR_KHZ(f) KHZ_TO_MHZ(f), f % 1000
3647 #define KHZ_F "%d.%03d"
3648 
3649 /* convert powers */
3650 #define DBI_TO_MBI(gain) ((gain) * 100)
3651 #define MBI_TO_DBI(gain) ((gain) / 100)
3652 #define DBM_TO_MBM(gain) ((gain) * 100)
3653 #define MBM_TO_DBM(gain) ((gain) / 100)
3654 
3655 /**
3656  * ieee80211_action_contains_tpc - checks if the frame contains TPC element
3657  * @skb: the skb containing the frame, length will be checked
3658  *
3659  * This function checks if it's either TPC report action frame or Link
3660  * Measurement report action frame as defined in IEEE Std. 802.11-2012 8.5.2.5
3661  * and 8.5.7.5 accordingly.
3662  */
3663 static inline bool ieee80211_action_contains_tpc(struct sk_buff *skb)
3664 {
3665 	struct ieee80211_mgmt *mgmt = (void *)skb->data;
3666 
3667 	if (!ieee80211_is_action(mgmt->frame_control))
3668 		return false;
3669 
3670 	if (skb->len < IEEE80211_MIN_ACTION_SIZE +
3671 		       sizeof(mgmt->u.action.u.tpc_report))
3672 		return false;
3673 
3674 	/*
3675 	 * TPC report - check that:
3676 	 * category = 0 (Spectrum Management) or 5 (Radio Measurement)
3677 	 * spectrum management action = 3 (TPC/Link Measurement report)
3678 	 * TPC report EID = 35
3679 	 * TPC report element length = 2
3680 	 *
3681 	 * The spectrum management's tpc_report struct is used here both for
3682 	 * parsing tpc_report and radio measurement's link measurement report
3683 	 * frame, since the relevant part is identical in both frames.
3684 	 */
3685 	if (mgmt->u.action.category != WLAN_CATEGORY_SPECTRUM_MGMT &&
3686 	    mgmt->u.action.category != WLAN_CATEGORY_RADIO_MEASUREMENT)
3687 		return false;
3688 
3689 	/* both spectrum mgmt and link measurement have same action code */
3690 	if (mgmt->u.action.u.tpc_report.action_code !=
3691 	    WLAN_ACTION_SPCT_TPC_RPRT)
3692 		return false;
3693 
3694 	if (mgmt->u.action.u.tpc_report.tpc_elem_id != WLAN_EID_TPC_REPORT ||
3695 	    mgmt->u.action.u.tpc_report.tpc_elem_length !=
3696 	    sizeof(struct ieee80211_tpc_report_ie))
3697 		return false;
3698 
3699 	return true;
3700 }
3701 
3702 struct element {
3703 	u8 id;
3704 	u8 datalen;
3705 	u8 data[];
3706 } __packed;
3707 
3708 /* element iteration helpers */
3709 #define for_each_element(_elem, _data, _datalen)			\
3710 	for (_elem = (const struct element *)(_data);			\
3711 	     (const u8 *)(_data) + (_datalen) - (const u8 *)_elem >=	\
3712 		(int)sizeof(*_elem) &&					\
3713 	     (const u8 *)(_data) + (_datalen) - (const u8 *)_elem >=	\
3714 		(int)sizeof(*_elem) + _elem->datalen;			\
3715 	     _elem = (const struct element *)(_elem->data + _elem->datalen))
3716 
3717 #define for_each_element_id(element, _id, data, datalen)		\
3718 	for_each_element(element, data, datalen)			\
3719 		if (element->id == (_id))
3720 
3721 #define for_each_element_extid(element, extid, _data, _datalen)		\
3722 	for_each_element(element, _data, _datalen)			\
3723 		if (element->id == WLAN_EID_EXTENSION &&		\
3724 		    element->datalen > 0 &&				\
3725 		    element->data[0] == (extid))
3726 
3727 #define for_each_subelement(sub, element)				\
3728 	for_each_element(sub, (element)->data, (element)->datalen)
3729 
3730 #define for_each_subelement_id(sub, id, element)			\
3731 	for_each_element_id(sub, id, (element)->data, (element)->datalen)
3732 
3733 #define for_each_subelement_extid(sub, extid, element)			\
3734 	for_each_element_extid(sub, extid, (element)->data, (element)->datalen)
3735 
3736 /**
3737  * for_each_element_completed - determine if element parsing consumed all data
3738  * @element: element pointer after for_each_element() or friends
3739  * @data: same data pointer as passed to for_each_element() or friends
3740  * @datalen: same data length as passed to for_each_element() or friends
3741  *
3742  * This function returns %true if all the data was parsed or considered
3743  * while walking the elements. Only use this if your for_each_element()
3744  * loop cannot be broken out of, otherwise it always returns %false.
3745  *
3746  * If some data was malformed, this returns %false since the last parsed
3747  * element will not fill the whole remaining data.
3748  */
3749 static inline bool for_each_element_completed(const struct element *element,
3750 					      const void *data, size_t datalen)
3751 {
3752 	return (const u8 *)element == (const u8 *)data + datalen;
3753 }
3754 
3755 /**
3756  * RSNX Capabilities:
3757  * bits 0-3: Field length (n-1)
3758  */
3759 #define WLAN_RSNX_CAPA_PROTECTED_TWT BIT(4)
3760 #define WLAN_RSNX_CAPA_SAE_H2E BIT(5)
3761 
3762 /*
3763  * reduced neighbor report, based on Draft P802.11ax_D5.0,
3764  * section 9.4.2.170
3765  */
3766 #define IEEE80211_AP_INFO_TBTT_HDR_TYPE				0x03
3767 #define IEEE80211_AP_INFO_TBTT_HDR_FILTERED			0x04
3768 #define IEEE80211_AP_INFO_TBTT_HDR_COLOC			0x08
3769 #define IEEE80211_AP_INFO_TBTT_HDR_COUNT			0xF0
3770 #define IEEE80211_TBTT_INFO_OFFSET_BSSID_BSS_PARAM		8
3771 #define IEEE80211_TBTT_INFO_OFFSET_BSSID_SSSID_BSS_PARAM	12
3772 
3773 #define IEEE80211_RNR_TBTT_PARAMS_OCT_RECOMMENDED		0x01
3774 #define IEEE80211_RNR_TBTT_PARAMS_SAME_SSID			0x02
3775 #define IEEE80211_RNR_TBTT_PARAMS_MULTI_BSSID			0x04
3776 #define IEEE80211_RNR_TBTT_PARAMS_TRANSMITTED_BSSID		0x08
3777 #define IEEE80211_RNR_TBTT_PARAMS_COLOC_ESS			0x10
3778 #define IEEE80211_RNR_TBTT_PARAMS_PROBE_ACTIVE			0x20
3779 #define IEEE80211_RNR_TBTT_PARAMS_COLOC_AP			0x40
3780 
3781 struct ieee80211_neighbor_ap_info {
3782        u8 tbtt_info_hdr;
3783        u8 tbtt_info_len;
3784        u8 op_class;
3785        u8 channel;
3786 } __packed;
3787 
3788 #endif /* LINUX_IEEE80211_H */
3789