linux/drivers/net/wireless/intel/iwlwifi/mvm/debugfs.c
<<
>>
Prefs
   1// SPDX-License-Identifier: GPL-2.0 OR BSD-3-Clause
   2/*
   3 * Copyright (C) 2012-2014, 2018-2020 Intel Corporation
   4 * Copyright (C) 2013-2015 Intel Mobile Communications GmbH
   5 * Copyright (C) 2016-2017 Intel Deutschland GmbH
   6 */
   7#include <linux/vmalloc.h>
   8#include <linux/ieee80211.h>
   9#include <linux/netdevice.h>
  10
  11#include "mvm.h"
  12#include "sta.h"
  13#include "iwl-io.h"
  14#include "debugfs.h"
  15#include "iwl-modparams.h"
  16#include "fw/error-dump.h"
  17
  18static ssize_t iwl_dbgfs_ctdp_budget_read(struct file *file,
  19                                          char __user *user_buf,
  20                                          size_t count, loff_t *ppos)
  21{
  22        struct iwl_mvm *mvm = file->private_data;
  23        char buf[16];
  24        int pos, budget;
  25
  26        if (!iwl_mvm_is_ctdp_supported(mvm))
  27                return -EOPNOTSUPP;
  28
  29        if (!iwl_mvm_firmware_running(mvm) ||
  30            mvm->fwrt.cur_fw_img != IWL_UCODE_REGULAR)
  31                return -EIO;
  32
  33        mutex_lock(&mvm->mutex);
  34        budget = iwl_mvm_ctdp_command(mvm, CTDP_CMD_OPERATION_REPORT, 0);
  35        mutex_unlock(&mvm->mutex);
  36
  37        if (budget < 0)
  38                return budget;
  39
  40        pos = scnprintf(buf, sizeof(buf), "%d\n", budget);
  41
  42        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
  43}
  44
  45static ssize_t iwl_dbgfs_stop_ctdp_write(struct iwl_mvm *mvm, char *buf,
  46                                         size_t count, loff_t *ppos)
  47{
  48        int ret;
  49
  50        if (!iwl_mvm_is_ctdp_supported(mvm))
  51                return -EOPNOTSUPP;
  52
  53        if (!iwl_mvm_firmware_running(mvm) ||
  54            mvm->fwrt.cur_fw_img != IWL_UCODE_REGULAR)
  55                return -EIO;
  56
  57        mutex_lock(&mvm->mutex);
  58        ret = iwl_mvm_ctdp_command(mvm, CTDP_CMD_OPERATION_STOP, 0);
  59        mutex_unlock(&mvm->mutex);
  60
  61        return ret ?: count;
  62}
  63
  64static ssize_t iwl_dbgfs_force_ctkill_write(struct iwl_mvm *mvm, char *buf,
  65                                            size_t count, loff_t *ppos)
  66{
  67        if (!iwl_mvm_firmware_running(mvm) ||
  68            mvm->fwrt.cur_fw_img != IWL_UCODE_REGULAR)
  69                return -EIO;
  70
  71        iwl_mvm_enter_ctkill(mvm);
  72
  73        return count;
  74}
  75
  76static ssize_t iwl_dbgfs_tx_flush_write(struct iwl_mvm *mvm, char *buf,
  77                                        size_t count, loff_t *ppos)
  78{
  79        int ret;
  80        u32 flush_arg;
  81
  82        if (!iwl_mvm_firmware_running(mvm) ||
  83            mvm->fwrt.cur_fw_img != IWL_UCODE_REGULAR)
  84                return -EIO;
  85
  86        if (kstrtou32(buf, 0, &flush_arg))
  87                return -EINVAL;
  88
  89        if (iwl_mvm_has_new_tx_api(mvm)) {
  90                IWL_DEBUG_TX_QUEUES(mvm,
  91                                    "FLUSHING all tids queues on sta_id = %d\n",
  92                                    flush_arg);
  93                mutex_lock(&mvm->mutex);
  94                ret = iwl_mvm_flush_sta_tids(mvm, flush_arg, 0xFFFF, 0)
  95                        ? : count;
  96                mutex_unlock(&mvm->mutex);
  97                return ret;
  98        }
  99
 100        IWL_DEBUG_TX_QUEUES(mvm, "FLUSHING queues mask to flush = 0x%x\n",
 101                            flush_arg);
 102
 103        mutex_lock(&mvm->mutex);
 104        ret =  iwl_mvm_flush_tx_path(mvm, flush_arg, 0) ? : count;
 105        mutex_unlock(&mvm->mutex);
 106
 107        return ret;
 108}
 109
 110static ssize_t iwl_dbgfs_sta_drain_write(struct iwl_mvm *mvm, char *buf,
 111                                         size_t count, loff_t *ppos)
 112{
 113        struct iwl_mvm_sta *mvmsta;
 114        int sta_id, drain, ret;
 115
 116        if (!iwl_mvm_firmware_running(mvm) ||
 117            mvm->fwrt.cur_fw_img != IWL_UCODE_REGULAR)
 118                return -EIO;
 119
 120        if (sscanf(buf, "%d %d", &sta_id, &drain) != 2)
 121                return -EINVAL;
 122        if (sta_id < 0 || sta_id >= mvm->fw->ucode_capa.num_stations)
 123                return -EINVAL;
 124        if (drain < 0 || drain > 1)
 125                return -EINVAL;
 126
 127        mutex_lock(&mvm->mutex);
 128
 129        mvmsta = iwl_mvm_sta_from_staid_protected(mvm, sta_id);
 130
 131        if (!mvmsta)
 132                ret = -ENOENT;
 133        else
 134                ret = iwl_mvm_drain_sta(mvm, mvmsta, drain) ? : count;
 135
 136        mutex_unlock(&mvm->mutex);
 137
 138        return ret;
 139}
 140
 141static ssize_t iwl_dbgfs_sram_read(struct file *file, char __user *user_buf,
 142                                   size_t count, loff_t *ppos)
 143{
 144        struct iwl_mvm *mvm = file->private_data;
 145        const struct fw_img *img;
 146        unsigned int ofs, len;
 147        size_t ret;
 148        u8 *ptr;
 149
 150        if (!iwl_mvm_firmware_running(mvm))
 151                return -EINVAL;
 152
 153        /* default is to dump the entire data segment */
 154        img = &mvm->fw->img[mvm->fwrt.cur_fw_img];
 155        ofs = img->sec[IWL_UCODE_SECTION_DATA].offset;
 156        len = img->sec[IWL_UCODE_SECTION_DATA].len;
 157
 158        if (mvm->dbgfs_sram_len) {
 159                ofs = mvm->dbgfs_sram_offset;
 160                len = mvm->dbgfs_sram_len;
 161        }
 162
 163        ptr = kzalloc(len, GFP_KERNEL);
 164        if (!ptr)
 165                return -ENOMEM;
 166
 167        iwl_trans_read_mem_bytes(mvm->trans, ofs, ptr, len);
 168
 169        ret = simple_read_from_buffer(user_buf, count, ppos, ptr, len);
 170
 171        kfree(ptr);
 172
 173        return ret;
 174}
 175
 176static ssize_t iwl_dbgfs_sram_write(struct iwl_mvm *mvm, char *buf,
 177                                    size_t count, loff_t *ppos)
 178{
 179        const struct fw_img *img;
 180        u32 offset, len;
 181        u32 img_offset, img_len;
 182
 183        if (!iwl_mvm_firmware_running(mvm))
 184                return -EINVAL;
 185
 186        img = &mvm->fw->img[mvm->fwrt.cur_fw_img];
 187        img_offset = img->sec[IWL_UCODE_SECTION_DATA].offset;
 188        img_len = img->sec[IWL_UCODE_SECTION_DATA].len;
 189
 190        if (sscanf(buf, "%x,%x", &offset, &len) == 2) {
 191                if ((offset & 0x3) || (len & 0x3))
 192                        return -EINVAL;
 193
 194                if (offset + len > img_offset + img_len)
 195                        return -EINVAL;
 196
 197                mvm->dbgfs_sram_offset = offset;
 198                mvm->dbgfs_sram_len = len;
 199        } else {
 200                mvm->dbgfs_sram_offset = 0;
 201                mvm->dbgfs_sram_len = 0;
 202        }
 203
 204        return count;
 205}
 206
 207static ssize_t iwl_dbgfs_set_nic_temperature_read(struct file *file,
 208                                                  char __user *user_buf,
 209                                                  size_t count, loff_t *ppos)
 210{
 211        struct iwl_mvm *mvm = file->private_data;
 212        char buf[16];
 213        int pos;
 214
 215        if (!mvm->temperature_test)
 216                pos = scnprintf(buf , sizeof(buf), "disabled\n");
 217        else
 218                pos = scnprintf(buf , sizeof(buf), "%d\n", mvm->temperature);
 219
 220        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
 221}
 222
 223/*
 224 * Set NIC Temperature
 225 * Cause the driver to ignore the actual NIC temperature reported by the FW
 226 * Enable: any value between IWL_MVM_DEBUG_SET_TEMPERATURE_MIN -
 227 * IWL_MVM_DEBUG_SET_TEMPERATURE_MAX
 228 * Disable: IWL_MVM_DEBUG_SET_TEMPERATURE_DISABLE
 229 */
 230static ssize_t iwl_dbgfs_set_nic_temperature_write(struct iwl_mvm *mvm,
 231                                                   char *buf, size_t count,
 232                                                   loff_t *ppos)
 233{
 234        int temperature;
 235
 236        if (!iwl_mvm_firmware_running(mvm) && !mvm->temperature_test)
 237                return -EIO;
 238
 239        if (kstrtoint(buf, 10, &temperature))
 240                return -EINVAL;
 241        /* not a legal temperature */
 242        if ((temperature > IWL_MVM_DEBUG_SET_TEMPERATURE_MAX &&
 243             temperature != IWL_MVM_DEBUG_SET_TEMPERATURE_DISABLE) ||
 244            temperature < IWL_MVM_DEBUG_SET_TEMPERATURE_MIN)
 245                return -EINVAL;
 246
 247        mutex_lock(&mvm->mutex);
 248        if (temperature == IWL_MVM_DEBUG_SET_TEMPERATURE_DISABLE) {
 249                if (!mvm->temperature_test)
 250                        goto out;
 251
 252                mvm->temperature_test = false;
 253                /* Since we can't read the temp while awake, just set
 254                 * it to zero until we get the next RX stats from the
 255                 * firmware.
 256                 */
 257                mvm->temperature = 0;
 258        } else {
 259                mvm->temperature_test = true;
 260                mvm->temperature = temperature;
 261        }
 262        IWL_DEBUG_TEMP(mvm, "%sabling debug set temperature (temp = %d)\n",
 263                       mvm->temperature_test ? "En" : "Dis" ,
 264                       mvm->temperature);
 265        /* handle the temperature change */
 266        iwl_mvm_tt_handler(mvm);
 267
 268out:
 269        mutex_unlock(&mvm->mutex);
 270
 271        return count;
 272}
 273
 274static ssize_t iwl_dbgfs_nic_temp_read(struct file *file,
 275                                       char __user *user_buf,
 276                                       size_t count, loff_t *ppos)
 277{
 278        struct iwl_mvm *mvm = file->private_data;
 279        char buf[16];
 280        int pos, ret;
 281        s32 temp;
 282
 283        if (!iwl_mvm_firmware_running(mvm))
 284                return -EIO;
 285
 286        mutex_lock(&mvm->mutex);
 287        ret = iwl_mvm_get_temp(mvm, &temp);
 288        mutex_unlock(&mvm->mutex);
 289
 290        if (ret)
 291                return -EIO;
 292
 293        pos = scnprintf(buf , sizeof(buf), "%d\n", temp);
 294
 295        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
 296}
 297
 298#ifdef CONFIG_ACPI
 299static ssize_t iwl_dbgfs_sar_geo_profile_read(struct file *file,
 300                                              char __user *user_buf,
 301                                              size_t count, loff_t *ppos)
 302{
 303        struct iwl_mvm *mvm = file->private_data;
 304        char buf[256];
 305        int pos = 0;
 306        int bufsz = sizeof(buf);
 307        int tbl_idx;
 308        u8 *value;
 309
 310        if (!iwl_mvm_firmware_running(mvm))
 311                return -EIO;
 312
 313        mutex_lock(&mvm->mutex);
 314        tbl_idx = iwl_mvm_get_sar_geo_profile(mvm);
 315        if (tbl_idx < 0) {
 316                mutex_unlock(&mvm->mutex);
 317                return tbl_idx;
 318        }
 319
 320        if (!tbl_idx) {
 321                pos = scnprintf(buf, bufsz,
 322                                "SAR geographic profile disabled\n");
 323        } else {
 324                value = &mvm->fwrt.geo_profiles[tbl_idx - 1].values[0];
 325
 326                pos += scnprintf(buf + pos, bufsz - pos,
 327                                 "Use geographic profile %d\n", tbl_idx);
 328                pos += scnprintf(buf + pos, bufsz - pos,
 329                                 "2.4GHz:\n\tChain A offset: %hhu dBm\n\tChain B offset: %hhu dBm\n\tmax tx power: %hhu dBm\n",
 330                                 value[1], value[2], value[0]);
 331                pos += scnprintf(buf + pos, bufsz - pos,
 332                                 "5.2GHz:\n\tChain A offset: %hhu dBm\n\tChain B offset: %hhu dBm\n\tmax tx power: %hhu dBm\n",
 333                                 value[4], value[5], value[3]);
 334        }
 335        mutex_unlock(&mvm->mutex);
 336
 337        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
 338}
 339#endif
 340
 341static ssize_t iwl_dbgfs_stations_read(struct file *file, char __user *user_buf,
 342                                       size_t count, loff_t *ppos)
 343{
 344        struct iwl_mvm *mvm = file->private_data;
 345        struct ieee80211_sta *sta;
 346        char buf[400];
 347        int i, pos = 0, bufsz = sizeof(buf);
 348
 349        mutex_lock(&mvm->mutex);
 350
 351        for (i = 0; i < mvm->fw->ucode_capa.num_stations; i++) {
 352                pos += scnprintf(buf + pos, bufsz - pos, "%.2d: ", i);
 353                sta = rcu_dereference_protected(mvm->fw_id_to_mac_id[i],
 354                                                lockdep_is_held(&mvm->mutex));
 355                if (!sta)
 356                        pos += scnprintf(buf + pos, bufsz - pos, "N/A\n");
 357                else if (IS_ERR(sta))
 358                        pos += scnprintf(buf + pos, bufsz - pos, "%ld\n",
 359                                         PTR_ERR(sta));
 360                else
 361                        pos += scnprintf(buf + pos, bufsz - pos, "%pM\n",
 362                                         sta->addr);
 363        }
 364
 365        mutex_unlock(&mvm->mutex);
 366
 367        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
 368}
 369
 370static ssize_t iwl_dbgfs_rs_data_read(struct file *file, char __user *user_buf,
 371                                      size_t count, loff_t *ppos)
 372{
 373        struct ieee80211_sta *sta = file->private_data;
 374        struct iwl_mvm_sta *mvmsta = iwl_mvm_sta_from_mac80211(sta);
 375        struct iwl_lq_sta_rs_fw *lq_sta = &mvmsta->lq_sta.rs_fw;
 376        struct iwl_mvm *mvm = lq_sta->pers.drv;
 377        static const size_t bufsz = 2048;
 378        char *buff;
 379        int desc = 0;
 380        ssize_t ret;
 381
 382        buff = kmalloc(bufsz, GFP_KERNEL);
 383        if (!buff)
 384                return -ENOMEM;
 385
 386        mutex_lock(&mvm->mutex);
 387
 388        desc += scnprintf(buff + desc, bufsz - desc, "sta_id %d\n",
 389                          lq_sta->pers.sta_id);
 390        desc += scnprintf(buff + desc, bufsz - desc,
 391                          "fixed rate 0x%X\n",
 392                          lq_sta->pers.dbg_fixed_rate);
 393        desc += scnprintf(buff + desc, bufsz - desc,
 394                          "A-MPDU size limit %d\n",
 395                          lq_sta->pers.dbg_agg_frame_count_lim);
 396        desc += scnprintf(buff + desc, bufsz - desc,
 397                          "valid_tx_ant %s%s%s\n",
 398                (iwl_mvm_get_valid_tx_ant(mvm) & ANT_A) ? "ANT_A," : "",
 399                (iwl_mvm_get_valid_tx_ant(mvm) & ANT_B) ? "ANT_B," : "",
 400                (iwl_mvm_get_valid_tx_ant(mvm) & ANT_C) ? "ANT_C" : "");
 401        desc += scnprintf(buff + desc, bufsz - desc,
 402                          "last tx rate=0x%X ",
 403                          lq_sta->last_rate_n_flags);
 404
 405        desc += rs_pretty_print_rate(buff + desc, bufsz - desc,
 406                                     lq_sta->last_rate_n_flags);
 407        if (desc < bufsz - 1)
 408                buff[desc++] = '\n';
 409        mutex_unlock(&mvm->mutex);
 410
 411        ret = simple_read_from_buffer(user_buf, count, ppos, buff, desc);
 412        kfree(buff);
 413        return ret;
 414}
 415
 416static ssize_t iwl_dbgfs_amsdu_len_write(struct ieee80211_sta *sta,
 417                                         char *buf, size_t count,
 418                                         loff_t *ppos)
 419{
 420        struct iwl_mvm_sta *mvmsta = iwl_mvm_sta_from_mac80211(sta);
 421        int i;
 422        u16 amsdu_len;
 423
 424        if (kstrtou16(buf, 0, &amsdu_len))
 425                return -EINVAL;
 426
 427        /* only change from debug set <-> debug unset */
 428        if ((amsdu_len && mvmsta->orig_amsdu_len) ||
 429            (!!amsdu_len && mvmsta->orig_amsdu_len))
 430                return -EBUSY;
 431
 432        if (amsdu_len) {
 433                mvmsta->orig_amsdu_len = sta->max_amsdu_len;
 434                sta->max_amsdu_len = amsdu_len;
 435                for (i = 0; i < ARRAY_SIZE(sta->max_tid_amsdu_len); i++)
 436                        sta->max_tid_amsdu_len[i] = amsdu_len;
 437        } else {
 438                sta->max_amsdu_len = mvmsta->orig_amsdu_len;
 439                mvmsta->orig_amsdu_len = 0;
 440        }
 441        return count;
 442}
 443
 444static ssize_t iwl_dbgfs_amsdu_len_read(struct file *file,
 445                                        char __user *user_buf,
 446                                        size_t count, loff_t *ppos)
 447{
 448        struct ieee80211_sta *sta = file->private_data;
 449        struct iwl_mvm_sta *mvmsta = iwl_mvm_sta_from_mac80211(sta);
 450
 451        char buf[32];
 452        int pos;
 453
 454        pos = scnprintf(buf, sizeof(buf), "current %d ", sta->max_amsdu_len);
 455        pos += scnprintf(buf + pos, sizeof(buf) - pos, "stored %d\n",
 456                         mvmsta->orig_amsdu_len);
 457
 458        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
 459}
 460
 461static ssize_t iwl_dbgfs_disable_power_off_read(struct file *file,
 462                                                char __user *user_buf,
 463                                                size_t count, loff_t *ppos)
 464{
 465        struct iwl_mvm *mvm = file->private_data;
 466        char buf[64];
 467        int bufsz = sizeof(buf);
 468        int pos = 0;
 469
 470        pos += scnprintf(buf+pos, bufsz-pos, "disable_power_off_d0=%d\n",
 471                         mvm->disable_power_off);
 472        pos += scnprintf(buf+pos, bufsz-pos, "disable_power_off_d3=%d\n",
 473                         mvm->disable_power_off_d3);
 474
 475        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
 476}
 477
 478static ssize_t iwl_dbgfs_disable_power_off_write(struct iwl_mvm *mvm, char *buf,
 479                                                 size_t count, loff_t *ppos)
 480{
 481        int ret, val;
 482
 483        if (!iwl_mvm_firmware_running(mvm))
 484                return -EIO;
 485
 486        if (!strncmp("disable_power_off_d0=", buf, 21)) {
 487                if (sscanf(buf + 21, "%d", &val) != 1)
 488                        return -EINVAL;
 489                mvm->disable_power_off = val;
 490        } else if (!strncmp("disable_power_off_d3=", buf, 21)) {
 491                if (sscanf(buf + 21, "%d", &val) != 1)
 492                        return -EINVAL;
 493                mvm->disable_power_off_d3 = val;
 494        } else {
 495                return -EINVAL;
 496        }
 497
 498        mutex_lock(&mvm->mutex);
 499        ret = iwl_mvm_power_update_device(mvm);
 500        mutex_unlock(&mvm->mutex);
 501
 502        return ret ?: count;
 503}
 504
 505static
 506int iwl_mvm_coex_dump_mbox(struct iwl_bt_coex_profile_notif *notif, char *buf,
 507                           int pos, int bufsz)
 508{
 509        pos += scnprintf(buf+pos, bufsz-pos, "MBOX dw0:\n");
 510
 511        BT_MBOX_PRINT(0, LE_SLAVE_LAT, false);
 512        BT_MBOX_PRINT(0, LE_PROF1, false);
 513        BT_MBOX_PRINT(0, LE_PROF2, false);
 514        BT_MBOX_PRINT(0, LE_PROF_OTHER, false);
 515        BT_MBOX_PRINT(0, CHL_SEQ_N, false);
 516        BT_MBOX_PRINT(0, INBAND_S, false);
 517        BT_MBOX_PRINT(0, LE_MIN_RSSI, false);
 518        BT_MBOX_PRINT(0, LE_SCAN, false);
 519        BT_MBOX_PRINT(0, LE_ADV, false);
 520        BT_MBOX_PRINT(0, LE_MAX_TX_POWER, false);
 521        BT_MBOX_PRINT(0, OPEN_CON_1, true);
 522
 523        pos += scnprintf(buf+pos, bufsz-pos, "MBOX dw1:\n");
 524
 525        BT_MBOX_PRINT(1, BR_MAX_TX_POWER, false);
 526        BT_MBOX_PRINT(1, IP_SR, false);
 527        BT_MBOX_PRINT(1, LE_MSTR, false);
 528        BT_MBOX_PRINT(1, AGGR_TRFC_LD, false);
 529        BT_MBOX_PRINT(1, MSG_TYPE, false);
 530        BT_MBOX_PRINT(1, SSN, true);
 531
 532        pos += scnprintf(buf+pos, bufsz-pos, "MBOX dw2:\n");
 533
 534        BT_MBOX_PRINT(2, SNIFF_ACT, false);
 535        BT_MBOX_PRINT(2, PAG, false);
 536        BT_MBOX_PRINT(2, INQUIRY, false);
 537        BT_MBOX_PRINT(2, CONN, false);
 538        BT_MBOX_PRINT(2, SNIFF_INTERVAL, false);
 539        BT_MBOX_PRINT(2, DISC, false);
 540        BT_MBOX_PRINT(2, SCO_TX_ACT, false);
 541        BT_MBOX_PRINT(2, SCO_RX_ACT, false);
 542        BT_MBOX_PRINT(2, ESCO_RE_TX, false);
 543        BT_MBOX_PRINT(2, SCO_DURATION, true);
 544
 545        pos += scnprintf(buf+pos, bufsz-pos, "MBOX dw3:\n");
 546
 547        BT_MBOX_PRINT(3, SCO_STATE, false);
 548        BT_MBOX_PRINT(3, SNIFF_STATE, false);
 549        BT_MBOX_PRINT(3, A2DP_STATE, false);
 550        BT_MBOX_PRINT(3, A2DP_SRC, false);
 551        BT_MBOX_PRINT(3, ACL_STATE, false);
 552        BT_MBOX_PRINT(3, MSTR_STATE, false);
 553        BT_MBOX_PRINT(3, OBX_STATE, false);
 554        BT_MBOX_PRINT(3, OPEN_CON_2, false);
 555        BT_MBOX_PRINT(3, TRAFFIC_LOAD, false);
 556        BT_MBOX_PRINT(3, CHL_SEQN_LSB, false);
 557        BT_MBOX_PRINT(3, INBAND_P, false);
 558        BT_MBOX_PRINT(3, MSG_TYPE_2, false);
 559        BT_MBOX_PRINT(3, SSN_2, false);
 560        BT_MBOX_PRINT(3, UPDATE_REQUEST, true);
 561
 562        return pos;
 563}
 564
 565static ssize_t iwl_dbgfs_bt_notif_read(struct file *file, char __user *user_buf,
 566                                       size_t count, loff_t *ppos)
 567{
 568        struct iwl_mvm *mvm = file->private_data;
 569        struct iwl_bt_coex_profile_notif *notif = &mvm->last_bt_notif;
 570        char *buf;
 571        int ret, pos = 0, bufsz = sizeof(char) * 1024;
 572
 573        buf = kmalloc(bufsz, GFP_KERNEL);
 574        if (!buf)
 575                return -ENOMEM;
 576
 577        mutex_lock(&mvm->mutex);
 578
 579        pos += iwl_mvm_coex_dump_mbox(notif, buf, pos, bufsz);
 580
 581        pos += scnprintf(buf + pos, bufsz - pos, "bt_ci_compliance = %d\n",
 582                         notif->bt_ci_compliance);
 583        pos += scnprintf(buf + pos, bufsz - pos, "primary_ch_lut = %d\n",
 584                         le32_to_cpu(notif->primary_ch_lut));
 585        pos += scnprintf(buf + pos, bufsz - pos, "secondary_ch_lut = %d\n",
 586                         le32_to_cpu(notif->secondary_ch_lut));
 587        pos += scnprintf(buf + pos,
 588                         bufsz - pos, "bt_activity_grading = %d\n",
 589                         le32_to_cpu(notif->bt_activity_grading));
 590        pos += scnprintf(buf + pos, bufsz - pos, "bt_rrc = %d\n",
 591                         notif->rrc_status & 0xF);
 592        pos += scnprintf(buf + pos, bufsz - pos, "bt_ttc = %d\n",
 593                         notif->ttc_status & 0xF);
 594
 595        pos += scnprintf(buf + pos, bufsz - pos, "sync_sco = %d\n",
 596                         IWL_MVM_BT_COEX_SYNC2SCO);
 597        pos += scnprintf(buf + pos, bufsz - pos, "mplut = %d\n",
 598                         IWL_MVM_BT_COEX_MPLUT);
 599
 600        mutex_unlock(&mvm->mutex);
 601
 602        ret = simple_read_from_buffer(user_buf, count, ppos, buf, pos);
 603        kfree(buf);
 604
 605        return ret;
 606}
 607#undef BT_MBOX_PRINT
 608
 609static ssize_t iwl_dbgfs_bt_cmd_read(struct file *file, char __user *user_buf,
 610                                     size_t count, loff_t *ppos)
 611{
 612        struct iwl_mvm *mvm = file->private_data;
 613        struct iwl_bt_coex_ci_cmd *cmd = &mvm->last_bt_ci_cmd;
 614        char buf[256];
 615        int bufsz = sizeof(buf);
 616        int pos = 0;
 617
 618        mutex_lock(&mvm->mutex);
 619
 620        pos += scnprintf(buf + pos, bufsz - pos, "Channel inhibition CMD\n");
 621        pos += scnprintf(buf + pos, bufsz - pos,
 622                         "\tPrimary Channel Bitmap 0x%016llx\n",
 623                         le64_to_cpu(cmd->bt_primary_ci));
 624        pos += scnprintf(buf + pos, bufsz - pos,
 625                         "\tSecondary Channel Bitmap 0x%016llx\n",
 626                         le64_to_cpu(cmd->bt_secondary_ci));
 627
 628        mutex_unlock(&mvm->mutex);
 629
 630        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
 631}
 632
 633static ssize_t
 634iwl_dbgfs_bt_tx_prio_write(struct iwl_mvm *mvm, char *buf,
 635                           size_t count, loff_t *ppos)
 636{
 637        u32 bt_tx_prio;
 638
 639        if (sscanf(buf, "%u", &bt_tx_prio) != 1)
 640                return -EINVAL;
 641        if (bt_tx_prio > 4)
 642                return -EINVAL;
 643
 644        mvm->bt_tx_prio = bt_tx_prio;
 645
 646        return count;
 647}
 648
 649static ssize_t
 650iwl_dbgfs_bt_force_ant_write(struct iwl_mvm *mvm, char *buf,
 651                             size_t count, loff_t *ppos)
 652{
 653        static const char * const modes_str[BT_FORCE_ANT_MAX] = {
 654                [BT_FORCE_ANT_DIS] = "dis",
 655                [BT_FORCE_ANT_AUTO] = "auto",
 656                [BT_FORCE_ANT_BT] = "bt",
 657                [BT_FORCE_ANT_WIFI] = "wifi",
 658        };
 659        int ret, bt_force_ant_mode;
 660
 661        ret = match_string(modes_str, ARRAY_SIZE(modes_str), buf);
 662        if (ret < 0)
 663                return ret;
 664
 665        bt_force_ant_mode = ret;
 666        ret = 0;
 667        mutex_lock(&mvm->mutex);
 668        if (mvm->bt_force_ant_mode == bt_force_ant_mode)
 669                goto out;
 670
 671        mvm->bt_force_ant_mode = bt_force_ant_mode;
 672        IWL_DEBUG_COEX(mvm, "Force mode: %s\n",
 673                       modes_str[mvm->bt_force_ant_mode]);
 674
 675        if (iwl_mvm_firmware_running(mvm))
 676                ret = iwl_mvm_send_bt_init_conf(mvm);
 677        else
 678                ret = 0;
 679
 680out:
 681        mutex_unlock(&mvm->mutex);
 682        return ret ?: count;
 683}
 684
 685static ssize_t iwl_dbgfs_fw_ver_read(struct file *file, char __user *user_buf,
 686                                     size_t count, loff_t *ppos)
 687{
 688        struct iwl_mvm *mvm = file->private_data;
 689        char *buff, *pos, *endpos;
 690        static const size_t bufsz = 1024;
 691        int ret;
 692
 693        buff = kmalloc(bufsz, GFP_KERNEL);
 694        if (!buff)
 695                return -ENOMEM;
 696
 697        pos = buff;
 698        endpos = pos + bufsz;
 699
 700        pos += scnprintf(pos, endpos - pos, "FW prefix: %s\n",
 701                         mvm->trans->cfg->fw_name_pre);
 702        pos += scnprintf(pos, endpos - pos, "FW: %s\n",
 703                         mvm->fwrt.fw->human_readable);
 704        pos += scnprintf(pos, endpos - pos, "Device: %s\n",
 705                         mvm->fwrt.trans->name);
 706        pos += scnprintf(pos, endpos - pos, "Bus: %s\n",
 707                         mvm->fwrt.dev->bus->name);
 708
 709        ret = simple_read_from_buffer(user_buf, count, ppos, buff, pos - buff);
 710        kfree(buff);
 711
 712        return ret;
 713}
 714
 715#define PRINT_STATS_LE32(_struct, _memb)                                \
 716                         pos += scnprintf(buf + pos, bufsz - pos,       \
 717                                          fmt_table, #_memb,            \
 718                                          le32_to_cpu(_struct->_memb))
 719
 720static ssize_t iwl_dbgfs_fw_rx_stats_read(struct file *file,
 721                                          char __user *user_buf, size_t count,
 722                                          loff_t *ppos)
 723{
 724        struct iwl_mvm *mvm = file->private_data;
 725        static const char *fmt_table = "\t%-30s %10u\n";
 726        static const char *fmt_header = "%-32s\n";
 727        int pos = 0;
 728        char *buf;
 729        int ret;
 730        size_t bufsz;
 731
 732        if (iwl_mvm_has_new_rx_stats_api(mvm))
 733                bufsz = ((sizeof(struct mvm_statistics_rx) /
 734                          sizeof(__le32)) * 43) + (4 * 33) + 1;
 735        else
 736                /* 43 = size of each data line; 33 = size of each header */
 737                bufsz = ((sizeof(struct mvm_statistics_rx_v3) /
 738                          sizeof(__le32)) * 43) + (4 * 33) + 1;
 739
 740        buf = kzalloc(bufsz, GFP_KERNEL);
 741        if (!buf)
 742                return -ENOMEM;
 743
 744        mutex_lock(&mvm->mutex);
 745
 746        if (iwl_mvm_firmware_running(mvm))
 747                iwl_mvm_request_statistics(mvm, false);
 748
 749        pos += scnprintf(buf + pos, bufsz - pos, fmt_header,
 750                         "Statistics_Rx - OFDM");
 751        if (!iwl_mvm_has_new_rx_stats_api(mvm)) {
 752                struct mvm_statistics_rx_phy_v2 *ofdm = &mvm->rx_stats_v3.ofdm;
 753
 754                PRINT_STATS_LE32(ofdm, ina_cnt);
 755                PRINT_STATS_LE32(ofdm, fina_cnt);
 756                PRINT_STATS_LE32(ofdm, plcp_err);
 757                PRINT_STATS_LE32(ofdm, crc32_err);
 758                PRINT_STATS_LE32(ofdm, overrun_err);
 759                PRINT_STATS_LE32(ofdm, early_overrun_err);
 760                PRINT_STATS_LE32(ofdm, crc32_good);
 761                PRINT_STATS_LE32(ofdm, false_alarm_cnt);
 762                PRINT_STATS_LE32(ofdm, fina_sync_err_cnt);
 763                PRINT_STATS_LE32(ofdm, sfd_timeout);
 764                PRINT_STATS_LE32(ofdm, fina_timeout);
 765                PRINT_STATS_LE32(ofdm, unresponded_rts);
 766                PRINT_STATS_LE32(ofdm, rxe_frame_lmt_overrun);
 767                PRINT_STATS_LE32(ofdm, sent_ack_cnt);
 768                PRINT_STATS_LE32(ofdm, sent_cts_cnt);
 769                PRINT_STATS_LE32(ofdm, sent_ba_rsp_cnt);
 770                PRINT_STATS_LE32(ofdm, dsp_self_kill);
 771                PRINT_STATS_LE32(ofdm, mh_format_err);
 772                PRINT_STATS_LE32(ofdm, re_acq_main_rssi_sum);
 773                PRINT_STATS_LE32(ofdm, reserved);
 774        } else {
 775                struct mvm_statistics_rx_phy *ofdm = &mvm->rx_stats.ofdm;
 776
 777                PRINT_STATS_LE32(ofdm, unresponded_rts);
 778                PRINT_STATS_LE32(ofdm, rxe_frame_lmt_overrun);
 779                PRINT_STATS_LE32(ofdm, sent_ba_rsp_cnt);
 780                PRINT_STATS_LE32(ofdm, dsp_self_kill);
 781                PRINT_STATS_LE32(ofdm, reserved);
 782        }
 783
 784        pos += scnprintf(buf + pos, bufsz - pos, fmt_header,
 785                         "Statistics_Rx - CCK");
 786        if (!iwl_mvm_has_new_rx_stats_api(mvm)) {
 787                struct mvm_statistics_rx_phy_v2 *cck = &mvm->rx_stats_v3.cck;
 788
 789                PRINT_STATS_LE32(cck, ina_cnt);
 790                PRINT_STATS_LE32(cck, fina_cnt);
 791                PRINT_STATS_LE32(cck, plcp_err);
 792                PRINT_STATS_LE32(cck, crc32_err);
 793                PRINT_STATS_LE32(cck, overrun_err);
 794                PRINT_STATS_LE32(cck, early_overrun_err);
 795                PRINT_STATS_LE32(cck, crc32_good);
 796                PRINT_STATS_LE32(cck, false_alarm_cnt);
 797                PRINT_STATS_LE32(cck, fina_sync_err_cnt);
 798                PRINT_STATS_LE32(cck, sfd_timeout);
 799                PRINT_STATS_LE32(cck, fina_timeout);
 800                PRINT_STATS_LE32(cck, unresponded_rts);
 801                PRINT_STATS_LE32(cck, rxe_frame_lmt_overrun);
 802                PRINT_STATS_LE32(cck, sent_ack_cnt);
 803                PRINT_STATS_LE32(cck, sent_cts_cnt);
 804                PRINT_STATS_LE32(cck, sent_ba_rsp_cnt);
 805                PRINT_STATS_LE32(cck, dsp_self_kill);
 806                PRINT_STATS_LE32(cck, mh_format_err);
 807                PRINT_STATS_LE32(cck, re_acq_main_rssi_sum);
 808                PRINT_STATS_LE32(cck, reserved);
 809        } else {
 810                struct mvm_statistics_rx_phy *cck = &mvm->rx_stats.cck;
 811
 812                PRINT_STATS_LE32(cck, unresponded_rts);
 813                PRINT_STATS_LE32(cck, rxe_frame_lmt_overrun);
 814                PRINT_STATS_LE32(cck, sent_ba_rsp_cnt);
 815                PRINT_STATS_LE32(cck, dsp_self_kill);
 816                PRINT_STATS_LE32(cck, reserved);
 817        }
 818
 819        pos += scnprintf(buf + pos, bufsz - pos, fmt_header,
 820                         "Statistics_Rx - GENERAL");
 821        if (!iwl_mvm_has_new_rx_stats_api(mvm)) {
 822                struct mvm_statistics_rx_non_phy_v3 *general =
 823                        &mvm->rx_stats_v3.general;
 824
 825                PRINT_STATS_LE32(general, bogus_cts);
 826                PRINT_STATS_LE32(general, bogus_ack);
 827                PRINT_STATS_LE32(general, non_bssid_frames);
 828                PRINT_STATS_LE32(general, filtered_frames);
 829                PRINT_STATS_LE32(general, non_channel_beacons);
 830                PRINT_STATS_LE32(general, channel_beacons);
 831                PRINT_STATS_LE32(general, num_missed_bcon);
 832                PRINT_STATS_LE32(general, adc_rx_saturation_time);
 833                PRINT_STATS_LE32(general, ina_detection_search_time);
 834                PRINT_STATS_LE32(general, beacon_silence_rssi_a);
 835                PRINT_STATS_LE32(general, beacon_silence_rssi_b);
 836                PRINT_STATS_LE32(general, beacon_silence_rssi_c);
 837                PRINT_STATS_LE32(general, interference_data_flag);
 838                PRINT_STATS_LE32(general, channel_load);
 839                PRINT_STATS_LE32(general, dsp_false_alarms);
 840                PRINT_STATS_LE32(general, beacon_rssi_a);
 841                PRINT_STATS_LE32(general, beacon_rssi_b);
 842                PRINT_STATS_LE32(general, beacon_rssi_c);
 843                PRINT_STATS_LE32(general, beacon_energy_a);
 844                PRINT_STATS_LE32(general, beacon_energy_b);
 845                PRINT_STATS_LE32(general, beacon_energy_c);
 846                PRINT_STATS_LE32(general, num_bt_kills);
 847                PRINT_STATS_LE32(general, mac_id);
 848                PRINT_STATS_LE32(general, directed_data_mpdu);
 849        } else {
 850                struct mvm_statistics_rx_non_phy *general =
 851                        &mvm->rx_stats.general;
 852
 853                PRINT_STATS_LE32(general, bogus_cts);
 854                PRINT_STATS_LE32(general, bogus_ack);
 855                PRINT_STATS_LE32(general, non_channel_beacons);
 856                PRINT_STATS_LE32(general, channel_beacons);
 857                PRINT_STATS_LE32(general, num_missed_bcon);
 858                PRINT_STATS_LE32(general, adc_rx_saturation_time);
 859                PRINT_STATS_LE32(general, ina_detection_search_time);
 860                PRINT_STATS_LE32(general, beacon_silence_rssi_a);
 861                PRINT_STATS_LE32(general, beacon_silence_rssi_b);
 862                PRINT_STATS_LE32(general, beacon_silence_rssi_c);
 863                PRINT_STATS_LE32(general, interference_data_flag);
 864                PRINT_STATS_LE32(general, channel_load);
 865                PRINT_STATS_LE32(general, beacon_rssi_a);
 866                PRINT_STATS_LE32(general, beacon_rssi_b);
 867                PRINT_STATS_LE32(general, beacon_rssi_c);
 868                PRINT_STATS_LE32(general, beacon_energy_a);
 869                PRINT_STATS_LE32(general, beacon_energy_b);
 870                PRINT_STATS_LE32(general, beacon_energy_c);
 871                PRINT_STATS_LE32(general, num_bt_kills);
 872                PRINT_STATS_LE32(general, mac_id);
 873        }
 874
 875        pos += scnprintf(buf + pos, bufsz - pos, fmt_header,
 876                         "Statistics_Rx - HT");
 877        if (!iwl_mvm_has_new_rx_stats_api(mvm)) {
 878                struct mvm_statistics_rx_ht_phy_v1 *ht =
 879                        &mvm->rx_stats_v3.ofdm_ht;
 880
 881                PRINT_STATS_LE32(ht, plcp_err);
 882                PRINT_STATS_LE32(ht, overrun_err);
 883                PRINT_STATS_LE32(ht, early_overrun_err);
 884                PRINT_STATS_LE32(ht, crc32_good);
 885                PRINT_STATS_LE32(ht, crc32_err);
 886                PRINT_STATS_LE32(ht, mh_format_err);
 887                PRINT_STATS_LE32(ht, agg_crc32_good);
 888                PRINT_STATS_LE32(ht, agg_mpdu_cnt);
 889                PRINT_STATS_LE32(ht, agg_cnt);
 890                PRINT_STATS_LE32(ht, unsupport_mcs);
 891        } else {
 892                struct mvm_statistics_rx_ht_phy *ht =
 893                        &mvm->rx_stats.ofdm_ht;
 894
 895                PRINT_STATS_LE32(ht, mh_format_err);
 896                PRINT_STATS_LE32(ht, agg_mpdu_cnt);
 897                PRINT_STATS_LE32(ht, agg_cnt);
 898                PRINT_STATS_LE32(ht, unsupport_mcs);
 899        }
 900
 901        mutex_unlock(&mvm->mutex);
 902
 903        ret = simple_read_from_buffer(user_buf, count, ppos, buf, pos);
 904        kfree(buf);
 905
 906        return ret;
 907}
 908#undef PRINT_STAT_LE32
 909
 910static ssize_t iwl_dbgfs_frame_stats_read(struct iwl_mvm *mvm,
 911                                          char __user *user_buf, size_t count,
 912                                          loff_t *ppos,
 913                                          struct iwl_mvm_frame_stats *stats)
 914{
 915        char *buff, *pos, *endpos;
 916        int idx, i;
 917        int ret;
 918        static const size_t bufsz = 1024;
 919
 920        buff = kmalloc(bufsz, GFP_KERNEL);
 921        if (!buff)
 922                return -ENOMEM;
 923
 924        spin_lock_bh(&mvm->drv_stats_lock);
 925
 926        pos = buff;
 927        endpos = pos + bufsz;
 928
 929        pos += scnprintf(pos, endpos - pos,
 930                         "Legacy/HT/VHT\t:\t%d/%d/%d\n",
 931                         stats->legacy_frames,
 932                         stats->ht_frames,
 933                         stats->vht_frames);
 934        pos += scnprintf(pos, endpos - pos, "20/40/80\t:\t%d/%d/%d\n",
 935                         stats->bw_20_frames,
 936                         stats->bw_40_frames,
 937                         stats->bw_80_frames);
 938        pos += scnprintf(pos, endpos - pos, "NGI/SGI\t\t:\t%d/%d\n",
 939                         stats->ngi_frames,
 940                         stats->sgi_frames);
 941        pos += scnprintf(pos, endpos - pos, "SISO/MIMO2\t:\t%d/%d\n",
 942                         stats->siso_frames,
 943                         stats->mimo2_frames);
 944        pos += scnprintf(pos, endpos - pos, "FAIL/SCSS\t:\t%d/%d\n",
 945                         stats->fail_frames,
 946                         stats->success_frames);
 947        pos += scnprintf(pos, endpos - pos, "MPDUs agg\t:\t%d\n",
 948                         stats->agg_frames);
 949        pos += scnprintf(pos, endpos - pos, "A-MPDUs\t\t:\t%d\n",
 950                         stats->ampdu_count);
 951        pos += scnprintf(pos, endpos - pos, "Avg MPDUs/A-MPDU:\t%d\n",
 952                         stats->ampdu_count > 0 ?
 953                         (stats->agg_frames / stats->ampdu_count) : 0);
 954
 955        pos += scnprintf(pos, endpos - pos, "Last Rates\n");
 956
 957        idx = stats->last_frame_idx - 1;
 958        for (i = 0; i < ARRAY_SIZE(stats->last_rates); i++) {
 959                idx = (idx + 1) % ARRAY_SIZE(stats->last_rates);
 960                if (stats->last_rates[idx] == 0)
 961                        continue;
 962                pos += scnprintf(pos, endpos - pos, "Rate[%d]: ",
 963                                 (int)(ARRAY_SIZE(stats->last_rates) - i));
 964                pos += rs_pretty_print_rate(pos, endpos - pos,
 965                                            stats->last_rates[idx]);
 966                if (pos < endpos - 1)
 967                        *pos++ = '\n';
 968        }
 969        spin_unlock_bh(&mvm->drv_stats_lock);
 970
 971        ret = simple_read_from_buffer(user_buf, count, ppos, buff, pos - buff);
 972        kfree(buff);
 973
 974        return ret;
 975}
 976
 977static ssize_t iwl_dbgfs_drv_rx_stats_read(struct file *file,
 978                                           char __user *user_buf, size_t count,
 979                                           loff_t *ppos)
 980{
 981        struct iwl_mvm *mvm = file->private_data;
 982
 983        return iwl_dbgfs_frame_stats_read(mvm, user_buf, count, ppos,
 984                                          &mvm->drv_rx_stats);
 985}
 986
 987static ssize_t iwl_dbgfs_fw_restart_write(struct iwl_mvm *mvm, char *buf,
 988                                          size_t count, loff_t *ppos)
 989{
 990        int __maybe_unused ret;
 991
 992        if (!iwl_mvm_firmware_running(mvm))
 993                return -EIO;
 994
 995        mutex_lock(&mvm->mutex);
 996
 997        /* allow one more restart that we're provoking here */
 998        if (mvm->fw_restart >= 0)
 999                mvm->fw_restart++;
1000
1001        /* take the return value to make compiler happy - it will fail anyway */
1002        ret = iwl_mvm_send_cmd_pdu(mvm, REPLY_ERROR, 0, 0, NULL);
1003
1004        mutex_unlock(&mvm->mutex);
1005
1006        return count;
1007}
1008
1009static ssize_t iwl_dbgfs_fw_nmi_write(struct iwl_mvm *mvm, char *buf,
1010                                      size_t count, loff_t *ppos)
1011{
1012        if (!iwl_mvm_firmware_running(mvm))
1013                return -EIO;
1014
1015        iwl_force_nmi(mvm->trans);
1016
1017        return count;
1018}
1019
1020static ssize_t
1021iwl_dbgfs_scan_ant_rxchain_read(struct file *file,
1022                                char __user *user_buf,
1023                                size_t count, loff_t *ppos)
1024{
1025        struct iwl_mvm *mvm = file->private_data;
1026        int pos = 0;
1027        char buf[32];
1028        const size_t bufsz = sizeof(buf);
1029
1030        /* print which antennas were set for the scan command by the user */
1031        pos += scnprintf(buf + pos, bufsz - pos, "Antennas for scan: ");
1032        if (mvm->scan_rx_ant & ANT_A)
1033                pos += scnprintf(buf + pos, bufsz - pos, "A");
1034        if (mvm->scan_rx_ant & ANT_B)
1035                pos += scnprintf(buf + pos, bufsz - pos, "B");
1036        if (mvm->scan_rx_ant & ANT_C)
1037                pos += scnprintf(buf + pos, bufsz - pos, "C");
1038        pos += scnprintf(buf + pos, bufsz - pos, " (%hhx)\n", mvm->scan_rx_ant);
1039
1040        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
1041}
1042
1043static ssize_t
1044iwl_dbgfs_scan_ant_rxchain_write(struct iwl_mvm *mvm, char *buf,
1045                                 size_t count, loff_t *ppos)
1046{
1047        u8 scan_rx_ant;
1048
1049        if (!iwl_mvm_firmware_running(mvm))
1050                return -EIO;
1051
1052        if (sscanf(buf, "%hhx", &scan_rx_ant) != 1)
1053                return -EINVAL;
1054        if (scan_rx_ant > ANT_ABC)
1055                return -EINVAL;
1056        if (scan_rx_ant & ~(iwl_mvm_get_valid_rx_ant(mvm)))
1057                return -EINVAL;
1058
1059        if (mvm->scan_rx_ant != scan_rx_ant) {
1060                mvm->scan_rx_ant = scan_rx_ant;
1061                if (fw_has_capa(&mvm->fw->ucode_capa,
1062                                IWL_UCODE_TLV_CAPA_UMAC_SCAN))
1063                        iwl_mvm_config_scan(mvm);
1064        }
1065
1066        return count;
1067}
1068
1069static ssize_t iwl_dbgfs_indirection_tbl_write(struct iwl_mvm *mvm,
1070                                               char *buf, size_t count,
1071                                               loff_t *ppos)
1072{
1073        struct iwl_rss_config_cmd cmd = {
1074                .flags = cpu_to_le32(IWL_RSS_ENABLE),
1075                .hash_mask = IWL_RSS_HASH_TYPE_IPV4_TCP |
1076                             IWL_RSS_HASH_TYPE_IPV4_UDP |
1077                             IWL_RSS_HASH_TYPE_IPV4_PAYLOAD |
1078                             IWL_RSS_HASH_TYPE_IPV6_TCP |
1079                             IWL_RSS_HASH_TYPE_IPV6_UDP |
1080                             IWL_RSS_HASH_TYPE_IPV6_PAYLOAD,
1081        };
1082        int ret, i, num_repeats, nbytes = count / 2;
1083
1084        ret = hex2bin(cmd.indirection_table, buf, nbytes);
1085        if (ret)
1086                return ret;
1087
1088        /*
1089         * The input is the redirection table, partial or full.
1090         * Repeat the pattern if needed.
1091         * For example, input of 01020F will be repeated 42 times,
1092         * indirecting RSS hash results to queues 1, 2, 15 (skipping
1093         * queues 3 - 14).
1094         */
1095        num_repeats = ARRAY_SIZE(cmd.indirection_table) / nbytes;
1096        for (i = 1; i < num_repeats; i++)
1097                memcpy(&cmd.indirection_table[i * nbytes],
1098                       cmd.indirection_table, nbytes);
1099        /* handle cut in the middle pattern for the last places */
1100        memcpy(&cmd.indirection_table[i * nbytes], cmd.indirection_table,
1101               ARRAY_SIZE(cmd.indirection_table) % nbytes);
1102
1103        netdev_rss_key_fill(cmd.secret_key, sizeof(cmd.secret_key));
1104
1105        mutex_lock(&mvm->mutex);
1106        if (iwl_mvm_firmware_running(mvm))
1107                ret = iwl_mvm_send_cmd_pdu(mvm, RSS_CONFIG_CMD, 0,
1108                                           sizeof(cmd), &cmd);
1109        else
1110                ret = 0;
1111        mutex_unlock(&mvm->mutex);
1112
1113        return ret ?: count;
1114}
1115
1116static ssize_t iwl_dbgfs_inject_packet_write(struct iwl_mvm *mvm,
1117                                             char *buf, size_t count,
1118                                             loff_t *ppos)
1119{
1120        struct iwl_rx_cmd_buffer rxb = {
1121                ._rx_page_order = 0,
1122                .truesize = 0, /* not used */
1123                ._offset = 0,
1124        };
1125        struct iwl_rx_packet *pkt;
1126        struct iwl_rx_mpdu_desc *desc;
1127        int bin_len = count / 2;
1128        int ret = -EINVAL;
1129        size_t mpdu_cmd_hdr_size = (mvm->trans->trans_cfg->device_family >=
1130                                    IWL_DEVICE_FAMILY_AX210) ?
1131                sizeof(struct iwl_rx_mpdu_desc) :
1132                IWL_RX_DESC_SIZE_V1;
1133
1134        if (!iwl_mvm_firmware_running(mvm))
1135                return -EIO;
1136
1137        /* supporting only 9000 descriptor */
1138        if (!mvm->trans->trans_cfg->mq_rx_supported)
1139                return -ENOTSUPP;
1140
1141        rxb._page = alloc_pages(GFP_ATOMIC, 0);
1142        if (!rxb._page)
1143                return -ENOMEM;
1144        pkt = rxb_addr(&rxb);
1145
1146        ret = hex2bin(page_address(rxb._page), buf, bin_len);
1147        if (ret)
1148                goto out;
1149
1150        /* avoid invalid memory access */
1151        if (bin_len < sizeof(*pkt) + mpdu_cmd_hdr_size)
1152                goto out;
1153
1154        /* check this is RX packet */
1155        if (WIDE_ID(pkt->hdr.group_id, pkt->hdr.cmd) !=
1156            WIDE_ID(LEGACY_GROUP, REPLY_RX_MPDU_CMD))
1157                goto out;
1158
1159        /* check the length in metadata matches actual received length */
1160        desc = (void *)pkt->data;
1161        if (le16_to_cpu(desc->mpdu_len) !=
1162            (bin_len - mpdu_cmd_hdr_size - sizeof(*pkt)))
1163                goto out;
1164
1165        local_bh_disable();
1166        iwl_mvm_rx_mpdu_mq(mvm, NULL, &rxb, 0);
1167        local_bh_enable();
1168        ret = 0;
1169
1170out:
1171        iwl_free_rxb(&rxb);
1172
1173        return ret ?: count;
1174}
1175
1176static int _iwl_dbgfs_inject_beacon_ie(struct iwl_mvm *mvm, char *bin, int len)
1177{
1178        struct ieee80211_vif *vif;
1179        struct iwl_mvm_vif *mvmvif;
1180        struct sk_buff *beacon;
1181        struct ieee80211_tx_info *info;
1182        struct iwl_mac_beacon_cmd beacon_cmd = {};
1183        u8 rate;
1184        u16 flags;
1185        int i;
1186
1187        len /= 2;
1188
1189        /* Element len should be represented by u8 */
1190        if (len >= U8_MAX)
1191                return -EINVAL;
1192
1193        if (!iwl_mvm_firmware_running(mvm))
1194                return -EIO;
1195
1196        if (!iwl_mvm_has_new_tx_api(mvm) &&
1197            !fw_has_api(&mvm->fw->ucode_capa,
1198                        IWL_UCODE_TLV_API_NEW_BEACON_TEMPLATE))
1199                return -EINVAL;
1200
1201        rcu_read_lock();
1202
1203        for (i = 0; i < NUM_MAC_INDEX_DRIVER; i++) {
1204                vif = iwl_mvm_rcu_dereference_vif_id(mvm, i, true);
1205                if (!vif)
1206                        continue;
1207
1208                if (vif->type == NL80211_IFTYPE_AP)
1209                        break;
1210        }
1211
1212        if (i == NUM_MAC_INDEX_DRIVER || !vif)
1213                goto out_err;
1214
1215        mvm->hw->extra_beacon_tailroom = len;
1216
1217        beacon = ieee80211_beacon_get_template(mvm->hw, vif, NULL);
1218        if (!beacon)
1219                goto out_err;
1220
1221        if (len && hex2bin(skb_put_zero(beacon, len), bin, len)) {
1222                dev_kfree_skb(beacon);
1223                goto out_err;
1224        }
1225
1226        mvm->beacon_inject_active = true;
1227
1228        mvmvif = iwl_mvm_vif_from_mac80211(vif);
1229        info = IEEE80211_SKB_CB(beacon);
1230        rate = iwl_mvm_mac_ctxt_get_lowest_rate(info, vif);
1231        flags = iwl_mvm_mac80211_idx_to_hwrate(rate);
1232
1233        if (rate == IWL_FIRST_CCK_RATE)
1234                flags |= IWL_MAC_BEACON_CCK;
1235
1236        beacon_cmd.flags = cpu_to_le16(flags);
1237        beacon_cmd.byte_cnt = cpu_to_le16((u16)beacon->len);
1238        beacon_cmd.template_id = cpu_to_le32((u32)mvmvif->id);
1239
1240        iwl_mvm_mac_ctxt_set_tim(mvm, &beacon_cmd.tim_idx,
1241                                 &beacon_cmd.tim_size,
1242                                 beacon->data, beacon->len);
1243
1244        mutex_lock(&mvm->mutex);
1245        iwl_mvm_mac_ctxt_send_beacon_cmd(mvm, beacon, &beacon_cmd,
1246                                         sizeof(beacon_cmd));
1247        mutex_unlock(&mvm->mutex);
1248
1249        dev_kfree_skb(beacon);
1250
1251        rcu_read_unlock();
1252        return 0;
1253
1254out_err:
1255        rcu_read_unlock();
1256        return -EINVAL;
1257}
1258
1259static ssize_t iwl_dbgfs_inject_beacon_ie_write(struct iwl_mvm *mvm,
1260                                                char *buf, size_t count,
1261                                                loff_t *ppos)
1262{
1263        int ret = _iwl_dbgfs_inject_beacon_ie(mvm, buf, count);
1264
1265        mvm->hw->extra_beacon_tailroom = 0;
1266        return ret ?: count;
1267}
1268
1269static ssize_t iwl_dbgfs_inject_beacon_ie_restore_write(struct iwl_mvm *mvm,
1270                                                        char *buf,
1271                                                        size_t count,
1272                                                        loff_t *ppos)
1273{
1274        int ret = _iwl_dbgfs_inject_beacon_ie(mvm, NULL, 0);
1275
1276        mvm->hw->extra_beacon_tailroom = 0;
1277        mvm->beacon_inject_active = false;
1278        return ret ?: count;
1279}
1280
1281static ssize_t iwl_dbgfs_fw_dbg_conf_read(struct file *file,
1282                                          char __user *user_buf,
1283                                          size_t count, loff_t *ppos)
1284{
1285        struct iwl_mvm *mvm = file->private_data;
1286        int conf;
1287        char buf[8];
1288        const size_t bufsz = sizeof(buf);
1289        int pos = 0;
1290
1291        mutex_lock(&mvm->mutex);
1292        conf = mvm->fwrt.dump.conf;
1293        mutex_unlock(&mvm->mutex);
1294
1295        pos += scnprintf(buf + pos, bufsz - pos, "%d\n", conf);
1296
1297        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
1298}
1299
1300static ssize_t iwl_dbgfs_fw_dbg_conf_write(struct iwl_mvm *mvm,
1301                                           char *buf, size_t count,
1302                                           loff_t *ppos)
1303{
1304        unsigned int conf_id;
1305        int ret;
1306
1307        if (!iwl_mvm_firmware_running(mvm))
1308                return -EIO;
1309
1310        ret = kstrtouint(buf, 0, &conf_id);
1311        if (ret)
1312                return ret;
1313
1314        if (WARN_ON(conf_id >= FW_DBG_CONF_MAX))
1315                return -EINVAL;
1316
1317        mutex_lock(&mvm->mutex);
1318        ret = iwl_fw_start_dbg_conf(&mvm->fwrt, conf_id);
1319        mutex_unlock(&mvm->mutex);
1320
1321        return ret ?: count;
1322}
1323
1324static ssize_t iwl_dbgfs_fw_dbg_collect_write(struct iwl_mvm *mvm,
1325                                              char *buf, size_t count,
1326                                              loff_t *ppos)
1327{
1328        if (count == 0)
1329                return 0;
1330
1331        iwl_dbg_tlv_time_point(&mvm->fwrt, IWL_FW_INI_TIME_POINT_USER_TRIGGER,
1332                               NULL);
1333
1334        iwl_fw_dbg_collect(&mvm->fwrt, FW_DBG_TRIGGER_USER, buf,
1335                           (count - 1), NULL);
1336
1337        return count;
1338}
1339
1340#define ADD_TEXT(...) pos += scnprintf(buf + pos, bufsz - pos, __VA_ARGS__)
1341#ifdef CONFIG_IWLWIFI_BCAST_FILTERING
1342static ssize_t iwl_dbgfs_bcast_filters_read(struct file *file,
1343                                            char __user *user_buf,
1344                                            size_t count, loff_t *ppos)
1345{
1346        struct iwl_mvm *mvm = file->private_data;
1347        struct iwl_bcast_filter_cmd cmd;
1348        const struct iwl_fw_bcast_filter *filter;
1349        char *buf;
1350        int bufsz = 1024;
1351        int i, j, pos = 0;
1352        ssize_t ret;
1353
1354        buf = kzalloc(bufsz, GFP_KERNEL);
1355        if (!buf)
1356                return -ENOMEM;
1357
1358        mutex_lock(&mvm->mutex);
1359        if (!iwl_mvm_bcast_filter_build_cmd(mvm, &cmd)) {
1360                ADD_TEXT("None\n");
1361                mutex_unlock(&mvm->mutex);
1362                goto out;
1363        }
1364        mutex_unlock(&mvm->mutex);
1365
1366        for (i = 0; cmd.filters[i].attrs[0].mask; i++) {
1367                filter = &cmd.filters[i];
1368
1369                ADD_TEXT("Filter [%d]:\n", i);
1370                ADD_TEXT("\tDiscard=%d\n", filter->discard);
1371                ADD_TEXT("\tFrame Type: %s\n",
1372                         filter->frame_type ? "IPv4" : "Generic");
1373
1374                for (j = 0; j < ARRAY_SIZE(filter->attrs); j++) {
1375                        const struct iwl_fw_bcast_filter_attr *attr;
1376
1377                        attr = &filter->attrs[j];
1378                        if (!attr->mask)
1379                                break;
1380
1381                        ADD_TEXT("\tAttr [%d]: offset=%d (from %s), mask=0x%x, value=0x%x reserved=0x%x\n",
1382                                 j, attr->offset,
1383                                 attr->offset_type ? "IP End" :
1384                                                     "Payload Start",
1385                                 be32_to_cpu(attr->mask),
1386                                 be32_to_cpu(attr->val),
1387                                 le16_to_cpu(attr->reserved1));
1388                }
1389        }
1390out:
1391        ret = simple_read_from_buffer(user_buf, count, ppos, buf, pos);
1392        kfree(buf);
1393        return ret;
1394}
1395
1396static ssize_t iwl_dbgfs_bcast_filters_write(struct iwl_mvm *mvm, char *buf,
1397                                             size_t count, loff_t *ppos)
1398{
1399        int pos, next_pos;
1400        struct iwl_fw_bcast_filter filter = {};
1401        struct iwl_bcast_filter_cmd cmd;
1402        u32 filter_id, attr_id, mask, value;
1403        int err = 0;
1404
1405        if (sscanf(buf, "%d %hhi %hhi %n", &filter_id, &filter.discard,
1406                   &filter.frame_type, &pos) != 3)
1407                return -EINVAL;
1408
1409        if (filter_id >= ARRAY_SIZE(mvm->dbgfs_bcast_filtering.cmd.filters) ||
1410            filter.frame_type > BCAST_FILTER_FRAME_TYPE_IPV4)
1411                return -EINVAL;
1412
1413        for (attr_id = 0; attr_id < ARRAY_SIZE(filter.attrs);
1414             attr_id++) {
1415                struct iwl_fw_bcast_filter_attr *attr =
1416                                &filter.attrs[attr_id];
1417
1418                if (pos >= count)
1419                        break;
1420
1421                if (sscanf(&buf[pos], "%hhi %hhi %i %i %n",
1422                           &attr->offset, &attr->offset_type,
1423                           &mask, &value, &next_pos) != 4)
1424                        return -EINVAL;
1425
1426                attr->mask = cpu_to_be32(mask);
1427                attr->val = cpu_to_be32(value);
1428                if (mask)
1429                        filter.num_attrs++;
1430
1431                pos += next_pos;
1432        }
1433
1434        mutex_lock(&mvm->mutex);
1435        memcpy(&mvm->dbgfs_bcast_filtering.cmd.filters[filter_id],
1436               &filter, sizeof(filter));
1437
1438        /* send updated bcast filtering configuration */
1439        if (iwl_mvm_firmware_running(mvm) &&
1440            mvm->dbgfs_bcast_filtering.override &&
1441            iwl_mvm_bcast_filter_build_cmd(mvm, &cmd))
1442                err = iwl_mvm_send_cmd_pdu(mvm, BCAST_FILTER_CMD, 0,
1443                                           sizeof(cmd), &cmd);
1444        mutex_unlock(&mvm->mutex);
1445
1446        return err ?: count;
1447}
1448
1449static ssize_t iwl_dbgfs_bcast_filters_macs_read(struct file *file,
1450                                                 char __user *user_buf,
1451                                                 size_t count, loff_t *ppos)
1452{
1453        struct iwl_mvm *mvm = file->private_data;
1454        struct iwl_bcast_filter_cmd cmd;
1455        char *buf;
1456        int bufsz = 1024;
1457        int i, pos = 0;
1458        ssize_t ret;
1459
1460        buf = kzalloc(bufsz, GFP_KERNEL);
1461        if (!buf)
1462                return -ENOMEM;
1463
1464        mutex_lock(&mvm->mutex);
1465        if (!iwl_mvm_bcast_filter_build_cmd(mvm, &cmd)) {
1466                ADD_TEXT("None\n");
1467                mutex_unlock(&mvm->mutex);
1468                goto out;
1469        }
1470        mutex_unlock(&mvm->mutex);
1471
1472        for (i = 0; i < ARRAY_SIZE(cmd.macs); i++) {
1473                const struct iwl_fw_bcast_mac *mac = &cmd.macs[i];
1474
1475                ADD_TEXT("Mac [%d]: discard=%d attached_filters=0x%x\n",
1476                         i, mac->default_discard, mac->attached_filters);
1477        }
1478out:
1479        ret = simple_read_from_buffer(user_buf, count, ppos, buf, pos);
1480        kfree(buf);
1481        return ret;
1482}
1483
1484static ssize_t iwl_dbgfs_bcast_filters_macs_write(struct iwl_mvm *mvm,
1485                                                  char *buf, size_t count,
1486                                                  loff_t *ppos)
1487{
1488        struct iwl_bcast_filter_cmd cmd;
1489        struct iwl_fw_bcast_mac mac = {};
1490        u32 mac_id, attached_filters;
1491        int err = 0;
1492
1493        if (!mvm->bcast_filters)
1494                return -ENOENT;
1495
1496        if (sscanf(buf, "%d %hhi %i", &mac_id, &mac.default_discard,
1497                   &attached_filters) != 3)
1498                return -EINVAL;
1499
1500        if (mac_id >= ARRAY_SIZE(cmd.macs) ||
1501            mac.default_discard > 1 ||
1502            attached_filters >= BIT(ARRAY_SIZE(cmd.filters)))
1503                return -EINVAL;
1504
1505        mac.attached_filters = cpu_to_le16(attached_filters);
1506
1507        mutex_lock(&mvm->mutex);
1508        memcpy(&mvm->dbgfs_bcast_filtering.cmd.macs[mac_id],
1509               &mac, sizeof(mac));
1510
1511        /* send updated bcast filtering configuration */
1512        if (iwl_mvm_firmware_running(mvm) &&
1513            mvm->dbgfs_bcast_filtering.override &&
1514            iwl_mvm_bcast_filter_build_cmd(mvm, &cmd))
1515                err = iwl_mvm_send_cmd_pdu(mvm, BCAST_FILTER_CMD, 0,
1516                                           sizeof(cmd), &cmd);
1517        mutex_unlock(&mvm->mutex);
1518
1519        return err ?: count;
1520}
1521#endif
1522
1523#define MVM_DEBUGFS_WRITE_FILE_OPS(name, bufsz) \
1524        _MVM_DEBUGFS_WRITE_FILE_OPS(name, bufsz, struct iwl_mvm)
1525#define MVM_DEBUGFS_READ_WRITE_FILE_OPS(name, bufsz) \
1526        _MVM_DEBUGFS_READ_WRITE_FILE_OPS(name, bufsz, struct iwl_mvm)
1527#define MVM_DEBUGFS_ADD_FILE_ALIAS(alias, name, parent, mode) do {      \
1528                debugfs_create_file(alias, mode, parent, mvm,           \
1529                                    &iwl_dbgfs_##name##_ops);           \
1530        } while (0)
1531#define MVM_DEBUGFS_ADD_FILE(name, parent, mode) \
1532        MVM_DEBUGFS_ADD_FILE_ALIAS(#name, name, parent, mode)
1533
1534#define MVM_DEBUGFS_WRITE_STA_FILE_OPS(name, bufsz) \
1535        _MVM_DEBUGFS_WRITE_FILE_OPS(name, bufsz, struct ieee80211_sta)
1536#define MVM_DEBUGFS_READ_WRITE_STA_FILE_OPS(name, bufsz) \
1537        _MVM_DEBUGFS_READ_WRITE_FILE_OPS(name, bufsz, struct ieee80211_sta)
1538
1539#define MVM_DEBUGFS_ADD_STA_FILE_ALIAS(alias, name, parent, mode) do {  \
1540                debugfs_create_file(alias, mode, parent, sta,           \
1541                                    &iwl_dbgfs_##name##_ops);           \
1542        } while (0)
1543#define MVM_DEBUGFS_ADD_STA_FILE(name, parent, mode) \
1544        MVM_DEBUGFS_ADD_STA_FILE_ALIAS(#name, name, parent, mode)
1545
1546static ssize_t
1547iwl_dbgfs_prph_reg_read(struct file *file,
1548                        char __user *user_buf,
1549                        size_t count, loff_t *ppos)
1550{
1551        struct iwl_mvm *mvm = file->private_data;
1552        int pos = 0;
1553        char buf[32];
1554        const size_t bufsz = sizeof(buf);
1555
1556        if (!mvm->dbgfs_prph_reg_addr)
1557                return -EINVAL;
1558
1559        pos += scnprintf(buf + pos, bufsz - pos, "Reg 0x%x: (0x%x)\n",
1560                mvm->dbgfs_prph_reg_addr,
1561                iwl_read_prph(mvm->trans, mvm->dbgfs_prph_reg_addr));
1562
1563        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
1564}
1565
1566static ssize_t
1567iwl_dbgfs_prph_reg_write(struct iwl_mvm *mvm, char *buf,
1568                         size_t count, loff_t *ppos)
1569{
1570        u8 args;
1571        u32 value;
1572
1573        args = sscanf(buf, "%i %i", &mvm->dbgfs_prph_reg_addr, &value);
1574        /* if we only want to set the reg address - nothing more to do */
1575        if (args == 1)
1576                goto out;
1577
1578        /* otherwise, make sure we have both address and value */
1579        if (args != 2)
1580                return -EINVAL;
1581
1582        iwl_write_prph(mvm->trans, mvm->dbgfs_prph_reg_addr, value);
1583
1584out:
1585        return count;
1586}
1587
1588static ssize_t
1589iwl_dbgfs_send_echo_cmd_write(struct iwl_mvm *mvm, char *buf,
1590                              size_t count, loff_t *ppos)
1591{
1592        int ret;
1593
1594        if (!iwl_mvm_firmware_running(mvm))
1595                return -EIO;
1596
1597        mutex_lock(&mvm->mutex);
1598        ret = iwl_mvm_send_cmd_pdu(mvm, ECHO_CMD, 0, 0, NULL);
1599        mutex_unlock(&mvm->mutex);
1600
1601        return ret ?: count;
1602}
1603
1604struct iwl_mvm_sniffer_apply {
1605        struct iwl_mvm *mvm;
1606        u8 *bssid;
1607        u16 aid;
1608};
1609
1610static bool iwl_mvm_sniffer_apply(struct iwl_notif_wait_data *notif_data,
1611                                  struct iwl_rx_packet *pkt, void *data)
1612{
1613        struct iwl_mvm_sniffer_apply *apply = data;
1614
1615        apply->mvm->cur_aid = cpu_to_le16(apply->aid);
1616        memcpy(apply->mvm->cur_bssid, apply->bssid,
1617               sizeof(apply->mvm->cur_bssid));
1618
1619        return true;
1620}
1621
1622static ssize_t
1623iwl_dbgfs_he_sniffer_params_write(struct iwl_mvm *mvm, char *buf,
1624                                  size_t count, loff_t *ppos)
1625{
1626        struct iwl_notification_wait wait;
1627        struct iwl_he_monitor_cmd he_mon_cmd = {};
1628        struct iwl_mvm_sniffer_apply apply = {
1629                .mvm = mvm,
1630        };
1631        u16 wait_cmds[] = {
1632                iwl_cmd_id(HE_AIR_SNIFFER_CONFIG_CMD, DATA_PATH_GROUP, 0),
1633        };
1634        u32 aid;
1635        int ret;
1636
1637        if (!iwl_mvm_firmware_running(mvm))
1638                return -EIO;
1639
1640        ret = sscanf(buf, "%x %2hhx:%2hhx:%2hhx:%2hhx:%2hhx:%2hhx", &aid,
1641                     &he_mon_cmd.bssid[0], &he_mon_cmd.bssid[1],
1642                     &he_mon_cmd.bssid[2], &he_mon_cmd.bssid[3],
1643                     &he_mon_cmd.bssid[4], &he_mon_cmd.bssid[5]);
1644        if (ret != 7)
1645                return -EINVAL;
1646
1647        he_mon_cmd.aid = cpu_to_le16(aid);
1648
1649        apply.aid = aid;
1650        apply.bssid = (void *)he_mon_cmd.bssid;
1651
1652        mutex_lock(&mvm->mutex);
1653
1654        /*
1655         * Use the notification waiter to get our function triggered
1656         * in sequence with other RX. This ensures that frames we get
1657         * on the RX queue _before_ the new configuration is applied
1658         * still have mvm->cur_aid pointing to the old AID, and that
1659         * frames on the RX queue _after_ the firmware processed the
1660         * new configuration (and sent the response, synchronously)
1661         * get mvm->cur_aid correctly set to the new AID.
1662         */
1663        iwl_init_notification_wait(&mvm->notif_wait, &wait,
1664                                   wait_cmds, ARRAY_SIZE(wait_cmds),
1665                                   iwl_mvm_sniffer_apply, &apply);
1666
1667        ret = iwl_mvm_send_cmd_pdu(mvm, iwl_cmd_id(HE_AIR_SNIFFER_CONFIG_CMD,
1668                                                   DATA_PATH_GROUP, 0), 0,
1669                                   sizeof(he_mon_cmd), &he_mon_cmd);
1670
1671        /* no need to really wait, we already did anyway */
1672        iwl_remove_notification(&mvm->notif_wait, &wait);
1673
1674        mutex_unlock(&mvm->mutex);
1675
1676        return ret ?: count;
1677}
1678
1679static ssize_t
1680iwl_dbgfs_he_sniffer_params_read(struct file *file, char __user *user_buf,
1681                                 size_t count, loff_t *ppos)
1682{
1683        struct iwl_mvm *mvm = file->private_data;
1684        u8 buf[32];
1685        int len;
1686
1687        len = scnprintf(buf, sizeof(buf),
1688                        "%d %02hhx:%02hhx:%02hhx:%02hhx:%02hhx:%02hhx\n",
1689                        le16_to_cpu(mvm->cur_aid), mvm->cur_bssid[0],
1690                        mvm->cur_bssid[1], mvm->cur_bssid[2], mvm->cur_bssid[3],
1691                        mvm->cur_bssid[4], mvm->cur_bssid[5]);
1692
1693        return simple_read_from_buffer(user_buf, count, ppos, buf, len);
1694}
1695
1696static ssize_t
1697iwl_dbgfs_uapsd_noagg_bssids_read(struct file *file, char __user *user_buf,
1698                                  size_t count, loff_t *ppos)
1699{
1700        struct iwl_mvm *mvm = file->private_data;
1701        u8 buf[IWL_MVM_UAPSD_NOAGG_BSSIDS_NUM * ETH_ALEN * 3 + 1];
1702        unsigned int pos = 0;
1703        size_t bufsz = sizeof(buf);
1704        int i;
1705
1706        mutex_lock(&mvm->mutex);
1707
1708        for (i = 0; i < IWL_MVM_UAPSD_NOAGG_LIST_LEN; i++)
1709                pos += scnprintf(buf + pos, bufsz - pos, "%pM\n",
1710                                 mvm->uapsd_noagg_bssids[i].addr);
1711
1712        mutex_unlock(&mvm->mutex);
1713
1714        return simple_read_from_buffer(user_buf, count, ppos, buf, pos);
1715}
1716
1717static ssize_t
1718iwl_dbgfs_ltr_config_write(struct iwl_mvm *mvm,
1719                           char *buf, size_t count, loff_t *ppos)
1720{
1721        int ret;
1722        struct iwl_ltr_config_cmd ltr_config = {0};
1723
1724        if (!iwl_mvm_firmware_running(mvm))
1725                return -EIO;
1726
1727        if (sscanf(buf, "%x,%x,%x,%x,%x,%x,%x",
1728                   &ltr_config.flags,
1729                   &ltr_config.static_long,
1730                   &ltr_config.static_short,
1731                   &ltr_config.ltr_cfg_values[0],
1732                   &ltr_config.ltr_cfg_values[1],
1733                   &ltr_config.ltr_cfg_values[2],
1734                   &ltr_config.ltr_cfg_values[3]) != 7) {
1735                return -EINVAL;
1736        }
1737
1738        mutex_lock(&mvm->mutex);
1739        ret = iwl_mvm_send_cmd_pdu(mvm, LTR_CONFIG, 0, sizeof(ltr_config),
1740                                   &ltr_config);
1741        mutex_unlock(&mvm->mutex);
1742
1743        if (ret)
1744                IWL_ERR(mvm, "failed to send ltr configuration cmd\n");
1745
1746        return ret ?: count;
1747}
1748
1749MVM_DEBUGFS_READ_WRITE_FILE_OPS(prph_reg, 64);
1750
1751/* Device wide debugfs entries */
1752MVM_DEBUGFS_READ_FILE_OPS(ctdp_budget);
1753MVM_DEBUGFS_WRITE_FILE_OPS(stop_ctdp, 8);
1754MVM_DEBUGFS_WRITE_FILE_OPS(force_ctkill, 8);
1755MVM_DEBUGFS_WRITE_FILE_OPS(tx_flush, 16);
1756MVM_DEBUGFS_WRITE_FILE_OPS(sta_drain, 8);
1757MVM_DEBUGFS_WRITE_FILE_OPS(send_echo_cmd, 8);
1758MVM_DEBUGFS_READ_WRITE_FILE_OPS(sram, 64);
1759MVM_DEBUGFS_READ_WRITE_FILE_OPS(set_nic_temperature, 64);
1760MVM_DEBUGFS_READ_FILE_OPS(nic_temp);
1761MVM_DEBUGFS_READ_FILE_OPS(stations);
1762MVM_DEBUGFS_READ_FILE_OPS(rs_data);
1763MVM_DEBUGFS_READ_FILE_OPS(bt_notif);
1764MVM_DEBUGFS_READ_FILE_OPS(bt_cmd);
1765MVM_DEBUGFS_READ_WRITE_FILE_OPS(disable_power_off, 64);
1766MVM_DEBUGFS_READ_FILE_OPS(fw_rx_stats);
1767MVM_DEBUGFS_READ_FILE_OPS(drv_rx_stats);
1768MVM_DEBUGFS_READ_FILE_OPS(fw_ver);
1769MVM_DEBUGFS_WRITE_FILE_OPS(fw_restart, 10);
1770MVM_DEBUGFS_WRITE_FILE_OPS(fw_nmi, 10);
1771MVM_DEBUGFS_WRITE_FILE_OPS(bt_tx_prio, 10);
1772MVM_DEBUGFS_WRITE_FILE_OPS(bt_force_ant, 10);
1773MVM_DEBUGFS_READ_WRITE_FILE_OPS(scan_ant_rxchain, 8);
1774MVM_DEBUGFS_READ_WRITE_FILE_OPS(fw_dbg_conf, 8);
1775MVM_DEBUGFS_WRITE_FILE_OPS(fw_dbg_collect, 64);
1776MVM_DEBUGFS_WRITE_FILE_OPS(indirection_tbl,
1777                           (IWL_RSS_INDIRECTION_TABLE_SIZE * 2));
1778MVM_DEBUGFS_WRITE_FILE_OPS(inject_packet, 512);
1779MVM_DEBUGFS_WRITE_FILE_OPS(inject_beacon_ie, 512);
1780MVM_DEBUGFS_WRITE_FILE_OPS(inject_beacon_ie_restore, 512);
1781
1782MVM_DEBUGFS_READ_FILE_OPS(uapsd_noagg_bssids);
1783
1784#ifdef CONFIG_IWLWIFI_BCAST_FILTERING
1785MVM_DEBUGFS_READ_WRITE_FILE_OPS(bcast_filters, 256);
1786MVM_DEBUGFS_READ_WRITE_FILE_OPS(bcast_filters_macs, 256);
1787#endif
1788
1789#ifdef CONFIG_ACPI
1790MVM_DEBUGFS_READ_FILE_OPS(sar_geo_profile);
1791#endif
1792
1793MVM_DEBUGFS_READ_WRITE_STA_FILE_OPS(amsdu_len, 16);
1794
1795MVM_DEBUGFS_READ_WRITE_FILE_OPS(he_sniffer_params, 32);
1796
1797MVM_DEBUGFS_WRITE_FILE_OPS(ltr_config, 512);
1798
1799static ssize_t iwl_dbgfs_mem_read(struct file *file, char __user *user_buf,
1800                                  size_t count, loff_t *ppos)
1801{
1802        struct iwl_mvm *mvm = file->private_data;
1803        struct iwl_dbg_mem_access_cmd cmd = {};
1804        struct iwl_dbg_mem_access_rsp *rsp;
1805        struct iwl_host_cmd hcmd = {
1806                .flags = CMD_WANT_SKB | CMD_SEND_IN_RFKILL,
1807                .data = { &cmd, },
1808                .len = { sizeof(cmd) },
1809        };
1810        size_t delta;
1811        ssize_t ret, len;
1812
1813        if (!iwl_mvm_firmware_running(mvm))
1814                return -EIO;
1815
1816        hcmd.id = iwl_cmd_id(*ppos >> 24 ? UMAC_RD_WR : LMAC_RD_WR,
1817                             DEBUG_GROUP, 0);
1818        cmd.op = cpu_to_le32(DEBUG_MEM_OP_READ);
1819
1820        /* Take care of alignment of both the position and the length */
1821        delta = *ppos & 0x3;
1822        cmd.addr = cpu_to_le32(*ppos - delta);
1823        cmd.len = cpu_to_le32(min(ALIGN(count + delta, 4) / 4,
1824                                  (size_t)DEBUG_MEM_MAX_SIZE_DWORDS));
1825
1826        mutex_lock(&mvm->mutex);
1827        ret = iwl_mvm_send_cmd(mvm, &hcmd);
1828        mutex_unlock(&mvm->mutex);
1829
1830        if (ret < 0)
1831                return ret;
1832
1833        rsp = (void *)hcmd.resp_pkt->data;
1834        if (le32_to_cpu(rsp->status) != DEBUG_MEM_STATUS_SUCCESS) {
1835                ret = -ENXIO;
1836                goto out;
1837        }
1838
1839        len = min((size_t)le32_to_cpu(rsp->len) << 2,
1840                  iwl_rx_packet_payload_len(hcmd.resp_pkt) - sizeof(*rsp));
1841        len = min(len - delta, count);
1842        if (len < 0) {
1843                ret = -EFAULT;
1844                goto out;
1845        }
1846
1847        ret = len - copy_to_user(user_buf, (void *)rsp->data + delta, len);
1848        *ppos += ret;
1849
1850out:
1851        iwl_free_resp(&hcmd);
1852        return ret;
1853}
1854
1855static ssize_t iwl_dbgfs_mem_write(struct file *file,
1856                                   const char __user *user_buf, size_t count,
1857                                   loff_t *ppos)
1858{
1859        struct iwl_mvm *mvm = file->private_data;
1860        struct iwl_dbg_mem_access_cmd *cmd;
1861        struct iwl_dbg_mem_access_rsp *rsp;
1862        struct iwl_host_cmd hcmd = {};
1863        size_t cmd_size;
1864        size_t data_size;
1865        u32 op, len;
1866        ssize_t ret;
1867
1868        if (!iwl_mvm_firmware_running(mvm))
1869                return -EIO;
1870
1871        hcmd.id = iwl_cmd_id(*ppos >> 24 ? UMAC_RD_WR : LMAC_RD_WR,
1872                             DEBUG_GROUP, 0);
1873
1874        if (*ppos & 0x3 || count < 4) {
1875                op = DEBUG_MEM_OP_WRITE_BYTES;
1876                len = min(count, (size_t)(4 - (*ppos & 0x3)));
1877                data_size = len;
1878        } else {
1879                op = DEBUG_MEM_OP_WRITE;
1880                len = min(count >> 2, (size_t)DEBUG_MEM_MAX_SIZE_DWORDS);
1881                data_size = len << 2;
1882        }
1883
1884        cmd_size = sizeof(*cmd) + ALIGN(data_size, 4);
1885        cmd = kzalloc(cmd_size, GFP_KERNEL);
1886        if (!cmd)
1887                return -ENOMEM;
1888
1889        cmd->op = cpu_to_le32(op);
1890        cmd->len = cpu_to_le32(len);
1891        cmd->addr = cpu_to_le32(*ppos);
1892        if (copy_from_user((void *)cmd->data, user_buf, data_size)) {
1893                kfree(cmd);
1894                return -EFAULT;
1895        }
1896
1897        hcmd.flags = CMD_WANT_SKB | CMD_SEND_IN_RFKILL,
1898        hcmd.data[0] = (void *)cmd;
1899        hcmd.len[0] = cmd_size;
1900
1901        mutex_lock(&mvm->mutex);
1902        ret = iwl_mvm_send_cmd(mvm, &hcmd);
1903        mutex_unlock(&mvm->mutex);
1904
1905        kfree(cmd);
1906
1907        if (ret < 0)
1908                return ret;
1909
1910        rsp = (void *)hcmd.resp_pkt->data;
1911        if (rsp->status != DEBUG_MEM_STATUS_SUCCESS) {
1912                ret = -ENXIO;
1913                goto out;
1914        }
1915
1916        ret = data_size;
1917        *ppos += ret;
1918
1919out:
1920        iwl_free_resp(&hcmd);
1921        return ret;
1922}
1923
1924static const struct file_operations iwl_dbgfs_mem_ops = {
1925        .read = iwl_dbgfs_mem_read,
1926        .write = iwl_dbgfs_mem_write,
1927        .open = simple_open,
1928        .llseek = default_llseek,
1929};
1930
1931void iwl_mvm_sta_add_debugfs(struct ieee80211_hw *hw,
1932                             struct ieee80211_vif *vif,
1933                             struct ieee80211_sta *sta,
1934                             struct dentry *dir)
1935{
1936        struct iwl_mvm *mvm = IWL_MAC80211_GET_MVM(hw);
1937
1938        if (iwl_mvm_has_tlc_offload(mvm)) {
1939                MVM_DEBUGFS_ADD_STA_FILE(rs_data, dir, 0400);
1940        }
1941        MVM_DEBUGFS_ADD_STA_FILE(amsdu_len, dir, 0600);
1942}
1943
1944void iwl_mvm_dbgfs_register(struct iwl_mvm *mvm, struct dentry *dbgfs_dir)
1945{
1946        struct dentry *bcast_dir __maybe_unused;
1947        char buf[100];
1948
1949        spin_lock_init(&mvm->drv_stats_lock);
1950
1951        mvm->debugfs_dir = dbgfs_dir;
1952
1953        MVM_DEBUGFS_ADD_FILE(tx_flush, mvm->debugfs_dir, 0200);
1954        MVM_DEBUGFS_ADD_FILE(sta_drain, mvm->debugfs_dir, 0200);
1955        MVM_DEBUGFS_ADD_FILE(sram, mvm->debugfs_dir, 0600);
1956        MVM_DEBUGFS_ADD_FILE(set_nic_temperature, mvm->debugfs_dir, 0600);
1957        MVM_DEBUGFS_ADD_FILE(nic_temp, dbgfs_dir, 0400);
1958        MVM_DEBUGFS_ADD_FILE(ctdp_budget, dbgfs_dir, 0400);
1959        MVM_DEBUGFS_ADD_FILE(stop_ctdp, dbgfs_dir, 0200);
1960        MVM_DEBUGFS_ADD_FILE(force_ctkill, dbgfs_dir, 0200);
1961        MVM_DEBUGFS_ADD_FILE(stations, dbgfs_dir, 0400);
1962        MVM_DEBUGFS_ADD_FILE(bt_notif, dbgfs_dir, 0400);
1963        MVM_DEBUGFS_ADD_FILE(bt_cmd, dbgfs_dir, 0400);
1964        MVM_DEBUGFS_ADD_FILE(disable_power_off, mvm->debugfs_dir, 0600);
1965        MVM_DEBUGFS_ADD_FILE(fw_ver, mvm->debugfs_dir, 0400);
1966        MVM_DEBUGFS_ADD_FILE(fw_rx_stats, mvm->debugfs_dir, 0400);
1967        MVM_DEBUGFS_ADD_FILE(drv_rx_stats, mvm->debugfs_dir, 0400);
1968        MVM_DEBUGFS_ADD_FILE(fw_restart, mvm->debugfs_dir, 0200);
1969        MVM_DEBUGFS_ADD_FILE(fw_nmi, mvm->debugfs_dir, 0200);
1970        MVM_DEBUGFS_ADD_FILE(bt_tx_prio, mvm->debugfs_dir, 0200);
1971        MVM_DEBUGFS_ADD_FILE(bt_force_ant, mvm->debugfs_dir, 0200);
1972        MVM_DEBUGFS_ADD_FILE(scan_ant_rxchain, mvm->debugfs_dir, 0600);
1973        MVM_DEBUGFS_ADD_FILE(prph_reg, mvm->debugfs_dir, 0600);
1974        MVM_DEBUGFS_ADD_FILE(fw_dbg_conf, mvm->debugfs_dir, 0600);
1975        MVM_DEBUGFS_ADD_FILE(fw_dbg_collect, mvm->debugfs_dir, 0200);
1976        MVM_DEBUGFS_ADD_FILE(send_echo_cmd, mvm->debugfs_dir, 0200);
1977        MVM_DEBUGFS_ADD_FILE(indirection_tbl, mvm->debugfs_dir, 0200);
1978        MVM_DEBUGFS_ADD_FILE(inject_packet, mvm->debugfs_dir, 0200);
1979        MVM_DEBUGFS_ADD_FILE(inject_beacon_ie, mvm->debugfs_dir, 0200);
1980        MVM_DEBUGFS_ADD_FILE(inject_beacon_ie_restore, mvm->debugfs_dir, 0200);
1981#ifdef CONFIG_ACPI
1982        MVM_DEBUGFS_ADD_FILE(sar_geo_profile, dbgfs_dir, 0400);
1983#endif
1984        MVM_DEBUGFS_ADD_FILE(he_sniffer_params, mvm->debugfs_dir, 0600);
1985
1986        if (fw_has_capa(&mvm->fw->ucode_capa, IWL_UCODE_TLV_CAPA_SET_LTR_GEN2))
1987                MVM_DEBUGFS_ADD_FILE(ltr_config, mvm->debugfs_dir, 0200);
1988
1989        debugfs_create_bool("enable_scan_iteration_notif", 0600,
1990                            mvm->debugfs_dir, &mvm->scan_iter_notif_enabled);
1991        debugfs_create_bool("drop_bcn_ap_mode", 0600, mvm->debugfs_dir,
1992                            &mvm->drop_bcn_ap_mode);
1993
1994        MVM_DEBUGFS_ADD_FILE(uapsd_noagg_bssids, mvm->debugfs_dir, S_IRUSR);
1995
1996#ifdef CONFIG_IWLWIFI_BCAST_FILTERING
1997        if (mvm->fw->ucode_capa.flags & IWL_UCODE_TLV_FLAGS_BCAST_FILTERING) {
1998                bcast_dir = debugfs_create_dir("bcast_filtering",
1999                                               mvm->debugfs_dir);
2000
2001                debugfs_create_bool("override", 0600, bcast_dir,
2002                                    &mvm->dbgfs_bcast_filtering.override);
2003
2004                MVM_DEBUGFS_ADD_FILE_ALIAS("filters", bcast_filters,
2005                                           bcast_dir, 0600);
2006                MVM_DEBUGFS_ADD_FILE_ALIAS("macs", bcast_filters_macs,
2007                                           bcast_dir, 0600);
2008        }
2009#endif
2010
2011#ifdef CONFIG_PM_SLEEP
2012        MVM_DEBUGFS_ADD_FILE(d3_test, mvm->debugfs_dir, 0400);
2013        debugfs_create_bool("d3_wake_sysassert", 0600, mvm->debugfs_dir,
2014                            &mvm->d3_wake_sysassert);
2015        debugfs_create_u32("last_netdetect_scans", 0400, mvm->debugfs_dir,
2016                           &mvm->last_netdetect_scans);
2017#endif
2018
2019        debugfs_create_u8("ps_disabled", 0400, mvm->debugfs_dir,
2020                          &mvm->ps_disabled);
2021        debugfs_create_blob("nvm_hw", 0400, mvm->debugfs_dir,
2022                            &mvm->nvm_hw_blob);
2023        debugfs_create_blob("nvm_sw", 0400, mvm->debugfs_dir,
2024                            &mvm->nvm_sw_blob);
2025        debugfs_create_blob("nvm_calib", 0400, mvm->debugfs_dir,
2026                            &mvm->nvm_calib_blob);
2027        debugfs_create_blob("nvm_prod", 0400, mvm->debugfs_dir,
2028                            &mvm->nvm_prod_blob);
2029        debugfs_create_blob("nvm_phy_sku", 0400, mvm->debugfs_dir,
2030                            &mvm->nvm_phy_sku_blob);
2031        debugfs_create_blob("nvm_reg", S_IRUSR,
2032                            mvm->debugfs_dir, &mvm->nvm_reg_blob);
2033
2034        debugfs_create_file("mem", 0600, dbgfs_dir, mvm, &iwl_dbgfs_mem_ops);
2035
2036        /*
2037         * Create a symlink with mac80211. It will be removed when mac80211
2038         * exists (before the opmode exists which removes the target.)
2039         */
2040        snprintf(buf, 100, "../../%pd2", dbgfs_dir->d_parent);
2041        debugfs_create_symlink("iwlwifi", mvm->hw->wiphy->debugfsdir, buf);
2042}
2043