GNU Linux-libre 4.9.318-gnu1
[releases.git] / drivers / staging / rtl8188eu / core / rtw_mlme.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  ******************************************************************************/
15 #define _RTW_MLME_C_
16
17 #include <linux/ieee80211.h>
18
19 #include <osdep_service.h>
20 #include <drv_types.h>
21 #include <recv_osdep.h>
22 #include <xmit_osdep.h>
23 #include <hal_intf.h>
24 #include <mlme_osdep.h>
25 #include <sta_info.h>
26 #include <wifi.h>
27 #include <wlan_bssdef.h>
28 #include <rtw_ioctl_set.h>
29 #include <linux/vmalloc.h>
30
31 extern unsigned char    MCS_rate_2R[16];
32 extern unsigned char    MCS_rate_1R[16];
33
34 int rtw_init_mlme_priv(struct adapter *padapter)
35 {
36         int     i;
37         u8      *pbuf;
38         struct wlan_network     *pnetwork;
39         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
40         int     res = _SUCCESS;
41
42         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by vzalloc(). */
43
44         pmlmepriv->nic_hdl = (u8 *)padapter;
45
46         pmlmepriv->pscanned = NULL;
47         pmlmepriv->fw_state = 0;
48         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
49         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
50
51         spin_lock_init(&(pmlmepriv->lock));
52         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
53         _rtw_init_queue(&(pmlmepriv->scanned_queue));
54
55         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
56
57         pbuf = vzalloc(MAX_BSS_CNT * (sizeof(struct wlan_network)));
58
59         if (pbuf == NULL) {
60                 res = _FAIL;
61                 goto exit;
62         }
63         pmlmepriv->free_bss_buf = pbuf;
64
65         pnetwork = (struct wlan_network *)pbuf;
66
67         for (i = 0; i < MAX_BSS_CNT; i++) {
68                 INIT_LIST_HEAD(&(pnetwork->list));
69
70                 list_add_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
71
72                 pnetwork++;
73         }
74
75         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
76
77         rtw_clear_scan_deny(padapter);
78
79         rtw_init_mlme_timer(padapter);
80
81 exit:
82         return res;
83 }
84
85 #if defined(CONFIG_88EU_AP_MODE)
86 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
87 {
88         kfree(*ppie);
89         *plen = 0;
90         *ppie = NULL;
91 }
92
93 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
94 {
95         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
96         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
97         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
98         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
99         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
100         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
101 }
102 #else
103 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
104 {
105 }
106 #endif
107
108 void rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
109 {
110         if (pmlmepriv) {
111                 rtw_free_mlme_priv_ie_data(pmlmepriv);
112                 vfree(pmlmepriv->free_bss_buf);
113         }
114 }
115
116 struct wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)
117                                         /* _queue *free_queue) */
118 {
119         struct wlan_network *pnetwork;
120         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
121
122         spin_lock_bh(&free_queue->lock);
123         pnetwork = list_first_entry_or_null(&free_queue->queue,
124                                             struct wlan_network, list);
125         if (!pnetwork)
126                 goto exit;
127
128         list_del_init(&pnetwork->list);
129
130         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
131                  ("_rtw_alloc_network: ptr=%p\n", &pnetwork->list));
132         pnetwork->network_type = 0;
133         pnetwork->fixed = false;
134         pnetwork->last_scanned = jiffies;
135         pnetwork->aid = 0;
136         pnetwork->join_res = 0;
137
138 exit:
139         spin_unlock_bh(&free_queue->lock);
140
141         return pnetwork;
142 }
143
144 static void _rtw_free_network(struct mlme_priv *pmlmepriv, struct wlan_network *pnetwork, u8 isfreeall)
145 {
146         unsigned long curr_time;
147         u32 delta_time;
148         u32 lifetime = SCANQUEUE_LIFETIME;
149         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
150
151         if (pnetwork == NULL)
152                 return;
153
154         if (pnetwork->fixed)
155                 return;
156         curr_time = jiffies;
157         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
158             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)))
159                 lifetime = 1;
160         if (!isfreeall) {
161                 delta_time = (curr_time - pnetwork->last_scanned)/HZ;
162                 if (delta_time < lifetime)/*  unit:sec */
163                         return;
164         }
165         spin_lock_bh(&free_queue->lock);
166         list_del_init(&(pnetwork->list));
167         list_add_tail(&(pnetwork->list), &(free_queue->queue));
168         spin_unlock_bh(&free_queue->lock);
169 }
170
171 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
172 {
173         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
174
175         if (pnetwork == NULL)
176                 return;
177         if (pnetwork->fixed)
178                 return;
179         list_del_init(&(pnetwork->list));
180         list_add_tail(&(pnetwork->list), get_list_head(free_queue));
181 }
182
183 /*
184         return the wlan_network with the matching addr
185
186         Shall be calle under atomic context... to avoid possible racing condition...
187 */
188 struct wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
189 {
190         struct list_head *phead, *plist;
191         struct  wlan_network *pnetwork = NULL;
192         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
193
194         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
195                 pnetwork = NULL;
196                 goto exit;
197         }
198         phead = get_list_head(scanned_queue);
199         plist = phead->next;
200
201         while (plist != phead) {
202                 pnetwork = container_of(plist, struct wlan_network, list);
203                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
204                         break;
205                 plist = plist->next;
206         }
207         if (plist == phead)
208                 pnetwork = NULL;
209 exit:
210         return pnetwork;
211 }
212
213
214 void rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
215 {
216         struct list_head *phead, *plist;
217         struct wlan_network *pnetwork;
218         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
219         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
220
221         spin_lock_bh(&scanned_queue->lock);
222
223         phead = get_list_head(scanned_queue);
224         plist = phead->next;
225
226         while (phead != plist) {
227                 pnetwork = container_of(plist, struct wlan_network, list);
228
229                 plist = plist->next;
230
231                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
232         }
233         spin_unlock_bh(&scanned_queue->lock);
234 }
235
236 int rtw_if_up(struct adapter *padapter)
237 {
238         int res;
239
240         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
241             (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
242                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
243                          ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)",
244                          padapter->bDriverStopped, padapter->bSurpriseRemoved));
245                 res = false;
246         } else {
247                 res =  true;
248         }
249         return res;
250 }
251
252 void rtw_generate_random_ibss(u8 *pibss)
253 {
254         unsigned long curtime = jiffies;
255
256         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
257         pibss[1] = 0x11;
258         pibss[2] = 0x87;
259         pibss[3] = (u8)(curtime & 0xff);/* p[0]; */
260         pibss[4] = (u8)((curtime>>8) & 0xff);/* p[1]; */
261         pibss[5] = (u8)((curtime>>16) & 0xff);/* p[2]; */
262 }
263
264 u8 *rtw_get_capability_from_ie(u8 *ie)
265 {
266         return ie + 8 + 2;
267 }
268
269
270 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
271 {
272         __le16  val;
273
274         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2);
275
276         return le16_to_cpu(val);
277 }
278
279 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
280 {
281         return ie + 8;
282 }
283
284 static struct wlan_network *rtw_alloc_network(struct mlme_priv *pmlmepriv)
285 {
286         return _rtw_alloc_network(pmlmepriv);
287 }
288
289 static void rtw_free_network_nolock(struct mlme_priv *pmlmepriv,
290                                     struct wlan_network *pnetwork)
291 {
292         _rtw_free_network_nolock(pmlmepriv, pnetwork);
293 }
294
295 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
296 {
297         int ret = true;
298         struct security_priv *psecuritypriv = &adapter->securitypriv;
299
300         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
301             (pnetwork->network.Privacy == 0))
302                 ret = false;
303         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
304                  (pnetwork->network.Privacy == 1))
305                 ret = false;
306         else
307                 ret = true;
308         return ret;
309 }
310
311 static int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
312 {
313         return (a->Ssid.SsidLength == b->Ssid.SsidLength) &&
314                !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
315 }
316
317 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst)
318 {
319          u16 s_cap, d_cap;
320         __le16 le_scap, le_dcap;
321
322         memcpy((u8 *)&le_scap, rtw_get_capability_from_ie(src->IEs), 2);
323         memcpy((u8 *)&le_dcap, rtw_get_capability_from_ie(dst->IEs), 2);
324
325
326         s_cap = le16_to_cpu(le_scap);
327         d_cap = le16_to_cpu(le_dcap);
328
329         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
330                 ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN)) == true) &&
331                 ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength)) == true) &&
332                 ((s_cap & WLAN_CAPABILITY_IBSS) ==
333                 (d_cap & WLAN_CAPABILITY_IBSS)) &&
334                 ((s_cap & WLAN_CAPABILITY_ESS) ==
335                 (d_cap & WLAN_CAPABILITY_ESS)));
336 }
337
338 struct  wlan_network    *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
339 {
340         struct list_head *plist, *phead;
341         struct  wlan_network    *pwlan = NULL;
342         struct  wlan_network    *oldest = NULL;
343
344         phead = get_list_head(scanned_queue);
345
346         for (plist = phead->next; plist != phead; plist = plist->next) {
347                 pwlan = container_of(plist, struct wlan_network, list);
348
349                 if (!pwlan->fixed) {
350                         if (oldest == NULL || time_after(oldest->last_scanned, pwlan->last_scanned))
351                                 oldest = pwlan;
352                 }
353         }
354         return oldest;
355 }
356
357 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
358         struct adapter *padapter, bool update_ie)
359 {
360         long rssi_ori = dst->Rssi;
361         u8 sq_smp = src->PhyInfo.SignalQuality;
362         u8 ss_final;
363         u8 sq_final;
364         long rssi_final;
365
366         rtw_hal_antdiv_rssi_compared(padapter, dst, src); /* this will update src.Rssi, need consider again */
367
368         /* The rule below is 1/5 for sample value, 4/5 for history value */
369         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src)) {
370                 /* Take the recvpriv's value for the connected AP*/
371                 ss_final = padapter->recvpriv.signal_strength;
372                 sq_final = padapter->recvpriv.signal_qual;
373                 /* the rssi value here is undecorated, and will be used for antenna diversity */
374                 if (sq_smp != 101) /* from the right channel */
375                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
376                 else
377                         rssi_final = rssi_ori;
378         } else {
379                 if (sq_smp != 101) { /* from the right channel */
380                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
381                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
382                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
383                 } else {
384                         /* bss info not receiving from the right channel, use the original RX signal infos */
385                         ss_final = dst->PhyInfo.SignalStrength;
386                         sq_final = dst->PhyInfo.SignalQuality;
387                         rssi_final = dst->Rssi;
388                 }
389         }
390         if (update_ie)
391                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
392         dst->PhyInfo.SignalStrength = ss_final;
393         dst->PhyInfo.SignalQuality = sq_final;
394         dst->Rssi = rssi_final;
395
396 }
397
398 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
399 {
400         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
401
402         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) &&
403             (is_same_network(&(pmlmepriv->cur_network.network), pnetwork))) {
404                 update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
405                 rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof(struct ndis_802_11_fixed_ie),
406                                       pmlmepriv->cur_network.network.IELength);
407         }
408 }
409
410 /*
411 Caller must hold pmlmepriv->lock first.
412 */
413 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
414 {
415         struct list_head *plist, *phead;
416         u32     bssid_ex_sz;
417         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
418         struct __queue *queue   = &(pmlmepriv->scanned_queue);
419         struct wlan_network     *pnetwork = NULL;
420         struct wlan_network     *oldest = NULL;
421
422         spin_lock_bh(&queue->lock);
423         phead = get_list_head(queue);
424         plist = phead->next;
425
426         while (phead != plist) {
427                 pnetwork        = container_of(plist, struct wlan_network, list);
428
429                 if (is_same_network(&(pnetwork->network), target))
430                         break;
431                 if ((oldest == ((struct wlan_network *)0)) ||
432                     time_after(oldest->last_scanned, pnetwork->last_scanned))
433                         oldest = pnetwork;
434                 plist = plist->next;
435         }
436         /* If we didn't find a match, then get a new network slot to initialize
437          * with this beacon's information */
438         if (phead == plist) {
439                 if (list_empty(&(pmlmepriv->free_bss_pool.queue))) {
440                         /* If there are no more slots, expire the oldest */
441                         pnetwork = oldest;
442
443                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
444                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
445                         /*  variable initialize */
446                         pnetwork->fixed = false;
447                         pnetwork->last_scanned = jiffies;
448
449                         pnetwork->network_type = 0;
450                         pnetwork->aid = 0;
451                         pnetwork->join_res = 0;
452
453                         /* bss info not receiving from the right channel */
454                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
455                                 pnetwork->network.PhyInfo.SignalQuality = 0;
456                 } else {
457                         /* Otherwise just pull from the free list */
458
459                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
460
461                         if (pnetwork == NULL) {
462                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
463                                 goto exit;
464                         }
465
466                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
467                         target->Length = bssid_ex_sz;
468                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
469                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
470
471                         pnetwork->last_scanned = jiffies;
472
473                         /* bss info not receiving from the right channel */
474                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
475                                 pnetwork->network.PhyInfo.SignalQuality = 0;
476                         list_add_tail(&(pnetwork->list), &(queue->queue));
477                 }
478         } else {
479                 /* we have an entry and we are going to update it. But this entry may
480                  * be already expired. In this case we do the same as we found a new
481                  * net and call the new_net handler
482                  */
483                 bool update_ie = true;
484
485                 pnetwork->last_scanned = jiffies;
486
487                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
488                 if ((pnetwork->network.IELength > target->IELength) && (target->Reserved[0] == 1))
489                         update_ie = false;
490
491                 update_network(&(pnetwork->network), target, adapter, update_ie);
492         }
493
494 exit:
495         spin_unlock_bh(&queue->lock);
496
497 }
498
499 static void rtw_add_network(struct adapter *adapter,
500                             struct wlan_bssid_ex *pnetwork)
501 {
502         update_current_network(adapter, pnetwork);
503         rtw_update_scanned_network(adapter, pnetwork);
504 }
505
506 /*
507  * select the desired network based on the capability of the (i)bss.
508  * check items: (1) security
509  *                      (2) network_type
510  *                      (3) WMM
511  *                      (4) HT
512  *                      (5) others
513  */
514 static int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
515 {
516         struct security_priv *psecuritypriv = &adapter->securitypriv;
517         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
518         u32 desired_encmode;
519         u32 privacy;
520
521         /* u8 wps_ie[512]; */
522         uint wps_ielen;
523
524         int bselected = true;
525
526         desired_encmode = psecuritypriv->ndisencryptstatus;
527         privacy = pnetwork->network.Privacy;
528
529         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
530                 if (rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen) != NULL)
531                         return true;
532                 else
533                         return false;
534         }
535         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
536                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
537                         bselected = false;
538         }
539
540
541         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
542                 DBG_88E("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
543                 bselected = false;
544         }
545
546         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
547                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
548                         bselected = false;
549         }
550
551
552         return bselected;
553 }
554
555 /* TODO: Perry: For Power Management */
556 void rtw_atimdone_event_callback(struct adapter *adapter, u8 *pbuf)
557 {
558         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_evet\n"));
559 }
560
561
562 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
563 {
564         u32 len;
565         struct wlan_bssid_ex *pnetwork;
566         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
567
568         pnetwork = (struct wlan_bssid_ex *)pbuf;
569
570         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid=%s\n",  pnetwork->Ssid.Ssid));
571
572         len = get_wlan_bssid_ex_sz(pnetwork);
573         if (len > (sizeof(struct wlan_bssid_ex))) {
574                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n****rtw_survey_event_callback: return a wrong bss ***\n"));
575                 return;
576         }
577         spin_lock_bh(&pmlmepriv->lock);
578
579         /*  update IBSS_network 's timestamp */
580         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) {
581                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN)) {
582                         struct wlan_network *ibss_wlan = NULL;
583
584                         memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
585                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
586                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
587                         if (ibss_wlan) {
588                                 memcpy(ibss_wlan->network.IEs, pnetwork->IEs, 8);
589                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
590                                 goto exit;
591                         }
592                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
593                 }
594         }
595
596         /*  lock pmlmepriv->lock when you accessing network_q */
597         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false) {
598                 if (pnetwork->Ssid.Ssid[0] == 0)
599                         pnetwork->Ssid.SsidLength = 0;
600                 rtw_add_network(adapter, pnetwork);
601         }
602
603 exit:
604
605         spin_unlock_bh(&pmlmepriv->lock);
606         return;
607 }
608
609 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
610 {
611         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
612
613         spin_lock_bh(&pmlmepriv->lock);
614
615         if (pmlmepriv->wps_probe_req_ie) {
616                 pmlmepriv->wps_probe_req_ie_len = 0;
617                 kfree(pmlmepriv->wps_probe_req_ie);
618                 pmlmepriv->wps_probe_req_ie = NULL;
619         }
620
621         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
622
623         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
624                 del_timer_sync(&pmlmepriv->scan_to_timer);
625                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
626         } else {
627                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status=%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
628         }
629
630         rtw_set_signal_stat_timer(&adapter->recvpriv);
631
632         if (pmlmepriv->to_join) {
633                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
634                         if (check_fwstate(pmlmepriv, _FW_LINKED) == false) {
635                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
636
637                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
638                                         mod_timer(&pmlmepriv->assoc_timer,
639                                                   jiffies + msecs_to_jiffies(MAX_JOIN_TIMEOUT));
640                                 } else {
641                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
642                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
643
644                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
645
646                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
647
648                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
649
650                                         rtw_update_registrypriv_dev_network(adapter);
651                                         rtw_generate_random_ibss(pibss);
652
653                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
654
655                                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
656                                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error=>rtw_createbss_cmd status FAIL\n"));
657                                         pmlmepriv->to_join = false;
658                                 }
659                         }
660                 } else {
661                         int s_ret;
662                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
663                         pmlmepriv->to_join = false;
664                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
665                         if (_SUCCESS == s_ret) {
666                                 mod_timer(&pmlmepriv->assoc_timer,
667                                         jiffies + msecs_to_jiffies(MAX_JOIN_TIMEOUT));
668                         } else if (s_ret == 2) { /* there is no need to wait for join */
669                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
670                                 rtw_indicate_connect(adapter);
671                         } else {
672                                 DBG_88E("try_to_join, but select scanning queue fail, to_roaming:%d\n", pmlmepriv->to_roaming);
673                                 if (pmlmepriv->to_roaming != 0) {
674                                         if (--pmlmepriv->to_roaming == 0 ||
675                                             _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)) {
676                                                 pmlmepriv->to_roaming = 0;
677                                                 rtw_free_assoc_resources(adapter);
678                                                 rtw_indicate_disconnect(adapter);
679                                         } else {
680                                                 pmlmepriv->to_join = true;
681                                         }
682                                 }
683                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
684                         }
685                 }
686         }
687
688         indicate_wx_scan_complete_event(adapter);
689
690         spin_unlock_bh(&pmlmepriv->lock);
691
692         rtw_os_xmit_schedule(adapter);
693 }
694
695 void rtw_dummy_event_callback(struct adapter *adapter, u8 *pbuf)
696 {
697 }
698
699 void rtw_fwdbg_event_callback(struct adapter *adapter, u8 *pbuf)
700 {
701 }
702
703 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
704 {
705         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
706         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
707         struct list_head *plist, *phead, *ptemp;
708
709         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
710         spin_lock_bh(&scan_queue->lock);
711         spin_lock_bh(&free_queue->lock);
712
713         phead = get_list_head(scan_queue);
714         plist = phead->next;
715
716         while (plist != phead) {
717                 ptemp = plist->next;
718                 list_del_init(plist);
719                 list_add_tail(plist, &free_queue->queue);
720                 plist = ptemp;
721         }
722
723         spin_unlock_bh(&free_queue->lock);
724         spin_unlock_bh(&scan_queue->lock);
725 }
726
727 /*
728 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
729 */
730 void rtw_free_assoc_resources(struct adapter *adapter)
731 {
732         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
733
734         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
735         rtw_free_assoc_resources_locked(adapter);
736         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
737 }
738
739 /*
740 *rtw_free_assoc_resources_locked: the caller has to lock pmlmepriv->lock
741 */
742 void rtw_free_assoc_resources_locked(struct adapter *adapter)
743 {
744         struct wlan_network *pwlan = NULL;
745         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
746         struct  sta_priv *pstapriv = &adapter->stapriv;
747         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
748
749         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
750         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
751                  ("tgt_network->network.MacAddress=%pM ssid=%s\n",
752                  tgt_network->network.MacAddress, tgt_network->network.Ssid.Ssid));
753
754         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_AP_STATE)) {
755                 struct sta_info *psta;
756
757                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
758
759                 spin_lock_bh(&(pstapriv->sta_hash_lock));
760                 rtw_free_stainfo(adapter,  psta);
761                 spin_unlock_bh(&pstapriv->sta_hash_lock);
762         }
763
764         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE | WIFI_ADHOC_MASTER_STATE | WIFI_AP_STATE)) {
765                 struct sta_info *psta;
766
767                 rtw_free_all_stainfo(adapter);
768
769                 psta = rtw_get_bcmc_stainfo(adapter);
770                 spin_lock_bh(&(pstapriv->sta_hash_lock));
771                 rtw_free_stainfo(adapter, psta);
772                 spin_unlock_bh(&pstapriv->sta_hash_lock);
773
774                 rtw_init_bcmc_stainfo(adapter);
775         }
776
777
778         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
779         if (pwlan)
780                 pwlan->fixed = false;
781         else
782                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources:pwlan==NULL\n\n"));
783
784         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) && (adapter->stapriv.asoc_sta_count == 1)))
785                 rtw_free_network_nolock(pmlmepriv, pwlan);
786
787         pmlmepriv->key_mask = 0;
788 }
789
790 /*
791 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
792 */
793 void rtw_indicate_connect(struct adapter *padapter)
794 {
795         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
796
797         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
798
799         pmlmepriv->to_join = false;
800
801         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
802                 set_fwstate(pmlmepriv, _FW_LINKED);
803
804                 rtw_led_control(padapter, LED_CTL_LINK);
805
806                 rtw_os_indicate_connect(padapter);
807         }
808
809         pmlmepriv->to_roaming = 0;
810
811         rtw_set_scan_deny(padapter, 3000);
812
813         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state=0x%08x\n", get_fwstate(pmlmepriv)));
814 }
815
816 /*
817 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
818 */
819 void rtw_indicate_disconnect(struct adapter *padapter)
820 {
821         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
822
823         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
824
825         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING | WIFI_UNDER_WPS);
826
827
828         if (pmlmepriv->to_roaming > 0)
829                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
830
831         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) ||
832             (pmlmepriv->to_roaming <= 0)) {
833                 rtw_os_indicate_disconnect(padapter);
834
835                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
836                 rtw_led_control(padapter, LED_CTL_NO_LINK);
837                 rtw_clear_scan_deny(padapter);
838         }
839
840         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
841 }
842
843 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
844 {
845         rtw_os_indicate_scan_done(padapter, aborted);
846 }
847
848 void rtw_scan_abort(struct adapter *adapter)
849 {
850         unsigned long start;
851         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
852         struct mlme_ext_priv    *pmlmeext = &(adapter->mlmeextpriv);
853
854         start = jiffies;
855         pmlmeext->scan_abort = true;
856         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY) &&
857                jiffies_to_msecs(jiffies - start) <= 200) {
858                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
859                         break;
860                 DBG_88E(FUNC_NDEV_FMT"fw_state=_FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
861                 msleep(20);
862         }
863         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
864                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
865                         DBG_88E(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
866                 rtw_indicate_scan_done(adapter, true);
867         }
868         pmlmeext->scan_abort = false;
869 }
870
871 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
872 {
873         int i;
874         struct sta_info *bmc_sta, *psta = NULL;
875         struct recv_reorder_ctrl *preorder_ctrl;
876         struct sta_priv *pstapriv = &padapter->stapriv;
877
878         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
879         if (psta == NULL)
880                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
881
882         if (psta) { /* update ptarget_sta */
883                 DBG_88E("%s\n", __func__);
884                 psta->aid  = pnetwork->join_res;
885                         psta->mac_id = 0;
886                 /* sta mode */
887                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
888                 /* security related */
889                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
890                         padapter->securitypriv.binstallGrpkey = false;
891                         padapter->securitypriv.busetkipkey = false;
892                         padapter->securitypriv.bgrpkey_handshake = false;
893                         psta->ieee8021x_blocked = true;
894                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
895                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
896                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
897                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
898                         memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
899                         memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
900                 }
901                 /*
902                  * Commented by Albert 2012/07/21
903                  * When doing the WPS, the wps_ie_len won't equal to 0
904                  * And the Wi-Fi driver shouldn't allow the data
905                  * packet to be tramsmitted.
906                  */
907                 if (padapter->securitypriv.wps_ie_len != 0) {
908                         psta->ieee8021x_blocked = true;
909                         padapter->securitypriv.wps_ie_len = 0;
910                 }
911                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
912                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
913                 /* todo: check if AP can send A-MPDU packets */
914                 for (i = 0; i < 16; i++) {
915                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
916                         preorder_ctrl = &psta->recvreorder_ctrl[i];
917                         preorder_ctrl->enable = false;
918                         preorder_ctrl->indicate_seq = 0xffff;
919                         preorder_ctrl->wend_b = 0xffff;
920                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
921                 }
922                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
923                 if (bmc_sta) {
924                         for (i = 0; i < 16; i++) {
925                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
926                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
927                                 preorder_ctrl->enable = false;
928                                 preorder_ctrl->indicate_seq = 0xffff;
929                                 preorder_ctrl->wend_b = 0xffff;
930                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
931                         }
932                 }
933                 /* misc. */
934                 update_sta_info(padapter, psta);
935         }
936         return psta;
937 }
938
939 /* pnetwork: returns from rtw_joinbss_event_callback */
940 /* ptarget_wlan: found from scanned_queue */
941 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
942 {
943         struct mlme_priv        *pmlmepriv = &(padapter->mlmepriv);
944         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
945
946         DBG_88E("%s\n", __func__);
947
948         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
949                  ("\nfw_state:%x, BSSID:%pM\n",
950                  get_fwstate(pmlmepriv), pnetwork->network.MacAddress));
951
952
953         /*  why not use ptarget_wlan?? */
954         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
955         /*  some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs */
956         cur_network->network.IELength = ptarget_wlan->network.IELength;
957         memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
958
959         cur_network->aid = pnetwork->join_res;
960
961
962         rtw_set_signal_stat_timer(&padapter->recvpriv);
963         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
964         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
965         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
966         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
967         rtw_set_signal_stat_timer(&padapter->recvpriv);
968
969         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
970         switch (pnetwork->network.InfrastructureMode) {
971         case Ndis802_11Infrastructure:
972                 if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
973                         pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
974                 else
975                         pmlmepriv->fw_state = WIFI_STATION_STATE;
976                 break;
977         case Ndis802_11IBSS:
978                 pmlmepriv->fw_state = WIFI_ADHOC_STATE;
979                 break;
980         default:
981                 pmlmepriv->fw_state = WIFI_NULL_STATE;
982                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
983                 break;
984         }
985
986         rtw_update_protection(padapter, (cur_network->network.IEs) +
987                               sizeof(struct ndis_802_11_fixed_ie),
988                               (cur_network->network.IELength));
989         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength);
990 }
991
992 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
993 /* pnetwork: returns from rtw_joinbss_event_callback */
994 /* ptarget_wlan: found from scanned_queue */
995 /* if join_res > 0, for (fw_state == WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
996 /* if join_res > 0, for (fw_state == WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
997 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
998
999 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
1000 {
1001         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
1002         struct  sta_priv *pstapriv = &adapter->stapriv;
1003         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
1004         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1005         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1006         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1007         unsigned int            the_same_macaddr = false;
1008
1009         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res=%d\n", pnetwork->join_res));
1010
1011         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1012
1013
1014         if (pmlmepriv->assoc_ssid.SsidLength == 0)
1015                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
1016         else
1017                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
1018
1019         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1020
1021         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1022         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
1023                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1024                 return;
1025         }
1026
1027         spin_lock_bh(&pmlmepriv->lock);
1028
1029         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nrtw_joinbss_event_callback!! _enter_critical\n"));
1030
1031         if (pnetwork->join_res > 0) {
1032                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1033                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1034                         /* s1. find ptarget_wlan */
1035                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1036                                 if (the_same_macaddr) {
1037                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1038                                 } else {
1039                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1040                                         if (pcur_wlan)
1041                                                 pcur_wlan->fixed = false;
1042
1043                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1044                                         if (pcur_sta) {
1045                                                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1046                                                 rtw_free_stainfo(adapter,  pcur_sta);
1047                                                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1048                                         }
1049
1050                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1051                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1052                                                 if (ptarget_wlan)
1053                                                         ptarget_wlan->fixed = true;
1054                                         }
1055                                 }
1056                         } else {
1057                                 ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1058                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1059                                         if (ptarget_wlan)
1060                                                 ptarget_wlan->fixed = true;
1061                                 }
1062                         }
1063
1064                         /* s2. update cur_network */
1065                         if (ptarget_wlan) {
1066                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1067                         } else {
1068                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't find ptarget_wlan when joinbss_event callback\n"));
1069                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1070                                 goto ignore_joinbss_callback;
1071                         }
1072
1073
1074                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1075                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1076                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1077                                 if (ptarget_sta == NULL) {
1078                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1079                                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1080                                         goto ignore_joinbss_callback;
1081                                 }
1082                         }
1083
1084                         /* s4. indicate connect */
1085                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1086                                         rtw_indicate_connect(adapter);
1087                                 } else {
1088                                         /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1089                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1090                                 }
1091
1092                         /* s5. Cancle assoc_timer */
1093                         del_timer_sync(&pmlmepriv->assoc_timer);
1094
1095                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancle assoc_timer\n"));
1096
1097                 } else {
1098                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1099                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1100                         goto ignore_joinbss_callback;
1101                 }
1102
1103                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1104
1105         } else if (pnetwork->join_res == -4) {
1106                 rtw_reset_securitypriv(adapter);
1107                 mod_timer(&pmlmepriv->assoc_timer,
1108                           jiffies + msecs_to_jiffies(1));
1109
1110                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true) {
1111                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state=%x\n", get_fwstate(pmlmepriv)));
1112                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1113                 }
1114         } else { /* if join_res < 0 (join fails), then try again */
1115                 mod_timer(&pmlmepriv->assoc_timer,
1116                           jiffies + msecs_to_jiffies(1));
1117                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1118         }
1119
1120 ignore_joinbss_callback:
1121         spin_unlock_bh(&pmlmepriv->lock);
1122 }
1123
1124 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1125 {
1126         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1127
1128         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1129
1130         rtw_os_xmit_schedule(adapter);
1131 }
1132
1133 static u8 search_max_mac_id(struct adapter *padapter)
1134 {
1135         u8 mac_id;
1136 #if defined(CONFIG_88EU_AP_MODE)
1137         u8 aid;
1138         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1139         struct sta_priv *pstapriv = &padapter->stapriv;
1140 #endif
1141         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
1142         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
1143
1144 #if defined(CONFIG_88EU_AP_MODE)
1145         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1146                 for (aid = (pstapriv->max_num_sta); aid > 0; aid--) {
1147                         if (pstapriv->sta_aid[aid-1] != NULL)
1148                                 break;
1149                 }
1150                 mac_id = aid + 1;
1151         } else
1152 #endif
1153         {/* adhoc  id =  31~2 */
1154                 for (mac_id = (NUM_STA-1); mac_id >= IBSS_START_MAC_ID; mac_id--) {
1155                         if (pmlmeinfo->FW_sta_info[mac_id].status == 1)
1156                                 break;
1157                 }
1158         }
1159         return mac_id;
1160 }
1161
1162 /* FOR AP , AD-HOC mode */
1163 void rtw_stassoc_hw_rpt(struct adapter *adapter, struct sta_info *psta)
1164 {
1165         u16 media_status;
1166         u8 macid;
1167
1168         if (psta == NULL)
1169                 return;
1170
1171         macid = search_max_mac_id(adapter);
1172         rtw_hal_set_hwreg(adapter, HW_VAR_TX_RPT_MAX_MACID, (u8 *)&macid);
1173         media_status = (psta->mac_id<<8)|1; /*   MACID|OPMODE:1 connect */
1174         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1175 }
1176
1177 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1178 {
1179         struct sta_info *psta;
1180         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1181         struct stassoc_event    *pstassoc = (struct stassoc_event *)pbuf;
1182         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1183         struct wlan_network     *ptarget_wlan = NULL;
1184
1185         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1186                 return;
1187
1188 #if defined(CONFIG_88EU_AP_MODE)
1189         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1190                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1191                 if (psta) {
1192                         ap_sta_info_defer_update(adapter, psta);
1193                         rtw_stassoc_hw_rpt(adapter, psta);
1194                 }
1195                 return;
1196         }
1197 #endif
1198         /* for AD-HOC mode */
1199         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1200         if (psta != NULL) {
1201                 /* the sta have been in sta_info_queue => do nothing */
1202                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1203                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1204         }
1205         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1206         if (psta == NULL) {
1207                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1208                 return;
1209         }
1210         /* to do: init sta_info variable */
1211         psta->qos_option = 0;
1212         psta->mac_id = (uint)pstassoc->cam_id;
1213         DBG_88E("%s\n", __func__);
1214         /* for ad-hoc mode */
1215         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1216         rtw_stassoc_hw_rpt(adapter, psta);
1217         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1218                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1219         psta->ieee8021x_blocked = false;
1220         spin_lock_bh(&pmlmepriv->lock);
1221         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
1222             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE))) {
1223                 if (adapter->stapriv.asoc_sta_count == 2) {
1224                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1225                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1226                         if (ptarget_wlan)
1227                                 ptarget_wlan->fixed = true;
1228                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1229                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1230                         rtw_indicate_connect(adapter);
1231                 }
1232         }
1233         spin_unlock_bh(&pmlmepriv->lock);
1234         mlmeext_sta_add_event_callback(adapter, psta);
1235 }
1236
1237 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1238 {
1239         int mac_id = -1;
1240         struct sta_info *psta;
1241         struct wlan_network *pwlan = NULL;
1242         struct wlan_bssid_ex *pdev_network = NULL;
1243         u8 *pibss = NULL;
1244         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1245         struct  stadel_event *pstadel = (struct stadel_event *)pbuf;
1246         struct  sta_priv *pstapriv = &adapter->stapriv;
1247         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1248
1249         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1250         if (psta)
1251                 mac_id = psta->mac_id;
1252         else
1253                 mac_id = pstadel->mac_id;
1254
1255         DBG_88E("%s(mac_id=%d)=%pM\n", __func__, mac_id, pstadel->macaddr);
1256
1257         if (mac_id >= 0) {
1258                 u16 media_status;
1259                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1260                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1261                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1262         }
1263
1264         if (check_fwstate(pmlmepriv, WIFI_AP_STATE))
1265                 return;
1266
1267         mlmeext_sta_del_event_callback(adapter);
1268
1269         spin_lock_bh(&pmlmepriv->lock);
1270
1271         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1272                 if (pmlmepriv->to_roaming > 0)
1273                         pmlmepriv->to_roaming--; /*  this stadel_event is caused by roaming, decrease to_roaming */
1274                 else if (pmlmepriv->to_roaming == 0)
1275                         pmlmepriv->to_roaming = adapter->registrypriv.max_roaming_times;
1276
1277                 if (*((unsigned short *)(pstadel->rsvd)) != WLAN_REASON_EXPIRATION_CHK)
1278                         pmlmepriv->to_roaming = 0; /*  don't roam */
1279
1280                 rtw_free_uc_swdec_pending_queue(adapter);
1281
1282                 rtw_free_assoc_resources(adapter);
1283                 rtw_indicate_disconnect(adapter);
1284                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1285                 /*  remove the network entry in scanned_queue */
1286                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1287                 if (pwlan) {
1288                         pwlan->fixed = false;
1289                         rtw_free_network_nolock(pmlmepriv, pwlan);
1290                 }
1291                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1292                 _rtw_roaming(adapter, tgt_network);
1293         }
1294         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1295             check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1296                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1297                 rtw_free_stainfo(adapter,  psta);
1298                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1299
1300                 if (adapter->stapriv.asoc_sta_count == 1) { /* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1301                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1302                         /* free old ibss network */
1303                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1304                         if (pwlan) {
1305                                 pwlan->fixed = false;
1306                                 rtw_free_network_nolock(pmlmepriv, pwlan);
1307                         }
1308                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1309                         /* re-create ibss */
1310                         pdev_network = &(adapter->registrypriv.dev_network);
1311                         pibss = adapter->registrypriv.dev_network.MacAddress;
1312
1313                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1314
1315                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1316
1317                         rtw_update_registrypriv_dev_network(adapter);
1318
1319                         rtw_generate_random_ibss(pibss);
1320
1321                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1322                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1323                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1324                         }
1325
1326                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
1327                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error=>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1328                 }
1329         }
1330         spin_unlock_bh(&pmlmepriv->lock);
1331 }
1332
1333 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1334 {
1335         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1336 }
1337
1338 /*
1339 * _rtw_join_timeout_handler - Timeout/faliure handler for CMD JoinBss
1340 * @adapter: pointer to struct adapter structure
1341 */
1342 void _rtw_join_timeout_handler (unsigned long data)
1343 {
1344         struct adapter *adapter = (struct adapter *)data;
1345         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1346         int do_join_r;
1347
1348         DBG_88E("%s, fw_state=%x\n", __func__, get_fwstate(pmlmepriv));
1349
1350         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1351                 return;
1352
1353
1354         spin_lock_bh(&pmlmepriv->lock);
1355
1356         if (pmlmepriv->to_roaming > 0) { /*  join timeout caused by roaming */
1357                 while (1) {
1358                         pmlmepriv->to_roaming--;
1359                         if (pmlmepriv->to_roaming != 0) { /* try another , */
1360                                 DBG_88E("%s try another roaming\n", __func__);
1361                                 do_join_r = rtw_do_join(adapter);
1362                                 if (_SUCCESS != do_join_r) {
1363                                         DBG_88E("%s roaming do_join return %d\n", __func__, do_join_r);
1364                                         continue;
1365                                 }
1366                                 break;
1367                         } else {
1368                                 DBG_88E("%s We've try roaming but fail\n", __func__);
1369                                 rtw_indicate_disconnect(adapter);
1370                                 break;
1371                         }
1372                 }
1373         } else {
1374                 rtw_indicate_disconnect(adapter);
1375                 free_scanqueue(pmlmepriv);/*  */
1376         }
1377         spin_unlock_bh(&pmlmepriv->lock);
1378 }
1379
1380 /*
1381 * rtw_scan_timeout_handler - Timeout/Faliure handler for CMD SiteSurvey
1382 * @adapter: pointer to struct adapter structure
1383 */
1384 void rtw_scan_timeout_handler (unsigned long data)
1385 {
1386         struct adapter *adapter = (struct adapter *)data;
1387         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1388
1389         DBG_88E(FUNC_ADPT_FMT" fw_state=%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1390         spin_lock_bh(&pmlmepriv->lock);
1391         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1392         spin_unlock_bh(&pmlmepriv->lock);
1393         rtw_indicate_scan_done(adapter, true);
1394 }
1395
1396 static void rtw_auto_scan_handler(struct adapter *padapter)
1397 {
1398         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1399
1400         /* auto site survey per 60sec */
1401         if (pmlmepriv->scan_interval > 0) {
1402                 pmlmepriv->scan_interval--;
1403                 if (pmlmepriv->scan_interval == 0) {
1404                         DBG_88E("%s\n", __func__);
1405                         rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1406                         pmlmepriv->scan_interval = SCAN_INTERVAL;/*  30*2 sec = 60sec */
1407                 }
1408         }
1409 }
1410
1411 void rtw_dynamic_check_timer_handlder(unsigned long data)
1412 {
1413         struct adapter *adapter = (struct adapter *)data;
1414         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1415
1416         if (!adapter)
1417                 return;
1418         if (!adapter->hw_init_completed)
1419                 goto exit;
1420         if ((adapter->bDriverStopped) || (adapter->bSurpriseRemoved))
1421                 goto exit;
1422         if (adapter->net_closed)
1423                 goto exit;
1424         rtw_dynamic_chk_wk_cmd(adapter);
1425
1426         if (pregistrypriv->wifi_spec == 1) {
1427                 /* auto site survey */
1428                 rtw_auto_scan_handler(adapter);
1429         }
1430 exit:
1431         mod_timer(&adapter->mlmepriv.dynamic_chk_timer,
1432                   jiffies + msecs_to_jiffies(2000));
1433 }
1434
1435 #define RTW_SCAN_RESULT_EXPIRE 2000
1436
1437 /*
1438 * Select a new join candidate from the original @param candidate and @param competitor
1439 * @return true: candidate is updated
1440 * @return false: candidate is not updated
1441 */
1442 static int rtw_check_join_candidate(struct mlme_priv *pmlmepriv
1443         , struct wlan_network **candidate, struct wlan_network *competitor)
1444 {
1445         int updated = false;
1446         unsigned long since_scan;
1447         struct adapter *adapter = container_of(pmlmepriv, struct adapter, mlmepriv);
1448
1449
1450         /* check bssid, if needed */
1451         if (pmlmepriv->assoc_by_bssid) {
1452                 if (memcmp(competitor->network.MacAddress, pmlmepriv->assoc_bssid, ETH_ALEN))
1453                         goto exit;
1454         }
1455
1456         /* check ssid, if needed */
1457         if (pmlmepriv->assoc_ssid.SsidLength) {
1458                 if (competitor->network.Ssid.SsidLength != pmlmepriv->assoc_ssid.SsidLength ||
1459                     !memcmp(competitor->network.Ssid.Ssid, pmlmepriv->assoc_ssid.Ssid, pmlmepriv->assoc_ssid.SsidLength) == false)
1460                         goto exit;
1461         }
1462
1463         if (rtw_is_desired_network(adapter, competitor)  == false)
1464                 goto exit;
1465
1466         if (pmlmepriv->to_roaming) {
1467                 since_scan = jiffies - competitor->last_scanned;
1468                 if (jiffies_to_msecs(since_scan) >= RTW_SCAN_RESULT_EXPIRE ||
1469                     is_same_ess(&competitor->network, &pmlmepriv->cur_network.network) == false)
1470                         goto exit;
1471         }
1472
1473         if (*candidate == NULL || (*candidate)->network.Rssi < competitor->network.Rssi) {
1474                 *candidate = competitor;
1475                 updated = true;
1476         }
1477         if (updated) {
1478                 DBG_88E("[by_bssid:%u][assoc_ssid:%s]new candidate: %s(%pM rssi:%d\n",
1479                         pmlmepriv->assoc_by_bssid,
1480                         pmlmepriv->assoc_ssid.Ssid,
1481                         (*candidate)->network.Ssid.Ssid,
1482                         (*candidate)->network.MacAddress,
1483                         (int)(*candidate)->network.Rssi);
1484                 DBG_88E("[to_roaming:%u]\n", pmlmepriv->to_roaming);
1485         }
1486
1487 exit:
1488         return updated;
1489 }
1490
1491 /*
1492 Calling context:
1493 The caller of the sub-routine will be in critical section...
1494 The caller must hold the following spinlock
1495 pmlmepriv->lock
1496 */
1497
1498 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
1499 {
1500         int ret;
1501         struct list_head *phead;
1502         struct adapter *adapter;
1503         struct __queue *queue   = &(pmlmepriv->scanned_queue);
1504         struct  wlan_network    *pnetwork = NULL;
1505         struct  wlan_network    *candidate = NULL;
1506         u8      supp_ant_div = false;
1507
1508         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1509         phead = get_list_head(queue);
1510         adapter = (struct adapter *)pmlmepriv->nic_hdl;
1511         pmlmepriv->pscanned = phead->next;
1512         while (phead != pmlmepriv->pscanned) {
1513                 pnetwork = container_of(pmlmepriv->pscanned, struct wlan_network, list);
1514                 if (pnetwork == NULL) {
1515                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork==NULL)\n", __func__));
1516                         ret = _FAIL;
1517                         goto exit;
1518                 }
1519                 pmlmepriv->pscanned = pmlmepriv->pscanned->next;
1520                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
1521         }
1522         if (candidate == NULL) {
1523                 DBG_88E("%s: return _FAIL(candidate==NULL)\n", __func__);
1524                 ret = _FAIL;
1525                 goto exit;
1526         } else {
1527                 DBG_88E("%s: candidate: %s(%pM ch:%u)\n", __func__,
1528                         candidate->network.Ssid.Ssid, candidate->network.MacAddress,
1529                         candidate->network.Configuration.DSConfig);
1530         }
1531
1532
1533         /*  check for situation of  _FW_LINKED */
1534         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
1535                 DBG_88E("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
1536
1537                 rtw_disassoc_cmd(adapter, 0, true);
1538                 rtw_indicate_disconnect(adapter);
1539                 rtw_free_assoc_resources_locked(adapter);
1540         }
1541
1542         rtw_hal_get_def_var(adapter, HAL_DEF_IS_SUPPORT_ANT_DIV, &(supp_ant_div));
1543         if (supp_ant_div) {
1544                 u8 cur_ant;
1545                 rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(cur_ant));
1546                 DBG_88E("#### Opt_Ant_(%s), cur_Ant(%s)\n",
1547                         (2 == candidate->network.PhyInfo.Optimum_antenna) ? "A" : "B",
1548                         (2 == cur_ant) ? "A" : "B"
1549                 );
1550         }
1551
1552         ret = rtw_joinbss_cmd(adapter, candidate);
1553
1554 exit:
1555         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1556         return ret;
1557 }
1558
1559 int rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
1560 {
1561         struct  cmd_obj *pcmd;
1562         struct  setauth_parm *psetauthparm;
1563         struct  cmd_priv *pcmdpriv = &(adapter->cmdpriv);
1564         int             res = _SUCCESS;
1565
1566         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
1567         if (!pcmd) {
1568                 res = _FAIL;  /* try again */
1569                 goto exit;
1570         }
1571
1572         psetauthparm = kzalloc(sizeof(struct setauth_parm), GFP_KERNEL);
1573         if (!psetauthparm) {
1574                 kfree(pcmd);
1575                 res = _FAIL;
1576                 goto exit;
1577         }
1578         memset(psetauthparm, 0, sizeof(struct setauth_parm));
1579         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
1580         pcmd->cmdcode = _SetAuth_CMD_;
1581         pcmd->parmbuf = (unsigned char *)psetauthparm;
1582         pcmd->cmdsz =  (sizeof(struct setauth_parm));
1583         pcmd->rsp = NULL;
1584         pcmd->rspsz = 0;
1585         INIT_LIST_HEAD(&pcmd->list);
1586         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1587                  ("after enqueue set_auth_cmd, auth_mode=%x\n",
1588                  psecuritypriv->dot11AuthAlgrthm));
1589         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1590 exit:
1591         return res;
1592 }
1593
1594 int rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, int keyid, u8 set_tx)
1595 {
1596         u8      keylen;
1597         struct cmd_obj          *pcmd;
1598         struct setkey_parm      *psetkeyparm;
1599         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
1600         struct mlme_priv                *pmlmepriv = &(adapter->mlmepriv);
1601         int     res = _SUCCESS;
1602
1603         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
1604         if (!pcmd)
1605                 return _FAIL;  /* try again */
1606
1607         psetkeyparm = kzalloc(sizeof(struct setkey_parm), GFP_KERNEL);
1608         if (!psetkeyparm) {
1609                 res = _FAIL;
1610                 goto err_free_cmd;
1611         }
1612
1613         memset(psetkeyparm, 0, sizeof(struct setkey_parm));
1614
1615         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1616                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
1617                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1618                          ("\n rtw_set_key: psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy=%d\n",
1619                          psetkeyparm->algorithm));
1620         } else {
1621                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
1622                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1623                          ("\n rtw_set_key: psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm=%d\n",
1624                          psetkeyparm->algorithm));
1625         }
1626         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
1627         psetkeyparm->set_tx = set_tx;
1628         pmlmepriv->key_mask |= BIT(psetkeyparm->keyid);
1629         DBG_88E("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n",
1630                 psetkeyparm->algorithm, psetkeyparm->keyid, pmlmepriv->key_mask);
1631         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1632                  ("\n rtw_set_key: psetkeyparm->algorithm=%d psetkeyparm->keyid=(u8)keyid=%d\n",
1633                  psetkeyparm->algorithm, keyid));
1634
1635         switch (psetkeyparm->algorithm) {
1636         case _WEP40_:
1637                 keylen = 5;
1638                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1639                 break;
1640         case _WEP104_:
1641                 keylen = 13;
1642                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1643                 break;
1644         case _TKIP_:
1645                 keylen = 16;
1646                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1647                 psetkeyparm->grpkey = 1;
1648                 break;
1649         case _AES_:
1650                 keylen = 16;
1651                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1652                 psetkeyparm->grpkey = 1;
1653                 break;
1654         default:
1655                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1656                          ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm=%x (must be 1 or 2 or 4 or 5)\n",
1657                          psecuritypriv->dot11PrivacyAlgrthm));
1658                 res = _FAIL;
1659                 goto err_free_parm;
1660         }
1661         pcmd->cmdcode = _SetKey_CMD_;
1662         pcmd->parmbuf = (u8 *)psetkeyparm;
1663         pcmd->cmdsz =  (sizeof(struct setkey_parm));
1664         pcmd->rsp = NULL;
1665         pcmd->rspsz = 0;
1666         INIT_LIST_HEAD(&pcmd->list);
1667         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1668         return res;
1669
1670 err_free_parm:
1671         kfree(psetkeyparm);
1672 err_free_cmd:
1673         kfree(pcmd);
1674         return res;
1675 }
1676
1677 /* adjust IEs for rtw_joinbss_cmd in WMM */
1678 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
1679 {
1680         unsigned        int ielength = 0;
1681         unsigned int i, j;
1682
1683         /* i = 12; after the fixed IE */
1684         for (i = 12; i < in_len; i += (in_ie[i + 1] + 2) /* to the next IE element */) {
1685                 ielength = initial_out_len;
1686
1687                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) {
1688                         /* WMM element ID and OUI */
1689                         /* Append WMM IE to the last index of out_ie */
1690
1691                         for (j = i; j < i + 9; j++) {
1692                                 out_ie[ielength] = in_ie[j];
1693                                 ielength++;
1694                         }
1695                         out_ie[initial_out_len + 1] = 0x07;
1696                         out_ie[initial_out_len + 6] = 0x00;
1697                         out_ie[initial_out_len + 8] = 0x00;
1698                         break;
1699                 }
1700         }
1701         return ielength;
1702 }
1703
1704 /*
1705  * Ported from 8185: IsInPreAuthKeyList().
1706  * (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.)
1707  * Added by Annie, 2006-05-07.
1708  * Search by BSSID,
1709  * Return Value:
1710  *              -1      :if there is no pre-auth key in the table
1711  *              >= 0    :if there is pre-auth key, and return the entry id
1712  */
1713 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
1714 {
1715         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1716         int i = 0;
1717
1718         do {
1719                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
1720                     (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN))) {
1721                         break;
1722                 } else {
1723                         i++;
1724                         /* continue; */
1725                 }
1726
1727         } while (i < NUM_PMKID_CACHE);
1728
1729         if (i == NUM_PMKID_CACHE)
1730                 i = -1;/*  Could not find. */
1731
1732         return i;
1733 }
1734
1735 /*  */
1736 /*  Check the RSN IE length */
1737 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
1738 /*  0-11th element in the array are the fixed IE */
1739 /*  12th element in the array is the IE */
1740 /*  13th element in the array is the IE length */
1741 /*  */
1742
1743 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
1744 {
1745         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1746
1747         if (ie[13] <= 20) {
1748                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
1749                 ie[ie_len] = 1;
1750                 ie_len++;
1751                 ie[ie_len] = 0; /* PMKID count = 0x0100 */
1752                 ie_len++;
1753                 memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
1754
1755                 ie_len += 16;
1756                 ie[13] += 18;/* PMKID length = 2+16 */
1757         }
1758         return ie_len;
1759 }
1760
1761 int rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
1762 {
1763         u8 authmode;
1764         uint    ielength;
1765         int iEntry;
1766
1767         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1768         struct security_priv *psecuritypriv = &adapter->securitypriv;
1769         uint    ndisauthmode = psecuritypriv->ndisauthtype;
1770         uint ndissecuritytype = psecuritypriv->ndisencryptstatus;
1771
1772         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
1773                  ("+rtw_restruct_sec_ie: ndisauthmode=%d ndissecuritytype=%d\n",
1774                   ndisauthmode, ndissecuritytype));
1775
1776         /* copy fixed ie only */
1777         memcpy(out_ie, in_ie, 12);
1778         ielength = 12;
1779         if ((ndisauthmode == Ndis802_11AuthModeWPA) ||
1780             (ndisauthmode == Ndis802_11AuthModeWPAPSK))
1781                         authmode = _WPA_IE_ID_;
1782         if ((ndisauthmode == Ndis802_11AuthModeWPA2) ||
1783             (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
1784                 authmode = _WPA2_IE_ID_;
1785
1786         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
1787                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
1788
1789                 ielength += psecuritypriv->wps_ie_len;
1790         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
1791                 /* copy RSN or SSN */
1792                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
1793                 ielength += psecuritypriv->supplicant_ie[1]+2;
1794                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
1795         }
1796
1797         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
1798         if (iEntry < 0) {
1799                 return ielength;
1800         } else {
1801                 if (authmode == _WPA2_IE_ID_)
1802                         ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
1803         }
1804         return ielength;
1805 }
1806
1807 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
1808 {
1809         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1810         struct eeprom_priv *peepriv = &adapter->eeprompriv;
1811         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
1812         u8 *myhwaddr = myid(peepriv);
1813
1814         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
1815
1816         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
1817
1818         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_config);
1819         pdev_network->Configuration.BeaconPeriod = 100;
1820         pdev_network->Configuration.FHConfig.Length = 0;
1821         pdev_network->Configuration.FHConfig.HopPattern = 0;
1822         pdev_network->Configuration.FHConfig.HopSet = 0;
1823         pdev_network->Configuration.FHConfig.DwellTime = 0;
1824 }
1825
1826 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
1827 {
1828         int sz = 0;
1829         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1830         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
1831         struct  security_priv *psecuritypriv = &adapter->securitypriv;
1832         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
1833
1834         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0); /*  adhoc no 802.1x */
1835
1836         pdev_network->Rssi = 0;
1837
1838         switch (pregistrypriv->wireless_mode) {
1839         case WIRELESS_11B:
1840                 pdev_network->NetworkTypeInUse = (Ndis802_11DS);
1841                 break;
1842         case WIRELESS_11G:
1843         case WIRELESS_11BG:
1844         case WIRELESS_11_24N:
1845         case WIRELESS_11G_24N:
1846         case WIRELESS_11BG_24N:
1847                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
1848                 break;
1849         case WIRELESS_11A:
1850         case WIRELESS_11A_5N:
1851                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
1852                 break;
1853         case WIRELESS_11ABGN:
1854                 if (pregistrypriv->channel > 14)
1855                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
1856                 else
1857                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
1858                 break;
1859         default:
1860                 /*  TODO */
1861                 break;
1862         }
1863
1864         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
1865         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
1866                  ("pregistrypriv->channel=%d, pdev_network->Configuration.DSConfig=0x%x\n",
1867                  pregistrypriv->channel, pdev_network->Configuration.DSConfig));
1868
1869         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
1870                 pdev_network->Configuration.ATIMWindow = (0);
1871
1872         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
1873
1874         /*  1. Supported rates */
1875         /*  2. IE */
1876
1877         sz = rtw_generate_ie(pregistrypriv);
1878         pdev_network->IELength = sz;
1879         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
1880
1881         /* notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd(); */
1882         /* pdev_network->IELength = cpu_to_le32(sz); */
1883 }
1884
1885 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
1886 {
1887 }
1888
1889 /* the function is at passive_level */
1890 void rtw_joinbss_reset(struct adapter *padapter)
1891 {
1892         u8      threshold;
1893         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1894         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
1895
1896         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
1897         pmlmepriv->num_FortyMHzIntolerant = 0;
1898
1899         pmlmepriv->num_sta_no_ht = 0;
1900
1901         phtpriv->ampdu_enable = false;/* reset to disabled */
1902
1903         /*  TH = 1 => means that invalidate usb rx aggregation */
1904         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
1905         if (phtpriv->ht_option) {
1906                 if (padapter->registrypriv.wifi_spec == 1)
1907                         threshold = 1;
1908                 else
1909                         threshold = 0;
1910                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
1911         } else {
1912                 threshold = 1;
1913                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
1914         }
1915 }
1916
1917 /* the function is >= passive_level */
1918 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len)
1919 {
1920         u32 ielen, out_len;
1921         enum ht_cap_ampdu_factor max_rx_ampdu_factor;
1922         unsigned char *p;
1923         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
1924         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1925         struct qos_priv         *pqospriv = &pmlmepriv->qospriv;
1926         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
1927         u32 rx_packet_offset, max_recvbuf_sz;
1928
1929
1930         phtpriv->ht_option = false;
1931
1932         p = rtw_get_ie(in_ie+12, _HT_CAPABILITY_IE_, &ielen, in_len-12);
1933
1934         if (p && ielen > 0) {
1935                 struct ieee80211_ht_cap ht_cap;
1936
1937                 if (pqospriv->qos_option == 0) {
1938                         out_len = *pout_len;
1939                         rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_,
1940                                    _WMM_IE_Length_, WMM_IE, pout_len);
1941
1942                         pqospriv->qos_option = 1;
1943                 }
1944
1945                 out_len = *pout_len;
1946
1947                 memset(&ht_cap, 0, sizeof(struct ieee80211_ht_cap));
1948
1949                 ht_cap.cap_info = cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH |
1950                                               IEEE80211_HT_CAP_SGI_20 |
1951                                               IEEE80211_HT_CAP_SGI_40 |
1952                                               IEEE80211_HT_CAP_TX_STBC |
1953                                               IEEE80211_HT_CAP_DSSSCCK40);
1954
1955                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
1956                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
1957
1958                 /*
1959                 ampdu_params_info [1:0]:Max AMPDU Len => 0:8k , 1:16k, 2:32k, 3:64k
1960                 ampdu_params_info [4:2]:Min MPDU Start Spacing
1961                 */
1962
1963                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor);
1964                 ht_cap.ampdu_params_info = max_rx_ampdu_factor & 0x03;
1965
1966                 if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
1967                         ht_cap.ampdu_params_info |= IEEE80211_HT_CAP_AMPDU_DENSITY & (0x07 << 2);
1968                 else
1969                         ht_cap.ampdu_params_info |= IEEE80211_HT_CAP_AMPDU_DENSITY & 0x00;
1970
1971                 rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
1972                            sizeof(struct ieee80211_ht_cap),
1973                            (unsigned char *)&ht_cap, pout_len);
1974
1975                 phtpriv->ht_option = true;
1976
1977                 p = rtw_get_ie(in_ie+12, _HT_ADD_INFO_IE_, &ielen, in_len-12);
1978                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
1979                         out_len = *pout_len;
1980                         rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2, pout_len);
1981                 }
1982         }
1983         return phtpriv->ht_option;
1984 }
1985
1986 /* the function is > passive_level (in critical_section) */
1987 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len)
1988 {
1989         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1990         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
1991         struct registry_priv *pregistrypriv = &padapter->registrypriv;
1992         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
1993         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
1994
1995         if (!phtpriv->ht_option)
1996                 return;
1997
1998         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
1999                 return;
2000
2001         DBG_88E("+rtw_update_ht_cap()\n");
2002
2003         /* maybe needs check if ap supports rx ampdu. */
2004         if ((!phtpriv->ampdu_enable) && (pregistrypriv->ampdu_enable == 1)) {
2005                 if (pregistrypriv->wifi_spec == 1)
2006                         phtpriv->ampdu_enable = false;
2007                 else
2008                         phtpriv->ampdu_enable = true;
2009         } else if (pregistrypriv->ampdu_enable == 2) {
2010                 phtpriv->ampdu_enable = true;
2011         }
2012
2013         /* update cur_bwmode & cur_ch_offset */
2014         if ((pregistrypriv->cbw40_enable) &&
2015             (le16_to_cpu(pmlmeinfo->HT_caps.cap_info) & BIT(1)) &&
2016             (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
2017                 int i;
2018                 u8      rf_type;
2019
2020                 rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2021
2022                 /* update the MCS rates */
2023                 for (i = 0; i < 16; i++) {
2024                         if ((rf_type == RF_1T1R) || (rf_type == RF_1T2R))
2025                                 ((u8 *)&pmlmeinfo->HT_caps.mcs)[i] &= MCS_rate_1R[i];
2026                         else
2027                                 ((u8 *)&pmlmeinfo->HT_caps.mcs)[i] &= MCS_rate_2R[i];
2028                 }
2029                 /* switch to the 40M Hz mode according to the AP */
2030                 pmlmeext->cur_bwmode = HT_CHANNEL_WIDTH_40;
2031                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
2032                 case HT_EXTCHNL_OFFSET_UPPER:
2033                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
2034                         break;
2035                 case HT_EXTCHNL_OFFSET_LOWER:
2036                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
2037                         break;
2038                 default:
2039                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
2040                         break;
2041                 }
2042         }
2043
2044         /*  Config SM Power Save setting */
2045         pmlmeinfo->SM_PS = (le16_to_cpu(pmlmeinfo->HT_caps.cap_info) & 0x0C) >> 2;
2046         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
2047                 DBG_88E("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
2048
2049         /*  Config current HT Protection mode. */
2050         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
2051 }
2052
2053 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
2054 {
2055         u8 issued;
2056         int priority;
2057         struct sta_info *psta = NULL;
2058         struct ht_priv  *phtpriv;
2059         struct pkt_attrib *pattrib = &pxmitframe->attrib;
2060         s32 bmcst = IS_MCAST(pattrib->ra);
2061
2062         if (bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100))
2063                 return;
2064
2065         priority = pattrib->priority;
2066
2067         if (pattrib->psta)
2068                 psta = pattrib->psta;
2069         else
2070                 psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
2071
2072         if (psta == NULL)
2073                 return;
2074
2075         phtpriv = &psta->htpriv;
2076
2077         if ((phtpriv->ht_option) && (phtpriv->ampdu_enable)) {
2078                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
2079                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
2080
2081                 if (0 == issued) {
2082                         DBG_88E("rtw_issue_addbareq_cmd, p=%d\n", priority);
2083                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
2084                         rtw_addbareq_cmd(padapter, (u8)priority, pattrib->ra);
2085                 }
2086         }
2087 }
2088
2089 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2090 {
2091         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2092
2093         spin_lock_bh(&pmlmepriv->lock);
2094         _rtw_roaming(padapter, tgt_network);
2095         spin_unlock_bh(&pmlmepriv->lock);
2096 }
2097 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2098 {
2099         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2100         int do_join_r;
2101
2102         struct wlan_network *pnetwork;
2103
2104         if (tgt_network != NULL)
2105                 pnetwork = tgt_network;
2106         else
2107                 pnetwork = &pmlmepriv->cur_network;
2108
2109         if (0 < pmlmepriv->to_roaming) {
2110                 DBG_88E("roaming from %s(%pM length:%d\n",
2111                         pnetwork->network.Ssid.Ssid, pnetwork->network.MacAddress,
2112                         pnetwork->network.Ssid.SsidLength);
2113                 memcpy(&pmlmepriv->assoc_ssid, &pnetwork->network.Ssid, sizeof(struct ndis_802_11_ssid));
2114
2115                 pmlmepriv->assoc_by_bssid = false;
2116
2117                 while (1) {
2118                         do_join_r = rtw_do_join(padapter);
2119                         if (_SUCCESS == do_join_r) {
2120                                 break;
2121                         } else {
2122                                 DBG_88E("roaming do_join return %d\n", do_join_r);
2123                                 pmlmepriv->to_roaming--;
2124
2125                                 if (0 < pmlmepriv->to_roaming) {
2126                                         continue;
2127                                 } else {
2128                                         DBG_88E("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
2129                                         rtw_indicate_disconnect(padapter);
2130                                         break;
2131                                 }
2132                         }
2133                 }
2134         }
2135 }