GNU Linux-libre 4.14.251-gnu1
[releases.git] / drivers / staging / rtl8723bs / core / rtw_mlme.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  ******************************************************************************/
15 #define _RTW_MLME_C_
16
17 #include <drv_types.h>
18 #include <rtw_debug.h>
19 #include <linux/jiffies.h>
20
21 extern u8 rtw_do_join(struct adapter *padapter);
22
23 sint    _rtw_init_mlme_priv(struct adapter *padapter)
24 {
25         sint    i;
26         u8 *pbuf;
27         struct wlan_network     *pnetwork;
28         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
29         sint    res = _SUCCESS;
30
31         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by vzalloc(). */
32         /* memset((u8 *)pmlmepriv, 0, sizeof(struct mlme_priv)); */
33
34         pmlmepriv->nic_hdl = (u8 *)padapter;
35
36         pmlmepriv->pscanned = NULL;
37         pmlmepriv->fw_state = WIFI_STATION_STATE; /*  Must sync with rtw_wdev_alloc() */
38         /*  wdev->iftype = NL80211_IFTYPE_STATION */
39         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
40         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
41
42         spin_lock_init(&(pmlmepriv->lock));
43         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
44         _rtw_init_queue(&(pmlmepriv->scanned_queue));
45
46         set_scanned_network_val(pmlmepriv, 0);
47
48         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
49
50         pbuf = vzalloc(MAX_BSS_CNT * (sizeof(struct wlan_network)));
51
52         if (pbuf == NULL) {
53                 res = _FAIL;
54                 goto exit;
55         }
56         pmlmepriv->free_bss_buf = pbuf;
57
58         pnetwork = (struct wlan_network *)pbuf;
59
60         for (i = 0; i < MAX_BSS_CNT; i++) {
61                 INIT_LIST_HEAD(&(pnetwork->list));
62
63                 list_add_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
64
65                 pnetwork++;
66         }
67
68         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
69
70         rtw_clear_scan_deny(padapter);
71
72         #define RTW_ROAM_SCAN_RESULT_EXP_MS 5000
73         #define RTW_ROAM_RSSI_DIFF_TH 10
74         #define RTW_ROAM_SCAN_INTERVAL_MS 10000
75
76         pmlmepriv->roam_flags = 0
77                 | RTW_ROAM_ON_EXPIRED
78                 | RTW_ROAM_ON_RESUME
79                 #ifdef CONFIG_LAYER2_ROAMING_ACTIVE /* FIXME */
80                 | RTW_ROAM_ACTIVE
81                 #endif
82                 ;
83
84         pmlmepriv->roam_scanr_exp_ms = RTW_ROAM_SCAN_RESULT_EXP_MS;
85         pmlmepriv->roam_rssi_diff_th = RTW_ROAM_RSSI_DIFF_TH;
86         pmlmepriv->roam_scan_int_ms = RTW_ROAM_SCAN_INTERVAL_MS;
87
88         rtw_init_mlme_timer(padapter);
89
90 exit:
91
92         return res;
93 }
94
95 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
96 {
97         if (*ppie) {
98                 kfree(*ppie);
99                 *plen = 0;
100                 *ppie = NULL;
101         }
102 }
103
104 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
105 {
106         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
107         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
108         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
109         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
110         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
111         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
112
113         rtw_free_mlme_ie_data(&pmlmepriv->p2p_beacon_ie, &pmlmepriv->p2p_beacon_ie_len);
114         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_req_ie, &pmlmepriv->p2p_probe_req_ie_len);
115         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_resp_ie, &pmlmepriv->p2p_probe_resp_ie_len);
116         rtw_free_mlme_ie_data(&pmlmepriv->p2p_go_probe_resp_ie, &pmlmepriv->p2p_go_probe_resp_ie_len);
117         rtw_free_mlme_ie_data(&pmlmepriv->p2p_assoc_req_ie, &pmlmepriv->p2p_assoc_req_ie_len);
118 }
119
120 void _rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
121 {
122         if (pmlmepriv) {
123                 rtw_free_mlme_priv_ie_data(pmlmepriv);
124                 if (pmlmepriv->free_bss_buf) {
125                         vfree(pmlmepriv->free_bss_buf);
126                 }
127         }
128 }
129
130 /*
131 struct  wlan_network *_rtw_dequeue_network(struct __queue *queue)
132 {
133         _irqL irqL;
134
135         struct wlan_network *pnetwork;
136
137         spin_lock_bh(&queue->lock);
138
139         if (list_empty(&queue->queue))
140
141                 pnetwork = NULL;
142
143         else
144         {
145                 pnetwork = LIST_CONTAINOR(get_next(&queue->queue), struct wlan_network, list);
146
147                 list_del_init(&(pnetwork->list));
148         }
149
150         spin_unlock_bh(&queue->lock);
151
152         return pnetwork;
153 }
154 */
155
156 struct  wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)/* _queue *free_queue) */
157 {
158         struct  wlan_network    *pnetwork;
159         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
160         struct list_head *plist = NULL;
161
162         spin_lock_bh(&free_queue->lock);
163
164         if (list_empty(&free_queue->queue)) {
165                 pnetwork = NULL;
166                 goto exit;
167         }
168         plist = get_next(&(free_queue->queue));
169
170         pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
171
172         list_del_init(&pnetwork->list);
173
174         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("_rtw_alloc_network: ptr =%p\n", plist));
175         pnetwork->network_type = 0;
176         pnetwork->fixed = false;
177         pnetwork->last_scanned = jiffies;
178         pnetwork->aid = 0;
179         pnetwork->join_res = 0;
180
181         pmlmepriv->num_of_scanned++;
182
183 exit:
184         spin_unlock_bh(&free_queue->lock);
185
186         return pnetwork;
187 }
188
189 void _rtw_free_network(struct   mlme_priv *pmlmepriv, struct wlan_network *pnetwork, u8 isfreeall)
190 {
191         unsigned int delta_time;
192         u32 lifetime = SCANQUEUE_LIFETIME;
193 /*      _irqL irqL; */
194         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
195
196         if (pnetwork == NULL)
197                 return;
198
199         if (pnetwork->fixed == true)
200                 return;
201
202         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
203                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true))
204                 lifetime = 1;
205
206         if (!isfreeall) {
207                 delta_time = jiffies_to_msecs(jiffies - pnetwork->last_scanned);
208                 if (delta_time < lifetime)/*  unit:msec */
209                         return;
210         }
211
212         spin_lock_bh(&free_queue->lock);
213
214         list_del_init(&(pnetwork->list));
215
216         list_add_tail(&(pnetwork->list), &(free_queue->queue));
217
218         pmlmepriv->num_of_scanned--;
219
220
221         /* DBG_871X("_rtw_free_network:SSID =%s\n", pnetwork->network.Ssid.Ssid); */
222
223         spin_unlock_bh(&free_queue->lock);
224 }
225
226 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
227 {
228
229         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
230
231         if (pnetwork == NULL)
232                 return;
233
234         if (pnetwork->fixed == true)
235                 return;
236
237         /* spin_lock_irqsave(&free_queue->lock, irqL); */
238
239         list_del_init(&(pnetwork->list));
240
241         list_add_tail(&(pnetwork->list), get_list_head(free_queue));
242
243         pmlmepriv->num_of_scanned--;
244
245         /* spin_unlock_irqrestore(&free_queue->lock, irqL); */
246 }
247
248 /*
249         return the wlan_network with the matching addr
250
251         Shall be called under atomic context... to avoid possible racing condition...
252 */
253 struct wlan_network *_rtw_find_network(struct __queue *scanned_queue, u8 *addr)
254 {
255         struct list_head        *phead, *plist;
256         struct  wlan_network *pnetwork = NULL;
257         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
258
259         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
260                 pnetwork = NULL;
261                 goto exit;
262         }
263
264         /* spin_lock_bh(&scanned_queue->lock); */
265
266         phead = get_list_head(scanned_queue);
267         plist = get_next(phead);
268
269         while (plist != phead) {
270                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
271
272                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
273                         break;
274
275                 plist = get_next(plist);
276         }
277
278         if (plist == phead)
279                 pnetwork = NULL;
280
281         /* spin_unlock_bh(&scanned_queue->lock); */
282
283 exit:
284         return pnetwork;
285 }
286
287 void _rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
288 {
289         struct list_head *phead, *plist;
290         struct wlan_network *pnetwork;
291         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
292         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
293
294         spin_lock_bh(&scanned_queue->lock);
295
296         phead = get_list_head(scanned_queue);
297         plist = get_next(phead);
298
299         while (phead != plist) {
300
301                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
302
303                 plist = get_next(plist);
304
305                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
306
307         }
308
309         spin_unlock_bh(&scanned_queue->lock);
310 }
311
312
313
314
315 sint rtw_if_up(struct adapter *padapter)
316 {
317
318         sint res;
319
320         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
321                 (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
322                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)", padapter->bDriverStopped, padapter->bSurpriseRemoved));
323                 res = false;
324         } else
325                 res =  true;
326         return res;
327 }
328
329
330 void rtw_generate_random_ibss(u8 *pibss)
331 {
332         unsigned long curtime = jiffies;
333
334         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
335         pibss[1] = 0x11;
336         pibss[2] = 0x87;
337         pibss[3] = (u8)(curtime & 0xff) ;/* p[0]; */
338         pibss[4] = (u8)((curtime>>8) & 0xff) ;/* p[1]; */
339         pibss[5] = (u8)((curtime>>16) & 0xff) ;/* p[2]; */
340         return;
341 }
342
343 u8 *rtw_get_capability_from_ie(u8 *ie)
344 {
345         return (ie + 8 + 2);
346 }
347
348
349 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
350 {
351         __le16  val;
352
353         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2);
354
355         return le16_to_cpu(val);
356 }
357
358 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
359 {
360         return (ie + 8);
361 }
362
363
364 int     rtw_init_mlme_priv(struct adapter *padapter)/* struct   mlme_priv *pmlmepriv) */
365 {
366         int     res;
367
368         res = _rtw_init_mlme_priv(padapter);/*  (pmlmepriv); */
369         return res;
370 }
371
372 void rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
373 {
374         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_mlme_priv\n"));
375         _rtw_free_mlme_priv(pmlmepriv);
376 }
377
378 /*
379 static struct   wlan_network *rtw_dequeue_network(struct __queue *queue)
380 {
381         struct wlan_network *pnetwork;
382
383         pnetwork = _rtw_dequeue_network(queue);
384         return pnetwork;
385 }
386 */
387
388 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv);
389 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv)/* _queue  *free_queue) */
390 {
391         struct  wlan_network    *pnetwork;
392
393         pnetwork = _rtw_alloc_network(pmlmepriv);
394         return pnetwork;
395 }
396
397 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork);
398 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork)
399 {
400         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_network ==> ssid = %s\n\n" , pnetwork->network.Ssid.Ssid)); */
401         _rtw_free_network_nolock(&(padapter->mlmepriv), pnetwork);
402         rtw_cfg80211_unlink_bss(padapter, pnetwork);
403 }
404
405
406 void rtw_free_network_queue(struct adapter *dev, u8 isfreeall)
407 {
408         _rtw_free_network_queue(dev, isfreeall);
409 }
410
411 /*
412         return the wlan_network with the matching addr
413
414         Shall be called under atomic context... to avoid possible racing condition...
415 */
416 struct  wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
417 {
418         struct  wlan_network *pnetwork = _rtw_find_network(scanned_queue, addr);
419
420         return pnetwork;
421 }
422
423 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
424 {
425         int ret = true;
426         struct security_priv *psecuritypriv = &adapter->securitypriv;
427
428         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
429                     (pnetwork->network.Privacy == 0))
430                 ret = false;
431         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
432                  (pnetwork->network.Privacy == 1))
433                 ret = false;
434         else
435                 ret = true;
436
437         return ret;
438
439 }
440
441 inline int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
442 {
443         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("(%s,%d)(%s,%d)\n", */
444         /*              a->Ssid.Ssid, a->Ssid.SsidLength, b->Ssid.Ssid, b->Ssid.SsidLength)); */
445         return (a->Ssid.SsidLength == b->Ssid.SsidLength)
446                 &&  !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
447 }
448
449 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst, u8 feature)
450 {
451         u16 s_cap, d_cap;
452         __le16 tmps, tmpd;
453
454         if (rtw_bug_check(dst, src, &s_cap, &d_cap) == false)
455                         return false;
456
457         memcpy((u8 *)&tmps, rtw_get_capability_from_ie(src->IEs), 2);
458         memcpy((u8 *)&tmpd, rtw_get_capability_from_ie(dst->IEs), 2);
459
460
461         s_cap = le16_to_cpu(tmps);
462         d_cap = le16_to_cpu(tmpd);
463
464         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
465                 /*      (src->Configuration.DSConfig == dst->Configuration.DSConfig) && */
466                         ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN))) &&
467                         ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength))) &&
468                         ((s_cap & WLAN_CAPABILITY_IBSS) ==
469                         (d_cap & WLAN_CAPABILITY_IBSS)) &&
470                         ((s_cap & WLAN_CAPABILITY_BSS) ==
471                         (d_cap & WLAN_CAPABILITY_BSS)));
472
473 }
474
475 struct wlan_network *_rtw_find_same_network(struct __queue *scanned_queue, struct wlan_network *network)
476 {
477         struct list_head *phead, *plist;
478         struct wlan_network *found = NULL;
479
480         phead = get_list_head(scanned_queue);
481         plist = get_next(phead);
482
483         while (plist != phead) {
484                 found = LIST_CONTAINOR(plist, struct wlan_network, list);
485
486                 if (is_same_network(&network->network, &found->network, 0))
487                         break;
488
489                 plist = get_next(plist);
490         }
491
492         if (plist == phead)
493                 found = NULL;
494
495         return found;
496 }
497
498 struct  wlan_network    *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
499 {
500         struct list_head        *plist, *phead;
501
502
503         struct  wlan_network    *pwlan = NULL;
504         struct  wlan_network    *oldest = NULL;
505
506         phead = get_list_head(scanned_queue);
507
508         plist = get_next(phead);
509
510         while (1) {
511
512                 if (phead == plist)
513                         break;
514
515                 pwlan = LIST_CONTAINOR(plist, struct wlan_network, list);
516
517                 if (pwlan->fixed != true) {
518                         if (oldest == NULL || time_after(oldest->last_scanned, pwlan->last_scanned))
519                                 oldest = pwlan;
520                 }
521
522                 plist = get_next(plist);
523         }
524         return oldest;
525
526 }
527
528 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
529         struct adapter *padapter, bool update_ie)
530 {
531         long rssi_ori = dst->Rssi;
532
533         u8 sq_smp = src->PhyInfo.SignalQuality;
534
535         u8 ss_final;
536         u8 sq_final;
537         long rssi_final;
538
539         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
540         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
541                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT", ch%u) ss_ori:%3u, sq_ori:%3u, rssi_ori:%3ld, ss_smp:%3u, sq_smp:%3u, rssi_smp:%3ld\n"
542                         , FUNC_ADPT_ARG(padapter)
543                         , src->Ssid.Ssid, MAC_ARG(src->MacAddress), src->Configuration.DSConfig
544                         , ss_ori, sq_ori, rssi_ori
545                         , ss_smp, sq_smp, rssi_smp
546                 );
547         }
548         #endif
549
550         /* The rule below is 1/5 for sample value, 4/5 for history value */
551         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src, 0)) {
552                 /* Take the recvpriv's value for the connected AP*/
553                 ss_final = padapter->recvpriv.signal_strength;
554                 sq_final = padapter->recvpriv.signal_qual;
555                 /* the rssi value here is undecorated, and will be used for antenna diversity */
556                 if (sq_smp != 101) /* from the right channel */
557                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
558                 else
559                         rssi_final = rssi_ori;
560         } else {
561                 if (sq_smp != 101) { /* from the right channel */
562                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
563                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
564                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
565                 } else {
566                         /* bss info not receiving from the right channel, use the original RX signal infos */
567                         ss_final = dst->PhyInfo.SignalStrength;
568                         sq_final = dst->PhyInfo.SignalQuality;
569                         rssi_final = dst->Rssi;
570                 }
571
572         }
573
574         if (update_ie) {
575                 dst->Reserved[0] = src->Reserved[0];
576                 dst->Reserved[1] = src->Reserved[1];
577                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
578         }
579
580         dst->PhyInfo.SignalStrength = ss_final;
581         dst->PhyInfo.SignalQuality = sq_final;
582         dst->Rssi = rssi_final;
583
584         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
585         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
586                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT"), SignalStrength:%u, SignalQuality:%u, RawRSSI:%ld\n"
587                         , FUNC_ADPT_ARG(padapter)
588                         , dst->Ssid.Ssid, MAC_ARG(dst->MacAddress), dst->PhyInfo.SignalStrength, dst->PhyInfo.SignalQuality, dst->Rssi);
589         }
590         #endif
591 }
592
593 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
594 {
595         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
596
597         rtw_bug_check(&(pmlmepriv->cur_network.network),
598                 &(pmlmepriv->cur_network.network),
599                 &(pmlmepriv->cur_network.network),
600                 &(pmlmepriv->cur_network.network));
601
602         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) && (is_same_network(&(pmlmepriv->cur_network.network), pnetwork, 0))) {
603                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"Same Network\n"); */
604
605                 /* if (pmlmepriv->cur_network.network.IELength<= pnetwork->IELength) */
606                 {
607                         update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
608                         rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof(struct ndis_802_11_fix_ie),
609                                                                         pmlmepriv->cur_network.network.IELength);
610                 }
611         }
612 }
613
614
615 /*
616
617 Caller must hold pmlmepriv->lock first.
618
619
620 */
621 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
622 {
623         struct list_head        *plist, *phead;
624         u32 bssid_ex_sz;
625         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
626         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
627         struct wlan_network     *pnetwork = NULL;
628         struct wlan_network     *oldest = NULL;
629         int target_find = 0;
630         u8 feature = 0;
631
632         spin_lock_bh(&queue->lock);
633         phead = get_list_head(queue);
634         plist = get_next(phead);
635
636         while (1) {
637                 if (phead == plist)
638                         break;
639
640                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
641
642                 rtw_bug_check(pnetwork, pnetwork, pnetwork, pnetwork);
643
644                 if (is_same_network(&(pnetwork->network), target, feature)) {
645                         target_find = 1;
646                         break;
647                 }
648
649                 if (rtw_roam_flags(adapter)) {
650                         /* TODO: don't  select netowrk in the same ess as oldest if it's new enough*/
651                 }
652
653                 if (oldest == NULL || time_after(oldest->last_scanned, pnetwork->last_scanned))
654                         oldest = pnetwork;
655
656                 plist = get_next(plist);
657
658         }
659
660
661         /* If we didn't find a match, then get a new network slot to initialize
662          * with this beacon's information */
663         /* if (phead == plist) { */
664         if (!target_find) {
665                 if (list_empty(&pmlmepriv->free_bss_pool.queue)) {
666                         /* If there are no more slots, expire the oldest */
667                         /* list_del_init(&oldest->list); */
668                         pnetwork = oldest;
669                         if (pnetwork == NULL) {
670                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
671                                 goto exit;
672                         }
673                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
674                         /*  variable initialize */
675                         pnetwork->fixed = false;
676                         pnetwork->last_scanned = jiffies;
677
678                         pnetwork->network_type = 0;
679                         pnetwork->aid = 0;
680                         pnetwork->join_res = 0;
681
682                         /* bss info not receiving from the right channel */
683                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
684                                 pnetwork->network.PhyInfo.SignalQuality = 0;
685                 } else {
686                         /* Otherwise just pull from the free list */
687
688                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
689
690                         if (pnetwork == NULL) {
691                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
692                                 goto exit;
693                         }
694
695                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
696                         target->Length = bssid_ex_sz;
697                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
698
699                         pnetwork->last_scanned = jiffies;
700
701                         /* bss info not receiving from the right channel */
702                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
703                                 pnetwork->network.PhyInfo.SignalQuality = 0;
704
705                         list_add_tail(&(pnetwork->list), &(queue->queue));
706
707                 }
708         } else {
709                 /* we have an entry and we are going to update it. But this entry may
710                  * be already expired. In this case we do the same as we found a new
711                  * net and call the new_net handler
712                  */
713                 bool update_ie = true;
714
715                 pnetwork->last_scanned = jiffies;
716
717                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
718                 if ((pnetwork->network.IELength > target->IELength) && (target->Reserved[0] == 1))
719                         update_ie = false;
720
721                 /*  probe resp(3) > beacon(1) > probe req(2) */
722                 if ((target->Reserved[0] != 2) &&
723                         (target->Reserved[0] >= pnetwork->network.Reserved[0])
724                         ) {
725                         update_ie = true;
726                 } else {
727                         update_ie = false;
728                 }
729
730                 update_network(&(pnetwork->network), target, adapter, update_ie);
731         }
732
733 exit:
734         spin_unlock_bh(&queue->lock);
735 }
736
737 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork);
738 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
739 {
740         /* struct __queue       *queue  = &(pmlmepriv->scanned_queue); */
741
742         /* spin_lock_bh(&queue->lock); */
743
744         update_current_network(adapter, pnetwork);
745
746         rtw_update_scanned_network(adapter, pnetwork);
747
748         /* spin_unlock_bh(&queue->lock); */
749 }
750
751 /* select the desired network based on the capability of the (i)bss. */
752 /*  check items: (1) security */
753 /*                         (2) network_type */
754 /*                         (3) WMM */
755 /*                         (4) HT */
756 /*                      (5) others */
757 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork);
758 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
759 {
760         struct security_priv *psecuritypriv = &adapter->securitypriv;
761         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
762         u32 desired_encmode;
763         u32 privacy;
764
765         /* u8 wps_ie[512]; */
766         uint wps_ielen;
767
768         int bselected = true;
769
770         desired_encmode = psecuritypriv->ndisencryptstatus;
771         privacy = pnetwork->network.Privacy;
772
773         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
774                 if (rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen) != NULL)
775                         return true;
776                 else
777                         return false;
778
779         }
780         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
781                 u8 *p = NULL;
782                 uint ie_len = 0;
783
784                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
785             bselected = false;
786
787                 if (psecuritypriv->ndisauthtype == Ndis802_11AuthModeWPA2PSK) {
788                         p = rtw_get_ie(pnetwork->network.IEs + _BEACON_IE_OFFSET_, _RSN_IE_2_, &ie_len, (pnetwork->network.IELength - _BEACON_IE_OFFSET_));
789                         if (p && ie_len > 0) {
790                                 bselected = true;
791                         } else {
792                                 bselected = false;
793                         }
794                 }
795         }
796
797
798         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
799                 DBG_871X("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
800                 bselected = false;
801         }
802
803         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
804                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
805                         bselected = false;
806         }
807
808
809         return bselected;
810 }
811
812 /* TODO: Perry : For Power Management */
813 void rtw_atimdone_event_callback(struct adapter *adapter, u8 *pbuf)
814 {
815         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_evet\n"));
816 }
817
818
819 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
820 {
821         u32 len;
822         struct wlan_bssid_ex *pnetwork;
823         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
824
825         pnetwork = (struct wlan_bssid_ex *)pbuf;
826
827         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid =%s\n",  pnetwork->Ssid.Ssid));
828
829         len = get_wlan_bssid_ex_sz(pnetwork);
830         if (len > (sizeof(struct wlan_bssid_ex))) {
831                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n ****rtw_survey_event_callback: return a wrong bss ***\n"));
832                 return;
833         }
834
835
836         spin_lock_bh(&pmlmepriv->lock);
837
838         /*  update IBSS_network 's timestamp */
839         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) {
840                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"rtw_survey_event_callback : WIFI_ADHOC_MASTER_STATE\n\n"); */
841                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN)) {
842                         struct wlan_network *ibss_wlan = NULL;
843
844                         memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
845                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
846                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
847                         if (ibss_wlan) {
848                                 memcpy(ibss_wlan->network.IEs, pnetwork->IEs, 8);
849                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
850                                 goto exit;
851                         }
852                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
853                 }
854         }
855
856         /*  lock pmlmepriv->lock when you accessing network_q */
857         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false) {
858                 if (pnetwork->Ssid.Ssid[0] == 0) {
859                         pnetwork->Ssid.SsidLength = 0;
860                 }
861                 rtw_add_network(adapter, pnetwork);
862         }
863
864 exit:
865
866         spin_unlock_bh(&pmlmepriv->lock);
867
868         return;
869 }
870
871
872
873 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
874 {
875         u8 timer_cancelled = false;
876         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
877
878         spin_lock_bh(&pmlmepriv->lock);
879         if (pmlmepriv->wps_probe_req_ie) {
880                 pmlmepriv->wps_probe_req_ie_len = 0;
881                 kfree(pmlmepriv->wps_probe_req_ie);
882                 pmlmepriv->wps_probe_req_ie = NULL;
883         }
884
885         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
886
887         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
888                 /* u8 timer_cancelled; */
889
890                 timer_cancelled = true;
891                 /* _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled); */
892
893                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
894         } else {
895
896                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status =%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
897         }
898         spin_unlock_bh(&pmlmepriv->lock);
899
900         if (timer_cancelled)
901                 _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
902
903
904         spin_lock_bh(&pmlmepriv->lock);
905
906         rtw_set_signal_stat_timer(&adapter->recvpriv);
907
908         if (pmlmepriv->to_join == true) {
909                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
910                         if (check_fwstate(pmlmepriv, _FW_LINKED) == false) {
911                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
912
913                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
914                                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
915                                 } else{
916                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
917                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
918
919                                         /* pmlmepriv->fw_state ^= _FW_UNDER_SURVEY;because don't set assoc_timer */
920                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
921
922                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
923
924                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
925
926                                         rtw_update_registrypriv_dev_network(adapter);
927                                         rtw_generate_random_ibss(pibss);
928
929                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
930
931                                         if (rtw_createbss_cmd(adapter) != _SUCCESS) {
932                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error =>rtw_createbss_cmd status FAIL\n"));
933                                         }
934
935                                         pmlmepriv->to_join = false;
936                                 }
937                         }
938                 } else{
939                         int s_ret;
940                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
941                         pmlmepriv->to_join = false;
942                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
943                         if (_SUCCESS == s_ret) {
944                              _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
945                         } else if (s_ret == 2) {/* there is no need to wait for join */
946                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
947                                 rtw_indicate_connect(adapter);
948                         } else{
949                                 DBG_871X("try_to_join, but select scanning queue fail, to_roam:%d\n", rtw_to_roam(adapter));
950
951                                 if (rtw_to_roam(adapter) != 0) {
952                                         if (rtw_dec_to_roam(adapter) == 0
953                                                 || _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)
954                                         ) {
955                                                 rtw_set_to_roam(adapter, 0);
956 #ifdef CONFIG_INTEL_WIDI
957                                                 if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING) {
958                                                         memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
959                                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
960                                                         DBG_871X("change to widi listen\n");
961                                                 }
962 #endif /*  CONFIG_INTEL_WIDI */
963                                                 rtw_free_assoc_resources(adapter, 1);
964                                                 rtw_indicate_disconnect(adapter);
965                                         } else {
966                                                 pmlmepriv->to_join = true;
967                                         }
968                                 } else
969                                         rtw_indicate_disconnect(adapter);
970
971                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
972                         }
973                 }
974         } else {
975                 if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
976                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)
977                                 && check_fwstate(pmlmepriv, _FW_LINKED)) {
978                                 if (rtw_select_roaming_candidate(pmlmepriv) == _SUCCESS) {
979                                         receive_disconnect(adapter, pmlmepriv->cur_network.network.MacAddress
980                                                 , WLAN_REASON_ACTIVE_ROAM);
981                                 }
982                         }
983                 }
984         }
985
986         /* DBG_871X("scan complete in %dms\n", jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time)); */
987
988         spin_unlock_bh(&pmlmepriv->lock);
989
990         rtw_os_xmit_schedule(adapter);
991
992         rtw_cfg80211_surveydone_event_callback(adapter);
993
994         rtw_indicate_scan_done(adapter, false);
995 }
996
997 void rtw_dummy_event_callback(struct adapter *adapter, u8 *pbuf)
998 {
999 }
1000
1001 void rtw_fwdbg_event_callback(struct adapter *adapter, u8 *pbuf)
1002 {
1003 }
1004
1005 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
1006 {
1007         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
1008         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
1009         struct list_head        *plist, *phead, *ptemp;
1010
1011         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
1012         spin_lock_bh(&scan_queue->lock);
1013         spin_lock_bh(&free_queue->lock);
1014
1015         phead = get_list_head(scan_queue);
1016         plist = get_next(phead);
1017
1018         while (plist != phead) {
1019                 ptemp = get_next(plist);
1020                 list_del_init(plist);
1021                 list_add_tail(plist, &free_queue->queue);
1022                 plist = ptemp;
1023                 pmlmepriv->num_of_scanned--;
1024         }
1025
1026         spin_unlock_bh(&free_queue->lock);
1027         spin_unlock_bh(&scan_queue->lock);
1028 }
1029
1030 static void rtw_reset_rx_info(struct debug_priv *pdbgpriv)
1031 {
1032         pdbgpriv->dbg_rx_ampdu_drop_count = 0;
1033         pdbgpriv->dbg_rx_ampdu_forced_indicate_count = 0;
1034         pdbgpriv->dbg_rx_ampdu_loss_count = 0;
1035         pdbgpriv->dbg_rx_dup_mgt_frame_drop_count = 0;
1036         pdbgpriv->dbg_rx_ampdu_window_shift_cnt = 0;
1037 }
1038
1039 static void find_network(struct adapter *adapter)
1040 {
1041         struct wlan_network *pwlan = NULL;
1042         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1043         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1044
1045         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1046         if (pwlan)
1047                 pwlan->fixed = false;
1048         else
1049                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources : pwlan == NULL\n\n"));
1050
1051
1052         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) &&
1053             (adapter->stapriv.asoc_sta_count == 1))
1054                 rtw_free_network_nolock(adapter, pwlan);
1055 }
1056
1057 /*
1058 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
1059 */
1060 void rtw_free_assoc_resources(struct adapter *adapter, int lock_scanned_queue)
1061 {
1062         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1063         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1064         struct  sta_priv *pstapriv = &adapter->stapriv;
1065         struct dvobj_priv *psdpriv = adapter->dvobj;
1066         struct debug_priv *pdbgpriv = &psdpriv->drv_dbg;
1067
1068         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
1069         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("tgt_network->network.MacAddress ="MAC_FMT" ssid =%s\n",
1070                 MAC_ARG(tgt_network->network.MacAddress), tgt_network->network.Ssid.Ssid));
1071
1072         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_AP_STATE)) {
1073                 struct sta_info *psta;
1074
1075                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
1076                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1077                 rtw_free_stainfo(adapter,  psta);
1078
1079                 spin_unlock_bh(&(pstapriv->sta_hash_lock));
1080
1081         }
1082
1083         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE|WIFI_AP_STATE)) {
1084                 struct sta_info *psta;
1085
1086                 rtw_free_all_stainfo(adapter);
1087
1088                 psta = rtw_get_bcmc_stainfo(adapter);
1089                 rtw_free_stainfo(adapter, psta);
1090
1091                 rtw_init_bcmc_stainfo(adapter);
1092         }
1093
1094         find_network(adapter);
1095
1096         if (lock_scanned_queue)
1097                 adapter->securitypriv.key_mask = 0;
1098
1099         rtw_reset_rx_info(pdbgpriv);
1100 }
1101
1102 /*
1103 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
1104 */
1105 void rtw_indicate_connect(struct adapter *padapter)
1106 {
1107         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1108
1109         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
1110
1111         pmlmepriv->to_join = false;
1112
1113         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
1114
1115                 set_fwstate(pmlmepriv, _FW_LINKED);
1116
1117                 rtw_os_indicate_connect(padapter);
1118         }
1119
1120         rtw_set_to_roam(padapter, 0);
1121 #ifdef CONFIG_INTEL_WIDI
1122         if (padapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING) {
1123                 memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1124                 intel_widi_wk_cmd(padapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1125                 DBG_871X("change to widi listen\n");
1126         }
1127 #endif /*  CONFIG_INTEL_WIDI */
1128
1129         rtw_set_scan_deny(padapter, 3000);
1130
1131         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state = 0x%08x\n", get_fwstate(pmlmepriv)));
1132 }
1133
1134 /*
1135 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
1136 */
1137 void rtw_indicate_disconnect(struct adapter *padapter)
1138 {
1139         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
1140
1141         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
1142
1143         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING|WIFI_UNDER_WPS);
1144
1145         /* DBG_871X("clear wps when %s\n", __func__); */
1146
1147         if (rtw_to_roam(padapter) > 0)
1148                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1149
1150         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED)
1151                 || (rtw_to_roam(padapter) <= 0)
1152         ) {
1153                 rtw_os_indicate_disconnect(padapter);
1154
1155                 /* set ips_deny_time to avoid enter IPS before LPS leave */
1156                 rtw_set_ips_deny(padapter, 3000);
1157
1158                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1159
1160                 rtw_clear_scan_deny(padapter);
1161         }
1162
1163         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
1164 }
1165
1166 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
1167 {
1168         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1169
1170         rtw_os_indicate_scan_done(padapter, aborted);
1171
1172         if (is_primary_adapter(padapter) &&
1173             (!adapter_to_pwrctl(padapter)->bInSuspend) &&
1174             (!check_fwstate(&padapter->mlmepriv,
1175                             WIFI_ASOC_STATE|WIFI_UNDER_LINKING))) {
1176                 struct pwrctrl_priv *pwrpriv;
1177
1178                 pwrpriv = adapter_to_pwrctl(padapter);
1179                 rtw_set_ips_deny(padapter, 0);
1180                 _set_timer(&padapter->mlmepriv.dynamic_chk_timer, 1);
1181         }
1182 }
1183
1184 void rtw_scan_abort(struct adapter *adapter)
1185 {
1186         unsigned long start;
1187         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1188         struct mlme_ext_priv *pmlmeext = &(adapter->mlmeextpriv);
1189
1190         start = jiffies;
1191         pmlmeext->scan_abort = true;
1192         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)
1193                 && jiffies_to_msecs(start) <= 200) {
1194
1195                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1196                         break;
1197
1198                 DBG_871X(FUNC_NDEV_FMT"fw_state = _FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1199                 msleep(20);
1200         }
1201
1202         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
1203                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
1204                         DBG_871X(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1205                 rtw_indicate_scan_done(adapter, true);
1206         }
1207         pmlmeext->scan_abort = false;
1208 }
1209
1210 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
1211 {
1212         int i;
1213         struct sta_info *bmc_sta, *psta = NULL;
1214         struct recv_reorder_ctrl *preorder_ctrl;
1215         struct sta_priv *pstapriv = &padapter->stapriv;
1216         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1217
1218         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
1219         if (psta == NULL) {
1220                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
1221         }
1222
1223         if (psta) { /* update ptarget_sta */
1224
1225                 DBG_871X("%s\n", __func__);
1226
1227                 psta->aid  = pnetwork->join_res;
1228
1229                 update_sta_info(padapter, psta);
1230
1231                 /* update station supportRate */
1232                 psta->bssratelen = rtw_get_rateset_len(pnetwork->network.SupportedRates);
1233                 memcpy(psta->bssrateset, pnetwork->network.SupportedRates, psta->bssratelen);
1234                 rtw_hal_update_sta_rate_mask(padapter, psta);
1235
1236                 psta->wireless_mode = pmlmeext->cur_wireless_mode;
1237                 psta->raid = rtw_hal_networktype_to_raid(padapter, psta);
1238
1239
1240                 /* sta mode */
1241                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
1242
1243                 /* security related */
1244                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1245                         padapter->securitypriv.binstallGrpkey = false;
1246                         padapter->securitypriv.busetkipkey = false;
1247                         padapter->securitypriv.bgrpkey_handshake = false;
1248
1249                         psta->ieee8021x_blocked = true;
1250                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
1251
1252                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
1253
1254                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
1255                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
1256
1257                         memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
1258                         psta->dot11txpn.val = psta->dot11txpn.val + 1;
1259                         memset((u8 *)&psta->dot11wtxpn, 0, sizeof(union pn48));
1260                         memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
1261                 }
1262
1263                 /*      Commented by Albert 2012/07/21 */
1264                 /*      When doing the WPS, the wps_ie_len won't equal to 0 */
1265                 /*      And the Wi-Fi driver shouldn't allow the data packet to be transmitted. */
1266                 if (padapter->securitypriv.wps_ie_len != 0) {
1267                         psta->ieee8021x_blocked = true;
1268                         padapter->securitypriv.wps_ie_len = 0;
1269                 }
1270
1271
1272                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
1273                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
1274                 /* todo: check if AP can send A-MPDU packets */
1275                 for (i = 0; i < 16 ; i++) {
1276                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1277                         preorder_ctrl = &psta->recvreorder_ctrl[i];
1278                         preorder_ctrl->enable = false;
1279                         preorder_ctrl->indicate_seq = 0xffff;
1280                         #ifdef DBG_RX_SEQ
1281                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1282                                 preorder_ctrl->indicate_seq);
1283                         #endif
1284                         preorder_ctrl->wend_b = 0xffff;
1285                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1286                 }
1287
1288
1289                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
1290                 if (bmc_sta) {
1291                         for (i = 0; i < 16 ; i++) {
1292                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1293                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
1294                                 preorder_ctrl->enable = false;
1295                                 preorder_ctrl->indicate_seq = 0xffff;
1296                                 #ifdef DBG_RX_SEQ
1297                                 DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1298                                         preorder_ctrl->indicate_seq);
1299                                 #endif
1300                                 preorder_ctrl->wend_b = 0xffff;
1301                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1302                         }
1303                 }
1304         }
1305
1306         return psta;
1307
1308 }
1309
1310 /* pnetwork : returns from rtw_joinbss_event_callback */
1311 /* ptarget_wlan: found from scanned_queue */
1312 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
1313 {
1314         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1315         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
1316
1317         DBG_871X("%s\n", __func__);
1318
1319         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nfw_state:%x, BSSID:"MAC_FMT"\n"
1320                 , get_fwstate(pmlmepriv), MAC_ARG(pnetwork->network.MacAddress)));
1321
1322
1323         /*  why not use ptarget_wlan?? */
1324         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
1325         /*  some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs */
1326         cur_network->network.IELength = ptarget_wlan->network.IELength;
1327         memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
1328
1329         cur_network->aid = pnetwork->join_res;
1330
1331
1332         rtw_set_signal_stat_timer(&padapter->recvpriv);
1333
1334         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
1335         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
1336         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
1337         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
1338         #if defined(DBG_RX_SIGNAL_DISPLAY_PROCESSING) && 1
1339                 DBG_871X(FUNC_ADPT_FMT" signal_strength:%3u, rssi:%3d, signal_qual:%3u"
1340                         "\n"
1341                         , FUNC_ADPT_ARG(padapter)
1342                         , padapter->recvpriv.signal_strength
1343                         , padapter->recvpriv.rssi
1344                         , padapter->recvpriv.signal_qual
1345         );
1346         #endif
1347
1348         rtw_set_signal_stat_timer(&padapter->recvpriv);
1349
1350         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
1351         switch (pnetwork->network.InfrastructureMode) {
1352         case Ndis802_11Infrastructure:
1353
1354                         if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
1355                                 pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
1356                         else
1357                                 pmlmepriv->fw_state = WIFI_STATION_STATE;
1358
1359                         break;
1360         case Ndis802_11IBSS:
1361                         pmlmepriv->fw_state = WIFI_ADHOC_STATE;
1362                         break;
1363         default:
1364                         pmlmepriv->fw_state = WIFI_NULL_STATE;
1365                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
1366                         break;
1367         }
1368
1369         rtw_update_protection(padapter, (cur_network->network.IEs) + sizeof(struct ndis_802_11_fix_ie),
1370                                                                         (cur_network->network.IELength));
1371
1372         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength, (u8) cur_network->network.Configuration.DSConfig);
1373 }
1374
1375 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
1376 /* pnetwork : returns from rtw_joinbss_event_callback */
1377 /* ptarget_wlan: found from scanned_queue */
1378 /* if join_res > 0, for (fw_state ==WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
1379 /* if join_res > 0, for (fw_state ==WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
1380 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
1381 /*  */
1382 /* define REJOIN */
1383 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
1384 {
1385         static u8 retry;
1386         u8 timer_cancelled;
1387         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
1388         struct  sta_priv *pstapriv = &adapter->stapriv;
1389         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1390         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1391         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1392         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1393         unsigned int            the_same_macaddr = false;
1394
1395         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res =%d\n", pnetwork->join_res));
1396
1397         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1398
1399
1400         if (pmlmepriv->assoc_ssid.SsidLength == 0) {
1401                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
1402         } else{
1403                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
1404         }
1405
1406         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1407
1408         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1409         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
1410                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1411                 return;
1412         }
1413
1414         spin_lock_bh(&pmlmepriv->lock);
1415
1416         pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 0;
1417         pmlmepriv->LinkDetectInfo.LowPowerTransitionCount = 0;
1418
1419         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\n rtw_joinbss_event_callback !! spin_lock_irqsave\n"));
1420
1421         if (pnetwork->join_res > 0) {
1422                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1423                 retry = 0;
1424                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1425                         /* s1. find ptarget_wlan */
1426                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1427                                 if (the_same_macaddr == true) {
1428                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1429                                 } else{
1430                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1431                                         if (pcur_wlan)
1432                                                 pcur_wlan->fixed = false;
1433
1434                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1435                                         if (pcur_sta)
1436                                                 rtw_free_stainfo(adapter,  pcur_sta);
1437
1438                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1439                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1440                                                 if (ptarget_wlan)
1441                                                         ptarget_wlan->fixed = true;
1442                                         }
1443                                 }
1444
1445                         } else{
1446                                 ptarget_wlan = _rtw_find_same_network(&pmlmepriv->scanned_queue, pnetwork);
1447                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1448                                         if (ptarget_wlan)
1449                                                 ptarget_wlan->fixed = true;
1450                                 }
1451                         }
1452
1453                         /* s2. update cur_network */
1454                         if (ptarget_wlan) {
1455                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1456                         } else{
1457                                 DBG_871X_LEVEL(_drv_always_, "Can't find ptarget_wlan when joinbss_event callback\n");
1458                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1459                                 goto ignore_joinbss_callback;
1460                         }
1461
1462
1463                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1464                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1465                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1466                                 if (ptarget_sta == NULL) {
1467                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1468                                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1469                                         goto ignore_joinbss_callback;
1470                                 }
1471                         }
1472
1473                         /* s4. indicate connect */
1474                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1475                                 pmlmepriv->cur_network_scanned = ptarget_wlan;
1476                                 rtw_indicate_connect(adapter);
1477                         } else{
1478                                 /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1479                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1480                         }
1481
1482
1483                         /* s5. Cancel assoc_timer */
1484                         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
1485
1486                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancel assoc_timer\n"));
1487
1488                 } else{
1489                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1490                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1491                         goto ignore_joinbss_callback;
1492                 }
1493
1494                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1495
1496         } else if (pnetwork->join_res == -4) {
1497                 rtw_reset_securitypriv(adapter);
1498                 _set_timer(&pmlmepriv->assoc_timer, 1);
1499
1500                 /* rtw_free_assoc_resources(adapter, 1); */
1501
1502                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true) {
1503                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state =%x\n", get_fwstate(pmlmepriv)));
1504                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1505                 }
1506
1507         } else{/* if join_res < 0 (join fails), then try again */
1508
1509                 #ifdef REJOIN
1510                 res = _FAIL;
1511                 if (retry < 2) {
1512                         res = rtw_select_and_join_from_scanned_queue(pmlmepriv);
1513                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_select_and_join_from_scanned_queue again! res:%d\n", res));
1514                 }
1515
1516                 if (res == _SUCCESS) {
1517                         /* extend time of assoc_timer */
1518                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
1519                         retry++;
1520                 } else if (res == 2) {/* there is no need to wait for join */
1521                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1522                         rtw_indicate_connect(adapter);
1523                 } else{
1524                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Set Assoc_Timer = 1; can't find match ssid in scanned_q\n"));
1525                 #endif
1526
1527                         _set_timer(&pmlmepriv->assoc_timer, 1);
1528                         /* rtw_free_assoc_resources(adapter, 1); */
1529                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1530
1531                 #ifdef REJOIN
1532                         retry = 0;
1533                 }
1534                 #endif
1535         }
1536
1537 ignore_joinbss_callback:
1538
1539         spin_unlock_bh(&pmlmepriv->lock);
1540 }
1541
1542 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1543 {
1544         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1545
1546         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1547
1548         rtw_os_xmit_schedule(adapter);
1549 }
1550
1551 /* FOR STA, AP , AD-HOC mode */
1552 void rtw_sta_media_status_rpt(struct adapter *adapter, struct sta_info *psta, u32 mstatus)
1553 {
1554         u16 media_status_rpt;
1555
1556         if (psta == NULL)
1557                 return;
1558
1559         media_status_rpt = (u16)((psta->mac_id<<8)|mstatus); /*   MACID|OPMODE:1 connect */
1560         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status_rpt);
1561 }
1562
1563 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1564 {
1565         struct sta_info *psta;
1566         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1567         struct stassoc_event    *pstassoc       = (struct stassoc_event *)pbuf;
1568         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1569         struct wlan_network     *ptarget_wlan = NULL;
1570
1571         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1572                 return;
1573
1574         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1575                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1576                 if (psta) {
1577                         u8 *passoc_req = NULL;
1578                         u32 assoc_req_len = 0;
1579
1580                         rtw_sta_media_status_rpt(adapter, psta, 1);
1581
1582 #ifndef CONFIG_AUTO_AP_MODE
1583
1584                         ap_sta_info_defer_update(adapter, psta);
1585
1586                         /* report to upper layer */
1587                         DBG_871X("indicate_sta_assoc_event to upper layer - hostapd\n");
1588                         spin_lock_bh(&psta->lock);
1589                         if (psta->passoc_req && psta->assoc_req_len > 0) {
1590                                 passoc_req = rtw_zmalloc(psta->assoc_req_len);
1591                                 if (passoc_req) {
1592                                         assoc_req_len = psta->assoc_req_len;
1593                                         memcpy(passoc_req, psta->passoc_req, assoc_req_len);
1594
1595                                         kfree(psta->passoc_req);
1596                                         psta->passoc_req = NULL;
1597                                         psta->assoc_req_len = 0;
1598                                 }
1599                         }
1600                         spin_unlock_bh(&psta->lock);
1601
1602                         if (passoc_req && assoc_req_len > 0) {
1603                                 rtw_cfg80211_indicate_sta_assoc(adapter, passoc_req, assoc_req_len);
1604
1605                                 kfree(passoc_req);
1606                         }
1607 #endif /* CONFIG_AUTO_AP_MODE */
1608                 }
1609                 return;
1610         }
1611
1612         /* for AD-HOC mode */
1613         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1614         if (psta != NULL) {
1615                 /* the sta have been in sta_info_queue => do nothing */
1616
1617                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1618
1619                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1620         }
1621
1622         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1623         if (psta == NULL) {
1624                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1625                 return;
1626         }
1627
1628         /* to do : init sta_info variable */
1629         psta->qos_option = 0;
1630         psta->mac_id = (uint)pstassoc->cam_id;
1631         /* psta->aid = (uint)pstassoc->cam_id; */
1632         DBG_871X("%s\n", __func__);
1633         /* for ad-hoc mode */
1634         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1635
1636         rtw_sta_media_status_rpt(adapter, psta, 1);
1637
1638         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1639                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1640
1641
1642         psta->ieee8021x_blocked = false;
1643
1644         spin_lock_bh(&pmlmepriv->lock);
1645
1646         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
1647                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
1648                 if (adapter->stapriv.asoc_sta_count == 2) {
1649                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1650                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1651                         pmlmepriv->cur_network_scanned = ptarget_wlan;
1652                         if (ptarget_wlan)
1653                                 ptarget_wlan->fixed = true;
1654                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1655                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1656                         rtw_indicate_connect(adapter);
1657                 }
1658         }
1659
1660         spin_unlock_bh(&pmlmepriv->lock);
1661
1662
1663         mlmeext_sta_add_event_callback(adapter, psta);
1664 }
1665
1666 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1667 {
1668         int mac_id = (-1);
1669         struct sta_info *psta;
1670         struct wlan_network *pwlan = NULL;
1671         struct wlan_bssid_ex    *pdev_network = NULL;
1672         u8 *pibss = NULL;
1673         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1674         struct  stadel_event *pstadel   = (struct stadel_event *)pbuf;
1675         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1676         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1677         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1678
1679         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1680         if (psta)
1681                 mac_id = psta->mac_id;
1682         else
1683                 mac_id = pstadel->mac_id;
1684
1685         DBG_871X("%s(mac_id =%d) =" MAC_FMT "\n", __func__, mac_id, MAC_ARG(pstadel->macaddr));
1686
1687         if (mac_id >= 0) {
1688                 u16 media_status;
1689                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1690                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1691                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1692         }
1693
1694         /* if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) */
1695         if ((pmlmeinfo->state&0x03) == WIFI_FW_AP_STATE)
1696                 return;
1697
1698
1699         mlmeext_sta_del_event_callback(adapter);
1700
1701         spin_lock_bh(&pmlmepriv->lock);
1702
1703         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1704                 u16 reason = *((unsigned short *)(pstadel->rsvd));
1705                 bool roam = false;
1706                 struct wlan_network *roam_target = NULL;
1707
1708                 if (adapter->registrypriv.wifi_spec == 1) {
1709                         roam = false;
1710                 } else if (reason == WLAN_REASON_EXPIRATION_CHK && rtw_chk_roam_flags(adapter, RTW_ROAM_ON_EXPIRED)) {
1711                         roam = true;
1712                 } else if (reason == WLAN_REASON_ACTIVE_ROAM && rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1713                         roam = true;
1714                         roam_target = pmlmepriv->roam_network;
1715                 }
1716 #ifdef CONFIG_INTEL_WIDI
1717                 else if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_CONNECTED) {
1718                         roam = true;
1719                 }
1720 #endif /*  CONFIG_INTEL_WIDI */
1721
1722                 if (roam == true) {
1723                         if (rtw_to_roam(adapter) > 0)
1724                                 rtw_dec_to_roam(adapter); /* this stadel_event is caused by roaming, decrease to_roam */
1725                         else if (rtw_to_roam(adapter) == 0)
1726                                 rtw_set_to_roam(adapter, adapter->registrypriv.max_roaming_times);
1727                 } else {
1728                         rtw_set_to_roam(adapter, 0);
1729                 }
1730
1731                 rtw_free_uc_swdec_pending_queue(adapter);
1732
1733                 rtw_free_assoc_resources(adapter, 1);
1734                 rtw_indicate_disconnect(adapter);
1735
1736                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1737                 /*  remove the network entry in scanned_queue */
1738                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1739                 if (pwlan) {
1740                         pwlan->fixed = false;
1741                         rtw_free_network_nolock(adapter, pwlan);
1742                 }
1743                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1744
1745 #ifdef CONFIG_INTEL_WIDI
1746                 if (!rtw_to_roam(adapter))
1747                         process_intel_widi_disconnect(adapter, 1);
1748 #endif /*  CONFIG_INTEL_WIDI */
1749
1750                 _rtw_roaming(adapter, roam_target);
1751         }
1752
1753         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1754               check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1755
1756                 rtw_free_stainfo(adapter,  psta);
1757
1758                 if (adapter->stapriv.asoc_sta_count == 1) {/* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1759                         /* rtw_indicate_disconnect(adapter);removed@20091105 */
1760                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1761                         /* free old ibss network */
1762                         /* pwlan = rtw_find_network(&pmlmepriv->scanned_queue, pstadel->macaddr); */
1763                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1764                         if (pwlan) {
1765                                 pwlan->fixed = false;
1766                                 rtw_free_network_nolock(adapter, pwlan);
1767                         }
1768                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1769                         /* re-create ibss */
1770                         pdev_network = &(adapter->registrypriv.dev_network);
1771                         pibss = adapter->registrypriv.dev_network.MacAddress;
1772
1773                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1774
1775                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1776
1777                         rtw_update_registrypriv_dev_network(adapter);
1778
1779                         rtw_generate_random_ibss(pibss);
1780
1781                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1782                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1783                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1784                         }
1785
1786                         if (rtw_createbss_cmd(adapter) != _SUCCESS) {
1787
1788                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error =>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1789
1790                         }
1791
1792
1793                 }
1794
1795         }
1796
1797         spin_unlock_bh(&pmlmepriv->lock);
1798 }
1799
1800 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1801 {
1802         struct reportpwrstate_parm *preportpwrstate;
1803
1804         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1805         preportpwrstate = (struct reportpwrstate_parm *)pbuf;
1806         preportpwrstate->state |= (u8)(adapter_to_pwrctl(padapter)->cpwm_tog + 0x80);
1807         cpwm_int_hdl(padapter, preportpwrstate);
1808 }
1809
1810
1811 void rtw_wmm_event_callback(struct adapter *padapter, u8 *pbuf)
1812 {
1813         WMMOnAssocRsp(padapter);
1814 }
1815
1816 /*
1817 * _rtw_join_timeout_handler - Timeout/failure handler for CMD JoinBss
1818 * @adapter: pointer to struct adapter structure
1819 */
1820 void _rtw_join_timeout_handler (struct adapter *adapter)
1821 {
1822         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1823
1824         DBG_871X("%s, fw_state =%x\n", __func__, get_fwstate(pmlmepriv));
1825
1826         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1827                 return;
1828
1829         spin_lock_bh(&pmlmepriv->lock);
1830
1831         if (rtw_to_roam(adapter) > 0) { /* join timeout caused by roaming */
1832                 while (1) {
1833                         rtw_dec_to_roam(adapter);
1834                         if (rtw_to_roam(adapter) != 0) { /* try another */
1835                                 int do_join_r;
1836                                 DBG_871X("%s try another roaming\n", __func__);
1837                                 do_join_r = rtw_do_join(adapter);
1838                                 if (_SUCCESS != do_join_r) {
1839                                         DBG_871X("%s roaming do_join return %d\n", __func__, do_join_r);
1840                                         continue;
1841                                 }
1842                                 break;
1843                         } else {
1844 #ifdef CONFIG_INTEL_WIDI
1845                                 if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING) {
1846                                         memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1847                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1848                                         DBG_871X("change to widi listen\n");
1849                                 }
1850 #endif /*  CONFIG_INTEL_WIDI */
1851                                 DBG_871X("%s We've try roaming but fail\n", __func__);
1852                                 rtw_indicate_disconnect(adapter);
1853                                 break;
1854                         }
1855                 }
1856
1857         } else{
1858                 rtw_indicate_disconnect(adapter);
1859                 free_scanqueue(pmlmepriv);/*  */
1860
1861                 /* indicate disconnect for the case that join_timeout and check_fwstate != FW_LINKED */
1862                 rtw_cfg80211_indicate_disconnect(adapter);
1863
1864         }
1865
1866         spin_unlock_bh(&pmlmepriv->lock);
1867 }
1868
1869 /*
1870 * rtw_scan_timeout_handler - Timeout/Failure handler for CMD SiteSurvey
1871 * @adapter: pointer to struct adapter structure
1872 */
1873 void rtw_scan_timeout_handler (struct adapter *adapter)
1874 {
1875         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1876
1877         DBG_871X(FUNC_ADPT_FMT" fw_state =%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1878
1879         spin_lock_bh(&pmlmepriv->lock);
1880
1881         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1882
1883         spin_unlock_bh(&pmlmepriv->lock);
1884
1885         rtw_indicate_scan_done(adapter, true);
1886 }
1887
1888 void rtw_mlme_reset_auto_scan_int(struct adapter *adapter)
1889 {
1890         struct mlme_priv *mlme = &adapter->mlmepriv;
1891         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1892         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1893
1894         if (pmlmeinfo->VHT_enable) /* disable auto scan when connect to 11AC AP */
1895                 mlme->auto_scan_int_ms = 0;
1896         else if (adapter->registrypriv.wifi_spec && is_client_associated_to_ap(adapter) == true)
1897                 mlme->auto_scan_int_ms = 60*1000;
1898         else if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1899                 if (check_fwstate(mlme, WIFI_STATION_STATE) && check_fwstate(mlme, _FW_LINKED))
1900                         mlme->auto_scan_int_ms = mlme->roam_scan_int_ms;
1901         } else
1902                 mlme->auto_scan_int_ms = 0; /* disabled */
1903
1904         return;
1905 }
1906
1907 static void rtw_auto_scan_handler(struct adapter *padapter)
1908 {
1909         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1910
1911         rtw_mlme_reset_auto_scan_int(padapter);
1912
1913         if (pmlmepriv->auto_scan_int_ms != 0
1914                 && jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time) > pmlmepriv->auto_scan_int_ms) {
1915
1916                 if (!padapter->registrypriv.wifi_spec) {
1917                         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == true) {
1918                                 DBG_871X(FUNC_ADPT_FMT" _FW_UNDER_SURVEY|_FW_UNDER_LINKING\n", FUNC_ADPT_ARG(padapter));
1919                                 goto exit;
1920                         }
1921
1922                         if (pmlmepriv->LinkDetectInfo.bBusyTraffic == true) {
1923                                 DBG_871X(FUNC_ADPT_FMT" exit BusyTraffic\n", FUNC_ADPT_ARG(padapter));
1924                                 goto exit;
1925                         }
1926                 }
1927
1928                 DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1929
1930                 rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1931         }
1932
1933 exit:
1934         return;
1935 }
1936
1937 void rtw_dynamic_check_timer_handlder(struct adapter *adapter)
1938 {
1939         if (!adapter)
1940                 return;
1941
1942         if (adapter->hw_init_completed == false)
1943                 return;
1944
1945         if ((adapter->bDriverStopped == true) || (adapter->bSurpriseRemoved == true))
1946                 return;
1947
1948         if (adapter->net_closed == true)
1949                 return;
1950
1951         if (is_primary_adapter(adapter))
1952                 DBG_871X("IsBtDisabled =%d, IsBtControlLps =%d\n", rtw_btcoex_IsBtDisabled(adapter), rtw_btcoex_IsBtControlLps(adapter));
1953
1954         if ((adapter_to_pwrctl(adapter)->bFwCurrentInPSMode == true)
1955                 && (rtw_btcoex_IsBtControlLps(adapter) == false)
1956                 ) {
1957                 u8 bEnterPS;
1958
1959                 linked_status_chk(adapter);
1960
1961                 bEnterPS = traffic_status_watchdog(adapter, 1);
1962                 if (bEnterPS) {
1963                         /* rtw_lps_ctrl_wk_cmd(adapter, LPS_CTRL_ENTER, 1); */
1964                         rtw_hal_dm_watchdog_in_lps(adapter);
1965                 } else{
1966                         /* call rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_LEAVE, 1) in traffic_status_watchdog() */
1967                 }
1968
1969         } else{
1970                 if (is_primary_adapter(adapter)) {
1971                         rtw_dynamic_chk_wk_cmd(adapter);
1972                 }
1973         }
1974
1975         /* auto site survey */
1976         rtw_auto_scan_handler(adapter);
1977 }
1978
1979
1980 inline bool rtw_is_scan_deny(struct adapter *adapter)
1981 {
1982         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1983         return (atomic_read(&mlmepriv->set_scan_deny) != 0) ? true : false;
1984 }
1985
1986 inline void rtw_clear_scan_deny(struct adapter *adapter)
1987 {
1988         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1989         atomic_set(&mlmepriv->set_scan_deny, 0);
1990
1991         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
1992 }
1993
1994 void rtw_set_scan_deny_timer_hdl(struct adapter *adapter)
1995 {
1996         rtw_clear_scan_deny(adapter);
1997 }
1998
1999 void rtw_set_scan_deny(struct adapter *adapter, u32 ms)
2000 {
2001         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2002
2003         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
2004         atomic_set(&mlmepriv->set_scan_deny, 1);
2005         _set_timer(&mlmepriv->set_scan_deny_timer, ms);
2006 }
2007
2008 /*
2009 * Select a new roaming candidate from the original @param candidate and @param competitor
2010 * @return true: candidate is updated
2011 * @return false: candidate is not updated
2012 */
2013 static int rtw_check_roaming_candidate(struct mlme_priv *mlme
2014         , struct wlan_network **candidate, struct wlan_network *competitor)
2015 {
2016         int updated = false;
2017         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
2018
2019         if (is_same_ess(&competitor->network, &mlme->cur_network.network) == false)
2020                 goto exit;
2021
2022         if (rtw_is_desired_network(adapter, competitor) == false)
2023                 goto exit;
2024
2025         DBG_871X("roam candidate:%s %s("MAC_FMT", ch%3u) rssi:%d, age:%5d\n",
2026                 (competitor == mlme->cur_network_scanned)?"*":" ",
2027                 competitor->network.Ssid.Ssid,
2028                 MAC_ARG(competitor->network.MacAddress),
2029                 competitor->network.Configuration.DSConfig,
2030                 (int)competitor->network.Rssi,
2031                 jiffies_to_msecs(jiffies - competitor->last_scanned)
2032         );
2033
2034         /* got specific addr to roam */
2035         if (!is_zero_mac_addr(mlme->roam_tgt_addr)) {
2036                 if (!memcmp(mlme->roam_tgt_addr, competitor->network.MacAddress, ETH_ALEN))
2037                         goto update;
2038                 else
2039                         goto exit;
2040         }
2041         if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms)
2042                 goto exit;
2043
2044         if (competitor->network.Rssi - mlme->cur_network_scanned->network.Rssi < mlme->roam_rssi_diff_th)
2045                 goto exit;
2046
2047         if (*candidate != NULL && (*candidate)->network.Rssi >= competitor->network.Rssi)
2048                 goto exit;
2049
2050 update:
2051         *candidate = competitor;
2052         updated = true;
2053
2054 exit:
2055         return updated;
2056 }
2057
2058 int rtw_select_roaming_candidate(struct mlme_priv *mlme)
2059 {
2060         int ret = _FAIL;
2061         struct list_head        *phead;
2062         struct adapter *adapter;
2063         struct __queue  *queue  = &(mlme->scanned_queue);
2064         struct  wlan_network    *pnetwork = NULL;
2065         struct  wlan_network    *candidate = NULL;
2066
2067         if (mlme->cur_network_scanned == NULL) {
2068                 rtw_warn_on(1);
2069                 return ret;
2070         }
2071
2072         spin_lock_bh(&(mlme->scanned_queue.lock));
2073         phead = get_list_head(queue);
2074         adapter = (struct adapter *)mlme->nic_hdl;
2075
2076         mlme->pscanned = get_next(phead);
2077
2078         while (phead != mlme->pscanned) {
2079
2080                 pnetwork = LIST_CONTAINOR(mlme->pscanned, struct wlan_network, list);
2081                 if (pnetwork == NULL) {
2082                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2083                         ret = _FAIL;
2084                         goto exit;
2085                 }
2086
2087                 mlme->pscanned = get_next(mlme->pscanned);
2088
2089                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2090                         , pnetwork->network.Ssid.Ssid
2091                         , MAC_ARG(pnetwork->network.MacAddress)
2092                         , pnetwork->network.Configuration.DSConfig
2093                         , (int)pnetwork->network.Rssi);
2094
2095                 rtw_check_roaming_candidate(mlme, &candidate, pnetwork);
2096
2097         }
2098
2099         if (candidate == NULL) {
2100                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2101                 ret = _FAIL;
2102                 goto exit;
2103         } else {
2104                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2105                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2106                         candidate->network.Configuration.DSConfig);
2107
2108                 mlme->roam_network = candidate;
2109
2110                 if (!memcmp(candidate->network.MacAddress, mlme->roam_tgt_addr, ETH_ALEN))
2111                         memset(mlme->roam_tgt_addr, 0, ETH_ALEN);
2112         }
2113
2114         ret = _SUCCESS;
2115 exit:
2116         spin_unlock_bh(&(mlme->scanned_queue.lock));
2117
2118         return ret;
2119 }
2120
2121 /*
2122 * Select a new join candidate from the original @param candidate and @param competitor
2123 * @return true: candidate is updated
2124 * @return false: candidate is not updated
2125 */
2126 static int rtw_check_join_candidate(struct mlme_priv *mlme
2127         , struct wlan_network **candidate, struct wlan_network *competitor)
2128 {
2129         int updated = false;
2130         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
2131
2132
2133         /* check bssid, if needed */
2134         if (mlme->assoc_by_bssid == true) {
2135                 if (memcmp(competitor->network.MacAddress, mlme->assoc_bssid, ETH_ALEN))
2136                         goto exit;
2137         }
2138
2139         /* check ssid, if needed */
2140         if (mlme->assoc_ssid.Ssid[0] && mlme->assoc_ssid.SsidLength) {
2141                 if (competitor->network.Ssid.SsidLength != mlme->assoc_ssid.SsidLength
2142                         || memcmp(competitor->network.Ssid.Ssid, mlme->assoc_ssid.Ssid, mlme->assoc_ssid.SsidLength)
2143                 )
2144                         goto exit;
2145         }
2146
2147         if (rtw_is_desired_network(adapter, competitor)  == false)
2148                 goto exit;
2149
2150         if (rtw_to_roam(adapter) > 0) {
2151                 if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms
2152                         || is_same_ess(&competitor->network, &mlme->cur_network.network) == false
2153                 )
2154                         goto exit;
2155         }
2156
2157         if (*candidate == NULL || (*candidate)->network.Rssi < competitor->network.Rssi) {
2158                 *candidate = competitor;
2159                 updated = true;
2160         }
2161
2162         if (updated) {
2163                 DBG_871X("[by_bssid:%u][assoc_ssid:%s]"
2164                         "[to_roam:%u] "
2165                         "new candidate: %s("MAC_FMT", ch%u) rssi:%d\n",
2166                         mlme->assoc_by_bssid,
2167                         mlme->assoc_ssid.Ssid,
2168                         rtw_to_roam(adapter),
2169                         (*candidate)->network.Ssid.Ssid,
2170                         MAC_ARG((*candidate)->network.MacAddress),
2171                         (*candidate)->network.Configuration.DSConfig,
2172                         (int)(*candidate)->network.Rssi
2173                 );
2174         }
2175
2176 exit:
2177         return updated;
2178 }
2179
2180 /*
2181 Calling context:
2182 The caller of the sub-routine will be in critical section...
2183
2184 The caller must hold the following spinlock
2185
2186 pmlmepriv->lock
2187
2188
2189 */
2190
2191 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
2192 {
2193         int ret;
2194         struct list_head        *phead;
2195         struct adapter *adapter;
2196         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
2197         struct  wlan_network    *pnetwork = NULL;
2198         struct  wlan_network    *candidate = NULL;
2199
2200         adapter = (struct adapter *)pmlmepriv->nic_hdl;
2201
2202         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
2203
2204         if (pmlmepriv->roam_network) {
2205                 candidate = pmlmepriv->roam_network;
2206                 pmlmepriv->roam_network = NULL;
2207                 goto candidate_exist;
2208         }
2209
2210         phead = get_list_head(queue);
2211         pmlmepriv->pscanned = get_next(phead);
2212
2213         while (phead != pmlmepriv->pscanned) {
2214
2215                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
2216                 if (pnetwork == NULL) {
2217                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2218                         ret = _FAIL;
2219                         goto exit;
2220                 }
2221
2222                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
2223
2224                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2225                         , pnetwork->network.Ssid.Ssid
2226                         , MAC_ARG(pnetwork->network.MacAddress)
2227                         , pnetwork->network.Configuration.DSConfig
2228                         , (int)pnetwork->network.Rssi);
2229
2230                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
2231
2232         }
2233
2234         if (candidate == NULL) {
2235                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2236 #ifdef CONFIG_WOWLAN
2237                 _clr_fwstate_(pmlmepriv, _FW_LINKED|_FW_UNDER_LINKING);
2238 #endif
2239                 ret = _FAIL;
2240                 goto exit;
2241         } else {
2242                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2243                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2244                         candidate->network.Configuration.DSConfig);
2245                 goto candidate_exist;
2246         }
2247
2248 candidate_exist:
2249
2250         /*  check for situation of  _FW_LINKED */
2251         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
2252                 DBG_871X("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
2253
2254                 rtw_disassoc_cmd(adapter, 0, true);
2255                 rtw_indicate_disconnect(adapter);
2256                 rtw_free_assoc_resources(adapter, 0);
2257         }
2258
2259         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
2260         ret = rtw_joinbss_cmd(adapter, candidate);
2261
2262 exit:
2263         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
2264         return ret;
2265 }
2266
2267 sint rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
2268 {
2269         struct  cmd_obj *pcmd;
2270         struct  setauth_parm *psetauthparm;
2271         struct  cmd_priv *pcmdpriv = &(adapter->cmdpriv);
2272         sint            res = _SUCCESS;
2273
2274         pcmd = (struct  cmd_obj *)rtw_zmalloc(sizeof(struct     cmd_obj));
2275         if (pcmd == NULL) {
2276                 res = _FAIL;  /* try again */
2277                 goto exit;
2278         }
2279
2280         psetauthparm = (struct setauth_parm *)rtw_zmalloc(sizeof(struct setauth_parm));
2281         if (psetauthparm == NULL) {
2282                 kfree((unsigned char *)pcmd);
2283                 res = _FAIL;
2284                 goto exit;
2285         }
2286
2287         memset(psetauthparm, 0, sizeof(struct setauth_parm));
2288         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
2289
2290         pcmd->cmdcode = _SetAuth_CMD_;
2291         pcmd->parmbuf = (unsigned char *)psetauthparm;
2292         pcmd->cmdsz =  (sizeof(struct setauth_parm));
2293         pcmd->rsp = NULL;
2294         pcmd->rspsz = 0;
2295
2296
2297         INIT_LIST_HEAD(&pcmd->list);
2298
2299         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("after enqueue set_auth_cmd, auth_mode =%x\n", psecuritypriv->dot11AuthAlgrthm));
2300
2301         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2302
2303 exit:
2304         return res;
2305 }
2306
2307 sint rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, sint keyid, u8 set_tx, bool enqueue)
2308 {
2309         u8 keylen;
2310         struct cmd_obj          *pcmd;
2311         struct setkey_parm      *psetkeyparm;
2312         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
2313         sint    res = _SUCCESS;
2314
2315         psetkeyparm = (struct setkey_parm *)rtw_zmalloc(sizeof(struct setkey_parm));
2316         if (psetkeyparm == NULL) {
2317                 res = _FAIL;
2318                 goto exit;
2319         }
2320         memset(psetkeyparm, 0, sizeof(struct setkey_parm));
2321
2322         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
2323                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
2324                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(unsigned char)psecuritypriv->dot118021XGrpPrivacy =%d\n", psetkeyparm->algorithm));
2325         } else {
2326                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
2327                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(u8)psecuritypriv->dot11PrivacyAlgrthm =%d\n", psetkeyparm->algorithm));
2328
2329         }
2330         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
2331         psetkeyparm->set_tx = set_tx;
2332         if (is_wep_enc(psetkeyparm->algorithm))
2333                 adapter->securitypriv.key_mask |= BIT(psetkeyparm->keyid);
2334
2335         DBG_871X("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n", psetkeyparm->algorithm, psetkeyparm->keyid, adapter->securitypriv.key_mask);
2336         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =%d psetkeyparm->keyid =(u8)keyid =%d\n", psetkeyparm->algorithm, keyid));
2337
2338         switch (psetkeyparm->algorithm) {
2339
2340         case _WEP40_:
2341                 keylen = 5;
2342                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2343                 break;
2344         case _WEP104_:
2345                 keylen = 13;
2346                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2347                 break;
2348         case _TKIP_:
2349                 keylen = 16;
2350                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2351                 psetkeyparm->grpkey = 1;
2352                 break;
2353         case _AES_:
2354                 keylen = 16;
2355                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2356                 psetkeyparm->grpkey = 1;
2357                 break;
2358         default:
2359                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm = %x (must be 1 or 2 or 4 or 5)\n", psecuritypriv->dot11PrivacyAlgrthm));
2360                 res = _FAIL;
2361                 kfree((unsigned char *)psetkeyparm);
2362                 goto exit;
2363         }
2364
2365
2366         if (enqueue) {
2367                 pcmd = (struct  cmd_obj *)rtw_zmalloc(sizeof(struct     cmd_obj));
2368                 if (pcmd == NULL) {
2369                         kfree((unsigned char *)psetkeyparm);
2370                         res = _FAIL;  /* try again */
2371                         goto exit;
2372                 }
2373
2374                 pcmd->cmdcode = _SetKey_CMD_;
2375                 pcmd->parmbuf = (u8 *)psetkeyparm;
2376                 pcmd->cmdsz =  (sizeof(struct setkey_parm));
2377                 pcmd->rsp = NULL;
2378                 pcmd->rspsz = 0;
2379
2380                 INIT_LIST_HEAD(&pcmd->list);
2381
2382                 /* sema_init(&(pcmd->cmd_sem), 0); */
2383
2384                 res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2385         } else{
2386                 setkey_hdl(adapter, (u8 *)psetkeyparm);
2387                 kfree((u8 *) psetkeyparm);
2388         }
2389 exit:
2390         return res;
2391 }
2392
2393 /* adjust IEs for rtw_joinbss_cmd in WMM */
2394 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
2395 {
2396         unsigned        int ielength = 0;
2397         unsigned int i, j;
2398
2399         i = 12; /* after the fixed IE */
2400         while (i < in_len) {
2401                 ielength = initial_out_len;
2402
2403                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) { /* WMM element ID and OUI */
2404                         for (j = i; j < i + 9; j++) {
2405                                         out_ie[ielength] = in_ie[j];
2406                                         ielength++;
2407                         }
2408                         out_ie[initial_out_len + 1] = 0x07;
2409                         out_ie[initial_out_len + 6] = 0x00;
2410                         out_ie[initial_out_len + 8] = 0x00;
2411
2412                         break;
2413                 }
2414
2415                 i += (in_ie[i+1]+2); /*  to the next IE element */
2416         }
2417
2418         return ielength;
2419
2420 }
2421
2422
2423 /*  */
2424 /*  Ported from 8185: IsInPreAuthKeyList(). (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.) */
2425 /*  Added by Annie, 2006-05-07. */
2426 /*  */
2427 /*  Search by BSSID, */
2428 /*  Return Value: */
2429 /*              -1              :if there is no pre-auth key in the  table */
2430 /*              >= 0            :if there is pre-auth key, and   return the entry id */
2431 /*  */
2432 /*  */
2433
2434 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
2435 {
2436         struct security_priv *psecuritypriv = &Adapter->securitypriv;
2437         int i = 0;
2438
2439         do {
2440                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
2441                                 (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN))) {
2442                         break;
2443                 } else{
2444                         i++;
2445                         /* continue; */
2446                 }
2447
2448         } while (i < NUM_PMKID_CACHE);
2449
2450         if (i == NUM_PMKID_CACHE) {
2451                 i = -1;/*  Could not find. */
2452         } else {
2453                 /*  There is one Pre-Authentication Key for the specific BSSID. */
2454         }
2455
2456         return i;
2457
2458 }
2459
2460 /*  */
2461 /*  Check the RSN IE length */
2462 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
2463 /*  0-11th element in the array are the fixed IE */
2464 /*  12th element in the array is the IE */
2465 /*  13th element in the array is the IE length */
2466 /*  */
2467
2468 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
2469 {
2470         struct security_priv *psecuritypriv = &Adapter->securitypriv;
2471
2472         if (ie[13] <= 20) {
2473                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
2474                         ie[ie_len] = 1;
2475                         ie_len++;
2476                         ie[ie_len] = 0; /* PMKID count = 0x0100 */
2477                         ie_len++;
2478                         memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
2479
2480                         ie_len += 16;
2481                         ie[13] += 18;/* PMKID length = 2+16 */
2482
2483         }
2484         return ie_len;
2485 }
2486
2487 sint rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
2488 {
2489         u8 authmode = 0x0;
2490         uint    ielength;
2491         int iEntry;
2492
2493         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
2494         struct security_priv *psecuritypriv = &adapter->securitypriv;
2495         uint    ndisauthmode = psecuritypriv->ndisauthtype;
2496
2497         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
2498                  ("+rtw_restruct_sec_ie: ndisauthmode =%d\n", ndisauthmode));
2499
2500         /* copy fixed ie only */
2501         memcpy(out_ie, in_ie, 12);
2502         ielength = 12;
2503         if ((ndisauthmode == Ndis802_11AuthModeWPA) || (ndisauthmode == Ndis802_11AuthModeWPAPSK))
2504                         authmode = _WPA_IE_ID_;
2505         if ((ndisauthmode == Ndis802_11AuthModeWPA2) || (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
2506                         authmode = _WPA2_IE_ID_;
2507
2508         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
2509                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
2510
2511                 ielength += psecuritypriv->wps_ie_len;
2512         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
2513                 /* copy RSN or SSN */
2514                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
2515                 /* debug for CONFIG_IEEE80211W
2516                 {
2517                         int jj;
2518                         printk("supplicant_ie_length =%d &&&&&&&&&&&&&&&&&&&\n", psecuritypriv->supplicant_ie[1]+2);
2519                         for (jj = 0; jj < psecuritypriv->supplicant_ie[1]+2; jj++)
2520                                 printk(" %02x ", psecuritypriv->supplicant_ie[jj]);
2521                         printk("\n");
2522                 }*/
2523                 ielength += psecuritypriv->supplicant_ie[1]+2;
2524                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
2525         }
2526
2527         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
2528         if (iEntry < 0) {
2529                 return ielength;
2530         } else{
2531                 if (authmode == _WPA2_IE_ID_)
2532                         ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
2533         }
2534         return ielength;
2535 }
2536
2537 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
2538 {
2539         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2540         struct eeprom_priv *peepriv = &adapter->eeprompriv;
2541         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2542         u8 *myhwaddr = myid(peepriv);
2543
2544         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
2545
2546         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
2547
2548         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_conf);
2549         pdev_network->Configuration.BeaconPeriod = 100;
2550         pdev_network->Configuration.FHConfig.Length = 0;
2551         pdev_network->Configuration.FHConfig.HopPattern = 0;
2552         pdev_network->Configuration.FHConfig.HopSet = 0;
2553         pdev_network->Configuration.FHConfig.DwellTime = 0;
2554 }
2555
2556 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
2557 {
2558         int sz = 0;
2559         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2560         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2561         struct  security_priv *psecuritypriv = &adapter->securitypriv;
2562         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
2563         /* struct       xmit_priv *pxmitpriv = &adapter->xmitpriv; */
2564
2565         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0) ; /*  adhoc no 802.1x */
2566
2567         pdev_network->Rssi = 0;
2568
2569         switch (pregistrypriv->wireless_mode) {
2570         case WIRELESS_11B:
2571                 pdev_network->NetworkTypeInUse = (Ndis802_11DS);
2572                 break;
2573         case WIRELESS_11G:
2574         case WIRELESS_11BG:
2575         case WIRELESS_11_24N:
2576         case WIRELESS_11G_24N:
2577         case WIRELESS_11BG_24N:
2578                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2579                 break;
2580         case WIRELESS_11A:
2581         case WIRELESS_11A_5N:
2582                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2583                 break;
2584         case WIRELESS_11ABGN:
2585                 if (pregistrypriv->channel > 14)
2586                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2587                 else
2588                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2589                 break;
2590         default:
2591                 /*  TODO */
2592                 break;
2593         }
2594
2595         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
2596         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("pregistrypriv->channel =%d, pdev_network->Configuration.DSConfig = 0x%x\n", pregistrypriv->channel, pdev_network->Configuration.DSConfig));
2597
2598         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
2599                 pdev_network->Configuration.ATIMWindow = (0);
2600
2601         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
2602
2603         /*  1. Supported rates */
2604         /*  2. IE */
2605
2606         /* rtw_set_supported_rate(pdev_network->SupportedRates, pregistrypriv->wireless_mode) ;  will be called in rtw_generate_ie */
2607         sz = rtw_generate_ie(pregistrypriv);
2608
2609         pdev_network->IELength = sz;
2610
2611         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
2612
2613         /* notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd(); */
2614         /* pdev_network->IELength = cpu_to_le32(sz); */
2615 }
2616
2617 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
2618 {
2619 }
2620
2621 /* the function is at passive_level */
2622 void rtw_joinbss_reset(struct adapter *padapter)
2623 {
2624         u8 threshold;
2625         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2626
2627         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2628
2629         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
2630
2631         pmlmepriv->num_FortyMHzIntolerant = 0;
2632
2633         pmlmepriv->num_sta_no_ht = 0;
2634
2635         phtpriv->ampdu_enable = false;/* reset to disabled */
2636
2637         /*  TH = 1 => means that invalidate usb rx aggregation */
2638         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
2639         if (phtpriv->ht_option) {
2640                 if (padapter->registrypriv.wifi_spec == 1)
2641                         threshold = 1;
2642                 else
2643                         threshold = 0;
2644                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2645         } else{
2646                 threshold = 1;
2647                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2648         }
2649 }
2650
2651 void rtw_ht_use_default_setting(struct adapter *padapter)
2652 {
2653         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2654         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2655         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2656         bool            bHwLDPCSupport = false, bHwSTBCSupport = false;
2657         bool            bHwSupportBeamformer = false, bHwSupportBeamformee = false;
2658
2659         if (pregistrypriv->wifi_spec)
2660                 phtpriv->bss_coexist = 1;
2661         else
2662                 phtpriv->bss_coexist = 0;
2663
2664         phtpriv->sgi_40m = TEST_FLAG(pregistrypriv->short_gi, BIT1) ? true : false;
2665         phtpriv->sgi_20m = TEST_FLAG(pregistrypriv->short_gi, BIT0) ? true : false;
2666
2667         /*  LDPC support */
2668         rtw_hal_get_def_var(padapter, HAL_DEF_RX_LDPC, (u8 *)&bHwLDPCSupport);
2669         CLEAR_FLAGS(phtpriv->ldpc_cap);
2670         if (bHwLDPCSupport) {
2671                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT4))
2672                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_RX);
2673         }
2674         rtw_hal_get_def_var(padapter, HAL_DEF_TX_LDPC, (u8 *)&bHwLDPCSupport);
2675         if (bHwLDPCSupport) {
2676                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT5))
2677                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_TX);
2678         }
2679         if (phtpriv->ldpc_cap)
2680                 DBG_871X("[HT] Support LDPC = 0x%02X\n", phtpriv->ldpc_cap);
2681
2682         /*  STBC */
2683         rtw_hal_get_def_var(padapter, HAL_DEF_TX_STBC, (u8 *)&bHwSTBCSupport);
2684         CLEAR_FLAGS(phtpriv->stbc_cap);
2685         if (bHwSTBCSupport) {
2686                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT5))
2687                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX);
2688         }
2689         rtw_hal_get_def_var(padapter, HAL_DEF_RX_STBC, (u8 *)&bHwSTBCSupport);
2690         if (bHwSTBCSupport) {
2691                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT4))
2692                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX);
2693         }
2694         if (phtpriv->stbc_cap)
2695                 DBG_871X("[HT] Support STBC = 0x%02X\n", phtpriv->stbc_cap);
2696
2697         /*  Beamforming setting */
2698         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMER, (u8 *)&bHwSupportBeamformer);
2699         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMEE, (u8 *)&bHwSupportBeamformee);
2700         CLEAR_FLAGS(phtpriv->beamform_cap);
2701         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT4) && bHwSupportBeamformer) {
2702                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE);
2703                 DBG_871X("[HT] Support Beamformer\n");
2704         }
2705         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT5) && bHwSupportBeamformee) {
2706                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE);
2707                 DBG_871X("[HT] Support Beamformee\n");
2708         }
2709 }
2710
2711 void rtw_build_wmm_ie_ht(struct adapter *padapter, u8 *out_ie, uint *pout_len)
2712 {
2713         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
2714         int out_len;
2715         u8 *pframe;
2716
2717         if (padapter->mlmepriv.qospriv.qos_option == 0) {
2718                 out_len = *pout_len;
2719                 pframe = rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_,
2720                                                         _WMM_IE_Length_, WMM_IE, pout_len);
2721
2722                 padapter->mlmepriv.qospriv.qos_option = 1;
2723         }
2724 }
2725
2726 /* the function is >= passive_level */
2727 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len, u8 channel)
2728 {
2729         u32 ielen, out_len;
2730         enum HT_CAP_AMPDU_FACTOR max_rx_ampdu_factor;
2731         unsigned char *p, *pframe;
2732         struct rtw_ieee80211_ht_cap ht_capie;
2733         u8 cbw40_enable = 0, stbc_rx_enable = 0, rf_type = 0, operation_bw = 0;
2734         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2735         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2736         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2737         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2738
2739         phtpriv->ht_option = false;
2740
2741         out_len = *pout_len;
2742
2743         memset(&ht_capie, 0, sizeof(struct rtw_ieee80211_ht_cap));
2744
2745         ht_capie.cap_info = cpu_to_le16(IEEE80211_HT_CAP_DSSSCCK40);
2746
2747         if (phtpriv->sgi_20m)
2748                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_20);
2749
2750         /* Get HT BW */
2751         if (in_ie == NULL) {
2752                 /* TDLS: TODO 20/40 issue */
2753                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
2754                         operation_bw = padapter->mlmeextpriv.cur_bwmode;
2755                         if (operation_bw > CHANNEL_WIDTH_40)
2756                                 operation_bw = CHANNEL_WIDTH_40;
2757                 } else
2758                         /* TDLS: TODO 40? */
2759                         operation_bw = CHANNEL_WIDTH_40;
2760         } else {
2761                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
2762                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2763                         struct HT_info_element *pht_info = (struct HT_info_element *)(p+2);
2764                         if (pht_info->infos[0] & BIT(2)) {
2765                                 switch (pht_info->infos[0] & 0x3) {
2766                                 case 1:
2767                                 case 3:
2768                                         operation_bw = CHANNEL_WIDTH_40;
2769                                         break;
2770                                 default:
2771                                         operation_bw = CHANNEL_WIDTH_20;
2772                                         break;
2773                                 }
2774                         } else {
2775                                 operation_bw = CHANNEL_WIDTH_20;
2776                         }
2777                 }
2778         }
2779
2780         /* to disable 40M Hz support while gd_bw_40MHz_en = 0 */
2781         if (channel > 14) {
2782                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
2783                         cbw40_enable = 1;
2784         } else {
2785                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
2786                         cbw40_enable = 1;
2787         }
2788
2789         if ((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) {
2790                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH);
2791                 if (phtpriv->sgi_40m)
2792                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_40);
2793         }
2794
2795         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX))
2796                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_TX_STBC);
2797
2798         /* todo: disable SM power save mode */
2799         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SM_PS);
2800
2801         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX)) {
2802                 if ((channel <= 14 && pregistrypriv->rx_stbc == 0x1) || /* enable for 2.4GHz */
2803                         (pregistrypriv->wifi_spec == 1)) {
2804                         stbc_rx_enable = 1;
2805                         DBG_871X("declare supporting RX STBC\n");
2806                 }
2807         }
2808
2809         /* fill default supported_mcs_set */
2810         memcpy(ht_capie.supp_mcs_set, pmlmeext->default_supported_mcs_set, 16);
2811
2812         /* update default supported_mcs_set */
2813         rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2814
2815         switch (rf_type) {
2816         case RF_1T1R:
2817                 if (stbc_rx_enable)
2818                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_1R);/* RX STBC One spatial stream */
2819
2820                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_1R);
2821                 break;
2822
2823         case RF_2T2R:
2824         case RF_1T2R:
2825         default:
2826                 if (stbc_rx_enable)
2827                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_2R);/* RX STBC two spatial stream */
2828
2829                 #ifdef CONFIG_DISABLE_MCS13TO15
2830                 if (((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) && (pregistrypriv->wifi_spec != 1))
2831                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R_13TO15_OFF);
2832                 else
2833                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
2834                 #else /* CONFIG_DISABLE_MCS13TO15 */
2835                         set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
2836                 #endif /* CONFIG_DISABLE_MCS13TO15 */
2837                 break;
2838         }
2839
2840         {
2841                 u32 rx_packet_offset, max_recvbuf_sz;
2842                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
2843                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
2844         }
2845
2846         if (padapter->driver_rx_ampdu_factor != 0xFF)
2847                 max_rx_ampdu_factor =
2848                   (enum HT_CAP_AMPDU_FACTOR)padapter->driver_rx_ampdu_factor;
2849         else
2850                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR,
2851                                     &max_rx_ampdu_factor);
2852
2853         /* rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor); */
2854         ht_capie.ampdu_params_info = (max_rx_ampdu_factor&0x03);
2855
2856         if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
2857                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&(0x07<<2));
2858         else
2859                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
2860
2861         pframe = rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
2862                                                 sizeof(struct rtw_ieee80211_ht_cap), (unsigned char *)&ht_capie, pout_len);
2863
2864         phtpriv->ht_option = true;
2865
2866         if (in_ie != NULL) {
2867                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
2868                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2869                         out_len = *pout_len;
2870                         pframe = rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2, pout_len);
2871                 }
2872         }
2873
2874         return phtpriv->ht_option;
2875
2876 }
2877
2878 /* the function is > passive_level (in critical_section) */
2879 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len, u8 channel)
2880 {
2881         u8 *p, max_ampdu_sz;
2882         int len;
2883         /* struct sta_info *bmc_sta, *psta; */
2884         struct rtw_ieee80211_ht_cap *pht_capie;
2885         struct ieee80211_ht_addt_info *pht_addtinfo;
2886         /* struct recv_reorder_ctrl *preorder_ctrl; */
2887         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2888         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2889         /* struct recv_priv *precvpriv = &padapter->recvpriv; */
2890         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2891         /* struct wlan_network *pcur_network = &(pmlmepriv->cur_network);; */
2892         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2893         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
2894         u8 cbw40_enable = 0;
2895
2896
2897         if (!phtpriv->ht_option)
2898                 return;
2899
2900         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
2901                 return;
2902
2903         DBG_871X("+rtw_update_ht_cap()\n");
2904
2905         /* maybe needs check if ap supports rx ampdu. */
2906         if ((phtpriv->ampdu_enable == false) && (pregistrypriv->ampdu_enable == 1)) {
2907                 if (pregistrypriv->wifi_spec == 1) {
2908                         /* remove this part because testbed AP should disable RX AMPDU */
2909                         /* phtpriv->ampdu_enable = false; */
2910                         phtpriv->ampdu_enable = true;
2911                 } else {
2912                         phtpriv->ampdu_enable = true;
2913                 }
2914         } else if (pregistrypriv->ampdu_enable == 2) {
2915                 /* remove this part because testbed AP should disable RX AMPDU */
2916                 /* phtpriv->ampdu_enable = true; */
2917         }
2918
2919
2920         /* check Max Rx A-MPDU Size */
2921         len = 0;
2922         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fix_ie), _HT_CAPABILITY_IE_, &len, ie_len-sizeof(struct ndis_802_11_fix_ie));
2923         if (p && len > 0) {
2924                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);
2925                 max_ampdu_sz = (pht_capie->ampdu_params_info & IEEE80211_HT_CAP_AMPDU_FACTOR);
2926                 max_ampdu_sz = 1 << (max_ampdu_sz+3); /*  max_ampdu_sz (kbytes); */
2927
2928                 /* DBG_871X("rtw_update_ht_cap(): max_ampdu_sz =%d\n", max_ampdu_sz); */
2929                 phtpriv->rx_ampdu_maxlen = max_ampdu_sz;
2930
2931         }
2932
2933
2934         len = 0;
2935         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fix_ie), _HT_ADD_INFO_IE_, &len, ie_len-sizeof(struct ndis_802_11_fix_ie));
2936         if (p && len > 0) {
2937                 pht_addtinfo = (struct ieee80211_ht_addt_info *)(p+2);
2938                 /* todo: */
2939         }
2940
2941         if (channel > 14) {
2942                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
2943                         cbw40_enable = 1;
2944         } else {
2945                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
2946                         cbw40_enable = 1;
2947         }
2948
2949         /* update cur_bwmode & cur_ch_offset */
2950         if ((cbw40_enable) &&
2951             (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
2952               BIT(1)) && (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
2953                 int i;
2954                 u8 rf_type;
2955
2956                 rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2957
2958                 /* update the MCS set */
2959                 for (i = 0; i < 16; i++)
2960                         pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= pmlmeext->default_supported_mcs_set[i];
2961
2962                 /* update the MCS rates */
2963                 switch (rf_type) {
2964                 case RF_1T1R:
2965                 case RF_1T2R:
2966                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_1R);
2967                         break;
2968                 case RF_2T2R:
2969                 default:
2970 #ifdef CONFIG_DISABLE_MCS13TO15
2971                         if (pmlmeext->cur_bwmode == CHANNEL_WIDTH_40 && pregistrypriv->wifi_spec != 1)
2972                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R_13TO15_OFF);
2973                         else
2974                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
2975 #else /* CONFIG_DISABLE_MCS13TO15 */
2976                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
2977 #endif /* CONFIG_DISABLE_MCS13TO15 */
2978                 }
2979
2980                 /* switch to the 40M Hz mode according to the AP */
2981                 /* pmlmeext->cur_bwmode = CHANNEL_WIDTH_40; */
2982                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
2983                 case EXTCHNL_OFFSET_UPPER:
2984                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
2985                         break;
2986
2987                 case EXTCHNL_OFFSET_LOWER:
2988                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
2989                         break;
2990
2991                 default:
2992                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
2993                         break;
2994                 }
2995         }
2996
2997         /*  */
2998         /*  Config SM Power Save setting */
2999         /*  */
3000         pmlmeinfo->SM_PS =
3001                 (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
3002                  0x0C) >> 2;
3003         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
3004                 DBG_871X("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
3005
3006         /*  */
3007         /*  Config current HT Protection mode. */
3008         /*  */
3009         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
3010 }
3011
3012 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
3013 {
3014         u8 issued;
3015         int priority;
3016         struct sta_info *psta = NULL;
3017         struct ht_priv *phtpriv;
3018         struct pkt_attrib *pattrib = &pxmitframe->attrib;
3019         s32 bmcst = IS_MCAST(pattrib->ra);
3020
3021         /* if (bmcst || (padapter->mlmepriv.LinkDetectInfo.bTxBusyTraffic == false)) */
3022         if (bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100))
3023                 return;
3024
3025         priority = pattrib->priority;
3026
3027         psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
3028         if (pattrib->psta != psta) {
3029                 DBG_871X("%s, pattrib->psta(%p) != psta(%p)\n", __func__, pattrib->psta, psta);
3030                 return;
3031         }
3032
3033         if (psta == NULL) {
3034                 DBG_871X("%s, psta ==NUL\n", __func__);
3035                 return;
3036         }
3037
3038         if (!(psta->state & _FW_LINKED)) {
3039                 DBG_871X("%s, psta->state(0x%x) != _FW_LINKED\n", __func__, psta->state);
3040                 return;
3041         }
3042
3043
3044         phtpriv = &psta->htpriv;
3045
3046         if ((phtpriv->ht_option == true) && (phtpriv->ampdu_enable == true)) {
3047                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
3048                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
3049
3050                 if (0 == issued) {
3051                         DBG_871X("rtw_issue_addbareq_cmd, p =%d\n", priority);
3052                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
3053                         rtw_addbareq_cmd(padapter, (u8) priority, pattrib->ra);
3054                 }
3055         }
3056
3057 }
3058
3059 void rtw_append_exented_cap(struct adapter *padapter, u8 *out_ie, uint *pout_len)
3060 {
3061         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3062         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
3063         u8 cap_content[8] = {0};
3064         u8 *pframe;
3065
3066
3067         if (phtpriv->bss_coexist) {
3068                 SET_EXT_CAPABILITY_ELE_BSS_COEXIST(cap_content, 1);
3069         }
3070
3071         pframe = rtw_set_ie(out_ie + *pout_len, EID_EXTCapability, 8, cap_content, pout_len);
3072 }
3073
3074 inline void rtw_set_to_roam(struct adapter *adapter, u8 to_roam)
3075 {
3076         if (to_roam == 0)
3077                 adapter->mlmepriv.to_join = false;
3078         adapter->mlmepriv.to_roam = to_roam;
3079 }
3080
3081 inline u8 rtw_dec_to_roam(struct adapter *adapter)
3082 {
3083         adapter->mlmepriv.to_roam--;
3084         return adapter->mlmepriv.to_roam;
3085 }
3086
3087 inline u8 rtw_to_roam(struct adapter *adapter)
3088 {
3089         return adapter->mlmepriv.to_roam;
3090 }
3091
3092 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3093 {
3094         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3095
3096         spin_lock_bh(&pmlmepriv->lock);
3097         _rtw_roaming(padapter, tgt_network);
3098         spin_unlock_bh(&pmlmepriv->lock);
3099 }
3100 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3101 {
3102         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3103         struct wlan_network *cur_network = &pmlmepriv->cur_network;
3104         int do_join_r;
3105
3106         if (0 < rtw_to_roam(padapter)) {
3107                 DBG_871X("roaming from %s("MAC_FMT"), length:%d\n",
3108                                 cur_network->network.Ssid.Ssid, MAC_ARG(cur_network->network.MacAddress),
3109                                 cur_network->network.Ssid.SsidLength);
3110                 memcpy(&pmlmepriv->assoc_ssid, &cur_network->network.Ssid, sizeof(struct ndis_802_11_ssid));
3111
3112                 pmlmepriv->assoc_by_bssid = false;
3113
3114                 while (1) {
3115                         do_join_r = rtw_do_join(padapter);
3116                         if (_SUCCESS == do_join_r) {
3117                                 break;
3118                         } else {
3119                                 DBG_871X("roaming do_join return %d\n", do_join_r);
3120                                 rtw_dec_to_roam(padapter);
3121
3122                                 if (rtw_to_roam(padapter) > 0) {
3123                                         continue;
3124                                 } else {
3125                                         DBG_871X("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
3126                                         rtw_indicate_disconnect(padapter);
3127                                         break;
3128                                 }
3129                         }
3130                 }
3131         }
3132
3133 }
3134
3135 sint rtw_linked_check(struct adapter *padapter)
3136 {
3137         if ((check_fwstate(&padapter->mlmepriv, WIFI_AP_STATE) == true) ||
3138                         (check_fwstate(&padapter->mlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE) == true)) {
3139                 if (padapter->stapriv.asoc_sta_count > 2)
3140                         return true;
3141         } else{ /* Station mode */
3142                 if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == true)
3143                         return true;
3144         }
3145         return false;
3146 }