GNU Linux-libre 5.10.215-gnu1
[releases.git] / drivers / staging / rtl8723bs / os_dep / ioctl_linux.c
1 // SPDX-License-Identifier: GPL-2.0
2 /******************************************************************************
3  *
4  * Copyright(c) 2007 - 2012 Realtek Corporation. All rights reserved.
5  *
6  ******************************************************************************/
7 #define _IOCTL_LINUX_C_
8
9 #include <linux/etherdevice.h>
10 #include <drv_types.h>
11 #include <rtw_debug.h>
12 #include <rtw_mp.h>
13 #include <hal_btcoex.h>
14 #include <linux/jiffies.h>
15 #include <linux/kernel.h>
16
17 #define RTL_IOCTL_WPA_SUPPLICANT        (SIOCIWFIRSTPRIV+30)
18
19 #define SCAN_ITEM_SIZE 768
20 #define MAX_CUSTOM_LEN 64
21 #define RATE_COUNT 4
22
23 /*  combo scan */
24 #define WEXT_CSCAN_HEADER               "CSCAN S\x01\x00\x00S\x00"
25 #define WEXT_CSCAN_HEADER_SIZE          12
26 #define WEXT_CSCAN_SSID_SECTION         'S'
27 #define WEXT_CSCAN_CHANNEL_SECTION      'C'
28 #define WEXT_CSCAN_ACTV_DWELL_SECTION   'A'
29 #define WEXT_CSCAN_PASV_DWELL_SECTION   'P'
30 #define WEXT_CSCAN_HOME_DWELL_SECTION   'H'
31 #define WEXT_CSCAN_TYPE_SECTION         'T'
32
33 static u32 rtw_rates[] = {1000000, 2000000, 5500000, 11000000,
34         6000000, 9000000, 12000000, 18000000, 24000000, 36000000, 48000000, 54000000};
35
36 static const char * const iw_operation_mode[] = {
37         "Auto", "Ad-Hoc", "Managed",  "Master", "Repeater", "Secondary", "Monitor"
38 };
39
40 void indicate_wx_scan_complete_event(struct adapter *padapter)
41 {
42         union iwreq_data wrqu;
43
44         memset(&wrqu, 0, sizeof(union iwreq_data));
45
46         /* DBG_871X("+rtw_indicate_wx_scan_complete_event\n"); */
47 }
48
49
50 void rtw_indicate_wx_assoc_event(struct adapter *padapter)
51 {
52         union iwreq_data wrqu;
53         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
54         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
55         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
56         struct wlan_bssid_ex            *pnetwork = (struct wlan_bssid_ex *)(&(pmlmeinfo->network));
57
58         memset(&wrqu, 0, sizeof(union iwreq_data));
59
60         wrqu.ap_addr.sa_family = ARPHRD_ETHER;
61
62         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true)
63                 memcpy(wrqu.ap_addr.sa_data, pnetwork->MacAddress, ETH_ALEN);
64         else
65                 memcpy(wrqu.ap_addr.sa_data, pmlmepriv->cur_network.network.MacAddress, ETH_ALEN);
66
67         DBG_871X_LEVEL(_drv_always_, "assoc success\n");
68 }
69
70 void rtw_indicate_wx_disassoc_event(struct adapter *padapter)
71 {
72         union iwreq_data wrqu;
73
74         memset(&wrqu, 0, sizeof(union iwreq_data));
75
76         wrqu.ap_addr.sa_family = ARPHRD_ETHER;
77         eth_zero_addr(wrqu.ap_addr.sa_data);
78 }
79
80 static char *translate_scan(struct adapter *padapter,
81                                 struct iw_request_info* info, struct wlan_network *pnetwork,
82                                 char *start, char *stop)
83 {
84         struct iw_event iwe;
85         u16 cap;
86         u32 ht_ielen = 0;
87         char *custom = NULL;
88         char *p;
89         u16 max_rate = 0, rate, ht_cap = false, vht_cap = false;
90         u32 i = 0;
91         u8 bw_40MHz = 0, short_GI = 0;
92         u16 mcs_rate = 0, vht_data_rate = 0;
93         u8 ie_offset = (pnetwork->network.Reserved[0] == 2 ? 0 : 12);
94         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
95         u8 ss, sq;
96
97         /*  AP MAC address  */
98         iwe.cmd = SIOCGIWAP;
99         iwe.u.ap_addr.sa_family = ARPHRD_ETHER;
100
101         memcpy(iwe.u.ap_addr.sa_data, pnetwork->network.MacAddress, ETH_ALEN);
102         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_ADDR_LEN);
103
104         /* Add the ESSID */
105         iwe.cmd = SIOCGIWESSID;
106         iwe.u.data.flags = 1;
107         iwe.u.data.length = min((u16)pnetwork->network.Ssid.SsidLength, (u16)32);
108         start = iwe_stream_add_point(info, start, stop, &iwe, pnetwork->network.Ssid.Ssid);
109
110         /* parsing HT_CAP_IE */
111         if (pnetwork->network.Reserved[0] == 2) { /*  Probe Request */
112                 p = rtw_get_ie(&pnetwork->network.IEs[0], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength);
113         } else {
114                 p = rtw_get_ie(&pnetwork->network.IEs[12], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength-12);
115         }
116         if (p && ht_ielen > 0) {
117                 struct rtw_ieee80211_ht_cap *pht_capie;
118                 ht_cap = true;
119                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);
120                 memcpy(&mcs_rate, pht_capie->supp_mcs_set, 2);
121                 bw_40MHz = (le16_to_cpu(pht_capie->cap_info) & IEEE80211_HT_CAP_SUP_WIDTH) ? 1 : 0;
122                 short_GI = (le16_to_cpu(pht_capie->cap_info) & (IEEE80211_HT_CAP_SGI_20 | IEEE80211_HT_CAP_SGI_40)) ? 1 : 0;
123         }
124
125         /* Add the protocol name */
126         iwe.cmd = SIOCGIWNAME;
127         if (rtw_is_cckratesonly_included((u8 *)&pnetwork->network.SupportedRates)) {
128                 if (ht_cap)
129                         snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11bn");
130                 else
131                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11b");
132         } else if (rtw_is_cckrates_included((u8 *)&pnetwork->network.SupportedRates)) {
133                 if (ht_cap)
134                         snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11bgn");
135                 else
136                         snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11bg");
137         } else {
138                 if (pnetwork->network.Configuration.DSConfig > 14) {
139                         if (vht_cap)
140                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11AC");
141                         else if (ht_cap)
142                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11an");
143                         else
144                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11a");
145                 } else {
146                         if (ht_cap)
147                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11gn");
148                         else
149                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11g");
150                 }
151         }
152
153         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_CHAR_LEN);
154
155           /* Add mode */
156         if (pnetwork->network.Reserved[0] == 2) { /*  Probe Request */
157                 cap = 0;
158         } else {
159                 __le16 le_tmp;
160
161                 iwe.cmd = SIOCGIWMODE;
162                 memcpy((u8 *)&le_tmp, rtw_get_capability_from_ie(pnetwork->network.IEs), 2);
163                 cap = le16_to_cpu(le_tmp);
164         }
165
166         if (cap & (WLAN_CAPABILITY_IBSS | WLAN_CAPABILITY_BSS)) {
167                 if (cap & WLAN_CAPABILITY_BSS)
168                         iwe.u.mode = IW_MODE_MASTER;
169                 else
170                         iwe.u.mode = IW_MODE_ADHOC;
171
172                 start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_UINT_LEN);
173         }
174
175         if (pnetwork->network.Configuration.DSConfig < 1 /*|| pnetwork->network.Configuration.DSConfig > 14*/)
176                 pnetwork->network.Configuration.DSConfig = 1;
177
178          /* Add frequency/channel */
179         iwe.cmd = SIOCGIWFREQ;
180         iwe.u.freq.m = rtw_ch2freq(pnetwork->network.Configuration.DSConfig) * 100000;
181         iwe.u.freq.e = 1;
182         iwe.u.freq.i = pnetwork->network.Configuration.DSConfig;
183         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_FREQ_LEN);
184
185         /* Add encryption capability */
186         iwe.cmd = SIOCGIWENCODE;
187         if (cap & WLAN_CAPABILITY_PRIVACY)
188                 iwe.u.data.flags = IW_ENCODE_ENABLED | IW_ENCODE_NOKEY;
189         else
190                 iwe.u.data.flags = IW_ENCODE_DISABLED;
191         iwe.u.data.length = 0;
192         start = iwe_stream_add_point(info, start, stop, &iwe, pnetwork->network.Ssid.Ssid);
193
194         /*Add basic and extended rates */
195         max_rate = 0;
196         custom = kzalloc(MAX_CUSTOM_LEN, GFP_ATOMIC);
197         if (!custom)
198                 return start;
199         p = custom;
200         p += scnprintf(p, MAX_CUSTOM_LEN - (p - custom), " Rates (Mb/s): ");
201         while (pnetwork->network.SupportedRates[i] != 0) {
202                 rate = pnetwork->network.SupportedRates[i]&0x7F;
203                 if (rate > max_rate)
204                         max_rate = rate;
205                 p += scnprintf(p, MAX_CUSTOM_LEN - (p - custom),
206                               "%d%s ", rate >> 1, (rate & 1) ? ".5" : "");
207                 i++;
208         }
209
210         if (vht_cap) {
211                 max_rate = vht_data_rate;
212         } else if (ht_cap) {
213                 if (mcs_rate&0x8000) { /* MCS15 */
214                         max_rate = (bw_40MHz) ? ((short_GI)?300:270):((short_GI)?144:130);
215                 } else { /* default MCS7 */
216                         /* DBG_871X("wx_get_scan, mcs_rate_bitmap = 0x%x\n", mcs_rate); */
217                         max_rate = (bw_40MHz) ? ((short_GI)?150:135):((short_GI)?72:65);
218                 }
219
220                 max_rate = max_rate*2;/* Mbps/2; */
221         }
222
223         iwe.cmd = SIOCGIWRATE;
224         iwe.u.bitrate.fixed = iwe.u.bitrate.disabled = 0;
225         iwe.u.bitrate.value = max_rate * 500000;
226         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_PARAM_LEN);
227
228         /* parsing WPA/WPA2 IE */
229         if (pnetwork->network.Reserved[0] != 2) { /*  Probe Request */
230                 u8 *buf;
231                 u8 wpa_ie[255], rsn_ie[255];
232                 u16 wpa_len = 0, rsn_len = 0;
233                 u8 *p;
234                 rtw_get_sec_ie(pnetwork->network.IEs, pnetwork->network.IELength, rsn_ie, &rsn_len, wpa_ie, &wpa_len);
235                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_wx_get_scan: ssid =%s\n", pnetwork->network.Ssid.Ssid));
236                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_wx_get_scan: wpa_len =%d rsn_len =%d\n", wpa_len, rsn_len));
237
238                 buf = kzalloc(MAX_WPA_IE_LEN*2, GFP_ATOMIC);
239                 if (!buf)
240                         return start;
241                 if (wpa_len > 0) {
242                         p = buf;
243                         p += sprintf(p, "wpa_ie =");
244                         for (i = 0; i < wpa_len; i++)
245                                 p += sprintf(p, "%02x", wpa_ie[i]);
246
247                         if (wpa_len > 100) {
248                                 printk("-----------------Len %d----------------\n", wpa_len);
249                                 for (i = 0; i < wpa_len; i++)
250                                         printk("%02x ", wpa_ie[i]);
251                                 printk("\n");
252                                 printk("-----------------Len %d----------------\n", wpa_len);
253                         }
254
255                         memset(&iwe, 0, sizeof(iwe));
256                         iwe.cmd = IWEVCUSTOM;
257                         iwe.u.data.length = strlen(buf);
258                         start = iwe_stream_add_point(info, start, stop, &iwe, buf);
259
260                         memset(&iwe, 0, sizeof(iwe));
261                         iwe.cmd = IWEVGENIE;
262                         iwe.u.data.length = wpa_len;
263                         start = iwe_stream_add_point(info, start, stop, &iwe, wpa_ie);
264                 }
265                 if (rsn_len > 0) {
266                         p = buf;
267                         memset(buf, 0, MAX_WPA_IE_LEN*2);
268                         p += sprintf(p, "rsn_ie =");
269                         for (i = 0; i < rsn_len; i++)
270                                 p += sprintf(p, "%02x", rsn_ie[i]);
271                         memset(&iwe, 0, sizeof(iwe));
272                         iwe.cmd = IWEVCUSTOM;
273                         iwe.u.data.length = strlen(buf);
274                         start = iwe_stream_add_point(info, start, stop, &iwe, buf);
275
276                         memset(&iwe, 0, sizeof(iwe));
277                         iwe.cmd = IWEVGENIE;
278                         iwe.u.data.length = rsn_len;
279                         start = iwe_stream_add_point(info, start, stop, &iwe, rsn_ie);
280                 }
281                 kfree(buf);
282         }
283
284         { /* parsing WPS IE */
285                 uint cnt = 0, total_ielen;
286                 u8 *wpsie_ptr = NULL;
287                 uint wps_ielen = 0;
288
289                 u8 *ie_ptr;
290                 total_ielen = pnetwork->network.IELength - ie_offset;
291
292                 if (pnetwork->network.Reserved[0] == 2) { /*  Probe Request */
293                         ie_ptr = pnetwork->network.IEs;
294                         total_ielen = pnetwork->network.IELength;
295                 } else {    /*  Beacon or Probe Respones */
296                         ie_ptr = pnetwork->network.IEs + _FIXED_IE_LENGTH_;
297                         total_ielen = pnetwork->network.IELength - _FIXED_IE_LENGTH_;
298                 }
299
300                 while (cnt < total_ielen) {
301                         if (rtw_is_wps_ie(&ie_ptr[cnt], &wps_ielen) && (wps_ielen > 2)) {
302                                 wpsie_ptr = &ie_ptr[cnt];
303                                 iwe.cmd = IWEVGENIE;
304                                 iwe.u.data.length = (u16)wps_ielen;
305                                 start = iwe_stream_add_point(info, start, stop, &iwe, wpsie_ptr);
306                         }
307                         cnt += ie_ptr[cnt + 1] + 2; /* goto next */
308                 }
309         }
310
311         /* Add quality statistics */
312         iwe.cmd = IWEVQUAL;
313         iwe.u.qual.updated = IW_QUAL_QUAL_UPDATED | IW_QUAL_LEVEL_UPDATED
314         #if defined(CONFIG_SIGNAL_DISPLAY_DBM) && defined(CONFIG_BACKGROUND_NOISE_MONITOR)
315                 | IW_QUAL_NOISE_UPDATED
316         #else
317                 | IW_QUAL_NOISE_INVALID
318         #endif
319         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
320                 | IW_QUAL_DBM
321         #endif
322         ;
323
324         if (check_fwstate(pmlmepriv, _FW_LINKED) == true &&
325                 is_same_network(&pmlmepriv->cur_network.network, &pnetwork->network, 0)) {
326                 ss = padapter->recvpriv.signal_strength;
327                 sq = padapter->recvpriv.signal_qual;
328         } else {
329                 ss = pnetwork->network.PhyInfo.SignalStrength;
330                 sq = pnetwork->network.PhyInfo.SignalQuality;
331         }
332
333
334         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
335         iwe.u.qual.level = (u8)translate_percentage_to_dbm(ss);/* dbm */
336         #else
337         #ifdef CONFIG_SKIP_SIGNAL_SCALE_MAPPING
338         {
339                 /* Do signal scale mapping when using percentage as the unit of signal strength, since the scale mapping is skipped in odm */
340
341                 struct hal_com_data *pHal = GET_HAL_DATA(padapter);
342
343                 iwe.u.qual.level = (u8)odm_SignalScaleMapping(&pHal->odmpriv, ss);
344         }
345         #else
346         iwe.u.qual.level = (u8)ss;/*  */
347         #endif
348         #endif
349
350         iwe.u.qual.qual = (u8)sq;   /*  signal quality */
351
352         #if defined(CONFIG_SIGNAL_DISPLAY_DBM) && defined(CONFIG_BACKGROUND_NOISE_MONITOR)
353         {
354                 s16 tmp_noise = 0;
355                 rtw_hal_get_odm_var(padapter, HAL_ODM_NOISE_MONITOR, &(pnetwork->network.Configuration.DSConfig), &(tmp_noise));
356                 iwe.u.qual.noise = tmp_noise;
357         }
358         #else
359         iwe.u.qual.noise = 0; /*  noise level */
360         #endif
361
362         /* DBG_871X("iqual =%d, ilevel =%d, inoise =%d, iupdated =%d\n", iwe.u.qual.qual, iwe.u.qual.level , iwe.u.qual.noise, iwe.u.qual.updated); */
363
364         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_QUAL_LEN);
365
366         {
367                 u8 *buf;
368                 u8 *p, *pos;
369
370                 buf = kzalloc(MAX_WPA_IE_LEN, GFP_ATOMIC);
371                 if (!buf)
372                         goto exit;
373                 p = buf;
374                 pos = pnetwork->network.Reserved;
375                 p += sprintf(p, "fm =%02X%02X", pos[1], pos[0]);
376                 memset(&iwe, 0, sizeof(iwe));
377                 iwe.cmd = IWEVCUSTOM;
378                 iwe.u.data.length = strlen(buf);
379                 start = iwe_stream_add_point(info, start, stop, &iwe, buf);
380                 kfree(buf);
381         }
382 exit:
383         kfree(custom);
384
385         return start;
386 }
387
388 static int wpa_set_auth_algs(struct net_device *dev, u32 value)
389 {
390         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
391         int ret = 0;
392
393         if ((value & WLAN_AUTH_SHARED_KEY) && (value & WLAN_AUTH_OPEN)) {
394                 DBG_871X("wpa_set_auth_algs, WLAN_AUTH_SHARED_KEY and WLAN_AUTH_OPEN [value:0x%x]\n", value);
395                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
396                 padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
397                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
398         } else if (value & WLAN_AUTH_SHARED_KEY)        {
399                 DBG_871X("wpa_set_auth_algs, WLAN_AUTH_SHARED_KEY  [value:0x%x]\n", value);
400                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
401
402                 padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeShared;
403                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Shared;
404         } else if (value & WLAN_AUTH_OPEN) {
405                 DBG_871X("wpa_set_auth_algs, WLAN_AUTH_OPEN\n");
406                 /* padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled; */
407                 if (padapter->securitypriv.ndisauthtype < Ndis802_11AuthModeWPAPSK) {
408                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeOpen;
409                         padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
410                 }
411         } else if (value & WLAN_AUTH_LEAP) {
412                 DBG_871X("wpa_set_auth_algs, WLAN_AUTH_LEAP\n");
413         } else {
414                 DBG_871X("wpa_set_auth_algs, error!\n");
415                 ret = -EINVAL;
416         }
417
418         return ret;
419
420 }
421
422 static int wpa_set_encryption(struct net_device *dev, struct ieee_param *param, u32 param_len)
423 {
424         int ret = 0;
425         u32 wep_key_idx, wep_key_len, wep_total_len;
426         struct ndis_802_11_wep   *pwep = NULL;
427         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
428         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
429         struct security_priv *psecuritypriv = &padapter->securitypriv;
430
431         param->u.crypt.err = 0;
432         param->u.crypt.alg[IEEE_CRYPT_ALG_NAME_LEN - 1] = '\0';
433
434         if (param_len < (u32)((u8 *)param->u.crypt.key - (u8 *)param) + param->u.crypt.key_len) {
435                 ret =  -EINVAL;
436                 goto exit;
437         }
438
439         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
440             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
441             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) {
442                 if (param->u.crypt.idx >= WEP_KEYS ||
443                     param->u.crypt.idx >= BIP_MAX_KEYID) {
444                         ret = -EINVAL;
445                         goto exit;
446                 }
447         } else {
448                 {
449                         ret = -EINVAL;
450                         goto exit;
451                 }
452         }
453
454         if (strcmp(param->u.crypt.alg, "WEP") == 0) {
455                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_err_, ("wpa_set_encryption, crypt.alg = WEP\n"));
456                 DBG_871X("wpa_set_encryption, crypt.alg = WEP\n");
457
458                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
459                 padapter->securitypriv.dot11PrivacyAlgrthm = _WEP40_;
460                 padapter->securitypriv.dot118021XGrpPrivacy = _WEP40_;
461
462                 wep_key_idx = param->u.crypt.idx;
463                 wep_key_len = param->u.crypt.key_len;
464
465                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_, ("(1)wep_key_idx =%d\n", wep_key_idx));
466                 DBG_871X("(1)wep_key_idx =%d\n", wep_key_idx);
467
468                 if (wep_key_idx > WEP_KEYS)
469                         return -EINVAL;
470
471                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_, ("(2)wep_key_idx =%d\n", wep_key_idx));
472
473                 if (wep_key_len > 0) {
474                         wep_key_len = wep_key_len <= 5 ? 5 : 13;
475                         wep_total_len = wep_key_len + FIELD_OFFSET(struct ndis_802_11_wep, KeyMaterial);
476                         pwep = kzalloc(wep_total_len, GFP_KERNEL);
477                         if (pwep == NULL) {
478                                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_err_, (" wpa_set_encryption: pwep allocate fail !!!\n"));
479                                 goto exit;
480                         }
481
482                         pwep->KeyLength = wep_key_len;
483                         pwep->Length = wep_total_len;
484
485                         if (wep_key_len == 13) {
486                                 padapter->securitypriv.dot11PrivacyAlgrthm = _WEP104_;
487                                 padapter->securitypriv.dot118021XGrpPrivacy = _WEP104_;
488                         }
489                 } else {
490                         ret = -EINVAL;
491                         goto exit;
492                 }
493
494                 pwep->KeyIndex = wep_key_idx;
495                 pwep->KeyIndex |= 0x80000000;
496
497                 memcpy(pwep->KeyMaterial,  param->u.crypt.key, pwep->KeyLength);
498
499                 if (param->u.crypt.set_tx) {
500                         DBG_871X("wep, set_tx = 1\n");
501
502                         if (rtw_set_802_11_add_wep(padapter, pwep) == (u8)_FAIL)
503                                 ret = -EOPNOTSUPP;
504                 } else {
505                         DBG_871X("wep, set_tx = 0\n");
506
507                         /* don't update "psecuritypriv->dot11PrivacyAlgrthm" and */
508                         /* psecuritypriv->dot11PrivacyKeyIndex =keyid", but can rtw_set_key to fw/cam */
509
510                         if (wep_key_idx >= WEP_KEYS) {
511                                 ret = -EOPNOTSUPP;
512                                 goto exit;
513                         }
514
515                         memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
516                         psecuritypriv->dot11DefKeylen[wep_key_idx] = pwep->KeyLength;
517                         rtw_set_key(padapter, psecuritypriv, wep_key_idx, 0, true);
518                 }
519
520                 goto exit;
521         }
522
523         if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) { /*  802_1x */
524                 struct sta_info *psta, *pbcmc_sta;
525                 struct sta_priv *pstapriv = &padapter->stapriv;
526
527                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_MP_STATE) == true) { /* sta mode */
528                         psta = rtw_get_stainfo(pstapriv, get_bssid(pmlmepriv));
529                         if (psta == NULL) {
530                                 /* DEBUG_ERR(("Set wpa_set_encryption: Obtain Sta_info fail\n")); */
531                         } else {
532                                 /* Jeff: don't disable ieee8021x_blocked while clearing key */
533                                 if (strcmp(param->u.crypt.alg, "none") != 0)
534                                         psta->ieee8021x_blocked = false;
535
536                                 if ((padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption2Enabled) ||
537                                                 (padapter->securitypriv.ndisencryptstatus ==  Ndis802_11Encryption3Enabled)) {
538                                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
539                                 }
540
541                                 if (param->u.crypt.set_tx == 1) { /* pairwise key */
542                                         memcpy(psta->dot118021x_UncstKey.skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
543
544                                         if (strcmp(param->u.crypt.alg, "TKIP") == 0) { /* set mic key */
545                                                 /* DEBUG_ERR(("\nset key length :param->u.crypt.key_len =%d\n", param->u.crypt.key_len)); */
546                                                 memcpy(psta->dot11tkiptxmickey.skey, &(param->u.crypt.key[16]), 8);
547                                                 memcpy(psta->dot11tkiprxmickey.skey, &(param->u.crypt.key[24]), 8);
548
549                                                 padapter->securitypriv.busetkipkey = false;
550                                                 /* _set_timer(&padapter->securitypriv.tkip_timer, 50); */
551                                         }
552
553                                         /* DEBUG_ERR((" param->u.crypt.key_len =%d\n", param->u.crypt.key_len)); */
554                                         DBG_871X(" ~~~~set sta key:unicastkey\n");
555
556                                         rtw_setstakey_cmd(padapter, psta, true, true);
557                                 } else { /* group key */
558                                         if (strcmp(param->u.crypt.alg, "TKIP") == 0 || strcmp(param->u.crypt.alg, "CCMP") == 0) {
559                                                 memcpy(padapter->securitypriv.dot118021XGrpKey[param->u.crypt.idx].skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
560                                                 /* only TKIP group key need to install this */
561                                                 if (param->u.crypt.key_len > 16) {
562                                                         memcpy(padapter->securitypriv.dot118021XGrptxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[16]), 8);
563                                                         memcpy(padapter->securitypriv.dot118021XGrprxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[24]), 8);
564                                                 }
565                                                 padapter->securitypriv.binstallGrpkey = true;
566                                                 /* DEBUG_ERR((" param->u.crypt.key_len =%d\n", param->u.crypt.key_len)); */
567                                                 DBG_871X(" ~~~~set sta key:groupkey\n");
568
569                                                 padapter->securitypriv.dot118021XGrpKeyid = param->u.crypt.idx;
570
571                                                 rtw_set_key(padapter, &padapter->securitypriv, param->u.crypt.idx, 1, true);
572                                         } else if (strcmp(param->u.crypt.alg, "BIP") == 0) {
573                                                 /* printk("BIP key_len =%d , index =%d @@@@@@@@@@@@@@@@@@\n", param->u.crypt.key_len, param->u.crypt.idx); */
574                                                 /* save the IGTK key, length 16 bytes */
575                                                 memcpy(padapter->securitypriv.dot11wBIPKey[param->u.crypt.idx].skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
576                                                 /*printk("IGTK key below:\n");
577                                                 for (no = 0;no<16;no++)
578                                                         printk(" %02x ", padapter->securitypriv.dot11wBIPKey[param->u.crypt.idx].skey[no]);
579                                                 printk("\n");*/
580                                                 padapter->securitypriv.dot11wBIPKeyid = param->u.crypt.idx;
581                                                 padapter->securitypriv.binstallBIPkey = true;
582                                                 DBG_871X(" ~~~~set sta key:IGKT\n");
583                                         }
584                                 }
585                         }
586
587                         pbcmc_sta = rtw_get_bcmc_stainfo(padapter);
588                         if (pbcmc_sta == NULL) {
589                                 /* DEBUG_ERR(("Set OID_802_11_ADD_KEY: bcmc stainfo is null\n")); */
590                         } else {
591                                 /* Jeff: don't disable ieee8021x_blocked while clearing key */
592                                 if (strcmp(param->u.crypt.alg, "none") != 0)
593                                         pbcmc_sta->ieee8021x_blocked = false;
594
595                                 if ((padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption2Enabled) ||
596                                                 (padapter->securitypriv.ndisencryptstatus ==  Ndis802_11Encryption3Enabled)) {
597                                         pbcmc_sta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
598                                 }
599                         }
600                 } else if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
601                         /* adhoc mode */
602                 }
603         }
604
605 exit:
606
607         kfree(pwep);
608         return ret;
609 }
610
611 static int rtw_set_wpa_ie(struct adapter *padapter, char *pie, unsigned short ielen)
612 {
613         u8 *buf = NULL;
614         int group_cipher = 0, pairwise_cipher = 0;
615         int ret = 0;
616         u8 null_addr[] = {0, 0, 0, 0, 0, 0};
617
618         if ((ielen > MAX_WPA_IE_LEN) || (pie == NULL)) {
619                 _clr_fwstate_(&padapter->mlmepriv, WIFI_UNDER_WPS);
620                 if (pie == NULL)
621                         return ret;
622                 else
623                         return -EINVAL;
624         }
625
626         if (ielen) {
627                 buf = rtw_zmalloc(ielen);
628                 if (buf == NULL) {
629                         ret =  -ENOMEM;
630                         goto exit;
631                 }
632
633                 memcpy(buf, pie, ielen);
634
635                 /* dump */
636                 {
637                         int i;
638                         DBG_871X("\n wpa_ie(length:%d):\n", ielen);
639                         for (i = 0; i < ielen; i = i + 8)
640                                 DBG_871X("0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x\n", buf[i], buf[i+1], buf[i+2], buf[i+3], buf[i+4], buf[i+5], buf[i+6], buf[i+7]);
641                 }
642
643                 if (ielen < RSN_HEADER_LEN) {
644                         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_err_, ("Ie len too short %d\n", ielen));
645                         ret  = -1;
646                         goto exit;
647                 }
648
649                 if (rtw_parse_wpa_ie(buf, ielen, &group_cipher, &pairwise_cipher, NULL) == _SUCCESS) {
650                         padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_8021X;
651                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPAPSK;
652                         memcpy(padapter->securitypriv.supplicant_ie, &buf[0], ielen);
653                 }
654
655                 if (rtw_parse_wpa2_ie(buf, ielen, &group_cipher, &pairwise_cipher, NULL) == _SUCCESS) {
656                         padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_8021X;
657                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPA2PSK;
658                         memcpy(padapter->securitypriv.supplicant_ie, &buf[0], ielen);
659                 }
660
661                 if (group_cipher == 0)
662                         group_cipher = WPA_CIPHER_NONE;
663                 if (pairwise_cipher == 0)
664                         pairwise_cipher = WPA_CIPHER_NONE;
665
666                 switch (group_cipher) {
667                         case WPA_CIPHER_NONE:
668                                 padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
669                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
670                                 break;
671                         case WPA_CIPHER_WEP40:
672                                 padapter->securitypriv.dot118021XGrpPrivacy = _WEP40_;
673                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
674                                 break;
675                         case WPA_CIPHER_TKIP:
676                                 padapter->securitypriv.dot118021XGrpPrivacy = _TKIP_;
677                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
678                                 break;
679                         case WPA_CIPHER_CCMP:
680                                 padapter->securitypriv.dot118021XGrpPrivacy = _AES_;
681                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
682                                 break;
683                         case WPA_CIPHER_WEP104:
684                                 padapter->securitypriv.dot118021XGrpPrivacy = _WEP104_;
685                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
686                                 break;
687                 }
688
689                 switch (pairwise_cipher) {
690                         case WPA_CIPHER_NONE:
691                                 padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
692                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
693                                 break;
694                         case WPA_CIPHER_WEP40:
695                                 padapter->securitypriv.dot11PrivacyAlgrthm = _WEP40_;
696                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
697                                 break;
698                         case WPA_CIPHER_TKIP:
699                                 padapter->securitypriv.dot11PrivacyAlgrthm = _TKIP_;
700                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
701                                 break;
702                         case WPA_CIPHER_CCMP:
703                                 padapter->securitypriv.dot11PrivacyAlgrthm = _AES_;
704                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
705                                 break;
706                         case WPA_CIPHER_WEP104:
707                                 padapter->securitypriv.dot11PrivacyAlgrthm = _WEP104_;
708                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
709                                 break;
710                 }
711
712                 _clr_fwstate_(&padapter->mlmepriv, WIFI_UNDER_WPS);
713                 {/* set wps_ie */
714                         u16 cnt = 0;
715                         u8 eid, wps_oui[4] = {0x0, 0x50, 0xf2, 0x04};
716
717                         while (cnt < ielen) {
718                                 eid = buf[cnt];
719
720                                 if ((eid == _VENDOR_SPECIFIC_IE_) && (!memcmp(&buf[cnt+2], wps_oui, 4))) {
721                                         DBG_871X("SET WPS_IE\n");
722
723                                         padapter->securitypriv.wps_ie_len = ((buf[cnt+1]+2) < MAX_WPS_IE_LEN) ? (buf[cnt+1]+2):MAX_WPS_IE_LEN;
724
725                                         memcpy(padapter->securitypriv.wps_ie, &buf[cnt], padapter->securitypriv.wps_ie_len);
726
727                                         set_fwstate(&padapter->mlmepriv, WIFI_UNDER_WPS);
728
729                                         cnt += buf[cnt+1]+2;
730
731                                         break;
732                                 } else {
733                                         cnt += buf[cnt+1]+2; /* goto next */
734                                 }
735                         }
736                 }
737         }
738
739         /* TKIP and AES disallow multicast packets until installing group key */
740         if (padapter->securitypriv.dot11PrivacyAlgrthm == _TKIP_
741                 || padapter->securitypriv.dot11PrivacyAlgrthm == _TKIP_WTMIC_
742                 || padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
743                 /* WPS open need to enable multicast */
744                 /*  check_fwstate(&padapter->mlmepriv, WIFI_UNDER_WPS) == true) */
745                 rtw_hal_set_hwreg(padapter, HW_VAR_OFF_RCR_AM, null_addr);
746
747         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
748                  ("rtw_set_wpa_ie: pairwise_cipher = 0x%08x padapter->securitypriv.ndisencryptstatus =%d padapter->securitypriv.ndisauthtype =%d\n",
749                   pairwise_cipher, padapter->securitypriv.ndisencryptstatus, padapter->securitypriv.ndisauthtype));
750
751 exit:
752
753         kfree(buf);
754
755         return ret;
756 }
757
758 static int rtw_wx_get_name(struct net_device *dev,
759                              struct iw_request_info *info,
760                              union iwreq_data *wrqu, char *extra)
761 {
762         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
763         u32 ht_ielen = 0;
764         char *p;
765         u8 ht_cap = false, vht_cap = false;
766         struct  mlme_priv *pmlmepriv = &(padapter->mlmepriv);
767         struct wlan_bssid_ex  *pcur_bss = &pmlmepriv->cur_network.network;
768         NDIS_802_11_RATES_EX* prates = NULL;
769
770         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("cmd_code =%x\n", info->cmd));
771
772         if (check_fwstate(pmlmepriv, _FW_LINKED|WIFI_ADHOC_MASTER_STATE) == true) {
773                 /* parsing HT_CAP_IE */
774                 p = rtw_get_ie(&pcur_bss->IEs[12], _HT_CAPABILITY_IE_, &ht_ielen, pcur_bss->IELength-12);
775                 if (p && ht_ielen > 0)
776                         ht_cap = true;
777
778                 prates = &pcur_bss->SupportedRates;
779
780                 if (rtw_is_cckratesonly_included((u8 *)prates)) {
781                         if (ht_cap)
782                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bn");
783                         else
784                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11b");
785                 } else if (rtw_is_cckrates_included((u8 *)prates)) {
786                         if (ht_cap)
787                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bgn");
788                         else
789                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bg");
790                 } else {
791                         if (pcur_bss->Configuration.DSConfig > 14) {
792                                 if (vht_cap)
793                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11AC");
794                                 else if (ht_cap)
795                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11an");
796                                 else
797                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11a");
798                         } else {
799                                 if (ht_cap)
800                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11gn");
801                                 else
802                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11g");
803                         }
804                 }
805         } else {
806                 /* prates = &padapter->registrypriv.dev_network.SupportedRates; */
807                 /* snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11g"); */
808                 snprintf(wrqu->name, IFNAMSIZ, "unassociated");
809         }
810         return 0;
811 }
812
813 static int rtw_wx_set_freq(struct net_device *dev,
814                              struct iw_request_info *info,
815                              union iwreq_data *wrqu, char *extra)
816 {
817         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_wx_set_freq\n"));
818
819         return 0;
820 }
821
822 static int rtw_wx_get_freq(struct net_device *dev,
823                              struct iw_request_info *info,
824                              union iwreq_data *wrqu, char *extra)
825 {
826         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
827         struct  mlme_priv *pmlmepriv = &(padapter->mlmepriv);
828         struct wlan_bssid_ex  *pcur_bss = &pmlmepriv->cur_network.network;
829
830         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
831                 /* wrqu->freq.m = ieee80211_wlan_frequencies[pcur_bss->Configuration.DSConfig-1] * 100000; */
832                 wrqu->freq.m = rtw_ch2freq(pcur_bss->Configuration.DSConfig) * 100000;
833                 wrqu->freq.e = 1;
834                 wrqu->freq.i = pcur_bss->Configuration.DSConfig;
835
836         } else {
837                 wrqu->freq.m = rtw_ch2freq(padapter->mlmeextpriv.cur_channel) * 100000;
838                 wrqu->freq.e = 1;
839                 wrqu->freq.i = padapter->mlmeextpriv.cur_channel;
840         }
841
842         return 0;
843 }
844
845 static int rtw_wx_set_mode(struct net_device *dev, struct iw_request_info *a,
846                              union iwreq_data *wrqu, char *b)
847 {
848         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
849         enum NDIS_802_11_NETWORK_INFRASTRUCTURE networkType;
850         int ret = 0;
851
852         if (_FAIL == rtw_pwr_wakeup(padapter)) {
853                 ret = -EPERM;
854                 goto exit;
855         }
856
857         if (!padapter->hw_init_completed) {
858                 ret = -EPERM;
859                 goto exit;
860         }
861
862         switch (wrqu->mode) {
863                 case IW_MODE_AUTO:
864                         networkType = Ndis802_11AutoUnknown;
865                         DBG_871X("set_mode = IW_MODE_AUTO\n");
866                         break;
867                 case IW_MODE_ADHOC:
868                         networkType = Ndis802_11IBSS;
869                         DBG_871X("set_mode = IW_MODE_ADHOC\n");
870                         break;
871                 case IW_MODE_MASTER:
872                         networkType = Ndis802_11APMode;
873                         DBG_871X("set_mode = IW_MODE_MASTER\n");
874                         /* rtw_setopmode_cmd(padapter, networkType, true); */
875                         break;
876                 case IW_MODE_INFRA:
877                         networkType = Ndis802_11Infrastructure;
878                         DBG_871X("set_mode = IW_MODE_INFRA\n");
879                         break;
880
881                 default:
882                         ret = -EINVAL;
883                         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_err_, ("\n Mode: %s is not supported \n", iw_operation_mode[wrqu->mode]));
884                         goto exit;
885         }
886
887 /*
888         if (Ndis802_11APMode == networkType)
889         {
890                 rtw_setopmode_cmd(padapter, networkType, true);
891         }
892         else
893         {
894                 rtw_setopmode_cmd(padapter, Ndis802_11AutoUnknown, true);
895         }
896 */
897
898         if (rtw_set_802_11_infrastructure_mode(padapter, networkType) == false) {
899
900                 ret = -EPERM;
901                 goto exit;
902
903         }
904
905         rtw_setopmode_cmd(padapter, networkType, true);
906
907 exit:
908         return ret;
909 }
910
911 static int rtw_wx_get_mode(struct net_device *dev, struct iw_request_info *a,
912                              union iwreq_data *wrqu, char *b)
913 {
914         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
915         struct  mlme_priv *pmlmepriv = &(padapter->mlmepriv);
916
917         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, (" rtw_wx_get_mode\n"));
918
919         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
920                 wrqu->mode = IW_MODE_INFRA;
921         } else if  ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
922                        (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
923                 wrqu->mode = IW_MODE_ADHOC;
924         } else if (check_fwstate(pmlmepriv, WIFI_AP_STATE) == true) {
925                 wrqu->mode = IW_MODE_MASTER;
926         } else {
927                 wrqu->mode = IW_MODE_AUTO;
928         }
929         return 0;
930 }
931
932
933 static int rtw_wx_set_pmkid(struct net_device *dev,
934                              struct iw_request_info *a,
935                              union iwreq_data *wrqu, char *extra)
936 {
937         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
938         u8          j, blInserted = false;
939         int         intReturn = false;
940         struct security_priv *psecuritypriv = &padapter->securitypriv;
941         struct iw_pmksa*  pPMK = (struct iw_pmksa *)extra;
942         u8     strZeroMacAddress[ETH_ALEN] = { 0x00 };
943         u8     strIssueBssid[ETH_ALEN] = { 0x00 };
944
945         /*
946         There are the BSSID information in the bssid.sa_data array.
947         If cmd is IW_PMKSA_FLUSH, it means the wpa_suppplicant wants to clear all the PMKID information.
948         If cmd is IW_PMKSA_ADD, it means the wpa_supplicant wants to add a PMKID/BSSID to driver.
949         If cmd is IW_PMKSA_REMOVE, it means the wpa_supplicant wants to remove a PMKID/BSSID from driver.
950         */
951
952         memcpy(strIssueBssid, pPMK->bssid.sa_data, ETH_ALEN);
953         if (pPMK->cmd == IW_PMKSA_ADD) {
954                 DBG_871X("[rtw_wx_set_pmkid] IW_PMKSA_ADD!\n");
955                 if (!memcmp(strIssueBssid, strZeroMacAddress, ETH_ALEN))
956                         return intReturn;
957                 else
958                     intReturn = true;
959
960                 blInserted = false;
961
962                 /* overwrite PMKID */
963                 for (j = 0; j < NUM_PMKID_CACHE; j++) {
964                         if (!memcmp(psecuritypriv->PMKIDList[j].Bssid, strIssueBssid, ETH_ALEN)) {
965                                 /*  BSSID is matched, the same AP => rewrite with new PMKID. */
966                                 DBG_871X("[rtw_wx_set_pmkid] BSSID exists in the PMKList.\n");
967
968                                 memcpy(psecuritypriv->PMKIDList[j].PMKID, pPMK->pmkid, IW_PMKID_LEN);
969                                 psecuritypriv->PMKIDList[j].bUsed = true;
970                                 psecuritypriv->PMKIDIndex = j+1;
971                                 blInserted = true;
972                                 break;
973                         }
974                 }
975
976                 if (!blInserted) {
977                     /*  Find a new entry */
978                     DBG_871X("[rtw_wx_set_pmkid] Use the new entry index = %d for this PMKID.\n",
979                             psecuritypriv->PMKIDIndex);
980
981                     memcpy(psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].Bssid, strIssueBssid, ETH_ALEN);
982                     memcpy(psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].PMKID, pPMK->pmkid, IW_PMKID_LEN);
983
984                     psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].bUsed = true;
985                     psecuritypriv->PMKIDIndex++;
986                     if (psecuritypriv->PMKIDIndex == 16)
987                         psecuritypriv->PMKIDIndex = 0;
988                 }
989         } else if (pPMK->cmd == IW_PMKSA_REMOVE) {
990                 DBG_871X("[rtw_wx_set_pmkid] IW_PMKSA_REMOVE!\n");
991                 intReturn = true;
992                 for (j = 0; j < NUM_PMKID_CACHE; j++) {
993                         if (!memcmp(psecuritypriv->PMKIDList[j].Bssid, strIssueBssid, ETH_ALEN)) {
994                                 /*  BSSID is matched, the same AP => Remove this PMKID information and reset it. */
995                                 eth_zero_addr(psecuritypriv->PMKIDList[j].Bssid);
996                                 psecuritypriv->PMKIDList[j].bUsed = false;
997                                 break;
998                         }
999                 }
1000         } else if (pPMK->cmd == IW_PMKSA_FLUSH) {
1001             DBG_871X("[rtw_wx_set_pmkid] IW_PMKSA_FLUSH!\n");
1002             memset(&psecuritypriv->PMKIDList[0], 0x00, sizeof(RT_PMKID_LIST) * NUM_PMKID_CACHE);
1003             psecuritypriv->PMKIDIndex = 0;
1004             intReturn = true;
1005         }
1006         return intReturn;
1007 }
1008
1009 static int rtw_wx_get_sens(struct net_device *dev,
1010                              struct iw_request_info *info,
1011                              union iwreq_data *wrqu, char *extra)
1012 {
1013         {
1014                 wrqu->sens.value = 0;
1015                 wrqu->sens.fixed = 0;   /* no auto select */
1016                 wrqu->sens.disabled = 1;
1017         }
1018         return 0;
1019 }
1020
1021 static int rtw_wx_get_range(struct net_device *dev,
1022                                 struct iw_request_info *info,
1023                                 union iwreq_data *wrqu, char *extra)
1024 {
1025         struct iw_range *range = (struct iw_range *)extra;
1026         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1027         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1028
1029         u16 val;
1030         int i;
1031
1032         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_wx_get_range. cmd_code =%x\n", info->cmd));
1033
1034         wrqu->data.length = sizeof(*range);
1035         memset(range, 0, sizeof(*range));
1036
1037         /* Let's try to keep this struct in the same order as in
1038          * linux/include/wireless.h
1039          */
1040
1041         /* TODO: See what values we can set, and remove the ones we can't
1042          * set, or fill them with some default data.
1043          */
1044
1045         /* ~5 Mb/s real (802.11b) */
1046         range->throughput = 5 * 1000 * 1000;
1047
1048         /* signal level threshold range */
1049
1050         /* percent values between 0 and 100. */
1051         range->max_qual.qual = 100;
1052         range->max_qual.level = 100;
1053         range->max_qual.noise = 100;
1054         range->max_qual.updated = 7; /* Updated all three */
1055
1056
1057         range->avg_qual.qual = 92; /* > 8% missed beacons is 'bad' */
1058         /* TODO: Find real 'good' to 'bad' threshol value for RSSI */
1059         range->avg_qual.level = 256 - 78;
1060         range->avg_qual.noise = 0;
1061         range->avg_qual.updated = 7; /* Updated all three */
1062
1063         range->num_bitrates = RATE_COUNT;
1064
1065         for (i = 0; i < RATE_COUNT && i < IW_MAX_BITRATES; i++)
1066                 range->bitrate[i] = rtw_rates[i];
1067
1068         range->min_frag = MIN_FRAG_THRESHOLD;
1069         range->max_frag = MAX_FRAG_THRESHOLD;
1070
1071         range->pm_capa = 0;
1072
1073         range->we_version_compiled = WIRELESS_EXT;
1074         range->we_version_source = 16;
1075
1076         for (i = 0, val = 0; i < MAX_CHANNEL_NUM; i++) {
1077
1078                 /*  Include only legal frequencies for some countries */
1079                 if (pmlmeext->channel_set[i].ChannelNum != 0) {
1080                         range->freq[val].i = pmlmeext->channel_set[i].ChannelNum;
1081                         range->freq[val].m = rtw_ch2freq(pmlmeext->channel_set[i].ChannelNum) * 100000;
1082                         range->freq[val].e = 1;
1083                         val++;
1084                 }
1085
1086                 if (val == IW_MAX_FREQUENCIES)
1087                         break;
1088         }
1089
1090         range->num_channels = val;
1091         range->num_frequency = val;
1092
1093 /*  Commented by Albert 2009/10/13 */
1094 /*  The following code will proivde the security capability to network manager. */
1095 /*  If the driver doesn't provide this capability to network manager, */
1096 /*  the WPA/WPA2 routers can't be chosen in the network manager. */
1097
1098 /*
1099 #define IW_SCAN_CAPA_NONE               0x00
1100 #define IW_SCAN_CAPA_ESSID              0x01
1101 #define IW_SCAN_CAPA_BSSID              0x02
1102 #define IW_SCAN_CAPA_CHANNEL    0x04
1103 #define IW_SCAN_CAPA_MODE               0x08
1104 #define IW_SCAN_CAPA_RATE               0x10
1105 #define IW_SCAN_CAPA_TYPE               0x20
1106 #define IW_SCAN_CAPA_TIME               0x40
1107 */
1108
1109         range->enc_capa = IW_ENC_CAPA_WPA | IW_ENC_CAPA_WPA2 |
1110                           IW_ENC_CAPA_CIPHER_TKIP | IW_ENC_CAPA_CIPHER_CCMP;
1111
1112         range->scan_capa = IW_SCAN_CAPA_ESSID | IW_SCAN_CAPA_TYPE | IW_SCAN_CAPA_BSSID |
1113                                         IW_SCAN_CAPA_CHANNEL | IW_SCAN_CAPA_MODE | IW_SCAN_CAPA_RATE;
1114
1115         return 0;
1116 }
1117
1118 /* set bssid flow */
1119 /* s1. rtw_set_802_11_infrastructure_mode() */
1120 /* s2. rtw_set_802_11_authentication_mode() */
1121 /* s3. set_802_11_encryption_mode() */
1122 /* s4. rtw_set_802_11_bssid() */
1123 static int rtw_wx_set_wap(struct net_device *dev,
1124                          struct iw_request_info *info,
1125                          union iwreq_data *awrq,
1126                          char *extra)
1127 {
1128         uint ret = 0;
1129         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1130         struct sockaddr *temp = (struct sockaddr *)awrq;
1131         struct  mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1132         struct list_head        *phead;
1133         u8 *dst_bssid, *src_bssid;
1134         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
1135         struct  wlan_network    *pnetwork = NULL;
1136         enum NDIS_802_11_AUTHENTICATION_MODE    authmode;
1137
1138         rtw_ps_deny(padapter, PS_DENY_JOIN);
1139         if (_FAIL == rtw_pwr_wakeup(padapter)) {
1140                 ret = -1;
1141                 goto exit;
1142         }
1143
1144         if (!padapter->bup) {
1145                 ret = -1;
1146                 goto exit;
1147         }
1148
1149
1150         if (temp->sa_family != ARPHRD_ETHER) {
1151                 ret = -EINVAL;
1152                 goto exit;
1153         }
1154
1155         authmode = padapter->securitypriv.ndisauthtype;
1156         spin_lock_bh(&queue->lock);
1157         phead = get_list_head(queue);
1158         pmlmepriv->pscanned = get_next(phead);
1159
1160         while (1) {
1161                 if (phead == pmlmepriv->pscanned)
1162                         break;
1163
1164                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
1165
1166                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
1167
1168                 dst_bssid = pnetwork->network.MacAddress;
1169
1170                 src_bssid = temp->sa_data;
1171
1172                 if ((!memcmp(dst_bssid, src_bssid, ETH_ALEN))) {
1173                         if (!rtw_set_802_11_infrastructure_mode(padapter, pnetwork->network.InfrastructureMode)) {
1174                                 ret = -1;
1175                                 spin_unlock_bh(&queue->lock);
1176                                 goto exit;
1177                         }
1178                         break;
1179                 }
1180
1181         }
1182         spin_unlock_bh(&queue->lock);
1183
1184         rtw_set_802_11_authentication_mode(padapter, authmode);
1185         /* set_802_11_encryption_mode(padapter, padapter->securitypriv.ndisencryptstatus); */
1186         if (rtw_set_802_11_bssid(padapter, temp->sa_data) == false) {
1187                 ret = -1;
1188                 goto exit;
1189         }
1190
1191 exit:
1192
1193         rtw_ps_deny_cancel(padapter, PS_DENY_JOIN);
1194
1195         return ret;
1196 }
1197
1198 static int rtw_wx_get_wap(struct net_device *dev,
1199                             struct iw_request_info *info,
1200                             union iwreq_data *wrqu, char *extra)
1201 {
1202
1203         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1204         struct  mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1205         struct wlan_bssid_ex  *pcur_bss = &pmlmepriv->cur_network.network;
1206
1207         wrqu->ap_addr.sa_family = ARPHRD_ETHER;
1208
1209         eth_zero_addr(wrqu->ap_addr.sa_data);
1210
1211         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_wx_get_wap\n"));
1212
1213         if  (((check_fwstate(pmlmepriv, _FW_LINKED)) == true) ||
1214                         ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) ||
1215                         ((check_fwstate(pmlmepriv, WIFI_AP_STATE)) == true)) {
1216                 memcpy(wrqu->ap_addr.sa_data, pcur_bss->MacAddress, ETH_ALEN);
1217         } else {
1218                 eth_zero_addr(wrqu->ap_addr.sa_data);
1219         }
1220
1221         return 0;
1222 }
1223
1224 static int rtw_wx_set_mlme(struct net_device *dev,
1225                              struct iw_request_info *info,
1226                              union iwreq_data *wrqu, char *extra)
1227 {
1228         int ret = 0;
1229         u16 reason;
1230         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1231         struct iw_mlme *mlme = (struct iw_mlme *)extra;
1232
1233
1234         if (mlme == NULL)
1235                 return -1;
1236
1237         DBG_871X("%s\n", __func__);
1238
1239         reason = mlme->reason_code;
1240
1241         DBG_871X("%s, cmd =%d, reason =%d\n", __func__, mlme->cmd, reason);
1242
1243         switch (mlme->cmd) {
1244         case IW_MLME_DEAUTH:
1245                 if (!rtw_set_802_11_disassociate(padapter))
1246                         ret = -1;
1247                 break;
1248         case IW_MLME_DISASSOC:
1249                 if (!rtw_set_802_11_disassociate(padapter))
1250                         ret = -1;
1251                 break;
1252         default:
1253                 return -EOPNOTSUPP;
1254         }
1255
1256         return ret;
1257 }
1258
1259 static int rtw_wx_set_scan(struct net_device *dev, struct iw_request_info *a,
1260                              union iwreq_data *wrqu, char *extra)
1261 {
1262         u8 _status = false;
1263         int ret = 0;
1264         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1265         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1266         struct ndis_802_11_ssid ssid[RTW_SSID_SCAN_AMOUNT];
1267         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_wx_set_scan\n"));
1268
1269         #ifdef DBG_IOCTL
1270         DBG_871X("DBG_IOCTL %s:%d\n", __func__, __LINE__);
1271         #endif
1272
1273         rtw_ps_deny(padapter, PS_DENY_SCAN);
1274         if (_FAIL == rtw_pwr_wakeup(padapter)) {
1275                 ret = -1;
1276                 goto exit;
1277         }
1278
1279         if (padapter->bDriverStopped) {
1280                 DBG_871X("bDriverStopped =%d\n", padapter->bDriverStopped);
1281                 ret = -1;
1282                 goto exit;
1283         }
1284
1285         if (!padapter->bup) {
1286                 ret = -1;
1287                 goto exit;
1288         }
1289
1290         if (!padapter->hw_init_completed) {
1291                 ret = -1;
1292                 goto exit;
1293         }
1294
1295         /*  When Busy Traffic, driver do not site survey. So driver return success. */
1296         /*  wpa_supplicant will not issue SIOCSIWSCAN cmd again after scan timeout. */
1297         /*  modify by thomas 2011-02-22. */
1298         if (pmlmepriv->LinkDetectInfo.bBusyTraffic) {
1299                 indicate_wx_scan_complete_event(padapter);
1300                 goto exit;
1301         }
1302
1303         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == true) {
1304                 indicate_wx_scan_complete_event(padapter);
1305                 goto exit;
1306         }
1307
1308         memset(ssid, 0, sizeof(struct ndis_802_11_ssid)*RTW_SSID_SCAN_AMOUNT);
1309
1310         if (wrqu->data.length == sizeof(struct iw_scan_req)) {
1311                 struct iw_scan_req *req = (struct iw_scan_req *)extra;
1312
1313                 if (wrqu->data.flags & IW_SCAN_THIS_ESSID) {
1314                         int len = min((int)req->essid_len, IW_ESSID_MAX_SIZE);
1315
1316                         memcpy(ssid[0].Ssid, req->essid, len);
1317                         ssid[0].SsidLength = len;
1318
1319                         DBG_871X("IW_SCAN_THIS_ESSID, ssid =%s, len =%d\n", req->essid, req->essid_len);
1320
1321                         spin_lock_bh(&pmlmepriv->lock);
1322
1323                         _status = rtw_sitesurvey_cmd(padapter, ssid, 1, NULL, 0);
1324
1325                         spin_unlock_bh(&pmlmepriv->lock);
1326
1327                 } else if (req->scan_type == IW_SCAN_TYPE_PASSIVE) {
1328                         DBG_871X("rtw_wx_set_scan, req->scan_type == IW_SCAN_TYPE_PASSIVE\n");
1329                 }
1330
1331         } else if (wrqu->data.length >= WEXT_CSCAN_HEADER_SIZE
1332                 && !memcmp(extra, WEXT_CSCAN_HEADER, WEXT_CSCAN_HEADER_SIZE)) {
1333                 int len = wrqu->data.length - WEXT_CSCAN_HEADER_SIZE;
1334                 char *pos = extra+WEXT_CSCAN_HEADER_SIZE;
1335                 char section;
1336                 char sec_len;
1337                 int ssid_index = 0;
1338
1339                 /* DBG_871X("%s COMBO_SCAN header is recognized\n", __func__); */
1340
1341                 while (len >= 1) {
1342                         section = *(pos++); len -= 1;
1343
1344                         switch (section) {
1345                                 case WEXT_CSCAN_SSID_SECTION:
1346                                         /* DBG_871X("WEXT_CSCAN_SSID_SECTION\n"); */
1347                                         if (len < 1) {
1348                                                 len = 0;
1349                                                 break;
1350                                         }
1351
1352                                         sec_len = *(pos++); len -= 1;
1353
1354                                         if (sec_len > 0 &&
1355                                             sec_len <= len &&
1356                                             sec_len <= 32) {
1357                                                 ssid[ssid_index].SsidLength = sec_len;
1358                                                 memcpy(ssid[ssid_index].Ssid, pos, sec_len);
1359                                                 /* DBG_871X("%s COMBO_SCAN with specific ssid:%s, %d\n", __func__ */
1360                                                 /*      , ssid[ssid_index].Ssid, ssid[ssid_index].SsidLength); */
1361                                                 ssid_index++;
1362                                         }
1363
1364                                         pos += sec_len; len -= sec_len;
1365                                         break;
1366
1367
1368                                 case WEXT_CSCAN_CHANNEL_SECTION:
1369                                         /* DBG_871X("WEXT_CSCAN_CHANNEL_SECTION\n"); */
1370                                         pos += 1; len -= 1;
1371                                         break;
1372                                 case WEXT_CSCAN_ACTV_DWELL_SECTION:
1373                                         /* DBG_871X("WEXT_CSCAN_ACTV_DWELL_SECTION\n"); */
1374                                         pos += 2; len -= 2;
1375                                         break;
1376                                 case WEXT_CSCAN_PASV_DWELL_SECTION:
1377                                         /* DBG_871X("WEXT_CSCAN_PASV_DWELL_SECTION\n"); */
1378                                         pos += 2; len -= 2;
1379                                         break;
1380                                 case WEXT_CSCAN_HOME_DWELL_SECTION:
1381                                         /* DBG_871X("WEXT_CSCAN_HOME_DWELL_SECTION\n"); */
1382                                         pos += 2; len -= 2;
1383                                         break;
1384                                 case WEXT_CSCAN_TYPE_SECTION:
1385                                         /* DBG_871X("WEXT_CSCAN_TYPE_SECTION\n"); */
1386                                         pos += 1; len -= 1;
1387                                         break;
1388                                 default:
1389                                         /* DBG_871X("Unknown CSCAN section %c\n", section); */
1390                                         len = 0; /*  stop parsing */
1391                         }
1392                         /* DBG_871X("len:%d\n", len); */
1393
1394                 }
1395
1396                 /* jeff: it has still some scan parameter to parse, we only do this now... */
1397                 _status = rtw_set_802_11_bssid_list_scan(padapter, ssid, RTW_SSID_SCAN_AMOUNT);
1398
1399         } else {
1400                 _status = rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1401         }
1402
1403         if (_status == false)
1404                 ret = -1;
1405
1406 exit:
1407
1408         rtw_ps_deny_cancel(padapter, PS_DENY_SCAN);
1409
1410         #ifdef DBG_IOCTL
1411         DBG_871X("DBG_IOCTL %s:%d return %d\n", __func__, __LINE__, ret);
1412         #endif
1413
1414         return ret;
1415 }
1416
1417 static int rtw_wx_get_scan(struct net_device *dev, struct iw_request_info *a,
1418                              union iwreq_data *wrqu, char *extra)
1419 {
1420         struct list_head                                        *plist, *phead;
1421         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1422         struct  mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1423         struct __queue                          *queue  = &(pmlmepriv->scanned_queue);
1424         struct  wlan_network    *pnetwork = NULL;
1425         char *ev = extra;
1426         char *stop = ev + wrqu->data.length;
1427         u32 ret = 0;
1428         sint wait_status;
1429
1430         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_wx_get_scan\n"));
1431         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_, (" Start of Query SIOCGIWSCAN .\n"));
1432
1433         #ifdef DBG_IOCTL
1434         DBG_871X("DBG_IOCTL %s:%d\n", __func__, __LINE__);
1435         #endif
1436
1437         if (adapter_to_pwrctl(padapter)->brfoffbyhw && padapter->bDriverStopped) {
1438                 ret = -EINVAL;
1439                 goto exit;
1440         }
1441
1442         wait_status = _FW_UNDER_SURVEY | _FW_UNDER_LINKING;
1443
1444         if (check_fwstate(pmlmepriv, wait_status))
1445                 return -EAGAIN;
1446
1447         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1448
1449         phead = get_list_head(queue);
1450         plist = get_next(phead);
1451
1452         while (1) {
1453                 if (phead == plist)
1454                         break;
1455
1456                 if ((stop - ev) < SCAN_ITEM_SIZE) {
1457                         ret = -E2BIG;
1458                         break;
1459                 }
1460
1461                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
1462
1463                 /* report network only if the current channel set contains the channel to which this network belongs */
1464                 if (rtw_ch_set_search_ch(padapter->mlmeextpriv.channel_set, pnetwork->network.Configuration.DSConfig) >= 0
1465                         && rtw_mlme_band_check(padapter, pnetwork->network.Configuration.DSConfig) == true
1466                         && true == rtw_validate_ssid(&(pnetwork->network.Ssid))) {
1467
1468                         ev = translate_scan(padapter, a, pnetwork, ev, stop);
1469                 }
1470
1471                 plist = get_next(plist);
1472
1473         }
1474
1475         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1476
1477         wrqu->data.length = ev-extra;
1478         wrqu->data.flags = 0;
1479
1480 exit:
1481
1482         #ifdef DBG_IOCTL
1483         DBG_871X("DBG_IOCTL %s:%d return %d\n", __func__, __LINE__, ret);
1484         #endif
1485
1486         return ret;
1487
1488 }
1489
1490 /* set ssid flow */
1491 /* s1. rtw_set_802_11_infrastructure_mode() */
1492 /* s2. set_802_11_authenticaion_mode() */
1493 /* s3. set_802_11_encryption_mode() */
1494 /* s4. rtw_set_802_11_ssid() */
1495 static int rtw_wx_set_essid(struct net_device *dev,
1496                               struct iw_request_info *a,
1497                               union iwreq_data *wrqu, char *extra)
1498 {
1499         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1500         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1501         struct __queue *queue = &pmlmepriv->scanned_queue;
1502         struct list_head *phead;
1503         struct wlan_network *pnetwork = NULL;
1504         enum NDIS_802_11_AUTHENTICATION_MODE authmode;
1505         struct ndis_802_11_ssid ndis_ssid;
1506         u8 *dst_ssid, *src_ssid;
1507
1508         uint ret = 0, len;
1509
1510         #ifdef DBG_IOCTL
1511         DBG_871X("DBG_IOCTL %s:%d\n", __func__, __LINE__);
1512         #endif
1513
1514         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
1515                  ("+rtw_wx_set_essid: fw_state = 0x%08x\n", get_fwstate(pmlmepriv)));
1516
1517         rtw_ps_deny(padapter, PS_DENY_JOIN);
1518         if (_FAIL == rtw_pwr_wakeup(padapter)) {
1519                 ret = -1;
1520                 goto exit;
1521         }
1522
1523         if (!padapter->bup) {
1524                 ret = -1;
1525                 goto exit;
1526         }
1527
1528         if (wrqu->essid.length > IW_ESSID_MAX_SIZE) {
1529                 ret = -E2BIG;
1530                 goto exit;
1531         }
1532
1533         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1534                 ret = -1;
1535                 goto exit;
1536         }
1537
1538         authmode = padapter->securitypriv.ndisauthtype;
1539         DBG_871X("=>%s\n", __func__);
1540         if (wrqu->essid.flags && wrqu->essid.length) {
1541                 len = (wrqu->essid.length < IW_ESSID_MAX_SIZE) ? wrqu->essid.length : IW_ESSID_MAX_SIZE;
1542
1543                 if (wrqu->essid.length != 33)
1544                         DBG_871X("ssid =%s, len =%d\n", extra, wrqu->essid.length);
1545
1546                 memset(&ndis_ssid, 0, sizeof(struct ndis_802_11_ssid));
1547                 ndis_ssid.SsidLength = len;
1548                 memcpy(ndis_ssid.Ssid, extra, len);
1549                 src_ssid = ndis_ssid.Ssid;
1550
1551                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_, ("rtw_wx_set_essid: ssid =[%s]\n", src_ssid));
1552                 spin_lock_bh(&queue->lock);
1553                 phead = get_list_head(queue);
1554                 pmlmepriv->pscanned = get_next(phead);
1555
1556                 while (1) {
1557                         if (phead == pmlmepriv->pscanned) {
1558                                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_warning_,
1559                                          ("rtw_wx_set_essid: scan_q is empty, set ssid to check if scanning again!\n"));
1560
1561                                 break;
1562                         }
1563
1564                         pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
1565
1566                         pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
1567
1568                         dst_ssid = pnetwork->network.Ssid.Ssid;
1569
1570                         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
1571                                  ("rtw_wx_set_essid: dst_ssid =%s\n",
1572                                   pnetwork->network.Ssid.Ssid));
1573
1574                         if ((!memcmp(dst_ssid, src_ssid, ndis_ssid.SsidLength)) &&
1575                                 (pnetwork->network.Ssid.SsidLength == ndis_ssid.SsidLength)) {
1576                                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
1577                                          ("rtw_wx_set_essid: find match, set infra mode\n"));
1578
1579                                 if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
1580                                         if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
1581                                                 continue;
1582                                 }
1583
1584                                 if (rtw_set_802_11_infrastructure_mode(padapter, pnetwork->network.InfrastructureMode) == false) {
1585                                         ret = -1;
1586                                         spin_unlock_bh(&queue->lock);
1587                                         goto exit;
1588                                 }
1589
1590                                 break;
1591                         }
1592                 }
1593                 spin_unlock_bh(&queue->lock);
1594                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
1595                          ("set ssid: set_802_11_auth. mode =%d\n", authmode));
1596                 rtw_set_802_11_authentication_mode(padapter, authmode);
1597                 /* set_802_11_encryption_mode(padapter, padapter->securitypriv.ndisencryptstatus); */
1598                 if (rtw_set_802_11_ssid(padapter, &ndis_ssid) == false) {
1599                         ret = -1;
1600                         goto exit;
1601                 }
1602         }
1603
1604 exit:
1605
1606         rtw_ps_deny_cancel(padapter, PS_DENY_JOIN);
1607
1608         DBG_871X("<=%s, ret %d\n", __func__, ret);
1609
1610         #ifdef DBG_IOCTL
1611         DBG_871X("DBG_IOCTL %s:%d return %d\n", __func__, __LINE__, ret);
1612         #endif
1613
1614         return ret;
1615 }
1616
1617 static int rtw_wx_get_essid(struct net_device *dev,
1618                               struct iw_request_info *a,
1619                               union iwreq_data *wrqu, char *extra)
1620 {
1621         u32 len, ret = 0;
1622         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1623         struct  mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1624         struct wlan_bssid_ex  *pcur_bss = &pmlmepriv->cur_network.network;
1625
1626         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_wx_get_essid\n"));
1627
1628         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) ||
1629               (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true)) {
1630                 len = pcur_bss->Ssid.SsidLength;
1631
1632                 wrqu->essid.length = len;
1633
1634                 memcpy(extra, pcur_bss->Ssid.Ssid, len);
1635
1636                 wrqu->essid.flags = 1;
1637         } else {
1638                 ret = -1;
1639                 goto exit;
1640         }
1641
1642 exit:
1643         return ret;
1644 }
1645
1646 static int rtw_wx_set_rate(struct net_device *dev,
1647                               struct iw_request_info *a,
1648                               union iwreq_data *wrqu, char *extra)
1649 {
1650         int     i, ret = 0;
1651         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1652         u8 datarates[NumRates];
1653         u32 target_rate = wrqu->bitrate.value;
1654         u32 fixed = wrqu->bitrate.fixed;
1655         u32 ratevalue = 0;
1656         u8 mpdatarate[NumRates] = {11, 10, 9, 8, 7, 6, 5, 4, 3, 2, 1, 0, 0xff};
1657
1658         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, (" rtw_wx_set_rate\n"));
1659         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_, ("target_rate = %d, fixed = %d\n", target_rate, fixed));
1660
1661         if (target_rate == -1) {
1662                 ratevalue = 11;
1663                 goto set_rate;
1664         }
1665         target_rate = target_rate/100000;
1666
1667         switch (target_rate) {
1668         case 10:
1669                 ratevalue = 0;
1670                 break;
1671         case 20:
1672                 ratevalue = 1;
1673                 break;
1674         case 55:
1675                 ratevalue = 2;
1676                 break;
1677         case 60:
1678                 ratevalue = 3;
1679                 break;
1680         case 90:
1681                 ratevalue = 4;
1682                 break;
1683         case 110:
1684                 ratevalue = 5;
1685                 break;
1686         case 120:
1687                 ratevalue = 6;
1688                 break;
1689         case 180:
1690                 ratevalue = 7;
1691                 break;
1692         case 240:
1693                 ratevalue = 8;
1694                 break;
1695         case 360:
1696                 ratevalue = 9;
1697                 break;
1698         case 480:
1699                 ratevalue = 10;
1700                 break;
1701         case 540:
1702                 ratevalue = 11;
1703                 break;
1704         default:
1705                 ratevalue = 11;
1706                 break;
1707         }
1708
1709 set_rate:
1710
1711         for (i = 0; i < NumRates; i++) {
1712                 if (ratevalue == mpdatarate[i]) {
1713                         datarates[i] = mpdatarate[i];
1714                         if (fixed == 0)
1715                                 break;
1716                 } else {
1717                         datarates[i] = 0xff;
1718                 }
1719
1720                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_, ("datarate_inx =%d\n", datarates[i]));
1721         }
1722
1723         if (rtw_setdatarate_cmd(padapter, datarates) != _SUCCESS) {
1724                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_err_, ("rtw_wx_set_rate Fail!!!\n"));
1725                 ret = -1;
1726         }
1727         return ret;
1728 }
1729
1730 static int rtw_wx_get_rate(struct net_device *dev,
1731                              struct iw_request_info *info,
1732                              union iwreq_data *wrqu, char *extra)
1733 {
1734         u16 max_rate = 0;
1735
1736         max_rate = rtw_get_cur_max_rate((struct adapter *)rtw_netdev_priv(dev));
1737
1738         if (max_rate == 0)
1739                 return -EPERM;
1740
1741         wrqu->bitrate.fixed = 0;        /* no auto select */
1742         wrqu->bitrate.value = max_rate * 100000;
1743
1744         return 0;
1745 }
1746
1747 static int rtw_wx_set_rts(struct net_device *dev,
1748                              struct iw_request_info *info,
1749                              union iwreq_data *wrqu, char *extra)
1750 {
1751         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1752
1753         if (wrqu->rts.disabled)
1754                 padapter->registrypriv.rts_thresh = 2347;
1755         else {
1756                 if (wrqu->rts.value < 0 ||
1757                     wrqu->rts.value > 2347)
1758                         return -EINVAL;
1759
1760                 padapter->registrypriv.rts_thresh = wrqu->rts.value;
1761         }
1762
1763         DBG_871X("%s, rts_thresh =%d\n", __func__, padapter->registrypriv.rts_thresh);
1764
1765         return 0;
1766 }
1767
1768 static int rtw_wx_get_rts(struct net_device *dev,
1769                              struct iw_request_info *info,
1770                              union iwreq_data *wrqu, char *extra)
1771 {
1772         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1773
1774         DBG_871X("%s, rts_thresh =%d\n", __func__, padapter->registrypriv.rts_thresh);
1775
1776         wrqu->rts.value = padapter->registrypriv.rts_thresh;
1777         wrqu->rts.fixed = 0;    /* no auto select */
1778         /* wrqu->rts.disabled = (wrqu->rts.value == DEFAULT_RTS_THRESHOLD); */
1779
1780         return 0;
1781 }
1782
1783 static int rtw_wx_set_frag(struct net_device *dev,
1784                              struct iw_request_info *info,
1785                              union iwreq_data *wrqu, char *extra)
1786 {
1787         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1788
1789         if (wrqu->frag.disabled)
1790                 padapter->xmitpriv.frag_len = MAX_FRAG_THRESHOLD;
1791         else {
1792                 if (wrqu->frag.value < MIN_FRAG_THRESHOLD ||
1793                     wrqu->frag.value > MAX_FRAG_THRESHOLD)
1794                         return -EINVAL;
1795
1796                 padapter->xmitpriv.frag_len = wrqu->frag.value & ~0x1;
1797         }
1798
1799         DBG_871X("%s, frag_len =%d\n", __func__, padapter->xmitpriv.frag_len);
1800
1801         return 0;
1802
1803 }
1804
1805 static int rtw_wx_get_frag(struct net_device *dev,
1806                              struct iw_request_info *info,
1807                              union iwreq_data *wrqu, char *extra)
1808 {
1809         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1810
1811         DBG_871X("%s, frag_len =%d\n", __func__, padapter->xmitpriv.frag_len);
1812
1813         wrqu->frag.value = padapter->xmitpriv.frag_len;
1814         wrqu->frag.fixed = 0;   /* no auto select */
1815         /* wrqu->frag.disabled = (wrqu->frag.value == DEFAULT_FRAG_THRESHOLD); */
1816
1817         return 0;
1818 }
1819
1820 static int rtw_wx_get_retry(struct net_device *dev,
1821                              struct iw_request_info *info,
1822                              union iwreq_data *wrqu, char *extra)
1823 {
1824         /* struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev); */
1825
1826
1827         wrqu->retry.value = 7;
1828         wrqu->retry.fixed = 0;  /* no auto select */
1829         wrqu->retry.disabled = 1;
1830
1831         return 0;
1832
1833 }
1834
1835 static int rtw_wx_set_enc(struct net_device *dev,
1836                             struct iw_request_info *info,
1837                             union iwreq_data *wrqu, char *keybuf)
1838 {
1839         u32 key, ret = 0;
1840         u32 keyindex_provided;
1841         struct ndis_802_11_wep   wep;
1842         enum NDIS_802_11_AUTHENTICATION_MODE authmode;
1843
1844         struct iw_point *erq = &(wrqu->encoding);
1845         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1846         struct pwrctrl_priv *pwrpriv = adapter_to_pwrctl(padapter);
1847         DBG_871X("+rtw_wx_set_enc, flags = 0x%x\n", erq->flags);
1848
1849         memset(&wep, 0, sizeof(struct ndis_802_11_wep));
1850
1851         key = erq->flags & IW_ENCODE_INDEX;
1852
1853         if (erq->flags & IW_ENCODE_DISABLED) {
1854                 DBG_871X("EncryptionDisabled\n");
1855                 padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
1856                 padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
1857                 padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
1858                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open; /* open system */
1859                 authmode = Ndis802_11AuthModeOpen;
1860                 padapter->securitypriv.ndisauthtype = authmode;
1861
1862                 goto exit;
1863         }
1864
1865         if (key) {
1866                 if (key > WEP_KEYS)
1867                         return -EINVAL;
1868                 key--;
1869                 keyindex_provided = 1;
1870         } else {
1871                 keyindex_provided = 0;
1872                 key = padapter->securitypriv.dot11PrivacyKeyIndex;
1873                 DBG_871X("rtw_wx_set_enc, key =%d\n", key);
1874         }
1875
1876         /* set authentication mode */
1877         if (erq->flags & IW_ENCODE_OPEN) {
1878                 DBG_871X("rtw_wx_set_enc():IW_ENCODE_OPEN\n");
1879                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;/* Ndis802_11EncryptionDisabled; */
1880
1881                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
1882
1883                 padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
1884                 padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
1885                 authmode = Ndis802_11AuthModeOpen;
1886                 padapter->securitypriv.ndisauthtype = authmode;
1887         } else if (erq->flags & IW_ENCODE_RESTRICTED) {
1888                 DBG_871X("rtw_wx_set_enc():IW_ENCODE_RESTRICTED\n");
1889                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1890
1891                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Shared;
1892
1893                 padapter->securitypriv.dot11PrivacyAlgrthm = _WEP40_;
1894                 padapter->securitypriv.dot118021XGrpPrivacy = _WEP40_;
1895                 authmode = Ndis802_11AuthModeShared;
1896                 padapter->securitypriv.ndisauthtype = authmode;
1897         } else {
1898                 DBG_871X("rtw_wx_set_enc():erq->flags = 0x%x\n", erq->flags);
1899
1900                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;/* Ndis802_11EncryptionDisabled; */
1901                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open; /* open system */
1902                 padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
1903                 padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
1904                 authmode = Ndis802_11AuthModeOpen;
1905                 padapter->securitypriv.ndisauthtype = authmode;
1906         }
1907
1908         wep.KeyIndex = key;
1909         if (erq->length > 0) {
1910                 wep.KeyLength = erq->length <= 5 ? 5 : 13;
1911
1912                 wep.Length = wep.KeyLength + FIELD_OFFSET(struct ndis_802_11_wep, KeyMaterial);
1913         } else {
1914                 wep.KeyLength = 0;
1915
1916                 if (keyindex_provided == 1) { /*  set key_id only, no given KeyMaterial(erq->length == 0). */
1917                         padapter->securitypriv.dot11PrivacyKeyIndex = key;
1918
1919                         DBG_871X("(keyindex_provided == 1), keyid =%d, key_len =%d\n", key, padapter->securitypriv.dot11DefKeylen[key]);
1920
1921                         switch (padapter->securitypriv.dot11DefKeylen[key]) {
1922                                 case 5:
1923                                         padapter->securitypriv.dot11PrivacyAlgrthm = _WEP40_;
1924                                         break;
1925                                 case 13:
1926                                         padapter->securitypriv.dot11PrivacyAlgrthm = _WEP104_;
1927                                         break;
1928                                 default:
1929                                         padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
1930                                         break;
1931                         }
1932
1933                         goto exit;
1934
1935                 }
1936
1937         }
1938
1939         wep.KeyIndex |= 0x80000000;
1940
1941         memcpy(wep.KeyMaterial, keybuf, wep.KeyLength);
1942
1943         if (rtw_set_802_11_add_wep(padapter, &wep) == false) {
1944                 if (rf_on == pwrpriv->rf_pwrstate)
1945                         ret = -EOPNOTSUPP;
1946                 goto exit;
1947         }
1948
1949 exit:
1950         return ret;
1951 }
1952
1953 static int rtw_wx_get_enc(struct net_device *dev,
1954                             struct iw_request_info *info,
1955                             union iwreq_data *wrqu, char *keybuf)
1956 {
1957         uint key, ret = 0;
1958         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
1959         struct iw_point *erq = &(wrqu->encoding);
1960         struct  mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1961
1962         if (check_fwstate(pmlmepriv, _FW_LINKED) != true) {
1963                  if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) != true) {
1964                          erq->length = 0;
1965                          erq->flags |= IW_ENCODE_DISABLED;
1966                          return 0;
1967                  }
1968         }
1969
1970
1971         key = erq->flags & IW_ENCODE_INDEX;
1972
1973         if (key) {
1974                 if (key > WEP_KEYS)
1975                         return -EINVAL;
1976                 key--;
1977         } else {
1978                 key = padapter->securitypriv.dot11PrivacyKeyIndex;
1979         }
1980
1981         erq->flags = key + 1;
1982
1983         /* if (padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeOpen) */
1984         /*  */
1985         /*       erq->flags |= IW_ENCODE_OPEN; */
1986         /*  */
1987
1988         switch (padapter->securitypriv.ndisencryptstatus) {
1989         case Ndis802_11EncryptionNotSupported:
1990         case Ndis802_11EncryptionDisabled:
1991                 erq->length = 0;
1992                 erq->flags |= IW_ENCODE_DISABLED;
1993                 break;
1994         case Ndis802_11Encryption1Enabled:
1995                 erq->length = padapter->securitypriv.dot11DefKeylen[key];
1996
1997                 if (erq->length) {
1998                         memcpy(keybuf, padapter->securitypriv.dot11DefKey[key].skey, padapter->securitypriv.dot11DefKeylen[key]);
1999
2000                         erq->flags |= IW_ENCODE_ENABLED;
2001
2002                         if (padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeOpen)
2003                                 erq->flags |= IW_ENCODE_OPEN;
2004                         else if (padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeShared)
2005                                 erq->flags |= IW_ENCODE_RESTRICTED;
2006                 } else {
2007                         erq->length = 0;
2008                         erq->flags |= IW_ENCODE_DISABLED;
2009                 }
2010                 break;
2011         case Ndis802_11Encryption2Enabled:
2012         case Ndis802_11Encryption3Enabled:
2013                 erq->length = 16;
2014                 erq->flags |= (IW_ENCODE_ENABLED | IW_ENCODE_OPEN | IW_ENCODE_NOKEY);
2015                 break;
2016         default:
2017                 erq->length = 0;
2018                 erq->flags |= IW_ENCODE_DISABLED;
2019                 break;
2020         }
2021         return ret;
2022 }
2023
2024 static int rtw_wx_get_power(struct net_device *dev,
2025                              struct iw_request_info *info,
2026                              union iwreq_data *wrqu, char *extra)
2027 {
2028         /* struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev); */
2029
2030         wrqu->power.value = 0;
2031         wrqu->power.fixed = 0;  /* no auto select */
2032         wrqu->power.disabled = 1;
2033
2034         return 0;
2035 }
2036
2037 static int rtw_wx_set_gen_ie(struct net_device *dev,
2038                              struct iw_request_info *info,
2039                              union iwreq_data *wrqu, char *extra)
2040 {
2041         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
2042
2043         return rtw_set_wpa_ie(padapter, extra, wrqu->data.length);
2044 }
2045
2046 static int rtw_wx_set_auth(struct net_device *dev,
2047                            struct iw_request_info *info,
2048                            union iwreq_data *wrqu, char *extra)
2049 {
2050         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
2051         struct iw_param *param = (struct iw_param *)&(wrqu->param);
2052         int ret = 0;
2053
2054         switch (param->flags & IW_AUTH_INDEX) {
2055         case IW_AUTH_WPA_VERSION:
2056                 break;
2057         case IW_AUTH_CIPHER_PAIRWISE:
2058                 break;
2059         case IW_AUTH_CIPHER_GROUP:
2060                 break;
2061         case IW_AUTH_KEY_MGMT:
2062                 /*
2063                  *  ??? does not use these parameters
2064                  */
2065                 break;
2066         case IW_AUTH_TKIP_COUNTERMEASURES:
2067                 /* wpa_supplicant is setting the tkip countermeasure. */
2068                 if (param->value) /* enabling */
2069                         padapter->securitypriv.btkip_countermeasure = true;
2070                 else /* disabling */
2071                         padapter->securitypriv.btkip_countermeasure = false;
2072                 break;
2073         case IW_AUTH_DROP_UNENCRYPTED:
2074                 /* HACK:
2075                  *
2076                  * wpa_supplicant calls set_wpa_enabled when the driver
2077                  * is loaded and unloaded, regardless of if WPA is being
2078                  * used.  No other calls are made which can be used to
2079                  * determine if encryption will be used or not prior to
2080                  * association being expected.  If encryption is not being
2081                  * used, drop_unencrypted is set to false, else true -- we
2082                  * can use this to determine if the CAP_PRIVACY_ON bit should
2083                  * be set.
2084                  */
2085
2086                 /*
2087                  * This means init value, or using wep, ndisencryptstatus =
2088                  * Ndis802_11Encryption1Enabled, then it needn't reset it;
2089                  */
2090                 if (padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption1Enabled)
2091                         break;
2092
2093                 if (param->value) {
2094                         padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
2095                         padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
2096                         padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
2097                         padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open; /* open system */
2098                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeOpen;
2099                 }
2100
2101                 break;
2102         case IW_AUTH_80211_AUTH_ALG:
2103                 /*
2104                  *  It's the starting point of a link layer connection using wpa_supplicant
2105                  */
2106                 if (check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
2107                         LeaveAllPowerSaveMode(padapter);
2108                         rtw_disassoc_cmd(padapter, 500, false);
2109                         DBG_871X("%s...call rtw_indicate_disconnect\n ", __func__);
2110                         rtw_indicate_disconnect(padapter);
2111                         rtw_free_assoc_resources(padapter, 1);
2112                 }
2113
2114                 ret = wpa_set_auth_algs(dev, (u32)param->value);
2115                 break;
2116         case IW_AUTH_WPA_ENABLED:
2117                 break;
2118         case IW_AUTH_RX_UNENCRYPTED_EAPOL:
2119                 break;
2120         case IW_AUTH_PRIVACY_INVOKED:
2121                 break;
2122         default:
2123                 return -EOPNOTSUPP;
2124         }
2125
2126         return ret;
2127 }
2128
2129 static int rtw_wx_set_enc_ext(struct net_device *dev,
2130                              struct iw_request_info *info,
2131                              union iwreq_data *wrqu, char *extra)
2132 {
2133         char *alg_name;
2134         u32 param_len;
2135         struct ieee_param *param = NULL;
2136         struct iw_point *pencoding = &wrqu->encoding;
2137         struct iw_encode_ext *pext = (struct iw_encode_ext *)extra;
2138         int ret = 0;
2139
2140         param_len = sizeof(struct ieee_param) + pext->key_len;
2141         param = kzalloc(param_len, GFP_KERNEL);
2142         if (param == NULL)
2143                 return -1;
2144
2145         param->cmd = IEEE_CMD_SET_ENCRYPTION;
2146         memset(param->sta_addr, 0xff, ETH_ALEN);
2147
2148
2149         switch (pext->alg) {
2150         case IW_ENCODE_ALG_NONE:
2151                 /* todo: remove key */
2152                 /* remove = 1; */
2153                 alg_name = "none";
2154                 break;
2155         case IW_ENCODE_ALG_WEP:
2156                 alg_name = "WEP";
2157                 break;
2158         case IW_ENCODE_ALG_TKIP:
2159                 alg_name = "TKIP";
2160                 break;
2161         case IW_ENCODE_ALG_CCMP:
2162                 alg_name = "CCMP";
2163                 break;
2164         case IW_ENCODE_ALG_AES_CMAC:
2165                 alg_name = "BIP";
2166                 break;
2167         default:
2168                 ret = -1;
2169                 goto exit;
2170         }
2171
2172         strncpy((char *)param->u.crypt.alg, alg_name, IEEE_CRYPT_ALG_NAME_LEN);
2173
2174         if (pext->ext_flags & IW_ENCODE_EXT_SET_TX_KEY)
2175                 param->u.crypt.set_tx = 1;
2176
2177         /* cliW: WEP does not have group key
2178          * just not checking GROUP key setting
2179          */
2180         if ((pext->alg != IW_ENCODE_ALG_WEP) &&
2181                 ((pext->ext_flags & IW_ENCODE_EXT_GROUP_KEY)
2182                 || (pext->ext_flags & IW_ENCODE_ALG_AES_CMAC))) {
2183                 param->u.crypt.set_tx = 0;
2184         }
2185
2186         param->u.crypt.idx = (pencoding->flags & 0x00FF) - 1;
2187
2188         if (pext->ext_flags & IW_ENCODE_EXT_RX_SEQ_VALID)
2189                 memcpy(param->u.crypt.seq, pext->rx_seq, 8);
2190
2191         if (pext->key_len) {
2192                 param->u.crypt.key_len = pext->key_len;
2193                 /* memcpy(param + 1, pext + 1, pext->key_len); */
2194                 memcpy(param->u.crypt.key, pext + 1, pext->key_len);
2195         }
2196
2197         if (pencoding->flags & IW_ENCODE_DISABLED) {
2198                 /* todo: remove key */
2199                 /* remove = 1; */
2200         }
2201
2202         ret =  wpa_set_encryption(dev, param, param_len);
2203
2204 exit:
2205         kfree(param);
2206
2207         return ret;
2208 }
2209
2210
2211 static int rtw_wx_get_nick(struct net_device *dev,
2212                              struct iw_request_info *info,
2213                              union iwreq_data *wrqu, char *extra)
2214 {
2215         /* struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev); */
2216          /* struct mlme_priv *pmlmepriv = &(padapter->mlmepriv); */
2217          /* struct security_priv *psecuritypriv = &padapter->securitypriv; */
2218
2219         if (extra) {
2220                 wrqu->data.length = 14;
2221                 wrqu->data.flags = 1;
2222                 memcpy(extra, "<WIFI@REALTEK>", 14);
2223         }
2224         return 0;
2225 }
2226
2227 static int rtw_wx_read32(struct net_device *dev,
2228                             struct iw_request_info *info,
2229                             union iwreq_data *wrqu, char *extra)
2230 {
2231         struct adapter *padapter;
2232         struct iw_point *p;
2233         u16 len;
2234         u32 addr;
2235         u32 data32;
2236         u32 bytes;
2237         u8 *ptmp;
2238         int ret;
2239
2240
2241         ret = 0;
2242         padapter = (struct adapter *)rtw_netdev_priv(dev);
2243         p = &wrqu->data;
2244         len = p->length;
2245         if (0 == len)
2246                 return -EINVAL;
2247
2248         ptmp = rtw_malloc(len);
2249         if (NULL == ptmp)
2250                 return -ENOMEM;
2251
2252         if (copy_from_user(ptmp, p->pointer, len)) {
2253                 ret = -EFAULT;
2254                 goto exit;
2255         }
2256
2257         bytes = 0;
2258         addr = 0;
2259         sscanf(ptmp, "%d,%x", &bytes, &addr);
2260
2261         switch (bytes) {
2262         case 1:
2263                 data32 = rtw_read8(padapter, addr);
2264                 sprintf(extra, "0x%02X", data32);
2265                 break;
2266         case 2:
2267                 data32 = rtw_read16(padapter, addr);
2268                 sprintf(extra, "0x%04X", data32);
2269                 break;
2270         case 4:
2271                 data32 = rtw_read32(padapter, addr);
2272                 sprintf(extra, "0x%08X", data32);
2273                 break;
2274         default:
2275                 DBG_871X(KERN_INFO "%s: usage> read [bytes],[address(hex)]\n", __func__);
2276                 ret = -EINVAL;
2277                 goto exit;
2278         }
2279         DBG_871X(KERN_INFO "%s: addr = 0x%08X data =%s\n", __func__, addr, extra);
2280
2281 exit:
2282         kfree(ptmp);
2283
2284         return ret;
2285 }
2286
2287 static int rtw_wx_write32(struct net_device *dev,
2288                             struct iw_request_info *info,
2289                             union iwreq_data *wrqu, char *extra)
2290 {
2291         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
2292
2293         u32 addr;
2294         u32 data32;
2295         u32 bytes;
2296
2297
2298         bytes = 0;
2299         addr = 0;
2300         data32 = 0;
2301         sscanf(extra, "%d,%x,%x", &bytes, &addr, &data32);
2302
2303         switch (bytes) {
2304         case 1:
2305                 rtw_write8(padapter, addr, (u8)data32);
2306                 DBG_871X(KERN_INFO "%s: addr = 0x%08X data = 0x%02X\n", __func__, addr, (u8)data32);
2307                 break;
2308         case 2:
2309                 rtw_write16(padapter, addr, (u16)data32);
2310                 DBG_871X(KERN_INFO "%s: addr = 0x%08X data = 0x%04X\n", __func__, addr, (u16)data32);
2311                 break;
2312         case 4:
2313                 rtw_write32(padapter, addr, data32);
2314                 DBG_871X(KERN_INFO "%s: addr = 0x%08X data = 0x%08X\n", __func__, addr, data32);
2315                 break;
2316         default:
2317                 DBG_871X(KERN_INFO "%s: usage> write [bytes],[address(hex)],[data(hex)]\n", __func__);
2318                 return -EINVAL;
2319         }
2320
2321         return 0;
2322 }
2323
2324 static int rtw_wx_read_rf(struct net_device *dev,
2325                             struct iw_request_info *info,
2326                             union iwreq_data *wrqu, char *extra)
2327 {
2328         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
2329         u32 path, addr, data32;
2330
2331
2332         path = *(u32 *)extra;
2333         addr = *((u32 *)extra + 1);
2334         data32 = rtw_hal_read_rfreg(padapter, path, addr, 0xFFFFF);
2335         /*
2336          * IMPORTANT!!
2337          * Only when wireless private ioctl is at odd order,
2338          * "extra" would be copied to user space.
2339          */
2340         sprintf(extra, "0x%05x", data32);
2341
2342         return 0;
2343 }
2344
2345 static int rtw_wx_write_rf(struct net_device *dev,
2346                             struct iw_request_info *info,
2347                             union iwreq_data *wrqu, char *extra)
2348 {
2349         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
2350         u32 path, addr, data32;
2351
2352
2353         path = *(u32 *)extra;
2354         addr = *((u32 *)extra + 1);
2355         data32 = *((u32 *)extra + 2);
2356 /*      DBG_871X("%s: path =%d addr = 0x%02x data = 0x%05x\n", __func__, path, addr, data32); */
2357         rtw_hal_write_rfreg(padapter, path, addr, 0xFFFFF, data32);
2358
2359         return 0;
2360 }
2361
2362 static int rtw_wx_priv_null(struct net_device *dev, struct iw_request_info *a,
2363                  union iwreq_data *wrqu, char *b)
2364 {
2365         return -1;
2366 }
2367
2368 static int dummy(struct net_device *dev, struct iw_request_info *a,
2369                  union iwreq_data *wrqu, char *b)
2370 {
2371         /* struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev); */
2372         /* struct mlme_priv *pmlmepriv = &(padapter->mlmepriv); */
2373
2374         /* DBG_871X("cmd_code =%x, fwstate = 0x%x\n", a->cmd, get_fwstate(pmlmepriv)); */
2375
2376         return -1;
2377
2378 }
2379
2380 static int rtw_wx_set_channel_plan(struct net_device *dev,
2381                                struct iw_request_info *info,
2382                                union iwreq_data *wrqu, char *extra)
2383 {
2384         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
2385         u8 channel_plan_req = (u8)(*((int *)wrqu));
2386
2387         if (_SUCCESS == rtw_set_chplan_cmd(padapter, channel_plan_req, 1, 1))
2388                 DBG_871X("%s set channel_plan = 0x%02X\n", __func__, channel_plan_req);
2389          else
2390                 return -EPERM;
2391
2392         return 0;
2393 }
2394
2395 static int rtw_wx_set_mtk_wps_probe_ie(struct net_device *dev,
2396                 struct iw_request_info *a,
2397                 union iwreq_data *wrqu, char *b)
2398 {
2399         return 0;
2400 }
2401
2402 static int rtw_wx_get_sensitivity(struct net_device *dev,
2403                                 struct iw_request_info *info,
2404                                 union iwreq_data *wrqu, char *buf)
2405 {
2406         return 0;
2407 }
2408
2409 static int rtw_wx_set_mtk_wps_ie(struct net_device *dev,
2410                                 struct iw_request_info *info,
2411                                 union iwreq_data *wrqu, char *extra)
2412 {
2413         return 0;
2414 }
2415
2416 /*
2417 typedef int (*iw_handler)(struct net_device *dev, struct iw_request_info *info,
2418                           union iwreq_data *wrqu, char *extra);
2419 */
2420 /*
2421  *For all data larger than 16 octets, we need to use a
2422  *pointer to memory allocated in user space.
2423  */
2424 static  int rtw_drvext_hdl(struct net_device *dev, struct iw_request_info *info,
2425                                                 union iwreq_data *wrqu, char *extra)
2426 {
2427         return 0;
2428 }
2429
2430 static int rtw_get_ap_info(struct net_device *dev,
2431                                struct iw_request_info *info,
2432                                union iwreq_data *wrqu, char *extra)
2433 {
2434         int ret = 0;
2435         int wpa_ielen;
2436         u32 cnt = 0;
2437         struct list_head        *plist, *phead;
2438         unsigned char *pbuf;
2439         u8 bssid[ETH_ALEN];
2440         char data[32];
2441         struct wlan_network *pnetwork = NULL;
2442         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
2443         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
2444         struct __queue *queue = &(pmlmepriv->scanned_queue);
2445         struct iw_point *pdata = &wrqu->data;
2446
2447         DBG_871X("+rtw_get_aplist_info\n");
2448
2449         if ((padapter->bDriverStopped) || (pdata == NULL)) {
2450                 ret = -EINVAL;
2451                 goto exit;
2452         }
2453
2454         while ((check_fwstate(pmlmepriv, (_FW_UNDER_SURVEY|_FW_UNDER_LINKING))) == true) {
2455                 msleep(30);
2456                 cnt++;
2457                 if (cnt > 100)
2458                         break;
2459         }
2460
2461
2462         /* pdata->length = 0;? */
2463         pdata->flags = 0;
2464         if (pdata->length >= 32) {
2465                 if (copy_from_user(data, pdata->pointer, 32)) {
2466                         ret = -EINVAL;
2467                         goto exit;
2468                 }
2469         } else {
2470                 ret = -EINVAL;
2471                 goto exit;
2472         }
2473
2474         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
2475
2476         phead = get_list_head(queue);
2477         plist = get_next(phead);
2478
2479         while (1) {
2480                 if (phead == plist)
2481                         break;
2482
2483
2484                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
2485
2486                 if (!mac_pton(data, bssid)) {
2487                         DBG_871X("Invalid BSSID '%s'.\n", (u8 *)data);
2488                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
2489                         return -EINVAL;
2490                 }
2491
2492
2493                 if (!memcmp(bssid, pnetwork->network.MacAddress, ETH_ALEN)) { /* BSSID match, then check if supporting wpa/wpa2 */
2494                         DBG_871X("BSSID:" MAC_FMT "\n", MAC_ARG(bssid));
2495
2496                         pbuf = rtw_get_wpa_ie(&pnetwork->network.IEs[12], &wpa_ielen, pnetwork->network.IELength-12);
2497                         if (pbuf && (wpa_ielen > 0)) {
2498                                 pdata->flags = 1;
2499                                 break;
2500                         }
2501
2502                         pbuf = rtw_get_wpa2_ie(&pnetwork->network.IEs[12], &wpa_ielen, pnetwork->network.IELength-12);
2503                         if (pbuf && (wpa_ielen > 0)) {
2504                                 pdata->flags = 2;
2505                                 break;
2506                         }
2507                 }
2508
2509                 plist = get_next(plist);
2510
2511         }
2512
2513         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
2514
2515         if (pdata->length >= 34) {
2516                 if (copy_to_user((u8 __force __user *)pdata->pointer+32, (u8 *)&pdata->flags, 1)) {
2517                         ret = -EINVAL;
2518                         goto exit;
2519                 }
2520         }
2521
2522 exit:
2523
2524         return ret;
2525
2526 }
2527
2528 static int rtw_set_pid(struct net_device *dev,
2529                                struct iw_request_info *info,
2530                                union iwreq_data *wrqu, char *extra)
2531 {
2532
2533         int ret = 0;
2534         struct adapter *padapter = rtw_netdev_priv(dev);
2535         int *pdata = (int *)wrqu;
2536         int selector;
2537
2538         if ((padapter->bDriverStopped) || (pdata == NULL)) {
2539                 ret = -EINVAL;
2540                 goto exit;
2541         }
2542
2543         selector = *pdata;
2544         if (selector < 3 && selector >= 0) {
2545                 padapter->pid[selector] = *(pdata+1);
2546                 DBG_871X("%s set pid[%d]=%d\n", __func__, selector, padapter->pid[selector]);
2547         }
2548         else
2549                 DBG_871X("%s selector %d error\n", __func__, selector);
2550
2551 exit:
2552
2553         return ret;
2554
2555 }
2556
2557 static int rtw_wps_start(struct net_device *dev,
2558                                struct iw_request_info *info,
2559                                union iwreq_data *wrqu, char *extra)
2560 {
2561
2562         int ret = 0;
2563         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
2564         struct iw_point *pdata = &wrqu->data;
2565         u32   u32wps_start = 0;
2566
2567         if ((true == padapter->bDriverStopped) || (true == padapter->bSurpriseRemoved) || (NULL == pdata)) {
2568                 ret = -EINVAL;
2569                 goto exit;
2570         }
2571
2572         if (copy_from_user((void *)&u32wps_start, pdata->pointer, 4)) {
2573                 ret = -EFAULT;
2574                 goto exit;
2575         }
2576         if (u32wps_start == 0)
2577                 u32wps_start = *extra;
2578
2579         DBG_871X("[%s] wps_start = %d\n", __func__, u32wps_start);
2580
2581 exit:
2582
2583         return ret;
2584
2585 }
2586
2587 static int rtw_p2p_set(struct net_device *dev,
2588                                struct iw_request_info *info,
2589                                union iwreq_data *wrqu, char *extra)
2590 {
2591
2592         return 0;
2593
2594 }
2595
2596 static int rtw_p2p_get(struct net_device *dev,
2597                                struct iw_request_info *info,
2598                                union iwreq_data *wrqu, char *extra)
2599 {
2600
2601         return 0;
2602
2603 }
2604
2605 static int rtw_p2p_get2(struct net_device *dev,
2606                                                 struct iw_request_info *info,
2607                                                 union iwreq_data *wrqu, char *extra)
2608 {
2609
2610         return 0;
2611
2612 }
2613
2614 static int rtw_rereg_nd_name(struct net_device *dev,
2615                                struct iw_request_info *info,
2616                                union iwreq_data *wrqu, char *extra)
2617 {
2618         int ret = 0;
2619         struct adapter *padapter = rtw_netdev_priv(dev);
2620         struct rereg_nd_name_data *rereg_priv = &padapter->rereg_nd_name_priv;
2621         char new_ifname[IFNAMSIZ];
2622
2623         if (rereg_priv->old_ifname[0] == 0) {
2624                 char *reg_ifname;
2625                 reg_ifname = padapter->registrypriv.ifname;
2626
2627                 strncpy(rereg_priv->old_ifname, reg_ifname, IFNAMSIZ);
2628                 rereg_priv->old_ifname[IFNAMSIZ-1] = 0;
2629         }
2630
2631         /* DBG_871X("%s wrqu->data.length:%d\n", __func__, wrqu->data.length); */
2632         if (wrqu->data.length > IFNAMSIZ)
2633                 return -EFAULT;
2634
2635         if (copy_from_user(new_ifname, wrqu->data.pointer, IFNAMSIZ))
2636                 return -EFAULT;
2637
2638         if (0 == strcmp(rereg_priv->old_ifname, new_ifname))
2639                 return ret;
2640
2641         DBG_871X("%s new_ifname:%s\n", __func__, new_ifname);
2642         if (0 != (ret = rtw_change_ifname(padapter, new_ifname)))
2643                 goto exit;
2644
2645         strncpy(rereg_priv->old_ifname, new_ifname, IFNAMSIZ);
2646         rereg_priv->old_ifname[IFNAMSIZ-1] = 0;
2647
2648         if (!memcmp(new_ifname, "disable%d", 9)) {
2649
2650                 DBG_871X("%s disable\n", __func__);
2651                 /*  free network queue for Android's timming issue */
2652                 rtw_free_network_queue(padapter, true);
2653
2654                 /*  the interface is being "disabled", we can do deeper IPS */
2655                 /* rereg_priv->old_ips_mode = rtw_get_ips_mode_req(&padapter->pwrctrlpriv); */
2656                 /* rtw_ips_mode_req(&padapter->pwrctrlpriv, IPS_NORMAL); */
2657         }
2658 exit:
2659         return ret;
2660
2661 }
2662
2663 static int rtw_dbg_port(struct net_device *dev,
2664                                struct iw_request_info *info,
2665                                union iwreq_data *wrqu, char *extra)
2666 {
2667         u8 major_cmd, minor_cmd;
2668         u16 arg;
2669         u32 extra_arg, *pdata, val32;
2670         struct sta_info *psta;
2671         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
2672         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
2673         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2674         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
2675         struct wlan_network *cur_network = &(pmlmepriv->cur_network);
2676         struct sta_priv *pstapriv = &padapter->stapriv;
2677
2678
2679         pdata = (u32 *)&wrqu->data;
2680
2681         val32 = *pdata;
2682         arg = (u16)(val32&0x0000ffff);
2683         major_cmd = (u8)(val32>>24);
2684         minor_cmd = (u8)((val32>>16)&0x00ff);
2685
2686         extra_arg = *(pdata+1);
2687
2688         switch (major_cmd) {
2689                 case 0x70:/* read_reg */
2690                         switch (minor_cmd) {
2691                                 case 1:
2692                                         DBG_871X("rtw_read8(0x%x) = 0x%02x\n", arg, rtw_read8(padapter, arg));
2693                                         break;
2694                                 case 2:
2695                                         DBG_871X("rtw_read16(0x%x) = 0x%04x\n", arg, rtw_read16(padapter, arg));
2696                                         break;
2697                                 case 4:
2698                                         DBG_871X("rtw_read32(0x%x) = 0x%08x\n", arg, rtw_read32(padapter, arg));
2699                                         break;
2700                         }
2701                         break;
2702                 case 0x71:/* write_reg */
2703                         switch (minor_cmd) {
2704                                 case 1:
2705                                         rtw_write8(padapter, arg, extra_arg);
2706                                         DBG_871X("rtw_write8(0x%x) = 0x%02x\n", arg, rtw_read8(padapter, arg));
2707                                         break;
2708                                 case 2:
2709                                         rtw_write16(padapter, arg, extra_arg);
2710                                         DBG_871X("rtw_write16(0x%x) = 0x%04x\n", arg, rtw_read16(padapter, arg));
2711                                         break;
2712                                 case 4:
2713                                         rtw_write32(padapter, arg, extra_arg);
2714                                         DBG_871X("rtw_write32(0x%x) = 0x%08x\n", arg, rtw_read32(padapter, arg));
2715                                         break;
2716                         }
2717                         break;
2718                 case 0x72:/* read_bb */
2719                         DBG_871X("read_bbreg(0x%x) = 0x%x\n", arg, rtw_hal_read_bbreg(padapter, arg, 0xffffffff));
2720                         break;
2721                 case 0x73:/* write_bb */
2722                         rtw_hal_write_bbreg(padapter, arg, 0xffffffff, extra_arg);
2723                         DBG_871X("write_bbreg(0x%x) = 0x%x\n", arg, rtw_hal_read_bbreg(padapter, arg, 0xffffffff));
2724                         break;
2725                 case 0x74:/* read_rf */
2726                         DBG_871X("read RF_reg path(0x%02x), offset(0x%x), value(0x%08x)\n", minor_cmd, arg, rtw_hal_read_rfreg(padapter, minor_cmd, arg, 0xffffffff));
2727                         break;
2728                 case 0x75:/* write_rf */
2729                         rtw_hal_write_rfreg(padapter, minor_cmd, arg, 0xffffffff, extra_arg);
2730                         DBG_871X("write RF_reg path(0x%02x), offset(0x%x), value(0x%08x)\n", minor_cmd, arg, rtw_hal_read_rfreg(padapter, minor_cmd, arg, 0xffffffff));
2731                         break;
2732
2733                 case 0x76:
2734                         switch (minor_cmd) {
2735                                 case 0x00: /* normal mode, */
2736                                         padapter->recvpriv.is_signal_dbg = 0;
2737                                         break;
2738                                 case 0x01: /* dbg mode */
2739                                         padapter->recvpriv.is_signal_dbg = 1;
2740                                         extra_arg = extra_arg > 100 ? 100 : extra_arg;
2741                                         padapter->recvpriv.signal_strength_dbg = extra_arg;
2742                                         break;
2743                         }
2744                         break;
2745                 case 0x78: /* IOL test */
2746                         break;
2747                 case 0x79:
2748                         {
2749                                 /*
2750                                 * dbg 0x79000000 [value], set RESP_TXAGC to + value, value:0~15
2751                                 * dbg 0x79010000 [value], set RESP_TXAGC to - value, value:0~15
2752                                 */
2753                                 u8 value =  extra_arg & 0x0f;
2754                                 u8 sign = minor_cmd;
2755                                 u16 write_value = 0;
2756
2757                                 DBG_871X("%s set RESP_TXAGC to %s %u\n", __func__, sign?"minus":"plus", value);
2758
2759                                 if (sign)
2760                                         value = value | 0x10;
2761
2762                                 write_value = value | (value << 5);
2763                                 rtw_write16(padapter, 0x6d9, write_value);
2764                         }
2765                         break;
2766                 case 0x7a:
2767                         receive_disconnect(padapter, pmlmeinfo->network.MacAddress
2768                                 , WLAN_REASON_EXPIRATION_CHK);
2769                         break;
2770                 case 0x7F:
2771                         switch (minor_cmd) {
2772                                 case 0x0:
2773                                         DBG_871X("fwstate = 0x%x\n", get_fwstate(pmlmepriv));
2774                                         break;
2775                                 case 0x01:
2776                                         DBG_871X("minor_cmd 0x%x\n", minor_cmd);
2777                                         break;
2778                                 case 0x02:
2779                                         DBG_871X("pmlmeinfo->state = 0x%x\n", pmlmeinfo->state);
2780                                         DBG_871X("DrvBcnEarly =%d\n", pmlmeext->DrvBcnEarly);
2781                                         DBG_871X("DrvBcnTimeOut =%d\n", pmlmeext->DrvBcnTimeOut);
2782                                         break;
2783                                 case 0x03:
2784                                         DBG_871X("qos_option =%d\n", pmlmepriv->qospriv.qos_option);
2785                                         DBG_871X("ht_option =%d\n", pmlmepriv->htpriv.ht_option);
2786                                         break;
2787                                 case 0x04:
2788                                         DBG_871X("cur_ch =%d\n", pmlmeext->cur_channel);
2789                                         DBG_871X("cur_bw =%d\n", pmlmeext->cur_bwmode);
2790                                         DBG_871X("cur_ch_off =%d\n", pmlmeext->cur_ch_offset);
2791
2792                                         DBG_871X("oper_ch =%d\n", rtw_get_oper_ch(padapter));
2793                                         DBG_871X("oper_bw =%d\n", rtw_get_oper_bw(padapter));
2794                                         DBG_871X("oper_ch_offset =%d\n", rtw_get_oper_choffset(padapter));
2795
2796                                         break;
2797                                 case 0x05:
2798                                         psta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
2799                                         if (psta) {
2800                                                 int i;
2801                                                 struct recv_reorder_ctrl *preorder_ctrl;
2802
2803                                                 DBG_871X("SSID =%s\n", cur_network->network.Ssid.Ssid);
2804                                                 DBG_871X("sta's macaddr:" MAC_FMT "\n", MAC_ARG(psta->hwaddr));
2805                                                 DBG_871X("cur_channel =%d, cur_bwmode =%d, cur_ch_offset =%d\n", pmlmeext->cur_channel, pmlmeext->cur_bwmode, pmlmeext->cur_ch_offset);
2806                                                 DBG_871X("rtsen =%d, cts2slef =%d\n", psta->rtsen, psta->cts2self);
2807                                                 DBG_871X("state = 0x%x, aid =%d, macid =%d, raid =%d\n", psta->state, psta->aid, psta->mac_id, psta->raid);
2808                                                 DBG_871X("qos_en =%d, ht_en =%d, init_rate =%d\n", psta->qos_option, psta->htpriv.ht_option, psta->init_rate);
2809                                                 DBG_871X("bwmode =%d, ch_offset =%d, sgi_20m =%d, sgi_40m =%d\n", psta->bw_mode, psta->htpriv.ch_offset, psta->htpriv.sgi_20m, psta->htpriv.sgi_40m);
2810                                                 DBG_871X("ampdu_enable = %d\n", psta->htpriv.ampdu_enable);
2811                                                 DBG_871X("agg_enable_bitmap =%x, candidate_tid_bitmap =%x\n", psta->htpriv.agg_enable_bitmap, psta->htpriv.candidate_tid_bitmap);
2812
2813                                                 for (i = 0; i < 16; i++) {
2814                                                         preorder_ctrl = &psta->recvreorder_ctrl[i];
2815                                                         if (preorder_ctrl->enable)
2816                                                                 DBG_871X("tid =%d, indicate_seq =%d\n", i, preorder_ctrl->indicate_seq);
2817                                                 }
2818
2819                                         } else {
2820                                                 DBG_871X("can't get sta's macaddr, cur_network's macaddr:" MAC_FMT "\n", MAC_ARG(cur_network->network.MacAddress));
2821                                         }
2822                                         break;
2823                                 case 0x06:
2824                                         {
2825                                                 u32 ODMFlag;
2826                                                 rtw_hal_get_hwreg(padapter, HW_VAR_DM_FLAG, (u8 *)(&ODMFlag));
2827                                                 DBG_871X("(B)DMFlag = 0x%x, arg = 0x%x\n", ODMFlag, arg);
2828                                                 ODMFlag = (u32)(0x0f&arg);
2829                                                 DBG_871X("(A)DMFlag = 0x%x\n", ODMFlag);
2830                                                 rtw_hal_set_hwreg(padapter, HW_VAR_DM_FLAG, (u8 *)(&ODMFlag));
2831                                         }
2832                                         break;
2833                                 case 0x07:
2834                                         DBG_871X("bSurpriseRemoved =%d, bDriverStopped =%d\n",
2835                                                 padapter->bSurpriseRemoved, padapter->bDriverStopped);
2836                                         break;
2837                                 case 0x08:
2838                                         {
2839                                                 DBG_871X("minor_cmd 0x%x\n", minor_cmd);
2840                                         }
2841                                         break;
2842                                 case 0x09:
2843                                         {
2844                                                 int i, j;
2845                                                 struct list_head        *plist, *phead;
2846                                                 struct recv_reorder_ctrl *preorder_ctrl;
2847
2848                                                 DBG_871X("sta_dz_bitmap = 0x%x, tim_bitmap = 0x%x\n", pstapriv->sta_dz_bitmap, pstapriv->tim_bitmap);
2849
2850                                                 spin_lock_bh(&pstapriv->sta_hash_lock);
2851
2852                                                 for (i = 0; i < NUM_STA; i++) {
2853                                                         phead = &(pstapriv->sta_hash[i]);
2854                                                         plist = get_next(phead);
2855
2856                                                         while (phead != plist) {
2857                                                                 psta = LIST_CONTAINOR(plist, struct sta_info, hash_list);
2858
2859                                                                 plist = get_next(plist);
2860
2861                                                                 if (extra_arg == psta->aid) {
2862                                                                         DBG_871X("sta's macaddr:" MAC_FMT "\n", MAC_ARG(psta->hwaddr));
2863                                                                         DBG_871X("rtsen =%d, cts2slef =%d\n", psta->rtsen, psta->cts2self);
2864                                                                         DBG_871X("state = 0x%x, aid =%d, macid =%d, raid =%d\n", psta->state, psta->aid, psta->mac_id, psta->raid);
2865                                                                         DBG_871X("qos_en =%d, ht_en =%d, init_rate =%d\n", psta->qos_option, psta->htpriv.ht_option, psta->init_rate);
2866                                                                         DBG_871X("bwmode =%d, ch_offset =%d, sgi_20m =%d, sgi_40m =%d\n", psta->bw_mode, psta->htpriv.ch_offset, psta->htpriv.sgi_20m, psta->htpriv.sgi_40m);
2867                                                                         DBG_871X("ampdu_enable = %d\n", psta->htpriv.ampdu_enable);
2868                                                                         DBG_871X("agg_enable_bitmap =%x, candidate_tid_bitmap =%x\n", psta->htpriv.agg_enable_bitmap, psta->htpriv.candidate_tid_bitmap);
2869                                                                         DBG_871X("capability = 0x%x\n", psta->capability);
2870                                                                         DBG_871X("flags = 0x%x\n", psta->flags);
2871                                                                         DBG_871X("wpa_psk = 0x%x\n", psta->wpa_psk);
2872                                                                         DBG_871X("wpa2_group_cipher = 0x%x\n", psta->wpa2_group_cipher);
2873                                                                         DBG_871X("wpa2_pairwise_cipher = 0x%x\n", psta->wpa2_pairwise_cipher);
2874                                                                         DBG_871X("qos_info = 0x%x\n", psta->qos_info);
2875                                                                         DBG_871X("dot118021XPrivacy = 0x%x\n", psta->dot118021XPrivacy);
2876
2877
2878
2879                                                                         for (j = 0; j < 16; j++) {
2880                                                                                 preorder_ctrl = &psta->recvreorder_ctrl[j];
2881                                                                                 if (preorder_ctrl->enable)
2882                                                                                         DBG_871X("tid =%d, indicate_seq =%d\n", j, preorder_ctrl->indicate_seq);
2883                                                                         }
2884                                                                 }
2885                                                         }
2886                                                 }
2887
2888                                                 spin_unlock_bh(&pstapriv->sta_hash_lock);
2889
2890                                         }
2891                                         break;
2892                                 case 0x0a:
2893                                         {
2894                                                 int max_mac_id = 0;
2895                                                 max_mac_id = rtw_search_max_mac_id(padapter);
2896                                                 printk("%s ==> max_mac_id = %d\n", __func__, max_mac_id);
2897                                         }
2898                                         break;
2899                                 case 0x0b: /* Enable = 1, Disable = 0 driver control vrtl_carrier_sense. */
2900                                         if (arg == 0) {
2901                                                 DBG_871X("disable driver ctrl vcs\n");
2902                                                 padapter->driver_vcs_en = 0;
2903                                         } else if (arg == 1) {
2904                                                 DBG_871X("enable driver ctrl vcs = %d\n", extra_arg);
2905                                                 padapter->driver_vcs_en = 1;
2906
2907                                                 if (extra_arg > 2)
2908                                                         padapter->driver_vcs_type = 1;
2909                                                 else
2910                                                         padapter->driver_vcs_type = extra_arg;
2911                                         }
2912                                         break;
2913                                 case 0x0c:/* dump rx/tx packet */
2914                                         {
2915                                                 if (arg == 0) {
2916                                                         DBG_871X("dump rx packet (%d)\n", extra_arg);
2917                                                         /* pHalData->bDumpRxPkt =extra_arg; */
2918                                                         rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DUMP_RXPKT, &(extra_arg));
2919                                                 } else if (arg == 1) {
2920                                                         DBG_871X("dump tx packet (%d)\n", extra_arg);
2921                                                         rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DUMP_TXPKT, &(extra_arg));
2922                                                 }
2923                                         }
2924                                         break;
2925                                 case 0x0e:
2926                                         {
2927                                                 if (arg == 0) {
2928                                                         DBG_871X("disable driver ctrl rx_ampdu_factor\n");
2929                                                         padapter->driver_rx_ampdu_factor = 0xFF;
2930                                                 } else if (arg == 1) {
2931
2932                                                         DBG_871X("enable driver ctrl rx_ampdu_factor = %d\n", extra_arg);
2933
2934                                                         if ((extra_arg & 0x03) > 0x03)
2935                                                                 padapter->driver_rx_ampdu_factor = 0xFF;
2936                                                         else
2937                                                                 padapter->driver_rx_ampdu_factor = extra_arg;
2938                                                 }
2939                                         }
2940                                         break;
2941
2942                                 case 0x10:/*  driver version display */
2943                                         dump_drv_version(RTW_DBGDUMP);
2944                                         break;
2945                                 case 0x11:/* dump linked status */
2946                                         {
2947                                                  linked_info_dump(padapter, extra_arg);
2948                                         }
2949                                         break;
2950                                 case 0x12: /* set rx_stbc */
2951                                 {
2952                                         struct registry_priv *pregpriv = &padapter->registrypriv;
2953                                         /*  0: disable, bit(0):enable 2.4g, bit(1):enable 5g, 0x3: enable both 2.4g and 5g */
2954                                         /* default is set to enable 2.4GHZ for IOT issue with bufflao's AP at 5GHZ */
2955                                         if (extra_arg == 0 || extra_arg == 1 || extra_arg == 2 || extra_arg == 3) {
2956                                                 pregpriv->rx_stbc = extra_arg;
2957                                                 DBG_871X("set rx_stbc =%d\n", pregpriv->rx_stbc);
2958                                         } else
2959                                                 DBG_871X("get rx_stbc =%d\n", pregpriv->rx_stbc);
2960
2961                                 }
2962                                 break;
2963                                 case 0x13: /* set ampdu_enable */
2964                                 {
2965                                         struct registry_priv *pregpriv = &padapter->registrypriv;
2966                                         /*  0: disable, 0x1:enable (but wifi_spec should be 0), 0x2: force enable (don't care wifi_spec) */
2967                                         if (extra_arg < 3) {
2968                                                 pregpriv->ampdu_enable = extra_arg;
2969                                                 DBG_871X("set ampdu_enable =%d\n", pregpriv->ampdu_enable);
2970                                         } else
2971                                                 DBG_871X("get ampdu_enable =%d\n", pregpriv->ampdu_enable);
2972
2973                                 }
2974                                 break;
2975                                 case 0x14:
2976                                 {
2977                                         DBG_871X("minor_cmd 0x%x\n", minor_cmd);
2978                                 }
2979                                 break;
2980                                 case 0x16:
2981                                 {
2982                                         if (arg == 0xff) {
2983                                                 rtw_odm_dbg_comp_msg(RTW_DBGDUMP, padapter);
2984                                         } else {
2985                                                 u64 dbg_comp = (u64)extra_arg;
2986                                                 rtw_odm_dbg_comp_set(padapter, dbg_comp);
2987                                         }
2988                                 }
2989                                         break;
2990 #ifdef DBG_FIXED_CHAN
2991                                 case 0x17:
2992                                         {
2993                                                 struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
2994                                                 printk("===>  Fixed channel to %d\n", extra_arg);
2995                                                 pmlmeext->fixed_chan = extra_arg;
2996
2997                                         }
2998                                         break;
2999 #endif
3000                                 case 0x18:
3001                                         {
3002                                                 printk("===>  Switch USB Mode %d\n", extra_arg);
3003                                                 rtw_hal_set_hwreg(padapter, HW_VAR_USB_MODE, (u8 *)&extra_arg);
3004                                         }
3005                                         break;
3006                                 case 0x19:
3007                                         {
3008                                                 struct registry_priv *pregistrypriv = &padapter->registrypriv;
3009                                                 /*  extra_arg : */
3010                                                 /*  BIT0: Enable VHT LDPC Rx, BIT1: Enable VHT LDPC Tx, */
3011                                                 /*  BIT4: Enable HT LDPC Rx, BIT5: Enable HT LDPC Tx */
3012                                                 if (arg == 0) {
3013                                                         DBG_871X("driver disable LDPC\n");
3014                                                         pregistrypriv->ldpc_cap = 0x00;
3015                                                 } else if (arg == 1) {
3016                                                         DBG_871X("driver set LDPC cap = 0x%x\n", extra_arg);
3017                                                         pregistrypriv->ldpc_cap = (u8)(extra_arg&0x33);
3018                                                 }
3019                                         }
3020                                         break;
3021                                 case 0x1a:
3022                                         {
3023                                                 struct registry_priv *pregistrypriv = &padapter->registrypriv;
3024                                                 /*  extra_arg : */
3025                                                 /*  BIT0: Enable VHT STBC Rx, BIT1: Enable VHT STBC Tx, */
3026                                                 /*  BIT4: Enable HT STBC Rx, BIT5: Enable HT STBC Tx */
3027                                                 if (arg == 0) {
3028                                                         DBG_871X("driver disable STBC\n");
3029                                                         pregistrypriv->stbc_cap = 0x00;
3030                                                 } else if (arg == 1) {
3031                                                         DBG_871X("driver set STBC cap = 0x%x\n", extra_arg);
3032                                                         pregistrypriv->stbc_cap = (u8)(extra_arg&0x33);
3033                                                 }
3034                                         }
3035                                         break;
3036                                 case 0x1b:
3037                                         {
3038                                                 struct registry_priv *pregistrypriv = &padapter->registrypriv;
3039
3040                                                 if (arg == 0) {
3041                                                         DBG_871X("disable driver ctrl max_rx_rate, reset to default_rate_set\n");
3042                                                         init_mlme_default_rate_set(padapter);
3043                                                         pregistrypriv->ht_enable = (u8)rtw_ht_enable;
3044                                                 } else if (arg == 1) {
3045
3046                                                         int i;
3047                                                         u8 max_rx_rate;
3048
3049                                                         DBG_871X("enable driver ctrl max_rx_rate = 0x%x\n", extra_arg);
3050
3051                                                         max_rx_rate = (u8)extra_arg;
3052
3053                                                         if (max_rx_rate < 0xc) { /*  max_rx_rate < MSC0 -> B or G -> disable HT */
3054                                                                 pregistrypriv->ht_enable = 0;
3055                                                                 for (i = 0; i < NumRates; i++) {
3056                                                                         if (pmlmeext->datarate[i] > max_rx_rate)
3057                                                                                 pmlmeext->datarate[i] = 0xff;
3058                                                                 }
3059
3060                                                         }
3061                                                         else if (max_rx_rate < 0x1c) { /*  mcs0~mcs15 */
3062                                                                 u32 mcs_bitmap = 0x0;
3063
3064                                                                 for (i = 0; i < ((max_rx_rate + 1) - 0xc); i++)
3065                                                                         mcs_bitmap |= BIT(i);
3066
3067                                                                 set_mcs_rate_by_mask(pmlmeext->default_supported_mcs_set, mcs_bitmap);
3068                                                         }
3069                                                 }
3070                                         }
3071                                         break;
3072                                 case 0x1c: /* enable/disable driver control AMPDU Density for peer sta's rx */
3073                                         {
3074                                                 if (arg == 0) {
3075                                                         DBG_871X("disable driver ctrl ampdu density\n");
3076                                                         padapter->driver_ampdu_spacing = 0xFF;
3077                                                 } else if (arg == 1) {
3078
3079                                                         DBG_871X("enable driver ctrl ampdu density = %d\n", extra_arg);
3080
3081                                                         if (extra_arg > 0x07)
3082                                                                 padapter->driver_ampdu_spacing = 0xFF;
3083                                                         else
3084                                                                 padapter->driver_ampdu_spacing = extra_arg;
3085                                                 }
3086                                         }
3087                                         break;
3088 #ifdef CONFIG_BACKGROUND_NOISE_MONITOR
3089                                 case 0x1e:
3090                                         {
3091                                                 struct hal_com_data     *pHalData = GET_HAL_DATA(padapter);
3092                                                 PDM_ODM_T pDM_Odm = &pHalData->odmpriv;
3093                                                 u8 chan = rtw_get_oper_ch(padapter);
3094                                                 DBG_871X("===========================================\n");
3095                                                 ODM_InbandNoise_Monitor(pDM_Odm, true, 0x1e, 100);
3096                                                 DBG_871X("channel(%d), noise_a = %d, noise_b = %d , noise_all:%d\n",
3097                                                         chan, pDM_Odm->noise_level.noise[ODM_RF_PATH_A],
3098                                                         pDM_Odm->noise_level.noise[ODM_RF_PATH_B],
3099                                                         pDM_Odm->noise_level.noise_all);
3100                                                 DBG_871X("===========================================\n");
3101
3102                                         }
3103                                         break;
3104 #endif
3105                                 case 0x23:
3106                                         {
3107                                                 DBG_871X("turn %s the bNotifyChannelChange Variable\n", (extra_arg == 1)?"on":"off");
3108                                                 padapter->bNotifyChannelChange = extra_arg;
3109                                                 break;
3110                                         }
3111                                 case 0x24:
3112                                         {
3113                                                 break;
3114                                         }
3115 #ifdef CONFIG_GPIO_API
3116                             case 0x25: /* Get GPIO register */
3117                                     {
3118                                             /*
3119                                             * dbg 0x7f250000 [gpio_num], Get gpio value, gpio_num:0~7
3120                                             */
3121
3122                                             int value;
3123                                             DBG_871X("Read GPIO Value  extra_arg = %d\n", extra_arg);
3124                                             value = rtw_get_gpio(dev, extra_arg);
3125                                             DBG_871X("Read GPIO Value = %d\n", value);
3126                                             break;
3127                                     }
3128                             case 0x26: /* Set GPIO direction */
3129                                     {
3130
3131                                             /* dbg 0x7f26000x [y], Set gpio direction,
3132                                             * x: gpio_num, 4~7  y: indicate direction, 0~1
3133                                             */
3134
3135                                             int value;
3136                                             DBG_871X("Set GPIO Direction! arg = %d , extra_arg =%d\n", arg, extra_arg);
3137                                             value = rtw_config_gpio(dev, arg, extra_arg);
3138                                             DBG_871X("Set GPIO Direction %s\n", (value == -1) ? "Fail!!!" : "Success");
3139                                             break;
3140                                         }
3141                                 case 0x27: /* Set GPIO output direction value */
3142                                         {
3143                                                 /*
3144                                                 * dbg 0x7f27000x [y], Set gpio output direction value,
3145                                                 * x: gpio_num, 4~7  y: indicate direction, 0~1
3146                                                 */
3147
3148                                                 int value;
3149                                                 DBG_871X("Set GPIO Value! arg = %d , extra_arg =%d\n", arg, extra_arg);
3150                                                 value = rtw_set_gpio_output_value(dev, arg, extra_arg);
3151                                                 DBG_871X("Set GPIO Value %s\n", (value == -1) ? "Fail!!!" : "Success");
3152                                                 break;
3153                                         }
3154 #endif
3155                                 case 0xaa:
3156                                         {
3157                                                 if ((extra_arg & 0x7F) > 0x3F) extra_arg = 0xFF;
3158                                                 DBG_871X("chang data rate to :0x%02x\n", extra_arg);
3159                                                 padapter->fix_rate = extra_arg;
3160                                         }
3161                                         break;
3162                                 case 0xdd:/* registers dump , 0 for mac reg, 1 for bb reg, 2 for rf reg */
3163                                         {
3164                                                 if (extra_arg == 0)
3165                                                         mac_reg_dump(RTW_DBGDUMP, padapter);
3166                                                 else if (extra_arg == 1)
3167                                                         bb_reg_dump(RTW_DBGDUMP, padapter);
3168                                                 else if (extra_arg == 2)
3169                                                         rf_reg_dump(RTW_DBGDUMP, padapter);
3170                                         }
3171                                         break;
3172
3173                                 case 0xee:/* turn on/off dynamic funcs */
3174                                         {
3175                                                 u32 odm_flag;
3176
3177                                                 if (0xf == extra_arg) {
3178                                                         rtw_hal_get_def_var(padapter, HAL_DEF_DBG_DM_FUNC, &odm_flag);
3179                                                         DBG_871X(" === DMFlag(0x%08x) ===\n", odm_flag);
3180                                                         DBG_871X("extra_arg = 0  - disable all dynamic func\n");
3181                                                         DBG_871X("extra_arg = 1  - disable DIG- BIT(0)\n");
3182                                                         DBG_871X("extra_arg = 2  - disable High power - BIT(1)\n");
3183                                                         DBG_871X("extra_arg = 3  - disable tx power tracking - BIT(2)\n");
3184                                                         DBG_871X("extra_arg = 4  - disable BT coexistence - BIT(3)\n");
3185                                                         DBG_871X("extra_arg = 5  - disable antenna diversity - BIT(4)\n");
3186                                                         DBG_871X("extra_arg = 6  - enable all dynamic func\n");
3187                                                 } else {
3188                                                         /*extra_arg = 0  - disable all dynamic func
3189                                                                 extra_arg = 1  - disable DIG
3190                                                                 extra_arg = 2  - disable tx power tracking
3191                                                                 extra_arg = 3  - turn on all dynamic func
3192                                                         */
3193                                                         rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DM_FUNC, &(extra_arg));
3194                                                         rtw_hal_get_def_var(padapter, HAL_DEF_DBG_DM_FUNC, &odm_flag);
3195                                                         DBG_871X(" === DMFlag(0x%08x) ===\n", odm_flag);
3196                                                 }
3197                                         }
3198                                         break;
3199
3200                                 case 0xfd:
3201                                         rtw_write8(padapter, 0xc50, arg);
3202                                         DBG_871X("wr(0xc50) = 0x%x\n", rtw_read8(padapter, 0xc50));
3203                                         rtw_write8(padapter, 0xc58, arg);
3204                                         DBG_871X("wr(0xc58) = 0x%x\n", rtw_read8(padapter, 0xc58));
3205                                         break;
3206                                 case 0xfe:
3207                                         DBG_871X("rd(0xc50) = 0x%x\n", rtw_read8(padapter, 0xc50));
3208                                         DBG_871X("rd(0xc58) = 0x%x\n", rtw_read8(padapter, 0xc58));
3209                                         break;
3210                                 case 0xff:
3211                                         {
3212                                                 DBG_871X("dbg(0x210) = 0x%x\n", rtw_read32(padapter, 0x210));
3213                                                 DBG_871X("dbg(0x608) = 0x%x\n", rtw_read32(padapter, 0x608));
3214                                                 DBG_871X("dbg(0x280) = 0x%x\n", rtw_read32(padapter, 0x280));
3215                                                 DBG_871X("dbg(0x284) = 0x%x\n", rtw_read32(padapter, 0x284));
3216                                                 DBG_871X("dbg(0x288) = 0x%x\n", rtw_read32(padapter, 0x288));
3217
3218                                                 DBG_871X("dbg(0x664) = 0x%x\n", rtw_read32(padapter, 0x664));
3219
3220
3221                                                 DBG_871X("\n");
3222
3223                                                 DBG_871X("dbg(0x430) = 0x%x\n", rtw_read32(padapter, 0x430));
3224                                                 DBG_871X("dbg(0x438) = 0x%x\n", rtw_read32(padapter, 0x438));
3225
3226                                                 DBG_871X("dbg(0x440) = 0x%x\n", rtw_read32(padapter, 0x440));
3227
3228                                                 DBG_871X("dbg(0x458) = 0x%x\n", rtw_read32(padapter, 0x458));
3229
3230                                                 DBG_871X("dbg(0x484) = 0x%x\n", rtw_read32(padapter, 0x484));
3231                                                 DBG_871X("dbg(0x488) = 0x%x\n", rtw_read32(padapter, 0x488));
3232
3233                                                 DBG_871X("dbg(0x444) = 0x%x\n", rtw_read32(padapter, 0x444));
3234                                                 DBG_871X("dbg(0x448) = 0x%x\n", rtw_read32(padapter, 0x448));
3235                                                 DBG_871X("dbg(0x44c) = 0x%x\n", rtw_read32(padapter, 0x44c));
3236                                                 DBG_871X("dbg(0x450) = 0x%x\n", rtw_read32(padapter, 0x450));
3237                                         }
3238                                         break;
3239                         }
3240                         break;
3241                 default:
3242                         DBG_871X("error dbg cmd!\n");
3243                         break;
3244         }
3245
3246
3247         return 0;
3248
3249 }
3250
3251 static int wpa_set_param(struct net_device *dev, u8 name, u32 value)
3252 {
3253         uint ret = 0;
3254         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3255
3256         switch (name) {
3257         case IEEE_PARAM_WPA_ENABLED:
3258
3259                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_8021X; /* 802.1x */
3260
3261                 /* ret = ieee80211_wpa_enable(ieee, value); */
3262
3263                 switch ((value)&0xff) {
3264                 case 1: /* WPA */
3265                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPAPSK; /* WPA_PSK */
3266                         padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
3267                         break;
3268                 case 2: /* WPA2 */
3269                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPA2PSK; /* WPA2_PSK */
3270                         padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
3271                         break;
3272                 }
3273
3274                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_, ("wpa_set_param:padapter->securitypriv.ndisauthtype =%d\n", padapter->securitypriv.ndisauthtype));
3275
3276                 break;
3277
3278         case IEEE_PARAM_TKIP_COUNTERMEASURES:
3279                 /* ieee->tkip_countermeasures =value; */
3280                 break;
3281
3282         case IEEE_PARAM_DROP_UNENCRYPTED:
3283         {
3284                 /* HACK:
3285                  *
3286                  * wpa_supplicant calls set_wpa_enabled when the driver
3287                  * is loaded and unloaded, regardless of if WPA is being
3288                  * used.  No other calls are made which can be used to
3289                  * determine if encryption will be used or not prior to
3290                  * association being expected.  If encryption is not being
3291                  * used, drop_unencrypted is set to false, else true -- we
3292                  * can use this to determine if the CAP_PRIVACY_ON bit should
3293                  * be set.
3294                  */
3295                 break;
3296
3297         }
3298         case IEEE_PARAM_PRIVACY_INVOKED:
3299
3300                 /* ieee->privacy_invoked =value; */
3301
3302                 break;
3303
3304         case IEEE_PARAM_AUTH_ALGS:
3305
3306                 ret = wpa_set_auth_algs(dev, value);
3307
3308                 break;
3309
3310         case IEEE_PARAM_IEEE_802_1X:
3311
3312                 /* ieee->ieee802_1x =value; */
3313
3314                 break;
3315
3316         case IEEE_PARAM_WPAX_SELECT:
3317
3318                 /*  added for WPA2 mixed mode */
3319                 /* DBG_871X(KERN_WARNING "------------------------>wpax value = %x\n", value); */
3320                 /*
3321                 spin_lock_irqsave(&ieee->wpax_suitlist_lock, flags);
3322                 ieee->wpax_type_set = 1;
3323                 ieee->wpax_type_notify = value;
3324                 spin_unlock_irqrestore(&ieee->wpax_suitlist_lock, flags);
3325                 */
3326
3327                 break;
3328
3329         default:
3330
3331
3332
3333                 ret = -EOPNOTSUPP;
3334
3335
3336                 break;
3337
3338         }
3339
3340         return ret;
3341
3342 }
3343
3344 static int wpa_mlme(struct net_device *dev, u32 command, u32 reason)
3345 {
3346         int ret = 0;
3347         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3348
3349         switch (command) {
3350         case IEEE_MLME_STA_DEAUTH:
3351
3352                 if (!rtw_set_802_11_disassociate(padapter))
3353                         ret = -1;
3354
3355                 break;
3356
3357         case IEEE_MLME_STA_DISASSOC:
3358
3359                 if (!rtw_set_802_11_disassociate(padapter))
3360                         ret = -1;
3361
3362                 break;
3363
3364         default:
3365                 ret = -EOPNOTSUPP;
3366                 break;
3367         }
3368
3369         return ret;
3370
3371 }
3372
3373 static int wpa_supplicant_ioctl(struct net_device *dev, struct iw_point *p)
3374 {
3375         struct ieee_param *param;
3376         uint ret = 0;
3377
3378         /* down(&ieee->wx_sem); */
3379
3380         if (!p->pointer || p->length != sizeof(struct ieee_param))
3381                 return -EINVAL;
3382
3383         param = rtw_malloc(p->length);
3384         if (param == NULL)
3385                 return -ENOMEM;
3386
3387         if (copy_from_user(param, p->pointer, p->length)) {
3388                 kfree(param);
3389                 return -EFAULT;
3390         }
3391
3392         switch (param->cmd) {
3393
3394         case IEEE_CMD_SET_WPA_PARAM:
3395                 ret = wpa_set_param(dev, param->u.wpa_param.name, param->u.wpa_param.value);
3396                 break;
3397
3398         case IEEE_CMD_SET_WPA_IE:
3399                 /* ret = wpa_set_wpa_ie(dev, param, p->length); */
3400                 ret =  rtw_set_wpa_ie((struct adapter *)rtw_netdev_priv(dev), (char *)param->u.wpa_ie.data, (u16)param->u.wpa_ie.len);
3401                 break;
3402
3403         case IEEE_CMD_SET_ENCRYPTION:
3404                 ret = wpa_set_encryption(dev, param, p->length);
3405                 break;
3406
3407         case IEEE_CMD_MLME:
3408                 ret = wpa_mlme(dev, param->u.mlme.command, param->u.mlme.reason_code);
3409                 break;
3410
3411         default:
3412                 DBG_871X("Unknown WPA supplicant request: %d\n", param->cmd);
3413                 ret = -EOPNOTSUPP;
3414                 break;
3415
3416         }
3417
3418         if (ret == 0 && copy_to_user(p->pointer, param, p->length))
3419                 ret = -EFAULT;
3420
3421         kfree(param);
3422
3423         /* up(&ieee->wx_sem); */
3424         return ret;
3425 }
3426
3427 static int rtw_set_encryption(struct net_device *dev, struct ieee_param *param, u32 param_len)
3428 {
3429         int ret = 0;
3430         u32 wep_key_idx, wep_key_len, wep_total_len;
3431         struct ndis_802_11_wep   *pwep = NULL;
3432         struct sta_info *psta = NULL, *pbcmc_sta = NULL;
3433         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3434         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3435         struct security_priv* psecuritypriv = &(padapter->securitypriv);
3436         struct sta_priv *pstapriv = &padapter->stapriv;
3437
3438         DBG_871X("%s\n", __func__);
3439
3440         param->u.crypt.err = 0;
3441         param->u.crypt.alg[IEEE_CRYPT_ALG_NAME_LEN - 1] = '\0';
3442
3443         /* sizeof(struct ieee_param) = 64 bytes; */
3444         /* if (param_len !=  (u32) ((u8 *) param->u.crypt.key - (u8 *) param) + param->u.crypt.key_len) */
3445         if (param_len !=  sizeof(struct ieee_param) + param->u.crypt.key_len) {
3446                 ret =  -EINVAL;
3447                 goto exit;
3448         }
3449
3450         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
3451             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
3452             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) {
3453                 if (param->u.crypt.idx >= WEP_KEYS) {
3454                         ret = -EINVAL;
3455                         goto exit;
3456                 }
3457         } else {
3458                 psta = rtw_get_stainfo(pstapriv, param->sta_addr);
3459                 if (!psta) {
3460                         /* ret = -EINVAL; */
3461                         DBG_871X("rtw_set_encryption(), sta has already been removed or never been added\n");
3462                         goto exit;
3463                 }
3464         }
3465
3466         if (strcmp(param->u.crypt.alg, "none") == 0 && (psta == NULL)) {
3467                 /* todo:clear default encryption keys */
3468
3469                 psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
3470                 psecuritypriv->ndisencryptstatus = Ndis802_11EncryptionDisabled;
3471                 psecuritypriv->dot11PrivacyAlgrthm = _NO_PRIVACY_;
3472                 psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
3473
3474                 DBG_871X("clear default encryption keys, keyid =%d\n", param->u.crypt.idx);
3475
3476                 goto exit;
3477         }
3478
3479
3480         if (strcmp(param->u.crypt.alg, "WEP") == 0 && (psta == NULL)) {
3481                 DBG_871X("r871x_set_encryption, crypt.alg = WEP\n");
3482
3483                 wep_key_idx = param->u.crypt.idx;
3484                 wep_key_len = param->u.crypt.key_len;
3485
3486                 DBG_871X("r871x_set_encryption, wep_key_idx =%d, len =%d\n", wep_key_idx, wep_key_len);
3487
3488                 if ((wep_key_idx >= WEP_KEYS) || (wep_key_len <= 0)) {
3489                         ret = -EINVAL;
3490                         goto exit;
3491                 }
3492
3493
3494                 if (wep_key_len > 0) {
3495                         wep_key_len = wep_key_len <= 5 ? 5 : 13;
3496                         wep_total_len = wep_key_len + FIELD_OFFSET(struct ndis_802_11_wep, KeyMaterial);
3497                         pwep = kzalloc(wep_total_len, GFP_KERNEL);
3498                         if (pwep == NULL) {
3499                                 DBG_871X(" r871x_set_encryption: pwep allocate fail !!!\n");
3500                                 goto exit;
3501                         }
3502
3503                         pwep->KeyLength = wep_key_len;
3504                         pwep->Length = wep_total_len;
3505
3506                 }
3507
3508                 pwep->KeyIndex = wep_key_idx;
3509
3510                 memcpy(pwep->KeyMaterial,  param->u.crypt.key, pwep->KeyLength);
3511
3512                 if (param->u.crypt.set_tx) {
3513                         DBG_871X("wep, set_tx = 1\n");
3514
3515                         psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
3516                         psecuritypriv->ndisencryptstatus = Ndis802_11Encryption1Enabled;
3517                         psecuritypriv->dot11PrivacyAlgrthm = _WEP40_;
3518                         psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
3519
3520                         if (pwep->KeyLength == 13) {
3521                                 psecuritypriv->dot11PrivacyAlgrthm = _WEP104_;
3522                                 psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
3523                         }
3524
3525
3526                         psecuritypriv->dot11PrivacyKeyIndex = wep_key_idx;
3527
3528                         memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
3529
3530                         psecuritypriv->dot11DefKeylen[wep_key_idx] = pwep->KeyLength;
3531
3532                         rtw_ap_set_wep_key(padapter, pwep->KeyMaterial, pwep->KeyLength, wep_key_idx, 1);
3533                 } else {
3534                         DBG_871X("wep, set_tx = 0\n");
3535
3536                         /* don't update "psecuritypriv->dot11PrivacyAlgrthm" and */
3537                         /* psecuritypriv->dot11PrivacyKeyIndex =keyid", but can rtw_set_key to cam */
3538
3539                         memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
3540
3541                         psecuritypriv->dot11DefKeylen[wep_key_idx] = pwep->KeyLength;
3542
3543                         rtw_ap_set_wep_key(padapter, pwep->KeyMaterial, pwep->KeyLength, wep_key_idx, 0);
3544                 }
3545
3546                 goto exit;
3547
3548         }
3549
3550
3551         if (!psta && check_fwstate(pmlmepriv, WIFI_AP_STATE)) { /*  group key */
3552                 if (param->u.crypt.set_tx == 1) {
3553                         if (strcmp(param->u.crypt.alg, "WEP") == 0) {
3554                                 DBG_871X("%s, set group_key, WEP\n", __func__);
3555
3556                                 memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
3557
3558                                 psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
3559                                 if (param->u.crypt.key_len == 13)
3560                                                 psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
3561
3562                         } else if (strcmp(param->u.crypt.alg, "TKIP") == 0) {
3563                                 DBG_871X("%s, set group_key, TKIP\n", __func__);
3564
3565                                 psecuritypriv->dot118021XGrpPrivacy = _TKIP_;
3566
3567                                 memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
3568
3569                                 /* DEBUG_ERR("set key length :param->u.crypt.key_len =%d\n", param->u.crypt.key_len); */
3570                                 /* set mic key */
3571                                 memcpy(psecuritypriv->dot118021XGrptxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[16]), 8);
3572                                 memcpy(psecuritypriv->dot118021XGrprxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[24]), 8);
3573
3574                                 psecuritypriv->busetkipkey = true;
3575
3576                         }
3577                         else if (strcmp(param->u.crypt.alg, "CCMP") == 0) {
3578                                 DBG_871X("%s, set group_key, CCMP\n", __func__);
3579
3580                                 psecuritypriv->dot118021XGrpPrivacy = _AES_;
3581
3582                                 memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
3583                         } else {
3584                                 DBG_871X("%s, set group_key, none\n", __func__);
3585
3586                                 psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
3587                         }
3588
3589                         psecuritypriv->dot118021XGrpKeyid = param->u.crypt.idx;
3590
3591                         psecuritypriv->binstallGrpkey = true;
3592
3593                         psecuritypriv->dot11PrivacyAlgrthm = psecuritypriv->dot118021XGrpPrivacy;/*  */
3594
3595                         rtw_ap_set_group_key(padapter, param->u.crypt.key, psecuritypriv->dot118021XGrpPrivacy, param->u.crypt.idx);
3596
3597                         pbcmc_sta = rtw_get_bcmc_stainfo(padapter);
3598                         if (pbcmc_sta) {
3599                                 pbcmc_sta->ieee8021x_blocked = false;
3600                                 pbcmc_sta->dot118021XPrivacy = psecuritypriv->dot118021XGrpPrivacy;/* rx will use bmc_sta's dot118021XPrivacy */
3601                         }
3602                 }
3603
3604                 goto exit;
3605
3606         }
3607
3608         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X && psta) { /*  psk/802_1x */
3609                 if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
3610                         if (param->u.crypt.set_tx == 1) {
3611                                 memcpy(psta->dot118021x_UncstKey.skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
3612
3613                                 if (strcmp(param->u.crypt.alg, "WEP") == 0) {
3614                                         DBG_871X("%s, set pairwise key, WEP\n", __func__);
3615
3616                                         psta->dot118021XPrivacy = _WEP40_;
3617                                         if (param->u.crypt.key_len == 13)
3618                                                 psta->dot118021XPrivacy = _WEP104_;
3619                                 } else if (strcmp(param->u.crypt.alg, "TKIP") == 0) {
3620                                         DBG_871X("%s, set pairwise key, TKIP\n", __func__);
3621
3622                                         psta->dot118021XPrivacy = _TKIP_;
3623
3624                                         /* DEBUG_ERR("set key length :param->u.crypt.key_len =%d\n", param->u.crypt.key_len); */
3625                                         /* set mic key */
3626                                         memcpy(psta->dot11tkiptxmickey.skey, &(param->u.crypt.key[16]), 8);
3627                                         memcpy(psta->dot11tkiprxmickey.skey, &(param->u.crypt.key[24]), 8);
3628
3629                                         psecuritypriv->busetkipkey = true;
3630
3631                                 } else if (strcmp(param->u.crypt.alg, "CCMP") == 0) {
3632
3633                                         DBG_871X("%s, set pairwise key, CCMP\n", __func__);
3634
3635                                         psta->dot118021XPrivacy = _AES_;
3636                                 } else {
3637                                         DBG_871X("%s, set pairwise key, none\n", __func__);
3638
3639                                         psta->dot118021XPrivacy = _NO_PRIVACY_;
3640                                 }
3641
3642                                 rtw_ap_set_pairwise_key(padapter, psta);
3643
3644                                 psta->ieee8021x_blocked = false;
3645
3646                         } else { /* group key??? */
3647                                 if (strcmp(param->u.crypt.alg, "WEP") == 0) {
3648                                         memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
3649
3650                                         psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
3651                                         if (param->u.crypt.key_len == 13)
3652                                                 psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
3653                                 } else if (strcmp(param->u.crypt.alg, "TKIP") == 0) {
3654                                         psecuritypriv->dot118021XGrpPrivacy = _TKIP_;
3655
3656                                         memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
3657
3658                                         /* DEBUG_ERR("set key length :param->u.crypt.key_len =%d\n", param->u.crypt.key_len); */
3659                                         /* set mic key */
3660                                         memcpy(psecuritypriv->dot118021XGrptxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[16]), 8);
3661                                         memcpy(psecuritypriv->dot118021XGrprxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[24]), 8);
3662
3663                                         psecuritypriv->busetkipkey = true;
3664
3665                                 } else if (strcmp(param->u.crypt.alg, "CCMP") == 0) {
3666                                         psecuritypriv->dot118021XGrpPrivacy = _AES_;
3667
3668                                         memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
3669                                 } else {
3670                                         psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
3671                                 }
3672
3673                                 psecuritypriv->dot118021XGrpKeyid = param->u.crypt.idx;
3674
3675                                 psecuritypriv->binstallGrpkey = true;
3676
3677                                 psecuritypriv->dot11PrivacyAlgrthm = psecuritypriv->dot118021XGrpPrivacy;/*  */
3678
3679                                 rtw_ap_set_group_key(padapter, param->u.crypt.key, psecuritypriv->dot118021XGrpPrivacy, param->u.crypt.idx);
3680
3681                                 pbcmc_sta = rtw_get_bcmc_stainfo(padapter);
3682                                 if (pbcmc_sta) {
3683                                         pbcmc_sta->ieee8021x_blocked = false;
3684                                         pbcmc_sta->dot118021XPrivacy = psecuritypriv->dot118021XGrpPrivacy;/* rx will use bmc_sta's dot118021XPrivacy */
3685                                 }
3686                         }
3687                 }
3688         }
3689
3690 exit:
3691         kfree(pwep);
3692
3693         return ret;
3694
3695 }
3696
3697 static int rtw_set_beacon(struct net_device *dev, struct ieee_param *param, int len)
3698 {
3699         int ret = 0;
3700         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3701         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3702         struct sta_priv *pstapriv = &padapter->stapriv;
3703         unsigned char *pbuf = param->u.bcn_ie.buf;
3704
3705
3706         DBG_871X("%s, len =%d\n", __func__, len);
3707
3708         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != true)
3709                 return -EINVAL;
3710
3711         memcpy(&pstapriv->max_num_sta, param->u.bcn_ie.reserved, 2);
3712
3713         if ((pstapriv->max_num_sta > NUM_STA) || (pstapriv->max_num_sta <= 0))
3714                 pstapriv->max_num_sta = NUM_STA;
3715
3716
3717         if (rtw_check_beacon_data(padapter, pbuf,  (len-12-2)) == _SUCCESS)/*  12 = param header, 2:no packed */
3718                 ret = 0;
3719         else
3720                 ret = -EINVAL;
3721
3722
3723         return ret;
3724
3725 }
3726
3727 static void rtw_hostapd_sta_flush(struct net_device *dev)
3728 {
3729         /* _irqL irqL; */
3730         /* struct list_head     *phead, *plist; */
3731         /* struct sta_info *psta = NULL; */
3732         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3733         /* struct sta_priv *pstapriv = &padapter->stapriv; */
3734
3735         DBG_871X("%s\n", __func__);
3736
3737         flush_all_cam_entry(padapter);  /* clear CAM */
3738
3739         rtw_sta_flush(padapter);
3740 }
3741
3742 static int rtw_add_sta(struct net_device *dev, struct ieee_param *param)
3743 {
3744         int ret = 0;
3745         struct sta_info *psta = NULL;
3746         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3747         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3748         struct sta_priv *pstapriv = &padapter->stapriv;
3749
3750         DBG_871X("rtw_add_sta(aid =%d) =" MAC_FMT "\n", param->u.add_sta.aid, MAC_ARG(param->sta_addr));
3751
3752         if (check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != true)
3753                 return -EINVAL;
3754
3755         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
3756             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
3757             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) {
3758                 return -EINVAL;
3759         }
3760
3761 /*
3762         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
3763         if (psta)
3764         {
3765                 DBG_871X("rtw_add_sta(), free has been added psta =%p\n", psta);
3766                 spin_lock_bh(&(pstapriv->sta_hash_lock));
3767                 rtw_free_stainfo(padapter,  psta);
3768                 spin_unlock_bh(&(pstapriv->sta_hash_lock));
3769
3770                 psta = NULL;
3771         }
3772 */
3773         /* psta = rtw_alloc_stainfo(pstapriv, param->sta_addr); */
3774         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
3775         if (psta) {
3776                 int flags = param->u.add_sta.flags;
3777
3778                 /* DBG_871X("rtw_add_sta(), init sta's variables, psta =%p\n", psta); */
3779
3780                 psta->aid = param->u.add_sta.aid;/* aid = 1~2007 */
3781
3782                 memcpy(psta->bssrateset, param->u.add_sta.tx_supp_rates, 16);
3783
3784
3785                 /* check wmm cap. */
3786                 if (WLAN_STA_WME&flags)
3787                         psta->qos_option = 1;
3788                 else
3789                         psta->qos_option = 0;
3790
3791                 if (pmlmepriv->qospriv.qos_option == 0)
3792                         psta->qos_option = 0;
3793
3794                 /* chec 802.11n ht cap. */
3795                 if (WLAN_STA_HT&flags) {
3796                         psta->htpriv.ht_option = true;
3797                         psta->qos_option = 1;
3798                         memcpy((void *)&psta->htpriv.ht_cap, (void *)&param->u.add_sta.ht_cap, sizeof(struct rtw_ieee80211_ht_cap));
3799                 } else {
3800                         psta->htpriv.ht_option = false;
3801                 }
3802
3803                 if (pmlmepriv->htpriv.ht_option == false)
3804                         psta->htpriv.ht_option = false;
3805
3806                 update_sta_info_apmode(padapter, psta);
3807
3808
3809         } else {
3810                 ret = -ENOMEM;
3811         }
3812
3813         return ret;
3814
3815 }
3816
3817 static int rtw_del_sta(struct net_device *dev, struct ieee_param *param)
3818 {
3819         int ret = 0;
3820         struct sta_info *psta = NULL;
3821         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3822         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3823         struct sta_priv *pstapriv = &padapter->stapriv;
3824
3825         DBG_871X("rtw_del_sta =" MAC_FMT "\n", MAC_ARG(param->sta_addr));
3826
3827         if (check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != true)
3828                 return -EINVAL;
3829
3830         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
3831             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
3832             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) {
3833                 return -EINVAL;
3834         }
3835
3836         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
3837         if (psta) {
3838                 u8 updated = false;
3839
3840                 /* DBG_871X("free psta =%p, aid =%d\n", psta, psta->aid); */
3841
3842                 spin_lock_bh(&pstapriv->asoc_list_lock);
3843                 if (list_empty(&psta->asoc_list) == false) {
3844                         list_del_init(&psta->asoc_list);
3845                         pstapriv->asoc_list_cnt--;
3846                         updated = ap_free_sta(padapter, psta, true, WLAN_REASON_DEAUTH_LEAVING);
3847
3848                 }
3849                 spin_unlock_bh(&pstapriv->asoc_list_lock);
3850
3851                 associated_clients_update(padapter, updated);
3852
3853                 psta = NULL;
3854
3855         } else {
3856                 DBG_871X("rtw_del_sta(), sta has already been removed or never been added\n");
3857
3858                 /* ret = -1; */
3859         }
3860
3861
3862         return ret;
3863
3864 }
3865
3866 static int rtw_ioctl_get_sta_data(struct net_device *dev, struct ieee_param *param, int len)
3867 {
3868         int ret = 0;
3869         struct sta_info *psta = NULL;
3870         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3871         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3872         struct sta_priv *pstapriv = &padapter->stapriv;
3873         struct ieee_param_ex *param_ex = (struct ieee_param_ex *)param;
3874         struct sta_data *psta_data = (struct sta_data *)param_ex->data;
3875
3876         DBG_871X("rtw_ioctl_get_sta_info, sta_addr: " MAC_FMT "\n", MAC_ARG(param_ex->sta_addr));
3877
3878         if (check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != true)
3879                 return -EINVAL;
3880
3881         if (param_ex->sta_addr[0] == 0xff && param_ex->sta_addr[1] == 0xff &&
3882             param_ex->sta_addr[2] == 0xff && param_ex->sta_addr[3] == 0xff &&
3883             param_ex->sta_addr[4] == 0xff && param_ex->sta_addr[5] == 0xff) {
3884                 return -EINVAL;
3885         }
3886
3887         psta = rtw_get_stainfo(pstapriv, param_ex->sta_addr);
3888         if (psta) {
3889                 psta_data->aid = (u16)psta->aid;
3890                 psta_data->capability = psta->capability;
3891                 psta_data->flags = psta->flags;
3892
3893 /*
3894                 nonerp_set : BIT(0)
3895                 no_short_slot_time_set : BIT(1)
3896                 no_short_preamble_set : BIT(2)
3897                 no_ht_gf_set : BIT(3)
3898                 no_ht_set : BIT(4)
3899                 ht_20mhz_set : BIT(5)
3900 */
3901
3902                 psta_data->sta_set = ((psta->nonerp_set) |
3903                                                          (psta->no_short_slot_time_set << 1) |
3904                                                          (psta->no_short_preamble_set << 2) |
3905                                                          (psta->no_ht_gf_set << 3) |
3906                                                          (psta->no_ht_set << 4) |
3907                                                          (psta->ht_20mhz_set << 5));
3908
3909                 psta_data->tx_supp_rates_len =  psta->bssratelen;
3910                 memcpy(psta_data->tx_supp_rates, psta->bssrateset, psta->bssratelen);
3911                 memcpy(&psta_data->ht_cap, &psta->htpriv.ht_cap, sizeof(struct rtw_ieee80211_ht_cap));
3912                 psta_data->rx_pkts = psta->sta_stats.rx_data_pkts;
3913                 psta_data->rx_bytes = psta->sta_stats.rx_bytes;
3914                 psta_data->rx_drops = psta->sta_stats.rx_drops;
3915
3916                 psta_data->tx_pkts = psta->sta_stats.tx_pkts;
3917                 psta_data->tx_bytes = psta->sta_stats.tx_bytes;
3918                 psta_data->tx_drops = psta->sta_stats.tx_drops;
3919
3920
3921         } else {
3922                 ret = -1;
3923         }
3924
3925         return ret;
3926
3927 }
3928
3929 static int rtw_get_sta_wpaie(struct net_device *dev, struct ieee_param *param)
3930 {
3931         int ret = 0;
3932         struct sta_info *psta = NULL;
3933         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3934         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3935         struct sta_priv *pstapriv = &padapter->stapriv;
3936
3937         DBG_871X("rtw_get_sta_wpaie, sta_addr: " MAC_FMT "\n", MAC_ARG(param->sta_addr));
3938
3939         if (check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != true)
3940                 return -EINVAL;
3941
3942         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
3943             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
3944             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) {
3945                 return -EINVAL;
3946         }
3947
3948         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
3949         if (psta) {
3950                 if ((psta->wpa_ie[0] == WLAN_EID_RSN) || (psta->wpa_ie[0] == WLAN_EID_GENERIC)) {
3951                         int wpa_ie_len;
3952                         int copy_len;
3953
3954                         wpa_ie_len = psta->wpa_ie[1];
3955
3956                         copy_len = ((wpa_ie_len+2) > sizeof(psta->wpa_ie)) ? (sizeof(psta->wpa_ie)):(wpa_ie_len+2);
3957
3958                         param->u.wpa_ie.len = copy_len;
3959
3960                         memcpy(param->u.wpa_ie.reserved, psta->wpa_ie, copy_len);
3961                 } else {
3962                         /* ret = -1; */
3963                         DBG_871X("sta's wpa_ie is NONE\n");
3964                 }
3965         } else {
3966                 ret = -1;
3967         }
3968
3969         return ret;
3970
3971 }
3972
3973 static int rtw_set_wps_beacon(struct net_device *dev, struct ieee_param *param, int len)
3974 {
3975         int ret = 0;
3976         unsigned char wps_oui[4] = {0x0, 0x50, 0xf2, 0x04};
3977         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
3978         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3979         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
3980         int ie_len;
3981
3982         DBG_871X("%s, len =%d\n", __func__, len);
3983
3984         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != true)
3985                 return -EINVAL;
3986
3987         ie_len = len-12-2;/*  12 = param header, 2:no packed */
3988
3989
3990         kfree(pmlmepriv->wps_beacon_ie);
3991         pmlmepriv->wps_beacon_ie = NULL;
3992
3993         if (ie_len > 0) {
3994                 pmlmepriv->wps_beacon_ie = rtw_malloc(ie_len);
3995                 pmlmepriv->wps_beacon_ie_len = ie_len;
3996                 if (pmlmepriv->wps_beacon_ie == NULL) {
3997                         DBG_871X("%s()-%d: rtw_malloc() ERROR!\n", __func__, __LINE__);
3998                         return -EINVAL;
3999                 }
4000
4001                 memcpy(pmlmepriv->wps_beacon_ie, param->u.bcn_ie.buf, ie_len);
4002
4003                 update_beacon(padapter, _VENDOR_SPECIFIC_IE_, wps_oui, true);
4004
4005                 pmlmeext->bstart_bss = true;
4006         }
4007
4008
4009         return ret;
4010
4011 }
4012
4013 static int rtw_set_wps_probe_resp(struct net_device *dev, struct ieee_param *param, int len)
4014 {
4015         int ret = 0;
4016         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
4017         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
4018         int ie_len;
4019
4020         DBG_871X("%s, len =%d\n", __func__, len);
4021
4022         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != true)
4023                 return -EINVAL;
4024
4025         ie_len = len-12-2;/*  12 = param header, 2:no packed */
4026
4027
4028         kfree(pmlmepriv->wps_probe_resp_ie);
4029         pmlmepriv->wps_probe_resp_ie = NULL;
4030
4031         if (ie_len > 0) {
4032                 pmlmepriv->wps_probe_resp_ie = rtw_malloc(ie_len);
4033                 pmlmepriv->wps_probe_resp_ie_len = ie_len;
4034                 if (pmlmepriv->wps_probe_resp_ie == NULL) {
4035                         DBG_871X("%s()-%d: rtw_malloc() ERROR!\n", __func__, __LINE__);
4036                         return -EINVAL;
4037                 }
4038                 memcpy(pmlmepriv->wps_probe_resp_ie, param->u.bcn_ie.buf, ie_len);
4039         }
4040
4041
4042         return ret;
4043
4044 }
4045
4046 static int rtw_set_wps_assoc_resp(struct net_device *dev, struct ieee_param *param, int len)
4047 {
4048         int ret = 0;
4049         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
4050         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
4051         int ie_len;
4052
4053         DBG_871X("%s, len =%d\n", __func__, len);
4054
4055         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != true)
4056                 return -EINVAL;
4057
4058         ie_len = len-12-2;/*  12 = param header, 2:no packed */
4059
4060
4061         kfree(pmlmepriv->wps_assoc_resp_ie);
4062         pmlmepriv->wps_assoc_resp_ie = NULL;
4063
4064         if (ie_len > 0) {
4065                 pmlmepriv->wps_assoc_resp_ie = rtw_malloc(ie_len);
4066                 pmlmepriv->wps_assoc_resp_ie_len = ie_len;
4067                 if (pmlmepriv->wps_assoc_resp_ie == NULL) {
4068                         DBG_871X("%s()-%d: rtw_malloc() ERROR!\n", __func__, __LINE__);
4069                         return -EINVAL;
4070                 }
4071
4072                 memcpy(pmlmepriv->wps_assoc_resp_ie, param->u.bcn_ie.buf, ie_len);
4073         }
4074
4075
4076         return ret;
4077
4078 }
4079
4080 static int rtw_set_hidden_ssid(struct net_device *dev, struct ieee_param *param, int len)
4081 {
4082         int ret = 0;
4083         struct adapter *adapter = (struct adapter *)rtw_netdev_priv(dev);
4084         struct mlme_priv *mlmepriv = &(adapter->mlmepriv);
4085         struct mlme_ext_priv *mlmeext = &(adapter->mlmeextpriv);
4086         struct mlme_ext_info *mlmeinfo = &(mlmeext->mlmext_info);
4087         int ie_len;
4088         u8 *ssid_ie;
4089         char ssid[NDIS_802_11_LENGTH_SSID + 1];
4090         sint ssid_len;
4091         u8 ignore_broadcast_ssid;
4092
4093         if (check_fwstate(mlmepriv, WIFI_AP_STATE) != true)
4094                 return -EPERM;
4095
4096         if (param->u.bcn_ie.reserved[0] != 0xea)
4097                 return -EINVAL;
4098
4099         mlmeinfo->hidden_ssid_mode = ignore_broadcast_ssid = param->u.bcn_ie.reserved[1];
4100
4101         ie_len = len-12-2;/*  12 = param header, 2:no packed */
4102         ssid_ie = rtw_get_ie(param->u.bcn_ie.buf,  WLAN_EID_SSID, &ssid_len, ie_len);
4103
4104         if (ssid_ie && ssid_len > 0 && ssid_len <= NDIS_802_11_LENGTH_SSID) {
4105                 struct wlan_bssid_ex *pbss_network = &mlmepriv->cur_network.network;
4106                 struct wlan_bssid_ex *pbss_network_ext = &mlmeinfo->network;
4107
4108                 memcpy(ssid, ssid_ie+2, ssid_len);
4109                 ssid[ssid_len] = 0x0;
4110
4111                 if (0)
4112                         DBG_871X(FUNC_ADPT_FMT" ssid:(%s,%d), from ie:(%s,%d), (%s,%d)\n", FUNC_ADPT_ARG(adapter),
4113                                  ssid, ssid_len,
4114                                  pbss_network->Ssid.Ssid, pbss_network->Ssid.SsidLength,
4115                                  pbss_network_ext->Ssid.Ssid, pbss_network_ext->Ssid.SsidLength);
4116
4117                 memcpy(pbss_network->Ssid.Ssid, (void *)ssid, ssid_len);
4118                 pbss_network->Ssid.SsidLength = ssid_len;
4119                 memcpy(pbss_network_ext->Ssid.Ssid, (void *)ssid, ssid_len);
4120                 pbss_network_ext->Ssid.SsidLength = ssid_len;
4121
4122                 if (0)
4123                         DBG_871X(FUNC_ADPT_FMT" after ssid:(%s,%d), (%s,%d)\n", FUNC_ADPT_ARG(adapter),
4124                                  pbss_network->Ssid.Ssid, pbss_network->Ssid.SsidLength,
4125                                  pbss_network_ext->Ssid.Ssid, pbss_network_ext->Ssid.SsidLength);
4126         }
4127
4128         DBG_871X(FUNC_ADPT_FMT" ignore_broadcast_ssid:%d, %s,%d\n", FUNC_ADPT_ARG(adapter),
4129                 ignore_broadcast_ssid, ssid, ssid_len);
4130
4131         return ret;
4132 }
4133
4134 static int rtw_ioctl_acl_remove_sta(struct net_device *dev, struct ieee_param *param, int len)
4135 {
4136         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
4137         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
4138
4139         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != true)
4140                 return -EINVAL;
4141
4142         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
4143             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
4144             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) {
4145                 return -EINVAL;
4146         }
4147
4148         rtw_acl_remove_sta(padapter, param->sta_addr);
4149         return 0;
4150
4151 }
4152
4153 static int rtw_ioctl_acl_add_sta(struct net_device *dev, struct ieee_param *param, int len)
4154 {
4155         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
4156         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
4157
4158         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != true)
4159                 return -EINVAL;
4160
4161         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
4162             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
4163             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) {
4164                 return -EINVAL;
4165         }
4166
4167         return rtw_acl_add_sta(padapter, param->sta_addr);
4168
4169 }
4170
4171 static int rtw_ioctl_set_macaddr_acl(struct net_device *dev, struct ieee_param *param, int len)
4172 {
4173         int ret = 0;
4174         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
4175         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
4176
4177         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != true)
4178                 return -EINVAL;
4179
4180         rtw_set_macaddr_acl(padapter, param->u.mlme.command);
4181
4182         return ret;
4183 }
4184
4185 static int rtw_hostapd_ioctl(struct net_device *dev, struct iw_point *p)
4186 {
4187         struct ieee_param *param;
4188         int ret = 0;
4189         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
4190
4191         /* DBG_871X("%s\n", __func__); */
4192
4193         /*
4194         * this function is expect to call in master mode, which allows no power saving
4195         * so, we just check hw_init_completed
4196         */
4197
4198         if (!padapter->hw_init_completed)
4199                 return -EPERM;
4200
4201         if (!p->pointer || p->length != sizeof(*param))
4202                 return -EINVAL;
4203
4204         param = rtw_malloc(p->length);
4205         if (param == NULL)
4206                 return -ENOMEM;
4207
4208         if (copy_from_user(param, p->pointer, p->length)) {
4209                 kfree(param);
4210                 return -EFAULT;
4211         }
4212
4213         /* DBG_871X("%s, cmd =%d\n", __func__, param->cmd); */
4214
4215         switch (param->cmd) {
4216         case RTL871X_HOSTAPD_FLUSH:
4217
4218                 rtw_hostapd_sta_flush(dev);
4219
4220                 break;
4221
4222         case RTL871X_HOSTAPD_ADD_STA:
4223
4224                 ret = rtw_add_sta(dev, param);
4225
4226                 break;
4227
4228         case RTL871X_HOSTAPD_REMOVE_STA:
4229
4230                 ret = rtw_del_sta(dev, param);
4231
4232                 break;
4233
4234         case RTL871X_HOSTAPD_SET_BEACON:
4235
4236                 ret = rtw_set_beacon(dev, param, p->length);
4237
4238                 break;
4239
4240         case RTL871X_SET_ENCRYPTION:
4241
4242                 ret = rtw_set_encryption(dev, param, p->length);
4243
4244                 break;
4245
4246         case RTL871X_HOSTAPD_GET_WPAIE_STA:
4247
4248                 ret = rtw_get_sta_wpaie(dev, param);
4249
4250                 break;
4251
4252         case RTL871X_HOSTAPD_SET_WPS_BEACON:
4253
4254                 ret = rtw_set_wps_beacon(dev, param, p->length);
4255
4256                 break;
4257
4258         case RTL871X_HOSTAPD_SET_WPS_PROBE_RESP:
4259
4260                 ret = rtw_set_wps_probe_resp(dev, param, p->length);
4261
4262                 break;
4263
4264         case RTL871X_HOSTAPD_SET_WPS_ASSOC_RESP:
4265
4266                 ret = rtw_set_wps_assoc_resp(dev, param, p->length);
4267
4268                 break;
4269
4270         case RTL871X_HOSTAPD_SET_HIDDEN_SSID:
4271
4272                 ret = rtw_set_hidden_ssid(dev, param, p->length);
4273
4274                 break;
4275
4276         case RTL871X_HOSTAPD_GET_INFO_STA:
4277
4278                 ret = rtw_ioctl_get_sta_data(dev, param, p->length);
4279
4280                 break;
4281
4282         case RTL871X_HOSTAPD_SET_MACADDR_ACL:
4283
4284                 ret = rtw_ioctl_set_macaddr_acl(dev, param, p->length);
4285
4286                 break;
4287
4288         case RTL871X_HOSTAPD_ACL_ADD_STA:
4289
4290                 ret = rtw_ioctl_acl_add_sta(dev, param, p->length);
4291
4292                 break;
4293
4294         case RTL871X_HOSTAPD_ACL_REMOVE_STA:
4295
4296                 ret = rtw_ioctl_acl_remove_sta(dev, param, p->length);
4297
4298                 break;
4299
4300         default:
4301                 DBG_871X("Unknown hostapd request: %d\n", param->cmd);
4302                 ret = -EOPNOTSUPP;
4303                 break;
4304
4305         }
4306
4307         if (ret == 0 && copy_to_user(p->pointer, param, p->length))
4308                 ret = -EFAULT;
4309
4310         kfree(param);
4311         return ret;
4312 }
4313
4314 static int rtw_wx_set_priv(struct net_device *dev,
4315                                 struct iw_request_info *info,
4316                                 union iwreq_data *awrq,
4317                                 char *extra)
4318 {
4319
4320 #ifdef DEBUG_RTW_WX_SET_PRIV
4321         char *ext_dbg;
4322 #endif
4323
4324         int ret = 0;
4325         int len = 0;
4326         char *ext;
4327
4328         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
4329         struct iw_point *dwrq = (struct iw_point *)awrq;
4330
4331         /* RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_notice_, ("+rtw_wx_set_priv\n")); */
4332         if (dwrq->length == 0)
4333                 return -EFAULT;
4334
4335         len = dwrq->length;
4336         if (!(ext = vmalloc(len)))
4337                 return -ENOMEM;
4338
4339         if (copy_from_user(ext, dwrq->pointer, len)) {
4340                 vfree(ext);
4341                 return -EFAULT;
4342         }
4343
4344
4345         /* RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_notice_, */
4346         /*       ("rtw_wx_set_priv: %s req =%s\n", */
4347         /*        dev->name, ext)); */
4348
4349         #ifdef DEBUG_RTW_WX_SET_PRIV
4350         if (!(ext_dbg = vmalloc(len))) {
4351                 vfree(ext, len);
4352                 return -ENOMEM;
4353         }
4354
4355         memcpy(ext_dbg, ext, len);
4356         #endif
4357
4358         /* added for wps2.0 @20110524 */
4359         if (dwrq->flags == 0x8766 && len > 8) {
4360                 u32 cp_sz;
4361                 struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
4362                 u8 *probereq_wpsie = ext;
4363                 int probereq_wpsie_len = len;
4364                 u8 wps_oui[4] = {0x0, 0x50, 0xf2, 0x04};
4365
4366                 if ((_VENDOR_SPECIFIC_IE_ == probereq_wpsie[0]) &&
4367                         (!memcmp(&probereq_wpsie[2], wps_oui, 4))) {
4368                         cp_sz = probereq_wpsie_len > MAX_WPS_IE_LEN ? MAX_WPS_IE_LEN : probereq_wpsie_len;
4369
4370                         if (pmlmepriv->wps_probe_req_ie) {
4371                                 pmlmepriv->wps_probe_req_ie_len = 0;
4372                                 kfree(pmlmepriv->wps_probe_req_ie);
4373                                 pmlmepriv->wps_probe_req_ie = NULL;
4374                         }
4375
4376                         pmlmepriv->wps_probe_req_ie = rtw_malloc(cp_sz);
4377                         if (pmlmepriv->wps_probe_req_ie == NULL) {
4378                                 printk("%s()-%d: rtw_malloc() ERROR!\n", __func__, __LINE__);
4379                                 ret =  -EINVAL;
4380                                 goto FREE_EXT;
4381
4382                         }
4383
4384                         memcpy(pmlmepriv->wps_probe_req_ie, probereq_wpsie, cp_sz);
4385                         pmlmepriv->wps_probe_req_ie_len = cp_sz;
4386
4387                 }
4388
4389                 goto FREE_EXT;
4390
4391         }
4392
4393         if (len >= WEXT_CSCAN_HEADER_SIZE
4394                 && !memcmp(ext, WEXT_CSCAN_HEADER, WEXT_CSCAN_HEADER_SIZE)) {
4395                 ret = rtw_wx_set_scan(dev, info, awrq, ext);
4396                 goto FREE_EXT;
4397         }
4398
4399 FREE_EXT:
4400
4401         vfree(ext);
4402         #ifdef DEBUG_RTW_WX_SET_PRIV
4403         vfree(ext_dbg);
4404         #endif
4405
4406         /* DBG_871X("rtw_wx_set_priv: (SIOCSIWPRIV) %s ret =%d\n", */
4407         /*              dev->name, ret); */
4408
4409         return ret;
4410
4411 }
4412
4413 static int rtw_pm_set(struct net_device *dev,
4414                                struct iw_request_info *info,
4415                                union iwreq_data *wrqu, char *extra)
4416 {
4417         int ret = 0;
4418         unsigned        mode = 0;
4419         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
4420
4421         DBG_871X("[%s] extra = %s\n", __func__, extra);
4422
4423         if (!memcmp(extra, "lps =", 4)) {
4424                 sscanf(extra+4, "%u", &mode);
4425                 ret = rtw_pm_set_lps(padapter, mode);
4426         } else if (!memcmp(extra, "ips =", 4)) {
4427                 sscanf(extra+4, "%u", &mode);
4428                 ret = rtw_pm_set_ips(padapter, mode);
4429         } else {
4430                 ret = -EINVAL;
4431         }
4432
4433         return ret;
4434 }
4435
4436 static int rtw_test(
4437         struct net_device *dev,
4438         struct iw_request_info *info,
4439         union iwreq_data *wrqu, char *extra)
4440 {
4441         u32 len;
4442         u8 *pbuf, *pch;
4443         char *ptmp;
4444         u8 *delim = ",";
4445         struct adapter *padapter = rtw_netdev_priv(dev);
4446
4447
4448         DBG_871X("+%s\n", __func__);
4449         len = wrqu->data.length;
4450
4451         pbuf = rtw_zmalloc(len);
4452         if (pbuf == NULL) {
4453                 DBG_871X("%s: no memory!\n", __func__);
4454                 return -ENOMEM;
4455         }
4456
4457         if (copy_from_user(pbuf, wrqu->data.pointer, len)) {
4458                 kfree(pbuf);
4459                 DBG_871X("%s: copy from user fail!\n", __func__);
4460                 return -EFAULT;
4461         }
4462         DBG_871X("%s: string =\"%s\"\n", __func__, pbuf);
4463
4464         ptmp = (char *)pbuf;
4465         pch = strsep(&ptmp, delim);
4466         if ((pch == NULL) || (strlen(pch) == 0)) {
4467                 kfree(pbuf);
4468                 DBG_871X("%s: parameter error(level 1)!\n", __func__);
4469                 return -EFAULT;
4470         }
4471
4472         if (strcmp(pch, "bton") == 0)
4473                 hal_btcoex_SetManualControl(padapter, false);
4474
4475         if (strcmp(pch, "btoff") == 0)
4476                 hal_btcoex_SetManualControl(padapter, true);
4477
4478         if (strcmp(pch, "h2c") == 0) {
4479                 u8 param[8];
4480                 u8 count = 0;
4481                 u32 tmp;
4482                 u8 i;
4483                 u32 pos;
4484                 s32 ret;
4485
4486
4487                 do {
4488                         pch = strsep(&ptmp, delim);
4489                         if ((pch == NULL) || (strlen(pch) == 0))
4490                                 break;
4491
4492                         sscanf(pch, "%x", &tmp);
4493                         param[count++] = (u8)tmp;
4494                 } while (count < 8);
4495
4496                 if (count == 0) {
4497                         kfree(pbuf);
4498                         DBG_871X("%s: parameter error(level 2)!\n", __func__);
4499                         return -EFAULT;
4500                 }
4501
4502                 ret = rtw_hal_fill_h2c_cmd(padapter, param[0], count-1, &param[1]);
4503
4504                 pos = sprintf(extra, "H2C ID = 0x%02x content =", param[0]);
4505                 for (i = 1; i < count; i++)
4506                         pos += sprintf(extra+pos, "%02x,", param[i]);
4507                 extra[pos] = 0;
4508                 pos--;
4509                 pos += sprintf(extra+pos, " %s", ret == _FAIL?"FAIL":"OK");
4510
4511                 wrqu->data.length = strlen(extra) + 1;
4512         }
4513
4514         kfree(pbuf);
4515         return 0;
4516 }
4517
4518 static iw_handler rtw_handlers[] = {
4519         NULL,                                   /* SIOCSIWCOMMIT */
4520         rtw_wx_get_name,                /* SIOCGIWNAME */
4521         dummy,                                  /* SIOCSIWNWID */
4522         dummy,                                  /* SIOCGIWNWID */
4523         rtw_wx_set_freq,                /* SIOCSIWFREQ */
4524         rtw_wx_get_freq,                /* SIOCGIWFREQ */
4525         rtw_wx_set_mode,                /* SIOCSIWMODE */
4526         rtw_wx_get_mode,                /* SIOCGIWMODE */
4527         dummy,                                  /* SIOCSIWSENS */
4528         rtw_wx_get_sens,                /* SIOCGIWSENS */
4529         NULL,                                   /* SIOCSIWRANGE */
4530         rtw_wx_get_range,               /* SIOCGIWRANGE */
4531         rtw_wx_set_priv,                /* SIOCSIWPRIV */
4532         NULL,                                   /* SIOCGIWPRIV */
4533         NULL,                                   /* SIOCSIWSTATS */
4534         NULL,                                   /* SIOCGIWSTATS */
4535         dummy,                                  /* SIOCSIWSPY */
4536         dummy,                                  /* SIOCGIWSPY */
4537         NULL,                                   /* SIOCGIWTHRSPY */
4538         NULL,                                   /* SIOCWIWTHRSPY */
4539         rtw_wx_set_wap,         /* SIOCSIWAP */
4540         rtw_wx_get_wap,         /* SIOCGIWAP */
4541         rtw_wx_set_mlme,                /* request MLME operation; uses struct iw_mlme */
4542         dummy,                                  /* SIOCGIWAPLIST -- depricated */
4543         rtw_wx_set_scan,                /* SIOCSIWSCAN */
4544         rtw_wx_get_scan,                /* SIOCGIWSCAN */
4545         rtw_wx_set_essid,               /* SIOCSIWESSID */
4546         rtw_wx_get_essid,               /* SIOCGIWESSID */
4547         dummy,                                  /* SIOCSIWNICKN */
4548         rtw_wx_get_nick,                /* SIOCGIWNICKN */
4549         NULL,                                   /* -- hole -- */
4550         NULL,                                   /* -- hole -- */
4551         rtw_wx_set_rate,                /* SIOCSIWRATE */
4552         rtw_wx_get_rate,                /* SIOCGIWRATE */
4553         rtw_wx_set_rts,                 /* SIOCSIWRTS */
4554         rtw_wx_get_rts,                 /* SIOCGIWRTS */
4555         rtw_wx_set_frag,                /* SIOCSIWFRAG */
4556         rtw_wx_get_frag,                /* SIOCGIWFRAG */
4557         dummy,                                  /* SIOCSIWTXPOW */
4558         dummy,                                  /* SIOCGIWTXPOW */
4559         dummy,                                  /* SIOCSIWRETRY */
4560         rtw_wx_get_retry,               /* SIOCGIWRETRY */
4561         rtw_wx_set_enc,                 /* SIOCSIWENCODE */
4562         rtw_wx_get_enc,                 /* SIOCGIWENCODE */
4563         dummy,                                  /* SIOCSIWPOWER */
4564         rtw_wx_get_power,               /* SIOCGIWPOWER */
4565         NULL,                                   /*---hole---*/
4566         NULL,                                   /*---hole---*/
4567         rtw_wx_set_gen_ie,              /* SIOCSIWGENIE */
4568         NULL,                                   /* SIOCGWGENIE */
4569         rtw_wx_set_auth,                /* SIOCSIWAUTH */
4570         NULL,                                   /* SIOCGIWAUTH */
4571         rtw_wx_set_enc_ext,             /* SIOCSIWENCODEEXT */
4572         NULL,                                   /* SIOCGIWENCODEEXT */
4573         rtw_wx_set_pmkid,               /* SIOCSIWPMKSA */
4574         NULL,                                   /*---hole---*/
4575 };
4576
4577 static const struct iw_priv_args rtw_private_args[] = {
4578         {
4579                 SIOCIWFIRSTPRIV + 0x0,
4580                 IW_PRIV_TYPE_CHAR | 0x7FF, 0, "write"
4581         },
4582         {
4583                 SIOCIWFIRSTPRIV + 0x1,
4584                 IW_PRIV_TYPE_CHAR | 0x7FF,
4585                 IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_FIXED | IFNAMSIZ, "read"
4586         },
4587         {
4588                 SIOCIWFIRSTPRIV + 0x2, 0, 0, "driver_ext"
4589         },
4590         {
4591                 SIOCIWFIRSTPRIV + 0x3, 0, 0, "mp_ioctl"
4592         },
4593         {
4594                 SIOCIWFIRSTPRIV + 0x4,
4595                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "apinfo"
4596         },
4597         {
4598                 SIOCIWFIRSTPRIV + 0x5,
4599                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, 0, "setpid"
4600         },
4601         {
4602                 SIOCIWFIRSTPRIV + 0x6,
4603                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_start"
4604         },
4605 /* for PLATFORM_MT53XX */
4606         {
4607                 SIOCIWFIRSTPRIV + 0x7,
4608                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "get_sensitivity"
4609         },
4610         {
4611                 SIOCIWFIRSTPRIV + 0x8,
4612                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_prob_req_ie"
4613         },
4614         {
4615                 SIOCIWFIRSTPRIV + 0x9,
4616                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_assoc_req_ie"
4617         },
4618
4619 /* for RTK_DMP_PLATFORM */
4620         {
4621                 SIOCIWFIRSTPRIV + 0xA,
4622                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "channel_plan"
4623         },
4624
4625         {
4626                 SIOCIWFIRSTPRIV + 0xB,
4627                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, 0, "dbg"
4628         },
4629         {
4630                 SIOCIWFIRSTPRIV + 0xC,
4631                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 3, 0, "rfw"
4632         },
4633         {
4634                 SIOCIWFIRSTPRIV + 0xD,
4635                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_FIXED | IFNAMSIZ, "rfr"
4636         },
4637         {
4638                 SIOCIWFIRSTPRIV + 0x10,
4639                 IW_PRIV_TYPE_CHAR | 1024, 0, "p2p_set"
4640         },
4641         {
4642                 SIOCIWFIRSTPRIV + 0x11,
4643                 IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "p2p_get"
4644         },
4645         {
4646                 SIOCIWFIRSTPRIV + 0x12, 0, 0, "NULL"
4647         },
4648         {
4649                 SIOCIWFIRSTPRIV + 0x13,
4650                 IW_PRIV_TYPE_CHAR | 64, IW_PRIV_TYPE_CHAR | 64, "p2p_get2"
4651         },
4652         {
4653                 SIOCIWFIRSTPRIV + 0x14,
4654                 IW_PRIV_TYPE_CHAR  | 64, 0, "tdls"
4655         },
4656         {
4657                 SIOCIWFIRSTPRIV + 0x15,
4658                 IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | 1024, "tdls_get"
4659         },
4660         {
4661                 SIOCIWFIRSTPRIV + 0x16,
4662                 IW_PRIV_TYPE_CHAR | 64, 0, "pm_set"
4663         },
4664
4665         {SIOCIWFIRSTPRIV + 0x18, IW_PRIV_TYPE_CHAR | IFNAMSIZ, 0, "rereg_nd_name"},
4666         {SIOCIWFIRSTPRIV + 0x1A, IW_PRIV_TYPE_CHAR | 1024, 0, "efuse_set"},
4667         {SIOCIWFIRSTPRIV + 0x1B, IW_PRIV_TYPE_CHAR | 128, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_get"},
4668         {
4669                 SIOCIWFIRSTPRIV + 0x1D,
4670                 IW_PRIV_TYPE_CHAR | 40, IW_PRIV_TYPE_CHAR | 0x7FF, "test"
4671         },
4672
4673 #ifdef CONFIG_WOWLAN
4674                 { MP_WOW_ENABLE, IW_PRIV_TYPE_CHAR | 1024, 0, "wow_mode" }, /* set */
4675 #endif
4676 #ifdef CONFIG_AP_WOWLAN
4677                 { MP_AP_WOW_ENABLE, IW_PRIV_TYPE_CHAR | 1024, 0, "ap_wow_mode" }, /* set */
4678 #endif
4679 };
4680
4681 static iw_handler rtw_private_handler[] = {
4682         rtw_wx_write32,                                 /* 0x00 */
4683         rtw_wx_read32,                                  /* 0x01 */
4684         rtw_drvext_hdl,                                 /* 0x02 */
4685         NULL,                                           /* 0x03 */
4686
4687 /*  for MM DTV platform */
4688         rtw_get_ap_info,                                        /* 0x04 */
4689
4690         rtw_set_pid,                                            /* 0x05 */
4691         rtw_wps_start,                                  /* 0x06 */
4692
4693 /*  for PLATFORM_MT53XX */
4694         rtw_wx_get_sensitivity,                 /* 0x07 */
4695         rtw_wx_set_mtk_wps_probe_ie,    /* 0x08 */
4696         rtw_wx_set_mtk_wps_ie,                  /* 0x09 */
4697
4698 /*  for RTK_DMP_PLATFORM */
4699 /*  Set Channel depend on the country code */
4700         rtw_wx_set_channel_plan,                /* 0x0A */
4701
4702         rtw_dbg_port,                                   /* 0x0B */
4703         rtw_wx_write_rf,                                        /* 0x0C */
4704         rtw_wx_read_rf,                                 /* 0x0D */
4705         rtw_wx_priv_null,                               /* 0x0E */
4706         rtw_wx_priv_null,                               /* 0x0F */
4707         rtw_p2p_set,                                    /* 0x10 */
4708         rtw_p2p_get,                                    /* 0x11 */
4709         NULL,                                                   /* 0x12 */
4710         rtw_p2p_get2,                                   /* 0x13 */
4711
4712         NULL,                                           /* 0x14 */
4713         NULL,                                           /* 0x15 */
4714
4715         rtw_pm_set,                                             /* 0x16 */
4716         rtw_wx_priv_null,                               /* 0x17 */
4717         rtw_rereg_nd_name,                              /* 0x18 */
4718         rtw_wx_priv_null,                               /* 0x19 */
4719         NULL,                                           /* 0x1A */
4720         NULL,                                           /* 0x1B */
4721         NULL,                                                   /*  0x1C is reserved for hostapd */
4722         rtw_test,                                               /*  0x1D */
4723 };
4724
4725 static struct iw_statistics *rtw_get_wireless_stats(struct net_device *dev)
4726 {
4727         struct adapter *padapter = (struct adapter *)rtw_netdev_priv(dev);
4728         struct iw_statistics *piwstats = &padapter->iwstats;
4729         int tmp_level = 0;
4730         int tmp_qual = 0;
4731         int tmp_noise = 0;
4732
4733         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) != true) {
4734                 piwstats->qual.qual = 0;
4735                 piwstats->qual.level = 0;
4736                 piwstats->qual.noise = 0;
4737                 /* DBG_871X("No link  level:%d, qual:%d, noise:%d\n", tmp_level, tmp_qual, tmp_noise); */
4738         } else {
4739                 #ifdef CONFIG_SIGNAL_DISPLAY_DBM
4740                 tmp_level = translate_percentage_to_dbm(padapter->recvpriv.signal_strength);
4741                 #else
4742                 #ifdef CONFIG_SKIP_SIGNAL_SCALE_MAPPING
4743                 {
4744                         /* Do signal scale mapping when using percentage as the unit of signal strength, since the scale mapping is skipped in odm */
4745
4746                         struct hal_com_data *pHal = GET_HAL_DATA(padapter);
4747
4748                         tmp_level = (u8)odm_SignalScaleMapping(&pHal->odmpriv, padapter->recvpriv.signal_strength);
4749                 }
4750                 #else
4751                 tmp_level = padapter->recvpriv.signal_strength;
4752                 #endif
4753                 #endif
4754
4755                 tmp_qual = padapter->recvpriv.signal_qual;
4756 #if defined(CONFIG_SIGNAL_DISPLAY_DBM) && defined(CONFIG_BACKGROUND_NOISE_MONITOR)
4757                 if (rtw_linked_check(padapter)) {
4758                         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
4759                         struct noise_info info;
4760                         info.bPauseDIG = true;
4761                         info.IGIValue = 0x1e;
4762                         info.max_time = 100;/* ms */
4763                         info.chan = pmlmeext->cur_channel ;/* rtw_get_oper_ch(padapter); */
4764                         rtw_ps_deny(padapter, PS_DENY_IOCTL);
4765                         LeaveAllPowerSaveModeDirect(padapter);
4766
4767                         rtw_hal_set_odm_var(padapter, HAL_ODM_NOISE_MONITOR, &info, false);
4768                         /* ODM_InbandNoise_Monitor(podmpriv, true, 0x20, 100); */
4769                         rtw_ps_deny_cancel(padapter, PS_DENY_IOCTL);
4770                         rtw_hal_get_odm_var(padapter, HAL_ODM_NOISE_MONITOR, &(info.chan), &(padapter->recvpriv.noise));
4771                         DBG_871X("chan:%d, noise_level:%d\n", info.chan, padapter->recvpriv.noise);
4772                 }
4773 #endif
4774                 tmp_noise = padapter->recvpriv.noise;
4775                 DBG_871X("level:%d, qual:%d, noise:%d, rssi (%d)\n", tmp_level, tmp_qual, tmp_noise, padapter->recvpriv.rssi);
4776
4777                 piwstats->qual.level = tmp_level;
4778                 piwstats->qual.qual = tmp_qual;
4779                 piwstats->qual.noise = tmp_noise;
4780         }
4781         piwstats->qual.updated = IW_QUAL_ALL_UPDATED ;/* IW_QUAL_DBM; */
4782
4783         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
4784         piwstats->qual.updated = piwstats->qual.updated | IW_QUAL_DBM;
4785         #endif
4786
4787         return &padapter->iwstats;
4788 }
4789
4790 struct iw_handler_def rtw_handlers_def = {
4791         .standard = rtw_handlers,
4792         .num_standard = ARRAY_SIZE(rtw_handlers),
4793 #if defined(CONFIG_WEXT_PRIV)
4794         .private = rtw_private_handler,
4795         .private_args = (struct iw_priv_args *)rtw_private_args,
4796         .num_private = ARRAY_SIZE(rtw_private_handler),
4797         .num_private_args = ARRAY_SIZE(rtw_private_args),
4798 #endif
4799         .get_wireless_stats = rtw_get_wireless_stats,
4800 };
4801
4802 /*  copy from net/wireless/wext.c start */
4803 /* ---------------------------------------------------------------- */
4804 /*
4805  * Calculate size of private arguments
4806  */
4807 static const char iw_priv_type_size[] = {
4808         0,                              /* IW_PRIV_TYPE_NONE */
4809         1,                              /* IW_PRIV_TYPE_BYTE */
4810         1,                              /* IW_PRIV_TYPE_CHAR */
4811         0,                              /* Not defined */
4812         sizeof(__u32),                  /* IW_PRIV_TYPE_INT */
4813         sizeof(struct iw_freq),         /* IW_PRIV_TYPE_FLOAT */
4814         sizeof(struct sockaddr),        /* IW_PRIV_TYPE_ADDR */
4815         0,                              /* Not defined */
4816 };
4817
4818 static int get_priv_size(__u16 args)
4819 {
4820         int num = args & IW_PRIV_SIZE_MASK;
4821         int type = (args & IW_PRIV_TYPE_MASK) >> 12;
4822
4823         return num * iw_priv_type_size[type];
4824 }
4825 /*  copy from net/wireless/wext.c end */
4826
4827 static int rtw_ioctl_wext_private(struct net_device *dev, union iwreq_data *wrq_data)
4828 {
4829         int err = 0;
4830         u8 *input = NULL;
4831         u32 input_len = 0;
4832         const char delim[] = " ";
4833         u8 *output = NULL;
4834         u32 output_len = 0;
4835         u32 count = 0;
4836         u8 *buffer = NULL;
4837         u32 buffer_len = 0;
4838         char *ptr = NULL;
4839         u8 cmdname[17] = {0}; /*  IFNAMSIZ+1 */
4840         u32 cmdlen;
4841         s32 len;
4842         u8 *extra = NULL;
4843         u32 extra_size = 0;
4844
4845         s32 k;
4846         const iw_handler *priv;         /* Private ioctl */
4847         const struct iw_priv_args *priv_args;   /* Private ioctl description */
4848         u32 num_priv_args;                      /* Number of descriptions */
4849         iw_handler handler;
4850         int temp;
4851         int subcmd = 0;                         /* sub-ioctl index */
4852         int offset = 0;                         /* Space for sub-ioctl index */
4853
4854         union iwreq_data wdata;
4855
4856
4857         memcpy(&wdata, wrq_data, sizeof(wdata));
4858
4859         input_len = 2048;
4860         input = rtw_zmalloc(input_len);
4861         if (NULL == input)
4862                 return -ENOMEM;
4863         if (copy_from_user(input, wdata.data.pointer, input_len)) {
4864                 err = -EFAULT;
4865                 goto exit;
4866         }
4867         ptr = input;
4868         len = strlen(input);
4869
4870         sscanf(ptr, "%16s", cmdname);
4871         cmdlen = strlen(cmdname);
4872         DBG_8192C("%s: cmd =%s\n", __func__, cmdname);
4873
4874         /*  skip command string */
4875         if (cmdlen > 0)
4876                 cmdlen += 1; /*  skip one space */
4877         ptr += cmdlen;
4878         len -= cmdlen;
4879         DBG_8192C("%s: parameters =%s\n", __func__, ptr);
4880
4881         priv = rtw_private_handler;
4882         priv_args = rtw_private_args;
4883         num_priv_args = ARRAY_SIZE(rtw_private_args);
4884
4885         if (num_priv_args == 0) {
4886                 err = -EOPNOTSUPP;
4887                 goto exit;
4888         }
4889
4890         /* Search the correct ioctl */
4891         k = -1;
4892         while ((++k < num_priv_args) && strcmp(priv_args[k].name, cmdname));
4893
4894         /* If not found... */
4895         if (k == num_priv_args) {
4896                 err = -EOPNOTSUPP;
4897                 goto exit;
4898         }
4899
4900         /* Watch out for sub-ioctls ! */
4901         if (priv_args[k].cmd < SIOCDEVPRIVATE) {
4902                 int j = -1;
4903
4904                 /* Find the matching *real* ioctl */
4905                 while ((++j < num_priv_args) && ((priv_args[j].name[0] != '\0') ||
4906                         (priv_args[j].set_args != priv_args[k].set_args) ||
4907                         (priv_args[j].get_args != priv_args[k].get_args)));
4908
4909                 /* If not found... */
4910                 if (j == num_priv_args) {
4911                         err = -EINVAL;
4912                         goto exit;
4913                 }
4914
4915                 /* Save sub-ioctl number */
4916                 subcmd = priv_args[k].cmd;
4917                 /* Reserve one int (simplify alignment issues) */
4918                 offset = sizeof(__u32);
4919                 /* Use real ioctl definition from now on */
4920                 k = j;
4921         }
4922
4923         buffer = rtw_zmalloc(4096);
4924         if (NULL == buffer) {
4925                 err = -ENOMEM;
4926                 goto exit;
4927         }
4928
4929         /* If we have to set some data */
4930         if ((priv_args[k].set_args & IW_PRIV_TYPE_MASK) &&
4931                 (priv_args[k].set_args & IW_PRIV_SIZE_MASK)) {
4932                 u8 *str;
4933
4934                 switch (priv_args[k].set_args & IW_PRIV_TYPE_MASK) {
4935                 case IW_PRIV_TYPE_BYTE:
4936                         /* Fetch args */
4937                         count = 0;
4938                         do {
4939                                 str = strsep(&ptr, delim);
4940                                 if (NULL == str) break;
4941                                 sscanf(str, "%i", &temp);
4942                                 buffer[count++] = (u8)temp;
4943                         } while (1);
4944                         buffer_len = count;
4945
4946                         /* Number of args to fetch */
4947                         wdata.data.length = count;
4948                         if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
4949                                 wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
4950
4951                         break;
4952
4953                 case IW_PRIV_TYPE_INT:
4954                         /* Fetch args */
4955                         count = 0;
4956                         do {
4957                                 str = strsep(&ptr, delim);
4958                                 if (NULL == str) break;
4959                                 sscanf(str, "%i", &temp);
4960                                 ((s32 *)buffer)[count++] = (s32)temp;
4961                         } while (1);
4962                         buffer_len = count * sizeof(s32);
4963
4964                         /* Number of args to fetch */
4965                         wdata.data.length = count;
4966                         if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
4967                                 wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
4968
4969                         break;
4970
4971                 case IW_PRIV_TYPE_CHAR:
4972                         if (len > 0) {
4973                                 /* Size of the string to fetch */
4974                                 wdata.data.length = len;
4975                                 if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
4976                                         wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
4977
4978                                 /* Fetch string */
4979                                 memcpy(buffer, ptr, wdata.data.length);
4980                         } else {
4981                                 wdata.data.length = 1;
4982                                 buffer[0] = '\0';
4983                         }
4984                         buffer_len = wdata.data.length;
4985                         break;
4986
4987                 default:
4988                         DBG_8192C("%s: Not yet implemented...\n", __func__);
4989                         err = -1;
4990                         goto exit;
4991                 }
4992
4993                 if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
4994                         (wdata.data.length != (priv_args[k].set_args & IW_PRIV_SIZE_MASK))) {
4995                         DBG_8192C("%s: The command %s needs exactly %d argument(s)...\n",
4996                                         __func__, cmdname, priv_args[k].set_args & IW_PRIV_SIZE_MASK);
4997                         err = -EINVAL;
4998                         goto exit;
4999                 }
5000         } else { /* if args to set */
5001                 wdata.data.length = 0L;
5002         }
5003
5004         /* Those two tests are important. They define how the driver
5005         * will have to handle the data */
5006         if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
5007                 ((get_priv_size(priv_args[k].set_args) + offset) <= IFNAMSIZ)) {
5008                 /* First case : all SET args fit within wrq */
5009                 if (offset)
5010                         wdata.mode = subcmd;
5011                 memcpy(wdata.name + offset, buffer, IFNAMSIZ - offset);
5012         } else {
5013                 if ((priv_args[k].set_args == 0) &&
5014                         (priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
5015                         (get_priv_size(priv_args[k].get_args) <= IFNAMSIZ)) {
5016                         /* Second case : no SET args, GET args fit within wrq */
5017                         if (offset)
5018                                 wdata.mode = subcmd;
5019                 } else {
5020                         /* Third case : args won't fit in wrq, or variable number of args */
5021                         if (copy_to_user(wdata.data.pointer, buffer, buffer_len)) {
5022                                 err = -EFAULT;
5023                                 goto exit;
5024                         }
5025                         wdata.data.flags = subcmd;
5026                 }
5027         }
5028
5029         kfree(input);
5030         input = NULL;
5031
5032         extra_size = 0;
5033         if (IW_IS_SET(priv_args[k].cmd)) {
5034                 /* Size of set arguments */
5035                 extra_size = get_priv_size(priv_args[k].set_args);
5036
5037                 /* Does it fits in iwr ? */
5038                 if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
5039                         ((extra_size + offset) <= IFNAMSIZ))
5040                         extra_size = 0;
5041         } else {
5042                 /* Size of get arguments */
5043                 extra_size = get_priv_size(priv_args[k].get_args);
5044
5045                 /* Does it fits in iwr ? */
5046                 if ((priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
5047                         (extra_size <= IFNAMSIZ))
5048                         extra_size = 0;
5049         }
5050
5051         if (extra_size == 0) {
5052                 extra = (u8 *)&wdata;
5053                 kfree(buffer);
5054                 buffer = NULL;
5055         } else
5056                 extra = buffer;
5057
5058         handler = priv[priv_args[k].cmd - SIOCIWFIRSTPRIV];
5059         err = handler(dev, NULL, &wdata, extra);
5060
5061         /* If we have to get some data */
5062         if ((priv_args[k].get_args & IW_PRIV_TYPE_MASK) &&
5063                 (priv_args[k].get_args & IW_PRIV_SIZE_MASK)) {
5064                 int j;
5065                 int n = 0;      /* number of args */
5066                 u8 str[20] = {0};
5067
5068                 /* Check where is the returned data */
5069                 if ((priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
5070                         (get_priv_size(priv_args[k].get_args) <= IFNAMSIZ))
5071                         n = priv_args[k].get_args & IW_PRIV_SIZE_MASK;
5072                 else
5073                         n = wdata.data.length;
5074
5075                 output = rtw_zmalloc(4096);
5076                 if (NULL == output) {
5077                         err =  -ENOMEM;
5078                         goto exit;
5079                 }
5080
5081                 switch (priv_args[k].get_args & IW_PRIV_TYPE_MASK) {
5082                 case IW_PRIV_TYPE_BYTE:
5083                         /* Display args */
5084                         for (j = 0; j < n; j++) {
5085                                 sprintf(str, "%d  ", extra[j]);
5086                                 len = strlen(str);
5087                                 output_len = strlen(output);
5088                                 if ((output_len + len + 1) > 4096) {
5089                                         err = -E2BIG;
5090                                         goto exit;
5091                                 }
5092                                 memcpy(output+output_len, str, len);
5093                         }
5094                         break;
5095
5096                 case IW_PRIV_TYPE_INT:
5097                         /* Display args */
5098                         for (j = 0; j < n; j++) {
5099                                 sprintf(str, "%d  ", ((__s32 *)extra)[j]);
5100                                 len = strlen(str);
5101                                 output_len = strlen(output);
5102                                 if ((output_len + len + 1) > 4096) {
5103                                         err = -E2BIG;
5104                                         goto exit;
5105                                 }
5106                                 memcpy(output+output_len, str, len);
5107                         }
5108                         break;
5109
5110                 case IW_PRIV_TYPE_CHAR:
5111                         /* Display args */
5112                         memcpy(output, extra, n);
5113                         break;
5114
5115                 default:
5116                         DBG_8192C("%s: Not yet implemented...\n", __func__);
5117                         err = -1;
5118                         goto exit;
5119                 }
5120
5121                 output_len = strlen(output) + 1;
5122                 wrq_data->data.length = output_len;
5123                 if (copy_to_user(wrq_data->data.pointer, output, output_len)) {
5124                         err = -EFAULT;
5125                         goto exit;
5126                 }
5127         } else { /* if args to set */
5128                 wrq_data->data.length = 0;
5129         }
5130
5131 exit:
5132         kfree(input);
5133         kfree(buffer);
5134         kfree(output);
5135
5136         return err;
5137 }
5138
5139 int rtw_ioctl(struct net_device *dev, struct ifreq *rq, int cmd)
5140 {
5141         struct iwreq *wrq = (struct iwreq *)rq;
5142         int ret = 0;
5143
5144         switch (cmd) {
5145         case RTL_IOCTL_WPA_SUPPLICANT:
5146                 ret = wpa_supplicant_ioctl(dev, &wrq->u.data);
5147                 break;
5148         case RTL_IOCTL_HOSTAPD:
5149                 ret = rtw_hostapd_ioctl(dev, &wrq->u.data);
5150                 break;
5151         case SIOCDEVPRIVATE:
5152                 ret = rtw_ioctl_wext_private(dev, &wrq->u);
5153                 break;
5154         default:
5155                 ret = -EOPNOTSUPP;
5156                 break;
5157         }
5158
5159         return ret;
5160 }