f07e4e233788ed8503693fd50e12d019bbc561da
[linux-2.6-microblaze.git] / drivers / staging / r8188eu / core / rtw_mlme.c
1 // SPDX-License-Identifier: GPL-2.0
2 /* Copyright(c) 2007 - 2011 Realtek Corporation. */
3
4 #define _RTW_MLME_C_
5
6 #include <linux/version.h>
7 #include "../include/osdep_service.h"
8 #include "../include/drv_types.h"
9 #include "../include/recv_osdep.h"
10 #include "../include/xmit_osdep.h"
11 #include "../include/hal_intf.h"
12 #include "../include/mlme_osdep.h"
13 #include "../include/sta_info.h"
14 #include "../include/wifi.h"
15 #include "../include/wlan_bssdef.h"
16 #include "../include/rtw_ioctl_set.h"
17 #include "../include/usb_osintf.h"
18
19 extern unsigned char    MCS_rate_2R[16];
20 extern unsigned char    MCS_rate_1R[16];
21
22 void rtw_set_roaming(struct adapter *adapter, u8 to_roaming)
23 {
24         if (to_roaming == 0)
25                 adapter->mlmepriv.to_join = false;
26         adapter->mlmepriv.to_roaming = to_roaming;
27 }
28
29 u8 rtw_to_roaming(struct adapter *adapter)
30 {
31         return adapter->mlmepriv.to_roaming;
32 }
33
34 int     _rtw_init_mlme_priv (struct adapter *padapter)
35 {
36         int     i;
37         u8      *pbuf;
38         struct wlan_network     *pnetwork;
39         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
40         int     res = _SUCCESS;
41
42         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by rtw_zvmalloc(). */
43
44         pmlmepriv->nic_hdl = (u8 *)padapter;
45
46         pmlmepriv->pscanned = NULL;
47         pmlmepriv->fw_state = 0;
48         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
49         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
50
51         spin_lock_init(&(pmlmepriv->lock));
52         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
53         _rtw_init_queue(&(pmlmepriv->scanned_queue));
54
55         set_scanned_network_val(pmlmepriv, 0);
56
57         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
58
59         pbuf = rtw_zvmalloc(MAX_BSS_CNT * (sizeof(struct wlan_network)));
60
61         if (pbuf == NULL) {
62                 res = _FAIL;
63                 goto exit;
64         }
65         pmlmepriv->free_bss_buf = pbuf;
66
67         pnetwork = (struct wlan_network *)pbuf;
68
69         for (i = 0; i < MAX_BSS_CNT; i++) {
70                 INIT_LIST_HEAD(&(pnetwork->list));
71
72                 list_add_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
73
74                 pnetwork++;
75         }
76
77         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
78
79         rtw_clear_scan_deny(padapter);
80
81         rtw_init_mlme_timer(padapter);
82
83 exit:
84
85         return res;
86 }
87
88 static void rtw_mfree_mlme_priv_lock (struct mlme_priv *pmlmepriv)
89 {
90         _rtw_spinlock_free(&pmlmepriv->lock);
91         _rtw_spinlock_free(&(pmlmepriv->free_bss_pool.lock));
92         _rtw_spinlock_free(&(pmlmepriv->scanned_queue.lock));
93 }
94
95 #if defined (CONFIG_88EU_AP_MODE)
96 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
97 {
98         kfree(*ppie);
99         *plen = 0;
100         *ppie = NULL;
101 }
102
103 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
104 {
105         kfree(&pmlmepriv->assoc_req);
106         pmlmepriv->assoc_req = NULL;
107         pmlmepriv->assoc_req_len = 0;
108         kfree(&pmlmepriv->assoc_rsp);
109         pmlmepriv->assoc_rsp = NULL;
110         pmlmepriv->assoc_rsp_len = 0;
111         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
112         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
113         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
114         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
115
116         rtw_free_mlme_ie_data(&pmlmepriv->p2p_beacon_ie, &pmlmepriv->p2p_beacon_ie_len);
117         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_req_ie, &pmlmepriv->p2p_probe_req_ie_len);
118         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_resp_ie, &pmlmepriv->p2p_probe_resp_ie_len);
119         rtw_free_mlme_ie_data(&pmlmepriv->p2p_go_probe_resp_ie, &pmlmepriv->p2p_go_probe_resp_ie_len);
120         rtw_free_mlme_ie_data(&pmlmepriv->p2p_assoc_req_ie, &pmlmepriv->p2p_assoc_req_ie_len);
121 }
122 #else
123 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
124 {
125 }
126 #endif
127
128 void _rtw_free_mlme_priv (struct mlme_priv *pmlmepriv)
129 {
130
131         rtw_free_mlme_priv_ie_data(pmlmepriv);
132
133         if (pmlmepriv) {
134                 rtw_mfree_mlme_priv_lock (pmlmepriv);
135
136                 if (pmlmepriv->free_bss_buf) {
137                         rtw_vmfree(pmlmepriv->free_bss_buf, MAX_BSS_CNT * sizeof(struct wlan_network));
138                 }
139         }
140
141 }
142
143 int     _rtw_enqueue_network(struct __queue *queue, struct wlan_network *pnetwork)
144 {
145
146         if (pnetwork == NULL)
147                 goto exit;
148
149         spin_lock_bh(&queue->lock);
150
151         list_add_tail(&pnetwork->list, &queue->queue);
152
153         spin_unlock_bh(&queue->lock);
154
155 exit:
156
157         return _SUCCESS;
158 }
159
160 struct  wlan_network *_rtw_dequeue_network(struct __queue *queue)
161 {
162         struct wlan_network *pnetwork;
163
164         spin_lock_bh(&queue->lock);
165
166         if (list_empty(&queue->queue)) {
167                 pnetwork = NULL;
168         } else {
169                 pnetwork = container_of((&queue->queue)->next, struct wlan_network, list);
170
171                 list_del_init(&(pnetwork->list));
172         }
173
174         spin_unlock_bh(&queue->lock);
175
176         return pnetwork;
177 }
178
179 struct  wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)/* _queue *free_queue) */
180 {
181         struct  wlan_network    *pnetwork;
182         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
183         struct list_head *plist = NULL;
184
185         spin_lock_bh(&free_queue->lock);
186
187         if (list_empty(&free_queue->queue)) {
188                 pnetwork = NULL;
189                 goto exit;
190         }
191         plist = (&(free_queue->queue))->next;
192
193         pnetwork = container_of(plist, struct wlan_network, list);
194
195         list_del_init(&pnetwork->list);
196
197         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("_rtw_alloc_network: ptr=%p\n", plist));
198         pnetwork->network_type = 0;
199         pnetwork->fixed = false;
200         pnetwork->last_scanned = jiffies;
201         pnetwork->aid = 0;
202         pnetwork->join_res = 0;
203
204         pmlmepriv->num_of_scanned++;
205
206 exit:
207         spin_unlock_bh(&free_queue->lock);
208
209         return pnetwork;
210 }
211
212 void _rtw_free_network(struct mlme_priv *pmlmepriv, struct wlan_network *pnetwork, u8 isfreeall)
213 {
214         u32 curr_time, delta_time;
215         u32 lifetime = SCANQUEUE_LIFETIME;
216         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
217
218         if (pnetwork == NULL)
219                 return;
220
221         if (pnetwork->fixed)
222                 return;
223         curr_time = jiffies;
224         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
225             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)))
226                 lifetime = 1;
227         if (!isfreeall) {
228                 delta_time = (curr_time - pnetwork->last_scanned)/HZ;
229                 if (delta_time < lifetime)/*  unit:sec */
230                         return;
231         }
232         spin_lock_bh(&free_queue->lock);
233         list_del_init(&(pnetwork->list));
234         list_add_tail(&(pnetwork->list), &(free_queue->queue));
235         pmlmepriv->num_of_scanned--;
236         spin_unlock_bh(&free_queue->lock);
237 }
238
239 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
240 {
241         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
242
243         if (pnetwork == NULL)
244                 return;
245         if (pnetwork->fixed)
246                 return;
247         list_del_init(&(pnetwork->list));
248         list_add_tail(&(pnetwork->list), get_list_head(free_queue));
249         pmlmepriv->num_of_scanned--;
250 }
251
252 /*
253         return the wlan_network with the matching addr
254
255         Shall be calle under atomic context... to avoid possible racing condition...
256 */
257 struct wlan_network *_rtw_find_network(struct __queue *scanned_queue, u8 *addr)
258 {
259         struct list_head *phead, *plist;
260         struct  wlan_network *pnetwork = NULL;
261         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
262
263         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
264                 pnetwork = NULL;
265                 goto exit;
266         }
267         phead = get_list_head(scanned_queue);
268         plist = phead->next;
269
270         while (plist != phead) {
271                 pnetwork = container_of(plist, struct wlan_network, list);
272                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
273                         break;
274                 plist = plist->next;
275         }
276         if (plist == phead)
277                 pnetwork = NULL;
278 exit:
279
280         return pnetwork;
281 }
282
283 void _rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
284 {
285         struct list_head *phead, *plist;
286         struct wlan_network *pnetwork;
287         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
288         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
289
290         spin_lock_bh(&scanned_queue->lock);
291
292         phead = get_list_head(scanned_queue);
293         plist = phead->next;
294
295         while (phead != plist) {
296                 pnetwork = container_of(plist, struct wlan_network, list);
297
298                 plist = plist->next;
299
300                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
301         }
302         spin_unlock_bh(&scanned_queue->lock);
303
304 }
305
306 int rtw_if_up(struct adapter *padapter)
307 {
308         int res;
309
310         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
311             (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
312                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
313                          ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)",
314                          padapter->bDriverStopped, padapter->bSurpriseRemoved));
315                 res = false;
316         } else {
317                 res =  true;
318         }
319
320         return res;
321 }
322
323 void rtw_generate_random_ibss(u8 *pibss)
324 {
325         u32     curtime = jiffies;
326
327         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
328         pibss[1] = 0x11;
329         pibss[2] = 0x87;
330         pibss[3] = (u8)(curtime & 0xff);/* p[0]; */
331         pibss[4] = (u8)((curtime>>8) & 0xff);/* p[1]; */
332         pibss[5] = (u8)((curtime>>16) & 0xff);/* p[2]; */
333
334         return;
335 }
336
337 u8 *rtw_get_capability_from_ie(u8 *ie)
338 {
339         return ie + 8 + 2;
340 }
341
342 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
343 {
344         __le16  val;
345
346         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2);
347
348         return le16_to_cpu(val);
349 }
350
351 u8 *rtw_get_timestampe_from_ie(u8 *ie)
352 {
353         return ie + 0;
354 }
355
356 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
357 {
358         return ie + 8;
359 }
360
361 int     rtw_init_mlme_priv (struct adapter *padapter)/* struct  mlme_priv *pmlmepriv) */
362 {
363         int     res;
364
365         res = _rtw_init_mlme_priv(padapter);/*  (pmlmepriv); */
366
367         return res;
368 }
369
370 void rtw_free_mlme_priv (struct mlme_priv *pmlmepriv)
371 {
372
373         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_mlme_priv\n"));
374         _rtw_free_mlme_priv (pmlmepriv);
375
376 }
377
378 static struct wlan_network *rtw_alloc_network(struct mlme_priv *pmlmepriv)
379 {
380         struct  wlan_network    *pnetwork;
381
382         pnetwork = _rtw_alloc_network(pmlmepriv);
383
384         return pnetwork;
385 }
386
387 static void rtw_free_network_nolock(struct mlme_priv *pmlmepriv,
388                                     struct wlan_network *pnetwork)
389 {
390
391         _rtw_free_network_nolock(pmlmepriv, pnetwork);
392
393 }
394
395 void rtw_free_network_queue(struct adapter *dev, u8 isfreeall)
396 {
397
398         _rtw_free_network_queue(dev, isfreeall);
399
400 }
401
402 /*
403         return the wlan_network with the matching addr
404
405         Shall be calle under atomic context... to avoid possible racing condition...
406 */
407 struct  wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
408 {
409         struct  wlan_network *pnetwork = _rtw_find_network(scanned_queue, addr);
410
411         return pnetwork;
412 }
413
414 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
415 {
416         int ret = true;
417         struct security_priv *psecuritypriv = &adapter->securitypriv;
418
419         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
420             (pnetwork->network.Privacy == 0))
421                 ret = false;
422         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
423                  (pnetwork->network.Privacy == 1))
424                 ret = false;
425         else
426                 ret = true;
427         return ret;
428 }
429
430 static int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
431 {
432         return (a->Ssid.SsidLength == b->Ssid.SsidLength) &&
433                !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
434 }
435
436 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst)
437 {
438          u16 s_cap, d_cap;
439         __le16 le_scap, le_dcap;
440
441         memcpy((u8 *)&le_scap, rtw_get_capability_from_ie(src->IEs), 2);
442         memcpy((u8 *)&le_dcap, rtw_get_capability_from_ie(dst->IEs), 2);
443
444         s_cap = le16_to_cpu(le_scap);
445         d_cap = le16_to_cpu(le_dcap);
446
447         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
448                 ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN))) &&
449                 ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength))) &&
450                 ((s_cap & WLAN_CAPABILITY_IBSS) ==
451                 (d_cap & WLAN_CAPABILITY_IBSS)) &&
452                 ((s_cap & WLAN_CAPABILITY_BSS) ==
453                 (d_cap & WLAN_CAPABILITY_BSS)));
454 }
455
456 struct  wlan_network    *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
457 {
458         struct list_head *plist, *phead;
459         struct  wlan_network    *pwlan = NULL;
460         struct  wlan_network    *oldest = NULL;
461
462         phead = get_list_head(scanned_queue);
463
464         plist = phead->next;
465
466         while (1) {
467                 if (phead == plist)
468                         break;
469
470                 pwlan = container_of(plist, struct wlan_network, list);
471
472                 if (!pwlan->fixed) {
473                         if (oldest == NULL || time_after(oldest->last_scanned, pwlan->last_scanned))
474                                 oldest = pwlan;
475                 }
476
477                 plist = plist->next;
478         }
479
480         return oldest;
481 }
482
483 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
484         struct adapter *padapter, bool update_ie)
485 {
486         long rssi_ori = dst->Rssi;
487         u8 sq_smp = src->PhyInfo.SignalQuality;
488         u8 ss_final;
489         u8 sq_final;
490         long rssi_final;
491
492         rtw_hal_antdiv_rssi_compared(padapter, dst, src); /* this will update src.Rssi, need consider again */
493
494         /* The rule below is 1/5 for sample value, 4/5 for history value */
495         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src)) {
496                 /* Take the recvpriv's value for the connected AP*/
497                 ss_final = padapter->recvpriv.signal_strength;
498                 sq_final = padapter->recvpriv.signal_qual;
499                 /* the rssi value here is undecorated, and will be used for antenna diversity */
500                 if (sq_smp != 101) /* from the right channel */
501                         rssi_final = dst->Rssi; //(src->Rssi+dst->Rssi*4)/5;
502                 else
503                         rssi_final = rssi_ori;
504         } else {
505 //              if (sq_smp != 101) { /* from the right channel */
506                         ss_final = (u32)dst->PhyInfo.SignalStrength; //((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
507                         sq_final = (u32)dst->PhyInfo.SignalQuality; //((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
508                         rssi_final = dst->Rssi; //(src->Rssi+dst->Rssi*4)/5;
509 //              } else {
510 //                      /* bss info not receiving from the right channel, use the original RX signal infos */
511 //                      ss_final = dst->PhyInfo.SignalStrength;
512 //                      sq_final = dst->PhyInfo.SignalQuality;
513 //                      rssi_final = dst->Rssi;
514 //              }
515         }
516         if (update_ie) {
517                 dst->Reserved[0] = src->Reserved[0];
518                 dst->Reserved[1] = src->Reserved[1];
519                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
520         }
521         dst->PhyInfo.SignalStrength = ss_final;
522         dst->PhyInfo.SignalQuality = sq_final;
523         dst->Rssi = rssi_final;
524
525 }
526
527 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
528 {
529         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
530
531         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) &&
532             (is_same_network(&(pmlmepriv->cur_network.network), pnetwork))) {
533                 update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
534                 rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof(struct ndis_802_11_fixed_ie),
535                                       pmlmepriv->cur_network.network.IELength);
536         }
537
538 }
539
540 /*
541 Caller must hold pmlmepriv->lock first.
542 */
543 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
544 {
545         struct list_head *plist, *phead;
546         u32     bssid_ex_sz;
547         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
548         struct __queue *queue   = &(pmlmepriv->scanned_queue);
549         struct wlan_network     *pnetwork = NULL;
550         struct wlan_network     *oldest = NULL;
551
552         spin_lock_bh(&queue->lock);
553         phead = get_list_head(queue);
554         plist = phead->next;
555
556         while (phead != plist) {
557                 pnetwork        = container_of(plist, struct wlan_network, list);
558
559                 if (is_same_network(&(pnetwork->network), target))
560                         break;
561                 if ((oldest == ((struct wlan_network *)0)) ||
562                     time_after(oldest->last_scanned, pnetwork->last_scanned))
563                         oldest = pnetwork;
564                 plist = plist->next;
565         }
566         /* If we didn't find a match, then get a new network slot to initialize
567          * with this beacon's information */
568         if (phead == plist) {
569                 if (list_empty(&(pmlmepriv->free_bss_pool.queue))) {
570                         /* If there are no more slots, expire the oldest */
571                         pnetwork = oldest;
572
573                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
574                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
575                         /*  variable initialize */
576                         pnetwork->fixed = false;
577                         pnetwork->last_scanned = jiffies;
578
579                         pnetwork->network_type = 0;
580                         pnetwork->aid = 0;
581                         pnetwork->join_res = 0;
582
583                         /* bss info not receiving from the right channel */
584                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
585                                 pnetwork->network.PhyInfo.SignalQuality = 0;
586                 } else {
587                         /* Otherwise just pull from the free list */
588
589                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
590
591                         if (pnetwork == NULL) {
592                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
593                                 goto exit;
594                         }
595
596                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
597                         target->Length = bssid_ex_sz;
598                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
599                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
600
601                         pnetwork->last_scanned = jiffies;
602
603                         /* bss info not receiving from the right channel */
604                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
605                                 pnetwork->network.PhyInfo.SignalQuality = 0;
606                         list_add_tail(&(pnetwork->list), &(queue->queue));
607                 }
608         } else {
609                 /* we have an entry and we are going to update it. But this entry may
610                  * be already expired. In this case we do the same as we found a new
611                  * net and call the new_net handler
612                  */
613                 bool update_ie = true;
614
615                 pnetwork->last_scanned = jiffies;
616
617                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
618                 /* probe resp(3) > beacon(1) > probe req(2) */
619                 if ((target->Reserved[0] != 2) &&
620                     (target->Reserved[0] >= pnetwork->network.Reserved[0]))
621                         update_ie = true;
622                 else
623                         update_ie = false;
624                 update_network(&(pnetwork->network), target, adapter, update_ie);
625         }
626
627 exit:
628         spin_unlock_bh(&queue->lock);
629
630 }
631
632 static void rtw_add_network(struct adapter *adapter,
633                             struct wlan_bssid_ex *pnetwork)
634 {
635
636 #if defined(CONFIG_88EU_P2P)
637         rtw_wlan_bssid_ex_remove_p2p_attr(pnetwork, P2P_ATTR_GROUP_INFO);
638 #endif
639         update_current_network(adapter, pnetwork);
640         rtw_update_scanned_network(adapter, pnetwork);
641
642 }
643
644 /* select the desired network based on the capability of the (i)bss. */
645 /*  check items:        (1) security */
646 /*                      (2) network_type */
647 /*                      (3) WMM */
648 /*                      (4) HT */
649 /*                      (5) others */
650 static int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
651 {
652         struct security_priv *psecuritypriv = &adapter->securitypriv;
653         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
654         u32 desired_encmode;
655         u32 privacy;
656
657         /* u8 wps_ie[512]; */
658         uint wps_ielen;
659
660         int bselected = true;
661
662         desired_encmode = psecuritypriv->ndisencryptstatus;
663         privacy = pnetwork->network.Privacy;
664
665         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
666                 if (rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen) != NULL)
667                         return true;
668                 else
669                         return false;
670         }
671         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
672                 u8 *p = NULL;
673                 uint ie_len = 0;
674
675                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
676                         bselected = false;
677                 if (psecuritypriv->ndisauthtype == Ndis802_11AuthModeWPA2PSK) {
678                         p = rtw_get_ie(pnetwork->network.IEs + _BEACON_IE_OFFSET_,
679                                        _RSN_IE_2_, &ie_len,
680                                        (pnetwork->network.IELength -
681                                        _BEACON_IE_OFFSET_));
682                         if (p && ie_len > 0)
683                                 bselected = true;
684                         else
685                                 bselected = false;
686                 }
687         }
688
689         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
690                 DBG_88E("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
691                 bselected = false;
692         }
693
694         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
695                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
696                         bselected = false;
697         }
698
699         return bselected;
700 }
701
702 /* TODO: Perry: For Power Management */
703 void rtw_atimdone_event_callback(struct adapter *adapter, u8 *pbuf)
704 {
705
706         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_evet\n"));
707
708         return;
709 }
710
711 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
712 {
713         u32 len;
714         struct wlan_bssid_ex *pnetwork;
715         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
716
717         pnetwork = (struct wlan_bssid_ex *)pbuf;
718
719         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid=%s\n",  pnetwork->Ssid.Ssid));
720
721         len = get_wlan_bssid_ex_sz(pnetwork);
722         if (len > (sizeof(struct wlan_bssid_ex))) {
723                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n****rtw_survey_event_callback: return a wrong bss ***\n"));
724                 return;
725         }
726         spin_lock_bh(&pmlmepriv->lock);
727
728         /*  update IBSS_network 's timestamp */
729         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) {
730                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN)) {
731                         struct wlan_network *ibss_wlan = NULL;
732
733                         memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
734                         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
735                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
736                         if (ibss_wlan) {
737                                 memcpy(ibss_wlan->network.IEs, pnetwork->IEs, 8);
738                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
739                                 goto exit;
740                         }
741                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
742                 }
743         }
744
745         /*  lock pmlmepriv->lock when you accessing network_q */
746         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false) {
747                 if (pnetwork->Ssid.Ssid[0] == 0)
748                         pnetwork->Ssid.SsidLength = 0;
749                 rtw_add_network(adapter, pnetwork);
750         }
751
752 exit:
753
754         spin_unlock_bh(&pmlmepriv->lock);
755
756         return;
757 }
758
759 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
760 {
761         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
762         struct mlme_ext_priv *pmlmeext;
763         u8 timer_cancelled = 0;
764
765         spin_lock_bh(&pmlmepriv->lock);
766
767         if (pmlmepriv->wps_probe_req_ie) {
768                 pmlmepriv->wps_probe_req_ie_len = 0;
769                 kfree(pmlmepriv->wps_probe_req_ie);
770                 pmlmepriv->wps_probe_req_ie = NULL;
771         }
772
773         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
774
775         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
776                 timer_cancelled = 1;
777
778                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
779         } else {
780                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status=%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
781         }
782
783         spin_unlock_bh(&pmlmepriv->lock);
784
785         if (timer_cancelled)
786                 _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
787
788         spin_lock_bh(&pmlmepriv->lock);
789         rtw_set_signal_stat_timer(&adapter->recvpriv);
790
791         if (pmlmepriv->to_join) {
792                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
793                         if (check_fwstate(pmlmepriv, _FW_LINKED) == false) {
794                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
795
796                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
797                                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
798                                 } else {
799                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
800                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
801
802                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
803
804                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
805
806                                         memset(&pdev_network->Ssid, 0, sizeof(struct ndis_802_11_ssid));
807                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
808
809                                         rtw_update_registrypriv_dev_network(adapter);
810                                         rtw_generate_random_ibss(pibss);
811
812                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
813
814                                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
815                                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error=>rtw_createbss_cmd status FAIL\n"));
816                                         pmlmepriv->to_join = false;
817                                 }
818                         }
819                 } else {
820                         int s_ret;
821                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
822                         pmlmepriv->to_join = false;
823                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
824                         if (_SUCCESS == s_ret) {
825                              _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
826                         } else if (s_ret == 2) { /* there is no need to wait for join */
827                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
828                                 rtw_indicate_connect(adapter);
829                         } else {
830                                 DBG_88E("try_to_join, but select scanning queue fail, to_roaming:%d\n",
831                                         pmlmepriv->to_roaming);
832                                 if (rtw_to_roaming(adapter) != 0) {
833                                         if (--pmlmepriv->to_roaming == 0 ||
834                                             _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)) {
835                                                 rtw_set_roaming(adapter, 0);
836                                                 rtw_free_assoc_resources(adapter, 1);
837                                                 rtw_indicate_disconnect(adapter);
838                                         } else {
839                                                 pmlmepriv->to_join = true;
840                                         }
841                                 } else {
842                                         rtw_indicate_disconnect(adapter);
843                                 }
844                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
845                         }
846                 }
847         }
848
849         indicate_wx_scan_complete_event(adapter);
850
851         spin_unlock_bh(&pmlmepriv->lock);
852
853         if (check_fwstate(pmlmepriv, _FW_LINKED) == true)
854                 p2p_ps_wk_cmd(adapter, P2P_PS_SCAN_DONE, 0);
855
856         rtw_os_xmit_schedule(adapter);
857
858         pmlmeext = &adapter->mlmeextpriv;
859
860 }
861
862 void rtw_dummy_event_callback(struct adapter *adapter, u8 *pbuf)
863 {
864 }
865
866 void rtw_fwdbg_event_callback(struct adapter *adapter, u8 *pbuf)
867 {
868 }
869
870 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
871 {
872         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
873         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
874         struct list_head *plist, *phead, *ptemp;
875
876         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
877         spin_lock_bh(&scan_queue->lock);
878         spin_lock_bh(&free_queue->lock);
879
880         phead = get_list_head(scan_queue);
881         plist = phead->next;
882
883         while (plist != phead) {
884                 ptemp = plist->next;
885                 list_del_init(plist);
886                 list_add_tail(plist, &free_queue->queue);
887                 plist = ptemp;
888                 pmlmepriv->num_of_scanned--;
889         }
890
891         spin_unlock_bh(&free_queue->lock);
892         spin_unlock_bh(&scan_queue->lock);
893 }
894
895 /*
896 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
897 */
898 void rtw_free_assoc_resources(struct adapter *adapter, int lock_scanned_queue)
899 {
900         struct wlan_network *pwlan = NULL;
901         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
902         struct  sta_priv *pstapriv = &adapter->stapriv;
903         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
904
905         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
906         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
907                  ("tgt_network->network.MacAddress=%pM ssid=%s\n",
908                  tgt_network->network.MacAddress, tgt_network->network.Ssid.Ssid));
909
910         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_AP_STATE)) {
911                 struct sta_info *psta;
912
913                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
914
915                 spin_lock_bh(&pstapriv->sta_hash_lock);
916                 rtw_free_stainfo(adapter,  psta);
917                 spin_unlock_bh(&pstapriv->sta_hash_lock);
918         }
919
920         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE | WIFI_ADHOC_MASTER_STATE | WIFI_AP_STATE)) {
921                 struct sta_info *psta;
922
923                 rtw_free_all_stainfo(adapter);
924
925                 psta = rtw_get_bcmc_stainfo(adapter);
926                 spin_lock_bh(&pstapriv->sta_hash_lock);
927                 rtw_free_stainfo(adapter, psta);
928                 spin_unlock_bh(&pstapriv->sta_hash_lock);
929
930                 rtw_init_bcmc_stainfo(adapter);
931         }
932
933         if (lock_scanned_queue)
934                 spin_lock_bh(&pmlmepriv->scanned_queue.lock);
935
936         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
937         if (pwlan)
938                 pwlan->fixed = false;
939         else
940                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources:pwlan==NULL\n\n"));
941
942         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) && (adapter->stapriv.asoc_sta_count == 1)))
943                 rtw_free_network_nolock(pmlmepriv, pwlan);
944
945         if (lock_scanned_queue)
946                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
947         pmlmepriv->key_mask = 0;
948
949 }
950
951 /*
952 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
953 */
954 void rtw_indicate_connect(struct adapter *padapter)
955 {
956         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
957
958         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
959
960         pmlmepriv->to_join = false;
961
962         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
963                 set_fwstate(pmlmepriv, _FW_LINKED);
964
965                 rtw_led_control(padapter, LED_CTL_LINK);
966
967                 rtw_os_indicate_connect(padapter);
968         }
969
970         pmlmepriv->to_roaming = 0;
971
972         rtw_set_scan_deny(padapter, 3000);
973
974         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state=0x%08x\n", get_fwstate(pmlmepriv)));
975
976 }
977
978 /*
979 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
980 */
981 void rtw_indicate_disconnect(struct adapter *padapter)
982 {
983         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
984
985         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
986
987         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING | WIFI_UNDER_WPS);
988
989         if (pmlmepriv->to_roaming > 0)
990                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
991
992         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) ||
993             (pmlmepriv->to_roaming <= 0)) {
994                 rtw_os_indicate_disconnect(padapter);
995
996                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
997                 rtw_led_control(padapter, LED_CTL_NO_LINK);
998                 rtw_clear_scan_deny(padapter);
999         }
1000         p2p_ps_wk_cmd(padapter, P2P_PS_DISABLE, 1);
1001
1002         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
1003
1004 }
1005
1006 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
1007 {
1008         rtw_os_indicate_scan_done(padapter, aborted);
1009 }
1010
1011 void rtw_scan_abort(struct adapter *adapter)
1012 {
1013         u32 start;
1014         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
1015         struct mlme_ext_priv    *pmlmeext = &(adapter->mlmeextpriv);
1016
1017         start = jiffies;
1018         pmlmeext->scan_abort = true;
1019         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY) &&
1020                rtw_get_passing_time_ms(start) <= 200) {
1021                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1022                         break;
1023                 DBG_88E(FUNC_NDEV_FMT"fw_state=_FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1024                 rtw_msleep_os(20);
1025         }
1026         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
1027                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
1028                         DBG_88E(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1029                 rtw_indicate_scan_done(adapter, true);
1030         }
1031         pmlmeext->scan_abort = false;
1032 }
1033
1034 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
1035 {
1036         int i;
1037         struct sta_info *bmc_sta, *psta = NULL;
1038         struct recv_reorder_ctrl *preorder_ctrl;
1039         struct sta_priv *pstapriv = &padapter->stapriv;
1040
1041         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
1042         if (psta == NULL)
1043                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
1044
1045         if (psta) { /* update ptarget_sta */
1046                 DBG_88E("%s\n", __func__);
1047                 psta->aid  = pnetwork->join_res;
1048                         psta->mac_id = 0;
1049                 /* sta mode */
1050                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
1051                 /* security related */
1052                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1053                         padapter->securitypriv.binstallGrpkey = false;
1054                         padapter->securitypriv.busetkipkey = false;
1055                         padapter->securitypriv.bgrpkey_handshake = false;
1056                         psta->ieee8021x_blocked = true;
1057                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
1058                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
1059                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
1060                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
1061                         memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
1062                         memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
1063                 }
1064                 /*      Commented by Albert 2012/07/21 */
1065                 /*      When doing the WPS, the wps_ie_len won't equal to 0 */
1066                 /*      And the Wi-Fi driver shouldn't allow the data packet to be tramsmitted. */
1067                 if (padapter->securitypriv.wps_ie_len != 0) {
1068                         psta->ieee8021x_blocked = true;
1069                         padapter->securitypriv.wps_ie_len = 0;
1070                 }
1071                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
1072                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
1073                 /* todo: check if AP can send A-MPDU packets */
1074                 for (i = 0; i < 16; i++) {
1075                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1076                         preorder_ctrl = &psta->recvreorder_ctrl[i];
1077                         preorder_ctrl->enable = false;
1078                         preorder_ctrl->indicate_seq = 0xffff;
1079                         preorder_ctrl->wend_b = 0xffff;
1080                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
1081                 }
1082                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
1083                 if (bmc_sta) {
1084                         for (i = 0; i < 16; i++) {
1085                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1086                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
1087                                 preorder_ctrl->enable = false;
1088                                 preorder_ctrl->indicate_seq = 0xffff;
1089                                 preorder_ctrl->wend_b = 0xffff;
1090                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
1091                         }
1092                 }
1093                 /* misc. */
1094                 update_sta_info(padapter, psta);
1095         }
1096         return psta;
1097 }
1098
1099 /* pnetwork: returns from rtw_joinbss_event_callback */
1100 /* ptarget_wlan: found from scanned_queue */
1101 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
1102 {
1103         struct mlme_priv        *pmlmepriv = &(padapter->mlmepriv);
1104         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
1105
1106         DBG_88E("%s\n", __func__);
1107
1108         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
1109                  ("\nfw_state:%x, BSSID:%pM\n",
1110                  get_fwstate(pmlmepriv), pnetwork->network.MacAddress));
1111
1112         /*  why not use ptarget_wlan?? */
1113         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
1114         /*  some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs */
1115         cur_network->network.IELength = ptarget_wlan->network.IELength;
1116         memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
1117
1118         cur_network->aid = pnetwork->join_res;
1119
1120         rtw_set_signal_stat_timer(&padapter->recvpriv);
1121         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
1122         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
1123         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
1124         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
1125         rtw_set_signal_stat_timer(&padapter->recvpriv);
1126
1127         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
1128         switch (pnetwork->network.InfrastructureMode) {
1129         case Ndis802_11Infrastructure:
1130                 if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
1131                         pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
1132                 else
1133                         pmlmepriv->fw_state = WIFI_STATION_STATE;
1134                 break;
1135         case Ndis802_11IBSS:
1136                 pmlmepriv->fw_state = WIFI_ADHOC_STATE;
1137                 break;
1138         default:
1139                 pmlmepriv->fw_state = WIFI_NULL_STATE;
1140                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
1141                 break;
1142         }
1143
1144         rtw_update_protection(padapter, (cur_network->network.IEs) +
1145                               sizeof(struct ndis_802_11_fixed_ie),
1146                               (cur_network->network.IELength));
1147         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength);
1148 }
1149
1150 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
1151 /* pnetwork: returns from rtw_joinbss_event_callback */
1152 /* ptarget_wlan: found from scanned_queue */
1153 /* if join_res > 0, for (fw_state == WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
1154 /* if join_res > 0, for (fw_state == WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
1155 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
1156
1157 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
1158 {
1159         u8 timer_cancelled;
1160         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
1161         struct  sta_priv *pstapriv = &adapter->stapriv;
1162         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
1163         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1164         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1165         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1166         unsigned int            the_same_macaddr = false;
1167
1168         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res=%d\n", pnetwork->join_res));
1169
1170         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1171
1172         if (pmlmepriv->assoc_ssid.SsidLength == 0)
1173                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
1174         else
1175                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
1176
1177         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1178
1179         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1180         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
1181                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1182                 return;
1183         }
1184
1185         spin_lock_bh(&pmlmepriv->lock);
1186
1187         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nrtw_joinbss_event_callback!! spin_lock_init\n"));
1188
1189         if (pnetwork->join_res > 0) {
1190                 spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1191                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1192                         /* s1. find ptarget_wlan */
1193                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1194                                 if (the_same_macaddr) {
1195                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1196                                 } else {
1197                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1198                                         if (pcur_wlan)
1199                                                 pcur_wlan->fixed = false;
1200
1201                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1202                                         if (pcur_sta) {
1203                                                 spin_lock_bh(&pstapriv->sta_hash_lock);
1204                                                 rtw_free_stainfo(adapter,  pcur_sta);
1205                                                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1206                                         }
1207
1208                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1209                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1210                                                 if (ptarget_wlan)
1211                                                         ptarget_wlan->fixed = true;
1212                                         }
1213                                 }
1214                         } else {
1215                                 ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1216                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1217                                         if (ptarget_wlan)
1218                                                 ptarget_wlan->fixed = true;
1219                                 }
1220                         }
1221
1222                         /* s2. update cur_network */
1223                         if (ptarget_wlan) {
1224                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1225                         } else {
1226                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't find ptarget_wlan when joinbss_event callback\n"));
1227                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1228                                 goto ignore_joinbss_callback;
1229                         }
1230
1231                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1232                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1233                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1234                                 if (ptarget_sta == NULL) {
1235                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1236                                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1237                                         goto ignore_joinbss_callback;
1238                                 }
1239                         }
1240
1241                         /* s4. indicate connect */
1242                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1243                                         pmlmepriv->cur_network_scanned = ptarget_wlan;
1244                                         rtw_indicate_connect(adapter);
1245                                 } else {
1246                                         /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1247                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1248                                 }
1249
1250                         /* s5. Cancle assoc_timer */
1251                         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
1252
1253                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancle assoc_timer\n"));
1254
1255                 } else {
1256                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1257                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1258                         goto ignore_joinbss_callback;
1259                 }
1260
1261                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1262
1263         } else if (pnetwork->join_res == -4) {
1264                 rtw_reset_securitypriv(adapter);
1265                 _set_timer(&pmlmepriv->assoc_timer, 1);
1266
1267                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true) {
1268                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state=%x\n", get_fwstate(pmlmepriv)));
1269                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1270                 }
1271         } else { /* if join_res < 0 (join fails), then try again */
1272                 _set_timer(&pmlmepriv->assoc_timer, 1);
1273                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1274         }
1275
1276 ignore_joinbss_callback:
1277         spin_unlock_bh(&pmlmepriv->lock);
1278 }
1279
1280 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1281 {
1282         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1283
1284         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1285
1286         rtw_os_xmit_schedule(adapter);
1287
1288 }
1289
1290 static u8 search_max_mac_id(struct adapter *padapter)
1291 {
1292         u8 mac_id;
1293 #if defined (CONFIG_88EU_AP_MODE)
1294         u8 aid;
1295         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1296         struct sta_priv *pstapriv = &padapter->stapriv;
1297 #endif
1298         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
1299         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
1300
1301 #if defined (CONFIG_88EU_AP_MODE)
1302         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1303                 for (aid = (pstapriv->max_num_sta); aid > 0; aid--) {
1304                         if (pstapriv->sta_aid[aid-1] != NULL)
1305                                 break;
1306                 }
1307                 mac_id = aid + 1;
1308         } else
1309 #endif
1310         {/* adhoc  id =  31~2 */
1311                 for (mac_id = (NUM_STA-1); mac_id >= IBSS_START_MAC_ID; mac_id--) {
1312                         if (pmlmeinfo->FW_sta_info[mac_id].status == 1)
1313                                 break;
1314                 }
1315         }
1316         return mac_id;
1317 }
1318
1319 /* FOR AP , AD-HOC mode */
1320 void rtw_sta_media_status_rpt(struct adapter *adapter,struct sta_info *psta,
1321                               u32 mstatus)
1322 {
1323         u16 media_status_rpt;
1324         u8 macid;
1325
1326         if (psta == NULL)
1327                 return;
1328
1329         macid = search_max_mac_id(adapter);
1330         rtw_hal_set_hwreg(adapter, HW_VAR_TX_RPT_MAX_MACID, (u8 *)&macid);
1331         /* MACID|OPMODE:1 connect */
1332         media_status_rpt = (u16)((psta->mac_id<<8) | mstatus);
1333         rtw_hal_set_hwreg(adapter,HW_VAR_H2C_MEDIA_STATUS_RPT,
1334                           (u8 *)&media_status_rpt);
1335 }
1336
1337 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1338 {
1339         struct sta_info *psta;
1340         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1341         struct stassoc_event    *pstassoc = (struct stassoc_event *)pbuf;
1342         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1343         struct wlan_network     *ptarget_wlan = NULL;
1344
1345         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1346                 return;
1347
1348 #if defined (CONFIG_88EU_AP_MODE)
1349         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1350                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1351                 if (psta)
1352                         rtw_indicate_sta_assoc_event(adapter, psta);
1353                 return;
1354         }
1355 #endif
1356         /* for AD-HOC mode */
1357         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1358         if (psta != NULL) {
1359                 /* the sta have been in sta_info_queue => do nothing */
1360                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1361                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1362         }
1363         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1364         if (psta == NULL) {
1365                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1366                 return;
1367         }
1368         /* to do: init sta_info variable */
1369         psta->qos_option = 0;
1370         psta->mac_id = (uint)pstassoc->cam_id;
1371         DBG_88E("%s\n", __func__);
1372         /* for ad-hoc mode */
1373         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1374         rtw_sta_media_status_rpt(adapter, psta, 1);
1375         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1376                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1377         psta->ieee8021x_blocked = false;
1378         spin_lock_bh(&pmlmepriv->lock);
1379         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
1380             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE))) {
1381                 if (adapter->stapriv.asoc_sta_count == 2) {
1382                         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1383                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1384                         pmlmepriv->cur_network_scanned = ptarget_wlan;
1385                         if (ptarget_wlan)
1386                                 ptarget_wlan->fixed = true;
1387                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1388                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1389                         rtw_indicate_connect(adapter);
1390                 }
1391         }
1392         spin_unlock_bh(&pmlmepriv->lock);
1393         mlmeext_sta_add_event_callback(adapter, psta);
1394 }
1395
1396 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1397 {
1398         int mac_id = -1;
1399         struct sta_info *psta;
1400         struct wlan_network *pwlan = NULL;
1401         struct wlan_bssid_ex *pdev_network = NULL;
1402         u8 *pibss = NULL;
1403         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1404         struct  stadel_event *pstadel = (struct stadel_event *)pbuf;
1405         struct  sta_priv *pstapriv = &adapter->stapriv;
1406         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1407
1408         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1409         if (psta)
1410                 mac_id = psta->mac_id;
1411         else
1412                 mac_id = pstadel->mac_id;
1413
1414         DBG_88E("%s(mac_id=%d)=%pM\n", __func__, mac_id, pstadel->macaddr);
1415
1416         if (mac_id >= 0) {
1417                 u16 media_status;
1418                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1419                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1420                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1421         }
1422
1423         if (check_fwstate(pmlmepriv, WIFI_AP_STATE))
1424                 return;
1425
1426         mlmeext_sta_del_event_callback(adapter);
1427
1428         spin_lock_bh(&pmlmepriv->lock);
1429
1430         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1431                 if(adapter->registrypriv.wifi_spec == 1)
1432                         rtw_set_roaming(adapter, 0); /* don't roam */
1433                 else if (rtw_to_roaming(adapter) > 0)
1434                         pmlmepriv->to_roaming--; /* this stadel_event is caused by roaming, decrease to_roaming */
1435                 else if (rtw_to_roaming(adapter) == 0)
1436                         rtw_set_roaming(adapter,
1437                                         adapter->registrypriv.max_roaming_times);
1438
1439                 if (*((unsigned short *)(pstadel->rsvd)) != WLAN_REASON_EXPIRATION_CHK)
1440                         rtw_set_roaming(adapter, 0); /* don't roam */
1441
1442                 rtw_free_uc_swdec_pending_queue(adapter);
1443
1444                 rtw_free_assoc_resources(adapter, 1);
1445                 rtw_indicate_disconnect(adapter);
1446                 spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1447                 /*  remove the network entry in scanned_queue */
1448                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1449                 if (pwlan) {
1450                         pwlan->fixed = false;
1451                         rtw_free_network_nolock(pmlmepriv, pwlan);
1452                 }
1453                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1454                 _rtw_roaming(adapter, tgt_network);
1455         }
1456         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1457             check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1458                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1459                 rtw_free_stainfo(adapter,  psta);
1460                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1461
1462                 if (adapter->stapriv.asoc_sta_count == 1) { /* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1463                         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1464                         /* free old ibss network */
1465                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1466                         if (pwlan) {
1467                                 pwlan->fixed = false;
1468                                 rtw_free_network_nolock(pmlmepriv, pwlan);
1469                         }
1470                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1471                         /* re-create ibss */
1472                         pdev_network = &(adapter->registrypriv.dev_network);
1473                         pibss = adapter->registrypriv.dev_network.MacAddress;
1474
1475                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1476
1477                         memset(&pdev_network->Ssid, 0, sizeof(struct ndis_802_11_ssid));
1478                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1479
1480                         rtw_update_registrypriv_dev_network(adapter);
1481
1482                         rtw_generate_random_ibss(pibss);
1483
1484                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1485                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1486                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1487                         }
1488
1489                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
1490                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error=>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1491                 }
1492         }
1493         spin_unlock_bh(&pmlmepriv->lock);
1494
1495 }
1496
1497 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1498 {
1499
1500         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1501
1502 }
1503
1504 /*
1505 * _rtw_join_timeout_handler - Timeout/faliure handler for CMD JoinBss
1506 * @adapter: pointer to struct adapter structure
1507 */
1508 void _rtw_join_timeout_handler (struct adapter *adapter)
1509 {
1510         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1511         int do_join_r;
1512
1513         DBG_88E("%s, fw_state=%x\n", __func__, get_fwstate(pmlmepriv));
1514
1515         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1516                 return;
1517
1518         spin_lock_bh(&pmlmepriv->lock);
1519
1520         if (rtw_to_roaming(adapter) > 0) { /* join timeout caused by roaming */
1521                 while (1) {
1522                         pmlmepriv->to_roaming--;
1523                         if (rtw_to_roaming(adapter) != 0) { /* try another */
1524                                 DBG_88E("%s try another roaming\n", __func__);
1525                                 do_join_r = rtw_do_join(adapter);
1526                                 if (_SUCCESS != do_join_r) {
1527                                         DBG_88E("%s roaming do_join return %d\n", __func__, do_join_r);
1528                                         continue;
1529                                 }
1530                                 break;
1531                         } else {
1532                                 DBG_88E("%s We've try roaming but fail\n", __func__);
1533                                 rtw_indicate_disconnect(adapter);
1534                                 break;
1535                         }
1536                 }
1537         } else {
1538                 rtw_indicate_disconnect(adapter);
1539                 free_scanqueue(pmlmepriv);/*  */
1540         }
1541         spin_unlock_bh(&pmlmepriv->lock);
1542
1543 }
1544
1545 /*
1546 * rtw_scan_timeout_handler - Timeout/Faliure handler for CMD SiteSurvey
1547 * @adapter: pointer to struct adapter structure
1548 */
1549 void rtw_scan_timeout_handler (struct adapter *adapter)
1550 {
1551         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1552
1553         DBG_88E(FUNC_ADPT_FMT" fw_state=%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1554         spin_lock_bh(&pmlmepriv->lock);
1555         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1556         spin_unlock_bh(&pmlmepriv->lock);
1557         rtw_indicate_scan_done(adapter, true);
1558 }
1559
1560 static void rtw_auto_scan_handler(struct adapter *padapter)
1561 {
1562         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1563
1564         /* auto site survey per 60sec */
1565         if (pmlmepriv->scan_interval > 0) {
1566                 pmlmepriv->scan_interval--;
1567                 if (pmlmepriv->scan_interval == 0) {
1568                         DBG_88E("%s\n", __func__);
1569                         rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1570                         pmlmepriv->scan_interval = SCAN_INTERVAL;/*  30*2 sec = 60sec */
1571                 }
1572         }
1573 }
1574
1575 void rtw_dynamic_check_timer_handlder(struct adapter *adapter)
1576 {
1577         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1578         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1579
1580         if (!adapter)
1581                 return;
1582         if (!adapter->hw_init_completed)
1583                 return;
1584         if ((adapter->bDriverStopped) || (adapter->bSurpriseRemoved))
1585                 return;
1586         if (adapter->net_closed)
1587                 return;
1588         rtw_dynamic_chk_wk_cmd(adapter);
1589
1590         if (pregistrypriv->wifi_spec == 1) {
1591 #ifdef CONFIG_88EU_P2P
1592                 struct wifidirect_info *pwdinfo = &adapter->wdinfo;
1593                 if (rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
1594 #endif
1595                 {
1596                         /* auto site survey */
1597                         rtw_auto_scan_handler(adapter);
1598                 }
1599         }
1600
1601         rcu_read_lock();
1602
1603 #if LINUX_VERSION_CODE >= KERNEL_VERSION(2,6,36)
1604         if (rcu_dereference(adapter->pnetdev->rx_handler_data) &&
1605 #else
1606         if (rcu_dereference(adapter->pnetdev->br_port) &&
1607 #endif
1608             (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_ADHOC_STATE) == true)) {
1609                 /*  expire NAT2.5 entry */
1610                 nat25_db_expire(adapter);
1611
1612                 if (adapter->pppoe_connection_in_progress > 0) {
1613                         adapter->pppoe_connection_in_progress--;
1614                 }
1615
1616                 /*  due to rtw_dynamic_check_timer_handlder() is called every 2 seconds */
1617                 if (adapter->pppoe_connection_in_progress > 0) {
1618                         adapter->pppoe_connection_in_progress--;
1619                 }
1620         }
1621
1622         rcu_read_unlock();
1623 }
1624
1625 #define RTW_SCAN_RESULT_EXPIRE 2000
1626
1627 /*
1628 * Select a new join candidate from the original @param candidate and @param competitor
1629 * @return true: candidate is updated
1630 * @return false: candidate is not updated
1631 */
1632 static int rtw_check_join_candidate(struct mlme_priv *pmlmepriv
1633         , struct wlan_network **candidate, struct wlan_network *competitor)
1634 {
1635         int updated = false;
1636         struct adapter *adapter = container_of(pmlmepriv, struct adapter, mlmepriv);
1637
1638         /* check bssid, if needed */
1639         if (pmlmepriv->assoc_by_bssid) {
1640                 if (memcmp(competitor->network.MacAddress, pmlmepriv->assoc_bssid, ETH_ALEN))
1641                         goto exit;
1642         }
1643
1644         /* check ssid, if needed */
1645         if (pmlmepriv->assoc_ssid.Ssid && pmlmepriv->assoc_ssid.SsidLength) {
1646                 if (competitor->network.Ssid.SsidLength != pmlmepriv->assoc_ssid.SsidLength ||
1647                     memcmp(competitor->network.Ssid.Ssid, pmlmepriv->assoc_ssid.Ssid, pmlmepriv->assoc_ssid.SsidLength))
1648                         goto exit;
1649         }
1650
1651         if (rtw_is_desired_network(adapter, competitor)  == false)
1652                 goto exit;
1653
1654         if(rtw_to_roaming(adapter) > 0) {
1655                 if (rtw_get_passing_time_ms((u32)competitor->last_scanned) >= RTW_SCAN_RESULT_EXPIRE ||
1656                     is_same_ess(&competitor->network, &pmlmepriv->cur_network.network) == false)
1657                         goto exit;
1658         }
1659
1660         if (*candidate == NULL || (*candidate)->network.Rssi < competitor->network.Rssi) {
1661                 *candidate = competitor;
1662                 updated = true;
1663         }
1664         if (updated) {
1665                 DBG_88E("[by_bssid:%u][assoc_ssid:%s]new candidate: %s(%pM rssi:%d\n",
1666                         pmlmepriv->assoc_by_bssid,
1667                         pmlmepriv->assoc_ssid.Ssid,
1668                         (*candidate)->network.Ssid.Ssid,
1669                         (*candidate)->network.MacAddress,
1670                         (int)(*candidate)->network.Rssi);
1671                 DBG_88E("[to_roaming:%u]\n",rtw_to_roaming(adapter));
1672         }
1673
1674 exit:
1675         return updated;
1676 }
1677
1678 /*
1679 Calling context:
1680 The caller of the sub-routine will be in critical section...
1681 The caller must hold the following spinlock
1682 pmlmepriv->lock
1683 */
1684
1685 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
1686 {
1687         int ret;
1688         struct list_head *phead;
1689         struct adapter *adapter;
1690         struct __queue *queue   = &(pmlmepriv->scanned_queue);
1691         struct  wlan_network    *pnetwork = NULL;
1692         struct  wlan_network    *candidate = NULL;
1693         u8      supp_ant_div = false;
1694
1695         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1696         phead = get_list_head(queue);
1697         adapter = (struct adapter *)pmlmepriv->nic_hdl;
1698         pmlmepriv->pscanned = phead->next;
1699         while (phead != pmlmepriv->pscanned) {
1700                 pnetwork = container_of(pmlmepriv->pscanned, struct wlan_network, list);
1701                 if (pnetwork == NULL) {
1702                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork==NULL)\n", __func__));
1703                         ret = _FAIL;
1704                         goto exit;
1705                 }
1706                 pmlmepriv->pscanned = pmlmepriv->pscanned->next;
1707                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
1708         }
1709         if (candidate == NULL) {
1710                 DBG_88E("%s: return _FAIL(candidate==NULL)\n", __func__);
1711                 ret = _FAIL;
1712                 goto exit;
1713         } else {
1714                 DBG_88E("%s: candidate: %s(%pM ch:%u)\n", __func__,
1715                         candidate->network.Ssid.Ssid, candidate->network.MacAddress,
1716                         candidate->network.Configuration.DSConfig);
1717         }
1718
1719         /*  check for situation of  _FW_LINKED */
1720         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
1721                 DBG_88E("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
1722
1723                 rtw_disassoc_cmd(adapter, 0, true);
1724                 rtw_indicate_disconnect(adapter);
1725                 rtw_free_assoc_resources(adapter, 0);
1726         }
1727
1728         rtw_hal_get_def_var(adapter, HAL_DEF_IS_SUPPORT_ANT_DIV, &(supp_ant_div));
1729         if (supp_ant_div) {
1730                 u8 cur_ant;
1731                 rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(cur_ant));
1732                 DBG_88E("#### Opt_Ant_(%s), cur_Ant(%s)\n",
1733                         (2 == candidate->network.PhyInfo.Optimum_antenna) ? "A" : "B",
1734                         (2 == cur_ant) ? "A" : "B"
1735                 );
1736         }
1737
1738         ret = rtw_joinbss_cmd(adapter, candidate);
1739
1740 exit:
1741         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1742
1743         return ret;
1744 }
1745
1746 int rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
1747 {
1748         struct  cmd_obj *pcmd;
1749         struct  setauth_parm *psetauthparm;
1750         struct  cmd_priv *pcmdpriv = &(adapter->cmdpriv);
1751         int             res = _SUCCESS;
1752
1753         pcmd = (struct  cmd_obj *)rtw_zmalloc(sizeof(struct cmd_obj));
1754         if (pcmd == NULL) {
1755                 res = _FAIL;  /* try again */
1756                 goto exit;
1757         }
1758
1759         psetauthparm = (struct setauth_parm *)rtw_zmalloc(sizeof(struct setauth_parm));
1760         if (psetauthparm == NULL) {
1761                 kfree(pcmd);
1762                 res = _FAIL;
1763                 goto exit;
1764         }
1765         memset(psetauthparm, 0, sizeof(struct setauth_parm));
1766         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
1767         pcmd->cmdcode = _SetAuth_CMD_;
1768         pcmd->parmbuf = (unsigned char *)psetauthparm;
1769         pcmd->cmdsz =  (sizeof(struct setauth_parm));
1770         pcmd->rsp = NULL;
1771         pcmd->rspsz = 0;
1772         INIT_LIST_HEAD(&pcmd->list);
1773         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1774                  ("after enqueue set_auth_cmd, auth_mode=%x\n",
1775                  psecuritypriv->dot11AuthAlgrthm));
1776         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1777 exit:
1778
1779         return res;
1780 }
1781
1782 int rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, int keyid, u8 set_tx)
1783 {
1784         u8      keylen;
1785         struct cmd_obj          *pcmd;
1786         struct setkey_parm      *psetkeyparm;
1787         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
1788         struct mlme_priv                *pmlmepriv = &(adapter->mlmepriv);
1789         int     res = _SUCCESS;
1790
1791         pcmd = (struct  cmd_obj *)rtw_zmalloc(sizeof(struct     cmd_obj));
1792         if (pcmd == NULL) {
1793                 res = _FAIL;  /* try again */
1794                 goto exit;
1795         }
1796         psetkeyparm = (struct setkey_parm *)rtw_zmalloc(sizeof(struct setkey_parm));
1797         if (psetkeyparm == NULL) {
1798                 kfree(pcmd);
1799                 res = _FAIL;
1800                 goto exit;
1801         }
1802
1803         memset(psetkeyparm, 0, sizeof(struct setkey_parm));
1804
1805         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1806                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
1807                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1808                          ("\n rtw_set_key: psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy=%d\n",
1809                          psetkeyparm->algorithm));
1810         } else {
1811                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
1812                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1813                          ("\n rtw_set_key: psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm=%d\n",
1814                          psetkeyparm->algorithm));
1815         }
1816         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
1817         psetkeyparm->set_tx = set_tx;
1818         pmlmepriv->key_mask |= BIT(psetkeyparm->keyid);
1819         DBG_88E("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n",
1820                 psetkeyparm->algorithm, psetkeyparm->keyid, pmlmepriv->key_mask);
1821         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1822                  ("\n rtw_set_key: psetkeyparm->algorithm=%d psetkeyparm->keyid=(u8)keyid=%d\n",
1823                  psetkeyparm->algorithm, keyid));
1824
1825         switch (psetkeyparm->algorithm) {
1826         case _WEP40_:
1827                 keylen = 5;
1828                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1829                 break;
1830         case _WEP104_:
1831                 keylen = 13;
1832                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1833                 break;
1834         case _TKIP_:
1835                 keylen = 16;
1836                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1837                 psetkeyparm->grpkey = 1;
1838                 break;
1839         case _AES_:
1840                 keylen = 16;
1841                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1842                 psetkeyparm->grpkey = 1;
1843                 break;
1844         default:
1845                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1846                          ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm=%x (must be 1 or 2 or 4 or 5)\n",
1847                          psecuritypriv->dot11PrivacyAlgrthm));
1848                 res = _FAIL;
1849                 goto exit;
1850         }
1851         pcmd->cmdcode = _SetKey_CMD_;
1852         pcmd->parmbuf = (u8 *)psetkeyparm;
1853         pcmd->cmdsz =  (sizeof(struct setkey_parm));
1854         pcmd->rsp = NULL;
1855         pcmd->rspsz = 0;
1856         INIT_LIST_HEAD(&pcmd->list);
1857         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1858 exit:
1859
1860         return res;
1861 }
1862
1863 /* adjust IEs for rtw_joinbss_cmd in WMM */
1864 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
1865 {
1866         unsigned        int ielength = 0;
1867         unsigned int i, j;
1868
1869         i = 12; /* after the fixed IE */
1870         while (i < in_len) {
1871                 ielength = initial_out_len;
1872
1873                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) {
1874                         /* WMM element ID and OUI */
1875                         /* Append WMM IE to the last index of out_ie */
1876
1877                         for (j = i; j < i + 9; j++) {
1878                                 out_ie[ielength] = in_ie[j];
1879                                 ielength++;
1880                         }
1881                         out_ie[initial_out_len + 1] = 0x07;
1882                         out_ie[initial_out_len + 6] = 0x00;
1883                         out_ie[initial_out_len + 8] = 0x00;
1884                         break;
1885                 }
1886                 i += (in_ie[i+1]+2); /*  to the next IE element */
1887         }
1888         return ielength;
1889 }
1890
1891 /*  */
1892 /*  Ported from 8185: IsInPreAuthKeyList(). (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.) */
1893 /*  Added by Annie, 2006-05-07. */
1894 /*  */
1895 /*  Search by BSSID, */
1896 /*  Return Value: */
1897 /*              -1              :if there is no pre-auth key in the  table */
1898 /*              >= 0            :if there is pre-auth key, and   return the entry id */
1899 /*  */
1900 /*  */
1901
1902 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
1903 {
1904         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1905         int i = 0;
1906
1907         do {
1908                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
1909                     (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN))) {
1910                         break;
1911                 } else {
1912                         i++;
1913                         /* continue; */
1914                 }
1915
1916         } while (i < NUM_PMKID_CACHE);
1917
1918         if (i == NUM_PMKID_CACHE) {
1919                 i = -1;/*  Could not find. */
1920         } else {
1921                 /*  There is one Pre-Authentication Key for the specific BSSID. */
1922         }
1923         return i;
1924 }
1925
1926 /*  */
1927 /*  Check the RSN IE length */
1928 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
1929 /*  0-11th element in the array are the fixed IE */
1930 /*  12th element in the array is the IE */
1931 /*  13th element in the array is the IE length */
1932 /*  */
1933
1934 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
1935 {
1936         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1937
1938         if (ie[13] <= 20) {
1939                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
1940                 ie[ie_len] = 1;
1941                 ie_len++;
1942                 ie[ie_len] = 0; /* PMKID count = 0x0100 */
1943                 ie_len++;
1944                 memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
1945
1946                 ie_len += 16;
1947                 ie[13] += 18;/* PMKID length = 2+16 */
1948         }
1949         return ie_len;
1950 }
1951
1952 int rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
1953 {
1954         u8 authmode;
1955         uint    ielength;
1956         int iEntry;
1957
1958         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1959         struct security_priv *psecuritypriv = &adapter->securitypriv;
1960         uint    ndisauthmode = psecuritypriv->ndisauthtype;
1961         uint ndissecuritytype = psecuritypriv->ndisencryptstatus;
1962
1963         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
1964                  ("+rtw_restruct_sec_ie: ndisauthmode=%d ndissecuritytype=%d\n",
1965                   ndisauthmode, ndissecuritytype));
1966
1967         /* copy fixed ie only */
1968         memcpy(out_ie, in_ie, 12);
1969         ielength = 12;
1970         if ((ndisauthmode == Ndis802_11AuthModeWPA) ||
1971             (ndisauthmode == Ndis802_11AuthModeWPAPSK))
1972                         authmode = _WPA_IE_ID_;
1973         if ((ndisauthmode == Ndis802_11AuthModeWPA2) ||
1974             (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
1975                 authmode = _WPA2_IE_ID_;
1976
1977         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
1978                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
1979
1980                 ielength += psecuritypriv->wps_ie_len;
1981         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
1982                 /* copy RSN or SSN */
1983                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
1984                 ielength += psecuritypriv->supplicant_ie[1]+2;
1985                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
1986         }
1987
1988         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
1989         if (iEntry < 0) {
1990                 return ielength;
1991         } else {
1992                 if (authmode == _WPA2_IE_ID_)
1993                         ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
1994         }
1995
1996         return ielength;
1997 }
1998
1999 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
2000 {
2001         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2002         struct eeprom_priv *peepriv = &adapter->eeprompriv;
2003         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2004         u8 *myhwaddr = myid(peepriv);
2005
2006         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
2007
2008         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
2009
2010         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_config);
2011         pdev_network->Configuration.BeaconPeriod = 100;
2012         pdev_network->Configuration.FHConfig.Length = 0;
2013         pdev_network->Configuration.FHConfig.HopPattern = 0;
2014         pdev_network->Configuration.FHConfig.HopSet = 0;
2015         pdev_network->Configuration.FHConfig.DwellTime = 0;
2016
2017 }
2018
2019 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
2020 {
2021         int sz = 0;
2022         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2023         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2024         struct  security_priv *psecuritypriv = &adapter->securitypriv;
2025         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
2026
2027         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0); /*  adhoc no 802.1x */
2028
2029         pdev_network->Rssi = 0;
2030
2031         switch (pregistrypriv->wireless_mode) {
2032         case WIRELESS_11B:
2033                 pdev_network->NetworkTypeInUse = (Ndis802_11DS);
2034                 break;
2035         case WIRELESS_11G:
2036         case WIRELESS_11BG:
2037         case WIRELESS_11_24N:
2038         case WIRELESS_11G_24N:
2039         case WIRELESS_11BG_24N:
2040                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2041                 break;
2042         case WIRELESS_11A:
2043         case WIRELESS_11A_5N:
2044                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2045                 break;
2046         case WIRELESS_11ABGN:
2047                 if (pregistrypriv->channel > 14)
2048                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2049                 else
2050                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2051                 break;
2052         default:
2053                 /*  TODO */
2054                 break;
2055         }
2056
2057         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
2058         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
2059                  ("pregistrypriv->channel=%d, pdev_network->Configuration.DSConfig=0x%x\n",
2060                  pregistrypriv->channel, pdev_network->Configuration.DSConfig));
2061
2062         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
2063                 pdev_network->Configuration.ATIMWindow = (0);
2064
2065         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
2066
2067         /*  1. Supported rates */
2068         /*  2. IE */
2069
2070         sz = rtw_generate_ie(pregistrypriv);
2071         pdev_network->IELength = sz;
2072         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
2073
2074         /* notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd(); */
2075         /* pdev_network->IELength = cpu_to_le32(sz); */
2076
2077 }
2078
2079 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
2080 {
2081
2082 }
2083
2084 /* the function is at passive_level */
2085 void rtw_joinbss_reset(struct adapter *padapter)
2086 {
2087         u8      threshold;
2088         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2089         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
2090
2091         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
2092         pmlmepriv->num_FortyMHzIntolerant = 0;
2093
2094         pmlmepriv->num_sta_no_ht = 0;
2095
2096         phtpriv->ampdu_enable = false;/* reset to disabled */
2097
2098         /*  TH = 1 => means that invalidate usb rx aggregation */
2099         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
2100         if (phtpriv->ht_option) {
2101                 if (padapter->registrypriv.wifi_spec == 1)
2102                         threshold = 1;
2103                 else
2104                         threshold = 0;
2105                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2106         } else {
2107                 threshold = 1;
2108                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2109         }
2110 }
2111
2112 /* the function is >= passive_level */
2113 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len)
2114 {
2115         u32 ielen, out_len;
2116         enum ht_cap_ampdu_factor max_rx_ampdu_factor;
2117         unsigned char *p;
2118         struct ieee80211_ht_cap ht_capie;
2119         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
2120         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2121         struct qos_priv         *pqospriv = &pmlmepriv->qospriv;
2122         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
2123         u32 rx_packet_offset, max_recvbuf_sz;
2124
2125         phtpriv->ht_option = false;
2126
2127         p = rtw_get_ie(in_ie+12, _HT_CAPABILITY_IE_, &ielen, in_len-12);
2128
2129         if (p && ielen > 0) {
2130                 if (pqospriv->qos_option == 0) {
2131                         out_len = *pout_len;
2132                         rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_,
2133                                    _WMM_IE_Length_, WMM_IE, pout_len);
2134
2135                         pqospriv->qos_option = 1;
2136                 }
2137
2138                 out_len = *pout_len;
2139
2140                 memset(&ht_capie, 0, sizeof(struct ieee80211_ht_cap));
2141
2142                 ht_capie.cap_info = cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH |
2143                                                 IEEE80211_HT_CAP_SGI_20 |
2144                                                 IEEE80211_HT_CAP_SGI_40 |
2145                                                 IEEE80211_HT_CAP_TX_STBC |
2146                                                 IEEE80211_HT_CAP_DSSSCCK40);
2147
2148                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
2149                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
2150
2151                 /*
2152                 AMPDU_para [1:0]:Max AMPDU Len => 0:8k , 1:16k, 2:32k, 3:64k
2153                 AMPDU_para [4:2]:Min MPDU Start Spacing
2154                 */
2155
2156                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor);
2157                 ht_capie.ampdu_params_info = (max_rx_ampdu_factor&0x03);
2158
2159                 if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
2160                         ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&(0x07<<2));
2161                 else
2162                         ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
2163
2164                 rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
2165                            sizeof(struct ieee80211_ht_cap), (unsigned char *)&ht_capie, pout_len);
2166
2167                 phtpriv->ht_option = true;
2168
2169                 p = rtw_get_ie(in_ie+12, _HT_ADD_INFO_IE_, &ielen, in_len-12);
2170                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2171                         out_len = *pout_len;
2172                         rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2, pout_len);
2173                 }
2174         }
2175         return phtpriv->ht_option;
2176 }
2177
2178 /* the function is > passive_level (in critical_section) */
2179 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len)
2180 {
2181         u8 *p, max_ampdu_sz;
2182         int len;
2183         struct ieee80211_ht_cap *pht_capie;
2184         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2185         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
2186         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2187         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
2188         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
2189
2190         if (!phtpriv->ht_option)
2191                 return;
2192
2193         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
2194                 return;
2195
2196         DBG_88E("+rtw_update_ht_cap()\n");
2197
2198         /* maybe needs check if ap supports rx ampdu. */
2199         if ((!phtpriv->ampdu_enable) && (pregistrypriv->ampdu_enable == 1)) {
2200                 if (pregistrypriv->wifi_spec == 1)
2201                         phtpriv->ampdu_enable = false;
2202                 else
2203                         phtpriv->ampdu_enable = true;
2204         } else if (pregistrypriv->ampdu_enable == 2) {
2205                 phtpriv->ampdu_enable = true;
2206         }
2207
2208         /* check Max Rx A-MPDU Size */
2209         len = 0;
2210         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fixed_ie), _HT_CAPABILITY_IE_, &len, ie_len-sizeof(struct ndis_802_11_fixed_ie));
2211         if (p && len > 0) {
2212                 pht_capie = (struct ieee80211_ht_cap *)(p+2);
2213                 max_ampdu_sz = (pht_capie->ampdu_params_info & IEEE80211_HT_CAP_AMPDU_FACTOR);
2214                 max_ampdu_sz = 1 << (max_ampdu_sz+3); /*  max_ampdu_sz (kbytes); */
2215                 phtpriv->rx_ampdu_maxlen = max_ampdu_sz;
2216         }
2217         len = 0;
2218         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fixed_ie), _HT_ADD_INFO_IE_, &len, ie_len-sizeof(struct ndis_802_11_fixed_ie));
2219
2220         /* update cur_bwmode & cur_ch_offset */
2221         if ((pregistrypriv->cbw40_enable) &&
2222             (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) & BIT(1)) &&
2223             (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
2224                 int i;
2225                 u8      rf_type;
2226
2227                 padapter->HalFunc.GetHwRegHandler(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2228
2229                 /* update the MCS rates */
2230                 for (i = 0; i < 16; i++) {
2231                         if ((rf_type == RF_1T1R) || (rf_type == RF_1T2R))
2232                                 pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= MCS_rate_1R[i];
2233                         else
2234                                 pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= MCS_rate_2R[i];
2235                 }
2236                 /* switch to the 40M Hz mode according to the AP */
2237                 pmlmeext->cur_bwmode = HT_CHANNEL_WIDTH_40;
2238                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
2239                 case HT_EXTCHNL_OFFSET_UPPER:
2240                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
2241                         break;
2242                 case HT_EXTCHNL_OFFSET_LOWER:
2243                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
2244                         break;
2245                 default:
2246                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
2247                         break;
2248                 }
2249         }
2250
2251         /*  Config SM Power Save setting */
2252         pmlmeinfo->SM_PS = (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) & 0x0C) >> 2;
2253         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
2254                 DBG_88E("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
2255
2256         /*  Config current HT Protection mode. */
2257         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
2258 }
2259
2260 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
2261 {
2262         u8 issued;
2263         int priority;
2264         struct sta_info *psta = NULL;
2265         struct ht_priv  *phtpriv;
2266         struct pkt_attrib *pattrib = &pxmitframe->attrib;
2267         s32 bmcst = IS_MCAST(pattrib->ra);
2268
2269         if (bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100))
2270                 return;
2271
2272         priority = pattrib->priority;
2273
2274         if (pattrib->psta)
2275                 psta = pattrib->psta;
2276         else
2277                 psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
2278
2279         if (psta == NULL)
2280                 return;
2281
2282         phtpriv = &psta->htpriv;
2283
2284         if ((phtpriv->ht_option) && (phtpriv->ampdu_enable)) {
2285                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
2286                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
2287
2288                 if (0 == issued) {
2289                         DBG_88E("rtw_issue_addbareq_cmd, p=%d\n", priority);
2290                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
2291                         rtw_addbareq_cmd(padapter, (u8) priority, pattrib->ra);
2292                 }
2293         }
2294 }
2295
2296 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2297 {
2298         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2299
2300         spin_lock_bh(&pmlmepriv->lock);
2301         _rtw_roaming(padapter, tgt_network);
2302         spin_unlock_bh(&pmlmepriv->lock);
2303 }
2304 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2305 {
2306         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2307         int do_join_r;
2308
2309         struct wlan_network *pnetwork;
2310
2311         if (tgt_network != NULL)
2312                 pnetwork = tgt_network;
2313         else
2314                 pnetwork = &pmlmepriv->cur_network;
2315
2316         if (0 < rtw_to_roaming(padapter)) {
2317                 DBG_88E("roaming from %s(%pM length:%d\n",
2318                         pnetwork->network.Ssid.Ssid, pnetwork->network.MacAddress,
2319                         pnetwork->network.Ssid.SsidLength);
2320                 memcpy(&pmlmepriv->assoc_ssid, &pnetwork->network.Ssid, sizeof(struct ndis_802_11_ssid));
2321
2322                 pmlmepriv->assoc_by_bssid = false;
2323
2324                 while (1) {
2325                         do_join_r = rtw_do_join(padapter);
2326                         if (_SUCCESS == do_join_r) {
2327                                 break;
2328                         } else {
2329                                 DBG_88E("roaming do_join return %d\n", do_join_r);
2330                                 pmlmepriv->to_roaming--;
2331
2332                                 if (0 < pmlmepriv->to_roaming) {
2333                                         continue;
2334                                 } else {
2335                                         DBG_88E("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
2336                                         rtw_indicate_disconnect(padapter);
2337                                         break;
2338                                 }
2339                         }
2340                 }
2341         }
2342 }