Linux 5.2-rc3
[platform/kernel/linux-starfive.git] / drivers / staging / rtl8188eu / core / rtw_mlme.c
1 // SPDX-License-Identifier: GPL-2.0
2 /******************************************************************************
3  *
4  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
5  *
6  ******************************************************************************/
7 #define _RTW_MLME_C_
8
9 #include <linux/ieee80211.h>
10
11 #include <osdep_service.h>
12 #include <drv_types.h>
13 #include <recv_osdep.h>
14 #include <xmit_osdep.h>
15 #include <hal_intf.h>
16 #include <mlme_osdep.h>
17 #include <sta_info.h>
18 #include <wifi.h>
19 #include <wlan_bssdef.h>
20 #include <rtw_ioctl_set.h>
21 #include <linux/vmalloc.h>
22
23 extern const u8 MCS_rate_1R[16];
24
25 int rtw_init_mlme_priv(struct adapter *padapter)
26 {
27         int i;
28         u8 *pbuf;
29         struct wlan_network *pnetwork;
30         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
31         int res = _SUCCESS;
32
33         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by vzalloc(). */
34
35         pmlmepriv->nic_hdl = (u8 *)padapter;
36
37         pmlmepriv->pscanned = NULL;
38         pmlmepriv->fw_state = 0;
39         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
40         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
41
42         spin_lock_init(&pmlmepriv->lock);
43         _rtw_init_queue(&pmlmepriv->free_bss_pool);
44         _rtw_init_queue(&pmlmepriv->scanned_queue);
45
46         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
47
48         pbuf = vzalloc(array_size(MAX_BSS_CNT, sizeof(struct wlan_network)));
49
50         if (!pbuf) {
51                 res = _FAIL;
52                 goto exit;
53         }
54         pmlmepriv->free_bss_buf = pbuf;
55
56         pnetwork = (struct wlan_network *)pbuf;
57
58         for (i = 0; i < MAX_BSS_CNT; i++) {
59                 INIT_LIST_HEAD(&pnetwork->list);
60
61                 list_add_tail(&pnetwork->list, &pmlmepriv->free_bss_pool.queue);
62
63                 pnetwork++;
64         }
65
66         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
67
68         rtw_clear_scan_deny(padapter);
69
70         rtw_init_mlme_timer(padapter);
71
72 exit:
73         return res;
74 }
75
76 #if defined(CONFIG_88EU_AP_MODE)
77 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
78 {
79         kfree(*ppie);
80         *plen = 0;
81         *ppie = NULL;
82 }
83
84 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
85 {
86         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
87         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
88         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
89         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
90         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
91         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
92 }
93 #else
94 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
95 {
96 }
97 #endif
98
99 void rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
100 {
101         if (pmlmepriv) {
102                 rtw_free_mlme_priv_ie_data(pmlmepriv);
103                 vfree(pmlmepriv->free_bss_buf);
104         }
105 }
106
107 struct wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)
108                                         /* _queue *free_queue) */
109 {
110         struct wlan_network *pnetwork;
111         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
112
113         spin_lock_bh(&free_queue->lock);
114         pnetwork = list_first_entry_or_null(&free_queue->queue,
115                                             struct wlan_network, list);
116         if (!pnetwork)
117                 goto exit;
118
119         list_del_init(&pnetwork->list);
120
121         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
122                  ("_rtw_alloc_network: ptr=%p\n", &pnetwork->list));
123         pnetwork->network_type = 0;
124         pnetwork->fixed = false;
125         pnetwork->last_scanned = jiffies;
126         pnetwork->aid = 0;
127         pnetwork->join_res = 0;
128
129 exit:
130         spin_unlock_bh(&free_queue->lock);
131
132         return pnetwork;
133 }
134
135 static void _rtw_free_network(struct mlme_priv *pmlmepriv, struct wlan_network *pnetwork, u8 isfreeall)
136 {
137         unsigned long curr_time;
138         u32 delta_time;
139         u32 lifetime = SCANQUEUE_LIFETIME;
140         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
141
142         if (!pnetwork)
143                 return;
144
145         if (pnetwork->fixed)
146                 return;
147         curr_time = jiffies;
148         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
149             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)))
150                 lifetime = 1;
151         if (!isfreeall) {
152                 delta_time = (curr_time - pnetwork->last_scanned)/HZ;
153                 if (delta_time < lifetime)/*  unit:sec */
154                         return;
155         }
156         spin_lock_bh(&free_queue->lock);
157         list_del_init(&pnetwork->list);
158         list_add_tail(&pnetwork->list, &free_queue->queue);
159         spin_unlock_bh(&free_queue->lock);
160 }
161
162 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
163 {
164         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
165
166         if (!pnetwork)
167                 return;
168         if (pnetwork->fixed)
169                 return;
170         list_del_init(&pnetwork->list);
171         list_add_tail(&pnetwork->list, get_list_head(free_queue));
172 }
173
174 /*
175  * return the wlan_network with the matching addr
176  *
177  * Shall be called under atomic context... to avoid possible racing condition...
178  */
179 struct wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
180 {
181         struct list_head *phead, *plist;
182         struct wlan_network *pnetwork = NULL;
183         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
184
185         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
186                 pnetwork = NULL;
187                 goto exit;
188         }
189         phead = get_list_head(scanned_queue);
190         plist = phead->next;
191
192         while (plist != phead) {
193                 pnetwork = container_of(plist, struct wlan_network, list);
194                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
195                         break;
196                 plist = plist->next;
197         }
198         if (plist == phead)
199                 pnetwork = NULL;
200 exit:
201         return pnetwork;
202 }
203
204 void rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
205 {
206         struct list_head *phead, *plist;
207         struct wlan_network *pnetwork;
208         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
209         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
210
211         spin_lock_bh(&scanned_queue->lock);
212
213         phead = get_list_head(scanned_queue);
214         plist = phead->next;
215
216         while (phead != plist) {
217                 pnetwork = container_of(plist, struct wlan_network, list);
218
219                 plist = plist->next;
220
221                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
222         }
223         spin_unlock_bh(&scanned_queue->lock);
224 }
225
226 int rtw_if_up(struct adapter *padapter)
227 {
228         int res;
229
230         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
231             !check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
232                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
233                          ("%s:bDriverStopped(%d) OR bSurpriseRemoved(%d)",
234                           __func__, padapter->bDriverStopped,
235                           padapter->bSurpriseRemoved));
236                 res = false;
237         } else {
238                 res =  true;
239         }
240         return res;
241 }
242
243 void rtw_generate_random_ibss(u8 *pibss)
244 {
245         unsigned long curtime = jiffies;
246
247         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
248         pibss[1] = 0x11;
249         pibss[2] = 0x87;
250         pibss[3] = (u8)(curtime & 0xff);/* p[0]; */
251         pibss[4] = (u8)((curtime>>8) & 0xff);/* p[1]; */
252         pibss[5] = (u8)((curtime>>16) & 0xff);/* p[2]; */
253 }
254
255 u8 *rtw_get_capability_from_ie(u8 *ie)
256 {
257         return ie + 8 + 2;
258 }
259
260 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
261 {
262         __le16 val;
263
264         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->ies), 2);
265
266         return le16_to_cpu(val);
267 }
268
269 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
270 {
271         return ie + 8;
272 }
273
274 static struct wlan_network *rtw_alloc_network(struct mlme_priv *pmlmepriv)
275 {
276         return _rtw_alloc_network(pmlmepriv);
277 }
278
279 static void rtw_free_network_nolock(struct mlme_priv *pmlmepriv,
280                                     struct wlan_network *pnetwork)
281 {
282         _rtw_free_network_nolock(pmlmepriv, pnetwork);
283 }
284
285 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
286 {
287         int ret = true;
288         struct security_priv *psecuritypriv = &adapter->securitypriv;
289
290         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
291             (pnetwork->network.Privacy == 0))
292                 ret = false;
293         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
294                  (pnetwork->network.Privacy == 1))
295                 ret = false;
296         else
297                 ret = true;
298         return ret;
299 }
300
301 static int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
302 {
303         return (a->ssid.ssid_length == b->ssid.ssid_length) &&
304                !memcmp(a->ssid.ssid, b->ssid.ssid, a->ssid.ssid_length);
305 }
306
307 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst)
308 {
309         u16 s_cap, d_cap;
310         __le16 le_scap, le_dcap;
311
312         memcpy((u8 *)&le_scap, rtw_get_capability_from_ie(src->ies), 2);
313         memcpy((u8 *)&le_dcap, rtw_get_capability_from_ie(dst->ies), 2);
314
315         s_cap = le16_to_cpu(le_scap);
316         d_cap = le16_to_cpu(le_dcap);
317
318         return ((src->ssid.ssid_length == dst->ssid.ssid_length) &&
319                 (!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN)) &&
320                 (!memcmp(src->ssid.ssid, dst->ssid.ssid, src->ssid.ssid_length)) &&
321                 ((s_cap & WLAN_CAPABILITY_IBSS) ==
322                 (d_cap & WLAN_CAPABILITY_IBSS)) &&
323                 ((s_cap & WLAN_CAPABILITY_ESS) ==
324                 (d_cap & WLAN_CAPABILITY_ESS)));
325 }
326
327 struct wlan_network *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
328 {
329         struct list_head *plist, *phead;
330         struct wlan_network *pwlan = NULL;
331         struct wlan_network *oldest = NULL;
332
333         phead = get_list_head(scanned_queue);
334
335         for (plist = phead->next; plist != phead; plist = plist->next) {
336                 pwlan = container_of(plist, struct wlan_network, list);
337
338                 if (!pwlan->fixed) {
339                         if (!oldest || time_after(oldest->last_scanned, pwlan->last_scanned))
340                                 oldest = pwlan;
341                 }
342         }
343         return oldest;
344 }
345
346 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
347         struct adapter *padapter, bool update_ie)
348 {
349         long rssi_ori = dst->Rssi;
350         u8 sq_smp = src->PhyInfo.SignalQuality;
351         u8 ss_final;
352         u8 sq_final;
353         long rssi_final;
354
355         rtw_hal_antdiv_rssi_compared(padapter, dst, src); /* this will update src.Rssi, need consider again */
356
357         /* The rule below is 1/5 for sample value, 4/5 for history value */
358         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) &&
359             is_same_network(&padapter->mlmepriv.cur_network.network, src)) {
360                 /* Take the recvpriv's value for the connected AP*/
361                 ss_final = padapter->recvpriv.signal_strength;
362                 sq_final = padapter->recvpriv.signal_qual;
363                 /* the rssi value here is undecorated, and will be used for antenna diversity */
364                 if (sq_smp != 101) /* from the right channel */
365                         rssi_final = (src->Rssi + dst->Rssi * 4) / 5;
366                 else
367                         rssi_final = rssi_ori;
368         } else {
369                 if (sq_smp != 101) { /* from the right channel */
370                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
371                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
372                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
373                 } else {
374                         /* bss info not receiving from the right channel, use the original RX signal infos */
375                         ss_final = dst->PhyInfo.SignalStrength;
376                         sq_final = dst->PhyInfo.SignalQuality;
377                         rssi_final = dst->Rssi;
378                 }
379         }
380         if (update_ie)
381                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
382         dst->PhyInfo.SignalStrength = ss_final;
383         dst->PhyInfo.SignalQuality = sq_final;
384         dst->Rssi = rssi_final;
385 }
386
387 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
388 {
389         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
390
391         if (check_fwstate(pmlmepriv, _FW_LINKED) &&
392             is_same_network(&pmlmepriv->cur_network.network, pnetwork)) {
393                 update_network(&pmlmepriv->cur_network.network, pnetwork, adapter, true);
394                 rtw_update_protection(adapter, (pmlmepriv->cur_network.network.ies) + sizeof(struct ndis_802_11_fixed_ie),
395                                       pmlmepriv->cur_network.network.ie_length);
396         }
397 }
398
399 /*
400  * Caller must hold pmlmepriv->lock first.
401  */
402 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
403 {
404         struct list_head *plist, *phead;
405         u32 bssid_ex_sz;
406         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
407         struct __queue *queue = &pmlmepriv->scanned_queue;
408         struct wlan_network *pnetwork = NULL;
409         struct wlan_network *oldest = NULL;
410
411         spin_lock_bh(&queue->lock);
412         phead = get_list_head(queue);
413         plist = phead->next;
414
415         while (phead != plist) {
416                 pnetwork = container_of(plist, struct wlan_network, list);
417
418                 if (is_same_network(&pnetwork->network, target))
419                         break;
420                 if ((oldest == ((struct wlan_network *)0)) ||
421                     time_after(oldest->last_scanned, pnetwork->last_scanned))
422                         oldest = pnetwork;
423                 plist = plist->next;
424         }
425         /* If we didn't find a match, then get a new network slot to initialize
426          * with this beacon's information
427          */
428         if (phead == plist) {
429                 if (list_empty(&pmlmepriv->free_bss_pool.queue)) {
430                         /* If there are no more slots, expire the oldest */
431                         pnetwork = oldest;
432
433                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA,
434                                             &target->PhyInfo.Optimum_antenna);
435                         memcpy(&pnetwork->network, target,
436                                get_wlan_bssid_ex_sz(target));
437                         /*  variable initialize */
438                         pnetwork->fixed = false;
439                         pnetwork->last_scanned = jiffies;
440
441                         pnetwork->network_type = 0;
442                         pnetwork->aid = 0;
443                         pnetwork->join_res = 0;
444
445                         /* bss info not receiving from the right channel */
446                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
447                                 pnetwork->network.PhyInfo.SignalQuality = 0;
448                 } else {
449                         /* Otherwise just pull from the free list */
450
451                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
452
453                         if (!pnetwork) {
454                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
455                                          ("\n\n\nsomething wrong here\n\n\n"));
456                                 goto exit;
457                         }
458
459                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
460                         target->Length = bssid_ex_sz;
461                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA,
462                                             &target->PhyInfo.Optimum_antenna);
463                         memcpy(&pnetwork->network, target, bssid_ex_sz);
464
465                         pnetwork->last_scanned = jiffies;
466
467                         /* bss info not receiving from the right channel */
468                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
469                                 pnetwork->network.PhyInfo.SignalQuality = 0;
470                         list_add_tail(&pnetwork->list, &queue->queue);
471                 }
472         } else {
473                 /* we have an entry and we are going to update it. But this
474                  * entry may be already expired. In this case we do the same
475                  * as we found a new net and call the new_net handler
476                  */
477                 bool update_ie = true;
478
479                 pnetwork->last_scanned = jiffies;
480
481                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
482                 if ((pnetwork->network.ie_length > target->ie_length) && (target->Reserved[0] == 1))
483                         update_ie = false;
484
485                 update_network(&pnetwork->network, target, adapter, update_ie);
486         }
487
488 exit:
489         spin_unlock_bh(&queue->lock);
490 }
491
492 static void rtw_add_network(struct adapter *adapter,
493                             struct wlan_bssid_ex *pnetwork)
494 {
495         update_current_network(adapter, pnetwork);
496         rtw_update_scanned_network(adapter, pnetwork);
497 }
498
499 /*
500  * select the desired network based on the capability of the (i)bss.
501  * check items: (1) security
502  *                      (2) network_type
503  *                      (3) WMM
504  *                      (4) HT
505  *                      (5) others
506  */
507 static int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
508 {
509         struct security_priv *psecuritypriv = &adapter->securitypriv;
510         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
511         u32 desired_encmode;
512         u32 privacy;
513
514         /* u8 wps_ie[512]; */
515         uint wps_ielen;
516
517         int bselected = true;
518
519         desired_encmode = psecuritypriv->ndisencryptstatus;
520         privacy = pnetwork->network.Privacy;
521
522         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
523                 if (rtw_get_wps_ie(pnetwork->network.ies+_FIXED_IE_LENGTH_, pnetwork->network.ie_length-_FIXED_IE_LENGTH_, NULL, &wps_ielen))
524                         return true;
525                 else
526                         return false;
527         }
528         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
529                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
530                         bselected = false;
531         }
532
533         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
534                 DBG_88E("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
535                 bselected = false;
536         }
537
538         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
539                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
540                         bselected = false;
541         }
542
543         return bselected;
544 }
545
546 /* TODO: Perry: For Power Management */
547 void rtw_atimdone_event_callback(struct adapter *adapter, u8 *pbuf)
548 {
549         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_event\n"));
550 }
551
552 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
553 {
554         u32 len;
555         struct wlan_bssid_ex *pnetwork;
556         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
557
558         pnetwork = (struct wlan_bssid_ex *)pbuf;
559
560         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
561                  ("%s, ssid=%s\n", __func__, pnetwork->ssid.ssid));
562
563         len = get_wlan_bssid_ex_sz(pnetwork);
564         if (len > (sizeof(struct wlan_bssid_ex))) {
565                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
566                          ("\n****%s: return a wrong bss ***\n", __func__));
567                 return;
568         }
569         spin_lock_bh(&pmlmepriv->lock);
570
571         /*  update IBSS_network 's timestamp */
572         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) {
573                 if (!memcmp(&pmlmepriv->cur_network.network.MacAddress, pnetwork->MacAddress, ETH_ALEN)) {
574                         struct wlan_network *ibss_wlan = NULL;
575
576                         memcpy(pmlmepriv->cur_network.network.ies, pnetwork->ies, 8);
577                         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
578                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
579                         if (ibss_wlan) {
580                                 memcpy(ibss_wlan->network.ies, pnetwork->ies, 8);
581                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
582                                 goto exit;
583                         }
584                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
585                 }
586         }
587
588         /*  lock pmlmepriv->lock when you accessing network_q */
589         if (!check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
590                 if (pnetwork->ssid.ssid[0] == 0)
591                         pnetwork->ssid.ssid_length = 0;
592                 rtw_add_network(adapter, pnetwork);
593         }
594
595 exit:
596         spin_unlock_bh(&pmlmepriv->lock);
597 }
598
599 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
600 {
601         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
602
603         spin_lock_bh(&pmlmepriv->lock);
604
605         if (pmlmepriv->wps_probe_req_ie) {
606                 pmlmepriv->wps_probe_req_ie_len = 0;
607                 kfree(pmlmepriv->wps_probe_req_ie);
608                 pmlmepriv->wps_probe_req_ie = NULL;
609         }
610
611         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
612                  ("%s: fw_state:%x\n\n", __func__, get_fwstate(pmlmepriv)));
613
614         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
615                 del_timer_sync(&pmlmepriv->scan_to_timer);
616                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
617         } else {
618                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status=%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
619         }
620
621         rtw_set_signal_stat_timer(&adapter->recvpriv);
622
623         if (pmlmepriv->to_join) {
624                 if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
625                         if (!check_fwstate(pmlmepriv, _FW_LINKED)) {
626                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
627
628                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
629                                         mod_timer(&pmlmepriv->assoc_timer,
630                                                   jiffies + msecs_to_jiffies(MAX_JOIN_TIMEOUT));
631                                 } else {
632                                         struct wlan_bssid_ex *pdev_network = &adapter->registrypriv.dev_network;
633                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
634
635                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
636
637                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
638
639                                         memcpy(&pdev_network->ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
640
641                                         rtw_update_registrypriv_dev_network(adapter);
642                                         rtw_generate_random_ibss(pibss);
643
644                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
645
646                                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
647                                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error=>rtw_createbss_cmd status FAIL\n"));
648                                         pmlmepriv->to_join = false;
649                                 }
650                         }
651                 } else {
652                         int s_ret;
653
654                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
655                         pmlmepriv->to_join = false;
656                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
657                         if (s_ret == _SUCCESS) {
658                                 mod_timer(&pmlmepriv->assoc_timer,
659                                         jiffies + msecs_to_jiffies(MAX_JOIN_TIMEOUT));
660                         } else if (s_ret == 2) { /* there is no need to wait for join */
661                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
662                                 rtw_indicate_connect(adapter);
663                         } else {
664                                 DBG_88E("try_to_join, but select scanning queue fail, to_roaming:%d\n", pmlmepriv->to_roaming);
665                                 if (pmlmepriv->to_roaming != 0) {
666                                         if (--pmlmepriv->to_roaming == 0 ||
667                                             rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0) != _SUCCESS) {
668                                                 pmlmepriv->to_roaming = 0;
669                                                 rtw_free_assoc_resources(adapter);
670                                                 rtw_indicate_disconnect(adapter);
671                                         } else {
672                                                 pmlmepriv->to_join = true;
673                                         }
674                                 }
675                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
676                         }
677                 }
678         }
679
680         indicate_wx_scan_complete_event(adapter);
681
682         spin_unlock_bh(&pmlmepriv->lock);
683
684         rtw_os_xmit_schedule(adapter);
685 }
686
687 void rtw_dummy_event_callback(struct adapter *adapter, u8 *pbuf)
688 {
689 }
690
691 void rtw_fwdbg_event_callback(struct adapter *adapter, u8 *pbuf)
692 {
693 }
694
695 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
696 {
697         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
698         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
699         struct list_head *plist, *phead, *ptemp;
700
701         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+%s\n", __func__));
702         spin_lock_bh(&scan_queue->lock);
703         spin_lock_bh(&free_queue->lock);
704
705         phead = get_list_head(scan_queue);
706         plist = phead->next;
707
708         while (plist != phead) {
709                 ptemp = plist->next;
710                 list_del_init(plist);
711                 list_add_tail(plist, &free_queue->queue);
712                 plist = ptemp;
713         }
714
715         spin_unlock_bh(&free_queue->lock);
716         spin_unlock_bh(&scan_queue->lock);
717 }
718
719 /*
720  * rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
721  */
722 void rtw_free_assoc_resources(struct adapter *adapter)
723 {
724         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
725
726         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
727         rtw_free_assoc_resources_locked(adapter);
728         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
729 }
730
731 /*
732  * rtw_free_assoc_resources_locked: the caller has to lock pmlmepriv->lock
733  */
734 void rtw_free_assoc_resources_locked(struct adapter *adapter)
735 {
736         struct wlan_network *pwlan = NULL;
737         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
738         struct sta_priv *pstapriv = &adapter->stapriv;
739         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
740
741         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
742         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
743                  ("tgt_network->network.MacAddress=%pM ssid=%s\n",
744                  tgt_network->network.MacAddress, tgt_network->network.ssid.ssid));
745
746         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_AP_STATE)) {
747                 struct sta_info *psta;
748
749                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
750
751                 spin_lock_bh(&pstapriv->sta_hash_lock);
752                 rtw_free_stainfo(adapter,  psta);
753                 spin_unlock_bh(&pstapriv->sta_hash_lock);
754         }
755
756         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE | WIFI_ADHOC_MASTER_STATE | WIFI_AP_STATE)) {
757                 struct sta_info *psta;
758
759                 rtw_free_all_stainfo(adapter);
760
761                 psta = rtw_get_bcmc_stainfo(adapter);
762                 spin_lock_bh(&pstapriv->sta_hash_lock);
763                 rtw_free_stainfo(adapter, psta);
764                 spin_unlock_bh(&pstapriv->sta_hash_lock);
765
766                 rtw_init_bcmc_stainfo(adapter);
767         }
768
769         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
770         if (pwlan)
771                 pwlan->fixed = false;
772         else
773                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources:pwlan==NULL\n\n"));
774
775         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) && (adapter->stapriv.asoc_sta_count == 1)))
776                 rtw_free_network_nolock(pmlmepriv, pwlan);
777
778         pmlmepriv->key_mask = 0;
779 }
780
781 /*
782  * rtw_indicate_connect: the caller has to lock pmlmepriv->lock
783  */
784 void rtw_indicate_connect(struct adapter *padapter)
785 {
786         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
787
788         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+%s\n", __func__));
789
790         pmlmepriv->to_join = false;
791
792         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
793                 set_fwstate(pmlmepriv, _FW_LINKED);
794
795                 led_control_8188eu(padapter, LED_CTL_LINK);
796
797                 rtw_os_indicate_connect(padapter);
798         }
799
800         pmlmepriv->to_roaming = 0;
801
802         rtw_set_scan_deny(padapter, 3000);
803
804         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-%s: fw_state=0x%08x\n", __func__, get_fwstate(pmlmepriv)));
805 }
806
807 /*
808  * rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
809  */
810 void rtw_indicate_disconnect(struct adapter *padapter)
811 {
812         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
813
814         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+%s\n", __func__));
815
816         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING | WIFI_UNDER_WPS);
817
818         if (pmlmepriv->to_roaming > 0)
819                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
820
821         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) ||
822             (pmlmepriv->to_roaming <= 0)) {
823                 rtw_os_indicate_disconnect(padapter);
824
825                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
826                 led_control_8188eu(padapter, LED_CTL_NO_LINK);
827                 rtw_clear_scan_deny(padapter);
828         }
829
830         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
831 }
832
833 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
834 {
835         rtw_os_indicate_scan_done(padapter, aborted);
836 }
837
838 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
839 {
840         int i;
841         struct sta_info *bmc_sta, *psta = NULL;
842         struct recv_reorder_ctrl *preorder_ctrl;
843         struct sta_priv *pstapriv = &padapter->stapriv;
844
845         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
846         if (!psta)
847                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
848
849         if (psta) { /* update ptarget_sta */
850                 DBG_88E("%s\n", __func__);
851                 psta->aid  = pnetwork->join_res;
852                 psta->mac_id = 0;
853                 /* sta mode */
854                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
855                 /* security related */
856                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
857                         padapter->securitypriv.binstallGrpkey = false;
858                         padapter->securitypriv.busetkipkey = false;
859                         padapter->securitypriv.bgrpkey_handshake = false;
860                         psta->ieee8021x_blocked = true;
861                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
862                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
863                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
864                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
865                         memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
866                         memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
867                 }
868                 /*
869                  * Commented by Albert 2012/07/21
870                  * When doing the WPS, the wps_ie_len won't equal to 0
871                  * And the Wi-Fi driver shouldn't allow the data
872                  * packet to be transmitted.
873                  */
874                 if (padapter->securitypriv.wps_ie_len != 0) {
875                         psta->ieee8021x_blocked = true;
876                         padapter->securitypriv.wps_ie_len = 0;
877                 }
878                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
879                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
880                 /* todo: check if AP can send A-MPDU packets */
881                 for (i = 0; i < 16; i++) {
882                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
883                         preorder_ctrl = &psta->recvreorder_ctrl[i];
884                         preorder_ctrl->enable = false;
885                         preorder_ctrl->indicate_seq = 0xffff;
886                         preorder_ctrl->wend_b = 0xffff;
887                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
888                 }
889                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
890                 if (bmc_sta) {
891                         for (i = 0; i < 16; i++) {
892                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
893                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
894                                 preorder_ctrl->enable = false;
895                                 preorder_ctrl->indicate_seq = 0xffff;
896                                 preorder_ctrl->wend_b = 0xffff;
897                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
898                         }
899                 }
900                 /* misc. */
901                 update_sta_info(padapter, psta);
902         }
903         return psta;
904 }
905
906 /* pnetwork: returns from rtw_joinbss_event_callback */
907 /* ptarget_wlan: found from scanned_queue */
908 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
909 {
910         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
911         struct wlan_network *cur_network = &pmlmepriv->cur_network;
912
913         DBG_88E("%s\n", __func__);
914
915         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
916                  ("\nfw_state:%x, BSSID:%pM\n",
917                  get_fwstate(pmlmepriv), pnetwork->network.MacAddress));
918
919         /*  why not use ptarget_wlan?? */
920         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
921         /*  some ies in pnetwork is wrong, so we should use ptarget_wlan ies */
922         cur_network->network.ie_length = ptarget_wlan->network.ie_length;
923         memcpy(&cur_network->network.ies[0], &ptarget_wlan->network.ies[0], MAX_IE_SZ);
924
925         cur_network->aid = pnetwork->join_res;
926
927         rtw_set_signal_stat_timer(&padapter->recvpriv);
928         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
929         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
930         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
931         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
932         rtw_set_signal_stat_timer(&padapter->recvpriv);
933
934         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
935         switch (pnetwork->network.InfrastructureMode) {
936         case Ndis802_11Infrastructure:
937                 if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
938                         pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
939                 else
940                         pmlmepriv->fw_state = WIFI_STATION_STATE;
941                 break;
942         case Ndis802_11IBSS:
943                 pmlmepriv->fw_state = WIFI_ADHOC_STATE;
944                 break;
945         default:
946                 pmlmepriv->fw_state = WIFI_NULL_STATE;
947                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
948                 break;
949         }
950
951         rtw_update_protection(padapter, (cur_network->network.ies) +
952                               sizeof(struct ndis_802_11_fixed_ie),
953                               (cur_network->network.ie_length));
954         rtw_update_ht_cap(padapter, cur_network->network.ies, cur_network->network.ie_length);
955 }
956
957 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
958 /* pnetwork: returns from rtw_joinbss_event_callback */
959 /* ptarget_wlan: found from scanned_queue */
960 /* if join_res > 0, for (fw_state == WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
961 /* if join_res > 0, for (fw_state == WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
962 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
963
964 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
965 {
966         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
967         struct sta_priv *pstapriv = &adapter->stapriv;
968         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
969         struct wlan_network *pnetwork = (struct wlan_network *)pbuf;
970         struct wlan_network *cur_network = &pmlmepriv->cur_network;
971         struct wlan_network *pcur_wlan = NULL, *ptarget_wlan = NULL;
972         unsigned int the_same_macaddr = false;
973
974         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res=%d\n", pnetwork->join_res));
975
976         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
977
978         if (pmlmepriv->assoc_ssid.ssid_length == 0)
979                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
980         else
981                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.ssid));
982
983         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
984
985         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
986         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
987                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
988                 return;
989         }
990
991         spin_lock_bh(&pmlmepriv->lock);
992
993         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nrtw_joinbss_event_callback!! _enter_critical\n"));
994
995         if (pnetwork->join_res > 0) {
996                 spin_lock_bh(&pmlmepriv->scanned_queue.lock);
997                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
998                         /* s1. find ptarget_wlan */
999                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1000                                 if (the_same_macaddr) {
1001                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1002                                 } else {
1003                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1004                                         if (pcur_wlan)
1005                                                 pcur_wlan->fixed = false;
1006
1007                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1008                                         if (pcur_sta) {
1009                                                 spin_lock_bh(&pstapriv->sta_hash_lock);
1010                                                 rtw_free_stainfo(adapter,  pcur_sta);
1011                                                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1012                                         }
1013
1014                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1015                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1016                                                 if (ptarget_wlan)
1017                                                         ptarget_wlan->fixed = true;
1018                                         }
1019                                 }
1020                         } else {
1021                                 ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1022                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1023                                         if (ptarget_wlan)
1024                                                 ptarget_wlan->fixed = true;
1025                                 }
1026                         }
1027
1028                         /* s2. update cur_network */
1029                         if (ptarget_wlan) {
1030                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1031                         } else {
1032                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't find ptarget_wlan when joinbss_event callback\n"));
1033                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1034                                 goto ignore_joinbss_callback;
1035                         }
1036
1037                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1038                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1039                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1040                                 if (!ptarget_sta) {
1041                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1042                                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1043                                         goto ignore_joinbss_callback;
1044                                 }
1045                         }
1046
1047                         /* s4. indicate connect */
1048                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1049                                 rtw_indicate_connect(adapter);
1050                         } else {
1051                                 /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1052                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1053                         }
1054
1055                         /* s5. Cancel assoc_timer */
1056                         del_timer_sync(&pmlmepriv->assoc_timer);
1057
1058                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancel assoc_timer\n"));
1059
1060                 } else {
1061                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1062                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1063                         goto ignore_joinbss_callback;
1064                 }
1065
1066                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1067
1068         } else if (pnetwork->join_res == -4) {
1069                 rtw_reset_securitypriv(adapter);
1070                 mod_timer(&pmlmepriv->assoc_timer,
1071                           jiffies + msecs_to_jiffies(1));
1072
1073                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1074                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state=%x\n", get_fwstate(pmlmepriv)));
1075                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1076                 }
1077         } else { /* if join_res < 0 (join fails), then try again */
1078                 mod_timer(&pmlmepriv->assoc_timer,
1079                           jiffies + msecs_to_jiffies(1));
1080                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1081         }
1082
1083 ignore_joinbss_callback:
1084         spin_unlock_bh(&pmlmepriv->lock);
1085 }
1086
1087 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1088 {
1089         struct wlan_network *pnetwork = (struct wlan_network *)pbuf;
1090
1091         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1092
1093         rtw_os_xmit_schedule(adapter);
1094 }
1095
1096 static u8 search_max_mac_id(struct adapter *padapter)
1097 {
1098         u8 mac_id;
1099 #if defined(CONFIG_88EU_AP_MODE)
1100         u8 aid;
1101         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1102         struct sta_priv *pstapriv = &padapter->stapriv;
1103 #endif
1104         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1105         struct mlme_ext_info *pmlmeinfo = &pmlmeext->mlmext_info;
1106
1107 #if defined(CONFIG_88EU_AP_MODE)
1108         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1109                 for (aid = pstapriv->max_num_sta; aid > 0; aid--) {
1110                         if (pstapriv->sta_aid[aid-1])
1111                                 break;
1112                 }
1113                 mac_id = aid + 1;
1114         } else
1115 #endif
1116         {/* adhoc  id =  31~2 */
1117                 for (mac_id = NUM_STA-1; mac_id >= IBSS_START_MAC_ID; mac_id--) {
1118                         if (pmlmeinfo->FW_sta_info[mac_id].status == 1)
1119                                 break;
1120                 }
1121         }
1122         return mac_id;
1123 }
1124
1125 /* FOR AP , AD-HOC mode */
1126 void rtw_stassoc_hw_rpt(struct adapter *adapter, struct sta_info *psta)
1127 {
1128         u16 media_status;
1129         u8 macid;
1130
1131         if (!psta)
1132                 return;
1133
1134         macid = search_max_mac_id(adapter);
1135         rtw_hal_set_hwreg(adapter, HW_VAR_TX_RPT_MAX_MACID, (u8 *)&macid);
1136         media_status = (psta->mac_id<<8)|1; /*   MACID|OPMODE:1 connect */
1137         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1138 }
1139
1140 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1141 {
1142         struct sta_info *psta;
1143         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1144         struct stassoc_event *pstassoc = (struct stassoc_event *)pbuf;
1145         struct wlan_network *cur_network = &pmlmepriv->cur_network;
1146         struct wlan_network *ptarget_wlan = NULL;
1147
1148         if (!rtw_access_ctrl(adapter, pstassoc->macaddr))
1149                 return;
1150
1151 #if defined(CONFIG_88EU_AP_MODE)
1152         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1153                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1154                 if (psta) {
1155                         ap_sta_info_defer_update(adapter, psta);
1156                         rtw_stassoc_hw_rpt(adapter, psta);
1157                 }
1158                 return;
1159         }
1160 #endif
1161         /* for AD-HOC mode */
1162         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1163         if (psta) {
1164                 /* the sta have been in sta_info_queue => do nothing */
1165                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1166                          ("Error: %s: sta has been in sta_hash_queue\n",
1167                           __func__));
1168                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1169         }
1170         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1171         if (!psta) {
1172                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1173                          ("Can't alloc sta_info when %s\n", __func__));
1174                 return;
1175         }
1176         /* to do: init sta_info variable */
1177         psta->qos_option = 0;
1178         psta->mac_id = (uint)pstassoc->cam_id;
1179         DBG_88E("%s\n", __func__);
1180         /* for ad-hoc mode */
1181         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1182         rtw_stassoc_hw_rpt(adapter, psta);
1183         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1184                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1185         psta->ieee8021x_blocked = false;
1186         spin_lock_bh(&pmlmepriv->lock);
1187         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
1188             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE))) {
1189                 if (adapter->stapriv.asoc_sta_count == 2) {
1190                         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1191                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1192                         if (ptarget_wlan)
1193                                 ptarget_wlan->fixed = true;
1194                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1195                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1196                         rtw_indicate_connect(adapter);
1197                 }
1198         }
1199         spin_unlock_bh(&pmlmepriv->lock);
1200         mlmeext_sta_add_event_callback(adapter, psta);
1201 }
1202
1203 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1204 {
1205         int mac_id = -1;
1206         struct sta_info *psta;
1207         struct wlan_network *pwlan = NULL;
1208         struct wlan_bssid_ex *pdev_network = NULL;
1209         u8 *pibss = NULL;
1210         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1211         struct stadel_event *pstadel = (struct stadel_event *)pbuf;
1212         struct sta_priv *pstapriv = &adapter->stapriv;
1213         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1214
1215         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1216         if (psta)
1217                 mac_id = psta->mac_id;
1218         else
1219                 mac_id = pstadel->mac_id;
1220
1221         DBG_88E("%s(mac_id=%d)=%pM\n", __func__, mac_id, pstadel->macaddr);
1222
1223         if (mac_id >= 0) {
1224                 u16 media_status;
1225
1226                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1227                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1228                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1229         }
1230
1231         if (check_fwstate(pmlmepriv, WIFI_AP_STATE))
1232                 return;
1233
1234         mlmeext_sta_del_event_callback(adapter);
1235
1236         spin_lock_bh(&pmlmepriv->lock);
1237
1238         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1239                 if (pmlmepriv->to_roaming > 0)
1240                         pmlmepriv->to_roaming--; /*  this stadel_event is caused by roaming, decrease to_roaming */
1241                 else if (pmlmepriv->to_roaming == 0)
1242                         pmlmepriv->to_roaming = adapter->registrypriv.max_roaming_times;
1243
1244                 if (*((unsigned short *)(pstadel->rsvd)) != WLAN_REASON_EXPIRATION_CHK)
1245                         pmlmepriv->to_roaming = 0; /*  don't roam */
1246
1247                 rtw_free_uc_swdec_pending_queue(adapter);
1248
1249                 rtw_free_assoc_resources(adapter);
1250                 rtw_indicate_disconnect(adapter);
1251                 spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1252                 /*  remove the network entry in scanned_queue */
1253                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1254                 if (pwlan) {
1255                         pwlan->fixed = false;
1256                         rtw_free_network_nolock(pmlmepriv, pwlan);
1257                 }
1258                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1259                 _rtw_roaming(adapter, tgt_network);
1260         }
1261         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1262             check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1263                 spin_lock_bh(&pstapriv->sta_hash_lock);
1264                 rtw_free_stainfo(adapter,  psta);
1265                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1266
1267                 if (adapter->stapriv.asoc_sta_count == 1) { /* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1268                         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1269                         /* free old ibss network */
1270                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1271                         if (pwlan) {
1272                                 pwlan->fixed = false;
1273                                 rtw_free_network_nolock(pmlmepriv, pwlan);
1274                         }
1275                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1276                         /* re-create ibss */
1277                         pdev_network = &adapter->registrypriv.dev_network;
1278                         pibss = adapter->registrypriv.dev_network.MacAddress;
1279
1280                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1281
1282                         memcpy(&pdev_network->ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1283
1284                         rtw_update_registrypriv_dev_network(adapter);
1285
1286                         rtw_generate_random_ibss(pibss);
1287
1288                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1289                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1290                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1291                         }
1292
1293                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
1294                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error=>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1295                 }
1296         }
1297         spin_unlock_bh(&pmlmepriv->lock);
1298 }
1299
1300 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1301 {
1302         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+%s !!!\n", __func__));
1303 }
1304
1305 /*
1306  * _rtw_join_timeout_handler - Timeout/failure handler for CMD JoinBss
1307  * @adapter: pointer to struct adapter structure
1308  */
1309 void _rtw_join_timeout_handler (struct timer_list *t)
1310 {
1311         struct adapter *adapter = from_timer(adapter, t, mlmepriv.assoc_timer);
1312         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1313         int do_join_r;
1314
1315         DBG_88E("%s, fw_state=%x\n", __func__, get_fwstate(pmlmepriv));
1316
1317         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1318                 return;
1319
1320         spin_lock_bh(&pmlmepriv->lock);
1321
1322         if (pmlmepriv->to_roaming > 0) { /*  join timeout caused by roaming */
1323                 while (1) {
1324                         pmlmepriv->to_roaming--;
1325                         if (pmlmepriv->to_roaming != 0) { /* try another , */
1326                                 DBG_88E("%s try another roaming\n", __func__);
1327                                 do_join_r = rtw_do_join(adapter);
1328                                 if (do_join_r != _SUCCESS) {
1329                                         DBG_88E("%s roaming do_join return %d\n", __func__, do_join_r);
1330                                         continue;
1331                                 }
1332                                 break;
1333                         } else {
1334                                 DBG_88E("%s We've try roaming but fail\n", __func__);
1335                                 rtw_indicate_disconnect(adapter);
1336                                 break;
1337                         }
1338                 }
1339         } else {
1340                 rtw_indicate_disconnect(adapter);
1341                 free_scanqueue(pmlmepriv);/*  */
1342         }
1343         spin_unlock_bh(&pmlmepriv->lock);
1344 }
1345
1346 /*
1347  * rtw_scan_timeout_handler - Timeout/Failure handler for CMD SiteSurvey
1348  * @adapter: pointer to struct adapter structure
1349  */
1350 void rtw_scan_timeout_handler (struct timer_list *t)
1351 {
1352         struct adapter *adapter = from_timer(adapter, t,
1353                                              mlmepriv.scan_to_timer);
1354         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1355
1356         DBG_88E(FUNC_ADPT_FMT" fw_state=%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1357         spin_lock_bh(&pmlmepriv->lock);
1358         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1359         spin_unlock_bh(&pmlmepriv->lock);
1360         rtw_indicate_scan_done(adapter, true);
1361 }
1362
1363 static void rtw_auto_scan_handler(struct adapter *padapter)
1364 {
1365         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1366
1367         /* auto site survey per 60sec */
1368         if (pmlmepriv->scan_interval > 0) {
1369                 pmlmepriv->scan_interval--;
1370                 if (pmlmepriv->scan_interval == 0) {
1371                         DBG_88E("%s\n", __func__);
1372                         rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1373                         pmlmepriv->scan_interval = SCAN_INTERVAL;/*  30*2 sec = 60sec */
1374                 }
1375         }
1376 }
1377
1378 void rtw_dynamic_check_timer_handlder(struct timer_list *t)
1379 {
1380         struct adapter *adapter = from_timer(adapter, t,
1381                                              mlmepriv.dynamic_chk_timer);
1382         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1383
1384         if (!adapter)
1385                 return;
1386         if (!adapter->hw_init_completed)
1387                 goto exit;
1388         if ((adapter->bDriverStopped) || (adapter->bSurpriseRemoved))
1389                 goto exit;
1390         if (adapter->net_closed)
1391                 goto exit;
1392         rtw_dynamic_chk_wk_cmd(adapter);
1393
1394         if (pregistrypriv->wifi_spec == 1) {
1395                 /* auto site survey */
1396                 rtw_auto_scan_handler(adapter);
1397         }
1398 exit:
1399         mod_timer(&adapter->mlmepriv.dynamic_chk_timer,
1400                   jiffies + msecs_to_jiffies(2000));
1401 }
1402
1403 #define RTW_SCAN_RESULT_EXPIRE 2000
1404
1405 /*
1406  * Select a new join candidate from the original @param candidate and @param competitor
1407  * @return true: candidate is updated
1408  * @return false: candidate is not updated
1409  */
1410 static int rtw_check_join_candidate(struct mlme_priv *pmlmepriv
1411         , struct wlan_network **candidate, struct wlan_network *competitor)
1412 {
1413         int updated = false;
1414         unsigned long since_scan;
1415         struct adapter *adapter = container_of(pmlmepriv, struct adapter,
1416                                                mlmepriv);
1417
1418         /* check bssid, if needed */
1419         if (pmlmepriv->assoc_by_bssid) {
1420                 if (memcmp(competitor->network.MacAddress, pmlmepriv->assoc_bssid, ETH_ALEN))
1421                         goto exit;
1422         }
1423
1424         /* check ssid, if needed */
1425         if (pmlmepriv->assoc_ssid.ssid_length) {
1426                 if (competitor->network.ssid.ssid_length != pmlmepriv->assoc_ssid.ssid_length ||
1427                     memcmp(competitor->network.ssid.ssid, pmlmepriv->assoc_ssid.ssid, pmlmepriv->assoc_ssid.ssid_length))
1428                         goto exit;
1429         }
1430
1431         if (!rtw_is_desired_network(adapter, competitor))
1432                 goto exit;
1433
1434         if (pmlmepriv->to_roaming) {
1435                 since_scan = jiffies - competitor->last_scanned;
1436                 if (jiffies_to_msecs(since_scan) >= RTW_SCAN_RESULT_EXPIRE ||
1437                     !is_same_ess(&competitor->network, &pmlmepriv->cur_network.network))
1438                         goto exit;
1439         }
1440
1441         if (!*candidate || (*candidate)->network.Rssi < competitor->network.Rssi) {
1442                 *candidate = competitor;
1443                 updated = true;
1444         }
1445         if (updated) {
1446                 DBG_88E("[by_bssid:%u][assoc_ssid:%s]new candidate: %s(%pM rssi:%d\n",
1447                         pmlmepriv->assoc_by_bssid,
1448                         pmlmepriv->assoc_ssid.ssid,
1449                         (*candidate)->network.ssid.ssid,
1450                         (*candidate)->network.MacAddress,
1451                         (int)(*candidate)->network.Rssi);
1452                 DBG_88E("[to_roaming:%u]\n", pmlmepriv->to_roaming);
1453         }
1454
1455 exit:
1456         return updated;
1457 }
1458
1459 /*
1460  * Calling context:
1461  * The caller of the sub-routine will be in critical section...
1462  * The caller must hold the following spinlock
1463  * pmlmepriv->lock
1464  */
1465
1466 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
1467 {
1468         int ret;
1469         struct list_head *phead;
1470         struct adapter *adapter;
1471         struct __queue *queue = &pmlmepriv->scanned_queue;
1472         struct wlan_network *pnetwork = NULL;
1473         struct wlan_network *candidate = NULL;
1474         u8 supp_ant_div = false;
1475
1476         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1477         phead = get_list_head(queue);
1478         adapter = (struct adapter *)pmlmepriv->nic_hdl;
1479         pmlmepriv->pscanned = phead->next;
1480         while (phead != pmlmepriv->pscanned) {
1481                 pnetwork = container_of(pmlmepriv->pscanned, struct wlan_network, list);
1482                 if (!pnetwork) {
1483                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork==NULL)\n", __func__));
1484                         ret = _FAIL;
1485                         goto exit;
1486                 }
1487                 pmlmepriv->pscanned = pmlmepriv->pscanned->next;
1488                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
1489         }
1490         if (!candidate) {
1491                 DBG_88E("%s: return _FAIL(candidate==NULL)\n", __func__);
1492                 ret = _FAIL;
1493                 goto exit;
1494         } else {
1495                 DBG_88E("%s: candidate: %s(%pM ch:%u)\n", __func__,
1496                         candidate->network.ssid.ssid, candidate->network.MacAddress,
1497                         candidate->network.Configuration.DSConfig);
1498         }
1499
1500         /*  check for situation of  _FW_LINKED */
1501         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1502                 DBG_88E("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
1503
1504                 rtw_disassoc_cmd(adapter, 0, true);
1505                 rtw_indicate_disconnect(adapter);
1506                 rtw_free_assoc_resources_locked(adapter);
1507         }
1508
1509         rtw_hal_get_def_var(adapter, HAL_DEF_IS_SUPPORT_ANT_DIV, &(supp_ant_div));
1510         if (supp_ant_div) {
1511                 u8 cur_ant;
1512
1513                 rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(cur_ant));
1514                 DBG_88E("#### Opt_Ant_(%s), cur_Ant(%s)\n",
1515                         (candidate->network.PhyInfo.Optimum_antenna == 2) ? "A" : "B",
1516                         (cur_ant == 2) ? "A" : "B"
1517                 );
1518         }
1519
1520         ret = rtw_joinbss_cmd(adapter, candidate);
1521
1522 exit:
1523         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1524         return ret;
1525 }
1526
1527 int rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
1528 {
1529         struct cmd_obj *pcmd;
1530         struct setauth_parm *psetauthparm;
1531         struct cmd_priv *pcmdpriv = &adapter->cmdpriv;
1532         int res = _SUCCESS;
1533
1534         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
1535         if (!pcmd) {
1536                 res = _FAIL;  /* try again */
1537                 goto exit;
1538         }
1539
1540         psetauthparm = kzalloc(sizeof(struct setauth_parm), GFP_KERNEL);
1541         if (!psetauthparm) {
1542                 kfree(pcmd);
1543                 res = _FAIL;
1544                 goto exit;
1545         }
1546         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
1547         pcmd->cmdcode = _SetAuth_CMD_;
1548         pcmd->parmbuf = (unsigned char *)psetauthparm;
1549         pcmd->cmdsz =  sizeof(struct setauth_parm);
1550         pcmd->rsp = NULL;
1551         pcmd->rspsz = 0;
1552         INIT_LIST_HEAD(&pcmd->list);
1553         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1554                  ("after enqueue set_auth_cmd, auth_mode=%x\n",
1555                  psecuritypriv->dot11AuthAlgrthm));
1556         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1557 exit:
1558         return res;
1559 }
1560
1561 int rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, int keyid, u8 set_tx)
1562 {
1563         u8 keylen;
1564         struct cmd_obj *pcmd;
1565         struct setkey_parm *psetkeyparm;
1566         struct cmd_priv *pcmdpriv = &adapter->cmdpriv;
1567         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1568         int res = _SUCCESS;
1569
1570         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
1571         if (!pcmd)
1572                 return _FAIL;  /* try again */
1573
1574         psetkeyparm = kzalloc(sizeof(struct setkey_parm), GFP_KERNEL);
1575         if (!psetkeyparm) {
1576                 res = _FAIL;
1577                 goto err_free_cmd;
1578         }
1579
1580         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1581                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
1582                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1583                          ("\n %s: psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy=%d\n",
1584                           __func__, psetkeyparm->algorithm));
1585         } else {
1586                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
1587                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1588                          ("\n %s: psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm=%d\n",
1589                           __func__, psetkeyparm->algorithm));
1590         }
1591         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
1592         psetkeyparm->set_tx = set_tx;
1593         pmlmepriv->key_mask |= BIT(psetkeyparm->keyid);
1594         DBG_88E("==> %s algorithm(%x), keyid(%x), key_mask(%x)\n",
1595                 __func__, psetkeyparm->algorithm, psetkeyparm->keyid,
1596                 pmlmepriv->key_mask);
1597         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1598                  ("\n %s: psetkeyparm->algorithm=%d psetkeyparm->keyid=(u8)keyid=%d\n",
1599                   __func__, psetkeyparm->algorithm, keyid));
1600
1601         switch (psetkeyparm->algorithm) {
1602         case _WEP40_:
1603                 keylen = 5;
1604                 memcpy(&psetkeyparm->key[0],
1605                        &psecuritypriv->dot11DefKey[keyid].skey[0], keylen);
1606                 break;
1607         case _WEP104_:
1608                 keylen = 13;
1609                 memcpy(&psetkeyparm->key[0],
1610                        &psecuritypriv->dot11DefKey[keyid].skey[0], keylen);
1611                 break;
1612         case _TKIP_:
1613                 keylen = 16;
1614                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1615                 psetkeyparm->grpkey = 1;
1616                 break;
1617         case _AES_:
1618                 keylen = 16;
1619                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1620                 psetkeyparm->grpkey = 1;
1621                 break;
1622         default:
1623                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1624                          ("\n %s:psecuritypriv->dot11PrivacyAlgrthm=%x (must be 1 or 2 or 4 or 5)\n",
1625                           __func__, psecuritypriv->dot11PrivacyAlgrthm));
1626                 res = _FAIL;
1627                 goto err_free_parm;
1628         }
1629         pcmd->cmdcode = _SetKey_CMD_;
1630         pcmd->parmbuf = (u8 *)psetkeyparm;
1631         pcmd->cmdsz =  sizeof(struct setkey_parm);
1632         pcmd->rsp = NULL;
1633         pcmd->rspsz = 0;
1634         INIT_LIST_HEAD(&pcmd->list);
1635         return rtw_enqueue_cmd(pcmdpriv, pcmd);
1636
1637 err_free_parm:
1638         kfree(psetkeyparm);
1639 err_free_cmd:
1640         kfree(pcmd);
1641         return res;
1642 }
1643
1644 /* adjust ies for rtw_joinbss_cmd in WMM */
1645 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
1646 {
1647         unsigned int ielength = 0;
1648         unsigned int i, j;
1649
1650         /* i = 12; after the fixed IE */
1651         for (i = 12; i < in_len; i += (in_ie[i + 1] + 2) /* to the next IE element */) {
1652                 ielength = initial_out_len;
1653
1654                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) {
1655                         /* WMM element ID and OUI */
1656                         /* Append WMM IE to the last index of out_ie */
1657
1658                         for (j = i; j < i + 9; j++) {
1659                                 out_ie[ielength] = in_ie[j];
1660                                 ielength++;
1661                         }
1662                         out_ie[initial_out_len + 1] = 0x07;
1663                         out_ie[initial_out_len + 6] = 0x00;
1664                         out_ie[initial_out_len + 8] = 0x00;
1665                         break;
1666                 }
1667         }
1668         return ielength;
1669 }
1670
1671 /*
1672  * Ported from 8185: IsInPreAuthKeyList().
1673  * (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.)
1674  * Added by Annie, 2006-05-07.
1675  * Search by BSSID,
1676  * Return Value:
1677  *              -1      :if there is no pre-auth key in the table
1678  *              >= 0    :if there is pre-auth key, and return the entry id
1679  */
1680 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
1681 {
1682         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1683         int i = 0;
1684
1685         do {
1686                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
1687                     (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN)))
1688                         break;
1689         } while (++i < NUM_PMKID_CACHE);
1690
1691         if (i == NUM_PMKID_CACHE)
1692                 i = -1;/*  Could not find. */
1693
1694         return i;
1695 }
1696
1697 /*  */
1698 /*  Check the RSN IE length */
1699 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
1700 /*  0-11th element in the array are the fixed IE */
1701 /*  12th element in the array is the IE */
1702 /*  13th element in the array is the IE length */
1703 /*  */
1704
1705 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
1706 {
1707         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1708
1709         if (ie[13] <= 20) {
1710                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
1711                 ie[ie_len] = 1;
1712                 ie_len++;
1713                 ie[ie_len] = 0; /* PMKID count = 0x0100 */
1714                 ie_len++;
1715                 memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
1716
1717                 ie_len += 16;
1718                 ie[13] += 18;/* PMKID length = 2+16 */
1719         }
1720         return ie_len;
1721 }
1722
1723 int rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
1724 {
1725         u8 authmode;
1726         uint ielength;
1727         int iEntry;
1728         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1729         struct security_priv *psecuritypriv = &adapter->securitypriv;
1730         uint ndisauthmode = psecuritypriv->ndisauthtype;
1731         uint ndissecuritytype = psecuritypriv->ndisencryptstatus;
1732
1733         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
1734                  ("+%s: ndisauthmode=%d ndissecuritytype=%d\n", __func__,
1735                   ndisauthmode, ndissecuritytype));
1736
1737         /* copy fixed ie only */
1738         memcpy(out_ie, in_ie, 12);
1739         ielength = 12;
1740         if ((ndisauthmode == Ndis802_11AuthModeWPA) ||
1741             (ndisauthmode == Ndis802_11AuthModeWPAPSK))
1742                 authmode = _WPA_IE_ID_;
1743         if ((ndisauthmode == Ndis802_11AuthModeWPA2) ||
1744             (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
1745                 authmode = _WPA2_IE_ID_;
1746
1747         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
1748                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
1749
1750                 ielength += psecuritypriv->wps_ie_len;
1751         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
1752                 /* copy RSN or SSN */
1753                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
1754                 ielength += psecuritypriv->supplicant_ie[1]+2;
1755                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
1756         }
1757
1758         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
1759         if (iEntry >= 0 && authmode == _WPA2_IE_ID_)
1760                 ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
1761
1762         return ielength;
1763 }
1764
1765 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
1766 {
1767         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1768         struct eeprom_priv *peepriv = &adapter->eeprompriv;
1769         struct wlan_bssid_ex *pdev_network = &pregistrypriv->dev_network;
1770         u8 *myhwaddr = myid(peepriv);
1771
1772         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
1773
1774         memcpy(&pdev_network->ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
1775
1776         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_config);
1777         pdev_network->Configuration.BeaconPeriod = 100;
1778         pdev_network->Configuration.FHConfig.Length = 0;
1779         pdev_network->Configuration.FHConfig.HopPattern = 0;
1780         pdev_network->Configuration.FHConfig.HopSet = 0;
1781         pdev_network->Configuration.FHConfig.DwellTime = 0;
1782 }
1783
1784 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
1785 {
1786         int sz = 0;
1787         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1788         struct wlan_bssid_ex *pdev_network = &pregistrypriv->dev_network;
1789         struct security_priv *psecuritypriv = &adapter->securitypriv;
1790         struct wlan_network *cur_network = &adapter->mlmepriv.cur_network;
1791
1792         pdev_network->Privacy = psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0; /*  adhoc no 802.1x */
1793
1794         pdev_network->Rssi = 0;
1795
1796         switch (pregistrypriv->wireless_mode) {
1797         case WIRELESS_11B:
1798                 pdev_network->NetworkTypeInUse = Ndis802_11DS;
1799                 break;
1800         case WIRELESS_11G:
1801         case WIRELESS_11BG:
1802         case WIRELESS_11_24N:
1803         case WIRELESS_11G_24N:
1804         case WIRELESS_11BG_24N:
1805                 pdev_network->NetworkTypeInUse = Ndis802_11OFDM24;
1806                 break;
1807         default:
1808                 pdev_network->NetworkTypeInUse = Ndis802_11OFDM24;
1809                 break;
1810         }
1811
1812         pdev_network->Configuration.DSConfig = pregistrypriv->channel;
1813         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
1814                  ("pregistrypriv->channel=%d, pdev_network->Configuration.DSConfig=0x%x\n",
1815                  pregistrypriv->channel, pdev_network->Configuration.DSConfig));
1816
1817         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
1818                 pdev_network->Configuration.ATIMWindow = 0;
1819
1820         pdev_network->InfrastructureMode = cur_network->network.InfrastructureMode;
1821
1822         /*  1. Supported rates */
1823         /*  2. IE */
1824
1825         sz = rtw_generate_ie(pregistrypriv);
1826         pdev_network->ie_length = sz;
1827         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
1828
1829         /* notes: translate ie_length & Length after assign the Length to cmdsz in createbss_cmd(); */
1830         /* pdev_network->ie_length = cpu_to_le32(sz); */
1831 }
1832
1833 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
1834 {
1835 }
1836
1837 /* the function is at passive_level */
1838 void rtw_joinbss_reset(struct adapter *padapter)
1839 {
1840         u8 threshold;
1841         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1842         struct ht_priv *phtpriv = &pmlmepriv->htpriv;
1843
1844         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
1845         pmlmepriv->num_FortyMHzIntolerant = 0;
1846
1847         pmlmepriv->num_sta_no_ht = 0;
1848
1849         phtpriv->ampdu_enable = false;/* reset to disabled */
1850
1851         /*  TH = 1 => means that invalidate usb rx aggregation */
1852         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
1853         if (phtpriv->ht_option) {
1854                 if (padapter->registrypriv.wifi_spec == 1)
1855                         threshold = 1;
1856                 else
1857                         threshold = 0;
1858                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
1859         } else {
1860                 threshold = 1;
1861                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
1862         }
1863 }
1864
1865 /* the function is >= passive_level */
1866 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len)
1867 {
1868         u32 ielen, out_len;
1869         enum ht_cap_ampdu_factor max_rx_ampdu_factor;
1870         unsigned char *p;
1871         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
1872         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1873         struct qos_priv *pqospriv = &pmlmepriv->qospriv;
1874         struct ht_priv *phtpriv = &pmlmepriv->htpriv;
1875         u32 rx_packet_offset, max_recvbuf_sz;
1876
1877         phtpriv->ht_option = false;
1878
1879         p = rtw_get_ie(in_ie+12, _HT_CAPABILITY_IE_, &ielen, in_len-12);
1880
1881         if (p && ielen > 0) {
1882                 struct ieee80211_ht_cap ht_cap;
1883
1884                 if (pqospriv->qos_option == 0) {
1885                         out_len = *pout_len;
1886                         rtw_set_ie(out_ie + out_len, _VENDOR_SPECIFIC_IE_,
1887                                    _WMM_IE_Length_, WMM_IE, pout_len);
1888
1889                         pqospriv->qos_option = 1;
1890                 }
1891
1892                 out_len = *pout_len;
1893
1894                 memset(&ht_cap, 0, sizeof(struct ieee80211_ht_cap));
1895
1896                 ht_cap.cap_info = cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH |
1897                                               IEEE80211_HT_CAP_SGI_20 |
1898                                               IEEE80211_HT_CAP_SGI_40 |
1899                                               IEEE80211_HT_CAP_TX_STBC |
1900                                               IEEE80211_HT_CAP_DSSSCCK40);
1901
1902                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
1903                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
1904
1905                 /*
1906                 ampdu_params_info [1:0]:Max AMPDU Len => 0:8k , 1:16k, 2:32k, 3:64k
1907                 ampdu_params_info [4:2]:Min MPDU Start Spacing
1908                 */
1909
1910                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor);
1911                 ht_cap.ampdu_params_info = max_rx_ampdu_factor & 0x03;
1912
1913                 if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
1914                         ht_cap.ampdu_params_info |= IEEE80211_HT_CAP_AMPDU_DENSITY & (0x07 << 2);
1915                 else
1916                         ht_cap.ampdu_params_info |= IEEE80211_HT_CAP_AMPDU_DENSITY & 0x00;
1917
1918                 rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
1919                            sizeof(struct ieee80211_ht_cap),
1920                            (unsigned char *)&ht_cap, pout_len);
1921
1922                 phtpriv->ht_option = true;
1923
1924                 p = rtw_get_ie(in_ie+12, _HT_ADD_INFO_IE_, &ielen, in_len-12);
1925                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
1926                         out_len = *pout_len;
1927                         rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2, pout_len);
1928                 }
1929         }
1930         return phtpriv->ht_option;
1931 }
1932
1933 /* the function is > passive_level (in critical_section) */
1934 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len)
1935 {
1936         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1937         struct ht_priv *phtpriv = &pmlmepriv->htpriv;
1938         struct registry_priv *pregistrypriv = &padapter->registrypriv;
1939         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1940         struct mlme_ext_info *pmlmeinfo = &pmlmeext->mlmext_info;
1941
1942         if (!phtpriv->ht_option)
1943                 return;
1944
1945         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
1946                 return;
1947
1948         DBG_88E("+%s()\n", __func__);
1949
1950         /* maybe needs check if ap supports rx ampdu. */
1951         if ((!phtpriv->ampdu_enable) && (pregistrypriv->ampdu_enable == 1)) {
1952                 if (pregistrypriv->wifi_spec == 1)
1953                         phtpriv->ampdu_enable = false;
1954                 else
1955                         phtpriv->ampdu_enable = true;
1956         } else if (pregistrypriv->ampdu_enable == 2) {
1957                 phtpriv->ampdu_enable = true;
1958         }
1959
1960         /* update cur_bwmode & cur_ch_offset */
1961         if ((pregistrypriv->cbw40_enable) &&
1962             (le16_to_cpu(pmlmeinfo->HT_caps.cap_info) & BIT(1)) &&
1963             (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
1964                 int i;
1965
1966                 /* update the MCS rates */
1967                 for (i = 0; i < 16; i++)
1968                         ((u8 *)&pmlmeinfo->HT_caps.mcs)[i] &= MCS_rate_1R[i];
1969                 /* switch to the 40M Hz mode according to the AP */
1970                 pmlmeext->cur_bwmode = HT_CHANNEL_WIDTH_40;
1971                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
1972                 case HT_EXTCHNL_OFFSET_UPPER:
1973                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
1974                         break;
1975                 case HT_EXTCHNL_OFFSET_LOWER:
1976                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
1977                         break;
1978                 default:
1979                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
1980                         break;
1981                 }
1982         }
1983
1984         /*  Config SM Power Save setting */
1985         pmlmeinfo->SM_PS = (le16_to_cpu(pmlmeinfo->HT_caps.cap_info) & 0x0C) >> 2;
1986         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
1987                 DBG_88E("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
1988
1989         /*  Config current HT Protection mode. */
1990         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
1991 }
1992
1993 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
1994 {
1995         u8 issued;
1996         int priority;
1997         struct sta_info *psta = NULL;
1998         struct ht_priv *phtpriv;
1999         struct pkt_attrib *pattrib = &pxmitframe->attrib;
2000
2001         if (is_multicast_ether_addr(pattrib->ra) ||
2002             padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100)
2003                 return;
2004
2005         priority = pattrib->priority;
2006
2007         if (pattrib->psta)
2008                 psta = pattrib->psta;
2009         else
2010                 psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
2011
2012         if (!psta)
2013                 return;
2014
2015         phtpriv = &psta->htpriv;
2016
2017         if ((phtpriv->ht_option) && (phtpriv->ampdu_enable)) {
2018                 issued = (phtpriv->agg_enable_bitmap >> priority) & 0x1;
2019                 issued |= (phtpriv->candidate_tid_bitmap >> priority) & 0x1;
2020
2021                 if (issued == 0) {
2022                         DBG_88E("%s, p=%d\n", __func__, priority);
2023                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
2024                         rtw_addbareq_cmd(padapter, (u8)priority, pattrib->ra);
2025                 }
2026         }
2027 }
2028
2029 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2030 {
2031         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2032
2033         spin_lock_bh(&pmlmepriv->lock);
2034         _rtw_roaming(padapter, tgt_network);
2035         spin_unlock_bh(&pmlmepriv->lock);
2036 }
2037
2038 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2039 {
2040         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2041         int do_join_r;
2042         struct wlan_network *pnetwork;
2043
2044         if (tgt_network)
2045                 pnetwork = tgt_network;
2046         else
2047                 pnetwork = &pmlmepriv->cur_network;
2048
2049         if (pmlmepriv->to_roaming > 0) {
2050                 DBG_88E("roaming from %s(%pM length:%d\n",
2051                         pnetwork->network.ssid.ssid, pnetwork->network.MacAddress,
2052                         pnetwork->network.ssid.ssid_length);
2053                 memcpy(&pmlmepriv->assoc_ssid, &pnetwork->network.ssid, sizeof(struct ndis_802_11_ssid));
2054
2055                 pmlmepriv->assoc_by_bssid = false;
2056
2057                 while (1) {
2058                         do_join_r = rtw_do_join(padapter);
2059                         if (do_join_r == _SUCCESS) {
2060                                 break;
2061                         } else {
2062                                 DBG_88E("roaming do_join return %d\n", do_join_r);
2063                                 pmlmepriv->to_roaming--;
2064
2065                                 if (pmlmepriv->to_roaming > 0) {
2066                                         continue;
2067                                 } else {
2068                                         DBG_88E("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
2069                                         rtw_indicate_disconnect(padapter);
2070                                         break;
2071                                 }
2072                         }
2073                 }
2074         }
2075 }