Merge tag 'riscv-for-linus-5.2-mw2' of git://git.kernel.org/pub/scm/linux/kernel...
[platform/kernel/linux-starfive.git] / drivers / staging / rtl8723bs / core / rtw_mlme.c
1 // SPDX-License-Identifier: GPL-2.0
2 /******************************************************************************
3  *
4  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
5  *
6  ******************************************************************************/
7 #define _RTW_MLME_C_
8
9 #include <linux/etherdevice.h>
10 #include <drv_types.h>
11 #include <rtw_debug.h>
12 #include <linux/jiffies.h>
13
14 extern u8 rtw_do_join(struct adapter *padapter);
15
16 int     rtw_init_mlme_priv(struct adapter *padapter)
17 {
18         int     i;
19         u8 *pbuf;
20         struct wlan_network     *pnetwork;
21         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
22         int     res = _SUCCESS;
23
24         pmlmepriv->nic_hdl = (u8 *)padapter;
25
26         pmlmepriv->pscanned = NULL;
27         pmlmepriv->fw_state = WIFI_STATION_STATE; /*  Must sync with rtw_wdev_alloc() */
28         /*  wdev->iftype = NL80211_IFTYPE_STATION */
29         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
30         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
31
32         spin_lock_init(&pmlmepriv->lock);
33         _rtw_init_queue(&pmlmepriv->free_bss_pool);
34         _rtw_init_queue(&pmlmepriv->scanned_queue);
35
36         set_scanned_network_val(pmlmepriv, 0);
37
38         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
39
40         pbuf = vzalloc(array_size(MAX_BSS_CNT, sizeof(struct wlan_network)));
41
42         if (pbuf == NULL) {
43                 res = _FAIL;
44                 goto exit;
45         }
46         pmlmepriv->free_bss_buf = pbuf;
47
48         pnetwork = (struct wlan_network *)pbuf;
49
50         for (i = 0; i < MAX_BSS_CNT; i++) {
51                 INIT_LIST_HEAD(&pnetwork->list);
52
53                 list_add_tail(&pnetwork->list, &pmlmepriv->free_bss_pool.queue);
54
55                 pnetwork++;
56         }
57
58         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
59
60         rtw_clear_scan_deny(padapter);
61
62         #define RTW_ROAM_SCAN_RESULT_EXP_MS 5000
63         #define RTW_ROAM_RSSI_DIFF_TH 10
64         #define RTW_ROAM_SCAN_INTERVAL_MS 10000
65
66         pmlmepriv->roam_flags = 0
67                 | RTW_ROAM_ON_EXPIRED
68                 | RTW_ROAM_ON_RESUME
69                 #ifdef CONFIG_LAYER2_ROAMING_ACTIVE /* FIXME */
70                 | RTW_ROAM_ACTIVE
71                 #endif
72                 ;
73
74         pmlmepriv->roam_scanr_exp_ms = RTW_ROAM_SCAN_RESULT_EXP_MS;
75         pmlmepriv->roam_rssi_diff_th = RTW_ROAM_RSSI_DIFF_TH;
76         pmlmepriv->roam_scan_int_ms = RTW_ROAM_SCAN_INTERVAL_MS;
77
78         rtw_init_mlme_timer(padapter);
79
80 exit:
81
82         return res;
83 }
84
85 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
86 {
87         if (*ppie) {
88                 kfree(*ppie);
89                 *plen = 0;
90                 *ppie = NULL;
91         }
92 }
93
94 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
95 {
96         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
97         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
98         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
99         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
100         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
101         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
102
103         rtw_free_mlme_ie_data(&pmlmepriv->p2p_beacon_ie, &pmlmepriv->p2p_beacon_ie_len);
104         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_req_ie, &pmlmepriv->p2p_probe_req_ie_len);
105         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_resp_ie, &pmlmepriv->p2p_probe_resp_ie_len);
106         rtw_free_mlme_ie_data(&pmlmepriv->p2p_go_probe_resp_ie, &pmlmepriv->p2p_go_probe_resp_ie_len);
107         rtw_free_mlme_ie_data(&pmlmepriv->p2p_assoc_req_ie, &pmlmepriv->p2p_assoc_req_ie_len);
108 }
109
110 void _rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
111 {
112         if (pmlmepriv) {
113                 rtw_free_mlme_priv_ie_data(pmlmepriv);
114                 if (pmlmepriv->free_bss_buf) {
115                         vfree(pmlmepriv->free_bss_buf);
116                 }
117         }
118 }
119
120 /*
121 struct  wlan_network *_rtw_dequeue_network(struct __queue *queue)
122 {
123         _irqL irqL;
124
125         struct wlan_network *pnetwork;
126
127         spin_lock_bh(&queue->lock);
128
129         if (list_empty(&queue->queue))
130
131                 pnetwork = NULL;
132
133         else
134         {
135                 pnetwork = LIST_CONTAINOR(get_next(&queue->queue), struct wlan_network, list);
136
137                 list_del_init(&(pnetwork->list));
138         }
139
140         spin_unlock_bh(&queue->lock);
141
142         return pnetwork;
143 }
144 */
145
146 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv)
147 {
148         struct  wlan_network    *pnetwork;
149         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
150         struct list_head *plist = NULL;
151
152         spin_lock_bh(&free_queue->lock);
153
154         if (list_empty(&free_queue->queue)) {
155                 pnetwork = NULL;
156                 goto exit;
157         }
158         plist = get_next(&(free_queue->queue));
159
160         pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
161
162         list_del_init(&pnetwork->list);
163
164         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
165                  ("rtw_alloc_network: ptr =%p\n", plist));
166         pnetwork->network_type = 0;
167         pnetwork->fixed = false;
168         pnetwork->last_scanned = jiffies;
169         pnetwork->aid = 0;
170         pnetwork->join_res = 0;
171
172         pmlmepriv->num_of_scanned++;
173
174 exit:
175         spin_unlock_bh(&free_queue->lock);
176
177         return pnetwork;
178 }
179
180 void _rtw_free_network(struct   mlme_priv *pmlmepriv, struct wlan_network *pnetwork, u8 isfreeall)
181 {
182         unsigned int delta_time;
183         u32 lifetime = SCANQUEUE_LIFETIME;
184 /*      _irqL irqL; */
185         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
186
187         if (pnetwork == NULL)
188                 return;
189
190         if (pnetwork->fixed == true)
191                 return;
192
193         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
194                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true))
195                 lifetime = 1;
196
197         if (!isfreeall) {
198                 delta_time = jiffies_to_msecs(jiffies - pnetwork->last_scanned);
199                 if (delta_time < lifetime)/*  unit:msec */
200                         return;
201         }
202
203         spin_lock_bh(&free_queue->lock);
204
205         list_del_init(&(pnetwork->list));
206
207         list_add_tail(&(pnetwork->list), &(free_queue->queue));
208
209         pmlmepriv->num_of_scanned--;
210
211
212         /* DBG_871X("_rtw_free_network:SSID =%s\n", pnetwork->network.Ssid.Ssid); */
213
214         spin_unlock_bh(&free_queue->lock);
215 }
216
217 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
218 {
219
220         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
221
222         if (pnetwork == NULL)
223                 return;
224
225         if (pnetwork->fixed == true)
226                 return;
227
228         /* spin_lock_irqsave(&free_queue->lock, irqL); */
229
230         list_del_init(&(pnetwork->list));
231
232         list_add_tail(&(pnetwork->list), get_list_head(free_queue));
233
234         pmlmepriv->num_of_scanned--;
235
236         /* spin_unlock_irqrestore(&free_queue->lock, irqL); */
237 }
238
239 /*
240         return the wlan_network with the matching addr
241
242         Shall be called under atomic context... to avoid possible racing condition...
243 */
244 struct wlan_network *_rtw_find_network(struct __queue *scanned_queue, u8 *addr)
245 {
246         struct list_head        *phead, *plist;
247         struct  wlan_network *pnetwork = NULL;
248         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
249
250         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
251                 pnetwork = NULL;
252                 goto exit;
253         }
254
255         /* spin_lock_bh(&scanned_queue->lock); */
256
257         phead = get_list_head(scanned_queue);
258         plist = get_next(phead);
259
260         while (plist != phead) {
261                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
262
263                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
264                         break;
265
266                 plist = get_next(plist);
267         }
268
269         if (plist == phead)
270                 pnetwork = NULL;
271
272         /* spin_unlock_bh(&scanned_queue->lock); */
273
274 exit:
275         return pnetwork;
276 }
277
278 void _rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
279 {
280         struct list_head *phead, *plist;
281         struct wlan_network *pnetwork;
282         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
283         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
284
285         spin_lock_bh(&scanned_queue->lock);
286
287         phead = get_list_head(scanned_queue);
288         plist = get_next(phead);
289
290         while (phead != plist) {
291
292                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
293
294                 plist = get_next(plist);
295
296                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
297
298         }
299
300         spin_unlock_bh(&scanned_queue->lock);
301 }
302
303
304
305
306 sint rtw_if_up(struct adapter *padapter)
307 {
308
309         sint res;
310
311         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
312                 (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
313                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)", padapter->bDriverStopped, padapter->bSurpriseRemoved));
314                 res = false;
315         } else
316                 res =  true;
317         return res;
318 }
319
320
321 void rtw_generate_random_ibss(u8 *pibss)
322 {
323         unsigned long curtime = jiffies;
324
325         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
326         pibss[1] = 0x11;
327         pibss[2] = 0x87;
328         pibss[3] = (u8)(curtime & 0xff) ;/* p[0]; */
329         pibss[4] = (u8)((curtime>>8) & 0xff) ;/* p[1]; */
330         pibss[5] = (u8)((curtime>>16) & 0xff) ;/* p[2]; */
331         return;
332 }
333
334 u8 *rtw_get_capability_from_ie(u8 *ie)
335 {
336         return ie + 8 + 2;
337 }
338
339
340 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
341 {
342         __le16  val;
343
344         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2);
345
346         return le16_to_cpu(val);
347 }
348
349 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
350 {
351         return ie + 8;
352 }
353
354 void rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
355 {
356         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_mlme_priv\n"));
357         _rtw_free_mlme_priv(pmlmepriv);
358 }
359
360 /*
361 static struct   wlan_network *rtw_dequeue_network(struct __queue *queue)
362 {
363         struct wlan_network *pnetwork;
364
365         pnetwork = _rtw_dequeue_network(queue);
366         return pnetwork;
367 }
368 */
369
370 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork);
371 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork)
372 {
373         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_network ==> ssid = %s\n\n" , pnetwork->network.Ssid.Ssid)); */
374         _rtw_free_network_nolock(&(padapter->mlmepriv), pnetwork);
375         rtw_cfg80211_unlink_bss(padapter, pnetwork);
376 }
377
378
379 void rtw_free_network_queue(struct adapter *dev, u8 isfreeall)
380 {
381         _rtw_free_network_queue(dev, isfreeall);
382 }
383
384 /*
385         return the wlan_network with the matching addr
386
387         Shall be called under atomic context... to avoid possible racing condition...
388 */
389 struct  wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
390 {
391         struct  wlan_network *pnetwork = _rtw_find_network(scanned_queue, addr);
392
393         return pnetwork;
394 }
395
396 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
397 {
398         int ret = true;
399         struct security_priv *psecuritypriv = &adapter->securitypriv;
400
401         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
402                     (pnetwork->network.Privacy == 0))
403                 ret = false;
404         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
405                  (pnetwork->network.Privacy == 1))
406                 ret = false;
407         else
408                 ret = true;
409
410         return ret;
411
412 }
413
414 inline int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
415 {
416         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("(%s,%d)(%s,%d)\n", */
417         /*              a->Ssid.Ssid, a->Ssid.SsidLength, b->Ssid.Ssid, b->Ssid.SsidLength)); */
418         return (a->Ssid.SsidLength == b->Ssid.SsidLength)
419                 &&  !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
420 }
421
422 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst, u8 feature)
423 {
424         u16 s_cap, d_cap;
425         __le16 tmps, tmpd;
426
427         if (rtw_bug_check(dst, src, &s_cap, &d_cap) == false)
428                         return false;
429
430         memcpy((u8 *)&tmps, rtw_get_capability_from_ie(src->IEs), 2);
431         memcpy((u8 *)&tmpd, rtw_get_capability_from_ie(dst->IEs), 2);
432
433
434         s_cap = le16_to_cpu(tmps);
435         d_cap = le16_to_cpu(tmpd);
436
437         return (src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
438                 /*      (src->Configuration.DSConfig == dst->Configuration.DSConfig) && */
439                         ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN))) &&
440                         ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength))) &&
441                         ((s_cap & WLAN_CAPABILITY_IBSS) ==
442                         (d_cap & WLAN_CAPABILITY_IBSS)) &&
443                         ((s_cap & WLAN_CAPABILITY_BSS) ==
444                         (d_cap & WLAN_CAPABILITY_BSS));
445
446 }
447
448 struct wlan_network *_rtw_find_same_network(struct __queue *scanned_queue, struct wlan_network *network)
449 {
450         struct list_head *phead, *plist;
451         struct wlan_network *found = NULL;
452
453         phead = get_list_head(scanned_queue);
454         plist = get_next(phead);
455
456         while (plist != phead) {
457                 found = LIST_CONTAINOR(plist, struct wlan_network, list);
458
459                 if (is_same_network(&network->network, &found->network, 0))
460                         break;
461
462                 plist = get_next(plist);
463         }
464
465         if (plist == phead)
466                 found = NULL;
467
468         return found;
469 }
470
471 struct  wlan_network    *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
472 {
473         struct list_head        *plist, *phead;
474
475
476         struct  wlan_network    *pwlan = NULL;
477         struct  wlan_network    *oldest = NULL;
478
479         phead = get_list_head(scanned_queue);
480
481         plist = get_next(phead);
482
483         while (1) {
484
485                 if (phead == plist)
486                         break;
487
488                 pwlan = LIST_CONTAINOR(plist, struct wlan_network, list);
489
490                 if (pwlan->fixed != true) {
491                         if (oldest == NULL || time_after(oldest->last_scanned, pwlan->last_scanned))
492                                 oldest = pwlan;
493                 }
494
495                 plist = get_next(plist);
496         }
497         return oldest;
498
499 }
500
501 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
502         struct adapter *padapter, bool update_ie)
503 {
504         long rssi_ori = dst->Rssi;
505
506         u8 sq_smp = src->PhyInfo.SignalQuality;
507
508         u8 ss_final;
509         u8 sq_final;
510         long rssi_final;
511
512         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
513         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
514                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT", ch%u) ss_ori:%3u, sq_ori:%3u, rssi_ori:%3ld, ss_smp:%3u, sq_smp:%3u, rssi_smp:%3ld\n"
515                         , FUNC_ADPT_ARG(padapter)
516                         , src->Ssid.Ssid, MAC_ARG(src->MacAddress), src->Configuration.DSConfig
517                         , ss_ori, sq_ori, rssi_ori
518                         , ss_smp, sq_smp, rssi_smp
519                 );
520         }
521         #endif
522
523         /* The rule below is 1/5 for sample value, 4/5 for history value */
524         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src, 0)) {
525                 /* Take the recvpriv's value for the connected AP*/
526                 ss_final = padapter->recvpriv.signal_strength;
527                 sq_final = padapter->recvpriv.signal_qual;
528                 /* the rssi value here is undecorated, and will be used for antenna diversity */
529                 if (sq_smp != 101) /* from the right channel */
530                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
531                 else
532                         rssi_final = rssi_ori;
533         } else {
534                 if (sq_smp != 101) { /* from the right channel */
535                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
536                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
537                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
538                 } else {
539                         /* bss info not receiving from the right channel, use the original RX signal infos */
540                         ss_final = dst->PhyInfo.SignalStrength;
541                         sq_final = dst->PhyInfo.SignalQuality;
542                         rssi_final = dst->Rssi;
543                 }
544
545         }
546
547         if (update_ie) {
548                 dst->Reserved[0] = src->Reserved[0];
549                 dst->Reserved[1] = src->Reserved[1];
550                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
551         }
552
553         dst->PhyInfo.SignalStrength = ss_final;
554         dst->PhyInfo.SignalQuality = sq_final;
555         dst->Rssi = rssi_final;
556
557         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
558         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
559                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT"), SignalStrength:%u, SignalQuality:%u, RawRSSI:%ld\n"
560                         , FUNC_ADPT_ARG(padapter)
561                         , dst->Ssid.Ssid, MAC_ARG(dst->MacAddress), dst->PhyInfo.SignalStrength, dst->PhyInfo.SignalQuality, dst->Rssi);
562         }
563         #endif
564 }
565
566 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
567 {
568         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
569
570         rtw_bug_check(&(pmlmepriv->cur_network.network),
571                 &(pmlmepriv->cur_network.network),
572                 &(pmlmepriv->cur_network.network),
573                 &(pmlmepriv->cur_network.network));
574
575         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) && (is_same_network(&(pmlmepriv->cur_network.network), pnetwork, 0))) {
576                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"Same Network\n"); */
577
578                 /* if (pmlmepriv->cur_network.network.IELength<= pnetwork->IELength) */
579                 {
580                         update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
581                         rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof(struct ndis_802_11_fix_ie),
582                                                                         pmlmepriv->cur_network.network.IELength);
583                 }
584         }
585 }
586
587
588 /*
589
590 Caller must hold pmlmepriv->lock first.
591
592
593 */
594 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
595 {
596         struct list_head        *plist, *phead;
597         u32 bssid_ex_sz;
598         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
599         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
600         struct wlan_network     *pnetwork = NULL;
601         struct wlan_network     *oldest = NULL;
602         int target_find = 0;
603         u8 feature = 0;
604
605         spin_lock_bh(&queue->lock);
606         phead = get_list_head(queue);
607         plist = get_next(phead);
608
609         while (1) {
610                 if (phead == plist)
611                         break;
612
613                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
614
615                 rtw_bug_check(pnetwork, pnetwork, pnetwork, pnetwork);
616
617                 if (is_same_network(&(pnetwork->network), target, feature)) {
618                         target_find = 1;
619                         break;
620                 }
621
622                 if (rtw_roam_flags(adapter)) {
623                         /* TODO: don't  select netowrk in the same ess as oldest if it's new enough*/
624                 }
625
626                 if (oldest == NULL || time_after(oldest->last_scanned, pnetwork->last_scanned))
627                         oldest = pnetwork;
628
629                 plist = get_next(plist);
630
631         }
632
633
634         /* If we didn't find a match, then get a new network slot to initialize
635          * with this beacon's information */
636         /* if (phead == plist) { */
637         if (!target_find) {
638                 if (list_empty(&pmlmepriv->free_bss_pool.queue)) {
639                         /* If there are no more slots, expire the oldest */
640                         /* list_del_init(&oldest->list); */
641                         pnetwork = oldest;
642                         if (pnetwork == NULL) {
643                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
644                                 goto exit;
645                         }
646                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
647                         /*  variable initialize */
648                         pnetwork->fixed = false;
649                         pnetwork->last_scanned = jiffies;
650
651                         pnetwork->network_type = 0;
652                         pnetwork->aid = 0;
653                         pnetwork->join_res = 0;
654
655                         /* bss info not receiving from the right channel */
656                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
657                                 pnetwork->network.PhyInfo.SignalQuality = 0;
658                 } else {
659                         /* Otherwise just pull from the free list */
660
661                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
662
663                         if (pnetwork == NULL) {
664                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
665                                 goto exit;
666                         }
667
668                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
669                         target->Length = bssid_ex_sz;
670                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
671
672                         pnetwork->last_scanned = jiffies;
673
674                         /* bss info not receiving from the right channel */
675                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
676                                 pnetwork->network.PhyInfo.SignalQuality = 0;
677
678                         list_add_tail(&(pnetwork->list), &(queue->queue));
679
680                 }
681         } else {
682                 /* we have an entry and we are going to update it. But this entry may
683                  * be already expired. In this case we do the same as we found a new
684                  * net and call the new_net handler
685                  */
686                 bool update_ie = true;
687
688                 pnetwork->last_scanned = jiffies;
689
690                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
691                 if ((pnetwork->network.IELength > target->IELength) && (target->Reserved[0] == 1))
692                         update_ie = false;
693
694                 /*  probe resp(3) > beacon(1) > probe req(2) */
695                 if ((target->Reserved[0] != 2) &&
696                         (target->Reserved[0] >= pnetwork->network.Reserved[0])
697                         ) {
698                         update_ie = true;
699                 } else {
700                         update_ie = false;
701                 }
702
703                 update_network(&(pnetwork->network), target, adapter, update_ie);
704         }
705
706 exit:
707         spin_unlock_bh(&queue->lock);
708 }
709
710 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork);
711 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
712 {
713         /* struct __queue       *queue  = &(pmlmepriv->scanned_queue); */
714
715         /* spin_lock_bh(&queue->lock); */
716
717         update_current_network(adapter, pnetwork);
718
719         rtw_update_scanned_network(adapter, pnetwork);
720
721         /* spin_unlock_bh(&queue->lock); */
722 }
723
724 /* select the desired network based on the capability of the (i)bss. */
725 /*  check items: (1) security */
726 /*                         (2) network_type */
727 /*                         (3) WMM */
728 /*                         (4) HT */
729 /*                      (5) others */
730 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork);
731 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
732 {
733         struct security_priv *psecuritypriv = &adapter->securitypriv;
734         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
735         u32 desired_encmode;
736         u32 privacy;
737
738         /* u8 wps_ie[512]; */
739         uint wps_ielen;
740
741         int bselected = true;
742
743         desired_encmode = psecuritypriv->ndisencryptstatus;
744         privacy = pnetwork->network.Privacy;
745
746         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
747                 if (rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen) != NULL)
748                         return true;
749                 else
750                         return false;
751
752         }
753         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
754                 u8 *p = NULL;
755                 uint ie_len = 0;
756
757                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
758             bselected = false;
759
760                 if (psecuritypriv->ndisauthtype == Ndis802_11AuthModeWPA2PSK) {
761                         p = rtw_get_ie(pnetwork->network.IEs + _BEACON_IE_OFFSET_, _RSN_IE_2_, &ie_len, (pnetwork->network.IELength - _BEACON_IE_OFFSET_));
762                         if (p && ie_len > 0) {
763                                 bselected = true;
764                         } else {
765                                 bselected = false;
766                         }
767                 }
768         }
769
770
771         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
772                 DBG_871X("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
773                 bselected = false;
774         }
775
776         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
777                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
778                         bselected = false;
779         }
780
781
782         return bselected;
783 }
784
785 /* TODO: Perry : For Power Management */
786 void rtw_atimdone_event_callback(struct adapter *adapter, u8 *pbuf)
787 {
788         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_event\n"));
789 }
790
791
792 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
793 {
794         u32 len;
795         struct wlan_bssid_ex *pnetwork;
796         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
797
798         pnetwork = (struct wlan_bssid_ex *)pbuf;
799
800         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid =%s\n",  pnetwork->Ssid.Ssid));
801
802         len = get_wlan_bssid_ex_sz(pnetwork);
803         if (len > (sizeof(struct wlan_bssid_ex))) {
804                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n ****rtw_survey_event_callback: return a wrong bss ***\n"));
805                 return;
806         }
807
808
809         spin_lock_bh(&pmlmepriv->lock);
810
811         /*  update IBSS_network 's timestamp */
812         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) {
813                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"rtw_survey_event_callback : WIFI_ADHOC_MASTER_STATE\n\n"); */
814                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN)) {
815                         struct wlan_network *ibss_wlan = NULL;
816
817                         memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
818                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
819                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
820                         if (ibss_wlan) {
821                                 memcpy(ibss_wlan->network.IEs, pnetwork->IEs, 8);
822                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
823                                 goto exit;
824                         }
825                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
826                 }
827         }
828
829         /*  lock pmlmepriv->lock when you accessing network_q */
830         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false) {
831                 if (pnetwork->Ssid.Ssid[0] == 0) {
832                         pnetwork->Ssid.SsidLength = 0;
833                 }
834                 rtw_add_network(adapter, pnetwork);
835         }
836
837 exit:
838
839         spin_unlock_bh(&pmlmepriv->lock);
840
841         return;
842 }
843
844
845
846 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
847 {
848         u8 timer_cancelled = false;
849         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
850
851         spin_lock_bh(&pmlmepriv->lock);
852         if (pmlmepriv->wps_probe_req_ie) {
853                 pmlmepriv->wps_probe_req_ie_len = 0;
854                 kfree(pmlmepriv->wps_probe_req_ie);
855                 pmlmepriv->wps_probe_req_ie = NULL;
856         }
857
858         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
859
860         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
861                 /* u8 timer_cancelled; */
862
863                 timer_cancelled = true;
864                 /* _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled); */
865
866                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
867         } else {
868
869                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status =%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
870         }
871         spin_unlock_bh(&pmlmepriv->lock);
872
873         if (timer_cancelled)
874                 _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
875
876
877         spin_lock_bh(&pmlmepriv->lock);
878
879         rtw_set_signal_stat_timer(&adapter->recvpriv);
880
881         if (pmlmepriv->to_join == true) {
882                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
883                         if (check_fwstate(pmlmepriv, _FW_LINKED) == false) {
884                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
885
886                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
887                                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
888                                 } else {
889                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
890                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
891
892                                         /* pmlmepriv->fw_state ^= _FW_UNDER_SURVEY;because don't set assoc_timer */
893                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
894
895                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
896
897                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
898
899                                         rtw_update_registrypriv_dev_network(adapter);
900                                         rtw_generate_random_ibss(pibss);
901
902                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
903
904                                         if (rtw_createbss_cmd(adapter) != _SUCCESS) {
905                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error =>rtw_createbss_cmd status FAIL\n"));
906                                         }
907
908                                         pmlmepriv->to_join = false;
909                                 }
910                         }
911                 } else {
912                         int s_ret;
913                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
914                         pmlmepriv->to_join = false;
915                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
916                         if (_SUCCESS == s_ret) {
917                              _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
918                         } else if (s_ret == 2) {/* there is no need to wait for join */
919                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
920                                 rtw_indicate_connect(adapter);
921                         } else {
922                                 DBG_871X("try_to_join, but select scanning queue fail, to_roam:%d\n", rtw_to_roam(adapter));
923
924                                 if (rtw_to_roam(adapter) != 0) {
925                                         if (rtw_dec_to_roam(adapter) == 0
926                                                 || _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)
927                                         ) {
928                                                 rtw_set_to_roam(adapter, 0);
929                                                 rtw_free_assoc_resources(adapter, 1);
930                                                 rtw_indicate_disconnect(adapter);
931                                         } else {
932                                                 pmlmepriv->to_join = true;
933                                         }
934                                 } else
935                                         rtw_indicate_disconnect(adapter);
936
937                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
938                         }
939                 }
940         } else {
941                 if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
942                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)
943                                 && check_fwstate(pmlmepriv, _FW_LINKED)) {
944                                 if (rtw_select_roaming_candidate(pmlmepriv) == _SUCCESS) {
945                                         receive_disconnect(adapter, pmlmepriv->cur_network.network.MacAddress
946                                                 , WLAN_REASON_ACTIVE_ROAM);
947                                 }
948                         }
949                 }
950         }
951
952         /* DBG_871X("scan complete in %dms\n", jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time)); */
953
954         spin_unlock_bh(&pmlmepriv->lock);
955
956         rtw_os_xmit_schedule(adapter);
957
958         rtw_cfg80211_surveydone_event_callback(adapter);
959
960         rtw_indicate_scan_done(adapter, false);
961 }
962
963 void rtw_dummy_event_callback(struct adapter *adapter, u8 *pbuf)
964 {
965 }
966
967 void rtw_fwdbg_event_callback(struct adapter *adapter, u8 *pbuf)
968 {
969 }
970
971 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
972 {
973         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
974         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
975         struct list_head        *plist, *phead, *ptemp;
976
977         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
978         spin_lock_bh(&scan_queue->lock);
979         spin_lock_bh(&free_queue->lock);
980
981         phead = get_list_head(scan_queue);
982         plist = get_next(phead);
983
984         while (plist != phead) {
985                 ptemp = get_next(plist);
986                 list_del_init(plist);
987                 list_add_tail(plist, &free_queue->queue);
988                 plist = ptemp;
989                 pmlmepriv->num_of_scanned--;
990         }
991
992         spin_unlock_bh(&free_queue->lock);
993         spin_unlock_bh(&scan_queue->lock);
994 }
995
996 static void rtw_reset_rx_info(struct debug_priv *pdbgpriv)
997 {
998         pdbgpriv->dbg_rx_ampdu_drop_count = 0;
999         pdbgpriv->dbg_rx_ampdu_forced_indicate_count = 0;
1000         pdbgpriv->dbg_rx_ampdu_loss_count = 0;
1001         pdbgpriv->dbg_rx_dup_mgt_frame_drop_count = 0;
1002         pdbgpriv->dbg_rx_ampdu_window_shift_cnt = 0;
1003 }
1004
1005 static void find_network(struct adapter *adapter)
1006 {
1007         struct wlan_network *pwlan = NULL;
1008         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1009         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1010
1011         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1012         if (pwlan)
1013                 pwlan->fixed = false;
1014         else
1015                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources : pwlan == NULL\n\n"));
1016
1017
1018         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) &&
1019             (adapter->stapriv.asoc_sta_count == 1))
1020                 rtw_free_network_nolock(adapter, pwlan);
1021 }
1022
1023 /*
1024 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
1025 */
1026 void rtw_free_assoc_resources(struct adapter *adapter, int lock_scanned_queue)
1027 {
1028         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1029         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1030         struct  sta_priv *pstapriv = &adapter->stapriv;
1031         struct dvobj_priv *psdpriv = adapter->dvobj;
1032         struct debug_priv *pdbgpriv = &psdpriv->drv_dbg;
1033
1034         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
1035         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("tgt_network->network.MacAddress ="MAC_FMT" ssid =%s\n",
1036                 MAC_ARG(tgt_network->network.MacAddress), tgt_network->network.Ssid.Ssid));
1037
1038         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_AP_STATE)) {
1039                 struct sta_info *psta;
1040
1041                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
1042                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1043                 rtw_free_stainfo(adapter,  psta);
1044
1045                 spin_unlock_bh(&(pstapriv->sta_hash_lock));
1046
1047         }
1048
1049         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE|WIFI_AP_STATE)) {
1050                 struct sta_info *psta;
1051
1052                 rtw_free_all_stainfo(adapter);
1053
1054                 psta = rtw_get_bcmc_stainfo(adapter);
1055                 rtw_free_stainfo(adapter, psta);
1056
1057                 rtw_init_bcmc_stainfo(adapter);
1058         }
1059
1060         find_network(adapter);
1061
1062         if (lock_scanned_queue)
1063                 adapter->securitypriv.key_mask = 0;
1064
1065         rtw_reset_rx_info(pdbgpriv);
1066 }
1067
1068 /*
1069 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
1070 */
1071 void rtw_indicate_connect(struct adapter *padapter)
1072 {
1073         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1074
1075         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
1076
1077         pmlmepriv->to_join = false;
1078
1079         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
1080
1081                 set_fwstate(pmlmepriv, _FW_LINKED);
1082
1083                 rtw_os_indicate_connect(padapter);
1084         }
1085
1086         rtw_set_to_roam(padapter, 0);
1087         rtw_set_scan_deny(padapter, 3000);
1088
1089         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state = 0x%08x\n", get_fwstate(pmlmepriv)));
1090 }
1091
1092 /*
1093 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
1094 */
1095 void rtw_indicate_disconnect(struct adapter *padapter)
1096 {
1097         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
1098
1099         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
1100
1101         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING|WIFI_UNDER_WPS);
1102
1103         /* DBG_871X("clear wps when %s\n", __func__); */
1104
1105         if (rtw_to_roam(padapter) > 0)
1106                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1107
1108         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED)
1109                 || (rtw_to_roam(padapter) <= 0)
1110         ) {
1111                 rtw_os_indicate_disconnect(padapter);
1112
1113                 /* set ips_deny_time to avoid enter IPS before LPS leave */
1114                 rtw_set_ips_deny(padapter, 3000);
1115
1116                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1117
1118                 rtw_clear_scan_deny(padapter);
1119         }
1120
1121         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
1122 }
1123
1124 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
1125 {
1126         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1127
1128         rtw_os_indicate_scan_done(padapter, aborted);
1129
1130         if (is_primary_adapter(padapter) &&
1131             (!adapter_to_pwrctl(padapter)->bInSuspend) &&
1132             (!check_fwstate(&padapter->mlmepriv,
1133                             WIFI_ASOC_STATE|WIFI_UNDER_LINKING))) {
1134                 struct pwrctrl_priv *pwrpriv;
1135
1136                 pwrpriv = adapter_to_pwrctl(padapter);
1137                 rtw_set_ips_deny(padapter, 0);
1138                 _set_timer(&padapter->mlmepriv.dynamic_chk_timer, 1);
1139         }
1140 }
1141
1142 void rtw_scan_abort(struct adapter *adapter)
1143 {
1144         unsigned long start;
1145         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1146         struct mlme_ext_priv *pmlmeext = &(adapter->mlmeextpriv);
1147
1148         start = jiffies;
1149         pmlmeext->scan_abort = true;
1150         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)
1151                 && jiffies_to_msecs(start) <= 200) {
1152
1153                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1154                         break;
1155
1156                 DBG_871X(FUNC_NDEV_FMT"fw_state = _FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1157                 msleep(20);
1158         }
1159
1160         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
1161                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
1162                         DBG_871X(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1163                 rtw_indicate_scan_done(adapter, true);
1164         }
1165         pmlmeext->scan_abort = false;
1166 }
1167
1168 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
1169 {
1170         int i;
1171         struct sta_info *bmc_sta, *psta = NULL;
1172         struct recv_reorder_ctrl *preorder_ctrl;
1173         struct sta_priv *pstapriv = &padapter->stapriv;
1174         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1175
1176         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
1177         if (psta == NULL) {
1178                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
1179         }
1180
1181         if (psta) { /* update ptarget_sta */
1182
1183                 DBG_871X("%s\n", __func__);
1184
1185                 psta->aid  = pnetwork->join_res;
1186
1187                 update_sta_info(padapter, psta);
1188
1189                 /* update station supportRate */
1190                 psta->bssratelen = rtw_get_rateset_len(pnetwork->network.SupportedRates);
1191                 memcpy(psta->bssrateset, pnetwork->network.SupportedRates, psta->bssratelen);
1192                 rtw_hal_update_sta_rate_mask(padapter, psta);
1193
1194                 psta->wireless_mode = pmlmeext->cur_wireless_mode;
1195                 psta->raid = rtw_hal_networktype_to_raid(padapter, psta);
1196
1197
1198                 /* sta mode */
1199                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
1200
1201                 /* security related */
1202                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1203                         padapter->securitypriv.binstallGrpkey = false;
1204                         padapter->securitypriv.busetkipkey = false;
1205                         padapter->securitypriv.bgrpkey_handshake = false;
1206
1207                         psta->ieee8021x_blocked = true;
1208                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
1209
1210                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
1211
1212                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
1213                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
1214
1215                         memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
1216                         psta->dot11txpn.val = psta->dot11txpn.val + 1;
1217                         memset((u8 *)&psta->dot11wtxpn, 0, sizeof(union pn48));
1218                         memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
1219                 }
1220
1221                 /*      Commented by Albert 2012/07/21 */
1222                 /*      When doing the WPS, the wps_ie_len won't equal to 0 */
1223                 /*      And the Wi-Fi driver shouldn't allow the data packet to be transmitted. */
1224                 if (padapter->securitypriv.wps_ie_len != 0) {
1225                         psta->ieee8021x_blocked = true;
1226                         padapter->securitypriv.wps_ie_len = 0;
1227                 }
1228
1229
1230                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
1231                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
1232                 /* todo: check if AP can send A-MPDU packets */
1233                 for (i = 0; i < 16 ; i++) {
1234                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1235                         preorder_ctrl = &psta->recvreorder_ctrl[i];
1236                         preorder_ctrl->enable = false;
1237                         preorder_ctrl->indicate_seq = 0xffff;
1238                         #ifdef DBG_RX_SEQ
1239                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1240                                 preorder_ctrl->indicate_seq);
1241                         #endif
1242                         preorder_ctrl->wend_b = 0xffff;
1243                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1244                 }
1245
1246
1247                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
1248                 if (bmc_sta) {
1249                         for (i = 0; i < 16 ; i++) {
1250                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1251                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
1252                                 preorder_ctrl->enable = false;
1253                                 preorder_ctrl->indicate_seq = 0xffff;
1254                                 #ifdef DBG_RX_SEQ
1255                                 DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1256                                         preorder_ctrl->indicate_seq);
1257                                 #endif
1258                                 preorder_ctrl->wend_b = 0xffff;
1259                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1260                         }
1261                 }
1262         }
1263
1264         return psta;
1265
1266 }
1267
1268 /* pnetwork : returns from rtw_joinbss_event_callback */
1269 /* ptarget_wlan: found from scanned_queue */
1270 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
1271 {
1272         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1273         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
1274
1275         DBG_871X("%s\n", __func__);
1276
1277         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nfw_state:%x, BSSID:"MAC_FMT"\n"
1278                 , get_fwstate(pmlmepriv), MAC_ARG(pnetwork->network.MacAddress)));
1279
1280
1281         /*  why not use ptarget_wlan?? */
1282         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
1283         /*  some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs */
1284         cur_network->network.IELength = ptarget_wlan->network.IELength;
1285         memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
1286
1287         cur_network->aid = pnetwork->join_res;
1288
1289
1290         rtw_set_signal_stat_timer(&padapter->recvpriv);
1291
1292         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
1293         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
1294         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
1295         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
1296         #if defined(DBG_RX_SIGNAL_DISPLAY_PROCESSING) && 1
1297                 DBG_871X(FUNC_ADPT_FMT" signal_strength:%3u, rssi:%3d, signal_qual:%3u"
1298                         "\n"
1299                         , FUNC_ADPT_ARG(padapter)
1300                         , padapter->recvpriv.signal_strength
1301                         , padapter->recvpriv.rssi
1302                         , padapter->recvpriv.signal_qual
1303         );
1304         #endif
1305
1306         rtw_set_signal_stat_timer(&padapter->recvpriv);
1307
1308         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
1309         switch (pnetwork->network.InfrastructureMode) {
1310         case Ndis802_11Infrastructure:
1311
1312                         if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
1313                                 pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
1314                         else
1315                                 pmlmepriv->fw_state = WIFI_STATION_STATE;
1316
1317                         break;
1318         case Ndis802_11IBSS:
1319                         pmlmepriv->fw_state = WIFI_ADHOC_STATE;
1320                         break;
1321         default:
1322                         pmlmepriv->fw_state = WIFI_NULL_STATE;
1323                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
1324                         break;
1325         }
1326
1327         rtw_update_protection(padapter, (cur_network->network.IEs) + sizeof(struct ndis_802_11_fix_ie),
1328                                                                         (cur_network->network.IELength));
1329
1330         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength, (u8) cur_network->network.Configuration.DSConfig);
1331 }
1332
1333 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
1334 /* pnetwork : returns from rtw_joinbss_event_callback */
1335 /* ptarget_wlan: found from scanned_queue */
1336 /* if join_res > 0, for (fw_state ==WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
1337 /* if join_res > 0, for (fw_state ==WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
1338 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
1339 /*  */
1340 /* define REJOIN */
1341 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
1342 {
1343         static u8 retry;
1344         u8 timer_cancelled;
1345         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
1346         struct  sta_priv *pstapriv = &adapter->stapriv;
1347         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1348         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1349         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1350         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1351         unsigned int            the_same_macaddr = false;
1352
1353         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res =%d\n", pnetwork->join_res));
1354
1355         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1356
1357
1358         if (pmlmepriv->assoc_ssid.SsidLength == 0) {
1359                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
1360         } else {
1361                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
1362         }
1363
1364         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1365
1366         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1367         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
1368                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1369                 return;
1370         }
1371
1372         spin_lock_bh(&pmlmepriv->lock);
1373
1374         pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 0;
1375         pmlmepriv->LinkDetectInfo.LowPowerTransitionCount = 0;
1376
1377         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\n rtw_joinbss_event_callback !! spin_lock_irqsave\n"));
1378
1379         if (pnetwork->join_res > 0) {
1380                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1381                 retry = 0;
1382                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1383                         /* s1. find ptarget_wlan */
1384                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1385                                 if (the_same_macaddr == true) {
1386                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1387                                 } else {
1388                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1389                                         if (pcur_wlan)
1390                                                 pcur_wlan->fixed = false;
1391
1392                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1393                                         if (pcur_sta)
1394                                                 rtw_free_stainfo(adapter,  pcur_sta);
1395
1396                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1397                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1398                                                 if (ptarget_wlan)
1399                                                         ptarget_wlan->fixed = true;
1400                                         }
1401                                 }
1402
1403                         } else {
1404                                 ptarget_wlan = _rtw_find_same_network(&pmlmepriv->scanned_queue, pnetwork);
1405                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1406                                         if (ptarget_wlan)
1407                                                 ptarget_wlan->fixed = true;
1408                                 }
1409                         }
1410
1411                         /* s2. update cur_network */
1412                         if (ptarget_wlan) {
1413                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1414                         } else {
1415                                 DBG_871X_LEVEL(_drv_always_, "Can't find ptarget_wlan when joinbss_event callback\n");
1416                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1417                                 goto ignore_joinbss_callback;
1418                         }
1419
1420
1421                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1422                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1423                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1424                                 if (ptarget_sta == NULL) {
1425                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1426                                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1427                                         goto ignore_joinbss_callback;
1428                                 }
1429                         }
1430
1431                         /* s4. indicate connect */
1432                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1433                                 pmlmepriv->cur_network_scanned = ptarget_wlan;
1434                                 rtw_indicate_connect(adapter);
1435                         } else {
1436                                 /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1437                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1438                         }
1439
1440
1441                         /* s5. Cancel assoc_timer */
1442                         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
1443
1444                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancel assoc_timer\n"));
1445
1446                 } else {
1447                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1448                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1449                         goto ignore_joinbss_callback;
1450                 }
1451
1452                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1453
1454         } else if (pnetwork->join_res == -4) {
1455                 rtw_reset_securitypriv(adapter);
1456                 _set_timer(&pmlmepriv->assoc_timer, 1);
1457
1458                 /* rtw_free_assoc_resources(adapter, 1); */
1459
1460                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true) {
1461                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state =%x\n", get_fwstate(pmlmepriv)));
1462                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1463                 }
1464
1465         } else {/* if join_res < 0 (join fails), then try again */
1466
1467                 #ifdef REJOIN
1468                 res = _FAIL;
1469                 if (retry < 2) {
1470                         res = rtw_select_and_join_from_scanned_queue(pmlmepriv);
1471                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_select_and_join_from_scanned_queue again! res:%d\n", res));
1472                 }
1473
1474                 if (res == _SUCCESS) {
1475                         /* extend time of assoc_timer */
1476                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
1477                         retry++;
1478                 } else if (res == 2) {/* there is no need to wait for join */
1479                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1480                         rtw_indicate_connect(adapter);
1481                 } else {
1482                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Set Assoc_Timer = 1; can't find match ssid in scanned_q\n"));
1483                 #endif
1484
1485                         _set_timer(&pmlmepriv->assoc_timer, 1);
1486                         /* rtw_free_assoc_resources(adapter, 1); */
1487                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1488
1489                 #ifdef REJOIN
1490                         retry = 0;
1491                 }
1492                 #endif
1493         }
1494
1495 ignore_joinbss_callback:
1496
1497         spin_unlock_bh(&pmlmepriv->lock);
1498 }
1499
1500 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1501 {
1502         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1503
1504         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1505
1506         rtw_os_xmit_schedule(adapter);
1507 }
1508
1509 /* FOR STA, AP , AD-HOC mode */
1510 void rtw_sta_media_status_rpt(struct adapter *adapter, struct sta_info *psta, u32 mstatus)
1511 {
1512         u16 media_status_rpt;
1513
1514         if (psta == NULL)
1515                 return;
1516
1517         media_status_rpt = (u16)((psta->mac_id<<8)|mstatus); /*   MACID|OPMODE:1 connect */
1518         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status_rpt);
1519 }
1520
1521 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1522 {
1523         struct sta_info *psta;
1524         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1525         struct stassoc_event    *pstassoc       = (struct stassoc_event *)pbuf;
1526         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1527         struct wlan_network     *ptarget_wlan = NULL;
1528
1529         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1530                 return;
1531
1532         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1533                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1534                 if (psta) {
1535                         u8 *passoc_req = NULL;
1536                         u32 assoc_req_len = 0;
1537
1538                         rtw_sta_media_status_rpt(adapter, psta, 1);
1539
1540 #ifndef CONFIG_AUTO_AP_MODE
1541
1542                         ap_sta_info_defer_update(adapter, psta);
1543
1544                         /* report to upper layer */
1545                         DBG_871X("indicate_sta_assoc_event to upper layer - hostapd\n");
1546                         spin_lock_bh(&psta->lock);
1547                         if (psta->passoc_req && psta->assoc_req_len > 0) {
1548                                 passoc_req = rtw_zmalloc(psta->assoc_req_len);
1549                                 if (passoc_req) {
1550                                         assoc_req_len = psta->assoc_req_len;
1551                                         memcpy(passoc_req, psta->passoc_req, assoc_req_len);
1552
1553                                         kfree(psta->passoc_req);
1554                                         psta->passoc_req = NULL;
1555                                         psta->assoc_req_len = 0;
1556                                 }
1557                         }
1558                         spin_unlock_bh(&psta->lock);
1559
1560                         if (passoc_req && assoc_req_len > 0) {
1561                                 rtw_cfg80211_indicate_sta_assoc(adapter, passoc_req, assoc_req_len);
1562
1563                                 kfree(passoc_req);
1564                         }
1565 #endif /* CONFIG_AUTO_AP_MODE */
1566                 }
1567                 return;
1568         }
1569
1570         /* for AD-HOC mode */
1571         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1572         if (psta != NULL) {
1573                 /* the sta have been in sta_info_queue => do nothing */
1574
1575                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1576
1577                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1578         }
1579
1580         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1581         if (psta == NULL) {
1582                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1583                 return;
1584         }
1585
1586         /* to do : init sta_info variable */
1587         psta->qos_option = 0;
1588         psta->mac_id = (uint)pstassoc->cam_id;
1589         /* psta->aid = (uint)pstassoc->cam_id; */
1590         DBG_871X("%s\n", __func__);
1591         /* for ad-hoc mode */
1592         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1593
1594         rtw_sta_media_status_rpt(adapter, psta, 1);
1595
1596         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1597                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1598
1599
1600         psta->ieee8021x_blocked = false;
1601
1602         spin_lock_bh(&pmlmepriv->lock);
1603
1604         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
1605                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
1606                 if (adapter->stapriv.asoc_sta_count == 2) {
1607                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1608                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1609                         pmlmepriv->cur_network_scanned = ptarget_wlan;
1610                         if (ptarget_wlan)
1611                                 ptarget_wlan->fixed = true;
1612                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1613                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1614                         rtw_indicate_connect(adapter);
1615                 }
1616         }
1617
1618         spin_unlock_bh(&pmlmepriv->lock);
1619
1620
1621         mlmeext_sta_add_event_callback(adapter, psta);
1622 }
1623
1624 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1625 {
1626         int mac_id = (-1);
1627         struct sta_info *psta;
1628         struct wlan_network *pwlan = NULL;
1629         struct wlan_bssid_ex    *pdev_network = NULL;
1630         u8 *pibss = NULL;
1631         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1632         struct  stadel_event *pstadel   = (struct stadel_event *)pbuf;
1633         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1634         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1635         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1636
1637         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1638         if (psta)
1639                 mac_id = psta->mac_id;
1640         else
1641                 mac_id = pstadel->mac_id;
1642
1643         DBG_871X("%s(mac_id =%d) =" MAC_FMT "\n", __func__, mac_id, MAC_ARG(pstadel->macaddr));
1644
1645         if (mac_id >= 0) {
1646                 u16 media_status;
1647                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1648                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1649                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1650         }
1651
1652         /* if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) */
1653         if ((pmlmeinfo->state&0x03) == WIFI_FW_AP_STATE)
1654                 return;
1655
1656
1657         mlmeext_sta_del_event_callback(adapter);
1658
1659         spin_lock_bh(&pmlmepriv->lock);
1660
1661         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1662                 u16 reason = *((unsigned short *)(pstadel->rsvd));
1663                 bool roam = false;
1664                 struct wlan_network *roam_target = NULL;
1665
1666                 if (adapter->registrypriv.wifi_spec == 1) {
1667                         roam = false;
1668                 } else if (reason == WLAN_REASON_EXPIRATION_CHK && rtw_chk_roam_flags(adapter, RTW_ROAM_ON_EXPIRED)) {
1669                         roam = true;
1670                 } else if (reason == WLAN_REASON_ACTIVE_ROAM && rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1671                         roam = true;
1672                         roam_target = pmlmepriv->roam_network;
1673                 }
1674
1675                 if (roam == true) {
1676                         if (rtw_to_roam(adapter) > 0)
1677                                 rtw_dec_to_roam(adapter); /* this stadel_event is caused by roaming, decrease to_roam */
1678                         else if (rtw_to_roam(adapter) == 0)
1679                                 rtw_set_to_roam(adapter, adapter->registrypriv.max_roaming_times);
1680                 } else {
1681                         rtw_set_to_roam(adapter, 0);
1682                 }
1683
1684                 rtw_free_uc_swdec_pending_queue(adapter);
1685
1686                 rtw_free_assoc_resources(adapter, 1);
1687                 rtw_indicate_disconnect(adapter);
1688
1689                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1690                 /*  remove the network entry in scanned_queue */
1691                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1692                 if (pwlan) {
1693                         pwlan->fixed = false;
1694                         rtw_free_network_nolock(adapter, pwlan);
1695                 }
1696                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1697
1698                 _rtw_roaming(adapter, roam_target);
1699         }
1700
1701         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1702               check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1703
1704                 rtw_free_stainfo(adapter,  psta);
1705
1706                 if (adapter->stapriv.asoc_sta_count == 1) {/* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1707                         /* rtw_indicate_disconnect(adapter);removed@20091105 */
1708                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1709                         /* free old ibss network */
1710                         /* pwlan = rtw_find_network(&pmlmepriv->scanned_queue, pstadel->macaddr); */
1711                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1712                         if (pwlan) {
1713                                 pwlan->fixed = false;
1714                                 rtw_free_network_nolock(adapter, pwlan);
1715                         }
1716                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1717                         /* re-create ibss */
1718                         pdev_network = &(adapter->registrypriv.dev_network);
1719                         pibss = adapter->registrypriv.dev_network.MacAddress;
1720
1721                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1722
1723                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1724
1725                         rtw_update_registrypriv_dev_network(adapter);
1726
1727                         rtw_generate_random_ibss(pibss);
1728
1729                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1730                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1731                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1732                         }
1733
1734                         if (rtw_createbss_cmd(adapter) != _SUCCESS) {
1735
1736                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error =>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1737
1738                         }
1739
1740
1741                 }
1742
1743         }
1744
1745         spin_unlock_bh(&pmlmepriv->lock);
1746 }
1747
1748 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1749 {
1750         struct reportpwrstate_parm *preportpwrstate;
1751
1752         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1753         preportpwrstate = (struct reportpwrstate_parm *)pbuf;
1754         preportpwrstate->state |= (u8)(adapter_to_pwrctl(padapter)->cpwm_tog + 0x80);
1755         cpwm_int_hdl(padapter, preportpwrstate);
1756 }
1757
1758
1759 void rtw_wmm_event_callback(struct adapter *padapter, u8 *pbuf)
1760 {
1761         WMMOnAssocRsp(padapter);
1762 }
1763
1764 /*
1765 * _rtw_join_timeout_handler - Timeout/failure handler for CMD JoinBss
1766 * @adapter: pointer to struct adapter structure
1767 */
1768 void _rtw_join_timeout_handler(struct timer_list *t)
1769 {
1770         struct adapter *adapter = from_timer(adapter, t,
1771                                                   mlmepriv.assoc_timer);
1772         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1773
1774         DBG_871X("%s, fw_state =%x\n", __func__, get_fwstate(pmlmepriv));
1775
1776         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1777                 return;
1778
1779         spin_lock_bh(&pmlmepriv->lock);
1780
1781         if (rtw_to_roam(adapter) > 0) { /* join timeout caused by roaming */
1782                 while (1) {
1783                         rtw_dec_to_roam(adapter);
1784                         if (rtw_to_roam(adapter) != 0) { /* try another */
1785                                 int do_join_r;
1786                                 DBG_871X("%s try another roaming\n", __func__);
1787                                 do_join_r = rtw_do_join(adapter);
1788                                 if (_SUCCESS != do_join_r) {
1789                                         DBG_871X("%s roaming do_join return %d\n", __func__, do_join_r);
1790                                         continue;
1791                                 }
1792                                 break;
1793                         } else {
1794                                 DBG_871X("%s We've try roaming but fail\n", __func__);
1795                                 rtw_indicate_disconnect(adapter);
1796                                 break;
1797                         }
1798                 }
1799
1800         } else {
1801                 rtw_indicate_disconnect(adapter);
1802                 free_scanqueue(pmlmepriv);/*  */
1803
1804                 /* indicate disconnect for the case that join_timeout and check_fwstate != FW_LINKED */
1805                 rtw_cfg80211_indicate_disconnect(adapter);
1806
1807         }
1808
1809         spin_unlock_bh(&pmlmepriv->lock);
1810 }
1811
1812 /*
1813 * rtw_scan_timeout_handler - Timeout/Failure handler for CMD SiteSurvey
1814 * @adapter: pointer to struct adapter structure
1815 */
1816 void rtw_scan_timeout_handler(struct timer_list *t)
1817 {
1818         struct adapter *adapter = from_timer(adapter, t,
1819                                                   mlmepriv.scan_to_timer);
1820         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1821
1822         DBG_871X(FUNC_ADPT_FMT" fw_state =%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1823
1824         spin_lock_bh(&pmlmepriv->lock);
1825
1826         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1827
1828         spin_unlock_bh(&pmlmepriv->lock);
1829
1830         rtw_indicate_scan_done(adapter, true);
1831 }
1832
1833 void rtw_mlme_reset_auto_scan_int(struct adapter *adapter)
1834 {
1835         struct mlme_priv *mlme = &adapter->mlmepriv;
1836         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1837         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1838
1839         if (pmlmeinfo->VHT_enable) /* disable auto scan when connect to 11AC AP */
1840                 mlme->auto_scan_int_ms = 0;
1841         else if (adapter->registrypriv.wifi_spec && is_client_associated_to_ap(adapter) == true)
1842                 mlme->auto_scan_int_ms = 60*1000;
1843         else if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1844                 if (check_fwstate(mlme, WIFI_STATION_STATE) && check_fwstate(mlme, _FW_LINKED))
1845                         mlme->auto_scan_int_ms = mlme->roam_scan_int_ms;
1846         } else
1847                 mlme->auto_scan_int_ms = 0; /* disabled */
1848
1849         return;
1850 }
1851
1852 static void rtw_auto_scan_handler(struct adapter *padapter)
1853 {
1854         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1855
1856         rtw_mlme_reset_auto_scan_int(padapter);
1857
1858         if (pmlmepriv->auto_scan_int_ms != 0
1859                 && jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time) > pmlmepriv->auto_scan_int_ms) {
1860
1861                 if (!padapter->registrypriv.wifi_spec) {
1862                         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == true) {
1863                                 DBG_871X(FUNC_ADPT_FMT" _FW_UNDER_SURVEY|_FW_UNDER_LINKING\n", FUNC_ADPT_ARG(padapter));
1864                                 goto exit;
1865                         }
1866
1867                         if (pmlmepriv->LinkDetectInfo.bBusyTraffic == true) {
1868                                 DBG_871X(FUNC_ADPT_FMT" exit BusyTraffic\n", FUNC_ADPT_ARG(padapter));
1869                                 goto exit;
1870                         }
1871                 }
1872
1873                 DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1874
1875                 rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1876         }
1877
1878 exit:
1879         return;
1880 }
1881
1882 void rtw_dynamic_check_timer_handler(struct adapter *adapter)
1883 {
1884         if (!adapter)
1885                 return;
1886
1887         if (adapter->hw_init_completed == false)
1888                 return;
1889
1890         if ((adapter->bDriverStopped == true) || (adapter->bSurpriseRemoved == true))
1891                 return;
1892
1893         if (adapter->net_closed == true)
1894                 return;
1895
1896         if (is_primary_adapter(adapter))
1897                 DBG_871X("IsBtDisabled =%d, IsBtControlLps =%d\n", rtw_btcoex_IsBtDisabled(adapter), rtw_btcoex_IsBtControlLps(adapter));
1898
1899         if ((adapter_to_pwrctl(adapter)->bFwCurrentInPSMode == true)
1900                 && (rtw_btcoex_IsBtControlLps(adapter) == false)
1901                 ) {
1902                 u8 bEnterPS;
1903
1904                 linked_status_chk(adapter);
1905
1906                 bEnterPS = traffic_status_watchdog(adapter, 1);
1907                 if (bEnterPS) {
1908                         /* rtw_lps_ctrl_wk_cmd(adapter, LPS_CTRL_ENTER, 1); */
1909                         rtw_hal_dm_watchdog_in_lps(adapter);
1910                 } else {
1911                         /* call rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_LEAVE, 1) in traffic_status_watchdog() */
1912                 }
1913
1914         } else {
1915                 if (is_primary_adapter(adapter)) {
1916                         rtw_dynamic_chk_wk_cmd(adapter);
1917                 }
1918         }
1919
1920         /* auto site survey */
1921         rtw_auto_scan_handler(adapter);
1922 }
1923
1924
1925 inline bool rtw_is_scan_deny(struct adapter *adapter)
1926 {
1927         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1928         return (atomic_read(&mlmepriv->set_scan_deny) != 0) ? true : false;
1929 }
1930
1931 inline void rtw_clear_scan_deny(struct adapter *adapter)
1932 {
1933         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1934         atomic_set(&mlmepriv->set_scan_deny, 0);
1935
1936         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
1937 }
1938
1939 void rtw_set_scan_deny_timer_hdl(struct adapter *adapter)
1940 {
1941         rtw_clear_scan_deny(adapter);
1942 }
1943
1944 void rtw_set_scan_deny(struct adapter *adapter, u32 ms)
1945 {
1946         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1947
1948         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
1949         atomic_set(&mlmepriv->set_scan_deny, 1);
1950         _set_timer(&mlmepriv->set_scan_deny_timer, ms);
1951 }
1952
1953 /*
1954 * Select a new roaming candidate from the original @param candidate and @param competitor
1955 * @return true: candidate is updated
1956 * @return false: candidate is not updated
1957 */
1958 static int rtw_check_roaming_candidate(struct mlme_priv *mlme
1959         , struct wlan_network **candidate, struct wlan_network *competitor)
1960 {
1961         int updated = false;
1962         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
1963
1964         if (is_same_ess(&competitor->network, &mlme->cur_network.network) == false)
1965                 goto exit;
1966
1967         if (rtw_is_desired_network(adapter, competitor) == false)
1968                 goto exit;
1969
1970         DBG_871X("roam candidate:%s %s("MAC_FMT", ch%3u) rssi:%d, age:%5d\n",
1971                 (competitor == mlme->cur_network_scanned)?"*":" ",
1972                 competitor->network.Ssid.Ssid,
1973                 MAC_ARG(competitor->network.MacAddress),
1974                 competitor->network.Configuration.DSConfig,
1975                 (int)competitor->network.Rssi,
1976                 jiffies_to_msecs(jiffies - competitor->last_scanned)
1977         );
1978
1979         /* got specific addr to roam */
1980         if (!is_zero_mac_addr(mlme->roam_tgt_addr)) {
1981                 if (!memcmp(mlme->roam_tgt_addr, competitor->network.MacAddress, ETH_ALEN))
1982                         goto update;
1983                 else
1984                         goto exit;
1985         }
1986         if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms)
1987                 goto exit;
1988
1989         if (competitor->network.Rssi - mlme->cur_network_scanned->network.Rssi < mlme->roam_rssi_diff_th)
1990                 goto exit;
1991
1992         if (*candidate != NULL && (*candidate)->network.Rssi >= competitor->network.Rssi)
1993                 goto exit;
1994
1995 update:
1996         *candidate = competitor;
1997         updated = true;
1998
1999 exit:
2000         return updated;
2001 }
2002
2003 int rtw_select_roaming_candidate(struct mlme_priv *mlme)
2004 {
2005         int ret = _FAIL;
2006         struct list_head        *phead;
2007         struct adapter *adapter;
2008         struct __queue  *queue  = &(mlme->scanned_queue);
2009         struct  wlan_network    *pnetwork = NULL;
2010         struct  wlan_network    *candidate = NULL;
2011
2012         if (mlme->cur_network_scanned == NULL) {
2013                 rtw_warn_on(1);
2014                 return ret;
2015         }
2016
2017         spin_lock_bh(&(mlme->scanned_queue.lock));
2018         phead = get_list_head(queue);
2019         adapter = (struct adapter *)mlme->nic_hdl;
2020
2021         mlme->pscanned = get_next(phead);
2022
2023         while (phead != mlme->pscanned) {
2024
2025                 pnetwork = LIST_CONTAINOR(mlme->pscanned, struct wlan_network, list);
2026                 if (pnetwork == NULL) {
2027                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2028                         ret = _FAIL;
2029                         goto exit;
2030                 }
2031
2032                 mlme->pscanned = get_next(mlme->pscanned);
2033
2034                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2035                         , pnetwork->network.Ssid.Ssid
2036                         , MAC_ARG(pnetwork->network.MacAddress)
2037                         , pnetwork->network.Configuration.DSConfig
2038                         , (int)pnetwork->network.Rssi);
2039
2040                 rtw_check_roaming_candidate(mlme, &candidate, pnetwork);
2041
2042         }
2043
2044         if (candidate == NULL) {
2045                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2046                 ret = _FAIL;
2047                 goto exit;
2048         } else {
2049                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2050                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2051                         candidate->network.Configuration.DSConfig);
2052
2053                 mlme->roam_network = candidate;
2054
2055                 if (!memcmp(candidate->network.MacAddress, mlme->roam_tgt_addr, ETH_ALEN))
2056                         eth_zero_addr(mlme->roam_tgt_addr);
2057         }
2058
2059         ret = _SUCCESS;
2060 exit:
2061         spin_unlock_bh(&(mlme->scanned_queue.lock));
2062
2063         return ret;
2064 }
2065
2066 /*
2067 * Select a new join candidate from the original @param candidate and @param competitor
2068 * @return true: candidate is updated
2069 * @return false: candidate is not updated
2070 */
2071 static int rtw_check_join_candidate(struct mlme_priv *mlme
2072         , struct wlan_network **candidate, struct wlan_network *competitor)
2073 {
2074         int updated = false;
2075         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
2076
2077
2078         /* check bssid, if needed */
2079         if (mlme->assoc_by_bssid == true) {
2080                 if (memcmp(competitor->network.MacAddress, mlme->assoc_bssid, ETH_ALEN))
2081                         goto exit;
2082         }
2083
2084         /* check ssid, if needed */
2085         if (mlme->assoc_ssid.Ssid[0] && mlme->assoc_ssid.SsidLength) {
2086                 if (competitor->network.Ssid.SsidLength != mlme->assoc_ssid.SsidLength
2087                         || memcmp(competitor->network.Ssid.Ssid, mlme->assoc_ssid.Ssid, mlme->assoc_ssid.SsidLength)
2088                 )
2089                         goto exit;
2090         }
2091
2092         if (rtw_is_desired_network(adapter, competitor)  == false)
2093                 goto exit;
2094
2095         if (rtw_to_roam(adapter) > 0) {
2096                 if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms
2097                         || is_same_ess(&competitor->network, &mlme->cur_network.network) == false
2098                 )
2099                         goto exit;
2100         }
2101
2102         if (*candidate == NULL || (*candidate)->network.Rssi < competitor->network.Rssi) {
2103                 *candidate = competitor;
2104                 updated = true;
2105         }
2106
2107         if (updated) {
2108                 DBG_871X("[by_bssid:%u][assoc_ssid:%s]"
2109                         "[to_roam:%u] "
2110                         "new candidate: %s("MAC_FMT", ch%u) rssi:%d\n",
2111                         mlme->assoc_by_bssid,
2112                         mlme->assoc_ssid.Ssid,
2113                         rtw_to_roam(adapter),
2114                         (*candidate)->network.Ssid.Ssid,
2115                         MAC_ARG((*candidate)->network.MacAddress),
2116                         (*candidate)->network.Configuration.DSConfig,
2117                         (int)(*candidate)->network.Rssi
2118                 );
2119         }
2120
2121 exit:
2122         return updated;
2123 }
2124
2125 /*
2126 Calling context:
2127 The caller of the sub-routine will be in critical section...
2128
2129 The caller must hold the following spinlock
2130
2131 pmlmepriv->lock
2132
2133
2134 */
2135
2136 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
2137 {
2138         int ret;
2139         struct list_head        *phead;
2140         struct adapter *adapter;
2141         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
2142         struct  wlan_network    *pnetwork = NULL;
2143         struct  wlan_network    *candidate = NULL;
2144
2145         adapter = (struct adapter *)pmlmepriv->nic_hdl;
2146
2147         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
2148
2149         if (pmlmepriv->roam_network) {
2150                 candidate = pmlmepriv->roam_network;
2151                 pmlmepriv->roam_network = NULL;
2152                 goto candidate_exist;
2153         }
2154
2155         phead = get_list_head(queue);
2156         pmlmepriv->pscanned = get_next(phead);
2157
2158         while (phead != pmlmepriv->pscanned) {
2159
2160                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
2161                 if (pnetwork == NULL) {
2162                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2163                         ret = _FAIL;
2164                         goto exit;
2165                 }
2166
2167                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
2168
2169                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2170                         , pnetwork->network.Ssid.Ssid
2171                         , MAC_ARG(pnetwork->network.MacAddress)
2172                         , pnetwork->network.Configuration.DSConfig
2173                         , (int)pnetwork->network.Rssi);
2174
2175                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
2176
2177         }
2178
2179         if (candidate == NULL) {
2180                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2181 #ifdef CONFIG_WOWLAN
2182                 _clr_fwstate_(pmlmepriv, _FW_LINKED|_FW_UNDER_LINKING);
2183 #endif
2184                 ret = _FAIL;
2185                 goto exit;
2186         } else {
2187                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2188                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2189                         candidate->network.Configuration.DSConfig);
2190                 goto candidate_exist;
2191         }
2192
2193 candidate_exist:
2194
2195         /*  check for situation of  _FW_LINKED */
2196         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
2197                 DBG_871X("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
2198
2199                 rtw_disassoc_cmd(adapter, 0, true);
2200                 rtw_indicate_disconnect(adapter);
2201                 rtw_free_assoc_resources(adapter, 0);
2202         }
2203
2204         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
2205         ret = rtw_joinbss_cmd(adapter, candidate);
2206
2207 exit:
2208         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
2209         return ret;
2210 }
2211
2212 sint rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
2213 {
2214         struct  cmd_obj *pcmd;
2215         struct  setauth_parm *psetauthparm;
2216         struct  cmd_priv *pcmdpriv = &(adapter->cmdpriv);
2217         sint            res = _SUCCESS;
2218
2219         pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
2220         if (pcmd == NULL) {
2221                 res = _FAIL;  /* try again */
2222                 goto exit;
2223         }
2224
2225         psetauthparm = rtw_zmalloc(sizeof(struct setauth_parm));
2226         if (psetauthparm == NULL) {
2227                 kfree((unsigned char *)pcmd);
2228                 res = _FAIL;
2229                 goto exit;
2230         }
2231
2232         memset(psetauthparm, 0, sizeof(struct setauth_parm));
2233         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
2234
2235         pcmd->cmdcode = _SetAuth_CMD_;
2236         pcmd->parmbuf = (unsigned char *)psetauthparm;
2237         pcmd->cmdsz =  (sizeof(struct setauth_parm));
2238         pcmd->rsp = NULL;
2239         pcmd->rspsz = 0;
2240
2241
2242         INIT_LIST_HEAD(&pcmd->list);
2243
2244         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("after enqueue set_auth_cmd, auth_mode =%x\n", psecuritypriv->dot11AuthAlgrthm));
2245
2246         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2247
2248 exit:
2249         return res;
2250 }
2251
2252 sint rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, sint keyid, u8 set_tx, bool enqueue)
2253 {
2254         u8 keylen;
2255         struct cmd_obj          *pcmd;
2256         struct setkey_parm      *psetkeyparm;
2257         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
2258         sint    res = _SUCCESS;
2259
2260         psetkeyparm = rtw_zmalloc(sizeof(struct setkey_parm));
2261         if (psetkeyparm == NULL) {
2262                 res = _FAIL;
2263                 goto exit;
2264         }
2265         memset(psetkeyparm, 0, sizeof(struct setkey_parm));
2266
2267         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
2268                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
2269                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(unsigned char)psecuritypriv->dot118021XGrpPrivacy =%d\n", psetkeyparm->algorithm));
2270         } else {
2271                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
2272                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(u8)psecuritypriv->dot11PrivacyAlgrthm =%d\n", psetkeyparm->algorithm));
2273
2274         }
2275         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
2276         psetkeyparm->set_tx = set_tx;
2277         if (is_wep_enc(psetkeyparm->algorithm))
2278                 adapter->securitypriv.key_mask |= BIT(psetkeyparm->keyid);
2279
2280         DBG_871X("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n", psetkeyparm->algorithm, psetkeyparm->keyid, adapter->securitypriv.key_mask);
2281         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =%d psetkeyparm->keyid =(u8)keyid =%d\n", psetkeyparm->algorithm, keyid));
2282
2283         switch (psetkeyparm->algorithm) {
2284
2285         case _WEP40_:
2286                 keylen = 5;
2287                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2288                 break;
2289         case _WEP104_:
2290                 keylen = 13;
2291                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2292                 break;
2293         case _TKIP_:
2294                 keylen = 16;
2295                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2296                 psetkeyparm->grpkey = 1;
2297                 break;
2298         case _AES_:
2299                 keylen = 16;
2300                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2301                 psetkeyparm->grpkey = 1;
2302                 break;
2303         default:
2304                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm = %x (must be 1 or 2 or 4 or 5)\n", psecuritypriv->dot11PrivacyAlgrthm));
2305                 res = _FAIL;
2306                 kfree((unsigned char *)psetkeyparm);
2307                 goto exit;
2308         }
2309
2310
2311         if (enqueue) {
2312                 pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
2313                 if (pcmd == NULL) {
2314                         kfree((unsigned char *)psetkeyparm);
2315                         res = _FAIL;  /* try again */
2316                         goto exit;
2317                 }
2318
2319                 pcmd->cmdcode = _SetKey_CMD_;
2320                 pcmd->parmbuf = (u8 *)psetkeyparm;
2321                 pcmd->cmdsz =  (sizeof(struct setkey_parm));
2322                 pcmd->rsp = NULL;
2323                 pcmd->rspsz = 0;
2324
2325                 INIT_LIST_HEAD(&pcmd->list);
2326
2327                 res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2328         } else {
2329                 setkey_hdl(adapter, (u8 *)psetkeyparm);
2330                 kfree((u8 *) psetkeyparm);
2331         }
2332 exit:
2333         return res;
2334 }
2335
2336 /* adjust IEs for rtw_joinbss_cmd in WMM */
2337 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
2338 {
2339         unsigned        int ielength = 0;
2340         unsigned int i, j;
2341
2342         i = 12; /* after the fixed IE */
2343         while (i < in_len) {
2344                 ielength = initial_out_len;
2345
2346                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) { /* WMM element ID and OUI */
2347                         for (j = i; j < i + 9; j++) {
2348                                         out_ie[ielength] = in_ie[j];
2349                                         ielength++;
2350                         }
2351                         out_ie[initial_out_len + 1] = 0x07;
2352                         out_ie[initial_out_len + 6] = 0x00;
2353                         out_ie[initial_out_len + 8] = 0x00;
2354
2355                         break;
2356                 }
2357
2358                 i += (in_ie[i+1]+2); /*  to the next IE element */
2359         }
2360
2361         return ielength;
2362
2363 }
2364
2365
2366 /*  */
2367 /*  Ported from 8185: IsInPreAuthKeyList(). (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.) */
2368 /*  Added by Annie, 2006-05-07. */
2369 /*  */
2370 /*  Search by BSSID, */
2371 /*  Return Value: */
2372 /*              -1              :if there is no pre-auth key in the  table */
2373 /*              >= 0            :if there is pre-auth key, and   return the entry id */
2374 /*  */
2375 /*  */
2376
2377 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
2378 {
2379         struct security_priv *psecuritypriv = &Adapter->securitypriv;
2380         int i = 0;
2381
2382         do {
2383                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
2384                                 (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN))) {
2385                         break;
2386                 } else {
2387                         i++;
2388                         /* continue; */
2389                 }
2390
2391         } while (i < NUM_PMKID_CACHE);
2392
2393         if (i == NUM_PMKID_CACHE) {
2394                 i = -1;/*  Could not find. */
2395         } else {
2396                 /*  There is one Pre-Authentication Key for the specific BSSID. */
2397         }
2398
2399         return i;
2400
2401 }
2402
2403 /*  */
2404 /*  Check the RSN IE length */
2405 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
2406 /*  0-11th element in the array are the fixed IE */
2407 /*  12th element in the array is the IE */
2408 /*  13th element in the array is the IE length */
2409 /*  */
2410
2411 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
2412 {
2413         struct security_priv *psecuritypriv = &Adapter->securitypriv;
2414
2415         if (ie[13] <= 20) {
2416                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
2417                         ie[ie_len] = 1;
2418                         ie_len++;
2419                         ie[ie_len] = 0; /* PMKID count = 0x0100 */
2420                         ie_len++;
2421                         memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
2422
2423                         ie_len += 16;
2424                         ie[13] += 18;/* PMKID length = 2+16 */
2425
2426         }
2427         return ie_len;
2428 }
2429
2430 sint rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
2431 {
2432         u8 authmode = 0x0;
2433         uint    ielength;
2434         int iEntry;
2435
2436         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
2437         struct security_priv *psecuritypriv = &adapter->securitypriv;
2438         uint    ndisauthmode = psecuritypriv->ndisauthtype;
2439
2440         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
2441                  ("+rtw_restruct_sec_ie: ndisauthmode =%d\n", ndisauthmode));
2442
2443         /* copy fixed ie only */
2444         memcpy(out_ie, in_ie, 12);
2445         ielength = 12;
2446         if ((ndisauthmode == Ndis802_11AuthModeWPA) || (ndisauthmode == Ndis802_11AuthModeWPAPSK))
2447                         authmode = _WPA_IE_ID_;
2448         if ((ndisauthmode == Ndis802_11AuthModeWPA2) || (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
2449                         authmode = _WPA2_IE_ID_;
2450
2451         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
2452                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
2453
2454                 ielength += psecuritypriv->wps_ie_len;
2455         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
2456                 /* copy RSN or SSN */
2457                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
2458                 /* debug for CONFIG_IEEE80211W
2459                 {
2460                         int jj;
2461                         printk("supplicant_ie_length =%d &&&&&&&&&&&&&&&&&&&\n", psecuritypriv->supplicant_ie[1]+2);
2462                         for (jj = 0; jj < psecuritypriv->supplicant_ie[1]+2; jj++)
2463                                 printk(" %02x ", psecuritypriv->supplicant_ie[jj]);
2464                         printk("\n");
2465                 }*/
2466                 ielength += psecuritypriv->supplicant_ie[1]+2;
2467                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
2468         }
2469
2470         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
2471         if (iEntry < 0) {
2472                 return ielength;
2473         } else {
2474                 if (authmode == _WPA2_IE_ID_)
2475                         ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
2476         }
2477         return ielength;
2478 }
2479
2480 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
2481 {
2482         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2483         struct eeprom_priv *peepriv = &adapter->eeprompriv;
2484         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2485         u8 *myhwaddr = myid(peepriv);
2486
2487         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
2488
2489         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
2490
2491         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_conf);
2492         pdev_network->Configuration.BeaconPeriod = 100;
2493         pdev_network->Configuration.FHConfig.Length = 0;
2494         pdev_network->Configuration.FHConfig.HopPattern = 0;
2495         pdev_network->Configuration.FHConfig.HopSet = 0;
2496         pdev_network->Configuration.FHConfig.DwellTime = 0;
2497 }
2498
2499 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
2500 {
2501         int sz = 0;
2502         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2503         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2504         struct  security_priv *psecuritypriv = &adapter->securitypriv;
2505         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
2506         /* struct       xmit_priv *pxmitpriv = &adapter->xmitpriv; */
2507
2508         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0) ; /*  adhoc no 802.1x */
2509
2510         pdev_network->Rssi = 0;
2511
2512         switch (pregistrypriv->wireless_mode) {
2513         case WIRELESS_11B:
2514                 pdev_network->NetworkTypeInUse = (Ndis802_11DS);
2515                 break;
2516         case WIRELESS_11G:
2517         case WIRELESS_11BG:
2518         case WIRELESS_11_24N:
2519         case WIRELESS_11G_24N:
2520         case WIRELESS_11BG_24N:
2521                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2522                 break;
2523         case WIRELESS_11A:
2524         case WIRELESS_11A_5N:
2525                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2526                 break;
2527         case WIRELESS_11ABGN:
2528                 if (pregistrypriv->channel > 14)
2529                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2530                 else
2531                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2532                 break;
2533         default:
2534                 /*  TODO */
2535                 break;
2536         }
2537
2538         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
2539         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("pregistrypriv->channel =%d, pdev_network->Configuration.DSConfig = 0x%x\n", pregistrypriv->channel, pdev_network->Configuration.DSConfig));
2540
2541         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
2542                 pdev_network->Configuration.ATIMWindow = (0);
2543
2544         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
2545
2546         /*  1. Supported rates */
2547         /*  2. IE */
2548
2549         /* rtw_set_supported_rate(pdev_network->SupportedRates, pregistrypriv->wireless_mode) ;  will be called in rtw_generate_ie */
2550         sz = rtw_generate_ie(pregistrypriv);
2551
2552         pdev_network->IELength = sz;
2553
2554         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
2555
2556         /* notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd(); */
2557         /* pdev_network->IELength = cpu_to_le32(sz); */
2558 }
2559
2560 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
2561 {
2562 }
2563
2564 /* the function is at passive_level */
2565 void rtw_joinbss_reset(struct adapter *padapter)
2566 {
2567         u8 threshold;
2568         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2569
2570         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2571
2572         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
2573
2574         pmlmepriv->num_FortyMHzIntolerant = 0;
2575
2576         pmlmepriv->num_sta_no_ht = 0;
2577
2578         phtpriv->ampdu_enable = false;/* reset to disabled */
2579
2580         /*  TH = 1 => means that invalidate usb rx aggregation */
2581         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
2582         if (phtpriv->ht_option) {
2583                 if (padapter->registrypriv.wifi_spec == 1)
2584                         threshold = 1;
2585                 else
2586                         threshold = 0;
2587                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2588         } else {
2589                 threshold = 1;
2590                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2591         }
2592 }
2593
2594 void rtw_ht_use_default_setting(struct adapter *padapter)
2595 {
2596         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2597         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2598         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2599         bool            bHwLDPCSupport = false, bHwSTBCSupport = false;
2600         bool            bHwSupportBeamformer = false, bHwSupportBeamformee = false;
2601
2602         if (pregistrypriv->wifi_spec)
2603                 phtpriv->bss_coexist = 1;
2604         else
2605                 phtpriv->bss_coexist = 0;
2606
2607         phtpriv->sgi_40m = TEST_FLAG(pregistrypriv->short_gi, BIT1) ? true : false;
2608         phtpriv->sgi_20m = TEST_FLAG(pregistrypriv->short_gi, BIT0) ? true : false;
2609
2610         /*  LDPC support */
2611         rtw_hal_get_def_var(padapter, HAL_DEF_RX_LDPC, (u8 *)&bHwLDPCSupport);
2612         CLEAR_FLAGS(phtpriv->ldpc_cap);
2613         if (bHwLDPCSupport) {
2614                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT4))
2615                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_RX);
2616         }
2617         rtw_hal_get_def_var(padapter, HAL_DEF_TX_LDPC, (u8 *)&bHwLDPCSupport);
2618         if (bHwLDPCSupport) {
2619                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT5))
2620                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_TX);
2621         }
2622         if (phtpriv->ldpc_cap)
2623                 DBG_871X("[HT] Support LDPC = 0x%02X\n", phtpriv->ldpc_cap);
2624
2625         /*  STBC */
2626         rtw_hal_get_def_var(padapter, HAL_DEF_TX_STBC, (u8 *)&bHwSTBCSupport);
2627         CLEAR_FLAGS(phtpriv->stbc_cap);
2628         if (bHwSTBCSupport) {
2629                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT5))
2630                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX);
2631         }
2632         rtw_hal_get_def_var(padapter, HAL_DEF_RX_STBC, (u8 *)&bHwSTBCSupport);
2633         if (bHwSTBCSupport) {
2634                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT4))
2635                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX);
2636         }
2637         if (phtpriv->stbc_cap)
2638                 DBG_871X("[HT] Support STBC = 0x%02X\n", phtpriv->stbc_cap);
2639
2640         /*  Beamforming setting */
2641         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMER, (u8 *)&bHwSupportBeamformer);
2642         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMEE, (u8 *)&bHwSupportBeamformee);
2643         CLEAR_FLAGS(phtpriv->beamform_cap);
2644         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT4) && bHwSupportBeamformer) {
2645                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE);
2646                 DBG_871X("[HT] Support Beamformer\n");
2647         }
2648         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT5) && bHwSupportBeamformee) {
2649                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE);
2650                 DBG_871X("[HT] Support Beamformee\n");
2651         }
2652 }
2653
2654 void rtw_build_wmm_ie_ht(struct adapter *padapter, u8 *out_ie, uint *pout_len)
2655 {
2656         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
2657         int out_len;
2658         u8 *pframe;
2659
2660         if (padapter->mlmepriv.qospriv.qos_option == 0) {
2661                 out_len = *pout_len;
2662                 pframe = rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_,
2663                                                         _WMM_IE_Length_, WMM_IE, pout_len);
2664
2665                 padapter->mlmepriv.qospriv.qos_option = 1;
2666         }
2667 }
2668
2669 /* the function is >= passive_level */
2670 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len, u8 channel)
2671 {
2672         u32 ielen, out_len;
2673         enum HT_CAP_AMPDU_FACTOR max_rx_ampdu_factor;
2674         unsigned char *p, *pframe;
2675         struct rtw_ieee80211_ht_cap ht_capie;
2676         u8 cbw40_enable = 0, stbc_rx_enable = 0, rf_type = 0, operation_bw = 0;
2677         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2678         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2679         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2680         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2681
2682         phtpriv->ht_option = false;
2683
2684         out_len = *pout_len;
2685
2686         memset(&ht_capie, 0, sizeof(struct rtw_ieee80211_ht_cap));
2687
2688         ht_capie.cap_info = cpu_to_le16(IEEE80211_HT_CAP_DSSSCCK40);
2689
2690         if (phtpriv->sgi_20m)
2691                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_20);
2692
2693         /* Get HT BW */
2694         if (in_ie == NULL) {
2695                 /* TDLS: TODO 20/40 issue */
2696                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
2697                         operation_bw = padapter->mlmeextpriv.cur_bwmode;
2698                         if (operation_bw > CHANNEL_WIDTH_40)
2699                                 operation_bw = CHANNEL_WIDTH_40;
2700                 } else
2701                         /* TDLS: TODO 40? */
2702                         operation_bw = CHANNEL_WIDTH_40;
2703         } else {
2704                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
2705                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2706                         struct HT_info_element *pht_info = (struct HT_info_element *)(p+2);
2707                         if (pht_info->infos[0] & BIT(2)) {
2708                                 switch (pht_info->infos[0] & 0x3) {
2709                                 case 1:
2710                                 case 3:
2711                                         operation_bw = CHANNEL_WIDTH_40;
2712                                         break;
2713                                 default:
2714                                         operation_bw = CHANNEL_WIDTH_20;
2715                                         break;
2716                                 }
2717                         } else {
2718                                 operation_bw = CHANNEL_WIDTH_20;
2719                         }
2720                 }
2721         }
2722
2723         /* to disable 40M Hz support while gd_bw_40MHz_en = 0 */
2724         if (channel > 14) {
2725                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
2726                         cbw40_enable = 1;
2727         } else {
2728                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
2729                         cbw40_enable = 1;
2730         }
2731
2732         if ((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) {
2733                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH);
2734                 if (phtpriv->sgi_40m)
2735                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_40);
2736         }
2737
2738         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX))
2739                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_TX_STBC);
2740
2741         /* todo: disable SM power save mode */
2742         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SM_PS);
2743
2744         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX)) {
2745                 if ((channel <= 14 && pregistrypriv->rx_stbc == 0x1) || /* enable for 2.4GHz */
2746                         (pregistrypriv->wifi_spec == 1)) {
2747                         stbc_rx_enable = 1;
2748                         DBG_871X("declare supporting RX STBC\n");
2749                 }
2750         }
2751
2752         /* fill default supported_mcs_set */
2753         memcpy(ht_capie.supp_mcs_set, pmlmeext->default_supported_mcs_set, 16);
2754
2755         /* update default supported_mcs_set */
2756         rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2757
2758         switch (rf_type) {
2759         case RF_1T1R:
2760                 if (stbc_rx_enable)
2761                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_1R);/* RX STBC One spatial stream */
2762
2763                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_1R);
2764                 break;
2765
2766         case RF_2T2R:
2767         case RF_1T2R:
2768         default:
2769                 if (stbc_rx_enable)
2770                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_2R);/* RX STBC two spatial stream */
2771
2772                 #ifdef CONFIG_DISABLE_MCS13TO15
2773                 if (((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) && (pregistrypriv->wifi_spec != 1))
2774                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R_13TO15_OFF);
2775                 else
2776                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
2777                 #else /* CONFIG_DISABLE_MCS13TO15 */
2778                         set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
2779                 #endif /* CONFIG_DISABLE_MCS13TO15 */
2780                 break;
2781         }
2782
2783         {
2784                 u32 rx_packet_offset, max_recvbuf_sz;
2785                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
2786                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
2787         }
2788
2789         if (padapter->driver_rx_ampdu_factor != 0xFF)
2790                 max_rx_ampdu_factor =
2791                   (enum HT_CAP_AMPDU_FACTOR)padapter->driver_rx_ampdu_factor;
2792         else
2793                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR,
2794                                     &max_rx_ampdu_factor);
2795
2796         /* rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor); */
2797         ht_capie.ampdu_params_info = (max_rx_ampdu_factor&0x03);
2798
2799         if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
2800                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&(0x07<<2));
2801         else
2802                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
2803
2804         pframe = rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
2805                                                 sizeof(struct rtw_ieee80211_ht_cap), (unsigned char *)&ht_capie, pout_len);
2806
2807         phtpriv->ht_option = true;
2808
2809         if (in_ie != NULL) {
2810                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
2811                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2812                         out_len = *pout_len;
2813                         pframe = rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2, pout_len);
2814                 }
2815         }
2816
2817         return phtpriv->ht_option;
2818
2819 }
2820
2821 /* the function is > passive_level (in critical_section) */
2822 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len, u8 channel)
2823 {
2824         u8 *p, max_ampdu_sz;
2825         int len;
2826         /* struct sta_info *bmc_sta, *psta; */
2827         struct rtw_ieee80211_ht_cap *pht_capie;
2828         struct ieee80211_ht_addt_info *pht_addtinfo;
2829         /* struct recv_reorder_ctrl *preorder_ctrl; */
2830         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2831         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2832         /* struct recv_priv *precvpriv = &padapter->recvpriv; */
2833         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2834         /* struct wlan_network *pcur_network = &(pmlmepriv->cur_network);; */
2835         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2836         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
2837         u8 cbw40_enable = 0;
2838
2839
2840         if (!phtpriv->ht_option)
2841                 return;
2842
2843         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
2844                 return;
2845
2846         DBG_871X("+rtw_update_ht_cap()\n");
2847
2848         /* maybe needs check if ap supports rx ampdu. */
2849         if ((phtpriv->ampdu_enable == false) && (pregistrypriv->ampdu_enable == 1)) {
2850                 if (pregistrypriv->wifi_spec == 1) {
2851                         /* remove this part because testbed AP should disable RX AMPDU */
2852                         /* phtpriv->ampdu_enable = false; */
2853                         phtpriv->ampdu_enable = true;
2854                 } else {
2855                         phtpriv->ampdu_enable = true;
2856                 }
2857         } else if (pregistrypriv->ampdu_enable == 2) {
2858                 /* remove this part because testbed AP should disable RX AMPDU */
2859                 /* phtpriv->ampdu_enable = true; */
2860         }
2861
2862
2863         /* check Max Rx A-MPDU Size */
2864         len = 0;
2865         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fix_ie), _HT_CAPABILITY_IE_, &len, ie_len-sizeof(struct ndis_802_11_fix_ie));
2866         if (p && len > 0) {
2867                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);
2868                 max_ampdu_sz = (pht_capie->ampdu_params_info & IEEE80211_HT_CAP_AMPDU_FACTOR);
2869                 max_ampdu_sz = 1 << (max_ampdu_sz+3); /*  max_ampdu_sz (kbytes); */
2870
2871                 /* DBG_871X("rtw_update_ht_cap(): max_ampdu_sz =%d\n", max_ampdu_sz); */
2872                 phtpriv->rx_ampdu_maxlen = max_ampdu_sz;
2873
2874         }
2875
2876
2877         len = 0;
2878         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fix_ie), _HT_ADD_INFO_IE_, &len, ie_len-sizeof(struct ndis_802_11_fix_ie));
2879         if (p && len > 0) {
2880                 pht_addtinfo = (struct ieee80211_ht_addt_info *)(p+2);
2881                 /* todo: */
2882         }
2883
2884         if (channel > 14) {
2885                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
2886                         cbw40_enable = 1;
2887         } else {
2888                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
2889                         cbw40_enable = 1;
2890         }
2891
2892         /* update cur_bwmode & cur_ch_offset */
2893         if ((cbw40_enable) &&
2894             (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
2895               BIT(1)) && (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
2896                 int i;
2897                 u8 rf_type;
2898
2899                 rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2900
2901                 /* update the MCS set */
2902                 for (i = 0; i < 16; i++)
2903                         pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= pmlmeext->default_supported_mcs_set[i];
2904
2905                 /* update the MCS rates */
2906                 switch (rf_type) {
2907                 case RF_1T1R:
2908                 case RF_1T2R:
2909                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_1R);
2910                         break;
2911                 case RF_2T2R:
2912                 default:
2913 #ifdef CONFIG_DISABLE_MCS13TO15
2914                         if (pmlmeext->cur_bwmode == CHANNEL_WIDTH_40 && pregistrypriv->wifi_spec != 1)
2915                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R_13TO15_OFF);
2916                         else
2917                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
2918 #else /* CONFIG_DISABLE_MCS13TO15 */
2919                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
2920 #endif /* CONFIG_DISABLE_MCS13TO15 */
2921                 }
2922
2923                 /* switch to the 40M Hz mode according to the AP */
2924                 /* pmlmeext->cur_bwmode = CHANNEL_WIDTH_40; */
2925                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
2926                 case EXTCHNL_OFFSET_UPPER:
2927                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
2928                         break;
2929
2930                 case EXTCHNL_OFFSET_LOWER:
2931                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
2932                         break;
2933
2934                 default:
2935                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
2936                         break;
2937                 }
2938         }
2939
2940         /*  */
2941         /*  Config SM Power Save setting */
2942         /*  */
2943         pmlmeinfo->SM_PS =
2944                 (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
2945                  0x0C) >> 2;
2946         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
2947                 DBG_871X("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
2948
2949         /*  */
2950         /*  Config current HT Protection mode. */
2951         /*  */
2952         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
2953 }
2954
2955 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
2956 {
2957         u8 issued;
2958         int priority;
2959         struct sta_info *psta = NULL;
2960         struct ht_priv *phtpriv;
2961         struct pkt_attrib *pattrib = &pxmitframe->attrib;
2962         s32 bmcst = IS_MCAST(pattrib->ra);
2963
2964         /* if (bmcst || (padapter->mlmepriv.LinkDetectInfo.bTxBusyTraffic == false)) */
2965         if (bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100))
2966                 return;
2967
2968         priority = pattrib->priority;
2969
2970         psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
2971         if (pattrib->psta != psta) {
2972                 DBG_871X("%s, pattrib->psta(%p) != psta(%p)\n", __func__, pattrib->psta, psta);
2973                 return;
2974         }
2975
2976         if (psta == NULL) {
2977                 DBG_871X("%s, psta ==NUL\n", __func__);
2978                 return;
2979         }
2980
2981         if (!(psta->state & _FW_LINKED)) {
2982                 DBG_871X("%s, psta->state(0x%x) != _FW_LINKED\n", __func__, psta->state);
2983                 return;
2984         }
2985
2986
2987         phtpriv = &psta->htpriv;
2988
2989         if ((phtpriv->ht_option == true) && (phtpriv->ampdu_enable == true)) {
2990                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
2991                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
2992
2993                 if (0 == issued) {
2994                         DBG_871X("rtw_issue_addbareq_cmd, p =%d\n", priority);
2995                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
2996                         rtw_addbareq_cmd(padapter, (u8) priority, pattrib->ra);
2997                 }
2998         }
2999
3000 }
3001
3002 void rtw_append_exented_cap(struct adapter *padapter, u8 *out_ie, uint *pout_len)
3003 {
3004         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3005         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
3006         u8 cap_content[8] = {0};
3007         u8 *pframe;
3008
3009
3010         if (phtpriv->bss_coexist) {
3011                 SET_EXT_CAPABILITY_ELE_BSS_COEXIST(cap_content, 1);
3012         }
3013
3014         pframe = rtw_set_ie(out_ie + *pout_len, EID_EXTCapability, 8, cap_content, pout_len);
3015 }
3016
3017 inline void rtw_set_to_roam(struct adapter *adapter, u8 to_roam)
3018 {
3019         if (to_roam == 0)
3020                 adapter->mlmepriv.to_join = false;
3021         adapter->mlmepriv.to_roam = to_roam;
3022 }
3023
3024 inline u8 rtw_dec_to_roam(struct adapter *adapter)
3025 {
3026         adapter->mlmepriv.to_roam--;
3027         return adapter->mlmepriv.to_roam;
3028 }
3029
3030 inline u8 rtw_to_roam(struct adapter *adapter)
3031 {
3032         return adapter->mlmepriv.to_roam;
3033 }
3034
3035 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3036 {
3037         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3038
3039         spin_lock_bh(&pmlmepriv->lock);
3040         _rtw_roaming(padapter, tgt_network);
3041         spin_unlock_bh(&pmlmepriv->lock);
3042 }
3043 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3044 {
3045         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3046         struct wlan_network *cur_network = &pmlmepriv->cur_network;
3047         int do_join_r;
3048
3049         if (0 < rtw_to_roam(padapter)) {
3050                 DBG_871X("roaming from %s("MAC_FMT"), length:%d\n",
3051                                 cur_network->network.Ssid.Ssid, MAC_ARG(cur_network->network.MacAddress),
3052                                 cur_network->network.Ssid.SsidLength);
3053                 memcpy(&pmlmepriv->assoc_ssid, &cur_network->network.Ssid, sizeof(struct ndis_802_11_ssid));
3054
3055                 pmlmepriv->assoc_by_bssid = false;
3056
3057                 while (1) {
3058                         do_join_r = rtw_do_join(padapter);
3059                         if (_SUCCESS == do_join_r) {
3060                                 break;
3061                         } else {
3062                                 DBG_871X("roaming do_join return %d\n", do_join_r);
3063                                 rtw_dec_to_roam(padapter);
3064
3065                                 if (rtw_to_roam(padapter) > 0) {
3066                                         continue;
3067                                 } else {
3068                                         DBG_871X("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
3069                                         rtw_indicate_disconnect(padapter);
3070                                         break;
3071                                 }
3072                         }
3073                 }
3074         }
3075
3076 }
3077
3078 sint rtw_linked_check(struct adapter *padapter)
3079 {
3080         if ((check_fwstate(&padapter->mlmepriv, WIFI_AP_STATE) == true) ||
3081                         (check_fwstate(&padapter->mlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE) == true)) {
3082                 if (padapter->stapriv.asoc_sta_count > 2)
3083                         return true;
3084         } else {        /* Station mode */
3085                 if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == true)
3086                         return true;
3087         }
3088         return false;
3089 }