Linux-libre 3.16.78-gnu
[librecmc/linux-libre.git] / drivers / staging / rtl8712 / rtl871x_cmd.c
1 /******************************************************************************
2  * rtl871x_cmd.c
3  *
4  * Copyright(c) 2007 - 2010 Realtek Corporation. All rights reserved.
5  * Linux device driver for RTL8192SU
6  *
7  * This program is free software; you can redistribute it and/or modify it
8  * under the terms of version 2 of the GNU General Public License as
9  * published by the Free Software Foundation.
10  *
11  * This program is distributed in the hope that it will be useful, but WITHOUT
12  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
13  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for
14  * more details.
15  *
16  * You should have received a copy of the GNU General Public License along with
17  * this program; if not, write to the Free Software Foundation, Inc.,
18  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
19  *
20  * Modifications for inclusion into the Linux staging tree are
21  * Copyright(c) 2010 Larry Finger. All rights reserved.
22  *
23  * Contact information:
24  * WLAN FAE <wlanfae@realtek.com>
25  * Larry Finger <Larry.Finger@lwfinger.net>
26  *
27  ******************************************************************************/
28
29 #define _RTL871X_CMD_C_
30
31 #include <linux/compiler.h>
32 #include <linux/kernel.h>
33 #include <linux/errno.h>
34 #include <linux/slab.h>
35 #include <linux/module.h>
36 #include <linux/kref.h>
37 #include <linux/netdevice.h>
38 #include <linux/skbuff.h>
39 #include <linux/usb.h>
40 #include <linux/usb/ch9.h>
41 #include <linux/circ_buf.h>
42 #include <linux/uaccess.h>
43 #include <asm/byteorder.h>
44 #include <linux/atomic.h>
45 #include <linux/semaphore.h>
46 #include <linux/rtnetlink.h>
47
48 #include "osdep_service.h"
49 #include "drv_types.h"
50 #include "recv_osdep.h"
51 #include "mlme_osdep.h"
52
53 /*
54 Caller and the r8712_cmd_thread can protect cmd_q by spin_lock.
55 No irqsave is necessary.
56 */
57
58 static sint _init_cmd_priv(struct cmd_priv *pcmdpriv)
59 {
60         sema_init(&(pcmdpriv->cmd_queue_sema), 0);
61         sema_init(&(pcmdpriv->terminate_cmdthread_sema), 0);
62
63         _init_queue(&(pcmdpriv->cmd_queue));
64
65         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
66         pcmdpriv->cmd_seq = 1;
67         pcmdpriv->cmd_allocated_buf = kmalloc(MAX_CMDSZ + CMDBUFF_ALIGN_SZ,
68                                               GFP_ATOMIC);
69         if (pcmdpriv->cmd_allocated_buf == NULL)
70                 return _FAIL;
71         pcmdpriv->cmd_buf = pcmdpriv->cmd_allocated_buf  +  CMDBUFF_ALIGN_SZ -
72                             ((addr_t)(pcmdpriv->cmd_allocated_buf) &
73                             (CMDBUFF_ALIGN_SZ-1));
74         pcmdpriv->rsp_allocated_buf = kmalloc(MAX_RSPSZ + 4, GFP_ATOMIC);
75         if (pcmdpriv->rsp_allocated_buf == NULL)
76                 return _FAIL;
77         pcmdpriv->rsp_buf = pcmdpriv->rsp_allocated_buf  +  4 -
78                             ((addr_t)(pcmdpriv->rsp_allocated_buf) & 3);
79         pcmdpriv->cmd_issued_cnt = 0;
80         pcmdpriv->cmd_done_cnt = 0;
81         pcmdpriv->rsp_cnt = 0;
82         return _SUCCESS;
83 }
84
85 static sint _init_evt_priv(struct evt_priv *pevtpriv)
86 {
87         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
88         pevtpriv->event_seq = 0;
89         pevtpriv->evt_allocated_buf = kmalloc(MAX_EVTSZ + 4, GFP_ATOMIC);
90
91         if (pevtpriv->evt_allocated_buf == NULL)
92                 return _FAIL;
93         pevtpriv->evt_buf = pevtpriv->evt_allocated_buf  +  4 -
94                             ((addr_t)(pevtpriv->evt_allocated_buf) & 3);
95         pevtpriv->evt_done_cnt = 0;
96         return _SUCCESS;
97 }
98
99 static void _free_evt_priv(struct evt_priv *pevtpriv)
100 {
101         kfree(pevtpriv->evt_allocated_buf);
102 }
103
104 static void _free_cmd_priv(struct cmd_priv *pcmdpriv)
105 {
106         if (pcmdpriv) {
107                 kfree(pcmdpriv->cmd_allocated_buf);
108                 kfree(pcmdpriv->rsp_allocated_buf);
109         }
110 }
111
112 /*
113 Calling Context:
114
115 _enqueue_cmd can only be called between kernel thread,
116 since only spin_lock is used.
117
118 ISR/Call-Back functions can't call this sub-function.
119
120 */
121
122 static sint _enqueue_cmd(struct  __queue *queue, struct cmd_obj *obj)
123 {
124         unsigned long irqL;
125
126         if (obj == NULL)
127                 return _SUCCESS;
128         spin_lock_irqsave(&queue->lock, irqL);
129         list_insert_tail(&obj->list, &queue->queue);
130         spin_unlock_irqrestore(&queue->lock, irqL);
131         return _SUCCESS;
132 }
133
134 static struct cmd_obj *_dequeue_cmd(struct  __queue *queue)
135 {
136         unsigned long irqL;
137         struct cmd_obj *obj;
138
139         spin_lock_irqsave(&(queue->lock), irqL);
140         if (is_list_empty(&(queue->queue)))
141                 obj = NULL;
142         else {
143                 obj = LIST_CONTAINOR(get_next(&(queue->queue)),
144                                      struct cmd_obj, list);
145                 list_delete(&obj->list);
146         }
147         spin_unlock_irqrestore(&(queue->lock), irqL);
148         return obj;
149 }
150
151 u32 r8712_init_cmd_priv(struct cmd_priv *pcmdpriv)
152 {
153         return _init_cmd_priv(pcmdpriv);
154 }
155
156 u32 r8712_init_evt_priv(struct evt_priv *pevtpriv)
157 {
158         return _init_evt_priv(pevtpriv);
159 }
160
161 void r8712_free_evt_priv(struct evt_priv *pevtpriv)
162 {
163         _free_evt_priv(pevtpriv);
164 }
165
166 void r8712_free_cmd_priv(struct cmd_priv *pcmdpriv)
167 {
168         _free_cmd_priv(pcmdpriv);
169 }
170
171 u32 r8712_enqueue_cmd(struct cmd_priv *pcmdpriv, struct cmd_obj *obj)
172 {
173         int res;
174
175         if (pcmdpriv->padapter->eeprompriv.bautoload_fail_flag == true)
176                 return _FAIL;
177         res = _enqueue_cmd(&pcmdpriv->cmd_queue, obj);
178         up(&pcmdpriv->cmd_queue_sema);
179         return res;
180 }
181
182 u32 r8712_enqueue_cmd_ex(struct cmd_priv *pcmdpriv, struct cmd_obj *obj)
183 {
184         unsigned long irqL;
185         struct  __queue *queue;
186
187         if (obj == NULL)
188                 return _SUCCESS;
189         if (pcmdpriv->padapter->eeprompriv.bautoload_fail_flag == true)
190                 return _FAIL;
191         queue = &pcmdpriv->cmd_queue;
192         spin_lock_irqsave(&queue->lock, irqL);
193         list_insert_tail(&obj->list, &queue->queue);
194         spin_unlock_irqrestore(&queue->lock, irqL);
195         up(&pcmdpriv->cmd_queue_sema);
196         return _SUCCESS;
197 }
198
199 struct cmd_obj *r8712_dequeue_cmd(struct  __queue *queue)
200 {
201         return _dequeue_cmd(queue);
202 }
203
204 void r8712_free_cmd_obj(struct cmd_obj *pcmd)
205 {
206         if ((pcmd->cmdcode != _JoinBss_CMD_) &&
207             (pcmd->cmdcode != _CreateBss_CMD_))
208                 kfree((unsigned char *)pcmd->parmbuf);
209         if (pcmd->rsp != NULL) {
210                 if (pcmd->rspsz != 0)
211                         kfree((unsigned char *)pcmd->rsp);
212         }
213         kfree((unsigned char *)pcmd);
214 }
215
216 /*
217 r8712_sitesurvey_cmd(~)
218         ### NOTE:#### (!!!!)
219         MUST TAKE CARE THAT BEFORE CALLING THIS FUNC,
220          YOU SHOULD HAVE LOCKED pmlmepriv->lock
221 */
222 u8 r8712_sitesurvey_cmd(struct _adapter *padapter,
223                         struct ndis_802_11_ssid *pssid)
224 {
225         struct cmd_obj  *ph2c;
226         struct sitesurvey_parm  *psurveyPara;
227         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
228         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
229
230         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
231         if (ph2c == NULL)
232                 return _FAIL;
233         psurveyPara = kmalloc(sizeof(struct sitesurvey_parm), GFP_ATOMIC);
234         if (psurveyPara == NULL) {
235                 kfree((unsigned char *) ph2c);
236                 return _FAIL;
237         }
238         init_h2fwcmd_w_parm_no_rsp(ph2c, psurveyPara,
239                                    GEN_CMD_CODE(_SiteSurvey));
240         psurveyPara->bsslimit = cpu_to_le32(48);
241         psurveyPara->passive_mode = cpu_to_le32(pmlmepriv->passive_mode);
242         psurveyPara->ss_ssidlen = 0;
243         memset(psurveyPara->ss_ssid, 0, IW_ESSID_MAX_SIZE + 1);
244         if ((pssid != NULL) && (pssid->SsidLength)) {
245                 memcpy(psurveyPara->ss_ssid, pssid->Ssid, pssid->SsidLength);
246                 psurveyPara->ss_ssidlen = cpu_to_le32(pssid->SsidLength);
247         }
248         set_fwstate(pmlmepriv, _FW_UNDER_SURVEY);
249         r8712_enqueue_cmd(pcmdpriv, ph2c);
250         _set_timer(&pmlmepriv->scan_to_timer, SCANNING_TIMEOUT);
251         padapter->ledpriv.LedControlHandler(padapter, LED_CTL_SITE_SURVEY);
252         padapter->blnEnableRxFF0Filter = 0;
253         return _SUCCESS;
254 }
255
256 u8 r8712_setdatarate_cmd(struct _adapter *padapter, u8 *rateset)
257 {
258         struct cmd_obj          *ph2c;
259         struct setdatarate_parm *pbsetdataratepara;
260         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
261
262         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
263         if (ph2c == NULL)
264                 return _FAIL;
265         pbsetdataratepara = kmalloc(sizeof(struct setdatarate_parm),
266                                     GFP_ATOMIC);
267         if (pbsetdataratepara == NULL) {
268                 kfree((u8 *) ph2c);
269                 return _FAIL;
270         }
271         init_h2fwcmd_w_parm_no_rsp(ph2c, pbsetdataratepara,
272                                    GEN_CMD_CODE(_SetDataRate));
273         pbsetdataratepara->mac_id = 5;
274         memcpy(pbsetdataratepara->datarates, rateset, NumRates);
275         r8712_enqueue_cmd(pcmdpriv, ph2c);
276         return _SUCCESS;
277 }
278
279 u8 r8712_set_chplan_cmd(struct _adapter *padapter, int chplan)
280 {
281         struct cmd_obj *ph2c;
282         struct SetChannelPlan_param *psetchplanpara;
283         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
284
285         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
286         if (ph2c == NULL)
287                 return _FAIL;
288         psetchplanpara = kmalloc(sizeof(struct SetChannelPlan_param),
289                                  GFP_ATOMIC);
290         if (psetchplanpara == NULL) {
291                 kfree((u8 *) ph2c);
292                 return _FAIL;
293         }
294         init_h2fwcmd_w_parm_no_rsp(ph2c, psetchplanpara,
295                                 GEN_CMD_CODE(_SetChannelPlan));
296         psetchplanpara->ChannelPlan = chplan;
297         r8712_enqueue_cmd(pcmdpriv, ph2c);
298         return _SUCCESS;
299 }
300
301 u8 r8712_setbasicrate_cmd(struct _adapter *padapter, u8 *rateset)
302 {
303         struct cmd_obj *ph2c;
304         struct setbasicrate_parm *pssetbasicratepara;
305         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
306
307         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
308         if (ph2c == NULL)
309                 return _FAIL;
310         pssetbasicratepara = kmalloc(sizeof(struct setbasicrate_parm),
311                                      GFP_ATOMIC);
312         if (pssetbasicratepara == NULL) {
313                 kfree((u8 *) ph2c);
314                 return _FAIL;
315         }
316         init_h2fwcmd_w_parm_no_rsp(ph2c, pssetbasicratepara,
317                 _SetBasicRate_CMD_);
318         memcpy(pssetbasicratepara->basicrates, rateset, NumRates);
319         r8712_enqueue_cmd(pcmdpriv, ph2c);
320         return _SUCCESS;
321 }
322
323 /* power tracking mechanism setting */
324 u8 r8712_setptm_cmd(struct _adapter *padapter, u8 type)
325 {
326         struct cmd_obj          *ph2c;
327         struct writePTM_parm    *pwriteptmparm;
328         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
329
330         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
331         if (ph2c == NULL)
332                 return _FAIL;
333         pwriteptmparm = kmalloc(sizeof(struct writePTM_parm), GFP_ATOMIC);
334         if (pwriteptmparm == NULL) {
335                 kfree((u8 *) ph2c);
336                 return _FAIL;
337         }
338         init_h2fwcmd_w_parm_no_rsp(ph2c, pwriteptmparm, GEN_CMD_CODE(_SetPT));
339         pwriteptmparm->type = type;
340         r8712_enqueue_cmd(pcmdpriv, ph2c);
341         return _SUCCESS;
342 }
343
344 u8 r8712_setfwdig_cmd(struct _adapter *padapter, u8 type)
345 {
346         struct cmd_obj *ph2c;
347         struct writePTM_parm *pwriteptmparm;
348         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
349
350         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
351         if (ph2c == NULL)
352                 return _FAIL;
353         pwriteptmparm = kmalloc(sizeof(struct writePTM_parm), GFP_ATOMIC);
354         if (pwriteptmparm == NULL) {
355                 kfree((u8 *) ph2c);
356                 return _FAIL;
357         }
358         init_h2fwcmd_w_parm_no_rsp(ph2c, pwriteptmparm, GEN_CMD_CODE(_SetDIG));
359         pwriteptmparm->type = type;
360         r8712_enqueue_cmd(pcmdpriv, ph2c);
361         return _SUCCESS;
362 }
363
364 u8 r8712_setfwra_cmd(struct _adapter *padapter, u8 type)
365 {
366         struct cmd_obj *ph2c;
367         struct writePTM_parm *pwriteptmparm;
368         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
369
370         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
371         if (ph2c == NULL)
372                 return _FAIL;
373         pwriteptmparm = kmalloc(sizeof(struct writePTM_parm), GFP_ATOMIC);
374         if (pwriteptmparm == NULL) {
375                 kfree((u8 *) ph2c);
376                 return _FAIL;
377         }
378         init_h2fwcmd_w_parm_no_rsp(ph2c, pwriteptmparm, GEN_CMD_CODE(_SetRA));
379         pwriteptmparm->type = type;
380         r8712_enqueue_cmd(pcmdpriv, ph2c);
381         return _SUCCESS;
382 }
383
384 u8 r8712_setrfreg_cmd(struct _adapter  *padapter, u8 offset, u32 val)
385 {
386         struct cmd_obj *ph2c;
387         struct writeRF_parm *pwriterfparm;
388         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
389
390         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
391         if (ph2c == NULL)
392                 return _FAIL;
393         pwriterfparm = kmalloc(sizeof(struct writeRF_parm), GFP_ATOMIC);
394         if (pwriterfparm == NULL) {
395                 kfree((u8 *) ph2c);
396                 return _FAIL;
397         }
398         init_h2fwcmd_w_parm_no_rsp(ph2c, pwriterfparm, GEN_CMD_CODE(_SetRFReg));
399         pwriterfparm->offset = offset;
400         pwriterfparm->value = val;
401         r8712_enqueue_cmd(pcmdpriv, ph2c);
402         return _SUCCESS;
403 }
404
405 u8 r8712_getrfreg_cmd(struct _adapter *padapter, u8 offset, u8 *pval)
406 {
407         struct cmd_obj *ph2c;
408         struct readRF_parm *prdrfparm;
409         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
410
411         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
412         if (ph2c == NULL)
413                 return _FAIL;
414         prdrfparm = kmalloc(sizeof(struct readRF_parm), GFP_ATOMIC);
415         if (prdrfparm == NULL) {
416                 kfree((u8 *) ph2c);
417                 return _FAIL;
418         }
419         _init_listhead(&ph2c->list);
420         ph2c->cmdcode = GEN_CMD_CODE(_GetRFReg);
421         ph2c->parmbuf = (unsigned char *)prdrfparm;
422         ph2c->cmdsz =  sizeof(struct readRF_parm);
423         ph2c->rsp = pval;
424         ph2c->rspsz = sizeof(struct readRF_rsp);
425         prdrfparm->offset = offset;
426         r8712_enqueue_cmd(pcmdpriv, ph2c);
427         return _SUCCESS;
428 }
429
430 void r8712_getbbrfreg_cmdrsp_callback(struct _adapter *padapter,
431                                       struct cmd_obj *pcmd)
432 {
433         kfree(pcmd->parmbuf);
434         kfree(pcmd);
435         padapter->mppriv.workparam.bcompleted = true;
436 }
437
438 void r8712_readtssi_cmdrsp_callback(struct _adapter *padapter,
439                                 struct cmd_obj *pcmd)
440 {
441         kfree(pcmd->parmbuf);
442         kfree(pcmd);
443
444         padapter->mppriv.workparam.bcompleted = true;
445 }
446
447 u8 r8712_createbss_cmd(struct _adapter *padapter)
448 {
449         struct cmd_obj *pcmd;
450         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
451         struct wlan_bssid_ex *pdev_network =
452                                  &padapter->registrypriv.dev_network;
453
454         padapter->ledpriv.LedControlHandler(padapter, LED_CTL_START_TO_LINK);
455         pcmd = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
456         if (pcmd == NULL)
457                 return _FAIL;
458         _init_listhead(&pcmd->list);
459         pcmd->cmdcode = _CreateBss_CMD_;
460         pcmd->parmbuf = (unsigned char *)pdev_network;
461         pcmd->cmdsz = r8712_get_ndis_wlan_bssid_ex_sz((
462                         struct ndis_wlan_bssid_ex *)
463                         pdev_network);
464         pcmd->rsp = NULL;
465         pcmd->rspsz = 0;
466         /* notes: translate IELength & Length after assign to cmdsz; */
467         pdev_network->Length = pcmd->cmdsz;
468         pdev_network->IELength = pdev_network->IELength;
469         pdev_network->Ssid.SsidLength = pdev_network->Ssid.SsidLength;
470         r8712_enqueue_cmd(pcmdpriv, pcmd);
471         return _SUCCESS;
472 }
473
474 u8 r8712_joinbss_cmd(struct _adapter  *padapter, struct wlan_network *pnetwork)
475 {
476         u8 *auth;
477         uint t_len = 0;
478         struct ndis_wlan_bssid_ex *psecnetwork;
479         struct cmd_obj          *pcmd;
480         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
481         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
482         struct qos_priv         *pqospriv = &pmlmepriv->qospriv;
483         struct security_priv    *psecuritypriv = &padapter->securitypriv;
484         struct registry_priv    *pregistrypriv = &padapter->registrypriv;
485         enum NDIS_802_11_NETWORK_INFRASTRUCTURE ndis_network_mode = pnetwork->
486                                                 network.InfrastructureMode;
487
488         padapter->ledpriv.LedControlHandler(padapter, LED_CTL_START_TO_LINK);
489         pcmd = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
490         if (pcmd == NULL)
491                 return _FAIL;
492         t_len = sizeof(u32) + 6 * sizeof(unsigned char) + 2 +
493                         sizeof(struct ndis_802_11_ssid) + sizeof(u32) +
494                         sizeof(s32) +
495                         sizeof(enum NDIS_802_11_NETWORK_TYPE) +
496                         sizeof(struct NDIS_802_11_CONFIGURATION) +
497                         sizeof(enum NDIS_802_11_NETWORK_INFRASTRUCTURE) +
498                         sizeof(NDIS_802_11_RATES_EX) +
499                         sizeof(u32) + MAX_IE_SZ;
500
501         /* for hidden ap to set fw_state here */
502         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_ADHOC_STATE) !=
503             true) {
504                 switch (ndis_network_mode) {
505                 case Ndis802_11IBSS:
506                         pmlmepriv->fw_state |= WIFI_ADHOC_STATE;
507                         break;
508                 case Ndis802_11Infrastructure:
509                         pmlmepriv->fw_state |= WIFI_STATION_STATE;
510                         break;
511                 case Ndis802_11APMode:
512                 case Ndis802_11AutoUnknown:
513                 case Ndis802_11InfrastructureMax:
514                         break;
515                 }
516         }
517         psecnetwork = (struct ndis_wlan_bssid_ex *)&psecuritypriv->sec_bss;
518         if (psecnetwork == NULL) {
519                 kfree(pcmd);
520                 return _FAIL;
521         }
522         memcpy(psecnetwork, &pnetwork->network, t_len);
523         auth = &psecuritypriv->authenticator_ie[0];
524         psecuritypriv->authenticator_ie[0] = (unsigned char)
525                                              psecnetwork->IELength;
526         if ((psecnetwork->IELength-12) < (256 - 1))
527                 memcpy(&psecuritypriv->authenticator_ie[1],
528                         &psecnetwork->IEs[12], psecnetwork->IELength-12);
529         else
530                 memcpy(&psecuritypriv->authenticator_ie[1],
531                         &psecnetwork->IEs[12], (256-1));
532         psecnetwork->IELength = 0;
533         /* If the the driver wants to use the bssid to create the connection.
534          * If not,  we copy the connecting AP's MAC address to it so that
535          * the driver just has the bssid information for PMKIDList searching.
536          */
537         if (pmlmepriv->assoc_by_bssid == false)
538                 memcpy(&pmlmepriv->assoc_bssid[0],
539                         &pnetwork->network.MacAddress[0], ETH_ALEN);
540         psecnetwork->IELength = r8712_restruct_sec_ie(padapter,
541                                                 &pnetwork->network.IEs[0],
542                                                 &psecnetwork->IEs[0],
543                                                 pnetwork->network.IELength);
544         pqospriv->qos_option = 0;
545         if (pregistrypriv->wmm_enable) {
546                 u32 tmp_len;
547
548                 tmp_len = r8712_restruct_wmm_ie(padapter,
549                                           &pnetwork->network.IEs[0],
550                                           &psecnetwork->IEs[0],
551                                           pnetwork->network.IELength,
552                                           psecnetwork->IELength);
553                 if (psecnetwork->IELength != tmp_len) {
554                         psecnetwork->IELength = tmp_len;
555                         pqospriv->qos_option = 1; /* WMM IE in beacon */
556                 } else
557                         pqospriv->qos_option = 0; /* no WMM IE in beacon */
558         }
559         if (pregistrypriv->ht_enable) {
560                 /* For WEP mode, we will use the bg mode to do the connection
561                  * to avoid some IOT issues, especially for Realtek 8192u
562                  * SoftAP.
563                  */
564                 if ((padapter->securitypriv.PrivacyAlgrthm != _WEP40_) &&
565                     (padapter->securitypriv.PrivacyAlgrthm != _WEP104_)) {
566                         /* restructure_ht_ie */
567                         r8712_restructure_ht_ie(padapter,
568                                                 &pnetwork->network.IEs[0],
569                                                 &psecnetwork->IEs[0],
570                                                 pnetwork->network.IELength,
571                                                 &psecnetwork->IELength);
572                 }
573         }
574         psecuritypriv->supplicant_ie[0] = (u8)psecnetwork->IELength;
575         if (psecnetwork->IELength < 255)
576                 memcpy(&psecuritypriv->supplicant_ie[1], &psecnetwork->IEs[0],
577                         psecnetwork->IELength);
578         else
579                 memcpy(&psecuritypriv->supplicant_ie[1], &psecnetwork->IEs[0],
580                         255);
581         /* get cmdsz before endian conversion */
582         pcmd->cmdsz = r8712_get_ndis_wlan_bssid_ex_sz(psecnetwork);
583 #ifdef __BIG_ENDIAN
584         /* wlan_network endian conversion */
585         psecnetwork->Length = cpu_to_le32(psecnetwork->Length);
586         psecnetwork->Ssid.SsidLength = cpu_to_le32(
587                                        psecnetwork->Ssid.SsidLength);
588         psecnetwork->Privacy = cpu_to_le32(psecnetwork->Privacy);
589         psecnetwork->Rssi = cpu_to_le32(psecnetwork->Rssi);
590         psecnetwork->NetworkTypeInUse = cpu_to_le32(
591                                         psecnetwork->NetworkTypeInUse);
592         psecnetwork->Configuration.ATIMWindow = cpu_to_le32(
593                                 psecnetwork->Configuration.ATIMWindow);
594         psecnetwork->Configuration.BeaconPeriod = cpu_to_le32(
595                                  psecnetwork->Configuration.BeaconPeriod);
596         psecnetwork->Configuration.DSConfig = cpu_to_le32(
597                                 psecnetwork->Configuration.DSConfig);
598         psecnetwork->Configuration.FHConfig.DwellTime = cpu_to_le32(
599                                 psecnetwork->Configuration.FHConfig.DwellTime);
600         psecnetwork->Configuration.FHConfig.HopPattern = cpu_to_le32(
601                                 psecnetwork->Configuration.FHConfig.HopPattern);
602         psecnetwork->Configuration.FHConfig.HopSet = cpu_to_le32(
603                                 psecnetwork->Configuration.FHConfig.HopSet);
604         psecnetwork->Configuration.FHConfig.Length = cpu_to_le32(
605                                 psecnetwork->Configuration.FHConfig.Length);
606         psecnetwork->Configuration.Length = cpu_to_le32(
607                                 psecnetwork->Configuration.Length);
608         psecnetwork->InfrastructureMode = cpu_to_le32(
609                                 psecnetwork->InfrastructureMode);
610         psecnetwork->IELength = cpu_to_le32(psecnetwork->IELength);
611 #endif
612         _init_listhead(&pcmd->list);
613         pcmd->cmdcode = _JoinBss_CMD_;
614         pcmd->parmbuf = (unsigned char *)psecnetwork;
615         pcmd->rsp = NULL;
616         pcmd->rspsz = 0;
617         r8712_enqueue_cmd(pcmdpriv, pcmd);
618         return _SUCCESS;
619 }
620
621 u8 r8712_disassoc_cmd(struct _adapter *padapter) /* for sta_mode */
622 {
623         struct cmd_obj *pdisconnect_cmd;
624         struct disconnect_parm *pdisconnect;
625         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
626
627         pdisconnect_cmd = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
628         if (pdisconnect_cmd == NULL)
629                 return _FAIL;
630         pdisconnect = kmalloc(sizeof(struct disconnect_parm), GFP_ATOMIC);
631         if (pdisconnect == NULL) {
632                 kfree((u8 *)pdisconnect_cmd);
633                 return _FAIL;
634         }
635         init_h2fwcmd_w_parm_no_rsp(pdisconnect_cmd, pdisconnect,
636                                    _DisConnect_CMD_);
637         r8712_enqueue_cmd(pcmdpriv, pdisconnect_cmd);
638         return _SUCCESS;
639 }
640
641 u8 r8712_setopmode_cmd(struct _adapter *padapter,
642                  enum NDIS_802_11_NETWORK_INFRASTRUCTURE networktype)
643 {
644         struct cmd_obj *ph2c;
645         struct setopmode_parm *psetop;
646
647         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
648
649         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
650         if (ph2c == NULL)
651                 return _FAIL;
652         psetop = kmalloc(sizeof(struct setopmode_parm), GFP_ATOMIC);
653         if (psetop == NULL) {
654                 kfree((u8 *) ph2c);
655                 return _FAIL;
656         }
657         init_h2fwcmd_w_parm_no_rsp(ph2c, psetop, _SetOpMode_CMD_);
658         psetop->mode = (u8)networktype;
659         r8712_enqueue_cmd(pcmdpriv, ph2c);
660         return _SUCCESS;
661 }
662
663 u8 r8712_setstakey_cmd(struct _adapter *padapter, u8 *psta, u8 unicast_key)
664 {
665         struct cmd_obj *ph2c;
666         struct set_stakey_parm *psetstakey_para;
667         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
668         struct set_stakey_rsp *psetstakey_rsp = NULL;
669         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
670         struct security_priv *psecuritypriv = &padapter->securitypriv;
671         struct sta_info *sta = (struct sta_info *)psta;
672
673         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
674         if (ph2c == NULL)
675                 return _FAIL;
676         psetstakey_para = kmalloc(sizeof(struct set_stakey_parm), GFP_ATOMIC);
677         if (psetstakey_para == NULL) {
678                 kfree((u8 *) ph2c);
679                 return _FAIL;
680         }
681         psetstakey_rsp = kmalloc(sizeof(struct set_stakey_rsp), GFP_ATOMIC);
682         if (psetstakey_rsp == NULL) {
683                 kfree((u8 *) ph2c);
684                 kfree((u8 *) psetstakey_para);
685                 return _FAIL;
686         }
687         init_h2fwcmd_w_parm_no_rsp(ph2c, psetstakey_para, _SetStaKey_CMD_);
688         ph2c->rsp = (u8 *) psetstakey_rsp;
689         ph2c->rspsz = sizeof(struct set_stakey_rsp);
690         memcpy(psetstakey_para->addr, sta->hwaddr, ETH_ALEN);
691         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE))
692                 psetstakey_para->algorithm = (unsigned char)
693                                             psecuritypriv->PrivacyAlgrthm;
694         else
695                 GET_ENCRY_ALGO(psecuritypriv, sta,
696                                psetstakey_para->algorithm, false);
697         if (unicast_key == true)
698                 memcpy(&psetstakey_para->key, &sta->x_UncstKey, 16);
699         else
700                 memcpy(&psetstakey_para->key,
701                         &psecuritypriv->XGrpKey[
702                         psecuritypriv->XGrpKeyid - 1]. skey, 16);
703         r8712_enqueue_cmd(pcmdpriv, ph2c);
704         return _SUCCESS;
705 }
706
707 u8 r8712_setrfintfs_cmd(struct _adapter *padapter, u8 mode)
708 {
709         struct cmd_obj *ph2c;
710         struct setrfintfs_parm *psetrfintfsparm;
711         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
712
713         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
714         if (ph2c == NULL)
715                 return _FAIL;
716         psetrfintfsparm = kmalloc(sizeof(struct setrfintfs_parm), GFP_ATOMIC);
717         if (psetrfintfsparm == NULL) {
718                 kfree((unsigned char *) ph2c);
719                 return _FAIL;
720         }
721         init_h2fwcmd_w_parm_no_rsp(ph2c, psetrfintfsparm,
722                                    GEN_CMD_CODE(_SetRFIntFs));
723         psetrfintfsparm->rfintfs = mode;
724         r8712_enqueue_cmd(pcmdpriv, ph2c);
725         return _SUCCESS;
726 }
727
728 u8 r8712_setrttbl_cmd(struct _adapter *padapter,
729                       struct setratable_parm *prate_table)
730 {
731         struct cmd_obj *ph2c;
732         struct setratable_parm *psetrttblparm;
733         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
734
735         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
736         if (ph2c == NULL)
737                 return _FAIL;
738         psetrttblparm = kmalloc(sizeof(struct setratable_parm), GFP_ATOMIC);
739         if (psetrttblparm == NULL) {
740                 kfree((unsigned char *)ph2c);
741                 return _FAIL;
742         }
743         init_h2fwcmd_w_parm_no_rsp(ph2c, psetrttblparm,
744                                    GEN_CMD_CODE(_SetRaTable));
745         memcpy(psetrttblparm, prate_table, sizeof(struct setratable_parm));
746         r8712_enqueue_cmd(pcmdpriv, ph2c);
747         return _SUCCESS;
748 }
749
750 u8 r8712_gettssi_cmd(struct _adapter *padapter, u8 offset, u8 *pval)
751 {
752         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
753         struct cmd_obj *ph2c;
754         struct readTSSI_parm *prdtssiparm;
755
756         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
757         if (ph2c == NULL)
758                 return _FAIL;
759         prdtssiparm = kmalloc(sizeof(struct readTSSI_parm), GFP_ATOMIC);
760         if (prdtssiparm == NULL) {
761                 kfree((unsigned char *) ph2c);
762                 return _FAIL;
763         }
764         _init_listhead(&ph2c->list);
765         ph2c->cmdcode = GEN_CMD_CODE(_ReadTSSI);
766         ph2c->parmbuf = (unsigned char *)prdtssiparm;
767         ph2c->cmdsz = sizeof(struct readTSSI_parm);
768         ph2c->rsp = pval;
769         ph2c->rspsz = sizeof(struct readTSSI_rsp);
770
771         prdtssiparm->offset = offset;
772         r8712_enqueue_cmd(pcmdpriv, ph2c);
773         return _SUCCESS;
774 }
775
776 u8 r8712_setMacAddr_cmd(struct _adapter *padapter, u8 *mac_addr)
777 {
778         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
779         struct cmd_obj *ph2c;
780         struct SetMacAddr_param *psetMacAddr_para;
781
782         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
783         if (ph2c == NULL)
784                 return _FAIL;
785         psetMacAddr_para = kmalloc(sizeof(struct SetMacAddr_param),
786                                    GFP_ATOMIC);
787         if (psetMacAddr_para == NULL) {
788                 kfree((u8 *) ph2c);
789                 return _FAIL;
790         }
791         init_h2fwcmd_w_parm_no_rsp(ph2c, psetMacAddr_para,
792                                    _SetMacAddress_CMD_);
793         memcpy(psetMacAddr_para->MacAddr, mac_addr, ETH_ALEN);
794         r8712_enqueue_cmd(pcmdpriv, ph2c);
795         return _SUCCESS;
796 }
797
798 u8 r8712_setassocsta_cmd(struct _adapter *padapter, u8 *mac_addr)
799 {
800         struct cmd_priv                 *pcmdpriv = &padapter->cmdpriv;
801         struct cmd_obj                  *ph2c;
802         struct set_assocsta_parm        *psetassocsta_para;
803         struct set_assocsta_rsp         *psetassocsta_rsp = NULL;
804
805         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
806         if (ph2c == NULL)
807                 return _FAIL;
808         psetassocsta_para = kmalloc(sizeof(struct set_assocsta_parm),
809                                     GFP_ATOMIC);
810         if (psetassocsta_para == NULL) {
811                 kfree((u8 *) ph2c);
812                 return _FAIL;
813         }
814         psetassocsta_rsp = kmalloc(sizeof(struct set_assocsta_rsp),
815                                    GFP_ATOMIC);
816         if (psetassocsta_rsp == NULL) {
817                 kfree((u8 *)ph2c);
818                 kfree((u8 *)psetassocsta_para);
819                 return _FAIL;
820         }
821         init_h2fwcmd_w_parm_no_rsp(ph2c, psetassocsta_para, _SetAssocSta_CMD_);
822         ph2c->rsp = (u8 *) psetassocsta_rsp;
823         ph2c->rspsz = sizeof(struct set_assocsta_rsp);
824         memcpy(psetassocsta_para->addr, mac_addr, ETH_ALEN);
825         r8712_enqueue_cmd(pcmdpriv, ph2c);
826         return _SUCCESS;
827 }
828
829 u8 r8712_addbareq_cmd(struct _adapter *padapter, u8 tid)
830 {
831         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
832         struct cmd_obj          *ph2c;
833         struct addBaReq_parm    *paddbareq_parm;
834
835         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
836         if (ph2c == NULL)
837                 return _FAIL;
838         paddbareq_parm = kmalloc(sizeof(struct addBaReq_parm), GFP_ATOMIC);
839         if (paddbareq_parm == NULL) {
840                 kfree((unsigned char *)ph2c);
841                 return _FAIL;
842         }
843         paddbareq_parm->tid = tid;
844         init_h2fwcmd_w_parm_no_rsp(ph2c, paddbareq_parm,
845                                    GEN_CMD_CODE(_AddBAReq));
846         r8712_enqueue_cmd_ex(pcmdpriv, ph2c);
847         return _SUCCESS;
848 }
849
850 u8 r8712_wdg_wk_cmd(struct _adapter *padapter)
851 {
852         struct cmd_obj *ph2c;
853         struct drvint_cmd_parm  *pdrvintcmd_param;
854         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
855
856         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
857         if (ph2c == NULL)
858                 return _FAIL;
859         pdrvintcmd_param = kmalloc(sizeof(struct drvint_cmd_parm), GFP_ATOMIC);
860         if (pdrvintcmd_param == NULL) {
861                 kfree((unsigned char *)ph2c);
862                 return _FAIL;
863         }
864         pdrvintcmd_param->i_cid = WDG_WK_CID;
865         pdrvintcmd_param->sz = 0;
866         pdrvintcmd_param->pbuf = NULL;
867         init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvintcmd_param, _DRV_INT_CMD_);
868         r8712_enqueue_cmd_ex(pcmdpriv, ph2c);
869         return _SUCCESS;
870 }
871
872 void r8712_survey_cmd_callback(struct _adapter *padapter, struct cmd_obj *pcmd)
873 {
874         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
875
876         if (pcmd->res != H2C_SUCCESS)
877                 clr_fwstate(pmlmepriv, _FW_UNDER_SURVEY);
878         r8712_free_cmd_obj(pcmd);
879 }
880
881 void r8712_disassoc_cmd_callback(struct _adapter *padapter,
882                                  struct cmd_obj *pcmd)
883 {
884         unsigned long irqL;
885         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
886
887         if (pcmd->res != H2C_SUCCESS) {
888                 spin_lock_irqsave(&pmlmepriv->lock, irqL);
889                 set_fwstate(pmlmepriv, _FW_LINKED);
890                 spin_unlock_irqrestore(&pmlmepriv->lock, irqL);
891                 return;
892         }
893         r8712_free_cmd_obj(pcmd);
894 }
895
896 void r8712_joinbss_cmd_callback(struct _adapter *padapter, struct cmd_obj *pcmd)
897 {
898         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
899
900         if (pcmd->res != H2C_SUCCESS)
901                 _set_timer(&pmlmepriv->assoc_timer, 1);
902         r8712_free_cmd_obj(pcmd);
903 }
904
905 void r8712_createbss_cmd_callback(struct _adapter *padapter,
906                                   struct cmd_obj *pcmd)
907 {
908         unsigned long irqL;
909         u8 timer_cancelled;
910         struct sta_info *psta = NULL;
911         struct wlan_network *pwlan = NULL;
912         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
913         struct ndis_wlan_bssid_ex *pnetwork = (struct ndis_wlan_bssid_ex *)
914                                               pcmd->parmbuf;
915         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
916
917         if (pcmd->res != H2C_SUCCESS)
918                 _set_timer(&pmlmepriv->assoc_timer, 1);
919         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
920 #ifdef __BIG_ENDIAN
921         /* endian_convert */
922         pnetwork->Length = le32_to_cpu(pnetwork->Length);
923         pnetwork->Ssid.SsidLength = le32_to_cpu(pnetwork->Ssid.SsidLength);
924         pnetwork->Privacy = le32_to_cpu(pnetwork->Privacy);
925         pnetwork->Rssi = le32_to_cpu(pnetwork->Rssi);
926         pnetwork->NetworkTypeInUse = le32_to_cpu(pnetwork->NetworkTypeInUse);
927         pnetwork->Configuration.ATIMWindow = le32_to_cpu(pnetwork->
928                                         Configuration.ATIMWindow);
929         pnetwork->Configuration.DSConfig = le32_to_cpu(pnetwork->
930                                         Configuration.DSConfig);
931         pnetwork->Configuration.FHConfig.DwellTime = le32_to_cpu(pnetwork->
932                                         Configuration.FHConfig.DwellTime);
933         pnetwork->Configuration.FHConfig.HopPattern = le32_to_cpu(pnetwork->
934                                         Configuration.FHConfig.HopPattern);
935         pnetwork->Configuration.FHConfig.HopSet = le32_to_cpu(pnetwork->
936                                         Configuration.FHConfig.HopSet);
937         pnetwork->Configuration.FHConfig.Length = le32_to_cpu(pnetwork->
938                                         Configuration.FHConfig.Length);
939         pnetwork->Configuration.Length = le32_to_cpu(pnetwork->
940                                         Configuration.Length);
941         pnetwork->InfrastructureMode = le32_to_cpu(pnetwork->
942                                            InfrastructureMode);
943         pnetwork->IELength = le32_to_cpu(pnetwork->IELength);
944 #endif
945         spin_lock_irqsave(&pmlmepriv->lock, irqL);
946         if ((pmlmepriv->fw_state) & WIFI_AP_STATE) {
947                 psta = r8712_get_stainfo(&padapter->stapriv,
948                                          pnetwork->MacAddress);
949                 if (!psta) {
950                         psta = r8712_alloc_stainfo(&padapter->stapriv,
951                                                    pnetwork->MacAddress);
952                         if (psta == NULL)
953                                 goto createbss_cmd_fail;
954                 }
955                 r8712_indicate_connect(padapter);
956         } else {
957                 pwlan = _r8712_alloc_network(pmlmepriv);
958                 if (pwlan == NULL) {
959                         pwlan = r8712_get_oldest_wlan_network(
960                                 &pmlmepriv->scanned_queue);
961                         if (pwlan == NULL)
962                                 goto createbss_cmd_fail;
963                         pwlan->last_scanned = jiffies;
964                 } else
965                         list_insert_tail(&(pwlan->list),
966                                          &pmlmepriv->scanned_queue.queue);
967                 pnetwork->Length = r8712_get_ndis_wlan_bssid_ex_sz(pnetwork);
968                 memcpy(&(pwlan->network), pnetwork, pnetwork->Length);
969                 pwlan->fixed = true;
970                 memcpy(&tgt_network->network, pnetwork,
971                         (r8712_get_ndis_wlan_bssid_ex_sz(pnetwork)));
972                 if (pmlmepriv->fw_state & _FW_UNDER_LINKING)
973                         pmlmepriv->fw_state ^= _FW_UNDER_LINKING;
974                 /* we will set _FW_LINKED when there is one more sat to
975                  * join us (stassoc_event_callback) */
976         }
977 createbss_cmd_fail:
978         spin_unlock_irqrestore(&pmlmepriv->lock, irqL);
979         r8712_free_cmd_obj(pcmd);
980 }
981
982 void r8712_setstaKey_cmdrsp_callback(struct _adapter *padapter,
983                                      struct cmd_obj *pcmd)
984 {
985         struct sta_priv *pstapriv = &padapter->stapriv;
986         struct set_stakey_rsp *psetstakey_rsp = (struct set_stakey_rsp *)
987                                                 (pcmd->rsp);
988         struct sta_info *psta = r8712_get_stainfo(pstapriv,
989                                                   psetstakey_rsp->addr);
990
991         if (psta == NULL)
992                 goto exit;
993         psta->aid = psta->mac_id = psetstakey_rsp->keyid; /*CAM_ID(CAM_ENTRY)*/
994 exit:
995         r8712_free_cmd_obj(pcmd);
996 }
997
998 void r8712_setassocsta_cmdrsp_callback(struct _adapter *padapter,
999                                        struct cmd_obj *pcmd)
1000 {
1001         unsigned long   irqL;
1002         struct sta_priv *pstapriv = &padapter->stapriv;
1003         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1004         struct set_assocsta_parm *passocsta_parm =
1005                                 (struct set_assocsta_parm *)(pcmd->parmbuf);
1006         struct set_assocsta_rsp *passocsta_rsp =
1007                                 (struct set_assocsta_rsp *) (pcmd->rsp);
1008         struct sta_info *psta = r8712_get_stainfo(pstapriv,
1009                                                   passocsta_parm->addr);
1010
1011         if (psta == NULL)
1012                 return;
1013         psta->aid = psta->mac_id = passocsta_rsp->cam_id;
1014         spin_lock_irqsave(&pmlmepriv->lock, irqL);
1015         if ((check_fwstate(pmlmepriv, WIFI_MP_STATE)) &&
1016             (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)))
1017                 pmlmepriv->fw_state ^= _FW_UNDER_LINKING;
1018         set_fwstate(pmlmepriv, _FW_LINKED);
1019         spin_unlock_irqrestore(&pmlmepriv->lock, irqL);
1020         r8712_free_cmd_obj(pcmd);
1021 }
1022
1023 u8 r8712_disconnectCtrlEx_cmd(struct _adapter *adapter, u32 enableDrvCtrl,
1024                         u32 tryPktCnt, u32 tryPktInterval, u32 firstStageTO)
1025 {
1026         struct cmd_obj *ph2c;
1027         struct DisconnectCtrlEx_param *param;
1028         struct cmd_priv *pcmdpriv = &adapter->cmdpriv;
1029
1030         ph2c = kmalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
1031         if (ph2c == NULL)
1032                 return _FAIL;
1033         param = kzalloc(sizeof(struct DisconnectCtrlEx_param), GFP_ATOMIC);
1034         if (param == NULL) {
1035                 kfree((unsigned char *) ph2c);
1036                 return _FAIL;
1037         }
1038
1039         param->EnableDrvCtrl = (unsigned char)enableDrvCtrl;
1040         param->TryPktCnt = (unsigned char)tryPktCnt;
1041         param->TryPktInterval = (unsigned char)tryPktInterval;
1042         param->FirstStageTO = (unsigned int)firstStageTO;
1043
1044         init_h2fwcmd_w_parm_no_rsp(ph2c, param,
1045                                 GEN_CMD_CODE(_DisconnectCtrlEx));
1046         r8712_enqueue_cmd(pcmdpriv, ph2c);
1047         return _SUCCESS;
1048 }