Linux-libre 5.0.14-gnu
[librecmc/linux-libre.git] / drivers / staging / rtl8723bs / core / rtw_mlme.c
1 // SPDX-License-Identifier: GPL-2.0
2 /******************************************************************************
3  *
4  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
5  *
6  ******************************************************************************/
7 #define _RTW_MLME_C_
8
9 #include <linux/etherdevice.h>
10 #include <drv_types.h>
11 #include <rtw_debug.h>
12 #include <linux/jiffies.h>
13
14 extern u8 rtw_do_join(struct adapter *padapter);
15
16 sint    _rtw_init_mlme_priv(struct adapter *padapter)
17 {
18         sint    i;
19         u8 *pbuf;
20         struct wlan_network     *pnetwork;
21         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
22         sint    res = _SUCCESS;
23
24         pmlmepriv->nic_hdl = (u8 *)padapter;
25
26         pmlmepriv->pscanned = NULL;
27         pmlmepriv->fw_state = WIFI_STATION_STATE; /*  Must sync with rtw_wdev_alloc() */
28         /*  wdev->iftype = NL80211_IFTYPE_STATION */
29         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
30         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
31
32         spin_lock_init(&(pmlmepriv->lock));
33         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
34         _rtw_init_queue(&(pmlmepriv->scanned_queue));
35
36         set_scanned_network_val(pmlmepriv, 0);
37
38         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
39
40         pbuf = vzalloc(array_size(MAX_BSS_CNT, sizeof(struct wlan_network)));
41
42         if (pbuf == NULL) {
43                 res = _FAIL;
44                 goto exit;
45         }
46         pmlmepriv->free_bss_buf = pbuf;
47
48         pnetwork = (struct wlan_network *)pbuf;
49
50         for (i = 0; i < MAX_BSS_CNT; i++) {
51                 INIT_LIST_HEAD(&(pnetwork->list));
52
53                 list_add_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
54
55                 pnetwork++;
56         }
57
58         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
59
60         rtw_clear_scan_deny(padapter);
61
62         #define RTW_ROAM_SCAN_RESULT_EXP_MS 5000
63         #define RTW_ROAM_RSSI_DIFF_TH 10
64         #define RTW_ROAM_SCAN_INTERVAL_MS 10000
65
66         pmlmepriv->roam_flags = 0
67                 | RTW_ROAM_ON_EXPIRED
68                 | RTW_ROAM_ON_RESUME
69                 #ifdef CONFIG_LAYER2_ROAMING_ACTIVE /* FIXME */
70                 | RTW_ROAM_ACTIVE
71                 #endif
72                 ;
73
74         pmlmepriv->roam_scanr_exp_ms = RTW_ROAM_SCAN_RESULT_EXP_MS;
75         pmlmepriv->roam_rssi_diff_th = RTW_ROAM_RSSI_DIFF_TH;
76         pmlmepriv->roam_scan_int_ms = RTW_ROAM_SCAN_INTERVAL_MS;
77
78         rtw_init_mlme_timer(padapter);
79
80 exit:
81
82         return res;
83 }
84
85 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
86 {
87         if (*ppie) {
88                 kfree(*ppie);
89                 *plen = 0;
90                 *ppie = NULL;
91         }
92 }
93
94 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
95 {
96         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
97         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
98         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
99         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
100         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
101         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
102
103         rtw_free_mlme_ie_data(&pmlmepriv->p2p_beacon_ie, &pmlmepriv->p2p_beacon_ie_len);
104         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_req_ie, &pmlmepriv->p2p_probe_req_ie_len);
105         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_resp_ie, &pmlmepriv->p2p_probe_resp_ie_len);
106         rtw_free_mlme_ie_data(&pmlmepriv->p2p_go_probe_resp_ie, &pmlmepriv->p2p_go_probe_resp_ie_len);
107         rtw_free_mlme_ie_data(&pmlmepriv->p2p_assoc_req_ie, &pmlmepriv->p2p_assoc_req_ie_len);
108 }
109
110 void _rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
111 {
112         if (pmlmepriv) {
113                 rtw_free_mlme_priv_ie_data(pmlmepriv);
114                 if (pmlmepriv->free_bss_buf) {
115                         vfree(pmlmepriv->free_bss_buf);
116                 }
117         }
118 }
119
120 /*
121 struct  wlan_network *_rtw_dequeue_network(struct __queue *queue)
122 {
123         _irqL irqL;
124
125         struct wlan_network *pnetwork;
126
127         spin_lock_bh(&queue->lock);
128
129         if (list_empty(&queue->queue))
130
131                 pnetwork = NULL;
132
133         else
134         {
135                 pnetwork = LIST_CONTAINOR(get_next(&queue->queue), struct wlan_network, list);
136
137                 list_del_init(&(pnetwork->list));
138         }
139
140         spin_unlock_bh(&queue->lock);
141
142         return pnetwork;
143 }
144 */
145
146 struct  wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)/* _queue *free_queue) */
147 {
148         struct  wlan_network    *pnetwork;
149         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
150         struct list_head *plist = NULL;
151
152         spin_lock_bh(&free_queue->lock);
153
154         if (list_empty(&free_queue->queue)) {
155                 pnetwork = NULL;
156                 goto exit;
157         }
158         plist = get_next(&(free_queue->queue));
159
160         pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
161
162         list_del_init(&pnetwork->list);
163
164         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("_rtw_alloc_network: ptr =%p\n", plist));
165         pnetwork->network_type = 0;
166         pnetwork->fixed = false;
167         pnetwork->last_scanned = jiffies;
168         pnetwork->aid = 0;
169         pnetwork->join_res = 0;
170
171         pmlmepriv->num_of_scanned++;
172
173 exit:
174         spin_unlock_bh(&free_queue->lock);
175
176         return pnetwork;
177 }
178
179 void _rtw_free_network(struct   mlme_priv *pmlmepriv, struct wlan_network *pnetwork, u8 isfreeall)
180 {
181         unsigned int delta_time;
182         u32 lifetime = SCANQUEUE_LIFETIME;
183 /*      _irqL irqL; */
184         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
185
186         if (pnetwork == NULL)
187                 return;
188
189         if (pnetwork->fixed == true)
190                 return;
191
192         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
193                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true))
194                 lifetime = 1;
195
196         if (!isfreeall) {
197                 delta_time = jiffies_to_msecs(jiffies - pnetwork->last_scanned);
198                 if (delta_time < lifetime)/*  unit:msec */
199                         return;
200         }
201
202         spin_lock_bh(&free_queue->lock);
203
204         list_del_init(&(pnetwork->list));
205
206         list_add_tail(&(pnetwork->list), &(free_queue->queue));
207
208         pmlmepriv->num_of_scanned--;
209
210
211         /* DBG_871X("_rtw_free_network:SSID =%s\n", pnetwork->network.Ssid.Ssid); */
212
213         spin_unlock_bh(&free_queue->lock);
214 }
215
216 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
217 {
218
219         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
220
221         if (pnetwork == NULL)
222                 return;
223
224         if (pnetwork->fixed == true)
225                 return;
226
227         /* spin_lock_irqsave(&free_queue->lock, irqL); */
228
229         list_del_init(&(pnetwork->list));
230
231         list_add_tail(&(pnetwork->list), get_list_head(free_queue));
232
233         pmlmepriv->num_of_scanned--;
234
235         /* spin_unlock_irqrestore(&free_queue->lock, irqL); */
236 }
237
238 /*
239         return the wlan_network with the matching addr
240
241         Shall be called under atomic context... to avoid possible racing condition...
242 */
243 struct wlan_network *_rtw_find_network(struct __queue *scanned_queue, u8 *addr)
244 {
245         struct list_head        *phead, *plist;
246         struct  wlan_network *pnetwork = NULL;
247         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
248
249         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
250                 pnetwork = NULL;
251                 goto exit;
252         }
253
254         /* spin_lock_bh(&scanned_queue->lock); */
255
256         phead = get_list_head(scanned_queue);
257         plist = get_next(phead);
258
259         while (plist != phead) {
260                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
261
262                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
263                         break;
264
265                 plist = get_next(plist);
266         }
267
268         if (plist == phead)
269                 pnetwork = NULL;
270
271         /* spin_unlock_bh(&scanned_queue->lock); */
272
273 exit:
274         return pnetwork;
275 }
276
277 void _rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
278 {
279         struct list_head *phead, *plist;
280         struct wlan_network *pnetwork;
281         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
282         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
283
284         spin_lock_bh(&scanned_queue->lock);
285
286         phead = get_list_head(scanned_queue);
287         plist = get_next(phead);
288
289         while (phead != plist) {
290
291                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
292
293                 plist = get_next(plist);
294
295                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
296
297         }
298
299         spin_unlock_bh(&scanned_queue->lock);
300 }
301
302
303
304
305 sint rtw_if_up(struct adapter *padapter)
306 {
307
308         sint res;
309
310         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
311                 (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
312                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)", padapter->bDriverStopped, padapter->bSurpriseRemoved));
313                 res = false;
314         } else
315                 res =  true;
316         return res;
317 }
318
319
320 void rtw_generate_random_ibss(u8 *pibss)
321 {
322         unsigned long curtime = jiffies;
323
324         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
325         pibss[1] = 0x11;
326         pibss[2] = 0x87;
327         pibss[3] = (u8)(curtime & 0xff) ;/* p[0]; */
328         pibss[4] = (u8)((curtime>>8) & 0xff) ;/* p[1]; */
329         pibss[5] = (u8)((curtime>>16) & 0xff) ;/* p[2]; */
330         return;
331 }
332
333 u8 *rtw_get_capability_from_ie(u8 *ie)
334 {
335         return (ie + 8 + 2);
336 }
337
338
339 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
340 {
341         __le16  val;
342
343         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2);
344
345         return le16_to_cpu(val);
346 }
347
348 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
349 {
350         return (ie + 8);
351 }
352
353
354 int     rtw_init_mlme_priv(struct adapter *padapter)/* struct   mlme_priv *pmlmepriv) */
355 {
356         int     res;
357
358         res = _rtw_init_mlme_priv(padapter);/*  (pmlmepriv); */
359         return res;
360 }
361
362 void rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
363 {
364         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_mlme_priv\n"));
365         _rtw_free_mlme_priv(pmlmepriv);
366 }
367
368 /*
369 static struct   wlan_network *rtw_dequeue_network(struct __queue *queue)
370 {
371         struct wlan_network *pnetwork;
372
373         pnetwork = _rtw_dequeue_network(queue);
374         return pnetwork;
375 }
376 */
377
378 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv);
379 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv)/* _queue  *free_queue) */
380 {
381         struct  wlan_network    *pnetwork;
382
383         pnetwork = _rtw_alloc_network(pmlmepriv);
384         return pnetwork;
385 }
386
387 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork);
388 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork)
389 {
390         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_network ==> ssid = %s\n\n" , pnetwork->network.Ssid.Ssid)); */
391         _rtw_free_network_nolock(&(padapter->mlmepriv), pnetwork);
392         rtw_cfg80211_unlink_bss(padapter, pnetwork);
393 }
394
395
396 void rtw_free_network_queue(struct adapter *dev, u8 isfreeall)
397 {
398         _rtw_free_network_queue(dev, isfreeall);
399 }
400
401 /*
402         return the wlan_network with the matching addr
403
404         Shall be called under atomic context... to avoid possible racing condition...
405 */
406 struct  wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
407 {
408         struct  wlan_network *pnetwork = _rtw_find_network(scanned_queue, addr);
409
410         return pnetwork;
411 }
412
413 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
414 {
415         int ret = true;
416         struct security_priv *psecuritypriv = &adapter->securitypriv;
417
418         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
419                     (pnetwork->network.Privacy == 0))
420                 ret = false;
421         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
422                  (pnetwork->network.Privacy == 1))
423                 ret = false;
424         else
425                 ret = true;
426
427         return ret;
428
429 }
430
431 inline int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
432 {
433         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("(%s,%d)(%s,%d)\n", */
434         /*              a->Ssid.Ssid, a->Ssid.SsidLength, b->Ssid.Ssid, b->Ssid.SsidLength)); */
435         return (a->Ssid.SsidLength == b->Ssid.SsidLength)
436                 &&  !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
437 }
438
439 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst, u8 feature)
440 {
441         u16 s_cap, d_cap;
442         __le16 tmps, tmpd;
443
444         if (rtw_bug_check(dst, src, &s_cap, &d_cap) == false)
445                         return false;
446
447         memcpy((u8 *)&tmps, rtw_get_capability_from_ie(src->IEs), 2);
448         memcpy((u8 *)&tmpd, rtw_get_capability_from_ie(dst->IEs), 2);
449
450
451         s_cap = le16_to_cpu(tmps);
452         d_cap = le16_to_cpu(tmpd);
453
454         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
455                 /*      (src->Configuration.DSConfig == dst->Configuration.DSConfig) && */
456                         ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN))) &&
457                         ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength))) &&
458                         ((s_cap & WLAN_CAPABILITY_IBSS) ==
459                         (d_cap & WLAN_CAPABILITY_IBSS)) &&
460                         ((s_cap & WLAN_CAPABILITY_BSS) ==
461                         (d_cap & WLAN_CAPABILITY_BSS)));
462
463 }
464
465 struct wlan_network *_rtw_find_same_network(struct __queue *scanned_queue, struct wlan_network *network)
466 {
467         struct list_head *phead, *plist;
468         struct wlan_network *found = NULL;
469
470         phead = get_list_head(scanned_queue);
471         plist = get_next(phead);
472
473         while (plist != phead) {
474                 found = LIST_CONTAINOR(plist, struct wlan_network, list);
475
476                 if (is_same_network(&network->network, &found->network, 0))
477                         break;
478
479                 plist = get_next(plist);
480         }
481
482         if (plist == phead)
483                 found = NULL;
484
485         return found;
486 }
487
488 struct  wlan_network    *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
489 {
490         struct list_head        *plist, *phead;
491
492
493         struct  wlan_network    *pwlan = NULL;
494         struct  wlan_network    *oldest = NULL;
495
496         phead = get_list_head(scanned_queue);
497
498         plist = get_next(phead);
499
500         while (1) {
501
502                 if (phead == plist)
503                         break;
504
505                 pwlan = LIST_CONTAINOR(plist, struct wlan_network, list);
506
507                 if (pwlan->fixed != true) {
508                         if (oldest == NULL || time_after(oldest->last_scanned, pwlan->last_scanned))
509                                 oldest = pwlan;
510                 }
511
512                 plist = get_next(plist);
513         }
514         return oldest;
515
516 }
517
518 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
519         struct adapter *padapter, bool update_ie)
520 {
521         long rssi_ori = dst->Rssi;
522
523         u8 sq_smp = src->PhyInfo.SignalQuality;
524
525         u8 ss_final;
526         u8 sq_final;
527         long rssi_final;
528
529         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
530         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
531                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT", ch%u) ss_ori:%3u, sq_ori:%3u, rssi_ori:%3ld, ss_smp:%3u, sq_smp:%3u, rssi_smp:%3ld\n"
532                         , FUNC_ADPT_ARG(padapter)
533                         , src->Ssid.Ssid, MAC_ARG(src->MacAddress), src->Configuration.DSConfig
534                         , ss_ori, sq_ori, rssi_ori
535                         , ss_smp, sq_smp, rssi_smp
536                 );
537         }
538         #endif
539
540         /* The rule below is 1/5 for sample value, 4/5 for history value */
541         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src, 0)) {
542                 /* Take the recvpriv's value for the connected AP*/
543                 ss_final = padapter->recvpriv.signal_strength;
544                 sq_final = padapter->recvpriv.signal_qual;
545                 /* the rssi value here is undecorated, and will be used for antenna diversity */
546                 if (sq_smp != 101) /* from the right channel */
547                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
548                 else
549                         rssi_final = rssi_ori;
550         } else {
551                 if (sq_smp != 101) { /* from the right channel */
552                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
553                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
554                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
555                 } else {
556                         /* bss info not receiving from the right channel, use the original RX signal infos */
557                         ss_final = dst->PhyInfo.SignalStrength;
558                         sq_final = dst->PhyInfo.SignalQuality;
559                         rssi_final = dst->Rssi;
560                 }
561
562         }
563
564         if (update_ie) {
565                 dst->Reserved[0] = src->Reserved[0];
566                 dst->Reserved[1] = src->Reserved[1];
567                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
568         }
569
570         dst->PhyInfo.SignalStrength = ss_final;
571         dst->PhyInfo.SignalQuality = sq_final;
572         dst->Rssi = rssi_final;
573
574         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
575         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
576                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT"), SignalStrength:%u, SignalQuality:%u, RawRSSI:%ld\n"
577                         , FUNC_ADPT_ARG(padapter)
578                         , dst->Ssid.Ssid, MAC_ARG(dst->MacAddress), dst->PhyInfo.SignalStrength, dst->PhyInfo.SignalQuality, dst->Rssi);
579         }
580         #endif
581 }
582
583 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
584 {
585         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
586
587         rtw_bug_check(&(pmlmepriv->cur_network.network),
588                 &(pmlmepriv->cur_network.network),
589                 &(pmlmepriv->cur_network.network),
590                 &(pmlmepriv->cur_network.network));
591
592         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) && (is_same_network(&(pmlmepriv->cur_network.network), pnetwork, 0))) {
593                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"Same Network\n"); */
594
595                 /* if (pmlmepriv->cur_network.network.IELength<= pnetwork->IELength) */
596                 {
597                         update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
598                         rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof(struct ndis_802_11_fix_ie),
599                                                                         pmlmepriv->cur_network.network.IELength);
600                 }
601         }
602 }
603
604
605 /*
606
607 Caller must hold pmlmepriv->lock first.
608
609
610 */
611 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
612 {
613         struct list_head        *plist, *phead;
614         u32 bssid_ex_sz;
615         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
616         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
617         struct wlan_network     *pnetwork = NULL;
618         struct wlan_network     *oldest = NULL;
619         int target_find = 0;
620         u8 feature = 0;
621
622         spin_lock_bh(&queue->lock);
623         phead = get_list_head(queue);
624         plist = get_next(phead);
625
626         while (1) {
627                 if (phead == plist)
628                         break;
629
630                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
631
632                 rtw_bug_check(pnetwork, pnetwork, pnetwork, pnetwork);
633
634                 if (is_same_network(&(pnetwork->network), target, feature)) {
635                         target_find = 1;
636                         break;
637                 }
638
639                 if (rtw_roam_flags(adapter)) {
640                         /* TODO: don't  select netowrk in the same ess as oldest if it's new enough*/
641                 }
642
643                 if (oldest == NULL || time_after(oldest->last_scanned, pnetwork->last_scanned))
644                         oldest = pnetwork;
645
646                 plist = get_next(plist);
647
648         }
649
650
651         /* If we didn't find a match, then get a new network slot to initialize
652          * with this beacon's information */
653         /* if (phead == plist) { */
654         if (!target_find) {
655                 if (list_empty(&pmlmepriv->free_bss_pool.queue)) {
656                         /* If there are no more slots, expire the oldest */
657                         /* list_del_init(&oldest->list); */
658                         pnetwork = oldest;
659                         if (pnetwork == NULL) {
660                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
661                                 goto exit;
662                         }
663                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
664                         /*  variable initialize */
665                         pnetwork->fixed = false;
666                         pnetwork->last_scanned = jiffies;
667
668                         pnetwork->network_type = 0;
669                         pnetwork->aid = 0;
670                         pnetwork->join_res = 0;
671
672                         /* bss info not receiving from the right channel */
673                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
674                                 pnetwork->network.PhyInfo.SignalQuality = 0;
675                 } else {
676                         /* Otherwise just pull from the free list */
677
678                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
679
680                         if (pnetwork == NULL) {
681                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
682                                 goto exit;
683                         }
684
685                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
686                         target->Length = bssid_ex_sz;
687                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
688
689                         pnetwork->last_scanned = jiffies;
690
691                         /* bss info not receiving from the right channel */
692                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
693                                 pnetwork->network.PhyInfo.SignalQuality = 0;
694
695                         list_add_tail(&(pnetwork->list), &(queue->queue));
696
697                 }
698         } else {
699                 /* we have an entry and we are going to update it. But this entry may
700                  * be already expired. In this case we do the same as we found a new
701                  * net and call the new_net handler
702                  */
703                 bool update_ie = true;
704
705                 pnetwork->last_scanned = jiffies;
706
707                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
708                 if ((pnetwork->network.IELength > target->IELength) && (target->Reserved[0] == 1))
709                         update_ie = false;
710
711                 /*  probe resp(3) > beacon(1) > probe req(2) */
712                 if ((target->Reserved[0] != 2) &&
713                         (target->Reserved[0] >= pnetwork->network.Reserved[0])
714                         ) {
715                         update_ie = true;
716                 } else {
717                         update_ie = false;
718                 }
719
720                 update_network(&(pnetwork->network), target, adapter, update_ie);
721         }
722
723 exit:
724         spin_unlock_bh(&queue->lock);
725 }
726
727 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork);
728 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
729 {
730         /* struct __queue       *queue  = &(pmlmepriv->scanned_queue); */
731
732         /* spin_lock_bh(&queue->lock); */
733
734         update_current_network(adapter, pnetwork);
735
736         rtw_update_scanned_network(adapter, pnetwork);
737
738         /* spin_unlock_bh(&queue->lock); */
739 }
740
741 /* select the desired network based on the capability of the (i)bss. */
742 /*  check items: (1) security */
743 /*                         (2) network_type */
744 /*                         (3) WMM */
745 /*                         (4) HT */
746 /*                      (5) others */
747 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork);
748 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
749 {
750         struct security_priv *psecuritypriv = &adapter->securitypriv;
751         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
752         u32 desired_encmode;
753         u32 privacy;
754
755         /* u8 wps_ie[512]; */
756         uint wps_ielen;
757
758         int bselected = true;
759
760         desired_encmode = psecuritypriv->ndisencryptstatus;
761         privacy = pnetwork->network.Privacy;
762
763         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
764                 if (rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen) != NULL)
765                         return true;
766                 else
767                         return false;
768
769         }
770         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
771                 u8 *p = NULL;
772                 uint ie_len = 0;
773
774                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
775             bselected = false;
776
777                 if (psecuritypriv->ndisauthtype == Ndis802_11AuthModeWPA2PSK) {
778                         p = rtw_get_ie(pnetwork->network.IEs + _BEACON_IE_OFFSET_, _RSN_IE_2_, &ie_len, (pnetwork->network.IELength - _BEACON_IE_OFFSET_));
779                         if (p && ie_len > 0) {
780                                 bselected = true;
781                         } else {
782                                 bselected = false;
783                         }
784                 }
785         }
786
787
788         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
789                 DBG_871X("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
790                 bselected = false;
791         }
792
793         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
794                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
795                         bselected = false;
796         }
797
798
799         return bselected;
800 }
801
802 /* TODO: Perry : For Power Management */
803 void rtw_atimdone_event_callback(struct adapter *adapter, u8 *pbuf)
804 {
805         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_event\n"));
806 }
807
808
809 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
810 {
811         u32 len;
812         struct wlan_bssid_ex *pnetwork;
813         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
814
815         pnetwork = (struct wlan_bssid_ex *)pbuf;
816
817         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid =%s\n",  pnetwork->Ssid.Ssid));
818
819         len = get_wlan_bssid_ex_sz(pnetwork);
820         if (len > (sizeof(struct wlan_bssid_ex))) {
821                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n ****rtw_survey_event_callback: return a wrong bss ***\n"));
822                 return;
823         }
824
825
826         spin_lock_bh(&pmlmepriv->lock);
827
828         /*  update IBSS_network 's timestamp */
829         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) {
830                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"rtw_survey_event_callback : WIFI_ADHOC_MASTER_STATE\n\n"); */
831                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN)) {
832                         struct wlan_network *ibss_wlan = NULL;
833
834                         memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
835                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
836                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
837                         if (ibss_wlan) {
838                                 memcpy(ibss_wlan->network.IEs, pnetwork->IEs, 8);
839                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
840                                 goto exit;
841                         }
842                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
843                 }
844         }
845
846         /*  lock pmlmepriv->lock when you accessing network_q */
847         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false) {
848                 if (pnetwork->Ssid.Ssid[0] == 0) {
849                         pnetwork->Ssid.SsidLength = 0;
850                 }
851                 rtw_add_network(adapter, pnetwork);
852         }
853
854 exit:
855
856         spin_unlock_bh(&pmlmepriv->lock);
857
858         return;
859 }
860
861
862
863 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
864 {
865         u8 timer_cancelled = false;
866         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
867
868         spin_lock_bh(&pmlmepriv->lock);
869         if (pmlmepriv->wps_probe_req_ie) {
870                 pmlmepriv->wps_probe_req_ie_len = 0;
871                 kfree(pmlmepriv->wps_probe_req_ie);
872                 pmlmepriv->wps_probe_req_ie = NULL;
873         }
874
875         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
876
877         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
878                 /* u8 timer_cancelled; */
879
880                 timer_cancelled = true;
881                 /* _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled); */
882
883                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
884         } else {
885
886                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status =%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
887         }
888         spin_unlock_bh(&pmlmepriv->lock);
889
890         if (timer_cancelled)
891                 _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
892
893
894         spin_lock_bh(&pmlmepriv->lock);
895
896         rtw_set_signal_stat_timer(&adapter->recvpriv);
897
898         if (pmlmepriv->to_join == true) {
899                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
900                         if (check_fwstate(pmlmepriv, _FW_LINKED) == false) {
901                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
902
903                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
904                                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
905                                 } else {
906                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
907                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
908
909                                         /* pmlmepriv->fw_state ^= _FW_UNDER_SURVEY;because don't set assoc_timer */
910                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
911
912                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
913
914                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
915
916                                         rtw_update_registrypriv_dev_network(adapter);
917                                         rtw_generate_random_ibss(pibss);
918
919                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
920
921                                         if (rtw_createbss_cmd(adapter) != _SUCCESS) {
922                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error =>rtw_createbss_cmd status FAIL\n"));
923                                         }
924
925                                         pmlmepriv->to_join = false;
926                                 }
927                         }
928                 } else {
929                         int s_ret;
930                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
931                         pmlmepriv->to_join = false;
932                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
933                         if (_SUCCESS == s_ret) {
934                              _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
935                         } else if (s_ret == 2) {/* there is no need to wait for join */
936                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
937                                 rtw_indicate_connect(adapter);
938                         } else {
939                                 DBG_871X("try_to_join, but select scanning queue fail, to_roam:%d\n", rtw_to_roam(adapter));
940
941                                 if (rtw_to_roam(adapter) != 0) {
942                                         if (rtw_dec_to_roam(adapter) == 0
943                                                 || _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)
944                                         ) {
945                                                 rtw_set_to_roam(adapter, 0);
946 #ifdef CONFIG_INTEL_WIDI
947                                                 if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING) {
948                                                         memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
949                                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
950                                                         DBG_871X("change to widi listen\n");
951                                                 }
952 #endif /*  CONFIG_INTEL_WIDI */
953                                                 rtw_free_assoc_resources(adapter, 1);
954                                                 rtw_indicate_disconnect(adapter);
955                                         } else {
956                                                 pmlmepriv->to_join = true;
957                                         }
958                                 } else
959                                         rtw_indicate_disconnect(adapter);
960
961                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
962                         }
963                 }
964         } else {
965                 if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
966                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)
967                                 && check_fwstate(pmlmepriv, _FW_LINKED)) {
968                                 if (rtw_select_roaming_candidate(pmlmepriv) == _SUCCESS) {
969                                         receive_disconnect(adapter, pmlmepriv->cur_network.network.MacAddress
970                                                 , WLAN_REASON_ACTIVE_ROAM);
971                                 }
972                         }
973                 }
974         }
975
976         /* DBG_871X("scan complete in %dms\n", jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time)); */
977
978         spin_unlock_bh(&pmlmepriv->lock);
979
980         rtw_os_xmit_schedule(adapter);
981
982         rtw_cfg80211_surveydone_event_callback(adapter);
983
984         rtw_indicate_scan_done(adapter, false);
985 }
986
987 void rtw_dummy_event_callback(struct adapter *adapter, u8 *pbuf)
988 {
989 }
990
991 void rtw_fwdbg_event_callback(struct adapter *adapter, u8 *pbuf)
992 {
993 }
994
995 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
996 {
997         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
998         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
999         struct list_head        *plist, *phead, *ptemp;
1000
1001         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
1002         spin_lock_bh(&scan_queue->lock);
1003         spin_lock_bh(&free_queue->lock);
1004
1005         phead = get_list_head(scan_queue);
1006         plist = get_next(phead);
1007
1008         while (plist != phead) {
1009                 ptemp = get_next(plist);
1010                 list_del_init(plist);
1011                 list_add_tail(plist, &free_queue->queue);
1012                 plist = ptemp;
1013                 pmlmepriv->num_of_scanned--;
1014         }
1015
1016         spin_unlock_bh(&free_queue->lock);
1017         spin_unlock_bh(&scan_queue->lock);
1018 }
1019
1020 static void rtw_reset_rx_info(struct debug_priv *pdbgpriv)
1021 {
1022         pdbgpriv->dbg_rx_ampdu_drop_count = 0;
1023         pdbgpriv->dbg_rx_ampdu_forced_indicate_count = 0;
1024         pdbgpriv->dbg_rx_ampdu_loss_count = 0;
1025         pdbgpriv->dbg_rx_dup_mgt_frame_drop_count = 0;
1026         pdbgpriv->dbg_rx_ampdu_window_shift_cnt = 0;
1027 }
1028
1029 static void find_network(struct adapter *adapter)
1030 {
1031         struct wlan_network *pwlan = NULL;
1032         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1033         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1034
1035         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1036         if (pwlan)
1037                 pwlan->fixed = false;
1038         else
1039                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources : pwlan == NULL\n\n"));
1040
1041
1042         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) &&
1043             (adapter->stapriv.asoc_sta_count == 1))
1044                 rtw_free_network_nolock(adapter, pwlan);
1045 }
1046
1047 /*
1048 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
1049 */
1050 void rtw_free_assoc_resources(struct adapter *adapter, int lock_scanned_queue)
1051 {
1052         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1053         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1054         struct  sta_priv *pstapriv = &adapter->stapriv;
1055         struct dvobj_priv *psdpriv = adapter->dvobj;
1056         struct debug_priv *pdbgpriv = &psdpriv->drv_dbg;
1057
1058         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
1059         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("tgt_network->network.MacAddress ="MAC_FMT" ssid =%s\n",
1060                 MAC_ARG(tgt_network->network.MacAddress), tgt_network->network.Ssid.Ssid));
1061
1062         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_AP_STATE)) {
1063                 struct sta_info *psta;
1064
1065                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
1066                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1067                 rtw_free_stainfo(adapter,  psta);
1068
1069                 spin_unlock_bh(&(pstapriv->sta_hash_lock));
1070
1071         }
1072
1073         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE|WIFI_AP_STATE)) {
1074                 struct sta_info *psta;
1075
1076                 rtw_free_all_stainfo(adapter);
1077
1078                 psta = rtw_get_bcmc_stainfo(adapter);
1079                 rtw_free_stainfo(adapter, psta);
1080
1081                 rtw_init_bcmc_stainfo(adapter);
1082         }
1083
1084         find_network(adapter);
1085
1086         if (lock_scanned_queue)
1087                 adapter->securitypriv.key_mask = 0;
1088
1089         rtw_reset_rx_info(pdbgpriv);
1090 }
1091
1092 /*
1093 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
1094 */
1095 void rtw_indicate_connect(struct adapter *padapter)
1096 {
1097         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1098
1099         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
1100
1101         pmlmepriv->to_join = false;
1102
1103         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
1104
1105                 set_fwstate(pmlmepriv, _FW_LINKED);
1106
1107                 rtw_os_indicate_connect(padapter);
1108         }
1109
1110         rtw_set_to_roam(padapter, 0);
1111 #ifdef CONFIG_INTEL_WIDI
1112         if (padapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING) {
1113                 memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1114                 intel_widi_wk_cmd(padapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1115                 DBG_871X("change to widi listen\n");
1116         }
1117 #endif /*  CONFIG_INTEL_WIDI */
1118
1119         rtw_set_scan_deny(padapter, 3000);
1120
1121         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state = 0x%08x\n", get_fwstate(pmlmepriv)));
1122 }
1123
1124 /*
1125 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
1126 */
1127 void rtw_indicate_disconnect(struct adapter *padapter)
1128 {
1129         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
1130
1131         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
1132
1133         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING|WIFI_UNDER_WPS);
1134
1135         /* DBG_871X("clear wps when %s\n", __func__); */
1136
1137         if (rtw_to_roam(padapter) > 0)
1138                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1139
1140         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED)
1141                 || (rtw_to_roam(padapter) <= 0)
1142         ) {
1143                 rtw_os_indicate_disconnect(padapter);
1144
1145                 /* set ips_deny_time to avoid enter IPS before LPS leave */
1146                 rtw_set_ips_deny(padapter, 3000);
1147
1148                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1149
1150                 rtw_clear_scan_deny(padapter);
1151         }
1152
1153         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
1154 }
1155
1156 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
1157 {
1158         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1159
1160         rtw_os_indicate_scan_done(padapter, aborted);
1161
1162         if (is_primary_adapter(padapter) &&
1163             (!adapter_to_pwrctl(padapter)->bInSuspend) &&
1164             (!check_fwstate(&padapter->mlmepriv,
1165                             WIFI_ASOC_STATE|WIFI_UNDER_LINKING))) {
1166                 struct pwrctrl_priv *pwrpriv;
1167
1168                 pwrpriv = adapter_to_pwrctl(padapter);
1169                 rtw_set_ips_deny(padapter, 0);
1170                 _set_timer(&padapter->mlmepriv.dynamic_chk_timer, 1);
1171         }
1172 }
1173
1174 void rtw_scan_abort(struct adapter *adapter)
1175 {
1176         unsigned long start;
1177         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1178         struct mlme_ext_priv *pmlmeext = &(adapter->mlmeextpriv);
1179
1180         start = jiffies;
1181         pmlmeext->scan_abort = true;
1182         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)
1183                 && jiffies_to_msecs(start) <= 200) {
1184
1185                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1186                         break;
1187
1188                 DBG_871X(FUNC_NDEV_FMT"fw_state = _FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1189                 msleep(20);
1190         }
1191
1192         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
1193                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
1194                         DBG_871X(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1195                 rtw_indicate_scan_done(adapter, true);
1196         }
1197         pmlmeext->scan_abort = false;
1198 }
1199
1200 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
1201 {
1202         int i;
1203         struct sta_info *bmc_sta, *psta = NULL;
1204         struct recv_reorder_ctrl *preorder_ctrl;
1205         struct sta_priv *pstapriv = &padapter->stapriv;
1206         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1207
1208         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
1209         if (psta == NULL) {
1210                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
1211         }
1212
1213         if (psta) { /* update ptarget_sta */
1214
1215                 DBG_871X("%s\n", __func__);
1216
1217                 psta->aid  = pnetwork->join_res;
1218
1219                 update_sta_info(padapter, psta);
1220
1221                 /* update station supportRate */
1222                 psta->bssratelen = rtw_get_rateset_len(pnetwork->network.SupportedRates);
1223                 memcpy(psta->bssrateset, pnetwork->network.SupportedRates, psta->bssratelen);
1224                 rtw_hal_update_sta_rate_mask(padapter, psta);
1225
1226                 psta->wireless_mode = pmlmeext->cur_wireless_mode;
1227                 psta->raid = rtw_hal_networktype_to_raid(padapter, psta);
1228
1229
1230                 /* sta mode */
1231                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
1232
1233                 /* security related */
1234                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1235                         padapter->securitypriv.binstallGrpkey = false;
1236                         padapter->securitypriv.busetkipkey = false;
1237                         padapter->securitypriv.bgrpkey_handshake = false;
1238
1239                         psta->ieee8021x_blocked = true;
1240                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
1241
1242                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
1243
1244                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
1245                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
1246
1247                         memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
1248                         psta->dot11txpn.val = psta->dot11txpn.val + 1;
1249                         memset((u8 *)&psta->dot11wtxpn, 0, sizeof(union pn48));
1250                         memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
1251                 }
1252
1253                 /*      Commented by Albert 2012/07/21 */
1254                 /*      When doing the WPS, the wps_ie_len won't equal to 0 */
1255                 /*      And the Wi-Fi driver shouldn't allow the data packet to be transmitted. */
1256                 if (padapter->securitypriv.wps_ie_len != 0) {
1257                         psta->ieee8021x_blocked = true;
1258                         padapter->securitypriv.wps_ie_len = 0;
1259                 }
1260
1261
1262                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
1263                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
1264                 /* todo: check if AP can send A-MPDU packets */
1265                 for (i = 0; i < 16 ; i++) {
1266                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1267                         preorder_ctrl = &psta->recvreorder_ctrl[i];
1268                         preorder_ctrl->enable = false;
1269                         preorder_ctrl->indicate_seq = 0xffff;
1270                         #ifdef DBG_RX_SEQ
1271                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1272                                 preorder_ctrl->indicate_seq);
1273                         #endif
1274                         preorder_ctrl->wend_b = 0xffff;
1275                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1276                 }
1277
1278
1279                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
1280                 if (bmc_sta) {
1281                         for (i = 0; i < 16 ; i++) {
1282                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1283                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
1284                                 preorder_ctrl->enable = false;
1285                                 preorder_ctrl->indicate_seq = 0xffff;
1286                                 #ifdef DBG_RX_SEQ
1287                                 DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1288                                         preorder_ctrl->indicate_seq);
1289                                 #endif
1290                                 preorder_ctrl->wend_b = 0xffff;
1291                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1292                         }
1293                 }
1294         }
1295
1296         return psta;
1297
1298 }
1299
1300 /* pnetwork : returns from rtw_joinbss_event_callback */
1301 /* ptarget_wlan: found from scanned_queue */
1302 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
1303 {
1304         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1305         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
1306
1307         DBG_871X("%s\n", __func__);
1308
1309         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nfw_state:%x, BSSID:"MAC_FMT"\n"
1310                 , get_fwstate(pmlmepriv), MAC_ARG(pnetwork->network.MacAddress)));
1311
1312
1313         /*  why not use ptarget_wlan?? */
1314         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
1315         /*  some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs */
1316         cur_network->network.IELength = ptarget_wlan->network.IELength;
1317         memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
1318
1319         cur_network->aid = pnetwork->join_res;
1320
1321
1322         rtw_set_signal_stat_timer(&padapter->recvpriv);
1323
1324         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
1325         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
1326         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
1327         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
1328         #if defined(DBG_RX_SIGNAL_DISPLAY_PROCESSING) && 1
1329                 DBG_871X(FUNC_ADPT_FMT" signal_strength:%3u, rssi:%3d, signal_qual:%3u"
1330                         "\n"
1331                         , FUNC_ADPT_ARG(padapter)
1332                         , padapter->recvpriv.signal_strength
1333                         , padapter->recvpriv.rssi
1334                         , padapter->recvpriv.signal_qual
1335         );
1336         #endif
1337
1338         rtw_set_signal_stat_timer(&padapter->recvpriv);
1339
1340         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
1341         switch (pnetwork->network.InfrastructureMode) {
1342         case Ndis802_11Infrastructure:
1343
1344                         if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
1345                                 pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
1346                         else
1347                                 pmlmepriv->fw_state = WIFI_STATION_STATE;
1348
1349                         break;
1350         case Ndis802_11IBSS:
1351                         pmlmepriv->fw_state = WIFI_ADHOC_STATE;
1352                         break;
1353         default:
1354                         pmlmepriv->fw_state = WIFI_NULL_STATE;
1355                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
1356                         break;
1357         }
1358
1359         rtw_update_protection(padapter, (cur_network->network.IEs) + sizeof(struct ndis_802_11_fix_ie),
1360                                                                         (cur_network->network.IELength));
1361
1362         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength, (u8) cur_network->network.Configuration.DSConfig);
1363 }
1364
1365 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
1366 /* pnetwork : returns from rtw_joinbss_event_callback */
1367 /* ptarget_wlan: found from scanned_queue */
1368 /* if join_res > 0, for (fw_state ==WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
1369 /* if join_res > 0, for (fw_state ==WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
1370 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
1371 /*  */
1372 /* define REJOIN */
1373 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
1374 {
1375         static u8 retry;
1376         u8 timer_cancelled;
1377         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
1378         struct  sta_priv *pstapriv = &adapter->stapriv;
1379         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1380         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1381         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1382         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1383         unsigned int            the_same_macaddr = false;
1384
1385         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res =%d\n", pnetwork->join_res));
1386
1387         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1388
1389
1390         if (pmlmepriv->assoc_ssid.SsidLength == 0) {
1391                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
1392         } else {
1393                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
1394         }
1395
1396         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1397
1398         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1399         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
1400                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1401                 return;
1402         }
1403
1404         spin_lock_bh(&pmlmepriv->lock);
1405
1406         pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 0;
1407         pmlmepriv->LinkDetectInfo.LowPowerTransitionCount = 0;
1408
1409         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\n rtw_joinbss_event_callback !! spin_lock_irqsave\n"));
1410
1411         if (pnetwork->join_res > 0) {
1412                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1413                 retry = 0;
1414                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1415                         /* s1. find ptarget_wlan */
1416                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1417                                 if (the_same_macaddr == true) {
1418                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1419                                 } else {
1420                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1421                                         if (pcur_wlan)
1422                                                 pcur_wlan->fixed = false;
1423
1424                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1425                                         if (pcur_sta)
1426                                                 rtw_free_stainfo(adapter,  pcur_sta);
1427
1428                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1429                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1430                                                 if (ptarget_wlan)
1431                                                         ptarget_wlan->fixed = true;
1432                                         }
1433                                 }
1434
1435                         } else {
1436                                 ptarget_wlan = _rtw_find_same_network(&pmlmepriv->scanned_queue, pnetwork);
1437                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1438                                         if (ptarget_wlan)
1439                                                 ptarget_wlan->fixed = true;
1440                                 }
1441                         }
1442
1443                         /* s2. update cur_network */
1444                         if (ptarget_wlan) {
1445                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1446                         } else {
1447                                 DBG_871X_LEVEL(_drv_always_, "Can't find ptarget_wlan when joinbss_event callback\n");
1448                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1449                                 goto ignore_joinbss_callback;
1450                         }
1451
1452
1453                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1454                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1455                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1456                                 if (ptarget_sta == NULL) {
1457                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1458                                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1459                                         goto ignore_joinbss_callback;
1460                                 }
1461                         }
1462
1463                         /* s4. indicate connect */
1464                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1465                                 pmlmepriv->cur_network_scanned = ptarget_wlan;
1466                                 rtw_indicate_connect(adapter);
1467                         } else {
1468                                 /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1469                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1470                         }
1471
1472
1473                         /* s5. Cancel assoc_timer */
1474                         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
1475
1476                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancel assoc_timer\n"));
1477
1478                 } else {
1479                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1480                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1481                         goto ignore_joinbss_callback;
1482                 }
1483
1484                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1485
1486         } else if (pnetwork->join_res == -4) {
1487                 rtw_reset_securitypriv(adapter);
1488                 _set_timer(&pmlmepriv->assoc_timer, 1);
1489
1490                 /* rtw_free_assoc_resources(adapter, 1); */
1491
1492                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true) {
1493                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state =%x\n", get_fwstate(pmlmepriv)));
1494                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1495                 }
1496
1497         } else {/* if join_res < 0 (join fails), then try again */
1498
1499                 #ifdef REJOIN
1500                 res = _FAIL;
1501                 if (retry < 2) {
1502                         res = rtw_select_and_join_from_scanned_queue(pmlmepriv);
1503                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_select_and_join_from_scanned_queue again! res:%d\n", res));
1504                 }
1505
1506                 if (res == _SUCCESS) {
1507                         /* extend time of assoc_timer */
1508                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
1509                         retry++;
1510                 } else if (res == 2) {/* there is no need to wait for join */
1511                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1512                         rtw_indicate_connect(adapter);
1513                 } else {
1514                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Set Assoc_Timer = 1; can't find match ssid in scanned_q\n"));
1515                 #endif
1516
1517                         _set_timer(&pmlmepriv->assoc_timer, 1);
1518                         /* rtw_free_assoc_resources(adapter, 1); */
1519                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1520
1521                 #ifdef REJOIN
1522                         retry = 0;
1523                 }
1524                 #endif
1525         }
1526
1527 ignore_joinbss_callback:
1528
1529         spin_unlock_bh(&pmlmepriv->lock);
1530 }
1531
1532 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1533 {
1534         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1535
1536         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1537
1538         rtw_os_xmit_schedule(adapter);
1539 }
1540
1541 /* FOR STA, AP , AD-HOC mode */
1542 void rtw_sta_media_status_rpt(struct adapter *adapter, struct sta_info *psta, u32 mstatus)
1543 {
1544         u16 media_status_rpt;
1545
1546         if (psta == NULL)
1547                 return;
1548
1549         media_status_rpt = (u16)((psta->mac_id<<8)|mstatus); /*   MACID|OPMODE:1 connect */
1550         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status_rpt);
1551 }
1552
1553 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1554 {
1555         struct sta_info *psta;
1556         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1557         struct stassoc_event    *pstassoc       = (struct stassoc_event *)pbuf;
1558         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1559         struct wlan_network     *ptarget_wlan = NULL;
1560
1561         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1562                 return;
1563
1564         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1565                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1566                 if (psta) {
1567                         u8 *passoc_req = NULL;
1568                         u32 assoc_req_len = 0;
1569
1570                         rtw_sta_media_status_rpt(adapter, psta, 1);
1571
1572 #ifndef CONFIG_AUTO_AP_MODE
1573
1574                         ap_sta_info_defer_update(adapter, psta);
1575
1576                         /* report to upper layer */
1577                         DBG_871X("indicate_sta_assoc_event to upper layer - hostapd\n");
1578                         spin_lock_bh(&psta->lock);
1579                         if (psta->passoc_req && psta->assoc_req_len > 0) {
1580                                 passoc_req = rtw_zmalloc(psta->assoc_req_len);
1581                                 if (passoc_req) {
1582                                         assoc_req_len = psta->assoc_req_len;
1583                                         memcpy(passoc_req, psta->passoc_req, assoc_req_len);
1584
1585                                         kfree(psta->passoc_req);
1586                                         psta->passoc_req = NULL;
1587                                         psta->assoc_req_len = 0;
1588                                 }
1589                         }
1590                         spin_unlock_bh(&psta->lock);
1591
1592                         if (passoc_req && assoc_req_len > 0) {
1593                                 rtw_cfg80211_indicate_sta_assoc(adapter, passoc_req, assoc_req_len);
1594
1595                                 kfree(passoc_req);
1596                         }
1597 #endif /* CONFIG_AUTO_AP_MODE */
1598                 }
1599                 return;
1600         }
1601
1602         /* for AD-HOC mode */
1603         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1604         if (psta != NULL) {
1605                 /* the sta have been in sta_info_queue => do nothing */
1606
1607                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1608
1609                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1610         }
1611
1612         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1613         if (psta == NULL) {
1614                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1615                 return;
1616         }
1617
1618         /* to do : init sta_info variable */
1619         psta->qos_option = 0;
1620         psta->mac_id = (uint)pstassoc->cam_id;
1621         /* psta->aid = (uint)pstassoc->cam_id; */
1622         DBG_871X("%s\n", __func__);
1623         /* for ad-hoc mode */
1624         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1625
1626         rtw_sta_media_status_rpt(adapter, psta, 1);
1627
1628         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1629                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1630
1631
1632         psta->ieee8021x_blocked = false;
1633
1634         spin_lock_bh(&pmlmepriv->lock);
1635
1636         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
1637                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
1638                 if (adapter->stapriv.asoc_sta_count == 2) {
1639                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1640                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1641                         pmlmepriv->cur_network_scanned = ptarget_wlan;
1642                         if (ptarget_wlan)
1643                                 ptarget_wlan->fixed = true;
1644                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1645                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1646                         rtw_indicate_connect(adapter);
1647                 }
1648         }
1649
1650         spin_unlock_bh(&pmlmepriv->lock);
1651
1652
1653         mlmeext_sta_add_event_callback(adapter, psta);
1654 }
1655
1656 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1657 {
1658         int mac_id = (-1);
1659         struct sta_info *psta;
1660         struct wlan_network *pwlan = NULL;
1661         struct wlan_bssid_ex    *pdev_network = NULL;
1662         u8 *pibss = NULL;
1663         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1664         struct  stadel_event *pstadel   = (struct stadel_event *)pbuf;
1665         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1666         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1667         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1668
1669         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1670         if (psta)
1671                 mac_id = psta->mac_id;
1672         else
1673                 mac_id = pstadel->mac_id;
1674
1675         DBG_871X("%s(mac_id =%d) =" MAC_FMT "\n", __func__, mac_id, MAC_ARG(pstadel->macaddr));
1676
1677         if (mac_id >= 0) {
1678                 u16 media_status;
1679                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1680                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1681                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1682         }
1683
1684         /* if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) */
1685         if ((pmlmeinfo->state&0x03) == WIFI_FW_AP_STATE)
1686                 return;
1687
1688
1689         mlmeext_sta_del_event_callback(adapter);
1690
1691         spin_lock_bh(&pmlmepriv->lock);
1692
1693         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1694                 u16 reason = *((unsigned short *)(pstadel->rsvd));
1695                 bool roam = false;
1696                 struct wlan_network *roam_target = NULL;
1697
1698                 if (adapter->registrypriv.wifi_spec == 1) {
1699                         roam = false;
1700                 } else if (reason == WLAN_REASON_EXPIRATION_CHK && rtw_chk_roam_flags(adapter, RTW_ROAM_ON_EXPIRED)) {
1701                         roam = true;
1702                 } else if (reason == WLAN_REASON_ACTIVE_ROAM && rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1703                         roam = true;
1704                         roam_target = pmlmepriv->roam_network;
1705                 }
1706 #ifdef CONFIG_INTEL_WIDI
1707                 else if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_CONNECTED) {
1708                         roam = true;
1709                 }
1710 #endif /*  CONFIG_INTEL_WIDI */
1711
1712                 if (roam == true) {
1713                         if (rtw_to_roam(adapter) > 0)
1714                                 rtw_dec_to_roam(adapter); /* this stadel_event is caused by roaming, decrease to_roam */
1715                         else if (rtw_to_roam(adapter) == 0)
1716                                 rtw_set_to_roam(adapter, adapter->registrypriv.max_roaming_times);
1717                 } else {
1718                         rtw_set_to_roam(adapter, 0);
1719                 }
1720
1721                 rtw_free_uc_swdec_pending_queue(adapter);
1722
1723                 rtw_free_assoc_resources(adapter, 1);
1724                 rtw_indicate_disconnect(adapter);
1725
1726                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1727                 /*  remove the network entry in scanned_queue */
1728                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1729                 if (pwlan) {
1730                         pwlan->fixed = false;
1731                         rtw_free_network_nolock(adapter, pwlan);
1732                 }
1733                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1734
1735 #ifdef CONFIG_INTEL_WIDI
1736                 if (!rtw_to_roam(adapter))
1737                         process_intel_widi_disconnect(adapter, 1);
1738 #endif /*  CONFIG_INTEL_WIDI */
1739
1740                 _rtw_roaming(adapter, roam_target);
1741         }
1742
1743         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1744               check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1745
1746                 rtw_free_stainfo(adapter,  psta);
1747
1748                 if (adapter->stapriv.asoc_sta_count == 1) {/* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1749                         /* rtw_indicate_disconnect(adapter);removed@20091105 */
1750                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1751                         /* free old ibss network */
1752                         /* pwlan = rtw_find_network(&pmlmepriv->scanned_queue, pstadel->macaddr); */
1753                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1754                         if (pwlan) {
1755                                 pwlan->fixed = false;
1756                                 rtw_free_network_nolock(adapter, pwlan);
1757                         }
1758                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1759                         /* re-create ibss */
1760                         pdev_network = &(adapter->registrypriv.dev_network);
1761                         pibss = adapter->registrypriv.dev_network.MacAddress;
1762
1763                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1764
1765                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1766
1767                         rtw_update_registrypriv_dev_network(adapter);
1768
1769                         rtw_generate_random_ibss(pibss);
1770
1771                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1772                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1773                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1774                         }
1775
1776                         if (rtw_createbss_cmd(adapter) != _SUCCESS) {
1777
1778                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error =>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1779
1780                         }
1781
1782
1783                 }
1784
1785         }
1786
1787         spin_unlock_bh(&pmlmepriv->lock);
1788 }
1789
1790 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1791 {
1792         struct reportpwrstate_parm *preportpwrstate;
1793
1794         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1795         preportpwrstate = (struct reportpwrstate_parm *)pbuf;
1796         preportpwrstate->state |= (u8)(adapter_to_pwrctl(padapter)->cpwm_tog + 0x80);
1797         cpwm_int_hdl(padapter, preportpwrstate);
1798 }
1799
1800
1801 void rtw_wmm_event_callback(struct adapter *padapter, u8 *pbuf)
1802 {
1803         WMMOnAssocRsp(padapter);
1804 }
1805
1806 /*
1807 * _rtw_join_timeout_handler - Timeout/failure handler for CMD JoinBss
1808 * @adapter: pointer to struct adapter structure
1809 */
1810 void _rtw_join_timeout_handler(struct timer_list *t)
1811 {
1812         struct adapter *adapter = from_timer(adapter, t,
1813                                                   mlmepriv.assoc_timer);
1814         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1815
1816         DBG_871X("%s, fw_state =%x\n", __func__, get_fwstate(pmlmepriv));
1817
1818         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1819                 return;
1820
1821         spin_lock_bh(&pmlmepriv->lock);
1822
1823         if (rtw_to_roam(adapter) > 0) { /* join timeout caused by roaming */
1824                 while (1) {
1825                         rtw_dec_to_roam(adapter);
1826                         if (rtw_to_roam(adapter) != 0) { /* try another */
1827                                 int do_join_r;
1828                                 DBG_871X("%s try another roaming\n", __func__);
1829                                 do_join_r = rtw_do_join(adapter);
1830                                 if (_SUCCESS != do_join_r) {
1831                                         DBG_871X("%s roaming do_join return %d\n", __func__, do_join_r);
1832                                         continue;
1833                                 }
1834                                 break;
1835                         } else {
1836 #ifdef CONFIG_INTEL_WIDI
1837                                 if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING) {
1838                                         memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1839                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1840                                         DBG_871X("change to widi listen\n");
1841                                 }
1842 #endif /*  CONFIG_INTEL_WIDI */
1843                                 DBG_871X("%s We've try roaming but fail\n", __func__);
1844                                 rtw_indicate_disconnect(adapter);
1845                                 break;
1846                         }
1847                 }
1848
1849         } else {
1850                 rtw_indicate_disconnect(adapter);
1851                 free_scanqueue(pmlmepriv);/*  */
1852
1853                 /* indicate disconnect for the case that join_timeout and check_fwstate != FW_LINKED */
1854                 rtw_cfg80211_indicate_disconnect(adapter);
1855
1856         }
1857
1858         spin_unlock_bh(&pmlmepriv->lock);
1859 }
1860
1861 /*
1862 * rtw_scan_timeout_handler - Timeout/Failure handler for CMD SiteSurvey
1863 * @adapter: pointer to struct adapter structure
1864 */
1865 void rtw_scan_timeout_handler(struct timer_list *t)
1866 {
1867         struct adapter *adapter = from_timer(adapter, t,
1868                                                   mlmepriv.scan_to_timer);
1869         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1870
1871         DBG_871X(FUNC_ADPT_FMT" fw_state =%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1872
1873         spin_lock_bh(&pmlmepriv->lock);
1874
1875         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1876
1877         spin_unlock_bh(&pmlmepriv->lock);
1878
1879         rtw_indicate_scan_done(adapter, true);
1880 }
1881
1882 void rtw_mlme_reset_auto_scan_int(struct adapter *adapter)
1883 {
1884         struct mlme_priv *mlme = &adapter->mlmepriv;
1885         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1886         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1887
1888         if (pmlmeinfo->VHT_enable) /* disable auto scan when connect to 11AC AP */
1889                 mlme->auto_scan_int_ms = 0;
1890         else if (adapter->registrypriv.wifi_spec && is_client_associated_to_ap(adapter) == true)
1891                 mlme->auto_scan_int_ms = 60*1000;
1892         else if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1893                 if (check_fwstate(mlme, WIFI_STATION_STATE) && check_fwstate(mlme, _FW_LINKED))
1894                         mlme->auto_scan_int_ms = mlme->roam_scan_int_ms;
1895         } else
1896                 mlme->auto_scan_int_ms = 0; /* disabled */
1897
1898         return;
1899 }
1900
1901 static void rtw_auto_scan_handler(struct adapter *padapter)
1902 {
1903         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1904
1905         rtw_mlme_reset_auto_scan_int(padapter);
1906
1907         if (pmlmepriv->auto_scan_int_ms != 0
1908                 && jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time) > pmlmepriv->auto_scan_int_ms) {
1909
1910                 if (!padapter->registrypriv.wifi_spec) {
1911                         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == true) {
1912                                 DBG_871X(FUNC_ADPT_FMT" _FW_UNDER_SURVEY|_FW_UNDER_LINKING\n", FUNC_ADPT_ARG(padapter));
1913                                 goto exit;
1914                         }
1915
1916                         if (pmlmepriv->LinkDetectInfo.bBusyTraffic == true) {
1917                                 DBG_871X(FUNC_ADPT_FMT" exit BusyTraffic\n", FUNC_ADPT_ARG(padapter));
1918                                 goto exit;
1919                         }
1920                 }
1921
1922                 DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1923
1924                 rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1925         }
1926
1927 exit:
1928         return;
1929 }
1930
1931 void rtw_dynamic_check_timer_handler(struct adapter *adapter)
1932 {
1933         if (!adapter)
1934                 return;
1935
1936         if (adapter->hw_init_completed == false)
1937                 return;
1938
1939         if ((adapter->bDriverStopped == true) || (adapter->bSurpriseRemoved == true))
1940                 return;
1941
1942         if (adapter->net_closed == true)
1943                 return;
1944
1945         if (is_primary_adapter(adapter))
1946                 DBG_871X("IsBtDisabled =%d, IsBtControlLps =%d\n", rtw_btcoex_IsBtDisabled(adapter), rtw_btcoex_IsBtControlLps(adapter));
1947
1948         if ((adapter_to_pwrctl(adapter)->bFwCurrentInPSMode == true)
1949                 && (rtw_btcoex_IsBtControlLps(adapter) == false)
1950                 ) {
1951                 u8 bEnterPS;
1952
1953                 linked_status_chk(adapter);
1954
1955                 bEnterPS = traffic_status_watchdog(adapter, 1);
1956                 if (bEnterPS) {
1957                         /* rtw_lps_ctrl_wk_cmd(adapter, LPS_CTRL_ENTER, 1); */
1958                         rtw_hal_dm_watchdog_in_lps(adapter);
1959                 } else {
1960                         /* call rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_LEAVE, 1) in traffic_status_watchdog() */
1961                 }
1962
1963         } else {
1964                 if (is_primary_adapter(adapter)) {
1965                         rtw_dynamic_chk_wk_cmd(adapter);
1966                 }
1967         }
1968
1969         /* auto site survey */
1970         rtw_auto_scan_handler(adapter);
1971 }
1972
1973
1974 inline bool rtw_is_scan_deny(struct adapter *adapter)
1975 {
1976         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1977         return (atomic_read(&mlmepriv->set_scan_deny) != 0) ? true : false;
1978 }
1979
1980 inline void rtw_clear_scan_deny(struct adapter *adapter)
1981 {
1982         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1983         atomic_set(&mlmepriv->set_scan_deny, 0);
1984
1985         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
1986 }
1987
1988 void rtw_set_scan_deny_timer_hdl(struct adapter *adapter)
1989 {
1990         rtw_clear_scan_deny(adapter);
1991 }
1992
1993 void rtw_set_scan_deny(struct adapter *adapter, u32 ms)
1994 {
1995         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1996
1997         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
1998         atomic_set(&mlmepriv->set_scan_deny, 1);
1999         _set_timer(&mlmepriv->set_scan_deny_timer, ms);
2000 }
2001
2002 /*
2003 * Select a new roaming candidate from the original @param candidate and @param competitor
2004 * @return true: candidate is updated
2005 * @return false: candidate is not updated
2006 */
2007 static int rtw_check_roaming_candidate(struct mlme_priv *mlme
2008         , struct wlan_network **candidate, struct wlan_network *competitor)
2009 {
2010         int updated = false;
2011         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
2012
2013         if (is_same_ess(&competitor->network, &mlme->cur_network.network) == false)
2014                 goto exit;
2015
2016         if (rtw_is_desired_network(adapter, competitor) == false)
2017                 goto exit;
2018
2019         DBG_871X("roam candidate:%s %s("MAC_FMT", ch%3u) rssi:%d, age:%5d\n",
2020                 (competitor == mlme->cur_network_scanned)?"*":" ",
2021                 competitor->network.Ssid.Ssid,
2022                 MAC_ARG(competitor->network.MacAddress),
2023                 competitor->network.Configuration.DSConfig,
2024                 (int)competitor->network.Rssi,
2025                 jiffies_to_msecs(jiffies - competitor->last_scanned)
2026         );
2027
2028         /* got specific addr to roam */
2029         if (!is_zero_mac_addr(mlme->roam_tgt_addr)) {
2030                 if (!memcmp(mlme->roam_tgt_addr, competitor->network.MacAddress, ETH_ALEN))
2031                         goto update;
2032                 else
2033                         goto exit;
2034         }
2035         if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms)
2036                 goto exit;
2037
2038         if (competitor->network.Rssi - mlme->cur_network_scanned->network.Rssi < mlme->roam_rssi_diff_th)
2039                 goto exit;
2040
2041         if (*candidate != NULL && (*candidate)->network.Rssi >= competitor->network.Rssi)
2042                 goto exit;
2043
2044 update:
2045         *candidate = competitor;
2046         updated = true;
2047
2048 exit:
2049         return updated;
2050 }
2051
2052 int rtw_select_roaming_candidate(struct mlme_priv *mlme)
2053 {
2054         int ret = _FAIL;
2055         struct list_head        *phead;
2056         struct adapter *adapter;
2057         struct __queue  *queue  = &(mlme->scanned_queue);
2058         struct  wlan_network    *pnetwork = NULL;
2059         struct  wlan_network    *candidate = NULL;
2060
2061         if (mlme->cur_network_scanned == NULL) {
2062                 rtw_warn_on(1);
2063                 return ret;
2064         }
2065
2066         spin_lock_bh(&(mlme->scanned_queue.lock));
2067         phead = get_list_head(queue);
2068         adapter = (struct adapter *)mlme->nic_hdl;
2069
2070         mlme->pscanned = get_next(phead);
2071
2072         while (phead != mlme->pscanned) {
2073
2074                 pnetwork = LIST_CONTAINOR(mlme->pscanned, struct wlan_network, list);
2075                 if (pnetwork == NULL) {
2076                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2077                         ret = _FAIL;
2078                         goto exit;
2079                 }
2080
2081                 mlme->pscanned = get_next(mlme->pscanned);
2082
2083                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2084                         , pnetwork->network.Ssid.Ssid
2085                         , MAC_ARG(pnetwork->network.MacAddress)
2086                         , pnetwork->network.Configuration.DSConfig
2087                         , (int)pnetwork->network.Rssi);
2088
2089                 rtw_check_roaming_candidate(mlme, &candidate, pnetwork);
2090
2091         }
2092
2093         if (candidate == NULL) {
2094                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2095                 ret = _FAIL;
2096                 goto exit;
2097         } else {
2098                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2099                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2100                         candidate->network.Configuration.DSConfig);
2101
2102                 mlme->roam_network = candidate;
2103
2104                 if (!memcmp(candidate->network.MacAddress, mlme->roam_tgt_addr, ETH_ALEN))
2105                         eth_zero_addr(mlme->roam_tgt_addr);
2106         }
2107
2108         ret = _SUCCESS;
2109 exit:
2110         spin_unlock_bh(&(mlme->scanned_queue.lock));
2111
2112         return ret;
2113 }
2114
2115 /*
2116 * Select a new join candidate from the original @param candidate and @param competitor
2117 * @return true: candidate is updated
2118 * @return false: candidate is not updated
2119 */
2120 static int rtw_check_join_candidate(struct mlme_priv *mlme
2121         , struct wlan_network **candidate, struct wlan_network *competitor)
2122 {
2123         int updated = false;
2124         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
2125
2126
2127         /* check bssid, if needed */
2128         if (mlme->assoc_by_bssid == true) {
2129                 if (memcmp(competitor->network.MacAddress, mlme->assoc_bssid, ETH_ALEN))
2130                         goto exit;
2131         }
2132
2133         /* check ssid, if needed */
2134         if (mlme->assoc_ssid.Ssid[0] && mlme->assoc_ssid.SsidLength) {
2135                 if (competitor->network.Ssid.SsidLength != mlme->assoc_ssid.SsidLength
2136                         || memcmp(competitor->network.Ssid.Ssid, mlme->assoc_ssid.Ssid, mlme->assoc_ssid.SsidLength)
2137                 )
2138                         goto exit;
2139         }
2140
2141         if (rtw_is_desired_network(adapter, competitor)  == false)
2142                 goto exit;
2143
2144         if (rtw_to_roam(adapter) > 0) {
2145                 if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms
2146                         || is_same_ess(&competitor->network, &mlme->cur_network.network) == false
2147                 )
2148                         goto exit;
2149         }
2150
2151         if (*candidate == NULL || (*candidate)->network.Rssi < competitor->network.Rssi) {
2152                 *candidate = competitor;
2153                 updated = true;
2154         }
2155
2156         if (updated) {
2157                 DBG_871X("[by_bssid:%u][assoc_ssid:%s]"
2158                         "[to_roam:%u] "
2159                         "new candidate: %s("MAC_FMT", ch%u) rssi:%d\n",
2160                         mlme->assoc_by_bssid,
2161                         mlme->assoc_ssid.Ssid,
2162                         rtw_to_roam(adapter),
2163                         (*candidate)->network.Ssid.Ssid,
2164                         MAC_ARG((*candidate)->network.MacAddress),
2165                         (*candidate)->network.Configuration.DSConfig,
2166                         (int)(*candidate)->network.Rssi
2167                 );
2168         }
2169
2170 exit:
2171         return updated;
2172 }
2173
2174 /*
2175 Calling context:
2176 The caller of the sub-routine will be in critical section...
2177
2178 The caller must hold the following spinlock
2179
2180 pmlmepriv->lock
2181
2182
2183 */
2184
2185 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
2186 {
2187         int ret;
2188         struct list_head        *phead;
2189         struct adapter *adapter;
2190         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
2191         struct  wlan_network    *pnetwork = NULL;
2192         struct  wlan_network    *candidate = NULL;
2193
2194         adapter = (struct adapter *)pmlmepriv->nic_hdl;
2195
2196         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
2197
2198         if (pmlmepriv->roam_network) {
2199                 candidate = pmlmepriv->roam_network;
2200                 pmlmepriv->roam_network = NULL;
2201                 goto candidate_exist;
2202         }
2203
2204         phead = get_list_head(queue);
2205         pmlmepriv->pscanned = get_next(phead);
2206
2207         while (phead != pmlmepriv->pscanned) {
2208
2209                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
2210                 if (pnetwork == NULL) {
2211                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2212                         ret = _FAIL;
2213                         goto exit;
2214                 }
2215
2216                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
2217
2218                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2219                         , pnetwork->network.Ssid.Ssid
2220                         , MAC_ARG(pnetwork->network.MacAddress)
2221                         , pnetwork->network.Configuration.DSConfig
2222                         , (int)pnetwork->network.Rssi);
2223
2224                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
2225
2226         }
2227
2228         if (candidate == NULL) {
2229                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2230 #ifdef CONFIG_WOWLAN
2231                 _clr_fwstate_(pmlmepriv, _FW_LINKED|_FW_UNDER_LINKING);
2232 #endif
2233                 ret = _FAIL;
2234                 goto exit;
2235         } else {
2236                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2237                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2238                         candidate->network.Configuration.DSConfig);
2239                 goto candidate_exist;
2240         }
2241
2242 candidate_exist:
2243
2244         /*  check for situation of  _FW_LINKED */
2245         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
2246                 DBG_871X("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
2247
2248                 rtw_disassoc_cmd(adapter, 0, true);
2249                 rtw_indicate_disconnect(adapter);
2250                 rtw_free_assoc_resources(adapter, 0);
2251         }
2252
2253         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
2254         ret = rtw_joinbss_cmd(adapter, candidate);
2255
2256 exit:
2257         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
2258         return ret;
2259 }
2260
2261 sint rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
2262 {
2263         struct  cmd_obj *pcmd;
2264         struct  setauth_parm *psetauthparm;
2265         struct  cmd_priv *pcmdpriv = &(adapter->cmdpriv);
2266         sint            res = _SUCCESS;
2267
2268         pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
2269         if (pcmd == NULL) {
2270                 res = _FAIL;  /* try again */
2271                 goto exit;
2272         }
2273
2274         psetauthparm = rtw_zmalloc(sizeof(struct setauth_parm));
2275         if (psetauthparm == NULL) {
2276                 kfree((unsigned char *)pcmd);
2277                 res = _FAIL;
2278                 goto exit;
2279         }
2280
2281         memset(psetauthparm, 0, sizeof(struct setauth_parm));
2282         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
2283
2284         pcmd->cmdcode = _SetAuth_CMD_;
2285         pcmd->parmbuf = (unsigned char *)psetauthparm;
2286         pcmd->cmdsz =  (sizeof(struct setauth_parm));
2287         pcmd->rsp = NULL;
2288         pcmd->rspsz = 0;
2289
2290
2291         INIT_LIST_HEAD(&pcmd->list);
2292
2293         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("after enqueue set_auth_cmd, auth_mode =%x\n", psecuritypriv->dot11AuthAlgrthm));
2294
2295         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2296
2297 exit:
2298         return res;
2299 }
2300
2301 sint rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, sint keyid, u8 set_tx, bool enqueue)
2302 {
2303         u8 keylen;
2304         struct cmd_obj          *pcmd;
2305         struct setkey_parm      *psetkeyparm;
2306         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
2307         sint    res = _SUCCESS;
2308
2309         psetkeyparm = rtw_zmalloc(sizeof(struct setkey_parm));
2310         if (psetkeyparm == NULL) {
2311                 res = _FAIL;
2312                 goto exit;
2313         }
2314         memset(psetkeyparm, 0, sizeof(struct setkey_parm));
2315
2316         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
2317                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
2318                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(unsigned char)psecuritypriv->dot118021XGrpPrivacy =%d\n", psetkeyparm->algorithm));
2319         } else {
2320                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
2321                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(u8)psecuritypriv->dot11PrivacyAlgrthm =%d\n", psetkeyparm->algorithm));
2322
2323         }
2324         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
2325         psetkeyparm->set_tx = set_tx;
2326         if (is_wep_enc(psetkeyparm->algorithm))
2327                 adapter->securitypriv.key_mask |= BIT(psetkeyparm->keyid);
2328
2329         DBG_871X("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n", psetkeyparm->algorithm, psetkeyparm->keyid, adapter->securitypriv.key_mask);
2330         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =%d psetkeyparm->keyid =(u8)keyid =%d\n", psetkeyparm->algorithm, keyid));
2331
2332         switch (psetkeyparm->algorithm) {
2333
2334         case _WEP40_:
2335                 keylen = 5;
2336                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2337                 break;
2338         case _WEP104_:
2339                 keylen = 13;
2340                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2341                 break;
2342         case _TKIP_:
2343                 keylen = 16;
2344                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2345                 psetkeyparm->grpkey = 1;
2346                 break;
2347         case _AES_:
2348                 keylen = 16;
2349                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2350                 psetkeyparm->grpkey = 1;
2351                 break;
2352         default:
2353                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm = %x (must be 1 or 2 or 4 or 5)\n", psecuritypriv->dot11PrivacyAlgrthm));
2354                 res = _FAIL;
2355                 kfree((unsigned char *)psetkeyparm);
2356                 goto exit;
2357         }
2358
2359
2360         if (enqueue) {
2361                 pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
2362                 if (pcmd == NULL) {
2363                         kfree((unsigned char *)psetkeyparm);
2364                         res = _FAIL;  /* try again */
2365                         goto exit;
2366                 }
2367
2368                 pcmd->cmdcode = _SetKey_CMD_;
2369                 pcmd->parmbuf = (u8 *)psetkeyparm;
2370                 pcmd->cmdsz =  (sizeof(struct setkey_parm));
2371                 pcmd->rsp = NULL;
2372                 pcmd->rspsz = 0;
2373
2374                 INIT_LIST_HEAD(&pcmd->list);
2375
2376                 res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2377         } else {
2378                 setkey_hdl(adapter, (u8 *)psetkeyparm);
2379                 kfree((u8 *) psetkeyparm);
2380         }
2381 exit:
2382         return res;
2383 }
2384
2385 /* adjust IEs for rtw_joinbss_cmd in WMM */
2386 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
2387 {
2388         unsigned        int ielength = 0;
2389         unsigned int i, j;
2390
2391         i = 12; /* after the fixed IE */
2392         while (i < in_len) {
2393                 ielength = initial_out_len;
2394
2395                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) { /* WMM element ID and OUI */
2396                         for (j = i; j < i + 9; j++) {
2397                                         out_ie[ielength] = in_ie[j];
2398                                         ielength++;
2399                         }
2400                         out_ie[initial_out_len + 1] = 0x07;
2401                         out_ie[initial_out_len + 6] = 0x00;
2402                         out_ie[initial_out_len + 8] = 0x00;
2403
2404                         break;
2405                 }
2406
2407                 i += (in_ie[i+1]+2); /*  to the next IE element */
2408         }
2409
2410         return ielength;
2411
2412 }
2413
2414
2415 /*  */
2416 /*  Ported from 8185: IsInPreAuthKeyList(). (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.) */
2417 /*  Added by Annie, 2006-05-07. */
2418 /*  */
2419 /*  Search by BSSID, */
2420 /*  Return Value: */
2421 /*              -1              :if there is no pre-auth key in the  table */
2422 /*              >= 0            :if there is pre-auth key, and   return the entry id */
2423 /*  */
2424 /*  */
2425
2426 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
2427 {
2428         struct security_priv *psecuritypriv = &Adapter->securitypriv;
2429         int i = 0;
2430
2431         do {
2432                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
2433                                 (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN))) {
2434                         break;
2435                 } else {
2436                         i++;
2437                         /* continue; */
2438                 }
2439
2440         } while (i < NUM_PMKID_CACHE);
2441
2442         if (i == NUM_PMKID_CACHE) {
2443                 i = -1;/*  Could not find. */
2444         } else {
2445                 /*  There is one Pre-Authentication Key for the specific BSSID. */
2446         }
2447
2448         return i;
2449
2450 }
2451
2452 /*  */
2453 /*  Check the RSN IE length */
2454 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
2455 /*  0-11th element in the array are the fixed IE */
2456 /*  12th element in the array is the IE */
2457 /*  13th element in the array is the IE length */
2458 /*  */
2459
2460 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
2461 {
2462         struct security_priv *psecuritypriv = &Adapter->securitypriv;
2463
2464         if (ie[13] <= 20) {
2465                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
2466                         ie[ie_len] = 1;
2467                         ie_len++;
2468                         ie[ie_len] = 0; /* PMKID count = 0x0100 */
2469                         ie_len++;
2470                         memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
2471
2472                         ie_len += 16;
2473                         ie[13] += 18;/* PMKID length = 2+16 */
2474
2475         }
2476         return ie_len;
2477 }
2478
2479 sint rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
2480 {
2481         u8 authmode = 0x0;
2482         uint    ielength;
2483         int iEntry;
2484
2485         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
2486         struct security_priv *psecuritypriv = &adapter->securitypriv;
2487         uint    ndisauthmode = psecuritypriv->ndisauthtype;
2488
2489         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
2490                  ("+rtw_restruct_sec_ie: ndisauthmode =%d\n", ndisauthmode));
2491
2492         /* copy fixed ie only */
2493         memcpy(out_ie, in_ie, 12);
2494         ielength = 12;
2495         if ((ndisauthmode == Ndis802_11AuthModeWPA) || (ndisauthmode == Ndis802_11AuthModeWPAPSK))
2496                         authmode = _WPA_IE_ID_;
2497         if ((ndisauthmode == Ndis802_11AuthModeWPA2) || (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
2498                         authmode = _WPA2_IE_ID_;
2499
2500         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
2501                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
2502
2503                 ielength += psecuritypriv->wps_ie_len;
2504         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
2505                 /* copy RSN or SSN */
2506                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
2507                 /* debug for CONFIG_IEEE80211W
2508                 {
2509                         int jj;
2510                         printk("supplicant_ie_length =%d &&&&&&&&&&&&&&&&&&&\n", psecuritypriv->supplicant_ie[1]+2);
2511                         for (jj = 0; jj < psecuritypriv->supplicant_ie[1]+2; jj++)
2512                                 printk(" %02x ", psecuritypriv->supplicant_ie[jj]);
2513                         printk("\n");
2514                 }*/
2515                 ielength += psecuritypriv->supplicant_ie[1]+2;
2516                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
2517         }
2518
2519         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
2520         if (iEntry < 0) {
2521                 return ielength;
2522         } else {
2523                 if (authmode == _WPA2_IE_ID_)
2524                         ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
2525         }
2526         return ielength;
2527 }
2528
2529 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
2530 {
2531         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2532         struct eeprom_priv *peepriv = &adapter->eeprompriv;
2533         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2534         u8 *myhwaddr = myid(peepriv);
2535
2536         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
2537
2538         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
2539
2540         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_conf);
2541         pdev_network->Configuration.BeaconPeriod = 100;
2542         pdev_network->Configuration.FHConfig.Length = 0;
2543         pdev_network->Configuration.FHConfig.HopPattern = 0;
2544         pdev_network->Configuration.FHConfig.HopSet = 0;
2545         pdev_network->Configuration.FHConfig.DwellTime = 0;
2546 }
2547
2548 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
2549 {
2550         int sz = 0;
2551         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2552         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2553         struct  security_priv *psecuritypriv = &adapter->securitypriv;
2554         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
2555         /* struct       xmit_priv *pxmitpriv = &adapter->xmitpriv; */
2556
2557         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0) ; /*  adhoc no 802.1x */
2558
2559         pdev_network->Rssi = 0;
2560
2561         switch (pregistrypriv->wireless_mode) {
2562         case WIRELESS_11B:
2563                 pdev_network->NetworkTypeInUse = (Ndis802_11DS);
2564                 break;
2565         case WIRELESS_11G:
2566         case WIRELESS_11BG:
2567         case WIRELESS_11_24N:
2568         case WIRELESS_11G_24N:
2569         case WIRELESS_11BG_24N:
2570                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2571                 break;
2572         case WIRELESS_11A:
2573         case WIRELESS_11A_5N:
2574                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2575                 break;
2576         case WIRELESS_11ABGN:
2577                 if (pregistrypriv->channel > 14)
2578                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2579                 else
2580                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2581                 break;
2582         default:
2583                 /*  TODO */
2584                 break;
2585         }
2586
2587         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
2588         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("pregistrypriv->channel =%d, pdev_network->Configuration.DSConfig = 0x%x\n", pregistrypriv->channel, pdev_network->Configuration.DSConfig));
2589
2590         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
2591                 pdev_network->Configuration.ATIMWindow = (0);
2592
2593         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
2594
2595         /*  1. Supported rates */
2596         /*  2. IE */
2597
2598         /* rtw_set_supported_rate(pdev_network->SupportedRates, pregistrypriv->wireless_mode) ;  will be called in rtw_generate_ie */
2599         sz = rtw_generate_ie(pregistrypriv);
2600
2601         pdev_network->IELength = sz;
2602
2603         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
2604
2605         /* notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd(); */
2606         /* pdev_network->IELength = cpu_to_le32(sz); */
2607 }
2608
2609 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
2610 {
2611 }
2612
2613 /* the function is at passive_level */
2614 void rtw_joinbss_reset(struct adapter *padapter)
2615 {
2616         u8 threshold;
2617         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2618
2619         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2620
2621         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
2622
2623         pmlmepriv->num_FortyMHzIntolerant = 0;
2624
2625         pmlmepriv->num_sta_no_ht = 0;
2626
2627         phtpriv->ampdu_enable = false;/* reset to disabled */
2628
2629         /*  TH = 1 => means that invalidate usb rx aggregation */
2630         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
2631         if (phtpriv->ht_option) {
2632                 if (padapter->registrypriv.wifi_spec == 1)
2633                         threshold = 1;
2634                 else
2635                         threshold = 0;
2636                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2637         } else {
2638                 threshold = 1;
2639                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2640         }
2641 }
2642
2643 void rtw_ht_use_default_setting(struct adapter *padapter)
2644 {
2645         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2646         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2647         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2648         bool            bHwLDPCSupport = false, bHwSTBCSupport = false;
2649         bool            bHwSupportBeamformer = false, bHwSupportBeamformee = false;
2650
2651         if (pregistrypriv->wifi_spec)
2652                 phtpriv->bss_coexist = 1;
2653         else
2654                 phtpriv->bss_coexist = 0;
2655
2656         phtpriv->sgi_40m = TEST_FLAG(pregistrypriv->short_gi, BIT1) ? true : false;
2657         phtpriv->sgi_20m = TEST_FLAG(pregistrypriv->short_gi, BIT0) ? true : false;
2658
2659         /*  LDPC support */
2660         rtw_hal_get_def_var(padapter, HAL_DEF_RX_LDPC, (u8 *)&bHwLDPCSupport);
2661         CLEAR_FLAGS(phtpriv->ldpc_cap);
2662         if (bHwLDPCSupport) {
2663                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT4))
2664                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_RX);
2665         }
2666         rtw_hal_get_def_var(padapter, HAL_DEF_TX_LDPC, (u8 *)&bHwLDPCSupport);
2667         if (bHwLDPCSupport) {
2668                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT5))
2669                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_TX);
2670         }
2671         if (phtpriv->ldpc_cap)
2672                 DBG_871X("[HT] Support LDPC = 0x%02X\n", phtpriv->ldpc_cap);
2673
2674         /*  STBC */
2675         rtw_hal_get_def_var(padapter, HAL_DEF_TX_STBC, (u8 *)&bHwSTBCSupport);
2676         CLEAR_FLAGS(phtpriv->stbc_cap);
2677         if (bHwSTBCSupport) {
2678                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT5))
2679                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX);
2680         }
2681         rtw_hal_get_def_var(padapter, HAL_DEF_RX_STBC, (u8 *)&bHwSTBCSupport);
2682         if (bHwSTBCSupport) {
2683                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT4))
2684                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX);
2685         }
2686         if (phtpriv->stbc_cap)
2687                 DBG_871X("[HT] Support STBC = 0x%02X\n", phtpriv->stbc_cap);
2688
2689         /*  Beamforming setting */
2690         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMER, (u8 *)&bHwSupportBeamformer);
2691         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMEE, (u8 *)&bHwSupportBeamformee);
2692         CLEAR_FLAGS(phtpriv->beamform_cap);
2693         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT4) && bHwSupportBeamformer) {
2694                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE);
2695                 DBG_871X("[HT] Support Beamformer\n");
2696         }
2697         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT5) && bHwSupportBeamformee) {
2698                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE);
2699                 DBG_871X("[HT] Support Beamformee\n");
2700         }
2701 }
2702
2703 void rtw_build_wmm_ie_ht(struct adapter *padapter, u8 *out_ie, uint *pout_len)
2704 {
2705         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
2706         int out_len;
2707         u8 *pframe;
2708
2709         if (padapter->mlmepriv.qospriv.qos_option == 0) {
2710                 out_len = *pout_len;
2711                 pframe = rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_,
2712                                                         _WMM_IE_Length_, WMM_IE, pout_len);
2713
2714                 padapter->mlmepriv.qospriv.qos_option = 1;
2715         }
2716 }
2717
2718 /* the function is >= passive_level */
2719 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len, u8 channel)
2720 {
2721         u32 ielen, out_len;
2722         enum HT_CAP_AMPDU_FACTOR max_rx_ampdu_factor;
2723         unsigned char *p, *pframe;
2724         struct rtw_ieee80211_ht_cap ht_capie;
2725         u8 cbw40_enable = 0, stbc_rx_enable = 0, rf_type = 0, operation_bw = 0;
2726         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2727         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2728         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2729         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2730
2731         phtpriv->ht_option = false;
2732
2733         out_len = *pout_len;
2734
2735         memset(&ht_capie, 0, sizeof(struct rtw_ieee80211_ht_cap));
2736
2737         ht_capie.cap_info = cpu_to_le16(IEEE80211_HT_CAP_DSSSCCK40);
2738
2739         if (phtpriv->sgi_20m)
2740                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_20);
2741
2742         /* Get HT BW */
2743         if (in_ie == NULL) {
2744                 /* TDLS: TODO 20/40 issue */
2745                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
2746                         operation_bw = padapter->mlmeextpriv.cur_bwmode;
2747                         if (operation_bw > CHANNEL_WIDTH_40)
2748                                 operation_bw = CHANNEL_WIDTH_40;
2749                 } else
2750                         /* TDLS: TODO 40? */
2751                         operation_bw = CHANNEL_WIDTH_40;
2752         } else {
2753                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
2754                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2755                         struct HT_info_element *pht_info = (struct HT_info_element *)(p+2);
2756                         if (pht_info->infos[0] & BIT(2)) {
2757                                 switch (pht_info->infos[0] & 0x3) {
2758                                 case 1:
2759                                 case 3:
2760                                         operation_bw = CHANNEL_WIDTH_40;
2761                                         break;
2762                                 default:
2763                                         operation_bw = CHANNEL_WIDTH_20;
2764                                         break;
2765                                 }
2766                         } else {
2767                                 operation_bw = CHANNEL_WIDTH_20;
2768                         }
2769                 }
2770         }
2771
2772         /* to disable 40M Hz support while gd_bw_40MHz_en = 0 */
2773         if (channel > 14) {
2774                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
2775                         cbw40_enable = 1;
2776         } else {
2777                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
2778                         cbw40_enable = 1;
2779         }
2780
2781         if ((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) {
2782                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH);
2783                 if (phtpriv->sgi_40m)
2784                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_40);
2785         }
2786
2787         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX))
2788                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_TX_STBC);
2789
2790         /* todo: disable SM power save mode */
2791         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SM_PS);
2792
2793         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX)) {
2794                 if ((channel <= 14 && pregistrypriv->rx_stbc == 0x1) || /* enable for 2.4GHz */
2795                         (pregistrypriv->wifi_spec == 1)) {
2796                         stbc_rx_enable = 1;
2797                         DBG_871X("declare supporting RX STBC\n");
2798                 }
2799         }
2800
2801         /* fill default supported_mcs_set */
2802         memcpy(ht_capie.supp_mcs_set, pmlmeext->default_supported_mcs_set, 16);
2803
2804         /* update default supported_mcs_set */
2805         rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2806
2807         switch (rf_type) {
2808         case RF_1T1R:
2809                 if (stbc_rx_enable)
2810                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_1R);/* RX STBC One spatial stream */
2811
2812                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_1R);
2813                 break;
2814
2815         case RF_2T2R:
2816         case RF_1T2R:
2817         default:
2818                 if (stbc_rx_enable)
2819                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_2R);/* RX STBC two spatial stream */
2820
2821                 #ifdef CONFIG_DISABLE_MCS13TO15
2822                 if (((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) && (pregistrypriv->wifi_spec != 1))
2823                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R_13TO15_OFF);
2824                 else
2825                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
2826                 #else /* CONFIG_DISABLE_MCS13TO15 */
2827                         set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
2828                 #endif /* CONFIG_DISABLE_MCS13TO15 */
2829                 break;
2830         }
2831
2832         {
2833                 u32 rx_packet_offset, max_recvbuf_sz;
2834                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
2835                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
2836         }
2837
2838         if (padapter->driver_rx_ampdu_factor != 0xFF)
2839                 max_rx_ampdu_factor =
2840                   (enum HT_CAP_AMPDU_FACTOR)padapter->driver_rx_ampdu_factor;
2841         else
2842                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR,
2843                                     &max_rx_ampdu_factor);
2844
2845         /* rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor); */
2846         ht_capie.ampdu_params_info = (max_rx_ampdu_factor&0x03);
2847
2848         if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
2849                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&(0x07<<2));
2850         else
2851                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
2852
2853         pframe = rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
2854                                                 sizeof(struct rtw_ieee80211_ht_cap), (unsigned char *)&ht_capie, pout_len);
2855
2856         phtpriv->ht_option = true;
2857
2858         if (in_ie != NULL) {
2859                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
2860                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2861                         out_len = *pout_len;
2862                         pframe = rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2, pout_len);
2863                 }
2864         }
2865
2866         return phtpriv->ht_option;
2867
2868 }
2869
2870 /* the function is > passive_level (in critical_section) */
2871 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len, u8 channel)
2872 {
2873         u8 *p, max_ampdu_sz;
2874         int len;
2875         /* struct sta_info *bmc_sta, *psta; */
2876         struct rtw_ieee80211_ht_cap *pht_capie;
2877         struct ieee80211_ht_addt_info *pht_addtinfo;
2878         /* struct recv_reorder_ctrl *preorder_ctrl; */
2879         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2880         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2881         /* struct recv_priv *precvpriv = &padapter->recvpriv; */
2882         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2883         /* struct wlan_network *pcur_network = &(pmlmepriv->cur_network);; */
2884         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2885         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
2886         u8 cbw40_enable = 0;
2887
2888
2889         if (!phtpriv->ht_option)
2890                 return;
2891
2892         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
2893                 return;
2894
2895         DBG_871X("+rtw_update_ht_cap()\n");
2896
2897         /* maybe needs check if ap supports rx ampdu. */
2898         if ((phtpriv->ampdu_enable == false) && (pregistrypriv->ampdu_enable == 1)) {
2899                 if (pregistrypriv->wifi_spec == 1) {
2900                         /* remove this part because testbed AP should disable RX AMPDU */
2901                         /* phtpriv->ampdu_enable = false; */
2902                         phtpriv->ampdu_enable = true;
2903                 } else {
2904                         phtpriv->ampdu_enable = true;
2905                 }
2906         } else if (pregistrypriv->ampdu_enable == 2) {
2907                 /* remove this part because testbed AP should disable RX AMPDU */
2908                 /* phtpriv->ampdu_enable = true; */
2909         }
2910
2911
2912         /* check Max Rx A-MPDU Size */
2913         len = 0;
2914         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fix_ie), _HT_CAPABILITY_IE_, &len, ie_len-sizeof(struct ndis_802_11_fix_ie));
2915         if (p && len > 0) {
2916                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);
2917                 max_ampdu_sz = (pht_capie->ampdu_params_info & IEEE80211_HT_CAP_AMPDU_FACTOR);
2918                 max_ampdu_sz = 1 << (max_ampdu_sz+3); /*  max_ampdu_sz (kbytes); */
2919
2920                 /* DBG_871X("rtw_update_ht_cap(): max_ampdu_sz =%d\n", max_ampdu_sz); */
2921                 phtpriv->rx_ampdu_maxlen = max_ampdu_sz;
2922
2923         }
2924
2925
2926         len = 0;
2927         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fix_ie), _HT_ADD_INFO_IE_, &len, ie_len-sizeof(struct ndis_802_11_fix_ie));
2928         if (p && len > 0) {
2929                 pht_addtinfo = (struct ieee80211_ht_addt_info *)(p+2);
2930                 /* todo: */
2931         }
2932
2933         if (channel > 14) {
2934                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
2935                         cbw40_enable = 1;
2936         } else {
2937                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
2938                         cbw40_enable = 1;
2939         }
2940
2941         /* update cur_bwmode & cur_ch_offset */
2942         if ((cbw40_enable) &&
2943             (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
2944               BIT(1)) && (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
2945                 int i;
2946                 u8 rf_type;
2947
2948                 rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2949
2950                 /* update the MCS set */
2951                 for (i = 0; i < 16; i++)
2952                         pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= pmlmeext->default_supported_mcs_set[i];
2953
2954                 /* update the MCS rates */
2955                 switch (rf_type) {
2956                 case RF_1T1R:
2957                 case RF_1T2R:
2958                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_1R);
2959                         break;
2960                 case RF_2T2R:
2961                 default:
2962 #ifdef CONFIG_DISABLE_MCS13TO15
2963                         if (pmlmeext->cur_bwmode == CHANNEL_WIDTH_40 && pregistrypriv->wifi_spec != 1)
2964                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R_13TO15_OFF);
2965                         else
2966                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
2967 #else /* CONFIG_DISABLE_MCS13TO15 */
2968                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
2969 #endif /* CONFIG_DISABLE_MCS13TO15 */
2970                 }
2971
2972                 /* switch to the 40M Hz mode according to the AP */
2973                 /* pmlmeext->cur_bwmode = CHANNEL_WIDTH_40; */
2974                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
2975                 case EXTCHNL_OFFSET_UPPER:
2976                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
2977                         break;
2978
2979                 case EXTCHNL_OFFSET_LOWER:
2980                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
2981                         break;
2982
2983                 default:
2984                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
2985                         break;
2986                 }
2987         }
2988
2989         /*  */
2990         /*  Config SM Power Save setting */
2991         /*  */
2992         pmlmeinfo->SM_PS =
2993                 (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
2994                  0x0C) >> 2;
2995         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
2996                 DBG_871X("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
2997
2998         /*  */
2999         /*  Config current HT Protection mode. */
3000         /*  */
3001         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
3002 }
3003
3004 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
3005 {
3006         u8 issued;
3007         int priority;
3008         struct sta_info *psta = NULL;
3009         struct ht_priv *phtpriv;
3010         struct pkt_attrib *pattrib = &pxmitframe->attrib;
3011         s32 bmcst = IS_MCAST(pattrib->ra);
3012
3013         /* if (bmcst || (padapter->mlmepriv.LinkDetectInfo.bTxBusyTraffic == false)) */
3014         if (bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100))
3015                 return;
3016
3017         priority = pattrib->priority;
3018
3019         psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
3020         if (pattrib->psta != psta) {
3021                 DBG_871X("%s, pattrib->psta(%p) != psta(%p)\n", __func__, pattrib->psta, psta);
3022                 return;
3023         }
3024
3025         if (psta == NULL) {
3026                 DBG_871X("%s, psta ==NUL\n", __func__);
3027                 return;
3028         }
3029
3030         if (!(psta->state & _FW_LINKED)) {
3031                 DBG_871X("%s, psta->state(0x%x) != _FW_LINKED\n", __func__, psta->state);
3032                 return;
3033         }
3034
3035
3036         phtpriv = &psta->htpriv;
3037
3038         if ((phtpriv->ht_option == true) && (phtpriv->ampdu_enable == true)) {
3039                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
3040                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
3041
3042                 if (0 == issued) {
3043                         DBG_871X("rtw_issue_addbareq_cmd, p =%d\n", priority);
3044                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
3045                         rtw_addbareq_cmd(padapter, (u8) priority, pattrib->ra);
3046                 }
3047         }
3048
3049 }
3050
3051 void rtw_append_exented_cap(struct adapter *padapter, u8 *out_ie, uint *pout_len)
3052 {
3053         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3054         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
3055         u8 cap_content[8] = {0};
3056         u8 *pframe;
3057
3058
3059         if (phtpriv->bss_coexist) {
3060                 SET_EXT_CAPABILITY_ELE_BSS_COEXIST(cap_content, 1);
3061         }
3062
3063         pframe = rtw_set_ie(out_ie + *pout_len, EID_EXTCapability, 8, cap_content, pout_len);
3064 }
3065
3066 inline void rtw_set_to_roam(struct adapter *adapter, u8 to_roam)
3067 {
3068         if (to_roam == 0)
3069                 adapter->mlmepriv.to_join = false;
3070         adapter->mlmepriv.to_roam = to_roam;
3071 }
3072
3073 inline u8 rtw_dec_to_roam(struct adapter *adapter)
3074 {
3075         adapter->mlmepriv.to_roam--;
3076         return adapter->mlmepriv.to_roam;
3077 }
3078
3079 inline u8 rtw_to_roam(struct adapter *adapter)
3080 {
3081         return adapter->mlmepriv.to_roam;
3082 }
3083
3084 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3085 {
3086         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3087
3088         spin_lock_bh(&pmlmepriv->lock);
3089         _rtw_roaming(padapter, tgt_network);
3090         spin_unlock_bh(&pmlmepriv->lock);
3091 }
3092 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3093 {
3094         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3095         struct wlan_network *cur_network = &pmlmepriv->cur_network;
3096         int do_join_r;
3097
3098         if (0 < rtw_to_roam(padapter)) {
3099                 DBG_871X("roaming from %s("MAC_FMT"), length:%d\n",
3100                                 cur_network->network.Ssid.Ssid, MAC_ARG(cur_network->network.MacAddress),
3101                                 cur_network->network.Ssid.SsidLength);
3102                 memcpy(&pmlmepriv->assoc_ssid, &cur_network->network.Ssid, sizeof(struct ndis_802_11_ssid));
3103
3104                 pmlmepriv->assoc_by_bssid = false;
3105
3106                 while (1) {
3107                         do_join_r = rtw_do_join(padapter);
3108                         if (_SUCCESS == do_join_r) {
3109                                 break;
3110                         } else {
3111                                 DBG_871X("roaming do_join return %d\n", do_join_r);
3112                                 rtw_dec_to_roam(padapter);
3113
3114                                 if (rtw_to_roam(padapter) > 0) {
3115                                         continue;
3116                                 } else {
3117                                         DBG_871X("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
3118                                         rtw_indicate_disconnect(padapter);
3119                                         break;
3120                                 }
3121                         }
3122                 }
3123         }
3124
3125 }
3126
3127 sint rtw_linked_check(struct adapter *padapter)
3128 {
3129         if ((check_fwstate(&padapter->mlmepriv, WIFI_AP_STATE) == true) ||
3130                         (check_fwstate(&padapter->mlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE) == true)) {
3131                 if (padapter->stapriv.asoc_sta_count > 2)
3132                         return true;
3133         } else {        /* Station mode */
3134                 if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == true)
3135                         return true;
3136         }
3137         return false;
3138 }