Merge branch 'for-3.15' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup
[cascardo/linux.git] / drivers / staging / rtl8188eu / core / rtw_mlme.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  * You should have received a copy of the GNU General Public License along with
15  * this program; if not, write to the Free Software Foundation, Inc.,
16  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
17  *
18  *
19  ******************************************************************************/
20 #define _RTW_MLME_C_
21
22
23 #include <osdep_service.h>
24 #include <drv_types.h>
25 #include <recv_osdep.h>
26 #include <xmit_osdep.h>
27 #include <hal_intf.h>
28 #include <mlme_osdep.h>
29 #include <sta_info.h>
30 #include <wifi.h>
31 #include <wlan_bssdef.h>
32 #include <rtw_ioctl_set.h>
33 #include <usb_osintf.h>
34 #include <linux/vmalloc.h>
35
36 extern unsigned char    MCS_rate_2R[16];
37 extern unsigned char    MCS_rate_1R[16];
38
39 int _rtw_init_mlme_priv(struct adapter *padapter)
40 {
41         int     i;
42         u8      *pbuf;
43         struct wlan_network     *pnetwork;
44         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
45         int     res = _SUCCESS;
46
47         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by vzalloc(). */
48
49         pmlmepriv->nic_hdl = (u8 *)padapter;
50
51         pmlmepriv->pscanned = NULL;
52         pmlmepriv->fw_state = 0;
53         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
54         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
55
56         spin_lock_init(&(pmlmepriv->lock));
57         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
58         _rtw_init_queue(&(pmlmepriv->scanned_queue));
59
60         set_scanned_network_val(pmlmepriv, 0);
61
62         _rtw_memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
63
64         pbuf = vzalloc(MAX_BSS_CNT * (sizeof(struct wlan_network)));
65
66         if (pbuf == NULL) {
67                 res = _FAIL;
68                 goto exit;
69         }
70         pmlmepriv->free_bss_buf = pbuf;
71
72         pnetwork = (struct wlan_network *)pbuf;
73
74         for (i = 0; i < MAX_BSS_CNT; i++) {
75                 _rtw_init_listhead(&(pnetwork->list));
76
77                 rtw_list_insert_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
78
79                 pnetwork++;
80         }
81
82         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
83
84         rtw_clear_scan_deny(padapter);
85
86         rtw_init_mlme_timer(padapter);
87
88 exit:
89         return res;
90 }
91
92 #if defined(CONFIG_88EU_AP_MODE)
93 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
94 {
95         kfree(*ppie);
96         *plen = 0;
97         *ppie = NULL;
98 }
99
100 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
101 {
102         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
103         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
104         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
105         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
106         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
107         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
108
109         rtw_free_mlme_ie_data(&pmlmepriv->p2p_beacon_ie, &pmlmepriv->p2p_beacon_ie_len);
110         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_req_ie, &pmlmepriv->p2p_probe_req_ie_len);
111         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_resp_ie, &pmlmepriv->p2p_probe_resp_ie_len);
112         rtw_free_mlme_ie_data(&pmlmepriv->p2p_go_probe_resp_ie, &pmlmepriv->p2p_go_probe_resp_ie_len);
113         rtw_free_mlme_ie_data(&pmlmepriv->p2p_assoc_req_ie, &pmlmepriv->p2p_assoc_req_ie_len);
114 }
115 #else
116 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
117 {
118 }
119 #endif
120
121 void _rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
122 {
123         rtw_free_mlme_priv_ie_data(pmlmepriv);
124
125         if (pmlmepriv) {
126                 if (pmlmepriv->free_bss_buf)
127                         vfree(pmlmepriv->free_bss_buf);
128         }
129 }
130
131 int     _rtw_enqueue_network(struct __queue *queue, struct wlan_network *pnetwork)
132 {
133         if (pnetwork == NULL)
134                 goto exit;
135
136         spin_lock_bh(&queue->lock);
137
138         rtw_list_insert_tail(&pnetwork->list, &queue->queue);
139
140         spin_unlock_bh(&queue->lock);
141
142 exit:
143         return _SUCCESS;
144 }
145
146 struct  wlan_network *_rtw_dequeue_network(struct __queue *queue)
147 {
148         struct wlan_network *pnetwork;
149
150         spin_lock_bh(&queue->lock);
151
152         if (_rtw_queue_empty(queue)) {
153                 pnetwork = NULL;
154         } else {
155                 pnetwork = container_of((&queue->queue)->next, struct wlan_network, list);
156
157                 rtw_list_delete(&(pnetwork->list));
158         }
159
160         spin_unlock_bh(&queue->lock);
161
162         return pnetwork;
163 }
164
165 struct  wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)/* _queue *free_queue) */
166 {
167         struct  wlan_network    *pnetwork;
168         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
169         struct list_head *plist = NULL;
170
171         spin_lock_bh(&free_queue->lock);
172
173         if (_rtw_queue_empty(free_queue) == true) {
174                 pnetwork = NULL;
175                 goto exit;
176         }
177         plist = free_queue->queue.next;
178
179         pnetwork = container_of(plist , struct wlan_network, list);
180
181         rtw_list_delete(&pnetwork->list);
182
183         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("_rtw_alloc_network: ptr=%p\n", plist));
184         pnetwork->network_type = 0;
185         pnetwork->fixed = false;
186         pnetwork->last_scanned = jiffies;
187         pnetwork->aid = 0;
188         pnetwork->join_res = 0;
189
190         pmlmepriv->num_of_scanned++;
191
192 exit:
193         spin_unlock_bh(&free_queue->lock);
194
195         return pnetwork;
196 }
197
198 void _rtw_free_network(struct   mlme_priv *pmlmepriv , struct wlan_network *pnetwork, u8 isfreeall)
199 {
200         u32 curr_time, delta_time;
201         u32 lifetime = SCANQUEUE_LIFETIME;
202         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
203
204         if (pnetwork == NULL)
205                 return;
206
207         if (pnetwork->fixed)
208                 return;
209         curr_time = jiffies;
210         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
211             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)))
212                 lifetime = 1;
213         if (!isfreeall) {
214                 delta_time = (curr_time - pnetwork->last_scanned)/HZ;
215                 if (delta_time < lifetime)/*  unit:sec */
216                         return;
217         }
218         spin_lock_bh(&free_queue->lock);
219         rtw_list_delete(&(pnetwork->list));
220         rtw_list_insert_tail(&(pnetwork->list), &(free_queue->queue));
221         pmlmepriv->num_of_scanned--;
222         spin_unlock_bh(&free_queue->lock);
223 }
224
225 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
226 {
227         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
228
229         if (pnetwork == NULL)
230                 return;
231         if (pnetwork->fixed)
232                 return;
233         rtw_list_delete(&(pnetwork->list));
234         rtw_list_insert_tail(&(pnetwork->list), get_list_head(free_queue));
235         pmlmepriv->num_of_scanned--;
236 }
237
238 /*
239         return the wlan_network with the matching addr
240
241         Shall be calle under atomic context... to avoid possible racing condition...
242 */
243 struct wlan_network *_rtw_find_network(struct __queue *scanned_queue, u8 *addr)
244 {
245         struct list_head *phead, *plist;
246         struct  wlan_network *pnetwork = NULL;
247         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
248
249         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
250                 pnetwork = NULL;
251                 goto exit;
252         }
253         phead = get_list_head(scanned_queue);
254         plist = phead->next;
255
256         while (plist != phead) {
257                 pnetwork = container_of(plist, struct wlan_network , list);
258                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
259                         break;
260                 plist = plist->next;
261         }
262         if (plist == phead)
263                 pnetwork = NULL;
264 exit:
265         return pnetwork;
266 }
267
268
269 void _rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
270 {
271         struct list_head *phead, *plist;
272         struct wlan_network *pnetwork;
273         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
274         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
275
276         spin_lock_bh(&scanned_queue->lock);
277
278         phead = get_list_head(scanned_queue);
279         plist = phead->next;
280
281         while (rtw_end_of_queue_search(phead, plist) == false) {
282                 pnetwork = container_of(plist, struct wlan_network, list);
283
284                 plist = plist->next;
285
286                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
287         }
288         spin_unlock_bh(&scanned_queue->lock);
289 }
290
291 int rtw_if_up(struct adapter *padapter)
292 {
293         int res;
294
295         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
296             (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
297                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
298                          ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)",
299                          padapter->bDriverStopped, padapter->bSurpriseRemoved));
300                 res = false;
301         } else {
302                 res =  true;
303         }
304         return res;
305 }
306
307 void rtw_generate_random_ibss(u8 *pibss)
308 {
309         u32     curtime = jiffies;
310
311         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
312         pibss[1] = 0x11;
313         pibss[2] = 0x87;
314         pibss[3] = (u8)(curtime & 0xff);/* p[0]; */
315         pibss[4] = (u8)((curtime>>8) & 0xff);/* p[1]; */
316         pibss[5] = (u8)((curtime>>16) & 0xff);/* p[2]; */
317         return;
318 }
319
320 u8 *rtw_get_capability_from_ie(u8 *ie)
321 {
322         return ie + 8 + 2;
323 }
324
325
326 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
327 {
328         __le16  val;
329
330         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2);
331
332         return le16_to_cpu(val);
333 }
334
335 u8 *rtw_get_timestampe_from_ie(u8 *ie)
336 {
337         return ie + 0;
338 }
339
340 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
341 {
342         return ie + 8;
343 }
344
345 int rtw_init_mlme_priv(struct adapter *padapter)
346 {
347         int     res;
348         res = _rtw_init_mlme_priv(padapter);/*  (pmlmepriv); */
349         return res;
350 }
351
352 void rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
353 {
354         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_mlme_priv\n"));
355         _rtw_free_mlme_priv(pmlmepriv);
356 }
357
358 static struct wlan_network *rtw_alloc_network(struct mlme_priv *pmlmepriv)
359 {
360         return _rtw_alloc_network(pmlmepriv);
361 }
362
363 static void rtw_free_network_nolock(struct mlme_priv *pmlmepriv,
364                                     struct wlan_network *pnetwork)
365 {
366         _rtw_free_network_nolock(pmlmepriv, pnetwork);
367 }
368
369
370 void rtw_free_network_queue(struct adapter *dev, u8 isfreeall)
371 {
372         _rtw_free_network_queue(dev, isfreeall);
373 }
374
375 /*
376         return the wlan_network with the matching addr
377
378         Shall be calle under atomic context... to avoid possible racing condition...
379 */
380 struct  wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
381 {
382         struct  wlan_network *pnetwork = _rtw_find_network(scanned_queue, addr);
383
384         return pnetwork;
385 }
386
387 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
388 {
389         int ret = true;
390         struct security_priv *psecuritypriv = &adapter->securitypriv;
391
392         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
393             (pnetwork->network.Privacy == 0))
394                 ret = false;
395         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
396                  (pnetwork->network.Privacy == 1))
397                 ret = false;
398         else
399                 ret = true;
400         return ret;
401 }
402
403 static int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
404 {
405         return (a->Ssid.SsidLength == b->Ssid.SsidLength) &&
406                !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
407 }
408
409 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst)
410 {
411          u16 s_cap, d_cap;
412         __le16 le_scap, le_dcap;
413
414         memcpy((u8 *)&le_scap, rtw_get_capability_from_ie(src->IEs), 2);
415         memcpy((u8 *)&le_dcap, rtw_get_capability_from_ie(dst->IEs), 2);
416
417
418         s_cap = le16_to_cpu(le_scap);
419         d_cap = le16_to_cpu(le_dcap);
420
421         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
422                 ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN)) == true) &&
423                 ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength)) == true) &&
424                 ((s_cap & WLAN_CAPABILITY_IBSS) ==
425                 (d_cap & WLAN_CAPABILITY_IBSS)) &&
426                 ((s_cap & WLAN_CAPABILITY_BSS) ==
427                 (d_cap & WLAN_CAPABILITY_BSS)));
428 }
429
430 struct  wlan_network    *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
431 {
432         struct list_head *plist, *phead;
433         struct  wlan_network    *pwlan = NULL;
434         struct  wlan_network    *oldest = NULL;
435
436         phead = get_list_head(scanned_queue);
437
438         plist = phead->next;
439
440         while (1) {
441                 if (rtw_end_of_queue_search(phead, plist) == true)
442                         break;
443
444                 pwlan = container_of(plist, struct wlan_network, list);
445
446                 if (!pwlan->fixed) {
447                         if (oldest == NULL || time_after(oldest->last_scanned, pwlan->last_scanned))
448                                 oldest = pwlan;
449                 }
450
451                 plist = plist->next;
452         }
453         return oldest;
454 }
455
456 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
457         struct adapter *padapter, bool update_ie)
458 {
459         long rssi_ori = dst->Rssi;
460         u8 sq_smp = src->PhyInfo.SignalQuality;
461         u8 ss_final;
462         u8 sq_final;
463         long rssi_final;
464
465         rtw_hal_antdiv_rssi_compared(padapter, dst, src); /* this will update src.Rssi, need consider again */
466
467         /* The rule below is 1/5 for sample value, 4/5 for history value */
468         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src)) {
469                 /* Take the recvpriv's value for the connected AP*/
470                 ss_final = padapter->recvpriv.signal_strength;
471                 sq_final = padapter->recvpriv.signal_qual;
472                 /* the rssi value here is undecorated, and will be used for antenna diversity */
473                 if (sq_smp != 101) /* from the right channel */
474                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
475                 else
476                         rssi_final = rssi_ori;
477         } else {
478                 if (sq_smp != 101) { /* from the right channel */
479                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
480                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
481                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
482                 } else {
483                         /* bss info not receiving from the right channel, use the original RX signal infos */
484                         ss_final = dst->PhyInfo.SignalStrength;
485                         sq_final = dst->PhyInfo.SignalQuality;
486                         rssi_final = dst->Rssi;
487                 }
488         }
489         if (update_ie)
490                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
491         dst->PhyInfo.SignalStrength = ss_final;
492         dst->PhyInfo.SignalQuality = sq_final;
493         dst->Rssi = rssi_final;
494
495 }
496
497 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
498 {
499         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
500
501         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) &&
502             (is_same_network(&(pmlmepriv->cur_network.network), pnetwork))) {
503                 update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
504                 rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof(struct ndis_802_11_fixed_ie),
505                                       pmlmepriv->cur_network.network.IELength);
506         }
507 }
508
509 /*
510 Caller must hold pmlmepriv->lock first.
511 */
512 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
513 {
514         struct list_head *plist, *phead;
515         u32     bssid_ex_sz;
516         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
517         struct __queue *queue   = &(pmlmepriv->scanned_queue);
518         struct wlan_network     *pnetwork = NULL;
519         struct wlan_network     *oldest = NULL;
520
521         spin_lock_bh(&queue->lock);
522         phead = get_list_head(queue);
523         plist = phead->next;
524
525         while (1) {
526                 if (rtw_end_of_queue_search(phead, plist) == true)
527                         break;
528
529                 pnetwork        = container_of(plist, struct wlan_network, list);
530
531                 if (is_same_network(&(pnetwork->network), target))
532                         break;
533                 if ((oldest == ((struct wlan_network *)0)) ||
534                     time_after(oldest->last_scanned, pnetwork->last_scanned))
535                         oldest = pnetwork;
536                 plist = plist->next;
537         }
538         /* If we didn't find a match, then get a new network slot to initialize
539          * with this beacon's information */
540         if (rtw_end_of_queue_search(phead, plist) == true) {
541                 if (_rtw_queue_empty(&(pmlmepriv->free_bss_pool)) == true) {
542                         /* If there are no more slots, expire the oldest */
543                         pnetwork = oldest;
544
545                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
546                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
547                         /*  variable initialize */
548                         pnetwork->fixed = false;
549                         pnetwork->last_scanned = jiffies;
550
551                         pnetwork->network_type = 0;
552                         pnetwork->aid = 0;
553                         pnetwork->join_res = 0;
554
555                         /* bss info not receiving from the right channel */
556                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
557                                 pnetwork->network.PhyInfo.SignalQuality = 0;
558                 } else {
559                         /* Otherwise just pull from the free list */
560
561                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
562
563                         if (pnetwork == NULL) {
564                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
565                                 goto exit;
566                         }
567
568                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
569                         target->Length = bssid_ex_sz;
570                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
571                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
572
573                         pnetwork->last_scanned = jiffies;
574
575                         /* bss info not receiving from the right channel */
576                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
577                                 pnetwork->network.PhyInfo.SignalQuality = 0;
578                         rtw_list_insert_tail(&(pnetwork->list), &(queue->queue));
579                 }
580         } else {
581                 /* we have an entry and we are going to update it. But this entry may
582                  * be already expired. In this case we do the same as we found a new
583                  * net and call the new_net handler
584                  */
585                 bool update_ie = true;
586
587                 pnetwork->last_scanned = jiffies;
588
589                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
590                 if ((pnetwork->network.IELength > target->IELength) && (target->Reserved[0] == 1))
591                         update_ie = false;
592
593                 update_network(&(pnetwork->network), target, adapter, update_ie);
594         }
595
596 exit:
597         spin_unlock_bh(&queue->lock);
598
599 }
600
601 static void rtw_add_network(struct adapter *adapter,
602                             struct wlan_bssid_ex *pnetwork)
603 {
604 #if defined(CONFIG_88EU_P2P)
605         rtw_wlan_bssid_ex_remove_p2p_attr(pnetwork, P2P_ATTR_GROUP_INFO);
606 #endif
607         update_current_network(adapter, pnetwork);
608         rtw_update_scanned_network(adapter, pnetwork);
609 }
610
611 /*
612  * select the desired network based on the capability of the (i)bss.
613  * check items: (1) security
614  *                      (2) network_type
615  *                      (3) WMM
616  *                      (4) HT
617  *                      (5) others
618  */
619 static int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
620 {
621         struct security_priv *psecuritypriv = &adapter->securitypriv;
622         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
623         u32 desired_encmode;
624         u32 privacy;
625
626         /* u8 wps_ie[512]; */
627         uint wps_ielen;
628
629         int bselected = true;
630
631         desired_encmode = psecuritypriv->ndisencryptstatus;
632         privacy = pnetwork->network.Privacy;
633
634         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
635                 if (rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen) != NULL)
636                         return true;
637                 else
638                         return false;
639         }
640         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
641                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
642                         bselected = false;
643         }
644
645
646         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
647                 DBG_88E("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
648                 bselected = false;
649         }
650
651         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
652                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
653                         bselected = false;
654         }
655
656
657         return bselected;
658 }
659
660 /* TODO: Perry: For Power Management */
661 void rtw_atimdone_event_callback(struct adapter *adapter , u8 *pbuf)
662 {
663         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_evet\n"));
664         return;
665 }
666
667
668 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
669 {
670         u32 len;
671         struct wlan_bssid_ex *pnetwork;
672         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
673
674         pnetwork = (struct wlan_bssid_ex *)pbuf;
675
676         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid=%s\n",  pnetwork->Ssid.Ssid));
677
678         len = get_wlan_bssid_ex_sz(pnetwork);
679         if (len > (sizeof(struct wlan_bssid_ex))) {
680                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n****rtw_survey_event_callback: return a wrong bss ***\n"));
681                 return;
682         }
683         spin_lock_bh(&pmlmepriv->lock);
684
685         /*  update IBSS_network 's timestamp */
686         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) {
687                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN)) {
688                         struct wlan_network *ibss_wlan = NULL;
689
690                         memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
691                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
692                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
693                         if (ibss_wlan) {
694                                 memcpy(ibss_wlan->network.IEs , pnetwork->IEs, 8);
695                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
696                                 goto exit;
697                         }
698                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
699                 }
700         }
701
702         /*  lock pmlmepriv->lock when you accessing network_q */
703         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false) {
704                 if (pnetwork->Ssid.Ssid[0] == 0)
705                         pnetwork->Ssid.SsidLength = 0;
706                 rtw_add_network(adapter, pnetwork);
707         }
708
709 exit:
710
711         spin_unlock_bh(&pmlmepriv->lock);
712         return;
713 }
714
715 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
716 {
717         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
718         struct mlme_ext_priv *pmlmeext;
719
720         spin_lock_bh(&pmlmepriv->lock);
721
722         if (pmlmepriv->wps_probe_req_ie) {
723                 pmlmepriv->wps_probe_req_ie_len = 0;
724                 kfree(pmlmepriv->wps_probe_req_ie);
725                 pmlmepriv->wps_probe_req_ie = NULL;
726         }
727
728         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
729
730         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
731                 u8 timer_cancelled;
732
733                 _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
734
735                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
736         } else {
737                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status=%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
738         }
739
740         rtw_set_signal_stat_timer(&adapter->recvpriv);
741
742         if (pmlmepriv->to_join) {
743                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
744                         if (check_fwstate(pmlmepriv, _FW_LINKED) == false) {
745                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
746
747                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
748                                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
749                                 } else {
750                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
751                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
752
753                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
754
755                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
756
757                                         _rtw_memset(&pdev_network->Ssid, 0, sizeof(struct ndis_802_11_ssid));
758                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
759
760                                         rtw_update_registrypriv_dev_network(adapter);
761                                         rtw_generate_random_ibss(pibss);
762
763                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
764
765                                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
766                                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error=>rtw_createbss_cmd status FAIL\n"));
767                                         pmlmepriv->to_join = false;
768                                 }
769                         }
770                 } else {
771                         int s_ret;
772                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
773                         pmlmepriv->to_join = false;
774                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
775                         if (_SUCCESS == s_ret) {
776                              _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
777                         } else if (s_ret == 2) { /* there is no need to wait for join */
778                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
779                                 rtw_indicate_connect(adapter);
780                         } else {
781                                 DBG_88E("try_to_join, but select scanning queue fail, to_roaming:%d\n", pmlmepriv->to_roaming);
782                                 if (pmlmepriv->to_roaming != 0) {
783                                         if (--pmlmepriv->to_roaming == 0 ||
784                                             _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)) {
785                                                 pmlmepriv->to_roaming = 0;
786                                                 rtw_free_assoc_resources(adapter, 1);
787                                                 rtw_indicate_disconnect(adapter);
788                                         } else {
789                                                 pmlmepriv->to_join = true;
790                                         }
791                                 }
792                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
793                         }
794                 }
795         }
796
797         indicate_wx_scan_complete_event(adapter);
798
799         spin_unlock_bh(&pmlmepriv->lock);
800
801         if (check_fwstate(pmlmepriv, _FW_LINKED) == true)
802                 p2p_ps_wk_cmd(adapter, P2P_PS_SCAN_DONE, 0);
803
804         rtw_os_xmit_schedule(adapter);
805
806         pmlmeext = &adapter->mlmeextpriv;
807         if (pmlmeext->sitesurvey_res.bss_cnt == 0)
808                 rtw_hal_sreset_reset(adapter);
809 }
810
811 void rtw_dummy_event_callback(struct adapter *adapter , u8 *pbuf)
812 {
813 }
814
815 void rtw_fwdbg_event_callback(struct adapter *adapter , u8 *pbuf)
816 {
817 }
818
819 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
820 {
821         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
822         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
823         struct list_head *plist, *phead, *ptemp;
824
825         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
826         spin_lock_bh(&scan_queue->lock);
827         spin_lock_bh(&free_queue->lock);
828
829         phead = get_list_head(scan_queue);
830         plist = phead->next;
831
832         while (plist != phead) {
833                 ptemp = plist->next;
834                 rtw_list_delete(plist);
835                 rtw_list_insert_tail(plist, &free_queue->queue);
836                 plist = ptemp;
837                 pmlmepriv->num_of_scanned--;
838         }
839
840         spin_unlock_bh(&free_queue->lock);
841         spin_unlock_bh(&scan_queue->lock);
842 }
843
844 /*
845 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
846 */
847 void rtw_free_assoc_resources(struct adapter *adapter, int lock_scanned_queue)
848 {
849         struct wlan_network *pwlan = NULL;
850         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
851         struct  sta_priv *pstapriv = &adapter->stapriv;
852         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
853
854         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
855         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
856                  ("tgt_network->network.MacAddress=%pM ssid=%s\n",
857                  tgt_network->network.MacAddress, tgt_network->network.Ssid.Ssid));
858
859         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_AP_STATE)) {
860                 struct sta_info *psta;
861
862                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
863
864                 spin_lock_bh(&(pstapriv->sta_hash_lock));
865                 rtw_free_stainfo(adapter,  psta);
866                 spin_unlock_bh(&pstapriv->sta_hash_lock);
867         }
868
869         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE | WIFI_ADHOC_MASTER_STATE | WIFI_AP_STATE)) {
870                 struct sta_info *psta;
871
872                 rtw_free_all_stainfo(adapter);
873
874                 psta = rtw_get_bcmc_stainfo(adapter);
875                 spin_lock_bh(&(pstapriv->sta_hash_lock));
876                 rtw_free_stainfo(adapter, psta);
877                 spin_unlock_bh(&pstapriv->sta_hash_lock);
878
879                 rtw_init_bcmc_stainfo(adapter);
880         }
881
882         if (lock_scanned_queue)
883                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
884
885         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
886         if (pwlan)
887                 pwlan->fixed = false;
888         else
889                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources:pwlan==NULL\n\n"));
890
891         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) && (adapter->stapriv.asoc_sta_count == 1)))
892                 rtw_free_network_nolock(pmlmepriv, pwlan);
893
894         if (lock_scanned_queue)
895                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
896         pmlmepriv->key_mask = 0;
897 }
898
899 /*
900 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
901 */
902 void rtw_indicate_connect(struct adapter *padapter)
903 {
904         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
905
906         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
907
908         pmlmepriv->to_join = false;
909
910         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
911                 set_fwstate(pmlmepriv, _FW_LINKED);
912
913                 rtw_led_control(padapter, LED_CTL_LINK);
914
915                 rtw_os_indicate_connect(padapter);
916         }
917
918         pmlmepriv->to_roaming = 0;
919
920         rtw_set_scan_deny(padapter, 3000);
921
922         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state=0x%08x\n", get_fwstate(pmlmepriv)));
923 }
924
925 /*
926 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
927 */
928 void rtw_indicate_disconnect(struct adapter *padapter)
929 {
930         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
931
932         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
933
934         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING | WIFI_UNDER_WPS);
935
936
937         if (pmlmepriv->to_roaming > 0)
938                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
939
940         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) ||
941             (pmlmepriv->to_roaming <= 0)) {
942                 rtw_os_indicate_disconnect(padapter);
943
944                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
945                 rtw_led_control(padapter, LED_CTL_NO_LINK);
946                 rtw_clear_scan_deny(padapter);
947         }
948         p2p_ps_wk_cmd(padapter, P2P_PS_DISABLE, 1);
949
950         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
951 }
952
953 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
954 {
955         rtw_os_indicate_scan_done(padapter, aborted);
956 }
957
958 void rtw_scan_abort(struct adapter *adapter)
959 {
960         u32 start;
961         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
962         struct mlme_ext_priv    *pmlmeext = &(adapter->mlmeextpriv);
963
964         start = jiffies;
965         pmlmeext->scan_abort = true;
966         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY) &&
967                rtw_get_passing_time_ms(start) <= 200) {
968                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
969                         break;
970                 DBG_88E(FUNC_NDEV_FMT"fw_state=_FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
971                 msleep(20);
972         }
973         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
974                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
975                         DBG_88E(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
976                 rtw_indicate_scan_done(adapter, true);
977         }
978         pmlmeext->scan_abort = false;
979 }
980
981 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
982 {
983         int i;
984         struct sta_info *bmc_sta, *psta = NULL;
985         struct recv_reorder_ctrl *preorder_ctrl;
986         struct sta_priv *pstapriv = &padapter->stapriv;
987
988         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
989         if (psta == NULL)
990                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
991
992         if (psta) { /* update ptarget_sta */
993                 DBG_88E("%s\n", __func__);
994                 psta->aid  = pnetwork->join_res;
995                         psta->mac_id = 0;
996                 /* sta mode */
997                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
998                 /* security related */
999                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1000                         padapter->securitypriv.binstallGrpkey = false;
1001                         padapter->securitypriv.busetkipkey = false;
1002                         padapter->securitypriv.bgrpkey_handshake = false;
1003                         psta->ieee8021x_blocked = true;
1004                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
1005                         _rtw_memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
1006                         _rtw_memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
1007                         _rtw_memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
1008                         _rtw_memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
1009                         _rtw_memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
1010                 }
1011                 /*
1012                  * Commented by Albert 2012/07/21
1013                  * When doing the WPS, the wps_ie_len won't equal to 0
1014                  * And the Wi-Fi driver shouldn't allow the data
1015                  * packet to be tramsmitted.
1016                  */
1017                 if (padapter->securitypriv.wps_ie_len != 0) {
1018                         psta->ieee8021x_blocked = true;
1019                         padapter->securitypriv.wps_ie_len = 0;
1020                 }
1021                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
1022                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
1023                 /* todo: check if AP can send A-MPDU packets */
1024                 for (i = 0; i < 16; i++) {
1025                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1026                         preorder_ctrl = &psta->recvreorder_ctrl[i];
1027                         preorder_ctrl->enable = false;
1028                         preorder_ctrl->indicate_seq = 0xffff;
1029                         preorder_ctrl->wend_b = 0xffff;
1030                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
1031                 }
1032                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
1033                 if (bmc_sta) {
1034                         for (i = 0; i < 16; i++) {
1035                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1036                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
1037                                 preorder_ctrl->enable = false;
1038                                 preorder_ctrl->indicate_seq = 0xffff;
1039                                 preorder_ctrl->wend_b = 0xffff;
1040                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
1041                         }
1042                 }
1043                 /* misc. */
1044                 update_sta_info(padapter, psta);
1045         }
1046         return psta;
1047 }
1048
1049 /* pnetwork: returns from rtw_joinbss_event_callback */
1050 /* ptarget_wlan: found from scanned_queue */
1051 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
1052 {
1053         struct mlme_priv        *pmlmepriv = &(padapter->mlmepriv);
1054         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
1055
1056         DBG_88E("%s\n", __func__);
1057
1058         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
1059                  ("\nfw_state:%x, BSSID:%pM\n",
1060                  get_fwstate(pmlmepriv), pnetwork->network.MacAddress));
1061
1062
1063         /*  why not use ptarget_wlan?? */
1064         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
1065         /*  some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs */
1066         cur_network->network.IELength = ptarget_wlan->network.IELength;
1067         memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
1068
1069         cur_network->aid = pnetwork->join_res;
1070
1071
1072         rtw_set_signal_stat_timer(&padapter->recvpriv);
1073         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
1074         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
1075         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
1076         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
1077         rtw_set_signal_stat_timer(&padapter->recvpriv);
1078
1079         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
1080         switch (pnetwork->network.InfrastructureMode) {
1081         case Ndis802_11Infrastructure:
1082                 if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
1083                         pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
1084                 else
1085                         pmlmepriv->fw_state = WIFI_STATION_STATE;
1086                 break;
1087         case Ndis802_11IBSS:
1088                 pmlmepriv->fw_state = WIFI_ADHOC_STATE;
1089                 break;
1090         default:
1091                 pmlmepriv->fw_state = WIFI_NULL_STATE;
1092                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
1093                 break;
1094         }
1095
1096         rtw_update_protection(padapter, (cur_network->network.IEs) +
1097                               sizeof(struct ndis_802_11_fixed_ie),
1098                               (cur_network->network.IELength));
1099         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength);
1100 }
1101
1102 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
1103 /* pnetwork: returns from rtw_joinbss_event_callback */
1104 /* ptarget_wlan: found from scanned_queue */
1105 /* if join_res > 0, for (fw_state == WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
1106 /* if join_res > 0, for (fw_state == WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
1107 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
1108
1109 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
1110 {
1111         u8 timer_cancelled;
1112         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
1113         struct  sta_priv *pstapriv = &adapter->stapriv;
1114         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
1115         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1116         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1117         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1118         unsigned int            the_same_macaddr = false;
1119
1120         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res=%d\n", pnetwork->join_res));
1121
1122         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1123
1124
1125         if (pmlmepriv->assoc_ssid.SsidLength == 0)
1126                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
1127         else
1128                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
1129
1130         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1131
1132         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1133         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
1134                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1135                 return;
1136         }
1137
1138         spin_lock_bh(&pmlmepriv->lock);
1139
1140         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nrtw_joinbss_event_callback!! _enter_critical\n"));
1141
1142         if (pnetwork->join_res > 0) {
1143                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1144                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1145                         /* s1. find ptarget_wlan */
1146                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1147                                 if (the_same_macaddr) {
1148                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1149                                 } else {
1150                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1151                                         if (pcur_wlan)
1152                                                 pcur_wlan->fixed = false;
1153
1154                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1155                                         if (pcur_sta) {
1156                                                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1157                                                 rtw_free_stainfo(adapter,  pcur_sta);
1158                                                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1159                                         }
1160
1161                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1162                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1163                                                 if (ptarget_wlan)
1164                                                         ptarget_wlan->fixed = true;
1165                                         }
1166                                 }
1167                         } else {
1168                                 ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1169                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1170                                         if (ptarget_wlan)
1171                                                 ptarget_wlan->fixed = true;
1172                                 }
1173                         }
1174
1175                         /* s2. update cur_network */
1176                         if (ptarget_wlan) {
1177                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1178                         } else {
1179                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't find ptarget_wlan when joinbss_event callback\n"));
1180                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1181                                 goto ignore_joinbss_callback;
1182                         }
1183
1184
1185                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1186                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1187                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1188                                 if (ptarget_sta == NULL) {
1189                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1190                                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1191                                         goto ignore_joinbss_callback;
1192                                 }
1193                         }
1194
1195                         /* s4. indicate connect */
1196                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1197                                         rtw_indicate_connect(adapter);
1198                                 } else {
1199                                         /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1200                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1201                                 }
1202
1203                         /* s5. Cancle assoc_timer */
1204                         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
1205
1206                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancle assoc_timer\n"));
1207
1208                 } else {
1209                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1210                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1211                         goto ignore_joinbss_callback;
1212                 }
1213
1214                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1215
1216         } else if (pnetwork->join_res == -4) {
1217                 rtw_reset_securitypriv(adapter);
1218                 _set_timer(&pmlmepriv->assoc_timer, 1);
1219
1220                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true) {
1221                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state=%x\n", get_fwstate(pmlmepriv)));
1222                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1223                 }
1224         } else { /* if join_res < 0 (join fails), then try again */
1225                 _set_timer(&pmlmepriv->assoc_timer, 1);
1226                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1227         }
1228
1229 ignore_joinbss_callback:
1230         spin_unlock_bh(&pmlmepriv->lock);
1231 }
1232
1233 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1234 {
1235         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1236
1237         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1238
1239         rtw_os_xmit_schedule(adapter);
1240 }
1241
1242 static u8 search_max_mac_id(struct adapter *padapter)
1243 {
1244         u8 mac_id;
1245 #if defined(CONFIG_88EU_AP_MODE)
1246         u8 aid;
1247         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1248         struct sta_priv *pstapriv = &padapter->stapriv;
1249 #endif
1250         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
1251         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
1252
1253 #if defined(CONFIG_88EU_AP_MODE)
1254         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1255                 for (aid = (pstapriv->max_num_sta); aid > 0; aid--) {
1256                         if (pstapriv->sta_aid[aid-1] != NULL)
1257                                 break;
1258                 }
1259                 mac_id = aid + 1;
1260         } else
1261 #endif
1262         {/* adhoc  id =  31~2 */
1263                 for (mac_id = (NUM_STA-1); mac_id >= IBSS_START_MAC_ID; mac_id--) {
1264                         if (pmlmeinfo->FW_sta_info[mac_id].status == 1)
1265                                 break;
1266                 }
1267         }
1268         return mac_id;
1269 }
1270
1271 /* FOR AP , AD-HOC mode */
1272 void rtw_stassoc_hw_rpt(struct adapter *adapter, struct sta_info *psta)
1273 {
1274         u16 media_status;
1275         u8 macid;
1276
1277         if (psta == NULL)
1278                 return;
1279
1280         macid = search_max_mac_id(adapter);
1281         rtw_hal_set_hwreg(adapter, HW_VAR_TX_RPT_MAX_MACID, (u8 *)&macid);
1282         media_status = (psta->mac_id<<8)|1; /*   MACID|OPMODE:1 connect */
1283         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1284 }
1285
1286 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1287 {
1288         struct sta_info *psta;
1289         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1290         struct stassoc_event    *pstassoc = (struct stassoc_event *)pbuf;
1291         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1292         struct wlan_network     *ptarget_wlan = NULL;
1293
1294         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1295                 return;
1296
1297 #if defined(CONFIG_88EU_AP_MODE)
1298         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1299                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1300                 if (psta) {
1301                         ap_sta_info_defer_update(adapter, psta);
1302                         rtw_stassoc_hw_rpt(adapter, psta);
1303                 }
1304                 return;
1305         }
1306 #endif
1307         /* for AD-HOC mode */
1308         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1309         if (psta != NULL) {
1310                 /* the sta have been in sta_info_queue => do nothing */
1311                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1312                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1313         }
1314         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1315         if (psta == NULL) {
1316                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1317                 return;
1318         }
1319         /* to do: init sta_info variable */
1320         psta->qos_option = 0;
1321         psta->mac_id = (uint)pstassoc->cam_id;
1322         DBG_88E("%s\n", __func__);
1323         /* for ad-hoc mode */
1324         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1325         rtw_stassoc_hw_rpt(adapter, psta);
1326         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1327                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1328         psta->ieee8021x_blocked = false;
1329         spin_lock_bh(&pmlmepriv->lock);
1330         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
1331             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE))) {
1332                 if (adapter->stapriv.asoc_sta_count == 2) {
1333                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1334                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1335                         if (ptarget_wlan)
1336                                 ptarget_wlan->fixed = true;
1337                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1338                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1339                         rtw_indicate_connect(adapter);
1340                 }
1341         }
1342         spin_unlock_bh(&pmlmepriv->lock);
1343         mlmeext_sta_add_event_callback(adapter, psta);
1344 }
1345
1346 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1347 {
1348         int mac_id = -1;
1349         struct sta_info *psta;
1350         struct wlan_network *pwlan = NULL;
1351         struct wlan_bssid_ex *pdev_network = NULL;
1352         u8 *pibss = NULL;
1353         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1354         struct  stadel_event *pstadel = (struct stadel_event *)pbuf;
1355         struct  sta_priv *pstapriv = &adapter->stapriv;
1356         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1357
1358         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1359         if (psta)
1360                 mac_id = psta->mac_id;
1361         else
1362                 mac_id = pstadel->mac_id;
1363
1364         DBG_88E("%s(mac_id=%d)=%pM\n", __func__, mac_id, pstadel->macaddr);
1365
1366         if (mac_id >= 0) {
1367                 u16 media_status;
1368                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1369                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1370                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1371         }
1372
1373         if (check_fwstate(pmlmepriv, WIFI_AP_STATE))
1374                 return;
1375
1376         mlmeext_sta_del_event_callback(adapter);
1377
1378         spin_lock_bh(&pmlmepriv->lock);
1379
1380         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1381                 if (pmlmepriv->to_roaming > 0)
1382                         pmlmepriv->to_roaming--; /*  this stadel_event is caused by roaming, decrease to_roaming */
1383                 else if (pmlmepriv->to_roaming == 0)
1384                         pmlmepriv->to_roaming = adapter->registrypriv.max_roaming_times;
1385
1386                 if (*((unsigned short *)(pstadel->rsvd)) != WLAN_REASON_EXPIRATION_CHK)
1387                         pmlmepriv->to_roaming = 0; /*  don't roam */
1388
1389                 rtw_free_uc_swdec_pending_queue(adapter);
1390
1391                 rtw_free_assoc_resources(adapter, 1);
1392                 rtw_indicate_disconnect(adapter);
1393                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1394                 /*  remove the network entry in scanned_queue */
1395                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1396                 if (pwlan) {
1397                         pwlan->fixed = false;
1398                         rtw_free_network_nolock(pmlmepriv, pwlan);
1399                 }
1400                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1401                 _rtw_roaming(adapter, tgt_network);
1402         }
1403         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1404             check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1405                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1406                 rtw_free_stainfo(adapter,  psta);
1407                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1408
1409                 if (adapter->stapriv.asoc_sta_count == 1) { /* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1410                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1411                         /* free old ibss network */
1412                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1413                         if (pwlan) {
1414                                 pwlan->fixed = false;
1415                                 rtw_free_network_nolock(pmlmepriv, pwlan);
1416                         }
1417                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1418                         /* re-create ibss */
1419                         pdev_network = &(adapter->registrypriv.dev_network);
1420                         pibss = adapter->registrypriv.dev_network.MacAddress;
1421
1422                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1423
1424                         _rtw_memset(&pdev_network->Ssid, 0, sizeof(struct ndis_802_11_ssid));
1425                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1426
1427                         rtw_update_registrypriv_dev_network(adapter);
1428
1429                         rtw_generate_random_ibss(pibss);
1430
1431                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1432                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1433                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1434                         }
1435
1436                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
1437                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error=>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1438                 }
1439         }
1440         spin_unlock_bh(&pmlmepriv->lock);
1441 }
1442
1443 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1444 {
1445         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1446 }
1447
1448 /*
1449 * _rtw_join_timeout_handler - Timeout/faliure handler for CMD JoinBss
1450 * @adapter: pointer to struct adapter structure
1451 */
1452 void _rtw_join_timeout_handler (struct adapter *adapter)
1453 {
1454         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1455         int do_join_r;
1456
1457         DBG_88E("%s, fw_state=%x\n", __func__, get_fwstate(pmlmepriv));
1458
1459         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1460                 return;
1461
1462
1463         spin_lock_bh(&pmlmepriv->lock);
1464
1465         if (pmlmepriv->to_roaming > 0) { /*  join timeout caused by roaming */
1466                 while (1) {
1467                         pmlmepriv->to_roaming--;
1468                         if (pmlmepriv->to_roaming != 0) { /* try another , */
1469                                 DBG_88E("%s try another roaming\n", __func__);
1470                                 do_join_r = rtw_do_join(adapter);
1471                                 if (_SUCCESS != do_join_r) {
1472                                         DBG_88E("%s roaming do_join return %d\n", __func__ , do_join_r);
1473                                         continue;
1474                                 }
1475                                 break;
1476                         } else {
1477                                 DBG_88E("%s We've try roaming but fail\n", __func__);
1478                                 rtw_indicate_disconnect(adapter);
1479                                 break;
1480                         }
1481                 }
1482         } else {
1483                 rtw_indicate_disconnect(adapter);
1484                 free_scanqueue(pmlmepriv);/*  */
1485         }
1486         spin_unlock_bh(&pmlmepriv->lock);
1487 }
1488
1489 /*
1490 * rtw_scan_timeout_handler - Timeout/Faliure handler for CMD SiteSurvey
1491 * @adapter: pointer to struct adapter structure
1492 */
1493 void rtw_scan_timeout_handler (struct adapter *adapter)
1494 {
1495         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1496
1497         DBG_88E(FUNC_ADPT_FMT" fw_state=%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1498         spin_lock_bh(&pmlmepriv->lock);
1499         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1500         spin_unlock_bh(&pmlmepriv->lock);
1501         rtw_indicate_scan_done(adapter, true);
1502 }
1503
1504 static void rtw_auto_scan_handler(struct adapter *padapter)
1505 {
1506         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1507
1508         /* auto site survey per 60sec */
1509         if (pmlmepriv->scan_interval > 0) {
1510                 pmlmepriv->scan_interval--;
1511                 if (pmlmepriv->scan_interval == 0) {
1512                         DBG_88E("%s\n", __func__);
1513                         rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1514                         pmlmepriv->scan_interval = SCAN_INTERVAL;/*  30*2 sec = 60sec */
1515                 }
1516         }
1517 }
1518
1519 void rtw_dynamic_check_timer_handlder(struct adapter *adapter)
1520 {
1521         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1522         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1523
1524         if (!adapter)
1525                 return;
1526         if (!adapter->hw_init_completed)
1527                 return;
1528         if ((adapter->bDriverStopped) || (adapter->bSurpriseRemoved))
1529                 return;
1530         if (adapter->net_closed)
1531                 return;
1532         rtw_dynamic_chk_wk_cmd(adapter);
1533
1534         if (pregistrypriv->wifi_spec == 1) {
1535 #ifdef CONFIG_88EU_P2P
1536                 struct wifidirect_info *pwdinfo = &adapter->wdinfo;
1537                 if (rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
1538 #endif
1539                 {
1540                         /* auto site survey */
1541                         rtw_auto_scan_handler(adapter);
1542                 }
1543         }
1544
1545         rcu_read_lock();
1546
1547         if (rcu_dereference(adapter->pnetdev->rx_handler_data) &&
1548             (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_ADHOC_STATE) == true)) {
1549                 /*  expire NAT2.5 entry */
1550                 nat25_db_expire(adapter);
1551
1552                 if (adapter->pppoe_connection_in_progress > 0)
1553                         adapter->pppoe_connection_in_progress--;
1554
1555                 /*  due to rtw_dynamic_check_timer_handlder() is called every 2 seconds */
1556                 if (adapter->pppoe_connection_in_progress > 0)
1557                         adapter->pppoe_connection_in_progress--;
1558         }
1559
1560         rcu_read_unlock();
1561 }
1562
1563 #define RTW_SCAN_RESULT_EXPIRE 2000
1564
1565 /*
1566 * Select a new join candidate from the original @param candidate and @param competitor
1567 * @return true: candidate is updated
1568 * @return false: candidate is not updated
1569 */
1570 static int rtw_check_join_candidate(struct mlme_priv *pmlmepriv
1571         , struct wlan_network **candidate, struct wlan_network *competitor)
1572 {
1573         int updated = false;
1574         struct adapter *adapter = container_of(pmlmepriv, struct adapter, mlmepriv);
1575
1576
1577         /* check bssid, if needed */
1578         if (pmlmepriv->assoc_by_bssid) {
1579                 if (memcmp(competitor->network.MacAddress, pmlmepriv->assoc_bssid, ETH_ALEN))
1580                         goto exit;
1581         }
1582
1583         /* check ssid, if needed */
1584         if (pmlmepriv->assoc_ssid.SsidLength) {
1585                 if (competitor->network.Ssid.SsidLength != pmlmepriv->assoc_ssid.SsidLength ||
1586                     !memcmp(competitor->network.Ssid.Ssid, pmlmepriv->assoc_ssid.Ssid, pmlmepriv->assoc_ssid.SsidLength) == false)
1587                         goto exit;
1588         }
1589
1590         if (rtw_is_desired_network(adapter, competitor)  == false)
1591                 goto exit;
1592
1593         if (pmlmepriv->to_roaming) {
1594                 if (rtw_get_passing_time_ms((u32)competitor->last_scanned) >= RTW_SCAN_RESULT_EXPIRE ||
1595                     is_same_ess(&competitor->network, &pmlmepriv->cur_network.network) == false)
1596                         goto exit;
1597         }
1598
1599         if (*candidate == NULL || (*candidate)->network.Rssi < competitor->network.Rssi) {
1600                 *candidate = competitor;
1601                 updated = true;
1602         }
1603         if (updated) {
1604                 DBG_88E("[by_bssid:%u][assoc_ssid:%s]new candidate: %s(%pM rssi:%d\n",
1605                         pmlmepriv->assoc_by_bssid,
1606                         pmlmepriv->assoc_ssid.Ssid,
1607                         (*candidate)->network.Ssid.Ssid,
1608                         (*candidate)->network.MacAddress,
1609                         (int)(*candidate)->network.Rssi);
1610                 DBG_88E("[to_roaming:%u]\n", pmlmepriv->to_roaming);
1611         }
1612
1613 exit:
1614         return updated;
1615 }
1616
1617 /*
1618 Calling context:
1619 The caller of the sub-routine will be in critical section...
1620 The caller must hold the following spinlock
1621 pmlmepriv->lock
1622 */
1623
1624 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
1625 {
1626         int ret;
1627         struct list_head *phead;
1628         struct adapter *adapter;
1629         struct __queue *queue   = &(pmlmepriv->scanned_queue);
1630         struct  wlan_network    *pnetwork = NULL;
1631         struct  wlan_network    *candidate = NULL;
1632         u8      supp_ant_div = false;
1633
1634         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1635         phead = get_list_head(queue);
1636         adapter = (struct adapter *)pmlmepriv->nic_hdl;
1637         pmlmepriv->pscanned = phead->next;
1638         while (!rtw_end_of_queue_search(phead, pmlmepriv->pscanned)) {
1639                 pnetwork = container_of(pmlmepriv->pscanned, struct wlan_network, list);
1640                 if (pnetwork == NULL) {
1641                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork==NULL)\n", __func__));
1642                         ret = _FAIL;
1643                         goto exit;
1644                 }
1645                 pmlmepriv->pscanned = pmlmepriv->pscanned->next;
1646                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
1647         }
1648         if (candidate == NULL) {
1649                 DBG_88E("%s: return _FAIL(candidate==NULL)\n", __func__);
1650                 ret = _FAIL;
1651                 goto exit;
1652         } else {
1653                 DBG_88E("%s: candidate: %s(%pM ch:%u)\n", __func__,
1654                         candidate->network.Ssid.Ssid, candidate->network.MacAddress,
1655                         candidate->network.Configuration.DSConfig);
1656         }
1657
1658
1659         /*  check for situation of  _FW_LINKED */
1660         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
1661                 DBG_88E("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
1662
1663                 rtw_disassoc_cmd(adapter, 0, true);
1664                 rtw_indicate_disconnect(adapter);
1665                 rtw_free_assoc_resources(adapter, 0);
1666         }
1667
1668         rtw_hal_get_def_var(adapter, HAL_DEF_IS_SUPPORT_ANT_DIV, &(supp_ant_div));
1669         if (supp_ant_div) {
1670                 u8 cur_ant;
1671                 rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(cur_ant));
1672                 DBG_88E("#### Opt_Ant_(%s), cur_Ant(%s)\n",
1673                         (2 == candidate->network.PhyInfo.Optimum_antenna) ? "A" : "B",
1674                         (2 == cur_ant) ? "A" : "B"
1675                 );
1676         }
1677
1678         ret = rtw_joinbss_cmd(adapter, candidate);
1679
1680 exit:
1681         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1682         return ret;
1683 }
1684
1685 int rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
1686 {
1687         struct  cmd_obj *pcmd;
1688         struct  setauth_parm *psetauthparm;
1689         struct  cmd_priv *pcmdpriv = &(adapter->cmdpriv);
1690         int             res = _SUCCESS;
1691
1692         pcmd = (struct  cmd_obj *)rtw_zmalloc(sizeof(struct cmd_obj));
1693         if (pcmd == NULL) {
1694                 res = _FAIL;  /* try again */
1695                 goto exit;
1696         }
1697
1698         psetauthparm = (struct setauth_parm *)rtw_zmalloc(sizeof(struct setauth_parm));
1699         if (psetauthparm == NULL) {
1700                 kfree(pcmd);
1701                 res = _FAIL;
1702                 goto exit;
1703         }
1704         _rtw_memset(psetauthparm, 0, sizeof(struct setauth_parm));
1705         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
1706         pcmd->cmdcode = _SetAuth_CMD_;
1707         pcmd->parmbuf = (unsigned char *)psetauthparm;
1708         pcmd->cmdsz =  (sizeof(struct setauth_parm));
1709         pcmd->rsp = NULL;
1710         pcmd->rspsz = 0;
1711         _rtw_init_listhead(&pcmd->list);
1712         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1713                  ("after enqueue set_auth_cmd, auth_mode=%x\n",
1714                  psecuritypriv->dot11AuthAlgrthm));
1715         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1716 exit:
1717         return res;
1718 }
1719
1720 int rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, int keyid, u8 set_tx)
1721 {
1722         u8      keylen;
1723         struct cmd_obj          *pcmd;
1724         struct setkey_parm      *psetkeyparm;
1725         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
1726         struct mlme_priv                *pmlmepriv = &(adapter->mlmepriv);
1727         int     res = _SUCCESS;
1728
1729         pcmd = (struct  cmd_obj *)rtw_zmalloc(sizeof(struct     cmd_obj));
1730         if (pcmd == NULL) {
1731                 res = _FAIL;  /* try again */
1732                 goto exit;
1733         }
1734         psetkeyparm = (struct setkey_parm *)rtw_zmalloc(sizeof(struct setkey_parm));
1735         if (psetkeyparm == NULL) {
1736                 kfree(pcmd);
1737                 res = _FAIL;
1738                 goto exit;
1739         }
1740
1741         _rtw_memset(psetkeyparm, 0, sizeof(struct setkey_parm));
1742
1743         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1744                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
1745                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1746                          ("\n rtw_set_key: psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy=%d\n",
1747                          psetkeyparm->algorithm));
1748         } else {
1749                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
1750                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1751                          ("\n rtw_set_key: psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm=%d\n",
1752                          psetkeyparm->algorithm));
1753         }
1754         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
1755         psetkeyparm->set_tx = set_tx;
1756         pmlmepriv->key_mask |= BIT(psetkeyparm->keyid);
1757         DBG_88E("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n",
1758                 psetkeyparm->algorithm, psetkeyparm->keyid, pmlmepriv->key_mask);
1759         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1760                  ("\n rtw_set_key: psetkeyparm->algorithm=%d psetkeyparm->keyid=(u8)keyid=%d\n",
1761                  psetkeyparm->algorithm, keyid));
1762
1763         switch (psetkeyparm->algorithm) {
1764         case _WEP40_:
1765                 keylen = 5;
1766                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1767                 break;
1768         case _WEP104_:
1769                 keylen = 13;
1770                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1771                 break;
1772         case _TKIP_:
1773                 keylen = 16;
1774                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1775                 psetkeyparm->grpkey = 1;
1776                 break;
1777         case _AES_:
1778                 keylen = 16;
1779                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1780                 psetkeyparm->grpkey = 1;
1781                 break;
1782         default:
1783                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1784                          ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm=%x (must be 1 or 2 or 4 or 5)\n",
1785                          psecuritypriv->dot11PrivacyAlgrthm));
1786                 res = _FAIL;
1787                 goto exit;
1788         }
1789         pcmd->cmdcode = _SetKey_CMD_;
1790         pcmd->parmbuf = (u8 *)psetkeyparm;
1791         pcmd->cmdsz =  (sizeof(struct setkey_parm));
1792         pcmd->rsp = NULL;
1793         pcmd->rspsz = 0;
1794         _rtw_init_listhead(&pcmd->list);
1795         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1796 exit:
1797         return res;
1798 }
1799
1800 /* adjust IEs for rtw_joinbss_cmd in WMM */
1801 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
1802 {
1803         unsigned        int ielength = 0;
1804         unsigned int i, j;
1805
1806         i = 12; /* after the fixed IE */
1807         while (i < in_len) {
1808                 ielength = initial_out_len;
1809
1810                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) {
1811                         /* WMM element ID and OUI */
1812                         /* Append WMM IE to the last index of out_ie */
1813
1814                         for (j = i; j < i + 9; j++) {
1815                                 out_ie[ielength] = in_ie[j];
1816                                 ielength++;
1817                         }
1818                         out_ie[initial_out_len + 1] = 0x07;
1819                         out_ie[initial_out_len + 6] = 0x00;
1820                         out_ie[initial_out_len + 8] = 0x00;
1821                         break;
1822                 }
1823                 i += (in_ie[i+1]+2); /*  to the next IE element */
1824         }
1825         return ielength;
1826 }
1827
1828 /*
1829  * Ported from 8185: IsInPreAuthKeyList().
1830  * (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.)
1831  * Added by Annie, 2006-05-07.
1832  * Search by BSSID,
1833  * Return Value:
1834  *              -1      :if there is no pre-auth key in the table
1835  *              >= 0    :if there is pre-auth key, and return the entry id
1836  */
1837 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
1838 {
1839         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1840         int i = 0;
1841
1842         do {
1843                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
1844                     (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN))) {
1845                         break;
1846                 } else {
1847                         i++;
1848                         /* continue; */
1849                 }
1850
1851         } while (i < NUM_PMKID_CACHE);
1852
1853         if (i == NUM_PMKID_CACHE)
1854                 i = -1;/*  Could not find. */
1855
1856         return i;
1857 }
1858
1859 /*  */
1860 /*  Check the RSN IE length */
1861 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
1862 /*  0-11th element in the array are the fixed IE */
1863 /*  12th element in the array is the IE */
1864 /*  13th element in the array is the IE length */
1865 /*  */
1866
1867 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
1868 {
1869         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1870
1871         if (ie[13] <= 20) {
1872                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
1873                 ie[ie_len] = 1;
1874                 ie_len++;
1875                 ie[ie_len] = 0; /* PMKID count = 0x0100 */
1876                 ie_len++;
1877                 memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
1878
1879                 ie_len += 16;
1880                 ie[13] += 18;/* PMKID length = 2+16 */
1881         }
1882         return ie_len;
1883 }
1884
1885 int rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
1886 {
1887         u8 authmode;
1888         uint    ielength;
1889         int iEntry;
1890
1891         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1892         struct security_priv *psecuritypriv = &adapter->securitypriv;
1893         uint    ndisauthmode = psecuritypriv->ndisauthtype;
1894         uint ndissecuritytype = psecuritypriv->ndisencryptstatus;
1895
1896         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
1897                  ("+rtw_restruct_sec_ie: ndisauthmode=%d ndissecuritytype=%d\n",
1898                   ndisauthmode, ndissecuritytype));
1899
1900         /* copy fixed ie only */
1901         memcpy(out_ie, in_ie, 12);
1902         ielength = 12;
1903         if ((ndisauthmode == Ndis802_11AuthModeWPA) ||
1904             (ndisauthmode == Ndis802_11AuthModeWPAPSK))
1905                         authmode = _WPA_IE_ID_;
1906         if ((ndisauthmode == Ndis802_11AuthModeWPA2) ||
1907             (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
1908                 authmode = _WPA2_IE_ID_;
1909
1910         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
1911                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
1912
1913                 ielength += psecuritypriv->wps_ie_len;
1914         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
1915                 /* copy RSN or SSN */
1916                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
1917                 ielength += psecuritypriv->supplicant_ie[1]+2;
1918                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
1919         }
1920
1921         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
1922         if (iEntry < 0) {
1923                 return ielength;
1924         } else {
1925                 if (authmode == _WPA2_IE_ID_)
1926                         ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
1927         }
1928         return ielength;
1929 }
1930
1931 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
1932 {
1933         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1934         struct eeprom_priv *peepriv = &adapter->eeprompriv;
1935         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
1936         u8 *myhwaddr = myid(peepriv);
1937
1938         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
1939
1940         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
1941
1942         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_config);
1943         pdev_network->Configuration.BeaconPeriod = 100;
1944         pdev_network->Configuration.FHConfig.Length = 0;
1945         pdev_network->Configuration.FHConfig.HopPattern = 0;
1946         pdev_network->Configuration.FHConfig.HopSet = 0;
1947         pdev_network->Configuration.FHConfig.DwellTime = 0;
1948 }
1949
1950 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
1951 {
1952         int sz = 0;
1953         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1954         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
1955         struct  security_priv *psecuritypriv = &adapter->securitypriv;
1956         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
1957
1958         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0); /*  adhoc no 802.1x */
1959
1960         pdev_network->Rssi = 0;
1961
1962         switch (pregistrypriv->wireless_mode) {
1963         case WIRELESS_11B:
1964                 pdev_network->NetworkTypeInUse = (Ndis802_11DS);
1965                 break;
1966         case WIRELESS_11G:
1967         case WIRELESS_11BG:
1968         case WIRELESS_11_24N:
1969         case WIRELESS_11G_24N:
1970         case WIRELESS_11BG_24N:
1971                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
1972                 break;
1973         case WIRELESS_11A:
1974         case WIRELESS_11A_5N:
1975                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
1976                 break;
1977         case WIRELESS_11ABGN:
1978                 if (pregistrypriv->channel > 14)
1979                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
1980                 else
1981                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
1982                 break;
1983         default:
1984                 /*  TODO */
1985                 break;
1986         }
1987
1988         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
1989         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
1990                  ("pregistrypriv->channel=%d, pdev_network->Configuration.DSConfig=0x%x\n",
1991                  pregistrypriv->channel, pdev_network->Configuration.DSConfig));
1992
1993         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
1994                 pdev_network->Configuration.ATIMWindow = (0);
1995
1996         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
1997
1998         /*  1. Supported rates */
1999         /*  2. IE */
2000
2001         sz = rtw_generate_ie(pregistrypriv);
2002         pdev_network->IELength = sz;
2003         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
2004
2005         /* notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd(); */
2006         /* pdev_network->IELength = cpu_to_le32(sz); */
2007 }
2008
2009 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
2010 {
2011 }
2012
2013 /* the function is at passive_level */
2014 void rtw_joinbss_reset(struct adapter *padapter)
2015 {
2016         u8      threshold;
2017         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2018         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
2019
2020         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
2021         pmlmepriv->num_FortyMHzIntolerant = 0;
2022
2023         pmlmepriv->num_sta_no_ht = 0;
2024
2025         phtpriv->ampdu_enable = false;/* reset to disabled */
2026
2027         /*  TH = 1 => means that invalidate usb rx aggregation */
2028         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
2029         if (phtpriv->ht_option) {
2030                 if (padapter->registrypriv.wifi_spec == 1)
2031                         threshold = 1;
2032                 else
2033                         threshold = 0;
2034                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2035         } else {
2036                 threshold = 1;
2037                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2038         }
2039 }
2040
2041 /* the function is >= passive_level */
2042 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len)
2043 {
2044         u32 ielen, out_len;
2045         enum ht_cap_ampdu_factor max_rx_ampdu_factor;
2046         unsigned char *p;
2047         struct rtw_ieee80211_ht_cap ht_capie;
2048         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
2049         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2050         struct qos_priv         *pqospriv = &pmlmepriv->qospriv;
2051         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
2052         u32 rx_packet_offset, max_recvbuf_sz;
2053
2054
2055         phtpriv->ht_option = false;
2056
2057         p = rtw_get_ie(in_ie+12, _HT_CAPABILITY_IE_, &ielen, in_len-12);
2058
2059         if (p && ielen > 0) {
2060                 if (pqospriv->qos_option == 0) {
2061                         out_len = *pout_len;
2062                         rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_,
2063                                    _WMM_IE_Length_, WMM_IE, pout_len);
2064
2065                         pqospriv->qos_option = 1;
2066                 }
2067
2068                 out_len = *pout_len;
2069
2070                 _rtw_memset(&ht_capie, 0, sizeof(struct rtw_ieee80211_ht_cap));
2071
2072                 ht_capie.cap_info = IEEE80211_HT_CAP_SUP_WIDTH |
2073                                     IEEE80211_HT_CAP_SGI_20 |
2074                                     IEEE80211_HT_CAP_SGI_40 |
2075                                     IEEE80211_HT_CAP_TX_STBC |
2076                                     IEEE80211_HT_CAP_DSSSCCK40;
2077
2078                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
2079                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
2080
2081                 /*
2082                 AMPDU_para [1:0]:Max AMPDU Len => 0:8k , 1:16k, 2:32k, 3:64k
2083                 AMPDU_para [4:2]:Min MPDU Start Spacing
2084                 */
2085
2086                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor);
2087                 ht_capie.ampdu_params_info = (max_rx_ampdu_factor&0x03);
2088
2089                 if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
2090                         ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&(0x07<<2));
2091                 else
2092                         ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
2093
2094
2095                 rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
2096                            sizeof(struct rtw_ieee80211_ht_cap), (unsigned char *)&ht_capie, pout_len);
2097
2098                 phtpriv->ht_option = true;
2099
2100                 p = rtw_get_ie(in_ie+12, _HT_ADD_INFO_IE_, &ielen, in_len-12);
2101                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2102                         out_len = *pout_len;
2103                         rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2 , pout_len);
2104                 }
2105         }
2106         return phtpriv->ht_option;
2107 }
2108
2109 /* the function is > passive_level (in critical_section) */
2110 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len)
2111 {
2112         u8 *p, max_ampdu_sz;
2113         int len;
2114         struct rtw_ieee80211_ht_cap *pht_capie;
2115         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2116         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
2117         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2118         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
2119         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
2120
2121         if (!phtpriv->ht_option)
2122                 return;
2123
2124         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
2125                 return;
2126
2127         DBG_88E("+rtw_update_ht_cap()\n");
2128
2129         /* maybe needs check if ap supports rx ampdu. */
2130         if ((!phtpriv->ampdu_enable) && (pregistrypriv->ampdu_enable == 1)) {
2131                 if (pregistrypriv->wifi_spec == 1)
2132                         phtpriv->ampdu_enable = false;
2133                 else
2134                         phtpriv->ampdu_enable = true;
2135         } else if (pregistrypriv->ampdu_enable == 2) {
2136                 phtpriv->ampdu_enable = true;
2137         }
2138
2139
2140         /* check Max Rx A-MPDU Size */
2141         len = 0;
2142         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fixed_ie), _HT_CAPABILITY_IE_, &len, ie_len-sizeof(struct ndis_802_11_fixed_ie));
2143         if (p && len > 0) {
2144                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);
2145                 max_ampdu_sz = (pht_capie->ampdu_params_info & IEEE80211_HT_CAP_AMPDU_FACTOR);
2146                 max_ampdu_sz = 1 << (max_ampdu_sz+3); /*  max_ampdu_sz (kbytes); */
2147                 phtpriv->rx_ampdu_maxlen = max_ampdu_sz;
2148         }
2149         len = 0;
2150         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fixed_ie), _HT_ADD_INFO_IE_, &len, ie_len-sizeof(struct ndis_802_11_fixed_ie));
2151
2152         /* update cur_bwmode & cur_ch_offset */
2153         if ((pregistrypriv->cbw40_enable) &&
2154             (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) & BIT(1)) &&
2155             (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
2156                 int i;
2157                 u8      rf_type;
2158
2159                 padapter->HalFunc.GetHwRegHandler(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2160
2161                 /* update the MCS rates */
2162                 for (i = 0; i < 16; i++) {
2163                         if ((rf_type == RF_1T1R) || (rf_type == RF_1T2R))
2164                                 pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= MCS_rate_1R[i];
2165                         else
2166                                 pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= MCS_rate_2R[i];
2167                 }
2168                 /* switch to the 40M Hz mode according to the AP */
2169                 pmlmeext->cur_bwmode = HT_CHANNEL_WIDTH_40;
2170                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
2171                 case HT_EXTCHNL_OFFSET_UPPER:
2172                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
2173                         break;
2174                 case HT_EXTCHNL_OFFSET_LOWER:
2175                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
2176                         break;
2177                 default:
2178                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
2179                         break;
2180                 }
2181         }
2182
2183         /*  Config SM Power Save setting */
2184         pmlmeinfo->SM_PS = (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) & 0x0C) >> 2;
2185         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
2186                 DBG_88E("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
2187
2188         /*  Config current HT Protection mode. */
2189         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
2190 }
2191
2192 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
2193 {
2194         u8 issued;
2195         int priority;
2196         struct sta_info *psta = NULL;
2197         struct ht_priv  *phtpriv;
2198         struct pkt_attrib *pattrib = &pxmitframe->attrib;
2199         s32 bmcst = IS_MCAST(pattrib->ra);
2200
2201         if (bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100))
2202                 return;
2203
2204         priority = pattrib->priority;
2205
2206         if (pattrib->psta)
2207                 psta = pattrib->psta;
2208         else
2209                 psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
2210
2211         if (psta == NULL)
2212                 return;
2213
2214         phtpriv = &psta->htpriv;
2215
2216         if ((phtpriv->ht_option) && (phtpriv->ampdu_enable)) {
2217                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
2218                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
2219
2220                 if (0 == issued) {
2221                         DBG_88E("rtw_issue_addbareq_cmd, p=%d\n", priority);
2222                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
2223                         rtw_addbareq_cmd(padapter, (u8) priority, pattrib->ra);
2224                 }
2225         }
2226 }
2227
2228 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2229 {
2230         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2231
2232         spin_lock_bh(&pmlmepriv->lock);
2233         _rtw_roaming(padapter, tgt_network);
2234         spin_unlock_bh(&pmlmepriv->lock);
2235 }
2236 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2237 {
2238         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2239         int do_join_r;
2240
2241         struct wlan_network *pnetwork;
2242
2243         if (tgt_network != NULL)
2244                 pnetwork = tgt_network;
2245         else
2246                 pnetwork = &pmlmepriv->cur_network;
2247
2248         if (0 < pmlmepriv->to_roaming) {
2249                 DBG_88E("roaming from %s(%pM length:%d\n",
2250                         pnetwork->network.Ssid.Ssid, pnetwork->network.MacAddress,
2251                         pnetwork->network.Ssid.SsidLength);
2252                 memcpy(&pmlmepriv->assoc_ssid, &pnetwork->network.Ssid, sizeof(struct ndis_802_11_ssid));
2253
2254                 pmlmepriv->assoc_by_bssid = false;
2255
2256                 while (1) {
2257                         do_join_r = rtw_do_join(padapter);
2258                         if (_SUCCESS == do_join_r) {
2259                                 break;
2260                         } else {
2261                                 DBG_88E("roaming do_join return %d\n", do_join_r);
2262                                 pmlmepriv->to_roaming--;
2263
2264                                 if (0 < pmlmepriv->to_roaming) {
2265                                         continue;
2266                                 } else {
2267                                         DBG_88E("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
2268                                         rtw_indicate_disconnect(padapter);
2269                                         break;
2270                                 }
2271                         }
2272                 }
2273         }
2274 }