Merge tag 'stable/for-linus-3.15-rc5-tag' of git://git.kernel.org/pub/scm/linux/kerne...
[cascardo/linux.git] / drivers / staging / rtl8712 / rtl871x_cmd.c
1 /******************************************************************************
2  * rtl871x_cmd.c
3  *
4  * Copyright(c) 2007 - 2010 Realtek Corporation. All rights reserved.
5  * Linux device driver for RTL8192SU
6  *
7  * This program is free software; you can redistribute it and/or modify it
8  * under the terms of version 2 of the GNU General Public License as
9  * published by the Free Software Foundation.
10  *
11  * This program is distributed in the hope that it will be useful, but WITHOUT
12  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
13  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for
14  * more details.
15  *
16  * You should have received a copy of the GNU General Public License along with
17  * this program; if not, write to the Free Software Foundation, Inc.,
18  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
19  *
20  * Modifications for inclusion into the Linux staging tree are
21  * Copyright(c) 2010 Larry Finger. All rights reserved.
22  *
23  * Contact information:
24  * WLAN FAE <wlanfae@realtek.com>
25  * Larry Finger <Larry.Finger@lwfinger.net>
26  *
27  ******************************************************************************/
28
29 #define _RTL871X_CMD_C_
30
31 #include <linux/compiler.h>
32 #include <linux/kernel.h>
33 #include <linux/errno.h>
34 #include <linux/slab.h>
35 #include <linux/module.h>
36 #include <linux/kref.h>
37 #include <linux/netdevice.h>
38 #include <linux/skbuff.h>
39 #include <linux/usb.h>
40 #include <linux/usb/ch9.h>
41 #include <linux/circ_buf.h>
42 #include <linux/uaccess.h>
43 #include <asm/byteorder.h>
44 #include <linux/atomic.h>
45 #include <linux/semaphore.h>
46 #include <linux/rtnetlink.h>
47
48 #include "osdep_service.h"
49 #include "drv_types.h"
50 #include "recv_osdep.h"
51 #include "mlme_osdep.h"
52
53 /*
54 Caller and the r8712_cmd_thread can protect cmd_q by spin_lock.
55 No irqsave is necessary.
56 */
57
58 static sint _init_cmd_priv(struct cmd_priv *pcmdpriv)
59 {
60         sema_init(&(pcmdpriv->cmd_queue_sema), 0);
61         sema_init(&(pcmdpriv->terminate_cmdthread_sema), 0);
62
63         _init_queue(&(pcmdpriv->cmd_queue));
64
65         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
66         pcmdpriv->cmd_seq = 1;
67         pcmdpriv->cmd_allocated_buf = _malloc(MAX_CMDSZ + CMDBUFF_ALIGN_SZ);
68         if (pcmdpriv->cmd_allocated_buf == NULL)
69                 return _FAIL;
70         pcmdpriv->cmd_buf = pcmdpriv->cmd_allocated_buf  +  CMDBUFF_ALIGN_SZ -
71                             ((addr_t)(pcmdpriv->cmd_allocated_buf) &
72                             (CMDBUFF_ALIGN_SZ-1));
73         pcmdpriv->rsp_allocated_buf = _malloc(MAX_RSPSZ + 4);
74         if (pcmdpriv->rsp_allocated_buf == NULL)
75                 return _FAIL;
76         pcmdpriv->rsp_buf = pcmdpriv->rsp_allocated_buf  +  4 -
77                             ((addr_t)(pcmdpriv->rsp_allocated_buf) & 3);
78         pcmdpriv->cmd_issued_cnt = 0;
79         pcmdpriv->cmd_done_cnt = 0;
80         pcmdpriv->rsp_cnt = 0;
81         return _SUCCESS;
82 }
83
84 static sint _init_evt_priv(struct evt_priv *pevtpriv)
85 {
86         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
87         pevtpriv->event_seq = 0;
88         pevtpriv->evt_allocated_buf = _malloc(MAX_EVTSZ + 4);
89
90         if (pevtpriv->evt_allocated_buf == NULL)
91                 return _FAIL;
92         pevtpriv->evt_buf = pevtpriv->evt_allocated_buf  +  4 -
93                             ((addr_t)(pevtpriv->evt_allocated_buf) & 3);
94         pevtpriv->evt_done_cnt = 0;
95         return _SUCCESS;
96 }
97
98 static void _free_evt_priv(struct evt_priv *pevtpriv)
99 {
100         kfree(pevtpriv->evt_allocated_buf);
101 }
102
103 static void _free_cmd_priv(struct cmd_priv *pcmdpriv)
104 {
105         if (pcmdpriv) {
106                 kfree(pcmdpriv->cmd_allocated_buf);
107                 kfree(pcmdpriv->rsp_allocated_buf);
108         }
109 }
110
111 /*
112 Calling Context:
113
114 _enqueue_cmd can only be called between kernel thread,
115 since only spin_lock is used.
116
117 ISR/Call-Back functions can't call this sub-function.
118
119 */
120
121 static sint _enqueue_cmd(struct  __queue *queue, struct cmd_obj *obj)
122 {
123         unsigned long irqL;
124
125         if (obj == NULL)
126                 return _SUCCESS;
127         spin_lock_irqsave(&queue->lock, irqL);
128         list_insert_tail(&obj->list, &queue->queue);
129         spin_unlock_irqrestore(&queue->lock, irqL);
130         return _SUCCESS;
131 }
132
133 static struct cmd_obj *_dequeue_cmd(struct  __queue *queue)
134 {
135         unsigned long irqL;
136         struct cmd_obj *obj;
137
138         spin_lock_irqsave(&(queue->lock), irqL);
139         if (is_list_empty(&(queue->queue)))
140                 obj = NULL;
141         else {
142                 obj = LIST_CONTAINOR(get_next(&(queue->queue)),
143                                      struct cmd_obj, list);
144                 list_delete(&obj->list);
145         }
146         spin_unlock_irqrestore(&(queue->lock), irqL);
147         return obj;
148 }
149
150 u32 r8712_init_cmd_priv(struct cmd_priv *pcmdpriv)
151 {
152         return _init_cmd_priv(pcmdpriv);
153 }
154
155 u32 r8712_init_evt_priv(struct evt_priv *pevtpriv)
156 {
157         return _init_evt_priv(pevtpriv);
158 }
159
160 void r8712_free_evt_priv(struct evt_priv *pevtpriv)
161 {
162         _free_evt_priv(pevtpriv);
163 }
164
165 void r8712_free_cmd_priv(struct cmd_priv *pcmdpriv)
166 {
167         _free_cmd_priv(pcmdpriv);
168 }
169
170 u32 r8712_enqueue_cmd(struct cmd_priv *pcmdpriv, struct cmd_obj *obj)
171 {
172         int res;
173
174         if (pcmdpriv->padapter->eeprompriv.bautoload_fail_flag == true)
175                 return _FAIL;
176         res = _enqueue_cmd(&pcmdpriv->cmd_queue, obj);
177         up(&pcmdpriv->cmd_queue_sema);
178         return res;
179 }
180
181 u32 r8712_enqueue_cmd_ex(struct cmd_priv *pcmdpriv, struct cmd_obj *obj)
182 {
183         unsigned long irqL;
184         struct  __queue *queue;
185
186         if (obj == NULL)
187                 return _SUCCESS;
188         if (pcmdpriv->padapter->eeprompriv.bautoload_fail_flag == true)
189                 return _FAIL;
190         queue = &pcmdpriv->cmd_queue;
191         spin_lock_irqsave(&queue->lock, irqL);
192         list_insert_tail(&obj->list, &queue->queue);
193         spin_unlock_irqrestore(&queue->lock, irqL);
194         up(&pcmdpriv->cmd_queue_sema);
195         return _SUCCESS;
196 }
197
198 struct cmd_obj *r8712_dequeue_cmd(struct  __queue *queue)
199 {
200         return _dequeue_cmd(queue);
201 }
202
203 void r8712_free_cmd_obj(struct cmd_obj *pcmd)
204 {
205         if ((pcmd->cmdcode != _JoinBss_CMD_) &&
206             (pcmd->cmdcode != _CreateBss_CMD_))
207                 kfree((unsigned char *)pcmd->parmbuf);
208         if (pcmd->rsp != NULL) {
209                 if (pcmd->rspsz != 0)
210                         kfree((unsigned char *)pcmd->rsp);
211         }
212         kfree((unsigned char *)pcmd);
213 }
214
215 /*
216 r8712_sitesurvey_cmd(~)
217         ### NOTE:#### (!!!!)
218         MUST TAKE CARE THAT BEFORE CALLING THIS FUNC,
219          YOU SHOULD HAVE LOCKED pmlmepriv->lock
220 */
221 u8 r8712_sitesurvey_cmd(struct _adapter *padapter,
222                         struct ndis_802_11_ssid *pssid)
223 {
224         struct cmd_obj  *ph2c;
225         struct sitesurvey_parm  *psurveyPara;
226         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
227         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
228
229         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
230         if (ph2c == NULL)
231                 return _FAIL;
232         psurveyPara = (struct sitesurvey_parm *)_malloc(
233                        sizeof(struct sitesurvey_parm));
234         if (psurveyPara == NULL) {
235                 kfree((unsigned char *) ph2c);
236                 return _FAIL;
237         }
238         init_h2fwcmd_w_parm_no_rsp(ph2c, psurveyPara,
239                                    GEN_CMD_CODE(_SiteSurvey));
240         psurveyPara->bsslimit = cpu_to_le32(48);
241         psurveyPara->passive_mode = cpu_to_le32(pmlmepriv->passive_mode);
242         psurveyPara->ss_ssidlen = 0;
243         memset(psurveyPara->ss_ssid, 0, IW_ESSID_MAX_SIZE + 1);
244         if ((pssid != NULL) && (pssid->SsidLength)) {
245                 memcpy(psurveyPara->ss_ssid, pssid->Ssid, pssid->SsidLength);
246                 psurveyPara->ss_ssidlen = cpu_to_le32(pssid->SsidLength);
247         }
248         set_fwstate(pmlmepriv, _FW_UNDER_SURVEY);
249         r8712_enqueue_cmd(pcmdpriv, ph2c);
250         _set_timer(&pmlmepriv->scan_to_timer, SCANNING_TIMEOUT);
251         padapter->ledpriv.LedControlHandler(padapter, LED_CTL_SITE_SURVEY);
252         padapter->blnEnableRxFF0Filter = 0;
253         return _SUCCESS;
254 }
255
256 u8 r8712_setdatarate_cmd(struct _adapter *padapter, u8 *rateset)
257 {
258         struct cmd_obj          *ph2c;
259         struct setdatarate_parm *pbsetdataratepara;
260         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
261
262         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
263         if (ph2c == NULL)
264                 return _FAIL;
265         pbsetdataratepara = (struct setdatarate_parm *)_malloc(
266                              sizeof(struct setdatarate_parm));
267         if (pbsetdataratepara == NULL) {
268                 kfree((u8 *) ph2c);
269                 return _FAIL;
270         }
271         init_h2fwcmd_w_parm_no_rsp(ph2c, pbsetdataratepara,
272                                    GEN_CMD_CODE(_SetDataRate));
273         pbsetdataratepara->mac_id = 5;
274         memcpy(pbsetdataratepara->datarates, rateset, NumRates);
275         r8712_enqueue_cmd(pcmdpriv, ph2c);
276         return _SUCCESS;
277 }
278
279 u8 r8712_set_chplan_cmd(struct _adapter *padapter, int chplan)
280 {
281         struct cmd_obj *ph2c;
282         struct SetChannelPlan_param *psetchplanpara;
283         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
284
285         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
286         if (ph2c == NULL)
287                 return _FAIL;
288         psetchplanpara = (struct SetChannelPlan_param *)
289                 _malloc(sizeof(struct SetChannelPlan_param));
290         if (psetchplanpara == NULL) {
291                 kfree((u8 *) ph2c);
292                 return _FAIL;
293         }
294         init_h2fwcmd_w_parm_no_rsp(ph2c, psetchplanpara,
295                                 GEN_CMD_CODE(_SetChannelPlan));
296         psetchplanpara->ChannelPlan = chplan;
297         r8712_enqueue_cmd(pcmdpriv, ph2c);
298         return _SUCCESS;
299 }
300
301 u8 r8712_setbasicrate_cmd(struct _adapter *padapter, u8 *rateset)
302 {
303         struct cmd_obj *ph2c;
304         struct setbasicrate_parm *pssetbasicratepara;
305         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
306
307         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
308         if (ph2c == NULL)
309                 return _FAIL;
310         pssetbasicratepara = (struct setbasicrate_parm *)_malloc(
311                               sizeof(struct setbasicrate_parm));
312         if (pssetbasicratepara == NULL) {
313                 kfree((u8 *) ph2c);
314                 return _FAIL;
315         }
316         init_h2fwcmd_w_parm_no_rsp(ph2c, pssetbasicratepara,
317                 _SetBasicRate_CMD_);
318         memcpy(pssetbasicratepara->basicrates, rateset, NumRates);
319         r8712_enqueue_cmd(pcmdpriv, ph2c);
320         return _SUCCESS;
321 }
322
323 /* power tracking mechanism setting */
324 u8 r8712_setptm_cmd(struct _adapter *padapter, u8 type)
325 {
326         struct cmd_obj          *ph2c;
327         struct writePTM_parm    *pwriteptmparm;
328         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
329
330         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
331         if (ph2c == NULL)
332                 return _FAIL;
333         pwriteptmparm = (struct writePTM_parm *)
334                 _malloc(sizeof(struct writePTM_parm));
335         if (pwriteptmparm == NULL) {
336                 kfree((u8 *) ph2c);
337                 return _FAIL;
338         }
339         init_h2fwcmd_w_parm_no_rsp(ph2c, pwriteptmparm, GEN_CMD_CODE(_SetPT));
340         pwriteptmparm->type = type;
341         r8712_enqueue_cmd(pcmdpriv, ph2c);
342         return _SUCCESS;
343 }
344
345 u8 r8712_setfwdig_cmd(struct _adapter *padapter, u8 type)
346 {
347         struct cmd_obj *ph2c;
348         struct writePTM_parm *pwriteptmparm;
349         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
350
351         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
352         if (ph2c == NULL)
353                 return _FAIL;
354         pwriteptmparm = (struct writePTM_parm *)
355                 _malloc(sizeof(struct setdig_parm));
356         if (pwriteptmparm == NULL) {
357                 kfree((u8 *) ph2c);
358                 return _FAIL;
359         }
360         init_h2fwcmd_w_parm_no_rsp(ph2c, pwriteptmparm, GEN_CMD_CODE(_SetDIG));
361         pwriteptmparm->type = type;
362         r8712_enqueue_cmd(pcmdpriv, ph2c);
363         return _SUCCESS;
364 }
365
366 u8 r8712_setfwra_cmd(struct _adapter *padapter, u8 type)
367 {
368         struct cmd_obj *ph2c;
369         struct writePTM_parm *pwriteptmparm;
370         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
371
372         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
373         if (ph2c == NULL)
374                 return _FAIL;
375         pwriteptmparm = (struct writePTM_parm *)
376                 _malloc(sizeof(struct setra_parm));
377         if (pwriteptmparm == NULL) {
378                 kfree((u8 *) ph2c);
379                 return _FAIL;
380         }
381         init_h2fwcmd_w_parm_no_rsp(ph2c, pwriteptmparm, GEN_CMD_CODE(_SetRA));
382         pwriteptmparm->type = type;
383         r8712_enqueue_cmd(pcmdpriv, ph2c);
384         return _SUCCESS;
385 }
386
387 u8 r8712_setrfreg_cmd(struct _adapter  *padapter, u8 offset, u32 val)
388 {
389         struct cmd_obj *ph2c;
390         struct writeRF_parm *pwriterfparm;
391         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
392
393         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
394         if (ph2c == NULL)
395                 return _FAIL;
396         pwriterfparm = (struct writeRF_parm *)_malloc(
397                         sizeof(struct writeRF_parm));
398         if (pwriterfparm == NULL) {
399                 kfree((u8 *) ph2c);
400                 return _FAIL;
401         }
402         init_h2fwcmd_w_parm_no_rsp(ph2c, pwriterfparm, GEN_CMD_CODE(_SetRFReg));
403         pwriterfparm->offset = offset;
404         pwriterfparm->value = val;
405         r8712_enqueue_cmd(pcmdpriv, ph2c);
406         return _SUCCESS;
407 }
408
409 u8 r8712_getrfreg_cmd(struct _adapter *padapter, u8 offset, u8 *pval)
410 {
411         struct cmd_obj *ph2c;
412         struct readRF_parm *prdrfparm;
413         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
414
415         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
416         if (ph2c == NULL)
417                 return _FAIL;
418         prdrfparm = (struct readRF_parm *)_malloc(sizeof(struct readRF_parm));
419         if (prdrfparm == NULL) {
420                 kfree((u8 *) ph2c);
421                 return _FAIL;
422         }
423         _init_listhead(&ph2c->list);
424         ph2c->cmdcode = GEN_CMD_CODE(_GetRFReg);
425         ph2c->parmbuf = (unsigned char *)prdrfparm;
426         ph2c->cmdsz =  sizeof(struct readRF_parm);
427         ph2c->rsp = pval;
428         ph2c->rspsz = sizeof(struct readRF_rsp);
429         prdrfparm->offset = offset;
430         r8712_enqueue_cmd(pcmdpriv, ph2c);
431         return _SUCCESS;
432 }
433
434 void r8712_getbbrfreg_cmdrsp_callback(struct _adapter *padapter,
435                                       struct cmd_obj *pcmd)
436 {
437         kfree(pcmd->parmbuf);
438         kfree(pcmd);
439         padapter->mppriv.workparam.bcompleted = true;
440 }
441
442 void r8712_readtssi_cmdrsp_callback(struct _adapter *padapter,
443                                 struct cmd_obj *pcmd)
444 {
445         kfree(pcmd->parmbuf);
446         kfree(pcmd);
447
448         padapter->mppriv.workparam.bcompleted = true;
449 }
450
451 u8 r8712_createbss_cmd(struct _adapter *padapter)
452 {
453         struct cmd_obj *pcmd;
454         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
455         struct wlan_bssid_ex *pdev_network =
456                                  &padapter->registrypriv.dev_network;
457
458         padapter->ledpriv.LedControlHandler(padapter, LED_CTL_START_TO_LINK);
459         pcmd = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
460         if (pcmd == NULL)
461                 return _FAIL;
462         _init_listhead(&pcmd->list);
463         pcmd->cmdcode = _CreateBss_CMD_;
464         pcmd->parmbuf = (unsigned char *)pdev_network;
465         pcmd->cmdsz = r8712_get_ndis_wlan_bssid_ex_sz((
466                         struct ndis_wlan_bssid_ex *)
467                         pdev_network);
468         pcmd->rsp = NULL;
469         pcmd->rspsz = 0;
470         /* notes: translate IELength & Length after assign to cmdsz; */
471         pdev_network->Length = pcmd->cmdsz;
472         pdev_network->IELength = pdev_network->IELength;
473         pdev_network->Ssid.SsidLength = pdev_network->Ssid.SsidLength;
474         r8712_enqueue_cmd(pcmdpriv, pcmd);
475         return _SUCCESS;
476 }
477
478 u8 r8712_joinbss_cmd(struct _adapter  *padapter, struct wlan_network *pnetwork)
479 {
480         u8 *auth;
481         uint t_len = 0;
482         struct ndis_wlan_bssid_ex *psecnetwork;
483         struct cmd_obj          *pcmd;
484         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
485         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
486         struct qos_priv         *pqospriv = &pmlmepriv->qospriv;
487         struct security_priv    *psecuritypriv = &padapter->securitypriv;
488         struct registry_priv    *pregistrypriv = &padapter->registrypriv;
489         enum NDIS_802_11_NETWORK_INFRASTRUCTURE ndis_network_mode = pnetwork->
490                                                 network.InfrastructureMode;
491
492         padapter->ledpriv.LedControlHandler(padapter, LED_CTL_START_TO_LINK);
493         pcmd = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
494         if (pcmd == NULL)
495                 return _FAIL;
496         t_len = sizeof(u32) + 6 * sizeof(unsigned char) + 2 +
497                         sizeof(struct ndis_802_11_ssid) + sizeof(u32) +
498                         sizeof(s32) +
499                         sizeof(enum NDIS_802_11_NETWORK_TYPE) +
500                         sizeof(struct NDIS_802_11_CONFIGURATION) +
501                         sizeof(enum NDIS_802_11_NETWORK_INFRASTRUCTURE) +
502                         sizeof(NDIS_802_11_RATES_EX) +
503                         sizeof(u32) + MAX_IE_SZ;
504
505         /* for hidden ap to set fw_state here */
506         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_ADHOC_STATE) !=
507             true) {
508                 switch (ndis_network_mode) {
509                 case Ndis802_11IBSS:
510                         pmlmepriv->fw_state |= WIFI_ADHOC_STATE;
511                         break;
512                 case Ndis802_11Infrastructure:
513                         pmlmepriv->fw_state |= WIFI_STATION_STATE;
514                         break;
515                 case Ndis802_11APMode:
516                 case Ndis802_11AutoUnknown:
517                 case Ndis802_11InfrastructureMax:
518                         break;
519                 }
520         }
521         psecnetwork = (struct ndis_wlan_bssid_ex *)&psecuritypriv->sec_bss;
522         if (psecnetwork == NULL) {
523                 kfree(pcmd);
524                 return _FAIL;
525         }
526         memcpy(psecnetwork, &pnetwork->network, t_len);
527         auth = &psecuritypriv->authenticator_ie[0];
528         psecuritypriv->authenticator_ie[0] = (unsigned char)
529                                              psecnetwork->IELength;
530         if ((psecnetwork->IELength-12) < (256 - 1))
531                 memcpy(&psecuritypriv->authenticator_ie[1],
532                         &psecnetwork->IEs[12], psecnetwork->IELength-12);
533         else
534                 memcpy(&psecuritypriv->authenticator_ie[1],
535                         &psecnetwork->IEs[12], (256-1));
536         psecnetwork->IELength = 0;
537         /* If the the driver wants to use the bssid to create the connection.
538          * If not,  we copy the connecting AP's MAC address to it so that
539          * the driver just has the bssid information for PMKIDList searching.
540          */
541         if (pmlmepriv->assoc_by_bssid == false)
542                 memcpy(&pmlmepriv->assoc_bssid[0],
543                         &pnetwork->network.MacAddress[0], ETH_ALEN);
544         psecnetwork->IELength = r8712_restruct_sec_ie(padapter,
545                                                 &pnetwork->network.IEs[0],
546                                                 &psecnetwork->IEs[0],
547                                                 pnetwork->network.IELength);
548         pqospriv->qos_option = 0;
549         if (pregistrypriv->wmm_enable) {
550                 u32 tmp_len;
551
552                 tmp_len = r8712_restruct_wmm_ie(padapter,
553                                           &pnetwork->network.IEs[0],
554                                           &psecnetwork->IEs[0],
555                                           pnetwork->network.IELength,
556                                           psecnetwork->IELength);
557                 if (psecnetwork->IELength != tmp_len) {
558                         psecnetwork->IELength = tmp_len;
559                         pqospriv->qos_option = 1; /* WMM IE in beacon */
560                 } else
561                         pqospriv->qos_option = 0; /* no WMM IE in beacon */
562         }
563         if (pregistrypriv->ht_enable) {
564                 /* For WEP mode, we will use the bg mode to do the connection
565                  * to avoid some IOT issues, especially for Realtek 8192u
566                  * SoftAP.
567                  */
568                 if ((padapter->securitypriv.PrivacyAlgrthm != _WEP40_) &&
569                     (padapter->securitypriv.PrivacyAlgrthm != _WEP104_)) {
570                         /* restructure_ht_ie */
571                         r8712_restructure_ht_ie(padapter,
572                                                 &pnetwork->network.IEs[0],
573                                                 &psecnetwork->IEs[0],
574                                                 pnetwork->network.IELength,
575                                                 &psecnetwork->IELength);
576                 }
577         }
578         psecuritypriv->supplicant_ie[0] = (u8)psecnetwork->IELength;
579         if (psecnetwork->IELength < 255)
580                 memcpy(&psecuritypriv->supplicant_ie[1], &psecnetwork->IEs[0],
581                         psecnetwork->IELength);
582         else
583                 memcpy(&psecuritypriv->supplicant_ie[1], &psecnetwork->IEs[0],
584                         255);
585         /* get cmdsz before endian conversion */
586         pcmd->cmdsz = r8712_get_ndis_wlan_bssid_ex_sz(psecnetwork);
587 #ifdef __BIG_ENDIAN
588         /* wlan_network endian conversion */
589         psecnetwork->Length = cpu_to_le32(psecnetwork->Length);
590         psecnetwork->Ssid.SsidLength = cpu_to_le32(
591                                        psecnetwork->Ssid.SsidLength);
592         psecnetwork->Privacy = cpu_to_le32(psecnetwork->Privacy);
593         psecnetwork->Rssi = cpu_to_le32(psecnetwork->Rssi);
594         psecnetwork->NetworkTypeInUse = cpu_to_le32(
595                                         psecnetwork->NetworkTypeInUse);
596         psecnetwork->Configuration.ATIMWindow = cpu_to_le32(
597                                 psecnetwork->Configuration.ATIMWindow);
598         psecnetwork->Configuration.BeaconPeriod = cpu_to_le32(
599                                  psecnetwork->Configuration.BeaconPeriod);
600         psecnetwork->Configuration.DSConfig = cpu_to_le32(
601                                 psecnetwork->Configuration.DSConfig);
602         psecnetwork->Configuration.FHConfig.DwellTime = cpu_to_le32(
603                                 psecnetwork->Configuration.FHConfig.DwellTime);
604         psecnetwork->Configuration.FHConfig.HopPattern = cpu_to_le32(
605                                 psecnetwork->Configuration.FHConfig.HopPattern);
606         psecnetwork->Configuration.FHConfig.HopSet = cpu_to_le32(
607                                 psecnetwork->Configuration.FHConfig.HopSet);
608         psecnetwork->Configuration.FHConfig.Length = cpu_to_le32(
609                                 psecnetwork->Configuration.FHConfig.Length);
610         psecnetwork->Configuration.Length = cpu_to_le32(
611                                 psecnetwork->Configuration.Length);
612         psecnetwork->InfrastructureMode = cpu_to_le32(
613                                 psecnetwork->InfrastructureMode);
614         psecnetwork->IELength = cpu_to_le32(psecnetwork->IELength);
615 #endif
616         _init_listhead(&pcmd->list);
617         pcmd->cmdcode = _JoinBss_CMD_;
618         pcmd->parmbuf = (unsigned char *)psecnetwork;
619         pcmd->rsp = NULL;
620         pcmd->rspsz = 0;
621         r8712_enqueue_cmd(pcmdpriv, pcmd);
622         return _SUCCESS;
623 }
624
625 u8 r8712_disassoc_cmd(struct _adapter *padapter) /* for sta_mode */
626 {
627         struct cmd_obj *pdisconnect_cmd;
628         struct disconnect_parm *pdisconnect;
629         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
630
631         pdisconnect_cmd = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
632         if (pdisconnect_cmd == NULL)
633                 return _FAIL;
634         pdisconnect = (struct disconnect_parm *)_malloc(
635                       sizeof(struct disconnect_parm));
636         if (pdisconnect == NULL) {
637                 kfree((u8 *)pdisconnect_cmd);
638                 return _FAIL;
639         }
640         init_h2fwcmd_w_parm_no_rsp(pdisconnect_cmd, pdisconnect,
641                                    _DisConnect_CMD_);
642         r8712_enqueue_cmd(pcmdpriv, pdisconnect_cmd);
643         return _SUCCESS;
644 }
645
646 u8 r8712_setopmode_cmd(struct _adapter *padapter,
647                  enum NDIS_802_11_NETWORK_INFRASTRUCTURE networktype)
648 {
649         struct cmd_obj *ph2c;
650         struct setopmode_parm *psetop;
651
652         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
653
654         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
655         if (ph2c == NULL)
656                 return _FAIL;
657         psetop = (struct setopmode_parm *)_malloc(
658                   sizeof(struct setopmode_parm));
659         if (psetop == NULL) {
660                 kfree((u8 *) ph2c);
661                 return _FAIL;
662         }
663         init_h2fwcmd_w_parm_no_rsp(ph2c, psetop, _SetOpMode_CMD_);
664         psetop->mode = (u8)networktype;
665         r8712_enqueue_cmd(pcmdpriv, ph2c);
666         return _SUCCESS;
667 }
668
669 u8 r8712_setstakey_cmd(struct _adapter *padapter, u8 *psta, u8 unicast_key)
670 {
671         struct cmd_obj *ph2c;
672         struct set_stakey_parm *psetstakey_para;
673         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
674         struct set_stakey_rsp *psetstakey_rsp = NULL;
675         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
676         struct security_priv *psecuritypriv = &padapter->securitypriv;
677         struct sta_info *sta = (struct sta_info *)psta;
678
679         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
680         if (ph2c == NULL)
681                 return _FAIL;
682         psetstakey_para = (struct set_stakey_parm *)_malloc(
683                           sizeof(struct set_stakey_parm));
684         if (psetstakey_para == NULL) {
685                 kfree((u8 *) ph2c);
686                 return _FAIL;
687         }
688         psetstakey_rsp = (struct set_stakey_rsp *)_malloc(
689                           sizeof(struct set_stakey_rsp));
690         if (psetstakey_rsp == NULL) {
691                 kfree((u8 *) ph2c);
692                 kfree((u8 *) psetstakey_para);
693                 return _FAIL;
694         }
695         init_h2fwcmd_w_parm_no_rsp(ph2c, psetstakey_para, _SetStaKey_CMD_);
696         ph2c->rsp = (u8 *) psetstakey_rsp;
697         ph2c->rspsz = sizeof(struct set_stakey_rsp);
698         memcpy(psetstakey_para->addr, sta->hwaddr, ETH_ALEN);
699         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE))
700                 psetstakey_para->algorithm = (unsigned char)
701                                             psecuritypriv->PrivacyAlgrthm;
702         else
703                 GET_ENCRY_ALGO(psecuritypriv, sta,
704                                psetstakey_para->algorithm, false);
705         if (unicast_key == true)
706                 memcpy(&psetstakey_para->key, &sta->x_UncstKey, 16);
707         else
708                 memcpy(&psetstakey_para->key,
709                         &psecuritypriv->XGrpKey[
710                         psecuritypriv->XGrpKeyid - 1]. skey, 16);
711         r8712_enqueue_cmd(pcmdpriv, ph2c);
712         return _SUCCESS;
713 }
714
715 u8 r8712_setrfintfs_cmd(struct _adapter *padapter, u8 mode)
716 {
717         struct cmd_obj *ph2c;
718         struct setrfintfs_parm *psetrfintfsparm;
719         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
720
721         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
722         if (ph2c == NULL)
723                 return _FAIL;
724         psetrfintfsparm = (struct setrfintfs_parm *)_malloc(
725                            sizeof(struct setrfintfs_parm));
726         if (psetrfintfsparm == NULL) {
727                 kfree((unsigned char *) ph2c);
728                 return _FAIL;
729         }
730         init_h2fwcmd_w_parm_no_rsp(ph2c, psetrfintfsparm,
731                                    GEN_CMD_CODE(_SetRFIntFs));
732         psetrfintfsparm->rfintfs = mode;
733         r8712_enqueue_cmd(pcmdpriv, ph2c);
734         return _SUCCESS;
735 }
736
737 u8 r8712_setrttbl_cmd(struct _adapter *padapter,
738                       struct setratable_parm *prate_table)
739 {
740         struct cmd_obj *ph2c;
741         struct setratable_parm *psetrttblparm;
742         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
743
744         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
745         if (ph2c == NULL)
746                 return _FAIL;
747         psetrttblparm = (struct setratable_parm *)_malloc(
748                         sizeof(struct setratable_parm));
749         if (psetrttblparm == NULL) {
750                 kfree((unsigned char *)ph2c);
751                 return _FAIL;
752         }
753         init_h2fwcmd_w_parm_no_rsp(ph2c, psetrttblparm,
754                                    GEN_CMD_CODE(_SetRaTable));
755         memcpy(psetrttblparm, prate_table, sizeof(struct setratable_parm));
756         r8712_enqueue_cmd(pcmdpriv, ph2c);
757         return _SUCCESS;
758 }
759
760 u8 r8712_gettssi_cmd(struct _adapter *padapter, u8 offset, u8 *pval)
761 {
762         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
763         struct cmd_obj *ph2c;
764         struct readTSSI_parm *prdtssiparm;
765
766         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
767         if (ph2c == NULL)
768                 return _FAIL;
769         prdtssiparm = (struct readTSSI_parm *)
770                 _malloc(sizeof(struct readTSSI_parm));
771         if (prdtssiparm == NULL) {
772                 kfree((unsigned char *) ph2c);
773                 return _FAIL;
774         }
775         _init_listhead(&ph2c->list);
776         ph2c->cmdcode = GEN_CMD_CODE(_ReadTSSI);
777         ph2c->parmbuf = (unsigned char *)prdtssiparm;
778         ph2c->cmdsz = sizeof(struct readTSSI_parm);
779         ph2c->rsp = pval;
780         ph2c->rspsz = sizeof(struct readTSSI_rsp);
781
782         prdtssiparm->offset = offset;
783         r8712_enqueue_cmd(pcmdpriv, ph2c);
784         return _SUCCESS;
785 }
786
787 u8 r8712_setMacAddr_cmd(struct _adapter *padapter, u8 *mac_addr)
788 {
789         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
790         struct cmd_obj *ph2c;
791         struct SetMacAddr_param *psetMacAddr_para;
792
793         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
794         if (ph2c == NULL)
795                 return _FAIL;
796         psetMacAddr_para = (struct SetMacAddr_param *)_malloc(
797                            sizeof(struct SetMacAddr_param));
798         if (psetMacAddr_para == NULL) {
799                 kfree((u8 *) ph2c);
800                 return _FAIL;
801         }
802         init_h2fwcmd_w_parm_no_rsp(ph2c, psetMacAddr_para,
803                                    _SetMacAddress_CMD_);
804         memcpy(psetMacAddr_para->MacAddr, mac_addr, ETH_ALEN);
805         r8712_enqueue_cmd(pcmdpriv, ph2c);
806         return _SUCCESS;
807 }
808
809 u8 r8712_setassocsta_cmd(struct _adapter *padapter, u8 *mac_addr)
810 {
811         struct cmd_priv                 *pcmdpriv = &padapter->cmdpriv;
812         struct cmd_obj                  *ph2c;
813         struct set_assocsta_parm        *psetassocsta_para;
814         struct set_assocsta_rsp         *psetassocsta_rsp = NULL;
815
816         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
817         if (ph2c == NULL)
818                 return _FAIL;
819         psetassocsta_para = (struct set_assocsta_parm *)
820                             _malloc(sizeof(struct set_assocsta_parm));
821         if (psetassocsta_para == NULL) {
822                 kfree((u8 *) ph2c);
823                 return _FAIL;
824         }
825         psetassocsta_rsp = (struct set_assocsta_rsp *)_malloc(
826                             sizeof(struct set_assocsta_rsp));
827         if (psetassocsta_rsp == NULL) {
828                 kfree((u8 *)ph2c);
829                 kfree((u8 *)psetassocsta_para);
830                 return _FAIL;
831         }
832         init_h2fwcmd_w_parm_no_rsp(ph2c, psetassocsta_para, _SetAssocSta_CMD_);
833         ph2c->rsp = (u8 *) psetassocsta_rsp;
834         ph2c->rspsz = sizeof(struct set_assocsta_rsp);
835         memcpy(psetassocsta_para->addr, mac_addr, ETH_ALEN);
836         r8712_enqueue_cmd(pcmdpriv, ph2c);
837         return _SUCCESS;
838 }
839
840 u8 r8712_addbareq_cmd(struct _adapter *padapter, u8 tid)
841 {
842         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
843         struct cmd_obj          *ph2c;
844         struct addBaReq_parm    *paddbareq_parm;
845
846         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
847         if (ph2c == NULL)
848                 return _FAIL;
849         paddbareq_parm = (struct addBaReq_parm *)_malloc(
850                           sizeof(struct addBaReq_parm));
851         if (paddbareq_parm == NULL) {
852                 kfree((unsigned char *)ph2c);
853                 return _FAIL;
854         }
855         paddbareq_parm->tid = tid;
856         init_h2fwcmd_w_parm_no_rsp(ph2c, paddbareq_parm,
857                                    GEN_CMD_CODE(_AddBAReq));
858         r8712_enqueue_cmd_ex(pcmdpriv, ph2c);
859         return _SUCCESS;
860 }
861
862 u8 r8712_wdg_wk_cmd(struct _adapter *padapter)
863 {
864         struct cmd_obj *ph2c;
865         struct drvint_cmd_parm  *pdrvintcmd_param;
866         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
867
868         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
869         if (ph2c == NULL)
870                 return _FAIL;
871         pdrvintcmd_param = (struct drvint_cmd_parm *)_malloc(
872                            sizeof(struct drvint_cmd_parm));
873         if (pdrvintcmd_param == NULL) {
874                 kfree((unsigned char *)ph2c);
875                 return _FAIL;
876         }
877         pdrvintcmd_param->i_cid = WDG_WK_CID;
878         pdrvintcmd_param->sz = 0;
879         pdrvintcmd_param->pbuf = NULL;
880         init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvintcmd_param, _DRV_INT_CMD_);
881         r8712_enqueue_cmd_ex(pcmdpriv, ph2c);
882         return _SUCCESS;
883 }
884
885 void r8712_survey_cmd_callback(struct _adapter *padapter, struct cmd_obj *pcmd)
886 {
887         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
888
889         if (pcmd->res != H2C_SUCCESS)
890                 clr_fwstate(pmlmepriv, _FW_UNDER_SURVEY);
891         r8712_free_cmd_obj(pcmd);
892 }
893
894 void r8712_disassoc_cmd_callback(struct _adapter *padapter,
895                                  struct cmd_obj *pcmd)
896 {
897         unsigned long irqL;
898         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
899
900         if (pcmd->res != H2C_SUCCESS) {
901                 spin_lock_irqsave(&pmlmepriv->lock, irqL);
902                 set_fwstate(pmlmepriv, _FW_LINKED);
903                 spin_unlock_irqrestore(&pmlmepriv->lock, irqL);
904                 return;
905         }
906         r8712_free_cmd_obj(pcmd);
907 }
908
909 void r8712_joinbss_cmd_callback(struct _adapter *padapter, struct cmd_obj *pcmd)
910 {
911         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
912
913         if (pcmd->res != H2C_SUCCESS)
914                 _set_timer(&pmlmepriv->assoc_timer, 1);
915         r8712_free_cmd_obj(pcmd);
916 }
917
918 void r8712_createbss_cmd_callback(struct _adapter *padapter,
919                                   struct cmd_obj *pcmd)
920 {
921         unsigned long irqL;
922         u8 timer_cancelled;
923         struct sta_info *psta = NULL;
924         struct wlan_network *pwlan = NULL;
925         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
926         struct ndis_wlan_bssid_ex *pnetwork = (struct ndis_wlan_bssid_ex *)
927                                               pcmd->parmbuf;
928         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
929
930         if (pcmd->res != H2C_SUCCESS)
931                 _set_timer(&pmlmepriv->assoc_timer, 1);
932         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
933 #ifdef __BIG_ENDIAN
934         /* endian_convert */
935         pnetwork->Length = le32_to_cpu(pnetwork->Length);
936         pnetwork->Ssid.SsidLength = le32_to_cpu(pnetwork->Ssid.SsidLength);
937         pnetwork->Privacy = le32_to_cpu(pnetwork->Privacy);
938         pnetwork->Rssi = le32_to_cpu(pnetwork->Rssi);
939         pnetwork->NetworkTypeInUse = le32_to_cpu(pnetwork->NetworkTypeInUse);
940         pnetwork->Configuration.ATIMWindow = le32_to_cpu(pnetwork->
941                                         Configuration.ATIMWindow);
942         pnetwork->Configuration.DSConfig = le32_to_cpu(pnetwork->
943                                         Configuration.DSConfig);
944         pnetwork->Configuration.FHConfig.DwellTime = le32_to_cpu(pnetwork->
945                                         Configuration.FHConfig.DwellTime);
946         pnetwork->Configuration.FHConfig.HopPattern = le32_to_cpu(pnetwork->
947                                         Configuration.FHConfig.HopPattern);
948         pnetwork->Configuration.FHConfig.HopSet = le32_to_cpu(pnetwork->
949                                         Configuration.FHConfig.HopSet);
950         pnetwork->Configuration.FHConfig.Length = le32_to_cpu(pnetwork->
951                                         Configuration.FHConfig.Length);
952         pnetwork->Configuration.Length = le32_to_cpu(pnetwork->
953                                         Configuration.Length);
954         pnetwork->InfrastructureMode = le32_to_cpu(pnetwork->
955                                            InfrastructureMode);
956         pnetwork->IELength = le32_to_cpu(pnetwork->IELength);
957 #endif
958         spin_lock_irqsave(&pmlmepriv->lock, irqL);
959         if ((pmlmepriv->fw_state) & WIFI_AP_STATE) {
960                 psta = r8712_get_stainfo(&padapter->stapriv,
961                                          pnetwork->MacAddress);
962                 if (!psta) {
963                         psta = r8712_alloc_stainfo(&padapter->stapriv,
964                                                    pnetwork->MacAddress);
965                         if (psta == NULL)
966                                 goto createbss_cmd_fail;
967                 }
968                 r8712_indicate_connect(padapter);
969         } else {
970                 pwlan = _r8712_alloc_network(pmlmepriv);
971                 if (pwlan == NULL) {
972                         pwlan = r8712_get_oldest_wlan_network(
973                                 &pmlmepriv->scanned_queue);
974                         if (pwlan == NULL)
975                                 goto createbss_cmd_fail;
976                         pwlan->last_scanned = jiffies;
977                 } else
978                         list_insert_tail(&(pwlan->list),
979                                          &pmlmepriv->scanned_queue.queue);
980                 pnetwork->Length = r8712_get_ndis_wlan_bssid_ex_sz(pnetwork);
981                 memcpy(&(pwlan->network), pnetwork, pnetwork->Length);
982                 pwlan->fixed = true;
983                 memcpy(&tgt_network->network, pnetwork,
984                         (r8712_get_ndis_wlan_bssid_ex_sz(pnetwork)));
985                 if (pmlmepriv->fw_state & _FW_UNDER_LINKING)
986                         pmlmepriv->fw_state ^= _FW_UNDER_LINKING;
987                 /* we will set _FW_LINKED when there is one more sat to
988                  * join us (stassoc_event_callback) */
989         }
990 createbss_cmd_fail:
991         spin_unlock_irqrestore(&pmlmepriv->lock, irqL);
992         r8712_free_cmd_obj(pcmd);
993 }
994
995 void r8712_setstaKey_cmdrsp_callback(struct _adapter *padapter,
996                                      struct cmd_obj *pcmd)
997 {
998         struct sta_priv *pstapriv = &padapter->stapriv;
999         struct set_stakey_rsp *psetstakey_rsp = (struct set_stakey_rsp *)
1000                                                 (pcmd->rsp);
1001         struct sta_info *psta = r8712_get_stainfo(pstapriv,
1002                                                   psetstakey_rsp->addr);
1003
1004         if (psta == NULL)
1005                 goto exit;
1006         psta->aid = psta->mac_id = psetstakey_rsp->keyid; /*CAM_ID(CAM_ENTRY)*/
1007 exit:
1008         r8712_free_cmd_obj(pcmd);
1009 }
1010
1011 void r8712_setassocsta_cmdrsp_callback(struct _adapter *padapter,
1012                                        struct cmd_obj *pcmd)
1013 {
1014         unsigned long   irqL;
1015         struct sta_priv *pstapriv = &padapter->stapriv;
1016         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1017         struct set_assocsta_parm *passocsta_parm =
1018                                 (struct set_assocsta_parm *)(pcmd->parmbuf);
1019         struct set_assocsta_rsp *passocsta_rsp =
1020                                 (struct set_assocsta_rsp *) (pcmd->rsp);
1021         struct sta_info *psta = r8712_get_stainfo(pstapriv,
1022                                                   passocsta_parm->addr);
1023
1024         if (psta == NULL)
1025                 return;
1026         psta->aid = psta->mac_id = passocsta_rsp->cam_id;
1027         spin_lock_irqsave(&pmlmepriv->lock, irqL);
1028         if ((check_fwstate(pmlmepriv, WIFI_MP_STATE)) &&
1029             (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)))
1030                 pmlmepriv->fw_state ^= _FW_UNDER_LINKING;
1031         set_fwstate(pmlmepriv, _FW_LINKED);
1032         spin_unlock_irqrestore(&pmlmepriv->lock, irqL);
1033         r8712_free_cmd_obj(pcmd);
1034 }
1035
1036 u8 r8712_disconnectCtrlEx_cmd(struct _adapter *adapter, u32 enableDrvCtrl,
1037                         u32 tryPktCnt, u32 tryPktInterval, u32 firstStageTO)
1038 {
1039         struct cmd_obj *ph2c;
1040         struct DisconnectCtrlEx_param *param;
1041         struct cmd_priv *pcmdpriv = &adapter->cmdpriv;
1042
1043         ph2c = (struct cmd_obj *)_malloc(sizeof(struct cmd_obj));
1044         if (ph2c == NULL)
1045                 return _FAIL;
1046         param = (struct DisconnectCtrlEx_param *)
1047                 _malloc(sizeof(struct DisconnectCtrlEx_param));
1048         if (param == NULL) {
1049                 kfree((unsigned char *) ph2c);
1050                 return _FAIL;
1051         }
1052         memset(param, 0, sizeof(struct DisconnectCtrlEx_param));
1053
1054         param->EnableDrvCtrl = (unsigned char)enableDrvCtrl;
1055         param->TryPktCnt = (unsigned char)tryPktCnt;
1056         param->TryPktInterval = (unsigned char)tryPktInterval;
1057         param->FirstStageTO = (unsigned int)firstStageTO;
1058
1059         init_h2fwcmd_w_parm_no_rsp(ph2c, param,
1060                                 GEN_CMD_CODE(_DisconnectCtrlEx));
1061         r8712_enqueue_cmd(pcmdpriv, ph2c);
1062         return _SUCCESS;
1063 }