]> git.kernelconcepts.de Git - karo-tx-linux.git/blob - drivers/staging/rtl8188eu/core/rtw_mlme.c
Merge tag 'sound-fix-4.13-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/tiwai...
[karo-tx-linux.git] / drivers / staging / rtl8188eu / core / rtw_mlme.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  ******************************************************************************/
15 #define _RTW_MLME_C_
16
17 #include <linux/ieee80211.h>
18
19 #include <osdep_service.h>
20 #include <drv_types.h>
21 #include <recv_osdep.h>
22 #include <xmit_osdep.h>
23 #include <hal_intf.h>
24 #include <mlme_osdep.h>
25 #include <sta_info.h>
26 #include <wifi.h>
27 #include <wlan_bssdef.h>
28 #include <rtw_ioctl_set.h>
29 #include <linux/vmalloc.h>
30
31 extern unsigned char    MCS_rate_1R[16];
32
33 int rtw_init_mlme_priv(struct adapter *padapter)
34 {
35         int     i;
36         u8      *pbuf;
37         struct wlan_network     *pnetwork;
38         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
39         int     res = _SUCCESS;
40
41         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by vzalloc(). */
42
43         pmlmepriv->nic_hdl = (u8 *)padapter;
44
45         pmlmepriv->pscanned = NULL;
46         pmlmepriv->fw_state = 0;
47         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
48         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
49
50         spin_lock_init(&(pmlmepriv->lock));
51         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
52         _rtw_init_queue(&(pmlmepriv->scanned_queue));
53
54         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
55
56         pbuf = vzalloc(MAX_BSS_CNT * (sizeof(struct wlan_network)));
57
58         if (!pbuf) {
59                 res = _FAIL;
60                 goto exit;
61         }
62         pmlmepriv->free_bss_buf = pbuf;
63
64         pnetwork = (struct wlan_network *)pbuf;
65
66         for (i = 0; i < MAX_BSS_CNT; i++) {
67                 INIT_LIST_HEAD(&(pnetwork->list));
68
69                 list_add_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
70
71                 pnetwork++;
72         }
73
74         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
75
76         rtw_clear_scan_deny(padapter);
77
78         rtw_init_mlme_timer(padapter);
79
80 exit:
81         return res;
82 }
83
84 #if defined(CONFIG_88EU_AP_MODE)
85 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
86 {
87         kfree(*ppie);
88         *plen = 0;
89         *ppie = NULL;
90 }
91
92 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
93 {
94         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
95         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
96         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
97         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
98         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
99         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
100 }
101 #else
102 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
103 {
104 }
105 #endif
106
107 void rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
108 {
109         rtw_free_mlme_priv_ie_data(pmlmepriv);
110
111         if (pmlmepriv)
112                 vfree(pmlmepriv->free_bss_buf);
113 }
114
115 struct wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)
116                                         /* _queue *free_queue) */
117 {
118         struct wlan_network *pnetwork;
119         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
120
121         spin_lock_bh(&free_queue->lock);
122         pnetwork = list_first_entry_or_null(&free_queue->queue,
123                                             struct wlan_network, list);
124         if (!pnetwork)
125                 goto exit;
126
127         list_del_init(&pnetwork->list);
128
129         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
130                  ("_rtw_alloc_network: ptr=%p\n", &pnetwork->list));
131         pnetwork->network_type = 0;
132         pnetwork->fixed = false;
133         pnetwork->last_scanned = jiffies;
134         pnetwork->aid = 0;
135         pnetwork->join_res = 0;
136
137 exit:
138         spin_unlock_bh(&free_queue->lock);
139
140         return pnetwork;
141 }
142
143 static void _rtw_free_network(struct mlme_priv *pmlmepriv, struct wlan_network *pnetwork, u8 isfreeall)
144 {
145         unsigned long curr_time;
146         u32 delta_time;
147         u32 lifetime = SCANQUEUE_LIFETIME;
148         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
149
150         if (!pnetwork)
151                 return;
152
153         if (pnetwork->fixed)
154                 return;
155         curr_time = jiffies;
156         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
157             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)))
158                 lifetime = 1;
159         if (!isfreeall) {
160                 delta_time = (curr_time - pnetwork->last_scanned)/HZ;
161                 if (delta_time < lifetime)/*  unit:sec */
162                         return;
163         }
164         spin_lock_bh(&free_queue->lock);
165         list_del_init(&(pnetwork->list));
166         list_add_tail(&(pnetwork->list), &(free_queue->queue));
167         spin_unlock_bh(&free_queue->lock);
168 }
169
170 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
171 {
172         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
173
174         if (!pnetwork)
175                 return;
176         if (pnetwork->fixed)
177                 return;
178         list_del_init(&(pnetwork->list));
179         list_add_tail(&(pnetwork->list), get_list_head(free_queue));
180 }
181
182 /*
183  * return the wlan_network with the matching addr
184  *
185  * Shall be called under atomic context... to avoid possible racing condition...
186  */
187 struct wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
188 {
189         struct list_head *phead, *plist;
190         struct  wlan_network *pnetwork = NULL;
191         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
192
193         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
194                 pnetwork = NULL;
195                 goto exit;
196         }
197         phead = get_list_head(scanned_queue);
198         plist = phead->next;
199
200         while (plist != phead) {
201                 pnetwork = container_of(plist, struct wlan_network, list);
202                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
203                         break;
204                 plist = plist->next;
205         }
206         if (plist == phead)
207                 pnetwork = NULL;
208 exit:
209         return pnetwork;
210 }
211
212
213 void rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
214 {
215         struct list_head *phead, *plist;
216         struct wlan_network *pnetwork;
217         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
218         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
219
220         spin_lock_bh(&scanned_queue->lock);
221
222         phead = get_list_head(scanned_queue);
223         plist = phead->next;
224
225         while (phead != plist) {
226                 pnetwork = container_of(plist, struct wlan_network, list);
227
228                 plist = plist->next;
229
230                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
231         }
232         spin_unlock_bh(&scanned_queue->lock);
233 }
234
235 int rtw_if_up(struct adapter *padapter)
236 {
237         int res;
238
239         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
240             (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
241                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
242                          ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)",
243                          padapter->bDriverStopped, padapter->bSurpriseRemoved));
244                 res = false;
245         } else {
246                 res =  true;
247         }
248         return res;
249 }
250
251 void rtw_generate_random_ibss(u8 *pibss)
252 {
253         unsigned long curtime = jiffies;
254
255         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
256         pibss[1] = 0x11;
257         pibss[2] = 0x87;
258         pibss[3] = (u8)(curtime & 0xff);/* p[0]; */
259         pibss[4] = (u8)((curtime>>8) & 0xff);/* p[1]; */
260         pibss[5] = (u8)((curtime>>16) & 0xff);/* p[2]; */
261 }
262
263 u8 *rtw_get_capability_from_ie(u8 *ie)
264 {
265         return ie + 8 + 2;
266 }
267
268
269 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
270 {
271         __le16  val;
272
273         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2);
274
275         return le16_to_cpu(val);
276 }
277
278 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
279 {
280         return ie + 8;
281 }
282
283 static struct wlan_network *rtw_alloc_network(struct mlme_priv *pmlmepriv)
284 {
285         return _rtw_alloc_network(pmlmepriv);
286 }
287
288 static void rtw_free_network_nolock(struct mlme_priv *pmlmepriv,
289                                     struct wlan_network *pnetwork)
290 {
291         _rtw_free_network_nolock(pmlmepriv, pnetwork);
292 }
293
294 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
295 {
296         int ret = true;
297         struct security_priv *psecuritypriv = &adapter->securitypriv;
298
299         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
300             (pnetwork->network.Privacy == 0))
301                 ret = false;
302         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
303                  (pnetwork->network.Privacy == 1))
304                 ret = false;
305         else
306                 ret = true;
307         return ret;
308 }
309
310 static int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
311 {
312         return (a->Ssid.SsidLength == b->Ssid.SsidLength) &&
313                !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
314 }
315
316 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst)
317 {
318          u16 s_cap, d_cap;
319         __le16 le_scap, le_dcap;
320
321         memcpy((u8 *)&le_scap, rtw_get_capability_from_ie(src->IEs), 2);
322         memcpy((u8 *)&le_dcap, rtw_get_capability_from_ie(dst->IEs), 2);
323
324         s_cap = le16_to_cpu(le_scap);
325         d_cap = le16_to_cpu(le_dcap);
326
327         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
328                 ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN)) == true) &&
329                 ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength)) == true) &&
330                 ((s_cap & WLAN_CAPABILITY_IBSS) ==
331                 (d_cap & WLAN_CAPABILITY_IBSS)) &&
332                 ((s_cap & WLAN_CAPABILITY_ESS) ==
333                 (d_cap & WLAN_CAPABILITY_ESS)));
334 }
335
336 struct  wlan_network    *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
337 {
338         struct list_head *plist, *phead;
339         struct  wlan_network    *pwlan = NULL;
340         struct  wlan_network    *oldest = NULL;
341
342         phead = get_list_head(scanned_queue);
343
344         for (plist = phead->next; plist != phead; plist = plist->next) {
345                 pwlan = container_of(plist, struct wlan_network, list);
346
347                 if (!pwlan->fixed) {
348                         if (!oldest || time_after(oldest->last_scanned, pwlan->last_scanned))
349                                 oldest = pwlan;
350                 }
351         }
352         return oldest;
353 }
354
355 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
356         struct adapter *padapter, bool update_ie)
357 {
358         long rssi_ori = dst->Rssi;
359         u8 sq_smp = src->PhyInfo.SignalQuality;
360         u8 ss_final;
361         u8 sq_final;
362         long rssi_final;
363
364         rtw_hal_antdiv_rssi_compared(padapter, dst, src); /* this will update src.Rssi, need consider again */
365
366         /* The rule below is 1/5 for sample value, 4/5 for history value */
367         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src)) {
368                 /* Take the recvpriv's value for the connected AP*/
369                 ss_final = padapter->recvpriv.signal_strength;
370                 sq_final = padapter->recvpriv.signal_qual;
371                 /* the rssi value here is undecorated, and will be used for antenna diversity */
372                 if (sq_smp != 101) /* from the right channel */
373                         rssi_final = (src->Rssi + dst->Rssi * 4) / 5;
374                 else
375                         rssi_final = rssi_ori;
376         } else {
377                 if (sq_smp != 101) { /* from the right channel */
378                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
379                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
380                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
381                 } else {
382                         /* bss info not receiving from the right channel, use the original RX signal infos */
383                         ss_final = dst->PhyInfo.SignalStrength;
384                         sq_final = dst->PhyInfo.SignalQuality;
385                         rssi_final = dst->Rssi;
386                 }
387         }
388         if (update_ie)
389                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
390         dst->PhyInfo.SignalStrength = ss_final;
391         dst->PhyInfo.SignalQuality = sq_final;
392         dst->Rssi = rssi_final;
393 }
394
395 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
396 {
397         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
398
399         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) &&
400             (is_same_network(&(pmlmepriv->cur_network.network), pnetwork))) {
401                 update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
402                 rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof(struct ndis_802_11_fixed_ie),
403                                       pmlmepriv->cur_network.network.IELength);
404         }
405 }
406
407 /*
408  * Caller must hold pmlmepriv->lock first.
409  */
410 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
411 {
412         struct list_head *plist, *phead;
413         u32     bssid_ex_sz;
414         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
415         struct __queue *queue   = &(pmlmepriv->scanned_queue);
416         struct wlan_network     *pnetwork = NULL;
417         struct wlan_network     *oldest = NULL;
418
419         spin_lock_bh(&queue->lock);
420         phead = get_list_head(queue);
421         plist = phead->next;
422
423         while (phead != plist) {
424                 pnetwork        = container_of(plist, struct wlan_network, list);
425
426                 if (is_same_network(&(pnetwork->network), target))
427                         break;
428                 if ((oldest == ((struct wlan_network *)0)) ||
429                     time_after(oldest->last_scanned, pnetwork->last_scanned))
430                         oldest = pnetwork;
431                 plist = plist->next;
432         }
433         /* If we didn't find a match, then get a new network slot to initialize
434          * with this beacon's information
435          */
436         if (phead == plist) {
437                 if (list_empty(&(pmlmepriv->free_bss_pool.queue))) {
438                         /* If there are no more slots, expire the oldest */
439                         pnetwork = oldest;
440
441                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
442                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
443                         /*  variable initialize */
444                         pnetwork->fixed = false;
445                         pnetwork->last_scanned = jiffies;
446
447                         pnetwork->network_type = 0;
448                         pnetwork->aid = 0;
449                         pnetwork->join_res = 0;
450
451                         /* bss info not receiving from the right channel */
452                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
453                                 pnetwork->network.PhyInfo.SignalQuality = 0;
454                 } else {
455                         /* Otherwise just pull from the free list */
456
457                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
458
459                         if (!pnetwork) {
460                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
461                                 goto exit;
462                         }
463
464                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
465                         target->Length = bssid_ex_sz;
466                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
467                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
468
469                         pnetwork->last_scanned = jiffies;
470
471                         /* bss info not receiving from the right channel */
472                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
473                                 pnetwork->network.PhyInfo.SignalQuality = 0;
474                         list_add_tail(&(pnetwork->list), &(queue->queue));
475                 }
476         } else {
477                 /* we have an entry and we are going to update it. But this entry may
478                  * be already expired. In this case we do the same as we found a new
479                  * net and call the new_net handler
480                  */
481                 bool update_ie = true;
482
483                 pnetwork->last_scanned = jiffies;
484
485                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
486                 if ((pnetwork->network.IELength > target->IELength) && (target->Reserved[0] == 1))
487                         update_ie = false;
488
489                 update_network(&(pnetwork->network), target, adapter, update_ie);
490         }
491
492 exit:
493         spin_unlock_bh(&queue->lock);
494 }
495
496 static void rtw_add_network(struct adapter *adapter,
497                             struct wlan_bssid_ex *pnetwork)
498 {
499         update_current_network(adapter, pnetwork);
500         rtw_update_scanned_network(adapter, pnetwork);
501 }
502
503 /*
504  * select the desired network based on the capability of the (i)bss.
505  * check items: (1) security
506  *                      (2) network_type
507  *                      (3) WMM
508  *                      (4) HT
509  *                      (5) others
510  */
511 static int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
512 {
513         struct security_priv *psecuritypriv = &adapter->securitypriv;
514         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
515         u32 desired_encmode;
516         u32 privacy;
517
518         /* u8 wps_ie[512]; */
519         uint wps_ielen;
520
521         int bselected = true;
522
523         desired_encmode = psecuritypriv->ndisencryptstatus;
524         privacy = pnetwork->network.Privacy;
525
526         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
527                 if (rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen))
528                         return true;
529                 else
530                         return false;
531         }
532         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
533                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
534                         bselected = false;
535         }
536
537
538         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
539                 DBG_88E("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
540                 bselected = false;
541         }
542
543         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
544                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
545                         bselected = false;
546         }
547
548         return bselected;
549 }
550
551 /* TODO: Perry: For Power Management */
552 void rtw_atimdone_event_callback(struct adapter *adapter, u8 *pbuf)
553 {
554         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_evet\n"));
555 }
556
557 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
558 {
559         u32 len;
560         struct wlan_bssid_ex *pnetwork;
561         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
562
563         pnetwork = (struct wlan_bssid_ex *)pbuf;
564
565         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid=%s\n",  pnetwork->Ssid.Ssid));
566
567         len = get_wlan_bssid_ex_sz(pnetwork);
568         if (len > (sizeof(struct wlan_bssid_ex))) {
569                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n****rtw_survey_event_callback: return a wrong bss ***\n"));
570                 return;
571         }
572         spin_lock_bh(&pmlmepriv->lock);
573
574         /*  update IBSS_network 's timestamp */
575         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) {
576                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN)) {
577                         struct wlan_network *ibss_wlan = NULL;
578
579                         memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
580                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
581                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
582                         if (ibss_wlan) {
583                                 memcpy(ibss_wlan->network.IEs, pnetwork->IEs, 8);
584                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
585                                 goto exit;
586                         }
587                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
588                 }
589         }
590
591         /*  lock pmlmepriv->lock when you accessing network_q */
592         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false) {
593                 if (pnetwork->Ssid.Ssid[0] == 0)
594                         pnetwork->Ssid.SsidLength = 0;
595                 rtw_add_network(adapter, pnetwork);
596         }
597
598 exit:
599
600         spin_unlock_bh(&pmlmepriv->lock);
601         return;
602 }
603
604 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
605 {
606         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
607
608         spin_lock_bh(&pmlmepriv->lock);
609
610         if (pmlmepriv->wps_probe_req_ie) {
611                 pmlmepriv->wps_probe_req_ie_len = 0;
612                 kfree(pmlmepriv->wps_probe_req_ie);
613                 pmlmepriv->wps_probe_req_ie = NULL;
614         }
615
616         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
617
618         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
619                 del_timer_sync(&pmlmepriv->scan_to_timer);
620                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
621         } else {
622                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status=%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
623         }
624
625         rtw_set_signal_stat_timer(&adapter->recvpriv);
626
627         if (pmlmepriv->to_join) {
628                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
629                         if (check_fwstate(pmlmepriv, _FW_LINKED) == false) {
630                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
631
632                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
633                                         mod_timer(&pmlmepriv->assoc_timer,
634                                                   jiffies + msecs_to_jiffies(MAX_JOIN_TIMEOUT));
635                                 } else {
636                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
637                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
638
639                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
640
641                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
642
643                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
644
645                                         rtw_update_registrypriv_dev_network(adapter);
646                                         rtw_generate_random_ibss(pibss);
647
648                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
649
650                                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
651                                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error=>rtw_createbss_cmd status FAIL\n"));
652                                         pmlmepriv->to_join = false;
653                                 }
654                         }
655                 } else {
656                         int s_ret;
657
658                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
659                         pmlmepriv->to_join = false;
660                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
661                         if (s_ret == _SUCCESS) {
662                                 mod_timer(&pmlmepriv->assoc_timer,
663                                         jiffies + msecs_to_jiffies(MAX_JOIN_TIMEOUT));
664                         } else if (s_ret == 2) { /* there is no need to wait for join */
665                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
666                                 rtw_indicate_connect(adapter);
667                         } else {
668                                 DBG_88E("try_to_join, but select scanning queue fail, to_roaming:%d\n", pmlmepriv->to_roaming);
669                                 if (pmlmepriv->to_roaming != 0) {
670                                         if (--pmlmepriv->to_roaming == 0 ||
671                                             rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0) != _SUCCESS) {
672                                                 pmlmepriv->to_roaming = 0;
673                                                 rtw_free_assoc_resources(adapter);
674                                                 rtw_indicate_disconnect(adapter);
675                                         } else {
676                                                 pmlmepriv->to_join = true;
677                                         }
678                                 }
679                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
680                         }
681                 }
682         }
683
684         indicate_wx_scan_complete_event(adapter);
685
686         spin_unlock_bh(&pmlmepriv->lock);
687
688         rtw_os_xmit_schedule(adapter);
689 }
690
691 void rtw_dummy_event_callback(struct adapter *adapter, u8 *pbuf)
692 {
693 }
694
695 void rtw_fwdbg_event_callback(struct adapter *adapter, u8 *pbuf)
696 {
697 }
698
699 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
700 {
701         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
702         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
703         struct list_head *plist, *phead, *ptemp;
704
705         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
706         spin_lock_bh(&scan_queue->lock);
707         spin_lock_bh(&free_queue->lock);
708
709         phead = get_list_head(scan_queue);
710         plist = phead->next;
711
712         while (plist != phead) {
713                 ptemp = plist->next;
714                 list_del_init(plist);
715                 list_add_tail(plist, &free_queue->queue);
716                 plist = ptemp;
717         }
718
719         spin_unlock_bh(&free_queue->lock);
720         spin_unlock_bh(&scan_queue->lock);
721 }
722
723 /*
724  * rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
725  */
726 void rtw_free_assoc_resources(struct adapter *adapter)
727 {
728         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
729
730         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
731         rtw_free_assoc_resources_locked(adapter);
732         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
733 }
734
735 /*
736  * rtw_free_assoc_resources_locked: the caller has to lock pmlmepriv->lock
737  */
738 void rtw_free_assoc_resources_locked(struct adapter *adapter)
739 {
740         struct wlan_network *pwlan = NULL;
741         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
742         struct  sta_priv *pstapriv = &adapter->stapriv;
743         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
744
745         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
746         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
747                  ("tgt_network->network.MacAddress=%pM ssid=%s\n",
748                  tgt_network->network.MacAddress, tgt_network->network.Ssid.Ssid));
749
750         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_AP_STATE)) {
751                 struct sta_info *psta;
752
753                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
754
755                 spin_lock_bh(&(pstapriv->sta_hash_lock));
756                 rtw_free_stainfo(adapter,  psta);
757                 spin_unlock_bh(&pstapriv->sta_hash_lock);
758         }
759
760         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE | WIFI_ADHOC_MASTER_STATE | WIFI_AP_STATE)) {
761                 struct sta_info *psta;
762
763                 rtw_free_all_stainfo(adapter);
764
765                 psta = rtw_get_bcmc_stainfo(adapter);
766                 spin_lock_bh(&(pstapriv->sta_hash_lock));
767                 rtw_free_stainfo(adapter, psta);
768                 spin_unlock_bh(&pstapriv->sta_hash_lock);
769
770                 rtw_init_bcmc_stainfo(adapter);
771         }
772
773
774         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
775         if (pwlan)
776                 pwlan->fixed = false;
777         else
778                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources:pwlan==NULL\n\n"));
779
780         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) && (adapter->stapriv.asoc_sta_count == 1)))
781                 rtw_free_network_nolock(pmlmepriv, pwlan);
782
783         pmlmepriv->key_mask = 0;
784 }
785
786 /*
787  * rtw_indicate_connect: the caller has to lock pmlmepriv->lock
788  */
789 void rtw_indicate_connect(struct adapter *padapter)
790 {
791         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
792
793         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
794
795         pmlmepriv->to_join = false;
796
797         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
798                 set_fwstate(pmlmepriv, _FW_LINKED);
799
800                 LedControl8188eu(padapter, LED_CTL_LINK);
801
802                 rtw_os_indicate_connect(padapter);
803         }
804
805         pmlmepriv->to_roaming = 0;
806
807         rtw_set_scan_deny(padapter, 3000);
808
809         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state=0x%08x\n", get_fwstate(pmlmepriv)));
810 }
811
812 /*
813  * rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
814  */
815 void rtw_indicate_disconnect(struct adapter *padapter)
816 {
817         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
818
819         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
820
821         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING | WIFI_UNDER_WPS);
822
823         if (pmlmepriv->to_roaming > 0)
824                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
825
826         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) ||
827             (pmlmepriv->to_roaming <= 0)) {
828                 rtw_os_indicate_disconnect(padapter);
829
830                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
831                 LedControl8188eu(padapter, LED_CTL_NO_LINK);
832                 rtw_clear_scan_deny(padapter);
833         }
834
835         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
836 }
837
838 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
839 {
840         rtw_os_indicate_scan_done(padapter, aborted);
841 }
842
843 void rtw_scan_abort(struct adapter *adapter)
844 {
845         unsigned long start;
846         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
847         struct mlme_ext_priv    *pmlmeext = &(adapter->mlmeextpriv);
848
849         start = jiffies;
850         pmlmeext->scan_abort = true;
851         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY) &&
852                jiffies_to_msecs(jiffies - start) <= 200) {
853                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
854                         break;
855                 DBG_88E(FUNC_NDEV_FMT"fw_state=_FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
856                 msleep(20);
857         }
858         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
859                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
860                         DBG_88E(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
861                 rtw_indicate_scan_done(adapter, true);
862         }
863         pmlmeext->scan_abort = false;
864 }
865
866 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
867 {
868         int i;
869         struct sta_info *bmc_sta, *psta = NULL;
870         struct recv_reorder_ctrl *preorder_ctrl;
871         struct sta_priv *pstapriv = &padapter->stapriv;
872
873         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
874         if (!psta)
875                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
876
877         if (psta) { /* update ptarget_sta */
878                 DBG_88E("%s\n", __func__);
879                 psta->aid  = pnetwork->join_res;
880                         psta->mac_id = 0;
881                 /* sta mode */
882                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
883                 /* security related */
884                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
885                         padapter->securitypriv.binstallGrpkey = false;
886                         padapter->securitypriv.busetkipkey = false;
887                         padapter->securitypriv.bgrpkey_handshake = false;
888                         psta->ieee8021x_blocked = true;
889                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
890                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
891                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
892                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
893                         memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
894                         memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
895                 }
896                 /*
897                  * Commented by Albert 2012/07/21
898                  * When doing the WPS, the wps_ie_len won't equal to 0
899                  * And the Wi-Fi driver shouldn't allow the data
900                  * packet to be tramsmitted.
901                  */
902                 if (padapter->securitypriv.wps_ie_len != 0) {
903                         psta->ieee8021x_blocked = true;
904                         padapter->securitypriv.wps_ie_len = 0;
905                 }
906                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
907                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
908                 /* todo: check if AP can send A-MPDU packets */
909                 for (i = 0; i < 16; i++) {
910                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
911                         preorder_ctrl = &psta->recvreorder_ctrl[i];
912                         preorder_ctrl->enable = false;
913                         preorder_ctrl->indicate_seq = 0xffff;
914                         preorder_ctrl->wend_b = 0xffff;
915                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
916                 }
917                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
918                 if (bmc_sta) {
919                         for (i = 0; i < 16; i++) {
920                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
921                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
922                                 preorder_ctrl->enable = false;
923                                 preorder_ctrl->indicate_seq = 0xffff;
924                                 preorder_ctrl->wend_b = 0xffff;
925                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
926                         }
927                 }
928                 /* misc. */
929                 update_sta_info(padapter, psta);
930         }
931         return psta;
932 }
933
934 /* pnetwork: returns from rtw_joinbss_event_callback */
935 /* ptarget_wlan: found from scanned_queue */
936 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
937 {
938         struct mlme_priv        *pmlmepriv = &(padapter->mlmepriv);
939         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
940
941         DBG_88E("%s\n", __func__);
942
943         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
944                  ("\nfw_state:%x, BSSID:%pM\n",
945                  get_fwstate(pmlmepriv), pnetwork->network.MacAddress));
946
947
948         /*  why not use ptarget_wlan?? */
949         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
950         /*  some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs */
951         cur_network->network.IELength = ptarget_wlan->network.IELength;
952         memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
953
954         cur_network->aid = pnetwork->join_res;
955
956         rtw_set_signal_stat_timer(&padapter->recvpriv);
957         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
958         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
959         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
960         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
961         rtw_set_signal_stat_timer(&padapter->recvpriv);
962
963         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
964         switch (pnetwork->network.InfrastructureMode) {
965         case Ndis802_11Infrastructure:
966                 if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
967                         pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
968                 else
969                         pmlmepriv->fw_state = WIFI_STATION_STATE;
970                 break;
971         case Ndis802_11IBSS:
972                 pmlmepriv->fw_state = WIFI_ADHOC_STATE;
973                 break;
974         default:
975                 pmlmepriv->fw_state = WIFI_NULL_STATE;
976                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
977                 break;
978         }
979
980         rtw_update_protection(padapter, (cur_network->network.IEs) +
981                               sizeof(struct ndis_802_11_fixed_ie),
982                               (cur_network->network.IELength));
983         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength);
984 }
985
986 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
987 /* pnetwork: returns from rtw_joinbss_event_callback */
988 /* ptarget_wlan: found from scanned_queue */
989 /* if join_res > 0, for (fw_state == WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
990 /* if join_res > 0, for (fw_state == WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
991 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
992
993 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
994 {
995         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
996         struct  sta_priv *pstapriv = &adapter->stapriv;
997         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
998         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
999         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1000         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1001         unsigned int            the_same_macaddr = false;
1002
1003         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res=%d\n", pnetwork->join_res));
1004
1005         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1006
1007         if (pmlmepriv->assoc_ssid.SsidLength == 0)
1008                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
1009         else
1010                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
1011
1012         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1013
1014         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1015         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
1016                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1017                 return;
1018         }
1019
1020         spin_lock_bh(&pmlmepriv->lock);
1021
1022         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nrtw_joinbss_event_callback!! _enter_critical\n"));
1023
1024         if (pnetwork->join_res > 0) {
1025                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1026                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1027                         /* s1. find ptarget_wlan */
1028                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1029                                 if (the_same_macaddr) {
1030                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1031                                 } else {
1032                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1033                                         if (pcur_wlan)
1034                                                 pcur_wlan->fixed = false;
1035
1036                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1037                                         if (pcur_sta) {
1038                                                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1039                                                 rtw_free_stainfo(adapter,  pcur_sta);
1040                                                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1041                                         }
1042
1043                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1044                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1045                                                 if (ptarget_wlan)
1046                                                         ptarget_wlan->fixed = true;
1047                                         }
1048                                 }
1049                         } else {
1050                                 ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1051                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1052                                         if (ptarget_wlan)
1053                                                 ptarget_wlan->fixed = true;
1054                                 }
1055                         }
1056
1057                         /* s2. update cur_network */
1058                         if (ptarget_wlan) {
1059                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1060                         } else {
1061                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't find ptarget_wlan when joinbss_event callback\n"));
1062                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1063                                 goto ignore_joinbss_callback;
1064                         }
1065
1066                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1067                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1068                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1069                                 if (!ptarget_sta) {
1070                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1071                                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1072                                         goto ignore_joinbss_callback;
1073                                 }
1074                         }
1075
1076                         /* s4. indicate connect */
1077                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1078                                         rtw_indicate_connect(adapter);
1079                                 } else {
1080                                         /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1081                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1082                                 }
1083
1084                         /* s5. Cancel assoc_timer */
1085                         del_timer_sync(&pmlmepriv->assoc_timer);
1086
1087                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancel assoc_timer\n"));
1088
1089                 } else {
1090                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1091                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1092                         goto ignore_joinbss_callback;
1093                 }
1094
1095                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1096
1097         } else if (pnetwork->join_res == -4) {
1098                 rtw_reset_securitypriv(adapter);
1099                 mod_timer(&pmlmepriv->assoc_timer,
1100                           jiffies + msecs_to_jiffies(1));
1101
1102                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true) {
1103                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state=%x\n", get_fwstate(pmlmepriv)));
1104                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1105                 }
1106         } else { /* if join_res < 0 (join fails), then try again */
1107                 mod_timer(&pmlmepriv->assoc_timer,
1108                           jiffies + msecs_to_jiffies(1));
1109                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1110         }
1111
1112 ignore_joinbss_callback:
1113         spin_unlock_bh(&pmlmepriv->lock);
1114 }
1115
1116 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1117 {
1118         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1119
1120         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1121
1122         rtw_os_xmit_schedule(adapter);
1123 }
1124
1125 static u8 search_max_mac_id(struct adapter *padapter)
1126 {
1127         u8 mac_id;
1128 #if defined(CONFIG_88EU_AP_MODE)
1129         u8 aid;
1130         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1131         struct sta_priv *pstapriv = &padapter->stapriv;
1132 #endif
1133         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
1134         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
1135
1136 #if defined(CONFIG_88EU_AP_MODE)
1137         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1138                 for (aid = (pstapriv->max_num_sta); aid > 0; aid--) {
1139                         if (pstapriv->sta_aid[aid-1])
1140                                 break;
1141                 }
1142                 mac_id = aid + 1;
1143         } else
1144 #endif
1145         {/* adhoc  id =  31~2 */
1146                 for (mac_id = (NUM_STA-1); mac_id >= IBSS_START_MAC_ID; mac_id--) {
1147                         if (pmlmeinfo->FW_sta_info[mac_id].status == 1)
1148                                 break;
1149                 }
1150         }
1151         return mac_id;
1152 }
1153
1154 /* FOR AP , AD-HOC mode */
1155 void rtw_stassoc_hw_rpt(struct adapter *adapter, struct sta_info *psta)
1156 {
1157         u16 media_status;
1158         u8 macid;
1159
1160         if (!psta)
1161                 return;
1162
1163         macid = search_max_mac_id(adapter);
1164         rtw_hal_set_hwreg(adapter, HW_VAR_TX_RPT_MAX_MACID, (u8 *)&macid);
1165         media_status = (psta->mac_id<<8)|1; /*   MACID|OPMODE:1 connect */
1166         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1167 }
1168
1169 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1170 {
1171         struct sta_info *psta;
1172         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1173         struct stassoc_event    *pstassoc = (struct stassoc_event *)pbuf;
1174         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1175         struct wlan_network     *ptarget_wlan = NULL;
1176
1177         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1178                 return;
1179
1180 #if defined(CONFIG_88EU_AP_MODE)
1181         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1182                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1183                 if (psta) {
1184                         ap_sta_info_defer_update(adapter, psta);
1185                         rtw_stassoc_hw_rpt(adapter, psta);
1186                 }
1187                 return;
1188         }
1189 #endif
1190         /* for AD-HOC mode */
1191         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1192         if (psta) {
1193                 /* the sta have been in sta_info_queue => do nothing */
1194                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1195                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1196         }
1197         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1198         if (!psta) {
1199                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1200                 return;
1201         }
1202         /* to do: init sta_info variable */
1203         psta->qos_option = 0;
1204         psta->mac_id = (uint)pstassoc->cam_id;
1205         DBG_88E("%s\n", __func__);
1206         /* for ad-hoc mode */
1207         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1208         rtw_stassoc_hw_rpt(adapter, psta);
1209         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1210                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1211         psta->ieee8021x_blocked = false;
1212         spin_lock_bh(&pmlmepriv->lock);
1213         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
1214             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE))) {
1215                 if (adapter->stapriv.asoc_sta_count == 2) {
1216                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1217                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1218                         if (ptarget_wlan)
1219                                 ptarget_wlan->fixed = true;
1220                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1221                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1222                         rtw_indicate_connect(adapter);
1223                 }
1224         }
1225         spin_unlock_bh(&pmlmepriv->lock);
1226         mlmeext_sta_add_event_callback(adapter, psta);
1227 }
1228
1229 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1230 {
1231         int mac_id = -1;
1232         struct sta_info *psta;
1233         struct wlan_network *pwlan = NULL;
1234         struct wlan_bssid_ex *pdev_network = NULL;
1235         u8 *pibss = NULL;
1236         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1237         struct  stadel_event *pstadel = (struct stadel_event *)pbuf;
1238         struct  sta_priv *pstapriv = &adapter->stapriv;
1239         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1240
1241         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1242         if (psta)
1243                 mac_id = psta->mac_id;
1244         else
1245                 mac_id = pstadel->mac_id;
1246
1247         DBG_88E("%s(mac_id=%d)=%pM\n", __func__, mac_id, pstadel->macaddr);
1248
1249         if (mac_id >= 0) {
1250                 u16 media_status;
1251
1252                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1253                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1254                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1255         }
1256
1257         if (check_fwstate(pmlmepriv, WIFI_AP_STATE))
1258                 return;
1259
1260         mlmeext_sta_del_event_callback(adapter);
1261
1262         spin_lock_bh(&pmlmepriv->lock);
1263
1264         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1265                 if (pmlmepriv->to_roaming > 0)
1266                         pmlmepriv->to_roaming--; /*  this stadel_event is caused by roaming, decrease to_roaming */
1267                 else if (pmlmepriv->to_roaming == 0)
1268                         pmlmepriv->to_roaming = adapter->registrypriv.max_roaming_times;
1269
1270                 if (*((unsigned short *)(pstadel->rsvd)) != WLAN_REASON_EXPIRATION_CHK)
1271                         pmlmepriv->to_roaming = 0; /*  don't roam */
1272
1273                 rtw_free_uc_swdec_pending_queue(adapter);
1274
1275                 rtw_free_assoc_resources(adapter);
1276                 rtw_indicate_disconnect(adapter);
1277                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1278                 /*  remove the network entry in scanned_queue */
1279                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1280                 if (pwlan) {
1281                         pwlan->fixed = false;
1282                         rtw_free_network_nolock(pmlmepriv, pwlan);
1283                 }
1284                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1285                 _rtw_roaming(adapter, tgt_network);
1286         }
1287         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1288             check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1289                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1290                 rtw_free_stainfo(adapter,  psta);
1291                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1292
1293                 if (adapter->stapriv.asoc_sta_count == 1) { /* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1294                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1295                         /* free old ibss network */
1296                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1297                         if (pwlan) {
1298                                 pwlan->fixed = false;
1299                                 rtw_free_network_nolock(pmlmepriv, pwlan);
1300                         }
1301                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1302                         /* re-create ibss */
1303                         pdev_network = &(adapter->registrypriv.dev_network);
1304                         pibss = adapter->registrypriv.dev_network.MacAddress;
1305
1306                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1307
1308                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1309
1310                         rtw_update_registrypriv_dev_network(adapter);
1311
1312                         rtw_generate_random_ibss(pibss);
1313
1314                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1315                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1316                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1317                         }
1318
1319                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
1320                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error=>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1321                 }
1322         }
1323         spin_unlock_bh(&pmlmepriv->lock);
1324 }
1325
1326 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1327 {
1328         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1329 }
1330
1331 /*
1332  * _rtw_join_timeout_handler - Timeout/faliure handler for CMD JoinBss
1333  * @adapter: pointer to struct adapter structure
1334  */
1335 void _rtw_join_timeout_handler (unsigned long data)
1336 {
1337         struct adapter *adapter = (struct adapter *)data;
1338         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1339         int do_join_r;
1340
1341         DBG_88E("%s, fw_state=%x\n", __func__, get_fwstate(pmlmepriv));
1342
1343         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1344                 return;
1345
1346         spin_lock_bh(&pmlmepriv->lock);
1347
1348         if (pmlmepriv->to_roaming > 0) { /*  join timeout caused by roaming */
1349                 while (1) {
1350                         pmlmepriv->to_roaming--;
1351                         if (pmlmepriv->to_roaming != 0) { /* try another , */
1352                                 DBG_88E("%s try another roaming\n", __func__);
1353                                 do_join_r = rtw_do_join(adapter);
1354                                 if (do_join_r != _SUCCESS) {
1355                                         DBG_88E("%s roaming do_join return %d\n", __func__, do_join_r);
1356                                         continue;
1357                                 }
1358                                 break;
1359                         } else {
1360                                 DBG_88E("%s We've try roaming but fail\n", __func__);
1361                                 rtw_indicate_disconnect(adapter);
1362                                 break;
1363                         }
1364                 }
1365         } else {
1366                 rtw_indicate_disconnect(adapter);
1367                 free_scanqueue(pmlmepriv);/*  */
1368         }
1369         spin_unlock_bh(&pmlmepriv->lock);
1370 }
1371
1372 /*
1373  * rtw_scan_timeout_handler - Timeout/Faliure handler for CMD SiteSurvey
1374  * @adapter: pointer to struct adapter structure
1375  */
1376 void rtw_scan_timeout_handler (unsigned long data)
1377 {
1378         struct adapter *adapter = (struct adapter *)data;
1379         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1380
1381         DBG_88E(FUNC_ADPT_FMT" fw_state=%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1382         spin_lock_bh(&pmlmepriv->lock);
1383         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1384         spin_unlock_bh(&pmlmepriv->lock);
1385         rtw_indicate_scan_done(adapter, true);
1386 }
1387
1388 static void rtw_auto_scan_handler(struct adapter *padapter)
1389 {
1390         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1391
1392         /* auto site survey per 60sec */
1393         if (pmlmepriv->scan_interval > 0) {
1394                 pmlmepriv->scan_interval--;
1395                 if (pmlmepriv->scan_interval == 0) {
1396                         DBG_88E("%s\n", __func__);
1397                         rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1398                         pmlmepriv->scan_interval = SCAN_INTERVAL;/*  30*2 sec = 60sec */
1399                 }
1400         }
1401 }
1402
1403 void rtw_dynamic_check_timer_handlder(unsigned long data)
1404 {
1405         struct adapter *adapter = (struct adapter *)data;
1406         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1407
1408         if (!adapter)
1409                 return;
1410         if (!adapter->hw_init_completed)
1411                 goto exit;
1412         if ((adapter->bDriverStopped) || (adapter->bSurpriseRemoved))
1413                 goto exit;
1414         if (adapter->net_closed)
1415                 goto exit;
1416         rtw_dynamic_chk_wk_cmd(adapter);
1417
1418         if (pregistrypriv->wifi_spec == 1) {
1419                 /* auto site survey */
1420                 rtw_auto_scan_handler(adapter);
1421         }
1422 exit:
1423         mod_timer(&adapter->mlmepriv.dynamic_chk_timer,
1424                   jiffies + msecs_to_jiffies(2000));
1425 }
1426
1427 #define RTW_SCAN_RESULT_EXPIRE 2000
1428
1429 /*
1430  * Select a new join candidate from the original @param candidate and @param competitor
1431  * @return true: candidate is updated
1432  * @return false: candidate is not updated
1433  */
1434 static int rtw_check_join_candidate(struct mlme_priv *pmlmepriv
1435         , struct wlan_network **candidate, struct wlan_network *competitor)
1436 {
1437         int updated = false;
1438         unsigned long since_scan;
1439         struct adapter *adapter = container_of(pmlmepriv, struct adapter, mlmepriv);
1440
1441         /* check bssid, if needed */
1442         if (pmlmepriv->assoc_by_bssid) {
1443                 if (memcmp(competitor->network.MacAddress, pmlmepriv->assoc_bssid, ETH_ALEN))
1444                         goto exit;
1445         }
1446
1447         /* check ssid, if needed */
1448         if (pmlmepriv->assoc_ssid.SsidLength) {
1449                 if (competitor->network.Ssid.SsidLength != pmlmepriv->assoc_ssid.SsidLength ||
1450                     !memcmp(competitor->network.Ssid.Ssid, pmlmepriv->assoc_ssid.Ssid, pmlmepriv->assoc_ssid.SsidLength) == false)
1451                         goto exit;
1452         }
1453
1454         if (rtw_is_desired_network(adapter, competitor)  == false)
1455                 goto exit;
1456
1457         if (pmlmepriv->to_roaming) {
1458                 since_scan = jiffies - competitor->last_scanned;
1459                 if (jiffies_to_msecs(since_scan) >= RTW_SCAN_RESULT_EXPIRE ||
1460                     is_same_ess(&competitor->network, &pmlmepriv->cur_network.network) == false)
1461                         goto exit;
1462         }
1463
1464         if (*candidate == NULL || (*candidate)->network.Rssi < competitor->network.Rssi) {
1465                 *candidate = competitor;
1466                 updated = true;
1467         }
1468         if (updated) {
1469                 DBG_88E("[by_bssid:%u][assoc_ssid:%s]new candidate: %s(%pM rssi:%d\n",
1470                         pmlmepriv->assoc_by_bssid,
1471                         pmlmepriv->assoc_ssid.Ssid,
1472                         (*candidate)->network.Ssid.Ssid,
1473                         (*candidate)->network.MacAddress,
1474                         (int)(*candidate)->network.Rssi);
1475                 DBG_88E("[to_roaming:%u]\n", pmlmepriv->to_roaming);
1476         }
1477
1478 exit:
1479         return updated;
1480 }
1481
1482 /*
1483  * Calling context:
1484  * The caller of the sub-routine will be in critical section...
1485  * The caller must hold the following spinlock
1486  * pmlmepriv->lock
1487  */
1488
1489 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
1490 {
1491         int ret;
1492         struct list_head *phead;
1493         struct adapter *adapter;
1494         struct __queue *queue   = &(pmlmepriv->scanned_queue);
1495         struct  wlan_network    *pnetwork = NULL;
1496         struct  wlan_network    *candidate = NULL;
1497         u8      supp_ant_div = false;
1498
1499         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1500         phead = get_list_head(queue);
1501         adapter = (struct adapter *)pmlmepriv->nic_hdl;
1502         pmlmepriv->pscanned = phead->next;
1503         while (phead != pmlmepriv->pscanned) {
1504                 pnetwork = container_of(pmlmepriv->pscanned, struct wlan_network, list);
1505                 if (pnetwork == NULL) {
1506                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork==NULL)\n", __func__));
1507                         ret = _FAIL;
1508                         goto exit;
1509                 }
1510                 pmlmepriv->pscanned = pmlmepriv->pscanned->next;
1511                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
1512         }
1513         if (!candidate) {
1514                 DBG_88E("%s: return _FAIL(candidate==NULL)\n", __func__);
1515                 ret = _FAIL;
1516                 goto exit;
1517         } else {
1518                 DBG_88E("%s: candidate: %s(%pM ch:%u)\n", __func__,
1519                         candidate->network.Ssid.Ssid, candidate->network.MacAddress,
1520                         candidate->network.Configuration.DSConfig);
1521         }
1522
1523         /*  check for situation of  _FW_LINKED */
1524         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
1525                 DBG_88E("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
1526
1527                 rtw_disassoc_cmd(adapter, 0, true);
1528                 rtw_indicate_disconnect(adapter);
1529                 rtw_free_assoc_resources_locked(adapter);
1530         }
1531
1532         rtw_hal_get_def_var(adapter, HAL_DEF_IS_SUPPORT_ANT_DIV, &(supp_ant_div));
1533         if (supp_ant_div) {
1534                 u8 cur_ant;
1535
1536                 rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(cur_ant));
1537                 DBG_88E("#### Opt_Ant_(%s), cur_Ant(%s)\n",
1538                         (candidate->network.PhyInfo.Optimum_antenna == 2) ? "A" : "B",
1539                         (cur_ant == 2) ? "A" : "B"
1540                 );
1541         }
1542
1543         ret = rtw_joinbss_cmd(adapter, candidate);
1544
1545 exit:
1546         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1547         return ret;
1548 }
1549
1550 int rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
1551 {
1552         struct  cmd_obj *pcmd;
1553         struct  setauth_parm *psetauthparm;
1554         struct  cmd_priv *pcmdpriv = &(adapter->cmdpriv);
1555         int             res = _SUCCESS;
1556
1557         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
1558         if (!pcmd) {
1559                 res = _FAIL;  /* try again */
1560                 goto exit;
1561         }
1562
1563         psetauthparm = kzalloc(sizeof(struct setauth_parm), GFP_KERNEL);
1564         if (!psetauthparm) {
1565                 kfree(pcmd);
1566                 res = _FAIL;
1567                 goto exit;
1568         }
1569         memset(psetauthparm, 0, sizeof(struct setauth_parm));
1570         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
1571         pcmd->cmdcode = _SetAuth_CMD_;
1572         pcmd->parmbuf = (unsigned char *)psetauthparm;
1573         pcmd->cmdsz =  (sizeof(struct setauth_parm));
1574         pcmd->rsp = NULL;
1575         pcmd->rspsz = 0;
1576         INIT_LIST_HEAD(&pcmd->list);
1577         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1578                  ("after enqueue set_auth_cmd, auth_mode=%x\n",
1579                  psecuritypriv->dot11AuthAlgrthm));
1580         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1581 exit:
1582         return res;
1583 }
1584
1585 int rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, int keyid, u8 set_tx)
1586 {
1587         u8      keylen;
1588         struct cmd_obj          *pcmd;
1589         struct setkey_parm      *psetkeyparm;
1590         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
1591         struct mlme_priv                *pmlmepriv = &(adapter->mlmepriv);
1592         int     res = _SUCCESS;
1593
1594         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
1595         if (!pcmd)
1596                 return _FAIL;  /* try again */
1597
1598         psetkeyparm = kzalloc(sizeof(struct setkey_parm), GFP_KERNEL);
1599         if (!psetkeyparm) {
1600                 res = _FAIL;
1601                 goto err_free_cmd;
1602         }
1603
1604         memset(psetkeyparm, 0, sizeof(struct setkey_parm));
1605
1606         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1607                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
1608                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1609                          ("\n rtw_set_key: psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy=%d\n",
1610                          psetkeyparm->algorithm));
1611         } else {
1612                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
1613                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1614                          ("\n rtw_set_key: psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm=%d\n",
1615                          psetkeyparm->algorithm));
1616         }
1617         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
1618         psetkeyparm->set_tx = set_tx;
1619         pmlmepriv->key_mask |= BIT(psetkeyparm->keyid);
1620         DBG_88E("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n",
1621                 psetkeyparm->algorithm, psetkeyparm->keyid, pmlmepriv->key_mask);
1622         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1623                  ("\n rtw_set_key: psetkeyparm->algorithm=%d psetkeyparm->keyid=(u8)keyid=%d\n",
1624                  psetkeyparm->algorithm, keyid));
1625
1626         switch (psetkeyparm->algorithm) {
1627         case _WEP40_:
1628                 keylen = 5;
1629                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1630                 break;
1631         case _WEP104_:
1632                 keylen = 13;
1633                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1634                 break;
1635         case _TKIP_:
1636                 keylen = 16;
1637                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1638                 psetkeyparm->grpkey = 1;
1639                 break;
1640         case _AES_:
1641                 keylen = 16;
1642                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1643                 psetkeyparm->grpkey = 1;
1644                 break;
1645         default:
1646                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1647                          ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm=%x (must be 1 or 2 or 4 or 5)\n",
1648                          psecuritypriv->dot11PrivacyAlgrthm));
1649                 res = _FAIL;
1650                 goto err_free_parm;
1651         }
1652         pcmd->cmdcode = _SetKey_CMD_;
1653         pcmd->parmbuf = (u8 *)psetkeyparm;
1654         pcmd->cmdsz =  (sizeof(struct setkey_parm));
1655         pcmd->rsp = NULL;
1656         pcmd->rspsz = 0;
1657         INIT_LIST_HEAD(&pcmd->list);
1658         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1659         return res;
1660
1661 err_free_parm:
1662         kfree(psetkeyparm);
1663 err_free_cmd:
1664         kfree(pcmd);
1665         return res;
1666 }
1667
1668 /* adjust IEs for rtw_joinbss_cmd in WMM */
1669 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
1670 {
1671         unsigned        int ielength = 0;
1672         unsigned int i, j;
1673
1674         /* i = 12; after the fixed IE */
1675         for (i = 12; i < in_len; i += (in_ie[i + 1] + 2) /* to the next IE element */) {
1676                 ielength = initial_out_len;
1677
1678                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) {
1679                         /* WMM element ID and OUI */
1680                         /* Append WMM IE to the last index of out_ie */
1681
1682                         for (j = i; j < i + 9; j++) {
1683                                 out_ie[ielength] = in_ie[j];
1684                                 ielength++;
1685                         }
1686                         out_ie[initial_out_len + 1] = 0x07;
1687                         out_ie[initial_out_len + 6] = 0x00;
1688                         out_ie[initial_out_len + 8] = 0x00;
1689                         break;
1690                 }
1691         }
1692         return ielength;
1693 }
1694
1695 /*
1696  * Ported from 8185: IsInPreAuthKeyList().
1697  * (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.)
1698  * Added by Annie, 2006-05-07.
1699  * Search by BSSID,
1700  * Return Value:
1701  *              -1      :if there is no pre-auth key in the table
1702  *              >= 0    :if there is pre-auth key, and return the entry id
1703  */
1704 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
1705 {
1706         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1707         int i = 0;
1708
1709         do {
1710                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
1711                     (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN))) {
1712                         break;
1713                 } else {
1714                         i++;
1715                         /* continue; */
1716                 }
1717
1718         } while (i < NUM_PMKID_CACHE);
1719
1720         if (i == NUM_PMKID_CACHE)
1721                 i = -1;/*  Could not find. */
1722
1723         return i;
1724 }
1725
1726 /*  */
1727 /*  Check the RSN IE length */
1728 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
1729 /*  0-11th element in the array are the fixed IE */
1730 /*  12th element in the array is the IE */
1731 /*  13th element in the array is the IE length */
1732 /*  */
1733
1734 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
1735 {
1736         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1737
1738         if (ie[13] <= 20) {
1739                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
1740                 ie[ie_len] = 1;
1741                 ie_len++;
1742                 ie[ie_len] = 0; /* PMKID count = 0x0100 */
1743                 ie_len++;
1744                 memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
1745
1746                 ie_len += 16;
1747                 ie[13] += 18;/* PMKID length = 2+16 */
1748         }
1749         return ie_len;
1750 }
1751
1752 int rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
1753 {
1754         u8 authmode;
1755         uint    ielength;
1756         int iEntry;
1757
1758         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1759         struct security_priv *psecuritypriv = &adapter->securitypriv;
1760         uint    ndisauthmode = psecuritypriv->ndisauthtype;
1761         uint ndissecuritytype = psecuritypriv->ndisencryptstatus;
1762
1763         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
1764                  ("+rtw_restruct_sec_ie: ndisauthmode=%d ndissecuritytype=%d\n",
1765                   ndisauthmode, ndissecuritytype));
1766
1767         /* copy fixed ie only */
1768         memcpy(out_ie, in_ie, 12);
1769         ielength = 12;
1770         if ((ndisauthmode == Ndis802_11AuthModeWPA) ||
1771             (ndisauthmode == Ndis802_11AuthModeWPAPSK))
1772                         authmode = _WPA_IE_ID_;
1773         if ((ndisauthmode == Ndis802_11AuthModeWPA2) ||
1774             (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
1775                 authmode = _WPA2_IE_ID_;
1776
1777         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
1778                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
1779
1780                 ielength += psecuritypriv->wps_ie_len;
1781         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
1782                 /* copy RSN or SSN */
1783                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
1784                 ielength += psecuritypriv->supplicant_ie[1]+2;
1785                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
1786         }
1787
1788         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
1789         if (iEntry < 0) {
1790                 return ielength;
1791         } else {
1792                 if (authmode == _WPA2_IE_ID_)
1793                         ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
1794         }
1795         return ielength;
1796 }
1797
1798 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
1799 {
1800         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1801         struct eeprom_priv *peepriv = &adapter->eeprompriv;
1802         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
1803         u8 *myhwaddr = myid(peepriv);
1804
1805         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
1806
1807         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
1808
1809         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_config);
1810         pdev_network->Configuration.BeaconPeriod = 100;
1811         pdev_network->Configuration.FHConfig.Length = 0;
1812         pdev_network->Configuration.FHConfig.HopPattern = 0;
1813         pdev_network->Configuration.FHConfig.HopSet = 0;
1814         pdev_network->Configuration.FHConfig.DwellTime = 0;
1815 }
1816
1817 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
1818 {
1819         int sz = 0;
1820         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1821         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
1822         struct  security_priv *psecuritypriv = &adapter->securitypriv;
1823         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
1824
1825         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0); /*  adhoc no 802.1x */
1826
1827         pdev_network->Rssi = 0;
1828
1829         switch (pregistrypriv->wireless_mode) {
1830         case WIRELESS_11B:
1831                 pdev_network->NetworkTypeInUse = (Ndis802_11DS);
1832                 break;
1833         case WIRELESS_11G:
1834         case WIRELESS_11BG:
1835         case WIRELESS_11_24N:
1836         case WIRELESS_11G_24N:
1837         case WIRELESS_11BG_24N:
1838                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
1839                 break;
1840         case WIRELESS_11A:
1841         case WIRELESS_11A_5N:
1842                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
1843                 break;
1844         case WIRELESS_11ABGN:
1845                 if (pregistrypriv->channel > 14)
1846                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
1847                 else
1848                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
1849                 break;
1850         default:
1851                 /*  TODO */
1852                 break;
1853         }
1854
1855         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
1856         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
1857                  ("pregistrypriv->channel=%d, pdev_network->Configuration.DSConfig=0x%x\n",
1858                  pregistrypriv->channel, pdev_network->Configuration.DSConfig));
1859
1860         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
1861                 pdev_network->Configuration.ATIMWindow = (0);
1862
1863         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
1864
1865         /*  1. Supported rates */
1866         /*  2. IE */
1867
1868         sz = rtw_generate_ie(pregistrypriv);
1869         pdev_network->IELength = sz;
1870         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
1871
1872         /* notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd(); */
1873         /* pdev_network->IELength = cpu_to_le32(sz); */
1874 }
1875
1876 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
1877 {
1878 }
1879
1880 /* the function is at passive_level */
1881 void rtw_joinbss_reset(struct adapter *padapter)
1882 {
1883         u8      threshold;
1884         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1885         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
1886
1887         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
1888         pmlmepriv->num_FortyMHzIntolerant = 0;
1889
1890         pmlmepriv->num_sta_no_ht = 0;
1891
1892         phtpriv->ampdu_enable = false;/* reset to disabled */
1893
1894         /*  TH = 1 => means that invalidate usb rx aggregation */
1895         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
1896         if (phtpriv->ht_option) {
1897                 if (padapter->registrypriv.wifi_spec == 1)
1898                         threshold = 1;
1899                 else
1900                         threshold = 0;
1901                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
1902         } else {
1903                 threshold = 1;
1904                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
1905         }
1906 }
1907
1908 /* the function is >= passive_level */
1909 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len)
1910 {
1911         u32 ielen, out_len;
1912         enum ht_cap_ampdu_factor max_rx_ampdu_factor;
1913         unsigned char *p;
1914         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
1915         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1916         struct qos_priv         *pqospriv = &pmlmepriv->qospriv;
1917         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
1918         u32 rx_packet_offset, max_recvbuf_sz;
1919
1920         phtpriv->ht_option = false;
1921
1922         p = rtw_get_ie(in_ie+12, _HT_CAPABILITY_IE_, &ielen, in_len-12);
1923
1924         if (p && ielen > 0) {
1925                 struct ieee80211_ht_cap ht_cap;
1926
1927                 if (pqospriv->qos_option == 0) {
1928                         out_len = *pout_len;
1929                         rtw_set_ie(out_ie + out_len, _VENDOR_SPECIFIC_IE_,
1930                                    _WMM_IE_Length_, WMM_IE, pout_len);
1931
1932                         pqospriv->qos_option = 1;
1933                 }
1934
1935                 out_len = *pout_len;
1936
1937                 memset(&ht_cap, 0, sizeof(struct ieee80211_ht_cap));
1938
1939                 ht_cap.cap_info = cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH |
1940                                               IEEE80211_HT_CAP_SGI_20 |
1941                                               IEEE80211_HT_CAP_SGI_40 |
1942                                               IEEE80211_HT_CAP_TX_STBC |
1943                                               IEEE80211_HT_CAP_DSSSCCK40);
1944
1945                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
1946                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
1947
1948                 /*
1949                 ampdu_params_info [1:0]:Max AMPDU Len => 0:8k , 1:16k, 2:32k, 3:64k
1950                 ampdu_params_info [4:2]:Min MPDU Start Spacing
1951                 */
1952
1953                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor);
1954                 ht_cap.ampdu_params_info = max_rx_ampdu_factor & 0x03;
1955
1956                 if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
1957                         ht_cap.ampdu_params_info |= IEEE80211_HT_CAP_AMPDU_DENSITY & (0x07 << 2);
1958                 else
1959                         ht_cap.ampdu_params_info |= IEEE80211_HT_CAP_AMPDU_DENSITY & 0x00;
1960
1961                 rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
1962                            sizeof(struct ieee80211_ht_cap),
1963                            (unsigned char *)&ht_cap, pout_len);
1964
1965                 phtpriv->ht_option = true;
1966
1967                 p = rtw_get_ie(in_ie+12, _HT_ADD_INFO_IE_, &ielen, in_len-12);
1968                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
1969                         out_len = *pout_len;
1970                         rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2, pout_len);
1971                 }
1972         }
1973         return phtpriv->ht_option;
1974 }
1975
1976 /* the function is > passive_level (in critical_section) */
1977 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len)
1978 {
1979         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1980         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
1981         struct registry_priv *pregistrypriv = &padapter->registrypriv;
1982         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
1983         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
1984
1985         if (!phtpriv->ht_option)
1986                 return;
1987
1988         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
1989                 return;
1990
1991         DBG_88E("+rtw_update_ht_cap()\n");
1992
1993         /* maybe needs check if ap supports rx ampdu. */
1994         if ((!phtpriv->ampdu_enable) && (pregistrypriv->ampdu_enable == 1)) {
1995                 if (pregistrypriv->wifi_spec == 1)
1996                         phtpriv->ampdu_enable = false;
1997                 else
1998                         phtpriv->ampdu_enable = true;
1999         } else if (pregistrypriv->ampdu_enable == 2) {
2000                 phtpriv->ampdu_enable = true;
2001         }
2002
2003         /* update cur_bwmode & cur_ch_offset */
2004         if ((pregistrypriv->cbw40_enable) &&
2005             (le16_to_cpu(pmlmeinfo->HT_caps.cap_info) & BIT(1)) &&
2006             (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
2007                 int i;
2008
2009                 /* update the MCS rates */
2010                 for (i = 0; i < 16; i++)
2011                         ((u8 *)&pmlmeinfo->HT_caps.mcs)[i] &= MCS_rate_1R[i];
2012                 /* switch to the 40M Hz mode according to the AP */
2013                 pmlmeext->cur_bwmode = HT_CHANNEL_WIDTH_40;
2014                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
2015                 case HT_EXTCHNL_OFFSET_UPPER:
2016                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
2017                         break;
2018                 case HT_EXTCHNL_OFFSET_LOWER:
2019                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
2020                         break;
2021                 default:
2022                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
2023                         break;
2024                 }
2025         }
2026
2027         /*  Config SM Power Save setting */
2028         pmlmeinfo->SM_PS = (le16_to_cpu(pmlmeinfo->HT_caps.cap_info) & 0x0C) >> 2;
2029         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
2030                 DBG_88E("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
2031
2032         /*  Config current HT Protection mode. */
2033         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
2034 }
2035
2036 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
2037 {
2038         u8 issued;
2039         int priority;
2040         struct sta_info *psta = NULL;
2041         struct ht_priv  *phtpriv;
2042         struct pkt_attrib *pattrib = &pxmitframe->attrib;
2043         s32 bmcst = IS_MCAST(pattrib->ra);
2044
2045         if (bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100))
2046                 return;
2047
2048         priority = pattrib->priority;
2049
2050         if (pattrib->psta)
2051                 psta = pattrib->psta;
2052         else
2053                 psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
2054
2055         if (!psta)
2056                 return;
2057
2058         phtpriv = &psta->htpriv;
2059
2060         if ((phtpriv->ht_option) && (phtpriv->ampdu_enable)) {
2061                 issued = (phtpriv->agg_enable_bitmap >> priority) & 0x1;
2062                 issued |= (phtpriv->candidate_tid_bitmap >> priority) & 0x1;
2063
2064                 if (issued == 0) {
2065                         DBG_88E("rtw_issue_addbareq_cmd, p=%d\n", priority);
2066                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
2067                         rtw_addbareq_cmd(padapter, (u8)priority, pattrib->ra);
2068                 }
2069         }
2070 }
2071
2072 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2073 {
2074         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2075
2076         spin_lock_bh(&pmlmepriv->lock);
2077         _rtw_roaming(padapter, tgt_network);
2078         spin_unlock_bh(&pmlmepriv->lock);
2079 }
2080
2081 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2082 {
2083         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2084         int do_join_r;
2085
2086         struct wlan_network *pnetwork;
2087
2088         if (tgt_network)
2089                 pnetwork = tgt_network;
2090         else
2091                 pnetwork = &pmlmepriv->cur_network;
2092
2093         if (pmlmepriv->to_roaming > 0) {
2094                 DBG_88E("roaming from %s(%pM length:%d\n",
2095                         pnetwork->network.Ssid.Ssid, pnetwork->network.MacAddress,
2096                         pnetwork->network.Ssid.SsidLength);
2097                 memcpy(&pmlmepriv->assoc_ssid, &pnetwork->network.Ssid, sizeof(struct ndis_802_11_ssid));
2098
2099                 pmlmepriv->assoc_by_bssid = false;
2100
2101                 while (1) {
2102                         do_join_r = rtw_do_join(padapter);
2103                         if (do_join_r == _SUCCESS) {
2104                                 break;
2105                         } else {
2106                                 DBG_88E("roaming do_join return %d\n", do_join_r);
2107                                 pmlmepriv->to_roaming--;
2108
2109                                 if (pmlmepriv->to_roaming > 0) {
2110                                         continue;
2111                                 } else {
2112                                         DBG_88E("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
2113                                         rtw_indicate_disconnect(padapter);
2114                                         break;
2115                                 }
2116                         }
2117                 }
2118         }
2119 }