2 *************************************************************************
4 * 5F., No.36, Taiyuan St., Jhubei City,
8 * (c) Copyright 2002-2007, Ralink Technology, Inc.
10 * This program is free software; you can redistribute it and/or modify *
11 * it under the terms of the GNU General Public License as published by *
12 * the Free Software Foundation; either version 2 of the License, or *
13 * (at your option) any later version. *
15 * This program is distributed in the hope that it will be useful, *
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
18 * GNU General Public License for more details. *
20 * You should have received a copy of the GNU General Public License *
21 * along with this program; if not, write to the *
22 * Free Software Foundation, Inc., *
23 * 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. *
25 *************************************************************************
34 -------- ---------- ----------------------------------------------
35 John 2004-9-3 porting from RT2500
37 #include "../rt_config.h"
39 UCHAR CipherWpaTemplate[] = {
42 0x00, 0x50, 0xf2, 0x01, // oui
43 0x01, 0x00, // Version
44 0x00, 0x50, 0xf2, 0x02, // Multicast
45 0x01, 0x00, // Number of unicast
46 0x00, 0x50, 0xf2, 0x02, // unicast
47 0x01, 0x00, // number of authentication method
48 0x00, 0x50, 0xf2, 0x01 // authentication
51 UCHAR CipherWpa2Template[] = {
54 0x01, 0x00, // Version
55 0x00, 0x0f, 0xac, 0x02, // group cipher, TKIP
56 0x01, 0x00, // number of pairwise
57 0x00, 0x0f, 0xac, 0x02, // unicast
58 0x01, 0x00, // number of authentication method
59 0x00, 0x0f, 0xac, 0x02, // authentication
60 0x00, 0x00, // RSN capability
63 UCHAR Ccx2IeInfo[] = { 0x00, 0x40, 0x96, 0x03, 0x02};
66 ==========================================================================
68 association state machine init, including state transition and timer init
70 S - pointer to the association state machine
74 ==========================================================================
76 VOID AssocStateMachineInit(
79 OUT STATE_MACHINE_FUNC Trans[])
81 StateMachineInit(S, Trans, MAX_ASSOC_STATE, MAX_ASSOC_MSG, (STATE_MACHINE_FUNC)Drop, ASSOC_IDLE, ASSOC_MACHINE_BASE);
84 StateMachineSetAction(S, ASSOC_IDLE, MT2_MLME_ASSOC_REQ, (STATE_MACHINE_FUNC)MlmeAssocReqAction);
85 StateMachineSetAction(S, ASSOC_IDLE, MT2_MLME_REASSOC_REQ, (STATE_MACHINE_FUNC)MlmeReassocReqAction);
86 StateMachineSetAction(S, ASSOC_IDLE, MT2_MLME_DISASSOC_REQ, (STATE_MACHINE_FUNC)MlmeDisassocReqAction);
87 StateMachineSetAction(S, ASSOC_IDLE, MT2_PEER_DISASSOC_REQ, (STATE_MACHINE_FUNC)PeerDisassocAction);
90 StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_MLME_ASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenAssoc);
91 StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_MLME_REASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenReassoc);
92 StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_MLME_DISASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenDisassociate);
93 StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_PEER_DISASSOC_REQ, (STATE_MACHINE_FUNC)PeerDisassocAction);
94 StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_PEER_ASSOC_RSP, (STATE_MACHINE_FUNC)PeerAssocRspAction);
96 // Patch 3Com AP MOde:3CRWE454G72
97 // We send Assoc request frame to this AP, it always send Reassoc Rsp not Associate Rsp.
99 StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_PEER_REASSOC_RSP, (STATE_MACHINE_FUNC)PeerAssocRspAction);
100 StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_ASSOC_TIMEOUT, (STATE_MACHINE_FUNC)AssocTimeoutAction);
103 StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_MLME_ASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenAssoc);
104 StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_MLME_REASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenReassoc);
105 StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_MLME_DISASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenDisassociate);
106 StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_PEER_DISASSOC_REQ, (STATE_MACHINE_FUNC)PeerDisassocAction);
107 StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_PEER_REASSOC_RSP, (STATE_MACHINE_FUNC)PeerReassocRspAction);
109 // Patch, AP doesn't send Reassociate Rsp frame to Station.
111 StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_PEER_ASSOC_RSP, (STATE_MACHINE_FUNC)PeerReassocRspAction);
112 StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_REASSOC_TIMEOUT, (STATE_MACHINE_FUNC)ReassocTimeoutAction);
115 StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_MLME_ASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenAssoc);
116 StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_MLME_REASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenReassoc);
117 StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_MLME_DISASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenDisassociate);
118 StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_PEER_DISASSOC_REQ, (STATE_MACHINE_FUNC)PeerDisassocAction);
119 StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_DISASSOC_TIMEOUT, (STATE_MACHINE_FUNC)DisassocTimeoutAction);
121 // initialize the timer
122 RTMPInitTimer(pAd, &pAd->MlmeAux.AssocTimer, GET_TIMER_FUNCTION(AssocTimeout), pAd, FALSE);
123 RTMPInitTimer(pAd, &pAd->MlmeAux.ReassocTimer, GET_TIMER_FUNCTION(ReassocTimeout), pAd, FALSE);
124 RTMPInitTimer(pAd, &pAd->MlmeAux.DisassocTimer, GET_TIMER_FUNCTION(DisassocTimeout), pAd, FALSE);
128 ==========================================================================
130 Association timeout procedure. After association timeout, this function
131 will be called and it will put a message into the MLME queue
133 Standard timer parameters
135 IRQL = DISPATCH_LEVEL
137 ==========================================================================
139 VOID AssocTimeout(IN PVOID SystemSpecific1,
140 IN PVOID FunctionContext,
141 IN PVOID SystemSpecific2,
142 IN PVOID SystemSpecific3)
144 RTMP_ADAPTER *pAd = (RTMP_ADAPTER *)FunctionContext;
146 // Do nothing if the driver is starting halt state.
147 // This might happen when timer already been fired before cancel timer with mlmehalt
148 if (RTMP_TEST_FLAG(pAd, fRTMP_ADAPTER_HALT_IN_PROGRESS | fRTMP_ADAPTER_NIC_NOT_EXIST))
151 MlmeEnqueue(pAd, ASSOC_STATE_MACHINE, MT2_ASSOC_TIMEOUT, 0, NULL);
152 RT28XX_MLME_HANDLER(pAd);
156 ==========================================================================
158 Reassociation timeout procedure. After reassociation timeout, this
159 function will be called and put a message into the MLME queue
161 Standard timer parameters
163 IRQL = DISPATCH_LEVEL
165 ==========================================================================
167 VOID ReassocTimeout(IN PVOID SystemSpecific1,
168 IN PVOID FunctionContext,
169 IN PVOID SystemSpecific2,
170 IN PVOID SystemSpecific3)
172 RTMP_ADAPTER *pAd = (RTMP_ADAPTER *)FunctionContext;
174 // Do nothing if the driver is starting halt state.
175 // This might happen when timer already been fired before cancel timer with mlmehalt
176 if (RTMP_TEST_FLAG(pAd, fRTMP_ADAPTER_HALT_IN_PROGRESS | fRTMP_ADAPTER_NIC_NOT_EXIST))
179 MlmeEnqueue(pAd, ASSOC_STATE_MACHINE, MT2_REASSOC_TIMEOUT, 0, NULL);
180 RT28XX_MLME_HANDLER(pAd);
184 ==========================================================================
186 Disassociation timeout procedure. After disassociation timeout, this
187 function will be called and put a message into the MLME queue
189 Standard timer parameters
191 IRQL = DISPATCH_LEVEL
193 ==========================================================================
195 VOID DisassocTimeout(IN PVOID SystemSpecific1,
196 IN PVOID FunctionContext,
197 IN PVOID SystemSpecific2,
198 IN PVOID SystemSpecific3)
200 RTMP_ADAPTER *pAd = (RTMP_ADAPTER *)FunctionContext;
202 // Do nothing if the driver is starting halt state.
203 // This might happen when timer already been fired before cancel timer with mlmehalt
204 if (RTMP_TEST_FLAG(pAd, fRTMP_ADAPTER_HALT_IN_PROGRESS | fRTMP_ADAPTER_NIC_NOT_EXIST))
207 MlmeEnqueue(pAd, ASSOC_STATE_MACHINE, MT2_DISASSOC_TIMEOUT, 0, NULL);
208 RT28XX_MLME_HANDLER(pAd);
212 ==========================================================================
214 mlme assoc req handling procedure
216 Adapter - Adapter pointer
217 Elem - MLME Queue Element
219 the station has been authenticated and the following information is stored in the config
221 -# supported rates and their length
222 -# listen interval (Adapter->StaCfg.default_listen_count)
223 -# Transmit power (Adapter->StaCfg.tx_power)
225 -# An association request frame is generated and sent to the air
226 -# Association timer starts
227 -# Association state -> ASSOC_WAIT_RSP
229 IRQL = DISPATCH_LEVEL
231 ==========================================================================
233 VOID MlmeAssocReqAction(
234 IN PRTMP_ADAPTER pAd,
235 IN MLME_QUEUE_ELEM *Elem)
238 HEADER_802_11 AssocHdr;
240 UCHAR WmeIe[9] = {IE_VENDOR_SPECIFIC, 0x07, 0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
243 USHORT CapabilityInfo;
244 BOOLEAN TimerCancelled;
245 PUCHAR pOutBuffer = NULL;
251 UCHAR CkipNegotiationBuffer[CKIP_NEGOTIATION_LENGTH];
252 UCHAR AironetCkipIe = IE_AIRONET_CKIP;
253 UCHAR AironetCkipLen = CKIP_NEGOTIATION_LENGTH;
254 UCHAR AironetIPAddressIE = IE_AIRONET_IPADDRESS;
255 UCHAR AironetIPAddressLen = AIRONET_IPADDRESS_LENGTH;
256 UCHAR AironetIPAddressBuffer[AIRONET_IPADDRESS_LENGTH] = {0x00, 0x40, 0x96, 0x00, 0x00, 0x00, 0x00, 0x00, 0x02, 0x00};
259 // Block all authentication request durning WPA block period
260 if (pAd->StaCfg.bBlockAssoc == TRUE)
262 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Block Assoc request durning WPA block period!\n"));
263 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
264 Status = MLME_STATE_MACHINE_REJECT;
265 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
267 // check sanity first
268 else if (MlmeAssocReqSanity(pAd, Elem->Msg, Elem->MsgLen, ApAddr, &CapabilityInfo, &Timeout, &ListenIntv))
270 RTMPCancelTimer(&pAd->MlmeAux.AssocTimer, &TimerCancelled);
271 COPY_MAC_ADDR(pAd->MlmeAux.Bssid, ApAddr);
273 // Get an unused nonpaged memory
274 NStatus = MlmeAllocateMemory(pAd, &pOutBuffer);
275 if (NStatus != NDIS_STATUS_SUCCESS)
277 DBGPRINT(RT_DEBUG_TRACE,("ASSOC - MlmeAssocReqAction() allocate memory failed \n"));
278 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
279 Status = MLME_FAIL_NO_RESOURCE;
280 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
284 // Add by James 03/06/27
285 pAd->StaCfg.AssocInfo.Length = sizeof(NDIS_802_11_ASSOCIATION_INFORMATION);
286 // Association don't need to report MAC address
287 pAd->StaCfg.AssocInfo.AvailableRequestFixedIEs =
288 NDIS_802_11_AI_REQFI_CAPABILITIES | NDIS_802_11_AI_REQFI_LISTENINTERVAL;
289 pAd->StaCfg.AssocInfo.RequestFixedIEs.Capabilities = CapabilityInfo;
290 pAd->StaCfg.AssocInfo.RequestFixedIEs.ListenInterval = ListenIntv;
291 // Only reassociate need this
292 //COPY_MAC_ADDR(pAd->StaCfg.AssocInfo.RequestFixedIEs.CurrentAPAddress, ApAddr);
293 pAd->StaCfg.AssocInfo.OffsetRequestIEs = sizeof(NDIS_802_11_ASSOCIATION_INFORMATION);
295 NdisZeroMemory(pAd->StaCfg.ReqVarIEs, MAX_VIE_LEN);
298 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &SsidIe, 1);
300 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &pAd->MlmeAux.SsidLen, 1);
302 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, pAd->MlmeAux.Ssid, pAd->MlmeAux.SsidLen);
303 VarIesOffset += pAd->MlmeAux.SsidLen;
305 // Second add Supported rates
306 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &SupRateIe, 1);
308 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &pAd->MlmeAux.SupRateLen, 1);
310 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, pAd->MlmeAux.SupRate, pAd->MlmeAux.SupRateLen);
311 VarIesOffset += pAd->MlmeAux.SupRateLen;
314 if ((pAd->CommonCfg.Channel > 14) &&
315 (pAd->CommonCfg.bIEEE80211H == TRUE))
316 CapabilityInfo |= 0x0100;
318 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Send ASSOC request...\n"));
319 MgtMacHeaderInit(pAd, &AssocHdr, SUBTYPE_ASSOC_REQ, 0, ApAddr, ApAddr);
321 // Build basic frame first
322 MakeOutgoingFrame(pOutBuffer, &FrameLen,
323 sizeof(HEADER_802_11), &AssocHdr,
327 1, &pAd->MlmeAux.SsidLen,
328 pAd->MlmeAux.SsidLen, pAd->MlmeAux.Ssid,
330 1, &pAd->MlmeAux.SupRateLen,
331 pAd->MlmeAux.SupRateLen, pAd->MlmeAux.SupRate,
334 if (pAd->MlmeAux.ExtRateLen != 0)
336 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
338 1, &pAd->MlmeAux.ExtRateLen,
339 pAd->MlmeAux.ExtRateLen, pAd->MlmeAux.ExtRate,
344 #ifdef DOT11_N_SUPPORT
346 if ((pAd->MlmeAux.HtCapabilityLen > 0) && (pAd->CommonCfg.PhyMode >= PHY_11ABGN_MIXED))
350 UCHAR BROADCOM[4] = {0x0, 0x90, 0x4c, 0x33};
351 if (pAd->StaActive.SupportedPhyInfo.bPreNHt == TRUE)
353 HtLen = SIZE_HT_CAP_IE + 4;
354 MakeOutgoingFrame(pOutBuffer + FrameLen, &TmpLen,
358 pAd->MlmeAux.HtCapabilityLen, &pAd->MlmeAux.HtCapability,
364 HT_CAPABILITY_IE HtCapabilityTmp;
367 #ifndef RT_BIG_ENDIAN
368 MakeOutgoingFrame(pOutBuffer + FrameLen, &TmpLen,
370 1, &pAd->MlmeAux.HtCapabilityLen,
371 pAd->MlmeAux.HtCapabilityLen, &pAd->MlmeAux.HtCapability,
374 NdisZeroMemory(&HtCapabilityTmp, sizeof(HT_CAPABILITY_IE));
375 NdisMoveMemory(&HtCapabilityTmp, &pAd->MlmeAux.HtCapability, pAd->MlmeAux.HtCapabilityLen);
376 *(USHORT *)(&HtCapabilityTmp.HtCapInfo) = SWAP16(*(USHORT *)(&HtCapabilityTmp.HtCapInfo));
377 *(USHORT *)(&HtCapabilityTmp.ExtHtCapInfo) = SWAP16(*(USHORT *)(&HtCapabilityTmp.ExtHtCapInfo));
379 MakeOutgoingFrame(pOutBuffer + FrameLen, &TmpLen,
381 1, &pAd->MlmeAux.HtCapabilityLen,
382 pAd->MlmeAux.HtCapabilityLen,&HtCapabilityTmp,
388 #endif // DOT11_N_SUPPORT //
390 // add Ralink proprietary IE to inform AP this STA is going to use AGGREGATION or PIGGY-BACK+AGGREGATION
391 // Case I: (Aggregation + Piggy-Back)
392 // 1. user enable aggregation, AND
393 // 2. Mac support piggy-back
394 // 3. AP annouces it's PIGGY-BACK+AGGREGATION-capable in BEACON
395 // Case II: (Aggregation)
396 // 1. user enable aggregation, AND
397 // 2. AP annouces it's AGGREGATION-capable in BEACON
398 if (pAd->CommonCfg.bAggregationCapable)
400 if ((pAd->CommonCfg.bPiggyBackCapable) && ((pAd->MlmeAux.APRalinkIe & 0x00000003) == 3))
403 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x03, 0x00, 0x00, 0x00};
404 MakeOutgoingFrame(pOutBuffer+FrameLen, &TmpLen,
409 else if (pAd->MlmeAux.APRalinkIe & 0x00000001)
412 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x01, 0x00, 0x00, 0x00};
413 MakeOutgoingFrame(pOutBuffer+FrameLen, &TmpLen,
422 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x06, 0x00, 0x00, 0x00};
423 MakeOutgoingFrame(pOutBuffer+FrameLen, &TmpLen,
429 if (pAd->MlmeAux.APEdcaParm.bValid)
431 if (pAd->CommonCfg.bAPSDCapable && pAd->MlmeAux.APEdcaParm.bAPSDCapable)
433 QBSS_STA_INFO_PARM QosInfo;
435 NdisZeroMemory(&QosInfo, sizeof(QBSS_STA_INFO_PARM));
436 QosInfo.UAPSD_AC_BE = pAd->CommonCfg.bAPSDAC_BE;
437 QosInfo.UAPSD_AC_BK = pAd->CommonCfg.bAPSDAC_BK;
438 QosInfo.UAPSD_AC_VI = pAd->CommonCfg.bAPSDAC_VI;
439 QosInfo.UAPSD_AC_VO = pAd->CommonCfg.bAPSDAC_VO;
440 QosInfo.MaxSPLength = pAd->CommonCfg.MaxSPLength;
441 WmeIe[8] |= *(PUCHAR)&QosInfo;
445 // The Parameter Set Count is set to ¡§0¡¨ in the association request frames
446 // WmeIe[8] |= (pAd->MlmeAux.APEdcaParm.EdcaUpdateCount & 0x0f);
449 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
456 // Let WPA(#221) Element ID on the end of this association frame.
457 // Otherwise some AP will fail on parsing Element ID and set status fail on Assoc Rsp.
458 // For example: Put Vendor Specific IE on the front of WPA IE.
459 // This happens on AP (Model No:Linksys WRK54G)
461 if (((pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPAPSK) ||
462 (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2PSK) ||
463 (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA) ||
464 (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2)
468 UCHAR RSNIe = IE_WPA;
470 if ((pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2PSK) ||
471 (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2))
476 RTMPMakeRSNIE(pAd, pAd->StaCfg.AuthMode, pAd->StaCfg.WepStatus, BSS0);
478 // Check for WPA PMK cache list
479 if (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2)
482 BOOLEAN FoundPMK = FALSE;
483 // Search chched PMKID, append it if existed
484 for (idx = 0; idx < PMKID_NO; idx++)
486 if (NdisEqualMemory(ApAddr, &pAd->StaCfg.SavedPMK[idx].BSSID, 6))
496 *(PUSHORT) &pAd->StaCfg.RSN_IE[pAd->StaCfg.RSNIE_Len] = 1;
497 NdisMoveMemory(&pAd->StaCfg.RSN_IE[pAd->StaCfg.RSNIE_Len + 2], &pAd->StaCfg.SavedPMK[idx].PMKID, 16);
498 pAd->StaCfg.RSNIE_Len += 18;
503 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
505 1, &pAd->StaCfg.RSNIE_Len,
506 pAd->StaCfg.RSNIE_Len, pAd->StaCfg.RSN_IE,
513 // Append Variable IE
514 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &RSNIe, 1);
516 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &pAd->StaCfg.RSNIE_Len, 1);
519 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, pAd->StaCfg.RSN_IE, pAd->StaCfg.RSNIE_Len);
520 VarIesOffset += pAd->StaCfg.RSNIE_Len;
522 // Set Variable IEs Length
523 pAd->StaCfg.ReqVarIELen = VarIesOffset;
526 // We have update that at PeerBeaconAtJoinRequest()
527 CkipFlag = pAd->StaCfg.CkipFlag;
530 NdisZeroMemory(CkipNegotiationBuffer, CKIP_NEGOTIATION_LENGTH);
531 CkipNegotiationBuffer[2] = 0x66;
532 // Make it try KP & MIC, since we have to follow the result from AssocRsp
533 CkipNegotiationBuffer[8] = 0x18;
534 CkipNegotiationBuffer[CKIP_NEGOTIATION_LENGTH - 1] = 0x22;
537 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
540 AironetCkipLen, CkipNegotiationBuffer,
545 // Add CCX v2 request if CCX2 admin state is on
546 if (pAd->StaCfg.CCXControl.field.Enable == 1)
550 // Add AironetIPAddressIE for Cisco CCX 2.X
553 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
554 1, &AironetIPAddressIE,
555 1, &AironetIPAddressLen,
556 AironetIPAddressLen, AironetIPAddressBuffer,
564 // Add CipherSuite CCKM or LeapTkip if setting.
567 if (LEAP_CCKM_ON(pAd))
569 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
570 CipherSuiteCiscoCCKMLen, CipherSuiteCiscoCCKM,
575 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, CipherSuiteCiscoCCKM, CipherSuiteCiscoCCKMLen); //Save CipherSuite
576 VarIesOffset += CipherSuiteCiscoCCKMLen;
578 else if ((pAd->StaCfg.LeapAuthMode == CISCO_AuthModeLEAP) && (pAd->StaCfg.WepStatus == Ndis802_11Encryption2Enabled))
580 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
581 CipherSuiteCCXTkipLen, CipherSuiteCCXTkip,
586 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, CipherSuiteCCXTkip, CipherSuiteCCXTkipLen);
587 VarIesOffset += CipherSuiteCCXTkipLen;
589 #endif // LEAP_SUPPORT //
591 // Add by James 03/06/27
592 // Set Variable IEs Length
593 pAd->StaCfg.ReqVarIELen = VarIesOffset;
594 pAd->StaCfg.AssocInfo.RequestIELength = VarIesOffset;
596 // OffsetResponseIEs follow ReqVarIE
597 pAd->StaCfg.AssocInfo.OffsetResponseIEs = sizeof(NDIS_802_11_ASSOCIATION_INFORMATION) + pAd->StaCfg.ReqVarIELen;
602 MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
603 MlmeFreeMemory(pAd, pOutBuffer);
605 RTMPSetTimer(&pAd->MlmeAux.AssocTimer, Timeout);
606 pAd->Mlme.AssocMachine.CurrState = ASSOC_WAIT_RSP;
610 DBGPRINT(RT_DEBUG_TRACE,("ASSOC - MlmeAssocReqAction() sanity check failed. BUG!!!!!! \n"));
611 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
612 Status = MLME_INVALID_FORMAT;
613 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
619 ==========================================================================
621 mlme reassoc req handling procedure
625 -# SSID (Adapter->StaCfg.ssid[])
626 -# BSSID (AP address, Adapter->StaCfg.bssid)
627 -# Supported rates (Adapter->StaCfg.supported_rates[])
628 -# Supported rates length (Adapter->StaCfg.supported_rates_len)
629 -# Tx power (Adapter->StaCfg.tx_power)
631 IRQL = DISPATCH_LEVEL
633 ==========================================================================
635 VOID MlmeReassocReqAction(
636 IN PRTMP_ADAPTER pAd,
637 IN MLME_QUEUE_ELEM *Elem)
640 HEADER_802_11 ReassocHdr;
642 UCHAR WmeIe[9] = {IE_VENDOR_SPECIFIC, 0x07, 0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
643 USHORT CapabilityInfo, ListenIntv;
646 BOOLEAN TimerCancelled;
649 PUCHAR pOutBuffer = NULL;
653 UCHAR CkipNegotiationBuffer[CKIP_NEGOTIATION_LENGTH];
654 UCHAR AironetCkipIe = IE_AIRONET_CKIP;
655 UCHAR AironetCkipLen = CKIP_NEGOTIATION_LENGTH;
656 UCHAR AironetIPAddressIE = IE_AIRONET_IPADDRESS;
657 UCHAR AironetIPAddressLen = AIRONET_IPADDRESS_LENGTH;
658 UCHAR AironetIPAddressBuffer[AIRONET_IPADDRESS_LENGTH] = {0x00, 0x40, 0x96, 0x00, 0x00, 0x00, 0x00, 0x00, 0x02, 0x00};
659 UCHAR AironetCCKMReassocIE = IE_AIRONET_CCKMREASSOC;
660 UCHAR AironetCCKMReassocLen = AIRONET_CCKMREASSOC_LENGTH;
661 UCHAR AironetCCKMReassocBuffer[AIRONET_CCKMREASSOC_LENGTH];
662 UCHAR AironetOUI[] = {0x00, 0x40, 0x96, 0x00};
664 UCHAR CalcMicBuffer[80];
665 ULONG CalcMicBufferLen = 0;
666 #endif // LEAP_SUPPORT //
669 // Block all authentication request durning WPA block period
670 if (pAd->StaCfg.bBlockAssoc == TRUE)
672 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Block ReAssoc request durning WPA block period!\n"));
673 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
674 Status = MLME_STATE_MACHINE_REJECT;
675 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
677 // the parameters are the same as the association
678 else if(MlmeAssocReqSanity(pAd, Elem->Msg, Elem->MsgLen, ApAddr, &CapabilityInfo, &Timeout, &ListenIntv))
680 RTMPCancelTimer(&pAd->MlmeAux.ReassocTimer, &TimerCancelled);
682 NStatus = MlmeAllocateMemory(pAd, &pOutBuffer); //Get an unused nonpaged memory
683 if(NStatus != NDIS_STATUS_SUCCESS)
685 DBGPRINT(RT_DEBUG_TRACE,("ASSOC - MlmeReassocReqAction() allocate memory failed \n"));
686 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
687 Status = MLME_FAIL_NO_RESOURCE;
688 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
692 COPY_MAC_ADDR(pAd->MlmeAux.Bssid, ApAddr);
694 // make frame, use bssid as the AP address??
695 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Send RE-ASSOC request...\n"));
696 MgtMacHeaderInit(pAd, &ReassocHdr, SUBTYPE_REASSOC_REQ, 0, ApAddr, ApAddr);
697 MakeOutgoingFrame(pOutBuffer, &FrameLen,
698 sizeof(HEADER_802_11), &ReassocHdr,
701 MAC_ADDR_LEN, ApAddr,
703 1, &pAd->MlmeAux.SsidLen,
704 pAd->MlmeAux.SsidLen, pAd->MlmeAux.Ssid,
706 1, &pAd->MlmeAux.SupRateLen,
707 pAd->MlmeAux.SupRateLen, pAd->MlmeAux.SupRate,
710 if (pAd->MlmeAux.ExtRateLen != 0)
712 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
714 1, &pAd->MlmeAux.ExtRateLen,
715 pAd->MlmeAux.ExtRateLen, pAd->MlmeAux.ExtRate,
720 if (pAd->MlmeAux.APEdcaParm.bValid)
722 if (pAd->CommonCfg.bAPSDCapable && pAd->MlmeAux.APEdcaParm.bAPSDCapable)
724 QBSS_STA_INFO_PARM QosInfo;
726 NdisZeroMemory(&QosInfo, sizeof(QBSS_STA_INFO_PARM));
727 QosInfo.UAPSD_AC_BE = pAd->CommonCfg.bAPSDAC_BE;
728 QosInfo.UAPSD_AC_BK = pAd->CommonCfg.bAPSDAC_BK;
729 QosInfo.UAPSD_AC_VI = pAd->CommonCfg.bAPSDAC_VI;
730 QosInfo.UAPSD_AC_VO = pAd->CommonCfg.bAPSDAC_VO;
731 QosInfo.MaxSPLength = pAd->CommonCfg.MaxSPLength;
732 WmeIe[8] |= *(PUCHAR)&QosInfo;
735 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
741 #ifdef DOT11_N_SUPPORT
743 if ((pAd->MlmeAux.HtCapabilityLen > 0) && (pAd->CommonCfg.PhyMode >= PHY_11ABGN_MIXED))
747 UCHAR BROADCOM[4] = {0x0, 0x90, 0x4c, 0x33};
748 if (pAd->StaActive.SupportedPhyInfo.bPreNHt == TRUE)
750 HtLen = SIZE_HT_CAP_IE + 4;
751 MakeOutgoingFrame(pOutBuffer + FrameLen, &TmpLen,
755 pAd->MlmeAux.HtCapabilityLen, &pAd->MlmeAux.HtCapability,
760 MakeOutgoingFrame(pOutBuffer + FrameLen, &TmpLen,
762 1, &pAd->MlmeAux.HtCapabilityLen,
763 pAd->MlmeAux.HtCapabilityLen, &pAd->MlmeAux.HtCapability,
768 #endif // DOT11_N_SUPPORT //
770 // add Ralink proprietary IE to inform AP this STA is going to use AGGREGATION or PIGGY-BACK+AGGREGATION
771 // Case I: (Aggregation + Piggy-Back)
772 // 1. user enable aggregation, AND
773 // 2. Mac support piggy-back
774 // 3. AP annouces it's PIGGY-BACK+AGGREGATION-capable in BEACON
775 // Case II: (Aggregation)
776 // 1. user enable aggregation, AND
777 // 2. AP annouces it's AGGREGATION-capable in BEACON
778 if (pAd->CommonCfg.bAggregationCapable)
780 if ((pAd->CommonCfg.bPiggyBackCapable) && ((pAd->MlmeAux.APRalinkIe & 0x00000003) == 3))
783 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x03, 0x00, 0x00, 0x00};
784 MakeOutgoingFrame(pOutBuffer+FrameLen, &TmpLen,
789 else if (pAd->MlmeAux.APRalinkIe & 0x00000001)
792 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x01, 0x00, 0x00, 0x00};
793 MakeOutgoingFrame(pOutBuffer+FrameLen, &TmpLen,
802 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x04, 0x00, 0x00, 0x00};
803 MakeOutgoingFrame(pOutBuffer+FrameLen, &TmpLen,
809 if (LEAP_CCKM_ON(pAd) && (pAd->StaCfg.CCKMLinkUpFlag == TRUE))
811 CkipFlag = pAd->StaCfg.CkipFlag; // We have update that at PeerBeaconAtJoinRequest()
814 NdisZeroMemory(CkipNegotiationBuffer, CKIP_NEGOTIATION_LENGTH);
815 CkipNegotiationBuffer[2] = 0x66;
816 // Make it try KP & MIC, since we have to follow the result from AssocRsp
817 CkipNegotiationBuffer[8] = 0x18;
818 CkipNegotiationBuffer[CKIP_NEGOTIATION_LENGTH - 1] = 0x22;
820 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
823 AironetCkipLen, CkipNegotiationBuffer,
828 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
829 1, &AironetIPAddressIE,
830 1, &AironetIPAddressLen,
831 AironetIPAddressLen, AironetIPAddressBuffer,
836 // The RN is incremented before each reassociation request.
838 pAd->StaCfg.CCKMRN++;
840 // Calculate MIC = hmac-md5(krk, STA-ID|BSSID|RSNIE|TSF|RN);
842 COPY_MAC_ADDR(CalcMicBuffer, pAd->CurrentAddress);
843 CalcMicBufferLen = MAC_ADDR_LEN;
844 COPY_MAC_ADDR(CalcMicBuffer + CalcMicBufferLen, pAd->MlmeAux.Bssid);
845 CalcMicBufferLen += MAC_ADDR_LEN;
846 NdisMoveMemory(CalcMicBuffer + CalcMicBufferLen, CipherSuiteCiscoCCKM, CipherSuiteCiscoCCKMLen);
847 CalcMicBufferLen += CipherSuiteCiscoCCKMLen;
848 NdisMoveMemory(CalcMicBuffer + CalcMicBufferLen, (PUCHAR) &pAd->StaCfg.CCKMBeaconAtJoinTimeStamp, sizeof(pAd->StaCfg.CCKMBeaconAtJoinTimeStamp));
849 CalcMicBufferLen += sizeof(pAd->StaCfg.CCKMBeaconAtJoinTimeStamp);
850 NdisMoveMemory(CalcMicBuffer + CalcMicBufferLen, (PUCHAR)&pAd->StaCfg.CCKMRN, sizeof(pAd->StaCfg.CCKMRN));
851 CalcMicBufferLen += sizeof(pAd->StaCfg.CCKMRN);
852 hmac_md5(pAd->StaCfg.KRK, LEN_EAP_MICK, CalcMicBuffer, CalcMicBufferLen, MICMN);
855 // fill up CCKM reassociation request element
857 NdisMoveMemory(AironetCCKMReassocBuffer, AironetOUI, 4);
858 NdisMoveMemory(AironetCCKMReassocBuffer + 4, (PUCHAR)&pAd->StaCfg.CCKMBeaconAtJoinTimeStamp, 8);
859 NdisMoveMemory(AironetCCKMReassocBuffer + 12, (PUCHAR) &pAd->StaCfg.CCKMRN, 4);
860 NdisMoveMemory(AironetCCKMReassocBuffer +16, MICMN, 8);
862 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
863 1, &AironetCCKMReassocIE,
864 1, &AironetCCKMReassocLen,
865 AironetCCKMReassocLen, AironetCCKMReassocBuffer,
869 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
870 CipherSuiteCiscoCCKMLen,CipherSuiteCiscoCCKM,
874 #endif // LEAP_SUPPORT //
876 // Add CCX v2 request if CCX2 admin state is on
877 if (pAd->StaCfg.CCXControl.field.Enable == 1)
882 MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
890 MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
891 MlmeFreeMemory(pAd, pOutBuffer);
893 RTMPSetTimer(&pAd->MlmeAux.ReassocTimer, Timeout); /* in mSec */
894 pAd->Mlme.AssocMachine.CurrState = REASSOC_WAIT_RSP;
898 DBGPRINT(RT_DEBUG_TRACE,("ASSOC - MlmeReassocReqAction() sanity check failed. BUG!!!! \n"));
899 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
900 Status = MLME_INVALID_FORMAT;
901 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
906 ==========================================================================
908 Upper layer issues disassoc request
914 ==========================================================================
916 VOID MlmeDisassocReqAction(
917 IN PRTMP_ADAPTER pAd,
918 IN MLME_QUEUE_ELEM *Elem)
920 PMLME_DISASSOC_REQ_STRUCT pDisassocReq;
921 HEADER_802_11 DisassocHdr;
922 PHEADER_802_11 pDisassocHdr;
923 PUCHAR pOutBuffer = NULL;
926 BOOLEAN TimerCancelled;
930 #ifdef QOS_DLS_SUPPORT
931 // send DLS-TEAR_DOWN message,
932 if (pAd->CommonCfg.bDLSCapable)
936 // tear down local dls table entry
937 for (i=0; i<MAX_NUM_OF_INIT_DLS_ENTRY; i++)
939 if (pAd->StaCfg.DLSEntry[i].Valid && (pAd->StaCfg.DLSEntry[i].Status == DLS_FINISH))
941 RTMPSendDLSTearDownFrame(pAd, pAd->StaCfg.DLSEntry[i].MacAddr);
942 pAd->StaCfg.DLSEntry[i].Status = DLS_NONE;
943 pAd->StaCfg.DLSEntry[i].Valid = FALSE;
947 // tear down peer dls table entry
948 for (i=MAX_NUM_OF_INIT_DLS_ENTRY; i<MAX_NUM_OF_DLS_ENTRY; i++)
950 if (pAd->StaCfg.DLSEntry[i].Valid && (pAd->StaCfg.DLSEntry[i].Status == DLS_FINISH))
952 RTMPSendDLSTearDownFrame(pAd, pAd->StaCfg.DLSEntry[i].MacAddr);
953 pAd->StaCfg.DLSEntry[i].Status = DLS_NONE;
954 pAd->StaCfg.DLSEntry[i].Valid = FALSE;
958 #endif // QOS_DLS_SUPPORT //
961 pDisassocReq = (PMLME_DISASSOC_REQ_STRUCT)(Elem->Msg);
963 NStatus = MlmeAllocateMemory(pAd, &pOutBuffer); //Get an unused nonpaged memory
964 if (NStatus != NDIS_STATUS_SUCCESS)
966 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - MlmeDisassocReqAction() allocate memory failed\n"));
967 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
968 Status = MLME_FAIL_NO_RESOURCE;
969 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_DISASSOC_CONF, 2, &Status);
975 RTMPCancelTimer(&pAd->MlmeAux.DisassocTimer, &TimerCancelled);
977 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Send DISASSOC request[BSSID::%02x:%02x:%02x:%02x:%02x:%02x (Reason=%d)\n",
978 pDisassocReq->Addr[0], pDisassocReq->Addr[1], pDisassocReq->Addr[2],
979 pDisassocReq->Addr[3], pDisassocReq->Addr[4], pDisassocReq->Addr[5], pDisassocReq->Reason));
980 MgtMacHeaderInit(pAd, &DisassocHdr, SUBTYPE_DISASSOC, 0, pDisassocReq->Addr, pDisassocReq->Addr); // patch peap ttls switching issue
981 MakeOutgoingFrame(pOutBuffer, &FrameLen,
982 sizeof(HEADER_802_11),&DisassocHdr,
983 2, &pDisassocReq->Reason,
985 MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
987 // To patch Instance and Buffalo(N) AP
988 // Driver has to send deauth to Instance AP, but Buffalo(N) needs to send disassoc to reset Authenticator's state machine
989 // Therefore, we send both of them.
990 pDisassocHdr = (PHEADER_802_11)pOutBuffer;
991 pDisassocHdr->FC.SubType = SUBTYPE_DEAUTH;
992 MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
994 MlmeFreeMemory(pAd, pOutBuffer);
996 pAd->StaCfg.DisassocReason = REASON_DISASSOC_STA_LEAVING;
997 COPY_MAC_ADDR(pAd->StaCfg.DisassocSta, pDisassocReq->Addr);
999 RTMPSetTimer(&pAd->MlmeAux.DisassocTimer, Timeout); /* in mSec */
1000 pAd->Mlme.AssocMachine.CurrState = DISASSOC_WAIT_RSP;
1002 #ifdef WPA_SUPPLICANT_SUPPORT
1003 #ifndef NATIVE_WPA_SUPPLICANT_SUPPORT
1004 if (pAd->StaCfg.WpaSupplicantUP != WPA_SUPPLICANT_DISABLE)
1006 union iwreq_data wrqu;
1007 //send disassociate event to wpa_supplicant
1008 memset(&wrqu, 0, sizeof(wrqu));
1009 wrqu.data.flags = RT_DISASSOC_EVENT_FLAG;
1010 wireless_send_event(pAd->net_dev, IWEVCUSTOM, &wrqu, NULL);
1012 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //
1013 #endif // WPA_SUPPLICANT_SUPPORT //
1015 #ifdef NATIVE_WPA_SUPPLICANT_SUPPORT
1017 union iwreq_data wrqu;
1018 memset(wrqu.ap_addr.sa_data, 0, MAC_ADDR_LEN);
1019 wireless_send_event(pAd->net_dev, SIOCGIWAP, &wrqu, NULL);
1021 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //
1026 ==========================================================================
1028 peer sends assoc rsp back
1030 Elme - MLME message containing the received frame
1032 IRQL = DISPATCH_LEVEL
1034 ==========================================================================
1036 VOID PeerAssocRspAction(
1037 IN PRTMP_ADAPTER pAd,
1038 IN MLME_QUEUE_ELEM *Elem)
1040 USHORT CapabilityInfo, Status, Aid;
1041 UCHAR SupRate[MAX_LEN_OF_SUPPORTED_RATES], SupRateLen;
1042 UCHAR ExtRate[MAX_LEN_OF_SUPPORTED_RATES], ExtRateLen;
1043 UCHAR Addr2[MAC_ADDR_LEN];
1044 BOOLEAN TimerCancelled;
1047 HT_CAPABILITY_IE HtCapability;
1048 ADD_HT_INFO_IE AddHtInfo; // AP might use this additional ht info IE
1049 UCHAR HtCapabilityLen;
1051 UCHAR NewExtChannelOffset = 0xff;
1053 if (PeerAssocRspSanity(pAd, Elem->Msg, Elem->MsgLen, Addr2, &CapabilityInfo, &Status, &Aid, SupRate, &SupRateLen, ExtRate, &ExtRateLen,
1054 &HtCapability,&AddHtInfo, &HtCapabilityLen,&AddHtInfoLen,&NewExtChannelOffset, &EdcaParm, &CkipFlag))
1056 // The frame is for me ?
1057 if(MAC_ADDR_EQUAL(Addr2, pAd->MlmeAux.Bssid))
1059 DBGPRINT(RT_DEBUG_TRACE, ("PeerAssocRspAction():ASSOC - receive ASSOC_RSP to me (status=%d)\n", Status));
1060 #ifdef DOT11_N_SUPPORT
1061 DBGPRINT(RT_DEBUG_TRACE, ("PeerAssocRspAction():MacTable [%d].AMsduSize = %d. ClientStatusFlags = 0x%lx \n",Elem->Wcid, pAd->MacTab.Content[BSSID_WCID].AMsduSize, pAd->MacTab.Content[BSSID_WCID].ClientStatusFlags));
1062 #endif // DOT11_N_SUPPORT //
1063 RTMPCancelTimer(&pAd->MlmeAux.AssocTimer, &TimerCancelled);
1064 if(Status == MLME_SUCCESS)
1066 // go to procedure listed on page 376
1067 AssocPostProc(pAd, Addr2, CapabilityInfo, Aid, SupRate, SupRateLen, ExtRate, ExtRateLen,
1068 &EdcaParm, &HtCapability, HtCapabilityLen, &AddHtInfo);
1070 #ifdef WPA_SUPPLICANT_SUPPORT
1071 #ifndef NATIVE_WPA_SUPPLICANT_SUPPORT
1072 if (pAd->StaCfg.WpaSupplicantUP != WPA_SUPPLICANT_DISABLE)
1074 union iwreq_data wrqu;
1076 SendAssocIEsToWpaSupplicant(pAd);
1077 memset(&wrqu, 0, sizeof(wrqu));
1078 wrqu.data.flags = RT_ASSOC_EVENT_FLAG;
1079 wireless_send_event(pAd->net_dev, IWEVCUSTOM, &wrqu, NULL);
1081 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //
1082 #endif // WPA_SUPPLICANT_SUPPORT //
1084 #ifdef NATIVE_WPA_SUPPLICANT_SUPPORT
1086 union iwreq_data wrqu;
1087 wext_notify_event_assoc(pAd);
1089 memset(wrqu.ap_addr.sa_data, 0, MAC_ADDR_LEN);
1090 memcpy(wrqu.ap_addr.sa_data, pAd->MlmeAux.Bssid, MAC_ADDR_LEN);
1091 wireless_send_event(pAd->net_dev, SIOCGIWAP, &wrqu, NULL);
1094 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //
1097 pAd->StaCfg.CkipFlag = CkipFlag;
1098 if (CkipFlag & 0x18)
1100 NdisZeroMemory(pAd->StaCfg.TxSEQ, 4);
1101 NdisZeroMemory(pAd->StaCfg.RxSEQ, 4);
1102 NdisZeroMemory(pAd->StaCfg.CKIPMIC, 4);
1103 pAd->StaCfg.GIV[0] = RandomByte(pAd);
1104 pAd->StaCfg.GIV[1] = RandomByte(pAd);
1105 pAd->StaCfg.GIV[2] = RandomByte(pAd);
1106 pAd->StaCfg.bCkipOn = TRUE;
1107 DBGPRINT(RT_DEBUG_TRACE, ("<CCX> pAd->StaCfg.CkipFlag = 0x%02x\n", pAd->StaCfg.CkipFlag));
1112 // Faile on Association, we need to check the status code
1113 // Is that a Rogue AP?
1115 if ((pAd->StaCfg.LeapAuthMode == CISCO_AuthModeLEAP) && (Status == MLME_ALG_NOT_SUPPORT))
1116 { //Possibly Rogue AP
1117 RogueApTableSetEntry(pAd, &pAd->StaCfg.RogueApTab, pAd->MlmeAux.Bssid, LEAP_REASON_INVALID_AUTH);
1119 #endif // LEAP_SUPPORT //
1121 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1122 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
1127 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerAssocRspAction() sanity check fail\n"));
1132 ==========================================================================
1134 peer sends reassoc rsp
1136 Elem - MLME message cntaining the received frame
1138 IRQL = DISPATCH_LEVEL
1140 ==========================================================================
1142 VOID PeerReassocRspAction(
1143 IN PRTMP_ADAPTER pAd,
1144 IN MLME_QUEUE_ELEM *Elem)
1146 USHORT CapabilityInfo;
1149 UCHAR SupRate[MAX_LEN_OF_SUPPORTED_RATES], SupRateLen;
1150 UCHAR ExtRate[MAX_LEN_OF_SUPPORTED_RATES], ExtRateLen;
1151 UCHAR Addr2[MAC_ADDR_LEN];
1153 BOOLEAN TimerCancelled;
1155 HT_CAPABILITY_IE HtCapability;
1156 ADD_HT_INFO_IE AddHtInfo; // AP might use this additional ht info IE
1157 UCHAR HtCapabilityLen;
1159 UCHAR NewExtChannelOffset = 0xff;
1161 if(PeerAssocRspSanity(pAd, Elem->Msg, Elem->MsgLen, Addr2, &CapabilityInfo, &Status, &Aid, SupRate, &SupRateLen, ExtRate, &ExtRateLen,
1162 &HtCapability, &AddHtInfo, &HtCapabilityLen, &AddHtInfoLen,&NewExtChannelOffset, &EdcaParm, &CkipFlag))
1164 if(MAC_ADDR_EQUAL(Addr2, pAd->MlmeAux.Bssid)) // The frame is for me ?
1166 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - receive REASSOC_RSP to me (status=%d)\n", Status));
1167 RTMPCancelTimer(&pAd->MlmeAux.ReassocTimer, &TimerCancelled);
1169 if(Status == MLME_SUCCESS)
1171 // go to procedure listed on page 376
1172 AssocPostProc(pAd, Addr2, CapabilityInfo, Aid, SupRate, SupRateLen, ExtRate, ExtRateLen,
1173 &EdcaParm, &HtCapability, HtCapabilityLen, &AddHtInfo);
1175 #ifdef WPA_SUPPLICANT_SUPPORT
1176 #ifndef NATIVE_WPA_SUPPLICANT_SUPPORT
1177 if (pAd->StaCfg.WpaSupplicantUP != WPA_SUPPLICANT_DISABLE)
1179 union iwreq_data wrqu;
1181 SendAssocIEsToWpaSupplicant(pAd);
1182 memset(&wrqu, 0, sizeof(wrqu));
1183 wrqu.data.flags = RT_ASSOC_EVENT_FLAG;
1184 wireless_send_event(pAd->net_dev, IWEVCUSTOM, &wrqu, NULL);
1186 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //
1187 #endif // WPA_SUPPLICANT_SUPPORT //
1189 #ifdef NATIVE_WPA_SUPPLICANT_SUPPORT
1191 union iwreq_data wrqu;
1192 wext_notify_event_assoc(pAd);
1194 memset(wrqu.ap_addr.sa_data, 0, MAC_ADDR_LEN);
1195 memcpy(wrqu.ap_addr.sa_data, pAd->MlmeAux.Bssid, MAC_ADDR_LEN);
1196 wireless_send_event(pAd->net_dev, SIOCGIWAP, &wrqu, NULL);
1199 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //
1204 // Cisco Leap CCKM supported Re-association.
1207 if (LEAP_CCKM_ON(pAd) && (pAd->StaCfg.CCKMLinkUpFlag == TRUE))
1209 if (CCKMAssocRspSanity(pAd, Elem->Msg, Elem->MsgLen) == TRUE)
1211 pAd->StaCfg.CkipFlag = CkipFlag;
1212 if (CkipFlag & 0x18)
1214 NdisZeroMemory(pAd->StaCfg.TxSEQ, 4);
1215 NdisZeroMemory(pAd->StaCfg.RxSEQ, 4);
1216 NdisZeroMemory(pAd->StaCfg.CKIPMIC, 4);
1217 pAd->StaCfg.GIV[0] = RandomByte(pAd);
1218 pAd->StaCfg.GIV[1] = RandomByte(pAd);
1219 pAd->StaCfg.GIV[2] = RandomByte(pAd);
1220 pAd->StaCfg.bCkipOn = TRUE;
1221 DBGPRINT(RT_DEBUG_TRACE, ("<CCX> pAd->StaCfg.CkipFlag = 0x%02x\n", pAd->StaCfg.CkipFlag));
1224 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1225 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
1229 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - CCKMAssocRspSanity() sanity check fail\n"));
1233 #endif // LEAP_SUPPORT //
1235 // CkipFlag is no use for reassociate
1236 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1237 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
1243 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerReassocRspAction() sanity check fail\n"));
1249 ==========================================================================
1251 procedures on IEEE 802.11/1999 p.376
1254 IRQL = DISPATCH_LEVEL
1256 ==========================================================================
1259 IN PRTMP_ADAPTER pAd,
1261 IN USHORT CapabilityInfo,
1264 IN UCHAR SupRateLen,
1266 IN UCHAR ExtRateLen,
1267 IN PEDCA_PARM pEdcaParm,
1268 IN HT_CAPABILITY_IE *pHtCapability,
1269 IN UCHAR HtCapabilityLen,
1270 IN ADD_HT_INFO_IE *pAddHtInfo) // AP might use this additional ht info IE
1274 pAd->MlmeAux.BssType = BSS_INFRA;
1275 COPY_MAC_ADDR(pAd->MlmeAux.Bssid, pAddr2);
1276 pAd->MlmeAux.Aid = Aid;
1277 pAd->MlmeAux.CapabilityInfo = CapabilityInfo & SUPPORTED_CAPABILITY_INFO;
1278 #ifdef DOT11_N_SUPPORT
1279 // Some HT AP might lost WMM IE. We add WMM ourselves. beacuase HT requires QoS on.
1280 if ((HtCapabilityLen > 0) && (pEdcaParm->bValid == FALSE))
1282 pEdcaParm->bValid = TRUE;
1283 pEdcaParm->Aifsn[0] = 3;
1284 pEdcaParm->Aifsn[1] = 7;
1285 pEdcaParm->Aifsn[2] = 2;
1286 pEdcaParm->Aifsn[3] = 2;
1288 pEdcaParm->Cwmin[0] = 4;
1289 pEdcaParm->Cwmin[1] = 4;
1290 pEdcaParm->Cwmin[2] = 3;
1291 pEdcaParm->Cwmin[3] = 2;
1293 pEdcaParm->Cwmax[0] = 10;
1294 pEdcaParm->Cwmax[1] = 10;
1295 pEdcaParm->Cwmax[2] = 4;
1296 pEdcaParm->Cwmax[3] = 3;
1298 pEdcaParm->Txop[0] = 0;
1299 pEdcaParm->Txop[1] = 0;
1300 pEdcaParm->Txop[2] = 96;
1301 pEdcaParm->Txop[3] = 48;
1304 #endif // DOT11_N_SUPPORT //
1306 NdisMoveMemory(&pAd->MlmeAux.APEdcaParm, pEdcaParm, sizeof(EDCA_PARM));
1308 // filter out un-supported rates
1309 pAd->MlmeAux.SupRateLen = SupRateLen;
1310 NdisMoveMemory(pAd->MlmeAux.SupRate, SupRate, SupRateLen);
1311 RTMPCheckRates(pAd, pAd->MlmeAux.SupRate, &pAd->MlmeAux.SupRateLen);
1313 // filter out un-supported rates
1314 pAd->MlmeAux.ExtRateLen = ExtRateLen;
1315 NdisMoveMemory(pAd->MlmeAux.ExtRate, ExtRate, ExtRateLen);
1316 RTMPCheckRates(pAd, pAd->MlmeAux.ExtRate, &pAd->MlmeAux.ExtRateLen);
1318 #ifdef DOT11_N_SUPPORT
1319 if (HtCapabilityLen > 0)
1321 RTMPCheckHt(pAd, BSSID_WCID, pHtCapability, pAddHtInfo);
1323 DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===> AP.AMsduSize = %d. ClientStatusFlags = 0x%lx \n", pAd->MacTab.Content[BSSID_WCID].AMsduSize, pAd->MacTab.Content[BSSID_WCID].ClientStatusFlags));
1325 DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===> (Mmps=%d, AmsduSize=%d, )\n",
1326 pAd->MacTab.Content[BSSID_WCID].MmpsMode, pAd->MacTab.Content[BSSID_WCID].AMsduSize));
1327 #endif // DOT11_N_SUPPORT //
1329 // Set New WPA information
1330 Idx = BssTableSearch(&pAd->ScanTab, pAddr2, pAd->MlmeAux.Channel);
1331 if (Idx == BSS_NOT_FOUND)
1333 DBGPRINT_ERR(("ASSOC - Can't find BSS after receiving Assoc response\n"));
1338 pAd->MacTab.Content[BSSID_WCID].RSNIE_Len = 0;
1339 NdisZeroMemory(pAd->MacTab.Content[BSSID_WCID].RSN_IE, MAX_LEN_OF_RSNIE);
1341 // Store appropriate RSN_IE for WPA SM negotiation later
1342 if ((pAd->StaCfg.AuthMode >= Ndis802_11AuthModeWPA) && (pAd->ScanTab.BssEntry[Idx].VarIELen != 0))
1348 pVIE = pAd->ScanTab.BssEntry[Idx].VarIEs;
1349 len = pAd->ScanTab.BssEntry[Idx].VarIELen;
1353 pEid = (PEID_STRUCT) pVIE;
1355 if ((pEid->Eid == IE_WPA) && (NdisEqualMemory(pEid->Octet, WPA_OUI, 4))
1356 && (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA || pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPAPSK))
1358 NdisMoveMemory(pAd->MacTab.Content[BSSID_WCID].RSN_IE, pVIE, (pEid->Len + 2));
1359 pAd->MacTab.Content[BSSID_WCID].RSNIE_Len = (pEid->Len + 2);
1360 DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===> Store RSN_IE for WPA SM negotiation \n"));
1363 else if ((pEid->Eid == IE_RSN) && (NdisEqualMemory(pEid->Octet + 2, RSN_OUI, 3))
1364 && (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2 || pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2PSK))
1366 NdisMoveMemory(pAd->MacTab.Content[BSSID_WCID].RSN_IE, pVIE, (pEid->Len + 2));
1367 pAd->MacTab.Content[BSSID_WCID].RSNIE_Len = (pEid->Len + 2);
1368 DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===> Store RSN_IE for WPA2 SM negotiation \n"));
1371 pVIE += (pEid->Len + 2);
1372 len -= (pEid->Len + 2);
1376 if (pAd->MacTab.Content[BSSID_WCID].RSNIE_Len == 0)
1378 DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===> no RSN_IE \n"));
1382 hex_dump("RSN_IE", pAd->MacTab.Content[BSSID_WCID].RSN_IE, pAd->MacTab.Content[BSSID_WCID].RSNIE_Len);
1388 ==========================================================================
1390 left part of IEEE 802.11/1999 p.374
1392 Elem - MLME message containing the received frame
1394 IRQL = DISPATCH_LEVEL
1396 ==========================================================================
1398 VOID PeerDisassocAction(
1399 IN PRTMP_ADAPTER pAd,
1400 IN MLME_QUEUE_ELEM *Elem)
1402 UCHAR Addr2[MAC_ADDR_LEN];
1405 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerDisassocAction()\n"));
1406 if(PeerDisassocSanity(pAd, Elem->Msg, Elem->MsgLen, Addr2, &Reason))
1408 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerDisassocAction() Reason = %d\n", Reason));
1409 if (INFRA_ON(pAd) && MAC_ADDR_EQUAL(pAd->CommonCfg.Bssid, Addr2))
1412 if (pAd->CommonCfg.bWirelessEvent)
1414 RTMPSendWirelessEvent(pAd, IW_DISASSOC_EVENT_FLAG, pAd->MacTab.Content[BSSID_WCID].Addr, BSS0, 0);
1419 if (pAd->StaCfg.LeapAuthMode == CISCO_AuthModeLEAP)
1421 // Cisco_LEAP has start a timer
1422 // We should cancel it if using LEAP
1423 RTMPCancelTimer(&pAd->StaCfg.LeapAuthTimer, &TimerCancelled);
1424 //Check is it mach the LEAP Authentication failed as possible a Rogue AP
1425 //on it's PortSecured not equal to WPA_802_1X_PORT_SECURED while process the Association.
1426 if ((pAd->Mlme.LeapMachine.CurrState != LEAP_IDLE) && (pAd->StaCfg.PortSecured != WPA_802_1X_PORT_SECURED))
1428 RogueApTableSetEntry(pAd, &pAd->StaCfg.RogueApTab, Addr2, LEAP_REASON_AUTH_TIMEOUT);
1431 #endif // LEAP_SUPPORT //
1433 // Get Current System time and Turn on AdjacentAPReport
1435 NdisGetSystemUpTime(&pAd->StaCfg.CCXAdjacentAPLinkDownTime);
1436 pAd->StaCfg.CCXAdjacentAPReportFlag = TRUE;
1437 LinkDown(pAd, TRUE);
1438 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1440 #ifdef WPA_SUPPLICANT_SUPPORT
1441 #ifndef NATIVE_WPA_SUPPLICANT_SUPPORT
1442 if (pAd->StaCfg.WpaSupplicantUP != WPA_SUPPLICANT_DISABLE)
1444 union iwreq_data wrqu;
1445 //send disassociate event to wpa_supplicant
1446 memset(&wrqu, 0, sizeof(wrqu));
1447 wrqu.data.flags = RT_DISASSOC_EVENT_FLAG;
1448 wireless_send_event(pAd->net_dev, IWEVCUSTOM, &wrqu, NULL);
1450 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //
1451 #endif // WPA_SUPPLICANT_SUPPORT //
1453 #ifdef NATIVE_WPA_SUPPLICANT_SUPPORT
1455 union iwreq_data wrqu;
1456 memset(wrqu.ap_addr.sa_data, 0, MAC_ADDR_LEN);
1457 wireless_send_event(pAd->net_dev, SIOCGIWAP, &wrqu, NULL);
1459 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //
1464 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerDisassocAction() sanity check fail\n"));
1470 ==========================================================================
1472 what the state machine will do after assoc timeout
1476 IRQL = DISPATCH_LEVEL
1478 ==========================================================================
1480 VOID AssocTimeoutAction(
1481 IN PRTMP_ADAPTER pAd,
1482 IN MLME_QUEUE_ELEM *Elem)
1485 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - AssocTimeoutAction\n"));
1486 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1487 Status = MLME_REJ_TIMEOUT;
1488 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
1492 ==========================================================================
1494 what the state machine will do after reassoc timeout
1496 IRQL = DISPATCH_LEVEL
1498 ==========================================================================
1500 VOID ReassocTimeoutAction(
1501 IN PRTMP_ADAPTER pAd,
1502 IN MLME_QUEUE_ELEM *Elem)
1505 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - ReassocTimeoutAction\n"));
1506 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1507 Status = MLME_REJ_TIMEOUT;
1508 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
1512 ==========================================================================
1514 what the state machine will do after disassoc timeout
1516 IRQL = DISPATCH_LEVEL
1518 ==========================================================================
1520 VOID DisassocTimeoutAction(
1521 IN PRTMP_ADAPTER pAd,
1522 IN MLME_QUEUE_ELEM *Elem)
1525 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - DisassocTimeoutAction\n"));
1526 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1527 Status = MLME_SUCCESS;
1528 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_DISASSOC_CONF, 2, &Status);
1531 VOID InvalidStateWhenAssoc(
1532 IN PRTMP_ADAPTER pAd,
1533 IN MLME_QUEUE_ELEM *Elem)
1536 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - InvalidStateWhenAssoc(state=%ld), reset ASSOC state machine\n",
1537 pAd->Mlme.AssocMachine.CurrState));
1538 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1539 Status = MLME_STATE_MACHINE_REJECT;
1540 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
1543 VOID InvalidStateWhenReassoc(
1544 IN PRTMP_ADAPTER pAd,
1545 IN MLME_QUEUE_ELEM *Elem)
1548 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - InvalidStateWhenReassoc(state=%ld), reset ASSOC state machine\n",
1549 pAd->Mlme.AssocMachine.CurrState));
1550 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1551 Status = MLME_STATE_MACHINE_REJECT;
1552 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
1555 VOID InvalidStateWhenDisassociate(
1556 IN PRTMP_ADAPTER pAd,
1557 IN MLME_QUEUE_ELEM *Elem)
1560 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - InvalidStateWhenDisassoc(state=%ld), reset ASSOC state machine\n",
1561 pAd->Mlme.AssocMachine.CurrState));
1562 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1563 Status = MLME_STATE_MACHINE_REJECT;
1564 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_DISASSOC_CONF, 2, &Status);
1568 ==========================================================================
1570 right part of IEEE 802.11/1999 page 374
1572 This event should never cause ASSOC state machine perform state
1573 transition, and has no relationship with CNTL machine. So we separate
1574 this routine as a service outside of ASSOC state transition table.
1576 IRQL = DISPATCH_LEVEL
1578 ==========================================================================
1581 IN PRTMP_ADAPTER pAd,
1584 HEADER_802_11 DisassocHdr;
1585 PHEADER_802_11 pDisassocHdr;
1586 PUCHAR pOutBuffer = NULL;
1588 NDIS_STATUS NStatus;
1589 USHORT Reason = REASON_CLS3ERR;
1591 NStatus = MlmeAllocateMemory(pAd, &pOutBuffer); //Get an unused nonpaged memory
1592 if (NStatus != NDIS_STATUS_SUCCESS)
1595 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Class 3 Error, Send DISASSOC frame\n"));
1596 MgtMacHeaderInit(pAd, &DisassocHdr, SUBTYPE_DISASSOC, 0, pAddr, pAd->CommonCfg.Bssid); // patch peap ttls switching issue
1597 MakeOutgoingFrame(pOutBuffer, &FrameLen,
1598 sizeof(HEADER_802_11),&DisassocHdr,
1601 MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
1603 // To patch Instance and Buffalo(N) AP
1604 // Driver has to send deauth to Instance AP, but Buffalo(N) needs to send disassoc to reset Authenticator's state machine
1605 // Therefore, we send both of them.
1606 pDisassocHdr = (PHEADER_802_11)pOutBuffer;
1607 pDisassocHdr->FC.SubType = SUBTYPE_DEAUTH;
1608 MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
1610 MlmeFreeMemory(pAd, pOutBuffer);
1612 pAd->StaCfg.DisassocReason = REASON_CLS3ERR;
1613 COPY_MAC_ADDR(pAd->StaCfg.DisassocSta, pAddr);
1617 ==========================================================================
1619 Switch between WEP and CKIP upon new association up.
1622 IRQL = DISPATCH_LEVEL
1624 ==========================================================================
1626 VOID SwitchBetweenWepAndCkip(
1627 IN PRTMP_ADAPTER pAd)
1630 SHAREDKEY_MODE_STRUC csr1;
1632 // if KP is required. change the CipherAlg in hardware shard key table from WEP
1633 // to CKIP. else remain as WEP
1634 if (pAd->StaCfg.bCkipOn && (pAd->StaCfg.CkipFlag & 0x10))
1636 // modify hardware key table so that MAC use correct algorithm to decrypt RX
1637 RTMP_IO_READ32(pAd, SHARED_KEY_MODE_BASE, &csr1.word);
1638 if (csr1.field.Bss0Key0CipherAlg == CIPHER_WEP64)
1639 csr1.field.Bss0Key0CipherAlg = CIPHER_CKIP64;
1640 else if (csr1.field.Bss0Key0CipherAlg == CIPHER_WEP128)
1641 csr1.field.Bss0Key0CipherAlg = CIPHER_CKIP128;
1643 if (csr1.field.Bss0Key1CipherAlg == CIPHER_WEP64)
1644 csr1.field.Bss0Key1CipherAlg = CIPHER_CKIP64;
1645 else if (csr1.field.Bss0Key1CipherAlg == CIPHER_WEP128)
1646 csr1.field.Bss0Key1CipherAlg = CIPHER_CKIP128;
1648 if (csr1.field.Bss0Key2CipherAlg == CIPHER_WEP64)
1649 csr1.field.Bss0Key2CipherAlg = CIPHER_CKIP64;
1650 else if (csr1.field.Bss0Key2CipherAlg == CIPHER_WEP128)
1651 csr1.field.Bss0Key2CipherAlg = CIPHER_CKIP128;
1653 if (csr1.field.Bss0Key3CipherAlg == CIPHER_WEP64)
1654 csr1.field.Bss0Key3CipherAlg = CIPHER_CKIP64;
1655 else if (csr1.field.Bss0Key3CipherAlg == CIPHER_WEP128)
1656 csr1.field.Bss0Key3CipherAlg = CIPHER_CKIP128;
1657 RTMP_IO_WRITE32(pAd, SHARED_KEY_MODE_BASE, csr1.word);
1658 DBGPRINT(RT_DEBUG_TRACE, ("SwitchBetweenWepAndCkip: modify BSS0 cipher to %s\n", CipherName[csr1.field.Bss0Key0CipherAlg]));
1660 // modify software key table so that driver can specify correct algorithm in TXD upon TX
1661 for (i=0; i<SHARE_KEY_NUM; i++)
1663 if (pAd->SharedKey[BSS0][i].CipherAlg == CIPHER_WEP64)
1664 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_CKIP64;
1665 else if (pAd->SharedKey[BSS0][i].CipherAlg == CIPHER_WEP128)
1666 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_CKIP128;
1670 // else if KP NOT inused. change the CipherAlg in hardware shard key table from CKIP
1674 // modify hardware key table so that MAC use correct algorithm to decrypt RX
1675 RTMP_IO_READ32(pAd, SHARED_KEY_MODE_BASE, &csr1.word);
1676 if (csr1.field.Bss0Key0CipherAlg == CIPHER_CKIP64)
1677 csr1.field.Bss0Key0CipherAlg = CIPHER_WEP64;
1678 else if (csr1.field.Bss0Key0CipherAlg == CIPHER_CKIP128)
1679 csr1.field.Bss0Key0CipherAlg = CIPHER_WEP128;
1681 if (csr1.field.Bss0Key1CipherAlg == CIPHER_CKIP64)
1682 csr1.field.Bss0Key1CipherAlg = CIPHER_WEP64;
1683 else if (csr1.field.Bss0Key1CipherAlg == CIPHER_CKIP128)
1684 csr1.field.Bss0Key1CipherAlg = CIPHER_WEP128;
1686 if (csr1.field.Bss0Key2CipherAlg == CIPHER_CKIP64)
1687 csr1.field.Bss0Key2CipherAlg = CIPHER_WEP64;
1688 else if (csr1.field.Bss0Key2CipherAlg == CIPHER_CKIP128)
1689 csr1.field.Bss0Key2CipherAlg = CIPHER_WEP128;
1691 if (csr1.field.Bss0Key3CipherAlg == CIPHER_CKIP64)
1692 csr1.field.Bss0Key3CipherAlg = CIPHER_WEP64;
1693 else if (csr1.field.Bss0Key3CipherAlg == CIPHER_CKIP128)
1694 csr1.field.Bss0Key3CipherAlg = CIPHER_WEP128;
1696 // modify software key table so that driver can specify correct algorithm in TXD upon TX
1697 for (i=0; i<SHARE_KEY_NUM; i++)
1699 if (pAd->SharedKey[BSS0][i].CipherAlg == CIPHER_CKIP64)
1700 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_WEP64;
1701 else if (pAd->SharedKey[BSS0][i].CipherAlg == CIPHER_CKIP128)
1702 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_WEP128;
1706 // On WPA-NONE, must update CipherAlg.
1707 // Because the OID_802_11_WEP_STATUS was been set after OID_802_11_ADD_KEY
1708 // and CipherAlg will be CIPHER_NONE by Windows ZeroConfig.
1709 // So we need to update CipherAlg after connect.
1711 if (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPANone)
1713 for (i = 0; i < SHARE_KEY_NUM; i++)
1715 if (pAd->SharedKey[BSS0][i].KeyLen != 0)
1717 if (pAd->StaCfg.WepStatus == Ndis802_11Encryption2Enabled)
1719 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_TKIP;
1721 else if (pAd->StaCfg.WepStatus == Ndis802_11Encryption3Enabled)
1723 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_AES;
1728 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_NONE;
1732 csr1.field.Bss0Key0CipherAlg = pAd->SharedKey[BSS0][0].CipherAlg;
1733 csr1.field.Bss0Key1CipherAlg = pAd->SharedKey[BSS0][1].CipherAlg;
1734 csr1.field.Bss0Key2CipherAlg = pAd->SharedKey[BSS0][2].CipherAlg;
1735 csr1.field.Bss0Key3CipherAlg = pAd->SharedKey[BSS0][3].CipherAlg;
1737 RTMP_IO_WRITE32(pAd, SHARED_KEY_MODE_BASE, csr1.word);
1738 DBGPRINT(RT_DEBUG_TRACE, ("SwitchBetweenWepAndCkip: modify BSS0 cipher to %s\n", CipherName[csr1.field.Bss0Key0CipherAlg]));
1742 #ifdef WPA_SUPPLICANT_SUPPORT
1743 #ifndef NATIVE_WPA_SUPPLICANT_SUPPORT
1744 VOID SendAssocIEsToWpaSupplicant(
1745 IN PRTMP_ADAPTER pAd)
1747 union iwreq_data wrqu;
1748 unsigned char custom[IW_CUSTOM_MAX] = {0};
1750 if ((pAd->StaCfg.ReqVarIELen + 17) <= IW_CUSTOM_MAX)
1752 sprintf(custom, "ASSOCINFO_ReqIEs=");
1753 NdisMoveMemory(custom+17, pAd->StaCfg.ReqVarIEs, pAd->StaCfg.ReqVarIELen);
1754 memset(&wrqu, 0, sizeof(wrqu));
1755 wrqu.data.length = pAd->StaCfg.ReqVarIELen + 17;
1756 wrqu.data.flags = RT_REQIE_EVENT_FLAG;
1757 wireless_send_event(pAd->net_dev, IWEVCUSTOM, &wrqu, custom);
1759 memset(&wrqu, 0, sizeof(wrqu));
1760 wrqu.data.flags = RT_ASSOCINFO_EVENT_FLAG;
1761 wireless_send_event(pAd->net_dev, IWEVCUSTOM, &wrqu, NULL);
1764 DBGPRINT(RT_DEBUG_TRACE, ("pAd->StaCfg.ReqVarIELen + 17 > MAX_CUSTOM_LEN\n"));
1768 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //
1769 #endif // WPA_SUPPLICANT_SUPPORT //
1771 #ifdef NATIVE_WPA_SUPPLICANT_SUPPORT
1772 int wext_notify_event_assoc(
1773 IN RTMP_ADAPTER *pAd)
1775 union iwreq_data wrqu;
1776 char custom[IW_CUSTOM_MAX] = {0};
1778 #if WIRELESS_EXT > 17
1779 if (pAd->StaCfg.ReqVarIELen <= IW_CUSTOM_MAX)
1781 wrqu.data.length = pAd->StaCfg.ReqVarIELen;
1782 memcpy(custom, pAd->StaCfg.ReqVarIEs, pAd->StaCfg.ReqVarIELen);
1783 wireless_send_event(pAd->net_dev, IWEVASSOCREQIE, &wrqu, custom);
1786 DBGPRINT(RT_DEBUG_TRACE, ("pAd->StaCfg.ReqVarIELen > MAX_CUSTOM_LEN\n"));
1788 if (((pAd->StaCfg.ReqVarIELen*2) + 17) <= IW_CUSTOM_MAX)
1791 wrqu.data.length = (pAd->StaCfg.ReqVarIELen*2) + 17;
1792 sprintf(custom, "ASSOCINFO(ReqIEs=");
1793 for (idx=0; idx<pAd->StaCfg.ReqVarIELen; idx++)
1794 sprintf(custom, "%s%02x", custom, pAd->StaCfg.ReqVarIEs[idx]);
1795 wireless_send_event(pAd->net_dev, IWEVCUSTOM, &wrqu, custom);
1798 DBGPRINT(RT_DEBUG_TRACE, ("(pAd->StaCfg.ReqVarIELen*2) + 17 > MAX_CUSTOM_LEN\n"));
1804 #endif // NATIVE_WPA_SUPPLICANT_SUPPORT //