Merge branch 'bind_unbind' into driver-core-next
[sfrench/cifs-2.6.git] / drivers / staging / rtl8723bs / core / rtw_mlme.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  ******************************************************************************/
15 #define _RTW_MLME_C_
16
17 #include <drv_types.h>
18 #include <rtw_debug.h>
19 #include <linux/jiffies.h>
20
21 extern u8 rtw_do_join(struct adapter *padapter);
22
23 sint    _rtw_init_mlme_priv(struct adapter *padapter)
24 {
25         sint    i;
26         u8 *pbuf;
27         struct wlan_network     *pnetwork;
28         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
29         sint    res = _SUCCESS;
30
31         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by vzalloc(). */
32         /* memset((u8 *)pmlmepriv, 0, sizeof(struct mlme_priv)); */
33
34         pmlmepriv->nic_hdl = (u8 *)padapter;
35
36         pmlmepriv->pscanned = NULL;
37         pmlmepriv->fw_state = WIFI_STATION_STATE; /*  Must sync with rtw_wdev_alloc() */
38         /*  wdev->iftype = NL80211_IFTYPE_STATION */
39         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
40         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
41
42         spin_lock_init(&(pmlmepriv->lock));
43         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
44         _rtw_init_queue(&(pmlmepriv->scanned_queue));
45
46         set_scanned_network_val(pmlmepriv, 0);
47
48         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
49
50         pbuf = vzalloc(MAX_BSS_CNT * (sizeof(struct wlan_network)));
51
52         if (pbuf == NULL) {
53                 res = _FAIL;
54                 goto exit;
55         }
56         pmlmepriv->free_bss_buf = pbuf;
57
58         pnetwork = (struct wlan_network *)pbuf;
59
60         for (i = 0; i < MAX_BSS_CNT; i++) {
61                 INIT_LIST_HEAD(&(pnetwork->list));
62
63                 list_add_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
64
65                 pnetwork++;
66         }
67
68         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
69
70         rtw_clear_scan_deny(padapter);
71
72         #define RTW_ROAM_SCAN_RESULT_EXP_MS 5000
73         #define RTW_ROAM_RSSI_DIFF_TH 10
74         #define RTW_ROAM_SCAN_INTERVAL_MS 10000
75
76         pmlmepriv->roam_flags = 0
77                 | RTW_ROAM_ON_EXPIRED
78                 | RTW_ROAM_ON_RESUME
79                 #ifdef CONFIG_LAYER2_ROAMING_ACTIVE /* FIXME */
80                 | RTW_ROAM_ACTIVE
81                 #endif
82                 ;
83
84         pmlmepriv->roam_scanr_exp_ms = RTW_ROAM_SCAN_RESULT_EXP_MS;
85         pmlmepriv->roam_rssi_diff_th = RTW_ROAM_RSSI_DIFF_TH;
86         pmlmepriv->roam_scan_int_ms = RTW_ROAM_SCAN_INTERVAL_MS;
87
88         rtw_init_mlme_timer(padapter);
89
90 exit:
91
92         return res;
93 }
94
95 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
96 {
97         if (*ppie) {
98                 kfree(*ppie);
99                 *plen = 0;
100                 *ppie = NULL;
101         }
102 }
103
104 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
105 {
106         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
107         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
108         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
109         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
110         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
111         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
112
113         rtw_free_mlme_ie_data(&pmlmepriv->p2p_beacon_ie, &pmlmepriv->p2p_beacon_ie_len);
114         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_req_ie, &pmlmepriv->p2p_probe_req_ie_len);
115         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_resp_ie, &pmlmepriv->p2p_probe_resp_ie_len);
116         rtw_free_mlme_ie_data(&pmlmepriv->p2p_go_probe_resp_ie, &pmlmepriv->p2p_go_probe_resp_ie_len);
117         rtw_free_mlme_ie_data(&pmlmepriv->p2p_assoc_req_ie, &pmlmepriv->p2p_assoc_req_ie_len);
118 }
119
120 void _rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
121 {
122         rtw_free_mlme_priv_ie_data(pmlmepriv);
123
124         if (pmlmepriv) {
125                 if (pmlmepriv->free_bss_buf) {
126                         vfree(pmlmepriv->free_bss_buf);
127                 }
128         }
129 }
130
131 /*
132 struct  wlan_network *_rtw_dequeue_network(struct __queue *queue)
133 {
134         _irqL irqL;
135
136         struct wlan_network *pnetwork;
137
138         spin_lock_bh(&queue->lock);
139
140         if (list_empty(&queue->queue))
141
142                 pnetwork = NULL;
143
144         else
145         {
146                 pnetwork = LIST_CONTAINOR(get_next(&queue->queue), struct wlan_network, list);
147
148                 list_del_init(&(pnetwork->list));
149         }
150
151         spin_unlock_bh(&queue->lock);
152
153         return pnetwork;
154 }
155 */
156
157 struct  wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)/* _queue *free_queue) */
158 {
159         struct  wlan_network    *pnetwork;
160         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
161         struct list_head *plist = NULL;
162
163         spin_lock_bh(&free_queue->lock);
164
165         if (list_empty(&free_queue->queue)) {
166                 pnetwork = NULL;
167                 goto exit;
168         }
169         plist = get_next(&(free_queue->queue));
170
171         pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
172
173         list_del_init(&pnetwork->list);
174
175         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("_rtw_alloc_network: ptr =%p\n", plist));
176         pnetwork->network_type = 0;
177         pnetwork->fixed = false;
178         pnetwork->last_scanned = jiffies;
179         pnetwork->aid = 0;
180         pnetwork->join_res = 0;
181
182         pmlmepriv->num_of_scanned++;
183
184 exit:
185         spin_unlock_bh(&free_queue->lock);
186
187         return pnetwork;
188 }
189
190 void _rtw_free_network(struct   mlme_priv *pmlmepriv, struct wlan_network *pnetwork, u8 isfreeall)
191 {
192         unsigned int delta_time;
193         u32 lifetime = SCANQUEUE_LIFETIME;
194 /*      _irqL irqL; */
195         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
196
197         if (pnetwork == NULL)
198                 return;
199
200         if (pnetwork->fixed == true)
201                 return;
202
203         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
204                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true))
205                 lifetime = 1;
206
207         if (!isfreeall) {
208                 delta_time = jiffies_to_msecs(jiffies - pnetwork->last_scanned);
209                 if (delta_time < lifetime)/*  unit:msec */
210                         return;
211         }
212
213         spin_lock_bh(&free_queue->lock);
214
215         list_del_init(&(pnetwork->list));
216
217         list_add_tail(&(pnetwork->list), &(free_queue->queue));
218
219         pmlmepriv->num_of_scanned--;
220
221
222         /* DBG_871X("_rtw_free_network:SSID =%s\n", pnetwork->network.Ssid.Ssid); */
223
224         spin_unlock_bh(&free_queue->lock);
225 }
226
227 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
228 {
229
230         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
231
232         if (pnetwork == NULL)
233                 return;
234
235         if (pnetwork->fixed == true)
236                 return;
237
238         /* spin_lock_irqsave(&free_queue->lock, irqL); */
239
240         list_del_init(&(pnetwork->list));
241
242         list_add_tail(&(pnetwork->list), get_list_head(free_queue));
243
244         pmlmepriv->num_of_scanned--;
245
246         /* spin_unlock_irqrestore(&free_queue->lock, irqL); */
247 }
248
249 /*
250         return the wlan_network with the matching addr
251
252         Shall be called under atomic context... to avoid possible racing condition...
253 */
254 struct wlan_network *_rtw_find_network(struct __queue *scanned_queue, u8 *addr)
255 {
256         struct list_head        *phead, *plist;
257         struct  wlan_network *pnetwork = NULL;
258         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
259
260         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
261                 pnetwork = NULL;
262                 goto exit;
263         }
264
265         /* spin_lock_bh(&scanned_queue->lock); */
266
267         phead = get_list_head(scanned_queue);
268         plist = get_next(phead);
269
270         while (plist != phead) {
271                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
272
273                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
274                         break;
275
276                 plist = get_next(plist);
277         }
278
279         if (plist == phead)
280                 pnetwork = NULL;
281
282         /* spin_unlock_bh(&scanned_queue->lock); */
283
284 exit:
285         return pnetwork;
286 }
287
288 void _rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
289 {
290         struct list_head *phead, *plist;
291         struct wlan_network *pnetwork;
292         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
293         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
294
295         spin_lock_bh(&scanned_queue->lock);
296
297         phead = get_list_head(scanned_queue);
298         plist = get_next(phead);
299
300         while (phead != plist) {
301
302                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
303
304                 plist = get_next(plist);
305
306                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
307
308         }
309
310         spin_unlock_bh(&scanned_queue->lock);
311 }
312
313
314
315
316 sint rtw_if_up(struct adapter *padapter)
317 {
318
319         sint res;
320
321         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
322                 (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
323                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)", padapter->bDriverStopped, padapter->bSurpriseRemoved));
324                 res = false;
325         } else
326                 res =  true;
327         return res;
328 }
329
330
331 void rtw_generate_random_ibss(u8 *pibss)
332 {
333         unsigned long curtime = jiffies;
334
335         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
336         pibss[1] = 0x11;
337         pibss[2] = 0x87;
338         pibss[3] = (u8)(curtime & 0xff) ;/* p[0]; */
339         pibss[4] = (u8)((curtime>>8) & 0xff) ;/* p[1]; */
340         pibss[5] = (u8)((curtime>>16) & 0xff) ;/* p[2]; */
341         return;
342 }
343
344 u8 *rtw_get_capability_from_ie(u8 *ie)
345 {
346         return (ie + 8 + 2);
347 }
348
349
350 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
351 {
352         __le16  val;
353
354         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2);
355
356         return le16_to_cpu(val);
357 }
358
359 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
360 {
361         return (ie + 8);
362 }
363
364
365 int     rtw_init_mlme_priv(struct adapter *padapter)/* struct   mlme_priv *pmlmepriv) */
366 {
367         int     res;
368
369         res = _rtw_init_mlme_priv(padapter);/*  (pmlmepriv); */
370         return res;
371 }
372
373 void rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
374 {
375         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_mlme_priv\n"));
376         _rtw_free_mlme_priv(pmlmepriv);
377 }
378
379 /*
380 static struct   wlan_network *rtw_dequeue_network(struct __queue *queue)
381 {
382         struct wlan_network *pnetwork;
383
384         pnetwork = _rtw_dequeue_network(queue);
385         return pnetwork;
386 }
387 */
388
389 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv);
390 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv)/* _queue  *free_queue) */
391 {
392         struct  wlan_network    *pnetwork;
393
394         pnetwork = _rtw_alloc_network(pmlmepriv);
395         return pnetwork;
396 }
397
398 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork);
399 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork)
400 {
401         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_network ==> ssid = %s\n\n" , pnetwork->network.Ssid.Ssid)); */
402         _rtw_free_network_nolock(&(padapter->mlmepriv), pnetwork);
403         rtw_cfg80211_unlink_bss(padapter, pnetwork);
404 }
405
406
407 void rtw_free_network_queue(struct adapter *dev, u8 isfreeall)
408 {
409         _rtw_free_network_queue(dev, isfreeall);
410 }
411
412 /*
413         return the wlan_network with the matching addr
414
415         Shall be called under atomic context... to avoid possible racing condition...
416 */
417 struct  wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
418 {
419         struct  wlan_network *pnetwork = _rtw_find_network(scanned_queue, addr);
420
421         return pnetwork;
422 }
423
424 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
425 {
426         int ret = true;
427         struct security_priv *psecuritypriv = &adapter->securitypriv;
428
429         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
430                     (pnetwork->network.Privacy == 0))
431                 ret = false;
432         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
433                  (pnetwork->network.Privacy == 1))
434                 ret = false;
435         else
436                 ret = true;
437
438         return ret;
439
440 }
441
442 inline int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
443 {
444         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("(%s,%d)(%s,%d)\n", */
445         /*              a->Ssid.Ssid, a->Ssid.SsidLength, b->Ssid.Ssid, b->Ssid.SsidLength)); */
446         return (a->Ssid.SsidLength == b->Ssid.SsidLength)
447                 &&  !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
448 }
449
450 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst, u8 feature)
451 {
452         u16 s_cap, d_cap;
453         __le16 tmps, tmpd;
454
455         if (rtw_bug_check(dst, src, &s_cap, &d_cap) == false)
456                         return false;
457
458         memcpy((u8 *)&tmps, rtw_get_capability_from_ie(src->IEs), 2);
459         memcpy((u8 *)&tmpd, rtw_get_capability_from_ie(dst->IEs), 2);
460
461
462         s_cap = le16_to_cpu(tmps);
463         d_cap = le16_to_cpu(tmpd);
464
465         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
466                 /*      (src->Configuration.DSConfig == dst->Configuration.DSConfig) && */
467                         ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN))) &&
468                         ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength))) &&
469                         ((s_cap & WLAN_CAPABILITY_IBSS) ==
470                         (d_cap & WLAN_CAPABILITY_IBSS)) &&
471                         ((s_cap & WLAN_CAPABILITY_BSS) ==
472                         (d_cap & WLAN_CAPABILITY_BSS)));
473
474 }
475
476 struct wlan_network *_rtw_find_same_network(struct __queue *scanned_queue, struct wlan_network *network)
477 {
478         struct list_head *phead, *plist;
479         struct wlan_network *found = NULL;
480
481         phead = get_list_head(scanned_queue);
482         plist = get_next(phead);
483
484         while (plist != phead) {
485                 found = LIST_CONTAINOR(plist, struct wlan_network, list);
486
487                 if (is_same_network(&network->network, &found->network, 0))
488                         break;
489
490                 plist = get_next(plist);
491         }
492
493         if (plist == phead)
494                 found = NULL;
495
496         return found;
497 }
498
499 struct  wlan_network    *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
500 {
501         struct list_head        *plist, *phead;
502
503
504         struct  wlan_network    *pwlan = NULL;
505         struct  wlan_network    *oldest = NULL;
506
507         phead = get_list_head(scanned_queue);
508
509         plist = get_next(phead);
510
511         while (1) {
512
513                 if (phead == plist)
514                         break;
515
516                 pwlan = LIST_CONTAINOR(plist, struct wlan_network, list);
517
518                 if (pwlan->fixed != true) {
519                         if (oldest == NULL || time_after(oldest->last_scanned, pwlan->last_scanned))
520                                 oldest = pwlan;
521                 }
522
523                 plist = get_next(plist);
524         }
525         return oldest;
526
527 }
528
529 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
530         struct adapter *padapter, bool update_ie)
531 {
532         long rssi_ori = dst->Rssi;
533
534         u8 sq_smp = src->PhyInfo.SignalQuality;
535
536         u8 ss_final;
537         u8 sq_final;
538         long rssi_final;
539
540         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
541         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
542                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT", ch%u) ss_ori:%3u, sq_ori:%3u, rssi_ori:%3ld, ss_smp:%3u, sq_smp:%3u, rssi_smp:%3ld\n"
543                         , FUNC_ADPT_ARG(padapter)
544                         , src->Ssid.Ssid, MAC_ARG(src->MacAddress), src->Configuration.DSConfig
545                         , ss_ori, sq_ori, rssi_ori
546                         , ss_smp, sq_smp, rssi_smp
547                 );
548         }
549         #endif
550
551         /* The rule below is 1/5 for sample value, 4/5 for history value */
552         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src, 0)) {
553                 /* Take the recvpriv's value for the connected AP*/
554                 ss_final = padapter->recvpriv.signal_strength;
555                 sq_final = padapter->recvpriv.signal_qual;
556                 /* the rssi value here is undecorated, and will be used for antenna diversity */
557                 if (sq_smp != 101) /* from the right channel */
558                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
559                 else
560                         rssi_final = rssi_ori;
561         } else {
562                 if (sq_smp != 101) { /* from the right channel */
563                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
564                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
565                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
566                 } else {
567                         /* bss info not receiving from the right channel, use the original RX signal infos */
568                         ss_final = dst->PhyInfo.SignalStrength;
569                         sq_final = dst->PhyInfo.SignalQuality;
570                         rssi_final = dst->Rssi;
571                 }
572
573         }
574
575         if (update_ie) {
576                 dst->Reserved[0] = src->Reserved[0];
577                 dst->Reserved[1] = src->Reserved[1];
578                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
579         }
580
581         dst->PhyInfo.SignalStrength = ss_final;
582         dst->PhyInfo.SignalQuality = sq_final;
583         dst->Rssi = rssi_final;
584
585         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
586         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
587                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT"), SignalStrength:%u, SignalQuality:%u, RawRSSI:%ld\n"
588                         , FUNC_ADPT_ARG(padapter)
589                         , dst->Ssid.Ssid, MAC_ARG(dst->MacAddress), dst->PhyInfo.SignalStrength, dst->PhyInfo.SignalQuality, dst->Rssi);
590         }
591         #endif
592 }
593
594 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
595 {
596         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
597
598         rtw_bug_check(&(pmlmepriv->cur_network.network),
599                 &(pmlmepriv->cur_network.network),
600                 &(pmlmepriv->cur_network.network),
601                 &(pmlmepriv->cur_network.network));
602
603         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) && (is_same_network(&(pmlmepriv->cur_network.network), pnetwork, 0))) {
604                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"Same Network\n"); */
605
606                 /* if (pmlmepriv->cur_network.network.IELength<= pnetwork->IELength) */
607                 {
608                         update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
609                         rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof(struct ndis_802_11_fix_ie),
610                                                                         pmlmepriv->cur_network.network.IELength);
611                 }
612         }
613 }
614
615
616 /*
617
618 Caller must hold pmlmepriv->lock first.
619
620
621 */
622 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
623 {
624         struct list_head        *plist, *phead;
625         u32 bssid_ex_sz;
626         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
627         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
628         struct wlan_network     *pnetwork = NULL;
629         struct wlan_network     *oldest = NULL;
630         int target_find = 0;
631         u8 feature = 0;
632
633         spin_lock_bh(&queue->lock);
634         phead = get_list_head(queue);
635         plist = get_next(phead);
636
637         while (1) {
638                 if (phead == plist)
639                         break;
640
641                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
642
643                 rtw_bug_check(pnetwork, pnetwork, pnetwork, pnetwork);
644
645                 if (is_same_network(&(pnetwork->network), target, feature)) {
646                         target_find = 1;
647                         break;
648                 }
649
650                 if (rtw_roam_flags(adapter)) {
651                         /* TODO: don't  select netowrk in the same ess as oldest if it's new enough*/
652                 }
653
654                 if (oldest == NULL || time_after(oldest->last_scanned, pnetwork->last_scanned))
655                         oldest = pnetwork;
656
657                 plist = get_next(plist);
658
659         }
660
661
662         /* If we didn't find a match, then get a new network slot to initialize
663          * with this beacon's information */
664         /* if (phead == plist) { */
665         if (!target_find) {
666                 if (list_empty(&pmlmepriv->free_bss_pool.queue)) {
667                         /* If there are no more slots, expire the oldest */
668                         /* list_del_init(&oldest->list); */
669                         pnetwork = oldest;
670                         if (pnetwork == NULL) {
671                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
672                                 goto exit;
673                         }
674                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
675                         /*  variable initialize */
676                         pnetwork->fixed = false;
677                         pnetwork->last_scanned = jiffies;
678
679                         pnetwork->network_type = 0;
680                         pnetwork->aid = 0;
681                         pnetwork->join_res = 0;
682
683                         /* bss info not receiving from the right channel */
684                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
685                                 pnetwork->network.PhyInfo.SignalQuality = 0;
686                 } else {
687                         /* Otherwise just pull from the free list */
688
689                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
690
691                         if (pnetwork == NULL) {
692                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
693                                 goto exit;
694                         }
695
696                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
697                         target->Length = bssid_ex_sz;
698                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
699
700                         pnetwork->last_scanned = jiffies;
701
702                         /* bss info not receiving from the right channel */
703                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
704                                 pnetwork->network.PhyInfo.SignalQuality = 0;
705
706                         list_add_tail(&(pnetwork->list), &(queue->queue));
707
708                 }
709         } else {
710                 /* we have an entry and we are going to update it. But this entry may
711                  * be already expired. In this case we do the same as we found a new
712                  * net and call the new_net handler
713                  */
714                 bool update_ie = true;
715
716                 pnetwork->last_scanned = jiffies;
717
718                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
719                 if ((pnetwork->network.IELength > target->IELength) && (target->Reserved[0] == 1))
720                         update_ie = false;
721
722                 /*  probe resp(3) > beacon(1) > probe req(2) */
723                 if ((target->Reserved[0] != 2) &&
724                         (target->Reserved[0] >= pnetwork->network.Reserved[0])
725                         ) {
726                         update_ie = true;
727                 } else {
728                         update_ie = false;
729                 }
730
731                 update_network(&(pnetwork->network), target, adapter, update_ie);
732         }
733
734 exit:
735         spin_unlock_bh(&queue->lock);
736 }
737
738 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork);
739 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
740 {
741         /* struct __queue       *queue  = &(pmlmepriv->scanned_queue); */
742
743         /* spin_lock_bh(&queue->lock); */
744
745         update_current_network(adapter, pnetwork);
746
747         rtw_update_scanned_network(adapter, pnetwork);
748
749         /* spin_unlock_bh(&queue->lock); */
750 }
751
752 /* select the desired network based on the capability of the (i)bss. */
753 /*  check items: (1) security */
754 /*                         (2) network_type */
755 /*                         (3) WMM */
756 /*                         (4) HT */
757 /*                      (5) others */
758 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork);
759 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
760 {
761         struct security_priv *psecuritypriv = &adapter->securitypriv;
762         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
763         u32 desired_encmode;
764         u32 privacy;
765
766         /* u8 wps_ie[512]; */
767         uint wps_ielen;
768
769         int bselected = true;
770
771         desired_encmode = psecuritypriv->ndisencryptstatus;
772         privacy = pnetwork->network.Privacy;
773
774         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
775                 if (rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen) != NULL)
776                         return true;
777                 else
778                         return false;
779
780         }
781         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
782                 u8 *p = NULL;
783                 uint ie_len = 0;
784
785                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
786             bselected = false;
787
788                 if (psecuritypriv->ndisauthtype == Ndis802_11AuthModeWPA2PSK) {
789                         p = rtw_get_ie(pnetwork->network.IEs + _BEACON_IE_OFFSET_, _RSN_IE_2_, &ie_len, (pnetwork->network.IELength - _BEACON_IE_OFFSET_));
790                         if (p && ie_len > 0) {
791                                 bselected = true;
792                         } else {
793                                 bselected = false;
794                         }
795                 }
796         }
797
798
799         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
800                 DBG_871X("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
801                 bselected = false;
802         }
803
804         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
805                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
806                         bselected = false;
807         }
808
809
810         return bselected;
811 }
812
813 /* TODO: Perry : For Power Management */
814 void rtw_atimdone_event_callback(struct adapter *adapter, u8 *pbuf)
815 {
816         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_evet\n"));
817 }
818
819
820 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
821 {
822         u32 len;
823         struct wlan_bssid_ex *pnetwork;
824         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
825
826         pnetwork = (struct wlan_bssid_ex *)pbuf;
827
828         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid =%s\n",  pnetwork->Ssid.Ssid));
829
830         len = get_wlan_bssid_ex_sz(pnetwork);
831         if (len > (sizeof(struct wlan_bssid_ex))) {
832                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n ****rtw_survey_event_callback: return a wrong bss ***\n"));
833                 return;
834         }
835
836
837         spin_lock_bh(&pmlmepriv->lock);
838
839         /*  update IBSS_network 's timestamp */
840         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) {
841                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"rtw_survey_event_callback : WIFI_ADHOC_MASTER_STATE\n\n"); */
842                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN)) {
843                         struct wlan_network *ibss_wlan = NULL;
844
845                         memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
846                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
847                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
848                         if (ibss_wlan) {
849                                 memcpy(ibss_wlan->network.IEs, pnetwork->IEs, 8);
850                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
851                                 goto exit;
852                         }
853                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
854                 }
855         }
856
857         /*  lock pmlmepriv->lock when you accessing network_q */
858         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false) {
859                 if (pnetwork->Ssid.Ssid[0] == 0) {
860                         pnetwork->Ssid.SsidLength = 0;
861                 }
862                 rtw_add_network(adapter, pnetwork);
863         }
864
865 exit:
866
867         spin_unlock_bh(&pmlmepriv->lock);
868
869         return;
870 }
871
872
873
874 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
875 {
876         u8 timer_cancelled = false;
877         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
878
879         spin_lock_bh(&pmlmepriv->lock);
880         if (pmlmepriv->wps_probe_req_ie) {
881                 pmlmepriv->wps_probe_req_ie_len = 0;
882                 kfree(pmlmepriv->wps_probe_req_ie);
883                 pmlmepriv->wps_probe_req_ie = NULL;
884         }
885
886         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
887
888         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
889                 /* u8 timer_cancelled; */
890
891                 timer_cancelled = true;
892                 /* _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled); */
893
894                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
895         } else {
896
897                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status =%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
898         }
899         spin_unlock_bh(&pmlmepriv->lock);
900
901         if (timer_cancelled)
902                 _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
903
904
905         spin_lock_bh(&pmlmepriv->lock);
906
907         rtw_set_signal_stat_timer(&adapter->recvpriv);
908
909         if (pmlmepriv->to_join == true) {
910                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
911                         if (check_fwstate(pmlmepriv, _FW_LINKED) == false) {
912                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
913
914                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
915                                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
916                                 } else{
917                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
918                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
919
920                                         /* pmlmepriv->fw_state ^= _FW_UNDER_SURVEY;because don't set assoc_timer */
921                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
922
923                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
924
925                                         memset(&pdev_network->Ssid, 0, sizeof(struct ndis_802_11_ssid));
926                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
927
928                                         rtw_update_registrypriv_dev_network(adapter);
929                                         rtw_generate_random_ibss(pibss);
930
931                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
932
933                                         if (rtw_createbss_cmd(adapter) != _SUCCESS) {
934                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error =>rtw_createbss_cmd status FAIL\n"));
935                                         }
936
937                                         pmlmepriv->to_join = false;
938                                 }
939                         }
940                 } else{
941                         int s_ret;
942                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
943                         pmlmepriv->to_join = false;
944                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
945                         if (_SUCCESS == s_ret) {
946                              _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
947                         } else if (s_ret == 2) {/* there is no need to wait for join */
948                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
949                                 rtw_indicate_connect(adapter);
950                         } else{
951                                 DBG_871X("try_to_join, but select scanning queue fail, to_roam:%d\n", rtw_to_roam(adapter));
952
953                                 if (rtw_to_roam(adapter) != 0) {
954                                         if (rtw_dec_to_roam(adapter) == 0
955                                                 || _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)
956                                         ) {
957                                                 rtw_set_to_roam(adapter, 0);
958 #ifdef CONFIG_INTEL_WIDI
959                                                 if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING) {
960                                                         memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
961                                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
962                                                         DBG_871X("change to widi listen\n");
963                                                 }
964 #endif /*  CONFIG_INTEL_WIDI */
965                                                 rtw_free_assoc_resources(adapter, 1);
966                                                 rtw_indicate_disconnect(adapter);
967                                         } else {
968                                                 pmlmepriv->to_join = true;
969                                         }
970                                 } else
971                                         rtw_indicate_disconnect(adapter);
972
973                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
974                         }
975                 }
976         } else {
977                 if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
978                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)
979                                 && check_fwstate(pmlmepriv, _FW_LINKED)) {
980                                 if (rtw_select_roaming_candidate(pmlmepriv) == _SUCCESS) {
981                                         receive_disconnect(adapter, pmlmepriv->cur_network.network.MacAddress
982                                                 , WLAN_REASON_ACTIVE_ROAM);
983                                 }
984                         }
985                 }
986         }
987
988         /* DBG_871X("scan complete in %dms\n", jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time)); */
989
990         spin_unlock_bh(&pmlmepriv->lock);
991
992         rtw_os_xmit_schedule(adapter);
993
994         rtw_cfg80211_surveydone_event_callback(adapter);
995
996         rtw_indicate_scan_done(adapter, false);
997 }
998
999 void rtw_dummy_event_callback(struct adapter *adapter, u8 *pbuf)
1000 {
1001 }
1002
1003 void rtw_fwdbg_event_callback(struct adapter *adapter, u8 *pbuf)
1004 {
1005 }
1006
1007 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
1008 {
1009         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
1010         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
1011         struct list_head        *plist, *phead, *ptemp;
1012
1013         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
1014         spin_lock_bh(&scan_queue->lock);
1015         spin_lock_bh(&free_queue->lock);
1016
1017         phead = get_list_head(scan_queue);
1018         plist = get_next(phead);
1019
1020         while (plist != phead) {
1021                 ptemp = get_next(plist);
1022                 list_del_init(plist);
1023                 list_add_tail(plist, &free_queue->queue);
1024                 plist = ptemp;
1025                 pmlmepriv->num_of_scanned--;
1026         }
1027
1028         spin_unlock_bh(&free_queue->lock);
1029         spin_unlock_bh(&scan_queue->lock);
1030 }
1031
1032 static void rtw_reset_rx_info(struct debug_priv *pdbgpriv)
1033 {
1034         pdbgpriv->dbg_rx_ampdu_drop_count = 0;
1035         pdbgpriv->dbg_rx_ampdu_forced_indicate_count = 0;
1036         pdbgpriv->dbg_rx_ampdu_loss_count = 0;
1037         pdbgpriv->dbg_rx_dup_mgt_frame_drop_count = 0;
1038         pdbgpriv->dbg_rx_ampdu_window_shift_cnt = 0;
1039 }
1040
1041 static void find_network(struct adapter *adapter)
1042 {
1043         struct wlan_network *pwlan = NULL;
1044         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1045         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1046
1047         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1048         if (pwlan)
1049                 pwlan->fixed = false;
1050         else
1051                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources : pwlan == NULL\n\n"));
1052
1053
1054         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) &&
1055             (adapter->stapriv.asoc_sta_count == 1))
1056                 rtw_free_network_nolock(adapter, pwlan);
1057 }
1058
1059 /*
1060 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
1061 */
1062 void rtw_free_assoc_resources(struct adapter *adapter, int lock_scanned_queue)
1063 {
1064         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1065         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1066         struct  sta_priv *pstapriv = &adapter->stapriv;
1067         struct dvobj_priv *psdpriv = adapter->dvobj;
1068         struct debug_priv *pdbgpriv = &psdpriv->drv_dbg;
1069
1070         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
1071         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("tgt_network->network.MacAddress ="MAC_FMT" ssid =%s\n",
1072                 MAC_ARG(tgt_network->network.MacAddress), tgt_network->network.Ssid.Ssid));
1073
1074         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_AP_STATE)) {
1075                 struct sta_info *psta;
1076
1077                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
1078                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1079                 rtw_free_stainfo(adapter,  psta);
1080
1081                 spin_unlock_bh(&(pstapriv->sta_hash_lock));
1082
1083         }
1084
1085         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE|WIFI_AP_STATE)) {
1086                 struct sta_info *psta;
1087
1088                 rtw_free_all_stainfo(adapter);
1089
1090                 psta = rtw_get_bcmc_stainfo(adapter);
1091                 rtw_free_stainfo(adapter, psta);
1092
1093                 rtw_init_bcmc_stainfo(adapter);
1094         }
1095
1096         find_network(adapter);
1097
1098         if (lock_scanned_queue)
1099                 adapter->securitypriv.key_mask = 0;
1100
1101         rtw_reset_rx_info(pdbgpriv);
1102 }
1103
1104 /*
1105 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
1106 */
1107 void rtw_indicate_connect(struct adapter *padapter)
1108 {
1109         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1110
1111         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
1112
1113         pmlmepriv->to_join = false;
1114
1115         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
1116
1117                 set_fwstate(pmlmepriv, _FW_LINKED);
1118
1119                 rtw_os_indicate_connect(padapter);
1120         }
1121
1122         rtw_set_to_roam(padapter, 0);
1123 #ifdef CONFIG_INTEL_WIDI
1124         if (padapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING) {
1125                 memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1126                 intel_widi_wk_cmd(padapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1127                 DBG_871X("change to widi listen\n");
1128         }
1129 #endif /*  CONFIG_INTEL_WIDI */
1130
1131         rtw_set_scan_deny(padapter, 3000);
1132
1133         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state = 0x%08x\n", get_fwstate(pmlmepriv)));
1134 }
1135
1136 /*
1137 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
1138 */
1139 void rtw_indicate_disconnect(struct adapter *padapter)
1140 {
1141         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
1142
1143         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
1144
1145         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING|WIFI_UNDER_WPS);
1146
1147         /* DBG_871X("clear wps when %s\n", __func__); */
1148
1149         if (rtw_to_roam(padapter) > 0)
1150                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1151
1152         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED)
1153                 || (rtw_to_roam(padapter) <= 0)
1154         ) {
1155                 rtw_os_indicate_disconnect(padapter);
1156
1157                 /* set ips_deny_time to avoid enter IPS before LPS leave */
1158                 rtw_set_ips_deny(padapter, 3000);
1159
1160                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1161
1162                 rtw_clear_scan_deny(padapter);
1163         }
1164
1165         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
1166 }
1167
1168 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
1169 {
1170         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1171
1172         rtw_os_indicate_scan_done(padapter, aborted);
1173
1174         if (is_primary_adapter(padapter) &&
1175             (!adapter_to_pwrctl(padapter)->bInSuspend) &&
1176             (!check_fwstate(&padapter->mlmepriv,
1177                             WIFI_ASOC_STATE|WIFI_UNDER_LINKING))) {
1178                 struct pwrctrl_priv *pwrpriv;
1179
1180                 pwrpriv = adapter_to_pwrctl(padapter);
1181                 rtw_set_ips_deny(padapter, 0);
1182                 _set_timer(&padapter->mlmepriv.dynamic_chk_timer, 1);
1183         }
1184 }
1185
1186 void rtw_scan_abort(struct adapter *adapter)
1187 {
1188         unsigned long start;
1189         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1190         struct mlme_ext_priv *pmlmeext = &(adapter->mlmeextpriv);
1191
1192         start = jiffies;
1193         pmlmeext->scan_abort = true;
1194         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)
1195                 && jiffies_to_msecs(start) <= 200) {
1196
1197                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1198                         break;
1199
1200                 DBG_871X(FUNC_NDEV_FMT"fw_state = _FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1201                 msleep(20);
1202         }
1203
1204         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
1205                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
1206                         DBG_871X(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1207                 rtw_indicate_scan_done(adapter, true);
1208         }
1209         pmlmeext->scan_abort = false;
1210 }
1211
1212 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
1213 {
1214         int i;
1215         struct sta_info *bmc_sta, *psta = NULL;
1216         struct recv_reorder_ctrl *preorder_ctrl;
1217         struct sta_priv *pstapriv = &padapter->stapriv;
1218         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1219
1220         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
1221         if (psta == NULL) {
1222                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
1223         }
1224
1225         if (psta) { /* update ptarget_sta */
1226
1227                 DBG_871X("%s\n", __func__);
1228
1229                 psta->aid  = pnetwork->join_res;
1230
1231                 update_sta_info(padapter, psta);
1232
1233                 /* update station supportRate */
1234                 psta->bssratelen = rtw_get_rateset_len(pnetwork->network.SupportedRates);
1235                 memcpy(psta->bssrateset, pnetwork->network.SupportedRates, psta->bssratelen);
1236                 rtw_hal_update_sta_rate_mask(padapter, psta);
1237
1238                 psta->wireless_mode = pmlmeext->cur_wireless_mode;
1239                 psta->raid = rtw_hal_networktype_to_raid(padapter, psta);
1240
1241
1242                 /* sta mode */
1243                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
1244
1245                 /* security related */
1246                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1247                         padapter->securitypriv.binstallGrpkey = false;
1248                         padapter->securitypriv.busetkipkey = false;
1249                         padapter->securitypriv.bgrpkey_handshake = false;
1250
1251                         psta->ieee8021x_blocked = true;
1252                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
1253
1254                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
1255
1256                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
1257                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
1258
1259                         memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
1260                         psta->dot11txpn.val = psta->dot11txpn.val + 1;
1261                         memset((u8 *)&psta->dot11wtxpn, 0, sizeof(union pn48));
1262                         memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
1263                 }
1264
1265                 /*      Commented by Albert 2012/07/21 */
1266                 /*      When doing the WPS, the wps_ie_len won't equal to 0 */
1267                 /*      And the Wi-Fi driver shouldn't allow the data packet to be transmitted. */
1268                 if (padapter->securitypriv.wps_ie_len != 0) {
1269                         psta->ieee8021x_blocked = true;
1270                         padapter->securitypriv.wps_ie_len = 0;
1271                 }
1272
1273
1274                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
1275                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
1276                 /* todo: check if AP can send A-MPDU packets */
1277                 for (i = 0; i < 16 ; i++) {
1278                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1279                         preorder_ctrl = &psta->recvreorder_ctrl[i];
1280                         preorder_ctrl->enable = false;
1281                         preorder_ctrl->indicate_seq = 0xffff;
1282                         #ifdef DBG_RX_SEQ
1283                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1284                                 preorder_ctrl->indicate_seq);
1285                         #endif
1286                         preorder_ctrl->wend_b = 0xffff;
1287                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1288                 }
1289
1290
1291                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
1292                 if (bmc_sta) {
1293                         for (i = 0; i < 16 ; i++) {
1294                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1295                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
1296                                 preorder_ctrl->enable = false;
1297                                 preorder_ctrl->indicate_seq = 0xffff;
1298                                 #ifdef DBG_RX_SEQ
1299                                 DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1300                                         preorder_ctrl->indicate_seq);
1301                                 #endif
1302                                 preorder_ctrl->wend_b = 0xffff;
1303                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1304                         }
1305                 }
1306         }
1307
1308         return psta;
1309
1310 }
1311
1312 /* pnetwork : returns from rtw_joinbss_event_callback */
1313 /* ptarget_wlan: found from scanned_queue */
1314 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
1315 {
1316         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1317         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
1318
1319         DBG_871X("%s\n", __func__);
1320
1321         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nfw_state:%x, BSSID:"MAC_FMT"\n"
1322                 , get_fwstate(pmlmepriv), MAC_ARG(pnetwork->network.MacAddress)));
1323
1324
1325         /*  why not use ptarget_wlan?? */
1326         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
1327         /*  some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs */
1328         cur_network->network.IELength = ptarget_wlan->network.IELength;
1329         memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
1330
1331         cur_network->aid = pnetwork->join_res;
1332
1333
1334         rtw_set_signal_stat_timer(&padapter->recvpriv);
1335
1336         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
1337         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
1338         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
1339         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
1340         #if defined(DBG_RX_SIGNAL_DISPLAY_PROCESSING) && 1
1341                 DBG_871X(FUNC_ADPT_FMT" signal_strength:%3u, rssi:%3d, signal_qual:%3u"
1342                         "\n"
1343                         , FUNC_ADPT_ARG(padapter)
1344                         , padapter->recvpriv.signal_strength
1345                         , padapter->recvpriv.rssi
1346                         , padapter->recvpriv.signal_qual
1347         );
1348         #endif
1349
1350         rtw_set_signal_stat_timer(&padapter->recvpriv);
1351
1352         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
1353         switch (pnetwork->network.InfrastructureMode) {
1354         case Ndis802_11Infrastructure:
1355
1356                         if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
1357                                 pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
1358                         else
1359                                 pmlmepriv->fw_state = WIFI_STATION_STATE;
1360
1361                         break;
1362         case Ndis802_11IBSS:
1363                         pmlmepriv->fw_state = WIFI_ADHOC_STATE;
1364                         break;
1365         default:
1366                         pmlmepriv->fw_state = WIFI_NULL_STATE;
1367                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
1368                         break;
1369         }
1370
1371         rtw_update_protection(padapter, (cur_network->network.IEs) + sizeof(struct ndis_802_11_fix_ie),
1372                                                                         (cur_network->network.IELength));
1373
1374         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength, (u8) cur_network->network.Configuration.DSConfig);
1375 }
1376
1377 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
1378 /* pnetwork : returns from rtw_joinbss_event_callback */
1379 /* ptarget_wlan: found from scanned_queue */
1380 /* if join_res > 0, for (fw_state ==WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
1381 /* if join_res > 0, for (fw_state ==WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
1382 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
1383 /*  */
1384 /* define REJOIN */
1385 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
1386 {
1387         static u8 retry = 0;
1388         u8 timer_cancelled;
1389         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
1390         struct  sta_priv *pstapriv = &adapter->stapriv;
1391         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1392         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1393         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1394         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1395         unsigned int            the_same_macaddr = false;
1396
1397         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res =%d\n", pnetwork->join_res));
1398
1399         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1400
1401
1402         if (pmlmepriv->assoc_ssid.SsidLength == 0) {
1403                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
1404         } else{
1405                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
1406         }
1407
1408         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1409
1410         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1411         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
1412                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1413                 return;
1414         }
1415
1416         spin_lock_bh(&pmlmepriv->lock);
1417
1418         pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 0;
1419         pmlmepriv->LinkDetectInfo.LowPowerTransitionCount = 0;
1420
1421         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\n rtw_joinbss_event_callback !! spin_lock_irqsave\n"));
1422
1423         if (pnetwork->join_res > 0) {
1424                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1425                 retry = 0;
1426                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1427                         /* s1. find ptarget_wlan */
1428                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1429                                 if (the_same_macaddr == true) {
1430                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1431                                 } else{
1432                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1433                                         if (pcur_wlan)
1434                                                 pcur_wlan->fixed = false;
1435
1436                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1437                                         if (pcur_sta)
1438                                                 rtw_free_stainfo(adapter,  pcur_sta);
1439
1440                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1441                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1442                                                 if (ptarget_wlan)
1443                                                         ptarget_wlan->fixed = true;
1444                                         }
1445                                 }
1446
1447                         } else{
1448                                 ptarget_wlan = _rtw_find_same_network(&pmlmepriv->scanned_queue, pnetwork);
1449                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1450                                         if (ptarget_wlan)
1451                                                 ptarget_wlan->fixed = true;
1452                                 }
1453                         }
1454
1455                         /* s2. update cur_network */
1456                         if (ptarget_wlan) {
1457                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1458                         } else{
1459                                 DBG_871X_LEVEL(_drv_always_, "Can't find ptarget_wlan when joinbss_event callback\n");
1460                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1461                                 goto ignore_joinbss_callback;
1462                         }
1463
1464
1465                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1466                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1467                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1468                                 if (ptarget_sta == NULL) {
1469                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1470                                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1471                                         goto ignore_joinbss_callback;
1472                                 }
1473                         }
1474
1475                         /* s4. indicate connect */
1476                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1477                                 pmlmepriv->cur_network_scanned = ptarget_wlan;
1478                                 rtw_indicate_connect(adapter);
1479                         } else{
1480                                 /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1481                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1482                         }
1483
1484
1485                         /* s5. Cancel assoc_timer */
1486                         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
1487
1488                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancel assoc_timer\n"));
1489
1490                 } else{
1491                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1492                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1493                         goto ignore_joinbss_callback;
1494                 }
1495
1496                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1497
1498         } else if (pnetwork->join_res == -4) {
1499                 rtw_reset_securitypriv(adapter);
1500                 _set_timer(&pmlmepriv->assoc_timer, 1);
1501
1502                 /* rtw_free_assoc_resources(adapter, 1); */
1503
1504                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true) {
1505                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state =%x\n", get_fwstate(pmlmepriv)));
1506                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1507                 }
1508
1509         } else{/* if join_res < 0 (join fails), then try again */
1510
1511                 #ifdef REJOIN
1512                 res = _FAIL;
1513                 if (retry < 2) {
1514                         res = rtw_select_and_join_from_scanned_queue(pmlmepriv);
1515                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_select_and_join_from_scanned_queue again! res:%d\n", res));
1516                 }
1517
1518                 if (res == _SUCCESS) {
1519                         /* extend time of assoc_timer */
1520                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
1521                         retry++;
1522                 } else if (res == 2) {/* there is no need to wait for join */
1523                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1524                         rtw_indicate_connect(adapter);
1525                 } else{
1526                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Set Assoc_Timer = 1; can't find match ssid in scanned_q\n"));
1527                 #endif
1528
1529                         _set_timer(&pmlmepriv->assoc_timer, 1);
1530                         /* rtw_free_assoc_resources(adapter, 1); */
1531                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1532
1533                 #ifdef REJOIN
1534                         retry = 0;
1535                 }
1536                 #endif
1537         }
1538
1539 ignore_joinbss_callback:
1540
1541         spin_unlock_bh(&pmlmepriv->lock);
1542 }
1543
1544 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1545 {
1546         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1547
1548         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1549
1550         rtw_os_xmit_schedule(adapter);
1551 }
1552
1553 /* FOR STA, AP , AD-HOC mode */
1554 void rtw_sta_media_status_rpt(struct adapter *adapter, struct sta_info *psta, u32 mstatus)
1555 {
1556         u16 media_status_rpt;
1557
1558         if (psta == NULL)
1559                 return;
1560
1561         media_status_rpt = (u16)((psta->mac_id<<8)|mstatus); /*   MACID|OPMODE:1 connect */
1562         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status_rpt);
1563 }
1564
1565 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1566 {
1567         struct sta_info *psta;
1568         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1569         struct stassoc_event    *pstassoc       = (struct stassoc_event *)pbuf;
1570         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1571         struct wlan_network     *ptarget_wlan = NULL;
1572
1573         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1574                 return;
1575
1576         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1577                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1578                 if (psta) {
1579                         u8 *passoc_req = NULL;
1580                         u32 assoc_req_len = 0;
1581
1582                         rtw_sta_media_status_rpt(adapter, psta, 1);
1583
1584 #ifndef CONFIG_AUTO_AP_MODE
1585
1586                         ap_sta_info_defer_update(adapter, psta);
1587
1588                         /* report to upper layer */
1589                         DBG_871X("indicate_sta_assoc_event to upper layer - hostapd\n");
1590                         spin_lock_bh(&psta->lock);
1591                         if (psta->passoc_req && psta->assoc_req_len > 0) {
1592                                 passoc_req = rtw_zmalloc(psta->assoc_req_len);
1593                                 if (passoc_req) {
1594                                         assoc_req_len = psta->assoc_req_len;
1595                                         memcpy(passoc_req, psta->passoc_req, assoc_req_len);
1596
1597                                         kfree(psta->passoc_req);
1598                                         psta->passoc_req = NULL;
1599                                         psta->assoc_req_len = 0;
1600                                 }
1601                         }
1602                         spin_unlock_bh(&psta->lock);
1603
1604                         if (passoc_req && assoc_req_len > 0) {
1605                                 rtw_cfg80211_indicate_sta_assoc(adapter, passoc_req, assoc_req_len);
1606
1607                                 kfree(passoc_req);
1608                         }
1609 #endif /* CONFIG_AUTO_AP_MODE */
1610                 }
1611                 return;
1612         }
1613
1614         /* for AD-HOC mode */
1615         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1616         if (psta != NULL) {
1617                 /* the sta have been in sta_info_queue => do nothing */
1618
1619                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1620
1621                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1622         }
1623
1624         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1625         if (psta == NULL) {
1626                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1627                 return;
1628         }
1629
1630         /* to do : init sta_info variable */
1631         psta->qos_option = 0;
1632         psta->mac_id = (uint)pstassoc->cam_id;
1633         /* psta->aid = (uint)pstassoc->cam_id; */
1634         DBG_871X("%s\n", __func__);
1635         /* for ad-hoc mode */
1636         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1637
1638         rtw_sta_media_status_rpt(adapter, psta, 1);
1639
1640         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1641                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1642
1643
1644         psta->ieee8021x_blocked = false;
1645
1646         spin_lock_bh(&pmlmepriv->lock);
1647
1648         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
1649                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
1650                 if (adapter->stapriv.asoc_sta_count == 2) {
1651                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1652                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1653                         pmlmepriv->cur_network_scanned = ptarget_wlan;
1654                         if (ptarget_wlan)
1655                                 ptarget_wlan->fixed = true;
1656                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1657                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1658                         rtw_indicate_connect(adapter);
1659                 }
1660         }
1661
1662         spin_unlock_bh(&pmlmepriv->lock);
1663
1664
1665         mlmeext_sta_add_event_callback(adapter, psta);
1666 }
1667
1668 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1669 {
1670         int mac_id = (-1);
1671         struct sta_info *psta;
1672         struct wlan_network *pwlan = NULL;
1673         struct wlan_bssid_ex    *pdev_network = NULL;
1674         u8 *pibss = NULL;
1675         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1676         struct  stadel_event *pstadel   = (struct stadel_event *)pbuf;
1677         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1678         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1679         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1680
1681         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1682         if (psta)
1683                 mac_id = psta->mac_id;
1684         else
1685                 mac_id = pstadel->mac_id;
1686
1687         DBG_871X("%s(mac_id =%d) =" MAC_FMT "\n", __func__, mac_id, MAC_ARG(pstadel->macaddr));
1688
1689         if (mac_id >= 0) {
1690                 u16 media_status;
1691                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1692                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1693                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1694         }
1695
1696         /* if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) */
1697         if ((pmlmeinfo->state&0x03) == WIFI_FW_AP_STATE)
1698                 return;
1699
1700
1701         mlmeext_sta_del_event_callback(adapter);
1702
1703         spin_lock_bh(&pmlmepriv->lock);
1704
1705         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1706                 u16 reason = *((unsigned short *)(pstadel->rsvd));
1707                 bool roam = false;
1708                 struct wlan_network *roam_target = NULL;
1709
1710                 if (adapter->registrypriv.wifi_spec == 1) {
1711                         roam = false;
1712                 } else if (reason == WLAN_REASON_EXPIRATION_CHK && rtw_chk_roam_flags(adapter, RTW_ROAM_ON_EXPIRED)) {
1713                         roam = true;
1714                 } else if (reason == WLAN_REASON_ACTIVE_ROAM && rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1715                         roam = true;
1716                         roam_target = pmlmepriv->roam_network;
1717                 }
1718 #ifdef CONFIG_INTEL_WIDI
1719                 else if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_CONNECTED) {
1720                         roam = true;
1721                 }
1722 #endif /*  CONFIG_INTEL_WIDI */
1723
1724                 if (roam == true) {
1725                         if (rtw_to_roam(adapter) > 0)
1726                                 rtw_dec_to_roam(adapter); /* this stadel_event is caused by roaming, decrease to_roam */
1727                         else if (rtw_to_roam(adapter) == 0)
1728                                 rtw_set_to_roam(adapter, adapter->registrypriv.max_roaming_times);
1729                 } else {
1730                         rtw_set_to_roam(adapter, 0);
1731                 }
1732
1733                 rtw_free_uc_swdec_pending_queue(adapter);
1734
1735                 rtw_free_assoc_resources(adapter, 1);
1736                 rtw_indicate_disconnect(adapter);
1737
1738                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1739                 /*  remove the network entry in scanned_queue */
1740                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1741                 if (pwlan) {
1742                         pwlan->fixed = false;
1743                         rtw_free_network_nolock(adapter, pwlan);
1744                 }
1745                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1746
1747 #ifdef CONFIG_INTEL_WIDI
1748                 if (!rtw_to_roam(adapter))
1749                         process_intel_widi_disconnect(adapter, 1);
1750 #endif /*  CONFIG_INTEL_WIDI */
1751
1752                 _rtw_roaming(adapter, roam_target);
1753         }
1754
1755         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1756               check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1757
1758                 rtw_free_stainfo(adapter,  psta);
1759
1760                 if (adapter->stapriv.asoc_sta_count == 1) {/* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1761                         /* rtw_indicate_disconnect(adapter);removed@20091105 */
1762                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1763                         /* free old ibss network */
1764                         /* pwlan = rtw_find_network(&pmlmepriv->scanned_queue, pstadel->macaddr); */
1765                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1766                         if (pwlan) {
1767                                 pwlan->fixed = false;
1768                                 rtw_free_network_nolock(adapter, pwlan);
1769                         }
1770                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1771                         /* re-create ibss */
1772                         pdev_network = &(adapter->registrypriv.dev_network);
1773                         pibss = adapter->registrypriv.dev_network.MacAddress;
1774
1775                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1776
1777                         memset(&pdev_network->Ssid, 0, sizeof(struct ndis_802_11_ssid));
1778                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1779
1780                         rtw_update_registrypriv_dev_network(adapter);
1781
1782                         rtw_generate_random_ibss(pibss);
1783
1784                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1785                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1786                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1787                         }
1788
1789                         if (rtw_createbss_cmd(adapter) != _SUCCESS) {
1790
1791                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error =>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1792
1793                         }
1794
1795
1796                 }
1797
1798         }
1799
1800         spin_unlock_bh(&pmlmepriv->lock);
1801 }
1802
1803 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1804 {
1805         struct reportpwrstate_parm *preportpwrstate;
1806
1807         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1808         preportpwrstate = (struct reportpwrstate_parm *)pbuf;
1809         preportpwrstate->state |= (u8)(adapter_to_pwrctl(padapter)->cpwm_tog + 0x80);
1810         cpwm_int_hdl(padapter, preportpwrstate);
1811 }
1812
1813
1814 void rtw_wmm_event_callback(struct adapter *padapter, u8 *pbuf)
1815 {
1816         WMMOnAssocRsp(padapter);
1817 }
1818
1819 /*
1820 * _rtw_join_timeout_handler - Timeout/failure handler for CMD JoinBss
1821 * @adapter: pointer to struct adapter structure
1822 */
1823 void _rtw_join_timeout_handler (struct adapter *adapter)
1824 {
1825         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1826
1827         DBG_871X("%s, fw_state =%x\n", __func__, get_fwstate(pmlmepriv));
1828
1829         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1830                 return;
1831
1832         spin_lock_bh(&pmlmepriv->lock);
1833
1834         if (rtw_to_roam(adapter) > 0) { /* join timeout caused by roaming */
1835                 while (1) {
1836                         rtw_dec_to_roam(adapter);
1837                         if (rtw_to_roam(adapter) != 0) { /* try another */
1838                                 int do_join_r;
1839                                 DBG_871X("%s try another roaming\n", __func__);
1840                                 do_join_r = rtw_do_join(adapter);
1841                                 if (_SUCCESS != do_join_r) {
1842                                         DBG_871X("%s roaming do_join return %d\n", __func__, do_join_r);
1843                                         continue;
1844                                 }
1845                                 break;
1846                         } else {
1847 #ifdef CONFIG_INTEL_WIDI
1848                                 if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING) {
1849                                         memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1850                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1851                                         DBG_871X("change to widi listen\n");
1852                                 }
1853 #endif /*  CONFIG_INTEL_WIDI */
1854                                 DBG_871X("%s We've try roaming but fail\n", __func__);
1855                                 rtw_indicate_disconnect(adapter);
1856                                 break;
1857                         }
1858                 }
1859
1860         } else{
1861                 rtw_indicate_disconnect(adapter);
1862                 free_scanqueue(pmlmepriv);/*  */
1863
1864                 /* indicate disconnect for the case that join_timeout and check_fwstate != FW_LINKED */
1865                 rtw_cfg80211_indicate_disconnect(adapter);
1866
1867         }
1868
1869         spin_unlock_bh(&pmlmepriv->lock);
1870 }
1871
1872 /*
1873 * rtw_scan_timeout_handler - Timeout/Failure handler for CMD SiteSurvey
1874 * @adapter: pointer to struct adapter structure
1875 */
1876 void rtw_scan_timeout_handler (struct adapter *adapter)
1877 {
1878         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1879
1880         DBG_871X(FUNC_ADPT_FMT" fw_state =%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1881
1882         spin_lock_bh(&pmlmepriv->lock);
1883
1884         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1885
1886         spin_unlock_bh(&pmlmepriv->lock);
1887
1888         rtw_indicate_scan_done(adapter, true);
1889 }
1890
1891 void rtw_mlme_reset_auto_scan_int(struct adapter *adapter)
1892 {
1893         struct mlme_priv *mlme = &adapter->mlmepriv;
1894         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1895         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1896
1897         if (pmlmeinfo->VHT_enable) /* disable auto scan when connect to 11AC AP */
1898                 mlme->auto_scan_int_ms = 0;
1899         else if (adapter->registrypriv.wifi_spec && is_client_associated_to_ap(adapter) == true)
1900                 mlme->auto_scan_int_ms = 60*1000;
1901         else if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1902                 if (check_fwstate(mlme, WIFI_STATION_STATE) && check_fwstate(mlme, _FW_LINKED))
1903                         mlme->auto_scan_int_ms = mlme->roam_scan_int_ms;
1904         } else
1905                 mlme->auto_scan_int_ms = 0; /* disabled */
1906
1907         return;
1908 }
1909
1910 static void rtw_auto_scan_handler(struct adapter *padapter)
1911 {
1912         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1913
1914         rtw_mlme_reset_auto_scan_int(padapter);
1915
1916         if (pmlmepriv->auto_scan_int_ms != 0
1917                 && jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time) > pmlmepriv->auto_scan_int_ms) {
1918
1919                 if (!padapter->registrypriv.wifi_spec) {
1920                         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == true) {
1921                                 DBG_871X(FUNC_ADPT_FMT" _FW_UNDER_SURVEY|_FW_UNDER_LINKING\n", FUNC_ADPT_ARG(padapter));
1922                                 goto exit;
1923                         }
1924
1925                         if (pmlmepriv->LinkDetectInfo.bBusyTraffic == true) {
1926                                 DBG_871X(FUNC_ADPT_FMT" exit BusyTraffic\n", FUNC_ADPT_ARG(padapter));
1927                                 goto exit;
1928                         }
1929                 }
1930
1931                 DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1932
1933                 rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1934         }
1935
1936 exit:
1937         return;
1938 }
1939
1940 void rtw_dynamic_check_timer_handlder(struct adapter *adapter)
1941 {
1942         if (!adapter)
1943                 return;
1944
1945         if (adapter->hw_init_completed == false)
1946                 return;
1947
1948         if ((adapter->bDriverStopped == true) || (adapter->bSurpriseRemoved == true))
1949                 return;
1950
1951         if (adapter->net_closed == true)
1952                 return;
1953
1954         if (is_primary_adapter(adapter))
1955                 DBG_871X("IsBtDisabled =%d, IsBtControlLps =%d\n", rtw_btcoex_IsBtDisabled(adapter), rtw_btcoex_IsBtControlLps(adapter));
1956
1957         if ((adapter_to_pwrctl(adapter)->bFwCurrentInPSMode == true)
1958                 && (rtw_btcoex_IsBtControlLps(adapter) == false)
1959                 ) {
1960                 u8 bEnterPS;
1961
1962                 linked_status_chk(adapter);
1963
1964                 bEnterPS = traffic_status_watchdog(adapter, 1);
1965                 if (bEnterPS) {
1966                         /* rtw_lps_ctrl_wk_cmd(adapter, LPS_CTRL_ENTER, 1); */
1967                         rtw_hal_dm_watchdog_in_lps(adapter);
1968                 } else{
1969                         /* call rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_LEAVE, 1) in traffic_status_watchdog() */
1970                 }
1971
1972         } else{
1973                 if (is_primary_adapter(adapter)) {
1974                         rtw_dynamic_chk_wk_cmd(adapter);
1975                 }
1976         }
1977
1978         /* auto site survey */
1979         rtw_auto_scan_handler(adapter);
1980 }
1981
1982
1983 inline bool rtw_is_scan_deny(struct adapter *adapter)
1984 {
1985         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1986         return (atomic_read(&mlmepriv->set_scan_deny) != 0) ? true : false;
1987 }
1988
1989 inline void rtw_clear_scan_deny(struct adapter *adapter)
1990 {
1991         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
1992         atomic_set(&mlmepriv->set_scan_deny, 0);
1993
1994         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
1995 }
1996
1997 void rtw_set_scan_deny_timer_hdl(struct adapter *adapter)
1998 {
1999         rtw_clear_scan_deny(adapter);
2000 }
2001
2002 void rtw_set_scan_deny(struct adapter *adapter, u32 ms)
2003 {
2004         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2005
2006         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
2007         atomic_set(&mlmepriv->set_scan_deny, 1);
2008         _set_timer(&mlmepriv->set_scan_deny_timer, ms);
2009 }
2010
2011 /*
2012 * Select a new roaming candidate from the original @param candidate and @param competitor
2013 * @return true: candidate is updated
2014 * @return false: candidate is not updated
2015 */
2016 static int rtw_check_roaming_candidate(struct mlme_priv *mlme
2017         , struct wlan_network **candidate, struct wlan_network *competitor)
2018 {
2019         int updated = false;
2020         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
2021
2022         if (is_same_ess(&competitor->network, &mlme->cur_network.network) == false)
2023                 goto exit;
2024
2025         if (rtw_is_desired_network(adapter, competitor) == false)
2026                 goto exit;
2027
2028         DBG_871X("roam candidate:%s %s("MAC_FMT", ch%3u) rssi:%d, age:%5d\n",
2029                 (competitor == mlme->cur_network_scanned)?"*":" ",
2030                 competitor->network.Ssid.Ssid,
2031                 MAC_ARG(competitor->network.MacAddress),
2032                 competitor->network.Configuration.DSConfig,
2033                 (int)competitor->network.Rssi,
2034                 jiffies_to_msecs(jiffies - competitor->last_scanned)
2035         );
2036
2037         /* got specific addr to roam */
2038         if (!is_zero_mac_addr(mlme->roam_tgt_addr)) {
2039                 if (!memcmp(mlme->roam_tgt_addr, competitor->network.MacAddress, ETH_ALEN))
2040                         goto update;
2041                 else
2042                         goto exit;
2043         }
2044         if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms)
2045                 goto exit;
2046
2047         if (competitor->network.Rssi - mlme->cur_network_scanned->network.Rssi < mlme->roam_rssi_diff_th)
2048                 goto exit;
2049
2050         if (*candidate != NULL && (*candidate)->network.Rssi >= competitor->network.Rssi)
2051                 goto exit;
2052
2053 update:
2054         *candidate = competitor;
2055         updated = true;
2056
2057 exit:
2058         return updated;
2059 }
2060
2061 int rtw_select_roaming_candidate(struct mlme_priv *mlme)
2062 {
2063         int ret = _FAIL;
2064         struct list_head        *phead;
2065         struct adapter *adapter;
2066         struct __queue  *queue  = &(mlme->scanned_queue);
2067         struct  wlan_network    *pnetwork = NULL;
2068         struct  wlan_network    *candidate = NULL;
2069
2070         if (mlme->cur_network_scanned == NULL) {
2071                 rtw_warn_on(1);
2072                 return ret;
2073         }
2074
2075         spin_lock_bh(&(mlme->scanned_queue.lock));
2076         phead = get_list_head(queue);
2077         adapter = (struct adapter *)mlme->nic_hdl;
2078
2079         mlme->pscanned = get_next(phead);
2080
2081         while (phead != mlme->pscanned) {
2082
2083                 pnetwork = LIST_CONTAINOR(mlme->pscanned, struct wlan_network, list);
2084                 if (pnetwork == NULL) {
2085                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2086                         ret = _FAIL;
2087                         goto exit;
2088                 }
2089
2090                 mlme->pscanned = get_next(mlme->pscanned);
2091
2092                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2093                         , pnetwork->network.Ssid.Ssid
2094                         , MAC_ARG(pnetwork->network.MacAddress)
2095                         , pnetwork->network.Configuration.DSConfig
2096                         , (int)pnetwork->network.Rssi);
2097
2098                 rtw_check_roaming_candidate(mlme, &candidate, pnetwork);
2099
2100         }
2101
2102         if (candidate == NULL) {
2103                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2104                 ret = _FAIL;
2105                 goto exit;
2106         } else {
2107                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2108                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2109                         candidate->network.Configuration.DSConfig);
2110
2111                 mlme->roam_network = candidate;
2112
2113                 if (!memcmp(candidate->network.MacAddress, mlme->roam_tgt_addr, ETH_ALEN))
2114                         memset(mlme->roam_tgt_addr, 0, ETH_ALEN);
2115         }
2116
2117         ret = _SUCCESS;
2118 exit:
2119         spin_unlock_bh(&(mlme->scanned_queue.lock));
2120
2121         return ret;
2122 }
2123
2124 /*
2125 * Select a new join candidate from the original @param candidate and @param competitor
2126 * @return true: candidate is updated
2127 * @return false: candidate is not updated
2128 */
2129 static int rtw_check_join_candidate(struct mlme_priv *mlme
2130         , struct wlan_network **candidate, struct wlan_network *competitor)
2131 {
2132         int updated = false;
2133         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
2134
2135
2136         /* check bssid, if needed */
2137         if (mlme->assoc_by_bssid == true) {
2138                 if (memcmp(competitor->network.MacAddress, mlme->assoc_bssid, ETH_ALEN))
2139                         goto exit;
2140         }
2141
2142         /* check ssid, if needed */
2143         if (mlme->assoc_ssid.Ssid[0] && mlme->assoc_ssid.SsidLength) {
2144                 if (competitor->network.Ssid.SsidLength != mlme->assoc_ssid.SsidLength
2145                         || memcmp(competitor->network.Ssid.Ssid, mlme->assoc_ssid.Ssid, mlme->assoc_ssid.SsidLength)
2146                 )
2147                         goto exit;
2148         }
2149
2150         if (rtw_is_desired_network(adapter, competitor)  == false)
2151                 goto exit;
2152
2153         if (rtw_to_roam(adapter) > 0) {
2154                 if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms
2155                         || is_same_ess(&competitor->network, &mlme->cur_network.network) == false
2156                 )
2157                         goto exit;
2158         }
2159
2160         if (*candidate == NULL || (*candidate)->network.Rssi < competitor->network.Rssi) {
2161                 *candidate = competitor;
2162                 updated = true;
2163         }
2164
2165         if (updated) {
2166                 DBG_871X("[by_bssid:%u][assoc_ssid:%s]"
2167                         "[to_roam:%u] "
2168                         "new candidate: %s("MAC_FMT", ch%u) rssi:%d\n",
2169                         mlme->assoc_by_bssid,
2170                         mlme->assoc_ssid.Ssid,
2171                         rtw_to_roam(adapter),
2172                         (*candidate)->network.Ssid.Ssid,
2173                         MAC_ARG((*candidate)->network.MacAddress),
2174                         (*candidate)->network.Configuration.DSConfig,
2175                         (int)(*candidate)->network.Rssi
2176                 );
2177         }
2178
2179 exit:
2180         return updated;
2181 }
2182
2183 /*
2184 Calling context:
2185 The caller of the sub-routine will be in critical section...
2186
2187 The caller must hold the following spinlock
2188
2189 pmlmepriv->lock
2190
2191
2192 */
2193
2194 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
2195 {
2196         int ret;
2197         struct list_head        *phead;
2198         struct adapter *adapter;
2199         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
2200         struct  wlan_network    *pnetwork = NULL;
2201         struct  wlan_network    *candidate = NULL;
2202
2203         adapter = (struct adapter *)pmlmepriv->nic_hdl;
2204
2205         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
2206
2207         if (pmlmepriv->roam_network) {
2208                 candidate = pmlmepriv->roam_network;
2209                 pmlmepriv->roam_network = NULL;
2210                 goto candidate_exist;
2211         }
2212
2213         phead = get_list_head(queue);
2214         pmlmepriv->pscanned = get_next(phead);
2215
2216         while (phead != pmlmepriv->pscanned) {
2217
2218                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
2219                 if (pnetwork == NULL) {
2220                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2221                         ret = _FAIL;
2222                         goto exit;
2223                 }
2224
2225                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
2226
2227                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2228                         , pnetwork->network.Ssid.Ssid
2229                         , MAC_ARG(pnetwork->network.MacAddress)
2230                         , pnetwork->network.Configuration.DSConfig
2231                         , (int)pnetwork->network.Rssi);
2232
2233                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
2234
2235         }
2236
2237         if (candidate == NULL) {
2238                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2239 #ifdef CONFIG_WOWLAN
2240                 _clr_fwstate_(pmlmepriv, _FW_LINKED|_FW_UNDER_LINKING);
2241 #endif
2242                 ret = _FAIL;
2243                 goto exit;
2244         } else {
2245                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2246                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2247                         candidate->network.Configuration.DSConfig);
2248                 goto candidate_exist;
2249         }
2250
2251 candidate_exist:
2252
2253         /*  check for situation of  _FW_LINKED */
2254         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
2255                 DBG_871X("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
2256
2257                 rtw_disassoc_cmd(adapter, 0, true);
2258                 rtw_indicate_disconnect(adapter);
2259                 rtw_free_assoc_resources(adapter, 0);
2260         }
2261
2262         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
2263         ret = rtw_joinbss_cmd(adapter, candidate);
2264
2265 exit:
2266         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
2267         return ret;
2268 }
2269
2270 sint rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
2271 {
2272         struct  cmd_obj *pcmd;
2273         struct  setauth_parm *psetauthparm;
2274         struct  cmd_priv *pcmdpriv = &(adapter->cmdpriv);
2275         sint            res = _SUCCESS;
2276
2277         pcmd = (struct  cmd_obj *)rtw_zmalloc(sizeof(struct     cmd_obj));
2278         if (pcmd == NULL) {
2279                 res = _FAIL;  /* try again */
2280                 goto exit;
2281         }
2282
2283         psetauthparm = (struct setauth_parm *)rtw_zmalloc(sizeof(struct setauth_parm));
2284         if (psetauthparm == NULL) {
2285                 kfree((unsigned char *)pcmd);
2286                 res = _FAIL;
2287                 goto exit;
2288         }
2289
2290         memset(psetauthparm, 0, sizeof(struct setauth_parm));
2291         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
2292
2293         pcmd->cmdcode = _SetAuth_CMD_;
2294         pcmd->parmbuf = (unsigned char *)psetauthparm;
2295         pcmd->cmdsz =  (sizeof(struct setauth_parm));
2296         pcmd->rsp = NULL;
2297         pcmd->rspsz = 0;
2298
2299
2300         INIT_LIST_HEAD(&pcmd->list);
2301
2302         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("after enqueue set_auth_cmd, auth_mode =%x\n", psecuritypriv->dot11AuthAlgrthm));
2303
2304         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2305
2306 exit:
2307         return res;
2308 }
2309
2310 sint rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, sint keyid, u8 set_tx, bool enqueue)
2311 {
2312         u8 keylen;
2313         struct cmd_obj          *pcmd;
2314         struct setkey_parm      *psetkeyparm;
2315         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
2316         sint    res = _SUCCESS;
2317
2318         psetkeyparm = (struct setkey_parm *)rtw_zmalloc(sizeof(struct setkey_parm));
2319         if (psetkeyparm == NULL) {
2320                 res = _FAIL;
2321                 goto exit;
2322         }
2323         memset(psetkeyparm, 0, sizeof(struct setkey_parm));
2324
2325         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
2326                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
2327                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(unsigned char)psecuritypriv->dot118021XGrpPrivacy =%d\n", psetkeyparm->algorithm));
2328         } else {
2329                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
2330                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(u8)psecuritypriv->dot11PrivacyAlgrthm =%d\n", psetkeyparm->algorithm));
2331
2332         }
2333         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
2334         psetkeyparm->set_tx = set_tx;
2335         if (is_wep_enc(psetkeyparm->algorithm))
2336                 adapter->securitypriv.key_mask |= BIT(psetkeyparm->keyid);
2337
2338         DBG_871X("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n", psetkeyparm->algorithm, psetkeyparm->keyid, adapter->securitypriv.key_mask);
2339         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =%d psetkeyparm->keyid =(u8)keyid =%d\n", psetkeyparm->algorithm, keyid));
2340
2341         switch (psetkeyparm->algorithm) {
2342
2343         case _WEP40_:
2344                 keylen = 5;
2345                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2346                 break;
2347         case _WEP104_:
2348                 keylen = 13;
2349                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2350                 break;
2351         case _TKIP_:
2352                 keylen = 16;
2353                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2354                 psetkeyparm->grpkey = 1;
2355                 break;
2356         case _AES_:
2357                 keylen = 16;
2358                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2359                 psetkeyparm->grpkey = 1;
2360                 break;
2361         default:
2362                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm = %x (must be 1 or 2 or 4 or 5)\n", psecuritypriv->dot11PrivacyAlgrthm));
2363                 res = _FAIL;
2364                 kfree((unsigned char *)psetkeyparm);
2365                 goto exit;
2366         }
2367
2368
2369         if (enqueue) {
2370                 pcmd = (struct  cmd_obj *)rtw_zmalloc(sizeof(struct     cmd_obj));
2371                 if (pcmd == NULL) {
2372                         kfree((unsigned char *)psetkeyparm);
2373                         res = _FAIL;  /* try again */
2374                         goto exit;
2375                 }
2376
2377                 pcmd->cmdcode = _SetKey_CMD_;
2378                 pcmd->parmbuf = (u8 *)psetkeyparm;
2379                 pcmd->cmdsz =  (sizeof(struct setkey_parm));
2380                 pcmd->rsp = NULL;
2381                 pcmd->rspsz = 0;
2382
2383                 INIT_LIST_HEAD(&pcmd->list);
2384
2385                 /* sema_init(&(pcmd->cmd_sem), 0); */
2386
2387                 res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2388         } else{
2389                 setkey_hdl(adapter, (u8 *)psetkeyparm);
2390                 kfree((u8 *) psetkeyparm);
2391         }
2392 exit:
2393         return res;
2394 }
2395
2396 /* adjust IEs for rtw_joinbss_cmd in WMM */
2397 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
2398 {
2399         unsigned        int ielength = 0;
2400         unsigned int i, j;
2401
2402         i = 12; /* after the fixed IE */
2403         while (i < in_len) {
2404                 ielength = initial_out_len;
2405
2406                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) { /* WMM element ID and OUI */
2407                         for (j = i; j < i + 9; j++) {
2408                                         out_ie[ielength] = in_ie[j];
2409                                         ielength++;
2410                         }
2411                         out_ie[initial_out_len + 1] = 0x07;
2412                         out_ie[initial_out_len + 6] = 0x00;
2413                         out_ie[initial_out_len + 8] = 0x00;
2414
2415                         break;
2416                 }
2417
2418                 i += (in_ie[i+1]+2); /*  to the next IE element */
2419         }
2420
2421         return ielength;
2422
2423 }
2424
2425
2426 /*  */
2427 /*  Ported from 8185: IsInPreAuthKeyList(). (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.) */
2428 /*  Added by Annie, 2006-05-07. */
2429 /*  */
2430 /*  Search by BSSID, */
2431 /*  Return Value: */
2432 /*              -1              :if there is no pre-auth key in the  table */
2433 /*              >= 0            :if there is pre-auth key, and   return the entry id */
2434 /*  */
2435 /*  */
2436
2437 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
2438 {
2439         struct security_priv *psecuritypriv = &Adapter->securitypriv;
2440         int i = 0;
2441
2442         do {
2443                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
2444                                 (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN))) {
2445                         break;
2446                 } else{
2447                         i++;
2448                         /* continue; */
2449                 }
2450
2451         } while (i < NUM_PMKID_CACHE);
2452
2453         if (i == NUM_PMKID_CACHE) {
2454                 i = -1;/*  Could not find. */
2455         } else {
2456                 /*  There is one Pre-Authentication Key for the specific BSSID. */
2457         }
2458
2459         return i;
2460
2461 }
2462
2463 /*  */
2464 /*  Check the RSN IE length */
2465 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
2466 /*  0-11th element in the array are the fixed IE */
2467 /*  12th element in the array is the IE */
2468 /*  13th element in the array is the IE length */
2469 /*  */
2470
2471 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
2472 {
2473         struct security_priv *psecuritypriv = &Adapter->securitypriv;
2474
2475         if (ie[13] <= 20) {
2476                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
2477                         ie[ie_len] = 1;
2478                         ie_len++;
2479                         ie[ie_len] = 0; /* PMKID count = 0x0100 */
2480                         ie_len++;
2481                         memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
2482
2483                         ie_len += 16;
2484                         ie[13] += 18;/* PMKID length = 2+16 */
2485
2486         }
2487         return ie_len;
2488 }
2489
2490 sint rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
2491 {
2492         u8 authmode = 0x0;
2493         uint    ielength;
2494         int iEntry;
2495
2496         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
2497         struct security_priv *psecuritypriv = &adapter->securitypriv;
2498         uint    ndisauthmode = psecuritypriv->ndisauthtype;
2499
2500         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
2501                  ("+rtw_restruct_sec_ie: ndisauthmode =%d ndissecuritytype =%d\n",
2502                   ndisauthmode, ndissecuritytype));
2503
2504         /* copy fixed ie only */
2505         memcpy(out_ie, in_ie, 12);
2506         ielength = 12;
2507         if ((ndisauthmode == Ndis802_11AuthModeWPA) || (ndisauthmode == Ndis802_11AuthModeWPAPSK))
2508                         authmode = _WPA_IE_ID_;
2509         if ((ndisauthmode == Ndis802_11AuthModeWPA2) || (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
2510                         authmode = _WPA2_IE_ID_;
2511
2512         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
2513                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
2514
2515                 ielength += psecuritypriv->wps_ie_len;
2516         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
2517                 /* copy RSN or SSN */
2518                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
2519                 /* debug for CONFIG_IEEE80211W
2520                 {
2521                         int jj;
2522                         printk("supplicant_ie_length =%d &&&&&&&&&&&&&&&&&&&\n", psecuritypriv->supplicant_ie[1]+2);
2523                         for (jj = 0; jj < psecuritypriv->supplicant_ie[1]+2; jj++)
2524                                 printk(" %02x ", psecuritypriv->supplicant_ie[jj]);
2525                         printk("\n");
2526                 }*/
2527                 ielength += psecuritypriv->supplicant_ie[1]+2;
2528                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
2529         }
2530
2531         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
2532         if (iEntry < 0) {
2533                 return ielength;
2534         } else{
2535                 if (authmode == _WPA2_IE_ID_)
2536                         ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
2537         }
2538         return ielength;
2539 }
2540
2541 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
2542 {
2543         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2544         struct eeprom_priv *peepriv = &adapter->eeprompriv;
2545         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2546         u8 *myhwaddr = myid(peepriv);
2547
2548         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
2549
2550         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
2551
2552         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_conf);
2553         pdev_network->Configuration.BeaconPeriod = 100;
2554         pdev_network->Configuration.FHConfig.Length = 0;
2555         pdev_network->Configuration.FHConfig.HopPattern = 0;
2556         pdev_network->Configuration.FHConfig.HopSet = 0;
2557         pdev_network->Configuration.FHConfig.DwellTime = 0;
2558 }
2559
2560 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
2561 {
2562         int sz = 0;
2563         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2564         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2565         struct  security_priv *psecuritypriv = &adapter->securitypriv;
2566         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
2567         /* struct       xmit_priv *pxmitpriv = &adapter->xmitpriv; */
2568
2569         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0) ; /*  adhoc no 802.1x */
2570
2571         pdev_network->Rssi = 0;
2572
2573         switch (pregistrypriv->wireless_mode) {
2574         case WIRELESS_11B:
2575                 pdev_network->NetworkTypeInUse = (Ndis802_11DS);
2576                 break;
2577         case WIRELESS_11G:
2578         case WIRELESS_11BG:
2579         case WIRELESS_11_24N:
2580         case WIRELESS_11G_24N:
2581         case WIRELESS_11BG_24N:
2582                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2583                 break;
2584         case WIRELESS_11A:
2585         case WIRELESS_11A_5N:
2586                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2587                 break;
2588         case WIRELESS_11ABGN:
2589                 if (pregistrypriv->channel > 14)
2590                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2591                 else
2592                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2593                 break;
2594         default:
2595                 /*  TODO */
2596                 break;
2597         }
2598
2599         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
2600         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("pregistrypriv->channel =%d, pdev_network->Configuration.DSConfig = 0x%x\n", pregistrypriv->channel, pdev_network->Configuration.DSConfig));
2601
2602         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
2603                 pdev_network->Configuration.ATIMWindow = (0);
2604
2605         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
2606
2607         /*  1. Supported rates */
2608         /*  2. IE */
2609
2610         /* rtw_set_supported_rate(pdev_network->SupportedRates, pregistrypriv->wireless_mode) ;  will be called in rtw_generate_ie */
2611         sz = rtw_generate_ie(pregistrypriv);
2612
2613         pdev_network->IELength = sz;
2614
2615         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
2616
2617         /* notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd(); */
2618         /* pdev_network->IELength = cpu_to_le32(sz); */
2619 }
2620
2621 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
2622 {
2623 }
2624
2625 /* the function is at passive_level */
2626 void rtw_joinbss_reset(struct adapter *padapter)
2627 {
2628         u8 threshold;
2629         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2630
2631         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2632
2633         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
2634
2635         pmlmepriv->num_FortyMHzIntolerant = 0;
2636
2637         pmlmepriv->num_sta_no_ht = 0;
2638
2639         phtpriv->ampdu_enable = false;/* reset to disabled */
2640
2641         /*  TH = 1 => means that invalidate usb rx aggregation */
2642         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
2643         if (phtpriv->ht_option) {
2644                 if (padapter->registrypriv.wifi_spec == 1)
2645                         threshold = 1;
2646                 else
2647                         threshold = 0;
2648                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2649         } else{
2650                 threshold = 1;
2651                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2652         }
2653 }
2654
2655 void rtw_ht_use_default_setting(struct adapter *padapter)
2656 {
2657         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2658         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2659         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2660         bool            bHwLDPCSupport = false, bHwSTBCSupport = false;
2661         bool            bHwSupportBeamformer = false, bHwSupportBeamformee = false;
2662
2663         if (pregistrypriv->wifi_spec)
2664                 phtpriv->bss_coexist = 1;
2665         else
2666                 phtpriv->bss_coexist = 0;
2667
2668         phtpriv->sgi_40m = TEST_FLAG(pregistrypriv->short_gi, BIT1) ? true : false;
2669         phtpriv->sgi_20m = TEST_FLAG(pregistrypriv->short_gi, BIT0) ? true : false;
2670
2671         /*  LDPC support */
2672         rtw_hal_get_def_var(padapter, HAL_DEF_RX_LDPC, (u8 *)&bHwLDPCSupport);
2673         CLEAR_FLAGS(phtpriv->ldpc_cap);
2674         if (bHwLDPCSupport) {
2675                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT4))
2676                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_RX);
2677         }
2678         rtw_hal_get_def_var(padapter, HAL_DEF_TX_LDPC, (u8 *)&bHwLDPCSupport);
2679         if (bHwLDPCSupport) {
2680                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT5))
2681                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_TX);
2682         }
2683         if (phtpriv->ldpc_cap)
2684                 DBG_871X("[HT] Support LDPC = 0x%02X\n", phtpriv->ldpc_cap);
2685
2686         /*  STBC */
2687         rtw_hal_get_def_var(padapter, HAL_DEF_TX_STBC, (u8 *)&bHwSTBCSupport);
2688         CLEAR_FLAGS(phtpriv->stbc_cap);
2689         if (bHwSTBCSupport) {
2690                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT5))
2691                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX);
2692         }
2693         rtw_hal_get_def_var(padapter, HAL_DEF_RX_STBC, (u8 *)&bHwSTBCSupport);
2694         if (bHwSTBCSupport) {
2695                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT4))
2696                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX);
2697         }
2698         if (phtpriv->stbc_cap)
2699                 DBG_871X("[HT] Support STBC = 0x%02X\n", phtpriv->stbc_cap);
2700
2701         /*  Beamforming setting */
2702         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMER, (u8 *)&bHwSupportBeamformer);
2703         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMEE, (u8 *)&bHwSupportBeamformee);
2704         CLEAR_FLAGS(phtpriv->beamform_cap);
2705         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT4) && bHwSupportBeamformer) {
2706                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE);
2707                 DBG_871X("[HT] Support Beamformer\n");
2708         }
2709         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT5) && bHwSupportBeamformee) {
2710                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE);
2711                 DBG_871X("[HT] Support Beamformee\n");
2712         }
2713 }
2714
2715 void rtw_build_wmm_ie_ht(struct adapter *padapter, u8 *out_ie, uint *pout_len)
2716 {
2717         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
2718         int out_len;
2719         u8 *pframe;
2720
2721         if (padapter->mlmepriv.qospriv.qos_option == 0) {
2722                 out_len = *pout_len;
2723                 pframe = rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_,
2724                                                         _WMM_IE_Length_, WMM_IE, pout_len);
2725
2726                 padapter->mlmepriv.qospriv.qos_option = 1;
2727         }
2728 }
2729
2730 /* the function is >= passive_level */
2731 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len, u8 channel)
2732 {
2733         u32 ielen, out_len;
2734         enum HT_CAP_AMPDU_FACTOR max_rx_ampdu_factor;
2735         unsigned char *p, *pframe;
2736         struct rtw_ieee80211_ht_cap ht_capie;
2737         u8 cbw40_enable = 0, stbc_rx_enable = 0, rf_type = 0, operation_bw = 0;
2738         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2739         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2740         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2741         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2742
2743         phtpriv->ht_option = false;
2744
2745         out_len = *pout_len;
2746
2747         memset(&ht_capie, 0, sizeof(struct rtw_ieee80211_ht_cap));
2748
2749         ht_capie.cap_info = cpu_to_le16(IEEE80211_HT_CAP_DSSSCCK40);
2750
2751         if (phtpriv->sgi_20m)
2752                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_20);
2753
2754         /* Get HT BW */
2755         if (in_ie == NULL) {
2756                 /* TDLS: TODO 20/40 issue */
2757                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
2758                         operation_bw = padapter->mlmeextpriv.cur_bwmode;
2759                         if (operation_bw > CHANNEL_WIDTH_40)
2760                                 operation_bw = CHANNEL_WIDTH_40;
2761                 } else
2762                         /* TDLS: TODO 40? */
2763                         operation_bw = CHANNEL_WIDTH_40;
2764         } else {
2765                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
2766                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2767                         struct HT_info_element *pht_info = (struct HT_info_element *)(p+2);
2768                         if (pht_info->infos[0] & BIT(2)) {
2769                                 switch (pht_info->infos[0] & 0x3) {
2770                                 case 1:
2771                                 case 3:
2772                                         operation_bw = CHANNEL_WIDTH_40;
2773                                         break;
2774                                 default:
2775                                         operation_bw = CHANNEL_WIDTH_20;
2776                                         break;
2777                                 }
2778                         } else {
2779                                 operation_bw = CHANNEL_WIDTH_20;
2780                         }
2781                 }
2782         }
2783
2784         /* to disable 40M Hz support while gd_bw_40MHz_en = 0 */
2785         if (channel > 14) {
2786                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
2787                         cbw40_enable = 1;
2788         } else {
2789                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
2790                         cbw40_enable = 1;
2791         }
2792
2793         if ((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) {
2794                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH);
2795                 if (phtpriv->sgi_40m)
2796                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_40);
2797         }
2798
2799         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX))
2800                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_TX_STBC);
2801
2802         /* todo: disable SM power save mode */
2803         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SM_PS);
2804
2805         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX)) {
2806                 if ((channel <= 14 && pregistrypriv->rx_stbc == 0x1) || /* enable for 2.4GHz */
2807                         (pregistrypriv->wifi_spec == 1)) {
2808                         stbc_rx_enable = 1;
2809                         DBG_871X("declare supporting RX STBC\n");
2810                 }
2811         }
2812
2813         /* fill default supported_mcs_set */
2814         memcpy(ht_capie.supp_mcs_set, pmlmeext->default_supported_mcs_set, 16);
2815
2816         /* update default supported_mcs_set */
2817         rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2818
2819         switch (rf_type) {
2820         case RF_1T1R:
2821                 if (stbc_rx_enable)
2822                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_1R);/* RX STBC One spatial stream */
2823
2824                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_1R);
2825                 break;
2826
2827         case RF_2T2R:
2828         case RF_1T2R:
2829         default:
2830                 if (stbc_rx_enable)
2831                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_2R);/* RX STBC two spatial stream */
2832
2833                 #ifdef CONFIG_DISABLE_MCS13TO15
2834                 if (((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) && (pregistrypriv->wifi_spec != 1))
2835                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R_13TO15_OFF);
2836                 else
2837                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
2838                 #else /* CONFIG_DISABLE_MCS13TO15 */
2839                         set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
2840                 #endif /* CONFIG_DISABLE_MCS13TO15 */
2841                 break;
2842         }
2843
2844         {
2845                 u32 rx_packet_offset, max_recvbuf_sz;
2846                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
2847                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
2848         }
2849
2850         if (padapter->driver_rx_ampdu_factor != 0xFF)
2851                 max_rx_ampdu_factor =
2852                   (enum HT_CAP_AMPDU_FACTOR)padapter->driver_rx_ampdu_factor;
2853         else
2854                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR,
2855                                     &max_rx_ampdu_factor);
2856
2857         /* rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor); */
2858         ht_capie.ampdu_params_info = (max_rx_ampdu_factor&0x03);
2859
2860         if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
2861                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&(0x07<<2));
2862         else
2863                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
2864
2865         pframe = rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
2866                                                 sizeof(struct rtw_ieee80211_ht_cap), (unsigned char *)&ht_capie, pout_len);
2867
2868         phtpriv->ht_option = true;
2869
2870         if (in_ie != NULL) {
2871                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
2872                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2873                         out_len = *pout_len;
2874                         pframe = rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2, pout_len);
2875                 }
2876         }
2877
2878         return phtpriv->ht_option;
2879
2880 }
2881
2882 /* the function is > passive_level (in critical_section) */
2883 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len, u8 channel)
2884 {
2885         u8 *p, max_ampdu_sz;
2886         int len;
2887         /* struct sta_info *bmc_sta, *psta; */
2888         struct rtw_ieee80211_ht_cap *pht_capie;
2889         struct ieee80211_ht_addt_info *pht_addtinfo;
2890         /* struct recv_reorder_ctrl *preorder_ctrl; */
2891         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2892         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2893         /* struct recv_priv *precvpriv = &padapter->recvpriv; */
2894         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2895         /* struct wlan_network *pcur_network = &(pmlmepriv->cur_network);; */
2896         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2897         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
2898         u8 cbw40_enable = 0;
2899
2900
2901         if (!phtpriv->ht_option)
2902                 return;
2903
2904         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
2905                 return;
2906
2907         DBG_871X("+rtw_update_ht_cap()\n");
2908
2909         /* maybe needs check if ap supports rx ampdu. */
2910         if ((phtpriv->ampdu_enable == false) && (pregistrypriv->ampdu_enable == 1)) {
2911                 if (pregistrypriv->wifi_spec == 1) {
2912                         /* remove this part because testbed AP should disable RX AMPDU */
2913                         /* phtpriv->ampdu_enable = false; */
2914                         phtpriv->ampdu_enable = true;
2915                 } else {
2916                         phtpriv->ampdu_enable = true;
2917                 }
2918         } else if (pregistrypriv->ampdu_enable == 2) {
2919                 /* remove this part because testbed AP should disable RX AMPDU */
2920                 /* phtpriv->ampdu_enable = true; */
2921         }
2922
2923
2924         /* check Max Rx A-MPDU Size */
2925         len = 0;
2926         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fix_ie), _HT_CAPABILITY_IE_, &len, ie_len-sizeof(struct ndis_802_11_fix_ie));
2927         if (p && len > 0) {
2928                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);
2929                 max_ampdu_sz = (pht_capie->ampdu_params_info & IEEE80211_HT_CAP_AMPDU_FACTOR);
2930                 max_ampdu_sz = 1 << (max_ampdu_sz+3); /*  max_ampdu_sz (kbytes); */
2931
2932                 /* DBG_871X("rtw_update_ht_cap(): max_ampdu_sz =%d\n", max_ampdu_sz); */
2933                 phtpriv->rx_ampdu_maxlen = max_ampdu_sz;
2934
2935         }
2936
2937
2938         len = 0;
2939         p = rtw_get_ie(pie+sizeof(struct ndis_802_11_fix_ie), _HT_ADD_INFO_IE_, &len, ie_len-sizeof(struct ndis_802_11_fix_ie));
2940         if (p && len > 0) {
2941                 pht_addtinfo = (struct ieee80211_ht_addt_info *)(p+2);
2942                 /* todo: */
2943         }
2944
2945         if (channel > 14) {
2946                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
2947                         cbw40_enable = 1;
2948         } else {
2949                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
2950                         cbw40_enable = 1;
2951         }
2952
2953         /* update cur_bwmode & cur_ch_offset */
2954         if ((cbw40_enable) &&
2955             (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
2956               BIT(1)) && (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
2957                 int i;
2958                 u8 rf_type;
2959
2960                 rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2961
2962                 /* update the MCS set */
2963                 for (i = 0; i < 16; i++)
2964                         pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= pmlmeext->default_supported_mcs_set[i];
2965
2966                 /* update the MCS rates */
2967                 switch (rf_type) {
2968                 case RF_1T1R:
2969                 case RF_1T2R:
2970                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_1R);
2971                         break;
2972                 case RF_2T2R:
2973                 default:
2974 #ifdef CONFIG_DISABLE_MCS13TO15
2975                         if (pmlmeext->cur_bwmode == CHANNEL_WIDTH_40 && pregistrypriv->wifi_spec != 1)
2976                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R_13TO15_OFF);
2977                         else
2978                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
2979 #else /* CONFIG_DISABLE_MCS13TO15 */
2980                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
2981 #endif /* CONFIG_DISABLE_MCS13TO15 */
2982                 }
2983
2984                 /* switch to the 40M Hz mode according to the AP */
2985                 /* pmlmeext->cur_bwmode = CHANNEL_WIDTH_40; */
2986                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
2987                 case EXTCHNL_OFFSET_UPPER:
2988                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
2989                         break;
2990
2991                 case EXTCHNL_OFFSET_LOWER:
2992                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
2993                         break;
2994
2995                 default:
2996                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
2997                         break;
2998                 }
2999         }
3000
3001         /*  */
3002         /*  Config SM Power Save setting */
3003         /*  */
3004         pmlmeinfo->SM_PS =
3005                 (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
3006                  0x0C) >> 2;
3007         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
3008                 DBG_871X("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
3009
3010         /*  */
3011         /*  Config current HT Protection mode. */
3012         /*  */
3013         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
3014 }
3015
3016 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
3017 {
3018         u8 issued;
3019         int priority;
3020         struct sta_info *psta = NULL;
3021         struct ht_priv *phtpriv;
3022         struct pkt_attrib *pattrib = &pxmitframe->attrib;
3023         s32 bmcst = IS_MCAST(pattrib->ra);
3024
3025         /* if (bmcst || (padapter->mlmepriv.LinkDetectInfo.bTxBusyTraffic == false)) */
3026         if (bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100))
3027                 return;
3028
3029         priority = pattrib->priority;
3030
3031         psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
3032         if (pattrib->psta != psta) {
3033                 DBG_871X("%s, pattrib->psta(%p) != psta(%p)\n", __func__, pattrib->psta, psta);
3034                 return;
3035         }
3036
3037         if (psta == NULL) {
3038                 DBG_871X("%s, psta ==NUL\n", __func__);
3039                 return;
3040         }
3041
3042         if (!(psta->state & _FW_LINKED)) {
3043                 DBG_871X("%s, psta->state(0x%x) != _FW_LINKED\n", __func__, psta->state);
3044                 return;
3045         }
3046
3047
3048         phtpriv = &psta->htpriv;
3049
3050         if ((phtpriv->ht_option == true) && (phtpriv->ampdu_enable == true)) {
3051                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
3052                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
3053
3054                 if (0 == issued) {
3055                         DBG_871X("rtw_issue_addbareq_cmd, p =%d\n", priority);
3056                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
3057                         rtw_addbareq_cmd(padapter, (u8) priority, pattrib->ra);
3058                 }
3059         }
3060
3061 }
3062
3063 void rtw_append_exented_cap(struct adapter *padapter, u8 *out_ie, uint *pout_len)
3064 {
3065         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3066         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
3067         u8 cap_content[8] = {0};
3068         u8 *pframe;
3069
3070
3071         if (phtpriv->bss_coexist) {
3072                 SET_EXT_CAPABILITY_ELE_BSS_COEXIST(cap_content, 1);
3073         }
3074
3075         pframe = rtw_set_ie(out_ie + *pout_len, EID_EXTCapability, 8, cap_content, pout_len);
3076 }
3077
3078 inline void rtw_set_to_roam(struct adapter *adapter, u8 to_roam)
3079 {
3080         if (to_roam == 0)
3081                 adapter->mlmepriv.to_join = false;
3082         adapter->mlmepriv.to_roam = to_roam;
3083 }
3084
3085 inline u8 rtw_dec_to_roam(struct adapter *adapter)
3086 {
3087         adapter->mlmepriv.to_roam--;
3088         return adapter->mlmepriv.to_roam;
3089 }
3090
3091 inline u8 rtw_to_roam(struct adapter *adapter)
3092 {
3093         return adapter->mlmepriv.to_roam;
3094 }
3095
3096 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3097 {
3098         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3099
3100         spin_lock_bh(&pmlmepriv->lock);
3101         _rtw_roaming(padapter, tgt_network);
3102         spin_unlock_bh(&pmlmepriv->lock);
3103 }
3104 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3105 {
3106         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3107         struct wlan_network *cur_network = &pmlmepriv->cur_network;
3108         int do_join_r;
3109
3110         if (0 < rtw_to_roam(padapter)) {
3111                 DBG_871X("roaming from %s("MAC_FMT"), length:%d\n",
3112                                 cur_network->network.Ssid.Ssid, MAC_ARG(cur_network->network.MacAddress),
3113                                 cur_network->network.Ssid.SsidLength);
3114                 memcpy(&pmlmepriv->assoc_ssid, &cur_network->network.Ssid, sizeof(struct ndis_802_11_ssid));
3115
3116                 pmlmepriv->assoc_by_bssid = false;
3117
3118                 while (1) {
3119                         do_join_r = rtw_do_join(padapter);
3120                         if (_SUCCESS == do_join_r) {
3121                                 break;
3122                         } else {
3123                                 DBG_871X("roaming do_join return %d\n", do_join_r);
3124                                 rtw_dec_to_roam(padapter);
3125
3126                                 if (rtw_to_roam(padapter) > 0) {
3127                                         continue;
3128                                 } else {
3129                                         DBG_871X("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
3130                                         rtw_indicate_disconnect(padapter);
3131                                         break;
3132                                 }
3133                         }
3134                 }
3135         }
3136
3137 }
3138
3139 sint rtw_linked_check(struct adapter *padapter)
3140 {
3141         if ((check_fwstate(&padapter->mlmepriv, WIFI_AP_STATE) == true) ||
3142                         (check_fwstate(&padapter->mlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE) == true)) {
3143                 if (padapter->stapriv.asoc_sta_count > 2)
3144                         return true;
3145         } else{ /* Station mode */
3146                 if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == true)
3147                         return true;
3148         }
3149         return false;
3150 }