GNU Linux-libre 4.19.264-gnu1
[releases.git] / drivers / staging / rtl8188eu / core / rtw_cmd.c
1 // SPDX-License-Identifier: GPL-2.0
2 /******************************************************************************
3  *
4  * Copyright(c) 2007 - 2012 Realtek Corporation. All rights reserved.
5  *
6  ******************************************************************************/
7 #define _RTW_CMD_C_
8
9 #include <osdep_service.h>
10 #include <drv_types.h>
11 #include <recv_osdep.h>
12 #include <mlme_osdep.h>
13 #include <rtw_mlme_ext.h>
14
15 /*
16  * Caller and the rtw_cmd_thread can protect cmd_q by spin_lock.
17  * No irqsave is necessary.
18  */
19
20 int rtw_init_cmd_priv(struct cmd_priv *pcmdpriv)
21 {
22         init_completion(&pcmdpriv->cmd_queue_comp);
23         init_completion(&pcmdpriv->terminate_cmdthread_comp);
24
25         _rtw_init_queue(&pcmdpriv->cmd_queue);
26         return _SUCCESS;
27 }
28
29 /*
30  * Calling Context:
31  *
32  * rtw_enqueue_cmd can only be called between kernel thread,
33  * since only spin_lock is used.
34  *
35  * ISR/Call-Back functions can't call this sub-function.
36  */
37
38 static int _rtw_enqueue_cmd(struct __queue *queue, struct cmd_obj *obj)
39 {
40         unsigned long irqL;
41
42         if (!obj)
43                 goto exit;
44
45         spin_lock_irqsave(&queue->lock, irqL);
46
47         list_add_tail(&obj->list, &queue->queue);
48
49         spin_unlock_irqrestore(&queue->lock, irqL);
50
51 exit:
52
53         return _SUCCESS;
54 }
55
56 struct cmd_obj *rtw_dequeue_cmd(struct __queue *queue)
57 {
58         unsigned long irqL;
59         struct cmd_obj *obj;
60
61         spin_lock_irqsave(&queue->lock, irqL);
62         obj = list_first_entry_or_null(&queue->queue, struct cmd_obj, list);
63         if (obj)
64                 list_del_init(&obj->list);
65         spin_unlock_irqrestore(&queue->lock, irqL);
66
67         return obj;
68 }
69
70 static int rtw_cmd_filter(struct cmd_priv *pcmdpriv, struct cmd_obj *cmd_obj)
71 {
72         u8 bAllow = false; /* set to true to allow enqueuing cmd when hw_init_completed is false */
73
74         /* To decide allow or not */
75         if ((pcmdpriv->padapter->pwrctrlpriv.bHWPwrPindetect) &&
76             (!pcmdpriv->padapter->registrypriv.usbss_enable)) {
77                 if (cmd_obj->cmdcode == _Set_Drv_Extra_CMD_) {
78                         struct drvextra_cmd_parm        *pdrvextra_cmd_parm = (struct drvextra_cmd_parm *)cmd_obj->parmbuf;
79
80                         if (pdrvextra_cmd_parm->ec_id == POWER_SAVING_CTRL_WK_CID)
81                                 bAllow = true;
82                 }
83         }
84
85         if (cmd_obj->cmdcode == _SetChannelPlan_CMD_)
86                 bAllow = true;
87
88         if ((!pcmdpriv->padapter->hw_init_completed && !bAllow) ||
89             !pcmdpriv->cmdthd_running)  /* com_thread not running */
90                 return _FAIL;
91         return _SUCCESS;
92 }
93
94 u32 rtw_enqueue_cmd(struct cmd_priv *pcmdpriv, struct cmd_obj *cmd_obj)
95 {
96         int res = _FAIL;
97         struct adapter *padapter = pcmdpriv->padapter;
98
99         if (!cmd_obj)
100                 goto exit;
101
102         cmd_obj->padapter = padapter;
103
104         res = rtw_cmd_filter(pcmdpriv, cmd_obj);
105         if (res == _FAIL) {
106                 rtw_free_cmd_obj(cmd_obj);
107                 goto exit;
108         }
109
110         res = _rtw_enqueue_cmd(&pcmdpriv->cmd_queue, cmd_obj);
111
112         if (res == _SUCCESS)
113                 complete(&pcmdpriv->cmd_queue_comp);
114
115 exit:
116
117         return res;
118 }
119
120 void rtw_free_cmd_obj(struct cmd_obj *pcmd)
121 {
122         if ((pcmd->cmdcode != _JoinBss_CMD_) && (pcmd->cmdcode != _CreateBss_CMD_)) {
123                 /* free parmbuf in cmd_obj */
124                 kfree(pcmd->parmbuf);
125         }
126
127         if (pcmd->rsp) {
128                 if (pcmd->rspsz != 0) {
129                         /* free rsp in cmd_obj */
130                         kfree(pcmd->rsp);
131                 }
132         }
133
134         /* free cmd_obj */
135         kfree(pcmd);
136 }
137
138 int rtw_cmd_thread(void *context)
139 {
140         u8 ret;
141         struct cmd_obj *pcmd;
142         u8 (*cmd_hdl)(struct adapter *padapter, u8 *pbuf);
143         void (*pcmd_callback)(struct adapter *dev, struct cmd_obj *pcmd);
144         struct adapter *padapter = context;
145         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
146
147         allow_signal(SIGTERM);
148
149         pcmdpriv->cmdthd_running = true;
150         complete(&pcmdpriv->terminate_cmdthread_comp);
151
152         RT_TRACE(_module_rtl871x_cmd_c_, _drv_info_,
153                  ("start r871x %s !!!!\n", __func__));
154
155         while (1) {
156                 if (wait_for_completion_interruptible(&pcmdpriv->cmd_queue_comp))
157                         break;
158
159                 if (padapter->bDriverStopped ||
160                     padapter->bSurpriseRemoved) {
161                         DBG_88E("%s: DriverStopped(%d) SurpriseRemoved(%d) break at line %d\n",
162                                 __func__, padapter->bDriverStopped, padapter->bSurpriseRemoved, __LINE__);
163                         break;
164                 }
165 _next:
166                 if (padapter->bDriverStopped ||
167                     padapter->bSurpriseRemoved) {
168                         DBG_88E("%s: DriverStopped(%d) SurpriseRemoved(%d) break at line %d\n",
169                                 __func__, padapter->bDriverStopped, padapter->bSurpriseRemoved, __LINE__);
170                         break;
171                 }
172
173                 pcmd = rtw_dequeue_cmd(&pcmdpriv->cmd_queue);
174                 if (!pcmd)
175                         continue;
176
177                 if (rtw_cmd_filter(pcmdpriv, pcmd) == _FAIL) {
178                         pcmd->res = H2C_DROPPED;
179                 } else {
180                         if (pcmd->cmdcode < ARRAY_SIZE(wlancmds)) {
181                                 cmd_hdl = wlancmds[pcmd->cmdcode].h2cfuns;
182
183                                 if (cmd_hdl) {
184                                         ret = cmd_hdl(pcmd->padapter, pcmd->parmbuf);
185                                         pcmd->res = ret;
186                                 }
187                         } else {
188                                 pcmd->res = H2C_PARAMETERS_ERROR;
189                         }
190
191                         cmd_hdl = NULL;
192                 }
193
194                 /* call callback function for post-processed */
195                 if (pcmd->cmdcode < ARRAY_SIZE(rtw_cmd_callback)) {
196                         pcmd_callback = rtw_cmd_callback[pcmd->cmdcode].callback;
197                         if (!pcmd_callback) {
198                                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_info_, ("mlme_cmd_hdl(): pcmd_callback = 0x%p, cmdcode = 0x%x\n", pcmd_callback, pcmd->cmdcode));
199                                 rtw_free_cmd_obj(pcmd);
200                         } else {
201                                 /* todo: !!! fill rsp_buf to pcmd->rsp if (pcmd->rsp!= NULL) */
202                                 pcmd_callback(pcmd->padapter, pcmd);/* need conider that free cmd_obj in rtw_cmd_callback */
203                         }
204                 } else {
205                         RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_, ("%s: cmdcode = 0x%x callback not defined!\n", __func__, pcmd->cmdcode));
206                         rtw_free_cmd_obj(pcmd);
207                 }
208
209                 if (signal_pending(current))
210                         flush_signals(current);
211
212                 goto _next;
213         }
214         pcmdpriv->cmdthd_running = false;
215
216         /*  free all cmd_obj resources */
217         while ((pcmd = rtw_dequeue_cmd(&pcmdpriv->cmd_queue))) {
218                 /* DBG_88E("%s: leaving... drop cmdcode:%u\n", __func__, pcmd->cmdcode); */
219
220                 rtw_free_cmd_obj(pcmd);
221         }
222
223         complete(&pcmdpriv->terminate_cmdthread_comp);
224
225         complete_and_exit(NULL, 0);
226 }
227
228 /*
229  * rtw_sitesurvey_cmd(~)
230  * ### NOTE:#### (!!!!)
231  * MUST TAKE CARE THAT BEFORE CALLING THIS FUNC, YOU SHOULD HAVE
232  * LOCKED pmlmepriv->lock
233  */
234 u8 rtw_sitesurvey_cmd(struct adapter  *padapter, struct ndis_802_11_ssid *ssid, int ssid_num,
235         struct rtw_ieee80211_channel *ch, int ch_num)
236 {
237         u8 res = _FAIL;
238         struct cmd_obj          *ph2c;
239         struct sitesurvey_parm  *psurveyPara;
240         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
241         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
242
243         if (check_fwstate(pmlmepriv, _FW_LINKED) == true)
244                 rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_SCAN, 1);
245
246         ph2c = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
247         if (!ph2c)
248                 return _FAIL;
249
250         psurveyPara = kzalloc(sizeof(struct sitesurvey_parm), GFP_ATOMIC);
251         if (!psurveyPara) {
252                 kfree(ph2c);
253                 return _FAIL;
254         }
255
256         rtw_free_network_queue(padapter, false);
257
258         RT_TRACE(_module_rtl871x_cmd_c_, _drv_info_, ("%s: flush network queue\n", __func__));
259
260         init_h2fwcmd_w_parm_no_rsp(ph2c, psurveyPara, _SiteSurvey_CMD_);
261
262         /* psurveyPara->bsslimit = 48; */
263         psurveyPara->scan_mode = pmlmepriv->scan_mode;
264
265         /* prepare ssid list */
266         if (ssid) {
267                 int i;
268
269                 for (i = 0; i < ssid_num && i < RTW_SSID_SCAN_AMOUNT; i++) {
270                         if (ssid[i].SsidLength) {
271                                 memcpy(&psurveyPara->ssid[i], &ssid[i], sizeof(struct ndis_802_11_ssid));
272                                 psurveyPara->ssid_num++;
273                         }
274                 }
275         }
276
277         /* prepare channel list */
278         if (ch) {
279                 int i;
280
281                 for (i = 0; i < ch_num && i < RTW_CHANNEL_SCAN_AMOUNT; i++) {
282                         if (ch[i].hw_value && !(ch[i].flags & RTW_IEEE80211_CHAN_DISABLED)) {
283                                 memcpy(&psurveyPara->ch[i], &ch[i], sizeof(struct rtw_ieee80211_channel));
284                                 psurveyPara->ch_num++;
285                         }
286                 }
287         }
288
289         set_fwstate(pmlmepriv, _FW_UNDER_SURVEY);
290
291         res = rtw_enqueue_cmd(pcmdpriv, ph2c);
292
293         if (res == _SUCCESS) {
294                 mod_timer(&pmlmepriv->scan_to_timer,
295                           jiffies + msecs_to_jiffies(SCANNING_TIMEOUT));
296
297                 LedControl8188eu(padapter, LED_CTL_SITE_SURVEY);
298
299                 pmlmepriv->scan_interval = SCAN_INTERVAL;/*  30*2 sec = 60sec */
300         } else {
301                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
302         }
303
304         return res;
305 }
306
307 void rtw_readtssi_cmdrsp_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
308 {
309         kfree(pcmd->parmbuf);
310         kfree(pcmd);
311 }
312
313 u8 rtw_createbss_cmd(struct adapter  *padapter)
314 {
315         struct cmd_obj *pcmd;
316         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
317         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
318         struct wlan_bssid_ex *pdev_network = &padapter->registrypriv.dev_network;
319         u8      res = _SUCCESS;
320
321         LedControl8188eu(padapter, LED_CTL_START_TO_LINK);
322
323         if (pmlmepriv->assoc_ssid.SsidLength == 0)
324                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_info_, (" createbss for Any SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
325         else
326                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_info_, (" createbss for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
327
328         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
329         if (!pcmd) {
330                 res = _FAIL;
331                 goto exit;
332         }
333
334         INIT_LIST_HEAD(&pcmd->list);
335         pcmd->cmdcode = _CreateBss_CMD_;
336         pcmd->parmbuf = (unsigned char *)pdev_network;
337         pcmd->cmdsz = get_wlan_bssid_ex_sz((struct wlan_bssid_ex *)pdev_network);
338         pcmd->rsp = NULL;
339         pcmd->rspsz = 0;
340         pdev_network->Length = pcmd->cmdsz;
341         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
342 exit:
343
344         return res;
345 }
346
347 u8 rtw_joinbss_cmd(struct adapter  *padapter, struct wlan_network *pnetwork)
348 {
349         u8      res = _SUCCESS;
350         uint    t_len = 0;
351         struct wlan_bssid_ex            *psecnetwork;
352         struct cmd_obj          *pcmd;
353         struct cmd_priv         *pcmdpriv = &padapter->cmdpriv;
354         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
355         struct qos_priv         *pqospriv = &pmlmepriv->qospriv;
356         struct security_priv    *psecuritypriv = &padapter->securitypriv;
357         struct registry_priv    *pregistrypriv = &padapter->registrypriv;
358         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
359         enum ndis_802_11_network_infra ndis_network_mode = pnetwork->network.InfrastructureMode;
360         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
361         struct mlme_ext_info    *pmlmeinfo = &pmlmeext->mlmext_info;
362
363         LedControl8188eu(padapter, LED_CTL_START_TO_LINK);
364
365         if (pmlmepriv->assoc_ssid.SsidLength == 0)
366                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_info_, ("+Join cmd: Any SSid\n"));
367         else
368                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_notice_, ("+Join cmd: SSid =[%s]\n", pmlmepriv->assoc_ssid.Ssid));
369
370         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
371         if (!pcmd) {
372                 res = _FAIL;
373                 goto exit;
374         }
375         /* for ies is fix buf size */
376         t_len = sizeof(struct wlan_bssid_ex);
377
378         /* for hidden ap to set fw_state here */
379         if (!check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_ADHOC_STATE)) {
380                 switch (ndis_network_mode) {
381                 case Ndis802_11IBSS:
382                         set_fwstate(pmlmepriv, WIFI_ADHOC_STATE);
383                         break;
384                 case Ndis802_11Infrastructure:
385                         set_fwstate(pmlmepriv, WIFI_STATION_STATE);
386                         break;
387                 case Ndis802_11APMode:
388                 case Ndis802_11AutoUnknown:
389                 case Ndis802_11InfrastructureMax:
390                         break;
391                 }
392         }
393
394         psecnetwork = (struct wlan_bssid_ex *)&psecuritypriv->sec_bss;
395         if (!psecnetwork) {
396                 kfree(pcmd);
397
398                 res = _FAIL;
399
400                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_,
401                          ("%s :psecnetwork == NULL!!!\n", __func__));
402
403                 goto exit;
404         }
405
406         memset(psecnetwork, 0, t_len);
407
408         memcpy(psecnetwork, &pnetwork->network, get_wlan_bssid_ex_sz(&pnetwork->network));
409
410         psecuritypriv->authenticator_ie[0] = (unsigned char)psecnetwork->ie_length;
411
412         if ((psecnetwork->ie_length-12) < (256-1))
413                 memcpy(&psecuritypriv->authenticator_ie[1], &psecnetwork->ies[12], psecnetwork->ie_length-12);
414         else
415                 memcpy(&psecuritypriv->authenticator_ie[1], &psecnetwork->ies[12], (256-1));
416
417         psecnetwork->ie_length = 0;
418         /*  Added by Albert 2009/02/18 */
419         /*  If the driver wants to use the bssid to create the connection. */
420         /*  If not,  we have to copy the connecting AP's MAC address to it so that */
421         /*  the driver just has the bssid information for PMKIDList searching. */
422
423         if (!pmlmepriv->assoc_by_bssid)
424                 memcpy(&pmlmepriv->assoc_bssid[0], &pnetwork->network.MacAddress[0], ETH_ALEN);
425
426         psecnetwork->ie_length = rtw_restruct_sec_ie(padapter, &pnetwork->network.ies[0], &psecnetwork->ies[0], pnetwork->network.ie_length);
427
428         pqospriv->qos_option = 0;
429
430         if (pregistrypriv->wmm_enable) {
431                 u32 tmp_len;
432
433                 tmp_len = rtw_restruct_wmm_ie(padapter, &pnetwork->network.ies[0], &psecnetwork->ies[0], pnetwork->network.ie_length, psecnetwork->ie_length);
434
435                 if (psecnetwork->ie_length != tmp_len) {
436                         psecnetwork->ie_length = tmp_len;
437                         pqospriv->qos_option = 1; /* There is WMM IE in this corresp. beacon */
438                 } else {
439                         pqospriv->qos_option = 0;/* There is no WMM IE in this corresp. beacon */
440                 }
441         }
442
443         phtpriv->ht_option = false;
444         if (pregistrypriv->ht_enable) {
445                 /*
446                  * Added by Albert 2010/06/23
447                  * For the WEP mode, we will use the bg mode to do
448                  * the connection to avoid some IOT issue.
449                  * Especially for Realtek 8192u SoftAP.
450                  */
451                 if ((padapter->securitypriv.dot11PrivacyAlgrthm != _WEP40_) &&
452                     (padapter->securitypriv.dot11PrivacyAlgrthm != _WEP104_) &&
453                     (padapter->securitypriv.dot11PrivacyAlgrthm != _TKIP_)) {
454                         /* rtw_restructure_ht_ie */
455                         rtw_restructure_ht_ie(padapter, &pnetwork->network.ies[0], &psecnetwork->ies[0],
456                                                                         pnetwork->network.ie_length, &psecnetwork->ie_length);
457                 }
458         }
459
460         pmlmeinfo->assoc_AP_vendor = check_assoc_AP(pnetwork->network.ies, pnetwork->network.ie_length);
461
462         if (pmlmeinfo->assoc_AP_vendor == HT_IOT_PEER_TENDA)
463                 padapter->pwrctrlpriv.smart_ps = 0;
464         else
465                 padapter->pwrctrlpriv.smart_ps = padapter->registrypriv.smart_ps;
466
467         DBG_88E("%s: smart_ps =%d\n", __func__, padapter->pwrctrlpriv.smart_ps);
468
469         pcmd->cmdsz = get_wlan_bssid_ex_sz(psecnetwork);/* get cmdsz before endian conversion */
470
471         INIT_LIST_HEAD(&pcmd->list);
472         pcmd->cmdcode = _JoinBss_CMD_;
473         pcmd->parmbuf = (unsigned char *)psecnetwork;
474         pcmd->rsp = NULL;
475         pcmd->rspsz = 0;
476
477         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
478
479 exit:
480
481         return res;
482 }
483
484 u8 rtw_disassoc_cmd(struct adapter *padapter, u32 deauth_timeout_ms, bool enqueue) /* for sta_mode */
485 {
486         struct cmd_obj *cmdobj = NULL;
487         struct disconnect_parm *param = NULL;
488         struct cmd_priv *cmdpriv = &padapter->cmdpriv;
489         u8 res = _SUCCESS;
490
491         RT_TRACE(_module_rtl871x_cmd_c_, _drv_notice_, ("+%s\n", __func__));
492
493         /* prepare cmd parameter */
494         param = kzalloc(sizeof(*param), GFP_ATOMIC);
495         if (!param) {
496                 res = _FAIL;
497                 goto exit;
498         }
499         param->deauth_timeout_ms = deauth_timeout_ms;
500
501         if (enqueue) {
502                 /* need enqueue, prepare cmd_obj and enqueue */
503                 cmdobj = kzalloc(sizeof(*cmdobj), GFP_ATOMIC);
504                 if (!cmdobj) {
505                         res = _FAIL;
506                         kfree(param);
507                         goto exit;
508                 }
509                 init_h2fwcmd_w_parm_no_rsp(cmdobj, param, _DisConnect_CMD_);
510                 res = rtw_enqueue_cmd(cmdpriv, cmdobj);
511         } else {
512                 /* no need to enqueue, do the cmd hdl directly and free cmd parameter */
513                 if (disconnect_hdl(padapter, (u8 *)param) != H2C_SUCCESS)
514                         res = _FAIL;
515                 kfree(param);
516         }
517
518 exit:
519
520         return res;
521 }
522
523 u8 rtw_setopmode_cmd(struct adapter  *padapter, enum ndis_802_11_network_infra networktype)
524 {
525         struct  cmd_obj *ph2c;
526         struct  setopmode_parm *psetop;
527
528         struct  cmd_priv   *pcmdpriv = &padapter->cmdpriv;
529
530         ph2c = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
531         psetop = kzalloc(sizeof(struct setopmode_parm), GFP_KERNEL);
532         if (!ph2c || !psetop) {
533                 kfree(ph2c);
534                 kfree(psetop);
535                 return false;
536         }
537
538         init_h2fwcmd_w_parm_no_rsp(ph2c, psetop, _SetOpMode_CMD_);
539         psetop->mode = (u8)networktype;
540
541         return rtw_enqueue_cmd(pcmdpriv, ph2c);
542 }
543
544 u8 rtw_setstakey_cmd(struct adapter *padapter, u8 *psta, u8 unicast_key)
545 {
546         struct cmd_obj *ph2c;
547         struct set_stakey_parm *psetstakey_para;
548         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
549         struct set_stakey_rsp *psetstakey_rsp = NULL;
550
551         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
552         struct security_priv *psecuritypriv = &padapter->securitypriv;
553         struct sta_info *sta = (struct sta_info *)psta;
554
555         ph2c = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
556         psetstakey_para = kzalloc(sizeof(struct set_stakey_parm), GFP_KERNEL);
557         psetstakey_rsp = kzalloc(sizeof(struct set_stakey_rsp), GFP_KERNEL);
558
559         if (!ph2c || !psetstakey_para || !psetstakey_rsp) {
560                 kfree(ph2c);
561                 kfree(psetstakey_para);
562                 kfree(psetstakey_rsp);
563                 return _FAIL;
564         }
565
566         init_h2fwcmd_w_parm_no_rsp(ph2c, psetstakey_para, _SetStaKey_CMD_);
567         ph2c->rsp = (u8 *)psetstakey_rsp;
568         ph2c->rspsz = sizeof(struct set_stakey_rsp);
569
570         ether_addr_copy(psetstakey_para->addr, sta->hwaddr);
571
572         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE))
573                 psetstakey_para->algorithm = (unsigned char)psecuritypriv->dot11PrivacyAlgrthm;
574         else
575                 GET_ENCRY_ALGO(psecuritypriv, sta, psetstakey_para->algorithm, false);
576
577         if (unicast_key)
578                 memcpy(&psetstakey_para->key, &sta->dot118021x_UncstKey, 16);
579         else
580                 memcpy(&psetstakey_para->key, &psecuritypriv->dot118021XGrpKey[psecuritypriv->dot118021XGrpKeyid].skey, 16);
581
582         /* jeff: set this because at least sw key is ready */
583         padapter->securitypriv.busetkipkey = true;
584
585         return rtw_enqueue_cmd(pcmdpriv, ph2c);
586 }
587
588 u8 rtw_clearstakey_cmd(struct adapter *padapter, u8 *psta, u8 entry, u8 enqueue)
589 {
590         struct cmd_obj *ph2c;
591         struct set_stakey_parm  *psetstakey_para;
592         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
593         struct set_stakey_rsp *psetstakey_rsp = NULL;
594         struct sta_info *sta = (struct sta_info *)psta;
595         u8      res = _SUCCESS;
596
597         if (!enqueue) {
598                 clear_cam_entry(padapter, entry);
599         } else {
600                 ph2c = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
601                 if (!ph2c) {
602                         res = _FAIL;
603                         goto exit;
604                 }
605
606                 psetstakey_para = kzalloc(sizeof(struct set_stakey_parm), GFP_ATOMIC);
607                 if (!psetstakey_para) {
608                         kfree(ph2c);
609                         res = _FAIL;
610                         goto exit;
611                 }
612
613                 psetstakey_rsp = kzalloc(sizeof(struct set_stakey_rsp), GFP_ATOMIC);
614                 if (!psetstakey_rsp) {
615                         kfree(ph2c);
616                         kfree(psetstakey_para);
617                         res = _FAIL;
618                         goto exit;
619                 }
620
621                 init_h2fwcmd_w_parm_no_rsp(ph2c, psetstakey_para, _SetStaKey_CMD_);
622                 ph2c->rsp = (u8 *)psetstakey_rsp;
623                 ph2c->rspsz = sizeof(struct set_stakey_rsp);
624
625                 ether_addr_copy(psetstakey_para->addr, sta->hwaddr);
626
627                 psetstakey_para->algorithm = _NO_PRIVACY_;
628
629                 psetstakey_para->id = entry;
630
631                 res = rtw_enqueue_cmd(pcmdpriv, ph2c);
632         }
633 exit:
634
635         return res;
636 }
637
638 u8 rtw_addbareq_cmd(struct adapter *padapter, u8 tid, u8 *addr)
639 {
640         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
641         struct cmd_obj *ph2c;
642         struct addBaReq_parm *paddbareq_parm;
643         u8      res = _SUCCESS;
644
645         ph2c = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
646         if (!ph2c) {
647                 res = _FAIL;
648                 goto exit;
649         }
650
651         paddbareq_parm = kzalloc(sizeof(struct addBaReq_parm), GFP_ATOMIC);
652         if (!paddbareq_parm) {
653                 kfree(ph2c);
654                 res = _FAIL;
655                 goto exit;
656         }
657
658         paddbareq_parm->tid = tid;
659         memcpy(paddbareq_parm->addr, addr, ETH_ALEN);
660
661         init_h2fwcmd_w_parm_no_rsp(ph2c, paddbareq_parm, _AddBAReq_CMD_);
662
663         /* DBG_88E("rtw_addbareq_cmd, tid =%d\n", tid); */
664
665         /* rtw_enqueue_cmd(pcmdpriv, ph2c); */
666         res = rtw_enqueue_cmd(pcmdpriv, ph2c);
667
668 exit:
669
670         return res;
671 }
672
673 u8 rtw_dynamic_chk_wk_cmd(struct adapter *padapter)
674 {
675         struct cmd_obj *ph2c;
676         struct drvextra_cmd_parm *pdrvextra_cmd_parm;
677         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
678         u8      res = _SUCCESS;
679
680         ph2c = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
681         if (!ph2c) {
682                 res = _FAIL;
683                 goto exit;
684         }
685
686         pdrvextra_cmd_parm = kzalloc(sizeof(struct drvextra_cmd_parm), GFP_ATOMIC);
687         if (!pdrvextra_cmd_parm) {
688                 kfree(ph2c);
689                 res = _FAIL;
690                 goto exit;
691         }
692
693         pdrvextra_cmd_parm->ec_id = DYNAMIC_CHK_WK_CID;
694         pdrvextra_cmd_parm->type_size = 0;
695         pdrvextra_cmd_parm->pbuf = (u8 *)padapter;
696
697         init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, _Set_Drv_Extra_CMD_);
698
699         /* rtw_enqueue_cmd(pcmdpriv, ph2c); */
700         res = rtw_enqueue_cmd(pcmdpriv, ph2c);
701 exit:
702         return res;
703 }
704
705 u8 rtw_set_chplan_cmd(struct adapter *padapter, u8 chplan, u8 enqueue)
706 {
707         struct  cmd_obj *pcmdobj;
708         struct  SetChannelPlan_param *setChannelPlan_param;
709         struct  cmd_priv   *pcmdpriv = &padapter->cmdpriv;
710
711         u8      res = _SUCCESS;
712
713         RT_TRACE(_module_rtl871x_cmd_c_, _drv_notice_, ("+%s\n", __func__));
714
715         /* check input parameter */
716         if (!rtw_is_channel_plan_valid(chplan)) {
717                 res = _FAIL;
718                 goto exit;
719         }
720
721         /* prepare cmd parameter */
722         setChannelPlan_param = kzalloc(sizeof(struct SetChannelPlan_param), GFP_KERNEL);
723         if (!setChannelPlan_param) {
724                 res = _FAIL;
725                 goto exit;
726         }
727         setChannelPlan_param->channel_plan = chplan;
728
729         if (enqueue) {
730                 /* need enqueue, prepare cmd_obj and enqueue */
731                 pcmdobj = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
732                 if (!pcmdobj) {
733                         kfree(setChannelPlan_param);
734                         res = _FAIL;
735                         goto exit;
736                 }
737
738                 init_h2fwcmd_w_parm_no_rsp(pcmdobj, setChannelPlan_param, _SetChannelPlan_CMD_);
739                 res = rtw_enqueue_cmd(pcmdpriv, pcmdobj);
740         } else {
741                 /* no need to enqueue, do the cmd hdl directly and free cmd parameter */
742                 if (set_chplan_hdl(padapter, (unsigned char *)setChannelPlan_param) != H2C_SUCCESS)
743                         res = _FAIL;
744
745                 kfree(setChannelPlan_param);
746         }
747
748         /* do something based on res... */
749         if (res == _SUCCESS)
750                 padapter->mlmepriv.ChannelPlan = chplan;
751
752 exit:
753
754         return res;
755 }
756
757 static void traffic_status_watchdog(struct adapter *padapter)
758 {
759         u8      bEnterPS;
760         u8      bBusyTraffic = false, bTxBusyTraffic = false, bRxBusyTraffic = false;
761         u8      bHigherBusyTraffic = false, bHigherBusyRxTraffic = false, bHigherBusyTxTraffic = false;
762         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
763
764         /*  */
765         /*  Determine if our traffic is busy now */
766         /*  */
767         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
768                 if (pmlmepriv->LinkDetectInfo.NumRxOkInPeriod > 100 ||
769                     pmlmepriv->LinkDetectInfo.NumTxOkInPeriod > 100) {
770                         bBusyTraffic = true;
771
772                         if (pmlmepriv->LinkDetectInfo.NumRxOkInPeriod > pmlmepriv->LinkDetectInfo.NumTxOkInPeriod)
773                                 bRxBusyTraffic = true;
774                         else
775                                 bTxBusyTraffic = true;
776                 }
777
778                 /*  Higher Tx/Rx data. */
779                 if (pmlmepriv->LinkDetectInfo.NumRxOkInPeriod > 4000 ||
780                     pmlmepriv->LinkDetectInfo.NumTxOkInPeriod > 4000) {
781                         bHigherBusyTraffic = true;
782
783                         if (pmlmepriv->LinkDetectInfo.NumRxOkInPeriod > pmlmepriv->LinkDetectInfo.NumTxOkInPeriod)
784                                 bHigherBusyRxTraffic = true;
785                         else
786                                 bHigherBusyTxTraffic = true;
787                 }
788
789                 /*  check traffic for  powersaving. */
790                 if (((pmlmepriv->LinkDetectInfo.NumRxUnicastOkInPeriod + pmlmepriv->LinkDetectInfo.NumTxOkInPeriod) > 8) ||
791                     (pmlmepriv->LinkDetectInfo.NumRxUnicastOkInPeriod > 2))
792                         bEnterPS = false;
793                 else
794                         bEnterPS = true;
795
796                 /*  LeisurePS only work in infra mode. */
797                 if (bEnterPS)
798                         LPS_Enter(padapter);
799                 else
800                         LPS_Leave(padapter);
801         } else {
802                 LPS_Leave(padapter);
803         }
804
805         pmlmepriv->LinkDetectInfo.NumRxOkInPeriod = 0;
806         pmlmepriv->LinkDetectInfo.NumTxOkInPeriod = 0;
807         pmlmepriv->LinkDetectInfo.NumRxUnicastOkInPeriod = 0;
808         pmlmepriv->LinkDetectInfo.bBusyTraffic = bBusyTraffic;
809         pmlmepriv->LinkDetectInfo.bTxBusyTraffic = bTxBusyTraffic;
810         pmlmepriv->LinkDetectInfo.bRxBusyTraffic = bRxBusyTraffic;
811         pmlmepriv->LinkDetectInfo.bHigherBusyTraffic = bHigherBusyTraffic;
812         pmlmepriv->LinkDetectInfo.bHigherBusyRxTraffic = bHigherBusyRxTraffic;
813         pmlmepriv->LinkDetectInfo.bHigherBusyTxTraffic = bHigherBusyTxTraffic;
814 }
815
816 static void dynamic_chk_wk_hdl(struct adapter *padapter, u8 *pbuf, int sz)
817 {
818         struct mlme_priv *pmlmepriv;
819
820         padapter = (struct adapter *)pbuf;
821         pmlmepriv = &padapter->mlmepriv;
822
823 #ifdef CONFIG_88EU_AP_MODE
824         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) == true)
825                 expire_timeout_chk(padapter);
826 #endif
827
828         linked_status_chk(padapter);
829         traffic_status_watchdog(padapter);
830
831         rtw_hal_dm_watchdog(padapter);
832 }
833
834 static void lps_ctrl_wk_hdl(struct adapter *padapter, u8 lps_ctrl_type)
835 {
836         struct pwrctrl_priv *pwrpriv = &padapter->pwrctrlpriv;
837         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
838         u8      mstatus;
839
840         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == true) ||
841             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true))
842                 return;
843
844         switch (lps_ctrl_type) {
845         case LPS_CTRL_SCAN:
846                 if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
847                         /* connect */
848                         LPS_Leave(padapter);
849                 }
850                 break;
851         case LPS_CTRL_JOINBSS:
852                 LPS_Leave(padapter);
853                 break;
854         case LPS_CTRL_CONNECT:
855                 mstatus = 1;/* connect */
856                 /*  Reset LPS Setting */
857                 padapter->pwrctrlpriv.LpsIdleCount = 0;
858                 rtw_hal_set_hwreg(padapter, HW_VAR_H2C_FW_JOINBSSRPT, (u8 *)(&mstatus));
859                 break;
860         case LPS_CTRL_DISCONNECT:
861                 mstatus = 0;/* disconnect */
862                 LPS_Leave(padapter);
863                 rtw_hal_set_hwreg(padapter, HW_VAR_H2C_FW_JOINBSSRPT, (u8 *)(&mstatus));
864                 break;
865         case LPS_CTRL_SPECIAL_PACKET:
866                 /* DBG_88E("LPS_CTRL_SPECIAL_PACKET\n"); */
867                 pwrpriv->DelayLPSLastTimeStamp = jiffies;
868                 LPS_Leave(padapter);
869                 break;
870         case LPS_CTRL_LEAVE:
871                 LPS_Leave(padapter);
872                 break;
873         default:
874                 break;
875         }
876 }
877
878 u8 rtw_lps_ctrl_wk_cmd(struct adapter *padapter, u8 lps_ctrl_type, u8 enqueue)
879 {
880         struct cmd_obj  *ph2c;
881         struct drvextra_cmd_parm        *pdrvextra_cmd_parm;
882         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
883         /* struct pwrctrl_priv *pwrctrlpriv = &padapter->pwrctrlpriv; */
884         u8      res = _SUCCESS;
885
886         if (enqueue) {
887                 ph2c = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
888                 if (!ph2c) {
889                         res = _FAIL;
890                         goto exit;
891                 }
892
893                 pdrvextra_cmd_parm = kzalloc(sizeof(struct drvextra_cmd_parm), GFP_ATOMIC);
894                 if (!pdrvextra_cmd_parm) {
895                         kfree(ph2c);
896                         res = _FAIL;
897                         goto exit;
898                 }
899
900                 pdrvextra_cmd_parm->ec_id = LPS_CTRL_WK_CID;
901                 pdrvextra_cmd_parm->type_size = lps_ctrl_type;
902                 pdrvextra_cmd_parm->pbuf = NULL;
903
904                 init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, _Set_Drv_Extra_CMD_);
905
906                 res = rtw_enqueue_cmd(pcmdpriv, ph2c);
907         } else {
908                 lps_ctrl_wk_hdl(padapter, lps_ctrl_type);
909         }
910
911 exit:
912
913         return res;
914 }
915
916 static void rpt_timer_setting_wk_hdl(struct adapter *padapter, u16 min_time)
917 {
918         rtw_hal_set_hwreg(padapter, HW_VAR_RPT_TIMER_SETTING, (u8 *)(&min_time));
919 }
920
921 u8 rtw_rpt_timer_cfg_cmd(struct adapter *padapter, u16 min_time)
922 {
923         struct cmd_obj          *ph2c;
924         struct drvextra_cmd_parm        *pdrvextra_cmd_parm;
925         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
926
927         u8      res = _SUCCESS;
928
929         ph2c = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
930         if (!ph2c) {
931                 res = _FAIL;
932                 goto exit;
933         }
934
935         pdrvextra_cmd_parm = kzalloc(sizeof(struct drvextra_cmd_parm), GFP_ATOMIC);
936         if (!pdrvextra_cmd_parm) {
937                 kfree(ph2c);
938                 res = _FAIL;
939                 goto exit;
940         }
941
942         pdrvextra_cmd_parm->ec_id = RTP_TIMER_CFG_WK_CID;
943         pdrvextra_cmd_parm->type_size = min_time;
944         pdrvextra_cmd_parm->pbuf = NULL;
945         init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, _Set_Drv_Extra_CMD_);
946         res = rtw_enqueue_cmd(pcmdpriv, ph2c);
947 exit:
948
949         return res;
950 }
951
952 static void antenna_select_wk_hdl(struct adapter *padapter, u8 antenna)
953 {
954         rtw_hal_set_hwreg(padapter, HW_VAR_ANTENNA_DIVERSITY_SELECT, (u8 *)(&antenna));
955 }
956
957 u8 rtw_antenna_select_cmd(struct adapter *padapter, u8 antenna, u8 enqueue)
958 {
959         struct cmd_obj          *ph2c;
960         struct drvextra_cmd_parm        *pdrvextra_cmd_parm;
961         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
962         u8      support_ant_div;
963         u8      res = _SUCCESS;
964
965         rtw_hal_get_def_var(padapter, HAL_DEF_IS_SUPPORT_ANT_DIV, &support_ant_div);
966         if (!support_ant_div)
967                 return res;
968
969         if (enqueue) {
970                 ph2c = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
971                 if (!ph2c) {
972                         res = _FAIL;
973                         goto exit;
974                 }
975
976                 pdrvextra_cmd_parm = kzalloc(sizeof(struct drvextra_cmd_parm), GFP_KERNEL);
977                 if (!pdrvextra_cmd_parm) {
978                         kfree(ph2c);
979                         res = _FAIL;
980                         goto exit;
981                 }
982
983                 pdrvextra_cmd_parm->ec_id = ANT_SELECT_WK_CID;
984                 pdrvextra_cmd_parm->type_size = antenna;
985                 pdrvextra_cmd_parm->pbuf = NULL;
986                 init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, _Set_Drv_Extra_CMD_);
987
988                 res = rtw_enqueue_cmd(pcmdpriv, ph2c);
989         } else {
990                 antenna_select_wk_hdl(padapter, antenna);
991         }
992 exit:
993
994         return res;
995 }
996
997 u8 rtw_ps_cmd(struct adapter *padapter)
998 {
999         struct cmd_obj          *ppscmd;
1000         struct drvextra_cmd_parm        *pdrvextra_cmd_parm;
1001         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1002
1003         ppscmd = kzalloc(sizeof(struct cmd_obj), GFP_ATOMIC);
1004         pdrvextra_cmd_parm = kzalloc(sizeof(struct drvextra_cmd_parm), GFP_ATOMIC);
1005         if (!ppscmd || !pdrvextra_cmd_parm) {
1006                 kfree(ppscmd);
1007                 kfree(pdrvextra_cmd_parm);
1008                 return _FAIL;
1009         }
1010
1011         pdrvextra_cmd_parm->ec_id = POWER_SAVING_CTRL_WK_CID;
1012         pdrvextra_cmd_parm->pbuf = NULL;
1013         init_h2fwcmd_w_parm_no_rsp(ppscmd, pdrvextra_cmd_parm, _Set_Drv_Extra_CMD_);
1014
1015         return rtw_enqueue_cmd(pcmdpriv, ppscmd);
1016 }
1017
1018 #ifdef CONFIG_88EU_AP_MODE
1019
1020 static void rtw_chk_hi_queue_hdl(struct adapter *padapter)
1021 {
1022         int cnt = 0;
1023         struct sta_info *psta_bmc;
1024         struct sta_priv *pstapriv = &padapter->stapriv;
1025
1026         psta_bmc = rtw_get_bcmc_stainfo(padapter);
1027         if (!psta_bmc)
1028                 return;
1029
1030         if (psta_bmc->sleepq_len == 0) {
1031                 u8 val = 0;
1032
1033                 /* while ((rtw_read32(padapter, 0x414)&0x00ffff00)!= 0) */
1034                 /* while ((rtw_read32(padapter, 0x414)&0x0000ff00)!= 0) */
1035
1036                 rtw_hal_get_hwreg(padapter, HW_VAR_CHK_HI_QUEUE_EMPTY, &val);
1037
1038                 while (!val) {
1039                         msleep(100);
1040
1041                         cnt++;
1042
1043                         if (cnt > 10)
1044                                 break;
1045
1046                         rtw_hal_get_hwreg(padapter, HW_VAR_CHK_HI_QUEUE_EMPTY, &val);
1047                 }
1048
1049                 if (cnt <= 10) {
1050                         pstapriv->tim_bitmap &= ~BIT(0);
1051                         pstapriv->sta_dz_bitmap &= ~BIT(0);
1052
1053                         update_beacon(padapter, _TIM_IE_, NULL, false);
1054                 } else { /* re check again */
1055                         rtw_chk_hi_queue_cmd(padapter);
1056                 }
1057         }
1058 }
1059
1060 u8 rtw_chk_hi_queue_cmd(struct adapter *padapter)
1061 {
1062         struct cmd_obj  *ph2c;
1063         struct drvextra_cmd_parm        *pdrvextra_cmd_parm;
1064         struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1065         u8      res = _SUCCESS;
1066
1067         ph2c = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
1068         if (!ph2c) {
1069                 res = _FAIL;
1070                 goto exit;
1071         }
1072
1073         pdrvextra_cmd_parm = kzalloc(sizeof(struct drvextra_cmd_parm), GFP_KERNEL);
1074         if (!pdrvextra_cmd_parm) {
1075                 kfree(ph2c);
1076                 res = _FAIL;
1077                 goto exit;
1078         }
1079
1080         pdrvextra_cmd_parm->ec_id = CHECK_HIQ_WK_CID;
1081         pdrvextra_cmd_parm->type_size = 0;
1082         pdrvextra_cmd_parm->pbuf = NULL;
1083
1084         init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, _Set_Drv_Extra_CMD_);
1085
1086         res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1087 exit:
1088         return res;
1089 }
1090 #endif
1091
1092 u8 rtw_drvextra_cmd_hdl(struct adapter *padapter, unsigned char *pbuf)
1093 {
1094         struct drvextra_cmd_parm *pdrvextra_cmd;
1095
1096         if (!pbuf)
1097                 return H2C_PARAMETERS_ERROR;
1098
1099         pdrvextra_cmd = (struct drvextra_cmd_parm *)pbuf;
1100
1101         switch (pdrvextra_cmd->ec_id) {
1102         case DYNAMIC_CHK_WK_CID:
1103                 dynamic_chk_wk_hdl(padapter, pdrvextra_cmd->pbuf, pdrvextra_cmd->type_size);
1104                 break;
1105         case POWER_SAVING_CTRL_WK_CID:
1106                 rtw_ps_processor(padapter);
1107                 break;
1108         case LPS_CTRL_WK_CID:
1109                 lps_ctrl_wk_hdl(padapter, (u8)pdrvextra_cmd->type_size);
1110                 break;
1111         case RTP_TIMER_CFG_WK_CID:
1112                 rpt_timer_setting_wk_hdl(padapter, pdrvextra_cmd->type_size);
1113                 break;
1114         case ANT_SELECT_WK_CID:
1115                 antenna_select_wk_hdl(padapter, pdrvextra_cmd->type_size);
1116                 break;
1117 #ifdef CONFIG_88EU_AP_MODE
1118         case CHECK_HIQ_WK_CID:
1119                 rtw_chk_hi_queue_hdl(padapter);
1120                 break;
1121 #endif /* CONFIG_88EU_AP_MODE */
1122         default:
1123                 break;
1124         }
1125
1126         if (pdrvextra_cmd->pbuf && pdrvextra_cmd->type_size > 0)
1127                 kfree(pdrvextra_cmd->pbuf);
1128
1129         return H2C_SUCCESS;
1130 }
1131
1132 void rtw_survey_cmd_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
1133 {
1134         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
1135
1136         if (pcmd->res == H2C_DROPPED) {
1137                 /* TODO: cancel timer and do timeout handler directly... */
1138                 /* need to make timeout handlerOS independent */
1139                 mod_timer(&pmlmepriv->scan_to_timer,
1140                           jiffies + msecs_to_jiffies(1));
1141         } else if (pcmd->res != H2C_SUCCESS) {
1142                 mod_timer(&pmlmepriv->scan_to_timer,
1143                           jiffies + msecs_to_jiffies(1));
1144                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_, ("\n ********Error: MgntActrtw_set_802_11_bssid_LIST_SCAN Fail ************\n\n."));
1145         }
1146
1147         /*  free cmd */
1148         rtw_free_cmd_obj(pcmd);
1149 }
1150
1151 void rtw_disassoc_cmd_callback(struct adapter *padapter, struct cmd_obj *pcmd)
1152 {
1153         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
1154
1155         if (pcmd->res != H2C_SUCCESS) {
1156                 spin_lock_bh(&pmlmepriv->lock);
1157                 set_fwstate(pmlmepriv, _FW_LINKED);
1158                 spin_unlock_bh(&pmlmepriv->lock);
1159
1160                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_, ("\n ***Error: disconnect_cmd_callback Fail ***\n."));
1161                 return;
1162         }
1163
1164         /*  free cmd */
1165         rtw_free_cmd_obj(pcmd);
1166 }
1167
1168 void rtw_joinbss_cmd_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
1169 {
1170         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
1171
1172         if (pcmd->res == H2C_DROPPED) {
1173                 /* TODO: cancel timer and do timeout handler directly... */
1174                 /* need to make timeout handlerOS independent */
1175                 mod_timer(&pmlmepriv->assoc_timer,
1176                           jiffies + msecs_to_jiffies(1));
1177         } else if (pcmd->res != H2C_SUCCESS) {
1178                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_, ("********Error:rtw_select_and_join_from_scanned_queue Wait Sema  Fail ************\n"));
1179                 mod_timer(&pmlmepriv->assoc_timer,
1180                           jiffies + msecs_to_jiffies(1));
1181         }
1182
1183         rtw_free_cmd_obj(pcmd);
1184 }
1185
1186 void rtw_createbss_cmd_callback(struct adapter *padapter, struct cmd_obj *pcmd)
1187 {
1188         struct sta_info *psta = NULL;
1189         struct wlan_network *pwlan = NULL;
1190         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
1191         struct wlan_bssid_ex *pnetwork = (struct wlan_bssid_ex *)pcmd->parmbuf;
1192         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1193
1194         if (pcmd->res != H2C_SUCCESS) {
1195                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_,
1196                          ("\n **** Error: %s  Fail ****\n\n.", __func__));
1197                 mod_timer(&pmlmepriv->assoc_timer,
1198                           jiffies + msecs_to_jiffies(1));
1199         }
1200
1201         del_timer_sync(&pmlmepriv->assoc_timer);
1202
1203         spin_lock_bh(&pmlmepriv->lock);
1204
1205         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1206                 psta = rtw_get_stainfo(&padapter->stapriv, pnetwork->MacAddress);
1207                 if (!psta) {
1208                         psta = rtw_alloc_stainfo(&padapter->stapriv, pnetwork->MacAddress);
1209                         if (!psta) {
1210                                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_, ("\nCan't alloc sta_info when createbss_cmd_callback\n"));
1211                                 goto createbss_cmd_fail;
1212                         }
1213                 }
1214
1215                 rtw_indicate_connect(padapter);
1216         } else {
1217                 pwlan = _rtw_alloc_network(pmlmepriv);
1218                 spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1219                 if (!pwlan) {
1220                         pwlan = rtw_get_oldest_wlan_network(&pmlmepriv->scanned_queue);
1221                         if (!pwlan) {
1222                                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_, ("\n Error:  can't get pwlan in rtw_joinbss_event_callback\n"));
1223                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1224                                 goto createbss_cmd_fail;
1225                         }
1226                         pwlan->last_scanned = jiffies;
1227                 } else {
1228                         list_add_tail(&pwlan->list,
1229                                       &pmlmepriv->scanned_queue.queue);
1230                 }
1231
1232                 pnetwork->Length = get_wlan_bssid_ex_sz(pnetwork);
1233                 memcpy(&pwlan->network, pnetwork, pnetwork->Length);
1234
1235                 memcpy(&tgt_network->network, pnetwork, (get_wlan_bssid_ex_sz(pnetwork)));
1236
1237                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1238
1239                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1240                 /*  we will set _FW_LINKED when there is one more sat to
1241                  *  join us (rtw_stassoc_event_callback)
1242                  */
1243         }
1244
1245 createbss_cmd_fail:
1246
1247         spin_unlock_bh(&pmlmepriv->lock);
1248
1249         rtw_free_cmd_obj(pcmd);
1250 }
1251
1252 void rtw_setstaKey_cmdrsp_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
1253 {
1254         struct sta_priv *pstapriv = &padapter->stapriv;
1255         struct set_stakey_rsp *psetstakey_rsp = (struct set_stakey_rsp *)(pcmd->rsp);
1256         struct sta_info *psta = rtw_get_stainfo(pstapriv, psetstakey_rsp->addr);
1257
1258         if (!psta) {
1259                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_, ("\nERROR: %s => can't get sta_info\n\n", __func__));
1260                 goto exit;
1261         }
1262 exit:
1263         rtw_free_cmd_obj(pcmd);
1264 }
1265
1266 void rtw_setassocsta_cmdrsp_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
1267 {
1268         struct sta_priv *pstapriv = &padapter->stapriv;
1269         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1270         struct set_assocsta_parm *passocsta_parm = (struct set_assocsta_parm *)(pcmd->parmbuf);
1271         struct set_assocsta_rsp *passocsta_rsp = (struct set_assocsta_rsp *)(pcmd->rsp);
1272         struct sta_info *psta = rtw_get_stainfo(pstapriv, passocsta_parm->addr);
1273
1274         if (!psta) {
1275                 RT_TRACE(_module_rtl871x_cmd_c_, _drv_err_, ("\nERROR: %s => can't get sta_info\n\n", __func__));
1276                 goto exit;
1277         }
1278
1279         psta->aid = passocsta_rsp->cam_id;
1280         psta->mac_id = passocsta_rsp->cam_id;
1281
1282         spin_lock_bh(&pmlmepriv->lock);
1283
1284         set_fwstate(pmlmepriv, _FW_LINKED);
1285         spin_unlock_bh(&pmlmepriv->lock);
1286
1287 exit:
1288         rtw_free_cmd_obj(pcmd);
1289 }