GNU Linux-libre 4.19.264-gnu1
[releases.git] / drivers / staging / rtl8188eu / core / rtw_mlme.c
1 // SPDX-License-Identifier: GPL-2.0
2 /******************************************************************************
3  *
4  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
5  *
6  ******************************************************************************/
7 #define _RTW_MLME_C_
8
9 #include <linux/ieee80211.h>
10
11 #include <osdep_service.h>
12 #include <drv_types.h>
13 #include <recv_osdep.h>
14 #include <xmit_osdep.h>
15 #include <hal_intf.h>
16 #include <mlme_osdep.h>
17 #include <sta_info.h>
18 #include <wifi.h>
19 #include <wlan_bssdef.h>
20 #include <rtw_ioctl_set.h>
21 #include <linux/vmalloc.h>
22
23 extern unsigned char    MCS_rate_1R[16];
24
25 int rtw_init_mlme_priv(struct adapter *padapter)
26 {
27         int     i;
28         u8      *pbuf;
29         struct wlan_network     *pnetwork;
30         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
31         int     res = _SUCCESS;
32
33         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by vzalloc(). */
34
35         pmlmepriv->nic_hdl = (u8 *)padapter;
36
37         pmlmepriv->pscanned = NULL;
38         pmlmepriv->fw_state = 0;
39         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
40         pmlmepriv->scan_mode = SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
41
42         spin_lock_init(&(pmlmepriv->lock));
43         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
44         _rtw_init_queue(&(pmlmepriv->scanned_queue));
45
46         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
47
48         pbuf = vzalloc(array_size(MAX_BSS_CNT, sizeof(struct wlan_network)));
49
50         if (!pbuf) {
51                 res = _FAIL;
52                 goto exit;
53         }
54         pmlmepriv->free_bss_buf = pbuf;
55
56         pnetwork = (struct wlan_network *)pbuf;
57
58         for (i = 0; i < MAX_BSS_CNT; i++) {
59                 INIT_LIST_HEAD(&(pnetwork->list));
60
61                 list_add_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
62
63                 pnetwork++;
64         }
65
66         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
67
68         rtw_clear_scan_deny(padapter);
69
70         rtw_init_mlme_timer(padapter);
71
72 exit:
73         return res;
74 }
75
76 #if defined(CONFIG_88EU_AP_MODE)
77 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
78 {
79         kfree(*ppie);
80         *plen = 0;
81         *ppie = NULL;
82 }
83
84 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
85 {
86         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
87         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
88         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
89         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
90         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
91         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
92 }
93 #else
94 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
95 {
96 }
97 #endif
98
99 void rtw_free_mlme_priv(struct mlme_priv *pmlmepriv)
100 {
101         if (pmlmepriv) {
102                 rtw_free_mlme_priv_ie_data(pmlmepriv);
103                 vfree(pmlmepriv->free_bss_buf);
104         }
105 }
106
107 struct wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)
108                                         /* _queue *free_queue) */
109 {
110         struct wlan_network *pnetwork;
111         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
112
113         spin_lock_bh(&free_queue->lock);
114         pnetwork = list_first_entry_or_null(&free_queue->queue,
115                                             struct wlan_network, list);
116         if (!pnetwork)
117                 goto exit;
118
119         list_del_init(&pnetwork->list);
120
121         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
122                  ("_rtw_alloc_network: ptr=%p\n", &pnetwork->list));
123         pnetwork->network_type = 0;
124         pnetwork->fixed = false;
125         pnetwork->last_scanned = jiffies;
126         pnetwork->aid = 0;
127         pnetwork->join_res = 0;
128
129 exit:
130         spin_unlock_bh(&free_queue->lock);
131
132         return pnetwork;
133 }
134
135 static void _rtw_free_network(struct mlme_priv *pmlmepriv, struct wlan_network *pnetwork, u8 isfreeall)
136 {
137         unsigned long curr_time;
138         u32 delta_time;
139         u32 lifetime = SCANQUEUE_LIFETIME;
140         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
141
142         if (!pnetwork)
143                 return;
144
145         if (pnetwork->fixed)
146                 return;
147         curr_time = jiffies;
148         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
149             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)))
150                 lifetime = 1;
151         if (!isfreeall) {
152                 delta_time = (curr_time - pnetwork->last_scanned)/HZ;
153                 if (delta_time < lifetime)/*  unit:sec */
154                         return;
155         }
156         spin_lock_bh(&free_queue->lock);
157         list_del_init(&(pnetwork->list));
158         list_add_tail(&(pnetwork->list), &(free_queue->queue));
159         spin_unlock_bh(&free_queue->lock);
160 }
161
162 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
163 {
164         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
165
166         if (!pnetwork)
167                 return;
168         if (pnetwork->fixed)
169                 return;
170         list_del_init(&(pnetwork->list));
171         list_add_tail(&(pnetwork->list), get_list_head(free_queue));
172 }
173
174 /*
175  * return the wlan_network with the matching addr
176  *
177  * Shall be called under atomic context... to avoid possible racing condition...
178  */
179 struct wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
180 {
181         struct list_head *phead, *plist;
182         struct  wlan_network *pnetwork = NULL;
183         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
184
185         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
186                 pnetwork = NULL;
187                 goto exit;
188         }
189         phead = get_list_head(scanned_queue);
190         plist = phead->next;
191
192         while (plist != phead) {
193                 pnetwork = container_of(plist, struct wlan_network, list);
194                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
195                         break;
196                 plist = plist->next;
197         }
198         if (plist == phead)
199                 pnetwork = NULL;
200 exit:
201         return pnetwork;
202 }
203
204 void rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
205 {
206         struct list_head *phead, *plist;
207         struct wlan_network *pnetwork;
208         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
209         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
210
211         spin_lock_bh(&scanned_queue->lock);
212
213         phead = get_list_head(scanned_queue);
214         plist = phead->next;
215
216         while (phead != plist) {
217                 pnetwork = container_of(plist, struct wlan_network, list);
218
219                 plist = plist->next;
220
221                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
222         }
223         spin_unlock_bh(&scanned_queue->lock);
224 }
225
226 int rtw_if_up(struct adapter *padapter)
227 {
228         int res;
229
230         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
231             (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
232                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
233                          ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)",
234                          padapter->bDriverStopped, padapter->bSurpriseRemoved));
235                 res = false;
236         } else {
237                 res =  true;
238         }
239         return res;
240 }
241
242 void rtw_generate_random_ibss(u8 *pibss)
243 {
244         unsigned long curtime = jiffies;
245
246         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
247         pibss[1] = 0x11;
248         pibss[2] = 0x87;
249         pibss[3] = (u8)(curtime & 0xff);/* p[0]; */
250         pibss[4] = (u8)((curtime>>8) & 0xff);/* p[1]; */
251         pibss[5] = (u8)((curtime>>16) & 0xff);/* p[2]; */
252 }
253
254 u8 *rtw_get_capability_from_ie(u8 *ie)
255 {
256         return ie + 8 + 2;
257 }
258
259 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
260 {
261         __le16  val;
262
263         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->ies), 2);
264
265         return le16_to_cpu(val);
266 }
267
268 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
269 {
270         return ie + 8;
271 }
272
273 static struct wlan_network *rtw_alloc_network(struct mlme_priv *pmlmepriv)
274 {
275         return _rtw_alloc_network(pmlmepriv);
276 }
277
278 static void rtw_free_network_nolock(struct mlme_priv *pmlmepriv,
279                                     struct wlan_network *pnetwork)
280 {
281         _rtw_free_network_nolock(pmlmepriv, pnetwork);
282 }
283
284 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
285 {
286         int ret = true;
287         struct security_priv *psecuritypriv = &adapter->securitypriv;
288
289         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
290             (pnetwork->network.Privacy == 0))
291                 ret = false;
292         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
293                  (pnetwork->network.Privacy == 1))
294                 ret = false;
295         else
296                 ret = true;
297         return ret;
298 }
299
300 static int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
301 {
302         return (a->Ssid.SsidLength == b->Ssid.SsidLength) &&
303                !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
304 }
305
306 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst)
307 {
308          u16 s_cap, d_cap;
309         __le16 le_scap, le_dcap;
310
311         memcpy((u8 *)&le_scap, rtw_get_capability_from_ie(src->ies), 2);
312         memcpy((u8 *)&le_dcap, rtw_get_capability_from_ie(dst->ies), 2);
313
314         s_cap = le16_to_cpu(le_scap);
315         d_cap = le16_to_cpu(le_dcap);
316
317         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
318                 ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN)) == true) &&
319                 ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength)) == true) &&
320                 ((s_cap & WLAN_CAPABILITY_IBSS) ==
321                 (d_cap & WLAN_CAPABILITY_IBSS)) &&
322                 ((s_cap & WLAN_CAPABILITY_ESS) ==
323                 (d_cap & WLAN_CAPABILITY_ESS)));
324 }
325
326 struct  wlan_network    *rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
327 {
328         struct list_head *plist, *phead;
329         struct  wlan_network    *pwlan = NULL;
330         struct  wlan_network    *oldest = NULL;
331
332         phead = get_list_head(scanned_queue);
333
334         for (plist = phead->next; plist != phead; plist = plist->next) {
335                 pwlan = container_of(plist, struct wlan_network, list);
336
337                 if (!pwlan->fixed) {
338                         if (!oldest || time_after(oldest->last_scanned, pwlan->last_scanned))
339                                 oldest = pwlan;
340                 }
341         }
342         return oldest;
343 }
344
345 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
346         struct adapter *padapter, bool update_ie)
347 {
348         long rssi_ori = dst->Rssi;
349         u8 sq_smp = src->PhyInfo.SignalQuality;
350         u8 ss_final;
351         u8 sq_final;
352         long rssi_final;
353
354         rtw_hal_antdiv_rssi_compared(padapter, dst, src); /* this will update src.Rssi, need consider again */
355
356         /* The rule below is 1/5 for sample value, 4/5 for history value */
357         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src)) {
358                 /* Take the recvpriv's value for the connected AP*/
359                 ss_final = padapter->recvpriv.signal_strength;
360                 sq_final = padapter->recvpriv.signal_qual;
361                 /* the rssi value here is undecorated, and will be used for antenna diversity */
362                 if (sq_smp != 101) /* from the right channel */
363                         rssi_final = (src->Rssi + dst->Rssi * 4) / 5;
364                 else
365                         rssi_final = rssi_ori;
366         } else {
367                 if (sq_smp != 101) { /* from the right channel */
368                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
369                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
370                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
371                 } else {
372                         /* bss info not receiving from the right channel, use the original RX signal infos */
373                         ss_final = dst->PhyInfo.SignalStrength;
374                         sq_final = dst->PhyInfo.SignalQuality;
375                         rssi_final = dst->Rssi;
376                 }
377         }
378         if (update_ie)
379                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
380         dst->PhyInfo.SignalStrength = ss_final;
381         dst->PhyInfo.SignalQuality = sq_final;
382         dst->Rssi = rssi_final;
383 }
384
385 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
386 {
387         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
388
389         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) &&
390             (is_same_network(&(pmlmepriv->cur_network.network), pnetwork))) {
391                 update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
392                 rtw_update_protection(adapter, (pmlmepriv->cur_network.network.ies) + sizeof(struct ndis_802_11_fixed_ie),
393                                       pmlmepriv->cur_network.network.ie_length);
394         }
395 }
396
397 /*
398  * Caller must hold pmlmepriv->lock first.
399  */
400 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
401 {
402         struct list_head *plist, *phead;
403         u32     bssid_ex_sz;
404         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
405         struct __queue *queue   = &(pmlmepriv->scanned_queue);
406         struct wlan_network     *pnetwork = NULL;
407         struct wlan_network     *oldest = NULL;
408
409         spin_lock_bh(&queue->lock);
410         phead = get_list_head(queue);
411         plist = phead->next;
412
413         while (phead != plist) {
414                 pnetwork        = container_of(plist, struct wlan_network, list);
415
416                 if (is_same_network(&(pnetwork->network), target))
417                         break;
418                 if ((oldest == ((struct wlan_network *)0)) ||
419                     time_after(oldest->last_scanned, pnetwork->last_scanned))
420                         oldest = pnetwork;
421                 plist = plist->next;
422         }
423         /* If we didn't find a match, then get a new network slot to initialize
424          * with this beacon's information
425          */
426         if (phead == plist) {
427                 if (list_empty(&(pmlmepriv->free_bss_pool.queue))) {
428                         /* If there are no more slots, expire the oldest */
429                         pnetwork = oldest;
430
431                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
432                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
433                         /*  variable initialize */
434                         pnetwork->fixed = false;
435                         pnetwork->last_scanned = jiffies;
436
437                         pnetwork->network_type = 0;
438                         pnetwork->aid = 0;
439                         pnetwork->join_res = 0;
440
441                         /* bss info not receiving from the right channel */
442                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
443                                 pnetwork->network.PhyInfo.SignalQuality = 0;
444                 } else {
445                         /* Otherwise just pull from the free list */
446
447                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
448
449                         if (!pnetwork) {
450                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
451                                 goto exit;
452                         }
453
454                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
455                         target->Length = bssid_ex_sz;
456                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
457                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
458
459                         pnetwork->last_scanned = jiffies;
460
461                         /* bss info not receiving from the right channel */
462                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
463                                 pnetwork->network.PhyInfo.SignalQuality = 0;
464                         list_add_tail(&(pnetwork->list), &(queue->queue));
465                 }
466         } else {
467                 /* we have an entry and we are going to update it. But this entry may
468                  * be already expired. In this case we do the same as we found a new
469                  * net and call the new_net handler
470                  */
471                 bool update_ie = true;
472
473                 pnetwork->last_scanned = jiffies;
474
475                 /* target.Reserved[0]== 1, means that scanned network is a bcn frame. */
476                 if ((pnetwork->network.ie_length > target->ie_length) && (target->Reserved[0] == 1))
477                         update_ie = false;
478
479                 update_network(&(pnetwork->network), target, adapter, update_ie);
480         }
481
482 exit:
483         spin_unlock_bh(&queue->lock);
484 }
485
486 static void rtw_add_network(struct adapter *adapter,
487                             struct wlan_bssid_ex *pnetwork)
488 {
489         update_current_network(adapter, pnetwork);
490         rtw_update_scanned_network(adapter, pnetwork);
491 }
492
493 /*
494  * select the desired network based on the capability of the (i)bss.
495  * check items: (1) security
496  *                      (2) network_type
497  *                      (3) WMM
498  *                      (4) HT
499  *                      (5) others
500  */
501 static int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
502 {
503         struct security_priv *psecuritypriv = &adapter->securitypriv;
504         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
505         u32 desired_encmode;
506         u32 privacy;
507
508         /* u8 wps_ie[512]; */
509         uint wps_ielen;
510
511         int bselected = true;
512
513         desired_encmode = psecuritypriv->ndisencryptstatus;
514         privacy = pnetwork->network.Privacy;
515
516         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
517                 if (rtw_get_wps_ie(pnetwork->network.ies+_FIXED_IE_LENGTH_, pnetwork->network.ie_length-_FIXED_IE_LENGTH_, NULL, &wps_ielen))
518                         return true;
519                 else
520                         return false;
521         }
522         if (adapter->registrypriv.wifi_spec == 1) { /* for  correct flow of 8021X  to do.... */
523                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
524                         bselected = false;
525         }
526
527         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
528                 DBG_88E("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
529                 bselected = false;
530         }
531
532         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true) {
533                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
534                         bselected = false;
535         }
536
537         return bselected;
538 }
539
540 /* TODO: Perry: For Power Management */
541 void rtw_atimdone_event_callback(struct adapter *adapter, u8 *pbuf)
542 {
543         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_evet\n"));
544 }
545
546 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
547 {
548         u32 len;
549         struct wlan_bssid_ex *pnetwork;
550         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
551
552         pnetwork = (struct wlan_bssid_ex *)pbuf;
553
554         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid=%s\n",  pnetwork->Ssid.Ssid));
555
556         len = get_wlan_bssid_ex_sz(pnetwork);
557         if (len > (sizeof(struct wlan_bssid_ex))) {
558                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n****rtw_survey_event_callback: return a wrong bss ***\n"));
559                 return;
560         }
561         spin_lock_bh(&pmlmepriv->lock);
562
563         /*  update IBSS_network 's timestamp */
564         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true) {
565                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN)) {
566                         struct wlan_network *ibss_wlan = NULL;
567
568                         memcpy(pmlmepriv->cur_network.network.ies, pnetwork->ies, 8);
569                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
570                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
571                         if (ibss_wlan) {
572                                 memcpy(ibss_wlan->network.ies, pnetwork->ies, 8);
573                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
574                                 goto exit;
575                         }
576                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
577                 }
578         }
579
580         /*  lock pmlmepriv->lock when you accessing network_q */
581         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false) {
582                 if (pnetwork->Ssid.Ssid[0] == 0)
583                         pnetwork->Ssid.SsidLength = 0;
584                 rtw_add_network(adapter, pnetwork);
585         }
586
587 exit:
588
589         spin_unlock_bh(&pmlmepriv->lock);
590         return;
591 }
592
593 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
594 {
595         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
596
597         spin_lock_bh(&pmlmepriv->lock);
598
599         if (pmlmepriv->wps_probe_req_ie) {
600                 pmlmepriv->wps_probe_req_ie_len = 0;
601                 kfree(pmlmepriv->wps_probe_req_ie);
602                 pmlmepriv->wps_probe_req_ie = NULL;
603         }
604
605         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
606
607         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
608                 del_timer_sync(&pmlmepriv->scan_to_timer);
609                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
610         } else {
611                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status=%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
612         }
613
614         rtw_set_signal_stat_timer(&adapter->recvpriv);
615
616         if (pmlmepriv->to_join) {
617                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)) {
618                         if (check_fwstate(pmlmepriv, _FW_LINKED) == false) {
619                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
620
621                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS) {
622                                         mod_timer(&pmlmepriv->assoc_timer,
623                                                   jiffies + msecs_to_jiffies(MAX_JOIN_TIMEOUT));
624                                 } else {
625                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
626                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
627
628                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
629
630                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
631
632                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
633
634                                         rtw_update_registrypriv_dev_network(adapter);
635                                         rtw_generate_random_ibss(pibss);
636
637                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
638
639                                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
640                                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error=>rtw_createbss_cmd status FAIL\n"));
641                                         pmlmepriv->to_join = false;
642                                 }
643                         }
644                 } else {
645                         int s_ret;
646
647                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
648                         pmlmepriv->to_join = false;
649                         s_ret = rtw_select_and_join_from_scanned_queue(pmlmepriv);
650                         if (s_ret == _SUCCESS) {
651                                 mod_timer(&pmlmepriv->assoc_timer,
652                                         jiffies + msecs_to_jiffies(MAX_JOIN_TIMEOUT));
653                         } else if (s_ret == 2) { /* there is no need to wait for join */
654                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
655                                 rtw_indicate_connect(adapter);
656                         } else {
657                                 DBG_88E("try_to_join, but select scanning queue fail, to_roaming:%d\n", pmlmepriv->to_roaming);
658                                 if (pmlmepriv->to_roaming != 0) {
659                                         if (--pmlmepriv->to_roaming == 0 ||
660                                             rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0) != _SUCCESS) {
661                                                 pmlmepriv->to_roaming = 0;
662                                                 rtw_free_assoc_resources(adapter);
663                                                 rtw_indicate_disconnect(adapter);
664                                         } else {
665                                                 pmlmepriv->to_join = true;
666                                         }
667                                 }
668                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
669                         }
670                 }
671         }
672
673         indicate_wx_scan_complete_event(adapter);
674
675         spin_unlock_bh(&pmlmepriv->lock);
676
677         rtw_os_xmit_schedule(adapter);
678 }
679
680 void rtw_dummy_event_callback(struct adapter *adapter, u8 *pbuf)
681 {
682 }
683
684 void rtw_fwdbg_event_callback(struct adapter *adapter, u8 *pbuf)
685 {
686 }
687
688 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
689 {
690         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
691         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
692         struct list_head *plist, *phead, *ptemp;
693
694         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
695         spin_lock_bh(&scan_queue->lock);
696         spin_lock_bh(&free_queue->lock);
697
698         phead = get_list_head(scan_queue);
699         plist = phead->next;
700
701         while (plist != phead) {
702                 ptemp = plist->next;
703                 list_del_init(plist);
704                 list_add_tail(plist, &free_queue->queue);
705                 plist = ptemp;
706         }
707
708         spin_unlock_bh(&free_queue->lock);
709         spin_unlock_bh(&scan_queue->lock);
710 }
711
712 /*
713  * rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
714  */
715 void rtw_free_assoc_resources(struct adapter *adapter)
716 {
717         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
718
719         spin_lock_bh(&pmlmepriv->scanned_queue.lock);
720         rtw_free_assoc_resources_locked(adapter);
721         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
722 }
723
724 /*
725  * rtw_free_assoc_resources_locked: the caller has to lock pmlmepriv->lock
726  */
727 void rtw_free_assoc_resources_locked(struct adapter *adapter)
728 {
729         struct wlan_network *pwlan = NULL;
730         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
731         struct  sta_priv *pstapriv = &adapter->stapriv;
732         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
733
734         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
735         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
736                  ("tgt_network->network.MacAddress=%pM ssid=%s\n",
737                  tgt_network->network.MacAddress, tgt_network->network.Ssid.Ssid));
738
739         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_AP_STATE)) {
740                 struct sta_info *psta;
741
742                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
743
744                 spin_lock_bh(&(pstapriv->sta_hash_lock));
745                 rtw_free_stainfo(adapter,  psta);
746                 spin_unlock_bh(&pstapriv->sta_hash_lock);
747         }
748
749         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE | WIFI_ADHOC_MASTER_STATE | WIFI_AP_STATE)) {
750                 struct sta_info *psta;
751
752                 rtw_free_all_stainfo(adapter);
753
754                 psta = rtw_get_bcmc_stainfo(adapter);
755                 spin_lock_bh(&(pstapriv->sta_hash_lock));
756                 rtw_free_stainfo(adapter, psta);
757                 spin_unlock_bh(&pstapriv->sta_hash_lock);
758
759                 rtw_init_bcmc_stainfo(adapter);
760         }
761
762         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
763         if (pwlan)
764                 pwlan->fixed = false;
765         else
766                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources:pwlan==NULL\n\n"));
767
768         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) && (adapter->stapriv.asoc_sta_count == 1)))
769                 rtw_free_network_nolock(pmlmepriv, pwlan);
770
771         pmlmepriv->key_mask = 0;
772 }
773
774 /*
775  * rtw_indicate_connect: the caller has to lock pmlmepriv->lock
776  */
777 void rtw_indicate_connect(struct adapter *padapter)
778 {
779         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
780
781         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+%s\n", __func__));
782
783         pmlmepriv->to_join = false;
784
785         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
786                 set_fwstate(pmlmepriv, _FW_LINKED);
787
788                 LedControl8188eu(padapter, LED_CTL_LINK);
789
790                 rtw_os_indicate_connect(padapter);
791         }
792
793         pmlmepriv->to_roaming = 0;
794
795         rtw_set_scan_deny(padapter, 3000);
796
797         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-%s: fw_state=0x%08x\n", __func__, get_fwstate(pmlmepriv)));
798 }
799
800 /*
801  * rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
802  */
803 void rtw_indicate_disconnect(struct adapter *padapter)
804 {
805         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
806
807         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
808
809         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING | WIFI_UNDER_WPS);
810
811         if (pmlmepriv->to_roaming > 0)
812                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
813
814         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) ||
815             (pmlmepriv->to_roaming <= 0)) {
816                 rtw_os_indicate_disconnect(padapter);
817
818                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
819                 LedControl8188eu(padapter, LED_CTL_NO_LINK);
820                 rtw_clear_scan_deny(padapter);
821         }
822
823         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
824 }
825
826 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
827 {
828         rtw_os_indicate_scan_done(padapter, aborted);
829 }
830
831 void rtw_scan_abort(struct adapter *adapter)
832 {
833         unsigned long start;
834         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
835         struct mlme_ext_priv    *pmlmeext = &(adapter->mlmeextpriv);
836
837         start = jiffies;
838         pmlmeext->scan_abort = true;
839         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY) &&
840                jiffies_to_msecs(jiffies - start) <= 200) {
841                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
842                         break;
843                 DBG_88E(FUNC_NDEV_FMT"fw_state=_FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
844                 msleep(20);
845         }
846         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
847                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
848                         DBG_88E(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
849                 rtw_indicate_scan_done(adapter, true);
850         }
851         pmlmeext->scan_abort = false;
852 }
853
854 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
855 {
856         int i;
857         struct sta_info *bmc_sta, *psta = NULL;
858         struct recv_reorder_ctrl *preorder_ctrl;
859         struct sta_priv *pstapriv = &padapter->stapriv;
860
861         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
862         if (!psta)
863                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
864
865         if (psta) { /* update ptarget_sta */
866                 DBG_88E("%s\n", __func__);
867                 psta->aid  = pnetwork->join_res;
868                         psta->mac_id = 0;
869                 /* sta mode */
870                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
871                 /* security related */
872                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
873                         padapter->securitypriv.binstallGrpkey = false;
874                         padapter->securitypriv.busetkipkey = false;
875                         padapter->securitypriv.bgrpkey_handshake = false;
876                         psta->ieee8021x_blocked = true;
877                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
878                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof(union Keytype));
879                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof(union Keytype));
880                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof(union Keytype));
881                         memset((u8 *)&psta->dot11txpn, 0, sizeof(union pn48));
882                         memset((u8 *)&psta->dot11rxpn, 0, sizeof(union pn48));
883                 }
884                 /*
885                  * Commented by Albert 2012/07/21
886                  * When doing the WPS, the wps_ie_len won't equal to 0
887                  * And the Wi-Fi driver shouldn't allow the data
888                  * packet to be transmitted.
889                  */
890                 if (padapter->securitypriv.wps_ie_len != 0) {
891                         psta->ieee8021x_blocked = true;
892                         padapter->securitypriv.wps_ie_len = 0;
893                 }
894                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
895                 /* if A-MPDU Rx is enabled, resetting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
896                 /* todo: check if AP can send A-MPDU packets */
897                 for (i = 0; i < 16; i++) {
898                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
899                         preorder_ctrl = &psta->recvreorder_ctrl[i];
900                         preorder_ctrl->enable = false;
901                         preorder_ctrl->indicate_seq = 0xffff;
902                         preorder_ctrl->wend_b = 0xffff;
903                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
904                 }
905                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
906                 if (bmc_sta) {
907                         for (i = 0; i < 16; i++) {
908                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
909                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
910                                 preorder_ctrl->enable = false;
911                                 preorder_ctrl->indicate_seq = 0xffff;
912                                 preorder_ctrl->wend_b = 0xffff;
913                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz; ex. 32(kbytes) -> wsize_b = 32 */
914                         }
915                 }
916                 /* misc. */
917                 update_sta_info(padapter, psta);
918         }
919         return psta;
920 }
921
922 /* pnetwork: returns from rtw_joinbss_event_callback */
923 /* ptarget_wlan: found from scanned_queue */
924 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
925 {
926         struct mlme_priv        *pmlmepriv = &(padapter->mlmepriv);
927         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
928
929         DBG_88E("%s\n", __func__);
930
931         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
932                  ("\nfw_state:%x, BSSID:%pM\n",
933                  get_fwstate(pmlmepriv), pnetwork->network.MacAddress));
934
935         /*  why not use ptarget_wlan?? */
936         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
937         /*  some ies in pnetwork is wrong, so we should use ptarget_wlan ies */
938         cur_network->network.ie_length = ptarget_wlan->network.ie_length;
939         memcpy(&cur_network->network.ies[0], &ptarget_wlan->network.ies[0], MAX_IE_SZ);
940
941         cur_network->aid = pnetwork->join_res;
942
943         rtw_set_signal_stat_timer(&padapter->recvpriv);
944         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
945         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
946         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
947         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
948         rtw_set_signal_stat_timer(&padapter->recvpriv);
949
950         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
951         switch (pnetwork->network.InfrastructureMode) {
952         case Ndis802_11Infrastructure:
953                 if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
954                         pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
955                 else
956                         pmlmepriv->fw_state = WIFI_STATION_STATE;
957                 break;
958         case Ndis802_11IBSS:
959                 pmlmepriv->fw_state = WIFI_ADHOC_STATE;
960                 break;
961         default:
962                 pmlmepriv->fw_state = WIFI_NULL_STATE;
963                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
964                 break;
965         }
966
967         rtw_update_protection(padapter, (cur_network->network.ies) +
968                               sizeof(struct ndis_802_11_fixed_ie),
969                               (cur_network->network.ie_length));
970         rtw_update_ht_cap(padapter, cur_network->network.ies, cur_network->network.ie_length);
971 }
972
973 /* Notes: the function could be > passive_level (the same context as Rx tasklet) */
974 /* pnetwork: returns from rtw_joinbss_event_callback */
975 /* ptarget_wlan: found from scanned_queue */
976 /* if join_res > 0, for (fw_state == WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
977 /* if join_res > 0, for (fw_state == WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
978 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
979
980 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
981 {
982         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
983         struct  sta_priv *pstapriv = &adapter->stapriv;
984         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
985         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
986         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
987         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
988         unsigned int            the_same_macaddr = false;
989
990         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res=%d\n", pnetwork->join_res));
991
992         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
993
994         if (pmlmepriv->assoc_ssid.SsidLength == 0)
995                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
996         else
997                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
998
999         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1000
1001         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1002         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex)) {
1003                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1004                 return;
1005         }
1006
1007         spin_lock_bh(&pmlmepriv->lock);
1008
1009         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nrtw_joinbss_event_callback!! _enter_critical\n"));
1010
1011         if (pnetwork->join_res > 0) {
1012                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1013                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) {
1014                         /* s1. find ptarget_wlan */
1015                         if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1016                                 if (the_same_macaddr) {
1017                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1018                                 } else {
1019                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1020                                         if (pcur_wlan)
1021                                                 pcur_wlan->fixed = false;
1022
1023                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1024                                         if (pcur_sta) {
1025                                                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1026                                                 rtw_free_stainfo(adapter,  pcur_sta);
1027                                                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1028                                         }
1029
1030                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1031                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1032                                                 if (ptarget_wlan)
1033                                                         ptarget_wlan->fixed = true;
1034                                         }
1035                                 }
1036                         } else {
1037                                 ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1038                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1039                                         if (ptarget_wlan)
1040                                                 ptarget_wlan->fixed = true;
1041                                 }
1042                         }
1043
1044                         /* s2. update cur_network */
1045                         if (ptarget_wlan) {
1046                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1047                         } else {
1048                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't find ptarget_wlan when joinbss_event callback\n"));
1049                                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1050                                 goto ignore_joinbss_callback;
1051                         }
1052
1053                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1054                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1055                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1056                                 if (!ptarget_sta) {
1057                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1058                                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1059                                         goto ignore_joinbss_callback;
1060                                 }
1061                         }
1062
1063                         /* s4. indicate connect */
1064                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1065                                         rtw_indicate_connect(adapter);
1066                                 } else {
1067                                         /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1068                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1069                                 }
1070
1071                         /* s5. Cancel assoc_timer */
1072                         del_timer_sync(&pmlmepriv->assoc_timer);
1073
1074                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancel assoc_timer\n"));
1075
1076                 } else {
1077                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1078                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1079                         goto ignore_joinbss_callback;
1080                 }
1081
1082                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1083
1084         } else if (pnetwork->join_res == -4) {
1085                 rtw_reset_securitypriv(adapter);
1086                 mod_timer(&pmlmepriv->assoc_timer,
1087                           jiffies + msecs_to_jiffies(1));
1088
1089                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true) {
1090                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state=%x\n", get_fwstate(pmlmepriv)));
1091                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1092                 }
1093         } else { /* if join_res < 0 (join fails), then try again */
1094                 mod_timer(&pmlmepriv->assoc_timer,
1095                           jiffies + msecs_to_jiffies(1));
1096                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1097         }
1098
1099 ignore_joinbss_callback:
1100         spin_unlock_bh(&pmlmepriv->lock);
1101 }
1102
1103 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1104 {
1105         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1106
1107         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1108
1109         rtw_os_xmit_schedule(adapter);
1110 }
1111
1112 static u8 search_max_mac_id(struct adapter *padapter)
1113 {
1114         u8 mac_id;
1115 #if defined(CONFIG_88EU_AP_MODE)
1116         u8 aid;
1117         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1118         struct sta_priv *pstapriv = &padapter->stapriv;
1119 #endif
1120         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
1121         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
1122
1123 #if defined(CONFIG_88EU_AP_MODE)
1124         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1125                 for (aid = pstapriv->max_num_sta; aid > 0; aid--) {
1126                         if (pstapriv->sta_aid[aid-1])
1127                                 break;
1128                 }
1129                 mac_id = aid + 1;
1130         } else
1131 #endif
1132         {/* adhoc  id =  31~2 */
1133                 for (mac_id = NUM_STA-1; mac_id >= IBSS_START_MAC_ID; mac_id--) {
1134                         if (pmlmeinfo->FW_sta_info[mac_id].status == 1)
1135                                 break;
1136                 }
1137         }
1138         return mac_id;
1139 }
1140
1141 /* FOR AP , AD-HOC mode */
1142 void rtw_stassoc_hw_rpt(struct adapter *adapter, struct sta_info *psta)
1143 {
1144         u16 media_status;
1145         u8 macid;
1146
1147         if (!psta)
1148                 return;
1149
1150         macid = search_max_mac_id(adapter);
1151         rtw_hal_set_hwreg(adapter, HW_VAR_TX_RPT_MAX_MACID, (u8 *)&macid);
1152         media_status = (psta->mac_id<<8)|1; /*   MACID|OPMODE:1 connect */
1153         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1154 }
1155
1156 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1157 {
1158         struct sta_info *psta;
1159         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1160         struct stassoc_event    *pstassoc = (struct stassoc_event *)pbuf;
1161         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1162         struct wlan_network     *ptarget_wlan = NULL;
1163
1164         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1165                 return;
1166
1167 #if defined(CONFIG_88EU_AP_MODE)
1168         if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1169                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1170                 if (psta) {
1171                         ap_sta_info_defer_update(adapter, psta);
1172                         rtw_stassoc_hw_rpt(adapter, psta);
1173                 }
1174                 return;
1175         }
1176 #endif
1177         /* for AD-HOC mode */
1178         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1179         if (psta) {
1180                 /* the sta have been in sta_info_queue => do nothing */
1181                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1182                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1183         }
1184         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1185         if (!psta) {
1186                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1187                 return;
1188         }
1189         /* to do: init sta_info variable */
1190         psta->qos_option = 0;
1191         psta->mac_id = (uint)pstassoc->cam_id;
1192         DBG_88E("%s\n", __func__);
1193         /* for ad-hoc mode */
1194         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1195         rtw_stassoc_hw_rpt(adapter, psta);
1196         if (adapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1197                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1198         psta->ieee8021x_blocked = false;
1199         spin_lock_bh(&pmlmepriv->lock);
1200         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) ||
1201             (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE))) {
1202                 if (adapter->stapriv.asoc_sta_count == 2) {
1203                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1204                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1205                         if (ptarget_wlan)
1206                                 ptarget_wlan->fixed = true;
1207                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1208                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1209                         rtw_indicate_connect(adapter);
1210                 }
1211         }
1212         spin_unlock_bh(&pmlmepriv->lock);
1213         mlmeext_sta_add_event_callback(adapter, psta);
1214 }
1215
1216 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1217 {
1218         int mac_id = -1;
1219         struct sta_info *psta;
1220         struct wlan_network *pwlan = NULL;
1221         struct wlan_bssid_ex *pdev_network = NULL;
1222         u8 *pibss = NULL;
1223         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1224         struct  stadel_event *pstadel = (struct stadel_event *)pbuf;
1225         struct  sta_priv *pstapriv = &adapter->stapriv;
1226         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1227
1228         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1229         if (psta)
1230                 mac_id = psta->mac_id;
1231         else
1232                 mac_id = pstadel->mac_id;
1233
1234         DBG_88E("%s(mac_id=%d)=%pM\n", __func__, mac_id, pstadel->macaddr);
1235
1236         if (mac_id >= 0) {
1237                 u16 media_status;
1238
1239                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1240                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1241                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1242         }
1243
1244         if (check_fwstate(pmlmepriv, WIFI_AP_STATE))
1245                 return;
1246
1247         mlmeext_sta_del_event_callback(adapter);
1248
1249         spin_lock_bh(&pmlmepriv->lock);
1250
1251         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
1252                 if (pmlmepriv->to_roaming > 0)
1253                         pmlmepriv->to_roaming--; /*  this stadel_event is caused by roaming, decrease to_roaming */
1254                 else if (pmlmepriv->to_roaming == 0)
1255                         pmlmepriv->to_roaming = adapter->registrypriv.max_roaming_times;
1256
1257                 if (*((unsigned short *)(pstadel->rsvd)) != WLAN_REASON_EXPIRATION_CHK)
1258                         pmlmepriv->to_roaming = 0; /*  don't roam */
1259
1260                 rtw_free_uc_swdec_pending_queue(adapter);
1261
1262                 rtw_free_assoc_resources(adapter);
1263                 rtw_indicate_disconnect(adapter);
1264                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1265                 /*  remove the network entry in scanned_queue */
1266                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1267                 if (pwlan) {
1268                         pwlan->fixed = false;
1269                         rtw_free_network_nolock(pmlmepriv, pwlan);
1270                 }
1271                 spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1272                 _rtw_roaming(adapter, tgt_network);
1273         }
1274         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1275             check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1276                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1277                 rtw_free_stainfo(adapter,  psta);
1278                 spin_unlock_bh(&pstapriv->sta_hash_lock);
1279
1280                 if (adapter->stapriv.asoc_sta_count == 1) { /* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1281                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1282                         /* free old ibss network */
1283                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1284                         if (pwlan) {
1285                                 pwlan->fixed = false;
1286                                 rtw_free_network_nolock(pmlmepriv, pwlan);
1287                         }
1288                         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1289                         /* re-create ibss */
1290                         pdev_network = &(adapter->registrypriv.dev_network);
1291                         pibss = adapter->registrypriv.dev_network.MacAddress;
1292
1293                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1294
1295                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1296
1297                         rtw_update_registrypriv_dev_network(adapter);
1298
1299                         rtw_generate_random_ibss(pibss);
1300
1301                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1302                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1303                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1304                         }
1305
1306                         if (rtw_createbss_cmd(adapter) != _SUCCESS)
1307                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error=>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1308                 }
1309         }
1310         spin_unlock_bh(&pmlmepriv->lock);
1311 }
1312
1313 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1314 {
1315         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1316 }
1317
1318 /*
1319  * _rtw_join_timeout_handler - Timeout/failure handler for CMD JoinBss
1320  * @adapter: pointer to struct adapter structure
1321  */
1322 void _rtw_join_timeout_handler (struct timer_list *t)
1323 {
1324         struct adapter *adapter =
1325                 from_timer(adapter, t, mlmepriv.assoc_timer);
1326         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1327         int do_join_r;
1328
1329         DBG_88E("%s, fw_state=%x\n", __func__, get_fwstate(pmlmepriv));
1330
1331         if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1332                 return;
1333
1334         spin_lock_bh(&pmlmepriv->lock);
1335
1336         if (pmlmepriv->to_roaming > 0) { /*  join timeout caused by roaming */
1337                 while (1) {
1338                         pmlmepriv->to_roaming--;
1339                         if (pmlmepriv->to_roaming != 0) { /* try another , */
1340                                 DBG_88E("%s try another roaming\n", __func__);
1341                                 do_join_r = rtw_do_join(adapter);
1342                                 if (do_join_r != _SUCCESS) {
1343                                         DBG_88E("%s roaming do_join return %d\n", __func__, do_join_r);
1344                                         continue;
1345                                 }
1346                                 break;
1347                         } else {
1348                                 DBG_88E("%s We've try roaming but fail\n", __func__);
1349                                 rtw_indicate_disconnect(adapter);
1350                                 break;
1351                         }
1352                 }
1353         } else {
1354                 rtw_indicate_disconnect(adapter);
1355                 free_scanqueue(pmlmepriv);/*  */
1356         }
1357         spin_unlock_bh(&pmlmepriv->lock);
1358 }
1359
1360 /*
1361  * rtw_scan_timeout_handler - Timeout/Failure handler for CMD SiteSurvey
1362  * @adapter: pointer to struct adapter structure
1363  */
1364 void rtw_scan_timeout_handler (struct timer_list *t)
1365 {
1366         struct adapter *adapter =
1367                 from_timer(adapter, t, mlmepriv.scan_to_timer);
1368         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1369
1370         DBG_88E(FUNC_ADPT_FMT" fw_state=%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1371         spin_lock_bh(&pmlmepriv->lock);
1372         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1373         spin_unlock_bh(&pmlmepriv->lock);
1374         rtw_indicate_scan_done(adapter, true);
1375 }
1376
1377 static void rtw_auto_scan_handler(struct adapter *padapter)
1378 {
1379         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1380
1381         /* auto site survey per 60sec */
1382         if (pmlmepriv->scan_interval > 0) {
1383                 pmlmepriv->scan_interval--;
1384                 if (pmlmepriv->scan_interval == 0) {
1385                         DBG_88E("%s\n", __func__);
1386                         rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
1387                         pmlmepriv->scan_interval = SCAN_INTERVAL;/*  30*2 sec = 60sec */
1388                 }
1389         }
1390 }
1391
1392 void rtw_dynamic_check_timer_handlder(struct timer_list *t)
1393 {
1394         struct adapter *adapter =
1395                 from_timer(adapter, t, mlmepriv.dynamic_chk_timer);
1396         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1397
1398         if (!adapter)
1399                 return;
1400         if (!adapter->hw_init_completed)
1401                 goto exit;
1402         if ((adapter->bDriverStopped) || (adapter->bSurpriseRemoved))
1403                 goto exit;
1404         if (adapter->net_closed)
1405                 goto exit;
1406         rtw_dynamic_chk_wk_cmd(adapter);
1407
1408         if (pregistrypriv->wifi_spec == 1) {
1409                 /* auto site survey */
1410                 rtw_auto_scan_handler(adapter);
1411         }
1412 exit:
1413         mod_timer(&adapter->mlmepriv.dynamic_chk_timer,
1414                   jiffies + msecs_to_jiffies(2000));
1415 }
1416
1417 #define RTW_SCAN_RESULT_EXPIRE 2000
1418
1419 /*
1420  * Select a new join candidate from the original @param candidate and @param competitor
1421  * @return true: candidate is updated
1422  * @return false: candidate is not updated
1423  */
1424 static int rtw_check_join_candidate(struct mlme_priv *pmlmepriv
1425         , struct wlan_network **candidate, struct wlan_network *competitor)
1426 {
1427         int updated = false;
1428         unsigned long since_scan;
1429         struct adapter *adapter = container_of(pmlmepriv, struct adapter, mlmepriv);
1430
1431         /* check bssid, if needed */
1432         if (pmlmepriv->assoc_by_bssid) {
1433                 if (memcmp(competitor->network.MacAddress, pmlmepriv->assoc_bssid, ETH_ALEN))
1434                         goto exit;
1435         }
1436
1437         /* check ssid, if needed */
1438         if (pmlmepriv->assoc_ssid.SsidLength) {
1439                 if (competitor->network.Ssid.SsidLength != pmlmepriv->assoc_ssid.SsidLength ||
1440                     !memcmp(competitor->network.Ssid.Ssid, pmlmepriv->assoc_ssid.Ssid, pmlmepriv->assoc_ssid.SsidLength) == false)
1441                         goto exit;
1442         }
1443
1444         if (rtw_is_desired_network(adapter, competitor)  == false)
1445                 goto exit;
1446
1447         if (pmlmepriv->to_roaming) {
1448                 since_scan = jiffies - competitor->last_scanned;
1449                 if (jiffies_to_msecs(since_scan) >= RTW_SCAN_RESULT_EXPIRE ||
1450                     is_same_ess(&competitor->network, &pmlmepriv->cur_network.network) == false)
1451                         goto exit;
1452         }
1453
1454         if (*candidate == NULL || (*candidate)->network.Rssi < competitor->network.Rssi) {
1455                 *candidate = competitor;
1456                 updated = true;
1457         }
1458         if (updated) {
1459                 DBG_88E("[by_bssid:%u][assoc_ssid:%s]new candidate: %s(%pM rssi:%d\n",
1460                         pmlmepriv->assoc_by_bssid,
1461                         pmlmepriv->assoc_ssid.Ssid,
1462                         (*candidate)->network.Ssid.Ssid,
1463                         (*candidate)->network.MacAddress,
1464                         (int)(*candidate)->network.Rssi);
1465                 DBG_88E("[to_roaming:%u]\n", pmlmepriv->to_roaming);
1466         }
1467
1468 exit:
1469         return updated;
1470 }
1471
1472 /*
1473  * Calling context:
1474  * The caller of the sub-routine will be in critical section...
1475  * The caller must hold the following spinlock
1476  * pmlmepriv->lock
1477  */
1478
1479 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
1480 {
1481         int ret;
1482         struct list_head *phead;
1483         struct adapter *adapter;
1484         struct __queue *queue   = &(pmlmepriv->scanned_queue);
1485         struct  wlan_network    *pnetwork = NULL;
1486         struct  wlan_network    *candidate = NULL;
1487         u8      supp_ant_div = false;
1488
1489         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1490         phead = get_list_head(queue);
1491         adapter = (struct adapter *)pmlmepriv->nic_hdl;
1492         pmlmepriv->pscanned = phead->next;
1493         while (phead != pmlmepriv->pscanned) {
1494                 pnetwork = container_of(pmlmepriv->pscanned, struct wlan_network, list);
1495                 if (!pnetwork) {
1496                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork==NULL)\n", __func__));
1497                         ret = _FAIL;
1498                         goto exit;
1499                 }
1500                 pmlmepriv->pscanned = pmlmepriv->pscanned->next;
1501                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
1502         }
1503         if (!candidate) {
1504                 DBG_88E("%s: return _FAIL(candidate==NULL)\n", __func__);
1505                 ret = _FAIL;
1506                 goto exit;
1507         } else {
1508                 DBG_88E("%s: candidate: %s(%pM ch:%u)\n", __func__,
1509                         candidate->network.Ssid.Ssid, candidate->network.MacAddress,
1510                         candidate->network.Configuration.DSConfig);
1511         }
1512
1513         /*  check for situation of  _FW_LINKED */
1514         if (check_fwstate(pmlmepriv, _FW_LINKED) == true) {
1515                 DBG_88E("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
1516
1517                 rtw_disassoc_cmd(adapter, 0, true);
1518                 rtw_indicate_disconnect(adapter);
1519                 rtw_free_assoc_resources_locked(adapter);
1520         }
1521
1522         rtw_hal_get_def_var(adapter, HAL_DEF_IS_SUPPORT_ANT_DIV, &(supp_ant_div));
1523         if (supp_ant_div) {
1524                 u8 cur_ant;
1525
1526                 rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(cur_ant));
1527                 DBG_88E("#### Opt_Ant_(%s), cur_Ant(%s)\n",
1528                         (candidate->network.PhyInfo.Optimum_antenna == 2) ? "A" : "B",
1529                         (cur_ant == 2) ? "A" : "B"
1530                 );
1531         }
1532
1533         ret = rtw_joinbss_cmd(adapter, candidate);
1534
1535 exit:
1536         spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1537         return ret;
1538 }
1539
1540 int rtw_set_auth(struct adapter *adapter, struct security_priv *psecuritypriv)
1541 {
1542         struct  cmd_obj *pcmd;
1543         struct  setauth_parm *psetauthparm;
1544         struct  cmd_priv *pcmdpriv = &(adapter->cmdpriv);
1545         int             res = _SUCCESS;
1546
1547         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
1548         if (!pcmd) {
1549                 res = _FAIL;  /* try again */
1550                 goto exit;
1551         }
1552
1553         psetauthparm = kzalloc(sizeof(struct setauth_parm), GFP_KERNEL);
1554         if (!psetauthparm) {
1555                 kfree(pcmd);
1556                 res = _FAIL;
1557                 goto exit;
1558         }
1559         psetauthparm->mode = (unsigned char)psecuritypriv->dot11AuthAlgrthm;
1560         pcmd->cmdcode = _SetAuth_CMD_;
1561         pcmd->parmbuf = (unsigned char *)psetauthparm;
1562         pcmd->cmdsz =  sizeof(struct setauth_parm);
1563         pcmd->rsp = NULL;
1564         pcmd->rspsz = 0;
1565         INIT_LIST_HEAD(&pcmd->list);
1566         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1567                  ("after enqueue set_auth_cmd, auth_mode=%x\n",
1568                  psecuritypriv->dot11AuthAlgrthm));
1569         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1570 exit:
1571         return res;
1572 }
1573
1574 int rtw_set_key(struct adapter *adapter, struct security_priv *psecuritypriv, int keyid, u8 set_tx)
1575 {
1576         u8      keylen;
1577         struct cmd_obj          *pcmd;
1578         struct setkey_parm      *psetkeyparm;
1579         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
1580         struct mlme_priv                *pmlmepriv = &(adapter->mlmepriv);
1581         int     res = _SUCCESS;
1582
1583         pcmd = kzalloc(sizeof(struct cmd_obj), GFP_KERNEL);
1584         if (!pcmd)
1585                 return _FAIL;  /* try again */
1586
1587         psetkeyparm = kzalloc(sizeof(struct setkey_parm), GFP_KERNEL);
1588         if (!psetkeyparm) {
1589                 res = _FAIL;
1590                 goto err_free_cmd;
1591         }
1592
1593         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) {
1594                 psetkeyparm->algorithm = (unsigned char)psecuritypriv->dot118021XGrpPrivacy;
1595                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1596                          ("\n rtw_set_key: psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy=%d\n",
1597                          psetkeyparm->algorithm));
1598         } else {
1599                 psetkeyparm->algorithm = (u8)psecuritypriv->dot11PrivacyAlgrthm;
1600                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1601                          ("\n rtw_set_key: psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm=%d\n",
1602                          psetkeyparm->algorithm));
1603         }
1604         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
1605         psetkeyparm->set_tx = set_tx;
1606         pmlmepriv->key_mask |= BIT(psetkeyparm->keyid);
1607         DBG_88E("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n",
1608                 psetkeyparm->algorithm, psetkeyparm->keyid, pmlmepriv->key_mask);
1609         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1610                  ("\n rtw_set_key: psetkeyparm->algorithm=%d psetkeyparm->keyid=(u8)keyid=%d\n",
1611                  psetkeyparm->algorithm, keyid));
1612
1613         switch (psetkeyparm->algorithm) {
1614         case _WEP40_:
1615                 keylen = 5;
1616                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1617                 break;
1618         case _WEP104_:
1619                 keylen = 13;
1620                 memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
1621                 break;
1622         case _TKIP_:
1623                 keylen = 16;
1624                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1625                 psetkeyparm->grpkey = 1;
1626                 break;
1627         case _AES_:
1628                 keylen = 16;
1629                 memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
1630                 psetkeyparm->grpkey = 1;
1631                 break;
1632         default:
1633                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,
1634                          ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm=%x (must be 1 or 2 or 4 or 5)\n",
1635                          psecuritypriv->dot11PrivacyAlgrthm));
1636                 res = _FAIL;
1637                 goto err_free_parm;
1638         }
1639         pcmd->cmdcode = _SetKey_CMD_;
1640         pcmd->parmbuf = (u8 *)psetkeyparm;
1641         pcmd->cmdsz =  sizeof(struct setkey_parm);
1642         pcmd->rsp = NULL;
1643         pcmd->rspsz = 0;
1644         INIT_LIST_HEAD(&pcmd->list);
1645         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
1646         return res;
1647
1648 err_free_parm:
1649         kfree(psetkeyparm);
1650 err_free_cmd:
1651         kfree(pcmd);
1652         return res;
1653 }
1654
1655 /* adjust ies for rtw_joinbss_cmd in WMM */
1656 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
1657 {
1658         unsigned        int ielength = 0;
1659         unsigned int i, j;
1660
1661         /* i = 12; after the fixed IE */
1662         for (i = 12; i < in_len; i += (in_ie[i + 1] + 2) /* to the next IE element */) {
1663                 ielength = initial_out_len;
1664
1665                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) {
1666                         /* WMM element ID and OUI */
1667                         /* Append WMM IE to the last index of out_ie */
1668
1669                         for (j = i; j < i + 9; j++) {
1670                                 out_ie[ielength] = in_ie[j];
1671                                 ielength++;
1672                         }
1673                         out_ie[initial_out_len + 1] = 0x07;
1674                         out_ie[initial_out_len + 6] = 0x00;
1675                         out_ie[initial_out_len + 8] = 0x00;
1676                         break;
1677                 }
1678         }
1679         return ielength;
1680 }
1681
1682 /*
1683  * Ported from 8185: IsInPreAuthKeyList().
1684  * (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.)
1685  * Added by Annie, 2006-05-07.
1686  * Search by BSSID,
1687  * Return Value:
1688  *              -1      :if there is no pre-auth key in the table
1689  *              >= 0    :if there is pre-auth key, and return the entry id
1690  */
1691 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
1692 {
1693         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1694         int i = 0;
1695
1696         do {
1697                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
1698                     (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN)))
1699                         break;
1700         } while (++i < NUM_PMKID_CACHE);
1701
1702         if (i == NUM_PMKID_CACHE)
1703                 i = -1;/*  Could not find. */
1704
1705         return i;
1706 }
1707
1708 /*  */
1709 /*  Check the RSN IE length */
1710 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
1711 /*  0-11th element in the array are the fixed IE */
1712 /*  12th element in the array is the IE */
1713 /*  13th element in the array is the IE length */
1714 /*  */
1715
1716 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
1717 {
1718         struct security_priv *psecuritypriv = &Adapter->securitypriv;
1719
1720         if (ie[13] <= 20) {
1721                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
1722                 ie[ie_len] = 1;
1723                 ie_len++;
1724                 ie[ie_len] = 0; /* PMKID count = 0x0100 */
1725                 ie_len++;
1726                 memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
1727
1728                 ie_len += 16;
1729                 ie[13] += 18;/* PMKID length = 2+16 */
1730         }
1731         return ie_len;
1732 }
1733
1734 int rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
1735 {
1736         u8 authmode;
1737         uint    ielength;
1738         int iEntry;
1739
1740         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1741         struct security_priv *psecuritypriv = &adapter->securitypriv;
1742         uint    ndisauthmode = psecuritypriv->ndisauthtype;
1743         uint ndissecuritytype = psecuritypriv->ndisencryptstatus;
1744
1745         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
1746                  ("+%s: ndisauthmode=%d ndissecuritytype=%d\n", __func__,
1747                   ndisauthmode, ndissecuritytype));
1748
1749         /* copy fixed ie only */
1750         memcpy(out_ie, in_ie, 12);
1751         ielength = 12;
1752         if ((ndisauthmode == Ndis802_11AuthModeWPA) ||
1753             (ndisauthmode == Ndis802_11AuthModeWPAPSK))
1754                         authmode = _WPA_IE_ID_;
1755         if ((ndisauthmode == Ndis802_11AuthModeWPA2) ||
1756             (ndisauthmode == Ndis802_11AuthModeWPA2PSK))
1757                 authmode = _WPA2_IE_ID_;
1758
1759         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
1760                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
1761
1762                 ielength += psecuritypriv->wps_ie_len;
1763         } else if ((authmode == _WPA_IE_ID_) || (authmode == _WPA2_IE_ID_)) {
1764                 /* copy RSN or SSN */
1765                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
1766                 ielength += psecuritypriv->supplicant_ie[1]+2;
1767                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
1768         }
1769
1770         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
1771         if (iEntry < 0) {
1772                 return ielength;
1773         } else {
1774                 if (authmode == _WPA2_IE_ID_)
1775                         ielength = rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
1776         }
1777         return ielength;
1778 }
1779
1780 void rtw_init_registrypriv_dev_network(struct adapter *adapter)
1781 {
1782         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1783         struct eeprom_priv *peepriv = &adapter->eeprompriv;
1784         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
1785         u8 *myhwaddr = myid(peepriv);
1786
1787         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
1788
1789         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
1790
1791         pdev_network->Configuration.Length = sizeof(struct ndis_802_11_config);
1792         pdev_network->Configuration.BeaconPeriod = 100;
1793         pdev_network->Configuration.FHConfig.Length = 0;
1794         pdev_network->Configuration.FHConfig.HopPattern = 0;
1795         pdev_network->Configuration.FHConfig.HopSet = 0;
1796         pdev_network->Configuration.FHConfig.DwellTime = 0;
1797 }
1798
1799 void rtw_update_registrypriv_dev_network(struct adapter *adapter)
1800 {
1801         int sz = 0;
1802         struct registry_priv *pregistrypriv = &adapter->registrypriv;
1803         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
1804         struct  security_priv *psecuritypriv = &adapter->securitypriv;
1805         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
1806
1807         pdev_network->Privacy = psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0; /*  adhoc no 802.1x */
1808
1809         pdev_network->Rssi = 0;
1810
1811         switch (pregistrypriv->wireless_mode) {
1812         case WIRELESS_11B:
1813                 pdev_network->NetworkTypeInUse = Ndis802_11DS;
1814                 break;
1815         case WIRELESS_11G:
1816         case WIRELESS_11BG:
1817         case WIRELESS_11_24N:
1818         case WIRELESS_11G_24N:
1819         case WIRELESS_11BG_24N:
1820                 pdev_network->NetworkTypeInUse = Ndis802_11OFDM24;
1821                 break;
1822         case WIRELESS_11A:
1823         case WIRELESS_11A_5N:
1824                 pdev_network->NetworkTypeInUse = Ndis802_11OFDM5;
1825                 break;
1826         case WIRELESS_11ABGN:
1827                 if (pregistrypriv->channel > 14)
1828                         pdev_network->NetworkTypeInUse = Ndis802_11OFDM5;
1829                 else
1830                         pdev_network->NetworkTypeInUse = Ndis802_11OFDM24;
1831                 break;
1832         default:
1833                 /*  TODO */
1834                 break;
1835         }
1836
1837         pdev_network->Configuration.DSConfig = pregistrypriv->channel;
1838         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_,
1839                  ("pregistrypriv->channel=%d, pdev_network->Configuration.DSConfig=0x%x\n",
1840                  pregistrypriv->channel, pdev_network->Configuration.DSConfig));
1841
1842         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
1843                 pdev_network->Configuration.ATIMWindow = 0;
1844
1845         pdev_network->InfrastructureMode = cur_network->network.InfrastructureMode;
1846
1847         /*  1. Supported rates */
1848         /*  2. IE */
1849
1850         sz = rtw_generate_ie(pregistrypriv);
1851         pdev_network->ie_length = sz;
1852         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
1853
1854         /* notes: translate ie_length & Length after assign the Length to cmdsz in createbss_cmd(); */
1855         /* pdev_network->ie_length = cpu_to_le32(sz); */
1856 }
1857
1858 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter *adapter)
1859 {
1860 }
1861
1862 /* the function is at passive_level */
1863 void rtw_joinbss_reset(struct adapter *padapter)
1864 {
1865         u8      threshold;
1866         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1867         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
1868
1869         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
1870         pmlmepriv->num_FortyMHzIntolerant = 0;
1871
1872         pmlmepriv->num_sta_no_ht = 0;
1873
1874         phtpriv->ampdu_enable = false;/* reset to disabled */
1875
1876         /*  TH = 1 => means that invalidate usb rx aggregation */
1877         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
1878         if (phtpriv->ht_option) {
1879                 if (padapter->registrypriv.wifi_spec == 1)
1880                         threshold = 1;
1881                 else
1882                         threshold = 0;
1883                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
1884         } else {
1885                 threshold = 1;
1886                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
1887         }
1888 }
1889
1890 /* the function is >= passive_level */
1891 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len)
1892 {
1893         u32 ielen, out_len;
1894         enum ht_cap_ampdu_factor max_rx_ampdu_factor;
1895         unsigned char *p;
1896         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
1897         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1898         struct qos_priv         *pqospriv = &pmlmepriv->qospriv;
1899         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
1900         u32 rx_packet_offset, max_recvbuf_sz;
1901
1902         phtpriv->ht_option = false;
1903
1904         p = rtw_get_ie(in_ie+12, _HT_CAPABILITY_IE_, &ielen, in_len-12);
1905
1906         if (p && ielen > 0) {
1907                 struct ieee80211_ht_cap ht_cap;
1908
1909                 if (pqospriv->qos_option == 0) {
1910                         out_len = *pout_len;
1911                         rtw_set_ie(out_ie + out_len, _VENDOR_SPECIFIC_IE_,
1912                                    _WMM_IE_Length_, WMM_IE, pout_len);
1913
1914                         pqospriv->qos_option = 1;
1915                 }
1916
1917                 out_len = *pout_len;
1918
1919                 memset(&ht_cap, 0, sizeof(struct ieee80211_ht_cap));
1920
1921                 ht_cap.cap_info = cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH |
1922                                               IEEE80211_HT_CAP_SGI_20 |
1923                                               IEEE80211_HT_CAP_SGI_40 |
1924                                               IEEE80211_HT_CAP_TX_STBC |
1925                                               IEEE80211_HT_CAP_DSSSCCK40);
1926
1927                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
1928                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
1929
1930                 /*
1931                 ampdu_params_info [1:0]:Max AMPDU Len => 0:8k , 1:16k, 2:32k, 3:64k
1932                 ampdu_params_info [4:2]:Min MPDU Start Spacing
1933                 */
1934
1935                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor);
1936                 ht_cap.ampdu_params_info = max_rx_ampdu_factor & 0x03;
1937
1938                 if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
1939                         ht_cap.ampdu_params_info |= IEEE80211_HT_CAP_AMPDU_DENSITY & (0x07 << 2);
1940                 else
1941                         ht_cap.ampdu_params_info |= IEEE80211_HT_CAP_AMPDU_DENSITY & 0x00;
1942
1943                 rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
1944                            sizeof(struct ieee80211_ht_cap),
1945                            (unsigned char *)&ht_cap, pout_len);
1946
1947                 phtpriv->ht_option = true;
1948
1949                 p = rtw_get_ie(in_ie+12, _HT_ADD_INFO_IE_, &ielen, in_len-12);
1950                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
1951                         out_len = *pout_len;
1952                         rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2, pout_len);
1953                 }
1954         }
1955         return phtpriv->ht_option;
1956 }
1957
1958 /* the function is > passive_level (in critical_section) */
1959 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len)
1960 {
1961         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1962         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
1963         struct registry_priv *pregistrypriv = &padapter->registrypriv;
1964         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
1965         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
1966
1967         if (!phtpriv->ht_option)
1968                 return;
1969
1970         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
1971                 return;
1972
1973         DBG_88E("+%s()\n", __func__);
1974
1975         /* maybe needs check if ap supports rx ampdu. */
1976         if ((!phtpriv->ampdu_enable) && (pregistrypriv->ampdu_enable == 1)) {
1977                 if (pregistrypriv->wifi_spec == 1)
1978                         phtpriv->ampdu_enable = false;
1979                 else
1980                         phtpriv->ampdu_enable = true;
1981         } else if (pregistrypriv->ampdu_enable == 2) {
1982                 phtpriv->ampdu_enable = true;
1983         }
1984
1985         /* update cur_bwmode & cur_ch_offset */
1986         if ((pregistrypriv->cbw40_enable) &&
1987             (le16_to_cpu(pmlmeinfo->HT_caps.cap_info) & BIT(1)) &&
1988             (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
1989                 int i;
1990
1991                 /* update the MCS rates */
1992                 for (i = 0; i < 16; i++)
1993                         ((u8 *)&pmlmeinfo->HT_caps.mcs)[i] &= MCS_rate_1R[i];
1994                 /* switch to the 40M Hz mode according to the AP */
1995                 pmlmeext->cur_bwmode = HT_CHANNEL_WIDTH_40;
1996                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3)) {
1997                 case HT_EXTCHNL_OFFSET_UPPER:
1998                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
1999                         break;
2000                 case HT_EXTCHNL_OFFSET_LOWER:
2001                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
2002                         break;
2003                 default:
2004                         pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
2005                         break;
2006                 }
2007         }
2008
2009         /*  Config SM Power Save setting */
2010         pmlmeinfo->SM_PS = (le16_to_cpu(pmlmeinfo->HT_caps.cap_info) & 0x0C) >> 2;
2011         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
2012                 DBG_88E("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
2013
2014         /*  Config current HT Protection mode. */
2015         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
2016 }
2017
2018 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
2019 {
2020         u8 issued;
2021         int priority;
2022         struct sta_info *psta = NULL;
2023         struct ht_priv  *phtpriv;
2024         struct pkt_attrib *pattrib = &pxmitframe->attrib;
2025
2026         if (is_multicast_ether_addr(pattrib->ra) ||
2027             padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod < 100)
2028                 return;
2029
2030         priority = pattrib->priority;
2031
2032         if (pattrib->psta)
2033                 psta = pattrib->psta;
2034         else
2035                 psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
2036
2037         if (!psta)
2038                 return;
2039
2040         phtpriv = &psta->htpriv;
2041
2042         if ((phtpriv->ht_option) && (phtpriv->ampdu_enable)) {
2043                 issued = (phtpriv->agg_enable_bitmap >> priority) & 0x1;
2044                 issued |= (phtpriv->candidate_tid_bitmap >> priority) & 0x1;
2045
2046                 if (issued == 0) {
2047                         DBG_88E("%s, p=%d\n", __func__, priority);
2048                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
2049                         rtw_addbareq_cmd(padapter, (u8)priority, pattrib->ra);
2050                 }
2051         }
2052 }
2053
2054 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2055 {
2056         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2057
2058         spin_lock_bh(&pmlmepriv->lock);
2059         _rtw_roaming(padapter, tgt_network);
2060         spin_unlock_bh(&pmlmepriv->lock);
2061 }
2062
2063 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
2064 {
2065         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2066         int do_join_r;
2067
2068         struct wlan_network *pnetwork;
2069
2070         if (tgt_network)
2071                 pnetwork = tgt_network;
2072         else
2073                 pnetwork = &pmlmepriv->cur_network;
2074
2075         if (pmlmepriv->to_roaming > 0) {
2076                 DBG_88E("roaming from %s(%pM length:%d\n",
2077                         pnetwork->network.Ssid.Ssid, pnetwork->network.MacAddress,
2078                         pnetwork->network.Ssid.SsidLength);
2079                 memcpy(&pmlmepriv->assoc_ssid, &pnetwork->network.Ssid, sizeof(struct ndis_802_11_ssid));
2080
2081                 pmlmepriv->assoc_by_bssid = false;
2082
2083                 while (1) {
2084                         do_join_r = rtw_do_join(padapter);
2085                         if (do_join_r == _SUCCESS) {
2086                                 break;
2087                         } else {
2088                                 DBG_88E("roaming do_join return %d\n", do_join_r);
2089                                 pmlmepriv->to_roaming--;
2090
2091                                 if (pmlmepriv->to_roaming > 0) {
2092                                         continue;
2093                                 } else {
2094                                         DBG_88E("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
2095                                         rtw_indicate_disconnect(padapter);
2096                                         break;
2097                                 }
2098                         }
2099                 }
2100         }
2101 }