OSDN Git Service

Remove memcpy wrapper
[android-x86/external-modules-rtl8723au.git] / core / rtw_recv.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2012 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  * You should have received a copy of the GNU General Public License along with
15  * this program; if not, write to the Free Software Foundation, Inc.,
16  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
17  *
18  *
19  ******************************************************************************/
20 #define _RTW_RECV_C_
21 #include <drv_conf.h>
22 #include <osdep_service.h>
23 #include <drv_types.h>
24 #include <recv_osdep.h>
25 #include <mlme_osdep.h>
26 #include <ip.h>
27 #include <if_ether.h>
28 #include <ethernet.h>
29
30 #ifdef CONFIG_USB_HCI
31 #include <usb_ops.h>
32 #endif
33
34 #include <wifi.h>
35 #include <circ_buf.h>
36
37 #ifdef CONFIG_NEW_SIGNAL_STAT_PROCESS
38 void rtw_signal_stat_timer_hdl(RTW_TIMER_HDL_ARGS);
39 #endif /* CONFIG_NEW_SIGNAL_STAT_PROCESS */
40
41 void _rtw_init_sta_recv_priv(struct sta_recv_priv *psta_recvpriv)
42 {
43
44 _func_enter_;
45
46         _rtw_memset((u8 *)psta_recvpriv, 0, sizeof (struct sta_recv_priv));
47
48         _rtw_spinlock_init(&psta_recvpriv->lock);
49
50         /* for(i=0; i<MAX_RX_NUMBLKS; i++) */
51         /*      _rtw_init_queue(&psta_recvpriv->blk_strms[i]); */
52
53         _rtw_init_queue(&psta_recvpriv->defrag_q);
54
55 _func_exit_;
56 }
57
58 sint _rtw_init_recv_priv(struct recv_priv *precvpriv, _adapter *padapter)
59 {
60         sint i;
61
62         union recv_frame *precvframe;
63
64         sint    res=_SUCCESS;
65
66 _func_enter_;
67
68         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by rtw_zvmalloc(). */
69         /* _rtw_memset((unsigned char *)precvpriv, 0, sizeof (struct  recv_priv)); */
70
71         _rtw_spinlock_init(&precvpriv->lock);
72
73         _rtw_init_queue(&precvpriv->free_recv_queue);
74         _rtw_init_queue(&precvpriv->recv_pending_queue);
75         _rtw_init_queue(&precvpriv->uc_swdec_pending_queue);
76
77         precvpriv->adapter = padapter;
78
79         precvpriv->free_recvframe_cnt = NR_RECVFRAME;
80
81         rtw_os_recv_resource_init(precvpriv, padapter);
82
83         precvpriv->pallocated_frame_buf = rtw_zvmalloc(NR_RECVFRAME * sizeof(union recv_frame) + RXFRAME_ALIGN_SZ);
84
85         if(precvpriv->pallocated_frame_buf==NULL){
86                 res= _FAIL;
87                 goto exit;
88         }
89         /* _rtw_memset(precvpriv->pallocated_frame_buf, 0, NR_RECVFRAME * sizeof(union recv_frame) + RXFRAME_ALIGN_SZ); */
90
91         precvpriv->precv_frame_buf = (u8 *)N_BYTE_ALIGMENT((SIZE_PTR)(precvpriv->pallocated_frame_buf), RXFRAME_ALIGN_SZ);
92         /* precvpriv->precv_frame_buf = precvpriv->pallocated_frame_buf + RXFRAME_ALIGN_SZ - */
93         /*                                              ((SIZE_PTR) (precvpriv->pallocated_frame_buf) &(RXFRAME_ALIGN_SZ-1)); */
94
95         precvframe = (union recv_frame*) precvpriv->precv_frame_buf;
96
97         for(i=0; i < NR_RECVFRAME ; i++)
98         {
99                 _rtw_init_listhead(&(precvframe->u.list));
100
101                 rtw_list_insert_tail(&(precvframe->u.list), &(precvpriv->free_recv_queue.queue));
102
103                 res = rtw_os_recv_resource_alloc(padapter, precvframe);
104
105                 precvframe->u.hdr.len = 0;
106
107                 precvframe->u.hdr.adapter =padapter;
108                 precvframe++;
109
110         }
111
112 #ifdef CONFIG_USB_HCI
113
114         precvpriv->rx_pending_cnt=1;
115
116         _rtw_init_sema(&precvpriv->allrxreturnevt, 0);
117
118 #endif
119
120         res = rtw_hal_init_recv_priv(padapter);
121
122 #ifdef CONFIG_NEW_SIGNAL_STAT_PROCESS
123         _init_timer(&precvpriv->signal_stat_timer, padapter->pnetdev, RTW_TIMER_HDL_NAME(signal_stat), padapter);
124
125         precvpriv->signal_stat_sampling_interval = 1000; /* ms */
126
127         rtw_set_signal_stat_timer(precvpriv);
128 #endif /* CONFIG_NEW_SIGNAL_STAT_PROCESS */
129
130 exit:
131
132 _func_exit_;
133
134         return res;
135 }
136
137 void rtw_mfree_recv_priv_lock(struct recv_priv *precvpriv);
138 void rtw_mfree_recv_priv_lock(struct recv_priv *precvpriv)
139 {
140         _rtw_spinlock_free(&precvpriv->lock);
141 #ifdef CONFIG_RECV_THREAD_MODE
142         _rtw_free_sema(&precvpriv->recv_sema);
143         _rtw_free_sema(&precvpriv->terminate_recvthread_sema);
144 #endif
145
146         _rtw_spinlock_free(&precvpriv->free_recv_queue.lock);
147         _rtw_spinlock_free(&precvpriv->recv_pending_queue.lock);
148
149         _rtw_spinlock_free(&precvpriv->free_recv_buf_queue.lock);
150
151 #ifdef CONFIG_USE_USB_BUFFER_ALLOC_RX
152         _rtw_spinlock_free(&precvpriv->recv_buf_pending_queue.lock);
153 #endif  /*  CONFIG_USE_USB_BUFFER_ALLOC_RX */
154 }
155
156 void _rtw_free_recv_priv (struct recv_priv *precvpriv)
157 {
158         _adapter        *padapter = precvpriv->adapter;
159
160 _func_enter_;
161
162         rtw_free_uc_swdec_pending_queue(padapter);
163
164         rtw_mfree_recv_priv_lock(precvpriv);
165
166         rtw_os_recv_resource_free(precvpriv);
167
168         if(precvpriv->pallocated_frame_buf) {
169                 rtw_vmfree(precvpriv->pallocated_frame_buf, NR_RECVFRAME * sizeof(union recv_frame) + RXFRAME_ALIGN_SZ);
170         }
171
172         rtw_hal_free_recv_priv(padapter);
173
174 _func_exit_;
175 }
176
177 union recv_frame *_rtw_alloc_recvframe (_queue *pfree_recv_queue)
178 {
179
180         union recv_frame  *precvframe;
181         _list   *plist, *phead;
182         _adapter *padapter;
183         struct recv_priv *precvpriv;
184 _func_enter_;
185
186         if(_rtw_queue_empty(pfree_recv_queue) == _TRUE)
187         {
188                 precvframe = NULL;
189         }
190         else
191         {
192                 phead = get_list_head(pfree_recv_queue);
193
194                 plist = get_next(phead);
195
196                 precvframe = LIST_CONTAINOR(plist, union recv_frame, u);
197
198                 rtw_list_delete(&precvframe->u.hdr.list);
199                 padapter=precvframe->u.hdr.adapter;
200                 if(padapter !=NULL){
201                         precvpriv=&padapter->recvpriv;
202                         if(pfree_recv_queue == &precvpriv->free_recv_queue)
203                                 precvpriv->free_recvframe_cnt--;
204                 }
205         }
206
207 _func_exit_;
208
209         return precvframe;
210 }
211
212 union recv_frame *rtw_alloc_recvframe (_queue *pfree_recv_queue)
213 {
214         _irqL irqL;
215         union recv_frame  *precvframe;
216
217         _enter_critical_bh(&pfree_recv_queue->lock, &irqL);
218
219         precvframe = _rtw_alloc_recvframe(pfree_recv_queue);
220
221         _exit_critical_bh(&pfree_recv_queue->lock, &irqL);
222
223         return precvframe;
224 }
225
226 void rtw_init_recvframe(union recv_frame *precvframe, struct recv_priv *precvpriv)
227 {
228         /* Perry: This can be removed */
229         _rtw_init_listhead(&precvframe->u.hdr.list);
230
231         precvframe->u.hdr.len=0;
232 }
233
234 int rtw_free_recvframe(union recv_frame *precvframe, _queue *pfree_recv_queue)
235 {
236         _irqL irqL;
237         _adapter *padapter=precvframe->u.hdr.adapter;
238         struct recv_priv *precvpriv = &padapter->recvpriv;
239
240 _func_enter_;
241
242 #ifdef CONFIG_CONCURRENT_MODE
243         if(padapter->adapter_type > PRIMARY_ADAPTER)
244         {
245                 padapter = padapter->pbuddy_adapter;/* get primary_padapter */
246                 precvpriv = &padapter->recvpriv;
247                 pfree_recv_queue = &precvpriv->free_recv_queue;
248                 precvframe->u.hdr.adapter = padapter;
249         }
250 #endif
251
252         if(precvframe->u.hdr.pkt)
253         {
254 #ifdef CONFIG_BSD_RX_USE_MBUF
255                 m_freem(precvframe->u.hdr.pkt);
256 #else   /*  CONFIG_BSD_RX_USE_MBUF */
257                 dev_kfree_skb_any(precvframe->u.hdr.pkt);/* free skb by driver */
258 #endif  /*  CONFIG_BSD_RX_USE_MBUF */
259                 precvframe->u.hdr.pkt = NULL;
260         }
261
262         _enter_critical_bh(&pfree_recv_queue->lock, &irqL);
263
264         rtw_list_delete(&(precvframe->u.hdr.list));
265
266         precvframe->u.hdr.len = 0;
267
268         rtw_list_insert_tail(&(precvframe->u.hdr.list), get_list_head(pfree_recv_queue));
269
270         if(padapter !=NULL){
271                 if(pfree_recv_queue == &precvpriv->free_recv_queue)
272                                 precvpriv->free_recvframe_cnt++;
273         }
274
275       _exit_critical_bh(&pfree_recv_queue->lock, &irqL);
276
277 _func_exit_;
278
279         return _SUCCESS;
280 }
281
282 sint _rtw_enqueue_recvframe(union recv_frame *precvframe, _queue *queue)
283 {
284
285         _adapter *padapter=precvframe->u.hdr.adapter;
286         struct recv_priv *precvpriv = &padapter->recvpriv;
287
288 _func_enter_;
289
290         /* _rtw_init_listhead(&(precvframe->u.hdr.list)); */
291         rtw_list_delete(&(precvframe->u.hdr.list));
292
293         rtw_list_insert_tail(&(precvframe->u.hdr.list), get_list_head(queue));
294
295         if (padapter != NULL) {
296                 if (queue == &precvpriv->free_recv_queue)
297                         precvpriv->free_recvframe_cnt++;
298         }
299
300 _func_exit_;
301
302         return _SUCCESS;
303 }
304
305 sint rtw_enqueue_recvframe(union recv_frame *precvframe, _queue *queue)
306 {
307         sint ret;
308         _irqL irqL;
309
310         /* _spinlock(&pfree_recv_queue->lock); */
311         _enter_critical_bh(&queue->lock, &irqL);
312         ret = _rtw_enqueue_recvframe(precvframe, queue);
313         /* _rtw_spinunlock(&pfree_recv_queue->lock); */
314         _exit_critical_bh(&queue->lock, &irqL);
315
316         return ret;
317 }
318
319 /*
320 sint    rtw_enqueue_recvframe(union recv_frame *precvframe, _queue *queue)
321 {
322         return rtw_free_recvframe(precvframe, queue);
323 }
324 */
325
326 /*
327 caller : defrag ; recvframe_chk_defrag in recv_thread  (passive)
328 pframequeue: defrag_queue : will be accessed in recv_thread  (passive)
329
330 using spinlock to protect
331
332 */
333
334 void rtw_free_recvframe_queue(_queue *pframequeue,  _queue *pfree_recv_queue)
335 {
336         union   recv_frame      *precvframe;
337         _list   *plist, *phead;
338
339 _func_enter_;
340         _rtw_spinlock(&pframequeue->lock);
341
342         phead = get_list_head(pframequeue);
343         plist = get_next(phead);
344
345         while(rtw_end_of_queue_search(phead, plist) == _FALSE) {
346                 precvframe = LIST_CONTAINOR(plist, union recv_frame, u);
347                 plist = get_next(plist);
348                 rtw_free_recvframe(precvframe, pfree_recv_queue);
349         }
350
351         _rtw_spinunlock(&pframequeue->lock);
352
353 _func_exit_;
354 }
355
356 u32 rtw_free_uc_swdec_pending_queue(_adapter *adapter)
357 {
358         u32 cnt = 0;
359         union recv_frame *pending_frame;
360         while((pending_frame=rtw_alloc_recvframe(&adapter->recvpriv.uc_swdec_pending_queue))) {
361                 rtw_free_recvframe(pending_frame, &adapter->recvpriv.free_recv_queue);
362                 DBG_8723A("%s: dequeue uc_swdec_pending_queue\n", __func__);
363                 cnt++;
364         }
365
366         return cnt;
367 }
368
369 sint rtw_enqueue_recvbuf_to_head(struct recv_buf *precvbuf, _queue *queue)
370 {
371         _irqL irqL;
372
373         _enter_critical_bh(&queue->lock, &irqL);
374
375         rtw_list_delete(&precvbuf->list);
376         rtw_list_insert_head(&precvbuf->list, get_list_head(queue));
377
378         _exit_critical_bh(&queue->lock, &irqL);
379
380         return _SUCCESS;
381 }
382
383 sint rtw_enqueue_recvbuf(struct recv_buf *precvbuf, _queue *queue)
384 {
385         _irqL irqL;
386 #ifdef CONFIG_SDIO_HCI
387         _enter_critical_bh(&queue->lock, &irqL);
388 #else
389         _enter_critical_ex(&queue->lock, &irqL);
390 #endif/*#ifdef  CONFIG_SDIO_HCI*/
391
392         rtw_list_delete(&precvbuf->list);
393
394         rtw_list_insert_tail(&precvbuf->list, get_list_head(queue));
395 #ifdef CONFIG_SDIO_HCI
396         _exit_critical_bh(&queue->lock, &irqL);
397 #else
398         _exit_critical_ex(&queue->lock, &irqL);
399 #endif/*#ifdef  CONFIG_SDIO_HCI*/
400         return _SUCCESS;
401 }
402
403 struct recv_buf *rtw_dequeue_recvbuf (_queue *queue)
404 {
405         _irqL irqL;
406         struct recv_buf *precvbuf;
407         _list   *plist, *phead;
408
409 #ifdef CONFIG_SDIO_HCI
410         _enter_critical_bh(&queue->lock, &irqL);
411 #else
412         _enter_critical_ex(&queue->lock, &irqL);
413 #endif/*#ifdef  CONFIG_SDIO_HCI*/
414
415         if(_rtw_queue_empty(queue) == _TRUE)
416         {
417                 precvbuf = NULL;
418         }
419         else
420         {
421                 phead = get_list_head(queue);
422
423                 plist = get_next(phead);
424
425                 precvbuf = LIST_CONTAINOR(plist, struct recv_buf, list);
426
427                 rtw_list_delete(&precvbuf->list);
428
429         }
430
431 #ifdef CONFIG_SDIO_HCI
432         _exit_critical_bh(&queue->lock, &irqL);
433 #else
434         _exit_critical_ex(&queue->lock, &irqL);
435 #endif/*#ifdef  CONFIG_SDIO_HCI*/
436
437         return precvbuf;
438 }
439
440 sint recvframe_chkmic(_adapter *adapter,  union recv_frame *precvframe);
441 sint recvframe_chkmic(_adapter *adapter,  union recv_frame *precvframe){
442
443         sint    i,res=_SUCCESS;
444         u32     datalen;
445         u8      miccode[8];
446         u8      bmic_err=_FALSE,brpt_micerror = _TRUE;
447         u8      *pframe, *payload,*pframemic;
448         u8      *mickey;
449         /* u8   *iv,rxdata_key_idx=0; */
450         struct  sta_info                *stainfo;
451         struct  rx_pkt_attrib   *prxattrib=&precvframe->u.hdr.attrib;
452         struct  security_priv   *psecuritypriv=&adapter->securitypriv;
453
454         struct mlme_ext_priv    *pmlmeext = &adapter->mlmeextpriv;
455         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
456 _func_enter_;
457
458         stainfo=rtw_get_stainfo(&adapter->stapriv ,&prxattrib->ta[0]);
459
460         if(prxattrib->encrypt ==_TKIP_)
461         {
462                 RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("\n recvframe_chkmic:prxattrib->encrypt ==_TKIP_\n"));
463                 RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("\n recvframe_chkmic:da=0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x\n",
464                         prxattrib->ra[0],prxattrib->ra[1],prxattrib->ra[2],prxattrib->ra[3],prxattrib->ra[4],prxattrib->ra[5]));
465
466                 /* calculate mic code */
467                 if(stainfo!= NULL)
468                 {
469                         if(IS_MCAST(prxattrib->ra))
470                         {
471                                 mickey=&psecuritypriv->dot118021XGrprxmickey[prxattrib->key_index].skey[0];
472
473                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("\n recvframe_chkmic: bcmc key \n"));
474
475                                 if(psecuritypriv->binstallGrpkey==_FALSE)
476                                 {
477                                         res=_FAIL;
478                                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("\n recvframe_chkmic:didn't install group key!!!!!!!!!!\n"));
479                                         DBG_8723A("\n recvframe_chkmic:didn't install group key!!!!!!!!!!\n");
480                                         goto exit;
481                                 }
482                         }
483                         else{
484                                 mickey=&stainfo->dot11tkiprxmickey.skey[0];
485                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("\n recvframe_chkmic: unicast key \n"));
486                         }
487
488                         datalen=precvframe->u.hdr.len-prxattrib->hdrlen-prxattrib->iv_len-prxattrib->icv_len-8;/* icv_len included the mic code */
489                         pframe=precvframe->u.hdr.rx_data;
490                         payload=pframe+prxattrib->hdrlen+prxattrib->iv_len;
491
492                         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("\n prxattrib->iv_len=%d prxattrib->icv_len=%d\n",prxattrib->iv_len,prxattrib->icv_len));
493
494                         rtw_seccalctkipmic(mickey,pframe,payload, datalen ,&miccode[0],(unsigned char)prxattrib->priority); /* care the length of the data */
495
496                         pframemic=payload+datalen;
497
498                         bmic_err=_FALSE;
499
500                         for(i=0;i<8;i++){
501                                 if(miccode[i] != *(pframemic+i)){
502                                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("recvframe_chkmic:miccode[%d](%02x) != *(pframemic+%d)(%02x) ",i,miccode[i],i,*(pframemic+i)));
503                                         bmic_err=_TRUE;
504                                 }
505                         }
506
507                         if(bmic_err==_TRUE){
508
509                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("\n *(pframemic-8)-*(pframemic-1)=0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x\n",
510                                         *(pframemic-8),*(pframemic-7),*(pframemic-6),*(pframemic-5),*(pframemic-4),*(pframemic-3),*(pframemic-2),*(pframemic-1)));
511                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("\n *(pframemic-16)-*(pframemic-9)=0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x\n",
512                                         *(pframemic-16),*(pframemic-15),*(pframemic-14),*(pframemic-13),*(pframemic-12),*(pframemic-11),*(pframemic-10),*(pframemic-9)));
513
514                                 {
515                                         uint i;
516                                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("\n ======demp packet (len=%d)======\n",precvframe->u.hdr.len));
517                                         for(i=0;i<precvframe->u.hdr.len;i=i+8){
518                                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x",
519                                                         *(precvframe->u.hdr.rx_data+i),*(precvframe->u.hdr.rx_data+i+1),
520                                                         *(precvframe->u.hdr.rx_data+i+2),*(precvframe->u.hdr.rx_data+i+3),
521                                                         *(precvframe->u.hdr.rx_data+i+4),*(precvframe->u.hdr.rx_data+i+5),
522                                                         *(precvframe->u.hdr.rx_data+i+6),*(precvframe->u.hdr.rx_data+i+7)));
523                                         }
524                                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("\n ======demp packet end [len=%d]======\n",precvframe->u.hdr.len));
525                                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("\n hrdlen=%d, \n",prxattrib->hdrlen));
526                                 }
527
528                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("ra=0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x psecuritypriv->binstallGrpkey=%d ",
529                                         prxattrib->ra[0],prxattrib->ra[1],prxattrib->ra[2],
530                                         prxattrib->ra[3],prxattrib->ra[4],prxattrib->ra[5],psecuritypriv->binstallGrpkey));
531
532                                 /*  double check key_index for some timing issue , */
533                                 /*  cannot compare with psecuritypriv->dot118021XGrpKeyid also cause timing issue */
534                                 if((IS_MCAST(prxattrib->ra)==_TRUE)  && (prxattrib->key_index != pmlmeinfo->key_index ))
535                                         brpt_micerror = _FALSE;
536
537                                 if((prxattrib->bdecrypted ==_TRUE)&& (brpt_micerror == _TRUE))
538                                 {
539                                         rtw_handle_tkip_mic_err(adapter,(u8)IS_MCAST(prxattrib->ra));
540                                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,(" mic error :prxattrib->bdecrypted=%d ",prxattrib->bdecrypted));
541                                         DBG_8723A(" mic error :prxattrib->bdecrypted=%d\n",prxattrib->bdecrypted);
542                                 }
543                                 else
544                                 {
545                                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,(" mic error :prxattrib->bdecrypted=%d ",prxattrib->bdecrypted));
546                                         DBG_8723A(" mic error :prxattrib->bdecrypted=%d\n",prxattrib->bdecrypted);
547                                 }
548
549                                 res=_FAIL;
550
551                         }
552                         else{
553                                 /* mic checked ok */
554                                 if((psecuritypriv->bcheck_grpkey ==_FALSE)&&(IS_MCAST(prxattrib->ra)==_TRUE)){
555                                         psecuritypriv->bcheck_grpkey =_TRUE;
556                                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("psecuritypriv->bcheck_grpkey =_TRUE"));
557                                 }
558                         }
559
560                 }
561                 else
562                 {
563                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("recvframe_chkmic: rtw_get_stainfo==NULL!!!\n"));
564                 }
565
566                 recvframe_pull_tail(precvframe, 8);
567
568         }
569
570 exit:
571
572 _func_exit_;
573
574         return res;
575 }
576
577 /* decrypt and set the ivlen,icvlen of the recv_frame */
578 union recv_frame * decryptor(_adapter *padapter,union recv_frame *precv_frame);
579 union recv_frame * decryptor(_adapter *padapter,union recv_frame *precv_frame)
580 {
581
582         struct rx_pkt_attrib *prxattrib = &precv_frame->u.hdr.attrib;
583         struct security_priv *psecuritypriv=&padapter->securitypriv;
584         union recv_frame *return_packet=precv_frame;
585         u32      res=_SUCCESS;
586 _func_enter_;
587
588         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("prxstat->decrypted=%x prxattrib->encrypt = 0x%03x\n",prxattrib->bdecrypted,prxattrib->encrypt));
589
590         if(prxattrib->encrypt>0)
591         {
592                 u8 *iv = precv_frame->u.hdr.rx_data+prxattrib->hdrlen;
593                 prxattrib->key_index = ( ((iv[3])>>6)&0x3) ;
594
595                 if(prxattrib->key_index > WEP_KEYS)
596                 {
597                         DBG_8723A("prxattrib->key_index(%d) > WEP_KEYS \n", prxattrib->key_index);
598
599                         switch(prxattrib->encrypt){
600                                 case _WEP40_:
601                                 case _WEP104_:
602                                         prxattrib->key_index = psecuritypriv->dot11PrivacyKeyIndex;
603                                         break;
604                                 case _TKIP_:
605                                 case _AES_:
606                                 default:
607                                         prxattrib->key_index = psecuritypriv->dot118021XGrpKeyid;
608                                         break;
609                         }
610                 }
611         }
612
613         if((prxattrib->encrypt>0) && ((prxattrib->bdecrypted==0) ||(psecuritypriv->sw_decrypt==_TRUE)))
614         {
615
616 #ifdef CONFIG_CONCURRENT_MODE
617                 if(!IS_MCAST(prxattrib->ra))/* bc/mc packets use sw decryption for concurrent mode */
618 #endif
619                 psecuritypriv->hw_decrypted=_FALSE;
620
621                 #ifdef DBG_RX_DECRYPTOR
622                 DBG_8723A("prxstat->bdecrypted:%d,  prxattrib->encrypt:%d,  Setting psecuritypriv->hw_decrypted = %d\n"
623                         , prxattrib->bdecrypted ,prxattrib->encrypt, psecuritypriv->hw_decrypted);
624                 #endif
625
626                 switch(prxattrib->encrypt){
627                 case _WEP40_:
628                 case _WEP104_:
629                         rtw_wep_decrypt(padapter, (u8 *)precv_frame);
630                         break;
631                 case _TKIP_:
632                         res = rtw_tkip_decrypt(padapter, (u8 *)precv_frame);
633                         break;
634                 case _AES_:
635                         res = rtw_aes_decrypt(padapter, (u8 * )precv_frame);
636                         break;
637 #ifdef CONFIG_WAPI_SUPPORT
638                 case _SMS4_:
639                         rtw_sms4_decrypt(padapter, (u8 * )precv_frame);
640                         break;
641 #endif
642                 default:
643                                 break;
644                 }
645         }
646         else if(prxattrib->bdecrypted==1
647                 && prxattrib->encrypt >0
648                 && (psecuritypriv->busetkipkey==1 || prxattrib->encrypt !=_TKIP_ )
649                 )
650         {
651                 {
652                         psecuritypriv->hw_decrypted=_TRUE;
653                         #ifdef DBG_RX_DECRYPTOR
654                         DBG_8723A("prxstat->bdecrypted:%d,  prxattrib->encrypt:%d,  Setting psecuritypriv->hw_decrypted = %d\n"
655                         , prxattrib->bdecrypted ,prxattrib->encrypt, psecuritypriv->hw_decrypted);
656                         #endif
657
658                 }
659         }
660         else {
661                 #ifdef DBG_RX_DECRYPTOR
662                 DBG_8723A("prxstat->bdecrypted:%d,  prxattrib->encrypt:%d,  psecuritypriv->hw_decrypted:%d\n"
663                 , prxattrib->bdecrypted ,prxattrib->encrypt, psecuritypriv->hw_decrypted);
664                 #endif
665         }
666
667         if(res == _FAIL)
668         {
669                 rtw_free_recvframe(return_packet,&padapter->recvpriv.free_recv_queue);
670                 return_packet = NULL;
671
672         }
673
674 _func_exit_;
675
676         return return_packet;
677 }
678 /* set the security information in the recv_frame */
679 union recv_frame * portctrl(_adapter *adapter,union recv_frame * precv_frame)
680 {
681         u8   *psta_addr, *ptr;
682         uint  auth_alg;
683         struct recv_frame_hdr *pfhdr;
684         struct sta_info *psta;
685         struct sta_priv *pstapriv ;
686         union recv_frame *prtnframe;
687         u16     ether_type=0;
688         u16  eapol_type = 0x888e;/* for Funia BD's WPA issue */
689         struct rx_pkt_attrib *pattrib;
690
691 _func_enter_;
692
693         pstapriv = &adapter->stapriv;
694         psta = rtw_get_stainfo(pstapriv, psta_addr);
695
696         auth_alg = adapter->securitypriv.dot11AuthAlgrthm;
697
698         ptr = get_recvframe_data(precv_frame);
699         pfhdr = &precv_frame->u.hdr;
700         pattrib = &pfhdr->attrib;
701         psta_addr = pattrib->ta;
702
703         prtnframe = NULL;
704
705         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("########portctrl:adapter->securitypriv.dot11AuthAlgrthm=%d\n",adapter->securitypriv.dot11AuthAlgrthm));
706
707         if(auth_alg==2)
708         {
709                 if ((psta!=NULL) && (psta->ieee8021x_blocked))
710                 {
711                         /* blocked */
712                         /* only accept EAPOL frame */
713                         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("########portctrl:psta->ieee8021x_blocked==1\n"));
714
715                         prtnframe=precv_frame;
716
717                         /* get ether_type */
718                         ptr=ptr+pfhdr->attrib.hdrlen+pfhdr->attrib.iv_len+LLC_HEADER_SIZE;
719                         memcpy(&ether_type,ptr, 2);
720                         ether_type= ntohs((unsigned short )ether_type);
721
722                         if (ether_type == eapol_type) {
723                                 prtnframe=precv_frame;
724                         }
725                         else {
726                                 /* free this frame */
727                                 rtw_free_recvframe(precv_frame, &adapter->recvpriv.free_recv_queue);
728                                 prtnframe=NULL;
729                         }
730                 }
731                 else
732                 {
733                         /* allowed */
734                         /* check decryption status, and decrypt the frame if needed */
735                         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("########portctrl:psta->ieee8021x_blocked==0\n"));
736                         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("portctrl:precv_frame->hdr.attrib.privacy=%x\n",precv_frame->u.hdr.attrib.privacy));
737
738                         if (pattrib->bdecrypted == 0)
739                         {
740                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("portctrl:prxstat->decrypted=%x\n", pattrib->bdecrypted));
741                         }
742
743                         prtnframe=precv_frame;
744                         /* check is the EAPOL frame or not (Rekey) */
745                         if(ether_type == eapol_type){
746
747                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_notice_,("########portctrl:ether_type == 0x888e\n"));
748                                 /* check Rekey */
749
750                                 prtnframe=precv_frame;
751                         }
752                         else{
753                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("########portctrl:ether_type=0x%04x\n", ether_type));
754                         }
755                 }
756         }
757         else
758         {
759                 prtnframe=precv_frame;
760         }
761
762 _func_exit_;
763
764                 return prtnframe;
765 }
766
767 sint recv_decache(union recv_frame *precv_frame, u8 bretry, struct stainfo_rxcache *prxcache);
768 sint recv_decache(union recv_frame *precv_frame, u8 bretry, struct stainfo_rxcache *prxcache)
769 {
770         sint tid = precv_frame->u.hdr.attrib.priority;
771
772         u16 seq_ctrl = ( (precv_frame->u.hdr.attrib.seq_num&0xffff) << 4) |
773                 (precv_frame->u.hdr.attrib.frag_num & 0xf);
774
775 _func_enter_;
776
777         if(tid>15)
778         {
779                 RT_TRACE(_module_rtl871x_recv_c_, _drv_notice_, ("recv_decache, (tid>15)! seq_ctrl=0x%x, tid=0x%x\n", seq_ctrl, tid));
780
781                 return _FAIL;
782         }
783
784         if(1)/* if(bretry) */
785         {
786                 if(seq_ctrl == prxcache->tid_rxseq[tid])
787                 {
788                         RT_TRACE(_module_rtl871x_recv_c_, _drv_notice_, ("recv_decache, seq_ctrl=0x%x, tid=0x%x, tid_rxseq=0x%x\n", seq_ctrl, tid, prxcache->tid_rxseq[tid]));
789
790                         return _FAIL;
791                 }
792         }
793
794         prxcache->tid_rxseq[tid] = seq_ctrl;
795
796 _func_exit_;
797
798         return _SUCCESS;
799 }
800
801 void process_pwrbit_data(_adapter *padapter, union recv_frame *precv_frame);
802 void process_pwrbit_data(_adapter *padapter, union recv_frame *precv_frame)
803 {
804 #ifdef CONFIG_AP_MODE
805         unsigned char pwrbit;
806         u8 *ptr = precv_frame->u.hdr.rx_data;
807         struct rx_pkt_attrib *pattrib = &precv_frame->u.hdr.attrib;
808         struct sta_priv *pstapriv = &padapter->stapriv;
809         struct sta_info *psta=NULL;
810
811         psta = rtw_get_stainfo(pstapriv, pattrib->src);
812
813         pwrbit = GetPwrMgt(ptr);
814
815         if(psta)
816         {
817                 if(pwrbit)
818                 {
819                         if(!(psta->state & WIFI_SLEEP_STATE))
820                         {
821                                 /* psta->state |= WIFI_SLEEP_STATE; */
822                                 /* pstapriv->sta_dz_bitmap |= BIT(psta->aid); */
823
824                                 stop_sta_xmit(padapter, psta);
825
826                                 /* DBG_8723A("to sleep, sta_dz_bitmap=%x\n", pstapriv->sta_dz_bitmap); */
827                         }
828                 }
829                 else
830                 {
831                         if(psta->state & WIFI_SLEEP_STATE)
832                         {
833                                 /* psta->state ^= WIFI_SLEEP_STATE; */
834                                 /* pstapriv->sta_dz_bitmap &= ~BIT(psta->aid); */
835
836                                 wakeup_sta_to_xmit(padapter, psta);
837
838                                 /* DBG_8723A("to wakeup, sta_dz_bitmap=%x\n", pstapriv->sta_dz_bitmap); */
839                         }
840                 }
841
842         }
843
844 #endif
845 }
846
847 void process_wmmps_data(_adapter *padapter, union recv_frame *precv_frame);
848 void process_wmmps_data(_adapter *padapter, union recv_frame *precv_frame)
849 {
850 #ifdef CONFIG_AP_MODE
851         struct rx_pkt_attrib *pattrib = &precv_frame->u.hdr.attrib;
852         struct sta_priv *pstapriv = &padapter->stapriv;
853         struct sta_info *psta=NULL;
854
855         psta = rtw_get_stainfo(pstapriv, pattrib->src);
856
857         if(!psta) return;
858
859 #ifdef CONFIG_TDLS
860         if( !(psta->tdls_sta_state & TDLS_LINKED_STATE ) )
861         {
862 #endif /* CONFIG_TDLS */
863
864         if(!psta->qos_option)
865                 return;
866
867         if(!(psta->qos_info&0xf))
868                 return;
869
870 #ifdef CONFIG_TDLS
871         }
872 #endif /* CONFIG_TDLS */
873
874         if(psta->state&WIFI_SLEEP_STATE)
875         {
876                 u8 wmmps_ac=0;
877
878                 switch(pattrib->priority)
879                 {
880                         case 1:
881                         case 2:
882                                 wmmps_ac = psta->uapsd_bk&BIT(1);
883                                 break;
884                         case 4:
885                         case 5:
886                                 wmmps_ac = psta->uapsd_vi&BIT(1);
887                                 break;
888                         case 6:
889                         case 7:
890                                 wmmps_ac = psta->uapsd_vo&BIT(1);
891                                 break;
892                         case 0:
893                         case 3:
894                         default:
895                                 wmmps_ac = psta->uapsd_be&BIT(1);
896                                 break;
897                 }
898
899                 if(wmmps_ac)
900                 {
901                         if(psta->sleepq_ac_len>0)
902                         {
903                                 /* process received triggered frame */
904                                 xmit_delivery_enabled_frames(padapter, psta);
905                         }
906                         else
907                         {
908                                 /* issue one qos null frame with More data bit = 0 and the EOSP bit set (=1) */
909                                 issue_qos_nulldata(padapter, psta->hwaddr, (u16)pattrib->priority, 0, 0);
910                         }
911                 }
912
913         }
914
915 #endif
916 }
917
918 #ifdef CONFIG_TDLS
919 sint OnTDLS(_adapter *adapter, union recv_frame *precv_frame)
920 {
921         struct rx_pkt_attrib    *pattrib = & precv_frame->u.hdr.attrib;
922         sint ret = _SUCCESS;
923         u8 *paction = get_recvframe_data(precv_frame);
924         u8 category_field = 1;
925 #ifdef CONFIG_WFD
926         u8 WFA_OUI[3] = { 0x50, 0x6f, 0x9a };
927 #endif /* CONFIG_WFD */
928         struct tdls_info *ptdlsinfo = &(adapter->tdlsinfo);
929
930         /* point to action field */
931         paction+=pattrib->hdrlen
932                         + pattrib->iv_len
933                         + SNAP_SIZE
934                         + ETH_TYPE_LEN
935                         + PAYLOAD_TYPE_LEN
936                         + category_field;
937
938         if(ptdlsinfo->enable == 0)
939         {
940                 DBG_8723A("recv tdls frame, "
941                                 "but tdls haven't enabled\n");
942                 ret = _FAIL;
943                 return ret;
944         }
945
946         switch(*paction){
947                 case TDLS_SETUP_REQUEST:
948                         DBG_8723A("recv tdls setup request frame\n");
949                         ret=On_TDLS_Setup_Req(adapter, precv_frame);
950                         break;
951                 case TDLS_SETUP_RESPONSE:
952                         DBG_8723A("recv tdls setup response frame\n");
953                         ret=On_TDLS_Setup_Rsp(adapter, precv_frame);
954                         break;
955                 case TDLS_SETUP_CONFIRM:
956                         DBG_8723A("recv tdls setup confirm frame\n");
957                         ret=On_TDLS_Setup_Cfm(adapter, precv_frame);
958                         break;
959                 case TDLS_TEARDOWN:
960                         DBG_8723A("recv tdls teardown, free sta_info\n");
961                         ret=On_TDLS_Teardown(adapter, precv_frame);
962                         break;
963                 case TDLS_DISCOVERY_REQUEST:
964                         DBG_8723A("recv tdls discovery request frame\n");
965                         ret=On_TDLS_Dis_Req(adapter, precv_frame);
966                         break;
967                 case TDLS_PEER_TRAFFIC_RESPONSE:
968                         DBG_8723A("recv tdls peer traffic response frame\n");
969                         ret=On_TDLS_Peer_Traffic_Rsp(adapter, precv_frame);
970                         break;
971                 case TDLS_CHANNEL_SWITCH_REQUEST:
972                         DBG_8723A("recv tdls channel switch request frame\n");
973                         ret=On_TDLS_Ch_Switch_Req(adapter, precv_frame);
974                         break;
975                 case TDLS_CHANNEL_SWITCH_RESPONSE:
976                         DBG_8723A("recv tdls channel switch response frame\n");
977                         ret=On_TDLS_Ch_Switch_Rsp(adapter, precv_frame);
978                         break;
979 #ifdef CONFIG_WFD
980                 case 0x50:      /* First byte of WFA OUI */
981                         if( _rtw_memcmp(WFA_OUI, (paction), 3) )
982                         {
983                                 if( *(paction + 3) == 0x04)     /* Probe request frame */
984                                 {
985                                         /* WFDTDLS: for sigma test, do not setup direct link automatically */
986                                         ptdlsinfo->dev_discovered = 1;
987                                         DBG_8723A("recv tunneled probe request frame\n");
988                                         issue_tunneled_probe_rsp(adapter, precv_frame);
989                                 }
990                                 if( *(paction + 3) == 0x05)     /* Probe response frame */
991                                 {
992                                         /* WFDTDLS: for sigma test, do not setup direct link automatically */
993                                         ptdlsinfo->dev_discovered = 1;
994                                         DBG_8723A("recv tunneled probe response frame\n");
995                                 }
996                         }
997                         break;
998 #endif /* CONFIG_WFD */
999                 default:
1000                         DBG_8723A("receive TDLS frame but not supported\n");
1001                         ret=_FAIL;
1002                         break;
1003         }
1004
1005 exit:
1006         return ret;
1007 }
1008 #endif
1009
1010 void count_rx_stats(_adapter *padapter, union recv_frame *prframe, struct sta_info*sta);
1011 void count_rx_stats(_adapter *padapter, union recv_frame *prframe, struct sta_info*sta)
1012 {
1013         int     sz;
1014         struct sta_info         *psta = NULL;
1015         struct stainfo_stats    *pstats = NULL;
1016         struct rx_pkt_attrib    *pattrib = & prframe->u.hdr.attrib;
1017         struct recv_priv                *precvpriv = &padapter->recvpriv;
1018
1019         sz = get_recvframe_len(prframe);
1020         precvpriv->rx_bytes += sz;
1021
1022         padapter->mlmepriv.LinkDetectInfo.NumRxOkInPeriod++;
1023
1024         if( (!MacAddr_isBcst(pattrib->dst)) && (!IS_MCAST(pattrib->dst))){
1025                 padapter->mlmepriv.LinkDetectInfo.NumRxUnicastOkInPeriod++;
1026         }
1027
1028         if(sta)
1029                 psta = sta;
1030         else
1031                 psta = prframe->u.hdr.psta;
1032
1033         if(psta)
1034         {
1035                 pstats = &psta->sta_stats;
1036
1037                 pstats->rx_data_pkts++;
1038                 pstats->rx_bytes += sz;
1039         }
1040 }
1041
1042 sint sta2sta_data_frame(
1043         _adapter *adapter,
1044         union recv_frame *precv_frame,
1045         struct sta_info**psta
1046 );
1047 sint sta2sta_data_frame(
1048         _adapter *adapter,
1049         union recv_frame *precv_frame,
1050         struct sta_info**psta
1051 )
1052 {
1053         u8 *ptr = precv_frame->u.hdr.rx_data;
1054         sint ret = _SUCCESS;
1055         struct rx_pkt_attrib *pattrib = & precv_frame->u.hdr.attrib;
1056         struct  sta_priv                *pstapriv = &adapter->stapriv;
1057         struct  mlme_priv       *pmlmepriv = &adapter->mlmepriv;
1058         u8 *mybssid  = get_bssid(pmlmepriv);
1059         u8 *myhwaddr = myid(&adapter->eeprompriv);
1060         u8 * sta_addr = NULL;
1061         sint bmcast = IS_MCAST(pattrib->dst);
1062
1063 #ifdef CONFIG_TDLS
1064         struct tdls_info *ptdlsinfo = &adapter->tdlsinfo;
1065         struct sta_info *ptdls_sta=NULL;
1066         u8 *psnap_type=ptr+pattrib->hdrlen + pattrib->iv_len+SNAP_SIZE;
1067         /* frame body located after [+2]: ether-type, [+1]: payload type */
1068         u8 *pframe_body = psnap_type+2+1;
1069 #endif
1070
1071 _func_enter_;
1072
1073         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE) ||
1074                 (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == _TRUE))
1075         {
1076
1077                 /*  filter packets that SA is myself or multicast or broadcast */
1078                 if (_rtw_memcmp(myhwaddr, pattrib->src, ETH_ALEN)){
1079                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,(" SA==myself \n"));
1080                         ret= _FAIL;
1081                         goto exit;
1082                 }
1083
1084                 if( (!_rtw_memcmp(myhwaddr, pattrib->dst, ETH_ALEN))    && (!bmcast) ){
1085                         ret= _FAIL;
1086                         goto exit;
1087                 }
1088
1089                 if( _rtw_memcmp(pattrib->bssid, "\x0\x0\x0\x0\x0\x0", ETH_ALEN) ||
1090                    _rtw_memcmp(mybssid, "\x0\x0\x0\x0\x0\x0", ETH_ALEN) ||
1091                    (!_rtw_memcmp(pattrib->bssid, mybssid, ETH_ALEN)) ) {
1092                         ret= _FAIL;
1093                         goto exit;
1094                 }
1095
1096                 sta_addr = pattrib->src;
1097
1098         }
1099         else if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE)
1100         {
1101 #ifdef CONFIG_TDLS
1102
1103                 /* direct link data transfer */
1104                 if(ptdlsinfo->setup_state == TDLS_LINKED_STATE){
1105                         ptdls_sta = rtw_get_stainfo(pstapriv, pattrib->src);
1106                         if(ptdls_sta==NULL)
1107                         {
1108                                 ret=_FAIL;
1109                                 goto exit;
1110                         }
1111                         else if(ptdls_sta->tdls_sta_state&TDLS_LINKED_STATE)
1112                         {
1113
1114                                 /* drop QoS-SubType Data, including QoS NULL, excluding QoS-Data */
1115                                 if( (GetFrameSubType(ptr) & WIFI_QOS_DATA_TYPE )== WIFI_QOS_DATA_TYPE)
1116                                 {
1117                                         if(GetFrameSubType(ptr)&(BIT(4)|BIT(5)|BIT(6)))
1118                                         {
1119                                                 DBG_8723A("drop QoS-Sybtype Data\n");
1120                                         ret= _FAIL;
1121                                         goto exit;
1122                                         }
1123                                 }
1124                                 /*  filter packets that SA is myself or multicast or broadcast */
1125                                 if (_rtw_memcmp(myhwaddr, pattrib->src, ETH_ALEN)){
1126                                         ret= _FAIL;
1127                                         goto exit;
1128                                 }
1129                                 /*  da should be for me */
1130                                 if((!_rtw_memcmp(myhwaddr, pattrib->dst, ETH_ALEN))&& (!bmcast))
1131                                 {
1132                                         ret= _FAIL;
1133                                         goto exit;
1134                                 }
1135                                 /*  check BSSID */
1136                                 if( _rtw_memcmp(pattrib->bssid, "\x0\x0\x0\x0\x0\x0", ETH_ALEN) ||
1137                                      _rtw_memcmp(mybssid, "\x0\x0\x0\x0\x0\x0", ETH_ALEN) ||
1138                                      (!_rtw_memcmp(pattrib->bssid, mybssid, ETH_ALEN)) )
1139                                 {
1140                                         ret= _FAIL;
1141                                         goto exit;
1142                                 }
1143
1144                                 /* process UAPSD tdls sta */
1145                                 process_pwrbit_data(adapter, precv_frame);
1146
1147                                 /*  if NULL-frame, check pwrbit */
1148                                 if ((GetFrameSubType(ptr)) == WIFI_DATA_NULL)
1149                                 {
1150                                         /* NULL-frame with pwrbit=1, buffer_STA should buffer frames for sleep_STA */
1151                                         if(GetPwrMgt(ptr))
1152                                         {
1153                                                 DBG_8723A("TDLS: recv peer null frame with pwr bit 1\n");
1154                                                 ptdls_sta->tdls_sta_state|=TDLS_PEER_SLEEP_STATE;
1155                                         /*  it would be triggered when we are off channel and receiving NULL DATA */
1156                                         /*  we can confirm that peer STA is at off channel */
1157                                         }
1158                                         else if(ptdls_sta->tdls_sta_state&TDLS_CH_SWITCH_ON_STATE)
1159                                         {
1160                                                 if((ptdls_sta->tdls_sta_state & TDLS_PEER_AT_OFF_STATE) != TDLS_PEER_AT_OFF_STATE)
1161                                                 {
1162                                                         issue_nulldata_to_TDLS_peer_STA(adapter, ptdls_sta, 0);
1163                                                         ptdls_sta->tdls_sta_state |= TDLS_PEER_AT_OFF_STATE;
1164                                                         On_TDLS_Peer_Traffic_Rsp(adapter, precv_frame);
1165                                                 }
1166                                         }
1167
1168                                         ret= _FAIL;
1169                                         goto exit;
1170                                 }
1171                                 /* receive some of all TDLS management frames, process it at ON_TDLS */
1172                                 if((_rtw_memcmp(psnap_type, SNAP_ETH_TYPE_TDLS, 2))){
1173                                         ret= OnTDLS(adapter, precv_frame);
1174                                         goto exit;
1175                                 }
1176
1177                         }
1178
1179                         sta_addr = pattrib->src;
1180
1181                 }
1182                 else
1183 #endif /* CONFIG_TDLS */
1184                 {
1185                         /*  For Station mode, sa and bssid should always be BSSID, and DA is my mac-address */
1186                         if(!_rtw_memcmp(pattrib->bssid, pattrib->src, ETH_ALEN) )
1187                         {
1188                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("bssid != TA under STATION_MODE; drop pkt\n"));
1189                                 ret= _FAIL;
1190                                 goto exit;
1191                 }
1192
1193                 sta_addr = pattrib->bssid;
1194                 }
1195
1196         }
1197         else if(check_fwstate(pmlmepriv, WIFI_AP_STATE) == _TRUE)
1198         {
1199                 if (bmcast)
1200                 {
1201                         /*  For AP mode, if DA == MCAST, then BSSID should be also MCAST */
1202                         if (!IS_MCAST(pattrib->bssid)){
1203                                         ret= _FAIL;
1204                                         goto exit;
1205                         }
1206                 }
1207                 else /*  not mc-frame */
1208                 {
1209                         /*  For AP mode, if DA is non-MCAST, then it must be BSSID, and bssid == BSSID */
1210                         if(!_rtw_memcmp(pattrib->bssid, pattrib->dst, ETH_ALEN)) {
1211                                 ret= _FAIL;
1212                                 goto exit;
1213                         }
1214
1215                         sta_addr = pattrib->src;
1216                 }
1217
1218         }
1219         else if(check_fwstate(pmlmepriv, WIFI_MP_STATE) == _TRUE)
1220         {
1221                 memcpy(pattrib->dst, GetAddr1Ptr(ptr), ETH_ALEN);
1222                 memcpy(pattrib->src, GetAddr2Ptr(ptr), ETH_ALEN);
1223                 memcpy(pattrib->bssid, GetAddr3Ptr(ptr), ETH_ALEN);
1224                 memcpy(pattrib->ra, pattrib->dst, ETH_ALEN);
1225                 memcpy(pattrib->ta, pattrib->src, ETH_ALEN);
1226
1227                 sta_addr = mybssid;
1228         }
1229         else
1230         {
1231                 ret  = _FAIL;
1232         }
1233
1234         if(bmcast)
1235                 *psta = rtw_get_bcmc_stainfo(adapter);
1236         else
1237                 *psta = rtw_get_stainfo(pstapriv, sta_addr); /*  get ap_info */
1238
1239 #ifdef CONFIG_TDLS
1240         if(ptdls_sta != NULL)
1241                 *psta = ptdls_sta;
1242 #endif /* CONFIG_TDLS */
1243
1244         if (*psta == NULL) {
1245                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("can't get psta under sta2sta_data_frame ; drop pkt\n"));
1246                 ret= _FAIL;
1247                 goto exit;
1248         }
1249
1250 exit:
1251 _func_exit_;
1252         return ret;
1253 }
1254
1255 sint ap2sta_data_frame(
1256         _adapter *adapter,
1257         union recv_frame *precv_frame,
1258         struct sta_info**psta );
1259 sint ap2sta_data_frame(
1260         _adapter *adapter,
1261         union recv_frame *precv_frame,
1262         struct sta_info**psta )
1263 {
1264         u8 *ptr = precv_frame->u.hdr.rx_data;
1265         struct rx_pkt_attrib *pattrib = & precv_frame->u.hdr.attrib;
1266         sint ret = _SUCCESS;
1267         struct  sta_priv                *pstapriv = &adapter->stapriv;
1268         struct  mlme_priv       *pmlmepriv = &adapter->mlmepriv;
1269         u8 *mybssid  = get_bssid(pmlmepriv);
1270         u8 *myhwaddr = myid(&adapter->eeprompriv);
1271         sint bmcast = IS_MCAST(pattrib->dst);
1272
1273 _func_enter_;
1274
1275         if ((check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE)
1276                 && (check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE
1277                         || check_fwstate(pmlmepriv, _FW_UNDER_LINKING) == _TRUE )
1278                 )
1279         {
1280
1281                 /*  filter packets that SA is myself or multicast or broadcast */
1282                 if (_rtw_memcmp(myhwaddr, pattrib->src, ETH_ALEN)){
1283                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,(" SA==myself \n"));
1284                         #ifdef DBG_RX_DROP_FRAME
1285                         DBG_8723A("DBG_RX_DROP_FRAME %s SA="MAC_FMT", myhwaddr="MAC_FMT"\n",
1286                                 __FUNCTION__, MAC_ARG(pattrib->src), MAC_ARG(myhwaddr));
1287                         #endif
1288                         ret= _FAIL;
1289                         goto exit;
1290                 }
1291
1292                 /*  da should be for me */
1293                 if((!_rtw_memcmp(myhwaddr, pattrib->dst, ETH_ALEN))&& (!bmcast))
1294                 {
1295                         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,
1296                                 (" ap2sta_data_frame:  compare DA fail; DA="MAC_FMT"\n", MAC_ARG(pattrib->dst)));
1297                         #ifdef DBG_RX_DROP_FRAME
1298                         DBG_8723A("DBG_RX_DROP_FRAME %s DA="MAC_FMT"\n", __func__, MAC_ARG(pattrib->dst));
1299                         #endif
1300                         ret= _FAIL;
1301                         goto exit;
1302                 }
1303
1304                 /*  check BSSID */
1305                 if( _rtw_memcmp(pattrib->bssid, "\x0\x0\x0\x0\x0\x0", ETH_ALEN) ||
1306                      _rtw_memcmp(mybssid, "\x0\x0\x0\x0\x0\x0", ETH_ALEN) ||
1307                      (!_rtw_memcmp(pattrib->bssid, mybssid, ETH_ALEN)) )
1308                 {
1309                         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,
1310                                 (" ap2sta_data_frame:  compare BSSID fail ; BSSID="MAC_FMT"\n", MAC_ARG(pattrib->bssid)));
1311                         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("mybssid="MAC_FMT"\n", MAC_ARG(mybssid)));
1312                         #ifdef DBG_RX_DROP_FRAME
1313                         DBG_8723A("DBG_RX_DROP_FRAME %s BSSID="MAC_FMT", mybssid="MAC_FMT"\n",
1314                                 __FUNCTION__, MAC_ARG(pattrib->bssid), MAC_ARG(mybssid));
1315                         DBG_8723A( "this adapter = %d, buddy adapter = %d\n", adapter->adapter_type, adapter->pbuddy_adapter->adapter_type );
1316                         #endif
1317
1318                         if(!bmcast)
1319                         {
1320                                 DBG_8723A("issue_deauth to the nonassociated ap=" MAC_FMT " for the reason(7)\n", MAC_ARG(pattrib->bssid));
1321                                 issue_deauth(adapter, pattrib->bssid, WLAN_REASON_CLASS3_FRAME_FROM_NONASSOC_STA);
1322                         }
1323
1324                         ret= _FAIL;
1325                         goto exit;
1326                 }
1327
1328                 if(bmcast)
1329                         *psta = rtw_get_bcmc_stainfo(adapter);
1330                 else
1331                         *psta = rtw_get_stainfo(pstapriv, pattrib->bssid); /*  get ap_info */
1332
1333                 if (*psta == NULL) {
1334                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("ap2sta: can't get psta under STATION_MODE ; drop pkt\n"));
1335                         #ifdef DBG_RX_DROP_FRAME
1336                         DBG_8723A("DBG_RX_DROP_FRAME %s can't get psta under STATION_MODE ; drop pkt\n", __FUNCTION__);
1337                         #endif
1338                         ret= _FAIL;
1339                         goto exit;
1340                 }
1341
1342                 /* if ((GetFrameSubType(ptr) & WIFI_QOS_DATA_TYPE) == WIFI_QOS_DATA_TYPE) { */
1343                 /*  */
1344
1345                 if (GetFrameSubType(ptr) & BIT(6)) {
1346                         /* No data, will not indicate to upper layer, temporily count it here */
1347                         count_rx_stats(adapter, precv_frame, *psta);
1348                         ret = RTW_RX_HANDLED;
1349                         goto exit;
1350                 }
1351
1352         }
1353         else if ((check_fwstate(pmlmepriv, WIFI_MP_STATE) == _TRUE) &&
1354                      (check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE) )
1355         {
1356                 memcpy(pattrib->dst, GetAddr1Ptr(ptr), ETH_ALEN);
1357                 memcpy(pattrib->src, GetAddr2Ptr(ptr), ETH_ALEN);
1358                 memcpy(pattrib->bssid, GetAddr3Ptr(ptr), ETH_ALEN);
1359                 memcpy(pattrib->ra, pattrib->dst, ETH_ALEN);
1360                 memcpy(pattrib->ta, pattrib->src, ETH_ALEN);
1361
1362                 /*  */
1363                 memcpy(pattrib->bssid,  mybssid, ETH_ALEN);
1364
1365                 *psta = rtw_get_stainfo(pstapriv, pattrib->bssid); /*  get sta_info */
1366                 if (*psta == NULL) {
1367                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("can't get psta under MP_MODE ; drop pkt\n"));
1368                         #ifdef DBG_RX_DROP_FRAME
1369                         DBG_8723A("DBG_RX_DROP_FRAME %s can't get psta under WIFI_MP_STATE ; drop pkt\n", __FUNCTION__);
1370                         #endif
1371                         ret= _FAIL;
1372                         goto exit;
1373                 }
1374
1375         }
1376         else if (check_fwstate(pmlmepriv, WIFI_AP_STATE) == _TRUE)
1377         {
1378                 /* Special case */
1379                 ret = RTW_RX_HANDLED;
1380                 goto exit;
1381         }
1382         else
1383         {
1384                 if(_rtw_memcmp(myhwaddr, pattrib->dst, ETH_ALEN)&& (!bmcast))
1385                 {
1386                         *psta = rtw_get_stainfo(pstapriv, pattrib->bssid); /*  get sta_info */
1387                         if (*psta == NULL)
1388                         {
1389                                 DBG_8723A("issue_deauth to the ap=" MAC_FMT " for the reason(7)\n", MAC_ARG(pattrib->bssid));
1390
1391                                 issue_deauth(adapter, pattrib->bssid, WLAN_REASON_CLASS3_FRAME_FROM_NONASSOC_STA);
1392                         }
1393                 }
1394
1395                 ret = _FAIL;
1396                 #ifdef DBG_RX_DROP_FRAME
1397                 DBG_8723A("DBG_RX_DROP_FRAME %s fw_state:0x%x\n", __FUNCTION__, get_fwstate(pmlmepriv));
1398                 #endif
1399         }
1400
1401 exit:
1402
1403 _func_exit_;
1404
1405         return ret;
1406 }
1407
1408 sint sta2ap_data_frame(
1409         _adapter *adapter,
1410         union recv_frame *precv_frame,
1411         struct sta_info**psta );
1412 sint sta2ap_data_frame(
1413         _adapter *adapter,
1414         union recv_frame *precv_frame,
1415         struct sta_info**psta )
1416 {
1417         u8 *ptr = precv_frame->u.hdr.rx_data;
1418         struct rx_pkt_attrib *pattrib = & precv_frame->u.hdr.attrib;
1419         struct  sta_priv                *pstapriv = &adapter->stapriv;
1420         struct  mlme_priv       *pmlmepriv = &adapter->mlmepriv;
1421         unsigned char *mybssid  = get_bssid(pmlmepriv);
1422         sint ret=_SUCCESS;
1423
1424 _func_enter_;
1425
1426         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) == _TRUE)
1427         {
1428                 /* For AP mode, RA=BSSID, TX=STA(SRC_ADDR), A3=DST_ADDR */
1429                 if(!_rtw_memcmp(pattrib->bssid, mybssid, ETH_ALEN))
1430                 {
1431                         ret= _FAIL;
1432                         goto exit;
1433                 }
1434
1435                 *psta = rtw_get_stainfo(pstapriv, pattrib->src);
1436                 if (*psta == NULL)
1437                 {
1438                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("can't get psta under AP_MODE; drop pkt\n"));
1439                         DBG_8723A("issue_deauth to sta=" MAC_FMT " for the reason(7)\n", MAC_ARG(pattrib->src));
1440
1441                         issue_deauth(adapter, pattrib->src, WLAN_REASON_CLASS3_FRAME_FROM_NONASSOC_STA);
1442
1443                         ret = RTW_RX_HANDLED;
1444                         goto exit;
1445                 }
1446
1447                 process_pwrbit_data(adapter, precv_frame);
1448
1449                 if ((GetFrameSubType(ptr) & WIFI_QOS_DATA_TYPE) == WIFI_QOS_DATA_TYPE) {
1450                         process_wmmps_data(adapter, precv_frame);
1451                 }
1452
1453                 if (GetFrameSubType(ptr) & BIT(6)) {
1454                         /* No data, will not indicate to upper layer, temporily count it here */
1455                         count_rx_stats(adapter, precv_frame, *psta);
1456                         ret = RTW_RX_HANDLED;
1457                         goto exit;
1458                 }
1459         }
1460         else {
1461                 u8 *myhwaddr = myid(&adapter->eeprompriv);
1462                 if (!_rtw_memcmp(pattrib->ra, myhwaddr, ETH_ALEN)) {
1463                         ret = RTW_RX_HANDLED;
1464                         goto exit;
1465                 }
1466                 DBG_8723A("issue_deauth to sta=" MAC_FMT " for the reason(7)\n", MAC_ARG(pattrib->src));
1467                 issue_deauth(adapter, pattrib->src, WLAN_REASON_CLASS3_FRAME_FROM_NONASSOC_STA);
1468                 ret = RTW_RX_HANDLED;
1469                 goto exit;
1470         }
1471
1472 exit:
1473
1474 _func_exit_;
1475
1476         return ret;
1477 }
1478
1479 sint validate_recv_ctrl_frame(_adapter *padapter, union recv_frame *precv_frame);
1480 sint validate_recv_ctrl_frame(_adapter *padapter, union recv_frame *precv_frame)
1481 {
1482 #ifdef CONFIG_AP_MODE
1483         struct rx_pkt_attrib *pattrib = &precv_frame->u.hdr.attrib;
1484         struct sta_priv *pstapriv = &padapter->stapriv;
1485         u8 *pframe = precv_frame->u.hdr.rx_data;
1486         /* uint len = precv_frame->u.hdr.len; */
1487
1488         /* DBG_8723A("+validate_recv_ctrl_frame\n"); */
1489
1490         if (GetFrameType(pframe) != WIFI_CTRL_TYPE)
1491         {
1492                 return _FAIL;
1493         }
1494
1495         /* receive the frames that ra(a1) is my address */
1496         if (!_rtw_memcmp(GetAddr1Ptr(pframe), myid(&padapter->eeprompriv), ETH_ALEN))
1497         {
1498                 return _FAIL;
1499         }
1500
1501         /* only handle ps-poll */
1502         if(GetFrameSubType(pframe) == WIFI_PSPOLL)
1503         {
1504                 u16 aid;
1505                 u8 wmmps_ac=0;
1506                 struct sta_info *psta=NULL;
1507
1508                 aid = GetAid(pframe);
1509                 psta = rtw_get_stainfo(pstapriv, GetAddr2Ptr(pframe));
1510
1511                 if((psta==NULL) || (psta->aid!=aid))
1512                 {
1513                         return _FAIL;
1514                 }
1515
1516                 /* for rx pkt statistics */
1517                 psta->sta_stats.rx_ctrl_pkts++;
1518
1519                 switch(pattrib->priority)
1520                 {
1521                         case 1:
1522                         case 2:
1523                                 wmmps_ac = psta->uapsd_bk&BIT(0);
1524                                 break;
1525                         case 4:
1526                         case 5:
1527                                 wmmps_ac = psta->uapsd_vi&BIT(0);
1528                                 break;
1529                         case 6:
1530                         case 7:
1531                                 wmmps_ac = psta->uapsd_vo&BIT(0);
1532                                 break;
1533                         case 0:
1534                         case 3:
1535                         default:
1536                                 wmmps_ac = psta->uapsd_be&BIT(0);
1537                                 break;
1538                 }
1539
1540                 if(wmmps_ac)
1541                         return _FAIL;
1542
1543                 if(psta->state & WIFI_STA_ALIVE_CHK_STATE)
1544                 {
1545                         DBG_8723A("%s alive check-rx ps-poll\n", __func__);
1546                         psta->expire_to = pstapriv->expire_to;
1547                         psta->state ^= WIFI_STA_ALIVE_CHK_STATE;
1548                 }
1549
1550                 if((psta->state&WIFI_SLEEP_STATE) && (pstapriv->sta_dz_bitmap&BIT(psta->aid)))
1551                 {
1552                         _irqL irqL;
1553                         _list   *xmitframe_plist, *xmitframe_phead;
1554                         struct xmit_frame *pxmitframe=NULL;
1555                         struct xmit_priv *pxmitpriv = &padapter->xmitpriv;
1556
1557                         /* _enter_critical_bh(&psta->sleep_q.lock, &irqL); */
1558                         _enter_critical_bh(&pxmitpriv->lock, &irqL);
1559
1560                         xmitframe_phead = get_list_head(&psta->sleep_q);
1561                         xmitframe_plist = get_next(xmitframe_phead);
1562
1563                         if ((rtw_end_of_queue_search(xmitframe_phead, xmitframe_plist)) == _FALSE)
1564                         {
1565                                 pxmitframe = LIST_CONTAINOR(xmitframe_plist, struct xmit_frame, list);
1566
1567                                 xmitframe_plist = get_next(xmitframe_plist);
1568
1569                                 rtw_list_delete(&pxmitframe->list);
1570
1571                                 psta->sleepq_len--;
1572
1573                                 if(psta->sleepq_len>0)
1574                                         pxmitframe->attrib.mdata = 1;
1575                                 else
1576                                         pxmitframe->attrib.mdata = 0;
1577
1578                                 pxmitframe->attrib.triggered = 1;
1579
1580                                 /* DBG_8723A("handling ps-poll, q_len=%d, tim=%x\n", psta->sleepq_len, pstapriv->tim_bitmap); */
1581
1582                                 rtw_hal_xmitframe_enqueue(padapter, pxmitframe);
1583
1584                                 if(psta->sleepq_len==0)
1585                                 {
1586                                         pstapriv->tim_bitmap &= ~BIT(psta->aid);
1587
1588                                         /* DBG_8723A("after handling ps-poll, tim=%x\n", pstapriv->tim_bitmap); */
1589
1590                                         /* upate BCN for TIM IE */
1591                                         /* update_BCNTIM(padapter); */
1592                                         update_beacon(padapter, _TIM_IE_, NULL, _FALSE);
1593                                 }
1594
1595                                 /* _exit_critical_bh(&psta->sleep_q.lock, &irqL); */
1596                                 _exit_critical_bh(&pxmitpriv->lock, &irqL);
1597
1598                         }
1599                         else
1600                         {
1601                                 /* _exit_critical_bh(&psta->sleep_q.lock, &irqL); */
1602                                 _exit_critical_bh(&pxmitpriv->lock, &irqL);
1603
1604                                 /* DBG_8723A("no buffered packets to xmit\n"); */
1605                                 if(pstapriv->tim_bitmap&BIT(psta->aid))
1606                                 {
1607                                         if(psta->sleepq_len==0)
1608                                         {
1609                                                 DBG_8723A("no buffered packets to xmit\n");
1610
1611                                                 /* issue nulldata with More data bit = 0 to indicate we have no buffered packets */
1612                                                 issue_nulldata(padapter, psta->hwaddr, 0, 0, 0);
1613                                         }
1614                                         else
1615                                         {
1616                                                 DBG_8723A("error!psta->sleepq_len=%d\n", psta->sleepq_len);
1617                                                 psta->sleepq_len=0;
1618                                         }
1619
1620                                         pstapriv->tim_bitmap &= ~BIT(psta->aid);
1621
1622                                         /* upate BCN for TIM IE */
1623                                         /* update_BCNTIM(padapter); */
1624                                         update_beacon(padapter, _TIM_IE_, NULL, _FALSE);
1625                                 }
1626
1627                         }
1628
1629                 }
1630
1631         }
1632
1633 #endif
1634
1635         return _FAIL;
1636 }
1637
1638 union recv_frame* recvframe_chk_defrag(PADAPTER padapter, union recv_frame *precv_frame);
1639 sint validate_recv_mgnt_frame(PADAPTER padapter, union recv_frame *precv_frame);
1640 sint validate_recv_mgnt_frame(PADAPTER padapter, union recv_frame *precv_frame)
1641 {
1642         /* struct mlme_priv *pmlmepriv = &adapter->mlmepriv; */
1643
1644         RT_TRACE(_module_rtl871x_recv_c_, _drv_info_, ("+validate_recv_mgnt_frame\n"));
1645
1646         precv_frame = recvframe_chk_defrag(padapter, precv_frame);
1647         if (precv_frame == NULL) {
1648                 RT_TRACE(_module_rtl871x_recv_c_, _drv_notice_,("%s: fragment packet\n",__FUNCTION__));
1649                 return _SUCCESS;
1650         }
1651
1652         {
1653                 /* for rx pkt statistics */
1654                 struct sta_info *psta = rtw_get_stainfo(&padapter->stapriv, GetAddr2Ptr(precv_frame->u.hdr.rx_data));
1655                 if (psta) {
1656                         psta->sta_stats.rx_mgnt_pkts++;
1657                         if (GetFrameSubType(precv_frame->u.hdr.rx_data) == WIFI_BEACON)
1658                                 psta->sta_stats.rx_beacon_pkts++;
1659                         else if (GetFrameSubType(precv_frame->u.hdr.rx_data) == WIFI_PROBEREQ)
1660                                 psta->sta_stats.rx_probereq_pkts++;
1661                         else if (GetFrameSubType(precv_frame->u.hdr.rx_data) == WIFI_PROBERSP) {
1662                                 if (_rtw_memcmp(padapter->eeprompriv.mac_addr, GetAddr1Ptr(precv_frame->u.hdr.rx_data), ETH_ALEN) == _TRUE)
1663                                         psta->sta_stats.rx_probersp_pkts++;
1664                                 else if (is_broadcast_mac_addr(GetAddr1Ptr(precv_frame->u.hdr.rx_data))
1665                                         || is_multicast_mac_addr(GetAddr1Ptr(precv_frame->u.hdr.rx_data)))
1666                                         psta->sta_stats.rx_probersp_bm_pkts++;
1667                                 else
1668                                         psta->sta_stats.rx_probersp_uo_pkts++;
1669                         }
1670                 }
1671         }
1672
1673 #ifdef CONFIG_INTEL_PROXIM
1674         if(padapter->proximity.proxim_on==_TRUE)
1675         {
1676                 struct rx_pkt_attrib * pattrib=&precv_frame->u.hdr.attrib;
1677                  struct recv_stat* prxstat=( struct recv_stat * )  precv_frame->u.hdr.rx_head ;
1678                  u8 * pda,*psa,*pbssid,*ptr;
1679                  ptr=precv_frame->u.hdr.rx_data;
1680                 pda = get_da(ptr);
1681                 psa = get_sa(ptr);
1682                 pbssid = get_hdr_bssid(ptr);
1683
1684                 memcpy(pattrib->dst, pda, ETH_ALEN);
1685                 memcpy(pattrib->src, psa, ETH_ALEN);
1686
1687                 memcpy(pattrib->bssid, pbssid, ETH_ALEN);
1688
1689         switch(pattrib->to_fr_ds)
1690         {
1691                 case 0:
1692                         memcpy(pattrib->ra, pda, ETH_ALEN);
1693                         memcpy(pattrib->ta, psa, ETH_ALEN);
1694                         break;
1695
1696                 case 1:
1697                         memcpy(pattrib->ra, pda, ETH_ALEN);
1698                         memcpy(pattrib->ta, pbssid, ETH_ALEN);
1699                         break;
1700
1701                 case 2:
1702                         memcpy(pattrib->ra, pbssid, ETH_ALEN);
1703                         memcpy(pattrib->ta, psa, ETH_ALEN);
1704                         break;
1705
1706                 case 3:
1707                         memcpy(pattrib->ra, GetAddr1Ptr(ptr), ETH_ALEN);
1708                         memcpy(pattrib->ta, GetAddr2Ptr(ptr), ETH_ALEN);
1709                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,(" case 3\n"));
1710                         break;
1711
1712                 default:
1713                         break;
1714
1715                 }
1716                         pattrib->priority=0;
1717                         pattrib->hdrlen = pattrib->to_fr_ds==3 ? 30 : 24;
1718
1719                  padapter->proximity.proxim_rx(padapter,precv_frame);
1720         }
1721 #endif
1722         mgt_dispatcher(padapter, precv_frame);
1723
1724         return _SUCCESS;
1725 }
1726
1727 sint validate_recv_data_frame(_adapter *adapter, union recv_frame *precv_frame);
1728 sint validate_recv_data_frame(_adapter *adapter, union recv_frame *precv_frame)
1729 {
1730         u8 bretry;
1731         u8 *psa, *pda, *pbssid;
1732         struct sta_info *psta = NULL;
1733         u8 *ptr = precv_frame->u.hdr.rx_data;
1734         struct rx_pkt_attrib    *pattrib = & precv_frame->u.hdr.attrib;
1735         struct sta_priv         *pstapriv = &adapter->stapriv;
1736         struct security_priv    *psecuritypriv = &adapter->securitypriv;
1737         sint ret = _SUCCESS;
1738 #ifdef CONFIG_TDLS
1739         struct tdls_info *ptdlsinfo = &adapter->tdlsinfo;
1740 #endif /* CONFIG_TDLS */
1741
1742 _func_enter_;
1743
1744         bretry = GetRetry(ptr);
1745         pda = get_da(ptr);
1746         psa = get_sa(ptr);
1747         pbssid = get_hdr_bssid(ptr);
1748
1749         if(pbssid == NULL){
1750                 #ifdef DBG_RX_DROP_FRAME
1751                 DBG_8723A("DBG_RX_DROP_FRAME %s pbssid == NULL\n", __func__);
1752                 #endif
1753                 ret= _FAIL;
1754                 goto exit;
1755         }
1756
1757         memcpy(pattrib->dst, pda, ETH_ALEN);
1758         memcpy(pattrib->src, psa, ETH_ALEN);
1759
1760         memcpy(pattrib->bssid, pbssid, ETH_ALEN);
1761
1762         switch(pattrib->to_fr_ds)
1763         {
1764                 case 0:
1765                         memcpy(pattrib->ra, pda, ETH_ALEN);
1766                         memcpy(pattrib->ta, psa, ETH_ALEN);
1767                         ret = sta2sta_data_frame(adapter, precv_frame, &psta);
1768                         break;
1769
1770                 case 1:
1771                         memcpy(pattrib->ra, pda, ETH_ALEN);
1772                         memcpy(pattrib->ta, pbssid, ETH_ALEN);
1773                         ret = ap2sta_data_frame(adapter, precv_frame, &psta);
1774                         break;
1775
1776                 case 2:
1777                         memcpy(pattrib->ra, pbssid, ETH_ALEN);
1778                         memcpy(pattrib->ta, psa, ETH_ALEN);
1779                         ret = sta2ap_data_frame(adapter, precv_frame, &psta);
1780                         break;
1781
1782                 case 3:
1783                         memcpy(pattrib->ra, GetAddr1Ptr(ptr), ETH_ALEN);
1784                         memcpy(pattrib->ta, GetAddr2Ptr(ptr), ETH_ALEN);
1785                         ret =_FAIL;
1786                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,(" case 3\n"));
1787                         break;
1788
1789                 default:
1790                         ret =_FAIL;
1791                         break;
1792
1793         }
1794
1795         if(ret ==_FAIL){
1796                 #ifdef DBG_RX_DROP_FRAME
1797                 DBG_8723A("DBG_RX_DROP_FRAME %s case:%d, res:%d\n", __FUNCTION__, pattrib->to_fr_ds, ret);
1798                 #endif
1799                 goto exit;
1800         } else if (ret == RTW_RX_HANDLED) {
1801                 goto exit;
1802         }
1803
1804         if(psta==NULL){
1805                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,(" after to_fr_ds_chk; psta==NULL \n"));
1806                 #ifdef DBG_RX_DROP_FRAME
1807                 DBG_8723A("DBG_RX_DROP_FRAME %s psta == NULL\n", __func__);
1808                 #endif
1809                 ret= _FAIL;
1810                 goto exit;
1811         }
1812
1813         /* psta->rssi = prxcmd->rssi; */
1814         /* psta->signal_quality= prxcmd->sq; */
1815         precv_frame->u.hdr.psta = psta;
1816
1817         pattrib->amsdu=0;
1818         pattrib->ack_policy = 0;
1819         /* parsing QC field */
1820         if(pattrib->qos == 1)
1821         {
1822                 pattrib->priority = GetPriority((ptr + 24));
1823                 pattrib->ack_policy = GetAckpolicy((ptr + 24));
1824                 pattrib->amsdu = GetAMsdu((ptr + 24));
1825                 pattrib->hdrlen = pattrib->to_fr_ds==3 ? 32 : 26;
1826
1827                 if(pattrib->priority!=0 && pattrib->priority!=3)
1828                 {
1829                         adapter->recvpriv.bIsAnyNonBEPkts = _TRUE;
1830                 }
1831         }
1832         else
1833         {
1834                 pattrib->priority=0;
1835                 pattrib->hdrlen = pattrib->to_fr_ds==3 ? 30 : 24;
1836         }
1837
1838         if(pattrib->order)/* HT-CTRL 11n */
1839         {
1840                 pattrib->hdrlen += 4;
1841         }
1842
1843         precv_frame->u.hdr.preorder_ctrl = &psta->recvreorder_ctrl[pattrib->priority];
1844
1845         /*  decache, drop duplicate recv packets */
1846         if(recv_decache(precv_frame, bretry, &psta->sta_recvpriv.rxcache) == _FAIL)
1847         {
1848                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("decache : drop pkt\n"));
1849                 #ifdef DBG_RX_DROP_FRAME
1850                 DBG_8723A("DBG_RX_DROP_FRAME %s recv_decache return _FAIL\n", __func__);
1851                 #endif
1852                 ret= _FAIL;
1853                 goto exit;
1854         }
1855
1856         if(pattrib->privacy){
1857
1858                 RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("validate_recv_data_frame:pattrib->privacy=%x\n", pattrib->privacy));
1859                 RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("\n ^^^^^^^^^^^IS_MCAST(pattrib->ra(0x%02x))=%d^^^^^^^^^^^^^^^6\n", pattrib->ra[0],IS_MCAST(pattrib->ra)));
1860
1861 #ifdef CONFIG_TDLS
1862                 if((psta->tdls_sta_state & TDLS_LINKED_STATE) && (psta->dot118021XPrivacy==_AES_))
1863                 {
1864                         pattrib->encrypt=psta->dot118021XPrivacy;
1865                 }
1866                 else
1867 #endif /* CONFIG_TDLS */
1868                 GET_ENCRY_ALGO(psecuritypriv, psta, pattrib->encrypt, IS_MCAST(pattrib->ra));
1869
1870                 RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("\n pattrib->encrypt=%d\n",pattrib->encrypt));
1871
1872                 SET_ICE_IV_LEN(pattrib->iv_len, pattrib->icv_len, pattrib->encrypt);
1873         }
1874         else
1875         {
1876                 pattrib->encrypt = 0;
1877                 pattrib->iv_len = pattrib->icv_len = 0;
1878         }
1879
1880 exit:
1881
1882 _func_exit_;
1883
1884         return ret;
1885 }
1886
1887 sint validate_recv_frame(_adapter *adapter, union recv_frame *precv_frame);
1888 sint validate_recv_frame(_adapter *adapter, union recv_frame *precv_frame)
1889 {
1890         /* shall check frame subtype, to / from ds, da, bssid */
1891
1892         /* then call check if rx seq/frag. duplicated. */
1893
1894         u8 type;
1895         u8 subtype;
1896         sint retval = _SUCCESS;
1897
1898         struct rx_pkt_attrib *pattrib = & precv_frame->u.hdr.attrib;
1899
1900         u8 *ptr = precv_frame->u.hdr.rx_data;
1901         u8  ver =(unsigned char) (*ptr)&0x3 ;
1902 #ifdef CONFIG_FIND_BEST_CHANNEL
1903         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1904 #endif
1905
1906 #ifdef CONFIG_TDLS
1907         struct tdls_info *ptdlsinfo = &adapter->tdlsinfo;
1908 #endif /* CONFIG_TDLS */
1909 #ifdef CONFIG_WAPI_SUPPORT
1910         PRT_WAPI_T      pWapiInfo = &adapter->wapiInfo;
1911         struct recv_frame_hdr *phdr = &precv_frame->u.hdr;
1912         u8 wai_pkt = 0;
1913         u16 sc;
1914         u8      external_len = 0;
1915 #endif
1916
1917 _func_enter_;
1918
1919 #ifdef CONFIG_FIND_BEST_CHANNEL
1920         if (pmlmeext->sitesurvey_res.state == SCAN_PROCESS) {
1921                 int ch_set_idx = rtw_ch_set_search_ch(pmlmeext->channel_set, rtw_get_oper_ch(adapter));
1922                 if (ch_set_idx >= 0)
1923                         pmlmeext->channel_set[ch_set_idx].rx_count++;
1924         }
1925 #endif
1926
1927 #ifdef CONFIG_TDLS
1928         if(ptdlsinfo->ch_sensing==1 && ptdlsinfo->cur_channel !=0){
1929                 ptdlsinfo->collect_pkt_num[ptdlsinfo->cur_channel-1]++;
1930         }
1931 #endif /* CONFIG_TDLS */
1932
1933         /* add version chk */
1934         if(ver!=0){
1935                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("validate_recv_data_frame fail! (ver!=0)\n"));
1936                 retval= _FAIL;
1937                 goto exit;
1938         }
1939
1940         type =  GetFrameType(ptr);
1941         subtype = GetFrameSubType(ptr); /* bit(7)~bit(2) */
1942
1943         pattrib->to_fr_ds = get_tofr_ds(ptr);
1944
1945         pattrib->frag_num = GetFragNum(ptr);
1946         pattrib->seq_num = GetSequence(ptr);
1947
1948         pattrib->pw_save = GetPwrMgt(ptr);
1949         pattrib->mfrag = GetMFrag(ptr);
1950         pattrib->mdata = GetMData(ptr);
1951         pattrib->privacy = GetPrivacy(ptr);
1952         pattrib->order = GetOrder(ptr);
1953 #ifdef CONFIG_WAPI_SUPPORT
1954         sc = (pattrib->seq_num<<4) | pattrib->frag_num;
1955 #endif
1956
1957 #if 1 /* Dump rx packets */
1958 {
1959         u8 bDumpRxPkt;
1960         rtw_hal_get_def_var(adapter, HAL_DEF_DBG_DUMP_RXPKT, &(bDumpRxPkt));
1961         if(bDumpRxPkt ==1){/* dump all rx packets */
1962                 int i;
1963                 DBG_8723A("############################# \n");
1964
1965                 for(i=0; i<64;i=i+8)
1966                         DBG_8723A("%02X:%02X:%02X:%02X:%02X:%02X:%02X:%02X:\n", *(ptr+i),
1967                         *(ptr+i+1), *(ptr+i+2) ,*(ptr+i+3) ,*(ptr+i+4),*(ptr+i+5), *(ptr+i+6), *(ptr+i+7));
1968                 DBG_8723A("############################# \n");
1969         }
1970         else if(bDumpRxPkt ==2){
1971                 if(type== WIFI_MGT_TYPE){
1972                         int i;
1973                         DBG_8723A("############################# \n");
1974
1975                         for(i=0; i<64;i=i+8)
1976                                 DBG_8723A("%02X:%02X:%02X:%02X:%02X:%02X:%02X:%02X:\n", *(ptr+i),
1977                                 *(ptr+i+1), *(ptr+i+2) ,*(ptr+i+3) ,*(ptr+i+4),*(ptr+i+5), *(ptr+i+6), *(ptr+i+7));
1978                         DBG_8723A("############################# \n");
1979                 }
1980         }
1981         else if(bDumpRxPkt ==3){
1982                 if(type== WIFI_DATA_TYPE){
1983                         int i;
1984                         DBG_8723A("############################# \n");
1985
1986                         for(i=0; i<64;i=i+8)
1987                                 DBG_8723A("%02X:%02X:%02X:%02X:%02X:%02X:%02X:%02X:\n", *(ptr+i),
1988                                 *(ptr+i+1), *(ptr+i+2) ,*(ptr+i+3) ,*(ptr+i+4),*(ptr+i+5), *(ptr+i+6), *(ptr+i+7));
1989                         DBG_8723A("############################# \n");
1990                 }
1991         }
1992 }
1993 #endif
1994         switch (type)
1995         {
1996                 case WIFI_MGT_TYPE: /* mgnt */
1997                         retval = validate_recv_mgnt_frame(adapter, precv_frame);
1998                         if (retval == _FAIL)
1999                         {
2000                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("validate_recv_mgnt_frame fail\n"));
2001                         }
2002                         retval = _FAIL; /*  only data frame return _SUCCESS */
2003                         break;
2004                 case WIFI_CTRL_TYPE: /* ctrl */
2005                         retval = validate_recv_ctrl_frame(adapter, precv_frame);
2006                         if (retval == _FAIL)
2007                         {
2008                                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("validate_recv_ctrl_frame fail\n"));
2009                         }
2010                         retval = _FAIL; /*  only data frame return _SUCCESS */
2011                         break;
2012                 case WIFI_DATA_TYPE: /* data */
2013 #ifdef CONFIG_WAPI_SUPPORT
2014                         if(pattrib->qos)
2015                                 external_len = 2;
2016                         else
2017                                 external_len= 0;
2018
2019                         wai_pkt = rtw_wapi_is_wai_packet(adapter,ptr);
2020
2021                         phdr->bIsWaiPacket = wai_pkt;
2022
2023                         if(wai_pkt !=0){
2024                                 if(sc != adapter->wapiInfo.wapiSeqnumAndFragNum)
2025                                 {
2026                                         adapter->wapiInfo.wapiSeqnumAndFragNum = sc;
2027                                 }
2028                                 else
2029                                 {
2030                                         retval = _FAIL;
2031                                         break;
2032                                 }
2033                         }
2034                         else{
2035
2036                                         if(rtw_wapi_drop_for_key_absent(adapter,GetAddr2Ptr(ptr))){
2037                                                 retval=_FAIL;
2038                                                 WAPI_TRACE(WAPI_RX,"drop for key absent for rx \n");
2039                                                 break;
2040                                         }
2041                         }
2042
2043 #endif
2044
2045                         rtw_led_control(adapter, LED_CTL_RX);
2046                         pattrib->qos = (subtype & BIT(7))? 1:0;
2047                         retval = validate_recv_data_frame(adapter, precv_frame);
2048                         if (retval == _FAIL)
2049                         {
2050                                 struct recv_priv *precvpriv = &adapter->recvpriv;
2051                                 /* RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("validate_recv_data_frame fail\n")); */
2052                                 precvpriv->rx_drop++;
2053                         }
2054                         break;
2055                 default:
2056                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("validate_recv_data_frame fail! type=0x%x\n", type));
2057                         #ifdef DBG_RX_DROP_FRAME
2058                         DBG_8723A("DBG_RX_DROP_FRAME validate_recv_data_frame fail! type=0x%x\n", type);
2059                         #endif
2060                         retval = _FAIL;
2061                         break;
2062         }
2063
2064 exit:
2065
2066 _func_exit_;
2067
2068         return retval;
2069 }
2070
2071 /* remove the wlanhdr and add the eth_hdr */
2072
2073 sint wlanhdr_to_ethhdr ( union recv_frame *precvframe)
2074 {
2075         sint    rmv_len;
2076         u16     eth_type, len;
2077         u8      bsnaphdr;
2078         u8      *psnap_type;
2079         struct ieee80211_snap_hdr       *psnap;
2080
2081         sint ret=_SUCCESS;
2082         _adapter                        *adapter =precvframe->u.hdr.adapter;
2083         struct mlme_priv        *pmlmepriv = &adapter->mlmepriv;
2084
2085         u8      *ptr = get_recvframe_data(precvframe) ; /*  point to frame_ctrl field */
2086         struct rx_pkt_attrib *pattrib = & precvframe->u.hdr.attrib;
2087
2088 _func_enter_;
2089
2090         if(pattrib->encrypt){
2091                 recvframe_pull_tail(precvframe, pattrib->icv_len);
2092         }
2093
2094         psnap=(struct ieee80211_snap_hdr        *)(ptr+pattrib->hdrlen + pattrib->iv_len);
2095         psnap_type=ptr+pattrib->hdrlen + pattrib->iv_len+SNAP_SIZE;
2096         /* convert hdr + possible LLC headers into Ethernet header */
2097         /* eth_type = (psnap_type[0] << 8) | psnap_type[1]; */
2098         if((_rtw_memcmp(psnap, rtw_rfc1042_header, SNAP_SIZE) &&
2099                 (_rtw_memcmp(psnap_type, SNAP_ETH_TYPE_IPX, 2) == _FALSE) &&
2100                 (_rtw_memcmp(psnap_type, SNAP_ETH_TYPE_APPLETALK_AARP, 2)==_FALSE) )||
2101                 /* eth_type != ETH_P_AARP && eth_type != ETH_P_IPX) || */
2102                  _rtw_memcmp(psnap, rtw_bridge_tunnel_header, SNAP_SIZE)){
2103                 /* remove RFC1042 or Bridge-Tunnel encapsulation and replace EtherType */
2104                 bsnaphdr = _TRUE;
2105         }
2106         else {
2107                 /* Leave Ethernet header part of hdr and full payload */
2108                 bsnaphdr = _FALSE;
2109         }
2110
2111         rmv_len = pattrib->hdrlen + pattrib->iv_len +(bsnaphdr?SNAP_SIZE:0);
2112         len = precvframe->u.hdr.len - rmv_len;
2113
2114         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("\n===pattrib->hdrlen: %x,  pattrib->iv_len:%x ===\n\n", pattrib->hdrlen,  pattrib->iv_len));
2115
2116         memcpy(&eth_type, ptr+rmv_len, 2);
2117         eth_type= ntohs((unsigned short )eth_type); /* pattrib->ether_type */
2118         pattrib->eth_type = eth_type;
2119
2120         if ((check_fwstate(pmlmepriv, WIFI_MP_STATE) == _TRUE))
2121         {
2122                 ptr += rmv_len ;
2123                 *ptr = 0x87;
2124                 *(ptr+1) = 0x12;
2125
2126                 eth_type = 0x8712;
2127                 /*  append rx status for mp test packets */
2128                 ptr = recvframe_pull(precvframe, (rmv_len-sizeof(struct ethhdr)+2)-24);
2129                 memcpy(ptr, get_rxmem(precvframe), 24);
2130                 ptr+=24;
2131         }
2132         else {
2133                 ptr = recvframe_pull(precvframe, (rmv_len-sizeof(struct ethhdr)+ (bsnaphdr?2:0)));
2134         }
2135
2136         memcpy(ptr, pattrib->dst, ETH_ALEN);
2137         memcpy(ptr+ETH_ALEN, pattrib->src, ETH_ALEN);
2138
2139         if(!bsnaphdr) {
2140                 len = htons(len);
2141                 memcpy(ptr+12, &len, 2);
2142         }
2143
2144 _func_exit_;
2145         return ret;
2146 }
2147
2148 #if defined(CONFIG_SDIO_HCI) || defined(CONFIG_GSPI_HCI)
2149 static void recvframe_expand_pkt(
2150         PADAPTER padapter,
2151         union recv_frame *prframe)
2152 {
2153         struct recv_frame_hdr *pfhdr;
2154         _pkt *ppkt;
2155         u8 shift_sz;
2156         u32 alloc_sz;
2157
2158         pfhdr = &prframe->u.hdr;
2159
2160         /*      6 is for IP header 8 bytes alignment in QoS packet case. */
2161         if (pfhdr->attrib.qos)
2162                 shift_sz = 6;
2163         else
2164                 shift_sz = 0;
2165
2166         /*  for first fragment packet, need to allocate */
2167         /*  (1536 + RXDESC_SIZE + drvinfo_sz) to reassemble packet */
2168         /*      8 is for skb->data 8 bytes alignment. */
2169 /*      alloc_sz = _RND(1536 + RXDESC_SIZE + pfhdr->attrib.drvinfosize + shift_sz + 8, 128); */
2170         alloc_sz = 1664; /*  round (1536 + 24 + 32 + shift_sz + 8) to 128 bytes alignment */
2171
2172         /* 3 1. alloc new skb */
2173         /*  prepare extra space for 4 bytes alignment */
2174 #if (LINUX_VERSION_CODE < KERNEL_VERSION(2,6,18)) /*  http:www.mail-archive.com/netdev@vger.kernel.org/msg17214.html */
2175         ppkt = dev_alloc_skb(alloc_sz);
2176         if (ppkt) ppkt->dev = padapter->pnetdev;
2177 #else
2178         ppkt = netdev_alloc_skb(padapter->pnetdev, alloc_sz);
2179 #endif
2180         if (!ppkt) return; /*  no way to expand */
2181
2182         /* 3 2. Prepare new skb to replace & release old skb */
2183         /*  force ppkt->data at 8-byte alignment address */
2184         skb_reserve(ppkt, 8 - ((SIZE_PTR)ppkt->data & 7));
2185         /*  force ip_hdr at 8-byte alignment address according to shift_sz */
2186         skb_reserve(ppkt, shift_sz);
2187
2188         /*  copy data to new pkt */
2189         memcpy(skb_put(ppkt, pfhdr->len), pfhdr->rx_data, pfhdr->len);
2190
2191         dev_kfree_skb_any(pfhdr->pkt);
2192
2193         /*  attach new pkt to recvframe */
2194         pfhdr->pkt = ppkt;
2195         pfhdr->rx_head = ppkt->head;
2196         pfhdr->rx_data = ppkt->data;
2197         pfhdr->rx_tail = skb_tail_pointer(ppkt);
2198         pfhdr->rx_end = skb_end_pointer(ppkt);
2199 }
2200 #endif
2201
2202 /* perform defrag */
2203 union recv_frame * recvframe_defrag(_adapter *adapter,_queue *defrag_q);
2204 union recv_frame * recvframe_defrag(_adapter *adapter,_queue *defrag_q)
2205 {
2206         _list    *plist, *phead;
2207         u8      *data,wlanhdr_offset;
2208         u8      curfragnum;
2209         struct recv_frame_hdr *pfhdr,*pnfhdr;
2210         union recv_frame* prframe, *pnextrframe;
2211         _queue  *pfree_recv_queue;
2212
2213 _func_enter_;
2214
2215         curfragnum=0;
2216         pfree_recv_queue=&adapter->recvpriv.free_recv_queue;
2217
2218         phead = get_list_head(defrag_q);
2219         plist = get_next(phead);
2220         prframe = LIST_CONTAINOR(plist, union recv_frame, u);
2221         pfhdr=&prframe->u.hdr;
2222         rtw_list_delete(&(prframe->u.list));
2223
2224         if(curfragnum!=pfhdr->attrib.frag_num)
2225         {
2226                 /* the first fragment number must be 0 */
2227                 /* free the whole queue */
2228                 rtw_free_recvframe(prframe, pfree_recv_queue);
2229                 rtw_free_recvframe_queue(defrag_q, pfree_recv_queue);
2230
2231                 return NULL;
2232         }
2233
2234 #if defined(CONFIG_SDIO_HCI) || defined(CONFIG_GSPI_HCI)
2235 #ifndef CONFIG_SDIO_RX_COPY
2236         recvframe_expand_pkt(adapter, prframe);
2237 #endif
2238 #endif
2239
2240         curfragnum++;
2241
2242         plist= get_list_head(defrag_q);
2243
2244         plist = get_next(plist);
2245
2246         data=get_recvframe_data(prframe);
2247
2248         while(rtw_end_of_queue_search(phead, plist) == _FALSE)
2249         {
2250                 pnextrframe = LIST_CONTAINOR(plist, union recv_frame , u);
2251                 pnfhdr=&pnextrframe->u.hdr;
2252
2253                 /* check the fragment sequence  (2nd ~n fragment frame) */
2254
2255                 if(curfragnum!=pnfhdr->attrib.frag_num)
2256                 {
2257                         /* the fragment number must be increasing  (after decache) */
2258                         /* release the defrag_q & prframe */
2259                         rtw_free_recvframe(prframe, pfree_recv_queue);
2260                         rtw_free_recvframe_queue(defrag_q, pfree_recv_queue);
2261                         return NULL;
2262                 }
2263
2264                 curfragnum++;
2265
2266                 /* copy the 2nd~n fragment frame's payload to the first fragment */
2267                 /* get the 2nd~last fragment frame's payload */
2268
2269                 wlanhdr_offset = pnfhdr->attrib.hdrlen + pnfhdr->attrib.iv_len;
2270
2271                 recvframe_pull(pnextrframe, wlanhdr_offset);
2272
2273                 /* append  to first fragment frame's tail (if privacy frame, pull the ICV) */
2274                 recvframe_pull_tail(prframe, pfhdr->attrib.icv_len);
2275
2276                 /* memcpy */
2277                 memcpy(pfhdr->rx_tail, pnfhdr->rx_data, pnfhdr->len);
2278
2279                 recvframe_put(prframe, pnfhdr->len);
2280
2281                 pfhdr->attrib.icv_len=pnfhdr->attrib.icv_len;
2282                 plist = get_next(plist);
2283
2284         };
2285
2286         /* free the defrag_q queue and return the prframe */
2287         rtw_free_recvframe_queue(defrag_q, pfree_recv_queue);
2288
2289         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("Performance defrag!!!!!\n"));
2290
2291 _func_exit_;
2292
2293         return prframe;
2294 }
2295
2296 /* check if need to defrag, if needed queue the frame to defrag_q */
2297 union recv_frame* recvframe_chk_defrag(PADAPTER padapter, union recv_frame *precv_frame)
2298 {
2299         u8      ismfrag;
2300         u8      fragnum;
2301         u8      *psta_addr;
2302         struct recv_frame_hdr *pfhdr;
2303         struct sta_info *psta;
2304         struct sta_priv *pstapriv;
2305         _list *phead;
2306         union recv_frame *prtnframe = NULL;
2307         _queue *pfree_recv_queue, *pdefrag_q;
2308
2309 _func_enter_;
2310
2311         pstapriv = &padapter->stapriv;
2312
2313         pfhdr = &precv_frame->u.hdr;
2314
2315         pfree_recv_queue = &padapter->recvpriv.free_recv_queue;
2316
2317         /* need to define struct of wlan header frame ctrl */
2318         ismfrag = pfhdr->attrib.mfrag;
2319         fragnum = pfhdr->attrib.frag_num;
2320
2321         psta_addr = pfhdr->attrib.ta;
2322         psta = rtw_get_stainfo(pstapriv, psta_addr);
2323         if (psta == NULL)
2324         {
2325                 u8 type = GetFrameType(pfhdr->rx_data);
2326                 if (type != WIFI_DATA_TYPE) {
2327                         psta = rtw_get_bcmc_stainfo(padapter);
2328                         pdefrag_q = &psta->sta_recvpriv.defrag_q;
2329                 } else
2330                         pdefrag_q = NULL;
2331         }
2332         else
2333                 pdefrag_q = &psta->sta_recvpriv.defrag_q;
2334
2335         if ((ismfrag==0) && (fragnum==0))
2336         {
2337                 prtnframe = precv_frame;/* isn't a fragment frame */
2338         }
2339
2340         if (ismfrag==1)
2341         {
2342                 /* 0~(n-1) fragment frame */
2343                 /* enqueue to defraf_g */
2344                 if(pdefrag_q != NULL)
2345                 {
2346                         if(fragnum==0)
2347                         {
2348                                 /* the first fragment */
2349                                 if(_rtw_queue_empty(pdefrag_q) == _FALSE)
2350                                 {
2351                                         /* free current defrag_q */
2352                                         rtw_free_recvframe_queue(pdefrag_q, pfree_recv_queue);
2353                                 }
2354                         }
2355
2356                         /* Then enqueue the 0~(n-1) fragment into the defrag_q */
2357
2358                         /* _rtw_spinlock(&pdefrag_q->lock); */
2359                         phead = get_list_head(pdefrag_q);
2360                         rtw_list_insert_tail(&pfhdr->list, phead);
2361                         /* _rtw_spinunlock(&pdefrag_q->lock); */
2362
2363                         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("Enqueuq: ismfrag = %d, fragnum= %d\n", ismfrag,fragnum));
2364
2365                         prtnframe=NULL;
2366
2367                 }
2368                 else
2369                 {
2370                         /* can't find this ta's defrag_queue, so free this recv_frame */
2371                         rtw_free_recvframe(precv_frame, pfree_recv_queue);
2372                         prtnframe=NULL;
2373                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("Free because pdefrag_q ==NULL: ismfrag = %d, fragnum= %d\n", ismfrag, fragnum));
2374                 }
2375
2376         }
2377
2378         if((ismfrag==0)&&(fragnum!=0))
2379         {
2380                 /* the last fragment frame */
2381                 /* enqueue the last fragment */
2382                 if(pdefrag_q != NULL)
2383                 {
2384                         /* _rtw_spinlock(&pdefrag_q->lock); */
2385                         phead = get_list_head(pdefrag_q);
2386                         rtw_list_insert_tail(&pfhdr->list,phead);
2387                         /* _rtw_spinunlock(&pdefrag_q->lock); */
2388
2389                         /* call recvframe_defrag to defrag */
2390                         RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("defrag: ismfrag = %d, fragnum= %d\n", ismfrag, fragnum));
2391                         precv_frame = recvframe_defrag(padapter, pdefrag_q);
2392                         prtnframe=precv_frame;
2393
2394                 }
2395                 else
2396                 {
2397                         /* can't find this ta's defrag_queue, so free this recv_frame */
2398                         rtw_free_recvframe(precv_frame, pfree_recv_queue);
2399                         prtnframe=NULL;
2400                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("Free because pdefrag_q ==NULL: ismfrag = %d, fragnum= %d\n", ismfrag,fragnum));
2401                 }
2402
2403         }
2404
2405         if((prtnframe!=NULL)&&(prtnframe->u.hdr.attrib.privacy))
2406         {
2407                 /* after defrag we must check tkip mic code */
2408                 if(recvframe_chkmic(padapter,  prtnframe)==_FAIL)
2409                 {
2410                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("recvframe_chkmic(padapter,  prtnframe)==_FAIL\n"));
2411                         rtw_free_recvframe(prtnframe,pfree_recv_queue);
2412                         prtnframe=NULL;
2413                 }
2414         }
2415
2416 _func_exit_;
2417
2418         return prtnframe;
2419 }
2420
2421 #define ENDIAN_FREE 1
2422
2423 int amsdu_to_msdu(_adapter *padapter, union recv_frame *prframe);
2424 int amsdu_to_msdu(_adapter *padapter, union recv_frame *prframe)
2425 {
2426         int     a_len, padding_len;
2427         u16     eth_type, nSubframe_Length;
2428         u8      nr_subframes, i;
2429         unsigned char *pdata;
2430         struct rx_pkt_attrib *pattrib;
2431         unsigned char *data_ptr;
2432         _pkt *sub_skb,*subframes[MAX_SUBFRAME_COUNT];
2433         struct recv_priv *precvpriv = &padapter->recvpriv;
2434         _queue *pfree_recv_queue = &(precvpriv->free_recv_queue);
2435         int     ret = _SUCCESS;
2436         nr_subframes = 0;
2437
2438         pattrib = &prframe->u.hdr.attrib;
2439
2440         recvframe_pull(prframe, prframe->u.hdr.attrib.hdrlen);
2441
2442         if(prframe->u.hdr.attrib.iv_len >0)
2443         {
2444                 recvframe_pull(prframe, prframe->u.hdr.attrib.iv_len);
2445         }
2446
2447         a_len = prframe->u.hdr.len;
2448
2449         pdata = prframe->u.hdr.rx_data;
2450
2451         while(a_len > ETH_HLEN) {
2452
2453                 /* Offset 12 denote 2 mac address */
2454 #ifdef ENDIAN_FREE
2455                 /* nSubframe_Length = ntohs(*((u16*)(pdata + 12))); */
2456                 nSubframe_Length = RTW_GET_BE16(pdata + 12);
2457 #else /*  ENDIAN_FREE */
2458                 nSubframe_Length = *((u16*)(pdata + 12));
2459                 /* m==>change the length order */
2460                 nSubframe_Length = (nSubframe_Length>>8) + (nSubframe_Length<<8);
2461                 /* ntohs(nSubframe_Length); */
2462 #endif /*  ENDIAN_FREE */
2463
2464                 if( a_len < (ETHERNET_HEADER_SIZE + nSubframe_Length) ) {
2465                         DBG_8723A("nRemain_Length is %d and nSubframe_Length is : %d\n",a_len,nSubframe_Length);
2466                         goto exit;
2467                 }
2468
2469                 /* move the data point to data content */
2470                 pdata += ETH_HLEN;
2471                 a_len -= ETH_HLEN;
2472
2473                 /* Allocate new skb for releasing to upper layer */
2474 #ifdef CONFIG_SKB_COPY
2475                 sub_skb = dev_alloc_skb(nSubframe_Length + 12);
2476                 if(sub_skb)
2477                 {
2478                         skb_reserve(sub_skb, 12);
2479                         data_ptr = (u8 *)skb_put(sub_skb, nSubframe_Length);
2480                         memcpy(data_ptr, pdata, nSubframe_Length);
2481                 }
2482                 else
2483 #endif /*  CONFIG_SKB_COPY */
2484                 {
2485                         sub_skb = skb_clone(prframe->u.hdr.pkt, GFP_ATOMIC);
2486                         if(sub_skb)
2487                         {
2488                                 sub_skb->data = pdata;
2489                                 sub_skb->len = nSubframe_Length;
2490                                 skb_set_tail_pointer(sub_skb, nSubframe_Length);
2491                         }
2492                         else
2493                         {
2494                                 DBG_8723A("skb_clone() Fail!!! , nr_subframes = %d\n",nr_subframes);
2495                                 break;
2496                         }
2497                 }
2498
2499
2500                 /* sub_skb->dev = padapter->pnetdev; */
2501                 subframes[nr_subframes++] = sub_skb;
2502
2503                 if(nr_subframes >= MAX_SUBFRAME_COUNT) {
2504                         DBG_8723A("ParseSubframe(): Too many Subframes! Packets dropped!\n");
2505                         break;
2506                 }
2507
2508                 pdata += nSubframe_Length;
2509                 a_len -= nSubframe_Length;
2510                 if(a_len != 0) {
2511                         padding_len = 4 - ((nSubframe_Length + ETH_HLEN) & (4-1));
2512                         if(padding_len == 4) {
2513                                 padding_len = 0;
2514                         }
2515
2516                         if(a_len < padding_len) {
2517                                 goto exit;
2518                         }
2519                         pdata += padding_len;
2520                         a_len -= padding_len;
2521                 }
2522         }
2523
2524         for(i=0; i<nr_subframes; i++){
2525                 sub_skb = subframes[i];
2526                 /* convert hdr + possible LLC headers into Ethernet header */
2527 #ifdef ENDIAN_FREE
2528                 /* eth_type = ntohs(*(u16*)&sub_skb->data[6]); */
2529                 eth_type = RTW_GET_BE16(&sub_skb->data[6]);
2530 #else /*  ENDIAN_FREE */
2531                 eth_type = (sub_skb->data[6] << 8) | sub_skb->data[7];
2532 #endif /*  ENDIAN_FREE */
2533                 if (sub_skb->len >= 8 &&
2534                         ((_rtw_memcmp(sub_skb->data, rtw_rfc1042_header, SNAP_SIZE) &&
2535                           eth_type != ETH_P_AARP && eth_type != ETH_P_IPX) ||
2536                          _rtw_memcmp(sub_skb->data, rtw_bridge_tunnel_header, SNAP_SIZE) )) {
2537                         /* remove RFC1042 or Bridge-Tunnel encapsulation and replace EtherType */
2538                         skb_pull(sub_skb, SNAP_SIZE);
2539                         memcpy(skb_push(sub_skb, ETH_ALEN), pattrib->src, ETH_ALEN);
2540                         memcpy(skb_push(sub_skb, ETH_ALEN), pattrib->dst, ETH_ALEN);
2541                 } else {
2542                         u16 len;
2543                         /* Leave Ethernet header part of hdr and full payload */
2544                         len = htons(sub_skb->len);
2545                         memcpy(skb_push(sub_skb, 2), &len, 2);
2546                         memcpy(skb_push(sub_skb, ETH_ALEN), pattrib->src, ETH_ALEN);
2547                         memcpy(skb_push(sub_skb, ETH_ALEN), pattrib->dst, ETH_ALEN);
2548                 }
2549
2550                 /* Indicat the packets to upper layer */
2551                 {
2552 #ifdef CONFIG_BR_EXT
2553                         /*  Insert NAT2.5 RX here! */
2554                         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2555                         void *br_port = NULL;
2556 #if (LINUX_VERSION_CODE <= KERNEL_VERSION(2, 6, 35))
2557                         br_port = padapter->pnetdev->br_port;
2558 #else   /*  (LINUX_VERSION_CODE <= KERNEL_VERSION(2, 6, 35)) */
2559                         rcu_read_lock();
2560                         br_port = rcu_dereference(padapter->pnetdev->rx_handler_data);
2561                         rcu_read_unlock();
2562 #endif  /*  (LINUX_VERSION_CODE <= KERNEL_VERSION(2, 6, 35)) */
2563
2564                         if (br_port &&
2565                             (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_ADHOC_STATE) == _TRUE)) {
2566                                 int nat25_handle_frame(_adapter *priv, struct sk_buff *skb);
2567                                 if (nat25_handle_frame(padapter, sub_skb) == -1) {
2568                                         /*  bypass this frame to upper layer!! */
2569                                 }
2570                         }
2571 #endif  /*  CONFIG_BR_EXT */
2572
2573                         sub_skb->protocol = eth_type_trans(sub_skb, padapter->pnetdev);
2574                         sub_skb->dev = padapter->pnetdev;
2575
2576 #ifdef CONFIG_TCP_CSUM_OFFLOAD_RX
2577                         if ( (pattrib->tcpchk_valid == 1) && (pattrib->tcp_chkrpt == 1) ) {
2578                                 sub_skb->ip_summed = CHECKSUM_UNNECESSARY;
2579                         } else {
2580                                 sub_skb->ip_summed = CHECKSUM_NONE;
2581                         }
2582 #else /* !CONFIG_TCP_CSUM_OFFLOAD_RX */
2583                         sub_skb->ip_summed = CHECKSUM_NONE;
2584 #endif /* CONFIG_TCP_CSUM_OFFLOAD_RX */
2585
2586                         netif_rx(sub_skb);
2587                 }
2588         }
2589
2590 exit:
2591
2592         prframe->u.hdr.len=0;
2593         rtw_free_recvframe(prframe, pfree_recv_queue);/* free this recv_frame */
2594
2595         return ret;
2596 }
2597
2598 int check_indicate_seq(struct recv_reorder_ctrl *preorder_ctrl, u16 seq_num);
2599 int check_indicate_seq(struct recv_reorder_ctrl *preorder_ctrl, u16 seq_num)
2600 {
2601         u8      wsize = preorder_ctrl->wsize_b;
2602         u16     wend = (preorder_ctrl->indicate_seq + wsize -1) & 0xFFF;/*  4096; */
2603
2604         /*  Rx Reorder initialize condition. */
2605         if (preorder_ctrl->indicate_seq == 0xFFFF)
2606         {
2607                 preorder_ctrl->indicate_seq = seq_num;
2608                 #ifdef DBG_RX_SEQ
2609                 DBG_8723A("DBG_RX_SEQ %s:%d init IndicateSeq: %d, NewSeq: %d\n", __FUNCTION__, __LINE__,
2610                         preorder_ctrl->indicate_seq, seq_num);
2611                 #endif
2612
2613                 /* DbgPrint("check_indicate_seq, 1st->indicate_seq=%d\n", precvpriv->indicate_seq); */
2614         }
2615
2616         /* DbgPrint("enter->check_indicate_seq(): IndicateSeq: %d, NewSeq: %d\n", precvpriv->indicate_seq, seq_num); */
2617
2618         /*  Drop out the packet which SeqNum is smaller than WinStart */
2619         if( SN_LESS(seq_num, preorder_ctrl->indicate_seq) )
2620         {
2621                 /* RT_TRACE(COMP_RX_REORDER, DBG_LOUD, ("CheckRxTsIndicateSeq(): Packet Drop! IndicateSeq: %d, NewSeq: %d\n", pTS->RxIndicateSeq, NewSeqNum)); */
2622                 /* DbgPrint("CheckRxTsIndicateSeq(): Packet Drop! IndicateSeq: %d, NewSeq: %d\n", precvpriv->indicate_seq, seq_num); */
2623
2624                 #ifdef DBG_RX_DROP_FRAME
2625                 DBG_8723A("%s IndicateSeq: %d > NewSeq: %d\n", __FUNCTION__,
2626                         preorder_ctrl->indicate_seq, seq_num);
2627                 #endif
2628
2629                 return _FALSE;
2630         }
2631
2632         /*  */
2633         /*  Sliding window manipulation. Conditions includes: */
2634         /*  1. Incoming SeqNum is equal to WinStart =>Window shift 1 */
2635         /*  2. Incoming SeqNum is larger than the WinEnd => Window shift N */
2636         /*  */
2637         if( SN_EQUAL(seq_num, preorder_ctrl->indicate_seq) )
2638         {
2639                 preorder_ctrl->indicate_seq = (preorder_ctrl->indicate_seq + 1) & 0xFFF;
2640                 #ifdef DBG_RX_SEQ
2641                 DBG_8723A("DBG_RX_SEQ %s:%d SN_EQUAL IndicateSeq: %d, NewSeq: %d\n", __FUNCTION__, __LINE__,
2642                         preorder_ctrl->indicate_seq, seq_num);
2643                 #endif
2644         }
2645         else if(SN_LESS(wend, seq_num))
2646         {
2647                 /* RT_TRACE(COMP_RX_REORDER, DBG_LOUD, ("CheckRxTsIndicateSeq(): Window Shift! IndicateSeq: %d, NewSeq: %d\n", pTS->RxIndicateSeq, NewSeqNum)); */
2648                 /* DbgPrint("CheckRxTsIndicateSeq(): Window Shift! IndicateSeq: %d, NewSeq: %d\n", precvpriv->indicate_seq, seq_num); */
2649
2650                 /*  boundary situation, when seq_num cross 0xFFF */
2651                 if(seq_num >= (wsize - 1))
2652                         preorder_ctrl->indicate_seq = seq_num + 1 -wsize;
2653                 else
2654                         preorder_ctrl->indicate_seq = 0xFFF - (wsize - (seq_num + 1)) + 1;
2655
2656                 #ifdef DBG_RX_SEQ
2657                 DBG_8723A("DBG_RX_SEQ %s:%d SN_LESS(wend, seq_num) IndicateSeq: %d, NewSeq: %d\n", __FUNCTION__, __LINE__,
2658                         preorder_ctrl->indicate_seq, seq_num);
2659                 #endif
2660         }
2661
2662         /* DbgPrint("exit->check_indicate_seq(): IndicateSeq: %d, NewSeq: %d\n", precvpriv->indicate_seq, seq_num); */
2663
2664         return _TRUE;
2665 }
2666
2667 int enqueue_reorder_recvframe(struct recv_reorder_ctrl *preorder_ctrl, union recv_frame *prframe);
2668 int enqueue_reorder_recvframe(struct recv_reorder_ctrl *preorder_ctrl, union recv_frame *prframe)
2669 {
2670         struct rx_pkt_attrib *pattrib = &prframe->u.hdr.attrib;
2671         _queue *ppending_recvframe_queue = &preorder_ctrl->pending_recvframe_queue;
2672         _list   *phead, *plist;
2673         union recv_frame *pnextrframe;
2674         struct rx_pkt_attrib *pnextattrib;
2675
2676         /* DbgPrint("+enqueue_reorder_recvframe()\n"); */
2677
2678         /* _enter_critical_ex(&ppending_recvframe_queue->lock, &irql); */
2679         /* _rtw_spinlock_ex(&ppending_recvframe_queue->lock); */
2680
2681         phead = get_list_head(ppending_recvframe_queue);
2682         plist = get_next(phead);
2683
2684         while(rtw_end_of_queue_search(phead, plist) == _FALSE)
2685         {
2686                 pnextrframe = LIST_CONTAINOR(plist, union recv_frame, u);
2687                 pnextattrib = &pnextrframe->u.hdr.attrib;
2688
2689                 if(SN_LESS(pnextattrib->seq_num, pattrib->seq_num))
2690                 {
2691                         plist = get_next(plist);
2692                 }
2693                 else if( SN_EQUAL(pnextattrib->seq_num, pattrib->seq_num))
2694                 {
2695                         /* Duplicate entry is found!! Do not insert current entry. */
2696                         /* RT_TRACE(COMP_RX_REORDER, DBG_TRACE, ("InsertRxReorderList(): Duplicate packet is dropped!! IndicateSeq: %d, NewSeq: %d\n", pTS->RxIndicateSeq, SeqNum)); */
2697
2698                         /* _exit_critical_ex(&ppending_recvframe_queue->lock, &irql); */
2699
2700                         return _FALSE;
2701                 }
2702                 else
2703                 {
2704                         break;
2705                 }
2706
2707                 /* DbgPrint("enqueue_reorder_recvframe():while\n"); */
2708
2709         }
2710
2711         /* _enter_critical_ex(&ppending_recvframe_queue->lock, &irql); */
2712         /* _rtw_spinlock_ex(&ppending_recvframe_queue->lock); */
2713
2714         rtw_list_delete(&(prframe->u.hdr.list));
2715
2716         rtw_list_insert_tail(&(prframe->u.hdr.list), plist);
2717
2718         /* _rtw_spinunlock_ex(&ppending_recvframe_queue->lock); */
2719         /* _exit_critical_ex(&ppending_recvframe_queue->lock, &irql); */
2720
2721         /* RT_TRACE(COMP_RX_REORDER, DBG_TRACE, ("InsertRxReorderList(): Pkt insert into buffer!! IndicateSeq: %d, NewSeq: %d\n", pTS->RxIndicateSeq, SeqNum)); */
2722         return _TRUE;
2723 }
2724
2725 int recv_indicatepkts_in_order(_adapter *padapter, struct recv_reorder_ctrl *preorder_ctrl, int bforced);
2726 int recv_indicatepkts_in_order(_adapter *padapter, struct recv_reorder_ctrl *preorder_ctrl, int bforced)
2727 {
2728         /* _irqL irql; */
2729         /* u8 bcancelled; */
2730         _list   *phead, *plist;
2731         union recv_frame *prframe;
2732         struct rx_pkt_attrib *pattrib;
2733         /* u8 index = 0; */
2734         int bPktInBuf = _FALSE;
2735         struct recv_priv *precvpriv = &padapter->recvpriv;
2736         _queue *ppending_recvframe_queue = &preorder_ctrl->pending_recvframe_queue;
2737
2738         /* DbgPrint("+recv_indicatepkts_in_order\n"); */
2739
2740         /* _enter_critical_ex(&ppending_recvframe_queue->lock, &irql); */
2741         /* _rtw_spinlock_ex(&ppending_recvframe_queue->lock); */
2742
2743         phead =         get_list_head(ppending_recvframe_queue);
2744         plist = get_next(phead);
2745
2746         /*  Handling some condition for forced indicate case. */
2747         if(bforced==_TRUE)
2748         {
2749                 if(rtw_is_list_empty(phead))
2750                 {
2751                         /*  _exit_critical_ex(&ppending_recvframe_queue->lock, &irql); */
2752                         /* _rtw_spinunlock_ex(&ppending_recvframe_queue->lock); */
2753                         return _TRUE;
2754                 }
2755
2756                  prframe = LIST_CONTAINOR(plist, union recv_frame, u);
2757                 pattrib = &prframe->u.hdr.attrib;
2758                 preorder_ctrl->indicate_seq = pattrib->seq_num;
2759                 #ifdef DBG_RX_SEQ
2760                 DBG_8723A("DBG_RX_SEQ %s:%d IndicateSeq: %d, NewSeq: %d\n", __FUNCTION__, __LINE__,
2761                         preorder_ctrl->indicate_seq, pattrib->seq_num);
2762                 #endif
2763         }
2764
2765         /*  Prepare indication list and indication. */
2766         /*  Check if there is any packet need indicate. */
2767         while(!rtw_is_list_empty(phead))
2768         {
2769
2770                 prframe = LIST_CONTAINOR(plist, union recv_frame, u);
2771                 pattrib = &prframe->u.hdr.attrib;
2772
2773                 if(!SN_LESS(preorder_ctrl->indicate_seq, pattrib->seq_num))
2774                 {
2775                         RT_TRACE(_module_rtl871x_recv_c_, _drv_notice_,
2776                                  ("recv_indicatepkts_in_order: indicate=%d seq=%d amsdu=%d\n",
2777                                   preorder_ctrl->indicate_seq, pattrib->seq_num, pattrib->amsdu));
2778
2779                         plist = get_next(plist);
2780                         rtw_list_delete(&(prframe->u.hdr.list));
2781
2782                         if(SN_EQUAL(preorder_ctrl->indicate_seq, pattrib->seq_num))
2783                         {
2784                                 preorder_ctrl->indicate_seq = (preorder_ctrl->indicate_seq + 1) & 0xFFF;
2785                                 #ifdef DBG_RX_SEQ
2786                                 DBG_8723A("DBG_RX_SEQ %s:%d IndicateSeq: %d, NewSeq: %d\n", __FUNCTION__, __LINE__,
2787                                         preorder_ctrl->indicate_seq, pattrib->seq_num);
2788                                 #endif
2789                         }
2790
2791                         if(!pattrib->amsdu)
2792                         {
2793                                 if ((padapter->bDriverStopped == _FALSE) &&
2794                                     (padapter->bSurpriseRemoved == _FALSE))
2795                                 {
2796
2797                                         rtw_recv_indicatepkt(padapter, prframe);/* indicate this recv_frame */
2798
2799                                 }
2800                         }
2801                         else if(pattrib->amsdu==1)
2802                         {
2803                                 if(amsdu_to_msdu(padapter, prframe)!=_SUCCESS)
2804                                 {
2805                                         rtw_free_recvframe(prframe, &precvpriv->free_recv_queue);
2806                                 }
2807                         }
2808                         else
2809                         {
2810                                 /* error condition; */
2811                         }
2812
2813                         /* Update local variables. */
2814                         bPktInBuf = _FALSE;
2815
2816                 }
2817                 else
2818                 {
2819                         bPktInBuf = _TRUE;
2820                         break;
2821                 }
2822
2823                 /* DbgPrint("recv_indicatepkts_in_order():while\n"); */
2824
2825         }
2826
2827         /* _rtw_spinunlock_ex(&ppending_recvframe_queue->lock); */
2828         /* _exit_critical_ex(&ppending_recvframe_queue->lock, &irql); */
2829
2830         return bPktInBuf;
2831 }
2832
2833 int recv_indicatepkt_reorder(_adapter *padapter, union recv_frame *prframe);
2834 int recv_indicatepkt_reorder(_adapter *padapter, union recv_frame *prframe)
2835 {
2836         _irqL irql;
2837         int retval = _SUCCESS;
2838         struct rx_pkt_attrib *pattrib = &prframe->u.hdr.attrib;
2839         struct recv_reorder_ctrl *preorder_ctrl = prframe->u.hdr.preorder_ctrl;
2840         _queue *ppending_recvframe_queue = &preorder_ctrl->pending_recvframe_queue;
2841
2842         if(!pattrib->amsdu)
2843         {
2844                 /* s1. */
2845                 wlanhdr_to_ethhdr(prframe);
2846
2847                 if ((pattrib->qos!=1) /*|| pattrib->priority!=0 || IS_MCAST(pattrib->ra)*/
2848                         || (pattrib->eth_type==0x0806) || (pattrib->ack_policy!=0))
2849                 {
2850                         if ((padapter->bDriverStopped == _FALSE) &&
2851                             (padapter->bSurpriseRemoved == _FALSE))
2852                         {
2853                                 RT_TRACE(_module_rtl871x_recv_c_, _drv_notice_, ("@@@@  recv_indicatepkt_reorder -recv_func recv_indicatepkt\n" ));
2854
2855                                 rtw_recv_indicatepkt(padapter, prframe);
2856                                 return _SUCCESS;
2857
2858                         }
2859
2860                         #ifdef DBG_RX_DROP_FRAME
2861                         DBG_8723A("DBG_RX_DROP_FRAME %s pattrib->qos !=1\n", __FUNCTION__);
2862                         #endif
2863
2864                         return _FAIL;
2865
2866                 }
2867
2868                 if (preorder_ctrl->enable == _FALSE)
2869                 {
2870                         /* indicate this recv_frame */
2871                         preorder_ctrl->indicate_seq = pattrib->seq_num;
2872                         #ifdef DBG_RX_SEQ
2873                         DBG_8723A("DBG_RX_SEQ %s:%d IndicateSeq: %d, NewSeq: %d\n", __FUNCTION__, __LINE__,
2874                                 preorder_ctrl->indicate_seq, pattrib->seq_num);
2875                         #endif
2876
2877                         rtw_recv_indicatepkt(padapter, prframe);
2878
2879                         preorder_ctrl->indicate_seq = (preorder_ctrl->indicate_seq + 1)%4096;
2880                         #ifdef DBG_RX_SEQ
2881                         DBG_8723A("DBG_RX_SEQ %s:%d IndicateSeq: %d, NewSeq: %d\n", __FUNCTION__, __LINE__,
2882                                 preorder_ctrl->indicate_seq, pattrib->seq_num);
2883                         #endif
2884
2885                         return _SUCCESS;
2886                 }
2887
2888 #ifndef CONFIG_RECV_REORDERING_CTRL
2889                 /* indicate this recv_frame */
2890                 rtw_recv_indicatepkt(padapter, prframe);
2891                 return _SUCCESS;
2892 #endif
2893
2894         }
2895         else if(pattrib->amsdu==1) /* temp filter -> means didn't support A-MSDUs in a A-MPDU */
2896         {
2897                 if (preorder_ctrl->enable == _FALSE)
2898                 {
2899                         preorder_ctrl->indicate_seq = pattrib->seq_num;
2900                         #ifdef DBG_RX_SEQ
2901                         DBG_8723A("DBG_RX_SEQ %s:%d IndicateSeq: %d, NewSeq: %d\n", __FUNCTION__, __LINE__,
2902                                 preorder_ctrl->indicate_seq, pattrib->seq_num);
2903                         #endif
2904
2905                         retval = amsdu_to_msdu(padapter, prframe);
2906
2907                         preorder_ctrl->indicate_seq = (preorder_ctrl->indicate_seq + 1)%4096;
2908                         #ifdef DBG_RX_SEQ
2909                         DBG_8723A("DBG_RX_SEQ %s:%d IndicateSeq: %d, NewSeq: %d\n", __FUNCTION__, __LINE__,
2910                                 preorder_ctrl->indicate_seq, pattrib->seq_num);
2911                         #endif
2912
2913                         if(retval != _SUCCESS){
2914                                 #ifdef DBG_RX_DROP_FRAME
2915                                 DBG_8723A("DBG_RX_DROP_FRAME %s amsdu_to_msdu fail\n", __FUNCTION__);
2916                                 #endif
2917                         }
2918
2919                         return retval;
2920                 }
2921         }
2922         else
2923         {
2924
2925         }
2926
2927         _enter_critical_bh(&ppending_recvframe_queue->lock, &irql);
2928
2929         RT_TRACE(_module_rtl871x_recv_c_, _drv_notice_,
2930                  ("recv_indicatepkt_reorder: indicate=%d seq=%d\n",
2931                   preorder_ctrl->indicate_seq, pattrib->seq_num));
2932
2933         /* s2. check if winstart_b(indicate_seq) needs to been updated */
2934         if(!check_indicate_seq(preorder_ctrl, pattrib->seq_num))
2935         {
2936                 /* pHTInfo->RxReorderDropCounter++; */
2937                 /* ReturnRFDList(Adapter, pRfd); */
2938                 /* RT_TRACE(COMP_RX_REORDER, DBG_TRACE, ("RxReorderIndicatePacket() ==> Packet Drop!!\n")); */
2939                 /* _exit_critical_ex(&ppending_recvframe_queue->lock, &irql); */
2940                 /* return _FAIL; */
2941
2942                 #ifdef DBG_RX_DROP_FRAME
2943                 DBG_8723A("DBG_RX_DROP_FRAME %s check_indicate_seq fail\n", __FUNCTION__);
2944                 #endif
2945                 goto _err_exit;
2946         }
2947
2948         /* s3. Insert all packet into Reorder Queue to maintain its ordering. */
2949         if(!enqueue_reorder_recvframe(preorder_ctrl, prframe))
2950         {
2951                 /* DbgPrint("recv_indicatepkt_reorder, enqueue_reorder_recvframe fail!\n"); */
2952                 /* _exit_critical_ex(&ppending_recvframe_queue->lock, &irql); */
2953                 /* return _FAIL; */
2954                 #ifdef DBG_RX_DROP_FRAME
2955                 DBG_8723A("DBG_RX_DROP_FRAME %s enqueue_reorder_recvframe fail\n", __FUNCTION__);
2956                 #endif
2957                 goto _err_exit;
2958         }
2959
2960         /* s4. */
2961         /*  Indication process. */
2962         /*  After Packet dropping and Sliding Window shifting as above, we can now just indicate the packets */
2963         /*  with the SeqNum smaller than latest WinStart and buffer other packets. */
2964         /*  */
2965         /*  For Rx Reorder condition: */
2966         /*  1. All packets with SeqNum smaller than WinStart => Indicate */
2967         /*  2. All packets with SeqNum larger than or equal to WinStart => Buffer it. */
2968         /*  */
2969
2970         /* recv_indicatepkts_in_order(padapter, preorder_ctrl, _TRUE); */
2971         if(recv_indicatepkts_in_order(padapter, preorder_ctrl, _FALSE)==_TRUE)
2972         {
2973                 _set_timer(&preorder_ctrl->reordering_ctrl_timer, REORDER_WAIT_TIME);
2974                 _exit_critical_bh(&ppending_recvframe_queue->lock, &irql);
2975         }
2976         else
2977         {
2978                 _exit_critical_bh(&ppending_recvframe_queue->lock, &irql);
2979                 _cancel_timer_ex(&preorder_ctrl->reordering_ctrl_timer);
2980         }
2981
2982 _success_exit:
2983
2984         return _SUCCESS;
2985
2986 _err_exit:
2987
2988         _exit_critical_bh(&ppending_recvframe_queue->lock, &irql);
2989
2990         return _FAIL;
2991 }
2992
2993 void rtw_reordering_ctrl_timeout_handler(void *pcontext)
2994 {
2995         _irqL irql;
2996         struct recv_reorder_ctrl *preorder_ctrl = (struct recv_reorder_ctrl *)pcontext;
2997         _adapter *padapter = preorder_ctrl->padapter;
2998         _queue *ppending_recvframe_queue = &preorder_ctrl->pending_recvframe_queue;
2999
3000         if(padapter->bDriverStopped ||padapter->bSurpriseRemoved)
3001         {
3002                 return;
3003         }
3004
3005         /* DBG_8723A("+rtw_reordering_ctrl_timeout_handler()=>\n"); */
3006
3007         _enter_critical_bh(&ppending_recvframe_queue->lock, &irql);
3008
3009         if(recv_indicatepkts_in_order(padapter, preorder_ctrl, _TRUE)==_TRUE)
3010         {
3011                 _set_timer(&preorder_ctrl->reordering_ctrl_timer, REORDER_WAIT_TIME);
3012         }
3013
3014         _exit_critical_bh(&ppending_recvframe_queue->lock, &irql);
3015 }
3016
3017 int process_recv_indicatepkts(_adapter *padapter, union recv_frame *prframe);
3018 int process_recv_indicatepkts(_adapter *padapter, union recv_frame *prframe)
3019 {
3020         int retval = _SUCCESS;
3021         /* struct recv_priv *precvpriv = &padapter->recvpriv; */
3022         /* struct rx_pkt_attrib *pattrib = &prframe->u.hdr.attrib; */
3023         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
3024 #ifdef CONFIG_TDLS
3025         struct sta_info *psta = prframe->u.hdr.psta;
3026 #endif /* CONFIG_TDLS */
3027
3028 #ifdef CONFIG_80211N_HT
3029
3030         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
3031
3032 #ifdef CONFIG_TDLS
3033         if( (phtpriv->ht_option==_TRUE) ||
3034                 ((psta->tdls_sta_state & TDLS_LINKED_STATE) &&
3035                  (psta->htpriv.ht_option==_TRUE) &&
3036                  (psta->htpriv.ampdu_enable==_TRUE))) /* B/G/N Mode */
3037 #else
3038         if(phtpriv->ht_option==_TRUE)  /* B/G/N Mode */
3039 #endif /* CONFIG_TDLS */
3040         {
3041                 /* prframe->u.hdr.preorder_ctrl = &precvpriv->recvreorder_ctrl[pattrib->priority]; */
3042
3043                 if(recv_indicatepkt_reorder(padapter, prframe)!=_SUCCESS)/*  including perform A-MPDU Rx Ordering Buffer Control */
3044                 {
3045                         #ifdef DBG_RX_DROP_FRAME
3046                         DBG_8723A("DBG_RX_DROP_FRAME %s recv_indicatepkt_reorder error!\n", __FUNCTION__);
3047                         #endif
3048
3049                         if ((padapter->bDriverStopped == _FALSE) &&
3050                             (padapter->bSurpriseRemoved == _FALSE))
3051                         {
3052                                 retval = _FAIL;
3053                                 return retval;
3054                         }
3055                 }
3056         }
3057         else /* B/G mode */
3058 #endif
3059         {
3060                 retval=wlanhdr_to_ethhdr (prframe);
3061                 if(retval != _SUCCESS)
3062                 {
3063                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("wlanhdr_to_ethhdr: drop pkt \n"));
3064                         #ifdef DBG_RX_DROP_FRAME
3065                         DBG_8723A("DBG_RX_DROP_FRAME %s wlanhdr_to_ethhdr error!\n", __FUNCTION__);
3066                         #endif
3067                         return retval;
3068                 }
3069
3070                 if ((padapter->bDriverStopped ==_FALSE)&&( padapter->bSurpriseRemoved==_FALSE))
3071                 {
3072                         /* indicate this recv_frame */
3073                         RT_TRACE(_module_rtl871x_recv_c_, _drv_notice_, ("@@@@ process_recv_indicatepkts- recv_func recv_indicatepkt\n" ));
3074                         rtw_recv_indicatepkt(padapter, prframe);
3075
3076                 }
3077                 else
3078                 {
3079                         RT_TRACE(_module_rtl871x_recv_c_, _drv_notice_, ("@@@@ process_recv_indicatepkts- recv_func free_indicatepkt\n" ));
3080
3081                         RT_TRACE(_module_rtl871x_recv_c_, _drv_notice_, ("recv_func:bDriverStopped(%d) OR bSurpriseRemoved(%d)", padapter->bDriverStopped, padapter->bSurpriseRemoved));
3082                         retval = _FAIL;
3083                         return retval;
3084                 }
3085
3086         }
3087
3088         return retval;
3089 }
3090
3091 int recv_func_prehandle(_adapter *padapter, union recv_frame *rframe)
3092 {
3093         int ret = _SUCCESS;
3094         struct rx_pkt_attrib *pattrib = &rframe->u.hdr.attrib;
3095         struct recv_priv *precvpriv = &padapter->recvpriv;
3096         _queue *pfree_recv_queue = &padapter->recvpriv.free_recv_queue;
3097
3098         /* check the frame crtl field and decache */
3099         ret = validate_recv_frame(padapter, rframe);
3100         if (ret != _SUCCESS)
3101         {
3102                 RT_TRACE(_module_rtl871x_recv_c_, _drv_info_, ("recv_func: validate_recv_frame fail! drop pkt\n"));
3103                 rtw_free_recvframe(rframe, pfree_recv_queue);/* free this recv_frame */
3104                 goto exit;
3105         }
3106
3107 exit:
3108         return ret;
3109 }
3110
3111 int recv_func_posthandle(_adapter *padapter, union recv_frame *prframe)
3112 {
3113         int ret = _SUCCESS;
3114         union recv_frame *orig_prframe = prframe;
3115         struct rx_pkt_attrib *pattrib = &prframe->u.hdr.attrib;
3116         struct recv_priv *precvpriv = &padapter->recvpriv;
3117         _queue *pfree_recv_queue = &padapter->recvpriv.free_recv_queue;
3118
3119 #ifdef CONFIG_TDLS
3120         u8 *psnap_type, *pcategory;
3121         struct sta_info *ptdls_sta = NULL;
3122 #endif /* CONFIG_TDLS */
3123
3124         /*  DATA FRAME */
3125         rtw_led_control(padapter, LED_CTL_RX);
3126
3127         prframe = decryptor(padapter, prframe);
3128         if (prframe == NULL) {
3129                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("decryptor: drop pkt\n"));
3130                 #ifdef DBG_RX_DROP_FRAME
3131                 DBG_8723A("DBG_RX_DROP_FRAME %s decryptor: drop pkt\n", __FUNCTION__);
3132                 #endif
3133                 ret = _FAIL;
3134                 goto _recv_data_drop;
3135         }
3136
3137 #ifdef CONFIG_TDLS
3138         /* check TDLS frame */
3139         psnap_type = get_recvframe_data(orig_prframe);
3140         psnap_type+=pattrib->hdrlen + pattrib->iv_len+SNAP_SIZE;
3141         pcategory = psnap_type + ETH_TYPE_LEN + PAYLOAD_TYPE_LEN;
3142
3143         if((_rtw_memcmp(psnap_type, SNAP_ETH_TYPE_TDLS, ETH_TYPE_LEN)) &&
3144                 ((*pcategory==RTW_WLAN_CATEGORY_TDLS) || (*pcategory==RTW_WLAN_CATEGORY_P2P))){
3145                 ret = OnTDLS(padapter, prframe);        /* all of functions will return _FAIL */
3146                 goto _exit_recv_func;
3147         }
3148 #endif /* CONFIG_TDLS */
3149
3150         prframe = recvframe_chk_defrag(padapter, prframe);
3151         if(prframe==NULL)       {
3152                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("recvframe_chk_defrag: drop pkt\n"));
3153                 #ifdef DBG_RX_DROP_FRAME
3154                 DBG_8723A("DBG_RX_DROP_FRAME %s recvframe_chk_defrag: drop pkt\n", __FUNCTION__);
3155                 #endif
3156                 goto _recv_data_drop;
3157         }
3158
3159         prframe=portctrl(padapter, prframe);
3160         if (prframe == NULL) {
3161                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("portctrl: drop pkt \n"));
3162                 #ifdef DBG_RX_DROP_FRAME
3163                 DBG_8723A("DBG_RX_DROP_FRAME %s portctrl: drop pkt\n", __FUNCTION__);
3164                 #endif
3165                 ret = _FAIL;
3166                 goto _recv_data_drop;
3167         }
3168
3169 #ifdef CONFIG_TDLS
3170         if(padapter->tdlsinfo.setup_state == TDLS_LINKED_STATE)
3171                 ptdls_sta = rtw_get_stainfo(&padapter->stapriv, pattrib->src);
3172         count_rx_stats(padapter, prframe, ptdls_sta);
3173 #else
3174         count_rx_stats(padapter, prframe, NULL);
3175 #endif /* CONFIG_TDLS */
3176
3177 #ifdef CONFIG_WAPI_SUPPORT
3178         rtw_wapi_update_info(padapter, prframe);
3179 #endif
3180
3181 #ifdef CONFIG_80211N_HT
3182         ret = process_recv_indicatepkts(padapter, prframe);
3183         if (ret != _SUCCESS)
3184         {
3185                 RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("recv_func: process_recv_indicatepkts fail! \n"));
3186                 #ifdef DBG_RX_DROP_FRAME
3187                 DBG_8723A("DBG_RX_DROP_FRAME %s process_recv_indicatepkts fail!\n", __FUNCTION__);
3188                 #endif
3189                 rtw_free_recvframe(orig_prframe, pfree_recv_queue);/* free this recv_frame */
3190                 goto _recv_data_drop;
3191         }
3192 #else /*  CONFIG_80211N_HT */
3193         if (!pattrib->amsdu)
3194         {
3195                 ret = wlanhdr_to_ethhdr (prframe);
3196                 if (ret != _SUCCESS)
3197                 {
3198                         RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("wlanhdr_to_ethhdr: drop pkt \n"));
3199                         #ifdef DBG_RX_DROP_FRAME
3200                         DBG_8723A("DBG_RX_DROP_FRAME %s wlanhdr_to_ethhdr: drop pkt\n", __FUNCTION__);
3201                         #endif
3202                         rtw_free_recvframe(orig_prframe, pfree_recv_queue);/* free this recv_frame */
3203                         goto _recv_data_drop;
3204                 }
3205
3206                 if ((padapter->bDriverStopped == _FALSE) && (padapter->bSurpriseRemoved == _FALSE))
3207                 {
3208                         RT_TRACE(_module_rtl871x_recv_c_, _drv_alert_, ("@@@@ recv_func: recv_func rtw_recv_indicatepkt\n" ));
3209                         /* indicate this recv_frame */
3210                         ret = rtw_recv_indicatepkt(padapter, prframe);
3211                         if (ret != _SUCCESS)
3212                         {
3213                                 #ifdef DBG_RX_DROP_FRAME
3214                                 DBG_8723A("DBG_RX_DROP_FRAME %s rtw_recv_indicatepkt fail!\n", __FUNCTION__);
3215                                 #endif
3216                                 goto _recv_data_drop;
3217                         }
3218                 }
3219                 else
3220                 {
3221                         RT_TRACE(_module_rtl871x_recv_c_, _drv_alert_, ("@@@@  recv_func: rtw_free_recvframe\n" ));
3222                         RT_TRACE(_module_rtl871x_recv_c_, _drv_debug_, ("recv_func:bDriverStopped(%d) OR bSurpriseRemoved(%d)", padapter->bDriverStopped, padapter->bSurpriseRemoved));
3223                         #ifdef DBG_RX_DROP_FRAME
3224                         DBG_8723A("DBG_RX_DROP_FRAME %s ecv_func:bDriverStopped(%d) OR bSurpriseRemoved(%d)\n", __FUNCTION__,
3225                                 padapter->bDriverStopped, padapter->bSurpriseRemoved);
3226                         #endif
3227                         ret = _FAIL;
3228                         rtw_free_recvframe(orig_prframe, pfree_recv_queue); /* free this recv_frame */
3229                 }
3230
3231         }
3232         else if(pattrib->amsdu==1)
3233         {
3234
3235                 ret = amsdu_to_msdu(padapter, prframe);
3236                 if(ret != _SUCCESS)
3237                 {
3238                         #ifdef DBG_RX_DROP_FRAME
3239                         DBG_8723A("DBG_RX_DROP_FRAME %s amsdu_to_msdu fail\n", __FUNCTION__);
3240                         #endif
3241                         rtw_free_recvframe(orig_prframe, pfree_recv_queue);
3242                         goto _recv_data_drop;
3243                 }
3244         }
3245         else
3246         {
3247                 #ifdef DBG_RX_DROP_FRAME
3248                 DBG_8723A("DBG_RX_DROP_FRAME %s what is this condition??\n", __FUNCTION__);
3249                 #endif
3250                 goto _recv_data_drop;
3251         }
3252 #endif /*  CONFIG_80211N_HT */
3253
3254 _exit_recv_func:
3255         return ret;
3256
3257 _recv_data_drop:
3258         precvpriv->rx_drop++;
3259         return ret;
3260 }
3261
3262 int recv_func(_adapter *padapter, union recv_frame *rframe);
3263 int recv_func(_adapter *padapter, union recv_frame *rframe)
3264 {
3265         int ret;
3266         struct rx_pkt_attrib *prxattrib = &rframe->u.hdr.attrib;
3267         struct recv_priv *recvpriv = &padapter->recvpriv;
3268         struct security_priv *psecuritypriv=&padapter->securitypriv;
3269         struct mlme_priv *mlmepriv = &padapter->mlmepriv;
3270
3271         /* check if need to handle uc_swdec_pending_queue*/
3272         if (check_fwstate(mlmepriv, WIFI_STATION_STATE) && psecuritypriv->busetkipkey)
3273         {
3274                 union recv_frame *pending_frame;
3275                 _irqL irqL;
3276
3277                 while((pending_frame=rtw_alloc_recvframe(&padapter->recvpriv.uc_swdec_pending_queue))) {
3278                         if (recv_func_posthandle(padapter, pending_frame) == _SUCCESS)
3279                                 DBG_8723A("%s: dequeue uc_swdec_pending_queue\n", __func__);
3280                 }
3281         }
3282
3283         ret = recv_func_prehandle(padapter, rframe);
3284
3285         if(ret == _SUCCESS) {
3286
3287                 /* check if need to enqueue into uc_swdec_pending_queue*/
3288                 if (check_fwstate(mlmepriv, WIFI_STATION_STATE) &&
3289                         !IS_MCAST(prxattrib->ra) && prxattrib->encrypt>0 &&
3290                         (prxattrib->bdecrypted == 0 ||psecuritypriv->sw_decrypt == _TRUE) &&
3291                         !is_wep_enc(psecuritypriv->dot11PrivacyAlgrthm) &&
3292                         !psecuritypriv->busetkipkey) {
3293                         rtw_enqueue_recvframe(rframe, &padapter->recvpriv.uc_swdec_pending_queue);
3294                         DBG_8723A("%s: no key, enqueue uc_swdec_pending_queue\n", __func__);
3295                         goto exit;
3296                 }
3297
3298                 ret = recv_func_posthandle(padapter, rframe);
3299         }
3300
3301 exit:
3302         return ret;
3303 }
3304
3305 s32 rtw_recv_entry(union recv_frame *precvframe)
3306 {
3307         _adapter *padapter;
3308         struct recv_priv *precvpriv;
3309         s32 ret=_SUCCESS;
3310
3311 _func_enter_;
3312
3313 /*      RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("+rtw_recv_entry\n")); */
3314
3315         padapter = precvframe->u.hdr.adapter;
3316
3317         precvpriv = &padapter->recvpriv;
3318
3319         if ((ret = recv_func(padapter, precvframe)) == _FAIL)
3320         {
3321                 RT_TRACE(_module_rtl871x_recv_c_,_drv_info_,("rtw_recv_entry: recv_func return fail!!!\n"));
3322                 goto _recv_entry_drop;
3323         }
3324
3325         precvpriv->rx_pkts++;
3326
3327 _func_exit_;
3328
3329         return ret;
3330
3331 _recv_entry_drop:
3332
3333         /* RT_TRACE(_module_rtl871x_recv_c_,_drv_err_,("_recv_entry_drop\n")); */
3334
3335 _func_exit_;
3336
3337         return ret;
3338 }
3339
3340 #ifdef CONFIG_NEW_SIGNAL_STAT_PROCESS
3341 void rtw_signal_stat_timer_hdl(RTW_TIMER_HDL_ARGS){
3342         _adapter *adapter = (_adapter *)FunctionContext;
3343         struct recv_priv *recvpriv = &adapter->recvpriv;
3344
3345         u32 tmp_s, tmp_q;
3346         u8 avg_signal_strength = 0;
3347         u8 avg_signal_qual = 0;
3348         u32 num_signal_strength = 0;
3349         u32 num_signal_qual = 0;
3350         u8 _alpha = 3; /*  this value is based on converging_constant = 5000 and sampling_interval = 1000 */
3351
3352         if(adapter->recvpriv.is_signal_dbg) {
3353                 /* update the user specific value, signal_strength_dbg, to signal_strength, rssi */
3354                 adapter->recvpriv.signal_strength= adapter->recvpriv.signal_strength_dbg;
3355                 adapter->recvpriv.rssi=(s8)translate_percentage_to_dbm((u8)adapter->recvpriv.signal_strength_dbg);
3356         } else {
3357
3358                 if(recvpriv->signal_strength_data.update_req == 0) {/*  update_req is clear, means we got rx */
3359                         avg_signal_strength = recvpriv->signal_strength_data.avg_val;
3360                         num_signal_strength = recvpriv->signal_strength_data.total_num;
3361                         /*  after avg_vals are accquired, we can re-stat the signal values */
3362                         recvpriv->signal_strength_data.update_req = 1;
3363                 }
3364
3365                 if(recvpriv->signal_qual_data.update_req == 0) {/*  update_req is clear, means we got rx */
3366                         avg_signal_qual = recvpriv->signal_qual_data.avg_val;
3367                         num_signal_qual = recvpriv->signal_qual_data.total_num;
3368                         /*  after avg_vals are accquired, we can re-stat the signal values */
3369                         recvpriv->signal_qual_data.update_req = 1;
3370                 }
3371
3372                 /* update value of signal_strength, rssi, signal_qual */
3373                 if(check_fwstate(&adapter->mlmepriv, _FW_UNDER_SURVEY) == _FALSE) {
3374                         tmp_s = (avg_signal_strength+(_alpha-1)*recvpriv->signal_strength);
3375                         if(tmp_s %_alpha)
3376                                 tmp_s = tmp_s/_alpha + 1;
3377                         else
3378                                 tmp_s = tmp_s/_alpha;
3379                         if(tmp_s>100)
3380                                 tmp_s = 100;
3381
3382                         tmp_q = (avg_signal_qual+(_alpha-1)*recvpriv->signal_qual);
3383                         if(tmp_q %_alpha)
3384                                 tmp_q = tmp_q/_alpha + 1;
3385                         else
3386                                 tmp_q = tmp_q/_alpha;
3387                         if(tmp_q>100)
3388                                 tmp_q = 100;
3389
3390                         recvpriv->signal_strength = tmp_s;
3391                         recvpriv->rssi = (s8)translate_percentage_to_dbm(tmp_s);
3392                         recvpriv->signal_qual = tmp_q;
3393
3394                         #if defined(DBG_RX_SIGNAL_DISPLAY_PROCESSING) && 1
3395                         DBG_8723A("%s signal_strength:%3u, rssi:%3d, signal_qual:%3u"
3396                                 ", num_signal_strength:%u, num_signal_qual:%u"
3397                                 "\n"
3398                                 , __FUNCTION__
3399                                 , recvpriv->signal_strength
3400                                 , recvpriv->rssi
3401                                 , recvpriv->signal_qual
3402                                 , num_signal_strength, num_signal_qual
3403                         );
3404                         #endif
3405                 }
3406         }
3407         rtw_set_signal_stat_timer(recvpriv);
3408 }
3409 #endif /* CONFIG_NEW_SIGNAL_STAT_PROCESS */