OSDN Git Service

staging: rtl8723bs: update to the latest driver
[android-x86/kernel.git] / drivers / staging / rtl8723bs / core / rtw_mlme.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  ******************************************************************************/
15 #define _RTW_MLME_C_
16
17 #include <drv_types.h>
18 #include <rtw_debug.h>
19 #include <linux/jiffies.h>
20
21 extern u8 rtw_do_join(struct adapter *padapter);
22
23 sint    _rtw_init_mlme_priv (struct adapter *padapter)
24 {
25         sint    i;
26         u8 *pbuf;
27         struct wlan_network     *pnetwork;
28         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
29         sint    res = _SUCCESS;
30
31         /*  We don't need to memset padapter->XXX to zero, because adapter is allocated by vzalloc(). */
32         /* memset((u8 *)pmlmepriv, 0, sizeof(struct mlme_priv)); */
33
34         pmlmepriv->nic_hdl = (u8 *)padapter;
35
36         pmlmepriv->pscanned = NULL;
37         pmlmepriv->fw_state = WIFI_STATION_STATE; /*  Must sync with rtw_wdev_alloc() */
38                                                   /*  wdev->iftype = NL80211_IFTYPE_STATION */
39         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
40         pmlmepriv->scan_mode =SCAN_ACTIVE;/*  1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff) */
41
42         spin_lock_init(&(pmlmepriv->lock));
43         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
44         _rtw_init_queue(&(pmlmepriv->scanned_queue));
45
46         set_scanned_network_val(pmlmepriv, 0);
47
48         memset(&pmlmepriv->assoc_ssid, 0, sizeof(struct ndis_802_11_ssid));
49
50         pbuf = vzalloc(MAX_BSS_CNT * (sizeof(struct wlan_network)));
51
52         if (pbuf == NULL) {
53                 res = _FAIL;
54                 goto exit;
55         }
56         pmlmepriv->free_bss_buf = pbuf;
57
58         pnetwork = (struct wlan_network *)pbuf;
59
60         for (i = 0; i < MAX_BSS_CNT; i++)
61         {
62                 INIT_LIST_HEAD(&(pnetwork->list));
63
64                 list_add_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
65
66                 pnetwork++;
67         }
68
69         /* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
70
71         rtw_clear_scan_deny(padapter);
72
73         #define RTW_ROAM_SCAN_RESULT_EXP_MS 5*1000
74         #define RTW_ROAM_RSSI_DIFF_TH 10
75         #define RTW_ROAM_SCAN_INTERVAL_MS 10*1000
76
77         pmlmepriv->roam_flags = 0
78                 | RTW_ROAM_ON_EXPIRED
79                 | RTW_ROAM_ON_RESUME
80                 #ifdef CONFIG_LAYER2_ROAMING_ACTIVE /* FIXME */
81                 | RTW_ROAM_ACTIVE
82                 #endif
83                 ;
84
85         pmlmepriv->roam_scanr_exp_ms = RTW_ROAM_SCAN_RESULT_EXP_MS;
86         pmlmepriv->roam_rssi_diff_th = RTW_ROAM_RSSI_DIFF_TH;
87         pmlmepriv->roam_scan_int_ms = RTW_ROAM_SCAN_INTERVAL_MS;
88
89         rtw_init_mlme_timer(padapter);
90
91 exit:
92
93         return res;
94 }
95
96 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
97 {
98         if (*ppie)
99         {
100                 kfree(*ppie);
101                 *plen = 0;
102                 *ppie = NULL;
103         }
104 }
105
106 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
107 {
108         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
109         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
110         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
111         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
112         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
113         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
114
115         rtw_free_mlme_ie_data(&pmlmepriv->p2p_beacon_ie, &pmlmepriv->p2p_beacon_ie_len);
116         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_req_ie, &pmlmepriv->p2p_probe_req_ie_len);
117         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_resp_ie, &pmlmepriv->p2p_probe_resp_ie_len);
118         rtw_free_mlme_ie_data(&pmlmepriv->p2p_go_probe_resp_ie, &pmlmepriv->p2p_go_probe_resp_ie_len);
119         rtw_free_mlme_ie_data(&pmlmepriv->p2p_assoc_req_ie, &pmlmepriv->p2p_assoc_req_ie_len);
120 }
121
122 void _rtw_free_mlme_priv (struct mlme_priv *pmlmepriv)
123 {
124         rtw_free_mlme_priv_ie_data(pmlmepriv);
125
126         if (pmlmepriv) {
127                 if (pmlmepriv->free_bss_buf) {
128                         vfree(pmlmepriv->free_bss_buf);
129                 }
130         }
131 }
132
133 /*
134 struct  wlan_network *_rtw_dequeue_network(struct __queue *queue)
135 {
136         _irqL irqL;
137
138         struct wlan_network *pnetwork;
139
140         spin_lock_bh(&queue->lock);
141
142         if (list_empty(&queue->queue))
143
144                 pnetwork = NULL;
145
146         else
147         {
148                 pnetwork = LIST_CONTAINOR(get_next(&queue->queue), struct wlan_network, list);
149
150                 list_del_init(&(pnetwork->list));
151         }
152
153         spin_unlock_bh(&queue->lock);
154
155         return pnetwork;
156 }
157 */
158
159 struct  wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv)/* _queue *free_queue) */
160 {
161         struct  wlan_network    *pnetwork;
162         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
163         struct list_head* plist = NULL;
164
165         spin_lock_bh(&free_queue->lock);
166
167         if (list_empty(&free_queue->queue)) {
168                 pnetwork = NULL;
169                 goto exit;
170         }
171         plist = get_next(&(free_queue->queue));
172
173         pnetwork = LIST_CONTAINOR(plist , struct wlan_network, list);
174
175         list_del_init(&pnetwork->list);
176
177         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("_rtw_alloc_network: ptr =%p\n", plist));
178         pnetwork->network_type = 0;
179         pnetwork->fixed = false;
180         pnetwork->last_scanned = jiffies;
181         pnetwork->aid = 0;
182         pnetwork->join_res = 0;
183
184         pmlmepriv->num_of_scanned ++;
185
186 exit:
187         spin_unlock_bh(&free_queue->lock);
188
189         return pnetwork;
190 }
191
192 void _rtw_free_network(struct   mlme_priv *pmlmepriv , struct wlan_network *pnetwork, u8 isfreeall)
193 {
194         unsigned int delta_time;
195         u32 lifetime = SCANQUEUE_LIFETIME;
196 /*      _irqL irqL; */
197         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
198
199         if (pnetwork == NULL)
200                 return;
201
202         if (pnetwork->fixed == true)
203                 return;
204
205         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ==true) ||
206                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) ==true))
207                 lifetime = 1;
208
209         if (!isfreeall)
210         {
211                 delta_time = jiffies_to_msecs(jiffies - pnetwork->last_scanned);
212                 if (delta_time < lifetime)/*  unit:msec */
213                         return;
214         }
215
216         spin_lock_bh(&free_queue->lock);
217
218         list_del_init(&(pnetwork->list));
219
220         list_add_tail(&(pnetwork->list),&(free_queue->queue));
221
222         pmlmepriv->num_of_scanned --;
223
224
225         /* DBG_871X("_rtw_free_network:SSID =%s\n", pnetwork->network.Ssid.Ssid); */
226
227         spin_unlock_bh(&free_queue->lock);
228 }
229
230 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
231 {
232
233         struct __queue *free_queue = &(pmlmepriv->free_bss_pool);
234
235         if (pnetwork == NULL)
236                 return;
237
238         if (pnetwork->fixed == true)
239                 return;
240
241         /* spin_lock_irqsave(&free_queue->lock, irqL); */
242
243         list_del_init(&(pnetwork->list));
244
245         list_add_tail(&(pnetwork->list), get_list_head(free_queue));
246
247         pmlmepriv->num_of_scanned --;
248
249         /* spin_unlock_irqrestore(&free_queue->lock, irqL); */
250 }
251
252 /*
253         return the wlan_network with the matching addr
254
255         Shall be calle under atomic context... to avoid possible racing condition...
256 */
257 struct wlan_network *_rtw_find_network(struct __queue *scanned_queue, u8 *addr)
258 {
259         struct list_head        *phead, *plist;
260         struct  wlan_network *pnetwork = NULL;
261         u8 zero_addr[ETH_ALEN] = {0, 0, 0, 0, 0, 0};
262
263         if (!memcmp(zero_addr, addr, ETH_ALEN)) {
264                 pnetwork = NULL;
265                 goto exit;
266         }
267
268         /* spin_lock_bh(&scanned_queue->lock); */
269
270         phead = get_list_head(scanned_queue);
271         plist = get_next(phead);
272
273         while (plist != phead)
274        {
275                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network , list);
276
277                 if (!memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN))
278                         break;
279
280                 plist = get_next(plist);
281         }
282
283         if (plist == phead)
284                 pnetwork = NULL;
285
286         /* spin_unlock_bh(&scanned_queue->lock); */
287
288 exit:
289         return pnetwork;
290 }
291
292 void _rtw_free_network_queue(struct adapter *padapter, u8 isfreeall)
293 {
294         struct list_head *phead, *plist;
295         struct wlan_network *pnetwork;
296         struct mlme_priv* pmlmepriv = &padapter->mlmepriv;
297         struct __queue *scanned_queue = &pmlmepriv->scanned_queue;
298
299         spin_lock_bh(&scanned_queue->lock);
300
301         phead = get_list_head(scanned_queue);
302         plist = get_next(phead);
303
304         while (phead != plist)
305         {
306
307                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
308
309                 plist = get_next(plist);
310
311                 _rtw_free_network(pmlmepriv, pnetwork, isfreeall);
312
313         }
314
315         spin_unlock_bh(&scanned_queue->lock);
316 }
317
318
319
320
321 sint rtw_if_up(struct adapter *padapter)        {
322
323         sint res;
324
325         if (padapter->bDriverStopped || padapter->bSurpriseRemoved ||
326                 (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == false)) {
327                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)", padapter->bDriverStopped, padapter->bSurpriseRemoved));
328                 res =false;
329         }
330         else
331                 res =  true;
332         return res;
333 }
334
335
336 void rtw_generate_random_ibss(u8 *pibss)
337 {
338         unsigned long curtime = jiffies;
339
340         pibss[0] = 0x02;  /* in ad-hoc mode bit1 must set to 1 */
341         pibss[1] = 0x11;
342         pibss[2] = 0x87;
343         pibss[3] = (u8)(curtime & 0xff) ;/* p[0]; */
344         pibss[4] = (u8)((curtime>>8) & 0xff) ;/* p[1]; */
345         pibss[5] = (u8)((curtime>>16) & 0xff) ;/* p[2]; */
346         return;
347 }
348
349 u8 *rtw_get_capability_from_ie(u8 *ie)
350 {
351         return (ie + 8 + 2);
352 }
353
354
355 u16 rtw_get_capability(struct wlan_bssid_ex *bss)
356 {
357         __le16  val;
358
359         memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2);
360
361         return le16_to_cpu(val);
362 }
363
364 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
365 {
366         return (ie + 8);
367 }
368
369
370 int     rtw_init_mlme_priv (struct adapter *padapter)/* struct  mlme_priv *pmlmepriv) */
371 {
372         int     res;
373
374         res = _rtw_init_mlme_priv(padapter);/*  (pmlmepriv); */
375         return res;
376 }
377
378 void rtw_free_mlme_priv (struct mlme_priv *pmlmepriv)
379 {
380         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_mlme_priv\n"));
381         _rtw_free_mlme_priv (pmlmepriv);
382 }
383
384 /*
385 static struct   wlan_network *rtw_dequeue_network(struct __queue *queue)
386 {
387         struct wlan_network *pnetwork;
388
389         pnetwork = _rtw_dequeue_network(queue);
390         return pnetwork;
391 }
392 */
393
394 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv);
395 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv)/* _queue  *free_queue) */
396 {
397         struct  wlan_network    *pnetwork;
398
399         pnetwork = _rtw_alloc_network(pmlmepriv);
400         return pnetwork;
401 }
402
403 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork);
404 void rtw_free_network_nolock(struct adapter *padapter, struct wlan_network *pnetwork)
405 {
406         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_network ==> ssid = %s\n\n" , pnetwork->network.Ssid.Ssid)); */
407         _rtw_free_network_nolock(&(padapter->mlmepriv), pnetwork);
408         rtw_cfg80211_unlink_bss(padapter, pnetwork);
409 }
410
411
412 void rtw_free_network_queue(struct adapter * dev, u8 isfreeall)
413 {
414         _rtw_free_network_queue(dev, isfreeall);
415 }
416
417 /*
418         return the wlan_network with the matching addr
419
420         Shall be calle under atomic context... to avoid possible racing condition...
421 */
422 struct  wlan_network *rtw_find_network(struct __queue *scanned_queue, u8 *addr)
423 {
424         struct  wlan_network *pnetwork = _rtw_find_network(scanned_queue, addr);
425
426         return pnetwork;
427 }
428
429 int rtw_is_same_ibss(struct adapter *adapter, struct wlan_network *pnetwork)
430 {
431         int ret =true;
432         struct security_priv *psecuritypriv = &adapter->securitypriv;
433
434         if ((psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_) &&
435                     (pnetwork->network.Privacy == 0))
436         {
437                 ret =false;
438         }
439         else if ((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_) &&
440                  (pnetwork->network.Privacy == 1))
441         {
442                 ret =false;
443         }
444         else
445         {
446                 ret =true;
447         }
448
449         return ret;
450
451 }
452
453 inline int is_same_ess(struct wlan_bssid_ex *a, struct wlan_bssid_ex *b)
454 {
455         /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("(%s,%d)(%s,%d)\n", */
456         /*              a->Ssid.Ssid, a->Ssid.SsidLength, b->Ssid.Ssid, b->Ssid.SsidLength)); */
457         return (a->Ssid.SsidLength == b->Ssid.SsidLength)
458                 &&  !memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength);
459 }
460
461 int is_same_network(struct wlan_bssid_ex *src, struct wlan_bssid_ex *dst, u8 feature)
462 {
463         u16 s_cap, d_cap;
464         __le16 tmps, tmpd;
465
466         if (rtw_bug_check(dst, src, &s_cap, &d_cap) ==false)
467                         return false;
468
469         memcpy((u8 *)&tmps, rtw_get_capability_from_ie(src->IEs), 2);
470         memcpy((u8 *)&tmpd, rtw_get_capability_from_ie(dst->IEs), 2);
471
472
473         s_cap = le16_to_cpu(tmps);
474         d_cap = le16_to_cpu(tmpd);
475
476         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
477                 /*      (src->Configuration.DSConfig == dst->Configuration.DSConfig) && */
478                         ((!memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN))) &&
479                         ((!memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength))) &&
480                         ((s_cap & WLAN_CAPABILITY_IBSS) ==
481                         (d_cap & WLAN_CAPABILITY_IBSS)) &&
482                         ((s_cap & WLAN_CAPABILITY_BSS) ==
483                         (d_cap & WLAN_CAPABILITY_BSS)));
484
485 }
486
487 struct wlan_network *_rtw_find_same_network(struct __queue *scanned_queue, struct wlan_network *network)
488 {
489         struct list_head *phead, *plist;
490         struct wlan_network *found = NULL;
491
492         phead = get_list_head(scanned_queue);
493         plist = get_next(phead);
494
495         while (plist != phead) {
496                 found = LIST_CONTAINOR(plist, struct wlan_network , list);
497
498                 if (is_same_network(&network->network, &found->network, 0))
499                         break;
500
501                 plist = get_next(plist);
502         }
503
504         if (plist == phead)
505                 found = NULL;
506
507         return found;
508 }
509
510 struct  wlan_network    * rtw_get_oldest_wlan_network(struct __queue *scanned_queue)
511 {
512         struct list_head        *plist, *phead;
513
514
515         struct  wlan_network    *pwlan = NULL;
516         struct  wlan_network    *oldest = NULL;
517
518         phead = get_list_head(scanned_queue);
519
520         plist = get_next(phead);
521
522         while (1)
523         {
524
525                 if (phead == plist)
526                         break;
527
528                 pwlan = LIST_CONTAINOR(plist, struct wlan_network, list);
529
530                 if (pwlan->fixed!=true)
531                 {
532                         if (oldest == NULL ||time_after(oldest->last_scanned, pwlan->last_scanned))
533                                 oldest = pwlan;
534                 }
535
536                 plist = get_next(plist);
537         }
538         return oldest;
539
540 }
541
542 void update_network(struct wlan_bssid_ex *dst, struct wlan_bssid_ex *src,
543         struct adapter *padapter, bool update_ie)
544 {
545         long rssi_ori = dst->Rssi;
546
547         u8 sq_smp = src->PhyInfo.SignalQuality;
548
549         u8 ss_final;
550         u8 sq_final;
551         long rssi_final;
552
553         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
554         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
555                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT", ch%u) ss_ori:%3u, sq_ori:%3u, rssi_ori:%3ld, ss_smp:%3u, sq_smp:%3u, rssi_smp:%3ld\n"
556                         , FUNC_ADPT_ARG(padapter)
557                         , src->Ssid.Ssid, MAC_ARG(src->MacAddress), src->Configuration.DSConfig
558                         , ss_ori, sq_ori, rssi_ori
559                         , ss_smp, sq_smp, rssi_smp
560                 );
561         }
562         #endif
563
564         /* The rule below is 1/5 for sample value, 4/5 for history value */
565         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src, 0)) {
566                 /* Take the recvpriv's value for the connected AP*/
567                 ss_final = padapter->recvpriv.signal_strength;
568                 sq_final = padapter->recvpriv.signal_qual;
569                 /* the rssi value here is undecorated, and will be used for antenna diversity */
570                 if (sq_smp != 101) /* from the right channel */
571                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
572                 else
573                         rssi_final = rssi_ori;
574         }
575         else {
576                 if (sq_smp != 101) { /* from the right channel */
577                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
578                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
579                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
580                 } else {
581                         /* bss info not receving from the right channel, use the original RX signal infos */
582                         ss_final = dst->PhyInfo.SignalStrength;
583                         sq_final = dst->PhyInfo.SignalQuality;
584                         rssi_final = dst->Rssi;
585                 }
586
587         }
588
589         if (update_ie) {
590                 dst->Reserved[0] = src->Reserved[0];
591                 dst->Reserved[1] = src->Reserved[1];
592                 memcpy((u8 *)dst, (u8 *)src, get_wlan_bssid_ex_sz(src));
593         }
594
595         dst->PhyInfo.SignalStrength = ss_final;
596         dst->PhyInfo.SignalQuality = sq_final;
597         dst->Rssi = rssi_final;
598
599         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
600         if (strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
601                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT"), SignalStrength:%u, SignalQuality:%u, RawRSSI:%ld\n"
602                         , FUNC_ADPT_ARG(padapter)
603                         , dst->Ssid.Ssid, MAC_ARG(dst->MacAddress), dst->PhyInfo.SignalStrength, dst->PhyInfo.SignalQuality, dst->Rssi);
604         }
605         #endif
606 }
607
608 static void update_current_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
609 {
610         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
611
612         rtw_bug_check(&(pmlmepriv->cur_network.network),
613                 &(pmlmepriv->cur_network.network),
614                 &(pmlmepriv->cur_network.network),
615                 &(pmlmepriv->cur_network.network));
616
617         if ((check_fwstate(pmlmepriv, _FW_LINKED) == true) && (is_same_network(&(pmlmepriv->cur_network.network), pnetwork, 0)))
618         {
619                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"Same Network\n"); */
620
621                 /* if (pmlmepriv->cur_network.network.IELength<= pnetwork->IELength) */
622                 {
623                         update_network(&(pmlmepriv->cur_network.network), pnetwork, adapter, true);
624                         rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof (struct ndis_802_11_fix_ie),
625                                                                         pmlmepriv->cur_network.network.IELength);
626                 }
627         }
628 }
629
630
631 /*
632
633 Caller must hold pmlmepriv->lock first.
634
635
636 */
637 void rtw_update_scanned_network(struct adapter *adapter, struct wlan_bssid_ex *target)
638 {
639         struct list_head        *plist, *phead;
640         u32 bssid_ex_sz;
641         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
642         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
643         struct wlan_network     *pnetwork = NULL;
644         struct wlan_network     *oldest = NULL;
645         int target_find = 0;
646         u8 feature = 0;
647
648         spin_lock_bh(&queue->lock);
649         phead = get_list_head(queue);
650         plist = get_next(phead);
651
652         while (1)
653         {
654                 if (phead == plist)
655                         break;
656
657                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
658
659                 rtw_bug_check(pnetwork, pnetwork, pnetwork, pnetwork);
660
661                 if (is_same_network(&(pnetwork->network), target, feature))
662                 {
663                         target_find = 1;
664                         break;
665                 }
666
667                 if (rtw_roam_flags(adapter)) {
668                         /* TODO: don't  select netowrk in the same ess as oldest if it's new enough*/
669                 }
670
671                 if (oldest == NULL || time_after(oldest->last_scanned, pnetwork->last_scanned))
672                         oldest = pnetwork;
673
674                 plist = get_next(plist);
675
676         }
677
678
679         /* If we didn't find a match, then get a new network slot to initialize
680          * with this beacon's information */
681         /* if (phead == plist) { */
682         if (!target_find) {
683                 if (list_empty(&pmlmepriv->free_bss_pool.queue)) {
684                         /* If there are no more slots, expire the oldest */
685                         /* list_del_init(&oldest->list); */
686                         pnetwork = oldest;
687                         if (pnetwork == NULL) {
688                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
689                                 goto exit;
690                         }
691                         memcpy(&(pnetwork->network), target,  get_wlan_bssid_ex_sz(target));
692                         /*  variable initialize */
693                         pnetwork->fixed = false;
694                         pnetwork->last_scanned = jiffies;
695
696                         pnetwork->network_type = 0;
697                         pnetwork->aid = 0;
698                         pnetwork->join_res = 0;
699
700                         /* bss info not receving from the right channel */
701                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
702                                 pnetwork->network.PhyInfo.SignalQuality = 0;
703                 }
704                 else {
705                         /* Otherwise just pull from the free list */
706
707                         pnetwork = rtw_alloc_network(pmlmepriv); /*  will update scan_time */
708
709                         if (pnetwork == NULL) {
710                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n\nsomething wrong here\n\n\n"));
711                                 goto exit;
712                         }
713
714                         bssid_ex_sz = get_wlan_bssid_ex_sz(target);
715                         target->Length = bssid_ex_sz;
716                         memcpy(&(pnetwork->network), target, bssid_ex_sz);
717
718                         pnetwork->last_scanned = jiffies;
719
720                         /* bss info not receving from the right channel */
721                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
722                                 pnetwork->network.PhyInfo.SignalQuality = 0;
723
724                         list_add_tail(&(pnetwork->list),&(queue->queue));
725
726                 }
727         }
728         else {
729                 /* we have an entry and we are going to update it. But this entry may
730                  * be already expired. In this case we do the same as we found a new
731                  * net and call the new_net handler
732                  */
733                 bool update_ie = true;
734
735                 pnetwork->last_scanned = jiffies;
736
737                 /* target.Reserved[0]== 1, means that scaned network is a bcn frame. */
738                 if ((pnetwork->network.IELength>target->IELength) && (target->Reserved[0]== 1))
739                         update_ie = false;
740
741                 /*  probe resp(3) > beacon(1) > probe req(2) */
742                 if ((target->Reserved[0] != 2) &&
743                         (target->Reserved[0] >= pnetwork->network.Reserved[0])
744                         ) {
745                         update_ie = true;
746                 }
747                 else {
748                         update_ie = false;
749                 }
750
751                 update_network(&(pnetwork->network), target, adapter, update_ie);
752         }
753
754 exit:
755         spin_unlock_bh(&queue->lock);
756 }
757
758 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork);
759 void rtw_add_network(struct adapter *adapter, struct wlan_bssid_ex *pnetwork)
760 {
761         /* struct __queue       *queue  = &(pmlmepriv->scanned_queue); */
762
763         /* spin_lock_bh(&queue->lock); */
764
765         update_current_network(adapter, pnetwork);
766
767         rtw_update_scanned_network(adapter, pnetwork);
768
769         /* spin_unlock_bh(&queue->lock); */
770 }
771
772 /* select the desired network based on the capability of the (i)bss. */
773 /*  check items: (1) security */
774 /*                         (2) network_type */
775 /*                         (3) WMM */
776 /*                         (4) HT */
777 /*                      (5) others */
778 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork);
779 int rtw_is_desired_network(struct adapter *adapter, struct wlan_network *pnetwork)
780 {
781         struct security_priv *psecuritypriv = &adapter->securitypriv;
782         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
783         u32 desired_encmode;
784         u32 privacy;
785
786         /* u8 wps_ie[512]; */
787         uint wps_ielen;
788
789         int bselected = true;
790
791         desired_encmode = psecuritypriv->ndisencryptstatus;
792         privacy = pnetwork->network.Privacy;
793
794         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS))
795         {
796                 if (rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen)!= NULL)
797                 {
798                         return true;
799                 }
800                 else
801                 {
802                         return false;
803                 }
804         }
805         if (adapter->registrypriv.wifi_spec == 1) /* for  correct flow of 8021X  to do.... */
806         {
807                 u8 *p = NULL;
808                 uint ie_len = 0;
809
810                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
811                     bselected = false;
812
813                 if (psecuritypriv->ndisauthtype == Ndis802_11AuthModeWPA2PSK) {
814                         p = rtw_get_ie(pnetwork->network.IEs + _BEACON_IE_OFFSET_, _RSN_IE_2_, &ie_len, (pnetwork->network.IELength - _BEACON_IE_OFFSET_));
815                         if (p && ie_len>0) {
816                                 bselected = true;
817                         } else {
818                                 bselected = false;
819                         }
820                 }
821         }
822
823
824         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
825                 DBG_871X("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
826                 bselected = false;
827         }
828
829         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == true)
830         {
831                 if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
832                         bselected = false;
833         }
834
835
836         return bselected;
837 }
838
839 /* TODO: Perry : For Power Management */
840 void rtw_atimdone_event_callback(struct adapter *adapter , u8 *pbuf)
841 {
842         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("receive atimdone_evet\n"));
843 }
844
845
846 void rtw_survey_event_callback(struct adapter   *adapter, u8 *pbuf)
847 {
848         u32 len;
849         struct wlan_bssid_ex *pnetwork;
850         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
851
852         pnetwork = (struct wlan_bssid_ex *)pbuf;
853
854         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_survey_event_callback, ssid =%s\n",  pnetwork->Ssid.Ssid));
855
856         len = get_wlan_bssid_ex_sz(pnetwork);
857         if (len > (sizeof(struct wlan_bssid_ex)))
858         {
859                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n ****rtw_survey_event_callback: return a wrong bss ***\n"));
860                 return;
861         }
862
863
864         spin_lock_bh(&pmlmepriv->lock);
865
866         /*  update IBSS_network 's timestamp */
867         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == true)
868         {
869                 /* RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_,"rtw_survey_event_callback : WIFI_ADHOC_MASTER_STATE\n\n"); */
870                 if (!memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN))
871                 {
872                         struct wlan_network* ibss_wlan = NULL;
873
874                         memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
875                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
876                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
877                         if (ibss_wlan)
878                         {
879                                 memcpy(ibss_wlan->network.IEs , pnetwork->IEs, 8);
880                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
881                                 goto exit;
882                         }
883                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
884                 }
885         }
886
887         /*  lock pmlmepriv->lock when you accessing network_q */
888         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == false)
889         {
890                 if (pnetwork->Ssid.Ssid[0] == 0)
891                 {
892                         pnetwork->Ssid.SsidLength = 0;
893                 }
894                 rtw_add_network(adapter, pnetwork);
895         }
896
897 exit:
898
899         spin_unlock_bh(&pmlmepriv->lock);
900
901         return;
902 }
903
904
905
906 void rtw_surveydone_event_callback(struct adapter       *adapter, u8 *pbuf)
907 {
908         u8 timer_cancelled = false;
909         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
910
911         spin_lock_bh(&pmlmepriv->lock);
912         if (pmlmepriv->wps_probe_req_ie)
913         {
914                 pmlmepriv->wps_probe_req_ie_len = 0;
915                 kfree(pmlmepriv->wps_probe_req_ie);
916                 pmlmepriv->wps_probe_req_ie = NULL;
917         }
918
919         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
920
921         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY))
922         {
923                 /* u8 timer_cancelled; */
924
925                 timer_cancelled = true;
926                 /* _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled); */
927
928                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
929         }
930         else {
931
932                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("nic status =%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));
933         }
934         spin_unlock_bh(&pmlmepriv->lock);
935
936         if (timer_cancelled)
937                 _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
938
939
940         spin_lock_bh(&pmlmepriv->lock);
941
942         rtw_set_signal_stat_timer(&adapter->recvpriv);
943
944         if (pmlmepriv->to_join == true)
945         {
946                 if ((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) ==true))
947                 {
948                         if (check_fwstate(pmlmepriv, _FW_LINKED) ==false)
949                         {
950                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
951
952                                 if (rtw_select_and_join_from_scanned_queue(pmlmepriv) == _SUCCESS)
953                                 {
954                                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
955                                 }
956                                 else
957                                 {
958                                         struct wlan_bssid_ex    *pdev_network = &(adapter->registrypriv.dev_network);
959                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
960
961                                         /* pmlmepriv->fw_state ^= _FW_UNDER_SURVEY;because don't set assoc_timer */
962                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
963
964                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("switching to adhoc master\n"));
965
966                                         memset(&pdev_network->Ssid, 0, sizeof(struct ndis_802_11_ssid));
967                                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
968
969                                         rtw_update_registrypriv_dev_network(adapter);
970                                         rtw_generate_random_ibss(pibss);
971
972                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
973
974                                         if (rtw_createbss_cmd(adapter)!= _SUCCESS)
975                                         {
976                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error =>rtw_createbss_cmd status FAIL\n"));
977                                         }
978
979                                         pmlmepriv->to_join = false;
980                                 }
981                         }
982                 }
983                 else
984                 {
985                         int s_ret;
986                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
987                         pmlmepriv->to_join = false;
988                         if (_SUCCESS == (s_ret =rtw_select_and_join_from_scanned_queue(pmlmepriv)))
989                         {
990                              _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
991                         }
992                         else if (s_ret == 2)/* there is no need to wait for join */
993                         {
994                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
995                                 rtw_indicate_connect(adapter);
996                         }
997                         else
998                         {
999                                 DBG_871X("try_to_join, but select scanning queue fail, to_roam:%d\n", rtw_to_roam(adapter));
1000
1001                                 if (rtw_to_roam(adapter) != 0) {
1002                                         if (rtw_dec_to_roam(adapter) == 0
1003                                                 || _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)
1004                                         ) {
1005                                                 rtw_set_to_roam(adapter, 0);
1006 #ifdef CONFIG_INTEL_WIDI
1007                                                 if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING)
1008                                                 {
1009                                                         memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1010                                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1011                                                         DBG_871X("change to widi listen\n");
1012                                                 }
1013 #endif /*  CONFIG_INTEL_WIDI */
1014                                                 rtw_free_assoc_resources(adapter, 1);
1015                                                 rtw_indicate_disconnect(adapter);
1016                                         } else {
1017                                                 pmlmepriv->to_join = true;
1018                                         }
1019                                 }
1020                                 else
1021                                 {
1022                                         rtw_indicate_disconnect(adapter);
1023                                 }
1024                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1025                         }
1026                 }
1027         } else {
1028                 if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1029                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)
1030                                 && check_fwstate(pmlmepriv, _FW_LINKED))
1031                         {
1032                                 if (rtw_select_roaming_candidate(pmlmepriv) == _SUCCESS) {
1033                                         receive_disconnect(adapter, pmlmepriv->cur_network.network.MacAddress
1034                                                 , WLAN_REASON_ACTIVE_ROAM);
1035                                 }
1036                         }
1037                 }
1038         }
1039
1040         /* DBG_871X("scan complete in %dms\n", jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time)); */
1041
1042         spin_unlock_bh(&pmlmepriv->lock);
1043
1044         rtw_os_xmit_schedule(adapter);
1045
1046         rtw_cfg80211_surveydone_event_callback(adapter);
1047
1048         rtw_indicate_scan_done(adapter, false);
1049 }
1050
1051 void rtw_dummy_event_callback(struct adapter *adapter , u8 *pbuf)
1052 {
1053 }
1054
1055 void rtw_fwdbg_event_callback(struct adapter *adapter , u8 *pbuf)
1056 {
1057 }
1058
1059 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
1060 {
1061         struct __queue *free_queue = &pmlmepriv->free_bss_pool;
1062         struct __queue *scan_queue = &pmlmepriv->scanned_queue;
1063         struct list_head        *plist, *phead, *ptemp;
1064
1065         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
1066         spin_lock_bh(&scan_queue->lock);
1067         spin_lock_bh(&free_queue->lock);
1068
1069         phead = get_list_head(scan_queue);
1070         plist = get_next(phead);
1071
1072         while (plist != phead)
1073        {
1074                 ptemp = get_next(plist);
1075                 list_del_init(plist);
1076                 list_add_tail(plist, &free_queue->queue);
1077                 plist =ptemp;
1078                 pmlmepriv->num_of_scanned --;
1079         }
1080
1081         spin_unlock_bh(&free_queue->lock);
1082         spin_unlock_bh(&scan_queue->lock);
1083 }
1084
1085 static void rtw_reset_rx_info(struct debug_priv *pdbgpriv)
1086 {
1087         pdbgpriv->dbg_rx_ampdu_drop_count = 0;
1088         pdbgpriv->dbg_rx_ampdu_forced_indicate_count = 0;
1089         pdbgpriv->dbg_rx_ampdu_loss_count = 0;
1090         pdbgpriv->dbg_rx_dup_mgt_frame_drop_count = 0;
1091         pdbgpriv->dbg_rx_ampdu_window_shift_cnt = 0;
1092 }
1093
1094 static void find_network(struct adapter *adapter)
1095 {
1096         struct wlan_network* pwlan = NULL;
1097         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1098         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1099
1100         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1101         if (pwlan)
1102                 pwlan->fixed = false;
1103         else
1104                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_free_assoc_resources : pwlan == NULL\n\n"));
1105
1106
1107         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) &&
1108             (adapter->stapriv.asoc_sta_count == 1))
1109                 rtw_free_network_nolock(adapter, pwlan);
1110 }
1111
1112 /*
1113 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
1114 */
1115 void rtw_free_assoc_resources(struct adapter *adapter, int lock_scanned_queue)
1116 {
1117         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1118         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1119         struct  sta_priv *pstapriv = &adapter->stapriv;
1120         struct dvobj_priv *psdpriv = adapter->dvobj;
1121         struct debug_priv *pdbgpriv = &psdpriv->drv_dbg;
1122
1123         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
1124         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("tgt_network->network.MacAddress ="MAC_FMT" ssid =%s\n",
1125                 MAC_ARG(tgt_network->network.MacAddress), tgt_network->network.Ssid.Ssid));
1126
1127         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_AP_STATE))
1128         {
1129                 struct sta_info* psta;
1130
1131                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
1132                 spin_lock_bh(&(pstapriv->sta_hash_lock));
1133                 rtw_free_stainfo(adapter,  psta);
1134
1135                 spin_unlock_bh(&(pstapriv->sta_hash_lock));
1136
1137         }
1138
1139         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE|WIFI_AP_STATE))
1140         {
1141                 struct sta_info* psta;
1142
1143                 rtw_free_all_stainfo(adapter);
1144
1145                 psta = rtw_get_bcmc_stainfo(adapter);
1146                 rtw_free_stainfo(adapter, psta);
1147
1148                 rtw_init_bcmc_stainfo(adapter);
1149         }
1150
1151         if (lock_scanned_queue) {
1152                 find_network(adapter);
1153         } else {
1154                 find_network(adapter);
1155         }
1156
1157         if (lock_scanned_queue)
1158
1159         adapter->securitypriv.key_mask = 0;
1160
1161         rtw_reset_rx_info(pdbgpriv);
1162 }
1163
1164 /*
1165 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
1166 */
1167 void rtw_indicate_connect(struct adapter *padapter)
1168 {
1169         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1170
1171         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
1172
1173         pmlmepriv->to_join = false;
1174
1175         if (!check_fwstate(&padapter->mlmepriv, _FW_LINKED))
1176         {
1177
1178                 set_fwstate(pmlmepriv, _FW_LINKED);
1179
1180                 rtw_os_indicate_connect(padapter);
1181         }
1182
1183         rtw_set_to_roam(padapter, 0);
1184 #ifdef CONFIG_INTEL_WIDI
1185         if (padapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING)
1186         {
1187                 memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1188                 intel_widi_wk_cmd(padapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1189                 DBG_871X("change to widi listen\n");
1190         }
1191 #endif /*  CONFIG_INTEL_WIDI */
1192
1193         rtw_set_scan_deny(padapter, 3000);
1194
1195         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state = 0x%08x\n", get_fwstate(pmlmepriv)));
1196 }
1197
1198 /*
1199 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
1200 */
1201 void rtw_indicate_disconnect(struct adapter *padapter)
1202 {
1203         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
1204
1205         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
1206
1207         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING|WIFI_UNDER_WPS);
1208
1209         /* DBG_871X("clear wps when %s\n", __func__); */
1210
1211         if (rtw_to_roam(padapter) > 0)
1212                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1213
1214         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED)
1215                 || (rtw_to_roam(padapter) <= 0)
1216         )
1217         {
1218                 rtw_os_indicate_disconnect(padapter);
1219
1220                 /* set ips_deny_time to avoid enter IPS before LPS leave */
1221                 rtw_set_ips_deny(padapter, 3000);
1222
1223               _clr_fwstate_(pmlmepriv, _FW_LINKED);
1224
1225                 rtw_clear_scan_deny(padapter);
1226         }
1227
1228         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
1229 }
1230
1231 inline void rtw_indicate_scan_done(struct adapter *padapter, bool aborted)
1232 {
1233         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1234
1235         rtw_os_indicate_scan_done(padapter, aborted);
1236
1237         if (is_primary_adapter(padapter) &&
1238             (!adapter_to_pwrctl(padapter)->bInSuspend) &&
1239             (!check_fwstate(&padapter->mlmepriv,
1240                             WIFI_ASOC_STATE|WIFI_UNDER_LINKING))) {
1241                 struct pwrctrl_priv *pwrpriv;
1242
1243                 pwrpriv = adapter_to_pwrctl(padapter);
1244                 rtw_set_ips_deny(padapter, 0);
1245                 _set_timer(&padapter->mlmepriv.dynamic_chk_timer, 1);
1246         }
1247 }
1248
1249 void rtw_scan_abort(struct adapter *adapter)
1250 {
1251         unsigned long start;
1252         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1253         struct mlme_ext_priv *pmlmeext = &(adapter->mlmeextpriv);
1254
1255         start = jiffies;
1256         pmlmeext->scan_abort = true;
1257         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)
1258                 && jiffies_to_msecs(start) <= 200) {
1259
1260                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1261                         break;
1262
1263                 DBG_871X(FUNC_NDEV_FMT"fw_state = _FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1264                 msleep(20);
1265         }
1266
1267         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
1268                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
1269                         DBG_871X(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1270                 rtw_indicate_scan_done(adapter, true);
1271         }
1272         pmlmeext->scan_abort = false;
1273 }
1274
1275 static struct sta_info *rtw_joinbss_update_stainfo(struct adapter *padapter, struct wlan_network *pnetwork)
1276 {
1277         int i;
1278         struct sta_info *bmc_sta, *psta = NULL;
1279         struct recv_reorder_ctrl *preorder_ctrl;
1280         struct sta_priv *pstapriv = &padapter->stapriv;
1281         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1282
1283         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
1284         if (psta == NULL) {
1285                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
1286         }
1287
1288         if (psta) /* update ptarget_sta */
1289         {
1290                 DBG_871X("%s\n", __func__);
1291
1292                 psta->aid  = pnetwork->join_res;
1293
1294                 update_sta_info(padapter, psta);
1295
1296                 /* update station supportRate */
1297                 psta->bssratelen = rtw_get_rateset_len(pnetwork->network.SupportedRates);
1298                 memcpy(psta->bssrateset, pnetwork->network.SupportedRates, psta->bssratelen);
1299                 rtw_hal_update_sta_rate_mask(padapter, psta);
1300
1301                 psta->wireless_mode = pmlmeext->cur_wireless_mode;
1302                 psta->raid = rtw_hal_networktype_to_raid(padapter, psta);
1303
1304
1305                 /* sta mode */
1306                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
1307
1308                 /* security related */
1309                 if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
1310                 {
1311                         padapter->securitypriv.binstallGrpkey =false;
1312                         padapter->securitypriv.busetkipkey =false;
1313                         padapter->securitypriv.bgrpkey_handshake =false;
1314
1315                         psta->ieee8021x_blocked =true;
1316                         psta->dot118021XPrivacy =padapter->securitypriv.dot11PrivacyAlgrthm;
1317
1318                         memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof (union Keytype));
1319
1320                         memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof (union Keytype));
1321                         memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof (union Keytype));
1322
1323                         memset((u8 *)&psta->dot11txpn, 0, sizeof (union pn48));
1324                         psta->dot11txpn.val = psta->dot11txpn.val + 1;
1325                         memset((u8 *)&psta->dot11wtxpn, 0, sizeof (union pn48));
1326                         memset((u8 *)&psta->dot11rxpn, 0, sizeof (union pn48));
1327                 }
1328
1329                 /*      Commented by Albert 2012/07/21 */
1330                 /*      When doing the WPS, the wps_ie_len won't equal to 0 */
1331                 /*      And the Wi-Fi driver shouldn't allow the data packet to be tramsmitted. */
1332                 if (padapter->securitypriv.wps_ie_len != 0)
1333                 {
1334                         psta->ieee8021x_blocked =true;
1335                         padapter->securitypriv.wps_ie_len = 0;
1336                 }
1337
1338
1339                 /* for A-MPDU Rx reordering buffer control for bmc_sta & sta_info */
1340                 /* if A-MPDU Rx is enabled, reseting  rx_ordering_ctrl wstart_b(indicate_seq) to default value = 0xffff */
1341                 /* todo: check if AP can send A-MPDU packets */
1342                 for (i = 0; i < 16 ; i++)
1343                 {
1344                         /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1345                         preorder_ctrl = &psta->recvreorder_ctrl[i];
1346                         preorder_ctrl->enable = false;
1347                         preorder_ctrl->indicate_seq = 0xffff;
1348                         #ifdef DBG_RX_SEQ
1349                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1350                                 preorder_ctrl->indicate_seq);
1351                         #endif
1352                         preorder_ctrl->wend_b = 0xffff;
1353                         preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1354                 }
1355
1356
1357                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
1358                 if (bmc_sta)
1359                 {
1360                         for (i = 0; i < 16 ; i++)
1361                         {
1362                                 /* preorder_ctrl = &precvpriv->recvreorder_ctrl[i]; */
1363                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
1364                                 preorder_ctrl->enable = false;
1365                                 preorder_ctrl->indicate_seq = 0xffff;
1366                                 #ifdef DBG_RX_SEQ
1367                                 DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u\n", __func__, __LINE__,
1368                                         preorder_ctrl->indicate_seq);
1369                                 #endif
1370                                 preorder_ctrl->wend_b = 0xffff;
1371                                 preorder_ctrl->wsize_b = 64;/* max_ampdu_sz;ex. 32(kbytes) -> wsize_b =32 */
1372                         }
1373                 }
1374         }
1375
1376         return psta;
1377
1378 }
1379
1380 /* pnetwork : returns from rtw_joinbss_event_callback */
1381 /* ptarget_wlan: found from scanned_queue */
1382 static void rtw_joinbss_update_network(struct adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
1383 {
1384         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1385         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
1386
1387         DBG_871X("%s\n", __func__);
1388
1389         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\nfw_state:%x, BSSID:"MAC_FMT"\n"
1390                 , get_fwstate(pmlmepriv), MAC_ARG(pnetwork->network.MacAddress)));
1391
1392
1393         /*  why not use ptarget_wlan?? */
1394         memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
1395         /*  some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs */
1396         cur_network->network.IELength = ptarget_wlan->network.IELength;
1397         memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
1398
1399         cur_network->aid = pnetwork->join_res;
1400
1401
1402         rtw_set_signal_stat_timer(&padapter->recvpriv);
1403
1404         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
1405         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
1406         /* the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled) */
1407         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
1408         #if defined(DBG_RX_SIGNAL_DISPLAY_PROCESSING) && 1
1409                 DBG_871X(FUNC_ADPT_FMT" signal_strength:%3u, rssi:%3d, signal_qual:%3u"
1410                         "\n"
1411                         , FUNC_ADPT_ARG(padapter)
1412                         , padapter->recvpriv.signal_strength
1413                         , padapter->recvpriv.rssi
1414                         , padapter->recvpriv.signal_qual
1415         );
1416         #endif
1417
1418         rtw_set_signal_stat_timer(&padapter->recvpriv);
1419
1420         /* update fw_state will clr _FW_UNDER_LINKING here indirectly */
1421         switch (pnetwork->network.InfrastructureMode)
1422         {
1423                 case Ndis802_11Infrastructure:
1424
1425                                 if (pmlmepriv->fw_state&WIFI_UNDER_WPS)
1426                                         pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
1427                                 else
1428                                         pmlmepriv->fw_state = WIFI_STATION_STATE;
1429
1430                                 break;
1431                 case Ndis802_11IBSS:
1432                                 pmlmepriv->fw_state = WIFI_ADHOC_STATE;
1433                                 break;
1434                 default:
1435                                 pmlmepriv->fw_state = WIFI_NULL_STATE;
1436                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Invalid network_mode\n"));
1437                                 break;
1438         }
1439
1440         rtw_update_protection(padapter, (cur_network->network.IEs) + sizeof (struct ndis_802_11_fix_ie),
1441                                                                         (cur_network->network.IELength));
1442
1443         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength, (u8) cur_network->network.Configuration.DSConfig);
1444 }
1445
1446 /* Notes: the fucntion could be > passive_level (the same context as Rx tasklet) */
1447 /* pnetwork : returns from rtw_joinbss_event_callback */
1448 /* ptarget_wlan: found from scanned_queue */
1449 /* if join_res > 0, for (fw_state ==WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist. */
1450 /* if join_res > 0, for (fw_state ==WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist. */
1451 /* if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan != NULL). */
1452 /*  */
1453 /* define REJOIN */
1454 void rtw_joinbss_event_prehandle(struct adapter *adapter, u8 *pbuf)
1455 {
1456         static u8 retry = 0;
1457         u8 timer_cancelled;
1458         struct sta_info *ptarget_sta = NULL, *pcur_sta = NULL;
1459         struct  sta_priv *pstapriv = &adapter->stapriv;
1460         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1461         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1462         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1463         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1464         unsigned int            the_same_macaddr = false;
1465
1466         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("joinbss event call back received with res =%d\n", pnetwork->join_res));
1467
1468         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1469
1470
1471         if (pmlmepriv->assoc_ssid.SsidLength == 0)
1472         {
1473                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   joinbss event call back  for Any SSid\n"));
1474         }
1475         else
1476         {
1477                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
1478         }
1479
1480         the_same_macaddr = !memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
1481
1482         pnetwork->network.Length = get_wlan_bssid_ex_sz(&pnetwork->network);
1483         if (pnetwork->network.Length > sizeof(struct wlan_bssid_ex))
1484         {
1485                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
1486                 return;
1487         }
1488
1489         spin_lock_bh(&pmlmepriv->lock);
1490
1491         pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 0;
1492         pmlmepriv->LinkDetectInfo.LowPowerTransitionCount = 0;
1493
1494         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("\n rtw_joinbss_event_callback !! spin_lock_irqsave\n"));
1495
1496         if (pnetwork->join_res > 0)
1497         {
1498                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1499                 retry = 0;
1500                 if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING))
1501                 {
1502                         /* s1. find ptarget_wlan */
1503                         if (check_fwstate(pmlmepriv, _FW_LINKED))
1504                         {
1505                                 if (the_same_macaddr == true)
1506                                 {
1507                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1508                                 }
1509                                 else
1510                                 {
1511                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1512                                         if (pcur_wlan)  pcur_wlan->fixed = false;
1513
1514                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
1515                                         if (pcur_sta)
1516                                                 rtw_free_stainfo(adapter,  pcur_sta);
1517
1518                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
1519                                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1520                                                 if (ptarget_wlan)       ptarget_wlan->fixed = true;
1521                                         }
1522                                 }
1523
1524                         }
1525                         else
1526                         {
1527                                 ptarget_wlan = _rtw_find_same_network(&pmlmepriv->scanned_queue, pnetwork);
1528                                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true) {
1529                                         if (ptarget_wlan)       ptarget_wlan->fixed = true;
1530                                 }
1531                         }
1532
1533                         /* s2. update cur_network */
1534                         if (ptarget_wlan)
1535                         {
1536                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
1537                         }
1538                         else
1539                         {
1540                                 DBG_871X_LEVEL(_drv_always_, "Can't find ptarget_wlan when joinbss_event callback\n");
1541                                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1542                                 goto ignore_joinbss_callback;
1543                         }
1544
1545
1546                         /* s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode */
1547                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true)
1548                         {
1549                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
1550                                 if (ptarget_sta == NULL)
1551                                 {
1552                                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't update stainfo when joinbss_event callback\n"));
1553                                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1554                                         goto ignore_joinbss_callback;
1555                                 }
1556                         }
1557
1558                         /* s4. indicate connect */
1559                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == true)
1560                         {
1561                                 pmlmepriv->cur_network_scanned = ptarget_wlan;
1562                                 rtw_indicate_connect(adapter);
1563                         }
1564                         else
1565                         {
1566                                 /* adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback */
1567                                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
1568                         }
1569
1570
1571                         /* s5. Cancle assoc_timer */
1572                         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
1573
1574                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("Cancle assoc_timer\n"));
1575
1576                 }
1577                 else
1578                 {
1579                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));
1580                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1581                         goto ignore_joinbss_callback;
1582                 }
1583
1584                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1585
1586         }
1587         else if (pnetwork->join_res == -4)
1588         {
1589                 rtw_reset_securitypriv(adapter);
1590                 _set_timer(&pmlmepriv->assoc_timer, 1);
1591
1592                 /* rtw_free_assoc_resources(adapter, 1); */
1593
1594                 if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == true)
1595                 {
1596                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("fail! clear _FW_UNDER_LINKING ^^^fw_state =%x\n", get_fwstate(pmlmepriv)));
1597                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1598                 }
1599
1600         }
1601         else /* if join_res < 0 (join fails), then try again */
1602         {
1603
1604                 #ifdef REJOIN
1605                 res = _FAIL;
1606                 if (retry < 2) {
1607                         res = rtw_select_and_join_from_scanned_queue(pmlmepriv);
1608                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("rtw_select_and_join_from_scanned_queue again! res:%d\n", res));
1609                 }
1610
1611                  if (res == _SUCCESS)
1612                 {
1613                         /* extend time of assoc_timer */
1614                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
1615                         retry++;
1616                 }
1617                 else if (res == 2)/* there is no need to wait for join */
1618                 {
1619                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1620                         rtw_indicate_connect(adapter);
1621                 }
1622                 else
1623                 {
1624                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Set Assoc_Timer = 1; can't find match ssid in scanned_q\n"));
1625                 #endif
1626
1627                         _set_timer(&pmlmepriv->assoc_timer, 1);
1628                         /* rtw_free_assoc_resources(adapter, 1); */
1629                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1630
1631                 #ifdef REJOIN
1632                         retry = 0;
1633                 }
1634                 #endif
1635         }
1636
1637 ignore_joinbss_callback:
1638
1639         spin_unlock_bh(&pmlmepriv->lock);
1640 }
1641
1642 void rtw_joinbss_event_callback(struct adapter *adapter, u8 *pbuf)
1643 {
1644         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1645
1646         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
1647
1648         rtw_os_xmit_schedule(adapter);
1649 }
1650
1651 /* FOR STA, AP , AD-HOC mode */
1652 void rtw_sta_media_status_rpt(struct adapter *adapter, struct sta_info *psta, u32 mstatus)
1653 {
1654         u16 media_status_rpt;
1655
1656         if (psta == NULL)       return;
1657
1658         media_status_rpt = (u16)((psta->mac_id<<8)|mstatus); /*   MACID|OPMODE:1 connect */
1659         rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status_rpt);
1660 }
1661
1662 void rtw_stassoc_event_callback(struct adapter *adapter, u8 *pbuf)
1663 {
1664         struct sta_info *psta;
1665         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1666         struct stassoc_event    *pstassoc       = (struct stassoc_event*)pbuf;
1667         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1668         struct wlan_network     *ptarget_wlan = NULL;
1669
1670         if (rtw_access_ctrl(adapter, pstassoc->macaddr) == false)
1671                 return;
1672
1673         if (check_fwstate(pmlmepriv, WIFI_AP_STATE))
1674         {
1675                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1676                 if (psta)
1677                 {
1678                         u8 *passoc_req = NULL;
1679                         u32 assoc_req_len = 0;
1680
1681                         rtw_sta_media_status_rpt(adapter, psta, 1);
1682
1683 #ifndef CONFIG_AUTO_AP_MODE
1684
1685                         ap_sta_info_defer_update(adapter, psta);
1686
1687                         /* report to upper layer */
1688                         DBG_871X("indicate_sta_assoc_event to upper layer - hostapd\n");
1689                         spin_lock_bh(&psta->lock);
1690                         if (psta->passoc_req && psta->assoc_req_len>0)
1691                         {
1692                                 passoc_req = rtw_zmalloc(psta->assoc_req_len);
1693                                 if (passoc_req)
1694                                 {
1695                                         assoc_req_len = psta->assoc_req_len;
1696                                         memcpy(passoc_req, psta->passoc_req, assoc_req_len);
1697
1698                                         kfree(psta->passoc_req);
1699                                         psta->passoc_req = NULL;
1700                                         psta->assoc_req_len = 0;
1701                                 }
1702                         }
1703                         spin_unlock_bh(&psta->lock);
1704
1705                         if (passoc_req && assoc_req_len>0)
1706                         {
1707                                 rtw_cfg80211_indicate_sta_assoc(adapter, passoc_req, assoc_req_len);
1708
1709                                 kfree(passoc_req);
1710                         }
1711 #endif /* CONFIG_AUTO_AP_MODE */
1712                 }
1713                 return;
1714         }
1715
1716         /* for AD-HOC mode */
1717         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);
1718         if (psta != NULL)
1719         {
1720                 /* the sta have been in sta_info_queue => do nothing */
1721
1722                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue\n"));
1723
1724                 return; /* between drv has received this event before and  fw have not yet to set key to CAM_ENTRY) */
1725         }
1726
1727         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr);
1728         if (psta == NULL) {
1729                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
1730                 return;
1731         }
1732
1733         /* to do : init sta_info variable */
1734         psta->qos_option = 0;
1735         psta->mac_id = (uint)pstassoc->cam_id;
1736         /* psta->aid = (uint)pstassoc->cam_id; */
1737         DBG_871X("%s\n", __func__);
1738         /* for ad-hoc mode */
1739         rtw_hal_set_odm_var(adapter, HAL_ODM_STA_INFO, psta, true);
1740
1741         rtw_sta_media_status_rpt(adapter, psta, 1);
1742
1743         if (adapter->securitypriv.dot11AuthAlgrthm ==dot11AuthAlgrthm_8021X)
1744                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
1745
1746
1747         psta->ieee8021x_blocked = false;
1748
1749         spin_lock_bh(&pmlmepriv->lock);
1750
1751         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ==true) ||
1752                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) ==true))
1753         {
1754                 if (adapter->stapriv.asoc_sta_count == 2)
1755                 {
1756                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1757                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
1758                         pmlmepriv->cur_network_scanned = ptarget_wlan;
1759                         if (ptarget_wlan)       ptarget_wlan->fixed = true;
1760                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1761                         /*  a sta + bc/mc_stainfo (not Ibss_stainfo) */
1762                         rtw_indicate_connect(adapter);
1763                 }
1764         }
1765
1766         spin_unlock_bh(&pmlmepriv->lock);
1767
1768
1769         mlmeext_sta_add_event_callback(adapter, psta);
1770 }
1771
1772 void rtw_stadel_event_callback(struct adapter *adapter, u8 *pbuf)
1773 {
1774         int mac_id = (-1);
1775         struct sta_info *psta;
1776         struct wlan_network* pwlan = NULL;
1777         struct wlan_bssid_ex    *pdev_network = NULL;
1778         u8 *pibss = NULL;
1779         struct  mlme_priv *pmlmepriv = &(adapter->mlmepriv);
1780         struct  stadel_event *pstadel   = (struct stadel_event*)pbuf;
1781         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
1782         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
1783         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1784
1785         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
1786         if (psta)
1787                 mac_id = psta->mac_id;
1788         else
1789                 mac_id = pstadel->mac_id;
1790
1791         DBG_871X("%s(mac_id =%d) =" MAC_FMT "\n", __func__, mac_id, MAC_ARG(pstadel->macaddr));
1792
1793         if (mac_id>= 0) {
1794                 u16 media_status;
1795                 media_status = (mac_id<<8)|0; /*   MACID|OPMODE:0 means disconnect */
1796                 /* for STA, AP, ADHOC mode, report disconnect stauts to FW */
1797                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
1798         }
1799
1800         /* if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) */
1801         if ((pmlmeinfo->state&0x03) == WIFI_FW_AP_STATE)
1802         {
1803                 return;
1804         }
1805
1806
1807         mlmeext_sta_del_event_callback(adapter);
1808
1809         spin_lock_bh(&pmlmepriv->lock);
1810
1811         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE))
1812         {
1813                 u16 reason = *((unsigned short *)(pstadel->rsvd));
1814                 bool roam = false;
1815                 struct wlan_network *roam_target = NULL;
1816
1817                 if (adapter->registrypriv.wifi_spec == 1) {
1818                         roam = false;
1819                 } else if (reason == WLAN_REASON_EXPIRATION_CHK && rtw_chk_roam_flags(adapter, RTW_ROAM_ON_EXPIRED)) {
1820                         roam = true;
1821                 } else if (reason == WLAN_REASON_ACTIVE_ROAM && rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1822                         roam = true;
1823                         roam_target = pmlmepriv->roam_network;
1824                 }
1825 #ifdef CONFIG_INTEL_WIDI
1826                 else if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_CONNECTED) {
1827                         roam = true;
1828                 }
1829 #endif /*  CONFIG_INTEL_WIDI */
1830
1831                 if (roam == true) {
1832                         if (rtw_to_roam(adapter) > 0)
1833                                 rtw_dec_to_roam(adapter); /* this stadel_event is caused by roaming, decrease to_roam */
1834                         else if (rtw_to_roam(adapter) == 0)
1835                                 rtw_set_to_roam(adapter, adapter->registrypriv.max_roaming_times);
1836                 } else {
1837                         rtw_set_to_roam(adapter, 0);
1838                 }
1839
1840                 rtw_free_uc_swdec_pending_queue(adapter);
1841
1842                 rtw_free_assoc_resources(adapter, 1);
1843                 rtw_indicate_disconnect(adapter);
1844
1845                 spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1846                 /*  remove the network entry in scanned_queue */
1847                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1848                 if (pwlan) {
1849                         pwlan->fixed = false;
1850                         rtw_free_network_nolock(adapter, pwlan);
1851                 }
1852                 spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1853
1854 #ifdef CONFIG_INTEL_WIDI
1855                 if (!rtw_to_roam(adapter))
1856                         process_intel_widi_disconnect(adapter, 1);
1857 #endif /*  CONFIG_INTEL_WIDI */
1858
1859                 _rtw_roaming(adapter, roam_target);
1860         }
1861
1862         if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1863               check_fwstate(pmlmepriv, WIFI_ADHOC_STATE))
1864         {
1865
1866                 rtw_free_stainfo(adapter,  psta);
1867
1868                 if (adapter->stapriv.asoc_sta_count == 1) /* a sta + bc/mc_stainfo (not Ibss_stainfo) */
1869                 {
1870                         /* rtw_indicate_disconnect(adapter);removed@20091105 */
1871                         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
1872                         /* free old ibss network */
1873                         /* pwlan = rtw_find_network(&pmlmepriv->scanned_queue, pstadel->macaddr); */
1874                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1875                         if (pwlan)
1876                         {
1877                                 pwlan->fixed = false;
1878                                 rtw_free_network_nolock(adapter, pwlan);
1879                         }
1880                         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
1881                         /* re-create ibss */
1882                         pdev_network = &(adapter->registrypriv.dev_network);
1883                         pibss = adapter->registrypriv.dev_network.MacAddress;
1884
1885                         memcpy(pdev_network, &tgt_network->network, get_wlan_bssid_ex_sz(&tgt_network->network));
1886
1887                         memset(&pdev_network->Ssid, 0, sizeof(struct ndis_802_11_ssid));
1888                         memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(struct ndis_802_11_ssid));
1889
1890                         rtw_update_registrypriv_dev_network(adapter);
1891
1892                         rtw_generate_random_ibss(pibss);
1893
1894                         if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE))
1895                         {
1896                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
1897                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
1898                         }
1899
1900                         if (rtw_createbss_cmd(adapter)!= _SUCCESS)
1901                         {
1902
1903                                 RT_TRACE(_module_rtl871x_ioctl_set_c_, _drv_err_, ("***Error =>stadel_event_callback: rtw_createbss_cmd status FAIL***\n "));
1904
1905                         }
1906
1907
1908                 }
1909
1910         }
1911
1912         spin_unlock_bh(&pmlmepriv->lock);
1913 }
1914
1915 void rtw_cpwm_event_callback(struct adapter *padapter, u8 *pbuf)
1916 {
1917         struct reportpwrstate_parm *preportpwrstate;
1918
1919         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_cpwm_event_callback !!!\n"));
1920         preportpwrstate = (struct reportpwrstate_parm*)pbuf;
1921         preportpwrstate->state |= (u8)(adapter_to_pwrctl(padapter)->cpwm_tog + 0x80);
1922         cpwm_int_hdl(padapter, preportpwrstate);
1923 }
1924
1925
1926 void rtw_wmm_event_callback(struct adapter *padapter, u8 *pbuf)
1927 {
1928         WMMOnAssocRsp(padapter);
1929 }
1930
1931 /*
1932 * _rtw_join_timeout_handler - Timeout/faliure handler for CMD JoinBss
1933 * @adapter: pointer to struct adapter structure
1934 */
1935 void _rtw_join_timeout_handler (struct adapter *adapter)
1936 {
1937         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1938
1939         DBG_871X("%s, fw_state =%x\n", __func__, get_fwstate(pmlmepriv));
1940
1941         if (adapter->bDriverStopped ||adapter->bSurpriseRemoved)
1942                 return;
1943
1944         spin_lock_bh(&pmlmepriv->lock);
1945
1946         if (rtw_to_roam(adapter) > 0) { /* join timeout caused by roaming */
1947                 while (1) {
1948                         rtw_dec_to_roam(adapter);
1949                         if (rtw_to_roam(adapter) != 0) { /* try another */
1950                                 int do_join_r;
1951                                 DBG_871X("%s try another roaming\n", __func__);
1952                                 if (_SUCCESS!=(do_join_r =rtw_do_join(adapter))) {
1953                                         DBG_871X("%s roaming do_join return %d\n", __func__ , do_join_r);
1954                                         continue;
1955                                 }
1956                                 break;
1957                         } else {
1958 #ifdef CONFIG_INTEL_WIDI
1959                                 if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING)
1960                                 {
1961                                         memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1962                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1963                                         DBG_871X("change to widi listen\n");
1964                                 }
1965 #endif /*  CONFIG_INTEL_WIDI */
1966                                 DBG_871X("%s We've try roaming but fail\n", __func__);
1967                                 rtw_indicate_disconnect(adapter);
1968                                 break;
1969                         }
1970                 }
1971
1972         } else
1973         {
1974                 rtw_indicate_disconnect(adapter);
1975                 free_scanqueue(pmlmepriv);/*  */
1976
1977                 /* indicate disconnect for the case that join_timeout and check_fwstate != FW_LINKED */
1978                 rtw_cfg80211_indicate_disconnect(adapter);
1979
1980         }
1981
1982         spin_unlock_bh(&pmlmepriv->lock);
1983 }
1984
1985 /*
1986 * rtw_scan_timeout_handler - Timeout/Faliure handler for CMD SiteSurvey
1987 * @adapter: pointer to struct adapter structure
1988 */
1989 void rtw_scan_timeout_handler (struct adapter *adapter)
1990 {
1991         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1992
1993         DBG_871X(FUNC_ADPT_FMT" fw_state =%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
1994
1995         spin_lock_bh(&pmlmepriv->lock);
1996
1997         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1998
1999         spin_unlock_bh(&pmlmepriv->lock);
2000
2001         rtw_indicate_scan_done(adapter, true);
2002 }
2003
2004 void rtw_mlme_reset_auto_scan_int(struct adapter *adapter)
2005 {
2006         struct mlme_priv *mlme = &adapter->mlmepriv;
2007         struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
2008         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
2009
2010         if (pmlmeinfo->VHT_enable) /* disable auto scan when connect to 11AC AP */
2011         {
2012                 mlme->auto_scan_int_ms = 0;
2013         }
2014         else if (adapter->registrypriv.wifi_spec && is_client_associated_to_ap(adapter) == true) {
2015                 mlme->auto_scan_int_ms = 60*1000;
2016         } else if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
2017                 if (check_fwstate(mlme, WIFI_STATION_STATE) && check_fwstate(mlme, _FW_LINKED))
2018                         mlme->auto_scan_int_ms = mlme->roam_scan_int_ms;
2019         } else {
2020                 mlme->auto_scan_int_ms = 0; /* disabled */
2021         }
2022
2023         return;
2024 }
2025
2026 static void rtw_auto_scan_handler(struct adapter *padapter)
2027 {
2028         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2029
2030         rtw_mlme_reset_auto_scan_int(padapter);
2031
2032         if (pmlmepriv->auto_scan_int_ms != 0
2033                 && jiffies_to_msecs(jiffies - pmlmepriv->scan_start_time) > pmlmepriv->auto_scan_int_ms) {
2034
2035                 if (!padapter->registrypriv.wifi_spec) {
2036                         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == true)
2037                         {
2038                                 DBG_871X(FUNC_ADPT_FMT" _FW_UNDER_SURVEY|_FW_UNDER_LINKING\n", FUNC_ADPT_ARG(padapter));
2039                                 goto exit;
2040                         }
2041
2042                         if (pmlmepriv->LinkDetectInfo.bBusyTraffic == true)
2043                         {
2044                                 DBG_871X(FUNC_ADPT_FMT" exit BusyTraffic\n", FUNC_ADPT_ARG(padapter));
2045                                 goto exit;
2046                         }
2047                 }
2048
2049                 DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
2050
2051                 rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
2052         }
2053
2054 exit:
2055         return;
2056 }
2057
2058 void rtw_dynamic_check_timer_handlder(struct adapter *adapter)
2059 {
2060         if (!adapter)
2061                 return;
2062
2063         if (adapter->hw_init_completed == false)
2064                 return;
2065
2066         if ((adapter->bDriverStopped == true)||(adapter->bSurpriseRemoved == true))
2067                 return;
2068
2069         if (adapter->net_closed == true)
2070         {
2071                 return;
2072         }
2073
2074         if (is_primary_adapter(adapter))
2075                 DBG_871X("IsBtDisabled =%d, IsBtControlLps =%d\n", rtw_btcoex_IsBtDisabled(adapter), rtw_btcoex_IsBtControlLps(adapter));
2076
2077         if ((adapter_to_pwrctl(adapter)->bFwCurrentInPSMode ==true)
2078                 && (rtw_btcoex_IsBtControlLps(adapter) == false)
2079                 )
2080         {
2081                 u8 bEnterPS;
2082
2083                 linked_status_chk(adapter);
2084
2085                 bEnterPS = traffic_status_watchdog(adapter, 1);
2086                 if (bEnterPS)
2087                 {
2088                         /* rtw_lps_ctrl_wk_cmd(adapter, LPS_CTRL_ENTER, 1); */
2089                         rtw_hal_dm_watchdog_in_lps(adapter);
2090                 }
2091                 else
2092                 {
2093                         /* call rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_LEAVE, 1) in traffic_status_watchdog() */
2094                 }
2095
2096         }
2097         else
2098         {
2099                 if (is_primary_adapter(adapter))
2100                 {
2101                         rtw_dynamic_chk_wk_cmd(adapter);
2102                 }
2103         }
2104
2105         /* auto site survey */
2106         rtw_auto_scan_handler(adapter);
2107 }
2108
2109
2110 inline bool rtw_is_scan_deny(struct adapter *adapter)
2111 {
2112         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2113         return (atomic_read(&mlmepriv->set_scan_deny) != 0) ? true : false;
2114 }
2115
2116 inline void rtw_clear_scan_deny(struct adapter *adapter)
2117 {
2118         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2119         atomic_set(&mlmepriv->set_scan_deny, 0);
2120
2121         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
2122 }
2123
2124 void rtw_set_scan_deny_timer_hdl(struct adapter *adapter)
2125 {
2126         rtw_clear_scan_deny(adapter);
2127 }
2128
2129 void rtw_set_scan_deny(struct adapter *adapter, u32 ms)
2130 {
2131         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2132
2133         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
2134         atomic_set(&mlmepriv->set_scan_deny, 1);
2135         _set_timer(&mlmepriv->set_scan_deny_timer, ms);
2136 }
2137
2138 /*
2139 * Select a new roaming candidate from the original @param candidate and @param competitor
2140 * @return true: candidate is updated
2141 * @return false: candidate is not updated
2142 */
2143 static int rtw_check_roaming_candidate(struct mlme_priv *mlme
2144         , struct wlan_network **candidate, struct wlan_network *competitor)
2145 {
2146         int updated = false;
2147         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
2148
2149         if (is_same_ess(&competitor->network, &mlme->cur_network.network) == false)
2150                 goto exit;
2151
2152         if (rtw_is_desired_network(adapter, competitor) == false)
2153                 goto exit;
2154
2155         DBG_871X("roam candidate:%s %s("MAC_FMT", ch%3u) rssi:%d, age:%5d\n",
2156                 (competitor == mlme->cur_network_scanned)?"*":" " ,
2157                 competitor->network.Ssid.Ssid,
2158                 MAC_ARG(competitor->network.MacAddress),
2159                 competitor->network.Configuration.DSConfig,
2160                 (int)competitor->network.Rssi,
2161                 jiffies_to_msecs(jiffies - competitor->last_scanned)
2162         );
2163
2164         /* got specific addr to roam */
2165         if (!is_zero_mac_addr(mlme->roam_tgt_addr)) {
2166                 if (!memcmp(mlme->roam_tgt_addr, competitor->network.MacAddress, ETH_ALEN))
2167                         goto update;
2168                 else
2169                         goto exit;
2170         }
2171         if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms)
2172                 goto exit;
2173
2174         if (competitor->network.Rssi - mlme->cur_network_scanned->network.Rssi < mlme->roam_rssi_diff_th)
2175                 goto exit;
2176
2177         if (*candidate != NULL && (*candidate)->network.Rssi>=competitor->network.Rssi)
2178                 goto exit;
2179
2180 update:
2181         *candidate = competitor;
2182         updated = true;
2183
2184 exit:
2185         return updated;
2186 }
2187
2188 int rtw_select_roaming_candidate(struct mlme_priv *mlme)
2189 {
2190         int ret = _FAIL;
2191         struct list_head        *phead;
2192         struct adapter *adapter;
2193         struct __queue  *queue  = &(mlme->scanned_queue);
2194         struct  wlan_network    *pnetwork = NULL;
2195         struct  wlan_network    *candidate = NULL;
2196
2197         if (mlme->cur_network_scanned == NULL) {
2198                 rtw_warn_on(1);
2199                 return ret;
2200         }
2201
2202         spin_lock_bh(&(mlme->scanned_queue.lock));
2203         phead = get_list_head(queue);
2204         adapter = (struct adapter *)mlme->nic_hdl;
2205
2206         mlme->pscanned = get_next(phead);
2207
2208         while (phead != mlme->pscanned) {
2209
2210                 pnetwork = LIST_CONTAINOR(mlme->pscanned, struct wlan_network, list);
2211                 if (pnetwork == NULL) {
2212                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2213                         ret = _FAIL;
2214                         goto exit;
2215                 }
2216
2217                 mlme->pscanned = get_next(mlme->pscanned);
2218
2219                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2220                         , pnetwork->network.Ssid.Ssid
2221                         , MAC_ARG(pnetwork->network.MacAddress)
2222                         , pnetwork->network.Configuration.DSConfig
2223                         , (int)pnetwork->network.Rssi);
2224
2225                 rtw_check_roaming_candidate(mlme, &candidate, pnetwork);
2226
2227         }
2228
2229         if (candidate == NULL) {
2230                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2231                 ret = _FAIL;
2232                 goto exit;
2233         } else {
2234                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2235                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2236                         candidate->network.Configuration.DSConfig);
2237
2238                 mlme->roam_network = candidate;
2239
2240                 if (!memcmp(candidate->network.MacAddress, mlme->roam_tgt_addr, ETH_ALEN))
2241                         memset(mlme->roam_tgt_addr, 0, ETH_ALEN);
2242         }
2243
2244         ret = _SUCCESS;
2245 exit:
2246         spin_unlock_bh(&(mlme->scanned_queue.lock));
2247
2248         return ret;
2249 }
2250
2251 /*
2252 * Select a new join candidate from the original @param candidate and @param competitor
2253 * @return true: candidate is updated
2254 * @return false: candidate is not updated
2255 */
2256 static int rtw_check_join_candidate(struct mlme_priv *mlme
2257         , struct wlan_network **candidate, struct wlan_network *competitor)
2258 {
2259         int updated = false;
2260         struct adapter *adapter = container_of(mlme, struct adapter, mlmepriv);
2261
2262
2263         /* check bssid, if needed */
2264         if (mlme->assoc_by_bssid ==true) {
2265                 if (memcmp(competitor->network.MacAddress, mlme->assoc_bssid, ETH_ALEN))
2266                         goto exit;
2267         }
2268
2269         /* check ssid, if needed */
2270         if (mlme->assoc_ssid.Ssid[0] && mlme->assoc_ssid.SsidLength) {
2271                 if (competitor->network.Ssid.SsidLength != mlme->assoc_ssid.SsidLength
2272                         || memcmp(competitor->network.Ssid.Ssid, mlme->assoc_ssid.Ssid, mlme->assoc_ssid.SsidLength)
2273                 )
2274                         goto exit;
2275         }
2276
2277         if (rtw_is_desired_network(adapter, competitor)  == false)
2278                 goto exit;
2279
2280         if (rtw_to_roam(adapter) > 0) {
2281                 if (jiffies_to_msecs(jiffies - competitor->last_scanned) >= mlme->roam_scanr_exp_ms
2282                         || is_same_ess(&competitor->network, &mlme->cur_network.network) == false
2283                 )
2284                         goto exit;
2285         }
2286
2287         if (*candidate == NULL ||(*candidate)->network.Rssi<competitor->network.Rssi)
2288         {
2289                 *candidate = competitor;
2290                 updated = true;
2291         }
2292
2293         if (updated) {
2294                 DBG_871X("[by_bssid:%u][assoc_ssid:%s]"
2295                         "[to_roam:%u] "
2296                         "new candidate: %s("MAC_FMT", ch%u) rssi:%d\n",
2297                         mlme->assoc_by_bssid,
2298                         mlme->assoc_ssid.Ssid,
2299                         rtw_to_roam(adapter),
2300                         (*candidate)->network.Ssid.Ssid,
2301                         MAC_ARG((*candidate)->network.MacAddress),
2302                         (*candidate)->network.Configuration.DSConfig,
2303                         (int)(*candidate)->network.Rssi
2304                 );
2305         }
2306
2307 exit:
2308         return updated;
2309 }
2310
2311 /*
2312 Calling context:
2313 The caller of the sub-routine will be in critical section...
2314
2315 The caller must hold the following spinlock
2316
2317 pmlmepriv->lock
2318
2319
2320 */
2321
2322 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv)
2323 {
2324         int ret;
2325         struct list_head        *phead;
2326         struct adapter *adapter;
2327         struct __queue  *queue  = &(pmlmepriv->scanned_queue);
2328         struct  wlan_network    *pnetwork = NULL;
2329         struct  wlan_network    *candidate = NULL;
2330
2331         adapter = (struct adapter *)pmlmepriv->nic_hdl;
2332
2333         spin_lock_bh(&(pmlmepriv->scanned_queue.lock));
2334
2335         if (pmlmepriv->roam_network) {
2336                 candidate = pmlmepriv->roam_network;
2337                 pmlmepriv->roam_network = NULL;
2338                 goto candidate_exist;
2339         }
2340
2341         phead = get_list_head(queue);
2342         pmlmepriv->pscanned = get_next(phead);
2343
2344         while (phead != pmlmepriv->pscanned) {
2345
2346                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
2347                 if (pnetwork == NULL) {
2348                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("%s return _FAIL:(pnetwork == NULL)\n", __func__));
2349                         ret = _FAIL;
2350                         goto exit;
2351                 }
2352
2353                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
2354
2355                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
2356                         , pnetwork->network.Ssid.Ssid
2357                         , MAC_ARG(pnetwork->network.MacAddress)
2358                         , pnetwork->network.Configuration.DSConfig
2359                         , (int)pnetwork->network.Rssi);
2360
2361                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
2362
2363         }
2364
2365         if (candidate == NULL) {
2366                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __func__);
2367 #ifdef CONFIG_WOWLAN
2368                 _clr_fwstate_(pmlmepriv, _FW_LINKED|_FW_UNDER_LINKING);
2369 #endif
2370                 ret = _FAIL;
2371                 goto exit;
2372         } else {
2373                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __func__,
2374                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
2375                         candidate->network.Configuration.DSConfig);
2376                 goto candidate_exist;
2377         }
2378
2379 candidate_exist:
2380
2381         /*  check for situation of  _FW_LINKED */
2382         if (check_fwstate(pmlmepriv, _FW_LINKED) == true)
2383         {
2384                 DBG_871X("%s: _FW_LINKED while ask_for_joinbss!!!\n", __func__);
2385
2386                 rtw_disassoc_cmd(adapter, 0, true);
2387                 rtw_indicate_disconnect(adapter);
2388                 rtw_free_assoc_resources(adapter, 0);
2389         }
2390
2391         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
2392         ret = rtw_joinbss_cmd(adapter, candidate);
2393
2394 exit:
2395         spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
2396         return ret;
2397 }
2398
2399 sint rtw_set_auth(struct adapter * adapter, struct security_priv *psecuritypriv)
2400 {
2401         struct  cmd_obj* pcmd;
2402         struct  setauth_parm *psetauthparm;
2403         struct  cmd_priv *pcmdpriv =&(adapter->cmdpriv);
2404         sint            res = _SUCCESS;
2405
2406         pcmd = (struct  cmd_obj*)rtw_zmalloc(sizeof(struct      cmd_obj));
2407         if (pcmd == NULL) {
2408                 res = _FAIL;  /* try again */
2409                 goto exit;
2410         }
2411
2412         psetauthparm =(struct setauth_parm*)rtw_zmalloc(sizeof(struct setauth_parm));
2413         if (psetauthparm == NULL) {
2414                 kfree((unsigned char *)pcmd);
2415                 res = _FAIL;
2416                 goto exit;
2417         }
2418
2419         memset(psetauthparm, 0, sizeof(struct setauth_parm));
2420         psetauthparm->mode =(unsigned char)psecuritypriv->dot11AuthAlgrthm;
2421
2422         pcmd->cmdcode = _SetAuth_CMD_;
2423         pcmd->parmbuf = (unsigned char *)psetauthparm;
2424         pcmd->cmdsz =  (sizeof(struct setauth_parm));
2425         pcmd->rsp = NULL;
2426         pcmd->rspsz = 0;
2427
2428
2429         INIT_LIST_HEAD(&pcmd->list);
2430
2431         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("after enqueue set_auth_cmd, auth_mode =%x\n", psecuritypriv->dot11AuthAlgrthm));
2432
2433         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2434
2435 exit:
2436         return res;
2437 }
2438
2439 sint rtw_set_key(struct adapter * adapter, struct security_priv *psecuritypriv, sint keyid, u8 set_tx, bool enqueue)
2440 {
2441         u8 keylen;
2442         struct cmd_obj          *pcmd;
2443         struct setkey_parm      *psetkeyparm;
2444         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
2445         sint    res = _SUCCESS;
2446
2447         psetkeyparm =(struct setkey_parm*)rtw_zmalloc(sizeof(struct setkey_parm));
2448         if (psetkeyparm == NULL) {
2449                 res = _FAIL;
2450                 goto exit;
2451         }
2452         memset(psetkeyparm, 0, sizeof(struct setkey_parm));
2453
2454         if (psecuritypriv->dot11AuthAlgrthm ==dot11AuthAlgrthm_8021X) {
2455                 psetkeyparm->algorithm =(unsigned char)psecuritypriv->dot118021XGrpPrivacy;
2456                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(unsigned char)psecuritypriv->dot118021XGrpPrivacy =%d\n", psetkeyparm->algorithm));
2457         }
2458         else {
2459                 psetkeyparm->algorithm =(u8)psecuritypriv->dot11PrivacyAlgrthm;
2460                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =(u8)psecuritypriv->dot11PrivacyAlgrthm =%d\n", psetkeyparm->algorithm));
2461
2462         }
2463         psetkeyparm->keyid = (u8)keyid;/* 0~3 */
2464         psetkeyparm->set_tx = set_tx;
2465         if (is_wep_enc(psetkeyparm->algorithm))
2466                 adapter->securitypriv.key_mask |= BIT(psetkeyparm->keyid);
2467
2468         DBG_871X("==> rtw_set_key algorithm(%x), keyid(%x), key_mask(%x)\n", psetkeyparm->algorithm, psetkeyparm->keyid, adapter->securitypriv.key_mask);
2469         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key: psetkeyparm->algorithm =%d psetkeyparm->keyid =(u8)keyid =%d\n", psetkeyparm->algorithm, keyid));
2470
2471         switch (psetkeyparm->algorithm) {
2472
2473                 case _WEP40_:
2474                         keylen =5;
2475                         memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2476                         break;
2477                 case _WEP104_:
2478                         keylen = 13;
2479                         memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
2480                         break;
2481                 case _TKIP_:
2482                         keylen = 16;
2483                         memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2484                         psetkeyparm->grpkey = 1;
2485                         break;
2486                 case _AES_:
2487                         keylen = 16;
2488                         memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
2489                         psetkeyparm->grpkey = 1;
2490                         break;
2491                 default:
2492                         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm = %x (must be 1 or 2 or 4 or 5)\n", psecuritypriv->dot11PrivacyAlgrthm));
2493                         res = _FAIL;
2494                         kfree((unsigned char *)psetkeyparm);
2495                         goto exit;
2496         }
2497
2498
2499         if (enqueue) {
2500                 pcmd = (struct  cmd_obj*)rtw_zmalloc(sizeof(struct      cmd_obj));
2501                 if (pcmd == NULL) {
2502                         kfree((unsigned char *)psetkeyparm);
2503                         res = _FAIL;  /* try again */
2504                         goto exit;
2505                 }
2506
2507                 pcmd->cmdcode = _SetKey_CMD_;
2508                 pcmd->parmbuf = (u8 *)psetkeyparm;
2509                 pcmd->cmdsz =  (sizeof(struct setkey_parm));
2510                 pcmd->rsp = NULL;
2511                 pcmd->rspsz = 0;
2512
2513                 INIT_LIST_HEAD(&pcmd->list);
2514
2515                 /* sema_init(&(pcmd->cmd_sem), 0); */
2516
2517                 res = rtw_enqueue_cmd(pcmdpriv, pcmd);
2518         }
2519         else {
2520                 setkey_hdl(adapter, (u8 *)psetkeyparm);
2521                 kfree((u8 *) psetkeyparm);
2522         }
2523 exit:
2524         return res;
2525 }
2526
2527 /* adjust IEs for rtw_joinbss_cmd in WMM */
2528 int rtw_restruct_wmm_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
2529 {
2530         unsigned        int ielength = 0;
2531         unsigned int i, j;
2532
2533         i = 12; /* after the fixed IE */
2534         while (i<in_len)
2535         {
2536                 ielength = initial_out_len;
2537
2538                 if (in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) /* WMM element ID and OUI */
2539                 {
2540                         for (j = i; j < i + 9; j++)
2541                         {
2542                             out_ie[ ielength] = in_ie[ j ];
2543                             ielength++;
2544                         }
2545                         out_ie[ initial_out_len + 1 ] = 0x07;
2546                         out_ie[ initial_out_len + 6 ] = 0x00;
2547                         out_ie[ initial_out_len + 8 ] = 0x00;
2548
2549                         break;
2550                 }
2551
2552                 i+=(in_ie[i+1]+2); /*  to the next IE element */
2553         }
2554
2555         return ielength;
2556
2557 }
2558
2559
2560 /*  */
2561 /*  Ported from 8185: IsInPreAuthKeyList(). (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.) */
2562 /*  Added by Annie, 2006-05-07. */
2563 /*  */
2564 /*  Search by BSSID, */
2565 /*  Return Value: */
2566 /*              -1              :if there is no pre-auth key in the  table */
2567 /*              >= 0            :if there is pre-auth key, and   return the entry id */
2568 /*  */
2569 /*  */
2570
2571 static int SecIsInPMKIDList(struct adapter *Adapter, u8 *bssid)
2572 {
2573         struct security_priv *psecuritypriv =&Adapter->securitypriv;
2574         int i = 0;
2575
2576         do
2577         {
2578                 if ((psecuritypriv->PMKIDList[i].bUsed) &&
2579                     (!memcmp(psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN)))
2580                 {
2581                         break;
2582                 }
2583                 else
2584                 {
2585                         i++;
2586                         /* continue; */
2587                 }
2588
2589         }while (i<NUM_PMKID_CACHE);
2590
2591         if (i == NUM_PMKID_CACHE)
2592         {
2593                 i = -1;/*  Could not find. */
2594         }
2595         else
2596         {
2597                 /*  There is one Pre-Authentication Key for the specific BSSID. */
2598         }
2599
2600         return (i);
2601
2602 }
2603
2604 /*  */
2605 /*  Check the RSN IE length */
2606 /*  If the RSN IE length <= 20, the RSN IE didn't include the PMKID information */
2607 /*  0-11th element in the array are the fixed IE */
2608 /*  12th element in the array is the IE */
2609 /*  13th element in the array is the IE length */
2610 /*  */
2611
2612 static int rtw_append_pmkid(struct adapter *Adapter, int iEntry, u8 *ie, uint ie_len)
2613 {
2614         struct security_priv *psecuritypriv =&Adapter->securitypriv;
2615
2616         if (ie[13]<=20) {
2617                 /*  The RSN IE didn't include the PMK ID, append the PMK information */
2618                         ie[ie_len]= 1;
2619                         ie_len++;
2620                         ie[ie_len]= 0;  /* PMKID count = 0x0100 */
2621                         ie_len++;
2622                         memcpy(&ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
2623
2624                         ie_len+= 16;
2625                         ie[13]+= 18;/* PMKID length = 2+16 */
2626
2627         }
2628         return (ie_len);
2629 }
2630
2631 sint rtw_restruct_sec_ie(struct adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len)
2632 {
2633         u8 authmode = 0x0;
2634         uint    ielength;
2635         int iEntry;
2636
2637         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
2638         struct security_priv *psecuritypriv =&adapter->securitypriv;
2639         uint    ndisauthmode =psecuritypriv->ndisauthtype;
2640
2641         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
2642                  ("+rtw_restruct_sec_ie: ndisauthmode =%d ndissecuritytype =%d\n",
2643                   ndisauthmode, ndissecuritytype));
2644
2645         /* copy fixed ie only */
2646         memcpy(out_ie, in_ie, 12);
2647         ielength = 12;
2648         if ((ndisauthmode ==Ndis802_11AuthModeWPA)||(ndisauthmode ==Ndis802_11AuthModeWPAPSK))
2649                         authmode = _WPA_IE_ID_;
2650         if ((ndisauthmode ==Ndis802_11AuthModeWPA2)||(ndisauthmode ==Ndis802_11AuthModeWPA2PSK))
2651                         authmode = _WPA2_IE_ID_;
2652
2653         if (check_fwstate(pmlmepriv, WIFI_UNDER_WPS))
2654         {
2655                 memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
2656
2657                 ielength += psecuritypriv->wps_ie_len;
2658         }
2659         else if ((authmode == _WPA_IE_ID_)||(authmode == _WPA2_IE_ID_))
2660         {
2661                 /* copy RSN or SSN */
2662                 memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
2663                 /* debug for CONFIG_IEEE80211W
2664                 {
2665                         int jj;
2666                         printk("supplicant_ie_length =%d &&&&&&&&&&&&&&&&&&&\n", psecuritypriv->supplicant_ie[1]+2);
2667                         for (jj = 0; jj < psecuritypriv->supplicant_ie[1]+2; jj++)
2668                                 printk(" %02x ", psecuritypriv->supplicant_ie[jj]);
2669                         printk("\n");
2670                 }*/
2671                 ielength+=psecuritypriv->supplicant_ie[1]+2;
2672                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
2673         }
2674
2675         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
2676         if (iEntry<0)
2677         {
2678                 return ielength;
2679         }
2680         else
2681         {
2682                 if (authmode == _WPA2_IE_ID_)
2683                 {
2684                         ielength =rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
2685                 }
2686         }
2687         return ielength;
2688 }
2689
2690 void rtw_init_registrypriv_dev_network(struct adapter * adapter)
2691 {
2692         struct registry_priv* pregistrypriv = &adapter->registrypriv;
2693         struct eeprom_priv* peepriv = &adapter->eeprompriv;
2694         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2695         u8 *myhwaddr = myid(peepriv);
2696
2697         memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
2698
2699         memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(struct ndis_802_11_ssid));
2700
2701         pdev_network->Configuration.Length =sizeof(struct ndis_802_11_conf);
2702         pdev_network->Configuration.BeaconPeriod = 100;
2703         pdev_network->Configuration.FHConfig.Length = 0;
2704         pdev_network->Configuration.FHConfig.HopPattern = 0;
2705         pdev_network->Configuration.FHConfig.HopSet = 0;
2706         pdev_network->Configuration.FHConfig.DwellTime = 0;
2707 }
2708
2709 void rtw_update_registrypriv_dev_network(struct adapter * adapter)
2710 {
2711         int sz = 0;
2712         struct registry_priv* pregistrypriv = &adapter->registrypriv;
2713         struct wlan_bssid_ex    *pdev_network = &pregistrypriv->dev_network;
2714         struct  security_priv*psecuritypriv = &adapter->securitypriv;
2715         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
2716         /* struct       xmit_priv *pxmitpriv = &adapter->xmitpriv; */
2717
2718         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0) ; /*  adhoc no 802.1x */
2719
2720         pdev_network->Rssi = 0;
2721
2722         switch (pregistrypriv->wireless_mode)
2723         {
2724                 case WIRELESS_11B:
2725                         pdev_network->NetworkTypeInUse = (Ndis802_11DS);
2726                         break;
2727                 case WIRELESS_11G:
2728                 case WIRELESS_11BG:
2729                 case WIRELESS_11_24N:
2730                 case WIRELESS_11G_24N:
2731                 case WIRELESS_11BG_24N:
2732                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2733                         break;
2734                 case WIRELESS_11A:
2735                 case WIRELESS_11A_5N:
2736                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2737                         break;
2738                 case WIRELESS_11ABGN:
2739                         if (pregistrypriv->channel > 14)
2740                                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
2741                         else
2742                                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
2743                         break;
2744                 default :
2745                         /*  TODO */
2746                         break;
2747         }
2748
2749         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
2750         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("pregistrypriv->channel =%d, pdev_network->Configuration.DSConfig = 0x%x\n", pregistrypriv->channel, pdev_network->Configuration.DSConfig));
2751
2752         if (cur_network->network.InfrastructureMode == Ndis802_11IBSS)
2753                 pdev_network->Configuration.ATIMWindow = (0);
2754
2755         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
2756
2757         /*  1. Supported rates */
2758         /*  2. IE */
2759
2760         /* rtw_set_supported_rate(pdev_network->SupportedRates, pregistrypriv->wireless_mode) ;  will be called in rtw_generate_ie */
2761         sz = rtw_generate_ie(pregistrypriv);
2762
2763         pdev_network->IELength = sz;
2764
2765         pdev_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pdev_network);
2766
2767         /* notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd(); */
2768         /* pdev_network->IELength = cpu_to_le32(sz); */
2769 }
2770
2771 void rtw_get_encrypt_decrypt_from_registrypriv(struct adapter * adapter)
2772 {
2773 }
2774
2775 /* the fucntion is at passive_level */
2776 void rtw_joinbss_reset(struct adapter *padapter)
2777 {
2778         u8 threshold;
2779         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2780
2781         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2782
2783         /* todo: if you want to do something io/reg/hw setting before join_bss, please add code here */
2784
2785         pmlmepriv->num_FortyMHzIntolerant = 0;
2786
2787         pmlmepriv->num_sta_no_ht = 0;
2788
2789         phtpriv->ampdu_enable = false;/* reset to disabled */
2790
2791         /*  TH = 1 => means that invalidate usb rx aggregation */
2792         /*  TH = 0 => means that validate usb rx aggregation, use init value. */
2793         if (phtpriv->ht_option)
2794         {
2795                 if (padapter->registrypriv.wifi_spec == 1)
2796                         threshold = 1;
2797                 else
2798                         threshold = 0;
2799                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2800         }
2801         else
2802         {
2803                 threshold = 1;
2804                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
2805         }
2806 }
2807
2808 void rtw_ht_use_default_setting(struct adapter *padapter)
2809 {
2810         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
2811         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2812         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2813         bool            bHwLDPCSupport = false, bHwSTBCSupport = false;
2814         bool            bHwSupportBeamformer = false, bHwSupportBeamformee = false;
2815
2816         if (pregistrypriv->wifi_spec)
2817                 phtpriv->bss_coexist = 1;
2818         else
2819                 phtpriv->bss_coexist = 0;
2820
2821         phtpriv->sgi_40m = TEST_FLAG(pregistrypriv->short_gi, BIT1) ? true : false;
2822         phtpriv->sgi_20m = TEST_FLAG(pregistrypriv->short_gi, BIT0) ? true : false;
2823
2824         /*  LDPC support */
2825         rtw_hal_get_def_var(padapter, HAL_DEF_RX_LDPC, (u8 *)&bHwLDPCSupport);
2826         CLEAR_FLAGS(phtpriv->ldpc_cap);
2827         if (bHwLDPCSupport)
2828         {
2829                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT4))
2830                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_RX);
2831         }
2832         rtw_hal_get_def_var(padapter, HAL_DEF_TX_LDPC, (u8 *)&bHwLDPCSupport);
2833         if (bHwLDPCSupport)
2834         {
2835                 if (TEST_FLAG(pregistrypriv->ldpc_cap, BIT5))
2836                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_TX);
2837         }
2838         if (phtpriv->ldpc_cap)
2839                 DBG_871X("[HT] Support LDPC = 0x%02X\n", phtpriv->ldpc_cap);
2840
2841         /*  STBC */
2842         rtw_hal_get_def_var(padapter, HAL_DEF_TX_STBC, (u8 *)&bHwSTBCSupport);
2843         CLEAR_FLAGS(phtpriv->stbc_cap);
2844         if (bHwSTBCSupport)
2845         {
2846                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT5))
2847                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX);
2848         }
2849         rtw_hal_get_def_var(padapter, HAL_DEF_RX_STBC, (u8 *)&bHwSTBCSupport);
2850         if (bHwSTBCSupport)
2851         {
2852                 if (TEST_FLAG(pregistrypriv->stbc_cap, BIT4))
2853                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX);
2854         }
2855         if (phtpriv->stbc_cap)
2856                 DBG_871X("[HT] Support STBC = 0x%02X\n", phtpriv->stbc_cap);
2857
2858         /*  Beamforming setting */
2859         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMER, (u8 *)&bHwSupportBeamformer);
2860         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMEE, (u8 *)&bHwSupportBeamformee);
2861         CLEAR_FLAGS(phtpriv->beamform_cap);
2862         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT4) && bHwSupportBeamformer)
2863         {
2864                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE);
2865                 DBG_871X("[HT] Support Beamformer\n");
2866         }
2867         if (TEST_FLAG(pregistrypriv->beamform_cap, BIT5) && bHwSupportBeamformee)
2868         {
2869                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE);
2870                 DBG_871X("[HT] Support Beamformee\n");
2871         }
2872 }
2873
2874 void rtw_build_wmm_ie_ht(struct adapter *padapter, u8 *out_ie, uint *pout_len)
2875 {
2876         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
2877         int out_len;
2878         u8 *pframe;
2879
2880         if (padapter->mlmepriv.qospriv.qos_option == 0)
2881         {
2882                 out_len = *pout_len;
2883                 pframe = rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_,
2884                                                         _WMM_IE_Length_, WMM_IE, pout_len);
2885
2886                 padapter->mlmepriv.qospriv.qos_option = 1;
2887         }
2888 }
2889
2890 /* the fucntion is >= passive_level */
2891 unsigned int rtw_restructure_ht_ie(struct adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len, u8 channel)
2892 {
2893         u32 ielen, out_len;
2894         enum HT_CAP_AMPDU_FACTOR max_rx_ampdu_factor;
2895         unsigned char *p, *pframe;
2896         struct rtw_ieee80211_ht_cap ht_capie;
2897         u8 cbw40_enable = 0, stbc_rx_enable = 0, rf_type = 0, operation_bw = 0;
2898         struct registry_priv *pregistrypriv = &padapter->registrypriv;
2899         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2900         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
2901         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2902
2903         phtpriv->ht_option = false;
2904
2905         out_len = *pout_len;
2906
2907         memset(&ht_capie, 0, sizeof(struct rtw_ieee80211_ht_cap));
2908
2909         ht_capie.cap_info = cpu_to_le16(IEEE80211_HT_CAP_DSSSCCK40);
2910
2911         if (phtpriv->sgi_20m)
2912                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_20);
2913
2914         /* Get HT BW */
2915         if (in_ie == NULL) {
2916                 /* TDLS: TODO 20/40 issue */
2917                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
2918                         operation_bw = padapter->mlmeextpriv.cur_bwmode;
2919                         if (operation_bw > CHANNEL_WIDTH_40)
2920                                 operation_bw = CHANNEL_WIDTH_40;
2921                 } else
2922                         /* TDLS: TODO 40? */
2923                         operation_bw = CHANNEL_WIDTH_40;
2924         } else {
2925                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
2926                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
2927                         struct HT_info_element *pht_info = (struct HT_info_element *)(p+2);
2928                         if (pht_info->infos[0] & BIT(2)) {
2929                                 switch (pht_info->infos[0] & 0x3) {
2930                                 case 1:
2931                                 case 3:
2932                                         operation_bw = CHANNEL_WIDTH_40;
2933                                         break;
2934                                 default:
2935                                         operation_bw = CHANNEL_WIDTH_20;
2936                                         break;
2937                                 }
2938                         } else {
2939                                 operation_bw = CHANNEL_WIDTH_20;
2940                         }
2941                 }
2942         }
2943
2944         /* to disable 40M Hz support while gd_bw_40MHz_en = 0 */
2945         if (channel > 14) {
2946                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
2947                         cbw40_enable = 1;
2948         } else {
2949                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
2950                         cbw40_enable = 1;
2951         }
2952
2953         if ((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) {
2954                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH);
2955                 if (phtpriv->sgi_40m)
2956                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SGI_40);
2957         }
2958
2959         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX))
2960                 ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_TX_STBC);
2961
2962         /* todo: disable SM power save mode */
2963         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_SM_PS);
2964
2965         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX)) {
2966                 if ((channel <= 14 && pregistrypriv->rx_stbc == 0x1) || /* enable for 2.4GHz */
2967                         (pregistrypriv->wifi_spec == 1)) {
2968                         stbc_rx_enable = 1;
2969                         DBG_871X("declare supporting RX STBC\n");
2970                 }
2971         }
2972
2973         /* fill default supported_mcs_set */
2974         memcpy(ht_capie.supp_mcs_set, pmlmeext->default_supported_mcs_set, 16);
2975
2976         /* update default supported_mcs_set */
2977         rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
2978
2979         switch (rf_type) {
2980         case RF_1T1R:
2981                 if (stbc_rx_enable)
2982                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_1R);/* RX STBC One spatial stream */
2983
2984                         set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_1R);
2985                         break;
2986
2987         case RF_2T2R:
2988         case RF_1T2R:
2989         default:
2990                 if (stbc_rx_enable)
2991                         ht_capie.cap_info |= cpu_to_le16(IEEE80211_HT_CAP_RX_STBC_2R);/* RX STBC two spatial stream */
2992
2993                 #ifdef CONFIG_DISABLE_MCS13TO15
2994                 if (((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) && (pregistrypriv->wifi_spec!= 1))
2995                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R_13TO15_OFF);
2996                 else
2997                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
2998                 #else /* CONFIG_DISABLE_MCS13TO15 */
2999                         set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);
3000                 #endif /* CONFIG_DISABLE_MCS13TO15 */
3001                 break;
3002         }
3003
3004         {
3005                 u32 rx_packet_offset, max_recvbuf_sz;
3006                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
3007                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
3008         }
3009
3010         if (padapter->driver_rx_ampdu_factor != 0xFF)
3011                 max_rx_ampdu_factor =
3012                   (enum HT_CAP_AMPDU_FACTOR)padapter->driver_rx_ampdu_factor;
3013         else
3014                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR,
3015                                     &max_rx_ampdu_factor);
3016
3017         /* rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor); */
3018         ht_capie.ampdu_params_info = (max_rx_ampdu_factor&0x03);
3019
3020         if (padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
3021                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&(0x07<<2));
3022         else
3023                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
3024
3025         pframe = rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_,
3026                                                 sizeof(struct rtw_ieee80211_ht_cap), (unsigned char*)&ht_capie, pout_len);
3027
3028         phtpriv->ht_option = true;
3029
3030         if (in_ie!= NULL)
3031         {
3032                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
3033                 if (p && (ielen ==sizeof(struct ieee80211_ht_addt_info)))
3034                 {
3035                         out_len = *pout_len;
3036                         pframe = rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2 , pout_len);
3037                 }
3038         }
3039
3040         return (phtpriv->ht_option);
3041
3042 }
3043
3044 /* the fucntion is > passive_level (in critical_section) */
3045 void rtw_update_ht_cap(struct adapter *padapter, u8 *pie, uint ie_len, u8 channel)
3046 {
3047         u8 *p, max_ampdu_sz;
3048         int len;
3049         /* struct sta_info *bmc_sta, *psta; */
3050         struct rtw_ieee80211_ht_cap *pht_capie;
3051         struct ieee80211_ht_addt_info *pht_addtinfo;
3052         /* struct recv_reorder_ctrl *preorder_ctrl; */
3053         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3054         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
3055         /* struct recv_priv *precvpriv = &padapter->recvpriv; */
3056         struct registry_priv *pregistrypriv = &padapter->registrypriv;
3057         /* struct wlan_network *pcur_network = &(pmlmepriv->cur_network);; */
3058         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
3059         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
3060         u8 cbw40_enable = 0;
3061
3062
3063         if (!phtpriv->ht_option)
3064                 return;
3065
3066         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
3067                 return;
3068
3069         DBG_871X("+rtw_update_ht_cap()\n");
3070
3071         /* maybe needs check if ap supports rx ampdu. */
3072         if ((phtpriv->ampdu_enable ==false) && (pregistrypriv->ampdu_enable == 1))
3073         {
3074                 if (pregistrypriv->wifi_spec == 1)
3075                 {
3076                         /* remove this part because testbed AP should disable RX AMPDU */
3077                         /* phtpriv->ampdu_enable = false; */
3078                         phtpriv->ampdu_enable = true;
3079                 }
3080                 else
3081                 {
3082                         phtpriv->ampdu_enable = true;
3083                 }
3084         }
3085         else if (pregistrypriv->ampdu_enable ==2)
3086         {
3087                 /* remove this part because testbed AP should disable RX AMPDU */
3088                 /* phtpriv->ampdu_enable = true; */
3089         }
3090
3091
3092         /* check Max Rx A-MPDU Size */
3093         len = 0;
3094         p = rtw_get_ie(pie+sizeof (struct ndis_802_11_fix_ie), _HT_CAPABILITY_IE_, &len, ie_len-sizeof (struct ndis_802_11_fix_ie));
3095         if (p && len>0)
3096         {
3097                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);
3098                 max_ampdu_sz = (pht_capie->ampdu_params_info & IEEE80211_HT_CAP_AMPDU_FACTOR);
3099                 max_ampdu_sz = 1 << (max_ampdu_sz+3); /*  max_ampdu_sz (kbytes); */
3100
3101                 /* DBG_871X("rtw_update_ht_cap(): max_ampdu_sz =%d\n", max_ampdu_sz); */
3102                 phtpriv->rx_ampdu_maxlen = max_ampdu_sz;
3103
3104         }
3105
3106
3107         len = 0;
3108         p = rtw_get_ie(pie+sizeof (struct ndis_802_11_fix_ie), _HT_ADD_INFO_IE_, &len, ie_len-sizeof (struct ndis_802_11_fix_ie));
3109         if (p && len>0)
3110         {
3111                 pht_addtinfo = (struct ieee80211_ht_addt_info *)(p+2);
3112                 /* todo: */
3113         }
3114
3115         if (channel > 14) {
3116                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
3117                         cbw40_enable = 1;
3118         } else {
3119                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
3120                         cbw40_enable = 1;
3121         }
3122
3123         /* update cur_bwmode & cur_ch_offset */
3124         if ((cbw40_enable) &&
3125             (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
3126               BIT(1)) && (pmlmeinfo->HT_info.infos[0] & BIT(2))) {
3127                 int i;
3128                 u8 rf_type;
3129
3130                 rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
3131
3132                 /* update the MCS set */
3133                 for (i = 0; i < 16; i++)
3134                         pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= pmlmeext->default_supported_mcs_set[i];
3135
3136                 /* update the MCS rates */
3137                 switch (rf_type)
3138                 {
3139                         case RF_1T1R:
3140                         case RF_1T2R:
3141                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_1R);
3142                                 break;
3143                         case RF_2T2R:
3144                         default:
3145 #ifdef CONFIG_DISABLE_MCS13TO15
3146                                 if (pmlmeext->cur_bwmode == CHANNEL_WIDTH_40 && pregistrypriv->wifi_spec != 1)
3147                                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R_13TO15_OFF);
3148                                 else
3149                                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
3150 #else /* CONFIG_DISABLE_MCS13TO15 */
3151                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
3152 #endif /* CONFIG_DISABLE_MCS13TO15 */
3153                 }
3154
3155                 /* switch to the 40M Hz mode accoring to the AP */
3156                 /* pmlmeext->cur_bwmode = CHANNEL_WIDTH_40; */
3157                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3))
3158                 {
3159                         case EXTCHNL_OFFSET_UPPER:
3160                                 pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
3161                                 break;
3162
3163                         case EXTCHNL_OFFSET_LOWER:
3164                                 pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
3165                                 break;
3166
3167                         default:
3168                                 pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
3169                                 break;
3170                 }
3171         }
3172
3173         /*  */
3174         /*  Config SM Power Save setting */
3175         /*  */
3176         pmlmeinfo->SM_PS =
3177                 (le16_to_cpu(pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info) &
3178                  0x0C) >> 2;
3179         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
3180         {
3181                 DBG_871X("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
3182         }
3183
3184         /*  */
3185         /*  Config current HT Protection mode. */
3186         /*  */
3187         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
3188 }
3189
3190 void rtw_issue_addbareq_cmd(struct adapter *padapter, struct xmit_frame *pxmitframe)
3191 {
3192         u8 issued;
3193         int priority;
3194         struct sta_info *psta = NULL;
3195         struct ht_priv *phtpriv;
3196         struct pkt_attrib *pattrib =&pxmitframe->attrib;
3197         s32 bmcst = IS_MCAST(pattrib->ra);
3198
3199         /* if (bmcst || (padapter->mlmepriv.LinkDetectInfo.bTxBusyTraffic == false)) */
3200         if (bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod<100))
3201                 return;
3202
3203         priority = pattrib->priority;
3204
3205         psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
3206         if (pattrib->psta != psta)
3207         {
3208                 DBG_871X("%s, pattrib->psta(%p) != psta(%p)\n", __func__, pattrib->psta, psta);
3209                 return;
3210         }
3211
3212         if (psta == NULL)
3213         {
3214                 DBG_871X("%s, psta ==NUL\n", __func__);
3215                 return;
3216         }
3217
3218         if (!(psta->state &_FW_LINKED))
3219         {
3220                 DBG_871X("%s, psta->state(0x%x) != _FW_LINKED\n", __func__, psta->state);
3221                 return;
3222         }
3223
3224
3225         phtpriv = &psta->htpriv;
3226
3227         if ((phtpriv->ht_option ==true) && (phtpriv->ampdu_enable ==true))
3228         {
3229                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
3230                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
3231
3232                 if (0 ==issued)
3233                 {
3234                         DBG_871X("rtw_issue_addbareq_cmd, p =%d\n", priority);
3235                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
3236                         rtw_addbareq_cmd(padapter, (u8) priority, pattrib->ra);
3237                 }
3238         }
3239
3240 }
3241
3242 void rtw_append_exented_cap(struct adapter *padapter, u8 *out_ie, uint *pout_len)
3243 {
3244         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3245         struct ht_priv  *phtpriv = &pmlmepriv->htpriv;
3246         u8 cap_content[8] = {0};
3247         u8 *pframe;
3248
3249
3250         if (phtpriv->bss_coexist) {
3251                 SET_EXT_CAPABILITY_ELE_BSS_COEXIST(cap_content, 1);
3252         }
3253
3254         pframe = rtw_set_ie(out_ie+*pout_len, EID_EXTCapability, 8, cap_content , pout_len);
3255 }
3256
3257 inline void rtw_set_to_roam(struct adapter *adapter, u8 to_roam)
3258 {
3259         if (to_roam == 0)
3260                 adapter->mlmepriv.to_join = false;
3261         adapter->mlmepriv.to_roam = to_roam;
3262 }
3263
3264 inline u8 rtw_dec_to_roam(struct adapter *adapter)
3265 {
3266         adapter->mlmepriv.to_roam--;
3267         return adapter->mlmepriv.to_roam;
3268 }
3269
3270 inline u8 rtw_to_roam(struct adapter *adapter)
3271 {
3272         return adapter->mlmepriv.to_roam;
3273 }
3274
3275 void rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3276 {
3277         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3278
3279         spin_lock_bh(&pmlmepriv->lock);
3280         _rtw_roaming(padapter, tgt_network);
3281         spin_unlock_bh(&pmlmepriv->lock);
3282 }
3283 void _rtw_roaming(struct adapter *padapter, struct wlan_network *tgt_network)
3284 {
3285         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3286         struct wlan_network *cur_network = &pmlmepriv->cur_network;
3287         int do_join_r;
3288
3289         if (0 < rtw_to_roam(padapter)) {
3290                 DBG_871X("roaming from %s("MAC_FMT"), length:%d\n",
3291                                 cur_network->network.Ssid.Ssid, MAC_ARG(cur_network->network.MacAddress),
3292                                 cur_network->network.Ssid.SsidLength);
3293                 memcpy(&pmlmepriv->assoc_ssid, &cur_network->network.Ssid, sizeof(struct ndis_802_11_ssid));
3294
3295                 pmlmepriv->assoc_by_bssid = false;
3296
3297                 while (1) {
3298                         if (_SUCCESS ==(do_join_r =rtw_do_join(padapter))) {
3299                                 break;
3300                         } else {
3301                                 DBG_871X("roaming do_join return %d\n", do_join_r);
3302                                 rtw_dec_to_roam(padapter);
3303
3304                                 if (rtw_to_roam(padapter) > 0) {
3305                                         continue;
3306                                 } else {
3307                                         DBG_871X("%s(%d) -to roaming fail, indicate_disconnect\n", __func__, __LINE__);
3308                                         rtw_indicate_disconnect(padapter);
3309                                         break;
3310                                 }
3311                         }
3312                 }
3313         }
3314
3315 }
3316
3317 sint rtw_linked_check(struct adapter *padapter)
3318 {
3319         if ((check_fwstate(&padapter->mlmepriv, WIFI_AP_STATE) == true) ||
3320                         (check_fwstate(&padapter->mlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE) == true))
3321         {
3322                 if (padapter->stapriv.asoc_sta_count > 2)
3323                         return true;
3324         }
3325         else
3326         {       /* Station mode */
3327                 if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == true)
3328                         return true;
3329         }
3330         return false;
3331 }