Merge branch 'linux-linaro-lsk-v4.4-android' of git://git.linaro.org/kernel/linux...
[firefly-linux-kernel-4.4.55.git] / drivers / net / wireless / rockchip_wlan / rtl8723bs / os_dep / linux / ioctl_linux.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2012 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  * You should have received a copy of the GNU General Public License along with
15  * this program; if not, write to the Free Software Foundation, Inc.,
16  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
17  *
18  *
19  ******************************************************************************/
20 #define _IOCTL_LINUX_C_
21
22 #include <drv_types.h>
23
24 //#ifdef CONFIG_MP_INCLUDED
25 #include <rtw_mp_ioctl.h>
26 #include "../../hal/OUTSRC/phydm_precomp.h"
27 //#endif
28
29 #if defined(CONFIG_RTL8723A)
30 #include "rtl8723a_hal.h"
31 #include <rtw_bt_mp.h>
32 #endif
33
34 #if defined(CONFIG_RTL8723B)
35 #include <rtw_bt_mp.h>
36 #endif
37
38 #if (LINUX_VERSION_CODE < KERNEL_VERSION(2,6,27))
39 #define  iwe_stream_add_event(a, b, c, d, e)  iwe_stream_add_event(b, c, d, e)
40 #define  iwe_stream_add_point(a, b, c, d, e)  iwe_stream_add_point(b, c, d, e)
41 #endif
42
43 #ifdef CONFIG_80211N_HT
44 extern int rtw_ht_enable;
45 #endif
46
47
48 #define RTL_IOCTL_WPA_SUPPLICANT        SIOCIWFIRSTPRIV+30
49
50 #define SCAN_ITEM_SIZE 768
51 #define MAX_CUSTOM_LEN 64
52 #define RATE_COUNT 4
53
54 #ifdef CONFIG_GLOBAL_UI_PID
55 extern int ui_pid[3];
56 #endif
57
58 // combo scan
59 #define WEXT_CSCAN_AMOUNT 9
60 #define WEXT_CSCAN_BUF_LEN              360
61 #define WEXT_CSCAN_HEADER               "CSCAN S\x01\x00\x00S\x00"
62 #define WEXT_CSCAN_HEADER_SIZE          12
63 #define WEXT_CSCAN_SSID_SECTION         'S'
64 #define WEXT_CSCAN_CHANNEL_SECTION      'C'
65 #define WEXT_CSCAN_NPROBE_SECTION       'N'
66 #define WEXT_CSCAN_ACTV_DWELL_SECTION   'A'
67 #define WEXT_CSCAN_PASV_DWELL_SECTION   'P'
68 #define WEXT_CSCAN_HOME_DWELL_SECTION   'H'
69 #define WEXT_CSCAN_TYPE_SECTION         'T'
70
71
72 extern u8 key_2char2num(u8 hch, u8 lch);
73 extern u8 str_2char2num(u8 hch, u8 lch);
74 extern void macstr2num(u8 *dst, u8 *src);
75 extern u8 convert_ip_addr(u8 hch, u8 mch, u8 lch);
76
77 u32 rtw_rates[] = {1000000,2000000,5500000,11000000,
78         6000000,9000000,12000000,18000000,24000000,36000000,48000000,54000000};
79
80 static const char * const iw_operation_mode[] = 
81
82         "Auto", "Ad-Hoc", "Managed",  "Master", "Repeater", "Secondary", "Monitor" 
83 };
84
85 static int hex2num_i(char c)
86 {
87         if (c >= '0' && c <= '9')
88                 return c - '0';
89         if (c >= 'a' && c <= 'f')
90                 return c - 'a' + 10;
91         if (c >= 'A' && c <= 'F')
92                 return c - 'A' + 10;
93         return -1;
94 }
95
96 static int hex2byte_i(const char *hex)
97 {
98         int a, b;
99         a = hex2num_i(*hex++);
100         if (a < 0)
101                 return -1;
102         b = hex2num_i(*hex++);
103         if (b < 0)
104                 return -1;
105         return (a << 4) | b;
106 }
107
108 /**
109  * hwaddr_aton - Convert ASCII string to MAC address
110  * @txt: MAC address as a string (e.g., "00:11:22:33:44:55")
111  * @addr: Buffer for the MAC address (ETH_ALEN = 6 bytes)
112  * Returns: 0 on success, -1 on failure (e.g., string not a MAC address)
113  */
114 static int hwaddr_aton_i(const char *txt, u8 *addr)
115 {
116         int i;
117
118         for (i = 0; i < 6; i++) {
119                 int a, b;
120
121                 a = hex2num_i(*txt++);
122                 if (a < 0)
123                         return -1;
124                 b = hex2num_i(*txt++);
125                 if (b < 0)
126                         return -1;
127                 *addr++ = (a << 4) | b;
128                 if (i < 5 && *txt++ != ':')
129                         return -1;
130         }
131
132         return 0;
133 }
134
135 static void indicate_wx_custom_event(_adapter *padapter, char *msg)
136 {
137         u8 *buff, *p;
138         union iwreq_data wrqu;
139
140         if (strlen(msg) > IW_CUSTOM_MAX) {
141                 DBG_871X("%s strlen(msg):%zu > IW_CUSTOM_MAX:%u\n", __FUNCTION__ , strlen(msg), IW_CUSTOM_MAX);
142                 return;
143         }
144
145         buff = rtw_zmalloc(IW_CUSTOM_MAX+1);
146         if(!buff)
147                 return;
148
149         _rtw_memcpy(buff, msg, strlen(msg));
150                 
151         _rtw_memset(&wrqu,0,sizeof(wrqu));
152         wrqu.data.length = strlen(msg);
153
154         DBG_871X("%s %s\n", __FUNCTION__, buff);        
155 #ifndef CONFIG_IOCTL_CFG80211
156         wireless_send_event(padapter->pnetdev, IWEVCUSTOM, &wrqu, buff);
157 #endif
158
159         rtw_mfree(buff, IW_CUSTOM_MAX+1);
160
161 }
162
163
164 static void request_wps_pbc_event(_adapter *padapter)
165 {
166         u8 *buff, *p;
167         union iwreq_data wrqu;
168
169
170         buff = rtw_malloc(IW_CUSTOM_MAX);
171         if(!buff)
172                 return;
173                 
174         _rtw_memset(buff, 0, IW_CUSTOM_MAX);
175                 
176         p=buff;
177                 
178         p+=sprintf(p, "WPS_PBC_START.request=TRUE");
179                 
180         _rtw_memset(&wrqu,0,sizeof(wrqu));
181                 
182         wrqu.data.length = p-buff;
183                 
184         wrqu.data.length = (wrqu.data.length<IW_CUSTOM_MAX) ? wrqu.data.length:IW_CUSTOM_MAX;
185
186         DBG_871X("%s\n", __FUNCTION__);
187                 
188 #ifndef CONFIG_IOCTL_CFG80211
189         wireless_send_event(padapter->pnetdev, IWEVCUSTOM, &wrqu, buff);
190 #endif
191
192         if(buff)
193         {
194                 rtw_mfree(buff, IW_CUSTOM_MAX);
195         }
196
197 }
198
199 #ifdef CONFIG_SUPPORT_HW_WPS_PBC
200 void rtw_request_wps_pbc_event(_adapter *padapter)
201 {
202 #ifdef RTK_DMP_PLATFORM
203 #if (LINUX_VERSION_CODE > KERNEL_VERSION(2,6,12))
204         kobject_uevent(&padapter->pnetdev->dev.kobj, KOBJ_NET_PBC);
205 #else
206         kobject_hotplug(&padapter->pnetdev->class_dev.kobj, KOBJ_NET_PBC);
207 #endif
208 #else
209
210         if ( padapter->pid[0] == 0 )
211         {       //      0 is the default value and it means the application monitors the HW PBC doesn't privde its pid to driver.
212                 return;
213         }
214
215         rtw_signal_process(padapter->pid[0], SIGUSR1);
216
217 #endif
218
219         rtw_led_control(padapter, LED_CTL_START_WPS_BOTTON);
220 }
221 #endif//#ifdef CONFIG_SUPPORT_HW_WPS_PBC
222
223 void indicate_wx_scan_complete_event(_adapter *padapter)
224 {       
225         union iwreq_data wrqu;
226         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;     
227
228         _rtw_memset(&wrqu, 0, sizeof(union iwreq_data));
229
230         //DBG_871X("+rtw_indicate_wx_scan_complete_event\n");
231 #ifndef CONFIG_IOCTL_CFG80211
232         wireless_send_event(padapter->pnetdev, SIOCGIWSCAN, &wrqu, NULL);
233 #endif
234 }
235
236
237 void rtw_indicate_wx_assoc_event(_adapter *padapter)
238 {       
239         union iwreq_data wrqu;
240         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
241         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
242         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
243         WLAN_BSSID_EX           *pnetwork = (WLAN_BSSID_EX*)(&(pmlmeinfo->network));
244
245         _rtw_memset(&wrqu, 0, sizeof(union iwreq_data));
246         
247         wrqu.ap_addr.sa_family = ARPHRD_ETHER;  
248         
249         if(check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)==_TRUE )
250                 _rtw_memcpy(wrqu.ap_addr.sa_data, pnetwork->MacAddress, ETH_ALEN);
251         else
252                 _rtw_memcpy(wrqu.ap_addr.sa_data, pmlmepriv->cur_network.network.MacAddress, ETH_ALEN);
253
254         DBG_871X_LEVEL(_drv_always_, "assoc success\n");
255 #ifndef CONFIG_IOCTL_CFG80211
256         wireless_send_event(padapter->pnetdev, SIOCGIWAP, &wrqu, NULL);
257 #endif
258 }
259
260 void rtw_indicate_wx_disassoc_event(_adapter *padapter)
261 {       
262         union iwreq_data wrqu;
263
264         _rtw_memset(&wrqu, 0, sizeof(union iwreq_data));
265
266         wrqu.ap_addr.sa_family = ARPHRD_ETHER;
267         _rtw_memset(wrqu.ap_addr.sa_data, 0, ETH_ALEN);
268
269 #ifndef CONFIG_IOCTL_CFG80211
270         DBG_871X_LEVEL(_drv_always_, "indicate disassoc\n");
271         wireless_send_event(padapter->pnetdev, SIOCGIWAP, &wrqu, NULL);
272 #endif
273 }
274
275 /*
276 uint    rtw_is_cckrates_included(u8 *rate)
277 {       
278                 u32     i = 0;                  
279
280                 while(rate[i]!=0)
281                 {               
282                         if  (  (((rate[i]) & 0x7f) == 2)        || (((rate[i]) & 0x7f) == 4) ||         
283                         (((rate[i]) & 0x7f) == 11)  || (((rate[i]) & 0x7f) == 22) )             
284                         return _TRUE;   
285                         i++;
286                 }
287                 
288                 return _FALSE;
289 }
290
291 uint    rtw_is_cckratesonly_included(u8 *rate)
292 {
293         u32 i = 0;
294
295         while(rate[i]!=0)
296         {
297                         if  (  (((rate[i]) & 0x7f) != 2) && (((rate[i]) & 0x7f) != 4) &&
298                                 (((rate[i]) & 0x7f) != 11)  && (((rate[i]) & 0x7f) != 22) )
299                         return _FALSE;          
300                         i++;
301         }
302         
303         return _TRUE;
304 }
305 */
306
307 static int search_p2p_wfd_ie(_adapter *padapter,
308                                 struct iw_request_info* info, struct wlan_network *pnetwork,
309                                 char *start, char *stop)
310 {
311 #ifdef CONFIG_P2P
312         struct wifidirect_info  *pwdinfo = &padapter->wdinfo;
313 #ifdef CONFIG_WFD
314         if ( SCAN_RESULT_ALL == pwdinfo->wfd_info->scan_result_type )
315         {
316
317         }
318         else if ( ( SCAN_RESULT_P2P_ONLY == pwdinfo->wfd_info->scan_result_type ) || 
319                       ( SCAN_RESULT_WFD_TYPE == pwdinfo->wfd_info->scan_result_type ) )
320 #endif // CONFIG_WFD
321         {
322                 if(!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
323                 {
324                         u32     blnGotP2PIE = _FALSE;
325                         
326                         //      User is doing the P2P device discovery
327                         //      The prefix of SSID should be "DIRECT-" and the IE should contains the P2P IE.
328                         //      If not, the driver should ignore this AP and go to the next AP.
329
330                         //      Verifying the SSID
331                         if ( _rtw_memcmp( pnetwork->network.Ssid.Ssid, pwdinfo->p2p_wildcard_ssid, P2P_WILDCARD_SSID_LEN ) )
332                         {
333                                 u32     p2pielen = 0;
334
335                                 //      Verifying the P2P IE
336                                 if (rtw_get_p2p_ie_from_scan_queue(&pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])) 
337                                 {
338                                         blnGotP2PIE = _TRUE;
339                                 }
340                         }
341
342                         if ( blnGotP2PIE == _FALSE )
343                         {
344                                 return _FALSE;
345                         }
346                         
347                 }
348         }
349
350 #ifdef CONFIG_WFD
351         if ( SCAN_RESULT_WFD_TYPE == pwdinfo->wfd_info->scan_result_type )
352         {
353                 u32     blnGotWFD = _FALSE;
354                 u8      wfd_ie[ 128 ] = { 0x00 };
355                 uint    wfd_ielen = 0;
356                 
357                 if ( rtw_get_wfd_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength,  wfd_ie, &wfd_ielen, pnetwork->network.Reserved[0]) )
358                 {
359                         u8      wfd_devinfo[ 6 ] = { 0x00 };
360                         uint    wfd_devlen = 6;
361                         
362                         if ( rtw_get_wfd_attr_content( wfd_ie, wfd_ielen, WFD_ATTR_DEVICE_INFO, wfd_devinfo, &wfd_devlen) )
363                         {
364                                 if ( pwdinfo->wfd_info->wfd_device_type == WFD_DEVINFO_PSINK )
365                                 {
366                                         //      the first two bits will indicate the WFD device type
367                                         if ( ( wfd_devinfo[ 1 ] & 0x03 ) == WFD_DEVINFO_SOURCE )
368                                         {
369                                                 //      If this device is Miracast PSink device, the scan reuslt should just provide the Miracast source.
370                                                 blnGotWFD = _TRUE;
371                                         }
372                                 }
373                                 else if ( pwdinfo->wfd_info->wfd_device_type == WFD_DEVINFO_SOURCE )
374                                 {
375                                         //      the first two bits will indicate the WFD device type
376                                         if ( ( wfd_devinfo[ 1 ] & 0x03 ) == WFD_DEVINFO_PSINK )
377                                         {
378                                                 //      If this device is Miracast source device, the scan reuslt should just provide the Miracast PSink.
379                                                 //      Todo: How about the SSink?!
380                                                 blnGotWFD = _TRUE;
381                                         }
382                                 }
383                         }
384                 }
385                 
386                 if ( blnGotWFD == _FALSE )
387                 {
388                         return _FALSE;
389                 }
390         }
391 #endif // CONFIG_WFD
392
393 #endif //CONFIG_P2P
394         return _TRUE;
395 }
396  static inline char *iwe_stream_mac_addr_proess(_adapter *padapter,
397                                 struct iw_request_info* info, struct wlan_network *pnetwork,
398                                 char *start, char *stop,struct iw_event *iwe)
399 {       
400         /*  AP MAC address  */
401         iwe->cmd = SIOCGIWAP;
402         iwe->u.ap_addr.sa_family = ARPHRD_ETHER;
403
404         _rtw_memcpy(iwe->u.ap_addr.sa_data, pnetwork->network.MacAddress, ETH_ALEN);
405         start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_ADDR_LEN);   
406         return start;
407 }
408  static inline char * iwe_stream_essid_proess(_adapter *padapter,
409                                 struct iw_request_info* info, struct wlan_network *pnetwork,
410                                 char *start, char *stop,struct iw_event *iwe)
411 {
412         
413         /* Add the ESSID */
414         iwe->cmd = SIOCGIWESSID;
415         iwe->u.data.flags = 1;  
416         iwe->u.data.length = min((u16)pnetwork->network.Ssid.SsidLength, (u16)32);
417         start = iwe_stream_add_point(info, start, stop, iwe, pnetwork->network.Ssid.Ssid);              
418         return start;
419 }
420
421  static inline char * iwe_stream_chan_process(_adapter *padapter,
422                                 struct iw_request_info* info, struct wlan_network *pnetwork,
423                                 char *start, char *stop,struct iw_event *iwe)
424 {
425         if(pnetwork->network.Configuration.DSConfig<1 /*|| pnetwork->network.Configuration.DSConfig>14*/)
426                 pnetwork->network.Configuration.DSConfig = 1;
427
428          /* Add frequency/channel */
429         iwe->cmd = SIOCGIWFREQ;
430         iwe->u.freq.m = rtw_ch2freq(pnetwork->network.Configuration.DSConfig) * 100000;
431         iwe->u.freq.e = 1;
432         iwe->u.freq.i = pnetwork->network.Configuration.DSConfig;
433         start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_FREQ_LEN);
434         return start;
435 }
436  static inline char * iwe_stream_mode_process(_adapter *padapter,
437                                 struct iw_request_info* info, struct wlan_network *pnetwork,
438                                 char *start, char *stop,struct iw_event *iwe,u16 cap)
439 {
440         /* Add mode */
441         if(cap & (WLAN_CAPABILITY_IBSS |WLAN_CAPABILITY_BSS)){
442                 iwe->cmd = SIOCGIWMODE;
443                 if (cap & WLAN_CAPABILITY_BSS)
444                         iwe->u.mode = IW_MODE_MASTER;
445                 else
446                         iwe->u.mode = IW_MODE_ADHOC;
447
448                 start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_UINT_LEN);
449         }
450         return start;
451  }
452  static inline char * iwe_stream_encryption_process(_adapter *padapter,
453                                 struct iw_request_info* info, struct wlan_network *pnetwork,
454                                 char *start, char *stop,struct iw_event *iwe,u16 cap)
455 {       
456
457         /* Add encryption capability */
458         iwe->cmd = SIOCGIWENCODE;
459         if (cap & WLAN_CAPABILITY_PRIVACY)
460                 iwe->u.data.flags = IW_ENCODE_ENABLED | IW_ENCODE_NOKEY;
461         else
462                 iwe->u.data.flags = IW_ENCODE_DISABLED;
463         iwe->u.data.length = 0;
464         start = iwe_stream_add_point(info, start, stop, iwe, pnetwork->network.Ssid.Ssid);
465         return start;
466
467 }       
468
469  static inline char * iwe_stream_protocol_process(_adapter *padapter,
470                                 struct iw_request_info* info, struct wlan_network *pnetwork,
471                                 char *start, char *stop,struct iw_event *iwe)
472  {
473         u16 ht_cap=_FALSE,vht_cap = _FALSE;
474         u32 ht_ielen = 0, vht_ielen = 0;
475         char *p;
476         u8 ie_offset = (pnetwork->network.Reserved[0] == 2? 0:12);// Probe Request      
477                 
478         //parsing HT_CAP_IE     
479         p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength-ie_offset); 
480         if(p && ht_ielen>0)             
481                 ht_cap = _TRUE;                 
482
483         #ifdef CONFIG_80211AC_VHT
484         //parsing VHT_CAP_IE
485         p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], EID_VHTCapability, &vht_ielen, pnetwork->network.IELength-ie_offset);
486         if(p && vht_ielen>0)
487                 vht_cap = _TRUE;        
488         #endif
489          /* Add the protocol name */
490         iwe->cmd = SIOCGIWNAME;
491         if ((rtw_is_cckratesonly_included((u8*)&pnetwork->network.SupportedRates)) == _TRUE)            
492         {
493                 if(ht_cap == _TRUE)
494                         snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11bn");
495                 else
496                         snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11b");
497         }       
498         else if ((rtw_is_cckrates_included((u8*)&pnetwork->network.SupportedRates)) == _TRUE)   
499         {
500                 if(ht_cap == _TRUE)
501                         snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11bgn");
502                 else
503                         snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11bg");
504         }       
505         else
506         {
507                 if(pnetwork->network.Configuration.DSConfig > 14)
508                 {
509                         #ifdef CONFIG_80211AC_VHT
510                         if(vht_cap == _TRUE){
511                                 snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11AC");
512                         }
513                         else 
514                         #endif  
515                         {
516                                 if(ht_cap == _TRUE)
517                                         snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11an");
518                                 else
519                                         snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11a");
520                         }
521                 }
522                 else
523                 {
524                         if(ht_cap == _TRUE)
525                                 snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11gn");
526                         else
527                                 snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11g");
528                 }
529         }
530         start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_CHAR_LEN);
531         return start;
532  }
533                                 
534  static inline char * iwe_stream_rate_process(_adapter *padapter,
535                                 struct iw_request_info* info, struct wlan_network *pnetwork,
536                                 char *start, char *stop,struct iw_event *iwe)
537 {
538         u32 ht_ielen = 0, vht_ielen = 0;
539         char *p;
540         u16 max_rate=0, rate, ht_cap=_FALSE, vht_cap = _FALSE;
541         u32 i = 0;              
542         u8 bw_40MHz=0, short_GI=0, bw_160MHz=0, vht_highest_rate = 0;
543         u16 mcs_rate=0, vht_data_rate=0;
544         char custom[MAX_CUSTOM_LEN]={0};
545         u8 ie_offset = (pnetwork->network.Reserved[0] == 2? 0:12);// Probe Request      
546         
547         //parsing HT_CAP_IE     
548         p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength-ie_offset); 
549         if(p && ht_ielen>0)
550         {
551                 struct rtw_ieee80211_ht_cap *pht_capie;
552                 ht_cap = _TRUE;                 
553                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);               
554                 _rtw_memcpy(&mcs_rate , pht_capie->supp_mcs_set, 2);
555                 bw_40MHz = (pht_capie->cap_info&IEEE80211_HT_CAP_SUP_WIDTH) ? 1:0;
556                 short_GI = (pht_capie->cap_info&(IEEE80211_HT_CAP_SGI_20|IEEE80211_HT_CAP_SGI_40)) ? 1:0;
557         }
558
559 #ifdef CONFIG_80211AC_VHT
560         //parsing VHT_CAP_IE
561         p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], EID_VHTCapability, &vht_ielen, pnetwork->network.IELength-ie_offset);
562         if(p && vht_ielen>0)
563         {
564                 u8      mcs_map[2];
565
566                 vht_cap = _TRUE;                
567                 bw_160MHz = GET_VHT_CAPABILITY_ELE_CHL_WIDTH(p+2);
568                 if(bw_160MHz)
569                         short_GI = GET_VHT_CAPABILITY_ELE_SHORT_GI160M(p+2);
570                 else
571                         short_GI = GET_VHT_CAPABILITY_ELE_SHORT_GI80M(p+2);
572
573                 _rtw_memcpy(mcs_map, GET_VHT_CAPABILITY_ELE_TX_MCS(p+2), 2);
574
575                 vht_highest_rate = rtw_get_vht_highest_rate(mcs_map);
576                 vht_data_rate = rtw_vht_mcs_to_data_rate(CHANNEL_WIDTH_80, short_GI, vht_highest_rate);
577         }
578 #endif  
579         
580         /*Add basic and extended rates */       
581         p = custom;
582         p += snprintf(p, MAX_CUSTOM_LEN - (p - custom), " Rates (Mb/s): ");
583         while(pnetwork->network.SupportedRates[i]!=0)
584         {
585                 rate = pnetwork->network.SupportedRates[i]&0x7F; 
586                 if (rate > max_rate)
587                         max_rate = rate;
588                 p += snprintf(p, MAX_CUSTOM_LEN - (p - custom),
589                               "%d%s ", rate >> 1, (rate & 1) ? ".5" : "");
590                 i++;
591         }
592 #ifdef CONFIG_80211AC_VHT
593         if(vht_cap == _TRUE) {
594                 max_rate = vht_data_rate;
595         }
596         else
597 #endif          
598         if(ht_cap == _TRUE)
599         {
600                 if(mcs_rate&0x8000)//MCS15
601                 {
602                         max_rate = (bw_40MHz) ? ((short_GI)?300:270):((short_GI)?144:130);
603                         
604                 }
605                 else if(mcs_rate&0x0080)//MCS7
606                 {
607                         max_rate = (bw_40MHz) ? ((short_GI)?150:135):((short_GI)?72:65);
608                 }
609                 else//default MCS7
610                 {
611                         //DBG_871X("wx_get_scan, mcs_rate_bitmap=0x%x\n", mcs_rate);
612                         max_rate = (bw_40MHz) ? ((short_GI)?150:135):((short_GI)?72:65);
613                 }
614
615                 max_rate = max_rate*2;//Mbps/2;         
616         }
617
618         iwe->cmd = SIOCGIWRATE;
619         iwe->u.bitrate.fixed = iwe->u.bitrate.disabled = 0;
620         iwe->u.bitrate.value = max_rate * 500000;
621         start =iwe_stream_add_event(info, start, stop, iwe, IW_EV_PARAM_LEN);
622         return start ;
623 }
624
625 static inline char * iwe_stream_wpa_wpa2_process(_adapter *padapter,
626                                 struct iw_request_info* info, struct wlan_network *pnetwork,
627                                 char *start, char *stop,struct iw_event *iwe)
628 {
629         int buf_size = MAX_WPA_IE_LEN*2;
630         //u8 pbuf[buf_size]={0};        
631         u8 *pbuf = rtw_zmalloc(buf_size);
632
633         u8 wpa_ie[255]={0},rsn_ie[255]={0};
634         u16 i, wpa_len=0,rsn_len=0;
635         u8 *p;
636         sint out_len=0;
637                 
638         
639         if(pbuf){
640                 p=pbuf; 
641         
642                 //parsing WPA/WPA2 IE
643                 if (pnetwork->network.Reserved[0] != 2) // Probe Request
644                 {       
645                         out_len=rtw_get_sec_ie(pnetwork->network.IEs ,pnetwork->network.IELength,rsn_ie,&rsn_len,wpa_ie,&wpa_len);
646                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: ssid=%s\n",pnetwork->network.Ssid.Ssid));
647                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: wpa_len=%d rsn_len=%d\n",wpa_len,rsn_len));
648
649                         if (wpa_len > 0){
650                                 
651                                 _rtw_memset(pbuf, 0, buf_size);
652                                 p += sprintf(p, "wpa_ie=");
653                                 for (i = 0; i < wpa_len; i++) {
654                                         p += sprintf(p, "%02x", wpa_ie[i]);
655                                 }
656
657                                 if (wpa_len > 100) {
658                                         printk("-----------------Len %d----------------\n", wpa_len);
659                                         for (i = 0; i < wpa_len; i++) {
660                                                 printk("%02x ", wpa_ie[i]);
661                                         }
662                                         printk("\n");
663                                         printk("-----------------Len %d----------------\n", wpa_len);
664                                 }
665                 
666                                 _rtw_memset(iwe, 0, sizeof(*iwe));
667                                 iwe->cmd = IWEVCUSTOM;
668                                 iwe->u.data.length = strlen(pbuf);
669                                 start = iwe_stream_add_point(info, start, stop, iwe,pbuf);
670                                 
671                                 _rtw_memset(iwe, 0, sizeof(*iwe));
672                                 iwe->cmd =IWEVGENIE;
673                                 iwe->u.data.length = wpa_len;
674                                 start = iwe_stream_add_point(info, start, stop, iwe, wpa_ie);                   
675                         }
676                         if (rsn_len > 0){
677                                 
678                                 _rtw_memset(pbuf, 0, buf_size);
679                                 p += sprintf(p, "rsn_ie=");
680                                 for (i = 0; i < rsn_len; i++) {
681                                         p += sprintf(p, "%02x", rsn_ie[i]);
682                                 }
683                                 _rtw_memset(iwe, 0, sizeof(*iwe));
684                                 iwe->cmd = IWEVCUSTOM;
685                                 iwe->u.data.length = strlen(pbuf);
686                                 start = iwe_stream_add_point(info, start, stop, iwe,pbuf);
687                         
688                                 _rtw_memset(iwe, 0, sizeof(*iwe));
689                                 iwe->cmd =IWEVGENIE;
690                                 iwe->u.data.length = rsn_len;
691                                 start = iwe_stream_add_point(info, start, stop, iwe, rsn_ie);           
692                         }
693                 }
694         
695                 rtw_mfree(pbuf, buf_size);      
696         }
697         return start;
698 }
699
700 static inline char * iwe_stream_wps_process(_adapter *padapter,
701                                 struct iw_request_info* info, struct wlan_network *pnetwork,
702                                 char *start, char *stop,struct iw_event *iwe)
703 {       
704         //parsing WPS IE
705         uint cnt = 0,total_ielen;       
706         u8 *wpsie_ptr=NULL;
707         uint wps_ielen = 0;             
708         u8 ie_offset = (pnetwork->network.Reserved[0] == 2? 0:12);
709         
710         u8 *ie_ptr = pnetwork->network.IEs + ie_offset;
711         total_ielen= pnetwork->network.IELength - ie_offset;
712
713         if (pnetwork->network.Reserved[0] == 2) // Probe Request
714         {
715                 ie_ptr = pnetwork->network.IEs;
716                 total_ielen = pnetwork->network.IELength;
717         }
718         else     // Beacon or Probe Respones
719         {
720                 ie_ptr = pnetwork->network.IEs + _FIXED_IE_LENGTH_;
721                 total_ielen = pnetwork->network.IELength - _FIXED_IE_LENGTH_;
722         }    
723         while(cnt < total_ielen)
724         {
725                 if(rtw_is_wps_ie(&ie_ptr[cnt], &wps_ielen) && (wps_ielen>2))                    
726                 {
727                         wpsie_ptr = &ie_ptr[cnt];
728                         iwe->cmd =IWEVGENIE;
729                         iwe->u.data.length = (u16)wps_ielen;
730                         start = iwe_stream_add_point(info, start, stop,iwe, wpsie_ptr);                                         
731                 }                       
732                 cnt+=ie_ptr[cnt+1]+2; //goto next
733         }
734         return start;
735 }
736
737 static inline char * iwe_stream_wapi_process(_adapter *padapter,
738                                 struct iw_request_info* info, struct wlan_network *pnetwork,
739                                 char *start, char *stop,struct iw_event *iwe)
740 {
741 #ifdef CONFIG_WAPI_SUPPORT
742         char *p;
743                 
744         if (pnetwork->network.Reserved[0] != 2) // Probe Request
745         {               
746                 sint out_len_wapi=0;
747                 /* here use static for stack size */
748                 static u8 buf_wapi[MAX_WAPI_IE_LEN*2]={0};
749                 static u8 wapi_ie[MAX_WAPI_IE_LEN]={0};
750                 u16 wapi_len=0;
751                 u16  i;
752
753                 out_len_wapi=rtw_get_wapi_ie(pnetwork->network.IEs ,pnetwork->network.IELength,wapi_ie,&wapi_len);
754                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: ssid=%s\n",pnetwork->network.Ssid.Ssid));
755                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: wapi_len=%d \n",wapi_len));
756
757                 DBG_871X("rtw_wx_get_scan: %s ",pnetwork->network.Ssid.Ssid);
758                 DBG_871X("rtw_wx_get_scan: ssid = %d ",wapi_len);
759
760
761                 if (wapi_len > 0)
762                 {
763                         p=buf_wapi;
764                         //_rtw_memset(buf_wapi, 0, MAX_WAPI_IE_LEN*2);
765                         p += sprintf(p, "wapi_ie=");
766                         for (i = 0; i < wapi_len; i++) {
767                                 p += sprintf(p, "%02x", wapi_ie[i]);
768                         }
769
770                         _rtw_memset(iwe, 0, sizeof(*iwe));
771                         iwe->cmd = IWEVCUSTOM;
772                         iwe->u.data.length = strlen(buf_wapi);
773                         start = iwe_stream_add_point(info, start, stop, iwe,buf_wapi);
774
775                         _rtw_memset(iwe, 0, sizeof(*iwe));
776                         iwe->cmd =IWEVGENIE;
777                         iwe->u.data.length = wapi_len;
778                         start = iwe_stream_add_point(info, start, stop, iwe, wapi_ie);
779                 }
780         }
781 #endif//#ifdef CONFIG_WAPI_SUPPORT
782         return start;
783 }
784
785 static inline char *  iwe_stream_rssi_process(_adapter *padapter,
786                                 struct iw_request_info* info, struct wlan_network *pnetwork,
787                                 char *start, char *stop,struct iw_event *iwe)
788 {
789         u8 ss, sq;
790         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
791         
792         /* Add quality statistics */
793         iwe->cmd = IWEVQUAL;
794         iwe->u.qual.updated = IW_QUAL_QUAL_UPDATED | IW_QUAL_LEVEL_UPDATED 
795         #if defined(CONFIG_SIGNAL_DISPLAY_DBM) && defined(CONFIG_BACKGROUND_NOISE_MONITOR)
796                 | IW_QUAL_NOISE_UPDATED
797         #else
798                 | IW_QUAL_NOISE_INVALID
799         #endif
800         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
801                 | IW_QUAL_DBM
802         #endif
803         ;
804
805         if ( check_fwstate(pmlmepriv, _FW_LINKED)== _TRUE &&
806                 is_same_network(&pmlmepriv->cur_network.network, &pnetwork->network, 0)){
807                 ss = padapter->recvpriv.signal_strength;
808                 sq = padapter->recvpriv.signal_qual;
809         } else {
810                 ss = pnetwork->network.PhyInfo.SignalStrength;
811                 sq = pnetwork->network.PhyInfo.SignalQuality;
812         }
813         
814         
815         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
816         iwe->u.qual.level = (u8) translate_percentage_to_dbm(ss);//dbm
817         #else
818         #ifdef CONFIG_SKIP_SIGNAL_SCALE_MAPPING
819         {
820                 /* Do signal scale mapping when using percentage as the unit of signal strength, since the scale mapping is skipped in odm */
821                 
822                 HAL_DATA_TYPE *pHal = GET_HAL_DATA(padapter);
823                 
824                 iwe->u.qual.level = (u8)odm_SignalScaleMapping(&pHal->odmpriv, ss);
825         }
826         #else
827         iwe->u.qual.level = (u8)ss;//%
828         #endif
829         #endif
830         
831         iwe->u.qual.qual = (u8)sq;   // signal quality
832
833         #ifdef CONFIG_PLATFORM_ROCKCHIPS
834         iwe->u.qual.noise = -100; // noise level suggest by zhf@rockchips
835         #else 
836         #if defined(CONFIG_SIGNAL_DISPLAY_DBM) && defined(CONFIG_BACKGROUND_NOISE_MONITOR)
837         {
838                 s16 tmp_noise=0;
839                 rtw_hal_get_odm_var(padapter, HAL_ODM_NOISE_MONITOR,&(pnetwork->network.Configuration.DSConfig), &(tmp_noise));
840                 iwe->u.qual.noise = tmp_noise ;
841         }
842         #else
843         iwe->u.qual.noise = 0; // noise level
844         #endif  
845         #endif //CONFIG_PLATFORM_ROCKCHIPS
846         
847         //DBG_871X("iqual=%d, ilevel=%d, inoise=%d, iupdated=%d\n", iwe.u.qual.qual, iwe.u.qual.level , iwe.u.qual.noise, iwe.u.qual.updated);
848
849         start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_QUAL_LEN);
850         return start;
851 }
852
853 static inline char *  iwe_stream_net_rsv_process(_adapter *padapter,
854                                 struct iw_request_info* info, struct wlan_network *pnetwork,
855                                 char *start, char *stop,struct iw_event *iwe)
856 {       
857         u8 buf[32] = {0};
858         u8 * p,*pos;
859         int len;
860         p = buf;
861         pos = pnetwork->network.Reserved;
862         
863         p += sprintf(p, "fm=%02X%02X", pos[1], pos[0]);
864         _rtw_memset(iwe, 0, sizeof(*iwe));
865         iwe->cmd = IWEVCUSTOM;
866         iwe->u.data.length = strlen(buf);
867         start = iwe_stream_add_point(info, start, stop,iwe, buf);
868         return start;
869 }
870
871 #if 1
872 static char *translate_scan(_adapter *padapter, 
873                                 struct iw_request_info* info, struct wlan_network *pnetwork,
874                                 char *start, char *stop)
875 {       
876         struct iw_event iwe;
877         u16 cap = 0;
878         _rtw_memset(&iwe, 0, sizeof(iwe));
879         
880         if(_FALSE == search_p2p_wfd_ie(padapter,info,pnetwork,start,stop))
881                 return start;
882
883         start = iwe_stream_mac_addr_proess(padapter,info,pnetwork,start,stop,&iwe);     
884         start = iwe_stream_essid_proess(padapter,info,pnetwork,start,stop,&iwe);        
885         start = iwe_stream_protocol_process(padapter,info,pnetwork,start,stop,&iwe);
886         if (pnetwork->network.Reserved[0] == 2) // Probe Request
887         {
888                 cap = 0;
889         }
890         else
891         {
892                 _rtw_memcpy((u8 *)&cap, rtw_get_capability_from_ie(pnetwork->network.IEs), 2);
893                 cap = le16_to_cpu(cap);
894         }
895
896         start = iwe_stream_mode_process(padapter,info,pnetwork,start,stop,&iwe,cap);    
897         start = iwe_stream_chan_process(padapter,info,pnetwork,start,stop,&iwe);        
898         start = iwe_stream_encryption_process(padapter,info,pnetwork,start,stop,&iwe,cap);      
899         start = iwe_stream_rate_process(padapter,info,pnetwork,start,stop,&iwe);        
900         start = iwe_stream_wpa_wpa2_process(padapter,info,pnetwork,start,stop,&iwe);
901         start = iwe_stream_wps_process(padapter,info,pnetwork,start,stop,&iwe);
902         start = iwe_stream_wapi_process(padapter,info,pnetwork,start,stop,&iwe);
903         start = iwe_stream_rssi_process(padapter,info,pnetwork,start,stop,&iwe);
904         start = iwe_stream_net_rsv_process(padapter,info,pnetwork,start,stop,&iwe);     
905         
906         return start;   
907 }
908 #else
909 static char *translate_scan(_adapter *padapter, 
910                                 struct iw_request_info* info, struct wlan_network *pnetwork,
911                                 char *start, char *stop)
912 {
913         struct iw_event iwe;
914         u16 cap;
915         u32 ht_ielen = 0, vht_ielen = 0;
916         char custom[MAX_CUSTOM_LEN];
917         char *p;
918         u16 max_rate=0, rate, ht_cap=_FALSE, vht_cap = _FALSE;
919         u32 i = 0;      
920         char    *current_val;
921         long rssi;
922         u8 bw_40MHz=0, short_GI=0, bw_160MHz=0, vht_highest_rate = 0;
923         u16 mcs_rate=0, vht_data_rate=0;
924         u8 ie_offset = (pnetwork->network.Reserved[0] == 2? 0:12);
925         struct registry_priv *pregpriv = &padapter->registrypriv;
926         
927         if(_FALSE == search_p2p_wfd_ie(padapter,info,pnetwork,start,stop))
928                 return start;
929
930         /*  AP MAC address  */
931         iwe.cmd = SIOCGIWAP;
932         iwe.u.ap_addr.sa_family = ARPHRD_ETHER;
933
934         _rtw_memcpy(iwe.u.ap_addr.sa_data, pnetwork->network.MacAddress, ETH_ALEN);
935         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_ADDR_LEN);
936         
937         /* Add the ESSID */
938         iwe.cmd = SIOCGIWESSID;
939         iwe.u.data.flags = 1;   
940         iwe.u.data.length = min((u16)pnetwork->network.Ssid.SsidLength, (u16)32);
941         start = iwe_stream_add_point(info, start, stop, &iwe, pnetwork->network.Ssid.Ssid);
942
943         //parsing HT_CAP_IE
944         if (pnetwork->network.Reserved[0] == 2) // Probe Request
945         {
946                 p = rtw_get_ie(&pnetwork->network.IEs[0], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength);
947         }
948         else
949         {
950                 p = rtw_get_ie(&pnetwork->network.IEs[12], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength-12);
951         }
952         if(p && ht_ielen>0)
953         {
954                 struct rtw_ieee80211_ht_cap *pht_capie;
955                 ht_cap = _TRUE;                 
956                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);               
957                 _rtw_memcpy(&mcs_rate , pht_capie->supp_mcs_set, 2);
958                 bw_40MHz = (pht_capie->cap_info&IEEE80211_HT_CAP_SUP_WIDTH) ? 1:0;
959                 short_GI = (pht_capie->cap_info&(IEEE80211_HT_CAP_SGI_20|IEEE80211_HT_CAP_SGI_40)) ? 1:0;
960         }
961
962 #ifdef CONFIG_80211AC_VHT
963         //parsing VHT_CAP_IE
964         p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], EID_VHTCapability, &vht_ielen, pnetwork->network.IELength-ie_offset);
965         if(p && vht_ielen>0)
966         {
967                 u8      mcs_map[2];
968
969                 vht_cap = _TRUE;                
970                 bw_160MHz = GET_VHT_CAPABILITY_ELE_CHL_WIDTH(p+2);
971                 if(bw_160MHz)
972                         short_GI = GET_VHT_CAPABILITY_ELE_SHORT_GI160M(p+2);
973                 else
974                         short_GI = GET_VHT_CAPABILITY_ELE_SHORT_GI80M(p+2);
975
976                 _rtw_memcpy(mcs_map, GET_VHT_CAPABILITY_ELE_TX_MCS(p+2), 2);
977
978                 vht_highest_rate = rtw_get_vht_highest_rate(mcs_map);
979                 vht_data_rate = rtw_vht_mcs_to_data_rate(CHANNEL_WIDTH_80, short_GI, vht_highest_rate);
980         }
981 #endif
982
983         /* Add the protocol name */
984         iwe.cmd = SIOCGIWNAME;
985         if ((rtw_is_cckratesonly_included((u8*)&pnetwork->network.SupportedRates)) == _TRUE)            
986         {
987                 if(ht_cap == _TRUE)
988                         snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11bn");
989                 else
990                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11b");
991         }       
992         else if ((rtw_is_cckrates_included((u8*)&pnetwork->network.SupportedRates)) == _TRUE)   
993         {
994                 if(ht_cap == _TRUE)
995                         snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11bgn");
996                 else
997                         snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11bg");
998         }       
999         else
1000         {
1001                 if(pnetwork->network.Configuration.DSConfig > 14)
1002                 {
1003                         if(vht_cap == _TRUE)
1004                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11AC");
1005                         else if(ht_cap == _TRUE)
1006                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11an");
1007                         else
1008                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11a");
1009                 }
1010                 else
1011                 {
1012                         if(ht_cap == _TRUE)
1013                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11gn");
1014                         else
1015                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11g");
1016                 }
1017         }       
1018
1019         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_CHAR_LEN);
1020
1021           /* Add mode */
1022         if (pnetwork->network.Reserved[0] == 2) // Probe Request
1023         {
1024                 cap = 0;
1025         }
1026         else
1027         {
1028         iwe.cmd = SIOCGIWMODE;
1029                 _rtw_memcpy((u8 *)&cap, rtw_get_capability_from_ie(pnetwork->network.IEs), 2);
1030                 cap = le16_to_cpu(cap);
1031         }
1032
1033         if(cap & (WLAN_CAPABILITY_IBSS |WLAN_CAPABILITY_BSS)){
1034                 if (cap & WLAN_CAPABILITY_BSS)
1035                         iwe.u.mode = IW_MODE_MASTER;
1036                 else
1037                         iwe.u.mode = IW_MODE_ADHOC;
1038
1039                 start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_UINT_LEN);
1040         }
1041
1042         if(pnetwork->network.Configuration.DSConfig<1 /*|| pnetwork->network.Configuration.DSConfig>14*/)
1043                 pnetwork->network.Configuration.DSConfig = 1;
1044
1045          /* Add frequency/channel */
1046         iwe.cmd = SIOCGIWFREQ;
1047         iwe.u.freq.m = rtw_ch2freq(pnetwork->network.Configuration.DSConfig) * 100000;
1048         iwe.u.freq.e = 1;
1049         iwe.u.freq.i = pnetwork->network.Configuration.DSConfig;
1050         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_FREQ_LEN);
1051
1052         /* Add encryption capability */
1053         iwe.cmd = SIOCGIWENCODE;
1054         if (cap & WLAN_CAPABILITY_PRIVACY)
1055                 iwe.u.data.flags = IW_ENCODE_ENABLED | IW_ENCODE_NOKEY;
1056         else
1057                 iwe.u.data.flags = IW_ENCODE_DISABLED;
1058         iwe.u.data.length = 0;
1059         start = iwe_stream_add_point(info, start, stop, &iwe, pnetwork->network.Ssid.Ssid);
1060
1061         /*Add basic and extended rates */
1062         max_rate = 0;
1063         p = custom;
1064         p += snprintf(p, MAX_CUSTOM_LEN - (p - custom), " Rates (Mb/s): ");
1065         while(pnetwork->network.SupportedRates[i]!=0)
1066         {
1067                 rate = pnetwork->network.SupportedRates[i]&0x7F; 
1068                 if (rate > max_rate)
1069                         max_rate = rate;
1070                 p += snprintf(p, MAX_CUSTOM_LEN - (p - custom),
1071                               "%d%s ", rate >> 1, (rate & 1) ? ".5" : "");
1072                 i++;
1073         }
1074
1075         if(vht_cap == _TRUE) {
1076                 max_rate = vht_data_rate;
1077         }
1078         else if(ht_cap == _TRUE)
1079         {
1080                 if(mcs_rate&0x8000)//MCS15
1081                 {
1082                         max_rate = (bw_40MHz) ? ((short_GI)?300:270):((short_GI)?144:130);
1083                         
1084                 }
1085                 else if(mcs_rate&0x0080)//MCS7
1086                 {
1087                         max_rate = (bw_40MHz) ? ((short_GI)?150:135):((short_GI)?72:65);
1088                 }
1089                 else//default MCS7
1090                 {
1091                         //DBG_871X("wx_get_scan, mcs_rate_bitmap=0x%x\n", mcs_rate);
1092                         max_rate = (bw_40MHz) ? ((short_GI)?150:135):((short_GI)?72:65);
1093                 }
1094
1095                 max_rate = max_rate*2;//Mbps/2;         
1096         }
1097
1098         iwe.cmd = SIOCGIWRATE;
1099         iwe.u.bitrate.fixed = iwe.u.bitrate.disabled = 0;
1100         iwe.u.bitrate.value = max_rate * 500000;
1101         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_PARAM_LEN);
1102
1103         //parsing WPA/WPA2 IE
1104         if (pnetwork->network.Reserved[0] != 2) // Probe Request
1105         {
1106                 u8 buf[MAX_WPA_IE_LEN*2];
1107                 u8 wpa_ie[255],rsn_ie[255];
1108                 u16 wpa_len=0,rsn_len=0;
1109                 u8 *p;
1110                 sint out_len=0;
1111                 out_len=rtw_get_sec_ie(pnetwork->network.IEs ,pnetwork->network.IELength,rsn_ie,&rsn_len,wpa_ie,&wpa_len);
1112                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: ssid=%s\n",pnetwork->network.Ssid.Ssid));
1113                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: wpa_len=%d rsn_len=%d\n",wpa_len,rsn_len));
1114
1115                 if (wpa_len > 0)
1116                 {
1117                         p=buf;
1118                         _rtw_memset(buf, 0, MAX_WPA_IE_LEN*2);
1119                         p += sprintf(p, "wpa_ie=");
1120                         for (i = 0; i < wpa_len; i++) {
1121                                 p += sprintf(p, "%02x", wpa_ie[i]);
1122                         }
1123
1124                         if (wpa_len > 100) {
1125                                 printk("-----------------Len %d----------------\n", wpa_len);
1126                                 for (i = 0; i < wpa_len; i++) {
1127                                         printk("%02x ", wpa_ie[i]);
1128                                 }
1129                                 printk("\n");
1130                                 printk("-----------------Len %d----------------\n", wpa_len);
1131                         }
1132         
1133                         _rtw_memset(&iwe, 0, sizeof(iwe));
1134                         iwe.cmd = IWEVCUSTOM;
1135                         iwe.u.data.length = strlen(buf);
1136                         start = iwe_stream_add_point(info, start, stop, &iwe,buf);
1137                         
1138                         _rtw_memset(&iwe, 0, sizeof(iwe));
1139                         iwe.cmd =IWEVGENIE;
1140                         iwe.u.data.length = wpa_len;
1141                         start = iwe_stream_add_point(info, start, stop, &iwe, wpa_ie);                  
1142                 }
1143                 if (rsn_len > 0)
1144                 {
1145                         p = buf;
1146                         _rtw_memset(buf, 0, MAX_WPA_IE_LEN*2);
1147                         p += sprintf(p, "rsn_ie=");
1148                         for (i = 0; i < rsn_len; i++) {
1149                                 p += sprintf(p, "%02x", rsn_ie[i]);
1150                         }
1151                         _rtw_memset(&iwe, 0, sizeof(iwe));
1152                         iwe.cmd = IWEVCUSTOM;
1153                         iwe.u.data.length = strlen(buf);
1154                         start = iwe_stream_add_point(info, start, stop, &iwe,buf);
1155                 
1156                         _rtw_memset(&iwe, 0, sizeof(iwe));
1157                         iwe.cmd =IWEVGENIE;
1158                         iwe.u.data.length = rsn_len;
1159                         start = iwe_stream_add_point(info, start, stop, &iwe, rsn_ie);          
1160                 }
1161         }
1162
1163         { //parsing WPS IE
1164                 uint cnt = 0,total_ielen;       
1165                 u8 *wpsie_ptr=NULL;
1166                 uint wps_ielen = 0;             
1167
1168                 u8 *ie_ptr = pnetwork->network.IEs + ie_offset;
1169                 total_ielen= pnetwork->network.IELength - ie_offset;
1170
1171                 if (pnetwork->network.Reserved[0] == 2) // Probe Request
1172                 {
1173                         ie_ptr = pnetwork->network.IEs;
1174                         total_ielen = pnetwork->network.IELength;
1175                 }
1176                 else     // Beacon or Probe Respones
1177                 {
1178                         ie_ptr = pnetwork->network.IEs + _FIXED_IE_LENGTH_;
1179                         total_ielen = pnetwork->network.IELength - _FIXED_IE_LENGTH_;
1180                 }
1181         
1182                 while(cnt < total_ielen)
1183                 {
1184                         if(rtw_is_wps_ie(&ie_ptr[cnt], &wps_ielen) && (wps_ielen>2))                    
1185                         {
1186                                 wpsie_ptr = &ie_ptr[cnt];
1187                                 iwe.cmd =IWEVGENIE;
1188                                 iwe.u.data.length = (u16)wps_ielen;
1189                                 start = iwe_stream_add_point(info, start, stop, &iwe, wpsie_ptr);                                               
1190                         }                       
1191                         cnt+=ie_ptr[cnt+1]+2; //goto next
1192                 }
1193         }
1194
1195 #ifdef CONFIG_WAPI_SUPPORT
1196         if (pnetwork->network.Reserved[0] != 2) // Probe Request
1197         {
1198                 sint out_len_wapi=0;
1199                 /* here use static for stack size */
1200                 static u8 buf_wapi[MAX_WAPI_IE_LEN*2];
1201                 static u8 wapi_ie[MAX_WAPI_IE_LEN];
1202                 u16 wapi_len=0;
1203                 u16  i;
1204
1205                 _rtw_memset(buf_wapi, 0, MAX_WAPI_IE_LEN);
1206                 _rtw_memset(wapi_ie, 0, MAX_WAPI_IE_LEN);
1207
1208                 out_len_wapi=rtw_get_wapi_ie(pnetwork->network.IEs ,pnetwork->network.IELength,wapi_ie,&wapi_len);
1209                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: ssid=%s\n",pnetwork->network.Ssid.Ssid));
1210                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: wapi_len=%d \n",wapi_len));
1211
1212                 DBG_871X("rtw_wx_get_scan: %s ",pnetwork->network.Ssid.Ssid);
1213                 DBG_871X("rtw_wx_get_scan: ssid = %d ",wapi_len);
1214
1215
1216                 if (wapi_len > 0)
1217                 {
1218                         p=buf_wapi;
1219                         _rtw_memset(buf_wapi, 0, MAX_WAPI_IE_LEN*2);
1220                         p += sprintf(p, "wapi_ie=");
1221                         for (i = 0; i < wapi_len; i++) {
1222                                 p += sprintf(p, "%02x", wapi_ie[i]);
1223                         }
1224
1225                         _rtw_memset(&iwe, 0, sizeof(iwe));
1226                         iwe.cmd = IWEVCUSTOM;
1227                         iwe.u.data.length = strlen(buf_wapi);
1228                         start = iwe_stream_add_point(info, start, stop, &iwe,buf_wapi);
1229
1230                         _rtw_memset(&iwe, 0, sizeof(iwe));
1231                         iwe.cmd =IWEVGENIE;
1232                         iwe.u.data.length = wapi_len;
1233                         start = iwe_stream_add_point(info, start, stop, &iwe, wapi_ie);
1234                 }
1235         }
1236 #endif
1237
1238 {
1239         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1240         u8 ss, sq;
1241         
1242         /* Add quality statistics */
1243         iwe.cmd = IWEVQUAL;
1244         iwe.u.qual.updated = IW_QUAL_QUAL_UPDATED | IW_QUAL_LEVEL_UPDATED 
1245         #if defined(CONFIG_SIGNAL_DISPLAY_DBM) && defined(CONFIG_BACKGROUND_NOISE_MONITOR)
1246                 | IW_QUAL_NOISE_UPDATED
1247         #else
1248                 | IW_QUAL_NOISE_INVALID
1249         #endif
1250         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
1251                 | IW_QUAL_DBM
1252         #endif
1253         ;
1254
1255         if ( check_fwstate(pmlmepriv, _FW_LINKED)== _TRUE &&
1256                 is_same_network(&pmlmepriv->cur_network.network, &pnetwork->network, 0)){
1257                 ss = padapter->recvpriv.signal_strength;
1258                 sq = padapter->recvpriv.signal_qual;
1259         } else {
1260                 ss = pnetwork->network.PhyInfo.SignalStrength;
1261                 sq = pnetwork->network.PhyInfo.SignalQuality;
1262         }
1263         
1264         
1265         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
1266         iwe.u.qual.level = (u8) translate_percentage_to_dbm(ss);//dbm
1267         #else
1268         #ifdef CONFIG_SKIP_SIGNAL_SCALE_MAPPING
1269         {
1270                 /* Do signal scale mapping when using percentage as the unit of signal strength, since the scale mapping is skipped in odm */
1271                 
1272                 HAL_DATA_TYPE *pHal = GET_HAL_DATA(padapter);
1273                 
1274                 iwe.u.qual.level = (u8)odm_SignalScaleMapping(&pHal->odmpriv, ss);
1275         }
1276         #else
1277         iwe.u.qual.level = (u8)ss;//%
1278         #endif
1279         #endif
1280         
1281         iwe.u.qual.qual = (u8)sq;   // signal quality
1282
1283         #ifdef CONFIG_PLATFORM_ROCKCHIPS
1284         iwe.u.qual.noise = -100; // noise level suggest by zhf@rockchips
1285         #else 
1286         #if defined(CONFIG_SIGNAL_DISPLAY_DBM) && defined(CONFIG_BACKGROUND_NOISE_MONITOR)
1287         {
1288                 s16 tmp_noise=0;
1289                 rtw_hal_get_odm_var(padapter, HAL_ODM_NOISE_MONITOR,&(pnetwork->network.Configuration.DSConfig), &(tmp_noise));
1290                 iwe.u.qual.noise = tmp_noise ;
1291         }
1292         #else
1293         iwe.u.qual.noise = 0; // noise level
1294         #endif  
1295         #endif //CONFIG_PLATFORM_ROCKCHIPS
1296         
1297         //DBG_871X("iqual=%d, ilevel=%d, inoise=%d, iupdated=%d\n", iwe.u.qual.qual, iwe.u.qual.level , iwe.u.qual.noise, iwe.u.qual.updated);
1298
1299         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_QUAL_LEN);
1300 }
1301
1302         {
1303                 u8 buf[MAX_WPA_IE_LEN];
1304                 u8 * p,*pos;
1305                 int len;
1306                 p = buf;
1307                 pos = pnetwork->network.Reserved;
1308                 _rtw_memset(buf, 0, MAX_WPA_IE_LEN);
1309                 p += sprintf(p, "fm=%02X%02X", pos[1], pos[0]);
1310                 _rtw_memset(&iwe, 0, sizeof(iwe));
1311                 iwe.cmd = IWEVCUSTOM;
1312                 iwe.u.data.length = strlen(buf);
1313                 start = iwe_stream_add_point(info, start, stop, &iwe, buf);
1314         }
1315         
1316         return start;   
1317 }
1318 #endif
1319
1320 static int wpa_set_auth_algs(struct net_device *dev, u32 value)
1321 {       
1322         _adapter *padapter = (_adapter *) rtw_netdev_priv(dev);
1323         int ret = 0;
1324
1325         if ((value & AUTH_ALG_SHARED_KEY)&&(value & AUTH_ALG_OPEN_SYSTEM))
1326         {
1327                 DBG_871X("wpa_set_auth_algs, AUTH_ALG_SHARED_KEY and  AUTH_ALG_OPEN_SYSTEM [value:0x%x]\n",value);
1328                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1329                 padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
1330                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
1331         } 
1332         else if (value & AUTH_ALG_SHARED_KEY)
1333         {
1334                 DBG_871X("wpa_set_auth_algs, AUTH_ALG_SHARED_KEY  [value:0x%x]\n",value);
1335                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1336
1337 #ifdef CONFIG_PLATFORM_MT53XX
1338                 padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
1339                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
1340 #else
1341                 padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeShared;
1342                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Shared;
1343 #endif
1344         } 
1345         else if(value & AUTH_ALG_OPEN_SYSTEM)
1346         {
1347                 DBG_871X("wpa_set_auth_algs, AUTH_ALG_OPEN_SYSTEM\n");
1348                 //padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
1349                 if(padapter->securitypriv.ndisauthtype < Ndis802_11AuthModeWPAPSK)
1350                 {
1351 #ifdef CONFIG_PLATFORM_MT53XX
1352                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
1353                         padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
1354 #else
1355                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeOpen;
1356                         padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
1357 #endif
1358                 }
1359                 
1360         }
1361         else if(value & AUTH_ALG_LEAP)
1362         {
1363                 DBG_871X("wpa_set_auth_algs, AUTH_ALG_LEAP\n");
1364         }
1365         else
1366         {
1367                 DBG_871X("wpa_set_auth_algs, error!\n");
1368                 ret = -EINVAL;
1369         }
1370
1371         return ret;
1372         
1373 }
1374
1375 static int wpa_set_encryption(struct net_device *dev, struct ieee_param *param, u32 param_len)
1376 {
1377         int ret = 0;
1378         u32 wep_key_idx, wep_key_len,wep_total_len;
1379         NDIS_802_11_WEP  *pwep = NULL;  
1380         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1381         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;               
1382         struct security_priv *psecuritypriv = &padapter->securitypriv;
1383 #ifdef CONFIG_P2P
1384         struct wifidirect_info* pwdinfo = &padapter->wdinfo;
1385 #endif //CONFIG_P2P
1386
1387 _func_enter_;
1388
1389         param->u.crypt.err = 0;
1390         param->u.crypt.alg[IEEE_CRYPT_ALG_NAME_LEN - 1] = '\0';
1391
1392         if (param_len < (u32) ((u8 *) param->u.crypt.key - (u8 *) param) + param->u.crypt.key_len)
1393         {
1394                 ret =  -EINVAL;
1395                 goto exit;
1396         }
1397
1398         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
1399             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
1400             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
1401         {
1402
1403                 if (param->u.crypt.idx >= WEP_KEYS
1404 #ifdef CONFIG_IEEE80211W
1405                         && param->u.crypt.idx > BIP_MAX_KEYID
1406 #endif //CONFIG_IEEE80211W
1407                         )
1408                 {
1409                         ret = -EINVAL;
1410                         goto exit;
1411                 }
1412         } 
1413         else 
1414         {
1415 #ifdef CONFIG_WAPI_SUPPORT
1416                 if (strcmp(param->u.crypt.alg, "SMS4"))
1417 #endif
1418                 {
1419                         ret = -EINVAL;
1420                         goto exit;
1421                 }
1422         }
1423
1424         if (strcmp(param->u.crypt.alg, "WEP") == 0)
1425         {
1426                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("wpa_set_encryption, crypt.alg = WEP\n"));
1427                 DBG_871X("wpa_set_encryption, crypt.alg = WEP\n");
1428
1429                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1430                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP40_;
1431                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP40_;
1432
1433                 wep_key_idx = param->u.crypt.idx;
1434                 wep_key_len = param->u.crypt.key_len;
1435
1436                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("(1)wep_key_idx=%d\n", wep_key_idx));
1437                 DBG_871X("(1)wep_key_idx=%d\n", wep_key_idx);
1438
1439                 if (wep_key_idx > WEP_KEYS)
1440                         return -EINVAL;
1441
1442                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("(2)wep_key_idx=%d\n", wep_key_idx));
1443
1444                 if (wep_key_len > 0) 
1445                 {
1446                         wep_key_len = wep_key_len <= 5 ? 5 : 13;
1447                         wep_total_len = wep_key_len + FIELD_OFFSET(NDIS_802_11_WEP, KeyMaterial);
1448                         pwep =(NDIS_802_11_WEP   *) rtw_malloc(wep_total_len);
1449                         if(pwep == NULL){
1450                                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,(" wpa_set_encryption: pwep allocate fail !!!\n"));
1451                                 goto exit;
1452                         }
1453
1454                         _rtw_memset(pwep, 0, wep_total_len);
1455
1456                         pwep->KeyLength = wep_key_len;
1457                         pwep->Length = wep_total_len;
1458
1459                         if(wep_key_len==13)
1460                         {
1461                                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP104_;
1462                                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP104_;
1463                         }
1464                 }
1465                 else {          
1466                         ret = -EINVAL;
1467                         goto exit;
1468                 }
1469
1470                 pwep->KeyIndex = wep_key_idx;
1471                 pwep->KeyIndex |= 0x80000000;
1472
1473                 _rtw_memcpy(pwep->KeyMaterial,  param->u.crypt.key, pwep->KeyLength);
1474
1475                 if(param->u.crypt.set_tx)
1476                 {
1477                         DBG_871X("wep, set_tx=1\n");
1478
1479                         if(rtw_set_802_11_add_wep(padapter, pwep) == (u8)_FAIL)
1480                         {
1481                                 ret = -EOPNOTSUPP ;
1482                         }
1483                 }
1484                 else
1485                 {
1486                         DBG_871X("wep, set_tx=0\n");
1487                         
1488                         //don't update "psecuritypriv->dot11PrivacyAlgrthm" and 
1489                         //"psecuritypriv->dot11PrivacyKeyIndex=keyid", but can rtw_set_key to fw/cam
1490                         
1491                         if (wep_key_idx >= WEP_KEYS) {
1492                                 ret = -EOPNOTSUPP ;
1493                                 goto exit;
1494                         }                               
1495                         
1496                       _rtw_memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
1497                         psecuritypriv->dot11DefKeylen[wep_key_idx]=pwep->KeyLength;     
1498                         rtw_set_key(padapter, psecuritypriv, wep_key_idx, 0, _TRUE);
1499                 }
1500
1501                 goto exit;              
1502         }
1503
1504         if(padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) // 802_1x
1505         {
1506                 struct sta_info * psta,*pbcmc_sta;
1507                 struct sta_priv * pstapriv = &padapter->stapriv;
1508
1509                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_MP_STATE) == _TRUE) //sta mode
1510                 {
1511                         psta = rtw_get_stainfo(pstapriv, get_bssid(pmlmepriv));                         
1512                         if (psta == NULL) {
1513                                 //DEBUG_ERR( ("Set wpa_set_encryption: Obtain Sta_info fail \n"));
1514                         }
1515                         else
1516                         {
1517                                 //Jeff: don't disable ieee8021x_blocked while clearing key
1518                                 if (strcmp(param->u.crypt.alg, "none") != 0) 
1519                                         psta->ieee8021x_blocked = _FALSE;
1520                                 
1521                                 if((padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption2Enabled)||
1522                                                 (padapter->securitypriv.ndisencryptstatus ==  Ndis802_11Encryption3Enabled))
1523                                 {
1524                                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
1525                                 }               
1526
1527                                 if(param->u.crypt.set_tx ==1)//pairwise key
1528                                 { 
1529                                         _rtw_memcpy(psta->dot118021x_UncstKey.skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
1530                                         
1531                                         if(strcmp(param->u.crypt.alg, "TKIP") == 0)//set mic key
1532                                         {                                               
1533                                                 //DEBUG_ERR(("\nset key length :param->u.crypt.key_len=%d\n", param->u.crypt.key_len));
1534                                                 _rtw_memcpy(psta->dot11tkiptxmickey.skey, &(param->u.crypt.key[16]), 8);
1535                                                 _rtw_memcpy(psta->dot11tkiprxmickey.skey, &(param->u.crypt.key[24]), 8);
1536
1537                                                 padapter->securitypriv.busetkipkey=_FALSE;
1538                                                 //_set_timer(&padapter->securitypriv.tkip_timer, 50);                                           
1539                                         }
1540
1541                                         //DEBUG_ERR((" param->u.crypt.key_len=%d\n",param->u.crypt.key_len));
1542                                         DBG_871X(" ~~~~set sta key:unicastkey\n");
1543                                         
1544                                         rtw_setstakey_cmd(padapter, psta, _TRUE, _TRUE);
1545                                 }
1546                                 else//group key
1547                                 {                                       
1548                                         if(strcmp(param->u.crypt.alg, "TKIP") == 0 || strcmp(param->u.crypt.alg, "CCMP") == 0)
1549                                         {
1550                                                 _rtw_memcpy(padapter->securitypriv.dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key,(param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
1551                                                 //only TKIP group key need to install this
1552                                                 if(param->u.crypt.key_len > 16)
1553                                                 {
1554                                                         _rtw_memcpy(padapter->securitypriv.dot118021XGrptxmickey[param->u.crypt.idx].skey,&(param->u.crypt.key[16]),8);
1555                                                         _rtw_memcpy(padapter->securitypriv.dot118021XGrprxmickey[param->u.crypt.idx].skey,&(param->u.crypt.key[24]),8);
1556                                                 }
1557                                                 padapter->securitypriv.binstallGrpkey = _TRUE;  
1558                                                 //DEBUG_ERR((" param->u.crypt.key_len=%d\n", param->u.crypt.key_len));
1559                                                 DBG_871X(" ~~~~set sta key:groupkey\n");
1560         
1561                                                 padapter->securitypriv.dot118021XGrpKeyid = param->u.crypt.idx;
1562         
1563                                                 rtw_set_key(padapter,&padapter->securitypriv,param->u.crypt.idx, 1, _TRUE);
1564                                         }
1565 #ifdef CONFIG_IEEE80211W
1566                                         else if(strcmp(param->u.crypt.alg, "BIP") == 0)
1567                                         {
1568                                                 int no;
1569                                                 //printk("BIP key_len=%d , index=%d @@@@@@@@@@@@@@@@@@\n", param->u.crypt.key_len, param->u.crypt.idx);
1570                                                 //save the IGTK key, length 16 bytes
1571                                                 _rtw_memcpy(padapter->securitypriv.dot11wBIPKey[param->u.crypt.idx].skey,  param->u.crypt.key,(param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
1572                                                 /*printk("IGTK key below:\n");
1573                                                 for(no=0;no<16;no++)
1574                                                         printk(" %02x ", padapter->securitypriv.dot11wBIPKey[param->u.crypt.idx].skey[no]);
1575                                                 printk("\n");*/
1576                                                 padapter->securitypriv.dot11wBIPKeyid = param->u.crypt.idx;
1577                                                 padapter->securitypriv.binstallBIPkey = _TRUE;
1578                                                 DBG_871X(" ~~~~set sta key:IGKT\n");
1579                                         }
1580 #endif //CONFIG_IEEE80211W
1581                                         
1582 #ifdef CONFIG_P2P
1583                                         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_PROVISIONING_ING))
1584                                         {
1585                                                 rtw_p2p_set_state(pwdinfo, P2P_STATE_PROVISIONING_DONE);
1586                                         }
1587 #endif //CONFIG_P2P
1588                                         
1589                                 }                                               
1590                         }
1591
1592                         pbcmc_sta=rtw_get_bcmc_stainfo(padapter);
1593                         if(pbcmc_sta==NULL)
1594                         {
1595                                 //DEBUG_ERR( ("Set OID_802_11_ADD_KEY: bcmc stainfo is null \n"));
1596                         }
1597                         else
1598                         {
1599                                 //Jeff: don't disable ieee8021x_blocked while clearing key
1600                                 if (strcmp(param->u.crypt.alg, "none") != 0) 
1601                                         pbcmc_sta->ieee8021x_blocked = _FALSE;
1602                                 
1603                                 if((padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption2Enabled)||
1604                                                 (padapter->securitypriv.ndisencryptstatus ==  Ndis802_11Encryption3Enabled))
1605                                 {                                                       
1606                                         pbcmc_sta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
1607                                 }                                       
1608                         }                               
1609                 }
1610                 else if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) //adhoc mode
1611                 {               
1612                 }                       
1613         }
1614
1615 #ifdef CONFIG_WAPI_SUPPORT
1616         if (strcmp(param->u.crypt.alg, "SMS4") == 0)
1617         {
1618                 PRT_WAPI_T                      pWapiInfo = &padapter->wapiInfo;
1619                 PRT_WAPI_STA_INFO       pWapiSta;
1620                 u8                                      WapiASUEPNInitialValueSrc[16] = {0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C} ;
1621                 u8                                      WapiAEPNInitialValueSrc[16] = {0x37,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C} ;
1622                 u8                                      WapiAEMultiCastPNInitialValueSrc[16] = {0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C} ;
1623
1624                 if(param->u.crypt.set_tx == 1)
1625                 {
1626                         list_for_each_entry(pWapiSta, &pWapiInfo->wapiSTAUsedList, list) {
1627                                 if(_rtw_memcmp(pWapiSta->PeerMacAddr,param->sta_addr,6))
1628                                 {
1629                                         _rtw_memcpy(pWapiSta->lastTxUnicastPN,WapiASUEPNInitialValueSrc,16);
1630
1631                                         pWapiSta->wapiUsk.bSet = true;
1632                                         _rtw_memcpy(pWapiSta->wapiUsk.dataKey,param->u.crypt.key,16);
1633                                         _rtw_memcpy(pWapiSta->wapiUsk.micKey,param->u.crypt.key+16,16);
1634                                         pWapiSta->wapiUsk.keyId = param->u.crypt.idx ;
1635                                         pWapiSta->wapiUsk.bTxEnable = true;
1636
1637                                         _rtw_memcpy(pWapiSta->lastRxUnicastPNBEQueue,WapiAEPNInitialValueSrc,16);
1638                                         _rtw_memcpy(pWapiSta->lastRxUnicastPNBKQueue,WapiAEPNInitialValueSrc,16);
1639                                         _rtw_memcpy(pWapiSta->lastRxUnicastPNVIQueue,WapiAEPNInitialValueSrc,16);
1640                                         _rtw_memcpy(pWapiSta->lastRxUnicastPNVOQueue,WapiAEPNInitialValueSrc,16);
1641                                         _rtw_memcpy(pWapiSta->lastRxUnicastPN,WapiAEPNInitialValueSrc,16);
1642                                         pWapiSta->wapiUskUpdate.bTxEnable = false;
1643                                         pWapiSta->wapiUskUpdate.bSet = false;
1644
1645                                         if (psecuritypriv->sw_encrypt== false || psecuritypriv->sw_decrypt == false)
1646                                         {
1647                                                 //set unicast key for ASUE
1648                                                 rtw_wapi_set_key(padapter, &pWapiSta->wapiUsk, pWapiSta, false, false);
1649                                         }
1650                                 }
1651                         }
1652                 }
1653                 else
1654                 {
1655                         list_for_each_entry(pWapiSta, &pWapiInfo->wapiSTAUsedList, list) {
1656                                 if(_rtw_memcmp(pWapiSta->PeerMacAddr,get_bssid(pmlmepriv),6))
1657                                 {
1658                                         pWapiSta->wapiMsk.bSet = true;
1659                                         _rtw_memcpy(pWapiSta->wapiMsk.dataKey,param->u.crypt.key,16);
1660                                         _rtw_memcpy(pWapiSta->wapiMsk.micKey,param->u.crypt.key+16,16);
1661                                         pWapiSta->wapiMsk.keyId = param->u.crypt.idx ;
1662                                         pWapiSta->wapiMsk.bTxEnable = false;
1663                                         if(!pWapiSta->bSetkeyOk)
1664                                                 pWapiSta->bSetkeyOk = true;
1665                                         pWapiSta->bAuthenticateInProgress = false;
1666
1667                                         _rtw_memcpy(pWapiSta->lastRxMulticastPN, WapiAEMultiCastPNInitialValueSrc, 16);
1668
1669                                         if (psecuritypriv->sw_decrypt == false)
1670                                         {
1671                                                 //set rx broadcast key for ASUE
1672                                                 rtw_wapi_set_key(padapter, &pWapiSta->wapiMsk, pWapiSta, true, false);
1673                                         }
1674                                 }
1675
1676                         }
1677                 }
1678         }
1679 #endif
1680
1681 exit:
1682         
1683         if (pwep) {
1684                 rtw_mfree((u8 *)pwep, wep_total_len);           
1685         }       
1686         
1687 _func_exit_;
1688
1689         return ret;     
1690 }
1691
1692 static int rtw_set_wpa_ie(_adapter *padapter, char *pie, unsigned short ielen)
1693 {
1694         u8 *buf=NULL, *pos=NULL;        
1695         u32 left;       
1696         int group_cipher = 0, pairwise_cipher = 0;
1697         int ret = 0;
1698         u8 null_addr[]= {0,0,0,0,0,0};
1699 #ifdef CONFIG_P2P
1700         struct wifidirect_info* pwdinfo = &padapter->wdinfo;
1701 #endif //CONFIG_P2P
1702
1703         if((ielen > MAX_WPA_IE_LEN) || (pie == NULL)){
1704                 _clr_fwstate_(&padapter->mlmepriv, WIFI_UNDER_WPS);
1705                 if(pie == NULL) 
1706                         return ret;
1707                 else
1708                         return -EINVAL;
1709         }
1710
1711         if(ielen)
1712         {               
1713                 buf = rtw_zmalloc(ielen);
1714                 if (buf == NULL){
1715                         ret =  -ENOMEM;
1716                         goto exit;
1717                 }
1718         
1719                 _rtw_memcpy(buf, pie , ielen);
1720
1721                 //dump
1722                 {
1723                         int i;
1724                         DBG_871X("\n wpa_ie(length:%d):\n", ielen);
1725                         for(i=0;i<ielen;i=i+8)
1726                                 DBG_871X("0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x \n",buf[i],buf[i+1],buf[i+2],buf[i+3],buf[i+4],buf[i+5],buf[i+6],buf[i+7]);
1727                 }
1728         
1729                 pos = buf;
1730                 if(ielen < RSN_HEADER_LEN){
1731                         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("Ie len too short %d\n", ielen));
1732                         ret  = -1;
1733                         goto exit;
1734                 }
1735
1736 #if 0
1737                 pos += RSN_HEADER_LEN;
1738                 left  = ielen - RSN_HEADER_LEN;
1739                 
1740                 if (left >= RSN_SELECTOR_LEN){
1741                         pos += RSN_SELECTOR_LEN;
1742                         left -= RSN_SELECTOR_LEN;
1743                 }               
1744                 else if (left > 0){
1745                         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("Ie length mismatch, %u too much \n", left));
1746                         ret =-1;
1747                         goto exit;
1748                 }
1749 #endif          
1750                 
1751                 if(rtw_parse_wpa_ie(buf, ielen, &group_cipher, &pairwise_cipher, NULL) == _SUCCESS)
1752                 {
1753                         padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_8021X;
1754                         padapter->securitypriv.ndisauthtype=Ndis802_11AuthModeWPAPSK;
1755                         _rtw_memcpy(padapter->securitypriv.supplicant_ie, &buf[0], ielen);      
1756                 }
1757         
1758                 if(rtw_parse_wpa2_ie(buf, ielen, &group_cipher, &pairwise_cipher, NULL) == _SUCCESS)
1759                 {
1760                         padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_8021X;
1761                         padapter->securitypriv.ndisauthtype=Ndis802_11AuthModeWPA2PSK;  
1762                         _rtw_memcpy(padapter->securitypriv.supplicant_ie, &buf[0], ielen);      
1763                 }
1764                         
1765                 if (group_cipher == 0)
1766                 {
1767                         group_cipher = WPA_CIPHER_NONE;
1768                 }
1769                 if (pairwise_cipher == 0)
1770                 {
1771                         pairwise_cipher = WPA_CIPHER_NONE;
1772                 }
1773                         
1774                 switch(group_cipher)
1775                 {
1776                         case WPA_CIPHER_NONE:
1777                                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
1778                                 padapter->securitypriv.ndisencryptstatus=Ndis802_11EncryptionDisabled;
1779                                 break;
1780                         case WPA_CIPHER_WEP40:
1781                                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP40_;
1782                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1783                                 break;
1784                         case WPA_CIPHER_TKIP:
1785                                 padapter->securitypriv.dot118021XGrpPrivacy=_TKIP_;
1786                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
1787                                 break;
1788                         case WPA_CIPHER_CCMP:
1789                                 padapter->securitypriv.dot118021XGrpPrivacy=_AES_;
1790                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
1791                                 break;
1792                         case WPA_CIPHER_WEP104: 
1793                                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP104_;
1794                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1795                                 break;
1796                 }
1797
1798                 switch(pairwise_cipher)
1799                 {
1800                         case WPA_CIPHER_NONE:
1801                                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
1802                                 padapter->securitypriv.ndisencryptstatus=Ndis802_11EncryptionDisabled;
1803                                 break;
1804                         case WPA_CIPHER_WEP40:
1805                                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP40_;
1806                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1807                                 break;
1808                         case WPA_CIPHER_TKIP:
1809                                 padapter->securitypriv.dot11PrivacyAlgrthm=_TKIP_;
1810                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
1811                                 break;
1812                         case WPA_CIPHER_CCMP:
1813                                 padapter->securitypriv.dot11PrivacyAlgrthm=_AES_;
1814                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
1815                                 break;
1816                         case WPA_CIPHER_WEP104: 
1817                                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP104_;
1818                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1819                                 break;
1820                 }
1821                 
1822                 _clr_fwstate_(&padapter->mlmepriv, WIFI_UNDER_WPS);
1823                 {//set wps_ie   
1824                         u16 cnt = 0;    
1825                         u8 eid, wps_oui[4]={0x0,0x50,0xf2,0x04};
1826                          
1827                         while( cnt < ielen )
1828                         {
1829                                 eid = buf[cnt];
1830                 
1831                                 if((eid==_VENDOR_SPECIFIC_IE_)&&(_rtw_memcmp(&buf[cnt+2], wps_oui, 4)==_TRUE))
1832                                 {
1833                                         DBG_871X("SET WPS_IE\n");
1834
1835                                         padapter->securitypriv.wps_ie_len = ((buf[cnt+1]+2) < MAX_WPS_IE_LEN) ? (buf[cnt+1]+2):MAX_WPS_IE_LEN;
1836
1837                                         _rtw_memcpy(padapter->securitypriv.wps_ie, &buf[cnt], padapter->securitypriv.wps_ie_len);
1838                                         
1839                                         set_fwstate(&padapter->mlmepriv, WIFI_UNDER_WPS);
1840                                         
1841 #ifdef CONFIG_P2P
1842                                         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_GONEGO_OK))
1843                                         {
1844                                                 rtw_p2p_set_state(pwdinfo, P2P_STATE_PROVISIONING_ING);
1845                                         }
1846 #endif //CONFIG_P2P
1847                                         cnt += buf[cnt+1]+2;
1848                                         
1849                                         break;
1850                                 } else {
1851                                         cnt += buf[cnt+1]+2; //goto next        
1852                                 }                               
1853                         }                       
1854                 }               
1855         }
1856         
1857         //TKIP and AES disallow multicast packets until installing group key
1858         if(padapter->securitypriv.dot11PrivacyAlgrthm == _TKIP_
1859                 || padapter->securitypriv.dot11PrivacyAlgrthm == _TKIP_WTMIC_
1860                 || padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
1861                 //WPS open need to enable multicast
1862                 //|| check_fwstate(&padapter->mlmepriv, WIFI_UNDER_WPS) == _TRUE)
1863                 rtw_hal_set_hwreg(padapter, HW_VAR_OFF_RCR_AM, null_addr);
1864         
1865         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
1866                  ("rtw_set_wpa_ie: pairwise_cipher=0x%08x padapter->securitypriv.ndisencryptstatus=%d padapter->securitypriv.ndisauthtype=%d\n",
1867                   pairwise_cipher, padapter->securitypriv.ndisencryptstatus, padapter->securitypriv.ndisauthtype));
1868         
1869 exit:
1870
1871         if (buf) rtw_mfree(buf, ielen);
1872
1873         return ret;
1874 }
1875
1876 static int rtw_wx_get_name(struct net_device *dev, 
1877                              struct iw_request_info *info, 
1878                              union iwreq_data *wrqu, char *extra)
1879 {
1880         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1881         u16 cap;
1882         u32 ht_ielen = 0;
1883         char *p;
1884         u8 ht_cap=_FALSE, vht_cap=_FALSE;
1885         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
1886         WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
1887         NDIS_802_11_RATES_EX* prates = NULL;
1888
1889         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("cmd_code=%x\n", info->cmd));
1890
1891         _func_enter_;   
1892
1893         if (check_fwstate(pmlmepriv, _FW_LINKED|WIFI_ADHOC_MASTER_STATE) == _TRUE)
1894         {
1895                 //parsing HT_CAP_IE
1896                 p = rtw_get_ie(&pcur_bss->IEs[12], _HT_CAPABILITY_IE_, &ht_ielen, pcur_bss->IELength-12);
1897                 if(p && ht_ielen>0)
1898                 {
1899                         ht_cap = _TRUE;
1900                 }
1901
1902 #ifdef CONFIG_80211AC_VHT
1903                 if(pmlmepriv->vhtpriv.vht_option == _TRUE)
1904                         vht_cap = _TRUE;
1905 #endif
1906
1907                 prates = &pcur_bss->SupportedRates;
1908
1909                 if (rtw_is_cckratesonly_included((u8*)prates) == _TRUE)
1910                 {
1911                         if(ht_cap == _TRUE)
1912                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bn");
1913                         else
1914                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11b");
1915                 }
1916                 else if ((rtw_is_cckrates_included((u8*)prates)) == _TRUE)
1917                 {
1918                         if(ht_cap == _TRUE)
1919                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bgn");
1920                         else
1921                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bg");
1922                 }
1923                 else
1924                 {
1925                         if(pcur_bss->Configuration.DSConfig > 14)
1926                         {
1927                         #ifdef CONFIG_80211AC_VHT
1928                                 if(vht_cap == _TRUE){
1929                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11AC");
1930                                 }
1931                                 else
1932                         #endif
1933                                 {
1934                                         if(ht_cap == _TRUE)
1935                                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11an");
1936                                         else
1937                                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11a");
1938                                 }
1939                         }
1940                         else
1941                         {
1942                                 if(ht_cap == _TRUE)
1943                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11gn");
1944                                 else
1945                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11g");
1946                         }
1947                 }
1948         }
1949         else
1950         {
1951                 //prates = &padapter->registrypriv.dev_network.SupportedRates;
1952                 //snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11g");
1953                 snprintf(wrqu->name, IFNAMSIZ, "unassociated");
1954         }
1955
1956         _func_exit_;
1957
1958         return 0;
1959 }
1960
1961 static int rtw_wx_set_freq(struct net_device *dev, 
1962                              struct iw_request_info *info, 
1963                              union iwreq_data *wrqu, char *extra)
1964 {       
1965         _func_enter_;
1966
1967         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_wx_set_freq\n"));
1968
1969         _func_exit_;
1970         
1971         return 0;
1972 }
1973
1974 static int rtw_wx_get_freq(struct net_device *dev, 
1975                              struct iw_request_info *info, 
1976                              union iwreq_data *wrqu, char *extra)
1977 {
1978         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1979         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
1980         WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
1981         
1982         if(check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE)
1983         {
1984                 //wrqu->freq.m = ieee80211_wlan_frequencies[pcur_bss->Configuration.DSConfig-1] * 100000;
1985                 wrqu->freq.m = rtw_ch2freq(pcur_bss->Configuration.DSConfig) * 100000;
1986                 wrqu->freq.e = 1;
1987                 wrqu->freq.i = pcur_bss->Configuration.DSConfig;
1988
1989         }
1990         else{
1991                 wrqu->freq.m = rtw_ch2freq(padapter->mlmeextpriv.cur_channel) * 100000;
1992                 wrqu->freq.e = 1;
1993                 wrqu->freq.i = padapter->mlmeextpriv.cur_channel;
1994         }
1995
1996         return 0;
1997 }
1998
1999 static int rtw_wx_set_mode(struct net_device *dev, struct iw_request_info *a,
2000                              union iwreq_data *wrqu, char *b)
2001 {
2002         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2003         NDIS_802_11_NETWORK_INFRASTRUCTURE networkType ;
2004         int ret = 0;
2005         
2006         _func_enter_;
2007         
2008         if(_FAIL == rtw_pwr_wakeup(padapter)) {
2009                 ret= -EPERM;
2010                 goto exit;
2011         }
2012
2013         if (padapter->hw_init_completed==_FALSE){
2014                 ret = -EPERM;
2015                 goto exit;
2016         }
2017         
2018         switch(wrqu->mode)
2019         {
2020                 case IW_MODE_AUTO:
2021                         networkType = Ndis802_11AutoUnknown;
2022                         DBG_871X("set_mode = IW_MODE_AUTO\n");  
2023                         break;                          
2024                 case IW_MODE_ADHOC:             
2025                         networkType = Ndis802_11IBSS;
2026                         DBG_871X("set_mode = IW_MODE_ADHOC\n");                 
2027                         break;
2028                 case IW_MODE_MASTER:            
2029                         networkType = Ndis802_11APMode;
2030                         DBG_871X("set_mode = IW_MODE_MASTER\n");
2031                         //rtw_setopmode_cmd(padapter, networkType,_TRUE);       
2032                         break;                          
2033                 case IW_MODE_INFRA:
2034                         networkType = Ndis802_11Infrastructure;
2035                         DBG_871X("set_mode = IW_MODE_INFRA\n");                 
2036                         break;
2037         
2038                 default :
2039                         ret = -EINVAL;;
2040                         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("\n Mode: %s is not supported  \n", iw_operation_mode[wrqu->mode]));
2041                         goto exit;
2042         }
2043         
2044 /*      
2045         if(Ndis802_11APMode == networkType)
2046         {
2047                 rtw_setopmode_cmd(padapter, networkType,_TRUE);
2048         }       
2049         else
2050         {
2051                 rtw_setopmode_cmd(padapter, Ndis802_11AutoUnknown,_TRUE);       
2052         }
2053 */
2054         
2055         if (rtw_set_802_11_infrastructure_mode(padapter, networkType) ==_FALSE){
2056
2057                 ret = -EPERM;
2058                 goto exit;
2059
2060         }
2061
2062         rtw_setopmode_cmd(padapter, networkType,_TRUE);
2063
2064 exit:
2065         
2066         _func_exit_;
2067         
2068         return ret;
2069         
2070 }
2071
2072 static int rtw_wx_get_mode(struct net_device *dev, struct iw_request_info *a,
2073                              union iwreq_data *wrqu, char *b)
2074 {
2075         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2076         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
2077         
2078         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,(" rtw_wx_get_mode \n"));
2079
2080         _func_enter_;
2081         
2082         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE)
2083         {
2084                 wrqu->mode = IW_MODE_INFRA;
2085         }
2086         else if  ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == _TRUE) ||
2087                        (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE))
2088                 
2089         {
2090                 wrqu->mode = IW_MODE_ADHOC;
2091         }
2092         else if(check_fwstate(pmlmepriv, WIFI_AP_STATE) == _TRUE)
2093         {
2094                 wrqu->mode = IW_MODE_MASTER;
2095         }
2096         else
2097         {
2098                 wrqu->mode = IW_MODE_AUTO;
2099         }
2100
2101         _func_exit_;
2102         
2103         return 0;
2104         
2105 }
2106
2107
2108 static int rtw_wx_set_pmkid(struct net_device *dev,
2109                              struct iw_request_info *a,
2110                              union iwreq_data *wrqu, char *extra)
2111 {
2112         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2113         u8          j,blInserted = _FALSE;
2114         int         intReturn = _FALSE;
2115         struct mlme_priv  *pmlmepriv = &padapter->mlmepriv;
2116         struct security_priv *psecuritypriv = &padapter->securitypriv;
2117         struct iw_pmksa*  pPMK = ( struct iw_pmksa* ) extra;
2118         u8     strZeroMacAddress[ ETH_ALEN ] = { 0x00 };
2119         u8     strIssueBssid[ ETH_ALEN ] = { 0x00 };
2120         
2121 /*
2122         struct iw_pmksa
2123         {
2124             __u32   cmd;
2125             struct sockaddr bssid;
2126             __u8    pmkid[IW_PMKID_LEN];   //IW_PMKID_LEN=16
2127         }
2128         There are the BSSID information in the bssid.sa_data array.
2129         If cmd is IW_PMKSA_FLUSH, it means the wpa_suppplicant wants to clear all the PMKID information.
2130         If cmd is IW_PMKSA_ADD, it means the wpa_supplicant wants to add a PMKID/BSSID to driver.
2131         If cmd is IW_PMKSA_REMOVE, it means the wpa_supplicant wants to remove a PMKID/BSSID from driver.
2132         */
2133
2134         _rtw_memcpy( strIssueBssid, pPMK->bssid.sa_data, ETH_ALEN);
2135         if ( pPMK->cmd == IW_PMKSA_ADD )
2136         {
2137                 DBG_871X( "[rtw_wx_set_pmkid] IW_PMKSA_ADD!\n" );
2138                 if ( _rtw_memcmp( strIssueBssid, strZeroMacAddress, ETH_ALEN ) == _TRUE )
2139                 {
2140                     return( intReturn );
2141                 }
2142                 else
2143                 {
2144                     intReturn = _TRUE;
2145                 }
2146                 blInserted = _FALSE;
2147                 
2148                 //overwrite PMKID
2149                 for(j=0 ; j<NUM_PMKID_CACHE; j++)
2150                 {
2151                         if( _rtw_memcmp( psecuritypriv->PMKIDList[j].Bssid, strIssueBssid, ETH_ALEN) ==_TRUE )
2152                         { // BSSID is matched, the same AP => rewrite with new PMKID.
2153                                 
2154                                 DBG_871X( "[rtw_wx_set_pmkid] BSSID exists in the PMKList.\n" );
2155
2156                                 _rtw_memcpy( psecuritypriv->PMKIDList[j].PMKID, pPMK->pmkid, IW_PMKID_LEN);
2157                                 psecuritypriv->PMKIDList[ j ].bUsed = _TRUE;
2158                                 psecuritypriv->PMKIDIndex = j+1;
2159                                 blInserted = _TRUE;
2160                                 break;
2161                         }       
2162                 }
2163
2164                 if(!blInserted)
2165                 {
2166                     // Find a new entry
2167                     DBG_871X( "[rtw_wx_set_pmkid] Use the new entry index = %d for this PMKID.\n",
2168                             psecuritypriv->PMKIDIndex );
2169
2170                     _rtw_memcpy(psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].Bssid, strIssueBssid, ETH_ALEN);
2171                     _rtw_memcpy(psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].PMKID, pPMK->pmkid, IW_PMKID_LEN);
2172
2173                     psecuritypriv->PMKIDList[ psecuritypriv->PMKIDIndex ].bUsed = _TRUE;
2174                     psecuritypriv->PMKIDIndex++ ;
2175                     if(psecuritypriv->PMKIDIndex==16)
2176                     {
2177                         psecuritypriv->PMKIDIndex =0;
2178                     }
2179                 }
2180         }
2181         else if ( pPMK->cmd == IW_PMKSA_REMOVE )
2182         {
2183                 DBG_871X( "[rtw_wx_set_pmkid] IW_PMKSA_REMOVE!\n" );
2184                 intReturn = _TRUE;
2185                 for(j=0 ; j<NUM_PMKID_CACHE; j++)
2186                 {
2187                         if( _rtw_memcmp( psecuritypriv->PMKIDList[j].Bssid, strIssueBssid, ETH_ALEN) ==_TRUE )
2188                         { // BSSID is matched, the same AP => Remove this PMKID information and reset it. 
2189                                 _rtw_memset( psecuritypriv->PMKIDList[ j ].Bssid, 0x00, ETH_ALEN );
2190                                 psecuritypriv->PMKIDList[ j ].bUsed = _FALSE;
2191                                 break;
2192                         }       
2193                 }
2194         }
2195         else if ( pPMK->cmd == IW_PMKSA_FLUSH ) 
2196         {
2197             DBG_871X( "[rtw_wx_set_pmkid] IW_PMKSA_FLUSH!\n" );
2198             _rtw_memset( &psecuritypriv->PMKIDList[ 0 ], 0x00, sizeof( RT_PMKID_LIST ) * NUM_PMKID_CACHE );
2199             psecuritypriv->PMKIDIndex = 0;
2200             intReturn = _TRUE;
2201         }
2202     return( intReturn );
2203 }
2204
2205 static int rtw_wx_get_sens(struct net_device *dev, 
2206                              struct iw_request_info *info, 
2207                              union iwreq_data *wrqu, char *extra)
2208 {
2209         #ifdef CONFIG_PLATFORM_ROCKCHIPS
2210         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2211         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv); 
2212         
2213         /*
2214         *  20110311 Commented by Jeff
2215         *  For rockchip platform's wpa_driver_wext_get_rssi
2216         */
2217         if(check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE) {
2218                 //wrqu->sens.value=-padapter->recvpriv.signal_strength;
2219                 wrqu->sens.value=-padapter->recvpriv.rssi;
2220                 //DBG_871X("%s: %d\n", __FUNCTION__, wrqu->sens.value);
2221                 wrqu->sens.fixed = 0; /* no auto select */ 
2222         } else 
2223         #endif
2224         {
2225                 wrqu->sens.value = 0;
2226                 wrqu->sens.fixed = 0;   /* no auto select */
2227                 wrqu->sens.disabled = 1;
2228         }
2229         return 0;
2230 }
2231
2232 static int rtw_wx_get_range(struct net_device *dev, 
2233                                 struct iw_request_info *info, 
2234                                 union iwreq_data *wrqu, char *extra)
2235 {
2236         struct iw_range *range = (struct iw_range *)extra;
2237         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2238         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
2239
2240         u16 val;
2241         int i;
2242         
2243         _func_enter_;
2244         
2245         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_range. cmd_code=%x\n", info->cmd));
2246
2247         wrqu->data.length = sizeof(*range);
2248         _rtw_memset(range, 0, sizeof(*range));
2249
2250         /* Let's try to keep this struct in the same order as in
2251          * linux/include/wireless.h
2252          */
2253
2254         /* TODO: See what values we can set, and remove the ones we can't
2255          * set, or fill them with some default data.
2256          */
2257
2258         /* ~5 Mb/s real (802.11b) */
2259         range->throughput = 5 * 1000 * 1000;     
2260
2261         // TODO: Not used in 802.11b?
2262 //      range->min_nwid;        /* Minimal NWID we are able to set */
2263         // TODO: Not used in 802.11b?
2264 //      range->max_nwid;        /* Maximal NWID we are able to set */
2265
2266         /* Old Frequency (backward compat - moved lower ) */
2267 //      range->old_num_channels; 
2268 //      range->old_num_frequency;
2269 //      range->old_freq[6]; /* Filler to keep "version" at the same offset */
2270
2271         /* signal level threshold range */
2272
2273         //percent values between 0 and 100.
2274         range->max_qual.qual = 100;     
2275         range->max_qual.level = 100;
2276         range->max_qual.noise = 100;
2277         range->max_qual.updated = 7; /* Updated all three */
2278
2279
2280         range->avg_qual.qual = 92; /* > 8% missed beacons is 'bad' */
2281         /* TODO: Find real 'good' to 'bad' threshol value for RSSI */
2282         range->avg_qual.level = 20 + -98;
2283         range->avg_qual.noise = 0;
2284         range->avg_qual.updated = 7; /* Updated all three */
2285
2286         range->num_bitrates = RATE_COUNT;
2287
2288         for (i = 0; i < RATE_COUNT && i < IW_MAX_BITRATES; i++) {
2289                 range->bitrate[i] = rtw_rates[i];
2290         }
2291
2292         range->min_frag = MIN_FRAG_THRESHOLD;
2293         range->max_frag = MAX_FRAG_THRESHOLD;
2294
2295         range->pm_capa = 0;
2296
2297         range->we_version_compiled = WIRELESS_EXT;
2298         range->we_version_source = 16;
2299
2300 //      range->retry_capa;      /* What retry options are supported */
2301 //      range->retry_flags;     /* How to decode max/min retry limit */
2302 //      range->r_time_flags;    /* How to decode max/min retry life */
2303 //      range->min_retry;       /* Minimal number of retries */
2304 //      range->max_retry;       /* Maximal number of retries */
2305 //      range->min_r_time;      /* Minimal retry lifetime */
2306 //      range->max_r_time;      /* Maximal retry lifetime */
2307
2308         for (i = 0, val = 0; i < MAX_CHANNEL_NUM; i++) {
2309
2310                 // Include only legal frequencies for some countries
2311                 if(pmlmeext->channel_set[i].ChannelNum != 0)
2312                 {
2313                         range->freq[val].i = pmlmeext->channel_set[i].ChannelNum;
2314                         range->freq[val].m = rtw_ch2freq(pmlmeext->channel_set[i].ChannelNum) * 100000;
2315                         range->freq[val].e = 1;
2316                         val++;
2317                 }
2318
2319                 if (val == IW_MAX_FREQUENCIES)
2320                         break;
2321         }
2322
2323         range->num_channels = val;
2324         range->num_frequency = val;
2325
2326 // Commented by Albert 2009/10/13
2327 // The following code will proivde the security capability to network manager.
2328 // If the driver doesn't provide this capability to network manager,
2329 // the WPA/WPA2 routers can't be choosen in the network manager.
2330
2331 /*
2332 #define IW_SCAN_CAPA_NONE               0x00
2333 #define IW_SCAN_CAPA_ESSID              0x01
2334 #define IW_SCAN_CAPA_BSSID              0x02
2335 #define IW_SCAN_CAPA_CHANNEL    0x04
2336 #define IW_SCAN_CAPA_MODE               0x08
2337 #define IW_SCAN_CAPA_RATE               0x10
2338 #define IW_SCAN_CAPA_TYPE               0x20
2339 #define IW_SCAN_CAPA_TIME               0x40
2340 */
2341
2342 #if WIRELESS_EXT > 17
2343         range->enc_capa = IW_ENC_CAPA_WPA|IW_ENC_CAPA_WPA2|
2344                           IW_ENC_CAPA_CIPHER_TKIP|IW_ENC_CAPA_CIPHER_CCMP;
2345 #endif
2346
2347 #ifdef IW_SCAN_CAPA_ESSID //WIRELESS_EXT > 21
2348         range->scan_capa = IW_SCAN_CAPA_ESSID | IW_SCAN_CAPA_TYPE |IW_SCAN_CAPA_BSSID|
2349                                         IW_SCAN_CAPA_CHANNEL|IW_SCAN_CAPA_MODE|IW_SCAN_CAPA_RATE;
2350 #endif
2351
2352
2353         _func_exit_;
2354
2355         return 0;
2356
2357 }
2358
2359 //set bssid flow
2360 //s1. rtw_set_802_11_infrastructure_mode()
2361 //s2. rtw_set_802_11_authentication_mode()
2362 //s3. set_802_11_encryption_mode()
2363 //s4. rtw_set_802_11_bssid()
2364 static int rtw_wx_set_wap(struct net_device *dev,
2365                          struct iw_request_info *info,
2366                          union iwreq_data *awrq,
2367                          char *extra)
2368 {
2369         _irqL   irqL;
2370         uint ret = 0;
2371         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2372         struct sockaddr *temp = (struct sockaddr *)awrq;
2373         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
2374         _list   *phead;
2375         u8 *dst_bssid, *src_bssid;
2376         _queue  *queue  = &(pmlmepriv->scanned_queue);
2377         struct  wlan_network    *pnetwork = NULL;
2378         NDIS_802_11_AUTHENTICATION_MODE authmode;
2379
2380         _func_enter_;
2381 /*
2382 #ifdef CONFIG_CONCURRENT_MODE
2383         if(padapter->iface_type > PRIMARY_IFACE)
2384         {
2385                 ret = -EINVAL;
2386                 goto exit;
2387         }
2388 #endif  
2389 */      
2390
2391 #ifdef CONFIG_CONCURRENT_MODE
2392         if (check_buddy_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE)
2393         {
2394                 DBG_871X("set bssid, but buddy_intf is under scanning or linking\n");
2395
2396                 ret = -EINVAL;
2397
2398                 goto exit;
2399         }
2400 #endif
2401
2402 #ifdef CONFIG_DUALMAC_CONCURRENT
2403         if (dc_check_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING)== _TRUE)
2404         {
2405                 DBG_871X("set bssid, but buddy_intf is under scanning or linking\n");
2406                 ret = -EINVAL;
2407                 goto exit;
2408         }
2409 #endif
2410
2411         rtw_ps_deny(padapter, PS_DENY_JOIN);
2412         if(_FAIL == rtw_pwr_wakeup(padapter))
2413         {
2414                 ret= -1;
2415                 goto exit;
2416         }
2417         
2418         if(!padapter->bup){
2419                 ret = -1;
2420                 goto exit;
2421         }
2422
2423         
2424         if (temp->sa_family != ARPHRD_ETHER){
2425                 ret = -EINVAL;
2426                 goto exit;
2427         }
2428
2429         authmode = padapter->securitypriv.ndisauthtype;
2430         _enter_critical_bh(&queue->lock, &irqL);
2431        phead = get_list_head(queue);
2432        pmlmepriv->pscanned = get_next(phead);
2433
2434         while (1)
2435          {
2436                         
2437                 if ((rtw_end_of_queue_search(phead, pmlmepriv->pscanned)) == _TRUE)
2438                 {
2439 #if 0           
2440                         ret = -EINVAL;
2441                         goto exit;
2442
2443                         if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE)
2444                         {
2445                                 rtw_set_802_11_bssid(padapter, temp->sa_data);
2446                                 goto exit;                    
2447                         }
2448                         else
2449                         {
2450                                 ret = -EINVAL;
2451                                 goto exit;
2452                         }
2453 #endif
2454
2455                         break;
2456                 }
2457         
2458                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
2459
2460                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
2461
2462                 dst_bssid = pnetwork->network.MacAddress;
2463
2464                 src_bssid = temp->sa_data;
2465
2466                 if ((_rtw_memcmp(dst_bssid, src_bssid, ETH_ALEN)) == _TRUE)
2467                 {                       
2468                         if(!rtw_set_802_11_infrastructure_mode(padapter, pnetwork->network.InfrastructureMode))
2469                         {
2470                                 ret = -1;
2471                                 _exit_critical_bh(&queue->lock, &irqL);
2472                                 goto exit;
2473                         }
2474
2475                                 break;                  
2476                 }
2477
2478         }               
2479         _exit_critical_bh(&queue->lock, &irqL);
2480         
2481         rtw_set_802_11_authentication_mode(padapter, authmode);
2482         //set_802_11_encryption_mode(padapter, padapter->securitypriv.ndisencryptstatus);
2483         if (rtw_set_802_11_bssid(padapter, temp->sa_data) == _FALSE) {
2484                 ret = -1;
2485                 goto exit;              
2486         }       
2487         
2488 exit:
2489         
2490         rtw_ps_deny_cancel(padapter, PS_DENY_JOIN);
2491
2492         _func_exit_;
2493         
2494         return ret;     
2495 }
2496
2497 static int rtw_wx_get_wap(struct net_device *dev, 
2498                             struct iw_request_info *info, 
2499                             union iwreq_data *wrqu, char *extra)
2500 {
2501
2502         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
2503         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
2504         WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;     
2505         
2506         wrqu->ap_addr.sa_family = ARPHRD_ETHER;
2507         
2508         _rtw_memset(wrqu->ap_addr.sa_data, 0, ETH_ALEN);
2509         
2510         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_wap\n"));
2511
2512         _func_enter_;
2513
2514         if  ( ((check_fwstate(pmlmepriv, _FW_LINKED)) == _TRUE) || 
2515                         ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == _TRUE) ||
2516                         ((check_fwstate(pmlmepriv, WIFI_AP_STATE)) == _TRUE) )
2517         {
2518
2519                 _rtw_memcpy(wrqu->ap_addr.sa_data, pcur_bss->MacAddress, ETH_ALEN);
2520         }
2521         else
2522         {
2523                 _rtw_memset(wrqu->ap_addr.sa_data, 0, ETH_ALEN);
2524         }               
2525
2526         _func_exit_;
2527         
2528         return 0;
2529         
2530 }
2531
2532 static int rtw_wx_set_mlme(struct net_device *dev, 
2533                              struct iw_request_info *info, 
2534                              union iwreq_data *wrqu, char *extra)
2535 {
2536 #if 0
2537 /* SIOCSIWMLME data */
2538 struct  iw_mlme
2539 {
2540         __u16           cmd; /* IW_MLME_* */
2541         __u16           reason_code;
2542         struct sockaddr addr;
2543 };
2544 #endif
2545
2546         int ret=0;
2547         u16 reason;
2548         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2549         struct iw_mlme *mlme = (struct iw_mlme *) extra;
2550
2551
2552         if(mlme==NULL)
2553                 return -1;
2554
2555         DBG_871X("%s\n", __FUNCTION__);
2556
2557         reason = cpu_to_le16(mlme->reason_code);
2558
2559
2560         DBG_871X("%s, cmd=%d, reason=%d\n", __FUNCTION__, mlme->cmd, reason);
2561         
2562
2563         switch (mlme->cmd) 
2564         {
2565                 case IW_MLME_DEAUTH:
2566                                 if(!rtw_set_802_11_disassociate(padapter))
2567                                 ret = -1;
2568                                 break;
2569
2570                 case IW_MLME_DISASSOC:
2571                                 if(!rtw_set_802_11_disassociate(padapter))
2572                                                 ret = -1;
2573
2574                                 break;
2575
2576                 default:
2577                         return -EOPNOTSUPP;
2578         }
2579
2580         return ret;
2581 }
2582
2583 static int rtw_wx_set_scan(struct net_device *dev, struct iw_request_info *a,
2584                              union iwreq_data *wrqu, char *extra)
2585 {
2586         u8 _status = _FALSE;
2587         int ret = 0;    
2588         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2589         struct mlme_priv *pmlmepriv= &padapter->mlmepriv;
2590         NDIS_802_11_SSID ssid[RTW_SSID_SCAN_AMOUNT];
2591         _irqL   irqL;
2592 #ifdef CONFIG_P2P
2593         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);   
2594 #endif //CONFIG_P2P
2595         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_set_scan\n"));
2596
2597 _func_enter_;
2598
2599         #ifdef DBG_IOCTL
2600         DBG_871X("DBG_IOCTL %s:%d\n",__FUNCTION__, __LINE__);
2601         #endif
2602 /*
2603 #ifdef CONFIG_CONCURRENT_MODE
2604         if(padapter->iface_type > PRIMARY_IFACE)
2605         {
2606                 ret = -1;
2607                 goto exit;
2608         }
2609 #endif
2610 */
2611 #ifdef CONFIG_MP_INCLUDED
2612                 if (padapter->registrypriv.mp_mode == 1)
2613                 {
2614                                 DBG_871X(FUNC_ADPT_FMT ": MP mode block Scan request\n", FUNC_ADPT_ARG(padapter));      
2615                                 ret = -1;
2616                                 goto exit;
2617                 }
2618 #ifdef CONFIG_CONCURRENT_MODE
2619                         if (padapter->pbuddy_adapter) {
2620                                 if (padapter->pbuddy_adapter->registrypriv.mp_mode == 1)
2621                                 {
2622                                         DBG_871X(FUNC_ADPT_FMT ": MP mode block Scan request\n", FUNC_ADPT_ARG(padapter->pbuddy_adapter));
2623                                         ret = -1;
2624                                         goto exit;
2625                                 }
2626                         }
2627 #endif //CONFIG_CONCURRENT_MODE
2628 #endif
2629
2630         rtw_ps_deny(padapter, PS_DENY_SCAN);
2631         if(_FAIL == rtw_pwr_wakeup(padapter))
2632         {
2633                 ret= -1;
2634                 goto exit;
2635         }
2636
2637         if(padapter->bDriverStopped){
2638            DBG_871X("bDriverStopped=%d\n", padapter->bDriverStopped);
2639                 ret= -1;
2640                 goto exit;
2641         }
2642         
2643         if(!padapter->bup){
2644                 ret = -1;
2645                 goto exit;
2646         }
2647         
2648         if (padapter->hw_init_completed==_FALSE){
2649                 ret = -1;
2650                 goto exit;
2651         }
2652
2653         // When Busy Traffic, driver do not site survey. So driver return success.
2654         // wpa_supplicant will not issue SIOCSIWSCAN cmd again after scan timeout.
2655         // modify by thomas 2011-02-22.
2656         if (pmlmepriv->LinkDetectInfo.bBusyTraffic == _TRUE
2657 #ifdef CONFIG_CONCURRENT_MODE
2658         || rtw_get_buddy_bBusyTraffic(padapter) == _TRUE
2659 #endif //CONFIG_CONCURRENT_MODE
2660         )
2661         {
2662                 indicate_wx_scan_complete_event(padapter);
2663                 goto exit;
2664         }
2665
2666         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE)
2667         {
2668                 indicate_wx_scan_complete_event(padapter);
2669                 goto exit;
2670         } 
2671
2672 #ifdef CONFIG_CONCURRENT_MODE
2673         if (check_buddy_fwstate(padapter,
2674                 _FW_UNDER_SURVEY|_FW_UNDER_LINKING|WIFI_UNDER_WPS) == _TRUE)
2675         {
2676                 indicate_wx_scan_complete_event(padapter);
2677                 goto exit;
2678         }
2679 #endif
2680
2681 #ifdef CONFIG_DUALMAC_CONCURRENT
2682         if (dc_check_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING)== _TRUE)
2683         {
2684                 indicate_wx_scan_complete_event(padapter);
2685                 goto exit;
2686         }
2687 #endif
2688
2689 #ifdef CONFIG_P2P
2690         if ( pwdinfo->p2p_state != P2P_STATE_NONE )
2691         {
2692                 rtw_p2p_set_pre_state( pwdinfo, rtw_p2p_state( pwdinfo ) );
2693                 rtw_p2p_set_state(pwdinfo, P2P_STATE_FIND_PHASE_SEARCH);
2694                 rtw_p2p_findphase_ex_set(pwdinfo, P2P_FINDPHASE_EX_FULL);
2695                 rtw_free_network_queue(padapter, _TRUE);
2696         }
2697 #endif //CONFIG_P2P
2698
2699         _rtw_memset(ssid, 0, sizeof(NDIS_802_11_SSID)*RTW_SSID_SCAN_AMOUNT);
2700
2701 #if WIRELESS_EXT >= 17
2702         if (wrqu->data.length == sizeof(struct iw_scan_req)) 
2703         {
2704                 struct iw_scan_req *req = (struct iw_scan_req *)extra;
2705         
2706                 if (wrqu->data.flags & IW_SCAN_THIS_ESSID)
2707                 {
2708                         int len = min((int)req->essid_len, IW_ESSID_MAX_SIZE);
2709
2710                         _rtw_memcpy(ssid[0].Ssid, req->essid, len);
2711                         ssid[0].SsidLength = len;       
2712
2713                         DBG_871X("IW_SCAN_THIS_ESSID, ssid=%s, len=%d\n", req->essid, req->essid_len);
2714                 
2715                         _enter_critical_bh(&pmlmepriv->lock, &irqL);                            
2716                 
2717                         _status = rtw_sitesurvey_cmd(padapter, ssid, 1, NULL, 0);
2718                 
2719                         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2720                         
2721                 }
2722                 else if (req->scan_type == IW_SCAN_TYPE_PASSIVE)
2723                 {
2724                         DBG_871X("rtw_wx_set_scan, req->scan_type == IW_SCAN_TYPE_PASSIVE\n");
2725                 }
2726                 
2727         }
2728         else
2729 #endif
2730
2731         if(     wrqu->data.length >= WEXT_CSCAN_HEADER_SIZE
2732                 && _rtw_memcmp(extra, WEXT_CSCAN_HEADER, WEXT_CSCAN_HEADER_SIZE) == _TRUE
2733         )
2734         {
2735                 int len = wrqu->data.length -WEXT_CSCAN_HEADER_SIZE;
2736                 char *pos = extra+WEXT_CSCAN_HEADER_SIZE;
2737                 char section;
2738                 char sec_len;
2739                 int ssid_index = 0;
2740
2741                 //DBG_871X("%s COMBO_SCAN header is recognized\n", __FUNCTION__);
2742                 
2743                 while(len >= 1) {
2744                         section = *(pos++); len-=1;
2745
2746                         switch(section) {
2747                                 case WEXT_CSCAN_SSID_SECTION:
2748                                         //DBG_871X("WEXT_CSCAN_SSID_SECTION\n");
2749                                         if(len < 1) {
2750                                                 len = 0;
2751                                                 break;
2752                                         }
2753                                         
2754                                         sec_len = *(pos++); len-=1;
2755
2756                                         if(sec_len>0 && sec_len<=len) {
2757                                                 ssid[ssid_index].SsidLength = sec_len;
2758                                                 _rtw_memcpy(ssid[ssid_index].Ssid, pos, ssid[ssid_index].SsidLength);
2759                                                 //DBG_871X("%s COMBO_SCAN with specific ssid:%s, %d\n", __FUNCTION__
2760                                                 //      , ssid[ssid_index].Ssid, ssid[ssid_index].SsidLength);
2761                                                 ssid_index++;
2762                                         }
2763                                         
2764                                         pos+=sec_len; len-=sec_len;
2765                                         break;
2766                                         
2767                                 
2768                                 case WEXT_CSCAN_CHANNEL_SECTION:
2769                                         //DBG_871X("WEXT_CSCAN_CHANNEL_SECTION\n");
2770                                         pos+=1; len-=1;
2771                                         break;
2772                                 case WEXT_CSCAN_ACTV_DWELL_SECTION:
2773                                         //DBG_871X("WEXT_CSCAN_ACTV_DWELL_SECTION\n");
2774                                         pos+=2; len-=2;
2775                                         break;
2776                                 case WEXT_CSCAN_PASV_DWELL_SECTION:
2777                                         //DBG_871X("WEXT_CSCAN_PASV_DWELL_SECTION\n");
2778                                         pos+=2; len-=2;                                 
2779                                         break;
2780                                 case WEXT_CSCAN_HOME_DWELL_SECTION:
2781                                         //DBG_871X("WEXT_CSCAN_HOME_DWELL_SECTION\n");
2782                                         pos+=2; len-=2;
2783                                         break;
2784                                 case WEXT_CSCAN_TYPE_SECTION:
2785                                         //DBG_871X("WEXT_CSCAN_TYPE_SECTION\n");
2786                                         pos+=1; len-=1;
2787                                         break;
2788                                 #if 0
2789                                 case WEXT_CSCAN_NPROBE_SECTION:
2790                                         DBG_871X("WEXT_CSCAN_NPROBE_SECTION\n");
2791                                         break;
2792                                 #endif
2793                                 
2794                                 default:
2795                                         //DBG_871X("Unknown CSCAN section %c\n", section);
2796                                         len = 0; // stop parsing
2797                         }
2798                         //DBG_871X("len:%d\n", len);
2799                         
2800                 }
2801                 
2802                 //jeff: it has still some scan paramater to parse, we only do this now...
2803                 _status = rtw_set_802_11_bssid_list_scan(padapter, ssid, RTW_SSID_SCAN_AMOUNT);
2804                 
2805         } else
2806         
2807         {
2808                 _status = rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
2809         }
2810
2811         if(_status == _FALSE)
2812                 ret = -1;
2813
2814 exit:
2815
2816         rtw_ps_deny_cancel(padapter, PS_DENY_SCAN);
2817
2818         #ifdef DBG_IOCTL
2819         DBG_871X("DBG_IOCTL %s:%d return %d\n",__FUNCTION__, __LINE__, ret);
2820         #endif
2821
2822 _func_exit_;
2823
2824         return ret;     
2825 }
2826
2827 static int rtw_wx_get_scan(struct net_device *dev, struct iw_request_info *a,
2828                              union iwreq_data *wrqu, char *extra)
2829 {
2830         _irqL   irqL;
2831         _list                                   *plist, *phead;
2832         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2833         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
2834         _queue                          *queue  = &(pmlmepriv->scanned_queue);
2835         struct  wlan_network    *pnetwork = NULL;
2836         char *ev = extra;
2837         char *stop = ev + wrqu->data.length;
2838         u32 ret = 0;
2839         u32 cnt=0;
2840         u32 wait_for_surveydone;
2841         sint wait_status;
2842 #ifdef CONFIG_CONCURRENT_MODE
2843         //PADAPTER pbuddy_adapter = padapter->pbuddy_adapter;
2844         //struct mlme_priv *pbuddy_mlmepriv = &(pbuddy_adapter->mlmepriv);      
2845 #endif
2846 #ifdef CONFIG_P2P
2847         struct  wifidirect_info*        pwdinfo = &padapter->wdinfo;
2848 #endif //CONFIG_P2P
2849         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan\n"));
2850         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_, (" Start of Query SIOCGIWSCAN .\n"));
2851
2852         _func_enter_;
2853
2854         #ifdef DBG_IOCTL
2855         DBG_871X("DBG_IOCTL %s:%d\n",__FUNCTION__, __LINE__);
2856         #endif
2857 /*
2858 #ifdef CONFIG_CONCURRENT_MODE
2859         if(padapter->iface_type > PRIMARY_IFACE)
2860         {
2861                 ret = -EINVAL;
2862                 goto exit;
2863         }
2864 #endif
2865 */      
2866         if(adapter_to_pwrctl(padapter)->brfoffbyhw && padapter->bDriverStopped)
2867         {
2868                 ret = -EINVAL;
2869                 goto exit;
2870         }
2871   
2872 #ifdef CONFIG_P2P
2873         if(!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
2874         {
2875                 //      P2P is enabled
2876                 if ( padapter->chip_type == RTL8192D )
2877                         wait_for_surveydone = 300;      //      Because the 8192du supports more channels.
2878                 else
2879                         wait_for_surveydone = 200;
2880         }
2881         else
2882         {
2883                 //      P2P is disabled
2884                 wait_for_surveydone = 100;
2885         }
2886 #else
2887         {
2888                 wait_for_surveydone = 100;
2889         }
2890 #endif //CONFIG_P2P
2891
2892 #if 1 // Wireless Extension use EAGAIN to try
2893         wait_status = _FW_UNDER_SURVEY
2894 #ifndef CONFIG_ANDROID
2895                 | _FW_UNDER_LINKING
2896 #endif
2897         ;
2898
2899         while (check_fwstate(pmlmepriv, wait_status) == _TRUE)
2900         {
2901                 return -EAGAIN;
2902         }
2903 #else
2904         wait_status = _FW_UNDER_SURVEY
2905                 #ifndef CONFIG_ANDROID
2906                 |_FW_UNDER_LINKING
2907                 #endif
2908         ;
2909
2910 #ifdef CONFIG_DUALMAC_CONCURRENT
2911         while(dc_check_fwstate(padapter, wait_status)== _TRUE)
2912         {
2913                 rtw_msleep_os(30);
2914                 cnt++;
2915                 if(cnt > wait_for_surveydone )
2916                         break;
2917         }
2918 #endif // CONFIG_DUALMAC_CONCURRENT
2919
2920         while(check_fwstate(pmlmepriv, wait_status) == _TRUE)
2921         {       
2922                 rtw_msleep_os(30);
2923                 cnt++;
2924                 if(cnt > wait_for_surveydone )
2925                         break;
2926         }
2927 #endif
2928         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2929
2930         phead = get_list_head(queue);
2931         plist = get_next(phead);
2932        
2933         while(1)
2934         {
2935                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
2936                         break;
2937
2938                 if((stop - ev) < SCAN_ITEM_SIZE) {
2939                         ret = -E2BIG;
2940                         break;
2941                 }
2942
2943                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
2944
2945                 //report network only if the current channel set contains the channel to which this network belongs
2946                 if(rtw_ch_set_search_ch(padapter->mlmeextpriv.channel_set, pnetwork->network.Configuration.DSConfig) >= 0
2947                         && rtw_mlme_band_check(padapter, pnetwork->network.Configuration.DSConfig) == _TRUE
2948                         && _TRUE == rtw_validate_ssid(&(pnetwork->network.Ssid))
2949                 )
2950                 {
2951                         ev=translate_scan(padapter, a, pnetwork, ev, stop);
2952                 }
2953
2954                 plist = get_next(plist);
2955         
2956         }        
2957
2958         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2959
2960        wrqu->data.length = ev-extra;
2961         wrqu->data.flags = 0;
2962         
2963 exit:           
2964         
2965         _func_exit_;    
2966         
2967         #ifdef DBG_IOCTL
2968         DBG_871X("DBG_IOCTL %s:%d return %d\n",__FUNCTION__, __LINE__, ret);
2969         #endif
2970         
2971         return ret ;
2972         
2973 }
2974
2975 //set ssid flow
2976 //s1. rtw_set_802_11_infrastructure_mode()
2977 //s2. set_802_11_authenticaion_mode()
2978 //s3. set_802_11_encryption_mode()
2979 //s4. rtw_set_802_11_ssid()
2980 static int rtw_wx_set_essid(struct net_device *dev, 
2981                               struct iw_request_info *a,
2982                               union iwreq_data *wrqu, char *extra)
2983 {
2984         _irqL irqL;
2985         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2986         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2987         _queue *queue = &pmlmepriv->scanned_queue;
2988         _list *phead;
2989         s8 status = _TRUE;
2990         struct wlan_network *pnetwork = NULL;
2991         NDIS_802_11_AUTHENTICATION_MODE authmode;       
2992         NDIS_802_11_SSID ndis_ssid;     
2993         u8 *dst_ssid, *src_ssid;
2994
2995         uint ret = 0, len;
2996
2997         _func_enter_;
2998         
2999         #ifdef DBG_IOCTL
3000         DBG_871X("DBG_IOCTL %s:%d\n",__FUNCTION__, __LINE__);
3001         #endif
3002         
3003 /*
3004 #ifdef CONFIG_CONCURRENT_MODE
3005         if(padapter->iface_type > PRIMARY_IFACE)
3006         {
3007                 ret = -EINVAL;
3008                 goto exit;
3009         }
3010 #endif
3011 */
3012
3013 #ifdef CONFIG_CONCURRENT_MODE
3014         if (check_buddy_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE)
3015         {               
3016                 DBG_871X("set ssid, but buddy_intf is under scanning or linking\n");
3017                 
3018                 ret = -EINVAL;
3019                 
3020                 goto exit;
3021         }
3022 #endif
3023
3024 #ifdef CONFIG_DUALMAC_CONCURRENT
3025         if (dc_check_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING)== _TRUE)
3026         {
3027                 DBG_871X("set bssid, but buddy_intf is under scanning or linking\n");
3028                 ret = -EINVAL;
3029                 goto exit;
3030         }
3031 #endif
3032
3033         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
3034                  ("+rtw_wx_set_essid: fw_state=0x%08x\n", get_fwstate(pmlmepriv)));
3035
3036         rtw_ps_deny(padapter, PS_DENY_JOIN);
3037         if(_FAIL == rtw_pwr_wakeup(padapter))
3038         {               
3039                 ret = -1;
3040                 goto exit;
3041         }
3042
3043         if(!padapter->bup){
3044                 ret = -1;
3045                 goto exit;
3046         }
3047
3048 #if WIRELESS_EXT <= 20
3049         if ((wrqu->essid.length-1) > IW_ESSID_MAX_SIZE){
3050 #else
3051         if (wrqu->essid.length > IW_ESSID_MAX_SIZE){
3052 #endif
3053                 ret= -E2BIG;
3054                 goto exit;
3055         }
3056         
3057         if(check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
3058                 ret = -1;
3059                 goto exit;
3060         }               
3061         
3062         authmode = padapter->securitypriv.ndisauthtype;
3063         DBG_871X("=>%s\n",__FUNCTION__);
3064         if (wrqu->essid.flags && wrqu->essid.length)
3065         {
3066                 // Commented by Albert 20100519
3067                 // We got the codes in "set_info" function of iwconfig source code.
3068                 //      =========================================
3069                 //      wrq.u.essid.length = strlen(essid) + 1;
3070                 //      if(we_kernel_version > 20)
3071                 //              wrq.u.essid.length--;
3072                 //      =========================================
3073                 //      That means, if the WIRELESS_EXT less than or equal to 20, the correct ssid len should subtract 1.
3074 #if WIRELESS_EXT <= 20
3075                 len = ((wrqu->essid.length-1) < IW_ESSID_MAX_SIZE) ? (wrqu->essid.length-1) : IW_ESSID_MAX_SIZE;
3076 #else
3077                 len = (wrqu->essid.length < IW_ESSID_MAX_SIZE) ? wrqu->essid.length : IW_ESSID_MAX_SIZE;
3078 #endif
3079
3080                 if( wrqu->essid.length != 33 )
3081                         DBG_871X("ssid=%s, len=%d\n", extra, wrqu->essid.length);
3082
3083                 _rtw_memset(&ndis_ssid, 0, sizeof(NDIS_802_11_SSID));
3084                 ndis_ssid.SsidLength = len;
3085                 _rtw_memcpy(ndis_ssid.Ssid, extra, len);                
3086                 src_ssid = ndis_ssid.Ssid;
3087                 
3088                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_, ("rtw_wx_set_essid: ssid=[%s]\n", src_ssid));
3089                 _enter_critical_bh(&queue->lock, &irqL);
3090                phead = get_list_head(queue);
3091               pmlmepriv->pscanned = get_next(phead);
3092
3093                 while (1)
3094                 {                       
3095                         if (rtw_end_of_queue_search(phead, pmlmepriv->pscanned) == _TRUE)
3096                         {
3097 #if 0                   
3098                                 if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE)
3099                                 {
3100                                         rtw_set_802_11_ssid(padapter, &ndis_ssid);
3101
3102                                         goto exit;                    
3103                                 }
3104                                 else
3105                                 {
3106                                         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("rtw_wx_set_ssid(): scanned_queue is empty\n"));
3107                                         ret = -EINVAL;
3108                                         goto exit;
3109                                 }
3110 #endif                  
3111                                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_warning_,
3112                                          ("rtw_wx_set_essid: scan_q is empty, set ssid to check if scanning again!\n"));
3113
3114                                 break;
3115                         }
3116         
3117                         pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
3118
3119                         pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
3120
3121                         dst_ssid = pnetwork->network.Ssid.Ssid;
3122
3123                         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
3124                                  ("rtw_wx_set_essid: dst_ssid=%s\n",
3125                                   pnetwork->network.Ssid.Ssid));
3126
3127                         if ((_rtw_memcmp(dst_ssid, src_ssid, ndis_ssid.SsidLength) == _TRUE) &&
3128                                 (pnetwork->network.Ssid.SsidLength==ndis_ssid.SsidLength))
3129                         {
3130                                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
3131                                          ("rtw_wx_set_essid: find match, set infra mode\n"));
3132                                 
3133                                 if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE)
3134                                 {
3135                                         if(pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
3136                                                 continue;
3137                                 }       
3138                                         
3139                                 if (rtw_set_802_11_infrastructure_mode(padapter, pnetwork->network.InfrastructureMode) == _FALSE)
3140                                 {
3141                                         ret = -1;
3142                                         _exit_critical_bh(&queue->lock, &irqL);
3143                                         goto exit;
3144                                 }
3145
3146                                 break;                  
3147                         }
3148                 }
3149                 _exit_critical_bh(&queue->lock, &irqL);
3150                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
3151                          ("set ssid: set_802_11_auth. mode=%d\n", authmode));
3152                 rtw_set_802_11_authentication_mode(padapter, authmode);
3153                 //set_802_11_encryption_mode(padapter, padapter->securitypriv.ndisencryptstatus);
3154                 if (rtw_set_802_11_ssid(padapter, &ndis_ssid) == _FALSE) {
3155                         ret = -1;
3156                         goto exit;
3157                 }       
3158         }                       
3159         
3160 exit:
3161
3162         rtw_ps_deny_cancel(padapter, PS_DENY_JOIN);
3163
3164         DBG_871X("<=%s, ret %d\n",__FUNCTION__, ret);
3165         
3166         #ifdef DBG_IOCTL
3167         DBG_871X("DBG_IOCTL %s:%d return %d\n",__FUNCTION__, __LINE__, ret);
3168         #endif
3169         
3170         _func_exit_;
3171         
3172         return ret;     
3173 }
3174
3175 static int rtw_wx_get_essid(struct net_device *dev, 
3176                               struct iw_request_info *a,
3177                               union iwreq_data *wrqu, char *extra)
3178 {
3179         u32 len,ret = 0;
3180         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3181         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
3182         WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
3183
3184         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_essid\n"));
3185
3186         _func_enter_;
3187
3188         if ( (check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE) ||
3189               (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == _TRUE))
3190         {
3191                 len = pcur_bss->Ssid.SsidLength;
3192
3193                 wrqu->essid.length = len;
3194                         
3195                 _rtw_memcpy(extra, pcur_bss->Ssid.Ssid, len);
3196
3197                 wrqu->essid.flags = 1;
3198         }
3199         else
3200         {
3201                 ret = -1;
3202                 goto exit;
3203         }
3204
3205 exit:
3206
3207         _func_exit_;
3208         
3209         return ret;
3210         
3211 }
3212
3213 static int rtw_wx_set_rate(struct net_device *dev, 
3214                               struct iw_request_info *a,
3215                               union iwreq_data *wrqu, char *extra)
3216 {
3217         int     i, ret = 0;
3218         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3219         u8      datarates[NumRates];
3220         u32     target_rate = wrqu->bitrate.value;
3221         u32     fixed = wrqu->bitrate.fixed;
3222         u32     ratevalue = 0;
3223          u8 mpdatarate[NumRates]={11, 10, 9, 8, 7, 6, 5, 4, 3, 2, 1, 0, 0xff};
3224
3225 _func_enter_;
3226
3227         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,(" rtw_wx_set_rate \n"));
3228         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("target_rate = %d, fixed = %d\n",target_rate,fixed));
3229         
3230         if(target_rate == -1){
3231                 ratevalue = 11;
3232                 goto set_rate;
3233         }
3234         target_rate = target_rate/100000;
3235
3236         switch(target_rate){
3237                 case 10:
3238                         ratevalue = 0;
3239                         break;
3240                 case 20:
3241                         ratevalue = 1;
3242                         break;
3243                 case 55:
3244                         ratevalue = 2;
3245                         break;
3246                 case 60:
3247                         ratevalue = 3;
3248                         break;
3249                 case 90:
3250                         ratevalue = 4;
3251                         break;
3252                 case 110:
3253                         ratevalue = 5;
3254                         break;
3255                 case 120:
3256                         ratevalue = 6;
3257                         break;
3258                 case 180:
3259                         ratevalue = 7;
3260                         break;
3261                 case 240:
3262                         ratevalue = 8;
3263                         break;
3264                 case 360:
3265                         ratevalue = 9;
3266                         break;
3267                 case 480:
3268                         ratevalue = 10;
3269                         break;
3270                 case 540:
3271                         ratevalue = 11;
3272                         break;
3273                 default:
3274                         ratevalue = 11;
3275                         break;
3276         }
3277
3278 set_rate:
3279
3280         for(i=0; i<NumRates; i++)
3281         {
3282                 if(ratevalue==mpdatarate[i])
3283                 {
3284                         datarates[i] = mpdatarate[i];
3285                         if(fixed == 0)
3286                                 break;
3287                 }
3288                 else{
3289                         datarates[i] = 0xff;
3290                 }
3291
3292                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("datarate_inx=%d\n",datarates[i]));
3293         }
3294
3295         if( rtw_setdatarate_cmd(padapter, datarates) !=_SUCCESS){
3296                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("rtw_wx_set_rate Fail!!!\n"));
3297                 ret = -1;
3298         }
3299
3300 _func_exit_;
3301
3302         return ret;
3303 }
3304
3305 static int rtw_wx_get_rate(struct net_device *dev, 
3306                              struct iw_request_info *info, 
3307                              union iwreq_data *wrqu, char *extra)
3308 {       
3309         u16 max_rate = 0;
3310
3311         max_rate = rtw_get_cur_max_rate((_adapter *)rtw_netdev_priv(dev));
3312
3313         if(max_rate == 0)
3314                 return -EPERM;
3315         
3316         wrqu->bitrate.fixed = 0;        /* no auto select */
3317         wrqu->bitrate.value = max_rate * 100000;
3318
3319         return 0;
3320 }
3321
3322 static int rtw_wx_set_rts(struct net_device *dev, 
3323                              struct iw_request_info *info, 
3324                              union iwreq_data *wrqu, char *extra)
3325 {
3326         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3327
3328         _func_enter_;
3329         
3330         if (wrqu->rts.disabled)
3331                 padapter->registrypriv.rts_thresh = 2347;
3332         else {
3333                 if (wrqu->rts.value < 0 ||
3334                     wrqu->rts.value > 2347)
3335                         return -EINVAL;
3336                 
3337                 padapter->registrypriv.rts_thresh = wrqu->rts.value;
3338         }
3339
3340         DBG_871X("%s, rts_thresh=%d\n", __func__, padapter->registrypriv.rts_thresh);
3341         
3342         _func_exit_;
3343         
3344         return 0;
3345
3346 }
3347
3348 static int rtw_wx_get_rts(struct net_device *dev, 
3349                              struct iw_request_info *info, 
3350                              union iwreq_data *wrqu, char *extra)
3351 {
3352         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3353         
3354         _func_enter_;
3355
3356         DBG_871X("%s, rts_thresh=%d\n", __func__, padapter->registrypriv.rts_thresh);   
3357         
3358         wrqu->rts.value = padapter->registrypriv.rts_thresh;
3359         wrqu->rts.fixed = 0;    /* no auto select */
3360         //wrqu->rts.disabled = (wrqu->rts.value == DEFAULT_RTS_THRESHOLD);
3361         
3362         _func_exit_;
3363         
3364         return 0;
3365 }
3366
3367 static int rtw_wx_set_frag(struct net_device *dev, 
3368                              struct iw_request_info *info, 
3369                              union iwreq_data *wrqu, char *extra)
3370 {
3371         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3372
3373         _func_enter_;
3374         
3375         if (wrqu->frag.disabled)
3376                 padapter->xmitpriv.frag_len = MAX_FRAG_THRESHOLD;
3377         else {
3378                 if (wrqu->frag.value < MIN_FRAG_THRESHOLD ||
3379                     wrqu->frag.value > MAX_FRAG_THRESHOLD)
3380                         return -EINVAL;
3381                 
3382                 padapter->xmitpriv.frag_len = wrqu->frag.value & ~0x1;
3383         }
3384
3385         DBG_871X("%s, frag_len=%d\n", __func__, padapter->xmitpriv.frag_len);
3386         
3387         _func_exit_;
3388         
3389         return 0;
3390         
3391 }
3392
3393 static int rtw_wx_get_frag(struct net_device *dev, 
3394                              struct iw_request_info *info, 
3395                              union iwreq_data *wrqu, char *extra)
3396 {
3397         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3398         
3399         _func_enter_;
3400
3401         DBG_871X("%s, frag_len=%d\n", __func__, padapter->xmitpriv.frag_len);
3402         
3403         wrqu->frag.value = padapter->xmitpriv.frag_len;
3404         wrqu->frag.fixed = 0;   /* no auto select */
3405         //wrqu->frag.disabled = (wrqu->frag.value == DEFAULT_FRAG_THRESHOLD);
3406         
3407         _func_exit_;
3408         
3409         return 0;
3410 }
3411
3412 static int rtw_wx_get_retry(struct net_device *dev, 
3413                              struct iw_request_info *info, 
3414                              union iwreq_data *wrqu, char *extra)
3415 {
3416         //_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3417
3418         
3419         wrqu->retry.value = 7;
3420         wrqu->retry.fixed = 0;  /* no auto select */
3421         wrqu->retry.disabled = 1;
3422         
3423         return 0;
3424
3425 }       
3426
3427 #if 0
3428 #define IW_ENCODE_INDEX         0x00FF  /* Token index (if needed) */
3429 #define IW_ENCODE_FLAGS         0xFF00  /* Flags defined below */
3430 #define IW_ENCODE_MODE          0xF000  /* Modes defined below */
3431 #define IW_ENCODE_DISABLED      0x8000  /* Encoding disabled */
3432 #define IW_ENCODE_ENABLED       0x0000  /* Encoding enabled */
3433 #define IW_ENCODE_RESTRICTED    0x4000  /* Refuse non-encoded packets */
3434 #define IW_ENCODE_OPEN          0x2000  /* Accept non-encoded packets */
3435 #define IW_ENCODE_NOKEY         0x0800  /* Key is write only, so not present */
3436 #define IW_ENCODE_TEMP          0x0400  /* Temporary key */
3437 /*
3438 iwconfig wlan0 key on -> flags = 0x6001 -> maybe it means auto
3439 iwconfig wlan0 key off -> flags = 0x8800
3440 iwconfig wlan0 key open -> flags = 0x2800
3441 iwconfig wlan0 key open 1234567890 -> flags = 0x2000
3442 iwconfig wlan0 key restricted -> flags = 0x4800
3443 iwconfig wlan0 key open [3] 1234567890 -> flags = 0x2003
3444 iwconfig wlan0 key restricted [2] 1234567890 -> flags = 0x4002
3445 iwconfig wlan0 key open [3] -> flags = 0x2803
3446 iwconfig wlan0 key restricted [2] -> flags = 0x4802
3447 */
3448 #endif
3449
3450 static int rtw_wx_set_enc(struct net_device *dev, 
3451                             struct iw_request_info *info, 
3452                             union iwreq_data *wrqu, char *keybuf)
3453 {       
3454         u32 key, ret = 0;
3455         u32 keyindex_provided;
3456         NDIS_802_11_WEP  wep;   
3457         NDIS_802_11_AUTHENTICATION_MODE authmode;
3458
3459         struct iw_point *erq = &(wrqu->encoding);
3460         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3461         struct pwrctrl_priv *pwrpriv = adapter_to_pwrctl(padapter);
3462         DBG_871X("+rtw_wx_set_enc, flags=0x%x\n", erq->flags);
3463
3464         _rtw_memset(&wep, 0, sizeof(NDIS_802_11_WEP));
3465         
3466         key = erq->flags & IW_ENCODE_INDEX;
3467         
3468         _func_enter_;   
3469
3470         if (erq->flags & IW_ENCODE_DISABLED)
3471         {
3472                 DBG_871X("EncryptionDisabled\n");
3473                 padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
3474                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
3475                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
3476                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Open; //open system
3477                 authmode = Ndis802_11AuthModeOpen;
3478                 padapter->securitypriv.ndisauthtype=authmode;
3479                 
3480                 goto exit;
3481         }
3482
3483         if (key) {
3484                 if (key > WEP_KEYS)
3485                         return -EINVAL;
3486                 key--;
3487                 keyindex_provided = 1;
3488         } 
3489         else
3490         {
3491                 keyindex_provided = 0;
3492                 key = padapter->securitypriv.dot11PrivacyKeyIndex;
3493                 DBG_871X("rtw_wx_set_enc, key=%d\n", key);
3494         }
3495         
3496         //set authentication mode       
3497         if(erq->flags & IW_ENCODE_OPEN)
3498         {
3499                 DBG_871X("rtw_wx_set_enc():IW_ENCODE_OPEN\n");
3500                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;//Ndis802_11EncryptionDisabled;
3501
3502 #ifdef CONFIG_PLATFORM_MT53XX
3503                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
3504 #else
3505                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Open;
3506 #endif
3507
3508                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
3509                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
3510                 authmode = Ndis802_11AuthModeOpen;
3511                 padapter->securitypriv.ndisauthtype=authmode;
3512         }       
3513         else if(erq->flags & IW_ENCODE_RESTRICTED)
3514         {               
3515                 DBG_871X("rtw_wx_set_enc():IW_ENCODE_RESTRICTED\n");
3516                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
3517
3518 #ifdef CONFIG_PLATFORM_MT53XX
3519                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
3520 #else
3521                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Shared;
3522 #endif
3523
3524                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP40_;
3525                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP40_;                    
3526                 authmode = Ndis802_11AuthModeShared;
3527                 padapter->securitypriv.ndisauthtype=authmode;
3528         }
3529         else
3530         {
3531                 DBG_871X("rtw_wx_set_enc():erq->flags=0x%x\n", erq->flags);
3532
3533                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;//Ndis802_11EncryptionDisabled;
3534                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Open; //open system
3535                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
3536                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
3537                 authmode = Ndis802_11AuthModeOpen;
3538                 padapter->securitypriv.ndisauthtype=authmode;
3539         }
3540         
3541         wep.KeyIndex = key;
3542         if (erq->length > 0)
3543         {
3544                 wep.KeyLength = erq->length <= 5 ? 5 : 13;
3545
3546                 wep.Length = wep.KeyLength + FIELD_OFFSET(NDIS_802_11_WEP, KeyMaterial);
3547         }
3548         else
3549         {
3550                 wep.KeyLength = 0 ;
3551                 
3552                 if(keyindex_provided == 1)// set key_id only, no given KeyMaterial(erq->length==0).
3553                 {
3554                         padapter->securitypriv.dot11PrivacyKeyIndex = key;
3555
3556                         DBG_871X("(keyindex_provided == 1), keyid=%d, key_len=%d\n", key, padapter->securitypriv.dot11DefKeylen[key]);
3557
3558                         switch(padapter->securitypriv.dot11DefKeylen[key])
3559                         {
3560                                 case 5:
3561                                         padapter->securitypriv.dot11PrivacyAlgrthm=_WEP40_;                                     
3562                                         break;
3563                                 case 13:
3564                                         padapter->securitypriv.dot11PrivacyAlgrthm=_WEP104_;                                    
3565                                         break;
3566                                 default:
3567                                         padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;                                        
3568                                         break;
3569                         }
3570                                 
3571                         goto exit;
3572                         
3573                 }
3574                 
3575         }
3576
3577         wep.KeyIndex |= 0x80000000;
3578
3579         _rtw_memcpy(wep.KeyMaterial, keybuf, wep.KeyLength);
3580         
3581         if (rtw_set_802_11_add_wep(padapter, &wep) == _FALSE) {
3582                 if(rf_on == pwrpriv->rf_pwrstate )
3583                         ret = -EOPNOTSUPP;
3584                 goto exit;
3585         }       
3586
3587 exit:
3588         
3589         _func_exit_;
3590         
3591         return ret;
3592         
3593 }
3594
3595 static int rtw_wx_get_enc(struct net_device *dev, 
3596                             struct iw_request_info *info, 
3597                             union iwreq_data *wrqu, char *keybuf)
3598 {
3599         uint key, ret =0;
3600         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3601         struct iw_point *erq = &(wrqu->encoding);
3602         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
3603
3604         _func_enter_;
3605         
3606         if(check_fwstate(pmlmepriv, _FW_LINKED) != _TRUE)
3607         {
3608                  if(check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) != _TRUE)
3609                  {
3610                 erq->length = 0;
3611                 erq->flags |= IW_ENCODE_DISABLED;
3612                 return 0;
3613         }       
3614         }       
3615
3616         
3617         key = erq->flags & IW_ENCODE_INDEX;
3618
3619         if (key) {
3620                 if (key > WEP_KEYS)
3621                         return -EINVAL;
3622                 key--;
3623         } else
3624         {
3625                 key = padapter->securitypriv.dot11PrivacyKeyIndex;
3626         }       
3627
3628         erq->flags = key + 1;
3629
3630         //if(padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeOpen)
3631         //{
3632         //      erq->flags |= IW_ENCODE_OPEN;
3633         //}       
3634         
3635         switch(padapter->securitypriv.ndisencryptstatus)
3636         {
3637                 case Ndis802_11EncryptionNotSupported:
3638                 case Ndis802_11EncryptionDisabled:
3639
3640                 erq->length = 0;
3641                 erq->flags |= IW_ENCODE_DISABLED;
3642         
3643                 break;
3644                 
3645                 case Ndis802_11Encryption1Enabled:                                      
3646                 
3647                 erq->length = padapter->securitypriv.dot11DefKeylen[key];               
3648
3649                 if(erq->length)
3650                 {
3651                         _rtw_memcpy(keybuf, padapter->securitypriv.dot11DefKey[key].skey, padapter->securitypriv.dot11DefKeylen[key]);
3652                 
3653                 erq->flags |= IW_ENCODE_ENABLED;
3654
3655                         if(padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeOpen)
3656                         {
3657                                 erq->flags |= IW_ENCODE_OPEN;
3658                         }
3659                         else if(padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeShared)
3660                         {
3661                 erq->flags |= IW_ENCODE_RESTRICTED;
3662                         }       
3663                 }       
3664                 else
3665                 {
3666                         erq->length = 0;
3667                         erq->flags |= IW_ENCODE_DISABLED;
3668                 }
3669
3670                 break;
3671
3672                 case Ndis802_11Encryption2Enabled:
3673                 case Ndis802_11Encryption3Enabled:
3674
3675                 erq->length = 16;
3676                 erq->flags |= (IW_ENCODE_ENABLED | IW_ENCODE_OPEN | IW_ENCODE_NOKEY);
3677
3678                 break;
3679         
3680                 default:
3681                 erq->length = 0;
3682                 erq->flags |= IW_ENCODE_DISABLED;
3683
3684                 break;
3685                 
3686         }
3687         
3688         _func_exit_;
3689         
3690         return ret;
3691         
3692 }                                    
3693
3694 static int rtw_wx_get_power(struct net_device *dev, 
3695                              struct iw_request_info *info, 
3696                              union iwreq_data *wrqu, char *extra)
3697 {
3698         //_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3699         
3700         wrqu->power.value = 0;
3701         wrqu->power.fixed = 0;  /* no auto select */
3702         wrqu->power.disabled = 1;
3703         
3704         return 0;
3705
3706 }
3707
3708 static int rtw_wx_set_gen_ie(struct net_device *dev, 
3709                              struct iw_request_info *info, 
3710                              union iwreq_data *wrqu, char *extra)
3711 {
3712         int ret;
3713         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3714         
3715        ret = rtw_set_wpa_ie(padapter, extra, wrqu->data.length);
3716            
3717         return ret;
3718 }       
3719
3720 static int rtw_wx_set_auth(struct net_device *dev, 
3721                              struct iw_request_info *info, 
3722                              union iwreq_data *wrqu, char *extra)
3723 {
3724         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3725         struct iw_param *param = (struct iw_param*)&(wrqu->param);
3726         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
3727         struct security_priv *psecuritypriv = &padapter->securitypriv;
3728         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
3729         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
3730         u32 value = param->value;
3731         int ret = 0;
3732         
3733         switch (param->flags & IW_AUTH_INDEX) {
3734
3735         case IW_AUTH_WPA_VERSION:
3736 #ifdef CONFIG_WAPI_SUPPORT
3737 #ifndef CONFIG_IOCTL_CFG80211
3738                  padapter->wapiInfo.bWapiEnable = false;
3739                  if(value == IW_AUTH_WAPI_VERSION_1)
3740                  {
3741                         padapter->wapiInfo.bWapiEnable = true;
3742                         psecuritypriv->dot11PrivacyAlgrthm = _SMS4_;
3743                         psecuritypriv->dot118021XGrpPrivacy = _SMS4_;
3744                         psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_WAPI;
3745                         pmlmeinfo->auth_algo = psecuritypriv->dot11AuthAlgrthm;
3746                         padapter->wapiInfo.extra_prefix_len = WAPI_EXT_LEN;
3747                         padapter->wapiInfo.extra_postfix_len = SMS4_MIC_LEN;
3748                 }
3749 #endif
3750 #endif
3751                 break;
3752         case IW_AUTH_CIPHER_PAIRWISE:
3753                 
3754                 break;
3755         case IW_AUTH_CIPHER_GROUP:
3756                 
3757                 break;
3758         case IW_AUTH_KEY_MGMT:
3759 #ifdef CONFIG_WAPI_SUPPORT
3760 #ifndef CONFIG_IOCTL_CFG80211
3761                 DBG_871X("rtw_wx_set_auth: IW_AUTH_KEY_MGMT case \n");
3762                 if(value == IW_AUTH_KEY_MGMT_WAPI_PSK)
3763                         padapter->wapiInfo.bWapiPSK = true;
3764                 else
3765                         padapter->wapiInfo.bWapiPSK = false;
3766                 DBG_871X("rtw_wx_set_auth: IW_AUTH_KEY_MGMT bwapipsk %d \n",padapter->wapiInfo.bWapiPSK);
3767 #endif
3768 #endif
3769                 /*
3770                  *  ??? does not use these parameters
3771                  */
3772                 break;
3773
3774         case IW_AUTH_TKIP_COUNTERMEASURES:
3775         {
3776             if ( param->value )
3777             {  // wpa_supplicant is enabling the tkip countermeasure.
3778                padapter->securitypriv.btkip_countermeasure = _TRUE; 
3779             }
3780             else
3781             {  // wpa_supplicant is disabling the tkip countermeasure.
3782                padapter->securitypriv.btkip_countermeasure = _FALSE; 
3783             }
3784                 break;
3785         }
3786         case IW_AUTH_DROP_UNENCRYPTED:
3787                 {
3788                         /* HACK:
3789                          *
3790                          * wpa_supplicant calls set_wpa_enabled when the driver
3791                          * is loaded and unloaded, regardless of if WPA is being
3792                          * used.  No other calls are made which can be used to
3793                          * determine if encryption will be used or not prior to
3794                          * association being expected.  If encryption is not being
3795                          * used, drop_unencrypted is set to false, else true -- we
3796                          * can use this to determine if the CAP_PRIVACY_ON bit should
3797                          * be set.
3798                          */
3799
3800                         if(padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption1Enabled)
3801                         {
3802                                 break;//it means init value, or using wep, ndisencryptstatus = Ndis802_11Encryption1Enabled, 
3803                                                 // then it needn't reset it;
3804                         }
3805                         
3806                         if(param->value){
3807                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
3808                                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
3809                                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
3810                                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Open; //open system
3811                                 padapter->securitypriv.ndisauthtype=Ndis802_11AuthModeOpen;
3812                         }
3813                         
3814                         break;
3815                 }
3816
3817         case IW_AUTH_80211_AUTH_ALG:
3818
3819                 #if defined(CONFIG_ANDROID) || 1
3820                 /*
3821                  *  It's the starting point of a link layer connection using wpa_supplicant
3822                 */
3823                 if(check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
3824                         LeaveAllPowerSaveMode(padapter);
3825                         rtw_disassoc_cmd(padapter, 500, _FALSE);
3826                         DBG_871X("%s...call rtw_indicate_disconnect\n ",__FUNCTION__);
3827                         rtw_indicate_disconnect(padapter);
3828                         rtw_free_assoc_resources(padapter, 1);
3829                 }
3830                 #endif
3831
3832
3833                 ret = wpa_set_auth_algs(dev, (u32)param->value);                
3834         
3835                 break;
3836
3837         case IW_AUTH_WPA_ENABLED:
3838
3839                 //if(param->value)
3840                 //      padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_8021X; //802.1x
3841                 //else
3842                 //      padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open;//open system
3843                 
3844                 //_disassociate(priv);
3845                 
3846                 break;
3847
3848         case IW_AUTH_RX_UNENCRYPTED_EAPOL:
3849                 //ieee->ieee802_1x = param->value;
3850                 break;
3851
3852         case IW_AUTH_PRIVACY_INVOKED:
3853                 //ieee->privacy_invoked = param->value;
3854                 break;
3855
3856 #ifdef CONFIG_WAPI_SUPPORT
3857 #ifndef CONFIG_IOCTL_CFG80211
3858         case IW_AUTH_WAPI_ENABLED:
3859                 break;
3860 #endif
3861 #endif
3862
3863         default:
3864                 return -EOPNOTSUPP;
3865                 
3866         }
3867         
3868         return ret;
3869         
3870 }
3871
3872 static int rtw_wx_set_enc_ext(struct net_device *dev, 
3873                              struct iw_request_info *info, 
3874                              union iwreq_data *wrqu, char *extra)
3875 {
3876         char *alg_name;
3877         u32 param_len;
3878         struct ieee_param *param = NULL;
3879         struct iw_point *pencoding = &wrqu->encoding;
3880         struct iw_encode_ext *pext = (struct iw_encode_ext *)extra;
3881         int ret=0;
3882
3883         param_len = sizeof(struct ieee_param) + pext->key_len;
3884         param = (struct ieee_param *)rtw_malloc(param_len);
3885         if (param == NULL)
3886                 return -1;
3887         
3888         _rtw_memset(param, 0, param_len);
3889
3890         param->cmd = IEEE_CMD_SET_ENCRYPTION;
3891         _rtw_memset(param->sta_addr, 0xff, ETH_ALEN);
3892
3893
3894         switch (pext->alg) {
3895         case IW_ENCODE_ALG_NONE:
3896                 //todo: remove key 
3897                 //remove = 1;   
3898                 alg_name = "none";
3899                 break;
3900         case IW_ENCODE_ALG_WEP:
3901                 alg_name = "WEP";
3902                 break;
3903         case IW_ENCODE_ALG_TKIP:
3904                 alg_name = "TKIP";
3905                 break;
3906         case IW_ENCODE_ALG_CCMP:
3907                 alg_name = "CCMP";
3908                 break;
3909 #ifdef CONFIG_IEEE80211W
3910         case IW_ENCODE_ALG_AES_CMAC:
3911                 alg_name = "BIP";
3912                 break;
3913 #endif //CONFIG_IEEE80211W
3914 #ifdef CONFIG_WAPI_SUPPORT
3915 #ifndef CONFIG_IOCTL_CFG80211
3916         case IW_ENCODE_ALG_SM4:
3917                 alg_name= "SMS4";
3918                 _rtw_memcpy(param->sta_addr, pext->addr.sa_data, ETH_ALEN);
3919                 DBG_871X("rtw_wx_set_enc_ext: SMS4 case \n");
3920                 break;
3921 #endif
3922 #endif
3923         default:
3924                 ret = -1;
3925                 goto exit;
3926         }
3927
3928         strncpy((char *)param->u.crypt.alg, alg_name, IEEE_CRYPT_ALG_NAME_LEN);
3929
3930         if (pext->ext_flags & IW_ENCODE_EXT_SET_TX_KEY)
3931         {
3932                 param->u.crypt.set_tx = 1;
3933         }
3934
3935         /* cliW: WEP does not have group key
3936          * just not checking GROUP key setting 
3937          */
3938         if ((pext->alg != IW_ENCODE_ALG_WEP) &&
3939                 ((pext->ext_flags & IW_ENCODE_EXT_GROUP_KEY)
3940 #ifdef CONFIG_IEEE80211W
3941                 || (pext->ext_flags & IW_ENCODE_ALG_AES_CMAC)
3942 #endif //CONFIG_IEEE80211W
3943         ))
3944         {
3945                 param->u.crypt.set_tx = 0;
3946         }
3947
3948         param->u.crypt.idx = (pencoding->flags&0x00FF) -1 ;
3949
3950         if (pext->ext_flags & IW_ENCODE_EXT_RX_SEQ_VALID)
3951         {
3952 #ifdef CONFIG_WAPI_SUPPORT
3953 #ifndef CONFIG_IOCTL_CFG80211
3954                 if(pext->alg == IW_ENCODE_ALG_SM4)
3955                         _rtw_memcpy(param->u.crypt.seq, pext->rx_seq, 16);
3956                 else
3957 #endif //CONFIG_IOCTL_CFG80211
3958 #endif //CONFIG_WAPI_SUPPORT
3959                 _rtw_memcpy(param->u.crypt.seq, pext->rx_seq, 8);
3960         }
3961
3962         if(pext->key_len)
3963         {
3964                 param->u.crypt.key_len = pext->key_len;
3965                 //_rtw_memcpy(param + 1, pext + 1, pext->key_len);
3966                 _rtw_memcpy(param->u.crypt.key, pext + 1, pext->key_len);
3967         }
3968
3969         if (pencoding->flags & IW_ENCODE_DISABLED)
3970         {
3971                 //todo: remove key 
3972                 //remove = 1;
3973         }
3974
3975         ret =  wpa_set_encryption(dev, param, param_len);
3976
3977 exit:
3978         if(param)
3979         {
3980                 rtw_mfree((u8*)param, param_len);
3981         }
3982
3983         return ret;
3984 }
3985
3986
3987 static int rtw_wx_get_nick(struct net_device *dev, 
3988                              struct iw_request_info *info, 
3989                              union iwreq_data *wrqu, char *extra)
3990 {       
3991         //_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3992          //struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3993          //struct security_priv *psecuritypriv = &padapter->securitypriv;
3994
3995         if(extra)
3996         {
3997                 wrqu->data.length = 14;
3998                 wrqu->data.flags = 1;
3999                 _rtw_memcpy(extra, "<WIFI@REALTEK>", 14);
4000         }
4001
4002         //rtw_signal_process(pid, SIGUSR1); //for test
4003
4004         //dump debug info here  
4005 /*
4006         u32 dot11AuthAlgrthm;           // 802.11 auth, could be open, shared, and 8021x
4007         u32 dot11PrivacyAlgrthm;        // This specify the privacy for shared auth. algorithm.
4008         u32 dot118021XGrpPrivacy;       // This specify the privacy algthm. used for Grp key 
4009         u32 ndisauthtype;
4010         u32 ndisencryptstatus;
4011 */
4012
4013         //DBG_871X("auth_alg=0x%x, enc_alg=0x%x, auth_type=0x%x, enc_type=0x%x\n", 
4014         //              psecuritypriv->dot11AuthAlgrthm, psecuritypriv->dot11PrivacyAlgrthm,
4015         //              psecuritypriv->ndisauthtype, psecuritypriv->ndisencryptstatus);
4016         
4017         //DBG_871X("enc_alg=0x%x\n", psecuritypriv->dot11PrivacyAlgrthm);
4018         //DBG_871X("auth_type=0x%x\n", psecuritypriv->ndisauthtype);
4019         //DBG_871X("enc_type=0x%x\n", psecuritypriv->ndisencryptstatus);
4020
4021 #if 0
4022         DBG_871X("dbg(0x210)=0x%x\n", rtw_read32(padapter, 0x210));
4023         DBG_871X("dbg(0x608)=0x%x\n", rtw_read32(padapter, 0x608));
4024         DBG_871X("dbg(0x280)=0x%x\n", rtw_read32(padapter, 0x280));
4025         DBG_871X("dbg(0x284)=0x%x\n", rtw_read32(padapter, 0x284));
4026         DBG_871X("dbg(0x288)=0x%x\n", rtw_read32(padapter, 0x288));
4027         
4028         DBG_871X("dbg(0x664)=0x%x\n", rtw_read32(padapter, 0x664));
4029
4030
4031         DBG_871X("\n");
4032
4033         DBG_871X("dbg(0x430)=0x%x\n", rtw_read32(padapter, 0x430));
4034         DBG_871X("dbg(0x438)=0x%x\n", rtw_read32(padapter, 0x438));
4035
4036         DBG_871X("dbg(0x440)=0x%x\n", rtw_read32(padapter, 0x440));
4037         
4038         DBG_871X("dbg(0x458)=0x%x\n", rtw_read32(padapter, 0x458));
4039         
4040         DBG_871X("dbg(0x484)=0x%x\n", rtw_read32(padapter, 0x484));
4041         DBG_871X("dbg(0x488)=0x%x\n", rtw_read32(padapter, 0x488));
4042         
4043         DBG_871X("dbg(0x444)=0x%x\n", rtw_read32(padapter, 0x444));
4044         DBG_871X("dbg(0x448)=0x%x\n", rtw_read32(padapter, 0x448));
4045         DBG_871X("dbg(0x44c)=0x%x\n", rtw_read32(padapter, 0x44c));
4046         DBG_871X("dbg(0x450)=0x%x\n", rtw_read32(padapter, 0x450));
4047 #endif
4048         
4049         return 0;
4050
4051 }
4052
4053 static int rtw_wx_read32(struct net_device *dev,
4054                             struct iw_request_info *info,
4055                             union iwreq_data *wrqu, char *extra)
4056 {
4057         PADAPTER padapter;
4058         struct iw_point *p;
4059         u16 len;
4060         u32 addr;
4061         u32 data32;
4062         u32 bytes;
4063         u8 *ptmp;
4064         int ret;
4065
4066
4067         ret = 0;
4068         padapter = (PADAPTER)rtw_netdev_priv(dev);
4069         p = &wrqu->data;
4070         len = p->length;
4071         if (0 == len)
4072                 return -EINVAL;
4073
4074         ptmp = (u8*)rtw_malloc(len);
4075         if (NULL == ptmp)
4076                 return -ENOMEM;
4077
4078         if (copy_from_user(ptmp, p->pointer, len)) {
4079                 ret = -EFAULT;
4080                 goto exit;
4081         }
4082
4083         bytes = 0;
4084         addr = 0;
4085         sscanf(ptmp, "%d,%x", &bytes, &addr);
4086
4087         switch (bytes) {
4088                 case 1:
4089                         data32 = rtw_read8(padapter, addr);
4090                         sprintf(extra, "0x%02X", data32);
4091                         break;
4092                 case 2:
4093                         data32 = rtw_read16(padapter, addr);
4094                         sprintf(extra, "0x%04X", data32);
4095                         break;
4096                 case 4:
4097                         data32 = rtw_read32(padapter, addr);
4098                         sprintf(extra, "0x%08X", data32);
4099                         break;
4100                 default:
4101                         DBG_871X(KERN_INFO "%s: usage> read [bytes],[address(hex)]\n", __func__);
4102                         ret = -EINVAL;
4103                         goto exit;
4104         }
4105         DBG_871X(KERN_INFO "%s: addr=0x%08X data=%s\n", __func__, addr, extra);
4106
4107 exit:
4108         rtw_mfree(ptmp, len);
4109
4110         return 0;
4111 }
4112
4113 static int rtw_wx_write32(struct net_device *dev,
4114                             struct iw_request_info *info,
4115                             union iwreq_data *wrqu, char *extra)
4116 {
4117         PADAPTER padapter = (PADAPTER)rtw_netdev_priv(dev);
4118
4119         u32 addr;
4120         u32 data32;
4121         u32 bytes;
4122
4123
4124         bytes = 0;
4125         addr = 0;
4126         data32 = 0;
4127         sscanf(extra, "%d,%x,%x", &bytes, &addr, &data32);
4128
4129         switch (bytes) {
4130                 case 1:
4131                         rtw_write8(padapter, addr, (u8)data32);
4132                         DBG_871X(KERN_INFO "%s: addr=0x%08X data=0x%02X\n", __func__, addr, (u8)data32);
4133                         break;
4134                 case 2:
4135                         rtw_write16(padapter, addr, (u16)data32);
4136                         DBG_871X(KERN_INFO "%s: addr=0x%08X data=0x%04X\n", __func__, addr, (u16)data32);
4137                         break;
4138                 case 4:
4139                         rtw_write32(padapter, addr, data32);
4140                         DBG_871X(KERN_INFO "%s: addr=0x%08X data=0x%08X\n", __func__, addr, data32);
4141                         break;
4142                 default:
4143                         DBG_871X(KERN_INFO "%s: usage> write [bytes],[address(hex)],[data(hex)]\n", __func__);
4144                         return -EINVAL;
4145         }
4146
4147         return 0;
4148 }
4149
4150 static int rtw_wx_read_rf(struct net_device *dev,
4151                             struct iw_request_info *info,
4152                             union iwreq_data *wrqu, char *extra)
4153 {
4154         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4155         u32 path, addr, data32;
4156
4157
4158         path = *(u32*)extra;
4159         addr = *((u32*)extra + 1);
4160         data32 = rtw_hal_read_rfreg(padapter, path, addr, 0xFFFFF);
4161 //      DBG_871X("%s: path=%d addr=0x%02x data=0x%05x\n", __func__, path, addr, data32);
4162         /*
4163          * IMPORTANT!!
4164          * Only when wireless private ioctl is at odd order,
4165          * "extra" would be copied to user space.
4166          */
4167         sprintf(extra, "0x%05x", data32);
4168
4169         return 0;
4170 }
4171
4172 static int rtw_wx_write_rf(struct net_device *dev,
4173                             struct iw_request_info *info,
4174                             union iwreq_data *wrqu, char *extra)
4175 {
4176         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4177         u32 path, addr, data32;
4178
4179
4180         path = *(u32*)extra;
4181         addr = *((u32*)extra + 1);
4182         data32 = *((u32*)extra + 2);
4183 //      DBG_871X("%s: path=%d addr=0x%02x data=0x%05x\n", __func__, path, addr, data32);
4184         rtw_hal_write_rfreg(padapter, path, addr, 0xFFFFF, data32);
4185
4186         return 0;
4187 }
4188
4189 static int rtw_wx_priv_null(struct net_device *dev, struct iw_request_info *a,
4190                  union iwreq_data *wrqu, char *b)
4191 {
4192         return -1;
4193 }
4194
4195 static int dummy(struct net_device *dev, struct iw_request_info *a,
4196                  union iwreq_data *wrqu, char *b)
4197 {
4198         //_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);        
4199         //struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
4200
4201         //DBG_871X("cmd_code=%x, fwstate=0x%x\n", a->cmd, get_fwstate(pmlmepriv));
4202         
4203         return -1;
4204         
4205 }
4206
4207 static int rtw_wx_set_channel_plan(struct net_device *dev,
4208                                struct iw_request_info *info,
4209                                union iwreq_data *wrqu, char *extra)
4210 {
4211         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4212         struct registry_priv *pregistrypriv = &padapter->registrypriv;
4213         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
4214         extern int rtw_channel_plan;
4215         u8 channel_plan_req = (u8) (*((int *)wrqu));
4216
4217         #if 0
4218         rtw_channel_plan = (int)wrqu->data.pointer;
4219         pregistrypriv->channel_plan = rtw_channel_plan;
4220         pmlmepriv->ChannelPlan = pregistrypriv->channel_plan;
4221         #endif
4222
4223         if (_SUCCESS == rtw_set_chplan_cmd(padapter, channel_plan_req, 1, 1)) {
4224                 DBG_871X("%s set channel_plan = 0x%02X\n", __func__, pmlmepriv->ChannelPlan);
4225         } else 
4226                 return -EPERM;
4227
4228         return 0;
4229 }
4230
4231 static int rtw_wx_set_mtk_wps_probe_ie(struct net_device *dev,
4232                 struct iw_request_info *a,
4233                 union iwreq_data *wrqu, char *b)
4234 {
4235 #ifdef CONFIG_PLATFORM_MT53XX
4236         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4237         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
4238
4239         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_notice_,
4240                  ("WLAN IOCTL: cmd_code=%x, fwstate=0x%x\n",
4241                   a->cmd, get_fwstate(pmlmepriv)));
4242 #endif
4243         return 0;
4244 }
4245
4246 static int rtw_wx_get_sensitivity(struct net_device *dev,
4247                                 struct iw_request_info *info,
4248                                 union iwreq_data *wrqu, char *buf)
4249 {
4250 #ifdef CONFIG_PLATFORM_MT53XX
4251         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4252
4253         //      Modified by Albert 20110914
4254         //      This is in dbm format for MTK platform.
4255         wrqu->qual.level = padapter->recvpriv.rssi;
4256         DBG_871X(" level = %u\n",  wrqu->qual.level );
4257 #endif
4258         return 0;
4259 }
4260
4261 static int rtw_wx_set_mtk_wps_ie(struct net_device *dev,
4262                                 struct iw_request_info *info,
4263                                 union iwreq_data *wrqu, char *extra)
4264 {
4265 #ifdef CONFIG_PLATFORM_MT53XX
4266         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4267
4268         return rtw_set_wpa_ie(padapter, wrqu->data.pointer, wrqu->data.length);
4269 #else
4270         return 0;
4271 #endif
4272 }
4273
4274 /*
4275 typedef int (*iw_handler)(struct net_device *dev, struct iw_request_info *info,
4276                           union iwreq_data *wrqu, char *extra);
4277 */
4278 /*
4279  *      For all data larger than 16 octets, we need to use a
4280  *      pointer to memory allocated in user space.
4281  */
4282 static  int rtw_drvext_hdl(struct net_device *dev, struct iw_request_info *info,
4283                                                 union iwreq_data *wrqu, char *extra)
4284 {
4285
4286  #if 0
4287 struct  iw_point
4288 {
4289   void __user   *pointer;       /* Pointer to the data  (in user space) */
4290   __u16         length;         /* number of fields or size in bytes */
4291   __u16         flags;          /* Optional params */
4292 };
4293  #endif
4294
4295 #ifdef CONFIG_DRVEXT_MODULE
4296         u8 res;
4297         struct drvext_handler *phandler;        
4298         struct drvext_oidparam *poidparam;              
4299         int ret;
4300         u16 len;
4301         u8 *pparmbuf, bset;
4302         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4303         struct iw_point *p = &wrqu->data;
4304
4305         if( (!p->length) || (!p->pointer)){
4306                 ret = -EINVAL;
4307                 goto _rtw_drvext_hdl_exit;
4308         }
4309         
4310         
4311         bset = (u8)(p->flags&0xFFFF);
4312         len = p->length;
4313         pparmbuf = (u8*)rtw_malloc(len);
4314         if (pparmbuf == NULL){
4315                 ret = -ENOMEM;
4316                 goto _rtw_drvext_hdl_exit;
4317         }
4318         
4319         if(bset)//set info
4320         {
4321                 if (copy_from_user(pparmbuf, p->pointer,len)) {
4322                         rtw_mfree(pparmbuf, len);
4323                         ret = -EFAULT;
4324                         goto _rtw_drvext_hdl_exit;
4325                 }               
4326         }
4327         else//query info
4328         {
4329         
4330         }
4331
4332         
4333         //
4334         poidparam = (struct drvext_oidparam *)pparmbuf; 
4335         
4336         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("drvext set oid subcode [%d], len[%d], InformationBufferLength[%d]\r\n",
4337                                                  poidparam->subcode, poidparam->len, len));
4338
4339
4340         //check subcode 
4341         if ( poidparam->subcode >= MAX_DRVEXT_HANDLERS)
4342         {
4343                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("no matching drvext handlers\r\n"));             
4344                 ret = -EINVAL;
4345                 goto _rtw_drvext_hdl_exit;
4346         }
4347
4348
4349         if ( poidparam->subcode >= MAX_DRVEXT_OID_SUBCODES)
4350         {
4351                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("no matching drvext subcodes\r\n"));             
4352                 ret = -EINVAL;
4353                 goto _rtw_drvext_hdl_exit;
4354         }
4355
4356
4357         phandler = drvextoidhandlers + poidparam->subcode;
4358
4359         if (poidparam->len != phandler->parmsize)
4360         {
4361                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("no matching drvext param size %d vs %d\r\n",                    
4362                                                 poidparam->len , phandler->parmsize));          
4363                 ret = -EINVAL;          
4364                 goto _rtw_drvext_hdl_exit;
4365         }
4366
4367
4368         res = phandler->handler(&padapter->drvextpriv, bset, poidparam->data);
4369
4370         if(res==0)
4371         {
4372                 ret = 0;
4373                         
4374                 if (bset == 0x00) {//query info
4375                         //_rtw_memcpy(p->pointer, pparmbuf, len);
4376                         if (copy_to_user(p->pointer, pparmbuf, len))
4377                                 ret = -EFAULT;
4378                 }               
4379         }               
4380         else
4381                 ret = -EFAULT;
4382
4383         
4384 _rtw_drvext_hdl_exit:   
4385         
4386         return ret;     
4387         
4388 #endif
4389
4390         return 0;
4391
4392 }
4393
4394 static void rtw_dbg_mode_hdl(_adapter *padapter, u32 id, u8 *pdata, u32 len)
4395 {
4396         pRW_Reg         RegRWStruct;
4397         struct rf_reg_param *prfreg;
4398         u8 path;
4399         u8 offset;
4400         u32 value;
4401
4402         DBG_871X("%s\n", __FUNCTION__);
4403
4404         switch(id)
4405         {
4406                 case GEN_MP_IOCTL_SUBCODE(MP_START):
4407                         DBG_871X("871x_driver is only for normal mode, can't enter mp mode\n");
4408                         break;
4409                 case GEN_MP_IOCTL_SUBCODE(READ_REG):
4410                         RegRWStruct = (pRW_Reg)pdata;
4411                         switch (RegRWStruct->width)
4412                         {
4413                                 case 1:
4414                                         RegRWStruct->value = rtw_read8(padapter, RegRWStruct->offset);
4415                                         break;
4416                                 case 2:
4417                                         RegRWStruct->value = rtw_read16(padapter, RegRWStruct->offset);
4418                                         break;
4419                                 case 4:
4420                                         RegRWStruct->value = rtw_read32(padapter, RegRWStruct->offset);
4421                                         break;
4422                                 default:
4423                                         break;
4424                         }
4425                 
4426                         break;
4427                 case GEN_MP_IOCTL_SUBCODE(WRITE_REG):
4428                         RegRWStruct = (pRW_Reg)pdata;
4429                         switch (RegRWStruct->width)
4430                         {
4431                                 case 1:
4432                                         rtw_write8(padapter, RegRWStruct->offset, (u8)RegRWStruct->value);
4433                                         break;
4434                                 case 2:
4435                                         rtw_write16(padapter, RegRWStruct->offset, (u16)RegRWStruct->value);
4436                                         break;
4437                                 case 4:
4438                                         rtw_write32(padapter, RegRWStruct->offset, (u32)RegRWStruct->value);
4439                                         break;
4440                                 default:                                        
4441                                 break;
4442                         }
4443                                 
4444                         break;
4445                 case GEN_MP_IOCTL_SUBCODE(READ_RF_REG):
4446
4447                         prfreg = (struct rf_reg_param *)pdata;
4448
4449                         path = (u8)prfreg->path;                
4450                         offset = (u8)prfreg->offset;    
4451
4452                         value = rtw_hal_read_rfreg(padapter, path, offset, 0xffffffff);
4453
4454                         prfreg->value = value;
4455
4456                         break;                  
4457                 case GEN_MP_IOCTL_SUBCODE(WRITE_RF_REG):
4458
4459                         prfreg = (struct rf_reg_param *)pdata;
4460
4461                         path = (u8)prfreg->path;
4462                         offset = (u8)prfreg->offset;    
4463                         value = prfreg->value;
4464
4465                         rtw_hal_write_rfreg(padapter, path, offset, 0xffffffff, value);
4466                         
4467                         break;                  
4468                 case GEN_MP_IOCTL_SUBCODE(TRIGGER_GPIO):
4469                         DBG_871X("==> trigger gpio 0\n");
4470                         rtw_hal_set_hwreg(padapter, HW_VAR_TRIGGER_GPIO_0, 0);
4471                         break;  
4472 #ifdef CONFIG_BT_COEXIST
4473                 case GEN_MP_IOCTL_SUBCODE(SET_DM_BT):                   
4474                         DBG_871X("==> set dm_bt_coexist:%x\n",*(u8 *)pdata);
4475                         rtw_hal_set_hwreg(padapter, HW_VAR_BT_SET_COEXIST, pdata);
4476                         break;
4477                 case GEN_MP_IOCTL_SUBCODE(DEL_BA):
4478                         DBG_871X("==> delete ba:%x\n",*(u8 *)pdata);
4479                         rtw_hal_set_hwreg(padapter, HW_VAR_BT_ISSUE_DELBA, pdata);
4480                         break;
4481 #endif
4482 #ifdef DBG_CONFIG_ERROR_DETECT
4483                 case GEN_MP_IOCTL_SUBCODE(GET_WIFI_STATUS):                                                     
4484                         *pdata = rtw_hal_sreset_get_wifi_status(padapter);                   
4485                         break;
4486 #endif
4487         
4488                 default:
4489                         break;
4490         }
4491         
4492 }
4493
4494 static int rtw_mp_ioctl_hdl(struct net_device *dev, struct iw_request_info *info,
4495                                                 union iwreq_data *wrqu, char *extra)
4496 {
4497         int ret = 0;
4498         u32 BytesRead, BytesWritten, BytesNeeded;
4499         struct oid_par_priv     oid_par;
4500         struct mp_ioctl_handler *phandler;
4501         struct mp_ioctl_param   *poidparam;
4502         uint status=0;
4503         u16 len;
4504         u8 *pparmbuf = NULL, bset;
4505         PADAPTER padapter = (PADAPTER)rtw_netdev_priv(dev);
4506         struct iw_point *p = &wrqu->data;
4507
4508         //DBG_871X("+rtw_mp_ioctl_hdl\n");
4509
4510         //mutex_lock(&ioctl_mutex);
4511
4512         if ((!p->length) || (!p->pointer)) {
4513                 ret = -EINVAL;
4514                 goto _rtw_mp_ioctl_hdl_exit;
4515         }
4516
4517         pparmbuf = NULL;
4518         bset = (u8)(p->flags & 0xFFFF);
4519         len = p->length;
4520         pparmbuf = (u8*)rtw_malloc(len);
4521         if (pparmbuf == NULL){
4522                 ret = -ENOMEM;
4523                 goto _rtw_mp_ioctl_hdl_exit;
4524         }
4525
4526         if (copy_from_user(pparmbuf, p->pointer, len)) {
4527                 ret = -EFAULT;
4528                 goto _rtw_mp_ioctl_hdl_exit;
4529         }
4530
4531         poidparam = (struct mp_ioctl_param *)pparmbuf;
4532         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
4533                  ("rtw_mp_ioctl_hdl: subcode [%d], len[%d], buffer_len[%d]\r\n",
4534                   poidparam->subcode, poidparam->len, len));
4535
4536         if (poidparam->subcode >= MAX_MP_IOCTL_SUBCODE) {
4537                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_err_, ("no matching drvext subcodes\r\n"));
4538                 ret = -EINVAL;
4539                 goto _rtw_mp_ioctl_hdl_exit;
4540         }
4541
4542         //DBG_871X("%s: %d\n", __func__, poidparam->subcode);
4543 #ifdef CONFIG_MP_INCLUDED 
4544 if (padapter->registrypriv.mp_mode == 1)
4545 {       
4546         phandler = mp_ioctl_hdl + poidparam->subcode;
4547
4548         if ((phandler->paramsize != 0) && (poidparam->len < phandler->paramsize))
4549         {
4550                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_err_,
4551                          ("no matching drvext param size %d vs %d\r\n",
4552                           poidparam->len, phandler->paramsize));
4553                 ret = -EINVAL;
4554                 goto _rtw_mp_ioctl_hdl_exit;
4555         }
4556
4557         if (phandler->handler)
4558         {
4559                 oid_par.adapter_context = padapter;
4560                 oid_par.oid = phandler->oid;
4561                 oid_par.information_buf = poidparam->data;
4562                 oid_par.information_buf_len = poidparam->len;
4563                 oid_par.dbg = 0;
4564
4565                 BytesWritten = 0;
4566                 BytesNeeded = 0;
4567
4568                 if (bset) {
4569                         oid_par.bytes_rw = &BytesRead;
4570                         oid_par.bytes_needed = &BytesNeeded;
4571                         oid_par.type_of_oid = SET_OID;
4572                 } else {
4573                         oid_par.bytes_rw = &BytesWritten;
4574                         oid_par.bytes_needed = &BytesNeeded;
4575                         oid_par.type_of_oid = QUERY_OID;
4576                 }
4577
4578                 status = phandler->handler(&oid_par);
4579
4580                 //todo:check status, BytesNeeded, etc.
4581         }
4582         else {
4583                 DBG_871X("rtw_mp_ioctl_hdl(): err!, subcode=%d, oid=%d, handler=%p\n", 
4584                         poidparam->subcode, phandler->oid, phandler->handler);
4585                 ret = -EFAULT;
4586                 goto _rtw_mp_ioctl_hdl_exit;
4587         }
4588 }
4589 else
4590 #endif
4591 {
4592         rtw_dbg_mode_hdl(padapter, poidparam->subcode, poidparam->data, poidparam->len);
4593 }
4594
4595         if (bset == 0x00) {//query info
4596                 if (copy_to_user(p->pointer, pparmbuf, len))
4597                         ret = -EFAULT;
4598         }
4599
4600         if (status) {
4601                 ret = -EFAULT;
4602                 goto _rtw_mp_ioctl_hdl_exit;
4603         }
4604
4605 _rtw_mp_ioctl_hdl_exit:
4606
4607         if (pparmbuf)
4608                 rtw_mfree(pparmbuf, len);
4609
4610         //mutex_unlock(&ioctl_mutex);
4611
4612         return ret;
4613 }
4614
4615 static int rtw_get_ap_info(struct net_device *dev,
4616                                struct iw_request_info *info,
4617                                union iwreq_data *wrqu, char *extra)
4618 {
4619         int bssid_match, ret = 0;
4620         u32 cnt=0, wpa_ielen;
4621         _irqL   irqL;
4622         _list   *plist, *phead;
4623         unsigned char *pbuf;
4624         u8 bssid[ETH_ALEN];
4625         char data[32];
4626         struct wlan_network *pnetwork = NULL;
4627         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4628         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
4629         _queue *queue = &(pmlmepriv->scanned_queue);
4630         struct iw_point *pdata = &wrqu->data;   
4631
4632         DBG_871X("+rtw_get_aplist_info\n");
4633
4634         if((padapter->bDriverStopped) || (pdata==NULL))
4635         {                
4636                 ret= -EINVAL;
4637                 goto exit;
4638         }               
4639   
4640         while((check_fwstate(pmlmepriv, (_FW_UNDER_SURVEY|_FW_UNDER_LINKING))) == _TRUE)
4641         {       
4642                 rtw_msleep_os(30);
4643                 cnt++;
4644                 if(cnt > 100)
4645                         break;
4646         }
4647         
4648
4649         //pdata->length = 0;//? 
4650         pdata->flags = 0;
4651         if(pdata->length>=32)
4652         {
4653                 if(copy_from_user(data, pdata->pointer, 32))
4654                 {
4655                         ret= -EINVAL;
4656                         goto exit;
4657                 }
4658         }       
4659         else
4660         {
4661                 ret= -EINVAL;
4662                 goto exit;
4663         }       
4664
4665         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4666         
4667         phead = get_list_head(queue);
4668         plist = get_next(phead);
4669        
4670         while(1)
4671         {
4672                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
4673                         break;
4674
4675
4676                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
4677
4678                 //if(hwaddr_aton_i(pdata->pointer, bssid)) 
4679                 if(hwaddr_aton_i(data, bssid)) 
4680                 {                       
4681                         DBG_871X("Invalid BSSID '%s'.\n", (u8*)data);
4682                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4683                         return -EINVAL;
4684                 }               
4685                 
4686         
4687                 if(_rtw_memcmp(bssid, pnetwork->network.MacAddress, ETH_ALEN) == _TRUE)//BSSID match, then check if supporting wpa/wpa2
4688                 {
4689                         DBG_871X("BSSID:" MAC_FMT "\n", MAC_ARG(bssid));
4690                         
4691                         pbuf = rtw_get_wpa_ie(&pnetwork->network.IEs[12], &wpa_ielen, pnetwork->network.IELength-12);                           
4692                         if(pbuf && (wpa_ielen>0))
4693                         {
4694                                 pdata->flags = 1;
4695                                 break;
4696                         }
4697
4698                         pbuf = rtw_get_wpa2_ie(&pnetwork->network.IEs[12], &wpa_ielen, pnetwork->network.IELength-12);
4699                         if(pbuf && (wpa_ielen>0))
4700                         {
4701                                 pdata->flags = 2;
4702                                 break;
4703                         }
4704                         
4705                 }
4706
4707                 plist = get_next(plist);                
4708         
4709         }        
4710
4711         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4712
4713         if(pdata->length>=34)
4714         {
4715                 if(copy_to_user((u8*)pdata->pointer+32, (u8*)&pdata->flags, 1))
4716                 {
4717                         ret= -EINVAL;
4718                         goto exit;
4719                 }
4720         }       
4721         
4722 exit:
4723         
4724         return ret;
4725                 
4726 }
4727
4728 static int rtw_set_pid(struct net_device *dev,
4729                                struct iw_request_info *info,
4730                                union iwreq_data *wrqu, char *extra)
4731 {
4732         
4733         int ret = 0;    
4734         _adapter *padapter = rtw_netdev_priv(dev);      
4735         int *pdata = (int *)wrqu;
4736         int selector;
4737
4738         if((padapter->bDriverStopped) || (pdata==NULL))
4739         {                
4740                 ret= -EINVAL;
4741                 goto exit;
4742         }               
4743   
4744         selector = *pdata;
4745         if(selector < 3 && selector >=0) {
4746                 padapter->pid[selector] = *(pdata+1);
4747                 #ifdef CONFIG_GLOBAL_UI_PID
4748                 ui_pid[selector] = *(pdata+1);
4749                 #endif
4750                 DBG_871X("%s set pid[%d]=%d\n", __FUNCTION__, selector ,padapter->pid[selector]);
4751         }
4752         else
4753                 DBG_871X("%s selector %d error\n", __FUNCTION__, selector);
4754
4755 exit:
4756         
4757         return ret;
4758                 
4759 }
4760
4761 static int rtw_wps_start(struct net_device *dev,
4762                                struct iw_request_info *info,
4763                                union iwreq_data *wrqu, char *extra)
4764 {
4765         
4766         int ret = 0;    
4767         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4768         struct iw_point *pdata = &wrqu->data;
4769         u32   u32wps_start = 0;
4770         unsigned int uintRet = 0;
4771
4772         if((_TRUE == padapter->bDriverStopped) ||(_TRUE==padapter->bSurpriseRemoved) || (NULL== pdata))
4773         {                
4774                 ret= -EINVAL;
4775                 goto exit;
4776         }               
4777
4778         uintRet = copy_from_user( ( void* ) &u32wps_start, pdata->pointer, 4 );
4779         if ( u32wps_start == 0 )
4780         {
4781                 u32wps_start = *extra;
4782         }
4783
4784         DBG_871X( "[%s] wps_start = %d\n", __FUNCTION__, u32wps_start );
4785
4786         if ( u32wps_start == 1 ) // WPS Start
4787         {
4788                 rtw_led_control(padapter, LED_CTL_START_WPS);
4789         }
4790         else if ( u32wps_start == 2 ) // WPS Stop because of wps success
4791         {
4792                 rtw_led_control(padapter, LED_CTL_STOP_WPS);
4793         }
4794         else if ( u32wps_start == 3 ) // WPS Stop because of wps fail
4795         {
4796                 rtw_led_control(padapter, LED_CTL_STOP_WPS_FAIL);
4797         }
4798
4799 #ifdef CONFIG_INTEL_WIDI
4800         process_intel_widi_wps_status(padapter, u32wps_start);
4801 #endif //CONFIG_INTEL_WIDI
4802         
4803 exit:
4804         
4805         return ret;
4806                 
4807 }
4808
4809 #ifdef CONFIG_P2P
4810 static int rtw_wext_p2p_enable(struct net_device *dev,
4811                                struct iw_request_info *info,
4812                                union iwreq_data *wrqu, char *extra)
4813 {
4814         
4815         int ret = 0;    
4816         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4817         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
4818         struct iw_point *pdata = &wrqu->data;
4819         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4820         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
4821         enum P2P_ROLE init_role = P2P_ROLE_DISABLE;
4822
4823         if(*extra == '0' )
4824                 init_role = P2P_ROLE_DISABLE;
4825         else if(*extra == '1')
4826                 init_role = P2P_ROLE_DEVICE;
4827         else if(*extra == '2')
4828                 init_role = P2P_ROLE_CLIENT;
4829         else if(*extra == '3')
4830                 init_role = P2P_ROLE_GO;
4831
4832         if(_FAIL == rtw_p2p_enable(padapter, init_role))
4833         {
4834                 ret = -EFAULT;
4835                 goto exit;
4836         }
4837
4838         //set channel/bandwidth
4839         if(init_role != P2P_ROLE_DISABLE) 
4840         {       
4841                 u8 channel, ch_offset;
4842                 u16 bwmode;
4843
4844                 if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_LISTEN))
4845                 {
4846                         //      Stay at the listen state and wait for discovery.
4847                         channel = pwdinfo->listen_channel;
4848                         pwdinfo->operating_channel = pwdinfo->listen_channel;
4849                         ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
4850                         bwmode = CHANNEL_WIDTH_20;
4851                 }
4852 #ifdef CONFIG_CONCURRENT_MODE
4853                 else if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_IDLE))
4854                 {
4855                         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
4856                         //struct wifidirect_info        *pbuddy_wdinfo = &pbuddy_adapter->wdinfo;
4857                         struct mlme_priv                *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
4858                         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
4859                         
4860                         _set_timer( &pwdinfo->ap_p2p_switch_timer, pwdinfo->ext_listen_interval );
4861                         if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
4862                         {
4863                                 pwdinfo->operating_channel = pbuddy_mlmeext->cur_channel;
4864                                 //      How about the ch_offset and bwmode ??
4865                         }
4866                         else
4867                         {
4868                                 pwdinfo->operating_channel = pwdinfo->listen_channel;
4869                         }
4870
4871                         channel = pbuddy_mlmeext->cur_channel;
4872                         ch_offset = pbuddy_mlmeext->cur_ch_offset;
4873                         bwmode = pbuddy_mlmeext->cur_bwmode;
4874                 }
4875 #endif
4876                 else
4877                 {
4878                         pwdinfo->operating_channel = pmlmeext->cur_channel;
4879                 
4880                         channel = pwdinfo->operating_channel;
4881                         ch_offset = pmlmeext->cur_ch_offset;
4882                         bwmode = pmlmeext->cur_bwmode;                                          
4883                 }
4884
4885                 set_channel_bwmode(padapter, channel, ch_offset, bwmode);
4886         }
4887
4888 exit:
4889         return ret;
4890                 
4891 }
4892
4893 static int rtw_p2p_set_go_nego_ssid(struct net_device *dev,
4894                                struct iw_request_info *info,
4895                                union iwreq_data *wrqu, char *extra)
4896 {
4897         
4898         int ret = 0;    
4899         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4900         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
4901         struct iw_point *pdata = &wrqu->data;
4902         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4903
4904         DBG_871X( "[%s] ssid = %s, len = %zu\n", __FUNCTION__, extra, strlen( extra ) );
4905         _rtw_memcpy( pwdinfo->nego_ssid, extra, strlen( extra ) );
4906         pwdinfo->nego_ssidlen = strlen( extra );
4907         
4908         return ret;
4909                 
4910 }
4911
4912
4913 static int rtw_p2p_set_intent(struct net_device *dev,
4914                                struct iw_request_info *info,
4915                                union iwreq_data *wrqu, char *extra)
4916 {
4917         int                                                     ret = 0;
4918         _adapter                                                *padapter = (_adapter *)rtw_netdev_priv(dev);
4919         struct wifidirect_info                  *pwdinfo= &(padapter->wdinfo);
4920         u8                                                      intent = pwdinfo->intent;
4921
4922         extra[ wrqu->data.length ] = 0x00;
4923
4924         intent = rtw_atoi( extra );
4925
4926         if ( intent <= 15 )
4927         {
4928                 pwdinfo->intent= intent;
4929         }
4930         else
4931         {
4932                 ret = -1;
4933         }
4934         
4935         DBG_871X( "[%s] intent = %d\n", __FUNCTION__, intent);
4936
4937         return ret;
4938                 
4939 }
4940
4941 static int rtw_p2p_set_listen_ch(struct net_device *dev,
4942                                struct iw_request_info *info,
4943                                union iwreq_data *wrqu, char *extra)
4944 {
4945         
4946         int ret = 0;    
4947         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4948         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4949         u8      listen_ch = pwdinfo->listen_channel;    //      Listen channel number
4950
4951         extra[ wrqu->data.length ] = 0x00;
4952         listen_ch = rtw_atoi( extra );
4953
4954         if ( ( listen_ch == 1 ) || ( listen_ch == 6 ) || ( listen_ch == 11 ) )
4955         {
4956                 pwdinfo->listen_channel = listen_ch;
4957                 set_channel_bwmode(padapter, pwdinfo->listen_channel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
4958         }
4959         else
4960         {
4961                 ret = -1;
4962         }
4963         
4964         DBG_871X( "[%s] listen_ch = %d\n", __FUNCTION__, pwdinfo->listen_channel );
4965         
4966         return ret;
4967                 
4968 }
4969
4970 static int rtw_p2p_set_op_ch(struct net_device *dev,
4971                                struct iw_request_info *info,
4972                                union iwreq_data *wrqu, char *extra)
4973 {
4974 //      Commented by Albert 20110524
4975 //      This function is used to set the operating channel if the driver will become the group owner
4976
4977         int ret = 0;    
4978         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4979         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4980         u8      op_ch = pwdinfo->operating_channel;     //      Operating channel number
4981
4982         extra[ wrqu->data.length ] = 0x00;
4983
4984         op_ch = ( u8 ) rtw_atoi( extra );
4985         if ( op_ch > 0 )
4986         {
4987                 pwdinfo->operating_channel = op_ch;
4988         }
4989         else
4990         {
4991                 ret = -1;
4992         }
4993         
4994         DBG_871X( "[%s] op_ch = %d\n", __FUNCTION__, pwdinfo->operating_channel );
4995         
4996         return ret;
4997
4998 }
4999
5000
5001 static int rtw_p2p_profilefound(struct net_device *dev,
5002                                struct iw_request_info *info,
5003                                union iwreq_data *wrqu, char *extra)
5004 {
5005         
5006         int ret = 0;    
5007         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5008         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
5009
5010         //      Comment by Albert 2010/10/13
5011         //      Input data format:
5012         //      Ex:  0
5013         //      Ex:  1XX:XX:XX:XX:XX:XXYYSSID
5014         //      0 => Reflush the profile record list.
5015         //      1 => Add the profile list
5016         //      XX:XX:XX:XX:XX:XX => peer's MAC Address ( ex: 00:E0:4C:00:00:01 )
5017         //      YY => SSID Length
5018         //      SSID => SSID for persistence group
5019
5020         DBG_871X( "[%s] In value = %s, len = %d \n", __FUNCTION__, extra, wrqu->data.length -1);
5021
5022         
5023         //      The upper application should pass the SSID to driver by using this rtw_p2p_profilefound function.
5024         if(!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
5025         {
5026                 if ( extra[ 0 ] == '0' )
5027                 {
5028                         //      Remove all the profile information of wifidirect_info structure.
5029                         _rtw_memset( &pwdinfo->profileinfo[ 0 ], 0x00, sizeof( struct profile_info ) * P2P_MAX_PERSISTENT_GROUP_NUM );
5030                         pwdinfo->profileindex = 0;
5031                 }
5032                 else
5033                 {
5034                         if ( pwdinfo->profileindex >= P2P_MAX_PERSISTENT_GROUP_NUM )
5035                 {
5036                                 ret = -1;
5037                 }
5038                 else
5039                 {
5040                                 int jj, kk;
5041                                 
5042                                 //      Add this profile information into pwdinfo->profileinfo
5043                                 //      Ex:  1XX:XX:XX:XX:XX:XXYYSSID
5044                                 for( jj = 0, kk = 1; jj < ETH_ALEN; jj++, kk += 3 )
5045                                 {
5046                                         pwdinfo->profileinfo[ pwdinfo->profileindex ].peermac[ jj ] = key_2char2num(extra[ kk ], extra[ kk+ 1 ]);
5047                                 }
5048
5049                                 //pwdinfo->profileinfo[ pwdinfo->profileindex ].ssidlen = ( extra[18] - '0' ) * 10 + ( extra[ 19 ] - '0' );
5050                                 //_rtw_memcpy( pwdinfo->profileinfo[ pwdinfo->profileindex ].ssid, &extra[ 20 ], pwdinfo->profileinfo[ pwdinfo->profileindex ].ssidlen );
5051                                 pwdinfo->profileindex++;
5052                         }
5053                 }
5054         }       
5055         
5056         return ret;
5057                 
5058 }
5059
5060 static int rtw_p2p_setDN(struct net_device *dev,
5061                                struct iw_request_info *info,
5062                                union iwreq_data *wrqu, char *extra)
5063 {
5064         
5065         int ret = 0;    
5066         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5067         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
5068
5069
5070         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
5071         _rtw_memset( pwdinfo->device_name, 0x00, WPS_MAX_DEVICE_NAME_LEN );
5072         _rtw_memcpy( pwdinfo->device_name, extra, wrqu->data.length - 1 );
5073         pwdinfo->device_name_len = wrqu->data.length - 1;
5074
5075         return ret;
5076                 
5077 }
5078
5079
5080 static int rtw_p2p_get_status(struct net_device *dev,
5081                                struct iw_request_info *info,
5082                                union iwreq_data *wrqu, char *extra)
5083 {
5084         
5085         int ret = 0;    
5086         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5087         struct iw_point *pdata = &wrqu->data;
5088         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5089 #ifdef CONFIG_CONCURRENT_MODE
5090         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
5091         struct wifidirect_info  *pbuddy_wdinfo = &pbuddy_adapter->wdinfo;
5092         struct mlme_priv                *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
5093         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv; 
5094 #endif
5095         
5096         if ( padapter->bShowGetP2PState )
5097         {
5098                 DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
5099                                 pwdinfo->p2p_peer_interface_addr[ 0 ], pwdinfo->p2p_peer_interface_addr[ 1 ], pwdinfo->p2p_peer_interface_addr[ 2 ],
5100                                 pwdinfo->p2p_peer_interface_addr[ 3 ], pwdinfo->p2p_peer_interface_addr[ 4 ], pwdinfo->p2p_peer_interface_addr[ 5 ]);
5101         }
5102
5103         //      Commented by Albert 2010/10/12
5104         //      Because of the output size limitation, I had removed the "Role" information.
5105         //      About the "Role" information, we will use the new private IOCTL to get the "Role" information.
5106         sprintf( extra, "\n\nStatus=%.2d\n", rtw_p2p_state(pwdinfo) );
5107         wrqu->data.length = strlen( extra );
5108
5109         return ret;
5110                 
5111 }
5112
5113 //      Commented by Albert 20110520
5114 //      This function will return the config method description 
5115 //      This config method description will show us which config method the remote P2P device is intented to use
5116 //      by sending the provisioning discovery request frame.
5117
5118 static int rtw_p2p_get_req_cm(struct net_device *dev,
5119                                struct iw_request_info *info,
5120                                union iwreq_data *wrqu, char *extra)
5121 {
5122         
5123         int ret = 0;    
5124         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5125         struct iw_point *pdata = &wrqu->data;
5126         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5127
5128         sprintf( extra, "\n\nCM=%s\n", pwdinfo->rx_prov_disc_info.strconfig_method_desc_of_prov_disc_req );
5129         wrqu->data.length = strlen( extra );
5130         return ret;
5131                 
5132 }
5133
5134
5135 static int rtw_p2p_get_role(struct net_device *dev,
5136                                struct iw_request_info *info,
5137                                union iwreq_data *wrqu, char *extra)
5138 {
5139         
5140         int ret = 0;    
5141         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5142         struct iw_point *pdata = &wrqu->data;
5143         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5144
5145         
5146         DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
5147                         pwdinfo->p2p_peer_interface_addr[ 0 ], pwdinfo->p2p_peer_interface_addr[ 1 ], pwdinfo->p2p_peer_interface_addr[ 2 ],
5148                         pwdinfo->p2p_peer_interface_addr[ 3 ], pwdinfo->p2p_peer_interface_addr[ 4 ], pwdinfo->p2p_peer_interface_addr[ 5 ]);
5149
5150         sprintf( extra, "\n\nRole=%.2d\n", rtw_p2p_role(pwdinfo) );
5151         wrqu->data.length = strlen( extra );
5152         return ret;
5153                 
5154 }
5155
5156
5157 static int rtw_p2p_get_peer_ifaddr(struct net_device *dev,
5158                                struct iw_request_info *info,
5159                                union iwreq_data *wrqu, char *extra)
5160 {
5161         
5162         int ret = 0;    
5163         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5164         struct iw_point *pdata = &wrqu->data;
5165         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5166
5167
5168         DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
5169                         pwdinfo->p2p_peer_interface_addr[ 0 ], pwdinfo->p2p_peer_interface_addr[ 1 ], pwdinfo->p2p_peer_interface_addr[ 2 ],
5170                         pwdinfo->p2p_peer_interface_addr[ 3 ], pwdinfo->p2p_peer_interface_addr[ 4 ], pwdinfo->p2p_peer_interface_addr[ 5 ]);
5171
5172         sprintf( extra, "\nMAC %.2X:%.2X:%.2X:%.2X:%.2X:%.2X",
5173                         pwdinfo->p2p_peer_interface_addr[ 0 ], pwdinfo->p2p_peer_interface_addr[ 1 ], pwdinfo->p2p_peer_interface_addr[ 2 ],
5174                         pwdinfo->p2p_peer_interface_addr[ 3 ], pwdinfo->p2p_peer_interface_addr[ 4 ], pwdinfo->p2p_peer_interface_addr[ 5 ]);
5175         wrqu->data.length = strlen( extra );
5176         return ret;
5177                 
5178 }
5179
5180 static int rtw_p2p_get_peer_devaddr(struct net_device *dev,
5181                                struct iw_request_info *info,
5182                                union iwreq_data *wrqu, char *extra)
5183
5184 {
5185         
5186         int ret = 0;    
5187         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5188         struct iw_point *pdata = &wrqu->data;
5189         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5190
5191         DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
5192                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 0 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 1 ], 
5193                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 2 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 3 ],
5194                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 4 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 5 ]);
5195         sprintf( extra, "\n%.2X%.2X%.2X%.2X%.2X%.2X",
5196                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 0 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 1 ], 
5197                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 2 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 3 ],
5198                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 4 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 5 ]);
5199         wrqu->data.length = strlen( extra );    
5200         return ret;
5201                 
5202 }
5203
5204 static int rtw_p2p_get_peer_devaddr_by_invitation(struct net_device *dev,
5205                                struct iw_request_info *info,
5206                                union iwreq_data *wrqu, char *extra)
5207
5208 {
5209         
5210         int ret = 0;    
5211         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5212         struct iw_point *pdata = &wrqu->data;
5213         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5214
5215         DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
5216                         pwdinfo->p2p_peer_device_addr[ 0 ], pwdinfo->p2p_peer_device_addr[ 1 ], 
5217                         pwdinfo->p2p_peer_device_addr[ 2 ], pwdinfo->p2p_peer_device_addr[ 3 ],
5218                         pwdinfo->p2p_peer_device_addr[ 4 ], pwdinfo->p2p_peer_device_addr[ 5 ]);
5219         sprintf( extra, "\nMAC %.2X:%.2X:%.2X:%.2X:%.2X:%.2X",
5220                         pwdinfo->p2p_peer_device_addr[ 0 ], pwdinfo->p2p_peer_device_addr[ 1 ], 
5221                         pwdinfo->p2p_peer_device_addr[ 2 ], pwdinfo->p2p_peer_device_addr[ 3 ],
5222                         pwdinfo->p2p_peer_device_addr[ 4 ], pwdinfo->p2p_peer_device_addr[ 5 ]);
5223         wrqu->data.length = strlen( extra );    
5224         return ret;
5225                 
5226 }
5227
5228 static int rtw_p2p_get_groupid(struct net_device *dev,
5229                                struct iw_request_info *info,
5230                                union iwreq_data *wrqu, char *extra)
5231
5232 {
5233         
5234         int ret = 0;    
5235         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5236         struct iw_point *pdata = &wrqu->data;
5237         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5238
5239         sprintf( extra, "\n%.2X:%.2X:%.2X:%.2X:%.2X:%.2X %s",
5240                         pwdinfo->groupid_info.go_device_addr[ 0 ], pwdinfo->groupid_info.go_device_addr[ 1 ], 
5241                         pwdinfo->groupid_info.go_device_addr[ 2 ], pwdinfo->groupid_info.go_device_addr[ 3 ],
5242                         pwdinfo->groupid_info.go_device_addr[ 4 ], pwdinfo->groupid_info.go_device_addr[ 5 ],
5243                         pwdinfo->groupid_info.ssid);
5244         wrqu->data.length = strlen( extra );    
5245         return ret;
5246                 
5247 }
5248
5249 static int rtw_p2p_get_op_ch(struct net_device *dev,
5250                                struct iw_request_info *info,
5251                                union iwreq_data *wrqu, char *extra)
5252
5253 {
5254         
5255         int ret = 0;    
5256         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5257         struct iw_point *pdata = &wrqu->data;
5258         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5259
5260         
5261         DBG_871X( "[%s] Op_ch = %02x\n", __FUNCTION__, pwdinfo->operating_channel);
5262         
5263         sprintf( extra, "\n\nOp_ch=%.2d\n", pwdinfo->operating_channel );
5264         wrqu->data.length = strlen( extra );
5265         return ret;
5266                 
5267 }
5268
5269 static int rtw_p2p_get_wps_configmethod(struct net_device *dev,
5270                                                                                 struct iw_request_info *info,
5271                                                                                 union iwreq_data *wrqu, char *extra, char *subcmd)
5272
5273         
5274         int ret = 0;
5275         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5276         u8 peerMAC[ETH_ALEN] = { 0x00 };
5277         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5278         _irqL irqL;
5279         _list * plist,*phead;
5280         _queue *queue = &(pmlmepriv->scanned_queue);
5281         struct wlan_network *pnetwork = NULL;
5282         u8 blnMatch = 0;
5283         u16     attr_content = 0;
5284         uint attr_contentlen = 0;
5285         u8      attr_content_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };
5286
5287         //      Commented by Albert 20110727
5288         //      The input data is the MAC address which the application wants to know its WPS config method.
5289         //      After knowing its WPS config method, the application can decide the config method for provisioning discovery.
5290         //      Format: iwpriv wlanx p2p_get_wpsCM 00:E0:4C:00:00:05
5291
5292         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
5293
5294         macstr2num(peerMAC, subcmd);
5295
5296         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5297
5298         phead = get_list_head(queue);
5299         plist = get_next(phead);
5300
5301         while (1)
5302         {
5303                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
5304
5305                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5306                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
5307                 {
5308                         u8 *wpsie;
5309                         uint    wpsie_len = 0;
5310
5311                         //      The mac address is matched.
5312
5313                         if ( (wpsie=rtw_get_wps_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &wpsie_len, pnetwork->network.Reserved[0])) )
5314                         {
5315                                 rtw_get_wps_attr_content(wpsie, wpsie_len, WPS_ATTR_CONF_METHOD, (u8 *)&attr_content, &attr_contentlen);
5316                                 if (attr_contentlen)
5317                                 {
5318                                         attr_content = be16_to_cpu(attr_content);
5319                                         sprintf(attr_content_str, "\n\nM=%.4d", attr_content);
5320                                         blnMatch = 1;
5321                                 }
5322                         }
5323
5324                         break;
5325                 }
5326
5327                 plist = get_next(plist);
5328
5329         }
5330
5331         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5332
5333         if (!blnMatch)
5334         {
5335                 sprintf(attr_content_str, "\n\nM=0000");
5336         }
5337
5338         wrqu->data.length = strlen(attr_content_str);
5339         _rtw_memcpy(extra, attr_content_str, wrqu->data.length);
5340
5341         return ret; 
5342                 
5343 }
5344
5345 #ifdef CONFIG_WFD
5346 static int rtw_p2p_get_peer_wfd_port(struct net_device *dev,
5347                                struct iw_request_info *info,
5348                                union iwreq_data *wrqu, char *extra)
5349 {
5350         
5351         int ret = 0;    
5352         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5353         struct iw_point *pdata = &wrqu->data;
5354         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5355
5356         DBG_871X( "[%s] p2p_state = %d\n", __FUNCTION__, rtw_p2p_state(pwdinfo) );
5357
5358         sprintf( extra, "\n\nPort=%d\n", pwdinfo->wfd_info->peer_rtsp_ctrlport );
5359         DBG_871X( "[%s] remote port = %d\n", __FUNCTION__, pwdinfo->wfd_info->peer_rtsp_ctrlport );
5360         
5361         wrqu->data.length = strlen( extra );
5362         return ret;
5363                 
5364 }
5365
5366 static int rtw_p2p_get_peer_wfd_preferred_connection(struct net_device *dev,
5367                                struct iw_request_info *info,
5368                                union iwreq_data *wrqu, char *extra)
5369 {
5370         
5371         int ret = 0;    
5372         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5373         struct iw_point *pdata = &wrqu->data;
5374         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5375
5376         sprintf( extra, "\n\nwfd_pc=%d\n", pwdinfo->wfd_info->wfd_pc );
5377         DBG_871X( "[%s] wfd_pc = %d\n", __FUNCTION__, pwdinfo->wfd_info->wfd_pc );
5378
5379         wrqu->data.length = strlen( extra );
5380         pwdinfo->wfd_info->wfd_pc = _FALSE;     //      Reset the WFD preferred connection to P2P
5381         return ret;
5382                 
5383 }
5384
5385 static int rtw_p2p_get_peer_wfd_session_available(struct net_device *dev,
5386                                struct iw_request_info *info,
5387                                union iwreq_data *wrqu, char *extra)
5388 {
5389         
5390         int ret = 0;    
5391         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
5392         struct iw_point *pdata = &wrqu->data;
5393         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5394
5395         sprintf( extra, "\n\nwfd_sa=%d\n", pwdinfo->wfd_info->peer_session_avail );
5396         DBG_871X( "[%s] wfd_sa = %d\n", __FUNCTION__, pwdinfo->wfd_info->peer_session_avail );
5397
5398         wrqu->data.length = strlen( extra );
5399         pwdinfo->wfd_info->peer_session_avail = _TRUE;  //      Reset the WFD session available
5400         return ret;
5401                 
5402 }
5403
5404 #endif // CONFIG_WFD
5405
5406 static int rtw_p2p_get_go_device_address(struct net_device *dev,
5407                                                                                  struct iw_request_info *info,
5408                                                                                  union iwreq_data *wrqu, char *extra, char *subcmd)
5409 {
5410
5411         int ret = 0;    
5412         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5413         u8 peerMAC[ETH_ALEN] = { 0x00 };
5414         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5415         _irqL irqL;
5416         _list *plist, *phead;
5417         _queue *queue   = &(pmlmepriv->scanned_queue);
5418         struct wlan_network *pnetwork = NULL;
5419         u8 blnMatch = 0;
5420         u8 *p2pie;
5421         uint p2pielen = 0, attr_contentlen = 0;
5422         u8 attr_content[100] = { 0x00 };
5423         u8 go_devadd_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };
5424
5425         //      Commented by Albert 20121209
5426         //      The input data is the GO's interface address which the application wants to know its device address.
5427         //      Format: iwpriv wlanx p2p_get2 go_devadd=00:E0:4C:00:00:05
5428
5429         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
5430
5431         macstr2num(peerMAC, subcmd);
5432
5433         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5434
5435         phead = get_list_head(queue);
5436         plist = get_next(phead);
5437
5438         while (1)
5439         {
5440                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
5441
5442                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5443                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
5444                 {
5445                         //      Commented by Albert 2011/05/18
5446                         //      Match the device address located in the P2P IE
5447                         //      This is for the case that the P2P device address is not the same as the P2P interface address.
5448
5449                         if ((p2pie = rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
5450                         {
5451                                 while (p2pie)
5452                                 {
5453                                         //      The P2P Device ID attribute is included in the Beacon frame.
5454                                         //      The P2P Device Info attribute is included in the probe response frame.
5455
5456                                         _rtw_memset(attr_content, 0x00, 100);
5457                                         if (rtw_get_p2p_attr_content(p2pie, p2pielen, P2P_ATTR_DEVICE_ID, attr_content, &attr_contentlen))
5458                                         {
5459                                                 //      Handle the P2P Device ID attribute of Beacon first
5460                                                 blnMatch = 1;
5461                                                 break;
5462
5463                                         } else if (rtw_get_p2p_attr_content(p2pie, p2pielen, P2P_ATTR_DEVICE_INFO, attr_content, &attr_contentlen))
5464                                         {
5465                                                 //      Handle the P2P Device Info attribute of probe response
5466                                                 blnMatch = 1;
5467                                                 break;
5468                                         }
5469
5470                                         //Get the next P2P IE
5471                                         p2pie = rtw_get_p2p_ie(p2pie + p2pielen, pnetwork->network.IELength - 12 - (p2pie - &pnetwork->network.IEs[12] + p2pielen), NULL, &p2pielen);
5472                                 }
5473                         }
5474                 }
5475
5476                 plist = get_next(plist);
5477
5478         }
5479
5480         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5481
5482         if (!blnMatch)
5483         {
5484                 sprintf(go_devadd_str, "\n\ndev_add=NULL");
5485         } else
5486         {
5487                 sprintf(go_devadd_str, "\n\ndev_add=%.2X:%.2X:%.2X:%.2X:%.2X:%.2X",
5488                                 attr_content[0], attr_content[1], attr_content[2], attr_content[3], attr_content[4], attr_content[5]);
5489         }
5490
5491         wrqu->data.length = strlen(go_devadd_str);
5492         _rtw_memcpy(extra, go_devadd_str, wrqu->data.length);
5493
5494         return ret; 
5495                 
5496 }
5497
5498 static int rtw_p2p_get_device_type(struct net_device *dev,
5499                                                                    struct iw_request_info *info,
5500                                                                    union iwreq_data *wrqu, char *extra, char *subcmd)
5501
5502         
5503         int ret = 0;
5504         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5505         u8 peerMAC[ETH_ALEN] = { 0x00 };
5506         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5507         _irqL irqL;
5508         _list *plist, *phead;
5509         _queue *queue = &(pmlmepriv->scanned_queue);
5510         struct wlan_network *pnetwork = NULL;
5511         u8 blnMatch = 0;
5512         u8 dev_type[8] = { 0x00 };
5513         uint dev_type_len = 0;
5514         u8 dev_type_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };    // +9 is for the str "dev_type=", we have to clear it at wrqu->data.pointer
5515
5516         //      Commented by Albert 20121209
5517         //      The input data is the MAC address which the application wants to know its device type.
5518         //      Such user interface could know the device type.
5519         //      Format: iwpriv wlanx p2p_get2 dev_type=00:E0:4C:00:00:05
5520
5521         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
5522
5523         macstr2num(peerMAC, subcmd);
5524
5525         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5526
5527         phead = get_list_head(queue);
5528         plist = get_next(phead);
5529
5530         while (1)
5531         {
5532                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
5533
5534                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5535                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
5536                 {
5537                         u8 *wpsie;
5538                         uint    wpsie_len = 0;
5539
5540                         //      The mac address is matched.
5541
5542                         if ( (wpsie=rtw_get_wps_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &wpsie_len, pnetwork->network.Reserved[0])) )
5543                         {
5544                                 rtw_get_wps_attr_content(wpsie, wpsie_len, WPS_ATTR_PRIMARY_DEV_TYPE, dev_type, &dev_type_len);
5545                                 if (dev_type_len)
5546                                 {
5547                                         u16     type = 0;
5548
5549                                         _rtw_memcpy(&type, dev_type, 2);
5550                                         type = be16_to_cpu(type);
5551                                         sprintf(dev_type_str, "\n\nN=%.2d", type);
5552                                         blnMatch = 1;
5553                                 }
5554                         }
5555                         break;
5556                 }
5557
5558                 plist = get_next(plist);
5559
5560         }
5561
5562         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5563
5564         if (!blnMatch)
5565         {
5566                 sprintf(dev_type_str, "\n\nN=00");
5567         }
5568
5569         wrqu->data.length = strlen(dev_type_str);
5570         _rtw_memcpy(extra, dev_type_str, wrqu->data.length);
5571
5572         return ret; 
5573                 
5574 }
5575
5576 static int rtw_p2p_get_device_name(struct net_device *dev,
5577                                                                    struct iw_request_info *info,
5578                                                                    union iwreq_data *wrqu, char *extra, char *subcmd)
5579
5580         
5581         int ret = 0;
5582         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5583         u8 peerMAC[ETH_ALEN] = { 0x00 };
5584         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5585         _irqL irqL;
5586         _list *plist, *phead;
5587         _queue *queue = &(pmlmepriv->scanned_queue);
5588         struct wlan_network *pnetwork = NULL;
5589         u8 blnMatch = 0;
5590         u8 dev_name[WPS_MAX_DEVICE_NAME_LEN] = { 0x00 };
5591         uint dev_len = 0;
5592         u8 dev_name_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };
5593
5594         //      Commented by Albert 20121225
5595         //      The input data is the MAC address which the application wants to know its device name.
5596         //      Such user interface could show peer device's device name instead of ssid.
5597         //      Format: iwpriv wlanx p2p_get2 devN=00:E0:4C:00:00:05
5598
5599         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
5600
5601         macstr2num(peerMAC, subcmd);
5602
5603         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5604
5605         phead = get_list_head(queue);
5606         plist = get_next(phead);
5607
5608         while (1)
5609         {
5610                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
5611
5612                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5613                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
5614                 {
5615                         u8 *wpsie;
5616                         uint    wpsie_len = 0;
5617
5618                         //      The mac address is matched.
5619
5620                         if ( (wpsie=rtw_get_wps_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &wpsie_len, pnetwork->network.Reserved[0])) )
5621                         {
5622                                 rtw_get_wps_attr_content(wpsie, wpsie_len, WPS_ATTR_DEVICE_NAME, dev_name, &dev_len);
5623                                 if (dev_len)
5624                                 {
5625                                         sprintf(dev_name_str, "\n\nN=%s", dev_name);
5626                                         blnMatch = 1;
5627                                 }
5628                         }
5629                         break;
5630                 }
5631
5632                 plist = get_next(plist);
5633
5634         }
5635
5636         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5637
5638         if (!blnMatch)
5639         {
5640                 sprintf(dev_name_str, "\n\nN=0000");
5641         }
5642
5643         wrqu->data.length = strlen(dev_name_str);
5644         _rtw_memcpy(extra, dev_name_str, wrqu->data.length);
5645
5646         return ret; 
5647                 
5648 }
5649
5650 static int rtw_p2p_get_invitation_procedure(struct net_device *dev,
5651                                                                                         struct iw_request_info *info,
5652                                                                                         union iwreq_data *wrqu, char *extra, char *subcmd)
5653 {
5654
5655         int ret = 0;    
5656         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5657         u8 peerMAC[ETH_ALEN] = { 0x00 };
5658         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5659         _irqL irqL;
5660         _list *plist, *phead;
5661         _queue *queue   = &(pmlmepriv->scanned_queue);
5662         struct wlan_network *pnetwork = NULL;
5663         u8 blnMatch = 0;
5664         u8 *p2pie;
5665         uint p2pielen = 0, attr_contentlen = 0;
5666         u8 attr_content[2] = { 0x00 };
5667         u8 inv_proc_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };
5668
5669         //      Commented by Ouden 20121226
5670         //      The application wants to know P2P initation procedure is support or not.
5671         //      Format: iwpriv wlanx p2p_get2 InvProc=00:E0:4C:00:00:05
5672
5673         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
5674
5675         macstr2num(peerMAC, subcmd);
5676
5677         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5678
5679         phead = get_list_head(queue);
5680         plist = get_next(phead);
5681
5682         while (1)
5683         {
5684                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
5685
5686                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5687                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
5688                 {
5689                         //      Commented by Albert 20121226
5690                         //      Match the device address located in the P2P IE
5691                         //      This is for the case that the P2P device address is not the same as the P2P interface address.
5692
5693                         if ((p2pie = rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
5694                         {
5695                                 while (p2pie)
5696                                 {
5697                                         //_rtw_memset( attr_content, 0x00, 2);
5698                                         if (rtw_get_p2p_attr_content(p2pie, p2pielen, P2P_ATTR_CAPABILITY, attr_content, &attr_contentlen))
5699                                         {
5700                                                 //      Handle the P2P capability attribute
5701                                                 blnMatch = 1;
5702                                                 break;
5703
5704                                         }
5705
5706                                         //Get the next P2P IE
5707                                         p2pie = rtw_get_p2p_ie(p2pie + p2pielen, pnetwork->network.IELength - 12 - (p2pie - &pnetwork->network.IEs[12] + p2pielen), NULL, &p2pielen);
5708                                 }
5709                         }
5710                 }
5711
5712                 plist = get_next(plist);
5713
5714         }
5715
5716         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5717
5718         if (!blnMatch)
5719         {
5720                 sprintf(inv_proc_str, "\nIP=-1");
5721         } else
5722         {
5723                 if (attr_content[0] && 0x20)
5724                 {
5725                         sprintf(inv_proc_str, "\nIP=1");
5726                 } else
5727                 {
5728                         sprintf(inv_proc_str, "\nIP=0");
5729                 }
5730         }
5731
5732         wrqu->data.length = strlen(inv_proc_str);
5733         _rtw_memcpy(extra, inv_proc_str, wrqu->data.length);
5734
5735         return ret; 
5736                 
5737 }
5738
5739 static int rtw_p2p_connect(struct net_device *dev,
5740                                struct iw_request_info *info,
5741                                union iwreq_data *wrqu, char *extra)
5742 {
5743         
5744         int ret = 0;    
5745         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);   
5746         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5747         u8                                      peerMAC[ ETH_ALEN ] = { 0x00 };
5748         int                                     jj,kk;
5749         u8                                      peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
5750         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
5751         _irqL                           irqL;
5752         _list                                   *plist, *phead;
5753         _queue                          *queue  = &(pmlmepriv->scanned_queue);
5754         struct  wlan_network    *pnetwork = NULL;
5755         uint                                    uintPeerChannel = 0;
5756 #ifdef CONFIG_CONCURRENT_MODE
5757         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
5758         struct mlme_priv                *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
5759         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
5760 #endif // CONFIG_CONCURRENT_MODE        
5761
5762         //      Commented by Albert 20110304
5763         //      The input data contains two informations.
5764         //      1. First information is the MAC address which wants to formate with
5765         //      2. Second information is the WPS PINCode or "pbc" string for push button method
5766         //      Format: 00:E0:4C:00:00:05
5767         //      Format: 00:E0:4C:00:00:05
5768
5769         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
5770
5771         if ( pwdinfo->p2p_state == P2P_STATE_NONE )
5772         {
5773                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
5774                 return ret;
5775         }
5776
5777 #ifdef CONFIG_INTEL_WIDI
5778         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY) == _TRUE) {
5779                 DBG_871X( "[%s] WiFi is under survey!\n", __FUNCTION__ );
5780                 return ret;
5781         }
5782 #endif //CONFIG_INTEL_WIDI      
5783
5784         if ( pwdinfo->ui_got_wps_info == P2P_NO_WPSINFO )
5785         {
5786                 return -1;
5787         }
5788         
5789         for( jj = 0, kk = 0; jj < ETH_ALEN; jj++, kk += 3 )
5790         {
5791                 peerMAC[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
5792         }
5793
5794         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5795
5796         phead = get_list_head(queue);
5797         plist = get_next(phead);
5798        
5799         while(1)
5800         {
5801                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
5802                         break;
5803
5804                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5805                 if ( _rtw_memcmp( pnetwork->network.MacAddress, peerMAC, ETH_ALEN ) )
5806                 {
5807                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
5808                         break;
5809                 }
5810
5811                 plist = get_next(plist);
5812         
5813         }
5814
5815         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5816
5817         if ( uintPeerChannel )
5818         {
5819 #ifdef CONFIG_CONCURRENT_MODE
5820                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
5821                 {
5822                         _cancel_timer_ex( &pwdinfo->ap_p2p_switch_timer );
5823                 }
5824 #endif // CONFIG_CONCURRENT_MODE
5825
5826                 _rtw_memset( &pwdinfo->nego_req_info, 0x00, sizeof( struct tx_nego_req_info ) );
5827                 _rtw_memset( &pwdinfo->groupid_info, 0x00, sizeof( struct group_id_info ) );
5828                 
5829                 pwdinfo->nego_req_info.peer_channel_num[ 0 ] = uintPeerChannel;
5830                 _rtw_memcpy( pwdinfo->nego_req_info.peerDevAddr, pnetwork->network.MacAddress, ETH_ALEN );
5831                 pwdinfo->nego_req_info.benable = _TRUE;
5832
5833                 _cancel_timer_ex( &pwdinfo->restore_p2p_state_timer );
5834                 if ( rtw_p2p_state(pwdinfo) != P2P_STATE_GONEGO_OK )
5835                 {
5836                         //      Restore to the listen state if the current p2p state is not nego OK
5837                         rtw_p2p_set_state(pwdinfo, P2P_STATE_LISTEN );
5838                 }
5839
5840                 rtw_p2p_set_pre_state(pwdinfo, rtw_p2p_state(pwdinfo));
5841                 rtw_p2p_set_state(pwdinfo, P2P_STATE_GONEGO_ING);
5842
5843 #ifdef CONFIG_CONCURRENT_MODE
5844                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
5845                 {
5846                         //      Have to enter the power saving with the AP
5847                         set_channel_bwmode(padapter, pbuddy_mlmeext->cur_channel, pbuddy_mlmeext->cur_ch_offset, pbuddy_mlmeext->cur_bwmode);
5848                         
5849                         issue_nulldata(pbuddy_adapter, NULL, 1, 3, 500);
5850                 }
5851 #endif // CONFIG_CONCURRENT_MODE
5852
5853                 DBG_871X( "[%s] Start PreTx Procedure!\n", __FUNCTION__ );
5854                 _set_timer( &pwdinfo->pre_tx_scan_timer, P2P_TX_PRESCAN_TIMEOUT );
5855 #ifdef CONFIG_CONCURRENT_MODE
5856                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
5857                 {
5858                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_CONCURRENT_GO_NEGO_TIMEOUT );
5859                 }
5860                 else
5861                 {
5862                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_GO_NEGO_TIMEOUT );
5863                 }
5864 #else
5865                 _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_GO_NEGO_TIMEOUT );
5866 #endif // CONFIG_CONCURRENT_MODE                
5867
5868         }
5869         else
5870         {
5871                 DBG_871X( "[%s] Not Found in Scanning Queue~\n", __FUNCTION__ );
5872 #ifdef CONFIG_INTEL_WIDI
5873                 _cancel_timer_ex( &pwdinfo->restore_p2p_state_timer );
5874                 rtw_p2p_set_state(pwdinfo, P2P_STATE_FIND_PHASE_SEARCH);
5875                 rtw_p2p_findphase_ex_set(pwdinfo, P2P_FINDPHASE_EX_NONE);
5876                 rtw_free_network_queue(padapter, _TRUE);
5877                 /** 
5878                  * For WiDi, if we can't find candidate device in scanning queue,
5879                  * driver will do scanning itself
5880                  */
5881                 _enter_critical_bh(&pmlmepriv->lock, &irqL);
5882                 rtw_sitesurvey_cmd(padapter, NULL, 0, NULL, 0);
5883                 _exit_critical_bh(&pmlmepriv->lock, &irqL);
5884 #endif //CONFIG_INTEL_WIDI 
5885                 ret = -1;
5886         }
5887 exit:   
5888         return ret;
5889 }
5890
5891 static int rtw_p2p_invite_req(struct net_device *dev,
5892                                struct iw_request_info *info,
5893                                union iwreq_data *wrqu, char *extra)
5894 {
5895         
5896         int ret = 0;    
5897         _adapter                                        *padapter = (_adapter *)rtw_netdev_priv(dev);   
5898         struct iw_point                         *pdata = &wrqu->data;
5899         struct wifidirect_info          *pwdinfo = &( padapter->wdinfo );
5900         int                                             jj,kk;
5901         u8                                              peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
5902         struct mlme_priv                        *pmlmepriv = &padapter->mlmepriv;
5903         _list                                           *plist, *phead;
5904         _queue                                  *queue  = &(pmlmepriv->scanned_queue);
5905         struct  wlan_network            *pnetwork = NULL;
5906         uint                                            uintPeerChannel = 0;
5907         u8                                              attr_content[50] = { 0x00 }, _status = 0;
5908         u8                                              *p2pie;
5909         uint                                            p2pielen = 0, attr_contentlen = 0;
5910         _irqL                                   irqL;
5911         struct tx_invite_req_info*      pinvite_req_info = &pwdinfo->invitereq_info;
5912         u8 ie_offset = 12;
5913 #ifdef CONFIG_CONCURRENT_MODE
5914         _adapter                                        *pbuddy_adapter = padapter->pbuddy_adapter;
5915         struct mlme_priv                        *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
5916         struct mlme_ext_priv            *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
5917 #endif // CONFIG_CONCURRENT_MODE
5918
5919 #ifdef CONFIG_WFD
5920         struct wifi_display_info*       pwfd_info = pwdinfo->wfd_info;
5921 #endif // CONFIG_WFD
5922         
5923         //      Commented by Albert 20120321
5924         //      The input data contains two informations.
5925         //      1. First information is the P2P device address which you want to send to.       
5926         //      2. Second information is the group id which combines with GO's mac address, space and GO's ssid.
5927         //      Command line sample: iwpriv wlan0 p2p_set invite="00:11:22:33:44:55 00:E0:4C:00:00:05 DIRECT-xy"
5928         //      Format: 00:11:22:33:44:55 00:E0:4C:00:00:05 DIRECT-xy
5929
5930         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
5931
5932         if ( wrqu->data.length <=  37 )
5933         {
5934                 DBG_871X( "[%s] Wrong format!\n", __FUNCTION__ );
5935                 return ret;
5936         }
5937
5938         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
5939         {
5940                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
5941                 return ret;
5942         }
5943         else
5944         {
5945                 //      Reset the content of struct tx_invite_req_info
5946                 pinvite_req_info->benable = _FALSE;
5947                 _rtw_memset( pinvite_req_info->go_bssid, 0x00, ETH_ALEN );
5948                 _rtw_memset( pinvite_req_info->go_ssid, 0x00, WLAN_SSID_MAXLEN );
5949                 pinvite_req_info->ssidlen = 0x00;
5950                 pinvite_req_info->operating_ch = pwdinfo->operating_channel;
5951                 _rtw_memset( pinvite_req_info->peer_macaddr, 0x00, ETH_ALEN );
5952                 pinvite_req_info->token = 3;
5953         }
5954         
5955         for( jj = 0, kk = 0; jj < ETH_ALEN; jj++, kk += 3 )
5956         {
5957                 pinvite_req_info->peer_macaddr[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
5958         }
5959
5960         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5961
5962         phead = get_list_head(queue);
5963         plist = get_next(phead);
5964        
5965         while(1)
5966         {
5967                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
5968                         break;
5969
5970                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5971
5972                 //      Commented by Albert 2011/05/18
5973                 //      Match the device address located in the P2P IE
5974                 //      This is for the case that the P2P device address is not the same as the P2P interface address.
5975
5976                 ie_offset = (pnetwork->network.Reserved[0] == 2? 0:12);
5977                 if ( (p2pie=rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
5978                 {
5979                         //      The P2P Device ID attribute is included in the Beacon frame.
5980                         //      The P2P Device Info attribute is included in the probe response frame.
5981
5982                         if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_ID, attr_content, &attr_contentlen) )
5983                         {
5984                                 //      Handle the P2P Device ID attribute of Beacon first
5985                                 if ( _rtw_memcmp( attr_content, pinvite_req_info->peer_macaddr, ETH_ALEN ) )
5986                                 {
5987                                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
5988                                         break;
5989                                 }
5990                         }
5991                         else if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_INFO, attr_content, &attr_contentlen) )
5992                         {
5993                                 //      Handle the P2P Device Info attribute of probe response
5994                                 if ( _rtw_memcmp( attr_content, pinvite_req_info->peer_macaddr, ETH_ALEN ) )
5995                                 {
5996                                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
5997                                         break;
5998                                 }                                       
5999                         }
6000
6001                 }
6002
6003                 plist = get_next(plist);
6004         
6005         }
6006
6007         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
6008
6009 #ifdef CONFIG_WFD
6010         if ( uintPeerChannel )
6011         {
6012                 u8      wfd_ie[ 128 ] = { 0x00 };
6013                 uint    wfd_ielen = 0;
6014                 
6015                 if ( rtw_get_wfd_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength,  wfd_ie, &wfd_ielen, pnetwork->network.Reserved[0]) )
6016                 {
6017                         u8      wfd_devinfo[ 6 ] = { 0x00 };
6018                         uint    wfd_devlen = 6;
6019
6020                         DBG_871X( "[%s] Found WFD IE!\n", __FUNCTION__ );
6021                         if ( rtw_get_wfd_attr_content( wfd_ie, wfd_ielen, WFD_ATTR_DEVICE_INFO, wfd_devinfo, &wfd_devlen ) )
6022                         {
6023                                 u16     wfd_devinfo_field = 0;
6024                                 
6025                                 //      Commented by Albert 20120319
6026                                 //      The first two bytes are the WFD device information field of WFD device information subelement.
6027                                 //      In big endian format.
6028                                 wfd_devinfo_field = RTW_GET_BE16(wfd_devinfo);
6029                                 if ( wfd_devinfo_field & WFD_DEVINFO_SESSION_AVAIL )
6030                                 {
6031                                         pwfd_info->peer_session_avail = _TRUE;
6032                                 }
6033                                 else
6034                                 {
6035                                         pwfd_info->peer_session_avail = _FALSE;
6036                                 }
6037                         }
6038                 }
6039                 
6040                 if ( _FALSE == pwfd_info->peer_session_avail )
6041                 {
6042                         DBG_871X( "[%s] WFD Session not avaiable!\n", __FUNCTION__ );
6043                         goto exit;
6044                 }
6045         }
6046 #endif // CONFIG_WFD
6047
6048         if ( uintPeerChannel )
6049         {
6050 #ifdef CONFIG_CONCURRENT_MODE
6051                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
6052                 {
6053                         _cancel_timer_ex( &pwdinfo->ap_p2p_switch_timer );
6054                 }
6055 #endif // CONFIG_CONCURRENT_MODE
6056
6057                 //      Store the GO's bssid
6058                 for( jj = 0, kk = 18; jj < ETH_ALEN; jj++, kk += 3 )
6059                 {
6060                         pinvite_req_info->go_bssid[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
6061                 }
6062
6063                 //      Store the GO's ssid
6064                 pinvite_req_info->ssidlen = wrqu->data.length - 36;
6065                 _rtw_memcpy( pinvite_req_info->go_ssid, &extra[ 36 ], (u32) pinvite_req_info->ssidlen );
6066                 pinvite_req_info->benable = _TRUE;
6067                 pinvite_req_info->peer_ch = uintPeerChannel;
6068
6069                 rtw_p2p_set_pre_state(pwdinfo, rtw_p2p_state(pwdinfo));
6070                 rtw_p2p_set_state(pwdinfo, P2P_STATE_TX_INVITE_REQ);
6071
6072 #ifdef CONFIG_CONCURRENT_MODE
6073                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
6074                 {
6075                         //      Have to enter the power saving with the AP
6076                         set_channel_bwmode(padapter, pbuddy_mlmeext->cur_channel, pbuddy_mlmeext->cur_ch_offset, pbuddy_mlmeext->cur_bwmode);
6077                         
6078                         issue_nulldata(pbuddy_adapter, NULL, 1, 3, 500);
6079                 }
6080                 else
6081                 {
6082                         set_channel_bwmode(padapter, uintPeerChannel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
6083                 }
6084 #else
6085                 set_channel_bwmode(padapter, uintPeerChannel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
6086 #endif
6087
6088                 _set_timer( &pwdinfo->pre_tx_scan_timer, P2P_TX_PRESCAN_TIMEOUT );
6089                 
6090 #ifdef CONFIG_CONCURRENT_MODE
6091                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
6092                 {
6093                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_CONCURRENT_INVITE_TIMEOUT );
6094                 }
6095                 else
6096                 {
6097                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_INVITE_TIMEOUT );
6098                 }
6099 #else
6100                 _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_INVITE_TIMEOUT );
6101 #endif // CONFIG_CONCURRENT_MODE                
6102
6103                 
6104         }
6105         else
6106         {
6107                 DBG_871X( "[%s] NOT Found in the Scanning Queue!\n", __FUNCTION__ );
6108         }
6109 exit:
6110         
6111         return ret;
6112                 
6113 }
6114
6115 static int rtw_p2p_set_persistent(struct net_device *dev,
6116                                struct iw_request_info *info,
6117                                union iwreq_data *wrqu, char *extra)
6118 {
6119         
6120         int ret = 0;    
6121         _adapter                                        *padapter = (_adapter *)rtw_netdev_priv(dev);   
6122         struct iw_point                         *pdata = &wrqu->data;
6123         struct wifidirect_info          *pwdinfo = &( padapter->wdinfo );
6124         int                                             jj,kk;
6125         u8                                              peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
6126         struct mlme_priv                        *pmlmepriv = &padapter->mlmepriv;
6127         _list                                           *plist, *phead;
6128         _queue                                  *queue  = &(pmlmepriv->scanned_queue);
6129         struct  wlan_network            *pnetwork = NULL;
6130         uint                                            uintPeerChannel = 0;
6131         u8                                              attr_content[50] = { 0x00 }, _status = 0;
6132         u8                                              *p2pie;
6133         uint                                            p2pielen = 0, attr_contentlen = 0;
6134         _irqL                                   irqL;
6135         struct tx_invite_req_info*      pinvite_req_info = &pwdinfo->invitereq_info;
6136 #ifdef CONFIG_CONCURRENT_MODE
6137         _adapter                                        *pbuddy_adapter = padapter->pbuddy_adapter;
6138         struct mlme_priv                        *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
6139         struct mlme_ext_priv            *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
6140 #endif // CONFIG_CONCURRENT_MODE
6141
6142 #ifdef CONFIG_WFD
6143         struct wifi_display_info*       pwfd_info = pwdinfo->wfd_info;
6144 #endif // CONFIG_WFD
6145         
6146         //      Commented by Albert 20120328
6147         //      The input data is 0 or 1
6148         //      0: disable persistent group functionality
6149         //      1: enable persistent group founctionality
6150         
6151         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
6152
6153         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
6154         {
6155                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
6156                 return ret;
6157         }
6158         else
6159         {
6160                 if ( extra[ 0 ] == '0' )        //      Disable the persistent group function.
6161                 {
6162                         pwdinfo->persistent_supported = _FALSE;
6163                 }
6164                 else if ( extra[ 0 ] == '1' )   //      Enable the persistent group function.
6165                 {
6166                         pwdinfo->persistent_supported = _TRUE;
6167                 }
6168                 else
6169                 {
6170                         pwdinfo->persistent_supported = _FALSE;
6171                 }
6172         }
6173         printk( "[%s] persistent_supported = %d\n", __FUNCTION__, pwdinfo->persistent_supported );
6174         
6175 exit:
6176         
6177         return ret;
6178                 
6179 }
6180
6181 static int hexstr2bin(const char *hex, u8 *buf, size_t len)
6182 {
6183         size_t i;
6184         int a;
6185         const char *ipos = hex;
6186         u8 *opos = buf;
6187
6188         for (i = 0; i < len; i++) {
6189                 a = hex2byte_i(ipos);
6190                 if (a < 0)
6191                         return -1;
6192                 *opos++ = a;
6193                 ipos += 2;
6194         }
6195         return 0;
6196 }
6197
6198 static int uuid_str2bin(const char *str, u8 *bin)
6199 {
6200         const char *pos;
6201         u8 *opos;
6202
6203         pos = str;
6204         opos = bin;
6205
6206         if (hexstr2bin(pos, opos, 4))
6207                 return -1;
6208         pos += 8;
6209         opos += 4;
6210
6211         if (*pos++ != '-' || hexstr2bin(pos, opos, 2))
6212                 return -1;
6213         pos += 4;
6214         opos += 2;
6215
6216         if (*pos++ != '-' || hexstr2bin(pos, opos, 2))
6217                 return -1;
6218         pos += 4;
6219         opos += 2;
6220
6221         if (*pos++ != '-' || hexstr2bin(pos, opos, 2))
6222                 return -1;
6223         pos += 4;
6224         opos += 2;
6225
6226         if (*pos++ != '-' || hexstr2bin(pos, opos, 6))
6227                 return -1;
6228
6229         return 0;
6230 }
6231
6232 static int rtw_p2p_set_wps_uuid(struct net_device *dev,
6233         struct iw_request_info *info,
6234         union iwreq_data *wrqu, char *extra)
6235 {
6236
6237         int ret = 0;
6238         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);
6239         struct wifidirect_info                  *pwdinfo = &(padapter->wdinfo);
6240
6241         DBG_871X("[%s] data = %s\n", __FUNCTION__, extra);
6242
6243         if ((36 == strlen(extra)) && (uuid_str2bin(extra, pwdinfo->uuid) == 0)) 
6244         {
6245                 pwdinfo->external_uuid = 1;
6246         } else {
6247                 pwdinfo->external_uuid = 0;
6248                 ret = -EINVAL;
6249         }
6250
6251         return ret;
6252
6253 }
6254 #ifdef CONFIG_WFD
6255 static int rtw_p2p_set_pc(struct net_device *dev,
6256                                struct iw_request_info *info,
6257                                union iwreq_data *wrqu, char *extra)
6258 {
6259         
6260         int ret = 0;    
6261         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);   
6262         struct iw_point                 *pdata = &wrqu->data;
6263         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
6264         u8                                      peerMAC[ ETH_ALEN ] = { 0x00 };
6265         int                                     jj,kk;
6266         u8                                      peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
6267         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
6268         _list                                   *plist, *phead;
6269         _queue                          *queue  = &(pmlmepriv->scanned_queue);
6270         struct  wlan_network    *pnetwork = NULL;
6271         u8                                      attr_content[50] = { 0x00 }, _status = 0;
6272         u8 *p2pie;
6273         uint                                    p2pielen = 0, attr_contentlen = 0;
6274         _irqL                           irqL;
6275         uint                                    uintPeerChannel = 0;
6276 #ifdef CONFIG_CONCURRENT_MODE
6277         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
6278         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
6279 #endif // CONFIG_CONCURRENT_MODE        
6280         
6281         struct wifi_display_info*       pwfd_info = pwdinfo->wfd_info;
6282         
6283         //      Commented by Albert 20120512
6284         //      1. Input information is the MAC address which wants to know the Preferred Connection bit (PC bit)
6285         //      Format: 00:E0:4C:00:00:05
6286
6287         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
6288
6289         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
6290         {
6291                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
6292                 return ret;
6293         }
6294         
6295         for( jj = 0, kk = 0; jj < ETH_ALEN; jj++, kk += 3 )
6296         {
6297                 peerMAC[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
6298         }
6299
6300         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
6301
6302         phead = get_list_head(queue);
6303         plist = get_next(phead);
6304        
6305         while(1)
6306         {
6307                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
6308                         break;
6309
6310                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
6311
6312                 //      Commented by Albert 2011/05/18
6313                 //      Match the device address located in the P2P IE
6314                 //      This is for the case that the P2P device address is not the same as the P2P interface address.
6315
6316                 if ( (p2pie=rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
6317                 {
6318                         //      The P2P Device ID attribute is included in the Beacon frame.
6319                         //      The P2P Device Info attribute is included in the probe response frame.
6320                         printk( "[%s] Got P2P IE\n", __FUNCTION__ );
6321                         if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_ID, attr_content, &attr_contentlen) )
6322                         {
6323                                 //      Handle the P2P Device ID attribute of Beacon first
6324                                 printk( "[%s] P2P_ATTR_DEVICE_ID \n", __FUNCTION__ );
6325                                 if ( _rtw_memcmp( attr_content, peerMAC, ETH_ALEN ) )
6326                                 {
6327                                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
6328                                         break;
6329                                 }
6330                         }
6331                         else if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_INFO, attr_content, &attr_contentlen) )
6332                         {
6333                                 //      Handle the P2P Device Info attribute of probe response
6334                                 printk( "[%s] P2P_ATTR_DEVICE_INFO \n", __FUNCTION__ );
6335                                 if ( _rtw_memcmp( attr_content, peerMAC, ETH_ALEN ) )
6336                                 {
6337                                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
6338                                         break;
6339                                 }                                       
6340                         }
6341
6342                 }
6343
6344                 plist = get_next(plist);
6345         
6346         }
6347
6348         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
6349         printk( "[%s] channel = %d\n", __FUNCTION__, uintPeerChannel );
6350
6351         if ( uintPeerChannel )
6352         {
6353                 u8      wfd_ie[ 128 ] = { 0x00 };
6354                 uint    wfd_ielen = 0;
6355                 u8 ie_offset = (pnetwork->network.Reserved[0] == 2 ? 0:12);
6356
6357                 if ( rtw_get_wfd_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength,  wfd_ie, &wfd_ielen, pnetwork->network.Reserved[0]) )
6358                 {
6359                         u8      wfd_devinfo[ 6 ] = { 0x00 };
6360                         uint    wfd_devlen = 6;
6361
6362                         DBG_871X( "[%s] Found WFD IE!\n", __FUNCTION__ );
6363                         if ( rtw_get_wfd_attr_content( wfd_ie, wfd_ielen, WFD_ATTR_DEVICE_INFO, wfd_devinfo, &wfd_devlen ) )
6364                         {
6365                                 u16     wfd_devinfo_field = 0;
6366                                 
6367                                 //      Commented by Albert 20120319
6368                                 //      The first two bytes are the WFD device information field of WFD device information subelement.
6369                                 //      In big endian format.
6370                                 wfd_devinfo_field = RTW_GET_BE16(wfd_devinfo);
6371                                 if ( wfd_devinfo_field & WFD_DEVINFO_PC_TDLS )
6372                                 {
6373                                         pwfd_info->wfd_pc = _TRUE;
6374                                 }
6375                                 else
6376                                 {
6377                                         pwfd_info->wfd_pc = _FALSE;
6378                                 }
6379                         }
6380                 }
6381         }       
6382         else
6383         {
6384                 DBG_871X( "[%s] NOT Found in the Scanning Queue!\n", __FUNCTION__ );
6385         }
6386
6387 exit:
6388         
6389         return ret;
6390                 
6391 }
6392
6393 static int rtw_p2p_set_wfd_device_type(struct net_device *dev,
6394                                struct iw_request_info *info,
6395                                union iwreq_data *wrqu, char *extra)
6396 {
6397         
6398         int ret = 0;    
6399         _adapter                                        *padapter = (_adapter *)rtw_netdev_priv(dev);   
6400         struct iw_point                         *pdata = &wrqu->data;
6401         struct wifidirect_info          *pwdinfo = &( padapter->wdinfo );
6402         struct wifi_display_info                *pwfd_info = pwdinfo->wfd_info;
6403         
6404         //      Commented by Albert 20120328
6405         //      The input data is 0 or 1
6406         //      0: specify to Miracast source device
6407         //      1 or others: specify to Miracast sink device (display device)
6408         
6409         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
6410
6411         if ( extra[ 0 ] == '0' )        //      Set to Miracast source device.
6412         {
6413                 pwfd_info->wfd_device_type = WFD_DEVINFO_SOURCE;
6414         }
6415         else                                    //      Set to Miracast sink device.
6416         {
6417                 pwfd_info->wfd_device_type = WFD_DEVINFO_PSINK;
6418         }
6419
6420 exit:
6421         
6422         return ret;
6423                 
6424 }
6425
6426 static int rtw_p2p_set_wfd_enable(struct net_device *dev,
6427                                struct iw_request_info *info,
6428                                union iwreq_data *wrqu, char *extra)
6429 {
6430 //      Commented by Kurt 20121206
6431 //      This function is used to set wfd enabled
6432
6433         int ret = 0;    
6434         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6435         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
6436
6437         if(*extra == '0' )
6438                 pwdinfo->wfd_info->wfd_enable = _FALSE;
6439         else if(*extra == '1')
6440                 pwdinfo->wfd_info->wfd_enable = _TRUE;
6441
6442         DBG_871X( "[%s] wfd_enable = %d\n", __FUNCTION__, pwdinfo->wfd_info->wfd_enable );
6443         
6444         return ret;
6445                 
6446 }
6447
6448 static int rtw_p2p_set_driver_iface(struct net_device *dev,
6449                                struct iw_request_info *info,
6450                                union iwreq_data *wrqu, char *extra)
6451 {
6452 //      Commented by Kurt 20121206
6453 //      This function is used to set driver iface is WEXT or CFG80211
6454         int ret = 0;    
6455         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6456         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
6457
6458         if(*extra == '1' )
6459         {
6460                 pwdinfo->driver_interface = DRIVER_WEXT;
6461                 DBG_871X( "[%s] driver_interface = WEXT\n", __FUNCTION__);
6462         }
6463         else if(*extra == '2')
6464         {
6465                 pwdinfo->driver_interface = DRIVER_CFG80211;
6466                 DBG_871X( "[%s] driver_interface = CFG80211\n", __FUNCTION__);
6467         }
6468         
6469         return ret;
6470                 
6471 }
6472
6473 //      To set the WFD session available to enable or disable
6474 static int rtw_p2p_set_sa(struct net_device *dev,
6475                                struct iw_request_info *info,
6476                                union iwreq_data *wrqu, char *extra)
6477 {
6478         
6479         int ret = 0;    
6480         _adapter                                        *padapter = (_adapter *)rtw_netdev_priv(dev);   
6481         struct iw_point                         *pdata = &wrqu->data;
6482         struct wifidirect_info          *pwdinfo = &( padapter->wdinfo );
6483         struct wifi_display_info                *pwfd_info = pwdinfo->wfd_info;
6484         
6485         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
6486
6487         if( 0 )
6488         {
6489                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
6490                 return ret;
6491         }
6492         else
6493         {
6494                 if ( extra[ 0 ] == '0' )        //      Disable the session available.
6495                 {
6496                         pwdinfo->session_available = _FALSE;
6497                 }
6498                 else if ( extra[ 0 ] == '1' )   //      Enable the session available.
6499                 {
6500                         pwdinfo->session_available = _TRUE;
6501                 }
6502                 else
6503                 {
6504                         pwdinfo->session_available = _FALSE;
6505                 }
6506         }
6507         printk( "[%s] session available = %d\n", __FUNCTION__, pwdinfo->session_available );
6508         
6509 exit:
6510         
6511         return ret;
6512                 
6513 }
6514 #endif // CONFIG_WFD
6515
6516 static int rtw_p2p_prov_disc(struct net_device *dev,
6517                                struct iw_request_info *info,
6518                                union iwreq_data *wrqu, char *extra)
6519 {
6520         int ret = 0;    
6521         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);   
6522         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
6523         u8                                      peerMAC[ ETH_ALEN ] = { 0x00 };
6524         int                                     jj,kk;
6525         u8                                      peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
6526         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
6527         _list                                   *plist, *phead;
6528         _queue                          *queue  = &(pmlmepriv->scanned_queue);
6529         struct  wlan_network    *pnetwork = NULL;
6530         uint                                    uintPeerChannel = 0;
6531         u8                                      attr_content[100] = { 0x00 }, _status = 0;
6532         u8 *p2pie;
6533         uint                                    p2pielen = 0, attr_contentlen = 0;
6534         _irqL                           irqL;
6535         u8                                      ie_offset = 12;
6536 #ifdef CONFIG_CONCURRENT_MODE
6537         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
6538         struct mlme_priv                *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
6539         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
6540 #endif // CONFIG_CONCURRENT_MODE        
6541 #ifdef CONFIG_WFD
6542         struct wifi_display_info*       pwfd_info = pwdinfo->wfd_info;
6543 #endif // CONFIG_WFD
6544
6545         //      Commented by Albert 20110301
6546         //      The input data contains two informations.
6547         //      1. First information is the MAC address which wants to issue the provisioning discovery request frame.
6548         //      2. Second information is the WPS configuration method which wants to discovery
6549         //      Format: 00:E0:4C:00:00:05_display
6550         //      Format: 00:E0:4C:00:00:05_keypad
6551         //      Format: 00:E0:4C:00:00:05_pbc
6552         //      Format: 00:E0:4C:00:00:05_label
6553
6554         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
6555
6556         if ( pwdinfo->p2p_state == P2P_STATE_NONE )
6557         {
6558                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
6559                 return ret;
6560         }
6561         else
6562         {
6563 #ifdef CONFIG_INTEL_WIDI
6564                 if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY) == _TRUE) {
6565                         DBG_871X( "[%s] WiFi is under survey!\n", __FUNCTION__ );
6566                         return ret;
6567                 }
6568 #endif //CONFIG_INTEL_WIDI
6569
6570                 //      Reset the content of struct tx_provdisc_req_info excluded the wps_config_method_request.
6571                 _rtw_memset( pwdinfo->tx_prov_disc_info.peerDevAddr, 0x00, ETH_ALEN );
6572                 _rtw_memset( pwdinfo->tx_prov_disc_info.peerIFAddr, 0x00, ETH_ALEN );
6573                 _rtw_memset( &pwdinfo->tx_prov_disc_info.ssid, 0x00, sizeof( NDIS_802_11_SSID ) );              
6574                 pwdinfo->tx_prov_disc_info.peer_channel_num[ 0 ] = 0;
6575                 pwdinfo->tx_prov_disc_info.peer_channel_num[ 1 ] = 0;
6576                 pwdinfo->tx_prov_disc_info.benable = _FALSE;
6577         }
6578         
6579         for( jj = 0, kk = 0; jj < ETH_ALEN; jj++, kk += 3 )
6580         {
6581                 peerMAC[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
6582         }
6583
6584         if ( _rtw_memcmp( &extra[ 18 ], "display", 7 ) )
6585         {
6586                 pwdinfo->tx_prov_disc_info.wps_config_method_request = WPS_CM_DISPLYA;
6587         }
6588         else if ( _rtw_memcmp( &extra[ 18 ], "keypad", 7 ) )
6589         {
6590                 pwdinfo->tx_prov_disc_info.wps_config_method_request = WPS_CM_KEYPAD;
6591         }
6592         else if ( _rtw_memcmp( &extra[ 18 ], "pbc", 3 ) )
6593         {
6594                 pwdinfo->tx_prov_disc_info.wps_config_method_request = WPS_CM_PUSH_BUTTON;
6595         }
6596         else if ( _rtw_memcmp( &extra[ 18 ], "label", 5 ) )
6597         {
6598                 pwdinfo->tx_prov_disc_info.wps_config_method_request = WPS_CM_LABEL;
6599         }
6600         else
6601         {
6602                 DBG_871X( "[%s] Unknown WPS config methodn", __FUNCTION__ );
6603                 return( ret );
6604         }
6605
6606         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
6607
6608         phead = get_list_head(queue);
6609         plist = get_next(phead);
6610        
6611         while(1)
6612         {
6613                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
6614                         break;
6615
6616                 if( uintPeerChannel != 0 )
6617                         break;
6618
6619                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
6620
6621                 //      Commented by Albert 2011/05/18
6622                 //      Match the device address located in the P2P IE
6623                 //      This is for the case that the P2P device address is not the same as the P2P interface address.
6624
6625                 ie_offset = (pnetwork->network.Reserved[0] == 2? 0:12);
6626                 if ( (p2pie=rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
6627                 {
6628                         while ( p2pie )
6629                         {
6630                                 //      The P2P Device ID attribute is included in the Beacon frame.
6631                                 //      The P2P Device Info attribute is included in the probe response frame.
6632
6633                                 if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_ID, attr_content, &attr_contentlen) )
6634                                 {
6635                                         //      Handle the P2P Device ID attribute of Beacon first
6636                                         if ( _rtw_memcmp( attr_content, peerMAC, ETH_ALEN ) )
6637                                         {
6638                                                 uintPeerChannel = pnetwork->network.Configuration.DSConfig;
6639                                                 break;
6640                                         }
6641                                 }
6642                                 else if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_INFO, attr_content, &attr_contentlen) )
6643                                 {
6644                                         //      Handle the P2P Device Info attribute of probe response
6645                                         if ( _rtw_memcmp( attr_content, peerMAC, ETH_ALEN ) )
6646                                         {
6647                                                 uintPeerChannel = pnetwork->network.Configuration.DSConfig;
6648                                                 break;
6649                                         }                                       
6650                                 }
6651
6652                                 //Get the next P2P IE
6653                                 p2pie = rtw_get_p2p_ie(p2pie+p2pielen, pnetwork->network.IELength - ie_offset -(p2pie -&pnetwork->network.IEs[ie_offset] + p2pielen), NULL, &p2pielen);
6654                         }
6655
6656                 }
6657
6658 #ifdef CONFIG_INTEL_WIDI
6659                 // Some Intel WiDi source may not provide P2P IE, 
6660                 // so we could only compare mac addr by 802.11 Source Address
6661                 if( pmlmepriv->widi_state == INTEL_WIDI_STATE_WFD_CONNECTION 
6662                         && uintPeerChannel == 0 )
6663                 {
6664                         if ( _rtw_memcmp( pnetwork->network.MacAddress, peerMAC, ETH_ALEN ) )
6665                         {
6666                                 uintPeerChannel = pnetwork->network.Configuration.DSConfig;
6667                                 break;
6668                         }
6669                 }
6670 #endif //CONFIG_INTEL_WIDI
6671
6672                 plist = get_next(plist);
6673         
6674         }
6675
6676         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
6677
6678         if ( uintPeerChannel )
6679         {
6680 #ifdef CONFIG_WFD
6681                 {
6682                         u8      wfd_ie[ 128 ] = { 0x00 };
6683                         uint    wfd_ielen = 0;
6684                         
6685                         if ( rtw_get_wfd_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength,  wfd_ie, &wfd_ielen, pnetwork->network.Reserved[0]) )
6686                         {
6687                                 u8      wfd_devinfo[ 6 ] = { 0x00 };
6688                                 uint    wfd_devlen = 6;
6689
6690                                 DBG_871X( "[%s] Found WFD IE!\n", __FUNCTION__ );
6691                                 if ( rtw_get_wfd_attr_content( wfd_ie, wfd_ielen, WFD_ATTR_DEVICE_INFO, wfd_devinfo, &wfd_devlen ) )
6692                                 {
6693                                         u16     wfd_devinfo_field = 0;
6694                                         
6695                                         //      Commented by Albert 20120319
6696                                         //      The first two bytes are the WFD device information field of WFD device information subelement.
6697                                         //      In big endian format.
6698                                         wfd_devinfo_field = RTW_GET_BE16(wfd_devinfo);
6699                                         if ( wfd_devinfo_field & WFD_DEVINFO_SESSION_AVAIL )
6700                                         {
6701                                                 pwfd_info->peer_session_avail = _TRUE;
6702                                         }
6703                                         else
6704                                         {
6705                                                 pwfd_info->peer_session_avail = _FALSE;
6706                                         }
6707                                 }
6708                         }
6709                         
6710                         if ( _FALSE == pwfd_info->peer_session_avail )
6711                         {
6712                                 DBG_871X( "[%s] WFD Session not avaiable!\n", __FUNCTION__ );
6713                                 goto exit;
6714                         }
6715                 }
6716 #endif // CONFIG_WFD
6717                 
6718                 DBG_871X( "[%s] peer channel: %d!\n", __FUNCTION__, uintPeerChannel );
6719 #ifdef CONFIG_CONCURRENT_MODE
6720                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
6721                 {
6722                         _cancel_timer_ex( &pwdinfo->ap_p2p_switch_timer );
6723                 }
6724 #endif // CONFIG_CONCURRENT_MODE
6725                 _rtw_memcpy( pwdinfo->tx_prov_disc_info.peerIFAddr, pnetwork->network.MacAddress, ETH_ALEN );
6726                 _rtw_memcpy( pwdinfo->tx_prov_disc_info.peerDevAddr, peerMAC, ETH_ALEN );
6727                 pwdinfo->tx_prov_disc_info.peer_channel_num[0] = ( u16 ) uintPeerChannel;
6728                 pwdinfo->tx_prov_disc_info.benable = _TRUE;
6729                 rtw_p2p_set_pre_state(pwdinfo, rtw_p2p_state(pwdinfo));
6730                 rtw_p2p_set_state(pwdinfo, P2P_STATE_TX_PROVISION_DIS_REQ);
6731
6732                 if(rtw_p2p_chk_role(pwdinfo, P2P_ROLE_CLIENT))
6733                 {
6734                         _rtw_memcpy( &pwdinfo->tx_prov_disc_info.ssid, &pnetwork->network.Ssid, sizeof( NDIS_802_11_SSID ) );
6735                 }
6736                 else if(rtw_p2p_chk_role(pwdinfo, P2P_ROLE_DEVICE) || rtw_p2p_chk_role(pwdinfo, P2P_ROLE_GO))
6737                 {
6738                         _rtw_memcpy( pwdinfo->tx_prov_disc_info.ssid.Ssid, pwdinfo->p2p_wildcard_ssid, P2P_WILDCARD_SSID_LEN );
6739                         pwdinfo->tx_prov_disc_info.ssid.SsidLength= P2P_WILDCARD_SSID_LEN;
6740                 }
6741
6742 #ifdef CONFIG_CONCURRENT_MODE
6743                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
6744                 {
6745                         //      Have to enter the power saving with the AP
6746                         set_channel_bwmode(padapter, pbuddy_mlmeext->cur_channel, pbuddy_mlmeext->cur_ch_offset, pbuddy_mlmeext->cur_bwmode);
6747                         
6748                         issue_nulldata(pbuddy_adapter, NULL, 1, 3, 500);
6749                 }
6750                 else
6751                 {
6752                         set_channel_bwmode(padapter, uintPeerChannel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
6753                 }
6754 #else
6755                 set_channel_bwmode(padapter, uintPeerChannel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
6756 #endif
6757
6758                 _set_timer( &pwdinfo->pre_tx_scan_timer, P2P_TX_PRESCAN_TIMEOUT );
6759                 
6760 #ifdef CONFIG_CONCURRENT_MODE
6761                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
6762                 {
6763                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_CONCURRENT_PROVISION_TIMEOUT );
6764                 }
6765                 else
6766                 {
6767                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_PROVISION_TIMEOUT );
6768                 }
6769 #else
6770                 _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_PROVISION_TIMEOUT );
6771 #endif // CONFIG_CONCURRENT_MODE                
6772                 
6773         }
6774         else
6775         {
6776                 DBG_871X( "[%s] NOT Found in the Scanning Queue!\n", __FUNCTION__ );
6777 #ifdef CONFIG_INTEL_WIDI
6778                 _cancel_timer_ex( &pwdinfo->restore_p2p_state_timer );
6779                 rtw_p2p_set_state(pwdinfo, P2P_STATE_FIND_PHASE_SEARCH);
6780                 rtw_p2p_findphase_ex_set(pwdinfo, P2P_FINDPHASE_EX_NONE);
6781                 rtw_free_network_queue(padapter, _TRUE);                
6782                 _enter_critical_bh(&pmlmepriv->lock, &irqL);                            
6783                 rtw_sitesurvey_cmd(padapter, NULL, 0, NULL, 0);
6784                 _exit_critical_bh(&pmlmepriv->lock, &irqL);
6785 #endif //CONFIG_INTEL_WIDI
6786         }
6787 exit:
6788         
6789         return ret;
6790                 
6791 }
6792
6793 //      Added by Albert 20110328
6794 //      This function is used to inform the driver the user had specified the pin code value or pbc
6795 //      to application.
6796
6797 static int rtw_p2p_got_wpsinfo(struct net_device *dev,
6798                                struct iw_request_info *info,
6799                                union iwreq_data *wrqu, char *extra)
6800 {
6801         
6802         int ret = 0;    
6803         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);   
6804         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
6805         
6806
6807         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
6808         //      Added by Albert 20110328
6809         //      if the input data is P2P_NO_WPSINFO -> reset the wpsinfo
6810         //      if the input data is P2P_GOT_WPSINFO_PEER_DISPLAY_PIN -> the utility just input the PIN code got from the peer P2P device.
6811         //      if the input data is P2P_GOT_WPSINFO_SELF_DISPLAY_PIN -> the utility just got the PIN code from itself.
6812         //      if the input data is P2P_GOT_WPSINFO_PBC -> the utility just determine to use the PBC
6813         
6814         if ( *extra == '0' )
6815         {
6816                 pwdinfo->ui_got_wps_info = P2P_NO_WPSINFO;
6817         }
6818         else if ( *extra == '1' )
6819         {
6820                 pwdinfo->ui_got_wps_info = P2P_GOT_WPSINFO_PEER_DISPLAY_PIN;
6821         }
6822         else if ( *extra == '2' )
6823         {
6824                 pwdinfo->ui_got_wps_info = P2P_GOT_WPSINFO_SELF_DISPLAY_PIN;
6825         }
6826         else if ( *extra == '3' )
6827         {
6828                 pwdinfo->ui_got_wps_info = P2P_GOT_WPSINFO_PBC;
6829         }
6830         else
6831         {
6832                 pwdinfo->ui_got_wps_info = P2P_NO_WPSINFO;
6833         }
6834         
6835         return ret;
6836                 
6837 }
6838
6839 #endif //CONFIG_P2P
6840
6841 static int rtw_p2p_set(struct net_device *dev,
6842                                struct iw_request_info *info,
6843                                union iwreq_data *wrqu, char *extra)
6844 {
6845         
6846         int ret = 0;
6847 #ifdef CONFIG_P2P
6848
6849         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6850         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
6851         struct iw_point *pdata = &wrqu->data;
6852         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
6853         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
6854
6855         DBG_871X( "[%s] extra = %s\n", __FUNCTION__, extra );
6856
6857         if ( _rtw_memcmp( extra, "enable=", 7 ) )
6858         {
6859                 rtw_wext_p2p_enable( dev, info, wrqu, &extra[7] );
6860         }
6861         else if ( _rtw_memcmp( extra, "setDN=", 6 ) )
6862         {
6863                 wrqu->data.length -= 6;
6864                 rtw_p2p_setDN( dev, info, wrqu, &extra[6] );
6865         }
6866         else if ( _rtw_memcmp( extra, "profilefound=", 13 ) )
6867         {
6868                 wrqu->data.length -= 13;
6869                 rtw_p2p_profilefound( dev, info, wrqu, &extra[13] );
6870         }
6871         else if ( _rtw_memcmp( extra, "prov_disc=", 10 ) )
6872         {
6873                 wrqu->data.length -= 10;
6874                 rtw_p2p_prov_disc( dev, info, wrqu, &extra[10] );
6875         }
6876         else if ( _rtw_memcmp( extra, "nego=", 5 ) )
6877         {
6878                 wrqu->data.length -= 5;
6879                 rtw_p2p_connect( dev, info, wrqu, &extra[5] );
6880         }
6881         else if ( _rtw_memcmp( extra, "intent=", 7 ) )
6882         {
6883                 //      Commented by Albert 2011/03/23
6884                 //      The wrqu->data.length will include the null character
6885                 //      So, we will decrease 7 + 1
6886                 wrqu->data.length -= 8;
6887                 rtw_p2p_set_intent( dev, info, wrqu, &extra[7] );
6888         }
6889         else if ( _rtw_memcmp( extra, "ssid=", 5 ) )
6890         {
6891                 wrqu->data.length -= 5;
6892                 rtw_p2p_set_go_nego_ssid( dev, info, wrqu, &extra[5] );
6893         }
6894         else if ( _rtw_memcmp( extra, "got_wpsinfo=", 12 ) )
6895         {
6896                 wrqu->data.length -= 12;
6897                 rtw_p2p_got_wpsinfo( dev, info, wrqu, &extra[12] );
6898         }
6899         else if ( _rtw_memcmp( extra, "listen_ch=", 10 ) )
6900         {
6901                 //      Commented by Albert 2011/05/24
6902                 //      The wrqu->data.length will include the null character
6903                 //      So, we will decrease (10 + 1)   
6904                 wrqu->data.length -= 11;
6905                 rtw_p2p_set_listen_ch( dev, info, wrqu, &extra[10] );
6906         }
6907         else if ( _rtw_memcmp( extra, "op_ch=", 6 ) )
6908         {
6909                 //      Commented by Albert 2011/05/24
6910                 //      The wrqu->data.length will include the null character
6911                 //      So, we will decrease (6 + 1)    
6912                 wrqu->data.length -= 7;
6913                 rtw_p2p_set_op_ch( dev, info, wrqu, &extra[6] );
6914         }
6915         else if ( _rtw_memcmp( extra, "invite=", 7 ) )
6916         {
6917                 wrqu->data.length -= 8;
6918                 rtw_p2p_invite_req( dev, info, wrqu, &extra[7] );
6919         }
6920         else if ( _rtw_memcmp( extra, "persistent=", 11 ) )
6921         {
6922                 wrqu->data.length -= 11;
6923                 rtw_p2p_set_persistent( dev, info, wrqu, &extra[11] );
6924         }
6925         else if ( _rtw_memcmp ( extra, "uuid=", 5) )
6926         {
6927                 wrqu->data.length -= 5;
6928                 ret = rtw_p2p_set_wps_uuid( dev, info, wrqu, &extra[5] );
6929         }
6930 #ifdef CONFIG_WFD
6931         else if ( _rtw_memcmp( extra, "sa=", 3 ) )
6932         {
6933                 //      sa: WFD Session Available information
6934                 wrqu->data.length -= 3;
6935                 rtw_p2p_set_sa( dev, info, wrqu, &extra[3] );
6936         }
6937         else if ( _rtw_memcmp( extra, "pc=", 3 ) )
6938         {
6939                 //      pc: WFD Preferred Connection
6940                 wrqu->data.length -= 3;
6941                 rtw_p2p_set_pc( dev, info, wrqu, &extra[3] );
6942         }
6943         else if ( _rtw_memcmp( extra, "wfd_type=", 9 ) )
6944         {
6945                 //      pc: WFD Preferred Connection
6946                 wrqu->data.length -= 9;
6947                 rtw_p2p_set_wfd_device_type( dev, info, wrqu, &extra[9] );
6948         }
6949         else if ( _rtw_memcmp( extra, "wfd_enable=", 11 ) )
6950         {
6951                 wrqu->data.length -= 11;
6952                 rtw_p2p_set_wfd_enable( dev, info, wrqu, &extra[11] );
6953         }
6954         else if ( _rtw_memcmp( extra, "driver_iface=", 13 ) )
6955         {
6956                 wrqu->data.length -= 13;
6957                 rtw_p2p_set_driver_iface( dev, info, wrqu, &extra[13] );
6958         }
6959 #endif //CONFIG_WFD
6960
6961 #endif //CONFIG_P2P
6962
6963         return ret;
6964                 
6965 }
6966
6967 static int rtw_p2p_get(struct net_device *dev,
6968                                struct iw_request_info *info,
6969                                union iwreq_data *wrqu, char *extra)
6970 {
6971         
6972         int ret = 0;    
6973         
6974 #ifdef CONFIG_P2P
6975
6976         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6977         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
6978         struct iw_point *pdata = &wrqu->data;
6979         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
6980         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
6981
6982         if ( padapter->bShowGetP2PState )
6983         {
6984                 DBG_871X( "[%s] extra = %s\n", __FUNCTION__, (char*) wrqu->data.pointer );
6985         }
6986
6987         if ( _rtw_memcmp( wrqu->data.pointer, "status", 6 ) )
6988         {
6989                 rtw_p2p_get_status( dev, info, wrqu, extra );
6990         }
6991         else if ( _rtw_memcmp( wrqu->data.pointer, "role", 4 ) )
6992         {
6993                 rtw_p2p_get_role( dev, info, wrqu, extra);
6994         }
6995         else if ( _rtw_memcmp( wrqu->data.pointer, "peer_ifa", 8 ) )
6996         {
6997                 rtw_p2p_get_peer_ifaddr( dev, info, wrqu, extra);
6998         }
6999         else if ( _rtw_memcmp( wrqu->data.pointer, "req_cm", 6 ) )
7000         {
7001                 rtw_p2p_get_req_cm( dev, info, wrqu, extra);
7002         }
7003         else if ( _rtw_memcmp( wrqu->data.pointer, "peer_deva", 9 ) )
7004         {
7005                 //      Get the P2P device address when receiving the provision discovery request frame.
7006                 rtw_p2p_get_peer_devaddr( dev, info, wrqu, extra);
7007         }
7008         else if ( _rtw_memcmp( wrqu->data.pointer, "group_id", 8 ) )
7009         {
7010                 rtw_p2p_get_groupid( dev, info, wrqu, extra);
7011         }
7012         else if ( _rtw_memcmp( wrqu->data.pointer, "inv_peer_deva", 13 ) )
7013         {
7014                 //      Get the P2P device address when receiving the P2P Invitation request frame.
7015                 rtw_p2p_get_peer_devaddr_by_invitation( dev, info, wrqu, extra);
7016         }
7017         else if ( _rtw_memcmp( wrqu->data.pointer, "op_ch", 5 ) )
7018         {
7019                 rtw_p2p_get_op_ch( dev, info, wrqu, extra);
7020         }
7021 #ifdef CONFIG_WFD
7022         else if ( _rtw_memcmp( wrqu->data.pointer, "peer_port", 9 ) )
7023         {
7024                 rtw_p2p_get_peer_wfd_port( dev, info, wrqu, extra );
7025         }
7026         else if ( _rtw_memcmp( wrqu->data.pointer, "wfd_sa", 6 ) )
7027         {
7028                 rtw_p2p_get_peer_wfd_session_available( dev, info, wrqu, extra );
7029         }
7030         else if ( _rtw_memcmp( wrqu->data.pointer, "wfd_pc", 6 ) )
7031         {
7032                 rtw_p2p_get_peer_wfd_preferred_connection( dev, info, wrqu, extra );
7033         }
7034 #endif // CONFIG_WFD    
7035         
7036 #endif //CONFIG_P2P
7037
7038         return ret;
7039                 
7040 }
7041
7042 static int rtw_p2p_get2(struct net_device *dev,
7043                                                 struct iw_request_info *info,
7044                                                 union iwreq_data *wrqu, char *extra)
7045 {
7046
7047         int ret = 0;
7048
7049 #ifdef CONFIG_P2P
7050
7051         int length = wrqu->data.length;
7052         char *buffer = (u8 *)rtw_malloc(length);
7053
7054         if (buffer == NULL)
7055         {
7056                 ret = -ENOMEM;
7057                 goto bad;
7058         }
7059
7060         if (copy_from_user(buffer, wrqu->data.pointer, wrqu->data.length))
7061         {
7062                 ret - EFAULT;
7063                 goto bad;
7064         }
7065
7066         DBG_871X("[%s] buffer = %s\n", __FUNCTION__, buffer);
7067
7068         if (_rtw_memcmp(buffer, "wpsCM=", 6))
7069         {
7070                 ret = rtw_p2p_get_wps_configmethod(dev, info, wrqu, extra, &buffer[6]);
7071         } else if (_rtw_memcmp(buffer, "devN=", 5))
7072         {
7073                 ret = rtw_p2p_get_device_name(dev, info, wrqu, extra, &buffer[5]);
7074         } else if (_rtw_memcmp(buffer, "dev_type=", 9))
7075         {
7076                 ret = rtw_p2p_get_device_type(dev, info, wrqu, extra, &buffer[9]);
7077         } else if (_rtw_memcmp(buffer, "go_devadd=", 10))
7078         {
7079                 ret = rtw_p2p_get_go_device_address(dev, info, wrqu, extra, &buffer[10]);
7080         } else if (_rtw_memcmp(buffer, "InvProc=", 8))
7081         {
7082                 ret = rtw_p2p_get_invitation_procedure(dev, info, wrqu, extra, &buffer[8]);
7083         } else
7084         {
7085                 snprintf(extra, sizeof("Command not found."), "Command not found.");
7086                 wrqu->data.length = strlen(extra);
7087         }
7088
7089 bad:
7090         if (buffer)
7091         {
7092                 rtw_mfree(buffer, length);
7093         }
7094
7095 #endif //CONFIG_P2P
7096
7097         return ret;
7098
7099 }
7100
7101 static int rtw_cta_test_start(struct net_device *dev,
7102                                                            struct iw_request_info *info,
7103                                                            union iwreq_data *wrqu, char *extra)
7104 {
7105         int ret = 0;
7106         _adapter        *padapter = (_adapter *)rtw_netdev_priv(dev);
7107         DBG_871X("%s %s\n", __func__, extra);
7108         if (!strcmp(extra, "1"))
7109                 padapter->in_cta_test = 1;
7110         else
7111                 padapter->in_cta_test = 0;
7112
7113         if(padapter->in_cta_test)
7114         {
7115                 u32 v = rtw_read32(padapter, REG_RCR);
7116                 v &= ~(RCR_CBSSID_DATA | RCR_CBSSID_BCN );//| RCR_ADF
7117                 rtw_write32(padapter, REG_RCR, v);
7118                 DBG_871X("enable RCR_ADF\n");
7119         }
7120         else
7121         {
7122                 u32 v = rtw_read32(padapter, REG_RCR);
7123                 v |= RCR_CBSSID_DATA | RCR_CBSSID_BCN ;//| RCR_ADF
7124                 rtw_write32(padapter, REG_RCR, v);
7125                 DBG_871X("disable RCR_ADF\n");
7126         }
7127         return ret;
7128 }
7129
7130
7131 extern int rtw_change_ifname(_adapter *padapter, const char *ifname);
7132 static int rtw_rereg_nd_name(struct net_device *dev,
7133                                struct iw_request_info *info,
7134                                union iwreq_data *wrqu, char *extra)
7135 {
7136         int ret = 0;    
7137         _adapter *padapter = rtw_netdev_priv(dev);
7138         struct rereg_nd_name_data *rereg_priv = &padapter->rereg_nd_name_priv;
7139         char new_ifname[IFNAMSIZ];
7140
7141         if(rereg_priv->old_ifname[0] == 0) {
7142                 char *reg_ifname;
7143 #ifdef CONFIG_CONCURRENT_MODE 
7144                 if (padapter->isprimary)
7145                         reg_ifname = padapter->registrypriv.ifname;
7146                 else
7147 #endif
7148                 reg_ifname = padapter->registrypriv.if2name;
7149
7150                 strncpy(rereg_priv->old_ifname, reg_ifname, IFNAMSIZ);
7151                 rereg_priv->old_ifname[IFNAMSIZ-1] = 0;
7152         }
7153
7154         //DBG_871X("%s wrqu->data.length:%d\n", __FUNCTION__, wrqu->data.length);
7155         if(wrqu->data.length > IFNAMSIZ)
7156                 return -EFAULT;
7157
7158         if ( copy_from_user(new_ifname, wrqu->data.pointer, IFNAMSIZ) ) {
7159                 return -EFAULT;
7160         }
7161
7162         if( 0 == strcmp(rereg_priv->old_ifname, new_ifname) ) {
7163                 return ret;
7164         }
7165
7166         DBG_871X("%s new_ifname:%s\n", __FUNCTION__, new_ifname);
7167         if( 0 != (ret = rtw_change_ifname(padapter, new_ifname)) ) {
7168                 goto exit;
7169         }
7170
7171         if(_rtw_memcmp(rereg_priv->old_ifname, "disable%d", 9) == _TRUE) {
7172                 padapter->ledpriv.bRegUseLed= rereg_priv->old_bRegUseLed;
7173                 rtw_hal_sw_led_init(padapter);
7174                 //rtw_ips_mode_req(&padapter->pwrctrlpriv, rereg_priv->old_ips_mode);
7175         }
7176
7177         strncpy(rereg_priv->old_ifname, new_ifname, IFNAMSIZ);
7178         rereg_priv->old_ifname[IFNAMSIZ-1] = 0;
7179         
7180         if(_rtw_memcmp(new_ifname, "disable%d", 9) == _TRUE) {
7181
7182                 DBG_871X("%s disable\n", __FUNCTION__);
7183                 // free network queue for Android's timming issue
7184                 rtw_free_network_queue(padapter, _TRUE);
7185                 
7186                 // close led
7187                 rtw_led_control(padapter, LED_CTL_POWER_OFF);
7188                 rereg_priv->old_bRegUseLed = padapter->ledpriv.bRegUseLed;
7189                 padapter->ledpriv.bRegUseLed= _FALSE;
7190                 rtw_hal_sw_led_deinit(padapter);
7191                 
7192                 // the interface is being "disabled", we can do deeper IPS
7193                 //rereg_priv->old_ips_mode = rtw_get_ips_mode_req(&padapter->pwrctrlpriv);
7194                 //rtw_ips_mode_req(&padapter->pwrctrlpriv, IPS_NORMAL);
7195         }
7196 exit:
7197         return ret;
7198
7199 }
7200
7201 #ifdef CONFIG_IOL
7202 #include <rtw_iol.h>
7203 #endif
7204
7205 #ifdef DBG_CMD_QUEUE
7206 u8 dump_cmd_id=0;
7207 #endif
7208 static int rtw_dbg_port(struct net_device *dev,
7209                                struct iw_request_info *info,
7210                                union iwreq_data *wrqu, char *extra)
7211 {       
7212         _irqL irqL;
7213         int ret = 0;
7214         u8 major_cmd, minor_cmd;
7215         u16 arg;
7216         u32 extra_arg, *pdata, val32;
7217         struct sta_info *psta;                                          
7218         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7219         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
7220         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
7221         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
7222         struct security_priv *psecuritypriv = &padapter->securitypriv;
7223         struct wlan_network *cur_network = &(pmlmepriv->cur_network);
7224         struct sta_priv *pstapriv = &padapter->stapriv;
7225         
7226
7227         pdata = (u32*)&wrqu->data;      
7228
7229         val32 = *pdata;
7230         arg = (u16)(val32&0x0000ffff);
7231         major_cmd = (u8)(val32>>24);
7232         minor_cmd = (u8)((val32>>16)&0x00ff);
7233
7234         extra_arg = *(pdata+1);
7235         
7236         switch(major_cmd)
7237         {
7238                 case 0x70://read_reg
7239                         switch(minor_cmd)
7240                         {
7241                                 case 1:
7242                                         DBG_871X("rtw_read8(0x%x)=0x%02x\n", arg, rtw_read8(padapter, arg));
7243                                         break;
7244                                 case 2:
7245                                         DBG_871X("rtw_read16(0x%x)=0x%04x\n", arg, rtw_read16(padapter, arg));
7246                                         break;
7247                                 case 4:
7248                                         DBG_871X("rtw_read32(0x%x)=0x%08x\n", arg, rtw_read32(padapter, arg));
7249                                         break;
7250                         }                       
7251                         break;
7252                 case 0x71://write_reg
7253                         switch(minor_cmd)
7254                         {
7255                                 case 1:
7256                                         rtw_write8(padapter, arg, extra_arg);
7257                                         DBG_871X("rtw_write8(0x%x)=0x%02x\n", arg, rtw_read8(padapter, arg));
7258                                         break;
7259                                 case 2:
7260                                         rtw_write16(padapter, arg, extra_arg);
7261                                         DBG_871X("rtw_write16(0x%x)=0x%04x\n", arg, rtw_read16(padapter, arg));
7262                                         break;
7263                                 case 4:
7264                                         rtw_write32(padapter, arg, extra_arg);
7265                                         DBG_871X("rtw_write32(0x%x)=0x%08x\n", arg, rtw_read32(padapter, arg));
7266                                         break;
7267                         }                       
7268                         break;
7269                 case 0x72://read_bb
7270                         DBG_871X("read_bbreg(0x%x)=0x%x\n", arg, rtw_hal_read_bbreg(padapter, arg, 0xffffffff));
7271                         break;
7272                 case 0x73://write_bb
7273                         rtw_hal_write_bbreg(padapter, arg, 0xffffffff, extra_arg);
7274                         DBG_871X("write_bbreg(0x%x)=0x%x\n", arg, rtw_hal_read_bbreg(padapter, arg, 0xffffffff));
7275                         break;
7276                 case 0x74://read_rf
7277                         DBG_871X("read RF_reg path(0x%02x),offset(0x%x),value(0x%08x)\n",minor_cmd,arg,rtw_hal_read_rfreg(padapter, minor_cmd, arg, 0xffffffff));       
7278                         break;
7279                 case 0x75://write_rf
7280                         rtw_hal_write_rfreg(padapter, minor_cmd, arg, 0xffffffff, extra_arg);
7281                         DBG_871X("write RF_reg path(0x%02x),offset(0x%x),value(0x%08x)\n",minor_cmd,arg, rtw_hal_read_rfreg(padapter, minor_cmd, arg, 0xffffffff));
7282                         break;  
7283
7284                 case 0x76:
7285                         switch(minor_cmd)
7286                         {
7287                                 case 0x00: //normal mode, 
7288                                         padapter->recvpriv.is_signal_dbg = 0;
7289                                         break;
7290                                 case 0x01: //dbg mode
7291                                         padapter->recvpriv.is_signal_dbg = 1;
7292                                         extra_arg = extra_arg>100?100:extra_arg;
7293                                         extra_arg = extra_arg<0?0:extra_arg;
7294                                         padapter->recvpriv.signal_strength_dbg=extra_arg;
7295                                         break;
7296                         }
7297                         break;
7298                 case 0x78: //IOL test
7299                         switch(minor_cmd)
7300                         {
7301                                 #ifdef CONFIG_IOL
7302                                 case 0x04: //LLT table initialization test
7303                                 {
7304                                         u8 page_boundary = 0xf9;
7305                                         {
7306                                                 struct xmit_frame       *xmit_frame;
7307
7308                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
7309                                                         ret = -ENOMEM;  
7310                                                         break;
7311                                                 }
7312                                                 
7313                                                 rtw_IOL_append_LLT_cmd(xmit_frame, page_boundary);
7314
7315
7316                                                 if(_SUCCESS != rtw_IOL_exec_cmds_sync(padapter, xmit_frame, 500,0) )
7317                                                         ret = -EPERM;
7318                                         }
7319                                 }
7320                                         break;
7321                                 case 0x05: //blink LED test
7322                                 {
7323                                         u16 reg = 0x4c;
7324                                         u32 blink_num = 50;
7325                                         u32 blink_delay_ms = 200;
7326                                         int i;
7327                                         
7328                                         {
7329                                                 struct xmit_frame       *xmit_frame;
7330
7331                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
7332                                                         ret = -ENOMEM;  
7333                                                         break;
7334                                                 }
7335
7336                                                 for(i=0;i<blink_num;i++){
7337                                                         #ifdef CONFIG_IOL_NEW_GENERATION
7338                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, 0x00,0xff);
7339                                                         rtw_IOL_append_DELAY_MS_cmd(xmit_frame, blink_delay_ms);
7340                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, 0x08,0xff);
7341                                                         rtw_IOL_append_DELAY_MS_cmd(xmit_frame, blink_delay_ms);
7342                                                         #else
7343                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, 0x00);
7344                                                         rtw_IOL_append_DELAY_MS_cmd(xmit_frame, blink_delay_ms);
7345                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, 0x08);
7346                                                         rtw_IOL_append_DELAY_MS_cmd(xmit_frame, blink_delay_ms);
7347                                                         #endif
7348                                                 }
7349                                                 if(_SUCCESS != rtw_IOL_exec_cmds_sync(padapter, xmit_frame, (blink_delay_ms*blink_num*2)+200,0) )
7350                                                         ret = -EPERM;
7351                                         }
7352                                 }
7353                                         break;
7354                                         
7355                                 case 0x06: //continuous wirte byte test
7356                                 {
7357                                         u16 reg = arg;
7358                                         u16 start_value = 0;
7359                                         u32 write_num = extra_arg;
7360                                         int i;
7361                                         u8 final;
7362                                         
7363                                         {
7364                                                 struct xmit_frame       *xmit_frame;
7365
7366                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
7367                                                         ret = -ENOMEM;  
7368                                                         break;
7369                                                 }
7370
7371                                                 for(i=0;i<write_num;i++){
7372                                                         #ifdef CONFIG_IOL_NEW_GENERATION
7373                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, i+start_value,0xFF);
7374                                                         #else
7375                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, i+start_value);
7376                                                         #endif
7377                                                 }
7378                                                 if(_SUCCESS != rtw_IOL_exec_cmds_sync(padapter, xmit_frame, 5000,0))
7379                                                         ret = -EPERM;
7380                                         }
7381
7382                                         if(start_value+write_num-1 == (final=rtw_read8(padapter, reg)) ) {
7383                                                 DBG_871X("continuous IOL_CMD_WB_REG to 0x%x %u times Success, start:%u, final:%u\n", reg, write_num, start_value, final);
7384                                         } else {
7385                                                 DBG_871X("continuous IOL_CMD_WB_REG to 0x%x %u times Fail, start:%u, final:%u\n", reg, write_num, start_value, final);
7386                                         }
7387                                 }
7388                                         break;
7389                                         
7390                                 case 0x07: //continuous wirte word test
7391                                 {
7392                                         u16 reg = arg;
7393                                         u16 start_value = 200;
7394                                         u32 write_num = extra_arg;
7395                                 
7396                                         int i;
7397                                         u16 final;
7398
7399                                         {
7400                                                 struct xmit_frame       *xmit_frame;
7401
7402                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
7403                                                         ret = -ENOMEM;  
7404                                                         break;
7405                                                 }
7406
7407                                                 for(i=0;i<write_num;i++){
7408                                                         #ifdef CONFIG_IOL_NEW_GENERATION
7409                                                         rtw_IOL_append_WW_cmd(xmit_frame, reg, i+start_value,0xFFFF);
7410                                                         #else
7411                                                         rtw_IOL_append_WW_cmd(xmit_frame, reg, i+start_value);
7412                                                         #endif
7413                                                 }
7414                                                 if(_SUCCESS !=rtw_IOL_exec_cmds_sync(padapter, xmit_frame, 5000,0))
7415                                                         ret = -EPERM;
7416                                         }
7417
7418                                         if(start_value+write_num-1 == (final=rtw_read16(padapter, reg)) ) {
7419                                                 DBG_871X("continuous IOL_CMD_WW_REG to 0x%x %u times Success, start:%u, final:%u\n", reg, write_num, start_value, final);
7420                                         } else {
7421                                                 DBG_871X("continuous IOL_CMD_WW_REG to 0x%x %u times Fail, start:%u, final:%u\n", reg, write_num, start_value, final);
7422                                         }
7423                                 }
7424                                         break;
7425                                         
7426                                 case 0x08: //continuous wirte dword test
7427                                 {
7428                                         u16 reg = arg;
7429                                         u32 start_value = 0x110000c7;
7430                                         u32 write_num = extra_arg;
7431                                 
7432                                         int i;
7433                                         u32 final;
7434
7435                                         {
7436                                                 struct xmit_frame       *xmit_frame;
7437
7438                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
7439                                                         ret = -ENOMEM;  
7440                                                         break;
7441                                                 }
7442
7443                                                 for(i=0;i<write_num;i++){
7444                                                         #ifdef CONFIG_IOL_NEW_GENERATION
7445                                                         rtw_IOL_append_WD_cmd(xmit_frame, reg, i+start_value,0xFFFFFFFF);
7446                                                         #else
7447                                                         rtw_IOL_append_WD_cmd(xmit_frame, reg, i+start_value);
7448                                                         #endif
7449                                                 }
7450                                                 if(_SUCCESS !=rtw_IOL_exec_cmds_sync(padapter, xmit_frame, 5000,0))
7451                                                         ret = -EPERM;
7452                                                         
7453                                         }
7454
7455                                         if(start_value+write_num-1 == (final=rtw_read32(padapter, reg)) ) {
7456                                                 DBG_871X("continuous IOL_CMD_WD_REG to 0x%x %u times Success, start:%u, final:%u\n", reg, write_num, start_value, final);
7457                                         } else {
7458                                                 DBG_871X("continuous IOL_CMD_WD_REG to 0x%x %u times Fail, start:%u, final:%u\n", reg, write_num, start_value, final);
7459                                         }
7460                                 }
7461                                         break;
7462                                 #endif //CONFIG_IOL
7463                         }
7464                         break;
7465                 case 0x79:
7466                         {
7467                                 /*
7468                                 * dbg 0x79000000 [value], set RESP_TXAGC to + value, value:0~15
7469                                 * dbg 0x79010000 [value], set RESP_TXAGC to - value, value:0~15
7470                                 */
7471                                 u8 value =  extra_arg & 0x0f;
7472                                 u8 sign = minor_cmd;
7473                                 u16 write_value = 0;
7474
7475                                 DBG_871X("%s set RESP_TXAGC to %s %u\n", __func__, sign?"minus":"plus", value);
7476
7477                                 if (sign)
7478                                         value = value | 0x10;
7479
7480                                 write_value = value | (value << 5);
7481                                 rtw_write16(padapter, 0x6d9, write_value);
7482                         }
7483                         break;
7484                 case 0x7a:
7485                         receive_disconnect(padapter, pmlmeinfo->network.MacAddress
7486                                 , WLAN_REASON_EXPIRATION_CHK);
7487                         break;
7488                 case 0x7F:
7489                         switch(minor_cmd)
7490                         {
7491                                 case 0x0:
7492                                         DBG_871X("fwstate=0x%x\n", get_fwstate(pmlmepriv));
7493                                         break;
7494                                 case 0x01:
7495                                         DBG_871X("auth_alg=0x%x, enc_alg=0x%x, auth_type=0x%x, enc_type=0x%x\n", 
7496                                                 psecuritypriv->dot11AuthAlgrthm, psecuritypriv->dot11PrivacyAlgrthm,
7497                                                 psecuritypriv->ndisauthtype, psecuritypriv->ndisencryptstatus);
7498                                         break;
7499                                 case 0x02:
7500                                         DBG_871X("pmlmeinfo->state=0x%x\n", pmlmeinfo->state);
7501                                         DBG_871X("DrvBcnEarly=%d\n", pmlmeext->DrvBcnEarly);
7502                                         DBG_871X("DrvBcnTimeOut=%d\n", pmlmeext->DrvBcnTimeOut);
7503                                         break;
7504                                 case 0x03:
7505                                         DBG_871X("qos_option=%d\n", pmlmepriv->qospriv.qos_option);
7506 #ifdef CONFIG_80211N_HT
7507                                         DBG_871X("ht_option=%d\n", pmlmepriv->htpriv.ht_option);
7508 #endif //CONFIG_80211N_HT
7509                                         break;
7510                                 case 0x04:
7511                                         DBG_871X("cur_ch=%d\n", pmlmeext->cur_channel);
7512                                         DBG_871X("cur_bw=%d\n", pmlmeext->cur_bwmode);
7513                                         DBG_871X("cur_ch_off=%d\n", pmlmeext->cur_ch_offset);
7514
7515                                         DBG_871X("oper_ch=%d\n", rtw_get_oper_ch(padapter));
7516                                         DBG_871X("oper_bw=%d\n", rtw_get_oper_bw(padapter));
7517                                         DBG_871X("oper_ch_offet=%d\n", rtw_get_oper_choffset(padapter));
7518                                 
7519                                         break;
7520                                 case 0x05:
7521                                         psta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
7522                                         if(psta)
7523                                         {
7524                                                 int i;
7525                                                 struct recv_reorder_ctrl *preorder_ctrl;
7526                                         
7527                                                 DBG_871X("SSID=%s\n", cur_network->network.Ssid.Ssid);
7528                                                 DBG_871X("sta's macaddr:" MAC_FMT "\n", MAC_ARG(psta->hwaddr));
7529                                                 DBG_871X("cur_channel=%d, cur_bwmode=%d, cur_ch_offset=%d\n", pmlmeext->cur_channel, pmlmeext->cur_bwmode, pmlmeext->cur_ch_offset);
7530                                                 DBG_871X("rtsen=%d, cts2slef=%d\n", psta->rtsen, psta->cts2self);
7531                                                 DBG_871X("state=0x%x, aid=%d, macid=%d, raid=%d\n", psta->state, psta->aid, psta->mac_id, psta->raid);
7532 #ifdef CONFIG_80211N_HT
7533                                                 DBG_871X("qos_en=%d, ht_en=%d, init_rate=%d\n", psta->qos_option, psta->htpriv.ht_option, psta->init_rate);
7534                                                 DBG_871X("bwmode=%d, ch_offset=%d, sgi_20m=%d,sgi_40m=%d\n", psta->bw_mode, psta->htpriv.ch_offset, psta->htpriv.sgi_20m, psta->htpriv.sgi_40m);
7535                                                 DBG_871X("ampdu_enable = %d\n", psta->htpriv.ampdu_enable);     
7536                                                 DBG_871X("agg_enable_bitmap=%x, candidate_tid_bitmap=%x\n", psta->htpriv.agg_enable_bitmap, psta->htpriv.candidate_tid_bitmap);
7537 #endif //CONFIG_80211N_HT
7538                                                 
7539                                                 for(i=0;i<16;i++)
7540                                                 {                                                       
7541                                                         preorder_ctrl = &psta->recvreorder_ctrl[i];
7542                                                         if(preorder_ctrl->enable)
7543                                                         {
7544                                                                 DBG_871X("tid=%d, indicate_seq=%d\n", i, preorder_ctrl->indicate_seq);
7545                                                         }
7546                                                 }       
7547                                                         
7548                                         }
7549                                         else
7550                                         {                                                       
7551                                                 DBG_871X("can't get sta's macaddr, cur_network's macaddr:" MAC_FMT "\n", MAC_ARG(cur_network->network.MacAddress));
7552                                         }                                       
7553                                         break;
7554                                 case 0x06:
7555                                         {
7556                                                 u32     ODMFlag;
7557                                                 rtw_hal_get_hwreg(padapter, HW_VAR_DM_FLAG, (u8*)(&ODMFlag));
7558                                                 DBG_871X("(B)DMFlag=0x%x, arg=0x%x\n", ODMFlag, arg);
7559                                                 ODMFlag = (u32)(0x0f&arg);
7560                                                 DBG_871X("(A)DMFlag=0x%x\n", ODMFlag);
7561                                                 rtw_hal_set_hwreg(padapter, HW_VAR_DM_FLAG, (u8 *)(&ODMFlag));
7562                                         }
7563                                         break;
7564                                 case 0x07:
7565                                         DBG_871X("bSurpriseRemoved=%d, bDriverStopped=%d\n", 
7566                                                 padapter->bSurpriseRemoved, padapter->bDriverStopped);
7567                                         break;
7568                                 case 0x08:
7569                                         {
7570                                                 struct xmit_priv *pxmitpriv = &padapter->xmitpriv;
7571                                                 struct recv_priv  *precvpriv = &padapter->recvpriv;
7572                                                 
7573                                                 DBG_871X("free_xmitbuf_cnt=%d, free_xmitframe_cnt=%d"
7574                                                         ", free_xmit_extbuf_cnt=%d, free_xframe_ext_cnt=%d"
7575                                                         ", free_recvframe_cnt=%d\n",
7576                                                         pxmitpriv->free_xmitbuf_cnt, pxmitpriv->free_xmitframe_cnt,
7577                                                         pxmitpriv->free_xmit_extbuf_cnt, pxmitpriv->free_xframe_ext_cnt,
7578                                                         precvpriv->free_recvframe_cnt);
7579                                                 #ifdef CONFIG_USB_HCI
7580                                                 DBG_871X("rx_urb_pending_cn=%d\n", ATOMIC_READ(&(precvpriv->rx_pending_cnt)));
7581                                                 #endif
7582                                         }
7583                                         break;  
7584                                 case 0x09:
7585                                         {
7586                                                 int i, j;
7587                                                 _list   *plist, *phead;
7588                                                 struct recv_reorder_ctrl *preorder_ctrl;
7589                                                 
7590 #ifdef CONFIG_AP_MODE
7591                                                 DBG_871X("sta_dz_bitmap=0x%x, tim_bitmap=0x%x\n", pstapriv->sta_dz_bitmap, pstapriv->tim_bitmap);
7592 #endif                                          
7593                                                 _enter_critical_bh(&pstapriv->sta_hash_lock, &irqL);
7594
7595                                                 for(i=0; i< NUM_STA; i++)
7596                                                 {
7597                                                         phead = &(pstapriv->sta_hash[i]);
7598                                                         plist = get_next(phead);
7599                 
7600                                                         while ((rtw_end_of_queue_search(phead, plist)) == _FALSE)
7601                                                         {
7602                                                                 psta = LIST_CONTAINOR(plist, struct sta_info, hash_list);
7603
7604                                                                 plist = get_next(plist);
7605
7606                                                                 if(extra_arg == psta->aid)
7607                                                                 {
7608                                                                         DBG_871X("sta's macaddr:" MAC_FMT "\n", MAC_ARG(psta->hwaddr));
7609                                                                         DBG_871X("rtsen=%d, cts2slef=%d\n", psta->rtsen, psta->cts2self);
7610                                                                         DBG_871X("state=0x%x, aid=%d, macid=%d, raid=%d\n", psta->state, psta->aid, psta->mac_id, psta->raid);
7611 #ifdef CONFIG_80211N_HT
7612                                                                         DBG_871X("qos_en=%d, ht_en=%d, init_rate=%d\n", psta->qos_option, psta->htpriv.ht_option, psta->init_rate);     
7613                                                                         DBG_871X("bwmode=%d, ch_offset=%d, sgi_20m=%d,sgi_40m=%d\n", psta->bw_mode, psta->htpriv.ch_offset, psta->htpriv.sgi_20m, psta->htpriv.sgi_40m);
7614                                                                         DBG_871X("ampdu_enable = %d\n", psta->htpriv.ampdu_enable);                                                                     
7615                                                                         DBG_871X("agg_enable_bitmap=%x, candidate_tid_bitmap=%x\n", psta->htpriv.agg_enable_bitmap, psta->htpriv.candidate_tid_bitmap);
7616 #endif //CONFIG_80211N_HT
7617                                                                         
7618 #ifdef CONFIG_AP_MODE
7619                                                                         DBG_871X("capability=0x%x\n", psta->capability);
7620                                                                         DBG_871X("flags=0x%x\n", psta->flags);
7621                                                                         DBG_871X("wpa_psk=0x%x\n", psta->wpa_psk);
7622                                                                         DBG_871X("wpa2_group_cipher=0x%x\n", psta->wpa2_group_cipher);
7623                                                                         DBG_871X("wpa2_pairwise_cipher=0x%x\n", psta->wpa2_pairwise_cipher);
7624                                                                         DBG_871X("qos_info=0x%x\n", psta->qos_info);
7625 #endif
7626                                                                         DBG_871X("dot118021XPrivacy=0x%x\n", psta->dot118021XPrivacy);
7627                                                                         
7628                                                                         
7629                                                 
7630                                                                         for(j=0;j<16;j++)
7631                                                                         {                                                       
7632                                                                                 preorder_ctrl = &psta->recvreorder_ctrl[j];
7633                                                                                 if(preorder_ctrl->enable)
7634                                                                                 {
7635                                                                                         DBG_871X("tid=%d, indicate_seq=%d\n", j, preorder_ctrl->indicate_seq);
7636                                                                                 }
7637                                                                         }               
7638                                                                         
7639                                                                 }                                                       
7640                         
7641                                                         }
7642                                                 }
7643         
7644                                                 _exit_critical_bh(&pstapriv->sta_hash_lock, &irqL);
7645
7646                                         }
7647                                         break;
7648                                 case 0x0a:
7649                                         {
7650                                                 int max_mac_id = 0;
7651                                                 max_mac_id = rtw_search_max_mac_id( padapter);
7652                                                 printk("%s ==> max_mac_id = %d \n",__FUNCTION__,max_mac_id);
7653                                         }       
7654                                         break;
7655                                 case 0x0b: //Enable=1, Disable=0 driver control vrtl_carrier_sense.
7656                                         {
7657                                                 //u8 driver_vcs_en; //Enable=1, Disable=0 driver control vrtl_carrier_sense.
7658                                                 //u8 driver_vcs_type;//force 0:disable VCS, 1:RTS-CTS, 2:CTS-to-self when vcs_en=1.
7659
7660                                                 if(arg == 0){
7661                                                         DBG_871X("disable driver ctrl vcs\n");                                          
7662                                                         padapter->driver_vcs_en = 0;                                    
7663                                                 }
7664                                                 else if(arg == 1){                                                      
7665                                                         DBG_871X("enable driver ctrl vcs = %d\n", extra_arg);
7666                                                         padapter->driver_vcs_en = 1;
7667         
7668                                                         if(extra_arg>2)
7669                                                                 padapter->driver_vcs_type = 1;                                          
7670                                                         else
7671                                                                 padapter->driver_vcs_type = extra_arg;
7672                                                 }
7673                                         }
7674                                         break;
7675                                 case 0x0c://dump rx/tx packet
7676                                         {
7677                                                 if(arg == 0){
7678                                                         DBG_871X("dump rx packet (%d)\n",extra_arg);                                            
7679                                                         //pHalData->bDumpRxPkt =extra_arg;                                              
7680                                                         rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DUMP_RXPKT, &(extra_arg));
7681                                                 }
7682                                                 else if(arg==1){
7683                                                         DBG_871X("dump tx packet (%d)\n",extra_arg);                                            
7684                                                         rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DUMP_TXPKT, &(extra_arg));
7685                                                 }
7686                                         }
7687                                         break;
7688 #if 0                           
7689                                 case 0x0d://dump cam
7690                                         {
7691                                                 //u8 entry = (u8) extra_arg;
7692                                                 u8 entry=0;
7693                                                 //dump cam
7694                                                 for(entry=0;entry<32;entry++)
7695                                                         read_cam(padapter,entry);
7696                                         }                               
7697                                         break;
7698 #endif
7699                                 case 0x0e:
7700                                         {
7701                                                 if(arg == 0){
7702                                                         DBG_871X("disable driver ctrl rx_ampdu_factor\n");                                              
7703                                                         padapter->driver_rx_ampdu_factor = 0xFF;
7704                                                 }
7705                                                 else if(arg == 1){
7706                                                         
7707                                                         DBG_871X("enable driver ctrl rx_ampdu_factor = %d\n", extra_arg);       
7708         
7709                                                         if(extra_arg > 0x03)
7710                                                                 padapter->driver_rx_ampdu_factor = 0xFF;                                                
7711                                                         else
7712                                                                 padapter->driver_rx_ampdu_factor = extra_arg;
7713                                                 }                                       
7714                                         }
7715                                         break;
7716                 #ifdef DBG_CONFIG_ERROR_DETECT
7717                                 case 0x0f:
7718                                                 {
7719                                                         if(extra_arg == 0){     
7720                                                                 DBG_871X("###### silent reset test.......#####\n");
7721                                                                 rtw_hal_sreset_reset(padapter);                                         
7722                                                         } else {
7723                                                                 HAL_DATA_TYPE   *pHalData = GET_HAL_DATA(padapter);
7724                                                                 struct sreset_priv *psrtpriv = &pHalData->srestpriv;
7725                                                                 psrtpriv->dbg_trigger_point = extra_arg;
7726                                                         }
7727                                                         
7728                                                 }
7729                                         break;
7730                                 case 0x15:
7731                                         {
7732                                                 struct pwrctrl_priv *pwrpriv = adapter_to_pwrctl(padapter);
7733                                                 DBG_871X("==>silent resete cnts:%d\n",pwrpriv->ips_enter_cnts);
7734                                         }
7735                                         break;  
7736                                         
7737                 #endif  
7738
7739                                 case 0x10:// driver version display
7740                                         dump_drv_version(RTW_DBGDUMP);
7741                                         break;
7742                                 case 0x11://dump linked status
7743                                         {
7744                                                 int pre_mode;
7745                                                 pre_mode=padapter->bLinkInfoDump;
7746                                                 // linked_info_dump(padapter,extra_arg);
7747                                                  if(extra_arg==1 || (extra_arg==0 && pre_mode==1) ) //not consider pwr_saving 0:
7748                                                 {
7749                                                         padapter->bLinkInfoDump = extra_arg;    
7750                 
7751                                                 }
7752                                                 else if( (extra_arg==2 ) || (extra_arg==0 && pre_mode==2))//consider power_saving
7753                                                 {               
7754                                                 //DBG_871X("linked_info_dump =%s \n", (padapter->bLinkInfoDump)?"enable":"disable")
7755                                                         linked_info_dump(padapter,extra_arg);   
7756                                                 }
7757
7758
7759                                                  
7760                                         }                                       
7761                                         break;
7762 #ifdef CONFIG_80211N_HT
7763                                 case 0x12: //set rx_stbc
7764                                 {
7765                                         struct registry_priv    *pregpriv = &padapter->registrypriv;
7766                                         // 0: disable, bit(0):enable 2.4g, bit(1):enable 5g, 0x3: enable both 2.4g and 5g
7767                                         //default is set to enable 2.4GHZ for IOT issue with bufflao's AP at 5GHZ
7768                                         if( pregpriv && (extra_arg == 0 || extra_arg == 1|| extra_arg == 2 || extra_arg == 3))
7769                                         {
7770                                                 pregpriv->rx_stbc= extra_arg;
7771                                                 DBG_871X("set rx_stbc=%d\n",pregpriv->rx_stbc);
7772                                         }
7773                                         else
7774                                                 DBG_871X("get rx_stbc=%d\n",pregpriv->rx_stbc);
7775                                         
7776                                 }
7777                                 break;
7778                                 case 0x13: //set ampdu_enable
7779                                 {
7780                                         struct registry_priv    *pregpriv = &padapter->registrypriv;
7781                                         // 0: disable, 0x1:enable (but wifi_spec should be 0), 0x2: force enable (don't care wifi_spec)
7782                                         if( pregpriv && extra_arg < 3 )
7783                                         {
7784                                                 pregpriv->ampdu_enable= extra_arg;
7785                                                 DBG_871X("set ampdu_enable=%d\n",pregpriv->ampdu_enable);
7786                                         }
7787                                         else
7788                                                 DBG_871X("get ampdu_enable=%d\n",pregpriv->ampdu_enable);
7789                                         
7790                                 }
7791                                 break;
7792 #endif
7793                                 case 0x14: //get wifi_spec
7794                                 {
7795                                         struct registry_priv    *pregpriv = &padapter->registrypriv;
7796                                         DBG_871X("get wifi_spec=%d\n",pregpriv->wifi_spec);
7797                                         
7798                                 }
7799                                 break;
7800                                 case 0x16:
7801                                 {
7802                                         if(arg == 0xff){
7803                                                 rtw_odm_dbg_comp_msg(RTW_DBGDUMP,padapter);
7804                                         }
7805                                         else{
7806                                                 u64 dbg_comp = (u64)extra_arg;
7807                                                 rtw_odm_dbg_comp_set(padapter, dbg_comp);
7808                                         }
7809                                 }
7810                                         break;
7811 #ifdef DBG_FIXED_CHAN
7812                                 case 0x17:
7813                                         {
7814                                                 struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);                                           
7815                                                 printk("===>  Fixed channel to %d \n",extra_arg);
7816                                                 pmlmeext->fixed_chan = extra_arg;       
7817                                                 
7818                                         }
7819                                         break;
7820 #endif
7821                                 case 0x18:
7822                                         {
7823                                                 printk("===>  Switch USB Mode %d \n",extra_arg);
7824                                                 rtw_hal_set_hwreg(padapter, HW_VAR_USB_MODE, (u8 *)&extra_arg);
7825                                         }
7826                                         break;
7827 #ifdef CONFIG_80211N_HT                 
7828                                 case 0x19:
7829                                         {
7830                                                 struct registry_priv    *pregistrypriv = &padapter->registrypriv;
7831                                                 // extra_arg :
7832                                                 // BIT0: Enable VHT LDPC Rx, BIT1: Enable VHT LDPC Tx, 
7833                                                 // BIT4: Enable HT LDPC Rx, BIT5: Enable HT LDPC Tx
7834                                                 if(arg == 0){
7835                                                         DBG_871X("driver disable LDPC\n");                                              
7836                                                         pregistrypriv->ldpc_cap = 0x00;
7837                                                 }
7838                                                 else if(arg == 1){                                                      
7839                                                         DBG_871X("driver set LDPC cap = 0x%x\n", extra_arg);
7840                                                         pregistrypriv->ldpc_cap = (u8)(extra_arg&0x33);                                         
7841                                                 }                                               
7842                                         }
7843                                         break;
7844                                 case 0x1a:
7845                                         {
7846                                                 struct registry_priv    *pregistrypriv = &padapter->registrypriv;
7847                                                 // extra_arg :
7848                                                 // BIT0: Enable VHT STBC Rx, BIT1: Enable VHT STBC Tx, 
7849                                                 // BIT4: Enable HT STBC Rx, BIT5: Enable HT STBC Tx
7850                                                 if(arg == 0){
7851                                                         DBG_871X("driver disable STBC\n");                                              
7852                                                         pregistrypriv->stbc_cap = 0x00;
7853                                                 }
7854                                                 else if(arg == 1){                                                      
7855                                                         DBG_871X("driver set STBC cap = 0x%x\n", extra_arg);
7856                                                         pregistrypriv->stbc_cap = (u8)(extra_arg&0x33);                                         
7857                                                 }                                               
7858                                         }
7859                                         break;
7860 #endif //CONFIG_80211N_HT
7861                                 case 0x1b:
7862                                         {       
7863                                                 struct registry_priv    *pregistrypriv = &padapter->registrypriv;
7864                                                 
7865                                                 if(arg == 0){
7866                                                         DBG_871X("disable driver ctrl max_rx_rate, reset to default_rate_set\n");                                                       
7867                                                         init_mlme_default_rate_set(padapter);
7868 #ifdef CONFIG_80211N_HT                                         
7869                                                         pregistrypriv->ht_enable = (u8)rtw_ht_enable;
7870 #endif //CONFIG_80211N_HT
7871                                                 }
7872                                                 else if(arg == 1){
7873
7874                                                         int i;
7875                                                         u8 max_rx_rate;                                         
7876                                                         
7877                                                         DBG_871X("enable driver ctrl max_rx_rate = 0x%x\n", extra_arg); 
7878
7879                                                         max_rx_rate = (u8)extra_arg;
7880
7881                                                         if(max_rx_rate < 0xc) // max_rx_rate < MSC0 -> B or G -> disable HT
7882                                                         {
7883 #ifdef CONFIG_80211N_HT                                         
7884                                                                 pregistrypriv->ht_enable = 0;
7885 #endif //CONFIG_80211N_HT
7886                                                                 for(i=0; i<NumRates; i++)
7887                                                                 {
7888                                                                         if(pmlmeext->datarate[i] > max_rx_rate)
7889                                                                                 pmlmeext->datarate[i] = 0xff;                                                                   
7890                                                                 }       
7891
7892                                                         }
7893 #ifdef CONFIG_80211N_HT 
7894                                                         else if(max_rx_rate < 0x1c) // mcs0~mcs15
7895                                                         {
7896                                                                 u32 mcs_bitmap=0x0;
7897                                                                                                         
7898                                                                 for(i=0; i<((max_rx_rate+1)-0xc); i++)
7899                                                                         mcs_bitmap |= BIT(i);
7900                                                                 
7901                                                                 set_mcs_rate_by_mask(pmlmeext->default_supported_mcs_set, mcs_bitmap);
7902                                                         }
7903 #endif //CONFIG_80211N_HT                                                       
7904                                                 }                                                                                       
7905                                         }
7906                                         break;
7907                                 case 0x1c: //enable/disable driver control AMPDU Density for peer sta's rx
7908                                         {
7909                                                 if(arg == 0){
7910                                                         DBG_871X("disable driver ctrl ampdu density\n");                                                
7911                                                         padapter->driver_ampdu_spacing = 0xFF;
7912                                                 }
7913                                                 else if(arg == 1){
7914                                                         
7915                                                         DBG_871X("enable driver ctrl ampdu density = %d\n", extra_arg); 
7916         
7917                                                         if(extra_arg > 0x07)
7918                                                                 padapter->driver_ampdu_spacing = 0xFF;                                          
7919                                                         else
7920                                                                 padapter->driver_ampdu_spacing = extra_arg;
7921                                                 }
7922                                         }
7923                                         break;
7924 #ifdef CONFIG_BACKGROUND_NOISE_MONITOR
7925                                 case 0x1e:
7926                                         {
7927                                                 HAL_DATA_TYPE   *pHalData = GET_HAL_DATA(padapter);
7928                                                 PDM_ODM_T pDM_Odm = &pHalData->odmpriv;
7929                                                 u8 chan = rtw_get_oper_ch(padapter);
7930                                                 DBG_871X("===========================================\n");
7931                                                 ODM_InbandNoise_Monitor(pDM_Odm,_TRUE,0x1e,100);
7932                                                 DBG_871X("channel(%d),noise_a = %d, noise_b = %d , noise_all:%d \n", 
7933                                                         chan,pDM_Odm->noise_level.noise[ODM_RF_PATH_A], 
7934                                                         pDM_Odm->noise_level.noise[ODM_RF_PATH_B],
7935                                                         pDM_Odm->noise_level.noise_all);
7936                                                 DBG_871X("===========================================\n");
7937                                                 
7938                                         }
7939                                         break;
7940 #endif
7941                                 case 0x23:
7942                                         {
7943                                                 DBG_871X("turn %s the bNotifyChannelChange Variable\n",(extra_arg==1)?"on":"off");
7944                                                 padapter->bNotifyChannelChange = extra_arg;
7945                                                 break;
7946                                         }
7947                                 case 0x24:
7948                                         {
7949 #ifdef CONFIG_P2P
7950                                                 DBG_871X("turn %s the bShowGetP2PState Variable\n",(extra_arg==1)?"on":"off");
7951                                                 padapter->bShowGetP2PState = extra_arg;
7952 #endif // CONFIG_P2P
7953                                                 break;                                          
7954                                         }
7955 #ifdef CONFIG_GPIO_API              
7956                             case 0x25: //Get GPIO register
7957                                     {
7958                                             /*
7959                                             * dbg 0x7f250000 [gpio_num], Get gpio value, gpio_num:0~7
7960                                             */                
7961                               
7962                                             u8 value;
7963                                             DBG_871X("Read GPIO Value  extra_arg = %d\n",extra_arg);
7964                                             value = rtw_hal_get_gpio(padapter,extra_arg);
7965                                             DBG_871X("Read GPIO Value = %d\n",value);                                        
7966                                             break;
7967                                     }
7968                             case 0x26: //Set GPIO direction
7969                                     {
7970                                                                                 
7971                                             /* dbg 0x7f26000x [y], Set gpio direction, 
7972                                             * x: gpio_num,4~7  y: indicate direction, 0~1  
7973                                             */ 
7974                                         
7975                                             int value;
7976                                             DBG_871X("Set GPIO Direction! arg = %d ,extra_arg=%d\n",arg ,extra_arg);
7977                                             value = rtw_hal_config_gpio(padapter, arg, extra_arg);
7978                                             DBG_871X("Set GPIO Direction %s \n",(value==-1)?"Fail!!!":"Success");
7979                                             break;
7980                                         }
7981                                 case 0x27: //Set GPIO output direction value
7982                                         {
7983                                                 /*
7984                                                 * dbg 0x7f27000x [y], Set gpio output direction value, 
7985                                                 * x: gpio_num,4~7  y: indicate direction, 0~1  
7986                                                 */ 
7987                                         
7988                                                 int value;
7989                                                 DBG_871X("Set GPIO Value! arg = %d ,extra_arg=%d\n",arg ,extra_arg);
7990                                                 value = rtw_hal_set_gpio_output_value(padapter,arg,extra_arg);
7991                                                 DBG_871X("Set GPIO Value %s \n",(value==-1)?"Fail!!!":"Success");
7992                                                 break;
7993                                         }
7994 #endif          
7995 #ifdef DBG_CMD_QUEUE
7996                                 case 0x28:
7997                                         {
7998                                                 dump_cmd_id = extra_arg;
7999                                                 DBG_871X("dump_cmd_id:%d\n",dump_cmd_id);
8000                                         }
8001                                         break;
8002 #endif //DBG_CMD_QUEUE
8003                                 case 0xaa:
8004                                         {
8005                                                 if((extra_arg & 0x7F)> 0x3F) extra_arg = 0xFF;
8006                                                 DBG_871X("chang data rate to :0x%02x\n",extra_arg);
8007                                                 padapter->fix_rate = extra_arg;
8008                                         }
8009                                         break;  
8010                                 case 0xdd://registers dump , 0 for mac reg,1 for bb reg, 2 for rf reg
8011                                         {
8012                                                 if(extra_arg==0){
8013                                                         mac_reg_dump(RTW_DBGDUMP, padapter);
8014                                                 }
8015                                                 else if(extra_arg==1){
8016                                                         bb_reg_dump(RTW_DBGDUMP, padapter);
8017                                                 }
8018                                                 else if(extra_arg==2){
8019                                                         rf_reg_dump(RTW_DBGDUMP, padapter);
8020                                                 }
8021                                         }
8022                                         break;          
8023
8024                                 case 0xee://turn on/off dynamic funcs
8025                                         {
8026                                                 u32 odm_flag;
8027
8028                                                 if(0xf==extra_arg){
8029                                                         rtw_hal_get_def_var(padapter, HAL_DEF_DBG_DM_FUNC,&odm_flag);                                                   
8030                                                         DBG_871X(" === DMFlag(0x%08x) === \n",odm_flag);
8031                                                         DBG_871X("extra_arg = 0  - disable all dynamic func \n");
8032                                                         DBG_871X("extra_arg = 1  - disable DIG- BIT(0)\n");
8033                                                         DBG_871X("extra_arg = 2  - disable High power - BIT(1)\n");
8034                                                         DBG_871X("extra_arg = 3  - disable tx power tracking - BIT(2)\n");
8035                                                         DBG_871X("extra_arg = 4  - disable BT coexistence - BIT(3)\n");
8036                                                         DBG_871X("extra_arg = 5  - disable antenna diversity - BIT(4)\n");
8037                                                         DBG_871X("extra_arg = 6  - enable all dynamic func \n");                                                        
8038                                                 }
8039                                                 else{
8040                                                         /*      extra_arg = 0  - disable all dynamic func
8041                                                                 extra_arg = 1  - disable DIG
8042                                                                 extra_arg = 2  - disable tx power tracking
8043                                                                 extra_arg = 3  - turn on all dynamic func
8044                                                         */                      
8045                                                         rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DM_FUNC, &(extra_arg));
8046                                                         rtw_hal_get_def_var(padapter, HAL_DEF_DBG_DM_FUNC,&odm_flag);                                                   
8047                                                         DBG_871X(" === DMFlag(0x%08x) === \n",odm_flag);
8048                                                 }
8049                                         }
8050                                         break;
8051
8052                                 case 0xfd:
8053                                         rtw_write8(padapter, 0xc50, arg);
8054                                         DBG_871X("wr(0xc50)=0x%x\n", rtw_read8(padapter, 0xc50));
8055                                         rtw_write8(padapter, 0xc58, arg);
8056                                         DBG_871X("wr(0xc58)=0x%x\n", rtw_read8(padapter, 0xc58));
8057                                         break;
8058                                 case 0xfe:
8059                                         DBG_871X("rd(0xc50)=0x%x\n", rtw_read8(padapter, 0xc50));
8060                                         DBG_871X("rd(0xc58)=0x%x\n", rtw_read8(padapter, 0xc58));
8061                                         break;
8062                                 case 0xff:
8063                                         {
8064                                                 DBG_871X("dbg(0x210)=0x%x\n", rtw_read32(padapter, 0x210));
8065                                                 DBG_871X("dbg(0x608)=0x%x\n", rtw_read32(padapter, 0x608));
8066                                                 DBG_871X("dbg(0x280)=0x%x\n", rtw_read32(padapter, 0x280));
8067                                                 DBG_871X("dbg(0x284)=0x%x\n", rtw_read32(padapter, 0x284));
8068                                                 DBG_871X("dbg(0x288)=0x%x\n", rtw_read32(padapter, 0x288));
8069         
8070                                                 DBG_871X("dbg(0x664)=0x%x\n", rtw_read32(padapter, 0x664));
8071
8072
8073                                                 DBG_871X("\n");
8074                 
8075                                                 DBG_871X("dbg(0x430)=0x%x\n", rtw_read32(padapter, 0x430));
8076                                                 DBG_871X("dbg(0x438)=0x%x\n", rtw_read32(padapter, 0x438));
8077
8078                                                 DBG_871X("dbg(0x440)=0x%x\n", rtw_read32(padapter, 0x440));
8079         
8080                                                 DBG_871X("dbg(0x458)=0x%x\n", rtw_read32(padapter, 0x458));
8081         
8082                                                 DBG_871X("dbg(0x484)=0x%x\n", rtw_read32(padapter, 0x484));
8083                                                 DBG_871X("dbg(0x488)=0x%x\n", rtw_read32(padapter, 0x488));
8084         
8085                                                 DBG_871X("dbg(0x444)=0x%x\n", rtw_read32(padapter, 0x444));
8086                                                 DBG_871X("dbg(0x448)=0x%x\n", rtw_read32(padapter, 0x448));
8087                                                 DBG_871X("dbg(0x44c)=0x%x\n", rtw_read32(padapter, 0x44c));
8088                                                 DBG_871X("dbg(0x450)=0x%x\n", rtw_read32(padapter, 0x450));
8089                                         }
8090                                         break;
8091                         }                       
8092                         break;
8093                 default:
8094                         DBG_871X("error dbg cmd!\n");
8095                         break;  
8096         }
8097         
8098
8099         return ret;
8100
8101 }
8102
8103 static int wpa_set_param(struct net_device *dev, u8 name, u32 value)
8104 {
8105         uint ret=0;
8106         u32 flags;
8107         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8108         
8109         switch (name){
8110         case IEEE_PARAM_WPA_ENABLED:
8111
8112                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_8021X; //802.1x
8113                 
8114                 //ret = ieee80211_wpa_enable(ieee, value);
8115                 
8116                 switch((value)&0xff)
8117                 {
8118                         case 1 : //WPA
8119                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPAPSK; //WPA_PSK
8120                         padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
8121                                 break;
8122                         case 2: //WPA2
8123                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPA2PSK; //WPA2_PSK
8124                         padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
8125                                 break;
8126                 }
8127                 
8128                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("wpa_set_param:padapter->securitypriv.ndisauthtype=%d\n", padapter->securitypriv.ndisauthtype));
8129                 
8130                 break;
8131
8132         case IEEE_PARAM_TKIP_COUNTERMEASURES:
8133                 //ieee->tkip_countermeasures=value;
8134                 break;
8135
8136         case IEEE_PARAM_DROP_UNENCRYPTED: 
8137         {
8138                 /* HACK:
8139                  *
8140                  * wpa_supplicant calls set_wpa_enabled when the driver
8141                  * is loaded and unloaded, regardless of if WPA is being
8142                  * used.  No other calls are made which can be used to
8143                  * determine if encryption will be used or not prior to
8144                  * association being expected.  If encryption is not being
8145                  * used, drop_unencrypted is set to false, else true -- we
8146                  * can use this to determine if the CAP_PRIVACY_ON bit should
8147                  * be set.
8148                  */
8149                  
8150 #if 0    
8151                 struct ieee80211_security sec = {
8152                         .flags = SEC_ENABLED,
8153                         .enabled = value,
8154                 };
8155                 ieee->drop_unencrypted = value;
8156                 /* We only change SEC_LEVEL for open mode. Others
8157                  * are set by ipw_wpa_set_encryption.
8158                  */
8159                 if (!value) {
8160                         sec.flags |= SEC_LEVEL;
8161                         sec.level = SEC_LEVEL_0;
8162                 }
8163                 else {
8164                         sec.flags |= SEC_LEVEL;
8165                         sec.level = SEC_LEVEL_1;
8166                 }
8167                 if (ieee->set_security)
8168                         ieee->set_security(ieee->dev, &sec);
8169 #endif          
8170                 break;
8171
8172         }
8173         case IEEE_PARAM_PRIVACY_INVOKED:        
8174                 
8175                 //ieee->privacy_invoked=value;
8176                 
8177                 break;
8178
8179         case IEEE_PARAM_AUTH_ALGS:
8180                 
8181                 ret = wpa_set_auth_algs(dev, value);
8182                 
8183                 break;
8184
8185         case IEEE_PARAM_IEEE_802_1X:
8186                 
8187                 //ieee->ieee802_1x=value;               
8188                 
8189                 break;
8190                 
8191         case IEEE_PARAM_WPAX_SELECT:
8192                 
8193                 // added for WPA2 mixed mode
8194                 //DBG_871X(KERN_WARNING "------------------------>wpax value = %x\n", value);
8195                 /*
8196                 spin_lock_irqsave(&ieee->wpax_suitlist_lock,flags);
8197                 ieee->wpax_type_set = 1;
8198                 ieee->wpax_type_notify = value;
8199                 spin_unlock_irqrestore(&ieee->wpax_suitlist_lock,flags);
8200                 */
8201                 
8202                 break;
8203
8204         default:                
8205
8206
8207                 
8208                 ret = -EOPNOTSUPP;
8209
8210                 
8211                 break;
8212         
8213         }
8214
8215         return ret;
8216         
8217 }
8218
8219 static int wpa_mlme(struct net_device *dev, u32 command, u32 reason)
8220 {       
8221         int ret = 0;
8222         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8223
8224         switch (command)
8225         {
8226                 case IEEE_MLME_STA_DEAUTH:
8227
8228                         if(!rtw_set_802_11_disassociate(padapter))
8229                                 ret = -1;               
8230                         
8231                         break;
8232
8233                 case IEEE_MLME_STA_DISASSOC:
8234                 
8235                         if(!rtw_set_802_11_disassociate(padapter))
8236                                 ret = -1;               
8237         
8238                         break;
8239
8240                 default:
8241                         ret = -EOPNOTSUPP;
8242                         break;
8243         }
8244
8245         return ret;
8246         
8247 }
8248
8249 static int wpa_supplicant_ioctl(struct net_device *dev, struct iw_point *p)
8250 {
8251         struct ieee_param *param;
8252         uint ret=0;
8253
8254         //down(&ieee->wx_sem);  
8255
8256         if (p->length < sizeof(struct ieee_param) || !p->pointer){
8257                 ret = -EINVAL;
8258                 goto out;
8259         }
8260         
8261         param = (struct ieee_param *)rtw_malloc(p->length);
8262         if (param == NULL)
8263         {
8264                 ret = -ENOMEM;
8265                 goto out;
8266         }
8267         
8268         if (copy_from_user(param, p->pointer, p->length))
8269         {
8270                 rtw_mfree((u8*)param, p->length);
8271                 ret = -EFAULT;
8272                 goto out;
8273         }
8274
8275         switch (param->cmd) {
8276
8277         case IEEE_CMD_SET_WPA_PARAM:
8278                 ret = wpa_set_param(dev, param->u.wpa_param.name, param->u.wpa_param.value);
8279                 break;
8280
8281         case IEEE_CMD_SET_WPA_IE:
8282                 //ret = wpa_set_wpa_ie(dev, param, p->length);
8283                 ret =  rtw_set_wpa_ie((_adapter *)rtw_netdev_priv(dev), (char*)param->u.wpa_ie.data, (u16)param->u.wpa_ie.len);
8284                 break;
8285
8286         case IEEE_CMD_SET_ENCRYPTION:
8287                 ret = wpa_set_encryption(dev, param, p->length);
8288                 break;
8289
8290         case IEEE_CMD_MLME:
8291                 ret = wpa_mlme(dev, param->u.mlme.command, param->u.mlme.reason_code);
8292                 break;
8293
8294         default:
8295                 DBG_871X("Unknown WPA supplicant request: %d\n", param->cmd);
8296                 ret = -EOPNOTSUPP;
8297                 break;
8298                 
8299         }
8300
8301         if (ret == 0 && copy_to_user(p->pointer, param, p->length))
8302                 ret = -EFAULT;
8303
8304         rtw_mfree((u8 *)param, p->length);
8305         
8306 out:
8307         
8308         //up(&ieee->wx_sem);
8309         
8310         return ret;
8311         
8312 }
8313
8314 #ifdef CONFIG_AP_MODE
8315 static int rtw_set_encryption(struct net_device *dev, struct ieee_param *param, u32 param_len)
8316 {
8317         int ret = 0;
8318         u32 wep_key_idx, wep_key_len,wep_total_len;
8319         NDIS_802_11_WEP  *pwep = NULL;
8320         struct sta_info *psta = NULL, *pbcmc_sta = NULL;        
8321         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8322         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
8323         struct security_priv* psecuritypriv=&(padapter->securitypriv);
8324         struct sta_priv *pstapriv = &padapter->stapriv;
8325
8326         DBG_871X("%s\n", __FUNCTION__);
8327
8328         param->u.crypt.err = 0;
8329         param->u.crypt.alg[IEEE_CRYPT_ALG_NAME_LEN - 1] = '\0';
8330
8331         //sizeof(struct ieee_param) = 64 bytes;
8332         //if (param_len !=  (u32) ((u8 *) param->u.crypt.key - (u8 *) param) + param->u.crypt.key_len)
8333         if (param_len !=  sizeof(struct ieee_param) + param->u.crypt.key_len)
8334         {
8335                 ret =  -EINVAL;
8336                 goto exit;
8337         }
8338
8339         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
8340             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
8341             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
8342         {
8343                 if (param->u.crypt.idx >= WEP_KEYS)
8344                 {
8345                         ret = -EINVAL;
8346                         goto exit;
8347                 }       
8348         }
8349         else 
8350         {               
8351                 psta = rtw_get_stainfo(pstapriv, param->sta_addr);
8352                 if(!psta)
8353                 {
8354                         //ret = -EINVAL;
8355                         DBG_871X("rtw_set_encryption(), sta has already been removed or never been added\n");
8356                         goto exit;
8357                 }                       
8358         }
8359
8360         if (strcmp(param->u.crypt.alg, "none") == 0 && (psta==NULL))
8361         {
8362                 //todo:clear default encryption keys
8363
8364                 psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
8365                 psecuritypriv->ndisencryptstatus = Ndis802_11EncryptionDisabled;
8366                 psecuritypriv->dot11PrivacyAlgrthm = _NO_PRIVACY_;
8367                 psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
8368
8369                 DBG_871X("clear default encryption keys, keyid=%d\n", param->u.crypt.idx);
8370                 
8371                 goto exit;
8372         }
8373
8374
8375         if (strcmp(param->u.crypt.alg, "WEP") == 0 && (psta==NULL))
8376         {               
8377                 DBG_871X("r871x_set_encryption, crypt.alg = WEP\n");
8378                 
8379                 wep_key_idx = param->u.crypt.idx;
8380                 wep_key_len = param->u.crypt.key_len;
8381                                         
8382                 DBG_871X("r871x_set_encryption, wep_key_idx=%d, len=%d\n", wep_key_idx, wep_key_len);
8383
8384                 if((wep_key_idx >= WEP_KEYS) || (wep_key_len<=0))
8385                 {
8386                         ret = -EINVAL;
8387                         goto exit;
8388                 }
8389                         
8390
8391                 if (wep_key_len > 0) 
8392                 {                       
8393                         wep_key_len = wep_key_len <= 5 ? 5 : 13;
8394                         wep_total_len = wep_key_len + FIELD_OFFSET(NDIS_802_11_WEP, KeyMaterial);
8395                         pwep =(NDIS_802_11_WEP *)rtw_malloc(wep_total_len);
8396                         if(pwep == NULL){
8397                                 DBG_871X(" r871x_set_encryption: pwep allocate fail !!!\n");
8398                                 goto exit;
8399                         }
8400                         
8401                         _rtw_memset(pwep, 0, wep_total_len);
8402                 
8403                         pwep->KeyLength = wep_key_len;
8404                         pwep->Length = wep_total_len;
8405                         
8406                 }
8407                 
8408                 pwep->KeyIndex = wep_key_idx;
8409
8410                 _rtw_memcpy(pwep->KeyMaterial,  param->u.crypt.key, pwep->KeyLength);
8411
8412                 if(param->u.crypt.set_tx)
8413                 {
8414                         DBG_871X("wep, set_tx=1\n");
8415
8416                         psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
8417                         psecuritypriv->ndisencryptstatus = Ndis802_11Encryption1Enabled;
8418                         psecuritypriv->dot11PrivacyAlgrthm=_WEP40_;
8419                         psecuritypriv->dot118021XGrpPrivacy=_WEP40_;
8420                         
8421                         if(pwep->KeyLength==13)
8422                         {
8423                                 psecuritypriv->dot11PrivacyAlgrthm=_WEP104_;
8424                                 psecuritypriv->dot118021XGrpPrivacy=_WEP104_;
8425                         }
8426
8427                 
8428                         psecuritypriv->dot11PrivacyKeyIndex = wep_key_idx;
8429                         
8430                         _rtw_memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
8431
8432                         psecuritypriv->dot11DefKeylen[wep_key_idx]=pwep->KeyLength;
8433
8434                         rtw_ap_set_wep_key(padapter, pwep->KeyMaterial, pwep->KeyLength, wep_key_idx, 1);
8435                 }
8436                 else
8437                 {
8438                         DBG_871X("wep, set_tx=0\n");
8439                         
8440                         //don't update "psecuritypriv->dot11PrivacyAlgrthm" and 
8441                         //"psecuritypriv->dot11PrivacyKeyIndex=keyid", but can rtw_set_key to cam
8442                                         
8443                       _rtw_memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
8444
8445                         psecuritypriv->dot11DefKeylen[wep_key_idx] = pwep->KeyLength;                   
8446
8447                         rtw_ap_set_wep_key(padapter, pwep->KeyMaterial, pwep->KeyLength, wep_key_idx, 0);
8448                 }
8449
8450                 goto exit;
8451                 
8452         }
8453
8454         
8455         if(!psta && check_fwstate(pmlmepriv, WIFI_AP_STATE)) // //group key
8456         {
8457                 if(param->u.crypt.set_tx ==1)
8458                 {
8459                         if(strcmp(param->u.crypt.alg, "WEP") == 0)
8460                         {
8461                                 DBG_871X("%s, set group_key, WEP\n", __FUNCTION__);
8462                                 
8463                                 _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
8464                                         
8465                                 psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
8466                                 if(param->u.crypt.key_len==13)
8467                                 {                                               
8468                                                 psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
8469                                 }
8470                                 
8471                         }
8472                         else if(strcmp(param->u.crypt.alg, "TKIP") == 0)
8473                         {                                               
8474                                 DBG_871X("%s, set group_key, TKIP\n", __FUNCTION__);
8475                                 
8476                                 psecuritypriv->dot118021XGrpPrivacy = _TKIP_;
8477
8478                                 _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
8479                                 
8480                                 //DEBUG_ERR("set key length :param->u.crypt.key_len=%d\n", param->u.crypt.key_len);
8481                                 //set mic key
8482                                 _rtw_memcpy(psecuritypriv->dot118021XGrptxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[16]), 8);
8483                                 _rtw_memcpy(psecuritypriv->dot118021XGrprxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[24]), 8);
8484
8485                                 psecuritypriv->busetkipkey = _TRUE;
8486                                                                                         
8487                         }
8488                         else if(strcmp(param->u.crypt.alg, "CCMP") == 0)
8489                         {
8490                                 DBG_871X("%s, set group_key, CCMP\n", __FUNCTION__);
8491                         
8492                                 psecuritypriv->dot118021XGrpPrivacy = _AES_;
8493
8494                                 _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
8495                         }
8496                         else
8497                         {
8498                                 DBG_871X("%s, set group_key, none\n", __FUNCTION__);
8499                                 
8500                                 psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
8501                         }
8502
8503                         psecuritypriv->dot118021XGrpKeyid = param->u.crypt.idx;
8504
8505                         psecuritypriv->binstallGrpkey = _TRUE;
8506
8507                         psecuritypriv->dot11PrivacyAlgrthm = psecuritypriv->dot118021XGrpPrivacy;//!!!
8508                                                                 
8509                         rtw_ap_set_group_key(padapter, param->u.crypt.key, psecuritypriv->dot118021XGrpPrivacy, param->u.crypt.idx);
8510                         
8511                         pbcmc_sta=rtw_get_bcmc_stainfo(padapter);
8512                         if(pbcmc_sta)
8513                         {
8514                                 pbcmc_sta->ieee8021x_blocked = _FALSE;
8515                                 pbcmc_sta->dot118021XPrivacy= psecuritypriv->dot118021XGrpPrivacy;//rx will use bmc_sta's dot118021XPrivacy                     
8516                         }       
8517                                                 
8518                 }
8519
8520                 goto exit;
8521                 
8522         }       
8523
8524         if(psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X && psta) // psk/802_1x
8525         {
8526                 if(check_fwstate(pmlmepriv, WIFI_AP_STATE))
8527                 {
8528                         if(param->u.crypt.set_tx ==1)
8529                         { 
8530                                 _rtw_memcpy(psta->dot118021x_UncstKey.skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
8531                                 
8532                                 if(strcmp(param->u.crypt.alg, "WEP") == 0)
8533                                 {
8534                                         DBG_871X("%s, set pairwise key, WEP\n", __FUNCTION__);
8535                                         
8536                                         psta->dot118021XPrivacy = _WEP40_;
8537                                         if(param->u.crypt.key_len==13)
8538                                         {                                               
8539                                                 psta->dot118021XPrivacy = _WEP104_;
8540                                         }
8541                                 }
8542                                 else if(strcmp(param->u.crypt.alg, "TKIP") == 0)
8543                                 {                                               
8544                                         DBG_871X("%s, set pairwise key, TKIP\n", __FUNCTION__);
8545                                         
8546                                         psta->dot118021XPrivacy = _TKIP_;
8547                                 
8548                                         //DEBUG_ERR("set key length :param->u.crypt.key_len=%d\n", param->u.crypt.key_len);
8549                                         //set mic key
8550                                         _rtw_memcpy(psta->dot11tkiptxmickey.skey, &(param->u.crypt.key[16]), 8);
8551                                         _rtw_memcpy(psta->dot11tkiprxmickey.skey, &(param->u.crypt.key[24]), 8);
8552
8553                                         psecuritypriv->busetkipkey = _TRUE;
8554                                                                                         
8555                                 }
8556                                 else if(strcmp(param->u.crypt.alg, "CCMP") == 0)
8557                                 {
8558
8559                                         DBG_871X("%s, set pairwise key, CCMP\n", __FUNCTION__);
8560                                         
8561                                         psta->dot118021XPrivacy = _AES_;
8562                                 }
8563                                 else
8564                                 {
8565                                         DBG_871X("%s, set pairwise key, none\n", __FUNCTION__);
8566                                         
8567                                         psta->dot118021XPrivacy = _NO_PRIVACY_;
8568                                 }
8569                                                 
8570                                 rtw_ap_set_pairwise_key(padapter, psta);
8571                                         
8572                                 psta->ieee8021x_blocked = _FALSE;
8573                                         
8574                         }                       
8575                         else//group key???
8576                         { 
8577                                 if(strcmp(param->u.crypt.alg, "WEP") == 0)
8578                                 {
8579                                         _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
8580                                         
8581                                         psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
8582                                         if(param->u.crypt.key_len==13)
8583                                         {                                               
8584                                                 psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
8585                                         }
8586                                 }
8587                                 else if(strcmp(param->u.crypt.alg, "TKIP") == 0)
8588                                 {                                               
8589                                         psecuritypriv->dot118021XGrpPrivacy = _TKIP_;
8590
8591                                         _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
8592                                 
8593                                         //DEBUG_ERR("set key length :param->u.crypt.key_len=%d\n", param->u.crypt.key_len);
8594                                         //set mic key
8595                                         _rtw_memcpy(psecuritypriv->dot118021XGrptxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[16]), 8);
8596                                         _rtw_memcpy(psecuritypriv->dot118021XGrprxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[24]), 8);
8597
8598                                         psecuritypriv->busetkipkey = _TRUE;
8599                                                                                         
8600                                 }
8601                                 else if(strcmp(param->u.crypt.alg, "CCMP") == 0)
8602                                 {
8603                                         psecuritypriv->dot118021XGrpPrivacy = _AES_;
8604
8605                                         _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
8606                                 }
8607                                 else
8608                                 {
8609                                         psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
8610                                 }
8611
8612                                 psecuritypriv->dot118021XGrpKeyid = param->u.crypt.idx;
8613
8614                                 psecuritypriv->binstallGrpkey = _TRUE;  
8615                                                                 
8616                                 psecuritypriv->dot11PrivacyAlgrthm = psecuritypriv->dot118021XGrpPrivacy;//!!!
8617                                                                 
8618                                 rtw_ap_set_group_key(padapter, param->u.crypt.key, psecuritypriv->dot118021XGrpPrivacy, param->u.crypt.idx);
8619                         
8620                                 pbcmc_sta=rtw_get_bcmc_stainfo(padapter);
8621                                 if(pbcmc_sta)
8622                                 {
8623                                         pbcmc_sta->ieee8021x_blocked = _FALSE;
8624                                         pbcmc_sta->dot118021XPrivacy= psecuritypriv->dot118021XGrpPrivacy;//rx will use bmc_sta's dot118021XPrivacy                     
8625                                 }                                       
8626
8627                         }
8628                         
8629                 }
8630                                 
8631         }
8632
8633 exit:
8634
8635         if(pwep)
8636         {
8637                 rtw_mfree((u8 *)pwep, wep_total_len);           
8638         }       
8639         
8640         return ret;
8641         
8642 }
8643
8644 static int rtw_set_beacon(struct net_device *dev, struct ieee_param *param, int len)
8645 {
8646         int ret=0;      
8647         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8648         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8649         struct sta_priv *pstapriv = &padapter->stapriv;
8650         unsigned char *pbuf = param->u.bcn_ie.buf;
8651
8652
8653         DBG_871X("%s, len=%d\n", __FUNCTION__, len);
8654
8655         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
8656                 return -EINVAL;
8657
8658         _rtw_memcpy(&pstapriv->max_num_sta, param->u.bcn_ie.reserved, 2);
8659
8660         if((pstapriv->max_num_sta>NUM_STA) || (pstapriv->max_num_sta<=0))
8661                 pstapriv->max_num_sta = NUM_STA;
8662
8663
8664         if(rtw_check_beacon_data(padapter, pbuf,  (len-12-2)) == _SUCCESS)// 12 = param header, 2:no packed
8665                 ret = 0;
8666         else
8667                 ret = -EINVAL;
8668         
8669
8670         return ret;
8671         
8672 }
8673
8674 static int rtw_hostapd_sta_flush(struct net_device *dev)
8675 {
8676         //_irqL irqL;
8677         //_list *phead, *plist;
8678         int ret=0;      
8679         //struct sta_info *psta = NULL;
8680         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
8681         //struct sta_priv *pstapriv = &padapter->stapriv;
8682
8683         DBG_871X("%s\n", __FUNCTION__);
8684
8685         flush_all_cam_entry(padapter);  //clear CAM
8686
8687         ret = rtw_sta_flush(padapter);  
8688
8689         return ret;
8690
8691 }
8692
8693 static int rtw_add_sta(struct net_device *dev, struct ieee_param *param)
8694 {
8695         _irqL irqL;
8696         int ret=0;      
8697         struct sta_info *psta = NULL;
8698         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8699         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8700         struct sta_priv *pstapriv = &padapter->stapriv;
8701
8702         DBG_871X("rtw_add_sta(aid=%d)=" MAC_FMT "\n", param->u.add_sta.aid, MAC_ARG(param->sta_addr));
8703         
8704         if(check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != _TRUE)       
8705         {
8706                 return -EINVAL;         
8707         }
8708
8709         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
8710             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
8711             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
8712         {
8713                 return -EINVAL; 
8714         }
8715
8716 /*
8717         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
8718         if(psta)
8719         {
8720                 DBG_871X("rtw_add_sta(), free has been added psta=%p\n", psta);
8721                 //_enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);                
8722                 rtw_free_stainfo(padapter,  psta);              
8723                 //_exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
8724
8725                 psta = NULL;
8726         }       
8727 */
8728         //psta = rtw_alloc_stainfo(pstapriv, param->sta_addr);
8729         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
8730         if(psta)
8731         {
8732                 int flags = param->u.add_sta.flags;                     
8733                 
8734                 //DBG_871X("rtw_add_sta(), init sta's variables, psta=%p\n", psta);
8735                 
8736                 psta->aid = param->u.add_sta.aid;//aid=1~2007
8737
8738                 _rtw_memcpy(psta->bssrateset, param->u.add_sta.tx_supp_rates, 16);
8739                 
8740                 
8741                 //check wmm cap.
8742                 if(WLAN_STA_WME&flags)
8743                         psta->qos_option = 1;
8744                 else
8745                         psta->qos_option = 0;
8746
8747                 if(pmlmepriv->qospriv.qos_option == 0)  
8748                         psta->qos_option = 0;
8749
8750                 
8751 #ifdef CONFIG_80211N_HT         
8752                 //chec 802.11n ht cap.
8753                 if(WLAN_STA_HT&flags)
8754                 {
8755                         psta->htpriv.ht_option = _TRUE;
8756                         psta->qos_option = 1;
8757                         _rtw_memcpy((void*)&psta->htpriv.ht_cap, (void*)&param->u.add_sta.ht_cap, sizeof(struct rtw_ieee80211_ht_cap));
8758                 }
8759                 else            
8760                 {
8761                         psta->htpriv.ht_option = _FALSE;
8762                 }
8763                 
8764                 if(pmlmepriv->htpriv.ht_option == _FALSE)       
8765                         psta->htpriv.ht_option = _FALSE;
8766 #endif          
8767
8768
8769                 update_sta_info_apmode(padapter, psta);
8770                 
8771                 
8772         }
8773         else
8774         {
8775                 ret = -ENOMEM;
8776         }       
8777         
8778         return ret;
8779         
8780 }
8781
8782 static int rtw_del_sta(struct net_device *dev, struct ieee_param *param)
8783 {
8784         _irqL irqL;
8785         int ret=0;      
8786         struct sta_info *psta = NULL;
8787         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8788         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8789         struct sta_priv *pstapriv = &padapter->stapriv;
8790
8791         DBG_871X("rtw_del_sta=" MAC_FMT "\n", MAC_ARG(param->sta_addr));
8792                 
8793         if(check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != _TRUE)               
8794         {
8795                 return -EINVAL;         
8796         }
8797
8798         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
8799             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
8800             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
8801         {
8802                 return -EINVAL; 
8803         }
8804
8805         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
8806         if(psta)
8807         {
8808                 u8 updated=_FALSE;
8809         
8810                 //DBG_871X("free psta=%p, aid=%d\n", psta, psta->aid);
8811
8812                 _enter_critical_bh(&pstapriv->asoc_list_lock, &irqL);
8813                 if(rtw_is_list_empty(&psta->asoc_list)==_FALSE)
8814                 {                       
8815                         rtw_list_delete(&psta->asoc_list);
8816                         pstapriv->asoc_list_cnt--;
8817                         updated = ap_free_sta(padapter, psta, _TRUE, WLAN_REASON_DEAUTH_LEAVING);
8818
8819                 }
8820                 _exit_critical_bh(&pstapriv->asoc_list_lock, &irqL);
8821                 
8822                 associated_clients_update(padapter, updated);
8823         
8824                 psta = NULL;
8825                 
8826         }
8827         else
8828         {
8829                 DBG_871X("rtw_del_sta(), sta has already been removed or never been added\n");
8830                 
8831                 //ret = -1;
8832         }
8833         
8834         
8835         return ret;
8836         
8837 }
8838
8839 static int rtw_ioctl_get_sta_data(struct net_device *dev, struct ieee_param *param, int len)
8840 {
8841         int ret=0;      
8842         struct sta_info *psta = NULL;
8843         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8844         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8845         struct sta_priv *pstapriv = &padapter->stapriv;
8846         struct ieee_param_ex *param_ex = (struct ieee_param_ex *)param;
8847         struct sta_data *psta_data = (struct sta_data *)param_ex->data;
8848
8849         DBG_871X("rtw_ioctl_get_sta_info, sta_addr: " MAC_FMT "\n", MAC_ARG(param_ex->sta_addr));
8850
8851         if(check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != _TRUE)               
8852         {
8853                 return -EINVAL;         
8854         }
8855
8856         if (param_ex->sta_addr[0] == 0xff && param_ex->sta_addr[1] == 0xff &&
8857             param_ex->sta_addr[2] == 0xff && param_ex->sta_addr[3] == 0xff &&
8858             param_ex->sta_addr[4] == 0xff && param_ex->sta_addr[5] == 0xff) 
8859         {
8860                 return -EINVAL; 
8861         }
8862
8863         psta = rtw_get_stainfo(pstapriv, param_ex->sta_addr);
8864         if(psta)
8865         {
8866 #if 0
8867                 struct {
8868                         u16 aid;
8869                         u16 capability;
8870                         int flags;
8871                         u32 sta_set;
8872                         u8 tx_supp_rates[16];   
8873                         u32 tx_supp_rates_len;
8874                         struct rtw_ieee80211_ht_cap ht_cap;
8875                         u64     rx_pkts;
8876                         u64     rx_bytes;
8877                         u64     rx_drops;
8878                         u64     tx_pkts;
8879                         u64     tx_bytes;
8880                         u64     tx_drops;
8881                 } get_sta;              
8882 #endif
8883                 psta_data->aid = (u16)psta->aid;
8884                 psta_data->capability = psta->capability;
8885                 psta_data->flags = psta->flags;
8886
8887 /*
8888                 nonerp_set : BIT(0)
8889                 no_short_slot_time_set : BIT(1)
8890                 no_short_preamble_set : BIT(2)
8891                 no_ht_gf_set : BIT(3)
8892                 no_ht_set : BIT(4)
8893                 ht_20mhz_set : BIT(5)
8894 */
8895
8896                 psta_data->sta_set =((psta->nonerp_set) |
8897                                                         (psta->no_short_slot_time_set <<1) |
8898                                                         (psta->no_short_preamble_set <<2) |
8899                                                         (psta->no_ht_gf_set <<3) |
8900                                                         (psta->no_ht_set <<4) |
8901                                                         (psta->ht_20mhz_set <<5));
8902
8903                 psta_data->tx_supp_rates_len =  psta->bssratelen;
8904                 _rtw_memcpy(psta_data->tx_supp_rates, psta->bssrateset, psta->bssratelen);
8905 #ifdef CONFIG_80211N_HT
8906                 _rtw_memcpy(&psta_data->ht_cap, &psta->htpriv.ht_cap, sizeof(struct rtw_ieee80211_ht_cap));
8907 #endif //CONFIG_80211N_HT
8908                 psta_data->rx_pkts = psta->sta_stats.rx_data_pkts;
8909                 psta_data->rx_bytes = psta->sta_stats.rx_bytes;
8910                 psta_data->rx_drops = psta->sta_stats.rx_drops;
8911
8912                 psta_data->tx_pkts = psta->sta_stats.tx_pkts;
8913                 psta_data->tx_bytes = psta->sta_stats.tx_bytes;
8914                 psta_data->tx_drops = psta->sta_stats.tx_drops;
8915                 
8916
8917         }
8918         else
8919         {
8920                 ret = -1;
8921         }
8922
8923         return ret;
8924
8925 }
8926
8927 static int rtw_get_sta_wpaie(struct net_device *dev, struct ieee_param *param)
8928 {
8929         int ret=0;      
8930         struct sta_info *psta = NULL;
8931         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8932         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8933         struct sta_priv *pstapriv = &padapter->stapriv;
8934
8935         DBG_871X("rtw_get_sta_wpaie, sta_addr: " MAC_FMT "\n", MAC_ARG(param->sta_addr));
8936
8937         if(check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != _TRUE)               
8938         {
8939                 return -EINVAL;         
8940         }
8941
8942         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
8943             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
8944             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
8945         {
8946                 return -EINVAL; 
8947         }
8948
8949         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
8950         if(psta)
8951         {
8952                 if((psta->wpa_ie[0] == WLAN_EID_RSN) || (psta->wpa_ie[0] == WLAN_EID_GENERIC))
8953                 {
8954                         int wpa_ie_len;
8955                         int copy_len;
8956
8957                         wpa_ie_len = psta->wpa_ie[1];
8958                         
8959                         copy_len = ((wpa_ie_len+2) > sizeof(psta->wpa_ie)) ? (sizeof(psta->wpa_ie)):(wpa_ie_len+2);
8960                                 
8961                         param->u.wpa_ie.len = copy_len;
8962
8963                         _rtw_memcpy(param->u.wpa_ie.reserved, psta->wpa_ie, copy_len);
8964                 }
8965                 else
8966                 {
8967                         //ret = -1;
8968                         DBG_871X("sta's wpa_ie is NONE\n");
8969                 }               
8970         }
8971         else
8972         {
8973                 ret = -1;
8974         }
8975
8976         return ret;
8977
8978 }
8979
8980 static int rtw_set_wps_beacon(struct net_device *dev, struct ieee_param *param, int len)
8981 {
8982         int ret=0;
8983         unsigned char wps_oui[4]={0x0,0x50,0xf2,0x04};
8984         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
8985         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8986         struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);
8987         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
8988         int ie_len;
8989
8990         DBG_871X("%s, len=%d\n", __FUNCTION__, len);
8991
8992         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
8993                 return -EINVAL;
8994
8995         ie_len = len-12-2;// 12 = param header, 2:no packed
8996
8997
8998         if(pmlmepriv->wps_beacon_ie)
8999         {
9000                 rtw_mfree(pmlmepriv->wps_beacon_ie, pmlmepriv->wps_beacon_ie_len);
9001                 pmlmepriv->wps_beacon_ie = NULL;                        
9002         }       
9003
9004         if(ie_len>0)
9005         {
9006                 pmlmepriv->wps_beacon_ie = rtw_malloc(ie_len);
9007                 pmlmepriv->wps_beacon_ie_len = ie_len;
9008                 if ( pmlmepriv->wps_beacon_ie == NULL) {
9009                         DBG_871X("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
9010                         return -EINVAL;
9011                 }
9012
9013                 _rtw_memcpy(pmlmepriv->wps_beacon_ie, param->u.bcn_ie.buf, ie_len);
9014
9015                 update_beacon(padapter, _VENDOR_SPECIFIC_IE_, wps_oui, _TRUE);
9016                 
9017                 pmlmeext->bstart_bss = _TRUE;
9018                 
9019         }
9020         
9021         
9022         return ret;             
9023
9024 }
9025
9026 static int rtw_set_wps_probe_resp(struct net_device *dev, struct ieee_param *param, int len)
9027 {
9028         int ret=0;
9029         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
9030         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
9031         int ie_len;
9032
9033         DBG_871X("%s, len=%d\n", __FUNCTION__, len);
9034
9035         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
9036                 return -EINVAL;
9037
9038         ie_len = len-12-2;// 12 = param header, 2:no packed
9039
9040
9041         if(pmlmepriv->wps_probe_resp_ie)
9042         {
9043                 rtw_mfree(pmlmepriv->wps_probe_resp_ie, pmlmepriv->wps_probe_resp_ie_len);
9044                 pmlmepriv->wps_probe_resp_ie = NULL;                    
9045         }       
9046
9047         if(ie_len>0)
9048         {
9049                 pmlmepriv->wps_probe_resp_ie = rtw_malloc(ie_len);
9050                 pmlmepriv->wps_probe_resp_ie_len = ie_len;
9051                 if ( pmlmepriv->wps_probe_resp_ie == NULL) {
9052                         DBG_871X("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
9053                         return -EINVAL;
9054                 }
9055                 _rtw_memcpy(pmlmepriv->wps_probe_resp_ie, param->u.bcn_ie.buf, ie_len);         
9056         }
9057         
9058         
9059         return ret;
9060
9061 }
9062
9063 static int rtw_set_wps_assoc_resp(struct net_device *dev, struct ieee_param *param, int len)
9064 {
9065         int ret=0;
9066         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
9067         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
9068         int ie_len;
9069
9070         DBG_871X("%s, len=%d\n", __FUNCTION__, len);
9071
9072         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
9073                 return -EINVAL;
9074
9075         ie_len = len-12-2;// 12 = param header, 2:no packed
9076
9077
9078         if(pmlmepriv->wps_assoc_resp_ie)
9079         {
9080                 rtw_mfree(pmlmepriv->wps_assoc_resp_ie, pmlmepriv->wps_assoc_resp_ie_len);
9081                 pmlmepriv->wps_assoc_resp_ie = NULL;                    
9082         }       
9083
9084         if(ie_len>0)
9085         {
9086                 pmlmepriv->wps_assoc_resp_ie = rtw_malloc(ie_len);
9087                 pmlmepriv->wps_assoc_resp_ie_len = ie_len;
9088                 if ( pmlmepriv->wps_assoc_resp_ie == NULL) {
9089                         DBG_871X("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
9090                         return -EINVAL;
9091                 }
9092                 
9093                 _rtw_memcpy(pmlmepriv->wps_assoc_resp_ie, param->u.bcn_ie.buf, ie_len);         
9094         }
9095         
9096         
9097         return ret;
9098
9099 }
9100
9101 static int rtw_set_hidden_ssid(struct net_device *dev, struct ieee_param *param, int len)
9102 {
9103         int ret=0;
9104         _adapter *adapter = (_adapter *)rtw_netdev_priv(dev);
9105         struct mlme_priv *mlmepriv = &(adapter->mlmepriv);
9106         struct mlme_ext_priv    *mlmeext = &(adapter->mlmeextpriv);
9107         struct mlme_ext_info    *mlmeinfo = &(mlmeext->mlmext_info);
9108         int ie_len;
9109         u8 *ssid_ie;
9110         char ssid[NDIS_802_11_LENGTH_SSID + 1];
9111         sint ssid_len;
9112         u8 ignore_broadcast_ssid;
9113
9114         if(check_fwstate(mlmepriv, WIFI_AP_STATE) != _TRUE)
9115                 return -EPERM;
9116
9117         if (param->u.bcn_ie.reserved[0] != 0xea)
9118                 return -EINVAL;
9119
9120         mlmeinfo->hidden_ssid_mode = ignore_broadcast_ssid = param->u.bcn_ie.reserved[1];
9121
9122         ie_len = len-12-2;// 12 = param header, 2:no packed
9123         ssid_ie = rtw_get_ie(param->u.bcn_ie.buf,  WLAN_EID_SSID, &ssid_len, ie_len);
9124
9125         if (ssid_ie && ssid_len > 0 && ssid_len <= NDIS_802_11_LENGTH_SSID) {
9126                 WLAN_BSSID_EX *pbss_network = &mlmepriv->cur_network.network;
9127                 WLAN_BSSID_EX *pbss_network_ext = &mlmeinfo->network;
9128
9129                 _rtw_memcpy(ssid, ssid_ie+2, ssid_len);
9130                 ssid[ssid_len] = 0x0;
9131
9132                 if(0)
9133                 DBG_871X(FUNC_ADPT_FMT" ssid:(%s,%d), from ie:(%s,%d), (%s,%d)\n", FUNC_ADPT_ARG(adapter),
9134                         ssid, ssid_len,
9135                         pbss_network->Ssid.Ssid, pbss_network->Ssid.SsidLength,
9136                         pbss_network_ext->Ssid.Ssid, pbss_network_ext->Ssid.SsidLength);
9137
9138                 _rtw_memcpy(pbss_network->Ssid.Ssid, (void *)ssid, ssid_len);
9139                 pbss_network->Ssid.SsidLength = ssid_len;
9140                 _rtw_memcpy(pbss_network_ext->Ssid.Ssid, (void *)ssid, ssid_len);
9141                 pbss_network_ext->Ssid.SsidLength = ssid_len;
9142
9143                 if(0)
9144                 DBG_871X(FUNC_ADPT_FMT" after ssid:(%s,%d), (%s,%d)\n", FUNC_ADPT_ARG(adapter),
9145                         pbss_network->Ssid.Ssid, pbss_network->Ssid.SsidLength,
9146                         pbss_network_ext->Ssid.Ssid, pbss_network_ext->Ssid.SsidLength);
9147         }
9148
9149         DBG_871X(FUNC_ADPT_FMT" ignore_broadcast_ssid:%d, %s,%d\n", FUNC_ADPT_ARG(adapter),
9150                 ignore_broadcast_ssid, ssid, ssid_len);
9151
9152         return ret;
9153 }
9154
9155 static int rtw_ioctl_acl_remove_sta(struct net_device *dev, struct ieee_param *param, int len)
9156 {
9157         int ret=0;
9158         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
9159         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
9160
9161         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
9162                 return -EINVAL;
9163
9164         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
9165             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
9166             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
9167         {
9168                 return -EINVAL; 
9169         }
9170
9171         ret = rtw_acl_remove_sta(padapter, param->sta_addr);    
9172
9173         return ret;             
9174
9175 }
9176
9177 static int rtw_ioctl_acl_add_sta(struct net_device *dev, struct ieee_param *param, int len)
9178 {
9179         int ret=0;
9180         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
9181         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
9182         
9183         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
9184                 return -EINVAL;
9185
9186         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
9187             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
9188             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
9189         {
9190                 return -EINVAL; 
9191         }
9192
9193         ret = rtw_acl_add_sta(padapter, param->sta_addr);       
9194
9195         return ret;             
9196
9197 }
9198
9199 static int rtw_ioctl_set_macaddr_acl(struct net_device *dev, struct ieee_param *param, int len)
9200 {
9201         int ret=0;
9202         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
9203         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
9204         
9205         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
9206                 return -EINVAL; 
9207         
9208         rtw_set_macaddr_acl(padapter, param->u.mlme.command);   
9209
9210         return ret;
9211 }
9212
9213 static int rtw_hostapd_ioctl(struct net_device *dev, struct iw_point *p)
9214 {
9215         struct ieee_param *param;
9216         int ret=0;
9217         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
9218
9219         //DBG_871X("%s\n", __FUNCTION__);
9220
9221         /*
9222         * this function is expect to call in master mode, which allows no power saving
9223         * so, we just check hw_init_completed
9224         */
9225
9226         if (padapter->hw_init_completed==_FALSE){
9227                 ret = -EPERM;
9228                 goto out;
9229         }
9230
9231
9232         //if (p->length < sizeof(struct ieee_param) || !p->pointer){
9233         if(!p->pointer){
9234                 ret = -EINVAL;
9235                 goto out;
9236         }
9237         
9238         param = (struct ieee_param *)rtw_malloc(p->length);
9239         if (param == NULL)
9240         {
9241                 ret = -ENOMEM;
9242                 goto out;
9243         }
9244         
9245         if (copy_from_user(param, p->pointer, p->length))
9246         {
9247                 rtw_mfree((u8*)param, p->length);
9248                 ret = -EFAULT;
9249                 goto out;
9250         }
9251
9252         //DBG_871X("%s, cmd=%d\n", __FUNCTION__, param->cmd);
9253
9254         switch (param->cmd) 
9255         {       
9256                 case RTL871X_HOSTAPD_FLUSH:
9257
9258                         ret = rtw_hostapd_sta_flush(dev);
9259
9260                         break;
9261         
9262                 case RTL871X_HOSTAPD_ADD_STA:   
9263                         
9264                         ret = rtw_add_sta(dev, param);                                  
9265                         
9266                         break;
9267
9268                 case RTL871X_HOSTAPD_REMOVE_STA:
9269
9270                         ret = rtw_del_sta(dev, param);
9271
9272                         break;
9273         
9274                 case RTL871X_HOSTAPD_SET_BEACON:
9275
9276                         ret = rtw_set_beacon(dev, param, p->length);
9277
9278                         break;
9279                         
9280                 case RTL871X_SET_ENCRYPTION:
9281
9282                         ret = rtw_set_encryption(dev, param, p->length);
9283                         
9284                         break;
9285                         
9286                 case RTL871X_HOSTAPD_GET_WPAIE_STA:
9287
9288                         ret = rtw_get_sta_wpaie(dev, param);
9289         
9290                         break;
9291                         
9292                 case RTL871X_HOSTAPD_SET_WPS_BEACON:
9293
9294                         ret = rtw_set_wps_beacon(dev, param, p->length);
9295
9296                         break;
9297
9298                 case RTL871X_HOSTAPD_SET_WPS_PROBE_RESP:
9299
9300                         ret = rtw_set_wps_probe_resp(dev, param, p->length);
9301                         
9302                         break;
9303                         
9304                 case RTL871X_HOSTAPD_SET_WPS_ASSOC_RESP:
9305
9306                         ret = rtw_set_wps_assoc_resp(dev, param, p->length);
9307                         
9308                         break;
9309
9310                 case RTL871X_HOSTAPD_SET_HIDDEN_SSID:
9311
9312                         ret = rtw_set_hidden_ssid(dev, param, p->length);
9313
9314                         break;
9315
9316                 case RTL871X_HOSTAPD_GET_INFO_STA:
9317
9318                         ret = rtw_ioctl_get_sta_data(dev, param, p->length);
9319
9320                         break;
9321                         
9322                 case RTL871X_HOSTAPD_SET_MACADDR_ACL:
9323
9324                         ret = rtw_ioctl_set_macaddr_acl(dev, param, p->length);
9325
9326                         break;
9327
9328                 case RTL871X_HOSTAPD_ACL_ADD_STA:
9329
9330                         ret = rtw_ioctl_acl_add_sta(dev, param, p->length);
9331
9332                         break;
9333
9334                 case RTL871X_HOSTAPD_ACL_REMOVE_STA:
9335
9336                         ret = rtw_ioctl_acl_remove_sta(dev, param, p->length);
9337
9338                         break;
9339                         
9340                 default:
9341                         DBG_871X("Unknown hostapd request: %d\n", param->cmd);
9342                         ret = -EOPNOTSUPP;
9343                         break;
9344                 
9345         }
9346
9347         if (ret == 0 && copy_to_user(p->pointer, param, p->length))
9348                 ret = -EFAULT;
9349
9350
9351         rtw_mfree((u8 *)param, p->length);
9352         
9353 out:
9354                 
9355         return ret;
9356         
9357 }
9358 #endif
9359
9360 static int rtw_wx_set_priv(struct net_device *dev,
9361                                 struct iw_request_info *info,
9362                                 union iwreq_data *awrq,
9363                                 char *extra)
9364 {
9365
9366 #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
9367         char *ext_dbg;
9368 #endif
9369
9370         int ret = 0;
9371         int len = 0;
9372         char *ext;
9373         int i;
9374
9375         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
9376         struct iw_point *dwrq = (struct iw_point*)awrq;
9377
9378         //RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_notice_, ("+rtw_wx_set_priv\n"));
9379         if(dwrq->length == 0)
9380                 return -EFAULT;
9381         
9382         len = dwrq->length;
9383         if (!(ext = rtw_vmalloc(len)))
9384                 return -ENOMEM;
9385
9386         if (copy_from_user(ext, dwrq->pointer, len)) {
9387                 rtw_vmfree(ext, len);
9388                 return -EFAULT;
9389         }
9390
9391
9392         //RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_notice_,
9393         //       ("rtw_wx_set_priv: %s req=%s\n",
9394         //        dev->name, ext));
9395
9396         #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV     
9397         if (!(ext_dbg = rtw_vmalloc(len)))
9398         {
9399                 rtw_vmfree(ext, len);
9400                 return -ENOMEM;
9401         }       
9402         
9403         _rtw_memcpy(ext_dbg, ext, len);
9404         #endif
9405
9406         //added for wps2.0 @20110524
9407         if(dwrq->flags == 0x8766 && len > 8)
9408         {
9409                 u32 cp_sz;              
9410                 struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
9411                 u8 *probereq_wpsie = ext;
9412                 int probereq_wpsie_len = len;
9413                 u8 wps_oui[4]={0x0,0x50,0xf2,0x04};             
9414         
9415                 if((_VENDOR_SPECIFIC_IE_ == probereq_wpsie[0]) &&
9416                         (_rtw_memcmp(&probereq_wpsie[2], wps_oui, 4) ==_TRUE))
9417                 {
9418                         cp_sz = probereq_wpsie_len>MAX_WPS_IE_LEN ? MAX_WPS_IE_LEN:probereq_wpsie_len;
9419
9420                         if(pmlmepriv->wps_probe_req_ie)
9421                         {
9422                                 u32 free_len = pmlmepriv->wps_probe_req_ie_len;
9423                                 pmlmepriv->wps_probe_req_ie_len = 0;
9424                                 rtw_mfree(pmlmepriv->wps_probe_req_ie, free_len);
9425                                 pmlmepriv->wps_probe_req_ie = NULL;                     
9426                         }       
9427
9428                         pmlmepriv->wps_probe_req_ie = rtw_malloc(cp_sz);
9429                         if ( pmlmepriv->wps_probe_req_ie == NULL) {
9430                                 printk("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
9431                                 ret =  -EINVAL;
9432                                 goto FREE_EXT;
9433                         
9434                         }
9435                         
9436                         _rtw_memcpy(pmlmepriv->wps_probe_req_ie, probereq_wpsie, cp_sz);
9437                         pmlmepriv->wps_probe_req_ie_len = cp_sz;                                        
9438                         
9439                 }       
9440                 
9441                 goto FREE_EXT;
9442                 
9443         }
9444
9445         if(     len >= WEXT_CSCAN_HEADER_SIZE
9446                 && _rtw_memcmp(ext, WEXT_CSCAN_HEADER, WEXT_CSCAN_HEADER_SIZE) == _TRUE
9447         ){
9448                 ret = rtw_wx_set_scan(dev, info, awrq, ext);
9449                 goto FREE_EXT;
9450         }
9451         
9452 #ifdef CONFIG_ANDROID
9453         //DBG_871X("rtw_wx_set_priv: %s req=%s\n", dev->name, ext);
9454
9455         i = rtw_android_cmdstr_to_num(ext);
9456
9457         switch(i) {
9458                 case ANDROID_WIFI_CMD_START :
9459                         indicate_wx_custom_event(padapter, "START");
9460                         break;
9461                 case ANDROID_WIFI_CMD_STOP :
9462                         indicate_wx_custom_event(padapter, "STOP");
9463                         break;
9464                 case ANDROID_WIFI_CMD_RSSI :
9465                         {
9466                                 struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);     
9467                                 struct  wlan_network    *pcur_network = &pmlmepriv->cur_network;
9468
9469                                 if(check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE) {
9470                                         sprintf(ext, "%s rssi %d", pcur_network->network.Ssid.Ssid, padapter->recvpriv.rssi);
9471                                 } else {
9472                                         sprintf(ext, "OK");
9473                                 }
9474                         }
9475                         break;
9476                 case ANDROID_WIFI_CMD_LINKSPEED :
9477                         {
9478                                 u16 mbps = rtw_get_cur_max_rate(padapter)/10;
9479                                 sprintf(ext, "LINKSPEED %d", mbps);
9480                         }
9481                         break;
9482                 case ANDROID_WIFI_CMD_MACADDR :
9483                         sprintf(ext, "MACADDR = " MAC_FMT, MAC_ARG(dev->dev_addr));
9484                         break;
9485                 case ANDROID_WIFI_CMD_SCAN_ACTIVE :
9486                         {
9487                                 //rtw_set_scan_mode(padapter, SCAN_ACTIVE);
9488                                 sprintf(ext, "OK");
9489                         }
9490                         break;
9491                 case ANDROID_WIFI_CMD_SCAN_PASSIVE :
9492                         {
9493                                 //rtw_set_scan_mode(padapter, SCAN_PASSIVE);
9494                                 sprintf(ext, "OK");
9495                         }
9496                         break;
9497
9498                 case ANDROID_WIFI_CMD_COUNTRY :
9499                         {
9500                                 char country_code[10];
9501                                 sscanf(ext, "%*s %s", country_code);
9502                                 rtw_set_country(padapter, country_code);
9503                                 sprintf(ext, "OK");
9504                         }
9505                         break;
9506                 default :
9507                         #ifdef  CONFIG_DEBUG_RTW_WX_SET_PRIV
9508                         DBG_871X("%s: %s unknowned req=%s\n", __FUNCTION__,
9509                                 dev->name, ext_dbg);
9510                         #endif
9511
9512                         sprintf(ext, "OK");
9513                 
9514         }
9515
9516         if (copy_to_user(dwrq->pointer, ext, min(dwrq->length, (u16)(strlen(ext)+1)) ) )
9517                 ret = -EFAULT;
9518
9519         #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
9520         DBG_871X("%s: %s req=%s rep=%s dwrq->length=%d, strlen(ext)+1=%d\n", __FUNCTION__,
9521                 dev->name, ext_dbg ,ext, dwrq->length, (u16)(strlen(ext)+1));
9522         #endif
9523 #endif //end of CONFIG_ANDROID
9524
9525
9526 FREE_EXT:
9527
9528         rtw_vmfree(ext, len);
9529         #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
9530         rtw_vmfree(ext_dbg, len);
9531         #endif
9532
9533         //DBG_871X("rtw_wx_set_priv: (SIOCSIWPRIV) %s ret=%d\n", 
9534         //              dev->name, ret);
9535
9536         return ret;
9537         
9538 }
9539 #ifdef CONFIG_WOWLAN
9540 static int rtw_wowlan_ctrl(struct net_device *dev,
9541                                                 struct iw_request_info *info,
9542                                                 union iwreq_data *wrqu, char *extra)
9543 {
9544         _adapter *padapter =  (_adapter *)rtw_netdev_priv(dev);
9545         struct wowlan_ioctl_param poidparam;
9546         struct pwrctrl_priv *pwrctrlpriv = adapter_to_pwrctl(padapter);
9547         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
9548         struct net_device *pnetdev = padapter->pnetdev;
9549 #ifdef CONFIG_CONCURRENT_MODE
9550         struct net_device *pbuddy_netdev = padapter->pbuddy_adapter->pnetdev;   
9551 #endif
9552         struct sta_info *psta = NULL;
9553         int ret = 0;
9554         u32 start_time = rtw_get_current_time();
9555         poidparam.subcode = 0;
9556
9557         DBG_871X("+rtw_wowlan_ctrl: %s\n", extra);
9558         
9559         if(pwrctrlpriv->bSupportRemoteWakeup==_FALSE){
9560                 ret = -EPERM;
9561                 DBG_871X("+rtw_wowlan_ctrl: Device didn't support the remote wakeup!!\n");
9562                 goto _rtw_wowlan_ctrl_exit_free;
9563         }
9564
9565         if (!check_fwstate(pmlmepriv, _FW_LINKED) && 
9566                         check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
9567 #ifdef CONFIG_PNO_SUPPORT
9568                         pwrctrlpriv->wowlan_pno_enable = _TRUE;
9569 #else
9570                         DBG_871X("[%s] WARNING: Please Connect With AP First!!\n", __func__);
9571                         goto _rtw_wowlan_ctrl_exit_free;
9572 #endif //CONFIG_PNO_SUPPORT
9573         }
9574
9575         if (_rtw_memcmp( extra, "enable", 6 )) {
9576
9577                 padapter->registrypriv.mp_mode = 1;
9578
9579                 pwrctrlpriv->wowlan_from_cmd = _TRUE;
9580
9581                 rtw_suspend_common(padapter);
9582
9583         } else if (_rtw_memcmp( extra, "disable", 6 )) {
9584
9585                 rtw_resume_common(padapter);
9586
9587                 pwrctrlpriv->wowlan_from_cmd = _FALSE;
9588
9589 #ifdef CONFIG_PNO_SUPPORT
9590                 pwrctrlpriv->wowlan_pno_enable = _FALSE;
9591 #endif //CONFIG_PNO_SUPPORT
9592
9593                 padapter->registrypriv.mp_mode = 0;
9594         } else {
9595                 DBG_871X("[%s] Invalid Parameter.\n", __func__);
9596                 goto _rtw_wowlan_ctrl_exit_free;
9597         }
9598         //mutex_lock(&ioctl_mutex);
9599 _rtw_wowlan_ctrl_exit_free:
9600         DBG_871X("-rtw_wowlan_ctrl( subcode = %d)\n", poidparam.subcode);
9601         DBG_871X_LEVEL(_drv_always_, "%s in %d ms\n", __func__,
9602                         rtw_get_passing_time_ms(start_time));
9603 _rtw_wowlan_ctrl_exit:
9604         return ret;
9605 }
9606 #endif //CONFIG_WOWLAN
9607
9608 #ifdef CONFIG_AP_WOWLAN
9609 static int rtw_ap_wowlan_ctrl(struct net_device *dev,
9610                                                 struct iw_request_info *info,
9611                                                 union iwreq_data *wrqu, char *extra)
9612 {
9613         _adapter *padapter =  (_adapter *)rtw_netdev_priv(dev);
9614         struct wowlan_ioctl_param poidparam;
9615         struct pwrctrl_priv *pwrctrlpriv = adapter_to_pwrctl(padapter);
9616         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
9617         struct sta_info *psta = NULL;
9618         int ret = 0;
9619         u32 start_time = rtw_get_current_time();
9620         poidparam.subcode = 0;
9621
9622         DBG_871X("+rtw_ap_wowlan_ctrl: %s\n", extra);
9623
9624         if(pwrctrlpriv->bSupportRemoteWakeup==_FALSE){
9625                 ret = -EPERM;
9626                 DBG_871X("+rtw_wowlan_ctrl: Device didn't support the remote wakeup!!\n");
9627                 goto _rtw_ap_wowlan_ctrl_exit_free;
9628         }
9629
9630         if (!check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
9631                 DBG_871X("[%s] It is not AP mode!!\n", __func__);
9632                 goto _rtw_ap_wowlan_ctrl_exit_free;
9633         }
9634
9635         if (_rtw_memcmp( extra, "enable", 6 )) {
9636                 pwrctrlpriv->wowlan_ap_mode = _TRUE;
9637                 while (pwrctrlpriv->bips_processing == _TRUE)
9638                         rtw_msleep_os(1);
9639
9640                 rtw_cancel_all_timer(padapter);
9641
9642                 padapter->bDriverStopped = _TRUE;       //for stop thread
9643                 rtw_stop_drv_threads(padapter);
9644                 padapter->bDriverStopped = _FALSE;      //for 32k command
9645
9646 #ifdef CONFIG_LPS
9647                 LeaveAllPowerSaveModeDirect(padapter);
9648 #endif
9649                 rtw_hal_disable_interrupt(padapter); // It need wait for leaving 32K.
9650
9651                 // 2.1 clean interupt
9652                 if (padapter->HalFunc.clear_interrupt)
9653                         padapter->HalFunc.clear_interrupt(padapter);
9654
9655                 poidparam.subcode = WOWLAN_AP_ENABLE;
9656
9657                 rtw_hal_set_hwreg(padapter, HW_VAR_AP_WOWLAN,(u8 *)&poidparam);
9658         } else if (_rtw_memcmp( extra, "disable", 6 )) {
9659 #ifdef CONFIG_LPS
9660                 LeaveAllPowerSaveModeDirect(padapter);
9661 #endif //CONFIG_LPS
9662                 pwrctrlpriv->bFwCurrentInPSMode = _FALSE;
9663
9664                 rtw_hal_disable_interrupt(padapter);
9665
9666                 if (padapter->HalFunc.clear_interrupt)
9667                         padapter->HalFunc.clear_interrupt(padapter);
9668
9669                 poidparam.subcode = WOWLAN_AP_ENABLE;
9670
9671                 rtw_hal_set_hwreg(padapter, HW_VAR_AP_WOWLAN,(u8 *)&poidparam);
9672
9673                 pwrctrlpriv->wowlan_ap_mode = _FALSE;
9674
9675                 psta = rtw_get_stainfo(&padapter->stapriv, get_bssid(&padapter->mlmepriv));
9676                 if (psta) {
9677                         set_sta_rate(padapter, psta);
9678                 }
9679
9680                 padapter->bDriverStopped = _FALSE;
9681                 DBG_871X("%s: wowmode resuming, DriverStopped:%d\n", __func__, padapter->bDriverStopped);
9682                 rtw_start_drv_threads(padapter);
9683
9684                 rtw_hal_enable_interrupt(padapter);
9685
9686                 _set_timer(&padapter->mlmepriv.dynamic_chk_timer, 2000);
9687                 pwrctrlpriv->bips_processing = _FALSE;
9688                 rtw_set_pwr_state_check_timer(pwrctrlpriv);
9689
9690         } else {
9691                 DBG_871X("[%s] Invalid Parameter.\n", __func__);
9692                 goto _rtw_ap_wowlan_ctrl_exit_free;
9693         }
9694         //mutex_lock(&ioctl_mutex);
9695 _rtw_ap_wowlan_ctrl_exit_free:
9696         DBG_871X("-rtw_ap_wowlan_ctrl( subcode = %d)\n", poidparam.subcode);
9697         DBG_871X_LEVEL(_drv_always_, "%s in %d ms\n", __func__,
9698                         rtw_get_passing_time_ms(start_time));
9699 _rtw_ap_wowlan_ctrl_exit:
9700         return ret;
9701 }
9702 #endif //CONFIG_AP_WOWLAN
9703
9704 static int rtw_pm_set(struct net_device *dev,
9705                                struct iw_request_info *info,
9706                                union iwreq_data *wrqu, char *extra)
9707 {
9708         int ret = 0;
9709         unsigned        mode = 0;
9710         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
9711
9712         DBG_871X( "[%s] extra = %s\n", __FUNCTION__, extra );
9713
9714         if ( _rtw_memcmp( extra, "lps=", 4 ) )
9715         {
9716                 sscanf(extra+4, "%u", &mode);   
9717                 ret = rtw_pm_set_lps(padapter,mode);
9718         }
9719         else if ( _rtw_memcmp( extra, "ips=", 4 ) )
9720         {
9721                 sscanf(extra+4, "%u", &mode);
9722                 ret = rtw_pm_set_ips(padapter,mode);
9723         }
9724         else{
9725                 ret = -EINVAL;
9726         }
9727
9728         return ret;
9729 }
9730
9731 static int rtw_mp_efuse_get(struct net_device *dev,
9732                         struct iw_request_info *info,
9733                         union iwreq_data *wdata, char *extra)
9734 {
9735         PADAPTER padapter = rtw_netdev_priv(dev);
9736         EEPROM_EFUSE_PRIV *pEEPROM = GET_EEPROM_EFUSE_PRIV(padapter);
9737         PHAL_DATA_TYPE pHalData = GET_HAL_DATA(padapter);
9738         PEFUSE_HAL pEfuseHal;
9739         struct iw_point *wrqu;
9740         
9741         u8      *PROMContent = pEEPROM->efuse_eeprom_data;
9742         u8 ips_mode = IPS_NUM; // init invalid value
9743         u8 lps_mode = PS_MODE_NUM; // init invalid value
9744         struct pwrctrl_priv *pwrctrlpriv ;
9745         u8 *data = NULL;
9746         u8 *rawdata = NULL;
9747         char *pch, *ptmp, *token, *tmp[3]={0x00,0x00,0x00};
9748         u16 i=0, j=0, mapLen=0, addr=0, cnts=0;
9749         u16 max_available_size=0, raw_cursize=0, raw_maxsize=0;
9750         int err;
9751         #ifdef CONFIG_IOL
9752         u8 org_fw_iol = padapter->registrypriv.fw_iol;// 0:Disable, 1:enable, 2:by usb speed
9753         #endif
9754         
9755         wrqu = (struct iw_point*)wdata;
9756         pwrctrlpriv = adapter_to_pwrctl(padapter);
9757         pEfuseHal = &pHalData->EfuseHal;
9758
9759         err = 0;
9760         data = rtw_zmalloc(EFUSE_BT_MAX_MAP_LEN);
9761         if (data == NULL)
9762         {
9763                 err = -ENOMEM;
9764                 goto exit;
9765         }
9766         rawdata = rtw_zmalloc(EFUSE_BT_MAX_MAP_LEN);
9767         if (rawdata == NULL)
9768         {
9769                 err = -ENOMEM;
9770                 goto exit;
9771         }
9772
9773         if (copy_from_user(extra, wrqu->pointer, wrqu->length))
9774         {
9775                 err = -EFAULT;
9776                 goto exit;
9777         }
9778         #ifdef CONFIG_LPS
9779         lps_mode = pwrctrlpriv->power_mgnt;//keep org value
9780         rtw_pm_set_lps(padapter,PS_MODE_ACTIVE);
9781         #endif  
9782         
9783         #ifdef CONFIG_IPS       
9784         ips_mode = pwrctrlpriv->ips_mode;//keep org value
9785         rtw_pm_set_ips(padapter,IPS_NONE);
9786         #endif  
9787         
9788         pch = extra;
9789         DBG_871X("%s: in=%s\n", __FUNCTION__, extra);
9790
9791         i = 0;
9792         //mac 16 "00e04c871200" rmap,00,2
9793         while ((token = strsep(&pch, ",")) != NULL)
9794         {
9795                 if (i > 2) break;
9796                 tmp[i] = token;
9797                 i++;
9798         }
9799         #ifdef CONFIG_IOL
9800         padapter->registrypriv.fw_iol = 0;// 0:Disable, 1:enable, 2:by usb speed
9801         #endif
9802         
9803         if(strcmp(tmp[0], "status") == 0){
9804                 sprintf(extra, "Load File efuse=%s,Load File MAC=%s",(pEEPROM->bloadfile_fail_flag? "FAIL" : "OK"),(pEEPROM->bloadmac_fail_flag? "FAIL" : "OK"));
9805
9806                   goto exit;
9807         }
9808         else if (strcmp(tmp[0], "drvmap") == 0)
9809         {
9810                 mapLen = EFUSE_MAP_SIZE;
9811                 
9812                 sprintf(extra, "\n");
9813                 for (i = 0; i < EFUSE_MAP_SIZE; i += 16)
9814                 {
9815 //                      DBG_871X("0x%02x\t", i);
9816                         sprintf(extra, "%s0x%02x\t", extra, i);
9817                         for (j=0; j<8; j++) {
9818 //                              DBG_871X("%02X ", data[i+j]);
9819                                 sprintf(extra, "%s%02X ", extra, PROMContent[i+j]);
9820                         }
9821 //                      DBG_871X("\t");
9822                         sprintf(extra, "%s\t", extra);
9823                         for (; j<16; j++) {
9824 //                              DBG_871X("%02X ", data[i+j]);
9825                                 sprintf(extra, "%s%02X ", extra, PROMContent[i+j]);
9826                         }
9827 //                      DBG_871X("\n");
9828                         sprintf(extra,"%s\n",extra);
9829                 }
9830 //              DBG_871X("\n");
9831         }
9832         else if (strcmp(tmp[0], "realmap") == 0)
9833         {
9834                 mapLen = EFUSE_MAP_SIZE;
9835                 if (rtw_efuse_map_read(padapter, EFUSE_WIFI , mapLen, pEfuseHal->fakeEfuseInitMap) == _FAIL)
9836                 {
9837                         DBG_871X("%s: read realmap Fail!!\n", __FUNCTION__);
9838                         err = -EFAULT;
9839                         goto exit;
9840                 }
9841
9842 //              DBG_871X("OFFSET\tVALUE(hex)\n");
9843                 sprintf(extra, "\n");
9844                 for (i = 0; i < EFUSE_MAP_SIZE; i += 16)
9845                 {
9846 //                      DBG_871X("0x%02x\t", i);
9847                         sprintf(extra, "%s0x%02x\t", extra, i);
9848                         for (j=0; j<8; j++) {
9849 //                              DBG_871X("%02X ", data[i+j]);
9850                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeEfuseInitMap[i+j]);
9851                         }
9852 //                      DBG_871X("\t");
9853                         sprintf(extra, "%s\t", extra);
9854                         for (; j<16; j++) {
9855 //                              DBG_871X("%02X ", data[i+j]);
9856                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeEfuseInitMap[i+j]);
9857                         }
9858 //                      DBG_871X("\n");
9859                         sprintf(extra,"%s\n",extra);
9860                 }
9861 //              DBG_871X("\n");
9862         }
9863         else if (strcmp(tmp[0], "rmap") == 0)
9864         {
9865                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
9866                 {
9867                         DBG_871X("%s: rmap Fail!! Parameters error!\n", __FUNCTION__);
9868                         err = -EINVAL;
9869                         goto exit;
9870                 }
9871
9872                 // rmap addr cnts
9873                 addr = simple_strtoul(tmp[1], &ptmp, 16);
9874                 DBG_871X("%s: addr=%x\n", __FUNCTION__, addr);
9875
9876                 cnts = simple_strtoul(tmp[2], &ptmp, 10);
9877                 if (cnts == 0)
9878                 {
9879                         DBG_871X("%s: rmap Fail!! cnts error!\n", __FUNCTION__);
9880                         err = -EINVAL;
9881                         goto exit;
9882                 }
9883                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
9884
9885                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_EFUSE_MAP_LEN , (PVOID)&max_available_size, _FALSE);
9886                 if ((addr+ cnts) > max_available_size)
9887                 {
9888                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
9889                         err = -EINVAL;
9890                         goto exit;
9891                 }
9892
9893                 if (rtw_efuse_map_read(padapter, addr, cnts, data) == _FAIL)
9894                 {
9895                         DBG_871X("%s: rtw_efuse_map_read error!\n", __FUNCTION__);
9896                         err = -EFAULT;
9897                         goto exit;
9898                 }
9899
9900 //              DBG_871X("%s: data={", __FUNCTION__);
9901                 *extra = 0;
9902                 for (i=0; i<cnts; i++) {
9903 //                      DBG_871X("0x%02x ", data[i]);
9904                         sprintf(extra, "%s0x%02X ", extra, data[i]);
9905                 }
9906 //              DBG_871X("}\n");
9907         }
9908         else if (strcmp(tmp[0], "realraw") == 0)
9909         {
9910                 addr = 0;
9911                 mapLen = EFUSE_MAX_SIZE;
9912                 if (rtw_efuse_access(padapter, _FALSE, addr, mapLen, rawdata) == _FAIL)
9913                 {
9914                         DBG_871X("%s: rtw_efuse_access Fail!!\n", __FUNCTION__);
9915                         err = -EFAULT;
9916                         goto exit;
9917                 }
9918                 _rtw_memset(extra,'\0',strlen(extra));
9919                 //              DBG_871X("%s: realraw={\n", __FUNCTION__);
9920                                 sprintf(extra, "\n0x00\t");
9921                                 for (i=0; i< mapLen; i++)
9922                                 {
9923                 //                      DBG_871X("%02X", rawdata[i]);
9924                                         sprintf(extra, "%s%02X", extra, rawdata[i]);
9925                                         if ((i & 0xF) == 0xF) {
9926                 //                              DBG_871X("\n");
9927                                                 sprintf(extra, "%s\n", extra);
9928                                                 sprintf(extra, "%s0x%02x\t", extra, i+1);
9929                                         }
9930                                         else if ((i & 0x7) == 0x7){
9931                 //                              DBG_871X("\t");
9932                                                 sprintf(extra, "%s \t", extra);
9933                                         } else {
9934                 //                              DBG_871X(" ");
9935                                                 sprintf(extra, "%s ", extra);
9936                                         }
9937                                 }
9938                 //              DBG_871X("}\n");
9939         }
9940         else if (strcmp(tmp[0], "mac") == 0)
9941         {
9942                 #ifdef CONFIG_RTL8192C
9943                 addr = EEPROM_MAC_ADDR_92C;
9944                 #endif // CONFIG_RTL8192C
9945                 #ifdef CONFIG_RTL8192D
9946                         #ifdef CONFIG_USB_HCI
9947                         if (pHalData->interfaceIndex == 0)
9948                                 addr = EEPROM_MAC_ADDR_MAC0_92DU;
9949                         else
9950                                 addr = EEPROM_MAC_ADDR_MAC1_92DU;
9951                         #else
9952                         if (pHalData->interfaceIndex == 0)
9953                                 addr = EEPROM_MAC_ADDR_MAC0_92DE;
9954                         else
9955                                 addr = EEPROM_MAC_ADDR_MAC1_92DE;
9956                         #endif
9957                 #endif // CONFIG_RTL8192D
9958                 #ifdef CONFIG_RTL8723A
9959                         #ifdef CONFIG_SDIO_HCI
9960                         addr = EEPROM_MAC_ADDR_8723AS;
9961                         #endif
9962                         #ifdef CONFIG_GSPI_HCI
9963                         addr = EEPROM_MAC_ADDR_8723AS;
9964                         #endif
9965                         #ifdef CONFIG_USB_HCI
9966                         addr = EEPROM_MAC_ADDR_8723AU;
9967                         #endif
9968                 #endif // CONFIG_RTL8723A
9969                 #ifdef CONFIG_RTL8188E
9970                         #ifdef CONFIG_USB_HCI
9971                         addr = EEPROM_MAC_ADDR_88EU;
9972                         #endif
9973                         #ifdef CONFIG_SDIO_HCI
9974                         addr = EEPROM_MAC_ADDR_88ES;
9975                         #endif
9976                         #ifdef CONFIG_PCI_HCI
9977                         addr = EEPROM_MAC_ADDR_88EE;
9978                         #endif
9979                 #endif // CONFIG_RTL8188E
9980
9981                 #ifdef CONFIG_RTL8192E
9982                         #ifdef CONFIG_USB_HCI
9983                         addr = EEPROM_MAC_ADDR_8192EU;
9984                         #endif
9985                         #ifdef CONFIG_SDIO_HCI
9986                         addr = EEPROM_MAC_ADDR_8192ES;
9987                         #endif
9988                         #ifdef CONFIG_PCI_HCI
9989                         addr = EEPROM_MAC_ADDR_8192EE;
9990                         #endif
9991                 #endif
9992                 #ifdef CONFIG_RTL8723B
9993                 #ifdef CONFIG_SDIO_HCI
9994                 addr = EEPROM_MAC_ADDR_8723BS;
9995                 #endif
9996                 #ifdef CONFIG_GSPI_HCI
9997                 addr = EEPROM_MAC_ADDR_8723BS;
9998                 #endif
9999                 #ifdef CONFIG_USB_HCI
10000                 addr = EEPROM_MAC_ADDR_8723BU;
10001                 #endif
10002                 #endif // CONFIG_RTL8723B
10003                 cnts = 6;
10004
10005                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
10006                 if ((addr + cnts) > max_available_size) {
10007                         DBG_871X("%s: addr(0x%02x)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
10008                         err = -EFAULT;
10009                         goto exit;
10010                 }
10011
10012                 if (rtw_efuse_map_read(padapter, addr, cnts, data) == _FAIL)
10013                 {
10014                         DBG_871X("%s: rtw_efuse_map_read error!\n", __FUNCTION__);
10015                         err = -EFAULT;
10016                         goto exit;
10017                 }
10018
10019 //              DBG_871X("%s: MAC address={", __FUNCTION__);
10020                 *extra = 0;
10021                 for (i=0; i<cnts; i++)
10022                 {
10023 //                      DBG_871X("%02X", data[i]);
10024                         sprintf(extra, "%s%02X", extra, data[i]);
10025                         if (i != (cnts-1))
10026                         {
10027 //                              DBG_871X(":");
10028                                 sprintf(extra,"%s:",extra);
10029                         }
10030                 }
10031 //              DBG_871X("}\n");
10032         }
10033         else if (strcmp(tmp[0], "vidpid") == 0)
10034         {
10035                 #ifdef CONFIG_RTL8192C
10036                 addr = EEPROM_VID_92C;
10037                 #endif // CONFIG_RTL8192C
10038                 #ifdef CONFIG_RTL8192D
10039                         #ifdef CONFIG_USB_HCI
10040                         addr = EEPROM_VID_92DU;
10041                         #else
10042                         addr = EEPROM_VID_92DE;
10043                         #endif
10044                 #endif // CONFIG_RTL8192D
10045                 #ifdef CONFIG_RTL8723A
10046                         #ifdef CONFIG_USB_HCI
10047                         addr = EEPROM_VID_8723AU;
10048                         #endif
10049                 #endif // CONFIG_RTL8723A
10050                 #ifdef CONFIG_RTL8188E
10051                         #ifdef CONFIG_USB_HCI
10052                         addr = EEPROM_VID_88EU;
10053                         #endif
10054                         #ifdef CONFIG_PCI_HCI
10055                         addr = EEPROM_VID_88EE;
10056                         #endif
10057                 #endif // CONFIG_RTL8188E
10058
10059                 #ifdef CONFIG_RTL8192E
10060                         #ifdef CONFIG_USB_HCI
10061                         addr = EEPROM_VID_8192EU;
10062                         #endif
10063                         #ifdef CONFIG_PCI_HCI
10064                         addr = EEPROM_VID_8192EE;
10065                         #endif
10066                 #endif // CONFIG_RTL8192E
10067                 #ifdef CONFIG_RTL8723B
10068                 addr = EEPROM_VID_8723BU;
10069                 #endif // CONFIG_RTL8192E
10070                 cnts = 4;
10071
10072                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
10073                 if ((addr + cnts) > max_available_size)
10074                 {
10075                         DBG_871X("%s: addr(0x%02x)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
10076                         err = -EFAULT;
10077                         goto exit;
10078                 }
10079                 if (rtw_efuse_map_read(padapter, addr, cnts, data) == _FAIL)
10080                 {
10081                         DBG_871X("%s: rtw_efuse_access error!!\n", __FUNCTION__);
10082                         err = -EFAULT;
10083                         goto exit;
10084                 }
10085
10086 //              DBG_871X("%s: {VID,PID}={", __FUNCTION__);
10087                 *extra = 0;
10088                 for (i=0; i<cnts; i++)
10089                 {
10090 //                      DBG_871X("0x%02x", data[i]);
10091                         sprintf(extra, "%s0x%02X", extra, data[i]);
10092                         if (i != (cnts-1))
10093                         {
10094 //                              DBG_871X(",");
10095                                 sprintf(extra,"%s,",extra);
10096                         }
10097                 }
10098 //              DBG_871X("}\n");
10099         }
10100         else if (strcmp(tmp[0], "ableraw") == 0)
10101         {
10102                 efuse_GetCurrentSize(padapter,&raw_cursize);
10103                 raw_maxsize = efuse_GetMaxSize(padapter);
10104                 sprintf(extra, "[available raw size]= %d bytes", raw_maxsize-raw_cursize);
10105         }
10106         else if (strcmp(tmp[0], "btfmap") == 0)
10107         {
10108                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
10109                                 
10110                 mapLen = EFUSE_BT_MAX_MAP_LEN;
10111                 if (rtw_BT_efuse_map_read(padapter, 0, mapLen, pEfuseHal->BTEfuseInitMap) == _FAIL)
10112                 {
10113                         DBG_871X("%s: rtw_BT_efuse_map_read Fail!!\n", __FUNCTION__);
10114                         err = -EFAULT;
10115                         goto exit;
10116                 }
10117
10118 //              DBG_871X("OFFSET\tVALUE(hex)\n");
10119                 sprintf(extra, "\n");
10120                 for (i=0; i<512; i+=16) // set 512 because the iwpriv's extra size have limit 0x7FF
10121                 {
10122 //                      DBG_871X("0x%03x\t", i);
10123                         sprintf(extra, "%s0x%03x\t", extra, i);
10124                         for (j=0; j<8; j++) {
10125 //                              DBG_871X("%02X ", pEfuseHal->BTEfuseInitMap[i+j]);
10126                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->BTEfuseInitMap[i+j]);
10127                         }
10128 //                      DBG_871X("\t");
10129                         sprintf(extra,"%s\t",extra);
10130                         for (; j<16; j++) {
10131 //                              DBG_871X("%02X ", pEfuseHal->BTEfuseInitMap[i+j]);
10132                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->BTEfuseInitMap[i+j]);
10133                         }
10134 //                      DBG_871X("\n");
10135                         sprintf(extra, "%s\n", extra);
10136                 }
10137 //              DBG_871X("\n");
10138         }
10139         else if (strcmp(tmp[0],"btbmap") == 0)
10140         {
10141                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
10142                 
10143                 mapLen = EFUSE_BT_MAX_MAP_LEN;
10144                 if (rtw_BT_efuse_map_read(padapter, 0, mapLen, pEfuseHal->BTEfuseInitMap) == _FAIL)
10145                 {
10146                         DBG_871X("%s: rtw_BT_efuse_map_read Fail!!\n", __FUNCTION__);
10147                         err = -EFAULT;
10148                         goto exit;
10149                 }
10150
10151 //              DBG_871X("OFFSET\tVALUE(hex)\n");
10152                 sprintf(extra, "\n");
10153                 for (i=512; i<1024 ; i+=16)
10154                 {
10155 //                      DBG_871X("0x%03x\t", i);
10156                         sprintf(extra, "%s0x%03x\t", extra, i);
10157                         for (j=0; j<8; j++)
10158                         {
10159 //                              DBG_871X("%02X ", data[i+j]);
10160                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->BTEfuseInitMap[i+j]);
10161                         }
10162 //                      DBG_871X("\t");
10163                         sprintf(extra,"%s\t",extra);
10164                         for (; j<16; j++) {
10165 //                              DBG_871X("%02X ", data[i+j]);
10166                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->BTEfuseInitMap[i+j]);
10167                         }
10168 //                      DBG_871X("\n");
10169                         sprintf(extra, "%s\n", extra);
10170                 }
10171 //              DBG_871X("\n");
10172         }
10173         else if (strcmp(tmp[0],"btrmap") == 0)
10174         {
10175                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
10176                 {
10177                         err = -EINVAL;
10178                         goto exit;
10179                 }
10180
10181                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
10182                 
10183                 // rmap addr cnts
10184                 addr = simple_strtoul(tmp[1], &ptmp, 16);
10185                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10186
10187                 cnts = simple_strtoul(tmp[2], &ptmp, 10);
10188                 if (cnts == 0)
10189                 {
10190                         DBG_871X("%s: btrmap Fail!! cnts error!\n", __FUNCTION__);
10191                         err = -EINVAL;
10192                         goto exit;
10193                 }
10194                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10195
10196                 EFUSE_GetEfuseDefinition(padapter, EFUSE_BT, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
10197                 if ((addr + cnts) > max_available_size)
10198                 {
10199                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
10200                         err = -EFAULT;
10201                         goto exit;
10202                 }
10203
10204                 if (rtw_BT_efuse_map_read(padapter, addr, cnts, data) == _FAIL) 
10205                 {
10206                         DBG_871X("%s: rtw_BT_efuse_map_read error!!\n", __FUNCTION__);
10207                         err = -EFAULT;
10208                         goto exit;
10209                 }
10210
10211                 *extra = 0;
10212 //              DBG_871X("%s: bt efuse data={", __FUNCTION__);
10213                 for (i=0; i<cnts; i++)
10214                 {
10215 //                      DBG_871X("0x%02x ", data[i]);
10216                         sprintf(extra, "%s 0x%02X ", extra, data[i]);
10217                 }
10218 //              DBG_871X("}\n");
10219                 DBG_871X(FUNC_ADPT_FMT ": BT MAC=[%s]\n", FUNC_ADPT_ARG(padapter), extra);
10220         }
10221         else if (strcmp(tmp[0], "btffake") == 0)
10222         {
10223 //              DBG_871X("OFFSET\tVALUE(hex)\n");
10224                 sprintf(extra, "\n");
10225                 for (i=0; i<512; i+=16)
10226                 {
10227 //                      DBG_871X("0x%03x\t", i);
10228                         sprintf(extra, "%s0x%03x\t", extra, i);
10229                         for (j=0; j<8; j++) {
10230 //                              DBG_871X("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10231                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10232                         }
10233 //                      DBG_871X("\t");
10234                         sprintf(extra, "%s\t", extra);
10235                         for (; j<16; j++) {
10236 //                              DBG_871X("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10237                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10238                         }
10239 //                      DBG_871X("\n");
10240                         sprintf(extra, "%s\n", extra);
10241                 }
10242 //              DBG_871X("\n");
10243         }
10244         else if (strcmp(tmp[0],"btbfake") == 0)
10245         {
10246 //              DBG_871X("OFFSET\tVALUE(hex)\n");
10247                 sprintf(extra, "\n");
10248                 for (i=512; i<1024; i+=16)
10249                 {
10250 //                      DBG_871X("0x%03x\t", i);
10251                         sprintf(extra, "%s0x%03x\t", extra, i);
10252                         for (j=0; j<8; j++) {
10253 //                              DBG_871X("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10254                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10255                         }
10256 //                      DBG_871X("\t");
10257                         sprintf(extra, "%s\t", extra);
10258                         for (; j<16; j++) {
10259 //                              DBG_871X("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10260                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10261                         }
10262 //                      DBG_871X("\n");
10263                         sprintf(extra, "%s\n", extra);
10264                 }
10265 //              DBG_871X("\n");
10266         }
10267         else if (strcmp(tmp[0],"wlrfkmap")== 0)
10268         {
10269 //              DBG_871X("OFFSET\tVALUE(hex)\n");
10270                 sprintf(extra, "\n");
10271                 for (i=0; i<EFUSE_MAP_SIZE; i+=16)
10272                 {
10273 //                      DBG_871X("\t0x%02x\t", i);
10274                         sprintf(extra, "%s0x%02x\t", extra, i);
10275                         for (j=0; j<8; j++) {
10276 //                              DBG_871X("%02X ", pEfuseHal->fakeEfuseModifiedMap[i+j]);
10277                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeEfuseModifiedMap[i+j]);
10278                         }
10279 //                      DBG_871X("\t");
10280                         sprintf(extra, "%s\t", extra);
10281                         for (; j<16; j++) {
10282 //                              DBG_871X("%02X ", pEfuseHal->fakeEfuseModifiedMap[i+j]);
10283                                 sprintf(extra, "%s %02X", extra, pEfuseHal->fakeEfuseModifiedMap[i+j]);
10284                         }
10285 //                      DBG_871X("\n");
10286                         sprintf(extra, "%s\n", extra);
10287                 }
10288 //              DBG_871X("\n");
10289
10290         }
10291         else if (strcmp(tmp[0],"wlrfkrmap")== 0)
10292         {
10293                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
10294                                 {
10295                                         DBG_871X("%s: rmap Fail!! Parameters error!\n", __FUNCTION__);
10296                                         err = -EINVAL;
10297                                         goto exit;
10298                                 }
10299                                 // rmap addr cnts
10300                                 addr = simple_strtoul(tmp[1], &ptmp, 16);
10301                                 DBG_871X("%s: addr=%x\n", __FUNCTION__, addr);
10302                 
10303                                 cnts = simple_strtoul(tmp[2], &ptmp, 10);
10304                                 if (cnts == 0)
10305                                 {
10306                                         DBG_871X("%s: rmap Fail!! cnts error!\n", __FUNCTION__);
10307                                         err = -EINVAL;
10308                                         goto exit;
10309                                 }
10310                                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10311                 
10312                 //              DBG_871X("%s: data={", __FUNCTION__);
10313                         *extra = 0;
10314                         for (i=0; i<cnts; i++) {
10315                                         DBG_871X("wlrfkrmap = 0x%02x \n", pEfuseHal->fakeEfuseModifiedMap[addr+i]);
10316                                         sprintf(extra, "%s0x%02X ", extra, pEfuseHal->fakeEfuseModifiedMap[addr+i]);
10317                         }
10318         }
10319         else if (strcmp(tmp[0],"btrfkrmap")== 0)
10320         {
10321                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
10322                                 {
10323                                         DBG_871X("%s: rmap Fail!! Parameters error!\n", __FUNCTION__);
10324                                         err = -EINVAL;
10325                                         goto exit;
10326                                 }
10327                                 // rmap addr cnts
10328                                 addr = simple_strtoul(tmp[1], &ptmp, 16);
10329                                 DBG_871X("%s: addr=%x\n", __FUNCTION__, addr);
10330                 
10331                                 cnts = simple_strtoul(tmp[2], &ptmp, 10);
10332                                 if (cnts == 0)
10333                                 {
10334                                         DBG_871X("%s: rmap Fail!! cnts error!\n", __FUNCTION__);
10335                                         err = -EINVAL;
10336                                         goto exit;
10337                                 }
10338                                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10339                 
10340                 //              DBG_871X("%s: data={", __FUNCTION__);
10341                         *extra = 0;
10342                         for (i=0; i<cnts; i++) {
10343                                         DBG_871X("wlrfkrmap = 0x%02x \n", pEfuseHal->fakeBTEfuseModifiedMap[addr+i]);
10344                                         sprintf(extra, "%s0x%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[addr+i]);
10345                         }
10346         }
10347         else
10348         {
10349                  sprintf(extra, "Command not found!");
10350         }
10351
10352 exit:
10353         if (data)
10354                 rtw_mfree(data, EFUSE_BT_MAX_MAP_LEN);
10355         if (rawdata)
10356                 rtw_mfree(rawdata, EFUSE_BT_MAX_MAP_LEN);
10357         if (!err)
10358                 wrqu->length = strlen(extra);
10359         
10360         if (padapter->registrypriv.mp_mode == 0)
10361         {
10362         #ifdef CONFIG_IPS               
10363         rtw_pm_set_ips(padapter, ips_mode);
10364 #endif // CONFIG_IPS
10365
10366         #ifdef CONFIG_LPS       
10367         rtw_pm_set_lps(padapter, lps_mode);
10368 #endif // CONFIG_LPS
10369         }
10370
10371         #ifdef CONFIG_IOL
10372         padapter->registrypriv.fw_iol = org_fw_iol;// 0:Disable, 1:enable, 2:by usb speed
10373         #endif
10374         return err;
10375 }
10376
10377 static int rtw_mp_efuse_set(struct net_device *dev,
10378                         struct iw_request_info *info,
10379                         union iwreq_data *wdata, char *extra)
10380 {
10381         struct iw_point *wrqu;
10382         PADAPTER padapter;
10383         struct pwrctrl_priv *pwrctrlpriv ;
10384         PHAL_DATA_TYPE pHalData;
10385         PEFUSE_HAL pEfuseHal;
10386
10387         u8 ips_mode = IPS_NUM; // init invalid value
10388         u8 lps_mode = PS_MODE_NUM; // init invalid value
10389         u32 i=0,j=0, jj, kk;
10390         u8 *setdata = NULL;
10391         u8 *ShadowMapBT = NULL;
10392         u8 *ShadowMapWiFi = NULL;
10393         u8 *setrawdata = NULL;
10394         char *pch, *ptmp, *token, *tmp[3]={0x00,0x00,0x00};
10395         u16 addr=0xFF, cnts=0, BTStatus=0 , max_available_size=0;
10396         int err;
10397
10398         wrqu = (struct iw_point*)wdata;
10399         padapter = rtw_netdev_priv(dev);
10400         pwrctrlpriv = adapter_to_pwrctl(padapter);
10401         pHalData = GET_HAL_DATA(padapter);
10402         pEfuseHal = &pHalData->EfuseHal;
10403         err = 0;
10404         
10405         if (copy_from_user(extra, wrqu->pointer, wrqu->length))
10406                         return -EFAULT;
10407                         
10408         setdata = rtw_zmalloc(1024);
10409         if (setdata == NULL)
10410         {
10411                 err = -ENOMEM;
10412                 goto exit;
10413         }
10414         ShadowMapBT = rtw_malloc(EFUSE_BT_MAX_MAP_LEN);
10415         if (ShadowMapBT == NULL)
10416         {
10417                 err = -ENOMEM;
10418                 goto exit;
10419         }
10420         ShadowMapWiFi = rtw_malloc(EFUSE_MAP_SIZE);
10421         if (ShadowMapWiFi == NULL)
10422         {
10423                 err = -ENOMEM;
10424                 goto exit;
10425         }
10426         setrawdata = rtw_malloc(EFUSE_MAX_SIZE);
10427         if (setrawdata == NULL)
10428         {
10429                 err = -ENOMEM;
10430                 goto exit;
10431         }
10432
10433         #ifdef CONFIG_LPS
10434         lps_mode = pwrctrlpriv->power_mgnt;//keep org value
10435         rtw_pm_set_lps(padapter,PS_MODE_ACTIVE);
10436         #endif  
10437         
10438         #ifdef CONFIG_IPS       
10439         ips_mode = pwrctrlpriv->ips_mode;//keep org value
10440         rtw_pm_set_ips(padapter,IPS_NONE);
10441         #endif  
10442                         
10443         pch = extra;
10444         DBG_871X("%s: in=%s\n", __FUNCTION__, extra);
10445         
10446         i = 0;
10447         while ((token = strsep(&pch, ",")) != NULL)
10448         {
10449                 if (i > 2) break;
10450                 tmp[i] = token;
10451                 i++;
10452         }
10453
10454         // tmp[0],[1],[2]
10455         // wmap,addr,00e04c871200
10456         if (strcmp(tmp[0], "wmap") == 0)
10457         {
10458                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
10459                 {
10460                         err = -EINVAL;
10461                         goto exit;
10462                 }
10463
10464 #if 1
10465                 // unknown bug workaround, need to fix later
10466                 addr=0x1ff;
10467                 rtw_write8(padapter, EFUSE_CTRL+1, (addr & 0xff));
10468                 rtw_msleep_os(10);
10469                 rtw_write8(padapter, EFUSE_CTRL+2, ((addr >> 8) & 0x03));
10470                 rtw_msleep_os(10);
10471                 rtw_write8(padapter, EFUSE_CTRL+3, 0x72);
10472                 rtw_msleep_os(10);
10473                 rtw_read8(padapter, EFUSE_CTRL);
10474 #endif
10475
10476                 addr = simple_strtoul(tmp[1], &ptmp, 16);
10477                 addr &= 0xFFF;
10478
10479                 cnts = strlen(tmp[2]);
10480                 if (cnts%2)
10481                 {
10482                         err = -EINVAL;
10483                         goto exit;
10484                 }
10485                 cnts /= 2;
10486                 if (cnts == 0)
10487                 {
10488                         err = -EINVAL;
10489                         goto exit;
10490                 }
10491
10492                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10493                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10494                 DBG_871X("%s: map data=%s\n", __FUNCTION__, tmp[2]);
10495                                 
10496                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
10497                 {
10498                         setdata[jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
10499                 }
10500 #ifndef CONFIG_RTL8188E
10501                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
10502 #else
10503                 //Change to check TYPE_EFUSE_MAP_LEN ,beacuse 8188E raw 256,logic map over 256.
10504                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_EFUSE_MAP_LEN, (PVOID)&max_available_size, _FALSE);
10505 #endif
10506                 if ((addr+cnts) > max_available_size)
10507                 {
10508                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
10509                         err = -EFAULT;
10510                         goto exit;
10511                 }
10512
10513                 if (rtw_efuse_map_write(padapter, addr, cnts, setdata) == _FAIL)
10514                 {
10515                         DBG_871X("%s: rtw_efuse_map_write error!!\n", __FUNCTION__);
10516                         err = -EFAULT;
10517                         goto exit;
10518                 }
10519                 *extra = 0;
10520                 DBG_871X("%s: after rtw_BT_efuse_map_write to _rtw_memcmp \n", __FUNCTION__);
10521                 if ( (rtw_efuse_map_read(padapter, addr, cnts, ShadowMapWiFi) == _SUCCESS ) )
10522                 {
10523                         if (_rtw_memcmp((void*)ShadowMapWiFi ,(void*)setdata,cnts))
10524                         { 
10525                                 DBG_871X("%s: WiFi write map afterf compare success\n", __FUNCTION__);
10526                                 sprintf(extra, "WiFi write map compare OK\n");
10527                                 err = 0;
10528                                 goto exit;
10529                         }
10530                         else
10531                         {
10532                                 sprintf(extra, "WiFi write map compare FAIL\n");
10533                                 DBG_871X("%s: WiFi write map compare Fail\n", __FUNCTION__);
10534                                 err = 0;
10535                                 goto exit;
10536                         }
10537                 }
10538         }
10539         else if (strcmp(tmp[0], "wraw") == 0)
10540         {
10541                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
10542                 {
10543                         err = -EINVAL;
10544                         goto exit;
10545                 }
10546
10547                 addr = simple_strtoul( tmp[1], &ptmp, 16 );
10548                 addr &= 0xFFF;
10549
10550                 cnts = strlen(tmp[2]);
10551                 if (cnts%2)
10552                 {
10553                         err = -EINVAL;
10554                         goto exit;
10555                 }
10556                 cnts /= 2;
10557                 if (cnts == 0)
10558                 {
10559                         err = -EINVAL;
10560                         goto exit;
10561                 }
10562
10563                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10564                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10565                 DBG_871X("%s: raw data=%s\n", __FUNCTION__, tmp[2]);
10566
10567                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
10568                 {
10569                         setrawdata[jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
10570                 }
10571
10572                 if (rtw_efuse_access(padapter, _TRUE, addr, cnts, setrawdata) == _FAIL)
10573                 {
10574                         DBG_871X("%s: rtw_efuse_access error!!\n", __FUNCTION__);
10575                         err = -EFAULT;
10576                         goto exit;
10577                 }
10578         }
10579         else if (strcmp(tmp[0], "mac") == 0)
10580         {
10581                 if (tmp[1]==NULL)
10582                 {
10583                         err = -EINVAL;
10584                         goto exit;
10585                 }
10586
10587                 //mac,00e04c871200
10588                 #ifdef CONFIG_RTL8192C
10589                 addr = EEPROM_MAC_ADDR_92C;
10590                 #endif
10591                 #ifdef CONFIG_RTL8192D
10592                         #ifdef CONFIG_USB_HCI
10593                         if (pHalData->interfaceIndex == 0)
10594                                 addr = EEPROM_MAC_ADDR_MAC0_92DU;
10595                         else
10596                                 addr = EEPROM_MAC_ADDR_MAC1_92DU;
10597                         #else
10598                         if (pHalData->interfaceIndex == 0)
10599                                 addr = EEPROM_MAC_ADDR_MAC0_92DE;
10600                         else
10601                                 addr = EEPROM_MAC_ADDR_MAC1_92DE;
10602                         #endif
10603                 #endif
10604                 #ifdef CONFIG_RTL8723A
10605                 #ifdef CONFIG_SDIO_HCI
10606                 addr = EEPROM_MAC_ADDR_8723AS;
10607                 #endif
10608                 #ifdef CONFIG_GSPI_HCI
10609                 addr = EEPROM_MAC_ADDR_8723AS;
10610                 #endif
10611                 #ifdef CONFIG_USB_HCI
10612                 addr = EEPROM_MAC_ADDR_8723AU;
10613                 #endif
10614                 #endif // CONFIG_RTL8723A
10615                 #ifdef CONFIG_RTL8188E
10616                         #ifdef CONFIG_USB_HCI
10617                         addr = EEPROM_MAC_ADDR_88EU;
10618                         #endif
10619                         #ifdef CONFIG_SDIO_HCI
10620                         addr = EEPROM_MAC_ADDR_88ES;
10621                         #endif
10622                         #ifdef CONFIG_PCI_HCI
10623                         addr = EEPROM_MAC_ADDR_88EE;
10624                         #endif
10625                 #endif //#ifdef CONFIG_RTL8188E
10626
10627                 #ifdef CONFIG_RTL8192E
10628                         #ifdef CONFIG_USB_HCI
10629                         addr = EEPROM_MAC_ADDR_8192EU;
10630                         #endif
10631                         #ifdef CONFIG_SDIO_HCI
10632                         addr = EEPROM_MAC_ADDR_8192ES;
10633                         #endif
10634                         #ifdef CONFIG_PCI_HCI
10635                         addr = EEPROM_MAC_ADDR_8192EE;
10636                         #endif
10637                 #endif //#ifdef CONFIG_RTL8192E
10638                 
10639                 #ifdef CONFIG_RTL8723B
10640                 #ifdef CONFIG_SDIO_HCI
10641                 addr = EEPROM_MAC_ADDR_8723BS;
10642                 #endif
10643                 #ifdef CONFIG_GSPI_HCI
10644                 addr = EEPROM_MAC_ADDR_8723BS;
10645                 #endif
10646                 #ifdef CONFIG_USB_HCI
10647                 addr = EEPROM_MAC_ADDR_8723BU;
10648                 #endif
10649                 #endif // CONFIG_RTL8723B
10650                 
10651                 #if defined(CONFIG_RTL8812A) || defined(CONFIG_RTL8821A)
10652                 #ifdef CONFIG_SDIO_HCI
10653                                 addr = EEPROM_MAC_ADDR_8821AS;
10654                 #endif
10655                 #ifdef CONFIG_PCI_HCI
10656                                 addr = EEPROM_MAC_ADDR_8821AE;
10657                 #endif
10658                 #ifdef CONFIG_USB_HCI
10659                                 addr = EEPROM_MAC_ADDR_8821AU;
10660                 #endif
10661                 
10662                 #endif // CONFIG_RTL8812A/CONFIG_RTL8821A
10663                 
10664                 cnts = strlen(tmp[1]);
10665                 if (cnts%2)
10666                 {
10667                         err = -EINVAL;
10668                         goto exit;
10669                 }
10670                 cnts /= 2;
10671                 if (cnts == 0)
10672                 {
10673                         err = -EINVAL;
10674                         goto exit;
10675                 }
10676                 if (cnts > 6)
10677                 {
10678                         DBG_871X("%s: error data for mac addr=\"%s\"\n", __FUNCTION__, tmp[1]);
10679                         err = -EFAULT;
10680                         goto exit;
10681                 }
10682
10683                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10684                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10685                 DBG_871X("%s: MAC address=%s\n", __FUNCTION__, tmp[1]);
10686
10687                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
10688                 {
10689                         setdata[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
10690                 }
10691 #ifndef CONFIG_RTL8188E
10692                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
10693 #else
10694                 //Change to check TYPE_EFUSE_MAP_LEN ,beacuse 8188E raw 256,logic map over 256.
10695                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_EFUSE_MAP_LEN, (PVOID)&max_available_size, _FALSE);
10696 #endif
10697                 if ((addr+cnts) > max_available_size)
10698                 {
10699                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
10700                         err = -EFAULT;
10701                         goto exit;
10702                 }
10703
10704                 if (rtw_efuse_map_write(padapter, addr, cnts, setdata) == _FAIL)
10705                 {
10706                         DBG_871X("%s: rtw_efuse_map_write error!!\n", __FUNCTION__);
10707                         err = -EFAULT;
10708                         goto exit;
10709                 }
10710         }
10711         else if (strcmp(tmp[0], "vidpid") == 0)
10712         {
10713                 if (tmp[1]==NULL)
10714                 {
10715                         err = -EINVAL;
10716                         goto exit;
10717                 }
10718
10719                 // pidvid,da0b7881
10720                 #ifdef CONFIG_RTL8192C
10721                 addr = EEPROM_VID_92C;
10722                 #endif // CONFIG_RTL8192C
10723                 #ifdef CONFIG_RTL8192D
10724                         #ifdef CONFIG_USB_HCI
10725                         addr = EEPROM_VID_92DU;
10726                         #else
10727                         addr = EEPROM_VID_92DE;
10728                         #endif
10729                 #endif // CONFIG_RTL8192D
10730                 #ifdef CONFIG_RTL8723A
10731                         #ifdef CONFIG_USB_HCI
10732                         addr = EEPROM_VID_8723AU;
10733                         #endif
10734                 #endif // CONFIG_RTL8723A
10735                 #ifdef CONFIG_RTL8188E
10736                         #ifdef CONFIG_USB_HCI
10737                         addr = EEPROM_VID_88EU;
10738                         #endif
10739                         #ifdef CONFIG_PCI_HCI
10740                         addr = EEPROM_VID_88EE;
10741                         #endif
10742                 #endif // CONFIG_RTL8188E
10743
10744                 #ifdef CONFIG_RTL8192E
10745                         #ifdef CONFIG_USB_HCI
10746                         addr = EEPROM_VID_8192EU;
10747                         #endif
10748                         #ifdef CONFIG_PCI_HCI
10749                         addr = EEPROM_VID_8192EE;
10750                         #endif
10751                 #endif // CONFIG_RTL8188E
10752
10753                 #ifdef CONFIG_RTL8723B
10754                 addr = EEPROM_VID_8723BU;
10755                 #endif
10756                 
10757                 cnts = strlen(tmp[1]);
10758                 if (cnts%2)
10759                 {
10760                         err = -EINVAL;
10761                         goto exit;
10762                 }
10763                 cnts /= 2;
10764                 if (cnts == 0)
10765                 {
10766                         err = -EINVAL;
10767                         goto exit;
10768                 }
10769
10770                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10771                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10772                 DBG_871X("%s: VID/PID=%s\n", __FUNCTION__, tmp[1]);
10773
10774                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
10775                 {
10776                         setdata[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
10777                 }
10778
10779                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
10780                 if ((addr+cnts) > max_available_size)
10781                 {
10782                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
10783                         err = -EFAULT;
10784                         goto exit;
10785                 }
10786
10787                 if (rtw_efuse_map_write(padapter, addr, cnts, setdata) == _FAIL)
10788                 {
10789                         DBG_871X("%s: rtw_efuse_map_write error!!\n", __FUNCTION__);
10790                         err = -EFAULT;
10791                         goto exit;
10792                 }
10793         }
10794         else if (strcmp(tmp[0], "wldumpfake") == 0)
10795         {
10796                 if (rtw_efuse_map_read(padapter, 0, EFUSE_MAP_SIZE,  pEfuseHal->fakeEfuseModifiedMap) == _SUCCESS) {
10797                         DBG_871X("%s: WiFi hw efuse dump to Fake map success \n", __FUNCTION__); 
10798                 } else {
10799                         DBG_871X("%s: WiFi hw efuse dump to Fake map Fail \n", __FUNCTION__);
10800                         err = -EFAULT;
10801                 }
10802         }
10803         else if (strcmp(tmp[0], "btwmap") == 0)
10804         {
10805                 rtw_write8(padapter, 0xa3, 0x05); //For 8723AB ,8821S ?
10806                 BTStatus=rtw_read8(padapter, 0xa0);
10807                 DBG_871X("%s: btwmap before read 0xa0 BT Status =0x%x \n", __FUNCTION__,BTStatus);
10808                 if (BTStatus != 0x04)
10809                 {
10810                         sprintf(extra, "BT Status not Active Write FAIL\n");
10811                         goto exit;
10812                 }
10813
10814                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
10815                 {
10816                         err = -EINVAL;
10817                         goto exit;
10818                 }
10819                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
10820                 
10821                 addr=0x1ff;
10822                 rtw_write8(padapter, EFUSE_CTRL+1, (addr & 0xff));
10823                 rtw_msleep_os(10);
10824                 rtw_write8(padapter, EFUSE_CTRL+2, ((addr >> 8) & 0x03));
10825                 rtw_msleep_os(10);
10826                 rtw_write8(padapter, EFUSE_CTRL+3, 0x72);
10827                 rtw_msleep_os(10);
10828                 rtw_read8(padapter, EFUSE_CTRL);
10829
10830                 addr = simple_strtoul(tmp[1], &ptmp, 16);
10831                 addr &= 0xFFF;
10832
10833                 cnts = strlen(tmp[2]);
10834                 if (cnts%2)
10835                 {
10836                         err = -EINVAL;
10837                         goto exit;
10838                 }
10839                 cnts /= 2;
10840                 if (cnts == 0)
10841                 {
10842                         err = -EINVAL;
10843                         goto exit;
10844                 }
10845
10846                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10847                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10848                 DBG_871X("%s: BT data=%s\n", __FUNCTION__, tmp[2]);
10849
10850                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
10851                 {
10852                         setdata[jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
10853                 }
10854
10855                 EFUSE_GetEfuseDefinition(padapter, EFUSE_BT, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
10856                 if ((addr+cnts) > max_available_size)
10857                 {
10858                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
10859                         err = -EFAULT;
10860                         goto exit;
10861                 }
10862
10863                 if (rtw_BT_efuse_map_write(padapter, addr, cnts, setdata) == _FAIL)
10864                 {
10865                         DBG_871X("%s: rtw_BT_efuse_map_write error!!\n", __FUNCTION__);
10866                         err = -EFAULT;
10867                         goto exit;
10868                 }
10869                 *extra = 0;
10870                 DBG_871X("%s: after rtw_BT_efuse_map_write to _rtw_memcmp \n", __FUNCTION__);
10871                 if ( (rtw_BT_efuse_map_read(padapter, addr, cnts, ShadowMapBT ) == _SUCCESS ) )
10872                 {
10873                         if (_rtw_memcmp((void*)ShadowMapBT ,(void*)setdata,cnts))
10874                         { 
10875                                 DBG_871X("%s: BT write map compare OK BTStatus=0x%x\n", __FUNCTION__,BTStatus);
10876                                 sprintf(extra, "BT write map compare OK");
10877                                 err = 0;
10878                                 goto exit;
10879                         }
10880                         else
10881                         {
10882                                 sprintf(extra, "BT write map compare FAIL");
10883                                 DBG_871X("%s: BT write map compare FAIL BTStatus=0x%x\n", __FUNCTION__,BTStatus);
10884                                 err = 0;
10885                                 goto exit;
10886                         }
10887                 }
10888         }
10889         else if (strcmp(tmp[0], "btwfake") == 0)
10890         {
10891                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
10892                 {
10893                         err = -EINVAL;
10894                         goto exit;
10895                 }
10896
10897                 addr = simple_strtoul(tmp[1], &ptmp, 16);
10898                 addr &= 0xFFF;
10899
10900                 cnts = strlen(tmp[2]);
10901                 if (cnts%2)
10902                 {
10903                         err = -EINVAL;
10904                         goto exit;
10905                 }
10906                 cnts /= 2;
10907                 if (cnts == 0)
10908                 {
10909                         err = -EINVAL;
10910                         goto exit;
10911                 }
10912
10913                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10914                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10915                 DBG_871X("%s: BT tmp data=%s\n", __FUNCTION__, tmp[2]);
10916                                 
10917                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
10918                 {
10919                         pEfuseHal->fakeBTEfuseModifiedMap[addr+jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
10920                 }
10921         }
10922         else if (strcmp(tmp[0], "btdumpfake") == 0)
10923         {
10924                 if (rtw_BT_efuse_map_read(padapter, 0, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseModifiedMap) == _SUCCESS) {
10925                         DBG_871X("%s: BT read all map success\n", __FUNCTION__);
10926                 } else {
10927                         DBG_871X("%s: BT read all map Fail!\n", __FUNCTION__);
10928                         err = -EFAULT;
10929                 }
10930         }
10931         else if (strcmp(tmp[0], "btfk2map") == 0)
10932         {
10933                 rtw_write8(padapter, 0xa3, 0x05);
10934                 BTStatus=rtw_read8(padapter, 0xa0);
10935                 DBG_871X("%s: btwmap before read 0xa0 BT Status =0x%x \n", __FUNCTION__,BTStatus);
10936                 if (BTStatus != 0x04)
10937                 {
10938                         sprintf(extra, "BT Status not Active Write FAIL\n");
10939                         goto exit;
10940                 }
10941                 
10942                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
10943
10944                 addr=0x1ff;
10945                 rtw_write8(padapter, EFUSE_CTRL+1, (addr & 0xff));
10946                 rtw_msleep_os(10);
10947                 rtw_write8(padapter, EFUSE_CTRL+2, ((addr >> 8) & 0x03));
10948                 rtw_msleep_os(10);
10949                 rtw_write8(padapter, EFUSE_CTRL+3, 0x72);
10950                 rtw_msleep_os(10);
10951                 rtw_read8(padapter, EFUSE_CTRL);
10952
10953                 _rtw_memcpy(pEfuseHal->BTEfuseModifiedMap, pEfuseHal->fakeBTEfuseModifiedMap, EFUSE_BT_MAX_MAP_LEN);
10954                         
10955                 EFUSE_GetEfuseDefinition(padapter, EFUSE_BT, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);     
10956                 if (max_available_size < 1)
10957                 {
10958                         err = -EFAULT;
10959                         goto exit;
10960                 }
10961
10962                 if (rtw_BT_efuse_map_write(padapter, 0x00, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseModifiedMap) == _FAIL)
10963                 {
10964                         DBG_871X("%s: rtw_BT_efuse_map_write error!\n", __FUNCTION__);
10965                         err = -EFAULT;
10966                         goto exit;
10967                 }
10968                 
10969                 DBG_871X("pEfuseHal->fakeBTEfuseModifiedMap OFFSET\tVALUE(hex)\n");
10970                 for (i = 0; i < EFUSE_BT_MAX_MAP_LEN; i += 16)
10971                 {
10972                         printk("0x%02x\t", i);
10973                         for (j=0; j<8; j++) {
10974                                 printk("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10975                         }
10976                         printk("\t");
10977
10978                         for (; j<16; j++) {
10979                                 printk("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10980                         }
10981                         printk("\n");
10982                 }
10983                 printk("\n");
10984 #if 1           
10985                 err = -EFAULT;
10986                 DBG_871X("%s: rtw_BT_efuse_map_read _rtw_memcmp \n", __FUNCTION__);
10987                 if ( (rtw_BT_efuse_map_read(padapter, 0x00, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseInitMap) == _SUCCESS ) )
10988                 { 
10989                         if (_rtw_memcmp((void*)pEfuseHal->fakeBTEfuseModifiedMap,(void*)pEfuseHal->fakeBTEfuseInitMap,EFUSE_BT_MAX_MAP_LEN))
10990                         { 
10991                                 sprintf(extra, "BT write map compare OK");
10992                                 DBG_871X("%s: BT write map afterf compare success BTStatus=0x%x \n", __FUNCTION__,BTStatus);
10993                                 err = 0;
10994                                 goto exit;
10995                         }
10996                         else
10997                         {
10998                                 sprintf(extra, "BT write map compare FAIL");
10999                                 if (rtw_BT_efuse_map_write(padapter, 0x00, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseModifiedMap) == _FAIL)
11000                                 {
11001                                         DBG_871X("%s: rtw_BT_efuse_map_write compare error,retry = %d!\n", __FUNCTION__,i);
11002                                 }
11003
11004                                 if (rtw_BT_efuse_map_read(padapter, EFUSE_BT, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseInitMap) == _SUCCESS)
11005                                 {
11006                                         DBG_871X("pEfuseHal->fakeBTEfuseInitMap OFFSET\tVALUE(hex)\n");
11007
11008                                         for (i = 0; i < EFUSE_BT_MAX_MAP_LEN; i += 16)
11009                                         {
11010                                                 printk("0x%02x\t", i);
11011                                                 for (j=0; j<8; j++) {
11012                                                         printk("%02X ", pEfuseHal->fakeBTEfuseInitMap[i+j]);
11013                                                 }
11014                                                 printk("\t");
11015                                                 for (; j<16; j++) {
11016                                                         printk("%02X ", pEfuseHal->fakeBTEfuseInitMap[i+j]);
11017                                                 }
11018                                                 printk("\n");
11019                                         }
11020                                         printk("\n"); 
11021                                 }
11022                                 DBG_871X("%s: BT write map afterf compare not match to write efuse try write Map again , BTStatus=0x%x\n", __FUNCTION__,BTStatus);      
11023                                 goto exit;
11024                         }
11025                 }
11026 #endif
11027
11028         }
11029         else if (strcmp(tmp[0], "wlfk2map") == 0)
11030         {
11031                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);                                   
11032                 if (max_available_size < 1)
11033                 {
11034                         err = -EFAULT;
11035                         goto exit;
11036                 }
11037                 if (rtw_efuse_map_write(padapter, 0x00, EFUSE_MAP_SIZE, pEfuseHal->fakeEfuseModifiedMap) == _FAIL)
11038                 {
11039                         DBG_871X("%s: rtw_efuse_map_write fakeEfuseModifiedMap error!\n", __FUNCTION__);
11040                         err = -EFAULT;
11041                         goto exit;
11042                 }
11043                 *extra = 0;
11044                 DBG_871X("%s: after rtw_BT_efuse_map_write to _rtw_memcmp \n", __FUNCTION__);
11045                 if ( (rtw_efuse_map_read(padapter, 0x00, EFUSE_MAP_SIZE, ShadowMapWiFi) == _SUCCESS ) )
11046                 {
11047                         if (_rtw_memcmp((void*)ShadowMapWiFi ,(void*)setdata,cnts))
11048                         {
11049                                 DBG_871X("%s: WiFi write map afterf compare OK\n", __FUNCTION__);
11050                                 sprintf(extra, "WiFi write map compare OK\n");
11051                                 err = 0;
11052                                 goto exit;
11053                         }
11054                         else
11055                         {
11056                                 sprintf(extra, "WiFi write map compare FAIL\n");
11057                                 DBG_871X("%s: WiFi write map compare Fail\n", __FUNCTION__);
11058                                 err = 0;
11059                                 goto exit;
11060                         }
11061                 }
11062         }
11063         else if (strcmp(tmp[0], "wlwfake") == 0)
11064         {
11065                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
11066                 {
11067                         err = -EINVAL;
11068                         goto exit;
11069                 }
11070
11071                 addr = simple_strtoul(tmp[1], &ptmp, 16);
11072                 addr &= 0xFFF;
11073
11074                 cnts = strlen(tmp[2]);
11075                 if (cnts%2)
11076                 {
11077                         err = -EINVAL;
11078                         goto exit;
11079                 }
11080                 cnts /= 2;
11081                 if (cnts == 0)
11082                 {
11083                         err = -EINVAL;
11084                         goto exit;
11085                 }
11086
11087                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
11088                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
11089                 DBG_871X("%s: map tmp data=%s\n", __FUNCTION__, tmp[2]);
11090
11091                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
11092                 {
11093                         pEfuseHal->fakeEfuseModifiedMap[addr+jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
11094                 }
11095         }
11096
11097 exit:
11098         if (setdata)
11099                 rtw_mfree(setdata, 1024);
11100         if (ShadowMapBT)
11101                 rtw_mfree(ShadowMapBT, EFUSE_BT_MAX_MAP_LEN);
11102         if (ShadowMapWiFi)
11103                 rtw_mfree(ShadowMapWiFi, EFUSE_MAP_SIZE);
11104         if (setrawdata)
11105                 rtw_mfree(setrawdata, EFUSE_MAX_SIZE);
11106         
11107         wrqu->length = strlen(extra);
11108
11109         if (padapter->registrypriv.mp_mode == 0)
11110         {
11111         #ifdef CONFIG_IPS               
11112         rtw_pm_set_ips(padapter, ips_mode);
11113         #endif // CONFIG_IPS
11114
11115         #ifdef CONFIG_LPS       
11116         rtw_pm_set_lps(padapter, lps_mode);
11117         #endif // CONFIG_LPS
11118         }
11119
11120         return err;
11121 }
11122
11123 #if defined(CONFIG_MP_INCLUDED) && defined(CONFIG_MP_IWPRIV_SUPPORT)
11124 /*
11125  * Input Format: %s,%d,%d
11126  *      %s is width, could be
11127  *              "b" for 1 byte
11128  *              "w" for WORD (2 bytes)
11129  *              "dw" for DWORD (4 bytes)
11130  *      1st %d is address(offset)
11131  *      2st %d is data to write
11132  */
11133 static int rtw_mp_write_reg(struct net_device *dev,
11134                         struct iw_request_info *info,
11135                         struct iw_point *wrqu, char *extra)
11136 {
11137         char *pch, *pnext, *ptmp;
11138         char *width_str;
11139         char width;
11140         u32 addr, data;
11141         int ret;
11142         PADAPTER padapter = rtw_netdev_priv(dev);
11143         char input[wrqu->length];
11144
11145         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11146                                  return -EFAULT;
11147                                  
11148         _rtw_memset(extra, 0, wrqu->length);    
11149           
11150         pch = input;
11151
11152         pnext = strpbrk(pch, " ,.-");
11153         if (pnext == NULL) return -EINVAL;
11154         *pnext = 0;
11155         width_str = pch;
11156
11157         pch = pnext + 1;
11158         pnext = strpbrk(pch, " ,.-");
11159         if (pnext == NULL) return -EINVAL;
11160         *pnext = 0;
11161         addr = simple_strtoul(pch, &ptmp, 16);
11162         if (addr > 0x3FFF) return -EINVAL;
11163
11164         pch = pnext + 1;
11165         if ((pch - extra) >= wrqu->length) return -EINVAL;
11166         data = simple_strtoul(pch, &ptmp, 16);
11167
11168         ret = 0;
11169         width = width_str[0];
11170         switch (width) {
11171                 case 'b':
11172                         // 1 byte
11173                         if (data > 0xFF) {
11174                                 ret = -EINVAL;
11175                                 break;
11176                         }
11177                         rtw_write8(padapter, addr, data);
11178                         break;
11179                 case 'w':
11180                         // 2 bytes
11181                         if (data > 0xFFFF) {
11182                                 ret = -EINVAL;
11183                                 break;
11184                         }
11185                         rtw_write16(padapter, addr, data);
11186                         break;
11187                 case 'd':
11188                         // 4 bytes
11189                         rtw_write32(padapter, addr, data);
11190                         break;
11191                 default:
11192                         ret = -EINVAL;
11193                         break;
11194         }
11195
11196         return ret;
11197 }
11198
11199 /*
11200  * Input Format: %s,%d
11201  *      %s is width, could be
11202  *              "b" for 1 byte
11203  *              "w" for WORD (2 bytes)
11204  *              "dw" for DWORD (4 bytes)
11205  *      %d is address(offset)
11206  *
11207  * Return:
11208  *      %d for data readed
11209  */
11210 static int rtw_mp_read_reg(struct net_device *dev,
11211                         struct iw_request_info *info,
11212                         struct iw_point *wrqu, char *extra)
11213 {
11214         char input[wrqu->length];
11215         char *pch, *pnext, *ptmp;
11216         char *width_str;
11217         char width;
11218         char data[20],tmp[20];
11219         u32 addr;
11220         //u32 *data = (u32*)extra;
11221         u32 ret, i=0, j=0, strtout=0;
11222         PADAPTER padapter = rtw_netdev_priv(dev);
11223
11224
11225         if (wrqu->length > 128) 
11226                 return -EFAULT;
11227
11228         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11229                 return -EFAULT;
11230
11231         _rtw_memset(data, 0, 20);
11232         _rtw_memset(tmp, 0, 20);
11233         _rtw_memset(extra, 0, wrqu->length);
11234
11235         pch = input;
11236         pnext = strpbrk(pch, " ,.-");
11237         if (pnext == NULL) return -EINVAL;
11238         *pnext = 0;
11239         width_str = pch;
11240
11241         pch = pnext + 1;
11242         if ((pch - input) >= wrqu->length) return -EINVAL;
11243         
11244         addr = simple_strtoul(pch, &ptmp, 16);
11245         if (addr > 0x3FFF) return -EINVAL;
11246
11247         ret = 0;
11248         width = width_str[0];
11249         switch (width)
11250         {
11251                 case 'b':
11252                         // 1 byte
11253                         // *(u8*)data = rtw_read8(padapter, addr);
11254                         sprintf(extra, "%d\n",  rtw_read8(padapter, addr));
11255                         wrqu->length = strlen(extra);
11256                         break;
11257                 case 'w':
11258                         // 2 bytes
11259                         //*(u16*)data = rtw_read16(padapter, addr);
11260                         sprintf(data, "%04x\n", rtw_read16(padapter, addr));
11261                         for( i=0 ; i <= strlen(data) ; i++)
11262                                 {
11263                                           if( i%2==0 )
11264                                           {
11265                                                    tmp[j]=' ';
11266                                                    j++;
11267                                           }
11268                                           if ( data[i] != '\0' )
11269                                                  tmp[j] = data[i];
11270                                                 
11271                                                  j++;
11272                                 }
11273                                 pch = tmp;              
11274                                 DBG_871X("pch=%s",pch);
11275                                 
11276                                 while( *pch != '\0' )
11277                                 {
11278                                         pnext = strpbrk(pch, " ");
11279                                         if (!pnext)
11280                                                 break;
11281                                         
11282                                         pnext++;
11283                                         if ( *pnext != '\0' )
11284                                         {
11285                                                   strtout = simple_strtoul (pnext , &ptmp, 16);
11286                                                   sprintf( extra, "%s %d" ,extra ,strtout );
11287                                         }
11288                                         else{
11289                                                   break;
11290                                         }
11291                                         pch = pnext;
11292                                 }
11293                         wrqu->length = 7;
11294                         break;
11295                 case 'd':
11296                         // 4 bytes
11297                         //*data = rtw_read32(padapter, addr);
11298                         sprintf(data, "%08x", rtw_read32(padapter, addr));
11299                                 //add read data format blank
11300                                 for( i=0 ; i <= strlen(data) ; i++)
11301                                 {
11302                                           if( i%2==0 )
11303                                           {
11304                                                    tmp[j]=' ';
11305                                                    j++;
11306                                           }
11307                                           if ( data[i] != '\0' )
11308                                           tmp[j] = data[i];
11309                                           
11310                                           j++;
11311                                 }
11312                                 pch = tmp;              
11313                                 DBG_871X("pch=%s",pch);
11314                                 
11315                                 while( *pch != '\0' )
11316                                 {
11317                                         pnext = strpbrk(pch, " ");
11318                                         if (!pnext)
11319                                                 break;
11320                                         
11321                                         pnext++;
11322                                         if ( *pnext != '\0' )
11323                                         {
11324                                                   strtout = simple_strtoul (pnext , &ptmp, 16);
11325                                                   sprintf( extra, "%s %d" ,extra ,strtout );
11326                                         }
11327                                         else{
11328                         break;
11329                                         }
11330                                         pch = pnext;
11331                                 }
11332                         wrqu->length = strlen(extra);
11333                         break;
11334                         
11335                 default:
11336                         wrqu->length = 0;
11337                         ret = -EINVAL;
11338                         break;
11339                         
11340         }
11341
11342         return ret;
11343 }
11344
11345 /*
11346  * Input Format: %d,%x,%x
11347  *      %d is RF path, should be smaller than MAX_RF_PATH_NUMS
11348  *      1st %x is address(offset)
11349  *      2st %x is data to write
11350  */
11351  static int rtw_mp_write_rf(struct net_device *dev,
11352                         struct iw_request_info *info,
11353                         struct iw_point *wrqu, char *extra)
11354 {                       
11355 /*static int rtw_mp_write_rf(struct net_device *dev,
11356                         struct iw_request_info *info,
11357                         union iwreq_data *wrqu, char *extra)
11358 */
11359         u32 path, addr, data;
11360         int ret;
11361         PADAPTER padapter = rtw_netdev_priv(dev);
11362         char input[wrqu->length];
11363
11364         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11365                          return -EFAULT;
11366
11367
11368         ret = sscanf(input, "%d,%x,%x", &path, &addr, &data);
11369         if (ret < 3) return -EINVAL;
11370
11371         if (path >= GET_HAL_RFPATH_NUM(padapter)) return -EINVAL;
11372         if (addr > 0xFF) return -EINVAL;
11373         if (data > 0xFFFFF) return -EINVAL;
11374         
11375         _rtw_memset(extra, 0, wrqu->length);
11376         
11377         write_rfreg(padapter, path, addr, data);
11378         
11379         sprintf(extra, "write_rf completed \n");
11380         wrqu->length = strlen(extra);
11381         
11382         return 0;
11383 }
11384
11385 /*
11386  * Input Format: %d,%x
11387  *      %d is RF path, should be smaller than MAX_RF_PATH_NUMS
11388  *      %x is address(offset)
11389  *
11390  * Return:
11391  *      %d for data readed
11392  */
11393 static int rtw_mp_read_rf(struct net_device *dev,
11394                         struct iw_request_info *info,
11395                         struct iw_point *wrqu, char *extra)
11396 {
11397         char input[wrqu->length];
11398         char *pch, *pnext, *ptmp;
11399         char data[20],tmp[20];
11400         //u32 *data = (u32*)extra;
11401         u32 path, addr;
11402         u32 ret,i=0 ,j=0,strtou=0;
11403         PADAPTER padapter = rtw_netdev_priv(dev);
11404
11405
11406         if (wrqu->length > 128) return -EFAULT;
11407         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11408                 return -EFAULT;
11409
11410         ret = sscanf(input, "%d,%x", &path, &addr);
11411         if (ret < 2) return -EINVAL;
11412
11413         if (path >= GET_HAL_RFPATH_NUM(padapter)) return -EINVAL;
11414         if (addr > 0xFF) return -EINVAL;
11415         
11416         _rtw_memset(extra, 0, wrqu->length);
11417         
11418         //*data = read_rfreg(padapter, path, addr);
11419         sprintf(data, "%08x", read_rfreg(padapter, path, addr));
11420                                 //add read data format blank
11421                                 for( i=0 ; i <= strlen(data) ; i++)
11422                                 {
11423                                           if( i%2==0 )
11424                                           {
11425                                                    tmp[j]=' ';
11426                                                    j++;
11427                                           }
11428                                           tmp[j] = data[i];
11429                                           j++;
11430                                 }
11431                                 pch = tmp;              
11432                                 DBG_871X("pch=%s",pch);
11433                                 
11434                                 while( *pch != '\0' )
11435                                 {
11436                                         pnext = strpbrk(pch, " ");
11437                                         if (!pnext)
11438                                                 break;
11439                                         pnext++;
11440                                         if ( *pnext != '\0' )
11441                                         {
11442                                                   strtou = simple_strtoul (pnext , &ptmp, 16);
11443                                                   sprintf( extra, "%s %d" ,extra ,strtou );
11444                                         }
11445                                         else{
11446                                                   break;
11447                                         }
11448                                         pch = pnext;
11449                                 }
11450                         wrqu->length = strlen(extra);   
11451
11452         return 0;
11453 }
11454
11455 static int rtw_mp_start(struct net_device *dev,
11456                         struct iw_request_info *info,
11457                         struct iw_point *wrqu, char *extra)
11458 {
11459         u8 val8;
11460         PADAPTER padapter = rtw_netdev_priv(dev);
11461         HAL_DATA_TYPE   *pHalData = GET_HAL_DATA(padapter);
11462         struct dm_priv  *pdmpriv = &pHalData->dmpriv;
11463         struct hal_ops *pHalFunc = &padapter->HalFunc;
11464
11465         rtw_pm_set_ips(padapter,IPS_NONE);
11466         LeaveAllPowerSaveMode(padapter);
11467
11468         if(padapter->registrypriv.mp_mode ==0)
11469         {
11470
11471 #ifdef CONFIG_BT_COEXIST
11472                 pdmpriv->DMFlag &= ~DYNAMIC_FUNC_BT;
11473 #endif          
11474                 pHalFunc->hal_deinit(padapter);
11475                 padapter->registrypriv.mp_mode =1;
11476                 pHalFunc->hal_init(padapter);
11477
11478                 rtw_pm_set_ips(padapter,IPS_NONE);
11479                 LeaveAllPowerSaveMode(padapter);
11480         }
11481
11482         if (padapter->registrypriv.mp_mode == 0)
11483                 return -EPERM;
11484
11485         if (padapter->mppriv.mode == MP_OFF) {
11486                 if (mp_start_test(padapter) == _FAIL)
11487                         return -EPERM;
11488                 padapter->mppriv.mode = MP_ON;
11489                 MPT_PwrCtlDM(padapter,0);
11490         }
11491         padapter->mppriv.bmac_filter = _FALSE;
11492 #ifdef CONFIG_RTL8723B
11493 #ifdef CONFIG_USB_HCI
11494         rtw_write32(padapter, 0x765, 0x0000);
11495         rtw_write32(padapter, 0x948, 0x0280);
11496 #else
11497         rtw_write32(padapter, 0x765, 0x0000);
11498         rtw_write32(padapter, 0x948, 0x0000);
11499 #endif  
11500 #ifdef CONFIG_FOR_RTL8723BS_VQ0
11501         rtw_write32(padapter, 0x765, 0x0000);
11502         rtw_write32(padapter, 0x948, 0x0280);
11503 #endif
11504         rtw_write8(padapter, 0x66, 0x27); //Open BT uart Log
11505         rtw_write8(padapter, 0xc50, 0x20); //for RX init Gain
11506 #endif  
11507         ODM_Write_DIG(&pHalData->odmpriv,0x20);
11508
11509         return 0;
11510 }
11511
11512 static int rtw_mp_stop(struct net_device *dev,
11513                         struct iw_request_info *info,
11514                         struct iw_point *wrqu, char *extra)
11515 {
11516         PADAPTER padapter = rtw_netdev_priv(dev);
11517         struct hal_ops *pHalFunc = &padapter->HalFunc;
11518
11519         if(padapter->registrypriv.mp_mode ==1)
11520         {
11521                 
11522                 MPT_DeInitAdapter(padapter);
11523                 pHalFunc->hal_deinit(padapter);
11524                 padapter->registrypriv.mp_mode=0;
11525                 pHalFunc->hal_init(padapter);
11526         }
11527         
11528         if (padapter->mppriv.mode != MP_OFF) {
11529                 mp_stop_test(padapter);
11530                 padapter->mppriv.mode = MP_OFF;
11531         }
11532
11533         return 0;
11534 }
11535
11536 extern int wifirate2_ratetbl_inx(unsigned char rate);
11537
11538 static int rtw_mp_rate(struct net_device *dev,
11539                         struct iw_request_info *info,
11540                         struct iw_point *wrqu, char *extra)
11541 {
11542         u32 rate = MPT_RATE_1M;
11543         u8              input[wrqu->length];
11544         PADAPTER padapter = rtw_netdev_priv(dev);
11545
11546         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11547                         return -EFAULT;
11548                         
11549         rate = rtw_mpRateParseFunc(padapter,input);
11550
11551         if (rate ==0 && strcmp(input,"1M")!=0)
11552         {
11553         rate = rtw_atoi(input); 
11554         if(rate <= 0x7f)
11555                 rate = wifirate2_ratetbl_inx( (u8)rate);        
11556         else if (rate < 0xC8)
11557                 rate =(rate - 0x80 + MPT_RATE_MCS0);
11558                 //HT  rate 0x80(MCS0)  ~ 0x8F(MCS15) ~ 0x9F(MCS31) 128~159 
11559         //VHT1SS~2SS rate 0xA0 (VHT1SS_MCS0 44) ~ 0xB3 (VHT2SS_MCS9 #63) 160~179
11560         //VHT rate 0xB4 (VHT3SS_MCS0 64) ~ 0xC7 (VHT2SS_MCS9 #83) 180~199 
11561         //else
11562                 //VHT rate 0x90(VHT1SS_MCS0) ~ 0x99(VHT1SS_MCS9) 144~153
11563         //      rate =(rate - MPT_RATE_VHT1SS_MCS0); 
11564         }
11565         _rtw_memset(extra, 0, wrqu->length);
11566
11567         sprintf( extra, "Set data rate to %s index %d" ,input,rate );
11568         DBG_871X("%s: %s rate index=%d \n", __func__,input,rate);
11569         
11570         if (rate >= MPT_RATE_LAST )     
11571         return -EINVAL;
11572
11573         padapter->mppriv.rateidx = rate;
11574         Hal_SetDataRate(padapter);
11575         
11576         wrqu->length = strlen(extra);
11577         return 0;
11578 }
11579
11580 static int rtw_mp_channel(struct net_device *dev,
11581                         struct iw_request_info *info,
11582                         struct iw_point *wrqu, char *extra)
11583 {
11584
11585         PADAPTER padapter = rtw_netdev_priv(dev);
11586         HAL_DATA_TYPE   *pHalData       = GET_HAL_DATA(padapter);
11587         u8              input[wrqu->length];
11588         u32     channel = 1;
11589         int cur_ch_offset;
11590
11591         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11592                         return -EFAULT;
11593         
11594         channel = rtw_atoi(input);
11595         //DBG_871X("%s: channel=%d\n", __func__, channel);
11596         _rtw_memset(extra, 0, wrqu->length);
11597         sprintf( extra, "Change channel %d to channel %d", padapter->mppriv.channel , channel );
11598         padapter->mppriv.channel = channel;
11599         Hal_SetChannel(padapter);
11600         pHalData->CurrentChannel = channel;
11601
11602         wrqu->length = strlen(extra);
11603         return 0;
11604 }
11605
11606 static int rtw_mp_bandwidth(struct net_device *dev,
11607                         struct iw_request_info *info,
11608                         struct iw_point *wrqu, char *extra)
11609 {
11610         u32 bandwidth=0, sg=0;
11611         int cur_ch_offset;
11612         //u8 buffer[40];
11613         PADAPTER padapter = rtw_netdev_priv(dev);
11614         HAL_DATA_TYPE   *pHalData       = GET_HAL_DATA(padapter);
11615         //if (copy_from_user(buffer, (void*)wrqu->data.pointer, wrqu->data.length))
11616     //            return -EFAULT;
11617                 
11618         //DBG_871X("%s:iwpriv in=%s\n", __func__, extra);
11619         
11620         sscanf(extra, "40M=%d,shortGI=%d", &bandwidth, &sg);
11621         
11622         if (bandwidth == 1)
11623                 bandwidth=CHANNEL_WIDTH_40;
11624         else if (bandwidth == 2)
11625                 bandwidth=CHANNEL_WIDTH_80;
11626         DBG_871X("%s: bw=%d sg=%d \n", __func__, bandwidth , sg);
11627         
11628         padapter->mppriv.bandwidth = (u8)bandwidth;
11629         padapter->mppriv.preamble = sg;
11630         
11631         SetBandwidth(padapter);
11632         pHalData->CurrentChannelBW = bandwidth;
11633         //cur_ch_offset =  rtw_get_offset_by_ch(padapter->mppriv.channel);
11634         //set_channel_bwmode(padapter, padapter->mppriv.channel, cur_ch_offset, bandwidth);
11635
11636         return 0;
11637 }
11638
11639
11640 static int rtw_mp_txpower_index(struct net_device *dev,
11641                         struct iw_request_info *info,
11642                         struct iw_point *wrqu, char *extra)
11643 {
11644         PADAPTER padapter = rtw_netdev_priv(dev);
11645         char input[wrqu->length];
11646         u32 rfpath;
11647         u32 txpower_inx;
11648
11649         if (wrqu->length > 128)
11650                 return -EFAULT;
11651
11652         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11653                 return -EFAULT;
11654
11655         rfpath = rtw_atoi(input);
11656         txpower_inx = mpt_ProQueryCalTxPower(padapter, rfpath);
11657         sprintf(extra, " %d", txpower_inx);
11658         wrqu->length = strlen(extra);
11659
11660         return 0;
11661 }
11662
11663
11664 static int rtw_mp_txpower(struct net_device *dev,
11665                         struct iw_request_info *info,
11666                         struct iw_point *wrqu, char *extra)
11667 {
11668         u32             idx_a=0,idx_b=0,MsetPower=1;
11669         u8              input[wrqu->length];
11670
11671         PADAPTER padapter = rtw_netdev_priv(dev);
11672
11673         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11674                         return -EFAULT;
11675
11676         MsetPower = strncmp(input, "off", 3); 
11677         sscanf(input,"patha=%d,pathb=%d",&idx_a,&idx_b);
11678         //DBG_871X("%s: tx_pwr_idx_a=%x b=%x\n", __func__, idx_a, idx_b);
11679         if(MsetPower==0)
11680         {
11681                 padapter->mppriv.bSetTxPower = 0;
11682                 sprintf( extra, "MP Set power off");
11683         }
11684         else
11685         {
11686         sprintf( extra, "Set power level path_A:%d path_B:%d", idx_a , idx_b );
11687         padapter->mppriv.txpoweridx = (u8)idx_a;
11688         padapter->mppriv.txpoweridx_b = (u8)idx_b;
11689         padapter->mppriv.bSetTxPower = 1;
11690                 Hal_SetAntennaPathPower(padapter);
11691         }
11692         wrqu->length = strlen(extra);
11693         return 0;
11694 }
11695
11696 static int rtw_mp_ant_tx(struct net_device *dev,
11697                         struct iw_request_info *info,
11698                         struct iw_point *wrqu, char *extra)
11699 {
11700         u8 i;
11701         u8              input[wrqu->length];
11702         u16 antenna = 0;
11703         PADAPTER padapter = rtw_netdev_priv(dev);
11704
11705         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11706                         return -EFAULT;
11707                         
11708         //DBG_871X("%s: input=%s\n", __func__, input);  
11709         
11710         sprintf( extra, "switch Tx antenna to %s", input);
11711         
11712         for (i=0; i < strlen(input); i++)
11713         {
11714                 switch(input[i])
11715                         {
11716                                 case 'a' :
11717                                                                 antenna|=ANTENNA_A;
11718                                                                 break;
11719                                 case 'b':
11720                                                                 antenna|=ANTENNA_B;
11721                                                                 break;
11722                         }
11723         }
11724         //antenna |= BIT(extra[i]-'a');
11725         //DBG_871X("%s: antenna=0x%x\n", __func__, antenna);            
11726         padapter->mppriv.antenna_tx = antenna;
11727         padapter->mppriv.antenna_rx = antenna;
11728         //DBG_871X("%s:mppriv.antenna_rx=%d\n", __func__, padapter->mppriv.antenna_tx);
11729         
11730         Hal_SetAntenna(padapter);
11731
11732         wrqu->length = strlen(extra);
11733         return 0;
11734 }
11735
11736 static int rtw_mp_ant_rx(struct net_device *dev,
11737                         struct iw_request_info *info,
11738                         struct iw_point *wrqu, char *extra)
11739 {
11740         u8 i;
11741         u16 antenna = 0;
11742         u8              input[wrqu->length];
11743         PADAPTER padapter = rtw_netdev_priv(dev);
11744
11745         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11746                         return -EFAULT;
11747         //DBG_871X("%s: input=%s\n", __func__, input);
11748         _rtw_memset(extra, 0, wrqu->length);
11749         
11750         sprintf( extra, "switch Rx antenna to %s", input );
11751         
11752         for (i=0; i < strlen(input); i++) {
11753         switch( input[i] )
11754                         {
11755                                 case 'a' :
11756                                                                 antenna|=ANTENNA_A;
11757                                                                 break;
11758                                 case 'b':
11759                                                                 antenna|=ANTENNA_B;
11760                                                                 break;
11761                                 case 'c' :
11762                                                                 antenna|=ANTENNA_C;
11763                                                                 break;
11764                         }
11765         }
11766         
11767         //DBG_871X("%s: antenna=0x%x\n", __func__, antenna);            
11768         padapter->mppriv.antenna_tx = antenna;
11769         padapter->mppriv.antenna_rx = antenna;
11770         //DBG_871X("%s:mppriv.antenna_rx=%d\n", __func__, padapter->mppriv.antenna_rx);
11771         Hal_SetAntenna(padapter);
11772         wrqu->length = strlen(extra);
11773         
11774         return 0;
11775 }
11776
11777 static int rtw_mp_ctx(struct net_device *dev,
11778                         struct iw_request_info *info,
11779                         struct iw_point *wrqu, char *extra)
11780 {
11781         u32 pkTx = 1, countPkTx = 1, cotuTx = 1, CarrSprTx = 1, scTx = 1, sgleTx = 1, stop = 1;
11782         u32 bStartTest = 1;
11783         u32 count = 0,pktinterval=0;
11784         struct mp_priv *pmp_priv;
11785         struct pkt_attrib *pattrib;
11786
11787         PADAPTER padapter = rtw_netdev_priv(dev);
11788
11789
11790         pmp_priv = &padapter->mppriv;
11791
11792         if (copy_from_user(extra, wrqu->pointer, wrqu->length))
11793                         return -EFAULT;
11794                         
11795         DBG_871X("%s: in=%s\n", __func__, extra);
11796
11797         countPkTx = strncmp(extra, "count=", 5); // strncmp TRUE is 0
11798         cotuTx = strncmp(extra, "background", 20);
11799         CarrSprTx = strncmp(extra, "background,cs", 20);
11800         scTx = strncmp(extra, "background,sc", 20);
11801         sgleTx = strncmp(extra, "background,stone", 20);
11802         pkTx = strncmp(extra, "background,pkt", 20);
11803         stop = strncmp(extra, "stop", 4);
11804         sscanf(extra, "count=%d,pkt", &count);
11805         sscanf(extra, "pktinterval=%d", &pktinterval);
11806         
11807         //DBG_871X("%s: count=%d countPkTx=%d cotuTx=%d CarrSprTx=%d scTx=%d sgleTx=%d pkTx=%d stop=%d\n", __func__, count, countPkTx, cotuTx, CarrSprTx, pkTx, sgleTx, scTx, stop);
11808         _rtw_memset(extra, '\0', sizeof(extra));
11809
11810         if( pktinterval !=0 )
11811         {
11812                 sprintf( extra, "Pkt Interval = %d",pktinterval);
11813                 padapter->mppriv.pktInterval = pktinterval;
11814                 
11815                 wrqu->length = strlen(extra);
11816                 return 0;
11817         }
11818         
11819         if (stop == 0) {
11820                 bStartTest = 0; // To set Stop
11821                 pmp_priv->tx.stop = 1;
11822                 sprintf( extra, "Stop continuous Tx");
11823         } else {
11824                 bStartTest = 1;
11825                 if (pmp_priv->mode != MP_ON) {
11826                         if (pmp_priv->tx.stop != 1) {
11827                                 DBG_871X("%s: MP_MODE != ON %d\n", __func__, pmp_priv->mode);
11828                                 return  -EFAULT;
11829                         }
11830                 }
11831         }
11832
11833         if (pkTx == 0 || countPkTx == 0)
11834                 pmp_priv->mode = MP_PACKET_TX;
11835         if (sgleTx == 0)
11836                 pmp_priv->mode = MP_SINGLE_TONE_TX;
11837         if (cotuTx == 0)
11838                 pmp_priv->mode = MP_CONTINUOUS_TX;
11839         if (CarrSprTx == 0)
11840                 pmp_priv->mode = MP_CARRIER_SUPPRISSION_TX;
11841         if (scTx == 0)
11842                 pmp_priv->mode = MP_SINGLE_CARRIER_TX;
11843
11844         switch (pmp_priv->mode)
11845         {
11846                 case MP_PACKET_TX:
11847                 
11848                         //DBG_871X("%s:pkTx %d\n", __func__,bStartTest);
11849                         if (bStartTest == 0)
11850                         {
11851                                 pmp_priv->tx.stop = 1;
11852                                 pmp_priv->mode = MP_ON;
11853                                 sprintf( extra, "Stop continuous Tx");
11854                         }
11855                         else if (pmp_priv->tx.stop == 1)
11856                         {
11857                                 sprintf( extra, "Start continuous DA=ffffffffffff len=1500 count=%u,\n",count);
11858                                 //DBG_871X("%s:countPkTx %d\n", __func__,count);
11859                                 pmp_priv->tx.stop = 0;
11860                                 pmp_priv->tx.count = count;
11861                                 pmp_priv->tx.payload = 2;
11862 #ifdef CONFIG_80211N_HT
11863                                 pmp_priv->tx.attrib.ht_en = 1;
11864 #endif
11865 #ifdef CONFIG_80211AC_VHT
11866                                 pmp_priv->tx.attrib.raid = RATEID_IDX_VHT_1SS; //10
11867 #endif
11868                                 pattrib = &pmp_priv->tx.attrib;
11869                                 pattrib->pktlen = 1000;
11870                                 _rtw_memset(pattrib->dst, 0xFF, ETH_ALEN);
11871                                 SetPacketTx(padapter);
11872                         } 
11873                         else {
11874                                 //DBG_871X("%s: pkTx not stop\n", __func__);
11875                                 return -EFAULT;
11876                         }
11877                                 wrqu->length = strlen(extra);
11878                                 return 0;
11879
11880                 case MP_SINGLE_TONE_TX:
11881                         //DBG_871X("%s: sgleTx %d \n", __func__, bStartTest);
11882                         if (bStartTest != 0){
11883                                 sprintf( extra, "Start continuous DA=ffffffffffff len=1500 \n infinite=yes.");
11884             }
11885                         Hal_SetSingleToneTx(padapter, (u8)bStartTest);
11886                         break;
11887
11888                 case MP_CONTINUOUS_TX:
11889                         //DBG_871X("%s: cotuTx %d\n", __func__, bStartTest);
11890                         if (bStartTest != 0){
11891                                 sprintf( extra, "Start continuous DA=ffffffffffff len=1500 \n infinite=yes.");
11892                          }
11893                         Hal_SetContinuousTx(padapter, (u8)bStartTest);
11894                         break;
11895
11896                 case MP_CARRIER_SUPPRISSION_TX:
11897                         //DBG_871X("%s: CarrSprTx %d\n", __func__, bStartTest);
11898                         if (bStartTest != 0){
11899                                 if( pmp_priv->rateidx <= MPT_RATE_11M ) 
11900                                 {
11901                                         sprintf( extra, "Start continuous DA=ffffffffffff len=1500 \n infinite=yes.");
11902                                         
11903                                 }else
11904                                         sprintf( extra, "Specify carrier suppression but not CCK rate");
11905                         }
11906                         Hal_SetCarrierSuppressionTx(padapter, (u8)bStartTest);
11907                         break;
11908
11909                 case MP_SINGLE_CARRIER_TX:
11910                         //DBG_871X("%s: scTx %d\n", __func__, bStartTest);
11911                         if (bStartTest != 0){
11912                                 sprintf( extra, "Start continuous DA=ffffffffffff len=1500 \n infinite=yes.");
11913                         }
11914                         Hal_SetSingleCarrierTx(padapter, (u8)bStartTest);
11915                         break;
11916
11917                 default:
11918                         //DBG_871X("%s:No Match MP_MODE\n", __func__);
11919                         sprintf( extra, "Error! Continuous-Tx is not on-going.");
11920                         return -EFAULT;
11921         }
11922
11923         if ( bStartTest==1 && pmp_priv->mode != MP_ON) {
11924                 struct mp_priv *pmp_priv = &padapter->mppriv;
11925                 if (pmp_priv->tx.stop == 0) {
11926                         pmp_priv->tx.stop = 1;
11927                         //DBG_871X("%s: pkt tx is running...\n", __func__);
11928                         rtw_msleep_os(5);
11929                 }
11930 #ifdef CONFIG_80211N_HT
11931                 pmp_priv->tx.attrib.ht_en = 1;
11932 #endif
11933 #ifdef CONFIG_80211AC_VHT
11934                 pmp_priv->tx.attrib.raid = RATEID_IDX_VHT_1SS; //10
11935 #endif
11936                 pmp_priv->tx.stop = 0;
11937                 pmp_priv->tx.count = 1;
11938                 SetPacketTx(padapter);
11939         } else {
11940                 pmp_priv->mode = MP_ON;
11941         }
11942
11943         wrqu->length = strlen(extra);
11944         return 0;
11945 }
11946
11947
11948 static int rtw_mp_disable_bt_coexist(struct net_device *dev,
11949                         struct iw_request_info *info,
11950                         union iwreq_data *wrqu, char *extra)
11951 {
11952         PADAPTER padapter = (PADAPTER)rtw_netdev_priv(dev);
11953         HAL_DATA_TYPE   *pHalData = GET_HAL_DATA(padapter);
11954         struct dm_priv  *pdmpriv = &pHalData->dmpriv;
11955         struct hal_ops *pHalFunc = &padapter->HalFunc;
11956         
11957         u8 input[wrqu->data.length];
11958         u32 bt_coexist;
11959
11960         if (copy_from_user(input, wrqu->data.pointer, wrqu->data.length))
11961                 return -EFAULT;
11962         
11963         bt_coexist = rtw_atoi(input);
11964         
11965         if( bt_coexist == 0 )
11966         {
11967                 RT_TRACE(_module_mp_, _drv_info_,
11968                         ("Set OID_RT_SET_DISABLE_BT_COEXIST: disable BT_COEXIST\n"));
11969                 DBG_871X("Set OID_RT_SET_DISABLE_BT_COEXIST: disable BT_COEXIST\n");
11970 #ifdef CONFIG_BT_COEXIST
11971                 rtw_btcoex_HaltNotify(padapter);
11972                 rtw_btcoex_SetManualControl(padapter, _TRUE);
11973                 pdmpriv->DMFlag &= ~DYNAMIC_FUNC_BT;
11974                 // Force to switch Antenna to WiFi
11975                 rtw_write16(padapter, 0x870, 0x300);
11976                 rtw_write16(padapter, 0x860, 0x110); 
11977 #endif // CONFIG_BT_COEXIST
11978         }
11979         else
11980         {
11981                 RT_TRACE(_module_mp_, _drv_info_,
11982                         ("Set OID_RT_SET_DISABLE_BT_COEXIST: enable BT_COEXIST\n"));
11983 #ifdef CONFIG_BT_COEXIST                
11984                 pdmpriv->DMFlag |= DYNAMIC_FUNC_BT;
11985                 rtw_btcoex_SetManualControl(padapter, _FALSE);
11986 #endif
11987         }
11988
11989         return 0;       
11990 }
11991
11992
11993 static int rtw_mp_arx(struct net_device *dev,
11994                         struct iw_request_info *info,
11995                         struct iw_point *wrqu, char *extra)
11996 {
11997         u8 bStartRx=0,bStopRx=0,bQueryPhy=0,bQueryMac=0,bSetBssid=0;
11998         u8 bmac_filter = 0,bfilter_init=0;
11999         u32 cckok=0,cckcrc=0,ofdmok=0,ofdmcrc=0,htok=0,htcrc=0,OFDM_FA=0,CCK_FA=0,DropPacket=0,vht_ok=0,vht_err=0;
12000         u32             mac_cck_ok=0, mac_ofdm_ok=0, mac_ht_ok=0, mac_vht_ok=0;
12001         u32             mac_cck_err=0, mac_ofdm_err=0, mac_ht_err=0, mac_vht_err=0;
12002         u8              input[wrqu->length];
12003         char *pch, *ptmp, *token, *tmp[2]={0x00,0x00};
12004         u32 i=0,ii=0,jj=0,kk=0,cnts=0,bmon=0;
12005         PADAPTER padapter = rtw_netdev_priv(dev);
12006         struct mp_priv *pmppriv = &padapter->mppriv;
12007
12008         if (copy_from_user(input, wrqu->pointer, wrqu->length))
12009                         return -EFAULT;
12010
12011         DBG_871X("%s: %s\n", __func__, input);
12012
12013         bStartRx = (strncmp(input, "start", 5)==0)?1:0; // strncmp TRUE is 0
12014         bStopRx = (strncmp(input, "stop", 5)==0)?1:0; // strncmp TRUE is 0
12015         bQueryPhy = (strncmp(input, "phy", 3)==0)?1:0; // strncmp TRUE is 0
12016         bQueryMac = (strncmp(input, "mac", 3)==0)?1:0; // strncmp TRUE is 0
12017         bSetBssid = (strncmp(input, "setbssid=", 8)==0)?1:0; // strncmp TRUE is 0
12018         //bfilter_init = (strncmp(input, "filter_init",11)==0)?1:0;
12019         bmac_filter = (strncmp(input, "accept_mac",10)==0)?1:0;
12020         bmon = (strncmp(input, "mon=",4)==0)?1:0;
12021
12022         if(bSetBssid==1){
12023                 pch = input;
12024                 while ((token = strsep(&pch, "=")) != NULL)
12025                 {
12026                         if (i > 1) break;
12027                         tmp[i] = token;
12028                         i++;
12029                 }
12030                 if ((tmp[0]==NULL) && (tmp[1]==NULL)){
12031                         return -EFAULT;
12032                 }
12033                 else{
12034                         cnts = strlen(tmp[1])/2;
12035                         if (cnts<1) return -EFAULT;
12036                         DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
12037                         DBG_871X("%s: data=%s\n", __FUNCTION__, tmp[1]);
12038                         for (jj=0, kk=0; jj < cnts ; jj++, kk+=2){
12039                                          pmppriv->network_macaddr[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
12040                                         DBG_871X("network_macaddr[%d]=%x \n",jj, pmppriv->network_macaddr[jj]);
12041                         }
12042                 }
12043                 pmppriv->bSetRxBssid = _TRUE;
12044         }
12045
12046         if(bmac_filter)
12047         {
12048                 pmppriv->bmac_filter = bmac_filter;
12049                 pch = input;
12050                 while ((token = strsep(&pch, "=")) != NULL)
12051                 {
12052                         if (i > 1) break;
12053                         tmp[i] = token;
12054                         i++;
12055                 }
12056                 if ((tmp[0]==NULL) && (tmp[1]==NULL)){
12057                         return -EFAULT;
12058                 }
12059                 else{
12060                         cnts = strlen(tmp[1])/2;
12061                         if (cnts<1) return -EFAULT;
12062                         DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
12063                         DBG_871X("%s: data=%s\n", __FUNCTION__, tmp[1]);
12064                         for (jj=0, kk=0; jj < cnts ; jj++, kk+=2){
12065                                         pmppriv->mac_filter[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
12066                                         DBG_871X("%s mac_filter[%d]=%x \n",__FUNCTION__,jj, pmppriv->mac_filter[jj]);
12067                         }
12068                 }
12069         }
12070         
12071         if(bStartRx)
12072         {
12073                 sprintf( extra, "start");
12074                 SetPacketRx(padapter, bStartRx);
12075         }
12076         else if(bStopRx)
12077         {
12078                 SetPacketRx(padapter, 0);
12079                 pmppriv->bmac_filter = _FALSE;
12080                 sprintf( extra, "Received packet OK:%d CRC error:%d ,Filter out:%d",padapter->mppriv.rx_pktcount,padapter->mppriv.rx_crcerrpktcount,padapter->mppriv.rx_pktcount_filter_out);
12081         }
12082         else if(bQueryPhy)
12083         {          
12084
12085                 if (IS_HARDWARE_TYPE_JAGUAR(padapter)) 
12086                 {
12087                         cckok      = PHY_QueryBBReg(padapter, 0xF04, 0x3FFF);        // [13:0]  
12088                         ofdmok     = PHY_QueryBBReg(padapter, 0xF14, 0x3FFF);        // [13:0]  
12089                         htok       = PHY_QueryBBReg(padapter, 0xF10, 0x3FFF);     // [13:0]
12090                         vht_ok      = PHY_QueryBBReg(padapter, 0xF0C, 0x3FFF);     // [13:0]
12091                                                                   
12092                         cckcrc     = PHY_QueryBBReg(padapter, 0xF04, 0x3FFF0000); // [29:16]                                            
12093                         ofdmcrc    = PHY_QueryBBReg(padapter, 0xF14, 0x3FFF0000); // [29:16]
12094                         htcrc      = PHY_QueryBBReg(padapter, 0xF10, 0x3FFF0000); // [29:16]            
12095                         vht_err     = PHY_QueryBBReg(padapter, 0xF0C, 0x3FFF0000); // [29:16]   
12096                         
12097                         CCK_FA = PHY_QueryBBReg(padapter, 0xa5c, bMaskLWord);
12098                         OFDM_FA = PHY_QueryBBReg(padapter, 0xF48, bMaskLWord);
12099                 } 
12100                 else
12101                 {
12102                         cckok      = PHY_QueryBBReg(padapter, 0xF88, bMaskDWord);               
12103                         ofdmok     = PHY_QueryBBReg(padapter, 0xF94, bMaskLWord);               
12104                             htok       = PHY_QueryBBReg(padapter, 0xF90, bMaskLWord);
12105                         vht_ok      = 0;
12106                     
12107                         cckcrc     = PHY_QueryBBReg(padapter, 0xF84, bMaskDWord);                                               
12108                         ofdmcrc    = PHY_QueryBBReg(padapter, 0xF94, bMaskHWord);
12109                         htcrc      = PHY_QueryBBReg(padapter, 0xF90, bMaskHWord);               
12110                         vht_err     = 0;
12111                 
12112                 OFDM_FA = PHY_QueryBBReg(padapter, 0xCF0, bMaskLWord) + PHY_QueryBBReg(padapter, 0xCF2, bMaskLWord) + 
12113                                         PHY_QueryBBReg(padapter, 0xDA2, bMaskLWord)+ PHY_QueryBBReg(padapter, 0xDA4, bMaskLWord) + 
12114                                         PHY_QueryBBReg(padapter, 0xDA6, bMaskLWord) + PHY_QueryBBReg(padapter, 0xDA8, bMaskLWord);
12115                 
12116                 CCK_FA=(rtw_read8(padapter, 0xa5b )<<8 ) | (rtw_read8(padapter, 0xa5c));
12117                 }
12118                 DBG_871X("%s: OFDM_FA =%d\n", __FUNCTION__, OFDM_FA);
12119                 DBG_871X("%s: CCK_FA =%d\n", __FUNCTION__, CCK_FA);
12120                 sprintf( extra, "Phy Received packet OK:%d CRC error:%d FA Counter: %d",cckok+ofdmok+htok+vht_ok,cckcrc+ofdmcrc+htcrc+vht_err,OFDM_FA+CCK_FA);
12121         }
12122         else if(bQueryMac)
12123         {
12124                 // for 8723A
12125                 {
12126                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x3);
12127                         mac_cck_ok      = PHY_QueryMacReg(padapter, 0x664, bMaskLWord);      // [15:0]    
12128                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x0);
12129                         mac_ofdm_ok     = PHY_QueryMacReg(padapter, 0x664, bMaskLWord);      // [15:0]   
12130                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x6);
12131                         mac_ht_ok       = PHY_QueryMacReg(padapter, 0x664, bMaskLWord);     // [15:0]   
12132                         mac_vht_ok      = 0;
12133                         
12134                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x4);
12135                         mac_cck_err     = PHY_QueryMacReg(padapter, 0x664, bMaskLWord); // [15:0]       
12136                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x1);
12137                         mac_ofdm_err    = PHY_QueryMacReg(padapter, 0x664, bMaskLWord); // [15:0]       
12138                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x7);
12139                         mac_ht_err      = PHY_QueryMacReg(padapter, 0x664, bMaskLWord); // [15:0]               
12140                         mac_vht_err     = 0;
12141                         //Mac_DropPacket
12142                         rtw_write32(padapter, 0x664, (rtw_read32(padapter, 0x0664)& 0x0FFFFFFF)| Mac_DropPacket);
12143                         DropPacket = rtw_read32(padapter, 0x664)& 0x0000FFFF;
12144                 } 
12145                 
12146                 sprintf( extra, "Mac Received packet OK: %d , CRC error: %d , Drop Packets: %d\n",
12147                                 mac_cck_ok+mac_ofdm_ok+mac_ht_ok+mac_vht_ok,mac_cck_err+mac_ofdm_err+mac_ht_err+mac_vht_err,DropPacket);                        
12148         }
12149
12150         if( bmon==1 ) { 
12151                 sscanf(input, "mon=%d", &bmon);
12152                 
12153                 if(bmon==1)
12154                 {
12155                         pmppriv->rx_bindicatePkt= _TRUE;
12156                         sprintf( extra, "Indicating Receive Packet to network start\n");
12157                 }else {
12158                         pmppriv->rx_bindicatePkt= _FALSE;
12159                         sprintf( extra, "Indicating Receive Packet to network Stop\n");
12160                 }       
12161         }
12162         
12163         wrqu->length = strlen(extra) + 1;
12164
12165         return 0;
12166 }
12167
12168 static int rtw_mp_trx_query(struct net_device *dev,
12169                         struct iw_request_info *info,
12170                         struct iw_point *wrqu, char *extra)
12171 {
12172         u32 txok,txfail,rxok,rxfail,rxfilterout;
12173         PADAPTER padapter = rtw_netdev_priv(dev);
12174         //if (copy_from_user(extra, wrqu->data.pointer, wrqu->data.length))
12175         //      return -EFAULT;
12176
12177         txok=padapter->mppriv.tx.sended;
12178         txfail=0;
12179         rxok = padapter->mppriv.rx_pktcount;
12180         rxfail = padapter->mppriv.rx_crcerrpktcount;
12181         rxfilterout = padapter->mppriv.rx_pktcount_filter_out;
12182
12183         _rtw_memset(extra, '\0', 128);
12184
12185         sprintf(extra, "Tx OK:%d, Tx Fail:%d, Rx OK:%d, CRC error:%d ,Rx Filter out:%d \n", txok, txfail,rxok,rxfail,rxfilterout);
12186
12187         wrqu->length=strlen(extra)+1;
12188
12189         return 0;
12190 }
12191
12192 static int rtw_mp_pwrtrk(struct net_device *dev,
12193                         struct iw_request_info *info,
12194                         struct iw_point *wrqu, char *extra)
12195 {
12196         u8 enable;
12197         u32 thermal;
12198         s32 ret;
12199         PADAPTER padapter = rtw_netdev_priv(dev);
12200         HAL_DATA_TYPE                   *pHalData = GET_HAL_DATA(padapter);
12201         u8              input[wrqu->length];
12202
12203         if (copy_from_user(input, wrqu->pointer, wrqu->length))
12204                         return -EFAULT;
12205
12206         _rtw_memset(extra, 0, wrqu->length);
12207
12208         enable = 1;
12209         if (wrqu->length > 1) { // not empty string
12210                 if (strncmp(input, "stop", 4) == 0)
12211                 {       
12212                         enable = 0;
12213                         sprintf(extra, "mp tx power tracking stop");
12214                         pHalData->TxPowerTrackControl = _FALSE;
12215                 }
12216                 else if (sscanf(input, "ther=%d", &thermal)) {
12217                         pHalData->TxPowerTrackControl = _TRUE;
12218                         ret = Hal_SetThermalMeter(padapter, (u8)thermal);
12219                         if (ret == _FAIL) return -EPERM;
12220                                 sprintf(extra, "mp tx power tracking start,target value=%d ok ",thermal);
12221                 }else{
12222                         return -EINVAL;
12223                 }
12224         }
12225
12226         ret = Hal_SetPowerTracking(padapter, enable);
12227         if (ret == _FAIL) return -EPERM;
12228
12229         wrqu->length = strlen(extra);
12230
12231         return 0;
12232 }
12233
12234 static int rtw_mp_psd(struct net_device *dev,
12235                         struct iw_request_info *info,
12236                         struct iw_point *wrqu, char *extra)
12237 {
12238         PADAPTER padapter = rtw_netdev_priv(dev);
12239         u8              input[wrqu->length];
12240         
12241         if (copy_from_user(input, wrqu->pointer, wrqu->length))
12242                 return -EFAULT;
12243         
12244         strcpy(extra,input);
12245         
12246         wrqu->length = mp_query_psd(padapter, extra);
12247         
12248         return 0;
12249 }
12250
12251 static int rtw_mp_thermal(struct net_device *dev,
12252                         struct iw_request_info *info,
12253                         struct iw_point *wrqu, char *extra)
12254 {
12255         u8 val;
12256         int bwrite=1;
12257         
12258         #ifdef CONFIG_RTL8192C
12259                         u16 addr=EEPROM_THERMAL_METER_92C;
12260         #endif
12261         #ifdef CONFIG_RTL8192D
12262                         u16 addr=EEPROM_THERMAL_METER_92D;
12263         #endif
12264         #ifdef CONFIG_RTL8723A
12265                         u16 addr=EEPROM_THERMAL_METER_8723A;
12266         #endif
12267         #ifdef CONFIG_RTL8188E
12268                         u16 addr=EEPROM_THERMAL_METER_88E;
12269         #endif
12270         #if defined(CONFIG_RTL8812A) || defined(CONFIG_RTL8821A)
12271                         u16 addr=EEPROM_THERMAL_METER_8812;
12272         #endif
12273         #ifdef CONFIG_RTL8192E
12274                         u16 addr=EEPROM_THERMAL_METER_8192E;
12275         #endif
12276         #ifdef CONFIG_RTL8723B
12277                         u16 addr=EEPROM_THERMAL_METER_8723B;
12278         #endif
12279         u16 cnt=1;
12280         u16 max_available_size=0;
12281         PADAPTER padapter = rtw_netdev_priv(dev);       
12282
12283         if (copy_from_user(extra, wrqu->pointer, wrqu->length))
12284                 return -EFAULT;
12285
12286         //DBG_871X("print extra %s \n",extra); 
12287          
12288          bwrite = strncmp(extra, "write", 6); // strncmp TRUE is 0
12289          
12290          Hal_GetThermalMeter(padapter, &val);
12291          
12292          if( bwrite == 0 )      
12293          {
12294                  //DBG_871X("to write val:%d",val);
12295                         EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
12296                         if( 2 > max_available_size )
12297                         {                       
12298                                 DBG_871X("no available efuse!\n");
12299                                 return -EFAULT;
12300                         }       
12301                         if ( rtw_efuse_map_write(padapter, addr, cnt, &val) == _FAIL )
12302                         {
12303                                 DBG_871X("rtw_efuse_map_write error \n");                       
12304                                 return -EFAULT;
12305                         } 
12306                         else
12307                         {
12308                                  sprintf(extra, " efuse write ok :%d", val);    
12309                         }
12310           }
12311           else
12312           {
12313                          sprintf(extra, "%d", val);
12314           }
12315         wrqu->length = strlen(extra);
12316         
12317         return 0;
12318 }
12319
12320 static int rtw_mp_reset_stats(struct net_device *dev,
12321                         struct iw_request_info *info,
12322                         struct iw_point *wrqu, char *extra)
12323 {
12324         struct mp_priv *pmp_priv;
12325         struct pkt_attrib *pattrib;
12326         PADAPTER padapter = rtw_netdev_priv(dev);
12327         
12328         pmp_priv = &padapter->mppriv;
12329         
12330         pmp_priv->tx.sended = 0;
12331         pmp_priv->tx_pktcount = 0;
12332         pmp_priv->rx_pktcount = 0;
12333         pmp_priv->rx_pktcount_filter_out=0;
12334         pmp_priv->rx_crcerrpktcount = 0;
12335
12336         //reset phy counter
12337         if (IS_HARDWARE_TYPE_JAGUAR(padapter))
12338         {
12339                 write_bbreg(padapter, 0xB58, BIT0, 0x1);
12340                 write_bbreg(padapter, 0xB58, BIT0, 0x0);
12341
12342                 write_bbreg(padapter, 0x9A4, BIT17, 0x1);//reset  OFDA FA counter
12343                 write_bbreg(padapter, 0x9A4, BIT17, 0x0);
12344                 
12345                 write_bbreg(padapter, 0xA5C, BIT15, 0x0);//reset  CCK FA counter
12346                 write_bbreg(padapter, 0xA5C, BIT15, 0x1);
12347         }
12348         else
12349         {
12350                 write_bbreg(padapter, 0xF14, BIT16, 0x1);
12351                 rtw_msleep_os(10);
12352                 write_bbreg(padapter, 0xF14, BIT16, 0x0);
12353                 
12354                 write_bbreg(padapter, 0xD00, BIT27, 0x1);//reset  OFDA FA counter
12355                 write_bbreg(padapter, 0xC0C, BIT31, 0x1);//reset  OFDA FA counter
12356                 write_bbreg(padapter, 0xD00, BIT27, 0x0);
12357                 write_bbreg(padapter, 0xC0C, BIT31, 0x0);
12358                 
12359                 write_bbreg(padapter, 0xA2C, BIT15, 0x0);//reset  CCK FA counter
12360                 write_bbreg(padapter, 0xA2C, BIT15, 0x1);
12361         }
12362         //reset mac counter
12363         PHY_SetMacReg(padapter, 0x664, BIT27, 0x1); 
12364         PHY_SetMacReg(padapter, 0x664, BIT27, 0x0);
12365         return 0;
12366 }
12367
12368 static int rtw_mp_dump(struct net_device *dev,
12369                         struct iw_request_info *info,
12370                         struct iw_point *wrqu, char *extra)
12371 {
12372         struct mp_priv *pmp_priv;
12373         struct pkt_attrib *pattrib;
12374         u32 value;
12375     u8          input[wrqu->length];
12376         u8 rf_type,path_nums = 0;
12377         u32 i,j=1,path;
12378         PADAPTER padapter = rtw_netdev_priv(dev);
12379         
12380         pmp_priv = &padapter->mppriv;
12381
12382         if (copy_from_user(input, wrqu->pointer, wrqu->length))
12383                 return -EFAULT;
12384         
12385         if ( strncmp(input, "all", 4)==0 )
12386         {
12387                 mac_reg_dump(RTW_DBGDUMP, padapter);
12388                 bb_reg_dump(RTW_DBGDUMP, padapter);
12389                 rf_reg_dump(RTW_DBGDUMP, padapter);
12390         }
12391         return 0;
12392 }
12393
12394 static int rtw_mp_phypara(struct net_device *dev,
12395                         struct iw_request_info *info,
12396                         struct iw_point *wrqu, char *extra)
12397 {
12398
12399         PADAPTER padapter = rtw_netdev_priv(dev);
12400         HAL_DATA_TYPE   *pHalData       = GET_HAL_DATA(padapter);
12401         char    input[wrqu->length];
12402         u32             valxcap;
12403         
12404         if (copy_from_user(input, wrqu->pointer, wrqu->length))
12405                         return -EFAULT;
12406         
12407         DBG_871X("%s:iwpriv in=%s\n", __func__, input);
12408         
12409         sscanf(input, "xcap=%d", &valxcap);
12410
12411         pHalData->CrystalCap = (u8)valxcap;
12412         Hal_ProSetCrystalCap( padapter , valxcap );
12413
12414         sprintf( extra, "Set xcap=%d",valxcap );
12415         wrqu->length = strlen(extra) + 1;
12416         
12417 return 0;
12418
12419 }
12420
12421 static int rtw_mp_SetRFPath(struct net_device *dev,
12422                         struct iw_request_info *info,
12423                         union iwreq_data *wrqu, char *extra)
12424 {
12425         PADAPTER padapter = rtw_netdev_priv(dev);
12426         char    input[wrqu->data.length];
12427         s32             bMain=1,bTurnoff=1;
12428         
12429         if (copy_from_user(input, wrqu->data.pointer, wrqu->data.length))
12430                         return -EFAULT;
12431         DBG_871X("%s:iwpriv in=%s\n", __func__, input); 
12432         
12433         bMain = strncmp(input, "1", 2); // strncmp TRUE is 0
12434         bTurnoff = strncmp(input, "0", 3); // strncmp TRUE is 0
12435
12436         if(bMain==0)
12437         {
12438                 MP_PHY_SetRFPathSwitch(padapter,_TRUE);
12439                 DBG_871X("%s:PHY_SetRFPathSwitch=TRUE\n", __func__);    
12440         }
12441         else if(bTurnoff==0)
12442         {
12443                 MP_PHY_SetRFPathSwitch(padapter,_FALSE);
12444                 DBG_871X("%s:PHY_SetRFPathSwitch=FALSE\n", __func__);   
12445         }
12446         
12447         return 0;
12448 }
12449
12450 static int rtw_mp_QueryDrv(struct net_device *dev,
12451                         struct iw_request_info *info,
12452                         union iwreq_data *wrqu, char *extra)
12453 {
12454         PADAPTER padapter = rtw_netdev_priv(dev);
12455         char    input[wrqu->data.length];
12456         s32     qAutoLoad=1;
12457
12458         EEPROM_EFUSE_PRIV *pEEPROM = GET_EEPROM_EFUSE_PRIV(padapter);
12459         
12460         if (copy_from_user(input, wrqu->data.pointer, wrqu->data.length))
12461                         return -EFAULT;
12462         DBG_871X("%s:iwpriv in=%s\n", __func__, input); 
12463         
12464         qAutoLoad = strncmp(input, "autoload", 8); // strncmp TRUE is 0
12465
12466         if(qAutoLoad==0)
12467         {
12468                 DBG_871X("%s:qAutoLoad\n", __func__);
12469                 
12470                 if(pEEPROM->bautoload_fail_flag)
12471                         sprintf(extra, "fail");
12472                 else
12473                 sprintf(extra, "ok");      
12474         }
12475                 wrqu->data.length = strlen(extra) + 1;
12476         return 0;
12477 }
12478
12479 /* update Tx AGC offset */
12480 static int rtw_mp_antBdiff(struct net_device *dev,
12481                         struct iw_request_info *info,
12482                         struct iw_point *wrqu, char *extra)
12483 {
12484
12485
12486         // MPT_ProSetTxAGCOffset
12487         return 0;
12488 }
12489
12490
12491 static int rtw_mp_PwrCtlDM(struct net_device *dev,
12492                         struct iw_request_info *info,
12493                         struct iw_point *wrqu, char *extra)
12494 {
12495         PADAPTER padapter = rtw_netdev_priv(dev);
12496         u8              input[wrqu->length];
12497         int             bstart=1;
12498         
12499         if (copy_from_user(input, wrqu->pointer, wrqu->length))
12500                         return -EFAULT;
12501
12502         bstart = strncmp(input, "start", 5); // strncmp TRUE is 0
12503         if(bstart==0){
12504                 sprintf(extra, "PwrCtlDM start \n");
12505                 MPT_PwrCtlDM(padapter,1);
12506         }else{
12507                 sprintf(extra, "PwrCtlDM stop \n");
12508                 MPT_PwrCtlDM(padapter,0);
12509         }
12510         wrqu->length = strlen(extra);
12511
12512         return 0;
12513 }
12514
12515 static int rtw_mp_getver(struct net_device *dev,
12516                         struct iw_request_info *info,
12517                         union iwreq_data *wrqu, char *extra)
12518 {
12519         PADAPTER padapter = rtw_netdev_priv(dev);
12520         struct mp_priv *pmp_priv;
12521         
12522         pmp_priv = &padapter->mppriv;
12523         
12524         if (copy_from_user(extra, wrqu->data.pointer, wrqu->data.length))
12525                         return -EFAULT;
12526
12527         sprintf(extra, "rtwpriv=%d\n",RTWPRIV_VER_INFO);
12528         wrqu->data.length = strlen(extra);
12529         return 0;
12530 }
12531
12532 #if (defined(CONFIG_RTL8723A) || defined(CONFIG_RTL8723B))
12533 /* update Tx AGC offset */
12534 static int rtw_mp_SetBT(struct net_device *dev,
12535                         struct iw_request_info *info,
12536                         union iwreq_data *wrqu, char *extra)
12537 {
12538         PADAPTER padapter = rtw_netdev_priv(dev);
12539         struct hal_ops *pHalFunc = &padapter->HalFunc;
12540         HAL_DATA_TYPE   *pHalData = GET_HAL_DATA(padapter);
12541         
12542         BT_REQ_CMD      BtReq;
12543         PMPT_CONTEXT    pMptCtx=&(padapter->mppriv.MptCtx);
12544         PBT_RSP_CMD     pBtRsp=(PBT_RSP_CMD)&pMptCtx->mptOutBuf[0];
12545         char    input[128];
12546         char *pch, *ptmp, *token, *tmp[2]={0x00,0x00};
12547         u8 setdata[100];
12548         u8 resetbt=0x00;
12549         u8 tempval,BTStatus;
12550         u8 H2cSetbtmac[6];
12551         u8 u1H2CBtMpOperParm[4]={0x01};
12552         u16 testmode=1,ready=1,trxparam=1,setgen=1,getgen=1,testctrl=1,testbt=1,readtherm=1,setbtmac=1;
12553         u32 i=0,ii=0,jj=0,kk=0,cnts=0,status=0;
12554         PRT_MP_FIRMWARE pBTFirmware = NULL;
12555         
12556         if (copy_from_user(extra, wrqu->data.pointer, wrqu->data.length))
12557                         return -EFAULT;
12558         if(strlen(extra)<1) return -EFAULT;
12559         
12560         DBG_871X("%s:iwpriv in=%s\n", __FUNCTION__, extra); 
12561         ready = strncmp(extra, "ready", 5); 
12562         testmode = strncmp(extra, "testmode", 8); // strncmp TRUE is 0
12563         trxparam = strncmp(extra, "trxparam", 8); 
12564         setgen = strncmp(extra, "setgen", 6);
12565         getgen = strncmp(extra, "getgen", 6); 
12566         testctrl = strncmp(extra, "testctrl", 8);
12567         testbt = strncmp(extra, "testbt", 6);
12568         readtherm = strncmp(extra, "readtherm", 9);
12569         setbtmac = strncmp(extra, "setbtmac", 8);
12570
12571         if ( strncmp(extra, "dlbt", 4) == 0)
12572         {
12573                 pHalData->LastHMEBoxNum=0;
12574                 padapter->bBTFWReady = _FALSE;
12575                 rtw_write8(padapter, 0xa3, 0x05);
12576                 BTStatus=rtw_read8(padapter, 0xa0);
12577                 DBG_871X("%s: btwmap before read 0xa0 BT Status =0x%x \n", __FUNCTION__,BTStatus);
12578                 if (BTStatus != 0x04)
12579                 {
12580                         sprintf(extra, "BT Status not Active DLFW FAIL\n");
12581                         goto exit;
12582                 }
12583
12584                 tempval = rtw_read8(padapter, 0x6B);
12585                 tempval |= BIT7;
12586                 rtw_write8(padapter, 0x6B, tempval);
12587
12588                 // Attention!! Between 0x6A[14] and 0x6A[15] setting need 100us delay
12589                 // So don't wirte 0x6A[14]=1 and 0x6A[15]=0 together!
12590                 rtw_usleep_os(100);
12591                 // disable BT power cut
12592                 // 0x6A[14] = 0
12593                 tempval = rtw_read8(padapter, 0x6B);
12594                 tempval &= ~BIT6;
12595                 rtw_write8(padapter, 0x6B, tempval);
12596                 rtw_usleep_os(100);
12597                 MPT_PwrCtlDM(padapter,0);
12598                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)| 0x00000004));
12599                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)& 0xFFFFFFEF));
12600                 rtw_msleep_os(600);
12601                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)| 0x00000010));
12602                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)& 0xFFFFFFFB));
12603                 rtw_msleep_os(1200);            
12604                 pBTFirmware = (PRT_MP_FIRMWARE)rtw_zmalloc(sizeof(RT_MP_FIRMWARE));
12605                 if(pBTFirmware==NULL)
12606                         goto exit;
12607                 padapter->bBTFWReady = _FALSE;
12608                 FirmwareDownloadBT(padapter, pBTFirmware);
12609                 if (pBTFirmware)
12610                         rtw_mfree((u8*)pBTFirmware, sizeof(RT_MP_FIRMWARE));
12611                         
12612                 DBG_871X("Wait for FirmwareDownloadBT fw boot!\n");
12613                 rtw_msleep_os(2000);
12614                 _rtw_memset(extra,'\0', wrqu->data.length);
12615                 BtReq.opCodeVer = 1;
12616                 BtReq.OpCode = 0;
12617                 BtReq.paraLength = 0;
12618                 mptbt_BtControlProcess(padapter, &BtReq);
12619                 rtw_msleep_os(100);
12620
12621                 DBG_8192C("FirmwareDownloadBT ready = 0x%x 0x%x", pMptCtx->mptOutBuf[4],pMptCtx->mptOutBuf[5]);
12622                 if( (pMptCtx->mptOutBuf[4]==0x00) && (pMptCtx->mptOutBuf[5]==0x00))
12623                         {
12624                                 if(padapter->mppriv.bTxBufCkFail==_TRUE)
12625                                         sprintf(extra, "check TxBuf Fail.\n");
12626                                 else
12627                                         sprintf(extra, "download FW Fail.\n");
12628                         }
12629                         else
12630                         {
12631                                 sprintf(extra, "download FW OK.\n");
12632                                 goto exit;
12633                         }
12634                 goto exit;
12635                 goto exit;      
12636         }
12637         if ( strncmp(extra, "dlfw", 4) == 0)
12638         {
12639                 pHalData->LastHMEBoxNum=0;
12640                 padapter->bBTFWReady = _FALSE;
12641                 rtw_write8(padapter, 0xa3, 0x05);
12642                 BTStatus=rtw_read8(padapter, 0xa0);
12643                 DBG_871X("%s: btwmap before read 0xa0 BT Status =0x%x \n", __FUNCTION__,BTStatus);
12644                 if (BTStatus != 0x04)
12645                 {
12646                         sprintf(extra, "BT Status not Active DLFW FAIL\n");
12647                         goto exit;
12648                 }
12649
12650                 tempval = rtw_read8(padapter, 0x6B);
12651                 tempval |= BIT7;
12652                 rtw_write8(padapter, 0x6B, tempval);
12653
12654                 // Attention!! Between 0x6A[14] and 0x6A[15] setting need 100us delay
12655                 // So don't wirte 0x6A[14]=1 and 0x6A[15]=0 together!
12656                 rtw_usleep_os(100);
12657                 // disable BT power cut
12658                 // 0x6A[14] = 0
12659                 tempval = rtw_read8(padapter, 0x6B);
12660                 tempval &= ~BIT6;
12661                 rtw_write8(padapter, 0x6B, tempval);
12662                 rtw_usleep_os(100);
12663         
12664                 MPT_PwrCtlDM(padapter,0);
12665                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)| 0x00000004));
12666                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)& 0xFFFFFFEF));
12667                 rtw_msleep_os(600);
12668                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)| 0x00000010));
12669                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)& 0xFFFFFFFB));
12670                 rtw_msleep_os(1200);
12671
12672 #if defined(CONFIG_PLATFORM_SPRD) && (MP_DRIVER == 1)
12673                 // Pull up BT reset pin.
12674                 DBG_871X("%s: pull up BT reset pin when bt start mp test\n", __FUNCTION__);
12675                 rtw_wifi_gpio_wlan_ctrl(WLAN_BT_PWDN_ON);
12676 #endif
12677                 DBG_871X(" rtl8723a_FirmwareDownload!\n");
12678
12679 #ifdef CONFIG_RTL8723A
12680                 status = rtl8723a_FirmwareDownload(padapter);
12681 #elif defined(CONFIG_RTL8723B)
12682                 status = rtl8723b_FirmwareDownload(padapter, _FALSE);
12683 #endif
12684                 DBG_871X("Wait for FirmwareDownloadBT fw boot!\n");
12685                 rtw_msleep_os(1000);
12686 #ifdef CONFIG_BT_COEXIST
12687                 rtw_btcoex_HaltNotify(padapter);
12688                 DBG_871X("SetBT btcoex HaltNotify !\n");
12689                 //hal_btcoex1ant_SetAntPath(padapter);
12690                 rtw_btcoex_SetManualControl(padapter, _TRUE);
12691 #endif          
12692                 _rtw_memset(extra,'\0', wrqu->data.length);
12693                 BtReq.opCodeVer = 1;
12694                 BtReq.OpCode = 0;
12695                 BtReq.paraLength = 0;
12696                 mptbt_BtControlProcess(padapter, &BtReq);
12697                 rtw_msleep_os(200);
12698
12699                 DBG_8192C("FirmwareDownloadBT ready = 0x%x 0x%x", pMptCtx->mptOutBuf[4],pMptCtx->mptOutBuf[5]);
12700                 if( (pMptCtx->mptOutBuf[4]==0x00) && (pMptCtx->mptOutBuf[5]==0x00))
12701                         {
12702                                 if(padapter->mppriv.bTxBufCkFail==_TRUE)
12703                                         sprintf(extra, "check TxBuf Fail.\n");
12704                                 else
12705                                         sprintf(extra, "download FW Fail.\n");
12706                         }
12707                         else
12708                         {
12709                                 #ifdef CONFIG_BT_COEXIST
12710                                 rtw_btcoex_SwitchBtTRxMask(padapter);
12711                                 #endif
12712                                 rtw_msleep_os(200);
12713                                 sprintf(extra, "download FW OK.\n");
12714                                 goto exit;
12715                         }
12716                 goto exit;
12717         }
12718
12719         if ( strncmp(extra, "down", 4) == 0){
12720                 DBG_871X("SetBT down for to hal_init !\n");
12721 #ifdef CONFIG_BT_COEXIST                
12722                 rtw_btcoex_SetManualControl(padapter, _FALSE);
12723                 rtw_btcoex_Initialize(padapter);
12724 #endif          
12725                 pHalFunc->read_adapter_info(padapter);
12726                 pHalFunc->hal_deinit(padapter);
12727                 pHalFunc->hal_init(padapter);
12728                 rtw_pm_set_ips(padapter,IPS_NONE);
12729                 LeaveAllPowerSaveMode(padapter);
12730                 MPT_PwrCtlDM(padapter,0);
12731                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)| 0x00000004));
12732                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)& 0xFFFFFFEF));
12733                 rtw_msleep_os(600);
12734                         //rtw_write32(padapter, 0x6a, (rtw_read32(padapter, 0x6a)& 0xFFFFFFFE));
12735                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)| 0x00000010));
12736                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)& 0xFFFFFFFB));
12737                 rtw_msleep_os(1200);
12738                 goto exit;
12739         }
12740         if ( strncmp(extra, "disable", 7) == 0){
12741                 DBG_871X("SetBT disable !\n");
12742                 rtw_write32(padapter, 0x6a, (rtw_read32(padapter, 0x6a)& 0xFFFFFFFB));
12743                 rtw_msleep_os(500);
12744                 goto exit;
12745                 }
12746         if ( strncmp(extra, "enable", 6) == 0){
12747                 DBG_871X("SetBT enable !\n");
12748                 rtw_write32(padapter, 0x6a, (rtw_read32(padapter, 0x6a)| 0x00000004));
12749                 rtw_msleep_os(500);
12750                 goto exit;
12751         }
12752         if ( strncmp(extra, "h2c", 3) == 0){
12753                         DBG_871X("SetBT h2c !\n");
12754                         padapter->bBTFWReady = _TRUE;
12755                         rtw_hal_fill_h2c_cmd(padapter, 0x63, 1, u1H2CBtMpOperParm);
12756                         goto exit;
12757                 }
12758         if ( strncmp(extra, "2ant", 4) == 0){
12759                 DBG_871X("Set BT 2ant use!\n");
12760                 PHY_SetMacReg(padapter,0x67,BIT5,0x1);
12761                 rtw_write32(padapter, 0x948, 0000);
12762                 
12763                 goto exit;
12764         }
12765                 
12766         if( ready!=0 && testmode!=0 && trxparam!=0 && setgen!=0 && getgen!=0 && testctrl!=0 && testbt!=0 && readtherm!=0 &&setbtmac!=0)
12767                 return -EFAULT;
12768                 
12769         if( testbt==0 )
12770         {
12771                         BtReq.opCodeVer=1;
12772                         BtReq.OpCode=6;
12773                         BtReq.paraLength=cnts/2;
12774                         goto todo;
12775         }
12776         if( ready==0 )
12777         {
12778                 BtReq.opCodeVer=1;
12779                 BtReq.OpCode=0;
12780                 BtReq.paraLength=0; 
12781                 goto todo;
12782         }
12783
12784         pch = extra;    
12785         i = 0;
12786         while ((token = strsep(&pch, ",")) != NULL)
12787         {
12788                 if (i > 1) break;
12789                 tmp[i] = token;
12790                 i++;
12791         }
12792
12793         if ((tmp[0]==NULL) && (tmp[1]==NULL))
12794         {
12795                 return -EFAULT;
12796         }
12797         else
12798         {
12799                 cnts = strlen(tmp[1]);
12800                 if (cnts<1) return -EFAULT;
12801         
12802                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
12803                 DBG_871X("%s: data=%s\n", __FUNCTION__, tmp[1]);
12804                                 
12805                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
12806                 {
12807                         BtReq.pParamStart[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
12808 //                      DBG_871X("BtReq.pParamStart[%d]=0x%02x\n", jj, BtReq.pParamStart[jj]);
12809                 }
12810         }
12811         
12812         if( testmode==0 )       
12813         {
12814                 BtReq.opCodeVer=1;
12815                 BtReq.OpCode=1;
12816                 BtReq.paraLength=1; 
12817         }
12818         if( trxparam==0 )
12819         {
12820                 BtReq.opCodeVer=1;
12821                 BtReq.OpCode=2;
12822                 BtReq.paraLength=cnts/2; 
12823         }
12824         if( setgen==0 )
12825         {       
12826                 DBG_871X("%s: BT_SET_GENERAL \n", __func__); 
12827                 BtReq.opCodeVer=1;
12828                 BtReq.OpCode=3; //BT_SET_GENERAL        3
12829                 BtReq.paraLength=cnts/2;        
12830         }
12831         if( getgen==0 )
12832         {       
12833                 DBG_871X("%s: BT_GET_GENERAL \n", __func__); 
12834                 BtReq.opCodeVer=1;
12835                 BtReq.OpCode=4;         //BT_GET_GENERAL        4
12836                 BtReq.paraLength=cnts/2;        
12837         }
12838         if( readtherm==0 )
12839         {       
12840                 DBG_871X("%s: BT_GET_GENERAL \n", __func__); 
12841                 BtReq.opCodeVer=1;
12842                 BtReq.OpCode=4;         //BT_GET_GENERAL        4
12843                 BtReq.paraLength=cnts/2;        
12844         }
12845         
12846         if( testctrl==0 )
12847         {       
12848                 DBG_871X("%s: BT_TEST_CTRL \n", __func__);
12849                 BtReq.opCodeVer=1;
12850                 BtReq.OpCode=5;         //BT_TEST_CTRL  5
12851                 BtReq.paraLength=cnts/2;        
12852         }
12853
12854         DBG_871X("%s: Req opCodeVer=%d OpCode=%d paraLength=%d\n",
12855                 __FUNCTION__, BtReq.opCodeVer, BtReq.OpCode, BtReq.paraLength);
12856
12857         if(BtReq.paraLength<1)
12858                 goto todo;
12859         for (i=0; i<BtReq.paraLength; i++)
12860         {
12861                 DBG_871X("%s: BtReq.pParamStart[%d] = 0x%02x \n",
12862                         __FUNCTION__, i, BtReq.pParamStart[i]);
12863         }
12864         
12865 todo:
12866         _rtw_memset(extra,'\0', wrqu->data.length);
12867
12868         if (padapter->bBTFWReady == _FALSE)
12869         {
12870                 sprintf(extra, "BTFWReady = FALSE.\n");
12871                 goto exit;
12872         }
12873
12874         mptbt_BtControlProcess(padapter, &BtReq);
12875
12876         if (readtherm == 0)
12877         {
12878                 sprintf(extra, "BT thermal=");
12879                 for (i=4; i<pMptCtx->mptOutLen; i++)
12880                 {
12881                         if ((pMptCtx->mptOutBuf[i]==0x00) && (pMptCtx->mptOutBuf[i+1]==0x00))
12882                                 goto exit;
12883
12884 #ifdef CONFIG_RTL8723A
12885                         sprintf(extra, "%s %d ", extra, (pMptCtx->mptOutBuf[i]& 0x3f));
12886 #else
12887                         sprintf(extra, "%s %d ", extra, (pMptCtx->mptOutBuf[i]& 0x1f));
12888 #endif
12889                 }
12890         }
12891         else
12892         {
12893                 for (i=4; i<pMptCtx->mptOutLen; i++)
12894                 {
12895                         sprintf(extra, "%s 0x%x ", extra, pMptCtx->mptOutBuf[i]);
12896                 }
12897         }
12898         
12899 exit:
12900         wrqu->data.length = strlen(extra) + 1;
12901         DBG_871X("-%s: output len=%d data=%s\n", __FUNCTION__, wrqu->data.length, extra);
12902
12903         return status;
12904 }
12905
12906 #endif //#ifdef CONFIG_RTL8723A
12907
12908 static int rtw_mp_set(struct net_device *dev,
12909                         struct iw_request_info *info,
12910                         union iwreq_data *wdata, char *extra)
12911 {
12912         struct iw_point *wrqu = (struct iw_point *)wdata;
12913         u32 subcmd = wrqu->flags;
12914         PADAPTER padapter = rtw_netdev_priv(dev);
12915
12916         if (padapter == NULL)
12917         {
12918                 return -ENETDOWN;
12919         }
12920
12921         if((padapter->bup == _FALSE ))
12922         {
12923                 DBG_871X(" %s fail =>(padapter->bup == _FALSE )\n",__FUNCTION__);
12924                 return -ENETDOWN;
12925         }
12926
12927         if( (padapter->bSurpriseRemoved == _TRUE) || ( padapter->bDriverStopped == _TRUE))
12928        {        
12929         DBG_871X("%s fail =>(padapter->bSurpriseRemoved == _TRUE) || ( padapter->bDriverStopped == _TRUE) \n",__FUNCTION__);
12930              return -ENETDOWN;
12931        }
12932
12933         
12934         //_rtw_memset(extra, 0x00, IW_PRIV_SIZE_MASK);
12935
12936         if (extra == NULL)
12937         {
12938                 wrqu->length = 0;
12939                 return -EIO;
12940         }
12941
12942         switch(subcmd)
12943         {
12944         case MP_START:
12945                         DBG_871X("set case mp_start \n");
12946                         rtw_mp_start (dev,info,wrqu,extra);
12947                          break; 
12948                          
12949         case MP_STOP:
12950                         DBG_871X("set case mp_stop \n");
12951                         rtw_mp_stop (dev,info,wrqu,extra);
12952                          break; 
12953                          
12954         case MP_BANDWIDTH:
12955                         DBG_871X("set case mp_bandwidth \n");
12956                         rtw_mp_bandwidth (dev,info,wrqu,extra);
12957                         break;
12958                                 
12959         case MP_RESET_STATS:
12960                         DBG_871X("set case MP_RESET_STATS \n");
12961                         rtw_mp_reset_stats      (dev,info,wrqu,extra);
12962                         break;
12963         case MP_SetRFPathSwh:           
12964                         DBG_871X("set MP_SetRFPathSwitch \n");
12965                         rtw_mp_SetRFPath  (dev,info,wdata,extra);
12966                         break;
12967         case CTA_TEST:
12968                         DBG_871X("set CTA_TEST\n");
12969                         rtw_cta_test_start (dev, info, wdata, extra);
12970                         break;
12971         case MP_DISABLE_BT_COEXIST:
12972                         DBG_871X("set case MP_DISABLE_BT_COEXIST \n");
12973                         rtw_mp_disable_bt_coexist(dev, info, wdata, extra);
12974                 break;
12975 #ifdef CONFIG_WOWLAN
12976         case MP_WOW_ENABLE:
12977                         DBG_871X("set case MP_WOW_ENABLE: %s \n", extra);
12978                         rtw_wowlan_ctrl(dev, info, wdata, extra);
12979         break;
12980 #endif
12981 #ifdef CONFIG_AP_WOWLAN
12982         case MP_AP_WOW_ENABLE:
12983                         DBG_871X("set case MP_AP_WOW_ENABLE: %s \n", extra);
12984                         rtw_ap_wowlan_ctrl(dev, info, wdata, extra);
12985         break;
12986 #endif
12987         }
12988
12989           
12990         return 0;               
12991 }
12992
12993
12994 static int rtw_mp_get(struct net_device *dev,
12995                         struct iw_request_info *info,
12996                         union iwreq_data *wdata, char *extra)
12997 {
12998         struct iw_point *wrqu = (struct iw_point *)wdata;
12999         u32 subcmd = wrqu->flags;
13000         PADAPTER padapter = rtw_netdev_priv(dev);
13001
13002         //DBG_871X("in mp_get extra= %s \n",extra);
13003
13004         if (padapter == NULL)
13005         {
13006                 return -ENETDOWN;
13007         }
13008         if((padapter->bup == _FALSE ))
13009         {
13010                 DBG_871X(" %s fail =>(padapter->bup == _FALSE )\n",__FUNCTION__);
13011                 return -ENETDOWN;
13012         }
13013
13014         if( (padapter->bSurpriseRemoved == _TRUE) || ( padapter->bDriverStopped == _TRUE))
13015        {        
13016         DBG_871X("%s fail =>(padapter->bSurpriseRemoved == _TRUE) || ( padapter->bDriverStopped == _TRUE) \n",__FUNCTION__);
13017              return -ENETDOWN;
13018        }
13019         
13020         if (extra == NULL)
13021         {
13022                 wrqu->length = 0;
13023                 return -EIO;
13024         }
13025         
13026         switch(subcmd)
13027         {
13028         case WRITE_REG :
13029                         rtw_mp_write_reg (dev,info,wrqu,extra);
13030                          break;
13031                          
13032         case WRITE_RF:
13033                         rtw_mp_write_rf (dev,info,wrqu,extra);
13034                          break; 
13035                          
13036         case MP_PHYPARA:
13037                         DBG_871X("mp_get  MP_PHYPARA \n");
13038                         rtw_mp_phypara(dev,info,wrqu,extra);    
13039                         break;
13040
13041         case MP_CHANNEL:
13042                         DBG_871X("set case mp_channel \n");
13043                         rtw_mp_channel (dev,info,wrqu,extra);
13044                         break;
13045                         
13046         case READ_REG:
13047                         DBG_871X("mp_get  READ_REG \n");
13048                         rtw_mp_read_reg (dev,info,wrqu,extra);
13049                          break; 
13050         case READ_RF:
13051                         DBG_871X("mp_get  READ_RF \n");
13052                         rtw_mp_read_rf (dev,info,wrqu,extra);
13053                         break; 
13054                         
13055         case MP_RATE:
13056                         DBG_871X("set case mp_rate \n");
13057                         rtw_mp_rate (dev,info,wrqu,extra);
13058                         break;
13059                         
13060         case MP_TXPOWER:
13061                         DBG_871X("set case MP_TXPOWER \n");
13062                         rtw_mp_txpower (dev,info,wrqu,extra);
13063                         break;
13064                         
13065         case MP_ANT_TX:
13066                         DBG_871X("set case MP_ANT_TX \n");
13067                         rtw_mp_ant_tx (dev,info,wrqu,extra);
13068                         break;
13069                         
13070         case MP_ANT_RX:
13071                         DBG_871X("set case MP_ANT_RX \n");
13072                         rtw_mp_ant_rx (dev,info,wrqu,extra);
13073                         break;
13074                         
13075         case MP_QUERY:
13076                         //DBG_871X("mp_get mp_query MP_QUERY \n");
13077                         rtw_mp_trx_query(dev,info,wrqu,extra);
13078                         break;
13079                                         
13080         case MP_CTX:
13081                         DBG_871X("set case MP_CTX \n");
13082                         rtw_mp_ctx (dev,info,wrqu,extra);
13083                         break;
13084                         
13085         case MP_ARX:
13086                         DBG_871X("set case MP_ARX \n");
13087                         rtw_mp_arx (dev,info,wrqu,extra);
13088                         break;
13089                         
13090         case EFUSE_GET:
13091                         DBG_871X("efuse get EFUSE_GET \n");
13092                         rtw_mp_efuse_get(dev,info,wdata,extra);
13093                  break; 
13094                  
13095         case MP_DUMP:
13096                         DBG_871X("set case MP_DUMP \n");
13097                         rtw_mp_dump (dev,info,wrqu,extra);
13098                  break; 
13099         case MP_PSD:
13100                         DBG_871X("set case MP_PSD \n");
13101                         rtw_mp_psd (dev,info,wrqu,extra);
13102                  break;
13103         case MP_THER:
13104                         DBG_871X("set case MP_THER \n");
13105                         rtw_mp_thermal (dev,info,wrqu,extra);
13106                 break;
13107         case MP_PwrCtlDM:
13108                         DBG_871X("set MP_PwrCtlDM\n");
13109                         rtw_mp_PwrCtlDM (dev,info,wrqu,extra);
13110                 break;
13111         case MP_QueryDrvStats:          
13112                         DBG_871X("mp_get MP_QueryDrvStats \n");
13113                         rtw_mp_QueryDrv(dev,info,wdata,extra);
13114                         break;
13115                 case MP_PWRTRK:
13116                         DBG_871X("set case MP_PWRTRK \n");
13117                         rtw_mp_pwrtrk(dev,info,wrqu,extra);
13118                         break;                   
13119         case EFUSE_SET:
13120                         DBG_871X("set case efuse set \n");
13121                         rtw_mp_efuse_set(dev,info,wdata,extra);
13122                         break;                   
13123         case MP_GET_TXPOWER_INX:
13124                         DBG_871X("mp_get MP_GET_TXPOWER_INX \n");
13125                         rtw_mp_txpower_index(dev,info,wrqu,extra);
13126                 break;
13127         case MP_GETVER:
13128                         DBG_871X("mp_get MP_GETVER \n");
13129                         rtw_mp_getver(dev,info,wdata,extra);
13130                         break;
13131 #if defined(CONFIG_RTL8723A) || defined(CONFIG_RTL8723B)
13132         case MP_SetBT:          
13133                         DBG_871X("set MP_SetBT \n");
13134                         rtw_mp_SetBT(dev,info,wdata,extra);
13135                         break;           
13136 #endif
13137
13138         }
13139
13140         rtw_msleep_os(10); //delay 5ms for sending pkt before exit adb shell operation
13141 return 0;       
13142 }
13143
13144 #endif //#if defined(CONFIG_MP_INCLUDED) && defined(CONFIG_MP_IWPRIV_SUPPORT)
13145
13146 static int rtw_wfd_tdls_enable(struct net_device *dev,
13147                                 struct iw_request_info *info,
13148                                 union iwreq_data *wrqu, char *extra)
13149 {
13150         int ret = 0;
13151
13152 #ifdef CONFIG_TDLS
13153 #ifdef CONFIG_WFD
13154
13155         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13156
13157         printk( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13158
13159         if ( extra[ 0 ] == '0' )
13160         {
13161                 padapter->wdinfo.wfd_tdls_enable = 0;
13162         }
13163         else
13164         {
13165                 padapter->wdinfo.wfd_tdls_enable = 1;
13166         }
13167
13168 #endif //CONFIG_WFD
13169 #endif //CONFIG_TDLS
13170         
13171         return ret;
13172 }
13173
13174 static int rtw_tdls_weaksec(struct net_device *dev,
13175                                 struct iw_request_info *info,
13176                                 union iwreq_data *wrqu, char *extra)
13177 {
13178         int ret = 0;
13179
13180 #ifdef CONFIG_TDLS
13181
13182         u8 i, j;
13183         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13184
13185         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13186
13187         if ( extra[ 0 ] == '0' )
13188         {
13189                 padapter->wdinfo.wfd_tdls_weaksec = 0;
13190         }
13191         else
13192         {
13193                 padapter->wdinfo.wfd_tdls_weaksec = 1;
13194         }
13195 #endif
13196         
13197         return ret;
13198 }
13199
13200
13201 static int rtw_tdls_enable(struct net_device *dev,
13202                                 struct iw_request_info *info,
13203                                 union iwreq_data *wrqu, char *extra)
13204 {
13205         int ret = 0;
13206
13207 #ifdef CONFIG_TDLS
13208
13209         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13210         struct tdls_info        *ptdlsinfo = &padapter->tdlsinfo;
13211         _irqL    irqL;
13212         _list   *plist, *phead;
13213         s32     index;
13214         struct sta_info *psta = NULL;
13215         struct  sta_priv *pstapriv = &padapter->stapriv;
13216         u8 tdls_sta[NUM_STA][ETH_ALEN];
13217         u8 empty_hwaddr[ETH_ALEN] = { 0x00 };
13218         struct tdls_txmgmt txmgmt;
13219
13220         printk( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13221
13222         _rtw_memset(tdls_sta, 0x00, sizeof(tdls_sta));
13223         _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
13224
13225         if ( extra[ 0 ] == '0' )
13226         {
13227                 ptdlsinfo->tdls_enable = 0;
13228
13229                 if(pstapriv->asoc_sta_count==1)
13230                         return ret;
13231
13232                 _enter_critical_bh(&pstapriv->sta_hash_lock, &irqL);
13233                 for(index=0; index< NUM_STA; index++)
13234                 {
13235                         phead = &(pstapriv->sta_hash[index]);
13236                         plist = get_next(phead);
13237                         
13238                         while ((rtw_end_of_queue_search(phead, plist)) == _FALSE)
13239                         {
13240                                 psta = LIST_CONTAINOR(plist, struct sta_info ,hash_list);
13241
13242                                 plist = get_next(plist);
13243
13244                                 if(psta->tdls_sta_state != TDLS_STATE_NONE)
13245                                 {
13246                                         _rtw_memcpy(tdls_sta[index], psta->hwaddr, ETH_ALEN);
13247                                 }
13248                         }
13249                 }
13250                 _exit_critical_bh(&pstapriv->sta_hash_lock, &irqL);
13251
13252                 for(index=0; index< NUM_STA; index++)
13253                 {
13254                         if( !_rtw_memcmp(tdls_sta[index], empty_hwaddr, ETH_ALEN) )
13255                         {
13256                                 printk("issue tear down to "MAC_FMT"\n", MAC_ARG(tdls_sta[index]));
13257                                 txmgmt.status_code = _RSON_TDLS_TEAR_UN_RSN_;
13258                                 _rtw_memcpy(txmgmt.peer, tdls_sta[index], ETH_ALEN);
13259                                 issue_tdls_teardown(padapter, &txmgmt, _FALSE);
13260                         }
13261                 }
13262                 rtw_tdls_cmd(padapter, myid(&(padapter->eeprompriv)), TDLS_RS_RCR);
13263                 rtw_reset_tdls_info(padapter);
13264         }
13265         else if ( extra[ 0 ] == '1' )
13266         {
13267                 ptdlsinfo->tdls_enable = 1;
13268         }
13269 #endif //CONFIG_TDLS
13270         
13271         return ret;
13272 }
13273
13274 static int rtw_tdls_setup(struct net_device *dev,
13275                                 struct iw_request_info *info,
13276                                 union iwreq_data *wrqu, char *extra)
13277 {
13278         int ret = 0;
13279 #ifdef CONFIG_TDLS
13280         u8 i, j;
13281         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13282         struct tdls_txmgmt txmgmt;
13283 #ifdef CONFIG_WFD
13284         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
13285 #endif // CONFIG_WFD
13286
13287         printk( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13288
13289         if(wrqu->data.length - 1 != 17 )
13290         {
13291                 printk( "[%s] length:%d != 17\n", __FUNCTION__, (wrqu->data.length -1)  );
13292                 return ret;
13293         }
13294
13295         _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
13296         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
13297                 txmgmt.peer[i]=key_2char2num(*(extra+j), *(extra+j+1));
13298         }
13299
13300 #ifdef CONFIG_WFD
13301         if ( _AES_ != padapter->securitypriv.dot11PrivacyAlgrthm )
13302         {
13303                 //      Weak Security situation with AP.
13304                 if ( 0 == pwdinfo->wfd_tdls_weaksec )
13305                 {
13306                         //      Can't send the tdls setup request out!!
13307                         DBG_871X( "[%s] Current link is not AES, SKIP sending the tdls setup request!!\n", __FUNCTION__ );
13308                 }
13309                 else
13310                 {
13311                         issue_tdls_setup_req(padapter, &txmgmt, _TRUE);
13312                 }
13313         }
13314         else
13315 #endif // CONFIG_WFD
13316         {
13317                 issue_tdls_setup_req(padapter, &txmgmt, _TRUE);
13318         }
13319 #endif
13320         
13321         return ret;
13322 }
13323
13324 static int rtw_tdls_teardown(struct net_device *dev,
13325                                 struct iw_request_info *info,
13326                                 union iwreq_data *wrqu, char *extra)
13327 {
13328         int ret = 0;
13329
13330 #ifdef CONFIG_TDLS
13331
13332         u8 i,j;
13333         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13334         struct sta_info *ptdls_sta = NULL;
13335         struct tdls_txmgmt txmgmt;
13336
13337         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13338
13339         if(wrqu->data.length - 1 != 17 && wrqu->data.length - 1 != 19)
13340         {
13341                 printk( "[%s] length:%d != 17 or 19\n", __FUNCTION__, (wrqu->data.length -1)  );
13342                 return ret;
13343         }
13344
13345         _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
13346         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
13347                 txmgmt.peer[i]=key_2char2num(*(extra+j), *(extra+j+1));
13348         }
13349
13350         ptdls_sta = rtw_get_stainfo( &(padapter->stapriv), txmgmt.peer);
13351         
13352         if(ptdls_sta != NULL)
13353         {
13354                 txmgmt.status_code = _RSON_TDLS_TEAR_UN_RSN_;
13355                 if(wrqu->data.length - 1 == 17)
13356                         issue_tdls_teardown(padapter, &txmgmt, _FALSE);
13357                 else if(wrqu->data.length - 1 == 19)
13358                         issue_tdls_teardown(padapter, &txmgmt, _TRUE);
13359         }
13360         else
13361                 DBG_871X( "TDLS peer not found\n");
13362 #endif //CONFIG_TDLS
13363         
13364         return ret;
13365 }
13366
13367 static int rtw_tdls_discovery(struct net_device *dev,
13368                                 struct iw_request_info *info,
13369                                 union iwreq_data *wrqu, char *extra)
13370 {
13371         int ret = 0;
13372
13373 #ifdef CONFIG_TDLS
13374         
13375         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13376         struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);
13377         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
13378         struct tdls_txmgmt      txmgmt;
13379         int i = 0, j=0;
13380
13381         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13382
13383         _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
13384         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
13385                 txmgmt.peer[i]=key_2char2num(*(extra+j), *(extra+j+1));
13386         }
13387
13388         issue_tdls_dis_req(padapter, &txmgmt);
13389
13390 #endif //CONFIG_TDLS
13391
13392         return ret;
13393 }
13394
13395 static int rtw_tdls_ch_switch(struct net_device *dev,
13396                                 struct iw_request_info *info,
13397                                 union iwreq_data *wrqu, char *extra)
13398 {
13399         int ret = 0;
13400
13401 #ifdef CONFIG_TDLS
13402         
13403         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13404         struct tdls_info        *ptdlsinfo = &padapter->tdlsinfo;
13405         u8 i, j, mac_addr[ETH_ALEN];
13406         struct sta_info *ptdls_sta = NULL;
13407
13408         DBG_8192C( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13409
13410         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
13411                 mac_addr[i]=key_2char2num(*(extra+j), *(extra+j+1));
13412         }
13413
13414         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
13415         if( ptdls_sta == NULL )
13416                 return ret;
13417
13418 //      ptdlsinfo->ch_sensing=1;
13419
13420 //      rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_INIT_CH_SEN);
13421
13422 #endif //CONFIG_TDLS
13423
13424                 return ret;
13425 }
13426         
13427 static int rtw_tdls_pson(struct net_device *dev,
13428                                 struct iw_request_info *info,
13429                                 union iwreq_data *wrqu, char *extra)
13430 {
13431         int ret = 0;
13432
13433 #ifdef CONFIG_TDLS
13434         
13435         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13436         struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);
13437         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
13438         u8 i, j, mac_addr[ETH_ALEN];
13439         struct sta_info *ptdls_sta = NULL;
13440
13441         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13442
13443         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
13444                 mac_addr[i]=key_2char2num(*(extra+j), *(extra+j+1));
13445         }
13446
13447         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
13448
13449         issue_nulldata_to_TDLS_peer_STA(padapter, ptdls_sta->hwaddr, 1, 3, 500);
13450
13451 #endif //CONFIG_TDLS
13452
13453                 return ret;
13454 }
13455         
13456 static int rtw_tdls_psoff(struct net_device *dev,
13457                                 struct iw_request_info *info,
13458                                 union iwreq_data *wrqu, char *extra)
13459 {
13460         int ret = 0;
13461
13462 #ifdef CONFIG_TDLS
13463         
13464         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13465         struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);
13466         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
13467         u8 i, j, mac_addr[ETH_ALEN];
13468         struct sta_info *ptdls_sta = NULL;
13469         
13470         DBG_8192C( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13471
13472         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
13473                 mac_addr[i]=key_2char2num(*(extra+j), *(extra+j+1));
13474         }
13475
13476         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
13477
13478         if(ptdls_sta)
13479         {
13480                 //issue_tdls_peer_traffic_rsp(padapter, ptdls_sta);
13481                 issue_nulldata_to_TDLS_peer_STA(padapter, ptdls_sta->hwaddr, 0, 3, 500);
13482         }
13483 #endif //CONFIG_TDLS
13484
13485         return ret;
13486 }
13487
13488 static int rtw_tdls_setip(struct net_device *dev,
13489                                 struct iw_request_info *info,
13490                                 union iwreq_data *wrqu, char *extra)
13491 {
13492         int ret = 0;
13493
13494 #ifdef CONFIG_TDLS
13495 #ifdef CONFIG_WFD
13496         
13497         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13498         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
13499         struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
13500         u8 i=0, j=0, k=0, tag=0, ip[3] = { 0xff }, *ptr = extra;
13501         
13502         printk( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1  );
13503
13504
13505         while( i < 4 )
13506         {
13507                 for( j=0; j < 4; j++)
13508                 {
13509                         if( *( extra + j + tag ) == '.' || *( extra + j + tag ) == '\0' )
13510                         {
13511                                 if( j == 1 )
13512                                         pwfd_info->ip_address[i]=convert_ip_addr( '0', '0', *(extra+(j-1)+tag));
13513                                 if( j == 2 )
13514                                         pwfd_info->ip_address[i]=convert_ip_addr( '0', *(extra+(j-2)+tag), *(extra+(j-1)+tag));
13515                                 if( j == 3 )
13516                                         pwfd_info->ip_address[i]=convert_ip_addr( *(extra+(j-3)+tag), *(extra+(j-2)+tag), *(extra+(j-1)+tag));  
13517
13518                                 tag += j + 1;
13519                                 break;
13520                         }
13521                 }
13522                 i++;
13523         }
13524
13525         printk( "[%s] Set IP = %u.%u.%u.%u \n", __FUNCTION__, 
13526                 ptdlsinfo->wfd_info->ip_address[0], ptdlsinfo->wfd_info->ip_address[1],
13527                 ptdlsinfo->wfd_info->ip_address[2], ptdlsinfo->wfd_info->ip_address[3]
13528         );
13529
13530 #endif //CONFIG_WFD     
13531 #endif //CONFIG_TDLS
13532
13533         return ret;
13534 }
13535
13536 static int rtw_tdls_getip(struct net_device *dev,
13537                                 struct iw_request_info *info,
13538                                 union iwreq_data *wrqu, char *extra)
13539 {
13540         int ret = 0;
13541
13542 #ifdef CONFIG_TDLS
13543 #ifdef CONFIG_WFD
13544         
13545         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13546         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
13547         struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
13548         
13549         printk( "[%s]\n", __FUNCTION__);
13550
13551         sprintf( extra, "\n\n%u.%u.%u.%u\n", 
13552                 pwfd_info->peer_ip_address[0], pwfd_info->peer_ip_address[1], 
13553                 pwfd_info->peer_ip_address[2], pwfd_info->peer_ip_address[3]
13554                 );
13555
13556         printk( "[%s] IP=%u.%u.%u.%u\n", __FUNCTION__,
13557                 pwfd_info->peer_ip_address[0], pwfd_info->peer_ip_address[1], 
13558                 pwfd_info->peer_ip_address[2], pwfd_info->peer_ip_address[3]
13559                 );
13560         
13561         wrqu->data.length = strlen( extra );
13562
13563 #endif //CONFIG_WFD     
13564 #endif //CONFIG_TDLS
13565
13566         return ret;
13567 }
13568
13569 static int rtw_tdls_getport(struct net_device *dev,
13570                                struct iw_request_info *info,
13571                                union iwreq_data *wrqu, char *extra)
13572 {
13573         
13574         int ret = 0;    
13575
13576 #ifdef CONFIG_TDLS
13577 #ifdef CONFIG_WFD
13578
13579         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13580         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
13581         struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
13582
13583         printk( "[%s]\n", __FUNCTION__);
13584
13585         sprintf( extra, "\n\n%d\n", pwfd_info->peer_rtsp_ctrlport );
13586         printk( "[%s] remote port = %d\n", __FUNCTION__, pwfd_info->peer_rtsp_ctrlport );
13587         
13588         wrqu->data.length = strlen( extra );
13589
13590 #endif //CONFIG_WFD
13591 #endif //CONFIG_TDLS
13592
13593         return ret;
13594                 
13595 }
13596
13597 //WFDTDLS, for sigma test
13598 static int rtw_tdls_dis_result(struct net_device *dev,
13599                                struct iw_request_info *info,
13600                                union iwreq_data *wrqu, char *extra)
13601 {
13602         
13603         int ret = 0;    
13604
13605 #ifdef CONFIG_TDLS
13606 #ifdef CONFIG_WFD
13607
13608         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13609         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
13610         struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
13611
13612         printk( "[%s]\n", __FUNCTION__);
13613
13614         if(ptdlsinfo->dev_discovered == 1 )
13615         {
13616                 sprintf( extra, "\n\nDis=1\n" );
13617                 ptdlsinfo->dev_discovered = 0;
13618         }
13619         
13620         wrqu->data.length = strlen( extra );
13621
13622 #endif //CONFIG_WFD
13623 #endif //CONFIG_TDLS
13624
13625         return ret;
13626                 
13627 }
13628
13629 //WFDTDLS, for sigma test
13630 static int rtw_wfd_tdls_status(struct net_device *dev,
13631                                struct iw_request_info *info,
13632                                union iwreq_data *wrqu, char *extra)
13633 {
13634         
13635         int ret = 0;    
13636
13637 #ifdef CONFIG_TDLS
13638
13639         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13640         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
13641
13642         printk( "[%s]\n", __FUNCTION__);
13643
13644         sprintf( extra, "\nlink_established:0x%08x \n"
13645                 "sta_cnt:%d \n"
13646                 "sta_maximum:%d \n"
13647                 "cur_channel:%d \n"
13648                 "tdls_enable:%d",
13649                 ptdlsinfo->link_established, ptdlsinfo->sta_cnt, ptdlsinfo->sta_maximum,
13650                 ptdlsinfo->cur_channel, ptdlsinfo->tdls_enable
13651                 );
13652
13653         wrqu->data.length = strlen( extra );
13654
13655 #endif //CONFIG_TDLS
13656
13657         return ret;
13658                 
13659         }
13660
13661 static int rtw_tdls_getsta(struct net_device *dev,
13662                                struct iw_request_info *info,
13663                                union iwreq_data *wrqu, char *extra)
13664         {
13665         
13666         int ret = 0;
13667 #ifdef CONFIG_TDLS
13668         u8 i, j;
13669         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13670         u8 addr[ETH_ALEN] = {0};
13671         char charmac[17];
13672         struct sta_info *ptdls_sta = NULL;
13673
13674         printk( "[%s] %s %d\n", __FUNCTION__, (char *)wrqu->data.pointer, wrqu->data.length -1  );
13675
13676         if(copy_from_user(charmac, wrqu->data.pointer+9, 17)){
13677                 ret = -EFAULT;
13678                 goto exit;
13679         }
13680         
13681         printk("[%s] %d, charmac:%s\n", __FUNCTION__, __LINE__, charmac);
13682         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
13683                 addr[i]=key_2char2num(*(charmac+j), *(charmac+j+1));
13684         }
13685
13686         printk("[%s] %d, charmac:%s, addr:"MAC_FMT"\n", __FUNCTION__, __LINE__, charmac, MAC_ARG(addr));
13687         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, addr);  
13688         if(ptdls_sta) {
13689                 sprintf(extra, "\n\ntdls_sta_state=%d\n", ptdls_sta->tdls_sta_state);
13690                 printk("\n\ntdls_sta_state=%d\n", ptdls_sta->tdls_sta_state);
13691         }
13692         else {
13693                 sprintf(extra, "\n\nNot found this sta\n");
13694                 printk("\n\nNot found this sta\n");
13695         }
13696         wrqu->data.length = strlen( extra );
13697
13698 #endif //CONFIG_TDLS
13699 exit:
13700         return ret;
13701                 
13702 }
13703
13704 static int rtw_tdls_ch_switch_off(struct net_device *dev,
13705                                 struct iw_request_info *info,
13706                                 union iwreq_data *wrqu, char *extra)
13707 {
13708         int ret = 0;
13709
13710 #ifdef CONFIG_TDLS
13711         
13712         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13713         u8 i, j, mac_addr[ETH_ALEN];
13714         struct sta_info *ptdls_sta = NULL;
13715         
13716         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
13717
13718         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
13719                 mac_addr[i]=key_2char2num(*(extra+j), *(extra+j+1));
13720         }
13721
13722         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
13723
13724         ptdls_sta->tdls_sta_state |= TDLS_SW_OFF_STATE;
13725 /*
13726         if((ptdls_sta->tdls_sta_state & TDLS_AT_OFF_CH_STATE) && (ptdls_sta->tdls_sta_state & TDLS_PEER_AT_OFF_STATE)){
13727                 pmlmeinfo->tdls_candidate_ch= pmlmeext->cur_channel;
13728                 issue_tdls_ch_switch_req(padapter, mac_addr);
13729                 DBG_871X("issue tdls ch switch req back to base channel\n");
13730         }
13731 */
13732         
13733 #endif //CONFIG_TDLS
13734
13735         return ret;
13736 }
13737
13738 static int rtw_tdls(struct net_device *dev,
13739                                 struct iw_request_info *info,
13740                                 union iwreq_data *wrqu, char *extra)
13741 {
13742         int ret = 0;
13743
13744 #ifdef CONFIG_TDLS
13745         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13746
13747
13748
13749         DBG_871X( "[%s] extra = %s\n", __FUNCTION__, extra );
13750         //      WFD Sigma will use the tdls enable command to let the driver know we want to test the tdls now!
13751         if ( _rtw_memcmp( extra, "wfdenable=", 10 ) )
13752         {
13753                 wrqu->data.length -=10;
13754                 rtw_wfd_tdls_enable( dev, info, wrqu, &extra[10] );
13755                 return ret;
13756         }
13757         else if ( _rtw_memcmp( extra, "weaksec=", 8 ) )
13758         {
13759                 wrqu->data.length -=8;
13760                 rtw_tdls_weaksec( dev, info, wrqu, &extra[8] );
13761                 return ret;
13762         }
13763         else if ( _rtw_memcmp( extra, "tdlsenable=", 11 ) )
13764         {
13765                 wrqu->data.length -=11;
13766                 rtw_tdls_enable( dev, info, wrqu, &extra[11] );
13767                 return ret;
13768         }
13769
13770         if( padapter->tdlsinfo.tdls_enable == 0 )
13771         {
13772                 printk("tdls haven't enabled\n");
13773                 return 0;
13774         }
13775
13776         if ( _rtw_memcmp( extra, "setup=", 6 ) )
13777         {
13778                 wrqu->data.length -=6;
13779                 rtw_tdls_setup( dev, info, wrqu, &extra[6] );
13780         }
13781         else if (_rtw_memcmp( extra, "tear=", 5 ) )
13782         {
13783                 wrqu->data.length -= 5;
13784                 rtw_tdls_teardown( dev, info, wrqu, &extra[5] );
13785         }
13786         else if (_rtw_memcmp( extra, "dis=", 4 ) )
13787         {
13788                 wrqu->data.length -= 4;
13789                 rtw_tdls_discovery( dev, info, wrqu, &extra[4] );
13790         }
13791         else if (_rtw_memcmp( extra, "sw=", 3 ) )
13792         {
13793                 wrqu->data.length -= 3;
13794                 rtw_tdls_ch_switch( dev, info, wrqu, &extra[3] );
13795         }
13796         else if (_rtw_memcmp( extra, "swoff=", 6 ) )
13797         {
13798                 wrqu->data.length -= 6;
13799                 rtw_tdls_ch_switch_off( dev, info, wrqu, &extra[6] );
13800         }       
13801         else if (_rtw_memcmp( extra, "pson=", 5 ) )
13802         {
13803                 wrqu->data.length -= 5;
13804                 rtw_tdls_pson( dev, info, wrqu, &extra[5] );
13805         }
13806         else if (_rtw_memcmp( extra, "psoff=", 6 ) )
13807         {
13808                 wrqu->data.length -= 6;
13809                 rtw_tdls_psoff( dev, info, wrqu, &extra[6] );
13810         }
13811 #ifdef CONFIG_WFD
13812         else if (_rtw_memcmp( extra, "setip=", 6 ) )
13813         {
13814                 wrqu->data.length -= 6;
13815                 rtw_tdls_setip( dev, info, wrqu, &extra[6] );
13816         }
13817         else if (_rtw_memcmp( extra, "tprobe=", 6 ) )
13818         {
13819                 issue_tunneled_probe_req((_adapter *)rtw_netdev_priv(dev));
13820         }
13821 #endif //CONFIG_WFD
13822
13823 #endif //CONFIG_TDLS
13824         
13825         return ret;
13826 }
13827
13828
13829 static int rtw_tdls_get(struct net_device *dev,
13830                                 struct iw_request_info *info,
13831                                 union iwreq_data *wrqu, char *extra)
13832 {
13833         int ret = 0;
13834
13835 #ifdef CONFIG_WFD
13836
13837         DBG_871X( "[%s] extra = %s\n", __FUNCTION__, (char*) wrqu->data.pointer );
13838
13839         if ( _rtw_memcmp( wrqu->data.pointer, "ip", 2 ) )
13840         {
13841                 rtw_tdls_getip( dev, info, wrqu, extra );
13842         }
13843         if ( _rtw_memcmp( wrqu->data.pointer, "port", 4 ) )
13844         {
13845                 rtw_tdls_getport( dev, info, wrqu, extra );
13846         }
13847         //WFDTDLS, for sigma test
13848         if ( _rtw_memcmp( wrqu->data.pointer, "dis", 3 ) )
13849         {
13850                 rtw_tdls_dis_result( dev, info, wrqu, extra );
13851         }
13852         if ( _rtw_memcmp( wrqu->data.pointer, "status", 6 ) )
13853         {
13854                 rtw_wfd_tdls_status( dev, info, wrqu, extra );
13855         }
13856         if ( _rtw_memcmp( wrqu->data.pointer, "tdls_sta=", 9 ) )
13857         {
13858                 rtw_tdls_getsta( dev, info, wrqu, extra );
13859         }
13860
13861 #endif //CONFIG_WFD
13862
13863         return ret;
13864 }
13865
13866
13867
13868
13869
13870 #ifdef CONFIG_INTEL_WIDI
13871 static int rtw_widi_set(struct net_device *dev,
13872                                struct iw_request_info *info,
13873                                union iwreq_data *wrqu, char *extra)
13874 {
13875         int ret = 0;
13876         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
13877
13878         process_intel_widi_cmd(padapter, extra);
13879
13880         return ret;
13881 }
13882
13883 static int rtw_widi_set_probe_request(struct net_device *dev,
13884                                struct iw_request_info *info,
13885                                union iwreq_data *wrqu, char *extra)
13886 {
13887         int     ret = 0;
13888         u8      *pbuf = NULL;
13889         _adapter        *padapter = (_adapter *)rtw_netdev_priv(dev);
13890
13891         pbuf = rtw_malloc(sizeof(l2_msg_t));
13892         if(pbuf)
13893         {
13894                 if ( copy_from_user(pbuf, wrqu->data.pointer, wrqu->data.length) )
13895                         ret = -EFAULT;
13896                 //_rtw_memcpy(pbuf, wrqu->data.pointer, wrqu->data.length);
13897
13898                 if( wrqu->data.flags == 0 )
13899                         intel_widi_wk_cmd(padapter, INTEL_WIDI_ISSUE_PROB_WK, pbuf, sizeof(l2_msg_t));
13900                 else if( wrqu->data.flags == 1 )
13901                         rtw_set_wfd_rds_sink_info( padapter, (l2_msg_t *)pbuf );
13902         }
13903         return ret;
13904 }
13905 #endif // CONFIG_INTEL_WIDI
13906
13907 #ifdef CONFIG_MAC_LOOPBACK_DRIVER
13908
13909 #ifdef CONFIG_RTL8723A
13910 extern void rtl8723a_cal_txdesc_chksum(struct tx_desc *ptxdesc);
13911 #define cal_txdesc_chksum rtl8723a_cal_txdesc_chksum
13912 extern void rtl8723a_fill_default_txdesc(struct xmit_frame *pxmitframe, u8 *pbuf);
13913 #define fill_default_txdesc rtl8723a_fill_default_txdesc
13914 #endif
13915 #if defined(CONFIG_RTL8188E)
13916 #include <rtl8188e_hal.h>
13917 extern void rtl8188e_cal_txdesc_chksum(struct tx_desc *ptxdesc);
13918 #define cal_txdesc_chksum rtl8188e_cal_txdesc_chksum
13919 #ifdef CONFIG_SDIO_HCI || defined(CONFIG_GSPI_HCI)
13920 extern void rtl8188es_fill_default_txdesc(struct xmit_frame *pxmitframe, u8 *pbuf);
13921 #define fill_default_txdesc rtl8188es_fill_default_txdesc
13922 #endif // CONFIG_SDIO_HCI
13923 #endif // CONFIG_RTL8188E
13924 #if defined(CONFIG_RTL8723B)
13925 extern void rtl8723b_cal_txdesc_chksum(struct tx_desc *ptxdesc);
13926 #define cal_txdesc_chksum rtl8723b_cal_txdesc_chksum
13927 extern void rtl8723b_fill_default_txdesc(struct xmit_frame *pxmitframe, u8 *pbuf);
13928 #define fill_default_txdesc rtl8723b_fill_default_txdesc
13929 #endif // CONFIG_RTL8723B
13930 #if defined(CONFIG_RTL8192E)
13931 extern void rtl8192e_cal_txdesc_chksum(struct tx_desc *ptxdesc);
13932 #define cal_txdesc_chksum rtl8192e_cal_txdesc_chksum
13933 #ifdef CONFIG_SDIO_HCI || defined(CONFIG_GSPI_HCI)
13934 extern void rtl8192es_fill_default_txdesc(struct xmit_frame *pxmitframe, u8 *pbuf);
13935 #define fill_default_txdesc rtl8192es_fill_default_txdesc
13936 #endif // CONFIG_SDIO_HCI
13937 #endif //CONFIG_RTL8192E
13938
13939 static s32 initLoopback(PADAPTER padapter)
13940 {
13941         PLOOPBACKDATA ploopback;
13942
13943
13944         if (padapter->ploopback == NULL) {
13945                 ploopback = (PLOOPBACKDATA)rtw_zmalloc(sizeof(LOOPBACKDATA));
13946                 if (ploopback == NULL) return -ENOMEM;
13947
13948                 _rtw_init_sema(&ploopback->sema, 0);
13949                 ploopback->bstop = _TRUE;
13950                 ploopback->cnt = 0;
13951                 ploopback->size = 300;
13952                 _rtw_memset(ploopback->msg, 0, sizeof(ploopback->msg));
13953
13954                 padapter->ploopback = ploopback;
13955         }
13956
13957         return 0;
13958 }
13959
13960 static void freeLoopback(PADAPTER padapter)
13961 {
13962         PLOOPBACKDATA ploopback;
13963
13964
13965         ploopback = padapter->ploopback;
13966         if (ploopback) {
13967                 rtw_mfree((u8*)ploopback, sizeof(LOOPBACKDATA));
13968                 padapter->ploopback = NULL;
13969         }
13970 }
13971
13972 static s32 initpseudoadhoc(PADAPTER padapter)
13973 {
13974         NDIS_802_11_NETWORK_INFRASTRUCTURE networkType;
13975         s32 err;
13976
13977         networkType = Ndis802_11IBSS;
13978         err = rtw_set_802_11_infrastructure_mode(padapter, networkType);
13979         if (err == _FALSE) return _FAIL;
13980
13981         err = rtw_setopmode_cmd(padapter, networkType,_TRUE);
13982         if (err == _FAIL) return _FAIL;
13983
13984         return _SUCCESS;
13985 }
13986
13987 static s32 createpseudoadhoc(PADAPTER padapter)
13988 {
13989         NDIS_802_11_AUTHENTICATION_MODE authmode;
13990         struct mlme_priv *pmlmepriv;
13991         NDIS_802_11_SSID *passoc_ssid;
13992         WLAN_BSSID_EX *pdev_network;
13993         u8 *pibss;
13994         u8 ssid[] = "pseduo_ad-hoc";
13995         s32 err;
13996         _irqL irqL;
13997
13998
13999         pmlmepriv = &padapter->mlmepriv;
14000
14001         authmode = Ndis802_11AuthModeOpen;
14002         err = rtw_set_802_11_authentication_mode(padapter, authmode);
14003         if (err == _FALSE) return _FAIL;
14004
14005         passoc_ssid = &pmlmepriv->assoc_ssid;
14006         _rtw_memset(passoc_ssid, 0, sizeof(NDIS_802_11_SSID));
14007         passoc_ssid->SsidLength = sizeof(ssid) - 1;
14008         _rtw_memcpy(passoc_ssid->Ssid, ssid, passoc_ssid->SsidLength);
14009
14010         pdev_network = &padapter->registrypriv.dev_network;
14011         pibss = padapter->registrypriv.dev_network.MacAddress;
14012         _rtw_memcpy(&pdev_network->Ssid, passoc_ssid, sizeof(NDIS_802_11_SSID));
14013
14014         rtw_update_registrypriv_dev_network(padapter);
14015         rtw_generate_random_ibss(pibss);
14016
14017         _enter_critical_bh(&pmlmepriv->lock, &irqL);
14018         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
14019         _exit_critical_bh(&pmlmepriv->lock, &irqL);
14020
14021 #if 0
14022         err = rtw_createbss_cmd(padapter);
14023         if (err == _FAIL) return _FAIL;
14024 #else
14025 {
14026         struct wlan_network *pcur_network;
14027         struct sta_info *psta;
14028
14029         //3  create a new psta
14030         pcur_network = &pmlmepriv->cur_network;
14031
14032         //clear psta in the cur_network, if any
14033         psta = rtw_get_stainfo(&padapter->stapriv, pcur_network->network.MacAddress);
14034         if (psta) rtw_free_stainfo(padapter, psta);
14035
14036         psta = rtw_alloc_stainfo(&padapter->stapriv, pibss);
14037         if (psta == NULL) return _FAIL;
14038
14039         //3  join psudo AdHoc
14040         pcur_network->join_res = 1;
14041         pcur_network->aid = psta->aid = 1;
14042         _rtw_memcpy(&pcur_network->network, pdev_network, get_WLAN_BSSID_EX_sz(pdev_network));
14043
14044         // set msr to WIFI_FW_ADHOC_STATE
14045 #if 0
14046         Set_NETYPE0_MSR(padapter, WIFI_FW_ADHOC_STATE);
14047 #else
14048         {
14049                 u8 val8;
14050
14051                 val8 = rtw_read8(padapter, MSR);
14052                 val8 &= 0xFC; // clear NETYPE0
14053                 val8 |= WIFI_FW_ADHOC_STATE & 0x3;
14054                 rtw_write8(padapter, MSR, val8);
14055         }
14056 #endif
14057 }
14058 #endif
14059
14060         return _SUCCESS;
14061 }
14062
14063 static struct xmit_frame* createloopbackpkt(PADAPTER padapter, u32 size)
14064 {
14065         struct xmit_priv *pxmitpriv;
14066         struct xmit_frame *pframe;
14067         struct xmit_buf *pxmitbuf;
14068         struct pkt_attrib *pattrib;
14069         struct tx_desc *desc;
14070         u8 *pkt_start, *pkt_end, *ptr;
14071         struct rtw_ieee80211_hdr *hdr;
14072         s32 bmcast;
14073         _irqL irqL;
14074
14075
14076         if ((TXDESC_SIZE + WLANHDR_OFFSET + size) > MAX_XMITBUF_SZ) return NULL;
14077
14078         pxmitpriv = &padapter->xmitpriv;
14079         pframe = NULL;
14080
14081         //2 1. allocate xmit frame
14082         pframe = rtw_alloc_xmitframe(pxmitpriv);
14083         if (pframe == NULL) return NULL;
14084         pframe->padapter = padapter;
14085
14086         //2 2. allocate xmit buffer
14087         _enter_critical_bh(&pxmitpriv->lock, &irqL);
14088         pxmitbuf = rtw_alloc_xmitbuf(pxmitpriv);
14089         _exit_critical_bh(&pxmitpriv->lock, &irqL);
14090         if (pxmitbuf == NULL) {
14091                 rtw_free_xmitframe(pxmitpriv, pframe);
14092                 return NULL;
14093         }
14094
14095         pframe->pxmitbuf = pxmitbuf;
14096         pframe->buf_addr = pxmitbuf->pbuf;
14097         pxmitbuf->priv_data = pframe;
14098
14099         //2 3. update_attrib()
14100         pattrib = &pframe->attrib;
14101
14102         // init xmitframe attribute
14103         _rtw_memset(pattrib, 0, sizeof(struct pkt_attrib));
14104
14105         pattrib->ether_type = 0x8723;
14106         _rtw_memcpy(pattrib->src, padapter->eeprompriv.mac_addr, ETH_ALEN);
14107         _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);
14108         _rtw_memset(pattrib->dst, 0xFF, ETH_ALEN);
14109         _rtw_memcpy(pattrib->ra, pattrib->dst, ETH_ALEN);
14110
14111 //      pattrib->dhcp_pkt = 0;
14112 //      pattrib->pktlen = 0;
14113         pattrib->ack_policy = 0;
14114 //      pattrib->pkt_hdrlen = ETH_HLEN;
14115         pattrib->hdrlen = WLAN_HDR_A3_LEN;
14116         pattrib->subtype = WIFI_DATA;
14117         pattrib->priority = 0;
14118         pattrib->qsel = pattrib->priority;
14119 //      do_queue_select(padapter, pattrib);
14120         pattrib->nr_frags = 1;
14121         pattrib->encrypt = 0;
14122         pattrib->bswenc = _FALSE;
14123         pattrib->qos_en = _FALSE;
14124
14125         bmcast = IS_MCAST(pattrib->ra);
14126         if (bmcast) {
14127                 pattrib->mac_id = 1;
14128                 pattrib->psta = rtw_get_bcmc_stainfo(padapter);
14129         } else {
14130                 pattrib->mac_id = 0;
14131                 pattrib->psta = rtw_get_stainfo(&padapter->stapriv, get_bssid(&padapter->mlmepriv));
14132         }
14133
14134         pattrib->pktlen = size;
14135         pattrib->last_txcmdsz = pattrib->hdrlen + pattrib->pktlen;
14136
14137         //2 4. fill TX descriptor
14138         desc = (struct tx_desc*)pframe->buf_addr;
14139         _rtw_memset(desc, 0, TXDESC_SIZE);
14140
14141         fill_default_txdesc(pframe, (u8*)desc);
14142
14143         // Hw set sequence number
14144         ((PTXDESC)desc)->hwseq_en = 0; // HWSEQ_EN, 0:disable, 1:enable
14145 //      ((PTXDESC)desc)->hwseq_sel = 0; // HWSEQ_SEL
14146
14147         ((PTXDESC)desc)->disdatafb = 1;
14148
14149         // convert to little endian
14150         desc->txdw0 = cpu_to_le32(desc->txdw0);
14151         desc->txdw1 = cpu_to_le32(desc->txdw1);
14152         desc->txdw2 = cpu_to_le32(desc->txdw2);
14153         desc->txdw3 = cpu_to_le32(desc->txdw3);
14154         desc->txdw4 = cpu_to_le32(desc->txdw4);
14155         desc->txdw5 = cpu_to_le32(desc->txdw5);
14156         desc->txdw6 = cpu_to_le32(desc->txdw6);
14157         desc->txdw7 = cpu_to_le32(desc->txdw7);
14158 #ifdef CONFIG_PCI_HCI
14159         desc->txdw8 = cpu_to_le32(desc->txdw8);
14160         desc->txdw9 = cpu_to_le32(desc->txdw9);
14161         desc->txdw10 = cpu_to_le32(desc->txdw10);
14162         desc->txdw11 = cpu_to_le32(desc->txdw11);
14163         desc->txdw12 = cpu_to_le32(desc->txdw12);
14164         desc->txdw13 = cpu_to_le32(desc->txdw13);
14165         desc->txdw14 = cpu_to_le32(desc->txdw14);
14166         desc->txdw15 = cpu_to_le32(desc->txdw15);
14167 #endif
14168
14169         cal_txdesc_chksum(desc);
14170
14171         //2 5. coalesce
14172         pkt_start = pframe->buf_addr + TXDESC_SIZE;
14173         pkt_end = pkt_start + pattrib->last_txcmdsz;
14174
14175         //3 5.1. make wlan header, make_wlanhdr()
14176         hdr = (struct rtw_ieee80211_hdr *)pkt_start;
14177         SetFrameSubType(&hdr->frame_ctl, pattrib->subtype);
14178         _rtw_memcpy(hdr->addr1, pattrib->dst, ETH_ALEN); // DA
14179         _rtw_memcpy(hdr->addr2, pattrib->src, ETH_ALEN); // SA
14180         _rtw_memcpy(hdr->addr3, get_bssid(&padapter->mlmepriv), ETH_ALEN); // RA, BSSID
14181
14182         //3 5.2. make payload
14183         ptr = pkt_start + pattrib->hdrlen;
14184         get_random_bytes(ptr, pkt_end - ptr);
14185
14186         pxmitbuf->len = TXDESC_SIZE + pattrib->last_txcmdsz;
14187         pxmitbuf->ptail += pxmitbuf->len;
14188
14189         return pframe;
14190 }
14191
14192 static void freeloopbackpkt(PADAPTER padapter, struct xmit_frame *pframe)
14193 {
14194         struct xmit_priv *pxmitpriv;
14195         struct xmit_buf *pxmitbuf;
14196
14197
14198         pxmitpriv = &padapter->xmitpriv;
14199         pxmitbuf = pframe->pxmitbuf;
14200
14201         rtw_free_xmitframe(pxmitpriv, pframe);
14202         rtw_free_xmitbuf(pxmitpriv, pxmitbuf);
14203 }
14204
14205 static void printdata(u8 *pbuf, u32 len)
14206 {
14207         u32 i, val;
14208
14209
14210         for (i = 0; (i+4) <= len; i+=4) {
14211                 printk("%08X", *(u32*)(pbuf + i));
14212                 if ((i+4) & 0x1F) printk(" ");
14213                 else printk("\n");
14214         }
14215
14216         if (i < len)
14217         {
14218 #ifdef CONFIG_BIG_ENDIAN
14219                 for (; i < len, i++)
14220                         printk("%02X", pbuf+i);
14221 #else // CONFIG_LITTLE_ENDIAN
14222 #if 0
14223                 val = 0;
14224                 _rtw_memcpy(&val, pbuf + i, len - i);
14225                 printk("%8X", val);
14226 #else
14227                 u8 str[9];
14228                 u8 n;
14229                 val = 0;
14230                 n = len - i;
14231                 _rtw_memcpy(&val, pbuf+i, n);
14232                 sprintf(str, "%08X", val);
14233                 n = (4 - n) * 2;
14234                 printk("%8s", str+n);
14235 #endif
14236 #endif // CONFIG_LITTLE_ENDIAN
14237         }
14238         printk("\n");
14239 }
14240
14241 static u8 pktcmp(PADAPTER padapter, u8 *txbuf, u32 txsz, u8 *rxbuf, u32 rxsz)
14242 {
14243         PHAL_DATA_TYPE phal;
14244         struct recv_stat *prxstat;
14245         struct recv_stat report;
14246         PRXREPORT prxreport;
14247         u32 drvinfosize;
14248         u32 rxpktsize;
14249         u8 fcssize;
14250         u8 ret = _FALSE;
14251
14252         prxstat = (struct recv_stat*)rxbuf;
14253         report.rxdw0 = le32_to_cpu(prxstat->rxdw0);
14254         report.rxdw1 = le32_to_cpu(prxstat->rxdw1);
14255         report.rxdw2 = le32_to_cpu(prxstat->rxdw2);
14256         report.rxdw3 = le32_to_cpu(prxstat->rxdw3);
14257         report.rxdw4 = le32_to_cpu(prxstat->rxdw4);
14258         report.rxdw5 = le32_to_cpu(prxstat->rxdw5);
14259
14260         prxreport = (PRXREPORT)&report;
14261         drvinfosize = prxreport->drvinfosize << 3;
14262         rxpktsize = prxreport->pktlen;
14263
14264         phal = GET_HAL_DATA(padapter);
14265         if (phal->ReceiveConfig & RCR_APPFCS) fcssize = IEEE80211_FCS_LEN;
14266         else fcssize = 0;
14267
14268         if ((txsz - TXDESC_SIZE) != (rxpktsize - fcssize)) {
14269                 DBG_8192C("%s: ERROR! size not match tx/rx=%d/%d !\n",
14270                         __func__, txsz - TXDESC_SIZE, rxpktsize - fcssize);
14271                 ret = _FALSE;
14272         } else {
14273                 ret = _rtw_memcmp(txbuf + TXDESC_SIZE,\
14274                                                   rxbuf + RXDESC_SIZE + drvinfosize,\
14275                                                   txsz - TXDESC_SIZE);
14276                 if (ret == _FALSE) {
14277                         DBG_8192C("%s: ERROR! pkt content mismatch!\n", __func__);
14278                 }
14279         }
14280
14281         if (ret == _FALSE)
14282         {
14283                 DBG_8192C("\n%s: TX PKT total=%d, desc=%d, content=%d\n",
14284                         __func__, txsz, TXDESC_SIZE, txsz - TXDESC_SIZE);
14285                 DBG_8192C("%s: TX DESC size=%d\n", __func__, TXDESC_SIZE);
14286                 printdata(txbuf, TXDESC_SIZE);
14287                 DBG_8192C("%s: TX content size=%d\n", __func__, txsz - TXDESC_SIZE);
14288                 printdata(txbuf + TXDESC_SIZE, txsz - TXDESC_SIZE);
14289
14290                 DBG_8192C("\n%s: RX PKT read=%d offset=%d(%d,%d) content=%d\n",
14291                         __func__, rxsz, RXDESC_SIZE + drvinfosize, RXDESC_SIZE, drvinfosize, rxpktsize);
14292                 if (rxpktsize != 0)
14293                 {
14294                         DBG_8192C("%s: RX DESC size=%d\n", __func__, RXDESC_SIZE);
14295                         printdata(rxbuf, RXDESC_SIZE);
14296                         DBG_8192C("%s: RX drvinfo size=%d\n", __func__, drvinfosize);
14297                         printdata(rxbuf + RXDESC_SIZE, drvinfosize);
14298                         DBG_8192C("%s: RX content size=%d\n", __func__, rxpktsize);
14299                         printdata(rxbuf + RXDESC_SIZE + drvinfosize, rxpktsize);
14300                 } else {
14301                         DBG_8192C("%s: RX data size=%d\n", __func__, rxsz);
14302                         printdata(rxbuf, rxsz);
14303                 }
14304         }
14305
14306         return ret;
14307 }
14308
14309 thread_return lbk_thread(thread_context context)
14310 {
14311         s32 err;
14312         PADAPTER padapter;
14313         PLOOPBACKDATA ploopback;
14314         struct xmit_frame *pxmitframe;
14315         u32 cnt, ok, fail, headerlen;
14316         u32 pktsize;
14317         u32 ff_hwaddr;
14318
14319
14320         padapter = (PADAPTER)context;
14321         ploopback = padapter->ploopback;
14322         if (ploopback == NULL) return -1;
14323         cnt = 0;
14324         ok = 0;
14325         fail = 0;
14326
14327         daemonize("%s", "RTW_LBK_THREAD");
14328         allow_signal(SIGTERM);
14329
14330         do {
14331                 if (ploopback->size == 0) {
14332                         get_random_bytes(&pktsize, 4);
14333                         pktsize = (pktsize % 1535) + 1; // 1~1535
14334                 } else
14335                         pktsize = ploopback->size;
14336                 
14337                 pxmitframe = createloopbackpkt(padapter, pktsize);
14338                 if (pxmitframe == NULL) {
14339                         sprintf(ploopback->msg, "loopback FAIL! 3. create Packet FAIL!");
14340                         break;
14341                 }
14342
14343                 ploopback->txsize = TXDESC_SIZE + pxmitframe->attrib.last_txcmdsz;
14344                 _rtw_memcpy(ploopback->txbuf, pxmitframe->buf_addr, ploopback->txsize);
14345                 ff_hwaddr = rtw_get_ff_hwaddr(pxmitframe);
14346                 cnt++;
14347                 DBG_8192C("%s: wirte port cnt=%d size=%d\n", __func__, cnt, ploopback->txsize);
14348                 pxmitframe->pxmitbuf->pdata = ploopback->txbuf;
14349                 rtw_write_port(padapter, ff_hwaddr, ploopback->txsize, (u8 *)pxmitframe->pxmitbuf);
14350
14351                 // wait for rx pkt
14352                 _rtw_down_sema(&ploopback->sema);
14353
14354                 err = pktcmp(padapter, ploopback->txbuf, ploopback->txsize, ploopback->rxbuf, ploopback->rxsize);
14355                 if (err == _TRUE)
14356                         ok++;
14357                 else
14358                         fail++;
14359
14360                 ploopback->txsize = 0;
14361                 _rtw_memset(ploopback->txbuf, 0, 0x8000);
14362                 ploopback->rxsize = 0;
14363                 _rtw_memset(ploopback->rxbuf, 0, 0x8000);
14364
14365                 freeloopbackpkt(padapter, pxmitframe);
14366                 pxmitframe = NULL;
14367
14368                 if (signal_pending(current)) {
14369                         flush_signals(current);
14370                 }
14371
14372                 if ((ploopback->bstop == _TRUE) ||
14373                         ((ploopback->cnt != 0) && (ploopback->cnt == cnt)))
14374                 {
14375                         u32 ok_rate, fail_rate, all;
14376                         all = cnt;
14377                         ok_rate = (ok*100)/all;
14378                         fail_rate = (fail*100)/all;
14379                         sprintf(ploopback->msg,\
14380                                         "loopback result: ok=%d%%(%d/%d),error=%d%%(%d/%d)",\
14381                                         ok_rate, ok, all, fail_rate, fail, all);
14382                         break;
14383                 }
14384         } while (1);
14385
14386         ploopback->bstop = _TRUE;
14387
14388         thread_exit();
14389 }
14390
14391 static void loopbackTest(PADAPTER padapter, u32 cnt, u32 size, u8* pmsg)
14392 {
14393         PLOOPBACKDATA ploopback;
14394         u32 len;
14395         s32 err;
14396
14397
14398         ploopback = padapter->ploopback;
14399
14400         if (ploopback)
14401         {
14402                 if (ploopback->bstop == _FALSE) {
14403                         ploopback->bstop = _TRUE;
14404                         _rtw_up_sema(&ploopback->sema);
14405                 }
14406                 len = 0;
14407                 do {
14408                         len = strlen(ploopback->msg);
14409                         if (len) break;
14410                         rtw_msleep_os(1);
14411                 } while (1);
14412                 _rtw_memcpy(pmsg, ploopback->msg, len+1);
14413                 freeLoopback(padapter);
14414
14415                 return;
14416         }
14417
14418         // disable dynamic algorithm
14419         {
14420         u32 DMFlag = DYNAMIC_FUNC_DISABLE;
14421         rtw_hal_get_hwreg(padapter, HW_VAR_DM_FLAG, (u8*)&DMFlag);
14422         }
14423
14424         // create pseudo ad-hoc connection
14425         err = initpseudoadhoc(padapter);
14426         if (err == _FAIL) {
14427                 sprintf(pmsg, "loopback FAIL! 1.1 init ad-hoc FAIL!");
14428                 return;
14429         }
14430
14431         err = createpseudoadhoc(padapter);
14432         if (err == _FAIL) {
14433                 sprintf(pmsg, "loopback FAIL! 1.2 create ad-hoc master FAIL!");
14434                 return;
14435         }
14436
14437         err = initLoopback(padapter);
14438         if (err) {
14439                 sprintf(pmsg, "loopback FAIL! 2. init FAIL! error code=%d", err);
14440                 return;
14441         }
14442
14443         ploopback = padapter->ploopback;
14444
14445         ploopback->bstop = _FALSE;
14446         ploopback->cnt = cnt;
14447         ploopback->size = size;
14448         ploopback->lbkthread = kthread_run(lbk_thread, padapter, "RTW_LBK_THREAD");
14449         if (IS_ERR(padapter->lbkthread))
14450         {
14451                 freeLoopback(padapter);
14452                 sprintf(pmsg, "loopback start FAIL! cnt=%d", cnt);
14453                 return;
14454         }
14455
14456         sprintf(pmsg, "loopback start! cnt=%d", cnt);
14457 }
14458 #endif // CONFIG_MAC_LOOPBACK_DRIVER
14459
14460 static int rtw_test(
14461         struct net_device *dev,
14462         struct iw_request_info *info,
14463         union iwreq_data *wrqu, char *extra)
14464 {
14465         u32 len;
14466         u8 *pbuf, *pch;
14467         char *ptmp;
14468         u8 *delim = ",";
14469         PADAPTER padapter = rtw_netdev_priv(dev);
14470
14471
14472         DBG_871X("+%s\n", __func__);
14473         len = wrqu->data.length;
14474
14475         pbuf = (u8*)rtw_zmalloc(len);
14476         if (pbuf == NULL) {
14477                 DBG_871X("%s: no memory!\n", __func__);
14478                 return -ENOMEM;
14479         }
14480
14481         if (copy_from_user(pbuf, wrqu->data.pointer, len)) {
14482                 rtw_mfree(pbuf, len);
14483                 DBG_871X("%s: copy from user fail!\n", __func__);
14484                 return -EFAULT;
14485         }
14486         DBG_871X("%s: string=\"%s\"\n", __func__, pbuf);
14487
14488         ptmp = (char*)pbuf;
14489         pch = strsep(&ptmp, delim);
14490         if ((pch == NULL) || (strlen(pch) == 0)) {
14491                 rtw_mfree(pbuf, len);
14492                 DBG_871X("%s: parameter error(level 1)!\n", __func__);
14493                 return -EFAULT;
14494         }
14495
14496 #ifdef CONFIG_MAC_LOOPBACK_DRIVER
14497         if (strcmp(pch, "loopback") == 0)
14498         {
14499                 s32 cnt = 0;
14500                 u32 size = 64;
14501
14502                 pch = strsep(&ptmp, delim);
14503                 if ((pch == NULL) || (strlen(pch) == 0)) {
14504                         rtw_mfree(pbuf, len);
14505                         DBG_871X("%s: parameter error(level 2)!\n", __func__);
14506                         return -EFAULT;
14507                 }
14508
14509                 sscanf(pch, "%d", &cnt);
14510                 DBG_871X("%s: loopback cnt=%d\n", __func__, cnt);
14511
14512                 pch = strsep(&ptmp, delim);
14513                 if ((pch == NULL) || (strlen(pch) == 0)) {
14514                         rtw_mfree(pbuf, len);
14515                         DBG_871X("%s: parameter error(level 2)!\n", __func__);
14516                         return -EFAULT;
14517                 }
14518
14519                 sscanf(pch, "%d", &size);
14520                 DBG_871X("%s: loopback size=%d\n", __func__, size);
14521
14522                 loopbackTest(padapter, cnt, size, extra);
14523                 wrqu->data.length = strlen(extra) + 1;
14524
14525                 rtw_mfree(pbuf, len);
14526                 return 0;
14527         }
14528 #endif
14529
14530 #if 0
14531 //#ifdef CONFIG_RTL8723A
14532         if (strcmp(pch, "poweron") == 0)
14533         {
14534                 s32 ret;
14535
14536                 ret = _InitPowerOn(padapter);
14537                 DBG_871X("%s: power on %s\n", __func__, (_FAIL==ret) ? "FAIL!":"OK.");
14538                 sprintf(extra, "Power ON %s", (_FAIL==ret) ? "FAIL!":"OK.");
14539                 wrqu->data.length = strlen(extra) + 1;
14540
14541                 rtw_mfree(pbuf, len);
14542                 return 0;
14543         }
14544
14545         if (strcmp(pch, "dlfw") == 0)
14546         {
14547                 s32 ret;
14548
14549                 ret = rtl8723a_FirmwareDownload(padapter);
14550                 DBG_871X("%s: download FW %s\n", __func__, (_FAIL==ret) ? "FAIL!":"OK.");
14551                 sprintf(extra, "download FW %s", (_FAIL==ret) ? "FAIL!":"OK.");
14552                 wrqu->data.length = strlen(extra) + 1;
14553
14554                 rtw_mfree(pbuf, len);
14555                 return 0;
14556         }
14557 #endif
14558
14559 #ifdef CONFIG_BT_COEXIST
14560         if (strcmp(pch, "bton") == 0)
14561         {
14562                 rtw_btcoex_SetManualControl(padapter, _FALSE);
14563         }
14564         else if (strcmp(pch, "btoff") == 0)
14565         {
14566                 rtw_btcoex_SetManualControl(padapter, _TRUE);
14567         }
14568         else if (strcmp(pch, "h2c") == 0)
14569         {
14570                 u8 param[8];
14571                 u8 count = 0;
14572                 u32 tmp;
14573                 u8 i;
14574                 u32 pos;
14575                 s32 ret;
14576
14577
14578                 do {
14579                         pch = strsep(&ptmp, delim);
14580                         if ((pch == NULL) || (strlen(pch) == 0))
14581                                 break;
14582
14583                         sscanf(pch, "%x", &tmp);
14584                         param[count++] = (u8)tmp;
14585                 } while (count < 8);
14586
14587                 if (count == 0) {
14588                         rtw_mfree(pbuf, len);
14589                         DBG_871X("%s: parameter error(level 2)!\n", __func__);
14590                         return -EFAULT;
14591                 }
14592
14593                 ret = rtw_hal_fill_h2c_cmd(padapter, param[0], count-1, &param[1]);
14594
14595                 pos = sprintf(extra, "H2C ID=0x%02x content=", param[0]);
14596                 for (i=1; i<count; i++) {
14597                         pos += sprintf(extra+pos, "%02x,", param[i]);
14598                 }
14599                 extra[pos] = 0;
14600                 pos--;
14601                 pos += sprintf(extra+pos, " %s", ret==_FAIL?"FAIL":"OK");
14602
14603                 wrqu->data.length = strlen(extra) + 1;
14604         }
14605         else if (strcmp(pch, "ba_rxbuf_sz") == 0)
14606         {
14607                 u8 ba_rxbuf_bz;
14608
14609                 pch = strsep(&ptmp, delim);
14610                 if ((pch != NULL) && (strlen(pch) != 0)) {
14611                         sscanf(pch, "%hhu", &ba_rxbuf_bz);
14612                         DBG_871X("%s set ba_rxbuf_bz as %u\n", __func__, ba_rxbuf_bz);
14613                         padapter->fix_ba_rxbuf_bz = ba_rxbuf_bz;
14614                         rtw_btcoex_RejectApAggregatedPacket(padapter, _TRUE);
14615                         rtw_btcoex_RejectApAggregatedPacket(padapter, _FALSE);
14616                 }
14617         }
14618
14619 #endif // CONFIG_BT_COEXIST
14620
14621         rtw_mfree(pbuf, len);
14622         return 0;
14623 }
14624
14625 static iw_handler rtw_handlers[] =
14626 {
14627         NULL,                                   /* SIOCSIWCOMMIT */
14628         rtw_wx_get_name,                /* SIOCGIWNAME */
14629         dummy,                                  /* SIOCSIWNWID */
14630         dummy,                                  /* SIOCGIWNWID */
14631         rtw_wx_set_freq,                /* SIOCSIWFREQ */
14632         rtw_wx_get_freq,                /* SIOCGIWFREQ */
14633         rtw_wx_set_mode,                /* SIOCSIWMODE */
14634         rtw_wx_get_mode,                /* SIOCGIWMODE */
14635         dummy,                                  /* SIOCSIWSENS */
14636         rtw_wx_get_sens,                /* SIOCGIWSENS */
14637         NULL,                                   /* SIOCSIWRANGE */
14638         rtw_wx_get_range,               /* SIOCGIWRANGE */
14639         rtw_wx_set_priv,                /* SIOCSIWPRIV */
14640         NULL,                                   /* SIOCGIWPRIV */
14641         NULL,                                   /* SIOCSIWSTATS */
14642         NULL,                                   /* SIOCGIWSTATS */
14643         dummy,                                  /* SIOCSIWSPY */
14644         dummy,                                  /* SIOCGIWSPY */
14645         NULL,                                   /* SIOCGIWTHRSPY */
14646         NULL,                                   /* SIOCWIWTHRSPY */
14647         rtw_wx_set_wap,         /* SIOCSIWAP */
14648         rtw_wx_get_wap,         /* SIOCGIWAP */
14649         rtw_wx_set_mlme,                /* request MLME operation; uses struct iw_mlme */
14650         dummy,                                  /* SIOCGIWAPLIST -- depricated */
14651         rtw_wx_set_scan,                /* SIOCSIWSCAN */
14652         rtw_wx_get_scan,                /* SIOCGIWSCAN */
14653         rtw_wx_set_essid,               /* SIOCSIWESSID */
14654         rtw_wx_get_essid,               /* SIOCGIWESSID */
14655         dummy,                                  /* SIOCSIWNICKN */
14656         rtw_wx_get_nick,                /* SIOCGIWNICKN */
14657         NULL,                                   /* -- hole -- */
14658         NULL,                                   /* -- hole -- */
14659         rtw_wx_set_rate,                /* SIOCSIWRATE */
14660         rtw_wx_get_rate,                /* SIOCGIWRATE */
14661         rtw_wx_set_rts,                 /* SIOCSIWRTS */
14662         rtw_wx_get_rts,                 /* SIOCGIWRTS */
14663         rtw_wx_set_frag,                /* SIOCSIWFRAG */
14664         rtw_wx_get_frag,                /* SIOCGIWFRAG */
14665         dummy,                                  /* SIOCSIWTXPOW */
14666         dummy,                                  /* SIOCGIWTXPOW */
14667         dummy,                                  /* SIOCSIWRETRY */
14668         rtw_wx_get_retry,               /* SIOCGIWRETRY */
14669         rtw_wx_set_enc,                 /* SIOCSIWENCODE */
14670         rtw_wx_get_enc,                 /* SIOCGIWENCODE */
14671         dummy,                                  /* SIOCSIWPOWER */
14672         rtw_wx_get_power,               /* SIOCGIWPOWER */
14673         NULL,                                   /*---hole---*/
14674         NULL,                                   /*---hole---*/
14675         rtw_wx_set_gen_ie,              /* SIOCSIWGENIE */
14676         NULL,                                   /* SIOCGWGENIE */
14677         rtw_wx_set_auth,                /* SIOCSIWAUTH */
14678         NULL,                                   /* SIOCGIWAUTH */
14679         rtw_wx_set_enc_ext,             /* SIOCSIWENCODEEXT */
14680         NULL,                                   /* SIOCGIWENCODEEXT */
14681         rtw_wx_set_pmkid,               /* SIOCSIWPMKSA */
14682         NULL,                                   /*---hole---*/
14683 }; 
14684
14685
14686 static const struct iw_priv_args rtw_private_args[] = {
14687         {
14688                 SIOCIWFIRSTPRIV + 0x0,
14689                 IW_PRIV_TYPE_CHAR | 0x7FF, 0, "write"
14690         },
14691         {
14692                 SIOCIWFIRSTPRIV + 0x1,
14693                 IW_PRIV_TYPE_CHAR | 0x7FF,
14694                 IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_FIXED | IFNAMSIZ, "read"
14695         },
14696         {
14697                 SIOCIWFIRSTPRIV + 0x2, 0, 0, "driver_ext"
14698         },
14699         {
14700                 SIOCIWFIRSTPRIV + 0x3, 0, 0, "mp_ioctl"
14701         },
14702         {
14703                 SIOCIWFIRSTPRIV + 0x4,
14704                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "apinfo"
14705         },
14706         {
14707                 SIOCIWFIRSTPRIV + 0x5,
14708                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, 0, "setpid"
14709         },
14710         {
14711                 SIOCIWFIRSTPRIV + 0x6,
14712                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_start"
14713         },
14714 //for PLATFORM_MT53XX   
14715         {
14716                 SIOCIWFIRSTPRIV + 0x7,
14717                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "get_sensitivity"
14718         },
14719         {
14720                 SIOCIWFIRSTPRIV + 0x8,
14721                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_prob_req_ie"
14722         },
14723         {
14724                 SIOCIWFIRSTPRIV + 0x9,
14725                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_assoc_req_ie"
14726         },
14727
14728 //for RTK_DMP_PLATFORM  
14729         {
14730                 SIOCIWFIRSTPRIV + 0xA,
14731                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "channel_plan"
14732         },
14733
14734         {
14735                 SIOCIWFIRSTPRIV + 0xB,
14736                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, 0, "dbg"
14737         },      
14738         {
14739                 SIOCIWFIRSTPRIV + 0xC,
14740                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 3, 0, "rfw"
14741         },
14742         {
14743                 SIOCIWFIRSTPRIV + 0xD,
14744                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_FIXED | IFNAMSIZ, "rfr"
14745         },
14746 #if 0
14747         {
14748                 SIOCIWFIRSTPRIV + 0xE,0,0, "wowlan_ctrl"
14749         },
14750 #endif
14751         {
14752                 SIOCIWFIRSTPRIV + 0x10,
14753                 IW_PRIV_TYPE_CHAR | 1024, 0, "p2p_set"
14754         },
14755         {
14756                 SIOCIWFIRSTPRIV + 0x11,
14757                 IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , "p2p_get"
14758         },
14759         {
14760                 SIOCIWFIRSTPRIV + 0x12, 0, 0, "NULL"
14761         },
14762         {
14763                 SIOCIWFIRSTPRIV + 0x13,
14764                 IW_PRIV_TYPE_CHAR | 64, IW_PRIV_TYPE_CHAR | 64 , "p2p_get2"
14765         },      
14766         {
14767                 SIOCIWFIRSTPRIV + 0x14,
14768                 IW_PRIV_TYPE_CHAR  | 64, 0, "tdls"
14769         },
14770         {
14771                 SIOCIWFIRSTPRIV + 0x15,
14772                 IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | 1024 , "tdls_get"
14773         },      
14774         {
14775                 SIOCIWFIRSTPRIV + 0x16,
14776                 IW_PRIV_TYPE_CHAR | 64, 0, "pm_set"
14777         },
14778
14779         {SIOCIWFIRSTPRIV + 0x18, IW_PRIV_TYPE_CHAR | IFNAMSIZ , 0 , "rereg_nd_name"},
14780 #ifdef CONFIG_MP_INCLUDED
14781         {SIOCIWFIRSTPRIV + 0x1A, IW_PRIV_TYPE_CHAR | 1024, 0,  "NULL"},
14782         {SIOCIWFIRSTPRIV + 0x1B, IW_PRIV_TYPE_CHAR | 128, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "NULL"},
14783 #else
14784         {SIOCIWFIRSTPRIV + 0x1A, IW_PRIV_TYPE_CHAR | 1024, 0, "efuse_set"},
14785         {SIOCIWFIRSTPRIV + 0x1B, IW_PRIV_TYPE_CHAR | 128, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_get"},
14786 #endif
14787         {
14788                 SIOCIWFIRSTPRIV + 0x1D,
14789                 IW_PRIV_TYPE_CHAR | 40, IW_PRIV_TYPE_CHAR | 0x7FF, "test"
14790         },
14791
14792 #ifdef CONFIG_INTEL_WIDI
14793         {
14794                 SIOCIWFIRSTPRIV + 0x1E,
14795                 IW_PRIV_TYPE_CHAR | 1024, 0, "widi_set"
14796         },
14797         {
14798                 SIOCIWFIRSTPRIV + 0x1F,
14799                 IW_PRIV_TYPE_CHAR | 128, 0, "widi_prob_req"
14800         },
14801 #endif // CONFIG_INTEL_WIDI
14802
14803 #ifdef CONFIG_MP_INCLUDED
14804         { SIOCIWFIRSTPRIV + 0x0E, IW_PRIV_TYPE_CHAR | 1024, 0 , ""},  //set 
14805         { SIOCIWFIRSTPRIV + 0x0F, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , ""},//get
14806 /* --- sub-ioctls definitions --- */   
14807                 { MP_START , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_start" }, //set
14808                 { MP_PHYPARA, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_phypara" },//get
14809                 { MP_STOP , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_stop" }, //set
14810                 { MP_CHANNEL , IW_PRIV_TYPE_CHAR | 1024 , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_channel" },//get
14811                 { MP_BANDWIDTH , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_bandwidth"}, //set
14812                 { MP_RATE , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rate" },//get
14813                 { MP_RESET_STATS , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_reset_stats"},
14814                 { MP_QUERY , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , "mp_query"}, //get
14815                 { READ_REG , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "read_reg" },
14816                 { MP_RATE , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rate" },
14817                 { READ_RF , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "read_rf" },
14818                 { MP_PSD , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_psd"}, 
14819                 { MP_DUMP, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_dump" },
14820                 { MP_TXPOWER , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_txpower"},
14821                 { MP_ANT_TX , IW_PRIV_TYPE_CHAR | 1024,  IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ant_tx"},
14822                 { MP_ANT_RX , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ant_rx"},
14823                 { WRITE_REG , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "write_reg" },
14824                 { WRITE_RF , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "write_rf" },
14825                 { MP_CTX , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ctx"},
14826                 { MP_ARX , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_arx"},
14827                 { MP_THER , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ther"},
14828                 { EFUSE_SET, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_set" },
14829                 { EFUSE_GET, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_get" },
14830                 { MP_PWRTRK , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_pwrtrk"},
14831                 { MP_QueryDrvStats, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_drvquery" },
14832                 { MP_IOCTL, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_ioctl"}, // mp_ioctl       
14833                 { MP_SetRFPathSwh, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_setrfpath" },               
14834                 { MP_PwrCtlDM, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_pwrctldm" },                
14835                 { MP_GET_TXPOWER_INX, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_get_txpower" },
14836                 { MP_GETVER, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_priv_ver" },
14837                 
14838 #if defined(CONFIG_RTL8723A) || defined(CONFIG_RTL8723B)
14839                 { MP_SetBT, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_setbt" },
14840         { MP_DISABLE_BT_COEXIST, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_disa_btcoex"},
14841 #endif
14842                 { CTA_TEST, IW_PRIV_TYPE_CHAR | 1024, 0, "cta_test"},
14843 #endif
14844 #ifdef CONFIG_WOWLAN
14845                 { MP_WOW_ENABLE , IW_PRIV_TYPE_CHAR | 1024, 0, "wow_mode" }, //set 
14846 #endif
14847 #ifdef CONFIG_AP_WOWLAN
14848                 { MP_AP_WOW_ENABLE , IW_PRIV_TYPE_CHAR | 1024, 0, "ap_wow_mode" }, //set 
14849 #endif
14850 };
14851
14852 static iw_handler rtw_private_handler[] = 
14853 {
14854         rtw_wx_write32,                                 //0x00
14855         rtw_wx_read32,                                  //0x01
14856         rtw_drvext_hdl,                                 //0x02
14857         rtw_mp_ioctl_hdl,                               //0x03
14858
14859 // for MM DTV platform
14860         rtw_get_ap_info,                                        //0x04
14861
14862         rtw_set_pid,                                            //0x05
14863         rtw_wps_start,                                  //0x06
14864
14865 // for PLATFORM_MT53XX
14866         rtw_wx_get_sensitivity,                 //0x07
14867         rtw_wx_set_mtk_wps_probe_ie,    //0x08
14868         rtw_wx_set_mtk_wps_ie,                  //0x09
14869
14870 // for RTK_DMP_PLATFORM
14871 // Set Channel depend on the country code
14872         rtw_wx_set_channel_plan,                //0x0A
14873
14874         rtw_dbg_port,                                   //0x0B
14875         rtw_wx_write_rf,                                        //0x0C
14876         rtw_wx_read_rf,                                 //0x0D
14877 #ifdef CONFIG_MP_INCLUDED
14878         rtw_mp_set,                                     //0x0E
14879         rtw_mp_get,                                     //0x0F
14880 #else
14881         rtw_wx_priv_null,                               //0x0E
14882         rtw_wx_priv_null,                               //0x0F
14883 #endif
14884         rtw_p2p_set,                                    //0x10
14885         rtw_p2p_get,                                    //0x11
14886         NULL,                                                   //0x12
14887         rtw_p2p_get2,                                   //0x13
14888
14889         rtw_tdls,                                               //0x14
14890         rtw_tdls_get,                                   //0x15
14891
14892         rtw_pm_set,                                             //0x16
14893         rtw_wx_priv_null,                               //0x17
14894         rtw_rereg_nd_name,                              //0x18
14895         rtw_wx_priv_null,                               //0x19
14896 #ifdef CONFIG_MP_INCLUDED
14897         rtw_wx_priv_null,                               //0x1A
14898         rtw_wx_priv_null,                               //0x1B
14899 #else
14900         rtw_mp_efuse_set,                               //0x1A
14901         rtw_mp_efuse_get,                               //0x1B
14902 #endif
14903         NULL,                                                   // 0x1C is reserved for hostapd
14904         rtw_test,                                               // 0x1D
14905 #ifdef CONFIG_INTEL_WIDI
14906         rtw_widi_set,                                   //0x1E
14907         rtw_widi_set_probe_request,             //0x1F
14908 #endif // CONFIG_INTEL_WIDI
14909 };
14910
14911
14912 #if WIRELESS_EXT >= 17  
14913 static struct iw_statistics *rtw_get_wireless_stats(struct net_device *dev)
14914 {
14915        _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
14916            struct iw_statistics *piwstats=&padapter->iwstats;
14917         int tmp_level = 0;
14918         int tmp_qual = 0;
14919         int tmp_noise = 0;
14920
14921         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) != _TRUE)
14922         {
14923                 piwstats->qual.qual = 0;
14924                 piwstats->qual.level = 0;
14925                 piwstats->qual.noise = 0;
14926                 //DBG_871X("No link  level:%d, qual:%d, noise:%d\n", tmp_level, tmp_qual, tmp_noise);
14927         }
14928         else{
14929                 #ifdef CONFIG_SIGNAL_DISPLAY_DBM
14930                 tmp_level = translate_percentage_to_dbm(padapter->recvpriv.signal_strength); 
14931                 #else
14932                 #ifdef CONFIG_SKIP_SIGNAL_SCALE_MAPPING
14933                 {
14934                         /* Do signal scale mapping when using percentage as the unit of signal strength, since the scale mapping is skipped in odm */
14935                         
14936                         HAL_DATA_TYPE *pHal = GET_HAL_DATA(padapter);
14937                         
14938                         tmp_level = (u8)odm_SignalScaleMapping(&pHal->odmpriv, padapter->recvpriv.signal_strength);
14939                 }
14940                 #else
14941                 tmp_level = padapter->recvpriv.signal_strength;
14942                 #endif
14943                 #endif
14944                 
14945                 tmp_qual = padapter->recvpriv.signal_qual;
14946 #if defined(CONFIG_SIGNAL_DISPLAY_DBM) && defined(CONFIG_BACKGROUND_NOISE_MONITOR)
14947                 if(rtw_linked_check(padapter)){                 
14948                         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
14949                         struct noise_info info;
14950                         info.bPauseDIG = _TRUE;
14951                         info.IGIValue = 0x1e;
14952                         info.max_time = 100;//ms                
14953                         info.chan = pmlmeext->cur_channel ;//rtw_get_oper_ch(padapter);
14954                         rtw_ps_deny(padapter, PS_DENY_IOCTL);   
14955                         LeaveAllPowerSaveModeDirect(padapter);  
14956
14957                         rtw_hal_set_odm_var(padapter, HAL_ODM_NOISE_MONITOR,&info, _FALSE);     
14958                         //ODM_InbandNoise_Monitor(podmpriv,_TRUE,0x20,100);
14959                         rtw_ps_deny_cancel(padapter, PS_DENY_IOCTL);
14960                         rtw_hal_get_odm_var(padapter, HAL_ODM_NOISE_MONITOR,&(info.chan), &(padapter->recvpriv.noise)); 
14961                         #ifdef DBG_NOISE_MONITOR
14962                         DBG_871X("chan:%d,noise_level:%d\n",info.chan,padapter->recvpriv.noise);
14963                         #endif
14964                 }
14965 #endif          
14966                 tmp_noise = padapter->recvpriv.noise;
14967                 //DBG_871X("level:%d, qual:%d, noise:%d, rssi (%d)\n", tmp_level, tmp_qual, tmp_noise,padapter->recvpriv.rssi);
14968
14969                 piwstats->qual.level = tmp_level;
14970                 piwstats->qual.qual = tmp_qual;
14971                 piwstats->qual.noise = tmp_noise;
14972         }
14973 #if (LINUX_VERSION_CODE >= KERNEL_VERSION(2,6,14))
14974         piwstats->qual.updated = IW_QUAL_ALL_UPDATED ;//|IW_QUAL_DBM;
14975 #else
14976 #ifdef RTK_DMP_PLATFORM
14977         //IW_QUAL_DBM= 0x8, if driver use this flag, wireless extension will show value of dbm.
14978         //remove this flag for show percentage 0~100
14979         piwstats->qual.updated = 0x07;
14980 #else
14981         piwstats->qual.updated = 0x0f;
14982 #endif
14983 #endif
14984
14985         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
14986         piwstats->qual.updated = piwstats->qual.updated | IW_QUAL_DBM;
14987         #endif
14988
14989         return &padapter->iwstats;
14990 }
14991 #endif
14992
14993 #ifdef CONFIG_WIRELESS_EXT
14994 struct iw_handler_def rtw_handlers_def =
14995 {
14996         .standard = rtw_handlers,
14997         .num_standard = sizeof(rtw_handlers) / sizeof(iw_handler),
14998 #if (LINUX_VERSION_CODE < KERNEL_VERSION(2,6,33)) || defined(CONFIG_WEXT_PRIV)
14999         .private = rtw_private_handler,
15000         .private_args = (struct iw_priv_args *)rtw_private_args,
15001         .num_private = sizeof(rtw_private_handler) / sizeof(iw_handler),
15002         .num_private_args = sizeof(rtw_private_args) / sizeof(struct iw_priv_args),
15003 #endif
15004 #if WIRELESS_EXT >= 17
15005         .get_wireless_stats = rtw_get_wireless_stats,
15006 #endif
15007 };
15008 #endif
15009
15010 // copy from net/wireless/wext.c start
15011 /* ---------------------------------------------------------------- */
15012 /*
15013  * Calculate size of private arguments
15014  */
15015 static const char iw_priv_type_size[] = {
15016         0,                              /* IW_PRIV_TYPE_NONE */
15017         1,                              /* IW_PRIV_TYPE_BYTE */
15018         1,                              /* IW_PRIV_TYPE_CHAR */
15019         0,                              /* Not defined */
15020         sizeof(__u32),                  /* IW_PRIV_TYPE_INT */
15021         sizeof(struct iw_freq),         /* IW_PRIV_TYPE_FLOAT */
15022         sizeof(struct sockaddr),        /* IW_PRIV_TYPE_ADDR */
15023         0,                              /* Not defined */
15024 };
15025
15026 static int get_priv_size(__u16 args)
15027 {
15028         int num = args & IW_PRIV_SIZE_MASK;
15029         int type = (args & IW_PRIV_TYPE_MASK) >> 12;
15030
15031         return num * iw_priv_type_size[type];
15032 }
15033 // copy from net/wireless/wext.c end
15034
15035
15036 static int _rtw_ioctl_wext_private(struct net_device *dev, union iwreq_data *wrq_data)
15037 {
15038         int err = 0;
15039         u8 *input = NULL;
15040         u32 input_len = 0;
15041         const char delim[] = " ";
15042         u8 *output = NULL;
15043         u32 output_len = 0;
15044         u32 count = 0;
15045         u8 *buffer= NULL;
15046         u32 buffer_len = 0;
15047         char *ptr = NULL;
15048         u8 cmdname[17] = {0}; // IFNAMSIZ+1
15049         u32 cmdlen;
15050         s32 len;
15051         u8 *extra = NULL;
15052         u32 extra_size = 0;
15053
15054         s32 k;
15055         const iw_handler *priv;         /* Private ioctl */
15056         const struct iw_priv_args *priv_args;   /* Private ioctl description */
15057         u32 num_priv;                           /* Number of ioctl */
15058         u32 num_priv_args;                      /* Number of descriptions */
15059         iw_handler handler;
15060         int temp;
15061         int subcmd = 0;                         /* sub-ioctl index */
15062         int offset = 0;                         /* Space for sub-ioctl index */
15063
15064         union iwreq_data wdata;
15065
15066         _rtw_memcpy(&wdata, wrq_data, sizeof(wdata));
15067
15068         input_len = wdata.data.length;
15069         input = rtw_zmalloc(input_len);
15070         if (NULL == input)
15071                 return -ENOMEM;
15072         if (copy_from_user(input, wdata.data.pointer, input_len)) {
15073                 err = -EFAULT;
15074                 goto exit;
15075         }
15076         ptr = input;
15077         len = input_len;
15078         sscanf(ptr, "%16s", cmdname);
15079         cmdlen = strlen(cmdname);
15080         DBG_871X("%s: cmd=%s\n", __func__, cmdname);
15081
15082         // skip command string
15083         if (cmdlen > 0)
15084                 cmdlen += 1; // skip one space
15085         ptr += cmdlen;
15086         len -= cmdlen;
15087         DBG_871X("%s: parameters=%s\n", __func__, ptr);
15088
15089         priv = rtw_private_handler;
15090         priv_args = rtw_private_args;
15091         num_priv = sizeof(rtw_private_handler) / sizeof(iw_handler);
15092         num_priv_args = sizeof(rtw_private_args) / sizeof(struct iw_priv_args);
15093
15094         if (num_priv_args == 0) {
15095                 err = -EOPNOTSUPP;
15096                 goto exit;
15097         }
15098
15099         /* Search the correct ioctl */
15100         k = -1;
15101         while((++k < num_priv_args) && strcmp(priv_args[k].name, cmdname));
15102
15103         /* If not found... */
15104         if (k == num_priv_args) {
15105                 err = -EOPNOTSUPP;
15106                 goto exit;
15107         }
15108
15109         /* Watch out for sub-ioctls ! */
15110         if (priv_args[k].cmd < SIOCDEVPRIVATE)
15111         {
15112                 int j = -1;
15113
15114                 /* Find the matching *real* ioctl */
15115                 while ((++j < num_priv_args) && ((priv_args[j].name[0] != '\0') ||
15116                         (priv_args[j].set_args != priv_args[k].set_args) ||
15117                         (priv_args[j].get_args != priv_args[k].get_args)));
15118
15119                 /* If not found... */
15120                 if (j == num_priv_args) {
15121                         err = -EINVAL;
15122                         goto exit;
15123                 }
15124
15125                 /* Save sub-ioctl number */
15126                 subcmd = priv_args[k].cmd;
15127                 /* Reserve one int (simplify alignment issues) */
15128                 offset = sizeof(__u32);
15129                 /* Use real ioctl definition from now on */
15130                 k = j;
15131         }
15132
15133         buffer = rtw_zmalloc(4096);
15134         if (NULL == buffer) {
15135                 err = -ENOMEM;
15136                 goto exit;
15137         }
15138
15139         /* If we have to set some data */
15140         if ((priv_args[k].set_args & IW_PRIV_TYPE_MASK) &&
15141                 (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
15142         {
15143                 u8 *str;
15144
15145                 switch (priv_args[k].set_args & IW_PRIV_TYPE_MASK)
15146                 {
15147                         case IW_PRIV_TYPE_BYTE:
15148                                 /* Fetch args */
15149                                 count = 0;
15150                                 do {
15151                                         str = strsep(&ptr, delim);
15152                                         if (NULL == str) break;
15153                                         sscanf(str, "%i", &temp);
15154                                         buffer[count++] = (u8)temp;
15155                                 } while (1);
15156                                 buffer_len = count;
15157
15158                                 /* Number of args to fetch */
15159                                 wdata.data.length = count;
15160                                 if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
15161                                         wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
15162
15163                                 break;
15164
15165                         case IW_PRIV_TYPE_INT:
15166                                 /* Fetch args */
15167                                 count = 0;
15168                                 do {
15169                                         str = strsep(&ptr, delim);
15170                                         if (NULL == str) break;
15171                                         sscanf(str, "%i", &temp);
15172                                         ((s32*)buffer)[count++] = (s32)temp;
15173                                 } while (1);
15174                                 buffer_len = count * sizeof(s32);
15175
15176                                 /* Number of args to fetch */
15177                                 wdata.data.length = count;
15178                                 if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
15179                                         wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
15180
15181                                 break;
15182
15183                         case IW_PRIV_TYPE_CHAR:
15184                                 if (len > 0)
15185                                 {
15186                                         /* Size of the string to fetch */
15187                                         wdata.data.length = len;
15188                                         if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
15189                                                 wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
15190
15191                                         /* Fetch string */
15192                                         _rtw_memcpy(buffer, ptr, wdata.data.length);
15193                                 }
15194                                 else
15195                                 {
15196                                         wdata.data.length = 1;
15197                                         buffer[0] = '\0';
15198                                 }
15199                                 buffer_len = wdata.data.length;
15200                                 break;
15201
15202                         default:
15203                                 DBG_8192C("%s: Not yet implemented...\n", __func__);
15204                                 err = -1;
15205                                 goto exit;
15206                 }
15207
15208                 if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
15209                         (wdata.data.length != (priv_args[k].set_args & IW_PRIV_SIZE_MASK)))
15210                 {
15211                         DBG_8192C("%s: The command %s needs exactly %d argument(s)...\n",
15212                                         __func__, cmdname, priv_args[k].set_args & IW_PRIV_SIZE_MASK);
15213                         err = -EINVAL;
15214                         goto exit;
15215                 }
15216         }   /* if args to set */
15217         else
15218         {
15219                 wdata.data.length = 0L;
15220         }
15221
15222         /* Those two tests are important. They define how the driver
15223         * will have to handle the data */
15224         if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
15225                 ((get_priv_size(priv_args[k].set_args) + offset) <= IFNAMSIZ))
15226         {
15227                 /* First case : all SET args fit within wrq */
15228                 if (offset)
15229                         wdata.mode = subcmd;
15230                 _rtw_memcpy(wdata.name + offset, buffer, IFNAMSIZ - offset);
15231         }
15232         else
15233         {
15234                 if ((priv_args[k].set_args == 0) &&
15235                         (priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
15236                         (get_priv_size(priv_args[k].get_args) <= IFNAMSIZ))
15237                 {
15238                         /* Second case : no SET args, GET args fit within wrq */
15239                         if (offset)
15240                                 wdata.mode = subcmd;
15241                 }
15242                 else
15243                 {
15244                         /* Third case : args won't fit in wrq, or variable number of args */
15245                         if (copy_to_user(wdata.data.pointer, buffer, buffer_len)) {
15246                                 err = -EFAULT;
15247                                 goto exit;
15248                         }
15249                         wdata.data.flags = subcmd;
15250                 }
15251         }
15252
15253         rtw_mfree(input, input_len);
15254         input = NULL;
15255
15256         extra_size = 0;
15257         if (IW_IS_SET(priv_args[k].cmd))
15258         {
15259                 /* Size of set arguments */
15260                 extra_size = get_priv_size(priv_args[k].set_args);
15261
15262                 /* Does it fits in iwr ? */
15263                 if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
15264                         ((extra_size + offset) <= IFNAMSIZ))
15265                         extra_size = 0;
15266         } else {
15267                 /* Size of get arguments */
15268                 extra_size = get_priv_size(priv_args[k].get_args);
15269
15270                 /* Does it fits in iwr ? */
15271                 if ((priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
15272                         (extra_size <= IFNAMSIZ))
15273                         extra_size = 0;
15274         }
15275
15276         if (extra_size == 0) {
15277                 extra = (u8*)&wdata;
15278                 rtw_mfree(buffer, 4096);
15279                 buffer = NULL;
15280         } else
15281                 extra = buffer;
15282
15283         handler = priv[priv_args[k].cmd - SIOCIWFIRSTPRIV];
15284         err = handler(dev, NULL, &wdata, extra);
15285
15286         /* If we have to get some data */
15287         if ((priv_args[k].get_args & IW_PRIV_TYPE_MASK) &&
15288                 (priv_args[k].get_args & IW_PRIV_SIZE_MASK))
15289         {
15290                 int j;
15291                 int n = 0;      /* number of args */
15292                 u8 str[20] = {0};
15293
15294                 /* Check where is the returned data */
15295                 if ((priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
15296                         (get_priv_size(priv_args[k].get_args) <= IFNAMSIZ))
15297                         n = priv_args[k].get_args & IW_PRIV_SIZE_MASK;
15298                 else
15299                         n = wdata.data.length;
15300
15301                 output = rtw_zmalloc(4096);
15302                 if (NULL == output) {
15303                         err =  -ENOMEM;
15304                         goto exit;
15305                 }
15306
15307                 switch (priv_args[k].get_args & IW_PRIV_TYPE_MASK)
15308                 {
15309                         case IW_PRIV_TYPE_BYTE:
15310                                 /* Display args */
15311                                 for (j = 0; j < n; j++)
15312                                 {
15313                                         sprintf(str, "%d  ", extra[j]);
15314                                         len = strlen(str);
15315                                         output_len = strlen(output);
15316                                         if ((output_len + len + 1) > 4096) {
15317                                                 err = -E2BIG;
15318                                                 goto exit;
15319                                         }
15320                                         _rtw_memcpy(output+output_len, str, len);
15321                                 }
15322                                 break;
15323
15324                         case IW_PRIV_TYPE_INT:
15325                                 /* Display args */
15326                                 for (j = 0; j < n; j++)
15327                                 {
15328                                         sprintf(str, "%d  ", ((__s32*)extra)[j]);
15329                                         len = strlen(str);
15330                                         output_len = strlen(output);
15331                                         if ((output_len + len + 1) > 4096) {
15332                                                 err = -E2BIG;
15333                                                 goto exit;
15334                                         }
15335                                         _rtw_memcpy(output+output_len, str, len);
15336                                 }
15337                                 break;
15338
15339                         case IW_PRIV_TYPE_CHAR:
15340                                 /* Display args */
15341                                 _rtw_memcpy(output, extra, n);
15342                                 break;
15343
15344                         default:
15345                                 DBG_8192C("%s: Not yet implemented...\n", __func__);
15346                                 err = -1;
15347                                 goto exit;
15348                 }
15349
15350                 output_len = strlen(output) + 1;
15351                 wrq_data->data.length = output_len;
15352                 if (copy_to_user(wrq_data->data.pointer, output, output_len)) {
15353                         err = -EFAULT;
15354                         goto exit;
15355                 }
15356         }   /* if args to set */
15357         else
15358         {
15359                 wrq_data->data.length = 0;
15360         }
15361
15362 exit:
15363         if (input)
15364                 rtw_mfree(input, input_len);
15365         if (buffer)
15366                 rtw_mfree(buffer, 4096);
15367         if (output)
15368                 rtw_mfree(output, 4096);
15369
15370         return err;
15371 }
15372
15373 #ifdef CONFIG_COMPAT
15374 static int rtw_ioctl_compat_wext_private(struct net_device *dev, struct ifreq *rq)
15375 {
15376         struct compat_iw_point iwp_compat;
15377         union iwreq_data wrq_data;
15378         int err = 0;
15379         DBG_871X("%s:...\n", __func__);
15380         if (copy_from_user(&iwp_compat, rq->ifr_ifru.ifru_data, sizeof(struct compat_iw_point)))
15381                         return -EFAULT;
15382         
15383         wrq_data.data.pointer = compat_ptr(iwp_compat.pointer);
15384         wrq_data.data.length = iwp_compat.length;
15385         wrq_data.data.flags = iwp_compat.flags;
15386
15387         err = _rtw_ioctl_wext_private(dev, &wrq_data);
15388
15389         iwp_compat.pointer = ptr_to_compat(wrq_data.data.pointer);
15390         iwp_compat.length = wrq_data.data.length;
15391         iwp_compat.flags = wrq_data.data.flags;
15392         if (copy_to_user(rq->ifr_ifru.ifru_data, &iwp_compat, sizeof(struct compat_iw_point)))
15393                         return -EFAULT;
15394
15395         return err;
15396 }
15397 #endif // CONFIG_COMPAT
15398
15399 static int rtw_ioctl_standard_wext_private(struct net_device *dev, struct ifreq *rq)
15400 {
15401         struct iw_point *iwp;
15402         struct ifreq ifrq;
15403         union iwreq_data wrq_data;
15404         int err = 0;
15405         iwp = &wrq_data.data;
15406         DBG_871X("%s:...\n", __func__);
15407         if (copy_from_user(iwp, rq->ifr_ifru.ifru_data, sizeof(struct iw_point)))
15408                 return -EFAULT;
15409
15410         err = _rtw_ioctl_wext_private(dev, &wrq_data);
15411
15412         if (copy_to_user(rq->ifr_ifru.ifru_data, iwp, sizeof(struct iw_point)))
15413                 return -EFAULT;
15414
15415         return err;
15416 }
15417  
15418 static int rtw_ioctl_wext_private(struct net_device *dev, struct ifreq *rq)
15419 {
15420 #ifdef CONFIG_COMPAT
15421         if(is_compat_task())
15422                 return rtw_ioctl_compat_wext_private( dev, rq );
15423         else
15424 #endif // CONFIG_COMPAT
15425                 return rtw_ioctl_standard_wext_private( dev, rq );
15426 }
15427
15428 int rtw_ioctl(struct net_device *dev, struct ifreq *rq, int cmd)
15429 {
15430         struct iwreq *wrq = (struct iwreq *)rq;
15431         int ret=0;
15432
15433         switch (cmd)
15434         {
15435                 case RTL_IOCTL_WPA_SUPPLICANT:
15436                         ret = wpa_supplicant_ioctl(dev, &wrq->u.data);
15437                         break;
15438 #ifdef CONFIG_AP_MODE
15439                 case RTL_IOCTL_HOSTAPD:
15440                         ret = rtw_hostapd_ioctl(dev, &wrq->u.data);
15441                         break;
15442 #ifdef CONFIG_NO_WIRELESS_HANDLERS
15443                 case SIOCSIWMODE:
15444                         ret = rtw_wx_set_mode(dev, NULL, &wrq->u, NULL);
15445                         break;
15446 #endif
15447 #endif // CONFIG_AP_MODE
15448                 case SIOCDEVPRIVATE:                            
15449                          ret = rtw_ioctl_wext_private(dev, rq);
15450                         break;
15451                 case (SIOCDEVPRIVATE+1):
15452                         ret = rtw_android_priv_cmd(dev, rq, cmd);
15453                         break;
15454                 default:
15455                         ret = -EOPNOTSUPP;
15456                         break;
15457         }
15458
15459         return ret;
15460 }
15461
15462