Merge tag 'lsk-v3.10-android-15.02'
[firefly-linux-kernel-4.4.55.git] / drivers / net / wireless / rockchip_wlan / rtl8723bu / core / rtw_mlme.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
4  *                                        
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  * You should have received a copy of the GNU General Public License along with
15  * this program; if not, write to the Free Software Foundation, Inc.,
16  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
17  *
18  *
19  ******************************************************************************/
20 #define _RTW_MLME_C_
21
22 #include <drv_types.h>
23
24
25 extern void indicate_wx_scan_complete_event(_adapter *padapter);
26 extern u8 rtw_do_join(_adapter * padapter);
27
28
29 sint    _rtw_init_mlme_priv (_adapter* padapter)
30 {
31         sint    i;
32         u8      *pbuf;
33         struct wlan_network     *pnetwork;
34         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
35         sint    res = _SUCCESS;
36
37 _func_enter_;
38
39         // We don't need to memset padapter->XXX to zero, because adapter is allocated by rtw_zvmalloc().
40         //_rtw_memset((u8 *)pmlmepriv, 0, sizeof(struct mlme_priv));
41
42         pmlmepriv->nic_hdl = (u8 *)padapter;
43
44         pmlmepriv->pscanned = NULL;
45         pmlmepriv->fw_state = WIFI_STATION_STATE; // Must sync with rtw_wdev_alloc() 
46                                                   // wdev->iftype = NL80211_IFTYPE_STATION
47         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
48         pmlmepriv->scan_mode=SCAN_ACTIVE;// 1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff)
49
50         _rtw_spinlock_init(&(pmlmepriv->lock)); 
51         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
52         _rtw_init_queue(&(pmlmepriv->scanned_queue));
53
54         set_scanned_network_val(pmlmepriv, 0);
55         
56         _rtw_memset(&pmlmepriv->assoc_ssid,0,sizeof(NDIS_802_11_SSID));
57
58         pbuf = rtw_zvmalloc(MAX_BSS_CNT * (sizeof(struct wlan_network)));
59         
60         if (pbuf == NULL){
61                 res=_FAIL;
62                 goto exit;
63         }
64         pmlmepriv->free_bss_buf = pbuf;
65                 
66         pnetwork = (struct wlan_network *)pbuf;
67         
68         for(i = 0; i < MAX_BSS_CNT; i++)
69         {               
70                 _rtw_init_listhead(&(pnetwork->list));
71
72                 rtw_list_insert_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
73
74                 pnetwork++;
75         }
76
77         //allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf
78
79         rtw_clear_scan_deny(padapter);
80
81 #ifdef CONFIG_LAYER2_ROAMING
82         #define RTW_ROAM_SCAN_RESULT_EXP_MS 5*1000
83         #define RTW_ROAM_RSSI_DIFF_TH 10
84         #define RTW_ROAM_SCAN_INTERVAL_MS 10*1000
85
86         pmlmepriv->roam_flags = 0
87                 | RTW_ROAM_ON_EXPIRED
88                 #ifdef CONFIG_LAYER2_ROAMING_RESUME
89                 | RTW_ROAM_ON_RESUME
90                 #endif
91                 #ifdef CONFIG_LAYER2_ROAMING_ACTIVE
92                 | RTW_ROAM_ACTIVE
93                 #endif
94                 ;
95
96         pmlmepriv->roam_scanr_exp_ms = RTW_ROAM_SCAN_RESULT_EXP_MS;
97         pmlmepriv->roam_rssi_diff_th = RTW_ROAM_RSSI_DIFF_TH;
98         pmlmepriv->roam_scan_int_ms = RTW_ROAM_SCAN_INTERVAL_MS;
99 #endif /* CONFIG_LAYER2_ROAMING */
100
101         rtw_init_mlme_timer(padapter);
102
103 exit:
104
105 _func_exit_;
106
107         return res;
108 }       
109
110 void rtw_mfree_mlme_priv_lock (struct mlme_priv *pmlmepriv);
111 void rtw_mfree_mlme_priv_lock (struct mlme_priv *pmlmepriv)
112 {
113         _rtw_spinlock_free(&pmlmepriv->lock);
114         _rtw_spinlock_free(&(pmlmepriv->free_bss_pool.lock));
115         _rtw_spinlock_free(&(pmlmepriv->scanned_queue.lock));
116 }
117
118 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
119 {
120         if(*ppie)
121         {               
122                 rtw_mfree(*ppie, *plen);
123                 *plen = 0;
124                 *ppie=NULL;
125         }       
126 }
127
128 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
129 {
130 #if defined (CONFIG_AP_MODE) && defined (CONFIG_NATIVEAP_MLME)
131         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
132         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
133         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
134         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
135         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
136         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
137         
138         rtw_free_mlme_ie_data(&pmlmepriv->p2p_beacon_ie, &pmlmepriv->p2p_beacon_ie_len);
139         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_req_ie, &pmlmepriv->p2p_probe_req_ie_len);
140         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_resp_ie, &pmlmepriv->p2p_probe_resp_ie_len);
141         rtw_free_mlme_ie_data(&pmlmepriv->p2p_go_probe_resp_ie, &pmlmepriv->p2p_go_probe_resp_ie_len);
142         rtw_free_mlme_ie_data(&pmlmepriv->p2p_assoc_req_ie, &pmlmepriv->p2p_assoc_req_ie_len);
143 #endif
144
145 #if defined(CONFIG_WFD) && defined(CONFIG_IOCTL_CFG80211)       
146         rtw_free_mlme_ie_data(&pmlmepriv->wfd_beacon_ie, &pmlmepriv->wfd_beacon_ie_len);
147         rtw_free_mlme_ie_data(&pmlmepriv->wfd_probe_req_ie, &pmlmepriv->wfd_probe_req_ie_len);
148         rtw_free_mlme_ie_data(&pmlmepriv->wfd_probe_resp_ie, &pmlmepriv->wfd_probe_resp_ie_len);
149         rtw_free_mlme_ie_data(&pmlmepriv->wfd_go_probe_resp_ie, &pmlmepriv->wfd_go_probe_resp_ie_len);
150         rtw_free_mlme_ie_data(&pmlmepriv->wfd_assoc_req_ie, &pmlmepriv->wfd_assoc_req_ie_len);
151 #endif
152
153 }
154
155 void _rtw_free_mlme_priv (struct mlme_priv *pmlmepriv)
156 {
157 _func_enter_;
158
159         rtw_free_mlme_priv_ie_data(pmlmepriv);
160
161         if(pmlmepriv){
162                 rtw_mfree_mlme_priv_lock (pmlmepriv);
163
164                 if (pmlmepriv->free_bss_buf) {
165                         rtw_vmfree(pmlmepriv->free_bss_buf, MAX_BSS_CNT * sizeof(struct wlan_network));
166                 }
167         }
168 _func_exit_;    
169 }
170
171 sint    _rtw_enqueue_network(_queue *queue, struct wlan_network *pnetwork)
172 {
173         _irqL irqL;
174
175 _func_enter_;   
176
177         if (pnetwork == NULL)
178                 goto exit;
179         
180         _enter_critical_bh(&queue->lock, &irqL);
181
182         rtw_list_insert_tail(&pnetwork->list, &queue->queue);
183
184         _exit_critical_bh(&queue->lock, &irqL);
185
186 exit:   
187
188 _func_exit_;            
189
190         return _SUCCESS;
191 }
192
193 /*
194 struct  wlan_network *_rtw_dequeue_network(_queue *queue)
195 {
196         _irqL irqL;
197
198         struct wlan_network *pnetwork;
199
200 _func_enter_;   
201
202         _enter_critical_bh(&queue->lock, &irqL);
203
204         if (_rtw_queue_empty(queue) == _TRUE)
205
206                 pnetwork = NULL;
207         
208         else
209         {
210                 pnetwork = LIST_CONTAINOR(get_next(&queue->queue), struct wlan_network, list);
211                 
212                 rtw_list_delete(&(pnetwork->list));
213         }
214         
215         _exit_critical_bh(&queue->lock, &irqL);
216
217 _func_exit_;            
218
219         return pnetwork;
220 }
221 */
222
223 struct  wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv )//(_queue *free_queue)
224 {
225         _irqL   irqL;
226         struct  wlan_network    *pnetwork;      
227         _queue *free_queue = &pmlmepriv->free_bss_pool;
228         _list* plist = NULL;
229         
230 _func_enter_;   
231
232         _enter_critical_bh(&free_queue->lock, &irqL);
233         
234         if (_rtw_queue_empty(free_queue) == _TRUE) {
235                 pnetwork=NULL;
236                 goto exit;
237         }
238         plist = get_next(&(free_queue->queue));
239         
240         pnetwork = LIST_CONTAINOR(plist , struct wlan_network, list);
241         
242         rtw_list_delete(&pnetwork->list);
243         
244         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("_rtw_alloc_network: ptr=%p\n", plist));
245         pnetwork->network_type = 0;
246         pnetwork->fixed = _FALSE;
247         pnetwork->last_scanned = rtw_get_current_time();
248         pnetwork->aid=0;        
249         pnetwork->join_res=0;
250
251         pmlmepriv->num_of_scanned ++;
252         
253 exit:
254         _exit_critical_bh(&free_queue->lock, &irqL);
255
256 _func_exit_;            
257
258         return pnetwork;        
259 }
260
261 void _rtw_free_network(struct   mlme_priv *pmlmepriv ,struct wlan_network *pnetwork, u8 isfreeall)
262 {
263         u32 delta_time;
264         u32 lifetime = SCANQUEUE_LIFETIME;
265         _irqL irqL;     
266         _queue *free_queue = &(pmlmepriv->free_bss_pool);
267         
268 _func_enter_;           
269
270         if (pnetwork == NULL)
271                 goto exit;
272
273         if (pnetwork->fixed == _TRUE)
274                 goto exit;
275
276         if ( (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)==_TRUE ) || 
277                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)==_TRUE ) )
278                 lifetime = 1;
279
280         if(!isfreeall)
281         {
282                 delta_time = (u32) rtw_get_passing_time_ms(pnetwork->last_scanned);
283                 if(delta_time < lifetime)// unit:msec
284                         goto exit;
285         }
286
287         _enter_critical_bh(&free_queue->lock, &irqL);
288         
289         rtw_list_delete(&(pnetwork->list));
290
291         rtw_list_insert_tail(&(pnetwork->list),&(free_queue->queue));
292                 
293         pmlmepriv->num_of_scanned --;
294         
295
296         //DBG_871X("_rtw_free_network:SSID=%s\n", pnetwork->network.Ssid.Ssid);
297         
298         _exit_critical_bh(&free_queue->lock, &irqL);
299         
300 exit:           
301         
302 _func_exit_;                    
303
304 }
305
306 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
307 {
308
309         _queue *free_queue = &(pmlmepriv->free_bss_pool);
310
311 _func_enter_;           
312
313         if (pnetwork == NULL)
314                 goto exit;
315
316         if (pnetwork->fixed == _TRUE)
317                 goto exit;
318
319         //_enter_critical(&free_queue->lock, &irqL);
320         
321         rtw_list_delete(&(pnetwork->list));
322
323         rtw_list_insert_tail(&(pnetwork->list), get_list_head(free_queue));
324                 
325         pmlmepriv->num_of_scanned --;
326         
327         //_exit_critical(&free_queue->lock, &irqL);
328         
329 exit:           
330
331 _func_exit_;                    
332
333 }
334
335
336 /*
337         return the wlan_network with the matching addr
338
339         Shall be calle under atomic context... to avoid possible racing condition...
340 */
341 struct wlan_network *_rtw_find_network(_queue *scanned_queue, u8 *addr)
342 {
343
344         //_irqL irqL;
345         _list   *phead, *plist;
346         struct  wlan_network *pnetwork = NULL;
347         u8 zero_addr[ETH_ALEN] = {0,0,0,0,0,0};
348         
349 _func_enter_;   
350
351         if(_rtw_memcmp(zero_addr, addr, ETH_ALEN)){
352                 pnetwork=NULL;
353                 goto exit;
354         }
355         
356         //_enter_critical_bh(&scanned_queue->lock, &irqL);
357         
358         phead = get_list_head(scanned_queue);
359         plist = get_next(phead);
360          
361         while (plist != phead)
362        {
363                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network ,list);
364
365                 if (_rtw_memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN) == _TRUE)
366                         break;
367                 
368                 plist = get_next(plist);
369         }
370
371         if(plist == phead)
372                 pnetwork = NULL;
373
374         //_exit_critical_bh(&scanned_queue->lock, &irqL);
375         
376 exit:           
377         
378 _func_exit_;            
379
380         return pnetwork;
381         
382 }
383
384
385 void _rtw_free_network_queue(_adapter *padapter, u8 isfreeall)
386 {
387         _irqL irqL;
388         _list *phead, *plist;
389         struct wlan_network *pnetwork;
390         struct mlme_priv* pmlmepriv = &padapter->mlmepriv;
391         _queue *scanned_queue = &pmlmepriv->scanned_queue;
392
393 _func_enter_;   
394         
395
396         _enter_critical_bh(&scanned_queue->lock, &irqL);
397
398         phead = get_list_head(scanned_queue);
399         plist = get_next(phead);
400
401         while (rtw_end_of_queue_search(phead, plist) == _FALSE)
402         {
403
404                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
405
406                 plist = get_next(plist);
407
408                 _rtw_free_network(pmlmepriv,pnetwork, isfreeall);
409                 
410         }
411
412         _exit_critical_bh(&scanned_queue->lock, &irqL);
413         
414 _func_exit_;            
415
416 }
417
418
419
420
421 sint rtw_if_up(_adapter *padapter)      {
422
423         sint res;
424 _func_enter_;           
425
426         if( padapter->bDriverStopped || padapter->bSurpriseRemoved ||
427                 (check_fwstate(&padapter->mlmepriv, _FW_LINKED)== _FALSE)){             
428                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)", padapter->bDriverStopped, padapter->bSurpriseRemoved));  
429                 res=_FALSE;
430         }
431         else
432                 res=  _TRUE;
433         
434 _func_exit_;
435         return res;
436 }
437
438
439 void rtw_generate_random_ibss(u8* pibss)
440 {
441         u32     curtime = rtw_get_current_time();
442
443 _func_enter_;
444         pibss[0] = 0x02;  //in ad-hoc mode bit1 must set to 1
445         pibss[1] = 0x11;
446         pibss[2] = 0x87;
447         pibss[3] = (u8)(curtime & 0xff) ;//p[0];
448         pibss[4] = (u8)((curtime>>8) & 0xff) ;//p[1];
449         pibss[5] = (u8)((curtime>>16) & 0xff) ;//p[2];
450 _func_exit_;
451         return;
452 }
453
454 u8 *rtw_get_capability_from_ie(u8 *ie)
455 {
456         return (ie + 8 + 2);
457 }
458
459
460 u16 rtw_get_capability(WLAN_BSSID_EX *bss)
461 {
462         u16     val;
463 _func_enter_;   
464
465         _rtw_memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2); 
466
467 _func_exit_;            
468         return le16_to_cpu(val);
469 }
470
471 u8 *rtw_get_timestampe_from_ie(u8 *ie)
472 {
473         return (ie + 0);        
474 }
475
476 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
477 {
478         return (ie + 8);        
479 }
480
481
482 int     rtw_init_mlme_priv (_adapter *padapter)//(struct        mlme_priv *pmlmepriv)
483 {
484         int     res;
485 _func_enter_;   
486         res = _rtw_init_mlme_priv(padapter);// (pmlmepriv);
487 _func_exit_;    
488         return res;
489 }
490
491 void rtw_free_mlme_priv (struct mlme_priv *pmlmepriv)
492 {
493 _func_enter_;
494         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_free_mlme_priv\n"));
495         _rtw_free_mlme_priv (pmlmepriv);
496 _func_exit_;    
497 }
498
499 int     rtw_enqueue_network(_queue *queue, struct wlan_network *pnetwork);
500 int     rtw_enqueue_network(_queue *queue, struct wlan_network *pnetwork)
501 {
502         int     res;
503 _func_enter_;           
504         res = _rtw_enqueue_network(queue, pnetwork);
505 _func_exit_;            
506         return res;
507 }
508
509 /*
510 static struct   wlan_network *rtw_dequeue_network(_queue *queue)
511 {
512         struct wlan_network *pnetwork;
513 _func_enter_;           
514         pnetwork = _rtw_dequeue_network(queue);
515 _func_exit_;            
516         return pnetwork;
517 }
518 */
519
520 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv );
521 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv )//(_queue *free_queue)
522 {
523         struct  wlan_network    *pnetwork;
524 _func_enter_;                   
525         pnetwork = _rtw_alloc_network(pmlmepriv);
526 _func_exit_;                    
527         return pnetwork;
528 }
529
530 void rtw_free_network(struct mlme_priv *pmlmepriv, struct       wlan_network *pnetwork, u8 is_freeall);
531 void rtw_free_network(struct mlme_priv *pmlmepriv, struct       wlan_network *pnetwork, u8 is_freeall)//(struct wlan_network *pnetwork, _queue  *free_queue)
532 {
533 _func_enter_;           
534         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_free_network==> ssid = %s \n\n" , pnetwork->network.Ssid.Ssid));
535         _rtw_free_network(pmlmepriv, pnetwork, is_freeall);
536 _func_exit_;
537 }
538
539 void rtw_free_network_nolock(_adapter * padapter, struct wlan_network *pnetwork );
540 void rtw_free_network_nolock(_adapter * padapter, struct wlan_network *pnetwork )
541 {
542 _func_enter_;           
543         //RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_free_network==> ssid = %s \n\n" , pnetwork->network.Ssid.Ssid));
544         _rtw_free_network_nolock(&(padapter->mlmepriv), pnetwork);
545 #ifdef CONFIG_IOCTL_CFG80211
546         rtw_cfg80211_unlink_bss(padapter, pnetwork);
547 #endif //CONFIG_IOCTL_CFG80211
548 _func_exit_;            
549 }
550
551
552 void rtw_free_network_queue(_adapter* dev, u8 isfreeall)
553 {
554 _func_enter_;           
555         _rtw_free_network_queue(dev, isfreeall);
556 _func_exit_;                    
557 }
558
559 /*
560         return the wlan_network with the matching addr
561
562         Shall be calle under atomic context... to avoid possible racing condition...
563 */
564 struct  wlan_network *rtw_find_network(_queue *scanned_queue, u8 *addr)
565 {
566         struct  wlan_network *pnetwork = _rtw_find_network(scanned_queue, addr);
567
568         return pnetwork;
569 }
570
571 int rtw_is_same_ibss(_adapter *adapter, struct wlan_network *pnetwork)
572 {
573         int ret=_TRUE;
574         struct security_priv *psecuritypriv = &adapter->securitypriv;
575
576         if ( (psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_ ) &&
577                     ( pnetwork->network.Privacy == 0 ) )
578         {
579                 ret=_FALSE;
580         }
581         else if((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_ ) &&
582                  ( pnetwork->network.Privacy == 1 ) )
583         {
584                 ret=_FALSE;
585         }
586         else
587         {
588                 ret=_TRUE;
589         }
590         
591         return ret;
592         
593 }
594
595 inline int is_same_ess(WLAN_BSSID_EX *a, WLAN_BSSID_EX *b)
596 {
597         //RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("(%s,%d)(%s,%d)\n",
598         //              a->Ssid.Ssid,a->Ssid.SsidLength,b->Ssid.Ssid,b->Ssid.SsidLength));
599         return (a->Ssid.SsidLength == b->Ssid.SsidLength) 
600                 &&  _rtw_memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength)==_TRUE;
601 }
602
603 int is_same_network(WLAN_BSSID_EX *src, WLAN_BSSID_EX *dst, u8 feature)
604 {
605          u16 s_cap, d_cap;
606          
607 _func_enter_;   
608
609         if(rtw_bug_check(dst, src, &s_cap, &d_cap)==_FALSE)
610                         return _FALSE;
611
612         _rtw_memcpy((u8 *)&s_cap, rtw_get_capability_from_ie(src->IEs), 2);
613         _rtw_memcpy((u8 *)&d_cap, rtw_get_capability_from_ie(dst->IEs), 2);
614
615         
616         s_cap = le16_to_cpu(s_cap);
617         d_cap = le16_to_cpu(d_cap);
618         
619 _func_exit_;                    
620
621 #ifdef CONFIG_P2P
622         if ((feature == 1) && // 1: P2P supported
623                 (_rtw_memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN) == _TRUE)
624                 ) {
625                 return _TRUE;
626         }
627 #endif
628
629         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
630                 //      (src->Configuration.DSConfig == dst->Configuration.DSConfig) &&
631                         ( (_rtw_memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN)) == _TRUE) &&
632                         ( (_rtw_memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength)) == _TRUE) &&
633                         ((s_cap & WLAN_CAPABILITY_IBSS) == 
634                         (d_cap & WLAN_CAPABILITY_IBSS)) &&
635                         ((s_cap & WLAN_CAPABILITY_BSS) == 
636                         (d_cap & WLAN_CAPABILITY_BSS)));
637         
638 }
639
640 struct wlan_network *_rtw_find_same_network(_queue *scanned_queue, struct wlan_network *network)
641 {
642         _list *phead, *plist;
643         struct wlan_network *found = NULL;
644
645         phead = get_list_head(scanned_queue);
646         plist = get_next(phead);
647
648         while (plist != phead) {
649                 found = LIST_CONTAINOR(plist, struct wlan_network ,list);
650
651                 if (is_same_network(&network->network, &found->network,0))
652                         break;
653
654                 plist = get_next(plist);
655         }
656
657         if(plist == phead)
658                 found = NULL;
659 exit:           
660         return found;
661 }
662
663 struct wlan_network *rtw_find_same_network(_queue *scanned_queue, struct wlan_network *network)
664 {
665         _irqL irqL;
666         struct wlan_network *found = NULL;
667
668         if (scanned_queue == NULL || network == NULL)
669                 goto exit;      
670
671         _enter_critical_bh(&scanned_queue->lock, &irqL);
672         found = _rtw_find_same_network(scanned_queue, network);
673         _exit_critical_bh(&scanned_queue->lock, &irqL);
674
675 exit:
676         return found;
677 }
678
679 struct  wlan_network    * rtw_get_oldest_wlan_network(_queue *scanned_queue)
680 {
681         _list   *plist, *phead;
682
683         
684         struct  wlan_network    *pwlan = NULL;
685         struct  wlan_network    *oldest = NULL;
686 _func_enter_;           
687         phead = get_list_head(scanned_queue);
688         
689         plist = get_next(phead);
690
691         while(1)
692         {
693                 
694                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
695                         break;
696                 
697                 pwlan= LIST_CONTAINOR(plist, struct wlan_network, list);
698
699                 if(pwlan->fixed!=_TRUE)
700                 {               
701                         if (oldest == NULL ||time_after(oldest->last_scanned, pwlan->last_scanned))
702                                 oldest = pwlan;
703                 }
704                 
705                 plist = get_next(plist);
706         }
707 _func_exit_;            
708         return oldest;
709         
710 }
711
712 void update_network(WLAN_BSSID_EX *dst, WLAN_BSSID_EX *src,
713         _adapter * padapter, bool update_ie)
714 {
715         u8 ss_ori = dst->PhyInfo.SignalStrength;
716         u8 sq_ori = dst->PhyInfo.SignalQuality;
717         long rssi_ori = dst->Rssi;
718
719         u8 ss_smp = src->PhyInfo.SignalStrength;
720         u8 sq_smp = src->PhyInfo.SignalQuality;
721         long rssi_smp = src->Rssi;
722
723         u8 ss_final;
724         u8 sq_final;
725         long rssi_final;
726
727 _func_enter_;           
728
729 #ifdef CONFIG_ANTENNA_DIVERSITY
730         rtw_hal_antdiv_rssi_compared(padapter, dst, src); //this will update src.Rssi, need consider again
731 #endif
732
733         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
734         if(strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
735                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT", ch%u) ss_ori:%3u, sq_ori:%3u, rssi_ori:%3ld, ss_smp:%3u, sq_smp:%3u, rssi_smp:%3ld\n"
736                         , FUNC_ADPT_ARG(padapter)
737                         , src->Ssid.Ssid, MAC_ARG(src->MacAddress), src->Configuration.DSConfig
738                         ,ss_ori, sq_ori, rssi_ori
739                         ,ss_smp, sq_smp, rssi_smp
740                 );
741         }
742         #endif
743
744         /* The rule below is 1/5 for sample value, 4/5 for history value */
745         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src, 0)) {
746                 /* Take the recvpriv's value for the connected AP*/
747                 ss_final = padapter->recvpriv.signal_strength;
748                 sq_final = padapter->recvpriv.signal_qual;
749                 /* the rssi value here is undecorated, and will be used for antenna diversity */
750                 if(sq_smp != 101) /* from the right channel */
751                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
752                 else
753                         rssi_final = rssi_ori;
754         }
755         else {
756                 if(sq_smp != 101) { /* from the right channel */
757                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
758                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
759                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
760                 } else {
761                         /* bss info not receving from the right channel, use the original RX signal infos */
762                         ss_final = dst->PhyInfo.SignalStrength;
763                         sq_final = dst->PhyInfo.SignalQuality;
764                         rssi_final = dst->Rssi;
765                 }
766                 
767         }
768
769         if (update_ie) {
770                 dst->Reserved[0] = src->Reserved[0];
771                 dst->Reserved[1] = src->Reserved[1];
772                 _rtw_memcpy((u8 *)dst, (u8 *)src, get_WLAN_BSSID_EX_sz(src));
773         }
774
775         dst->PhyInfo.SignalStrength = ss_final;
776         dst->PhyInfo.SignalQuality = sq_final;
777         dst->Rssi = rssi_final;
778
779         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
780         if(strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
781                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT"), SignalStrength:%u, SignalQuality:%u, RawRSSI:%ld\n"
782                         , FUNC_ADPT_ARG(padapter)
783                         , dst->Ssid.Ssid, MAC_ARG(dst->MacAddress), dst->PhyInfo.SignalStrength, dst->PhyInfo.SignalQuality, dst->Rssi);
784         }
785         #endif
786
787 #if 0 // old codes, may be useful one day...
788 //      DBG_871X("update_network: rssi=0x%lx dst->Rssi=%d ,dst->Rssi=0x%lx , src->Rssi=0x%lx",(dst->Rssi+src->Rssi)/2,dst->Rssi,dst->Rssi,src->Rssi);
789         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src))
790         {
791         
792                 //DBG_871X("b:ssid=%s update_network: src->rssi=0x%d padapter->recvpriv.ui_rssi=%d\n",src->Ssid.Ssid,src->Rssi,padapter->recvpriv.signal);
793                 if(padapter->recvpriv.signal_qual_data.total_num++ >= PHY_LINKQUALITY_SLID_WIN_MAX)
794                 {
795                       padapter->recvpriv.signal_qual_data.total_num = PHY_LINKQUALITY_SLID_WIN_MAX;
796                       last_evm = padapter->recvpriv.signal_qual_data.elements[padapter->recvpriv.signal_qual_data.index];
797                       padapter->recvpriv.signal_qual_data.total_val -= last_evm;
798                 }
799                 padapter->recvpriv.signal_qual_data.total_val += query_rx_pwr_percentage(src->Rssi);
800
801                 padapter->recvpriv.signal_qual_data.elements[padapter->recvpriv.signal_qual_data.index++] = query_rx_pwr_percentage(src->Rssi);
802                 if(padapter->recvpriv.signal_qual_data.index >= PHY_LINKQUALITY_SLID_WIN_MAX)
803                        padapter->recvpriv.signal_qual_data.index = 0;
804
805                 //DBG_871X("Total SQ=%d  pattrib->signal_qual= %d\n", padapter->recvpriv.signal_qual_data.total_val, src->Rssi);
806
807                 // <1> Showed on UI for user,in percentage.
808                 tmpVal = padapter->recvpriv.signal_qual_data.total_val/padapter->recvpriv.signal_qual_data.total_num;
809                 padapter->recvpriv.signal=(u8)tmpVal;//Link quality
810
811                 src->Rssi= translate_percentage_to_dbm(padapter->recvpriv.signal) ;
812         }
813         else{
814 //      DBG_871X("ELSE:ssid=%s update_network: src->rssi=0x%d dst->rssi=%d\n",src->Ssid.Ssid,src->Rssi,dst->Rssi);
815                 src->Rssi=(src->Rssi +dst->Rssi)/2;//dBM
816         }       
817
818 //      DBG_871X("a:update_network: src->rssi=0x%d padapter->recvpriv.ui_rssi=%d\n",src->Rssi,padapter->recvpriv.signal);
819
820 #endif
821
822 _func_exit_;            
823 }
824
825 static void update_current_network(_adapter *adapter, WLAN_BSSID_EX *pnetwork)
826 {
827         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
828         
829 _func_enter_;           
830
831         rtw_bug_check(&(pmlmepriv->cur_network.network), 
832                 &(pmlmepriv->cur_network.network), 
833                 &(pmlmepriv->cur_network.network), 
834                 &(pmlmepriv->cur_network.network));
835
836         if ( (check_fwstate(pmlmepriv, _FW_LINKED)== _TRUE) && (is_same_network(&(pmlmepriv->cur_network.network), pnetwork, 0)))
837         {
838                 //RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,"Same Network\n");
839
840                 //if(pmlmepriv->cur_network.network.IELength<= pnetwork->IELength)
841                 {
842                         update_network(&(pmlmepriv->cur_network.network), pnetwork,adapter, _TRUE);
843                         rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof (NDIS_802_11_FIXED_IEs), 
844                                                                         pmlmepriv->cur_network.network.IELength);
845                 }
846         }
847
848 _func_exit_;                    
849
850 }
851
852
853 /*
854
855 Caller must hold pmlmepriv->lock first.
856
857
858 */
859 void rtw_update_scanned_network(_adapter *adapter, WLAN_BSSID_EX *target)
860 {
861         _irqL irqL;
862         _list   *plist, *phead;
863         ULONG   bssid_ex_sz;
864         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
865         struct mlme_ext_priv    *pmlmeext = &(adapter->mlmeextpriv);
866         struct wifidirect_info *pwdinfo= &(adapter->wdinfo);    
867         _queue  *queue  = &(pmlmepriv->scanned_queue);
868         struct wlan_network     *pnetwork = NULL;
869         struct wlan_network     *oldest = NULL;
870         int target_find = 0;
871         u8 feature = 0;    
872
873 _func_enter_;
874
875         _enter_critical_bh(&queue->lock, &irqL);
876         phead = get_list_head(queue);
877         plist = get_next(phead);
878
879 #ifdef CONFIG_P2P
880         if (!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
881                 feature = 1; // p2p enable
882 #endif
883
884         while(1)
885         {
886                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
887                         break;
888
889                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
890
891                 rtw_bug_check(pnetwork, pnetwork, pnetwork, pnetwork);
892
893 #ifdef CONFIG_P2P
894                 if (!rtw_p2p_chk_state(&(adapter->wdinfo), P2P_STATE_NONE) &&
895                         (_rtw_memcmp(pnetwork->network.MacAddress, target->MacAddress, ETH_ALEN) == _TRUE))
896                 {
897                         target_find = 1;
898                         break;
899                 }
900 #endif
901
902                 if (is_same_network(&(pnetwork->network), target, feature))
903                 {
904                         target_find = 1;
905                         break;
906                 }
907
908                 if (rtw_roam_flags(adapter)) {
909                         /* TODO: don't  select netowrk in the same ess as oldest if it's new enough*/
910                 }
911
912                 if (oldest == NULL || time_after(oldest->last_scanned, pnetwork->last_scanned))
913                         oldest = pnetwork;
914
915                 plist = get_next(plist);
916
917         }
918         
919         
920         /* If we didn't find a match, then get a new network slot to initialize
921          * with this beacon's information */
922         //if (rtw_end_of_queue_search(phead,plist)== _TRUE) {
923         if (!target_find) {             
924                 if (_rtw_queue_empty(&(pmlmepriv->free_bss_pool)) == _TRUE) {
925                         /* If there are no more slots, expire the oldest */
926                         //list_del_init(&oldest->list);
927                         pnetwork = oldest;
928                         if(pnetwork==NULL){ 
929                                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n\n\nsomething wrong here\n\n\n"));
930                                 goto exit;
931                         }
932 #ifdef CONFIG_ANTENNA_DIVERSITY
933                         //target->PhyInfo.Optimum_antenna = pHalData->CurAntenna;//optimum_antenna=>For antenna diversity
934                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
935 #endif
936                         _rtw_memcpy(&(pnetwork->network), target,  get_WLAN_BSSID_EX_sz(target));
937                         //pnetwork->last_scanned = rtw_get_current_time();
938                         // variable initialize
939                         pnetwork->fixed = _FALSE;
940                         pnetwork->last_scanned = rtw_get_current_time();
941
942                         pnetwork->network_type = 0;     
943                         pnetwork->aid=0;                
944                         pnetwork->join_res=0;
945
946                         /* bss info not receving from the right channel */
947                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
948                                 pnetwork->network.PhyInfo.SignalQuality = 0;
949                 }
950                 else {
951                         /* Otherwise just pull from the free list */
952
953                         pnetwork = rtw_alloc_network(pmlmepriv); // will update scan_time
954
955                         if(pnetwork==NULL){ 
956                                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n\n\nsomething wrong here\n\n\n"));
957                                 goto exit;
958                         }
959
960                         bssid_ex_sz = get_WLAN_BSSID_EX_sz(target);
961                         target->Length = bssid_ex_sz;
962 #ifdef CONFIG_ANTENNA_DIVERSITY
963                         //target->PhyInfo.Optimum_antenna = pHalData->CurAntenna;
964                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
965 #endif
966                         _rtw_memcpy(&(pnetwork->network), target, bssid_ex_sz );
967
968                         pnetwork->last_scanned = rtw_get_current_time();
969
970                         /* bss info not receving from the right channel */
971                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
972                                 pnetwork->network.PhyInfo.SignalQuality = 0;
973
974                         rtw_list_insert_tail(&(pnetwork->list),&(queue->queue)); 
975
976                 }
977         }
978         else {
979                 /* we have an entry and we are going to update it. But this entry may
980                  * be already expired. In this case we do the same as we found a new 
981                  * net and call the new_net handler
982                  */
983                 bool update_ie = _TRUE;
984
985                 pnetwork->last_scanned = rtw_get_current_time();
986
987                 //target.Reserved[0]==1, means that scaned network is a bcn frame.
988                 if((pnetwork->network.IELength>target->IELength) && (target->Reserved[0]==1))
989                         update_ie = _FALSE;
990
991                 // probe resp(3) > beacon(1) > probe req(2)
992                 if ((target->Reserved[0] != 2) &&
993                         (target->Reserved[0] >= pnetwork->network.Reserved[0])
994                         ) {
995                         update_ie = _TRUE;
996                 }
997                 else {
998                         update_ie = _FALSE;
999                 }
1000
1001                 update_network(&(pnetwork->network), target,adapter, update_ie);
1002         }
1003
1004 exit:
1005         _exit_critical_bh(&queue->lock, &irqL);
1006
1007 _func_exit_;
1008 }
1009
1010 void rtw_add_network(_adapter *adapter, WLAN_BSSID_EX *pnetwork);
1011 void rtw_add_network(_adapter *adapter, WLAN_BSSID_EX *pnetwork)
1012 {
1013         _irqL irqL;
1014         struct  mlme_priv       *pmlmepriv = &(((_adapter *)adapter)->mlmepriv);
1015         //_queue        *queue  = &(pmlmepriv->scanned_queue);
1016
1017 _func_enter_;           
1018
1019         //_enter_critical_bh(&queue->lock, &irqL);
1020
1021         #if defined(CONFIG_P2P) && defined(CONFIG_P2P_REMOVE_GROUP_INFO)
1022         rtw_WLAN_BSSID_EX_remove_p2p_attr(pnetwork, P2P_ATTR_GROUP_INFO);
1023         #endif
1024         
1025         update_current_network(adapter, pnetwork);
1026         
1027         rtw_update_scanned_network(adapter, pnetwork);
1028
1029         //_exit_critical_bh(&queue->lock, &irqL);
1030         
1031 _func_exit_;            
1032 }
1033
1034 //select the desired network based on the capability of the (i)bss.
1035 // check items: (1) security
1036 //                         (2) network_type
1037 //                         (3) WMM
1038 //                         (4) HT
1039 //                     (5) others
1040 int rtw_is_desired_network(_adapter *adapter, struct wlan_network *pnetwork);
1041 int rtw_is_desired_network(_adapter *adapter, struct wlan_network *pnetwork)
1042 {
1043         struct security_priv *psecuritypriv = &adapter->securitypriv;
1044         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1045         u32 desired_encmode;
1046         u32 privacy;
1047
1048         //u8 wps_ie[512];
1049         uint wps_ielen;
1050
1051         int bselected = _TRUE;
1052         
1053         desired_encmode = psecuritypriv->ndisencryptstatus;
1054         privacy = pnetwork->network.Privacy;
1055
1056         if(check_fwstate(pmlmepriv, WIFI_UNDER_WPS))
1057         {
1058                 if(rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen)!=NULL)
1059                 {
1060                         return _TRUE;
1061                 }
1062                 else
1063                 {       
1064                         return _FALSE;
1065                 }       
1066         }
1067         if (adapter->registrypriv.wifi_spec == 1) //for  correct flow of 8021X  to do....
1068         {
1069                 u8 *p=NULL;
1070                 uint ie_len=0;
1071
1072                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
1073                     bselected = _FALSE;
1074
1075                 if ( psecuritypriv->ndisauthtype == Ndis802_11AuthModeWPA2PSK) {
1076                         p = rtw_get_ie(pnetwork->network.IEs + _BEACON_IE_OFFSET_, _RSN_IE_2_, &ie_len, (pnetwork->network.IELength - _BEACON_IE_OFFSET_));
1077                         if (p && ie_len>0) {
1078                                 bselected = _TRUE;
1079                         } else {
1080                                 bselected = _FALSE;
1081                         }
1082                 }
1083         }
1084         
1085
1086         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
1087                 DBG_871X("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
1088                 bselected = _FALSE;
1089         }
1090
1091         if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE)
1092         {
1093                 if(pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
1094                         bselected = _FALSE;
1095         }       
1096                 
1097
1098         return bselected;
1099 }
1100
1101 /* TODO: Perry : For Power Management */
1102 void rtw_atimdone_event_callback(_adapter       *adapter , u8 *pbuf)
1103 {
1104
1105 _func_enter_;           
1106         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("receive atimdone_evet\n"));        
1107 _func_exit_;                    
1108         return; 
1109 }
1110
1111
1112 void rtw_survey_event_callback(_adapter *adapter, u8 *pbuf)
1113 {
1114         _irqL  irqL;
1115         u32 len;
1116         WLAN_BSSID_EX *pnetwork;
1117         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
1118
1119 _func_enter_;           
1120
1121         pnetwork = (WLAN_BSSID_EX *)pbuf;
1122
1123         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_survey_event_callback, ssid=%s\n",  pnetwork->Ssid.Ssid));
1124
1125 #ifdef CONFIG_RTL8712
1126         //endian_convert
1127         pnetwork->Length = le32_to_cpu(pnetwork->Length);
1128         pnetwork->Ssid.SsidLength = le32_to_cpu(pnetwork->Ssid.SsidLength);     
1129         pnetwork->Privacy =le32_to_cpu( pnetwork->Privacy);
1130         pnetwork->Rssi = le32_to_cpu(pnetwork->Rssi);
1131         pnetwork->NetworkTypeInUse =le32_to_cpu(pnetwork->NetworkTypeInUse);    
1132         pnetwork->Configuration.ATIMWindow = le32_to_cpu(pnetwork->Configuration.ATIMWindow);
1133         pnetwork->Configuration.BeaconPeriod = le32_to_cpu(pnetwork->Configuration.BeaconPeriod);
1134         pnetwork->Configuration.DSConfig =le32_to_cpu(pnetwork->Configuration.DSConfig);
1135         pnetwork->Configuration.FHConfig.DwellTime=le32_to_cpu(pnetwork->Configuration.FHConfig.DwellTime);
1136         pnetwork->Configuration.FHConfig.HopPattern=le32_to_cpu(pnetwork->Configuration.FHConfig.HopPattern);
1137         pnetwork->Configuration.FHConfig.HopSet=le32_to_cpu(pnetwork->Configuration.FHConfig.HopSet);
1138         pnetwork->Configuration.FHConfig.Length=le32_to_cpu(pnetwork->Configuration.FHConfig.Length);   
1139         pnetwork->Configuration.Length = le32_to_cpu(pnetwork->Configuration.Length);
1140         pnetwork->InfrastructureMode = le32_to_cpu(pnetwork->InfrastructureMode);
1141         pnetwork->IELength = le32_to_cpu(pnetwork->IELength);
1142 #endif  
1143
1144         len = get_WLAN_BSSID_EX_sz(pnetwork);
1145         if(len > (sizeof(WLAN_BSSID_EX)))
1146         {
1147                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n ****rtw_survey_event_callback: return a wrong bss ***\n"));
1148                 return;
1149         }
1150
1151
1152         _enter_critical_bh(&pmlmepriv->lock, &irqL);
1153
1154         // update IBSS_network 's timestamp
1155         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == _TRUE)
1156         {
1157                 //RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,"rtw_survey_event_callback : WIFI_ADHOC_MASTER_STATE \n\n");
1158                 if(_rtw_memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN))
1159                 {
1160                         struct wlan_network* ibss_wlan = NULL;
1161                         _irqL   irqL;
1162                         
1163                         _rtw_memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
1164                         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
1165                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
1166                         if(ibss_wlan)
1167                         {
1168                                 _rtw_memcpy(ibss_wlan->network.IEs , pnetwork->IEs, 8);                 
1169                                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);             
1170                                 goto exit;
1171                         }
1172                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
1173                 }
1174         }
1175
1176         // lock pmlmepriv->lock when you accessing network_q
1177         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == _FALSE)
1178         {               
1179                 if( pnetwork->Ssid.Ssid[0] == 0 )
1180                 {
1181                         pnetwork->Ssid.SsidLength = 0;
1182                 }       
1183                 rtw_add_network(adapter, pnetwork);
1184         }       
1185
1186 exit:   
1187                 
1188         _exit_critical_bh(&pmlmepriv->lock, &irqL);
1189
1190 _func_exit_;            
1191
1192         return; 
1193 }
1194
1195
1196
1197 void rtw_surveydone_event_callback(_adapter     *adapter, u8 *pbuf)
1198 {
1199         _irqL  irqL;
1200         u8 timer_cancelled = _FALSE;
1201         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
1202         
1203 #ifdef CONFIG_MLME_EXT  
1204
1205         mlmeext_surveydone_event_callback(adapter);
1206
1207 #endif
1208
1209 _func_enter_;                   
1210
1211         _enter_critical_bh(&pmlmepriv->lock, &irqL);
1212         if(pmlmepriv->wps_probe_req_ie)
1213         {
1214                 u32 free_len = pmlmepriv->wps_probe_req_ie_len;
1215                 pmlmepriv->wps_probe_req_ie_len = 0;
1216                 rtw_mfree(pmlmepriv->wps_probe_req_ie, free_len);
1217                 pmlmepriv->wps_probe_req_ie = NULL;                     
1218         }
1219         
1220         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
1221         
1222         if (check_fwstate(pmlmepriv,_FW_UNDER_SURVEY))
1223         {
1224                 //u8 timer_cancelled;
1225
1226                 timer_cancelled = _TRUE;
1227                 //_cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
1228                 
1229                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1230         }
1231         else {
1232         
1233                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("nic status =%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));    
1234         }
1235         _exit_critical_bh(&pmlmepriv->lock, &irqL);
1236
1237         if(timer_cancelled)
1238                 _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
1239
1240
1241         _enter_critical_bh(&pmlmepriv->lock, &irqL);
1242
1243         #ifdef CONFIG_NEW_SIGNAL_STAT_PROCESS
1244         rtw_set_signal_stat_timer(&adapter->recvpriv);
1245         #endif
1246
1247         if(pmlmepriv->to_join == _TRUE)
1248         {
1249                 if((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)==_TRUE) )
1250                 {
1251                         if(check_fwstate(pmlmepriv, _FW_LINKED)==_FALSE)
1252                         {
1253                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);      
1254                                 
1255                                 if(rtw_select_and_join_from_scanned_queue(pmlmepriv)==_SUCCESS)
1256                                 {
1257                                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT );
1258                                 }
1259                                 else    
1260                                 {
1261                                         WLAN_BSSID_EX    *pdev_network = &(adapter->registrypriv.dev_network);                  
1262                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
1263
1264                                         //pmlmepriv->fw_state ^= _FW_UNDER_SURVEY;//because don't set assoc_timer
1265                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1266
1267                                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("switching to adhoc master\n"));
1268                                 
1269                                         _rtw_memset(&pdev_network->Ssid, 0, sizeof(NDIS_802_11_SSID));
1270                                         _rtw_memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(NDIS_802_11_SSID));
1271         
1272                                         rtw_update_registrypriv_dev_network(adapter);
1273                                         rtw_generate_random_ibss(pibss);
1274
1275                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
1276                         
1277                                         if(rtw_createbss_cmd(adapter)!=_SUCCESS)
1278                                         {
1279                                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Error=>rtw_createbss_cmd status FAIL\n"));                                         
1280                                         }       
1281
1282                                         pmlmepriv->to_join = _FALSE;
1283                                 }
1284                         }
1285                 }
1286                 else
1287                 {
1288                         int s_ret;
1289                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
1290                         pmlmepriv->to_join = _FALSE;
1291                         if(_SUCCESS == (s_ret=rtw_select_and_join_from_scanned_queue(pmlmepriv)))
1292                         {
1293                              _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);      
1294                         }
1295                         else if(s_ret == 2)//there is no need to wait for join
1296                         {
1297                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1298                                 rtw_indicate_connect(adapter);
1299                         }
1300                         else
1301                         {
1302                                 DBG_871X("try_to_join, but select scanning queue fail, to_roam:%d\n", rtw_to_roam(adapter));
1303
1304                                 if (rtw_to_roam(adapter) != 0) {
1305                                         if(rtw_dec_to_roam(adapter) == 0
1306                                                 || _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)
1307                                         ) {
1308                                                 rtw_set_to_roam(adapter, 0);
1309 #ifdef CONFIG_INTEL_WIDI
1310                                                 if(adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING)
1311                                                 {
1312                                                         _rtw_memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1313                                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1314                                                         DBG_871X("change to widi listen\n");
1315                                                 }
1316 #endif // CONFIG_INTEL_WIDI
1317                                                 rtw_free_assoc_resources(adapter, 1);
1318                                                 rtw_indicate_disconnect(adapter);
1319                                         } else {
1320                                                 pmlmepriv->to_join = _TRUE;
1321                                         }
1322                                 }
1323                                 else
1324                                 {
1325                                         rtw_indicate_disconnect(adapter);
1326                                 }
1327                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1328                         }
1329                 }
1330         } else {
1331                 if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1332                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)
1333                                 && check_fwstate(pmlmepriv, _FW_LINKED))
1334                         {
1335                                 if (rtw_select_roaming_candidate(pmlmepriv) == _SUCCESS) {
1336                                         receive_disconnect(adapter, pmlmepriv->cur_network.network.MacAddress
1337                                                 , WLAN_REASON_ACTIVE_ROAM);
1338                                 }
1339                         }
1340                 }
1341         }
1342         
1343         //DBG_871X("scan complete in %dms\n",rtw_get_passing_time_ms(pmlmepriv->scan_start_time));
1344
1345         _exit_critical_bh(&pmlmepriv->lock, &irqL);
1346
1347 #ifdef CONFIG_P2P_PS
1348         if (check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE) {
1349                 p2p_ps_wk_cmd(adapter, P2P_PS_SCAN_DONE, 0);
1350         }
1351 #endif // CONFIG_P2P_PS
1352
1353         rtw_os_xmit_schedule(adapter);
1354 #ifdef CONFIG_CONCURRENT_MODE   
1355         rtw_os_xmit_schedule(adapter->pbuddy_adapter);
1356 #endif
1357 #ifdef CONFIG_DUALMAC_CONCURRENT
1358         dc_resume_xmit(adapter);
1359 #endif
1360
1361 #ifdef CONFIG_DRVEXT_MODULE_WSC
1362         drvext_surveydone_callback(&adapter->drvextpriv);
1363 #endif
1364
1365 #ifdef DBG_CONFIG_ERROR_DETECT
1366         {
1367                 struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;         
1368                 if(pmlmeext->sitesurvey_res.bss_cnt == 0){
1369                         //rtw_hal_sreset_reset(adapter);
1370                 }
1371         }
1372 #endif
1373
1374 #ifdef CONFIG_IOCTL_CFG80211
1375         rtw_cfg80211_surveydone_event_callback(adapter);
1376 #endif //CONFIG_IOCTL_CFG80211
1377
1378         rtw_indicate_scan_done(adapter, _FALSE);
1379
1380 #if defined(CONFIG_CONCURRENT_MODE) && defined(CONFIG_IOCTL_CFG80211)
1381         if (adapter->pbuddy_adapter) {
1382                 _adapter *buddy_adapter = adapter->pbuddy_adapter;
1383                 struct mlme_priv *buddy_mlme = &(buddy_adapter->mlmepriv);
1384                 struct rtw_wdev_priv *buddy_wdev_priv = adapter_wdev_data(buddy_adapter);
1385                 bool indicate_buddy_scan = _FALSE;
1386
1387                 _enter_critical_bh(&buddy_wdev_priv->scan_req_lock, &irqL);
1388                 if (buddy_wdev_priv->scan_request && buddy_mlme->scanning_via_buddy_intf == _TRUE) {
1389                         buddy_mlme->scanning_via_buddy_intf = _FALSE;
1390                         clr_fwstate(buddy_mlme, _FW_UNDER_SURVEY);
1391                         indicate_buddy_scan = _TRUE;
1392                 }
1393                 _exit_critical_bh(&buddy_wdev_priv->scan_req_lock, &irqL);
1394
1395                 if (indicate_buddy_scan == _TRUE) {
1396                         #ifdef CONFIG_IOCTL_CFG80211
1397                         rtw_cfg80211_surveydone_event_callback(buddy_adapter);
1398                         #endif
1399                         rtw_indicate_scan_done(buddy_adapter, _FALSE);
1400                 }
1401         }
1402 #endif /* CONFIG_CONCURRENT_MODE */
1403
1404 _func_exit_;    
1405
1406 }
1407
1408 void rtw_dummy_event_callback(_adapter *adapter , u8 *pbuf)
1409 {
1410
1411 }
1412
1413 void rtw_fwdbg_event_callback(_adapter *adapter , u8 *pbuf)
1414 {
1415
1416 }
1417
1418 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
1419 {
1420         _irqL irqL, irqL0;
1421         _queue *free_queue = &pmlmepriv->free_bss_pool;
1422         _queue *scan_queue = &pmlmepriv->scanned_queue;
1423         _list   *plist, *phead, *ptemp;
1424         
1425 _func_enter_;           
1426         
1427         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
1428         _enter_critical_bh(&scan_queue->lock, &irqL0);
1429         _enter_critical_bh(&free_queue->lock, &irqL);
1430
1431         phead = get_list_head(scan_queue);
1432         plist = get_next(phead);
1433
1434         while (plist != phead)
1435        {
1436                 ptemp = get_next(plist);
1437                 rtw_list_delete(plist);
1438                 rtw_list_insert_tail(plist, &free_queue->queue);
1439                 plist =ptemp;
1440                 pmlmepriv->num_of_scanned --;
1441         }
1442         
1443         _exit_critical_bh(&free_queue->lock, &irqL);
1444         _exit_critical_bh(&scan_queue->lock, &irqL0);
1445         
1446 _func_exit_;
1447 }
1448
1449 void rtw_reset_rx_info(struct debug_priv *pdbgpriv){
1450         pdbgpriv->dbg_rx_ampdu_drop_count = 0;
1451         pdbgpriv->dbg_rx_ampdu_forced_indicate_count = 0;
1452         pdbgpriv->dbg_rx_ampdu_loss_count = 0;
1453         pdbgpriv->dbg_rx_dup_mgt_frame_drop_count = 0;
1454         pdbgpriv->dbg_rx_ampdu_window_shift_cnt = 0;
1455 }
1456         
1457 /*
1458 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
1459 */
1460 void rtw_free_assoc_resources(_adapter *adapter, int lock_scanned_queue)
1461 {
1462         _irqL irqL;
1463         struct wlan_network* pwlan = NULL;
1464         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1465         struct  sta_priv *pstapriv = &adapter->stapriv;
1466         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1467         struct dvobj_priv *psdpriv = adapter->dvobj;
1468         struct debug_priv *pdbgpriv = &psdpriv->drv_dbg;        
1469
1470         
1471 #ifdef CONFIG_TDLS
1472         struct tdls_info *ptdlsinfo = &adapter->tdlsinfo;
1473 #endif //CONFIG_TDLS
1474 _func_enter_;                   
1475
1476         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
1477         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("tgt_network->network.MacAddress="MAC_FMT" ssid=%s\n",
1478                 MAC_ARG(tgt_network->network.MacAddress), tgt_network->network.Ssid.Ssid));
1479
1480         if(check_fwstate( pmlmepriv, WIFI_STATION_STATE|WIFI_AP_STATE))
1481         {
1482                 struct sta_info* psta;
1483                 
1484                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
1485
1486 #ifdef CONFIG_TDLS
1487                 if(ptdlsinfo->link_established == _TRUE)
1488                 {
1489                         rtw_tdls_cmd(adapter, myid(&(adapter->eeprompriv)), TDLS_RS_RCR);
1490                         rtw_reset_tdls_info(adapter);
1491                         rtw_free_all_stainfo(adapter);
1492                         _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
1493                 }
1494                 else
1495 #endif //CONFIG_TDLS
1496                 {
1497                         _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
1498                         rtw_free_stainfo(adapter,  psta);
1499                 }
1500
1501                 _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
1502                 
1503         }
1504
1505         if(check_fwstate( pmlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE|WIFI_AP_STATE))
1506         {
1507                 struct sta_info* psta;
1508         
1509                 rtw_free_all_stainfo(adapter);
1510
1511                 psta = rtw_get_bcmc_stainfo(adapter);
1512                 _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);          
1513                 rtw_free_stainfo(adapter, psta);
1514                 _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL);           
1515
1516                 rtw_init_bcmc_stainfo(adapter); 
1517         }
1518
1519         if(lock_scanned_queue)
1520                 _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
1521         
1522         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1523         if(pwlan)               
1524         {
1525                 pwlan->fixed = _FALSE;
1526 #ifdef CONFIG_P2P
1527                 if(!rtw_p2p_chk_state(&adapter->wdinfo, P2P_STATE_NONE))
1528                 {
1529                         u32 p2p_ielen=0;
1530                         u8  *p2p_ie;
1531                         //u16 capability;
1532                         u8 *pcap = NULL;
1533                         u32 capability_len=0;
1534                         
1535                         //DBG_871X("free disconnecting network\n");
1536                         //rtw_free_network_nolock(pmlmepriv, pwlan);
1537
1538                         if((p2p_ie=rtw_get_p2p_ie(pwlan->network.IEs+_FIXED_IE_LENGTH_, pwlan->network.IELength-_FIXED_IE_LENGTH_, NULL, &p2p_ielen)))
1539                         {                       
1540                                 pcap = rtw_get_p2p_attr_content(p2p_ie, p2p_ielen, P2P_ATTR_CAPABILITY, NULL, &capability_len);
1541                                 if(pcap && capability_len==2)
1542                                 {
1543                                         u16 cap = *(u16*)pcap ;
1544                                         *(u16*)pcap = cap&0x00ff;//clear group capability when free this network
1545                                 }
1546
1547         }       
1548
1549                         rtw_set_scan_deny(adapter, 2000);
1550                         //rtw_clear_scan_deny(adapter);
1551                         
1552                 }
1553 #endif //CONFIG_P2P
1554         }       
1555         else
1556         {
1557                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_free_assoc_resources : pwlan== NULL \n\n"));
1558         }
1559
1560
1561         if((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) && (adapter->stapriv.asoc_sta_count== 1))
1562                 /*||check_fwstate(pmlmepriv, WIFI_STATION_STATE)*/)
1563         {
1564                 rtw_free_network_nolock(adapter, pwlan); 
1565         }
1566
1567         if(lock_scanned_queue)
1568                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
1569         
1570         adapter->securitypriv.key_mask = 0;
1571
1572         rtw_reset_rx_info(pdbgpriv);
1573
1574 _func_exit_;    
1575         
1576 }
1577
1578 /*
1579 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
1580 */
1581 void rtw_indicate_connect(_adapter *padapter)
1582 {
1583         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1584         struct xmit_priv        *pxmitpriv = &padapter->xmitpriv;
1585         
1586 _func_enter_;
1587
1588         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
1589  
1590         pmlmepriv->to_join = _FALSE;
1591
1592         if(!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) 
1593         {
1594
1595 #ifdef CONFIG_SW_ANTENNA_DIVERSITY
1596                 rtw_hal_set_hwreg(padapter, HW_VAR_ANTENNA_DIVERSITY_LINK, 0);
1597 #endif
1598
1599                 set_fwstate(pmlmepriv, _FW_LINKED);
1600
1601                 rtw_led_control(padapter, LED_CTL_LINK);
1602
1603         
1604 #ifdef CONFIG_DRVEXT_MODULE
1605                 if(padapter->drvextpriv.enable_wpa)
1606                 {
1607                         indicate_l2_connect(padapter);
1608                 }
1609                 else
1610 #endif
1611                 {
1612                         rtw_os_indicate_connect(padapter);
1613                 }
1614
1615         }
1616
1617         rtw_set_to_roam(padapter, 0);
1618 #ifdef CONFIG_INTEL_WIDI
1619         if(padapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING)
1620         {
1621                 _rtw_memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1622                 intel_widi_wk_cmd(padapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1623                 DBG_871X("change to widi listen\n");
1624         }
1625 #endif // CONFIG_INTEL_WIDI
1626
1627         rtw_set_scan_deny(padapter, 3000);
1628
1629         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state=0x%08x\n", get_fwstate(pmlmepriv)));
1630  
1631 _func_exit_;
1632
1633 }
1634
1635
1636 /*
1637 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
1638 */
1639 void rtw_indicate_disconnect( _adapter *padapter )
1640 {
1641         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;     
1642         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
1643         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1644         WLAN_BSSID_EX   *cur_network = &(pmlmeinfo->network);
1645         struct sta_info *psta;
1646         struct sta_priv *pstapriv = &padapter->stapriv;
1647
1648 _func_enter_;   
1649         
1650         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
1651
1652         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING|WIFI_UNDER_WPS);
1653
1654         //DBG_871X("clear wps when %s\n", __func__);
1655
1656         if(rtw_to_roam(padapter) > 0)
1657                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1658
1659 #ifdef CONFIG_WAPI_SUPPORT
1660         psta = rtw_get_stainfo(pstapriv,cur_network->MacAddress);
1661         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE))
1662         {
1663                 rtw_wapi_return_one_sta_info(padapter, psta->hwaddr);
1664         }
1665         else if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) ||
1666                 check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE))
1667         {
1668                 rtw_wapi_return_all_sta_info(padapter);
1669         }
1670 #endif
1671
1672         if(check_fwstate(&padapter->mlmepriv, _FW_LINKED) 
1673                 || (rtw_to_roam(padapter) <= 0)
1674         )
1675         {
1676                 rtw_os_indicate_disconnect(padapter);
1677
1678                 //set ips_deny_time to avoid enter IPS before LPS leave
1679                 rtw_set_ips_deny(padapter, 3000);
1680
1681               _clr_fwstate_(pmlmepriv, _FW_LINKED);
1682
1683                 rtw_led_control(padapter, LED_CTL_NO_LINK);
1684
1685                 rtw_clear_scan_deny(padapter);
1686         }
1687
1688 #ifdef CONFIG_P2P_PS
1689         p2p_ps_wk_cmd(padapter, P2P_PS_DISABLE, 1);
1690 #endif // CONFIG_P2P_PS
1691
1692 #ifdef CONFIG_LPS
1693         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
1694 #endif
1695
1696 #ifdef CONFIG_BEAMFORMING
1697         beamforming_wk_cmd(padapter, BEAMFORMING_CTRL_LEAVE, cur_network->MacAddress, ETH_ALEN, 1);
1698 #endif
1699
1700 _func_exit_;    
1701 }
1702
1703 inline void rtw_indicate_scan_done( _adapter *padapter, bool aborted)
1704 {
1705         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1706
1707         rtw_os_indicate_scan_done(padapter, aborted);
1708
1709 #ifdef CONFIG_IPS
1710         if (is_primary_adapter(padapter)
1711                 && (_FALSE == adapter_to_pwrctl(padapter)->bInSuspend)
1712                 && (check_fwstate(&padapter->mlmepriv, WIFI_ASOC_STATE|WIFI_UNDER_LINKING) == _FALSE))
1713         {
1714                 struct pwrctrl_priv *pwrpriv;
1715
1716                 pwrpriv = adapter_to_pwrctl(padapter);
1717                 rtw_set_ips_deny(padapter, 0);
1718 #ifdef CONFIG_IPS_CHECK_IN_WD
1719                 _set_timer(&padapter->mlmepriv.dynamic_chk_timer, 1);
1720 #else // !CONFIG_IPS_CHECK_IN_WD
1721                 _rtw_set_pwr_state_check_timer(pwrpriv, 1);
1722 #endif // !CONFIG_IPS_CHECK_IN_WD
1723         }
1724 #endif // CONFIG_IPS
1725 }
1726
1727 void rtw_scan_abort(_adapter *adapter)
1728 {
1729         u32 cnt=0;
1730         u32 start;
1731         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
1732         struct mlme_ext_priv    *pmlmeext = &(adapter->mlmeextpriv);
1733
1734         start = rtw_get_current_time();
1735         pmlmeext->scan_abort = _TRUE;
1736         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)
1737                 && rtw_get_passing_time_ms(start) <= 200) {
1738
1739                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1740                         break;
1741
1742                 DBG_871X(FUNC_NDEV_FMT"fw_state=_FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1743                 rtw_msleep_os(20);
1744         }
1745
1746         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
1747                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
1748                         DBG_871X(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1749                 #ifdef CONFIG_PLATFORM_MSTAR
1750                 //_clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1751                 set_survey_timer(pmlmeext, 0);
1752                 _set_timer(&pmlmepriv->scan_to_timer, 50);
1753                 #endif
1754                 rtw_indicate_scan_done(adapter, _TRUE);
1755         }
1756         pmlmeext->scan_abort = _FALSE;
1757 }
1758
1759 static struct sta_info *rtw_joinbss_update_stainfo(_adapter *padapter, struct wlan_network *pnetwork)
1760 {
1761         int i;
1762         struct sta_info *bmc_sta, *psta=NULL;
1763         struct recv_reorder_ctrl *preorder_ctrl;
1764         struct sta_priv *pstapriv = &padapter->stapriv;
1765         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
1766
1767         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
1768         if(psta==NULL) {
1769                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
1770         }
1771
1772         if(psta) //update ptarget_sta
1773         {
1774                 DBG_871X("%s\n", __FUNCTION__);
1775         
1776                 psta->aid  = pnetwork->join_res;
1777
1778 #if 0 //alloc macid when call rtw_alloc_stainfo(), and release macid when call rtw_free_stainfo()
1779 #ifdef CONFIG_CONCURRENT_MODE   
1780
1781                 if(PRIMARY_ADAPTER == padapter->adapter_type)
1782                         psta->mac_id=0;
1783                 else
1784                         psta->mac_id=2;
1785 #else
1786                 psta->mac_id=0;
1787 #endif
1788 #endif //removed
1789
1790                 update_sta_info(padapter, psta);
1791
1792                 //update station supportRate
1793                 psta->bssratelen = rtw_get_rateset_len(pnetwork->network.SupportedRates);
1794                 _rtw_memcpy(psta->bssrateset, pnetwork->network.SupportedRates, psta->bssratelen);
1795                 rtw_hal_update_sta_rate_mask(padapter, psta);
1796
1797                 psta->wireless_mode = pmlmeext->cur_wireless_mode;
1798                 psta->raid = rtw_hal_networktype_to_raid(padapter,psta);
1799
1800
1801                 //sta mode
1802                 rtw_hal_set_odm_var(padapter,HAL_ODM_STA_INFO,psta,_TRUE);
1803
1804                 //security related
1805                 if(padapter->securitypriv.dot11AuthAlgrthm== dot11AuthAlgrthm_8021X)
1806                 {                                               
1807                         padapter->securitypriv.binstallGrpkey=_FALSE;
1808                         padapter->securitypriv.busetkipkey=_FALSE;                                              
1809                         padapter->securitypriv.bgrpkey_handshake=_FALSE;
1810
1811                         psta->ieee8021x_blocked=_TRUE;
1812                         psta->dot118021XPrivacy=padapter->securitypriv.dot11PrivacyAlgrthm;
1813                                                 
1814                         _rtw_memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof (union Keytype));
1815                                                 
1816                         _rtw_memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof (union Keytype));
1817                         _rtw_memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof (union Keytype));
1818                                                 
1819                         _rtw_memset((u8 *)&psta->dot11txpn, 0, sizeof (union pn48));
1820                         psta->dot11txpn.val = psta->dot11txpn.val + 1;
1821 #ifdef CONFIG_IEEE80211W
1822                         _rtw_memset((u8 *)&psta->dot11wtxpn, 0, sizeof (union pn48));
1823 #endif //CONFIG_IEEE80211W
1824                         _rtw_memset((u8 *)&psta->dot11rxpn, 0, sizeof (union pn48));    
1825                 }
1826
1827                 //      Commented by Albert 2012/07/21
1828                 //      When doing the WPS, the wps_ie_len won't equal to 0
1829                 //      And the Wi-Fi driver shouldn't allow the data packet to be tramsmitted.
1830                 if ( padapter->securitypriv.wps_ie_len != 0 )
1831                 {
1832                         psta->ieee8021x_blocked=_TRUE;
1833                         padapter->securitypriv.wps_ie_len = 0;
1834                 }
1835
1836
1837                 //for A-MPDU Rx reordering buffer control for bmc_sta & sta_info
1838                 //if A-MPDU Rx is enabled, reseting  rx_ordering_ctrl wstart_b(indicate_seq) to default value=0xffff
1839                 //todo: check if AP can send A-MPDU packets
1840                 for(i=0; i < 16 ; i++)
1841                 {
1842                         //preorder_ctrl = &precvpriv->recvreorder_ctrl[i];
1843                         preorder_ctrl = &psta->recvreorder_ctrl[i];
1844                         preorder_ctrl->enable = _FALSE;
1845                         preorder_ctrl->indicate_seq = 0xffff;
1846                         #ifdef DBG_RX_SEQ
1847                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u \n", __FUNCTION__, __LINE__,
1848                                 preorder_ctrl->indicate_seq);
1849                         #endif
1850                         preorder_ctrl->wend_b= 0xffff;
1851                         preorder_ctrl->wsize_b = 64;//max_ampdu_sz;//ex. 32(kbytes) -> wsize_b=32
1852                 }
1853
1854                 
1855                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
1856                 if(bmc_sta)
1857                 {
1858                         for(i=0; i < 16 ; i++)
1859                         {
1860                                 //preorder_ctrl = &precvpriv->recvreorder_ctrl[i];
1861                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
1862                                 preorder_ctrl->enable = _FALSE;
1863                                 preorder_ctrl->indicate_seq = 0xffff;
1864                                 #ifdef DBG_RX_SEQ
1865                                 DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u \n", __FUNCTION__, __LINE__,
1866                                         preorder_ctrl->indicate_seq);
1867                                 #endif
1868                                 preorder_ctrl->wend_b= 0xffff;
1869                                 preorder_ctrl->wsize_b = 64;//max_ampdu_sz;//ex. 32(kbytes) -> wsize_b=32
1870                         }
1871                 }
1872         }
1873                                         
1874         return psta;
1875         
1876 }
1877
1878 //pnetwork : returns from rtw_joinbss_event_callback
1879 //ptarget_wlan: found from scanned_queue
1880 static void rtw_joinbss_update_network(_adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
1881 {
1882         struct mlme_priv        *pmlmepriv = &(padapter->mlmepriv);     
1883         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
1884
1885         DBG_871X("%s\n", __FUNCTION__);
1886         
1887         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("\nfw_state:%x, BSSID:"MAC_FMT"\n"
1888                 ,get_fwstate(pmlmepriv), MAC_ARG(pnetwork->network.MacAddress)));
1889
1890                                 
1891         // why not use ptarget_wlan??
1892         _rtw_memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
1893         // some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs
1894         cur_network->network.IELength = ptarget_wlan->network.IELength;
1895         _rtw_memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
1896
1897         cur_network->aid = pnetwork->join_res;
1898
1899                                 
1900 #ifdef CONFIG_NEW_SIGNAL_STAT_PROCESS
1901         rtw_set_signal_stat_timer(&padapter->recvpriv);
1902 #endif
1903         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
1904         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
1905         //the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled)
1906         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
1907         #if defined(DBG_RX_SIGNAL_DISPLAY_PROCESSING) && 1
1908                 DBG_871X(FUNC_ADPT_FMT" signal_strength:%3u, rssi:%3d, signal_qual:%3u"
1909                         "\n"
1910                         , FUNC_ADPT_ARG(padapter)
1911                         , padapter->recvpriv.signal_strength
1912                         , padapter->recvpriv.rssi
1913                         , padapter->recvpriv.signal_qual
1914         );
1915         #endif
1916 #ifdef CONFIG_NEW_SIGNAL_STAT_PROCESS
1917         rtw_set_signal_stat_timer(&padapter->recvpriv);
1918 #endif
1919                                 
1920         //update fw_state //will clr _FW_UNDER_LINKING here indirectly
1921         switch(pnetwork->network.InfrastructureMode)
1922         {       
1923                 case Ndis802_11Infrastructure:                                          
1924                         
1925                                 if(pmlmepriv->fw_state&WIFI_UNDER_WPS)
1926                                         pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
1927                                 else
1928                                         pmlmepriv->fw_state = WIFI_STATION_STATE;
1929                                 
1930                                 break;
1931                 case Ndis802_11IBSS:            
1932                                 pmlmepriv->fw_state = WIFI_ADHOC_STATE;
1933                                 break;
1934                 default:
1935                                 pmlmepriv->fw_state = WIFI_NULL_STATE;
1936                                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Invalid network_mode\n"));
1937                                 break;
1938         }
1939
1940         rtw_update_protection(padapter, (cur_network->network.IEs) + sizeof (NDIS_802_11_FIXED_IEs), 
1941                                                                         (cur_network->network.IELength));
1942
1943 #ifdef CONFIG_80211N_HT                 
1944         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength, (u8) cur_network->network.Configuration.DSConfig);
1945 #endif
1946 }
1947
1948 //Notes: the fucntion could be > passive_level (the same context as Rx tasklet)
1949 //pnetwork : returns from rtw_joinbss_event_callback
1950 //ptarget_wlan: found from scanned_queue
1951 //if join_res > 0, for (fw_state==WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist.       
1952 //if join_res > 0, for (fw_state==WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist.
1953 //if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan !=NULL).
1954 //
1955 //#define REJOIN
1956 void rtw_joinbss_event_prehandle(_adapter *adapter, u8 *pbuf)
1957 {
1958         _irqL irqL,irqL2;
1959         static u8 retry=0;
1960         u8 timer_cancelled;
1961         struct sta_info *ptarget_sta= NULL, *pcur_sta = NULL;
1962         struct  sta_priv *pstapriv = &adapter->stapriv;
1963         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
1964         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1965         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1966         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1967         unsigned int            the_same_macaddr = _FALSE;      
1968
1969 _func_enter_;   
1970
1971 #ifdef CONFIG_RTL8712
1972        //endian_convert
1973         pnetwork->join_res = le32_to_cpu(pnetwork->join_res);
1974         pnetwork->network_type = le32_to_cpu(pnetwork->network_type);
1975         pnetwork->network.Length = le32_to_cpu(pnetwork->network.Length);
1976         pnetwork->network.Ssid.SsidLength = le32_to_cpu(pnetwork->network.Ssid.SsidLength);
1977         pnetwork->network.Privacy =le32_to_cpu( pnetwork->network.Privacy);
1978         pnetwork->network.Rssi = le32_to_cpu(pnetwork->network.Rssi);
1979         pnetwork->network.NetworkTypeInUse =le32_to_cpu(pnetwork->network.NetworkTypeInUse) ;   
1980         pnetwork->network.Configuration.ATIMWindow = le32_to_cpu(pnetwork->network.Configuration.ATIMWindow);
1981         pnetwork->network.Configuration.BeaconPeriod = le32_to_cpu(pnetwork->network.Configuration.BeaconPeriod);
1982         pnetwork->network.Configuration.DSConfig = le32_to_cpu(pnetwork->network.Configuration.DSConfig);
1983         pnetwork->network.Configuration.FHConfig.DwellTime=le32_to_cpu(pnetwork->network.Configuration.FHConfig.DwellTime);
1984         pnetwork->network.Configuration.FHConfig.HopPattern=le32_to_cpu(pnetwork->network.Configuration.FHConfig.HopPattern);
1985         pnetwork->network.Configuration.FHConfig.HopSet=le32_to_cpu(pnetwork->network.Configuration.FHConfig.HopSet);
1986         pnetwork->network.Configuration.FHConfig.Length=le32_to_cpu(pnetwork->network.Configuration.FHConfig.Length);   
1987         pnetwork->network.Configuration.Length = le32_to_cpu(pnetwork->network.Configuration.Length);
1988         pnetwork->network.InfrastructureMode = le32_to_cpu(pnetwork->network.InfrastructureMode);
1989         pnetwork->network.IELength = le32_to_cpu(pnetwork->network.IELength );
1990 #endif
1991
1992         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("joinbss event call back received with res=%d\n", pnetwork->join_res));
1993
1994         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1995         
1996
1997         if (pmlmepriv->assoc_ssid.SsidLength == 0)
1998         {
1999                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("@@@@@   joinbss event call back  for Any SSid\n"));                
2000         }
2001         else
2002         {
2003                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
2004         }
2005         
2006         the_same_macaddr = _rtw_memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
2007
2008         pnetwork->network.Length = get_WLAN_BSSID_EX_sz(&pnetwork->network);
2009         if(pnetwork->network.Length > sizeof(WLAN_BSSID_EX))
2010         {
2011                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
2012                 goto ignore_joinbss_callback;
2013         }
2014                 
2015         _enter_critical_bh(&pmlmepriv->lock, &irqL);
2016         
2017         pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 0;
2018         pmlmepriv->LinkDetectInfo.LowPowerTransitionCount = 0;
2019         
2020         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("\n rtw_joinbss_event_callback !! _enter_critical \n"));
2021
2022         if(pnetwork->join_res > 0)
2023         {
2024                 _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2025                 retry = 0;
2026                 if (check_fwstate(pmlmepriv,_FW_UNDER_LINKING) )
2027                 {
2028                         //s1. find ptarget_wlan
2029                         if(check_fwstate(pmlmepriv, _FW_LINKED) )
2030                         {
2031                                 if(the_same_macaddr == _TRUE)
2032                                 {
2033                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);                                    
2034                                 }
2035                                 else
2036                                 {
2037                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
2038                                         if(pcur_wlan)   pcur_wlan->fixed = _FALSE;
2039
2040                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
2041                                         if(pcur_sta){
2042                                                 _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL2);
2043                                                 rtw_free_stainfo(adapter,  pcur_sta);
2044                                                 _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL2);
2045                                         }
2046
2047                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
2048                                         if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE){
2049                                                 if(ptarget_wlan)        ptarget_wlan->fixed = _TRUE;                    
2050                                         }
2051                                 }
2052
2053                         }
2054                         else
2055                         {
2056                                 ptarget_wlan = _rtw_find_same_network(&pmlmepriv->scanned_queue, pnetwork);
2057                                 if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE){
2058                                         if(ptarget_wlan)        ptarget_wlan->fixed = _TRUE;                    
2059                                 }
2060                         }
2061                 
2062                         //s2. update cur_network 
2063                         if(ptarget_wlan)
2064                         {                       
2065                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
2066                         }
2067                         else
2068                         {                       
2069                                 DBG_871X_LEVEL(_drv_always_, "Can't find ptarget_wlan when joinbss_event callback\n");
2070                                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2071                                 goto ignore_joinbss_callback;
2072                         }
2073                                         
2074                         
2075                         //s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode 
2076                         if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE)
2077                         { 
2078                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
2079                                 if(ptarget_sta==NULL)
2080                                 {
2081                                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Can't update stainfo when joinbss_event callback\n"));
2082                                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2083                                         goto ignore_joinbss_callback;
2084                                 }
2085                         }
2086
2087                         //s4. indicate connect                  
2088                         if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE)
2089                         {
2090                                 pmlmepriv->cur_network_scanned = ptarget_wlan;
2091                                 rtw_indicate_connect(adapter);
2092                         }
2093                         else
2094                         {
2095                                 //adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback
2096                                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
2097                         }
2098
2099                                 
2100                         //s5. Cancle assoc_timer                                        
2101                         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
2102                 
2103                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("Cancle assoc_timer \n"));         
2104                 
2105                 }
2106                 else
2107                 {
2108                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));    
2109                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2110                         goto ignore_joinbss_callback;
2111                 }
2112                 
2113                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);     
2114                                 
2115         }
2116         else if(pnetwork->join_res == -4) 
2117         {
2118                 rtw_reset_securitypriv(adapter);
2119                 _set_timer(&pmlmepriv->assoc_timer, 1);                                 
2120
2121                 //rtw_free_assoc_resources(adapter, 1);
2122
2123                 if((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == _TRUE)
2124                 {               
2125                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("fail! clear _FW_UNDER_LINKING ^^^fw_state=%x\n", get_fwstate(pmlmepriv)));
2126                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
2127                 }       
2128                 
2129         }
2130         else //if join_res < 0 (join fails), then try again
2131         {
2132         
2133                 #ifdef REJOIN
2134                 res = _FAIL;
2135                 if(retry < 2) {
2136                         res = rtw_select_and_join_from_scanned_queue(pmlmepriv);
2137                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_select_and_join_from_scanned_queue again! res:%d\n",res));
2138                 }
2139
2140                  if(res == _SUCCESS)
2141                 {
2142                         //extend time of assoc_timer
2143                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
2144                         retry++;
2145                 }
2146                 else if(res == 2)//there is no need to wait for join
2147                 {
2148                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
2149                         rtw_indicate_connect(adapter);
2150                 }       
2151                 else
2152                 {
2153                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Set Assoc_Timer = 1; can't find match ssid in scanned_q \n"));
2154                 #endif
2155                         
2156                         _set_timer(&pmlmepriv->assoc_timer, 1);
2157                         //rtw_free_assoc_resources(adapter, 1);
2158                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
2159                         
2160                 #ifdef REJOIN
2161                         retry = 0;      
2162                 }
2163                 #endif
2164         }
2165
2166 ignore_joinbss_callback:
2167
2168         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2169         _func_exit_;    
2170 }
2171
2172 void rtw_joinbss_event_callback(_adapter *adapter, u8 *pbuf)
2173 {
2174         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
2175
2176 _func_enter_;
2177
2178         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
2179
2180         rtw_os_xmit_schedule(adapter);
2181
2182 #ifdef CONFIG_CONCURRENT_MODE   
2183         rtw_os_xmit_schedule(adapter->pbuddy_adapter);
2184 #endif  
2185
2186 #ifdef CONFIG_DUALMAC_CONCURRENT
2187         dc_resume_xmit(adapter);
2188 #endif
2189
2190 _func_exit_;
2191 }
2192
2193 #if 0
2194 //#if (RATE_ADAPTIVE_SUPPORT==1)        //for 88E RA            
2195 u8 search_max_mac_id(_adapter *padapter)
2196 {
2197         u8 mac_id, aid;
2198         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
2199         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
2200         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
2201         struct sta_priv *pstapriv = &padapter->stapriv;
2202
2203 #if defined (CONFIG_AP_MODE) && defined (CONFIG_NATIVEAP_MLME)  
2204         if(check_fwstate(pmlmepriv, WIFI_AP_STATE)){            
2205                 
2206 #if 1
2207                 _irqL irqL;
2208                 struct dvobj_priv *pdvobj = adapter_to_dvobj(padapter);
2209
2210                 _enter_critical_bh(&pdvobj->lock, &irqL);
2211                 for(mac_id=(NUM_STA-1); mac_id>0; mac_id--)
2212                         if(pdvobj->macid[mac_id] == _TRUE)
2213                                 break;
2214                 _exit_critical_bh(&pdvobj->lock, &irqL);
2215
2216 #else
2217                 for (aid = (pstapriv->max_num_sta); aid > 0; aid--)
2218                 {
2219                         if (pstapriv->sta_aid[aid-1] != NULL)
2220                         {
2221                                 psta = pstapriv->sta_aid[aid-1];
2222                                 break;
2223                         }       
2224                 }
2225 /*
2226                 for (mac_id = (pstapriv->max_num_sta-1); mac_id >= 0; mac_id--)
2227                 {
2228                         if (pstapriv->sta_aid[mac_id] != NULL)
2229                                 break;
2230                 }       
2231 */
2232                 mac_id = aid + 1;
2233 #endif
2234         }
2235         else
2236 #endif
2237         {//adhoc  id =  31~2
2238                 for (mac_id = (NUM_STA-1); mac_id >= IBSS_START_MAC_ID ; mac_id--)
2239                 {
2240                         if (pmlmeinfo->FW_sta_info[mac_id].status == 1)
2241                         {
2242                                 break;
2243                         }
2244                 }
2245         }
2246
2247         DBG_871X("max mac_id=%d\n", mac_id);
2248
2249         return mac_id;
2250
2251 }               
2252 #endif  
2253
2254 //FOR STA, AP ,AD-HOC mode
2255 void rtw_sta_media_status_rpt(_adapter *adapter,struct sta_info *psta, u32 mstatus)
2256 {
2257         u16 media_status_rpt;
2258
2259         if(psta==NULL)  return;
2260
2261         #if (RATE_ADAPTIVE_SUPPORT==1)  //for 88E RA    
2262         {
2263                 u8 macid = rtw_search_max_mac_id(adapter);                              
2264                 rtw_hal_set_hwreg(adapter,HW_VAR_TX_RPT_MAX_MACID, (u8*)&macid);
2265         }
2266         #endif
2267         media_status_rpt = (u16)((psta->mac_id<<8)|mstatus); //  MACID|OPMODE:1 connect                         
2268         rtw_hal_set_hwreg(adapter,HW_VAR_H2C_MEDIA_STATUS_RPT,(u8 *)&media_status_rpt);                 
2269 }
2270
2271 void rtw_stassoc_event_callback(_adapter *adapter, u8 *pbuf)
2272 {
2273         _irqL irqL;     
2274         struct sta_info *psta;
2275         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
2276         struct stassoc_event    *pstassoc       = (struct stassoc_event*)pbuf;
2277         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
2278         struct wlan_network     *ptarget_wlan = NULL;
2279         
2280 _func_enter_;   
2281         
2282         if(rtw_access_ctrl(adapter, pstassoc->macaddr) == _FALSE)
2283                 return;
2284
2285 #if defined (CONFIG_AP_MODE) && defined (CONFIG_NATIVEAP_MLME)
2286         if(check_fwstate(pmlmepriv, WIFI_AP_STATE))
2287         {
2288                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);   
2289                 if(psta)
2290                 {               
2291                         u8 *passoc_req = NULL;
2292                         u32 assoc_req_len = 0;
2293                 
2294                         rtw_sta_media_status_rpt(adapter, psta, 1);
2295                 
2296 #ifndef CONFIG_AUTO_AP_MODE
2297
2298                         ap_sta_info_defer_update(adapter, psta);
2299
2300                         //report to upper layer 
2301                         DBG_871X("indicate_sta_assoc_event to upper layer - hostapd\n");
2302 #ifdef CONFIG_IOCTL_CFG80211
2303                         _enter_critical_bh(&psta->lock, &irqL);
2304                         if(psta->passoc_req && psta->assoc_req_len>0)
2305                         {                               
2306                                 passoc_req = rtw_zmalloc(psta->assoc_req_len);
2307                                 if(passoc_req)
2308                                 {
2309                                         assoc_req_len = psta->assoc_req_len;
2310                                         _rtw_memcpy(passoc_req, psta->passoc_req, assoc_req_len);
2311                                         
2312                                         rtw_mfree(psta->passoc_req , psta->assoc_req_len);
2313                                         psta->passoc_req = NULL;
2314                                         psta->assoc_req_len = 0;
2315                                 }
2316                         }                       
2317                         _exit_critical_bh(&psta->lock, &irqL);
2318
2319                         if(passoc_req && assoc_req_len>0)
2320                         {
2321                                 rtw_cfg80211_indicate_sta_assoc(adapter, passoc_req, assoc_req_len);
2322
2323                                 rtw_mfree(passoc_req, assoc_req_len);
2324                         }                       
2325 #else //!CONFIG_IOCTL_CFG80211  
2326                         rtw_indicate_sta_assoc_event(adapter, psta);
2327 #endif //!CONFIG_IOCTL_CFG80211
2328 #endif //!CONFIG_AUTO_AP_MODE
2329
2330 #ifdef CONFIG_BEAMFORMING
2331                         beamforming_wk_cmd(adapter, BEAMFORMING_CTRL_ENTER, (u8 *)psta, sizeof(struct sta_info), 0);
2332 #endif
2333                 }               
2334                 goto exit;
2335         }       
2336 #endif //defined (CONFIG_AP_MODE) && defined (CONFIG_NATIVEAP_MLME)
2337
2338         //for AD-HOC mode
2339         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);   
2340         if( psta != NULL)
2341         {
2342                 //the sta have been in sta_info_queue => do nothing 
2343                 
2344                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue \n"));
2345                 
2346                 goto exit; //(between drv has received this event before and  fw have not yet to set key to CAM_ENTRY)
2347         }
2348
2349         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr); 
2350         if (psta == NULL) {
2351                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
2352                 goto exit;
2353         }       
2354         
2355         //to do : init sta_info variable
2356         psta->qos_option = 0;
2357         psta->mac_id = (uint)pstassoc->cam_id;
2358         //psta->aid = (uint)pstassoc->cam_id;
2359         DBG_871X("%s\n",__FUNCTION__);
2360         //for ad-hoc mode
2361         rtw_hal_set_odm_var(adapter,HAL_ODM_STA_INFO,psta,_TRUE);
2362
2363         rtw_sta_media_status_rpt(adapter, psta, 1);
2364         
2365         if(adapter->securitypriv.dot11AuthAlgrthm==dot11AuthAlgrthm_8021X)
2366                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
2367         
2368
2369         psta->ieee8021x_blocked = _FALSE;               
2370         
2371         _enter_critical_bh(&pmlmepriv->lock, &irqL);
2372
2373         if ( (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)==_TRUE ) || 
2374                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)==_TRUE ) )
2375         {
2376                 if(adapter->stapriv.asoc_sta_count== 2)
2377                 {
2378                         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2379                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
2380                         pmlmepriv->cur_network_scanned = ptarget_wlan;
2381                         if(ptarget_wlan)        ptarget_wlan->fixed = _TRUE;
2382                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2383                         // a sta + bc/mc_stainfo (not Ibss_stainfo)
2384                         rtw_indicate_connect(adapter);
2385                 }
2386         }
2387
2388         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2389
2390
2391         mlmeext_sta_add_event_callback(adapter, psta);
2392         
2393 #ifdef CONFIG_RTL8711
2394         //submit SetStaKey_cmd to tell fw, fw will allocate an CAM entry for this sta   
2395         rtw_setstakey_cmd(adapter, psta, _FALSE, _TRUE);
2396 #endif
2397                 
2398 exit:
2399         
2400 _func_exit_;    
2401
2402 }
2403
2404 void rtw_stadel_event_callback(_adapter *adapter, u8 *pbuf)
2405 {
2406         _irqL irqL,irqL2;
2407         int mac_id = (-1);
2408         struct sta_info *psta;
2409         struct wlan_network* pwlan = NULL;
2410         WLAN_BSSID_EX    *pdev_network=NULL;
2411         u8* pibss = NULL;
2412         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
2413         struct  stadel_event *pstadel   = (struct stadel_event*)pbuf;
2414         struct  sta_priv *pstapriv = &adapter->stapriv;
2415         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
2416         struct mlme_ext_priv    *pmlmeext = &adapter->mlmeextpriv;
2417         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
2418         
2419 _func_enter_;   
2420         
2421         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
2422         if(psta)
2423                 mac_id = psta->mac_id;
2424         else
2425                 mac_id = pstadel->mac_id;
2426
2427         DBG_871X("%s(mac_id=%d)=" MAC_FMT "\n", __func__, mac_id, MAC_ARG(pstadel->macaddr));
2428
2429         if(mac_id>=0){
2430                 u16 media_status;
2431                 media_status = (mac_id<<8)|0; //  MACID|OPMODE:0 means disconnect
2432                 //for STA,AP,ADHOC mode, report disconnect stauts to FW
2433                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
2434         }       
2435
2436         //if(check_fwstate(pmlmepriv, WIFI_AP_STATE))
2437         if((pmlmeinfo->state&0x03) == WIFI_FW_AP_STATE)
2438         {
2439 #ifdef CONFIG_IOCTL_CFG80211
2440                 #ifdef COMPAT_KERNEL_RELEASE
2441
2442                 #elif (LINUX_VERSION_CODE < KERNEL_VERSION(2,6,37)) || defined(CONFIG_CFG80211_FORCE_COMPATIBLE_2_6_37_UNDER)
2443                 rtw_cfg80211_indicate_sta_disassoc(adapter, pstadel->macaddr, *(u16*)pstadel->rsvd);
2444                 #endif //(LINUX_VERSION_CODE < KERNEL_VERSION(2,6,37)) || defined(CONFIG_CFG80211_FORCE_COMPATIBLE_2_6_37_UNDER)
2445 #endif //CONFIG_IOCTL_CFG80211
2446
2447                 return;
2448         }
2449
2450
2451         mlmeext_sta_del_event_callback(adapter);
2452
2453         _enter_critical_bh(&pmlmepriv->lock, &irqL2);
2454
2455         if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) )
2456         {
2457                 u16 reason = *((unsigned short *)(pstadel->rsvd));
2458                 bool roam = _FALSE;
2459                 struct wlan_network *roam_target = NULL;
2460
2461                 #ifdef CONFIG_LAYER2_ROAMING
2462                 if(adapter->registrypriv.wifi_spec==1) {
2463                         roam = _FALSE;
2464                 } else if (reason == WLAN_REASON_EXPIRATION_CHK && rtw_chk_roam_flags(adapter, RTW_ROAM_ON_EXPIRED)) {
2465                         roam = _TRUE;
2466                 } else if (reason == WLAN_REASON_ACTIVE_ROAM && rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
2467                         roam = _TRUE;
2468                         roam_target = pmlmepriv->roam_network;
2469                 }
2470 #ifdef CONFIG_INTEL_WIDI
2471                 else if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_CONNECTED) {
2472                         roam = _TRUE;
2473                 }
2474 #endif // CONFIG_INTEL_WIDI
2475
2476                 if (roam == _TRUE) {
2477                         if (rtw_to_roam(adapter) > 0)
2478                                 rtw_dec_to_roam(adapter); /* this stadel_event is caused by roaming, decrease to_roam */
2479                         else if (rtw_to_roam(adapter) == 0)
2480                                 rtw_set_to_roam(adapter, adapter->registrypriv.max_roaming_times);
2481                 } else {
2482                         rtw_set_to_roam(adapter, 0);
2483                 }
2484                 #endif /* CONFIG_LAYER2_ROAMING */
2485
2486                 rtw_free_uc_swdec_pending_queue(adapter);
2487
2488                 rtw_free_assoc_resources(adapter, 1);
2489                 rtw_indicate_disconnect(adapter);
2490
2491                 _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2492                 // remove the network entry in scanned_queue
2493                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);   
2494                 if (pwlan) {                    
2495                         pwlan->fixed = _FALSE;
2496                         rtw_free_network_nolock(adapter, pwlan);
2497                 }
2498                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2499
2500 #ifdef CONFIG_INTEL_WIDI
2501                 if (!rtw_to_roam(adapter))
2502                         process_intel_widi_disconnect(adapter, 1);
2503 #endif // CONFIG_INTEL_WIDI
2504
2505                 _rtw_roaming(adapter, roam_target);
2506         }
2507
2508         if ( check_fwstate(pmlmepriv,WIFI_ADHOC_MASTER_STATE) || 
2509               check_fwstate(pmlmepriv,WIFI_ADHOC_STATE))
2510         {
2511                 
2512                 _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
2513                 rtw_free_stainfo(adapter,  psta);
2514                 _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
2515                 
2516                 if(adapter->stapriv.asoc_sta_count== 1) //a sta + bc/mc_stainfo (not Ibss_stainfo)
2517                 { 
2518                         //rtw_indicate_disconnect(adapter);//removed@20091105
2519                         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2520                         //free old ibss network
2521                         //pwlan = rtw_find_network(&pmlmepriv->scanned_queue, pstadel->macaddr);
2522                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
2523                         if(pwlan)       
2524                         {
2525                                 pwlan->fixed = _FALSE;
2526                                 rtw_free_network_nolock(adapter, pwlan); 
2527                         }
2528                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2529                         //re-create ibss
2530                         pdev_network = &(adapter->registrypriv.dev_network);                    
2531                         pibss = adapter->registrypriv.dev_network.MacAddress;
2532
2533                         _rtw_memcpy(pdev_network, &tgt_network->network, get_WLAN_BSSID_EX_sz(&tgt_network->network));
2534                         
2535                         _rtw_memset(&pdev_network->Ssid, 0, sizeof(NDIS_802_11_SSID));
2536                         _rtw_memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(NDIS_802_11_SSID));
2537         
2538                         rtw_update_registrypriv_dev_network(adapter);                   
2539
2540                         rtw_generate_random_ibss(pibss);
2541                         
2542                         if(check_fwstate(pmlmepriv,WIFI_ADHOC_STATE))
2543                         {
2544                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
2545                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
2546                         }
2547
2548                         if(rtw_createbss_cmd(adapter)!=_SUCCESS)
2549                         {
2550
2551                                 RT_TRACE(_module_rtl871x_ioctl_set_c_,_drv_err_,("***Error=>stadel_event_callback: rtw_createbss_cmd status FAIL*** \n "));                                                                             
2552
2553                         }
2554
2555                         
2556                 }
2557                 
2558         }
2559         
2560         _exit_critical_bh(&pmlmepriv->lock, &irqL2);
2561         
2562 _func_exit_;    
2563
2564 }
2565
2566
2567 void rtw_cpwm_event_callback(PADAPTER padapter, u8 *pbuf)
2568 {
2569 #ifdef CONFIG_LPS_LCLK
2570         struct reportpwrstate_parm *preportpwrstate;
2571 #endif
2572
2573 _func_enter_;
2574
2575         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("+rtw_cpwm_event_callback !!!\n"));
2576 #ifdef CONFIG_LPS_LCLK
2577         preportpwrstate = (struct reportpwrstate_parm*)pbuf;
2578         preportpwrstate->state |= (u8)(adapter_to_pwrctl(padapter)->cpwm_tog + 0x80);
2579         cpwm_int_hdl(padapter, preportpwrstate);
2580 #endif
2581
2582 _func_exit_;
2583
2584 }
2585
2586
2587 void rtw_wmm_event_callback(PADAPTER padapter, u8 *pbuf)
2588 {
2589 _func_enter_;
2590
2591         WMMOnAssocRsp(padapter);
2592
2593 _func_exit_;
2594
2595 }
2596
2597 /*
2598 * _rtw_join_timeout_handler - Timeout/faliure handler for CMD JoinBss
2599 * @adapter: pointer to _adapter structure
2600 */
2601 void _rtw_join_timeout_handler (_adapter *adapter)
2602 {
2603         _irqL irqL;
2604         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
2605
2606 #if 0
2607         if (adapter->bDriverStopped == _TRUE){
2608                 _rtw_up_sema(&pmlmepriv->assoc_terminate);
2609                 return;
2610         }
2611 #endif  
2612
2613 _func_enter_;           
2614
2615
2616         DBG_871X("%s, fw_state=%x\n", __FUNCTION__, get_fwstate(pmlmepriv));
2617         
2618         if(adapter->bDriverStopped ||adapter->bSurpriseRemoved)
2619                 return;
2620
2621         
2622         _enter_critical_bh(&pmlmepriv->lock, &irqL);
2623
2624         #ifdef CONFIG_LAYER2_ROAMING
2625         if (rtw_to_roam(adapter) > 0) { /* join timeout caused by roaming */
2626                 while(1) {
2627                         rtw_dec_to_roam(adapter);
2628                         if (rtw_to_roam(adapter) != 0) { /* try another */
2629                                 int do_join_r;
2630                                 DBG_871X("%s try another roaming\n", __FUNCTION__);
2631                                 if( _SUCCESS!=(do_join_r=rtw_do_join(adapter)) ) {
2632                                         DBG_871X("%s roaming do_join return %d\n", __FUNCTION__ ,do_join_r);
2633                                         continue;
2634                                 }
2635                                 break;
2636                         } else {
2637 #ifdef CONFIG_INTEL_WIDI
2638                                 if(adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING)
2639                                 {
2640                                         _rtw_memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
2641                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
2642                                         DBG_871X("change to widi listen\n");
2643                                 }
2644 #endif // CONFIG_INTEL_WIDI
2645                                 DBG_871X("%s We've try roaming but fail\n", __FUNCTION__);
2646                                 rtw_indicate_disconnect(adapter);
2647                                 break;
2648                         }
2649                 }
2650                 
2651         } else 
2652         #endif
2653         {
2654                 rtw_indicate_disconnect(adapter);
2655                 free_scanqueue(pmlmepriv);//???
2656
2657 #ifdef CONFIG_IOCTL_CFG80211
2658                 //indicate disconnect for the case that join_timeout and check_fwstate != FW_LINKED
2659                 rtw_cfg80211_indicate_disconnect(adapter);
2660 #endif //CONFIG_IOCTL_CFG80211
2661
2662         }
2663
2664         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2665         
2666
2667 #ifdef CONFIG_DRVEXT_MODULE_WSC 
2668         drvext_assoc_fail_indicate(&adapter->drvextpriv);       
2669 #endif  
2670
2671         
2672 _func_exit_;
2673
2674 }
2675
2676 /*
2677 * rtw_scan_timeout_handler - Timeout/Faliure handler for CMD SiteSurvey
2678 * @adapter: pointer to _adapter structure
2679 */
2680 void rtw_scan_timeout_handler (_adapter *adapter)
2681 {       
2682         _irqL irqL;
2683         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
2684         
2685         DBG_871X(FUNC_ADPT_FMT" fw_state=%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
2686
2687         _enter_critical_bh(&pmlmepriv->lock, &irqL);
2688         
2689         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
2690
2691         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2692
2693         rtw_indicate_scan_done(adapter, _TRUE);
2694
2695 #if defined(CONFIG_CONCURRENT_MODE) && defined(CONFIG_IOCTL_CFG80211)
2696         if (adapter->pbuddy_adapter) {
2697                 _adapter *buddy_adapter = adapter->pbuddy_adapter;
2698                 struct mlme_priv *buddy_mlme = &(buddy_adapter->mlmepriv);
2699                 struct rtw_wdev_priv *buddy_wdev_priv = adapter_wdev_data(buddy_adapter);
2700                 bool indicate_buddy_scan = _FALSE;
2701
2702                 _enter_critical_bh(&buddy_wdev_priv->scan_req_lock, &irqL);
2703                 if (buddy_wdev_priv->scan_request && buddy_mlme->scanning_via_buddy_intf == _TRUE) {
2704                         buddy_mlme->scanning_via_buddy_intf = _FALSE;
2705                         clr_fwstate(buddy_mlme, _FW_UNDER_SURVEY);
2706                         indicate_buddy_scan = _TRUE;
2707                 }
2708                 _exit_critical_bh(&buddy_wdev_priv->scan_req_lock, &irqL);
2709
2710                 if (indicate_buddy_scan == _TRUE) {
2711                         rtw_indicate_scan_done(buddy_adapter, _TRUE);
2712                 }
2713         }
2714 #endif /* CONFIG_CONCURRENT_MODE */
2715 }
2716
2717 void rtw_mlme_reset_auto_scan_int(_adapter *adapter)
2718 {
2719         struct mlme_priv *mlme = &adapter->mlmepriv;
2720         struct mlme_ext_priv    *pmlmeext = &adapter->mlmeextpriv;
2721         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
2722
2723 #ifdef CONFIG_P2P
2724         if(!rtw_p2p_chk_state(&adapter->wdinfo, P2P_STATE_NONE)) {
2725                 mlme->auto_scan_int_ms = 0; /* disabled */
2726                 goto exit;
2727         }
2728 #endif  
2729         if(pmlmeinfo->VHT_enable) //disable auto scan when connect to 11AC AP
2730         {
2731                 mlme->auto_scan_int_ms = 0;
2732         }
2733         else if(adapter->registrypriv.wifi_spec && is_client_associated_to_ap(adapter) == _TRUE) {
2734                 mlme->auto_scan_int_ms = 60*1000;
2735 #ifdef CONFIG_LAYER2_ROAMING
2736         } else if(rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
2737                 if (check_fwstate(mlme, WIFI_STATION_STATE) && check_fwstate(mlme, _FW_LINKED))
2738                         mlme->auto_scan_int_ms = mlme->roam_scan_int_ms;
2739 #endif
2740         } else {
2741                 mlme->auto_scan_int_ms = 0; /* disabled */
2742         }
2743 exit:
2744         return;
2745 }
2746
2747 static void rtw_auto_scan_handler(_adapter *padapter)
2748 {
2749         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2750
2751         rtw_mlme_reset_auto_scan_int(padapter);
2752
2753         if (pmlmepriv->auto_scan_int_ms != 0
2754                 && rtw_get_passing_time_ms(pmlmepriv->scan_start_time) > pmlmepriv->auto_scan_int_ms) {
2755
2756                 if (!padapter->registrypriv.wifi_spec) {
2757                         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE) 
2758                         {
2759                                 DBG_871X(FUNC_ADPT_FMT" _FW_UNDER_SURVEY|_FW_UNDER_LINKING\n", FUNC_ADPT_ARG(padapter));
2760                                 goto exit;
2761                         }
2762                         
2763                         if(pmlmepriv->LinkDetectInfo.bBusyTraffic == _TRUE)
2764                         {
2765                                 DBG_871X(FUNC_ADPT_FMT" exit BusyTraffic\n", FUNC_ADPT_ARG(padapter));
2766                                 goto exit;
2767                         }
2768                 }
2769
2770 #ifdef CONFIG_CONCURRENT_MODE
2771                 if (rtw_buddy_adapter_up(padapter))
2772                 {
2773                         if ((check_buddy_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE) ||
2774                                 (padapter->pbuddy_adapter->mlmepriv.LinkDetectInfo.bBusyTraffic == _TRUE))
2775                         {               
2776                                 DBG_871X(FUNC_ADPT_FMT", but buddy_intf is under scanning or linking or BusyTraffic\n"
2777                                         , FUNC_ADPT_ARG(padapter));
2778                                 goto exit;
2779                         }
2780                 }
2781 #endif
2782
2783                 DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
2784
2785                 rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
2786         }
2787
2788 exit:
2789         return;
2790 }
2791
2792 void rtw_dynamic_check_timer_handlder(_adapter *adapter)
2793 {
2794 #ifdef CONFIG_AP_MODE
2795         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
2796 #endif //CONFIG_AP_MODE
2797         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2798 #ifdef CONFIG_CONCURRENT_MODE   
2799         PADAPTER pbuddy_adapter = adapter->pbuddy_adapter;
2800 #endif
2801
2802         if(!adapter)
2803                 return; 
2804
2805         if(adapter->hw_init_completed == _FALSE)
2806                 return;
2807
2808         if ((adapter->bDriverStopped == _TRUE)||(adapter->bSurpriseRemoved== _TRUE))
2809                 return;
2810
2811         
2812 #ifdef CONFIG_CONCURRENT_MODE
2813         if(pbuddy_adapter)
2814         {
2815                 if(adapter->net_closed == _TRUE && pbuddy_adapter->net_closed == _TRUE)
2816                 {
2817                         return;
2818                 }               
2819         }
2820         else
2821 #endif //CONFIG_CONCURRENT_MODE
2822         if(adapter->net_closed == _TRUE)
2823         {
2824                 return;
2825         }       
2826
2827 #ifdef CONFIG_BT_COEXIST
2828         if(is_primary_adapter(adapter))
2829                 DBG_871X("IsBtDisabled=%d, IsBtControlLps=%d\n", rtw_btcoex_IsBtDisabled(adapter), rtw_btcoex_IsBtControlLps(adapter));
2830 #endif
2831
2832 #ifdef CONFIG_LPS_LCLK_WD_TIMER
2833         if ((adapter_to_pwrctl(adapter)->bFwCurrentInPSMode ==_TRUE )
2834 #ifdef CONFIG_BT_COEXIST
2835                 && (rtw_btcoex_IsBtControlLps(adapter) == _FALSE)
2836 #endif          
2837                 ) 
2838         {
2839                 u8 bEnterPS;    
2840                 
2841                 linked_status_chk(adapter);     
2842                         
2843                 bEnterPS = traffic_status_watchdog(adapter, 1);
2844                 if(bEnterPS)
2845                 {
2846                         //rtw_lps_ctrl_wk_cmd(adapter, LPS_CTRL_ENTER, 1);
2847                         rtw_hal_dm_watchdog_in_lps(adapter);
2848                 }
2849                 else
2850                 {
2851                         //call rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_LEAVE, 1) in traffic_status_watchdog()
2852                 }
2853                         
2854         }
2855         else
2856 #endif //CONFIG_LPS_LCLK_WD_TIMER       
2857         {
2858                 if(is_primary_adapter(adapter))
2859                 {       
2860                         rtw_dynamic_chk_wk_cmd(adapter);                
2861                 }       
2862         }       
2863
2864         /* auto site survey */
2865         rtw_auto_scan_handler(adapter);
2866
2867 #ifndef CONFIG_ACTIVE_KEEP_ALIVE_CHECK
2868 #ifdef CONFIG_AP_MODE
2869         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) == _TRUE)
2870         {
2871                 expire_timeout_chk(adapter);
2872         }       
2873 #endif
2874 #endif //!CONFIG_ACTIVE_KEEP_ALIVE_CHECK
2875
2876 #ifdef CONFIG_BR_EXT
2877
2878 #if (LINUX_VERSION_CODE > KERNEL_VERSION(2, 6, 35))
2879         rcu_read_lock();
2880 #endif  // (LINUX_VERSION_CODE > KERNEL_VERSION(2, 6, 35))
2881
2882 #if (LINUX_VERSION_CODE <= KERNEL_VERSION(2, 6, 35)) 
2883         if( adapter->pnetdev->br_port 
2884 #else   // (LINUX_VERSION_CODE <= KERNEL_VERSION(2, 6, 35))
2885         if( rcu_dereference(adapter->pnetdev->rx_handler_data)
2886 #endif  // (LINUX_VERSION_CODE <= KERNEL_VERSION(2, 6, 35))
2887                 && (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_ADHOC_STATE) == _TRUE) )
2888         {
2889                 // expire NAT2.5 entry
2890                 void nat25_db_expire(_adapter *priv);
2891                 nat25_db_expire(adapter);
2892
2893                 if (adapter->pppoe_connection_in_progress > 0) {
2894                         adapter->pppoe_connection_in_progress--;
2895                 }
2896                 
2897                 // due to rtw_dynamic_check_timer_handlder() is called every 2 seconds
2898                 if (adapter->pppoe_connection_in_progress > 0) {
2899                         adapter->pppoe_connection_in_progress--;
2900                 }
2901         }
2902
2903 #if (LINUX_VERSION_CODE > KERNEL_VERSION(2, 6, 35))
2904         rcu_read_unlock();
2905 #endif  // (LINUX_VERSION_CODE > KERNEL_VERSION(2, 6, 35))
2906
2907 #endif  // CONFIG_BR_EXT
2908         
2909 }
2910
2911
2912 #ifdef CONFIG_SET_SCAN_DENY_TIMER
2913 inline bool rtw_is_scan_deny(_adapter *adapter)
2914 {
2915         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2916         return (ATOMIC_READ(&mlmepriv->set_scan_deny) != 0) ? _TRUE : _FALSE;
2917 }
2918
2919 inline void rtw_clear_scan_deny(_adapter *adapter)
2920 {
2921         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2922         ATOMIC_SET(&mlmepriv->set_scan_deny, 0);
2923         if (0)
2924         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
2925 }
2926
2927 void rtw_set_scan_deny_timer_hdl(_adapter *adapter)
2928 {
2929         rtw_clear_scan_deny(adapter);
2930 }
2931
2932 void rtw_set_scan_deny(_adapter *adapter, u32 ms)
2933 {
2934         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2935 #ifdef CONFIG_CONCURRENT_MODE
2936         struct mlme_priv *b_mlmepriv;
2937 #endif
2938
2939         if (0)
2940         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
2941         ATOMIC_SET(&mlmepriv->set_scan_deny, 1);
2942         _set_timer(&mlmepriv->set_scan_deny_timer, ms);
2943         
2944 #ifdef CONFIG_CONCURRENT_MODE
2945         if (!adapter->pbuddy_adapter)
2946                 return;
2947
2948         if (0)
2949         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter->pbuddy_adapter));
2950         b_mlmepriv = &adapter->pbuddy_adapter->mlmepriv;
2951         ATOMIC_SET(&b_mlmepriv->set_scan_deny, 1);
2952         _set_timer(&b_mlmepriv->set_scan_deny_timer, ms);       
2953 #endif
2954         
2955 }
2956 #endif
2957
2958 #ifdef CONFIG_LAYER2_ROAMING
2959 /*
2960 * Select a new roaming candidate from the original @param candidate and @param competitor
2961 * @return _TRUE: candidate is updated
2962 * @return _FALSE: candidate is not updated
2963 */
2964 static int rtw_check_roaming_candidate(struct mlme_priv *mlme
2965         , struct wlan_network **candidate, struct wlan_network *competitor)
2966 {
2967         int updated = _FALSE;
2968         _adapter *adapter = container_of(mlme, _adapter, mlmepriv);
2969
2970         if(is_same_ess(&competitor->network, &mlme->cur_network.network) == _FALSE)
2971                 goto exit;
2972
2973         if(rtw_is_desired_network(adapter, competitor) == _FALSE)
2974                 goto exit;
2975
2976         DBG_871X("roam candidate:%s %s("MAC_FMT", ch%3u) rssi:%d, age:%5d\n",
2977                 (competitor == mlme->cur_network_scanned)?"*":" " ,
2978                 competitor->network.Ssid.Ssid,
2979                 MAC_ARG(competitor->network.MacAddress),
2980                 competitor->network.Configuration.DSConfig,
2981                 (int)competitor->network.Rssi,
2982                 rtw_get_passing_time_ms(competitor->last_scanned)
2983         );
2984
2985         /* got specific addr to roam */
2986         if (!is_zero_mac_addr(mlme->roam_tgt_addr)) {
2987                 if(_rtw_memcmp(mlme->roam_tgt_addr, competitor->network.MacAddress, ETH_ALEN) == _TRUE)
2988                         goto update;
2989                 else
2990                         goto exit;
2991         }
2992         #if 1
2993         if(rtw_get_passing_time_ms((u32)competitor->last_scanned) >= mlme->roam_scanr_exp_ms)
2994                 goto exit;
2995
2996         if (competitor->network.Rssi - mlme->cur_network_scanned->network.Rssi < mlme->roam_rssi_diff_th)
2997                 goto exit;
2998
2999         if(*candidate != NULL && (*candidate)->network.Rssi>=competitor->network.Rssi)
3000                 goto exit;
3001         #else
3002         goto exit;
3003         #endif
3004
3005 update:
3006         *candidate = competitor;
3007         updated = _TRUE;
3008
3009 exit:
3010         return updated;
3011 }
3012
3013 int rtw_select_roaming_candidate(struct mlme_priv *mlme)
3014 {
3015         _irqL   irqL;
3016         int ret = _FAIL;
3017         _list   *phead;
3018         _adapter *adapter;      
3019         _queue  *queue  = &(mlme->scanned_queue);
3020         struct  wlan_network    *pnetwork = NULL;
3021         struct  wlan_network    *candidate = NULL;
3022         u8              bSupportAntDiv = _FALSE;
3023
3024 _func_enter_;
3025
3026         if (mlme->cur_network_scanned == NULL) {
3027                 rtw_warn_on(1);
3028                 goto exit;
3029         }
3030
3031         _enter_critical_bh(&(mlme->scanned_queue.lock), &irqL);
3032         phead = get_list_head(queue);           
3033         adapter = (_adapter *)mlme->nic_hdl;
3034
3035         mlme->pscanned = get_next(phead);
3036
3037         while (!rtw_end_of_queue_search(phead, mlme->pscanned)) {
3038
3039                 pnetwork = LIST_CONTAINOR(mlme->pscanned, struct wlan_network, list);
3040                 if(pnetwork==NULL){
3041                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("%s return _FAIL:(pnetwork==NULL)\n", __FUNCTION__));
3042                         ret = _FAIL;
3043                         goto exit;
3044                 }
3045                 
3046                 mlme->pscanned = get_next(mlme->pscanned);
3047
3048                 if (0)
3049                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
3050                         , pnetwork->network.Ssid.Ssid
3051                         , MAC_ARG(pnetwork->network.MacAddress)
3052                         , pnetwork->network.Configuration.DSConfig
3053                         , (int)pnetwork->network.Rssi);
3054
3055                 rtw_check_roaming_candidate(mlme, &candidate, pnetwork);
3056  
3057         }
3058
3059         if(candidate == NULL) {
3060                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __FUNCTION__);
3061                 ret = _FAIL;
3062                 goto exit;
3063         } else {
3064                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __FUNCTION__,
3065                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
3066                         candidate->network.Configuration.DSConfig);
3067
3068                 mlme->roam_network = candidate;
3069
3070                 if (_rtw_memcmp(candidate->network.MacAddress, mlme->roam_tgt_addr, ETH_ALEN) == _TRUE)
3071                         _rtw_memset(mlme->roam_tgt_addr,0, ETH_ALEN);
3072         }
3073
3074         ret = _SUCCESS;
3075 exit:
3076         _exit_critical_bh(&(mlme->scanned_queue.lock), &irqL);
3077
3078         return ret;
3079 }
3080 #endif /* CONFIG_LAYER2_ROAMING */
3081
3082 /*
3083 * Select a new join candidate from the original @param candidate and @param competitor
3084 * @return _TRUE: candidate is updated
3085 * @return _FALSE: candidate is not updated
3086 */
3087 static int rtw_check_join_candidate(struct mlme_priv *mlme
3088         , struct wlan_network **candidate, struct wlan_network *competitor)
3089 {
3090         int updated = _FALSE;
3091         _adapter *adapter = container_of(mlme, _adapter, mlmepriv);
3092
3093
3094         //check bssid, if needed
3095         if(mlme->assoc_by_bssid==_TRUE) {
3096                 if(_rtw_memcmp(competitor->network.MacAddress, mlme->assoc_bssid, ETH_ALEN) ==_FALSE)
3097                         goto exit;
3098         }
3099
3100         //check ssid, if needed
3101         if(mlme->assoc_ssid.Ssid[0] && mlme->assoc_ssid.SsidLength) {
3102                 if(     competitor->network.Ssid.SsidLength != mlme->assoc_ssid.SsidLength
3103                         || _rtw_memcmp(competitor->network.Ssid.Ssid, mlme->assoc_ssid.Ssid, mlme->assoc_ssid.SsidLength) == _FALSE
3104                 )
3105                         goto exit;
3106         }
3107
3108         if(rtw_is_desired_network(adapter, competitor)  == _FALSE)
3109                 goto exit;
3110
3111 #ifdef  CONFIG_LAYER2_ROAMING
3112         if(rtw_to_roam(adapter) > 0) {
3113                 if(     rtw_get_passing_time_ms((u32)competitor->last_scanned) >= mlme->roam_scanr_exp_ms
3114                         || is_same_ess(&competitor->network, &mlme->cur_network.network) == _FALSE
3115                 )
3116                         goto exit;
3117         }
3118 #endif
3119         
3120         if(*candidate == NULL ||(*candidate)->network.Rssi<competitor->network.Rssi )
3121         {
3122                 *candidate = competitor;
3123                 updated = _TRUE;
3124         }
3125
3126         if(updated){
3127                 DBG_871X("[by_bssid:%u][assoc_ssid:%s]"
3128                         #ifdef  CONFIG_LAYER2_ROAMING
3129                         "[to_roam:%u] "
3130                         #endif
3131                         "new candidate: %s("MAC_FMT", ch%u) rssi:%d\n",
3132                         mlme->assoc_by_bssid,
3133                         mlme->assoc_ssid.Ssid,
3134                         #ifdef  CONFIG_LAYER2_ROAMING
3135                         rtw_to_roam(adapter),
3136                         #endif
3137                         (*candidate)->network.Ssid.Ssid,
3138                         MAC_ARG((*candidate)->network.MacAddress),
3139                         (*candidate)->network.Configuration.DSConfig,
3140                         (int)(*candidate)->network.Rssi
3141                 );
3142         }
3143
3144 exit:
3145         return updated;
3146 }
3147
3148 /*
3149 Calling context:
3150 The caller of the sub-routine will be in critical section...
3151
3152 The caller must hold the following spinlock
3153
3154 pmlmepriv->lock
3155
3156
3157 */
3158
3159 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv )
3160 {
3161         _irqL   irqL;
3162         int ret;
3163         _list   *phead;
3164         _adapter *adapter;      
3165         _queue  *queue  = &(pmlmepriv->scanned_queue);
3166         struct  wlan_network    *pnetwork = NULL;
3167         struct  wlan_network    *candidate = NULL;
3168         u8              bSupportAntDiv = _FALSE;
3169
3170 _func_enter_;
3171
3172         adapter = (_adapter *)pmlmepriv->nic_hdl;
3173
3174         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
3175
3176         #ifdef CONFIG_LAYER2_ROAMING
3177         if (pmlmepriv->roam_network) {
3178                 candidate = pmlmepriv->roam_network;
3179                 pmlmepriv->roam_network = NULL;
3180                 goto candidate_exist;
3181         }
3182         #endif
3183
3184         phead = get_list_head(queue);
3185         pmlmepriv->pscanned = get_next(phead);
3186
3187         while (!rtw_end_of_queue_search(phead, pmlmepriv->pscanned)) {
3188
3189                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
3190                 if(pnetwork==NULL){
3191                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("%s return _FAIL:(pnetwork==NULL)\n", __FUNCTION__));
3192                         ret = _FAIL;
3193                         goto exit;
3194                 }
3195                 
3196                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
3197
3198                 if (0)
3199                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
3200                         , pnetwork->network.Ssid.Ssid
3201                         , MAC_ARG(pnetwork->network.MacAddress)
3202                         , pnetwork->network.Configuration.DSConfig
3203                         , (int)pnetwork->network.Rssi);
3204
3205                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
3206  
3207         }
3208
3209         if(candidate == NULL) {
3210                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __FUNCTION__);
3211 #ifdef CONFIG_WOWLAN
3212                 _clr_fwstate_(pmlmepriv, _FW_LINKED|_FW_UNDER_LINKING);
3213 #endif
3214                 ret = _FAIL;
3215                 goto exit;
3216         } else {
3217                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __FUNCTION__,
3218                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
3219                         candidate->network.Configuration.DSConfig);
3220                 goto candidate_exist;
3221         }
3222         
3223 candidate_exist:
3224
3225         // check for situation of  _FW_LINKED 
3226         if (check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE)
3227         {
3228                 DBG_871X("%s: _FW_LINKED while ask_for_joinbss!!!\n", __FUNCTION__);
3229
3230                 #if 0 // for WPA/WPA2 authentication, wpa_supplicant will expect authentication from AP, it is needed to reconnect AP...
3231                 if(is_same_network(&pmlmepriv->cur_network.network, &candidate->network))
3232                 {
3233                         DBG_871X("%s: _FW_LINKED and is same network, it needn't join again\n", __FUNCTION__);
3234
3235                         rtw_indicate_connect(adapter);//rtw_indicate_connect again
3236                                 
3237                         ret = 2;
3238                         goto exit;
3239                 }
3240                 else
3241                 #endif
3242                 {
3243                         rtw_disassoc_cmd(adapter, 0, _TRUE);
3244                         rtw_indicate_disconnect(adapter);
3245                         rtw_free_assoc_resources(adapter, 0);
3246                 }
3247         }
3248         
3249         #ifdef CONFIG_ANTENNA_DIVERSITY
3250         rtw_hal_get_def_var(adapter, HAL_DEF_IS_SUPPORT_ANT_DIV, &(bSupportAntDiv));
3251         if(_TRUE == bSupportAntDiv)     
3252         {
3253                 u8 CurrentAntenna;
3254                 rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(CurrentAntenna));                       
3255                 DBG_871X("#### Opt_Ant_(%s) , cur_Ant(%s)\n",
3256                         (2==candidate->network.PhyInfo.Optimum_antenna)?"A":"B",
3257                         (2==CurrentAntenna)?"A":"B"
3258                 );
3259         }
3260         #endif
3261         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
3262         ret = rtw_joinbss_cmd(adapter, candidate);
3263         
3264 exit:
3265         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
3266
3267 _func_exit_;
3268
3269         return ret;
3270 }
3271
3272 sint rtw_set_auth(_adapter * adapter,struct security_priv *psecuritypriv)
3273 {
3274         struct  cmd_obj* pcmd;
3275         struct  setauth_parm *psetauthparm;
3276         struct  cmd_priv        *pcmdpriv=&(adapter->cmdpriv);
3277         sint            res=_SUCCESS;
3278         
3279 _func_enter_;   
3280
3281         pcmd = (struct  cmd_obj*)rtw_zmalloc(sizeof(struct      cmd_obj));
3282         if(pcmd==NULL){
3283                 res= _FAIL;  //try again
3284                 goto exit;
3285         }
3286         
3287         psetauthparm=(struct setauth_parm*)rtw_zmalloc(sizeof(struct setauth_parm));
3288         if(psetauthparm==NULL){
3289                 rtw_mfree((unsigned char *)pcmd, sizeof(struct  cmd_obj));
3290                 res= _FAIL;
3291                 goto exit;
3292         }
3293
3294         _rtw_memset(psetauthparm, 0, sizeof(struct setauth_parm));
3295         psetauthparm->mode=(unsigned char)psecuritypriv->dot11AuthAlgrthm;
3296         
3297         pcmd->cmdcode = _SetAuth_CMD_;
3298         pcmd->parmbuf = (unsigned char *)psetauthparm;   
3299         pcmd->cmdsz =  (sizeof(struct setauth_parm));  
3300         pcmd->rsp = NULL;
3301         pcmd->rspsz = 0;
3302
3303
3304         _rtw_init_listhead(&pcmd->list);
3305
3306         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("after enqueue set_auth_cmd, auth_mode=%x\n", psecuritypriv->dot11AuthAlgrthm));
3307
3308         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
3309
3310 exit:
3311
3312 _func_exit_;
3313
3314         return res;
3315
3316 }
3317
3318
3319 sint rtw_set_key(_adapter * adapter,struct security_priv *psecuritypriv,sint keyid, u8 set_tx, bool enqueue)
3320 {
3321         u8      keylen;
3322         struct cmd_obj          *pcmd;
3323         struct setkey_parm      *psetkeyparm;
3324         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
3325         struct mlme_priv                *pmlmepriv = &(adapter->mlmepriv);
3326         sint    res=_SUCCESS;
3327         
3328 _func_enter_;
3329
3330         psetkeyparm=(struct setkey_parm*)rtw_zmalloc(sizeof(struct setkey_parm));
3331         if(psetkeyparm==NULL){          
3332                 res= _FAIL;
3333                 goto exit;
3334         }
3335         _rtw_memset(psetkeyparm, 0, sizeof(struct setkey_parm));
3336
3337         if(psecuritypriv->dot11AuthAlgrthm ==dot11AuthAlgrthm_8021X){           
3338                 psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy;      
3339                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n rtw_set_key: psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy=%d \n", psetkeyparm->algorithm));
3340         }       
3341         else{
3342                 psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm;
3343                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n rtw_set_key: psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm=%d \n", psetkeyparm->algorithm));
3344
3345         }
3346         psetkeyparm->keyid = (u8)keyid;//0~3
3347         psetkeyparm->set_tx = set_tx;
3348         if (is_wep_enc(psetkeyparm->algorithm))
3349                 adapter->securitypriv.key_mask |= BIT(psetkeyparm->keyid);
3350
3351         DBG_871X("==> rtw_set_key algorithm(%x),keyid(%x),key_mask(%x)\n",psetkeyparm->algorithm,psetkeyparm->keyid, adapter->securitypriv.key_mask);
3352         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n rtw_set_key: psetkeyparm->algorithm=%d psetkeyparm->keyid=(u8)keyid=%d \n",psetkeyparm->algorithm, keyid));
3353
3354         switch(psetkeyparm->algorithm){
3355                         
3356                 case _WEP40_:
3357                         keylen=5;
3358                         _rtw_memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
3359                         break;
3360                 case _WEP104_:
3361                         keylen=13;
3362                         _rtw_memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
3363                         break;
3364                 case _TKIP_:
3365                         keylen=16;                      
3366                         _rtw_memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
3367                         psetkeyparm->grpkey=1;
3368                         break;
3369                 case _AES_:
3370                         keylen=16;                      
3371                         _rtw_memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
3372                         psetkeyparm->grpkey=1;
3373                         break;
3374                 default:
3375                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm = %x (must be 1 or 2 or 4 or 5)\n",psecuritypriv->dot11PrivacyAlgrthm));
3376                         res= _FAIL;
3377                         rtw_mfree((unsigned char *)psetkeyparm, sizeof(struct setkey_parm));
3378                         goto exit;
3379         }
3380                 
3381                 
3382         if(enqueue){
3383                 pcmd = (struct  cmd_obj*)rtw_zmalloc(sizeof(struct      cmd_obj));
3384                 if(pcmd==NULL){
3385                         rtw_mfree((unsigned char *)psetkeyparm, sizeof(struct setkey_parm));
3386                         res= _FAIL;  //try again
3387                         goto exit;
3388                 }
3389                 
3390                 pcmd->cmdcode = _SetKey_CMD_;
3391                 pcmd->parmbuf = (u8 *)psetkeyparm;   
3392                 pcmd->cmdsz =  (sizeof(struct setkey_parm));  
3393                 pcmd->rsp = NULL;
3394                 pcmd->rspsz = 0;
3395
3396                 _rtw_init_listhead(&pcmd->list);
3397
3398                 //_rtw_init_sema(&(pcmd->cmd_sem), 0);
3399
3400                 res = rtw_enqueue_cmd(pcmdpriv, pcmd);
3401         }
3402         else{
3403                 setkey_hdl(adapter, (u8 *)psetkeyparm);
3404                 rtw_mfree((u8 *) psetkeyparm, sizeof(struct setkey_parm));
3405         }
3406 exit:
3407 _func_exit_;
3408         return res;
3409
3410 }
3411
3412
3413 //adjust IEs for rtw_joinbss_cmd in WMM
3414 int rtw_restruct_wmm_ie(_adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
3415 {
3416         unsigned        int ielength=0;
3417         unsigned int i, j;
3418
3419         i = 12; //after the fixed IE
3420         while(i<in_len)
3421         {
3422                 ielength = initial_out_len;             
3423                 
3424                 if(in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) //WMM element ID and OUI
3425                 {
3426
3427                         //Append WMM IE to the last index of out_ie
3428                         /*
3429                         for(j=i; j< i+(in_ie[i+1]+2); j++)
3430                         {
3431                                 out_ie[ielength] = in_ie[j];                            
3432                                 ielength++;
3433                         }
3434                         out_ie[initial_out_len+8] = 0x00; //force the QoS Info Field to be zero
3435                         */
3436                        
3437                         for ( j = i; j < i + 9; j++ )
3438                         {
3439                             out_ie[ ielength] = in_ie[ j ];
3440                             ielength++;
3441                         } 
3442                         out_ie[ initial_out_len + 1 ] = 0x07;
3443                         out_ie[ initial_out_len + 6 ] = 0x00;
3444                         out_ie[ initial_out_len + 8 ] = 0x00;
3445         
3446                         break;
3447                 }
3448
3449                 i+=(in_ie[i+1]+2); // to the next IE element
3450         }
3451         
3452         return ielength;
3453         
3454 }
3455
3456
3457 //
3458 // Ported from 8185: IsInPreAuthKeyList(). (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.)
3459 // Added by Annie, 2006-05-07.
3460 //
3461 // Search by BSSID,
3462 // Return Value:
3463 //              -1              :if there is no pre-auth key in the  table
3464 //              >=0             :if there is pre-auth key, and   return the entry id
3465 //
3466 //
3467
3468 static int SecIsInPMKIDList(_adapter *Adapter, u8 *bssid)
3469 {
3470         struct security_priv *psecuritypriv=&Adapter->securitypriv;
3471         int i=0;
3472
3473         do
3474         {
3475                 if( ( psecuritypriv->PMKIDList[i].bUsed ) && 
3476                     (  _rtw_memcmp( psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN ) == _TRUE ) )
3477                 {
3478                         break;
3479                 }
3480                 else
3481                 {       
3482                         i++;
3483                         //continue;
3484                 }
3485                 
3486         }while(i<NUM_PMKID_CACHE);
3487
3488         if( i == NUM_PMKID_CACHE )
3489         { 
3490                 i = -1;// Could not find.
3491         }
3492         else
3493         { 
3494                 // There is one Pre-Authentication Key for the specific BSSID.
3495         }
3496
3497         return (i);
3498         
3499 }
3500
3501 //
3502 // Check the RSN IE length
3503 // If the RSN IE length <= 20, the RSN IE didn't include the PMKID information
3504 // 0-11th element in the array are the fixed IE
3505 // 12th element in the array is the IE
3506 // 13th element in the array is the IE length  
3507 //
3508
3509 static int rtw_append_pmkid(_adapter *Adapter,int iEntry, u8 *ie, uint ie_len)
3510 {
3511         struct security_priv *psecuritypriv=&Adapter->securitypriv;
3512
3513         if(ie[13]<=20){ 
3514                 // The RSN IE didn't include the PMK ID, append the PMK information 
3515                         ie[ie_len]=1;
3516                         ie_len++;
3517                         ie[ie_len]=0;   //PMKID count = 0x0100
3518                         ie_len++;
3519                         _rtw_memcpy(    &ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
3520                 
3521                         ie_len+=16;
3522                         ie[13]+=18;//PMKID length = 2+16
3523
3524         }
3525         return (ie_len);
3526 }
3527
3528 sint rtw_restruct_sec_ie(_adapter *adapter,u8 *in_ie, u8 *out_ie, uint in_len)
3529 {
3530         u8 authmode=0x0, securitytype, match;
3531         u8 sec_ie[255], uncst_oui[4], bkup_ie[255];
3532         u8 wpa_oui[4]={0x0, 0x50, 0xf2, 0x01};
3533         uint    ielength, cnt, remove_cnt;
3534         int iEntry;
3535
3536         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
3537         struct security_priv *psecuritypriv=&adapter->securitypriv;
3538         uint    ndisauthmode=psecuritypriv->ndisauthtype;
3539         uint ndissecuritytype = psecuritypriv->ndisencryptstatus;
3540         
3541 _func_enter_;
3542
3543         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
3544                  ("+rtw_restruct_sec_ie: ndisauthmode=%d ndissecuritytype=%d\n",
3545                   ndisauthmode, ndissecuritytype));
3546         
3547         //copy fixed ie only
3548         _rtw_memcpy(out_ie, in_ie,12);
3549         ielength=12;
3550         if((ndisauthmode==Ndis802_11AuthModeWPA)||(ndisauthmode==Ndis802_11AuthModeWPAPSK))
3551                         authmode=_WPA_IE_ID_;
3552         if((ndisauthmode==Ndis802_11AuthModeWPA2)||(ndisauthmode==Ndis802_11AuthModeWPA2PSK))
3553                         authmode=_WPA2_IE_ID_;
3554
3555         if(check_fwstate(pmlmepriv, WIFI_UNDER_WPS))
3556         {
3557                 _rtw_memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
3558                 
3559                 ielength += psecuritypriv->wps_ie_len;
3560         }
3561         else if((authmode==_WPA_IE_ID_)||(authmode==_WPA2_IE_ID_))
3562         {               
3563                 //copy RSN or SSN               
3564                 _rtw_memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
3565                 /* debug for CONFIG_IEEE80211W
3566                 {
3567                         int jj;
3568                         printk("supplicant_ie_length=%d &&&&&&&&&&&&&&&&&&&\n", psecuritypriv->supplicant_ie[1]+2);
3569                         for(jj=0; jj < psecuritypriv->supplicant_ie[1]+2; jj++)
3570                                 printk(" %02x ", psecuritypriv->supplicant_ie[jj]);
3571                         printk("\n");
3572                 }*/
3573                 ielength+=psecuritypriv->supplicant_ie[1]+2;
3574                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
3575         
3576 #ifdef CONFIG_DRVEXT_MODULE
3577                 drvext_report_sec_ie(&adapter->drvextpriv, authmode, sec_ie);   
3578 #endif
3579         }
3580
3581         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
3582         if(iEntry<0)
3583         {
3584                 return ielength;
3585         }
3586         else
3587         {
3588                 if(authmode == _WPA2_IE_ID_)
3589                 {
3590                         ielength=rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
3591                 }
3592         }
3593
3594 _func_exit_;
3595         
3596         return ielength;        
3597 }
3598
3599 void rtw_init_registrypriv_dev_network( _adapter* adapter)
3600 {
3601         struct registry_priv* pregistrypriv = &adapter->registrypriv;
3602         struct eeprom_priv* peepriv = &adapter->eeprompriv;
3603         WLAN_BSSID_EX    *pdev_network = &pregistrypriv->dev_network;
3604         u8 *myhwaddr = myid(peepriv);
3605         
3606 _func_enter_;
3607
3608         _rtw_memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
3609
3610         _rtw_memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(NDIS_802_11_SSID));
3611         
3612         pdev_network->Configuration.Length=sizeof(NDIS_802_11_CONFIGURATION);
3613         pdev_network->Configuration.BeaconPeriod = 100; 
3614         pdev_network->Configuration.FHConfig.Length = 0;
3615         pdev_network->Configuration.FHConfig.HopPattern = 0;
3616         pdev_network->Configuration.FHConfig.HopSet = 0;
3617         pdev_network->Configuration.FHConfig.DwellTime = 0;
3618         
3619         
3620 _func_exit_;    
3621         
3622 }
3623
3624 void rtw_update_registrypriv_dev_network(_adapter* adapter) 
3625 {
3626         int sz=0;
3627         struct registry_priv* pregistrypriv = &adapter->registrypriv;   
3628         WLAN_BSSID_EX    *pdev_network = &pregistrypriv->dev_network;
3629         struct  security_priv*  psecuritypriv = &adapter->securitypriv;
3630         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
3631         //struct        xmit_priv       *pxmitpriv = &adapter->xmitpriv;
3632
3633 _func_enter_;
3634
3635 #if 0
3636         pxmitpriv->vcs_setting = pregistrypriv->vrtl_carrier_sense;
3637         pxmitpriv->vcs = pregistrypriv->vcs_type;
3638         pxmitpriv->vcs_type = pregistrypriv->vcs_type;
3639         //pxmitpriv->rts_thresh = pregistrypriv->rts_thresh;
3640         pxmitpriv->frag_len = pregistrypriv->frag_thresh;
3641         
3642         adapter->qospriv.qos_option = pregistrypriv->wmm_enable;
3643 #endif  
3644
3645         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0) ; // adhoc no 802.1x
3646
3647         pdev_network->Rssi = 0;
3648
3649         switch(pregistrypriv->wireless_mode)
3650         {
3651                 case WIRELESS_11B:
3652                         pdev_network->NetworkTypeInUse = (Ndis802_11DS);
3653                         break;  
3654                 case WIRELESS_11G:
3655                 case WIRELESS_11BG:
3656                 case WIRELESS_11_24N:
3657                 case WIRELESS_11G_24N:
3658                 case WIRELESS_11BG_24N:
3659                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
3660                         break;
3661                 case WIRELESS_11A:
3662                 case WIRELESS_11A_5N:
3663                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
3664                         break;
3665                 case WIRELESS_11ABGN:
3666                         if(pregistrypriv->channel > 14)
3667                                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
3668                         else
3669                                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
3670                         break;
3671                 default :
3672                         // TODO
3673                         break;
3674         }
3675         
3676         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
3677         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("pregistrypriv->channel=%d, pdev_network->Configuration.DSConfig=0x%x\n", pregistrypriv->channel, pdev_network->Configuration.DSConfig));  
3678
3679         if(cur_network->network.InfrastructureMode == Ndis802_11IBSS)
3680                 pdev_network->Configuration.ATIMWindow = (0);
3681
3682         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
3683
3684         // 1. Supported rates
3685         // 2. IE
3686
3687         //rtw_set_supported_rate(pdev_network->SupportedRates, pregistrypriv->wireless_mode) ; // will be called in rtw_generate_ie
3688         sz = rtw_generate_ie(pregistrypriv);
3689
3690         pdev_network->IELength = sz;
3691
3692         pdev_network->Length = get_WLAN_BSSID_EX_sz((WLAN_BSSID_EX  *)pdev_network);
3693
3694         //notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd();
3695         //pdev_network->IELength = cpu_to_le32(sz);
3696                 
3697 _func_exit_;    
3698
3699 }
3700
3701 void rtw_get_encrypt_decrypt_from_registrypriv(_adapter* adapter)
3702 {
3703 _func_enter_;
3704
3705
3706 _func_exit_;    
3707         
3708 }
3709
3710 //the fucntion is at passive_level 
3711 void rtw_joinbss_reset(_adapter *padapter)
3712 {
3713         u8      threshold;
3714         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
3715
3716 #ifdef CONFIG_80211N_HT 
3717         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
3718 #endif
3719
3720         //todo: if you want to do something io/reg/hw setting before join_bss, please add code here
3721         
3722
3723
3724
3725 #ifdef CONFIG_80211N_HT
3726
3727         pmlmepriv->num_FortyMHzIntolerant = 0;
3728
3729         pmlmepriv->num_sta_no_ht = 0;
3730
3731         phtpriv->ampdu_enable = _FALSE;//reset to disabled
3732
3733 #if defined( CONFIG_USB_HCI) || defined (CONFIG_SDIO_HCI)
3734         // TH=1 => means that invalidate usb rx aggregation
3735         // TH=0 => means that validate usb rx aggregation, use init value.
3736         if(phtpriv->ht_option)
3737         {
3738                 if(padapter->registrypriv.wifi_spec==1)         
3739                         threshold = 1;
3740                 else
3741                         threshold = 0;          
3742                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
3743         }
3744         else
3745         {
3746                 threshold = 1;
3747                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
3748         }
3749 #endif
3750
3751 #endif  
3752
3753 }
3754
3755
3756 #ifdef CONFIG_80211N_HT
3757 void    rtw_ht_use_default_setting(_adapter *padapter)
3758 {
3759         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
3760         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
3761         struct registry_priv    *pregistrypriv = &padapter->registrypriv;
3762         BOOLEAN         bHwLDPCSupport = _FALSE, bHwSTBCSupport = _FALSE;
3763         BOOLEAN         bHwSupportBeamformer = _FALSE, bHwSupportBeamformee = _FALSE;
3764
3765         if (pregistrypriv->wifi_spec)
3766                 phtpriv->bss_coexist = 1;
3767         else
3768                 phtpriv->bss_coexist = 0;
3769
3770         phtpriv->sgi_40m = TEST_FLAG(pregistrypriv->short_gi, BIT1) ? _TRUE : _FALSE;
3771         phtpriv->sgi_20m = TEST_FLAG(pregistrypriv->short_gi, BIT0) ? _TRUE : _FALSE;
3772
3773         // LDPC support
3774         rtw_hal_get_def_var(padapter, HAL_DEF_RX_LDPC, (u8 *)&bHwLDPCSupport);
3775         CLEAR_FLAGS(phtpriv->ldpc_cap);
3776         if(bHwLDPCSupport)
3777         {
3778                 if(TEST_FLAG(pregistrypriv->ldpc_cap, BIT4))
3779                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_RX);
3780         }
3781         rtw_hal_get_def_var(padapter, HAL_DEF_TX_LDPC, (u8 *)&bHwLDPCSupport);
3782         if(bHwLDPCSupport)
3783         {
3784                 if(TEST_FLAG(pregistrypriv->ldpc_cap, BIT5))
3785                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_TX);
3786         }
3787         if (phtpriv->ldpc_cap)
3788                 DBG_871X("[HT] Support LDPC = 0x%02X\n", phtpriv->ldpc_cap);
3789
3790         // STBC
3791         rtw_hal_get_def_var(padapter, HAL_DEF_TX_STBC, (u8 *)&bHwSTBCSupport);
3792         CLEAR_FLAGS(phtpriv->stbc_cap);
3793         if(bHwSTBCSupport)
3794         {
3795                 if(TEST_FLAG(pregistrypriv->stbc_cap, BIT5))
3796                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX);
3797         }
3798         rtw_hal_get_def_var(padapter, HAL_DEF_RX_STBC, (u8 *)&bHwSTBCSupport);
3799         if(bHwSTBCSupport)
3800         {
3801                 if(TEST_FLAG(pregistrypriv->stbc_cap, BIT4))
3802                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX);
3803         }
3804         if (phtpriv->stbc_cap)
3805                 DBG_871X("[HT] Support STBC = 0x%02X\n", phtpriv->stbc_cap);
3806
3807         // Beamforming setting
3808         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMER, (u8 *)&bHwSupportBeamformer);
3809         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMEE, (u8 *)&bHwSupportBeamformee);
3810         CLEAR_FLAGS(phtpriv->beamform_cap);
3811         if(TEST_FLAG(pregistrypriv->beamform_cap, BIT4) && bHwSupportBeamformer)
3812         {
3813                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE);
3814                 DBG_871X("[HT] Support Beamformer\n");
3815         }
3816         if(TEST_FLAG(pregistrypriv->beamform_cap, BIT5) && bHwSupportBeamformee)
3817         {
3818                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE);
3819                 DBG_871X("[HT] Support Beamformee\n");
3820         }
3821 }
3822
3823 void rtw_build_wmm_ie_ht(_adapter *padapter, u8 *out_ie, uint *pout_len)
3824 {
3825         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
3826         int out_len;
3827         u8 *pframe;
3828
3829         if(padapter->mlmepriv.qospriv.qos_option == 0)
3830         {
3831                 out_len = *pout_len;
3832                 pframe = rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_, 
3833                                                         _WMM_IE_Length_, WMM_IE, pout_len);
3834
3835                 padapter->mlmepriv.qospriv.qos_option = 1;
3836         }
3837 }
3838
3839 /* the fucntion is >= passive_level */
3840 unsigned int rtw_restructure_ht_ie(_adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len, u8 channel)
3841 {
3842         u32 ielen, out_len;
3843         HT_CAP_AMPDU_FACTOR max_rx_ampdu_factor;
3844         unsigned char *p, *pframe;
3845         struct rtw_ieee80211_ht_cap ht_capie;
3846         u8      cbw40_enable = 0, stbc_rx_enable = 0, rf_type = 0, operation_bw=0;
3847         struct registry_priv *pregistrypriv = &padapter->registrypriv;
3848         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
3849         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
3850         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
3851
3852         phtpriv->ht_option = _FALSE;
3853
3854         out_len = *pout_len;
3855
3856         _rtw_memset(&ht_capie, 0, sizeof(struct rtw_ieee80211_ht_cap));
3857
3858         ht_capie.cap_info = IEEE80211_HT_CAP_DSSSCCK40;
3859
3860         if (phtpriv->sgi_20m)
3861                 ht_capie.cap_info |= IEEE80211_HT_CAP_SGI_20;
3862
3863         /* Get HT BW */
3864         if (in_ie == NULL) {
3865                 /* TDLS: TODO 20/40 issue */
3866                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
3867                         operation_bw = padapter->mlmeextpriv.cur_bwmode;
3868                         if (operation_bw > CHANNEL_WIDTH_40)
3869                                 operation_bw = CHANNEL_WIDTH_40;
3870                 } else
3871                         /* TDLS: TODO 40? */
3872                         operation_bw = CHANNEL_WIDTH_40;
3873         } else {
3874                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
3875                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
3876                         struct HT_info_element *pht_info = (struct HT_info_element *)(p+2);
3877                         if (pht_info->infos[0] & BIT(2)) {
3878                                 switch (pht_info->infos[0] & 0x3) {
3879                                 case 1:
3880                                 case 3:
3881                                         operation_bw = CHANNEL_WIDTH_40;
3882                                         break;
3883                                 default:
3884                                         operation_bw = CHANNEL_WIDTH_20;
3885                                         break;
3886                                 }
3887                         } else {
3888                                 operation_bw = CHANNEL_WIDTH_20;
3889                         }
3890                 }
3891         }
3892
3893         /* to disable 40M Hz support while gd_bw_40MHz_en = 0 */
3894         if (channel > 14) {
3895                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
3896                         cbw40_enable = 1;
3897         } else {
3898                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
3899                         cbw40_enable = 1;
3900         }
3901
3902         if ((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) {
3903                 ht_capie.cap_info |= IEEE80211_HT_CAP_SUP_WIDTH;
3904                 if (phtpriv->sgi_40m)
3905                         ht_capie.cap_info |= IEEE80211_HT_CAP_SGI_40;
3906         }
3907
3908         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX))
3909                 ht_capie.cap_info |= IEEE80211_HT_CAP_TX_STBC;
3910
3911         /* todo: disable SM power save mode */
3912         ht_capie.cap_info |= IEEE80211_HT_CAP_SM_PS;
3913
3914         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX)) {
3915                 if((pregistrypriv->rx_stbc == 0x3) ||                                                   /* enable for 2.4/5 GHz */
3916                         ((channel <= 14) && (pregistrypriv->rx_stbc == 0x1)) || /* enable for 2.4GHz */
3917                         ((channel > 14) && (pregistrypriv->rx_stbc == 0x2)) ||          /* enable for 5GHz */
3918                         (pregistrypriv->wifi_spec == 1)) {
3919                         stbc_rx_enable = 1;
3920                         DBG_871X("declare supporting RX STBC\n");
3921                 }
3922         }
3923
3924         //fill default supported_mcs_set
3925         _rtw_memcpy(ht_capie.supp_mcs_set, pmlmeext->default_supported_mcs_set, 16);
3926
3927         //update default supported_mcs_set
3928         rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
3929
3930         switch(rf_type)
3931         {
3932         case RF_1T1R:
3933                 
3934                 if (stbc_rx_enable)
3935                         ht_capie.cap_info |= IEEE80211_HT_CAP_RX_STBC_1R;//RX STBC One spatial stream
3936
3937                         set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_1R);                       
3938                         break;
3939
3940         case RF_2T2R:
3941         case RF_1T2R:
3942         default:
3943
3944                 if (stbc_rx_enable)
3945                         ht_capie.cap_info |= IEEE80211_HT_CAP_RX_STBC_2R;//RX STBC two spatial stream
3946
3947                 #ifdef CONFIG_DISABLE_MCS13TO15
3948                 if(((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) && (pregistrypriv->wifi_spec!=1))
3949                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R_13TO15_OFF);    
3950                 else
3951                                 set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);       
3952                 #else //CONFIG_DISABLE_MCS13TO15
3953                         set_mcs_rate_by_mask(ht_capie.supp_mcs_set, MCS_RATE_2R);       
3954                 #endif //CONFIG_DISABLE_MCS13TO15
3955                 break;
3956         }
3957
3958         {
3959                 u32 rx_packet_offset, max_recvbuf_sz;
3960                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
3961                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
3962                 //if(max_recvbuf_sz-rx_packet_offset>(8191-256)) {
3963                 //      DBG_871X("%s IEEE80211_HT_CAP_MAX_AMSDU is set\n", __FUNCTION__);
3964                 //      ht_capie.cap_info = ht_capie.cap_info |IEEE80211_HT_CAP_MAX_AMSDU;
3965                 //}
3966         }
3967         /*      
3968         AMPDU_para [1:0]:Max AMPDU Len => 0:8k , 1:16k, 2:32k, 3:64k
3969         AMPDU_para [4:2]:Min MPDU Start Spacing 
3970         */
3971
3972         /*
3973         #if defined(CONFIG_RTL8188E )&& defined (CONFIG_SDIO_HCI)
3974         ht_capie.ampdu_params_info = 2;
3975         #else
3976         ht_capie.ampdu_params_info = (IEEE80211_HT_CAP_AMPDU_FACTOR&0x03);
3977         #endif
3978         */
3979
3980         if(padapter->driver_rx_ampdu_factor != 0xFF)
3981                 max_rx_ampdu_factor = (HT_CAP_AMPDU_FACTOR)padapter->driver_rx_ampdu_factor;
3982         else
3983                 rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor);
3984                                 
3985         //rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor);
3986         ht_capie.ampdu_params_info = (max_rx_ampdu_factor&0x03);
3987
3988         if(padapter->securitypriv.dot11PrivacyAlgrthm == _AES_ )
3989                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&(0x07<<2));
3990         else
3991                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
3992
3993 #ifdef CONFIG_BEAMFORMING
3994         ht_capie.tx_BF_cap_info = 0;
3995
3996         // HT Beamformer
3997         if(TEST_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE))
3998         {
3999                 // Transmit NDP Capable
4000                 SET_HT_CAP_TXBF_TRANSMIT_NDP_CAP(&ht_capie, 1);
4001                 // Explicit Compressed Steering Capable
4002                 SET_HT_CAP_TXBF_EXPLICIT_COMP_STEERING_CAP(&ht_capie, 1);
4003                 // Compressed Steering Number Antennas
4004                 SET_HT_CAP_TXBF_COMP_STEERING_NUM_ANTENNAS(&ht_capie, 1);
4005         }
4006
4007         // HT Beamformee
4008         if(TEST_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE))
4009         {
4010                 // Receive NDP Capable
4011                 SET_HT_CAP_TXBF_RECEIVE_NDP_CAP(&ht_capie, 1);
4012                 // Explicit Compressed Beamforming Feedback Capable
4013                 SET_HT_CAP_TXBF_EXPLICIT_COMP_FEEDBACK_CAP(&ht_capie, 2);
4014         }
4015 #endif
4016
4017         pframe = rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_, 
4018                                                 sizeof(struct rtw_ieee80211_ht_cap), (unsigned char*)&ht_capie, pout_len);
4019
4020         phtpriv->ht_option = _TRUE;
4021
4022         if(in_ie!=NULL)
4023         {
4024                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
4025                 if(p && (ielen==sizeof(struct ieee80211_ht_addt_info)))
4026                 {
4027                         out_len = *pout_len;            
4028                         pframe = rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2 , pout_len);
4029                 }
4030         }
4031
4032         return (phtpriv->ht_option);
4033         
4034 }
4035
4036 //the fucntion is > passive_level (in critical_section)
4037 void rtw_update_ht_cap(_adapter *padapter, u8 *pie, uint ie_len, u8 channel)
4038 {       
4039         u8 *p, max_ampdu_sz;
4040         int len;                
4041         //struct sta_info *bmc_sta, *psta;
4042         struct rtw_ieee80211_ht_cap *pht_capie;
4043         struct ieee80211_ht_addt_info *pht_addtinfo;
4044         //struct recv_reorder_ctrl *preorder_ctrl;
4045         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
4046         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
4047         //struct recv_priv *precvpriv = &padapter->recvpriv;
4048         struct registry_priv *pregistrypriv = &padapter->registrypriv;
4049         //struct wlan_network *pcur_network = &(pmlmepriv->cur_network);;
4050         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
4051         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
4052         u8 cbw40_enable=0;
4053         
4054
4055         if(!phtpriv->ht_option)
4056                 return;
4057
4058         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
4059                 return;
4060
4061         DBG_871X("+rtw_update_ht_cap()\n");
4062
4063         //maybe needs check if ap supports rx ampdu.
4064         if((phtpriv->ampdu_enable==_FALSE) &&(pregistrypriv->ampdu_enable==1))
4065         {
4066                 if(pregistrypriv->wifi_spec==1)
4067                 {
4068                         //remove this part because testbed AP should disable RX AMPDU
4069                         //phtpriv->ampdu_enable = _FALSE;
4070                         phtpriv->ampdu_enable = _TRUE;
4071                 }
4072                 else
4073                 {
4074                         phtpriv->ampdu_enable = _TRUE;
4075                 }
4076         }
4077         else if(pregistrypriv->ampdu_enable==2)
4078         {
4079                 //remove this part because testbed AP should disable RX AMPDU
4080                 //phtpriv->ampdu_enable = _TRUE;
4081         }
4082
4083         
4084         //check Max Rx A-MPDU Size 
4085         len = 0;
4086         p = rtw_get_ie(pie+sizeof (NDIS_802_11_FIXED_IEs), _HT_CAPABILITY_IE_, &len, ie_len-sizeof (NDIS_802_11_FIXED_IEs));
4087         if(p && len>0)  
4088         {
4089                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);
4090                 max_ampdu_sz = (pht_capie->ampdu_params_info & IEEE80211_HT_CAP_AMPDU_FACTOR);
4091                 max_ampdu_sz = 1 << (max_ampdu_sz+3); // max_ampdu_sz (kbytes);
4092                 
4093                 //DBG_871X("rtw_update_ht_cap(): max_ampdu_sz=%d\n", max_ampdu_sz);
4094                 phtpriv->rx_ampdu_maxlen = max_ampdu_sz;
4095                 
4096         }
4097
4098
4099         len=0;
4100         p = rtw_get_ie(pie+sizeof (NDIS_802_11_FIXED_IEs), _HT_ADD_INFO_IE_, &len, ie_len-sizeof (NDIS_802_11_FIXED_IEs));
4101         if(p && len>0)  
4102         {
4103                 pht_addtinfo = (struct ieee80211_ht_addt_info *)(p+2);
4104                 //todo:
4105         }
4106
4107         if (channel > 14) {
4108                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
4109                         cbw40_enable = 1;
4110         } else {
4111                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
4112                         cbw40_enable = 1;
4113         }
4114
4115         //update cur_bwmode & cur_ch_offset
4116         if ((cbw40_enable) &&
4117                 (pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info & BIT(1)) && 
4118                 (pmlmeinfo->HT_info.infos[0] & BIT(2)))
4119         {
4120                 int i;
4121                 u8      rf_type;
4122
4123                 rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
4124
4125                 //update the MCS set
4126                 for (i = 0; i < 16; i++)
4127                         pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= pmlmeext->default_supported_mcs_set[i];
4128
4129                 //update the MCS rates
4130                 switch(rf_type)
4131                 {
4132                         case RF_1T1R:
4133                         case RF_1T2R:
4134                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_1R);                                                        
4135                                 break;
4136                         case RF_2T2R:                   
4137                         default:
4138 #ifdef CONFIG_DISABLE_MCS13TO15
4139                                 if(pmlmeext->cur_bwmode == CHANNEL_WIDTH_40 && pregistrypriv->wifi_spec != 1 )                          
4140                                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R_13TO15_OFF);                             
4141                                 else
4142                                         set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
4143 #else //CONFIG_DISABLE_MCS13TO15
4144                                 set_mcs_rate_by_mask(pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate, MCS_RATE_2R);
4145 #endif //CONFIG_DISABLE_MCS13TO15
4146                 }
4147
4148                 //switch to the 40M Hz mode accoring to the AP
4149                 //pmlmeext->cur_bwmode = CHANNEL_WIDTH_40;
4150                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3))
4151                 {
4152                         case EXTCHNL_OFFSET_UPPER:
4153                                 pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
4154                                 break;
4155                         
4156                         case EXTCHNL_OFFSET_LOWER:
4157                                 pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
4158                                 break;
4159                                 
4160                         default:
4161                                 pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
4162                                 break;
4163                 }               
4164         }
4165
4166         //
4167         // Config SM Power Save setting
4168         //
4169         pmlmeinfo->SM_PS = (pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info & 0x0C) >> 2;
4170         if(pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
4171         {
4172                 /*u8 i;
4173                 //update the MCS rates
4174                 for (i = 0; i < 16; i++)
4175                 {
4176                         pmlmeinfo->HT_caps.HT_cap_element.MCS_rate[i] &= MCS_rate_1R[i];
4177                 }*/
4178                 DBG_871X("%s(): WLAN_HT_CAP_SM_PS_STATIC\n",__FUNCTION__);
4179         }
4180
4181         //
4182         // Config current HT Protection mode.
4183         //
4184         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
4185
4186         
4187         
4188 #if 0 //move to rtw_update_sta_info_client()
4189         //for A-MPDU Rx reordering buffer control for bmc_sta & sta_info
4190         //if A-MPDU Rx is enabled, reseting  rx_ordering_ctrl wstart_b(indicate_seq) to default value=0xffff
4191         //todo: check if AP can send A-MPDU packets
4192         bmc_sta = rtw_get_bcmc_stainfo(padapter);
4193         if(bmc_sta)
4194         {
4195                 for(i=0; i < 16 ; i++)
4196                 {
4197                         //preorder_ctrl = &precvpriv->recvreorder_ctrl[i];
4198                         preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
4199                         preorder_ctrl->enable = _FALSE;
4200                         preorder_ctrl->indicate_seq = 0xffff;
4201                         #ifdef DBG_RX_SEQ
4202                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u \n", __FUNCTION__, __LINE__,
4203                                 preorder_ctrl->indicate_seq);
4204                         #endif
4205                         preorder_ctrl->wend_b= 0xffff;
4206                         preorder_ctrl->wsize_b = 64;//max_ampdu_sz;//ex. 32(kbytes) -> wsize_b=32
4207                 }
4208         }
4209
4210         psta = rtw_get_stainfo(&padapter->stapriv, pcur_network->network.MacAddress);
4211         if(psta)
4212         {
4213                 for(i=0; i < 16 ; i++)
4214                 {
4215                         //preorder_ctrl = &precvpriv->recvreorder_ctrl[i];
4216                         preorder_ctrl = &psta->recvreorder_ctrl[i];
4217                         preorder_ctrl->enable = _FALSE;
4218                         preorder_ctrl->indicate_seq = 0xffff;
4219                         #ifdef DBG_RX_SEQ
4220                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u \n", __FUNCTION__, __LINE__,
4221                                 preorder_ctrl->indicate_seq);
4222                         #endif
4223                         preorder_ctrl->wend_b= 0xffff;
4224                         preorder_ctrl->wsize_b = 64;//max_ampdu_sz;//ex. 32(kbytes) -> wsize_b=32
4225                 }
4226         }
4227 #endif  
4228
4229 }
4230
4231 #ifdef CONFIG_TDLS
4232 void rtw_issue_addbareq_cmd_tdls(_adapter *padapter, struct xmit_frame *pxmitframe)
4233 {
4234         struct pkt_attrib *pattrib =&pxmitframe->attrib;
4235         struct sta_info *ptdls_sta = NULL;
4236         u8 issued;
4237         int priority;
4238         struct ht_priv  *phtpriv;
4239
4240         priority = pattrib->priority;
4241
4242         if(pattrib->direct_link == _TRUE)
4243         {
4244                 ptdls_sta = rtw_get_stainfo(&padapter->stapriv, pattrib->dst);
4245                 if((ptdls_sta != NULL) && (ptdls_sta->tdls_sta_state & TDLS_ESTABLISHED))
4246                 {
4247                         phtpriv = &ptdls_sta->htpriv;
4248
4249                         if((phtpriv->ht_option==_TRUE) && (phtpriv->ampdu_enable==_TRUE)) 
4250                         {
4251                                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
4252                                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
4253
4254                                 if(0==issued)
4255                                 {
4256                                         DBG_871X("rtw_issue_addbareq_cmd, p=%d\n", priority);
4257                                         ptdls_sta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
4258                                         rtw_addbareq_cmd(padapter,(u8)priority, pattrib->dst);
4259                                 }
4260                         }
4261                 }
4262         }
4263 }
4264 #endif //CONFIG_TDLS
4265
4266 void rtw_issue_addbareq_cmd(_adapter *padapter, struct xmit_frame *pxmitframe)
4267 {
4268         u8 issued;
4269         int priority;
4270         struct sta_info *psta=NULL;
4271         struct ht_priv  *phtpriv;
4272         struct pkt_attrib *pattrib =&pxmitframe->attrib;
4273         s32 bmcst = IS_MCAST(pattrib->ra);
4274
4275         //if(bmcst || (padapter->mlmepriv.LinkDetectInfo.bTxBusyTraffic == _FALSE))
4276         if(bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod<100))    
4277                 return;
4278         
4279         priority = pattrib->priority;
4280
4281 #ifdef CONFIG_TDLS
4282         rtw_issue_addbareq_cmd_tdls(padapter, pxmitframe);
4283 #endif //CONFIG_TDLS
4284
4285         psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
4286         if(pattrib->psta != psta)
4287         {
4288                 DBG_871X("%s, pattrib->psta(%p) != psta(%p)\n", __func__, pattrib->psta, psta);
4289                 return;
4290         }
4291         
4292         if(psta==NULL)
4293         {
4294                 DBG_871X("%s, psta==NUL\n", __func__);
4295                 return;
4296         }
4297
4298         if(!(psta->state &_FW_LINKED))
4299         {
4300                 DBG_871X("%s, psta->state(0x%x) != _FW_LINKED\n", __func__, psta->state);
4301                 return;
4302         }       
4303
4304
4305         phtpriv = &psta->htpriv;
4306
4307         if((phtpriv->ht_option==_TRUE) && (phtpriv->ampdu_enable==_TRUE)) 
4308         {
4309                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
4310                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
4311
4312                 if(0==issued)
4313                 {
4314                         DBG_871X("rtw_issue_addbareq_cmd, p=%d\n", priority);
4315                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
4316                         rtw_addbareq_cmd(padapter,(u8) priority, pattrib->ra);
4317                 }
4318         }
4319
4320 }
4321
4322 void rtw_append_exented_cap(_adapter *padapter, u8 *out_ie, uint *pout_len)
4323 {
4324         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
4325         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
4326 #ifdef CONFIG_80211AC_VHT
4327         struct vht_priv *pvhtpriv = &pmlmepriv->vhtpriv;
4328 #endif //CONFIG_80211AC_VHT
4329         u8      cap_content[8] = {0};
4330         u8      *pframe;
4331
4332
4333         if (phtpriv->bss_coexist) {
4334                 SET_EXT_CAPABILITY_ELE_BSS_COEXIST(cap_content, 1);
4335         }
4336
4337 #ifdef CONFIG_80211AC_VHT
4338         if (pvhtpriv->vht_option) {
4339                 SET_EXT_CAPABILITY_ELE_OP_MODE_NOTIF(cap_content, 1);
4340         }
4341 #endif //CONFIG_80211AC_VHT
4342
4343         pframe = rtw_set_ie(out_ie+*pout_len, EID_EXTCapability, 8, cap_content , pout_len);
4344 }
4345 #endif
4346
4347 #ifdef CONFIG_LAYER2_ROAMING
4348 inline void rtw_set_to_roam(_adapter *adapter, u8 to_roam)
4349 {
4350         if (to_roam == 0)
4351                 adapter->mlmepriv.to_join = _FALSE;
4352         adapter->mlmepriv.to_roam = to_roam;
4353 }
4354
4355 inline u8 rtw_dec_to_roam(_adapter *adapter)
4356 {
4357         adapter->mlmepriv.to_roam--;
4358         return adapter->mlmepriv.to_roam;
4359 }
4360
4361 inline u8 rtw_to_roam(_adapter *adapter)
4362 {
4363         return adapter->mlmepriv.to_roam;
4364 }
4365
4366 void rtw_roaming(_adapter *padapter, struct wlan_network *tgt_network)
4367 {
4368         _irqL irqL;
4369         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
4370
4371         _enter_critical_bh(&pmlmepriv->lock, &irqL);
4372         _rtw_roaming(padapter, tgt_network);
4373         _exit_critical_bh(&pmlmepriv->lock, &irqL);
4374 }
4375 void _rtw_roaming(_adapter *padapter, struct wlan_network *tgt_network)
4376 {
4377         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
4378         struct wlan_network *cur_network = &pmlmepriv->cur_network;
4379         int do_join_r;
4380         
4381         if(0 < rtw_to_roam(padapter)) {
4382                 DBG_871X("roaming from %s("MAC_FMT"), length:%d\n",
4383                                 cur_network->network.Ssid.Ssid, MAC_ARG(cur_network->network.MacAddress),
4384                                 cur_network->network.Ssid.SsidLength);
4385                 _rtw_memcpy(&pmlmepriv->assoc_ssid, &cur_network->network.Ssid, sizeof(NDIS_802_11_SSID));
4386
4387                 pmlmepriv->assoc_by_bssid = _FALSE;
4388
4389 #ifdef CONFIG_WAPI_SUPPORT
4390                 rtw_wapi_return_all_sta_info(padapter);
4391 #endif
4392
4393                 while(1) {
4394                         if( _SUCCESS==(do_join_r=rtw_do_join(padapter)) ) {
4395                                 break;
4396                         } else {
4397                                 DBG_871X("roaming do_join return %d\n", do_join_r);
4398                                 rtw_dec_to_roam(padapter);
4399                                 
4400                                 if(rtw_to_roam(padapter) > 0) {
4401                                         continue;
4402                                 } else {
4403                                         DBG_871X("%s(%d) -to roaming fail, indicate_disconnect\n", __FUNCTION__,__LINE__);
4404                                         rtw_indicate_disconnect(padapter);
4405                                         break;
4406                                 }
4407                         }
4408                 }
4409         }
4410         
4411 }
4412 #endif /* CONFIG_LAYER2_ROAMING */
4413
4414 sint rtw_linked_check(_adapter *padapter)
4415 {
4416         if(     (check_fwstate(&padapter->mlmepriv, WIFI_AP_STATE) == _TRUE) ||
4417                         (check_fwstate(&padapter->mlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE) == _TRUE))
4418         {
4419                 if(padapter->stapriv.asoc_sta_count > 2)
4420                         return _TRUE;
4421         }
4422         else
4423         {       //Station mode
4424                 if(check_fwstate(&padapter->mlmepriv, _FW_LINKED)== _TRUE)
4425                         return _TRUE;
4426         }
4427         return _FALSE;
4428 }
4429
4430 #ifdef CONFIG_CONCURRENT_MODE
4431 sint rtw_buddy_adapter_up(_adapter *padapter)
4432 {       
4433         sint res = _FALSE;
4434         
4435         if(padapter == NULL)
4436                 return res;
4437
4438
4439         if(padapter->pbuddy_adapter == NULL)
4440         {
4441                 res = _FALSE;
4442         }
4443         else if( (padapter->pbuddy_adapter->bDriverStopped) || (padapter->pbuddy_adapter->bSurpriseRemoved) ||
4444                 (padapter->pbuddy_adapter->bup == _FALSE) || (padapter->pbuddy_adapter->hw_init_completed == _FALSE))
4445         {               
4446                 res = _FALSE;
4447         }
4448         else
4449         {
4450                 res = _TRUE;
4451         }       
4452
4453         return res;     
4454
4455 }
4456
4457 sint check_buddy_fwstate(_adapter *padapter, sint state)
4458 {
4459         if(padapter == NULL)
4460                 return _FALSE;  
4461         
4462         if(padapter->pbuddy_adapter == NULL)
4463                 return _FALSE;  
4464                 
4465         if ((state == WIFI_FW_NULL_STATE) && 
4466                 (padapter->pbuddy_adapter->mlmepriv.fw_state == WIFI_FW_NULL_STATE))
4467                 return _TRUE;           
4468         
4469         if (padapter->pbuddy_adapter->mlmepriv.fw_state & state)
4470                 return _TRUE;
4471
4472         return _FALSE;
4473 }
4474
4475 u8 rtw_get_buddy_bBusyTraffic(_adapter *padapter)
4476 {
4477         if(padapter == NULL)
4478                 return _FALSE;  
4479         
4480         if(padapter->pbuddy_adapter == NULL)
4481                 return _FALSE;  
4482         
4483         return padapter->pbuddy_adapter->mlmepriv.LinkDetectInfo.bBusyTraffic;
4484 }
4485
4486 #endif //CONFIG_CONCURRENT_MODE