Merge tag 'lsk-v3.10-android-14.11'
[firefly-linux-kernel-4.4.55.git] / drivers / net / wireless / rockchip_wlan / rtl8723bu / core / rtw_mlme.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.
4  *                                        
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  * You should have received a copy of the GNU General Public License along with
15  * this program; if not, write to the Free Software Foundation, Inc.,
16  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
17  *
18  *
19  ******************************************************************************/
20 #define _RTW_MLME_C_
21
22 #include <drv_types.h>
23
24
25 extern void indicate_wx_scan_complete_event(_adapter *padapter);
26 extern u8 rtw_do_join(_adapter * padapter);
27
28 #ifdef CONFIG_DISABLE_MCS13TO15
29 extern unsigned char    MCS_rate_2R_MCS13TO15_OFF[16];
30 extern unsigned char    MCS_rate_2R[16];
31 #else //CONFIG_DISABLE_MCS13TO15
32 extern unsigned char    MCS_rate_2R[16];
33 #endif //CONFIG_DISABLE_MCS13TO15
34 extern unsigned char    MCS_rate_1R[16];
35
36 sint    _rtw_init_mlme_priv (_adapter* padapter)
37 {
38         sint    i;
39         u8      *pbuf;
40         struct wlan_network     *pnetwork;
41         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
42         sint    res = _SUCCESS;
43
44 _func_enter_;
45
46         // We don't need to memset padapter->XXX to zero, because adapter is allocated by rtw_zvmalloc().
47         //_rtw_memset((u8 *)pmlmepriv, 0, sizeof(struct mlme_priv));
48
49         pmlmepriv->nic_hdl = (u8 *)padapter;
50
51         pmlmepriv->pscanned = NULL;
52         pmlmepriv->fw_state = WIFI_STATION_STATE; // Must sync with rtw_wdev_alloc() 
53                                                   // wdev->iftype = NL80211_IFTYPE_STATION
54         pmlmepriv->cur_network.network.InfrastructureMode = Ndis802_11AutoUnknown;
55         pmlmepriv->scan_mode=SCAN_ACTIVE;// 1: active, 0: pasive. Maybe someday we should rename this varable to "active_mode" (Jeff)
56
57         _rtw_spinlock_init(&(pmlmepriv->lock)); 
58         _rtw_init_queue(&(pmlmepriv->free_bss_pool));
59         _rtw_init_queue(&(pmlmepriv->scanned_queue));
60
61         set_scanned_network_val(pmlmepriv, 0);
62         
63         _rtw_memset(&pmlmepriv->assoc_ssid,0,sizeof(NDIS_802_11_SSID));
64
65         pbuf = rtw_zvmalloc(MAX_BSS_CNT * (sizeof(struct wlan_network)));
66         
67         if (pbuf == NULL){
68                 res=_FAIL;
69                 goto exit;
70         }
71         pmlmepriv->free_bss_buf = pbuf;
72                 
73         pnetwork = (struct wlan_network *)pbuf;
74         
75         for(i = 0; i < MAX_BSS_CNT; i++)
76         {               
77                 _rtw_init_listhead(&(pnetwork->list));
78
79                 rtw_list_insert_tail(&(pnetwork->list), &(pmlmepriv->free_bss_pool.queue));
80
81                 pnetwork++;
82         }
83
84         //allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf
85
86         rtw_clear_scan_deny(padapter);
87
88 #ifdef CONFIG_LAYER2_ROAMING
89         #define RTW_ROAM_SCAN_RESULT_EXP_MS 5*1000
90         #define RTW_ROAM_RSSI_DIFF_TH 10
91         #define RTW_ROAM_SCAN_INTERVAL_MS 10*1000
92
93         pmlmepriv->roam_flags = 0
94                 | RTW_ROAM_ON_EXPIRED
95                 #ifdef CONFIG_LAYER2_ROAMING_RESUME
96                 | RTW_ROAM_ON_RESUME
97                 #endif
98                 #ifdef CONFIG_LAYER2_ROAMING_ACTIVE
99                 | RTW_ROAM_ACTIVE
100                 #endif
101                 ;
102
103         pmlmepriv->roam_scanr_exp_ms = RTW_ROAM_SCAN_RESULT_EXP_MS;
104         pmlmepriv->roam_rssi_diff_th = RTW_ROAM_RSSI_DIFF_TH;
105         pmlmepriv->roam_scan_int_ms = RTW_ROAM_SCAN_INTERVAL_MS;
106 #endif /* CONFIG_LAYER2_ROAMING */
107
108         rtw_init_mlme_timer(padapter);
109
110 exit:
111
112 _func_exit_;
113
114         return res;
115 }       
116
117 void rtw_mfree_mlme_priv_lock (struct mlme_priv *pmlmepriv);
118 void rtw_mfree_mlme_priv_lock (struct mlme_priv *pmlmepriv)
119 {
120         _rtw_spinlock_free(&pmlmepriv->lock);
121         _rtw_spinlock_free(&(pmlmepriv->free_bss_pool.lock));
122         _rtw_spinlock_free(&(pmlmepriv->scanned_queue.lock));
123 }
124
125 static void rtw_free_mlme_ie_data(u8 **ppie, u32 *plen)
126 {
127         if(*ppie)
128         {               
129                 rtw_mfree(*ppie, *plen);
130                 *plen = 0;
131                 *ppie=NULL;
132         }       
133 }
134
135 void rtw_free_mlme_priv_ie_data(struct mlme_priv *pmlmepriv)
136 {
137 #if defined (CONFIG_AP_MODE) && defined (CONFIG_NATIVEAP_MLME)
138         rtw_buf_free(&pmlmepriv->assoc_req, &pmlmepriv->assoc_req_len);
139         rtw_buf_free(&pmlmepriv->assoc_rsp, &pmlmepriv->assoc_rsp_len);
140         rtw_free_mlme_ie_data(&pmlmepriv->wps_beacon_ie, &pmlmepriv->wps_beacon_ie_len);
141         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_req_ie, &pmlmepriv->wps_probe_req_ie_len);
142         rtw_free_mlme_ie_data(&pmlmepriv->wps_probe_resp_ie, &pmlmepriv->wps_probe_resp_ie_len);
143         rtw_free_mlme_ie_data(&pmlmepriv->wps_assoc_resp_ie, &pmlmepriv->wps_assoc_resp_ie_len);
144         
145         rtw_free_mlme_ie_data(&pmlmepriv->p2p_beacon_ie, &pmlmepriv->p2p_beacon_ie_len);
146         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_req_ie, &pmlmepriv->p2p_probe_req_ie_len);
147         rtw_free_mlme_ie_data(&pmlmepriv->p2p_probe_resp_ie, &pmlmepriv->p2p_probe_resp_ie_len);
148         rtw_free_mlme_ie_data(&pmlmepriv->p2p_go_probe_resp_ie, &pmlmepriv->p2p_go_probe_resp_ie_len);
149         rtw_free_mlme_ie_data(&pmlmepriv->p2p_assoc_req_ie, &pmlmepriv->p2p_assoc_req_ie_len);
150 #endif
151
152 #if defined(CONFIG_WFD) && defined(CONFIG_IOCTL_CFG80211)       
153         rtw_free_mlme_ie_data(&pmlmepriv->wfd_beacon_ie, &pmlmepriv->wfd_beacon_ie_len);
154         rtw_free_mlme_ie_data(&pmlmepriv->wfd_probe_req_ie, &pmlmepriv->wfd_probe_req_ie_len);
155         rtw_free_mlme_ie_data(&pmlmepriv->wfd_probe_resp_ie, &pmlmepriv->wfd_probe_resp_ie_len);
156         rtw_free_mlme_ie_data(&pmlmepriv->wfd_go_probe_resp_ie, &pmlmepriv->wfd_go_probe_resp_ie_len);
157         rtw_free_mlme_ie_data(&pmlmepriv->wfd_assoc_req_ie, &pmlmepriv->wfd_assoc_req_ie_len);
158 #endif
159
160 }
161
162 void _rtw_free_mlme_priv (struct mlme_priv *pmlmepriv)
163 {
164 _func_enter_;
165
166         rtw_free_mlme_priv_ie_data(pmlmepriv);
167
168         if(pmlmepriv){
169                 rtw_mfree_mlme_priv_lock (pmlmepriv);
170
171                 if (pmlmepriv->free_bss_buf) {
172                         rtw_vmfree(pmlmepriv->free_bss_buf, MAX_BSS_CNT * sizeof(struct wlan_network));
173                 }
174         }
175 _func_exit_;    
176 }
177
178 sint    _rtw_enqueue_network(_queue *queue, struct wlan_network *pnetwork)
179 {
180         _irqL irqL;
181
182 _func_enter_;   
183
184         if (pnetwork == NULL)
185                 goto exit;
186         
187         _enter_critical_bh(&queue->lock, &irqL);
188
189         rtw_list_insert_tail(&pnetwork->list, &queue->queue);
190
191         _exit_critical_bh(&queue->lock, &irqL);
192
193 exit:   
194
195 _func_exit_;            
196
197         return _SUCCESS;
198 }
199
200 /*
201 struct  wlan_network *_rtw_dequeue_network(_queue *queue)
202 {
203         _irqL irqL;
204
205         struct wlan_network *pnetwork;
206
207 _func_enter_;   
208
209         _enter_critical_bh(&queue->lock, &irqL);
210
211         if (_rtw_queue_empty(queue) == _TRUE)
212
213                 pnetwork = NULL;
214         
215         else
216         {
217                 pnetwork = LIST_CONTAINOR(get_next(&queue->queue), struct wlan_network, list);
218                 
219                 rtw_list_delete(&(pnetwork->list));
220         }
221         
222         _exit_critical_bh(&queue->lock, &irqL);
223
224 _func_exit_;            
225
226         return pnetwork;
227 }
228 */
229
230 struct  wlan_network *_rtw_alloc_network(struct mlme_priv *pmlmepriv )//(_queue *free_queue)
231 {
232         _irqL   irqL;
233         struct  wlan_network    *pnetwork;      
234         _queue *free_queue = &pmlmepriv->free_bss_pool;
235         _list* plist = NULL;
236         
237 _func_enter_;   
238
239         _enter_critical_bh(&free_queue->lock, &irqL);
240         
241         if (_rtw_queue_empty(free_queue) == _TRUE) {
242                 pnetwork=NULL;
243                 goto exit;
244         }
245         plist = get_next(&(free_queue->queue));
246         
247         pnetwork = LIST_CONTAINOR(plist , struct wlan_network, list);
248         
249         rtw_list_delete(&pnetwork->list);
250         
251         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("_rtw_alloc_network: ptr=%p\n", plist));
252         pnetwork->network_type = 0;
253         pnetwork->fixed = _FALSE;
254         pnetwork->last_scanned = rtw_get_current_time();
255         pnetwork->aid=0;        
256         pnetwork->join_res=0;
257
258         pmlmepriv->num_of_scanned ++;
259         
260 exit:
261         _exit_critical_bh(&free_queue->lock, &irqL);
262
263 _func_exit_;            
264
265         return pnetwork;        
266 }
267
268 void _rtw_free_network(struct   mlme_priv *pmlmepriv ,struct wlan_network *pnetwork, u8 isfreeall)
269 {
270         u32 delta_time;
271         u32 lifetime = SCANQUEUE_LIFETIME;
272         _irqL irqL;     
273         _queue *free_queue = &(pmlmepriv->free_bss_pool);
274         
275 _func_enter_;           
276
277         if (pnetwork == NULL)
278                 goto exit;
279
280         if (pnetwork->fixed == _TRUE)
281                 goto exit;
282
283         if ( (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)==_TRUE ) || 
284                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)==_TRUE ) )
285                 lifetime = 1;
286
287         if(!isfreeall)
288         {
289                 delta_time = (u32) rtw_get_passing_time_ms(pnetwork->last_scanned);
290                 if(delta_time < lifetime)// unit:msec
291                         goto exit;
292         }
293
294         _enter_critical_bh(&free_queue->lock, &irqL);
295         
296         rtw_list_delete(&(pnetwork->list));
297
298         rtw_list_insert_tail(&(pnetwork->list),&(free_queue->queue));
299                 
300         pmlmepriv->num_of_scanned --;
301         
302
303         //DBG_871X("_rtw_free_network:SSID=%s\n", pnetwork->network.Ssid.Ssid);
304         
305         _exit_critical_bh(&free_queue->lock, &irqL);
306         
307 exit:           
308         
309 _func_exit_;                    
310
311 }
312
313 void _rtw_free_network_nolock(struct    mlme_priv *pmlmepriv, struct wlan_network *pnetwork)
314 {
315
316         _queue *free_queue = &(pmlmepriv->free_bss_pool);
317
318 _func_enter_;           
319
320         if (pnetwork == NULL)
321                 goto exit;
322
323         if (pnetwork->fixed == _TRUE)
324                 goto exit;
325
326         //_enter_critical(&free_queue->lock, &irqL);
327         
328         rtw_list_delete(&(pnetwork->list));
329
330         rtw_list_insert_tail(&(pnetwork->list), get_list_head(free_queue));
331                 
332         pmlmepriv->num_of_scanned --;
333         
334         //_exit_critical(&free_queue->lock, &irqL);
335         
336 exit:           
337
338 _func_exit_;                    
339
340 }
341
342
343 /*
344         return the wlan_network with the matching addr
345
346         Shall be calle under atomic context... to avoid possible racing condition...
347 */
348 struct wlan_network *_rtw_find_network(_queue *scanned_queue, u8 *addr)
349 {
350
351         //_irqL irqL;
352         _list   *phead, *plist;
353         struct  wlan_network *pnetwork = NULL;
354         u8 zero_addr[ETH_ALEN] = {0,0,0,0,0,0};
355         
356 _func_enter_;   
357
358         if(_rtw_memcmp(zero_addr, addr, ETH_ALEN)){
359                 pnetwork=NULL;
360                 goto exit;
361         }
362         
363         //_enter_critical_bh(&scanned_queue->lock, &irqL);
364         
365         phead = get_list_head(scanned_queue);
366         plist = get_next(phead);
367          
368         while (plist != phead)
369        {
370                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network ,list);
371
372                 if (_rtw_memcmp(addr, pnetwork->network.MacAddress, ETH_ALEN) == _TRUE)
373                         break;
374                 
375                 plist = get_next(plist);
376         }
377
378         if(plist == phead)
379                 pnetwork = NULL;
380
381         //_exit_critical_bh(&scanned_queue->lock, &irqL);
382         
383 exit:           
384         
385 _func_exit_;            
386
387         return pnetwork;
388         
389 }
390
391
392 void _rtw_free_network_queue(_adapter *padapter, u8 isfreeall)
393 {
394         _irqL irqL;
395         _list *phead, *plist;
396         struct wlan_network *pnetwork;
397         struct mlme_priv* pmlmepriv = &padapter->mlmepriv;
398         _queue *scanned_queue = &pmlmepriv->scanned_queue;
399
400 _func_enter_;   
401         
402
403         _enter_critical_bh(&scanned_queue->lock, &irqL);
404
405         phead = get_list_head(scanned_queue);
406         plist = get_next(phead);
407
408         while (rtw_end_of_queue_search(phead, plist) == _FALSE)
409         {
410
411                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
412
413                 plist = get_next(plist);
414
415                 _rtw_free_network(pmlmepriv,pnetwork, isfreeall);
416                 
417         }
418
419         _exit_critical_bh(&scanned_queue->lock, &irqL);
420         
421 _func_exit_;            
422
423 }
424
425
426
427
428 sint rtw_if_up(_adapter *padapter)      {
429
430         sint res;
431 _func_enter_;           
432
433         if( padapter->bDriverStopped || padapter->bSurpriseRemoved ||
434                 (check_fwstate(&padapter->mlmepriv, _FW_LINKED)== _FALSE)){             
435                 RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("rtw_if_up:bDriverStopped(%d) OR bSurpriseRemoved(%d)", padapter->bDriverStopped, padapter->bSurpriseRemoved));  
436                 res=_FALSE;
437         }
438         else
439                 res=  _TRUE;
440         
441 _func_exit_;
442         return res;
443 }
444
445
446 void rtw_generate_random_ibss(u8* pibss)
447 {
448         u32     curtime = rtw_get_current_time();
449
450 _func_enter_;
451         pibss[0] = 0x02;  //in ad-hoc mode bit1 must set to 1
452         pibss[1] = 0x11;
453         pibss[2] = 0x87;
454         pibss[3] = (u8)(curtime & 0xff) ;//p[0];
455         pibss[4] = (u8)((curtime>>8) & 0xff) ;//p[1];
456         pibss[5] = (u8)((curtime>>16) & 0xff) ;//p[2];
457 _func_exit_;
458         return;
459 }
460
461 u8 *rtw_get_capability_from_ie(u8 *ie)
462 {
463         return (ie + 8 + 2);
464 }
465
466
467 u16 rtw_get_capability(WLAN_BSSID_EX *bss)
468 {
469         u16     val;
470 _func_enter_;   
471
472         _rtw_memcpy((u8 *)&val, rtw_get_capability_from_ie(bss->IEs), 2); 
473
474 _func_exit_;            
475         return le16_to_cpu(val);
476 }
477
478 u8 *rtw_get_timestampe_from_ie(u8 *ie)
479 {
480         return (ie + 0);        
481 }
482
483 u8 *rtw_get_beacon_interval_from_ie(u8 *ie)
484 {
485         return (ie + 8);        
486 }
487
488
489 int     rtw_init_mlme_priv (_adapter *padapter)//(struct        mlme_priv *pmlmepriv)
490 {
491         int     res;
492 _func_enter_;   
493         res = _rtw_init_mlme_priv(padapter);// (pmlmepriv);
494 _func_exit_;    
495         return res;
496 }
497
498 void rtw_free_mlme_priv (struct mlme_priv *pmlmepriv)
499 {
500 _func_enter_;
501         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_free_mlme_priv\n"));
502         _rtw_free_mlme_priv (pmlmepriv);
503 _func_exit_;    
504 }
505
506 int     rtw_enqueue_network(_queue *queue, struct wlan_network *pnetwork);
507 int     rtw_enqueue_network(_queue *queue, struct wlan_network *pnetwork)
508 {
509         int     res;
510 _func_enter_;           
511         res = _rtw_enqueue_network(queue, pnetwork);
512 _func_exit_;            
513         return res;
514 }
515
516 /*
517 static struct   wlan_network *rtw_dequeue_network(_queue *queue)
518 {
519         struct wlan_network *pnetwork;
520 _func_enter_;           
521         pnetwork = _rtw_dequeue_network(queue);
522 _func_exit_;            
523         return pnetwork;
524 }
525 */
526
527 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv );
528 struct  wlan_network *rtw_alloc_network(struct  mlme_priv *pmlmepriv )//(_queue *free_queue)
529 {
530         struct  wlan_network    *pnetwork;
531 _func_enter_;                   
532         pnetwork = _rtw_alloc_network(pmlmepriv);
533 _func_exit_;                    
534         return pnetwork;
535 }
536
537 void rtw_free_network(struct mlme_priv *pmlmepriv, struct       wlan_network *pnetwork, u8 is_freeall);
538 void rtw_free_network(struct mlme_priv *pmlmepriv, struct       wlan_network *pnetwork, u8 is_freeall)//(struct wlan_network *pnetwork, _queue  *free_queue)
539 {
540 _func_enter_;           
541         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_free_network==> ssid = %s \n\n" , pnetwork->network.Ssid.Ssid));
542         _rtw_free_network(pmlmepriv, pnetwork, is_freeall);
543 _func_exit_;            
544 }
545
546 void rtw_free_network_nolock(struct mlme_priv *pmlmepriv, struct wlan_network *pnetwork );
547 void rtw_free_network_nolock(struct mlme_priv *pmlmepriv, struct wlan_network *pnetwork )
548 {
549 _func_enter_;           
550         //RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_free_network==> ssid = %s \n\n" , pnetwork->network.Ssid.Ssid));
551         _rtw_free_network_nolock(pmlmepriv, pnetwork);
552 _func_exit_;            
553 }
554
555
556 void rtw_free_network_queue(_adapter* dev, u8 isfreeall)
557 {
558 _func_enter_;           
559         _rtw_free_network_queue(dev, isfreeall);
560 _func_exit_;                    
561 }
562
563 /*
564         return the wlan_network with the matching addr
565
566         Shall be calle under atomic context... to avoid possible racing condition...
567 */
568 struct  wlan_network *rtw_find_network(_queue *scanned_queue, u8 *addr)
569 {
570         struct  wlan_network *pnetwork = _rtw_find_network(scanned_queue, addr);
571
572         return pnetwork;
573 }
574
575 int rtw_is_same_ibss(_adapter *adapter, struct wlan_network *pnetwork)
576 {
577         int ret=_TRUE;
578         struct security_priv *psecuritypriv = &adapter->securitypriv;
579
580         if ( (psecuritypriv->dot11PrivacyAlgrthm != _NO_PRIVACY_ ) &&
581                     ( pnetwork->network.Privacy == 0 ) )
582         {
583                 ret=_FALSE;
584         }
585         else if((psecuritypriv->dot11PrivacyAlgrthm == _NO_PRIVACY_ ) &&
586                  ( pnetwork->network.Privacy == 1 ) )
587         {
588                 ret=_FALSE;
589         }
590         else
591         {
592                 ret=_TRUE;
593         }
594         
595         return ret;
596         
597 }
598
599 inline int is_same_ess(WLAN_BSSID_EX *a, WLAN_BSSID_EX *b)
600 {
601         //RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("(%s,%d)(%s,%d)\n",
602         //              a->Ssid.Ssid,a->Ssid.SsidLength,b->Ssid.Ssid,b->Ssid.SsidLength));
603         return (a->Ssid.SsidLength == b->Ssid.SsidLength) 
604                 &&  _rtw_memcmp(a->Ssid.Ssid, b->Ssid.Ssid, a->Ssid.SsidLength)==_TRUE;
605 }
606
607 int is_same_network(WLAN_BSSID_EX *src, WLAN_BSSID_EX *dst, u8 feature)
608 {
609          u16 s_cap, d_cap;
610          
611 _func_enter_;   
612
613         if(rtw_bug_check(dst, src, &s_cap, &d_cap)==_FALSE)
614                         return _FALSE;
615
616         _rtw_memcpy((u8 *)&s_cap, rtw_get_capability_from_ie(src->IEs), 2);
617         _rtw_memcpy((u8 *)&d_cap, rtw_get_capability_from_ie(dst->IEs), 2);
618
619         
620         s_cap = le16_to_cpu(s_cap);
621         d_cap = le16_to_cpu(d_cap);
622         
623 _func_exit_;                    
624
625 #ifdef CONFIG_P2P
626         if ((feature == 1) && // 1: P2P supported
627                 (_rtw_memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN) == _TRUE)
628                 ) {
629                 return _TRUE;
630         }
631 #endif
632
633         return ((src->Ssid.SsidLength == dst->Ssid.SsidLength) &&
634                 //      (src->Configuration.DSConfig == dst->Configuration.DSConfig) &&
635                         ( (_rtw_memcmp(src->MacAddress, dst->MacAddress, ETH_ALEN)) == _TRUE) &&
636                         ( (_rtw_memcmp(src->Ssid.Ssid, dst->Ssid.Ssid, src->Ssid.SsidLength)) == _TRUE) &&
637                         ((s_cap & WLAN_CAPABILITY_IBSS) == 
638                         (d_cap & WLAN_CAPABILITY_IBSS)) &&
639                         ((s_cap & WLAN_CAPABILITY_BSS) == 
640                         (d_cap & WLAN_CAPABILITY_BSS)));
641         
642 }
643
644 struct wlan_network *_rtw_find_same_network(_queue *scanned_queue, struct wlan_network *network)
645 {
646         _list *phead, *plist;
647         struct wlan_network *found = NULL;
648
649         phead = get_list_head(scanned_queue);
650         plist = get_next(phead);
651
652         while (plist != phead) {
653                 found = LIST_CONTAINOR(plist, struct wlan_network ,list);
654
655                 if (is_same_network(&network->network, &found->network,0))
656                         break;
657
658                 plist = get_next(plist);
659         }
660
661         if(plist == phead)
662                 found = NULL;
663 exit:           
664         return found;
665 }
666
667 struct wlan_network *rtw_find_same_network(_queue *scanned_queue, struct wlan_network *network)
668 {
669         _irqL irqL;
670         struct wlan_network *found = NULL;
671
672         if (scanned_queue == NULL || network == NULL)
673                 goto exit;      
674
675         _enter_critical_bh(&scanned_queue->lock, &irqL);
676         found = _rtw_find_same_network(scanned_queue, network);
677         _exit_critical_bh(&scanned_queue->lock, &irqL);
678
679 exit:
680         return found;
681 }
682
683 struct  wlan_network    * rtw_get_oldest_wlan_network(_queue *scanned_queue)
684 {
685         _list   *plist, *phead;
686
687         
688         struct  wlan_network    *pwlan = NULL;
689         struct  wlan_network    *oldest = NULL;
690 _func_enter_;           
691         phead = get_list_head(scanned_queue);
692         
693         plist = get_next(phead);
694
695         while(1)
696         {
697                 
698                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
699                         break;
700                 
701                 pwlan= LIST_CONTAINOR(plist, struct wlan_network, list);
702
703                 if(pwlan->fixed!=_TRUE)
704                 {               
705                         if (oldest == NULL ||time_after(oldest->last_scanned, pwlan->last_scanned))
706                                 oldest = pwlan;
707                 }
708                 
709                 plist = get_next(plist);
710         }
711 _func_exit_;            
712         return oldest;
713         
714 }
715
716 void update_network(WLAN_BSSID_EX *dst, WLAN_BSSID_EX *src,
717         _adapter * padapter, bool update_ie)
718 {
719         u8 ss_ori = dst->PhyInfo.SignalStrength;
720         u8 sq_ori = dst->PhyInfo.SignalQuality;
721         long rssi_ori = dst->Rssi;
722
723         u8 ss_smp = src->PhyInfo.SignalStrength;
724         u8 sq_smp = src->PhyInfo.SignalQuality;
725         long rssi_smp = src->Rssi;
726
727         u8 ss_final;
728         u8 sq_final;
729         long rssi_final;
730
731 _func_enter_;           
732
733 #ifdef CONFIG_ANTENNA_DIVERSITY
734         rtw_hal_antdiv_rssi_compared(padapter, dst, src); //this will update src.Rssi, need consider again
735 #endif
736
737         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
738         if(strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
739                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT", ch%u) ss_ori:%3u, sq_ori:%3u, rssi_ori:%3ld, ss_smp:%3u, sq_smp:%3u, rssi_smp:%3ld\n"
740                         , FUNC_ADPT_ARG(padapter)
741                         , src->Ssid.Ssid, MAC_ARG(src->MacAddress), src->Configuration.DSConfig
742                         ,ss_ori, sq_ori, rssi_ori
743                         ,ss_smp, sq_smp, rssi_smp
744                 );
745         }
746         #endif
747
748         /* The rule below is 1/5 for sample value, 4/5 for history value */
749         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src, 0)) {
750                 /* Take the recvpriv's value for the connected AP*/
751                 ss_final = padapter->recvpriv.signal_strength;
752                 sq_final = padapter->recvpriv.signal_qual;
753                 /* the rssi value here is undecorated, and will be used for antenna diversity */
754                 if(sq_smp != 101) /* from the right channel */
755                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
756                 else
757                         rssi_final = rssi_ori;
758         }
759         else {
760                 if(sq_smp != 101) { /* from the right channel */
761                         ss_final = ((u32)(src->PhyInfo.SignalStrength)+(u32)(dst->PhyInfo.SignalStrength)*4)/5;
762                         sq_final = ((u32)(src->PhyInfo.SignalQuality)+(u32)(dst->PhyInfo.SignalQuality)*4)/5;
763                         rssi_final = (src->Rssi+dst->Rssi*4)/5;
764                 } else {
765                         /* bss info not receving from the right channel, use the original RX signal infos */
766                         ss_final = dst->PhyInfo.SignalStrength;
767                         sq_final = dst->PhyInfo.SignalQuality;
768                         rssi_final = dst->Rssi;
769                 }
770                 
771         }
772
773         if (update_ie) {
774                 dst->Reserved[0] = src->Reserved[0];
775                 dst->Reserved[1] = src->Reserved[1];
776                 _rtw_memcpy((u8 *)dst, (u8 *)src, get_WLAN_BSSID_EX_sz(src));
777         }
778
779         dst->PhyInfo.SignalStrength = ss_final;
780         dst->PhyInfo.SignalQuality = sq_final;
781         dst->Rssi = rssi_final;
782
783         #if defined(DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) && 1
784         if(strcmp(dst->Ssid.Ssid, DBG_RX_SIGNAL_DISPLAY_SSID_MONITORED) == 0) {
785                 DBG_871X(FUNC_ADPT_FMT" %s("MAC_FMT"), SignalStrength:%u, SignalQuality:%u, RawRSSI:%ld\n"
786                         , FUNC_ADPT_ARG(padapter)
787                         , dst->Ssid.Ssid, MAC_ARG(dst->MacAddress), dst->PhyInfo.SignalStrength, dst->PhyInfo.SignalQuality, dst->Rssi);
788         }
789         #endif
790
791 #if 0 // old codes, may be useful one day...
792 //      DBG_871X("update_network: rssi=0x%lx dst->Rssi=%d ,dst->Rssi=0x%lx , src->Rssi=0x%lx",(dst->Rssi+src->Rssi)/2,dst->Rssi,dst->Rssi,src->Rssi);
793         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) && is_same_network(&(padapter->mlmepriv.cur_network.network), src))
794         {
795         
796                 //DBG_871X("b:ssid=%s update_network: src->rssi=0x%d padapter->recvpriv.ui_rssi=%d\n",src->Ssid.Ssid,src->Rssi,padapter->recvpriv.signal);
797                 if(padapter->recvpriv.signal_qual_data.total_num++ >= PHY_LINKQUALITY_SLID_WIN_MAX)
798                 {
799                       padapter->recvpriv.signal_qual_data.total_num = PHY_LINKQUALITY_SLID_WIN_MAX;
800                       last_evm = padapter->recvpriv.signal_qual_data.elements[padapter->recvpriv.signal_qual_data.index];
801                       padapter->recvpriv.signal_qual_data.total_val -= last_evm;
802                 }
803                 padapter->recvpriv.signal_qual_data.total_val += query_rx_pwr_percentage(src->Rssi);
804
805                 padapter->recvpriv.signal_qual_data.elements[padapter->recvpriv.signal_qual_data.index++] = query_rx_pwr_percentage(src->Rssi);
806                 if(padapter->recvpriv.signal_qual_data.index >= PHY_LINKQUALITY_SLID_WIN_MAX)
807                        padapter->recvpriv.signal_qual_data.index = 0;
808
809                 //DBG_871X("Total SQ=%d  pattrib->signal_qual= %d\n", padapter->recvpriv.signal_qual_data.total_val, src->Rssi);
810
811                 // <1> Showed on UI for user,in percentage.
812                 tmpVal = padapter->recvpriv.signal_qual_data.total_val/padapter->recvpriv.signal_qual_data.total_num;
813                 padapter->recvpriv.signal=(u8)tmpVal;//Link quality
814
815                 src->Rssi= translate_percentage_to_dbm(padapter->recvpriv.signal) ;
816         }
817         else{
818 //      DBG_871X("ELSE:ssid=%s update_network: src->rssi=0x%d dst->rssi=%d\n",src->Ssid.Ssid,src->Rssi,dst->Rssi);
819                 src->Rssi=(src->Rssi +dst->Rssi)/2;//dBM
820         }       
821
822 //      DBG_871X("a:update_network: src->rssi=0x%d padapter->recvpriv.ui_rssi=%d\n",src->Rssi,padapter->recvpriv.signal);
823
824 #endif
825
826 _func_exit_;            
827 }
828
829 static void update_current_network(_adapter *adapter, WLAN_BSSID_EX *pnetwork)
830 {
831         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
832         
833 _func_enter_;           
834
835         rtw_bug_check(&(pmlmepriv->cur_network.network), 
836                 &(pmlmepriv->cur_network.network), 
837                 &(pmlmepriv->cur_network.network), 
838                 &(pmlmepriv->cur_network.network));
839
840         if ( (check_fwstate(pmlmepriv, _FW_LINKED)== _TRUE) && (is_same_network(&(pmlmepriv->cur_network.network), pnetwork, 0)))
841         {
842                 //RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,"Same Network\n");
843
844                 //if(pmlmepriv->cur_network.network.IELength<= pnetwork->IELength)
845                 {
846                         update_network(&(pmlmepriv->cur_network.network), pnetwork,adapter, _TRUE);
847                         rtw_update_protection(adapter, (pmlmepriv->cur_network.network.IEs) + sizeof (NDIS_802_11_FIXED_IEs), 
848                                                                         pmlmepriv->cur_network.network.IELength);
849                 }
850         }
851
852 _func_exit_;                    
853
854 }
855
856
857 /*
858
859 Caller must hold pmlmepriv->lock first.
860
861
862 */
863 void rtw_update_scanned_network(_adapter *adapter, WLAN_BSSID_EX *target)
864 {
865         _irqL irqL;
866         _list   *plist, *phead;
867         ULONG   bssid_ex_sz;
868         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
869         struct mlme_ext_priv    *pmlmeext = &(adapter->mlmeextpriv);
870         struct wifidirect_info *pwdinfo= &(adapter->wdinfo);    
871         _queue  *queue  = &(pmlmepriv->scanned_queue);
872         struct wlan_network     *pnetwork = NULL;
873         struct wlan_network     *oldest = NULL;
874         int target_find = 0;
875         u8 feature = 0;    
876
877 _func_enter_;
878
879         _enter_critical_bh(&queue->lock, &irqL);
880         phead = get_list_head(queue);
881         plist = get_next(phead);
882
883 #ifdef CONFIG_P2P
884         if (!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
885                 feature = 1; // p2p enable
886 #endif
887
888         while(1)
889         {
890                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
891                         break;
892
893                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
894
895                 rtw_bug_check(pnetwork, pnetwork, pnetwork, pnetwork);
896
897 #ifdef CONFIG_P2P
898                 if (!rtw_p2p_chk_state(&(adapter->wdinfo), P2P_STATE_NONE) &&
899                         (_rtw_memcmp(pnetwork->network.MacAddress, target->MacAddress, ETH_ALEN) == _TRUE))
900                 {
901                         target_find = 1;
902                         break;
903                 }
904 #endif
905
906                 if (is_same_network(&(pnetwork->network), target, feature))
907                 {
908                         target_find = 1;
909                         break;
910                 }
911
912                 if (rtw_roam_flags(adapter)) {
913                         /* TODO: don't  select netowrk in the same ess as oldest if it's new enough*/
914                 }
915
916                 if (oldest == NULL || time_after(oldest->last_scanned, pnetwork->last_scanned))
917                         oldest = pnetwork;
918
919                 plist = get_next(plist);
920
921         }
922         
923         
924         /* If we didn't find a match, then get a new network slot to initialize
925          * with this beacon's information */
926         //if (rtw_end_of_queue_search(phead,plist)== _TRUE) {
927         if (!target_find) {             
928                 if (_rtw_queue_empty(&(pmlmepriv->free_bss_pool)) == _TRUE) {
929                         /* If there are no more slots, expire the oldest */
930                         //list_del_init(&oldest->list);
931                         pnetwork = oldest;
932                         if(pnetwork==NULL){ 
933                                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n\n\nsomething wrong here\n\n\n"));
934                                 goto exit;
935                         }
936 #ifdef CONFIG_ANTENNA_DIVERSITY
937                         //target->PhyInfo.Optimum_antenna = pHalData->CurAntenna;//optimum_antenna=>For antenna diversity
938                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
939 #endif
940                         _rtw_memcpy(&(pnetwork->network), target,  get_WLAN_BSSID_EX_sz(target));
941                         //pnetwork->last_scanned = rtw_get_current_time();
942                         // variable initialize
943                         pnetwork->fixed = _FALSE;
944                         pnetwork->last_scanned = rtw_get_current_time();
945
946                         pnetwork->network_type = 0;     
947                         pnetwork->aid=0;                
948                         pnetwork->join_res=0;
949
950                         /* bss info not receving from the right channel */
951                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
952                                 pnetwork->network.PhyInfo.SignalQuality = 0;
953                 }
954                 else {
955                         /* Otherwise just pull from the free list */
956
957                         pnetwork = rtw_alloc_network(pmlmepriv); // will update scan_time
958
959                         if(pnetwork==NULL){ 
960                                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n\n\nsomething wrong here\n\n\n"));
961                                 goto exit;
962                         }
963
964                         bssid_ex_sz = get_WLAN_BSSID_EX_sz(target);
965                         target->Length = bssid_ex_sz;
966 #ifdef CONFIG_ANTENNA_DIVERSITY
967                         //target->PhyInfo.Optimum_antenna = pHalData->CurAntenna;
968                         rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(target->PhyInfo.Optimum_antenna));
969 #endif
970                         _rtw_memcpy(&(pnetwork->network), target, bssid_ex_sz );
971
972                         pnetwork->last_scanned = rtw_get_current_time();
973
974                         /* bss info not receving from the right channel */
975                         if (pnetwork->network.PhyInfo.SignalQuality == 101)
976                                 pnetwork->network.PhyInfo.SignalQuality = 0;
977
978                         rtw_list_insert_tail(&(pnetwork->list),&(queue->queue)); 
979
980                 }
981         }
982         else {
983                 /* we have an entry and we are going to update it. But this entry may
984                  * be already expired. In this case we do the same as we found a new 
985                  * net and call the new_net handler
986                  */
987                 bool update_ie = _TRUE;
988
989                 pnetwork->last_scanned = rtw_get_current_time();
990
991                 //target.Reserved[0]==1, means that scaned network is a bcn frame.
992                 if((pnetwork->network.IELength>target->IELength) && (target->Reserved[0]==1))
993                         update_ie = _FALSE;
994
995                 // probe resp(3) > beacon(1) > probe req(2)
996                 if ((target->Reserved[0] != 2) &&
997                         (target->Reserved[0] >= pnetwork->network.Reserved[0])
998                         ) {
999                         update_ie = _TRUE;
1000                 }
1001                 else {
1002                         update_ie = _FALSE;
1003                 }
1004
1005                 update_network(&(pnetwork->network), target,adapter, update_ie);
1006         }
1007
1008 exit:
1009         _exit_critical_bh(&queue->lock, &irqL);
1010
1011 _func_exit_;
1012 }
1013
1014 void rtw_add_network(_adapter *adapter, WLAN_BSSID_EX *pnetwork);
1015 void rtw_add_network(_adapter *adapter, WLAN_BSSID_EX *pnetwork)
1016 {
1017         _irqL irqL;
1018         struct  mlme_priv       *pmlmepriv = &(((_adapter *)adapter)->mlmepriv);
1019         //_queue        *queue  = &(pmlmepriv->scanned_queue);
1020
1021 _func_enter_;           
1022
1023         //_enter_critical_bh(&queue->lock, &irqL);
1024
1025         #if defined(CONFIG_P2P) && defined(CONFIG_P2P_REMOVE_GROUP_INFO)
1026         rtw_WLAN_BSSID_EX_remove_p2p_attr(pnetwork, P2P_ATTR_GROUP_INFO);
1027         #endif
1028         
1029         update_current_network(adapter, pnetwork);
1030         
1031         rtw_update_scanned_network(adapter, pnetwork);
1032
1033         //_exit_critical_bh(&queue->lock, &irqL);
1034         
1035 _func_exit_;            
1036 }
1037
1038 //select the desired network based on the capability of the (i)bss.
1039 // check items: (1) security
1040 //                         (2) network_type
1041 //                         (3) WMM
1042 //                         (4) HT
1043 //                     (5) others
1044 int rtw_is_desired_network(_adapter *adapter, struct wlan_network *pnetwork);
1045 int rtw_is_desired_network(_adapter *adapter, struct wlan_network *pnetwork)
1046 {
1047         struct security_priv *psecuritypriv = &adapter->securitypriv;
1048         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
1049         u32 desired_encmode;
1050         u32 privacy;
1051
1052         //u8 wps_ie[512];
1053         uint wps_ielen;
1054
1055         int bselected = _TRUE;
1056         
1057         desired_encmode = psecuritypriv->ndisencryptstatus;
1058         privacy = pnetwork->network.Privacy;
1059
1060         if(check_fwstate(pmlmepriv, WIFI_UNDER_WPS))
1061         {
1062                 if(rtw_get_wps_ie(pnetwork->network.IEs+_FIXED_IE_LENGTH_, pnetwork->network.IELength-_FIXED_IE_LENGTH_, NULL, &wps_ielen)!=NULL)
1063                 {
1064                         return _TRUE;
1065                 }
1066                 else
1067                 {       
1068                         return _FALSE;
1069                 }       
1070         }
1071         if (adapter->registrypriv.wifi_spec == 1) //for  correct flow of 8021X  to do....
1072         {
1073                 u8 *p=NULL;
1074                 uint ie_len=0;
1075
1076                 if ((desired_encmode == Ndis802_11EncryptionDisabled) && (privacy != 0))
1077                     bselected = _FALSE;
1078
1079                 if ( psecuritypriv->ndisauthtype == Ndis802_11AuthModeWPA2PSK) {
1080                         p = rtw_get_ie(pnetwork->network.IEs + _BEACON_IE_OFFSET_, _RSN_IE_2_, &ie_len, (pnetwork->network.IELength - _BEACON_IE_OFFSET_));
1081                         if (p && ie_len>0) {
1082                                 bselected = _TRUE;
1083                         } else {
1084                                 bselected = _FALSE;
1085                         }
1086                 }
1087         }
1088         
1089
1090         if ((desired_encmode != Ndis802_11EncryptionDisabled) && (privacy == 0)) {
1091                 DBG_871X("desired_encmode: %d, privacy: %d\n", desired_encmode, privacy);
1092                 bselected = _FALSE;
1093         }
1094
1095         if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE)
1096         {
1097                 if(pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
1098                         bselected = _FALSE;
1099         }       
1100                 
1101
1102         return bselected;
1103 }
1104
1105 /* TODO: Perry : For Power Management */
1106 void rtw_atimdone_event_callback(_adapter       *adapter , u8 *pbuf)
1107 {
1108
1109 _func_enter_;           
1110         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("receive atimdone_evet\n"));        
1111 _func_exit_;                    
1112         return; 
1113 }
1114
1115
1116 void rtw_survey_event_callback(_adapter *adapter, u8 *pbuf)
1117 {
1118         _irqL  irqL;
1119         u32 len;
1120         WLAN_BSSID_EX *pnetwork;
1121         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
1122
1123 _func_enter_;           
1124
1125         pnetwork = (WLAN_BSSID_EX *)pbuf;
1126
1127         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_survey_event_callback, ssid=%s\n",  pnetwork->Ssid.Ssid));
1128
1129 #ifdef CONFIG_RTL8712
1130         //endian_convert
1131         pnetwork->Length = le32_to_cpu(pnetwork->Length);
1132         pnetwork->Ssid.SsidLength = le32_to_cpu(pnetwork->Ssid.SsidLength);     
1133         pnetwork->Privacy =le32_to_cpu( pnetwork->Privacy);
1134         pnetwork->Rssi = le32_to_cpu(pnetwork->Rssi);
1135         pnetwork->NetworkTypeInUse =le32_to_cpu(pnetwork->NetworkTypeInUse);    
1136         pnetwork->Configuration.ATIMWindow = le32_to_cpu(pnetwork->Configuration.ATIMWindow);
1137         pnetwork->Configuration.BeaconPeriod = le32_to_cpu(pnetwork->Configuration.BeaconPeriod);
1138         pnetwork->Configuration.DSConfig =le32_to_cpu(pnetwork->Configuration.DSConfig);
1139         pnetwork->Configuration.FHConfig.DwellTime=le32_to_cpu(pnetwork->Configuration.FHConfig.DwellTime);
1140         pnetwork->Configuration.FHConfig.HopPattern=le32_to_cpu(pnetwork->Configuration.FHConfig.HopPattern);
1141         pnetwork->Configuration.FHConfig.HopSet=le32_to_cpu(pnetwork->Configuration.FHConfig.HopSet);
1142         pnetwork->Configuration.FHConfig.Length=le32_to_cpu(pnetwork->Configuration.FHConfig.Length);   
1143         pnetwork->Configuration.Length = le32_to_cpu(pnetwork->Configuration.Length);
1144         pnetwork->InfrastructureMode = le32_to_cpu(pnetwork->InfrastructureMode);
1145         pnetwork->IELength = le32_to_cpu(pnetwork->IELength);
1146 #endif  
1147
1148         len = get_WLAN_BSSID_EX_sz(pnetwork);
1149         if(len > (sizeof(WLAN_BSSID_EX)))
1150         {
1151                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n ****rtw_survey_event_callback: return a wrong bss ***\n"));
1152                 return;
1153         }
1154
1155
1156         _enter_critical_bh(&pmlmepriv->lock, &irqL);
1157
1158         // update IBSS_network 's timestamp
1159         if ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == _TRUE)
1160         {
1161                 //RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,"rtw_survey_event_callback : WIFI_ADHOC_MASTER_STATE \n\n");
1162                 if(_rtw_memcmp(&(pmlmepriv->cur_network.network.MacAddress), pnetwork->MacAddress, ETH_ALEN))
1163                 {
1164                         struct wlan_network* ibss_wlan = NULL;
1165                         _irqL   irqL;
1166                         
1167                         _rtw_memcpy(pmlmepriv->cur_network.network.IEs, pnetwork->IEs, 8);
1168                         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
1169                         ibss_wlan = rtw_find_network(&pmlmepriv->scanned_queue,  pnetwork->MacAddress);
1170                         if(ibss_wlan)
1171                         {
1172                                 _rtw_memcpy(ibss_wlan->network.IEs , pnetwork->IEs, 8);                 
1173                                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);             
1174                                 goto exit;
1175                         }
1176                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
1177                 }
1178         }
1179
1180         // lock pmlmepriv->lock when you accessing network_q
1181         if ((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == _FALSE)
1182         {               
1183                 if( pnetwork->Ssid.Ssid[0] == 0 )
1184                 {
1185                         pnetwork->Ssid.SsidLength = 0;
1186                 }       
1187                 rtw_add_network(adapter, pnetwork);
1188         }       
1189
1190 exit:   
1191                 
1192         _exit_critical_bh(&pmlmepriv->lock, &irqL);
1193
1194 _func_exit_;            
1195
1196         return; 
1197 }
1198
1199
1200
1201 void rtw_surveydone_event_callback(_adapter     *adapter, u8 *pbuf)
1202 {
1203         _irqL  irqL;
1204         u8 timer_cancelled = _FALSE;
1205         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
1206         
1207 #ifdef CONFIG_MLME_EXT  
1208
1209         mlmeext_surveydone_event_callback(adapter);
1210
1211 #endif
1212
1213 _func_enter_;                   
1214
1215         _enter_critical_bh(&pmlmepriv->lock, &irqL);
1216         if(pmlmepriv->wps_probe_req_ie)
1217         {
1218                 u32 free_len = pmlmepriv->wps_probe_req_ie_len;
1219                 pmlmepriv->wps_probe_req_ie_len = 0;
1220                 rtw_mfree(pmlmepriv->wps_probe_req_ie, free_len);
1221                 pmlmepriv->wps_probe_req_ie = NULL;                     
1222         }
1223         
1224         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_surveydone_event_callback: fw_state:%x\n\n", get_fwstate(pmlmepriv)));
1225         
1226         if (check_fwstate(pmlmepriv,_FW_UNDER_SURVEY))
1227         {
1228                 //u8 timer_cancelled;
1229
1230                 timer_cancelled = _TRUE;
1231                 //_cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
1232                 
1233                 _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1234         }
1235         else {
1236         
1237                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("nic status =%x, survey done event comes too late!\n", get_fwstate(pmlmepriv)));    
1238         }
1239         _exit_critical_bh(&pmlmepriv->lock, &irqL);
1240
1241         if(timer_cancelled)
1242                 _cancel_timer(&pmlmepriv->scan_to_timer, &timer_cancelled);
1243
1244
1245         _enter_critical_bh(&pmlmepriv->lock, &irqL);
1246
1247         #ifdef CONFIG_NEW_SIGNAL_STAT_PROCESS
1248         rtw_set_signal_stat_timer(&adapter->recvpriv);
1249         #endif
1250
1251         if(pmlmepriv->to_join == _TRUE)
1252         {
1253                 if((check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)==_TRUE) )
1254                 {
1255                         if(check_fwstate(pmlmepriv, _FW_LINKED)==_FALSE)
1256                         {
1257                                 set_fwstate(pmlmepriv, _FW_UNDER_LINKING);      
1258                                 
1259                                 if(rtw_select_and_join_from_scanned_queue(pmlmepriv)==_SUCCESS)
1260                                 {
1261                                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT );
1262                                 }
1263                                 else    
1264                                 {
1265                                         WLAN_BSSID_EX    *pdev_network = &(adapter->registrypriv.dev_network);                  
1266                                         u8 *pibss = adapter->registrypriv.dev_network.MacAddress;
1267
1268                                         //pmlmepriv->fw_state ^= _FW_UNDER_SURVEY;//because don't set assoc_timer
1269                                         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1270
1271                                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("switching to adhoc master\n"));
1272                                 
1273                                         _rtw_memset(&pdev_network->Ssid, 0, sizeof(NDIS_802_11_SSID));
1274                                         _rtw_memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(NDIS_802_11_SSID));
1275         
1276                                         rtw_update_registrypriv_dev_network(adapter);
1277                                         rtw_generate_random_ibss(pibss);
1278
1279                                         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
1280                         
1281                                         if(rtw_createbss_cmd(adapter)!=_SUCCESS)
1282                                         {
1283                                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Error=>rtw_createbss_cmd status FAIL\n"));                                         
1284                                         }       
1285
1286                                         pmlmepriv->to_join = _FALSE;
1287                                 }
1288                         }
1289                 }
1290                 else
1291                 {
1292                         int s_ret;
1293                         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
1294                         pmlmepriv->to_join = _FALSE;
1295                         if(_SUCCESS == (s_ret=rtw_select_and_join_from_scanned_queue(pmlmepriv)))
1296                         {
1297                              _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);      
1298                         }
1299                         else if(s_ret == 2)//there is no need to wait for join
1300                         {
1301                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1302                                 rtw_indicate_connect(adapter);
1303                         }
1304                         else
1305                         {
1306                                 DBG_871X("try_to_join, but select scanning queue fail, to_roam:%d\n", rtw_to_roam(adapter));
1307
1308                                 if (rtw_to_roam(adapter) != 0) {
1309                                         if(rtw_dec_to_roam(adapter) == 0
1310                                                 || _SUCCESS != rtw_sitesurvey_cmd(adapter, &pmlmepriv->assoc_ssid, 1, NULL, 0)
1311                                         ) {
1312                                                 rtw_set_to_roam(adapter, 0);
1313 #ifdef CONFIG_INTEL_WIDI
1314                                                 if(adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING)
1315                                                 {
1316                                                         _rtw_memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1317                                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1318                                                         DBG_871X("change to widi listen\n");
1319                                                 }
1320 #endif // CONFIG_INTEL_WIDI
1321                                                 rtw_free_assoc_resources(adapter, 1);
1322                                                 rtw_indicate_disconnect(adapter);
1323                                         } else {
1324                                                 pmlmepriv->to_join = _TRUE;
1325                                         }
1326                                 }
1327                                 else
1328                                 {
1329                                         rtw_indicate_disconnect(adapter);
1330                                 }
1331                                 _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1332                         }
1333                 }
1334         } else {
1335                 if (rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
1336                         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)
1337                                 && check_fwstate(pmlmepriv, _FW_LINKED))
1338                         {
1339                                 if (rtw_select_roaming_candidate(pmlmepriv) == _SUCCESS) {
1340                                         receive_disconnect(adapter, pmlmepriv->cur_network.network.MacAddress
1341                                                 , WLAN_REASON_ACTIVE_ROAM);
1342                                 }
1343                         }
1344                 }
1345         }
1346         
1347         //DBG_871X("scan complete in %dms\n",rtw_get_passing_time_ms(pmlmepriv->scan_start_time));
1348
1349         _exit_critical_bh(&pmlmepriv->lock, &irqL);
1350
1351 #ifdef CONFIG_P2P_PS
1352         if (check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE) {
1353                 p2p_ps_wk_cmd(adapter, P2P_PS_SCAN_DONE, 0);
1354         }
1355 #endif // CONFIG_P2P_PS
1356
1357         rtw_os_xmit_schedule(adapter);
1358 #ifdef CONFIG_CONCURRENT_MODE   
1359         rtw_os_xmit_schedule(adapter->pbuddy_adapter);
1360 #endif
1361 #ifdef CONFIG_DUALMAC_CONCURRENT
1362         dc_resume_xmit(adapter);
1363 #endif
1364
1365 #ifdef CONFIG_DRVEXT_MODULE_WSC
1366         drvext_surveydone_callback(&adapter->drvextpriv);
1367 #endif
1368
1369 #ifdef DBG_CONFIG_ERROR_DETECT
1370         {
1371                 struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;         
1372                 if(pmlmeext->sitesurvey_res.bss_cnt == 0){
1373                         //rtw_hal_sreset_reset(adapter);
1374                 }
1375         }
1376 #endif
1377
1378 #ifdef CONFIG_IOCTL_CFG80211
1379         rtw_cfg80211_surveydone_event_callback(adapter);
1380 #endif //CONFIG_IOCTL_CFG80211
1381
1382         rtw_indicate_scan_done(adapter, _FALSE);
1383
1384 #if defined(CONFIG_CONCURRENT_MODE) && defined(CONFIG_IOCTL_CFG80211)
1385         if (adapter->pbuddy_adapter) {
1386                 _adapter *buddy_adapter = adapter->pbuddy_adapter;
1387                 struct mlme_priv *buddy_mlme = &(buddy_adapter->mlmepriv);
1388                 struct rtw_wdev_priv *buddy_wdev_priv = adapter_wdev_data(buddy_adapter);
1389                 bool indicate_buddy_scan = _FALSE;
1390
1391                 _enter_critical_bh(&buddy_wdev_priv->scan_req_lock, &irqL);
1392                 if (buddy_wdev_priv->scan_request && buddy_mlme->scanning_via_buddy_intf == _TRUE) {
1393                         buddy_mlme->scanning_via_buddy_intf = _FALSE;
1394                         clr_fwstate(buddy_mlme, _FW_UNDER_SURVEY);
1395                         indicate_buddy_scan = _TRUE;
1396                 }
1397                 _exit_critical_bh(&buddy_wdev_priv->scan_req_lock, &irqL);
1398
1399                 if (indicate_buddy_scan == _TRUE) {
1400                         #ifdef CONFIG_IOCTL_CFG80211
1401                         rtw_cfg80211_surveydone_event_callback(buddy_adapter);
1402                         #endif
1403                         rtw_indicate_scan_done(buddy_adapter, _FALSE);
1404                 }
1405         }
1406 #endif /* CONFIG_CONCURRENT_MODE */
1407
1408 _func_exit_;    
1409
1410 }
1411
1412 void rtw_dummy_event_callback(_adapter *adapter , u8 *pbuf)
1413 {
1414
1415 }
1416
1417 void rtw_fwdbg_event_callback(_adapter *adapter , u8 *pbuf)
1418 {
1419
1420 }
1421
1422 static void free_scanqueue(struct       mlme_priv *pmlmepriv)
1423 {
1424         _irqL irqL, irqL0;
1425         _queue *free_queue = &pmlmepriv->free_bss_pool;
1426         _queue *scan_queue = &pmlmepriv->scanned_queue;
1427         _list   *plist, *phead, *ptemp;
1428         
1429 _func_enter_;           
1430         
1431         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+free_scanqueue\n"));
1432         _enter_critical_bh(&scan_queue->lock, &irqL0);
1433         _enter_critical_bh(&free_queue->lock, &irqL);
1434
1435         phead = get_list_head(scan_queue);
1436         plist = get_next(phead);
1437
1438         while (plist != phead)
1439        {
1440                 ptemp = get_next(plist);
1441                 rtw_list_delete(plist);
1442                 rtw_list_insert_tail(plist, &free_queue->queue);
1443                 plist =ptemp;
1444                 pmlmepriv->num_of_scanned --;
1445         }
1446         
1447         _exit_critical_bh(&free_queue->lock, &irqL);
1448         _exit_critical_bh(&scan_queue->lock, &irqL0);
1449         
1450 _func_exit_;
1451 }
1452
1453 void rtw_reset_rx_info(struct debug_priv *pdbgpriv){
1454         pdbgpriv->dbg_rx_ampdu_drop_count = 0;
1455         pdbgpriv->dbg_rx_ampdu_forced_indicate_count = 0;
1456         pdbgpriv->dbg_rx_ampdu_loss_count = 0;
1457         pdbgpriv->dbg_rx_dup_mgt_frame_drop_count = 0;
1458         pdbgpriv->dbg_rx_ampdu_window_shift_cnt = 0;
1459 }
1460         
1461 /*
1462 *rtw_free_assoc_resources: the caller has to lock pmlmepriv->lock
1463 */
1464 void rtw_free_assoc_resources(_adapter *adapter, int lock_scanned_queue)
1465 {
1466         _irqL irqL;
1467         struct wlan_network* pwlan = NULL;
1468         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
1469         struct  sta_priv *pstapriv = &adapter->stapriv;
1470         struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1471         struct dvobj_priv *psdpriv = adapter->dvobj;
1472         struct debug_priv *pdbgpriv = &psdpriv->drv_dbg;        
1473
1474         
1475 #ifdef CONFIG_TDLS
1476         struct tdls_info *ptdlsinfo = &adapter->tdlsinfo;
1477 #endif //CONFIG_TDLS
1478 _func_enter_;                   
1479
1480         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_free_assoc_resources\n"));
1481         RT_TRACE(_module_rtl871x_mlme_c_, _drv_info_, ("tgt_network->network.MacAddress="MAC_FMT" ssid=%s\n",
1482                 MAC_ARG(tgt_network->network.MacAddress), tgt_network->network.Ssid.Ssid));
1483
1484         if(check_fwstate( pmlmepriv, WIFI_STATION_STATE|WIFI_AP_STATE))
1485         {
1486                 struct sta_info* psta;
1487                 
1488                 psta = rtw_get_stainfo(&adapter->stapriv, tgt_network->network.MacAddress);
1489
1490 #ifdef CONFIG_TDLS
1491                 if(ptdlsinfo->link_established == _TRUE)
1492                 {
1493                         rtw_tdls_cmd(adapter, myid(&(adapter->eeprompriv)), TDLS_RS_RCR);
1494                         rtw_reset_tdls_info(adapter);
1495                         rtw_free_all_stainfo(adapter);
1496                         _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
1497                 }
1498                 else
1499 #endif //CONFIG_TDLS
1500                 {
1501                         _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
1502                         rtw_free_stainfo(adapter,  psta);
1503                 }
1504
1505                 _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
1506                 
1507         }
1508
1509         if(check_fwstate( pmlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE|WIFI_AP_STATE))
1510         {
1511                 struct sta_info* psta;
1512         
1513                 rtw_free_all_stainfo(adapter);
1514
1515                 psta = rtw_get_bcmc_stainfo(adapter);
1516                 _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);          
1517                 rtw_free_stainfo(adapter, psta);
1518                 _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL);           
1519
1520                 rtw_init_bcmc_stainfo(adapter); 
1521         }
1522
1523         if(lock_scanned_queue)
1524                 _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
1525         
1526         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
1527         if(pwlan)               
1528         {
1529                 pwlan->fixed = _FALSE;
1530 #ifdef CONFIG_P2P
1531                 if(!rtw_p2p_chk_state(&adapter->wdinfo, P2P_STATE_NONE))
1532                 {
1533                         u32 p2p_ielen=0;
1534                         u8  *p2p_ie;
1535                         //u16 capability;
1536                         u8 *pcap = NULL;
1537                         u32 capability_len=0;
1538                         
1539                         //DBG_871X("free disconnecting network\n");
1540                         //rtw_free_network_nolock(pmlmepriv, pwlan);
1541
1542                         if((p2p_ie=rtw_get_p2p_ie(pwlan->network.IEs+_FIXED_IE_LENGTH_, pwlan->network.IELength-_FIXED_IE_LENGTH_, NULL, &p2p_ielen)))
1543                         {                       
1544                                 pcap = rtw_get_p2p_attr_content(p2p_ie, p2p_ielen, P2P_ATTR_CAPABILITY, NULL, &capability_len);
1545                                 if(pcap && capability_len==2)
1546                                 {
1547                                         u16 cap = *(u16*)pcap ;
1548                                         *(u16*)pcap = cap&0x00ff;//clear group capability when free this network
1549                                 }
1550
1551         }       
1552
1553                         rtw_set_scan_deny(adapter, 2000);
1554                         //rtw_clear_scan_deny(adapter);
1555                         
1556                 }
1557 #endif //CONFIG_P2P
1558         }       
1559         else
1560         {
1561                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_free_assoc_resources : pwlan== NULL \n\n"));
1562         }
1563
1564
1565         if((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) && (adapter->stapriv.asoc_sta_count== 1))
1566                 /*||check_fwstate(pmlmepriv, WIFI_STATION_STATE)*/)
1567         {
1568                 rtw_free_network_nolock(pmlmepriv, pwlan); 
1569         }
1570
1571         if(lock_scanned_queue)
1572                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
1573         
1574         adapter->securitypriv.key_mask = 0;
1575
1576         rtw_reset_rx_info(pdbgpriv);
1577
1578 _func_exit_;    
1579         
1580 }
1581
1582 /*
1583 *rtw_indicate_connect: the caller has to lock pmlmepriv->lock
1584 */
1585 void rtw_indicate_connect(_adapter *padapter)
1586 {
1587         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
1588         struct xmit_priv        *pxmitpriv = &padapter->xmitpriv;
1589         
1590 _func_enter_;
1591
1592         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_connect\n"));
1593  
1594         pmlmepriv->to_join = _FALSE;
1595
1596         if(!check_fwstate(&padapter->mlmepriv, _FW_LINKED)) 
1597         {
1598
1599 #ifdef CONFIG_SW_ANTENNA_DIVERSITY
1600                 rtw_hal_set_hwreg(padapter, HW_VAR_ANTENNA_DIVERSITY_LINK, 0);
1601 #endif
1602
1603                 set_fwstate(pmlmepriv, _FW_LINKED);
1604
1605                 rtw_led_control(padapter, LED_CTL_LINK);
1606
1607         
1608 #ifdef CONFIG_DRVEXT_MODULE
1609                 if(padapter->drvextpriv.enable_wpa)
1610                 {
1611                         indicate_l2_connect(padapter);
1612                 }
1613                 else
1614 #endif
1615                 {
1616                         rtw_os_indicate_connect(padapter);
1617                 }
1618
1619         }
1620
1621         rtw_set_to_roam(padapter, 0);
1622 #ifdef CONFIG_INTEL_WIDI
1623         if(padapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING)
1624         {
1625                 _rtw_memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
1626                 intel_widi_wk_cmd(padapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
1627                 DBG_871X("change to widi listen\n");
1628         }
1629 #endif // CONFIG_INTEL_WIDI
1630
1631         rtw_set_scan_deny(padapter, 3000);
1632
1633         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("-rtw_indicate_connect: fw_state=0x%08x\n", get_fwstate(pmlmepriv)));
1634  
1635 _func_exit_;
1636
1637 }
1638
1639
1640 /*
1641 *rtw_indicate_disconnect: the caller has to lock pmlmepriv->lock
1642 */
1643 void rtw_indicate_disconnect( _adapter *padapter )
1644 {
1645         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;     
1646         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
1647         struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
1648         WLAN_BSSID_EX   *cur_network = &(pmlmeinfo->network);
1649         struct sta_info *psta;
1650         struct sta_priv *pstapriv = &padapter->stapriv;
1651
1652 _func_enter_;   
1653         
1654         RT_TRACE(_module_rtl871x_mlme_c_, _drv_err_, ("+rtw_indicate_disconnect\n"));
1655
1656         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING|WIFI_UNDER_WPS);
1657
1658         //DBG_871X("clear wps when %s\n", __func__);
1659
1660         if(rtw_to_roam(padapter) > 0)
1661                 _clr_fwstate_(pmlmepriv, _FW_LINKED);
1662
1663 #ifdef CONFIG_WAPI_SUPPORT
1664         psta = rtw_get_stainfo(pstapriv,cur_network->MacAddress);
1665         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE))
1666         {
1667                 rtw_wapi_return_one_sta_info(padapter, psta->hwaddr);
1668         }
1669         else if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) ||
1670                 check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE))
1671         {
1672                 rtw_wapi_return_all_sta_info(padapter);
1673         }
1674 #endif
1675
1676         if(check_fwstate(&padapter->mlmepriv, _FW_LINKED) 
1677                 || (rtw_to_roam(padapter) <= 0)
1678         )
1679         {
1680                 rtw_os_indicate_disconnect(padapter);
1681
1682                 //set ips_deny_time to avoid enter IPS before LPS leave
1683                 rtw_set_ips_deny(padapter, 3000);
1684
1685               _clr_fwstate_(pmlmepriv, _FW_LINKED);
1686
1687                 rtw_led_control(padapter, LED_CTL_NO_LINK);
1688
1689                 rtw_clear_scan_deny(padapter);
1690         }
1691
1692 #ifdef CONFIG_P2P_PS
1693         p2p_ps_wk_cmd(padapter, P2P_PS_DISABLE, 1);
1694 #endif // CONFIG_P2P_PS
1695
1696 #ifdef CONFIG_LPS
1697         rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_DISCONNECT, 1);
1698 #endif
1699
1700 #ifdef CONFIG_BEAMFORMING
1701         beamforming_wk_cmd(padapter, BEAMFORMING_CTRL_LEAVE, cur_network->MacAddress, ETH_ALEN, 1);
1702 #endif
1703
1704 _func_exit_;    
1705 }
1706
1707 inline void rtw_indicate_scan_done( _adapter *padapter, bool aborted)
1708 {
1709         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1710
1711         rtw_os_indicate_scan_done(padapter, aborted);
1712
1713 #ifdef CONFIG_IPS
1714         if (is_primary_adapter(padapter)
1715                 && (_FALSE == adapter_to_pwrctl(padapter)->bInSuspend)
1716                 && (check_fwstate(&padapter->mlmepriv, WIFI_ASOC_STATE|WIFI_UNDER_LINKING) == _FALSE))
1717         {
1718                 struct pwrctrl_priv *pwrpriv;
1719
1720                 pwrpriv = adapter_to_pwrctl(padapter);
1721                 rtw_set_ips_deny(padapter, 0);
1722 #ifdef CONFIG_IPS_CHECK_IN_WD
1723                 _set_timer(&padapter->mlmepriv.dynamic_chk_timer, 1);
1724 #else // !CONFIG_IPS_CHECK_IN_WD
1725                 _rtw_set_pwr_state_check_timer(pwrpriv, 1);
1726 #endif // !CONFIG_IPS_CHECK_IN_WD
1727         }
1728 #endif // CONFIG_IPS
1729 }
1730
1731 void rtw_scan_abort(_adapter *adapter)
1732 {
1733         u32 cnt=0;
1734         u32 start;
1735         struct mlme_priv        *pmlmepriv = &(adapter->mlmepriv);
1736         struct mlme_ext_priv    *pmlmeext = &(adapter->mlmeextpriv);
1737
1738         start = rtw_get_current_time();
1739         pmlmeext->scan_abort = _TRUE;
1740         while (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)
1741                 && rtw_get_passing_time_ms(start) <= 200) {
1742
1743                 if (adapter->bDriverStopped || adapter->bSurpriseRemoved)
1744                         break;
1745
1746                 DBG_871X(FUNC_NDEV_FMT"fw_state=_FW_UNDER_SURVEY!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1747                 rtw_msleep_os(20);
1748         }
1749
1750         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY)) {
1751                 if (!adapter->bDriverStopped && !adapter->bSurpriseRemoved)
1752                         DBG_871X(FUNC_NDEV_FMT"waiting for scan_abort time out!\n", FUNC_NDEV_ARG(adapter->pnetdev));
1753                 #ifdef CONFIG_PLATFORM_MSTAR
1754                 //_clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
1755                 set_survey_timer(pmlmeext, 0);
1756                 _set_timer(&pmlmepriv->scan_to_timer, 50);
1757                 #endif
1758                 rtw_indicate_scan_done(adapter, _TRUE);
1759         }
1760         pmlmeext->scan_abort = _FALSE;
1761 }
1762
1763 static struct sta_info *rtw_joinbss_update_stainfo(_adapter *padapter, struct wlan_network *pnetwork)
1764 {
1765         int i;
1766         struct sta_info *bmc_sta, *psta=NULL;
1767         struct recv_reorder_ctrl *preorder_ctrl;
1768         struct sta_priv *pstapriv = &padapter->stapriv;
1769         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
1770
1771         psta = rtw_get_stainfo(pstapriv, pnetwork->network.MacAddress);
1772         if(psta==NULL) {
1773                 psta = rtw_alloc_stainfo(pstapriv, pnetwork->network.MacAddress);
1774         }
1775
1776         if(psta) //update ptarget_sta
1777         {
1778                 DBG_871X("%s\n", __FUNCTION__);
1779         
1780                 psta->aid  = pnetwork->join_res;
1781
1782 #if 0 //alloc macid when call rtw_alloc_stainfo(), and release macid when call rtw_free_stainfo()
1783 #ifdef CONFIG_CONCURRENT_MODE   
1784
1785                 if(PRIMARY_ADAPTER == padapter->adapter_type)
1786                         psta->mac_id=0;
1787                 else
1788                         psta->mac_id=2;
1789 #else
1790                 psta->mac_id=0;
1791 #endif
1792 #endif //removed
1793
1794                 update_sta_info(padapter, psta);
1795
1796                 //update station supportRate
1797                 psta->bssratelen = rtw_get_rateset_len(pnetwork->network.SupportedRates);
1798                 _rtw_memcpy(psta->bssrateset, pnetwork->network.SupportedRates, psta->bssratelen);
1799                 rtw_hal_update_sta_rate_mask(padapter, psta);
1800
1801                 psta->wireless_mode = pmlmeext->cur_wireless_mode;
1802                 psta->raid = rtw_hal_networktype_to_raid(padapter,psta);
1803
1804
1805                 //sta mode
1806                 rtw_hal_set_odm_var(padapter,HAL_ODM_STA_INFO,psta,_TRUE);
1807
1808                 //security related
1809                 if(padapter->securitypriv.dot11AuthAlgrthm== dot11AuthAlgrthm_8021X)
1810                 {                                               
1811                         padapter->securitypriv.binstallGrpkey=_FALSE;
1812                         padapter->securitypriv.busetkipkey=_FALSE;                                              
1813                         padapter->securitypriv.bgrpkey_handshake=_FALSE;
1814
1815                         psta->ieee8021x_blocked=_TRUE;
1816                         psta->dot118021XPrivacy=padapter->securitypriv.dot11PrivacyAlgrthm;
1817                                                 
1818                         _rtw_memset((u8 *)&psta->dot118021x_UncstKey, 0, sizeof (union Keytype));
1819                                                 
1820                         _rtw_memset((u8 *)&psta->dot11tkiprxmickey, 0, sizeof (union Keytype));
1821                         _rtw_memset((u8 *)&psta->dot11tkiptxmickey, 0, sizeof (union Keytype));
1822                                                 
1823                         _rtw_memset((u8 *)&psta->dot11txpn, 0, sizeof (union pn48));
1824 #ifdef CONFIG_IEEE80211W
1825                         _rtw_memset((u8 *)&psta->dot11wtxpn, 0, sizeof (union pn48));
1826 #endif //CONFIG_IEEE80211W
1827                         _rtw_memset((u8 *)&psta->dot11rxpn, 0, sizeof (union pn48));    
1828                 }
1829
1830                 //      Commented by Albert 2012/07/21
1831                 //      When doing the WPS, the wps_ie_len won't equal to 0
1832                 //      And the Wi-Fi driver shouldn't allow the data packet to be tramsmitted.
1833                 if ( padapter->securitypriv.wps_ie_len != 0 )
1834                 {
1835                         psta->ieee8021x_blocked=_TRUE;
1836                         padapter->securitypriv.wps_ie_len = 0;
1837                 }
1838
1839
1840                 //for A-MPDU Rx reordering buffer control for bmc_sta & sta_info
1841                 //if A-MPDU Rx is enabled, reseting  rx_ordering_ctrl wstart_b(indicate_seq) to default value=0xffff
1842                 //todo: check if AP can send A-MPDU packets
1843                 for(i=0; i < 16 ; i++)
1844                 {
1845                         //preorder_ctrl = &precvpriv->recvreorder_ctrl[i];
1846                         preorder_ctrl = &psta->recvreorder_ctrl[i];
1847                         preorder_ctrl->enable = _FALSE;
1848                         preorder_ctrl->indicate_seq = 0xffff;
1849                         #ifdef DBG_RX_SEQ
1850                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u \n", __FUNCTION__, __LINE__,
1851                                 preorder_ctrl->indicate_seq);
1852                         #endif
1853                         preorder_ctrl->wend_b= 0xffff;
1854                         preorder_ctrl->wsize_b = 64;//max_ampdu_sz;//ex. 32(kbytes) -> wsize_b=32
1855                 }
1856
1857                 
1858                 bmc_sta = rtw_get_bcmc_stainfo(padapter);
1859                 if(bmc_sta)
1860                 {
1861                         for(i=0; i < 16 ; i++)
1862                         {
1863                                 //preorder_ctrl = &precvpriv->recvreorder_ctrl[i];
1864                                 preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
1865                                 preorder_ctrl->enable = _FALSE;
1866                                 preorder_ctrl->indicate_seq = 0xffff;
1867                                 #ifdef DBG_RX_SEQ
1868                                 DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u \n", __FUNCTION__, __LINE__,
1869                                         preorder_ctrl->indicate_seq);
1870                                 #endif
1871                                 preorder_ctrl->wend_b= 0xffff;
1872                                 preorder_ctrl->wsize_b = 64;//max_ampdu_sz;//ex. 32(kbytes) -> wsize_b=32
1873                         }
1874                 }
1875         }
1876                                         
1877         return psta;
1878         
1879 }
1880
1881 //pnetwork : returns from rtw_joinbss_event_callback
1882 //ptarget_wlan: found from scanned_queue
1883 static void rtw_joinbss_update_network(_adapter *padapter, struct wlan_network *ptarget_wlan, struct wlan_network  *pnetwork)
1884 {
1885         struct mlme_priv        *pmlmepriv = &(padapter->mlmepriv);     
1886         struct wlan_network  *cur_network = &(pmlmepriv->cur_network);
1887
1888         DBG_871X("%s\n", __FUNCTION__);
1889         
1890         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("\nfw_state:%x, BSSID:"MAC_FMT"\n"
1891                 ,get_fwstate(pmlmepriv), MAC_ARG(pnetwork->network.MacAddress)));
1892
1893                                 
1894         // why not use ptarget_wlan??
1895         _rtw_memcpy(&cur_network->network, &pnetwork->network, pnetwork->network.Length);
1896         // some IEs in pnetwork is wrong, so we should use ptarget_wlan IEs
1897         cur_network->network.IELength = ptarget_wlan->network.IELength;
1898         _rtw_memcpy(&cur_network->network.IEs[0], &ptarget_wlan->network.IEs[0], MAX_IE_SZ);
1899
1900         cur_network->aid = pnetwork->join_res;
1901
1902                                 
1903 #ifdef CONFIG_NEW_SIGNAL_STAT_PROCESS
1904         rtw_set_signal_stat_timer(&padapter->recvpriv);
1905 #endif
1906         padapter->recvpriv.signal_strength = ptarget_wlan->network.PhyInfo.SignalStrength;
1907         padapter->recvpriv.signal_qual = ptarget_wlan->network.PhyInfo.SignalQuality;
1908         //the ptarget_wlan->network.Rssi is raw data, we use ptarget_wlan->network.PhyInfo.SignalStrength instead (has scaled)
1909         padapter->recvpriv.rssi = translate_percentage_to_dbm(ptarget_wlan->network.PhyInfo.SignalStrength);
1910         #if defined(DBG_RX_SIGNAL_DISPLAY_PROCESSING) && 1
1911                 DBG_871X(FUNC_ADPT_FMT" signal_strength:%3u, rssi:%3d, signal_qual:%3u"
1912                         "\n"
1913                         , FUNC_ADPT_ARG(padapter)
1914                         , padapter->recvpriv.signal_strength
1915                         , padapter->recvpriv.rssi
1916                         , padapter->recvpriv.signal_qual
1917         );
1918         #endif
1919 #ifdef CONFIG_NEW_SIGNAL_STAT_PROCESS
1920         rtw_set_signal_stat_timer(&padapter->recvpriv);
1921 #endif
1922                                 
1923         //update fw_state //will clr _FW_UNDER_LINKING here indirectly
1924         switch(pnetwork->network.InfrastructureMode)
1925         {       
1926                 case Ndis802_11Infrastructure:                                          
1927                         
1928                                 if(pmlmepriv->fw_state&WIFI_UNDER_WPS)
1929                                         pmlmepriv->fw_state = WIFI_STATION_STATE|WIFI_UNDER_WPS;
1930                                 else
1931                                         pmlmepriv->fw_state = WIFI_STATION_STATE;
1932                                 
1933                                 break;
1934                 case Ndis802_11IBSS:            
1935                                 pmlmepriv->fw_state = WIFI_ADHOC_STATE;
1936                                 break;
1937                 default:
1938                                 pmlmepriv->fw_state = WIFI_NULL_STATE;
1939                                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Invalid network_mode\n"));
1940                                 break;
1941         }
1942
1943         rtw_update_protection(padapter, (cur_network->network.IEs) + sizeof (NDIS_802_11_FIXED_IEs), 
1944                                                                         (cur_network->network.IELength));
1945
1946 #ifdef CONFIG_80211N_HT                 
1947         rtw_update_ht_cap(padapter, cur_network->network.IEs, cur_network->network.IELength, (u8) cur_network->network.Configuration.DSConfig);
1948 #endif
1949 }
1950
1951 //Notes: the fucntion could be > passive_level (the same context as Rx tasklet)
1952 //pnetwork : returns from rtw_joinbss_event_callback
1953 //ptarget_wlan: found from scanned_queue
1954 //if join_res > 0, for (fw_state==WIFI_STATION_STATE), we check if  "ptarget_sta" & "ptarget_wlan" exist.       
1955 //if join_res > 0, for (fw_state==WIFI_ADHOC_STATE), we only check if "ptarget_wlan" exist.
1956 //if join_res > 0, update "cur_network->network" from "pnetwork->network" if (ptarget_wlan !=NULL).
1957 //
1958 //#define REJOIN
1959 void rtw_joinbss_event_prehandle(_adapter *adapter, u8 *pbuf)
1960 {
1961         _irqL irqL,irqL2;
1962         static u8 retry=0;
1963         u8 timer_cancelled;
1964         struct sta_info *ptarget_sta= NULL, *pcur_sta = NULL;
1965         struct  sta_priv *pstapriv = &adapter->stapriv;
1966         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
1967         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
1968         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
1969         struct wlan_network     *pcur_wlan = NULL, *ptarget_wlan = NULL;
1970         unsigned int            the_same_macaddr = _FALSE;      
1971
1972 _func_enter_;   
1973
1974 #ifdef CONFIG_RTL8712
1975        //endian_convert
1976         pnetwork->join_res = le32_to_cpu(pnetwork->join_res);
1977         pnetwork->network_type = le32_to_cpu(pnetwork->network_type);
1978         pnetwork->network.Length = le32_to_cpu(pnetwork->network.Length);
1979         pnetwork->network.Ssid.SsidLength = le32_to_cpu(pnetwork->network.Ssid.SsidLength);
1980         pnetwork->network.Privacy =le32_to_cpu( pnetwork->network.Privacy);
1981         pnetwork->network.Rssi = le32_to_cpu(pnetwork->network.Rssi);
1982         pnetwork->network.NetworkTypeInUse =le32_to_cpu(pnetwork->network.NetworkTypeInUse) ;   
1983         pnetwork->network.Configuration.ATIMWindow = le32_to_cpu(pnetwork->network.Configuration.ATIMWindow);
1984         pnetwork->network.Configuration.BeaconPeriod = le32_to_cpu(pnetwork->network.Configuration.BeaconPeriod);
1985         pnetwork->network.Configuration.DSConfig = le32_to_cpu(pnetwork->network.Configuration.DSConfig);
1986         pnetwork->network.Configuration.FHConfig.DwellTime=le32_to_cpu(pnetwork->network.Configuration.FHConfig.DwellTime);
1987         pnetwork->network.Configuration.FHConfig.HopPattern=le32_to_cpu(pnetwork->network.Configuration.FHConfig.HopPattern);
1988         pnetwork->network.Configuration.FHConfig.HopSet=le32_to_cpu(pnetwork->network.Configuration.FHConfig.HopSet);
1989         pnetwork->network.Configuration.FHConfig.Length=le32_to_cpu(pnetwork->network.Configuration.FHConfig.Length);   
1990         pnetwork->network.Configuration.Length = le32_to_cpu(pnetwork->network.Configuration.Length);
1991         pnetwork->network.InfrastructureMode = le32_to_cpu(pnetwork->network.InfrastructureMode);
1992         pnetwork->network.IELength = le32_to_cpu(pnetwork->network.IELength );
1993 #endif
1994
1995         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("joinbss event call back received with res=%d\n", pnetwork->join_res));
1996
1997         rtw_get_encrypt_decrypt_from_registrypriv(adapter);
1998         
1999
2000         if (pmlmepriv->assoc_ssid.SsidLength == 0)
2001         {
2002                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("@@@@@   joinbss event call back  for Any SSid\n"));                
2003         }
2004         else
2005         {
2006                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("@@@@@   rtw_joinbss_event_callback for SSid:%s\n", pmlmepriv->assoc_ssid.Ssid));
2007         }
2008         
2009         the_same_macaddr = _rtw_memcmp(pnetwork->network.MacAddress, cur_network->network.MacAddress, ETH_ALEN);
2010
2011         pnetwork->network.Length = get_WLAN_BSSID_EX_sz(&pnetwork->network);
2012         if(pnetwork->network.Length > sizeof(WLAN_BSSID_EX))
2013         {
2014                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n\n ***joinbss_evt_callback return a wrong bss ***\n\n"));
2015                 goto ignore_joinbss_callback;
2016         }
2017                 
2018         _enter_critical_bh(&pmlmepriv->lock, &irqL);
2019         
2020         pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 0;
2021         pmlmepriv->LinkDetectInfo.LowPowerTransitionCount = 0;
2022         
2023         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("\n rtw_joinbss_event_callback !! _enter_critical \n"));
2024
2025         if(pnetwork->join_res > 0)
2026         {
2027                 _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2028                 retry = 0;
2029                 if (check_fwstate(pmlmepriv,_FW_UNDER_LINKING) )
2030                 {
2031                         //s1. find ptarget_wlan
2032                         if(check_fwstate(pmlmepriv, _FW_LINKED) )
2033                         {
2034                                 if(the_same_macaddr == _TRUE)
2035                                 {
2036                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);                                    
2037                                 }
2038                                 else
2039                                 {
2040                                         pcur_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
2041                                         if(pcur_wlan)   pcur_wlan->fixed = _FALSE;
2042
2043                                         pcur_sta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
2044                                         if(pcur_sta){
2045                                                 _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL2);
2046                                                 rtw_free_stainfo(adapter,  pcur_sta);
2047                                                 _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL2);
2048                                         }
2049
2050                                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, pnetwork->network.MacAddress);
2051                                         if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE){
2052                                                 if(ptarget_wlan)        ptarget_wlan->fixed = _TRUE;                    
2053                                         }
2054                                 }
2055
2056                         }
2057                         else
2058                         {
2059                                 ptarget_wlan = _rtw_find_same_network(&pmlmepriv->scanned_queue, pnetwork);
2060                                 if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE){
2061                                         if(ptarget_wlan)        ptarget_wlan->fixed = _TRUE;                    
2062                                 }
2063                         }
2064                 
2065                         //s2. update cur_network 
2066                         if(ptarget_wlan)
2067                         {                       
2068                                 rtw_joinbss_update_network(adapter, ptarget_wlan, pnetwork);
2069                         }
2070                         else
2071                         {                       
2072                                 DBG_871X_LEVEL(_drv_always_, "Can't find ptarget_wlan when joinbss_event callback\n");
2073                                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2074                                 goto ignore_joinbss_callback;
2075                         }
2076                                         
2077                         
2078                         //s3. find ptarget_sta & update ptarget_sta after update cur_network only for station mode 
2079                         if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE)
2080                         { 
2081                                 ptarget_sta = rtw_joinbss_update_stainfo(adapter, pnetwork);
2082                                 if(ptarget_sta==NULL)
2083                                 {
2084                                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Can't update stainfo when joinbss_event callback\n"));
2085                                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2086                                         goto ignore_joinbss_callback;
2087                                 }
2088                         }
2089
2090                         //s4. indicate connect                  
2091                         if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE)
2092                         {
2093                                 pmlmepriv->cur_network_scanned = ptarget_wlan;
2094                                 rtw_indicate_connect(adapter);
2095                         }
2096                         else
2097                         {
2098                                 //adhoc mode will rtw_indicate_connect when rtw_stassoc_event_callback
2099                                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("adhoc mode, fw_state:%x", get_fwstate(pmlmepriv)));
2100                         }
2101
2102                                 
2103                         //s5. Cancle assoc_timer                                        
2104                         _cancel_timer(&pmlmepriv->assoc_timer, &timer_cancelled);
2105                 
2106                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("Cancle assoc_timer \n"));         
2107                 
2108                 }
2109                 else
2110                 {
2111                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_joinbss_event_callback err: fw_state:%x", get_fwstate(pmlmepriv)));    
2112                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2113                         goto ignore_joinbss_callback;
2114                 }
2115                 
2116                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);     
2117                                 
2118         }
2119         else if(pnetwork->join_res == -4) 
2120         {
2121                 rtw_reset_securitypriv(adapter);
2122                 _set_timer(&pmlmepriv->assoc_timer, 1);                                 
2123
2124                 //rtw_free_assoc_resources(adapter, 1);
2125
2126                 if((check_fwstate(pmlmepriv, _FW_UNDER_LINKING)) == _TRUE)
2127                 {               
2128                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("fail! clear _FW_UNDER_LINKING ^^^fw_state=%x\n", get_fwstate(pmlmepriv)));
2129                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
2130                 }       
2131                 
2132         }
2133         else //if join_res < 0 (join fails), then try again
2134         {
2135         
2136                 #ifdef REJOIN
2137                 res = _FAIL;
2138                 if(retry < 2) {
2139                         res = rtw_select_and_join_from_scanned_queue(pmlmepriv);
2140                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("rtw_select_and_join_from_scanned_queue again! res:%d\n",res));
2141                 }
2142
2143                  if(res == _SUCCESS)
2144                 {
2145                         //extend time of assoc_timer
2146                         _set_timer(&pmlmepriv->assoc_timer, MAX_JOIN_TIMEOUT);
2147                         retry++;
2148                 }
2149                 else if(res == 2)//there is no need to wait for join
2150                 {
2151                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
2152                         rtw_indicate_connect(adapter);
2153                 }       
2154                 else
2155                 {
2156                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Set Assoc_Timer = 1; can't find match ssid in scanned_q \n"));
2157                 #endif
2158                         
2159                         _set_timer(&pmlmepriv->assoc_timer, 1);
2160                         //rtw_free_assoc_resources(adapter, 1);
2161                         _clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
2162                         
2163                 #ifdef REJOIN
2164                         retry = 0;      
2165                 }
2166                 #endif
2167         }
2168
2169 ignore_joinbss_callback:
2170
2171         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2172         _func_exit_;    
2173 }
2174
2175 void rtw_joinbss_event_callback(_adapter *adapter, u8 *pbuf)
2176 {
2177         struct wlan_network     *pnetwork       = (struct wlan_network *)pbuf;
2178
2179 _func_enter_;
2180
2181         mlmeext_joinbss_event_callback(adapter, pnetwork->join_res);
2182
2183         rtw_os_xmit_schedule(adapter);
2184
2185 #ifdef CONFIG_CONCURRENT_MODE   
2186         rtw_os_xmit_schedule(adapter->pbuddy_adapter);
2187 #endif  
2188
2189 #ifdef CONFIG_DUALMAC_CONCURRENT
2190         dc_resume_xmit(adapter);
2191 #endif
2192
2193 _func_exit_;
2194 }
2195
2196 #if 0
2197 //#if (RATE_ADAPTIVE_SUPPORT==1)        //for 88E RA            
2198 u8 search_max_mac_id(_adapter *padapter)
2199 {
2200         u8 mac_id, aid;
2201         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
2202         struct mlme_ext_priv *pmlmeext = &(padapter->mlmeextpriv);
2203         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
2204         struct sta_priv *pstapriv = &padapter->stapriv;
2205
2206 #if defined (CONFIG_AP_MODE) && defined (CONFIG_NATIVEAP_MLME)  
2207         if(check_fwstate(pmlmepriv, WIFI_AP_STATE)){            
2208                 
2209 #if 1
2210                 _irqL irqL;
2211                 struct dvobj_priv *pdvobj = adapter_to_dvobj(padapter);
2212
2213                 _enter_critical_bh(&pdvobj->lock, &irqL);
2214                 for(mac_id=(NUM_STA-1); mac_id>0; mac_id--)
2215                         if(pdvobj->macid[mac_id] == _TRUE)
2216                                 break;
2217                 _exit_critical_bh(&pdvobj->lock, &irqL);
2218
2219 #else
2220                 for (aid = (pstapriv->max_num_sta); aid > 0; aid--)
2221                 {
2222                         if (pstapriv->sta_aid[aid-1] != NULL)
2223                         {
2224                                 psta = pstapriv->sta_aid[aid-1];
2225                                 break;
2226                         }       
2227                 }
2228 /*
2229                 for (mac_id = (pstapriv->max_num_sta-1); mac_id >= 0; mac_id--)
2230                 {
2231                         if (pstapriv->sta_aid[mac_id] != NULL)
2232                                 break;
2233                 }       
2234 */
2235                 mac_id = aid + 1;
2236 #endif
2237         }
2238         else
2239 #endif
2240         {//adhoc  id =  31~2
2241                 for (mac_id = (NUM_STA-1); mac_id >= IBSS_START_MAC_ID ; mac_id--)
2242                 {
2243                         if (pmlmeinfo->FW_sta_info[mac_id].status == 1)
2244                         {
2245                                 break;
2246                         }
2247                 }
2248         }
2249
2250         DBG_871X("max mac_id=%d\n", mac_id);
2251
2252         return mac_id;
2253
2254 }               
2255 #endif  
2256
2257 //FOR STA, AP ,AD-HOC mode
2258 void rtw_sta_media_status_rpt(_adapter *adapter,struct sta_info *psta, u32 mstatus)
2259 {
2260         u16 media_status_rpt;
2261
2262         if(psta==NULL)  return;
2263
2264         #if (RATE_ADAPTIVE_SUPPORT==1)  //for 88E RA    
2265         {
2266                 u8 macid = rtw_search_max_mac_id(adapter);                              
2267                 rtw_hal_set_hwreg(adapter,HW_VAR_TX_RPT_MAX_MACID, (u8*)&macid);
2268         }
2269         #endif
2270         media_status_rpt = (u16)((psta->mac_id<<8)|mstatus); //  MACID|OPMODE:1 connect                         
2271         rtw_hal_set_hwreg(adapter,HW_VAR_H2C_MEDIA_STATUS_RPT,(u8 *)&media_status_rpt);                 
2272 }
2273
2274 void rtw_stassoc_event_callback(_adapter *adapter, u8 *pbuf)
2275 {
2276         _irqL irqL;     
2277         struct sta_info *psta;
2278         struct mlme_priv *pmlmepriv = &(adapter->mlmepriv);
2279         struct stassoc_event    *pstassoc       = (struct stassoc_event*)pbuf;
2280         struct wlan_network     *cur_network = &(pmlmepriv->cur_network);
2281         struct wlan_network     *ptarget_wlan = NULL;
2282         
2283 _func_enter_;   
2284         
2285         if(rtw_access_ctrl(adapter, pstassoc->macaddr) == _FALSE)
2286                 return;
2287
2288 #if defined (CONFIG_AP_MODE) && defined (CONFIG_NATIVEAP_MLME)
2289         if(check_fwstate(pmlmepriv, WIFI_AP_STATE))
2290         {
2291                 psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);   
2292                 if(psta)
2293                 {               
2294                         u8 *passoc_req = NULL;
2295                         u32 assoc_req_len = 0;
2296                 
2297                         rtw_sta_media_status_rpt(adapter, psta, 1);
2298                 
2299 #ifndef CONFIG_AUTO_AP_MODE
2300
2301                         ap_sta_info_defer_update(adapter, psta);
2302
2303                         //report to upper layer 
2304                         DBG_871X("indicate_sta_assoc_event to upper layer - hostapd\n");
2305 #ifdef CONFIG_IOCTL_CFG80211
2306                         _enter_critical_bh(&psta->lock, &irqL);
2307                         if(psta->passoc_req && psta->assoc_req_len>0)
2308                         {                               
2309                                 passoc_req = rtw_zmalloc(psta->assoc_req_len);
2310                                 if(passoc_req)
2311                                 {
2312                                         assoc_req_len = psta->assoc_req_len;
2313                                         _rtw_memcpy(passoc_req, psta->passoc_req, assoc_req_len);
2314                                         
2315                                         rtw_mfree(psta->passoc_req , psta->assoc_req_len);
2316                                         psta->passoc_req = NULL;
2317                                         psta->assoc_req_len = 0;
2318                                 }
2319                         }                       
2320                         _exit_critical_bh(&psta->lock, &irqL);
2321
2322                         if(passoc_req && assoc_req_len>0)
2323                         {
2324                                 rtw_cfg80211_indicate_sta_assoc(adapter, passoc_req, assoc_req_len);
2325
2326                                 rtw_mfree(passoc_req, assoc_req_len);
2327                         }                       
2328 #else //!CONFIG_IOCTL_CFG80211  
2329                         rtw_indicate_sta_assoc_event(adapter, psta);
2330 #endif //!CONFIG_IOCTL_CFG80211
2331 #endif //!CONFIG_AUTO_AP_MODE
2332
2333 #ifdef CONFIG_BEAMFORMING
2334                         beamforming_wk_cmd(adapter, BEAMFORMING_CTRL_ENTER, (u8 *)psta, sizeof(struct sta_info), 0);
2335 #endif
2336                 }               
2337                 goto exit;
2338         }       
2339 #endif //defined (CONFIG_AP_MODE) && defined (CONFIG_NATIVEAP_MLME)
2340
2341         //for AD-HOC mode
2342         psta = rtw_get_stainfo(&adapter->stapriv, pstassoc->macaddr);   
2343         if( psta != NULL)
2344         {
2345                 //the sta have been in sta_info_queue => do nothing 
2346                 
2347                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Error: rtw_stassoc_event_callback: sta has been in sta_hash_queue \n"));
2348                 
2349                 goto exit; //(between drv has received this event before and  fw have not yet to set key to CAM_ENTRY)
2350         }
2351
2352         psta = rtw_alloc_stainfo(&adapter->stapriv, pstassoc->macaddr); 
2353         if (psta == NULL) {
2354                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("Can't alloc sta_info when rtw_stassoc_event_callback\n"));
2355                 goto exit;
2356         }       
2357         
2358         //to do : init sta_info variable
2359         psta->qos_option = 0;
2360         psta->mac_id = (uint)pstassoc->cam_id;
2361         //psta->aid = (uint)pstassoc->cam_id;
2362         DBG_871X("%s\n",__FUNCTION__);
2363         //for ad-hoc mode
2364         rtw_hal_set_odm_var(adapter,HAL_ODM_STA_INFO,psta,_TRUE);
2365
2366         rtw_sta_media_status_rpt(adapter, psta, 1);
2367         
2368         if(adapter->securitypriv.dot11AuthAlgrthm==dot11AuthAlgrthm_8021X)
2369                 psta->dot118021XPrivacy = adapter->securitypriv.dot11PrivacyAlgrthm;
2370         
2371
2372         psta->ieee8021x_blocked = _FALSE;               
2373         
2374         _enter_critical_bh(&pmlmepriv->lock, &irqL);
2375
2376         if ( (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)==_TRUE ) || 
2377                 (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)==_TRUE ) )
2378         {
2379                 if(adapter->stapriv.asoc_sta_count== 2)
2380                 {
2381                         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2382                         ptarget_wlan = rtw_find_network(&pmlmepriv->scanned_queue, cur_network->network.MacAddress);
2383                         pmlmepriv->cur_network_scanned = ptarget_wlan;
2384                         if(ptarget_wlan)        ptarget_wlan->fixed = _TRUE;
2385                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2386                         // a sta + bc/mc_stainfo (not Ibss_stainfo)
2387                         rtw_indicate_connect(adapter);
2388                 }
2389         }
2390
2391         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2392
2393
2394         mlmeext_sta_add_event_callback(adapter, psta);
2395         
2396 #ifdef CONFIG_RTL8711
2397         //submit SetStaKey_cmd to tell fw, fw will allocate an CAM entry for this sta   
2398         rtw_setstakey_cmd(adapter, (unsigned char*)psta, _FALSE, _TRUE);
2399 #endif
2400                 
2401 exit:
2402         
2403 _func_exit_;    
2404
2405 }
2406
2407 void rtw_stadel_event_callback(_adapter *adapter, u8 *pbuf)
2408 {
2409         _irqL irqL,irqL2;
2410         int mac_id = (-1);
2411         struct sta_info *psta;
2412         struct wlan_network* pwlan = NULL;
2413         WLAN_BSSID_EX    *pdev_network=NULL;
2414         u8* pibss = NULL;
2415         struct  mlme_priv       *pmlmepriv = &(adapter->mlmepriv);
2416         struct  stadel_event *pstadel   = (struct stadel_event*)pbuf;
2417         struct  sta_priv *pstapriv = &adapter->stapriv;
2418         struct wlan_network *tgt_network = &(pmlmepriv->cur_network);
2419         struct mlme_ext_priv    *pmlmeext = &adapter->mlmeextpriv;
2420         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
2421         
2422 _func_enter_;   
2423         
2424         psta = rtw_get_stainfo(&adapter->stapriv, pstadel->macaddr);
2425         if(psta)
2426                 mac_id = psta->mac_id;
2427         else
2428                 mac_id = pstadel->mac_id;
2429
2430         DBG_871X("%s(mac_id=%d)=" MAC_FMT "\n", __func__, mac_id, MAC_ARG(pstadel->macaddr));
2431
2432         if(mac_id>=0){
2433                 u16 media_status;
2434                 media_status = (mac_id<<8)|0; //  MACID|OPMODE:0 means disconnect
2435                 //for STA,AP,ADHOC mode, report disconnect stauts to FW
2436                 rtw_hal_set_hwreg(adapter, HW_VAR_H2C_MEDIA_STATUS_RPT, (u8 *)&media_status);
2437         }       
2438
2439         //if(check_fwstate(pmlmepriv, WIFI_AP_STATE))
2440         if((pmlmeinfo->state&0x03) == WIFI_FW_AP_STATE)
2441         {
2442 #ifdef CONFIG_IOCTL_CFG80211
2443                 #ifdef COMPAT_KERNEL_RELEASE
2444
2445                 #elif (LINUX_VERSION_CODE < KERNEL_VERSION(2,6,37)) || defined(CONFIG_CFG80211_FORCE_COMPATIBLE_2_6_37_UNDER)
2446                 rtw_cfg80211_indicate_sta_disassoc(adapter, pstadel->macaddr, *(u16*)pstadel->rsvd);
2447                 #endif //(LINUX_VERSION_CODE < KERNEL_VERSION(2,6,37)) || defined(CONFIG_CFG80211_FORCE_COMPATIBLE_2_6_37_UNDER)
2448 #endif //CONFIG_IOCTL_CFG80211
2449
2450                 return;
2451         }
2452
2453
2454         mlmeext_sta_del_event_callback(adapter);
2455
2456         _enter_critical_bh(&pmlmepriv->lock, &irqL2);
2457
2458         if(check_fwstate(pmlmepriv, WIFI_STATION_STATE) )
2459         {
2460                 u16 reason = *((unsigned short *)(pstadel->rsvd));
2461                 bool roam = _FALSE;
2462                 struct wlan_network *roam_target = NULL;
2463
2464                 #ifdef CONFIG_LAYER2_ROAMING
2465                 if(adapter->registrypriv.wifi_spec==1) {
2466                         roam = _FALSE;
2467                 } else if (reason == WLAN_REASON_EXPIRATION_CHK && rtw_chk_roam_flags(adapter, RTW_ROAM_ON_EXPIRED)) {
2468                         roam = _TRUE;
2469                 } else if (reason == WLAN_REASON_ACTIVE_ROAM && rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
2470                         roam = _TRUE;
2471                         roam_target = pmlmepriv->roam_network;
2472                 }
2473 #ifdef CONFIG_INTEL_WIDI
2474                 else if (adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_CONNECTED) {
2475                         roam = _TRUE;
2476                 }
2477 #endif // CONFIG_INTEL_WIDI
2478
2479                 if (roam == _TRUE) {
2480                         if (rtw_to_roam(adapter) > 0)
2481                                 rtw_dec_to_roam(adapter); /* this stadel_event is caused by roaming, decrease to_roam */
2482                         else if (rtw_to_roam(adapter) == 0)
2483                                 rtw_set_to_roam(adapter, adapter->registrypriv.max_roaming_times);
2484                 } else {
2485                         rtw_set_to_roam(adapter, 0);
2486                 }
2487                 #endif /* CONFIG_LAYER2_ROAMING */
2488
2489                 rtw_free_uc_swdec_pending_queue(adapter);
2490
2491                 rtw_free_assoc_resources(adapter, 1);
2492                 rtw_indicate_disconnect(adapter);
2493
2494                 _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2495                 // remove the network entry in scanned_queue
2496                 pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);   
2497                 if (pwlan) {                    
2498                         pwlan->fixed = _FALSE;
2499                         rtw_free_network_nolock(pmlmepriv, pwlan);
2500                 }
2501                 _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2502
2503 #ifdef CONFIG_INTEL_WIDI
2504                 if (!rtw_to_roam(adapter))
2505                         process_intel_widi_disconnect(adapter, 1);
2506 #endif // CONFIG_INTEL_WIDI
2507
2508                 _rtw_roaming(adapter, roam_target);
2509         }
2510
2511         if ( check_fwstate(pmlmepriv,WIFI_ADHOC_MASTER_STATE) || 
2512               check_fwstate(pmlmepriv,WIFI_ADHOC_STATE))
2513         {
2514                 
2515                 _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
2516                 rtw_free_stainfo(adapter,  psta);
2517                 _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
2518                 
2519                 if(adapter->stapriv.asoc_sta_count== 1) //a sta + bc/mc_stainfo (not Ibss_stainfo)
2520                 { 
2521                         //rtw_indicate_disconnect(adapter);//removed@20091105
2522                         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2523                         //free old ibss network
2524                         //pwlan = rtw_find_network(&pmlmepriv->scanned_queue, pstadel->macaddr);
2525                         pwlan = rtw_find_network(&pmlmepriv->scanned_queue, tgt_network->network.MacAddress);
2526                         if(pwlan)       
2527                         {
2528                                 pwlan->fixed = _FALSE;
2529                                 rtw_free_network_nolock(pmlmepriv, pwlan); 
2530                         }
2531                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2532                         //re-create ibss
2533                         pdev_network = &(adapter->registrypriv.dev_network);                    
2534                         pibss = adapter->registrypriv.dev_network.MacAddress;
2535
2536                         _rtw_memcpy(pdev_network, &tgt_network->network, get_WLAN_BSSID_EX_sz(&tgt_network->network));
2537                         
2538                         _rtw_memset(&pdev_network->Ssid, 0, sizeof(NDIS_802_11_SSID));
2539                         _rtw_memcpy(&pdev_network->Ssid, &pmlmepriv->assoc_ssid, sizeof(NDIS_802_11_SSID));
2540         
2541                         rtw_update_registrypriv_dev_network(adapter);                   
2542
2543                         rtw_generate_random_ibss(pibss);
2544                         
2545                         if(check_fwstate(pmlmepriv,WIFI_ADHOC_STATE))
2546                         {
2547                                 set_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
2548                                 _clr_fwstate_(pmlmepriv, WIFI_ADHOC_STATE);
2549                         }
2550
2551                         if(rtw_createbss_cmd(adapter)!=_SUCCESS)
2552                         {
2553
2554                                 RT_TRACE(_module_rtl871x_ioctl_set_c_,_drv_err_,("***Error=>stadel_event_callback: rtw_createbss_cmd status FAIL*** \n "));                                                                             
2555
2556                         }
2557
2558                         
2559                 }
2560                 
2561         }
2562         
2563         _exit_critical_bh(&pmlmepriv->lock, &irqL2);
2564         
2565 _func_exit_;    
2566
2567 }
2568
2569
2570 void rtw_cpwm_event_callback(PADAPTER padapter, u8 *pbuf)
2571 {
2572 #ifdef CONFIG_LPS_LCLK
2573         struct reportpwrstate_parm *preportpwrstate;
2574 #endif
2575
2576 _func_enter_;
2577
2578         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("+rtw_cpwm_event_callback !!!\n"));
2579 #ifdef CONFIG_LPS_LCLK
2580         preportpwrstate = (struct reportpwrstate_parm*)pbuf;
2581         preportpwrstate->state |= (u8)(adapter_to_pwrctl(padapter)->cpwm_tog + 0x80);
2582         cpwm_int_hdl(padapter, preportpwrstate);
2583 #endif
2584
2585 _func_exit_;
2586
2587 }
2588
2589
2590 void rtw_wmm_event_callback(PADAPTER padapter, u8 *pbuf)
2591 {
2592 _func_enter_;
2593
2594         WMMOnAssocRsp(padapter);
2595
2596 _func_exit_;
2597
2598 }
2599
2600 /*
2601 * _rtw_join_timeout_handler - Timeout/faliure handler for CMD JoinBss
2602 * @adapter: pointer to _adapter structure
2603 */
2604 void _rtw_join_timeout_handler (_adapter *adapter)
2605 {
2606         _irqL irqL;
2607         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
2608
2609 #if 0
2610         if (adapter->bDriverStopped == _TRUE){
2611                 _rtw_up_sema(&pmlmepriv->assoc_terminate);
2612                 return;
2613         }
2614 #endif  
2615
2616 _func_enter_;           
2617
2618
2619         DBG_871X("%s, fw_state=%x\n", __FUNCTION__, get_fwstate(pmlmepriv));
2620         
2621         if(adapter->bDriverStopped ||adapter->bSurpriseRemoved)
2622                 return;
2623
2624         
2625         _enter_critical_bh(&pmlmepriv->lock, &irqL);
2626
2627         #ifdef CONFIG_LAYER2_ROAMING
2628         if (rtw_to_roam(adapter) > 0) { /* join timeout caused by roaming */
2629                 while(1) {
2630                         rtw_dec_to_roam(adapter);
2631                         if (rtw_to_roam(adapter) != 0) { /* try another */
2632                                 int do_join_r;
2633                                 DBG_871X("%s try another roaming\n", __FUNCTION__);
2634                                 if( _SUCCESS!=(do_join_r=rtw_do_join(adapter)) ) {
2635                                         DBG_871X("%s roaming do_join return %d\n", __FUNCTION__ ,do_join_r);
2636                                         continue;
2637                                 }
2638                                 break;
2639                         } else {
2640 #ifdef CONFIG_INTEL_WIDI
2641                                 if(adapter->mlmepriv.widi_state == INTEL_WIDI_STATE_ROAMING)
2642                                 {
2643                                         _rtw_memset(pmlmepriv->sa_ext, 0x00, L2SDTA_SERVICE_VE_LEN);
2644                                         intel_widi_wk_cmd(adapter, INTEL_WIDI_LISTEN_WK, NULL, 0);
2645                                         DBG_871X("change to widi listen\n");
2646                                 }
2647 #endif // CONFIG_INTEL_WIDI
2648                                 DBG_871X("%s We've try roaming but fail\n", __FUNCTION__);
2649                                 rtw_indicate_disconnect(adapter);
2650                                 break;
2651                         }
2652                 }
2653                 
2654         } else 
2655         #endif
2656         {
2657                 rtw_indicate_disconnect(adapter);
2658                 free_scanqueue(pmlmepriv);//???
2659
2660 #ifdef CONFIG_IOCTL_CFG80211
2661                 //indicate disconnect for the case that join_timeout and check_fwstate != FW_LINKED
2662                 rtw_cfg80211_indicate_disconnect(adapter);
2663 #endif //CONFIG_IOCTL_CFG80211
2664
2665         }
2666
2667         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2668         
2669
2670 #ifdef CONFIG_DRVEXT_MODULE_WSC 
2671         drvext_assoc_fail_indicate(&adapter->drvextpriv);       
2672 #endif  
2673
2674         
2675 _func_exit_;
2676
2677 }
2678
2679 /*
2680 * rtw_scan_timeout_handler - Timeout/Faliure handler for CMD SiteSurvey
2681 * @adapter: pointer to _adapter structure
2682 */
2683 void rtw_scan_timeout_handler (_adapter *adapter)
2684 {       
2685         _irqL irqL;
2686         struct  mlme_priv *pmlmepriv = &adapter->mlmepriv;
2687         
2688         DBG_871X(FUNC_ADPT_FMT" fw_state=%x\n", FUNC_ADPT_ARG(adapter), get_fwstate(pmlmepriv));
2689
2690         _enter_critical_bh(&pmlmepriv->lock, &irqL);
2691         
2692         _clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
2693
2694         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2695
2696         rtw_indicate_scan_done(adapter, _TRUE);
2697
2698 #if defined(CONFIG_CONCURRENT_MODE) && defined(CONFIG_IOCTL_CFG80211)
2699         if (adapter->pbuddy_adapter) {
2700                 _adapter *buddy_adapter = adapter->pbuddy_adapter;
2701                 struct mlme_priv *buddy_mlme = &(buddy_adapter->mlmepriv);
2702                 struct rtw_wdev_priv *buddy_wdev_priv = adapter_wdev_data(buddy_adapter);
2703                 bool indicate_buddy_scan = _FALSE;
2704
2705                 _enter_critical_bh(&buddy_wdev_priv->scan_req_lock, &irqL);
2706                 if (buddy_wdev_priv->scan_request && buddy_mlme->scanning_via_buddy_intf == _TRUE) {
2707                         buddy_mlme->scanning_via_buddy_intf = _FALSE;
2708                         clr_fwstate(buddy_mlme, _FW_UNDER_SURVEY);
2709                         indicate_buddy_scan = _TRUE;
2710                 }
2711                 _exit_critical_bh(&buddy_wdev_priv->scan_req_lock, &irqL);
2712
2713                 if (indicate_buddy_scan == _TRUE) {
2714                         rtw_indicate_scan_done(buddy_adapter, _TRUE);
2715                 }
2716         }
2717 #endif /* CONFIG_CONCURRENT_MODE */
2718 }
2719
2720 void rtw_mlme_reset_auto_scan_int(_adapter *adapter)
2721 {
2722         struct mlme_priv *mlme = &adapter->mlmepriv;
2723
2724 #ifdef CONFIG_P2P
2725         if(!rtw_p2p_chk_state(&adapter->wdinfo, P2P_STATE_NONE)) {
2726                 mlme->auto_scan_int_ms = 0; /* disabled */
2727                 goto exit;
2728         }
2729 #endif  
2730
2731         if(adapter->registrypriv.wifi_spec) {
2732                 mlme->auto_scan_int_ms = 60*1000;
2733 #ifdef CONFIG_LAYER2_ROAMING
2734         } else if(rtw_chk_roam_flags(adapter, RTW_ROAM_ACTIVE)) {
2735                 if (check_fwstate(mlme, WIFI_STATION_STATE) && check_fwstate(mlme, _FW_LINKED))
2736                         mlme->auto_scan_int_ms = mlme->roam_scan_int_ms;
2737 #endif
2738         } else {
2739                 mlme->auto_scan_int_ms = 0; /* disabled */
2740         }
2741 exit:
2742         return;
2743 }
2744
2745 static void rtw_auto_scan_handler(_adapter *padapter)
2746 {
2747         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2748
2749         rtw_mlme_reset_auto_scan_int(padapter);
2750
2751         if (pmlmepriv->auto_scan_int_ms != 0
2752                 && rtw_get_passing_time_ms(pmlmepriv->scan_start_time) > pmlmepriv->auto_scan_int_ms) {
2753
2754                 if (!padapter->registrypriv.wifi_spec) {
2755                         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE) 
2756                         {
2757                                 DBG_871X(FUNC_ADPT_FMT" _FW_UNDER_SURVEY|_FW_UNDER_LINKING\n", FUNC_ADPT_ARG(padapter));
2758                                 goto exit;
2759                         }
2760                         
2761                         if(pmlmepriv->LinkDetectInfo.bBusyTraffic == _TRUE)
2762                         {
2763                                 DBG_871X(FUNC_ADPT_FMT" exit BusyTraffic\n", FUNC_ADPT_ARG(padapter));
2764                                 goto exit;
2765                         }
2766                 }
2767
2768 #ifdef CONFIG_CONCURRENT_MODE
2769                 if (rtw_buddy_adapter_up(padapter))
2770                 {
2771                         if ((check_buddy_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE) ||
2772                                 (padapter->pbuddy_adapter->mlmepriv.LinkDetectInfo.bBusyTraffic == _TRUE))
2773                         {               
2774                                 DBG_871X(FUNC_ADPT_FMT", but buddy_intf is under scanning or linking or BusyTraffic\n"
2775                                         , FUNC_ADPT_ARG(padapter));
2776                                 goto exit;
2777                         }
2778                 }
2779 #endif
2780
2781                 DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
2782
2783                 rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
2784         }
2785
2786 exit:
2787         return;
2788 }
2789
2790 void rtw_dynamic_check_timer_handlder(_adapter *adapter)
2791 {
2792 #ifdef CONFIG_AP_MODE
2793         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
2794 #endif //CONFIG_AP_MODE
2795         struct registry_priv *pregistrypriv = &adapter->registrypriv;
2796 #ifdef CONFIG_CONCURRENT_MODE   
2797         PADAPTER pbuddy_adapter = adapter->pbuddy_adapter;
2798 #endif
2799
2800         if(!adapter)
2801                 return; 
2802
2803         if(adapter->hw_init_completed == _FALSE)
2804                 return;
2805
2806         if ((adapter->bDriverStopped == _TRUE)||(adapter->bSurpriseRemoved== _TRUE))
2807                 return;
2808
2809         
2810 #ifdef CONFIG_CONCURRENT_MODE
2811         if(pbuddy_adapter)
2812         {
2813                 if(adapter->net_closed == _TRUE && pbuddy_adapter->net_closed == _TRUE)
2814                 {
2815                         return;
2816                 }               
2817         }
2818         else
2819 #endif //CONFIG_CONCURRENT_MODE
2820         if(adapter->net_closed == _TRUE)
2821         {
2822                 return;
2823         }       
2824
2825 #ifdef CONFIG_BT_COEXIST
2826         if(is_primary_adapter(adapter))
2827                 DBG_871X("IsBtDisabled=%d, IsBtControlLps=%d\n", rtw_btcoex_IsBtDisabled(adapter), rtw_btcoex_IsBtControlLps(adapter));
2828 #endif
2829
2830 #ifdef CONFIG_LPS_LCLK_WD_TIMER
2831         if ((adapter_to_pwrctl(adapter)->bFwCurrentInPSMode ==_TRUE )
2832 #ifdef CONFIG_BT_COEXIST
2833                 && (rtw_btcoex_IsBtControlLps(adapter) == _FALSE)
2834 #endif          
2835                 ) 
2836         {
2837                 u8 bEnterPS;    
2838                 
2839                 linked_status_chk(adapter);     
2840                         
2841                 bEnterPS = traffic_status_watchdog(adapter, 1);
2842                 if(bEnterPS)
2843                 {
2844                         //rtw_lps_ctrl_wk_cmd(adapter, LPS_CTRL_ENTER, 1);
2845                         rtw_hal_dm_watchdog_in_lps(adapter);
2846                 }
2847                 else
2848                 {
2849                         //call rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_LEAVE, 1) in traffic_status_watchdog()
2850                 }
2851                         
2852         }
2853         else
2854 #endif //CONFIG_LPS_LCLK_WD_TIMER       
2855         {
2856                 if(is_primary_adapter(adapter))
2857                 {       
2858                         rtw_dynamic_chk_wk_cmd(adapter);                
2859                 }       
2860         }       
2861
2862         /* auto site survey */
2863         rtw_auto_scan_handler(adapter);
2864
2865 #ifndef CONFIG_ACTIVE_KEEP_ALIVE_CHECK
2866 #ifdef CONFIG_AP_MODE
2867         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) == _TRUE)
2868         {
2869                 expire_timeout_chk(adapter);
2870         }       
2871 #endif
2872 #endif //!CONFIG_ACTIVE_KEEP_ALIVE_CHECK
2873
2874 #ifdef CONFIG_BR_EXT
2875
2876 #if (LINUX_VERSION_CODE > KERNEL_VERSION(2, 6, 35))
2877         rcu_read_lock();
2878 #endif  // (LINUX_VERSION_CODE > KERNEL_VERSION(2, 6, 35))
2879
2880 #if (LINUX_VERSION_CODE <= KERNEL_VERSION(2, 6, 35)) 
2881         if( adapter->pnetdev->br_port 
2882 #else   // (LINUX_VERSION_CODE <= KERNEL_VERSION(2, 6, 35))
2883         if( rcu_dereference(adapter->pnetdev->rx_handler_data)
2884 #endif  // (LINUX_VERSION_CODE <= KERNEL_VERSION(2, 6, 35))
2885                 && (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_ADHOC_STATE) == _TRUE) )
2886         {
2887                 // expire NAT2.5 entry
2888                 void nat25_db_expire(_adapter *priv);
2889                 nat25_db_expire(adapter);
2890
2891                 if (adapter->pppoe_connection_in_progress > 0) {
2892                         adapter->pppoe_connection_in_progress--;
2893                 }
2894                 
2895                 // due to rtw_dynamic_check_timer_handlder() is called every 2 seconds
2896                 if (adapter->pppoe_connection_in_progress > 0) {
2897                         adapter->pppoe_connection_in_progress--;
2898                 }
2899         }
2900
2901 #if (LINUX_VERSION_CODE > KERNEL_VERSION(2, 6, 35))
2902         rcu_read_unlock();
2903 #endif  // (LINUX_VERSION_CODE > KERNEL_VERSION(2, 6, 35))
2904
2905 #endif  // CONFIG_BR_EXT
2906         
2907 }
2908
2909
2910 #ifdef CONFIG_SET_SCAN_DENY_TIMER
2911 inline bool rtw_is_scan_deny(_adapter *adapter)
2912 {
2913         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2914         return (ATOMIC_READ(&mlmepriv->set_scan_deny) != 0) ? _TRUE : _FALSE;
2915 }
2916
2917 inline void rtw_clear_scan_deny(_adapter *adapter)
2918 {
2919         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2920         ATOMIC_SET(&mlmepriv->set_scan_deny, 0);
2921         if (0)
2922         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
2923 }
2924
2925 void rtw_set_scan_deny_timer_hdl(_adapter *adapter)
2926 {
2927         rtw_clear_scan_deny(adapter);
2928 }
2929
2930 void rtw_set_scan_deny(_adapter *adapter, u32 ms)
2931 {
2932         struct mlme_priv *mlmepriv = &adapter->mlmepriv;
2933 #ifdef CONFIG_CONCURRENT_MODE
2934         struct mlme_priv *b_mlmepriv;
2935 #endif
2936
2937         if (0)
2938         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter));
2939         ATOMIC_SET(&mlmepriv->set_scan_deny, 1);
2940         _set_timer(&mlmepriv->set_scan_deny_timer, ms);
2941         
2942 #ifdef CONFIG_CONCURRENT_MODE
2943         if (!adapter->pbuddy_adapter)
2944                 return;
2945
2946         if (0)
2947         DBG_871X(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(adapter->pbuddy_adapter));
2948         b_mlmepriv = &adapter->pbuddy_adapter->mlmepriv;
2949         ATOMIC_SET(&b_mlmepriv->set_scan_deny, 1);
2950         _set_timer(&b_mlmepriv->set_scan_deny_timer, ms);       
2951 #endif
2952         
2953 }
2954 #endif
2955
2956 #ifdef CONFIG_LAYER2_ROAMING
2957 /*
2958 * Select a new roaming candidate from the original @param candidate and @param competitor
2959 * @return _TRUE: candidate is updated
2960 * @return _FALSE: candidate is not updated
2961 */
2962 static int rtw_check_roaming_candidate(struct mlme_priv *mlme
2963         , struct wlan_network **candidate, struct wlan_network *competitor)
2964 {
2965         int updated = _FALSE;
2966         _adapter *adapter = container_of(mlme, _adapter, mlmepriv);
2967
2968         if(is_same_ess(&competitor->network, &mlme->cur_network.network) == _FALSE)
2969                 goto exit;
2970
2971         if(rtw_is_desired_network(adapter, competitor) == _FALSE)
2972                 goto exit;
2973
2974         DBG_871X("roam candidate:%s %s("MAC_FMT", ch%3u) rssi:%d, age:%5d\n",
2975                 (competitor == mlme->cur_network_scanned)?"*":" " ,
2976                 competitor->network.Ssid.Ssid,
2977                 MAC_ARG(competitor->network.MacAddress),
2978                 competitor->network.Configuration.DSConfig,
2979                 (int)competitor->network.Rssi,
2980                 rtw_get_passing_time_ms(competitor->last_scanned)
2981         );
2982
2983         /* got specific addr to roam */
2984         if (!is_zero_mac_addr(mlme->roam_tgt_addr)) {
2985                 if(_rtw_memcmp(mlme->roam_tgt_addr, competitor->network.MacAddress, ETH_ALEN) == _TRUE)
2986                         goto update;
2987                 else
2988                         goto exit;
2989         }
2990         #if 1
2991         if(rtw_get_passing_time_ms((u32)competitor->last_scanned) >= mlme->roam_scanr_exp_ms)
2992                 goto exit;
2993
2994         if (competitor->network.Rssi - mlme->cur_network_scanned->network.Rssi < mlme->roam_rssi_diff_th)
2995                 goto exit;
2996
2997         if(*candidate != NULL && (*candidate)->network.Rssi>=competitor->network.Rssi)
2998                 goto exit;
2999         #else
3000         goto exit;
3001         #endif
3002
3003 update:
3004         *candidate = competitor;
3005         updated = _TRUE;
3006
3007 exit:
3008         return updated;
3009 }
3010
3011 int rtw_select_roaming_candidate(struct mlme_priv *mlme)
3012 {
3013         _irqL   irqL;
3014         int ret = _FAIL;
3015         _list   *phead;
3016         _adapter *adapter;      
3017         _queue  *queue  = &(mlme->scanned_queue);
3018         struct  wlan_network    *pnetwork = NULL;
3019         struct  wlan_network    *candidate = NULL;
3020         u8              bSupportAntDiv = _FALSE;
3021
3022 _func_enter_;
3023
3024         if (mlme->cur_network_scanned == NULL) {
3025                 rtw_warn_on(1);
3026                 goto exit;
3027         }
3028
3029         _enter_critical_bh(&(mlme->scanned_queue.lock), &irqL);
3030         phead = get_list_head(queue);           
3031         adapter = (_adapter *)mlme->nic_hdl;
3032
3033         mlme->pscanned = get_next(phead);
3034
3035         while (!rtw_end_of_queue_search(phead, mlme->pscanned)) {
3036
3037                 pnetwork = LIST_CONTAINOR(mlme->pscanned, struct wlan_network, list);
3038                 if(pnetwork==NULL){
3039                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("%s return _FAIL:(pnetwork==NULL)\n", __FUNCTION__));
3040                         ret = _FAIL;
3041                         goto exit;
3042                 }
3043                 
3044                 mlme->pscanned = get_next(mlme->pscanned);
3045
3046                 if (0)
3047                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
3048                         , pnetwork->network.Ssid.Ssid
3049                         , MAC_ARG(pnetwork->network.MacAddress)
3050                         , pnetwork->network.Configuration.DSConfig
3051                         , (int)pnetwork->network.Rssi);
3052
3053                 rtw_check_roaming_candidate(mlme, &candidate, pnetwork);
3054  
3055         }
3056
3057         if(candidate == NULL) {
3058                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __FUNCTION__);
3059                 ret = _FAIL;
3060                 goto exit;
3061         } else {
3062                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __FUNCTION__,
3063                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
3064                         candidate->network.Configuration.DSConfig);
3065
3066                 mlme->roam_network = candidate;
3067
3068                 if (_rtw_memcmp(candidate->network.MacAddress, mlme->roam_tgt_addr, ETH_ALEN) == _TRUE)
3069                         _rtw_memset(mlme->roam_tgt_addr,0, ETH_ALEN);
3070         }
3071
3072         ret = _SUCCESS;
3073 exit:
3074         _exit_critical_bh(&(mlme->scanned_queue.lock), &irqL);
3075
3076         return ret;
3077 }
3078 #endif /* CONFIG_LAYER2_ROAMING */
3079
3080 /*
3081 * Select a new join candidate from the original @param candidate and @param competitor
3082 * @return _TRUE: candidate is updated
3083 * @return _FALSE: candidate is not updated
3084 */
3085 static int rtw_check_join_candidate(struct mlme_priv *mlme
3086         , struct wlan_network **candidate, struct wlan_network *competitor)
3087 {
3088         int updated = _FALSE;
3089         _adapter *adapter = container_of(mlme, _adapter, mlmepriv);
3090
3091
3092         //check bssid, if needed
3093         if(mlme->assoc_by_bssid==_TRUE) {
3094                 if(_rtw_memcmp(competitor->network.MacAddress, mlme->assoc_bssid, ETH_ALEN) ==_FALSE)
3095                         goto exit;
3096         }
3097
3098         //check ssid, if needed
3099         if(mlme->assoc_ssid.Ssid[0] && mlme->assoc_ssid.SsidLength) {
3100                 if(     competitor->network.Ssid.SsidLength != mlme->assoc_ssid.SsidLength
3101                         || _rtw_memcmp(competitor->network.Ssid.Ssid, mlme->assoc_ssid.Ssid, mlme->assoc_ssid.SsidLength) == _FALSE
3102                 )
3103                         goto exit;
3104         }
3105
3106         if(rtw_is_desired_network(adapter, competitor)  == _FALSE)
3107                 goto exit;
3108
3109 #ifdef  CONFIG_LAYER2_ROAMING
3110         if(rtw_to_roam(adapter) > 0) {
3111                 if(     rtw_get_passing_time_ms((u32)competitor->last_scanned) >= mlme->roam_scanr_exp_ms
3112                         || is_same_ess(&competitor->network, &mlme->cur_network.network) == _FALSE
3113                 )
3114                         goto exit;
3115         }
3116 #endif
3117         
3118         if(*candidate == NULL ||(*candidate)->network.Rssi<competitor->network.Rssi )
3119         {
3120                 *candidate = competitor;
3121                 updated = _TRUE;
3122         }
3123
3124         if(updated){
3125                 DBG_871X("[by_bssid:%u][assoc_ssid:%s]"
3126                         #ifdef  CONFIG_LAYER2_ROAMING
3127                         "[to_roam:%u] "
3128                         #endif
3129                         "new candidate: %s("MAC_FMT", ch%u) rssi:%d\n",
3130                         mlme->assoc_by_bssid,
3131                         mlme->assoc_ssid.Ssid,
3132                         #ifdef  CONFIG_LAYER2_ROAMING
3133                         rtw_to_roam(adapter),
3134                         #endif
3135                         (*candidate)->network.Ssid.Ssid,
3136                         MAC_ARG((*candidate)->network.MacAddress),
3137                         (*candidate)->network.Configuration.DSConfig,
3138                         (int)(*candidate)->network.Rssi
3139                 );
3140         }
3141
3142 exit:
3143         return updated;
3144 }
3145
3146 /*
3147 Calling context:
3148 The caller of the sub-routine will be in critical section...
3149
3150 The caller must hold the following spinlock
3151
3152 pmlmepriv->lock
3153
3154
3155 */
3156
3157 int rtw_select_and_join_from_scanned_queue(struct mlme_priv *pmlmepriv )
3158 {
3159         _irqL   irqL;
3160         int ret;
3161         _list   *phead;
3162         _adapter *adapter;      
3163         _queue  *queue  = &(pmlmepriv->scanned_queue);
3164         struct  wlan_network    *pnetwork = NULL;
3165         struct  wlan_network    *candidate = NULL;
3166         u8              bSupportAntDiv = _FALSE;
3167
3168 _func_enter_;
3169
3170         adapter = (_adapter *)pmlmepriv->nic_hdl;
3171
3172         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
3173
3174         #ifdef CONFIG_LAYER2_ROAMING
3175         if (pmlmepriv->roam_network) {
3176                 candidate = pmlmepriv->roam_network;
3177                 pmlmepriv->roam_network = NULL;
3178                 goto candidate_exist;
3179         }
3180         #endif
3181
3182         phead = get_list_head(queue);
3183         pmlmepriv->pscanned = get_next(phead);
3184
3185         while (!rtw_end_of_queue_search(phead, pmlmepriv->pscanned)) {
3186
3187                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
3188                 if(pnetwork==NULL){
3189                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("%s return _FAIL:(pnetwork==NULL)\n", __FUNCTION__));
3190                         ret = _FAIL;
3191                         goto exit;
3192                 }
3193                 
3194                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
3195
3196                 if (0)
3197                 DBG_871X("%s("MAC_FMT", ch%u) rssi:%d\n"
3198                         , pnetwork->network.Ssid.Ssid
3199                         , MAC_ARG(pnetwork->network.MacAddress)
3200                         , pnetwork->network.Configuration.DSConfig
3201                         , (int)pnetwork->network.Rssi);
3202
3203                 rtw_check_join_candidate(pmlmepriv, &candidate, pnetwork);
3204  
3205         }
3206
3207         if(candidate == NULL) {
3208                 DBG_871X("%s: return _FAIL(candidate == NULL)\n", __FUNCTION__);
3209 #ifdef CONFIG_WOWLAN
3210                 _clr_fwstate_(pmlmepriv, _FW_LINKED|_FW_UNDER_LINKING);
3211 #endif
3212                 ret = _FAIL;
3213                 goto exit;
3214         } else {
3215                 DBG_871X("%s: candidate: %s("MAC_FMT", ch:%u)\n", __FUNCTION__,
3216                         candidate->network.Ssid.Ssid, MAC_ARG(candidate->network.MacAddress),
3217                         candidate->network.Configuration.DSConfig);
3218                 goto candidate_exist;
3219         }
3220         
3221 candidate_exist:
3222
3223         // check for situation of  _FW_LINKED 
3224         if (check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE)
3225         {
3226                 DBG_871X("%s: _FW_LINKED while ask_for_joinbss!!!\n", __FUNCTION__);
3227
3228                 #if 0 // for WPA/WPA2 authentication, wpa_supplicant will expect authentication from AP, it is needed to reconnect AP...
3229                 if(is_same_network(&pmlmepriv->cur_network.network, &candidate->network))
3230                 {
3231                         DBG_871X("%s: _FW_LINKED and is same network, it needn't join again\n", __FUNCTION__);
3232
3233                         rtw_indicate_connect(adapter);//rtw_indicate_connect again
3234                                 
3235                         ret = 2;
3236                         goto exit;
3237                 }
3238                 else
3239                 #endif
3240                 {
3241                         rtw_disassoc_cmd(adapter, 0, _TRUE);
3242                         rtw_indicate_disconnect(adapter);
3243                         rtw_free_assoc_resources(adapter, 0);
3244                 }
3245         }
3246         
3247         #ifdef CONFIG_ANTENNA_DIVERSITY
3248         rtw_hal_get_def_var(adapter, HAL_DEF_IS_SUPPORT_ANT_DIV, &(bSupportAntDiv));
3249         if(_TRUE == bSupportAntDiv)     
3250         {
3251                 u8 CurrentAntenna;
3252                 rtw_hal_get_def_var(adapter, HAL_DEF_CURRENT_ANTENNA, &(CurrentAntenna));                       
3253                 DBG_871X("#### Opt_Ant_(%s) , cur_Ant(%s)\n",
3254                         (2==candidate->network.PhyInfo.Optimum_antenna)?"A":"B",
3255                         (2==CurrentAntenna)?"A":"B"
3256                 );
3257         }
3258         #endif
3259         set_fwstate(pmlmepriv, _FW_UNDER_LINKING);
3260         ret = rtw_joinbss_cmd(adapter, candidate);
3261         
3262 exit:
3263         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
3264
3265 _func_exit_;
3266
3267         return ret;
3268 }
3269
3270 sint rtw_set_auth(_adapter * adapter,struct security_priv *psecuritypriv)
3271 {
3272         struct  cmd_obj* pcmd;
3273         struct  setauth_parm *psetauthparm;
3274         struct  cmd_priv        *pcmdpriv=&(adapter->cmdpriv);
3275         sint            res=_SUCCESS;
3276         
3277 _func_enter_;   
3278
3279         pcmd = (struct  cmd_obj*)rtw_zmalloc(sizeof(struct      cmd_obj));
3280         if(pcmd==NULL){
3281                 res= _FAIL;  //try again
3282                 goto exit;
3283         }
3284         
3285         psetauthparm=(struct setauth_parm*)rtw_zmalloc(sizeof(struct setauth_parm));
3286         if(psetauthparm==NULL){
3287                 rtw_mfree((unsigned char *)pcmd, sizeof(struct  cmd_obj));
3288                 res= _FAIL;
3289                 goto exit;
3290         }
3291
3292         _rtw_memset(psetauthparm, 0, sizeof(struct setauth_parm));
3293         psetauthparm->mode=(unsigned char)psecuritypriv->dot11AuthAlgrthm;
3294         
3295         pcmd->cmdcode = _SetAuth_CMD_;
3296         pcmd->parmbuf = (unsigned char *)psetauthparm;   
3297         pcmd->cmdsz =  (sizeof(struct setauth_parm));  
3298         pcmd->rsp = NULL;
3299         pcmd->rspsz = 0;
3300
3301
3302         _rtw_init_listhead(&pcmd->list);
3303
3304         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("after enqueue set_auth_cmd, auth_mode=%x\n", psecuritypriv->dot11AuthAlgrthm));
3305
3306         res = rtw_enqueue_cmd(pcmdpriv, pcmd);
3307
3308 exit:
3309
3310 _func_exit_;
3311
3312         return res;
3313
3314 }
3315
3316
3317 sint rtw_set_key(_adapter * adapter,struct security_priv *psecuritypriv,sint keyid, u8 set_tx, bool enqueue)
3318 {
3319         u8      keylen;
3320         struct cmd_obj          *pcmd;
3321         struct setkey_parm      *psetkeyparm;
3322         struct cmd_priv         *pcmdpriv = &(adapter->cmdpriv);
3323         struct mlme_priv                *pmlmepriv = &(adapter->mlmepriv);
3324         sint    res=_SUCCESS;
3325         
3326 _func_enter_;
3327
3328         psetkeyparm=(struct setkey_parm*)rtw_zmalloc(sizeof(struct setkey_parm));
3329         if(psetkeyparm==NULL){          
3330                 res= _FAIL;
3331                 goto exit;
3332         }
3333         _rtw_memset(psetkeyparm, 0, sizeof(struct setkey_parm));
3334
3335         if(psecuritypriv->dot11AuthAlgrthm ==dot11AuthAlgrthm_8021X){           
3336                 psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy;      
3337                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n rtw_set_key: psetkeyparm->algorithm=(unsigned char)psecuritypriv->dot118021XGrpPrivacy=%d \n", psetkeyparm->algorithm));
3338         }       
3339         else{
3340                 psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm;
3341                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n rtw_set_key: psetkeyparm->algorithm=(u8)psecuritypriv->dot11PrivacyAlgrthm=%d \n", psetkeyparm->algorithm));
3342
3343         }
3344         psetkeyparm->keyid = (u8)keyid;//0~3
3345         psetkeyparm->set_tx = set_tx;
3346         if (is_wep_enc(psetkeyparm->algorithm))
3347                 adapter->securitypriv.key_mask |= BIT(psetkeyparm->keyid);
3348
3349         DBG_871X("==> rtw_set_key algorithm(%x),keyid(%x),key_mask(%x)\n",psetkeyparm->algorithm,psetkeyparm->keyid, adapter->securitypriv.key_mask);
3350         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n rtw_set_key: psetkeyparm->algorithm=%d psetkeyparm->keyid=(u8)keyid=%d \n",psetkeyparm->algorithm, keyid));
3351
3352         switch(psetkeyparm->algorithm){
3353                         
3354                 case _WEP40_:
3355                         keylen=5;
3356                         _rtw_memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
3357                         break;
3358                 case _WEP104_:
3359                         keylen=13;
3360                         _rtw_memcpy(&(psetkeyparm->key[0]), &(psecuritypriv->dot11DefKey[keyid].skey[0]), keylen);
3361                         break;
3362                 case _TKIP_:
3363                         keylen=16;                      
3364                         _rtw_memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
3365                         psetkeyparm->grpkey=1;
3366                         break;
3367                 case _AES_:
3368                         keylen=16;                      
3369                         _rtw_memcpy(&psetkeyparm->key, &psecuritypriv->dot118021XGrpKey[keyid], keylen);
3370                         psetkeyparm->grpkey=1;
3371                         break;
3372                 default:
3373                         RT_TRACE(_module_rtl871x_mlme_c_,_drv_err_,("\n rtw_set_key:psecuritypriv->dot11PrivacyAlgrthm = %x (must be 1 or 2 or 4 or 5)\n",psecuritypriv->dot11PrivacyAlgrthm));
3374                         res= _FAIL;
3375                         rtw_mfree((unsigned char *)psetkeyparm, sizeof(struct setkey_parm));
3376                         goto exit;
3377         }
3378                 
3379                 
3380         if(enqueue){
3381                 pcmd = (struct  cmd_obj*)rtw_zmalloc(sizeof(struct      cmd_obj));
3382                 if(pcmd==NULL){
3383                         rtw_mfree((unsigned char *)psetkeyparm, sizeof(struct setkey_parm));
3384                         res= _FAIL;  //try again
3385                         goto exit;
3386                 }
3387                 
3388                 pcmd->cmdcode = _SetKey_CMD_;
3389                 pcmd->parmbuf = (u8 *)psetkeyparm;   
3390                 pcmd->cmdsz =  (sizeof(struct setkey_parm));  
3391                 pcmd->rsp = NULL;
3392                 pcmd->rspsz = 0;
3393
3394                 _rtw_init_listhead(&pcmd->list);
3395
3396                 //_rtw_init_sema(&(pcmd->cmd_sem), 0);
3397
3398                 res = rtw_enqueue_cmd(pcmdpriv, pcmd);
3399         }
3400         else{
3401                 setkey_hdl(adapter, (u8 *)psetkeyparm);
3402                 rtw_mfree((u8 *) psetkeyparm, sizeof(struct setkey_parm));
3403         }
3404 exit:
3405 _func_exit_;
3406         return res;
3407
3408 }
3409
3410
3411 //adjust IEs for rtw_joinbss_cmd in WMM
3412 int rtw_restruct_wmm_ie(_adapter *adapter, u8 *in_ie, u8 *out_ie, uint in_len, uint initial_out_len)
3413 {
3414         unsigned        int ielength=0;
3415         unsigned int i, j;
3416
3417         i = 12; //after the fixed IE
3418         while(i<in_len)
3419         {
3420                 ielength = initial_out_len;             
3421                 
3422                 if(in_ie[i] == 0xDD && in_ie[i+2] == 0x00 && in_ie[i+3] == 0x50  && in_ie[i+4] == 0xF2 && in_ie[i+5] == 0x02 && i+5 < in_len) //WMM element ID and OUI
3423                 {
3424
3425                         //Append WMM IE to the last index of out_ie
3426                         /*
3427                         for(j=i; j< i+(in_ie[i+1]+2); j++)
3428                         {
3429                                 out_ie[ielength] = in_ie[j];                            
3430                                 ielength++;
3431                         }
3432                         out_ie[initial_out_len+8] = 0x00; //force the QoS Info Field to be zero
3433                         */
3434                        
3435                         for ( j = i; j < i + 9; j++ )
3436                         {
3437                             out_ie[ ielength] = in_ie[ j ];
3438                             ielength++;
3439                         } 
3440                         out_ie[ initial_out_len + 1 ] = 0x07;
3441                         out_ie[ initial_out_len + 6 ] = 0x00;
3442                         out_ie[ initial_out_len + 8 ] = 0x00;
3443         
3444                         break;
3445                 }
3446
3447                 i+=(in_ie[i+1]+2); // to the next IE element
3448         }
3449         
3450         return ielength;
3451         
3452 }
3453
3454
3455 //
3456 // Ported from 8185: IsInPreAuthKeyList(). (Renamed from SecIsInPreAuthKeyList(), 2006-10-13.)
3457 // Added by Annie, 2006-05-07.
3458 //
3459 // Search by BSSID,
3460 // Return Value:
3461 //              -1              :if there is no pre-auth key in the  table
3462 //              >=0             :if there is pre-auth key, and   return the entry id
3463 //
3464 //
3465
3466 static int SecIsInPMKIDList(_adapter *Adapter, u8 *bssid)
3467 {
3468         struct security_priv *psecuritypriv=&Adapter->securitypriv;
3469         int i=0;
3470
3471         do
3472         {
3473                 if( ( psecuritypriv->PMKIDList[i].bUsed ) && 
3474                     (  _rtw_memcmp( psecuritypriv->PMKIDList[i].Bssid, bssid, ETH_ALEN ) == _TRUE ) )
3475                 {
3476                         break;
3477                 }
3478                 else
3479                 {       
3480                         i++;
3481                         //continue;
3482                 }
3483                 
3484         }while(i<NUM_PMKID_CACHE);
3485
3486         if( i == NUM_PMKID_CACHE )
3487         { 
3488                 i = -1;// Could not find.
3489         }
3490         else
3491         { 
3492                 // There is one Pre-Authentication Key for the specific BSSID.
3493         }
3494
3495         return (i);
3496         
3497 }
3498
3499 //
3500 // Check the RSN IE length
3501 // If the RSN IE length <= 20, the RSN IE didn't include the PMKID information
3502 // 0-11th element in the array are the fixed IE
3503 // 12th element in the array is the IE
3504 // 13th element in the array is the IE length  
3505 //
3506
3507 static int rtw_append_pmkid(_adapter *Adapter,int iEntry, u8 *ie, uint ie_len)
3508 {
3509         struct security_priv *psecuritypriv=&Adapter->securitypriv;
3510
3511         if(ie[13]<=20){ 
3512                 // The RSN IE didn't include the PMK ID, append the PMK information 
3513                         ie[ie_len]=1;
3514                         ie_len++;
3515                         ie[ie_len]=0;   //PMKID count = 0x0100
3516                         ie_len++;
3517                         _rtw_memcpy(    &ie[ie_len], &psecuritypriv->PMKIDList[iEntry].PMKID, 16);
3518                 
3519                         ie_len+=16;
3520                         ie[13]+=18;//PMKID length = 2+16
3521
3522         }
3523         return (ie_len);
3524 }
3525
3526 sint rtw_restruct_sec_ie(_adapter *adapter,u8 *in_ie, u8 *out_ie, uint in_len)
3527 {
3528         u8 authmode=0x0, securitytype, match;
3529         u8 sec_ie[255], uncst_oui[4], bkup_ie[255];
3530         u8 wpa_oui[4]={0x0, 0x50, 0xf2, 0x01};
3531         uint    ielength, cnt, remove_cnt;
3532         int iEntry;
3533
3534         struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
3535         struct security_priv *psecuritypriv=&adapter->securitypriv;
3536         uint    ndisauthmode=psecuritypriv->ndisauthtype;
3537         uint ndissecuritytype = psecuritypriv->ndisencryptstatus;
3538         
3539 _func_enter_;
3540
3541         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_,
3542                  ("+rtw_restruct_sec_ie: ndisauthmode=%d ndissecuritytype=%d\n",
3543                   ndisauthmode, ndissecuritytype));
3544         
3545         //copy fixed ie only
3546         _rtw_memcpy(out_ie, in_ie,12);
3547         ielength=12;
3548         if((ndisauthmode==Ndis802_11AuthModeWPA)||(ndisauthmode==Ndis802_11AuthModeWPAPSK))
3549                         authmode=_WPA_IE_ID_;
3550         if((ndisauthmode==Ndis802_11AuthModeWPA2)||(ndisauthmode==Ndis802_11AuthModeWPA2PSK))
3551                         authmode=_WPA2_IE_ID_;
3552
3553         if(check_fwstate(pmlmepriv, WIFI_UNDER_WPS))
3554         {
3555                 _rtw_memcpy(out_ie+ielength, psecuritypriv->wps_ie, psecuritypriv->wps_ie_len);
3556                 
3557                 ielength += psecuritypriv->wps_ie_len;
3558         }
3559         else if((authmode==_WPA_IE_ID_)||(authmode==_WPA2_IE_ID_))
3560         {               
3561                 //copy RSN or SSN               
3562                 _rtw_memcpy(&out_ie[ielength], &psecuritypriv->supplicant_ie[0], psecuritypriv->supplicant_ie[1]+2);
3563                 /* debug for CONFIG_IEEE80211W
3564                 {
3565                         int jj;
3566                         printk("supplicant_ie_length=%d &&&&&&&&&&&&&&&&&&&\n", psecuritypriv->supplicant_ie[1]+2);
3567                         for(jj=0; jj < psecuritypriv->supplicant_ie[1]+2; jj++)
3568                                 printk(" %02x ", psecuritypriv->supplicant_ie[jj]);
3569                         printk("\n");
3570                 }*/
3571                 ielength+=psecuritypriv->supplicant_ie[1]+2;
3572                 rtw_report_sec_ie(adapter, authmode, psecuritypriv->supplicant_ie);
3573         
3574 #ifdef CONFIG_DRVEXT_MODULE
3575                 drvext_report_sec_ie(&adapter->drvextpriv, authmode, sec_ie);   
3576 #endif
3577         }
3578
3579         iEntry = SecIsInPMKIDList(adapter, pmlmepriv->assoc_bssid);
3580         if(iEntry<0)
3581         {
3582                 return ielength;
3583         }
3584         else
3585         {
3586                 if(authmode == _WPA2_IE_ID_)
3587                 {
3588                         ielength=rtw_append_pmkid(adapter, iEntry, out_ie, ielength);
3589                 }
3590         }
3591
3592 _func_exit_;
3593         
3594         return ielength;        
3595 }
3596
3597 void rtw_init_registrypriv_dev_network( _adapter* adapter)
3598 {
3599         struct registry_priv* pregistrypriv = &adapter->registrypriv;
3600         struct eeprom_priv* peepriv = &adapter->eeprompriv;
3601         WLAN_BSSID_EX    *pdev_network = &pregistrypriv->dev_network;
3602         u8 *myhwaddr = myid(peepriv);
3603         
3604 _func_enter_;
3605
3606         _rtw_memcpy(pdev_network->MacAddress, myhwaddr, ETH_ALEN);
3607
3608         _rtw_memcpy(&pdev_network->Ssid, &pregistrypriv->ssid, sizeof(NDIS_802_11_SSID));
3609         
3610         pdev_network->Configuration.Length=sizeof(NDIS_802_11_CONFIGURATION);
3611         pdev_network->Configuration.BeaconPeriod = 100; 
3612         pdev_network->Configuration.FHConfig.Length = 0;
3613         pdev_network->Configuration.FHConfig.HopPattern = 0;
3614         pdev_network->Configuration.FHConfig.HopSet = 0;
3615         pdev_network->Configuration.FHConfig.DwellTime = 0;
3616         
3617         
3618 _func_exit_;    
3619         
3620 }
3621
3622 void rtw_update_registrypriv_dev_network(_adapter* adapter) 
3623 {
3624         int sz=0;
3625         struct registry_priv* pregistrypriv = &adapter->registrypriv;   
3626         WLAN_BSSID_EX    *pdev_network = &pregistrypriv->dev_network;
3627         struct  security_priv*  psecuritypriv = &adapter->securitypriv;
3628         struct  wlan_network    *cur_network = &adapter->mlmepriv.cur_network;
3629         //struct        xmit_priv       *pxmitpriv = &adapter->xmitpriv;
3630
3631 _func_enter_;
3632
3633 #if 0
3634         pxmitpriv->vcs_setting = pregistrypriv->vrtl_carrier_sense;
3635         pxmitpriv->vcs = pregistrypriv->vcs_type;
3636         pxmitpriv->vcs_type = pregistrypriv->vcs_type;
3637         //pxmitpriv->rts_thresh = pregistrypriv->rts_thresh;
3638         pxmitpriv->frag_len = pregistrypriv->frag_thresh;
3639         
3640         adapter->qospriv.qos_option = pregistrypriv->wmm_enable;
3641 #endif  
3642
3643         pdev_network->Privacy = (psecuritypriv->dot11PrivacyAlgrthm > 0 ? 1 : 0) ; // adhoc no 802.1x
3644
3645         pdev_network->Rssi = 0;
3646
3647         switch(pregistrypriv->wireless_mode)
3648         {
3649                 case WIRELESS_11B:
3650                         pdev_network->NetworkTypeInUse = (Ndis802_11DS);
3651                         break;  
3652                 case WIRELESS_11G:
3653                 case WIRELESS_11BG:
3654                 case WIRELESS_11_24N:
3655                 case WIRELESS_11G_24N:
3656                 case WIRELESS_11BG_24N:
3657                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
3658                         break;
3659                 case WIRELESS_11A:
3660                 case WIRELESS_11A_5N:
3661                         pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
3662                         break;
3663                 case WIRELESS_11ABGN:
3664                         if(pregistrypriv->channel > 14)
3665                                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM5);
3666                         else
3667                                 pdev_network->NetworkTypeInUse = (Ndis802_11OFDM24);
3668                         break;
3669                 default :
3670                         // TODO
3671                         break;
3672         }
3673         
3674         pdev_network->Configuration.DSConfig = (pregistrypriv->channel);
3675         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("pregistrypriv->channel=%d, pdev_network->Configuration.DSConfig=0x%x\n", pregistrypriv->channel, pdev_network->Configuration.DSConfig));  
3676
3677         if(cur_network->network.InfrastructureMode == Ndis802_11IBSS)
3678                 pdev_network->Configuration.ATIMWindow = (0);
3679
3680         pdev_network->InfrastructureMode = (cur_network->network.InfrastructureMode);
3681
3682         // 1. Supported rates
3683         // 2. IE
3684
3685         //rtw_set_supported_rate(pdev_network->SupportedRates, pregistrypriv->wireless_mode) ; // will be called in rtw_generate_ie
3686         sz = rtw_generate_ie(pregistrypriv);
3687
3688         pdev_network->IELength = sz;
3689
3690         pdev_network->Length = get_WLAN_BSSID_EX_sz((WLAN_BSSID_EX  *)pdev_network);
3691
3692         //notes: translate IELength & Length after assign the Length to cmdsz in createbss_cmd();
3693         //pdev_network->IELength = cpu_to_le32(sz);
3694                 
3695 _func_exit_;    
3696
3697 }
3698
3699 void rtw_get_encrypt_decrypt_from_registrypriv(_adapter* adapter)
3700 {
3701 _func_enter_;
3702
3703
3704 _func_exit_;    
3705         
3706 }
3707
3708 //the fucntion is at passive_level 
3709 void rtw_joinbss_reset(_adapter *padapter)
3710 {
3711         u8      threshold;
3712         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
3713
3714 #ifdef CONFIG_80211N_HT 
3715         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
3716 #endif
3717
3718         //todo: if you want to do something io/reg/hw setting before join_bss, please add code here
3719         
3720
3721
3722
3723 #ifdef CONFIG_80211N_HT
3724
3725         pmlmepriv->num_FortyMHzIntolerant = 0;
3726
3727         pmlmepriv->num_sta_no_ht = 0;
3728
3729         phtpriv->ampdu_enable = _FALSE;//reset to disabled
3730
3731 #if defined( CONFIG_USB_HCI) || defined (CONFIG_SDIO_HCI)
3732         // TH=1 => means that invalidate usb rx aggregation
3733         // TH=0 => means that validate usb rx aggregation, use init value.
3734         if(phtpriv->ht_option)
3735         {
3736                 if(padapter->registrypriv.wifi_spec==1)         
3737                         threshold = 1;
3738                 else
3739                         threshold = 0;          
3740                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
3741         }
3742         else
3743         {
3744                 threshold = 1;
3745                 rtw_hal_set_hwreg(padapter, HW_VAR_RXDMA_AGG_PG_TH, (u8 *)(&threshold));
3746         }
3747 #endif
3748
3749 #endif  
3750
3751 }
3752
3753
3754 #ifdef CONFIG_80211N_HT
3755 void    rtw_ht_use_default_setting(_adapter *padapter)
3756 {
3757         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
3758         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
3759         struct registry_priv    *pregistrypriv = &padapter->registrypriv;
3760         BOOLEAN         bHwLDPCSupport = _FALSE, bHwSTBCSupport = _FALSE;
3761         BOOLEAN         bHwSupportBeamformer = _FALSE, bHwSupportBeamformee = _FALSE;
3762
3763         if (pregistrypriv->wifi_spec)
3764                 phtpriv->bss_coexist = 1;
3765         else
3766                 phtpriv->bss_coexist = 0;
3767
3768         phtpriv->sgi_40m = TEST_FLAG(pregistrypriv->short_gi, BIT1) ? _TRUE : _FALSE;
3769         phtpriv->sgi_20m = TEST_FLAG(pregistrypriv->short_gi, BIT0) ? _TRUE : _FALSE;
3770
3771         // LDPC support
3772         rtw_hal_get_def_var(padapter, HAL_DEF_RX_LDPC, (u8 *)&bHwLDPCSupport);
3773         CLEAR_FLAGS(phtpriv->ldpc_cap);
3774         if(bHwLDPCSupport)
3775         {
3776                 if(TEST_FLAG(pregistrypriv->ldpc_cap, BIT4))
3777                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_RX);
3778         }
3779         rtw_hal_get_def_var(padapter, HAL_DEF_TX_LDPC, (u8 *)&bHwLDPCSupport);
3780         if(bHwLDPCSupport)
3781         {
3782                 if(TEST_FLAG(pregistrypriv->ldpc_cap, BIT5))
3783                         SET_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_TX);
3784         }
3785         if (phtpriv->ldpc_cap)
3786                 DBG_871X("[HT] Support LDPC = 0x%02X\n", phtpriv->ldpc_cap);
3787
3788         // STBC
3789         rtw_hal_get_def_var(padapter, HAL_DEF_TX_STBC, (u8 *)&bHwSTBCSupport);
3790         CLEAR_FLAGS(phtpriv->stbc_cap);
3791         if(bHwSTBCSupport)
3792         {
3793                 if(TEST_FLAG(pregistrypriv->stbc_cap, BIT5))
3794                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX);
3795         }
3796         rtw_hal_get_def_var(padapter, HAL_DEF_RX_STBC, (u8 *)&bHwSTBCSupport);
3797         if(bHwSTBCSupport)
3798         {
3799                 if(TEST_FLAG(pregistrypriv->stbc_cap, BIT4))
3800                         SET_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX);
3801         }
3802         if (phtpriv->stbc_cap)
3803                 DBG_871X("[HT] Support STBC = 0x%02X\n", phtpriv->stbc_cap);
3804
3805         // Beamforming setting
3806         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMER, (u8 *)&bHwSupportBeamformer);
3807         rtw_hal_get_def_var(padapter, HAL_DEF_EXPLICIT_BEAMFORMEE, (u8 *)&bHwSupportBeamformee);
3808         CLEAR_FLAGS(phtpriv->beamform_cap);
3809         if(TEST_FLAG(pregistrypriv->beamform_cap, BIT4) && bHwSupportBeamformer)
3810         {
3811                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE);
3812                 DBG_871X("[HT] Support Beamformer\n");
3813         }
3814         if(TEST_FLAG(pregistrypriv->beamform_cap, BIT5) && bHwSupportBeamformee)
3815         {
3816                 SET_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE);
3817                 DBG_871X("[HT] Support Beamformee\n");
3818         }
3819 }
3820
3821 void rtw_build_wmm_ie_ht(_adapter *padapter, u8 *out_ie, uint *pout_len)
3822 {
3823         unsigned char WMM_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
3824         int out_len;
3825         u8 *pframe;
3826
3827         if(padapter->mlmepriv.qospriv.qos_option == 0)
3828         {
3829                 out_len = *pout_len;
3830                 pframe = rtw_set_ie(out_ie+out_len, _VENDOR_SPECIFIC_IE_, 
3831                                                         _WMM_IE_Length_, WMM_IE, pout_len);
3832
3833                 padapter->mlmepriv.qospriv.qos_option = 1;
3834         }
3835 }
3836
3837 /* the fucntion is >= passive_level */
3838 unsigned int rtw_restructure_ht_ie(_adapter *padapter, u8 *in_ie, u8 *out_ie, uint in_len, uint *pout_len, u8 channel)
3839 {
3840         u32 ielen, out_len;
3841         HT_CAP_AMPDU_FACTOR max_rx_ampdu_factor;
3842         unsigned char *p, *pframe;
3843         struct rtw_ieee80211_ht_cap ht_capie;
3844         u8      cbw40_enable = 0, stbc_rx_enable = 0, rf_type = 0, operation_bw=0;
3845         struct registry_priv *pregistrypriv = &padapter->registrypriv;
3846         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
3847         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
3848
3849         phtpriv->ht_option = _FALSE;
3850
3851         out_len = *pout_len;
3852
3853         _rtw_memset(&ht_capie, 0, sizeof(struct rtw_ieee80211_ht_cap));
3854
3855         ht_capie.cap_info = IEEE80211_HT_CAP_DSSSCCK40;
3856
3857         if (phtpriv->sgi_20m)
3858                 ht_capie.cap_info |= IEEE80211_HT_CAP_SGI_20;
3859
3860         /* Get HT BW */
3861         if (in_ie == NULL) {
3862                 /* TDLS: TODO 20/40 issue */
3863                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
3864                         operation_bw = padapter->mlmeextpriv.cur_bwmode;
3865                         if (operation_bw > CHANNEL_WIDTH_40)
3866                                 operation_bw = CHANNEL_WIDTH_40;
3867                 } else
3868                         /* TDLS: TODO 40? */
3869                         operation_bw = CHANNEL_WIDTH_40;
3870         } else {
3871                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
3872                 if (p && (ielen == sizeof(struct ieee80211_ht_addt_info))) {
3873                         struct HT_info_element *pht_info = (struct HT_info_element *)(p+2);
3874                         if (pht_info->infos[0] & BIT(2)) {
3875                                 switch (pht_info->infos[0] & 0x3) {
3876                                 case 1:
3877                                 case 3:
3878                                         operation_bw = CHANNEL_WIDTH_40;
3879                                         break;
3880                                 default:
3881                                         operation_bw = CHANNEL_WIDTH_20;
3882                                         break;
3883                                 }
3884                         } else {
3885                                 operation_bw = CHANNEL_WIDTH_20;
3886                         }
3887                 }
3888         }
3889
3890         /* to disable 40M Hz support while gd_bw_40MHz_en = 0 */
3891         if (channel > 14) {
3892                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
3893                         cbw40_enable = 1;
3894         } else {
3895                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
3896                         cbw40_enable = 1;
3897         }
3898
3899         if ((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) {
3900                 ht_capie.cap_info |= IEEE80211_HT_CAP_SUP_WIDTH;
3901                 if (phtpriv->sgi_40m)
3902                         ht_capie.cap_info |= IEEE80211_HT_CAP_SGI_40;
3903         }
3904
3905         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX))
3906                 ht_capie.cap_info |= IEEE80211_HT_CAP_TX_STBC;
3907
3908         /* todo: disable SM power save mode */
3909         ht_capie.cap_info |= IEEE80211_HT_CAP_SM_PS;
3910
3911         if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_RX)) {
3912                 if((pregistrypriv->rx_stbc == 0x3) ||                                                   /* enable for 2.4/5 GHz */
3913                         ((channel <= 14) && (pregistrypriv->rx_stbc == 0x1)) || /* enable for 2.4GHz */
3914                         ((channel > 14) && (pregistrypriv->rx_stbc == 0x2)) ||          /* enable for 5GHz */
3915                         (pregistrypriv->wifi_spec == 1)) {
3916                         stbc_rx_enable = 1;
3917                         DBG_871X("declare supporting RX STBC\n");
3918                 }
3919         }
3920
3921         rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
3922 #ifdef RTL8192C_RECONFIG_TO_1T1R
3923         rf_type = RF_1T1R;
3924 #endif
3925         switch (rf_type) {
3926         case RF_1T1R:
3927                 if (stbc_rx_enable)
3928                         ht_capie.cap_info |= IEEE80211_HT_CAP_RX_STBC_1R;//RX STBC One spatial stream
3929
3930                 _rtw_memcpy(ht_capie.supp_mcs_set, MCS_rate_1R, 16);
3931                 break;
3932
3933         case RF_2T2R:
3934         case RF_1T2R:
3935         default:
3936
3937                 if (stbc_rx_enable)
3938                         ht_capie.cap_info |= IEEE80211_HT_CAP_RX_STBC_2R;//RX STBC two spatial stream
3939
3940                 #ifdef CONFIG_DISABLE_MCS13TO15
3941                 if(((cbw40_enable == 1) && (operation_bw == CHANNEL_WIDTH_40)) && (pregistrypriv->wifi_spec!=1))
3942                         _rtw_memcpy(ht_capie.supp_mcs_set, MCS_rate_2R_MCS13TO15_OFF, 16);
3943                 else
3944                         _rtw_memcpy(ht_capie.supp_mcs_set, MCS_rate_2R, 16);
3945                 #else //CONFIG_DISABLE_MCS13TO15
3946                 _rtw_memcpy(ht_capie.supp_mcs_set, MCS_rate_2R, 16);
3947                 #endif //CONFIG_DISABLE_MCS13TO15
3948                 break;
3949         }
3950
3951         {
3952                 u32 rx_packet_offset, max_recvbuf_sz;
3953                 rtw_hal_get_def_var(padapter, HAL_DEF_RX_PACKET_OFFSET, &rx_packet_offset);
3954                 rtw_hal_get_def_var(padapter, HAL_DEF_MAX_RECVBUF_SZ, &max_recvbuf_sz);
3955                 //if(max_recvbuf_sz-rx_packet_offset>(8191-256)) {
3956                 //      DBG_871X("%s IEEE80211_HT_CAP_MAX_AMSDU is set\n", __FUNCTION__);
3957                 //      ht_capie.cap_info = ht_capie.cap_info |IEEE80211_HT_CAP_MAX_AMSDU;
3958                 //}
3959         }
3960         /*      
3961         AMPDU_para [1:0]:Max AMPDU Len => 0:8k , 1:16k, 2:32k, 3:64k
3962         AMPDU_para [4:2]:Min MPDU Start Spacing 
3963         */
3964
3965         /*
3966         #if defined(CONFIG_RTL8188E )&& defined (CONFIG_SDIO_HCI)
3967         ht_capie.ampdu_params_info = 2;
3968         #else
3969         ht_capie.ampdu_params_info = (IEEE80211_HT_CAP_AMPDU_FACTOR&0x03);
3970         #endif
3971         */
3972
3973         rtw_hal_get_def_var(padapter, HW_VAR_MAX_RX_AMPDU_FACTOR, &max_rx_ampdu_factor);
3974         ht_capie.ampdu_params_info = (max_rx_ampdu_factor&0x03);
3975
3976         if(padapter->securitypriv.dot11PrivacyAlgrthm == _AES_ )
3977                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&(0x07<<2));
3978         else
3979                 ht_capie.ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
3980
3981 #ifdef CONFIG_BEAMFORMING
3982         ht_capie.tx_BF_cap_info = 0;
3983
3984         // HT Beamformer
3985         if(TEST_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE))
3986         {
3987                 // Transmit NDP Capable
3988                 SET_HT_CAP_TXBF_TRANSMIT_NDP_CAP(&ht_capie, 1);
3989                 // Explicit Compressed Steering Capable
3990                 SET_HT_CAP_TXBF_EXPLICIT_COMP_STEERING_CAP(&ht_capie, 1);
3991                 // Compressed Steering Number Antennas
3992                 SET_HT_CAP_TXBF_COMP_STEERING_NUM_ANTENNAS(&ht_capie, 1);
3993         }
3994
3995         // HT Beamformee
3996         if(TEST_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE))
3997         {
3998                 // Receive NDP Capable
3999                 SET_HT_CAP_TXBF_RECEIVE_NDP_CAP(&ht_capie, 1);
4000                 // Explicit Compressed Beamforming Feedback Capable
4001                 SET_HT_CAP_TXBF_EXPLICIT_COMP_FEEDBACK_CAP(&ht_capie, 2);
4002         }
4003 #endif
4004
4005         pframe = rtw_set_ie(out_ie+out_len, _HT_CAPABILITY_IE_, 
4006                                                 sizeof(struct rtw_ieee80211_ht_cap), (unsigned char*)&ht_capie, pout_len);
4007
4008         phtpriv->ht_option = _TRUE;
4009
4010         if(in_ie!=NULL)
4011         {
4012                 p = rtw_get_ie(in_ie, _HT_ADD_INFO_IE_, &ielen, in_len);
4013                 if(p && (ielen==sizeof(struct ieee80211_ht_addt_info)))
4014                 {
4015                         out_len = *pout_len;            
4016                         pframe = rtw_set_ie(out_ie+out_len, _HT_ADD_INFO_IE_, ielen, p+2 , pout_len);
4017                 }
4018         }
4019
4020         return (phtpriv->ht_option);
4021         
4022 }
4023
4024 //the fucntion is > passive_level (in critical_section)
4025 void rtw_update_ht_cap(_adapter *padapter, u8 *pie, uint ie_len, u8 channel)
4026 {       
4027         u8 *p, max_ampdu_sz;
4028         int len;                
4029         //struct sta_info *bmc_sta, *psta;
4030         struct rtw_ieee80211_ht_cap *pht_capie;
4031         struct ieee80211_ht_addt_info *pht_addtinfo;
4032         //struct recv_reorder_ctrl *preorder_ctrl;
4033         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
4034         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
4035         //struct recv_priv *precvpriv = &padapter->recvpriv;
4036         struct registry_priv *pregistrypriv = &padapter->registrypriv;
4037         //struct wlan_network *pcur_network = &(pmlmepriv->cur_network);;
4038         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
4039         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
4040         u8 cbw40_enable=0;
4041         
4042
4043         if(!phtpriv->ht_option)
4044                 return;
4045
4046         if ((!pmlmeinfo->HT_info_enable) || (!pmlmeinfo->HT_caps_enable))
4047                 return;
4048
4049         DBG_871X("+rtw_update_ht_cap()\n");
4050
4051         //maybe needs check if ap supports rx ampdu.
4052         if((phtpriv->ampdu_enable==_FALSE) &&(pregistrypriv->ampdu_enable==1))
4053         {
4054                 if(pregistrypriv->wifi_spec==1)
4055                 {
4056                         phtpriv->ampdu_enable = _FALSE;
4057                 }
4058                 else
4059                 {
4060                         phtpriv->ampdu_enable = _TRUE;
4061                 }
4062         }
4063         else if(pregistrypriv->ampdu_enable==2)
4064         {
4065                 phtpriv->ampdu_enable = _TRUE;
4066         }
4067
4068         
4069         //check Max Rx A-MPDU Size 
4070         len = 0;
4071         p = rtw_get_ie(pie+sizeof (NDIS_802_11_FIXED_IEs), _HT_CAPABILITY_IE_, &len, ie_len-sizeof (NDIS_802_11_FIXED_IEs));
4072         if(p && len>0)  
4073         {
4074                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);
4075                 max_ampdu_sz = (pht_capie->ampdu_params_info & IEEE80211_HT_CAP_AMPDU_FACTOR);
4076                 max_ampdu_sz = 1 << (max_ampdu_sz+3); // max_ampdu_sz (kbytes);
4077                 
4078                 //DBG_871X("rtw_update_ht_cap(): max_ampdu_sz=%d\n", max_ampdu_sz);
4079                 phtpriv->rx_ampdu_maxlen = max_ampdu_sz;
4080                 
4081         }
4082
4083
4084         len=0;
4085         p = rtw_get_ie(pie+sizeof (NDIS_802_11_FIXED_IEs), _HT_ADD_INFO_IE_, &len, ie_len-sizeof (NDIS_802_11_FIXED_IEs));
4086         if(p && len>0)  
4087         {
4088                 pht_addtinfo = (struct ieee80211_ht_addt_info *)(p+2);
4089                 //todo:
4090         }
4091
4092         if (channel > 14) {
4093                 if ((pregistrypriv->bw_mode & 0xf0) > 0)
4094                         cbw40_enable = 1;
4095         } else {
4096                 if ((pregistrypriv->bw_mode & 0x0f) > 0)
4097                         cbw40_enable = 1;
4098         }
4099
4100         //update cur_bwmode & cur_ch_offset
4101         if ((cbw40_enable) &&
4102                 (pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info & BIT(1)) && 
4103                 (pmlmeinfo->HT_info.infos[0] & BIT(2)))
4104         {
4105                 int i;
4106                 u8      rf_type;
4107
4108                 padapter->HalFunc.GetHwRegHandler(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
4109
4110                 //update the MCS rates
4111                 for (i = 0; i < 16; i++)
4112                 {
4113                         if((rf_type == RF_1T1R) || (rf_type == RF_1T2R))
4114                         {
4115                                 pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= MCS_rate_1R[i];
4116                         }
4117                         else
4118                         {
4119                                 #ifdef CONFIG_DISABLE_MCS13TO15
4120                                 if(pmlmeext->cur_bwmode == CHANNEL_WIDTH_40 && pregistrypriv->wifi_spec != 1 )
4121                                 {
4122                                         pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= MCS_rate_2R_MCS13TO15_OFF[i];
4123                                 }
4124                                 else
4125                                         pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= MCS_rate_2R[i];
4126                                 #else
4127                                 pmlmeinfo->HT_caps.u.HT_cap_element.MCS_rate[i] &= MCS_rate_2R[i];
4128                                 #endif //CONFIG_DISABLE_MCS13TO15
4129                         }
4130                         #ifdef RTL8192C_RECONFIG_TO_1T1R
4131                         {
4132                                 pmlmeinfo->HT_caps.HT_cap_element.MCS_rate[i] &= MCS_rate_1R[i];
4133                         }
4134                         #endif
4135                 }
4136                 //switch to the 40M Hz mode accoring to the AP
4137                 //pmlmeext->cur_bwmode = CHANNEL_WIDTH_40;
4138                 switch ((pmlmeinfo->HT_info.infos[0] & 0x3))
4139                 {
4140                         case EXTCHNL_OFFSET_UPPER:
4141                                 pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
4142                                 break;
4143                         
4144                         case EXTCHNL_OFFSET_LOWER:
4145                                 pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
4146                                 break;
4147                                 
4148                         default:
4149                                 pmlmeext->cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
4150                                 break;
4151                 }               
4152         }
4153
4154         //
4155         // Config SM Power Save setting
4156         //
4157         pmlmeinfo->SM_PS = (pmlmeinfo->HT_caps.u.HT_cap_element.HT_caps_info & 0x0C) >> 2;
4158         if(pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
4159         {
4160                 /*u8 i;
4161                 //update the MCS rates
4162                 for (i = 0; i < 16; i++)
4163                 {
4164                         pmlmeinfo->HT_caps.HT_cap_element.MCS_rate[i] &= MCS_rate_1R[i];
4165                 }*/
4166                 DBG_871X("%s(): WLAN_HT_CAP_SM_PS_STATIC\n",__FUNCTION__);
4167         }
4168
4169         //
4170         // Config current HT Protection mode.
4171         //
4172         pmlmeinfo->HT_protection = pmlmeinfo->HT_info.infos[1] & 0x3;
4173
4174         
4175         
4176 #if 0 //move to rtw_update_sta_info_client()
4177         //for A-MPDU Rx reordering buffer control for bmc_sta & sta_info
4178         //if A-MPDU Rx is enabled, reseting  rx_ordering_ctrl wstart_b(indicate_seq) to default value=0xffff
4179         //todo: check if AP can send A-MPDU packets
4180         bmc_sta = rtw_get_bcmc_stainfo(padapter);
4181         if(bmc_sta)
4182         {
4183                 for(i=0; i < 16 ; i++)
4184                 {
4185                         //preorder_ctrl = &precvpriv->recvreorder_ctrl[i];
4186                         preorder_ctrl = &bmc_sta->recvreorder_ctrl[i];
4187                         preorder_ctrl->enable = _FALSE;
4188                         preorder_ctrl->indicate_seq = 0xffff;
4189                         #ifdef DBG_RX_SEQ
4190                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u \n", __FUNCTION__, __LINE__,
4191                                 preorder_ctrl->indicate_seq);
4192                         #endif
4193                         preorder_ctrl->wend_b= 0xffff;
4194                         preorder_ctrl->wsize_b = 64;//max_ampdu_sz;//ex. 32(kbytes) -> wsize_b=32
4195                 }
4196         }
4197
4198         psta = rtw_get_stainfo(&padapter->stapriv, pcur_network->network.MacAddress);
4199         if(psta)
4200         {
4201                 for(i=0; i < 16 ; i++)
4202                 {
4203                         //preorder_ctrl = &precvpriv->recvreorder_ctrl[i];
4204                         preorder_ctrl = &psta->recvreorder_ctrl[i];
4205                         preorder_ctrl->enable = _FALSE;
4206                         preorder_ctrl->indicate_seq = 0xffff;
4207                         #ifdef DBG_RX_SEQ
4208                         DBG_871X("DBG_RX_SEQ %s:%d indicate_seq:%u \n", __FUNCTION__, __LINE__,
4209                                 preorder_ctrl->indicate_seq);
4210                         #endif
4211                         preorder_ctrl->wend_b= 0xffff;
4212                         preorder_ctrl->wsize_b = 64;//max_ampdu_sz;//ex. 32(kbytes) -> wsize_b=32
4213                 }
4214         }
4215 #endif  
4216
4217 }
4218
4219 #ifdef CONFIG_TDLS
4220 void rtw_issue_addbareq_cmd_tdls(_adapter *padapter, struct xmit_frame *pxmitframe)
4221 {
4222         struct pkt_attrib *pattrib =&pxmitframe->attrib;
4223         struct sta_info *ptdls_sta = NULL;
4224         u8 issued;
4225         int priority;
4226         struct ht_priv  *phtpriv;
4227
4228         priority = pattrib->priority;
4229
4230         if(pattrib->direct_link == _TRUE)
4231         {
4232                 ptdls_sta = rtw_get_stainfo(&padapter->stapriv, pattrib->dst);
4233                 if((ptdls_sta != NULL) && (ptdls_sta->tdls_sta_state & TDLS_ESTABLISHED))
4234                 {
4235                         phtpriv = &ptdls_sta->htpriv;
4236
4237                         if((phtpriv->ht_option==_TRUE) && (phtpriv->ampdu_enable==_TRUE)) 
4238                         {
4239                                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
4240                                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
4241
4242                                 if(0==issued)
4243                                 {
4244                                         DBG_871X("rtw_issue_addbareq_cmd, p=%d\n", priority);
4245                                         ptdls_sta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
4246                                         rtw_addbareq_cmd(padapter,(u8)priority, pattrib->dst);
4247                                 }
4248                         }
4249                 }
4250         }
4251 }
4252 #endif //CONFIG_TDLS
4253
4254 void rtw_issue_addbareq_cmd(_adapter *padapter, struct xmit_frame *pxmitframe)
4255 {
4256         u8 issued;
4257         int priority;
4258         struct sta_info *psta=NULL;
4259         struct ht_priv  *phtpriv;
4260         struct pkt_attrib *pattrib =&pxmitframe->attrib;
4261         s32 bmcst = IS_MCAST(pattrib->ra);
4262
4263         //if(bmcst || (padapter->mlmepriv.LinkDetectInfo.bTxBusyTraffic == _FALSE))
4264         if(bmcst || (padapter->mlmepriv.LinkDetectInfo.NumTxOkInPeriod<100))    
4265                 return;
4266         
4267         priority = pattrib->priority;
4268
4269 #ifdef CONFIG_TDLS
4270         rtw_issue_addbareq_cmd_tdls(padapter, pxmitframe);
4271 #endif //CONFIG_TDLS
4272
4273         psta = rtw_get_stainfo(&padapter->stapriv, pattrib->ra);
4274         if(pattrib->psta != psta)
4275         {
4276                 DBG_871X("%s, pattrib->psta(%p) != psta(%p)\n", __func__, pattrib->psta, psta);
4277                 return;
4278         }
4279         
4280         if(psta==NULL)
4281         {
4282                 DBG_871X("%s, psta==NUL\n", __func__);
4283                 return;
4284         }
4285
4286         if(!(psta->state &_FW_LINKED))
4287         {
4288                 DBG_871X("%s, psta->state(0x%x) != _FW_LINKED\n", __func__, psta->state);
4289                 return;
4290         }       
4291
4292
4293         phtpriv = &psta->htpriv;
4294
4295         if((phtpriv->ht_option==_TRUE) && (phtpriv->ampdu_enable==_TRUE)) 
4296         {
4297                 issued = (phtpriv->agg_enable_bitmap>>priority)&0x1;
4298                 issued |= (phtpriv->candidate_tid_bitmap>>priority)&0x1;
4299
4300                 if(0==issued)
4301                 {
4302                         DBG_871X("rtw_issue_addbareq_cmd, p=%d\n", priority);
4303                         psta->htpriv.candidate_tid_bitmap |= BIT((u8)priority);
4304                         rtw_addbareq_cmd(padapter,(u8) priority, pattrib->ra);
4305                 }
4306         }
4307
4308 }
4309
4310 void rtw_append_exented_cap(_adapter *padapter, u8 *out_ie, uint *pout_len)
4311 {
4312         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
4313         struct ht_priv          *phtpriv = &pmlmepriv->htpriv;
4314 #ifdef CONFIG_80211AC_VHT
4315         struct vht_priv *pvhtpriv = &pmlmepriv->vhtpriv;
4316 #endif //CONFIG_80211AC_VHT
4317         u8      cap_content[8] = {0};
4318         u8      *pframe;
4319
4320
4321         if (phtpriv->bss_coexist) {
4322                 SET_EXT_CAPABILITY_ELE_BSS_COEXIST(cap_content, 1);
4323         }
4324
4325 #ifdef CONFIG_80211AC_VHT
4326         if (pvhtpriv->vht_option) {
4327                 SET_EXT_CAPABILITY_ELE_OP_MODE_NOTIF(cap_content, 1);
4328         }
4329 #endif //CONFIG_80211AC_VHT
4330
4331         pframe = rtw_set_ie(out_ie+*pout_len, EID_EXTCapability, 8, cap_content , pout_len);
4332 }
4333 #endif
4334
4335 #ifdef CONFIG_LAYER2_ROAMING
4336 inline void rtw_set_to_roam(_adapter *adapter, u8 to_roam)
4337 {
4338         if (to_roam == 0)
4339                 adapter->mlmepriv.to_join = _FALSE;
4340         adapter->mlmepriv.to_roam = to_roam;
4341 }
4342
4343 inline u8 rtw_dec_to_roam(_adapter *adapter)
4344 {
4345         adapter->mlmepriv.to_roam--;
4346         return adapter->mlmepriv.to_roam;
4347 }
4348
4349 inline u8 rtw_to_roam(_adapter *adapter)
4350 {
4351         return adapter->mlmepriv.to_roam;
4352 }
4353
4354 void rtw_roaming(_adapter *padapter, struct wlan_network *tgt_network)
4355 {
4356         _irqL irqL;
4357         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
4358
4359         _enter_critical_bh(&pmlmepriv->lock, &irqL);
4360         _rtw_roaming(padapter, tgt_network);
4361         _exit_critical_bh(&pmlmepriv->lock, &irqL);
4362 }
4363 void _rtw_roaming(_adapter *padapter, struct wlan_network *tgt_network)
4364 {
4365         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
4366         struct wlan_network *cur_network = &pmlmepriv->cur_network;
4367         int do_join_r;
4368         
4369         if(0 < rtw_to_roam(padapter)) {
4370                 DBG_871X("roaming from %s("MAC_FMT"), length:%d\n",
4371                                 cur_network->network.Ssid.Ssid, MAC_ARG(cur_network->network.MacAddress),
4372                                 cur_network->network.Ssid.SsidLength);
4373                 _rtw_memcpy(&pmlmepriv->assoc_ssid, &cur_network->network.Ssid, sizeof(NDIS_802_11_SSID));
4374
4375                 pmlmepriv->assoc_by_bssid = _FALSE;
4376
4377 #ifdef CONFIG_WAPI_SUPPORT
4378                 rtw_wapi_return_all_sta_info(padapter);
4379 #endif
4380
4381                 while(1) {
4382                         if( _SUCCESS==(do_join_r=rtw_do_join(padapter)) ) {
4383                                 break;
4384                         } else {
4385                                 DBG_871X("roaming do_join return %d\n", do_join_r);
4386                                 rtw_dec_to_roam(padapter);
4387                                 
4388                                 if(rtw_to_roam(padapter) > 0) {
4389                                         continue;
4390                                 } else {
4391                                         DBG_871X("%s(%d) -to roaming fail, indicate_disconnect\n", __FUNCTION__,__LINE__);
4392                                         rtw_indicate_disconnect(padapter);
4393                                         break;
4394                                 }
4395                         }
4396                 }
4397         }
4398         
4399 }
4400 #endif /* CONFIG_LAYER2_ROAMING */
4401
4402 sint rtw_linked_check(_adapter *padapter)
4403 {
4404         if(     (check_fwstate(&padapter->mlmepriv, WIFI_AP_STATE) == _TRUE) ||
4405                         (check_fwstate(&padapter->mlmepriv, WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE) == _TRUE))
4406         {
4407                 if(padapter->stapriv.asoc_sta_count > 2)
4408                         return _TRUE;
4409         }
4410         else
4411         {       //Station mode
4412                 if(check_fwstate(&padapter->mlmepriv, _FW_LINKED)== _TRUE)
4413                         return _TRUE;
4414         }
4415         return _FALSE;
4416 }
4417
4418 #ifdef CONFIG_CONCURRENT_MODE
4419 sint rtw_buddy_adapter_up(_adapter *padapter)
4420 {       
4421         sint res = _FALSE;
4422         
4423         if(padapter == NULL)
4424                 return res;
4425
4426
4427         if(padapter->pbuddy_adapter == NULL)
4428         {
4429                 res = _FALSE;
4430         }
4431         else if( (padapter->pbuddy_adapter->bDriverStopped) || (padapter->pbuddy_adapter->bSurpriseRemoved) ||
4432                 (padapter->pbuddy_adapter->bup == _FALSE) || (padapter->pbuddy_adapter->hw_init_completed == _FALSE))
4433         {               
4434                 res = _FALSE;
4435         }
4436         else
4437         {
4438                 res = _TRUE;
4439         }       
4440
4441         return res;     
4442
4443 }
4444
4445 sint check_buddy_fwstate(_adapter *padapter, sint state)
4446 {
4447         if(padapter == NULL)
4448                 return _FALSE;  
4449         
4450         if(padapter->pbuddy_adapter == NULL)
4451                 return _FALSE;  
4452                 
4453         if ((state == WIFI_FW_NULL_STATE) && 
4454                 (padapter->pbuddy_adapter->mlmepriv.fw_state == WIFI_FW_NULL_STATE))
4455                 return _TRUE;           
4456         
4457         if (padapter->pbuddy_adapter->mlmepriv.fw_state & state)
4458                 return _TRUE;
4459
4460         return _FALSE;
4461 }
4462
4463 u8 rtw_get_buddy_bBusyTraffic(_adapter *padapter)
4464 {
4465         if(padapter == NULL)
4466                 return _FALSE;  
4467         
4468         if(padapter->pbuddy_adapter == NULL)
4469                 return _FALSE;  
4470         
4471         return padapter->pbuddy_adapter->mlmepriv.LinkDetectInfo.bBusyTraffic;
4472 }
4473
4474 #endif //CONFIG_CONCURRENT_MODE