staging: rtl8188eu: prevent an underflow in rtw_check_beacon_data()
[linux-block.git] / drivers / staging / rtl8188eu / core / rtw_ap.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2012 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  ******************************************************************************/
15 #define _RTW_AP_C_
16
17 #include <linux/ieee80211.h>
18
19 #include <osdep_service.h>
20 #include <drv_types.h>
21 #include <wifi.h>
22 #include <ieee80211.h>
23 #include <asm/unaligned.h>
24
25 #ifdef CONFIG_88EU_AP_MODE
26
27 void init_mlme_ap_info(struct adapter *padapter)
28 {
29         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
30         struct sta_priv *pstapriv = &padapter->stapriv;
31         struct wlan_acl_pool *pacl_list = &pstapriv->acl_list;
32
33         spin_lock_init(&pmlmepriv->bcn_update_lock);
34
35         /* for ACL */
36         _rtw_init_queue(&pacl_list->acl_node_q);
37
38         start_ap_mode(padapter);
39 }
40
41 void free_mlme_ap_info(struct adapter *padapter)
42 {
43         struct sta_info *psta = NULL;
44         struct sta_priv *pstapriv = &padapter->stapriv;
45         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
46         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
47         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
48
49         pmlmepriv->update_bcn = false;
50         pmlmeext->bstart_bss = false;
51
52         rtw_sta_flush(padapter);
53
54         pmlmeinfo->state = _HW_STATE_NOLINK_;
55
56         /* free_assoc_sta_resources */
57         rtw_free_all_stainfo(padapter);
58
59         /* free bc/mc sta_info */
60         psta = rtw_get_bcmc_stainfo(padapter);
61         spin_lock_bh(&pstapriv->sta_hash_lock);
62         rtw_free_stainfo(padapter, psta);
63         spin_unlock_bh(&pstapriv->sta_hash_lock);
64 }
65
66 static void update_BCNTIM(struct adapter *padapter)
67 {
68         struct sta_priv *pstapriv = &padapter->stapriv;
69         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
70         struct mlme_ext_info *pmlmeinfo = &pmlmeext->mlmext_info;
71         struct wlan_bssid_ex *pnetwork_mlmeext = &pmlmeinfo->network;
72         unsigned char *pie = pnetwork_mlmeext->IEs;
73         u8 *p, *dst_ie, *premainder_ie = NULL;
74         u8 *pbackup_remainder_ie = NULL;
75         uint offset, tmp_len, tim_ielen, tim_ie_offset, remainder_ielen;
76
77         /* update TIM IE */
78         p = rtw_get_ie(pie + _FIXED_IE_LENGTH_, _TIM_IE_, &tim_ielen,
79                         pnetwork_mlmeext->IELength - _FIXED_IE_LENGTH_);
80         if (p && tim_ielen > 0) {
81                 tim_ielen += 2;
82                 premainder_ie = p + tim_ielen;
83                 tim_ie_offset = (int)(p - pie);
84                 remainder_ielen = pnetwork_mlmeext->IELength -
85                                         tim_ie_offset - tim_ielen;
86                 /* append TIM IE from dst_ie offset */
87                 dst_ie = p;
88         } else {
89                 tim_ielen = 0;
90
91                 /* calculate head_len */
92                 offset = _FIXED_IE_LENGTH_;
93                 offset += pnetwork_mlmeext->Ssid.SsidLength + 2;
94
95                 /*  get supported rates len */
96                 p = rtw_get_ie(pie + _BEACON_IE_OFFSET_, _SUPPORTEDRATES_IE_,
97                                &tmp_len, (pnetwork_mlmeext->IELength -
98                                           _BEACON_IE_OFFSET_));
99                 if (p)
100                         offset += tmp_len+2;
101
102                 /* DS Parameter Set IE, len = 3 */
103                 offset += 3;
104
105                 premainder_ie = pie + offset;
106
107                 remainder_ielen = pnetwork_mlmeext->IELength -
108                                         offset - tim_ielen;
109
110                 /* append TIM IE from offset */
111                 dst_ie = pie + offset;
112         }
113
114         if (remainder_ielen > 0) {
115                 pbackup_remainder_ie = rtw_malloc(remainder_ielen);
116                 if (pbackup_remainder_ie && premainder_ie)
117                         memcpy(pbackup_remainder_ie, premainder_ie,
118                                remainder_ielen);
119         }
120         *dst_ie++ = _TIM_IE_;
121
122         if ((pstapriv->tim_bitmap&0xff00) && (pstapriv->tim_bitmap&0x00fc))
123                 tim_ielen = 5;
124         else
125                 tim_ielen = 4;
126
127         *dst_ie++ = tim_ielen;
128
129         *dst_ie++ = 0;/* DTIM count */
130         *dst_ie++ = 1;/* DTIM period */
131
132         if (pstapriv->tim_bitmap&BIT(0))/* for bc/mc frames */
133                 *dst_ie++ = BIT(0);/* bitmap ctrl */
134         else
135                 *dst_ie++ = 0;
136
137         if (tim_ielen == 4) {
138                 *dst_ie++ = pstapriv->tim_bitmap & 0xff;
139         } else if (tim_ielen == 5) {
140                 put_unaligned_le16(pstapriv->tim_bitmap, dst_ie);
141                 dst_ie += 2;
142         }
143
144         /* copy remainder IE */
145         if (pbackup_remainder_ie) {
146                 memcpy(dst_ie, pbackup_remainder_ie, remainder_ielen);
147
148                 kfree(pbackup_remainder_ie);
149         }
150         offset =  (uint)(dst_ie - pie);
151         pnetwork_mlmeext->IELength = offset + remainder_ielen;
152
153         set_tx_beacon_cmd(padapter);
154 }
155
156 void rtw_add_bcn_ie(struct adapter *padapter, struct wlan_bssid_ex *pnetwork,
157                     u8 index, u8 *data, u8 len)
158 {
159         struct ndis_802_11_var_ie *pIE;
160         u8 bmatch = false;
161         u8 *pie = pnetwork->IEs;
162         u8 *p = NULL, *dst_ie = NULL, *premainder_ie = NULL;
163         u8 *pbackup_remainder_ie = NULL;
164         u32 i, offset, ielen = 0, ie_offset, remainder_ielen = 0;
165
166         for (i = sizeof(struct ndis_802_11_fixed_ie); i < pnetwork->IELength;) {
167                 pIE = (struct ndis_802_11_var_ie *)(pnetwork->IEs + i);
168
169                 if (pIE->ElementID > index) {
170                         break;
171                 /*  already exist the same IE */
172                 } else if (pIE->ElementID == index) {
173                         p = (u8 *)pIE;
174                         ielen = pIE->Length;
175                         bmatch = true;
176                         break;
177                 }
178                 p = (u8 *)pIE;
179                 ielen = pIE->Length;
180                 i += (pIE->Length + 2);
181         }
182
183         if (p && ielen > 0) {
184                 ielen += 2;
185
186                 premainder_ie = p + ielen;
187
188                 ie_offset = (int)(p - pie);
189
190                 remainder_ielen = pnetwork->IELength - ie_offset - ielen;
191
192                 if (bmatch)
193                         dst_ie = p;
194                 else
195                         dst_ie = p + ielen;
196         }
197
198         if (remainder_ielen > 0) {
199                 pbackup_remainder_ie = rtw_malloc(remainder_ielen);
200                 if (pbackup_remainder_ie && premainder_ie)
201                         memcpy(pbackup_remainder_ie, premainder_ie,
202                                remainder_ielen);
203         }
204
205         *dst_ie++ = index;
206         *dst_ie++ = len;
207
208         memcpy(dst_ie, data, len);
209         dst_ie += len;
210
211         /* copy remainder IE */
212         if (pbackup_remainder_ie) {
213                 memcpy(dst_ie, pbackup_remainder_ie, remainder_ielen);
214
215                 kfree(pbackup_remainder_ie);
216         }
217
218         offset =  (uint)(dst_ie - pie);
219         pnetwork->IELength = offset + remainder_ielen;
220 }
221
222 void rtw_remove_bcn_ie(struct adapter *padapter, struct wlan_bssid_ex *pnetwork,
223                        u8 index)
224 {
225         u8 *p, *dst_ie = NULL, *premainder_ie = NULL;
226         u8 *pbackup_remainder_ie = NULL;
227         uint offset, ielen, ie_offset, remainder_ielen = 0;
228         u8      *pie = pnetwork->IEs;
229
230         p = rtw_get_ie(pie + _FIXED_IE_LENGTH_, index, &ielen,
231                        pnetwork->IELength - _FIXED_IE_LENGTH_);
232         if (p && ielen > 0) {
233                 ielen += 2;
234
235                 premainder_ie = p + ielen;
236
237                 ie_offset = (int)(p - pie);
238
239                 remainder_ielen = pnetwork->IELength - ie_offset - ielen;
240
241                 dst_ie = p;
242         }
243
244         if (remainder_ielen > 0) {
245                 pbackup_remainder_ie = rtw_malloc(remainder_ielen);
246                 if (pbackup_remainder_ie && premainder_ie)
247                         memcpy(pbackup_remainder_ie, premainder_ie,
248                                remainder_ielen);
249         }
250
251         /* copy remainder IE */
252         if (pbackup_remainder_ie) {
253                 memcpy(dst_ie, pbackup_remainder_ie, remainder_ielen);
254
255                 kfree(pbackup_remainder_ie);
256         }
257
258         offset =  (uint)(dst_ie - pie);
259         pnetwork->IELength = offset + remainder_ielen;
260 }
261
262 static u8 chk_sta_is_alive(struct sta_info *psta)
263 {
264         u8 ret = false;
265
266         if ((psta->sta_stats.last_rx_data_pkts +
267                         psta->sta_stats.last_rx_ctrl_pkts) ==
268                         (psta->sta_stats.rx_data_pkts +
269                         psta->sta_stats.rx_ctrl_pkts))
270                 ;
271         else
272                 ret = true;
273
274         sta_update_last_rx_pkts(psta);
275
276         return ret;
277 }
278
279 void    expire_timeout_chk(struct adapter *padapter)
280 {
281         struct list_head *phead, *plist;
282         u8 updated = 0;
283         struct sta_info *psta = NULL;
284         struct sta_priv *pstapriv = &padapter->stapriv;
285         u8 chk_alive_num = 0;
286         char chk_alive_list[NUM_STA];
287         int i;
288
289         spin_lock_bh(&pstapriv->auth_list_lock);
290
291         phead = &pstapriv->auth_list;
292         plist = phead->next;
293
294         /* check auth_queue */
295         while (phead != plist) {
296                 psta = container_of(plist, struct sta_info, auth_list);
297                 plist = plist->next;
298
299                 if (psta->expire_to > 0) {
300                         psta->expire_to--;
301                         if (psta->expire_to == 0) {
302                                 list_del_init(&psta->auth_list);
303                                 pstapriv->auth_list_cnt--;
304
305                                 DBG_88E("auth expire %6ph\n",
306                                         psta->hwaddr);
307
308                                 spin_unlock_bh(&pstapriv->auth_list_lock);
309
310                                 spin_lock_bh(&pstapriv->sta_hash_lock);
311                                 rtw_free_stainfo(padapter, psta);
312                                 spin_unlock_bh(&pstapriv->sta_hash_lock);
313
314                                 spin_lock_bh(&pstapriv->auth_list_lock);
315                         }
316                 }
317
318         }
319         spin_unlock_bh(&pstapriv->auth_list_lock);
320
321         psta = NULL;
322
323         spin_lock_bh(&pstapriv->asoc_list_lock);
324
325         phead = &pstapriv->asoc_list;
326         plist = phead->next;
327
328         /* check asoc_queue */
329         while (phead != plist) {
330                 psta = container_of(plist, struct sta_info, asoc_list);
331                 plist = plist->next;
332
333                 if (chk_sta_is_alive(psta) || !psta->expire_to) {
334                         psta->expire_to = pstapriv->expire_to;
335                         psta->keep_alive_trycnt = 0;
336                         psta->under_exist_checking = 0;
337                 } else {
338                         psta->expire_to--;
339                 }
340
341                 if (psta->expire_to <= 0) {
342                         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
343
344                         if (padapter->registrypriv.wifi_spec == 1) {
345                                 psta->expire_to = pstapriv->expire_to;
346                                 continue;
347                         }
348
349                         if (psta->state & WIFI_SLEEP_STATE) {
350                                 if (!(psta->state & WIFI_STA_ALIVE_CHK_STATE)) {
351                                         /* to check if alive by another methods
352                                          * if station is at ps mode.
353                                          */
354                                         psta->expire_to = pstapriv->expire_to;
355                                         psta->state |= WIFI_STA_ALIVE_CHK_STATE;
356
357                                         /* to update bcn with tim_bitmap
358                                          * for this station
359                                          */
360                                         pstapriv->tim_bitmap |= BIT(psta->aid);
361                                         update_beacon(padapter, _TIM_IE_, NULL,
362                                                       false);
363
364                                         if (!pmlmeext->active_keep_alive_check)
365                                                 continue;
366                                 }
367                         }
368                         if (pmlmeext->active_keep_alive_check) {
369                                 int stainfo_offset;
370
371                                 stainfo_offset =
372                                         rtw_stainfo_offset(pstapriv, psta);
373                                 if (stainfo_offset_valid(stainfo_offset))
374                                         chk_alive_list[chk_alive_num++] = stainfo_offset;
375                                 continue;
376                         }
377
378                         list_del_init(&psta->asoc_list);
379                         pstapriv->asoc_list_cnt--;
380
381                         DBG_88E("asoc expire %pM, state = 0x%x\n", (psta->hwaddr), psta->state);
382                         updated = ap_free_sta(padapter, psta, true, WLAN_REASON_DEAUTH_LEAVING);
383                 } else {
384                         /* TODO: Aging mechanism to digest frames in sleep_q to avoid running out of xmitframe */
385                         if (psta->sleepq_len > (NR_XMITFRAME / pstapriv->asoc_list_cnt) &&
386                             padapter->xmitpriv.free_xmitframe_cnt < (NR_XMITFRAME / pstapriv->asoc_list_cnt / 2)) {
387                                 DBG_88E("%s sta:%pM, sleepq_len:%u, free_xmitframe_cnt:%u, asoc_list_cnt:%u, clear sleep_q\n", __func__,
388                                         (psta->hwaddr), psta->sleepq_len,
389                                         padapter->xmitpriv.free_xmitframe_cnt,
390                                         pstapriv->asoc_list_cnt);
391                                 wakeup_sta_to_xmit(padapter, psta);
392                         }
393                 }
394         }
395
396         spin_unlock_bh(&pstapriv->asoc_list_lock);
397
398         if (chk_alive_num) {
399                 u8 backup_oper_channel = 0;
400                 struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
401                 /* switch to correct channel of current network  before issue keep-alive frames */
402                 if (rtw_get_oper_ch(padapter) != pmlmeext->cur_channel) {
403                         backup_oper_channel = rtw_get_oper_ch(padapter);
404                         SelectChannel(padapter, pmlmeext->cur_channel);
405                 }
406
407                 /* issue null data to check sta alive*/
408                 for (i = 0; i < chk_alive_num; i++) {
409                         int ret = _FAIL;
410
411                         psta = rtw_get_stainfo_by_offset(pstapriv, chk_alive_list[i]);
412
413                         if (psta->state & WIFI_SLEEP_STATE)
414                                 ret = issue_nulldata(padapter, psta->hwaddr, 0, 1, 50);
415                         else
416                                 ret = issue_nulldata(padapter, psta->hwaddr, 0, 3, 50);
417
418                         psta->keep_alive_trycnt++;
419                         if (ret == _SUCCESS) {
420                                 DBG_88E("asoc check, sta(%pM) is alive\n", (psta->hwaddr));
421                                 psta->expire_to = pstapriv->expire_to;
422                                 psta->keep_alive_trycnt = 0;
423                                 continue;
424                         } else if (psta->keep_alive_trycnt <= 3) {
425                                 DBG_88E("ack check for asoc expire, keep_alive_trycnt =%d\n", psta->keep_alive_trycnt);
426                                 psta->expire_to = 1;
427                                 continue;
428                         }
429
430                         psta->keep_alive_trycnt = 0;
431
432                         DBG_88E("asoc expire %pM, state = 0x%x\n", (psta->hwaddr), psta->state);
433                         spin_lock_bh(&pstapriv->asoc_list_lock);
434                         list_del_init(&psta->asoc_list);
435                         pstapriv->asoc_list_cnt--;
436                         updated = ap_free_sta(padapter, psta, true, WLAN_REASON_DEAUTH_LEAVING);
437                         spin_unlock_bh(&pstapriv->asoc_list_lock);
438                 }
439
440                 if (backup_oper_channel > 0) /* back to the original operation channel */
441                         SelectChannel(padapter, backup_oper_channel);
442         }
443
444         associated_clients_update(padapter, updated);
445 }
446
447 void add_RATid(struct adapter *padapter, struct sta_info *psta, u8 rssi_level)
448 {
449         int i;
450         u32 init_rate = 0;
451         unsigned char sta_band = 0, raid, shortGIrate = false;
452         unsigned int tx_ra_bitmap = 0;
453         struct ht_priv  *psta_ht = NULL;
454         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
455         struct wlan_bssid_ex *pcur_network = (struct wlan_bssid_ex *)&pmlmepriv->cur_network.network;
456
457         if (psta)
458                 psta_ht = &psta->htpriv;
459         else
460                 return;
461
462         if (!(psta->state & _FW_LINKED))
463                 return;
464
465         /* b/g mode ra_bitmap */
466         for (i = 0; i < sizeof(psta->bssrateset); i++) {
467                 if (psta->bssrateset[i])
468                         tx_ra_bitmap |= rtw_get_bit_value_from_ieee_value(psta->bssrateset[i] & 0x7f);
469         }
470         /* n mode ra_bitmap */
471         if (psta_ht->ht_option) {
472                 for (i = 0; i < 8; i++)
473                         if (psta_ht->ht_cap.mcs.rx_mask[0] & BIT(i))
474                                 tx_ra_bitmap |= BIT(i + 12);
475
476                 /* max short GI rate */
477                 shortGIrate = psta_ht->sgi;
478         }
479
480         if (pcur_network->Configuration.DSConfig > 14) {
481                 /*  5G band */
482                 if (tx_ra_bitmap & 0xffff000)
483                         sta_band |= WIRELESS_11_5N | WIRELESS_11A;
484                 else
485                         sta_band |= WIRELESS_11A;
486         } else {
487                 if (tx_ra_bitmap & 0xffff000)
488                         sta_band |= WIRELESS_11_24N | WIRELESS_11G | WIRELESS_11B;
489                 else if (tx_ra_bitmap & 0xff0)
490                         sta_band |= WIRELESS_11G | WIRELESS_11B;
491                 else
492                         sta_band |= WIRELESS_11B;
493         }
494
495         psta->wireless_mode = sta_band;
496
497         raid = networktype_to_raid(sta_band);
498         init_rate = get_highest_rate_idx(tx_ra_bitmap & 0x0fffffff) & 0x3f;
499
500         if (psta->aid < NUM_STA) {
501                 u8 arg = 0;
502
503                 arg = psta->mac_id & 0x1f;
504
505                 arg |= BIT(7);/* support entry 2~31 */
506
507                 if (shortGIrate)
508                         arg |= BIT(5);
509
510                 tx_ra_bitmap |= ((raid << 28) & 0xf0000000);
511
512                 DBG_88E("%s => mac_id:%d , raid:%d , bitmap = 0x%x, arg = 0x%x\n",
513                         __func__, psta->mac_id, raid, tx_ra_bitmap, arg);
514
515                 /* bitmap[0:27] = tx_rate_bitmap */
516                 /* bitmap[28:31]= Rate Adaptive id */
517                 /* arg[0:4] = macid */
518                 /* arg[5] = Short GI */
519                 rtw_hal_add_ra_tid(padapter, tx_ra_bitmap, arg, rssi_level);
520
521                 if (shortGIrate)
522                         init_rate |= BIT(6);
523
524                 /* set ra_id, init_rate */
525                 psta->raid = raid;
526                 psta->init_rate = init_rate;
527
528         } else {
529                 DBG_88E("station aid %d exceed the max number\n", psta->aid);
530         }
531 }
532
533 static void update_bmc_sta(struct adapter *padapter)
534 {
535         u32 init_rate = 0;
536         unsigned char   network_type, raid;
537         int i, supportRateNum = 0;
538         unsigned int tx_ra_bitmap = 0;
539         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
540         struct wlan_bssid_ex *pcur_network = (struct wlan_bssid_ex *)&pmlmepriv->cur_network.network;
541         struct sta_info *psta = rtw_get_bcmc_stainfo(padapter);
542
543         if (psta) {
544                 psta->aid = 0;/* default set to 0 */
545                 psta->mac_id = psta->aid + 1;
546
547                 psta->qos_option = 0;
548                 psta->htpriv.ht_option = false;
549
550                 psta->ieee8021x_blocked = 0;
551
552                 memset(&psta->sta_stats, 0, sizeof(struct stainfo_stats));
553
554                 /* prepare for add_RATid */
555                 supportRateNum = rtw_get_rateset_len((u8 *)&pcur_network->SupportedRates);
556                 network_type = rtw_check_network_type((u8 *)&pcur_network->SupportedRates, supportRateNum, 1);
557
558                 memcpy(psta->bssrateset, &pcur_network->SupportedRates, supportRateNum);
559                 psta->bssratelen = supportRateNum;
560
561                 /* b/g mode ra_bitmap */
562                 for (i = 0; i < supportRateNum; i++) {
563                         if (psta->bssrateset[i])
564                                 tx_ra_bitmap |= rtw_get_bit_value_from_ieee_value(psta->bssrateset[i] & 0x7f);
565                 }
566
567                 if (pcur_network->Configuration.DSConfig > 14) {
568                         /* force to A mode. 5G doesn't support CCK rates */
569                         network_type = WIRELESS_11A;
570                         tx_ra_bitmap = 0x150; /*  6, 12, 24 Mbps */
571                 } else {
572                         /* force to b mode */
573                         network_type = WIRELESS_11B;
574                         tx_ra_bitmap = 0xf;
575                 }
576
577                 raid = networktype_to_raid(network_type);
578                 init_rate = get_highest_rate_idx(tx_ra_bitmap & 0x0fffffff) & 0x3f;
579
580                 /* ap mode */
581                 rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
582
583                 {
584                         u8 arg = 0;
585
586                         arg = psta->mac_id&0x1f;
587                         arg |= BIT(7);
588                         tx_ra_bitmap |= ((raid << 28) & 0xf0000000);
589                         DBG_88E("update_bmc_sta, mask = 0x%x, arg = 0x%x\n", tx_ra_bitmap, arg);
590
591                         /* bitmap[0:27] = tx_rate_bitmap */
592                         /* bitmap[28:31]= Rate Adaptive id */
593                         /* arg[0:4] = macid */
594                         /* arg[5] = Short GI */
595                         rtw_hal_add_ra_tid(padapter, tx_ra_bitmap, arg, 0);
596                 }
597                 /* set ra_id, init_rate */
598                 psta->raid = raid;
599                 psta->init_rate = init_rate;
600
601                 rtw_stassoc_hw_rpt(padapter, psta);
602
603                 spin_lock_bh(&psta->lock);
604                 psta->state = _FW_LINKED;
605                 spin_unlock_bh(&psta->lock);
606
607         } else {
608                 DBG_88E("add_RATid_bmc_sta error!\n");
609         }
610 }
611
612 /* notes: */
613 /* AID: 1~MAX for sta and 0 for bc/mc in ap/adhoc mode */
614 /* MAC_ID = AID+1 for sta in ap/adhoc mode */
615 /* MAC_ID = 1 for bc/mc for sta/ap/adhoc */
616 /* MAC_ID = 0 for bssid for sta/ap/adhoc */
617 /* CAM_ID = 0~3 for default key, cmd_id = macid + 3, macid = aid+1; */
618
619 void update_sta_info_apmode(struct adapter *padapter, struct sta_info *psta)
620 {
621         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
622         struct security_priv *psecuritypriv = &padapter->securitypriv;
623         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
624         struct ht_priv  *phtpriv_ap = &pmlmepriv->htpriv;
625         struct ht_priv  *phtpriv_sta = &psta->htpriv;
626
627         psta->mac_id = psta->aid + 1;
628         DBG_88E("%s\n", __func__);
629
630         /* ap mode */
631         rtw_hal_set_odm_var(padapter, HAL_ODM_STA_INFO, psta, true);
632
633         if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X)
634                 psta->ieee8021x_blocked = true;
635         else
636                 psta->ieee8021x_blocked = false;
637
638
639         /* update sta's cap */
640
641         /* ERP */
642         VCS_update(padapter, psta);
643         /* HT related cap */
644         if (phtpriv_sta->ht_option) {
645                 /* check if sta supports rx ampdu */
646                 phtpriv_sta->ampdu_enable = phtpriv_ap->ampdu_enable;
647
648                 /* check if sta support s Short GI */
649                 if (le16_to_cpu(phtpriv_sta->ht_cap.cap_info &
650                                 phtpriv_ap->ht_cap.cap_info) &
651                     (IEEE80211_HT_CAP_SGI_20 | IEEE80211_HT_CAP_SGI_40))
652                         phtpriv_sta->sgi = true;
653
654                 /*  bwmode */
655                 if (le16_to_cpu(phtpriv_sta->ht_cap.cap_info &
656                                 phtpriv_ap->ht_cap.cap_info) &
657                     IEEE80211_HT_CAP_SUP_WIDTH) {
658                         phtpriv_sta->bwmode = pmlmeext->cur_bwmode;
659                         phtpriv_sta->ch_offset = pmlmeext->cur_ch_offset;
660                 }
661                 psta->qos_option = true;
662         } else {
663                 phtpriv_sta->ampdu_enable = false;
664                 phtpriv_sta->sgi = false;
665                 phtpriv_sta->bwmode = HT_CHANNEL_WIDTH_20;
666                 phtpriv_sta->ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
667         }
668
669         /* Rx AMPDU */
670         send_delba(padapter, 0, psta->hwaddr);/*  recipient */
671
672         /* TX AMPDU */
673         send_delba(padapter, 1, psta->hwaddr);/* originator */
674         phtpriv_sta->agg_enable_bitmap = 0x0;/* reset */
675         phtpriv_sta->candidate_tid_bitmap = 0x0;/* reset */
676
677         /* todo: init other variables */
678
679         memset(&psta->sta_stats, 0, sizeof(struct stainfo_stats));
680
681         spin_lock_bh(&psta->lock);
682         psta->state |= _FW_LINKED;
683         spin_unlock_bh(&psta->lock);
684 }
685
686 static void update_hw_ht_param(struct adapter *padapter)
687 {
688         unsigned char           max_AMPDU_len;
689         unsigned char           min_MPDU_spacing;
690         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
691         struct mlme_ext_info    *pmlmeinfo = &pmlmeext->mlmext_info;
692
693         DBG_88E("%s\n", __func__);
694
695         /* handle A-MPDU parameter field */
696         /*
697                 ampdu_params_info [1:0]:Max AMPDU Len => 0:8k , 1:16k, 2:32k, 3:64k
698                 ampdu_params_info [4:2]:Min MPDU Start Spacing
699         */
700         max_AMPDU_len = pmlmeinfo->HT_caps.ampdu_params_info & 0x03;
701
702         min_MPDU_spacing = (pmlmeinfo->HT_caps.ampdu_params_info & 0x1c) >> 2;
703
704         rtw_hal_set_hwreg(padapter, HW_VAR_AMPDU_MIN_SPACE, (u8 *)(&min_MPDU_spacing));
705
706         rtw_hal_set_hwreg(padapter, HW_VAR_AMPDU_FACTOR, (u8 *)(&max_AMPDU_len));
707
708         /*  */
709         /*  Config SM Power Save setting */
710         /*  */
711         pmlmeinfo->SM_PS = (le16_to_cpu(pmlmeinfo->HT_caps.cap_info) & 0x0C) >> 2;
712         if (pmlmeinfo->SM_PS == WLAN_HT_CAP_SM_PS_STATIC)
713                 DBG_88E("%s(): WLAN_HT_CAP_SM_PS_STATIC\n", __func__);
714 }
715
716 static void start_bss_network(struct adapter *padapter, u8 *pbuf)
717 {
718         u8 *p;
719         u8 val8, cur_channel, cur_bwmode, cur_ch_offset;
720         u16 bcn_interval;
721         u32     acparm;
722         uint    ie_len;
723         struct registry_priv     *pregpriv = &padapter->registrypriv;
724         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
725         struct security_priv *psecuritypriv = &padapter->securitypriv;
726         struct wlan_bssid_ex *pnetwork = (struct wlan_bssid_ex *)&pmlmepriv->cur_network.network;
727         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
728         struct mlme_ext_info    *pmlmeinfo = &pmlmeext->mlmext_info;
729         struct wlan_bssid_ex *pnetwork_mlmeext = &pmlmeinfo->network;
730         struct HT_info_element *pht_info = NULL;
731
732         bcn_interval = (u16)pnetwork->Configuration.BeaconPeriod;
733         cur_channel = pnetwork->Configuration.DSConfig;
734         cur_bwmode = HT_CHANNEL_WIDTH_20;
735         cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
736
737
738         /* check if there is wps ie, */
739         /* if there is wpsie in beacon, the hostapd will update beacon twice when stating hostapd, */
740         /* and at first time the security ie (RSN/WPA IE) will not include in beacon. */
741         if (!rtw_get_wps_ie(pnetwork->IEs + _FIXED_IE_LENGTH_, pnetwork->IELength - _FIXED_IE_LENGTH_, NULL, NULL))
742                 pmlmeext->bstart_bss = true;
743
744         /* todo: update wmm, ht cap */
745         if (pmlmepriv->qospriv.qos_option)
746                 pmlmeinfo->WMM_enable = true;
747         if (pmlmepriv->htpriv.ht_option) {
748                 pmlmeinfo->WMM_enable = true;
749                 pmlmeinfo->HT_enable = true;
750
751                 update_hw_ht_param(padapter);
752         }
753
754         if (pmlmepriv->cur_network.join_res != true) { /* setting only at  first time */
755                 /* WEP Key will be set before this function, do not clear CAM. */
756                 if ((psecuritypriv->dot11PrivacyAlgrthm != _WEP40_) &&
757                     (psecuritypriv->dot11PrivacyAlgrthm != _WEP104_))
758                         flush_all_cam_entry(padapter);  /* clear CAM */
759         }
760
761         /* set MSR to AP_Mode */
762         Set_MSR(padapter, _HW_STATE_AP_);
763
764         /* Set BSSID REG */
765         rtw_hal_set_hwreg(padapter, HW_VAR_BSSID, pnetwork->MacAddress);
766
767         /* Set EDCA param reg */
768         acparm = 0x002F3217; /*  VO */
769         rtw_hal_set_hwreg(padapter, HW_VAR_AC_PARAM_VO, (u8 *)(&acparm));
770         acparm = 0x005E4317; /*  VI */
771         rtw_hal_set_hwreg(padapter, HW_VAR_AC_PARAM_VI, (u8 *)(&acparm));
772         acparm = 0x005ea42b;
773         rtw_hal_set_hwreg(padapter, HW_VAR_AC_PARAM_BE, (u8 *)(&acparm));
774         acparm = 0x0000A444; /*  BK */
775         rtw_hal_set_hwreg(padapter, HW_VAR_AC_PARAM_BK, (u8 *)(&acparm));
776
777         /* Set Security */
778         val8 = (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) ? 0xcc : 0xcf;
779         rtw_hal_set_hwreg(padapter, HW_VAR_SEC_CFG, (u8 *)(&val8));
780
781         /* Beacon Control related register */
782         rtw_hal_set_hwreg(padapter, HW_VAR_BEACON_INTERVAL, (u8 *)(&bcn_interval));
783
784         UpdateBrateTbl(padapter, pnetwork->SupportedRates);
785         rtw_hal_set_hwreg(padapter, HW_VAR_BASIC_RATE, pnetwork->SupportedRates);
786
787         if (!pmlmepriv->cur_network.join_res) { /* setting only at  first time */
788                 /* turn on all dynamic functions */
789                 Switch_DM_Func(padapter, DYNAMIC_ALL_FUNC_ENABLE, true);
790         }
791         /* set channel, bwmode */
792         p = rtw_get_ie((pnetwork->IEs + sizeof(struct ndis_802_11_fixed_ie)), _HT_ADD_INFO_IE_, &ie_len, (pnetwork->IELength - sizeof(struct ndis_802_11_fixed_ie)));
793         if (p && ie_len) {
794                 pht_info = (struct HT_info_element *)(p + 2);
795
796                 if ((pregpriv->cbw40_enable) &&  (pht_info->infos[0] & BIT(2))) {
797                         /* switch to the 40M Hz mode */
798                         cur_bwmode = HT_CHANNEL_WIDTH_40;
799                         switch (pht_info->infos[0] & 0x3) {
800                         case 1:
801                                 cur_ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;
802                                 break;
803                         case 3:
804                                 cur_ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;
805                                 break;
806                         default:
807                                 cur_ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
808                                 break;
809                         }
810                 }
811         }
812         /* TODO: need to judge the phy parameters on concurrent mode for single phy */
813         set_channel_bwmode(padapter, cur_channel, cur_ch_offset, cur_bwmode);
814
815         DBG_88E("CH =%d, BW =%d, offset =%d\n", cur_channel, cur_bwmode, cur_ch_offset);
816
817         /*  */
818         pmlmeext->cur_channel = cur_channel;
819         pmlmeext->cur_bwmode = cur_bwmode;
820         pmlmeext->cur_ch_offset = cur_ch_offset;
821         pmlmeext->cur_wireless_mode = pmlmepriv->cur_network.network_type;
822
823         /* update cur_wireless_mode */
824         update_wireless_mode(padapter);
825
826         /* update capability after cur_wireless_mode updated */
827         update_capinfo(padapter, rtw_get_capability((struct wlan_bssid_ex *)pnetwork));
828
829         /* let pnetwork_mlmeext == pnetwork_mlme. */
830         memcpy(pnetwork_mlmeext, pnetwork, pnetwork->Length);
831
832         if (pmlmeext->bstart_bss) {
833                 update_beacon(padapter, _TIM_IE_, NULL, false);
834
835                 /* issue beacon frame */
836                 if (send_beacon(padapter) == _FAIL)
837                         DBG_88E("send_beacon, fail!\n");
838         }
839
840         /* update bc/mc sta_info */
841         update_bmc_sta(padapter);
842 }
843
844 int rtw_check_beacon_data(struct adapter *padapter, u8 *pbuf,  int len)
845 {
846         int ret = _SUCCESS;
847         u8 *p;
848         u8 *pHT_caps_ie = NULL;
849         u8 *pHT_info_ie = NULL;
850         struct sta_info *psta = NULL;
851         u16 cap, ht_cap = false;
852         uint ie_len = 0;
853         int group_cipher, pairwise_cipher;
854         u8      channel, network_type, supportRate[NDIS_802_11_LENGTH_RATES_EX];
855         int supportRateNum = 0;
856         u8 OUI1[] = {0x00, 0x50, 0xf2, 0x01};
857         u8 WMM_PARA_IE[] = {0x00, 0x50, 0xf2, 0x02, 0x01, 0x01};
858         struct registry_priv *pregistrypriv = &padapter->registrypriv;
859         struct security_priv *psecuritypriv = &padapter->securitypriv;
860         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
861         struct wlan_bssid_ex *pbss_network = (struct wlan_bssid_ex *)&pmlmepriv->cur_network.network;
862         u8 *ie = pbss_network->IEs;
863
864         /* SSID */
865         /* Supported rates */
866         /* DS Params */
867         /* WLAN_EID_COUNTRY */
868         /* ERP Information element */
869         /* Extended supported rates */
870         /* WPA/WPA2 */
871         /* Wi-Fi Wireless Multimedia Extensions */
872         /* ht_capab, ht_oper */
873         /* WPS IE */
874
875         DBG_88E("%s, len =%d\n", __func__, len);
876
877         if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != true)
878                 return _FAIL;
879
880
881         if (len < 0 || len > MAX_IE_SZ)
882                 return _FAIL;
883
884         pbss_network->IELength = len;
885
886         memset(ie, 0, MAX_IE_SZ);
887
888         memcpy(ie, pbuf, pbss_network->IELength);
889
890
891         if (pbss_network->InfrastructureMode != Ndis802_11APMode)
892                 return _FAIL;
893
894         pbss_network->Rssi = 0;
895
896         ether_addr_copy(pbss_network->MacAddress, myid(&padapter->eeprompriv));
897
898         /* beacon interval */
899         p = rtw_get_beacon_interval_from_ie(ie);/* 8: TimeStamp, 2: Beacon Interval 2:Capability */
900         pbss_network->Configuration.BeaconPeriod = get_unaligned_le16(p);
901
902         /* capability */
903         cap = get_unaligned_le16(ie);
904
905         /* SSID */
906         p = rtw_get_ie(ie + _BEACON_IE_OFFSET_, _SSID_IE_, &ie_len, (pbss_network->IELength - _BEACON_IE_OFFSET_));
907         if (p && ie_len > 0) {
908                 memset(&pbss_network->Ssid, 0, sizeof(struct ndis_802_11_ssid));
909                 memcpy(pbss_network->Ssid.Ssid, (p + 2), ie_len);
910                 pbss_network->Ssid.SsidLength = ie_len;
911         }
912
913         /* channel */
914         channel = 0;
915         pbss_network->Configuration.Length = 0;
916         p = rtw_get_ie(ie + _BEACON_IE_OFFSET_, _DSSET_IE_, &ie_len, (pbss_network->IELength - _BEACON_IE_OFFSET_));
917         if (p && ie_len > 0)
918                 channel = *(p + 2);
919
920         pbss_network->Configuration.DSConfig = channel;
921
922         memset(supportRate, 0, NDIS_802_11_LENGTH_RATES_EX);
923         /*  get supported rates */
924         p = rtw_get_ie(ie + _BEACON_IE_OFFSET_, _SUPPORTEDRATES_IE_, &ie_len, (pbss_network->IELength - _BEACON_IE_OFFSET_));
925         if (p) {
926                 memcpy(supportRate, p + 2, ie_len);
927                 supportRateNum = ie_len;
928         }
929
930         /* get ext_supported rates */
931         p = rtw_get_ie(ie + _BEACON_IE_OFFSET_, _EXT_SUPPORTEDRATES_IE_, &ie_len, pbss_network->IELength - _BEACON_IE_OFFSET_);
932         if (p) {
933                 memcpy(supportRate + supportRateNum, p + 2, ie_len);
934                 supportRateNum += ie_len;
935         }
936
937         network_type = rtw_check_network_type(supportRate, supportRateNum, channel);
938
939         rtw_set_supported_rate(pbss_network->SupportedRates, network_type);
940
941         /* parsing ERP_IE */
942         p = rtw_get_ie(ie + _BEACON_IE_OFFSET_, _ERPINFO_IE_, &ie_len, (pbss_network->IELength - _BEACON_IE_OFFSET_));
943         if (p && ie_len > 0)
944                 ERP_IE_handler(padapter, (struct ndis_802_11_var_ie *)p);
945
946         /* update privacy/security */
947         if (cap & BIT(4))
948                 pbss_network->Privacy = 1;
949         else
950                 pbss_network->Privacy = 0;
951
952         psecuritypriv->wpa_psk = 0;
953
954         /* wpa2 */
955         group_cipher = 0;
956         pairwise_cipher = 0;
957         psecuritypriv->wpa2_group_cipher = _NO_PRIVACY_;
958         psecuritypriv->wpa2_pairwise_cipher = _NO_PRIVACY_;
959         p = rtw_get_ie(ie + _BEACON_IE_OFFSET_, _RSN_IE_2_, &ie_len, (pbss_network->IELength - _BEACON_IE_OFFSET_));
960         if (p && ie_len > 0) {
961                 if (rtw_parse_wpa2_ie(p, ie_len + 2, &group_cipher, &pairwise_cipher, NULL) == _SUCCESS) {
962                         psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_8021X;
963
964                         psecuritypriv->dot8021xalg = 1;/* psk,  todo:802.1x */
965                         psecuritypriv->wpa_psk |= BIT(1);
966
967                         psecuritypriv->wpa2_group_cipher = group_cipher;
968                         psecuritypriv->wpa2_pairwise_cipher = pairwise_cipher;
969                 }
970         }
971         /* wpa */
972         ie_len = 0;
973         group_cipher = 0;
974         pairwise_cipher = 0;
975         psecuritypriv->wpa_group_cipher = _NO_PRIVACY_;
976         psecuritypriv->wpa_pairwise_cipher = _NO_PRIVACY_;
977         for (p = ie + _BEACON_IE_OFFSET_;; p += (ie_len + 2)) {
978                 p = rtw_get_ie(p, _SSN_IE_1_, &ie_len,
979                                (pbss_network->IELength - _BEACON_IE_OFFSET_ - (ie_len + 2)));
980                 if ((p) && (!memcmp(p + 2, OUI1, 4))) {
981                         if (rtw_parse_wpa_ie(p, ie_len + 2, &group_cipher,
982                                              &pairwise_cipher, NULL) == _SUCCESS) {
983                                 psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_8021X;
984
985                                 psecuritypriv->dot8021xalg = 1;/* psk,  todo:802.1x */
986
987                                 psecuritypriv->wpa_psk |= BIT(0);
988
989                                 psecuritypriv->wpa_group_cipher = group_cipher;
990                                 psecuritypriv->wpa_pairwise_cipher = pairwise_cipher;
991                         }
992                         break;
993                 }
994                 if ((p == NULL) || (ie_len == 0))
995                         break;
996         }
997
998         /* wmm */
999         ie_len = 0;
1000         pmlmepriv->qospriv.qos_option = 0;
1001         if (pregistrypriv->wmm_enable) {
1002                 for (p = ie + _BEACON_IE_OFFSET_;; p += (ie_len + 2)) {
1003                         p = rtw_get_ie(p, _VENDOR_SPECIFIC_IE_, &ie_len,
1004                                        (pbss_network->IELength - _BEACON_IE_OFFSET_ - (ie_len + 2)));
1005                         if ((p) && !memcmp(p + 2, WMM_PARA_IE, 6)) {
1006                                 pmlmepriv->qospriv.qos_option = 1;
1007
1008                                 *(p + 8) |= BIT(7);/* QoS Info, support U-APSD */
1009
1010                                 /* disable all ACM bits since the WMM admission control is not supported */
1011                                 *(p + 10) &= ~BIT(4); /* BE */
1012                                 *(p + 14) &= ~BIT(4); /* BK */
1013                                 *(p + 18) &= ~BIT(4); /* VI */
1014                                 *(p + 22) &= ~BIT(4); /* VO */
1015                                 break;
1016                         }
1017
1018                         if ((p == NULL) || (ie_len == 0))
1019                                 break;
1020                 }
1021         }
1022         /* parsing HT_CAP_IE */
1023         p = rtw_get_ie(ie + _BEACON_IE_OFFSET_, _HT_CAPABILITY_IE_, &ie_len,
1024                        (pbss_network->IELength - _BEACON_IE_OFFSET_));
1025         if (p && ie_len > 0) {
1026                 struct ieee80211_ht_cap *pht_cap = (struct ieee80211_ht_cap *)(p + 2);
1027
1028                 pHT_caps_ie = p;
1029                 ht_cap = true;
1030                 network_type |= WIRELESS_11_24N;
1031
1032                 if ((psecuritypriv->wpa_pairwise_cipher & WPA_CIPHER_CCMP) ||
1033                     (psecuritypriv->wpa2_pairwise_cipher & WPA_CIPHER_CCMP))
1034                         pht_cap->ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY & (0x07 << 2));
1035                 else
1036                         pht_cap->ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_DENSITY&0x00);
1037
1038                 /* set  Max Rx AMPDU size  to 64K */
1039                 pht_cap->ampdu_params_info |= (IEEE80211_HT_CAP_AMPDU_FACTOR & 0x03);
1040
1041                 pht_cap->mcs.rx_mask[0] = 0xff;
1042                 pht_cap->mcs.rx_mask[1] = 0x0;
1043                 memcpy(&pmlmepriv->htpriv.ht_cap, p+2, ie_len);
1044         }
1045
1046         /* parsing HT_INFO_IE */
1047         p = rtw_get_ie(ie + _BEACON_IE_OFFSET_, _HT_ADD_INFO_IE_, &ie_len,
1048                        (pbss_network->IELength - _BEACON_IE_OFFSET_));
1049         if (p && ie_len > 0)
1050                 pHT_info_ie = p;
1051         switch (network_type) {
1052         case WIRELESS_11B:
1053                 pbss_network->NetworkTypeInUse = Ndis802_11DS;
1054                 break;
1055         case WIRELESS_11G:
1056         case WIRELESS_11BG:
1057         case WIRELESS_11G_24N:
1058         case WIRELESS_11BG_24N:
1059                 pbss_network->NetworkTypeInUse = Ndis802_11OFDM24;
1060                 break;
1061         case WIRELESS_11A:
1062                 pbss_network->NetworkTypeInUse = Ndis802_11OFDM5;
1063                 break;
1064         default:
1065                 pbss_network->NetworkTypeInUse = Ndis802_11OFDM24;
1066                 break;
1067         }
1068
1069         pmlmepriv->cur_network.network_type = network_type;
1070
1071         pmlmepriv->htpriv.ht_option = false;
1072
1073         if ((psecuritypriv->wpa2_pairwise_cipher & WPA_CIPHER_TKIP) ||
1074             (psecuritypriv->wpa_pairwise_cipher & WPA_CIPHER_TKIP)) {
1075                 /* todo: */
1076                 /* ht_cap = false; */
1077         }
1078
1079         /* ht_cap */
1080         if (pregistrypriv->ht_enable && ht_cap) {
1081                 pmlmepriv->htpriv.ht_option = true;
1082                 pmlmepriv->qospriv.qos_option = 1;
1083
1084                 if (pregistrypriv->ampdu_enable == 1)
1085                         pmlmepriv->htpriv.ampdu_enable = true;
1086                 HT_caps_handler(padapter, (struct ndis_802_11_var_ie *)pHT_caps_ie);
1087
1088                 HT_info_handler(padapter, (struct ndis_802_11_var_ie *)pHT_info_ie);
1089         }
1090
1091         pbss_network->Length = get_wlan_bssid_ex_sz((struct wlan_bssid_ex  *)pbss_network);
1092
1093         /* issue beacon to start bss network */
1094         start_bss_network(padapter, (u8 *)pbss_network);
1095
1096         /* alloc sta_info for ap itself */
1097         psta = rtw_get_stainfo(&padapter->stapriv, pbss_network->MacAddress);
1098         if (!psta) {
1099                 psta = rtw_alloc_stainfo(&padapter->stapriv, pbss_network->MacAddress);
1100                 if (psta == NULL)
1101                         return _FAIL;
1102         }
1103
1104         /* fix bug of flush_cam_entry at STOP AP mode */
1105         psta->state |= WIFI_AP_STATE;
1106         rtw_indicate_connect(padapter);
1107         pmlmepriv->cur_network.join_res = true;/* for check if already set beacon */
1108         return ret;
1109 }
1110
1111 void rtw_set_macaddr_acl(struct adapter *padapter, int mode)
1112 {
1113         struct sta_priv *pstapriv = &padapter->stapriv;
1114         struct wlan_acl_pool *pacl_list = &pstapriv->acl_list;
1115
1116         DBG_88E("%s, mode =%d\n", __func__, mode);
1117
1118         pacl_list->mode = mode;
1119 }
1120
1121 int rtw_acl_add_sta(struct adapter *padapter, u8 *addr)
1122 {
1123         struct list_head *plist, *phead;
1124         u8 added = false;
1125         int i, ret = 0;
1126         struct rtw_wlan_acl_node *paclnode;
1127         struct sta_priv *pstapriv = &padapter->stapriv;
1128         struct wlan_acl_pool *pacl_list = &pstapriv->acl_list;
1129         struct __queue *pacl_node_q = &pacl_list->acl_node_q;
1130
1131         DBG_88E("%s(acl_num =%d) =%pM\n", __func__, pacl_list->num, (addr));
1132
1133         if ((NUM_ACL - 1) < pacl_list->num)
1134                 return -1;
1135
1136         spin_lock_bh(&pacl_node_q->lock);
1137
1138         phead = get_list_head(pacl_node_q);
1139         plist = phead->next;
1140
1141         while (phead != plist) {
1142                 paclnode = container_of(plist, struct rtw_wlan_acl_node, list);
1143                 plist = plist->next;
1144
1145                 if (!memcmp(paclnode->addr, addr, ETH_ALEN)) {
1146                         if (paclnode->valid) {
1147                                 added = true;
1148                                 DBG_88E("%s, sta has been added\n", __func__);
1149                                 break;
1150                         }
1151                 }
1152         }
1153
1154         spin_unlock_bh(&pacl_node_q->lock);
1155
1156         if (added)
1157                 return ret;
1158
1159         spin_lock_bh(&pacl_node_q->lock);
1160
1161         for (i = 0; i < NUM_ACL; i++) {
1162                 paclnode = &pacl_list->aclnode[i];
1163
1164                 if (!paclnode->valid) {
1165                         INIT_LIST_HEAD(&paclnode->list);
1166
1167                         ether_addr_copy(paclnode->addr, addr);
1168
1169                         paclnode->valid = true;
1170
1171                         list_add_tail(&paclnode->list, get_list_head(pacl_node_q));
1172
1173                         pacl_list->num++;
1174
1175                         break;
1176                 }
1177         }
1178
1179         DBG_88E("%s, acl_num =%d\n", __func__, pacl_list->num);
1180
1181         spin_unlock_bh(&pacl_node_q->lock);
1182
1183         return ret;
1184 }
1185
1186 int rtw_acl_remove_sta(struct adapter *padapter, u8 *addr)
1187 {
1188         struct list_head *plist, *phead;
1189         struct rtw_wlan_acl_node *paclnode;
1190         struct sta_priv *pstapriv = &padapter->stapriv;
1191         struct wlan_acl_pool *pacl_list = &pstapriv->acl_list;
1192         struct __queue *pacl_node_q = &pacl_list->acl_node_q;
1193
1194         DBG_88E("%s(acl_num =%d) =%pM\n", __func__, pacl_list->num, (addr));
1195
1196         spin_lock_bh(&pacl_node_q->lock);
1197
1198         phead = get_list_head(pacl_node_q);
1199         plist = phead->next;
1200
1201         while (phead != plist) {
1202                 paclnode = container_of(plist, struct rtw_wlan_acl_node, list);
1203                 plist = plist->next;
1204
1205                 if (!memcmp(paclnode->addr, addr, ETH_ALEN)) {
1206                         if (paclnode->valid) {
1207                                 paclnode->valid = false;
1208
1209                                 list_del_init(&paclnode->list);
1210
1211                                 pacl_list->num--;
1212                         }
1213                 }
1214         }
1215
1216         spin_unlock_bh(&pacl_node_q->lock);
1217
1218         DBG_88E("%s, acl_num =%d\n", __func__, pacl_list->num);
1219         return 0;
1220 }
1221
1222 static void update_bcn_erpinfo_ie(struct adapter *padapter)
1223 {
1224         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1225         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
1226         struct mlme_ext_info    *pmlmeinfo = &pmlmeext->mlmext_info;
1227         struct wlan_bssid_ex *pnetwork = &pmlmeinfo->network;
1228         unsigned char *p, *ie = pnetwork->IEs;
1229         u32 len = 0;
1230
1231         DBG_88E("%s, ERP_enable =%d\n", __func__, pmlmeinfo->ERP_enable);
1232
1233         if (!pmlmeinfo->ERP_enable)
1234                 return;
1235
1236         /* parsing ERP_IE */
1237         p = rtw_get_ie(ie + _BEACON_IE_OFFSET_, _ERPINFO_IE_, &len,
1238                        (pnetwork->IELength - _BEACON_IE_OFFSET_));
1239         if (p && len > 0) {
1240                 struct ndis_802_11_var_ie *pIE = (struct ndis_802_11_var_ie *)p;
1241
1242                 if (pmlmepriv->num_sta_non_erp == 1)
1243                         pIE->data[0] |= RTW_ERP_INFO_NON_ERP_PRESENT|RTW_ERP_INFO_USE_PROTECTION;
1244                 else
1245                         pIE->data[0] &= ~(RTW_ERP_INFO_NON_ERP_PRESENT|RTW_ERP_INFO_USE_PROTECTION);
1246
1247                 if (pmlmepriv->num_sta_no_short_preamble > 0)
1248                         pIE->data[0] |= RTW_ERP_INFO_BARKER_PREAMBLE_MODE;
1249                 else
1250                         pIE->data[0] &= ~(RTW_ERP_INFO_BARKER_PREAMBLE_MODE);
1251
1252                 ERP_IE_handler(padapter, pIE);
1253         }
1254 }
1255
1256 static void update_bcn_wps_ie(struct adapter *padapter)
1257 {
1258         u8 *pwps_ie = NULL, *pwps_ie_src;
1259         u8 *premainder_ie, *pbackup_remainder_ie = NULL;
1260         uint wps_ielen = 0, wps_offset, remainder_ielen;
1261         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1262         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
1263         struct mlme_ext_info    *pmlmeinfo = &pmlmeext->mlmext_info;
1264         struct wlan_bssid_ex *pnetwork = &pmlmeinfo->network;
1265         unsigned char *ie = pnetwork->IEs;
1266         u32 ielen = pnetwork->IELength;
1267
1268         DBG_88E("%s\n", __func__);
1269
1270         pwps_ie_src = pmlmepriv->wps_beacon_ie;
1271         if (pwps_ie_src == NULL)
1272                 return;
1273
1274         pwps_ie = rtw_get_wps_ie(ie+_FIXED_IE_LENGTH_, ielen-_FIXED_IE_LENGTH_, NULL, &wps_ielen);
1275
1276         if (pwps_ie == NULL || wps_ielen == 0)
1277                 return;
1278
1279         wps_offset = (uint)(pwps_ie-ie);
1280
1281         premainder_ie = pwps_ie + wps_ielen;
1282
1283         remainder_ielen = ielen - wps_offset - wps_ielen;
1284
1285         if (remainder_ielen > 0) {
1286                 pbackup_remainder_ie = rtw_malloc(remainder_ielen);
1287                 if (pbackup_remainder_ie)
1288                         memcpy(pbackup_remainder_ie, premainder_ie, remainder_ielen);
1289         }
1290
1291         wps_ielen = (uint)pwps_ie_src[1];/* to get ie data len */
1292         if ((wps_offset+wps_ielen+2+remainder_ielen) <= MAX_IE_SZ) {
1293                 memcpy(pwps_ie, pwps_ie_src, wps_ielen+2);
1294                 pwps_ie += (wps_ielen+2);
1295
1296                 if (pbackup_remainder_ie)
1297                         memcpy(pwps_ie, pbackup_remainder_ie, remainder_ielen);
1298
1299                 /* update IELength */
1300                 pnetwork->IELength = wps_offset + (wps_ielen+2) + remainder_ielen;
1301         }
1302
1303         kfree(pbackup_remainder_ie);
1304 }
1305
1306 static void update_bcn_vendor_spec_ie(struct adapter *padapter, u8 *oui)
1307 {
1308         DBG_88E("%s\n", __func__);
1309
1310         if (!memcmp(WPS_OUI, oui, 4))
1311                 update_bcn_wps_ie(padapter);
1312         else
1313                 DBG_88E("unknown OUI type!\n");
1314 }
1315
1316 void update_beacon(struct adapter *padapter, u8 ie_id, u8 *oui, u8 tx)
1317 {
1318         struct mlme_priv *pmlmepriv;
1319         struct mlme_ext_priv    *pmlmeext;
1320
1321         if (!padapter)
1322                 return;
1323
1324         pmlmepriv = &padapter->mlmepriv;
1325         pmlmeext = &padapter->mlmeextpriv;
1326
1327         if (!pmlmeext->bstart_bss)
1328                 return;
1329
1330         spin_lock_bh(&pmlmepriv->bcn_update_lock);
1331
1332         switch (ie_id) {
1333         case _TIM_IE_:
1334                 update_BCNTIM(padapter);
1335                 break;
1336         case _ERPINFO_IE_:
1337                 update_bcn_erpinfo_ie(padapter);
1338                 break;
1339         case _VENDOR_SPECIFIC_IE_:
1340                 update_bcn_vendor_spec_ie(padapter, oui);
1341                 break;
1342         default:
1343                 break;
1344         }
1345
1346         pmlmepriv->update_bcn = true;
1347
1348         spin_unlock_bh(&pmlmepriv->bcn_update_lock);
1349
1350         if (tx)
1351                 set_tx_beacon_cmd(padapter);
1352 }
1353
1354 /*
1355 op_mode
1356 Set to 0 (HT pure) under the following conditions
1357         - all STAs in the BSS are 20/40 MHz HT in 20/40 MHz BSS or
1358         - all STAs in the BSS are 20 MHz HT in 20 MHz BSS
1359 Set to 1 (HT non-member protection) if there may be non-HT STAs
1360         in both the primary and the secondary channel
1361 Set to 2 if only HT STAs are associated in BSS,
1362         however and at least one 20 MHz HT STA is associated
1363 Set to 3 (HT mixed mode) when one or more non-HT STAs are associated
1364         (currently non-GF HT station is considered as non-HT STA also)
1365 */
1366 static int rtw_ht_operation_update(struct adapter *padapter)
1367 {
1368         u16 cur_op_mode, new_op_mode;
1369         int op_mode_changes = 0;
1370         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1371         struct ht_priv  *phtpriv_ap = &pmlmepriv->htpriv;
1372
1373         if (pmlmepriv->htpriv.ht_option)
1374                 return 0;
1375
1376         DBG_88E("%s current operation mode = 0x%X\n",
1377                 __func__, pmlmepriv->ht_op_mode);
1378
1379         if (!(pmlmepriv->ht_op_mode & HT_INFO_OPERATION_MODE_NON_GF_DEVS_PRESENT) &&
1380             pmlmepriv->num_sta_ht_no_gf) {
1381                 pmlmepriv->ht_op_mode |=
1382                         HT_INFO_OPERATION_MODE_NON_GF_DEVS_PRESENT;
1383                 op_mode_changes++;
1384         } else if ((pmlmepriv->ht_op_mode &
1385                    HT_INFO_OPERATION_MODE_NON_GF_DEVS_PRESENT) &&
1386                    pmlmepriv->num_sta_ht_no_gf == 0) {
1387                 pmlmepriv->ht_op_mode &=
1388                         ~HT_INFO_OPERATION_MODE_NON_GF_DEVS_PRESENT;
1389                 op_mode_changes++;
1390         }
1391
1392         if (!(pmlmepriv->ht_op_mode & HT_INFO_OPERATION_MODE_NON_HT_STA_PRESENT) &&
1393             (pmlmepriv->num_sta_no_ht || pmlmepriv->olbc_ht)) {
1394                 pmlmepriv->ht_op_mode |= HT_INFO_OPERATION_MODE_NON_HT_STA_PRESENT;
1395                 op_mode_changes++;
1396         } else if ((pmlmepriv->ht_op_mode &
1397                     HT_INFO_OPERATION_MODE_NON_HT_STA_PRESENT) &&
1398                    (pmlmepriv->num_sta_no_ht == 0 && !pmlmepriv->olbc_ht)) {
1399                 pmlmepriv->ht_op_mode &=
1400                         ~HT_INFO_OPERATION_MODE_NON_HT_STA_PRESENT;
1401                 op_mode_changes++;
1402         }
1403
1404         /* Note: currently we switch to the MIXED op mode if HT non-greenfield
1405          * station is associated. Probably it's a theoretical case, since
1406          * it looks like all known HT STAs support greenfield.
1407          */
1408         new_op_mode = 0;
1409         if (pmlmepriv->num_sta_no_ht ||
1410             (pmlmepriv->ht_op_mode & HT_INFO_OPERATION_MODE_NON_GF_DEVS_PRESENT))
1411                 new_op_mode = OP_MODE_MIXED;
1412         else if ((le16_to_cpu(phtpriv_ap->ht_cap.cap_info) &
1413                   IEEE80211_HT_CAP_SUP_WIDTH) &&
1414                  pmlmepriv->num_sta_ht_20mhz)
1415                 new_op_mode = OP_MODE_20MHZ_HT_STA_ASSOCED;
1416         else if (pmlmepriv->olbc_ht)
1417                 new_op_mode = OP_MODE_MAY_BE_LEGACY_STAS;
1418         else
1419                 new_op_mode = OP_MODE_PURE;
1420
1421         cur_op_mode = pmlmepriv->ht_op_mode & HT_INFO_OPERATION_MODE_OP_MODE_MASK;
1422         if (cur_op_mode != new_op_mode) {
1423                 pmlmepriv->ht_op_mode &= ~HT_INFO_OPERATION_MODE_OP_MODE_MASK;
1424                 pmlmepriv->ht_op_mode |= new_op_mode;
1425                 op_mode_changes++;
1426         }
1427
1428         DBG_88E("%s new operation mode = 0x%X changes =%d\n",
1429                 __func__, pmlmepriv->ht_op_mode, op_mode_changes);
1430
1431         return op_mode_changes;
1432 }
1433
1434 void associated_clients_update(struct adapter *padapter, u8 updated)
1435 {
1436         /* update associated stations cap. */
1437         if (updated) {
1438                 struct list_head *phead, *plist;
1439                 struct sta_info *psta = NULL;
1440                 struct sta_priv *pstapriv = &padapter->stapriv;
1441
1442                 spin_lock_bh(&pstapriv->asoc_list_lock);
1443
1444                 phead = &pstapriv->asoc_list;
1445                 plist = phead->next;
1446
1447                 /* check asoc_queue */
1448                 while (phead != plist) {
1449                         psta = container_of(plist, struct sta_info, asoc_list);
1450
1451                         plist = plist->next;
1452
1453                         VCS_update(padapter, psta);
1454                 }
1455                 spin_unlock_bh(&pstapriv->asoc_list_lock);
1456         }
1457 }
1458
1459 /* called > TSR LEVEL for USB or SDIO Interface*/
1460 void bss_cap_update_on_sta_join(struct adapter *padapter, struct sta_info *psta)
1461 {
1462         u8 beacon_updated = false;
1463         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1464         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1465
1466         if (!(psta->flags & WLAN_STA_SHORT_PREAMBLE)) {
1467                 if (!psta->no_short_preamble_set) {
1468                         psta->no_short_preamble_set = 1;
1469
1470                         pmlmepriv->num_sta_no_short_preamble++;
1471
1472                         if ((pmlmeext->cur_wireless_mode > WIRELESS_11B) &&
1473                             (pmlmepriv->num_sta_no_short_preamble == 1)) {
1474                                 beacon_updated = true;
1475                                 update_beacon(padapter, 0xFF, NULL, true);
1476                         }
1477                 }
1478         } else {
1479                 if (psta->no_short_preamble_set) {
1480                         psta->no_short_preamble_set = 0;
1481
1482                         pmlmepriv->num_sta_no_short_preamble--;
1483
1484                         if ((pmlmeext->cur_wireless_mode > WIRELESS_11B) &&
1485                             (pmlmepriv->num_sta_no_short_preamble == 0)) {
1486                                 beacon_updated = true;
1487                                 update_beacon(padapter, 0xFF, NULL, true);
1488                         }
1489                 }
1490         }
1491
1492         if (psta->flags & WLAN_STA_NONERP) {
1493                 if (!psta->nonerp_set) {
1494                         psta->nonerp_set = 1;
1495
1496                         pmlmepriv->num_sta_non_erp++;
1497
1498                         if (pmlmepriv->num_sta_non_erp == 1) {
1499                                 beacon_updated = true;
1500                                 update_beacon(padapter, _ERPINFO_IE_, NULL, true);
1501                         }
1502                 }
1503         } else {
1504                 if (psta->nonerp_set) {
1505                         psta->nonerp_set = 0;
1506
1507                         pmlmepriv->num_sta_non_erp--;
1508
1509                         if (pmlmepriv->num_sta_non_erp == 0) {
1510                                 beacon_updated = true;
1511                                 update_beacon(padapter, _ERPINFO_IE_, NULL, true);
1512                         }
1513                 }
1514         }
1515
1516         if (!(psta->capability & WLAN_CAPABILITY_SHORT_SLOT_TIME)) {
1517                 if (!psta->no_short_slot_time_set) {
1518                         psta->no_short_slot_time_set = 1;
1519
1520                         pmlmepriv->num_sta_no_short_slot_time++;
1521
1522                         if ((pmlmeext->cur_wireless_mode > WIRELESS_11B) &&
1523                             (pmlmepriv->num_sta_no_short_slot_time == 1)) {
1524                                 beacon_updated = true;
1525                                 update_beacon(padapter, 0xFF, NULL, true);
1526                         }
1527                 }
1528         } else {
1529                 if (psta->no_short_slot_time_set) {
1530                         psta->no_short_slot_time_set = 0;
1531
1532                         pmlmepriv->num_sta_no_short_slot_time--;
1533
1534                         if ((pmlmeext->cur_wireless_mode > WIRELESS_11B) &&
1535                             (pmlmepriv->num_sta_no_short_slot_time == 0)) {
1536                                 beacon_updated = true;
1537                                 update_beacon(padapter, 0xFF, NULL, true);
1538                         }
1539                 }
1540         }
1541
1542         if (psta->flags & WLAN_STA_HT) {
1543                 u16 ht_capab = le16_to_cpu(psta->htpriv.ht_cap.cap_info);
1544
1545                 DBG_88E("HT: STA %pM HT Capabilities Info: 0x%04x\n",
1546                         (psta->hwaddr), ht_capab);
1547
1548                 if (psta->no_ht_set) {
1549                         psta->no_ht_set = 0;
1550                         pmlmepriv->num_sta_no_ht--;
1551                 }
1552
1553                 if ((ht_capab & IEEE80211_HT_CAP_GRN_FLD) == 0) {
1554                         if (!psta->no_ht_gf_set) {
1555                                 psta->no_ht_gf_set = 1;
1556                                 pmlmepriv->num_sta_ht_no_gf++;
1557                         }
1558                         DBG_88E("%s STA %pM - no greenfield, num of non-gf stations %d\n",
1559                                 __func__, (psta->hwaddr),
1560                                 pmlmepriv->num_sta_ht_no_gf);
1561                 }
1562
1563                 if ((ht_capab & IEEE80211_HT_CAP_SUP_WIDTH) == 0) {
1564                         if (!psta->ht_20mhz_set) {
1565                                 psta->ht_20mhz_set = 1;
1566                                 pmlmepriv->num_sta_ht_20mhz++;
1567                         }
1568                         DBG_88E("%s STA %pM - 20 MHz HT, num of 20MHz HT STAs %d\n",
1569                                 __func__, (psta->hwaddr),
1570                                 pmlmepriv->num_sta_ht_20mhz);
1571                 }
1572         } else {
1573                 if (!psta->no_ht_set) {
1574                         psta->no_ht_set = 1;
1575                         pmlmepriv->num_sta_no_ht++;
1576                 }
1577                 if (pmlmepriv->htpriv.ht_option) {
1578                         DBG_88E("%s STA %pM - no HT, num of non-HT stations %d\n",
1579                                 __func__, (psta->hwaddr),
1580                                 pmlmepriv->num_sta_no_ht);
1581                 }
1582         }
1583
1584         if (rtw_ht_operation_update(padapter) > 0) {
1585                 update_beacon(padapter, _HT_CAPABILITY_IE_, NULL, false);
1586                 update_beacon(padapter, _HT_ADD_INFO_IE_, NULL, true);
1587         }
1588
1589         /* update associated stations cap. */
1590         associated_clients_update(padapter,  beacon_updated);
1591
1592         DBG_88E("%s, updated =%d\n", __func__, beacon_updated);
1593 }
1594
1595 u8 bss_cap_update_on_sta_leave(struct adapter *padapter, struct sta_info *psta)
1596 {
1597         u8 beacon_updated = false;
1598         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1599         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1600
1601         if (!psta)
1602                 return beacon_updated;
1603
1604         if (psta->no_short_preamble_set) {
1605                 psta->no_short_preamble_set = 0;
1606                 pmlmepriv->num_sta_no_short_preamble--;
1607                 if (pmlmeext->cur_wireless_mode > WIRELESS_11B &&
1608                     pmlmepriv->num_sta_no_short_preamble == 0) {
1609                         beacon_updated = true;
1610                         update_beacon(padapter, 0xFF, NULL, true);
1611                 }
1612         }
1613
1614         if (psta->nonerp_set) {
1615                 psta->nonerp_set = 0;
1616                 pmlmepriv->num_sta_non_erp--;
1617                 if (pmlmepriv->num_sta_non_erp == 0) {
1618                         beacon_updated = true;
1619                         update_beacon(padapter, _ERPINFO_IE_, NULL, true);
1620                 }
1621         }
1622
1623         if (psta->no_short_slot_time_set) {
1624                 psta->no_short_slot_time_set = 0;
1625                 pmlmepriv->num_sta_no_short_slot_time--;
1626                 if (pmlmeext->cur_wireless_mode > WIRELESS_11B &&
1627                     pmlmepriv->num_sta_no_short_slot_time == 0) {
1628                         beacon_updated = true;
1629                         update_beacon(padapter, 0xFF, NULL, true);
1630                 }
1631         }
1632
1633         if (psta->no_ht_gf_set) {
1634                 psta->no_ht_gf_set = 0;
1635                 pmlmepriv->num_sta_ht_no_gf--;
1636         }
1637
1638         if (psta->no_ht_set) {
1639                 psta->no_ht_set = 0;
1640                 pmlmepriv->num_sta_no_ht--;
1641         }
1642
1643         if (psta->ht_20mhz_set) {
1644                 psta->ht_20mhz_set = 0;
1645                 pmlmepriv->num_sta_ht_20mhz--;
1646         }
1647
1648         if (rtw_ht_operation_update(padapter) > 0) {
1649                 update_beacon(padapter, _HT_CAPABILITY_IE_, NULL, false);
1650                 update_beacon(padapter, _HT_ADD_INFO_IE_, NULL, true);
1651         }
1652
1653         /* update associated stations cap. */
1654
1655         DBG_88E("%s, updated =%d\n", __func__, beacon_updated);
1656
1657         return beacon_updated;
1658 }
1659
1660 u8 ap_free_sta(struct adapter *padapter, struct sta_info *psta,
1661                bool active, u16 reason)
1662 {
1663         u8 beacon_updated = false;
1664         struct sta_priv *pstapriv = &padapter->stapriv;
1665
1666         if (!psta)
1667                 return beacon_updated;
1668
1669         /* tear down Rx AMPDU */
1670         send_delba(padapter, 0, psta->hwaddr);/*  recipient */
1671
1672         /* tear down TX AMPDU */
1673         send_delba(padapter, 1, psta->hwaddr);/*  originator */
1674         psta->htpriv.agg_enable_bitmap = 0x0;/* reset */
1675         psta->htpriv.candidate_tid_bitmap = 0x0;/* reset */
1676
1677         if (active)
1678                 issue_deauth(padapter, psta->hwaddr, reason);
1679
1680         /* clear cam entry / key */
1681         rtw_clearstakey_cmd(padapter, (u8 *)psta, (u8)(psta->mac_id + 3), true);
1682
1683
1684         spin_lock_bh(&psta->lock);
1685         psta->state &= ~_FW_LINKED;
1686         spin_unlock_bh(&psta->lock);
1687
1688         rtw_indicate_sta_disassoc_event(padapter, psta);
1689
1690         report_del_sta_event(padapter, psta->hwaddr, reason);
1691
1692         beacon_updated = bss_cap_update_on_sta_leave(padapter, psta);
1693
1694         spin_lock_bh(&pstapriv->sta_hash_lock);
1695         rtw_free_stainfo(padapter, psta);
1696         spin_unlock_bh(&pstapriv->sta_hash_lock);
1697
1698         return beacon_updated;
1699 }
1700
1701 int rtw_sta_flush(struct adapter *padapter)
1702 {
1703         struct list_head *phead, *plist;
1704         struct sta_info *psta = NULL;
1705         struct sta_priv *pstapriv = &padapter->stapriv;
1706         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1707         struct mlme_ext_info    *pmlmeinfo = &pmlmeext->mlmext_info;
1708         u8 bc_addr[ETH_ALEN] = {0xff, 0xff, 0xff, 0xff, 0xff, 0xff};
1709
1710         DBG_88E(FUNC_NDEV_FMT"\n", FUNC_NDEV_ARG(padapter->pnetdev));
1711
1712         if ((pmlmeinfo->state&0x03) != WIFI_FW_AP_STATE)
1713                 return 0;
1714
1715         spin_lock_bh(&pstapriv->asoc_list_lock);
1716         phead = &pstapriv->asoc_list;
1717         plist = phead->next;
1718
1719         /* free sta asoc_queue */
1720         while (phead != plist) {
1721                 psta = container_of(plist, struct sta_info, asoc_list);
1722
1723                 plist = plist->next;
1724
1725                 list_del_init(&psta->asoc_list);
1726                 pstapriv->asoc_list_cnt--;
1727
1728                 ap_free_sta(padapter, psta, true, WLAN_REASON_DEAUTH_LEAVING);
1729         }
1730         spin_unlock_bh(&pstapriv->asoc_list_lock);
1731
1732
1733         issue_deauth(padapter, bc_addr, WLAN_REASON_DEAUTH_LEAVING);
1734
1735         associated_clients_update(padapter, true);
1736
1737         return 0;
1738 }
1739
1740 /* called > TSR LEVEL for USB or SDIO Interface*/
1741 void sta_info_update(struct adapter *padapter, struct sta_info *psta)
1742 {
1743         int flags = psta->flags;
1744         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1745
1746         /* update wmm cap. */
1747         if (WLAN_STA_WME&flags)
1748                 psta->qos_option = 1;
1749         else
1750                 psta->qos_option = 0;
1751
1752         if (pmlmepriv->qospriv.qos_option == 0)
1753                 psta->qos_option = 0;
1754
1755         /* update 802.11n ht cap. */
1756         if (WLAN_STA_HT&flags) {
1757                 psta->htpriv.ht_option = true;
1758                 psta->qos_option = 1;
1759         } else {
1760                 psta->htpriv.ht_option = false;
1761         }
1762
1763         if (!pmlmepriv->htpriv.ht_option)
1764                 psta->htpriv.ht_option = false;
1765
1766         update_sta_info_apmode(padapter, psta);
1767 }
1768
1769 /* called >= TSR LEVEL for USB or SDIO Interface*/
1770 void ap_sta_info_defer_update(struct adapter *padapter, struct sta_info *psta)
1771 {
1772         if (psta->state & _FW_LINKED) {
1773                 /* add ratid */
1774                 add_RATid(padapter, psta, 0);/* DM_RATR_STA_INIT */
1775         }
1776 }
1777
1778 void start_ap_mode(struct adapter *padapter)
1779 {
1780         int i;
1781         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1782         struct sta_priv *pstapriv = &padapter->stapriv;
1783         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1784         struct wlan_acl_pool *pacl_list = &pstapriv->acl_list;
1785
1786         pmlmepriv->update_bcn = false;
1787
1788         pmlmeext->bstart_bss = false;
1789
1790         pmlmepriv->num_sta_non_erp = 0;
1791
1792         pmlmepriv->num_sta_no_short_slot_time = 0;
1793
1794         pmlmepriv->num_sta_no_short_preamble = 0;
1795
1796         pmlmepriv->num_sta_ht_no_gf = 0;
1797         pmlmepriv->num_sta_no_ht = 0;
1798         pmlmepriv->num_sta_ht_20mhz = 0;
1799
1800         pmlmepriv->olbc = false;
1801
1802         pmlmepriv->olbc_ht = false;
1803
1804         pmlmepriv->ht_op_mode = 0;
1805
1806         for (i = 0; i < NUM_STA; i++)
1807                 pstapriv->sta_aid[i] = NULL;
1808
1809         pmlmepriv->wps_beacon_ie = NULL;
1810         pmlmepriv->wps_probe_resp_ie = NULL;
1811         pmlmepriv->wps_assoc_resp_ie = NULL;
1812
1813         /* for ACL */
1814         INIT_LIST_HEAD(&pacl_list->acl_node_q.queue);
1815         pacl_list->num = 0;
1816         pacl_list->mode = 0;
1817         for (i = 0; i < NUM_ACL; i++) {
1818                 INIT_LIST_HEAD(&pacl_list->aclnode[i].list);
1819                 pacl_list->aclnode[i].valid = false;
1820         }
1821 }
1822
1823 void stop_ap_mode(struct adapter *padapter)
1824 {
1825         struct list_head *phead, *plist;
1826         struct rtw_wlan_acl_node *paclnode;
1827         struct sta_info *psta = NULL;
1828         struct sta_priv *pstapriv = &padapter->stapriv;
1829         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1830         struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
1831         struct wlan_acl_pool *pacl_list = &pstapriv->acl_list;
1832         struct __queue *pacl_node_q = &pacl_list->acl_node_q;
1833
1834         pmlmepriv->update_bcn = false;
1835         pmlmeext->bstart_bss = false;
1836
1837         /* reset and init security priv , this can refine with rtw_reset_securitypriv */
1838         memset((unsigned char *)&padapter->securitypriv, 0, sizeof(struct security_priv));
1839         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeOpen;
1840         padapter->securitypriv.ndisencryptstatus = Ndis802_11WEPDisabled;
1841
1842         /* for ACL */
1843         spin_lock_bh(&pacl_node_q->lock);
1844         phead = get_list_head(pacl_node_q);
1845         plist = phead->next;
1846         while (phead != plist) {
1847                 paclnode = container_of(plist, struct rtw_wlan_acl_node, list);
1848                 plist = plist->next;
1849
1850                 if (paclnode->valid) {
1851                         paclnode->valid = false;
1852
1853                         list_del_init(&paclnode->list);
1854
1855                         pacl_list->num--;
1856                 }
1857         }
1858         spin_unlock_bh(&pacl_node_q->lock);
1859
1860         DBG_88E("%s, free acl_node_queue, num =%d\n", __func__, pacl_list->num);
1861
1862         rtw_sta_flush(padapter);
1863
1864         /* free_assoc_sta_resources */
1865         rtw_free_all_stainfo(padapter);
1866
1867         psta = rtw_get_bcmc_stainfo(padapter);
1868         spin_lock_bh(&pstapriv->sta_hash_lock);
1869         rtw_free_stainfo(padapter, psta);
1870         spin_unlock_bh(&pstapriv->sta_hash_lock);
1871
1872         rtw_init_bcmc_stainfo(padapter);
1873
1874         rtw_free_mlme_priv_ie_data(pmlmepriv);
1875 }
1876
1877 #endif /* CONFIG_88EU_AP_MODE */